Are you using a Password Manager?

While FastBound has never had a security breach, you have undoubtedly heard of sites that have. As of July 2018, Troy Hunt’s Have I Been Pwned (HIBP) site has collected more than 11.7 billion compromised (aka pwned) accounts compiled from 588 website breaches and more than 114 thousand pastes of more than 222 million accounts alone. Data breaches have taught us 1) that most people don’t use a password manager and 2) humans love to reuse their passwords. Reusing passwords is extremely risky. It’s so prevalent because it’s really easy to do, and people aren’t aware of the potential impact.

Credential Stuffing Attacks 

Attacks such as credential stuffing take advantage of reused credentials by automating login attempts against systems using known emails and password combinations.

Consumers have no control or insight into how companies store their passwords. When they have a data breach, the email addresses and passwords are then made available for attackers to try at other sites and apps.

Password Manager

Using a password manager like 1Password or BitWarden to Generate long, strong, and unique passwords for each site you have a login for will significantly reduce your risk of falling victim to a credential stuffing attack.

Complexity adds unnecessary complexity

Current NIST password guidelines suggest that you focus primarily on password length instead of the complexity when creating passwords. Ironically, using complex passwords (adding special characters, capitalization, and numbers) makes it easier to guess your password. Complex passwords are harder to remember, which means users may need to update their passwords more often, making minor changes, making them easier prey for cyber attacks. NIST requires an 8-character minimum for passwords.

Don’t allow previously breached passwords

In August 2017, The National Institute of Standards and Technology (NIST) released guidance recommending that user-provided passwords be checked against existing data breaches. The rationale for this advice and suggestions for how applications may leverage this data are detailed in Troy Hunt’s Introducing 306 Million Freely Downloadable Pwned Passwords blog post.

Accordingly, when you set a password for the first time, change your password, or reset your password, we check to ensure that your password is not among the 11.7+ billion Pwned Passwords. If your password has been seen in a data breach, FastBound asks you to pick another one. FastBound also checks if your password has been breached when you log in to FastBound. If you log in with a breached password, we’ll let you know and guide you through changing it. If you use that same password on other websites, you should be changing it there, too. It would be best to use a random password generated by your password manager.

If you are curious about how we check your password against billions of breached passwords without breaching your password, protecting the privacy of searched passwords, check out Troy’s blog post about Cloudflare, Privacy, and k-Anonymity. It gets a little technical, but it’s worth the read.

Article reviewed 03/29/2022

Jason Smith

Co-founder at FastBound

About the Reviewer:

Jason co-founded FastBound in 2010 and has dedicated over 25 years to developing software solutions for regulated industries, with a notable focus on the firearms compliance sector. His expertise and innovative approach have propelled FastBound to the forefront of the industry, introducing numerous firsts that have significantly improved compliance management and operational efficiency. Jason's leadership and vision have made FastBound a leader in firearms compliance, underscoring his commitment to enhancing industry standards and regulatory adherence.

Recent Blogs

An image of a criminal background check.
Business

All About the Role of an Industry Operations Investigator (IOI)

Industry Operations Investigators (IOIs) play an important role in the firearms industry by ensuring businesses ...
An image of a man going through a firearm transaction.
Legal

Understanding ATF Bound Book Requirements for Firearms Businesses

In the highly regulated firearms industry, it’s mandatory to adhere to the regulations set by ...
Software

March 2024 Features & Enhancements for Streamlined Firearm Management

At FastBound, we’re dedicated to providing the best solutions for Federal Firearms Licensee Compliance. Our ...
A graphic representing compliance with firearm regulations.
Business

Reporting a Stolen Gun

The Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) sets specific requirements for FFLs regarding ...
An image of someone purchasing a firearm.
Business

How to Transfer Ownership of a Gun

Transferring gun ownership in the United States is a task that comes with significant responsibility. ...
handing over a firearm.
Software

Filling Out ATF Form 4473

When purchasing a firearm in the United States, the transaction process is strictly regulated to ...
An image of a gun with money to represent the cost of an FFL.
Uncategorized

Understanding How Much an FFL Costs

For those wanting to engage in the sale, manufacture, or import of firearms, they must ...
Image of a gun laying on the American flag.
Uncategorized

FFL Renewal

Renewing your Federal Firearms License (FFL) is an important step for every firearms dealer to ...
The state flag of Georgia waving in the wind.
Uncategorized

A Comprehensive Guide: How to Get an FFL in Georgia

The process of obtaining a Federal Firearms License in Georgia can be complex, so it’s ...
Uncategorized

How to Get an FFL in Colorado

In Colorado, obtaining a Federal Firearms License (FFL) is a key step for anyone looking ...
Uncategorized

FFL Application Process: How Long Does it Take to Get an FFL?

Are you ready to start your own firearm business or looking to deepen your involvement ...
Uncategorized

What is ATF Form 5320.23?

Form 5320.23, also known as the Responsible Person Questionnaire, is an important document under the ...