Password Security
Password security
User accounts are secured by passwords. Having a look at the top ten of the most popular passwords in Germany reveals that, even today, many people severely underestimate the importance of secure passwords. Among the most-used passwords are number sequences like “123456”, “12345”, combinations of such with simple words like “hello123” and the all-time favourite “password”. For skilled hackers, it is a cakewalk to guess such passwords. In addition, there are automated processes hackers use to test millions of passwords within a matter of seconds. Once the password is cracked, the attacker gains full access to the account and hence to all data and information handled via the account (addresses, credit card numbers, photos, etc.). Publishing or selling the seized login details may also lead to identity fraud, and to the copying, alteration or destruction of data.
It is therefore important to choose a secure password. So what makes a secure password? Please read our advice below. In general, you should treat your passwords as responsibly as the keys to your home or the PIN of your EC card.
Tips, tricks and rules for passwords
Should I change passwords regularly?
For a long time, experts shared the opinion that passwords need to be changed regularly. However, current research proves that changing passwords regularly does not add to security anymore [2] [3]. Actually, the opposite is the case: The more often you change a password, the harder it gets to remember it. Thus, users tend to use slightly different versions of their old passwords when changing it or to write their passwords down.
So if you have chosen a secure password, it only needs to be changed once it has been leaked. It is advisable to regularly check whether the passwords are still considered secure by performing an Identity Leak Check.
If you suspect that your passwords are easily spied on, are compromisable, or have been leaked otherwise, you should change them immediately.
Please visit the websites of the IT Service Centre (available in German) to read how you change your password: Password change.
Tips for secure passwords
- A secure password should have at least ten (or more) characters.
- It should consist of upper and lower case letters and special characters (?!%+…).
- However, the password should not contain umlaut letters (ä, ö, ü), as some programmes will process them incorrectly, and they cannot be found on most country-specific keyboards.
- Do not use passwords hackers can easily guess (surname, relatives, pets, birthdays, etc.).
- Secure passwords are found in no dictionary.
- Your password must not consist of well-known variants and repetitions of keyboard patterns like “asdfgh”, “1234abcd”, “qwertz”, “1qay2wsx” etc.
How to memorise a good password? [1]
There are some tricks to memorise passwords more easily. A very popular method works like this: You make up a sentence and only use the first letter of each word (or only the second or last letter). Then you write certain letters as numbers or special characters.
Example:
“I get up in the morning and brush my teeth for three minutes.” Only use the first letter of each word: “Iguitmabmtftm”. “I” looks like the digit “1”, “&” replaces the “and”, “4” replaces “for” and “3” replaces “three”: “1guitm&bmt43m”.
By applying this method, you can build a mnemonic you can remember easily. It is important that the password user makes up the password her/himself. If you use the first letters of a quote from literature or a children’s song, it will be relatively easy to guess the password derived from it.
When you change a password, please do so before you begin a period of permanent use (e.g. when the semester starts) and not before your holidays or a period of longer absence.
Do not write down passwords!
You should never store passwords on your PC unencrypted, neither should you write them down on sticky notes on your screen or keyboard.
If you have many accounts to handle, you may want to use a password management software, e.g. keepass. A password manager stores all of them and helps you generate secure passwords. All you have to do is create and memorise a secure master password to access the password manager. The master password grants you access to all other passwords stored. The downside: If an attacker knows the master password, s/he will have access to all passwords stored in the password manager.
Thus, it is imperative to ensure that your master password is complicated and long enough that no one will ever find out!
Do not use the same password multiple times!
It is a bad habit to use the same password for multiple accounts. For example, one and the same password used for online banking and social networks. If the password of a single account gets into the wrong hands, the attacker gains access to several accounts at once.
Thus, you have to assign an individual password to each application!
Change default passwords [1]!
