---
title: Your Passwords Are Bad (and there’s probably no fool-proof solution.)
description: Some password attacks could have been prevented by the account owners using secure, randomly-generated passwords.
image: https://email.networksgroup.com/hubfs/Blogs/your%20passwords%20are%20bad.png
---

- info@networksgroup.com
- [Contact Us](https://www.networksgroup.com/contact/)

- <https://www.facebook.com/networksgroupinc/>
- <https://www.facebook.com/networksgroupinc/>
- <https://twitter.com/networksgroup>
- [mailto:info@networksgroup.com](mailto:info@networksgroup.com)

[![NetWorks Group](https://email.networksgroup.com/hubfs/Networksgroup%20August%202017/Images/NWG_Black_Logo_300-154x42.png "NetWorks Group") ![NetWorks Group](https://email.networksgroup.com/hubfs/Networksgroup%20August%202017/Images/NWG_Black_Logo_750px.png "NetWorks Group") ![NetWorks Group](https://email.networksgroup.com/hubfs/Networksgroup%20August%202017/Images/NWG_Black_Logo_1500px.png "NetWorks Group")](https://www.networksgroup.com/)

- [Home](https://www.networksgroup.com/)
- Detect & Respond 
    - [Managed Detection & Response](https://www.networksgroup.com/managed-detection-response/)
    - [Endpoint Managed Detection & Response](https://www.networksgroup.com/managed-detection-response/endpoint-mdr/)
- Ethical Hacking 
    - [Full Scope Penetration Test](https://www.networksgroup.com/full-scope-penetration-test/)
    - [Web Application Security Test](https://www.networksgroup.com/web-application-security-test/)
- Security Services 
    - [Managed Security Infrastructure](https://www.networksgroup.com/managed-security-services/)
    - [Compliance Services](https://www.networksgroup.com/pci/)
    - [Vulnerability Management](https://www.networksgroup.com/vulnerability-management/)
    - [Security Architecture Review](https://www.networksgroup.com/security-architecture-review/)
- Resources 
    - [Blog](http://blog.networksgroup.com/)
    - [Library](https://www.networksgroup.com/library/)
- Company 
    - [About](https://www.networksgroup.com/about/)
    - [Contact Us](https://www.networksgroup.com/contact/)
    - [Careers](https://www.networksgroup.com/careers/)
    - [Partners](https://www.networksgroup.com/partners/)

<https://email.networksgroup.com/your-passwords-are-bad-and-theres-probably-no-fool-proof-solution#sidr>

[![NetWorks Group](https://email.networksgroup.com/hubfs/Networksgroup%20August%202017/Images/NWG_Black_Logo_750px.png "NetWorks Group")](https://www.networksgroup.com/)

- [Home](https://www.networksgroup.com/)
- Detect & Respond 
    - [Managed Detection & Response](https://www.networksgroup.com/managed-detection-response/)
    - [Endpoint Managed Detection & Response](https://www.networksgroup.com/managed-detection-response/endpoint-mdr/)
- Ethical Hacking 
    - [Full Scope Penetration Test](https://www.networksgroup.com/full-scope-penetration-test/)
    - [Web Application Security Test](https://www.networksgroup.com/web-application-security-test/)
- Security Services 
    - [Managed Security Infrastructure](https://www.networksgroup.com/managed-security-services/)
    - [Compliance Services](https://www.networksgroup.com/pci/)
    - [Vulnerability Management](https://www.networksgroup.com/vulnerability-management/)
    - [Security Architecture Review](https://www.networksgroup.com/security-architecture-review/)
- Resources 
    - [Blog](http://blog.networksgroup.com/)
    - [Library](https://www.networksgroup.com/library/)
- Company 
    - [About](https://www.networksgroup.com/about/)
    - [Contact Us](https://www.networksgroup.com/contact/)
    - [Careers](https://www.networksgroup.com/careers/)
    - [Partners](https://www.networksgroup.com/partners/)

# NetWorks Group Blog

# Your Passwords Are Bad (and there’s probably no fool-proof solution.)

Posted by [Aaron Pohl](https://email.networksgroup.com/author/aaron-pohl) on Aug 3, 2016 11:21:00 AM

![](https://email.networksgroup.com/hubfs/Portraits/Aaron.png)

- [Tweet](https://twitter.com/share)

Adobe, MySpace, LinkedIn, and many other large organizations have had major password breaches in the last few years. Breaches where attackers have exfiltrated usernames, email addresses, passwords, and in some cases, plaintext password hints and other data from the company’s database. The initial response is always, "Log into ***that service***, and change your password before the hackers get in and take over ***that account***!" The sad truth is that it’s rarely ***that account*** that matters – it’s the ***other*** ***accounts*** where you (or your users) used the same password and email address that you’re (or they’re) already using on the compromised account with another service.

In the last few weeks, there have been several ([https://techcrunch.com/2016/06/29/hacker-takes-over-oculus-ceos-twitter-...](https://techcrunch.com/2016/06/29/hacker-takes-over-oculus-ceos-twitter-account-announces-new-ceo/)) high-profile ([http://arstechnica.com/security/2016/06/mark-zuckerberg-twitter-pinteres...](http://arstechnica.com/security/2016/06/mark-zuckerberg-twitter-pinterest-hacked/)) attacks ([http://fortune.com/2016/06/27/google-ceo-sundar-pichai/](http://fortune.com/2016/06/27/google-ceo-sundar-pichai/)) where the CEO of a large company had their Twitter account hacked because they were using the same password for Twitter as they had been using on another service that was compromised.

