Share

Related Links

Related Stories

  • Cloud based wireless password crack service launches
    A hacker who found a flaw in the SSL protocol last year has launched a new project that cracks wireless network passwords using a cloud based computing service.
  • German Firm Develops World's First "Trojan-proof" Password System
    Global IP Communications claims to have developed the world's first Trojan-proof password dialog system for Windows PCs.
  • UK government loses data on 25m Britons
    The UK government has lost personal data on every child in the country, as well as national insurance numbers and bank account details of parents and carers claiming child benefit, on two password-protected CDs sent through an internal mail service.
  • Keeping sensitive information secure when staff is leaving
    Career loyalty is an endangered creature. Unlike our predecessors, today’s workforce is unlikely to stay committed to a job for five years, let alone their entire lives. But with such a fluid stream of employees keeping human resources busy, and countless eyes being cast over company data, Rob Stringer investigates how sensitive information can stay faithful to its organisation, even if its staff don’t...
  • Gordon Brown’s hacked emails – the lessons to be learnt
    Operation Tuleta, the British police investigation into potential computer hacking offenses related to the press phone hacking scandal, has suggested that ex-prime minister Gordon Brown’s emails may have been hacked.

Top 5 Stories

News

RockYou users display poor password skills

21 January 2010

Social media site RockYou may be the subject of a lawsuit from disgruntled customers after it allowed 32 million of their accounts to be compromised, but new data suggest that many of its users are equally unsavvy when it comes to security, especially password security.

Database security firm Imperva obtained a list of the records exposed during the account breach, and analyzed them to see which passwords showed up the most. After crunching the numbers, it found that only 0.2% of RockYou's compromised customers were using what NASA would describe as a strong password.

Its report highlighted a predictably obvious set of entries topping the list of most commonly used passwords:

  1. 123456
  2. 12345
  3. 123456789
  4. Password
  5. iloveyou
  6. princess
  7. rockyou
  8. 1234567
  9. 12345678
  10. abc123

A total of 290 731 RockYou users used "123456" as their password, with over 155 000 using a password of either "12345" or "123456789". Amazingly, over 61 000 RockYou users had the word "Password" as their password.

Not only does this make dictionary attacks viable – in which common words and phrases are used to try and break into accounts – but it also makes other types of attack possible.

"The shortness and simplicity of passwords means many users select credentials that will make them susceptible to basic forms of cyber attacks known as 'brute force attacks'", said the company in a statement. Brute force attacks simply try every combination of digits in a word of a given length until it finds the right match. Thirty percent of users chose a password with six characters or less, Imperva's report said.

RockYou, which develops applications for social network sites such as Facebook and MySpace, reported the breach in December. It advised users that it would be taking measures to prevent the problem from happening again. Notably, it said that it would encrypt the paswords that it stored, upgrade legacy platforms, and review current data security practices. RockYou is now the subject of a lawsuit from angry customers.

Imperva recommended using a password of at least eight characters in the report on RockYou's password distribution. It also suggested using a mixture of different character types, such as upper and lower case letters, along with numbers, and symbols. 

This article is featured in:
Internet and Network Security

 

Comment on this article

You must be registered and logged in to leave a comment about this article.