Setting up parental controls on home devices
Sep 21,2018 - Sports
For years we were told a good password was a jumble of capitals, numbers and symbols. So millions of us turned our dogs' names into R0ver! and felt rather pleased with ourselves. The trouble is that attackers know these tricks too. Their tools don't sit there guessing letter by letter; they run through enormous lists of real passwords already leaked from other websites, complete with all the common substitutions: a becomes @, o becomes 0, an exclamation mark appears at the end.
What actually protects you is length, followed by uniqueness. A long password made of ordinary words takes vastly longer to crack than a short one stuffed with symbols. And a password used on only one account can't drag the rest of your life down with it when that site is breached.
A passphrase is simply several unrelated words strung together. Because each word adds so much length, the result is far harder to crack than it looks, and it's far easier for a human to remember and type. Four or five random words, at least 16 characters in total, is a solid target.
Randomness matters. "Ilove my family and my dog" is long, but it's a sentence pattern that cracking tools model well. Instead, pull words from different corners of your memory and don't let them connect into a story:
Add a number or symbol somewhere that isn't the end, if the site insists: teapot-lantern-7-gravel-cushion. And please don't use the famous horse-battery-staple example. It's been printed in a thousand articles, so it sits near the top of every cracking list.
The best passphrase is one that means something to you and nothing to anyone else. A private in-joke, a misheard lyric, a silly phrase from a family holiday. Then scramble it: swap the order, change one word for its opposite, drop in a word from a language you half-remember.
What you should avoid is anything an attacker could find out. Names of children, pets, streets, workplaces and favourite football clubs are often plastered across social media. Birthdays and anniversaries are easy to dig up. If a stranger could learn it from your profile, or from a quick conversation with someone who knows you, leave it out.
You may be tempted to build a system, such as adding the site's initials to a base phrase. It's a reasonable compromise if you truly won't use a manager, but be honest about the risk: once one password leaks, a clever attacker can often work out the pattern and try it everywhere.
Here's the sensible arrangement. You memorise one strong passphrase. A password manager remembers all the rest, generating long random strings for every account you own. You never see most of them, and neither does anyone else.
Managers come built into browsers and phones, and there are dedicated apps for a few pounds a month. Most will fill in logins automatically, sync between your devices and warn you when a password has appeared in a known breach. That last feature alone is worth the cost.
Treat the master passphrase carefully. Make it long, make it memorable, and don't use it anywhere else. Writing it on paper and keeping it somewhere secure at home is perfectly respectable — a burglar is a different threat from a criminal sitting in another country. What you shouldn't do is save it in a file called passwords.docx on your desktop.
Two-factor authentication means an attacker needs your password and something else, usually a code from an app or a small hardware key. Turn it on for your email first — email is the master key to everything else, because password reset links arrive there. Banking, shopping and social accounts come next.
An authenticator app or a hardware key is stronger than a code sent by text message, which can be intercepted. While you're in your account settings, check that your recovery email address and phone number are current. If they're years out of date, you could be locked out at the worst possible moment.
Security questions deserve a mention too. Treat them as passwords. If asked for your mother's maiden name, give a nonsense answer and store it in your manager. It's genuinely satisfying.
You don't need to fix everything tonight. Start with the accounts that could cause real damage: email, online banking, anything holding your card details. Set those to long, unique passphrases today.
Then work through the rest in batches. Your manager will flag passwords you've reused across sites, which is the quickest way to spot the ones that matter. Any account still using a password you've had since university should be changed.
None of this takes much effort once it's set up, and the peace of mind is considerable. Length, uniqueness and a manager to hold it all together — that's really the whole trick.
Copyright © 2026 Compulite. All rights reserved.Compulite. All Right Reserved.
John Doe - 29 july 2018
Compulite Written for people who value the details, and want honest guidance they can trust.
John Doe - 29 july 2018
Compulite An honest, everyday look at the things that make life a little better — with advice you can actually use.
John Doe - 29 july 2018
Compulite An honest, everyday look at the things that make life a little better — with advice you can actually use.
John Doe - 29 july 2018
Compulite An honest, everyday look at the things that make life a little better — with advice you can actually use.