{"id":1458,"date":"2024-03-22T11:57:03","date_gmt":"2024-03-22T15:57:03","guid":{"rendered":"https:\/\/www.magicspam.com\/blog\/?p=1458"},"modified":"2024-04-02T18:41:31","modified_gmt":"2024-04-02T22:41:31","slug":"safe-vs-common-weak-passwords","status":"publish","type":"post","link":"https:\/\/www.magicspam.com\/blog\/safe-vs-common-weak-passwords\/","title":{"rendered":"Safe vs Weak Passwords: Could you be hacked in the next 5 minutes?"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\">Why do people use weak passwords?<\/h2>\n\n\n\n<p>It&#8217;s no secret that most people prioritize convenience over security. When it comes to passwords, people like to use their cat&#8217;s name or their birthday \u2014 something easy to remember. They also don&#8217;t want to remember a bunch of different passwords, so they recycle that same password and use it everywhere. When weak passwords are the preference, security becomes an oversight.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>How hackable is my password?<\/strong><\/h2>\n\n\n\n<p>That depends. If you are using an email platform, any random combination of letters and numbers probably won&#8217;t get hacked <strong>as long as you don&#8217;t use the same password elsewhere<\/strong> and <strong>your password isn&#8217;t discovered in a data breach<\/strong>. <\/p>\n\n\n\n<figure class=\"wp-block-pullquote\"><blockquote><p><em>&#8220;The strongest passwords are at least 12 characters long, contain uppercase letters, lowercase letters, numbers and symbols, and do not incorporate personal details.&#8221;<\/em><\/p><\/blockquote><\/figure>\n\n\n\n<p>If you&#8217;re using your name and birthday as your password, hacking bots can discover these kinds of details in minutes. One of the most common password guessing bots simply tries your name and a four-digit year. That&#8217;s less than 100 combinations since the year you were born, and covers most dates that are important to you. <\/p>\n\n\n\n<p>So, how hackable is your password? Let&#8217;s talk about that.<\/p>\n\n\n\n<h5 class=\"wp-block-heading\"><strong>Short passwords<\/strong><\/h5>\n\n\n\n<figure data-wp-context=\"{&quot;imageId&quot;:&quot;6a2ce0aade33c&quot;}\" data-wp-interactive=\"core\/image\" data-wp-key=\"6a2ce0aade33c\" class=\"wp-block-image size-full wp-lightbox-container\"><img loading=\"lazy\" decoding=\"async\" width=\"1480\" height=\"647\" data-wp-class--hide=\"state.isContentHidden\" data-wp-class--show=\"state.isContentVisible\" data-wp-init=\"callbacks.setButtonStyles\" data-wp-on--click=\"actions.showLightbox\" data-wp-on--load=\"callbacks.setButtonStyles\" data-wp-on-window--resize=\"callbacks.setButtonStyles\" src=\"https:\/\/www.magicspam.com\/blog\/wp-content\/uploads\/2024\/03\/password-12345-short.png\" alt=\"short password on black notebook next to padlock on a laptop\" class=\"wp-image-1828\" srcset=\"https:\/\/www.magicspam.com\/blog\/wp-content\/uploads\/2024\/03\/password-12345-short.png 1480w, https:\/\/www.magicspam.com\/blog\/wp-content\/uploads\/2024\/03\/password-12345-short-300x131.png 300w, https:\/\/www.magicspam.com\/blog\/wp-content\/uploads\/2024\/03\/password-12345-short-1024x448.png 1024w, https:\/\/www.magicspam.com\/blog\/wp-content\/uploads\/2024\/03\/password-12345-short-768x336.png 768w\" sizes=\"auto, (max-width: 1480px) 100vw, 1480px\" \/><button\n\t\t\tclass=\"lightbox-trigger\"\n\t\t\ttype=\"button\"\n\t\t\taria-haspopup=\"dialog\"\n\t\t\taria-label=\"Enlarge\"\n\t\t\tdata-wp-init=\"callbacks.initTriggerButton\"\n\t\t\tdata-wp-on--click=\"actions.showLightbox\"\n\t\t\tdata-wp-style--right=\"state.imageButtonRight\"\n\t\t\tdata-wp-style--top=\"state.imageButtonTop\"\n\t\t>\n\t\t\t<svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"12\" height=\"12\" fill=\"none\" viewBox=\"0 0 12 12\">\n\t\t\t\t<path fill=\"#fff\" d=\"M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z\" \/>\n\t\t\t<\/svg>\n\t\t<\/button><\/figure>\n\n\n\n<p><\/p>\n\n\n\n<p>A password&#8217;s length alone does not determine how easy it is to hack. It does play a role, though, especially in the context of brute force attacks.<\/p>\n\n\n\n<p>If your password is compromised in a data breach, hackers can run a brute force attack locally on their machine. A weak password eight characters or less can be hacked in under a minute, which is why many experts recommend longer passwords. The longer the password, the more difficult it will be to brute force.