Data breaches are a dime a dozen these days. But when hackers steal databases full of customer info, login names, and passwords, the passwords aren’t usually in plain sight. Typically, the passwords will be cryptographically hashed. Hashing a password takes a string of any length (the password in this example) and produces a fixed-length hash value. Password cracking tools can be used to try and guess the password that converts into these hashes. This leads to a need for strong passwords to make the guessing process time-consuming and hopefully infeasible. I asked a friend, IT security expert Josh Kaldor, about what makes a good password, and he had quite a lot to say on the subject. Josh did research, creating hashes using various combinations of passwords with different attributes, then cracked them and compared the results against a benchmark. Here are some of his conclusions:
Common methods used to create “strong” passwords
Phrase Methods Phrases are a great way to meet password requirements for length and complexity. A common problem is that users will be apt to choose non-random (guessable/relatable) phrases or pop-culture references such as ‘The Hunger Games1,’ which are subject to obvious dictionary attacks. The words have to be non-relational.
Strong Example: SpaceTrunk!=SeaElephant
Weak Example: TheHungerGames1
Acronym Methods Using acronyms to create a password is a handy way to hamper Dictionary Attacks on your password and create a password that is hard to remember for the person who doesn’t know the acronym behind it. The issue here is that it’s hard to create a long string, and if a user adds digits to the end, it is incredibly weak (as crackers assume digits or modifiers at the start or end). Make these passwords stronger by combining them with a phrase.
Strong: Iu2w4acw3e (
I used to work 4 a company with 3 employees)
Weak: IgfHSi93 (
I graduated HS in 93)
Pattern Methods Like the acronym method, a pattern method is great for creating a seemingly illogical string that is hard to remember and will foil Dictionary Attacks. The issue in this case is people’s tendency to use similar patterns (like QWERTY), which in turn play right into the Dictionary Attack’s hands.
Strong: de3LO)Ptre
Weak: qWERTY12345
Considerations for the Auditor
PCI-DSS requirements for a strong password include the password being at least seven characters long and including uppercase, lowercase, numerical, special characters, and more. Other compliance standards require very similar sets of attributes. As an auditor, you should go above and beyond by providing recommendations like educating end users on what makes a strong password, identifying common characteristics of weak passwords, and ensuring other strong preventative controls are in place. Controls might include:- Checking for the adoption of a Clean Desk Policy and adherence to it.
- Checking for passwords being passed in support tickets or emails.
- Verify that new users must change passwords when they first log in.
- Verifying that passwords are not stored unencrypted within databases.
- Verifying that even internal systems (such as ticketing and help desk systems) utilize encrypted communications since users on the network could be packet sniffing and capture passwords that might be passed in plain text.
Christian Hyatt
Like our content? Subscribe and stay informed.
Related posts
Tags
- Access Control (3)
- Amazon (1)
- Artificial Intelligence (3)
- Assessment (1)
- Attack Surface (2)
- Attack Surface Management (3)
- Attestation (1)
- Audit (1)
- Awareness Week (3)
- AWS (2)
- Backup And Recovery (1)
- BCAW (4)
- BCMS (1)
- Blackbasta (1)
- Business (16)
- Business Continuity (6)
- Business Continuity Planning (2)
- Caas (1)
- Certification (1)
- Christian Hyatt (19)
- CI (1)
- CISO (8)
- CISO Discussions (24)
- Cloud (1)
- CMMC (1)
- Competitive (1)
- Compliance (17)
- Compliance As A Service (5)
- COVID (1)
- Cyber Risk (6)
- Cyber Risk Management (59)
- Cyber Security Law (2)
- Cybersecurity (26)
- Cybersecurity Controls (4)
- Disaster Recovery (5)
- Engineers (1)
- Ethical Hacking (1)
- EU AI Act (3)
- Exercises (1)
- GDPR (4)
- GRC Tool (6)
- Grit (1)
- Hacking (3)
- Hashcat (1)
- HITRUST (16)
- IaaS (1)
- Information Security (11)
- Internal Audit (2)
- ISO (3)
- ISO 22301 (1)
- ISO 27001 (18)
- ISO 27001 Compliance (19)
- ISO 27018 (1)
- ISO 27701 (2)
- ISO 42001 (6)
- ISO 42005 (1)
- IT Audit (9)
- IT Audit And Compliance (33)
- Kahoot (1)
- Leadership (6)
- Management (1)
- Network Security (4)
- News (5)
- News And Events (20)
- NIST 800 Series (2)
- NIST 800-171 (1)
- OSINT (1)
- Outsourced Pci (1)
- P2pe (1)
- Passwords (3)
- PCI DSS (13)
- Penetration Test (7)
- Penetration Testing (31)
- Pentest Report (1)
- Phishing (1)
- PIA (1)
- Press Release (3)
- Privacy (8)
- Privacy Compliance (7)
- Privacy Impact Assessment (1)
- Privacy Shield (1)
- Ransomeware (1)
- Regulatory Compliance (12)
- Report (2)
- Risk Assessment (5)
- Risk Management (19)
- SDLC (2)
- Security (22)
- Security Advisory (1)
- SOC 2 (18)
- SOC Reporting (23)
- Soc2 (1)
- Strategy (1)
- System Backdoor (1)
- Tabletop (1)
- Training (5)
- VCISO (7)
- Vendor Management (2)
- Vulnerability Management (2)
- Vulnerability Scan (1)
- Wannacry (1)
- Webinars (9)