This Trick Will Make Your Passwords Even More Secure

preview_player
Показать описание
Peppering is a technique where you add or substract some characters from a stored password, so that the whole password is known only to you. This increases the security for your essential accounts and means that if your stored passwords are ever revealed (by hackers or because your little black book has been stolen) then the attackers don't know the complete password!
---

#garyexplains
Рекомендации по теме
Комментарии
Автор

Gary I wanna give you a hug for this one mate

taher
Автор

'Peppering' is a good mitigation (for those in the 'know').
Not only is it tricky to incorporate, it is neigh impossible to implement or teach company-wide.
Best (albeit weak) practice is (imho) long passwords (e.g. 14 characters or more) using spaces and/or ASCII characters.
This will (semi) force users to use sentences.
A combination of words will reduce the 'brute-force'-likelihood of a breach (especially if there is BF-mitigation implemented).
All said, Gary, you're a great source for security knowledge.

maartentoors
Автор

I was skeptical of watching this video, but then after watching this video can I say "Today I learned". It is really good techinique I never thought of. Awesome, thank you Gary

deepgsingh
Автор

Great advice! I watched another YouTuber who called it a "double blind" password. The password manager never has the full password stored for your high valued sites.

BlueFlyer
Автор

Simple and Effective. A really Helpful Explanation too. Great !

dezmondwhitney
Автор

Peppering, or double-blind, I add mine at the beginning instead of at the end.

manny
Автор

I have been using a mnemonic style where I replaces a word with a character and forms a short sentence combined with what you call peppering.
~ = water
< = in
= = is
$ = money
@ = at

NexuJin
Автор

I used to do it myself, the 3 letters I added at the end: the first letter of the month the account was created, the last letter of the site capitalized, the second letter of the site. I don't do it anymore but this allows to have no need to remember these 3 letters. The general idea is to memorize a mental algorithm that you can follow to calculate your password instead of memorizing the password itself.

phir
Автор

This is great and helpful. You are a genius!

TravelEndleslie
Автор

This is brilliant! Thanks for sharing, I never thought about this

murtadha
Автор

I use an offline password manager, Keepass, No server to be hacked. Backing up the database to USB drives, portable storage, mobile phone and other computers and syncing manually. I do not know a single password to any of my accounts, only a pass phrase compiled with diceware, using an actual dice and a printed hard copy dictionary list.

coweatsman
Автор

Thanks, great idea but you need to peppering all your passwords. If no, you may forget which have the pepper

JustinWong-wj
Автор

Chuck Norris doesn’t use passwords. He is the password.

uidx-bob
Автор

Clever but my swiss cheese brain will have trouble remembering the pattern 6 months from now. Awesome idea though.

test
Автор

*GARY!!!*

GOOD MORNING PROFESSOR!

GOOD MORNING FELLOW CLASSMATES!

Stay safe out there everyone!

MarkKeller
Автор

My "cookie cutter password" is (very basically), Symbol, Uppercaseletter, Lowercaseletter, number, Uppercaseletter, lowercaseletter, number, symbol, Uppercaseletter, lowercaseletter, number, Uppercaseletter, lowercaseletter, number, symbol. Works 100% and took me two tries to fully remember it. :^)

GustavoMsTrashCan
Автор

I'm going to do this with my 100 character bank password that I store in a local password manager that uses a key file as well as a master password, oh, and the bank also requires two factor authentication. Can't be too secure, you know.
But I'm going to type 1 2 3 4 17 characters in, instead of at the end. (at least that is what I'm saying I will do)

Are you related to Veronica Explains?

paulgee-ij
Автор

Never delete characters. Password length is by far the biggest determinant in security. A 16 character password using nothing but random upper case letters will have a higher entropy rating than a 12 character password randomly generated using uppercase, lowercase, numeric, and special characters. Even a 16 all-numeric password rates nearly as high as the most complex 12 character password. Anyone can verify this using an online password evaluator.

reefhound
Автор

Safest place for Passwords are in your head and your home in a encrypted USB drive. Not in Password Managers. .. Do you trust other people with your money, your Business? LOL give your head a shake folks.

STONE_
Автор

Salting just stops rainbow tables and really doesn't make it any harder for someone to crack an individual password. If a hacker can get the password file, it's likely they will also be able to known or have the salt as well.

Ken.-