Jump to content
Ban Hammer

If Your Password Is 123456, Just Make It HackMe

 Share

18 posts in this topic

Recommended Posts

Filed: Citizen (apr) Country: Brazil
Timeline

Back at the dawn of the Web, the most popular account password was "12345."

Today, it's one digit longer but hardly safer: "123456."

Despite all the reports of Internet security breaches over the years, including the recent attacks on Google's e-mail service, many people have reacted to the break-ins with a shrug.

According to a new analysis, one out of five Web users still decides to leave the digital equivalent of a key under the doormat: they choose a simple, easily guessed password like "abc123," "iloveyou" or even "password" to protect their data.

"I guess it's just a genetic flaw in humans," said Amichai Shulman, the chief technology officer at Imperva, which makes software for blocking hackers. "We've been following the same patterns since the 1990s."

Mr. Shulman and his company examined a list of 32 million passwords that an unknown hacker stole last month from RockYou, a company that makes software for users of social networking sites like Facebook and MySpace. The list was briefly posted on the Web, and hackers and security researchers downloaded it. (RockYou, which had already been widely criticized for lax privacy practices, has advised its customers to change their passwords, as the hacker gained information about their e-mail accounts as well.)

The trove provided an unusually detailed window into computer users' password habits. Typically, only government agencies like the F.B.I. or the National Security Agency have had access to such a large password list.

"This was the mother lode," said Matt Weir, a doctoral candidate in the e-crimes and investigation technology lab at Florida State University, where researchers are also examining the data.

Imperva found that nearly 1 percent of the 32 million people it studied had used "123456" as a password. The second-most-popular password was "12345." Others in the top 20 included "qwerty," "abc123" and "princess."

More disturbing, said Mr. Shulman, was that about 20 percent of people on the RockYou list picked from the same, relatively small pool of 5,000 passwords.

That suggests that hackers could easily break into many accounts just by trying the most common passwords. Because of the prevalence of fast computers and speedy networks, hackers can fire off thousands of password guesses per minute.

"We tend to think of password guessing as a very time-consuming attack in which I take each account and try a large number of name-and-password combinations," Mr. Shulman said. "The reality is that you can be very effective by choosing a small number of common passwords."

Some Web sites try to thwart the attackers by freezing an account for a certain period of time if too many incorrect passwords are typed. But experts say that the hackers simply learn to trick the system, by making guesses at an acceptable rate, for instance.

To improve security, some Web sites are forcing users to mix letters, numbers and even symbols in their passwords. Others, like Twitter, prevent people from picking common passwords.

Still, researchers say, social networking and entertainment Web sites often try to make life simpler for their users and are reluctant to put too many controls in place.

Even commercial sites like eBay must weigh the consequences of freezing accounts, since a hacker could, say, try to win an auction by freezing the accounts of other bidders.

Overusing simple passwords is not a new phenomenon. A similar survey examined computer passwords used in the mid-1990s and found that the most popular ones at that time were "12345," "abc123" and "password."

Why do so many people continue to choose easy-to-guess passwords, despite so many warnings about the risks?

Security experts suggest that we are simply overwhelmed by the sheer number of things we have to remember in this digital age.

"Nowadays, we have to keep probably 10 times as many passwords in our head as we did 10 years ago," said Jeff Moss, who founded a popular hacking conference and is now on the Homeland Security Advisory Council. "Voice mail passwords, A.T.M. PINs and Internet passwords — it's so hard to keep track of."

In the idealized world championed by security specialists, people would have different passwords for every Web site they visit and store them in their head or, if absolutely necessary, on a piece of paper.

But bowing to the reality of our overcrowded brains, the experts suggest that everyone choose at least two different passwords — a complex one for Web sites were security is vital, such as banks and e-mail, and a simpler one for places where the stakes are lower, such as social networking and entertainment sites.

Mr. Moss relies on passwords at least 12 characters long, figuring that those make him a more difficult target than the millions of people who choose five- and six-character passwords.

