//--> |
Rockyou.com is a website where users can develop apps to use on social networking sites. Last December, a hacker gained access to all of Rockyou’s members’ usernames, email addresses and passwords (which had been stored in plain, unencrypted text) and posted the passwords to the Internet. Given that many people use the same username and password for all of their online dealings, such as banking, the results could have been disastrous. Fortunately, the perpetrator seemed to be mainly interested in exposing Rockyou’s insufficient security, as they didn’t post the usernames or emails.
Imperva analyzed the hacked data, and compiled their findings in the Consumer Password Worst Practices report. Of the 32 million passwords involved, the ten most common were:
- 123456
- 12345
- 123456789
- Password
- iloveyou
- princess
- rockyou
- 1234567
- 12345678
- abc123
So, what sort of password SHOULD people be using?
Imperva made the following recommendations:
- It should contain at least eight characters (30% of users had passwords that were six letters or less)
- It should contain a mix of four different types of characters (i.e: upper case, lower case, numbers, symbols)
- It should not be a name, word, or contain any part of your name or email address
“The data provides a unique glimpse into the way that users select passwords and an opportunity to evaluate the true strength of passwords as a security mechanism,” said Imperva CTO Amichai Shulman. “Never before has there been such a high volume of real-world passwords to examine.”
Article Source:
http://www.gizmag.com/worst-passwords-on-the-web/13960/
No comments:
Post a Comment