Home > Security Tips > Compliance Counselor > User-friendly and secure passwords
Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

COMPLIANCE COUNSELOR

User-friendly and secure passwords


09.24.2001
Rating: -3.17- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


User-friendly and secure passwords
By searchSecurity Users

Some companies include guidelines in their security policy for creating user passwords. While these guidelines are developed with the intent to strengthen password security, they can make remembering passwords difficult. It doesn't do any good to have strict guidelines if users write their passwords on sticky notes to remember them.

But with a little creativity, companies can benefit from the protection of strong passwords that are also user-friendly. Users who have developed their own password generators submitted the tips below to searchSecurity. If you have a different method for creating secure passwords, submit it to searchSecurity.

Chuck Steffel suggests a new use for old phone numbers

I have worked on several systems logins that require 14 digit passwords and password rotation every 60 days. I do not always remember passwords, so I use a code with a numerical beginning and ending concatenated to a name.

I keep passwords in the cell phone telephone listing and in my written phone book. The nonsense listings are real people whom I would never call and dead relatives with valid area codes, etc. I have a listing of numbers (ready-made passwords) for when I get the password expiration message.

For example, decoding the telephone listing:
Charlie Peterson 651 319 1761
produces passwords such as:
319charlie1761 or 1761charlie319
319charlie1761 or 1761peterson319.

For systems that screen for real words,
1671eilrahc913 or 319eilrahc1671
1671osretep913 or 319osretep1671

The reordered phone numbers are easy to find in a cell phone or datebook. A simple PDA program can do the sorting.

Mark Farrar puts his mind to work with mnemonics

One of my interests is mnemonics (i.e. memory training techniques), and there is a relatively little known technique called the Figure Alphabet. This Figure Alphabet allows numbers to be converted into words, and its original purpose was to enable you to remember numbers by converting them into something more tangible and, consequently, easier to remember. You can find out more at http://freespace.virgin.net/mark.farrar1/mnefa01.htm, if you are interested.

However, the Figure Alphabet may also be used "backwards," i.e. words can be converted back into a number, and the system will always generate the same number for the same word.

My tip, therefore, is to use any password that is easy to remember for you (e.g. your wife's name) and convert it, using this Figure Alphabet, into a number.

As an example, my wife's name is Carol Farrar, which would convert into the number 745844, which is just as easy to remember but much harder to guess.

I know this sounds complicated, but the Figure Alphabet takes all of half an hour to learn -- at most! -- and it is a useful tool for daily life and work, as well.


SearchSecurity Bookstore

Information Security Policies and Procedures: A Practitioner's Reference

Rate this Tip
To rate tips, you must be a member of SearchSecurity.com.
Register now to start rating these tips. Log in if you are already a member.




Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Compliance Counselor
Compliance recycling: Combining compliance efforts to manage PCI DSS
Web 2.0 and e-discovery: Risks and countermeasures
Learn from NIST: Best practices in security program management
Best practices for application-level firewall selection and deployment
The 'security standards dilemma': Network segmentation and PCI Compliance
Penetration testing: Helping your compliance efforts
Worst practices: Recognizing the biggest compliance mistakes
E-discovery management: How IT should interact with the legal team
E-discovery management: How IT should interact with the legal team
Incident response success in five quick steps

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.

TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineWebcastsWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2003 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts