1
00:00:00,000 --> 00:00:00,833
In this lesson,

2
00:00:00,833 --> 00:00:03,180
we're going to discuss password security.

3
00:00:03,180 --> 00:00:05,370
Password security is a measure of the effectiveness

4
00:00:05,370 --> 00:00:08,790
of a password in resisting guessing and brute-force attacks.

5
00:00:08,790 --> 00:00:09,900
In this user form,

6
00:00:09,900 --> 00:00:11,460
password security is used to estimate

7
00:00:11,460 --> 00:00:13,020
how many attempts an attacker

8
00:00:13,020 --> 00:00:15,300
who does not have direct access to the password

9
00:00:15,300 --> 00:00:17,220
may receive to guess it correctly.

10
00:00:17,220 --> 00:00:19,260
For us to create our password policies,

11
00:00:19,260 --> 00:00:21,540
we're going to use the group policy editor.

12
00:00:21,540 --> 00:00:23,400
I'm using a Windows 11 machine here

13
00:00:23,400 --> 00:00:26,220
on a local computer network that's not part of domain.

14
00:00:26,220 --> 00:00:27,900
Using a domain environment,

15
00:00:27,900 --> 00:00:30,120
you can use your global policy orchestrator,

16
00:00:30,120 --> 00:00:31,410
but for a local machine,

17
00:00:31,410 --> 00:00:34,350
we're going to stick with the local group policy editor.

18
00:00:34,350 --> 00:00:35,340
Now, to do this,

19
00:00:35,340 --> 00:00:37,260
we're going to simply search "gpedit"

20
00:00:37,260 --> 00:00:38,860
in the search bar at the bottom.

21
00:00:47,790 --> 00:00:48,810
Now on the screen,

22
00:00:48,810 --> 00:00:49,643
we just need to go

23
00:00:49,643 --> 00:00:52,200
to the Computer Configuration setting at the top,

24
00:00:52,200 --> 00:00:54,540
and then we're going to click the Windows Setting.

25
00:00:54,540 --> 00:00:57,390
Next we're going to go to the Security Settings,

26
00:00:57,390 --> 00:01:01,050
Account Policies, and then Password Policy.

27
00:01:01,050 --> 00:01:03,330
Now, you'll see that there are several different settings

28
00:01:03,330 --> 00:01:05,430
here that relate to the five characteristics

29
00:01:05,430 --> 00:01:06,960
that you need to consider when managing

30
00:01:06,960 --> 00:01:08,760
your organization's password policies,

31
00:01:08,760 --> 00:01:11,490
including password length, password complexity,

32
00:01:11,490 --> 00:01:15,420
password reuse, password expiration, and the password age.

33
00:01:15,420 --> 00:01:17,430
First, we have the password length.

34
00:01:17,430 --> 00:01:20,580
The longer password is, the harder it will be to crack.

35
00:01:20,580 --> 00:01:21,570
For best security,

36
00:01:21,570 --> 00:01:23,040
your password should be at least 12

37
00:01:23,040 --> 00:01:24,750
to 16 characters in length.

38
00:01:24,750 --> 00:01:26,624
After all, the longer the password

39
00:01:26,624 --> 00:01:27,630
and an attack method that says

40
00:01:27,630 --> 00:01:29,520
a lot more different passwords,

41
00:01:29,520 --> 00:01:32,010
which will ultimately slow down their ability

42
00:01:32,010 --> 00:01:33,570
to compromise your password.

43
00:01:33,570 --> 00:01:36,180
For example, if we use a simple seven-letter word

44
00:01:36,180 --> 00:01:37,950
of pencils as our password,

45
00:01:37,950 --> 00:01:40,260
this will only take about 0.4 seconds

46
00:01:40,260 --> 00:01:41,973
to crack it in a modern laptop.

47
00:01:42,810 --> 00:01:44,610
But if we were to change it

48
00:01:44,610 --> 00:01:46,710
to something like PencilsAreForWriting,

49
00:01:46,710 --> 00:01:48,570
then now that's 20 characters

50
00:01:48,570 --> 00:01:50,460
and it would take about two months if we were conducting

51
00:01:50,460 --> 00:01:53,190
a brute-force attack on a modern laptop.

