Uncategorized

Tech Talk: Simplicity to Complicity

By James Loomis

For those of you who didn’t hear about a recent security issue, at the end of last semester an issue with the way web sites transmitted your passwords and security information was over an open line. Which meant that anyone with the right, or wrong knowledge could use this to get your passwords. There are two ways to make this harder on these people. 1) Is to make your password a COMPLEX one and I’m not talking just This_is_my_complex_password (note the underscore would not be there), but something more like this: 10rD0fTh3r!nG$. Obviously the password could be shorter, but can anyone who is not a geek, or good with letter swapping guess what it is?

For those of you who don’t want to have to think about using a special character in place of letters or take the few seconds to make a complex password. There is a software program that I use to make complex passwords for myself, it’s called: https://lastpass.com/

This is a very secure service that was not affected by the 3year security issue. This serves will create your passwords with the complexity rules used above. The service also gives you the option for multi-layered authentication, which means you could use more than one password to access your password vault.

One of the ways you could secure your data is to add a One Time Password (OTP). The purpose of an OTP is that it only works once. So when you add an OTP on top of your credentials, if you get hacked, the hacker can only get half way into your info. All that is, is an error that the password is wrong cause they are trying to use an OTP. That’s just what it says it is only good once. As well as your real password, I hope you don’t make it simple.

The service I listed above gives you that option. One of the devices I recommend is called a yubikey, you can get one at https://store.yubico.com/lastpass The cost is a onetime fee ranging from $33.00-$70.00. The fee will include a twelve-month subscription to lastpass, and give you a yubikey for an OTP generator. The reason I would recommend this device is that it generates a 128-bit encrypted OTP at 128-bit encryption on top of another 128-bit encryption. They have recently released a key that will send a near field communication (NFC) signal. This will work with your mobile device. If you use your banks mobile banking application on your cell or tablet, then I would recommend this key for you as it encrypts your data securely.

The last trick I can recommend to you is that when you are setting up an account on a new web site. Make the password about that site, or the reason you’re on that site. Don’t forget to through in a number or two, with a few special characters as well. The key to using this method is that you all ways put your numbers in the same part of the password every time as well as the special characters you use.

Lastly, for those of you wondering what this 10rD0fTh3r!nG$ is, its lorD_of_The_rinGs. I hope this was helpful for those who needed seek securing their online information.

Categories: Uncategorized

Leave a comment