Wow... It's sound difficult to many of us, because we like to use the same password for most of our logon websites. However, this is not good for the security reasons. There are many logon websites do not have the technology to ensure your keyed password is transfer/transmitted (securely) to their server before granting your access.
Why it is important ?
Some web servers have hacked or infected with malware/virus/rootkit which may 'catch' our logon information (Email, username, password), then they can use our identity to access to other websites and to steal other information.
Many web servers do not implement the security mechanism (eg. https:// or SSL) to protect your keyed-in username & password, and to ensure those keyed information will be encrypted (locked) before sending it to their server, securely. During the transmission, somebody or any network routing devices (or servers) may steal your information.
Why do they steal our information ?
For example, with those information, they (can be human, device or server) know your online behaviours, interests, or even ...etc, they may send to us some junk emails or instant messengers. Sometimes, they can use our logon information (on our behalf, with our identify) to send fake/junk messages to all our friends in our address book.
You may read my other blog posts: About the junk messages,
Why it is important ?
Some web servers have hacked or infected with malware/virus/rootkit which may 'catch' our logon information (Email, username, password), then they can use our identity to access to other websites and to steal other information.
Many web servers do not implement the security mechanism (eg. https:// or SSL) to protect your keyed-in username & password, and to ensure those keyed information will be encrypted (locked) before sending it to their server, securely. During the transmission, somebody or any network routing devices (or servers) may steal your information.
Why do they steal our information ?
For example, with those information, they (can be human, device or server) know your online behaviours, interests, or even ...etc, they may send to us some junk emails or instant messengers. Sometimes, they can use our logon information (on our behalf, with our identify) to send fake/junk messages to all our friends in our address book.
You may read my other blog posts: About the junk messages,
http://tech.wk2u.com/2008/10/081023a.html
How to have an easy remember passwords ? Even if it is different password for different websites.
No worries, see my sample of how to generate password and yet it is still easy to remember.
How to have an easy remember passwords ? Even if it is different password for different websites.
No worries, see my sample of how to generate password and yet it is still easy to remember.
- Think of 5 characters (must have capital and small character)
- Include at least 1 number/digit
- then include additional 3 characters (which will be depended on the website that we visit)
| Logon Web address | At least 5 characters (with small & big letter) | Characters based on web address | New Password |
| https://mail.yahoo.com/ | xWorld | yah | xWorld23yah |
| https://forum.testing.com/ | xWorld | tes | xWorld23tes |
| https://www.facebook.com/ | xWorld | fac | xWorld23fac |
| https://login.live.com/ | xWorld | liv | xWorld23liv |
| https://www.friendster.com/ | xWorld | fri | xWorld23fri |
About the 3 characters that based on web address, can be picked at any characters, for example, yahoo.com, and you may choose "hoo" or "yoc"...etc, all is up to your choice.
So, you just need to remember the front portion of your password, the rest is just based on the web address.
NOTE: Even there are websites are using the security technology (SSL or https://) but there is still some issue, see my another blog post about https & fake web address.
http://tech.wk2u.com/2009/03/090301.html
Yeah! Thanks!
ReplyDelete