We beg, implore and beseech thee. Stop reusing the same damn password everywhere
- Reference: 1588682414
- News link: https://www.theregister.co.uk/2020/05/05/logmein_password_survey/
- Source link:
Even though more than 90 per cent of people surveyed by the password manager biz said they knew it was risky to recycle passwords or light variations on a theme, 66 per cent of respondents admitted they "always or mostly use the same password or a variation".
These findings came from LogMeIn's Psychology of Passwords report, released today, that quizzed 3,250 people and discovered that half of them across the world hadn't changed their passwords over the past 12 months "even after hearing about a breach in the news".
Depressingly, that number rose to 58 per cent for Britons specifically who did not change their passwords after reading about a breach on the news. A whopping 92 per cent of Brits reuse passwords despite being aware of the risks.
A possible explanation for this is the age-old problem of forgetting sufficiently complex ones: just under two-thirds of UK dwellers who responded to the survey cited that as their reason for doing the bad thing. Across the full 3,250 people surveyed, 42 per cent agreed with the statement "having a password that's easy to remember is more important than one that is very secure".
Meanwhile in America, a third of people admitted to writing down passwords, while 67 per cent "trust biometrics more than traditional text passwords".
That's what makes you hackable: Please, baby. Stop using 'onedirection' as a password [1]READ MORE
Rather forlornly, LogMeIn commented in a statement: "Will this finally be the tipping point that causes people to show more concern for their online data?"
Thirty years of widespread consumer (mis)use of the internet tends to suggest the answer will be "no", but it's gods' work to keep preaching the online security gospel.
The standard password advice, repeated by LogMeIn, is to use a password manager to remember your passwords for you; enable multi-factor authentication (MFA), so if someone else does obtain your password they can't easily log in and steal your account – though 20 per cent of respondents to the survey said they didn't know what MFA was; and stay vigilant. While biometric logins (facial or fingerprint recognition) are controversial, they can be a useful and hassle-free way of securing an account where the option exists.
"Individuals seem to be numb to the threats that weak passwords pose and continue to exhibit behaviours that put their information at risk," complained John Bennett, gros fromage of all things identity and access management at LogMeIn. "Taking just a few simple steps to improve how you manage passwords can lead to increased safety for your online accounts, whether personal or professional."
LogMeIn itself, which provides remote access, collaboration and famously is still the home to password manager LastPass (which it [2]bought for $110m in 2015 ), was [3]sold to a private equity outfit for $4.3bn in December last year. At the time, it raised concerns from users about the data it held. The sale was due to close in the middle of this year.
Other password managers include Bitwarden, Dashlane, 1Password and KeePass. ®
Sponsored: [4]Forrester Build a Digital Experience Portfolio
[1] https://www.theregister.co.uk/2020/02/05/one_direction_is_a_rubbish_band_and_password/
[2] https://www.theregister.co.uk/2015/10/09/logmein_gobbles_lastpass/
[3] https://www.theregister.co.uk/2019/12/18/log_me_in_acquired/
[4] https://go.theregister.co.uk/tl/1936/-8554/forrester-build-a-digital-experience-portfolio?td=wptl1936
Re: In other news....
It sounds like this report is berating humans for being unable to use a system that's basically unsuitable for use by humans.
Most of the people who claim not to regularly re-use passwords are probably liars. Some are probably using password managers, but not a third of the population. Surely no-one is really remembering a completely unique password for every single device, internet shop, social media site and forum they ever used.
Re: In other news....
Surely no-one is really remembering a completely unique password for every single device, internet shop, social media site and forum they ever used.
Just use a password manager on your phone. Then you can lose them all at the same time.
Re: In other news....
"Surely no-one is really remembering a completely unique password for every single device, internet shop, social media site and forum they ever used."
One part of this is sites demanding passwords when they don't need them.
Take, for instance, online shops. If I go into a physical shop - it's already getting to the point where it's a stretch to remember doing that - to make a one-off purchase I don't have to set up an account. So why do I have to set up an account for a one-off purchase online? They get some junk that I'll not remember as a password because I'm not going back there again if I can help it. For a logon ID - they'll insist on en email address - they'll get one that will be deleted after a short while.
The there's iPlayer or sound app as it has become (why?). For no clear reason except possibly they think they can't operate a website without one, they need a userID and password. For a while it worked quite well if this was saved in the browser. The the sound side changed it so that it had to be entered manually. I haven't bothered with the whole thing since then (what pissed me off most is that it stopped working with the iPlayer app on OSMC) but if I had it would have been swapped from the secure password-manager generated random string for the least variation on "password" that I could have got away with.
Another example is familysearch.org. This used to be a perfectly straightforward free genealogy site with a compact UI. Then the UX designers got at it so the actual user experience started the usual downhill progression that I doubt has bottomed out, part of which was to add a login requirement it never had before. At least that didn't need an email address; I think Mickey Mouse was taken but it got an equally contemptuous one.
Basically, if the password is important for me I'll keep it secure. If it's just the site being obnoxious about I'll treat it with the contempt it I think it deserves.
Meantime - RESULT. Whilst writing this I finally got an email confirming the removal of my email address the customer list from a firm of whom I've never been a customer but who insisted on spamming me with their coronavirus updates for customers.
Re: In other news....
"For a while it worked quite well if this was saved in the browser."
For anything not overly important I store (unique and complex) passwords in the browser, e.g. for El Reg. What really bugs me are sites that won't let me paste in a password. As I always chose long complex passwords it can be a pain in the rear to type them in; so I tend to avoid such sites... I'll often abandon a site registration form if it blocks password pasting and either not bother or go to another site.
Recently tried to register with the National Lottery but they did the password pasting blocking thing so abandoned my registration. I'll probably be a couple of quid a week better off anyway.
As for storing my passwords, I use encrypted documents stored in an encrypted folder on an encrypted drive on my local hardware (not cloud). Backed up to other encrypted drives. While it can be a little tedious accessing my bank login details etc, it does allow me to use long, complex usernames and passwords and I don't need to trust a third party to store them for me. Just a pain if some sites block me from pasting them in.
Re: In other news....
Yup. That was the case with the Beeb. Wouldn't let the browser enter it. Wouldn't let it be pasted from KeepassX either. How much more desperate could they be for users to use weak passwords?
Re: In other news....
I reuse the same password on loads of sites, such as here on the Reg.
Let me guess. "drowssaP"?
Re: In other news....
Got to be "Password1!". It's got upper and lower case, numbers and punctuation, and it's way more than 8 characters long. You can't get much more secure than that, surely.
Re: In other news....
Remember to change it every 90days Password2!, Password3!.....
Re: In other news....
Mine at work is now up to 14...
Re: In other news....
correct-horse-battery-staple
Re: In other news....
If I could give one piece of advice to web site designers about password policies, it would be this:
Put the password policy on the log-in page.
I come across so many sites that I fail to log in to, have to use the password reset option, wait for the password reset email, go back to the site, try to enter a new password, have it rejected, and only then find out that the reason I couldn't use one of my "normal" passwords was that this site doesn't allow punctuation, or spaces, or swears, or has odd length limits, or wants you to use at least 2 upper case letters, or something equally pointless.
Re: "Put the password policy on the log-in page"
ITYM the registration page, as that's where passwords are created.
But also make sure that pages that deal with passwords (principally the login page, the registration page and the self-service reset page) and the supporting backend processes all implement the exact same policy!
I came across a site recently where this was not the case, so I could reset with a new password that was accepted by the reset page (and it reported success), but would then not work on the login page.
Cue multiple rounds of resets until I found something that both elements were happy with.
Re: "Put the password policy on the log-in page"
ITYM the registration page, as that's where passwords are created
I want it on the login page. That way when I'm trying to login and failing I can look at what stupidly unusual thing it needs. This would "normally" be enough for me to remember it and avoid me going round the password reset route, which would end up with me trying to reset it to to the same password I was forced to choose last time.
Re: ITYM the registration page
No, the log-in page, for exactly the reason Persona has described above.
Occasionally you see sites that tell you the password policy as part of the error message the first time you fail to log in, which is also a fair enough way of doing it.
Re: In other news....
"If I could give one piece of advice to web site designers about password policies, it would be this:
Put the password policy on the log-in page."
