July 14, 2016 By Douglas Bonderud 2 min read

Passwords are a popular commodity on the Dark Web. As noted by Wired, the total number of stolen passwords for sale now tops 640 million thanks to a recent set of megabreaches. While cybercriminals are happy to leverage these credentials for access to a linked account, they’re also looking to reuse passwords on other sites.

To improve user peace of mind, security researcher Philip O’Keefe developed a tool called Shard, which lets users test if a password they use for one site is popular somewhere else. But what happens if cybercriminals repurpose the protective program?

Peace By Piece?

According to Ars Technica, Shard is a command-line tool that lets end users check to see if their current password for Facebook, Twitter or other social sharing sites is commonly used on other platforms. O’Keefe said he got the idea after discovering that a randomly generated, eight-character password he used to protect several services was among the 177 million leaked LinkedIn passwords this May.

While changing one password on a single site is no problem, remembering exactly which sites and services share the same credentials can be time consuming. More worrisome, if users forget a single access point, passwords leaked from another site become an easy way in for cybercriminals.

Enter Shard, which O’Keefe hopes will help users track down and eliminate duplicate passwords. He noted that users shouldn’t encounter any issues using the tool, since “it is difficult for services to ban traffic originating from this tool because it looks like normal traffic.”

Password Problems

O’Keefe’s tool taps a huge market: Password problems remain one of the top threat vectors for malicious actors because many employees prefer to use easily guessed, familiar account details across multiple sites.

But the issue affects more than just front-line users. As noted by The Verge, Twitter CEO Jack Dorsey recently had his account compromised by cybercrime group OurMine, possibly as a result of the recent megabreaches.

According to Threatpost, meanwhile, Citrix’s GoToMyPC remote desktop access tool was on the receiving end of a password reuse attack, prompting the service to initiate a total password reset.

Shard Knocks

Despite the big benefits of identifying multiple password pieces with Shard, there are potential drawbacks. If attackers get their hands on the code, for example, it could be modified to check financial services and e-commerce sites in addition to social platforms.

What’s more, cybercrooks could further reconfigure the application to add random characters at the end of popular passwords in case users simply add a few numbers or letters to make each password unique.

Put simply: While Shard may help users discover their risk of compromise, it could also be used by cybercriminals to markedly increase this risk.

More from

FYSA – Adobe Cold Fusion Path Traversal Vulnerability

2 min read - Summary Adobe has released a security bulletin (APSB24-107) addressing an arbitrary file system read vulnerability in ColdFusion, a web application server. The vulnerability, identified as CVE-2024-53961, can be exploited to read arbitrary files on the system, potentially leading to unauthorized access and data exposure. Threat Topography Threat Type: Arbitrary File System Read Industries Impacted: Technology, Software, and Web Development Geolocation: Global Environment Impact: Web servers running ColdFusion 2021 and 2023 are vulnerable Overview X-Force Incident Command is monitoring the disclosure…

What does resilience in the cyber world look like in 2025 and beyond?

6 min read -  Back in 2021, we ran a series called “A Journey in Organizational Resilience.” These issues of this series remain applicable today and, in many cases, are more important than ever, given the rapid changes of the last few years. But the term "resilience" can be difficult to define, and when we define it, we may limit its scope, missing the big picture.In the age of generative artificial intelligence (gen AI), the prevalence of breach data from infostealers and the near-constant…

Airplane cybersecurity: Past, present, future

4 min read - With most aviation processes now digitized, airlines and the aviation industry as a whole must prioritize cybersecurity. If a cyber criminal launches an attack that affects a system involved in aviation — either an airline’s system or a third-party vendor — the entire process, from safety to passenger comfort, may be impacted.To improve security in the aviation industry, the FAA recently proposed new rules to tighten cybersecurity on airplanes. These rules would “protect the equipment, systems and networks of transport…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today