But is this really the best solution? How can one remember such passwords? Sometimes, just coming up with them can be difficult. While remembering one or two passwords may be feasible (though their quick forgetting is also highly probable), the number of places secured by passwords is much greater. For individuals not using a password manager, which – unfortunately – is still a tool that is too little popular, such passwords are very problematic. This, in turn, leads to the frequent repetition of the same, hard-to-remember combination and the use of one password to secure different accounts. In the event of that password being compromised, the risk of a successful attack on other places secured by the same password significantly increases (as one of our clients recently learned the hard way).
Another downside of passwords that consist of lowercase and uppercase letters, numbers, and symbols is the repetition of random patterns commonly used when creating such passwords: choosing one word and additionally substituting, for example, “0” for “o”, “1” for “i”, “3” for “E”, “4” for “A”, adding “!” or combining a sequence of numbers like “12345”, “qwerty”, etc. Such methods are well known to cybercriminals, making it easier for them to optimize their attacks.
What solution is better?
Recently, another method of creating passwords has been promoted, based on the technique of three random words. The effectiveness of this method is said to stem from that randomness, further supported by the length of the phrase created from these three words. Such password creation increases the effectiveness of protection, as there are as many ideas for unique passwords as there are people, composed of any chosen words. This password will, of course, be longer than a single-word password, but for the person creating it – easier to remember than a string of random letters, numbers, and special characters. The ease of remembering passwords also increases the likelihood that different passwords will be used for different accounts, which will definitely positively impact the user's security.
An additional advantage of adopting a different password policy is that the more different password methods there are, the more algorithms potential cybercriminals must try to break the passwords, which is more difficult and time-consuming for them. If there is only one accepted password method, one algorithm focused solely on breaking such passwords is sufficient.


