Is it time to change passwords ? New research shows how easy it is to crack some passwords, allowing attackers to gain access to personal or corporate accounts in a matter of seconds.

The new report from Dojo is quite alarming, but it also shows that some very simple tweaks can ensure that your online accounts remain secure.
See also: Passwords: Users continue to use them despite the risks
Dojo explains that passwords that are less than 8 characters long and contain only lowercase letters or numbers are easier to crack. For example, passwords like “purple,” “letmein,” or “202201” can be cracked in under a second. In comparison, a password like “wednesday1” can take over 2000 seconds to crack. So small changes can make a big difference in security.
Another common mistake people make is using the same password for their business and personal accounts. This can increase the risk of an attack on their personal data.
“With 51% of people using the same passwords for both work and personal accounts, it’s common for people to repeat password patterns that are easy to remember. But the study found that 365,174 passwords feature only lowercase letters and are an average of eight characters long,” Dojo explained.
“When you use this password pattern, hackers can easily access your data as the number of combinations they have to try is less. If you use only lowercase letters for your passwords, hackers will only need three seconds to guess them.“.
See also: KeePass v2.54 fixes the bug that leaked the cleartext master password

Also, a major mistake is using nicknames, TV shows, colors, and fashion brands. These codes are the ones that are most easily broken.
Dojo says its study found that over 1.5 million passwords were only eight characters or fewer.
Account protection
To make your accounts more secure, use 8-12 character passwords that contain a combination of uppercase and lowercase letters, numbers, and symbols.
For extra security, you can also enable MFA (multi-factor authentication), where possible, so that an additional password is required before someone can log into account .
This extra code can be sent to email or to your mobile phone via SMS. This way, even if a hacker gets your password, they won't be able to log into your account without this code.
See also: How to use Firefox Password Manager?
Additionally, you can use the Have I been Pwned (HIBP) to monitor whether your username and password have been compromised.
It is very important not to use personal information in your passwords, as information such as names, dates of birth, nicknames, pet names can be found by someone through social media and generally through your online presence.
Finally, using a password manager can also help you create unique and strong passwords.
Source: www.mirror.co.uk
