Skip to main content

Why you do not need 27 different passwords

Passwords. The bane of modern existence. To celebrate this nuisance, the holiday gods have given us World Password Day, where thousands of people come together online and pledge to improve their password habits. How many of those pledges do you think stick? According to the 2017 Verizon Data Breach Investigation Report, not many. A little over 50 percent of all breaches in the last year leveraged either stolen or weak passwords.

Coincidentally, today is also Star Wars Day (May the 4th Be with You). And while we all wouldn’t mind having a lovable droid guard our passwords as loyally as R2D2 guarded the blueprints for the Death Star, the reality is we’ve got to do the guarding ourselves. And that has become burdensome enough to send Yoda himself over to the Dark Side.

Current state of affairs

According to a poll by Intel Security, the average person has 27 discrete online logins. From social media accounts to banking to online shopping to utilities, credentials—which usually include a username and password—are required for each. And if people are practicing good password hygiene, they’re engaging in the following recommended practices:
  • DO: Use a different password for each account.
  • DO: Use a long password. In fact, the longer, the better.
  • DO: Use special characters, numbers, and capital letters.
  • DO: Change your passwords every couple of months.
  • DO NOT: Write down your password, whether that’s on a piece of paper or stored electronically.
  • DO NOT: Share passwords via text, email, or chat.
  • DO NOT: Use easily identifiable information, such as a birthday or a child’s name.
  • DO NOT: Use an incredibly generic password such as 12345. (That’s the combination an idiot would use on his luggage.)
All of this, for 27 different logins, is simply unmanageable. In fact, the Intel study found that 37 percent of its respondents forgot a password at least once a week. And people are so sick of juggling dozens of different passwords, that 20 percent said they would give up ESPN if it meant never having to remember another one. Six percent said they’d give up pizza. PIZZA.

This level of discontent and security fatigue means that very likely, most users are falling back on bad habits: writing passwords down in a notebook or a Google sheet, for example, or using the same password across multiple logins. (A study by the National Institute of Standards and Technology confirms this: 91 percent of its respondents admitted to reusing passwords.)

So this is why we say: stop it. Stop the bad habits, yes, but stop the “good” ones, too. Having 27 different passwords that are lengthy and full of characters and numbers and need to be changed every few months and can’t be written down—you’d need the memory of an eidetic elephant to keep up. Online services will only multiply, so what should you do?
It’s very simple. Get a password manager.

Password manager 101

For those who might not be familiar, password managers assist in generating, storing, and retrieving passwords from an encrypted database. They typically require that users create and remember one master password to rule them all. One master password to find them. One master password to bring them all, and in the darkness bind them.

One master password to stand at the precipice and shout gallantly, “YOU SHALL NOT PASS!”
Sorry, it couldn’t be helped. As we were saying. Generally, most password managers work the same way. You’ll be asked to create a strong master password during setup (and here’s where you’ll use those password best practices, such as generating a long passphrase with numbers and capitals that steers away from guessable personal info). From there, you’ll add your other credentials to the password manager either manually or through tools that can automatically find and upload passwords for you.

While most password managers have similar setups, they secure passwords in different ways. Web-based password managers store your passwords encrypted in the cloud. Some are built into browsers, such as Safari, Firefox, and Chrome. Others may store your passwords locally in an encrypted file on your computer, tablet, or phone.

In addition, some password managers have features that help you audit your credentials, allowing you to weed out duplicate login info and remove sites you don’t use, or alerting you to breaches that have happened to the companies you log into. Many have customizations that allow increased security, such as regional lockout and two-factor authentication (which we highly recommend taking advantage of).

But aren’t I just asking to be hacked by storing everything in one place?

While some folks might be wary of using a single point of access for all their sites, remember that password managers still use your individual passwords to log in to your accounts. Those passwords are locked in an encrypted database, which is way more secure than a post-it on your office desk or a faulty memory. Ask yourself this: is it safer to store all your money in one bank or to hide it in piles underneath several mattresses?

As for fear of password managers being breached—sure, it’s possible. In fact, it’s already happened, as was the case in 2015 when LastPass was breached. However, even though cybercriminals got their hands on some email addresses, they were unable to crack master passwords. This is because master passwords are protected with military-grade security, hidden behind thousands of rounds of hashing, or algorithms that convert strings of text into longer strings of text. So far, no reputable password manager has leaked consumer master passwords (that we know of).

So which password manager should I use?

The following password managers come highly recommended by our staff and tech reviewers from The New York Times, Lifehacker, and PCMag:
If you don’t trust third-party apps with all of your personal information, you can try an open-source password manager such as KeePassX, though it requires a fair bit of technical know-how to set up.

I am absolutely opposed to a password manager. What else can I do?

While we stand by our recommendation to use password managers, we understand the urge to reject placing all your trust in the hands of another company. So here are a few alternate methods for choosing more secure passwords than the random hodgepodge you’re likely working with now.
  1. Split up your online services into major groups, such as bills, entertainment, shopping, and social media. Assign a single password to each group according to a theme. For example, you could choose movies as your theme and assign quotes from one movie to one group, or character names from a second movie to the second group. Rotate these passwords every 90 days by incrementally adding a number or changing a character. This requires a lot more effort but is still preferable to using the same password across all accounts or having to reset forgotten passwords every week.
  2. Choose one semi-difficult password for all accounts but insert a naming convention in the middle of the password to denote which account you are signing into. For example, if your password is L3tme1npleaz, your Gmail password could be L3tme1nGMAILpleaz. Your Amazon password could be L3tme1nAMAZONpleaz, and so on and so forth.
  3. When possible, choose a service that has two-factor authentication over one that does not. More than 150 applications currently implement two-factor authentication. 
Passwords don’t have to rule your life. You can lock them up behind a password manager and worry about remembering a single, slightly complex phrase instead of 27. You can relax knowing how well guarded your passwords are. And you can go ahead and burn that secret list of passwords you keep in your address book even though you’re not supposed to.

Do you have a favorite password manager? Or a method for creating and remembering unique passwords? Let us know in the comments below.

Posted: May 4, 2017
Malwarebytes Labs by Wendy Zamora
Last updated: May 3, 2017

Comments

Popular posts from this blog

Sunday Reading - Year of the Fire Horse

        Year of the Fire Horse   Lunar New Year celebrations kick off  tomorrow, ushering in the Year of the Fire Horse in the Chinese zodiac. The 15-day festivities, observed by billions worldwide, start with the new moon and end with the Lantern Festival. China anticipates a record 9.5 billion trips during the 40-day travel rush around the holiday, the world’s largest annual human migration. The horse is the seventh animal in the 12-year zodiac cycle and symbolizes energy, independence, and ambition. Those born in horse years are seen as dynamic, courageous, and charismatic. Many see the Year of the Fire Horse as a time to tak...

The NCOFCU Podcast: Clear Insight. No Jargon.

Every week, we cover the latest trends and developments within the credit union industry. At NCOFCU, we are dedicated to providing you with insightful discussions that cut through the clutter. Our podcast features expert opinions, in-depth analyses, and an exploration of the challenges and opportunities that credit unions, directors, and staff face today. Join us as we navigate the evolving industry and empower associations with the knowledge they need to thrive. https://ceohp.podbean.com/ ================================================= Remember, you're not alone with  NCOFCU.org Join/Upgrade Check out some of NCOFCU's additional features: First Responder Credit Union Academy Financial Literacy Podcasts YouTube Mini's Blog Job Board

Why First Responder Credit Unions Are Built to Adopt Blockchain Faster

  For years, blockchain in financial services lived mostly in the world of experimentation—proofs of concept, pilot programs, and innovation labs that rarely touched day-to-day operations. That era is ending. Today, blockchain adoption is moving from experimentation to scale. Across payments, capital markets, and banking infrastructure, financial institutions are beginning to operate on new rails—powered by tokenized money, programmable assets, and always-on settlement models. For credit unions serving first responders, this shift presents not just a technology opportunity, but a strategic one. Blockchain Is Becoming Core Infrastructure The most important change isn’t the technology itself—it’s how it’s being used. Blockchain is no longer about testing what might work. It’s increasingly being deployed as infrastructure to solve long-standing problems in financial services, including slow settlement, trapped liquidity, manual reconciliation, and limited operating hours. Cr...

No New Pennies, New Rules: Treasury Sets Guidance For Cash Transactions

WASHINGTON—For credit unions and their members, the penny’s long goodbye is no longer theoretical—it’s operational. Just before Christmas the U.S. Treasury quietly released a detailed set of  Penny Production Cessation FAQs,  confirming that the federal government has stopped manufacturing new pennies and laying out how businesses, financial institutions, and consumers should prepare as the coin gradually slips out of everyday use. The move reflects a basic math problem: It now costs 3.69 cents to produce a single penny, nearly triple its cost a decade ago. Treasury estimates halting production will save taxpayers $56 million annually, while acknowledging that the coin’s purchasing power—and relevance—has steadily eroded in an economy dominated by electronic payments. What Changes At The Register—And What Doesn’t Despite the halt in production, pennies are not being eliminated. Roughly 114 billion pennies remain in circulation, and the Federal Reserve will continue recirculati...

