Skip to content
  • 509-783-5450
Search
Close
  • Home
  • Services & Solutions
    • Compliance
      • Cyber Security Maturity Model (CMMC)
      • HIPAA Compliance
      • PCI Compliance
      • CyberSecurity
    • Network Management Services
      • Proactive Network Management
    • Business Continuity Planning
      • Data Backup
      • Disaster Recovery Solutions
    • Technology Consulting
      • Security
      • Reactive Support Services
    • Telecommunications
      • VoIP
      • Infrastructure – Cabling & Moves
  • Support
  • Resources
    • Blog
    • White Papers
  • About Us
    • Testimonials
    • Community Involvement
    • Careers
    • Referral Program
    • Staff
  • Contact Us
Menu
  • Home
  • Services & Solutions
    • Compliance
      • Cyber Security Maturity Model (CMMC)
      • HIPAA Compliance
      • PCI Compliance
      • CyberSecurity
    • Network Management Services
      • Proactive Network Management
    • Business Continuity Planning
      • Data Backup
      • Disaster Recovery Solutions
    • Technology Consulting
      • Security
      • Reactive Support Services
    • Telecommunications
      • VoIP
      • Infrastructure – Cabling & Moves
  • Support
  • Resources
    • Blog
    • White Papers
  • About Us
    • Testimonials
    • Community Involvement
    • Careers
    • Referral Program
    • Staff
  • Contact Us
  • August 7, 2020

Think your password is secure? Think again

2017October19Security_C_PH

The National Institute of Standards and Technology (NIST) created many of the password best practices you probably loathe — using a combination of letters, numbers, and special characters. The NIST now says those guidelines were ill-advised and has changed its stance. Find out why and what this means for you.

The problem

The issue isn’t that the NIST advised people to create easy-to-crack passwords, but their previous advice inadvertently made people create weak passwords using predictable capitalization, special characters, and numbers, like “P@ssW0rd1.”

Such a password may seem secure, but the strings of characters and numbers could easily be compromised by hackers using common algorithms.

What’s more, the NIST also recommended that people change their passwords regularly, but did not specify how and when to change them. Since many people thought their passwords were already secure because they’ve included special characters in them, most only added or changed one character.

The NIST essentially forced everyone to use passwords that are hard for humans to remember but easy for a hacker’s algorithm to crack.

Eventually, the institution admitted that this can cause more problems than solutions. It has reversed its stance on organizational password management requirements, and is now recommending banishing forced periodic password changes and getting rid of complexity requirements.

The solution

Security consultant Frank Abagnale and Chief Hacking Officer for KnowBe4 Kevin Mitnick both see a future without passwords. Both security experts advise enterprises to implement multifactor authentication in login policies.

This requires a user to present two valid credentials aside from a password to gain access to an account. This could be a code sent to the account owner’s smartphone, a login prompt on a mobile device, or a facial or a fingerprint scan. This way, hackers’ login efforts are futile unless they fulfill the succeeding security requirements.

Moreover, Mitnick recommended implementing long passphrases of 25 characters or more, such as “recedemarmaladecrockplacate” or “cavalryfigurineunderdoneexalted.” These are much more difficult to guess and less prone to hacking. As for the frequency of changing passphrases, it will depend on a company’s risk tolerance.

Simply put, passwords should be longer and include nonsensical phrases and English words that make it almost impossible for an automated system to crack.

You should also enforce the following security solutions within your company:

  • Single sign-on – allows users to securely access multiple accounts with one set of credentials
  • Account monitoring tools – recognizes suspicious activity and locks out hackers

When it comes to security, ignorance is your business’s kryptonite. If you’d like to learn about what else you can do to remain secure, just give us a call.

Published with permission from TechAdvisory.org. Source.
PrevPrevious
NextNext

Contact Information

1900 Fowler Street
Suite G
Richland, WA 99352
Phone: 509-783-5450
Toll Free: 800-214-5450

IT Services

  • Network Management Services
  • Proactive Network Management
  • Business Continuity Planning
  • Technology Consulting
  • Telecommunications
  • Infrastructure – Cabling & Moves
  • Compliance Services
  • Security Services

Testimonials

Inline Computer has been critical in keeping us running day to day. They are friendly and helpful, and offer reasonable solutions and advice for our organization’s technology needs.
TheresaNon-Profit
You guys are the best! Thank you for years of knocking it out of the ballpark with your top notch customer service... and always with a big smile.
SummersHospitality
We selected Inline Computer and have had no regrets. This is a knowledgeable, courteous, and proactive crew and I highly recommend them.
ChristieO&G
We’ve worked with Inline Computer & Communications now for over ten years and trust their team to meet our IT needs. With Inline Computer & Communications we get fast response time, experienced professionals, and best of all, peace of mind. We know they can handle any issue that comes up so we don’t have to worry about our technology.
MelodyHealthcare
I worked with Inline Computer & Communications at my previous company and I highly recommend working with them if you are looking for an IT management service provider. The team at Inline is organized, professional, responsive and provides great service. They have a knowledgeable and diverse team that can assist with any issue that might arise. Inline kept our IT infrastructure running smoothly at all times. They were always eager to assist us and very committed to helping us find the right solution. I give them five stars for their knowledge, capabilities and customer service!
GlynisManufacturing
I called Inline Tuesday morning asking for set-up of a temporary laptop for our employee who is hospitalized. Ken and Jordan went above and beyond and had the laptop ready for pick up by 3:30pm the same day. The staff is always helpful and friendly. I appreciate all they do for us.
JannaIndustrial
I called in to request an expedited service on this as this was an unplanned new hire on the first working day of the month. I was very pleased on how quickly this was completed. Greatly appreciated!
TeresaSales
My experience was awesome! It was handled immediately upon making the call and the tech was very patient with me while working to resolve the issue. Thanks a lot!
WayneConstruction
Each time I have requested a service ticket, I have always had good experiences. They are nice and are able to resolve my problems quickly. Please thank them for everything they do.
AngelaNon-Profit
There has never been a need to make a suggestion of what Inline needs to do to improve their services. The services are quick, reliable and the issues are always remedied. Thank you!
BeckyNon-Profit
Inline staff is always available to assist me with the IT fires that come up. They are always kind regardless of the silly questions or requests made. If they are in the midst of another project they will give a timeframe on completion of my request. I appreciate them very much!
K.J.Manufacturing
James is always very helpful and patient to the "technologically challenged", like me. He gives clear directions and makes things easy to understand. THANK YOU, JAMES!
TristaNon-Profit
I truly appreciate how professional and kind all of you are when I call with my technical questions and am never left feeling like I am "stupid". All of you are so kind and patient. Thank you.
BetsyNon-Profit
Those who assist me on any of my questions/concerns are always prompt, thorough, and courteous. Excellent customer service.
BeckyNon-Profit

©2021 Inline Computer & Communications | Privacy Policy