## <center>Introduction/Summary</center><br> Most of us are struggling with keeping up with the many passwords we have to use when doing our things online. Although many recommendations are given to make unique and complex passwords for each service we use, we tend to create very simple and weak passwords and use the same one for many of the services we us. We also read and hear username and password databases being hacked more often then we like; Something that will increase even more in the future since digital crime just started. - Standards & Recommendations - Recommendation: Check Strength of Your Password - Recommendation: Check Password Breach - Recommendation: Use a Password Manager - Recommendation: Setup 2-Factor Authentication In the remainder of the post I give you most recent changes to recommendations by standardisation institutes and IT experts, suggestions for websites to assist you to check if your passwords are ever found on the internet or in databases of criminals, to check how strong your password really is, what password managers are good to use, and how best to setup 2-Factor Authentication. <center></center> ## <center>Standards & Recommendations</center><br> Maybe the recommendation and standards that were defined in 2003 by the National Institute of Standards and Technology (NIST) of the US Department of Commerce and copied as recommendations in many other countries in the world an implemented by many internet services, where to complex. Those recommendation included the replacement of characters with equivalent symbols, change of passwords every 90 days and more intensive tasks. The result: almost nobody created strong passwords. One of the founding fathers of these recommendation, IT-expert William Burr, recently told the Wall Street Journal in an interview: > "Much of what I did I now regret. It just drives people bananas and they don't pick good passwords no matter what you do." Those interested in all the details of the recommendation as adopted by NIST in 2003, page 46 to 52 of [this](http://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-63ver1.0.2.pdf) document list them all. Recently NIST adopted a re-write of the recommendation, which can be found [here](https://pages.nist.gov/800-63-3/sp800-63b.html). A lengthy and not easy to read document, therefor you may not like to look at it. Paul Grassi, senior standards and technology adviser at NIST, who led the new revision says: > "Keep passwords simple, long and memorable. Phrases, lowercase letters and typical English words work well." Experts suggests: > Special characters and a mixture of lower and uppercase letters are not required anymore. And passwords never need to expire, but the main recommendation of NIST shall be followed as mentioned before "Keep passwords simple, long and memorable". Many websites came out with their summary of recommendation but they are not all that consistent. And since the recommendations by NIST are quite vague, I can imagine you may be puzzled and doubt how a password should be crafted to be save, especially when not changing it for a long time to come. ## <center>Recommendation: Check Strength of Your Password</center><br> My recommendation is for any important website - banks, webshops where you leave your bankcard and creditcard information, social networks holding many of your private information, contact books, crypto exchanges - check the strength of the password with a service like "howsecureismypassword.net" (click [here](https://howsecureismypassword.net/)). This service is a trusted service, sponsored by one of the leading companies offering commercial password managers. ## <center>Recommendation: Check Password Breach</center><br> Another recommendation I have for you is to check if the passwords your are already using was part of a leak or hack. Many service exists on the internet that can assist you by giving them your email addresses. Although many of these services are legit, there are also services out there that are in the game of harvesting email addresses for whatever purpose. One of the most trusted service works differently. With this service, you give them your password (without username or any other information) and the service returns to you if that password was part of any of the hacked username/password databases. Navigate to this service "haveibeenpwned.com" by clicking [here](https://haveibeenpwned.com/Passwords). You