Expert names the most insecure passwords


Passwords for personal accounts should not be too simple, they should not be stored as a photo in a smartphone, and online prompts can compromise user data, said Nikita Chugunov, head of the bank's digital business department and senior vice president of VTB. His words were quoted by "Izvestia" press service of the credit organization on February 21. The expert gave advice on account protection.
Chugunov noted that most often users choose predictable combinations for the password, which are quickly picked up by attackers. In addition, sometimes they use information that can be easily found in social networks or calculated through leaks.
Among the unreliable variants are passwords with a sequence of consecutive digits (9876543210 or a user's personal number), with known constants or a numeric sequence (pi), with simple words (password), with personal data (date of birth or wedding, phone number or zip code, child's name or pet's name, SNILS or car number). Also among the unfortunate variations is a "transparent" hint in the password hint ("wife's name and last year" or "street name and apartment number"). In addition, it is dangerous to store your password or bank card in notes or in the form of photos (screenshots) in your smartphone.
Modern password cracking programs check millions of such variants in seconds, so weak combinations are no longer a protection. In addition, viruses have appeared that are able to recognize such information in texts and photos and send it to fraudsters, Chugunov specified.
"Password is the first line of defense of your data. You can come up with and memorize a password through association with some incident or object that only you know about. You can also complicate a simple password by replacing some of the letters with symbols and characters, such as "!" instead of "1", etc. However, we recommend using password managers and two-factor authentication to minimize risks," he said.
On January 11, Ashot Oganesyan, founder of the DLBI data leak intelligence and darknet monitoring service, told Izvestia that if fraudsters gained access to Gosusluga, the user should go to the MFC and change the password and the number to which SMS codes are sent. Having regained access to the profile, it is necessary to analyze what exactly the attackers were doing and cancel these operations.
Переведено сервисом «Яндекс Переводчик»