Showing posts with label Passwords. Show all posts
Showing posts with label Passwords. Show all posts

Monday, September 16, 2013

Google knows every single Android user's WiFi password



New privacy issues have come to light surrounding Google's Android mobile OS. Experts on the matter are claiming that back up tools in the operating system make it so that a copy of every person's WiFi password (or the password of other networks you log onto) is being stored on Google's servers. Unfortunately, this might mean that Google could be legally forced to hand over the data at the government's request for one reason or another.

In Android 4.2, the back up service under Settings, lists WiFi passwords as part of the data that will be included, where as earlier versions of the OS did not specifically mention that. Although the feature can be turned off, users lose other, helpful functionality like bookmarks etc.

The main problem here is beyond the fact that Google is storing the passwords. The company is storing them in such a way that means it can read the passwords if it wants to. This is clear to see by the way new Android devices can suck in old passwords, login data and device settings from Google servers, once you have setup your Gmail address and new password.

Obviously, this functionality has its up sides, we can easily manage passwords for several devices and services this way, but it certainly leaves the networks we use in a much less secure state than we may have originally thought. Although this isn't shocking in the least, it is surprising that Google would leave these passwords in a readable form as well as opening itself up for an almost guaranteed public back lash if the government ever does strong arm them for that data.

Friday, November 18, 2011

25 Worst Passwords of 2011


Pro tip: choosing “password” as your online password is not a good idea. In fact, unless you’re hoping to be an easy target for hackers, it’s the worst password you can possibly choose.
“Password” ranks first on password management application provider SplashData’s annual list of worst internet passwords, which are ordered by how common they are. (“Passw0rd,” with a numeral zero, isn’t much smarter, ranking 18th on the list.)
The list is somewhat predictable: Sequences of adjacent numbers or letters on the keyboard, such as “qwerty” and “123456,” and popular names, such as “ashley” and “michael,” all are common choices. Other common choices, such as “monkey” and “shadow,” are harder to explain.
SEE ALSO: HOW TO: Protect Your Company’s Passwords
As some websites have begun to require passwords to include both numbers and letters, it makes sense varied choices, such as “abc123″ and “trustno1,” are popular choices.
SplashData created the rankings based on millions of stolen passwords posted online by hackers. Here is the complete list:
  • 1. password
  • 2. 123456
  • 3.12345678
  • 4. qwerty
  • 5. abc123
  • 6. monkey
  • 7. 1234567
  • 8. letmein
  • 9. trustno1
  • 10. dragon
  • 11. baseball
  • 12. 111111
  • 13. iloveyou
  • 14. master
  • 15. sunshine
  • 16. ashley
  • 17. bailey
  • 18. passw0rd
  • 19. shadow
  • 20. 123123
  • 21. 654321
  • 22. superman
  • 23. qazwsx
  • 24. michael
  • 25. football
SplashData CEO Morgan Slain urges businesses and consumers using any password on the list to change them immediately.
“Hackers can easily break into many accounts just by repeatedly trying common passwords,” Slain says. “Even though people are encouraged to select secure, strong passwords, many people continue to choose weak, easy-to-guess ones, placing themselves at risk from fraud and identity theft.”
SEE ALSO: 5 Tools for Keeping Track of Your Passwords
The company provided some tips for choosing secure passwords in a statement:
  • 1. Vary different types of characters in your passwords; include numbers, letters and special characters when possible.
  • 2. Choose passwords of eight characters or more. Separate short words with spaces or underscores.
  • 3. Don’t use the same password and username combination for multiple websites. Use an online password manager to keep track of your different accounts.
Are these lists helpful? Do you need to rethink any of your password choices? Let us know in the comments