Showing posts sorted by relevance for query password. Sort by date Show all posts
Showing posts sorted by relevance for query password. Sort by date Show all posts

20 November 2018

Top 5 ways to pick a secure password


Oh, passwords. Someday the FIDO alliance or somebody will save us from them. Until that heady day, we still need them and we need to choose ones that are really hard to guess. Even if you have two-factor authentication turned on—which you should—secure passwords are still a good idea. Fire up your Horse Battery Staple, here are five things to know to pick a good password:

1) Never reuse one. Ever. Data breaches are very common. When your password is breached at a service, that service will usually make you change it. But the service where you re-used it doesn't know that, so you just made that password very insecure.

2) Choose a long and strong passphrase. Yes, it is possible to remember your password and make it secure. Don't choose dictionary words. Security researcher Bruce Schneier suggests taking a sentence like: "When I was seven, my sister threw my stuffed rabbit in the toilet." And using the first letters numbers and punctuation to make "WIw7,mstmsritt."

3) Let a password manager do it for you. Yes, password managers are a single-point of failure, so be honest with yourself. Are your passwords more secure if you let a manager that is 2FA-protected pick really good ones for you? Or do you want to manage all that yourself? And is the way you manage it, more secure than a password manager? Be honest—nobody else needs to know.

4) Don't update it regularly unless you're forced to. It used to be that it took 90 days to crack a password, so if you changed it every 90 days, you could stay ahead. Now it takes seconds, unless you've picked a strong one.

5) Skip the secret question. If that's not an option, answer it like you're making a second password. There's no point in having a really secure password only to have it backed up by a dictionary word in your secret question that's easily guessable.


07 May 2020

Protecting your organisation against password spray attacks


When hackers plan an attack, they often engage in a numbers game. They can invest significant time pursing a single, high-value target—someone in the C-suite for example and do “spear phishing.” Or if they just need low-level access to gain a foothold in an organization or do reconnaissance, they target a huge volume of people and spend less time on each one which is called “password spray.” Last December Seema Kathuria and I described an example of the first approach in Spear phishing campaigns—they’re sharper than you think! Today, I want to talk about a high-volume tactic: password spray.

In a password spray attack, adversaries “spray” passwords at a large volume of usernames. When I talk to security professionals in the field, I often compare password spray to a brute force attack. Brute force is targeted. The hacker goes after specific users and cycles through as many passwords as possible using either a full dictionary or one that’s edited to common passwords. An even more targeted password guessing attack is when the hacker selects a person and conducts research to see if they can guess the user’s password—discovering family names through social media posts, for example. And then trying those variants against an account to gain access. Password spray is the opposite. Adversaries acquire a list of accounts and attempt to sign into all of them using a small subset of the most popular, or most likely, passwords. Until they get a hit. This blog describes the steps adversaries use to conduct these attacks and how you can reduce the risk to your organisation.

Three steps to a successful password spray attack:
Step 1: Acquire a list of usernames
Step 2: Spray passwords
Step 3: Gain access


11 February 2019

A new extension for Google Chrome: Password Checkup. A tool to help you to stay safe, stay secure


Google Password Checkup helps you re-secure accounts that were affected by data breaches. Wherever you sign-in, if you enter a username and password that is no longer safe due to appearing in a data breach known to Google, you’ll receive an alert. Please reset your password. If you use the same username and password for any other accounts, please reset your password there as well.

Password Checkup was built with privacy in mind. It never reports any identifying information about your accounts, passwords, or device. We do report anonymous information about the number of lookups that surface an unsafe credential, whether an alert leads to a password change, and the domain involved for improving site coverage. Click HERE to learn more about how Password Checkup works.


04 May 2018

Have a Twitter account? Now is a good time to reset your password


When you set a password for your Twitter account, we use technology that masks it so no one at the company can see it. We recently identified a bug that stored passwords unmasked in an internal log. We have fixed the bug, and our investigation shows no indication of breach or misuse by anyone.

Out of an abundance of caution, we ask that you consider changing your password on all services where you’ve used this password. You can change your Twitter password anytime by going to the password settings page.

About The Bug: We mask passwords through a process called hashing using a function known as bcrypt, which replaces the actual password with a random set of numbers and letters that are stored in Twitter's system. This allows our systems to validate your account credentials without revealing your password. This is an industry standard.

Due to a bug, passwords were written to an internal log before completing the hashing process. We found this error ourselves, removed the passwords, and are implementing plans to prevent this bug from happening again.


19 November 2020

Some people never learn - behold the poopie password top ten

 

It's that time of year again -- when we see whether or not password security has improved over the past 12 months. Going back to 2015, the worst passwords still commonly used included "123456" and "password." Fast forward five years, and these examples are still very much alive. 

