The page you were trying to view is not available for your role.
While many of us are enjoying the convenience that online services bring to our lives, we have all probably struggled at some point to remember the numerous passwords we now need to manage and update.
But it’s a minor inconvenience for the security they provide us.
To help you improve your online security, our experts in our Information Security team have shared their insight into what makes a good password, and why we should keep them up to date.
The movies might portray a hacker trying to access an account by guessing a password. In reality however, programs automate the process for criminals – allowing them to upload password breaches and dictionaries full of words into huge databases, so that these can be used in what are called ‘Brute Force’ attacks. This is where a computer program tries millions of combinations of passwords until it gets the right one.
When ‘simple’ passwords are used (for instance, short/alpha-only/dictionary word passwords, such as ‘holiday’ or ‘password’), it’s an easy and near instantaneous matter for even low-tech computers to crack them. It takes very little time and resource (a cybercriminal dream come true!) which means that more criminals have the ability to try this.
However, when long, complex passwords/passphrases are used it’s another matter. It would take even an advanced ‘super’ computer thousands of years to be able to cycle through the combinations needed to crack these.
Once you have a strong password, it is tempting to use that to protect all of your accounts. However, this is not a good idea. It is a very predictable human behaviour. Which is why, if your ‘strong’ password is cracked or leaked (and millions are, every year), automated programs will be trying it across thousands of online accounts. This makes it not only redundant, but actually increases the risk of more accounts being compromised. Passwords only remain strong for as long as they are a secret.
(TIP: check in here to make sure your passwords have not been leaked online)
While it may seem as if there are a lot of words in English (over 300,000 according to Dictionary.com), these are a standard part of a ‘dictionary attack’ program, and take very little time to work through – therefore, never use single words (Holiday, Friday, Weekend, Password etc) as a password!
Note: ‘dictionaries’ and ‘rainbow tables’ (databases of pre-populated combinations) used in attacks are also updated with prefixes/suffixes (for example, years, numbers, commonly used/substituted characters such as ! or *;@ for ‘a’, 0 for ‘o’ etc. They really do think of everything, these criminals!).
See also: Top 200 most commonly used passwords
TIP: Passphrases, not passwords! Combining a random string of words (as well as numbers, mixed cases and other characters), ensures a much stronger ‘passphrase’, and make it more likely for the owner to remember it.
For example: “candle” as a password would be considered very weak. “digitopencandlefridge” – a long, random combination of words - would be considered a strong passphrase. However, “DigiT42openCand!eFridge9” would be stronger still .
There is no value in having a password that takes a million years for a computer to crack, if it is written down for someone to see it and copy it.
Takeaways:
- The longer the password, the longer it would take a computer to crack (this is just simple maths: for each additional character, the combinations needed increase exponentially!).
- Complex passwords containing alphabetic, numeric and special characters (ascii characters) increase possible combinations for each character from a power of 26, to 95, drastically reducing the chances of a password cracker being successful.
- Password managers create passwords with both length and complexity and can automatically create and populate for you – meaning you only need to create and remember one unique, complex password: for the password manager.
- Think ‘PassPHRASE’ rather than ‘PassWORD’. Think of three or four random words as your passphrases. These can help you remember and create what are effective and complex passwords that reduce your risk of being hacked. This guidance from NCSC is helpful for this.
- Add multi-factor authentication wherever it is available as a second line of defence for your accounts.
- Keep work and personal passwords separate and different, for obvious reasons.
One simple way to increase your online security now
Update your passwords to passphrases of 14 characters or more - this will disrupt most password crackers. At that length, with a good mixture of varying styles of characters, it would take years for most brute force applications to crack a password.
How long will it take to crack your password?
| Length of password (chars) | Only numbers | Mixed lower and upper case letters | Mixed numbers, lower and upper case letters | Mixed numbers, lower and upper case letters, symbols |
| 3 | Instantly | Instantly | Instantly | Instantly |
| 4 | Instantly | Instantly | Instantly | Instantly |
| 5 | Instantly | Instantly | 3 secs | 10 secs |
| 6 | Instantly | 8 secs | 3 mins | 13 mins |
| 7 | Instantly | 5 mins | 3 hours | 17 hours |
| 8 | Instantly | 3 hours | 10 days | 57 days |
| 9 | 4 secs | 4 days | 153 days | 12 years |
| 10 | 40 secs | 169 days | 1 year | 928 years |
| 11 | 6 mins | 16 years | 106 years | 71k years |
| 12 | 1 hour | 600 years | 6k years | 5m years |
| 13 | 11 hours | 21k years | 108k years | 423m years |
| 14 | 4 days | 778k years | 25m years | 5bn years |
| 15 | 46 days | 28m years | 1bn years | 2tn years |
| 16 | 1 year | 1bn years | 97bn years | 193tn years |
| 17 | 12 years | 36bn years | 6tn years | 14qd years |
| 18 | 126 years | 1tn years | 374tn years | 1qt years |
K=thousand (1000)
m=million (1,000,000)
bn=billion (1,000,000,000)
tn=trillion (1,000,000,000,000)
qd=quadrillion (1,000,000,000,000,000)
qt=quintillion (1,000,000,000,000,000,000)
Source: How Long Will It Take To Hack Your Password? – Frank on Fraud
Stay safe from scams
Your security is our priority. Read more about keeping your finances safe online.