52
00:01:53,190 --> 00:01:55,920
Length is an important characteristic of strong password

53
00:01:55,920 --> 00:01:57,840
because every additional character

54
00:01:57,840 --> 00:02:00,600
exponentially increases your password security.

55
00:02:00,600 --> 00:02:01,433
For example,

56
00:02:01,433 --> 00:02:02,880
let's take this simple example

57
00:02:02,880 --> 00:02:05,520
of creating a pin to protect your smartphone.

58
00:02:05,520 --> 00:02:07,440
Most smartphones will let you set a PIN

59
00:02:07,440 --> 00:02:11,009
either four, five, six, seven, or eight digits in length.

60
00:02:11,009 --> 00:02:13,200
If we opt to only use a four-digit PIN,

61
00:02:13,200 --> 00:02:15,420
we only have 10,000 possible combinations,

62
00:02:15,420 --> 00:02:19,410
ranging from 0000 to 9,999.

63
00:02:19,410 --> 00:02:23,640
This is because a PIN can only have the digits zero to nine,

64
00:02:23,640 --> 00:02:26,520
which gives us 10 options per digit chosen.

65
00:02:26,520 --> 00:02:29,250
So if we choose a four-digit PIN,

66
00:02:29,250 --> 00:02:33,240
we have 10 times 10, times 10, times 10,

67
00:02:33,240 --> 00:02:37,680
or 10 to the fourth power, or 10,000 options.

68
00:02:37,680 --> 00:02:41,400
If I simply add one more digit to the chosen five-digit pin,

69
00:02:41,400 --> 00:02:43,920
I will have increased the password length by just one digit,

70
00:02:43,920 --> 00:02:46,470
but now I have expanded my options

71
00:02:46,470 --> 00:02:50,490
from 10 to the fourth power to 10 to the fifth power,

72
00:02:50,490 --> 00:02:53,040
or 100,000 choices.

73
00:02:53,040 --> 00:02:55,230
If I continue to add another digit,

74
00:02:55,230 --> 00:02:58,590
each digit will add 10x more choices for us.

75
00:02:58,590 --> 00:03:02,130
So if we opt for the maximum pin size of eight digits,

76
00:03:02,130 --> 00:03:05,070
this gives us 100 million choices.

77
00:03:05,070 --> 00:03:06,540
Now, you can see though,

78
00:03:06,540 --> 00:03:08,400
even though we've only doubled our length

79
00:03:08,400 --> 00:03:10,110
from four to eight digits,

80
00:03:10,110 --> 00:03:12,780
we actually increase our possible PIN choice

81
00:03:12,780 --> 00:03:16,200
from 10,000 choices to 100,000,000 choices,

82
00:03:16,200 --> 00:03:18,840
which is 10,000 times more options

83
00:03:18,840 --> 00:03:21,630
by simply adding four more digits to our password length.

84
00:03:21,630 --> 00:03:23,700
This is why we say increasing length

85
00:03:23,700 --> 00:03:25,860
is increasing your security.

86
00:03:25,860 --> 00:03:28,560
For this example, we will set it to 14.

87
00:03:28,560 --> 00:03:30,090
To adjust it to higher than that,

88
00:03:30,090 --> 00:03:33,000
we must change the relaxed minimum password length limits,

89
00:03:33,000 --> 00:03:36,540
which is there to help with compatibility in legacy systems.

90
00:03:36,540 --> 00:03:41,540
Let's go to minimum password length, 14, Apply.

91
00:03:41,880 --> 00:03:43,080
Now just to point out,

92
00:03:43,080 --> 00:03:44,130
what was I referencing

93
00:03:44,130 --> 00:03:46,013
about the relaxed minimum password length?

94
00:03:46,013 --> 00:03:47,520
There's this option here.

95
00:03:47,520 --> 00:03:50,460
As you read it, has a little warning though,

96
00:03:50,460 --> 00:03:53,100
saying, "Modifying this setting may affect compatibility

97
00:03:53,100 --> 00:03:56,040
with clients, services, and applications."

98
00:03:56,040 --> 00:03:59,100
So in order to change this, you must enable it.

99
00:03:59,100 --> 00:04:00,120
Now, when you enable it,

100
00:04:00,120 --> 00:04:02,370
it allows you to increase the password length

101
00:04:02,370 --> 00:04:04,350
beyond the 14 characters.

102
00:04:04,350 --> 00:04:07,020
If you click this Explain, they give you more details here.

103
00:04:07,020 --> 00:04:10,290
Second, we need to consider the password complexity.

104
00:04:10,290 --> 00:04:13,200
Password complexity refers to the use of a combination

105
00:04:13,200 --> 00:04:15,780
of uppercase and lowercase letters, numbers,

106
00:04:15,780 --> 00:04:18,000
and special characters in the password.

107
00:04:18,000 --> 00:04:19,380
The more complex the password,

108
00:04:19,380 --> 00:04:22,350
the harder it will be to guess using a brute-force attack.

109
00:04:22,350 --> 00:04:23,640
If we use a PIN,

110
00:04:23,640 --> 00:04:25,560
we only have 10 character choices

111
00:04:25,560 --> 00:04:27,210
that we can use for each digit of a PIN

112
00:04:27,210 --> 00:04:30,300
because each digit can either be zero, one,

113
00:04:30,300 --> 00:04:35,300
two, three, four, five, six, seven, eight, or nine.

114
00:04:36,630 --> 00:04:39,900
So if I use a four-digit password only using numbers,

115
00:04:39,900 --> 00:04:42,360
then I have 10,000 possible choices

116
00:04:42,360 --> 00:04:45,573
or 10 times 10, times 10, times 10.

117
00:04:46,440 --> 00:04:49,740
Now, if I wanted to use lowercase letters instead

118
00:04:49,740 --> 00:04:52,800
and still use a four-character password,

119
00:04:52,800 --> 00:04:55,890
I would have 26 letter options for each character

120
00:04:55,890 --> 00:05:00,300
or 26 times 26, times 26, times 26,

121
00:05:00,300 --> 00:05:05,010
which equals 456,976 choices.

122
00:05:05,010 --> 00:05:08,340
So just switching from numbers to lowercase letters

123
00:05:08,340 --> 00:05:10,800
gives me more than a 40x the number

124
00:05:10,800 --> 00:05:13,380
of possible four-character passwords.

125
00:05:13,380 --> 00:05:16,200
But if we add in uppercase,

126
00:05:16,200 --> 00:05:20,970
we move the 26 choice options to 52 options per character.

127
00:05:20,970 --> 00:05:22,800
For a four-character password,

128
00:05:22,800 --> 00:05:25,320
this gives us 52 to the power of four

129
00:05:25,320 --> 00:05:29,820
or 7,311,616 choices,

130
00:05:29,820 --> 00:05:33,570
which is now 731 times more options

131
00:05:33,570 --> 00:05:35,793
than our original four-digit PIN.

132
00:05:36,690 --> 00:05:39,960
But in most of our modern authentication systems,

133
00:05:39,960 --> 00:05:41,820
we don't just use letters or numbers.

134
00:05:41,820 --> 00:05:44,610
We use lowercase letters, uppercase letters,

135
00:05:44,610 --> 00:05:46,590
numbers, and special characters.

136
00:05:46,590 --> 00:05:49,170
This means that we have 26 lowercase letters,

137
00:05:49,170 --> 00:05:51,930
26 uppercase letters, 10 numbers,

138
00:05:51,930 --> 00:05:53,820
and usually around 10 special characters,

139
00:05:53,820 --> 00:05:56,580
like the plus sign, minus sign, period, exclamation point,

140
00:05:56,580 --> 00:05:59,310
hashtag, asterisk, and things like that.

141
00:05:59,310 --> 00:06:02,760
So if we use all four of these character types,

142
00:06:02,760 --> 00:06:05,070
we no longer just have 10,000 combination

143
00:06:05,070 --> 00:06:07,500
using our four-digit numeric password,

144
00:06:07,500 --> 00:06:11,730
but we can now have a password like aW3+,

145
00:06:11,730 --> 00:06:13,170
which is considered to be complex

146
00:06:13,170 --> 00:06:15,777
since it has lowercase letter, an uppercase letter,

147
00:06:15,777 --> 00:06:18,270
a number and a special symbol.

148
00:06:18,270 --> 00:06:20,850
This gives us 72 characters that could be used

149
00:06:20,850 --> 00:06:23,490
in each of the four characters in the password,

150
00:06:23,490 --> 00:06:25,860
or 72 to the fourth power,

151
00:06:25,860 --> 00:06:30,510
which is 26,873,856.

