Skip to content

Software Development at Program Tom LTD

Place for coding, programming, development and software in general.

Menu
  • Blog
  • PDF Booklets
  • Dev Utils & Content
  • Java Spring Boot Or Web Apps
  • English
    • български
    • English
    • Español
    • Português
    • हिन्दी
    • Русский
    • Deutsch
    • Français
    • Italiano
    • العربية
  • About Us
Menu
Strong Password Generator App

Pa$$W0rds Best Practices – Strong Passwords

Posted on December 21, 2020December 29, 2020 by Toma Velev

With the progress of time – users, database administrators, developers, experts and all actors in the Internet World have embraced the truth that Passwords Break out. It doesn’t matter how secure the organization, no matter the effort of security experts and investments. There are ways to make this less of a problem from the user side and from the developer/application/service owner side.

From the User Side

  • Don’t use Passwords at All – There are tons of Sign In With Options – Google, Facebook, Apple, Twitter, LinkedIn, Snapchat and more. This way you’ll “get in” faster, with less interactions, with less thinking. If something is wrong with the passwords in these companies, you’ll know and they will force you to change them or add some more security.
  • Use Different and Long Passwords. Because once one Web Site breaches, the hackers will be able to log in any other Web Site that you’ve used the same password. Yes, the passwords this way are not impossible to memorize, but, don’t write them down on paper. The Browsers nowadays can save them. There are also bunch of services that keep the password and offer bring them to you across browsers & devices.

I’ve created a tool for generating Strong Passwords – as Android App  or as a Web App. The longer the password – the harder it will be to be guessed. The more variations of characters – the more secure they (probably) are. Some platforms don’t allow special characters (or some of the other symbols), so I’ve included an option for skipping out some of the groups of types of characters.

From the Other Side

Because of security concerns, the creators of apps could walk away as much as possible from allowing users to type in passwords. The developers could include generators like the mine within the apps and web pages. Besides using the passwords – there are OAuth services from the big companies and institutions for logging into side services. After a User is registered, there are also bunch of layers that can be added that are described in a previous article about Authentication & Authorization. In Short these are:

  • IP & Device white/black lists
  • Temp Login Tokens (with Authenticator Apps)
  • Securely protected Public/Private Keys. Developers could put in work bio-protected private keys and other type of securities that the devices provide. Fingerprints, face recognition, security screen and OS user account protections are standard features for medium to high priced devices. Example of this move away from passwords: https://www.theregister.com/2020/12/17/github_bans_passwords/

The best practices for encrypting passwords – if you need to do this is with Bcript with cost factor 10 or more. It is heavy operation, so the recommended best practice nowadays for authorization is public-private cryptography with lighter hashing. But this is for another article. Good Luck and may the Code be With you.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

  • Prompt-to-Production: How AI is Forcing Us to Build Higher Quality Software
  • Debug Web View Flutter App
  • Skipping AI? You’re a Relic – Time to Evolve or Perish!
  • 2026 Flutter Launch Blueprint: Your 10-Step Checklist to App Store Domination
  • Product Requirements Document – for different software development levels

Categories

  • Apps (25)
  • ChatGPT (27)
  • Choosing a Framework (38)
  • Flutter (281)
  • Graphical User Interface (14)
  • Marketing (119)
  • Software Development (292)
  • Spring (45)
  • StartUp (22)
  • Uncategorized (14)
  • Uncategorized (4)
  • Vaadin (16)

Tags

Algorithms (9) crypto (29) flutterdev (39) General (86) Java (7) QR & Bar Codes (3) Software Dev Choices (33) Spring Boot (1) standards (1) Theme (3) User Authentication & Authorization (9) User Experience (10) Utilities (19) WordPress (11)

Product categories

  • All Technologies (87)
    • Flutter Apps (26)
    • GPT (4)
    • Java (39)
    • Native Android (3)
    • PHP (9)
    • Spring (Boot) / Quarkus (36)
    • Utils (15)
    • Vaadin 24+ (28)
    • Vaadin 8 (1)
  • Apps (18)
    • Employees DB (1)
    • Notes (6)
    • Personal Budget (1)
    • Recipes Book (1)
    • Stuff Organizer (1)
    • To-Do (2)
  • PDF Books (3)
  • Source Code Generators (8)

Recent Posts

  • Prompt-to-Production: How AI is Forcing Us to Build Higher Quality Software
  • Debug Web View Flutter App
  • Skipping AI? You’re a Relic – Time to Evolve or Perish!
  • 2026 Flutter Launch Blueprint: Your 10-Step Checklist to App Store Domination
  • Product Requirements Document – for different software development levels

Post Categories

  • Apps (25)
  • ChatGPT (27)
  • Choosing a Framework (38)
  • Flutter (281)
  • Graphical User Interface (14)
  • Marketing (119)
  • Software Development (292)
  • Spring (45)
  • StartUp (22)
  • Uncategorized (14)
  • Uncategorized (4)
  • Vaadin (16)