SPARK
Dan Misener
SPARKCould your username be used against you?
By Dan Misener, CBC News
Posted: Feb 16, 2011 9:29 AM ET
Last Updated: Feb 16, 2011 9:29 AM ET
Dan Misener You don’t need a computer science degree to know that “password” is not a very good password. Nor is your birth date, your street address or the name of your dog (unless your dog’s name happens to be 3$m_iLtVF3M9w8s, but that’s a terrible name for a dog).
We’re told again and again about the importance of choosing strong, hard-to-guess passwords. What’s more, we’re told that our passwords should be unique — your email password should be different from your Facebook, eBay and online banking passwords. Reusing passwords is a no-no.
Even if you manage to choose strong, unique passwords for each and every service you use, you shouldn’t stop worrying. New research suggests there’s another factor that may put your online security and privacy at risk: your username.
On some websites, I go by “danmisener.” On others, I’m “dmisener.” At work, I’m “misenerd” (or, as some people are fond out pointing out, “miseNERD”). The thing is, I tend to reuse the same handful of usernames, based on what’s already been taken by Miseners that have come before me.
By utilizing the same username across multiple websites, you may be giving marketers and online scammers an easy way to profile and track you.
According to researchers from the French National Institute of Computer Science, that may not be such a good idea. They’ve found that by reusing usernames across multiple websites, you may be giving marketers and online scammers an easy way to profile and track you.
Daniele Perito, one of the researchers, says: “We looked into the uniqueness of the usernames that people use online. We found that people tend to reuse the usernames a lot, and tend to choose extremely identifying usernames for their online activity, which can pose privacy risks.”
Just what are those privacy risks? If you use the same username across multiple computer networks, it’s not hard for an advertiser or marketer to pull together bits of your digital identity from across the internet into one place, creating a more complete profile than one network could provide alone.
For example, I might use Facebook to share personal information with my friends and family. And I might use LinkedIn to connect with business colleagues. Try as I might to keep the two separate, if I use the same username for both websites, they can be linked. Advertisers and marketers will love this. People concerned about online profiling won’t.
In a more nefarious example, multiple online profiles could be linked together by scammers for phishing or targeted spam campaigns. The more scammers know about you, the better they can tailor their attacks. Though it may be easy to ignore an email plea for money from “Mr. Richard Ramos” of the “Capital Diplomatic Courier Services Company” in West Africa, it’s harder to ignore one that claims to come from Aunt Peggy, especially if it mentions cousins Eric and Julia by name. Sure, it might actually be from Aunt Peggy, but it might also be from a scammer who’s been browsing my public Facebook profile.
In order to do their experiments, the French researchers needed usernames. So they collected more than 10 million of them (from Google, eBay, and other sources), and were able to calculate what they call “username probabilities.” According to their system, statistically speaking, the usernames “dmisener” and “misenerd” probably belong to the same person (me). So even if you only use similar usernames across different sites, you can still be tracked or targeted.
This isn’t just an issue for people who re-use their usernames, but also for people with uncommon usernames. For instance, there aren’t too many Dan Miseners in the world, but there are a lot of John Smiths. Daniele Perito told me that people with more uncommon and unusual username are more susceptible to profiling techniques. So bad news for “EngelbertHumperdinck1936,” but good news for anyone named John Smith.
Taking responsibility
What am I supposed to do with this information? Should I spend an afternoon changing all my existing usernames, whilst I fashion a cap out of tin foil? Perito says no, he doesn’t expect people to go and change their usernames. He and his colleagues are more interested in techniques that large web services like Google, eBay or Facebook could use to keep username information out of unscrupulous hands. Several websites display usernames publicly for the world to see. The French researchers were able to download 3.5 million usernames from Google, and 6.5 million from eBay. Daniele says that’s part of the problem.
For those of us who don’t run large web services, the researchers have created a tool that lets you analyze your own usernames. You type one in, and it’ll tell you how easily it can be used to identify you. Or, you can type in two usernames, and the software will tell you if it thinks they belong to the same person. You can find the tool by searching for “How unique are your usernames?”
Personally, I’m not going to start changing all my existing usernames. But I am going to be much more aware of the ones I choose going forward.
The thing that strikes me most about this story is the tension of online identity. Often, we want our friends and family to be able to find us easily. I like that I’m misener on Twitter, misener on Facebook and misener on Instagram. In one sense, there’s a strong case for having a single, pervasive online identity. But at the same time, this research suggests there are risks.
That’s what happens when you sign up for a pervasive online identity. You get a pervasive online identity, for better or worse.
But just to be safe, you can call me John Smith from now on.
(Dan Misener is a national technology columnist for CBC Radio afternoon shows, and one of the minds behind Spark, with Nora Young.)
Share Tools
Top News Headlines
- Canadian Pacific strikers face back-to-work legislation
- Labour Minister Lisa Raitt is prepared to end the Canadian Pacific Railway strike if necessary, after both CP and the union rejected a proposal for voluntary arbitration by the government-appointed negotiator on Sunday. Raitt says she is "extremely disappointed." more »
- Syrian regime denies role in Houla massacre
- The UN Security Council condemned the Syrian regime at an emergency meeting Sunday, holding president Bashar al-Assad's military responsible for the massacre of more than 100 people, dozens of whom were children younger than 10 years old. more »
- Ryder Hesjedal wins prestigious Giro d'Italia
- Victoria native Ryder Hesjedal has become the first Canadian to win one of the cycling world's three Grand Tour events, wrapping up the 2012 Giro d'Italia with an excellent performance in the final stage in Milan. more »
- Neighbour may have helped find missing kids in Mexico
- Two Winnipeg children who had been missing for nearly four years were found in Mexico after a man raised concerns about his neighbour, according to a private investigator. more »
Latest Technology & Science News Headlines
- South Africa, Australia to share world's largest telescope
- South Africa and Australia will jointly host the Square Kilometre Array, which promises to be the world's largest telescope, the international consortium in charge of the project said Friday. more »
- Bonavista, N.L., 'coyote' was really wolf, tests confirm
- Wolves have not been seen in Newfoundland since around 1930 and were believed to have been hunted to extinction on the island, but genetic tests have confirmed that an 82-pound animal shot on the Bonavista Peninsula in March was, in fact, a wolf. more »
- Once-rare argus butterfly thriving thanks to climate change
- Global warming is threatening the existence of many species, such as the giant polar bear, but in the case of Britain's brown argus butterfly, it took a species in trouble and made it thrive. more »
- Yahoo scraps digital magazine designed for iPad
- Yahoo has killed Livestand, a tablet magazine, just six months after its debut on the iPad. more »
Bob McDonald's Blog
Government to shut down unique fresh water research area May. 25, 2012 12:31 PM The Experimental Lakes Area research facility in Northern Ontario is being closed down after 44 years of providing invaluable data to scientists in Canada and internationally, a decision that has stunned researchers and environmental groups.
Quirks & Quarks
- May 26: Before the Lights Go Out May. 25, 2012 4:15 PM A new book, "Before the Lights Go Out: Conquering the Energy Crisis Before It Conquers Us", suggests that the unpredictable, unplanned, ad-hoc way our energy use developed in the past will shape our energy future.
Latest Features
- Seniors float above Montreal's Quartier Latin
- Accused in blast that killed Alberta mom handled her funds
- Remains found in bag on Cape Breton river ID'd
- Neighbour may have helped find missing kids in Mexico
- Quebec students and province to resume talks
- Lip-dub marriage proposal an internet hit
- Syrian regime denies role in Houla massacre
- B.C. NDP calls for unity in fighting coast guard closure
- Canadian Pacific strikers face back-to-work legislation

