Showing posts sorted by relevance for query passwords. Sort by date Show all posts
Showing posts sorted by relevance for query passwords. Sort by date Show all posts

18 November 2022

Online security experts discuss why the future of passwords is no passwords.

 

Watch a short video featuring online security experts from CISA, FIDO Alliance, Google, and Microsoft. These experts highlight why the future of passwords is no passwords – with FIDO.

FIDO Authentication: The FIDO Alliance is involved in three areas to work towards achieving its mission to reduce the world’s reliance on passwords to better secure the web: user authentication; identity verification and binding; and the Internet of Things (IoT). The work areas address essential aspects of the digital identity lifecycle management including identity verification for initial account onboarding and account recovery, and user and device authentication.

FIDO Authentication: Passwords endure despite the growing consensus their use needs to be reduced, if not replaced. But even though effective PKI and strong authentication solutions have existed for years, barriers to widespread adoption persist. Consumers don’t like the user experience, and online service providers don’t want the cost and complexity of developing and provisioning their own dedicated solutions.

The industry’s answer to the password problem: The FIDO Alliance developed FIDO Authentication standards based on public key cryptography for authentication that is more secure than passwords and SMS OTPs, simpler for consumers to use, and easier for service providers to deploy and manage. FIDO Authentication enables password-only logins to be replaced with secure and fast login experiences across websites and apps.

www.fidoalliance.org


11 April 2023

Terrifying study shows how fast AI can crack your passwords

 

Along with the positive aspects of the new generative AI services come new risks. One that’s surfaced is an advanced approach to cracking passwords called PassGAN. Using the latest AI, it was able to compromise 51% of passwords in under one minute with 71% of passwords cracked in less than a day. 

Last month, Microsoft brought attention to the security concerns that will come with the quick advancement of AI by announcing its new Security Copilot suite that will help security researchers protect against malicious use of modern technology.

Now Home Security Heroes has published a study showing how scary powerful the latest generative AI is at cracking passwords. The company used the new password cracker PassGAN (password generative adversarial network) to process a list of over 15,000,000 credentials from the Rockyou dataset and the results were wild:

51% of all common passwords were cracked in less than one minute, 65% in less than an hour, 71% in less than a day, and 81% in less than a month.

To stay safe: stick with at least 12 characters with a mix of upper, and lowercase letters plus numbers. Never reuse passwords - a unique one per service / account. Need help securing your accounts? Contact Donline.


21 January 2021

New Year, new password protections - in Chrome v88

Passwords help protect our online information, which is why it’s never been more important to keep them safe. But when we’re juggling dozens (if not hundreds!) of passwords across various websites—from shopping, to entertainment to personal finance—it feels like there’s always a new account to set up or manage. While it’s definitely a best practice to have a strong, unique password for each account, it can be really difficult to remember them all—that’s why we have a password manager in Chrome to back you up.

As you browse the web, on your phone, computer or tablet, Chrome can create, store and fill in your passwords with a single click. We'll warn you if your passwords have been compromised after logging in to sites, and you can always check for yourself in Chrome Settings. As we kick off the New Year, we’re excited to announce new updates that will give you even greater control over your passwords:

We’ve all had moments where we’ve rushed to set up a new login, choosing a simple “name-of-your-pet” password to get set up quickly. However, weak passwords expose you to security risks and should be avoided. In Chrome 88, you can now complete a simple check to identify any weak passwords and take action easily.

www.googleblog.com


07 November 2025

You'll never guess what the most common passwords are. Oh, wait, yes you will

123456. admin. password. For years, the IT world has been reminding users not to rely on such predictable passwords. And yet here we are with another study finding that those sorts of quickly-guessable, universally-held-to-be-bad passwords are still the most popular ones.

Tech advice website Comparitech on Thursday published the 100 most common passwords based on a deep dive into more than two billion passwords leaked on breach forums in 2025. 

The three mentioned above all finish in the top ten, along with various variations of the numerals 1-9 in ascending sequential order. 

Puh-leaze, don't do this! Have a look here to get some useful tips on how to secure your credentials - or contact Donline.

www.theregister.com


06 May 2020

We beg, implore and beseech thee. Stop reusing the same damn password everywhere!


Two-thirds of people recycle the same password or use variations on the same basic one, according to LogMeIn.

Even though more than 90 per cent of people surveyed by the password manager biz said they knew it was risky to recycle passwords or light variations on a theme, 66 per cent of respondents admitted they "always or mostly use the same password or a variation".

These findings came from LogMeIn's Psychology of Passwords report, released recently, that quizzed 3,250 people and discovered that half of them across the world hadn't changed their passwords over the past 12 months "even after hearing about a breach in the news".

