{"id":23329,"date":"2026-09-29T09:46:24","date_gmt":"2026-09-29T14:46:24","guid":{"rendered":"https:\/\/wp.stolaf.edu\/lits\/?p=23329"},"modified":"2026-09-29T15:24:04","modified_gmt":"2026-09-29T20:24:04","slug":"cybersecurity-awareness-month-week-1-use-strong-passwords-and-a-password-manager","status":"publish","type":"post","link":"https:\/\/wp.stolaf.edu\/lits\/cybersecurity-awareness-month-week-1-use-strong-passwords-and-a-password-manager\/","title":{"rendered":"Cybersecurity Awareness Month Week 1: Use strong passwords and a password manager"},"content":{"rendered":"<div data-modular-content-collection><div class=\"wp-block-image\">\n<figure class=\"alignright size-medium\"><img loading=\"lazy\" decoding=\"async\" width=\"2560\" height=\"2560\" src=\"https:\/\/i0.wp.com\/wp.stolaf.edu\/lits\/files\/2026\/09\/2026-Week-One.jpg?fit=300%2C300&amp;ssl=1\" alt=\"October is Cybersecurity Awareness Month.\" class=\"wp-image-23338\"\/><\/figure>\n<\/div>\n\n\n<p class=\"has-text-align-left wp-block-paragraph\">October is Cybersecurity Awareness Month. While we need to stay vigilant because threats come at us every day and at an alarming rate, this month we join security-minded people worldwide to focus on upping our cybersecurity game. This week we focus on passwords.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">You wouldn\u2019t hand out your house keys to strangers or leave them under the doormat. The same mindset should apply to your digital life. Passwords are still the first line of defense against cybercriminals and data breaches. Yet creating, storing, and remembering dozens (or even hundreds) of them can feel overwhelming. The good news is that with a few simple habits and a password manager, you can take control of your security without the stress.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>The Power of Long, Unique, and Complex Passwords<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">When it comes to passwords, three principles matter most:<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>1. Long<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Longer is stronger. Today, an eight-character password can be cracked in minutes by brute force tools that try every possible combination of letters, numbers, and characters. A 16-character password, by contrast, could take billions of years to guess<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"1024\" src=\"https:\/\/i0.wp.com\/wp.stolaf.edu\/lits\/files\/2026\/09\/HiveSystemsPasswordTable-3YearAnimation.gif?resize=1024%2C1024&#038;ssl=1\" alt=\"HIve Systems Password Complexity Chart\" class=\"wp-image-23332\"\/><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>2. Unique<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Each account should have its own password. Reusing passwords is common, but a very risky practice. If one account is breached, attackers will try to use that same password to access your other accounts. Small tweaks, like adding a number or symbol, aren\u2019t enough. Each password should be completely unique. A password manager makes this easy by generating unique credentials and storing them for you.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>3. Complex<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">You can include a mix of uppercase and lowercase letters, numbers, and special characters to make your password harder to crack. However, password length will drive strength more than complexity.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>+1. Consider Using Passphrases<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Passphrases are short sentences or combinations of words that are easy to remember and type. These are especially helpful for passwords you enter by hand frequently. Every additional letter requires exponentially more effort to crack! So, even without complex characters, they&#8217;re much stronger than short passwords with complexity.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>How Often Should You Change Passwords?<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">For years, the standard advice was to change your passwords regularly\u2014annually or more often. That\u2019s no longer best practice. The National Institute of Standards and Technology (NIST) now recommends changing your password only if you suspect unauthorized access or if the account is involved in a breach.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Why? Because frequent forced changes lead to bad habits\u2014like recycling old passwords or creating simple ones you can easily remember. Instead, create long, strong, unique passwords and update them only when necessary.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Why Password Managers Are a Game-Changer<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The advice above probably sounds daunting if you\u2019re managing passwords on your own. The reality is that most of us have so many accounts that keeping track of them is a challenge. A password manager solves this problem.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">With a password manager, you only need to remember one master password. The manager securely stores the rest in an encrypted vault. Password managers can also automatically generate strong, random passwords for every account and autofill them when you log in.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Here\u2019s why a password manager is worth adopting:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\" style=\"text-indent:12px\"><strong>Convenience:<\/strong> No more memorizing dozens of passwords.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\" style=\"text-indent:12px\"><strong>Security: <\/strong>Automatically generates long, unique, complex passwords.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\" style=\"text-indent:12px\"><strong>Time-Saving:<\/strong> Autofill features make logging in quick and secure.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\" style=\"text-indent:12px\"><strong>Encrypted Vaults: <\/strong>High-quality managers use strong encryption and \u201czero-knowledge\u201d architecture, meaning even the provider can\u2019t see your passwords.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Password managers are much safer than notebooks, sticky notes, spreadsheets, or trying to remember passwords yourself. They also reduce your risk if one account is breached\u2014because every other password is unique.