Has Anyone Learned Anything?
You’ve probably heard that Yahoo was hacked. They were hacked through SQL Injection of all things (for those who don’t know SQL injection is kiddy stuff, I could do it and that’s saying a lot) and, to make matters so much worse, they stored the passwords in plaintext – no encryption, not so much as obfuscation. It’s pathetic.
This is the same exact thing that happened to Sony (twice as I recall) years back. It’s what happened to another site just a few weeks ago. It’s what keeps happening over and over and over again.
Sanitize input. Encrypt passwords. Don’t use MD5.
And then there’s our users. Hundreds of thousands of users and these are the top passwords.
picture taken from sophos blog
The top passwords are all short and awful and the first thing anyone would guess in a dictionary. Except ninja – that’s still short and awful but I actually would not have guessed that so bravo whoever started that trend.
Seriously? How many people’s accounts have to be hacked before the public realizes that five characters is not enough. You can not get away with a five character password. You can not get away with a 6 or even 7 character password. 8 characters is the minimum.
Of course it isn’t the users fault Yahoo was hacked but I think it’s enlightening.
For good measure here’s my link to creating a strong password.
blog comments powered by Disqus
