Password reuse bot steals creds from weak sites, logs in to banks

If your Netflix password is your banking password, you’ll get what you deserve.

By Darren Pauli

The perils of password re-use have been laid bare with the discovery of a botnet dedicated to finding account credentials on websites and testing the logins it finds on banks.

The work is clever since it avoids tripping botnet detection and brute force rate limiters in place at most security-savvy banks, but absent across the wider web.

