Showing posts with label Passwords. Show all posts
Showing posts with label Passwords. Show all posts

Passwords Don't Have to Threaten Business Security


The emergence of the World Wide Web as a global, around the clock marketplace has opened a multitude of new opportunities to businesses which have never before been seen. Computers and global communication networks have brought vendors, customers and markets together in new and beneficial ways. Along with all of the benefits which business has gained from the information age come some downsides. New crimes have not been created by new technology, but rather new technology has given new tools to criminals to commit the same crimes as they always have. The difference is that criminals now have a global reach, just as businesses do. In the U.S. at least, the responsibility for protecting consumers from having their personal information pilfered is placed upon businesses.

While some will blame the computer itself for crimes involving identity theft, it is usually not the computer but rather the way in which the victim has made use of it which is at issue. Their lack of attention to network and computer security has offered access to criminals - right into their home or business. After all, if we never lock our doors, would we blame the contractor who built our home for a burglary? In a corporate environment, it is typically employees, including IT staff who are really at fault.

About 70% of data breaches at businesses can be laid at the feet of people within the company. Employees using weak passwords or making the egregious mistake of writing down their passwords in plain view allow unscrupulous employees and others easy access to company information. Employees know that the quickest way to find a password is to sit at someone's desk; quite often, employees will tape passwords on notes on the monitor, to the desk (or underneath it) or in desk drawers, often simply labeled "passwords" or worse yet, on the desktop of their computer in an unencrypted document. Keep in mind that if a security breach happens through the use of a legitimate user name and password, it is very difficult for your IT staff to catch. Poor password management on the part of your employees can give criminals complete access to sensitive corporate data.

IT departments try to reduce the risk of data breaches through the implementation of stronger security policies. There are six basic rules of password security which they commonly use. These are:

LENGTH - Passwords should always be at least eight characters long. The longer, the better as long as you can remember your password.

RANDOMNESS - A password should be difficult to guess. Use combinations of numbers and letters; words, dates and so on.

COMPLEXITY - Employ a mix of numbers, punctuation marks and lower and uppercase letters in your passwords.

UNIQUENESS - Use a unique password for each user account.

ROTATION - Passwords should be changed every two to three months.

MANAGEMENT - Never let anyone see your password. And never, ever write it down.

The conflict which is going here is between IT departments and other employees. As IT departments make security measures more complex and difficult for employees, they use weaker security habits to increase the ease of access for themselves. Employees will nearly always forgo security for the sake of convenience.

One way to avoid this conflict is to adopt token based password management. These sorts of systems include:

Security:o PIN protected smartcards which lock data after a predetermined number of failed attempts at access.

o Passwords are never stored in computers, where hackers and snoopers can find and use them.

o Passwords can be as long as 20 characters, with all 96 possible characters on the keyboard being available to use.

o Each website, encrypted file and network can (and should) have its own unique, complex.

o Since your passwords are never typed in, a keylogger cannot record them.

o The card can be encrypted so that only the software used to manage the cards can access the data on them.

Convenience:

o The management system for these cards can handle logins for different accounts, files, applications and networks.

o The management system can launch a web browser, navigate to the appropriate login page and take care of authentication, all with a double click.

o Users never have to remember (or type)passwords.

o Users will have their passwords on them at all times.

o These cards can be carried in a wallet or even used as an employee ID badge.

o Passwords will not be written or stored where they can be found.

o Cards can store over 100 different passwords and their associated account information

o Login sites are saved to the card.

Portability:

o Passwords are available to users at any workstation once their smartcard is inserted.

o The card can be used in the office or at home or from another remote location. These sorts of smartcards are great for students and others as well.

o Smartcards are ideal for employees who work remotely but need secure access to the company network.

It takes more than just a password to make your network secure, but with the use of security tokens, passwords are no longer the weakest link in a company's security scheme. Tokens have been developed by security companies for a variety of different applications - companies can evaluate these offerings on the basis of form, usability, the amount of modifications which will be required in their infrastructure, ease of installation and of course, cost. Some smartcards offer advances security but also mean that a lot of back-end server work must be done in order to implement them. Others are easy to set up and use, but are a risk if they are lost or stolen.

Business owners are required by the Privacy Protection Act to keep customer data secure. While no one security measure can provide total security, proper password management should be part of every company's overall security strategy.




Headquartered in Ladera Ranch, California, Access Smart, LLC reduces the cost and burden of network and internet security on employees, IT administrators and business owners. Dedicated to empowering businesses and consumers to securely regain control over their digital information, Access Smart offers low cost, highly secure, integrated hardware and software packages that securely manage important data over wired and wireless networks, computers, Point-of-Sale devices, kiosks, and any other device that can accept and communicate via smartcard technology.

For more information about Access Smart, please visit http://www.Access-Smart.com.




Tips For Creating Strong and Secure Passwords


Computer hacking happens when hackers who know your password do not have to resort to technological exploits, instead they can log on and do anything that you can do on the computer or network. Keeping your password secret is one of the most important things you can do to in information security to protect your computer against security breaches.

The first step in information security is creating strong passwords that cannot be easily guessed or deduced. Tips for creating strong passwords include the following: Do not use personal information for your password. Social security numbers, driver's license numbers, phone numbers, birth dates, spouse names, and pet names are all factual information that can be found out by others.

Do not use words that are in the dictionary, including words in foreign languages. Dictionary attacks try these words and combinations of them. Do use a combination of uppercase and lowercase letters, numbers and symbols. Do not substitute numbers for letters to make words (for example, s0ph1st1cated). Hackers are aware of this trick. Do not use sample passwords that you see in security articles or books, even if they are exceptionally complex.

Generally, longer passwords are harder to crack because a brute force attack must try more combinations before finding a correct one. Windows XP allows up to 128 character passwords, although the welcome screen only displays 12 characters at the password prompt. You can switch to the classic logon screen, or just keep typing the characters after the password field appears to stop accepting them.

Do use a combination of letters, numbers, and symbols that have meaning to you so you - but no one else - will be able to easily remember the password. For example, mfcrB&G might mean EURomy favorite colors are Blue and Green to you, but to anyone else while computer hacking it looks like a random combination of characters. Do select a password that you can type quickly, to minimize the chance of someone discovering it by watching over your shoulder when you type it. However, do not use common key sequences such as qwerty.

After you create a strong password, you must keep it secure. Tips for keeping passwords secure in information security include the following: Never share your password with anyone else. Do not write your password down. This is the reason why you need to create a password that is easy for you to remember. If you disregard this advice and do write it down, keep the written copy in a locked off-site container.

Do change your password on a regular basis, even if your network policies do not require you to do so. Always change your password if you suspect it might have been compromised (for example, if someone was standing over you when you typed it). Do not use the same password for multiple purposes. For example, some people might use the same number combination for their ATM PIN, network logon password, e-mail password, and for all protected Web sites. If this password is cracked in computer hacking, all of your accounts and activities will be compromised.




Appin Knowledge Solution is an affiliate of Appin group of companies based in Austin, Texas (US) known worldwide for education and IT training and information security training.




 
Support : Creating Website | Johny Template | Mas Template
Copyright © 2011. Information Computer and Technology - All Rights Reserved
Template Modify by Creating Website
Proudly powered by Blogger