After analyzing 275,699,516 passwords leaked during 2020 data breaches, NordPass and partners found that the most common passwords are incredibly easy to guess -- and it could take less than a second or two for attackers to break into accounts using these credentials. Only 44% of those recorded were considered "unique."

On Wednesday, the password manager solutions provider published its annual report on the state of password security, finding that the most popular options were "123456," "123456789," "picture1," "password," and "12345678."

OK 1-9 are obviously terrible passwords, but what is #10: "senha"? It is a Portuguese word which means, yes you guessed it: "password"!

www.zdnet.com


29 November 2017

Apple bug means you can log into macOS High Sierra as root - with no password


A trivial-to-exploit flaw in macOS High Sierra, aka macOS 10.13, allows users to gain admin rights, or log in as root, without a password.

The security bug can be triggered via the authentication dialog box in Apple's operating system, which prompts you for an administrator's username and password when you need to do stuff like configure privacy and network settings.

If you type in "root" as the username, leave the password box blank, hit "enter" and then click on unlock a few times, the prompt disappears and, congrats, you now have admin rights. You can do this from the user login screen, too.

The vulnerability effectively allows someone with physical access to the machine to log in, cause extra mischief, install malware, and so on. You should not leave your vulnerable Mac unattended, nor allow remote desktop access, until you can fix the problem.

Apple has now published this handy guide to enabling the root account and setting a password for it, which defeats the above exploit. Setting a password and then disabling root may also work for you: in any case, set a password for the root account.

08 March 2022

How an 8-character password could be cracked in less than an hour

 

Security experts keep advising us to create strong and complex passwords to protect our online accounts and data from savvy cybercriminals. And “complex” typically means using lowercase and uppercase characters, numbers and even special symbols. But complexity by itself can still open your password to cracking if it doesn’t contain enough characters, according to research by security firm Hive Systems.

As described in a recent report, Hive found that an 8-character complex password could be cracked in just 39 minutes if the attacker were to take advantage of the latest graphics processing technology. A seven-character complex password could be cracked in 31 seconds, while one with six or fewer characters could be cracked instantly. Shorter passwords with only one or two character types, such as only numbers or lowercase letters, or only numbers and letters, would take just minutes to crack.

On the plus side, even simpler passwords with a greater number of characters are less vulnerable to cracking in a short amount of time, according to Hive’s research. An 18-character password with just numbers would require three weeks to crack, but one with the same number of characters using lowercase letters would take 2 million years to crack. This piece of data shows why passphrases, which use a long string of real but random words, can be more secure than a complex but short password.

www.techrepublic.com


11 October 2017

Malicious iOS app popup windows could be stealing your Apple ID


Cybercriminals have a surefire way to steal Apple ID credentials: Just ask users to provide them.

A blog post by software engineer and fastlane founder Felix Krause reveals that it's dead simple to spoof iOS popups that ask for Apple ID passwords. What makes it worse, Krause said, is that we're trained to put in passwords for a variety of reasons in a variety of apps.

The average user won't question the legitimacy of an Apple ID password request, which makes the spoof a very dangerous form of phishing. All an app needs to do is show a UIAlertController popup—an incredibly common part of an app.

As impossible as it may be for a user to tell the difference between a fake and legitimate dialog window there are still things that iOS users can do to protect themselves.
  • If you get a popup asking for a password inside an app, hit the home button. If you can quit back to the home screen it's not a legitimate request. Real system dialogs that ask for passwords are run as a separate process and can't be quit in that fashion.
  • Treat password requests inside apps like you would a link in an email—don't use it. Instead, open the Settings app and put the password in there, similar to going directly to a website that wants you to verify your information.
  • Don't type anything into a password-requesting popup. Even if you press the cancel button the information has already been captured.


05 October 2017

Ask Apple for your password hint: get your password!


Apple on Thursday released a security patch for macOS High Sierra 10.13 to address vulnerabilities in Apple File System (APFS) volumes and its Keychain software.

The bug (CVE-2017-7149) undoes the protection afforded to encrypted volumes under the new Apple File System (APFS).

The problem becomes apparent when you create an encrypted APFS volume on a Mac with an SSD using Apple's Disk Utility app. 

After setting up a password hint, invoking the password hint mechanism during an attempt to remount the volume will display the actual password in plaintext rather than the hint.


28 October 2019

The top ten password-cracking techniques used by hackers


Think your passwords are secure? Think again

Understanding the password-cracking techniques hackers use to blow your online accounts wide open is a great way to ensure it never happens to you.

You will certainly always need to change your password, and sometimes more urgently than you think, but mitigating against theft is a great way to stay on top of your account security. You can always head to www.haveibeenpwned.com to check if you're at risk but simply thinking your password is secure enough to not be hacked into, is a bad mindset to have.

