.
Feedback

Longer Passwords Are Better

By creating complex passwords you can help protect your email accounts from being hacked. The team at Portable CIO computer service shows you how.

By Evan Corstorphine, Portable CIO

The telephone calls we get go like this: “Over the last couple of days, all of my friends/business associates have begun receiving emails from me that have a link to a weird website, and their antivirus goes crazy when they go to it, but I didn’t send them that email. Then, it happened again this morning, and I’m starting to get concerned. Is my computer hacked?”  No, your computer isn’t hacked, your email password is hacked.

What is happening? The bad guys are relentless in their effort to find email accounts from which they can send spam email links to their infected websites to millions of people. Their infected website usually contains embedded code that will automatically try to infect your computer with something like “XP Antivirus,” the fake antivirus program that pops up endless messages telling you to enter your credit card information to “fix” it.  The more people they can trick into clicking onto their website, the more infections, and the larger number of people who unwittingly give out their credit card information to be stolen. More opportunity for identity theft is good business for the bad guys (and yes, people give their credit card information to them - we’ve seen it happen multiple times).

The bad guys have some extremely clever computer programs that go around and target email accounts from the largest email domains, such as AOL, Hotmail, ATT, MSN, Comcast and Yahoo. They go one by one, using a “bot” to test commonly used passwords and even attempting some limited brute-force cracking. This sort of “farming” of email addresses ensures they have a steady revenue stream. Virus infections are no longer courtesy of your neighborhood teenager experimenting on his dad’s computer. Now, they’re big business for Eastern Bloc mafia cartels, which goes far to explain why the problem has exploded over the last few years.

Back to passwords. Who do you think the bad guys are going to victimize? Are they going to be able to take over person A’s email account who uses the password “flower,” or person B who uses the password “Plausible*Deniability”?  If you guessed person A, you win. Why? According to the password checking website http://howsecureismypassword.net, “flower” is among the 260 most common passwords, so it would be hacked almost instantly, and “Plausible*Deniability” would take 28 million years for a common desktop computer to break. Even adding an exclamation point to “flower!” would only extend your safety to twelve minutes before it could be broken, because it’s a common word and it’s far too short. 

The problem with password security is that the IT guys (yes, heavy sigh, my brethren) have made password management a royal pain in the neck, and they have burned people out. If you work for a state or federal agency, or a typical large corporation, they’ve probably fueled the law of unintended consequences with rules that make it impossible to remember your password. I never thought it was reasonable to make people change their passwords every 30 days to something completely unique and unused over the previous year. I don’t know anyone who can remember that many unique complex passwords. What happens is that normal people like you and I end up writing down that ridiculous password we had to create (or that we were given), and we put it on a Post-it note, and stick it on our monitor or under our keyboard. We’re just trying to do our job, right? Who can remember this password: “3RzH@=#xFq” ? But sticking it on a Post-It note is not very secure, thus the unintended consequence.

Password philosophies are beginning to change. Long password phrases are more powerful than outright password complexity, because every additional simple character increases the complexity 26 times. But if you add complexity such as a punctuation mark to that phrase, a 20-character phrase is virtually un-crackable by common desktop standards, because it’s added an additional 33 character set that the cracker must include in their cracking search. For example, the phrase “twentygoodcharacters!” is one trillion times more complex than “twentygoodcharacters” because the addition of the exclamation mark increases the overall search space so dramatically. THAT is why upper and lower case, numbers and special characters are so important to use. 

Most websites don’t accommodate long phrases because they’re still adapting to this new knowledge. For example, AOL wants a password of between only 6-16 characters that must include letters, numbers and punctuation characters. Others want upper AND lower case letters, punctuation and numbers. One of their examples; Harry Potter becomes “ HaRrieP0tt3r!”.

There is much more to write about this, but I’m out of room. I’ve put some great links to password testing sites on Portable CIO’s Facebook page, as well as more examples of ways to substitute numbers and punctuation into a password in a way that helps it make sense. In the meantime, if you get stuck please call the experts at Portable CIO at (925)552-7953, or email us at helpdesk@theportablecio.com. 

Newsletter & Alerts

Get the best stories each day and important breaking news

Subscribe

Not from Lamorinda Patch? Find your Local Patch »

