Skip to content
HALOCK Logo

Reasonable Security847-221-0200

Incident Response Hotline: 800-925-0559

  • Services
    • Artificial Intelligence (AI) Security
      • AI Risk Assessment
      • CCPA Privacy Risk Assessment
      • Microsoft Copilot Security
    • Offensive Security (Pen Testing, Adversarial Test, Application Test)
      • Application Testing
      • Adversarial Testing
      • Penetration Testing
    • Governance and Risk Management
      • Risk Assessments
      • Governance and Risk Solutions
      • CISO & vCISO Advisory
      • CIS RAM Consulting
      • DoCRA Services
    • Security Management
      • Policy Library & Development
      • Security Awareness Training
      • Incident Response Plan Development
    • Compliance
      • PCI DSS Compliance
    • Security Engineering
      • Microsoft Copilot Security Services
      • External Attack Surface Management (EASM)
      • CIS Based Security Assessment
      • Risk Based Threat Assessment
      • Cloud Assessment Services
      • HALOCK Industry Threat HIT Index
      • Sensitive Data Scanning
      • Compromise Assessment
    • Incident Response and Forensic Services
      • Live Breach Response & Forensic Services
      • Incident Response Readiness as a Service (IRRaaS)
      • Compromise Assessment
  • Products
  • Industries
    • Communications
    • Cloud Based
    • Education
    • Energy Utilities
    • Financial Services
    • Gambling Businesses
    • Government
    • Healthcare
    • IT Cyber Security
    • Manufacturing
    • Media And Entertainment
    • Nonprofit
    • Payments
    • Retail
    • Startups
    • Supply Chain
    • Transportation
  • Resources
    • Blog – Cyber Security Articles
    • Reference Materials
    • InfoSec Tip Posters
    • Client Security Briefing
    • On-Demand Webinars
    • eNewsletters
    • HALOCK Media Room
  • About Us
    • Why HALOCK?
    • Our Team
    • Careers
    • HALOCK News
    • Events
    • HALOCK in the Press
    • Blog
  • Contact Us

emergency phone
  • Services
    • Artificial Intelligence (AI) Security
      • AI Risk Assessment
      • CCPA Privacy Risk Assessment
      • Microsoft Copilot Security
    • Offensive Security (Pen Testing, Adversarial Test, Application Test)
      • Application Testing
      • Adversarial Testing
      • Penetration Testing
    • Governance and Risk Management
      • Risk Assessments
      • Governance and Risk Solutions
      • CISO & vCISO Advisory
      • CIS RAM Consulting
      • DoCRA Services
    • Security Management
      • Policy Library & Development
      • Security Awareness Training
      • Incident Response Plan Development
    • Compliance
      • PCI DSS Compliance
    • Security Engineering
      • Microsoft Copilot Security Services
      • External Attack Surface Management (EASM)
      • CIS Based Security Assessment
      • Risk Based Threat Assessment
      • Cloud Assessment Services
      • HALOCK Industry Threat HIT Index
      • Sensitive Data Scanning
      • Compromise Assessment
    • Incident Response and Forensic Services
      • Live Breach Response & Forensic Services
      • Incident Response Readiness as a Service (IRRaaS)
      • Compromise Assessment
  • Products
  • Industries
    • Communications
    • Cloud Based
    • Education
    • Energy Utilities
    • Financial Services
    • Gambling Businesses
    • Government
    • Healthcare
    • IT Cyber Security
    • Manufacturing
    • Media And Entertainment
    • Nonprofit
    • Payments
    • Retail
    • Startups
    • Supply Chain
    • Transportation
  • Resources
    • Blog – Cyber Security Articles
    • Reference Materials
    • InfoSec Tip Posters
    • Client Security Briefing
    • On-Demand Webinars
    • eNewsletters
    • HALOCK Media Room
  • About Us
    • Why HALOCK?
    • Our Team
    • Careers
    • HALOCK News
    • Events
    • HALOCK in the Press
    • Blog
  • Contact Us

HOW TO CREATE A REALLY STRONG PASSWORD: A PEN TESTER’S PERSPECTIVE

  • View Larger Image Strong Password Reasonable Cyber Security

 

CREATE A REALLY STRONG PASSWORD: A PEN TESTER’S PERSPECTIVE.

Attackers have figured out how to crack even what you and I think are the toughest passwords.  HALOCK pen testers almost always find passwords as a weak spot in every investigation. With so much at stake, it’s a wonder why password safety still isn’t being taken seriously.

In a recent study at Concordia University in Montreal, researchers found that password strength testers are not all that accurate or consistent. Instead of relying on a password checker, follow this list of Do’s and don’ts and your passwords should be stronger.

