Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Vulnerabilities / Threats

Women Are Four Times More Likely to Give Up Passwords for Chocolate

But overall willingness to give up passwords has dropped sharply since 2007, study finds

As part of this week's Infosecurity Europe conference, researchers stood outside the Liverpool Street tube station in London and offered 576 office workers a bar of chocolate for filling out a survey.

Included in the survey was a range of personal information, including name, address, birthdate, and computer passwords. While 45 percent of the women surveyed provided the passwords, only 10 percent of the men did so.

Overall, the local population did much better this year than during the 2007 Infosecurity Europe conference, when 64 percent of all respondents gave up their personal data for chocolate. This year, only 21 percent offered their passwords.

However, 61 percent of the respondents offered their birthdate, which is the date most often used to create passwords, the researchers noted.

"Our researchers also asked for workers' names and telephone numbers so that they could be entered into a drawing to go to Paris. With this incentive, 60 percent of men and 62 percent of women gave us their contact information," said Claire Sellick, event director for Infosecurity Europe.

"That promise of a trip could cost you dear," Sellick said. "Once a criminal has your date of birth, name and phone number, they are well on the way to carrying out more sophisticated social engineering attacks on you, such as pretending to be from your bank or phone company and extracting more valuable information that can be used in ID theft or fraud."

Workers were also queried about their use of passwords at work. Half said that they knew their colleagues' passwords. When asked if they would give their passwords to someone who phoned and said they were from the IT department, 58 percent said they would.

"This research shows that it's pretty simple for a perpetrator to gain access to information that is restricted by having a chat around the coffee machine, getting a temporary job as a [personal assistant], or pretending to be from the IT department," Sellick said. "This type of social engineering technique is often used by hackers targeting a specific organization with valuable data or assets, such as a government department or a bank."

— Tim Wilson, Site Editor, Dark Reading

Tim Wilson is Editor in Chief and co-founder of Dark Reading.com, UBM Tech's online community for information security professionals. He is responsible for managing the site, assigning and editing content, and writing breaking news stories. Wilson has been recognized as one ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Threaded  |  Newest First  |  Oldest First
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: "I feel safe, but I can't understand a word he's saying."
Current Issue
6 Emerging Cyber Threats That Enterprises Face in 2020
This Tech Digest gives an in-depth look at six emerging cyber threats that enterprises could face in 2020. Download your copy today!
Flash Poll
State of Cybersecurity Incident Response
State of Cybersecurity Incident Response
Data breaches and regulations have forced organizations to pay closer attention to the security incident response function. However, security leaders may be overestimating their ability to detect and respond to security incidents. Read this report to find out more.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-11111
PUBLISHED: 2020-03-31
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.activemq.* (aka activemq-jms, activemq-core, activemq-pool, and activemq-pool-jms).
CVE-2020-11112
PUBLISHED: 2020-03-31
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.proxy.provider.remoting.RmiProvider (aka apache/commons-proxy).
CVE-2020-11113
PUBLISHED: 2020-03-31
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.openjpa.ee.WASRegistryManagedRuntime (aka openjpa).
CVE-2020-10374
PUBLISHED: 2020-03-30
A webserver component in Paessler PRTG Network Monitor 19.2.50 to PRTG 20.1.56 allows unauthenticated remote command execution via a crafted POST request or the what parameter of the screenshot function in the Contact Support form.
CVE-2020-11104
PUBLISHED: 2020-03-30
An issue was discovered in USC iLab cereal through 1.3.0. Serialization of an (initialized) C/C++ long double variable into a BinaryArchive or PortableBinaryArchive leaks several bytes of stack or heap memory, from which sensitive information (such as memory layout or private keys) can be gleaned if...