Unless you've been living under a rock you have no doubt heard about the Heartbleed Bug. Basically it's a bug (a glitch) in the encryption used by many big companies such as Facebook and Dropbox. No doubt you do use some of the companies who may have been afffected or at risk. That means we all need to change our passwords once a site has given the thumbs up that they've patched the security risk.
To make your life easier, here is a link to Mashable's list of sites that have recommended user passwords be changed. It is updated daily so check it often to see if new sites have been added. If you do not live in the United States you won't find the list of banks and government sites much help.
For those you will have to visit your country's specific bank and government agency sites to see if you need to take precautions.
When you go to change your password, please create a strong password. It should be a mix of characters, numbers and letters and it should be random. Don't use your pet's name or your child's date of birth. Don't use your mother's maiden name. Don't use a recognizable sentence or phrase such as "thecheshirecat" or "thequickbrownfoxjumpedoverthelazydog" Even changing some of the letters such as a and e to characters is useless against the amazing fast tools hackers have to crack passwords.
Here's a list of the top 500 worst passwords. Make sure your password isn't on this list!
And please do not use the "trick" of creating a base password and altering it slightly for different websites. That's not a good idea even though many are touting it as a way to remember all the passwords we need to keep. Because of course you are not using the same password for every site, are you? I hope not! You must have a unique password for each site or you are at risk. If you use one password for all, and then Site A is hacked the hacker now has access to all sites you frequent.
If like me you have dozens of passwords for all the services you use, you must either use a password Manager such as Dashlane or LastPass, or you must write them down and keep them in a secure (preferably locked) spot in your home. Obviously I can't share specific secrets with you of the ways I manage or store my passwords but I can tell you that for the dozen passwords I must take with me on the road, I use a code to disguise the actual password. In other words, the password is there but the name of the site to which it refers is not noted in any way a person would understand. As well the actual password is coded so that only I know what certain letters and characters mean. Some mean I remove them from the password. Some mean I capitalize the letter. Some mean I substitute a specific character.
Yep I know, it sounds like a spy novel. But my motto is "Better Safe than Sorry". With all the hacking going on these days and with the incredibly fast ways hackers have to break passwords, I take no chances.
Don't wait. Change your passwords when each site has fixed or patched the security flaw.
Showing posts with label Passwords. Show all posts
Showing posts with label Passwords. Show all posts
April 12, 2014
March 4, 2013
Evernote Security Issue - Reset Your Password
For those who, like me, couldn't get into their Evernote account over the weekend, Evernote reset all users' passwords. The site was compromised by hackers so as a security precaution, Evernote reset passwords. To log back into your account you will need to reset your password at the Evernote site.
The company said it has seen no evidence that any customer data had been tampered with or that any payment information had been compromised.
Evernote did send emails to all their users but mine went into my SPAM folder (thanks gmail!) so I didn't realize until I tried to use my account. When you reset your password, make it a good one that will be more difficult to break when it's encrypted by Evernote. I suggest using 14 characters made up of a mix of letters and numbers and special characters.
The company said it has seen no evidence that any customer data had been tampered with or that any payment information had been compromised.
Evernote did send emails to all their users but mine went into my SPAM folder (thanks gmail!) so I didn't realize until I tried to use my account. When you reset your password, make it a good one that will be more difficult to break when it's encrypted by Evernote. I suggest using 14 characters made up of a mix of letters and numbers and special characters.
August 13, 2008
Organizing and Remembering Passwords
I've been thinking a lot about passwords. It seems more and more websites require a login (username and password) to use their facilities. Of course as genealogists many of us already belong to subscription websites like Ancestry.com
, Footnote.com, Genealogy Today and so on - all of which require a login. Google mail and other mail services need a password. Online banking is also password protected as are E-Bay and other auction sites.
We all learn pretty quickly that it is not a good idea to have one password for all our important or private areas of the internet. Instead we are urged to create separate passwords for every spot we visit. We're also urged to not record these passwords, but at the same time, told to guard them carefully and not forget them!
As my password list began to grow (and being the webmaster of over a dozen sites as well as volunteer list admin of dozens of mailing lists and message boards) just adds to that list!) I realized I had to come up with a method that would allow me quick and easy access to my safe-guarded areas.
My husband uses post-it notes. They are stuck all over his desk shelves. For me that doesn't work as it takes too long to find the one I want. Plus I don't like the clutter and the fact that anyone coming into our computer area has easy access to our "stuff".
I tried writing mine in an address book. Nope, I didn't like it as I couldn't keep the sites in alphabetical order within the letter category. I also ran out of room under one letter and had to expand into a letter that was incorrect. For someone with only a few passwords this might be a viable option but not for me
In desperation I bought Digital Personal Password Manager. It's a cool little device that you hook up to your computer. Then you teach it your fingerprint and your passwords. Whenever you go to a password protected site that you have "entered" on the device, you simply press your finger or thumb on the red pad and bingo your password is entered on the site and you are in.
At first I liked this method but I quickly began having problems. many times the fingerprint reader would not accept my finger! I had to move it, adjusting it ever so slightly, rolling it one way and another until it would take. My husband loves his, it works like a charm every time! But for me it was a dismal failure.
[Photo on left is an invented password and username, it's not the real one!] Finally last year I hit on what for me works beautifully. I use a roladex. The roladex allows me to create one card for each site. I can make changes as needed, I can change my password, record what credit card I used to buy a subscription, etc. I can buy extra roladex cards if I need more. I can insert a card so that the sites are in alphabetical order. When a card gets too full of scribbled notations, I can toss it and start a new one!
I'm the Roladex Queen now and I can't say enough about how much easier my online life is since I started using it.
We all learn pretty quickly that it is not a good idea to have one password for all our important or private areas of the internet. Instead we are urged to create separate passwords for every spot we visit. We're also urged to not record these passwords, but at the same time, told to guard them carefully and not forget them!
As my password list began to grow (and being the webmaster of over a dozen sites as well as volunteer list admin of dozens of mailing lists and message boards) just adds to that list!) I realized I had to come up with a method that would allow me quick and easy access to my safe-guarded areas.
I tried writing mine in an address book. Nope, I didn't like it as I couldn't keep the sites in alphabetical order within the letter category. I also ran out of room under one letter and had to expand into a letter that was incorrect. For someone with only a few passwords this might be a viable option but not for me
At first I liked this method but I quickly began having problems. many times the fingerprint reader would not accept my finger! I had to move it, adjusting it ever so slightly, rolling it one way and another until it would take. My husband loves his, it works like a charm every time! But for me it was a dismal failure.
I'm the Roladex Queen now and I can't say enough about how much easier my online life is since I started using it.
Subscribe to:
Posts (Atom)

