Change Language
Sun Sun Sun

You are here: News >> IT Security News >> Guessing becomes as easy as 1-2-3

» IT Security NEWS
 
» 12 March 2010
Guessing becomes as easy as 1-2-3

 

A group of computer science researchers conducted a study and they were able to conclude that there is a great chance that hackers can deduce answers to common password reset questions without any difficulty.
 
Conventional question incurs greater risk
 
Joseph Bonneau of University of Cambridge, together with the two other researchers from University of Edinburgh, wrote a paper entitled “What’s in a Name? Evaluating Statistical Attacks on Personal Knowledge Questions”. Through the study, it was proved that a hacker has an approximately 1 out of 80 chances of getting the right answer for the reset questions in just three trials. These personal questions include the mother’s maiden name and the school where the person first studied.
 
The study of by these researchers was conducted by browsing through 270 million pairs of first and last names from the popular social networking service, Facebook. The conclusion was drawn due to the existence of a subject or a previous relationship that allows hackers to easily guess the answer to security questions.
 
Online community is not as safe anymore
 
During the time of 2008 presidential election, Sarah Palin’s Yahoo! webmail was hacked and this had a great impact on the online community. Based on the study, publicly-available information was used in order to answer the security reset questions of her account. Also, Bonneau’s study proves that there is a big probability that a hacker can access personal accounts by answering reset questions without any previous knowledge or information about the subject.
 
Tighter security is necessary
 
The research, carried out by Bonneau and two of his colleagues, concentrates mainly on the security system of social networking services. And based on the results of the study, they recommend that these sites update their reset password questions into something that is more protected.
 
The researchers believe that establishing multiple questions will lessen the hacking incidents online. Another way of increasing security is through sending of text messages using mobile phones when resetting account passwords.
 
Dangers brought about by hacking
 
Invasion of privacy is just one of the many concerns in the occurrences of hacking through the reset password question. There is also a greater threat since these webmails may contain serious data like a method of accessing through online bank accounts.
 
Browse through our website for more information: About SecPoint, SecPoint Press, and SecPoint Awards.

 

Get a Free Vulnerability Scan

Got a Question? Please mail us



News
 
  Email :
     
29 July 2010
Penetrator S700 Vulnerability ...
29 July 2010
Penetrator S1600 Vulnerability...
27 July 2010
Portable Penetrator PP6000...
 
Customer References
 
View More...
   
Product Awards
 
View More...
Privacy Statement | Link Policy | User Policy | IT Security Blog | IT Security Forum | SecPoint Pictures
Event Pictures | Exploit Archive | IT Security Web Shop | Vulnerability Library
IT Security Video | Sitemap
© Copyright 1999-2010: SecPoint®
SecPoint ApS - Lergravsvej 53 - 2300 Copenhagen S - Phone +45 70 235 245
Recent awards Compatible with Visit us on Facebook! Visit us on LinkedIn! Visit us on Myspace!
   
Facebook
Group!


Follow us on Twitter!
Anti-Spam Appliance - Anti-Spam Firewall - Unified Threat Management Appliance Anti-Virus - Web Filter Appliance - Anti Spam Appliance - Anti Spam Firewall - UTM Appliance Wifi Security - Wifi Pen Test - Wifi Crack - Wifi Hack - Wifi Audit - Wep Wpa2 Crack Vulnerability Scanner - Vulnerability Assessment - Security Scanner - Pen Test Appliance