<\/p>\n\n\n\n<h5 class=\"wp-block-heading\"><strong>Simple passwords<\/strong><\/h5>\n\n\n\n<p>Simple passwords consisting of all lowercase letters, numbers, or dictionary words can be cracked very easily.<\/p>\n\n\n\n<p>If your password is more complex, it may be strong, but it will also be harder to remember. Most people typically prefer simple passwords or use a password manager to keep track of everything. This route has its own vulnerabilities, because if the password manager is breached, all of your stored passwords go with it.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure data-wp-context=\"{&quot;imageId&quot;:&quot;6a2ce0aadef0f&quot;}\" data-wp-interactive=\"core\/image\" data-wp-key=\"6a2ce0aadef0f\" class=\"aligncenter size-full is-resized wp-lightbox-container\"><img loading=\"lazy\" decoding=\"async\" width=\"1667\" height=\"938\" data-wp-class--hide=\"state.isContentHidden\" data-wp-class--show=\"state.isContentVisible\" data-wp-init=\"callbacks.setButtonStyles\" data-wp-on--click=\"actions.showLightbox\" data-wp-on--load=\"callbacks.setButtonStyles\" data-wp-on-window--resize=\"callbacks.setButtonStyles\" src=\"https:\/\/www.magicspam.com\/blog\/wp-content\/uploads\/2024\/03\/Dictionary-Attacks-EX-edited.png\" alt=\"hacker with dictionary passwords over top\" class=\"wp-image-1908\" style=\"width:728px;height:auto\" srcset=\"https:\/\/www.magicspam.com\/blog\/wp-content\/uploads\/2024\/03\/Dictionary-Attacks-EX-edited.png 1667w, https:\/\/www.magicspam.com\/blog\/wp-content\/uploads\/2024\/03\/Dictionary-Attacks-EX-edited-300x169.png 300w, https:\/\/www.magicspam.com\/blog\/wp-content\/uploads\/2024\/03\/Dictionary-Attacks-EX-edited-1024x576.png 1024w, https:\/\/www.magicspam.com\/blog\/wp-content\/uploads\/2024\/03\/Dictionary-Attacks-EX-edited-768x432.png 768w, https:\/\/www.magicspam.com\/blog\/wp-content\/uploads\/2024\/03\/Dictionary-Attacks-EX-edited-1536x864.png 1536w\" sizes=\"auto, (max-width: 1667px) 100vw, 1667px\" \/><button\n\t\t\tclass=\"lightbox-trigger\"\n\t\t\ttype=\"button\"\n\t\t\taria-haspopup=\"dialog\"\n\t\t\taria-label=\"Enlarge\"\n\t\t\tdata-wp-init=\"callbacks.initTriggerButton\"\n\t\t\tdata-wp-on--click=\"actions.showLightbox\"\n\t\t\tdata-wp-style--right=\"state.imageButtonRight\"\n\t\t\tdata-wp-style--top=\"state.imageButtonTop\"\n\t\t>\n\t\t\t<svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"12\" height=\"12\" fill=\"none\" viewBox=\"0 0 12 12\">\n\t\t\t\t<path fill=\"#fff\" d=\"M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z\" \/>\n\t\t\t<\/svg>\n\t\t<\/button><figcaption class=\"wp-element-caption\">Avoid dictionary-based passwords like the plague wherever possible.<\/figcaption><\/figure>\n<\/div>\n\n\n<p><a id=\"JPlink1\"> <\/a>\n<p>Whether or not you use a complex password, one of the best ways to protect your account is with <a href=\"https:\/\/spamauditor.org\/2021\/10\/2-factor-and-multi-factor-authentication\/\" data-type=\"link\" data-id=\"https:\/\/spamauditor.org\/2021\/10\/2-factor-and-multi-factor-authentication\/\">Two-Factor Authentication (2FA)<\/a>. This adds an extra layer of protection over your password. It&#8217;s more difficult to crack Two-Factor Authentication than even a long, complex password. <\/p><\/p>\n\n\n\n<h5 class=\"wp-block-heading\"><strong>Recycled passwords<\/strong><\/h5>\n\n\n\n<p>Don&#8217;t use the same passwords from account to account. If a hacker successfully gains access to one of your accounts, the first thing they will do is try the password against your other accounts. If that&#8217;s unsuccessful, they will attempt variants of that first successful password, or move on to social engineering techniques.<\/p>\n\n\n\n<p>Back when FriendFinder Networks was hacked in 2016, over 412 million accounts (including 15 million deleted accounts) were exposed. Account usernames, emails, passwords, last logins, and IP addresses were all leaked.