Forum Moderators: open
Online passwords are so insecure that 1% can be cracked within 10 guesses, according to a researcher at Cambridge University.
Gates Cambridge Trust scholar Joseph Bonneau of the university's computer laboratory was given access to 70 million anonymous passwords through internet services firm Yahoo.Using statistical guessing metrics, he trawled them for information, including demographic information and site usage characteristics.
Even people who had had their accounts hacked did not opt for passwords which were significantly more secure.
The analysis did find, however, that older users tended to have stronger online passwords than their younger counterparts. German and Korean speakers also had passwords which were more difficult to crack, while Indonesian-speaking users' passwords were the least secure.
The main finding of the research was that passwords in general contain only between 10 and 20 bits of security against an online or offline attack.
Speaking to Mrs engine, she finds it a chore to remember all the passwords, not to mention changing them.