As you may be aware, yesterday was World Password Day. So, at CSP we thought we could take a look into what makes a good password and what doesn’t. What is the latest advice on a strong password, ways you can make your life easier and which passwords are simply too easy to guess.
Single Sign-On
One way to reduce the number of passwords that you have to remember, is using single sign-on. This allows for a user to remember one set of credentials, and use this to automatically sign into other applications and services. As an example, you could use a google account to log into social media websites, it is far easier to remember one set of passwords. To compliment this, we would strongly recommend the use of Multi-Factor Authentication (MFA) to protect accounts.
This is one of the most effective ways of providing additional protection to passwords. Accounts that have been set up to use MFA require a second factor, which is something that you (and only you) can access. This could be a code that’s sent to you by text message, or that’s created by an app, so even if an attacker discovers a password, they won’t be able to access the associated account without also compromising the other factor.
Email addresses
One important password you need to protect is your email, your email password should be strong and different from all your other passwords. Combining 3 random words that each mean something to you, is a great way to create a password that is easy to remember but hard to crack. You should also turn on 2-step verification, to help provide extra protection
Password Deny List
As a business you should apply a password deny list, a deny list can be created from a published lists of common passwords or can be tailored to your organisation. The NCSC have created a text list of the 100,000 top compromised passwords from ‘Have I Been Pwned’ dataset. This is a good place to export and import into a deny list, you should consider banning words which have relevance to the business, as this is commonly used by users. To find this, look on the NCSC website for the ‘Passwords, Passwords everywhere’ blog post.
Our top tips for using stronger passwords
- Only use passwords where they are needed and appropriate.
- Use MFA where possible for all important accounts and internet facing systems.
- Use account lockout or throttling to defend against brute force attacks.
- Protect any access management systems you manage.
- Change all default passwords.
- Allow users to securely store their passwords.
- If password managers are used, encourage the use of the built-in password generator.
- Emphasise the risks of re-using passwords across work and home accounts.
So, with all that in mind, you should now be better equipped in protecting your passwords, accounts and potential sensitive information. For more help, contacts the CSP Team at info@csp.partners or call us on 0113 5323763.
