Hotmail hacks easy as 123456
BY ASHER MOSES
Related Links
Relevant offers
Digital living
The Hotmail hack attack this week has laid bare the woeful password choices of web users, as reports emerged that up to 1 million web email accounts could have been compromised.
The most common password was "123456", while many users had names or dates of birth - all easy pickings for the determined password cracker.
Password security was thrown into the spotlight this week after it was revealed that 10,000 Hotmail user names and passwords had been leaked online. A day later, a separate list of 20,000 addresses and passwords for Gmail, Yahoo and AOL were found on the web.
The size of the lists, one of which contains only email addresses beginning with A and B, have led security experts to fear that thousands more accounts have been compromised.
Hackers frequently target email accounts because from there they can obtain passwords to other more important accounts such as internet banking. Often, the same password is used for multiple online accounts.
Hijacked email addresses are also used to conduct spam campaigns and targeted phishing attacks on the victim's contacts. Security firm Websense reported that some of the addresses compromised this week were already being used for this purpose.
A security researcher was able to obtain the list of 10,000 Hotmail account details before it was removed from the web and found the passwords used were alarmingly simple.
Bogdan Calin, of Acunetix, found "123456" and "123456789" were the most common, appearing 82 times, while 12345678, 1234567 and 111111 also appeared in the top 10.
Furthermore, 42 per cent of the passwords used only lower case letters from a to z. Just 6 per cent mixed letters and numbers.
The longest password was 30 characters - lafaroleratropezoooooooooooooo - but this still evidently did not prevent the user's account from being hacked. The shortest password was one character: ")".
"A big majority of users still use very poor passwords," Calin concluded.
Security experts say people should always use a combination of letters and numbers in their passwords and avoid those that are easily guessed such as names, dates of birth or words from the dictionary.
F-Secure is even advising people to write down their passwords and put them in their wallets, arguing that people use weak passwords because they can't remember strong ones.
Neil O'Neil, a digital forensics investigator at The Logic Group told Computerworld the security breach was likely to spread even further.
"Making the breach public so soon after the attack occurred has allowed unethical hackers to access the passwords very easily, even though they were deleted a couple of days ago at the request of Microsoft," he said.
"The list went through A and B, so you would think whoever released these has more. And if you do the maths, they could have more than a million passwords."
The BBC reported that Google is already aware of a third list, but it is not clear how many names are on it.
Users of web email accounts are being advised to change their passwords immediately.
- © Fairfax NZ News
Sponsored links
'Janitor satellite' made to clean up space
Australia to get R18 rating for games
iPad factory conditions 'better than the norm'
App turns iPhone into adult toy
Review: Samsung Series 7 UA46D7000
Bulgaria could suspend vote on ACTA
Internet in Iran severely disrupted as elections loom
Review: The Darkness 2 for Xbox 360
Nasdaq website disrupted by online attacks
Angry Birds join Facebook, hope for 800M likes
Kiwis in cruise ship cocaine bust
New Zealand's 'biggest' P-lab busted
Greens: Crafar approval politically motivated
All the ingredients for thunderstorms
15-minute-old newborn gets heart pacemaker
Mallard ridiculed over scalping accusations
'Starved, beaten' teen weighed just 32kg
Bookies favour Crusaders to win Super Rugby
Dragons deny wrongdoing as wee row erupts
Cyclist shot, retaliates with rock
From TV to a tent: Family of eight evicted
Fallen property king arrested in Auckland raids
Star claims Home and Away racism
Sonny Bill Williams finds rugby boring: mate
Robyn Malcolm lays it all bare
Pub owners give up, open kindergarten
Mallard ridiculed over scalping accusations
Mallard ridiculed over scalping accusations
Mallard sells festival tickets online at profit
Should you take your groom's name?
Cyclist: Don't fine us, fix the road
Is Kutcher an upgrade over Sheen?