1 Ten tips for managing passwords - Security - Insight - ZDNet Australia

Ten tips for managing passwords

Passwords are fatally flawed, it's true, but for now they are the best option for many companies. But almost everybody could be managing them more effectively.

In all likelihood passwords will remain a problem until the very day they are replaced by technologies such as biometrics, which is the direction the industry appears to be heading. However, until that day comes, below are some tips for fostering a culture of secure and more effective password management.

1. Passwords must not be written down
If it seems incredible that we are still talking about password management at all, then it is unimaginable that we have to make this first point.

If staff are writing down their passwords, having been told why they must not do so, then the system is too complex and too much is being asked of them. Companies must strike a balance between security and usability because a failure to understand the latter can easily undermine the former.

So consider whether employees have been properly educated about the need to keep passwords secure and then consult the measures below if you need to update your password policy.

2. Passwords must be set
And you thought the first tip seemed obvious? It's staggering to hear instances where systems have been compromised because the password was still set as a default 'password' or 'changeme' or similar.

3. Require as few passwords as possible
Balance how much password protection you need with how many passwords can reasonably be managed. Identify which networks, systems and applications have the highest priority. If staff have to remember 10 passwords -- from ones guarding highly sensitive data to ones that really serve little or no purpose - they may be unable to manage all of them.

What's to say the one they write down and lose isn't the most sensitive?

4. Staff must change their passwords regularly
This limits the likelihood of old passwords, shared between colleagues in less-secure times, coming back to haunt you. It also limits the window of opportunity if passwords subsequently fall into the wrong hands.

How often they are changed must again be a balance between security and usability. If staff are required to come up with a new password every week, they will likely become confused and start writing them down. In fact longer periods between changes -- 90 days rather than 30 days for example -- can actually prove beneficial as knowing a password will have a longer lifespan makes a more complex password far more manageable and may encourage staff to give it more careful consideration.

5. Make new passwords new
When passwords are changed users must not distinguish them from a previous password by just one character. RandomW0RD1, RandomW0RD2, RandomW0RD3 becomes a pattern that is pretty easy to figure out.

6. Avoid obvious words
Passwords must be more complex than a single word which can be hacked with a dictionary attack (using software to automatically enter all the words in the dictionary as well as proper nouns). Names, addresses and other words which are easily linked back to the individual should also be blocked from use. It's alarming how many instances there are of staff using their name, their partner's name or their pet's name.

7. Think long -- but not too long
A password which consists of at least eight characters with a mix of upper case, lower case and numbers is a good start. If the minimum requirement is too long staff may be encouraged to be lazy and use repeat characters or obvious strings: ABCDEFG123456789.

However, a minimum with a reasonably high upper limit would allow staff to be creative. One suggestion is to use phrases rather than words. Certainly 'mYd0g1sCALLEDf1d0' is less likely to be guessed that 'Fido'. Again, it's a step in the right direction towards creating more secure passwords.

8. Automate password changes
The process of making staff reset and choose secure passwords must also be automated. Do not rely on staff to remember how long it has been since they last reset it, what passwords they have used in the past year or what types of words are off-policy. It's not a question of trust. It's a question of history showing us that policies are never adhered to by choice.

9. Educate staff
Ensure password policy is written into employment contracts and that all staff understand why and what that entails. Hopefully, if all other measures work, the most serious human piece of the jigsaw will be the requirement for staff not to share their password and not to write it down. Such wording should also prohibit repetition of passwords between services -- particularly between those outside and inside the enterprise. A corporate login is likely to be more sensitive than a newspaper subscription login which may be shared with friends and family.

10. Look to the future
Finally, look at long-term solutions which will eventually replace passwords -- such as biometrics and two-factor authentication. Passwords are flawed and the above tips are recommendations for how they can be more secure -- for now.

Talkback

Add your opinion

In order to post a comment, you need to be registered. (Sign In or register below)

Post your comment

Terms of Service - As a ZDNet registrant, and by using this service, you indicate that you agree to our Terms and Conditions and have read and understand our Privacy Policy.

