CipherWatch Home

Category

Password Security

6 articles

When Your Username Outlives Your Interest: The Thriving Underground Trade in Abandoned Digital Identities

When Your Username Outlives Your Interest: The Thriving Underground Trade in Abandoned Digital Identities

Every dormant social media profile, forgotten email address, and inactive username you have left behind represents a potential asset in a shadow marketplace where threat actors buy, sell, and repurpose abandoned digital identities. Account recovery mechanisms designed to help legitimate users can be weaponized by social engineers, and the credibility attached to an old account — its follower count, its posting history, its apparent age — makes it more dangerous than a newly created fake. CipherW

Ghost Accounts: The Forgotten Corners of Your Digital Past That Are Still Leaking Your Data Today

Millions of Americans have dozens — sometimes hundreds — of dormant online accounts they created years ago and never thought about again. Those forgotten profiles are not merely inactive; they are live data repositories sitting in the crosshairs of credential-stuffing attacks and breach-hungry cybercriminals. This investigation examines how abandoned accounts become persistent security liabilities and what you can do right now to close the door.

The Policy That Made Passwords Worse: How Mandatory Rotation Rules Backfired — and What Security Experts Now Recommend

For decades, IT departments across America enforced a rule that felt responsible but quietly undermined the very security it was meant to protect: change your password every 90 days. New research, updated federal guidance, and a growing consensus among security professionals have since exposed this practice as counterproductive. CipherWatch investigates how the policy was born, why it persisted, and what the evidence-based alternatives actually look like.

Face Value: The Hidden Security Risks Behind Your Bank's Biometric Login

Face Value: The Hidden Security Risks Behind Your Bank's Biometric Login

Financial institutions across the United States are racing to deploy facial recognition as a next-generation authentication tool, positioning it as both more secure and more convenient than traditional passwords. But security researchers warn that biometric systems introduce a category of risk that passwords never could — one that cannot be reset if compromised.

Can You Trust What You See? A Practical Field Guide to Detecting AI-Fabricated Media and Deepfake Fraud

Can You Trust What You See? A Practical Field Guide to Detecting AI-Fabricated Media and Deepfake Fraud

Generative artificial intelligence has lowered the barrier to creating convincing fake video, audio, and images to near zero, and fraudsters are exploiting that capability to impersonate executives, romantic partners, and government officials in scams targeting everyday Americans. Knowing how to critically evaluate digital media — before wiring money, sharing sensitive information, or making decisions based on what you have seen or heard — has become an essential survival skill for the modern in

Locked Out of Logic: Why Millions of Americans Still Refuse to Trust a Password Manager

Locked Out of Logic: Why Millions of Americans Still Refuse to Trust a Password Manager

Despite overwhelming evidence that password managers dramatically reduce account compromise, adoption rates among American adults remain stubbornly low. CipherWatch investigates the psychological, cultural, and practical forces keeping users tethered to sticky notes and recycled passwords — and offers a clear framework for deciding whether it's time to make the switch.