Feeds

Passwords? We don't need no stinking passwords

Some PINs never change

  • alert
  • submit to reddit

SANS - Survey on application security programs

RSA 2005 Concerns over online security are continuing to slow consumer e-commerce growth. A quarter of the respondents in a recent survey have reduced their online purchases in the past year and 21 per cent refuse to conduct business with their financial institutions online because of security fears. More than half (53 per cent) of the 1,000 consumers quizzed believe that basic passwords fail to provide sufficient protection for sensitive personal information.

According to the RSA Security-sponsored telephone survey, poor management of PINs and passwords for access to online services, desktop computer systems, ATMs and other electronic accounts is a major vulnerability. As a major supplier of two-factor authentication products and services that offer an alternative to traditional static passwords, the issues raised by RSA Security's survey are more than a little self-serving. That doesn't mean its analysis is necessarily wrong, though. More and more security experts are lining up against the use of static passwords for e-banking; in part because the technique makes consumers easy prey for phishers. Even so, obituaries for the humble password may be premature.

Adi Shamir, professor at Israel's Weizmann Institute of Science and noted cryptographer, said: "Passwords are not completely dead. For low level security apps they are still sufficiently good. It depends on the application".

One PIN to rule them all

More than two in three respondents (65 per cent) quizzed in RSA Security's survey use fewer than five passwords for all electronic information access and 15 percent use a single password for everything. These figures are unchanged from a similar survey last year.

John Worrall, VP of worldwide marketing at RSA Security, said: "The majority of consumers are aware of the problems associated with passwords, but until they are presented with a reliable, easy-to-use alternative, they're going to continue to exhibit poor password management practices." ®

Related stories

RSA cosies up to AOL as VeriSign enters token market
Stunned pundit agrees with Gates over passwords
Women are crap with PIN numbers - shock survey
Brits are crap at password security
Passwords are passport to theft

RSA 2005

All the Reg stories from this year's conference

High performance access to file storage

More from The Register

next story
Obama allows NSA to exploit 0-days: report
If the spooks say they need it, they get it
Putin tells Snowden: Russia conducts no US-style mass surveillance
Gov't is too broke for that, Russian prez says
Snowden-inspired crypto-email service Lavaboom launches
German service pays tribute to Lavabit
Mounties always get their man: Heartbleed 'hacker', 19, CUFFED
Canadian teen accused of raiding tax computers using OpenSSL bug
Heartbleed exploit, inoculation, both released
File under 'this is going to hurt you more than it hurts me'
Arts and crafts store Michaels says 3 million credit cards exposed in breach
Meanwhile, Target investigators prepare for long process in nabbing hackers
Canadian taxman says hundreds pierced by Heartbleed SSL skewer
900 social insurance numbers nicked, says revenue watchman
prev story

Whitepapers

SANS - Survey on application security programs
In this whitepaper learn about the state of application security programs and practices of 488 surveyed respondents, and discover how mature and effective these programs are.
Combat fraud and increase customer satisfaction
Based on their experience using HP ArcSight Enterprise Security Manager for IT security operations, Finansbank moved to HP ArcSight ESM for fraud management.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Top three mobile application threats
Learn about three of the top mobile application security threats facing businesses today and recommendations on how to mitigate the risk.
3 Big data security analytics techniques
Applying these Big Data security analytics techniques can help you make your business safer by detecting attacks early, before significant damage is done.