पाठ 6 / 24

मज़बूत और अनोखे Passwords

लंबे random passwords या passphrases बनाएँ और उन्हें कभी दोहराएँ नहीं।

लंबाई और अनोखापन जीतते हैं

लंबा random password अनुमान लगाना कठिन होता है, पर दोहराव ज़्यादा बड़ा ख़तरा है: एक साइट में सेंध लगे तो हमलावर वही email और password दूसरी साइटों पर आज़माते हैं ("credential stuffing")। Manager से हर account के लिए अलग password बनवाएँ।

CLI से password बनाना

1Password CLI चुनी हुई लंबाई का password बना सकती है। कई random शब्दों वाले याद रखने योग्य passphrases उस एक password के लिए अच्छे हैं जो आपको टाइप करना पड़ता है, जैसे master password।

op item create --category=login --title="Example" \
  --generate-password=24,letters,digits,symbols

Breaches जाँचें

1Password का Watchtower दोहराए, कमज़ोर या breach हुए passwords बताता है। सबसे पुराने और अहम accounts, जैसे email, banking और cloud consoles, पहले ठीक करें।

त्वरित जाँच: अलग-अलग साइटों पर password दोहराना ख़तरनाक क्यों है?

  • साइटें धीमी हो जाती हैं
  • एक साइट में breach से आपके बाक़ी accounts खुल जाते हैं
  • Browsers इसे मना करते हैं
  • यह ज़्यादा storage लेता है
Answer

एक साइट में breach से आपके बाक़ी accounts खुल जाते हैं — हमलावर leak हुए credentials दूसरी services पर आज़माते हैं, इसलिए हर account का अपना password हो।