{"id":23485,"date":"2023-11-29T15:10:07","date_gmt":"2023-11-29T23:10:07","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2023\/11\/29\/news-17215\/"},"modified":"2023-11-29T15:10:07","modified_gmt":"2023-11-29T23:10:07","slug":"news-17215","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2023\/11\/29\/news-17215\/","title":{"rendered":"Many major websites allow users to have weak passwords"},"content":{"rendered":"\n<p>A new study that examines the current state of password policies across the internet shows that many of the most popular websites allow users to create weak passwords.<\/p>\n<p>For the <a href=\"https:\/\/www.cc.gatech.edu\/news\/largest-study-its-kind-shows-outdated-password-practices-are-widespread\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Georgia Tech study<\/a>, the researchers designed an algorithm that automatically determined a website\u2019s password policy. With the help of machine learning, they could see the consistency of length requirements and restrictions for numbers, upper- and lower-case letters, special symbols, combinations, and starting letters. They could also see if sites permitted dictionary words or known breached passwords.<\/p>\n<p>Using this tool they found:<\/p>\n<ul>\n<li>12% of the websites they looked at completely lack password length requirements<\/li>\n<li>3 out of 4 fail to meet minimum requirement standards which means they:\n<ul>\n<li>Allow very short passwords<\/li>\n<\/ul>\n<ul>\n<li>Do not block common passwords<\/li>\n<\/ul>\n<ul>\n<li>Use outdated requirements like complex characters<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p>More than half of the websites in the study accepted passwords with six characters or less, with 75% failing to require the recommended eight-character minimum. Around 12% of the websites had no length requirements, and 30% did not support spaces or special characters.<\/p>\n<p>Giving users that kind of freedom is asking for them to be duped. As we pointed out a while back, even tech-savvy users like <a href=\"https:\/\/www.malwarebytes.com\/blog\/news\/2023\/10\/it-administrator-passwords-are-leading-by-bad-example\">IT administrators resort to awful passwords<\/a> when given the chance. <\/p>\n<p>The reasons for not enforcing standards are obvious. Most websites care more about customer satisfaction than security, and you can guess which one is better for business.<\/p>\n<p>Users don\u2019t like passwords, especially since the password situation has been made worse by ridiculous and unnecessary rules, such as asking users to pick passwords that follow formulas, or forcing users to change their password every few months. Both rules have been discredited but continue to haunt us. Formulas reduce the number of possible passwords a user can pick from, and regular password resets encourage users to pick passwords that conform to a predictable pattern, both of which can make guessing passwords easier, which is the opposite of what we want.<\/p>\n<p>If you\u2019d like to read more about this, read \u201c<a href=\"https:\/\/www.malwarebytes.com\/blog\/news\/2022\/10\/why-almost-everything-we-told-you-about-passwords-was-wrong\">Why (almost) everything we told you about passwords was wrong<\/a>.\u201d The article summarizes how a lot of what you\u2019ve been told about passwords over the years was either wrong (change your passwords as often as your underwear), misguided (choose long, complicated passwords), or counterproductive (don\u2019t reuse passwords).<\/p>\n<p>We feel that we should entirely move away from the model that requires users to create and remember passwords. It is time for something more secure AND user-friendly. And it\u2019s not like these systems don\u2019t exist (hello <a href=\"https:\/\/www.malwarebytes.com\/blog\/podcast\/2023\/03\/solving-the-passwords-hardest-problem-with-passkeys-featuring-anna-pobletts\">Passkeys<\/a>), we just need to embrace them more widely.<\/p>\n<p>Let\u2019s enable <a href=\"https:\/\/www.malwarebytes.com\/glossary\/multi-factor-authentication-mfa\">muti-factor authentication (MFA)<\/a> where we can, even if we feel that using a password as the first factor doesn\u2019t add a lot of extra security to the login procedure. And if we need to rely on passwords alone, try using a password manager. They help you create complex passwords and remember them for you.<\/p>\n<p>The full report of the researchers will be presented at the ACM Conference on Computer and Communications Security (CCS) in Copenhagen, Denmark, later this month.<\/p>\n<hr class=\"wp-block-separator has-text-color has-cyan-bluish-gray-color has-alpha-channel-opacity has-cyan-bluish-gray-background-color has-background is-style-wide\" \/>\n<p><strong>We don\u2019t just report on threats\u2014we remove them<\/strong><\/p>\n<p>Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by&nbsp;<a href=\"https:\/\/www.malwarebytes.com\/for-home\">downloading Malwarebytes today<\/a>.<\/p>\n<p><a href=\"https:\/\/www.malwarebytes.com\/blog\/news\/2023\/11\/many-major-websites-allow-users-to-have-weak-passwords\" target=\"bwo\" >https:\/\/blog.malwarebytes.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p> A new study that looked at the password requirements of the most popular websites came to a disappointing but not surprising conclusion. <\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10488,10378],"tags":[32,26699],"class_list":["post-23485","post","type-post","status-publish","format-standard","hentry","category-malwarebytes","category-security","tag-news","tag-personal"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/23485","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=23485"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/23485\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=23485"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=23485"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=23485"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}