152
00:06:30,510 --> 00:06:34,500
This is 2,687 times more secure

153
00:06:34,500 --> 00:06:37,980
and complex than using just a four-digit PIN.

154
00:06:37,980 --> 00:06:41,610
So instead of using a long string of dictionary words

155
00:06:41,610 --> 00:06:44,100
like PencilsAreForWriting that would only take

156
00:06:44,100 --> 00:06:47,130
about two months to crack using a brute-force attack,

157
00:06:47,130 --> 00:06:49,110
we could change out some of the letters

158
00:06:49,110 --> 00:06:51,450
for numbers and add a special character to,

159
00:06:51,450 --> 00:06:52,780
such as p3nc

160
00:06:55,683 --> 00:06:56,516
1l5Ar3

161
00:07:00,939 --> 00:07:01,772
F0r

162
00:07:03,976 --> 00:07:04,809
Wr1

163
00:07:07,373 --> 00:07:11,820
t1ng!

164
00:07:11,820 --> 00:07:14,460
which would take about 15 years to crack

165
00:07:14,460 --> 00:07:17,313
using a brute-force technique on a modern laptop.

166
00:07:19,290 --> 00:07:20,430
Now to demonstrate this,

167
00:07:20,430 --> 00:07:21,510
we're simply just going

168
00:07:21,510 --> 00:07:24,273
to enable the password complexity requirements.

169
00:07:25,110 --> 00:07:27,750
Windows has a built in default complexity requirement

170
00:07:27,750 --> 00:07:29,700
that you don't have to configure specifically.

171
00:07:29,700 --> 00:07:33,540
So if you go to explanation, here are the rules here.

172
00:07:33,540 --> 00:07:35,670
Okay? All right.

173
00:07:35,670 --> 00:07:38,400
Third, we have to consider password reuse.

174
00:07:38,400 --> 00:07:41,310
Password reuse is the practice of using the same password

175
00:07:41,310 --> 00:07:43,680
across multiple different accounts or applications,

176
00:07:43,680 --> 00:07:45,330
which increases vulnerabilities

177
00:07:45,330 --> 00:07:47,700
because one compromised password can lead

178
00:07:47,700 --> 00:07:49,770
to multiple accounts being breached.

179
00:07:49,770 --> 00:07:51,540
You should always avoid reusing

180
00:07:51,540 --> 00:07:53,460
passwords across different accounts.

181
00:07:53,460 --> 00:07:56,670
Another way that people consider a password to be reused

182
00:07:56,670 --> 00:07:58,920
is if a formal password is used again

183
00:07:58,920 --> 00:08:01,530
with the same application or website.

184
00:08:01,530 --> 00:08:02,363
For example,

185
00:08:02,363 --> 00:08:04,320
if you tried to log into Facebook this morning

186
00:08:04,320 --> 00:08:05,910
but you forgot your password,

187
00:08:05,910 --> 00:08:07,590
you may well need to change it.

188
00:08:07,590 --> 00:08:09,600
Now, let's pretend your original password,

189
00:08:09,600 --> 00:08:11,880
which you forgot, is Password1.

190
00:08:11,880 --> 00:08:14,220
Well, using the password reset function,

191
00:08:14,220 --> 00:08:15,540
you choose a new password,

192
00:08:15,540 --> 00:08:18,930
and we'll call this Password2 for our example.

193
00:08:18,930 --> 00:08:21,450
A few weeks go by and you forgot your password again,

194
00:08:21,450 --> 00:08:23,820
so you reset it to Password3.

195
00:08:23,820 --> 00:08:25,200
Now, you really want to set

196
00:08:25,200 --> 00:08:26,670
your password back to Password1,

197
00:08:26,670 --> 00:08:29,610
but the system is designed to remember your password history

198
00:08:29,610 --> 00:08:31,920
and it won't let you reuse the same password,

199
00:08:31,920 --> 00:08:33,510
Password1, in this case,

200
00:08:33,510 --> 00:08:35,970
until you have changed your password at least five times.

201
00:08:35,970 --> 00:08:37,770
This is known as the password history

202
00:08:37,770 --> 00:08:41,250
or number of new passwords that must have been created

203
00:08:41,250 --> 00:08:44,070
before you can reuse an older password.