Let me suggest an even better piece of advice: don't require logins if you don't need them. The fact that marketing want a list to pester people isn't a need - just the opposite because one day that list will be conspicuously toxic when it gets leaked and until then will be quietly toxic when potential customers are put off by it.
Re: In other news....
Rather than berate the 7 billion people on the planet into conforming to password requirements, how about companies do a little work and spend a little money to clean up their act. The first time I was confronted with a "your password is too long" error message, I assumed I had fallen through a wormhole and arrived in the before times where 80-columns was enough for anybody.
"correcthorsebatterystaple" has been dismissed unfairly I think. Sure, 48 characters of line noise is safer, but for quite a lot of sites 4 or 5 random words is far better and easier to remember than 7 alpha-numerics and a special character (which is almost always "!"). Sure, if a site gets their password hashes breached evildoers can gigahash through it with a couple of NVidia cards, but if the users are able to have a handful of long, yet easy to remember passwords, they're less likely to reuse them.
In any event, if you're a developer, dropping the $3.50/mo for haveibeenpwned API access is cheap at twice the price. Want to stop password reuse? Let your users know that their sooper-sekrit password is already in the hands of the evil hacker 4chan.
Re: I reuse the same password on loads of sites
I will admit that I have a throwaway password for sites that I do not consider important, yet still ask me for a login, or sites that I have no intention to return to after the reason for which I went there in the first place.
But for anything important, I have a system that gives me at least 13 characters, and I have a database to store them in along with the URL that is concerned.
Re: In other news....
Agreed on banking websites sucking. Just got a reminder to change my password on the website for my work credit card. Password expires every 30 days (yikes). The site does have password crtieria on the pw change page. I use keepass as password manager, and our default password generator profile (including the Administrator profile) didn't meet complexity requirements.
On the flip side, I have a personal account with the same bank. No password expiration. "Two factor" verification includes a typical set of predefined questions that could be answered by anyone creeping your facebook (one of many reasons I have no FB account).
Re: In other news....
Earlier today I have up registering an account (for a software service) because it
a) demanded a complex password (>10 characters, digits symbols upper and lowercase)
b) my browser let me store the password but the site spoofed the browser so it would not offer the password
c) did not allow me to paste the password
If you don't ..
You will only have yourself to blame when your are pwned. A different password for each app may seem a faff but there are ways around that. The main upside is that it becomes very easy to track which account has been exposed and to take appropriate actions..
Re: If you don't ..
A good trick is to use the same password but different usernames
Re: If you don't ..
"different" works if you do this:
correct-horse
horse-correct
h0r5e+CoRR3ct
etc. (to crack these would require human intervention and some social engineering, and knowledge of one of them, and a good guess as to where the others might get used).
but yeah a password manager to track the HUNDRED or so passwords is probably a good idea. LONG ago I'd write them down. The page got full. Then I discovered KeePassXC [NOT the C-pound one WITHOUT the "XC" at the end, but the C language one WITH the 'XC' at the end, that builds properly on Linux and FreeBSD _WITHOUT_ _MONO_ - the LAST thing I need is MONO DEPENDENCIES on my Linux and FreeBSD systems]
in any case my master password is SO long I often make typing mistakes entering it...
(if the password is long enough, chances are you will NOT be "social engineered" to discover all of your derived passwords based on one that was obtained by cracking some 3rd party web site)
OK, sp which password manager to plump for?
LastPass, 1Password, Dashlane etc?
Re: OK, sp which password manager to plump for?
My passwords.txt
Re: OK, sp which password manager to plump for?
Hey how did you get on my computer?
Re: OK, sp which password manager to plump for?
Since your on-line access to everything is going to be dependent on it, ideally you want the one that guarantees they will never go out of business, bump up the price, or start pissing you off with ads, and will always fully support any new browser or platform you want to browse the web from. Good luck.
Re: OK, sp which password manager to plump for?
Oh yeah, and in addition to all those things, your password manager has to be perfectly secure since any security flaws in your password manager will likely result in ALL it's user data being sold as part of a 50Gb file on the dark web.
Re: OK, sp which password manager to plump for?
"ideally you want the one that guarantees they will never go out of business, bump up the price, or start pissing you off with ads, and will always fully support any new browser or platform you want to browse the web from. Good luck."
