Kindernothilfe (KNH) is a German non-profit organization dedicated to supporting vulnerable children in impoverished and underprivileged regions worldwide. Founded in 1959, it has made significant contributions as one of Europe's largest charities dedicated to child aid.
Operating in over 30 countries, Kindernothilfe emphasizes the importance of ensuring children's rights and providing access to education, healthcare, child protection, and community development initiatives, all aimed at enhancing children's living conditions and eradicating poverty.
Company: Kindernothilfe Location: Duisburg, Germany Industry: Non-profit organization Company size: Over 300 employees in more than 30 countries
The challenge: Finding a secure and user-friendly solution for global teams
Before choosing Passwork, Kindernothilfe relied on KeePass, a solution that limited scalability and lacked user-friendly features essential for a globally operating organization. With over 300 employees across more than 30 countries, the organization required a secure, scalable, and intuitive password management solution.
Doing so was crucial to meet the growing demands of its international team, especially for enhancing password sharing and access management capabilities for remote employees.
The solution: Switching to Passwork for improved security and simplified user access
Kindernothilfe opted for Passwork for its robust self-hosting capabilities, ensuring optimal data control and security. The seamless integration with SAML2 for Single Sign-On (SSO) streamlined access management across multiple platforms.
Furthermore, Passwork's intuitive interface, along with its mobile app and browser extension, made it possible to manage passwords effortlessly from any device. The secure password-sharing features enhanced team collaboration, significantly reducing human error and improving overall security protocols.
The implementation: Gradual rollout and building a secure infrastructure
The implementation process took approximately two months. It was primarily focused on establishing and thoroughly testing the infrastructure to ensure Passwork met Kindernothilfe's security requirements. The integration of SAML2 for Single Sign-On (SSO) was smooth and completed within a short timeframe.
To facilitate the successful implementation of Passwork, Kindernothilfe opted for a phased rollout rather than deploying the password management solution organization-wide all at once. They began with a smaller group of employees to showcase the benefits of the system and gradually promoted its use.
While organizing various promotional and educational activities, such as "Lunch and Learn" events, the organization encouraged employees to engage with Passwork. The goal was to achieve the point where at least 50% of the staff actively used Passwork before expanding the system to the entire organization.
The results: Increasing operational efficiency for cross-border teams
Currently, approximately 50% of the staff are actively using Passwork — a centralized, secure, and user-friendly solution for password sharing. This incremental approach not only ensured higher user engagement but also significantly strengthened security protocols across the organization.
By improving password management processes, Kindernothilfe increased its overall operational efficiency, especially for cross-border teams. Educational initiatives, such as "Lunch and Learn" sessions, were instrumental in raising awareness about Passwork and facilitating its successful adoption throughout the organization.
"Passwork met our needs with its affordable pricing and ease of use, making it an essential tool for our global workforce." — Bernd Schlürmann, network and security manager
Take the first step too! Start your free Passwork trial and see how easy secure password management can be.
Kindernothilfe: Simplifying global employee collaboration with Passwork
Kindernothilfe, one of Europe's largest child aid organizations, needed a scalable password manager for a globally distributed team. They chose Passwork for self-hosting, SSO via SAML2, and an intuitive interface that simplified access management across borders.
Passwork 6.4, we have introduced a number of changes which enhance our browser extension security, make user permissions settings more flexible, and improve the logging of settings related changes:
Mandatory extension PIN code
Logging of all changes related to settings
User access to history of actions with passwords
Automatic updating of LDAP group lists
Mandatory extension PIN code
With the new setting ‘Mandatory PIN code in extension’, administrators can set a mandatory browser extension PIN code for all users, minimizing potential unauthorized access. Once enabled, users who have not yet set a PIN code will be prompted to do so upon their next login to the extension. Users will be able to configure their auto-lock timeout and change the PIN code, but they cannot disable these functions.
The ‘Mandatory PIN code in extension’ setting is located in the ‘API, extension and mobile app’ section of the System settings
Logging of all changes related to settings
Now all changes in the Account settings, User management, LDAP settings, SSO settings, License info, and Background tasks are displayed in the Activity log.
All changes related to settings logged in the Activity log in the Settings and users
History of actions with passwords
The new setting ‘Who can view the history of actions with passwords’ makes it possible for vault administrators to let other users view password history, password editions, and receive notifications related to their changes. Previously, these features were available only to vault administrators.
You can customize this feature in the Vaults section of the System settings
Automatic updating of LDAP group lists
Automatic updating of LDAP group lists can now be configured on the Groups tab in the LDAP settings. The update is performed through background tasks with a selected time interval.
To configure LDAP group list updates, select LDAP server, go to the Groups tab, and click the Edit settings button
Other improvements
Added pop-up notifications when exporting data or moving data to the Bin
Improved display of dropdown lists on the Activity log page
Changed time display format of the ‘Automatic logout when inactive’ and ‘Maximum lifetime of the session when inactive’ settings
Changed the Enabled / Disabled dropdown lists on the System settings and LDAP settings pages with toggles
Increased minimum length of generated passwords to six characters
Bug fixes
Fixed an issue in the Password generator where selected characters were sometimes missing in the generated password
Fixed an issue where local users could not independently recover their account password when an LDAP server was enabled
Fixed an issue where local users could not register in Passwork when an LDAP server was enabled
Fixed an issue which occurred after moving a folder with shortcuts to another vault and shortcuts not being displayed in the new vault
Fixed an issue that occurred when trying to move a shortcut found in search results without opening any vaults right after logging into Passwork
Fixed an issue that occurred when trying to copy a password found in search results without opening any vaults right after logging into Passwork
Fixed an issue that occurred when a password was sent to another user and remained on the recipient's Recents and Starred pages after the initial password was moved to the Bin
Fixed the value in the time field for the ‘API key rotation period (in hours)’ setting which was reset to zero after disabling it
Fixed incorrect event logging in the Activity log after changing folder permissions
Fixed incorrect text notification about assigning access rights to a user through a role
Fixed incorrect tooltip text when hovering over the username of a recently created user
Fixed incorrect display of long invitation titles
Removed the local registration page when the LDAP server is enabled
In Passwork 6.3, we have implemented numerous changes that significantly improve organization management efficiency, provide more flexible user permission settings, and increase security:
Administrative rights
Hidden vaults
Improved private vaults
Improved settings interface
Administrative rights
Available with the Advanced license
Now there is no need to make users administrators in order to grant them specific administrative rights. This option is a response to one of the most frequent requests from our customers.
Administrators can grant only those rights or permissions that are necessary for users to fulfill their duties and flexibly customize access to settings sections and manage Passwork. For instance, you can grant employees the right to create and edit new users, view the history of user activity, track settings changes, while restricting access to organization vaults and System settings.
You can configure additional rights on the Administrative rights tab in User management. There are four settings sections to flexibly customize Passwork for your business:
General In this section, you can grant users access rights to manage all existing and new organization vaults, view the history of actions with settings and users, access license info and upload license keys, view and modify the parameters of SSO settings and Background tasks.
User management In this section, you can grant users access rights to view and modify User management parameters. This includes performing any necessary actions with users and roles, such as creating, deleting, and editing users, changing their authorization type and sending invitations.
System settings In this section of settings, you can grant users the right to view and modify specific groups of System settings.
LDAP settings In this section, you can grant users the right to view and modify LDAP parameters which include adding and deleting servers, registering new users, managing group lists, viewing and configuring synchronization settings.
Activity log The event of changing user administrative rights has been added to the Activity log. All changes are now recorded in the Activity log, that includes the users who initiated such changes as well as each setting that was modified with its previous and current values.
Interface improvements
Users with additional administrative rights are marked with a special icon next to their user status.
Some items remain unavailable until the necessary settings have been activated. When hovering your cursor over such items, a tooltip with information regarding dependent settings will be displayed.
Hidden vaults
In the previous versions of Passwork only organization administrators were able to hide vaults. Also, only organization vaults could be hidden. In this new version, all users can hide any vaults. Hiding makes vaults invisible only to the users who choose to do it and does not affect others.
Hidden vault management is now carried out in a new window, which is available directly from the list of vaults. You can view the list of all available vaults and customize their visibility there.
Private vault improvements
Displaying private vaults in User management Besides hiding private vaults, employees with User management access can now see all vaults which they administer (including private vaults). The new feature which makes it possible to add users to private vaults has also been added to User management.
Logging of events in private vaults Private vault administrators can view all events related to their vaults in the Activity log.
Other changes
Fixed an issue which prevented users from changing their temporary master password
Fixed an issue which prevented users from setting the minimum length for authorization and master passwords
Fixed an issue in User management which made administrator self-deletion possible
In Passwork 6.2 we have introduced a range of features aimed at enhancing your security and convenience:
Bin
Protection against accidental removal of vault
Protection against 2FA brute force
Accelerated synchronization with LDAP
Improved API settings
Bug fixes in role management
Bin
Now, when deleting folders and passwords, they will be moved to the Bin. If needed, they can be restored while preserving previously set access permissions. Vaults are deleted without being moved to the Bin — they can only be restored from a backup.
Who can view deleted passwords and folders in the Bin?
Inside the bin users can see the deleted items from those vaults in which they are administrators. For instance, an employee who is not an administrator of organization vaults will only see the deleted passwords and folders from his personal vaults when opening the Bin.
In addition to object names, the Bin also displays the usernames of people who deleted data. You can also see the initial directory name and the deletion date.
Object restoration
Objects from the Bin can be restored to their initial directory if it has not been deleted or moved. Alternatively, you can choose any other directory where you have edit and higher access levels.
When restoring deleted folders to their initial directories, user and role access levels will also be restored exactly as they were previously manually set in these folders. Other access permissions will be set based on the current permissions in the initial directory.
When restoring folders to a directory different from the initial, access levels will always depend on the current permissions in the selected directory.
Additional access to deleted passwords
If passwords have been shared with users, moving them to the Bin will remove them from the “Inbox” section, and any shortcuts or links to these passwords will become nonfunctional.
Restoring additional access
When restoring from the Bin, it is possible to regain additional access levels to passwords. Passwords that were shared with users will reappear in their “Inbox” section, access to passwords through shortcuts will be restored, and links that have not expired will become functional again.
Bin cleanup
You can delete selected items from the Bin or use the "Empty Bin" button to remove all items contained inside.
It's important to note that in the Bin you only see the items which were deleted from the vaults where you are an administrator. Objects from other vaults are not visible, and clearing the Bin will not affect them.
In future, the option to configure automatic Bin cleanup will be added.
Protection against accidental removal of vault
To confirm the deletion of a vault, you now need to enter its name. It will be permanently deleted along with all the data inside. Additionally, if there are passwords or folders from this vault in the Bin, they will also be removed.
Protection against 2FA brute force
Protection against 2FA brute-force attacks has been added. After several incorrect attempts to enter the 2FA code, the user will be temporarily locked. The number of attempts, input intervals, and the lockout time are set in the config.ini file.
Other changes
LDAP synchronization has been accelerated
Descriptions of parameters and minimum allowable values for API token expiration time and API refresh token expiration time have been added to the API settings section
Automatic assignment of "Navigation" to parent folders in role management has been fixed
The issue when a vault administrator could not add roles to a vault and manage its permissions has been fixed
The issue with showing additional access rights to passwords when moved to another vault has been fixed
This latest update demonstrates our focus on refining user experience and enhancing collaborative password management.
No longer will you need to create password copies in various vaults — we've introduced shortcuts. With these handy labels, you can easily organize access to passwords from different directories.
The new enhanced settings provide administrators with more control over configurations and user rights, and all changes require approvals, preventing any unintentional actions.
LDAP user management has now become simpler with its cleaner interface and background data updates.
In addition to that, Passwork 6.0 brings new notifications and interface improvements. All these enhancements contribute to a more comfortable user experience while ensuring the security of passwords and sensitive data.
Shortcuts
Shortcuts are a new way to share passwords, enhancing collaboration flexibility. There's no need for creating password duplicates in different vaults — instead, create multiple shortcuts in required directories. All changes to original passwords are reflected in shortcuts, keeping your team up to date. Users can view or edit data via shortcuts according to their access rights.
Choose the directories where you would like to create shortcutsView the complete list of shortcuts to passwords created in a specific vault
Sending passwords without granting partial access to vaults
Previous versions of Passwork encrypt passwords at the vault level. This type of encryption gives users partial access to vaults even when a single password is shared with them. Now, when users access passwords via their "Inbox" or a shortcut, they receive keys to specific passwords, but not their vaults.
Administrators can clearly see who has vault access rights, and who can only work with specific passwords.
Send passwords to users with necessary access rightsView the complete list of all passwords that were sent from a specific vault
LDAP
The LDAP interface is now cleaner and more intuitive, with a reimagined user management logic. Adding new LDAP users is simpler and safer, especially with the client-side encryption enabled.
Previously, admins had to add an employee and provide a master password. Now, users set their master passwords upon the first login, and admins confirm them afterwards.
The "Users" tab shows registered users, and there is a separate window for adding new ones. LDAP user data updates take place in the background, allowing admins to navigate elsewhere without waiting for data refresh.
View your LDAP user list and add users to PassworkSet up your LDAP integration in the updated interface
Passwork now provides more detailed security group information. The groups that are linked to roles are marked with special tags, and the groups which were not loaded from LDAP during the last update are marked as "Deleted", alerting admins to adjust the search settings or remove such groups. Also, you can now see the members of each security group.
Map your LDAP groups with Passwork roles and set up their automatic synchronization
Improved settings
We've redesigned all settings sections for a unified visual style and enhanced functionality, reimagined the logics of some settings.
Rights for links, tags, and password sharing Previously, these settings were applied individually to each user. Now, they are applied to everyone with a certain level of vault access. For example, anyone with the “Edit” access rights or higher can create hyperlinks to passwords. These parameters are located in the system settings under the “Global” tab.
Change confirmation We've added “Save” and “Cancel changes” buttons in system settings. Now, any changes to settings must be confirmed — this helps to prevent accidental actions.
Custom auto-logout time Users can now set these parameters individually, and admins specify the maximum inactivity time period before automatic logout.
Language selection In the new version of Passwork, admins can allow employees to choose their interface language.
Choose the required access level which will make it possible to send passwords, create links and shortcuts
Interface enhancements
Improved drag and drop Now, when dragging and dropping passwords and folders into desired directories, Passwork displays selectable actions — move, copy, or create a shortcut.
Select folders and passwords, then drag and drop them to the required directoryChoose actions for the selected objects: move, copy, create shortcuts
Other improvements
Separate windows for access to the vault and additional access Vault access info is now split into two easy-to-read windows. One window shows users who has access to a specific vault, and the other displays alternative ways passwords from this vault can be accessed — shortcuts, hyperlinks, or shared passwords.
Redesigned password action buttons On the password panel, we've added the "Edit" button and grouped together all actions for additional password access via shortcuts, links, or direct user sharing.
Additional fields for password import and export Passwork 6.0 supports the use of custom fields, that means you can transfer not only login and password but also additional information stored within password cards.
New notifications Administrators will receive notifications about new unconfirmed users, and employees will be notified of new passwords in the "Incoming" section.
A Security Operations Center (SOC) is a critical hub for cybersecurity within organizations. It combines people, processes, and technologies to detect, analyze, and respond to security incidents. In this article, we will delve into the components that make up a SOC, starting with its basic systems, then moving on to heavier software tools, and finally exploring emerging technologies that hold promise for the future of SOC operations.
Basic systems
The foundation of any SOC lies in its basic systems, which provide fundamental capabilities for monitoring, analysis, and incident response. These systems include:
A Security Information and Event Management (SIEM) system: A SIEM tool collects and correlates data from various sources, such as logs, network traffic, and endpoint events. It helps identify security incidents and generates alerts for further investigation. SIEM systems provide a centralized view of security events, allowing SOC analysts to detect patterns and anomalies.
Intrusion Detection Systems (IDS) and Intrusion Prevention Systems (IPS): IDS and IPS monitor network traffic, searching for suspicious patterns or known attack signatures. IDS detects intrusions, while IPS can actively block or mitigate threats in real time. These systems play a crucial role in detecting and preventing unauthorized access and malicious activities within the network.
Vulnerability management systems: Vulnerability management systems scan and assess the organization's network, applications, and systems for vulnerabilities. They enable proactive identification and remediation of security weaknesses, reducing the risk of exploitation by attackers. These systems play a vital role in maintaining a secure infrastructure.
Log management systems: Logs are critical for forensic analysis and incident response. Log management systems collect, store, and analyze logs from various sources, providing valuable insights into security events. They help SOC teams investigate incidents, identify the root cause of security breaches, and ensure compliance with regulatory requirements.
Network Traffic Analysis (NTA) tools: NTA tools analyze network traffic at a granular level, identifying anomalies and potential threats. By monitoring and analyzing network traffic patterns, these tools help SOC teams detect and respond to suspicious activities. NTA tools enhance visibility into network behavior, allowing SOC analysts to identify sophisticated threats that traditional security systems may miss.
Heavier software
As threats become more sophisticated, SOC teams require advanced software tools to combat them effectively. Let’s take a look at some examples.
Threat intelligence platforms: Threat intelligence platforms aggregate data from various sources to provide up-to-date information about known threats, vulnerabilities, and indicators of compromise. They enhance incident detection and response capabilities by enabling SOC teams to proactively identify and mitigate potential risks. Threat intelligence platforms allow organizations to stay informed about emerging threats and adopt appropriate defense measures.
Endpoint Detection and Response (EDR): EDR solutions monitor endpoint devices for suspicious activities and potential threats. They provide real-time visibility, investigation, and response capabilities, helping SOC teams swiftly identify and contain incidents. EDR tools leverage behavioral analysis and threat intelligence to detect and respond to advanced threats, such as file-less malware and insider threats, at the endpoint level.
Security Orchestration, Automation, and Response (SOAR): SOAR platforms streamline and automate SOC processes, integrating various tools and technologies. They facilitate incident triage, investigation, and response, enabling faster and more efficient security operations. SOAR platforms automate routine tasks, allowing SOC analysts to focus on high-value activities like threat hunting and incident response.
User and Entity Behavior Analytics (UEBA): UEBA tools leverage machine learning algorithms to establish baseline behaviors for users and entities within an organization. They detect anomalous activities, such as insider threats or compromised accounts, by analyzing behavior patterns. UEBA tools provide insights into user activities, helping SOC teams identify potential security incidents and mitigate risks.
Deception technologies: Deception technologies create decoys and traps within a network, luring attackers and diverting their attention. By interacting with deception assets, SOC teams can gather valuable threat intelligence and gain insights into attackers' techniques. Deception technologies complement traditional security measures by providing early detection and response capabilities.
Looking forward
The evolving threat landscape calls for constant innovation in the field of cybersecurity. Several technologies show promise for enhancing SOC capabilities in the future. Let’s take a look at a few.
Artificial Intelligence (AI) and Machine Learning (ML): AI and ML techniques are already being utilized in various aspects of cybersecurity. They can aid in threat detection, anomaly detection, and behavior analysis, enabling more proactive and accurate identification of security incidents. AI and ML algorithms can analyze vast amounts of data and identify patterns that human analysts may miss, improving the efficiency and effectiveness of SOC operations.
Advanced analytics: Advanced analytics techniques, such as predictive analytics and behavioral analytics, can provide deeper insights into security events and help identify emerging threats. By analyzing historical and real-time data, SOC teams can uncover hidden connections and predict future attack trends. Advanced analytics empower SOC analysts to make informed decisions, prioritize threats, and allocate resources effectively.
Cloud-based security: As organizations increasingly adopt cloud infrastructure, SOC operations will need to adapt accordingly. Cloud-native security solutions, including Cloud Access Security Brokers (CASBs) and Cloud Security Posture Management (CSPM) tools, are emerging to address the unique challenges of cloud environments. These solutions provide visibility, control, and compliance assurance across cloud services, ensuring that organizations can protect their data and applications effectively.
Internet of Things (IoT) security: With the proliferation of IoT devices, SOC teams will face the challenge of securing these endpoints. Future SOC technologies should incorporate specialized IoT security solutions that monitor and protect connected devices. IoT security platforms can detect and mitigate IoT-specific threats, such as device tampering, unauthorized access, and data exfiltration. These technologies enable SOC teams to secure the expanding landscape of IoT devices within organizations.
Quantum computing: Quantum computing has the potential to revolutionize cryptography and threat intelligence analysis. With its immense computational power, quantum computers may help SOC teams tackle complex cryptographic algorithms and facilitate faster threat analysis. Quantum-resistant encryption algorithms and quantum-enabled threat detection techniques may become crucial components of future SOC operations.
Conclusion
A well-equipped SOC comprises basic systems, advanced software, and future technologies. The basic systems form the foundation, providing essential monitoring and analysis capabilities. Heavier software tools enhance incident response and detection, allowing SOC teams to stay ahead of evolving threats. Looking ahead, emerging technologies like AI, advanced analytics, cloud-based security, IoT security solutions, and quantum computing hold the potential to revolutionize SOC operations, enabling organizations to protect their assets and data more effectively in an ever-changing cybersecurity landscape.
Symmetric encryption is the workhorse of modern data security. AES-256 protects everything from database records to TLS sessions, and it does so faster than any alternative at scale. The cipher itself is not the problem. The problem is the key — who holds it, how it's stored, and what happens when it's stolen. Understanding both sides of that equation is what separates a sound encryption strategy from a false sense of security.
What is symmetric encryption?
Symmetric encryption uses a single shared key to both encrypt and decrypt data. The sender and receiver must possess the same key. If either party loses it or an attacker obtains it, the protection collapses entirely. This contrasts with asymmetric encryption (public-key cryptography), where a public key encrypts data and a mathematically linked private key decrypts it.
The distinction matters in practice. Symmetric algorithms are fast and computationally cheap, making them the right tool for bulk data encryption. Asymmetric algorithms are slower but solve a problem symmetric encryption cannot: securely exchanging a key over an untrusted channel. Modern systems use both, and understanding when to use which (and how to combine them) is the core of practical cryptographic architecture.
Criterion
Symmetric encryption
Asymmetric encryption
Keys
Single shared key for encrypt + decrypt
Key pair: public key encrypts, private key decrypts
Required for digital signatures, PKI, code signing
Primary weakness
Key distribution and key management at scale
Performance; vulnerable to quantum attacks without PQC migration
The pros of symmetric algorithms
Symmetric encryption offers three concrete advantages that explain why it remains the dominant choice for protecting data at rest and in transit.
Unmatched speed and efficiency
Symmetric algorithms process data faster and at lower computational cost than asymmetric alternatives. A single shared key eliminates the need for complex operations like prime factorization or modular arithmetic, which means less CPU overhead and lower latency. That efficiency scales well: secure communication channels, VPNs, cloud storage, and real-time data transfers all benefit from ciphers that can sustain high throughput without taxing the underlying hardware.
Asymmetric operations, by comparison, involve computationally expensive modular exponentiation or elliptic curve math. RSA-2048 encryption is roughly 1,000 times slower than AES-256 for equivalent data volumes. This is why TLS 1.3 uses asymmetric cryptography only for the handshake — to exchange a session key — then switches immediately to AES for the actual data transfer.
Ideal for large-scale data encryption at rest
Symmetric encryption is the default choice for protecting stored data at scale. Encrypting a multi-terabyte database with an asymmetric algorithm is not practical — the computational cost makes it a non-starter. AES-256-GCM handles the same job routinely, which is why every major cloud provider uses it as the default for storage volumes, database snapshots, and object storage.
Once both parties share a key through a secure initial exchange, symmetric encryption requires no further cryptographic overhead per session. There is no per-message public-key operation, no certificate validation, no asymmetric handshake on every connection. For large organizations where many parties need to communicate securely, this reduces operational complexity significantly — the hard part is the initial key exchange, not the ongoing communication.
Computational simplicity
Symmetric algorithms are straightforward to implement correctly, which matters as much as raw performance. Without complex mathematical operations underlying the design, they run efficiently on resource-constrained hardware — embedded systems, IoT devices, and microcontrollers where CPU cycles and memory are tight. That simplicity also makes implementations easier to audit and maintain, reducing the surface area for the kind of subtle coding errors that quietly undermine security.
Quantum resistance
Quantum computing threatens asymmetric cryptography far more than symmetric.Shor's algorithm, running on a sufficiently powerful quantum computer, can break RSA and elliptic curve cryptography by solving the underlying mathematical problems efficiently. This is why NIST's Post-Quantum Cryptography (PQC) standardization effort, finalized in 2024, focuses almost entirely on replacing asymmetric algorithms.
Symmetric encryption faces a different and more manageable threat.Grover's algorithm can theoretically search an unsorted key space in the square root of the time a classical computer requires. Applied to AES-256, this halves the effective key length — from 256 bits to 128 bits of security. AES-128 bits of security remains computationally unbreakable by any known or projected hardware. AES-128 would be more concerning; AES-256 is not.
The 2025 Thales Data Threat Report found that 62% of critical infrastructure organizations are concerned about future encryption compromise, and 60% specifically worry about the "Harvest Now, Decrypt Later" (HNDL) threat — where adversaries exfiltrate encrypted data today to decrypt it once quantum hardware matures. For data protected with AES-256, HNDL is a much lower risk than for data protected with RSA or ECDH. Organizations using symmetric encryption for long-lived sensitive data are in a stronger position than those relying on asymmetric-only approaches.
The cons of symmetric algorithms
The cipher is sound. The operational challenges around it are not.
The key distribution problem
Two parties who have never communicated cannot securely share a symmetric key over an untrusted channel without help from a third mechanism. This is the key distribution problem, and it is the fundamental limitation of symmetric cryptography.
If you encrypt a file with AES-256 and email it to a colleague, you still need to send them the key. If you send the key in the same email, you've negated the encryption. If you call them on the phone, you've introduced a different channel with its own security assumptions. At small scale, this is manageable. Across thousands of services, APIs, and automated systems, it becomes an architectural problem.
The practical solution (hybrid encryption) is covered in the section on enterprise best practices below.
Scalability challenges
Symmetric encryption requires a unique key for every pair of communicating parties. The number of keys required grows as n(n-1)/2, where n is the number of participants. Ten users need 45 keys. One hundred users need 4,950. A thousand users need nearly half a million.
In enterprise environments with hundreds of services, microservices, and automated pipelines, key proliferation becomes a real operational burden. Without centralized key management, teams default to reusing keys across contexts — which eliminates the isolation that per-pair keys are supposed to provide.
Lack of non-repudiation
Because both parties share the same key, symmetric encryption cannot prove who created a ciphertext. Either party could have encrypted the data. This makes symmetric encryption unsuitable for digital signatures, legal agreements, or any scenario where you need cryptographic proof of origin.
Non-repudiation requires asymmetric cryptography — specifically, a private key that only one party holds. This is why code signing, email signing (S/MIME), and document authentication use RSA or ECDSA rather than AES.
Common symmetric algorithms in 2026
Algorithm
Key size
Recommended mode
Status
AES
128 / 192 / 256 bit
GCM (authenticated)
Current standard
ChaCha20
256 bit
Poly1305 (authenticated)
Current standard
3DES
168 bit (effective 112)
CBC
Deprecated (NIST SP 800-131A Rev. 2)
DES
56 bit
—
Broken; do not use
Blowfish
32–448 bit
—
Legacy; superseded by AES
AES (Advanced Encryption Standard)
AES is the NIST-standardized block cipher defined in FIPS 197 (2001, revised 2023). It operates on 128-bit blocks with key sizes of 128, 192, or 256 bits. AES-256 is the enterprise default for high-assurance environments.
The mode of operation matters as much as the algorithm. AES-GCM (Galois/Counter Mode) provides authenticated encryption — it simultaneously encrypts data and produces a message authentication code (MAC) that detects tampering. Using AES without authentication (AES-CBC without a separate HMAC, for example) leaves ciphertext vulnerable to padding oracle attacks and bit-flipping. Always use AES-256-GCM or AES-256-CCM for new implementations.
AES-NI hardware instructions, available on virtually all modern Intel and AMD server CPUs since 2010, make AES-256-GCM the fastest authenticated encryption option available on standard server hardware.
ChaCha20
ChaCha20-Poly1305 is a stream cipher designed by Daniel Bernstein. It provides strong security with a 256-bit key and is the preferred alternative to AES in environments without hardware acceleration — primarily mobile devices and older embedded systems. TLS 1.3 includes ChaCha20-Poly1305 as a mandatory cipher suite alongside AES-256-GCM.
On servers with AES-NI, AES-256-GCM is faster. On hardware without it, ChaCha20-Poly1305 is the better choice. The decision is architectural, not cryptographic — both algorithms provide equivalent security margins.
Overcoming the cons: Enterprise best practices
The key distribution problem and scalability challenges are real, but they are solved problems. Modern enterprise architectures address both systematically.
Hybrid encryption: The TLS 1.3 model
Hybrid encryption combines asymmetric and symmetric cryptography to get the benefits of both. The asymmetric algorithm handles key exchange. The symmetric algorithm handles data encryption.
TLS 1.3 is the clearest example. During the handshake, the client and server use Diffie-Hellman key exchange (an asymmetric operation) to derive a shared session key without ever transmitting it over the network. Once both sides hold the same session key, all subsequent data is encrypted with AES-256-GCM. The asymmetric step solves the distribution problem; the symmetric step provides the throughput.
The same pattern applies to file encryption, secure email, and encrypted storage systems. The symmetric key that protects the data is itself encrypted with a public key and stored alongside the ciphertext. Only the holder of the corresponding private key can recover the symmetric key and decrypt the data.
Robust key management: KMS and HSMs
The 2023 Storm-0558 breach is the clearest recent example of what happens when key management fails. A Chinese threat actor obtained a Microsoft MSA signing key and used it to forge authentication tokens for Exchange Online and Outlook.com, accessing email accounts across multiple U.S. government agencies. The Cyber Safety Review Board's subsequent investigation found that Microsoft could not definitively determine how the key was stolen — a finding that reflects inadequate key lifecycle controls, not a weakness in the underlying cipher.
Attackers rarely try to break AES-256. They steal the key. According to Verizon's 2025 DBIR, 68% of data breaches involve a human element — stolen credentials, phishing, or misuse. The cipher is not the attack surface. The key is.
This is why Key Management Systems (KMS) and Hardware Security Modules (HSMs) exist. A KMS centralizes key generation, storage, rotation, and revocation. An HSM is a tamper-resistant hardware device that performs cryptographic operations without ever exposing the raw key material to software. Keys generated inside an HSM cannot be extracted — even by the administrator who configured it.
Effective key management requires four operational controls:
Rotation schedules. Keys should be rotated on a defined schedule and immediately upon any suspected compromise. NIST SP 800-57 Part 1 provides guidance on cryptoperiods by algorithm and use case.
Separation of duties. The team that manages encryption keys should not be the same team that manages the data those keys protect.
Access logging. Every key access event should be logged with timestamp, identity, and purpose. This is a prerequisite for SOC 2 CC6.1 and ISO 27001 Annex A.10 compliance.
Automated rotation. Manual key rotation at scale is error-prone. Automation reduces the window of exposure and eliminates the human errors that create incidents like Storm-0558.
IBM's 2025 Cost of a Data Breach Report puts the global average breach cost at $4.44 million — a 9% decrease from 2024, driven largely by faster detection and containment. Organizations with mature key management practices detect breaches faster because they have the audit trails to trace anomalous access.
Symmetric encryption and compliance requirements
Compliance frameworks don't prescribe specific algorithms in most cases, but they do require demonstrably strong encryption — and AES-256 is the benchmark auditors expect to see.
GDPR Article 32 requires "appropriate technical and organisational measures" to protect personal data, explicitly citing encryption as an example. PCI DSS v4.0 Requirement 3.5.1 mandates strong cryptography for stored primary account numbers, with AES-256 as the accepted standard. HIPAA's Security Rule (45 CFR § 164.312(a)(2)(iv)) treats encryption of data at rest as an addressable implementation specification — meaning organizations must implement it or document why an equivalent alternative is in place.
For organizations subject to NIS2, the directive requires "state of the art" cryptographic measures for critical infrastructure. AES-256-GCM satisfies that requirement today. Weaker algorithms — 3DES, DES, or AES-128 in unauthenticated modes — do not.
The connection between encryption choices and compliance outcomes is direct. Using a deprecated algorithm like 3DES (which NIST deprecated in SP 800-131A Rev. 2) in a PCI DSS audit is a finding. Using AES-256-GCM with documented key management is not.
Conclusion
Symmetric algorithms occupy a pivotal place in the realm of cryptography. Their efficiency and speed make them an invaluable asset for many applications, especially those involving large-scale data encryption. However, the limitations inherent in symmetric algorithms, including key management complexities, lack of authentication, and absence of perfect forward secrecy, necessitate meticulous implementation and the incorporation of additional security measures.
Therefore, the decision to utilize symmetric algorithms should be made based on a thorough understanding of these pros and cons, as well as the specific requirements of the system in question.
FAQ: Symmetric algorithms for data security
What is the difference between symmetric and asymmetric encryption?
Symmetric encryption uses one shared key for both encryption and decryption. Asymmetric encryption uses a mathematically linked key pair: a public key to encrypt and a private key to decrypt. Symmetric algorithms are faster and suited for bulk data; asymmetric algorithms solve the key distribution problem and enable digital signatures. Modern systems use both in combination.
Is AES-256 quantum-resistant?
AES-256 is considered quantum-resistant under current projections. Grover's algorithm reduces the effective security of AES-256 from 256 bits to 128 bits on a quantum computer — a level that remains computationally infeasible to attack with any known or projected hardware. Asymmetric algorithms like RSA and ECDH are far more vulnerable to quantum attacks via Shor's algorithm and are the primary focus of NIST's Post-Quantum Cryptography standardization effort.
What is the key distribution problem in symmetric encryption?
The key distribution problem is the challenge of securely sharing a symmetric key between two parties over an untrusted channel. If the key is transmitted insecurely, an attacker who intercepts it can decrypt all protected data. The standard solution is hybrid encryption: an asymmetric key exchange (such as Diffie-Hellman) establishes the shared symmetric key without transmitting it directly, eliminating the exposure.
Why do enterprises use AES-256-GCM instead of AES-256-CBC?
AES-256-GCM provides authenticated encryption — it encrypts data and generates a message authentication code in a single operation, detecting any tampering with the ciphertext. AES-256-CBC encrypts data but provides no integrity verification on its own. Without a separate HMAC, CBC-mode ciphertext is vulnerable to padding oracle attacks and bit-flipping. GCM mode is the current best practice for new implementations.
What is a Hardware Security Module (HSM) and why does it matter for key management?
An HSM is a tamper-resistant hardware device that generates, stores, and uses cryptographic keys without ever exposing the raw key material to the host system's software or memory. Keys created inside an HSM cannot be extracted, even by administrators. HSMs are used to protect root keys, signing keys, and master encryption keys in high-assurance environments. They are required by PCI DSS for protecting key-encrypting keys and are a best practice for any organization managing long-lived cryptographic material.
How does the "Harvest Now, Decrypt Later" threat affect symmetric encryption?
