Password awareness critical

1 June 2019 Information Security, Security Services & Risk Management

If you knew just how valuable your identity was, would you pay more attention to securing it? A recent Kaspersky Lab study revealed that digital identity data and information holds significant value to cybercriminals – who craft ways of gaining this data without potential victims’ knowledge and exploit it on the dark Web for as little as $50. This reality raises the need to create more awareness about the importance of password protection and stronger password controls in the digital world.

Says Riaan Badenhorst; general manager of Kaspersky Lab in Africa, “While the digital world brings with it many conveniences that are enjoyed without a second thought, it also poses many risks to people. Turning a blind eye to these risks can be detrimental and lead to devastating effects – just think about a stolen identity and the impact this can have. And people often don’t realise the value of their digital identity/data to the cybercriminal world and how this is used on the dark Web – thus don’t pay enough attention to the need for strong password protection.”

While it is often common security practice to change passwords regularly to mitigate possible risk, this method alone is not always effective. The password problem is twofold; firstly, for effective protection, passwords need to be difficult to guess. Secondly, to be usable, passwords need to be easy to remember. While changing passwords regularly does have some positive impact on the first aspect here, regular changes drastically complicate the ability to remember passwords.

Continues Badenhorst, “It is human nature to not like the fact that one has to remember a variety of long, complicated passwords for various devices and online accounts. This often results in an individual creating one strong password for all accounts or using the same password and changing only one symbol or number for each device or account to make it easier to remember. The problem with this is that the passwords lack uniqueness and if compromised puts all devices and accounts at risk.”

A unique password is made up of two properties – a set of characters used and the length. The more diverse the characters and the longer the password, the stronger and better. Uniqueness, however, and considering how the digital world is evolving, can also come in the form of individual biometrics, which can provide an additional layer of security, especially for devices.

Says Pine Pienaar, MD of Afiswitch, “Incorporating biometrics into password procedures and in devices where viable, is a growing global practice as part of managing device access and control. While there will likely always be a place for text-based passwords that one would have to input, character-based biometric passwords will naturally progress in the digital realm, where we are already starting to see a significant uptake of biometrics-based features, for example, using fingerprints and facial recognition for the purpose of unlocking devices.”

“Based on the success of these use cases and the growing consumer demand for simplified mechanisms to protect their identities, personal data and password-secure their devices, we expect these solutions to become more mainstream and used as an additional line of defence in the war against cybercrime,” continues Pienaar.

While consumers may be able to look forward to a possible future reliant on biometric-based passwords, until this future comes to fruition, password awareness and safety measures must be taken to protect identities in the digital realm.

Concludes Badenhorst, “Passwords are there for a reason – they should not be viewed as a mechanic that causes frustration. Rather they aim to protect what matters to you most – your data. And with the opportunity to invest in password manager solutions, creating and remembering strong passwords doesn’t need to be a chore.”



Credit(s)




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Highest increase in global cyberattacks in two years
Information Security News & Events
Check Point Global Research released new data on Q2 2024 cyber-attack trends, noting a 30% global increase in Q2 2024, with Africa experiencing the highest average weekly per organisation.

Read more...
Empower individuals to control their biometric data
Information Security Access Control & Identity Management Security Services & Risk Management
What if your biometrics, now embedded in devices, workplaces, and airports, promising seamless access and enhanced security, was your greatest vulnerability in a cyberattack? Cybercriminals are focusing on knowing where biometric data is stored.

Read more...
Strategies for combating insider threats
Information Security Security Services & Risk Management
In Africa, insider threats pose an increasingly significant risk to businesses, driven by economic uncertainty, labour disputes, and rapid digital transformation. These threats can arise from various sources, including disgruntled employees and compromised third-party service providers

Read more...
World-first safe K9 training for drug detection
Technews Publishing SMART Security Solutions Editor's Choice News & Events Security Services & Risk Management Government and Parastatal (Industry)
The Braveheart Bio-Dog Academy recently announced the results of its scientific research into training dogs to accurately detect drugs and explosives without harming either the dogs or their handlers.

Read more...
Five tech trends shaping business in 2025
Information Security Infrastructure
From runaway IT costs to the urgent need for comprehensive AI strategies that drive sustainable business impact, executives must be prepared to navigate a complex and evolving technology environment to extract maximum value from their investments.

Read more...
Kaspersky’s predictions for 2025 APT landscape
Information Security
The 2025 advanced persistent threat (APT) includes the rise of hacktivist alliances, increased use of AI-powered tools by state-affiliated actors – often with embedded backdoor – more supply chain attacks on open-source projects.

Read more...
SecurityHQ certified B-BBEE Level 1: Delivering global services from a local entity
SecurityHQ Information Security
SecurityHQ, a global managed security services provider (MSSP) with an office in South Africa, has announced it can now offer local companies a complete managed cybersecurity service from a Level-1 B-BBEE accredited and 51% black-owned service provider.

Read more...
2024, the year of Fraud-as-a-Service
Information Security
A report from AU10TIX outlines how ‘the industry’s dark engine’ offers user-friendly fraud kits that enable amateurs to execute complex attacks against thousands of accounts in minutes.

Read more...
The future of endpoint security
Information Security
Endpoint security is a critical pillar of cybersecurity, especially for South African businesses, which are becoming prime targets for cybercriminals. Endpoint security involves safeguarding devices connected to a network from a range of cyberthreats.

Read more...
Not enough businesses take cybercrime seriously
Information Security
Interpol recently revealed that cybercrime, specifically ransomware incidents, cost the South African economy up to 1% of the country’s GDP, while the Council for Scientific and Industrial Research estimated the loss at R2,2 billion a year.

Read more...