Article New research: Understanding the root cause of account takeover

Technoglitch

Core Member
Account takeover, or ‘hijacking’, is unfortunately a common problem for users across the web. More than 15% of Internet users have reported experiencing the takeover of an email or social networking account. However, despite its familiarity, there is a dearth of research about the root causes of hijacking.

With Google accounts as a case-study, we teamed up with the University of California, Berkeley to better understand how hijackers attempt to take over accounts in the wild. From March 2016 to March 2017, we analyzed several black markets to see how hijackers steal passwords and other sensitive data. We’ve highlighted some important findings from our investigation below. We presented our study at the Conference on Computer and Communications Security (CCS) and it’s now available here.


blog_infographic.png




How hijackers steal passwords on the black market

Our research tracked several black markets that traded third-party password breaches, as well as 25,000 blackhat tools used for phishing and keylogging. In total, these sources helped us identify 788,000 credentials stolen via keyloggers, 12 million credentials stolen via phishing, and 3.3 billion credentials exposed by third-party breaches.

While our study focused on Google, these password stealing tactics pose a risk to all account-based online services. In the case of third-party data breaches, 12% of the exposed records included a Gmail address serving as a username and a password; of those passwords, 7% were valid due to reuse. When it comes to phishing and keyloggers, attackers frequently target Google accounts to varying success: 12-25% of attacks yield a valid password.




Google Online Security Blog: New research: Understanding the root cause of account takeover
 

IndianMascot

Core Member
Only solution is Change Ur Password in monthly or fortnightly basis

i have 5 email account, 6 bank accounts, 4 credit cards. In addition to that several websites like facebook, twitter, instagram etc etc and etc.

now what and how you expect to manage these many accounts and remember the password If you same them in pocket diary, then you need to keep it safe and carry everywhere, if you store in a password keeper app then also it can be hacked.

So, whatever you do if someone is keen to hack, they will hack.
 

Technoglitch

Core Member
i have 5 email account, 6 bank accounts, 4 credit cards. In addition to that several websites like facebook, twitter, instagram etc etc and etc.

now what and how you expect to manage these many accounts and remember the password If you same them in pocket diary, then you need to keep it safe and carry everywhere, if you store in a password keeper app then also it can be hacked.

So, whatever you do if someone is keen to hack, they will hack.
keep the diary at home and carry the essential ones in a wallet.
 

IndianMascot

Core Member
You never know bro which password is required when. I still unable to remember the atm pin of my debit card . I have to use password keeper app.

There was an instance when I was my phone and couldn't recall the atm pin. So I have install that password keeper app on my mobile and then was able to withdraw money.

Thing is that there are so many passwords in our life and all of them ask us to change monthly and quarterly that I have ran out of passwords now
 
Top