Showing posts sorted by date for query password. Sort by relevance Show all posts
Showing posts sorted by date for query password. Sort by relevance Show all posts

28 August 2026

Actors calling for law on AI voice cloning

Actors including Matt Lucas, Hugh Bonneville and Nicola Coughlan have written to the UK government demanding greater protection against their voices being used by AI.

The performers are asking Prime Minister Andy Burnham to introduce legislation which would give every person in the UK a legal right to own their voice.

Voice clones are created by training AI on recordings of real people. Quick versions can be made in minutes from a few seconds of audio, but high-quality copycats tend to require hours.

Audiobook narrator Alice Sockett, who co-founded the campaign, called it "an existential threat to our entire industry".

"My voice is out there in the public domain but completely unprotected," she said.

"We're seeing voice theft increase every week."

A government spokesperson told the BBC that, while "digital replicas can be a powerful tool, including for the creative industries," there was also possibility for harm.

"We value and protect human creators, and that is why we have announced we will launch a consultation on how we address these harms, while protecting legitimate innovation", the spokesperson said.

Meanwhile in other news: Banks tell us that it's safe to use "my voice is my password" - I think not! AI is truly an existential threat to humanity - not the great panacea that we are being lead to believe.

www.bbc.co.uk


20 February 2026

Your AI-generated password isn't random, it just looks that way

AI security company Irregular looked at Claude, ChatGPT, and Gemini, and found all three GenAI tools put forward seemingly strong passwords that were, in fact, easily guessable.

Prompting each of them to generate 16-character passwords featuring special characters, numbers, and letters in different cases, produced what appeared to be complex passphrases. When submitted to various online password strength checkers, they returned strong results. Some said they would take centuries for standard PCs to crack.

The online password checkers passed these as strong options because they are not aware of the common patterns. In reality, the time it would take to crack them is much less than it would otherwise seem.

Irregular found that all three AI chatbots produced passwords with common patterns, and if hackers understood them, they could use that knowledge to inform their brute-force strategies.

The researchers took to Claude, running the Opus 4.6 model, and prompted it 50 times, each in separate conversations and windows, to generate a password. Of the 50 returned, only 30 were unique (20 duplicates, 18 of which were the exact same string), and the vast majority started and ended with the same characters.

www.theregister.com


07 November 2025

You'll never guess what the most common passwords are. Oh, wait, yes you will

123456. admin. password. For years, the IT world has been reminding users not to rely on such predictable passwords. And yet here we are with another study finding that those sorts of quickly-guessable, universally-held-to-be-bad passwords are still the most popular ones.

Tech advice website Comparitech on Thursday published the 100 most common passwords based on a deep dive into more than two billion passwords leaked on breach forums in 2025. 

The three mentioned above all finish in the top ten, along with various variations of the numerals 1-9 in ascending sequential order. 

Puh-leaze, don't do this! Have a look here to get some useful tips on how to secure your credentials - or contact Donline.

www.theregister.com


18 July 2025

Police dismantle DiskStation ransomware gang targeting NAS devices, arrest suspected ringleader


"Operation Elicius", a joint international law enforcement operation involving Europol and police forces in Italy, France, and Romania, has successfully dismantled a Romanian ransomware gang that targeted network-attached storage (NAS) devices and arrested its suspected leader.

The so-called "DiskStation Security" ransomware group has targeted and compromised NAS devices - particularly those manufactured by Synology - since 2021, leaving the data of businesses and non-profit organisations encrypted, and demanding a ransom for its recovery...

...Synology has been advising users on how to protect their NAS devices from ransomware attacks for several years.  Much of the advice revolves around minimising the exposure of NAS devices to the internet, hardening password security, and ensuring that regular backups are made of critical data.

The accounts used to secure NAS devices are no different from any other when it comes to security - you should ensure that passwords are unique, and not easy-to-crack.  Attackers will often use automated tools to brute force their way into poorly-secured devices, or take advantage of users who have used easy-to-guess, predictable passwords.

Donline supports dozens of business & home clients in specifying, building, deploying & ongoing management of Synology NAS devices. They are excellent, reliable, cost effective devices to manage your network & data. HOWEVER, as with all IT: internet connectivity, credentials, patching, etc - MUST be carefully managed. Got questions about IT? Contact Donline.

www.fortra.com


17 June 2024

Microsoft: New Outlook security changes coming to personal accounts


Microsoft has announced new cybersecurity enhancements for Outlook personal email accounts as part of its 'Secure Future Initiative,' including the deprecation of basic authentication (username + password) by September 16, 2024.

