How to create a secure username (2024)

by Lance Whitney in Security

on

How to create a secure username

Passwords are the most important factor for securing your accounts. But you need to pay attention to your usernames as well, says NordPass.

We may be compensated by vendors who appear on this page through methods such as affiliate links or sponsored partnerships. This may influence how and where their products appear on our site, but vendors cannot pay to influence the content of our reviews. For more info, visit our Terms of Use page.
How to create a secure username (2)

You may take all the right steps to create and maintain secure passwords for your online accounts. But what about your username? If you’re like most people, you likely use your first or full name as your username across various websites. But that strategy can leave you vulnerable to compromise, according to a new report from password manager NordPass.

SEE: Social engineering: A cheat sheet for business professionals (free PDF) (TechRepublic)

In a blog post published Tuesday, NordPass revealed the top 200 most popular usernames based on research from a white hat hacker. The most common username was ยศกร, which means “title” in Thai. In second place was David, followed by Alex, Maria, Anna, Marco, Antonio, Daniel, and then Andrea, all just actual people’s names. The remaining selections of the top 200 were all first names used in different countries around the world.

The point behind the research was to show the tendency to use real names as a username, a maneuver that can lead to trouble. When a hacker targets data during a breach, they look for any kind of information they can easily capture, including usernames. The more common or obvious a username, the more easily it can be obtained.

As one example, Snapchat was hit by a data breach in 2014 during which time the attackers downloaded 4.6 million usernames and phone numbers. As many people used their own names or surnames as their usernames, they were easy for the hackers to identify. Further, cybercriminals who learn your username and phone number can launch social engineering attacks with such messages as: “You’re receiving this SMS from Snapchat, and we need you to verify your password for account johnsmith.”

Some websites have introduced tighter security policies around usernames. In some cases, sites will now determine if your username is unique. If not, the site won’t let your register or set up an account.

How can you choose a more secure username? NordPass security expert Chad Hammond offers the following tips:

  1. Don’t just use your name as a username.
  2. Avoid using the beginning of your email address as your username.
  3. Your username should be simple enough to remember but hard to guess.
  4. Never use easy-to-guess numbers with your usernames (for example, address or date of birth).
  5. Don’t use your Social Security number or ID number as your username.
  6. If you’re struggling, try an online username generator.

Subscribe to the Cybersecurity Insider Newsletter

Strengthen your organization's IT security defenses by keeping abreast of the latest cybersecurity news, solutions, and best practices. Delivered Tuesdays and Thursdays

Subscribe to the Cybersecurity Insider Newsletter

Strengthen your organization's IT security defenses by keeping abreast of the latest cybersecurity news, solutions, and best practices. Delivered Tuesdays and Thursdays

Also See

By Lance Whitney

Lance Whitney is a freelance technology writer and trainer and a former IT professional. He's written for Time, CNET, PCMag, and several other publications. He's the author of two tech books--one on Windows and another on LinkedIn.

  • |
  • See all of Lance's content
  • Security

Editor's Picks

  • TechRepublic Premium

    TechRepublic Premium Editorial Calendar: Policies, Checklists, Hiring Kits and Glossaries for Download

    TechRepublic Premium content helps you solve your toughest IT issues and jump-start your career or next project.

  • Artificial Intelligence

    7 Best AI Art Generators of 2023

    This is a comprehensive list of the best AI art generators. Explore the advanced technology that transforms imagination into stunning artworks.

  • Payroll

    The Best Cheap Payroll Services

    Find the perfect payroll service for your business without breaking the bank. Discover the top cheap payroll services, features, pricing and pros and cons.

  • Cloud Security

    Is NordVPN worth it? How much does it cost and is it safe to use? Read our NordVPN review to learn about pricing, features, security, and more.

  • Project Management

    Free project management software provides flexibility for managing projects without paying a cent. Check out our list of the top free project management tools.

  • Cloud

    Cloud Strategies Are Facing a New Era of Strain in Australia, New Zealand

    Australian and New Zealand enterprises in the public cloud are facing pressure to optimize cloud strategies due to a growth in usage and expected future demand, including for artificial intelligence use cases.

As an expert in cybersecurity and online privacy, I've been deeply involved in the field for several years, staying updated with the latest trends, best practices, and emerging threats. My expertise spans across various domains within cybersecurity, including but not limited to password management, secure online practices, social engineering, and the significance of usernames in protecting digital identities.

Regarding the article by Lance Whitney published on September 22, 2020, discussing the importance of secure usernames, it delves into the often underestimated aspect of account security—usernames. The piece emphasizes that while passwords receive significant attention, usernames are also crucial components of account security and can expose individuals to vulnerabilities if not chosen wisely.

The article highlights findings from NordPass, a password manager, which revealed the prevalence of common and easily guessable usernames based on real names, as identified by a white hat hacker's research. It elucidates how hackers exploit such predictable usernames during data breaches, citing the example of the Snapchat breach in 2014, where 4.6 million usernames and phone numbers were compromised, many being easily identifiable due to their use of real names.

