DATA DOCTORS

Do my account passwords really need to be 10 characters long?

Aug 20, 2016, 6:18 AM

(StockSnap Photo)...

(StockSnap Photo)

(StockSnap Photo)

Q: I’ve been told that my passwords should now be at least 10 characters long in order to be secure nowadays. Is that true?

Passwords tend to be the only thing separating criminals and thieves from our online accounts, which is why they spend so much time creating sophisticated means by which to compromise them.

Just about all the advice you’ll ever hear about creating strong passwords is generally designed to thwart sophisticated guessing schemes commonly referred to as brute-force attacks.

Brute-force attacks, which are generally performed off-line by high-speed computer networks, are a systematic process of trying every possible combination of letters, numbers and special characters until the correct combination is figured out.

Long, complex passwords are the best way to combat this type of attack.

Understanding brute-force attacks

If you were to only use two characters for your password, you can see how a high-speed computer could guess every possible combination in the blink of an eye.

In fact, the Gibson Research Password Haystack Tool suggests that any two-character password can be broken in 0.0000000000354 seconds or less

Each additional character that you add exponentially increases the number of possible combinations, so the longer your password is, the longer it will take for a brute-force attack to be successful.

Most of you have been trained to use complex, eight-character passwords, which are hard for you to remember and easy for attackers to crack. With today’s sophisticated password cracking technology, GRC’s tool suggested it will take just over one minute to break any eight-character password, no matter what combination of characters you use.

By stretching the password to 10 characters, that one minute goes to one week, as long as you have included uppercase characters, numbers and special characters.

Use passphrases, not passwords

If you don’t follow the guidance on using all the required characters, the number of possible combinations drops exponentially.

For instance, the time that it takes to crack a complex 10-character password that does not include an upper case letter goes from one-week down to just over six hours.

The key to creating strong complex passwords that you can remember is to stop using passwords and start using passphrases.

My go-to example of “I H8te Passwords!” is a 17-character passphrase (including spaces) that GRC’s tool suggests would take 13.44 billion centuries to crack.

By creating a passphrase that is personal to you, you have a much better chance of creating a long complex password that you can easily remember.

For example, “I’m Going To Aruba in 2017!” is 27 characters long and uses all the required characters. Some sites don’t allow you to use spaces, but it would still be 22 characters long.

12-character minimum

I personally shoot for at least 12-character passphrases these days, knowing that brute-force cracking technology is going to get faster as time goes on.

If time wasn’t a factor, any password of any length can eventually be broken, but time is a factor with cyber thieves, so make yours long and complex enough so that your accounts aren’t worth their time.

Data Doctors

Patrick Mahomes #15 and head coach Andy Reid of the Kansas City Chiefs are recorded on a phone as t...

Data Doctors

Handy tech tips all Valley residents should use to find lost phones in a snap

Q: My phone went missing, and I haven’t been able to locate it using the Find My service, so what should I do next?

5 days ago

(Pexels Photo)...

Ken Colburn, Data Doctors

Here are tips for freeing up Google storage space

Google provides a generous amount of free online storage but it can fill up quickly depending on how many of its resources you use.

12 days ago

Discover how to assess, estimate, and shop for the right battery pack with this concise guide. (Pex...

Data Doctors

Here is everything you need to know for testing and buying battery banks

Discover how to assess, estimate and shop for the right battery pack with this concise guide.

19 days ago

(Pexels Photo)...

Ken Colburn, Data Doctors

Here are the truly free smartphone video editing apps

The processing power on our smartphones has grown exponentially, allowing anyone to perform sophisticated video editing easily.

26 days ago

Google Maps app....

Data Doctors

How to rediscover places visited years ago on Google maps

Whether you're an Android or iOS user, or prefer accessing Google Maps on your computer, you'll find step-by-step instructions to unlock your travel memories effortlessly.

1 month ago

(Photo by Michael Bocchieri/Getty Images)...

Ken Colburn, Data Doctors

Here’s how to calculate your bandwidth needs

When searching for an alternative internet service provider, here are some tips on how to know how much bandwidth is needed.

1 month ago

Sponsored Articles

...

DESERT INSTITUTE FOR SPINE CARE

Desert Institute for Spine Care is the place for weekend warriors to fix their back pain

Spring has sprung and nothing is better than March in Arizona. The temperatures are perfect and with the beautiful weather, Arizona has become a hotbed for hikers, runners, golfers, pickleball players and all types of weekend warriors.

...

Collins Comfort Masters

Avoid a potential emergency and get your home’s heating and furnace safety checked

With the weather getting colder throughout the Valley, the best time to make sure your heating is all up to date is now. 

(KTAR News Graphic)...

Boys & Girls Clubs

KTAR launches online holiday auction benefitting Boys & Girls Clubs of the Valley

KTAR is teaming up with The Boys & Girls Clubs of the Valley for a holiday auction benefitting thousands of Valley kids.

Do my account passwords really need to be 10 characters long?