The software giant also announced the end of support for 'Mail' and 'Calendar' apps on Windows, the deprecation of Outlook Light, and removing users' ability to access Gmail accounts via Outlook.com.

Starting September 16, 2024, Basic Authentication (username and password) for Outlook clients will be phased out for all Outlook personal accounts, including Outlook.com, Hotmail.com, and Live.com.

The basic authentication method is unsafe as it sends credentials over the wire without encryption, allowing networking monitoring tools to capture them. Furthermore, browsers and other applications commonly cache basic authentication credentials until the browser is restarted, allowing them to be used by others with access to the device.

"While Basic Auth was the standard for quite some time, it also made it easier for bad actors to capture a person's login information," explains Microsoft.

"This increased the risk of those stolen credentials being reused to gain access to a person's email or personal data. Email-based cyberattacks have only increased with time, so we are requiring modern authentication for all Outlook customers to better help protect their personal accounts."

By switching to more modern authentication methods, the basic authentication credentials will be replaced by token-based authentication backed by multi-factor authentication (MFA).


29 April 2024

Smart gadgets: Tougher rules for sellers of internet connected devices in the UK


Manufacturers will have to follow stricter rules if they want to sell "smart" gadgets in the UK after a new law came into effect.

It is designed to ensure there is better security around devices such as baby monitors, televisions and speakers that are linked to the internet. These gadgets can pose a risk because cyber-criminals use them to hack into home networks and steal private data. The government said the new law should give consumers "peace of mind".

The risks have ballooned in recent years as our houses have filled with more and more web-linked smart devices - from games consoles to fitness trackers, doorbells and even dishwashers, also sometimes referred to as the "internet of things" (IoT).

Until now, manufacturers were expected to follow security guidelines, but the new law makes three new requirements:

  • that password procedures are more secure, including ensuring any set by the manufacturer are not left blank or using easy-to-guess choices like "12345" or "admin"
  • that there is clarity around how to report "bugs" or security problems that arise
  • that manufacturers and retailers inform customers how long they will receive support, including software updates, for the device they are buying

Failure to meet these minimum requirements, known as the Product Security and Telecommunications Infrastructure (PSTI) regime, can trigger fines.

www.bbc.co.uk


26 June 2023

Do you have a Hikvision or Dahua security camera? Time to check/update firmware, or replace!

Chinese-made surveillance cameras are in British offices, high streets and even government buildings - and Panorama has investigated security flaws involving the two top brands. How easy is it to hack them and what does it mean for our security?

In a darkened studio inside the BBC's Broadcasting House in London, a man sits at his laptop and enters his password. Thousands of miles away, a hacker is watching everything he types. Next, the BBC employee picks up his mobile phone and enters the passcode. The hacker now has that, too.

A security flaw in the surveillance camera on the ceiling - manufactured by the Chinese firm Hikvision - means it's now vulnerable to attack.

"I own that device now - I can do whatever I want with that," says the hacker. "I can disable it… or I can use it to watch what's going on at the BBC." Thankfully for the man being watched, the hacker is working with the BBC. This is part of a series of experiments by Panorama to test the security of some Chinese-made surveillance cameras.

Hikvision and Dahua are two of the world's leading manufacturers of surveillance cameras. Nobody knows how many of their units line the UK's streets...

www.bbc.co.uk


11 April 2023

Terrifying study shows how fast AI can crack your passwords

 

Along with the positive aspects of the new generative AI services come new risks. One that’s surfaced is an advanced approach to cracking passwords called PassGAN. Using the latest AI, it was able to compromise 51% of passwords in under one minute with 71% of passwords cracked in less than a day. 

Last month, Microsoft brought attention to the security concerns that will come with the quick advancement of AI by announcing its new Security Copilot suite that will help security researchers protect against malicious use of modern technology.

Now Home Security Heroes has published a study showing how scary powerful the latest generative AI is at cracking passwords. The company used the new password cracker PassGAN (password generative adversarial network) to process a list of over 15,000,000 credentials from the Rockyou dataset and the results were wild:

51% of all common passwords were cracked in less than one minute, 65% in less than an hour, 71% in less than a day, and 81% in less than a month.

