CISO's 'r3@lg00dp@$w0rd' undone by unpatched flaw
UKPulse News Desk
A CISO reportedly believed a symbol-substituted password was strong, but an unpatched system was the real problem. The Register notes that swapping letters for symbols does not make a password good.
- A CISO thought a password written as 'r3@lg00dp@$w0rd' was secure.
- The issue was reportedly a failure to patch, not the password itself.
- Replacing letters with symbols does not by itself make a password strong.
A chief information security officer believed a password styled as 'r3@lg00dp@$w0rd' was strong, according to The Register. The same report says the real failure was that the CISO forgot to patch.
The Register's summary states plainly that replacing letters with symbols still does not make a password good.
The evidence does not identify the organisation, the system involved, the vulnerability, or any outcome. No date for a fix or further action is given.
Why this matters: The case illustrates that password styling is not a substitute for patching known flaws, though the evidence does not specify the vulnerability involved.