HNDL is an attack strategy where adversaries collect encrypted data today and store it until quantum hardware capable of breaking the encryption becomes available. Symmetric encryption protected with AES-256 is significantly more resistant to this threat than asymmetric encryption: Grover's algorithm reduces AES-256 to 128 bits of effective security, which remains infeasible to attack. Data protected only with RSA or ECDH is at higher risk, since Shor's algorithm could break those algorithms on a sufficiently powerful quantum computer.
What symmetric algorithms should organizations avoid in 2026?
DES (56-bit key) has been broken since the late 1990s and should never be used. 3DES was deprecated by NIST in SP 800-131A Rev. 2 (2019) and is disallowed in new systems. Blowfish is a legacy algorithm superseded by AES. RC4 is broken and prohibited in TLS. Any AES implementation without authenticated encryption (GCM or CCM mode) should be treated as incomplete. The current standard for new implementations is AES-256-GCM or ChaCha20-Poly1305.
In an era where cybercrime is rampant, businesses must take a proactive approach to safeguard their confidential information. In 2021 alone, over 118 million people have been affected by data breaches, and this number is expected to rise exponentially.
In this post, we’ll discuss some of the best practices for businesses to protect themselves from cyber threats.
Always have a back-up
A good backup system is one of the best ways to maintain computers’ security and protect your business’s data. Regularly backing up important files can help ensure that you don’t lose any information if a cyber incident or computer issue occurs. Here are some tips on how to effectively back up your data:
Use multiple backup methods. Have an effective backup system by using daily incremental backups to portable devices or cloud storage, end-of-week server backups, quarterly server backups, and yearly server backups. Remember to regularly check and test whether you can restore your data from these backups.
Use portable devices. Consider using external drives or portable devices such as USB sticks to store your data. Store the devices separately offsite, and make sure they are not connected to the computer when not in use to prevent malicious attacks.
Utilize cloud storage solutions. Cloud storage solutions are a great way of backing up all your important information. Choose a solution that provides encryption for transferring and storing your data and multi-factor authentication for access.
Practice safe backup habits. Make it a habit to regularly back up your data, not just once but multiple times throughout the week or month, depending on the type of information you’re backing up. Additionally, it’s important to practice safe backup habits, such as keeping your devices away from computers when not in use and regularly testing that your data is properly backed up.
Train your employees
To protect your business from cyber threats, educating your employees about the risks and how to stay safe is essential. Training should focus on identifying phishing emails, using strong passwords, and reporting any suspicious activity immediately to the IT department.
Ensure that everyone is up-to-date with the latest threats and strategies for protection by conducting regular cybersecurity training sessions with all of your employees. Provide helpful resources such as tips for creating secure passwords, methods for spotting phishing attempts, and steps for safely sharing confidential information online.
Putting this emphasis on education and training will help create an environment of alertness so that any potential risk can be identified quickly and addressed appropriately.
Password management
Weak passwords are one of the most common entry points for cyber attackers, so using a secure password and password manager is essential to keep your business safe.
A password manager is a tool that allows you to store and manage all your passwords securely, with only one strong master password needed to access them all. Here are some tips for creating strong passwords and using a reliable password manager:
Create strong passwords. Choose passwords that include numbers, symbols, upper-case letters, and lower-case letters. Avoid using personal information like birthdays or pet names in your passwords. Additionally, avoid using the same username/password combination for multiple accounts.
Use a password manager. A reliable password manager will help you create and store secure passwords. Be sure to select a trustworthy provider, as they will be responsible for protecting your data.
An on-premise password manager like Passwork is an excellent option for businesses that need to store passwords on their own servers. Passwork provides the advantage of having full control over your data and features like password sharing and a secure audit log.
Enable multi-factor authentication. Adding an extra layer of security to your accounts is easy with multi-factor authentication (MFA). MFA requires two or more pieces of evidence to authenticate the user's identity, such as passwords and biometric data. Most password managers can enable MFA for all your accounts, so be sure to take advantage of this feature.
Finally, make sure you update your passwords regularly and always keep them private. Following these tips will help ensure that you are protecting your business from cyber threats.
Securing your network
Using a Virtual Private Network (VPN) effectively protects your business's sensitive data and prevents unauthorized access to your network. A VPN creates an encrypted connection between your device and the internet, making it more difficult for hackers or malicious actors to intercept and access confidential information. Here are some tips on how to leverage a VPN for optimal security:
Research the best VPN providers for features that best suit the needs of your organization
Ensure that the provider meets industry standards such as AES 256-bit encryption
Set up two-factor authentication with users’ login credentials
Configure the VPN for reliable and secure connections
Monitor your network for any suspicious activity or unauthorized access attempts
Make sure to update the VPN software with new security patches regularly
Train users on the proper internet safety and best practices when using a VPN
Use an antivirus program and scan all devices connected to the network for malware threats
VPNs are not only important for protecting data and preventing unauthorized access but also for maintaining user privacy. By encrypting the data sent and received over the internet, your organization can ensure that any information stays secure and confidential.
Consistent vulnerability assessments are crucial
Organizations of all sizes must remain vigilant in mitigating cyber threats — and one of the best ways to do this is by conducting regular vulnerability assessments. This will help identify any potential weaknesses or vulnerabilities that could be used by malicious actors to gain access to your system, allowing you to patch and address them before they become a problem.
Here are a few steps to help get you started:
Develop an assessment plan for your organization
Before starting, it’s important to understand the scope and objectives of the vulnerability assessment. Define the overall goals and objectives before identifying any assets or systems that should be included in the assessment.
Identify and document threats
Once you have developed a plan, it’s time to begin searching for potential vulnerabilities within your system. You can use various open-source intelligence techniques, such as scanning public databases and researching known security issues with similar software versions or operating systems that are present in your system.
Create a testing environment
After potential threats have been identified and documented, you should create a safe testing environment to validate the vulnerability assessment results. Doing so will help ensure that any tests conducted do not adversely affect production systems.
Run automated scans
Following the creation of your secure test environment, it’s time to run automated scans on your organization's target systems or assets. This should include both internal and external scanning tools, such as port scanners, web application scanners, or configuration management tools, depending on the scope of the assessment.
Analyze scan results
Once the automated scans have been completed, it’s time to analyze the results and identify any potential issues or vulnerabilities. Assess any weaknesses present in order to prioritize and address them more effectively.
Develop a remediation plan
After identifying potential security issues, you should develop a remediation plan based on the risk level of each issue. This could include patching vulnerable systems, implementing new security measures, or restricting access to certain areas of your system, depending on the severity of the threat.
By conducting regular vulnerability assessments, organizations can stay ahead of cyber threats and ensure their systems remain secure.
Bottom line
Protecting your business from cyber threats should be a top priority for any organization. With the increasing prevalence of cybercrime and data breaches, implementing effective cybersecurity practices is more important than ever.
By regularly backing up important files, training employees on identifying and reporting potential threats, using a secure password manager, utilizing a VPN, and conducting consistent vulnerability assessments, businesses can significantly reduce their risk of falling victim to cyber-attacks.
We live in a digital age, and children must learn about internet safety as a first port of call. They are constantly on their phones and tablets, and many of them complete their coursework online. To secure personal information, all of these services require a password, but the passwords are frequently pre-set for youngsters, who do not get to create their own.
Children will never learn how to create secure passwords if such passwords are never changed. This renders them vulnerable to hacking. It is our responsibility as parents to educate our children about internet safety. This includes not only stopping kids from accessing improper information, but also explaining why. The greatest method for children to learn about computer security is to see adults who are skilled in the field. Continue reading to learn how to teach your children about password security fast and effortlessly.
Make unique and fun passwords
Passwords should be easy for your children to remember but tough for others to guess. That may appear to be an oxymoron, but if you make it fun, your child will be more likely to remember their passwords. Here are some easy ideas to get their creative juices flowing:
• Make up your own sentences or words. If they had a favorite stuffed animal as a youngster, try to integrate it, but don't make it the sole word. Use three or more to create complexity.
• Use basic, popular passwords such as ABCDE, 123455, or "password" instead. Hackers can easily breach them and obtain access to your accounts.
• Use passwords that are at least eight characters long
• Use numbers, uppercase letters, and symbols as needed. Also, avoid using them in apparent ways. Avoid substituting letters for vowels, such as an exclamation point (!) for I and an at symbol (@) for a. These are basic replacements that are easy to understand.
• Create unique passwords for each website. If your password is hacked and you use it in several places, hackers will have access to your children's sensitive information in multiple areas.
Passwords should not be shared
This one may be difficult for your children to grasp. They do, after all, know your phone's password! However, it is critical that your children do not share their passwords with anyone other than their parents—including their siblings. The more people who know their password, the more likely it is that people who should not have access to their accounts will.
Explain some of the scenarios that could occur to your children to ensure that they understand why they should not share their passwords. Listed below are a few examples:
• Someone could steal their identity
• Someone could send hurtful messages and jeopardize friendships
• Someone could open accounts on questionable platforms using their identity
• Someone could change their passwords and keep them from accessing their accounts
• If there are bank accounts attached, someone could spend their money
These are just a few examples, but they should be enough to convince your children not to share their passwords. If they do, they must inform you of who they shared it with and why. You can then decide whether or not to change their passwords.
Remember, as a parent, this does not apply to you. As a precaution, you should have all of your children's passwords who are under the age of 18. This will give you peace of mind because you will know you can monitor their online activity for their safety and security. There are many frightening people out there, and not just those looking to steal their passwords.
Avoid using the same password in multiple places
It may be difficult to keep track of so many different passwords, but it is critical that you and your child develop a unique password for each website, platform, or program. This will assist to safeguard their data:
• If there is a data breach in one place, they simply need to be concerned about that one location
• If you use the same password, they may have access to far more information, which might be harmful
Your child may not be able to use a password manager at school, but there are security services that can assist you in storing passwords across various platforms. They can also generate secure passwords that are difficult to decipher. These are useful tools, but you should not rely only on them for all of your passwords in case you are locked out.
What does a strong password look like?
You may be asking what makes a password strong now that you know what to do and what to avoid while teaching your children password safety. There are several approaches to constructing a secure password, and you must ensure that passwords are simple for your youngster to remember.
One method is to speak to their interests or their sense of humor.
• Use their passions as a source of inspiration. If they enjoy magic, you may perform something like AbramagiCkadabrA#7. This is an excellent password since it includes random capitalization, a number, and a distinctive character.
• Use something amusing for them. For example, because little children are typically delighted by potty humor, you may establish their username @uniFARTcorn3. Again, you've covered all of the possible factors for password requirements, and your kids will have a good time inputting it.
• Make use of meals and pastimes. You might, for example, create their password Apple3picking! EAO. They enjoy apple harvesting, their favorite number, a special character, and strange apple orchard letters or abbreviations.
You want to make your password difficult to guess but easy to remember, so choosing items that will activate your memory or make you smile when your child enters it will increase the likelihood that they will remember it.
It is not suggested to keep a digital file of passwords on your computer, but if necessary, you may write them down for your children until they learn them. Just be careful not to lose track of where you wrote them!
We have made enormous leaps forward in terms of technology over the past decade. However, the growth of cyberspace brings with it new challenges for cybersecurity; cybercriminals have adapted their techniques to the new environment. Nevertheless, there is a solution to every challenge.
In light of this, let's take a look at some of the most serious cybersecurity threats and the solutions that have been offered for them in 2023.
The biggest threats to cybersecurity today and how to combat them
Adaptation to a remote workforce
Employees encounter one of the most common security threats when working from home. Employees may mistakenly let hackers access their computers or corporate files due to inattention, weariness, or ignorance. However, protecting remote and hybrid working environments will remain the most difficult tasks in the world of cyber security.
Cloud-based cybersecurity solutions that safeguard the user's identity, devices, and the cloud are essential for secure remote working.
Blockchain and cryptocurrency attacks
Attacks on blockchain-based systems can be launched by both outsiders and insiders. Many of these assaults use well-known tactics such as phishing, social engineering, data-in-transit attacks, and those that focus on coding faults.
To defend organizations against cyberattacks, stronger technological infrastructure may be constructed using blockchain-powered cybersecurity controls and standards. Combining the blockchain with other cutting-edge technologies like AI, IoT, and machine learning may also be required.
Ransomware development
Ransomware is a type of virus that encrypts files on a victim's computer until a ransom is paid. Historically, organizations could keep their data fairly safe by using a standard backup procedure. The organization may be able to restore the data held hostage without paying the ransom, but this does not guarantee that the bad guys will not try to take over the data.
As a result, users must prioritize frequently backing up their devices, employing cutting-edge anti-malware and anti-phishing solutions, and keeping them up to date at all times
BYOD policies
Personal devices are more likely to be used to breach company networks, whether or not BYOD is permitted by IT, because they are less secure and more likely to contain security weaknesses than corporate devices. As a result, businesses of all sizes must understand and address BYOD security.
Among the management options are BYOD services, and the process begins with enrollment software that adds a device to the network. Company-owned devices can be configured individually or in bulk.
The dangers involved with serverless apps
For some developers, the event-driven nature of serverless computing and the lack of permanent states are drawbacks. Developers that need persistent data may encounter problems since the values of local variables may not survive between instantiations.
Enlisting the support of your company's cybersecurity expertise may be the best line of action for those who use serverless architectures.
Supply chain attacks are increasing
An attack on the supply chain happens when someone breaches your digital infrastructure by leveraging an external supplier or partner who has access to your data and systems. This type of attack is known as a supply chain assault.
Upkeep and maintenance of a highly secure build infrastructure, fast software security upgrades, and the creation of safe software updates as part of the software development life cycle are all essential.
Preventive social engineering measures
Cybercriminals use social engineering to get critical information from their targets by influencing their psychology. It causes users to make security mistakes and steal sensitive information such as banking passwords, login information, system access, and other similar information.
To avoid cyberattacks, organizations should employ a technology-and-training-based strategy. There is no one-size-fits-all solution to defeating these social engineers; instead, you must adopt an integrated approach that includes multi-factor authentication, email gateways, respected antivirus software, staff training, and other components to thwart such social engineering assaults.
Cyber security challenges in different industries
Cybersecurity issues are common anywhere cyberspace is used. Some significant industries that face specific cybersecurity challenges in business are listed below.
Vehicular communications
As Vehicle-to-Everything (V2X) communication technologies evolve and current cars are able to interface with external infrastructure, the necessity of securing communications becomes increasingly apparent. There is a very real possibility that the vehicles of today may be the targets of cyberattacks that are directed at vehicular communications.
Cybersecurity challenges in the healthcare industry
Cybercriminals continue to develop new methods to attack healthcare cybersecurity policies, whether it be high-value patient data or a low tolerance for downtime that might interfere with patient care. Both of these vulnerabilities present opportunities for cybercriminals. Hackers now have access to a market worth $13.2 billion thanks to the 55% rise in cyberattacks on healthcare providers that have occurred over the past several years. This has turned the healthcare industry into a veritable gold mine.
Banking
Threats are constantly evolving and the cybersecurity landscape is constantly changing. With huge sums of money and the potential for significant economic shocks at stake in the banking and financial business, the stakes are high in this area. A significant hacking assault on banks and other financial institutions might result in severe economic consequences.
Online retailing
Retailers present a favorable and low-risk target environment for those who commit cybercrime. These businesses are responsible for the processing, storage, and protection of the data and sensitive information of their customers. This information may include financial credentials, usernames, and passwords. These details are susceptible to being attacked because of the ease with which they might be utilized in both online and offline operations.
Conclusion
Recent years have demonstrated how the key cyber security issues and threat actors are adapting their techniques to a changing global environment. The greatest strategy to safeguard your organization and plan for cybersecurity in 2023 is to be proactive. A single data breach can cost millions of dollars in lost data, penalties, and regulatory action. Understanding the hazards that are on the horizon will allow you to account for them in your procedures and stay one step ahead of attackers.
Of course you want to keep your data safe. So why are so many security precautions frequently overlooked? Many accounts, for example, are protected by weak passwords, making it easy for hackers to do their work. There is a fine line between selecting a password that no one can guess and selecting a password that is easy to remember. As a result, we will examine this topic in depth today and ensure that you no longer need to click on the "lost password" link.
What exactly is a strong password?
So let's begin with a definition. A secure password is one that cannot be guessed or broken by an intruder.
Computers are utilized by hackers in order to try out various combinations of letters, numbers, and symbols. Passwords that are only a few characters long and consist entirely of letters and digits are easy for modern computers to crack in a couple of seconds. Because of this, it is vital to utilize robust combinations of capital and lowercase letters, numbers, and special characters in one password. There is a minimum length requirement of 12 characters for passwords, although using a longer password is strongly encouraged.
To summarize the attributes of a secure password, they are as follows:
• At least 12 characters are required. The more complicated your password, the better.
• Upper and lower case letters, numbers, and special characters are included. Such passwords are more difficult to crack.
• Does not contain keyboard paths
• It is not based on your personal information
• Each of your accounts has its own password
You have undoubtedly observed that a variety of websites "care" about the security level of your password. When you are making an account, you will frequently see tooltips that remind you to include a particular amount of characters, as well as numbers and letters. Weak passwords have a far higher chance of being disapproved by the system. Keep in mind that, for reasons related to your security, you should never use the same password for several accounts.
A secure password should be unique
You may use a strong password for all of your accounts after you've created one. However, doing so will leave you more exposed to assaults. If a hacker obtains your password, they will be able to access whatever account you used it for, including email, social media, and work accounts.
According to surveys, many people use the same password because it is easier to remember. Don't worry, there are several tools available to assist you with managing multiple passwords. We'll get to them later.
While adding special characters in passwords is an excellent approach to increase their security, not all accounts accept all characters. However, in most scenarios, the following are used: ! " #% & *, / : | $ ; ': _? ().
