Podcast: Troy Hunt Talks Bad Passwords – and Who’s to Blame for Them

Join thousands of people who receive the latest breaking cybersecurity news every day.

The administrator of your personal data will be Threatpost, Inc., 500 Unicorn Park, Woburn, MA 01801. Detailed information on the processing of personal data can be found in the privacy policy. In addition, you will find them in the message confirming the subscription to the newsletter.

The administrator of your personal data will be Threatpost, Inc., 500 Unicorn Park, Woburn, MA 01801. Detailed information on the processing of personal data can be found in the privacy policy. In addition, you will find them in the message confirming the subscription to the newsletter.

HSBC breach reported earlier this week – the security community has continued to ponder an age-old question: Who is responsible for effective password hygiene and security measures? The account holder, or the service? And what solutions exist on both ends to promote better security measures?

To find out, Threatpost’s Lindsey O’Donnell speaks with Troy Hunt, a web security expert and the owner of Have I Been Pwned (a data breach search website allowing people to see if their passwords have been compromised), during this week’s Threatpost Podcast.

It’s a well-known fact that most people re-use passwords despite knowing that they shouldn’t, but Hunt believes that the responsibility is shared between the account holders, the organization responsible for the account and the person breaking into the account.

“So by all means, call it victim-blaming if you must, but when applied to making poor security decisions…the responsibility is a shared one,” he said a Thursday post.

Hunt, who recently said that passwords are never going away despite alternatives being available, sat down with Threatpost to further discuss the issue of responsibility when it comes to creating — and promoting — strong passwords.

For direct download click here.

Passwords: Here to Stay, Despite Smart Alternatives?

“Password-killing” authentication efforts may be on a road to nowhere.

Tricky DoS Attack Crashes Mozilla Firefox

There are currently no mitigations for the Firefox attack, a researcher told Threatpost.

Mozilla Patches Critical Code Execution Bug in Firefox 62

The update includes nine security patches overall.

Join thousands of people who receive the latest breaking cybersecurity news every day.

Get the latest breaking news delivered daily to your inbox.

InfoSec Insider Post

InfoSec Insider content is written by a trusted community of Threatpost cybersecurity subject matter experts. Each contribution has a goal of bringing a unique voice to important cybersecurity topics. Content strives to be of the highest quality, objective and non-commercial.

Sponsored Post

Sponsored Content is paid for by an advertiser. Sponsored content is written and edited by members of our sponsor community. This content creates an opportunity for a sponsor to provide insight and commentary from their point-of-view directly to the Threatpost audience. The Threatpost editorial team does not participate in the writing or editing of Sponsored Content.