Close Menu
    Trending
    • ‘They Left Failed States, But Want To Reenact The Disaster They Fled From’ (VIDEO) * The Gateway Pundit * by Mike LaChance
    • Insider Claims Blake Lively ‘Knows Everything’ About Taylor Swift
    • ICC prosecutor Karim Khan removed over ‘serious misconduct’
    • ‘The show must go on’: Trump returns to rescheduled White House press gala | Donald Trump News
    • Layne Riggs dominates NASCAR Truck Series race at IRP
    • Why Wall Street Trusts Some CEOs and Doubts Others With the Same Balance Sheet
    • SpaceX launches Starship on successful test flight
    • Warning shot or publicity stunt – how worried should we be about the OpenAI hack?
    Benjamin Franklin Institute
    Saturday, July 25
    • Home
    • Politics
    • Business
    • Science
    • Technology
    • Arts & Entertainment
    • International
    Benjamin Franklin Institute
    Home»Science»The 3 things you need to know about passwords, from a security expert
    Science

    The 3 things you need to know about passwords, from a security expert

    Team_Benjamin Franklin InstituteBy Team_Benjamin Franklin InstituteMarch 13, 2026No Comments5 Mins Read
    Share Facebook Twitter Pinterest Copy Link LinkedIn Tumblr Email VKontakte Telegram
    Share
    Facebook Twitter Pinterest Email Copy Link


    Passwords are both a curse and a blessing

    tete_escape/Shutterstock

    Passwords occupy an odd place in our lives. They’re both a blessing – keeping our data and information safe from anyone intruding into our IT systems and accessing them – and a curse, in that they’re often difficult to manage and tricky to remember. Cybersecurity expert Jake Moore at ESET, a European cybersecurity firm, is here with three tips to help you rethink your relationship with passwords – and hopefully keep hackers at bay.

    1. Use a password manager, even if it feels counterintuitive

    I’m a big fan of password managers, and I think they’re wildly underused. Depending on where you are in the world, and who’s doing the study, only around one-third of people use password managers. That to me seems a criminally low number. They’re a gamechanger. They give you the ability to create long passwords for your account and to store them securely. They’re so good at generating the passwords for you, you don’t have to think of one.

    That’s important because we know that when people are asked to come up with their own passwords, they tend to rely on things or words they know – all of which could be information a hacker or bad actor could have on you, and could make you vulnerable. They also nullify another big risk, which is people reusing passwords across accounts. If a password is used by someone else, even just one person, and that person’s account is breached, it can end up in the tables of vulnerable passwords that are used to try and probe and test getting access to accounts.

    I sometimes wonder why people don’t use password managers more. It might be that they misunderstand how password managers work, thinking that storing passwords online somewhere that can be unlocked with a single password is insecure. But it’s not. The vault in which the passwords are stored isn’t just a simple list of passwords sitting on a server: your data is encrypted on your device with a strong key derived from your master password, and what’s stored online is the scrambled cipher text, which even the password manager provider can’t read without that key.

    2. Multi-factor authentication is an absolute must

    Even with the strongest password in the world – and national cybersecurity agencies recommend that a combination of between 14 and 16 different characters is enough to dissuade drive-by attacks – it’s still possible to fall victim to hackers. Multi-factor authentication (MFA) adds a layer of friction for hackers to make sure that any login you make is approved by you, the user.

    It’s an extra layer of security, such as a code to your phone. It can be done via SMS text message, but that’s not as a secure as the other levels. Authenticator apps are to me a wonderful next level in MFA, and it’s a shame people aren’t forced to use it. If we think about Instagram, for example, they only inform once you hit 10,000 followers about the need to use MFA. It’s as if they’re thinking, ‘Well, if we enforce it at 10,000 followers, they’re going to do it because they don’t want to lose their 10,000 followers. But if we enforce them to do that at signup, when they have zero followers, they might get bogged down by it and not open an account.’ That to me is absurd.

    We shouldn’t be putting people’s ease of use ahead of security, and until we enforce it, we will still see people frantically worried about their social media accounts or any of their accounts being compromised. So turn on MFA wherever it is offered.

    3. Where you can, avoid passwords entirely

    Passwords are far from perfect – and handily, there’s a more modern, secure alternative that’s being adopted with increasing pace. We’re moving towards a passwordless society, and that’s a move in the right direction.

    This alternative is passkeys, and the beauty of them is they remove a lot of the human error from the equation. Instead of typing in a password, you sign in using your device or a secure key stored on your phone, often with a fingerprint. Behind the scenes, cryptographic keys do the hard work, but the user doesn’t see that – it stays simple. The simplicity is why they’re such a gamechanger: they take away the temptation to reuse an old password or add a predictable number on the end of something familiar.

    In some ways, they’re too easy. When I talk to people they’re suspicious of passkeys because they seem too simple. If it feels simple for them, they assume it must be simple for a criminal too. But that’s not how it works – the tech behind the scenes is working far harder than you need to.

    Passkeys aren’t yet available everywhere, and there are still pain points, especially if you lose a device. But overall, passkeys are a major step forward because they remove one of the oldest and weakest links in security – the password itself.

    As told to Chris Stokel-Walker

    Topics:



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Telegram Copy Link

    Related Posts

    Science

    SpaceX launches Starship on successful test flight

    July 25, 2026
    Science

    NHTSA considers new car door safety rules after fatal Tesla crashes

    July 24, 2026
    Science

    Fungus made fashion—researchers turn living organisms into textiles

    July 24, 2026
    Science

    How a 99-year-old mathematician unraveled a century-old braid mystery

    July 24, 2026
    Science

    Is it possible to regain a sense of smell? These scientists are working on it

    July 24, 2026
    Science

    Why don’t insects live in the ocean?

    July 24, 2026
    Editors Picks

    Belgrade Halts Arms Exports After Russia Says Serbian Weapons Went to Ukraine

    July 2, 2025

    USAFacts’ new campaign is showing voters that data rules everything around them

    June 9, 2026

    EU Officially Votes To Ban Russian Gas

    January 27, 2026

    PK Kemsley Reveals Dorit’s Lavish Spending

    May 7, 2026

    Opinion | S the Wolf

    June 4, 2026
    About Us
    About Us

    Welcome to Benjamin Franklin Institute, your premier destination for insightful, engaging, and diverse Political News and Opinions.

    The Benjamin Franklin Institute supports free speech, the U.S. Constitution and political candidates and organizations that promote and protect both of these important features of the American Experiment.

    We are passionate about delivering high-quality, accurate, and engaging content that resonates with our readers. Sign up for our text alerts and email newsletter to stay informed.

    Latest Posts

    ‘They Left Failed States, But Want To Reenact The Disaster They Fled From’ (VIDEO) * The Gateway Pundit * by Mike LaChance

    July 25, 2026

    Insider Claims Blake Lively ‘Knows Everything’ About Taylor Swift

    July 25, 2026

    ICC prosecutor Karim Khan removed over ‘serious misconduct’

    July 25, 2026

    Subscribe for Updates

    Stay informed by signing up for our free news alerts.

    Paid for by the Benjamin Franklin Institute. Not authorized by any candidate or candidate’s committee.
    • Privacy Policy
    • About us
    • Contact us

    Type above and press Enter to search. Press Esc to cancel.