Depressingly, that number rose to 58 per cent for Britons specifically who did not change their passwords after reading about a breach on the news. A whopping 92 per cent of Brits reuse passwords despite being aware of the risks.

Click here to find out more about the risks in poor password hygiene, and advice on how to stay safe.


07 May 2020

Protecting your organisation against password spray attacks


When hackers plan an attack, they often engage in a numbers game. They can invest significant time pursing a single, high-value target—someone in the C-suite for example and do “spear phishing.” Or if they just need low-level access to gain a foothold in an organization or do reconnaissance, they target a huge volume of people and spend less time on each one which is called “password spray.” Last December Seema Kathuria and I described an example of the first approach in Spear phishing campaigns—they’re sharper than you think! Today, I want to talk about a high-volume tactic: password spray.

In a password spray attack, adversaries “spray” passwords at a large volume of usernames. When I talk to security professionals in the field, I often compare password spray to a brute force attack. Brute force is targeted. The hacker goes after specific users and cycles through as many passwords as possible using either a full dictionary or one that’s edited to common passwords. An even more targeted password guessing attack is when the hacker selects a person and conducts research to see if they can guess the user’s password—discovering family names through social media posts, for example. And then trying those variants against an account to gain access. Password spray is the opposite. Adversaries acquire a list of accounts and attempt to sign into all of them using a small subset of the most popular, or most likely, passwords. Until they get a hit. This blog describes the steps adversaries use to conduct these attacks and how you can reduce the risk to your organisation.

Three steps to a successful password spray attack:
Step 1: Acquire a list of usernames
Step 2: Spray passwords
Step 3: Gain access


22 April 2019

Millions of people STILL using 123456 as password, security study finds!


The UK's National Cyber Security Centre (NCSC) has today published analysis of the 100,000 most commonly re-occurring passwords that have been accessed by third parties in global cyber breaches. The results show a huge number of regularly used passwords breached to access sensitive information.

The NCSC hope to reduce the risk of further breaches by building awareness of how attackers use easy to guess passwords, or those obtained from breaches and help guide developers and System Administrators to protect their users.

The compromised passwords were obtained from global breaches that are already in the public domain having been sold or shared by hackers.

The list was created after breached usernames and passwords were collected and published on Have I Been Pwned by international web security expert Troy Hunt. The website allows people to check if they have an account that has been compromised in a data breach.


27 September 2018

Another security breach: NewsNow. Another reason not to reuse passwords!


Online news aggregation service NewsNow has admitted that it has suffered a security breach.

It’s a shame that they didn’t include more technical details on how the passwords are stored, even if only for those readers who might understand them.

What is clear is that you should ensure that you are not using the password you were using on NewsNow anywhere else on the web.

Furthermore, NewsNow appears to be so burnt by the experience that it has decided it never wants to store passwords (hashed or otherwise) again.

In an age of “toxic data”, the site has declared that it has revamped its login system. In future users will simply enter their email address into a form, and will then need to wait for a message to be sent to their email address containing a link that will log them into the NewsNow system.

So, puhleaze: choose your passwords carefully, no simple ones, complexity is the key, and no reuse of passwords either! 
If you need help: contact Donline.


13 May 2019

Windows Hello FIDO2 certification gets you closer to password-less computing


With the FIDO2 certification of Windows Hello, Microsoft is putting the 800 million people who use Windows 10 one step closer to a world without passwords.

No one likes passwords (except hackers). People don’t like passwords because we have to remember them. As a result, we often create passwords that are easy to guess—which makes them the first target for hackers trying to access your computer or network at work.

Since 2015, Microsoft has been building a path to a secure and passwordless world with Windows Hello, enabling Windows 10 users everywhere to sign in to their devices using biometrics or a PIN and leave the world of passwords behind. Continuing this momentum, Microsoft announced in November of 2018 the ability to use Windows Hello or a FIDO2 security key to securely sign in to your Microsoft account on the web, without a password!

Today, the FIDO Alliance announced that, with the upcoming release of Windows 10, version 1903, Windows Hello is a FIDO2 Certified authenticator. FIDO2 enables developers to leverage standards-based protocols and devices to provide users easy authentication to online services—in both mobile and desktop environments. Microsoft is a leading member of the FIDO Alliance and is working closely with alliance members to enable passwordless login for websites supporting FIDO2 authentication. Collectively, these standards enable users to more easily and securely login to online services with FIDO2-compliant security keys and Windows Hello.


29 August 2018

No, eight characters, some capital letters and numbers is not a good password policy


Bad passwords are one of those problems that never goes out of fashion, and sure enough, in a recent audit (26 per cent) of  Active Directory passwords were found to be somewhere between easily guessed and downright lamentable.

