Having a strong password may not be enough

Typical advice on how to create and maintain passwords says things like ‘use a complex password with numbers and punctuation’. Whilst this is theoretically good advice and good practice, it can be difficult to maintain, and crucially it is very likely not enough to protect your accounts and services online.
The vast majority of breaches occur when hackers already have your password, usually in one of two key ways:
- 1. Credential Stuffing – where credentials are purchased or gathered, and then tried against multiple services. These have likely been previously stolen or leaked in a breach of a different service. For example, if you use Facebook and that password was compromised, a hacker could try that password against other accounts you are known to use, eg other social media or email etc.
- 2. Phishing – where credentials are gained under false pretences by sending you emails or links to sign in to fake versions of services you use, thereby giving away your password for that service.
In both cases above, the strength of your password does not matter. All other hacking methods – which we tend to imagine, probably due to Hollywood movies – such as logging keystrokes on your keyboard and attempting to guess passwords using powerful computers using brute force.
Microsoft report that they see Credential Stuffing attempts on more than 20 million accounts per day across their platforms (source), which is a huge amount, and shows just how many services have been compromised and how many peoples’ credentials have been leaked.
So what can you do you protect your accounts and services, in light of this? You should implement all of the below points for the best protection.
- 1. Do not use an obvious and easy to guess password. Anything based on “…1234…” or “…password…” and the like can be easily tried against your account. If you don’t use these very common passwords (there are typically around 45 variations), even if someone does try to access your account then they will very likely move along if these don’t work.
- 2. Use a different password for every single account/service to guard against Credential Stuffing, as one compromised password cannot be used to access another service. However, this is arguably quote laborious to do, and could lead to keeping notes of all passwords in one place, which is a problem in itself.
- 3. The real answer is to use Multi Factor Authentication (MFA), which requires you to enter an additional code or some sort of verification from another device (typically your smartphone) in order to access your account. Using MFA means you are 99.9% less likely to be compromised (source).