July 14, 2016 By Douglas Bonderud 2 min read

Passwords are a popular commodity on the Dark Web. As noted by Wired, the total number of stolen passwords for sale now tops 640 million thanks to a recent set of megabreaches. While cybercriminals are happy to leverage these credentials for access to a linked account, they’re also looking to reuse passwords on other sites.

To improve user peace of mind, security researcher Philip O’Keefe developed a tool called Shard, which lets users test if a password they use for one site is popular somewhere else. But what happens if cybercriminals repurpose the protective program?

Peace By Piece?

According to Ars Technica, Shard is a command-line tool that lets end users check to see if their current password for Facebook, Twitter or other social sharing sites is commonly used on other platforms. O’Keefe said he got the idea after discovering that a randomly generated, eight-character password he used to protect several services was among the 177 million leaked LinkedIn passwords this May.

While changing one password on a single site is no problem, remembering exactly which sites and services share the same credentials can be time consuming. More worrisome, if users forget a single access point, passwords leaked from another site become an easy way in for cybercriminals.

Enter Shard, which O’Keefe hopes will help users track down and eliminate duplicate passwords. He noted that users shouldn’t encounter any issues using the tool, since “it is difficult for services to ban traffic originating from this tool because it looks like normal traffic.”

Password Problems

O’Keefe’s tool taps a huge market: Password problems remain one of the top threat vectors for malicious actors because many employees prefer to use easily guessed, familiar account details across multiple sites.

But the issue affects more than just front-line users. As noted by The Verge, Twitter CEO Jack Dorsey recently had his account compromised by cybercrime group OurMine, possibly as a result of the recent megabreaches.

According to Threatpost, meanwhile, Citrix’s GoToMyPC remote desktop access tool was on the receiving end of a password reuse attack, prompting the service to initiate a total password reset.

Shard Knocks

Despite the big benefits of identifying multiple password pieces with Shard, there are potential drawbacks. If attackers get their hands on the code, for example, it could be modified to check financial services and e-commerce sites in addition to social platforms.

What’s more, cybercrooks could further reconfigure the application to add random characters at the end of popular passwords in case users simply add a few numbers or letters to make each password unique.

Put simply: While Shard may help users discover their risk of compromise, it could also be used by cybercriminals to markedly increase this risk.

More from

How to craft a comprehensive data cleanliness policy

3 min read - Practicing good data hygiene is critical for today’s businesses. With everything from operational efficiency to cybersecurity readiness relying on the integrity of stored data, having confidence in your organization’s data cleanliness policy is essential.But what does this involve, and how can you ensure your data cleanliness policy checks the right boxes? Luckily, there are practical steps you can follow to ensure data accuracy while mitigating the security and compliance risks that come with poor data hygiene.Understanding the 6 dimensions of…

2024 roundup: Top data breach stories and industry trends

3 min read - With 2025 on the horizon, it’s important to reflect on the developments and various setbacks that happened in cybersecurity this past year. While there have been many improvements in security technologies and growing awareness of emerging cybersecurity threats, 2024 was also a hard reminder that the ongoing fight against cyber criminals is far from over.We've summarized this past year's top five data breach stories and industry trends, with key takeaways from each that organizations should note going into the following…

Black Friday chaos: The return of Gozi malware

4 min read - On November 29th, 2024, Black Friday, shoppers flooded online stores to grab the best deals of the year. But while consumers were busy filling their carts, cyber criminals were also seizing the opportunity to exploit the shopping frenzy. Our system detected a significant surge in Gozi malware activity, targeting financial institutions across North America. The Black Friday connection Black Friday creates an ideal environment for cyber criminals to thrive. The combination of skyrocketing transaction volumes, a surge in online activity…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today