Technology

One password for everything is one breach away from losing everything — seven ways reuse goes wrong, and the twenty-minute fix

When a shopping site leaks its user list, criminals feed those email-and-password pairs into automated tools that try them on Gmail, Facebook, bKash and your office login within hours. If the password is the same, they are in. The seven specific ways that plays out, why the email account is the one that matters most, and how to end the problem in an evening with a password manager.

One password for everything is one breach away from losing everything — seven ways reuse goes wrong, and the twenty-minute fix

Most people use one password, or one password with small variations, for everything, because remembering thirty is impossible. Security researchers regard this as the single most dangerous habit in ordinary computing, and the reason is not that any one password is weak. It is that the accounts are linked by it. Here is how that link is used against you.

The seven risks

  1. One breach opens every door. Websites are breached constantly, and the stolen lists of email addresses and passwords are traded openly. If the password on a breached recipe forum is also your Facebook password, your Facebook is as good as breached too.
  2. The email account is the master key. Whoever controls your email can reset the password of every other service by clicking “forgot password”. An attacker who gets into Gmail with a reused password does not need the others; they can take them one by one.
  3. Money goes first. Reusing a password on shopping sites, bank portals or mobile-money apps turns a leaked forum login into unauthorised purchases, transfers and drained balances.
  4. The attack is automated. Criminals do not try passwords by hand. Credential stuffing tools test millions of leaked pairs against hundreds of popular sites in hours. A reused password is found and used before you have heard of the breach.
  5. Your identity is used against your friends. A hijacked Facebook or WhatsApp account becomes a tool for scamming everyone who trusts you — “I’m stuck, send Tk 5,000 by bKash” — and often ends with the account permanently banned.
  6. Home leaks into work. Using the same password for personal accounts and the office means a hobby site’s breach becomes a route into company email, documents and internal systems — and a disciplinary matter.
  7. Recovery becomes a crisis. When several accounts fall at once, each must be recovered separately while the attacker is still changing recovery emails and phone numbers. It takes days, and some are never recovered.

The fix, in one evening

You do not need to memorise thirty passwords; you need to memorise one. Install a password manager — Bitwarden is free and open-source; Google’s and Apple’s built-in managers are adequate — and let it generate and store a different long password for every site. Then, in this order:

  1. Change the email account’s password first, to something unique, and switch on two-step verification there.
  2. Do the same for mobile money and banking.
  3. Work through social media and shopping accounts as you next log in to each.

Check whether your addresses already appear in known breaches at haveibeenpwned.com. In Bangladesh, where the NID number, a phone number and one common password are enough to impersonate a person in most systems, the reused password is the weakest of the three and the only one entirely in your hands.

Source: Techlusive, via Prothom Alo.

Source: Prothom Alo

Written by

Rakin M

Rakin M writes Tech BD’s security and privacy coverage — breaches, scams, surveillance and account safety. He is more interested in the step a reader can take this evening than in the name of the vulnerability, and says so in most of what he writes.