Researchers tracked the passwords 154 people used online for an average of 147 days and found them logging into 26 websites with fewer than 10 unique passwords — roughly 60 percent were reused outright or built from pieces of passwords they were already using elsewhere
Source ↗
👁 0
💬 0
For about five months, a browser extension sat quietly on the home computers of 154 people and watched them log in.
The researchers never saw a password. Everything was hashed on the machine before it went anywhere, leaving them with the shape of each one: its length, its mix of characters, the site it was typed into, and whether the same string had appeared before.
Very often, it had.
What 154 people actually typed
Sarah Pearman and her co-authors at Carnegie Mellon University presented the res
The researchers never saw a password. Everything was hashed on the machine before it went anywhere, leaving them with the shape of each one: its length, its mix of characters, the site it was typed into, and whether the same string had appeared before.
Very often, it had.
What 154 people actually typed
Sarah Pearman and her co-authors at Carnegie Mellon University presented the res
Comments (0)