October is National Cybersecurity Awareness Month, so the importance of passwords, how they work, how they are cracked, and best practices for adding layers to password security becomes that much more important right now. To dig into these topics, we reached out to industry expert Bogdan Botezatu, Director of Threat Research and Reporting at Bitdefender.
VMblog: How easy is it for cybercriminals to crack passwords?
Bogdan Botezatu: Cracking passwords has become extremely easy, especially in the past few years. The advancements in computing have made it relatively simple and inexpensive for cyber-criminals to brute-force hashes. These hashes are then packed in “rainbow tables”, which are a precomputed tables for caching the outputs of a cryptographic hash function and made available to other cybercrime groups to make it easier for other hackers to crack passwords.
VMblog: Why are good password protection practices still often neglected in both personal and business?
Botezatu: In order to be secure, passwords have to be long, unique, complex, and with a pre-defined life expectancy. These prerequisites are difficult to meet and enforce when it comes to regular users, as they often prefer simpler, easy to remember passwords that log them into every service they use – forever. Some good password protection practices go along these lines:
- Choose complex passwords that are 16 characters or longer. They should include a combination of uppercase, lowercase, numbers, and special characters, as random as possible.
- Choose unique passwords for all accounts you create. Make sure you never reuse passwords as, once exposed, they might allow hackers access to more than one account.
- If supported, enable a second type of authentication factor. If possible, prioritize app or email-based one-time-password delivery over SMS.
- Monitor for possible account leaks. Hackers often target databases of usernames and passwords that they crack and sell online. It is important that you become aware about recent data breaches (especially if they are massive) and change your passwords immediately to prevent the account from falling into the wrong hands. One good way of checking if an email associated with your account has been compromised is by checking free services such as Have I Been Pwned.
VMblog: Do you recommend the use of passwords managers – why or why not?
Botezatu: Yes, password managers fix most of the issues outlined earlier: They deliver strong, impossible to guess passwords and save them for us, so we don’t have to remember them. They also safely synchronize these passwords across the many devices we may own. Last, but not least, some password managers include data leak monitoring technologies that alert the user once their account username and passwords have gotten into the wrong hands.
VMblog: What emerging technologies and/or authentication methods are likely to shape the future of password protection, and how will they address the limitations of traditional passwords?
Botezatu: The world has been battling passwords since forever. Difficult to secure and highly susceptible to theft, they stood their ground because they are cheap and easy to implement. However, as the number of data breaches increased in the past few years, passwords are now regarded as a liability. There have been many attempts to replace them with smartcards, hardware keys, certificates, and anything in between. It seems though that the proliferation of smartphones has been capitalized on to slowly phase passwords out. Passkeys are special credentials stored on a device that authenticate you into an account that supports this feature by simply unlocking your device. The passkey authentication system uses biometrics like a fingerprint or face scan, or a screen lock PIN instead of passwords.
VMblog: How will advancements in artificial intelligence impact the evolution of password protection, and what role will they play in enhancing or circumventing password security?
Botezatu: Artificial intelligence is changing the way we perceive reality and is an important contributor to advanced attacks, deepfake generation, and confusion attacks. Malicious AI models can generate personalized phishing emails and social engineering tactics made to fit one context or victim. Additionally, deepfake videos or audio could be used to impersonate individuals and bypass biometric authentication systems. In terms of passwords, the evolution quantum computing will be more of an issue with its ability to crack even seemingly strong passwords in minutes. Bitdefender and other security research teams are already looking into ways of protecting computers and networks for when quantum computing becomes more mainstream and threat actors have access to it.
##






