Don't make these common mistakes with your passwords

Passwords are a necessary evil. They’re a pain to create and a struggle to remember – as this comedian hilariously explains. But if you decide to take shortcuts, you make a hacker’s job much, much easier.

Fortunately, I know a few tricks to make the whole thing simpler. Before I get to that, though, it’s good to refresh your memory on a few ground rules for creating strong passwords. Let’s start with the most basic rule:

Don’t make the password easy to guess

Whenever there’s a big data breach and user passwords are exposed, security companies always make a list of the most common passwords people were using.

Among those studies, the five most common passwords were “123456,” “password,” “12345678,” “qwerty” and “12345.”

But weak passwords aren’t the only thing to watch out for. Hackers have computers that can “guess” for them. And chances are good that even security-conscious folks might make a common mistake in creating their password.

DARPA released a study not long ago that tracked passwords at a Fortune 100 company and found that about half followed five common patterns. Here are three of the most common patterns found in the study:

  • One uppercase, five lowercase and three digits (Example: Komand123)
  • One uppercase, six lowercase and two digits (Example: Komando12)
  • One uppercase, three lowercase and five digits (Example: Koma12345)

These are just things people do without thinking about them. However, if you create a password with any of those patterns it makes a computer’s job a lot easier.

Obviously, you shouldn’t use those patterns or anything like them. The same goes for using special dates, names of spouses, children, relatives or pets, or any password using the full name of the service you’re making the password for.

The strongest password is one that contains a random collection of letters (uppercase and lowercase), numbers and symbols. Of course, that’s nearly impossible to remember, but we’ll deal with that later on.

Make the password 8 characters or longer

Despite what you see in the movies, professional hackers rarely sit down at a computer and try to guess your password; that’s usually done by casual snoops such as relatives. Instead, hackers get millions of passwords at once from company data breaches or other sources.

You might have seen my coverage of a security vulnerability in Google Docs recently, a service that lets you save spreadsheets, text files and other productivity files online.

The flaw allowed crooks to potentially look at any document that they wanted without any password at all. Now normally this wouldn’t be such a big deal, but many users had passwords for other websites, bank account numbers and other information stored in a Google Doc file or spreadsheet.

If a hacker came across the right file, they would have stumbled across a goldmine. While remembering your passwords can be important – and forgetting them can sometimes be disastrous – it’s important to keep track of where you’re storing passwords.

Usually, if the breached company was being good, the leaked passwords were hashed so they’re just a huge string of letters and numbers. However, with enough passwords hashed the same way, hackers can figure out the scheme and decrypt many of them.

In fact, with modern computers, they can usually crack tens of thousands of passwords in mere hours.

The shorter passwords are easier to crack and hackers go for those first. As passwords get longer, it takes longer – as long as they aren’t obvious like “123456789”. Hackers scan for the obvious ones first a different way.

Many hackers don’t even bother with passwords eight characters or longer, although as computers get more powerful, it will take less time. So, 10 characters would be better.

Don’t use the same password everywhere

As I said, most hackers don’t try to guess your password. But if they get one of your passwords in a data breach, or from a virus on your computer, they will go after your other online accounts.

That’s why you want a different password for every account, especially your critical financial accounts. If the password they have doesn’t work right away, they’ll usually move on to someone else’s that does.

Creating a password

So, in summary, the ground rules for passwords are:

  1. It has to contain a random collection of letters (uppercase and lowercase), numbers and symbols
  2. It has to be eight characters or longer
  3. You have to create a unique password for every account

That’s a tall order. While something like “Tl|_|,BwwB2R” is really strong, it isn’t easy to remember. Or is it? Let me show you how I came up with it.

Start by thinking up a random sentence. You can use a catch phrase, quote or even a song lyric. I chose a lyric from one of my favorite songs: “Tramps like us, baby we were born to run.”

I took the first character from each word to get “tlu,bwwbtr”. Not bad, but it could be better. So, I added some symbols in place of similar letters. U becomes |_|, the “to” from the original lyric becomes 2. Then, I capitalized a few of the letters to make a strong password that I can easily remember: “Tl|_|,BwwB2R”.

Bonus tip: Setting up consistent symbol replacement and capitalization rules for all your passwords helps keep things from becoming too complex.

Once you have that you can tweak the same password for multiple accounts. For Facebook, you could make it “Tl|_|$,BwwB2RFB.” Amazon can be “AmzTl|_|$,BwwB2R.” You can make a consistent scheme there as well so you always know how you shorten the company name and where it goes.

Now, if you’re like me and have dozens of accounts online, even using this system can be too much. That’s why a password manager can be a great help. It keeps your passwords secure, and you only need to remember the one to open it.

Of course, a secure password doesn’t make a difference if a hacker can bypass it another way. Learn how to create a strong security question that hackers can’t guess.

Then head over to my Security Center for everything you need to know to secure your computers, smartphones, tablets, Wi-Fi and online accounts.

5 sites for men only - Covering the topics you care about most

Finding a good site to follow isn’t always easy, especially one that’s written specifically for a male audience. You could spend hours wading through webpages, looking for the good ones – but there’s no need.

