
Whether you are an individual, a student, or part of a large organization, a strong password is your first line of defense to protect your data, your privacy and your online accounts.
Although more and more users have come to realize that a strong password is a (very) good idea, too few still know how hackers are obtaining the precious Sesame! This article aims at listing the most common methods used by hackers to violate your privacy.
Hackers are like everyone else: although they have significant capacity, they remain partisans of minimum effort. In order to penetrate into a system, they systematically look for the weakest link. So first, to ensure your password will not be the weakest link, we recommend you to use our online password generator: It is fast, free, and will help you generating complex passwords in a breeze.
The ingenuity implemented by hackers in the attacks they perform has virtually no limit. Not only their techniques change frequently, but also quickly, and at a very large scale. While the simplest techniques are still in force, evildoers have developed (and are constantly developing) more sophisticated techniques to find your password.
The first tip we could give you is to frequently change it. Our online generator is here to do this for you in less than 1 second, then you have no excuse to stick with an outdated password (yes, they all become outdated until a certain time).
After having generated a strong and hard to guess password, you must be warned about the ways hackers will travel through just to steal it! Below, we have listed the main and most frequently used tactics to perpetrate credentials stealing, and the possible precautions you can apply to protect yourself against such an annoying situation.
After having read this article, you will probably wish to strengthen your security. That is probably why we would not strongly advise you enough to avoid the common mistakes listed in our article, and apply 10 quick good practices listed in our other article.
These types of attacks are the most basic, but the most common. One such attack consists in trying every imaginable combination of keys and characters, and because of the power of the actual computers, they often end up succeeding. Programs can run a brute force attack at a very high rate: it systematically checks all combinations until finding the correct one. A single computer is capable of testing over a million combinations in less than one second, and attacks are commonly performed by using hundreds of computers simultaneously to increase their chances of cracking your password in a very limited time. This can also result in blocking your computer or server, which is over-solicited during the attack duration.
Please note that "Brute-Force" attacks have a lot of harmful consequences, even if they fail to access your account: they will slow you down and even paralyze your system. To learn more about the way these attacks can poison your life and the solutions you can implement to be protected against them, be sure to read our article "The hidden risks of brute-force attacks".
The best way to protect yourself from such an attack is to use a long and complex password that uses lowercase and uppercase letters, numbers and punctuation marks, and also special symbols such as non-alphanumeric characters (eg. !#$.&=+-/\_@?()[]{}). In fact, complex characters makes brute-force attacks take significantly longer before guessing your password. To not miss the point, also be sure to regularly change it.
The best and easiest way to obtain a password remains … human spying! In fact, passwords are not only stolen online, cracked or guessed: they can be obtained just by watching you while you are typing them. Someone can prowl around you when you are at the office, in a cafe, airport, or library…
You should not share your password, even to someone you trust. Never give any advice that can ease the guessing/deducing of your password. You never know what the future will be made of …
Choose a password that you can type quickly, without looking at your keyboard (or the least possible), and ensure other people are not too close to you, or… just behind your shoulders! (Behave the exact same way as when you type your credit card code when you withdraw cash).
One of the simplest strategies into obtaining a password is often by simply asking for it! Someone claiming to be a "system administrator" or a member of the "technical support" or "network security team" can send you an email or call you on the phone. These type of fake requests (SCAMS ) can come from inside your company, of from every external service you use.
These type of fake emails usually contains typos, but are sometimes very well imitated with logos that will make you believe it is legitimate, while not. The hacker then just asks you for your login credentials and / or password for "verification" purposes, or under the pretext of a "problem in the system". They usually like making you believe that "your account will be suspended" if you do not provide your password. But the website they redirect you to is a fake one, only crafted to collect passwords.
You should never obey to such requests unless you clearly have identified the sender of the email, or the phone caller. In case of an Email, you should carefully review the detailed mail headers , as the basic mail headers may have been disguised/spoofed. The method to view the mail headers can vary with the email client you are using: here is a list of the procedure for most common ones.
This one is an extension of the "Identity Fraud" explained at the previous point. Phishing scams are usually sent by Email, but can only be sent to your instant messaging programs like Skype, AOL IM, Viber, or your own internal company application. They basically try to get your attention alarmingly, by telling you that a prompt action on your part is necessary.
