Password security: How to choose an unbreakable password

April 15, 2022 by
Password security: How to choose an unbreakable password
ST DIGITAL CAMEROUN, Jean-Philippe LAGUNA

The password is still considered by many to be the last line of defense for most of us. Whether in a business or personal context, we must therefore take great care in choosing it, and today more than ever given the risks that weigh on the password. 

Cybercriminals use password attacks to gain control of our information. This is facilitated by the fact that we very often choose weak passwords that cannot withstand brute force attacks or dictionary attacks for long. The strength of a password generally depends on its complexity. 

To help choose truly secure passwords, here are a few simple rules: 

  • If you want a simple rule: Choose passwords of at least 12 characters using different types (uppercase, lowercase, numbers and special characters) 

There are two methods for choosing your passwords: 

  • The phonetic method: "I bought eight CDs for one hundred Francs this afternoon" would become ght8CD%F7am; 

  • The first-letter method: the quote "better one bird in the hand than two in the bush" would give 1boh2ib. 

Beyond choosing unbreakable passwords, here are some best practices for password usage: 

  • Use a unique password for each service. In particular, using the same password for your professional email and personal email is absolutely to be avoided; 

  • Choose a password that has no connection to you (a password made up of a company name, a date of birth, etc.); 

  • Never ask a third party to generate a password for you; 

  • Systematically and as early as possible change default passwords when systems contain them; 

  • Renew your passwords at a reasonable frequency. Every 90 days is a good compromise for systems containing sensitive data; 

  • Do not store passwords in a file on a computer that is particularly exposed to risk (for example: online on the Internet), and even less so on an easily accessible piece of paper; 

  • Do not send your own passwords to your personal email; 

  • Configure software, including your web browser, so that it does not "remember" chosen passwords. 

The password remains the last line of defense for securing our systems, and therefore must be given the utmost care. 


Archive