Good Day, I hope that this finds you doing well. Today I thought I would switch things up a bit and write a Technology article.
Everyone has at
least one but probably more than one account that requires a password. Passwords are like physical keys in that they
are a bit of a pain. As you evolve you
will undoubtedly have to create passwords for more and more accounts. What is the best method? How many characters should I make it? How will I remember it? When should I change it?
Best practices are not to use anything simple. Most people use something that is easy for them to remember but also easy for others to guess. At least one of you reading this article has a password that contains at least one of the following … a current or former pet’s name, your house number, part of your social security number, a spouse’s name, a crushes name, part of your name or the numbers 123. Passwords are personal so folks tend to personalize them. They aren’t license plates and no one should ever know them. What to do?
Your best bet is to sign up for a password manager. This is essentially a vault where you can securely store multiple passwords the advantage being that you only have to remember the master password aka the password to the vault. Be careful because if you lose the master password you will lose access to your vault. Some password managers will choose random passwords for you to use on sites/accounts that you need. Your best bet is to make a password lengthy 16 characters or greater to be more specific. Some older systems won’t allow for super long passwords but use as many characters as possible. Change your passwords on a regular basis. Every 60 to 90 days is good but at a minimum 1 time per year. Whatever password your using, do not tack an extra character on the new password, make it totally different.
There are many password managers on the market. I found an article that PC Magazine put together that outlines the Best PasswordManagers for 2020. Give it a read and hopefully it will help you make your choice. Most password managers are free but paid versions offer greater features and they aren’t terribly expensive. If you have the extra cash I would recommend paying for the extra features.
The best approach in security is to have layers. In addition to having complex passwords it is also best to enable something called Two Factor Authentication [2FA]. What is that?
Two-Factor Authentication (2FA) is sometimes called multiple factor authentication. Adding one more step of authenticating your identity makes it harder for an attacker to access your data. This drastically reduces the chances of fraud, data loss, or identity theft. This is typically something physical. Back in the day businesses used small devices that fit on your key chain called RSA tokens. Today you can use a cell phone and have as many digital tokens as you need. Usually this is a 6-digit number that randomly changes every 30 seconds.
In order to take advantage of 2FA the provider of the account needs to have it available for you to use. Most financial institutions, some health care providers, some email providers, both Google and Apple as well as other organizations take advantage of 2FA. If it’s available I suggest enabling it.
Some organizations use SMS or text messaging to send a code to your cell phone. This is old school and has been proven to be insecure but if it’s the only option offered take it, as it’s better than nothing.
Just like Password Managers there are multiple 2FA managers. I recently learned of an app called Authy and it seems great because the key advantage is that it lets you backup your data as well as run the application on multiple devices which makes it a bit more convenient. Personally, I like a push notification to my phone and then to acknowledge yes, I approve or no I reject rather than having to look up what the present 6-digit code is. But that is a personal preference.
I found an article that outlines the Best 2FA authenticator apps in the hopes that it will assist you in making a choice.
I’m looking to avoid a potential headache from posting this but I want to be polite at the same time. Suffice to say that I work in IT to generate an income/living and to have a career. I am not looking for side work. I actually avoid it like the plague because as soon as you touch a machine the next time something goes wrong, you get the blame. If you have a generalized question or two, I don’t mind providing some feedback or my opinion but I don’t want to embroil myself in any issues. Hopefully, you understand. I don’t expect anything like this to happen but I want to put it out there to be safe. I do hope that you find this information useful and helpful. That is the purpose/goal of this post, as well as to educate/inform.
Take care and I will talk with you peeps again soon! Be well.

No comments:
Post a Comment