Slashdot Log In
MySpace Users Have Stronger Passwords Than Corporate Employees
Posted by
Zonk
on Thu Dec 14, 2006 03:36 PM
from the hardly-surprising dept.
from the hardly-surprising dept.
Ant writes "A Wired News column reports on Bruce Schneier's analysis of data from a successful phishing attack on MySpace, and compares the captured user-passwords to an earlier data-set from a corporation. He concludes that MySpace users are better at coming up with good passwords than corporate drones." From the article: "We used to quip that 'password' is the most common password. Now it's 'password1.' Who said users haven't learned anything about security? But seriously, passwords are getting better. I'm impressed that less than 4 percent were dictionary words and that the great majority were at least alphanumeric. Writing in 1989, Daniel Klein was able to crack (.gz) 24 percent of his sample passwords with a small dictionary of just 63,000 words, and found that the average password was 6.4 characters long."
This discussion has been archived.
No new comments can be posted.
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
Full
Abbreviated
Hidden
Loading... please wait.
Okay... (Score:5, Insightful)
It doesn't matter how strong their password is if they are still giving it to whoever asks for it.
Re: (Score:3, Interesting)
Or maybe nothing really happened, it's just a fake analysis.
Re:Okay... (Score:5, Funny)
Parent
Re:Okay... (Score:4, Funny)
Parent
Duh! (Score:4, Insightful)
Are myspace users really more security consious? Or are the typical demographics those people who tend to use oddball non-English words and text phrases that end up being "good passwords". yourmom69
Parent
Re:Duh! (Score:4, Insightful)
Parent
Re:Duh! (Score:4, Insightful)
Au contraire! It shows that MySpace users value their virtual presence more than corporate users value data security on the corporate network. Not the same thing. Most people don't get fired for choosing a shit password and getting the company hacked up.
Parent
Re: (Score:3, Insightful)
Riddle me this Batman.
How is a password from sample A more secure than sample B when BOTH sample A and B's passwords were compromised?
Re:Duh! (Score:4, Interesting)
They were both compromised by social engineering. Which allows us to see the passwords people are choosing and find that corporate passwords are more venerable to brute force attacks.
Parent
Re: (Score:3, Interesting)
I was being a little facetious. I'm not one who believes in "strong" passwords simply because I don't believe that they are secure to begin with.
A standard lock on a door may not be as "strong" as a steel door with bolts going through it like a vault, but I do believe that most weak passwords are strong enough, like standard l
Re: (Score:3, Informative)
Re:Okay... (Score:4, Funny)
Parent
Re:MOD PARENT INSIGHTFUL (Score:4, Informative)
Parent
Re:MOD PARENT INSIGHTFUL (Score:5, Interesting)
Parent
Re:Okay... (Score:5, Informative)
Parent
Re: (Score:3, Interesting)
It doesn't really surprise me. The slashdot hive mind may not greatly respect Myspace users, but the fact that they are on the internet and trying new stuff like Myspace, makes them a lot more tech-friendly than the
Re:Okay... (Score:5, Funny)
Parent
Re:Okay... (Score:5, Informative)
"The attacker had registered a MySpace account named login_home_index_html, meaning that the MySpace page hosting the fake login, looked like a legitimate place where users would sign on to the service."
So it was just a user page but it DID have myspace.com in the URL. The URL was:
http://www.myspace.com/login_home_index_html [myspace.com]
Parent
The Lesson? (Score:5, Interesting)
Re:The Lesson? (Score:5, Insightful)
Parent
Re:The Lesson? (Score:5, Insightful)
Parent
Re: (Score:3, Interesting)
Of course l0phtcrack would sniff and crack weak passwords in a matter of minutes, so I'm not sure how 30
Re: (Score:3, Informative)
The passwords I use at work are pretty pathetic.
The first reason is that I have to be able to remember them which is difficult when they have to change every 6 weeks, the second reason is that only people within the company have access to the network anyway.
In order to get in from outside, I need another (strong, permanent, set by me) password and a 6-digit Tamagotchi code which changes every 60 seconds. If I did not have to change my work password so frequently, it would be a lot stronger.
Password1? (Score:2, Funny)
Re: (Score:3, Insightful)
Only because someone made him use at least one numeral.
The three most commonly used passwords are... (Score:4, Funny)
Security through obscurity? (Score:4, Funny)
Re:Security through obscurity? (Score:5, Funny)
Parent
nobody can guess mine (Score:4, Funny)
Re:nobody can guess mine (Score:5, Funny)
Parent
Re:nobody can guess mine (Score:5, Funny)
"you can go hunter2 my hunter2-ing hunter2"
*Cough* [bash.org]
Parent
Re: (Score:3, Informative)
You can also hold alt while you type numbers on your keypad. like alt(128) = Ç
Note: most password forms won't allow anything non alphanumeric even slashdot didn't allow alt(127)
i'm not suprised (Score:5, Funny)
More to lose (Score:5, Insightful)
Which do you care more about? (Score:3, Insightful)
Stronger Passwords (Score:5, Insightful)
Password Rotation Insanity (Score:3, Insightful)
I understand the theory that it makes it tough on the crackers, of course, but that theory presumes that all other things are equal. I don't believe they are.
Passwords Expire (Score:5, Insightful)
The corporate drones have to deal with passwords that expire every 30/60/90 days, and once expired those passwords can never be reused. So creating a hard password and then remembering it is not so trivial. The myspace users can come up with one hard password and keep it forever.
Re:Passwords Expire (Score:5, Insightful)
Parent
Pr0gr355 (Score:2)
Awesome statistic (Score:4, Interesting)
Draw your own conclusions, but I think there might be something to this.
(and yes I did RTFA+LFA, do I lose my subscription?)
fear and netspeak (Score:5, Insightful)
1) They're terrified of their peers breaking in and sabotaging their profiles. (I once got assaulted by a drunk girl I knew who thought I hacked her LiveJournal... which I didn't.)
2) They can't spell worth shit, due to netspeak, so typical dictionary approaches aren't going to work.
Also, you have to take into account the basic fact that younger people have grown up around computers, and understand the concept of passwords a bit better than your average middle-aged office worker.
This is all wrong... (Score:5, Funny)
Dictionary words? (Score:5, Funny)
Maybe the users just used their usernames as passwords - that would probably be the best way to generate a random sequence of characters.
Don't be impressed. (Score:4, Interesting)
I'm not. MySpace users have good passwords because MySpace requires them to, not because they're savvy. "Your password must contain at least one number and one punctuation mark," etc.
It's obvious! (Score:3, Funny)
Getoffamylawn!
Statistics from phishing attacks are wrong! (Score:3, Insightful)
The quality of passwords has nothing to do with the type of people that where scammed, but with the difficulty of detecting the spam.
MySpace requires strong passwords (Score:3, Informative)
learning at age 6 (Score:4, Interesting)
Re: (Score:3, Informative)
With just alphabetic characters and a 6 character length you have about 26^6 or about 308 million possibilities
With alphanumeric characters and a 6 character length you have about 36^6 or about 2.1 billion possibilities
Extending to common non-alphanumeric characters (us