i3m Blog

Why passwords have never been weaker—and crackers have never been stronger

 Internet News, Tech News  281 Responses »
Aug 212012
 

In late 2010, Sean Brooks received three e-mails over a span of 30 hours warning that his accounts on LinkedIn, Battle.net, and other popular websites were at risk. He was tempted to dismiss them as hoaxes—until he noticed they included specifics that weren’t typical of mass-produced phishing scams. The e-mails said that his login credentials for various Gawker websites had been exposed by hackers who rooted the sites’ servers, then bragged about it online; if Brooks used the same e-mail and password for other accounts, they would be compromised too.

The warnings Brooks and millions of other people received that December weren’t fabrications. Within hours of anonymous hackers penetrating Gawker servers and exposing cryptographically protected passwords for 1.3 million of its users, botnets were cracking the passwords and using them to commandeer Twitter accounts and send spam. Over the next few days, the sites advising or requiring their users to change passwords expanded to include Twitter, Amazon, and Yahoo.

“The danger of weak password habits is becoming increasingly well-recognized,” said Brooks, who at the time blogged about the warnings as the Program Associate for the Center for Democracy and Technology. The warnings, he told me, “show [that] these companies understand how a security breach outside their systems can create a vulnerability within their networks.”

The ancient art of password cracking has advanced further in the past five years than it did in the previous several decades combined. At the same time, the dangerous practice of password reuse has surged. The result: security provided by the average password in 2012 has never been weaker.

A new world

The average Web user maintains 25 separate accounts but uses just 6.5 passwords to protect them, according to a landmark study (PDF) from 2007. As the Gawker breach demonstrated, such password reuse, combined with the frequent use of e-mail addresses as user names, means that once hackers have plucked login credentials from one site, they often have the means to compromise dozens of other accounts, too.

Newer hardware and modern techniques have also helped to contribute to the rise in password cracking. Now used increasingly for computing, graphics processors allow password-cracking programs to work thousands of times faster than they did just a decade ago on similarly priced PCs that used traditional CPUs alone. A PC running a single AMD Radeon HD7970 GPU, for instance, can try on average an astounding 8.2 billion password combinations each second, depending on the algorithm used to scramble them. Only a decade ago, such speeds were possible only when using pricey supercomputers.

MORE:  Why passwords have never been weaker—and crackers have never been stronger | Ars Technica.

 


 Posted by ..internal.. at 8:05 am  Tagged with: accounts, cracking, hacking, login, passwords

Recent Posts

  • Adblocking could be the best thing for the advertising industry
  • Instagram Officially Turns On Multi-Account Switching For Mobile, And This Is Why It’s Important
  • Have a pirated version of Windows? You’ll also get a free upgrade to Windows 10
  • FCC: Blocking Wi-Fi in hotels is prohibited
  • Facebook Rolls Out a Tool for Testing Ads With Control Groups

Tags

ads advertising android app apps browser code content copyright css design email engagement facebook games google hack images interface internet like malware marketing mobile music new feature new features pages pinterest piracy posts sales search security sharing social timeline tools TV twitter update video website wifi youtube

Archives

  • April 2016
  • February 2016
  • March 2015
  • January 2015
  • October 2014
  • August 2014
  • June 2014
  • May 2014
  • January 2014
  • October 2013
  • September 2013
  • July 2013
  • June 2013
  • May 2013
  • April 2013
  • March 2013
  • February 2013
  • January 2013
  • December 2012
  • November 2012
  • October 2012
  • September 2012
  • August 2012
  • July 2012
  • June 2012
  • May 2012
  • April 2012
  • March 2012
  • January 2012
  • November 2011
  • October 2011
  • September 2011
  • August 2011
  • July 2011
  • October 2010
© 2013 internal3m Suffusion theme by Sayontan Sinha