204
00:08:44,070 --> 00:08:46,100
I have seen many people who really, really want

205
00:08:46,100 --> 00:08:48,240
to set their password back to the same one,

206
00:08:48,240 --> 00:08:50,730
and what they will usually do in this situation

207
00:08:50,730 --> 00:08:53,340
is simply reset their password five times

208
00:08:53,340 --> 00:08:55,920
until they can rotate back to their original password.

209
00:08:55,920 --> 00:08:57,960
The problem with this is if the password is

210
00:08:57,960 --> 00:08:59,820
more than 90 days old,

211
00:08:59,820 --> 00:09:03,030
it has a very high chance of being cracked by an attacker.

212
00:09:03,030 --> 00:09:04,020
Many times,

213
00:09:04,020 --> 00:09:05,460
password cracking can take anywhere

214
00:09:05,460 --> 00:09:08,280
from three to six months depending on the password strength.

215
00:09:08,280 --> 00:09:10,560
So if you recycle an old password,

216
00:09:10,560 --> 00:09:11,940
the attacker may have been able

217
00:09:11,940 --> 00:09:13,650
to crack it since you last used it,

218
00:09:13,650 --> 00:09:16,830
and you're now going to be vulnerable to that attack again.

219
00:09:16,830 --> 00:09:17,663
Now, to do that,

220
00:09:17,663 --> 00:09:20,400
we're going to simply go to the enforce password history,

221
00:09:20,400 --> 00:09:23,643
and we're going to set it to the maximum, which is going to be 24.

222
00:09:25,860 --> 00:09:27,270
So that means that a user will have

223
00:09:27,270 --> 00:09:29,640
to reset their password 24 times

224
00:09:29,640 --> 00:09:32,310
before they can use the original password.

225
00:09:32,310 --> 00:09:35,190
Fourth, we have password expiration.

226
00:09:35,190 --> 00:09:37,980
Password expiration is a policy that requires users

227
00:09:37,980 --> 00:09:40,380
to change their password after a certain period.

228
00:09:40,380 --> 00:09:41,213
For instance,

229
00:09:41,213 --> 00:09:43,800
a company might have a policy that requires all employees

230
00:09:43,800 --> 00:09:46,050
to change their password every 90 days.

231
00:09:46,050 --> 00:09:47,610
When the 90 day period is up,

232
00:09:47,610 --> 00:09:51,120
the password expires and a new one must be set.

233
00:09:51,120 --> 00:09:53,670
However, this practice is being reconsidered

234
00:09:53,670 --> 00:09:55,620
as it often leads to poor passwords,

235
00:09:55,620 --> 00:09:58,050
since many people have difficulty remembering

236
00:09:58,050 --> 00:10:00,750
a lot of long, strong and complex passwords.

237
00:10:00,750 --> 00:10:04,410
So they tend to reuse the same one across multiple sites

238
00:10:04,410 --> 00:10:06,450
or simply do some keyboard walking

239
00:10:06,450 --> 00:10:10,050
to add something to the end of some basic password.

240
00:10:10,050 --> 00:10:10,950
For example,

241
00:10:10,950 --> 00:10:13,710
you might use DionTraining1 as your first password,

242
00:10:13,710 --> 00:10:16,710
then DionTraining2 as your next password in 90 days,

243
00:10:16,710 --> 00:10:19,380
then DionTraining3 as your third password,

244
00:10:19,380 --> 00:10:20,790
and so on and so forth.

245
00:10:20,790 --> 00:10:21,660
For this reason,

246
00:10:21,660 --> 00:10:24,900
the National Institute of Standard and Technology or NIST

247
00:10:24,900 --> 00:10:27,480
no longer recommends password expiration policies

248
00:10:27,480 --> 00:10:29,940
to be implemented in most organizations

249
00:10:29,940 --> 00:10:32,480
unless you are already forcing the use

250
00:10:32,480 --> 00:10:34,980
of password managers across your organization

251
00:10:34,980 --> 00:10:37,470
to securely track all of your long, strong,

252
00:10:37,470 --> 00:10:40,350
and complex passwords for each website and application.

253
00:10:40,350 --> 00:10:41,790
To configure the password expiration,

254
00:10:41,790 --> 00:10:45,120
we're simply going to go to maximum password age,

255
00:10:45,120 --> 00:10:47,070
and we're just going to set it to 90 days.

