Password Prompt
|

Linked: How Nest, designed to keep intruders out of people’s homes, effectively allowed hackers to get in

In this case, it wasn’t even that Nest had an insecure device, though that is often open to debate with Internet of Things devices. No, this was all about reusing passwords.

“The method used to spy on the Thomases is one of the oldest tricks on the Internet. Hackers essentially look for email addresses and passwords that have been dumped online after being stolen from one website or service and then check to see whether the same credentials work on another site. Like the vast majority of Internet users, the family used similar passwords on more than one account. While their Nest account had not been hacked, their password had essentially become public knowledge, thanks to countless other data breaches.

In recent years, this practice, which the security industry calls “credential stuffing”, has gotten incredibly easy. One factor is the sheer number of stolen passwords being dumped online publicly. It’s difficult to find someone who hasn’t been victimized.

A new breed of credential-stuffing software programs allows people with little to no computer skills to check the log-in credentials of millions of users against hundreds of websites and online services such as Netflix and Spotify in a matter of minutes.”

So how do you avoid this? First, just go ahead and assume that some website that you use has been breached and your username and password for that site is out there somewhere.

Once you assume that, of course, it now seems silly to use the same one on multiple sites, no? So don’t do that.

But, how will you remember all those different passwords?

That’s what password managers are for. Use one. Have it remember the passwords for you. When you hear of a site being breached, change that password, and relax in the comfort of knowing that that password won’t work anywhere else.

https://www.chron.com/news/article/How-Nest-designed-to-keep-intruders-out-of-13788592.php

Similar Posts

  • Stolen Data is a Risk, Here’s an Example of Altered Data That is Worse

    The entire system is based on the license plate database being connected to all of the automated plate readers. All it took for this to become a problem was for part of that not to stay safe. Since the license plate database isn’t, anyone can create a fake license plate, pop it on a similar-looking vehicle, and the collected data is tainted. All those people who had nothing to hide now have a system that assumes they were driving illegally, causing accidents, etc. They are facing actual fines, increased insurance costs, and possible arrests because of surveillance data that’s been hacked. Data that should show them as innocent but false information has been injected into it.

  • Gsyncit Problems

    I had been loving Gsyncit, as I mentioned before. Unfortunately, as with many other tools, an update created chaos with my machine tonight. When I opened Outlook, I was prompted to install an update to Gsyncit. I agreed to do that. Naturally, the install required me to close Outlook, which hadn’t finished opening in the…

  • Linked – Why public chats are better than direct messages

    But, here it the real world, this doesn’t always work out very well. You really need the culture to be one where everyone is used to working asynchronously and checking the public channel for chances to help out the team. It sounds like that is both the expectation and the reality at this company but for a lot of us the reality is very different. Posting something in a public channel where no one gets a notification that a message is being posted generally means no one sees it. So we go back to using private channels or tagging people in the public channel in order so that we purposefully interrupt them. We haven’t developed a culture where asynchronous communication works and I suspect it’s because we don’t really want it. We want people to respond to us now. We don’t trust them to get back later and, to be fair, we don’t give our peers reason to trust us because we spend all of our time putting out fires and frequently forget to get back to people.

    In many cases, it’s a humblebrag. “Oh I saw your message but then I got involved in important things because I’m an important person and never got back to you”.

  • IT and Productivity

    Thinking Faster has some thoughts on why technology doesn’t make business as productive as it should be. Some snippets (But read the whole thing!): “I have been in the bowels of the beast, and I think I can say fairly definitively that very few people receive the information they need from the systems they have….

  • |

    Conduct Computer Forensics without a proper license: Go to Jail?

    At least that’s what the rule is now in the State of Michigan. I agree with the commentary at the end of the article. Commentary: It is disappointing that the Michigan legislature does not require licensed professional investigators to be certified in computer forensics before they can provide computer forensic services. The law raises considerable…

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

To respond on your own website, enter the URL of your response which should contain a link to this post's permalink URL. Your response will then appear (possibly after moderation) on this page. Want to update or remove your response? Update or delete your post and re-enter your post's URL again. (Find out more about Webmentions.)