Tosec Security Team Blog
45% of the internet security fields are attributed to password security. If you are studying cryptography, you should be very familiar with this situation.
In the edge culture of the network, we refer to the process of learning others' passwords in some way as social engineering (hereinafter referred to as social engineering). Of course, this is only one branch, because the goal of social engineering is not just to get a password
We can use social engineering to obtain the information we want, while cryptography can be roughly summarized into a branch of social engineering because we use some psychological states to obtain passwords, for example:
1. Think of a simple password to facilitate memory
2. Common password principles, convenient and quick
3. Password Association
These will bring a lot of potential harm to the Internet.
Is this an Internet security risk?
Of course, this is for sure, because it has caused harm to us from the network, and we have included this in the penetration test scope.