Quick Poll

What is the biggest data management challenge in your organisation?

ZDNet Australia Live

Kayak boosts its hotels database through TripAdvisor partnership http://t.co/nDE2jWyu

Making security sexy http://t.co/3txpPZuW via @zdnetaustralia < Practice what you preach; the blog is as tedious as a crypto seminar ;-)

More untruths about #cloud RT “@andrew_sf: Multi-tenant cloud computing fear mongering, sponsored by SAP. http://t.co/sMdy94m9

Microsoft brand Google as malware. How low can they go?
http://t.co/WIrPX9qJ

RT @andrew_sf: Some bona fide #cloud scaremongering from SAP, inc paranoia about 'foreign govt agents'. A hoot. #in http://t.co/Hv9VtX1O

App permissions: We are our worst enemy http://t.co/tZjQIr36

Apple's 'Mountain Lion': Another step toward iOS, Mac feature unification http://t.co/e1Vca8jS

Adobe Flash Player XSS flaw under 'active attack' http://t.co/5BjMLzXx

3D printer produces new titanium jaw http://t.co/OYcmEOsu

Sad state of affairs for Iran. http://t.co/y6VBcU7v

Avi Rubin's TED talk: All Your Devices Can Be Hacked http://t.co/QyXE1EUL (via @zdnet)

Groupon CEO: 'We've cracked the code': In a still-crowded daily deals market, Groupon CEO Andrew Mason argues th... http://t.co/KXa3ZRxB

Groupon CEO: 'We've cracked the code': In a still-crowded daily deals market, Groupon CEO Andrew Mason argues th... http://t.co/f52UrqUC

RT @marciahofmann: Avi Rubin's TED talk: All Your Devices Can Be Hacked http://t.co/QyXE1EUL (via @zdnet)

RT @OracleRetail: eBay wants to partner with large retailers, not compete with them (via ZDNet) http://t.co/z1RWedMl #retail ^TE

Cheap Android smartphones will dominate developing markets: report - ZDNet http://t.co/opRUID33

Chinese authorities reviewing Google, Motorola merger - ZDNet (blog) #Google #News...
http://t.co/JpICbmSj

From poking to pinning: Facebook CEO Mark Zuckerberg joins Pinterest - http://t.co/ut8aDiat

SanDisk bringt SSD-Reihe mit bis zu 550 MByte/s Leserate - http://t.co/hqaLKlvT #technews #seo @activetraffic

Groupon CEO: 'We've cracked the code' http://t.co/19P8HoLC

Apple wins injunction against Motorola slide-to-unlock phones http://t.co/DgKpx2NV #Linux #Android

RT @activetraffic: SanDisk bringt SSD-Reihe mit bis zu 550 MByte/s Leserate - http://t.co/hqaLKlvT #technews #seo @activetraffic

Facebook CEO Mark Zuckerberg joins Pinterest - http://t.co/eYpdvRju

RT @ZDNet: Apple's OS X 10.8 Mountain Lion features Twitter, no Facebook http://t.co/VKphifZ8

http://t.co/IhdGn0Uc Twitter uploads contact list data without consent; retains for 18 months

ZDNet: Facebook Mobile Hack events coming to Europe next month: Facebook is hosting three Mobile Hack events in ... http://t.co/4bj3GxJJ

RT @ZDNet: Apple pushes 'Gatekeeper' to protect Mac OS X from malware attacks http://t.co/8rZvKCDY

Apple PR’s dirty little secret http://t.co/baNw9e6i via @zite

RT @jdg: Our friends @twittelator had a great review over at ZDNet :

http://t.co/54TlLyQ2

(And a Boxcar mention or two! ;)

Facebook Mobile Hack events coming to Europe next month http://t.co/MBAcA067 #facebook

Appearing on Wall St. Journal "Daily Wrap" radio today re: online privacy. My post "Three principles of #cloud trust" http://t.co/LXXV7jwW

FAST ‘12 conference paper quantifies flash’s declining reliability, endurance, and performance as density increases.
http://t.co/ok6Ausr2

Facebook to launch verified accounts, pseudonyms http://t.co/6quEhVj8

Latest Apple rumor: Mac Pro desktop to be updated with Ivy Bridge-E processors ... http://t.co/TDaI85tt

@tomflack really wanna ser amaxon release official figures http://t.co/kGEazMOH - iSuppli: Kindle Fire jumps from zero to 14 percent

In addition to business cards, how do you advertise your online business(s)? I sell on ebay, etsy u0026 my web site. Every ...

