Credential stuffing
You may have heard before that one of the best things you can do to stay safe online is to ensure that you use a unique password for every site. But why?
The answer is because criminals can get your password on a relatively insecure site, and then reuse that email/password combination on a different site that itself hasn't been breached.
Credential stuffing is when criminals take usernames and passwords stolen from one website and automatically try them on other websites.
How credential stuffing works
There are many things that companies can do to secure your password. (For example, they can salt, pepper, and hash them. No joke.) The problem is that many places might use one safeguard, but not all of them.
If a criminal gains access to a site that doesn't properly secure its
passwords, then they may be able to recover your password, and then they
know that apple.pie.baker@example.com likes to use the
password 123AppleCinnamon.
Now that they have that combination, along with thousands of others, they can start going to other sites that haven't been compromised and try to log in. This could be a bigger website that you want to keep secure, like Google, Facebook, or even Chase or Vanguard. If those accounts have the same email and password, then the criminal just hacked you.
Imagine using the exact same key for your house, car, storage unit, bike lock, and safe. If someone managed to copy the key to your bike lock, they would now have access to your safe.
These attacks don't target just one person, either — criminals can obtain millions of stolen usernames and passwords, then use automated tools to try them against many other websites. Even if only a small percentage work, that can still mean thousands of compromised accounts.
How to check if you are vulnerable
Ask yourself: if you had to create a new password right now, what would it
be? Would you generate a random password or come up with a unique
passphrase (these are good options), or would you take your old standby
Judy1952 and make it Judy1952! or
Judy1952@?
If you have ever used the same password on two websites, you are vulnerable. If you have ever used variations of the same password, those passwords are vulnerable as well.
Please don't use the same password, or the same base password.
Do this today
Type your email address into Have I Been Pwned. It will tell you which known data breaches included your address and what other kinds of information were exposed. It's free, it doesn't want an account, and it doesn't email you unless you ask it to.
Don't be surprised if your address appears in several breaches. That's common, and it isn't cause for panic. Start with any account where you realize that you use that same password elsewhere.
How to protect yourself
-
Use a passkey whenever a website offers it.
- Your phone, computer, or password manager can usually save the passkey for you.
-
Use a password manager to generate (and use) unique passwords on every account.
-
Your password manager might generate something like
LyFMPHg&HdHjY9kq. This is secure, and you don't need to remember it — the manager will remember it for you, and type it in for you as well.
-
Your password manager might generate something like
-
Turn on multi-factor authentication whenever possible.
- This puts up a barrier to stop a hacker even when they have your password.
- If possible and practical, use email aliases when opening new accounts.