Here are some examples of strong passwords that make use of special characters:
• P7j12$# eBT1cL@Kfg
• $j2kr^ALpr!Kf#ZjnGb#
Ideas for creating a strong password
Fortunately, there are several methods for creating unique and secure passwords for each of your accounts. Let's go over each one in detail:
1. Use a password generator/password manager
If you don't have the time to come up with secure passwords, a password generator that can also serve as a manager is a very simple and straightforward solution that you may use.
2. Choose a phrase, not a word
Passwords are significantly less secure than passphrases since they are often lengthier and more difficult to guess or crack. Instead of a word, pick a phrase and use the first letters, digits, and punctuation from that phrase to generate an apparently random combination of characters. Experiment with different wording and punctuation.
Here are some examples of how the passphrases technique may be used to generate secure passwords:
• I first went to Disneyland when I was four years old and it made me happy: I1stw2DLwIw8yrs&immJ
• My friend Matt ate six donuts at a bakery cafe and it cost him £10: MfMa6d@tbc&ich£10
3. Pick a more unique option
Open a dictionary or book and select a random word, or better yet, many. Combine them with numbers and symbols to make it far more difficult for a hacker to decipher.
If you need a password that is difficult for others to guess but easy for you to remember, try variants on a phrase or statement that means something to you. Simply choose a memorable sentence and replace parts of the letters with numbers and symbols.
For example:
• “For the first time in forever”: Disney’s Frozen: 4da1stTymein4eva-Frozen
5. Make use of emojis
You may always use emoticons to add symbols to your passwords without making them difficult to remember. You can't add emojis, but you can attempt emoticons made out of punctuation marks, characters, and/or numbers.
For example:
• \_(ツ)_/¯
• (>^_^)> <(^_^<)
• (~.~) (o_O)
What should I do after I have created a password?
1. Set passwords for specific accounts You'll still need to generate a unique password for each of your accounts once you've created a strong password that you can remember. Instead of creating several new ones, you may include the name of the platform you use at the end. For example, if your password was nHd3#pHAuFP8, just add the word EMa1l to the end of your email address to get nHd3#pHAuFP8EMa1l.
2. Make your password a part of your muscle memory If you want to be able to recall your password, typing it out several times can help you do so. You will be able to memorize information far more easily as a result of the muscle memory that you will develop.
How to keep your passwords safe?
1. Choose a good password manager Use a trustworthy password manager whether you're setting your own safe passwords or looking for an internet service to handle it for you. It creates, saves, and manages all of your passwords in a single safe online account. All you have to do is put all your account passwords in the application and then safeguard them with one "master password". This means you just have to remember a single strong password.
2. Use two-factor authentication You've heard it before, but we'll say it again. Two-factor authentication (2FA) adds an additional level of protection. Even if someone steals your password, you can prevent them from accessing your account. This is often a one-time code supplied to you by text message or other means. Receiving an SMS, by the way, is not the most secure method since a hacker might obtain your mobile phone number in a SIM swap fraud and gain access to your verification code.
Apps using two-factor authentication are far more secure. Google Authenticator, for example, or Microsoft Authenticator.
3. Passwords should not be saved on your phone, tablet, or computer Although it might not be immediately visible, this is a common approach for people to save their passwords. That should not be done. Your files, emails, messenger conversations, and notes may all be hacked.
4. Keep your password confidential Even if you completely trust the person to whom you are handing your password, sending it in a text message or email is risky. Even if you speak it aloud or write it down on paper, someone who is interested can overhear you and take notes behind you.
Ransomware assaults are something that all of us have been keeping an eye on for some time. According to the most recent findings, over 21 percent of companies throughout the world were victims of ransomware attacks in 2022. 43% of these had a substantial influence on the way in which their business activities were carried out.
It’s true that cybercrime is on the rise, and those who commit these crimes are going after both individuals and businesses. In order to maintain a competitive advantage, it is essential to have a solid understanding of the types of cyber threats that will be prevalent in 2023.
The purpose of this article is to familiarize you with the most important developments in the field of cybersecurity that are expected to take place in 2023. There are a lot of different things to keep an eye on here, from emerging malware to security solutions based on artificial intelligence. In this section, we will discuss the potential effects of these trends on the future of cybersecurity and the steps you can take to better defend yourself.
Top 5 cybersecurity trends for 2023
1. The Internet of Things (IoT) and cloud security
It's critical to stay up to date on the newest cybersecurity developments in an ever-changing technological context. As more firms utilize cloud computing and Internet of Things (IoT) technology, the importance of adequate security measures grows.
When it comes to IoT and cloud security, it is critical to recognize the particular dangers that these technologies entail. One of the most serious concerns about IoT devices, for example, is that they are frequently "always on," leaving them exposed to external assaults. Similarly, if security mechanisms are not adequately established, cloud services might be accessible to hackers.
It is critical to have robust security procedures for your IoT devices and cloud services in order to keep your organization secure. This includes adopting strong passwords on all devices, enabling multi-factor authentication for access control, and ensuring that any data saved in the cloud is encrypted.
2. SaaS security solutions are becoming increasingly popular
As businesses and consumers rely more on cloud computing and software solutions, the requirement for effective security becomes even more critical. When compared to traditional on-premises solutions, SaaS security solutions provide rapid scale-up or scale-out based on demand and cost savings. These solutions are also well suited for working with remote or dispersed teams where several business components may be located all over the world.
Data protection, identity and access management, web application firewalls, and mobile device security are all available through Security as a Service (SECaaS) solutions. They also provide managed services, which allow customers to delegate the monitoring and maintenance of their cloud security systems to qualified specialists. This helps guard against dangers like malware and ransomware while also keeping businesses up to date on the newest security developments.
3. Increased security for remote and hybrid employees
As the world continues to migrate to remote and hybrid work arrangements, cybersecurity must change to meet these new needs. Organizations must safeguard their systems and train their staff with cyberthreat defenses as their dependence on technology and access to sensitive data grows.
Multi-factor authentication (MFA), which requires multiple authentication stages to validate a user's identity before giving access to systems or data, is one security protocol that organizations should consider using. MFA can offer an extra degree of security against attackers who use stolen credentials to gain access to accounts.
Businesses should also consider adopting rules and processes to ensure the security of their workers' devices. This may involve offering safe antivirus software and encrypted virtual private networks (VPNs) for remote connectivity to employees. Employees must also be trained on the significance of using strong and unique passwords for each account, alongside the risks of connecting to public networks.
4. Machine learning and artificial intelligence
Artificial intelligence and machine learning have grown in popularity in the realm of cybersecurity in recent years. AI and machine learning (ML) offer automated threat detection and enhanced security processes, making them effective instruments in the battle against cyberattacks. Organizations may employ AI and machine learning to proactively detect and avoid dangers as these technologies evolve.
AI and machine learning can assist in the rapid and accurate analysis of vast volumes of data, enabling more effective threat identification and prevention. For example, AI may detect harmful or suspicious network activities, such as increased traffic from a certain source or trends in user behavior. Organizations can also use machine learning algorithms to identify abnormalities and prioritize warnings that may signal a possible breach.
Furthermore, AI and machine learning can automate key cybersecurity operations like patch management, malware detection, and compliance checks. Organizations can save time and money that would otherwise be spent on manual processes. Furthermore, the application of AI and machine learning may assist businesses in lowering the risk of false positives and ensuring that only the most critical security incidents are highlighted.
5. Creating a Safe Culture
Businesses in today's environment must cultivate a culture of safety. Security cannot be handled after the fact or as a one-time job. It should be the organization's fundamental value, ingrained in all parts of its operations. This implies that everyone in the business must be informed of current cybersecurity trends and understand how to secure their data.
Employee training and checks and balances should be part of a safe culture. All personnel should be trained in the fundamentals of Internet security, as well as how to utilize systems and software safely. Policies, systems, and processes should be evaluated on a regular basis to ensure they are in compliance with the most up-to-date security guidelines.
Conclusion
As technology advances, cybersecurity risks and patterns will alter. Businesses must keep ahead of the curve by monitoring emerging trends and updating their security measures as needed. Organizations can secure their data and networks from intruders by staying up to date with the newest 5 cybersecurity trends in 2023.
Organizations may maintain the security of their data by keeping with the times on trends and implementing the required safeguards. Furthermore, they should work to educate their personnel on the need to adhere to best practices in cybersecurity. This will aid in the creation of a secure environment and reduce the likelihood of hacking.
The most frequently-used password globally is "123456”. However, analyzing passwords by country can yield some quite fascinating results.
We frequently choose weak passwords such as "123456" since they are easy to remember and input. The differences between such passwords can sometimes be found in the language itself. For example, if the English have "password" at the top of their list, the Germans prefer "passwort", and the French use "azerty" instead of "qwerty" due to the peculiarities of the French keyboard layout, which has the letter A instead of the usual Q.
When a weak password is driven by culture, things get much more intriguing. The password "Juventus" is likely to appeal to fans of the Italian football team Juventus. This password is also the fourth most popular option among Italian Internet users. The club is from Turin, Piedmont, and is supported by about 9 million people. At first look, the unique password "Anathema" appears to be a typical occurrence in Turkey, where the British band Anathema's name is among the top ten most common passwords.
A weak password is widespread
ExpressVPN together with Pollfish interviewed 1,000 customers about their password preferences in order to learn more about how individuals approach password formation.
Here are some of their findings:
• The typical internet-goer uses the same password for six different websites and/or platforms
• Relatives are likely to be able to guess their passwords from internet accounts, according to 43% of respondents
• When generating passwords, two out of every five people utilize different variants of their first and/or last name
These findings demonstrate a lack of cybersecurity knowledge, despite the fact that 81% of respondents feel confident in the security and privacy of their existing passwords.
According to the survey results, passwords frequently contain personal information. Below, you will find the most shared personal information with the percentage of respondents who revealed that their passwords contained personal information.
• First Name (42.3%)
• Surname (40%)
• Middle Name (31.6%)
• Date of birth (43.9%)
• Social security number (30.3%)
• Phone number (32.2%)
• Pet name (43.8%)
• Child's name (37.5%)
• Ex-partner's name (26.1%)
The most common passwords in various countries
Based on an infographic from ExpressVPN, the picture below illustrates the most often used passwords in various nations, practically all of which are in the top ten in their respective countries. Many are exclusive to these nations and demonstrate how cultural influences impact password creation.
Much of the information presented comes from a third-party study of stolen credentials (which were made public by Github user Ata Hakç). These datasets are based on the language of the individual sites, allowing the information to be distributed by country.
Let's have a look at some interesting variations of passwords. For instance, the phrase "I love you forever" may be deciphered from the password "5201314," which is commonly used by people from Hong Kong. In contrast, users in Croatia make use of the password “Dinamo”, which is derived from the name of an illustrious football team based in Zagreb. Martin is the password that is used by people from Slovakia. In Slovakia, the name Martin has a position as the fourth most common name. The Greeks, on the other hand, chose not to put undue effort into themselves and instead went with the most straightforward password out of the list, which was 212121. On the other hand, Ukrainians use the pretty difficult password Pov1mLy727. Apart from Ukraine, there are other countries where users more often than not create strong passwords. Let’s take a look.
These 10 countries create the strongest passwords
According to the results of the National Privacy Test that was carried out by NordVPN, the greatest marks were obtained by Italians in regard to their understanding of robust passwords. The following is a list of the top ten nations in which people come up with the most complicated passwords.
1. Italy 94.3 (points out of 100)
2. Switzerland 94
3. Spain 93.5
4. Germany 93.3
5. France 92.3
6. Denmark 91.8
7. UK 90.7
8. Belgium 90.4
9. Canada 89.4
10. USA 89.3
The top 10 did not include Australia (88.9), South Africa (86.2), Saudi Arabia (85.7), Russia (81.4), Brazil (81.2), Turkey (73.9), and India (78.4).
"This study demonstrates that individuals from all around the world are aware of how to generate secure passwords. The information is there, but people aren't using it in the right ways," says Chad Hammond, a security specialist at NordPass.
Also in November 2022, NordPass published a study that found out which passwords network users use most often. According to the findings of the survey, the majority of individuals still rely on simple passwords such as their own names, the names of their favorite sports teams or foods, simple numerical combinations, and other straightforward options.
NordPass security specialist Chad Hammond also stated, "Using unique passwords is really crucial, and it's scary that so many individuals still don't." It is critical to generate distinct passwords for each account. "We put all accounts with the same password in danger when we reuse passwords: in the case of a data breach, one account at risk can compromise the others."To summarize, it is reasonable to state that it does not matter where you were born, where you live, or what you are passionate about; you must always use unique passwords. We recommend that you make your password difficult to guess by making it more complicated or by using a password generator. This will increase the level of security provided by your password. In addition to this, we strongly suggest that you take advantage of two-factor authentication wherever it is an option. If you add an additional layer of protection to your accounts, be it in the form of an app, biometrics, or a physical security key, you will notice a significant increase in their level of security.
Ein Passwort mit chinesischen Schriftzeichen kann sehr sicher sein, wenn die Zeichen zufällig gewählt werden, das Passwort ausreichend lang ist und die Website oder Anwendung Unicode korrekt verarbeitet. Chinesische Schriftzeichen machen ein Passwort nicht automatisch stark. Vorhersagbare Phrasen, Daten, Namen und wiederverwendete Passwörter bleiben unabhängig vom verwendeten Zeichensatz anfällig.
Die Frage ist wichtig, weil die Antwort tatsächlich geteilt ist. Die Mathematik spricht für chinesische Schriftzeichen – ein größerer Zeichenpool erhöht die theoretische Entropie pro Zeichen. Die realen Daten erzählen eine komplexere Geschichte. Eine USENIX Security-Studie aus dem Jahr 2019 analysierte 73,1 Millionen chinesische Web-Passwörter und stellte fest, dass viele davon anfälliger für Online-Rateangriffe waren als ihre englischen Pendants. Dieser Artikel beleuchtet beide Seiten: die Entropie-Mathematik, die Verhaltensbefunde, die Unicode-Implementierungsrisiken und was IT-Teams mit diesen Informationen tatsächlich anfangen sollten.
Wichtigste Erkenntnisse
Ein größerer Zeichensatz erhöht die theoretische Entropie, aber nur wenn die Zeichen zufällig gewählt werden. CJK-Zeichen umfassen Zehntausende von Unicode-Codepunkten im Vergleich zu 95 für druckbares ASCII. Diese Lücke ist auf dem Papier real. Sie verschwindet in dem Moment, in dem ein Mensch eine erkennbare Phrase anstelle einer zufälligen Zeichenfolge wählt.
Von Menschen gewählte chinesische Passwörter sind oft schwächer als sie erscheinen. Eine USENIX Security-Studie aus dem Jahr 2019 analysierte 73,1 Millionen reale chinesische Web-Passwörter und stellte fest, dass diese anfälliger für Online-Rateangriffe waren als englische Passwörter. Pinyin-Sequenzen, kulturell übliche Ziffernfolgen und bekannte Phrasen sind in sprachspezifischen Angriffswörterbüchern gut vertreten.
Unicode-Kompatibilität ist auf vielen Systemen ein ungelöstes Problem. Authentifizierungssysteme, die auf ASCII-Annahmen aufgebaut wurden, können Nicht-ASCII-Eingaben ablehnen, inkonsistente Normalisierung anwenden, Bytes statt Zeichen zählen oder Passwörter stillschweigend kürzen. Ein Passwort, das bei der Kontoerstellung funktioniert, kann beim Login, bei der Wiederherstellung oder auf einem mobilen Gerät versagen.
Länge und Zufälligkeit sind wichtiger als die verwendeten Zeichen. NIST, OWASP und CISA verweisen alle auf dieselbe Grundlage: lange, einzigartige, zufällig generierte Passwörter, die in einem Passwort-Manager gespeichert und mit MFA kombiniert werden. Die Zeichenkategorie ist eine nachrangige Überlegung.
Passwortkomplexität schützt nicht vor Phishing, Credential Stuffing oder Session-Diebstahl. Vier der fünf größten US-Mega-Datenlecks im Jahr 2024 betrafen gestohlene oder kompromittierte Passwörter. Der verwendete Zeichensatz war irrelevant. MFA, einzigartige Passwörter pro Account und Blocklisten für kompromittierte Passwörter sind die Maßnahmen, die das reale Risiko reduzieren.
Sind Passwörter mit chinesischen Schriftzeichen tatsächlich sicherer?
Sie können es sein, aber nicht automatisch. Die Sicherheit jedes Passworts hängt davon ab, wie unvorhersagbar es für einen Angreifer ist. Ein größerer Zeichensatz erhöht die theoretische Anzahl möglicher Passwörter. CJK-Zeichen in Unicode umfassen Zehntausende von Codepunkten – verglichen mit 95 für druckbares ASCII. Auf dem Papier ist diese Lücke erheblich.
Das Problem ist, dass theoretische Stärke eine zufällige Auswahl voraussetzt. Von Menschen gewählte Passwörter funktionieren nicht so. Ein Passwort, das aus einer erkennbaren chinesischen Phrase, einer Zeichenfolge verbunden mit einem Namen oder Datum oder einem kulturell üblichen Muster besteht, gibt einem Angreifer ein viel kleineres Ziel als der gesamte Zeichensatz vermuten lässt. Ein sprachbewusstes Wörterbuch, das aus echten chinesischen Passwörtern erstellt wurde, kann 我的密码 (Chinesisch für „mein Passwort") in Sekunden knacken – unabhängig davon, wie groß der CJK-Pool technisch gesehen ist.
Der Zeichensatz ist also wichtig, aber nur wenn das Passwort zufällig generiert wird. Eine bedeutungsvolle chinesische Phrase und eine zufällige CJK-Zeichenfolge sind sicherheitstechnisch nicht dasselbe.
💡
CJK-Zeichen (Chinesisch, Japanisch, Koreanisch) in Unicode umfassen Zehntausende von Codepunkten. Das ist theoretisch ein bedeutender Vorteil. In der Praxis materialisiert sich dieser Vorteil nur, wenn das Passwort zufällig generiert wird und das System Unicode korrekt verarbeitet.
Was ist ein Zeichensatz?
Zeichensatz — Die Sammlung unterschiedlicher Zeichen, aus denen ein Passwort zusammengesetzt werden kann. Standard-druckbares ASCII hat 95 Zeichen; ein gängiges CJK-Subset hat etwa 20.000. Ein größerer Zeichensatz erhöht die theoretische Anzahl möglicher Passwörter für eine bestimmte Länge, was die Kosten eines Brute-Force-Angriffs erhöht — aber nur wenn die Zeichen zufällig gewählt werden.
Was ist ein Wörterbuchangriff?
Wörterbuchangriff — Eine Methode zum Knacken von Passwörtern durch systematisches Testen einer vorgefertigten Liste wahrscheinlicher Kandidaten: gängige Wörter, Namen, Phrasen, Tastaturmuster und bekannte geleakte Passwörter. Im Gegensatz zu Brute-Force-Angriffen, die jede mögliche Kombination ausprobieren, nutzen Wörterbuchangriffe vorhersagbare menschliche Entscheidungen aus. Sprachspezifische Wörterbücher — einschließlich Pinyin-Sequenzen und kulturell üblicher chinesischer Phrasen — machen diesen Angriff auch gegen Nicht-ASCII-Passwörter effektiv.
Die Entropie-Mathematik: Warum CJK-Zeichen Stärke hinzufügen können
Passwort-Entropie misst, wie viele Versuche ein Angreifer benötigen würde, um alle möglichen Passwörter eines bestimmten Typs durchzuprobieren. Das Standardmodell lautet: Entropie (in Bits) = log₂(Zeichensatzgröße) × Passwortlänge. Eine höhere Zahl bedeutet ein schwierigeres Brute-Force-Problem.
Die folgende Tabelle zeigt, wie verschiedene Zeichenpools unter diesem Modell abschneiden. Alle Werte setzen voraus, dass das Passwort zufällig generiert wird – eine Bedingung, die von Menschen gewählte Passwörter selten erfüllen.
Passwortmodell
Angenommener Zeichenpool
Bits pro Zeichen
Anmerkungen
Druckbares ASCII
95 Zeichen
6,57
Weitgehend kompatibel; einfach für Passwort-Manager zu generieren und automatisch auszufüllen.
20.000-Zeichen CJK-Subset
20.000 Zeichen
14,29
Höhere theoretische Entropie pro Zeichen; Eingabe und Systemunterstützung sind schwieriger.
90.000-Zeichen CJK/Han-ähnlicher Satz
90.000 Zeichen
16,46
Illustrative Obergrenze; kein praktischer täglicher Eingabepool.
Gängige chinesische Phrase
Von Menschen gewählte Wörter
Nicht sicher berechenbar
Anfällig für sprachspezifische Wörterbücher unabhängig von der Zeichenanzahl.
Die Zahlen sehen für CJK-Zeichen überzeugend aus. Ein zufällig gewähltes Zeichen aus einem 20.000-Zeichen-Pool trägt mehr als die doppelte Entropie eines zufällig gewählten druckbaren ASCII-Zeichens. Ein fünf Zeichen langes zufälliges CJK-Passwort könnte theoretisch die Entropie eines zehn Zeichen langen zufälligen ASCII-Passworts erreichen.
Zwei Einschränkungen sind zu beachten:
Zufällige Auswahl. Die Formel setzt voraus, dass jedes Zeichen mit gleicher Wahrscheinlichkeit gewählt wird. Ein Mensch, der chinesische Schriftzeichen auswählt, verhält sich nicht wie ein Zufallszahlengenerator.
Systemunterstützung. Höhere Entropie pro Zeichen hilft nicht, wenn das System die Eingabe ablehnt, kürzt oder falsch verarbeitet. Theoretische Stärke und praktische Sicherheit sind nicht dasselbe.
Unicode 17.0, veröffentlicht 2025, definiert insgesamt 159.801 Zeichen über alle Schriftsysteme hinweg (Unicode Consortium, 2025). Diese Zahl wird oft zitiert, um einen enormen Passwortraum nahezulegen. Es ist erwähnenswert, dass 159.801 die Größe des gesamten Unicode-Repertoires ist – nicht ein realistischer Pool von Zeichen, aus dem ein Benutzer bei der Passworterstellung schöpfen würde. Der praktische CJK-Zeichenpool für die meisten Benutzer sind die etwa 20.000 Zeichen im allgemeinen Gebrauch, nicht das gesamte Unicode-Inventar.
Die reale Einschränkung: Chinesische Benutzer wählen oft vorhersagbare Passwörter
Der wichtigste empirische Beleg zu diesem Thema stammt aus einer USENIX Security-Studie aus dem Jahr 2019 von Ding Wang und Kollegen der Peking University, Wuhan University und der University of Virginia. Die Forscher analysierten 73,1 Millionen reale chinesische Web-Passwörter und 33,2 Millionen englische Web-Passwörter von neun Diensten, darunter soziale Foren, Gaming-Plattformen, E-Commerce-Seiten und Programmierer-Communities.
Ihr Hauptergebnis war das, was sie bifaziale Sicherheit nannten: Chinesische Passwörter waren anfälliger für Online-Rateangriffe (bis zu 10.000 Versuche) als englische Passwörter, aber die Passwörter, die diese ersten Versuche überstanden, waren stärker gegen hochvolumige Offline-Angriffe. Bei 10 Millionen Versuchen war ihr verbesserter Cracking-Algorithmus bei 33,2% bis 49,8% der chinesischen Datensätze erfolgreich – er knackte zwischen 92% und 188% mehr Passwörter als der bisherige Stand der Technik. Wie die IEEE Spectrum-Zusammenfassung der Forschung anmerkt, kann ein Passwort, das nach englischsprachigen Annahmen stark aussieht, für einen Mandarin-Sprecher sofort offensichtlich sein.
Die Muster, die Angreifer ausnutzen, umfassen:
Pinyin-Sequenzen – romanisiertes Chinesisch, wie „woaini" („Ich liebe dich"), das von Passwort-Stärke-Messern großer Dienste als „stark" bewertet wurde, obwohl es für Mandarin-Sprecher trivial zu erraten ist.
Kulturell übliche Ziffernfolgen – „5201314" klingt im Chinesischen wie „Ich liebe dich für immer"; „520" allein ist eine gängige Kurzform.
Telefonnummer-Fragmente – chinesische Benutzer fügen Mobilnummern häufiger in Passwörter ein als englischsprachige Benutzer.
Geburtstags- und Datumsformate – in Passwörtern mit höheren Raten eingebettet als in englischsprachigen Datensätzen.
Reine Ziffernfolgen – „123456", „111111", „123321" und ähnliche Sequenzen erscheinen mit hoher Häufigkeit.
Verschachtelte Muster – abwechselnde Buchstaben und Ziffern in Formaten wie „a12345" oder „12345a".
Nichts davon bedeutet, dass chinesischsprachige Benutzer weniger sicherheitsbewusst sind. Es bedeutet, dass jede Sprachgemeinschaft vorhersagbare Muster entwickelt, und Angreifer Wörterbücher erstellen, die dazu passen. Die praktische Lektion: Die Verwendung chinesischer Schriftzeichen umgeht keine Wörterbuchangriffe. Sie verändert nur, zu welchem Wörterbuch der Angreifer greift.
Der Passwortgenerator von Passwork erstellt lange, zufällige Anmeldedaten, die all diese Muster vermeiden — unabhängig davon, mit welchem Zeichensatz Sie arbeiten. Erfahren Sie, wie es funktioniert
Unicode-Kompatibilitätsrisiken: Warum manche Seiten diese Passwörter ablehnen oder beschädigen
Viele Authentifizierungssysteme wurden auf ASCII-Annahmen aufgebaut und wurden nie vollständig aktualisiert. Das Ergebnis ist eine Reihe von Fehlermodi, die Benutzer aussperren, ihre Passwörter stillschweigend schwächen oder die Wiederherstellung unmöglich machen können.
Einige Definitionen sind hier hilfreich. UTF-8 ist die gängigste Kodierung für Unicode-Text im Web – sie stellt jeden Unicode-Codepunkt als ein bis vier Bytes dar. Ein Unicode-Codepunkt ist die eindeutige Nummer, die jedem Zeichen zugewiesen ist. Unicode-Normalisierung ist der Prozess der Umwandlung visuell äquivalenter Zeichensequenzen in eine kanonische Form; NFC (Normalization Form Composed) ist der gängigste Standard für die Textspeicherung. Visuell ähnliche Zeichen sind verschiedene Codepunkte, die auf dem Bildschirm identisch aussehen, was zu Login-Fehlern führen kann, wenn sich die gespeicherten und eingegebenen Formen unterscheiden.
Risiko
Warum es wichtig ist
Empfehlung für Benutzer
Empfehlung für IT-Teams
Ablehnung von Nicht-ASCII-Eingaben
Das Passwort wird möglicherweise gar nicht akzeptiert.
Testen Sie Kontoerstellung, Login, Wiederherstellung und mobilen Zugriff, bevor Sie sich darauf festlegen.
Entfernen Sie Zeichenverbote, die keine spezifische technische Begründung haben.
Inkonsistente Normalisierung
Das gleiche sichtbare Passwort kann je nach Normalisierung des Systems unterschiedlich gehasht werden.
Vermeiden Sie kombinierende Zeichensequenzen für wichtige Accounts.
Definieren und dokumentieren Sie das Normalisierungsverhalten; wenden Sie es konsistent an jedem Eingabepunkt an.
Stillschweigende Kürzung
Zeichen jenseits eines Byte- oder Zeichenlimits können stillschweigend entfernt werden.
Vermeiden Sie Systeme, die ohne Warnung kürzen; testen Sie mit einem langen Passwort.
Kürzen Sie niemals stillschweigend; erzwingen Sie ein klares Maximum und geben Sie eine explizite Fehlermeldung zurück.
Eingabemethoden-Abhängigkeit
Benutzer können das Passwort möglicherweise nicht auf jedem Gerät oder Tastaturlayout eingeben.
Bestätigen Sie den Zugriff von mobilen Geräten, Notfall-Wiederherstellungsabläufen und jedem Gerät, das Sie in einer Krise nutzen könnten.
Testen Sie Unicode-Eingabe über Web-, Mobil-, SSO-, API- und Helpdesk-Wiederherstellungspfade hinweg.
Das Problem mit der Eingabemethode verdient besondere Aufmerksamkeit. Ein Passwort, das mit einem IME (Input Method Editor) auf einem Desktop eingegeben wird, kann auf einem abgesicherten Firmengerät, einem Hotelcomputer oder einem Telefon mit einer anderen Tastatur-App unmöglich zu reproduzieren sein. Für ein Masterpasswort oder Wiederherstellungsdaten ist das ein ernsthaftes Benutzerfreundlichkeitsrisiko.
Was moderne Passwortrichtlinien über Unicode-Zeichen sagen
OWASPs Authentication Cheat Sheet ist eindeutig: Erlauben Sie alle Zeichen, einschließlich Unicode und Leerzeichen. Es empfiehlt, auf Kompositionsregeln zu verzichten, die Zeichentypen einschränken, legt eine Mindestpasswortlänge fest, die davon abhängt, ob MFA aktiviert ist (8 Zeichen mit MFA, 15 ohne, gemäß NIST SP 800-63B), und verlangt ein Maximum von mindestens 64 Zeichen ohne stillschweigende Kürzung. Es empfiehlt außerdem, Passwörter zu blockieren, die in Datensätzen kompromittierter Passwörter erscheinen.
CISAs Richtlinien für starke Passwörter empfehlen Passwörter, die mindestens 16 Zeichen lang, zufällig und einzigartig pro Account sind – gespeichert in einem Passwort-Manager und kombiniert mit Phishing-resistenter MFA. Die Richtlinien schränken Zeichensätze nicht ein.
NISTs benutzerorientierte Richtlinien rahmen Passwörter als inhärent unsicher ein und empfehlen den Übergang zu MFA und Passkeys, wo immer möglich. Es wird darauf hingewiesen, dass Offline-Angriffe eine enorme Anzahl von Versuchen durchführen können – was Passwortlänge und Zufälligkeit zu den primären Verteidigungsmaßnahmen gegen das Knacken macht, nicht die Zeichenkategorie.
Der gemeinsame Nenner aller drei Quellen: Länge und Zufälligkeit sind wichtiger als die verwendeten Zeichen. Unicode-Zeichen sind erlaubt und können helfen, aber sie sind kein Ersatz für Länge, Einzigartigkeit und einen Passwort-Manager.
Sollten Sie chinesische Schriftzeichen in Ihrem eigenen Passwort verwenden?
Für die meisten Accounts lautet die Antwort: Lassen Sie Ihren Passwort-Manager entscheiden. Ein zufällig generiertes 20-Zeichen ASCII-Passwort aus einem Passwort-Manager hat hohe Entropie, funktioniert auf jedem System und erfordert keine manuelle Eingabe. Das ist die Grundlage.
Chinesische Schriftzeichen sind in einem engeren Rahmen sinnvoll: Der Benutzer kann sie zuverlässig auf jedem verwendeten Gerät eingeben, der Dienst unterstützt nachweislich Unicode an jedem Berührungspunkt (Login, Wiederherstellung, Mobil, API), und das resultierende Passwort ist lang, einzigartig und keine erkennbare Phrase.
Szenario
Empfohlener Ansatz
Begründung
Passwort-Manager kann generieren und automatisch ausfüllen
Langes zufälliges Passwort, üblicherweise ASCII-kompatibel
Hohe Entropie und breite Kompatibilität ohne manuelle Eingabe erforderlich.
Passwort muss auswendig gelernt werden
Lange Passphrase aus nicht zusammenhängenden Wörtern
Einfacher geräteübergreifend einzugeben; weniger abhängig von Unicode-Unterstützung.
Als Teil eines längeren einzigartigen Passworts verwenden, erst nachdem die Unicode-Unterstützung vollständig getestet wurde
Fügt mögliche Entropie hinzu, birgt aber Kompatibilitätsrisiken.
Unternehmens-Account
Richtlinie befolgen: mindestens 16 Zeichen, einzigartig, MFA erforderlich, Blockliste für kompromittierte Passwörter aktiv
Reduziert das reale Risiko von Account-Kompromittierungen in der gesamten Organisation.
Hochrisiko-Account
Starkes einzigartiges Passwort plus MFA oder Passkeys
Komplexität allein schützt nicht vor Phishing oder gestohlenen Anmeldedaten.
Das einzige Szenario, in dem chinesische Schriftzeichen einen klaren Mehrwert bieten: Ein Passwort, das ein Angreifer realistischerweise in kein Wörterbuch aufnehmen könnte, zufällig generiert, verwendet auf einem System mit verifizierter Unicode-Unterstützung. Außerhalb dieses Szenarios überwiegen die Kompatibilitätskosten oft die Entropiegewinne.
Wovor chinesische Schriftzeichen nicht schützen können
Entropie ist eine Verteidigung gegen Raten und Knacken. Sie adressiert nicht die anderen Wege, auf denen Anmeldedaten kompromittiert werden.
Der Jahresbericht 2024 des ITRC zu Datenlecks verzeichnete 3.158 US-Datenkompromittierungen und 1.350.835.988 Benachrichtigungen über Datenlecks im Jahr 2024 – ein Anstieg der Benachrichtigungen um 211% gegenüber 2023. Vier der fünf größten Mega-Datenlecks betrafen gestohlene oder kompromittierte Passwörter. Angriffe auf Ticketmaster, AT&T und Change Healthcare, unter anderem, hätten mit MFA oder Passkeys blockiert werden können. Die Zeichenkomplexität dieser Passwörter war irrelevant.
Die Bedrohungen, die Passwortkomplexität nicht adressieren kann:
Phishing – eine überzeugende gefälschte Login-Seite erfasst das Passwort unabhängig davon, wie es konstruiert wurde
Keylogging und Malware – Anmeldedaten werden bei der Eingabe erfasst, bevor die Verschlüsselung greift
Session-Diebstahl – ein Angreifer, der einen authentifizierten Sitzungstoken stiehlt, umgeht das Passwort vollständig
Credential Stuffing – wiederverwendete Passwörter aus einem Datenleck werden gegen andere Dienste getestet; Einzigartigkeit ist die einzige Verteidigung
Passwort-Wiederverwendung – ein starkes Passwort mit chinesischen Schriftzeichen, das auf fünf Accounts verwendet wird, ist fünfmal so exponiert
Social Engineering – ein Angreifer, der einen Helpdesk überzeugt, einen Account zurückzusetzen, berührt das Passwort nie
Kompromittierter Passwort-Manager-Tresor – wenn der Tresor gehackt wird und das Masterpasswort schwach ist, sind alle gespeicherten Anmeldedaten gefährdet
Die Maßnahmen, die diese Bedrohungen adressieren, sind MFA, Passkeys, einzigartige Passwörter pro Account, Blocklisten für kompromittierte Passwörter, Phishing-resistente Authentifizierung und regelmäßige Sicherheitsaudits. Ein komplexeres Passwort ist eine Schicht. Es ist kein Ersatz für die anderen.
Fazit
Chinesische Schriftzeichen können die theoretische Stärke eines Passworts verbessern – aber nur unter denselben Bedingungen, die jedes Passwort stark machen: ausreichende Länge, echte Zufälligkeit, Einzigartigkeit über Accounts hinweg und ein System, das Unicode korrekt verarbeitet. Eine bedeutungsvolle chinesische Phrase, eine Pinyin-Sequenz oder eine kulturell vertraute Ziffernfolge erfüllt diese Bedingungen nicht. Die USENIX-Forschung zu 73,1 Millionen chinesischen Web-Passwörtern macht das deutlich.
Für die meisten Benutzer lautet die praktische Antwort: Ein Passwort-Manager, der lange, zufällige Anmeldedaten generiert, kombiniert mit MFA oder Passkeys auf jedem Account, der diese unterstützt. Für IT-Teams liegt die Priorität darin, Authentifizierungssysteme zu bauen, die Unicode erlauben, ohne es zu beschädigen – und Länge, Einzigartigkeit und Prüfungen auf kompromittierte Passwörter als Grundlage jeder Passwortrichtlinie durchzusetzen.
Für Organisationen, die Anmeldedaten über Teams und Systeme hinweg verwalten, hilft ein Unternehmens-Passwort-Manager wie Passwork dabei, einzigartige Anmeldedaten zu generieren, zu speichern, zu teilen und zu prüfen, während Administratoren die nötigen Kontrollen erhalten, um konsistente Passwortpraktiken durchzusetzen.
Starke Anmeldedaten sind eine Schicht einer funktionierenden Sicherheitsstrategie. Passwork gibt IT-Teams die Infrastruktur, um diese Schicht in großem Maßstab zu verwalten — selbstgehostet oder Cloud, prüfbar und für Unternehmensumgebungen konzipiert. Passwork kostenlos testen
FAQ
Sind chinesische Schriftzeichen besser als Sonderzeichen in Passwörtern?
Chinesische Schriftzeichen können einen größeren theoretischen Zeichenpool bieten als der Standardsatz von Sonderzeichen, was eine höhere Entropie pro zufällig gewähltem Zeichen ergibt. In der Praxis sind Zufälligkeit und Länge wichtiger als die verwendete Zeichenkategorie. Ein langes zufälliges Passwort mit druckbarem ASCII ist stärker als eine kurze bedeutungsvolle chinesische Phrase.
Ist ein kurzes chinesisches Passwort sicher?
Nicht zuverlässig. Ein kurzes Passwort aus einem großen Zeichensatz kann eine akzeptable theoretische Entropie haben, wenn es zufällig gewählt wird, aber kurze Passwörter bleiben anfällig für Offline-Cracking, da die Hardware-Leistung zunimmt. Ein fünf Zeichen langes zufälliges CJK-Passwort ist kein Ersatz für ein 16 Zeichen oder längeres Passwort. Länge und Zufälligkeit zusammen bestimmen die reale Stärke.
Kann ich Pinyin als Passwort verwenden?
Pinyin allein ist eine schlechte Wahl. Romanisiertes Chinesisch ist ein bekanntes Muster, und Angreifer erstellen sprachspezifische Wörterbücher, die gängige Pinyin-Sequenzen, Namen und Phrasen enthalten. Die USENIX-Forschung ergab, dass Pinyin-basierte Passwörter zu den am erfolgreichsten geknackten im chinesischen Datensatz gehörten. Pinyin kombiniert mit anderen zufälligen Elementen in einem längeren Passwort ist weniger vorhersagbar, aber ein vom Passwort-Manager generiertes Passwort ist sicherer.
Erlauben alle Websites chinesische Schriftzeichen in Passwörtern?
Nein. Viele Systeme lehnen Nicht-ASCII-Eingaben ab, wenden inkonsistente Unicode-Normalisierung an, zählen Bytes statt Zeichen oder kürzen lange Zeichenfolgen stillschweigend. Bevor Sie sich für wichtige Accounts auf chinesische Schriftzeichen verlassen, testen Sie den vollständigen Authentifizierungsablauf: Kontoerstellung, Login, Passwortänderung, Wiederherstellung und mobilen Zugriff. Wenn ein Schritt fehlschlägt, verwenden Sie stattdessen ein kompatibles Passwort.
Sind Emojis sicherer als chinesische Schriftzeichen?
Emojis bringen dieselben Unicode-Kompatibilitätsrisiken wie CJK-Zeichen mit sich und führen zusätzliche Probleme ein: Emoji-Codepunkte können sich zwischen Unicode-Versionen ändern, die Darstellung variiert plattformübergreifend, und die Eingabe auf vielen Geräten ist langsam und unzuverlässig. Sie sind nicht automatisch sicherer. Dieselben Bedingungen gelten – Zufälligkeit, Länge und verifizierte Systemunterstützung.
Sollte ein Passwort-Manager chinesische Schriftzeichen generieren?
Die meisten Passwort-Manager verwenden aus gutem Grund standardmäßig ASCII-kompatible Zeichensätze: breite Kompatibilität, zuverlässiges Autofill und keine Abhängigkeit von Eingabemethoden. Wenn Sie CJK-Zeichen einbeziehen möchten, überprüfen Sie, ob der Zieldienst Unicode korrekt von Anfang bis Ende verarbeitet, bevor Sie es aktivieren. Für die meisten Accounts ist ein langes zufälliges ASCII-Passwort die sicherere und praktischere Wahl.
Nein. Credential-Stuffing-Angriffe verwenden Passwörter, die bei einem Datenleck gestohlen wurden, gegen andere Dienste. Die Verteidigung ist Einzigartigkeit – ein Passwort pro Account – nicht Komplexität. Ein einzigartiges 16-Zeichen ASCII-Passwort stoppt Credential Stuffing genauso effektiv wie ein einzigartiges Passwort mit chinesischen Schriftzeichen. Blocklisten für kompromittierte Passwörter und MFA bieten zusätzlichen Schutz.
Was ist die beste praktische Empfehlung?
Verwenden Sie einen Passwort-Manager, um lange, einzigartige, zufällige Passwörter für jeden Account zu generieren. Aktivieren Sie MFA oder Passkeys überall dort, wo der Dienst es unterstützt. Wenn Sie chinesische Schriftzeichen verwenden möchten, überprüfen Sie zuerst die Unicode-Unterstützung auf jedem Authentifizierungspfad. Die Kombination aus einzigartigen Passwörtern, einem Passwort-Manager und MFA adressiert das gesamte Spektrum realer Bedrohungen für Anmeldedaten.
Wie sicher ist ein Passwort mit chinesischen Schriftzeichen?
Chinesische Schriftzeichen können die Entropie erhöhen, wenn sie zufällig sind, aber Kompatibilität und Vorhersehbarkeit sind entscheidend. Sichere Unicode-Passwort-Praktiken.
Una contraseña que utiliza caracteres chinos puede ser muy segura si los caracteres se eligen aleatoriamente, la contraseña es lo suficientemente larga y el sitio web o la aplicación maneja Unicode correctamente. Los caracteres chinos no hacen que una contraseña sea fuerte automáticamente. Las frases predecibles, las fechas, los nombres y las contraseñas reutilizadas siguen siendo vulnerables independientemente del conjunto de caracteres del que provengan.
La pregunta importa porque la respuesta está genuinamente dividida. Las matemáticas favorecen a los caracteres chinos — un conjunto de caracteres más grande aumenta la entropía teórica por carácter. Los datos del mundo real cuentan una historia más complicada. Un estudio de USENIX Security de 2019 analizó 73,1 millones de contraseñas web chinas y descubrió que muchas eran más débiles contra ataques de adivinación en línea que sus equivalentes en inglés. Este artículo examina ambos lados: las matemáticas de la entropía, la evidencia conductual, los riesgos de implementación de Unicode y lo que los equipos de TI deberían hacer realmente con esta información.
Puntos clave
Un conjunto de caracteres más grande aumenta la entropía teórica, pero solo cuando los caracteres se eligen aleatoriamente. Los caracteres CJK cubren decenas de miles de puntos de código Unicode en comparación con 95 para ASCII imprimible. Esa diferencia es real en el papel. Desaparece en el momento en que un humano elige una frase reconocible en lugar de una cadena aleatoria.
Las contraseñas chinas elegidas por humanos suelen ser más débiles de lo que parecen. Un estudio de USENIX Security de 2019 analizó 73,1 millones de contraseñas web chinas del mundo real y descubrió que eran más vulnerables a ataques de adivinación en línea que las contraseñas en inglés. Las secuencias de pinyin, las cadenas de dígitos culturalmente comunes y las frases familiares están bien representadas en los diccionarios de ataque específicos del idioma.
La compatibilidad con Unicode es un problema sin resolver en muchos sistemas. Los sistemas de autenticación construidos con suposiciones de ASCII pueden rechazar la entrada no ASCII, aplicar normalización inconsistente, contar bytes en lugar de caracteres o truncar silenciosamente las contraseñas. Una contraseña que funciona en la creación de la cuenta puede fallar en el inicio de sesión, la recuperación o en un dispositivo móvil.
La longitud y la aleatoriedad importan más que qué caracteres se usan. NIST, OWASP y CISA apuntan a la misma base: contraseñas largas, únicas y generadas aleatoriamente, almacenadas en un gestor de contraseñas, combinadas con MFA. La categoría de caracteres es una consideración secundaria.
La complejidad de la contraseña no aborda el phishing, el credential stuffing o el robo de sesiones. Cuatro de las cinco mayores mega-brechas de EE. UU. en 2024 involucraron contraseñas robadas o comprometidas. El conjunto de caracteres utilizado fue irrelevante. MFA, contraseñas únicas por cuenta y listas de bloqueo de contraseñas filtradas son los controles que reducen el riesgo en el mundo real.
¿Son realmente más seguras las contraseñas con caracteres chinos?
Pueden serlo, pero no automáticamente. La seguridad de cualquier contraseña depende de cuán impredecible sea para un atacante. Un conjunto de caracteres más grande aumenta el número teórico de contraseñas posibles. Los caracteres CJK en Unicode cubren decenas de miles de puntos de código — en comparación con 95 para ASCII imprimible. En el papel, esa diferencia es significativa.
El problema es que la fortaleza teórica asume una selección aleatoria. Las contraseñas elegidas por humanos no funcionan así. Una contraseña construida a partir de una frase china reconocible, una secuencia de caracteres vinculada a un nombre o fecha, o un patrón culturalmente común le da al atacante un objetivo mucho más pequeño de lo que sugiere el conjunto completo de caracteres. Un diccionario consciente del idioma construido a partir de contraseñas chinas reales puede descifrar 我的密码 (en chino «mi contraseña») en segundos — independientemente de cuán grande sea técnicamente el conjunto CJK.
Por lo tanto, el conjunto de caracteres importa, pero solo cuando la contraseña se genera aleatoriamente. Una frase china significativa y una cadena CJK aleatoria no son la misma propuesta de seguridad.
💡
Los caracteres CJK (chino, japonés, coreano) en Unicode cubren decenas de miles de puntos de código. Eso es una ventaja significativa en teoría. En la práctica, la ventaja solo se materializa cuando la contraseña se genera aleatoriamente y el sistema maneja Unicode correctamente.
¿Qué es un conjunto de caracteres?
Conjunto de caracteres — La colección de caracteres distintos de los que puede componerse una contraseña. El ASCII imprimible estándar tiene 95 caracteres; un subconjunto CJK común tiene alrededor de 20.000. Un conjunto de caracteres más grande aumenta el número teórico de contraseñas posibles para una longitud determinada, lo que eleva el costo de un ataque de fuerza bruta — pero solo cuando los caracteres se eligen aleatoriamente.
¿Qué es un ataque de diccionario?
Ataque de diccionario — Un método para descifrar contraseñas probando sistemáticamente una lista preconstruida de candidatos probables: palabras comunes, nombres, frases, patrones de teclado y contraseñas filtradas conocidas. A diferencia de los ataques de fuerza bruta que prueban todas las combinaciones posibles, los ataques de diccionario explotan las elecciones humanas predecibles. Los diccionarios específicos del idioma — incluyendo secuencias de pinyin y frases chinas culturalmente comunes — hacen que este ataque sea efectivo también contra contraseñas no ASCII.
Las matemáticas de la entropía: por qué los caracteres CJK pueden añadir fortaleza
La entropía de la contraseña mide cuántos intentos necesitaría un atacante para agotar todas las contraseñas posibles de un tipo determinado. El modelo estándar es: entropía (en bits) = log₂(tamaño del conjunto de caracteres) × longitud de la contraseña. Un número más alto significa un problema de fuerza bruta más difícil.
La tabla a continuación muestra cómo se comparan diferentes conjuntos de caracteres bajo este modelo. Cada cifra asume que la contraseña se genera aleatoriamente — una condición que las contraseñas elegidas por humanos rara vez cumplen.
Modelo de contraseña
Conjunto de caracteres asumido
Bits por carácter
Notas
ASCII imprimible
95 caracteres
6,57
Ampliamente compatible; fácil de generar y autocompletar para los gestores de contraseñas.
Subconjunto CJK de 20.000 caracteres
20.000 caracteres
14,29
Mayor entropía teórica por carácter; la entrada y el soporte del sistema son más difíciles.
Conjunto CJK/Han de 90.000 caracteres
90.000 caracteres
16,46
Límite superior ilustrativo; no es un conjunto de entrada práctico para uso diario.
Frase china común
Palabras elegidas por humanos
No calculable de forma segura
Vulnerable a diccionarios específicos del idioma independientemente del número de caracteres.
Los números parecen convincentes para los caracteres CJK. Un carácter elegido aleatoriamente de un conjunto de 20.000 caracteres tiene más del doble de la entropía de un carácter ASCII imprimible elegido aleatoriamente. Una contraseña CJK aleatoria de cinco caracteres podría teóricamente igualar la entropía de una contraseña ASCII aleatoria de diez caracteres.
Se aplican dos advertencias:
Selección aleatoria. La fórmula asume que cada carácter se elige con igual probabilidad. Un humano eligiendo caracteres chinos no se comporta como un generador de números aleatorios.
Soporte del sistema. Una mayor entropía por carácter no ayuda si el sistema rechaza, trunca o maneja incorrectamente la entrada. La fortaleza teórica y la seguridad práctica no son lo mismo.
Unicode 17.0, publicado en 2025, define un total de 159.801 caracteres en todos los scripts (Unicode Consortium, 2025). Esa cifra se cita a menudo para sugerir un enorme espacio de contraseñas. Vale la pena señalar que 159.801 es el tamaño del repertorio completo de Unicode — no un conjunto realista de caracteres del que un usuario extraería al crear una contraseña. El conjunto práctico de caracteres CJK para la mayoría de los usuarios son los aproximadamente 20.000 caracteres de uso común, no el inventario completo de Unicode.
La advertencia del mundo real: los usuarios chinos a menudo eligen contraseñas predecibles
La evidencia empírica más importante sobre este tema proviene de un estudio de USENIX Security de 2019 realizado por Ding Wang y colegas de la Universidad de Pekín, la Universidad de Wuhan y la Universidad de Virginia. Los investigadores analizaron 73,1 millones de contraseñas web chinas del mundo real y 33,2 millones de contraseñas web en inglés de nueve servicios, cubriendo foros sociales, plataformas de juegos, sitios de comercio electrónico y comunidades de programadores.
Su hallazgo clave fue lo que llamaron seguridad bifacial: las contraseñas chinas eran más débiles contra ataques de adivinación en línea (hasta 10.000 intentos) que las contraseñas en inglés, pero las contraseñas que sobrevivieron a esos intentos iniciales eran más fuertes contra ataques fuera de línea de alto volumen. Con 10 millones de intentos, su algoritmo de descifrado mejorado tuvo éxito contra el 33,2% al 49,8% de los conjuntos de datos chinos — descifrando entre un 92% y un 188% más contraseñas que el estado del arte anterior. Como señala el resumen de IEEE Spectrum de la investigación, una contraseña que parece fuerte según las suposiciones del idioma inglés puede ser inmediatamente obvia para un hablante de mandarín.
Los patrones que explotan los atacantes incluyen:
Secuencias de pinyin — chino romanizado, como «woaini» («te amo»), que los medidores de fortaleza de contraseñas en los principales servicios calificaron como «fuerte» a pesar de ser trivialmente adivinable por hablantes de mandarín.
Cadenas de dígitos culturalmente comunes — «5201314» suena como «te amo para siempre» en chino; «520» solo es una abreviatura común.
Fragmentos de números de teléfono — los usuarios chinos incluyen números de móvil en las contraseñas con más frecuencia que los usuarios de habla inglesa.
Formatos de cumpleaños y fechas — incrustados en contraseñas con tasas más altas que en los conjuntos de datos en inglés.
Cadenas de solo dígitos — «123456», «111111», «123321» y secuencias similares aparecen con alta frecuencia.
Patrones intercalados — letras y dígitos alternados en formatos como «a12345» o «12345a».
Nada de esto significa que los usuarios de habla china sean menos conscientes de la seguridad. Significa que cualquier comunidad lingüística desarrolla patrones predecibles, y los atacantes construyen diccionarios para coincidir con ellos. La lección práctica: usar caracteres chinos no evita los ataques de diccionario. Cambia qué diccionario alcanza el atacante.
El generador de contraseñas de Passwork crea credenciales largas y aleatorias que evitan todos estos patrones — independientemente del conjunto de caracteres con el que esté trabajando. Vea cómo funciona
Riesgos de compatibilidad con Unicode: por qué algunos sitios rechazan o rompen estas contraseñas
Muchos sistemas de autenticación fueron construidos con suposiciones de ASCII y nunca se han actualizado completamente. El resultado es un conjunto de modos de fallo que pueden bloquear a los usuarios, debilitar silenciosamente sus contraseñas o hacer imposible la recuperación.