To stay safe: stick with at least 12 characters with a mix of upper, and lowercase letters plus numbers. Never reuse passwords - a unique one per service / account. Need help securing your accounts? Contact Donline.


02 December 2022

Intruders gain access to user data in LastPass incident

Intruders broke into a third-party cloud storage service LastPass shares with affiliate company GoTo and gained access to "certain elements" of customers' information, the pair have confirmed.

LastPass did not define what it meant by "certain elements," saying it was unsure what data was looked at: "We are working diligently to understand the scope of the incident and identify what specific information has been accessed this morning."

It did maintain, however, that services were unaffected and that customers' passwords remained "safely encrypted" – without ruling out that some of the data was stolen. The company is known to use a one-way salted hash for master passwords, with a fuller description in this technical whitepaper. The master passwords are used to lock users' password vaults, where their logins for various websites etc. can be stored, with the passphrase only ever entered by the user on their browser or app and not sent to or stored by LastPass.

www.theregister.com


25 November 2022

Guess the most common password. Hint: We just told you

NordPass has released its list of the most common passwords of 2022. Topping the list of the most common passwords was, sadly, "password," followed by "123456" and its more secure relative "123456789," "guest," "qwerty" and lots more you can definitely figure out without needing the help of a cracking tool.

Seriously, few of the passwords in this list are even words: Most are just repetitions of a single character, sequences of easy-to-guess numbers, a straight run down a row of keys, or basic combinations like "pass@123." 

Along with a depressingly basic list of common passwords and the speed it takes to crack them (most are listed as < 1 second), NordPass shared some statistics about what's trending in the password world, like the word "Oscars," which pops up especially around award season, as well as "batman," "euphoria" and "encanto" after the eponymous films and TV series that have been popular this year.

FYI: here are five things to know to pick a good password.

www.theregister.com


18 November 2022

Online security experts discuss why the future of passwords is no passwords.

 

Watch a short video featuring online security experts from CISA, FIDO Alliance, Google, and Microsoft. These experts highlight why the future of passwords is no passwords – with FIDO.

FIDO Authentication: The FIDO Alliance is involved in three areas to work towards achieving its mission to reduce the world’s reliance on passwords to better secure the web: user authentication; identity verification and binding; and the Internet of Things (IoT). The work areas address essential aspects of the digital identity lifecycle management including identity verification for initial account onboarding and account recovery, and user and device authentication.

FIDO Authentication: Passwords endure despite the growing consensus their use needs to be reduced, if not replaced. But even though effective PKI and strong authentication solutions have existed for years, barriers to widespread adoption persist. Consumers don’t like the user experience, and online service providers don’t want the cost and complexity of developing and provisioning their own dedicated solutions.

The industry’s answer to the password problem: The FIDO Alliance developed FIDO Authentication standards based on public key cryptography for authentication that is more secure than passwords and SMS OTPs, simpler for consumers to use, and easier for service providers to deploy and manage. FIDO Authentication enables password-only logins to be replaced with secure and fast login experiences across websites and apps.

www.fidoalliance.org


20 September 2022

Why you should turn on Multi Factor Authentication

Multi-factor authentication (MFA; encompassing two-factor authentication, or 2FA, along with similar terms) is an electronic authentication method in which a user is granted access to a website or application only after successfully presenting two or more pieces of evidence (or factors) to an authentication mechanism: knowledge (something only the user knows), possession (something only the user has), and inherence (something only the user is). MFA protects user data - which may include personal identification or financial assets - from being accessed by an unauthorised third party that may have been able to discover, for example, a single password.

A third-party authenticator (TPA) app enables two-factor authentication, usually by showing a randomly generated and frequently changing code to use for authentication. Great examples are: Microsoft Athenticator & Google Authenticator

So why use MFA/2FA? The short answer is: "because it'll make things more secure". Watch this short video by the brilliant Tom Scott to find out more. Then use ramp up your online security for things like Google (Gmail) accounts, Microsoft Office365, Zoom, etc...

