Password of three random words better than complex variation, experts say

https://www.theguardian.com/technology/2021/aug/07/password-of-three-random-words-better-than-complex-variation-experts-say

Robin McKie Observer science editor
Sat 7 Aug 2021 07.29 EDT

Last modified on Sat 7 Aug 2021 10.48 EDT

It is much better to concoct passwords for online accounts that are made up of 
three random words as opposed to creating complex variations of letters, 
numbers and symbols, government experts have said.

In a blogpost, the National Cyber Security Centre (NCSC) – which is part of 
Government Communications Headquarters – said a three-word system creates 
passwords that are easy to remember. In addition, it creates unusual 
combinations of letters, which means the system is strong enough to keep online 
accounts secure from cybercriminals. By contrast, more complex passwords can be 
ineffective as their makeup can often be guessed by criminals using specialist 
software.

The agency said cybercriminals targeted predictable strategies meant to make 
passwords more complex. Examples include substituting the letter O with a zero, 
or the number one with an exclamation mark.

Criminals allow for such patterns in their hacking software, negating any added 
security from such passwords. “Counterintuitively, the enforcement of these 
complexity requirements results in the creation of more predictable passwords,” 
the agency said.

By contrast, passwords constructed from three random words tended to be longer 
and harder to predict, and used letter combinations that were more difficult 
for hacking algorithms to detect, it said.

The blogpost conceded that using three random words was not 100% safe, since 
people might use predictable word combinations, but said a major advantage of 
the system was its usability “because security that’s not usable doesn’t work”.

Cybercrime has soared during the pandemic, with online fraud rising 70% over 
the past year, according to data from the Office for National Statistics.

“Traditional password advice telling us to remember multiple complex passwords 
is simply daft,” the NCSC’s technical director, Dr Ian Levy, said on the 
centre’s website.

“There are several good reasons why we decided on the three random words 
approach – not least because they create passwords which are both strong and 
easier to remember.

“By following this advice, people will be much less vulnerable to 
cybercriminals and I’d encourage people to think about the passwords they use 
on their important accounts, and consider a password manager.”

-- 
Iw mailing list
[email protected]
http://sticklist.org/mailman/listinfo/iw_sticklist.org

Reply via email to