{"id":6113,"date":"2021-12-16T11:00:00","date_gmt":"2021-12-16T09:00:00","guid":{"rendered":"https:\/\/blog.eset.ee\/?p=6113"},"modified":"2026-06-14T10:26:45","modified_gmt":"2026-06-14T07:26:45","slug":"a-recipe-for-failure-predictably-poor-passwords","status":"publish","type":"post","link":"https:\/\/blog.eset.ee\/et\/en\/2021\/12\/16\/a-recipe-for-failure-predictably-poor-passwords\/","title":{"rendered":"A recipe for failure: Predictably poor passwords"},"content":{"rendered":"<p><!\u2013 wp:paragraph \u2013><\/p>\n<p>Passwords are the bane of everyone\u2019s lives but let\u2019s face it \u2013 we all need them. And they aren\u2019t going away as fast as <a href=\"https:\/\/www.microsoft.com\/security\/blog\/2021\/09\/15\/the-passwordless-future-is-here-for-your-microsoft-account\/\">Microsoft may want them to<\/a>. For the time being, we will continue to depend on them for the unforeseeable future. You may have 50, 100, or even 200 online accounts but how many passwords do you have? Are they all unique? Well, here is one anecdote suggesting that people still only use the same few personalized passwords or <a href=\"https:\/\/www.welivesecurity.com\/2016\/05\/05\/forget-about-passwords-you-need-a-passphrase\/\">passphrases<\/a> for <em>all<\/em> of their accounts.<\/p>\n<p><!\u2013 \/wp:paragraph \u2013><\/p>\n<p><!\u2013 wp:paragraph \u2013><\/p>\n<p>I recently went to a conference hosted by a wealth management firm where they had invited me to present on cybersecurity. There were over 50 people in attendance and when I mentioned passwords, they did what so many people do when I mention the subject \u2013 they started looking around the room avoiding eye contact hoping not to be picked on. I quickly realized their body language was telling me they had poor password hygiene, so I decided to dig a little deeper and I asked them questions about their password management with some interesting responses.<\/p>\n<p><!\u2013 \/wp:paragraph \u2013><\/p>\n<p><!\u2013 wp:paragraph \u2013><\/p>\n<p>I first asked if anyone used a <a href=\"https:\/\/www.welivesecurity.com\/2020\/06\/26\/what-is-password-manager-why-is-it-useful\/\">password manager<\/a>. One member of the audience put his hand up and said it was only because he had heard one of my talks in the past (I felt so humbled!). So, 98% of the people in the room did not use a password manager or have a system in place to take care of their accounts. I then asked them how they managed their online accounts and some owned up to using the same three or four passwords and many said these passwords included personal information such as special dates or names that meant something to them (wow, yes this was a facepalm moment where I really <em>really<\/em> tried to remain calm).<\/p>\n<p><!\u2013 \/wp:paragraph \u2013><\/p>\n<p><!\u2013 wp:paragraph \u2013><\/p>\n<p>I decided to conduct a little experiment on the fly with one of the delegates. I have always found real life experiments to work wonders when \u2018in the moment\u2019 because if they work, it gets the audience members doing their homework before they go to bed that night.<\/p>\n<p><!\u2013 \/wp:paragraph \u2013><\/p>\n<p><!\u2013 wp:paragraph \u2013><\/p>\n<p>With his permission, this particular gentleman allowed me to proceed, and I quickly found him on Facebook. I located all his public content and made a list on the whiteboard of the possible passwords that I imagined he could be using. I jotted down places of interest, pets\u2019 names, children\u2019s names, dates of interest, sports teams, books, music\u2026 all the classic possibilities. I had about 20 different words and numbers in a list. This was the shocking part where I felt like I had located buried treasure.<\/p>\n<p><!\u2013 \/wp:paragraph \u2013><\/p>\n<p><!\u2013 wp:paragraph \u2013><\/p>\n<p>As he picked his jaw up off the floor, he not only said that I had found one of his passwords, but I found iterations of 3 of his 4 passwords he \u201cuses for everything\u201d. I later found out that the iterations were in fact missing a capital letter at the beginning and a number at the end (typical, hey?!). This number was always the same \u2013 the date of the month he was born. The crowd were perplexed that I had cracked his passwords. I was not. This is standard behaviour and cybercriminals know it.<\/p>\n<p><!\u2013 \/wp:paragraph \u2013><\/p>\n<p><!