recently jointly issued the Beijing Key Laboratory of China software testing center and the Peking University Internet security technology "web site user password handling security external evaluation report" shows that in 100 sites from the site, most of the user password processing safety awareness is not enough, there are 59 sites did not take any security measures, the the user’s password in a naked state.

85% website can see the original password


report from the portal, e-mail, e-commerce, recruitment and other 9 categories of 100 websites for evaluation, evaluation found that only 8 sites to take adequate security measures for treatment on the user password, there are 59 sites did not take any security measures. In addition, there are 85 sites in the site directly to get the password of the user’s original text, in which the recruitment of the class, love and marriage, e-commerce website user password security status of the worst.


Internet Security Technology Key Laboratory of Beijing city engineer Gong Xiaorui believes that the original user password is the user’s personal privacy information, which constitute a great risk of leakage of personal information of users. Some users in different sites to register the account habit of using the same user name and password, once the password on a site is compromised, the data in other sites will be a certain degree of joint and several leaks".

handle passwords without explicit specification

Gao Chiyang, deputy director of the China Software Evaluation Center, said

, improve user password security is a routine security measures, and the cost of improving security is very low. A common programmer can use existing open technology, one day can be achieved, but also do not have to update the customer information.

Gao Chiyang believes that the current user password processing site, there is no clear standard or specification. How to handle the user password, can only rely on the web site developers, operators and self-discipline to understand the common sense of safety, one of the main reason which is caused by the existing problems.

survey shows

select the site: a total of portal, mailbox, e-commerce, recruitment, marriage and love, games, forums, blogs, micro-blog 9 categories of 100 sites. The reason why the choice of these sites, because of the large number of these sites, users, more personal information is also true.

results: portal, e-mail, games, such as the site is relatively good, e-commerce, recruitment, love and marriage website password security status of the worst. Survey a total of 12 e-commerce classes, the recruitment of the 15 categories, the marriage of the 10 sites, these sites are the transmission of the password form".

according to the Beijing News


          domestic web site user security issues the most serious protection of love and marriage website


