Remember Enid Blyton’s Secret Seven? Members of their team of little investigators would be allowed to attend meetings only if they were in possession of a password. The password would change periodically to ensure it was truly secret, and often reflected some interesting event that had taken place in their life, so that they would all find it easy to remember. That is essentially what a password should do in modern times as well. Your password should allow you, and only you, to gain access and control of your accounts. It should be easy for you to remember, without being obvious to others.
Your passwords are the keys to your digital life. Nowadays, this means so much more than just your email id. It can start with logging into your personal computer, and covers your Facebook profile, Twitter id, LinkedIn profile, blog, online music collection, confidential documents (if saved on cloud based services), bank accounts, stock trading accounts and lots more. Anyone who gains access to these with a malicious intent can cause significant damage depending on what part the web plays in your life. The keys to your house may be shared amongst family, but the keys to your digital life needs a lot more security than that.
It appears convenient to use a single password for everything you do online. But the risk is equally big, considering anyone who hacks into one of your accounts will have access to all your accounts. You may not care if someone hacks into your music collection, but if he/she can use the same password to transfer money from your bank account, or chat with your private circle of friends, then you have a bigger problem. The most common (and unimaginative) password in the world today, according to several surveys, is simply “password”. It is also one of the first words which will be attempted by those who try to gain unauthorised access to your account, in addition to your date of birth, first name, child’s name, pet name, and favourite sportsperson’s name. That means, those are bad ideas for secure passwords. But let’s agree that the average individual cannot remember more than two to three passwords at once, especially as you advance in age. Writing it down for reference often spoils the very purpose of having a password. What you need, in that case, is a formula to create secure passwords. Here is one suggestion:
Think of a keyword that you will certainly not forget. Since it won’t be used directly, it is all right to use a name, zodiac sign, favourite word or phrase. As an example, let us take CAR. Add a series of numbers, preferably not your date of birth or anniversary. Let us take a portion of a mobile phone number as part of this example: 9846, which will be familiar for all the old BPL Mobile subscribers. Now think of a two or three digit number, and add the symbol equivalents of those numbers (by pressing Shift along with those numbers on a normal keyboard). If we take 25, then the equivalent is @%. Add that in between the keyword and the number. So we have CAR@%9846, which in itself is a reasonably secure password by most websites’ standards. But here is the icing on the cake, designed to prevent having the same password for all services. To your password, add the first three letters of whichever website you are using. For example, your gmail password can be CAR@%9846GMA, while your Facebook password would be CAR@%9846FAC. Let me explain why this is a good password.
Many hackers use what is called a “brute force attack” to steal passwords. This involves individually trying out different key combinations (with the help of a computer) and checking for a match. As long as the hacker does not know how long your password is, he/she will need to try out different lengths, thus making the job harder. So, the longer your password, the tougher it is to break. Similarly, a homogenous password (one made up of alphabets only or numbers only, or symbols only) is easier to crack. So it is advisable to use a combination of all of these in your password. Of course, there are different methods, but this is one of the most common ones, according to many active hackers.
According to password testing services available on the web, the two passwords I suggested above will take a normal computer more than 3,40,000 years to crack. This is in comparison to “password” which it says would be cracked instantly, most dates of birth which would be cracked in 0.0025 seconds, and a stylised version of my own name, @ravind, which would take 48 seconds.
Of course, there can be no guarantees given on the topic. You can (and probably should) customise the formula I suggested, according to what suits you, especially by altering the order and lengths of the different components. Plus, of course, change the keyword, symbols and numbers once every few months, while remaining faithful to the formula to ensure you don’t forget it. After that, of course, hope for the best!