Skip to main content
Search

Tips to improve your password security

Date: 15 May 2023

3 minute read

While many of us are enjoying the convenience that online services bring to our lives, we have all probably struggled at some point to remember the numerous passwords we now need to manage and update.  

But it’s a minor inconvenience for the security they provide us.

To help you improve your online security, our experts in our Information Security team have shared their insight into what makes a good password, and why we should keep them up to date.

The movies might portray a hacker trying to access an account by guessing a password. In reality however, programs automate the process for criminals – allowing them to upload password breaches and dictionaries full of words into huge databases, so that these can be used in what are called ‘Brute Force’ attacks.  This is where a computer program tries millions of combinations of passwords until it gets the right one. 

When ‘simple’ passwords are used (for instance, short/alpha-only/dictionary word passwords, such as ‘holiday’ or ‘password’), it’s an easy and near instantaneous matter for even low-tech computers to crack them. It takes very little time and resource (a cybercriminal dream come true!) which means that more criminals have the ability to try this.

However, when long, complex passwords/passphrases are used it’s another matter.  It would take even an advanced ‘super’ computer thousands of years to be able to cycle through the combinations needed to crack these.

Once you have a strong password, it is tempting to use that to protect all of your accounts. However, this is not a good idea. It is a very predictable human behaviour.  Which is why, if your ‘strong’ password is cracked or leaked (and millions are, every year), automated programs will be trying it across thousands of online accounts. This makes it not only redundant, but actually increases the risk of more accounts being compromised. Passwords only remain strong for as long as they are a secret.

(TIP: check in here to make sure your passwords have not been leaked online)

While it may seem as if there are a lot of words in English (over 300,000 according to Dictionary.com), these are a standard part of a ‘dictionary attack’ program, and take very little time to work through – therefore, never use single words (Holiday, Friday, Weekend, Password etc) as a password!

Note: ‘dictionaries’ and ‘rainbow tables’ (databases of pre-populated combinations) used in attacks are also updated with prefixes/suffixes (for example, years, numbers, commonly used/substituted characters such as ! or *;@ for ‘a’, 0 for ‘o’ etc. They really do think of everything, these criminals!).

See also: Top 200 most commonly used passwords

TIP: Passphrases, not passwords! Combining a random string of words (as well as numbers, mixed cases and other characters), ensures a much stronger ‘passphrase’, and make it more likely for the owner to remember it.

For example: “candle” as a password would be considered very weak. “digitopencandlefridge” – a long, random combination of words - would be considered a strong passphrase. However, “DigiT42openCand!eFridge9” would be stronger still .

There is no value in having a password that takes a million years for a computer to crack, if it is written down for someone to see it and copy it.

Takeaways:

  • The longer the password, the longer it would take a computer to crack (this is just simple maths: for each additional character, the combinations needed increase exponentially!).
  • Complex passwords containing alphabetic, numeric and special characters (ascii characters) increase possible combinations for each character from a power of 26, to 95, drastically reducing the chances of a password cracker being successful.
  • Password managers create passwords with both length and complexity and can automatically create and populate for you – meaning you only need to create and remember one unique, complex password: for the password manager.
  • Think ‘PassPHRASE’ rather than ‘PassWORD’. Think of three or four random words as your passphrases.  These can help you remember and create what are effective and complex passwords that reduce your risk of being hacked. This guidance from NCSC is helpful for this.
  • Add multi-factor authentication wherever it is available as a second line of defence for your accounts.
  • Keep work and personal passwords separate and different, for obvious reasons.

One simple way to increase your online security now

Update your passwords to passphrases of 14 characters or more - this will disrupt most password crackers. At that length, with a good mixture of varying styles of characters, it would take years for most brute force applications to crack a password.

Password maths! An 8-character lowercase password (26x8) has a total of 208,827,064,576 possible combinations that a cracker would have to attempt, which sounds like a lot but would take a computer less than 3 hours to crack. However, if you increase that to 14 characters (26x14), it would take about 778,000 years to crack!

How long will it take to crack your password?

Length of password (chars) Only numbers Mixed lower and upper case letters Mixed numbers, lower and upper case letters Mixed numbers, lower and upper case letters, symbols
3 Instantly Instantly Instantly Instantly
4 Instantly Instantly Instantly Instantly
5 Instantly Instantly 3 secs 10 secs
6 Instantly 8 secs 3 mins 13 mins
7 Instantly 5 mins 3 hours 17 hours
8 Instantly 3 hours 10 days 57 days
9 4 secs 4 days 153 days 12 years
10 40 secs 169 days 1 year 928 years
11 6 mins 16 years 106 years 71k years
12 1 hour 600 years 6k years 5m years
13 11 hours 21k years 108k years 423m years
14 4 days 778k years 25m years 5bn years
15 46 days 28m years 1bn years 2tn years
16 1 year 1bn years 97bn years 193tn years
17 12 years 36bn years 6tn years 14qd years
18 126 years 1tn years 374tn years 1qt years

K=thousand (1000)
m=million (1,000,000)
bn=billion (1,000,000,000)
tn=trillion (1,000,000,000,000)
qd=quadrillion (1,000,000,000,000,000)
qt=quintillion (1,000,000,000,000,000,000)

Source: How Long Will It Take To Hack Your Password? – Frank on Fraud

Stay safe from scams

Your security is our priority. Read more about keeping your finances safe online.

Stay safe online