Tag Archive for Star Wars

Passwords That Won’t Keep You Safe

These Passwords Won't Keep You Safe OnlineI could not let 2021 wrap up without the annual look at the OMG WTF are they thinking worst passwords list. I have been covering the sorry-state of passwords since 2010 and unfortunately little has changed. The biggest change has come in the increased number of mega-breaches leaking passwords all over the Intertubes.

Nordpass logoHere is NordPass’s 2021 list. Nordpass and independent cybersecurity researchers evaluated a database with 4 terabytes’ worth of data. You can visit the NordPass website to see all 200 of the entries from 2021. But here are the top 25 most common passwords:

2021's Worst Passwords

2021's 25 worst passwords compiled by Nordpass.
RankPasswordChange from 2020
1123456-
2123456789-
312345+5
4qwerty+8
5password(1)
612345678-+1
7111111(2)
8123123(2)
91234567890(1)
101234567+1
11qwerty123New
12000000+3
131q2w3eNew
14aa12345678New
15abc123(2)
16password1+3
171234(1)
18qwertyuiop+6
19123321+4
20password123New
211q2w3e4r5tNew
22iloveyou(5)
23654321+1
24666666New
25987654321New

Bad password factoids

  • The top 25 bad passwords can be cracked in less than 1 second by a bot (or person) according to Nordpass.
  • different types of passwords94% of the most frequent passwords – can be cracked in less than 10 seconds
  • The most secure password “myspace1” ranked #54 on the list. It was used by 1,619,027 users and can be cracked in 3 hours.
  • The most popular sport on the list is “football.” It ranked #60 and was used by 1,468,381 users.
  • Superman” protected 1,180,436 accounts. He ranked 81st but could be cracked in less than 1 second.
  • The most popular movie on the list was “starwars.” 701,474 users tried to use the Force to protect their accounts. Unfortunately the Force is not strong with this one, it could be cracked in less than 1 second.

Password risk index

The NordPass researchers also devised a risk index based on the number of passwords leaked in each country per capitaRussia came in first with an astounding 19.9 passwords leaked per capita. Other counties that leaked the most passwords are:

  • The Czech Republic 6.2,
  • France 6.0,
  • Germany 5.8,
  • U.S. 5.2,
  • Italy 4.4,
  • Canada 3.6,
  • Australia3.3
  • and Poland 3.6.

rb-

You can test the strength of your password by visiting this site and typing it in. They claim the site isn’t creating a repository of passwords because your information is never sent over an internet connection. The best part? As you type, the software tells you approximately how long it would take a computer to figure out your password. The site turns red if your password is weak but slowly turns green as you make it stronger. It’ll even give you tips on how to improve your password security.

 

Stay safe out there!

Related article

 

Ralph Bach has been in IT long enough to know better and has blogged from his Bach Seat about IT, careers, and anything else that catches his attention since 2005. You can follow him on LinkedInFacebook, and Twitter. Email the Bach Seat here.

Celebrities You Shouldn’t Google in 2019

Celebrities You Shouldn't Google in 2019It is time once again for McAfee’s annual search for the most dangerous celebrity online. The 2019 version of the cyber-security firm’s research found which celebrities’ internet searches expose users to the most risk from malicious websites, malware, and ransomware, and other risky outcomes. McAfee says that criminals use deceptive websites to dupe unsuspecting consumers into accessing malicious files or content.

McAfee logoMcAfee crowned actress Alexis Bledel the riskiest celeb online for 2019. Searches for the actress, known for her role as Rory Gilmore. in the TV show Gilmore Girls landed the most users on risky websites that carry viruses or malware in 2019.

McAfee speculates that the Texas-born Bledel’s role as Ofglen in the fan-favorite Hulu series “The Handmaid’s Tale” and big-screen role in the “Sisterhood of the Traveling Pants” movies led to her top ranking.

Alexis Bledel is McAfees 2019 riskiest celeb onlineThe actress takes over the number one spot from Ruby Rose, who topped last year’s list mainly because of fans’ interest in her playing Batwoman.

The second most dangerous celebrity online was British comedian and actor and host of the Late Late Night show, James Corden. The popularity of viral videos from the Late Late Show gives attackers more options to spread their malware.

Sophie Turner made the list at number 3. She has been trending lately due to her role on “Game of Thrones,” as well as her relationship with singer Joe Jonas.

Lupita Nyong'o is McAfees 5th riskiest celeb onlinePitch Perfect series’ actress Anna Kendrick reached 4th place.  She was followed by Lupita Nyong’o as the 5th riskiest position on the risky celebrity list. McAfee speculates that interest in “Star Wars: The Rise of Skywalker” put Ms. Nyong’o on the list.