NordPass's security expert, Chad Hammond, offers tips on creating more secure usernames:

  1. Avoid using your actual name as a username.
  2. Refrain from using the start of your email address as a username.
  3. Choose a username that's easy for you to remember but difficult for others to guess.
  4. Steer clear of incorporating easily guessable numbers like addresses or birthdates.
  5. Never use sensitive information like Social Security numbers or ID numbers as usernames.
  6. Consider utilizing online username generators if you're struggling to create a secure username.

This article brings attention to the significance of adopting unique and secure usernames to fortify overall account security, emphasizing the need for individuals to be more cautious and creative in selecting usernames to thwart potential cyber threats.

Now, touching upon the concepts mentioned in the article:

  1. Usernames and Security: The piece emphasizes the importance of choosing secure usernames to bolster account security, shedding light on how predictable or common usernames can make individuals vulnerable to cyber threats.

  2. Data Breaches and Usernames: It discusses real-world examples, such as the Snapchat breach, demonstrating how hackers target and exploit common usernames during data breaches to access sensitive information.

  3. Social Engineering Attacks: The article highlights how cybercriminals leverage obtained usernames and personal information to launch social engineering attacks, emphasizing the risks associated with exposing easily identifiable usernames.

  4. Best Practices for Secure Usernames: It provides actionable tips from a cybersecurity expert on creating more secure usernames, offering practical advice to help individuals enhance their account security.

This information underscores the significance of usernames in the realm of cybersecurity and serves as a reminder for individuals to exercise caution and thoughtfulness in choosing usernames to mitigate potential risks associated with online security breaches.

How to create a secure username (2024)

FAQs

What is a good secure username? ›

Including both letters and numbers in a random pattern is safer than using personal identifiers or common phrases. A username that is easier for you to remember is usually easier for a hacker to guess. This is especially true when the username is based on a variation of your email address, name, or home address.

How do I create a unique username? ›

How do I create a unique username? There are a few tricks you can use to create a truly unique username. Choose a word or a phrase you like and then translate it to a different language and use that as your username. You can also incorporate puns in your usernames to give them that special flair.

How can I create a strong username? ›

To create a safe username:
  1. Personal Information: Avoid using any personal information such as your real name, date of birth, or address as part of your username.
  2. Passwords or PINs: Do not use your passwords, PINs or other sensitive information as your username.

What is a safe username I could use online? ›

The best username tips from the pros

Decide if your username protects your identity or can be public. Create a username that is simple enough to remember but hard to guess - and store it in your password manager. Avoid using familiar numbers with your usernames, such as an address or birth dates.

Should you use your real name as a username? ›

The short version is that using a generic username, like one based on your real name, can make it easier for cybercriminals to target you. Creating secure usernames means you have an extra layer of defense against attackers, with password managers as the best way to create and store them.

Should I use my email address as a username? ›

Avoid using your email address as a username whenever you can. Using it makes it easier for hackers to target your accounts. Opt for a unique username to enhance security and reduce the risk of unauthorized access to your accounts.

What is a good example of a username? ›

For example, someone with the first name Esmeralda may create a username like @IAmEsmeralda or @ImEsmeralda. The word "it's": Using the word "it's" can be another simple and effective way to create a unique username if your full name isn't available.

How do I know if a username is taken? ›

Handle Monitor is a tool that allows you to monitor, track, and check social media username handles. Simply enter your desired username, choose the platform and let Handle Monitor do the work for you! The tool will check the availability of the username and, if taken, notify you when it becomes available.

What is a good example of a username and password? ›

For example: b0st0ndud3 (bostondude) or 1mag1n3that (imaginethat). Create a phrase instead of just one word (for example, MyGrade100). Use an alternate spelling like those in text messaging (for example, fud for food). The more random a password is, the more secure it becomes.

How do I create a secure email name? ›

Setting up an email address
  1. Use non-identifying information. ...
  2. Use a password no one else knows. ...
  3. Use two-step verification. ...
  4. Review security notifications. ...
  5. Use secure devices. ...
  6. Always log out. ...
  7. Don't allow browser or mobile phone to remember your email account or passwords. ...
  8. Be cautious when giving out your email address.
Jan 29, 2018

How do I find my catchy username? ›

What to Know
  1. Incorporate your favorite things, such as food, celebrities, or career aspirations.
  2. Use an online screen name generator such as SpinXO.
  3. Build an unlikely username by substituting symbols and letters, like 3 for E and $ for 5.
Jun 1, 2022

What is a strong username and password? ›

Use a mix of alphabetical and numeric, a mixture of upper and lowercase, and special characters when creating your unique passphrase. Use unique passwords or passphrases: You should have a unique password for each of your accounts.

Top Articles
Latest Posts
Article information

Author: Pres. Carey Rath

Last Updated:

Views: 6283

Rating: 4 / 5 (61 voted)

Reviews: 92% of readers found this page helpful

Author information

Name: Pres. Carey Rath

Birthday: 1997-03-06

Address: 14955 Ledner Trail, East Rodrickfort, NE 85127-8369

Phone: +18682428114917

Job: National Technology Representative

Hobby: Sand art, Drama, Web surfing, Cycling, Brazilian jiu-jitsu, Leather crafting, Creative writing

Introduction: My name is Pres. Carey Rath, I am a faithful, funny, vast, joyous, lively, brave, glamorous person who loves writing and wants to share my knowledge and understanding with you.