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure data-wp-context=\"{&quot;imageId&quot;:&quot;6a2ce0aadfb36&quot;}\" data-wp-interactive=\"core\/image\" data-wp-key=\"6a2ce0aadfb36\" class=\"aligncenter size-full is-resized wp-lightbox-container\"><img loading=\"lazy\" decoding=\"async\" width=\"1380\" height=\"754\" data-wp-class--hide=\"state.isContentHidden\" data-wp-class--show=\"state.isContentVisible\" data-wp-init=\"callbacks.setButtonStyles\" data-wp-on--click=\"actions.showLightbox\" data-wp-on--load=\"callbacks.setButtonStyles\" data-wp-on-window--resize=\"callbacks.setButtonStyles\" src=\"https:\/\/www.magicspam.com\/blog\/wp-content\/uploads\/2024\/03\/friendfinderhack.png\" alt=\"hacker next to a diagram of the friendfinder hack\" class=\"wp-image-1802\" style=\"width:715px;height:auto\" srcset=\"https:\/\/www.magicspam.com\/blog\/wp-content\/uploads\/2024\/03\/friendfinderhack.png 1380w, https:\/\/www.magicspam.com\/blog\/wp-content\/uploads\/2024\/03\/friendfinderhack-300x164.png 300w, https:\/\/www.magicspam.com\/blog\/wp-content\/uploads\/2024\/03\/friendfinderhack-1024x559.png 1024w, https:\/\/www.magicspam.com\/blog\/wp-content\/uploads\/2024\/03\/friendfinderhack-768x420.png 768w\" sizes=\"auto, (max-width: 1380px) 100vw, 1380px\" \/><button\n\t\t\tclass=\"lightbox-trigger\"\n\t\t\ttype=\"button\"\n\t\t\taria-haspopup=\"dialog\"\n\t\t\taria-label=\"Enlarge\"\n\t\t\tdata-wp-init=\"callbacks.initTriggerButton\"\n\t\t\tdata-wp-on--click=\"actions.showLightbox\"\n\t\t\tdata-wp-style--right=\"state.imageButtonRight\"\n\t\t\tdata-wp-style--top=\"state.imageButtonTop\"\n\t\t>\n\t\t\t<svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"12\" height=\"12\" fill=\"none\" viewBox=\"0 0 12 12\">\n\t\t\t\t<path fill=\"#fff\" d=\"M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z\" \/>\n\t\t\t<\/svg>\n\t\t<\/button><figcaption class=\"wp-element-caption\">FindFinder Networks suffered a devastating data breach in 2016 due to poor security measures.<\/figcaption><\/figure>\n<\/div>\n\n\n<p>If your username and password were found in the FriendFinder Networks hack, it could have implications far beyond immoral adult activity. If you used the same username for other services, hackers could scrape that information on the web to figure out what other services you use. Most importantly, however, would be if you recycled the same password. If you used &#8216;123456&#8217; as your password for AdultFriendFinder, and reused that weak password for your email, online banking, and Facebook accounts, bots could crack your digital identity wide open instantly. <\/p>\n\n\n\n<p>The bottom line: you don\u2019t want someone to sit there and get into your email because you\u2019re using the same password elsewhere. No matter how tempting it may be, never recycle passwords.<\/p>\n\n\n\n<h5 class=\"wp-block-heading\"><strong>Sending passwords unencrypted<\/strong><\/h5>\n\n\n\n<figure data-wp-context=\"{&quot;imageId&quot;:&quot;6a2ce0aae062e&quot;}\" data-wp-interactive=\"core\/image\" data-wp-key=\"6a2ce0aae062e\" class=\"wp-block-image size-full wp-lightbox-container\"><img loading=\"lazy\" decoding=\"async\" width=\"2560\" height=\"1185\" data-wp-class--hide=\"state.isContentHidden\" data-wp-class--show=\"state.isContentVisible\" data-wp-init=\"callbacks.setButtonStyles\" data-wp-on--click=\"actions.showLightbox\" data-wp-on--load=\"callbacks.setButtonStyles\" data-wp-on-window--resize=\"callbacks.setButtonStyles\" src=\"https:\/\/www.magicspam.com\/blog\/wp-content\/uploads\/2024\/03\/encrypted-password.png\" alt=\"numbers being chewed up in encryption\" class=\"wp-image-1902\" srcset=\"https:\/\/www.magicspam.com\/blog\/wp-content\/uploads\/2024\/03\/encrypted-password.png 2560w, https:\/\/www.magicspam.com\/blog\/wp-content\/uploads\/2024\/03\/encrypted-password-300x139.png 300w, https:\/\/www.magicspam.com\/blog\/wp-content\/uploads\/2024\/03\/encrypted-password-1024x474.png 1024w, https:\/\/www.magicspam.com\/blog\/wp-content\/uploads\/2024\/03\/encrypted-password-768x356.png 768w, https:\/\/www.magicspam.com\/blog\/wp-content\/uploads\/2024\/03\/encrypted-password-1536x711.png 1536w, https:\/\/www.magicspam.com\/blog\/wp-content\/uploads\/2024\/03\/encrypted-password-2048x948.png 2048w\" sizes=\"auto, (max-width: 2560px) 100vw, 2560px\" \/><button\n\t\t\tclass=\"lightbox-trigger\"\n\t\t\ttype=\"button\"\n\t\t\taria-haspopup=\"dialog\"\n\t\t\taria-label=\"Enlarge\"\n\t\t\tdata-wp-init=\"callbacks.initTriggerButton\"\n\t\t\tdata-wp-on--click=\"actions.showLightbox\"\n\t\t\tdata-wp-style--right=\"state.imageButtonRight\"\n\t\t\tdata-wp-style--top=\"state.imageButtonTop\"\n\t\t>\n\t\t\t<svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"12\" height=\"12\" fill=\"none\" viewBox=\"0 