Showing posts with label passwords. Show all posts
Showing posts with label passwords. Show all posts

Monday, October 28, 2013

Handout from Today's Password Management Lunch 'n Learn

If you couldn't make it today's Lunch 'n Learn, don't worry!  We'll be doing another one of these sessions in the near future. In the meantime, here's the handout on KeePass, the FREE password management software that we use here in Information Security.  We highly recommend it! 

It works on PC, Mac and mobile devices so you can have your passwords at your fingertips when you need them.  With KeePass, you just need to remember your master password to get into the password database.  It can even generate passwords for you and log you into websites securely.

We highly recommend it! 
Click on the picture to open the file.

Join Us for Lunch Today: Got (Too Many) Passwords?

We're kicking our celebration of National Computer Security Awareness Month into high gear this week with contests, prizes and 4 Lunch 'n Learns on topics that affect all of us in our online lives.  Want to know more about upcoming events and how to win?  Check out the main NCSAM post.

Why not join us for today's Lunch n' Learn topic on managing all those passwords you have to keep track of?



Everyone gets 2 entries into the prize raffle for each session they attend, so this is a great way to really rack up the points and increase your chance for winning one of our great prizes.

Hope to see you there!
 
p.s.  The online contest starts later today.  Check back here for more details on how you can get an additional entry into the prize raffle.

Wednesday, October 2, 2013

Passphrases, Not Passwords

 
Did you know that the average person's password is fairly easy to guess?  Most people use their name or something personal about them in their passwords, so hackers use dictionaries of common English names, numbers and words to hack passwords.  In fact, you can see the list of the top 10,000 passwords here.  (Hopefully you're isn't on the list!)  But perhaps what's even more startling is that current software has been successfully used to crack passwords that are 55 characters long!

But you don't need to be one of those average people...  Instead, think about replacing your out of date passwords with strong passphrases.  What's that?  What's a passphrase and how do I pick one?  We're glad you asked. 

These 5 tips will help you out:
  1. Choose a phrase that's at least five words long. You might start with your favorite book, song, movie or a quote. Longer passwords are harder to guess than shorter ones, so you could use the entire phrase as your password.  We still recommend doing Step 2.  If the application won't allow such long passwords, then you could use the first letters of each word as your password. For example, the first letters of the book title "The Cat in the Hat" are: tcith. This step protects you from a dictionary attack, in which someone tries to crack your phrase using known words (and proper names).
  2. Alter some of it. The hardest to guess passwords\passphrases are "complex", which means they use a mix of numbers, symbols and upper and lower case letters.  Take your passphrase from Step 1 and replace some lowercase letters with capital letters, numbers or symbols. For example: Tc!tH capitalizes the first and last letter and replaces the "i" with an exclamation point. (You could replace an "a" with the "@" symbol too.) Make it simple; don't write your system down.
  3. Customize the password for each use. Add a character or three to the core password to ensure that every pass phrase is at least seven characters long and includes a number. Generate an extra letter and number based on the name of the program you're accessing. For example: g6Tc!tH could be a password for a Google Gmail account, adding an "o" for the last letter of Google, and a 6, for the number of letters in Google.
  4. Write down your hint. Now you can write down a mnemonic device that will jog your memory without being obvious to anyone else. Hide this piece of paper or keep it in your wallet. For example, you could write down "basic: cat" to recall the Dr. Seuss title.
  5. Establish different levels of passwords. Use different core phrases to develop passwords for online banking, for accounts that use your credit card and for those that don't involve financial information.
  6. Change your passwords often.  If you can't change your password every 90 days, use daylight-saving time as the reminder to change your passwords.  If you don't change them and someone is able to get them, this will stop them from using your accounts for a long period of time.
Want to test how long it would take a hacker to crack your password?  You can test a password over at HowSecureIsMyPassword.net.  But don't put in your actual passwords!!!

Tuesday, October 1, 2013

Happy National Computer Security Awareness Month!

NCSAM It's finally here! National Computer Security Awareness Month starts today and the entire KUMC campus is celebrating throughout the month of October with both online and face-to-face opportunities to learn more about how to keep you, your family, and your data safe and secure. Each day on this blog, we'll focus on a different risk or threat such as phishing, iPad and mobile device security, social media privacy, or keeping track of all those passwords.  It will be a learning experience, but it will be a fun one....we promise!

During the week of October 28th, we hope you'll bring your lunch and join us for all four of the following Lunch 'n Learn sessions from 12 to 1 p.m. 
(You can sign up now using the links below):

Monday, October 28th:  Got (Too Many) Passwords?
Description:  Passwords, passwords, passwords for your bank site, your personal and work email, Facebook, and on and on. How do you keep track of all of them? Bring your lunch and learn about a FREE and secure way to manage your passwords, including how to make sure they're always available when you need them.

Tuesday, October 29th:  Defend Yourself: Top 10 FREE Security Tools
Description:  A new computer taken out of the box and connected to the Internet is easily taken over by a hacker within minutes. If you've got a computer, you need to arm yourself with the right tools to fight this constant battle. Bring your lunch and learn about the FREE security tools that are a must-have for any PC owner.

Thursday, October 31st:  R U My Friend? Privacy and Social Media
Description: Social media sites like Facebook and Instragram are great for keeping track of friends and sharing your everyday life with those you love. But there's also a dark side to sharing your information on these types of sites. Bring your lunch and find out how companies and criminals use the information and photos that you share on these sites and what YOU can do to protect yourself on social media.

Friday, November 1st:   Mobile Revolution: Mobile Device and Cloud Security
Description: Smartphones, iPads, tablets and other mobile devices are literally changing the way we work and play. But do you know how to protect your shiny new device from hackers? And just what does it mean to store your data "in the cloud"? Bring your lunch and your questions as we discuss security issues related to mobile devices and storing data in the cloud.


 
The more you participate, the more chances you have to win one of the great prizes* to be raffled off on November 1st!  And, even if you can' t make one of the sessions, you can still enter the raffle by participating in the online treasure hunt starting October 28th.
 *Prizes to be announced later this month.

We hope you'll join us in the celebration!

UPDATE 10/24/13:  Prizes for this year have been announced and they look great.  Click here to find out details on what prizes are available and how you can enter to win. 

UPDATE 10/28/13: The online security scavenger hunt is now open.  Even if you can't find time to attend the Lunch 'n Learn sessions, completing the hunt will give you an entry into the prize drawing on Friday.  Good luck!