cancel
Showing results for 
Search instead for 
Did you mean: 

Recycling - just not for passwords, please!

pgn
Level 79: Lord of the Boards
  • 43466 Posts
  • 260 Topics
  • 1890 Solutions
Registered:

The scenario:

...

"My0ldPassword24."

"Password expired, please enter a new one:

"My0ldPassword25."

"Your new password has been accepted, please login now..."

...

Wrong move, pardner! This explains why:

https://archive.ph/mVSqV

"A spokesperson for Virgin Media O2 says: “Human behaviour is quite easy to model. [Criminals] know, for example, you might use one password and then add a full stop or an exclamation mark to the end.”"

 

Read and learn (link has been modified to take out the Guardian nag-prompts!)

Message 1 of 3
521 Views
2 REPLIES 2

Anonymous
Not applicable

@pgn I change my password on an annual basis.

 

 

Message 2 of 3
517 Views

madasaf1sh
Level 79: Lord of the Boards
  • 12976 Posts
  • 85 Topics
  • 3340 Solutions
Registered:

You should change your password every 30 to 90 days or so, not once a year that is a security risk and you are putting your data at risk. 

It should also be secured using an authenticator app or passkeys and not using SMS / Calls for MFA

 

@pgn 
I wouldnt trust VMo2 for security advise, as they dont allow complex or over 12 character passwords... I wish VMo2 would implement support for long complex passwords and proper MFA (3FA would be ideal)

This is not customer services and we dont have access to your account
I do not work for o2 or any VMo2 /Telefonica/Liberty Global Company
Message 3 of 3
509 Views