can also check with them based on your email address and usernames [here](https://haveibeenpwned.com/). References for haveibeenpwned service include: - CNet ([here](https://www.cnet.com/how-to/find-out-if-your-passwords-been-hacked/)) - Toms Guide ([here](https://www.tomsguide.com/us/data-breach-pwned,news-17950.html)) - Techlicious ([here](https://www.techlicious.com/tip/how-to-check-if-your-password-has-been-stolen/)) In the Netherlands the police launched a service to provide information if your email address is found in the databases of criminals that they got into their possession. The service is in Dutch and can be found [here](https://www.politie.nl/themas/controleer-of-mijn-inloggegevens-zijn-gestolen.html). ## <center>Recommendation: Use a Password Manager</center><br> In addition I recommend to use a password manager. I personally use the open source KeePass ([here](http://keepass.info/)). Although this one is super good, it is a little more difficult to synchronise the password database with multiple devices. I use a small trusted cloud company to story the password database online and a super long, but easy to remember password (28 characters, digits and symbols in a sentence form). howsecureismypassword tells me that it takes "1 UNDECILLION YEARS to crack your password". I'm not sure how big UNDECILLION is, but I'm pretty sure this is longer than my lifetime. Therefore I'm not afraid when my online cloud storage provider gets hacked and criminals will get my password database in their hands. Another good password manager is LastPass ([here](https://www.lastpass.com/)) which gives you an easy way of synchronising across your devices. The reason I'm not using LastPass is that I cannot use my trusted cloud storage provider. ## <center>Recommendation: Setup 2-Factor Authentication</center><br> Especially in CryptoSpace, I recommend to setup 2-Factor Authentication (2FA). After your username/password process at a web service, you will receive a code through email, text message, or Apps like Google Authenticator which you subsequently type in your web browser during the login process. When your username and password get into the hands of criminals, they also need your phone to login into your account (when using text messaging or smartphone App). This makes it extremely difficult for criminals to hack your accounts online. Most service make use of Google Authenticator App, and I prefer that over text message. Email I find not save enough and do not like to use it for 2FA. ### Success with bringing more safety in your digital online presence. ### Let me know in case you have question, I may be able to give you some guidance. <br> <center> # NJOY ###### follow me [@edje](https://steemit.com/@edje) </center>
author | edje |
---|---|
permlink | howto-check-your-online-security-and-is-your-password-save-tips-and-tools-inside |
category | security |
json_metadata | {"tags":["security","hacking","steemit","writing","tutorial"],"image":["https://s12.postimg.org/xr36zd4vx/170815_advise_passwords.png"],"links":["http://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-63ver1.0.2.pdf","https://pages.nist.gov/800-63-3/sp800-63b.html","https://howsecureismypassword.net/","https://haveibeenpwned.com/Passwords","https://haveibeenpwned.com/","https://www.cnet.com/how-to/find-out-if-your-passwords-been-hacked/","https://www.tomsguide.com/us/data-breach-pwned,news-17950.html","https://www.techlicious.com/tip/how-to-check-if-your-password-has-been-stolen/","https://www.politie.nl/themas/controleer-of-mijn-inloggegevens-zijn-gestolen.html","http://keepass.info/","https://www.lastpass.com/","https://steemit.com/@edje"],"app":"steemit/0.1","format":"markdown"} |
created | 2017-08-15 15:51:27 |
last_update | 2017-08-15 17:31:09 |
depth | 0 |
children | 10 |
last_payout | 2017-08-22 15:51:27 |
cashout_time | 1969-12-31 23:59:59 |
total_payout_value | 3.087 HBD |
curator_payout_value | 0.509 HBD |
pending_payout_value | 0.000 HBD |
promoted | 0.000 HBD |
body_length | 7,318 |
author_reputation | 182,981,833,957,909 |
root_title | "HOWTO: Check YOUR Online SECURITY & Is YOUR Password SAVE (tips and tools inside)" |
beneficiaries | [] |
max_accepted_payout | 1,000,000.000 HBD |
percent_hbd | 10,000 |
post_id | 11,891,831 |
net_rshares | 1,049,382,234,361 |
author_curate_reward | "" |
voter | weight | wgt% | rshares | pct | time |
---|---|---|---|---|---|
pharesim | 0 | 229,813,788,926 | 1% | ||