Microsoft says: "There are over 300 million fraudulent sign-in attempts to our cloud services every day. All it takes is one compromised credential or one legacy application to cause a data breach. One of the best things you can do to prevent these attacks is to just turn on multifactor authentication, which can block over 99.9 percent of account compromise attacks."

www.youtube.com


19 May 2022

The passwords most used by CEOs are startlingly dumb

A recent cybersecurity report shows how immensely idiotic many CEOs and business owners can be, considering the strength of their chosen account passwords. Imagine entrusting the livelihood of hundreds, even thousands of employees to someone who uses '123456' or 'qwerty' as a password.

The research comes from NordPass password manager which identified back in 2020 that the general public's most commonly used passwords were sequential numbers like '123456', 'picture1', and yep, you guessed it: 'password'.

The more recent research sample consists of 290 million cybersecurity data breaches around the globe, and denotes the job level of those affected. Turns out, when it comes to CEOs and other high-ranking businesses execs, their password choices are much the same as the general public, although many often feature names. Tiffany was spotted in 100,534 breaches; then there was Charlie with 33,699; Michael was found 10,647 times; and Jordan, 10,472 times.

The research is pretty worrying, and makes it painfully clear that most data breaches don't happen because of some profound cyber hacking initiative; around 80% are down to people choosing really poor passwords.

Read the above? Now - how to do it properly: 5 Top Tips to pick a secure password.

www.pcgamer.com


06 May 2022

Google, Apple, Microsoft promise end to passwords, courtesy of your mobile phone

A future without passwords may be closer than we think, at least when a new initiative to enlist your smartphone as a mobile authenticator gets off the ground.

On Thursday, the FIDO Alliance - announced a new type of authentication that would use passkeys stored on your phone to unlock your online accounts without requiring a password. Google, Apple and Microsoft are all on board with the new method and have promised that their respective operating systems will support this technology.

Passwords have always been a poor way to secure our accounts. We’re constantly told to create a strong, complex and unique password for each account. But that’s a difficult task, leading many people to use weak and repetitive passwords, which can easily be compromised and used in data breaches and account takeovers. Such tools as password managers have provided some relief but still chain us to this clumsy and ineffective means of authentication.

With support from Google, Apple and Microsoft, the new authentication method will store a FIDO-based passkey on your mobile phone. That key will be encrypted to protect it from compromise and will be accessible only when you unlock your phone. When you try to sign into an app or website either on the phone itself, a nearby computer or other device, that passkey will automatically log you in regardless of the operating system or browser and without you having to enroll or re-enroll your device. If you switch to a new phone, your passkey will make the trip with you.

www.techrepublic.com


08 March 2022

How an 8-character password could be cracked in less than an hour

 

Security experts keep advising us to create strong and complex passwords to protect our online accounts and data from savvy cybercriminals. And “complex” typically means using lowercase and uppercase characters, numbers and even special symbols. But complexity by itself can still open your password to cracking if it doesn’t contain enough characters, according to research by security firm Hive Systems.

As described in a recent report, Hive found that an 8-character complex password could be cracked in just 39 minutes if the attacker were to take advantage of the latest graphics processing technology. A seven-character complex password could be cracked in 31 seconds, while one with six or fewer characters could be cracked instantly. Shorter passwords with only one or two character types, such as only numbers or lowercase letters, or only numbers and letters, would take just minutes to crack.

On the plus side, even simpler passwords with a greater number of characters are less vulnerable to cracking in a short amount of time, according to Hive’s research. An 18-character password with just numbers would require three weeks to crack, but one with the same number of characters using lowercase letters would take 2 million years to crack. This piece of data shows why passphrases, which use a long string of real but random words, can be more secure than a complex but short password.

www.techrepublic.com


14 February 2022

What is a SIM swap attack?

SIM swapping is a scam in which malicious parties target cell phone carriers to gain access to victims’ bank accounts, virtual currency accounts and additional sensitive information by using social engineering, insider threat or phishing techniques. Social engineering involves a criminal to impersonate the victim’s mobile number by tricking the cell phone carrier into switching the victim’s mobile number to a SIM card that is in the criminal’s possession, allowing the malicious party to access the victim’s calls, texts and other data, but this is only one of the three methods used to steal funds from victims.