Among these, ‘Password123’ was in use by 1,464 accounts, ‘Project10’ by 994, ‘support’ by 866, ‘password1’ by 813, and ‘October2017’ by 226, to pick only the top five worst offenders in popularity order.

In one particularly epic fail, the auditors said they were able to remotely access a test environment for the agency’s web system using the password ‘Summer123’.

So, puhleaze: choose your passwords carefully, no simple ones, complexity is the key, and no reuse of passwords either! If you need help: contact Donline.


02 May 2018

Microsoft: Here's our plan for getting rid of passwords forever


Microsoft wants to create a world in which passwords are replaced with other secure user credentials that cannot be breached.

The Windows 10 April 2018 Update in S mode allows cloud users an end-to-end experience that does not require any passwords.

Microsoft is doubling down on its promise to rid the world of passwords and replace them with more convenient and secure options, the company announced in a Tuesday blog post.


25 November 2022

Guess the most common password. Hint: We just told you

NordPass has released its list of the most common passwords of 2022. Topping the list of the most common passwords was, sadly, "password," followed by "123456" and its more secure relative "123456789," "guest," "qwerty" and lots more you can definitely figure out without needing the help of a cracking tool.

Seriously, few of the passwords in this list are even words: Most are just repetitions of a single character, sequences of easy-to-guess numbers, a straight run down a row of keys, or basic combinations like "pass@123." 

Along with a depressingly basic list of common passwords and the speed it takes to crack them (most are listed as < 1 second), NordPass shared some statistics about what's trending in the password world, like the word "Oscars," which pops up especially around award season, as well as "batman," "euphoria" and "encanto" after the eponymous films and TV series that have been popular this year.

FYI: here are five things to know to pick a good password.

www.theregister.com


19 November 2020

Some people never learn - behold the poopie password top ten

 

It's that time of year again -- when we see whether or not password security has improved over the past 12 months. Going back to 2015, the worst passwords still commonly used included "123456" and "password." Fast forward five years, and these examples are still very much alive. 

After analyzing 275,699,516 passwords leaked during 2020 data breaches, NordPass and partners found that the most common passwords are incredibly easy to guess -- and it could take less than a second or two for attackers to break into accounts using these credentials. Only 44% of those recorded were considered "unique."

On Wednesday, the password manager solutions provider published its annual report on the state of password security, finding that the most popular options were "123456," "123456789," "picture1," "password," and "12345678."

OK 1-9 are obviously terrible passwords, but what is #10: "senha"? It is a Portuguese word which means, yes you guessed it: "password"!

www.zdnet.com


06 May 2022

Google, Apple, Microsoft promise end to passwords, courtesy of your mobile phone

A future without passwords may be closer than we think, at least when a new initiative to enlist your smartphone as a mobile authenticator gets off the ground.

On Thursday, the FIDO Alliance - announced a new type of authentication that would use passkeys stored on your phone to unlock your online accounts without requiring a password. Google, Apple and Microsoft are all on board with the new method and have promised that their respective operating systems will support this technology.

Passwords have always been a poor way to secure our accounts. We’re constantly told to create a strong, complex and unique password for each account. But that’s a difficult task, leading many people to use weak and repetitive passwords, which can easily be compromised and used in data breaches and account takeovers. Such tools as password managers have provided some relief but still chain us to this clumsy and ineffective means of authentication.

With support from Google, Apple and Microsoft, the new authentication method will store a FIDO-based passkey on your mobile phone. That key will be encrypted to protect it from compromise and will be accessible only when you unlock your phone. When you try to sign into an app or website either on the phone itself, a nearby computer or other device, that passkey will automatically log you in regardless of the operating system or browser and without you having to enroll or re-enroll your device. If you switch to a new phone, your passkey will make the trip with you.

www.techrepublic.com


29 April 2019

Microsoft says expiring passwords are no longer secure


Microsoft will scrap its archaic password expiration policies in the upcoming Windows 10 May 2019 update to encourage organisations to implement more contemporary and effective security measures.

The update will apply to Windows 10 version 1903 and Windows Server version 1903 and to replace the time-based periodic password expirations, organisations should set up.

The company explained that if customers are required to change their password regularly, they are more likely to write down the passwords so they don't forget them and this could mean that others can quite easily get their hands on them, increasing the likelihood of them being stolen.

Microsoft also noted that if people are asked to change their passwords often, they probably will only make very small changes and thus they won't be particularly secure. They are also more likely to forget their passwords and will have to reset them, affecting user experience and loyalty.


04 May 2018

Have a Twitter account? Now is a good time to reset your password


When you set a password for your Twitter account, we use technology that masks it so no one at the company can see it. We recently identified a bug that stored passwords unmasked in an internal log. We have fixed the bug, and our investigation shows no indication of breach or misuse by anyone.

