Skip to main content

What You Need to Know About Password Management and Recovery

As more and more of our everyday life is lived online, passwords are becoming more and more important. You need a password for just about everything you do online, and a lot of things you do offline, too: social media, email, banking, shopping, logging into wifi, logging into your personal computer, logging into your work computer, and even unlocking your phone, if you’ve got a passcode lock. All these things require their own password. It can all be very difficult and confusing to manage. In today’s post we’re going to give you some tips and tools for creating strong passwords, keeping track of your passwords, and what to do if you forget a password.

Good Password Practices

First things first, we’re going to talk about some tips for creating and using strong passwords. The first and most important tip is pretty simple: don’t pick something that’s easy to guess. “Password” is a lousy password. Variations on your or your family members’ names aren’t great either. Those are all things that someone with a small amount of access to your personal information could guess pretty easily.

The other major tip is to avoid reusing passwords. You may have heard the old saying that a secret isn’t a secret if two people know it. Much the same is true of passwords. You can pick an extremely secure password, but the more you use it, the greater the risk to you if it’s compromised. Data breaches happen in all sorts of ways. Maybe you sign into Facebook on a computer at the library and someone sees you typing it in, maybe you’re the victim of a phishing scam or some other sort of hacking, or maybe one of the sites where you use the password suffers a data breach. If you’ve used the same password for your bank account, your email, and your social media accounts, for example, then someone who gets it suddenly has access to a huge amount of personal information, and the ability to wreak all sorts of havoc in your digital life. If you use a different password for each account, the damage from a single compromised password is much more limited.

New Rules?

There’s been a lot of discussion over the last couple years about what good password practices are, and the best way to create a strong password. Back in 2003 the National Institute for Standards and Technology issued a document with some basic recommendations for password creation. This document - rivetingly titled “NIST Special Publication 800-63: Digital Identity Guidelines” - made recommendations for creating strong passwords. You’ve probably heard most of these guidelines: passwords should be at least 8-10 characters long, include random capitalization, numbers, and special characters. Most websites still follow these guidelines.

While NIST’s 2003 recommendations are still sound when followed properly, security experts in recent years have begun moving away from those toward a passphrase model that emphasizes password length, since longer passwords are harder for machines to crack. Under these new recommendations you should still be using capital letters, numbers, and special characters, but the focus is on choosing a 2-4 word phrase that you can easily remember, but other people and computers will have a hard time guessing, like “correcthorsebatterystaple.”

Password Managers

Following good password practices for all your accounts can be daunting, especially if, like many people nowadays, you have lots of accounts to lots of different services. Keeping track of it all safely and securely can be extremely difficult. Fortunately, there are some excellent password managers out there that can help make the job easier. Password managers will generate strong passwords for you and store them for easy access when you need them. Most password managers offer mobile applications and extensions for web browsers like Chrome and Firefox, enabling you to automatically fill in your username and password when you sign in to a website. With a password manager, all you need to remember is one master password, and the software remembers the rest for you. There are dozens of good password managers out there that you can use, but LastPass and Dashlane are generally regarded as two of the best. Both offer mobile applications, browser extensions, and both give you the choice between a feature rich free version and a reasonably priced paid version with more bells and whistles. A third popular option, 1Password, is also reasonably priced, but lacks a free version.

Recovering Lost Passwords

So, we’ve talked a lot about how to create strong passwords and keep track of your passwords, but there’s still the question of what to do with lost passwords. Unfortunately, lost passwords are one of the nearly inevitable realities of life on the internet. At some point, you’re going to forget a password. Fortunately, most websites and online services understand that, and provide you easy ways to solve this problem. As long as you signed up for a website with your email address, then recovering your password is pretty simple. On the login page for most websites, you should see a “Forgot password?” link somewhere near the box where you type your password. Typically, you just need to click that box and enter the email address you used to sign up. When you do that, the site will send you an email with a link to reset your password (in the early days of the internet, many sites would simply email you your password, but security concerns mean that nowadays passwords are typically stored in such a way that even the website owners can’t access them). Click the link in your email, enter your new password, make sure it gets added to your password manager, and you’re good to go.

