IMPERVAious to common sense

Opinion
Jan 27, 20102 mins

The awful truth about passwords

One of my favorite correspondents is Nahum Goldmann of Array Development in Ottawa, Canada and publisher of the Journal of Internet Banking and Commerce and other peer-reviewed publications. Goldman never fails to send out interesting links and commentary, and recently he pointed to a valuable research study that I think will significantly help system administrators in reaching users on the perennial battle over passwords.

In December 2009, 32 million passwords stored without encryption on the Rockyou.com Web site were stolen and published on the Web for anyone to see. The security firm IMPERVA published a thorough analysis of these passwords to see how a large sample of users – not just those responding to a survey – actually manage their personal authentication.

The results were not good.

The five-page report is confirmation that passwords are a terrible way to authenticate people. Users chose short, simple passwords that would be easy to crack using brute force; nearly half “used names, slang words, dictionary words or trivial passwords (consecutive digits, adjacent keyboard keys, and so on). The most common password among Rockyou.com account owners is ‘123456’.”

The authors provide clear pie charts and bar graphs to make their point in a way that anyone can understand, including scoffers who consistently sneer at the security team’s attempts to improve password complexity.

The last page has simple, clear advice that may reach at least some of your users:

1. Choose a strong password for sites you care for the privacy of the information you store. Bruce Schneier’s advice is useful: “take a sentence and turn it into a password. Something like “This little piggy went to market” might become “tlpWENT2m”. That nine-character password won’t be in anyone’s dictionary.”

2. Use a different password for all sites – even for the ones where privacy isn’t an issue. To help remember the passwords, again, following Bruce Schneier’s advice is recommended: “If you can’t remember your passwords, write them down and put the paper in your wallet. But just write the sentence – or better yet – a hint that will help you remember your sentence.”

3. Never trust a third party with your important passwords (webmail, banking, medical etc.).

The advice for administrators is also worth discussing at your next security group meeting.

The PDF file is free, simple to distribute, and attractive. What have you got to lose?