raphaelom | 0 | 2,828,977,867 | 100% | ||
mammasitta | 0 | 110,120,743,991 | 25% | ||
luisucv34 | 0 | 3,220,073,721 | 21% | ||
metafzx | 0 | 589,069,635 | 100% | ||
pollux.one | 0 | 352,506,022,679 | 100% | ||
uwelang | 0 | 8,734,974,793 | 10% | ||
positivesteem | 0 | 3,762,537,277 | 10% | ||
swtcamito | 0 | 1,177,355,294 | 100% | ||
ebryans | 0 | 101,619,476,382 | 100% | ||
crypto-trail | 0 | 3,401,483,118 | 100% | ||
steemspoker | 0 | 23,108,448,230 | 100% | ||
markush | 0 | 12,513,650,191 | 30% | ||
edje | 0 | 126,103,601,732 | 100% | ||
luxurylifestyle | 0 | 4,139,010,580 | 33.9% | ||
steemcenterwiki | 0 | 6,235,534,001 | 100% | ||
dovetail | 0 | 16,719,368,522 | 100% | ||
cgame | 0 | 6,919,274,314 | 10% | ||
jaibaru | 0 | 1,019,733,302 | 100% | ||
necrophagist | 0 | 6,109,454,842 | 51% | ||
mrpomidor | 0 | 387,777,058 | 100% | ||
liberty-minded | 0 | 6,222,430,996 | 25% | ||
greengroove | 0 | 10,298,450,629 | 100% | ||
romantic4 | 0 | 986,877,633 | 100% | ||
cherishdcm | 0 | 362,475,402 | 100% | ||
simolab | 0 | 3,008,864,768 | 100% | ||
andrewlyte | 0 | 632,193,700 | 100% | ||
teks | 0 | 2,048,258,234 | 100% | ||
rezachaisar | 0 | 170,631,753 | 100% | ||
techtek | 0 | 723,256,318 | 100% | ||
massivevibration | 0 | 3,898,438,473 | 100% |
author | massivevibration |
---|---|
permlink | re-edje-howto-check-your-online-security-and-is-your-password-save-tips-and-tools-inside-20170815t161504742z |
category | security |
json_metadata | {"tags":["security"],"app":"steemit/0.1"} |
created | 2017-08-15 16:15:06 |
last_update | 2017-08-15 16:15:06 |
depth | 1 |
children | 1 |
last_payout | 2017-08-22 16:15:06 |
cashout_time | 1969-12-31 23:59:59 |
total_payout_value | 0.155 HBD |
curator_payout_value | 0.010 HBD |
pending_payout_value | 0.000 HBD |
promoted | 0.000 HBD |
body_length | 28 |
author_reputation | 3,077,666,938,555 |
root_title | "HOWTO: Check YOUR Online SECURITY & Is YOUR Password SAVE (tips and tools inside)" |
beneficiaries | [] |
max_accepted_payout | 1,000,000.000 HBD |
percent_hbd | 10,000 |
post_id | 11,894,009 |
net_rshares | 49,057,397,152 |
author_curate_reward | "" |
voter | weight | wgt% | rshares | pct | time |
---|---|---|---|---|---|
edje | 0 | 48,649,105,236 | 40% | ||
freakred | 0 | 237,965,652 | 10% | ||
cricinfo | 0 | 170,326,264 | 10% |
You are welcome!
author | edje |
---|---|
permlink | re-massivevibration-re-edje-howto-check-your-online-security-and-is-your-password-save-tips-and-tools-inside-20170815t164226151z |
category | security |
json_metadata | {"tags":["security"],"app":"steemit/0.1"} |
created | 2017-08-15 16:42:27 |
last_update | 2017-08-15 16:42:27 |
depth | 2 |
children | 0 |
last_payout | 2017-08-22 16:42:27 |
cashout_time | 1969-12-31 23:59:59 |
total_payout_value | 0.000 HBD |
curator_payout_value | 0.000 HBD |
pending_payout_value | 0.000 HBD |
promoted | 0.000 HBD |
body_length | 16 |
author_reputation | 182,981,833,957,909 |
root_title | "HOWTO: Check YOUR Online SECURITY & Is YOUR Password SAVE (tips and tools inside)" |
beneficiaries | [] |
max_accepted_payout | 1,000,000.000 HBD |
percent_hbd | 10,000 |
post_id | 11,896,518 |
net_rshares | 3,733,621,400 |
author_curate_reward | "" |
voter | weight | wgt% | rshares | pct | time |
---|---|---|---|---|---|
massivevibration | 0 | 3,733,621,400 | 100% |
Upvoted by Emma
author | romantic4 |
---|---|
permlink | re-edje-howto-check-your-online-security-and-is-your-password-save-tips-and-tools-inside-20170815t160934740z |
category | security |
json_metadata | {"tags":["security"],"app":"steemit/0.1"} |
created | 2017-08-15 16:09:45 |
last_update | 2017-08-15 16:09:45 |
depth | 1 |
children | 1 |
last_payout | 2017-08-22 16:09:45 |
cashout_time | 1969-12-31 23:59:59 |
total_payout_value | 0.000 HBD |
curator_payout_value | 0.000 HBD |
pending_payout_value | 0.000 HBD |
promoted | 0.000 HBD |
body_length | 15 |
author_reputation | 354,445,303,380 |
root_title | "HOWTO: Check YOUR Online SECURITY & Is YOUR Password SAVE (tips and tools inside)" |
beneficiaries | [] |
max_accepted_payout | 1,000,000.000 HBD |
percent_hbd | 10,000 |
post_id | 11,893,475 |
net_rshares | 0 |
Thank you @romantic4. I voted with just a small percentage of my power for your latest post; This post seems to be copy/paste from the Internet, not something that we like here at Steemit. But to give you a little incentive to create own unique posts, I gave a couple of cents in rewards on that post.
