It’s Cybersecurity Awareness Month: When Did You Last Change Your Password?

It’s Cybersecurity Awareness Month: When Did You Last Change Your Password?

October is Cybersecurity Awareness Month, and I wanted to use the opportunity to share a quick reminder about the value of taking a few minutes to do some basic account housekeeping every now and then.

Here’s the ask: If you haven’t changed your ARIN Online account password recently, please take a moment to update it.

That’s it. This isn’t a response to any incident or suspicious activity. It’s simply good security hygiene. Think of it like changing the batteries in your smoke detector: Nothing’s on fire, but you don’t wait for the beep either.

Why now?

Passwords become less secure over time, often without you noticing. For example:

  • A site on which you used that same password may have been breached, and reused passwords are one of the most common ways accounts get compromised.
  • You may have entered the password on a device or network you don’t control and shouldn’t have trusted: a shared computer, an airport lounge, a friend’s laptop.
  • Old passwords tend to be weaker passwords. If you set yours a few years ago, it may not hold up the way a fresh, longer password would.

None of these are necessarily reasons to panic. A periodic refresh clears most of them out.

Why bother updating my password if I’m using multifactor authentication?

Multifactor authentication (MFA) is an additional lock, not a replacement for the first one. If a password is the front door lock, MFA is the deadbolt. A strong password keeps both locks working effectively, so an attacker has to defeat two things instead of one.

If your password is weak or compromised, an attacker is already halfway in, and the only thing standing between them and your account is that second factor. At that point, you’re essentially relying on a single factor again. The layered approach is what makes MFA effective in the first place.

How to Change Your ARIN Online Password

  1. Head to the Settings page by selecting ‘Settings’ from the drop-down menu in the upper right of any page in ARIN Online. In the Security Info section of this page, select ‘Actions,’ then ‘Change Password.’
  2. Choose a new password that is long and not a variation of your last one.
  3. If you use a password manager, let it generate and store the new one for you. If you don’t, this is a great time to give one a try.

One tip: A long passphrase (four or five random words strung together with no spaces) is easier to remember and harder to crack than the classic “P@ssw0rd1” formula that uses fewer characters.

A new password only helps if it’s actually new. Recycling one you use elsewhere, or adding a “2” to the end of your old one, doesn’t really move the needle.

Thank you for taking care of it. It makes your account safer and my job easier.

Thank You to Our MFA Users

If you’ve configured MFA for your ARIN Online account, thank you. You’ve added the single most effective layer of protection available to your account. However, not all MFA methods offer the same level of protection. It’s worth considering whether yours matches how important your account is to you.

  • One-time passcodes (OTPs) sent via SMS are far better than nothing, but they’re the weakest of the three methods supported by ARIN Online; text messages can be intercepted or redirected through SIM-swapping.
  • Authenticator apps (TOTP) are more secure, because the codes live on your device rather than traveling over the phone network.
  • Security keys and passkeys (FIDO2) are the strongest option we offer — they’re resistant to breaches in a way the others aren’t.

If you currently use SMS codes, consider moving up a tier. MFA settings can be accessed and changed anytime by:

  1. Logging in to ARIN Online,
  2. Selecting ‘Settings’ from the drop-down menu in the upper right of any page,
  3. Selecting ‘Actions’ under Security Info,
  4. Selecting ‘Manage Multifactor Authentication,’
  5. And following the prompts to complete setup.

Happy Cybersecurity Awareness Month!

Post written by:

Christian Johnson
Chief Information Security Officer

Recent blogs categorized under: Tips


Sign up to receive the latest news about ARIN and the most pressing issues facing the Internet community.

SIGN ME UP →

Tips •  Training •  Security •  Public Policy •  Elections •  ARIN Bits •  Grant Program •  Fellowship Program •  Caribbean •  IPv6 •  Data Accuracy •  IPv4 •  Guest Post •  Customer Feedback •  Outreach •  Internet Governance •  RPKI •  Updates •  IRR •  Business Case for IPv6

 

Connect with us on Instagram!