What the password and login should look like. What is login and password? Why do you need a login, how to come up with one

Today I want to touch on a very important topic that concerns any user who works on a computer and has access to the Internet.

And this topic concerns passwords that we are required to enter in almost all services, from email and social networks to a personal account on the government services website.

And, although the password policy on many sites may differ slightly (which characters can be entered when entering a password and which cannot), all services without exception insist that we use complex passwords.

Very often we simply ignore this warning. Why? In my opinion, for two reasons.

The first reason is simply laziness.

Well, the second reason, rather, partially follows from the first. It's much easier for us to remember simple password "123456 " or "qwerty", since it is simple and convenient for us to press 6 keys in succession rather than remember difficult type password "!QjhRt^&018@asW", consisting of 15 characters ( , numbers and special characters). Moreover special characters for this password ( !^& And @ ) you still need to find it on the keyboard, which is not always possible the first, second, and sometimes even the tenth time (your humble servant is no exception to this rule).

So why do you need to enter complex passwords? How to make a complex password so that it is easy to remember?
I want to talk to you about this and much more in this lesson.

First, about logins

The Internet is remarkable in that we ourselves can come up with a “name” under which, firstly, we will be recognized on the Internet, and secondly, we will be entered into forms in which we are asked to enter our username and password.

This could be your real name, or it could be something original that you came up with.

There are some problems with real names on the Internet today. Real names are practically all taken. What does "busy" mean?

One illustrative example is creating an email account on any email service.

For example, I want to create a mailbox on the yandex.ru mail service. And I want my email address to be [email protected].

Beautiful, understandable, recognizable and easy to remember.

I'm trying to do this. I enter it into the field “Create a login” your name in Latin - Oleg.

The service tells me that "Sorry, login is busy". And it offers me 10 options for free logins.

But all of them do not suit me for one simple reason - they are too long. Moreover, it asks you to enter your mobile phone number as a unique login. It turns out that everyone who receives my letters will know my mobile phone number. Is this what you want? For example, I don't want to.

OK then. I’ll overcome my laziness and bias towards long logins and add my last name with a dot. Judging by the options offered by the service, you can use the dot in the login. I enter Oleg.Ivashinenko.

The result is similar to the previous one. It turns out that there is already an account on the Yandex mail service with the same first and last name.

This means I need to come up with my own unique name, which, most importantly, I liked myself.

At one time, I racked my brain for a long time on how to come up with a name for myself so that I would definitely not forget it and so that it would be more or less sonorous.

In the end, I took the first two letters of my first and last name and got Nick(nickname - from the English nickname, which means “another name”, “pseudonym”) oliv.

But over time, this nickname was also occupied by the services where I registered. Then I added two more letters from my middle name and it turned out to be a nickname olivur.

For the last 10 years I have used this nickname during registrations without any problems. So if I have a postal email address in the form [email protected], that will also be good.

I enter into the form my original, as I believe, login “olivur”.

Busy too. I don't want to give up. I add the magic seven to the name.

Everything worked out. Basically, the email address [email protected] looks good too. You can continue registration.

True, I won’t do this, since I already have 2 mailboxes on Yandex. Enough for now. Let's move on to passwords.

I have nothing to hide. I'm an honest person.

Very often on various forums, especially on forums on computer and Internet security, I often come across comments like “I have nothing to hide. I'm an honest person."

And, although I usually don’t comment on such statements, one time I still couldn’t stand it and wrote something like this: “Well, since you have nothing to hide and you are an honest person, then write your login And password from this forum where we communicate."

Do you think there was a response to my comment? Right. There wasn't. This means there is something to hide. And if there is something to hide, then in the context of this phrase the forum member is no longer an honest person.

Okay, this is all sophistry.

In fact, all information relating to each user should still remain confidential. Starting from the passport number and TIN to the email address, as well as logins and passwords for various resources and services on the Internet.

At the initial stage of mastering a computer, it is really difficult to understand why confidentiality is needed. But with time, understanding will come.

Let me give you a few of my own examples.

For the second year now I have not gone to the post office or Sberbank to pay utility bills.

I make all payments from home using my home computer. These are the so-called online services of various banks.

Russian Standard Bank calls its service “Bank in your pocket”, VTB24 calls it “Telebank”, etc. And, although the names may be different, the essence is the same - everything is very convenient and transparent.

To conduct financial transactions, I have three plastic cards - salary, debit and credit.

I use the debit card as a “passbook” and very rarely pay in the store. Very convenient. There are no fees for maintaining cards or accounts. Well, interest also accrues on the accumulated funds.

I pay all payments using my salary card. Well, if suddenly the time comes to pay the receipt, and there is nothing on the salary card, then I pay with a credit card. Well, from my next paycheck I’ll transfer the required amount to my credit card so that no interest is charged.

