article thumbnail

National Public Data Published Its Own Passwords

Krebs on Security

KrebsOnSecurity has learned that another NPD data broker which shares access to the same consumer records inadvertently published the passwords to its back-end database in a file that was freely available from its homepage until today. In April, a cybercriminal named USDoD began selling data stolen from NPD.

Passwords 341
article thumbnail

Cisco Can’t Stop Using Hard-Coded Passwords

Schneier on Security

There’s a new Cisco vulnerability in its Emergency Responder product: This vulnerability is due to the presence of static user credentials for the root account that are typically reserved for use during development. An attacker could exploit this vulnerability by using the account to log in to an affected system.

Passwords 361
Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

Easily Guessed Passwords for New Accounts Include “User”, “Temp”, “Welcome”

Security Boulevard

New account passwords, often used during onboarding, are vulnerable to sophisticated attacks from malicious actors. The post Easily Guessed Passwords for New Accounts Include “User”, “Temp”, “Welcome” appeared first on Security Boulevard. Good idea to check: What’s your company using?

Passwords 116
article thumbnail

Prevent Account Takeover with Better Password Security

The Hacker News

He has a long, complex password that would be near-impossible to guess. He’s memorized it by heart, so he started using it for his social media accounts and on his personal devices too. Unbeknownst to Tom, one of these sites has had its password database compromised by hackers and put it up for sale on the dark web.

Passwords 108
article thumbnail

Passwords Are Terrible (Surprising No One)

Schneier on Security

This is the result of a security audit: More than a fifth of the passwords protecting network accounts at the US Department of the Interior—including Password1234, Password1234!, In the first 90 minutes of testing, auditors cracked the hashes for 16 percent of the department’s user accounts. and ChangeItN0w!—were

Passwords 289
article thumbnail

Google adds passkey option to replace passwords on Gmail and other account services

Tech Republic Security

Is it the beginning of the end for passwords? The post Google adds passkey option to replace passwords on Gmail and other account services appeared first on TechRepublic. Storing passkeys directly on devices will cut down on successful phishing, Google suggests.

Passwords 165
article thumbnail

How to generate secure passwords for your accounts

Tech Republic Security

A password generator can help when you need a strong and complex password to protect an account. The post How to generate secure passwords for your accounts appeared first on TechRepublic.

Passwords 141