Surprising New Password Guidelines from NIST

The US National Institute of Standards and Technology (NIST) just finalized new draft guidelines, completely reversing previous password security recommendations and upending many of the standards and best practices security professionals use when forming policies for their companies.

LeakedSource Shut Down by DOJ

Last week, a breach notification site named LeakedSource was allegedly shut down by US law enforcement and much of their equipment confiscated. The reasons why they may have been targeted by law enforcement are unknown, although it’s possible to hazard some guesses as to why. Were they White Hat, Black Hat or Grey Hat?

PasswordPing Launches Exposed Password and Credentials API Service for Enterprises

PasswordPing announces the launch of its patent-pending password and credential breach notification service, which proactively notifies organizations if their users are using exposed credentials. Billions of accounts have been exposed in breaches and often the users are completely unaware of it. PasswordPing now has a number of tools to help organizations protect their users.

Punishing users for *possibly* using another site with a breach

I recently received an email that notified me of a forced password reset for one of my online accounts due to the AdultFriendFinder breach. I DON’T have an AdultFriendFinder account and have never used that site, but because of the reuse of passwords across multiple sites, a breach for one company creates a domino effect for other companies.

Users suck at secure passwords. Help them.

How many of your users are using insecure and compromised passwords? You may have a standard password strength meter on your site so you may think that your users have secure passwords. Think again. Password strength meters and password complexity requirements are simply not enough.

What the Heck is “Credential Stuffing”?

Billions of user credentials (usernames and passwords) have been exposed publicly over the last few years. The natural question that comes up is “what do cybercriminals do with these stolen credentials?” Well, apart from using them to attempt logins to the breached website itself, the second most common thing cybercriminals will do with stolen credentials is to use them in an attack called “credential stuffing.”

Yahoo Confirms Largest Known Breach in History: 500M Accounts

Back in August, a hacker named peace_of_mind claimed to be selling a database containing credentials for 200 million Yahoo accounts.

At the time Yahoo indicated they were investigating the matter, but could not confirm.

Today, Yahoo confirmed that 500 million accounts were compromised in what we believe is the largest known data breach in history.