Skip to content
  • Home
  • ABOUT US
  • SERVICES
    • Medical Workflow Management
    • Managed Services
    • Network Security
    • Backup & Disaster Recovery
    • VoIP
    • IT Support & Consulting
    • Help Desk Support
    • Healthcare IT
  • CONTACT US 
  • (561)-880-4945
  • Windows 10 Upgrade
Menu
  • Home
  • ABOUT US
  • SERVICES
    • Medical Workflow Management
    • Managed Services
    • Network Security
    • Backup & Disaster Recovery
    • VoIP
    • IT Support & Consulting
    • Help Desk Support
    • Healthcare IT
  • CONTACT US 
  • (561)-880-4945
  • Windows 10 Upgrade

Recent Posts

  • A primer on watering hole attacks
  • 3 Common storage virtualization issues
  • The rising popularity of telemedicine
  • What makes a great keyboard
  • Improve communication by dealing with VoIP issues

Think your password is secure? Think again

  • By Alan Grjna
  • December 14, 2018
  • 5:00 pm
  • Security
2017October19Security_C_PH.jpg

For years, we’ve been told that strong passwords include three things: upper- and lowercase letters, numbers, and symbols. And why wouldn’t we when the National Institute of Standards and Technology (NIST) told us they were the minimum for robust passwords? Here’s why not and how it involves you.

The problem

The issue isn’t necessarily that the NIST advised people to create passwords that are easy to crack, but it steered people into creating lazy passwords, using capitalization, special characters, and numbers that are easy to predict, like “P@ssW0rd1.”

This may seem secure, but in reality, these strings of characters and numbers could easily be compromised by hackers using common algorithms.

To make matters worse, NIST also recommended that people change their passwords regularly, but did not define what it actually means to “change” them. Since people thought their passwords were already secure with special characters, most only added one number or symbol.

NIST essentially forced everyone to use passwords that are hard for humans to remember but easy for computers to guess.

Recently, the institution admitted that this scheme can cause more problems than solutions. It has reversed its stance on organizational password management requirements, and is now recommending banishing forced periodic password changes and getting rid of complexity requirements.

The solution

Security consultant Frank Abagnale and Chief hacking officer for KnowBe4 Kevin Mitnick both see a future without passwords. Both security experts advise enterprises to utilize multifactor authentication (MFA) in login policies.

This requires users to present two valid credentials to gain access to their data. For instance, a code texted to an employee’s smartphone can serve as an added security measure to thwart hackers.

Moreover, Mitnick recommended implementing long passphrases of 25 characters or more, such as “correcthorsebatterystaple” or “iknewweretroublewhenwalkedin5623”. These are much more difficult to guess and less prone to hacking. As for the frequency of changing passphrases, it will depend on a company’s risk tolerance.

Simply put, passwords should be longer and include nonsensical phrases and English words that make it almost impossible for an automated system to make sense of.

Even better, you should enforce the following security solutions within your company:

  • Single sign-on – allows users to securely access multiple accounts with one set of credentials
  • Account monitoring tools – recognizes suspicious activity and locks out hackers

When it comes to security, ignorance is the biggest threat. If you’d like to learn about what else you can do, just give us a call.

Published with permission from TechAdvisory.org. Source.

PrevPreviousAre your mobile devices protected?
Next5 Reasons to use Google Data Studio nowNext

Deliver outstanding care at a lower cost

Let’s start with a comprehensive, no-obligation network assessment today

let's talk

Healthcare IT Specialists

1690 rye terrace,

Wellington, fl 33414

Phone: (561)-880-4945

Social Links

Linkedin

Services

Help Desk Support

IT Support & Consulting

VoIP

Backup & Disaster Recovery

Network Security

Managed Services

Medical Workflow Management

Contact Us

Your Message Has been Successfully Sent. Looking forward to speaking with you soon.
Your Message Has Not been sent. Try again later.

©2019 Healthcare IT Specialists. All Rights Reserved. | Nav Map | Privacy Policy

Call Now Button(561)-247-0562