Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - The Cure For Compromised Credentials
Articles

The Cure For Compromised Credentials

ISBuzz TeamBy ISBuzz TeamJune 28, 20164 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Ask the average computer user how to keep safe and secure online, and ‘strong passwords’ is likely to be one of the first principles mentioned.  We’ve all been instructed, at some point or another, to ensure that we use long, complex and various passwords across different online accounts and websites.

It is an easy principle to explain to end users.  The more complex and unusual your password, the harder it is for a cybercriminal to guess or crack it.  Simple, right?  The trouble is, the majority of cyberattacks involving compromised passwords don’t involve guessing or cracking at all – they involve bulk password thefts.

Twitter is just one of many high profile companies to have fallen victim to a login credentials theft, with over 30,000,000 usernames and password pairs allegedly now being sold online.  Little surprise, perhaps, that Verizon’s Data Breach Investigations Report for this year suggests that over half of recent data breaches were due to compromised credentials.

A bulk credentials theft immediately undoes the benefit gained from creating strong passwords, both for the end users and the targeted companies.  In the Twitter case, many of the stolen passwords contained 30 characters or more; they were strong password by most commonly accepted standards.  Yet the minute they were stolen, their strength became irrelevant.  They were already openly in malicious hands.

‘Encryption’ is the classic response to this scenario; if those passwords are encrypted, surely it matters less if they are stolen?  Well, yes and no.  Sophisticated attackers may still be able to decrypt and use the stolen passwords; and, regardless of what actually happens to them, the organization from which they were stolen is still obliged to tell its users what has happened – and brace itself for the reputational damage that ensues.

 One step stronger

So, in a world in which cybercriminals can, and increasingly frequently, do manage to steal passwords en masse, a new type of protection is needed.  Enter two-factor or even multi-factor authentication (MFA).

The basic aim of two-factor authentication or MFA is to add an additional, context-specific verification step beyond the initial password request.  This strengthens the login process not only by making it more complex, but also by making it time-sensitive, so an attacker who does manage to steal the verification information is unable to use it outside of the initial login attempt.

The most common way of introducing this layer is by sending a code, known as a token, to the user’s phone. This, too, adds extra security, because SMS messages are extremely difficult for cybercriminals to intercept; the user will almost always have their phone with them, and the SMS does not touch their email account, which may have already been separately compromised.

Variations of multi-factor authentication include secondary passwords for which only selected characters are requested during each login attempt, and biometric data such as fingerprints and iris scans.  Other organizations choose to send out physical devices to their users, which generate those unique tokens.  However, the code option is not only extremely efficient; it is also easy and cost-effective to implement, making it a suitable option for rolling out to organizations on the same scale as regular username/password verification.

 Protecting credential outside and inside

It is crucial for organizations to remember that the weaknesses of standard username/password credentials apply not just to customer accounts, but also to their employees, business partners and contractors – in fact, anyone that wants to access the organization’s networks or resources. Here, basic username and password pairs are typically used to control access to the corporate network, applications, files and, increasingly, endpoint mobile devices.  MFA can play a critical role here, in improving enterprises’ internal network security, and guarding against theft of sensitive data.

Perhaps it is unsurprising, then, that the market for integrated, secure multifactor authentication solutions is growing fast, as more and more organizations introduce this extra layer of verification for consumers and employees alike.

One useful element for businesses to consider when introducing MFA internally is the ability to assign variable levels of verification according to, for example, the user in question, the services they require, the resources they need to access and even the IP address they are using.  This sort of flexibility is crucial in order to build a truly scalable and agile security posture.

 Bulk thefts of login credentials have taught us that the one-size-fits-all, blanket approach of traditional username and password pairs is broken.  Now, end user security needs to be context-specific, time-sensitive and adaptable to the needs and situation of different users. Two-factor authentication or MFA can truly be the cure for compromised credentials.

[su_box title=”About Andreas Åsander” style=”noise” box_color=”#336588″][short_info id=’74459′ desc=”true” all=”false”][/su_box]

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read

Making stolen data worthless: why security must start with the data

March 30, 20265 Mins Read

Meta’s Smart Glasses Privacy Scandal Expands After Sama Credentials Found on the Dark Web

March 10, 20264 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}