So, to help you understand just how hackers get your passwords – secure or otherwise – we've put together a list of the top ten password-cracking techniques used by hackers. Some of the below methods are certainly outdated, but that doesn't mean they aren't still being used. Read carefully and learn what to mitigate against.


06 May 2020

We beg, implore and beseech thee. Stop reusing the same damn password everywhere!


Two-thirds of people recycle the same password or use variations on the same basic one, according to LogMeIn.

Even though more than 90 per cent of people surveyed by the password manager biz said they knew it was risky to recycle passwords or light variations on a theme, 66 per cent of respondents admitted they "always or mostly use the same password or a variation".

These findings came from LogMeIn's Psychology of Passwords report, released recently, that quizzed 3,250 people and discovered that half of them across the world hadn't changed their passwords over the past 12 months "even after hearing about a breach in the news".

Depressingly, that number rose to 58 per cent for Britons specifically who did not change their passwords after reading about a breach on the news. A whopping 92 per cent of Brits reuse passwords despite being aware of the risks.

Click here to find out more about the risks in poor password hygiene, and advice on how to stay safe.


19 May 2022

The passwords most used by CEOs are startlingly dumb

A recent cybersecurity report shows how immensely idiotic many CEOs and business owners can be, considering the strength of their chosen account passwords. Imagine entrusting the livelihood of hundreds, even thousands of employees to someone who uses '123456' or 'qwerty' as a password.

The research comes from NordPass password manager which identified back in 2020 that the general public's most commonly used passwords were sequential numbers like '123456', 'picture1', and yep, you guessed it: 'password'.

The more recent research sample consists of 290 million cybersecurity data breaches around the globe, and denotes the job level of those affected. Turns out, when it comes to CEOs and other high-ranking businesses execs, their password choices are much the same as the general public, although many often feature names. Tiffany was spotted in 100,534 breaches; then there was Charlie with 33,699; Michael was found 10,647 times; and Jordan, 10,472 times.

The research is pretty worrying, and makes it painfully clear that most data breaches don't happen because of some profound cyber hacking initiative; around 80% are down to people choosing really poor passwords.

Read the above? Now - how to do it properly: 5 Top Tips to pick a secure password.

www.pcgamer.com


12 June 2018

25% of employees use the same password for every account


Employees may be a company's greatest asset, but they also remain the greatest cybersecurity risk, according to a Monday report from OpenVPN.

Despite an increased focus on security training, 25% of the 500 US employees surveyed report that they use the same password for every account, the report found. Another 23% of employees said they frequently click on links before verifying that they lead to a legitimate, safe website.

Of the employees that use the same password for everything, a whopping 81% said they do not password protect their computer or phone at all, according to the report.


25 November 2022

Guess the most common password. Hint: We just told you

NordPass has released its list of the most common passwords of 2022. Topping the list of the most common passwords was, sadly, "password," followed by "123456" and its more secure relative "123456789," "guest," "qwerty" and lots more you can definitely figure out without needing the help of a cracking tool.

Seriously, few of the passwords in this list are even words: Most are just repetitions of a single character, sequences of easy-to-guess numbers, a straight run down a row of keys, or basic combinations like "pass@123." 

Along with a depressingly basic list of common passwords and the speed it takes to crack them (most are listed as < 1 second), NordPass shared some statistics about what's trending in the password world, like the word "Oscars," which pops up especially around award season, as well as "batman," "euphoria" and "encanto" after the eponymous films and TV series that have been popular this year.

FYI: here are five things to know to pick a good password.

www.theregister.com


20 February 2026

Your AI-generated password isn't random, it just looks that way

AI security company Irregular looked at Claude, ChatGPT, and Gemini, and found all three GenAI tools put forward seemingly strong passwords that were, in fact, easily guessable.

Prompting each of them to generate 16-character passwords featuring special characters, numbers, and letters in different cases, produced what appeared to be complex passphrases. When submitted to various online password strength checkers, they returned strong results. Some said they would take centuries for standard PCs to crack.

The online password checkers passed these as strong options because they are not aware of the common patterns. In reality, the time it would take to crack them is much less than it would otherwise seem.

Irregular found that all three AI chatbots produced passwords with common patterns, and if hackers understood them, they could use that knowledge to inform their brute-force strategies.

The researchers took to Claude, running the Opus 4.6 model, and prompted it 50 times, each in separate conversations and windows, to generate a password. Of the 50 returned, only 30 were unique (20 duplicates, 18 of which were the exact same string), and the vast majority started and ended with the same characters.

www.theregister.com


06 July 2020

One out of every 142 passwords is '123456'


In one of the biggest password re-use studies of its kind, an analysis of more than one billion leaked credentials has discovered that one out of every 142 passwords is the classic "123456" string.

