Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revisionPrevious revision
Next revision
Previous revision
security:passwords [2021/03/19 15:57] niklassecurity:passwords [2024/02/14 12:20] (current) – external edit 127.0.0.1
Line 1: Line 1:
 ====== How to secure passwords? ====== ====== How to secure passwords? ======
  
-Passwords and login methods must be secured. The following is a suggestion for how to create secure passwords for your computer and your password manager. Use the password manager for all your online passwords, as they are prone to getting hacked and you don't have to memorise a new one to replace it. The password manager will automatically generate passwords for you, one for each website. Don't use the same password twice for any website. This is particularly important for the organisation's accounts, or any account with administrative privileges to social media profiles etc.+Passwords and login methods must be secured.
  
 +**Use a password manager for all your online passwords**, as they are prone to getting hacked and you don't have to memorise a new one to replace it. The password manager will automatically generate passwords for you, one for each website.
 +
 +**Don't use the same password twice for any website.** This is particularly important for the organisation's accounts, or any account with administrative privileges to social media profiles etc.
  
 Suggested password managers: Suggested password managers:
Line 8: Line 11:
   * [[https://keepassxc.org/]]   * [[https://keepassxc.org/]]
  
 +==== Passphrase ====
 +
 +For some time now, passphrases have been recommended instead of passwords. Passphrases uses random words instead of random characters. This makes the phrase easier to remember. With four or five words, it becomes as strong as a much more difficult to remember password (see for example: [[https://protonmail.com/blog/protonmail-com-blog-password-vs-passphrase/]]). This passphrase can then be used to secure your password manager. An additional one can be used for your computer login. 
 +
 +There are multiple ways of generating passwords and passphrases. We suggest using your password manager to generate them. KeepassXC allows you to generate random passphrases, for example.
 +
 +{{:security:pasted:20210319-160823.png}}
 +
 +==== Two-Factor Authentication (2FA) ====
  
-In addition, it is worth adding two-factor authentication. This involves using an app on your phone like Google Authenticator and linking it to your phone, or using SMS where you get an SMS sent to your phone from the website in order to log in to new devices. All the major websites will offer some version of this now, but be careful when changing phones or phone numbers. +In addition, it is worth adding two-factor authentication (2FA). This involves using an app on your phone like Google Authenticator and linking it to your phone, or using SMS where you get an SMS sent to your phone from the website in order to log in to new devices. All the major websites will offer some version of this now, but be careful when changing phones or phone numbers.
  
 +Note that it is [[https://www.cnet.com/how-to/do-you-use-sms-for-two-factor-authentication-heres-why-you-shouldnt/|more secure]] to use an app than to use SMS verification, but SMS verification is much better than not using 2FA at all.