Should You Be Concerned When a Company Asks You to Reset Your Password?

We try our best to keep Lifehacker readers informed about recent data breaches and security vulnerabilities that could have compromised their data. Any good website or service should tell you what’s going on too. Sometimes, though, you get an email unexpectedly that your account credentials have been compromised – even if the company sending you the information is okay.

What gives?

As internet security reporter Brian Krebs notes in a recent blog post , a company that asks you to change your password does not necessarily mean that your account was specially targeted, or that your data has been hijacked by hackers due to poor security measures. It might just be a proactive measure on behalf of the company to help you keep your account secure.

Large companies actively cross-validate their hashed user data – for example, your secure password – using the same hashing mechanisms to convert plaintext passwords found in various data breaches. If these hashed passwords match the hashed data already found in the company database for the user, that person is asked to update their password.

It is also important to note that these notifications are not the same as unrecognized login attempts or password change requests that indicate someone is trying to actively access your account. While the latter scenario requires a more urgent response, both should be taken seriously: change your password and update your security measures when asked, and do so as soon as possible.

However, passwords by themselves are poor security measures. When you receive a notification from a company that your password has been compromised as a result of an unrelated data breach, consider this a great opportunity to brush up on the security of your password, as well as all the other security methods that can protect you:

More…

Leave a Reply