Heard a guy at Harbor Coffee in Tampa brag about using the same password for 9 years, and I can't stop thinking about it | Cybersecurity Tips - Vivisector
Heard a guy at Harbor Coffee in Tampa brag about using the same password for 9 years, and I can't stop thinking about it
I was waiting on my order last Thursday and this guy at the next table was telling his friend he's used the same password since 2015 because 'nobody's gonna guess it.' His friend laughed, and then the guy said his email, bank, and Amazon all use it. I wanted to say something but just sat there. For anyone who knows more than me, what's the easiest first step for a person like that, a password manager or just turning on two factor on the email?
2015 is 9 years only if you're counting from today, so that part checks out, but the "nobody's gonna guess it" logic is backwards. The problem isn't guessing, it's that his password is already sitting in some leaked database from a random site he signed up for years ago, and crooks just try it everywhere. Two factor on the email is a good start, but it's not enough on its own, because a lot of banks still let you reset things through email or text. The real fix is a password manager so every site gets its own random password, and then two factor on top of that. Do both, not one or the other. And the email is the one to lock down first since everything else hangs off it.