author | edje |
---|---|
permlink | re-romantic4-re-edje-howto-check-your-online-security-and-is-your-password-save-tips-and-tools-inside-20170815t161452756z |
category | security |
json_metadata | {"tags":["security"],"users":["romantic4"],"app":"steemit/0.1"} |
created | 2017-08-15 16:14:54 |
last_update | 2017-08-15 16:14:54 |
depth | 2 |
children | 0 |
last_payout | 2017-08-22 16:14:54 |
cashout_time | 1969-12-31 23:59:59 |
total_payout_value | 0.000 HBD |
curator_payout_value | 0.000 HBD |
pending_payout_value | 0.000 HBD |
promoted | 0.000 HBD |
body_length | 301 |
author_reputation | 182,981,833,957,909 |
root_title | "HOWTO: Check YOUR Online SECURITY & Is YOUR Password SAVE (tips and tools inside)" |
beneficiaries | [] |
max_accepted_payout | 1,000,000.000 HBD |
percent_hbd | 10,000 |
post_id | 11,893,996 |
net_rshares | 0 |
Very useful and with lots of information that everyone should know. I will resteem for its enormous utility for all.
author | teks |
---|---|
permlink | re-edje-howto-check-your-online-security-and-is-your-password-save-tips-and-tools-inside-20170816t141610841z |
category | security |
json_metadata | {"tags":["security"],"app":"steemit/0.1"} |
created | 2017-08-16 14:16:12 |
last_update | 2017-08-16 14:16:12 |
depth | 1 |
children | 1 |
last_payout | 2017-08-23 14:16:12 |
cashout_time | 1969-12-31 23:59:59 |
total_payout_value | 0.090 HBD |
curator_payout_value | 0.000 HBD |
pending_payout_value | 0.000 HBD |
promoted | 0.000 HBD |
body_length | 116 |
author_reputation | 4,222,158,630,123 |
root_title | "HOWTO: Check YOUR Online SECURITY & Is YOUR Password SAVE (tips and tools inside)" |
beneficiaries | [] |
max_accepted_payout | 1,000,000.000 HBD |
percent_hbd | 10,000 |
post_id | 11,989,225 |
net_rshares | 25,650,550,290 |
author_curate_reward | "" |
voter | weight | wgt% | rshares | pct | time |
---|---|---|---|---|---|
edje | 0 | 25,650,550,290 | 20% |
Thanks for the ReSteem and appreciation.