9 hours ago by Offeftbib on Broadband Speedtest

Highlights the problem that such lockin only seem to be considered when reaching a 'monopoly situation, which of course any business migh...

11 hours ago by Patanjali on Cisco asks EU to rethink Microsoft-Skype

Oh, and many have found that the 64GB microSD cards work in the Note, as they seem to do in most late model phones, except you-know-whose.

11 hours ago by Patanjali on Samsung Galaxy Note

I have a EU Note, and am using it on Telstra without problem on HSDPA+ (speed same as their Elite wireless modem). I bought it for the u...

11 hours ago by Patanjali on Samsung Galaxy Note

Political banter aside (how the government made it's way into here, I'll never know (gotta keep an eye on those slippery **** I hope that...

12 hours ago by techkid on Decision time for SKA bid

Good on him. If you really want to motivate a bureaucrat into action, put them in the public spotlight (either doing something they shoul...

12 hours ago by techkid on Filters kill innovation: ex-US CIO Kundra

Thanks for sharing the information but it depends on person to person...and every person will have a different point of view..

13 hours ago by samanthalewis on Online video: An online video

Yes what ever happened to what's-his-name who said "before roads there were no roads" (sadly one of his more sensible comments...). You k...

15 hours ago by Beta on Decision time for SKA bid

Lo and behold I agree Doubt, nicely surmised.

16 hours ago by Beta on Telstra, NBN showdown over Tassie devices

He could totally submit like your hero Mal and gift Telstra the entire network... again!

16 hours ago by Beta on Telstra, NBN showdown over Tassie devices

"Did you like the 50's Abbott analogy about the dishes, apt eh?" That post war era time warp bubble is real cosy for them, don't burst i...

16 hours ago by Hubert Cumberdale on Decision time for SKA bid

Its not an NBN with the speed stuck at 100megs, Telstra already delivers that speed on its cable3.0 mainland network. Why should Telstra ...

16 hours ago by kirwan on Telstra, NBN showdown over Tassie devices

Ye Vdai... I was of course, simply doing this to save those like Doubt here, who actually believe such BS in relation to the NBN, the tr...

17 hours ago by Beta on Decision time for SKA bid

"Well Hubert, I hear North Korea is looking for people like yourself!" Sorry but that makes absolutely no sense. Perhaps the Luddites th...

18 hours ago by Hubert Cumberdale on Decision time for SKA bid

Well Hubert, I hear North Korea is looking for people like yourself!

19 hours ago by Doubt on Decision time for SKA bid

Yes Beta, sometimes you forget yourself. Let's keep to reasoned debate please.

19 hours ago by Doubt on Decision time for SKA bid

NBN co has 4000 users in Tas? I suspect Telstra do not see much money to be made, so put in a few delaying tactics and leave the rest to ...

19 hours ago by Doubt on Telstra, NBN showdown over Tassie devices

I do hope you are trolling, Beta, because your statements are beyond laughable. "After all who needs something 10000 times faster? What ...

19 hours ago by Vdai on Decision time for SKA bid

Sadly one of the reasons the Minister has given for foisting this NBN Co on us is to provide elverage over Telstra and get thme to behave...

19 hours ago by Rossyduck on Telstra, NBN showdown over Tassie devices

Too right Hubert. White elephant... After all who needs something 10000 times faster? What we have now is good enough, we will not ne...

19 hours ago by Beta on Decision time for SKA bid

Facebook Activity

Keep up with ZDNet Australia

ZDNet Events Calendar

ZDNet Events Calendar