"People are not aware of the value of their data."
A conversation with Prof. Dr.-Ing. Spangenberg about passwords, hackers and the convenience of Germans.
February 1 is Change-Your-Password Day. We spoke with Prof. Dr.-Ing. Marietta Spangenberg about her field of expertise, information security. A conversation about passwords, hackers, and the Germans’ preference for convenience.
Prof. Dr. Spangenberg, should we all change our passwords on February 1?
No, that doesn’t necessarily make sense. But you can use today as an opportunity to at least think about how secure your own passwords are. And if you haven’t changed your passwords in a while, it’s a good idea to tackle that in the next few days—especially if you’re currently affected by the massive email leak, just like 2 billion others. Then it’s high time for a secure password.
What makes a password secure?
The password length is important; it should be at least eight characters, preferably more. This ensures the password is resistant to attacks. The characters used should include lowercase and uppercase letters, numbers, and special characters. You should avoid using terms from your immediate surroundings, such as nicknames for your partner or pet. You could come up with a sentence that’s good to remember; then just take the first letters of the sentence and add a few tweaks, such as replacing a “b” with an “8,” or something similar.
Does a good password really protect me from hacker attacks?
Of course, there are other ways an attacker can strike. But a good password is a key part of your defense. There’s never 100% protection.
How often should I change my passwords?
There’s no one-size-fits-all answer. If you suspect or realize that someone might have access to your password or one of your accounts, you should act immediately. Many platforms also automatically prompt you to change your password at regular intervals, e.g., every 72 days. Constantly changing your password is pointless and actually compromises its security.
In what way?
If you only change a little bit at a time, you end up with “sister passwords.” These are very similar to the old password, differing only in minor details—such as a single letter or number—and can therefore be easily cracked.
Should you use a different password for every platform?
Definitely. Especially if that password is also linked to your email account—and thus to your most personal data and most important accounts. People often use their email account to have forgotten passwords sent to them: once hackers have cracked your password, it’s a breeze for them to get their hands on your private information, such as your bank account details and PIN.
How can you possibly remember the right password for every platform you’re logged into?
There are systems for managing passwords—so-called password managers. All you need to do is remember a single password: the master password. The program takes care of the rest. If your computer or cell phone were hacked, everything would be securely encrypted.
So there’s a lot at stake when we’re careless with passwords. So why are we so unimaginative when it comes to coming up with passwords? Among the most popular options are simple number sequences, like 1234.
Because people are lazy and don’t appreciate the valueof their information. A password is like a key to our very important and private information. And normally, we do take good care of our keys—we don’t just hand over a house key carelessly. In the virtual world, we think: oh, it’s just data. People aren’t really aware of the value of this information.
What is the future of the password? Will we eventually rely solely on fingerprints?
The password as such will be with us for a while yet, because biometrics doesn’t offer comprehensive security either. Fingerprints are quite easy to manipulate. On the iPhone, this feature was hacked almost immediately. Facial recognition was also compromised after only a short time. In the future, two-factor authentication will be used more widely—likely in a combination of fingerprint and password.
Prof. Dr.-Ing. Marietta Spangenberg from the Faculty of Electrical Engineering and Computer Science has been teaching at HSZG since 1992. Her areas of expertise include computer networks, information security, IT security management, and data protection.
The interview was conducted by Sophie Herwig
1st floor
1st floor