Why you can do so much better than the three-random-word rule that’s still being churned out by the NCSC

skip the three words thing, go straight for the ‘use a password manager, dammit’ jugular

Shutterstock

I’m about to so do something I’m sure won’t shock regular readers: pick an argument with the powers that be. The organisation in question, being the National Cyber Security Centre (NCSC) which, by and large, does a splendid job in both public and private sectors in matters of security advice and support. By and large, but not on one occasion recently when it decided the time was right to remind us of some password construction advice it first offered five years ago. It was wrong then and remains so to this day.

Using the perfectly reasonable hashtag of #thinkrandom, that advice was to use three random words as your password. That’s three words, not four, so you can forget about the XKCD comic suggestion of “correct, horse, battery, staple” that’s wedged itself into cyber security folklore. Not that you should use it anyway, as password reuse is obviously verboten if you want to maintain any semblance of a strong security posture.

While admitting the use of three random words is “not a password panacea”, the latest NCSC posting serves to press home the message that it’s better than using traditional password complexity advice, because the latter relies upon us memorising lots of long and complex strings. Using three random words, we are advised, creates passwords that are “strong enough for many purposes”, and helps get around the reuse problem that it says traditional complex passwords creates.

Random access memories

Let’s deal with the last of these first: password reuse. There is absolutely no bloody difference between trying to remember 97 unique complex and random password strings and doing so with 97 three random word passphrases. You will fail unless you are a memory savant. That is a fact. It’s a fact because as humans we are simply not wired to remember random things.

This brings me to the second problem I have with the advice: the reality of randomness. Most people, most of the time, will choose three words that are far from random when constructing a whole bunch of passphrases. What people will do is, totally subconsciously, adopt patterns in the phrases they come up with. Patterns in both the connections between the words used to make recall easier and patterns between the passphrases themselves to make multiple ones easier to recall.

Humans just don’t do randomness well; that’s why there are computer-me-bobs for creating truly random stuff, and more on that later. There’s a really interesting piece of research from the University of Cambridge Computer Laboratory, admittedly now almost a decade old but still relevant, that explains this very well. Its evidence on multi-word passphrases was pretty damning: “By our metrics, even five-word phrases would be highly insecure against offline attacks,” the researchers found, because people naturally sway towards speech rather than randomness. “Phrases like young man which come up often in speech are proportionately more likely to be chosen than rare phrases like young table” the research concluded. Which is exactly what I would expect.

There’s an app for that

Look, I perfectly understand plenty of security professionals disagree with me here. Their argument generally being along the same lines as the NCSC, that adopting a three random words approach will create stronger passwords than those we often see being used and reused today. This is true, and I’m not suggesting that Password, or P@ssw0rd, or even P@ssw0rd1 is a super-duper credential to be using. What I am suggesting is that, rather than getting people to use three supposedly random words, it would be far better to advise them to use some form of secure password manager instead.

Skip the whole three words thing, don’t mention it at all, go straight for the “use a password manager dammit” jugular. That way you can create truly random and complex and extremely long passwords, or the application can, and have a unique one for every login.

Of course, the perennial problem of master password creation rears its very ugly head once more. Rather than go over old ground involving muscle memory, encrypted USB sticks (which need yet another password) or a biometric device (JEMpass) and even dice with multiple patterns rolled randomly into a locked box (DiceKeys), let’s approach this from the three random words angle. Or, rather, let’s not. Just three words, no matter how random, would make a spectacularly poor master password if you ask me. Instead, go for five or six, or more if your memory will allow.

These would, of course, need to be random rather than your idea of random. Which is where one password manager, in fact 1Password, comes in. Did you see what I did there? Anyway, it has a password generator that anyone can use – which has the option of generating a passphrase using random words. Just select the “memorable password” dropdown, set the number of words to something you are comfortable with, and you’re away. Other services, of course, are also available, such as Kaspersky's own password generator.

As I say, don’t go for anything too short as this is the key that unlocks all your other passwords. I’d also avoid unchecking the “full words” box as this produces gibberish words that aren’t really easier than a long password to memorise. Practise typing the result over and over to get that muscle memory working, and if you are a 1Password user, be sure to save the “emergency kit” that can be printed out and stored somewhere secure. The reality is that for 99% of use cases a threat actor isn’t going to ransack your house searching for a master password, nor your office for that matter. If you do fall into the 1% then the chances are high that you’ll already be using some kind of security protocol that makes the entire three random words argument moot anyway.