![your passwords are bad.png](https://email.networksgroup.com/hs-fs/hubfs/Blogs/your%20passwords%20are%20bad.png?width=711&height=533&name=your%20passwords%20are%20bad.png)

These attacks all could have been prevented by the account owners using secure, randomly-generated passwords. The problem is that our brains aren’t so good at remembering random strings of characters without meaning or purpose associated with them, and the last thing any of us want is to lose access to any of our accounts simply because we can’t remember our passwords, so many users tend towards ease of access over absolute security. The idea that I want to try to present to you is to completely forget the ***word*** “password” -- Strike it from your memory as though it had never been -- and replace it with the word “pass***phrase***.”

Remember back to elementary school math? I know it’s really fuzzy for me too. Remember the *mnemonic* that they taught you to remember the order of operations? PEMDAS? Please Excuse My Dear Aunt Sally – Parenthesis, Exponents, Multiplication, Division, Addition, and Subtraction. Obviously PEMDAS would be a terrible passphrase, because it’s one that most people know. Let’s try with another example that would be likely to stand up to an offline brute-force attack:

“Mps,”Sy’gdm2d’iUd’sdtHRL”” = “My pappy said, "Son you’re gonna drive me to drinkin' If you don't stop driving that hot rod Lincoln"” -- Twenty-four characters, Upper, Lower, Numbers, and symbols. If you’re a Johnny Cash fan, you probably remember that lyric, and won’t be likely to forget it. Try not to hum the song while you’re typing it in, and you should be good to go. Not even a monster GPU-based cracking rig is likely to find that passphrase unless they’re starting with a dictionary of song lyrics, and a rule that tells them how to condense the lyrics down into that format.

Try creating a mnemonic passphrase for another phrase that has meaning in your life – a favorite song lyric, a movie quote, a bible verse – whatever works for you. Don’t use this passphrase everywhere – that would defeat the purpose. I recommend using this strong passphrase as the key to unlock a secure, encrypted password manager, such as LastPass, or KeyPassX, and then store unique, randomly-generated passwords for each service within the manager, then you personally still only have to remember a single good passphrase. You can even place an additional measure of security on this by adding two-factor authentication to your password manager, so that in addition to entering your strong passphrase, you also have to enter a 6-digit code generated within a mobile application such as Google Authenticator, or Duo Mobile. If you attach Duo to your LastPass account, you can set it up so that your phone receives a quick pop-up asking you to approve authentication to your account, so that even if someone manages to compromise your strong passphrase, if they try to log in with it, you’ll receive a notification.

 Topics: [Ethical Hacking](https://email.networksgroup.com/topic/ethical-hacking), [Information Security](https://email.networksgroup.com/topic/information-security), [Vulnerability Management](https://email.networksgroup.com/topic/vulnerability-management), [Penetration Testing](https://email.networksgroup.com/topic/penetration-testing), [Threat Management](https://email.networksgroup.com/topic/threat-management)

### Subscribe to our blog!

### Stay Informed!

### Recent Posts

### Posts by Topic

- [Information Security (50)](https://email.networksgroup.com/topic/information-security)
- [Threat Management (34)](https://email.networksgroup.com/topic/threat-management)
- [Ethical Hacking (31)](https://email.networksgroup.com/topic/ethical-hacking)
- [Managed Detection & Response (25)](https://email.networksgroup.com/topic/managed-detection-response)
- [Penetration Testing (21)](https://email.networksgroup.com/topic/penetration-testing)
- [Vulnerability Management (12)](https://email.networksgroup.com/topic/vulnerability-management)
- [Compliance (11)](https://email.networksgroup.com/topic/compliance)
- [Security Monitoring (11)](https://email.networksgroup.com/topic/security-monitoring)
- [Healthcare (9)](https://email.networksgroup.com/topic/healthcare)
- [Threat Advisory (8)](https://email.networksgroup.com/topic/threat-advisory)
- [Threat Hunting (7)](https://email.networksgroup.com/topic/threat-hunting)
- [Security Architecture Review (6)](https://email.networksgroup.com/topic/security-architecture-review)
- [HIPAA (5)](https://email.networksgroup.com/topic/hipaa)
- [Device Management (4)](https://email.networksgroup.com/topic/device-management)
- [Incident Response (4)](https://email.networksgroup.com/topic/incident-response)
- [Events (1)](https://email.networksgroup.com/topic/events)
- [PCI (1)](https://email.networksgroup.com/topic/pci)

see all

###### About Us

NetWorks Group is a Managed Detection & Response (MDR) and Ethical Hacking Service provider. We help organizations detect and respond to advanced cyber security threats through a powerful combination of our proprietary threat detection platform, expertise and security tools. Our unique approach to security not only helps you stay ahead of cyber criminals but also helps you reduce cost and increase efficiency.

###### More Links

- [Home](https://www.networksgroup.com/)
- [Blog](http://blog.networksgroup.com/)
- [About](https://www.networksgroup.com/about/)

###### Contact Us

(888) 798-1012  
 info@networksgroup.com  
 www.networksgroup.com

- <https://www.facebook.com/networksgroupinc/>
- <https://www.linkedin.com/company/networks-group>
- <https://twitter.com/networksgroup>

© 2017 - NetWorks Group