{"id":2226,"date":"2010-12-14T14:43:45","date_gmt":"2010-12-14T13:43:45","guid":{"rendered":"http:\/\/blog.intego.com\/?p=2226"},"modified":"2015-01-13T08:05:31","modified_gmt":"2015-01-13T16:05:31","slug":"passwords-in-the-news-are-yours-secure","status":"publish","type":"post","link":"https:\/\/www.intego.com\/mac-security-blog\/passwords-in-the-news-are-yours-secure\/","title":{"rendered":"Passwords In the News &#8211; Are Yours Secure?"},"content":{"rendered":"<p>There has been a fair amount of news about the recent <a href=\"http:\/\/www.computerworld.com\/s\/article\/9200978\/Update_Gawker_Media_hacked_firm_warns_users_to_change_passwords\">hack of Gawker&#8217;s servers<\/a>, in which hackers obtained e-mail addresses and passwords for some 200,000 users of the company&#8217;s web sites. These sites include Lifehacker, Gizmodo, Gawker, Jezebel, io9, Jalopnik, Kotaku, Deadspin and Fleshbot, and the e-mail addresses and passwords are for those users who registered on the sites to post comments.<\/p>\n<p>Think about the last time you went to a web site and registered either to get access to the site or to post comments. What kind of password did you use? Something simple, easy to remember, like <i>12345678<\/i>? Or your dog&#8217;s name, your kid&#8217;s birthday, or your spouse&#8217;s name? Or did you use a solid, serious password, such as <i>h389)wn-te<\/i>? (You can see the most commonly used passwords from the Gawker data <a href=\"http:\/\/www.computerworld.com\/s\/article\/9201139\/Gawker_hack_analysis_reveals_incredibly_weak_passwords\">here<\/a>.)<\/p>\n<p>And, that password you used&#8230; was it the same one you use for other sites, such as Facebook, Amazon, eBay, PayPal and most of the other sites you visit? If so, you should rethink your password strategy.<\/p>\n<p>Since hackers have obtained this user information, and since many people use the same passwords on many, if not all sites they visit, these hackers are likely to break into accounts on all sorts of sites. (Actually, this has already started, with the hackers using the credentials to <a href=\"http:\/\/www.bbc.co.uk\/news\/technology-11981816\">send spam on Twitter<\/a>.) But it can go much further, if they start trying out the credentials on web sites where money is involved. Any site where users enter credit card information is a juicy target.<\/p>\n<p>So how can you deal with this in the future? First, consider that you need two types of passwords: very secure passwords for all sites where you may lose money, or your reputation (your bank, Amazon, PayPal, Facebook, Twitter, etc.), and less secure passwords for web sites if you want to post comments, or for forums.<\/p>\n<p>We won&#8217;t go into detail about how to choose good passwords here; if you want to look into the topic, an ebook, <a href=\"http:\/\/www.takecontrolbooks.com\/passwords-macosx\">Take Control of Passwords in Mac OS X<\/a>, by Joe Kissell, can help you out. But we will give one valuable tip.<\/p>\n<p>If you use Safari, your passwords get stored in your Mac OS X Keychain. You can have the browser remember them by checking &#8220;User names and passwords&#8221; in the AutFill web forms section of Safari&#8217;s AutoFill preferences. (Firefox has a similar option, but one that isn&#8217;t linked to the keychain.) To create really secure passwords, open the Keychain Access application (in \/Applications\/Utilities), choose File &gt; New Password Item, then click the key button. You&#8217;ll see the Apple Password Assistant:<\/p>\n<p><center><br \/>\n<img loading=\"lazy\" class=\"alignnone size-full wp-image-2227\" title=\"password-assistant\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2010\/12\/password-assistant.jpg\" alt=\"\" width=\"360\" height=\"266\" srcset=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2010\/12\/password-assistant.jpg 360w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2010\/12\/password-assistant-300x221.jpg 300w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2010\/12\/password-assistant-100x73.jpg 100w\" sizes=\"(max-width: 360px) 100vw, 360px\" \/><\/center>You can either enter your own password and see how strong it is, or have the assistant choose one that is essentially unbreakable. (If you choose, say, 12 characters, Letters &amp; Numbers, no one will be able to crack it in your lifetime.) Enter that password for your web site, and make sure that you have Safari remember it in the keychain. In the future, you&#8217;ll be able to log in automatically using your keychain, and you won&#8217;t have to remember the complex password.<\/p>\n<p>There&#8217;s a lot to know about how to best use and manage passwords, but the simplest thing to remember is that passwords for sites where you would be at risk if your access were compromised must be complex. They don&#8217;t have to be too complex, but enough that they&#8217;re not in a dictionary, or easy to figure out. And you should never use the same password for multiple sites, unless those sites are unimportant (such as sites for entering comments or posting in forums).<\/p>\n","protected":false},"excerpt":{"rendered":"<p>There has been a fair amount of news about the recent hack of Gawker&#8217;s servers, in which hackers obtained e-mail addresses and passwords for some 200,000 users of the company&#8217;s web sites. These sites include Lifehacker, Gizmodo, Gawker, Jezebel, io9, Jalopnik, Kotaku, Deadspin and Fleshbot, and the e-mail addresses and passwords are for those users [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"spay_email":"","jetpack_publicize_message":"","jetpack_is_tweetstorm":false},"categories":[13],"tags":[353,96],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v17.4 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<meta name=\"description\" content=\"There has been a fair amount of news about the recent hack of Gawker&#039;s servers, in which hackers obtained e-mail addresses and passwords for some 200,000\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.intego.com\/mac-security-blog\/passwords-in-the-news-are-yours-secure\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Passwords In the News - Are Yours Secure?  - The Mac Security Blog\" \/>\n<meta property=\"og:description\" content=\"There has been a fair amount of news about the recent hack of Gawker&#039;s servers, in which hackers obtained e-mail addresses and passwords for some 200,000\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.intego.com\/mac-security-blog\/passwords-in-the-news-are-yours-secure\/\" \/>\n<meta property=\"og:site_name\" content=\"The Mac Security Blog\" \/>\n<meta property=\"article:published_time\" content=\"2010-12-14T13:43:45+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2015-01-13T16:05:31+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2010\/12\/password-assistant.jpg\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Peter James\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#organization\",\"name\":\"Intego\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/\",\"sameAs\":[],\"logo\":{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#logo\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2022\/10\/intego-organization-logo-for-google-knowledge-graph-875x875-1.png\",\"contentUrl\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2022\/10\/intego-organization-logo-for-google-knowledge-graph-875x875-1.png\",\"width\":875,\"height\":875,\"caption\":\"Intego\"},\"image\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#logo\"}},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#website\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/\",\"name\":\"The Mac Security Blog\",\"description\":\"Keep Macs safe from the dangers of the Internet\",\"publisher\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.intego.com\/mac-security-blog\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/passwords-in-the-news-are-yours-secure\/#primaryimage\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2010\/12\/password-assistant.jpg\",\"contentUrl\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2010\/12\/password-assistant.jpg\",\"width\":\"360\",\"height\":\"266\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/passwords-in-the-news-are-yours-secure\/#webpage\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/passwords-in-the-news-are-yours-secure\/\",\"name\":\"Passwords In the News - Are Yours Secure? - The Mac Security Blog\",\"isPartOf\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/passwords-in-the-news-are-yours-secure\/#primaryimage\"},\"datePublished\":\"2010-12-14T13:43:45+00:00\",\"dateModified\":\"2015-01-13T16:05:31+00:00\",\"description\":\"There has been a fair amount of news about the recent hack of Gawker's servers, in which hackers obtained e-mail addresses and passwords for some 200,000\",\"breadcrumb\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/passwords-in-the-news-are-yours-secure\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.intego.com\/mac-security-blog\/passwords-in-the-news-are-yours-secure\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/passwords-in-the-news-are-yours-secure\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.intego.com\/mac-security-blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Passwords In the News &#8211; Are Yours Secure?\"}]},{\"@type\":\"Article\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/passwords-in-the-news-are-yours-secure\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/passwords-in-the-news-are-yours-secure\/#webpage\"},\"author\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#\/schema\/person\/d0c16bd0a4dd8f82d91204f400c8d116\"},\"headline\":\"Passwords In the News &#8211; Are Yours Secure?\",\"datePublished\":\"2010-12-14T13:43:45+00:00\",\"dateModified\":\"2015-01-13T16:05:31+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/passwords-in-the-news-are-yours-secure\/#webpage\"},\"wordCount\":611,\"publisher\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#organization\"},\"image\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/passwords-in-the-news-are-yours-secure\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2010\/12\/password-assistant.jpg\",\"keywords\":[\"Password Security\",\"Passwords\"],\"articleSection\":[\"Security &amp; Privacy\"],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#\/schema\/person\/d0c16bd0a4dd8f82d91204f400c8d116\",\"name\":\"Peter James\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#personlogo\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/0626bfb4ada576ba5aa775322329ad47?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/0626bfb4ada576ba5aa775322329ad47?s=96&d=mm&r=g\",\"caption\":\"Peter James\"},\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/author\/peter\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"description":"There has been a fair amount of news about the recent hack of Gawker's servers, in which hackers obtained e-mail addresses and passwords for some 200,000","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.intego.com\/mac-security-blog\/passwords-in-the-news-are-yours-secure\/","og_locale":"en_US","og_type":"article","og_title":"Passwords In the News - Are Yours Secure?  - The Mac Security Blog","og_description":"There has been a fair amount of news about the recent hack of Gawker's servers, in which hackers obtained e-mail addresses and passwords for some 200,000","og_url":"https:\/\/www.intego.com\/mac-security-blog\/passwords-in-the-news-are-yours-secure\/","og_site_name":"The Mac Security Blog","article_published_time":"2010-12-14T13:43:45+00:00","article_modified_time":"2015-01-13T16:05:31+00:00","og_image":[{"url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2010\/12\/password-assistant.jpg"}],"twitter_card":"summary_large_image","twitter_misc":{"Written by":"Peter James","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Organization","@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization","name":"Intego","url":"https:\/\/www.intego.com\/mac-security-blog\/","sameAs":[],"logo":{"@type":"ImageObject","@id":"https:\/\/www.intego.com\/mac-security-blog\/#logo","inLanguage":"en-US","url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2022\/10\/intego-organization-logo-for-google-knowledge-graph-875x875-1.png","contentUrl":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2022\/10\/intego-organization-logo-for-google-knowledge-graph-875x875-1.png","width":875,"height":875,"caption":"Intego"},"image":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#logo"}},{"@type":"WebSite","@id":"https:\/\/www.intego.com\/mac-security-blog\/#website","url":"https:\/\/www.intego.com\/mac-security-blog\/","name":"The Mac Security Blog","description":"Keep Macs safe from the dangers of the Internet","publisher":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.intego.com\/mac-security-blog\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"ImageObject","@id":"https:\/\/www.intego.com\/mac-security-blog\/passwords-in-the-news-are-yours-secure\/#primaryimage","inLanguage":"en-US","url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2010\/12\/password-assistant.jpg","contentUrl":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2010\/12\/password-assistant.jpg","width":"360","height":"266"},{"@type":"WebPage","@id":"https:\/\/www.intego.com\/mac-security-blog\/passwords-in-the-news-are-yours-secure\/#webpage","url":"https:\/\/www.intego.com\/mac-security-blog\/passwords-in-the-news-are-yours-secure\/","name":"Passwords In the News - Are Yours Secure? - The Mac Security Blog","isPartOf":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/passwords-in-the-news-are-yours-secure\/#primaryimage"},"datePublished":"2010-12-14T13:43:45+00:00","dateModified":"2015-01-13T16:05:31+00:00","description":"There has been a fair amount of news about the recent hack of Gawker's servers, in which hackers obtained e-mail addresses and passwords for some 200,000","breadcrumb":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/passwords-in-the-news-are-yours-secure\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.intego.com\/mac-security-blog\/passwords-in-the-news-are-yours-secure\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.intego.com\/mac-security-blog\/passwords-in-the-news-are-yours-secure\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.intego.com\/mac-security-blog\/"},{"@type":"ListItem","position":2,"name":"Passwords In the News &#8211; Are Yours Secure?"}]},{"@type":"Article","@id":"https:\/\/www.intego.com\/mac-security-blog\/passwords-in-the-news-are-yours-secure\/#article","isPartOf":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/passwords-in-the-news-are-yours-secure\/#webpage"},"author":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#\/schema\/person\/d0c16bd0a4dd8f82d91204f400c8d116"},"headline":"Passwords In the News &#8211; Are Yours Secure?","datePublished":"2010-12-14T13:43:45+00:00","dateModified":"2015-01-13T16:05:31+00:00","mainEntityOfPage":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/passwords-in-the-news-are-yours-secure\/#webpage"},"wordCount":611,"publisher":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization"},"image":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/passwords-in-the-news-are-yours-secure\/#primaryimage"},"thumbnailUrl":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2010\/12\/password-assistant.jpg","keywords":["Password Security","Passwords"],"articleSection":["Security &amp; Privacy"],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/www.intego.com\/mac-security-blog\/#\/schema\/person\/d0c16bd0a4dd8f82d91204f400c8d116","name":"Peter James","image":{"@type":"ImageObject","@id":"https:\/\/www.intego.com\/mac-security-blog\/#personlogo","inLanguage":"en-US","url":"https:\/\/secure.gravatar.com\/avatar\/0626bfb4ada576ba5aa775322329ad47?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/0626bfb4ada576ba5aa775322329ad47?s=96&d=mm&r=g","caption":"Peter James"},"url":"https:\/\/www.intego.com\/mac-security-blog\/author\/peter\/"}]}},"jetpack_featured_media_url":"","jetpack_publicize_connections":[],"jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/p4VAYd-zU","amp_enabled":true,"_links":{"self":[{"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/2226"}],"collection":[{"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/comments?post=2226"}],"version-history":[{"count":1,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/2226\/revisions"}],"predecessor-version":[{"id":35515,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/2226\/revisions\/35515"}],"wp:attachment":[{"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/media?parent=2226"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/categories?post=2226"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/tags?post=2226"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}