Tag: passwords

Google: Change your passwords!

google-ICSearch engine behemoth Google advised users of its Gmail email software to change their passports after a Russian website was hacked.

Apparently five million passwords were hacked from a Russian site called Bitcoin Security with people from the UK, Spain and Russia.

It’s not entirely clear what all those passwords were doing on the Russian site in the first place.

Google said it was advising folk to set up two step verification on their accounts.

A representative said Google had no evidence that its own servers had been compromised.

The passwords relate not only to Gmail but other Google services.

Half of users share their passwords

face-palmMore than half of users risk their computer being hacked because they share their passwords or sign up for automatic log on to mobile apps and services.

Research by security outfit Intercede said that while more than half of users thought security was important they putting their personal data at risk by sharing usernames and passwords with friends, family and colleagues.

The survey of 2,000 consumers also questioned whether these passwords are strong enough to protect consumers’ applications and the data they hold.

Half of respondents stated that they try and remember passwords rather than writing them down or using password management solutions, suggesting that consumers are relying on easy to remember combinations and using the same password across multiple sites and devices.

Richard Parris, CEO of Intercede said that we need so many passwords today, for social networking, email, online banking and a whole host of other things, that it’s not surprising consumers are taking shortcuts with automatic log ins and easy to remember passwords.

The research revealed that consumers are not only sharing passwords but also potentially putting their personal and sensitive information at risk by leaving themselves logged in to applications on their mobile devices, with over half of those using social media applications and email admitting that they leave themselves logged in on their mobile device.

Parris said that consumers are also compromising their bank and credit card details by selecting ‘Remember me’ or ‘Keep me signed in’ options.

Of those that use Amazon and other shopping sites, 21 per cent said they were automatically logged in, while the figures stood at 16 per cent for mobile banking and 12 per cent for PayPal.

Google: Pets are most popular passwords

google-ICGoogle commissioned a survey of 2,000 adults – and one in ten said they could accurately guess a colleague’s password. Probably because the most popular passwords are, according to the research, easy guesses.

Wedding anniversaries, birthdays and kids’ names were all top choices for passwords, while football teams and the word ‘password’ also appeared a fair few times. Indeed – ‘password’ was tenth most popular.

Shockingly, half of web users surveyed admitted to sharing their passwords with other people. Women, the survey found, were more likely than men to share their password, and twice as likely to share it with their children.

But the most chosen password was the name of a pet. Favourite holidays or place of birth were also frequently chosen – the kind of passwords that would also be answers to security questions.

Given that it is often social engineering tricks or the simple human gaffe that leads to compromised security, this is a security nightmare.

“People often leave their information open to online security breaches without even realising it,” director of security for Google Apps, Eran Feigenbaum, told the Telegraph. “Lax attitudes to online security can lead to serious consequences
if strangers access your information.”

Speaking with ChannelEye, security expert Graham Cluley said it’d sadly be no surprise if the research was accurate.

“It never ceases to amaze me how – despite all the high profile hacks and data breaches – people still haven’t learnt the most basic lesson about passwords,” Cluley said. “Of if they have, they’ve decided to ignore it because it’s ‘too difficult’ to remember tricky passwords, let alone different passwords for different websites”.

As with other calls from the UK’s security pundits, companies, consumer action groups, and Cluley himself, he said it’s easy to imagine the positive impact  of a public education campaign.

It could explain that “password management software exists, often for free, which will remember all your passwords for you, and generate new, complex passwords so you don’t end up using ‘Tiddles’ over and over again,” Cluley said.