Password

Facebook Introduces Disposable Passwords

Published: October 15, 2010 Reading time: 2 min

Accessing Facebook from a public computer or Internet cafe can now be done more securely. Moving to enhance online security, Facebook on Tuesday said that it will soon offer users the ability to receive one-time passwords on their mobile phones and that it has already enabled the ability to sign out of Facebook remotely. “We’re launching one-time passwords to make it safer to use public computers in places like hotels, cafes or airports,” said Facebook product manager Jake Brill in a blog post. “If you have any concerns about security of the computer you’re using while accessing Facebook, we can text you a one-time password to use instead of your regular password.” ...

Continue Reading

Twitter password phishing

Published: October 7, 2010 Reading time: 2 min

Our friend in the UK got this via a contact. It was from a Twitterer who obviously had his Twitter login stolen: (Twitter apparently is filtering this URL at this point.) The link led to a phishing page that used the deceptive tactic of showing an error message: “Wrong Username/Email and password combination.” You login, it steals your Twitter password, sends the above Tweet to all your contacts and continuing rounding up passwords. ...

Continue Reading

Social media is exposure for password guessing

Published: April 3, 2010 Reading time: 1 min

The Inquirer security news site were reporting that the 25-year-old arrested by French police for hacking a Twitter data base and accessing U.S. President Barak Obama’s account guessed the admin’s password. The unemployed man, who went by the handle “Hacker Croll.” is not a genius, the news site concluded. “Apparently it was a doddle to do. He simply guessed people’s passwords by working them out from information on their blogs or online pages they had created about themselves,” it said. ...

Continue Reading

Too many passwords? Here is a solution!

Published: March 4, 2010 Reading time: 2 min

How many sites do you log into? Bank, email, shopping, work tools, social networks — each one wants a password, and serious sites add rules about length or character types. You already know not to use the same password everywhere. Recycling variants (david1, david2, david3) is not much better: one leak still maps to the rest. For what weak choices look like in the wild, see Passwords used by the Conficker worm. ...

Continue Reading

Passwords used by the Conficker worm

Published: January 15, 2009 Reading time: 1 min

It’s not possible to emphasise enough the importance of using sensible passwords on your network. Not just on the areas of your network that you don’t want your users to traipse through, but also on the default network shares that are present on installations of commonly used operating systems. The Windows versions Conficker targeted — NT, 2000, XP, and 2003 — are all end of life and no longer receive security updates. The lesson still applies to any machine with open shares today. ...

Continue Reading

5 tips to help keep your passwords secret

Published: January 14, 2009 Reading time: 2 min

Treat passwords with as much care as the information they protect. For how to make them strong — and why a manager should generate them — see Passwords. These tips are about keeping secrets secret day to day. 1. Never provide your password over e-mail Phishing messages pretend to be a bank, a shop, or a social network and ask you to “confirm” your login. Legitimate services do not need your password by email. Learn how to spot phishing. ...

Continue Reading

Passwords

Published: January 13, 2009 Reading time: 3 min

Strong passwords still matter, but the way we handle them has changed since this post first ran in 2009. The default today is simple: let a password manager create a unique random password for every site, turn on two-factor authentication (2FA) wherever it is offered, and use a passkey when a service supports one. What actually makes a password strong Attackers guess and crack passwords with dictionaries, leaked lists, and raw computing power. Strength comes from: ...

Continue Reading