Passwords continue to be weakest link in cyber security

Computer Weekly is reporting that one of the biggest problems continues to be compromised passwords according to Darren Martyn, a security researcher who breaks into organisations as part of enterprise network security assessments.

…The easiest way into any organisation, he says, is to search for people’s usernames and passwords online from previous breaches and trying them in their work environment.

“You don’t need to do anything complicated or fancy when someone in the organisation somewhere has re-used their work password on LinkedIn or MySpace with a leaked database out there,” says Martyn…

…Once an attacker has a valid password, they are able to bypass any firewall or other security system because they have the same access to corporate systems as the employee they are impersonating.

Another easy way in with unfettered access to corporate networks, applications and systems is to use a phishing email to trick employees into revealing their usernames and passwords.

“It is simple stuff. If you send a phishing email to every single employee, you are going to get in, that is pretty much guaranteed. From an attacker’s point of view, that is usually the cheapest and easiest way to go about things,” says Martyn….

“Gaining administrative privileges usually does not take long, but if people used something like two-factor authentication and a password manager it would make an attacker’s life infinitely more difficult because they couldn’t rely on credential re-use and phishing as they would still need the second factor,” says Martyn.

Read more at How UK organisations are leaving themselves open for cyber attack