Tips for Creating Strong Passwords
You probably have dozens, if not hundreds, of online accounts. From your email and bank account to streaming services and online shopping, passwords are the first line of defense in protecting your personal information.
But cybercriminals are becoming more sophisticated, and oftentimes, simply having a password isn’t enough. The strength of your passwords and the habits that surround them can make a significant difference in keeping your accounts secure.
To help explain how passwords get hacked and how you can create stronger passwords, we spoke with Torie Cullers, Risk and Fraud Manager here at Amplify Credit Union. Throughout this guide, Cullers shares practical insights on how you can protect your accounts from unauthorized access and keep your data safe.
How Passwords Get Hacked
Before we dive into some tips, it is important to understand the ways that hackers get our passwords in the first place. Here are some common methods of password hacking:
Phishing
This scam method is a psychological tactic where cybercriminals try to manipulate you into giving them your personal information. Phishing attacks typically come in the form of an email, pop-up, or text message (also known as smishing) from a seemingly reputable party, like a bank or a network provider.
“This is one of the most common tactics we see,” Cullers explains. “The goal of phishing emails is to get you to log in with your real account credentials, thereby passing them along to the phisher.”
For example, you may get an email that tells you there’s a problem with your account, asking you to click on a link to verify your identity by logging in with your password. The site will be designed to look legitimate, so if you’re not paying attention, you won’t even realize you’re handing your information right over to hackers.
Phishing scams increasingly come by phone call too, sometimes called vishing. If a caller says they’re from your bank and asks you to verify your password or a one-time code, hang up and call the number on the back of your card instead.
Brute Force
This type of attack occurs when a hacker repeatedly tries different guesses at your password until they are able to get in successfully. Hackers use computer programs to automate the guessing and make thousands of guesses in seconds.
Keylogging
A keylogger is a type of software or hardware that can track your keystrokes. In the wrong hands, a keylogger can be used to capture data like passwords and credit card numbers.
Cullers says that victims often never know something is wrong since keyloggers are designed to remain hidden and send information quietly in the background.
“A keylogger can be installed remotely on your computer through hidden malware or Trojan viruses,” Cullers says. “It may be as simple as accidentally clicking an unknown link. Once a keylogger is installed on your system, the hacker has visibility into everything that you type and can easily collect your passwords.”
Credential Stuffing
This type of attack relies on the fact that many people use the same password for multiple accounts. With this method, a hacker who already has your login information for one website will then attempt to use that username and password combination for many other websites.
6 Tips for Creating Strong Passwords
The good news is that creating a strong password doesn’t require any special technical knowledge. Implementing these six tips can go a long way toward protecting your accounts.
1. Use a unique password for every account.
Healthy passwords start with the basics: don’t recycle your passwords.
“As tempting as it can be to use the same password for all the accounts that you use, this is one of the easiest ways to have your information compromised,” Cullers says.
If you’re using one password for everything, one data breach can put all of your accounts at risk, even if it’s a strong password that seems impossible to guess.
2. Make it random.
It’s one thing to use a different password for every account— but if those passwords look like “password123”, it’s not going to help much! By using random passwords, you can further prevent anyone from guessing them. Two common ways to create stronger passwords are:
- Random string: This is a completely random combination of uppercase and lowercase letters, numbers, and special characters, such as Mfdi9@kd&kL.
- Passphrase: A passphrase is a longer password made up of several unrelated words, such as friends-anchovy-1001-hut. Passphrases are typically easier to remember than random strings while still providing strong security, especially when you use unexpected words and add numbers or symbols.
If remembering dozens of unique passwords sounds impossible, that’s exactly what password managers are for. They can generate strong, random passwords for every account and securely store them, so you only have to remember one master password.
3. Avoid using personal information.
Your password should not contain information that can be easily found on the internet, like your name, address, city, birthdate, and so on.
4. Make it long.
It’s harder to remember, yes, but a longer password is simply more secure. The National Institute of Standards and Technology recommends using the longest password or passphrase permissible when you can. So if a website says your password can be up to 28 characters, aim for a password that’s 28 characters long.
5. Include a mix of characters.
Your password should include a mix of unique characters: numbers, symbols, and uppercase and lowercase letters.
