Watch Out for Password Gotchas

Weak passwords are often a factor in the theft of user data. It is also true that it is becoming harder to create secure passwords. No longer can we simply add a few numbers to the end of our old passwords. Even using symbols to replace letters, like @ for a, or 3 for e, isn’t as effective as it used to be because hackers have figured that out, too. More and more it seems that random character generation is the answer.

Programs that store and protect our passwords usually provide random character generators and have the added value of not taxing our memory. Yet, are they any safer than the single password used to open your list? Biometric password protection is on the horizon, but not yet here for the average computer user. So what are we to do?

For me the answer is still long, complicated passwords that are easy to remember, and a password system that doesn’t required writing them down. (See “Creating a Secure Password That’s Easy to Remember”) Today I’m updating that article with a few new rules for creating passwords.

  1. Create long passwords; as long as a site’s rules will allow if they are limited.
  2. Avoid beginning passwords with a capital letter, because that is the most common way to begin a password. Try starting with a number, small letter or a symbol.
  3. Avoid ending passwords with a string of numbers. It won’t fool the hackers.
  4. To give the appearance of randomness try strings of initials such as the first letter of each word in a sentence, title or quote that you can easily remember.
  5. Find ways to use symbols and numbers creatively.

Here are a few examples for creating passwords using a combination of rules:

“The Lakewood Center for Orthopedics and Sports Medicine gets too much of my money,” becomes tLC4O&SMg2momm.

“A Funny Thing Happened on the Way to the Forum starring Zero Mostel is my favorite comedy,” becomes (with a smiley representing the word Funny) – a:-)THotW2tFsZMimfc.

“My day begins at six with a shower and breakfast so I won’t be late to work,” becomes mdb@6waS&BsIwbl82w

Get creative. You Can Do It!