So why am I telling all this?

I do all this (payment of utility bills using ready-made templates, transfer of money from account to account) in the personal accounts of the relevant banks. Well, access to these personal accounts carried out according to logins and passwords.

Since this is my personal finance, I am very keen that no one except me knows my credentials in these banks. And, although when performing financial transactions banks require confirmation codes, which they send me via SMS to my mobile phone, my passwords are quite complex.

And, although, just in case, they are written down in my , I remember these passwords. But more on that a little later.

Another illustrative example.

Just recently I registered on the government services website. It turned out to be quite an interesting and necessary portal for me, at least.

I was surprised to discover that I had a tax debt. But the surprise quickly passed, as I remembered that I paid the land tax too late. And I got a penalty. My debt to the state a month ago was already 12 rubles. 75 kop.

At the same time, I looked to see if I had any traffic fines. It turned out that there is one. Although I have not yet received any paper by mail.

Although I’m not going abroad yet, I still paid off these debts so that my soul would be at peace.

The resource turned out to be interesting. You can easily get a foreign passport, register your car, enroll your child in kindergarten, etc. etc.

So, as login this resource uses the number SNILS A. This login is truly unique and only I know it.

SNILS is the Insurance Number of the Individual Personal Account of the insurance certificate of the state pension insurance. Well, so that no one had access to my personal information, I had to come up with a really complex but memorable password.

How passwords are cracked

I'm not a hacker or a computer security expert. But I am familiar with the basic principles of information security. And you should know them. This will help save a lot of nerve cells in the future.

I will not deny that a hacker (the largest specialist in the field of computer system security), if he wants to hack your computer, will do it. Provided, of course, that you yourself are not an expert in this field.

One thing consoles me. To be honest, neither you nor I are needed by hackers at all. Take my word for it. They have global interests.

But as for us mere mortals, quite common programs on the Internet work with us and are available to any user.

I have already described how such programs get onto our computers in the lesson “”. Therefore, I will not repeat myself.

Now I want to tell you about one of the types of such programs that select passwords on various information resources.

This type of program is called "Brutforce". This name comes from a combination of two English words "brute force" , which mean "Total overkill" or "Brute force method".

Such password guessing programs use special "dictionaries". What are "dictionaries"?

A “dictionary” is a regular text file (or several files), each line of which contains a “word”. For example:


So here it is. Such programs take each “word” from such a “dictionary” in turn and substitute it in the password field until this “word” matches the “word” you created that you use as a password.

Depending on the complexity of your password, such a program may take from a few seconds to hundreds of years. Or maybe he won’t be able to pick it up at all.

So if you have a password "qwerty" or, let's say "z,kjrj"(word "apple", typed in English), then this type of program will take seconds to guess the password.

So what to do? How do you know how simple or complex your password is?

In fact, it's not all doom and gloom.

Coming up with a complex password

Computer security specialists are also not sitting idle. They conduct ongoing analysis of various malware. In particular, programs like “Brute force”.

And at the moment there are already a lot of resources on the Internet where you can check the uniqueness of your password.

Let's use one of these resources as an example and see how to create a “complex” but easy-to-remember password.

Let’s choose http://password.ru/ as such a resource (More services for checking password strength: 2ip.ru, howsecureismypassword.net)

Another resource, the link to which was sent to me by reader Mary: https://ru.vpnmentor.com

I will tell you about one of the algorithms. But you can show your imagination and come up with your own algorithm.

Let, for example, your name is Ivanov Ivan Ivanovich. We “come up” with a password based on our last name, since we definitely remember this word from childhood - ivanov

Judging by the site's response, cracking such a password will take less than a second. Add an exclamation point (or any other special character) before the last name - !ivanov

Already better. To crack such a password, the program will need 12 minutes 57 seconds.

Add an exclamation point after the last name - !ivanov!

The result is also not a very complex password, which can be cracked in 12 hours and 31 minutes.

Add the numbers 12345 to the end - !ivanov!12345

As you can see from the message, such a password can be cracked in 7 and a half million years.

Although the password turned out to be complex, it is quite easy to remember. These are roughly the same algorithms for creating passwords that I use myself.

There is another option for creating complex passwords that are easy to remember.

For example, this morning before work, the cartoon “The Scarlet Flower” was shown on TV. Why not a password? Easy to remember.

But, of course, it is not advisable to leave such a password. Let's change it. Let's type the name of the cartoon in English case with a small letter without a space: fktymrbqwdtnjxtr and check it on the website.

It would take about half a million years to crack such a password.

As you can see, it is not at all difficult to come up with a complex, easy-to-remember password.

That's all for today. Good luck and creative success to everyone. 🙂

Oleg Ivashinenko

Oleg Ivashinenko

