The Ins and Outs of Password Security | Mostly Blog
Recent News
Home / Software / The Ins and Outs of Password Security

The Ins and Outs of Password Security

Passwords today seem to have become something akin to modern house keys. They unlock the things that are most important to us, and if we lose them or they’re stolen, our lives can be disrupted. In the same way that it’s wise to have multiple ways of securing your house, the same care should be taken with passwords.

According to the Huffington Post, many people have still not moved away from the trend of using simple passwords for their many Web accounts. While this may make life much simpler, it also makes the task of swiping password much simpler for the hacker.

There are several ways to understand the basic concept of how passwords work, how they are transmitted to the server and what happens to them on their journey, and how you can take steps to make your passwords as secure as possible. These simple facts can make a big difference when it comes to personal data security, and those interested in learning more about cybersecurity would do well to master this basic knowledge.

The Creation of Secure Passwords

Many people are very familiar with the process of setting up an account on a website and creating a password to accompany it, but what happens to the password then?

In simple terms, a hash algorithm is the process of converting a simple string of text into a fixed length string of characters through the use of a mathematical equation. This means the password you type to access your account is converted, the server uses the algorithm to compare the hashed password against the hash of the original password and grants access based on that comparison.

How Passwords Are Stolen

Given the seemingly complex nature of the hash algorithm, it might seem that passwords are incredibly difficult or impossible to decipher. That is true in some regards but it is also much more complex.

In most cases, passwords are compromised due to user error. Phishing schemes are the most common method that hackers use to gain access to accounts. Mass emails are sent purportedly from the recipient’s bank or other financial company. The email indicates that a security breach has happened or account information needs to be updated, and the user is given a link to click to provide said information. The link text indicates that the actual company is represented, and the page the user is directed to may look legitimate as well. However, all of this is false, and the account password has just been stolen.

When user error is not the issue, it’s the security of a database or the specific hash algorithm. As cybersecurity becomes more involved and precise, so do hackers’ methods of attacking that security.

Total security depends on a number of factors, and the most important is likely to be database security. If the database is not as secure as it possibly can be, hackers can easily decipher the hash algorithms that have been used and potentially compromise hundreds of thousands of accounts. This was the method used by hackers in the data breach that Yahoo suffered in July of 2012.

How to Ensure Password Security

One of the most important steps a person can take is to create complex passwords. This advice has been given to consumers for years, but many don’t heed these instructions. In most cases, people are unsure of their ability to recall such complex strings of text, and realizing that keeping a written record of passwords is unwise, they revert back to simplicity. Many people also utilize simple variations of a password, which leaves multiple accounts at risk for compromise.

Perhaps the easiest and best method of password security is to purchase password management software. These programs create, organize and store passwords in a local database. Most of the programs utilize a master password key to open the database, and then use a password generator to randomly assign strings of text to accounts.

Online password managers are Web-based versions of password security software. These can be more convenient, as multiple users within a network can utilize the functions. However, cloud security is becoming more of an issue, and these types of password security functions would be at risk if the cloud was breached.

Touted by experts as the most secure form of password storage, the security token method utilizes chips, USB sticks or smart cards to gain access to the network. The disadvantage to this solution may be the expense involved, as the tokens and the methods of reading them must be installed on multiple systems. However, some Web services have made the security token process easier by simply sending an SMS token to the user’s phone, eliminating the need for the installation of complex POS systems.

While there may not ever be a truly secure way of storing passwords, IT and computer specialists continue to improve their methods of encryption and security. However, a great deal of responsibility lies with the user, so it’s important to be aware of the dos and don’ts of password security.

 

About Yogesh Giri

Leave a Reply

Your email address will not be published. Required fields are marked *

*

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

Scroll To Top