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>About Passkeys<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Passkeys represent the next evolutionary leap in authentication, replacing traditional passwords entirely with a faster, virtually uncrackable alternative. Built on robust public-key cryptography, a passkey pairs a public key stored on a website&#8217;s server with a private key locked securely inside your physical device or password manager. Logging in requires no memorization or typing\u2014just a quick biometric check like Face ID, Touch ID, or your device password or PIN. Crucially, passkeys are cryptographically bound to the legitimate domain, making them inherently immune to phishing attacks because a spoofed site simply cannot trick your device into surrendering access. Since servers never hold your secret key, a data breach at a vendor leaves hackers with zero actionable credentials, delivering the rare cybersecurity trifecta of superior protection, zero password fatigue, and frictionless convenience.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>About Federated Login<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Federated login\u2014such as &#8220;Sign in with Google, Apple, or Microsoft&#8221;\u2014is one of the simplest ways to boost your online security while reducing complexity. By consolidating your access behind trusted identity providers, you eliminate password fatigue and curb the dangerous habit of reusing credentials across multiple websites. Crucially, federated authentication relies on secure digital tokens rather than sharing raw credentials; the destination site never receives, sees, or stores your password. If that site suffers a data breach, attackers leave empty-handed because their servers never stored your password to steal in the first place. Additionally, federated login lets everyday web services piggyback on enterprise-grade security features\u2014such as real-time threat detection, biometric passkeys, and robust Multi-Factor Authentication (MFA)\u2014so a single, tightly fortified front door protects access to several services.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Taking the First Step<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Passwords may never feel fun, but they don\u2019t need to be overwhelming. Start by choosing a password manager and securing your most important accounts (email, banking, social media). From there, you\u2019ll find that keeping your digital life secure becomes much easier.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">By using long, unique, and complex passwords, you\u2019re taking one of the most effective steps available to protect your identity and data. Small actions like this add up to a big impact in cybersecurity.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Want to learn more? <\/strong>Check out this article at staysafeonline.org. (<a href=\"https:\/\/www.staysafeonline.org\/articles\/passwords\">https:\/\/www.staysafeonline.org\/articles\/passwords<\/a>)<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Remember\u2026<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>About phishing simulations. <\/strong>We\u2019ll conduct two phishing simulations for students in October and November. Phishing simulations for employees will continue at the monthly cadence we started in the spring. As always, if you see unusual or suspicious emails, report them as you would any other spam or phishing messages. Your vigilance keeps our community safer.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Get your cybersecurity training done.<\/strong> We aim for all faculty, staff, and first-year students to complete Cybersecurity 101 by the end of the month. It doesn\u2019t take long! Employees who complete the training by the end of October will be entered into a drawing for a $20 Bon App\u00e9tit gift card. Separate courses for <a href=\"https:\/\/mdl.stolaf.edu\/course\/view.php?id=67132\">students<\/a>&nbsp;and&nbsp;<a href=\"https:\/\/mdl.stolaf.edu\/course\/view.php?id=66698\">employees <\/a>can be found in Moodle.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Our online Cybersecurity Town Hall is on October 26.&nbsp;<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"800\" height=\"520\" class=\"wp-image-23335\" style=\"width: 800px;\" src=\"https:\/\/i0.wp.com\/wp.stolaf.edu\/lits\/files\/2026\/09\/october-graphic-vfinal-no-border.gif?resize=800%2C520&#038;ssl=1\" alt=\"\"\/><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Join Kendall George, information security officer for Carleton and St. Olaf Colleges, at our annual <strong><em>Cybersecurity Town Hall: Cybermaxxing to Securitymog the Ops. <\/em><\/strong>This engaging, interactive session will describe the current state of cyberthreats in higher education and the steps you can take to keep both campus and your own digital life secure. There will be ample time for questions and answers.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/wp.stolaf.edu\/calendar\/event\/cybersecurity-town-hall-cybermaxxing-to-securitymog-the-ops\/\">\ud83d\udcc5 Monday, October 26 at noon<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Stay safe out there.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Kendall George<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Information Security Officer<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Carleton and St. Olaf Colleges<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>October is Cybersecurity Awareness Month. While we need to stay vigilant because threats come at us every day and at an alarming rate, this month we join security-minded people worldwide [&hellip;]<\/p>\n","protected":false},"author":3478,"featured_media":23338,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_spp_custom_css":"","footnotes":"","_members_access_role":[],"_members_access_error":""},"categories":[31,29],"tags":[],"class_list":["post-23329","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","category-it"],"acf":[],"jetpack_featured_media_url":"https:\/\/i0.wp.com\/wp.stolaf.edu\/lits\/files\/2026\/09\/2026-Week-One.jpg?fit=2560%2C2560&ssl=1","_links":{"self":[{"href":"https:\/\/wp.stolaf.edu\/lits\/wp-json\/wp\/v2\/posts\/23329","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wp.stolaf.edu\/lits\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/wp.stolaf.edu\/lits\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/wp.stolaf.edu\/lits\/wp-json\/wp\/v2\/users\/3478"}],"replies":[{"embeddable":true,"href":"https:\/\/wp.stolaf.edu\/lits\/wp-json\/wp\/v2\/comments?post=23329"}],"version-history":[{"count":17,"href":"https:\/\/wp.stolaf.edu\/lits\/wp-json\/wp\/v2\/posts\/23329\/revisions"}],"predecessor-version":[{"id":23372,"href":"https:\/\/wp.stolaf.edu\/lits\/wp-json\/wp\/v2\/posts\/23329\/revisions\/23372"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/wp.stolaf.edu\/lits\/wp-json\/wp\/v2\/media\/23338"}],"wp:attachment":[{"href":"https:\/\/wp.stolaf.edu\/lits\/wp-json\/wp\/v2\/media?parent=23329"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/wp.stolaf.edu\/lits\/wp-json\/wp\/v2\/categories?post=23329"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/wp.stolaf.edu\/lits\/wp-json\/wp\/v2\/tags?post=23329"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}