Stop using difficult-to-guess passwords, UKs spying agency GCHQ recommends
A painting of the government listening station GCHQ (L) is displayed at the 'A Year with MI6' exhibition at the Mount Street Gallery on February 14, 2011 in London, England (Getty Images)pThe British spying agency, found to have been conducting wholesale surveillance on UK citizens, has recommended that the public make their passwords less complex./p
pIn a brand new document called a href=https://www.gov.uk/government/uploads/system/uploads/attachment_data/file/458857/Password_guidance_-_simplifying_your_approach.pdf‘Password guidance: simplifying your approach’/a, the company gives a range of guidelines to keep consumers safe. That includes rolling back previous guidance “that complex passwords are ‘stronger’” — instead recommending that people simplify their approach./ppThe agency gives a range of hints to those working in IT as well as normal consumers./ppThose include warning people to change their default passwords, to make sure that accounts can be locked out if they’re under attack and avoid storing passwords as plain text files that can be read by anyone./ph5Read morebra href=http://www.independent.co.uk/life-style/gadgets-and-tech/news/gchq-spying-on-british-citizens-was-unlawful-secret-court-rules-in-shock-decision-10028306.htmlGCHQ spying on British citizens was unlawful, secret court rules in shock decision/abra href=http://www.independent.co.uk/life-style/gadgets-and-tech/news/privacy-watchdog-launches-did-gchq-spy-on-you-campaign-to-allow-citizens-to-find-out-if-they-were-under-surveillance-10049284.htmlPrivacy watchdog launches Did GCHQ spy on you? campaign/abra href=http://www.independent.co.uk/life-style/gadgets-and-tech/news/uk-government-rewrites-surveillance-law-to-get-away-with-hacking-and-allow-cyber-attacks-campaigners-claim-10253485.htmlUK government rewrites surveillance law to get away with hacking and allow cyber attacks/a/h5pThe agency also warns against the problems of “password overload”. That is what happens when people create too many complex and unmemorable passwords, which leads them to write them down or re-use them and so become unsafe./ppThose complicated passwords are often the result of organisations imposing rules about the complexity of passwords — requiring that they are a certain length, for instance, or include special characters. But instead companies should just create more security rules, so that people can use their own, more simple passwords./ppThose simple passwords might be made up of just three simple words, for instance. Or users could sign up for password managers — software that generates and then stores the passwords so that are both complex and never have to be remembered./pp
a class=escenic-gallery href=http://www.independent.co.uk/life-style/gadgets-and-tech/gadgets-and-tech-news-in-pictures-10002971.html id=10002971 Gadgets and Tech News in Pictures /a
/pp“Software password managers can help users by generating, storing and even inputting passwords when required,” the report says. “However, like any piece of security software, they are not impregnable and are an attractive target for attackers.”/ppThat second sentence might be of note to people looking to use the password —a href=http://www.independent.co.uk/life-style/gadgets-and-tech/news/gchq-and-nsa-broke-antivirus-software-so-that-they-could-spy-on-people-leaks-indicate-10338488.html GCHQ itself has been found to have been attacking security services used by British citizens, in an attempt to make it more easy to conduct its surveillance and spying operations/a./p
Sign up to read this article
Read news from 100’s of titles, curated specifically for you.