There are reports in the news that Hotmail, Gmail and other email services have been compromised. (Reported online by BBC news)
This is interesting as I was discussing passwords with some friends only a few days ago. I was amazed that one person uses ‘vvvvvvv’ as his office password; that IT department needs to check their procedures!
Password strength has always been an issue. If you have ever worked in an environment where the office system forces a password change at regular intervals and does not let you reuse previous passwords, or indeed some of the characters from previous passwords, you will know what I am talking about.
BUT, if the user falls for a phishing scam, that user can have a 64 character UPPER and lower case, numerical and symbol password but it may as well be ‘fred12345′ (Look at your keyboard for the significance of FRED) or even ‘password’ because the user is giving away the password to the bad guys.
If you get an email and it looks like it’s from your ISP, email supplier, Paypal, bank, credit card or ANYTHING secure DO NOT click on the link. Go to a saved bookmark or type the address in manually.
I checked the emails my own bank and credit card company send out and they don’t have links in them. They just ask me to login to my account.
Strong passwords are good, but education of the user is even better.