These kind of scams can take many forms, and inventiveness of hackers has virtually no limit: False invoices, false alerts telling you that your account has been suspended, urgent IM request, emails specially designed to imitate a legit source (Apple, PayPal, Yahoo, Outlook, your bank, etc...) and redirecting you to a mimic website asking you to provide personal information, such as your credentials (your login, user name and obviously...your password!).
If you receive such notification, the first thing to do is not to panic. Hackers will try to tell you that there has been a security breach and that you should change your password immediately "for security reasons". If you think that you are doing what is needed, you are wrong! Due to the multiple channels these kind of messages use to come to you, they can seem like authentic and legitimate, but actually are probably on a FAKE WEBSITE : you should then never type any personal information or password on a website unless you are sure that it is legitimate.
Never click on a message that surprises you. Before clicking on a link, check the website address indicated in the yellow tooltip or at the bottom of your screen when you put your mouse over it, and never provide your personal information until you are certain that the source is legitimate.
To ensure that an email is really sent by who it claims, you should carefully review the detailed mail headers , as the basic mail headers may have been disguised/spoofed. The method to view the mail headers can vary with the email client you are using: here is a list of the procedure for most common ones.
A lot of hacking software are specifically designed to guess passwords based on personal information are available on the internet, by collecting all sort of personal data about you. In addition to be very common and freely accessible to anyone, they are also very powerful, and easy-to use, even to people that are not computer experts.
Concretely, this means that your nephew, your jealous neighbor or your most dishonest colleague can become hacker for one day.
This kind of programs mostly make intensive use personal information found online, such as your name, your friends names, the birth dates, your license plate number, or any significant other kind of information, including your family members occupations, your favorite meals, your pet names, the company your work for, …
These programs are designed to test thousands of combinations every second, reverse letters, replace certain characters by others (e.g. replacing O by 0), and add other numbers or letters to the beginning or the end of tested and passwords.
Although you can use certain personal information in your passwords as it will help you to remember it, we highly recommend you to mangle them (for example prefer "D3an=" over "dean"). Also, use other information unrelated to you, such as special characters.
Hackers also have at their disposal automated programs that test all types of combinations linked to common dictionary words, names and figures or famous brands, in your native language, but also in other foreign languages. Using the Brute-force method, they could end up in guessing your password.
Concretely, this means that your nephew, your jealous neighbor or your most dishonest colleague can use of such programs in order to discover your passwords.
Do not use obvious words found in the dictionary unless you highly change their spelling, and add other sequences of letters or numbers, and special characters.
A "Keylogger" is a malicious program installed without your knowledge on your computer or tablet (mostly Android), whose purpose is to spy on all your keystrokes. Back in 2014, the FBI's Internet Crime Complaint Center revealed that cybercrooks had tried to access a lot of user bank accounts, for a total of approximately $100 million.
Not only individuals are targeted by hackers when it comes to key-loggers: quite the opposite, trojan horse programs are increasingly targeting small businesses and specific company employees, that have access to fund transfers tools on behalf of the company. Keyloggers can quietly spy on all the keys stroked by those employees, including the most wanted information by the hackers: the log-in credentials to an account. This type of malware is usually contained in infected Word (.doc/.docx) files, or other fake PDF concerning pretended bills.
Have a strong antivirus program, and keep it up-to-date. If you are the system administrator, enforce a very strong and complex password for this kind of employees, and for all the fund transfer services they have access to. If you are the end-user… do exactly the same! Otherwise, the consequences for you and your company could be disastrous.
Also think about setting up two-factor authentication mechanisms. This way, even if a hacker obtains your password, it will not allow him to enter your system or account. And the obvious tip is to NEVER open email attachements that you are unsure about!
If you have the slightest doubt about that your password have been compromised, however small it may be, do not take the risk, and generate a new one now using our online secure tool.
Even if your passwords are all strong and regularly changed, Brute-force attacks are a plague, because they abuse your system resources constantly, even when they fail. Discover how to detect, slow-down and circumvent such attacks.
Passwords are everywhere, including in the tools your company or business uses on a daily basis. Your web or mail servers, online applications, Cloud/SaaS tools, desktop software and mobile apps all make an intensive use of passwords. But how can you use them wisely across your entire infrastructure?…
NOTE: Your changes will be applied from the next page you will visit/load.
By using this website, you consent that we use technologies such as anonymous statistics and cookies to improve your browsing experience on our site, customise content and advertising, and analyse our traffic. This anonymous information may be shared with our trusted social media, advertising and analytics partners.