256
00:10:48,750 --> 00:10:51,300
Fifth, we have password age.

257
00:10:51,300 --> 00:10:52,657
Password age refers to the length

258
00:10:52,657 --> 00:10:55,440
of time a password has been in use.

259
00:10:55,440 --> 00:10:58,560
Now, the minimum password age refers to the shortest period

260
00:10:58,560 --> 00:11:01,140
of time within which a user is disallowed

261
00:11:01,140 --> 00:11:02,910
from changing their password again

262
00:11:02,910 --> 00:11:04,440
after it has been changed.

263
00:11:04,440 --> 00:11:05,940
This policy prevents users

264
00:11:05,940 --> 00:11:08,310
from rapidly cycling through password changes

265
00:11:08,310 --> 00:11:10,650
in attempt to revert back to their old,

266
00:11:10,650 --> 00:11:12,060
more familiar password.

267
00:11:12,060 --> 00:11:14,820
For example, without minimum password age,

268
00:11:14,820 --> 00:11:17,400
a user might change their password multiple times

269
00:11:17,400 --> 00:11:18,360
within a few minutes,

270
00:11:18,360 --> 00:11:21,180
effectively bypassing the system's password history

271
00:11:21,180 --> 00:11:23,340
and using their initial password again.

272
00:11:23,340 --> 00:11:25,140
By setting a minimum password age,

273
00:11:25,140 --> 00:11:27,180
such as one or a few days,

274
00:11:27,180 --> 00:11:29,430
organizations can assure that once passwords are changed,

275
00:11:29,430 --> 00:11:31,410
they stay changed for a reasonable period,

276
00:11:31,410 --> 00:11:33,180
further bolstering security.

277
00:11:33,180 --> 00:11:36,390
This policy combined with an enforced password history

278
00:11:36,390 --> 00:11:38,640
deters users from frequently alternating

279
00:11:38,640 --> 00:11:41,100
between a small set of familiar passwords

280
00:11:41,100 --> 00:11:42,720
and encourages the adoption

281
00:11:42,720 --> 00:11:45,240
of newer, secure passwords over time.

282
00:11:45,240 --> 00:11:46,073
Now, to do that,

283
00:11:46,073 --> 00:11:49,320
we're going to simply configure the minimum password age,

284
00:11:49,320 --> 00:11:52,200
and we're going to change it to least, just say three days.

285
00:11:52,200 --> 00:11:55,050
So this simply means that a user cannot change

286
00:11:55,050 --> 00:11:57,543
their password unless it's been three days.

287
00:11:58,590 --> 00:12:01,200
Now that we have seen the five different characteristics

288
00:12:01,200 --> 00:12:02,130
that you should consider

289
00:12:02,130 --> 00:12:04,350
in your organization's password policies

290
00:12:04,350 --> 00:12:06,660
such as password length, password complexity,

291
00:12:06,660 --> 00:12:10,680
password reuse, password expiration, and password age,

292
00:12:10,680 --> 00:12:12,540
to help our organization's increase

293
00:12:12,540 --> 00:12:14,730
their overall password security,

294
00:12:14,730 --> 00:12:17,640
they should implement and utilize a secure password manager

295
00:12:17,640 --> 00:12:19,380
for their end users.

296
00:12:19,380 --> 00:12:21,900
Password managers are tools that store and manage

297
00:12:21,900 --> 00:12:25,020
all your passwords in one centralized location for you

298
00:12:25,020 --> 00:12:27,780
by generating a strong and unique password

299
00:12:27,780 --> 00:12:29,910
that then automatically fills them

300
00:12:29,910 --> 00:12:32,400
into a website or application for you

301
00:12:32,400 --> 00:12:33,950
whenever you attempt to log in.

302
00:12:34,950 --> 00:12:37,170
Password managers have some key features

303
00:12:37,170 --> 00:12:39,420
that make them an essential security tool

304
00:12:39,420 --> 00:12:41,880
for your organization, including password generation,

305
00:12:41,880 --> 00:12:44,970
autofill, secure sharing, and cross-platform access.

306
00:12:44,970 --> 00:12:47,160
First, we have password generation.

