Secure passwords

There's an old saying: "The bigger the choice, the harder it is to choose." - this also applies when choosing a password. The choice of a secure password is difficult for many people. This can also be seen in the list of the most common passwords 2018 (source: https://hpi.de/pressemitteilungen/2018/die-top-ten-deutscher-passwoerter.html):

  1. 123456
  2. 12345
  3. 123456789
  4. ficken
  5. 12345678
  6. hallo123
  7. hallo
  8. 1234
  9. passwort
  10. master

Method 1: The Password-Generator

A password generator can be used to create a secure password that meets all complexity requirements.
These can be found online, e.g. at the Central Data Protection Office of Baden-Württemberg Universities: https://www.zendas.de/service/passwort_generator.html!  Alternatively you can choose „The PAYBACK Way“ and use a password manager. You will find our password manager KeePass pre-installed on every notebook - you can find instructions here: https://toolbox.loyaltypartner.com/fileadmin/Dateien/Office_IT/KeePass2_DE_04.pdf!

Method 2: The Password-Sentence

Another method is to use a sentence to remember a secure password. To create a password from a sentence, use any initial letter, number, or special character that occurs in the sentence. 
Example: Sentence: I drive a green Mercedes SL55 with 360 hp!
               Password: IdagMSL55w360hp!

In order to create a separate password for each individual service - and to be able to remember this - we use a password sentence, which we extend by a certain scheme. Here, for example, by adding the first three digits of the service name to the password:
Example: Sentence: I drive a green Mercedes SL55 with 360 hp!
               Password: IdagMSL55w360hp!
                  ebay.de: IdagMSL55w360hp!eba
             amazon.de: IdagMSL55w360hp!ama

Method 3: The Password-Card

The password card has the advantage that you can take it with you everywhere. You can easily remember a complex password for each individual service using an easy-to-remember reading scheme. Further information about the password card can be found here: https://www.sicher-im-netz.de/dsin-passwortkarte.
Of course you can also generate your own password card - you can find a template here: 

  1. Keep passwords locked up
  2. Change passwords regularly - at the latest if abuse is suspected
  3. No unique passwords for different accounts
  4. Change preset passwords
  5. Do not share passwords with third parties and do not send them by e-mail.
  1. The more characters the better
    The password should have at least 8 characters to provide some protection against brute force attacks (trying different combinations).
  2. Use small, large letters, special characters and digits.
    The use of several different characters also increases the number of possible combinations. This also increases protection against brute force attacks.
  3. Do not use known names or data
    Names of family members, pets, the favourite singer or their dates of birth are absolutely taboo. Such passwords can be easily guessed with a little background research.
  4. Do not use words from dictionaries
    Another method is the so-called dictionary attack. Here the attacker tries a password list (dictionary).
  5. Do not use keyboard patterns or repetitions
    Keyboard patterns (e.g. qwertz) or the appending of numbers or special characters at the end of an otherwise simple password meet the complexity requirements - but are also taken into account by attackers when creating dictionaries.
  6. One password per service
    If you use only one username/password combination for all services, then an attacker who has uncovered a password can access all accounts.
  7. Use a password manager
    In reality, it is almost impossible for most people to follow all the above points and remember several such complex passwords. The consequence is that the above rules are not followed or passwords are not securely noted. To avoid this, we recommend the use of a password manager.