Password awareness critical

1 June 2019 Information Security, Security Services & Risk Management

If you knew just how valuable your identity was, would you pay more attention to securing it? A recent Kaspersky Lab study revealed that digital identity data and information holds significant value to cybercriminals – who craft ways of gaining this data without potential victims’ knowledge and exploit it on the dark Web for as little as $50. This reality raises the need to create more awareness about the importance of password protection and stronger password controls in the digital world.

Says Riaan Badenhorst; general manager of Kaspersky Lab in Africa, “While the digital world brings with it many conveniences that are enjoyed without a second thought, it also poses many risks to people. Turning a blind eye to these risks can be detrimental and lead to devastating effects – just think about a stolen identity and the impact this can have. And people often don’t realise the value of their digital identity/data to the cybercriminal world and how this is used on the dark Web – thus don’t pay enough attention to the need for strong password protection.”

While it is often common security practice to change passwords regularly to mitigate possible risk, this method alone is not always effective. The password problem is twofold; firstly, for effective protection, passwords need to be difficult to guess. Secondly, to be usable, passwords need to be easy to remember. While changing passwords regularly does have some positive impact on the first aspect here, regular changes drastically complicate the ability to remember passwords.

Continues Badenhorst, “It is human nature to not like the fact that one has to remember a variety of long, complicated passwords for various devices and online accounts. This often results in an individual creating one strong password for all accounts or using the same password and changing only one symbol or number for each device or account to make it easier to remember. The problem with this is that the passwords lack uniqueness and if compromised puts all devices and accounts at risk.”

A unique password is made up of two properties – a set of characters used and the length. The more diverse the characters and the longer the password, the stronger and better. Uniqueness, however, and considering how the digital world is evolving, can also come in the form of individual biometrics, which can provide an additional layer of security, especially for devices.

Says Pine Pienaar, MD of Afiswitch, “Incorporating biometrics into password procedures and in devices where viable, is a growing global practice as part of managing device access and control. While there will likely always be a place for text-based passwords that one would have to input, character-based biometric passwords will naturally progress in the digital realm, where we are already starting to see a significant uptake of biometrics-based features, for example, using fingerprints and facial recognition for the purpose of unlocking devices.”

“Based on the success of these use cases and the growing consumer demand for simplified mechanisms to protect their identities, personal data and password-secure their devices, we expect these solutions to become more mainstream and used as an additional line of defence in the war against cybercrime,” continues Pienaar.

While consumers may be able to look forward to a possible future reliant on biometric-based passwords, until this future comes to fruition, password awareness and safety measures must be taken to protect identities in the digital realm.

Concludes Badenhorst, “Passwords are there for a reason – they should not be viewed as a mechanic that causes frustration. Rather they aim to protect what matters to you most – your data. And with the opportunity to invest in password manager solutions, creating and remembering strong passwords doesn’t need to be a chore.”





Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Cybersecurity needs actual intelligence before artificial intelligence
Information Security AI & Data Analytics
Cybersecurity depends on interpretation. A tool can tell you that something unusual has happened, but people need to determine whether it is a genuine risk, the business impact, and how to respond without causing unnecessary disruption.

Read more...
Duxbury Cybersecurity sharpens reseller offering
Duxbury Networking Information Security News & Events
Duxbury Networking has strengthened its Duxbury Cybersecurity business unit by adding WatchGuard and Cynet, giving South African resellers broader, more integrated coverage for the security risks customers are now asking them to address.

Read more...
Echoes of 2018? Follow-up on Woolworths explosions
Technews Publishing News & Events Security Services & Risk Management Retail (Industry) Facilities & Building Management
SMART Security Solutions follows up with Jimmy Roodt to find out more about an old connection to the Woolworths bombings from 2018. The investigation remains ongoing.

Read more...
NEC XON detects and stops ransomware attack
NEC XON Information Security IoT & Automation
Ransomware attacks rarely begin with chaos. More often, they start quietly, with probing, mapping, and patient reconnaissance inside a target’s network. That was the situation facing a global recruitment firm when cybercriminals attempted to navigate its systems.

Read more...
Next-generation cash-in-transit vehicle
News & Events Security Services & Risk Management
Fidelity Services Group has unveiled a new, purpose-engineered Cash-in-Transit (CIT) vehicle designed to redefine crew protection, deter threats, and enhance operational resilience in an increasingly complex criminal environment.

Read more...
Sara AI Pentesting available in South Africa
Information Security News & Events
Synack and Wolfpack Information Risk are offering Sara AI Pentesting to organisations across South Africa, helping companies move from point-in-time testing to continuous security validation with AI and human expertise.

Read more...
Sophos establishes South African legal entity to strengthen local operations
News & Events Information Security
Global cybersecurity company, Sophos, has announced the formation of its local legal entity, which will support local invoicing, partner enablement, compliance requirements and expanded regional investment.

Read more...
AURA partners with Discovery to launch Discovery 911
News & Events Security Services & Risk Management
AURA has announced a partnership with Discovery Insure to power the security-response component of its new Discovery 911 virtual panic-button offering, which is available through the Discovery Insure app.

Read more...
Cybersecurity in a digitally connected security industry
SA Technologies Information Security IoT & Automation
As more organisations move towards digital visitor management, cloud-based access control, mobile applications, biometric verification, and connected security platforms, cybersecurity must be viewed as part of the full security environment.

Read more...
Enterprises must prepare for digital conflict
Information Security
Cyberattacks can be launched remotely and at scale. A coordinated attack launched from anywhere in the world can disrupt supply chains, shut down utilities, or expose millions of customer records within minutes.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.