HomeSecurityEven the US government uses weak passwords

Even the US government uses weak passwords

It is alarming how even the most important US federal agencies fail to create effective passwords. It is surprising that even the US government uses the password “Password1234”.

A stunning audit by the US Department of the Interior revealed that more than a fifth of user accounts had weak passwords, making them vulnerable to hackers.

See also: Fake AnyDesk sites infect victims with Vidar malware

Even the US government uses weak passwords
US: Even the government uses weak passwords

Password hashes for nearly 86,000 active directory (AD) accounts were obtained, and more than 18,000 of them were cracked using fairly standard hacking methods. Most were cracked within the first 90 minutes.

Additionally, nearly 300 of the hacked accounts belonged to executives, while nearly the same number had elevated privileges.

The auditors were able to crack the hashes with two devices that cost a total of less than $15,000. These devices included a total of 16 GPUs – some older models – and ran an extensive list containing over a billion words that could be used in the passwords for the accounts.

See also: New Dark Pink hacking group discovered: Who is it targeting?

To guess passwords, hackers used words like “qwerty,” phrases related to the U.S. government , and references from popular culture. They also used information obtained from publicly accessible lists of data breaches of private and public organizations.

Among the most common passwords used, “Password-1234” was chosen by nearly 500 accounts. Even minor variations like “Password1234,” “Password123$,” and “Password1234!” were used by hundreds of other accounts.

Password
Protection

The audit revealed a dangerous deficiency in the organization ’s multi-factor authentication (MFA) to protect accounts – nearly 90% of high-value assets (HVAs) remained unprotected. This lack of security for HVAs, which are an integral part of the organization’s operations, is unacceptable and must be addressed immediately.

The audit report stated that if a malicious actor gains access to the department's password hashes, they would be able to achieve similar results to what the auditors achieved.

Another issue is that all passwords adhered to the strict guidelines set by the department – ​​at least 12 characters including uppercase letters, numbers and special characters.

However, testing shows that adhering to these standards doesn’t always lead to secure passwords. In general, hackers use lists of words that people commonly use and don’t have to force each one individually to crack them. This easier , as they won’t have to spend time cracking difficult passwords.

See also: Puzzle trojan attack trains AI assistants to suggest malicious code

The audit found that the second most frequently used password was “Br0nc0$2012,” as stated in the report.

This password may seem “stronger,” but it is actually incredibly weak, as it relies on a single dictionary term with obvious character substitutions.

The Inspector General also stated that passwords were not changed every 60 days, as required.

Creating strong passwords is essential for keeping your online accounts safe from hackers and cybercriminals.

Information source: techradar.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS