Length beats complexity
A long password is far harder to crack than a short complicated one. A random 16-character password or a passphrase of four or five random words is strong; P@ssw0rd1! is not — it’s in every attacker’s list.
Reuse is the real danger
Websites are breached all the time and their password lists are published. Attackers take those email-and-password pairs and try them everywhere, automatically. If your hosting password is the same as the one you used on a breached forum, it isn’t secret any more, however strong it is.
Every login needs its own password.
Password managers
A password manager generates, stores and fills unique passwords for every site. You remember one strong master password.
- Generate a new password for each hosting login
- Store DirectAdmin, email, database and FTP passwords in it
- Share access with a colleague or developer through the manager instead of email or chat
Two-factor authentication
Where available — registrar, personal email, WordPress (with a plugin) — turn on two-factor authentication with an authenticator app. A stolen password alone is then not enough.
Things not to do
- Write passwords in a document on your desktop
- Send them in email, text or chat
- Save them in the browser on a shared computer
- Use personal information: names, birthdays, pets
New to Traxio? Hosting is 30 days free with no card needed, then £0.99 a month. See what’s included