author | edje |
---|---|
permlink | re-teks-re-edje-howto-check-your-online-security-and-is-your-password-save-tips-and-tools-inside-20170816t142859636z |
category | security |
json_metadata | {"tags":["security"],"app":"steemit/0.1"} |
created | 2017-08-16 14:29:00 |
last_update | 2017-08-16 14:29:00 |
depth | 2 |
children | 0 |
last_payout | 2017-08-23 14:29:00 |
cashout_time | 1969-12-31 23:59:59 |
total_payout_value | 0.000 HBD |
curator_payout_value | 0.000 HBD |
pending_payout_value | 0.000 HBD |
promoted | 0.000 HBD |
body_length | 40 |
author_reputation | 182,981,833,957,909 |
root_title | "HOWTO: Check YOUR Online SECURITY & Is YOUR Password SAVE (tips and tools inside)" |
beneficiaries | [] |
max_accepted_payout | 1,000,000.000 HBD |
percent_hbd | 10,000 |
post_id | 11,990,532 |
net_rshares | 0 |
author | trumpman |
---|---|
permlink | re-edje-howto-check-your-online-security-and-is-your-password-save-tips-and-tools-inside-20170815t162817308z |
category | security |
json_metadata | {"tags":["security"],"app":"steemit/0.1"} |
created | 2017-08-15 16:28:18 |
last_update | 2017-08-15 16:28:18 |
depth | 1 |
children | 3 |
last_payout | 2017-08-22 16:28:18 |
cashout_time | 1969-12-31 23:59:59 |
total_payout_value | 0.020 HBD |
curator_payout_value | 0.001 HBD |
pending_payout_value | 0.000 HBD |
promoted | 0.000 HBD |
body_length | 51 |
author_reputation | 2,470,427,551,514,855 |
root_title | "HOWTO: Check YOUR Online SECURITY & Is YOUR Password SAVE (tips and tools inside)" |
beneficiaries | [] |
max_accepted_payout | 1,000,000.000 HBD |
percent_hbd | 10,000 |
post_id | 11,895,249 |
net_rshares | 6,900,698,275 |
author_curate_reward | "" |
voter | weight | wgt% | rshares | pct | time |
---|---|---|---|---|---|
edje | 0 | 6,401,198,057 | 5% | ||
papadimos | 0 | 499,500,218 | 100% |
I thought SteemStem was also technology and services. I removed the SteemStem tag.
author | edje |
---|---|
permlink | re-trumpman-re-edje-howto-check-your-online-security-and-is-your-password-save-tips-and-tools-inside-20170815t164022355z |
category | security |
json_metadata | {"tags":["security"],"app":"steemit/0.1"} |
created | 2017-08-15 16:40:21 |
last_update | 2017-08-15 17:11:27 |
depth | 2 |
children | 2 |
last_payout | 2017-08-22 16:40:21 |
cashout_time | 1969-12-31 23:59:59 |
total_payout_value | 0.000 HBD |
curator_payout_value | 0.000 HBD |
pending_payout_value | 0.000 HBD |
promoted | 0.000 HBD |
body_length | 82 |
author_reputation | 182,981,833,957,909 |
root_title | "HOWTO: Check YOUR Online SECURITY & Is YOUR Password SAVE (tips and tools inside)" |
beneficiaries | [] |
max_accepted_payout | 1,000,000.000 HBD |
percent_hbd | 10,000 |
post_id | 11,896,345 |
net_rshares | 1,589,111,296 |
author_curate_reward | "" |
voter | weight | wgt% | rshares | pct | time |
---|---|---|---|---|---|
trumpman | 0 | 1,589,111,296 | 100% |
It's ok, mistakes happen. Thanks for the understanding :)
author | trumpman |
---|---|
permlink | re-edje-re-trumpman-re-edje-howto-check-your-online-security-and-is-your-password-save-tips-and-tools-inside-20170815t173834392z |
category | security |
json_metadata | {"tags":["security"],"app":"steemit/0.1"} |
created | 2017-08-15 17:38:33 |
last_update | 2017-08-15 17:38:33 |
depth | 3 |
children | 1 |
last_payout | 2017-08-22 17:38:33 |
cashout_time | 1969-12-31 23:59:59 |
total_payout_value | 0.016 HBD |
curator_payout_value | 0.004 HBD |
pending_payout_value | 0.000 HBD |
promoted | 0.000 HBD |
body_length | 57 |
author_reputation | 2,470,427,551,514,855 |
root_title | "HOWTO: Check YOUR Online SECURITY & Is YOUR Password SAVE (tips and tools inside)" |
beneficiaries | [] |
max_accepted_payout | 1,000,000.000 HBD |
percent_hbd | 10,000 |
post_id | 11,901,486 |
net_rshares | 6,401,198,057 |
author_curate_reward | "" |
voter | weight | wgt% | rshares | pct | time |
---|---|---|---|---|---|
edje | 0 | 6,401,198,057 | 5% |