Do you *really* need unique passwords everywhere?

preview_player
Показать описание
The first time I was told I needed a strong password was in high school. It was to protect against brute force cracking. No one even really mentioned "unique" passwords for years but now everyone is screaming about it. Is it really that big of a deal? Spoiler alert: yes it is, unfortunately.

Reused passwords are the cause of millions of account takeovers every month. Starting with a data breach that leaks one set of passwords, attackers will feed those giant lists of passwords (combolists) into specialized tools (checkers) and run them against any number of other services to find out who reuses passwords. Once the list of valid accounts is generated, criminals will then defraud them in mass, individually, or sell these accounts on dark web marketplaces. This is called "credential stuffing" - replaying breached credentials over and over again to see what hits.

To see these checkers for yourself, google "[website name] account checker" e.g. "netflix account checker" like in the video. To find cymbalists, simply search for "combolist". Twitter is a good place to search for these things as well. Users will advertise combolists for sale by posting partial lists on services like pastebin.

Рекомендации по теме
Комментарии
Автор

You did a great job of picking apart all the major mindsets people have around password creation. I really liked the visuals with the envelopes. I hope you do more visually illustrative stuff, even with a whiteboard etc. Looking at the same problem from different angles is quite rare these days, especially in youtube tutorials.

dittilio
Автор

I think what's interesting is the way you explain, it's to the point and easy to understand even though this is a long video, and this topic is relatable to me. Also you remind me of Travis Neilson from DevTips.

mfi
Автор

Equally informative and terrifying. I'd never thought about how password managers actually work to keep all that info secure(ish.) Thanks JRod!

HardyCozen
Автор

You convinced me to use a password manager. Nice video dude.

nostrilsopen
Автор

Great video!
My suggestion for the next topic is cryptography/security in email. How can i guarantee my personal messages isn't being collected by companies and still have a nice email provider?

rdgv
Автор

I still have so many envelopes to get rid of. Anyone have any ideas on what to do with the 100s I have left?

jsoverson
Автор

That´s really helpful advices..But u should be sure u don´t have any keyloggers spying on you. Another thing I´ll never have this lamp, plant sock combination making part of my passwords.coz u and many other people already know tham..Kidding. lol

paulosilva-dmqb
Автор

I couldn't quite follow... all I could see was User: Jarrod | Password: I don't see where the security flaw is.

dittilio