eight-character passwords, even complex ones, are no longer enough

Services may soon ask us to change our passwords to new, much longer ones of at least 16 characters. To get around this difficulty, other solutions are beginning to emerge.

Published


Reading time: 2 min

The best chips can guess a said password "strong" in one hour if it only has eight characters.  Illustrative photo (JUST_SUPER / E+)

A report from cybersecurity specialists Hive Systems warns against the passwords in use today. Today, most services require a password of at least eight characters with uppercase, lowercase, numbers, and special characters. But the computing power of the latest chips is such that by trying all possible combinations, it would take them just an hour to guess this kind of password, even complex ones. We’re not even talking about supercomputers, but machines available in any store for less than 3,000 euros. Hence their recommendation to switch to longer passwords, of at least 16 characters, which would take several billion years to decipher.

Get rid of passwords completely?

Passwords have become a real pain. You need a different one for each department, they need to be long, with special characters that are difficult to remember, and they need to be changed regularly. This is why some are currently seeking to get rid of the very concept of a password altogether. Tech giants have agreed on a standard called “Passkey”.

Its principle is very simple: when you need to connect, you simply give your username. And instead of typing a password, you scan the QR code displayed on the computer with your phone. Then, you validate your identity on your mobile, with your fingerprint or your face, as you usually do to unlock it. And if the connection is made directly on the mobile, it’s even faster. He will simply ask to scan his fingerprint or his face. So, no more passwords to remember or type. It is the telephone which serves, in a way, as a key to validate the connection.

The system is already working now. In recent weeks alone, the standard has been activated for connection to Windows, Google, WhatsApp, X and the Playstation… So, don’t hesitate to find out. This will avoid long passwords that are impossible to remember.


source site-15