Special offer

Creating Passwords that are Bulletproof

Reblogger Lynn B. Friedman CRS Atlanta, GA 404-617-6375
Real Estate Broker/Owner with Atlanta Homes ODAT Realty - Love our Great City - Love our Clients! Buckhead - Midtown - Westside

Dear Readers,

At a Tuesday ZOOM Meet-up AR Member, Robert Siciliano, from the Boston, MA area, CEO of IDTheftSecurity.com added to our knowledge base.

Robert says that he is "fiercely committed to informing, educating, and empowering Americans so they can be protected from violence and crime in the physical and virtual worlds."

In all his presentations and all the classes he teaches, his goal is simple – "to wake up and empower people across Main Street USA so they can avoid becoming victims of crime."

EDIT: Decided to mention I use LastPass - really simple to use and available across all devices - office, home and mobile. They offer a "free" version as well if one wants to try it. Just REMEMBER your Master Password - they don't keep a copy of it! 

After you enjoy this post, you may want to read the following other posts:

Photos Show Locations!   Erase Data the Secure Way  Contactless Credit Cards

Freeze Your Credit Before It Is Too Late    Legalities of Monitoring a Cell Phone

 

Enjoy yourself, enjoy your success - be Security Conscious!

Original content by Robert Siciliano

It can be a real hassle to keep track of the passwords you use. So many people use the same combination of username and password for every account. However, this isn’t a good idea. In fact, it’s terrible. You see, these days, many data breaches could be traced back to people using the same password across multiple accounts. And once the bad guy finds his way in, especially logging into your email, it is game over. From there, it’s easy to reset the pass code for almost all of your accounts when the bad guy controls your email too.

All it takes is a cracker to find this password, and now every account you have is compromised. And finding that password is even easier. Some studies show as many as 40 billion records were compromised in 2021. Many of those records are passwords. At ProtectNowLLC.com, we have a tool that has access to over 12 billion compromised records where you can search your username aka your email address to find out if your username and associated password have been compromised on a variety of breached accounts.

Thankfully, there is an easy solution: use a password manager. I’ve had a password manager in place since 2004. At this point I probably have close to 700 different online accounts. And I might know the password for maybe five of them. The rest, only my password manager knows the password which I can easily look up. But I’ve never committed them to memory. Most people say “what if the password manager gets hacked” while this might be a valid concern, it’s not a concern of mine.

The low hanging fruit isn’t a password manager getting hacked, it’s people reusing the same passcode across multiple accounts and those credentials being available on the dark web. But, if you don’t want to use a password manager because you’re afraid the password manager is going to get hacked, you can also do the following:

Creating a Unique Password

Research shows that the best passwords are 14 characters long. Those that are shorter than that are easier to figure out. If a site doesn’t let you create a password that is 14 characters, it is possible to adapt it. Password managers do a very good job of creating/generating long strong unique complicated passcodes.

First, make a list of all of the sites you have a username and password for, and then put those sites into categories. For example, all of your sites for social media would be in a category, all of your email sites together, all of your banking sites together, and all of your shopping sites together.

Then you want to create a password that is eight characters. This will serve as the first part of any other password that you create. For example, the first eight

characters might look like this:

CM&@t*yZ

Next, remember your categories? You will create a three-character password that is significant to those. For instance:

  • Social media sites – SM#
  • Email sites - &eM
  • Shopping sites - $h0
  • Banking sites – 8aN

So, this gives you 11 characters of the recommended 14-character password that you want to use. Now, you need three more characters, and that would be specific to the site.  So, let’s say you are creating a password for your bank. This is made up like the following:

Eight-character + three-character password (category) + three-character (site)

So, for your bank, it would look like this:

CM&@t*yZ8aNp$X

This is a very difficult password to guess, and for many people, easier to remember. But it’s not easy for everyone to remember. There is a solution, but first, keep this in mind. When you have to change your password, you can keep the final six characters and just change the first eight.