"It's like the joke where the hikers run into a bear in the forest, and the hiker that survives is the one who outruns his buddy," Mr. Moss said. "You just want to run that bit faster."

link

32.png

* ~ * Charles * ~ *
 

I carry a gun because a cop is too heavy.

 

USE THE REPORT BUTTON INSTEAD OF MESSAGING A MODERATOR!

Link to comment
Share on other sites

Filed: Citizen (apr) Country: Thailand
Timeline

haha count me in :whistle: only those site that I go once in a while have that easy password, all my emails and facebook all have different ones..

K-1 = 4 months

AOS = 5 months

I-751 = almost one year

I Love My Life With You

"A society is judged by how it treats its animals and elderly"

Link to comment
Share on other sites

Filed: Timeline
Back at the dawn of the Web, the most popular account password was "12345."

Today, it's one digit longer but hardly safer: "123456."

Despite all the reports of Internet security breaches over the years, including the recent attacks on Google's e-mail service, many people have reacted to the break-ins with a shrug.

According to a new analysis, one out of five Web users still decides to leave the digital equivalent of a key under the doormat: they choose a simple, easily guessed password like "abc123," "iloveyou" or even "password" to protect their data.

"I guess it's just a genetic flaw in humans," said Amichai Shulman, the chief technology officer at Imperva, which makes software for blocking hackers. "We've been following the same patterns since the 1990s."

Mr. Shulman and his company examined a list of 32 million passwords that an unknown hacker stole last month from RockYou, a company that makes software for users of social networking sites like Facebook and MySpace. The list was briefly posted on the Web, and hackers and security researchers downloaded it. (RockYou, which had already been widely criticized for lax privacy practices, has advised its customers to change their passwords, as the hacker gained information about their e-mail accounts as well.)

The trove provided an unusually detailed window into computer users' password habits. Typically, only government agencies like the F.B.I. or the National Security Agency have had access to such a large password list.

"This was the mother lode," said Matt Weir, a doctoral candidate in the e-crimes and investigation technology lab at Florida State University, where researchers are also examining the data.

Imperva found that nearly 1 percent of the 32 million people it studied had used "123456" as a password. The second-most-popular password was "12345." Others in the top 20 included "qwerty," "abc123" and "princess."

More disturbing, said Mr. Shulman, was that about 20 percent of people on the RockYou list picked from the same, relatively small pool of 5,000 passwords.

That suggests that hackers could easily break into many accounts just by trying the most common passwords. Because of the prevalence of fast computers and speedy networks, hackers can fire off thousands of password guesses per minute.

"We tend to think of password guessing as a very time-consuming attack in which I take each account and try a large number of name-and-password combinations," Mr. Shulman said. "The reality is that you can be very effective by choosing a small number of common passwords."

Some Web sites try to thwart the attackers by freezing an account for a certain period of time if too many incorrect passwords are typed. But experts say that the hackers simply learn to trick the system, by making guesses at an acceptable rate, for instance.

To improve security, some Web sites are forcing users to mix letters, numbers and even symbols in their passwords. Others, like Twitter, prevent people from picking common passwords.

Still, researchers say, social networking and entertainment Web sites often try to make life simpler for their users and are reluctant to put too many controls in place.

Even commercial sites like eBay must weigh the consequences of freezing accounts, since a hacker could, say, try to win an auction by freezing the accounts of other bidders.

Overusing simple passwords is not a new phenomenon. A similar survey examined computer passwords used in the mid-1990s and found that the most popular ones at that time were "12345," "abc123" and "password."

Why do so many people continue to choose easy-to-guess passwords, despite so many warnings about the risks?

Security experts suggest that we are simply overwhelmed by the sheer number of things we have to remember in this digital age.

"Nowadays, we have to keep probably 10 times as many passwords in our head as we did 10 years ago," said Jeff Moss, who founded a popular hacking conference and is now on the Homeland Security Advisory Council. "Voice mail passwords, A.T.M. PINs and Internet passwords — it's so hard to keep track of."

