1.2 billion stolen login credentials expose major issue of user authentication code breaches
The problem of the vulnerable way of confirming users' identities through keywords (passwords) - which are often repeated, as most people use the same "secret" word to access different online services (such as email and social media accounts or even web banking applications), is demonstrated by a recent report, according to which a group of Russians stole 1.2 billion usernames and passwords from 420,000 websites.
According to information, the breaches concern different sizes of companies, from Fortune 500 companies to very small businesses. The websites that were breached were not reported, as many of them are still vulnerable to attacks.
The Russian group allegedly managed to obtain this data using botnets, thus identifying websites with vulnerabilities. It is believed that the attackers have not sold much of the information they have intercepted, instead they have used it to send spam messages via social networks. However, this information could be of great importance to other cybercriminals. If users reuse the passwords on other online services - something that is common for most people - then the attackers can gain access to other accounts, thus collecting additional sensitive personal information about the victim.
The incident demonstrates once again how problematic the current password system is. It is common to reuse passwords on countless websites and services or create passwords that can be easily predicted.
This means that if an attacker manages to gain access to a user's login credentials by hacking one website, they can potentially gain unauthorized access to many of their other accounts.
Even frequent updates about major vulnerabilities aren’t enough to convince people to change their passwords. A recent report from the Pew Research Center found that fewer than four in ten people who were aware of the Heartbleed vulnerability changed their passwords in response to the bug.
Mobile Device Use
The proliferation of smartphones has boosted the popularity of two-factor authentication. When users log in with their passwords, they receive a second, temporary code via email, SMS, or directly in apps.
This means that even if a user’s password is compromised, an attacker still needs to gain access to the second code to breach the targeted account.
The next step in making any login secure seems to be biometric authentication. Although this type of technology has been around for some time, Apple was the first to make it widely known, with the addition of a fingerprint recognition sensor in the iPhone 5S. Users can unlock their phones or check their iTunes purchases by placing their finger on the home button. Biometric authentication on smartphones doesn’t just include fingerprints. A Samsung executive recently said the company is looking into devices that scan users’ irises to identify them.
The authentication of the future
The process of authenticating users seems to still have a long way to go, as researchers are constantly looking for new ways that often seem straight out of science fiction. Last year, Regina Dugan, head of the Advanced Technology and Projects group at Google, proposed a tattoo or a pill that could identify the user. All users would have to do is touch their device – or even their car – to unlock it.
A company that emerged from the University of Oxford is also working on a new authentication system. Oxford BioChronometrics’ system calculates the countless different behaviors a user exhibits when interacting with their device.
This could include the way the user tilts their phone when typing, the speed at which they scroll, the movements they make with their mouse, and more. The system combines this information to create an “electronically Defined Natural Attributes (eDNA)” of the user, which it then uses to identify them.
Helpful steps
However, it may be some time before these ambitious projects for authentication methods become a reality.
So, for now, companies that specialize in providing security solutions and protecting computer systems, such as Symantec, advise users to safeguard their online information from attackers by following some simple steps:
- Always use strong passwords and never reuse them on other websites or applications.
- Enable two-factor authentication on websites that offer it.
-Consider using a password manager, such as Norton Identity Safe, which securely stores different passwords to online services.
Source: protothema.gr

