Three out of four of the world’s most popular websites are allowing tens of millions of users to create weak passwords and, in the process, failing to meet minimum requirement standards.
Researchers at Georgia Tech (https://www.cc.gatech.edu/news/largest-study-its-kind-shows-outdated-password-practices-are-widespread) developed an automated tool - the first of its kind - to assess password creation policies and found that more than 10% of websites failed when it came to password length requirements.
The tool explored the database of one million websites and pages in the Google Chrome User Experience Report (CrUX) and showed that many sites allowed very short passwords, didn't block common passwords and used outdated requirements such as complex characters.
Other findings included:
- Sites used (outdated) guidelines from 2004 - More than half of the websites accepted passwords of six characters or less - 75% of websites failed to require the recommended eight-character minimum - Nearly a third did not support spaces or special characters - 12% of had no length requirements
Additional to this, less than a third of websites enforced a password block list, so thousands are vulnerable to a password spraying attack i.e. hacker using common passwords to break into accounts.
Not many of us like passwords. Who wants to change one or more every few months or follow all sorts of guidelines to set up one? Humans are creatures of habit and use patterns when choosing or changing passwords. This makes guessing passwords easier, which plays straight into the hands of hackers.
If this study is any guide, many websites are more concerned with customer satisfaction than security, and 99% of the time a happy customer wins out.




