View Full Version : How secure is your password? Stay safe online.
Just thought I would offer up a bit of advice re passwords, as I have recently via work had the misfortune to learn about somebody who fell victim to quite an elaborate scam where their on-line identity was breached via one retailer and as a similar password was used for multiple accounts, they managed to hijack the lot, changed them all and assumed this persons identity using information that was readily available via social media. They also managed to remotely lock them out of their iPhone too!
Kickstarter was recently breached and they are linked to Amazon for payments, so if you have ever pledged on Kickstarter, your Amazon account might be vulnerable. Its good practice to change passwords often, a pain I know, but getting hacked is a lot more painful I can assure you.
So how secure are your passwords? Check them out here https://howsecureismypassword.net/ by using something similar (not your real one!)
I think I should be reasonably safe.
http://i173.photobucket.com/albums/w63/greatgig/password_zps8d75d4eb.jpg (http://s173.photobucket.com/user/greatgig/media/password_zps8d75d4eb.jpg.html)
I have been using Roboform (http://www.roboform.com/) for many years to manage my passwords and it comes highly recommended.
"A sextillion years" - I don't know what that is, but I like the sound of all those years! ;) Seriously though, a very valid point, Tim. IT is my profession, and even I have managed to get suckered once...
Plenty of good advice on passwords out there on the web - but I like to make sure there is a good mix of capital letters, lowercase and at least one symbol - a space or two helps as well - but try not to use the same one on all sites as Tim has eluded to, and change them periodically. :)
rectorydp
26-02-2014, 23:25
+1 from me. Using the same password on multiple sites should definitely be avoided unless you are not bothered about your access being abused. Many people now have so many logons that it is very difficult to manage without some helpful software. I also recommend Roboform and couldn't manage without it (I have hundreds of passwords). Another advantage of Roboform (and there are other similar products) is that it will generate nice secure passwords for you so you don't even have to think them up.
This is very pertinent and worth a read?
'Treasure trove' of personal details found (http://www.bbc.co.uk/news/technology-26351123)
http://i173.photobucket.com/albums/w63/greatgig/trove_zps9fdc7c02.jpg (http://s173.photobucket.com/user/greatgig/media/trove_zps9fdc7c02.jpg.html)
Mark Grant
28-02-2014, 14:27
Also think of the level of security above your passwords.
If you use an online storage email service such as gmail, yahoo, hotmail etc then old emails are stored online.
If a hacker gains access to that email account they will use the search box to search for 'paypal', 'ebay', etc in old emails and then do the 'forgot password' on those sites so your long and complicated password is absolutely worthless.
Always enable two step log in authorisation such as an sms text if possible and don't use real fathers middle names or mothers maiden names as answers to security questions as that information can easily be found out. make up your own security question answers when creating accounts that you wont forget.
Also think of the level of security above your passwords.
If you use an online storage email service such as gmail, yahoo, hotmail etc then old emails are stored online.
If a hacker gains access to that email account they will use the search box to search for 'paypal', 'ebay', etc in old emails and then do the 'forgot password' on those sites so your long and complicated password is absolutely worthless.
Always enable two step log in authorisation such as an sms text if possible and don't use real fathers middle names or mothers maiden names as answers to security questions as that information can easily be found out. make up your own security question answers when creating accounts that you wont forget.
Really good advice Mark. Most accounts now offer secondary (or more) phones to be contacted with verification codes plus there's often a little icon at the base of on-line email accounts which brings up a window detailing when your account was last accessed and the IP address of the machine used to access the account. This is well worth checking often because many of us subscribe to other sites which can be accessed via the central email account. Nothing to prevent you opening multiple on line email accounts with each subscribed solely to one on-line regular shopping haunt to prevent malicious access to your other accounts.
Mark Grant
02-03-2014, 22:46
A few links about two step
https://www.paypal.com/us/cgi-bin?cmd=xpt/Marketing_CommandDriven/securitycenter/PayPalSecurityKey-outside&bn_r=o
http://www.google.com/landing/2step/
https://www.facebook.com/note.php?note_id=10150172618258920
Takes a little longer each time you log in but makes unauthorised access a lot more difficult.
Powered by vBulletin® Version 4.2.3 Copyright © 2026 vBulletin Solutions, Inc. All rights reserved.