0 12 12\">\n\t\t\t\t<path fill=\"#fff\" d=\"M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z\" \/>\n\t\t\t<\/svg>\n\t\t<\/button><\/figure>\n\n\n\n<p>If you send your password unencrypted over the internet, there&#8217;s a good chance someone will sniff it. Virtually every coffee shop has a compromised router, and cybercriminals can even hack even your home router or IoT device to sniff passwords. When you set up your email account, you must use SSL (Secure Sockets Layer) or TLS (Transport Layer Security), and you never put a password web form unless it is HTTPS.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Has my password been leaked?<\/strong><\/h2>\n\n\n\n<p>The best way to know is to check a site like <strong>haveibeenpwned.com<\/strong> that tells you whether your information has been compromised as part of a breach. There&#8217;s also a tab on the site for &#8220;Pwned Passwords&#8221; to check if your password has previously been discovered in a data breach.<\/p>\n\n\n\n<figure class=\"wp-block-pullquote\"><blockquote><p><em>&#8220;Never use your name or domain as part of an email password, and at least implement a combination of letters and numbers.&nbsp;Whenever possible, use Two-Factor Authentication \u2014 preferably <a href=\"https:\/\/spamauditor.org\/2021\/10\/what-does-transparent-2fa-solve\/\" data-type=\"link\" data-id=\"https:\/\/spamauditor.org\/2021\/10\/what-does-transparent-2fa-solve\/\">Transparent Two-Factor Authentication (T2FA)<\/a> methods like passing in a CLIENTID.&#8221; <\/em><\/p><\/blockquote><\/figure>\n\n\n\n<p>If you need help with creating safe password complexity testers, you can always reach out to the team at <a href=\"http:\/\/www.linuxmagic.com\/?link_id=M0hMSN7N02\" data-type=\"link\" data-id=\"http:\/\/www.linuxmagic.com\/?link_id=M0hMSN7N02\">LinuxMagic<\/a> for examples, or validation code you can use.<\/p>\n\n\n\n<h5 class=\"wp-block-heading\"><strong>What to do if your password has been leaked<\/strong><\/h5>\n\n\n\n<figure data-wp-context=\"{&quot;imageId&quot;:&quot;6a2ce0aae10ea&quot;}\" data-wp-interactive=\"core\/image\" data-wp-key=\"6a2ce0aae10ea\" class=\"wp-block-image size-full wp-lightbox-container\"><img loading=\"lazy\" decoding=\"async\" width=\"1426\" height=\"552\" data-wp-class--hide=\"state.isContentHidden\" data-wp-class--show=\"state.isContentVisible\" data-wp-init=\"callbacks.setButtonStyles\" data-wp-on--click=\"actions.showLightbox\" data-wp-on--load=\"callbacks.setButtonStyles\" data-wp-on-window--resize=\"callbacks.setButtonStyles\" src=\"https:\/\/www.magicspam.com\/blog\/wp-content\/uploads\/2024\/03\/pwnedpassword.png\" alt=\"haveibeenpwned password breach\" class=\"wp-image-1841\" srcset=\"https:\/\/www.magicspam.com\/blog\/wp-content\/uploads\/2024\/03\/pwnedpassword.png 1426w, https:\/\/www.magicspam.com\/blog\/wp-content\/uploads\/2024\/03\/pwnedpassword-300x116.png 300w, https:\/\/www.magicspam.com\/blog\/wp-content\/uploads\/2024\/03\/pwnedpassword-1024x396.png 1024w, https:\/\/www.magicspam.com\/blog\/wp-content\/uploads\/2024\/03\/pwnedpassword-768x297.png 768w\" sizes=\"auto, (max-width: 1426px) 100vw, 1426px\" \/><button\n\t\t\tclass=\"lightbox-trigger\"\n\t\t\ttype=\"button\"\n\t\t\taria-haspopup=\"dialog\"\n\t\t\taria-label=\"Enlarge\"\n\t\t\tdata-wp-init=\"callbacks.initTriggerButton\"\n\t\t\tdata-wp-on--click=\"actions.showLightbox\"\n\t\t\tdata-wp-style--right=\"state.imageButtonRight\"\n\t\t\tdata-wp-style--top=\"state.imageButtonTop\"\n\t\t>\n\t\t\t<svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"12\" height=\"12\" fill=\"none\" viewBox=\"0 0 12 12\">\n\t\t\t\t<path fill=\"#fff\" d=\"M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z\" \/>\n\t\t\t<\/svg>\n\t\t<\/button><\/figure>\n\n\n\n<p>Say you have an account on a website called &#8220;ilikecats.com&#8221; and a hacker infiltrates it. Your ilikecats.com account is now compromised. <\/p>\n\n\n\n<p><strong>Step one<\/strong> is to change the password for your email. If you created your ilikecats.com account with your email and reused its password, hackers could compromise your account quickly. This is why you never recycle passwords.