ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Hackers steal easily guessed passwords

Andy McCue silicon.com

Published: 23 Oct 2003 13:05 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Hackers are increasingly resorting to social engineering techniques to obtain confidential passwords, as businesses become better at locking down and patching their computer networks.

And the bad news is that users are still very much the weak link when it comes to choosing and protecting their passwords, according to the results of a survey of IT security experts.

It found that 15 percent of those asked in an online questionnaire to give their network passwords in order to be entered into a prize draw happily clicked through to the page ready to divulge the information.

Paul Vlissidis, head of risk services at technology consultancy NCC Group, which carried out the survey, told silicon.com that the problem of staff -- and especially those in IT who should know better -- being lazy with passwords is leaving companies at risk.

"It is laziness and ignorance causing network security problems. Passwords are of greater importance now that remote access has increased from laptops and PCs with broadband at home," he said.

He said that social-engineering techniques used by hackers to glean passwords that will give them access to corporate networks are on the increase, as IT departments get better at protecting their systems.

"It is increasing as people wake up to other kinds of network vulnerabilities, such as patching systems, and as they narrow down areas of attack, hackers are going to run out of places to exploit and so will go for passwords."

Common bad practice includes shared passwords for departments and obvious popular passwords such as football clubs -- and Vlissidis said those in the boardroom are often the main culprits.

The advice for users is to avoid using for passwords dictionary words that can be cracked by programs, and to use a mixture of numbers and letters. One method is to choose a favourite song or poem and take the first letter from each line of the first verse along with a couple of numbers. When it comes round to change the password, just move on to the next verse.

"As long as you know what that song is, you will never forget the password," said Vlissidis.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
109 out of 218 people found this useful



Company/Topic Alerts

Create a new alert from the list below:



Related Jobs

Security Consultant Ethical Hacking / Penetration Testing - London

Responsibilities: - Deliver security assessment services including network scanning, vulnerability testing, penetration testing, search engine ...

Network Engineer - Aberdeen - Up to 50,000

The company's solutions enable customers within the oil and gas, commercial shipping, government services, engineering and construction, maritime, ...

Business Analyst / Senior Business Analyst / Windsor, South West London

A background in the energy sector, gained within industry or consultancy, preferably with experience in some of the following areas: UK Power Market, ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

The Google Apple Merger: Fantasy or Fu...

The Google Apple Merger: Fantasy or Future? Author: Eric Everson, Founder MyMobiSafe.com Market research suggests that Microsoft controls upwards of 90% of the respective computer-based... More

2 comments