Password fatigue? Technology could help
06/27/2014 12:00 AM
06/26/2014 6:04 PM
Good thing she doesn’t need a password to get into heaven. That’s what Donna Spinner often mutters when she tries to remember the growing list of letter-number-and-symbol codes she's had to create to access her various online accounts.
“At my age, it just gets too confusing,” says the 72-year-old grandmother who lives outside Decatur, Ill.
But this is far from just a senior moment. Frustration over passwords is as common across the age brackets as the little reminder notes on which people often write them.
“We are in the midst of an era I call the ‘tyranny of the password,’ ” says Thomas Way, a computer science professor at Villanova University.
“We’re due for a revolution.”
One could argue that the revolution is already well underway, with passwords destined to go the way of the floppy disk and dial-up Internet. Already, there are multiple services that generate and store your passwords so you don't have to remember them. Beyond that, biometric technology is emerging, using thumbprints and face recognition to help us get into our accounts and our devices. Some new iPhones use the technology, for instance, as do a few retailers, whose employees log into work computers with a touch of the hand.
Still, many people cling to the password, the devil we know – even though the passwords we end up creating, the ones we CAN remember, often aren't very secure at all. Look at any list of the most common passwords making the rounds on the Internet and you'll find anything from “abc123,” “letmein” and “iloveyou” to – you guessed it – use of the word “password” as a password.
Even so, a good password doesn’t necessarily have to be maddeningly complicated, says Keith Palmgren, a cybersecurity expert in Texas.
“Whoever coined the phrase ‘complex password’ did us a disservice,” says Palmgren, an instructor at the SANS Institute, a research and education organization that focuses on high-tech security.
He’s teaching a course on passwords to other tech professionals later this summer and plans to tell them that the focus should be on unpredictability and length – the more characters, the better.
But it doesn’t have to be something you can’t remember. If a site allows long passwords and special characters, Palmgren suggests using an entire sentence as a password, including spaces and punctuation, if possible: “This sentence is an example.”
He also suggests plugging in various types of passwords on a website developed by California-based Gibson Research Corp. to see how long it could take to crack each type of password: https://www.grc.com/haystack.htm
According to the site, it could take centuries to uncover some passwords, but seconds for others.
Bill Lidinsky, director of security and forensics at the School of Applied Technology at the Illinois Institute of Technology, recommends using a “simple mental algorithm,” including those that use a space, if a site allows that. As an example, he says one might try “Ama95 zon” for an Amazon account, and “Yah95 oo” for a Yahoo! account, and so on. (But choose your own combination.)
There are other ways around the password headache.
Some people have taken to using password generators, which create and store passwords for various sites you use. Generally, all the user has to remember is a master password to unlock a generator program and then it plugs in the passwords to whichever account is being used. There are numerous password managers like this, including LastPass and Dashlane and 1Password.
Some wonder whether it’s wise to trust services like this.
“But sooner or later, you have to trust somebody,” says Palmgren, who uses a password manager himself.
Ultimately, experts say, reducing the stress of online security – and decreasing reliance on passwords – will rest on what’s known as “multifactor identification.”
Those factors are often based on three things:
1. “What you know” – a password, security question or some sort of information that only you would know (but that doesn’t have to be difficult to remember, just exclusive to you);
2. “What you have” – a phone, tablet or laptop – or even a card or token – that an online site or tech-based retail outlet would recognize as yours;
3. “What you are” – biometric information, such as face recognition or a thumb print.
Editor's Choice Videos
Join the Discussion
Charlotte Observer is pleased to provide this opportunity to share information, experiences and observations about what's in the news. Some of the comments may be reprinted elsewhere on the site or in the newspaper. We encourage lively, open debate on the issues of the day, and ask that you refrain from profanity, hate speech, personal comments and remarks that are off point. Thank you for taking the time to offer your thoughts.