• CERTIFICATE
    • Eminent VARs of India
    • Best OEM 2023
  • SYNDICATION
    • AMD
    • DELL TECHNOLOGIES
    • HITACHI
    • LOGMEIN
    • MICROSOFT
    • RIVERBED
    • STORAGECRAFT
    • THALES
  • EVENTS
  • GO DIGITAL
  • INFOGRAPHICS
  • PRESS
    • Press Release PR News Wire
    • Press Release Business Wire
    • GlobeNewsWire
  • SPECIAL
    • WHITE PAPER
    • TECHNOMANIA
    • SME
    • SMART CITY
    • SERVICES
    • EDITOR SPEAK
    • CSR INITIATIVES
    • CHANNEL GURU
    • CHANNEL CHIEF
    • CASE STUDY
  • TECHTREND
    • VAR PANCHAYAT
    • TELECOM
    • SOFTWARE
    • POWER
    • PERIPHERALS
    • NETWORKING
    • LTE
    • CHANNEL BUZZ
    • ASK AN EXPERT
  • SUBSCRIBE
  • Apps
  • Gaming
  • KDS
  • Security
  • Telecom
  • WFH
  • Subscriber to Newsletter
  • April Issue
  • Blogs
  • Vlogs
  • Faceoff AI
    

HOME
NEWS

Make Life And Security Easier: Use A Password Manager


By VARINDIA - 2021-01-12
Make Life And Security Easier: Use A Password Manager

Yesterday morning, I got an email message from the brilliant site created by security expert Troy Hunt, HaveIbeenpwnd, informing me of a problem with a service I haven’t used in a long time, 123RF, a clipart and illustrations library: the site suffered an intrusion that managed to take over the email addresses, user names, IP addresses, names, passwords (in principle encrypted), telephone numbers and physical addresses of more than 8.5 million users.

 

First point: this can happen to anyone. It is not even evidence that this site, 123RF, had bad security practices: practically any site is vulnerable if someone invests the necessary resources and time. This happens all the time, and the thing to do is simply to be prepared for when it happens.

 

The problem with this type of intrusions is that, generally, the stolen information ends up on several easily accessible sites in the dark web, allowing anyone to download the file and then try to access accounts on other sites belonging to the many reckless people who still recycle the same password for different services or who use easy to guess rules to generate them.

 

 

A problem? Not for me. The password I was using at 123RF was generated by my password manager, LastPass, which I never knew (or wanted to), and of course, it wasn’t used anywhere else. In the event I might want to use 123RF again, I went onto the site, changed my password, and put in another, equally impossible to remember: 25 characters with numbers, letters and symbols, that would take a computer something like a hundred octillion years to figure out :-) criminals trying to try to use the previous password elsewhere would fail. As long as quantum computers are not in common use, I can sleep at night. If only I could solve all my problems so easily.

 

What do you know about your passwords? The first thing should be that all those absurd rules about replacing an “E” with a “3”, an “A” with a “4”, etc. don’t work. Today’s cybercrooks are much smarter. If you are going to start creating your own passwords, which I don’t advise, at least take a look at the recent research of this group of Carnegie Mellon scientists. If you want to know how long it would take a criminal to figure out your password, check out this chart, or enter it on this page, which claims not to save it or share it with anyone.

 

 

The second thing you should do is enter the email addresses you usually use on HaveIbeenpwned, which will tell you how many data dumps it’s on, and then not only change the passwords of these sites if they were services you used regularly, but also, think about whether you have recycled these passwords for other services (and if so, change them too). I’ve been using HaveIbeenpwned for a while now: I’m even using the feature that allows you to enter your email and get a warning when new security violations are made public, and I haven’t gotten any spam as a result. The latest versions of some browsers also warn when you enter a password on a site if that password has already been exposed or when you try to use the same password on several sites, and invite you to change it. If so, listen to them.

 

If you run an organization and are still following the classic rules for periodically changing passwords, stop now: all you are doing in terms of security is confusing your workforce, who will probably resort to writing their password down on a post-it stuck to their computer screen. You are not going to improve your company’s cybersecurity with these practices. 

 

If you’re going to take your internet security seriously, then sign up for a password manager. There are many articles out there on which are the best to use, some of them are free. This way, even if the security of your password manager was breached, the criminals would only take away a useless list of encrypted passwords. From then on, you will only have to remember one password, so just make sure you choose that one well. I would also recommend choosing a password manager with a version for smartphone, and that you spend around an hour when you have installed it browsing all the services you use regularly and not so regularly to register them, as well as changing all the passwords you have for other new ones generated by the manager, which can be very long and impossible to remember or guess.

 

If you don’t want to use a separate password manager, you can use the one offered by most browsers. It’s not the best option, nor the most comfortable if you use several browsers, nor the safest, but it’s definitely better than using nothing or your cat’s name.

