Password awareness critical

1 June 2019 Information Security, Security Services & Risk Management

If you knew just how valuable your identity was, would you pay more attention to securing it? A recent Kaspersky Lab study revealed that digital identity data and information holds significant value to cybercriminals – who craft ways of gaining this data without potential victims’ knowledge and exploit it on the dark Web for as little as $50. This reality raises the need to create more awareness about the importance of password protection and stronger password controls in the digital world.

Says Riaan Badenhorst; general manager of Kaspersky Lab in Africa, “While the digital world brings with it many conveniences that are enjoyed without a second thought, it also poses many risks to people. Turning a blind eye to these risks can be detrimental and lead to devastating effects – just think about a stolen identity and the impact this can have. And people often don’t realise the value of their digital identity/data to the cybercriminal world and how this is used on the dark Web – thus don’t pay enough attention to the need for strong password protection.”

While it is often common security practice to change passwords regularly to mitigate possible risk, this method alone is not always effective. The password problem is twofold; firstly, for effective protection, passwords need to be difficult to guess. Secondly, to be usable, passwords need to be easy to remember. While changing passwords regularly does have some positive impact on the first aspect here, regular changes drastically complicate the ability to remember passwords.

Continues Badenhorst, “It is human nature to not like the fact that one has to remember a variety of long, complicated passwords for various devices and online accounts. This often results in an individual creating one strong password for all accounts or using the same password and changing only one symbol or number for each device or account to make it easier to remember. The problem with this is that the passwords lack uniqueness and if compromised puts all devices and accounts at risk.”

A unique password is made up of two properties – a set of characters used and the length. The more diverse the characters and the longer the password, the stronger and better. Uniqueness, however, and considering how the digital world is evolving, can also come in the form of individual biometrics, which can provide an additional layer of security, especially for devices.

Says Pine Pienaar, MD of Afiswitch, “Incorporating biometrics into password procedures and in devices where viable, is a growing global practice as part of managing device access and control. While there will likely always be a place for text-based passwords that one would have to input, character-based biometric passwords will naturally progress in the digital realm, where we are already starting to see a significant uptake of biometrics-based features, for example, using fingerprints and facial recognition for the purpose of unlocking devices.”

“Based on the success of these use cases and the growing consumer demand for simplified mechanisms to protect their identities, personal data and password-secure their devices, we expect these solutions to become more mainstream and used as an additional line of defence in the war against cybercrime,” continues Pienaar.

While consumers may be able to look forward to a possible future reliant on biometric-based passwords, until this future comes to fruition, password awareness and safety measures must be taken to protect identities in the digital realm.

Concludes Badenhorst, “Passwords are there for a reason – they should not be viewed as a mechanic that causes frustration. Rather they aim to protect what matters to you most – your data. And with the opportunity to invest in password manager solutions, creating and remembering strong passwords doesn’t need to be a chore.”





Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

What are MFA fatigue attacks, and how can they be prevented?
Information Security
Multifactor authentication is a security measure that requires users to provide a second form of verification before they can log into a corporate network. It has long been considered essential for keeping fraudsters out. However, cybercriminals have been discovering clever ways to bypass it.

Read more...
SA's cybersecurity risks to watch
Information Security
The persistent myth is that cybercrime only targets the biggest companies and economies, but cybercriminals are not bound by geography, and rapidly digitising economies lure them in large numbers.

Read more...
Cyber insurance a key component in cyber defence strategies
Information Security
[Sponsored] Cyber insurance has become a key part of South African organisations’ risk reduction strategies, driven by the need for additional financial protection and contingency plans in the event of a cyber incident.

Read more...
Deception technology crucial to unmasking data theft
Information Security Security Services & Risk Management
The ‘silent theft’ of data is an increasingly prevalent cyber threat to businesses, driving the ongoing leakage of personal information in the public domain through undetected attacks that cannot even be policed by data privacy legislation.

Read more...
Data security and privacy in global mobility
Security Services & Risk Management Information Security
Data security and privacy in today’s interconnected world is of paramount importance. In the realm of global mobility, where individuals and organisations traverse borders for various reasons, safeguarding sensitive information becomes an even more critical imperative.

Read more...
Sophos celebrates partners and cybersecurity innovation at annual conference
News & Events Information Security
[Sponsored] Sun City hosted Sophos' annual partner event this year, which took place from 12 to 14 March. Sophos’ South African cybersecurity distributors and resellers gathered for an engaging two-day conference.

Read more...
Proactive strategies against payment fraud
Financial (Industry) Security Services & Risk Management
Amid a spate of high-profile payment fraud cases in South Africa, the need for robust fraud payment prevention measures has never been more apparent, says Ryan Mer, CEO of eftsure Africa.

Read more...
How to prevent and survive fires
Fire & Safety Security Services & Risk Management
Since its launch in August 2023, Fidelity SecureFire, a division of the Fidelity Services Group, has been making significant strides in revolutionising fire response services in South Africa.

Read more...
A long career in mining security
Technews Publishing Editor's Choice Security Services & Risk Management Mining (Industry)
Nash Lutchman recently retired from a security and law enforcement career, initially as a police officer, and for the past 16 years as a leader of risk and security operations in the mining industry.

Read more...
Risk management: There's an app for that
Editor's Choice News & Events Security Services & Risk Management
Zulu Consulting has streamlined the corporate risk management process with the launch of Risk-IO, a web-based app designed to consolidate and guide risk managers through the process, monitoring progress as one proceeds.

Read more...