Wednesday, February 6, 2008

Use Strong Passwords for Web Accounts

You should use strong passwords to protect online accounts for your mobile phone, especially the wireless operator's web account for your service, and web sites you frequently use to share photos.

Many web services also allow users to retrieve forgotten passwords by answering a personal question (i.e., the "password question"). It is important to use a password question that is not easy to guess. And don't forget: the answer to the question "what is your favorite pet's name" does not have to really be your favorite pet's name. It just has to be something you can remember.

In early 2005, it is believed that a cracker either guessed socialite Paris Hilton's T-Mobile account password, or exploited an SQL injection vulnerability on the T-Mobile portal web site and reset her password. Regardless of how the attacker did it, Paris's account was compromised. After logging into her account, the cracker downloaded and then posted all her personal information, including her Contacts list and phone camera photos, on the Internet.


No comments: