
The best password is a long, nonsensical string of letters and numbers and punctuation marks, a combination never put together before. Some admirable people actually do memorize random strings of characters for their passwords--and replace them with other random strings every couple of months. Then there's the rest of us, selecting the short, the familiar and the easiest to remember; and holding onto it forever.
Computer security experts say that choosing hard-to-guess passwords ultimately <A HREF="http://www.nytimes.com/2008/08/10/technology/10digi.html?_r=1&no_interstitial&oref=slogin">brings little security protection.</A> Passwords won't keep us safe from identity theft, no matter how clever we are in choosing them. That would be the case even if we had done a better job of listening to instructions. Surveys show that we've remained stubbornly fond of perennial favorites like "password," "123456" and "LetMeIn." The underlying problem, however, isn't their simplicity; it's the log-on procedure itself.