Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> Over 80% of data breaches are through static passwords.

Static passwords are bad, for sure. But do you have a source for this?



See page 5 of the Verizon report and the number is 81%:

https://www.verizon.com/business/resources/reports/2017_dbir...


Awesome, thanks for sharing that link from 2017.

For everyone not going to go to the PDF, the text is "81% of hacking-related breaches leveraged either stolen and/or weak passwords."

So I'm not sure that you can say that all data breaches are related to static passwords, but it sure a big number and a problem.

I looked at the 2020 Verizon report, but unfortunately they changed their methodology or reporting so I didn't see a figure for that year for "hacking-related breaches".


> not sure that you can say that all data breaches are related to static passwords

Nobody said that.


Sorry, you are absolutely correct. I mistyped. The original post ( https://news.ycombinator.com/item?id=29306921 ) said "Over 80% of data breaches are through static passwords."

What I should have said was "So I'm not sure that you can say that ~80% of data breaches are related to static passwords, but it sure a big number and a problem" because:

  * hacking-related breaches != data breaches and
  * stolen and/or weak passwords != static passwords
But the bigger point stands: passwords are a problem.


weak passwords can be mitigated against, and password reuse limits (of one - no password reuse, ever) the attack surface from there, along with using HIBP's breach database. NIST updated their recommendations about passwords, and forcing a change of password every 30 days was removed because it caused other, more leaky behavior in practice.


Over 80% of statistics posted in comments are made on the spot.


no, the correct figure is 78%


The figure that I used was one from the Verizon Data Breach report in 2017 of 81%.

Page 5 in the executive summary:

https://www.verizon.com/business/resources/reports/2017_dbir...


> no, the correct figure is 78%

Not credible. There should be some odd number of tenths: 78.3% is clearly more credible than 78%




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: