- Always opt in for MFA for accounts where it is offered, especially those that contain personal or financial sensitive information.
- When selecting an MFA option, we recommend using a smart-phone application (such as Microsoft Authenticator) as the most secure option. These applications will typically allow you to enter a code or use a “push notification”. Both are secure, but the push notification is the most convenient as it asks you to verity that you just attempted to log in.
Selecting the option 'yes' (or checkmark for some apps) and you are good to go. - If you use the text or call option instead, always remember to select a device or phone number that you will have access to when logging into your account.
Thursday, May 6, 2021
Multi-Factor Authentication - World Password Day
Wednesday, May 5, 2021
One Password, Slightly Used? - World Password Day
PASSWORD RE-USE:
Let’s say you have formulated the most perfect password that is possible to construct. It is easy to remember, a mile long, and has all
the available character types. Now you’re set to use it for all of your
accounts, right?
Not so fast. Even the most perfect password can be
vulnerable to sophisticated attacks against the company that runs the servers
that your account uses. In some recent high-profile cases, servers have been
attacked and user account information siphoned out. So even doing all the right things doesn’t
mean a determined hacker can’t figure out what the password is (through no
fault of your own).
Yikes! Now what? If this happens to you it could have
serious consequences that you could not have avoided. But what if that perfect
password that just got hacked is used for everything in your life? All of a sudden, the attacker has access to
EVERYTHING! Your social media accounts, your school accounts, even your bank
account!
That is why we recommend you never “re-use” a password. If you have a separate password for each account, it won’t prevent a determined hacker from getting into one account, but it will prevent that same attacker from getting into everything.
But that’s a lot of passwords, right. “How am I going to remember all of those?!”
1. As we covered in or last Daily Download, make your long passphrases something memorable. You can use that as a basis for a series of passphrases (a theme) and use significant variations on that theme (Remember, if they are too similar then it won’t be any better than using the same one for everything).
2. Alternately, you can use a password manager. These are applications that can manage multiple account passwords for you. All you, then, have to remember is the one password for that application and it will do the rest. A Google search on “password manager” will give you a number of applications to choose from, each with their strengths, weaknesses, and prices (some are free). If you have questions, ask IT Security – we’ll be glad to help you decide on a suitable solution.
3. Finally, avoid the temptation to allow your web-browser to remember your passwords. These are less secure than a password manager. Hackers may be able to “harvest” those passwords if you ever get malware on your computer (which is a whole topic for another time). Besides being less secure, they only work when you are using that browser to access your accounts and they may forget all your passwords in certain circumstances.
Tuesday, May 4, 2021
Strength in Numbers (or Characters?!) - World Password Day
PASSWORD STRENGTH:
We all know the drill: enter a username and password to access your accounts. But are you aware
that, in many cases, your password is the only thing standing between your
important on-line accounts and a malicious actor trying to get in and steal
your information, your identity, and your money? That is why having an effective password is
so important.
So, what constitutes an “effective” password?
Well, a password is “effective” if it keeps bad actors out.
But to do that, you need to know what you are up against. These bad actors have at their disposal many
tools that try to defeat your password. One is a list of maybe the 10 million
or so most common or previously hacked passwords, including popular variations
of some of the more common. Adding a zero in place of the “o” in “password”
will not be any more secure. They also use “dictionary” attack tools that look
for actual words or variations of words (like the zero vs “o” above). Finally, if those fail, they use tools to
rapidly guess passwords one character at a time. So just using any a random collection
of characters, if too short, will still allow the hacker to guess the password
in a reasonable amount of time.
1. Make it long – 14 or more characters. This dramatically
slows down the character-at-a-time guessing technique.
2.
Use a “pass-phrase” instead of a
“password”. String words and characters
together in a way that is meaningful to you (and therefore easier to remember)
but impossible to guess (hint: don’t use information about yourself that may be
available on the internet).
3.
Include as many types of characters as you can.
For examples, use lower and uppercase alphabetic characters, numbers, and
special characters as allowed by the application or account. Some include
minimum requirements to include, for example, 3 of the 4 types mentioned here.
Finally, if you discover that a password you currently use
is on the weak side, change it!
Most sites and accounts will let you change your password whenever you
like.
If you want to test your password to see if it has been used
in a data breach, try haveibeenpwned.com.
Their database consists of over 600,000,000 passwords that have been obtained
from data breaches. To test your
password strength to see how long it would take a hacker to guess it, go on
over to security.org.
Monday, May 3, 2021
Designing the Perfect Password - World Password Day
Are YOU still using that same password you created way back in day?
Pets Name? Kids’ names? Birthdates? Anniversaries? The word 'password'?
Today those tactics no longer work. With data breaches at an
all time high, we need to protect ourselves more than ever! Just a few small
things can drastically help protect all your important online accounts. Here is
a few you can try!
Create Robust Passwords: Make it
difficult for Hackers to guess. Make your passwords contain at least 10
characters, have BOTH a capital and lower-case letter, and one or more
symbols/numbers. (i.e., !@#$%^&*() 123456789). Use a “pass-phrase” instead
of a password to make it longer and more memorable to you but even harder to
guess.
Use Different Passwords: Make sure to use a different
password for every account you have. If you use the same password for your
personal e-mail, work e-mail, Facebook, Twitter, bank account, etc., and just
one of those sites were to be compromised, the attacker would then have the “Golden
Key” to all of your accounts. Do not make it that easy for them!
Always
opt for Two-Factor Authentication (2FA) or Multi-Factor Authentication (MFA): It is very important to make our data as
secure as we can. Having a second layer
of security in place to protect us is never a bad thing! That way, even if your
password is obtained by a bad actor, they still won’t have access to those
accounts protected by a 2nd factor.
Most companies now offer MFA or 2FA when you sign up for their services.
When available always OPT IN! If you already have an account that is not
protected by these, check back every so often. More and more companies are enabling
these features.
Change your password every few weeks: The reason for
changing your password on a regular basis is to protect you and your data from
ongoing password attacks. With today’s hacking tools, guessing a simple
password (a name, word, or common pattern) trivially easy. But even a good
password can be guessed eventually, but it does take time. Also, when hackers compromise an account,
they may not always act right then and there, some continue to silently watch
for as long as the password remains the same. When you change your password
regularly it does not allow the hackers much time to act.
Do NOT Tell Anyone Your Password: Your Passwords are Personal and
Non-transferable. Do not give anyone the “Golden Key” to your
information. Protect it like you would a safety deposit key!
May 6 is World Password day. We will post information and
helpful tips all week, so watch for more information!


