Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Vulnerabilities / Threats

Women Are Four Times More Likely to Give Up Passwords for Chocolate

But overall willingness to give up passwords has dropped sharply since 2007, study finds

As part of this week's Infosecurity Europe conference, researchers stood outside the Liverpool Street tube station in London and offered 576 office workers a bar of chocolate for filling out a survey.

Included in the survey was a range of personal information, including name, address, birthdate, and computer passwords. While 45 percent of the women surveyed provided the passwords, only 10 percent of the men did so.

Overall, the local population did much better this year than during the 2007 Infosecurity Europe conference, when 64 percent of all respondents gave up their personal data for chocolate. This year, only 21 percent offered their passwords.

However, 61 percent of the respondents offered their birthdate, which is the date most often used to create passwords, the researchers noted.

"Our researchers also asked for workers' names and telephone numbers so that they could be entered into a drawing to go to Paris. With this incentive, 60 percent of men and 62 percent of women gave us their contact information," said Claire Sellick, event director for Infosecurity Europe.

"That promise of a trip could cost you dear," Sellick said. "Once a criminal has your date of birth, name and phone number, they are well on the way to carrying out more sophisticated social engineering attacks on you, such as pretending to be from your bank or phone company and extracting more valuable information that can be used in ID theft or fraud."

Workers were also queried about their use of passwords at work. Half said that they knew their colleagues' passwords. When asked if they would give their passwords to someone who phoned and said they were from the IT department, 58 percent said they would.

"This research shows that it's pretty simple for a perpetrator to gain access to information that is restricted by having a chat around the coffee machine, getting a temporary job as a [personal assistant], or pretending to be from the IT department," Sellick said. "This type of social engineering technique is often used by hackers targeting a specific organization with valuable data or assets, such as a government department or a bank."

— Tim Wilson, Site Editor, Dark Reading

Tim Wilson is Editor in Chief and co-founder of Dark Reading.com, UBM Tech's online community for information security professionals. He is responsible for managing the site, assigning and editing content, and writing breaking news stories. Wilson has been recognized as one ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Commentary
What the FedEx Logo Taught Me About Cybersecurity
Matt Shea, Head of Federal @ MixMode,  6/4/2021
Edge-DRsplash-10-edge-articles
A View From Inside a Deception
Sara Peters, Senior Editor at Dark Reading,  6/2/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
The State of Cybersecurity Incident Response
In this report learn how enterprises are building their incident response teams and processes, how they research potential compromises, how they respond to new breaches, and what tools and processes they use to remediate problems and improve their cyber defenses for the future.
Flash Poll
How Enterprises are Developing Secure Applications
How Enterprises are Developing Secure Applications
Recent breaches of third-party apps are driving many organizations to think harder about the security of their off-the-shelf software as they continue to move left in secure software development practices.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-34682
PUBLISHED: 2021-06-12
Receita Federal IRPF 2021 1.7 allows a man-in-the-middle attack against the update feature.
CVE-2021-31811
PUBLISHED: 2021-06-12
In Apache PDFBox, a carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the file. This issue affects Apache PDFBox version 2.0.23 and prior 2.0.x versions.
CVE-2021-31812
PUBLISHED: 2021-06-12
In Apache PDFBox, a carefully crafted PDF file can trigger an infinite loop while loading the file. This issue affects Apache PDFBox version 2.0.23 and prior 2.0.x versions.
CVE-2021-32552
PUBLISHED: 2021-06-12
It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-16 package apport hooks, it could expose private data to other local users.
CVE-2021-32553
PUBLISHED: 2021-06-12
It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-17 package apport hooks, it could expose private data to other local users.