140 likes | 259 Views
Passwords are high value targets. Did your Adobe password leak? Now you and 150m others can check The Guardian, 7 November 2013. 2,000,000 passwords stolen from Facebook, Twitter and Google The Independent, 5 December 2013.
E N D
Passwords are high value targets • Did your Adobe password leak? Now you and 150m others can checkThe Guardian, 7 November 2013 2,000,000passwords stolen from Facebook, Twitter and Google The Independent, 5 December 2013 Stolen Facebookand Yahoo passwordsdumped onlineBBC News, 4 December 2013 Racing Post Breached: Users' Passwords StolenInfosecurity Magazine, 25 November 2013
How are passwords stolen? VIRUS Passwordcracking Phishing Malware
Password mistakes Pet’s name Significant dates Child’s name Username John Smith Place of birth Password Favourite football team 1234567 Photoshop • 123456 123456789 password 12345678 Qwerty 111111 123123 Partner’s name
Don’t make it easy! • Names, dictionary words or acronymsin any language • Sequential numbers (e.g. 12345678 or 987654321) • A word with a number after it (e.g. password1) • Your username • Logical number replacements for letters in a word (e.g. pa55w0rd) • Words that could be guessed easily by researching your life • Keyboard patterns (e.g. qwertyuiop or poiuytrewq)
How to create a strong password Use UPPER CASE and lower case letters Use at least eight characters, preferably more Use letters, numbers and special characters 2 3 1 Make itlook like a random configuration Use a passphrase 4 5
How to create a passphrase “I Eat Fish And Chips For Lunch Every Friday” “I Eat Fish And Chips For Lunch Every Friday” I E F A C F L E F Think of a phrase 1 • Take the initial letters 2 • Substitute some of the letters for logical numbers • 4 I E F A C 4 L E F 3 @ I E F @ C 4 L £ F £ • Add logical special characters e 4 • Ie F @ c 4 L £ f • Vary the letter case 5 c f
How to protect your passwords • Never reuse old passwords Passwords are classified Strictly Confidential • Never allow websites to remember your password • Never share your password • Never use the same password for different systems or devices • Passwords can only be stored in an encrypted file • Change default passwords immediately • Change your password every 90 days
Mobile device passwords and PINs Passwords and PINs must be at least four characters long Never use sequential numbers (e.g. 0000, 9999, etc.) Never use sequences (e.g. 1234, 9876, etc.) Make it appear random
Compromised password? Change your password immediately Contact the IT Helpdesk immediately Use Password Manager to protectyour passwords
To take away... Your passwords are extremely valuable Create strong passwords Never share your password Never use the same password for different systems or devices Passwords can only be stored in an encrypted format Report compromised passwords to the IT Helpdesk immediately