\u2013 wp:paragraph \u2013><\/p>\n<p>So it begs the question why anyone, especially with access to a huge amount of wealth, data and livelihoods, would still choose to use a password that is weak \u2013 on so many levels.<\/p>\n<p><!\u2013 \/wp:paragraph \u2013><\/p>\n<p><!\u2013 wp:heading \u2013><\/p>\n<h2>The future<\/h2>\n<p><!\u2013 \/wp:heading \u2013><\/p>\n<p><!\u2013 wp:paragraph \u2013><\/p>\n<p>What is the future of the password? Are we able to truly go where humans haven\u2019t properly ventured yet and attempt a true passwordless society? Or do you think, like me, that passwords actually have a place in cyber-society and, when used well, they are actually a bonus. <a href=\"https:\/\/www.welivesecurity.com\/2020\/10\/06\/had-face-stolen-lately-biometrics-data-breach\/\">Unlike biometrics<\/a>, there is no limit to how many you can have, plus you can store your passwords in a password manager and have it generate one for you. Furthermore, when used with <a href=\"https:\/\/www.welivesecurity.com\/2019\/12\/13\/2fa-double-down-your-security\/\">multi-factor authentication<\/a> such as an authenticator app or security key, the entry to an account is seamless and extremely easy for even the most entry-level user. I\u2019ve even got my parents, in their mid-70s, using password managers alongside phone-based authenticator apps for all their accounts that support it \u2013 and they can\u2019t stop telling me how easy it is!<\/p>\n<p><!\u2013 \/wp:paragraph \u2013><\/p>\n<p><!\u2013 wp:paragraph \u2013><\/p>\n<p>One breach is enough to give a hacker access to all your accounts if you <a href=\"https:\/\/www.welivesecurity.com\/2018\/05\/03\/recycling-reuse-password\/\">recycle passwords<\/a>, so you may want to keep your passwords in a safe place. Many people already use Apple\u2019s Keychain password manager or just save them in their browser. However, should your laptop or computer ever get stolen, and it is not <a href=\"https:\/\/www.welivesecurity.com\/2020\/05\/22\/how-encryption-can-help-protect-sensitive-data\/\">full-disk encrypted<\/a>, the potential hacker will still be able to be granted access with the computer even without seeing what the password is. Therefore, a third-party, cross-device password manager may be more beneficial.&nbsp;<\/p>\n<p><!\u2013 \/wp:paragraph \u2013><\/p>\n<p><!\u2013 wp:paragraph \u2013><\/p>\n<p>Another top tip to keep your data safe and away from prying eyes or data breaches is by using a feature on Apple devices where it lets you hide your email address from other parties. \u2018Sign In With Apple\u2019 lets you anonymize your email address when logging into services that support the feature. In fact, more recently there has been an upgrade where iCloud users can make use of the feature called \u2018Hide My Email\u2019. This does exactly what it says by letting you generate a single-use address that forwards incoming emails to your real account. This way, if the data is ever compromised, your email address will remain safe!<br \/><strong>Create your free and secure password here: <\/strong><a href=\"https:\/\/www.eset.com\/ee\/password-generator\/\">PASS.ESET.EE<\/a><\/p>\n<p><!\u2013 \/wp:paragraph \u2013><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Passwords are the bane of everyone\u2019s lives but let\u2019s face it \u2013 we all need them. And they aren\u2019t going away as fast as Microsoft may want them to. For the time being, we will continue to depend on them for the unforeseeable future. You may have 50, 100, or even 200 online accounts but [&hellip;]<\/p>\n","protected":false},"author":5,"featured_media":6100,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[2880],"tags":[],"class_list":["post-6113","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-digital-security"],"acf":[],"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/posts\/6113","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/comments?post=6113"}],"version-history":[{"count":0,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/posts\/6113\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/media\/6100"}],"wp:attachment":[{"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/media?parent=6113"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/categories?post=6113"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.eset.ee\/et\/en\/wp-json\/wp\/v2\/tags?post=6113"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}