In my last column, I wrote about a recent study conducted by Imperva. The security firm analyzed 32 million different passwords that were publicly revealed by a hacker who had cracked into the database of the Web site rockyou.com. Imperva found that most of the passwords were weak and vulnerable and would have been easy to decipher using brute force password-cracking software.
The study was significant in that it shed a light on a growing problem. As we access an increasing array of network logins, Web sites, and other accounts, maintaining strong passwords for each becomes more and more difficult. Imperva and other security experts offer advice to help protect your accounts. Use complex passwords, e.g, ones with a minimum length and special characters. Don't use the same password for multiple accounts. Use passphrases instead of passwords. Write down clues to your passwords on paper and them them in your wallet.
These suggestions are all well and good. But most people simply won't follow them. We can juggle only so many different things in our brain before we start to forget them. And most of us are usually so busy in our typical workday that we're not going to spend extra time maintaining good passwords. Telling people to choose strong passwords, to use a different password for each site, and to remember to write down password clues is advice that will go in one ear and out the other.
IT admins also face challenges on the job. To protect your users and your network, you should be enforcing a strong password policy, which demands passwords of a minimum length and complexity and requires users to change their passwords periodically. But I know from my days in IT that users always griped about these policies and would struggle to work around them. One popular strategy was to use a password like 'Password#1' and then, when required, simply change it to 'Password#2' and then 'Password#3' and so on.
Another problem with corporate password policies is that they typically cover only domain logins. Users can set up a single sign-on password for their network and email accounts but usually not much beyond those. Passwords for other business systems, Web-based apps, and of course external Websites must be maintained and updated separately.
In short, password management is a mess out there, and it ain't getting easier. So what are users and IT admins to do?
The solution I use and the one I think works best is to use a password manager. This type of software can generate strong and complex passwords, store them for you, and send those passwords to the different accounts and Websites you access. I've used a password manager for years and now could never work without one.
You'll find a variety of password managers on the market—commercial, shareware, and freeware. There are password managers for the PC, for the Mac, and for portable devices like the iPhone (News - Alert). But the two password managers I recommend you consider are RoboForm and LastPass.
RoboForm is the one I've used for several years, so it's the product I know best. RoboForm offers a free version, which limits the number of passwords you can store, and a paid version for $30, which grants you an unlimited number of passwords.
The software is relatively simple to use. After installation, RoboForm sets itself up as a toolbar in your Web browser. You open one of your Website accounts and ask RoboForm to generate a password. The password can be any length and use any complexity. That password is then stored in your RoboForm list. The next time you need to access that Website, RoboForm can automatically fill in your username, password, and other credentials to log you in. The password is sent to the site in an encrypted format, so you're protected.
RoboForm offers a complimentary product called GoodSync, which synchronizes your passwords among multiple computers. A RoboForm To Go app is also available for USB drives, so you can use RoboForm on public or shared computers where the software is not installed.
To protect your RoboForm password list, you should set up a strong master password, which you would need to enter after you log into Windows. But remembering one good password is a lot easier than remembering dozens or potentially hundreds.
For you IT admins, RoboForm also sells an
Enterprise edition, which offers single sign-on for Websites and business applications. You can set up RoboForm for your users and administer it through centralized policies.
Since I've used RoboForm exclusively for several years, I'm not as familiar with
LastPass, but I've heard and read good things about it. Similar to RoboForm, LastPass can generate and automatically fill in usernames, strong passwords, and other credentials at the Websites you access. The basic version is free, while the premium edition costs $1 per month.
Like RoboForm, LastPass urges you to create one single master password to access your password list. You can store your passwords on a USB stick to use them on public computers and sync your passwords among multiple browsers and PCs. An
enterprise edition is also available for you IT pros on the job.
Managing passwords has never been particularly easy. But as we access more systems and sites, maintaining strong passwords becomes even more of a challenge. Good advice and password policies can only go so far. Down the road, I believe more state-of-the art technologies like fingerprint readers and even iris scanners will help alleviate this problem. But for now, if you and your users are struggling to juggle all of your passwords, I think a good password manager such as RoboForm or LastPass is your best bet.
Lance Whitney is a journalist, IT consultant, and Web Developer with almost 20 years of experience in the IT world. To read more of Lance's articles, please visit his columnist page
Edited by
Stefania Viscusi