Many People Reuse Unsafe Credentials for Sensitive Government and Email Accounts: Google

Follow Us

Many people re-use breached, unsafe credentials for sensitive financial, government and email accounts, putting their account at risk of hijacking by cybercriminals, according to tech giant Google. In a recent blog post, Google said hijackers routinely attempt to sign in to sites across the web with credentials exposed by third-party breaches. If netizens use strong, unique passwords for all their accounts, this risk disappears, it said, as reported by PTI.




"Based on anonymous telemetry reported by the Password Checkup extension, we found that users reused breached, unsafe credentials for some of their most sensitive financial, government, and email accounts," it added.

Cyber attackers often have wide-scale access to billions of stolen usernames and passwords. The risk, as per Google, was even more prevalent in shopping sites (where users may save credit card details), news, and entertainment sites.

"In fact, outside the most popular web sites, users are 2.5X more likely to reuse vulnerable passwords, putting their account at risk of hijacking," the blogpost said.

In February, Google had announced the Password Checkup extension for Chrome. This extension displays a warning when a user signs in to a site using one of the over four billion usernames and passwords that Google knows to be unsafe due to a third-party data breach.

Google said in the first month alone, it scanned 21 million usernames and passwords, and flagged over 3,16,000 accounts as unsafe - which was 1.5 per cent of the sign-ins scanned by the extension.

The tech giant has added two new features for the Password Checkup extension.

It is adding a direct feedback mechanism where users can inform the company about any issues that they are facing via a quick comment box.

The second features are aimed at giving users more control over their data, the blogpost said.

It allows users to opt-out of the anonymous telemetry that the extension reports, including the number of lookups that surface an unsafe credential, whether an alert leads to a password change and the domain involved for improving site coverage, the blogpost said.

"By design, the Password Checkup extension ensures that Google never learns the username or password of the user, regardless of whether they enable telemetry, but we still want to provide this option if users would prefer not to share this information," it added.

Reported By

Managing Editor

Chakri is a go-to guy for your next smartphone recommendation. Back in his engineering days, he used to play with smartphones by installing custom ROMs and that passion got him into the tech industry. He still goes nuts about a smartphone knocking his door for review. Currently managing everything at Telecom Talk, Chakri is trying to master PUBG Mobile in his free time.

Recent Comments

bharat khanna :

where are the plans?no details , whats new whats changed?

Airtel Introduces Affordable International Roaming Packs for Seamless Travel Connectivity

Jobins :

Vi should decrease the tariff somewhere near to Jio's. So it can grab users from Airtel and Jio.

Vodafone Idea Needs Tariff Hikes: Analysts

Faraz :

If out of 481, 108 is 5G customers. That means customer on Jio 4G network reduced from 452 million in…

Reliance Jio Posts Rs 5583 Crore Net Profit in Q4…

Sujata :

In my nearest enodeB, Jio switches off b40 daily at around 1 am, restores around 6 am. b3 and b5…

Reliance Jio Launches 5G in 27 Cities in Holi 2023

Faraz :

If they already reached 482 million, I wonder in how many months it will reach 500 million customers. Their ARPU…

Reliance Jio Posts Rs 5583 Crore Net Profit in Q4…

Load More
Subscribe
Notify of
0 Comments
Inline Feedbacks
View all comments