No luck needed. The password manager is kept locally. It's also synced to my home Nextcloud server. So unless I go out of business in a very personal manner or lose my marbles to the extent that I can't remember my master password that's not a problem.
Re: OK, sp which password manager to plump for?
I use KeePassXC, because:
- Still in active development
- Fully open source (Peace of mind...)
- Fully offline by default - no internet/cloud required
- Includes a built-in password generator which can be adjusted/altered to match a sites particular requirements
- Integrates with your desktop keyring - useful for apps such as evolution storing passwords
- Not owned by a corporation - Your passwords won't be sold...
- No risk of simply "vanishing" if a business stops operating
- Included in pretty much every distro, so installing is quick and simple - no hunting for binaries.
- Mobile applications exist in f-droid for reading your DB on a mobile device.
- Many other reasons - but if I continue I start to sound like a sales bod.
Re: OK, sp which password manager to plump for?
"Many other reasons - but if I continue I start to sound like a sales bod."
There's the thing. So many people won't use something unless it's sold to them by a sales bod - or even worse - they're allowed to use it free and it's they who are being sold.
Yes, KeypassX.
Re: OK, sp which password manager to plump for?
KeepassX.
Synced by NextCloud to any device where I might need a copy.
Re: OK, sp which password manager to plump for?
Hiow about something a) open source and runs on Linux/FreeBSD, b) *NOT* written in C-pound, c) does *NOT* have a boatload of unique dependencies (which is why I don't want something written in C-pound).
keepassXC comes to mind - which is the MAINTAINED open source version of keepassX that builds on Linux and FreeBSD.
Why would an investor think that a bunch of passwords is worth multiple billions of dollah? How are they planning to monetise them?
Hey! Psst! Wanna buy a password?
"How are they planning to monetise them?"
Wring question.
How are they planning to monetise the users?
scott
tiger
Re: scott
Isn't it jack/jack these days?
Re: scott
If it's root/toor remember to change it at first login.
mean ≠ median
I use always the same 3-4 passwords, because else I don't remember them. And also because most of the times I don't care about the site (seriously: what if my account on ElReg gets hacked ?). And for those sites that I DO care, I use a different browser and a unique password. Which means that in 95% of the occasions, I use always 3-4 passwords and a generic browser, so if such a survey only looks at the number of occurrences, it's going to have a very bad representative image of how secure/unsecure my use of passwords and Internet is.
And for me it's still very few passwords to remember.
Surely that should be .netrc?
protect what you value
> they knew it was risky to recycle passwords or light variations on a theme
People reuse passwords on so many sites because it is of no consequence to them if those accounts get compromised.
For example, if you joined, or were forced to join, a website or forum because you ONE TIME wanted some information that was only available to members, it is quite reasonable to use abc123 as a universal password.
The same if you wanted support from a user forum. Join - ask question - get ignored as a noob - leave.
If the account gets hacked and your password is stolen, it's no big deal (you've probably forgotten about it anyway). There is no risk as nothing of value is being risked.
Re: protect what you value
Agreed.
I have a generic password that I know has been compromised but is still in use on a few sites where it really, really doesn't matter. Eventually I'll probably catch up and change them to something equally obvious.
For anything that is important I use totally unique passwords and a password manager.
Re: protect what you value
If you have to register to get a data sheet, try "User Name" and "Password". Sometimes someone else has already save me the trouble - or Mr Name makes no effort keeping his account secure.
Re: protect what you value
Isn't that what BugMeNot is for?
A while ago there was a browser extension called BugMeNot that would quickly provide a login for a large number of sites that demanded registration for no good reason. That login would be the same for every user of BugMeNot. I wonder if it's still around.
Check your password here
I use https://haveibeenpwned.com/Passwords to see if a password I want to use has been compromised somewhere else.
Re: Check your password here
Mandatory XKCD image:
https://xkcd.com/2228/
I use the same password for many sites that I consider low-risk. I can't really get too exercised over whether someone can post as me on this site.
I don't use the same password for home banking!
If my bank's online banking system used something as crude and insecure as a password to identify me, I would be switching to a bank that understands security issues pronto!
In other news....
66% of people think password policies on websites are a joke, the worst offenders being banking.
I reuse the same password on loads of sites, such as here on the Reg.