We use cookies to provide you with a better experience. If you continue to use this site, we'll assume you're happy with this. Alternatively, click here to find out how to manage these cookies

hide cookie message
80,258 News Articles

Weak passwords to blame for Australian Defence Force Academy hack

The Australian Defence Force Academy (ADFA) has been slammed by an Australian security expert for using "weak" passwords stored in plain text which were stolen by a hacker known as Darwinare in November.

Sophos Asia Pacific head of technology Paul Ducklin said in a blog posting that the hack, which saw a number of SQL database records containing student and staff identification details posted online, shouldn't have happened and there could be "no excuses".

Students at ADFA apply to the Defence Force and to the University of New South Wales (UNSW), which runs the academic side of ADFA's operations in Canberra.

While Ducklin praised the UNSW for acting quickly and notifying students/staff a day after the breach occurred, he scolded the University for storing usernames and passwords for at least one of its computer systems in plain text.

"To be fair, these passwords were meant just for initial login, and were therefore expected to have a short life. But passwords should never be weak or guessable, or, for that matter, stored in plain text."

He said the algorithm for generating the passwords was like a "time warp" back into the 1970s because all of the passwords were seven and eight lower-case letters long.

"Many of these passwords are repeated and all are meant to be pronounceable -- surely an unnecessary step for a password that is intended to be typed in once and then changed -- which leads to a conspicuous lack of randomness."

For example, Ducklin pointed out that 1 per cent of the passwords end in the word 'poo' which made the passwords "sadly self-descriptive".

He warned companies to harden their Web services and bring password handling into the 21st Century to avoid compromises like the ADFA incident.

Follow Hamish Barwick on Twitter: @HamishBarwick

Follow Computerworld Australia on Twitter: @ComputerworldAU, or take part in the Computerworld conversation on LinkedIn: Computerworld Australia


IDG UK Sites

Best January sales 2015 UK tech deals LIVE: Best New Year bargains and savings on phones, tablets,...

IDG UK Sites

Chromebooks: ready for the prime time (but not for everybody)

IDG UK Sites

Hands-on with Sony's latest smartglasses

IDG UK Sites

Apple TV expert tips: get US Apple TV content, watch Google Play, use multiple Apple IDs and more