6. Don’t use sequential numbers or common keystrokes.
When using numbers in your password, avoid sequential numbers like “12345”, as well as common keystrokes like “qwerty”. Choose numbers and letters that are far apart from one another on your keyboard.
Additional Security Measures to Layer with Strong Passwords
“The key to great password security lies in layers,” Cullers notes. “More than just doing one thing and hoping it works, it’s best to build a collection of strong habits around the way we protect our accounts.”
When used together, the following strategies can go a long way toward protecting your accounts.
Utilize a Passkey Instead of a Password
Where a site offers it, consider setting up a passkey instead of a password. Passkeys use your device’s fingerprint, face scan, pattern or PIN to sign you in, and since there’s no password to steal, they can’t be phished or guessed.
Enable Two-Factor Authentication
For an extra layer of security, always use two-factor authentication, particularly for accounts like email, banking and social media— anywhere sensitive data is stored.
This two-step process involves an additional step on top of entering your username and password. The second piece of information, or “factor”, will be:
- Something you know, like a PIN or an answer to a question
- Something you have, like a smartphone or a one-time code sent to you by text or email
- Something you are, like a fingerprint
There are two common methods of two-factor authentication: through SMS or through an authentication app, like Google Authenticator, which generates unique, one-time authentication codes that refresh every 30 seconds.
When you log into an account that is using two-factor authentication, it will prompt you to enter the authentication code you received.
Keep in mind that SMS codes are convenient but can be intercepted through SIM-swapping. Where available, an authenticator app or a passkey offers stronger protection than text-message codes.
Store Your Passwords Securely
It’s all well and good to recommend using a different password for every account–but remembering that many passwords can be very challenging! Here are some options to wrangle your passwords:
- Physical journal: One option is to keep a physical journal or notebook with usernames or passwords. Be sure to keep this in a secure place, like in a safe at home.
- Password manager: A password manager is a secure application that can generate, store, and autofill passwords. This option comes with a huge warning: It’s important to fully research a password manager before you dive in.
What’s not recommended? Cullers warns against keeping a list of passwords somewhere that can easily be accessed by someone else.
“Don’t keep a list of passwords on your phone’s notes app or in your email,” she notes. “Whichever method you choose, the key is to have your method of storing the passwords be just as secure as the passwords themselves.”
It’s also worth periodically checking whether any of your accounts have shown up in a data breach (sites like haveibeenpwned.com offer free lookups). If one turns up, change that password, and any others using it, right away.
Online Safety Recommendations
As technology continues to advance, safety recommendations will too. Here are some basic rules to keep in mind when you’re interacting with technology:
- Never click on a link within an email. It’s always better to navigate directly to the site, especially if the email is asking you to log in or verify information.
- Make sure your software is always up-to-date. This rule applies to computers, but it also applies to phones, cars, and anything else with a “brain”! Keeping your software up-to-date ensures that the latest security patches are in place and your operating system isn’t left vulnerable.
- Keep your information to yourself. Unless someone else absolutely needs to know, don’t share logins or passwords.
- Beware phone calls from tech support. Tech support scams are very common. If you receive a phone call or direct message from someone claiming to be tech support, do not give them any information.
- Check your account activity and statements regularly: Catching a suspicious login or transaction early is often what limits the damage.
“Education is also important here,” says Cullers. “Hackers and scammers are always coming up with new ways to infiltrate systems and trick individuals into handing over valuable information. With the technology constantly changing, one of the best things you can do to protect yourself is to stay up to date with common trends and tactics.”
Strong Passwords Are Worth the Effort
Creating strong passwords and building good security habits may seem like small steps, but they can dramatically reduce your risk of becoming the victim of fraud or identity theft. Every improvement makes your accounts more difficult for cybercriminals to access, whether you’re updating old passwords, enabling two-factor authentication, or using a password manager.
“Cybercriminals are always looking for the easiest way to get into an account,” Cullers reminds us. “When you use strong, unique passwords and layer on additional security measures, you’re encouraging them to move on and look for an easier target.”
By taking a little time to strengthen your passwords today, you’ll be in a much better position to keep your personal information secure tomorrow.
This article was first published on December 12, 2022.