[ PW-04 · Password Security ]
Password security without memorizing nonsense
The old advice was to make every password a jumble of symbols and change it every 90 days. Current NIST guidance for U.S. agencies dropped forced periodic changes and favors length over complexity. Long, unique and stored in a password manager beats short and clever.
Reuse is the real danger. When a shop or forum gets breached, attackers try the leaked email and password pairs on email, banking and shopping sites. It’s automated and cheap. If your email password shows up in that list, everything that resets through your inbox is exposed too.
This section covers how to pick and set up a password manager, how to write a passphrase you’ll remember, how to check whether your details appeared in a known breach, and the order to fix accounts in: email first, then banking, then everything with a saved card.
Small offices get their own notes on shared logins, default passwords on routers and printers, and what to do when someone leaves the business.
Coming up: the password mistakes we see most, and a beginner’s guide to switching to a password manager in an afternoon.
Briefings in Password Security
No briefings filed in this section yet. The wire below is tracking the topic until our first one lands.
Reporting from The Hacker News
- Hacked Ukrainian Sites Serve Fake Cloudflare ClickFix Lures for Psychedelic StealerThe Hacker News
- Corp MDM Spyware Targets Logistics Firms, Steals New SMS and Redirects CallsThe Hacker News
- Secrets Sprawl Is an Identity Problem That AI Just Made Impossible to IgnoreThe Hacker News
- 17,000 URLs Reveal How ClickFix Turns Trusted Websites Into Malware Traps: Report by CTM360The Hacker News
- OpenAI Agent Bypassed Australian Medicare Portal Controls to Access Non-Public FilesThe Hacker News
- TeamFiltration Campaign Compromises Seven Microsoft 365 Accounts Using Default PasswordsThe Hacker News