Comedian, former SNL star, and current Tonight Show host Jimmy Fallon is ranked number 6. Viral videos from Tonight Show are popular with threat actors.

Martial arts master Jackie Chan, who came in at 7. McAfee  explained that rumors circulated about his return to the big screen in “Rush Hour 4” and “The Karate Kid 2.” His team denied the gossip, but cyber-criminals took advantage of fans’ nostalgia to spread their malware.

Rappers take the #8 and 9 positions on McAfee’s list. Lil Wayne was named the eighth most dangerous driven by his summer tour with Blink-182  and fans search for illegal downloads. Nicki Minaj came in at 9. She caused many of her fans to panic in September after she tweeted she was retiring from music and attackers took advantage of her fans’ quest for more information by poisoning her searches.

Tessa Thompson is McAfees 10th riskiest celeb onlineTessa Thompson, known for her role as ValkyrieMarvel’s first LGBTQ superhero, was listed as the number 10 riskiest popular search term this year thanks to her leading roles in “Men in Black: International” and “Avengers: Endgame.”

Cyber-criminals also use the same celebrity-baiting tactics internationally. According to McAfee, the most dangerous online celebs around the world are:

Gary Davis, chief consumer security evangelist at McAfee explained the risks involved with searches for these celebrities.

Camila Cabello is McAfees riskiest celeb online in SpainConsumers may not be fully aware that the searches they conduct pose risk, nor may they understand the detrimental effects that can occur when personal information is compromised in exchange for access to their favorite celebrities, movies, TV shows, or music

He warns celebrity seekers to be cautious.

It is essential that consumers learn to protect their digital lives from lurking cyber-criminals by thinking twice before they click on suspicious links or download content.

rb-

Cord-cutting could be driving some of this risky behavior. McAfee found that the names of the risky celebs like Bledel, Fallon, and Chan are strongly associated with searches including the term “torrent.”

These users are bypassing the subscription services like Hulu and Amazon to save a few bucks put their digital lives at risk in exchange for pirated content.

Related article

 

Ralph Bach has been in IT long enough to know better and has blogged from his Bach Seat about IT, careers, and anything else that catches his attention since 2005. You can follow him on LinkedInFacebook, and Twitter. Email the Bach Seat here.

Worst Passwords – 2017

Worst Passwords - 2017Today is “Safer Internet Day” which is needed. Despite the spate of well-publicized hacks, attacks, ransoms, and even extortion attempts, millions of people continue to use weak, easily guessable passwords to protect their online information. SplashData, provider of password management applications has released its annual Worst Passwords of the Year (NSFW) list. The seventh annual report was compiled from more than five million passwords leaked during 2017.

FSplashData logoor the fourth consecutive year, “123456” and “password” held on to the number 1 and #2 spots on the SplashData list. Variations of each, either with extra digits on the numerical string or replacing the “o” with a “0” in “password,” make up six of the top 10 most often used passwords. Morgan Slain, CEO of SplashData warns, “Hackers know your tricks, and merely tweaking an easily guessable password does not make it secure.

Star Wars is popular

Star Wars fans were so excited by the recent premiere of “Star Wars: The Last Jedi“, that they moved “starwars” up to #16 on the most frequently used bad passwords list. SplashData’s Slain observed that it is not a good password.

Unfortunately, while the newest episode may be a fantastic addition to the Star Wars franchise, ‘starwars’ is a dangerous password to use … Hackers are using common terms from pop culture and sports to break into accounts online because they know many people are using those easy-to-remember words.

Another problem with many of these bad passwords, they are simply a straight row of characters across the keyboard making them easy for attackers to guess. Pattern passwords in the bad list include:

  • Password12345
  • 123456
  • 1234567
  • 12345678
  • 123456789
  • qwerty
  • qazwsx
  • 1qaz2wsx

SplashData’s 25 worst passwords of 2017:

1 – 123456
2 – password
3 – 12345678
4 – qwerty
5 – 12345
6 – 123456789
7 – letmein
8 – 1234567
9 – football
Sisyphus10 – iloveyou
11 – admin
12 – welcome
13 – monkey
14 – login
15 – abc123
16 – starwars
17 – 123123
18 – dragon
19 – passw0rd
20 – master
21 – hello
22 – freedom
23 – whatever
24 – qazwsx
25 – trustno1

SplashData estimates almost 10% of people have used at least one of the 25 worst passwords on this year’s list, and nearly 3% of people have used the worst password, 123456.

SplashData offers these tips to be safer from hackers online:

1. Use passphrases of twelve characters or more with mixed types of characters including upper and lower cases.
2. Use a different password for each of your website logins. If a hacker gets your password they will try it to access other sites.
3. Protect your assets and personal identity by using a password manager to organize passwords, generate secure random passwords, and automatically log into websites.

rb-

Sighs – I covered this again and again ……

One older report I’ve seen says that attackers were able to crack open 254,776 of 499,556  (51%) hashed passwords within 24 hours and 439,610 (88%) within two weeks. The same report says that it can only take one day to crack an eight-character password, while it takes an average of 591 days to crack a 10 character password. 

Another report on password hacks points out the value of each additional character in a password.

  • A 6-character password with only letters has 308,915,776 possible combinations.
  • An 8-character password with only letters has 208,827,064,576 possible combinations.
  • An 8-character password with letters (upper & lower case) and includes numbers and symbols has 6,095,689,385,410,816 possible combinations.

Related article

 

Ralph Bach has been in IT long enough to know better and has blogged from his Bach Seat about IT, careers, and anything else that catches his attention since 2005. You can follow him on LinkedInFacebook, and Twitter. Email the Bach Seat here.

2015’s Worst Passwords

2015's Worst PasswordsFollowers of Bach Seat know that passwords suck. For even more proof that passwords suck, the password-management company SplashData released its fifth annual list of the most popular passwords. SplashData studied more than 2 million passwords that were leaked in 2015 and identified the most commonly leaked passwords and those that were least secure from Western European and North American users according to Business Insider.

2015’s worst passwords

SplashData logoMost of the 2015 results are not surprising.

  • 123456 is the most common password. It has been #1 since 2013.
  • Password is the second most common password. It too has been #2 since 2013. Password was the most common password in 2012 and 2011.
  • 12345678 is the third most common password found in the Splash data results. In fact, 12345678 has been the most consistent performer, having been in the #3 place four of the past five years.

One surprise was that the Disney marketing machine was able to get Star Wars related terms into the top 25 worst passwords in 2015.

  1. princess
  2. solo
  3. starwars

Here’s SplashData’s full list. If your password is on here, think about changing it.

25 Worst passwords

20152014201320122011
1123456123456
123456
password
password
2passwordpasswordpassword123456
123456
3123456781234512345678
12345678
12345678
4qwerty12345678
qwerty
1234
qwerty
512345qwertyabc123qwertyabc123
612345678912345678912345678912345
monkey
7football1234
111111dragon
1234567
81234baseball
1234567pussy
letmein
91234567dragoniloveyou
baseball
trustno1
10baseballfootballadobe123
football
dragon
11welcome1234567123123
letmein
baseball
121234567890 monkey
admin
monkey
111111
13abc123letmein
1234567890
696969
iloveyou
14111111abc123
letmeinabc123
master
151qaz2wsx111111photoshopmustang
sunshine
16dragonmustang1234michaelashley
17masteraccessmonkey
shadow
bailey
18monkeyshadow
shadowmasterpassw0rd
19letmeinmastersunshinejennifer
shadow
20loginmichael
12345
111111
123123
21princesssupermanpassword1
2000
654321
22qwertyuiop696969princessjordansuperman
23solo123123azertysupermanqazwsx
24passw0rdbatmantrustno1harleymichael
25starwarstrustno10000001234567football

 

Protect yourself

keep your passwords secureTo keep your passwords secure, you definitely shouldn’t use any of the passwords on the list.

SplashData offers three simple tips to help people protect themselves:

  1. Use passwords or passphrases of twelve characters or more with mixed types of characters;
  2. Avoid using the same password over and over on different websites
  3. Use a password manager such as SplashID to organize and protect passwords, generate random passwords, and automatically log into websites.

rb-

What to do if you are responsible for securing systems where your users use these passwords? Stop Them!

This is what makes passwords suck – Implement complexity rules:

  • Minimum of 8 characters
  • A mix of characters, UPPER CASE, lower case, numbers, and special characters.
  • Prevent reusing passwords
  • Blacklist all the above passwords so they can never be used again.
Related articles

 

Ralph Bach has been in IT long enough to know better and has blogged from his Bach Seat about IT, careers, and anything else that catches his attention since 2005. You can follow him on LinkedInFacebook, and Twitter. Email the Bach Seat here.

May the Fourth Be With You

May the Fourth be With You

 

 

Ralph Bach has been in IT long enough to know better and has blogged from his Bach Seat about IT, careers, and anything else that catches his attention since 2005. You can follow him on LinkedInFacebook, and Twitter. Email the Bach Seat here.