Risk of Residual passwords

Our dependence on E-services has increased tremendously. All such services have the usernames and Passwords. This is main gateway for entry in to systems. Apart from that, transactional passwords. Even the password with secured and digital certified access portal. Portal was accessed by only the browsers. when we log in for the first time, browsers have an option to save passwords.Due to lack of awareness of the security implications users intend to say 'Yes' to save the password. One simple example is how many users actually read a EULA agreement / Usage rights agreement in its entirety. They simply scroll down to the bottom of the screen, and accept the same.

(Read more:  Top 5 Application Security Technology Trends)

Passwords saved in browsers can be accessed by the other users of the system, and more importantly, hackers. All the browsers store passwords in the same manner, which is readable by the same browser by simply copying this valet to another computer.

Unknowingly, we are creating Vulnerabilities and threats around us. Most of the time it was either taken for granted or Ignored.

Prevention: even the the security password stores save with password so that other users can't get in to there with readable format.

Don't click remember password for your mail sign in in any of your mobile devices. Mobile devices are easy to get lost/ share with someone.

(Read more: How to choose your Security / Penetration Testing Vendor?)

Votes: 0
E-mail me when people leave their comments –

You need to be a member of CISO Platform to add comments!

Join CISO Platform

Join The Community Discussion

CISO Platform

A global community of 5K+ Senior IT Security executives and 40K+ subscribers with the vision of meaningful collaboration, knowledge, and intelligence sharing to fight the growing cyber security threats.

Join CISO Community Share Your Knowledge (Post A Blog)
 

 

 

Atlanta Chapter Meet: Build the Pen Test Maturity Model (Virtual Session)

  • Description:

    The Atlanta Pen Test Chapter has officially begun and is now actively underway.

    Atlanta CISOs and security teams have kicked off Pen Test Chapter #1 (Virtual), an ongoing working series focused on drafting Pen Test Maturity Model v0.1, designed for an intel-led, exploit-validated, and AI-assisted security reality. The chapter was announced at …

  • Created by: Biswajit Banerjee
  • Tags: ciso, pen testing, red team, security leadership