Technology Is Not the Final Answer….
Every year Infosecurity performs a security-related experiment. They ask office workers questions about their passwords, where they work, what they do…then ask for their actual password. A shocking number of people hand it right over.
OK, so here’s the question: Exactly how ignorant are they? The experiment found that out of 576 people questioned this year, 21% were quite happy to reveal their passwords in exchange for candy.
But maybe some of the dire news of late is sinking in, because that number is a heck of a lot lower than when the same experiment was conducted last year. Back then, a whopping 64% of the respondents were willing to give away their passwords. It seems that users have never paid attention to their mother’s advice about strangers and candy.
A curious aspect of the results was that, of those willing to trade away their passwords, women were 4.5 times more likely to spill the beans then men. Even more astounding was that 61% of all people surveyed happily revealed their date of birth!
This stuff drives me crazy. I see people handing over personal data all the time in stores in exchange for a free t-shirt or even a free sample of something. I always chalked this up to naiveté, but I can point to my own derivative experiment based on the Infosecurity one. When the results are announced each year, I bring this up at work with my IT peers. Usually 80% of my co-workers are willing to tell me enough about their passwords for me to guess or find out what it is (“My password is always my girlfriend’s birthday, so I never forget it” or “I always use Star Wars, but spelled with a Z instead of an S.”) without my even asking. I’d also say 9 times out of 10, talk turns to passwords for the non-user accounts, say the SA password for a production SQL Server. For some reason, all sense of security of this information goes out the door as the password is almost always mentioned. I’ve always wondered if this is because workers don’t value these non-personal resources as much as they do their own browser history, e-mail, and YouTube ratings.
I remember meeting with a potential financial advisor for a very large financial institution. Our talk turned to passwords and I told him about the study where people would hand over their passwords for the most trivial of treats. He rolled his eyes and then said how stupid IT professionals are to require these. I mentioned that I was an IT professional and that strong passwords were the best defence against data theft and fraud. He then proceeded to talk about all the new online systems that his company was foisting upon him and his clients. And, of course, then he proceeded to tell us what his login and passwords were and why they were so easy to remember. I sat their in stunned silence. His giving out this information was not a great selling point for me for his services. After having bragged about managing millions and millions of dollars of portfolios for some very famous people, then telling me his login credentials, he had basically showed me he could not be trusted with my data or my finances. Needless to say, he did not get my business.
And what is this “women were 4.5 times more likely” to fall for this scheme? Are we females really that clueless? Is it that we avoid confrontation or have been raised to never say “no” when asked for a favor? That number bothers me. The Register believes it is because women love chocolate more than security.
I remember another conversation with a budding IT professional. He had been talking to our intern about how secure the newest encryption technology was and how absolutely unbreakable it was. As a sage (old) IT pro, I had to break the news to both the intern and the IT-wannabe that the encryption technology was useless in an age of social engineering and corporate cluelessness. Both were flabbergasted that I could possibly question the value of what was probably 32-bit encryption at the time. They both spouted off mathematical certainties of how many billions of years it would take to crack the code of highly secure encryption. I tried to explain to them that technology was not the issue most of the time. The both rolled their eyes and said that I just couldn’t understand how big the numbers were.
So I dragged our IT-wannabe over to the assistant to the CIO’s desk and lifted up her keyboard to show him the Post-It note with all the CIOs logins and passwords. He objected that the list of what were obviously user names and passwords could be anything. Then I took him over to the DBA set of cubicles and showed him how the whiteboard outside their cubes contained mysterious pairs of what were obvious user names and passwords. He still didn’t believe me. So he asked the admin assistant the next day how she kept track of all the logins and she showed him that she wrote them down on a Post-It and stuck it under her keyboard. Then he asked the DBAs if those were credentials on the whiteboard, and they first denied it, then admitted it. He chalked this up to clueless IT people. So I walked with him back to his cube, and pointed out that he kept his own password on a Post-It note stuck on the side of his monitor. Cluelessness, indeed.