The study, carried out last month by computer engineering student Ata Hakçıl, analyzed username and password combinations that leaked online after data breaches at various companies.

These "data dumps" have been around for more than half a decade, and have been piling up as new companies are getting hacked. The data dumps are easily available online, on sites like GitHub or GitLab, or freely distributed via hacking forums and file-sharing portals.

Over the years, tech companies have been collecting these data dumps. For example, Google, Microsoft, and Apple, have collected leaked credentials to create in-house alert systems that warn users when they're utilizing a "weak" or "common" password.

Furthermore, the Have I Been Pwned online service also works on top of these leaked data dumps and credentials.

Please dear reader - take security seriously. Here are five things to know to hep you pick a good password.


21 January 2021

New Year, new password protections - in Chrome v88

Passwords help protect our online information, which is why it’s never been more important to keep them safe. But when we’re juggling dozens (if not hundreds!) of passwords across various websites—from shopping, to entertainment to personal finance—it feels like there’s always a new account to set up or manage. While it’s definitely a best practice to have a strong, unique password for each account, it can be really difficult to remember them all—that’s why we have a password manager in Chrome to back you up.

As you browse the web, on your phone, computer or tablet, Chrome can create, store and fill in your passwords with a single click. We'll warn you if your passwords have been compromised after logging in to sites, and you can always check for yourself in Chrome Settings. As we kick off the New Year, we’re excited to announce new updates that will give you even greater control over your passwords:

We’ve all had moments where we’ve rushed to set up a new login, choosing a simple “name-of-your-pet” password to get set up quickly. However, weak passwords expose you to security risks and should be avoided. In Chrome 88, you can now complete a simple check to identify any weak passwords and take action easily.

www.googleblog.com


17 December 2019

Google: turning off less secure app access to G Suite accounts

What’s changing: Starting in June 2020, we’ll limit the ability for less secure apps (LSAs) to access G Suite account data. LSAs are non-Google apps that can access your Google account with only a username and password. They make your account more vulnerable to hijacking attempts. Instead of LSAs, you can use apps that support OAuth—a modern and secure access method.

This is most likely to impact users of legacy email, calendar, and contacts apps—see below for more details. We’ve also emailed your organization’s primary admin with details around this change. That email includes a list of users who are likely to be affected.

Access to LSAs will be turned off in two stages:
1) After June 15, 2020 - Users who try to connect to an LSA for the first time will no longer be able to do so. This includes third-party apps that allow password-only access to Google calendars, contacts, and email via protocols such as CalDAV, CardDAV and IMAP. Users who have connected to LSAs prior to this date will be able to continue using them until usage of all LSAs is turned off. 
2) After February 15, 2021 - Access to LSAs will be turned off for all G Suite accounts. 

This is a continuation of our previously announced process to limit access to less secure apps to protect G Suite accounts. See below for more details on the possible impact of this change, and some recommendations for change management with users of LSAs.

Why this matters: Many users use non-Google apps, and give those apps permission to access G Suite data. For example, you may give the iOS mail app or Microsoft Outlook - permission to see your work email.  When account access is provided through an LSA, it puts that account at risk of hijacking. That’s because LSAs provide a non-Google app access to your account through just a username and password, without any other authentication factor.


01 June 2017

Password manager OneLogin hit by data breach


Encrypted information has been accessed during a data breach at the password management service, OneLogin.

It affects "all customers served by our US data centre" and perpetrators had "the ability to decrypt encrypted data", according to The Register.

Those affected have been advised to visit a registration-only support page, outlining the steps they need to take.

Security experts said the breach was "embarrassing" and showed every company was open to attack.

OneLogin is a single sign-on service, allowing users to access multiple apps and sites with just one password.

In 2013, the company had 700 business customers and passed 12 million licensed users.


18 January 2018

IT Security 101: don't put your password on a post-it note!


A photograph, taken by Associated Press back in July 2017, shows Hawaii Emergency Management Agency’s operations officer in front of a bank of computer screens at its headquarters in Honolulu. But if you look past the colourful Hawaiian shirt, and zoom in on the computers used to monitor potential hazards, you’ll see a solitary Post-it note - detailing their password!

To be honest, I've seen worse... No names, no pack drill, but years ago a director of a major company passed me a laptop case which had a laptop with installed corporate VPN software. Also in the bag were a smartcard reader, with the smartcard in it & the password on a post-it note stuck to the reader! This is literally everything required to externally breach a corporate network - at director level!

Post-it notes are great, but puhleaze - don't use them for passwords!!!