top of page

Issue - May/June 2025

Defending Your Data

Password Strength Is a Security Problem of Your Own Making

AdobeStock_613250119 - sm.jpg

By Miguel Lopez, CTO, Mudinmar

In many companies, a larger security problem is being created by trying to solve a smaller security problem. We are all fearful of having our passwords hacked to access our email, our CRM or even our own computer.


That’s why many companies use complex passwords, such as &F45%4ERdt$, which are very difficult to hack, but may cause a bigger problem than they solve: They are very difficult to remember.


The common solution? Employees write them down in a file. Often this file is in a common access folder, and in a demonstration of the spirit of collaboration, everyone adds their passwords so that colleagues can access their mail when they are on holiday.


Are we crazy? All passwords are in one place, and everyone from the new intern to the owner of the company has access! Note: The business owner is often the biggest cybersecurity risk in many companies.


Now, here’s the hard truth: until recently, at Mudinmar, we handled passwords this way. What did we do to fix it? The first thing was to delete the password file. Only I, as the CTO, had everyone’s passwords, but only I had access to the file. Employee by employee, we let them set their password. It was no longer written down anywhere—even I didn’t know what their password was. We only gave them a few limitations: upper and lower case, a number, optionally a symbol, and that it should be a sentence. And they didn’t write them down anywhere, you ask? No, we didn’t let them write it down; they have to learn it by heart. And I assure you that it is possible with a simple trick: make it personal, and make it a simple sentence—long, but simple, and most importantly, make it personal.


Let’s look at some very simple examples:


When an employee has to change their password I ask them one of these questions:

  • When were you born?

  • When did you get married?

  • What football team do you support?

  • What is your partner’s name?

  • Where do you go on holiday in the summer?


And with those answers, the passwords I propose are:

  • ILoveMyWifeShopieSince1997$ (He got married to Sophie in 1997)

  • YouWillNeverWalkAloneWithMudinmar!2019 (If she is a Liverpool supporter she will never forget)

  • MySonPeterIsRedHead2014# (His son was born in 2014)

  • ILoveGoingOnVacation2Benidorm& (A fan of spanish coast)


And you must be thinking…But these passwords are so simple, aren’t they easy to hack? Hahaha!!


When they say this, we visit www.passwordmonster.com and show them how tough they are, expressed in the length of time they would take to hack:

  • ILoveMyWifeShopieSince1997$: 43 million years

  • YouWillNeverWalkAloneWithMudinmar!2019: 55 billion years

  • MySonPeterIsRedHead2014#: 2 thousand years

  • ILoveGoingOnVacation2Benidorm&: 176 million years


Hard to hack, easy for every employee to remember, no need to write it down or store it anywhere.


And best of all, they don’t have to look for me when they want to change their password, because they have left it with a colleague in their absence, or because it has been a month since they updated it. They can do it themselves by putting together another sentence that is personal, easy to remember, long, and yet very difficult to hack.

bottom of page