Shared Security Podcast

Social Media Security Podcast 30 – The Password Episode


Listen Later

This is the 30th episode of the Social Media Security Podcast sponsored by SecureState.  This episode was hosted by Tom Eston and Scott Wright.  In this episode we talk about the password problem and why we continue to choose easy to guess passwords.  Tom and Scott also talk about ways to select more secure passwords and how technology can help.  Below are the show notes, links to articles and news mentioned in the podcast:

The password Episode!  It’s episode 30!

  • Study shows hackers more focused on passwords than those who create them
  • Major password breaches in the last few months:
    • Formspring (420,000)
    • LinkedIn (6 million)
    • eHarmony (1.5 million)
    • Last.fm (2.5 million)
    • Blizzard Battle.net
    • Brute force attacks on passwords is the #1 way we break into companies during pentests! Want to see the poor passwords people choose? SkullSecurity has very good lists from previous breaches.  Looking for more information? Tom wrote a white paper on how easy it is to profile user passwords on social networks.
      The password problem.  Users continue to make poor password choices. Why? 
      • Too many to remember?
        • It’s easier to use the same password for each site
        • Also the same user id and email
        • Failures in user awareness?
        • Users are not provided the technology to help
        • Social networks and other sites make it easy to choose weak passwords, little adoption of two factor authentication because users will complain
        • Mobile apps are not designed to constantly enter passwords.  This is why you “stay logged in”.
        • Worse case scenario?
          • Mat Honan’s “Epic” Hacking
          • What is the solution?
            • It’s tough but we need to stop blaming the companies that hold our data…take personal responsibility and educate yourself!
            • It’s also complex to figure out a solution.
            • Technology can help: KeePass, 1Password, LastPassGoogle Two-Step Verification (application specific passwords), Facebook Two Factor
            • Please send any show feedback to feedback [aT] socialmediasecurity.com or comment below.  You can also call our voice mail box at 1-613-693-0997 if you have a question for our Q&A section on the next episode.  You can also subscribe to the podcast in iTunes and follow us on Twitter.  Thanks for listening!

              The post Social Media Security Podcast 30 – The Password Episode appeared first on Shared Security Podcast.

              ...more
              View all episodesView all episodes
              Download on the App Store

              Shared Security PodcastBy Tom Eston, Scott Wright, Kevin Tackett

              • 4.5
              • 4.5
              • 4.5
              • 4.5
              • 4.5

              4.5

              28 ratings


              More shows like Shared Security Podcast

              View all
              Hacked by Hacked

              Hacked

              187 Listeners

              Security Now (Audio) by TWiT

              Security Now (Audio)

              2,007 Listeners

              Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec by Jerry Bell and Andrew Kalat

              Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec

              372 Listeners

              Risky Business by Patrick Gray

              Risky Business

              371 Listeners

              SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

              SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

              651 Listeners

              CyberWire Daily by N2K Networks

              CyberWire Daily

              1,021 Listeners

              Smashing Security by Graham Cluley

              Smashing Security

              319 Listeners

              Click Here by Recorded Future News

              Click Here

              416 Listeners

              Darknet Diaries by Jack Rhysider

              Darknet Diaries

              8,062 Listeners

              Cybersecurity Today by Jim Love

              Cybersecurity Today

              179 Listeners

              Hacking Humans by N2K Networks

              Hacking Humans

              315 Listeners

              CISO Series Podcast by David Spark, Mike Johnson, and Andy Ellis

              CISO Series Podcast

              188 Listeners

              Defense in Depth by David Spark, Steve Zalewski, Geoff Belknap

              Defense in Depth

              74 Listeners

              Cyber Security Headlines by CISO Series

              Cyber Security Headlines

              139 Listeners

              The 404 Media Podcast by 404 Media

              The 404 Media Podcast

              391 Listeners