 

In any case, use the tools I have provided links for to at least diagnose your security level. We spend a lot of time online and shouldn’t allow criminals to test our security. Doing things right costs very little. Think about it.

 

Oh, and one final piece of advice: Even if, as is probably the case with most of the internet-savvy people reading this on Forbes, you think your security practices are good enough, think about your friends and family. It is often older people who still use extremely weak passwords or just one password for everything. Better safe than sorry.

See What’s Next in Tech With the Fast Forward Newsletter

SECURITY
View All
Zscaler announces AI innovations to its Data Protection Platform
Technology

Zscaler announces AI innovations to its Data Protection Platform

by VARINDIA 2024-05-20
SHIELD to enhance Swiggy’s fraud prevention and detection capabilities
Technology

SHIELD to enhance Swiggy’s fraud prevention and detection capabilities

by VARINDIA 2024-05-20
Axis Communications announces its first thermometric camera designed for Zone/Division 2
Technology

Axis Communications announces its first thermometric camera designed for Zone/Division 2

by VARINDIA 2024-05-20
SOFTWARE
View All
Hitachi Vantara and Veeam announce Global Strategic Alliance
Technology

Hitachi Vantara and Veeam announce Global Strategic Alliance

by VARINDIA 2024-05-16
Adobe launches Acrobat AI Assistant for the Enterprise
Technology

Adobe launches Acrobat AI Assistant for the Enterprise

by VARINDIA 2024-05-11
Oracle Database 23ai offers the power of AI to Enterprise Data and Applications
Technology

Oracle Database 23ai offers the power of AI to Enterprise Data and Applications

by VARINDIA 2024-05-10
START - UP
View All
Data Subject Access Request is an integrated module within ID-REDACT®
Technology

Data Subject Access Request is an integrated module within ID-REDACT®

by VARINDIA 2024-04-30
SiMa.ai Secures $70M Funds from Maverick Capital
Technology

SiMa.ai Secures $70M Funds from Maverick Capital

by VARINDIA 2024-04-05
Sarvam AI collaborates with Microsoft to bring its Indic voice LLM to Azure
Technology

Sarvam AI collaborates with Microsoft to bring its Indic voice LLM to Azure

by VARINDIA 2024-02-08

Tweets From @varindiamag

Nothing to see here - yet

When they Tweet, their Tweets will show up here.

CIO - SPEAK
Automation has the potential to greatly improve efficiency and production

Automation has the potential to greatly improve efficiency and production

by VARINDIA
Various approaches are followed to enhance efficiency, productivity, and cost-effectiveness

Various approaches are followed to enhance efficiency, productivity, and cost-effectiveness

by VARINDIA
Technology can be leveraged in several ways to boost efficiency, productivity and reduce cost

Technology can be leveraged in several ways to boost efficiency, productivity and reduce cost

by VARINDIA
Start-Up and Unicorn Ecosystem
GoDaddy harnesses AI power for new domain name recommendations

GoDaddy harnesses AI power for new domain name recommendations

by VARINDIA
UAE’s du Telecom selects STL as a strategic fibre partner

UAE’s du Telecom selects STL as a strategic fibre partner

by VARINDIA
JLR and Dassault Systèmes extend partnership for All Vehicle Programs worldwide

JLR and Dassault Systèmes extend partnership for All Vehicle Programs worldwide

by VARINDIA
Rapyder partners with AWS to accelerate Generative AI led innovation

Rapyder partners with AWS to accelerate Generative AI led innovation

by VARINDIA
ManageEngine integrates its SIEM solution with Constella Intelligence

ManageEngine integrates its SIEM solution with Constella Intelligence

by VARINDIA
Elastic replaces traditional SIEM game with AI-driven security analytics

Elastic replaces traditional SIEM game with AI-driven security analytics

by VARINDIA
Infosys and ServiceNow to transform customer experiences with generative AI-powered solutions

Infosys and ServiceNow to transform customer experiences with generative AI-powered solutions

by VARINDIA
Crayon Software Experts India inaugurates its ISV Incubation Center in Kolkata

Crayon Software Experts India inaugurates its ISV Incubation Center in Kolkata

by VARINDIA
Dassault Systèmes to accelerate EV charging infrastructure development in India

Dassault Systèmes to accelerate EV charging infrastructure development in India

by VARINDIA
Tech Mahindra and Atento to deliver GenAI powered business transformation services

Tech Mahindra and Atento to deliver GenAI powered business transformation services

by VARINDIA
×

Reproduction in whole or in part in any form or medium without express written permission of Kalinga Digital Media Pvt. Ltd. is prohibited.

  • Distributors & VADs
  • Industry Associations
  • Telco's in India
  • Indian Global Leaders
  • Edit Calendar
  • About Us
  • Advertise Us
  • Contact Us
  • Disclaimer
  • Privacy Statement
  • Sitemap

Copyright varindia.com @1999-2024 - All rights reserved.