Only around a third of users usually change their passwords following a data breach announcement, according to a recent study published by academics from the Carnegie Mellon University's Security and Privacy Institute (CyLab). Read More
Topic: Password Security
Password strength is a measure of the effectiveness of a password against guessing or brute-force attacks. In its usual form, it estimates how many trials an attacker who does not have direct access to the password would need, on average, to guess it correctly. The strength of a password is a function of length, complexity, and unpredictability.
Using strong passwords lowers overall risk of a security breach, but strong passwords do not replace the need for other effective security controls.
Suspect Can’t be Compelled to Reveal “64-character” Password, Court Rules
The Fifth Amendment to the US Constitution bars people from being forced to turn over personal passwords to police, the Pennsylvania Supreme Court ruled this week. Read More
Clear and Creepy Danger of Machine Learning: Hacking Passwords
Not too long ago, it was considered state of the art research to make a computer distinguish cats vs dogs. Now image classification is 'Hello World' of Machine Learning (ML), something one can implement in just a few lines of code using TensorFlow. Read More
Security-Conscious Password Behavior from the End-User’s Perspective

Watch The CSIAC Podcast video on this Report: https://www.csiac.org/podcast/security-conscious-password-behavior/ Introduction Even though technical solutions for security problems are widespread, there are no adequate security measures against precarious user behavior. Even if hashing and encrypting are used correctly in masking the passwords, attackers Read More
Security-Conscious Password Behavior from the End-User’s Perspective

Even though technical solutions for security problems are widespread, there are no adequate security measures against precarious user behavior. Even if hashing and encrypting are used correctly in masking the passwords, attackers can bypass these strongpoints by going for the weakest link. Most likely this will happen through sharing a password, using an Read More
Most Hacked Passwords Revealed as UK Cyber Survey Exposes Gaps in Online Security
The NCSC's first 'UK cyber survey' published alongside global password risk list. Read More
Microsoft Knows Password-Expiration Policies are Useless
Microsoft isn't doing away with its password-expiration policies across the board, but the blog post makes the company's stance clear: expiring passwords does little good. Read More
Facebook Stored Hundreds of Millions of User Passwords in Plain Text for Years
Hundreds of millions of Facebook users had their account passwords stored in plain text and searchable by thousands of Facebook employees - in some cases going back to 2012, KrebsOnSecurity has learned. Facebook says an ongoing investigation has so far found no indication that employees have abused access to this data. Read More
Password Security

We are all overwhelmed with login credentials for our various personal and professional accounts. Having said that, so much important information relies on our ability to generate and maintain a secure password. In practice we find weaknesses in our own human nature is too often our worst enemy, not a malicious attacker. This video demonstrates the Read More
1.4 Billion Clear Text Credentials Discovered in a Single Database
A Massive Resource for Cybercriminals Makes it Easy to Access Billions of Credentials. Read More