Password reuse is rampant: nearly half of observed user logins are compromised

25 points by gmem


dpk

The point’s been raised elsewhere on social media, but just to mention it here: Cloudflare appears to have got this data by spying on cleartext usernames and passwords passed through their infrastructure between web service users’ browsers and their clients’ servers, and then analysing the data they got from that spying.

The ethics here are … questionable. Cloudflare, you will recall, claims to be neutral internet infrastructure. Imagine the phone company putting out a press release one day announcing how many phone calls included someone entering a credit card number over touch-tone on unsecured lines. (Okay, that doesn’t happen very much any more. Imagine it had happened in the 1990s.)