ZME Science
No Result
View All Result
ZME Science
No Result
View All Result
ZME Science

Home → Science

Password meters may actually help make your data less secure by offering ‘misleading’ advice

'Password1!' isn't a good password.

Alexandru MicubyAlexandru Micu
December 19, 2019
in News, Science, Tech
A A
Share on FacebookShare on TwitterSubmit to Reddit

Password meters are meant to help secure your data, but some may be doing the exact opposite. A new paper explains that the “inconsistent and misleading” advice such helpers often give can promote weak passwords.

Image credits Markus Spiske.

The study from the University of Plymouth assessed the effectiveness of 16 password meters that are likely to see heavy and regular use. While it focused heavily on sites dedicated to this purpose, the study also included meter systems embedded in online platforms such as Dropbox and Reddit.

They concluded that there is a wide range of advice that these different platforms offer users, with various levels of quality (some being pretty abysmal).

Qwerty1234

“What this study shows is that some of the available meters will flag an attempted password as being a potential risk whereas others will deem it acceptable,” explains Steve Furnell, a Professor of Information Security and Leader of the University’s Centre for Security, Communications & Network Research, the study’s author.

“Security awareness and education is hard enough, without wasting the opportunity by offering misleading information that leaves users misguided and with a false sense of security.”

Furnell pitted 16 passwords of varying degrees of reliability — 10 of them were selected from rankings of the world’s most commonly-used passwords — against a number of meters. The purpose of such meters is to help users pick effective and secure passwords.

However, some will not even flag ‘123456’, ‘qwerty’ or ‘iloveyou’ — all listed among the worst passwords of 2019 — as being unsafe. Only five of the 10 explicitly weak passwords were consistently flagged as such by the meters. ‘Password1!’ performed surprisingly well — three meters even rated it as secure or very secure. You should probably change it on any platform you’re using it for right now.

Professor Furnell explains that the issue is further exacerbated by the fact that some of the most prominent online platforms out there haven’t improved or expanded on the password guidance they offer to users. Most of the top-ten biggest English-speaking websites are guilty of this, the study found.

And it’s not a victimless oversight. Furnell cites Verizon’s 2017 “Data Breach Investigations Report” with finding that around “81% of hacking-related breaches had ‘leveraged either stolen and/or weak passwords'”.

RelatedPosts

Yesterday, US officials said you had no right to online privacy — we don’t agree so here’s Internet Noise to help you out
Online apps and social media platforms heavily track your behavior, without your consent
Are we finally seeing the end of passwords?

Not all is lost, however. A browser-generated password used in the study was consistently rated strong, so we can probably trust these automatically-generated passwords.

“Password meters themselves are not a bad idea, but you clearly need to be using or providing the right one,” the paper explains. “It is also worth remembering that, regardless of how the meters handled them, many systems and sites would still accept the weak passwords in practice and without having offered users any advice or feedback on how to make better choices.”

“While all the attention tends to focus on the replacement of passwords, the fact is that we continue to use them with little or no attempt being made to support users in doing so properly. Credible password meters can have a valuable role to play but misleading meters work against the interest of security and can simply give further advantage to attackers.”

The paper “Password meters: inaccurate advice offered inconsistently?” has been published in the journal Computer Fraud & Security.

Tags: HelpersOnlinePasswords

ShareTweetShare
Alexandru Micu

Alexandru Micu

Stunningly charming pun connoisseur, I have been fascinated by the world around me since I first laid eyes on it. Always curious, I'm just having a little fun with some very serious science.

Related Posts

Future

Are we finally seeing the end of passwords?

byTibi Puiu
2 years ago
Science

Online apps and social media platforms heavily track your behavior, without your consent

byAlexandru Micu
3 years ago
Privacy Policy Keyboard.
Science

Yesterday, US officials said you had no right to online privacy — we don’t agree so here’s Internet Noise to help you out

byAlexandru Micu
8 years ago

Recent news

Science Just Debunked the ‘Guns Don’t Kill People’ Argument Again. This Time, It’s Kids

June 13, 2025

It Looks Like a Ruby But This Is Actually the Rarest Kind of Diamond on Earth

June 12, 2025

ChatGPT Got Destroyed in Chess by a 1970s Atari Console. But Should You Be Surprised?

June 12, 2025
  • About
  • Advertise
  • Editorial Policy
  • Privacy Policy and Terms of Use
  • How we review products
  • Contact

© 2007-2025 ZME Science - Not exactly rocket science. All Rights Reserved.

No Result
View All Result
  • Science News
  • Environment
  • Health
  • Space
  • Future
  • Features
    • Natural Sciences
    • Physics
      • Matter and Energy
      • Quantum Mechanics
      • Thermodynamics
    • Chemistry
      • Periodic Table
      • Applied Chemistry
      • Materials
      • Physical Chemistry
    • Biology
      • Anatomy
      • Biochemistry
      • Ecology
      • Genetics
      • Microbiology
      • Plants and Fungi
    • Geology and Paleontology
      • Planet Earth
      • Earth Dynamics
      • Rocks and Minerals
      • Volcanoes
      • Dinosaurs
      • Fossils
    • Animals
      • Mammals
      • Birds
      • Fish
      • Amphibians
      • Reptiles
      • Invertebrates
      • Pets
      • Conservation
      • Animal facts
    • Climate and Weather
      • Climate change
      • Weather and atmosphere
    • Health
      • Drugs
      • Diseases and Conditions
      • Human Body
      • Mind and Brain
      • Food and Nutrition
      • Wellness
    • History and Humanities
      • Anthropology
      • Archaeology
      • History
      • Economics
      • People
      • Sociology
    • Space & Astronomy
      • The Solar System
      • Sun
      • The Moon
      • Planets
      • Asteroids, meteors & comets
      • Astronomy
      • Astrophysics
      • Cosmology
      • Exoplanets & Alien Life
      • Spaceflight and Exploration
    • Technology
      • Computer Science & IT
      • Engineering
      • Inventions
      • Sustainability
      • Renewable Energy
      • Green Living
    • Culture
    • Resources
  • Videos
  • Reviews
  • About Us
    • About
    • The Team
    • Advertise
    • Contribute
    • Editorial policy
    • Privacy Policy
    • Contact

© 2007-2025 ZME Science - Not exactly rocket science. All Rights Reserved.