Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Wednesday, 3 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Why are default passwords unchanged – industry views

by The Gurus
May 14, 2014
in Opinions & Analysis
Share on FacebookShare on Twitter

The continued use of default credentials, including passwords, was identified as a key security failing by the Information Commissioner’s Office (ICO) report this week.
 
Correlating with recent research by NCC Group, it seems that there is an expectation of things working out of the box so much that the security functions are not really considered. I put the question to some key industry spokespeople, and asked why people do not check the settings of such crucial things?
 
 

Andy Green, technical content specialist at Varonis
In many organisations there’s a tendency to focus on the latest malware, viruses or APTs. Companies invest in defences that scan and monitor for these specific threats at ingress-on the network or in emails but in trying to keep up with the latest APTs, IT underplays the threat from basic attacks, typically involving guessable credentials and more recently social engineering and phishing.
 
Verizon’s Data Breach Investigations Report, which covers security incidents on a worldwide basis, has been noting for many years that weak or defaults passwords have been involved in roughly more than half the intrusions. They’ve also been regularly pointing out that the solution is to deploy relatively simple “block and tackle” strategies– password lockout controls, two-factor authentication, and better monitoring of logs.
 

David Harley, senior research fellow at ESET
I think many people – even outside the security field – realise that static passwords, even ‘good’ passwords, are less effective than they used to be in terms of crackability – even less so if credentials aren’t well-protected by the service provider, in which case they’re all but useless.
 
I’m not sure what the article means by ‘default passwords’: if you’re going to allow the user to accept a default, it should at least be a cryptographically efficient, randomly generated password unique to that user, not ‘password’ or one of the other Top n bad passwords that are published time and time again. If it just means static passwords as the only means of authentication because that’s the ‘out of the box’ method,  I have to agree: the chances are that it’s being done that way because it’s cheap and easy to implement, and requires a minimum of effort from the customer, which often still trumps securing that same customer’s data.
 

Andrew Rose, principal analyst for security and risk at Forrester Research
IT operations guys are struggling with massive amounts of complexity, with interacting systems, layers and data repositories. Getting these to work can be an art, and leaving default passwords in place removes one layer of complexity and eradicates a possible failure point.
 
Similarly, when setting up these systems (and virtualisation has just increased the rate of system creation and setup), it removes an element of “what was the password?” constantly being asked by the different admins. I sympathise that IT ops guys are busy, but leaving defau
lt credentials is just sloppy behaviour.
 

TK Keanini, CTO of Lancope
People are still getting used to the fact that the internet is hostile and that they will be hacked if they don’t practice some level of security – and even then you will get hacked eventually. Vendors also need better practices to be secure by default.  While there could be a default password, the application should force a change as soon as the initial user logs in.
 

Andrew Barratt, managing director Europe at Coalfire
It’s still a fairly common problem in low-end (cheap) kit. However a lot of operating systems have removed the concept of a default password – neither Windows / Linux nor Mac OSX have them.
This tends to crop up with ‘appliance’ type devices which is almost worse in some respects as there is an over zealous expectation of security with some of these devices.
The problem is when it is with low end kit, you typically see them in volume, which then leaves lots of people vulnerable (and often in the SME space) all because the devices are ‘easier’ to set up and get working. Functionality fast – often trumps security in this space. Mainly because this means the SME-types don’t have to pay for external support to set them up properly. Or the people that are doing this are really entry level IT bods who are just throwing them in without much consideration for security.

ShareTweet
Previous Post

Ajax Security Team operated in grey area between hacktivism and nation-state sponsored

Next Post

Adobe Creative Cloud Is Down Worldwide

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol