Security - Channel Insider
Empowering the next generation Channel
 

Sponsored Links
  • Try Windows Azure free for 90 days

  • Introducing the world's first family of systems with integrated expertise

  • FREE Securing Smartphones & Tablets for Dummies Book from Sophos
  • 5 New Technologies That Will Change Enterprise ITAdvertisement
  • Build an IT Infrastructure That Delivers the Future

  •  

    Despite Public Data Breaches, Password Security Still Weak

    in Security



    Article Rating:starstarstarstarstar / 0
    Article Views: 2277

    Online users are still lazy about password security, meaning companies shouldn't rely on them to protect corporate data.

    Rate This Article:
    Add This Article To:

    Despite repeated reminders to select strong passwords and not to reuse them across Websites and services, online users continue to be frighteningly lax in their password security, according to a recent analysis of leaked passwords.

    Security experts recommend taking a multilayered approach to security. Instead of relying on a single point of failure, organizations should be implementing several mechanisms to make it harder for cyber-attackers to steal sensitive, confidential data, Mike Yaffe, government security strategist at Core Security, told eWEEK.

    Considering how easy it has become to steal passwords, using phishing emails or by installing keyloggers on a target computer, relying solely on passwords to protect data is very risky, Yaffe said.

    Organizations are often leery of putting up any security measures that may affect the user experience and interrupt workflow because they are worried users will get annoyed and go elsewhere. But some tolerance for inconvenience is necessary, since it will result in a significant boost in security, Yaffe said. Many banks are rolling out additional protections such as image verification and hardware tokens, which may feel a little tedious, but Yaffe said he s willing to put up with them because he would rather be overprotected than underprotected.

    Other protections include multiple security questions, forcing users to change passwords regularly, and checking to ensure the passwords aren t dictionary words or being reused.

    Attackers should have to get past multiple gatekeepers before they even get to the database, Josh Shaul, CTO of Application Security, told eWEEK. Organizations should be combining all the security layers that will help trap attackers, or at least slow them down enough by raising enough flags for the IT department to notice something is wrong, according to Shaul.


    To read the original eWeek article, click here: Password Security Remains the Weakest Link Even After Big Data Breaches




    comments dic


     
     
    >>> More Security Articles          >>> More By Channel Insider Staff
     


     



    channel chatter


    HTML PLAIN TEXT

    Keep on top of news for VARs and Resellers with CI's Weekly Newsletter and Alerts.


    [ci] feeds
    XML
    Add Channel News, Product Reviews, Trends and Analysis to your RSS newsreader or My Yahoo!


     


    CHANNEL SPONSORED RESOURCE CENTER
     
     
     
    Start the New Year with business intelligence—it’s a smart move
    Join us on February 1 for an encore rebroadcast at either 5 am or 12 noon EST and discover how business intelligence (BI) supports companies in uncertain business and economic climates. Get expert advice on how to create a strategy that fits your organization's needs and budget and see how quickly it can pay for itself.
    Click Here
     
    Security and Availability Essentials for Running Your Business in the Cloud
    Are you moving to the cloud? Find out what every IT professional should know about security and availability before moving to the cloud. Hear what a security provider’s own CSO has to say.
    Watch Video
    A new algorithm automatically identifies relationships between variables to help reduce researcher prejudice.
    Click HereAdvertisement