Out of an abundance of caution, we ask that you consider changing your password on all services where you’ve used this password. You can change your Twitter password anytime by going to the password settings page.

About The Bug: We mask passwords through a process called hashing using a function known as bcrypt, which replaces the actual password with a random set of numbers and letters that are stored in Twitter's system. This allows our systems to validate your account credentials without revealing your password. This is an industry standard.

Due to a bug, passwords were written to an internal log before completing the hashing process. We found this error ourselves, removed the passwords, and are implementing plans to prevent this bug from happening again.


19 May 2022

The passwords most used by CEOs are startlingly dumb

A recent cybersecurity report shows how immensely idiotic many CEOs and business owners can be, considering the strength of their chosen account passwords. Imagine entrusting the livelihood of hundreds, even thousands of employees to someone who uses '123456' or 'qwerty' as a password.

The research comes from NordPass password manager which identified back in 2020 that the general public's most commonly used passwords were sequential numbers like '123456', 'picture1', and yep, you guessed it: 'password'.

The more recent research sample consists of 290 million cybersecurity data breaches around the globe, and denotes the job level of those affected. Turns out, when it comes to CEOs and other high-ranking businesses execs, their password choices are much the same as the general public, although many often feature names. Tiffany was spotted in 100,534 breaches; then there was Charlie with 33,699; Michael was found 10,647 times; and Jordan, 10,472 times.

The research is pretty worrying, and makes it painfully clear that most data breaches don't happen because of some profound cyber hacking initiative; around 80% are down to people choosing really poor passwords.

Read the above? Now - how to do it properly: 5 Top Tips to pick a secure password.

www.pcgamer.com


11 October 2017

Malicious iOS app popup windows could be stealing your Apple ID


Cybercriminals have a surefire way to steal Apple ID credentials: Just ask users to provide them.

A blog post by software engineer and fastlane founder Felix Krause reveals that it's dead simple to spoof iOS popups that ask for Apple ID passwords. What makes it worse, Krause said, is that we're trained to put in passwords for a variety of reasons in a variety of apps.

The average user won't question the legitimacy of an Apple ID password request, which makes the spoof a very dangerous form of phishing. All an app needs to do is show a UIAlertController popup—an incredibly common part of an app.

As impossible as it may be for a user to tell the difference between a fake and legitimate dialog window there are still things that iOS users can do to protect themselves.
  • If you get a popup asking for a password inside an app, hit the home button. If you can quit back to the home screen it's not a legitimate request. Real system dialogs that ask for passwords are run as a separate process and can't be quit in that fashion.
  • Treat password requests inside apps like you would a link in an email—don't use it. Instead, open the Settings app and put the password in there, similar to going directly to a website that wants you to verify your information.
  • Don't type anything into a password-requesting popup. Even if you press the cancel button the information has already been captured.


31 August 2016

Dropbox users are being advised to change their passwords


Earlier this year, reports first began to appear that a historic data breach at Dropbox may have exposed tens of millions of user passwords, after a file claiming to contain approximately 100 million Dropbox account details was made available for anyone to download.

Dropbox has confirmed to the media that a 5GB archive of files, containing the email addresses and hashed passwords for some 68,680,741 accounts, is genuine.


25 July 2019

Synology urges all users to take immediate action to protect data from ransomware attack



TAIPEI, Taiwan - July 23, 2019 Synology recently found that several users were under a ransomware attack, where admins' credentials were stolen by brute-force login attacks, and their data was encrypted as a result. We investigated and found that the causes of these attacks were due to dictionary attacks instead of specific system vulnerabilities. This large-scale attack was targeted at various NAS models from different vendors; therefore we strongly recommend users check network and account settings to protect data from ransomware.

"We believe this is an organized attack. After an intensive investigation into this matter, we found that the attacker used botnet addresses to hide the real source IP," said Ken Lee, Manager of Security Incident Response Team at Synology Inc. "After collecting admin account passwords with brute-force attacks, the attack was launched on July 19 and caught users off guard. We therefore informed TWCERT/CC and CERT/CC immediately of this matter in hopes of accelerating the collaborative efforts to resolve this incident."

Since this attack is not related to system security vulnerabilities, it is recommended that Synology users utilize built-in network and account management settings to enhance system security level, preventing malicious attacks from the Internet.

"We urge all Synology users to take immediate action to protect their NAS from the ransomware attack," said Hewitt Lee, Director of Product Management at Synology Inc. "Users' data security is always our priority. For those who are not using Synology NAS, we still recommend you take corresponding actions to protect your precious data."

Synology are a great company with fantastic NAS devices. However, any piece of IT is only as secure as it's weakest link. Use a trivial password & expect to lose control of your device and data! ALWAYS use complex passwords & never reuse passwords!