In the idealized world championed by security specialists, people would have different passwords for every Web site they visit and store them in their head or, if absolutely necessary, on a piece of paper.

But bowing to the reality of our overcrowded brains, the experts suggest that everyone choose at least two different passwords — a complex one for Web sites were security is vital, such as banks and e-mail, and a simpler one for places where the stakes are lower, such as social networking and entertainment sites.

Mr. Moss relies on passwords at least 12 characters long, figuring that those make him a more difficult target than the millions of people who choose five- and six-character passwords.

"It's like the joke where the hikers run into a bear in the forest, and the hiker that survives is the one who outruns his buddy," Mr. Moss said. "You just want to run that bit faster."

link

32.png

read this article in yahoo :)

Link to comment
Share on other sites

You don't have to be faster than the other runner, just stronger,

see - you push the other person down if your getting chased by a bear.

:)

My Advice is usually based on "Worst Case Scenario" and what is written in the rules/laws/instructions. That is the way I roll... -Protect your Status - file before your I-94 expires.

WARNING: Phrases in this post may sound meaner than they were intended to be. Read the Adjudicator's Field Manual from USCIS

Link to comment
Share on other sites

Filed: Citizen (apr) Country: Colombia
Timeline

As a kid living in the sticks, we had a telephone party line and shared our line with seven other people. Same thing with computers today, one big fat party line, except millions are on it.

If symbols were allowed in passwords, one could put in a long mathematical equation that can be remembered. Another way, but not hackproof is using keyboard arangements, like qywter by alternating your fingers at two end of the keyboard, more complex would be, qpwoeiruty, or qazxswedc, try, you will get the picture. Alternating with the shift key even makes it more complex.

But best to use a ready weird handle and passport for you bank accounts and a different one for each of them.

Link to comment
Share on other sites

Filed: K-1 Visa Country: Colombia
Timeline

technology helps us in many things, but we also complicates other, it is common have more than 5 passwords, in my case I have like 10 (i think more, huh, i don´t remember :whistle: ) and they are only of personal things, no count the passwords in the job, for that reason many people choose an easy password

We can all make a difference. Please recycle

por favor no escribas en mayúsculas sostenidas, eso equivale a GRITAR

crazy-cats.jpg

Link to comment
Share on other sites

Most of my password have a combination of French Russian English and a symbol lately adding an indian word to it.

try to crack that

Edited by Nikita2Charles

Gone but not Forgotten!

Link to comment
Share on other sites

Wow. I've never used one of these.

"The fact that we are here today to debate raising America’s debt limit is a sign of leadership failure. It is a sign that the U.S. Government can’t pay its own bills. It is a sign that we now depend on ongoing financial assistance from foreign countries to finance our Government’s reckless fiscal policies."

Senator Barack Obama
Senate Floor Speech on Public Debt
March 16, 2006



barack-cowboy-hat.jpg
90f.JPG

Link to comment
Share on other sites

Filed: Citizen (apr) Country: Brazil
Timeline

here's an example of a good password:

PTEkdj!!85@@



* K1 Timeline *
* 04/07/06: I-129F Sent to NSC
* 10/02/06: Interview date - APPROVED!
* 10/10/06: POE Houston
* 11/25/06: Wedding day!!!

* AOS/EAD/AP Timeline *
*01/05/07: AOS/EAD/AP sent
*02/19/08: AOS approved
*02/27/08: Permanent Resident Card received

* LOC Timeline *
*12/31/09: Applied Lifting of Condition
*01/04/10: NOA
*02/12/10: Biometrics
*03/03/10: LOC approved
*03/11/10: 10 years green card received

* Naturalization Timeline *
*12/17/10: package sent
*12/29/10: NOA date
*01/19/11: biometrics
*04/12/11: interview
*04/15/11: approval letter
*05/13/11: Oath Ceremony - Officially done with Immigration.