Continue reading

Finding a sperm donor has become as easy as online shopping

Open/download audioImagine swiping left or right on your smartphone to choose your child, or scrolling through Facebook & Craigslist for a sperm donor. Today, non-traditional methods are taking over. The process is as easy as pointing & clicking. A day or two later, sperm is delivered to your house. In this Komando on Demand podcast, we speak with experts from a national sperm bank & a company that created an in-home kit to measure sperm count.

Learn more about your ad choices. Visit megaphone.fm/adchoices

5 details Facebook asks for that you shouldn't give

Facebook is all about making it easy to share your life with your friends and family. Unfortunately, there are just some things you shouldn’t share online. These bits of information can put you in danger of identity theft, losing your job or causing other major headaches.

Continue reading

Stop Facebook from following you around the web

Sometimes it seems like Facebook knows you personally, and that’s because it does. It has algorithms that track what you like, watch and click on. Facebook uses this information to target ads or relevant posts to users on behalf of advertisers. An ad pops up that’s right up your alley, or three new articles show up in your feed that are similar to something you’ve just clicked on. Luckily, there’s a way to stop this.

Continue reading

Best way to sell things online and not use Craigslist

You’ve heard the Craigslist scam horror stories. That’s why you have to be extremely careful about selling things online. But what if I told you there were better ways to sell your things locally? Here are three suggestions, starting with a site you’ve probably spent a few hours on today.

Continue reading

Read this before you take a Facebook quiz again

We get it. Facebook quizzes are fun. We all enjoy taking them, but they can also have a negative effect on your privacy. Keep reading to find out how scammers obtain your information and what you can do to avoid it.

Continue reading

How to read your 'secret' messages on Facebook

It’s always exciting when a new message pops up in Facebook Messenger. But guess what? There’s a hidden folder that might be holding messages you never knew about. I’ll show you how to access it.

Continue reading

3 ways to save money on your internet bill right now

If you feel like you never have enough money, your two options are to make more or spend less. I’m always looking for ways to share with you to help you make money on the side, on your schedule. Today, though, we’re going to talk about how to save money.

Continue reading

5 ways to find out if your computer is secure

There are always digital threats looming out there such as hackers, snoopers, viruses, phishing attacks, and I could go on. If you don’t think computer security is a big deal, think again. Hopefully, you’ve taken some steps to secure your devices, but the big question is whether it worked. Is your computer really safe? Here are some easy ways to make sure.

Continue reading

Make Amazon, Facebook and your other favorite services smarter

Tired of sites showing you recommendations for things you don’t even like? Tell them what you want to see.

Continue reading

5 ways people are getting scammed online

Between phishing scams, spyware, ransomware and the like, there are already tons of threats out there. But now there are other ways people are being fooled, and they’re much harder to decipher. Are you falling for these deceptive tactics? Read this, and I’ll show you five things you need to watch out for.

Continue reading

Incredibly quick fixes for your slow internet problem

Is there anything more frustrating than a slow internet connection? Just when you need it most, your internet slows to a crawl. It’s annoying, and it can also cause some serious problems. Don’t let that happen! Use these three tips to fix your sluggish Wi-Fi network.

Continue reading

Criminals using SIM card swaps to steal your money

Have you noticed some strange behavior from your phone lately? It could be a sign that your SIM card has been stolen. This critical chip is what tells the mobile network where to send your calls, voicemails and text messages. But thieves are more interested in intercepting the details of your bank account.

Continue reading

Avoid this viral Facebook survey at all costs!

We’ve all taken surveys on Facebook before, but this story will make you think twice! A viral survey that’s spreading around isn’t as harmless as it seems. Answering the questions it asks will put you at more risk than you realize. What makes this particular survey so dangerous?

Continue reading

Thieves stealing cars with $11 equipment

You’ve locked your car, but it’s not as safe as you think. Thieves have found a way to use cheap equipment to steal your vehicle. You’ll be shocked when you see how easy it is to gain access without picking locks or breaking windows. I’ll give you a hint: It has to do with the signal between your car and the fob on your keychain. Luckily, the solution is simple.

Continue reading

How to print from your smartphone

Here at Komando.com, we’ve made the argument that a modern tablet can replace your desktop or laptop computer … in certain cases. For web browsing, Facebook, email, watching videos, reading books and other basic tasks, a tablet, or even a smartphone, works just fine for many people.

Continue reading

Pesky Facebook bug gets you BANNED from your account!

We all know how addictive Facebook can be. For many people it’s the first site they check when they get up in the morning and the last site they visit before turning in for the night.

The social media giant must be doing something right to have nearly 2 billion active monthly users worldwide. Unfortunately, the company is having to deal with some irate customers because of a glitch locking them out of their account.

Continue reading

Easy desktop organizer saves you time and energy

It’s the little things that add up. At work, or when you’re on the computer at home, those little things include clicking from one window to another window, over and over.

Say you’re writing an email about last month’s expenses. Normally, you’d have your email open as you’re typing. But, you need to see your budget, perhaps on an Excel spreadsheet, so you click over to that to check the figures.

Continue reading

Take control of Google's interest-based ads

You’ve heard us talk about targeted ads before, and you’ve probably experienced them firsthand. This is when ads for an online store you shop at or a product you’ve looked at recently seem to follow you around the internet.

Continue reading