Some days I feel as if all the work we put into data governance, information quality, and information security is for naught. Why bother if no one values the data in the first place? Why don’t business uses and IT caretakers love their data?
I believe that we data management professionals must hold ourselves to a higher standard that what we see in the rest of the world. We can go on and on about data quality, information integrity, and information protection. But if we are giving out passwords right and left, writing passwords on whiteboards, and generally following terrible security practices, how are we ever going to convince the business that they need to treat the data better than we do?
Your thoughts? Your observations?
4 Comments
Leave a comment
Subscribe via E-mail
Recent Comments
- Karen Lopez on Strutting: We all Know When You are Doing It. So Stop.
- Joey D'Antoni on Strutting: We all Know When You are Doing It. So Stop.
- Karen Lopez on Strutting: We all Know When You are Doing It. So Stop.
- Thomas LaRock on Strutting: We all Know When You are Doing It. So Stop.
- Karen Lopez on Strutting: We all Know When You are Doing It. So Stop.
Recent Posts
Downloads
- EDW 2013 Karen Lopez Get Blogging
- Karen Lopez presentation DAMA PS 2012
- Data Modeling Contentious Issues - DAMA Nebraska
- Karen Lopez - 10 Physical Blunders - DAMA
- Career Success In Data Profession - DAMA
- The Straw Poll
- You've Just Inherited a Data Model CheckList
- KarenLopez - 5 Physical Blunders - 24HOP-2011
- Handouts for OEMUG / CA Global Modeling User Group Why Be Normal Webcast
- Handouts Database Design Contentious Issues - New York 2010
- Handouts Database Design Contentious Issues - DC 2010
Archive
- May 2013 (4)
- April 2013 (5)
- March 2013 (4)
- February 2013 (7)
- January 2013 (12)
- December 2012 (2)
- November 2012 (3)
- October 2012 (3)
- September 2012 (13)
- August 2012 (5)
- July 2012 (17)
- June 2012 (2)
- May 2012 (4)
- April 2012 (4)
- March 2012 (8)
- February 2012 (11)
- January 2012 (3)
- December 2011 (10)
- November 2011 (8)
- October 2011 (5)
- September 2011 (3)
- August 2011 (9)
- July 2011 (5)
- June 2011 (5)
- May 2011 (5)
- April 2011 (9)
- March 2011 (4)
- February 2011 (9)
- January 2011 (8)
- December 2010 (15)
- November 2010 (27)
- September 2010 (2)
- August 2010 (1)
- July 2010 (4)





I’ve several friends who’ve had accounts broken into, but I’ve given up trying to get them to adopt a password manager.
I can’t say I blame them: most such tools suffer from feature-bloat and don’t delineate core from advanced functionality. They then require you to spend the better part of an afternoon retrofitting your existing accounts.
And the trend to allowing facebook/google/openID credentials to serve as universal logins is probably a wash.
Well, thanks to Infoadvisors for not requiring account creation to post here
Right now the spam comments are at a low enough level that I haven’t required a login. That might change if I have to spend more time removing spam comments that enjoying my blog and comment posters.
I think that is why so many sites have adopted third party authentications such as Facebook and Open IDs.
This is not a new phenomenon but in the age of instant access to vast quantities of mission critical data, social engineering can be the best way to get unauthorized access. The problem with password managers is that by their very nature they are at best a single point of failure or at worst an “Aladdin’s Cave” of precious data for the blackhats. In an ideal world the encryption is perfect and the employees are suspicious of strangers. In the real world I’m handing out my credit card number in an email so I can get that thing on craigslist.
http://www.esecurityplanet.com/news/article.php/3896386/Companies-Fail-DefCon-Social-Engineering-Security-Test.htm
I have not read about any password keeper hacks. That doesn’t mean they don’t exist, though.
People will always be the weakest link in security.