The results of two recent computer security polls show too many of us are doing a poor job securing our password-protected data.
With a typical computer user routinely accessing a dozen or more password-protected sites — from media to entertainment to financial sites — Symantec, the diagnostic and security software firm, found nearly half the respondents reuse a handful of passwords for all of their accounts. If one account is hacked, the culprit can use the same password to enter some of the user’s other sites as well.
Some 63 percent of us change our passwords infrequently, which is contrary to the recommended practice of routinely changing passwords to keep would-be hackers at bay.
And the security firm Imperva found that users are making poor choices when selecting passwords that act as barriers to sensitive sites. Among the bad practices:
* About 30 percent are using six or fewer characters in passwords, greatly increasing the odds of successful hacking.
* About 50 percent used names, common words or “lazy” passwords such as adjacent letters (e.g. “qwerty”) or numeric strings (e.g. 777777). Most security experts suggest that passwords not contain any construction that can be found in a dictionary, lest automated code-breakers drill through a database of words (including names) until they score a hit.
* Among the most common passwords used: “Password,” “123456” and pet names such as “Fluffy.”
Folks, if your password is Fluffy, here’s a suggestion: Why not just hand over all your savings to me?
The dilemma facing security-conscious computer users is that while you want to use as tough a password as possible, you don’t want it to be so obscure that you forget it a minute after you create it.
The password gPq#2m1+]X5e is a wonderfully powerful one that will tax the most skillful of hackers; but it is not terribly easy to remember,…