
The recent breach popular password management service LastPass suffered serves as the latest in a constant stream of reminders that something is only as secure as its weakest link. For many, the appeal of having to remember only a single password is strong enough to place their trust in a single service despite these breaches. However, the choices need not be split into inscrutable gibberish randomized for dozens of services, or praying that your chosen password manager won’t have a breach. Instead, consider easy to remember, nigh impossible to guess passwords utilizing the principle of password entropy.
High Entropy, High Security
Password entropy is a measure of the complexity of a password. The higher the entropy of a password, the more secure it is. The entropy of a password can be calculated using a variety of factors, including the length of the password, the types of characters used (e.g., character case, numbers, and special characters), and the number of possible characters in the character set.
In the end user’s case, it’s more important to understand how to increase password entropy than how to calculate it. The harder it is for attackers to predict which character comes next, the higher password entropy will be—and the more secure the password is. The simplest way to increase password entropy is to use what’s called a passphrase: a string of words that are easy for the user to remember. It can be as few as two or as many as the password requirements allow; simply using two random words in the Oxford dictionary raises the number of possible combinations from 171,476 to a whopping 29,404,018,576. If these two words have personal meaning to you, but no meaning to anyone else then it’s both easy to remember and an absolute nightmare to crack!
Take the password Apple1962Johnny, used by Mr. John Doe born in 1962. While ‘Johnny’ is an easy guess, attackers likely will not know where in the password ‘Johnny’ is. Perhaps John Doe is a public fan of apples however, and the attackers make the guess that ‘Apple’ is somewhere else in his password. Even with this knowledge, they have no way of knowing where the ‘1962’ is located in the password. The possible combinations now equal 30,000, and this is only if the attackers know the password consists of a four-digit number and the words ‘Apple’ and ‘Johnny’ (and they know the four-digit number isn’t placed in the middle of either word). In other words, this password is all but uncrackable by anyone not very determined to crack this particular password.
Still, the password could be better. Take AppleJohnny1962and ColonialAardvark212. They’re roughly the same length, but ColonialAardvark has even less relation to outside observers, yet to John Doe it may mean a lot. Perhaps the he grew up enjoying the children’s character Arthur the Aardvark and is an avid student of early American history. What’s vital is that the words are easy to remember by you, but to anyone else would appear to be random words pushed together.
It’s important to note that password entropy is not the only measure of password security. Other factors such as how the password is stored and transmitted also play a role. This is one of the most important reasons you should never reuse passwords; if one service falls, then all others that you use that password with are compromised.
Conclusion
The barrier to having a secure password is not as high as the lessons learned in the halcyon days of Web 1.0 would have us believe. Not reusing passwords, and ensuring that you have a memorable but unique passphrase for each password instead of gibberish will protect the vast majority of users from the worst data breaches. If you are in a position where you have to worry about individuals trying to access your specific account, then your security concerns are beyond merely having a secure password. Consider researching how to secure your home internet, keeping your personal devices virus-free, and physical device security in this case.
Leave a Reply