While it's pretty awful that a million Sony users' passwords and 0.25 million Gawker passwords were published online, it has made for an interesting comparative analysis of the weaknesses in password protection, a subject near and dear to many security researchers' hearts.
Troy Hunt has published one such analysis, and it's a fascinating read, full of real, verifiable stats about the problems users have managing their passwords (for example, 67% of users with accounts on both Sony and Gawker used the same password for both).
In short, half of the passwords had only one character type and nine out of ten of those where all lowercase. But the really startling bit is the use of non-alphanumeric or characters: Yep, less than 1% of passwords contained a non-alphanumeric character. Interestingly, this also reconciles with the analysis done on the Gawker database a little while back.A brief Sony password analysis (via Some Bits)
Couple of notes from that Link at bottom, and a link or two from there;
ReplyDeletePassword tool "1Password";
http://agilebits.com/products/1Password
With Download and review at CNet;
http://download.cnet.com/1Password/3000-18501_4-95581.html?tag=contentMain;contentBody;1d#editorsreview
If you're even a little bit curious about password security, bounce to that link at the end of the Article "A brief Sony Password analysis" - it's very good. And of course, by "good", One means "Evil".
-Lord Malignance
Anyone interested to see if there email was 'hacked' might be interested in this:
ReplyDeletehttp://www.internetsecuritydb.com/2011/06/free-online-tool-to-find-out-if-your.html