Cybersecurity Awareness Month: Create stronger, safer passwords
Passwords are an inevitable part of the digital age, making strong password practices important for protecting accounts and information.
In recognition of Cybersecurity Awareness Month, the Case Western Reserve University Office of Information Security recommends several tips to help members of the campus community create stronger and safer passwords.
Read on to learn more.
Passwords vs. Passphrases
Passwords are typically shorter, and as a result must have a wider range of characters in them than passphrases. Passphrases are composed mostly of real words and rely on length to keep them secure. While both have their uses and can be used interchangeably in most contexts, passphrases are easier to remember which means you’re more likely to use a secure one compared to a password.
Several factors can make a passphrase vulnerable to attackers, such as:
- Brute force: If the passphrase’s short enough, an attacker can guess every possible combination of characters it could be, sometimes even if there’s a limit on login attempts.
- Dictionary attacks: Attackers often compile lists of previously compromised and common passphrases; if yours could be on the list there’s a greater chance they get to it quicker than brute force.
- Social engineering: One of the most common and successful ways to get a passphrase is to trick or manipulate a user into entering it or giving it up.
- Spying/stalking: Attackers can use your online presence to come up with relevant guesses, or if you wrote them down on paper even find a photo where they can see them.
Tips for creating stronger passphrases
To make your passphrase as strong as possible, the Office of Information Security suggests the following strategies:
- Make it long: The longer a passphrase is, the more time it will take and the harder it will be for an attacker to guess it.
- Make it complicated: If you put enough effort into expanding the range of characters you use in an unpredictable pattern, attackers won’t be able to use a dictionary attack against you.
- Make it different: If an attacker gets one of your passphrases, they may try using it to access your other accounts. Use different passphrases for important accounts, and avoid simply adding a number to an existing passphrase.
- Get help: The better you make your passphrases, the harder it will be to remember all of them. A reputable passphrase manager can help you generate and keep track of them without running the risk of exposure.
- Stay vigilant: Check out the Office of Information Security's phishing guide to see how to spot scams and social engineering.
- Take action: Take a few minutes today to review your accounts and update any weak, reused or outdated passwords.
At CWRU, official passphrase guidelines and best practices include:
- Use at least 12-15 characters;
- Aim for a green complexity rating, based on factors, such as character variety and avoiding weak words;
- Use a passphrase that differs from your current passphrase and the four you used previously;
- Combine numbers, uppercase and lowercase letters, and special characters;
- Use real words in an uncommon or unexpected combination; and
- Choose a passphrase that is memorable to you but difficult for others to guess.
What to do if your account is compromised
If any of your accounts are compromised, there could be serious consequences for both you and the account provider. Your account could be used to steal your information, impersonate you or launch attacks against the company, which could be blamed on you.
If you believe any of your CWRU accounts may have been compromised, contact the CWRU Help Desk at 216.368.4357 or email help@case.edu.
For general or non-urgent information security questions, email askinfosec@case.edu.