Nov 3, 2011

Use Unique Passwords - Always

A real story from a technical subscription service I support. A tech services individual had a client who signed up for a local newspaper web site. Since the website was NOT requesting detailed personal information to register, his client registered on the site with an email address and a frequently used password - 12345678. The newspaper site did not have specific protocol or specific security rules (thinking ... how secure does a site need to be to have visitors comment on news article, anyway?). Here is the rest of the story ...
  • an out of country hacker was searching for un-secure 'easy sign-on' websites and found this newspaper site
  • without difficulty and using the web and YouTube videos, he learned how to crack the newspaper database
  • he gained access to 3,400 user names and to get peer credit, posted those names on the web
  • another individual, using the name, email address and simple password attempted to sign into a local financial institution site unsuccessfully
  • he then proceeded to use the 'Forgotten Password' link and then accessed the client's email address to obtain a new password for the financial institution
  • within two minutes he was accessing the individual's accounts 
  • Issue: the individual used the same user name and password for his email and the newspaper site!
Solution: Use unique passwords for every site you require a user name and password and consider using a password manager like LastPass.

No comments: