A government team of hackers tasked with testing the Department of the Interior’s cyber vulnerabilities cracked more than 16 percent of the department’s 85,000 passwords in 90 minutes, a new report reveals.
An unclassified Jan. 3 report (pdf) from the Inspector General for Audits, Inspections, and Evaluations found that the department’s password protection and use of multi-factor authentication were woefully insecure.
“Our objective was to determine whether the Department’s password management and enforcement controls were effective enough to prevent a malicious actor from gaining unauthorized access to Department computer systems by capturing and ‘cracking’ user passwords,” the report stated.
“We initiated this inspection because we were able to crack between 20 and 40 percent of the passwords we captured during past projects.”…