| |
Good Passwords & Bad Passwords
No encryption algorithm will protect your data from a criminal that will acquire or be able to pick the password to your data basing on the information that she knows about you. (Remember, that the password is defined when a protected disk is created and may be changed afterwards). Bad choice or careless behavior may negate all the strong sides of StrongDisk Pro and the algorithms used.
Of course, security level is higher when you use an external key, however, the password should be good as well, providing for the case when violators get hold of your external key.
Please follow the following guidelines when choosing a password:
- It is better if the password is at least 14 characters long.
- Mix digits, lower- and upper-case letters and other characters in your password.
- Do not use words or phrases that can be guessed easily as a password. Your name as well as the names of your relatives, colleagues, friends, pets along with your date of birth, Email address, passport number and the like must be excluded.
- Do not use meaningless character sequences that can be easily guessed.
- Do not use words from the dictionary or phrases as the password. The password should be meaningless. A meaningful password is easier to guess.
- The longer the password – the better.
Let us give an example. A good password can be made from an easy-to-remember phrase by picking certain letters from it and adding some arbitrary digits and characters to it. Let us take the "Data security is vitally important" phrase and take the first and two last letters from each word. We get Dtastyiisvlyint. Next we add a couple of arbitrary symbols, and get a good password: $Dta1styiisvlyint5#.
Do not use these examples as passwords.
Bad passwords and their weak points are shown in the table.
| Password |
Weak point |
| 11111111111
ggggggg |
A sign on your monitor reading "Stay away from my files. Real McCoy" will protect your data better than these passwords. |
| 1234567890 QWERTYUIOP ABCDEFGHIJKLM |
We daresay that these passwords are not too new. Besides, the first two passwords are too short. |
| JohnSmith |
Do not use this password if your name is John Smith. Nine times out of ten the first thing a criminal will try as the password will be your name. |
| I love Wendy |
If this fact of your biography is wide-known, this password will not provide enough security. |
| Invulnerability |
The length of this password is more than 14 characters. But even if we assume that this is not your first or second name and that your incredible invulnerability is not the fact that everyone is well aware of, this is not a good password, since a determined attacker can create a program that will try all the words from a dictionary as a password. |
Even if you have chosen a very long and a completely meaningless password you have to follow some rules. Otherwise somebody else may learn this password.
- Do not write your password. Somebody may see the file or the piece of paper where you have written it (specially if it is sticked to the monitor).
- Change the passwords from time to time. Avoid using the passwords that you have used before.
- Do not use same password for two different things, like both for the mailbox and the protected disk access.
- Do not use the same password for access to all the StrongDisk Pro protected disks.
- If for some reason you have had to tell the password to one of your relatives or colleagues (for example to get the phone number that you have forgotten when going for a vacation), change it as soon as possible. What is known to two is known to everyone".
- Do not type the password when someone is watching you.
|