Close Menu
GeekFenceGeekFence
    Facebook Instagram
    Facebook Instagram
    GeekFenceGeekFence
    • Home
    • Contact Geekfence
    • Computing

      Apple kerfuffles, praise groups, and media layoffs

      2019-03-17

      Podcasts, smart speakers soar as social media stalls, based on new survey

      2019-03-07

      Security token offerings aren’t looking much better in 2019

      2019-03-04

      How far are you willing to go for growth?

      2019-03-03

      Can we ever evaluate technical debt?

      2019-02-28
    • Business

      Top 10 Tech Companies in the World

      2024-01-04

      Soar into the New Year: Inspirational Quotes to Elevate Your Spirit

      2023-12-31

      Non-invasive glucose monitor EasyGlucose takes home Microsoft’s Imagine Cup and $100K

      2019-05-12

      Google opens Android Automotive OS to Spotify, other media app developers

      2019-05-02

      Kiwi’s food delivery bots are rolling out to 12 more colleges

      2019-04-30
    • Entrepreneur

      Decade in review: Trends in seed- and early-stage funding

      2019-03-18

      Apple kerfuffles, praise groups, and media layoffs

      2019-03-17

      NVIDIA and OpenAI’s capped returns

      2019-03-13

      Can we ever evaluate technical debt?

      2019-02-28

      #LetYourBrandReign SME Business Networking Series Inauguration Successfully Kicks Off

      2019-02-12
    • Electronics

      Disc-free Xbox One S could land on May 7th

      2019-04-24

      TP-Link EAP225-Outdoor Review

      2019-04-23

      Flying taxis could be more efficient than gas and electric cars on long-distance trips

      2019-04-10

      GPS Rollover is today. Here’s why devices might get wacky

      2019-04-08

      Tonal raises $45 million to bring strength training to more living rooms

      2019-04-07
    • Mini-Stories

      Non-invasive glucose monitor EasyGlucose takes home Microsoft’s Imagine Cup and $100K

      2019-05-12

      LEGO Braille bricks are the best, nicest and, in retrospect, most obvious idea ever

      2019-04-29

      Resurgent HappyFresh raises $20M for its online grocery service in Southeast Asia

      2019-04-22

      Tonal raises $45 million to bring strength training to more living rooms

      2019-04-07

      Alcatraz AI is building Face ID for corporate badges

      2019-04-03
    • Mustreads

      Is this the vertical-folding Motorola Razr?

      2019-05-01

      LEGO Braille bricks are the best, nicest and, in retrospect, most obvious idea ever

      2019-04-29

      Avengers Endgame – A Love letter to the MCU

      2019-04-28

      Flying taxis could be more efficient than gas and electric cars on long-distance trips

      2019-04-10

      Camera maker Insta360 raises $30M as it eyes 2020 IPO

      2019-03-21
    GeekFenceGeekFence
    Home»Computers»Surprise! Top sites still fail at encouraging non-terrible passwords
    Computers

    Surprise! Top sites still fail at encouraging non-terrible passwords

    geekfencebloggerBy geekfenceblogger2018-07-20No Comments4 Mins Read0 Views
    Facebook Twitter Pinterest LinkedIn Telegram Tumblr Email
    Share
    Facebook Twitter LinkedIn Pinterest Email

    You would think that Amazon, Reddit, Wikipedia and other highly popular websites would by now tell you that “password1” or “hunter2” is a terrible password — just terrible. But they don’t. A research project that has kept tabs on the top sites and their password habits for the last 11 years shows that most provide only rudimentary password restrictions and do little to help users.

    Steven Furnell, of the University of Plymouth, first did a survey of websites’ password practices in 2007, repeating the process in 2011 and 2014 — and then once more this week. His conclusions?

    It is somewhat disappointing to find that the overall story in 2018 remains largely similar to that of 2007. In the intervening years, much has been written about the failings of passwords and the ways in which we use them, yet little is done to encourage or oblige us to follow the right path.

    Although the university writeup notes that Google, Microsoft and Yahoo had the best password practices and Amazon, Reddit and Wikipedia had the worst, it diplomatically declined to go into specifics. Fortunately, I acquired the paper for myself and am prepared to name and shame.

    The top 10 unique sites in English (as measured by Alexa; the lineup has changed somewhat over the years) were evaluated: Google, Facebook, Wikipedia, Reddit, Yahoo, Amazon, Twitter, Instagram, Microsoft Live and Netflix.

    The biggest failure is inarguably Amazon, which combines truly inadequate password controls with an incredibly valuable and personal service. Wikipedia and Reddit had fewer restrictions, but neither protects such important data; an Amazon account being accessed by malicious actors is a far greater danger.

    Amazon accepted practically every password Furnell threw at it, including repeats of the username, the user’s own name and, of course, the all-time classic, “password.” (Netflix and Reddit also took “password,” though Wikipedia didn’t. Wikipedia, on the other hand, accepted single-character passwords like “b.”)

    Even sites that do have restrictions, like requiring multiple character types or rejecting commonly used passwords, seldom explain themselves. Presented with no feedback at the start, users creating an account may enter a password, only to be told it must be longer… and then, again, that it can’t have a certain word (like the user’s last name)… and then, again, that it must include special characters. And some sites have different requirements when you sign up than when you set a new one!

    Why not lay it all out at the start? And for that matter, why not explain the reasoning behind it? It’d be trivial to make a little info box saying “We require X because Y.” But hardly any of the top sites do.

    The one bit of light in this dreary report is that two-factor authentication — arguably more important than a good password — is in fact making strides, and some of the worst offenders in password policy (looking at you, Amazon) allow it. Now they just have to move it off of SMS and onto a secure authenticator app.

    The final word is pretty the same as it’s been for the last decade:

    The basic argument here – as with the earlier versions of the study and the others referenced – is for provision of user-facing security to be matched with accompanying support. Passwords are a good example because we know that many people are poor at using them. And yet the lesson continues to go unheeded and we continue to criticise the method and blame the users instead.

    Two-factor is a start, but:

    Users arguably require more encouragement – or indeed obligation – to use them. Otherwise, like passwords themselves, they will offer the potential for protection, while falling short of doing so in practice.

    In other words, quit talking about how bad passwords are and do something about it!

    gadgets tech tech crunch
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    geekfenceblogger

    Related Posts

    Top 10 Tech Companies in the World

    2024-01-04

    Exploring the Year: 5 Tech Trends in 2023

    2023-12-30

    Disc-free Xbox One S could land on May 7th

    2019-04-24

    TP-Link EAP225-Outdoor Review

    2019-04-23

    Flying taxis could be more efficient than gas and electric cars on long-distance trips

    2019-04-10

    GPS Rollover is today. Here’s why devices might get wacky

    2019-04-08

    Comments are closed.

    Latest Post

    Unveiling the Architecture Behind OpenAI’s Language Models: The Power of GPT-3

    2024-01-05

    Top 10 Tech Companies in the World

    2024-01-04

    Wanna Lose Weight: Your How to Lose Weight Guide

    2024-01-02

    How to make new year resolutions last?

    2024-01-02
    Stay In Touch
    • Facebook
    • Instagram

    Unveiling the Architecture Behind OpenAI’s Language Models: The Power of GPT-3

    2024-01-05

    In the ever-evolving landscape of artificial intelligence, OpenAI has been at the forefront of cutting-edge…

    Top 10 Tech Companies in the World

    2024-01-04

    Here’s a more inspirational perspective on some of the leading tech companies that are shaping…

    Wanna Lose Weight: Your How to Lose Weight Guide

    2024-01-02

    Losing weight is not just about changing your appearance; it’s about transforming your life and…

    How to make new year resolutions last?

    2024-01-02

    Embarking on a journey of self-improvement through New Year’s resolutions is a powerful and transformative…

    GeekFence
    Facebook Instagram
    © 2025 Geekfence. All Right Reserved

    Type above and press Enter to search. Press Esc to cancel.