Skip to main content
  1. Home
  2. Computing
  3. Legacy Archives

Foiled by Sticky Notes

Add as a preferred source on Google

It’s often said that a computer system’s security is only as good as its worst password; now, a new survey from Nucleus Research and KnowledgeStorm finds that it may be only as good as the most-legible sticky note plastered to a desk or monitor.

The study (PDF) surveyed the habits of 325 U.S. employees and found that roughly one in three enterprise computer users keep a written record their passwords, potentially compromising the security of their companies’ computer networks. Passwords jotted on a sticky note—or stashed in a notebook, desk drawer, or other convenient location—are more vulnerable to theft or snooping than passwords which never exist in unencrypted form outside the computer. As cracking, IT security, and corporate theft concerns continue to escalate, stashed "plain text" passwords are a ripe area for security compromise.

Recommended Videos

Interestingly, the study found no clear correlation between the complexity of a password and a user’s likelihood of writing down a password. In other words, users were just as likely to want to write down simple, less-secure passwords as complex, difficult-to-crack ones. Some 54 percent of companies required users to select passwords which incorporated both letters and numbers; 38 percent required numbers, letters, and a special character, and only 8 percent allowed only letters in passwords.

Similarly, requiring users to change their passwords frequently didn’t seem to increase the chance that users would write down their passwords. Similarly, implementation of single sign-on systems—where one password gives access to the entire range of enterprise resources—didn’t reduce the likelihood users would write down passwords. Whether folks need one password to get their work done, or four different ones, about one in three is likely to write those passwords down somewhere.

Overall, the study recommends enterprises look beyond password-based security systems and towards technologies which are not as prone to the "sticky note compromise;" technologies like fingerprint readers, biometric systems (like voice, face, retina recognition), or even behavioral metrics to authenticate users without passwords.

Geoff Duncan
Former Contributor
Geoff Duncan writes, programs, edits, plays music, and delights in making software misbehave. He's probably the only member…
Chrome wants more extension reviews, but good ratings won’t keep malware out
Google is testing built-in extension review prompts, but good ratings can still hide malware
malicious-google-chrome-extensions-on-web-store

Google is preparing to add extension review links directly inside Chrome, putting feedback closer to the menus people already use to manage their add-ons.

A Chromium change, first spotted by Windows Report, points to review options in the Extensions menu, the chrome://extensions management page, and extension context menus. Only eligible Chrome Web Store extensions in good standing would qualify, and the feature is still under development.

Read more
Passkeys were pushed as a safer future. Hackers have figured out ways to break those synced to Google
Google’s “uncopyable” passkeys may be easier to steal than promised
google-lawsuite-AI-Scams

Passkeys have been pushed as the safer successor to passwords. It promised protection from phishing, credential reuse, and password leaks. Google even claims that it cannot be copied or accidentally handed to someone else. But it might not be as secure as the company wants it to be.

Security researchers (Via BleepingComputer) have now found three ways malware can undermine those promises for passkeys synced through Google Password Manager. The techniques, collectively named Pass-ta-key, target Google Password Manager inside Chrome on Windows computers equipped with a Trusted Platform Module. Every attack requires malware to already be running on the victim’s computer.

Read more
Apple’s OpenAI lawsuit just tripped over an embarrassing wrong-recipient email
Apple came for OpenAI’s trade secrets, but OpenAI had email receipts
OpenAI

Apple and OpenAI’s legal battle has quickly moved beyond carefully worded court statements. OpenAI has just shared the email and message trails behind the dispute, and one exchange leaves Apple’s version of events looking questionable.

In a bluntly titled post, “Apple is getting this wrong,” OpenAI challenged Apple’s request for a preliminary injunction and accused the iPhone maker of building parts of its case around false or incomplete information. Apple wants a court to prevent OpenAI and two former Apple employees from accessing, acquiring, using, or disclosing its alleged confidential information.

Read more