IT Reseller Magazine
Article Search: Go To: Keyword 
 
   

FREE Subscription to IT Reseller Magazine






Internet Security
Internet control, email and network protection


TWO THIRDS OF WORKERS REVEAL PASSWORDS FOR CHOCOLATE AND A PRETTY SMILE
11 May 2007  

A survey by Infosecurity Europe of 300 office workers and IT professionals has found that 64% were prepared to give their passwords in exchange for a bar of chocolate and a smile.  The survey also found that 67% thought that someone else in their organisation knew their CEO's password with the most likely candidate being the secretary or PA.

The survey was carried out to find out how easy it was to extract peoples work passwords using social engineering techniques with literally just the offer of a chocolate bar for taking part in a survey.  The survey was carried out amongst commuters in London Stations and also at an IT exhibition full of computer professionals just to see how much more security savvy they were compared with the average worker.

The survey found that it took a little more probing and a bit more coercion than the average office worker, but even the IT professional eventually succumbed to the questions of the attractive researcher who still managed to extract their passwords in exchange for a smile and a chocolate bar!

The researchers asked the delegates if they knew what the most common password is and then asked them what their password was.  Only 22% of IT professionals revealed their password at this point compared to 40% of commuters, if at first they refused to give their password the researchers would then ask if it was based on a child, pet, football team, etc, and then suggest potential passwords by guessing the name of their child or team.  By using this technique, a further 42% of IT professionals and 22% of commuters then inadvertently revealed their password.   This then took the total number of people who revealed their password to 64% overall for both groups.   What many of IT professionals failed to realise is that the researchers, who conducted the survey at the IT exhibition, had also read their names and organisation from their delegate badge as well!

The survey found that 20% of organisations no longer use passwords, with 5% using biometric technology and tokens for identity and access management and a further 15% using tokens.

The average number of passwords used at work was 5 per person, with some using as many as 20.  The frequency of changing passwords was 71% monthly, 10% rarely and 20% never as they used biometrics and tokens instead.  Some of the IT professionals said that the real issue was not user passwords but the passwords on servers or buried in applications which were never changed as the consequence of changing them on the overall company IT system was unknown and there was a fear that if they were changed a critical part of the system could crash.  Some other IT experts said that they often come across servers on which the administrator password was left blank.

When asked if they knew any of their colleagues passwords 29% admitted that they did. A person should never need to give their password to someone claiming to be from the IT department but 39% said that they would give their password to someone who called them from the IT department.  They would not be quite so trusting if asked by their boss as only 32% said they would be prepared to give their password if asked.

When asked about confidential information two thirds said that they would look at a file containing everyone's salary details if they were sent it by mistake and 20% said they would pass it on to colleagues.  A third said that they would keep it confidential, with many of them also saying that their IT systems tracked everything they looked at and if they passed this type of information on to anyone it would mean instant dismissal.  When asked if they would take any contacts or competitive information with them when they left their jobs, 58% said that they would.  One senior sales manager said I left my job last week and took my whole pipeline with me.

Just under half of people used the same password they used for their corporate access for all their personal web accounts such as online banking, retailing, and email.  When asked if they felt safe using online banking half said that they did but only a fifth said they felt safe using online retailing but this figure rose to 52% if the retail site was a well know reputable one.


Other Internet Security News Security White Papers
Newly patented technology 'reaffirms AhnLab position as premier provider of online banking security'
AhnLab Inc., provider of integrated security solutions, has announced the issuance of Korea Intellectual Property Office (KIPO) Patent No. 10-2008-0007159: "Protection System and Method for Internet Websites."
Employee survey highlights dangers of insider threat
Whilst the media seems pre-occupied with the problems of cybercriminals and hackers causing problems for organisations from outside their network, a survey just published shows that 23 per cent of UK employees will take customer lists and other sensitive data when they leave their employer.
Trusteer warns financial malware is attacking leading US banks using Visa and MasterCard
Trusteer has announced that the Zeus (Zbot) financial malware is targeting online banking customers of 15 leading US financial institutions by exploiting two trusted credit card security programs.
Barracuda spam & virus firewall offers broader outbound email content filtering capabilities
Barracuda Networks Inc., provider of security, storage and networking solutions, has announced new features to its flagship Barracuda Spam & Virus Firewall that enhance full inbound and outbound email scanning from the same appliance.
Over half of IT professionals are still leaving mobile security to chance
As threats to corporate data grow, and the cost of breaches increase, a survey of alleged security conscious professionals has remarkably revealed that over half of respondents (52%), who admit to carrying company data on a USB stick, do not encrypt it.
Webroot announces channel expansion in Ireland
Webroot has announced its plans to recruit an additional ten strategic channel partners in Ireland, to expand the availability of Webroot Web Security Service, Webroot Email Security Service and Webroot Email Archiving Service.

More >>

Understanding the value of outsourcing network security services
This white paper will examine the many new challenges that are facing today’s network owners, the pros and cons of using in-house resources and outsourcing for your network assessment and day-to-day monitoring, as well as guidelines to help select and maximize the value of outside resources.
GFI warns one anti-virus engine is not enough to protect your business
Although 99% of large British companies use anti-virus products, 43% were still infected by viruses (UK ISBS Survey 2006)
CONTENT FILTERING SOLUTIONS TECHNOLOGY REPORT APRIL 2006
Source: West Coast Labs/Netintelligence
The Trend of Threats Today: 2005 Annual Roundup and 2006 Forecast
Trend Micro
The report that follows is not only an account and analysis of 2005 threat
incidents. It also serves as a forecast of what the future holds in 2006 and
onwards. Through Trend Micro‘s extensive research and analysis of the 2005
incidents, this paper documents how threats evolved into the multi-purpose
threat regime – thus providing corporate and home users information on what
to do to ensure they remain protected against future threats. Download free white paper.
If you can't beat it, manage it
David Caughtry of Computerlinks looks at the challenges facing IT managers with the growing use of Instant Messaging in the workplace.
Are you becoming a one-stop security shop?
David Ellis, director of e-security at Unipalm discusses best practice security management and the evolution of protection technology.

More >>

advertisements


 



Related Articles


Let the news come to you!
Subscribe to our weekly newsletter and the digital edition of IT Reseller Magazine!

Email Address:   



© Copyright 2006, IBC - Interactive Business Communications

Help | Contact Us | PrivacyRSS Feeds | Site Map | Advertise
YourTechTV.com Only Technology Videos