Insider threat takes place when a criminal actor pays off a mobile carrier employee to switch the victim’s SIM to a card currently in the criminal’s possession. Malicious parties can also employ phishing techniques to access victims’ sensitive data, and steal funds from the victim through their banking data or third-party services like PayPal or Venmo. This level of access to a victim’s cell data then allows a malicious party entry to everything from text message verification to SMS based two-factor authentication to exploit victims’ sensitive information.

“Service providers must move from more simplistic means of validating identity to more sophisticated ones,” Clements said. “PIN codes unique to each user’s account can be one way of adding additional security to the process, and ‘out of wallet’ questions are another alternative that works by verifying much harder to compromise information such as last three home addresses or cars. It may be more of a hassle for everyone, but it’s simply no longer viable to rely on information that has been routinely compromised to validate a person’s identity.”

The FBI encourages both cell phone users and the companies that provide service to take additional security measures in protecting their personal information. For cell phone users, the agency outlines the following tips:

Do not advertise information about financial assets, including ownership or investment of cryptocurrency, on social media websites and forums.

Do not provide your mobile number account information over the phone to representatives that request your account password or pin. Verify the call by dialing the customer service line of your mobile carrier.

Avoid posting personal information online, such as mobile phone number, address or other personal identifying information.

Use a variation of unique passwords to access online accounts.

Be aware of any changes in SMS-based connectivity.

Use strong multi-factor authentication methods such as biometrics, physical security tokens, or standalone authentication applications to access online accounts.

Do not store passwords, usernames or other information for easy login on mobile device applications.

www.techrepublic.com


15 September 2021

Microsoft accounts can now go fully passwordless

 

Microsoft now lets you remove passwords from Microsoft accounts to embrace a passwordless future. Starting today, the software giant will let consumers sign into Microsoft accounts with its Microsoft Authenticator app, Windows Hello, a security key, or an SMS / email verification code instead of a password.

The new option arrives just months after Microsoft started rolling out passwordless authentication for commercial users in March to help people adjust to the realities of remote work. “When I think of security, I think you’ve got to protect your whole life,” says Vasu Jakkal, corporate vice president of Microsoft security, compliance & identity, in an interview with The Verge. “It’s no longer enough just to think about work or home and anything in between.”

www.theverge.com


25 June 2021

Do you have a WD My Book Live? Disconnect it from your network / the Internet now!

Storage drive maker Western Digital is telling owners of its WD My Book Live device to disconnect it from the internet after reports that some have had their data erased by malicious software.

According to an advisory issued by the firm, malicious attackers are compromising the devices – commonly used to back up data such as home movies, photographs, and important documents – resulting in their entire contents being wiped in some cases.

Western Digital has determined that some My Book Live devices are being compromised by malicious software. In some cases, this compromise has led to a factory reset that appears to erase all data on the device.

The first indication that most victims will see is an “invalid password” message when they attempt to log into their device.

In a thread on Western Digital’s support forum, many My Book Live owners have described how all of their data has disappeared.

www.tripwire.com


19 April 2021

Top 200 most common passwords of the year 2020 - top 10 on this pic!

 

Here are the worst 200 passwords of 2020. The list details how many times a password has been exposed, used, and how much time it would take to crack it. 

We also compare the most common passwords of 2019 and 2020, highlighting how their positions have changed. The green arrows indicate a rise in the position while the red ones - a fall off. 

Check if your password is on the list and strengthen it if it is.

www.nordpass.com


11 February 2021

Another example of how not to do IT - asking for trouble!

The Florida water treatment facility whose computer system experienced a potentially hazardous computer breach last week used an unsupported version of Windows with no firewall and shared the same TeamViewer password among its employees, government officials have reported.

The computer intrusion happened last Friday in Oldsmar, a Florida city of about 15,000 that’s roughly 15 miles northwest of Tampa. After gaining remote access to a computer that controlled equipment inside the Oldsmar water treatment plant, the unknown intruder increased the amount of sodium hydroxide - a caustic chemical better known as lye - by a factor of 100. The tampering could have caused severe sickness or death had it not been for safeguards the city has in place.

According to an advisory from the state of Massachusetts, employees with the Oldsmar facility used a computer running Windows 7 to remotely access plant controls known as a SCADA - short for “supervisory control and data acquisition” - system. What’s more, the computer had no firewall installed and used a password that was shared among employees for remotely logging into city systems with the TeamViewer application.

www.arstechnica.com