HomeSecurityOnly a few users change passwords after a data breach!

Only a few users change passwords after a data breach!

passwords

A study by Carnegie Mellon University's Security and Privacy Institute (CyLab) showed that after a data breach is announced, only a third of usersaffected

The study, presented earlier this month at the IEEE 2020 Workshop, was not based on data , but on actual browser traffic.

The academics analyzed real web traffic, collected with the help of the Security Behavior Observatory (SBO) , a research group where users register and share their full browser history to enhance academic research.

The dataset included information collected from the home computers of 249 participants. The data was collected between January 2017 and December 2018. It included web traffic as well as passwords used to log in to sites and stored in the browser.

The academics discovered that of the 249 users, 63 had accounts on domains that had been compromised and had publicly announced the breach dataduring the research.

CyLab researchers stated that out of 63 users, only 21 (33%) visited the compromised sites to change their passwords, and of those 21, only 15 users changed their passwords within the first three months after the data breach was announced.

In total, only 23 passwords were changed on the compromised domains. Of the 21 participants, 18 were Yahoo! users. The remaining Yahoo! users did not change their passwords, even though they were all affected by the data breach. Two participants changed their Yahoo! passwords twice after the breach was announced. Two participants changed their passwords on the compromised domain within the first month after the breach was announced, five within two months , and the remaining eight within three months.

data breach

The researchers were also able to analyze the complexity of the new passwords chosen by users.

The research team found that of the 21 users who changed passwords, only 9 chose a stronger password (with appropriate size, characters, etc.).

The rest created passwords with lower or similar strength, reusing character sequences from their previous password or using passwords that were similar to those of other accounts that had been saved in the browser.

The study shows that most users still lack the knowledge needed to choose unique and stronger passwords. The researchers say much of the blame lies with the compromised services, which “almost never tell people to change passwords on their other accounts.”

The study didn't include a large number of participants (like others), but it is more accurate in terms of user behavior after a data breach , as it is based on actual browsing data rather than responses that may be inaccurate.

The study is called “(How) Do People Change Their Passwords After a Breach?” and you can read it here.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS