惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

aimingoo的专栏
aimingoo的专栏
S
Securelist
博客园 - Franky
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
IT之家
IT之家
GbyAI
GbyAI
Microsoft Azure Blog
Microsoft Azure Blog
The Cloudflare Blog
云风的 BLOG
云风的 BLOG
N
News and Events Feed by Topic
AI
AI
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
Schneier on Security
Schneier on Security
Attack and Defense Labs
Attack and Defense Labs
Vercel News
Vercel News
腾讯CDC
Google DeepMind News
Google DeepMind News
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
M
MIT News - Artificial intelligence
WordPress大学
WordPress大学
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
N
Netflix TechBlog - Medium
量子位
S
Schneier on Security
Hacker News: Ask HN
Hacker News: Ask HN
Cyberwarzone
Cyberwarzone
S
Security Affairs
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
N
News and Events Feed by Topic
T
Tenable Blog
PCI Perspectives
PCI Perspectives
MyScale Blog
MyScale Blog
L
Lohrmann on Cybersecurity
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
C
Cyber Attacks, Cyber Crime and Cyber Security
W
WeLiveSecurity
N
News | PayPal Newsroom
P
Proofpoint News Feed
O
OpenAI News
C
CERT Recently Published Vulnerability Notes
B
Blog
Cisco Talos Blog
Cisco Talos Blog
Microsoft Security Blog
Microsoft Security Blog
V
Visual Studio Blog
MongoDB | Blog
MongoDB | Blog
大猫的无限游戏
大猫的无限游戏
A
Arctic Wolf
Y
Y Combinator Blog
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Spread Privacy
Spread Privacy

The Register - Security: CSO

Anthropic's Mythos has The Kettle crew curious, skeptical 'People's Panel' to check if UK wants controversial Digital ID will cost £630K Top npm package backdoored to drop dirty RAT on dev machines Lightning-fast exploits mean patch fast, says Cisco Talos Lightning-fast exploits mean patch fast, says Cisco Talos Smooth criminals talking their way into cloud environments, Google says Cybercrime up 245% since the start of the Iran war Scattered Lapsus$ Hunters seeks women to defraud helpdesks CISA quietly updated ransomware flags on 59 flaws last year Deepfake job seeker applied to work for an AI security firm Deepfake job seeker applied to work for an AI security firm AI-powered cyberattack kits are 'just a matter of time' AI-powered cyberattack kits are 'just a matter of time' FortiGate SSO bug still exploitable despite December patch FortiGate SSO bug still exploitable despite December patch Judge tosses CrowdStrike shareholder suit over 2024 outage DRAM shortage may drive firewall prices higher: analysts Ransomware attacks kept climbing in 2025 as gangs refused to stay dead Around 1,000 systems compromised in ransomware attack on Romanian water agency 1,000 systems pwned in Romanian Waters ransomware attack Half of exposed React servers remain unpatched amid attacks CISA warns spyware crews are breaking into Signal and WhatsApp accounts FCC guts Salt Typhoon telco rules despite espionage risk CISA orders feds to patch Oracle Identity Manager zero-day SEC drops SolarWinds lawsuit that painted a target on CISOs everywhere SEC bails on SolarWinds lawsuit Palo Alto kit sees massive surge in malicious activity amid mystery traffic flood Palo Alto kit sees massive surge in malicious activity Countries use cyber targeting to plan strikes: Amazon CSO Overconfidence is the new zero-day as teams stumble through cyber simulations UK's Cyber Security and Resilience Bill makes Parliamentary debut Cyber insurers paid out over twice as much for UK ransomware attacks last year Cyberpunks mess with Canada's water, energy, and farm systems Trump's workforce cuts blamed as America's cyber edge dulls Feds flag active exploitation of patched Windows SMB vuln How malware vaccines could stop ransomware's rampage Salesforce refuses to pay ransomware crims' extortion demand Germany slams brakes on EU's Chat Control snoopfest Germany slams brakes on EU's Chat Control snoopfest Employees regularly paste company secrets into ChatGPT Oracle tells Clop-targeted EBS users to apply July patch Red Hat repos raided, claims cybercrew, files stolen Suspected Chinese spies broke into 'numerous' enterprises UK gov acknowledges 'strong case' for JLR financial support JLR extends shutdown – again – as toll on workers laid bare UK chancellor blames cyberattacks on Russia despite evidence Fortra discloses 10/10 severity bug in GoAnywhere MFT Entra ID bug could have granted access to every tenant UEFI Secure Boot for Linux Arm64 – where do we stand? JLR says cyber cleanup to take additional week Insider blamed for FinWise data breach affecting nearly 700K Nork snoops whip up fake military ID with help from ChatGPT UK government dragged for incomplete security reforms Church of England abuse victims exposed by lawyer's email US spy chief claims UK backdown on Apple backdoor demand Workday confirms CRM breach via social engineering Black Hat/DEF CON: AI more useful for defense than hacking Ex-White House cyber guru talks Microsoft security fails CISA releases malware analysis for Sharepoint Server attack China: US spies used Microsoft Exchange 0-day to steal info Security pros drowning in threat-intel data Identity attacks surge 156% as phishermen get craftier Organizations can’t keep up with supply chain security musts Amazon CISO: Iranian hacking crews ‘on high alert’ UK data watchdog fines 23andMe £2.3M over 2023 breach Employers are demanding too much from junior cyber recruits FCA warned four staffers who pocketed regulator data Ransomware just wrecked your network – now what? Ivanti RCE attacks 'ongoing,' exploitation hits clouds Ex-NSA listened to Scattered Spider's calls: 'They're good' Snowflake CISO talks lessons learned from breaches, improv Why CVSS is failing us and what we can do about it Infosec pros still aren't nailing the basics of AI security Ransomware crims targeting systems between IT and operations Why aggregating asset inventory leads to better security NCSC and industry at odds over how to tackle shoddy software Powerschool extortionists may not have deleted stolen data CrowdStrike trims workforce by 5 percent, aims to rely on AI NSO Group must pay Meta $168M in WhatsApp spy case Ghost in the shell script: Boffins seek code correctness How Intruder finds what others miss in cloud security Linux malware can avoid syscall-based endpoint protection Infosec pro blabs about alleged malware mishap on LinkedIn The future of AI in cybersecurity in a word – optimistic CVE board 'kept in the dark' on funding, members say Security snafus caused by third parties up from 15% to 30% Blue Shield shared 4.7M people's health info with Google Ads Who needs phishing when your login's already in the wild? US cyber defenses are being dismantled from the inside Bug hunter obtains an SSL cert for Alibaba Cloud in 5 steps
Every day in every way, passwords are getting worse
Rupert Goodwins Rupert Goodwins · 2026-02-23 · via The Register - Security: CSO

OPINION Passwords turn 65 this year. They became a feature of computer users' lives in 1961, with MIT's Compatible Time-Sharing System (CTSS). Before then, sysops were real sysops. All jobs went through them, one at a time, and access by others was forbidden by laws written on blocks of stone.

There are many, mostly sysops, who consider the introduction of direct user access as an abomination that has brought plague and chaos. They may well be right. Nevertheless, we are now stuck with this godless world. Passwords have hit retirement age, yet show no signs of going away, voluntarily or forcibly. They are, unhappily, getting worse at their job.

In the past couple of weeks alone, three new wrinkles in password security have appeared. Too-clever-by-half compilers can optimize away protection against time-based password attacks, password managers that are supposed to be architecturally invulnerable to compromise are less than perfect after all, and if you ask your AI to generate a strong password, you may get something that looks right but isn't. You might not ask an LLM for a password, but if your password manager offers one, how's that generated?

That's not the only issue with password managers. Most people use those provided by Apple and Google. Both companies are American and must withdraw your access to their services if you annoy the wrong person. Digital sovereignty means never having all your passwords vanish, and you don't have it.

To be fair to our superannuated security strings, none of this is inherent to passwords. A properly specified and implemented password system, used by properly educated and motivated people, is as secure as anyone could want. You see the problem.

It is, of course, getting worse. The whole idea of agentic AI is pinned to the donkey by the assumption that your agents need your access rights to act on your behalf. There being no industry-wide best practices, no inherent management principles, or indeed inherent anything, this means giving AI agents your passwords – something that in a sane and godly world you would not do. Instead we've just seen agentic AI vibe-coded polycules like OpenClaw wink into existence to facilitate a global orgy of info-swapping among the robots, without a single silicon condom in sight. We only had time to say the first syllable of "What could possibly go wrong?" before it did.

The answer to keeping agentic AI secure is not to use it – let alone declare your OS as agentic from top to bottom, Microsoft. If you want to use it, then you'd better understand and properly implement privilege isolation, security segmentation, and all the other good things that you need when sharing your digital environment with a universe of mischievous djinn. Rewatch the Sorcerer's Apprentice scene from Fantasia for a refresher.

For everything else, the good news is that since the early 1960s, there has been considerable progress in making passwords much safer, even in the hands of humans, or not needed at all. Most of us use these techniques multiple times a day with local fingerprint or facial recognition on our devices. The weakest of passwords, the PIN, is plenty good enough when backed by three-strike or rate-limited locks.

So far, implementation and availability have been good enough that most users can use them reliably, mostly because it's quite hard to mess them up. Extending them into online services, however, is a different matter, as is managing service security on multiple devices. Two-factor authentication and passkeys are fine in principle, but far less so in practice.

Take two-factor auth. There are lots of options such as SMS or authenticator apps, device biometrics, or physical security keys, but all have different problems connected with social engineering, device or account loss, or spotty compatibility. Even availability isn't guaranteed where you might expect it. Your sparkling new Mac mini might sport a processor of unrivaled brilliance, but Apple forgot the fingerprint sensor. This is a complicated landscape to navigate for a naive user.

Passkeys, as currently implemented, are worse. Not because the underlying technology is flawed, but because they are hard to explain, easy to misunderstand, and typically offer options that can confuse not just the naive. They are a challenge-and-authenticate channel between a service and a device that relies on previously agreed cryptographically signed tokens. They can't be stolen or duplicated, and are strictly a per-device system. That's something that can be explained to anyone, although probably with different words, and the advantages made clear. Use passkeys, and you won't need passwords and you'll be safer.

What, then, does it mean when a system offers to store the passkey in the cloud-based password manager? What should you do if, as per usual, the system offers you a choice of passkey and some don't work? What if a service doesn't use passkeys at all?

When it all works, it can't be beaten. Go to an online service, the system fills in your username, dab the fingerprint sensor, and you're in. Getting to that stage when so many of the processes, vocabulary, and options aren't standardized isn't standard, and quelling the fear that if something goes wrong you'll be locked out is hard, even for those who've been authenticating since CTSS.

Like so many security woes, this is a solution that needs to be fixed itself. What's needed is a common message across the industry, a standardized user experience, and a commitment to customer education. But the industry – platform makers, service providers, app builders alike – is so high on the smell of its own flatus that it's completely in thrall to Apple Lightning Syndrome. There is no sin greater than voluntarily agreeing to a common standard just because it makes everything better.

Well, tough. Passwords are broken, the better technology is being pointlessly obfuscated, and instead of taking the time to sit in a room for a month and fix it, everyone is obsessed with experimental AI that is to security what anti-vax is to healthy children. Passwords aren't the only idea needing to be pensioned off. ®