Data breach victims aren’t changing their passwords


A new study by academics from Carnegie Mellon University’s Security and Privacy Institute (CyLab) has revealed that only a third of users actually change their passwords after a data breach announcement.
The study, titled “(How) Do People Change Their Passwords After a Breach?”, is not based on responses from survey participants but on their actual browser traffic. To compile their study, the academics analyzed real-world web traffic collected by the university’s opt-in research group Security Behavior Observatory (SBO) which collected the full browser history of those who signed up for the purpose of academic research.
The research team then used information collected from the home computers of 249 participants between January 2017 and December 2018. This dataset not only included web traffic but also the passwords used to log into websites and those stored in participant’s browsers.
By analyzing this data, the academics found that only 63 of the 249 users had accounts on breached domains that had publicly announced a data breach during that time. According to CyLab, only 21 (33%) of these 63 users visited the breached sites in order to change their passwords. To make matters worse, of these 21 users, only 15 changed their passwords within three months after the data breach announcement.
Password security
As the SBO also captured the user’s password data, the CyLab team was able to analyze the complexity of the users’ new passwords.
The research team revealed that of those who changed their passwords, only a third changed them to a stronger password. The rest of the users created passwords of weaker or similar strength and many reused character sequences from their previous password or used passwords that were similar to their other online accounts.
While the study shows that users are still not receiving proper education when it comes to password security, the researchers argue that the hacked services are also to blame as they rarely tell users to reset their similar or identical passwords on their other accounts.
If you’re worried about your own password security, you can visit Have I Been Pwned to see if any of your online accounts have been involved in a data breach. If this is the case, you should change all of these passwords immediately and make sure that your new passwords are both strong and complex.
Via ZDNet
A new study by academics from Carnegie Mellon University’s Security and Privacy Institute (CyLab) has revealed that only a third of users actually change their passwords after a data breach announcement. The study, titled “(How) Do People Change Their Passwords After a Breach?”, is not based on responses from survey…
Recent Posts
- The government is still threatening to ‘semi-fire’ workers who don’t answer an email from Elon Musk
- Sigma’s latest camera is so minimalist it doesn’t have a memory card slot
- China ‘sinks’ 400 servers equivalent to 30,000 gaming PCs as it powers ahead with massive underwater data center project – but I wonder what GPU they use
- Can 18A save Intel from being devoured by its rivals – and Wall Street?
- SpaceX thinks it knows why Starship exploded on its last test flight
Archives
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010