Now, how can you remember the first part of the password? One way to do this is to simply write it down and store it in a safe place. However, don’t keep it near your computer. Another thing you can do is to create a phrase that will help you remember.

Here’s an example. Let’s say our phrase is “My brother asked me for bread and salt.” If you take the first letter for all of the words, it would be this:

MBAMFBAS

This could be your eight-character first part…and you can make it more secure by making some swaps:

M3@MFBA$

This still makes the password very difficult for a hacker to guess but makes it easier for you to remember. You can use the same method, of course, for the smaller parts of the password.

Honestly, if you’ve got even this far in this article, congratulations to you. You must be some weird math savant with an elephants memory. Frankly, the above gives me a headache. Like I said in the first three paragraphs, it’s best to just use a password manager and forget all of this work, but if you don’t want to, this method works pretty well.

Written by Robert Siciliano, CEO of Credit Parent, Head of Training & Security Awareness Expert at Protect Now, #1 Best Selling Amazon author, Media Personality & Architect of CSI Protection Certification.

Laura Cerrano
Feng Shui Manhattan Long Island - Locust Valley, NY
Certified Feng Shui Expert, Speaker & Researcher

It’s tricky because I think a lot of us one to not have to deal with that many passwords in our heads. Excellent post

Feb 10, 2022 09:22 PM
Lynn B. Friedman CRS Atlanta, GA 404-617-6375

Laura Cerrano 
Yes. Robert does a wonderful job. Please see my reply to Endre below. You can try LastPass for free... Thanks for reading - Lynn

Feb 11, 2022 05:16 AM
Endre Barath, Jr.
Berkshire Hathaway HomeServices California Properties - Beverly Hills, CA
Realtor - Los Angeles Home Sales 310.486.1002

So where do you keep all these complicated passwords? Do you have a note book or you ask Mr Google to save it for you? and when Mr Google gets broken into your efforts went out the window...just sayin, Endre

Feb 10, 2022 10:06 PM
Lynn B. Friedman CRS Atlanta, GA 404-617-6375

Endre Barath, Jr. 
P E R F E C T question. Who would expect less from you???? Wouldn't want all my "efforts ... out the window, just sayin" Nothing saved on Google -  I use LastPass to store all the passwords plus 2-step. I only have to remember one password that opens LastPass. Then I go to the LastPass Authentication app on my cell phone which holds a 6-digit code that changes every time I use it. Two-step safety! Thanks for stopping by! Lynn  Laura Cerrano 

Feb 11, 2022 05:14 AM
Jeff Masich-Scottsdale AZ Associate Broker,MBA,GRI
HomeSmart Real Estate - Scottsdale, AZ
Arizona Homes and Land Group/ Buy or Sell

Creating and remembering long passwords is difficult but certainly safer. A password encrypted password manager is well worth it.

Feb 10, 2022 10:16 PM
Lynn B. Friedman CRS Atlanta, GA 404-617-6375

Jeff Masich-Scottsdale AZ Associate Broker,MBA,GRI 
EXACTLY!!!! You got it! I explained that in my reply to Endre Barath, Jr. at his comment. Glad you replied - Lynn

Feb 11, 2022 05:18 AM
Wayne Martin
Wayne M Martin - Chicago, IL
Real Estate Broker - Retired

Good morning Lynn. Missed another good Zoom meeting. Passwords are a big issue. I need to study this a bit more. Enjoy your day!

Feb 11, 2022 05:25 AM
George Souto
George Souto NMLS #65149 FHA, CHFA, VA Mortgages - Middletown, CT
Your Connecticut Mortgage Expert

Lynn having strong passwords is very important, but these day I am happy if I just can remember them.  😇

Feb 11, 2022 04:47 PM
Myrl Jeffcoat
Sacramento, CA
Greater Sacramento Realtor - Retired

I am sure those able to attend this past Tuesday's Zoom meeting benefitted from it, Lynn.

Feb 11, 2022 09:05 PM