Loading comments ...
Note Article
Just a short thought to get the word out quickly about anything in your neighborhood.
Share something with your neighbors. Write a new post... What's up? Make an announcement, speak your mind, or sell something
LamorindaMan May 20, 2013 at 08:38 am
There were some rather inappropriate photos uploaded last week. I wonder if someone was offered upRead More as a sacrificial lamb because of it. I've never understood why Patch allows user submitted photos as it would seem that such a practice would allow such things to occur.
Danielle May 20, 2013 at 08:28 am
Heard about that but didn't see it though others apparently did. I have moved toRead More http://www.news24-680.com as JD landed there and they seem to be moving ahead. I hate to see anyone lose their work right now though.
Chris Nicholson May 20, 2013 at 08:22 am
Please elaborate. I must have missed something. Unless Lance was behind the IRS scandal.
Chris Nicholson May 19, 2013 at 09:38 am
LamoMan: "Back to school" is beginning of year and "Open House" is toward theRead More end. W/R/T high school, I agree with you that it's not as fun as K-5. I was disappointed, for example, to see no exemplary integral homework stapled to the wall of Calculus class-- I love the funny f/s hybrid symbol. Basically, I was bullied into attending by my wife (and the lure of Taco Truck catering). In seriousness, it was nice to stop by and (re)connect names and faces and be reminded of the dedication and talent of many (but not, ahem, all) of the teachers we're lucky enough to have here.
LamorindaMan May 18, 2013 at 11:46 pm
I don't have children so maybe I'm missing something. But, what is the point of an open house at theRead More high school level and what is the point of an open house at the end of the school year? What do they do at open house for high schoolers?
Vincent Carter May 17, 2013 at 01:21 am
At $400,000 of Tax Payer money i expected it to be the Contract Negotaitor.
Carlos Garcia May 16, 2013 at 04:43 pm
I imagine the person was a trainer
lovelafayette May 15, 2013 at 10:44 am
This brochure took a lot of work by a small group of people, supported by a cast of 400! We needRead More your help! PRINT AND SHARE AND POST this great flyer/sign. Parks is conducting a stealth campaign for BMX, NO PUBLICITY ALLOWED!! Jennifer Russell is hounding me personally using the CODE ENFORCEMENT OFFICER as a tool. I have been threatened with fines and fees, citations and misdemeanors, for informing the public about BMX. “Someone” posted our iconic signs, “Your Park with BMX”, on all the park public forum bulletin boards! No photos of the mystery posters exist, Jennifer lied and told code enforcement I admitted to posting THAT sign. I admitted posting signs about the April 8 meeting, but that is not the sign I am charged with! Please help confound the code enforcement officer by printing and posting and distributing this great flyer. Take it to church, youth group, PTA meetings. We could try our own stealth campaign, all wear Giants baseball hats and black hoodies! The rest of the story is at: WWW.NOLAFAYETTEBIKEPARK.COM and www.lafayettebikepark.com (city site) Suzanne Sommer lovelafayette@msn.com
Beau Behan April 23, 2013 at 03:00 pm
Hi Everyone, Thanks for dropping by PATCH. We really appreciate your taking the time. Hard toRead More imagine at times that Tom Cruise has been in the showbiz for at least three decades now.. It is as if it were just yesterday when I first watched "The Outsiders". We will have more film reviews for you all.. Thanks again. Beau
c5 April 23, 2013 at 02:12 pm
He was great in 'Risky Business', still one of my all time favorites. "Ok, which one of you isRead More the U-boat commander?".... :)
KAC April 22, 2013 at 09:56 pm
Tom Cruise? Pass...
LamorindaMan April 17, 2013 at 10:43 am
Will this workshop benefit motorcyclists? Bicycle riding requires way too much work. I'd rather rideRead More a motorcycle and let the engine do all the heavy lifting.
Napoleon Solo April 16, 2013 at 03:44 pm
They think they are doing something for the environment. When one of my kids had to do a schoolRead More project showing they were using recycled materials, I did not have anything reasonable around and had to go to the store, buy a large soda bottle, and pour it down the drain when I got home so there was a "recycled" item for the project. How did that save the environment?
CJ April 16, 2013 at 03:30 pm
Really?- How long is this farce going to be pushed? This has been going on for what seems likeRead More forever. 10 kids (of Envirotreehuggers) and 2- Environazi's will get on their bikes and ride to school and their nearby offices. While the rest of the reasonable people see this for what it is.....ridiculous. This will never be practical and if you want to be so, then do it without all the nonsense. I used to bike 15miles to my job and back, but that was when I was a wacked out Triathlete trying to qualify for Ironman. It is ridiculous as a daily practice for a myriad of reasons. Sustainable Lafaytette? - I sincerely hope this is not an actual public tax money paid position.
lovelafayette May 20, 2013 at 07:12 am
A dog park in Lafayette has been discussed by the Parks Department for years. Carol Singer, ParksRead More Commissioner always expresses interest but it never goes beyond talking. Parks is in the midst of a major review of CIP projects, email Council or Parks and let them know you want a dog park now! Funding is available, we just need to convince parks this is a priority.
TMoraga April 19, 2013 at 12:49 pm
Hey Paula you don't get it. It doesn't matter what happened. #1 School property is not an off leashRead More location. School district insurance doesn't cover such thing. And yes this is a big liability issue. Dogs! Do not belong on CAMPUS! It really is not hard to understand however if one can't grasp why this is a bad idea they probably should not have a dog in their stewardship either.
Paula Capps April 19, 2013 at 11:28 am
The dog group at Stanley has been going to the school for decades. We have always cleaned up afterRead More the dogs and everyone gets along beautifully. It's been a strong sense of community I myself gained from the group of kind and friendly owners. The incident that stemmed this has become distorted. There are other witnesses besides the parents who literally screamed at a very nice mild mannered young man. They cursed at him and treated him like dirt. What kind of an example was that to a child? His dog was not mean, excited yes, but in fact the dog diid NOT even touch the little girl. The girl chased after the dog's rolling ball. The dog came toward her to claim his ball. She freaked out and started screaming. Instead of talking to the little girl and man in instructive and calm ways to show dog and child all was ok the parents made themselves look crazy and the poor man was verbally abused. Dogs need to run and play just like people. I'd like to add it is a fine to throw food wrappers, bottles, cap tops, and unwanted food all over the field, and most anywhere in this lovely Bay Area we all share. l have picked up hands full, two and times each night. Why are parents allowing this? We have a beautiful place to live here please teach children to respect our earth. They'll be around here longer than the adults at this writing.