Like laptops, passwords can walk away.
While laptops are often lost or stolen–just last month the U.S. Commerce Department announced that a whopping 1,137 of its laptops were missing–passwords are regularly targeted by hackers and the automated programs they create.
It doesn’t help that we, as Internet users, have countless passwords to track and manage. These days, Web sites for banks, credit cards, e-commerce stores, auction sites, not to mention newspapers, community message boards, dating sites and instant messaging tools, all call for passwords.
How to manage?
I asked Marc Boroditsky, who has been running a security company called PassLogix (www.passlogix.com) for the past 10 years in New York, for advice.
At home, Boroditsky advises that the first and most important rule for password-overloaded consumers is to avoid words listed in the dictionary. Using dictionary words for a password is akin to leaving your laptop unattended in a crowded area.
“You want your passwords to include letters and numbers and even punctuation characters so they’re not a word in the dictionary,” Boroditsky said.
Dictionary words are easy for hackers’ tools to catch as they fly around the Internet.
“Mix letters and numbers in a way that’s memorable to you. So for eBay, you might have a password that starts with the letters `eb’ followed by `go Cubs,'” Boroditsky said. “Then you finish it off with the year you were married.
“Now you have a random string of letters and numbers that hacking tools won’t get,” he said.
To be safe, you should maintain a different password for each Web site you use that involves cash transactions. These include any e-commerce, credit card and banking sites.
“God forbid somebody figures out all of your passwords by figuring out one,” said Boroditsky. “You want to make it difficult for someone to not only figure out one password, but make it difficult to figure out many passwords.”
Also, if you only use a single password, and hackers obtain access to your credit card statements online, they can find out exactly where you shop with that password. And because most sites store your credit card number in your account, this could be a big problem.
But with this one-password-per-site approach, how do you keep from drowning in a password tidal wave?
Boroditsky draws a distinction between financial-related sites and “utility Web sites,” such as news and community sites. These kinds of sites can all share a single password.
“If somebody uses my New York Times account, it doesn’t hurt me,” he said. “But I would be really upset if somebody used my Chase banking account, especially now that banks are making it easier for customers to do transfers.”
He also advises consumers to practice “password hygiene.”
“You get your teeth cleaned on a regular basis,” he said. “You should change your passwords on a regular basis too. Just to be safe, change them every few months. Actually, I change my more sensitive ones more frequently than that.”
In all, Boroditsky estimates his personal repertoire consists of about 15 passwords. “But my wife has a lot more,” he said.
More Top Picks Best Laptop Risers For Professionals
Of course, personal passwords are only the beginning for working consumers. There’s a whole other set of impossible-to-remember phrases that must be remembered at work.
“And companies work to make those passwords complex,” Boroditsky said.
This creates a corporate password paradox.
“The challenge is, if you want to be secure, your passwords must be complex,” he said. “But if you’re too complex, it’s too hard for your employees to remember.”
Which is where Boroditsky’s company, PassLogix, focuses its attention.
PassLogix installs software that allows employees to use a single password at sign-on to access every password-protected portion of the corporate system throughout the day.
“This helps companies eliminate the need for users to remember and enter a multitude of passwords,” Boroditsky said. “The organization still maintains the individual application passwords, but now the employee comes to work and is automatically signed on by our software.”
The application is called v-Go Single Sign-On, and it sells for about $70 per user. Discounts for volume are built in.
The company’s largest customer is the U.S. Post Office, which has 205,000 users.
In addition to their personal passwords, the average corporate computer user must remember 10 different company passwords, Boroditsky said. A third of American employees have more than 15 passwords at work.
Think that’s bad?
Information technology administrators have it worst of all. They average more than 100 passwords.
———-
Alex L. Goldfayn is host of “The Technology Tailor Show” on WGN-AM 720 on Saturdays from 6 to 8 p.m.