Talking of passwords in the workplace, I can’t wrap up this conversation without mentioning some more research, this time from Beyond Identity. This found that not only did nearly a quarter of employees questioned still have access to accounts from a previous job, but 41% admitted to sharing passwords in the office, and 20% used the same passwords at home as they did for work-related accounts. Just in case you wondered why I bang on about the importance of password hygiene, month after month.

Keyword: Skip the three words thing, go straight for the ‘use a password manager, dammit’ jugular

CAR'S NEWS RELATED

Best cars for a 'Love Bug' remake

Tennessee’s Yard Art The Thorndyke Special The Hot Rod The Hippie Van Jim’s Lamborghini Growing up, it’s safe to say my absolute favorite movie was Disney’s “The Love Bug.” As a kid living in a world before Pixar’s “Cars,” it was pretty much the best car movie. I loved ...

View more: Best cars for a 'Love Bug' remake

Audi timing belt tensioner prompts Utah bomb squad visit

An aftermarket timing belt tensioner found in a Salt Lake City apartment prompted a visit from the bomb squad this week after it was mistaken for a potential explosive device. Police partially evacuated the apartment complex in which it was found “out of an abundance of caution” and called ...

View more: Audi timing belt tensioner prompts Utah bomb squad visit

2023 GMC Sierra HD 2500 and 3500 will get more expensive

GMC Sierra HD pickups are about to get more expensive again after recently becoming more expensive, according to GM Authority. In July, GMC and Buick raised the prices on certain vehicles in their lineups anywhere from $975 to $1,675 by making the previously optional OnStar a standard feature. Next ...

View more: 2023 GMC Sierra HD 2500 and 3500 will get more expensive

Our week with EVs: Recapping the diverse collection of electric cars we tested

Mercedes-Benz EQB First Drive Review: Next electric Benz is a little different 2022 Chevy Bolt EV Road Test Review: Time to play EV, gas or airplane 2023 Genesis GV60 Road Test Review: The third of Hyundai Group’s E-GMP EVs is the fastest, but softest It may be hard to ...

View more: Our week with EVs: Recapping the diverse collection of electric cars we tested

Europe car sales lowest since 1996 after 12-month decline

BERLIN – Europe registered the lowest number of new passenger cars in the month of June this year since 1996 at just over 1.06 million vehicles, with some carmakers seeing sales drop by nearly 50%, data from Europe’s automobile association showed on Friday. Volkswagen Group was the hardest-hit major ...

View more: Europe car sales lowest since 1996 after 12-month decline

More Than Just A Carmaker: Toyota Motor PH Launches Toyota Mobility Solutions

Automotive industry leader, Toyota Motor Philippines Corporation (TMP) inaugurated today Toyota Mobility Solutions Philippines, Inc. (TMSPH), a wholly owned subsidiary that will be a provider of mobility-related services. TMSPH ventures into the development and offering of a range of ‘new mobility solutions’ that will enhance Toyota as a brand ...

View more: More Than Just A Carmaker: Toyota Motor PH Launches Toyota Mobility Solutions

'F1 22' feels fast and familiar | Gaming Roundup

‘F1 22’ impressions ‘Construction Simulator’ is launching Sept. 20 Autoblog may receive a share from purchases made via links on this page. Pricing and availability are subject to change. This week in racing game news: ‘F1 22’ impressions At its core, “F1 22,” the latest installment in the F1 ...

View more: 'F1 22' feels fast and familiar | Gaming Roundup

Watch a single-engine plane crash-land on 91 Freeway in California

A single-engine Piper Cherokee airplane was forced to crash land on the 91 Freeway in California after losing power about 45 minutes outside of Los Angeles. Yes, that means this was a very busy highway, practically bursting at the seams with traffic. No, amazingly nobody died, either in the ...

View more: Watch a single-engine plane crash-land on 91 Freeway in California

Ford files 'Mustang Dark Horse' trademark application

Make adventures more comfortable with high-quality Jeep grab handles

New Lucid Air variant to debut & Stealth Look to be on display during Monetary Car Week

Chevy offers incentives to prevent Corvette Z06 flipping

Average U.S. gas price falls below $4/gallon

German court: SUV driver must pay more than a car for running red light

Australian vehicle crash tests to include underwater performance

Toyota C-HR rumored to get revamp next year and an EV version

Geely's electric Zeekr 009 is an EV Alphard we never had; 700 km, 542 PS, top speed 190 km/h

