A: In today’s digital age, you have to protect your online accounts. Every week criminals hack into another company and steal information. In January 2023 PayPal suffered a well-publicized data breach.
You can sharply reduce your risks, but you’ll have to contend with Password Enemy #1.
Password Enemy #1
Short, eight-character passwords are Password Enemy #1.
If you follow the old wisdom on passwords, you risk having your accounts breached, your privacy invaded, and, worse yet, your identity stolen.
- Old Password Wisdom: Use eight characters, including upper- and lowercase letters, a number, and a symbol.
- New Password Wisdom: Eight characters are not enough!
You would be amazed at the ingenuity, persistence, and power of password crackers. They figure out the “clever” systems many of us devise for creating passwords that follow the password rules and that we can remember.
Unfortunately, the hackers are onto our little tricks. They know our substitutions, such as @ for a and $ for s, and much more. They develop pattern recognition code and enormous password libraries to crack most eight-character passwords in seconds.
12-Character Password Are Game-Changers
The difference between eight and 12 characters may seem small. To a thief, it makes all the difference.
Hackers are using botnets of millions of compromised personal computers to break passwords. They don’t need supercomputers to have supercomputer powers.
A 12-character password neutralizes the thieves’ supercomputer powers. With a mix of upper- and lowercase letters, numbers, and symbols, you can have up to 95^12 or 6.6 x 10^17 possible combinations. This is an astronomical number. Even if we “cheat” and don’t create truly random 12-character passwords, we can still foil the hackers.
Thieves don’t bother running their diabolical password crackers long enough on a single, strong, 12-character password. It would take many years to crack, even if not totally random.
New Password Rules
You can make your passwords strong enough by following these rules:
- Generate two or three words from a large word list, such as the 4 Letter Word Generator from Cool Generator.
- Break up each word with a symbol.
- Capitalize a letter and insert two numbers, but not at the beginning or end.
It is important to use a random word generator. Words that you dream up, especially if they relate to each other, are far more likely to be tried by a hacker’s program.
Here is an example of a good 12-character password created in this fashion:
This password doesn’t fit known patterns and isn’t made of any whole words.
How long would it take to crack it? Running 632 billion passwords per second, it would take eight million years!
To speed up your process of replacing passwords, create a list of good ones and then log into a number of your accounts to update their passwords. You don’t have to do all your accounts at once. Pace yourself.
How are you going to keep track of all your new, good passwords? With a password manager. But that is a topic for another Q&A. Stay tuned to Ask Techie for advice on password managers.
(Spoiler: Bitwarden is free, secure, and highly recommended by experts.)