Algunas definiciones ayudan aquí. UTF-8 es la codificación más común para texto Unicode en la web — representa cada punto de código Unicode como de uno a cuatro bytes. Un punto de código Unicode es el número único asignado a cada carácter. La normalización Unicode es el proceso de convertir secuencias de caracteres visualmente equivalentes en una forma canónica; NFC (Forma de Normalización Compuesta) es el estándar más común para el almacenamiento de texto. Los caracteres visualmente similares son puntos de código diferentes que se ven idénticos en pantalla, lo que puede causar fallos de inicio de sesión si las formas almacenadas e ingresadas difieren.
Riesgo
Por qué importa
Consejo para usuarios
Consejo para equipos de TI
Rechazo de entrada no ASCII
La contraseña puede no ser aceptada en absoluto.
Pruebe la creación de cuenta, el inicio de sesión, la recuperación y el acceso móvil antes de comprometerse con ella.
Elimine las prohibiciones de caracteres que no tengan una justificación técnica específica.
Normalización inconsistente
La misma contraseña visible puede generar un hash diferente dependiendo de cómo el sistema normalice la entrada.
Evite combinar secuencias de caracteres para cuentas importantes.
Defina y documente el comportamiento de normalización; aplíquelo consistentemente en cada punto de entrada.
Truncamiento silencioso
Los caracteres más allá de un límite de bytes o caracteres pueden ser eliminados silenciosamente.
Evite sistemas que truncan sin advertencia; pruebe con una contraseña larga.
Nunca trunque silenciosamente; aplique un máximo claro y devuelva un error explícito.
Dependencia del método de entrada
Los usuarios pueden no poder escribir la contraseña en todos los dispositivos o configuraciones de teclado.
Confirme el acceso desde dispositivos móviles, flujos de recuperación de emergencia y cualquier dispositivo que pueda usar en una crisis.
Pruebe la entrada Unicode en web, móvil, SSO, API y rutas de recuperación del servicio de asistencia.
El problema del método de entrada merece énfasis. Una contraseña escrita con un IME (editor de método de entrada) en un escritorio puede ser imposible de reproducir en un dispositivo corporativo bloqueado, una computadora de hotel o un teléfono con una aplicación de teclado diferente. Para una contraseña maestra o una credencial de recuperación, eso es un riesgo serio de usabilidad.
Lo que dice la guía moderna de contraseñas sobre los caracteres Unicode
La hoja de trucos de autenticación de OWASP es directa: permita todos los caracteres, incluidos Unicode y espacios en blanco. Recomienda no establecer reglas de composición que restrinjan los tipos de caracteres, establece una longitud mínima de contraseña vinculada a si MFA está habilitado (8 caracteres con MFA, 15 sin él, según NIST SP 800-63B), y requiere un máximo de al menos 64 caracteres sin truncamiento silencioso. También recomienda bloquear contraseñas que aparezcan en conjuntos de datos de contraseñas filtradas.
La guía de contraseñas seguras de CISA recomienda contraseñas de al menos 16 caracteres de longitud, aleatorias y únicas por cuenta — almacenadas en un gestor de contraseñas y combinadas con MFA resistente al phishing. La guía no restringe los conjuntos de caracteres.
La guía para usuarios de NIST enmarca las contraseñas como inherentemente inseguras y recomienda avanzar hacia MFA y passkeys siempre que sea posible. Señala que los ataques fuera de línea pueden intentar una cantidad enorme de conjeturas — haciendo que la longitud y la aleatoriedad de la contraseña sean las defensas principales contra el descifrado, no la categoría de caracteres.
El hilo común en las tres fuentes: la longitud y la aleatoriedad importan más que qué caracteres se usen. Los caracteres Unicode están permitidos y pueden ayudar, pero no son un sustituto de la longitud, la unicidad y un gestor de contraseñas.
¿Debería usar caracteres chinos en su propia contraseña?
Para la mayoría de las cuentas, la respuesta es: deje que su gestor de contraseñas decida. Una contraseña ASCII de 20 caracteres generada aleatoriamente por un gestor de contraseñas tiene alta entropía, funciona en todos los sistemas y no requiere escritura manual. Esa es la línea base.
Los caracteres chinos tienen sentido en un conjunto más reducido de circunstancias: el usuario puede escribirlos de manera confiable en todos los dispositivos que usa, el servicio demuestra soportar Unicode en cada punto de contacto (inicio de sesión, recuperación, móvil, API), y la contraseña resultante es larga, única y no es una frase reconocible.
Escenario
Enfoque recomendado
Razón
El gestor de contraseñas puede generar y autocompletar
Contraseña larga aleatoria, generalmente compatible con ASCII
Alta entropía y amplia compatibilidad sin necesidad de escritura manual.
La contraseña debe memorizarse
Frase de contraseña larga de palabras no relacionadas
Más fácil de escribir en todos los dispositivos; menos dependiente del soporte Unicode.
El usuario quiere usar caracteres chinos
Úselos como parte de una contraseña única más larga solo después de probar el soporte Unicode de extremo a extremo
Añade posible entropía pero introduce riesgos de compatibilidad.
Cuenta empresarial
Siga la política: mínimo 16 caracteres, única, MFA requerido, lista de bloqueo de contraseñas filtradas activa
Reduce el riesgo de compromiso de cuenta en el mundo real en toda la organización.
Cuenta de alto riesgo
Contraseña única fuerte más MFA o passkeys
La complejidad por sí sola no protege contra el phishing o las credenciales robadas.
El único escenario donde los caracteres chinos claramente añaden valor: una contraseña que un atacante no podría incluir de manera realista en ningún diccionario, generada aleatoriamente, usada en un sistema con soporte Unicode verificado. Fuera de ese escenario, los costos de compatibilidad a menudo superan las ganancias de entropía.
Contra qué no pueden proteger los caracteres chinos
La entropía es una defensa contra la adivinación y el descifrado. No aborda las otras formas en que las credenciales se ven comprometidas.
El Informe anual de brechas de datos 2024 del ITRC registró 3.158 compromisos de datos en EE. UU. y 1.350.835.988 notificaciones de brechas en 2024 — un aumento del 211% en notificaciones desde 2023. Cuatro de las cinco mayores mega-brechas involucraron contraseñas robadas o comprometidas. Los ataques contra Ticketmaster, AT&T y Change Healthcare, entre otros, podrían haberse bloqueado con MFA o passkeys. La complejidad de caracteres de esas contraseñas fue irrelevante.
Las amenazas que la complejidad de la contraseña no puede abordar:
Phishing — una página de inicio de sesión falsa convincente captura la contraseña independientemente de cómo se haya construido
Keylogging y malware — las credenciales se capturan en la entrada antes de que se aplique el cifrado
Robo de sesión — un atacante que roba un token de sesión autenticado evita la contraseña por completo
Credential stuffing — las contraseñas reutilizadas de una brecha se prueban contra otros servicios; la unicidad es la única defensa
Reutilización de contraseñas — una contraseña fuerte de caracteres chinos usada en cinco cuentas está cinco veces más expuesta
Ingeniería social — un atacante que convence a un servicio de asistencia de restablecer una cuenta nunca toca la contraseña
Bóveda de gestor de contraseñas comprometida — si la bóveda es vulnerada y la contraseña maestra es débil, todas las credenciales almacenadas están en riesgo
Los controles que abordan estas amenazas son MFA, passkeys, contraseñas únicas por cuenta, listas de bloqueo de contraseñas filtradas, autenticación resistente al phishing y auditorías de seguridad regulares. Una contraseña más compleja es una capa. No es un sustituto de las demás.
Conclusión
Los caracteres chinos pueden mejorar la fortaleza teórica de una contraseña — pero solo bajo las mismas condiciones que hacen que cualquier contraseña sea fuerte: longitud suficiente, aleatoriedad genuina, unicidad entre cuentas y un sistema que maneje Unicode correctamente. Una frase china significativa, una secuencia de pinyin o una cadena de números culturalmente familiar no cumple esas condiciones. La investigación de USENIX sobre 73,1 millones de contraseñas web chinas lo deja claro.
Para la mayoría de los usuarios, la respuesta práctica es un gestor de contraseñas que genere credenciales largas, aleatorias y únicas, combinado con MFA o passkeys en cualquier cuenta que los soporte. Para los equipos de TI, la prioridad es construir sistemas de autenticación que permitan Unicode sin romperlo — y aplicar la longitud, la unicidad y las verificaciones de contraseñas filtradas como la base de cualquier política de contraseñas.
Para las organizaciones que gestionan credenciales en equipos y sistemas, un gestor de contraseñas corporativo como Passwork ayuda a generar, almacenar, compartir y auditar credenciales únicas mientras brinda a los administradores los controles que necesitan para aplicar prácticas de contraseñas consistentes.
Las credenciales fuertes son una capa de una postura de seguridad funcional. Passwork brinda a los equipos de TI la infraestructura para gestionar esa capa a escala — autoalojado o en la nube, auditable y diseñado para entornos empresariales. Pruebe Passwork gratis
Preguntas frecuentes
¿Son los caracteres chinos mejores que los caracteres especiales en las contraseñas?
Los caracteres chinos pueden ofrecer un conjunto de caracteres teórico más grande que el conjunto estándar de caracteres especiales, lo que proporciona mayor entropía por carácter elegido aleatoriamente. En la práctica, la aleatoriedad y la longitud importan más que qué categoría de carácter se use. Una contraseña larga aleatoria usando ASCII imprimible es más fuerte que una frase china corta con significado.
¿Es segura una contraseña china corta?
No de manera confiable. Una contraseña corta de un conjunto de caracteres grande puede tener una entropía teórica razonable si se elige aleatoriamente, pero las contraseñas cortas siguen siendo vulnerables al descifrado fuera de línea a medida que el hardware mejora. Una contraseña CJK aleatoria de cinco caracteres no es un sustituto de una contraseña de 16 caracteres o más. La longitud y la aleatoriedad juntas determinan la fortaleza en el mundo real.
¿Puedo usar pinyin como contraseña?
El pinyin solo es una mala elección. El chino romanizado es un patrón bien conocido, y los atacantes construyen diccionarios específicos del idioma que incluyen secuencias de pinyin comunes, nombres y frases. La investigación de USENIX encontró que las contraseñas basadas en pinyin estaban entre las más exitosamente descifradas en el conjunto de datos chino. El pinyin combinado con otros elementos aleatorios en una contraseña más larga es menos predecible, pero una credencial generada por un gestor de contraseñas es más segura.
¿Todos los sitios web permiten caracteres chinos en las contraseñas?
No. Muchos sistemas rechazan la entrada no ASCII, aplican normalización Unicode inconsistente, cuentan bytes en lugar de caracteres o truncan silenciosamente cadenas largas. Antes de confiar en caracteres chinos para cualquier cuenta importante, pruebe el flujo de autenticación completo: creación de cuenta, inicio de sesión, cambio de contraseña, recuperación y acceso móvil. Si algún paso falla, use una contraseña compatible en su lugar.
¿Son los emojis más seguros que los caracteres chinos?
Los emojis conllevan los mismos riesgos de compatibilidad con Unicode que los caracteres CJK e introducen problemas adicionales: los puntos de código de emoji pueden cambiar entre versiones de Unicode, la representación varía entre plataformas, y la entrada en muchos dispositivos es lenta y poco confiable. No son automáticamente más seguros. Se aplican las mismas condiciones — aleatoriedad, longitud y soporte del sistema verificado.
¿Debería un gestor de contraseñas generar caracteres chinos?
La mayoría de los gestores de contraseñas utilizan por defecto conjuntos de caracteres compatibles con ASCII por una buena razón: amplia compatibilidad, autocompletado confiable y sin dependencia del método de entrada. Si desea incluir caracteres CJK, verifique que el servicio de destino maneje Unicode correctamente de extremo a extremo antes de habilitarlo. Para la mayoría de las cuentas, una contraseña ASCII larga y aleatoria es la opción más segura y práctica.
¿Los caracteres chinos detienen el credential stuffing?
No. Los ataques de credential stuffing reproducen contraseñas robadas de una brecha contra otros servicios. La defensa es la unicidad — una contraseña por cuenta — no la complejidad. Una contraseña ASCII única de 16 caracteres detiene el credential stuffing tan efectivamente como una contraseña única de caracteres chinos. Las listas de bloqueo de contraseñas filtradas y MFA añaden protección adicional.
¿Cuál es la mejor recomendación práctica?
Use un gestor de contraseñas para generar contraseñas largas, únicas y aleatorias para cada cuenta. Habilite MFA o passkeys siempre que el servicio los soporte. Si desea usar caracteres chinos, verifique primero el soporte Unicode en cada ruta de autenticación. La combinación de contraseñas únicas, un gestor de contraseñas y MFA aborda toda la gama de amenazas de credenciales del mundo real.
¿Qué tan segura es una contraseña con caracteres chinos?
Los caracteres chinos pueden aumentar la entropía si son aleatorios, pero la compatibilidad y previsibilidad importan. Aprenda prácticas seguras con Unicode.
A password that uses Chinese characters can be very secure if the characters are chosen randomly, the password is long enough, and the website or application handles Unicode correctly. Chinese characters do not automatically make a password strong. Predictable phrases, dates, names, and reused passwords remain vulnerable regardless of the character set they draw from.
The question matters because the answer is genuinely split. The math favors Chinese characters – a larger character pool raises theoretical entropy per character. The real-world data tells a more complicated story. A 2019 USENIX Security study analyzed 73.1 million Chinese web passwords and found that many were weaker against online guessing attacks than their English counterparts. This article works through both sides: the entropy math, the behavioral evidence, the Unicode implementation risks, and what IT teams should actually do with this information.
Key takeaways
A larger character set raises theoretical entropy but only when characters are chosen randomly. CJK characters cover tens of thousands of Unicode code points compared to 95 for printable ASCII. That gap is real on paper. It disappears the moment a human picks a recognizable phrase instead of a random string.
Human-chosen Chinese passwords are often weaker than they appear. A 2019 USENIX Security study analyzed 73.1 million real-world Chinese web passwords and found they were more vulnerable to online guessing attacks than English passwords. Pinyin sequences, culturally common digit strings, and familiar phrases are well-represented in language-specific attack dictionaries.
Unicode compatibility is an unsolved problem on many systems. Authentication systems built around ASCII assumptions can reject non-ASCII input, apply inconsistent normalization, count bytes instead of characters, or silently truncate passwords. A password that works at account creation may fail at login, recovery, or on a mobile device.
Length and randomness matter more than which characters you use. NIST, OWASP, and CISA all point to the same foundation: long, unique, randomly generated passwords stored in a password manager, paired with MFA. Character category is a secondary consideration.
Password complexity does not address phishing, credential stuffing, or session theft. Four of the five largest U.S. mega-breaches in 2024 involved stolen or compromised passwords. The character set used was irrelevant. MFA, unique passwords per account, and breached-password blocklists are the controls that reduce real-world risk.
Are Chinese-character passwords actually more secure?
They can be, but not automatically. The security of any password depends on how unpredictable it is to an attacker. A larger character set raises the theoretical number of possible passwords. CJK characters in Unicode cover tens of thousands of code points – compared to 95 for printable ASCII. On paper, that gap is significant.
The problem is that theoretical strength assumes random selection. Human-chosen passwords don't work that way. A password built from a recognizable Chinese phrase, a character sequence tied to a name or date, or a culturally common pattern gives an attacker a much smaller target than the full character set suggests. A language-aware dictionary built from real Chinese passwords can crack 我的密码 (Chinese for "my password") in seconds – regardless of how large the CJK pool technically is.
So the character set matters, but only when the password is generated randomly. A meaningful Chinese phrase and a random CJK string are not the same security proposition.
💡
CJK (Chinese, Japanese, Korean) characters in Unicode cover tens of thousands of code points. That is a meaningful advantage in theory. In practice, the advantage only materializes when the password is generated randomly and the system handles Unicode correctly.
What is character set?
Character set — The collection of distinct characters a password can be drawn from. Standard printable ASCII has 95 characters; a common CJK subset has around 20,000. A larger character set increases the theoretical number of possible passwords for a given length, which raises the cost of a brute-force attack — but only when characters are chosen randomly.
What is a dictionary attack?
Dictionary attack — A method of cracking passwords by systematically testing a pre-built list of likely candidates: common words, names, phrases, keyboard patterns, and known leaked passwords. Unlike brute-force attacks that try every possible combination, dictionary attacks exploit predictable human choices. Language-specific dictionaries — including pinyin sequences and culturally common Chinese phrases — make this attack effective against non-ASCII passwords too.
The entropy math: why CJK characters can add strength
Password entropy measures how many guesses an attacker would need to exhaust all possible passwords of a given type. The standard model is: entropy (in bits) = log₂(character set size) × password length. A higher number means a harder brute-force problem.
The table below shows how different character pools compare under this model. Every figure assumes the password is generated randomly – a condition that human-chosen passwords rarely meet.
Password model
Assumed character pool
Bits per character
Notes
Printable ASCII
95 characters
6.57
Broadly compatible; easy for password managers to generate and autofill.
20,000-character CJK subset
20,000 characters
14.29
Higher theoretical entropy per character; input and system support are harder.
90,000-character CJK/Han-like set
90,000 characters
16.46
Illustrative upper bound; not a practical daily input pool.
Common Chinese phrase
Human-chosen words
Not safely calculable
Vulnerable to language-specific dictionaries regardless of character count.
The numbers look compelling for CJK characters. A randomly chosen character from a 20,000-character pool carries more than twice the entropy of a randomly chosen printable ASCII character. A five-character random CJK password could theoretically match the entropy of a ten-character random ASCII password.
Two caveats apply:
Random selection. The formula assumes every character is chosen with equal probability. A human picking Chinese characters does not behave like a random number generator.
System support. Higher entropy per character does not help if the system rejects, truncates, or mishandles the input. Theoretical strength and practical security are not the same thing.
Unicode 17.0, released in 2025, defines a total of 159,801 characters across all scripts (Unicode Consortium, 2025). That figure is often cited to suggest an enormous password space. It is worth noting that 159,801 is the size of the entire Unicode repertoire – not a realistic pool of characters a user would draw from when creating a password. The practical CJK character pool for most users is the roughly 20,000 characters in common use, not the full Unicode inventory.
The real-world caveat: Chinese users often choose predictable passwords
The most important empirical evidence on this topic comes from a 2019 USENIX Security study by Ding Wang and colleagues at Peking University, Wuhan University, and the University of Virginia. The researchers analyzed 73.1 million real-world Chinese web passwords and 33.2 million English web passwords from nine services, covering social forums, gaming platforms, e-commerce sites, and programmer communities.
Their key finding was what they called bifacial security: Chinese passwords were weaker against online guessing attacks (up to 10,000 guesses) than English passwords, but the passwords that survived those initial guesses were stronger against high-volume offline attacks. At 10 million guesses, their improved cracking algorithm succeeded against 33.2% to 49.8% of the Chinese datasets -- cracking between 92% and 188% more passwords than the prior state of the art. As the IEEE Spectrum summary of the research notes, a password that looks strong by English-language assumptions can be immediately obvious to a Mandarin speaker.
The patterns attackers exploit include:
Pinyin sequences – romanized Chinese, such as "woaini" ("I love you"), which password strength meters at major services rated as "strong" despite being trivially guessable by Mandarin speakers.
Culturally common digit strings – "5201314" sounds like "I love you forever" in Chinese; "520" alone is a common shorthand.
Phone-number fragments – Chinese users include mobile numbers in passwords more often than English-speaking users.
Birthday and date formats – embedded in passwords at higher rates than in English-language datasets.
Digit-only strings – "123456," "111111," "123321," and similar sequences appear at high frequency.
Interleaved patterns – alternating letters and digits in formats like "a12345" or "12345a".
None of this means Chinese-speaking users are less security-conscious. It means that any language community develops predictable patterns, and attackers build dictionaries to match. The practical lesson: using Chinese characters does not bypass dictionary attacks. It shifts which dictionary the attacker reaches for.
Passwork's password generator creates long, random credentials that avoid all of these patterns —regardless of which character set you're working with. See how it works
Unicode compatibility risks: why some sites reject or break these passwords
Many authentication systems were built around ASCII assumptions and have never been fully updated. The result is a set of failure modes that can lock users out, silently weaken their passwords, or make recovery impossible.
A few definitions help here. UTF-8 is the most common encoding for Unicode text on the web – it represents each Unicode code point as one to four bytes. A Unicode code point is the unique number assigned to each character. Unicode normalization is the process of converting visually equivalent character sequences into a canonical form; NFC (Normalization Form Composed) is the most common standard for text storage. Visually similar characters are different code points that look identical on screen which can cause login failures if the stored and entered forms differ.
Risk
Why it matters
Advice for users
Advice for IT teams
Rejection of non-ASCII input
The password may not be accepted at all.
Test account creation, login, recovery, and mobile access before committing to it.
Remove character bans that have no specific technical justification.
Inconsistent normalization
The same visible password may hash differently depending on how the system normalizes input.
Avoid combining character sequences for important accounts.
Define and document normalization behavior; apply it consistently at every input point.
Silent truncation
Characters beyond a byte or character limit may be silently dropped.
Avoid systems that truncate without warning; test with a long password.
Never truncate silently; enforce a clear maximum and return an explicit error.
Input-method dependency
Users may not be able to type the password on every device or keyboard layout.
Confirm access from mobile devices, emergency recovery flows, and any device you might use in a crisis.
Test Unicode input across web, mobile, SSO, API, and helpdesk recovery paths.
The input-method problem deserves emphasis. A password typed with an IME (input method editor) on a desktop may be impossible to reproduce on a locked-down corporate device, a hotel computer, or a phone with a different keyboard app. For a master password or a recovery credential, that is a serious usability risk.
What modern password guidance says about Unicode characters
OWASP's Authentication Cheat Sheet is direct: allow all characters, including Unicode and whitespace. It recommends against composition rules that restrict character types, sets a minimum password length tied to whether MFA is enabled (8 characters with MFA, 15 without, per NIST SP 800-63B), and requires a maximum of at least 64 characters with no silent truncation. It also recommends blocking passwords that appear in breached-password datasets.
CISA's strong-password guidance recommends passwords that are at least 16 characters long, random, and unique per account – stored in a password manager and paired with phishing-resistant MFA. The guidance does not restrict character sets.
NIST's user-facing guidance frames passwords as inherently insecure and recommends moving toward MFA and passkeys wherever possible. It notes that offline attacks can attempt an enormous number of guesses – making password length and randomness the primary defenses against cracking, not character category.
The consistent thread across all three sources: length and randomness matter more than which characters you use. Unicode characters are permitted and can help, but they are not a substitute for length, uniqueness, and a password manager.
Should you use Chinese characters in your own password?
For most accounts, the answer is: let your password manager decide. A randomly generated 20-character ASCII password from a password manager has high entropy, works on every system, and requires no manual typing. That is the baseline.
Chinese characters make sense in a narrower set of circumstances: the user can type them reliably on every device they use, the service demonstrably supports Unicode at every touchpoint (login, recovery, mobile, API), and the resulting password is long, unique, and not a recognizable phrase.
Scenario
Recommended approach
Reason
Password manager can generate and autofill
Long random password, usually ASCII-compatible
High entropy and broad compatibility with no manual typing required.
Password must be memorized
Long passphrase of unrelated words
Easier to type across devices; less dependent on Unicode support.
User wants to use Chinese characters
Use them as part of a longer unique password only after testing Unicode support end-to-end
Adds possible entropy but introduces compatibility risks.
Reduces real-world account compromise risk across the organization.
High-risk account
Strong unique password plus MFA or passkeys
Complexity alone does not protect against phishing or stolen credentials.
The one scenario where Chinese characters clearly add value: a password that an attacker could not realistically include in any dictionary, generated randomly, used on a system with verified Unicode support. Outside that scenario, the compatibility costs often outweigh the entropy gains.
What Chinese characters cannot protect against
Entropy is a defense against guessing and cracking. It does not address the other ways credentials get compromised.
The ITRC's 2024 Annual Data Breach Report recorded 3,158 U.S. data compromises and 1,350,835,988 breach notices in 2024 – a 211% increase in notices from 2023. Four of the five largest mega-breaches involved stolen or compromised passwords. Attacks against Ticketmaster, AT&T, and Change Healthcare, among others, could have been blocked with MFA or passkeys. The character complexity of those passwords was irrelevant.
The threats that password complexity cannot address:
Phishing -- a convincing fake login page captures the password regardless of how it was constructed
Keylogging and malware -- credentials are captured at input before encryption applies
Session theft -- an attacker who steals an authenticated session token bypasses the password entirely
Credential stuffing -- reused passwords from one breach are tested against other services; uniqueness is the only defense
Password reuse -- a strong Chinese-character password used across five accounts is five times as exposed
Social engineering -- an attacker who convinces a help desk to reset an account never touches the password
Compromised password manager vault -- if the vault is breached and the master password is weak, all stored credentials are at risk
The controls that address these threats are MFA, passkeys, unique passwords per account, breached-password blocklists, phishing-resistant authentication, and regular security audits. A more complex password is one layer. It is not a substitute for the others.
Conclusion
Chinese characters can improve a password's theoretical strength – but only under the same conditions that make any password strong: sufficient length, genuine randomness, uniqueness across accounts, and a system that handles Unicode correctly. A meaningful Chinese phrase, a pinyin sequence, or a culturally familiar number string does not meet those conditions. The USENIX research on 73.1 million Chinese web passwords makes that clear.
For most users, the practical answer is a password manager generating long, random credentials, paired with MFA or passkeys on any account that supports them. For IT teams, the priority is building authentication systems that allow Unicode without breaking it -- and enforcing length, uniqueness, and breached-password checks as the foundation of any password policy.
For organizations managing credentials across teams and systems, a corporate password manager such as Passwork helps generate, store, share, and audit unique credentials while giving administrators the controls they need to enforce consistent password practices.
Strong credentials are one layer of a working security posture. Passwork gives IT teams the infrastructure to manage that layer at scale — self-hosted or cloud, auditable, and built for enterprise environments. Try Passwork free
FAQ
Are Chinese characters better than special characters in passwords?
Chinese characters can offer a larger theoretical character pool than the standard set of special characters, which gives higher entropy per randomly chosen character. In practice, randomness and length matter more than which category of character you use. A long random password using printable ASCII is stronger than a short meaningful Chinese phrase.
Is a short Chinese password secure?
Not reliably. A short password from a large character set can have reasonable theoretical entropy if chosen randomly, but short passwords remain vulnerable to offline cracking as hardware improves. A five-character random CJK password is not a substitute for a 16-character or longer password. Length and randomness together determine real-world strength.
Can I use pinyin as a password?
Pinyin alone is a poor choice. Romanized Chinese is a well-known pattern, and attackers build language-specific dictionaries that include common pinyin sequences, names, and phrases. The USENIX research found that pinyin-based passwords were among the most successfully cracked in the Chinese dataset. Pinyin combined with other random elements in a longer password is less predictable, but a password manager-generated credential is safer.
Do all websites allow Chinese characters in passwords?
No. Many systems reject non-ASCII input, apply inconsistent Unicode normalization, count bytes instead of characters, or silently truncate long strings. Before relying on Chinese characters for any important account, test the full authentication flow: account creation, login, password change, recovery, and mobile access. If any step fails, use a compatible password instead.
Are emojis safer than Chinese characters?
Emojis carry the same Unicode compatibility risks as CJK characters and introduce additional problems: emoji code points can change across Unicode versions, rendering varies across platforms, and input on many devices is slow and unreliable. They are not automatically more secure. The same conditions apply -- randomness, length, and verified system support.
Should a password manager generate Chinese characters?
Most password managers default to ASCII-compatible character sets for good reason: broad compatibility, reliable autofill, and no input-method dependency. If you want to include CJK characters, verify that the target service handles Unicode correctly end-to-end before enabling it. For most accounts, a long random ASCII password is the safer and more practical choice.
Do Chinese characters stop credential stuffing?
No. Credential stuffing attacks replay passwords stolen from one breach against other services. The defense is uniqueness -- one password per account -- not complexity. A unique 16-character ASCII password stops credential stuffing just as effectively as a unique Chinese-character password. Breached-password blocklists and MFA add further protection.
What is the best practical recommendation?
Use a password manager to generate long, unique, random passwords for every account. Enable MFA or passkeys wherever the service supports it. If you want to use Chinese characters, verify Unicode support on every authentication path first. The combination of unique passwords, a password manager, and MFA addresses the full range of real-world credential threats.
In the new version of Passwork, we have completely redesigned the System settings. They are now divided into three sections:
Global — organization settings that determine the operations of most of the Passwork functions
Default — the values of the settings that will be used if no other custom settings are specified
Custom — settings that can be set for individual users and roles
Now you can set up different interface languages, configure authorization methods, and enable mandatory two-factor authentication for individual users and roles.
To do this, click "Create a new settings group" in Сustom settings, add users or roles and select your desired settings. The newly created group will be added to the top of the list and will get the highest priority.
The following settings are now available:
Ability to create organization vaults and private vaults
Ability to create links to passwords
Mandatory 2FA
Time of automatic logout when inactive
Authorization method (by local password, LDAP password or SSO)
Multi-factor authentication (often known as MFA for short), refers to the process of confirming the identity of a user who is attempting to log in to a website, application, or another type of resource using more than one piece of information. Indeed, multi-factor authentication is the difference between entering a password to gain access to a resource and entering a password plus a one-time password (OTP), or a password plus the answer to a security question. Another example of multi-factor authentication is entering a password plus the answer to a security question.
Multi-factor authentication provides greater assurance that individuals are who they claim to be by requiring them to confirm their identity in more than one way. This, in turn, reduces the risk of unauthorised access to sensitive data. Multi-factor authentication requires individuals to confirm their identity in more than one way. After all, entering a stolen password to get access is one thing; it is quite another to enter a stolen password and then be needed to additionally input an OTP that was sent to the smartphone of the real user.
Multi-factor authentication can be achieved through the use of any combination of two or more factors. Two-factor authentication is another name for the practice of using only two factors to verify a user's identity.
How Does MFA work?
MFA is effective because it necessitates the collection of extra verification information (factors). One-time passwords are one of the multi-factor authentication mechanisms that consumers encounter most frequently (OTP). OTPs are the four-digit to eight-digit codes that you frequently receive through email, SMS, or a mobile application of some kind. When using OTPs, a fresh code will be created at predetermined intervals or whenever an authentication request is sent in. The code is created based on a seed value that is assigned to the user when they first register and some other component, which might simply be a counter that is incremented or a time value. This seed value is used in conjunction with some other factor to generate the code.
The three categories of multi-factor authentication methods
Generally speaking, a technique of multi-factor authentication will fall into one of these three categories:
• Something you are familiar with: a PIN, password, or the solution to a security question
• Something you own: an OTP, a token, a trusted device, a smart card, or a badge
• Something you are, such as your face, fingerprint, retinal scan, or other biometric information
Methods of multi-factor authentication
In order to accomplish multi-factor authentication, you will need to utilize at least one of the following methods in addition to a password.
Biometrics
A method of verification that depends on a piece of hardware or software being able to recognize biometric data, such as a person's fingerprint, facial characteristics, or the retina or iris of their eye.
Push to approve
A notice is shown on someone's smartphone that prompts the user to tap their screen in order to accept or deny a request for access to their device.
One-time password (OTP)
A collection of characters that are created automatically and are used to authenticate a user for a single login session or transaction only.
An SMS
A method for sending a One-Time Password (OTP) to the user's smartphone or other devices.
Hardware token
A compact, portable OTP-generating device that is sometimes referred to as a key fob.
Software token
A token that does not exist in the form of a physical token but rather as a software program that can be downloaded onto a smartphone or other device.
The advantages of multi-factor authentication
Enhancing the level of safety
Authentication that takes into account many factors is more secure. After all, when there is only one mechanism defending a point of access, such as a password, all a malicious actor needs to do to get admission is figure out a means to guess or steal that password. This is the only thing that needs to be done in order to acquire access. However, if admittance additionally needs a second (or perhaps a second and a third) element of authentication, then it becomes far more difficult to obtain access, particularly if the requirement is for something that is more difficult to guess or steal, such as a biometric characteristic.
Providing support for various digital initiatives
Multi-factor authentication is a key enabler in today's business world, where more companies are keen to deploy remote workforces, more customers want to purchase online rather than in shops, and more companies are migrating apps and other resources to the cloud. In this day and age, it can be difficult to ensure the safety of organisational and e-commerce resources. Multi-factor authentication can be an extremely useful tool for assisting in the protection of online interactions and financial transactions.
Are there any disadvantages to multi-factor authentication?
It is feasible to establish a less easy-to-access environment while building a more secure one — and this might be a disadvantage (this is especially true as zero trust, which sees everything as a possible threat, including the network and any apps or services running on it, gains acceptance as a safe access basis). No employee wants to spend additional time each day dealing with several impediments to getting on and accessing resources, and no consumer wants to be slowed down by multiple authentication procedures. The objective is to strike a balance between security and convenience so that access is secure but not so onerous that it causes excessive hardship for those who legitimately require it.
The role of risk-based authentication in multi-factor authentication
One technique to achieve a balance between security and convenience is to increase or decrease authentication requirements based on the risk associated with an access request. This is what risk-based authentication entails. The risk might be associated with either what is being accessed or who is requesting access.
The risk presented by what is accessed
For example, if someone seeks digital access to a bank account, is it to initiate a money transfer or simply to verify the status of an existing transfer? Or, if someone interacts with an online shopping website or app, is it to place an order or to monitor the progress of an existing purchase? For the latter, a username and password may be sufficient, but multi-factor authentication makes sense when a high-value item is at stake.
The risk is presented by the person requesting access
When a remote employee or contractor seeks access to the corporate network from the same city, on the same laptop, day after day, there's little reason to assume it's not that person. But what happens when a request from Mary in Minneapolis arrives from Moscow unexpectedly one morning? A request for extra authentication is warranted due to the possible danger – is it really her?
The future of Multi-Factor Authentication: AI, Machine Learning and more
Multi-factor authentication is always improving to provide enterprises with access that is both more secure and less unpleasant for individuals. Biometrics is an excellent example of this concept. It's more secure, since stealing a fingerprint or a face is difficult, and it's more convenient because the user doesn't have to remember anything (such as a password) or make any other substantial effort. The following are some of the current advancements in multi-factor authentication.
Machine learning (ML) and artificial intelligence (AI)
AI and ML may be used to identify characteristics that indicate if a particular access request is "normal" and as such, does not require extra authentication (or, conversely, to recognize anomalous behaviour that does warrant it).
Online Quick Identity (FIDO)
The FIDO Alliance's free and open standards serve as the foundation for FIDO authentication. It facilitates the replacement of password logins with safe and quick login experiences across websites and applications.
Authentication without a password
Rather than utilizing a password as the primary means of identity verification and complementing it with alternative non-password methods, passwordless authentication does away with passwords entirely.
Be certain that multi-factor authentication will continue to evolve and develop in the pursuit of methods for individuals to show they are who they say they are — reliably and without having to jump through an endless number of hoops.