Of course, all of that presumes you have access to your email in the first place. Where things get tricky is if the password you’ve lost is to your email account. Fortunately, there are ways to deal with that, too. Google, Microsoft, and Apple all have ways to give you access to your account if you’ve lost your password. As with the services we talked about above, the login screen for your email will have a link near the password box that says “Forgot password?” or something similar. Click on that, and you’ll be taken through a series of steps to help you regain access to your account. The steps will vary depending on which service you’re using and whether you’ve got two-factor authentication turned on, but they’re pretty similar. If you don’t have two-factor authentication turned on, you’ll be asked to either answer the security questions you provided when you signed up for the account, or receive a recovery email at the alternate address you provided. Answer the questions, follow the email link or, if you have two-factor authentication turned on, input the code that was sent to your phone, and you’ll be given the opportunity to reset your password. Make sure your new password gets added to your password manager, and you’ll be all set.

Google Factory Reset Protection

All that said, there’s one important thing to be aware of if you lose your Google account password. For the last few years, Android phones and tablets have included a safety feature called Factory Reset Protection (FRP). Here’s how it works: if you perform a factory reset on a device with FRP active, then as soon as the reset is complete the phone will ask for the Google account username and password that were originally used to setup the phone. Without the correct login credentials, it’s very difficult to gain access to the phone. The feature is meant to deter theft by making sure a thief can’t simply factory reset a stolen phone and then sell it. Unfortunately, it also sometimes backfires on users who find they need to reset their phone but don’t remember their Google password. So if you need to reset your phone - whether to sell it or to fix some problem you’re having with it - make sure you know your remember or recover password before you get started.

At Phone Medics Plus, we understand the headaches that come with a lost or compromised password. That’s why we’re dedicated to making sure you have the tools you need to manage your passwords effectively, and recover them when something goes wrong. As always, if you’re having trouble with a password issue, feel free to give us a call, schedule an appointment, or bring your phone or computer to our facility at 91 E. Merritt Island Causeway in Merritt Island, where our experienced technicians have the skills and the know-how to help get you solve your problems.

Comments

Popular posts from this blog

Parental Controls Part 2: Android

In our previous post we talked about the need to have a little control over what your kids do on their devices, and some of the best ways to implement that on the iPhone (and other Apple devices). Today we’re going to go over how to accomplish some of the same things on Android devices. Fair warning: the variability of Android devices on the market means that some features, settings, and options might not be available on your particular device. With that caveat in mind, here are some of the things you can do to keep your kids safe when using Android devices. System Settings While Android lacks an equivalent to the device restrictions settings on the iPhone, there are still some things you can do to control what your kids do on their phones. For one thing, any tablet running Android 4.3 or newer offers you the option of creating restricted profiles - separate user profiles for your kids that limit their access to certain apps, the Google Play store, etc. Phones running Android 5.0

- Maximizing Your Phones Battery Lifespan -

- Maximizing Your Phones Battery Lifespan-                 In today's fast-paced world, smartphones have become a lifeline for many people. Whether it's for work or personal use, we rely on our phones to stay connected with the world around us. However, one of the biggest challenges with smartphones is battery life. A dead battery can leave you stranded, unable to make calls or use apps. In this blog post, we'll explore some tips for maximizing your phone battery life. Keep the battery above 30%      Charging a lithium-ion battery to 100% capacity and keeping it at that level for prolonged periods can cause stress to the battery and accelerate its aging. (We will go into more details about this later) On the other hand, keeping the battery at a low charge level for an extended period can also damage the battery and reduce its capacity.  The optimal level of charge for a lithium-ion battery is around 80% for daily use, and it is essential to avoid letting the battery charge

Managing Android Data Usage

If you’ve spent much time as a smartphone owner, you know the feeling of using up your cell phone plan’s monthly data allowance before the month is over. It’s especially frustrating if you aren’t even sure exactly how it happened. Fortunately, at Phone Medics Plus, we’ve got some ways you can take control of your phone’s data usage and keep from going over your limit. In our last post we talked about some of the ways to do that on your iPhone . Today we’re going to talk about how to manage your Android device. Data Limits Android has a fantastically helpful feature for managing your data usage built right in. If you go into Settings, then tap Data Usage, Billing Cycle, and Data Limit and Billing Cycle, you’ll see a series of options to help keep you from going over your monthly allotment of data. You can put in the details of your cell phone plan - how much data you’re allowed per month, and when your billing cycle renews - and see how much data you’ve used in the current cycle. Y