75 Percent of Individuals Use Same Password for Social Networking and Email
securityweek.com
securityweek.com
Barring super-secure sites like banks, if you have the email password, you have every 'forgot my password' link available - which will typically either let you reset the password, locking the user out, or even send you the password itself!
This fact made me stop caring too much about varying individual 'random site' passwords - I just make sure to use a unique for my email.
I take the name of the website I'm visiting as the input for the hash.
Probably not the safest method of creating passwords, but it's practical in that I get a unique password per site... and I access my list of unique passwords anywhere I go.
But given a seemingly random string of characters, is it easy to deduce the exact hash function that I use?
That is a pretty strong case of using an OAuth account that can show you everything that is authorized. I have no idea how many old "jaxn" accounts from the Web2.0 phase are active and forgotten.
I would imagine that 75% figure is pretty close to the percentage of people who use the same password for pretty much everything. I would also imagine that at least 75% of HNers are in the other 25%.
Of course this is probably not the best technique, but its probably secure enough. In addition, I do use alternate passwords for sites that I don't trust. So, for example, I would never use a permutation of my email password for a random site on the internet.
(ftp, cpanels and other client info excluded)
Although KeePass is annoyingly fussy about concurrent access to the database. I should investigate if there are other options that also will work across Linux, Mac, iOS, Android, and Windows.
Linux - KeePassX Win 7 - KeePass iOS - MyKeePass {manually updated from database in Dropbox) Blackberry - KeePass for Blackberry (manual update of database)
I've luckily not had issues with concurrent database access.
(Doesn't help
Level 1: Social networks, forums, etc. simple 8 character alphanumeric.
Level 2: iTunes, ebay, amazon. Longer alphanumeric with variations unique to each site.
Level 3: Paypal, email, banking. Longer alphanumeric + special characters and completely unique for each site.
Others: Some sites, like my ISP and bank send the password only by snail mail (I had to change my password once for DSL. It was not pretty). This goes into a lockbox.
I'm looking into applications like 1Password.
If you're an Emacs user, as of version 23 or so GNU Emacs can transparently read and write GnuPG-encrypted .txt.gpg (or .org.gpg, or...) files. Not that there aren't plenty other ways to save encrypted text, but it's nice to have something that's integrated into the program you spend half your time in anyway...
If you use Windows but not Emacs, Steganos LockNote is a free, minimalist program offering symmetric AES encryption — it's a standalone .exe containing both the program and your data, so you just double-click on the .exe "document" to open your encrypted file in a Notepad-like interface. I doubt it has been vetted to the extent that GnuPG has, but it's surely enough to keep your average laptop thief from getting all your passwords.
A few months ago I started using KeePass for storing everything, and it's worked out really well for me (I wrote a post about it, plus some tips n' tricks, here: http://www.loopycode.com/solving-sign-up-anxiety/.)
I can put a 32-character alphanumeric string as my answer to "what is your mother's maiden name?" or "what city were you born in?" and store the answers in the KeePass entry.
The only downside is that since I also create a unique email address for everything, it can become a bit tedious to sign up for a new service and generate the email address and password.
http://agilewebsolutions.com/products/1Password
Absolutely fantastic.
Most people aren't aware of the dangers, though. Are you?
PclarkGmail123$%^I am under the impression direct, targeted attacks are pretty rare, and that most of the purpose of a password is to prevent wide-spread automated attacks.
There are ample examples on the Internet on how hackers manage to exploit one vulnerability, obtain a password, and then cause all sorts of damage since people tend to use the same password almost everywhere.
Getting someone's information and exploiting it has become so easy with social networking, it is frightening. This article http://l.niden.net/identitytheft demonstrates how someone can use your social circle to steal your identity. It is definitely not a far fetched story - it is reality and most people seem to ignore it.
Let us not forget the debacle of Rock You (http://l.niden.net/rockyou-cleartextpasswords) where they were storing passwords in clear text. Once the hacker got in, he had everyone's password for that service and for many others I'm sure.
I would be very interested to see what is the percentage of Facebook users that use passwords like: 'password', '123456', 'letmein' etc. I know my brother in law was one of them....
I wonder if any people from that 75% have heard of services like LastPass? (http://lastpass.com).