Stories
Slash Boxes
Comments

SoylentNews is people

posted by martyb on Friday December 13 2019, @03:11PM   Printer-friendly
from the https://xkcd.com/936/ dept.

49% of workers, when forced to update their password, reuse the same one with just a minor change:

A survey of 200 people conducted by security outfit HYPR has some alarming findings.

For instance, not only did 72% of users admit that they reused the same passwords in their personal life, but also 49% admitted that when forced to update their passwords in the workplace they reused the same one with a minor change.

Furthermore, many users were clearly relying upon their puny human memory to remember passwords (42% in the office, 35% in their personal lives) rather than something more reliable. This, no doubt, feeds users' tendency to choose weak, easy-to-crack passwords as well as reusing old passwords or making minor changes to existing ones.

What is so bad about changing "Password1" to "Password2"?


Original Submission

 
This discussion has been archived. No new comments can be posted.
Display Options Threshold/Breakthrough Mark All as Read Mark All as Unread
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
  • (Score: 5, Informative) by barbara hudson on Friday December 13 2019, @04:35PM

    by barbara hudson (6443) <barbara.Jane.hudson@icloud.com> on Friday December 13 2019, @04:35PM (#931741) Journal
    Current bullshit password "best practices" reduce security.

    When you know the user needs to use at least 1 digit, and 1 special character, you've eliminated the need to check all alpha-only passwords.

    Second, because so many people need password resets, it's easier to convince the keepers of the keys to reset a password via social engineering - hence the epidemic of identity theft.

    Biometrics? Fingerprint readers don't actually compare fingerprints- they generate a number based on a small number of features of a fingerprint. Doesn't work if you don't have well defined features, like mine. We tried registering my fingerprint on a time clock for weeks. Never worked. I deleted my bank app when they needed fingerprint I'd because I don't want to get locked out by 10 failures of verification.

    And we all know facial ID also can be easily compromised.

    Only physical security can be trusted- anything else is smoke and mirrors.

    --
    SoylentNews is social media. Says so right in the slogan. Soylentnews is people, not tech.
    Starting Score:    1  point
    Moderation   +3  
       Insightful=1, Informative=2, Total=3
    Extra 'Informative' Modifier   0  
    Karma-Bonus Modifier   +1  

    Total Score:   5