Password
Password
Password security is the practice of creating, storing, and managing passwords in a way that protects accounts, systems, and data from unauthorized access.
Passwords are often the first line of defense in cybersecurity.
Why Password Security Matters
A weak password can allow attackers to access:
Email accounts
Banking accounts
Cloud services
Company networks
Social media accounts
Example:
Plain Text
Username: jsmith
Password: password123
This would be considered very weak and easily guessed.
Characteristics of a Strong Password
A strong password should be:
✅ Long
✅ Unique
✅ Difficult to guess
✅ Not reused across multiple accounts
Example:
Plain Text
Blue-Tiger!River7-Coffee
Stronger than:
Plain Text
Password1
`
Passphrases
A passphrase is a longer password made of multiple words.
Example:
Plain Text
Coffee-Cactus-River-Sunset
Benefits:
Easier to remember
Harder to crack
More secure than short complex passwords
Password Best Practices
✅ Use at least 12-16 characters
✅ Use a password manager
✅ Enable MFA
✅ Use unique passwords
✅ Change compromised passwords immediately
✅ Avoid personal information
✅ Never share passwords
Password Managers
A password manager securely stores passwords.
Examples:
Microsoft Authenticator Password Manager
Bitwarden
1Password
LastPass
Dashlane
Benefits:
Plain Text
One Master Password
↓
Many Strong Passwords
``
Common Password Attacks
1. Brute Force Attack
An attacker tries every possible password combination until one works.
Example:
Plain Text
aaaa
aaab
aaac
...
Benefits for attacker:
Eventually works against weak passwords
Defense:
✅ Long passwords
✅ Account lockout policies
✅ MFA
2. Dictionary Attack
Uses a list of common words and passwords.
Example:
Plain Text
password
admin
welcome
football
qwerty
Defense:
✅ Avoid common words
✅ Use passphrases
✅ Enable MFA
3. Password Spraying
Attackers try a few common passwords against many accounts.
Example:
Plain Text
Password123!
Welcome123!
Summer2026!
against hundreds of users.
Why it works:
Avoids triggering account lockouts
Defense:
✅ Strong password policies
✅ MFA
✅ Monitoring failed logins
4. Credential Stuffing
Uses usernames and passwords stolen from another breach.
Example:
Plain Text
Netflix Password
↓
Used Against
↓
Microsoft 365
If the user reused the password, the attack succeeds.
Defense:
✅ Never reuse passwords
✅ MFA
5. Phishing
Attackers trick users into revealing passwords.
Example:
Plain Text
"Your account is locked.
Click here to log in."
User enters credentials into a fake website.
Defense:
✅ Security awareness
✅ Verify links
✅ MFA
6. Keylogger Attack
Malware records keystrokes.
Example:
Plain Text
User types password
↓
Keylogger records it
Defense:
✅ Antivirus
✅ EDR solutions
✅ Updated software
7. Shoulder Surfing
An attacker physically watches someone enter a password.
Example:
Plain Text
Airport
Coffee Shop
Office
Defense:
✅ Privacy screens
✅ Awareness
8. Rainbow Table Attack
Uses precomputed password hashes to recover passwords.
Example:
Plain Text
Stolen Password Hash
↓
Rainbow Table Lookup
Defense:
✅ Password salting
✅ Strong hashing algorithms
Password Hashing
Organizations should never store passwords in plain text.
Bad:
Plain Text
Password = MyPassword123
Good:
Plain Text
Password Hash = X7K82L@...
Common hashing algorithms:
SHA-256
SHA-512
bcrypt
Argon2
PBKDF2
Password Salting
A random value is added before hashing.
Plain Text
Password
+
Random Salt
↓
Hash
Benefits:
✅ Protects against rainbow table attacks
✅ Makes password cracking more difficult
Account Lockout Policies
After several incorrect passwords:
Plain Text
5 Failed Attempts
↓
Account Locked
Helps defend against:
Brute force attacks
Dictionary attacks
Password Security and MFA
Even a strong password can be stolen.
That's why organizations use:
Plain Text
Password
+
MFA
Example:
Plain Text
Password
+
Fingerprint
or
Plain Text
Password
+
Authenticator App
This significantly improves security.
Security+ Exam Tips
Know These Attacks
Attack DescriptionBrute Force Tries all combinations
Dictionary Uses common words
Password Spraying Common passwords against many users
Credential Stuffing Reused stolen credentials
Phishing Tricks users into revealing passwords
Keylogger Records keystrokes
Shoulder Surfing Watches password entry
Rainbow Table Cracks password hashes
Best Defenses
✅ Strong passwords
✅ Passphrases
✅ Password managers
✅ Password hashing
✅ Password salting
✅ Account lockouts
✅ MFA
Quick Memory Trick
Plain Text
Strong Password
+
Unique Password
+
MFA
=
Best Protection
Simple Definition
Password security is the protection of user credentials through strong passwords, password managers, hashing, salting, and MFA. Password attacks are methods used by attackers to steal, guess, crack, or misuse passwords, including brute force, dictionary attacks, password spraying, credential stuffing, phishing, and keylogging.
Provide your feedback on BizChat
Subscribe to our newsletter
Sign up with your email address to receive news and updates.