How to Navigate the Password Jungle

SaaS, Technology January 17th, 2008

In a funny (scary?) case of coincidence, the password problem became got highlighted in TechMeme just weeks after I came under an attack that caused me to rethink my password strategy.  My login credentials got compromised at a Gmail account that I only use for mail-lists:  – I fixed it soon, no harm done.  Two month earlier my eBay account got hijacked, and while I was p***ed at eBay not doing anything about it, again, I could regain control, and changed all related accounts (PayPal ..etc, before suffering any consequences).

Then I started to think: what’s the point in stealing an account at a site like, let’s say photo sharing?  The hijackers really can’t benefit… or can they?  Then it hit me: I am (well, I was, until that point) just like 61% of Internet users, using the same userid/password combination on all sites.  To purpose of attacking not-so-critical sites may just be to harvest login credentials, which the bad guys then can feed to their bots to try on all sorts of financial sites.  Oops.. now I had a crisis.  Needless to say I spent the next half day researching the subject and changing my login credentials.

Now, while I am fairly opinionated, I am by no means expert on Internet security best practices, so instead of trying to dispense advice, I am opening to subject to discussion, and hope to get some real feedback.   Here are some of the options we all have:

  • Use the same, or very few userid/password combos on all sites, so we can remember them without having to write them down or physically store them in any form.  This may not have been that bad… years ago, when we all accessed less than a handful sites.  With the proliferation of Web usage, this practice has become a timebomb waiting to explode.
  • Use some variation of the basic credentials, simple enough to remember the actual “algorithm”,  i.e. some characters from the site name combined with your own “standard” keywords.  The benefit is that you use different credentials on every site (which you probably would not remember, but can re-construct every time), and still don’t need to record all the passwords. The weakness is that once the bad guys get hold of two-three sites, they can pretty much figure out your simple algorithm.
  • Use different credentials on every site, preferably strong ones.  The benefit is obvious, very secure, but it would be impossible to remember, so you would need to record them somewhere, whether on paper or electronic form, which itself is a huge security risk.
  • Use different, strong credentials, and use a “password manager” system.  There have been a number of client (PC) based solutions, or ones that code your information on a USB stick, but I don’t want to depend on anything tied to a physical location/device.   I am experimenting with Web-based solutions, but am not fully convinced.  OpenID got a huge boost today, with Yahoo adapting it.  The system I am trying out is PassPack: here’s  why Passpack’s founder thinks her solution is significantly different from OpenID.   I can tell you it’s a hell of a pain to log in to PassPack – I guess it’s supposed to be that way.  But other than the inconvenience, whether it’s Passpack, OpenID, or any online system, I am worried that if the info there ever gets compromised, it will expose everything.

With that, I’d like to turn this over to the security experts (I hope I have some amongst my readers). What do you think?  What’s the ideal Web-login policy?

Update:  How could I not think of this?   (via Web Worker Daily)

Related posts: ReadWriteWeb, The Guardian,  TechCrunch,  Jeremy Zawodny’s blog, InfoWorld,  Mark Evans, Compiler,  CyberNet, Identity Woman,  WeBreakStuff,  Mashable!, Ars Technica, and many others.

Tags: id theft, openid, passpack, password manager, password security, web indentity, web login, web passwords, web security

117614 Commentshttp://www.zoliblog.com/2008/01/17/how-to-navigate-the-password-jungle/How+to+Navigate+the+Password+Jungle2008-01-17+21%3A10%3A55Zoli+Erdos

Zoli's Blog

  • About meZoli Erdos
    Connecting the dots …
  • About
  • Archives

Categories

Apple atlassian Blogging business model CloudAve cloud computing Collaboration confluence crm Enterprise Software entrepreneurship erp facebook firefox gmail Google Humor iPhone Jotspot marketing microsoft netsuite office 2.0 On-Demand Politics SaaS salesforce.com sap smb sme Social Networking socialtext Startups techcrunch Twitter vc Funding venture Capital vista vistasucks web office wiki wikis Windows windows vista zoho

WP Cumulus Flash tag cloud by Roy Tanck and Luke Morton requires Flash Player 9 or better.

RSS CloudAve

  • Launchpad LA – More Details Revealed
  • T Shirt Friday #35 - Tweet4YourTee #2
  • Stunning Business Intelligence Visualizations… from 1830
  • Talking with David Siegel about ‘Pull’ and the Semantic Web
  • Want to Start a Technology Company in LA?
  • MYOB Goes SaaS…. Again
  • Hacker Disables Cars via the Web - Our Remote Controlled Life
  • Three Things Businesses Need to Focus on For Successful Social CRM
  • The Two-Year Lag from Web 2.0 to Enterprise 2.0
  • HubCast – Ponoko for Printing ;-)

RSS Enterprise Irregulars

  • Software Insider Index™ (SII): 2009 SII Top 35 Enterprise Business Apps Vendors™
  • Putting The “Strength of Weak Ties” to the Test
  • Men on Top
  • On Open Data, Open Source, UK Libel Law and Evidence-based Sustainability
  • Gist Acquires Startup Weekend Project Learn that Name
  • Earthquakes Show Supply Chain Risk Extends Beyond Supplier Financial Viability
  • We Are Pleased to Present… Trada!
  • Five Years of Column 2
  • Coupa Heads for the Clouds — eProcurement, T&E and Beyond (Part 2)
  • Security risks of multi-tenancy

Recent Posts

  • Hacker Disables Cars via the Web – Our Remote Controlled Life
  • The Sleek and the Geek @ SAP
  • Has SXSW Peaked?
  • Google Apps in a Box. Oh, and an iPad Killer.
  • My New Favorite Old Blog…
  • Google Launches Apps Marketplace

Recent Comments

  • Goodbye, OpenOffice, Back to MS Office? For All the Wrong Reasons. | Zoli's Blog on IDC’s Storage Paradox
  • tom on Web 2.0 in the Enterprise – Blogging the TIE Event
  • jashua on Spreadsheet Macros and Pivot Tables: Google Says No. EditGrid Says No. Zoho Just Does It.
  • rob d. rich on Comcast Digital Enhancement Off to an Analogue Start
  • Google Apps in a Box. Oh, and an iPad Killer. | CloudAve on TechCrunch in the Toilet

Add this blog to my Technorati Favorites!

Upcoming Events


More of zoli's events
design » smashing wordpress themes
  • Home
  • Sitemap
  • Contact
  • Feed