  1. Don’t use dictionary words, or common proper nouns (cities, states, etc.) in your passwords.
  2. Don’t use common defaults (cisco, apple, password, etc).
  3. Don’t reuse similar or sequential passwords when it’s time to change. If your last password was compromised (Password1), an attacker has a pretty good idea what you changed it to. Don’t use Password2, Password3, et al.
  4. Don’t use personal details or other information an attacker could infer by checking your social media page before targeting you. Maiden names, your dog’s name, favorite food, etc. would be examples of passwords that should be avoided.
  5. Don’t try a character pattern-based password. Anything pattern-based is a common target for brute force attacks. For example, A123!A123!A123!A123!A123! might seem secure, but the pattern can carry through to the hash. Once the first five positions are cracked A123! the rest is already known and merely repeated.
  6. Don’t use simple character substitution. It might be easy to remember “I always use a zero where the password has the letter ‘O’ as in Passw0rd”. It’s easy to remember, but any password scanner or brute force tool incorporates this as well.
  7. Do use mixed case passwords. PASSword does not equal password or passWORD.
  8. Do add numbers (0-9) and special characters (!@#$%^&*) to your passwords for good measure.
  9. Do use different passwords on different websites and applications. Even the strongest password, if obtained, is a weak spot if you use the same password everywhere (websites, etc.). If any are compromised, they are all effectively compromised at that point.
  10. Do use long passwords. The longer the password is, the harder it is for a hacker’s tools to guess them. Privileged account passwords should be even longer.
  11. Do use passphrases. A generally viable approach to remembering passwords is to use a passphrase: Today, I’m writing an article about selecting good passwords! could be committed to memory as 2dayI’mWaAaSgP! This passphrase will be easy for you to remember, is long, contains letter, numbers and punctuation, and will be difficult for anyone to guess.
  12. Do use a random password vault. These generally come with random password generators and can securely store hundreds of passwords without you needing to know or remember what they are.
  13. Don’t rely solely on passwords for critical systems. Use a second factor of authentication such as RSA tools or Google Authenticator.

Do you have any other tips to share?  Feel free to tell us in the comments!
Also, be sure to download a security awareness poster that will remind you to change your password.

Strong Password Cyber Security

Time to check your security controls? Schedule a penetration test.

Enhance your security strategy to address your changing working environment and risk profile due to COVID-19. HALOCK is a trusted cyber security consulting firm, penetration testing company headquartered in Schaumburg, IL in the Chicago area servicing clients on reasonable security throughout the United States.
 
Cindy Kaplan2024-07-03T20:38:48+00:00Tags: crack, password, passwords, pen tester, Reasonable, secure passwords, security|

BLOG CATEGORIES

  • Artificial Intelligence (AI)
  • Bug Reports
  • Case Study
  • Checklists
  • Cloud Security Insights
  • Compromise Assessments
  • Cyber Insurance
  • Duty of Care Risk Assessment (DoCRA)
  • Education
  • Emerging Solutions & Trends
  • Enewsletters
  • Events
  • Exploit Insider
  • Financial
  • Gambling
  • Governance & Risk Management
  • HALOCK
  • HALOCK Breach Bulletin
  • HALOCK Helps
  • HALOCK Investigates
  • HALOCK Pandemic Breach Bulletin
  • HALOCK Radio
  • Healthcare
  • HIPAA Compliance
  • Incident Response
  • Industry Verticals
  • Infosec Industry Reports
  • ISO 27001
  • Modern Malware
  • Past Events
  • PCI Compliance
  • Penetration Testing
  • Posters
  • Primers
  • Privacy
  • Reasonable Security | Reasonable Risk
  • Regulation & Litigation
  • Retail
  • Risk Assessments
  • Securities and Exchange Commission (SEC)
  • Security Approaches & Methods
  • Security Awareness
  • Security Breach
  • Security Briefing
  • Security Briefing Solutions
  • Security Incidents
  • Security Incidents
  • Security Industry Reports
  • Security Privacy Risk
  • Security Ransomware
  • Sensitive Data
  • Standards & Frameworks
  • Templates & Tools
  • Third-Party Risk & Vendor Risk Management
  • Transportation
  • Uncategorized
  • Vulnerability Management
  • What's New & Tech
  • WorkForce

Incident Response Hotline: 800-925-0559

cybersecurity managementSubscribe to Our Newsletter

© 2025 HALOCK. All rights reserved.
Privacy Policy      Terms of Use     Site Map

blue Halock logo
1834 Walden Office Square, Suite 200
Schaumburg, IL 60173
847-221-0200
Page load link
Go to Top