Passwords aren’t Secure Enough

Mat Honan:

You have a secret that can ruin your life.

It’s not a well-kept secret, either. Just a simple string of characters—maybe six of them if you’re careless, 16 if you’re cautious—that can reveal everything about you.

Your email. Your bank account. Your address and credit card number. Photos of your kids or, worse, of yourself, naked. The precise location where you’re sitting right now as you read these words. Since the dawn of the information age, we’ve bought into the idea that a password, so long as it’s elaborate enough, is an adequate means of protecting all this precious data. But in 2012 that’s a fallacy, a fantasy, an outdated sales pitch. And anyone who still mouths it is a sucker—or someone who takes you for one.

No matter how complex, no matter how unique, your passwords can no longer protect you.

Look around. Leaks and dumps—hackers breaking into computer systems and releasing lists of usernames and passwords on the open web—are now regular occurrences. The way we daisy-chain accounts, with our email address doubling as a universal username, creates a single point of failure that can be exploited with devastating results. Thanks to an explosion of personal information being stored in the cloud, tricking customer service agents into resetting passwords has never been easier. All a hacker has to do is use personal information that’s publicly available on one service to gain entry into another.

Honan, you may remember, had his entire digital life destroyed this summer in a matter of moments. His article on the insufficiency of passwords for our hyperconnected digital lives is an eye-opener. It’s long, but absolutely worth it.

Honan says to use two-factor authentication when available, give bogus answers to security questions that you can remember (since most of this personal information is easily discoverable through Google), use a unique and secure email address for password recovery, and when all else fails you can scrub your online footprint.

Comments on this entry are closed.