Friday, March 12, 2010

Poor security questions put e-mails at risk


Experts have warned that hackers can comfortably crack questions used as security checks in webmails. Security researchers at the University of Cambridge, insists that attackers can break into at least 1 in every 80 accounts if they get three chances to guess answers.

They recommends webmail firms to replace simple answers with more complex tests to confirm a person's identity. The researchers claim that hackers are successful in getting answers to security-check questions correct every 80 accounts, as information people use as answers are often publicly accessible, such as US marriage and birth records which were viewable online for a long time.

They measured how hard it was to guess answers. Asking what was the name of someone's first grade teacher seems like a secure choice. The problem is that there's a tonne of teachers out there named Mrs Smith."

They warns that cyber criminals maintain a long lists of e-mail addresses to attack. Webmail was never really designed for mail security but it is taking on a pretty important security role. Once you have an e-mail account you can take over a lot of other things with it. However, the researchers believe Webmail firms can tighten their security.

Websites such as Google, are already sending reset passwords by text message in a bid to protect the account of its users.

No comments:

Post a Comment