<\/p>\n\n\n\n<p><strong>Step two<\/strong> is to change the passwords for all of your accounts where you used the leaked password. Then, change the passwords for all of the accounts you created using that email.<\/p>\n\n\n\n<p><strong>Step three<\/strong> is to enable <a href=\"#JPlink1\">Two-Factor Authentication (2FA)<\/a> for all of your accounts, including the compromised one for ilikecats.com. This will add a layer of security over your password like a one-time password or biometric scan. Adding it over the compromised account may mitigate some damage, but those credentials are likely already available on the dark web.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>How often should you change your password?<\/strong><\/h2>\n\n\n<div class=\"wp-block-image\">\n<figure data-wp-context=\"{&quot;imageId&quot;:&quot;6a2ce0aae1b59&quot;}\" data-wp-interactive=\"core\/image\" data-wp-key=\"6a2ce0aae1b59\" class=\"aligncenter size-full is-resized wp-lightbox-container\"><img loading=\"lazy\" decoding=\"async\" width=\"1380\" height=\"920\" data-wp-class--hide=\"state.isContentHidden\" data-wp-class--show=\"state.isContentVisible\" data-wp-init=\"callbacks.setButtonStyles\" data-wp-on--click=\"actions.showLightbox\" data-wp-on--load=\"callbacks.setButtonStyles\" data-wp-on-window--resize=\"callbacks.setButtonStyles\" src=\"https:\/\/www.magicspam.com\/blog\/wp-content\/uploads\/2024\/03\/change-password.png\" alt=\"guy changing his password in google form\" class=\"wp-image-1855\" style=\"width:656px;height:auto\" srcset=\"https:\/\/www.magicspam.com\/blog\/wp-content\/uploads\/2024\/03\/change-password.png 1380w, https:\/\/www.magicspam.com\/blog\/wp-content\/uploads\/2024\/03\/change-password-300x200.png 300w, https:\/\/www.magicspam.com\/blog\/wp-content\/uploads\/2024\/03\/change-password-1024x683.png 1024w, https:\/\/www.magicspam.com\/blog\/wp-content\/uploads\/2024\/03\/change-password-768x512.png 768w\" sizes=\"auto, (max-width: 1380px) 100vw, 1380px\" \/><button\n\t\t\tclass=\"lightbox-trigger\"\n\t\t\ttype=\"button\"\n\t\t\taria-haspopup=\"dialog\"\n\t\t\taria-label=\"Enlarge\"\n\t\t\tdata-wp-init=\"callbacks.initTriggerButton\"\n\t\t\tdata-wp-on--click=\"actions.showLightbox\"\n\t\t\tdata-wp-style--right=\"state.imageButtonRight\"\n\t\t\tdata-wp-style--top=\"state.imageButtonTop\"\n\t\t>\n\t\t\t<svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"12\" height=\"12\" fill=\"none\" viewBox=\"0 0 12 12\">\n\t\t\t\t<path fill=\"#fff\" d=\"M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z\" \/>\n\t\t\t<\/svg>\n\t\t<\/button><\/figure>\n<\/div>\n\n\n<p>Email password compromise is a real problem, and you should get into the habit of changing your passwords regularly.<\/p>\n\n\n\n<p>Generally, it&#8217;s a good idea to change your email password <strong>once a year<\/strong>. Many businesses advise changing passwords every three months, but if you aren&#8217;t compromised, once a year should be fine. For example, you could change your password when it&#8217;s time to change the batteries in your home smoke detectors! <\/p>\n\n\n\n<p>Record your passwords privately in an encrypted note-taking program or physical notebook \u2014 and don&#8217;t forget to implement <a href=\"#JPlink1\">Two-Factor Authentication<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Why do people use weak passwords? It&#8217;s no secret that most people prioritize convenience over security. When it comes to passwords, people like to use their cat&#8217;s name or their birthday \u2014 something easy to remember. They also don&#8217;t want to remember a bunch of different passwords, so they recycle that same password and use [&hellip;]<\/p>\n","protected":false},"author":6,"featured_media":1753,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[24,16],"tags":[27,26,30,37,29,25,36],"class_list":["post-1458","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-email-security","category-magicspam","tag-authentication","tag-cybersecurity","tag-data-protection","tag-dictionary-words","tag-password-management","tag-password-security","tag-weak-passwords"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v24.3 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Safe vs Weak Passwords - MagicSpam Blog<\/title>\n<meta name=\"description\" content=\"Weak passwords are a problem for email administrators, as well as every other user on the planet. Learn what makes a safe password today.