833-847-3280
Schedule a Call

Password Behavior: How to Secure Your Accounts Better

Password

LastPass, a password management software company, recently conducted a survey on password behavior.  They surveyed 3,250 global respondents revealing poor password hygiene.

Nearly half (44%) of the respondents stated that they reuse passwords or similar passwords on multiple sites.  While most (91%) stated they know they should not do this, it still happens.  Some people feel trying to remember a billion passwords is impossible with the timeouts that take place for incorrect passwords.  Some feel their accounts are not worth much to hackers (41% of respondents), so why bother.

However, if there is a breach where a hacker knows one password, that means he or she can then try it on other accounts and likely gain access.  Maybe an Amazon account doesn’t seem like too big of a deal, but banking accounts are something entirely different!

Trying to remember them can be hard; 60% said they were afraid of forgetting their login information.  And 54% said they memorize them, which doesn’t work out so well to try and remember what password goes with what account.  Another 25% said they reset their passwords about once a month because they continue to forget what it was.

That means if people aren’t reusing their passwords, they are probably writing them down somewhere.  Hopefully it’s not sticky notes on their monitors, or on their desk.  That is another disaster waiting to happen if someone comes by and takes a quick picture, for later usage.

Another problem is that people tend to ignore or forget about breaches.  Over half (52%) said they haven’t changed their passwords in the last 12 months, even after a known breach.  This might be going back to the fact that many people don’t think their accounts matter that much to anyone other than themselves.

A third issue is that we as a species are very predictable; we are creature of habit and like our routines and don’t like change for the most part.  About a quarter of respondents (22%) said they could guess their significant others’ passwords.  Of course, when people use “password1234”, that makes it pretty easy to guess and really easy for a computer code to guess it for a hacker.  People generally use things that are sentimental in their passwords, like their dog’s name, or their kids’ birthdate, or their anniversary.  The anniversary one does double duty for the people who forget to buy their significant other’s a gift once a year.

The issue with the use of such passwords is that a lot of the information is public knowledge, and with the internet, so much information can be found.

Not everything is doom and gloom.  People are using multi-factor authentication (MFA) for personal accounts (54%) and banking accounts (62%), and biometrics (65%).  MFA is not being utilized that often on business accounts (37%).  Also, 69% of respondents use stronger passwords on their banking accounts and 47% on their email accounts.

The information from this LastPass survey can help guide password best practices.  Another good resource is NIST SP 800-63B Digital Identity Guidelines.

Last but not least, this is a friendly reminder to check out those default passwords.  Those are easy finds and something that our penetration testers look for on a regular basis.

Latest Posts

A transparent image used for creating empty spaces in columns
Web application security is like maintaining a boat. You inspect the hull, find a small crack, patch it, and continue sailing. A week after that, you find another crack. You patch that too. The week after that? Another crack. This continues indefinitely because boats are…
A transparent image used for creating empty spaces in columns
 Your password isn’t enough anymore. It doesn’t matter how strong it is. It doesn’t matter if it’s 16 characters with special symbols and numbers. And it doesn’t matter if you’ve never written it down or shared it with anyone. Passwords alone are no longer…
A transparent image used for creating empty spaces in columns
“We’re secure because nobody knows about our systems.” “We use non-standard ports so attackers can’t find our services.” “We don’t publish our architecture, so nobody knows how to attack us.” This is security through obscurity; the idea that hiding something makes it secure. And it’s…
A transparent image used for creating empty spaces in columns
 You can’t “fix” web application security and call it done. Security isn’t a project with a start and end date. It’s not something you achieve once and move on from, or a checkbox you mark complete. Web application vulnerabilities aren’t a problem you solve…
A transparent image used for creating empty spaces in columns
Your firewall is important, but it’s just not enough. For years, the security model was simple: build a strong perimeter around your network. Put up a firewall, lock down the border, and keep the bad guys outside. Everything inside the perimeter was trusted, and everything…
A transparent image used for creating empty spaces in columns
Sarah walked into the conference room already skeptical. As CFO of a mid-sized manufacturing company, she’d approved the $6,000 penetration test because the CISO insisted it was necessary for their cyber insurance renewal. Fine. But now she was being pulled into a “findings debrief” that…
contact

Our Team

This field is for validation purposes and should be left unchanged.
Name(Required)
On Load
Where? .serviceMM
What? Mega Menu: Services