Many breaches can be traced to poor password security
Many breaches can be traced to poor password security

Four passwords needed to foil hackers

Users urged to maintain different passwords for home, work, surfing and banking

Written by Steve Ranger

Every computer user should have at least four different types of password to securely access websites and work systems, according to the Computing Technology Industry Association (CompTIA).

The IT trade organisation said that human error is the primary cause of IT security breaches, and in many instances security breaches can be traced back to poor password security.

CompTIA warned that people should use multiple passwords, because if one is compromised or stolen they could become the victim of identity theft or financial loss. And if the lost password is the same one used at work, the organisation warned that "the consequences for your employer could be disastrous".

"As we have incorporated computer use into more and more of our lives at home and at work, the number of passwords we use has grown exponentially," said John Venator, president and chief executive at CompTIA.

The organisation recommends that users maintain four passwords. The first should be easy to remember for use on general websites. The same password can be used in many low-risk places because the consequences are minimal if the password is compromised.

The second password should be more complex, with a mix of numbers and letters, for e-commerce websites. But if this password is compromised, CompTIA warned, there may be financial implications, such as credit card theft.

Thirdly a "very complex" password is required for banking websites. This password should contain lower case letters, uppercase letters, numbers and punctuation marks, or at least three of these four categories. If this password is compromised, identity theft is possible.

Finally a separate password should be used only at work, which should not resemble any of the passwords used for home and personal computing.

All passwords except the easy website password should be changed at least every 90 days, the trade body advised.

Tags:

reader comments

related articles

Conference hears gloomy forecast for online fraud

Online fraud hits record levels

Total amount stolen in the US last year estimated at $1.2bn 16 Feb 2005

 

Worm uses passwords to hit MySQL

Password protection wake-up call alarms admins 08 Feb 2005

E-commerce hit hard by fear of fraud

Who's got your credit card number? 09 Dec 2004

Gone phishing

Phishing is becoming ever more prevalent and ever more dangerous 29 Nov 2004

Security

The latest wave of cyber-crimes and acts of vandalism have demonstrated once again that many systems are still vulnerable to attack. 15 Apr 2004

NHS falls victim to another data breach

Another public sector organisation loses personal details 01 Jul 2008

2007 Roundup: Data loss hits the headlines

Nationwide, Halifax, TK Maxx, HMRC and many, many more to blame 24 Dec 2007

Colombian cyber-crook jailed for nine years

Man guilty of $1.4m fraud 14 Apr 2008

today's top stories

Analysis: The true cost of printing

Organisations need to get a better sense of how much they spend on printing before finding ways to reduce it 05 Sep 2008

Computing podcast 4 September 2008

Find out what Michael Dell told Computing, and listen to our take on the latest browser wars 04 Sep 2008

Looking to the future - exclusive Michael Dell interview

Dell's chief executive talks to Computing about the way the company continues to adapt to major changes in the industry 04 Sep 2008

Interview: Delivering power where it's needed at Betfair

The online gambling firm is putting its money on grid computing and virtualisation to underpin global expansion 04 Sep 2008

E-paper displays are an open book

A display revolution is on the way - but only once the user interface issues are solved 04 Sep 2008

Most commented stories

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Would you use a mobile phone as an alternative to cash?

Would you use a mobile phone as an alternative to cash?

When mobile phones include inbuilt payment technology - would you use one instead of cash?

Previous poll results

Latest audio and video articles

BlackBerry BoldVideo

Video Review: BlackBerry Bold

Technology editor Daniel Robinson takes a hands-on look at the latest device from Research in Motion 01 Sep 2008

Podcast imageAudio

Computing podcast 4 September 2008

Find out what Michael Dell told Computing, and listen to our take on the latest browser wars 04 Sep 2008

Latest in-depth articles

A meetingAnalysis

Turning adversity into an advantage

IT chiefs under pressure to make cost cuts can turn the situation to their benefit 04 Sep 2008

CloudAnalysis

How to introduce cloud computing into your organisation

Best practice advice from Forrester Research 04 Sep 2008

Primary Navigation