Study Reveals Bad Password Habits

執筆者
Dennis Fisher
Dennis Fisher
Published: Aug 5, 2003
Updated: Feb 2, 2021
2 minute read
eWeek のコンテンツおよび製品のおすすめは、編集上の独立性を保っています。パートナーへのリンクをクリックすると、当社が報酬を得る場合があります。 詳細を見る

The majority of users mishandle their passwords and user IDs, forget their passwords on a regular basis and then resort to calling their IT departments for help when they cant log on to their PCs, according to a new survey.

The results of the study, done by security vendor Rainbow Technologies Inc. and released Tuesday, should come as no surprise to anyone in the IT world. Most enterprise IT workers are painfully familiar with the poor security habits of the users they support. However, the extent to which users drop the ball and endanger their corporate networks is nonetheless disconcerting.

“It surprised me how aware people were of how weak passwords are, and yet they continue to rely on them,” said Bernie Cowens, vice president of security services at Rainbow. “You can see that they are really no security at all. Passwords are a real problem, but we continue to keep our heads in the sand and our fingers crossed.”

In a survey of 3,000 administrators, managers and security specialists, Rainbow found that 55 percent of users write their passwords down at least once and that nine percent write down every password at some point. Even worse, 40 percent of the respondents said their users share passwords with co-workers or other people.

The survey also found that some of the security measures that companies have put in place to strengthen passwords have actually backfired. A common corporate policy is to require users to select passwords that either include both letters and numbers or are simply a string of letters that dont form a word. The idea is to defeat so-called dictionary attacks, which use automated tools to try thousands of words until one matches the users password.

However, 80 percent of respondents to the survey said that this policy has in fact increased the likelihood that users will either write down or forget their passwords.

“It was clear from the survey that while the implementation of password strengthening methods may make IT and business managers feel better about the use of passwords, they may not result in stronger actual security,” the company said in its introduction to the survey results. “In fact the security may be weaker, which represents a fundamental flaw in the password paradigm.”

Advertisement

But not all of the blame for the poor state of password management should fall to users. Rainbow, based in Irvine, Calif., also found that almost 20 percent of respondents are not required to change their passwords on a regular basis and only 38 percent have to switch passwords five or more times each year.

“This is a very poor security policy to start with. Obviously, people recognize today the weaknesses of passwords. Its hard to fathom that some organizations dont require [password changes] at all,” Cowens said.

Dennis Fisher

Dennis Fisher

Content Writer
eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

TechnologyAdvice が所有・運営しています。 © 2026 TechnologyAdvice. 無断転載を禁じます

広告主に関する開示:このサイトに掲載されている製品の一部は、TechnologyAdvice が報酬を受け取っている企業のものです。この報酬は、製品がこのサイトのどこにどのように表示されるか(表示される順序など)に影響する場合があります。TechnologyAdvice は、市場で入手可能なすべての企業やすべての種類の製品を掲載しているわけではありません。