Sophos: One third of surfers use the same password for all Web sites

Enterprise Innovation Editors
26 Mar 2009
00:00

IT security and control firm, Sophos, is urging all computer users to assess the strength of their passwords and ensure that they are choosing unique and multiple passwords for every different sensitive account in order to thwart hackers and protect their personal and corporate identities.

The warning follows numerous recent cyberattacks whereby fraudsters have bypassed password security in order to break into Web mail and social networking sites. Despite high-profile security breaches such as Jack Straw's Hotmail account being compromised, and cybercriminals gaining access to celebrity Twitter accounts after cracking an administrator password, a third of computer users are still using the same password for every website they access, according to a Sophos poll conducted earlier this month*.

According to experts at Sophos, many computer users continue to overlook the importance of choosing strong passwords. When asked the same question three years ago, 41% admitted to using the same password for all Web sites, with just 14% always using a different one.

"It's worrying that in three years very few computer users seem to have woken up to the risks of using weak passwords and the same ones for every site they visit," said Graham Cluley, senior technology consultant at Sophos. "With social networking and other Internet accounts now even more popular, there's plenty on offer for hackers and by using the same password to access Facebook, Amazon and your online bank account, you're making it much easier for them. Once one password has been compromised, it's only a matter of time before the fraudsters will be able to gain access to your other accounts and steal information for financial gain."

Sophos advises all computer users to ensure they don't use dictionary words as passwords as it is relatively easy for hackers to figure these out using electronic dictionaries that simply try out every word until they get the right one. Furthermore, it's important not to choose common passwords like "˜admin' or "˜1234' as cybercriminals also check these first. In fact, the Conficker worm uses lists of 200 common passwords to try and gain access to other computers on the network, meaning that if one employee is infected, the whole corporate network could quickly be compromised if strong passwords are not enforced.

Related content

Follow Telecom Asia Sport!
Comments
No Comments Yet! Be the first to share what you think!
This website uses cookies
This provides customers with a personalized experience and increases the efficiency of visiting the site, allowing us to provide the most efficient service. By using the website and accepting the terms of the policy, you consent to the use of cookies in accordance with the terms of this policy.