Long random password can secure you from hacking: Expert

Image
IANS New Delhi
Last Updated : Sep 25 2016 | 6:02 PM IST

With Yahoo announcing a massive data breach last week where 500 million of its user accounts were compromised in 2014, experts feel that the trick to avoid email account hacking is to use really long random string for a password.

"The password length should be at least 20 characters, but preferably 32," said lead researcher Jarno Niemela from the European cyber security provider F-Secure.

Criminals who attempt to crack the password databases use various forms of attacks based on words found in the dictionary.

This method usually works quite well because so many users pick terrible passwords.

"Humans in general are really bad password generators. No matter how unique you think your password is, its components are still likely to be in some dictionary, and a powerful cracking cluster will come up with the exactly right combination," Niemela said in a statement on Sunday.

But there are a few catches for this tip and two of them depend on the security practices of the service one is using.

First, the site or app has to accept long passwords and then the developers behind the software have to use any kind of "hashing" for the passwords they store.

Hashing employs an algorithm to hide passwords so they are not stored in clear text.

"So, you, as a customer, cannot affect what kind of password storage the service providers are using," he says, adding, "But you can still frustrate all but the most advanced attacker's efforts by using long enough random passwords."

So now you may be thinking: "Great! I have uncrackable passwords. They are also impossible to memorise."

Jarno recommended "some form of password storage" like F-Secure KEY which you can use on one device for free.

Many password lockers like KEY will help you generate extra long passwords, too.

"Also it might be a good idea to use a unique user name per service, and maybe unique email for critical services," Jarno said.

The unique user name will give you added privacy as you cannot be tracked easily across services.

--IANS

na/ask/dg

Disclaimer: No Business Standard Journalist was involved in creation of this content

*Subscribe to Business Standard digital and get complimentary access to The New York Times

Smart Quarterly

₹900

3 Months

₹300/Month

SAVE 25%

Smart Essential

₹2,700

1 Year

₹225/Month

SAVE 46%
*Complimentary New York Times access for the 2nd year will be given after 12 months

Super Saver

₹3,900

2 Years

₹162/Month

Subscribe

Renews automatically, cancel anytime

Here’s what’s included in our digital subscription plans

Exclusive premium stories online

  • Over 30 premium stories daily, handpicked by our editors

Complimentary Access to The New York Times

  • News, Games, Cooking, Audio, Wirecutter & The Athletic

Business Standard Epaper

  • Digital replica of our daily newspaper — with options to read, save, and share

Curated Newsletters

  • Insights on markets, finance, politics, tech, and more delivered to your inbox

Market Analysis & Investment Insights

  • In-depth market analysis & insights with access to The Smart Investor

Archives

  • Repository of articles and publications dating back to 1997

Ad-free Reading

  • Uninterrupted reading experience with no advertisements

Seamless Access Across All Devices

  • Access Business Standard across devices — mobile, tablet, or PC, via web or app

More From This Section

First Published: Sep 25 2016 | 5:54 PM IST

Next Story