307
00:12:47,160 --> 00:12:49,980
Most password managers can generate strong, random,

308
00:12:49,980 --> 00:12:52,200
and unique password for each of your accounts,

309
00:12:52,200 --> 00:12:54,960
which helps in maintaining password complexity

310
00:12:54,960 --> 00:12:56,940
and avoiding password reuse.

311
00:12:56,940 --> 00:12:58,740
When you need to create a new password,

312
00:12:58,740 --> 00:13:00,570
you can specify the policy to use

313
00:13:00,570 --> 00:13:02,490
such as numbers only, alphanumeric,

314
00:13:02,490 --> 00:13:03,900
or with special characters,

315
00:13:03,900 --> 00:13:06,120
along with the length and complexity requirements

316
00:13:06,120 --> 00:13:09,270
that the website or application requires for its passwords.

317
00:13:09,270 --> 00:13:11,040
Second, we have autofill.

318
00:13:11,040 --> 00:13:13,050
Password managers can automatically fill in

319
00:13:13,050 --> 00:13:15,570
your username and password when you visit a site,

320
00:13:15,570 --> 00:13:16,890
which can save you from the hassle

321
00:13:16,890 --> 00:13:18,960
of remembering and typing them in yourself.

322
00:13:18,960 --> 00:13:21,810
This also decreases the chance of human error.

323
00:13:21,810 --> 00:13:23,880
Third, we have secure sharing.

324
00:13:23,880 --> 00:13:25,950
If you need to share a password with someone,

325
00:13:25,950 --> 00:13:28,110
password managers can often do this in a secure way

326
00:13:28,110 --> 00:13:30,120
without revealing the password itself.

327
00:13:30,120 --> 00:13:32,370
For example, if I have a personal assistant

328
00:13:32,370 --> 00:13:33,600
and I need for them to be able

329
00:13:33,600 --> 00:13:35,400
to log into my email on my behalf,

330
00:13:35,400 --> 00:13:37,080
I could give them permissions

331
00:13:37,080 --> 00:13:39,210
in my password manager to log in as me,

332
00:13:39,210 --> 00:13:40,560
but the password manager

333
00:13:40,560 --> 00:13:42,750
will actually do the logging in on their behalf

334
00:13:42,750 --> 00:13:44,430
and it would never show them the password

335
00:13:44,430 --> 00:13:46,860
being used during a login process.

336
00:13:46,860 --> 00:13:49,470
Fourth, we have the cross-platform access.

337
00:13:49,470 --> 00:13:51,240
Most password managers are available

338
00:13:51,240 --> 00:13:53,280
across multiple devices and platforms,

339
00:13:53,280 --> 00:13:54,900
which ensures that you have access

340
00:13:54,900 --> 00:13:56,580
to your passwords wherever you are.

341
00:13:56,580 --> 00:13:58,830
For example, I personally use Bitwarden

342
00:13:58,830 --> 00:14:00,630
and I have it installed on my laptop,

343
00:14:00,630 --> 00:14:02,820
my Google Chrome browser, as an extension,

344
00:14:02,820 --> 00:14:04,350
and on my smartphone.

345
00:14:04,350 --> 00:14:05,700
That way, no matter where I am,

346
00:14:05,700 --> 00:14:07,607
I can access my passwords within Bitwarden

347
00:14:07,607 --> 00:14:09,990
on any device that I'm logging into.

348
00:14:09,990 --> 00:14:12,780
Lastly, we need to discuss passwordless authentication,

349
00:14:12,780 --> 00:14:14,340
which has become a very popular

350
00:14:14,340 --> 00:14:16,530
new method of authentication.

351
00:14:16,530 --> 00:14:18,300
Passwordless authentication methods

352
00:14:18,300 --> 00:14:19,650
are increasingly being used

353
00:14:19,650 --> 00:14:22,500
because they provide us with a higher level of security

354
00:14:22,500 --> 00:14:24,330
and a better user experience.

355
00:14:24,330 --> 00:14:27,090
This passwordless authentication can be achieved

356
00:14:27,090 --> 00:14:28,740
through biometric authentication.

357
00:14:28,740 --> 00:14:31,737
Some trusted password managers include 1Password,

358
00:14:31,737 --> 00:14:34,380
Bitwarden and Dashlane,

359
00:14:34,380 --> 00:14:36,630
but there are many others on the market as well.