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.magicspam.com\/blog\/safe-vs-common-weak-passwords\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Safe vs Weak Passwords - MagicSpam Blog\" \/>\n<meta property=\"og:description\" content=\"Weak passwords are a problem for email administrators, as well as every other user on the planet. Learn what makes a safe password today.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.magicspam.com\/blog\/safe-vs-common-weak-passwords\/\" \/>\n<meta property=\"og:site_name\" content=\"MagicSpam Business Email Security Blog\" \/>\n<meta property=\"article:published_time\" content=\"2024-03-22T15:57:03+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-04-02T22:41:31+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.magicspam.com\/blog\/wp-content\/uploads\/2024\/03\/safevsweak.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"2560\" \/>\n\t<meta property=\"og:image:height\" content=\"1280\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Curtis Joe\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@magicspam\" \/>\n<meta name=\"twitter:site\" content=\"@magicspam\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Curtis Joe\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.magicspam.com\/blog\/safe-vs-common-weak-passwords\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.magicspam.com\/blog\/safe-vs-common-weak-passwords\/\"},\"author\":{\"name\":\"Curtis Joe\",\"@id\":\"https:\/\/www.magicspam.com\/blog\/#\/schema\/person\/c6cdf8f1780a94f94acfa7fe509e78a6\"},\"headline\":\"Safe vs Weak Passwords: Could you be hacked in the next 5 minutes?\",\"datePublished\":\"2024-03-22T15:57:03+00:00\",\"dateModified\":\"2024-04-02T22:41:31+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.magicspam.com\/blog\/safe-vs-common-weak-passwords\/\"},\"wordCount\":1090,\"publisher\":{\"@id\":\"https:\/\/www.magicspam.com\/blog\/#organization\"},\"image\":{\"@id\":\"https:\/\/www.magicspam.com\/blog\/safe-vs-common-weak-passwords\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.magicspam.com\/blog\/wp-content\/uploads\/2024\/03\/safevsweak.jpg\",\"keywords\":[\"Authentication\",\"Cybersecurity\",\"Data Protection\",\"Dictionary words\",\"Password Management\",\"Password Security\",\"Weak Passwords\"],\"articleSection\":[\"Email Security\",\"MagicSpam\"],\"inLanguage\":\"en-CA\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.magicspam.com\/blog\/safe-vs-common-weak-passwords\/\",\"url\":\"https:\/\/www.magicspam.com\/blog\/safe-vs-common-weak-passwords\/\",\"name\":\"Safe vs Weak Passwords - MagicSpam Blog\",\"isPartOf\":{\"@id\":\"https:\/\/www.magicspam.com\/blog\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.magicspam.com\/blog\/safe-vs-common-weak-passwords\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/www.magicspam.com\/blog\/safe-vs-common-weak-passwords\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.magicspam.com\/blog\/wp-content\/uploads\/2024\/03\/safevsweak.jpg\",\"datePublished\":\"2024-03-22T15:57:03+00:00\",\"dateModified\":\"2024-04-02T22:41:31+00:00\",\"description\":\"Weak passwords are a problem for email administrators, as well as every other user on the planet. Learn what makes a safe password today.\",\"breadcrumb\":{\"@id\":\"https:\/\/www.magicspam.com\/blog\/safe-vs-common-weak-passwords\/#breadcrumb\"},\"inLanguage\":\"en-CA\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.magicspam.com\/blog\/safe-vs-common-weak-passwords\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-CA\",\"@id\":\"https:\/\/www.magicspam.com\/blog\/safe-vs-common-weak-passwords\/#primaryimage\",\"url\":\"https:\/\/www.magicspam.com\/blog\/wp-content\/uploads\/2024\/03\/safevsweak.jpg\",\"contentUrl\":\"https:\/\/www.magicspam.com\/blog\/wp-content\/uploads\/2024\/03\/safevsweak.jpg\",\"width\":2560,\"height\":1280,\"caption\":\"man trying different passwords next to safe versus weak header\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.magicspam.com\/blog\/safe-vs-common-weak-passwords\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.magicspam.com\/blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Safe vs Weak Passwords: Could you be hacked in the next 5 minutes?