One issue that has been an ongoing problem for me as a business owner is impressiong on employees the need for good passwords. I have had employees use such great passwords as "0333", "Pass2041" (done in 2014), names of girlfriends, and other weak combinations.
The problem with a weak password should be obvious. If you work for me, and your password gets hacked, somebody can get in and hold our data (which are all of our records going back 18 years) hostage, or just plain destroy it out of malice. I do have numerous backups for that reason, but there are other issues too. A password hack can lead to identity theft issues, and possibly get into our finances.
I don't even need to mention that most of us use the same password for everything, so if your password is hacked in one place, the hacker now can get into all sorts of stuff, like your credit cards, Amazon account, bank account, and all sorts of personal information to take out his or her own credit line in your name.
So, why is using your dog's name such a bad idea? Wouldn't it be hard for a hacker to guess the name "Spot2016"? Let me go through all the ways this is a bad idea.
The first way a hacker can get your password is use some obvious ones, like "!234567" or "Password", or "Pass2018", "Pass2014", or "Pass2041". Yeah, a lot of people use those as passwords.
The second is social engineering. If you use the name of your pet or one of your children, a hacker can guess that pretty easily from watching your feeds on social media. If you are careless about accepting friend requests, you may be opening to a hacker all sorts of information about you. I recently removed over 100 people from my Facebook "friends" list because I barely knew them, or didn't know who the heck they were.
Both of the above methods take a bit of work for relatively little reward, and I thought at one time I had a really great password, "Marlowe". Mr. Marlowe is the narrator's name in Joseph Conrad's
Heart of Darkness. I tought that was obscure enough. It wasn't.
A more sophisticated hacker can crack your password with a Dictionary Attack. The method is pretty simple. Every now and then some company is really stupid, and a list of their customers user names and passwords is hacked (Target had it happen, and recently so did Marriott). Now, the passwords are encrypted, but...
Passwords are encrypted with a one way math function called a
hash. It's a rather complex method of scrambling your password so that it becomes a meaningless group of numbers and letters. When you login and enter your password, a hash is created from it, and it is compared to the hash on file, and if it matches you are in.
So, to crack passwords, the system gets to be pretty easy for simple ones. Let's say our enterprising hacker has his database of login names and passwords from Target. These can now get sold to another hacker.
The next hacker can find passwords with a fairly simple method. He or she can simply enter your user name in a program that generates the hash, and guess different passwords. One the right password is guessed, your hash is matched, and the hacker now has an in to all of your stuff.
Now, this is time consuming for a human, but our enterprising hacker doesn't do any of this by hand. The hacker uses a database of possible passwords, and runs it through a computer program. It's pretty simple stuff, you can run the simple guessed passwords against your hacked user database first, like "Password" and "12345678" and you generate quite a number of user names and password combinations.
After our hacker's program does that, the program can start generating combinations with the database of various word and number combinations. So, my "unbreakable" Marlowe password is hacked pretty fast.
The final method is "Brute Force" where the computer just startes generating random combinations. For short passwords of limited character sets, it can break them pretty quick.
So, how do you generate a good password? First, I recommend using a separate password for sites you don't care about. So many sites make you sign up with an account, and you really don't know what their security is. Don't use the same password with them that you do with your credit cards or Amazon.
Second, use a password that is hard to crack. For a start, the more characters, the better. A 4 place password with only numbers has 10 to the 4th power possible combinations (10,000), which is nothing for computers. If you are using letters, we're now at 26 to the 4th power. Add in numbers to that, and it's now 36 to the 4th power. Add another character, and it is 36 to the 5th power. Add the special characters at the top of your keyboard, and we're now 46 to the 5th power. See where I am going? Pretty soon it could take thousands of years for even a supercomputer to break your password - if it is not a dictionary word.
Doing this is pretty easy. Take a phrase you can remember, like "In 1968 ? I had detention 2 times a week at Fernwood Elementary. Take the first letter and the numbers and characters - I1968?Ihd2tawaFE - you now have a password you can remember which would be a nightmare to guess.
The next best level of protection is two step authentication. In this type, you enter your password, and the site sends a code to your cell phone. You have to enter that. To break this, a hacker needs your password, and access to your cell phone, making it harder.
Ultimately, the system is only as good as its weakest link. So, if you go through all this, and one of your employees uses his girlfriend's name as the password to your network, you are probably going to be hacked. This becomes a serious management issue, and has been one I've struggled with repeatedly. There may be a way to get around this with hardware, I'll cover that in a future issue.