360
00:14:36,630 --> 00:14:39,210
Hardware tokens, one-time password,

361
00:14:39,210 --> 00:14:41,640
magic links, and passkeys.

362
00:14:41,640 --> 00:14:43,530
Biometric authentication uses

363
00:14:43,530 --> 00:14:45,450
unique biological characteristics,

364
00:14:45,450 --> 00:14:47,580
such as fingerprints, facial recognition,

365
00:14:47,580 --> 00:14:50,340
or iris scans to verify identity.

366
00:14:50,340 --> 00:14:52,080
If you use your fingerprint or your face

367
00:14:52,080 --> 00:14:53,910
to authenticate or unlock a device,

368
00:14:53,910 --> 00:14:56,940
that will be considered biometric authentication.

369
00:14:56,940 --> 00:15:00,450
Hardware tokens use physical devices, like a security key,

370
00:15:00,450 --> 00:15:03,603
that generate a short duration and ever-changing login code.

371
00:15:04,440 --> 00:15:07,590
A one-time password or OTP is a code

372
00:15:07,590 --> 00:15:09,270
that is sent your email or phone,

373
00:15:09,270 --> 00:15:11,700
which you can enter to log in.

374
00:15:11,700 --> 00:15:14,160
The code is usually valid for only a short period of time,

375
00:15:14,160 --> 00:15:15,720
maybe like 3 to 10 minutes,

376
00:15:15,720 --> 00:15:18,420
and it can only be used once to log in.

377
00:15:18,420 --> 00:15:20,550
After that, a new code would need to be requested

378
00:15:20,550 --> 00:15:22,590
when you want to log in again.

379
00:15:22,590 --> 00:15:25,350
A magic link is a link that is sent to your email.

380
00:15:25,350 --> 00:15:26,280
By clicking the link,

381
00:15:26,280 --> 00:15:28,590
you're automatically logged into that website.

382
00:15:28,590 --> 00:15:31,200
This link is also valid for a short period of time

383
00:15:31,200 --> 00:15:32,610
and can only be used once,

384
00:15:32,610 --> 00:15:34,543
similar to a one-time passcode.

385
00:15:34,543 --> 00:15:37,290
A passkey serves as an authentication tool

386
00:15:37,290 --> 00:15:39,960
that integrates with the browser or operating system.

387
00:15:39,960 --> 00:15:42,840
When set up, users are prompted to establish a passkey.

388
00:15:42,840 --> 00:15:45,120
Instead of remembering and typing passwords,

389
00:15:45,120 --> 00:15:47,970
users utilize their device's built-in security feature,

390
00:15:47,970 --> 00:15:49,860
such as a fingerprint sensor.

391
00:15:49,860 --> 00:15:51,930
When logging into a site or application,

392
00:15:51,930 --> 00:15:53,790
users are asked to unlock the device

393
00:15:53,790 --> 00:15:55,200
using the chosen method.

394
00:15:55,200 --> 00:15:56,040
Once unlocked,

395
00:15:56,040 --> 00:15:58,410
the device fetches its securely stored passkey

396
00:15:58,410 --> 00:16:00,240
and presents it to the site or application,

397
00:16:00,240 --> 00:16:02,970
verifying the user identity and granting access.

398
00:16:02,970 --> 00:16:05,310
So remember, when it comes to passwords,

399
00:16:05,310 --> 00:16:08,310
the longer your password, the more time it will take crack.

400
00:16:08,310 --> 00:16:10,920
Password complexity evolves the use of a mix of letters,

401
00:16:10,920 --> 00:16:13,200
numbers, and special characters.

402
00:16:13,200 --> 00:16:15,150
You also should never reuse passwords,

403
00:16:15,150 --> 00:16:16,470
and each of your accounts should have

404
00:16:16,470 --> 00:16:17,820
its own unique password.

405
00:16:17,820 --> 00:16:19,933
Also, your organization should consider using

406
00:16:19,933 --> 00:16:23,160
a password manager to help manage your passwords effectively

407
00:16:23,160 --> 00:16:26,190
and explore passwordless options too if they're available,

408
00:16:26,190 --> 00:16:27,690
since they provide higher security

409
00:16:27,690 --> 00:16:29,883
and a better overall user experience.

