Home | Cyber Crime | No Easy Answers to Password Problems

No Easy Answers to Password Problems

Font size: Decrease font Enlarge font
Share

Even "strong" passwords have big weaknesses, so companies serious about security ought to rely on additional methods of authentication.

When hackers breached the servers of Sony Pictures in June, they cast a harsh light on one of the Web's most bedeviling security problems: passwords. After finding that a million user passwords for three Sony sites were stored without encryption, the intruders posted them online for anyone to see.

Security researcher Troy Hunt pored over the file and found that half of the passwords could be considered weak because they had a low degree of randomness—they had only lowercase letters, only uppercase letters, or only numbers. More than a third of the passwords could have been found in a dictionary and easily guessed by a password cracker, a tool that quickly tries different words and word combinations. Half the passwords were seven characters or less. Finally, the researcher found 90 e-mail accounts that had also shown up in another leaked password file, from Gawker.com, and discovered that about two-thirds of those users had the same password at both sites. "It indicates to me that this was a normal practice for people to plug in the same password into their accounts," says Hunt, a software architect who studies security. More...

Rate this article:
0
  • email Email to a friend
  • print Print version
  • Plain text Plain text

Comments (30 posted):

reseller hosting on 07/06/11 07:05:00
avatar
finding that a million user passwords for three Sony sites were stored without encryption, the intruders posted them online for anyone to see.
aidandtrade scam on 07/07/11 12:09:29
avatar
This is an interesting blog, i like the post.......
Wholesaler on 07/08/11 02:51:09
avatar
There are thousands of hackers available online for hacking your account . so always use a safe password.
Bingo Bonus on 07/17/11 10:50:38
avatar
There is no excuse for those companies not to encrypt our passwords. Why would they need to know our password and safe it unencrypted? Do they have other plans with it? Or are the companies just incompetent when it is about security?
juicy couture tracksuits on 07/31/11 06:09:37
avatar
Very good article, thanks author's share.
Flash Website Templates on 08/07/11 10:20:14
avatar
Nice Post! It is very difficult to have security that can be breached, hackers are mastering in all the bits.
Christian Louboutin Luxury Heels on 08/21/11 04:06:54
avatar
My dear friends, do you want to be more sexy in people's eyes? Just come in, please!
We are international trade that specializes in the <a href="http://www.heelsvogue.com"title="http://www.heelsvogue.com"> Christian Louboutin Shoes</a>. Christian Louboutin is your best choice! Our products are authentic quality with original box. <a href="http://www.heelsvogue.com"title="http://www.heelsvogue.com">Discount Christian Louboutin </a>will cost you less money. So, please don’t hesitate, just contact us for details ! We will be your reliable business partner!
Welcome to our website:==http://www.heelsvogue.com== Thank you!
web design company on 09/04/11 10:16:59
avatar
Timely updates from your blog will be very useful since I’m always on the lookout for do follow blogs.
virtual dedicated server on 09/27/11 07:36:36
avatar
Recently technology has become a part in our life because every days used in twitter and face book social site open daily then no easy answer to password problem. that can be able to understand properly.
buy essay on 10/06/11 03:24:35
avatar
You put them in a situation where something is running from them, like a dog or a child, and that instinct could kick right in,”
Home Security on 10/09/11 05:02:28
avatar
The postings are very unique and also out standing performance with the new creativity and excellency with the new different ideas and concepts.Really I am waiting for some more new posts from you.Keep up your excellency and efficiency in this same levels
Credit Calculators on 10/16/11 05:37:21
avatar
good article, thanks author's share.
sperm banks on 11/02/11 01:36:33
avatar
This problem is increase now day it is bad sectors and happens in to the cyber cafe.
<a href="http://holisticdrugrehab.net/">Florida holistic drug rehab</a> on 11/08/11 02:35:55
avatar
This affects not only simple people but also the bussiness men.
lexington law on 11/09/11 07:35:46
avatar
Use Roboform to manage your passwords.
Alarm Monitoring Atlanta on 11/15/11 05:12:15
avatar
Your blog article is very interesting and fanatic, at the same time the blog theme is unique and perfect, great job. To your success, one of the more impressive blogs I've seen. Thanks so much for keeping the internet classy for a change.
How to register a domain on 11/16/11 09:45:15
avatar
Really you have sharing informative news here.keep sharing the more information like this
gout remedies on 11/24/11 11:27:33
avatar
a million user passwords for three Sony sites were stored without encryption,
bed on 11/30/11 08:37:01
avatar
Normally sites provide safety on the basis of password. Hackers find it easy to get password. There must be some more information regarding security.
Seo Services on 12/04/11 02:59:51
avatar
Nice post.....
Miele Ecoline on 12/09/11 03:22:51
avatar
Hacking password is a major problem. The more technical solutions are innovated, the more hacking techniques are found. This blog is so informative. Keep sharing such information.
golden gate estates fl real estate on 12/11/11 02:24:00
avatar
I always change my password like once a month for certain reasons, but only for very important accounts. I can never risk the security of those, ever. Hackers and viruses are right around the corner.
News Stock Market on 12/19/11 07:32:24
avatar
Thanks for sharing.
free casino games on 12/21/11 08:18:25
avatar
I was just checkin’ out this blog and I really like the foundation of the article, and have nothing to do, so if anyone wants to have an compelling chat about it, please contact me on AIM, my name is lisa oiutale.!!
avatar
Well, I'm so delighted that I have found your post because I have been seeking some information regarding it for nearly 3 hours.
Richard F. Sands on 02/08/12 02:34:15
avatar
You’re the best, beautiful site with great informational content. This is a really interesting and informative post.
WebDesign on 03/03/12 07:46:35
avatar
Really good post i am gonna repost it

http://www.webagents.in
Trade Show Booths on 03/19/12 03:28:11
avatar
I agree password protection is a big problem. However, to be honest its very hard to have multiple passwords and be able to remember them all for each site that you login at.
buy rolex daytona on 03/19/12 11:55:58
avatar
It's so nice to visit here a nice article.Am so impressed with your such a good hard work,it's definitely a good and different idea for others,your guys are doing good work.Good luck,keep it up...[url=http://www.swisswatchuk.co.uk/swiss-replica-rolex-daytona-cb4.html]buy rolex daytona[/url]
Tim on 04/18/12 01:05:00
avatar
Yup sure is difficult.
Hackers are a big threat to our lives since we live most of it online

Post your comment comment

Please enter the code you see in the image:

Access restricted articles free
TheSafetyChannel
To show your safety related video, Contact Us.
Protecting public health through food safety and defence.
What Simon says about...


Monthly Newsletter
Email:
Supporting SafetyIssues
If you support this website, please consider making a donation and help us continue providing this free service.
Please consider making a donation
Tags
No tags for this article