Once upon a time, passwords could be relatively simple. You could swap an “e” for a “3”, or add a number on the end of a word, and it was all pretty easy.
But nowadays, password attacking scripts specifically target common habits like this. If you’re using the same password everywhere, things can turn out badly!
Using strong and unique passwords can be one of the key differences between being hacked, and not.
Weak passwords are easily compromised
Fact: Predictable words, sequential numbers, and personal information create weak passwords.
Each year, SplashData identifies the top 25 most common passwords. If you’re using one of these anywhere online, the chances of that password being cracked is extremely high.
What is a strong password?
Take a look at this infographic, showing how long it takes to crack passwords of different lengths:

Ideally, a strong password is at least 12 characters long, and a mix of numbers, uppercase, lowercase, and symbols.
And it should only be used ONCE.
Why? Because there are databases around that collect compromised email address/password combinations, and use them to try to hack into other websites.
So how do you remember all the different passwords for different things?
This is where a password manager comes in. A password manager allows you to generate random, strong passwords, and store them in a secure database which is protected by a password. This means you only need to remember ONE password (and yes it should be a very strong one!).
Some well-known password managers include*:
- KeePass (Windows/Mac/Linux/Mobile, Free)
- LastPass (Windows/Mac/Linux/Mobile, Basic: Free/Premium: $US1/month)
- 1Password (Mac OS X/iPhone, Desktop: $US39.95/iPhone:$US14.95)
- Roboform (Windows, Basic: Free/Pro: $US29.95)
- SplashID (Windows/Mac/Mobile, Desktop: $US19.95/Mobile:$US9.95)
- Dashlane (Windows, Mac, iOS, Android, Free / Premium)
- and a bunch more if you Google “password manager”
* Note that LastPass has experienced security incidents in recent years – research current reviews before choosing.
Consider your needs before choosing a password manager. For instance, if you need to access your passwords on a desktop browser and a phone, choose a password manager that works with all the software and hardware you use.
We’ve always used KeePass, but that’s mostly because it was one of the first and it’s open-source, simple and free. The downside is those things probably make it a little less user-friendly than newer options.
Two-Factor (2FA) or Multi-Factor Authentication (MFA)
2FA/MFA adds a second level to a login, which provides a stronger defence for that account. It combines something you know (your password), with something you have (your phone).
In simple terms, you login using a password, and then verify the login via a code sent to your phone or app. If 2FA/MFA is enabled and somebody gets hold of your password, they still need that 2nd factor to get in.
2FA/MFA can be enabled on many different accounts, including Gmail, social media accounts like Facebook & Twitter, eBay – AND your website.
How do I know if my email address has been compromised?
An Australian security researcher, Troy Hunt, has created a free online tool called Have I Been Pwned, where you can check your email address without entering any passwords. If your email address comes up for a particular site, it means the email/password combination for that website has been compromised and you should change your password(s) for that site immediately.
This is obviously much easier to do, if you’ve used different passwords for every site every time! If you’ve used the same email address/password on multiple sites, then you should change your password on all of those sites.
If you’d like help with password policies or security practices for your business, get in touch.







