Passwords are vulnerable to several cyber threats and attacks. Humans choose passwords, also known as memorised secrets, as usually something easy for them to remember and something personal (NIST, 2017), such as phone number, date of birth, name, nickname, pet name, favourite colour…
However, this practice enables and enhances the likelihood of the following threats:
Password guessing – where a cybercriminal attempts to guess passwords using common dictionary words (sometimes they work!)
Password cracking – a cybercriminal uses software to trial and error a vast set of words, phrases and alphanumeric characters to gain authentication onto the user’s online account.