Passwords have become a truly maddening aspect of modern life, but with this book, you can discover how the experts handle all manner of password situations, including multi-factor authentication that can protect you even if your password is hacked or stolen.
The book explains what makes a password secure and helps you create a strategy that includes using a password manager, working with oddball security questions like “What is your pet’s favorite movie?”, and making sure your passwords are always available when needed.
Joe helps you choose a password manager (or switch to a better one) in a chapter that discusses desirable features and describes 10 different apps, with a focus on those that work on Mac, iPhone, iPad, Windows, and Android. The book also looks at how you can audit your passwords to keep them in tip-top shape, use two-step verification and two-factor authentication, and deal with situations where a password manager can’t help.
The book also includes complete coverage of passkeys, which offer a way to log in without passwords and are rapidly gaining popularity—but also come with a new set of challenges and complications. The book also now says more about passcodes for mobile devices.
An appendix shows you how to help a friend or relative set up a reasonable password strategy if they’re unable or unwilling to follow the recommended security steps, and an extended explanation of password entropy is provided for those who want to consider the math behind passwords.
This book shows you exactly why:
- Short passwords with upper- and lowercase letters, digits, and punctuation are not strong enough.
- You cannot turn a so-so password into a great one by tacking a punctuation character and number on the end.
- It is not safe to use the same password everywhere, even if it’s a great password.
- A password is not immune to automated cracking because there’s a delay between login attempts.
- Even if you’re an ordinary person without valuable data, your account may still be hacked, causing you problems.
- You cannot manually devise “random” passwords that will defeat potential attackers.
- Just because a password doesn’t appear in a dictionary, that does not necessarily mean that it’s adequate.
- It is not a smart idea to change your passwords every month.
- Truthfully answering security questions like “What is your mother’s maiden name?” does not keep your data more secure.
- Adding a character to a 10-character password does not make it 10% stronger.
- Easy-to-remember passwords like “correct horse battery staple” will not solve all your password problems.
- All password managers are not pretty much the same.
- Passkeys are beginning to make inroads, and may one day replace most—but not all!—of your passwords.
- Your passwords will not be safest if you never write them down and keep them only in your head.
But don’t worry, the book also teaches you a straightforward strategy for handling your passwords that will keep your data safe without driving you batty.
Joe Kissell is the author of more than 75 books about technology. In 2017, he also became the publisher of Take Control Books, when alt concepts—the company he runs with his wife, Morgen Jahnke—acquired the Take Control imprint from TidBITS Publishing Inc.’s owners, Adam and Tonya Engst. Before he began writing full-time in 2003, Joe managed software development, a totally normal profession for someone with degrees in philosophy and linguistics.
In his rare non-work hours, Joe likes to walk, cook, read, and teach tai chi. He lives in Saskatoon, Saskatchewan, Canada, with Morgen and their sons. You can follow him on Mastodon (@joekissell) or Bluesky (@joekissell.com), or visit his personal website, JoeKissell.com.
What’s New in Version 4.3
Version 4.3 cleans up the book by removing references to outdated operating systems, apps, and devices; fixing broken links; and making numerous small tweaks to keep it current. Other changes:
- Expanded and updated the sidebar “About Hashes and Salts”
- Updated the descriptions of 1Password and Apple’s Password Tools to reflect recent changes
- Updated pricing information for some third-party password managers
- Added information to “Syncing Passkeys Across Devices” about apps with Credential Exchange Protocol (CXP) support
What Was New in Version 4.2
Version 4.2 covered changes in the industry, and especially at Apple, since the previous version of this book was published. Most notably:
- In “Threat #3: Brute-Force Attacks,” added information about how encryption algorithms affect cracking time
- Revised “Apple’s Password Tools” (previously titled “iCloud Keychain”) to cover the Passwords app introduced in macOS 15 Sequoia, iOS 18, and iPadOS 18 and provide more information on the iCloud Passwords software
- Made numerous updates to the “Authenticate Without Passwords” chapter to reflect new passkey-related developments (and ongoing limitations)
Posted by Joe Kissell on June 26, 2023
Joe Kissell joined host Chuck Joiner on MacVoices to talk about Take Control of Your Passwords, Fourth Edition.
In part one, Joe discusses the continuing importance of good passwords and what’s going on with passkeys, which promise one day to replace passwords.
In part two, Joe talks more about passkeys and discusses mobile device security.
Posted by Joe Kissell on August 8, 2021
Once again, Joe Kissell joined Chuck Joiner on MacVoices to discuss passwords in the context of his recently updated books Take Control of Your Passwords version 3.2 and Take Control of 1Password, Fifth Edition.
In part one, Joe talks about passwords generally, including changes that may affect your overall password strategy.
In part two, Joe covers some of the new features in 1Password.
Posted by Michael E. Cohen on March 30, 2016
Joe and Chuck Joiner of MacVoices sit down for a wide-ranging chat about the new edition of this book and the state of passwords in this age of multi-factor authentication, password entropy, and password managers. They discuss all the myriad ways you can improve your personal online security without having to create and memorize a new password like R>preVckEf7*fh% every few weeks.
Posted by Adam Engst on April 15, 2014
For anyone who is wondering, neither the Take Control Web site nor the eSellerate ecommerce site that we use for purchases were ever vulnerable to the Heartbleed bug, so you don’t need to worry about the security of your Take Control transactions or account information. There’s no reason to change your Take Control password either, although it’s always a good idea to do that if your current password is weak.
Reviews
There are no reviews yet.