Gemalto is now part of the Thales Group, find out more.
Skip to content
Gemalto: Security to be free
Our blogs: Conversations around digital security
Search
Back to articles
  • Home
  • Mobile
  • Enterprise Security
  • IoT
  • Financial Services
  • Government
  • Software Monetization
  • Featured Bloggers
    • Gemalto (658)
    • Manfred Kube (113)
    • Tim Cawsey (83)
    • Jennifer Dean (62)
    • Marta Bordonada (59)
    • Rémi de Fouchier (53)
    • Arta Sylejmani (41)
    • Dominique Brulé (38)
    • Philippe Benitez (37)
    • Didier Benkoel-Adechy (32)
    • Maria Barbieri (30)
    • Kristel Teyras (24)
    • Xavier Larduinat (21)
    • Haider Iqbal (21)
    • Sebastien Violette (20)
    • Frederic Martinez (20)
    • Neville Pattinson (20)
    • Sophie Bessin-Py (19)
    • John Ahlberg (19)
    • Ken Abbott (19)
    • Brittany Jedrzejewski (18)
    • Nicole Williams (14)
    • Isabelle Lodo (13)
    • Sek Leong (12)
    • Jennifer Hindle (12)
    • Axel Hansmann (10)
    • Sharon Ginga (10)
    • Cecile Eurendjian (10)
    • Christian Hartwigsson (8)
    • Kim Depussé (8)

    Latest blog posts by:

    • Jennifer HindleJennifer Hindle
    • Manfred KubeManfred Kube
    • Tim CawseyTim Cawsey
    • Jennifer DeanJennifer Dean
    • GemaltoGemalto
    • Dominique BruléDominique Brulé
    See all bloggers
  • Blogroll
    • Amrit Williams blog
    • Communities Dominate Brands
    • GoMo News
    • HIT Consultant
    • ID Theft Security
    • Independent Identity
    • Kantara Initiative
    • Krebs on Security
    • Life as a Healthcare CIO
    • Michael N. Dundas
    • Mobile Marketer Blog
    • Mobile Marketing Watch
    • Mobile Money Asia
    • Mobile Zeitgeist
    • MSearchGroove (MSG)
    • Musings of a mobile marketer
    • Naked Security
    • Network Security Blog
    • NFC World
    • RFID Journal
    • Ric Ferraro's Blog
    • Schneier on Security
    • SecDev
    • Security Nirvana
    • Virginia Benedict
  • Countries
    • Brazil
    • China
    • France
    • Germany
    • Italy
    • Japan
    • Kenya
    • South Korea
    • Spain
    • Turkey
    • UK
    • US
  • Tags
    • Apple
    • Authentication
    • BYOD
    • Banking
    • Biometrics
    • Cloud
    • Connected devices
    • Contactless
    • Convenience
    • Cybersecurity
    • Data breach
    • Digital Security
    • EMV
    • Ebanking
    • Encryption
    • Facebook
    • Fraud
    • Gemalto
    • IOT
    • Identity
    • Innovation
    • Internet of things
    • LTE
    • M2M
    • MWC
    • Machine-to-machine
    • MasterCard
    • Mobile wallet
    • Mobile marketing
    • Mobile
    • Mobile payment
    • Mobile payments
    • Mobile World Congress
    • Multi-factor authentication
    • NFC
    • OTP
    • Online banking
    • Password
    • Passwords
    • Payments
    • SIM
    • SMS
    • Security
    • Smartphone
    • Strong authentication
    • Technology
    • Trust
    • Two factor authentication
    • USA
    • Visa
Back to articles

Posted on 20 July 2012 by Gemalto in Enterprise Security

Can a website tell you when it’s time to change your password?

Last updated: 21 March 2014

This week has seen yet another study highlighting the inherent dangers of securing your personal information with just a password. According to research from Experian, the average internet user in the UK has just five different passwords, despite having 26 different online accounts. Indeed, a quarter use just one password for most of their logins.

This follows on from last week’s Yahoo! breach, meaning passwords (or, more correctly, our use of them) have come in for some pretty bad press recently. Now that we are keeping more and more of our sensitive data online, I hope that it’s only a matter of time before static passwords are discarded altogether in favor of stronger forms of authentication.

Until then, however, we have to keep looking for new ways of ensuring that we keep our passwords as safe as possible. A site I came across this week, shouldichangemypassword.com, could prove to be a valuable tool in doing this. The site invites visitors to input their email address and then tells them if their account is at risk of being compromised, encouraging them to change their password if so.

It claims that it has so far uncovered almost 12 million compromised addresses – a number which has risen by over 200,000 in recent days. This could mean one of two things: either the site is experiencing a huge surge in popularity, or the number of accounts at risk is rapidly increasing. In reality, both of these are likely to be true. The site gathers its information from breaches where email addresses have been published by hacktivist groups like Anonymous or the now disbanded LulzSec and keeps them in a database for users to check their address.

While I wouldn’t recommend anyone solely relying on services like this to tell them whether their accounts are safe or not, any tool which can help to keep internet users informed of the risks they face is welcome. And until static passwords are replaced by more robust two-factor authentication methods (such as those offered by Google) then it falls to the user to regularly change their password (which should not be password, but something much stronger) and to use services like this to ensure they are not exposed.

Related posts:

Secure mobile payments and tokenization: the five key benefits for…

Posted on 05 March 2015 by Dominique Brulé in Corporate

One of the key sections of our stand at MWC this year is dedicated to our Trusted Service Hub and tokenization; in this post, we explain why our tokenization solution…

Are UK companies being left vulnerable by their CIOs?

Posted on 23 October 2012 by Gemalto in Corporate

We had a great reaction from our followers on our research into the issues that are keeping CIOs awake at night. Here on the blog we discussed the findings across…

Thoughts on Google’s Two-Factor Authentication – Part Two

Posted on 22 November 2011 by Gemalto in Corporate

In the first of these two posts on Google’s two-factor authentication I discussed Google’s authentication push and how this is a good step forward for spreading strong authentication. Here I…

From Twitter

Loading...
    More from Twitter

    Subscribe to updates

    Delivered by FeedBurner.
    Submitting this form will open a popup window to the FeedBurner website.

    Gemalto: a Thales company
    Visit Gemalto corporate site | Blogs FAQ | Privacy Policy | © 2006 - 2023 Gemalto NV
    This work is licensed under a Creative Commons Attribution-NonCommercial-NoDerivs 3.0 Unported License.

    • ACTIVITIES
    • Defence & Security
    • Digital Identity and Security
    • Aerospace
    • Space
    • Ground Transportation
    • Market-specific solutions
    • GLOBAL
    • Career
    • Investor
    • Journalist
    • Customer Online
    • SOCIAL NETWORKS
    • Facebook
    • Twitter
    • LinkedIn
    • Instagram
    • Youtube
    Decisive technology for decisive moments
    www.thalesgroup.com
    Be aware that this site uses cookies. Before continuing browsing we advise you to click on Privacy Policy to access and read our cookie policy.OkPrivacy policy