The Fox News hack shows once again the importance of having a strong password to protect your online identity. Here’s a short guide to how to keep or break your reputation
What can go wrong
Finding someone else’s passwords can be as complex as using using an application for a ‘brute force’ attack relying on random character sequencing or a ‘dictionary’ attack that try every word on the assumption that something will fit.
At a more basic level having your passwords compromised can be a result of something as simple as leaving your laptop on a train. If you’re using an open access PC (for example in an Internet cafe), be sure that your passwords are not stored. A quick clearing of private data can be done in two clicks.
If you are a business owner, be careful who you leave your passwords with. Disgruntled employees have been known to plant objectionable content on company websites.
We don’t know just how one of Fox News’ Twitter feeds was hacked to post false tweets about Barack Obama, but a rogue element within the company would not be out of the question.
And beware angry kids as well. According to a report in ITManagerDaily, in April 2010 an elementary school teacher found herself locked out of the school whiteboard system after an angry pupil found her password written down on a piece of paper on her desk. Unfortunately for the teaching staff it was an admninistrator password, granting the 9-year-old full access to the school system, including the ability to change other teachers’ logins. It was all fun and games until the cops were called.
While writing passwords down may not be the smartest move, so long as you don’t label them with what they relate to and keep them in a safe, secure place it won’t be an issue.
Weak passwords
According to Woopra founder John P. of onemansblog.com 20% of people use such gems as: password, 1234, letmein, money, and love. Slightly less generic are the use of partner/children’s names with or without a 0 or 1, and your favourite local sports team. The closer someone is to you, the chances are they know how to get into your inbox/e-commerce account.
According to advice from Microsoft, repeating sequences of characters (abcabc, 123123, 11111, 22222 etc.) should be avoided, and ‘dictionary words’ are a poor choice if you want to put off a dictionary attack – the only person you’re impressing is yourself.
Strong passwords
To start with, your passsword should be at least eight characters in length. Microsoft has a few simple rules for creating strong passwords, but its by no means an exhaustive list. Adding punctuation symbols and numbers will increase length and complexity; you might also take a long sentence and use the first letter of each word in it – it should look like gibberish, but easily remembered jibberish it will be.
To put it in perspective, an eight-character password comprised of seeming-random letters and numbers can take hundreds of years to crack by a brute force attack.
What to do if you get hacked
Different services have different procedures for what to do in the event of a breach. The key thing is to have a current security package running on your PC to make sure an attack didn’t leave anything lying in wait on your hard drive. Also be sure to report anything unusual straight away. Financial institutions are wise to what fraudulent transactions look like (have you spent €1 on camping gear in Lithuania lately?) and will contact you if they see anything untoward. Similarly you can query charges on PayPal – although their appeals process has been known to be difficult.
The worst case scenario is you have to wipe your PC and start all over again. This is another good reason to keep a back-up of your documents, music etc.
And always change your password as soon as possible.
Of course hacks work in the opposite direction as well. As we have learned from LulzSec, large companies can be guilty of leaving open doors for hackers to sneak in, copy their databases and publish usernames and passwords without fear of recrimination. Keep an eye on the headlines, and be ready to change your password at the first sign of trouble.







Ltd