I had to create a new password to log into my work computer. The mail system in use is Lotus Notes, and there is a option to choose the same password for Notes and Xp. Some simple rules are applied to ensure everybody is using a strong enough password.
This requirement brought me to rethink something that hit me recently, the RockYou.com hack. It happened in December 2009 by a very simple technique, but the impact was disastrous. Over 32 million user account details were aquired and brought into the public. Later on Imperva issued an analysis of the passwords in use and the outcome was shocking.
continue reading…