A Newey, Brawn and Anderson row that shows F1 doesn’t change

Sorry, EV buyers, you won't get to pick your own pedestrian safety sounds

There won't be enough copper to meet climate goals, study indicates

OTHER CAR NEWS

; Top List in the World https://www.pinterest.com/newstopcar/pins/
Top Best Sushi Restaurants in SeoulTop Best Caribbean HoneymoonsTop Most Beautiful Islands in PeruTop Best Outdoor Grill BrandsTop Best Global Seafood RestaurantsTop Foods to Boost Your Immune SystemTop Best Foods to Fight HemorrhoidsTop Foods That Pack More Potassium Than a BananaTop Best Healthy Foods to Gain Weight FastTop Best Cosmetic Brands in the U.STop Best Destinations for Food Lovers in EuropeTop Best Foods High in Vitamin ATop Best Foods to Lower Your Blood SugarTop Best Things to Do in LouisianaTop Best Cities to Visit in New YorkTop Best Makeup Addresses In PennsylvaniaTop Reasons to Visit NorwayTop Most Beautiful Islands In The WorldTop Best Law Universities in the WorldTop Richest Sportsmen In The WorldTop Biggest Aquariums In The WorldTop Best Peruvian Restaurants In MiamiTop Best Road Trips From MiamiTop Best Places to Visit in MarylandTop Best Places to Visit in North CarolinaTop Best Electric Cars For KidsTop Best Swedish Brands in The USTop Best Skincare Brands in AmericaTop Best American Lipstick BrandsTop Michelin-starred Restaurants in MiamiTop Best Secluded Getaways From MiamiTop Best Things To Do On A Rainy Day In MiamiTop Most Instagrammable Places In MiamiTop Interesting Facts about FlorenceTop Facts About The First Roman Emperor - AugustusTop Best Japanese FoodsTop Most Beautiful Historical Sites in IsraelTop Best Places To Visit In Holy SeeTop Best Hawaiian IslandsTop Reasons to Visit PortugalTop Best Hotels In L.A. With Free Wi-FiTop Best Scenic Drives in MiamiTop Best Vegan Restaurants in BerlinTop Most Interesting Attractions In WalesTop Health Benefits of a Vegan DietTop Best Thai Restaurant in Las VegasTop Most Beautiful Forests in SwitzerlandTop Best Global Universities in GermanyTop Most Beautiful Lakes in GuyanaTop Best Things To Do in IdahoTop Things to Know Before Traveling to North MacedoniaTop Best German Sunglasses BrandsTop Highest Mountains In FranceTop Biggest Hydroelectric Plants in AmericaTop Best Spa Hotels in NYCTop The World's Scariest BridgeTop Largest Hotels In AmericaTop Most Famous Festivals in JordanTop Best European Restaurants in MunichTop Best Japanese Hiking Boot BrandsTop Best Universities in PolandTop Best Tips for Surfing the Web Safely and AnonymouslyTop Most Valuable Football Clubs in EuropeTop Highest Mountains In ColombiaTop Real-Life Characters of Texas RisingTop Best Beaches in GuatelamaTop Things About DR Congo You Should KnowTop Best Korean Reality & Variety ShowsTop Best RockstarsTop Most Beautiful Waterfalls in GermanyTop Best Fountain Pen Ink BrandsTop Best European Restaurants in ChicagoTop Best Fighter Jets in the WorldTop Best Three-Wheel MotorcyclesTop Most Beautiful Lakes in ManitobaTop Best Dive Sites in VenezuelaTop Best Websites For Art StudentsTop Best Japanese Instant Noodle BrandsTop Best Comedy Manhwa (Webtoons)Top Best Japanese Sunglasses BrandsTop Most Expensive Air Jordan SneakersTop Health Benefits of CucumberTop Famous Universities in SwedenTop Most Popular Films Starring Jo Jung-sukTop Interesting Facts about CougarsTop Best Hospitals for Hip Replacement in the USATop Most Expensive DefendersTop Health Benefits of GooseberriesTop Health Benefits of ParsnipsTop Best Foods and Drinks in LondonTop Health Benefits of Rosehip TeaTop Best Air Fryers for Low-fat CookingTop Most Asked Teacher Interview Questions with AnswersTop Best Shopping Malls in ZurichTop The Most Beautiful Botanical Gardens In L.A.Top Best Mexican Restaurants in Miami for Carb-loading rightTop Best Energy Companies in GermanyTop Best Garage HeatersTop Largest Banks in IrelandTop Leading Provider - Audit and Assurance In The USTop Best Jewelry Brands in IndiaTop Prettiest Streets in the UKTop Best Lakes to Visit in TunisiaTop Highest Mountains in Israel