\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.magicspam.com\/blog\/#website\",\"url\":\"https:\/\/www.magicspam.com\/blog\/\",\"name\":\"MagicSpam Email Security Blog\",\"description\":\"Helping Email Administrators stopping threats\",\"publisher\":{\"@id\":\"https:\/\/www.magicspam.com\/blog\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.magicspam.com\/blog\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-CA\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.magicspam.com\/blog\/#organization\",\"name\":\"mThreat Technologies Inc - MagicSpam Spam and Threat Protection\",\"url\":\"https:\/\/www.magicspam.com\/blog\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-CA\",\"@id\":\"https:\/\/www.magicspam.com\/blog\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.magicspam.com\/blog\/wp-content\/uploads\/2022\/07\/cropped-Logo-3x3x.png\",\"contentUrl\":\"https:\/\/www.magicspam.com\/blog\/wp-content\/uploads\/2022\/07\/cropped-Logo-3x3x.png\",\"width\":853,\"height\":234,\"caption\":\"mThreat Technologies Inc - MagicSpam Spam and Threat Protection\"},\"image\":{\"@id\":\"https:\/\/www.magicspam.com\/blog\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/x.com\/magicspam\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.magicspam.com\/blog\/#\/schema\/person\/c6cdf8f1780a94f94acfa7fe509e78a6\",\"name\":\"Curtis Joe\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-CA\",\"@id\":\"https:\/\/www.magicspam.com\/blog\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/d5e4779861d2377288e005128adc76ff52451e5da0eb250332bafd40d9b6790e?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/d5e4779861d2377288e005128adc76ff52451e5da0eb250332bafd40d9b6790e?s=96&d=mm&r=g\",\"caption\":\"Curtis Joe\"},\"url\":\"https:\/\/www.magicspam.com\/blog\/author\/curtis\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Safe vs Weak Passwords - MagicSpam Blog","description":"Weak passwords are a problem for email administrators, as well as every other user on the planet. Learn what makes a safe password today.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.magicspam.com\/blog\/safe-vs-common-weak-passwords\/","og_locale":"en_US","og_type":"article","og_title":"Safe vs Weak Passwords - MagicSpam Blog","og_description":"Weak passwords are a problem for email administrators, as well as every other user on the planet. Learn what makes a safe password today.","og_url":"https:\/\/www.magicspam.com\/blog\/safe-vs-common-weak-passwords\/","og_site_name":"MagicSpam Business Email Security Blog","article_published_time":"2024-03-22T15:57:03+00:00","article_modified_time":"2024-04-02T22:41:31+00:00","og_image":[{"width":2560,"height":1280,"url":"https:\/\/www.magicspam.com\/blog\/wp-content\/uploads\/2024\/03\/safevsweak.jpg","type":"image\/jpeg"}],"author":"Curtis Joe","twitter_card":"summary_large_image","twitter_creator":"@magicspam","twitter_site":"@magicspam","twitter_misc":{"Written by":"Curtis Joe","Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.magicspam.com\/blog\/safe-vs-common-weak-passwords\/#article","isPartOf":{"@id":"https:\/\/www.magicspam.com\/blog\/safe-vs-common-weak-passwords\/"},"author":{"name":"Curtis Joe","@id":"https:\/\/www.magicspam.com\/blog\/#\/schema\/person\/c6cdf8f1780a94f94acfa7fe509e78a6"},"headline":"Safe vs Weak Passwords: Could you be hacked in the next 5 minutes?","datePublished":"2024-03-22T15:57:03+00:00","dateModified":"2024-04-02T22:41:31+00:00","mainEntityOfPage":{"@id":"https:\/\/www.magicspam.com\/blog\/safe-vs-common-weak-passwords\/"},"wordCount":1090,"publisher":{"@id":"https:\/\/www.magicspam.com\/blog\/#organization"},"image":{"@id":"https:\/\/www.magicspam.com\/blog\/safe-vs-common-weak-passwords\/#primaryimage"},"thumbnailUrl":"https:\/\/www.magicspam.com\/blog\/wp-content\/uploads\/2024\/03\/safevsweak.jpg","keywords":["Authentication","Cybersecurity","Data Protection","Dictionary words","Password Management","Password Security","Weak Passwords"],"articleSection":["Email Security","MagicSpam"],"inLanguage":"en-CA"},{"@type":"WebPage","@id":"https:\/\/www.magicspam.com\/blog\/safe-vs-common-weak-passwords\/","url":"https:\/\/www.magicspam.com\/blog\/safe-vs-common-weak-passwords\/","name":"Safe vs Weak Passwords - MagicSpam Blog","isPartOf":{"@id":"https:\/\/www.magicspam.