O
20

Drove 30 miles for an incident response consult and the client had 'password' as their VPN login

Got a call from a small law firm in Albany last Tuesday because they thought they had a breach. Turns out their office manager set up their remote access with the password literally as 'password123'. I told them to change it and they asked if they could keep it because 'it's easy to remember'. What's the worst default password you've seen at a real business?
2 comments

Log in to join the discussion

Log In
2 Comments
elizabethwhite
Oh man, I gotta jump in here and play the other side of this for a second. Look, I get why everyone screams about passwords like that, but think about a small law firm in Albany where the office manager is probably juggling a zillion things and just needs stuff to work. Making the password something simple means nobody gets locked out or has to call IT every Monday morning because they forgot something complicated. Honestly, if they had it on a sticky note under the keyboard anyways, isn't a memorable password just the same risk with less hassle? What's the real difference between 'password123' and some random 12-character thing they write down on a desk?
2
margaretj40
Just last month at my dentist's office in Schenectady, they had the same exact problem with their billing system. The password was literally "dentist2023" and the hygienist told me it's because nobody could remember the one the IT guy set up. I totally get what @elizabethwhite is saying about smaller offices where people just need to get their work done without jumping through hoops. Honestly, if someone's determined enough to look under a keyboard or dig through a desk drawer for a sticky note, they're probably going to find the password either way. So might as well save everyone the headache of resetting passwords every other day.
2