In many software products, placeholder passwords or generally-known passwords are used for the purpose of installation (or as factory setting). Hackers are aware: In an attack, they first check if users have forgotten to assign new passwords to these accounts. It therefore makes sense to read manuals if such accounts are present and, if that is the case, to immediately secure them with appropriate passwords. Do not pass on passwords to third parties or by e-mail.
If you pass on your password to third parties, you will lose control over it and the efforts invested into the creation of a good password is lost. Therefore: Never tell your password to others!
Never send passwords by e-mail. By default, e-mails are sent unencrypted. Everybody can read unencrypted e-mails on their way through the internet.
Thus, never send passwords by e-mail and never let anyone know about your passwords!
Does anyone else know your login details? Perform an Identity Leak Check!
There are services on the internet which can check whether your login details (e-mail addresses and passwords) are known to the public. This data might have been revealed through a data breach or leakage in the past. For example, in 2012, hackers could steal 68 million e-mail addresses together with their (encrypted) passwords from Dropbox. If hackers do not use the valuable information themselves, they often sell it via the so-called darknet.
Services that allow you to check whether your data is part of an identity leak using your e-mail address are offered by the Hasso Plattner Institute (HPI) and IT security expert Troy Hunt (Have I been Pwned).
The probability that you too have been a victim of such a data leak is very high. The HPI, for example, states that almost 820,000 accounts are published every day.
To check your email address, simply enter it on the providers' websites. With the "Have I been Pwned" service, you will immediately receive a response; with the HPI, you will receive this response by e-mail.
Dienst | Link | Anbieter |
Have I Been Pwned | Troy Hunt | |
Identity Leak Check | Hasso Plattner Institut (HPI)
|
Please only let your own e-mail address(es) be checked via the services, as in case of the HPI, a notification e-mail will be sent to the address you are checking.
If your THWS e-mail address shows up in one of the leaks, please immediately contact the ITSC help desk at THWS and change your password as a precaution!
-> Website of the IT Service Centre: itsc.thws.de
Standort | Telefon | |
Würzburg | helpdesk.itsc[at]thws.de | 0931 3511-6260 |
Schweinfurt | helpdesk.itsc[at]thws.de | 0931 9721-6262 |
If your private e-mail address shows up in one of the leaks, we recommend you to change your passwords used in connection with this e-mail address immediately!
You will find further information on the processes, purposes and sources regarding Identity Leak Checks in the FAQ sections of the corresponding pages.
Sources: (Cf. [4] [5])
Authentification Policy & Training course
The THWS has implemented a binding authentication policy for members of the THWS. A trainings-course has also been created in the THWS-E-learning Tool.
------------------------
Training course for students: https://elearning.thws.de/course/view.php?id=20197
Training course for staff: https://elearning.thws.de/course/view.php?id=20196
References
[1] BSI für Bürger, "Passwörter", Federal Office for Information Security, www.bsi-fuer-buerger.de/BSIFB/DE/Empfehlungen/Passwoerter/Umgang/umgang_node.html).
[2] Y. Zhang, F. Monrose und M. K. Reiter, "The Security of Modern Password Expiration: An Algorithmic Framework and Empirical Analysis," in CCS '10: Proceedings of the 17th ACM conference on Computer and communications security, Illinois, Chicago, USA, 2010. Accessible at: dl.acm.org/doi/abs/10.1145/1866307.1866328
[3] S. Chiasson und P. C. van Oorschot, "Quantifying the security advantage of password expiration policies. 77. 10.1007/s10623-015-0071-9.," Designs Codes and Cryptography, 2015. Accessible at: people.scs.carleton.ca/~paulv/papers/expiration-authorcopy.pdf
[4] T. Hunt, "Have I Been Pwned," [Online]. Available at: haveibeenpwned.com. [Last accessed on 26 February 2020].
[5] Hasso-Plattner-Institut, "Identity Leak Check", [Online]. Available: sec.hpi.de/ilc/. [Last accessed on 26 February 2020].