Complete Timeline

Link to comment
Share on other sites

I like abcD123 myself :devil:
Rather inapt since you are NOT an ABCD! :lol:

2005/07/10 I-129F filed for Pras

2005/11/07 I-129F approved, forwarded to NVC--to Chennai Consulate 2005/11/14

2005/12/02 Packet-3 received from Chennai

2005/12/21 Visa Interview Date

2006/04/04 Pras' entry into US at DTW

2006/04/15 Church Wedding at Novi (Detroit suburb), MI

2006/05/01 AOS Packet (I-485/I-131/I-765) filed at Chicago

2006/08/23 AP and EAD approved. Two down, 1.5 to go

2006/10/13 Pras' I-485 interview--APPROVED!

2006/10/27 Pras' conditional GC arrives -- .5 to go (2 yrs to Conditions Removal)

2008/07/21 I-751 (conditions removal) filed

2008/08/22 I-751 biometrics completed

2009/06/18 I-751 approved

2009/07/03 10-year GC received; last 0.5 done!

2009/07/23 Pras files N-400

2009/11/16 My 46TH birthday, Pras N-400 approved

2010/03/18 Pras' swear-in

---------------------------------------------------------------------

As long as the LORD's beside me, I don't care if this road ever ends.

Link to comment
Share on other sites

Filed: K-1 Visa Country: Thailand
Timeline
But bowing to the reality of our overcrowded brains, the experts suggest that everyone choose at least two different passwords — a complex one for Web sites were security is vital, such as banks and e-mail, and a simpler one for places where the stakes are lower, such as social networking and entertainment sites.

This is very good advice, and I generally do this. I have a password that I've used for years for "don't care" sites. It's not easily cracked, but even if it were it wouldn't give the cracker anything important. (E.g. my NY Times online membership, stuff like that).

For bank accounts etc. I'm obviously much more careful with unique and unguessable passwords.

One thing I find entirely counterproductive are sites which require you to change your password periodically. I'm much better off choosing a strong password and memorizing it for life than I am having to think up a new password every 2 to 3 months. The latter is a surefire recipe to force people to write their passwords down, or even worse store them on their computers, or email them to themselves.

Link to comment
Share on other sites

This is very good advice, and I generally do this. I have a password that I've used for years for "don't care" sites. It's not easily cracked, but even if it were it wouldn't give the cracker anything important. (E.g. my NY Times online membership, stuff like that).

For bank accounts etc. I'm obviously much more careful with unique and unguessable passwords.

One thing I find entirely counterproductive are sites which require you to change your password periodically. I'm much better off choosing a strong password and memorizing it for life than I am having to think up a new password every 2 to 3 months. The latter is a surefire recipe to force people to write their passwords down, or even worse store them on their computers, or email them to themselves.

Why not give us an example of your bank password? :devil:

R.I.P Spooky 2004-2015

Link to comment
Share on other sites

 

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
- Back to Top -

Important Disclaimer: Please read carefully the Visajourney.com Terms of Service. If you do not agree to the Terms of Service you should not access or view any page (including this page) on VisaJourney.com. Answers and comments provided on Visajourney.com Forums are general information, and are not intended to substitute for informed professional medical, psychiatric, psychological, tax, legal, investment, accounting, or other professional advice. Visajourney.com does not endorse, and expressly disclaims liability for any product, manufacturer, distributor, service or service provider mentioned or any opinion expressed in answers or comments. VisaJourney.com does not condone immigration fraud in any way, shape or manner. VisaJourney.com recommends that if any member or user knows directly of someone involved in fraudulent or illegal activity, that they report such activity directly to the Department of Homeland Security, Immigration and Customs Enforcement. You can contact ICE via email at Immigration.Reply@dhs.gov or you can telephone ICE at 1-866-347-2423. All reported threads/posts containing reference to immigration fraud or illegal activities will be removed from this board. If you feel that you have found inappropriate content, please let us know by contacting us here with a url link to that content. Thank you.
×
×
  • Create New...