Many Faces of TimRSS Icon

Please stop using the same passwords!!!

A scary 92% of people use the same password across all websites including their email accounts this is the finding of a short research project we did for a client recently.

92% is a scary statistic here how we got it

Over the last 6 months we have been working with two clients to experiment with their security authentication methods our first issue was to see if what the issues was, one of the questions asked was do people use the same passwords across multiple sites.

So we set up a very simple test using several websites registration processes, we identified users who's email address were yahoo, gmail, hotmail and a few of the smaller free email providers. Next we added a special terms and condition box (this was in addition to the normal terms and conditions) which they needed to opt into but was not defaulted to nor a requirement. We tried very hard to make sure what we were going to do was utterly transparent, to our surprise the opt-in rate was nearly 70% we can only assume people were blind clicking.

Why do we think they were Blind Clicking because they just agreed to:

Give xxxxxx permission to attempt to login to your mail account using the details you provided, no mail or contact details will be collected and no personal identifiable information will be stored about this attempt. Please be aware allowing this action maybe in breach of the terms of service for your email provider and could cause discontinuation of your service. xxxxxx will not be held liable in such cases.

We then provided a link with more explicit information on what we were planning on doing and all the legal arse covering bits. now we had just over 2000 "volunteer" that link was clicked just twice and one of them then went and agreed to it! Sadly as the data is dissociated with the account we have no way of knowing if that person did it because he knew it would be a failed login or not.

Once we had their permission we used a simple bot to attempt to login, storing successful logins in a database identifiable only by an ID and the mail server we never stored who's email it was which is just as well as it would have been a privacy nightmare.

Our Registration pages were split into two types, one that required at minimum a weak password and ones that required alpha numeric password of more then 8 characters.

Finally we surveyed 1 in 10 about their email and password habits.

Gmail users the worst at password protection

With a little over 93% of the passwords working with their Gmail accounts, it would appear Gmail password users are the laziest of those we tested, though the figure dropped to 89% when a stronger password was required.

Yahoo Mail users have shocking memories

That's the conclusion we reached as they were the only user group where the secure password sites had a higher % of successful logins then the weak account 91% vs 90% which is strange because it has only been recently that YMail has had any decent requirement for password strength.

Hotmail passwords most secure, surely not!

It's true Hotmail users came out best but we are pretty sure we know why, in the follow up survey almost a third of Hotmail users claimed they believed their account had been hacked.

Oh and users lie about their password habits

We all know security and regularly changing and different passwords is important which is probably why only 42% of people asked admitted to using the same password on both email and the site they registered on.

So couple of take away points, people really really do not read terms and conditions and for god sake use a different password for your email to the one you use to register at free sites!

Go change it now...

update As if to reinforce the point news at thousands of Hotmail passwords being posted online is announced.

Quickly Linking?

If you want to link to this post quickly please use: http://tnash.eu/t390

alternativly use one of these services Tiny URL | bit.ly |is.gd

RSS feed | Trackback URI | Add your comment!

6 Comments »

Comment by Alistair MacDonald from Alistair\'s blog
2009-10-02 12:06:55
Alistair MacDonald avatar

I can honestly say that my Gmail password is unique. All my commonly used passwords are, but Gmail, banking passwords, and DNS related passwords are more random. I am also very very reluctant to give those password to 3rd partys and have no problem in emailing them to let them know that.

That being said when I sign up to a lot of beta services to try them out I use a standard password. If I use the service seriously then I change it. There is only just so much space in my head.

This is a big problem. Recently when setting up services for my family I have been told to use passwords that “I use for everything”. Even when the site requires a more complex password or frequent changing numbers are normally added, and predictable.

I honestly don’t believe enforcing more complex passwords is the solution. It only reduced the uniqueness by 4%, and I bet if the other sites imposed the same restrictions they would be the same again. This also increases the need for people to write the password down, normally in an obvious location.

My favoured solution to this is to first educate the user, and when that fails look at a more hardware based security key solution. If Google, Yahoo, and Microsoft adopted the same technology then there is a realistic possibility it would work. Now you must excuse me, I need to get back to cloud cuckoo land. ;-)

 
Comment by Bill Marshall from SpiderWriting
2009-10-09 14:34:50
Bill Marshall avatar

This highlights an increasing problem in modern society, not just on the web. We have passwords and PINs for just about everything.

How many bank cards do you have? Hmm, 2 credit cards, a debit for each of about 5 current and investment accounts, a business account. And I suspect others will have more than that with store cards and suchlike. How do you store the PINs? What do you mean you’re not supposed to store them anywhere – can you remember 8 different numbers reliably?

Websites; far too many to think about. Do I get the browser to save them all and risk someone stealing them from malware hacking my machine? If not do I note them all down somewhere and risk that being found? Maybe the only way is to use a standard password for all the non-critical sites and only use unique ones for the most important ones like bank accounts. But even then it’s a nightmare trying to keep track of them all – the human memory just isn’t up to the job, particularly with accounts that you maybe only access once or twice a year.

We are nowhere near a satisfactory solution to this and until we are users will continue to use soft and/or universal passwords. I hate to say it but only something like iris recognition can improve matters unless someone comes up with a master password system that is truely uncrackable – and I’m not at all sure that’s possible. But I don’t like the implications of what iris tracking might let loose.

 
Comment by Niall Harbison from www.simplyzesty.com
2009-10-22 23:03:52
Niall Harbison avatar

I have always wondered about this and the fact that once you crack one password you have access to pretty much everything people do online. The bggest problem is that I have 100s of online accounts and no way of keeping track of them all. I know pen ID is a good start but why isn’t there a better system for logging in?

 

Responses to this post:

dont be an idiot, use a real name and all comments are moderated
Name Your name not your website(required)
E-mail (required - never shown publicly)
Website address (URL)
Web site name will be used as link text
Your Comment (smaller size | larger size)
You may use <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong> in your comment.
Spam protection: Sum of three + 7 ?
Tim Nash consulting