Password advice for 2017
I’ve written several posts over the past few years on passwords. In particularly my post on password strategy remains just as relevant now as when I wrote it several years ago.
the National Institute of Standards and Technology recently updated its guidelines on creating secure passwords and it made some fairly significant changes. The main change was to remind user on the importance of password length and less on included special characters etc. From an NPR interview, the NIST spokesperson offers the following advice “Keep passwords simple, long and memorable. Phrases, lowercase letters and typical English words work well”.
For phrases try and use unrelated words but something you will remember. For example Starbuckshamburgernever, this is 23 characters long and you remember it as it’s something you will never order at Starbucks.
According to Steve Gibson’s haystack brute force calculator, it would take approximately 9.53 hundred trillion trillion centuries to guess this password based on 1000 guesses per second.
The recommendation of using a password manager is still mixed but I and others I trust recommend it as long as a very strong master password is used and you generate passwords of at least 16 characters in length. I use and recommend LastPass, it is cross platform and very easy to setup and use.


Leave a Reply