Article

Data Breach Highlights People’s Predilection for Weak Passwords

Jan 01, 0001

The recent news that the passwords and login credentials for approximately two million online accounts were stolen and posted online serves as a reminder of the importance of password security. The stolen credentials were for all kinds of user accounts, including those on Facebook, Google, Linkedin, Twitter, Yahoo and ADP payroll services.

December 2013 

By Mark Scott, J.D., CFE 

 

The recent news that the passwords and login credentials for approximately two million online accounts were stolen and posted online serves as a reminder of the importance of password security. The stolen credentials were for all kinds of user accounts, including those on Facebook, Google, Linkedin, Twitter, Yahoo and ADP payroll services.

 

The account credentials were harvested by a botnet, according to researchers at security firm Trustwave, who discovered the data while investigating the server that cyber criminals use to control the “Pony” botnet. A botnet is a network of Internet-connected computers that have been infected with malware that puts them under the command and control of a remote operator who uses the infected devices to carry out criminal activities.

 

Analysis of the Stolen Passwords  

The Trustwave researchers analyzed the compromised passwords to learn about the password habits of Internet users, and the analysis, like similar studies, demonstrated that many Internet users have poor password practices. In particular, the analysis revealed that many Internet users employ simple, predictable passwords, with the most common being “123456.” About half of the passwords contained only one character type, and many were derived from common keyboard patterns and swipes (e.g., 1234 and qwerty).

 

The following table depicts the top 10 passwords discovered by the Trustwave analysis.

 

Rank 

Password 

Number of Accounts with Password 

1

123456

15,820

2

123456789

4,875

3

1234

3,135

4

password

2,212

5

12345

2,094

6

12345678

2,045

7

admin

1,991

8

123

1,453

9

1

1,224

10

1234567

1,170

 

The fact that so many users choose simple, predictable passwords to protect their online accounts suggests that many people disregard — or lack awareness of — online security, and entrusting people to secure their accounts with strong, complex passwords does not work.

  

The Importance of Strong Passwords 

Strong passwords can help keep online accounts safe from hackers and scammers. Password strength is a measure of a password’s effectiveness in resisting various types of attacks, and generally, the strength of a password depends on its length and complexity. Thus, the shorter and more simple the password, the more susceptible it will be to attack.

 

What’s more, the problem of poor password security is compounded by the fact that many people use the same passwords for different accounts, meaning that one account breach translates into multiple account breaches.

 

Unfortunately, strong passwords are not without their drawbacks. Among other things, they are difficult to remember, and they do not improve security against keylogger, phishing, social engineering and shoulder surfing attacks. Even so, Internet users should strive to use strong passwords for each individual account.

 

Tips for Stronger Password Security 

Here are some tips for making passwords more secure:

 

Do not use the same password for multiple accounts.

Use unique passwords. Do not use passwords on any common password lists, such as SplashData’s annual list of worst Internet passwords.

Use passwords with a variety of character types (i.e., use passwords that contain upper and lowercase letters, numbers and special, non-alphanumeric characters). The more uncommon the combination of letters, numbers and symbols used in a password, the safer it will be.

Use passwords that are at least eight characters long. The longer the password, the stronger it will be.

Use password generators to create random passwords.

Do not use passwords that are based on personal information (e.g., birthday, Social Security number, nicknames, names of family members, etc.).

Do not use single dictionary words for passwords. Such passwords are susceptible to dictionary attacks.

Use passphrases instead of passwords.

Do not use passwords derived from strings of sequential numbers or letters (e.g., 123456 and qwerty).

Do not use standard number substitutions (e.g., p455word instead of password).

Use multifactor authentication when available. Facebook, Google, Microsoft and Twitter all offer multiple layers of authentication.

Change passwords periodically, especially for major accounts such as those for banking and shopping sites.

Keep computers and browsers patched, updated and malware free. 

  

Conclusion 

Poor password practices are nothing new. Users have bad habits when it comes to creating and managing passwords, and they often select simple and thus easy-to-crack passwords. And even if Internet users have the best intentions when it comes to password security, their actions typically do not follow suit, putting their accounts at increased risk for breach.

 

Nonetheless, massive breaches such as those caused by the Pony botnet highlight why it is so important for users to employ strong and unique passwords for their online accounts.