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.magicspam.com\/blog\/safe-vs-common-weak-passwords\/#primaryimage"},"image":{"@id":"https:\/\/www.magicspam.com\/blog\/safe-vs-common-weak-passwords\/#primaryimage"},"thumbnailUrl":"https:\/\/www.magicspam.com\/blog\/wp-content\/uploads\/2024\/03\/safevsweak.jpg","datePublished":"2024-03-22T15:57:03+00:00","dateModified":"2024-04-02T22:41:31+00:00","description":"Weak passwords are a problem for email administrators, as well as every other user on the planet. Learn what makes a safe password today.","breadcrumb":{"@id":"https:\/\/www.magicspam.com\/blog\/safe-vs-common-weak-passwords\/#breadcrumb"},"inLanguage":"en-CA","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.magicspam.com\/blog\/safe-vs-common-weak-passwords\/"]}]},{"@type":"ImageObject","inLanguage":"en-CA","@id":"https:\/\/www.magicspam.com\/blog\/safe-vs-common-weak-passwords\/#primaryimage","url":"https:\/\/www.magicspam.com\/blog\/wp-content\/uploads\/2024\/03\/safevsweak.jpg","contentUrl":"https:\/\/www.magicspam.com\/blog\/wp-content\/uploads\/2024\/03\/safevsweak.jpg","width":2560,"height":1280,"caption":"man trying different passwords next to safe versus weak header"},{"@type":"BreadcrumbList","@id":"https:\/\/www.magicspam.com\/blog\/safe-vs-common-weak-passwords\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.magicspam.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Safe vs Weak Passwords: Could you be hacked in the next 5 minutes?"}]},{"@type":"WebSite","@id":"https:\/\/www.magicspam.com\/blog\/#website","url":"https:\/\/www.magicspam.com\/blog\/","name":"MagicSpam Email Security Blog","description":"Helping Email Administrators stopping threats","publisher":{"@id":"https:\/\/www.magicspam.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.magicspam.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-CA"},{"@type":"Organization","@id":"https:\/\/www.magicspam.com\/blog\/#organization","name":"mThreat Technologies Inc - MagicSpam Spam and Threat Protection","url":"https:\/\/www.magicspam.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-CA","@id":"https:\/\/www.magicspam.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.magicspam.com\/blog\/wp-content\/uploads\/2022\/07\/cropped-Logo-3x3x.png","contentUrl":"https:\/\/www.magicspam.com\/blog\/wp-content\/uploads\/2022\/07\/cropped-Logo-3x3x.png","width":853,"height":234,"caption":"mThreat Technologies Inc - MagicSpam Spam and Threat Protection"},"image":{"@id":"https:\/\/www.magicspam.com\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/magicspam"]},{"@type":"Person","@id":"https:\/\/www.magicspam.com\/blog\/#\/schema\/person\/c6cdf8f1780a94f94acfa7fe509e78a6","name":"Curtis Joe","image":{"@type":"ImageObject","inLanguage":"en-CA","@id":"https:\/\/www.magicspam.com\/blog\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/d5e4779861d2377288e005128adc76ff52451e5da0eb250332bafd40d9b6790e?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/d5e4779861d2377288e005128adc76ff52451e5da0eb250332bafd40d9b6790e?s=96&d=mm&r=g","caption":"Curtis Joe"},"url":"https:\/\/www.magicspam.com\/blog\/author\/curtis\/"}]}},"_links":{"self":[{"href":"https:\/\/www.magicspam.com\/blog\/wp-json\/wp\/v2\/posts\/1458","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.magicspam.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.magicspam.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.magicspam.com\/blog\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/www.magicspam.com\/blog\/wp-json\/wp\/v2\/comments?post=1458"}],"version-history":[{"count":242,"href":"https:\/\/www.magicspam.com\/blog\/wp-json\/wp\/v2\/posts\/1458\/revisions"}],"predecessor-version":[{"id":2209,"href":"https:\/\/www.magicspam.com\/blog\/wp-json\/wp\/v2\/posts\/1458\/revisions\/2209"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.magicspam.com\/blog\/wp-json\/wp\/v2\/media\/1753"}],"wp:attachment":[{"href":"https:\/\/www.magicspam.com\/blog\/wp-json\/wp\/v2\/media?parent=1458"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.magicspam.com\/blog\/wp-json\/wp\/v2\/categories?post=1458"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.magicspam.com\/blog\/wp-json\/wp\/v2\/tags?post=1458"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}