Welcome Guest. | Log In| Register | Membership Benefits
  • Email this page E-mail this page
  • |  Print Print this page
  • |   Bookmark and Share

Women Are Four Times More Likely to Give Up Passwords for Chocolate

But overall willingness to give up passwords has dropped sharply since 2007, study finds

Apr 16, 2008 | 04:30 AM

By Tim Wilson
DarkReading

As part of this week's Infosecurity Europe conference, researchers stood outside the Liverpool Street tube station in London and offered 576 office workers a bar of chocolate for filling out a survey.

Included in the survey was a range of personal information, including name, address, birthdate, and computer passwords. While 45 percent of the women surveyed provided the passwords, only 10 percent of the men did so.

Overall, the local population did much better this year than during the 2007 Infosecurity Europe conference, when 64 percent of all respondents gave up their personal data for chocolate. This year, only 21 percent offered their passwords.

However, 61 percent of the respondents offered their birthdate, which is the date most often used to create passwords, the researchers noted.

"Our researchers also asked for workers' names and telephone numbers so that they could be entered into a drawing to go to Paris. With this incentive, 60 percent of men and 62 percent of women gave us their contact information," said Claire Sellick, event director for Infosecurity Europe.

"That promise of a trip could cost you dear," Sellick said. "Once a criminal has your date of birth, name and phone number, they are well on the way to carrying out more sophisticated social engineering attacks on you, such as pretending to be from your bank or phone company and extracting more valuable information that can be used in ID theft or fraud."

Workers were also queried about their use of passwords at work. Half said that they knew their colleagues' passwords. When asked if they would give their passwords to someone who phoned and said they were from the IT department, 58 percent said they would.

"This research shows that it's pretty simple for a perpetrator to gain access to information that is restricted by having a chat around the coffee machine, getting a temporary job as a [personal assistant], or pretending to be from the IT department," Sellick said. "This type of social engineering technique is often used by hackers targeting a specific organization with valuable data or assets, such as a government department or a bank."

— Tim Wilson, Site Editor, Dark Reading


Subscribe to RSS










Bugs
ENTERPRISE VULNERABILITIES
Vulnerability:suse linux
Published:2010-01-22
Severity:High
Description:SUSE Linux Enterprise 10 SP3 (SLE10-SP3) configures postfix to listen on all network interfaces, which might allow remote attackers to bypass intended access restrictions.
Vulnerability:ie
Published:2010-01-22
Severity:High
Description:The URL validation functionality in Microsoft Internet Explorer 7 and 8 does not properly process input parameters, which allows remote attackers to execute arbitrary local programs via a crafted URL, aka "URL Validation Vulnerability."
Vulnerability:bind
Published:2010-01-22
Severity:Medium
Description:ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P5, 9.5 before 9.5.2-P2, 9.6 before 9.6.1-P3, and 9.7.0 beta does not properly validate DNSSEC (1) NSEC and (2) NSEC3 records, which allows remote attackers to add the Authenticated Data (AD) flag to a forged NXDOMAIN response for an existing domain.
Vulnerability:ie
Published:2010-01-22
Severity:High
Description:Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-2530 and CVE-2009-2531.
Vulnerability:ie
Published:2010-01-22
Severity:High
Description:Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-3671, CVE-2009-3674, and CVE-2010-0246.


Briefing Centers
POWERFUL INFORMATION
AT YOUR FINGERTIPS
(SPONSORED LINKS)