Account sharing

Last updated

Account sharing, also known as credential sharing, is the process of sharing login information with multiple users to access online accounts or services. [1] This can include sharing information like e-mail addresses, usernames and passwords for social media accounts, subscription services, gaming platforms or other online services.

Contents

Reasons for account sharing

Account sharing is a common practice, especially among younger users who may not have the financial resources to pay for multiple accounts or subscriptions. It is also commonly used among families or groups of friends who want to access a shared account or service. Another reason could be to gain special features that depends on a single account like special items in a game account.[ citation needed ]

People may also share passwords with their significant others as a symbol of affection or absolute trust. [2]

Reasons against account sharing

Account sharing is prohibited by the terms of service of many online accounts, such as Google [3] and Facebook. [4] It can result in account suspensions or even termination, possibly causing users to lose access to important data or services. On the other hand, account sharing can lose money for the service the account is being shared for. [5] [6]

Account sharing can also make it easier for hackers to gain access to multiple accounts using a single set of login credentials. This can lead to sensitive data being compromised or accounts being taken over by unauthorized users. The person the information is shared with could act careless and not secure enough with the login data or could steal the information for other purposes as a social engineering-strategy. [7]

Prevention

Some services offer combined accounts, such as multiple family accounts (Family Sharing) with special child safety options or software license for multiple company accounts to a cheaper prize to prevent account sharing. Another system to make account sharing more difficult is the Multi-factor authentication which often requires the sharer to instantly share the information on their device with the receiver.[ citation needed ]

In 2022, Netflix limited where accounts could be used, based on IP addresses. [8] Their terms of service state that "personal and non-commercial use only and may not be shared with individuals beyond your household". The company later released paid options for account sharing, and is expected to remove free account sharing in 2023. [9] [ needs update ]

Legality

In the United Kingdom, sharing passwords for certain services, such as streaming services, without authorization is considered copyright infringement. [10] [11]

Related Research Articles

<span class="mw-page-title-main">Password</span> Used for user authentication to prove identity or access approval

A password, sometimes called a passcode, is secret data, typically a string of characters, usually used to confirm a user's identity. Traditionally, passwords were expected to be memorized, but the large number of password-protected services that a typical individual accesses can make memorization of unique passwords for each service impractical. Using the terminology of the NIST Digital Identity Guidelines, the secret is held by a party called the claimant while the party verifying the identity of the claimant is called the verifier. When the claimant successfully demonstrates knowledge of the password to the verifier through an established authentication protocol, the verifier is able to infer the claimant's identity.

<span class="mw-page-title-main">BugMeNot</span> Internet service

BugMeNot is an Internet service that provides usernames and passwords to let Internet users bypass mandatory free registration on websites. It was started in August 2003 by an anonymous person, later revealed to be Guy King, and allowed Internet users to access websites that have registration walls with the requirement of compulsory registration. This came in response to the increasing number of websites that request such registration, which many Internet users find to be an annoyance and a potential source of email spam.

Single sign-on (SSO) is an authentication scheme that allows a user to log in with a single ID to any of several related, yet independent, software systems.

Internet privacy involves the right or mandate of personal privacy concerning the storage, re-purposing, provision to third parties, and display of information pertaining to oneself via the Internet. Internet privacy is a subset of data privacy. Privacy concerns have been articulated from the beginnings of large-scale computer sharing and especially relate to mass surveillance.

A federated identity in information technology is the means of linking a person's electronic identity and attributes, stored across multiple distinct identity management systems.

Digital identity is the phrase referring to the data that computer systems use to represent external agents, which can be individuals, organizations, applications, or devices. For individuals, it involves an aggregation of personal data that is essential for facilitating automated access to digital services, confirming one's identity on the internet, and allowing digital systems to manage interactions between different parties. It is a component of a person's social identity in the digital realm, often referred to as their online identity.

Logical security consists of software safeguards for an organization's systems, including user identification and password access, authenticating, access rights and authority levels. These measures are to ensure that only authorized users are able to perform actions or access information in a network or a workstation. It is a subset of computer security.

<span class="mw-page-title-main">OpenID</span> Open and decentralized authentication protocol standard

OpenID is an open standard and decentralized authentication protocol promoted by the non-profit OpenID Foundation. It allows users to be authenticated by co-operating sites using a third-party identity provider (IDP) service, eliminating the need for webmasters to provide their own ad hoc login systems, and allowing users to log in to multiple unrelated websites without having to have a separate identity and password for each. Users create accounts by selecting an OpenID identity provider, and then use those accounts to sign on to any website that accepts OpenID authentication. Several large organizations either issue or accept OpenIDs on their websites.

