Passwords really ARE a big deal

Solutionary Blog and Bloggers

Solutionary is an information security company. What does that mean? Simply put, we help businesses protect their assets, remain fully secure and safe online, and maintain and adhere to compliance regulations and standards. Solutionary's blog will be a place to learn about and discuss a wide variety of security and compliance topics. More information about Solutionary can be found here. To read the Solutionary blog comment policy and disclaimer, click here.

Solutionary Bloggers: 

Brad Curtis, Compliance Manager              Jon Heimerl, Director of Strategic Security
Mike Hrabik, Chief Technology Officer
Don Gray, Chief Security Strategist
Court Little, Director of Strategic Security
Phoram Mehta, Senior Security Consultant
Doug Picotte, Regional Technical Manager
Scott Simpson, Director, Security Consulting Services


Subscribe to our blog

Your email:

Solutionary Minds - Your Information Security Blog Source

Current Articles | RSS Feed RSS Feed

Passwords really ARE a big deal

Posted by Jon Heimerl on Thu, Feb 04, 2010 @ 08:59 AM
Share on Twitter Twitter | Share on Facebook Facebook | Submit to Digg digg it |  Add to delicious  delicious |  Submit to StumbleUpon StumbleUpon | Submit to Reddit reddit 
Man. Sometimes I don't get it. Perhaps after 25 years in this business I have started becoming cyber security paranoid.

I saw an article this week that says 73% of people they checked use their online banking passwords for other purposes - be it another banking site, or other online accounts, like Facebook or email. To me, a person that lives and breathes information security, passwords really are a big deal.

But I guess that's real-life, eh? It's human nature to work towards a point of diminishing returns and no further. This suggests to me that people think it's more work to protect their banking information than the information is worth protecting. The article basically makes the same point.

In reality, I don't believe it for a second. Granted, I have no statistics to back me up, but I would certainly imagine that if you asked 1,000 online users whether their bank accounts or some other online account was more valuable, that something north of 900 users would say "bank account" without blinking. So why the disparity?

Part of the problem is just the size of the issue. All sorts of websites now require you to log-on, and sometimes for no real service. The problem is that a person simply cannot remember a unique username and password to every site they need to log on to. I just checked my favorites list, and I find 59 sites I visit that require username and password. Me, as an admitted cyber security paranoid, obviously have 59 unique usernames and passwords, right?

Heh.

So, how do you do it? There are password managers that will help organize and remember passwords for you. Like Symantec's Identity Safe (available in Norton 360 and Internet Security). You store your sites, username and password in Identity Safe, then you log onto Identity Safe instead of each site. The software does all the matching for you. There are others, but this is the only one I have used and it gets the job done.

If you don't like that option? Classify your logins. Group your logins by generic accounts (which have no real personal information), social media (some personal information with no financial), shopping sites (that have personal information and may store credit card numbers), and absolutely personal sites (like banking sites, or sites that provide access to online medical information). If I use the same username and password on Newsvine as I do on WSJ and foxsports, and someone gets my password on one, am I really concerned if they can log onto one of the others?

At the other extreme are the banking sites. Now, I, personally, really am paranoid enough to use unique passwords on each of my banking sites, but there are only four of those - and four passwords I can remember. And since 30 of my 59 favorites are general sites that contain no valuable information, I am starting to control the size of my problem. But, for the rest, even writing them down and storing them in my desk drawer is better than using the same password everywhere.

Isn't it?


Tags: ,

COMMENTS

Post Comment
Name
 *
Email
 *
Website (optional)
Comment
 *

Allowed tags: <a> link, <b> bold, <i> italics