Beehaw
  • Communities
  • Create Post
  • search
    Search
  • Login
  • Sign Up
 tfm   ( @tfm@europe.pub )  to Privacy@lemmy.mlEnglish · 9 months ago

Hackers know half of passwords entered online, Cloudflare finds

cybernews.com

external-link
message-square
14
link
fedilink
58
external-link

Hackers know half of passwords entered online, Cloudflare finds

cybernews.com

 tfm   ( @tfm@europe.pub )  to Privacy@lemmy.mlEnglish · 9 months ago
message-square
14
link
fedilink
Attention Required! | Cloudflare
cybernews.com
external-link
alert-triangle
You must log in or # to comment.
  •  flatbield   ( @furrowsofar@beehaw.org ) 
    link
    fedilink
    English
    arrow-up
    40
    ·
    9 months ago

    I wonder how much of this stems from two stupid IT policies. For decades users have been told to not write down passwords and to change them regularly. The result of this policy is to use a small number of password variations that one reuses. Then IT complaims about it.

    The better plan has always been to use long random passwords that you never reuse and write them down by some method like a password manger and only change them rarely for example when they may be compromised,

    •  HubertManne   ( @HubertManne@piefed.social ) 
      link
      fedilink
      English
      arrow-up
      7
      ·
      9 months ago

      I remember asking my company if they have official password management software in my job before my last job. They did not. I can’t believe we have all this specific software to be used at the company but they don’t put some time to identify what they want employees to use for this. Funny thing is security teams are such big deals but I think they actually don’t want to get involved in case it does not work out.

      •  flatbield   ( @furrowsofar@beehaw.org ) 
        link
        fedilink
        English
        arrow-up
        2
        ·
        9 months ago

        Lot of security is theater. IT doing a CYA thing.

    •  psud   ( @psud@aussie.zone ) 
      link
      fedilink
      English
      arrow-up
      5
      ·
      9 months ago

      My workplace has finally gone to passphrases and 1 year password life, which is nice as it’s a password I often need to type, so I’d rather 20 easy to type and memorise chars than 16 random

      •  flatbield   ( @furrowsofar@beehaw.org ) 
        link
        fedilink
        English
        arrow-up
        2
        ·
        edit-2
        9 months ago

        The missleading thing about passphrases is that anything a human can remember is low entropy. That it has 20 charachers says nothing about how random.

        Edit: I also wonder how much randomness is really needed. Properly salted and hashed passwords shoud not need that much randomness. Lot of this is about users just choosing bad passwords, reusing, and IT not properly salting and hashingon their end.

        •  psud   ( @psud@aussie.zone ) 
          link
          fedilink
          English
          arrow-up
          3
          ·
          9 months ago

          Are you sure you can’t make a high entropy memorable password?

          My scheme pulls four words at random from a large corpus

          •  flatbield   ( @furrowsofar@beehaw.org ) 
            link
            fedilink
            English
            arrow-up
            1
            ·
            9 months ago

            Just compare the number of possibilities. Number of words to the 4th power to 94 to the 15th power. Your corpus would have to be 25 million words. In contrast, there are about 800K words in the english language and about 1000 commonly used words.

  •  shortwavesurfer   ( @shortwavesurfer@lemmy.zip ) 
    link
    fedilink
    arrow-up
    15
    ·
    9 months ago

    I’m glad I’ve been using a password manager for several years now.

    •  mac   ( @mac@lemm.ee ) 
      link
      fedilink
      arrow-up
      7
      ·
      9 months ago

      Yeah I think I’ve got 600 distinct logins in my bitwarden at this point, lol.

      •  flatbield   ( @furrowsofar@beehaw.org ) 
        link
        fedilink
        English
        arrow-up
        5
        ·
        9 months ago

        This is a great example of how impossible it is not write down usernmes and passwords and how infeasible forcing changes is.

        The other thing people do not talk about enough is user names. They should be somewhat random too and not reused. Forcing people to use their email address is particularly stupid but very common.

        •  mac   ( @mac@lemm.ee ) 
          link
          fedilink
          arrow-up
          3
          ·
          9 months ago

          Yep, before I switched to a password manager in college I had 3-4 passwords I would use across all accounts, and I would constantly need to recover accounts because I would forget the PW.

          I actually don’t remember the last time I needed to recover an account. Having a password manager has been a massive time savings for me.

  •  nothacking   ( @nothacking@discuss.tchncs.de ) 
    link
    fedilink
    arrow-up
    12
    ·
    9 months ago

    https://xkcd.com/936/

  •  UltraGiGaGigantic   ( @UltraGiGaGigantic@lemmy.ml ) 
    link
    fedilink
    English
    arrow-up
    10
    ·
    9 months ago

  •  huquad   ( @huquad@lemmy.ml ) 
    link
    fedilink
    English
    arrow-up
    5
    ·
    9 months ago

    Always two there are. No more, no less. The one they know, and the one they don’t.

Privacy@lemmy.ml

privacy@lemmy.ml

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !privacy@lemmy.ml

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

  • Posting a link to a website containing tracking isn’t great, if contents of the website are behind a paywall maybe copy them into the post
  • Don’t promote proprietary software
  • Try to keep things on topic
  • If you have a question, please try searching for previous discussions, maybe it has already been answered
  • Reposts are fine, but should have at least a couple of weeks in between so that the post can reach a new audience
  • Be nice :)

Related communities

  • Lemmy.ml libre_culture
  • Lemmy.ml privatelife
  • Lemmy.ml DeGoogle
  • Lemmy.ca privacy

much thanks to @gary_host_laptop for the logo design :)

Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 47 users / day
  • 560 users / week
  • 2.78K users / month
  • 7.49K users / 6 months
  • 831 local subscribers
  • 43.7K subscribers
  • 3.86K Posts
  • 49K Comments
  • Modlog
  • mods:
  •  k_o_t   ( @k_o_t@lemmy.ml ) 
  •  tmpod   ( @tmpod@lemmy.pt ) 
  •  Yayannick   ( @Yayannick@lemmy.ml ) 
  •  ranok   ( @ranok@sopuli.xyz ) 
  • BE: 0.19.13
  • Modlog
  • Legal
  • Instances
  • Docs
  • Code