<span class="mw-page-title-main">Keychain (software)</span> Password management system in macOS

Keychain is the password management system in macOS, developed by Apple. It was introduced with Mac OS 8.6, and has been included in all subsequent versions of the operating system, now known as macOS. A Keychain can contain various types of data: passwords, private keys, certificates, and secure notes.

There are several forms of software used to help users or organizations better manage passwords:

A Google Account is a user account that is required for access, authentication and authorization to certain online Google services. It is also often used as single sign-on for third party services.

Password fatigue is the feeling experienced by many people who are required to remember an excessive number of passwords as part of their daily routine, such as to log in to a computer at work, undo a bicycle lock or conduct banking from an automated teller machine. The concept is also known as password chaos, or more broadly as identity chaos.

A roaming user profile is a file synchronization concept in the Windows NT family of operating systems that allows users with a computer joined to a Windows domain to log on to any computer on the same domain and access their documents and have a consistent desktop experience, such as applications remembering toolbar positions and preferences, or the desktop appearance staying the same, while keeping all related files stored locally, to not continuously depend on a fast and reliable network connection to a file server.

Digital inheritance is the passing down of digital assets to designated beneficiaries after a person’s death as part of the estate of the deceased. The process includes understanding what digital assets exist and navigating the rights for heirs to access and use those digital assets after a person has died.

A recent extension to the cultural relationship with death is the increasing number of people who die having created a large amount of digital content, such as social media profiles, that will remain after death. This may result in concern and confusion, because of automated features of dormant accounts, uncertainty of the deceased's preferences that profiles be deleted or left as a memorial, and whether information that may violate the deceased's privacy should be made accessible to family.

Apple ID is a user account by Apple for their devices and software. Apple IDs contain the user's personal data and settings. When an Apple ID is used to log in to an Apple device, the device will automatically use the data and settings associated with the Apple ID.

Since the arrival of early social networking sites in the early 2000s, online social networking platforms have expanded exponentially, with the biggest names in social media in the mid-2010s being Facebook, Instagram, Twitter and Snapchat. The massive influx of personal information that has become available online and stored in the cloud has put user privacy at the forefront of discussion regarding the database's ability to safely store such personal information. The extent to which users and social media platform administrators can access user profiles has become a new topic of ethical consideration, and the legality, awareness, and boundaries of subsequent privacy violations are critical concerns in advance of the technological age.

Social login is a form of single sign-on using existing information from a social networking service such as Facebook, Twitter or Google, to login to a third party website instead of creating a new login account specifically for that website. It is designed to simplify logins for end users as well as provide more reliable demographic information to web developers.

Identity-based security is a type of security that focuses on access to digital information or services based on the authenticated identity of an entity. It ensures that the users and services of these digital resources are entitled to what they receive. The most common form of identity-based security involves the login of an account with a username and password. However, recent technology has evolved into fingerprinting or facial recognition.

Meta Platforms Inc., or Meta for short, has faced a number of privacy concerns. These stem partly from the company's revenue model that involves selling information collected about its users for many things including advertisement targeting. Meta Platforms Inc. has also been a part of many data breaches that have occurred within the company. These issues and others are further described including user data concerns, vulnerabilities in the company's platform, investigations by pressure groups and government agencies, and even issues with students. In addition, employers and other organizations/individuals have been known to use Meta Platforms Inc. for their own purposes. As a result, individuals’ identities and private information have sometimes been compromised without their permission. In response to these growing privacy concerns, some pressure groups and government agencies have increasingly asserted the users’ right to privacy and to be able to control their personal data.

References

  1. "Sharing your Netflix account". Help Center.
  2. Richtel, Matt (January 17, 2012). "Young, in Love and Sharing Everything, Including a Password". The New York Times.
  3. "Avoid sharing an account among users". Google Workspace Admin Help.
  4. "Can I create a joint Facebook account or share a Facebook account with someone else?". Facebook Help Center.
  5. "EVE Online" . Retrieved 3 June 2023.
  6. Brizuela, James (October 18, 2022). "Netflix Is Banning Account Sharing". MSN.
  7. "The Risks of Password and Account Sharing - Best Practices". October 21, 2021.
  8. Sharma, Adamya; Blichert, Frederick (December 1, 2022). "Netflix account sharing: Everything you need to know". Android Authority.
  9. Goss, Tricia (January 24, 2023). "How To Transfer Netflix Profiles Before Free Account Sharing Ends". Newsy.
  10. Muncaster, Phil (December 22, 2022). "UK Government: Sharing Some Passwords is Illegal". Infosecurity Magazine.
  11. "Meta counterfeit and piracy campaign". GOV.UK.