Protect data – but securely
Industry 4.0: Secure passwords are essential for protecting company data online. But what should tradespeople consider to ensure their data is protected as effectively as possible?
This article is part of the special topic Digital Crafts
Germans aren't very original when it comes to choosing passwords. The top ten most commonly used passwords primarily include number sequences like "123456," "123," or easily guessed words like "hallo," "password," or "master." This is the result of a study by the Hasso Plattner Institute from December 2018 based on 500.000 login credentials. It's no wonder, then, that criminals repeatedly have an easy time: Using professional software, they simply try millions of passwords in just one second – cracking many login credentials in a very short time. Often, multiple logins are at risk at the same time, because according to a representative Bitkom survey from 2018, around 32 percent of all internet users use the same password for different services. This makes it easy for criminals to make purchases online at the victim's expense or send spam emails in their name.
More secure: complex passwords
But it doesn't have to come to that: When tradespeople use secure and unique passwords, hackers have significantly less chance of success. To make passwords less easy to crack, they should be as long and complex as possible. It goes without saying that passwords shouldn't be written down on pieces of paper or stored unencrypted on devices. Sending them unencrypted via email is also not a good idea, as hackers could intercept the login details. Passwords for your own email accounts should be especially well-protected and secure: This access usually allows you to quickly delete and create new ones for other online services.
Hackers' target: access data
Changing your passwords regularly is especially important because you never know if hackers have unknowingly breached an online service's server and stolen millions of login credentials in a matter of seconds. Criminals regularly offer such lists of usernames and passwords for sale online. Internet users can check whether their email address has been compromised on the Hasso Plattner Institute's "HPI Identity Leak Checker" website (https://sec.hpi.uni-potsdam.de/ilc).
As a precautionary measure against data theft, security experts recommend changing your passwords at least once a year. An immediate change is recommended if a password has already fallen into the wrong hands or your PC has been infected with malware that can read passwords. Updating your passwords is also recommended when purchasing new devices or apps: Sometimes there are preset default passwords, such as "0000" or "root," that are well known to criminals.
Convenient: Password manager
Photo: © Thomas BuschTo avoid forgetting the different passwords for different services, the Federal Office for Information Security (BSI) recommends the use of password managers. These serve as a kind of safe for personal passwords, which are stored encrypted. To gain access, the user only needs to remember a single master password. Synchronization is often also possible, so that your password collection is directly accessible on multiple devices, such as smartphones and tablets. A practical feature: Many password managers save the associated username and automatically fill in all fields when logging in. While many internet browsers also offer this service, many security experts have concerns: Information from browsers can often be easily read by malware. And if the device itself falls into the wrong hands, third parties can log in to all services with just a few clicks, provided your password list isn't protected with a master password.
The biggest disadvantage of password managers: If you forget your master password, you can no longer access your password collection – and have to create new login credentials for all stored services. Companies should also review the terms and conditions and privacy policies of password manager providers in advance to consider who they want to entrust with their sensitive data.
Checklist: Tips for secure passwords
Two-factor authentication: If available, you should always use two-factor authentication. This involves using a password and another method—for example, an SMS code or a TAN generator.
Password length: Always use the maximum available length of a password, then it will be harder to crack.
Character mix: Use the full range of available characters for your password, including lowercase and uppercase letters, numbers, and, ideally, special characters like "/," "&," or "?". You should only use German umlauts if you won't need to use them later on foreign keyboards, for example, while on vacation.
model: Avoid passwords with easily guessed patterns, such as "123456," "qwerty," or "aaaaaaaaaa." Also, the password should not contain any similarities to the associated username.
Mnemonic: A seemingly random sequence of characters created using a mnemonic is particularly secure. For example, "MTsiWz11/18u04/19iW" represents the sentence "My potted plants were in the conservatory during the winter between November 2018 and April 2019." Replacing some letters with special characters makes the password even harder to crack, for example, "MT$!Wz11/18&04/19@W."
Word choice: Avoid passwords containing names, dates of birth, and any words found in the Duden dictionary or in German or foreign dictionaries. As an exception and safe alternative, the Federal Office for Information Security (BSI) recommends stringing together words with illogical content. For example, "Autumnally welcome to the pot of singing vanilla spiders."
Uniqueness: Never use the same password for different services, even with easy-to-understand changes like adding a number or a special character.
changes: Change passwords for important services regularly – at least once a year.
Password manager: To manage your own passwords, we recommend using a password manager that is protected with a password that is as long, strong and unique as possible.
Text:
Thomas Busch /
handwerksblatt.de
Write a comment