CHAPTER 3

Credential Stuffing With Reused Passwords—So Easy a Cybercriminal Could Do It

Happy birthday, Password! The password blew out 62 candles on a birthday cake in 2023, but don’t expect it to retire anytime soon. The venerable password remains the most efficient way to authenticate a user’s access to computer systems and will likely be so for another 62 years. And yet, passwords are easily compromised by cybercriminals using a combination of trickery and technology.

Like Willie Sutton robbing banks “Because that’s where the money is,” stolen passwords are the obvious, and easiest, path to a successful cyberattack. It’s no wonder the vast majority of cyberattacks are focused on hacking passwords, with weak passwords being the Holy Grail ...

Get Mobilizing the C-Suite now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.