TheTechArea.com: Security report: Web users pick passwords that are way too easy to hack - TheTechArea.com

Jump to content

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

Security report: Web users pick passwords that are way too easy to hack

#1 User is offline   The Joker 

  • WhY sO sErIoUs?!?
  • Group: Administrator
  • Posts: 7,635
  • Joined: 28-July 05
  • Gender:Male
  • Location:Buffalo, NY, USA
  • Interests:Computers, Home Theater, Console Games, Movies

Posted 21 January 2010 - 09:26 PM

According to a report on Consumer Password Best Practices culled from an analysis of 32 million passwords exposed in the recent Rockyou.com Web security breach, the three most commonly used passwords among users of the Rockyou social networking site turned out to be 123456, 12345, and 123456789.Also making in into the top ten, in this order, were the following: Password, iloveyou, princess, rockyou, 1234567, 12345678, and abc123.

During the Rockyou breach last month, a hacker exploited a SQL Injection vulnerability to expose 32 million passwords -- which had been stored in clear text in Rockyou's database -- and then posted the passwords, without any other identifying information, on the Web.

In analyzing the results for a report issued today, researchers at the Imperva Application Defense Center (ADC) discovered that even now, people are still relying on the same kinds of "weak" passwords detected in earlier studies of Unix passwords 20 years ago, and Hotmail passwords a decade ago.

About 30% of Rockyou users chose passwords with five or fewer characters, and almost 50% opted for "names, slang words, dictionary words or trivial passwords (consecutive digits, adjacent keyboards keys, and so on)," according to key findings of Imperva's report.

>> Source: Betanews


Image created by CarnageX | You've been Mak'd! | Decaptured...listen! | All thanks to Hefe for the parts for my new PC!
This is what happens when an unstoppable force meets an immovable object. | Twitter | TTA Facebook

Posted Image
Posted ImagePosted Image

View PostAtlas, on 24 January 2010 - 01:34 PM, said:

New from Apple... the iPost. Full online forum backup, protects your e-peen from being shrank by post count reductions. Protect your e-Rep for pennies!


0

#2 User is offline   Subject Delta 

  • Would You Kindly...
  • Group: Administrator
  • Posts: 12,073
  • Joined: 13-March 04
  • Gender:Male
  • Location:Kent, England
  • Interests:If you really wanna know, feel free to PM me :p

Posted 21 January 2010 - 09:36 PM

Ugh, this could be solved with 2 simple implementations

1: Database password encription

2: Password strength enforcement rules

You will never take the idiot out of the common man, so you should legislate it away instead.


0

Share this topic:


Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users