Science News

Passwords Are A Piece Of Cake -- For Cybercrooks

ScienceDaily (July 23, 2007) — Choosing a good password is one of the many choices students make as they head to college, and it's a decision that should not be taken lightly, says David Ripley, researcher at the Pervasive Technology Labs' Advanced Network Management Lab at Indiana University Bloomington.

What really makes a password difficult -- or easy -- for someone else to figure out? A computer cracker or identity thief will never know the name of your favorite great-aunt's cousin's dog -- so that's a good password, right?

"Sadly, that's not true," said Ripley. "Modern-day bad guys don't bother trying to guess your password themselves; they have computers do it for them."

Using special programs and huge lists of words, these cybercrooks try millions of different words -- long words, short words and foreign words. They can try every word in every dictionary, in every language on Earth; every dog's and cat's and goldfish's name imaginable. They try all those words with dIffErenT cApITaLiZation, and all kinds of oth3r vArati0ns! They'll keep guessing for hours, or even days -- the program doing the guessing never gets tired or bored.

"A random string of numbers and letters makes the best password," says Ripley, "Unfortunately those are very difficult passwords for most people to remember."

Ripley offers these tips on choosing and protecting a password:

  • Long and complicated isn't so hard. Think of a phrase that will be easy for you to remember; use the first letter of each word to make a new word, leaving in the punctuation, capitalization and any numbers. Here's an example: "My first cat was named Fluffy. He was orange, with stripes. He only had 3 legs!" Taking the first letter of each word makes "MfcwnF.Hwo,ws.Hoh3l!"…which would be a really good password. Much better than just using the word "Fluffy."
  • Longer the better. In general, choose a longer password, rather than a shorter one.
  • Since you might forget ... Don't write passwords on a sticky note and leave them on your monitor or near your computer. And definitely don't keep your password in a text file on your computer as crackers can potentially access them. However, keeping a list of your passwords in an envelope in a safety deposit box, home safe, or other secure location away from the computer can be a good idea, just in case of an emergency.

Adapted from materials provided by Indiana University, via Newswise.
APA

MLA

Search ScienceDaily

Number of stories in archives: 44,032

Find with keyword(s):
 
Enter a keyword or phrase to search ScienceDaily's archives for related news topics,
the latest news stories, reference articles, science videos, images, and books.
 

Science Video News


Protect Yourself: Fighting Computer Crimes

Web sites that visualize images while the user enters a password could help prevent impostors from stealing personal data or money. The user would. ...  > full story

Breaking News

... from NewsDaily.com

In Other News ...

Copyright Reuters 2008. See Restrictions.

Free Subscriptions

... from ScienceDaily

Get the latest science news with our free email newsletters, updated daily and weekly. Or view hourly updated newsfeeds in your RSS reader:

Feedback

... we want to hear from you!

Tell us what you think of the new ScienceDaily -- we welcome both positive and negative comments. Have any problems using the site? Questions?
Post this page to your favorite social bookmarking site:
close
Include this item in your blog or web site:
close
Cite this article in your essay, paper, or report:
close
Email this page's link to a friend or colleague:
close