Economic and Industry Issues

Weekly News Summary -  July 30, 2020 Press Release For Immediate Release Weekly News Summary Hello NCOFCU Members, Here are some things that were in the news last week. Please share these articles with your Supervisory Committee and Board of Directors. If you missed previous editions of the weekly news, summaries of those can be viewed at our  archive .  Have a great week! Mike Richards, CPA         The Callahan Credit Union A...

Health Coverage Tailored for You! Allstate Health Solutions

Health Coverage Tailored for You!  Allstate Health Solutions At the National Council of Firefighter Credit Unions ( NCOFCU), we can help credit unions and their members find health coverage that supports their lifestyle and budget . Through our partnership with Allstate Health Solutions , you get access to flexible health plan options — including short-term medical, supplemental coverage, dental, and more — designed to fill gaps and bring peace of mind when life shifts or coverage matters most. Why choose Allstate Health Solutions?   https://ncofcu.allstatehealth.com/ Flexible health plan options — Explore short-term medical, supplemental accident, critical illness, and dental coverage that fits your needs and budget. Coverage made simple — Find and compare plans quickly with our easy online experience. Support for transitions — Ideal for periods between job-based coverage, changes in life circumstances, or when you want supplement...

Sunday Reading - Where Beatniks Come From

  Where Beatniks Come From       An introduction to the Beat Generation The Beat Generation   was an American literary movement that rose to prominence in the 1950s. A loosely affiliated collection of poets, novelists, playwrights, publishers, and other artists reacted to what they considered an anti-intellectual and homogeneous social order following World War II.   The writing of the Beat Generation used experimental forms, surreal imagery, and vernacular language, and emphasized the importance of " spontaneous prose " to mimic the improvisation of jazz. Although the Beats praised canonical poets like William Blake, Arthur Rimbaud, and Walt Whitman, much of their work sought to rebel against literary tradition.   The Beats' radical politics and nonconformity influenced several subsequent countercultural ...

7 Things to Do (And Avoid) with SMS/Text in Credit Union Marketing

By not using SMS text messaging for marketing, you are missing a channel with a 98% open rate and a rapid response rate. Consumers love the convenience and are open to receiving personalized and relevant texts from their bank and credit union. Naturally there are some caveats to be aware of. Here are seven pointers. Are you content to have your customers take 90 minutes to respond back to a communication you’ve sent, or would 90 seconds be better? That’s the difference in average response times between email and SMS text. Then there is the open rate: SMS texts have high open rates — up to 98%, according to Gartner and 82% by another source. The average open rate of email is around 20%. If you send an email with a link to a survey to find out what a consumer thinks about the virtual meeting with a lending officer they just had, it may linger in the consumers’ inbox for days, at which point the experience is no longer top-of-mind or the consumer decides to simply delete the ...

Next Gen of Payments Could Leave ACH System Behind, Bank CEO Cautions

NEW YORK–The next generation of payments could leave the Automated Clearing House (ACH) system behind as stablecoins and tokenized deposits move into the banking core, according to one bank CEO. Custodia Bank CEO Caitlin Long said during a discussion with TheStreet Roundtable host Scott Melker that the “tokenized dollars are going to be big. Yes, there’s a distinction between tokenized bank deposits and stablecoins. Yes, right now, all the activity is in stablecoins, but we’re going to link the two in a safe and sound way.” During the discussion, Long cited Citi’s upgraded forecast for the sector, which now projects between $3 trillion and $4 trillion in stablecoins outstanding by 2030, according to Yahoo Finance, which noted Long believes even that range is far too conservative. “Those numbers are still too low,” she said. “I think they’re way too low.” According to Long, the innovation lies in embedding blockchain technology directly into the banking infrastructure rath...

NCUA Releases Q4 2017 Credit Union System Performance Data

ALEXANDRIA, Va. (March 5, 2018) – Data on the financial performance of federally insured credit unions in the quarter ending Dec. 31, 2017, are now available from the National Credit Union Administration. Q4 2017 Credit Union System Performance Data The number of federally insured credit unions declined to 5,573 in the fourth quarter of 2017 from 5,785 in the fourth quarter of 2016. In the fourth quarter of 2017, there were 3,499 federal credit unions and 2,074 federally insured, state-chartered credit unions. The year-over-year decline is consistent with long-running industry consolidation trends. NCUA makes detailed credit union system performance data available on its Credit Union and Call Report Data webpage, including Call Report quarterly summaries and financial performance reports . The agency’s Industry Data page includes a Financial Trends in Federally Insured Credit Unions package illustrating industry trends. The NCUA has made changes to the quarterly data report to...