Urgent.News

What's breaking now, across thousands of outlets.

Tech

We need to talk about passwords

How did credentials become the most common control in the business and still the one nobody is managing properly?

We need to talk about passwords

In June 2026, around 75,000 Fortinet firewalls, approximately half of all Fortinet devices connected to the internet, had their administrator passwords compromised. The company had rectified the underlying vulnerability a year prior. Initially, passwords were stored using SHA-256, a rapid hashing algorithm. Although a more secure replacement, PBKDF2, had been implemented, it was not automatic.

The upgraded protection only activated upon the next login of an administrator, which many did not do. This incident, dubbed "FortiBleed," is among the most extensive credential leaks associated with a single vendor, highlighting how plaintext exposure negates even well-enforced password policies. Although Fortinet took responsibility, they could not compel users to log into their firewalls and trigger the update.

In recognition of World Password Day in May, Kaspersky examined 231 million leaked passwords from breaches over the past three years. They discovered that 68% of these passwords could be cracked within a single day, and more than half of the compromised passwords had previously appeared in a data breach. Tatyana Shishkova, Kaspersky's lead security researcher, asserts that the issue does not stem from negligence but rather from the overwhelming number of accounts individuals must manage.

The average internet user now maintains over 100 passwords, with Dashlane estimating the figure to be closer to 250. Shishkova explains that users often resort to reusing passwords or modifying slightly to mitigate the burden. This behavior, known as security fatigue in cyberpsychology, occurs when the mental effort to maintain security surpasses practicality.

Caryn Gilmour, executive for fraud risk authentication at Absa Personal and Private Banking, emphasizes that as the number of accounts increases, so does the cognitive effort required to remember and manage unique login credentials. A common mistake companies make is enforcing simple rules like adding a capital letter, a number, and a symbol, which does not necessarily enhance password unpredictability; instead, it creates a new predictable pattern across all accounts.

Kaspersky's research revealed that 53% of examined passwords end with digits, 17% begin with them, and nearly 12% contain a number resembling a date. Additionally, ' @ ' is the most commonly used symbol, followed by a period and an exclamation mark. These patterns indicate that complexity rules can inadvertently produce weak passwords at scale.

Shishkova emphasizes that while complexity requirements might check format, they do not guarantee password strength, as entropy, the true measure of password unpredictability, remains unaddressed. Each additional random character roughly doubles the number of possible combinations an attacker must traverse, while predictable patterns, regardless of length, shrink the search space.

Shishkova acknowledges that addressing this problem requires a multifaceted approach, encompassing individual responsibility (such as unique passwords, unique passwords, and two-factor authentication) and organizational duties (like secure password storage and policies that minimize user frustration). She asserts that security cannot solely depend on individual perfect decisions daily.

According to HYPR's 'State of Passwordless Identity Assurance 2026' report, 76% of organizations still depend on legacy passwords, although 43% have already implemented some form of passwordless authentication, though most have not rolled it out to more than half of their workforce. Passkeys offer passwordless authentication through cryptographic credentials stored on trusted devices and biometric verification to ensure the user is legitimate.

However, transitioning to passwordless requires robust devices, stronger verification mechanisms, and authentication controls that accommodate both security and a seamless user experience. Kaspersky believes the challenge lies not in technology but rather in user behavior. Recovery flows often default to password resets when devices are lost or replaced, reopening the vulnerability that passwordless solutions aim to eliminate.

Shishkova argues that users must stop relying on passwords as the default safety net. Instead, the objective should be to move beyond passwords as the primary line of defense.

Written by urgent.news from ITWeb's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at itweb.co.za →

More in Tech

More from Thursday 13 August →