Home > Security Tips > Compliance Counselor > Passwords: Complexity equals easy to forget
Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

COMPLIANCE COUNSELOR

Passwords: Complexity equals easy to forget


James Michael Stewart
03.26.2002
Rating: -3.76- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   




One of the key components of a good security policy is the enforcement of strong passwords. In many cases, a strong password requires the following:

Seeing these restrictions often leads one to think that users must select a password that is so complex that they often can't remember it, Such as oA16I8aCCp.

But in fact, "oA16I8aCCp" is an easy to remember password if you know one simple fact:

As humans, we can remember activities, events, people and occurrences. We especially remember things that happen to us or near us that are either exciting, dangerous or at least out of the ordinary (subjective to each individual).

Using this fact, I suggest to users to think of an event that they can easily remember. When they think of that event, try to think of a simple sentence to describe that event. In most cases, the sentence will be the one you generally use to communicate the event to someone else. Such as "Hey Bob, I just saw the weirdest thing during lunch," or "Amanda, I just went hang gliding in the Virgin Islands!" Now, add a date to the sentence: "On July 5, I saw a weird thing during lunch."

Next, take the first letter of every word, and keep any numbers: OJ5Isawtdl

You can elect to drop common words such as "a," "in," or "the." You can also choose to alternate capitalization. When possible, change out a letter (or entire words) for numbers which are similar, such as three for e/E or one for i/I/l/L or even eight for "ate." You could even throw in a number sign "#" before the mention of any numbers from your initial sentence.

In my first example, oA16I8aCCp is created from the sentence



"on April 16, I ate a Chucky Cheese pizza".

With this simple method, you can train your users to create very complex passwords that meet all complexity requirements without forcing them to extreme measures to remember a random password or cause them to write it down.

If users still have problems remembering their passwords using this method because they forget their initial sentence, you can suggest that they write down a short phrase that reminds them of the sentence, as long as that phrase does not contain any significant word from the initial sentence. Ideas might include "bright-green eye shadow is strange," "I crashed into an ice-cream cart," or "I love pepperoni and extra cheese."

One final idea on complex passwords. If you have a two or three digit number (less than 255) which is either easy to remember or becomes evident during the sentence to password conversion process, you can use it as a high-order ASCII character instead of just plain old keyboard numerical digits. Just press and hold the ALT key while entering your numerals. If you only have two numerals, enter a zero ("0") first. This will place a high-order ASCII character into your password. It still counts as only a single character even though you will press four digits to create it. The best part about ALT-generated characters in a password is that most brute-force password-cracking tools do not use these characters in a standard attempt to extract passwords. Instead, they usually default to (or are programmatically limited to) the keyboard-based characters.

About the author
James Michael Stewart is a researcher and writer for Lanwrights, Inc.


Rate this Tip
To rate tips, you must be a member of SearchSecurity.com.
Register now to start rating these tips. Log in if you are already a member.




BROWSE BY TAG
Security Management,   Password Management and Policy,   Identity Management Technology and Strategy,   Enterprise Identity and Access Management,   Compliance Counselor,   VIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Security Management
Smart shopper's guide to correlation tools
What's your infosec IQ?
Countdown begins for Mydoom DDoS attacks
Hackers scanning for ports opened by Mydoom
National cybersecurity alert system launched
Dangerous, familiar application vulnerabilities top list
Potent Mydoom worm flooding inboxes
SSL VPNs stealing IPSec's thunder
Expert sheds light on Wi-Fi liability issues
Security insurance may be a smart policy for some

Password Management and Policy
Privileged account management critical to data security
Making the case for enterprise IAM centralized access control
How to prevent brute force webmail attacks
Best practices for a privileged access policy to secure user accounts
Mature SIMs do more than log aggregation and correlation
PCI compliance requirement 2: Defaults
PCI compliance requirement 8: Unique IDs
Enterprise password management policy: Finding the balance
Ease the compliance burden with automation
Security book chapter: The Truth About Identity Theft

Compliance Counselor
Common PCI questions: Web application firewalls or source code review?
PCI management: The case for Web application firewalls
The basics of enterprise GRC project management
PCI DSS: The structure of a standard
How to choose between source code reviews or Web application firewalls
HIPAA compliance: New regulations change the game
Data security best practices for PCI DSS compliance
Key elements of a HIPAA compliance checklist
A preview of PCI virtualization specifications
Strategies for email archiving and meeting compliance regulations

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
graphical password  (SearchSecurity.com)
identity chaos  (SearchSecurity.com)
logon  (SearchSecurity.com)
masquerade  (SearchSecurity.com)
OpenID  (WhatIs.com)
salt  (SearchSecurity.com)
session replay  (SearchSecurity.com)
single-factor authentication (SFA)  (SearchSecurity.com)
TACACS  (SearchSecurity.com)
war dialer  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Research Solutions for Network Security, Access Control and Security Threats
More Security Resources for Resellers, VARs and OEMs
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts