Alert icon Keyboard navigation enabled.
Alert icon TAB or Shift+TAB to navigate across. Down ↓ to open menu. ESC to close menu.
Alert icon Down ↓ to select section. Right → to activate. Up ↑ / Down ↓ / Tab to traverse all. ESC to exit.
BeyondTrust
Skip to content Use space or enter to skip.

What can we help you find today?

Instant Results
  • Website Results
  • Technical Documentation

Filter Options

Focus your search

Filtering by

Your recent searches:

Contact Us Chat with Sales Get Support
  • English
  • Deutsch
  • français
  • español
  • 한국어
  • português
  • Home
  • Resources
  • Blog
  • A Christmas Fail – Putting holiday hacklore on the naughty list current page
Link copied

A Christmas Fail – Putting Holiday Hacklore On The Naughty List

Dec 22, 2025

Every holiday season, cybersecurity myths resurface alongside festive folklore. This article explores “hacklore”—outdated security advice rooted in past truths—and explains why clinging to these myths can distract organizations from today’s real identity-based risks.

Author:
James Maude Headshot 2024
James Maude
Field Chief Technology Officer
Cybersecurity Hacklore
A Christmas Fail – Putting Holiday Hacklore On The Naughty List
James Maude Headshot 2024
James Maude
Field Chief Technology Officer

What Is Cybersecurity “Hacklore” and Why Does It Still Persist?

White chain icon to symbolize the ability to copy a link
Link copied
Check mark to visually show text has been copied

Every holiday season, we retell strange and wonderful stories: yule cats prowling Iceland devouring children without new socks; Krampus, the horned shadow of St. Nicholas, punishing naughty children in Germany; and Tió de Nadal, a magical log that “poops” candies and gifts in Catalonia. Folklore (no matter how strange) is part of the season’s charm.

In IT and cyber security, we have our own folklore—or rather, hacklore: well-meaning stories that started from a grain of truth but have been repeated so often that they have become fact, even when the technology landscape has moved on. The best gift you can give this season is being able to separate the facts from the cybersecurity myths and misconceptions. So let’s call out a few of the most persistent pieces of hacklore, explain why they no longer hold up, and put them on the naughty list before they do more harm than good.

The Top 3 Myths about Cybersecurity

White chain icon to symbolize the ability to copy a link
Link copied
Check mark to visually show text has been copied

Myth #1 - Don’t connect to public Wi-Fi

If you’ve been watching the news headlines this month, this one might look familiar: “TSA warns travelers to avoid free public Wi-Fi”. The coverage makes it sound like hackers have infiltrated every transport hub with free Wi-Fi. In fact, this lore is so embedded in the public psyche that, if you tell someone you work in cyber security, they will gleefully tell you how they know not to connect to public Wi-Fi and use a VPN at all times.

The origins of this hacklore date back to a time when most internet traffic wasn’t encrypted and you could grab plain text credentials out of the Wi-Fi-filled air. However, the world has moved on. Now, the vast majority of modern apps and websites use encryption to protect your web traffic, browsers and apps warn of unsecured connections, and messaging apps add end-to-end encryption.

The most common risk is the same no matter what network you connect to: fake login pages that compromise your credentials. This could be a phishing login page that appears when you connect to some public Wi-Fi, or when you click a link in an email on your home Wi-Fi. We need to warn people more about where to enter credentials and less about where to connect to Wi-Fi. Enabling multi-factor authentication should be at the top of your Christmas list for the same reason.

This hacklore is in part driven by consumer VPN apps that claim to secure your web browsing from the prying eyes of attackers—while, at the same time, neglecting to mention that they can snoop on all your traffic and won’t protect against rogue login pages that phish credentials.


Myth #2 - Developers/Engineers/Support Desk need standing privilege

I recently spoke with an IT leader whose organization had removed 5000 local administrator accounts, but, just like in The Santa Clause, you have to be wary of the small print. Their policy said that users who needed this privilege reinstated just needed a director’s sign-off.

This of, course, resulted in a flurry of “admin gifting” as directors blindly signed off on 4200 requests as if they were Christmas cards. They believed the lore: that local admin privileges are needed, and that it was easier to just elevate the entire account than to grant only the specific permissions a task actually required.

When it comes to any form of privileged access, you shouldn’t hold on to it all year-round. Instead, you need a just-enough and just-in-time (JIT) approach—much like how I do gift shopping. Users, no matter how technical (or senior), don’t need permanent, always-on privilege; they need frictionless, just-in-time (JIT) access for when a task truly requires it.

In the age of identity threats, the number one thing on the threat actor’s wish list is compromising an identity with standing privilege. That isn’t just about local admin rights. It applies to dozens of privilege escalation pathways across on-prem systems, cloud environments, and in SaaS applications. So, when it comes to privilege, less is more this holiday season.


Myth #3 - Changing passwords regularly

You’re making a password, you’re checking it twice; gonna find out who’s been compromised.

We used to encourage users to change their passwords regularly, with some companies enthusiastically enforcing 30-day limits. The result reads much like a Christmas cracker joke: “What do you get if you force users to rotate their password every month? Weaker passwords!”.

Like much cybersecurity hacklore, it actually detracts from solving the real problem. What we need is for users to not reuse passwords across multiple systems and focus on using a strong password, ideally alongside strong MFA. By forcing regular rotations, users are more likely to reuse and recycle passwords to help them remember, thereby lowering the security of their identity.

Since 2024, NIST guidance (SP 800-63B) has recommended rotating passwords only after a confirmed compromise because, if they haven’t been compromised or shared, then one strong password is better than 10 weak ones. There are, of course, exceptions for privileged accounts, shared accounts, and non-human identities, where having an enterprise secrets management solution is essential for securing and managing those credentials.


And one more thing…

Instead of reflexively warning people not to scan QR codes or use public USB ports to charge their devices, and to clear their browser cookies regularly, let’s focus on helping them secure their identities and spot real scams in 2026.

Wrapping up

White chain icon to symbolize the ability to copy a link
Link copied
Check mark to visually show text has been copied

Folklore travels and endures because it’s vivid, memorable, and social. Cybersecurity hacklore is no different. With vivid images of hackers in the shadows wielding magical exploits, it’s easy for cybersecurity myths and misconceptions to outrun the truth. Every industry has its own lore, from urban legends to superstitions. So before you tie a bow on another piece of outdated advice, make your New Year’s resolution to focus on reducing real risks over telling winter’s tales.

This season, unwrap the real risks in your environment with the complimentary BeyondTrust Identity Security Risk Assessment.

FAQs

White chain icon to symbolize the ability to copy a link
Link copied
Check mark to visually show text has been copied

Cybersecurity hacklore refers to outdated cybersecurity myths or advice that originated from real risks, but no longer reflect how modern technology and attacks work today. These myths persist because they’re easy to repeat and remember, even though they distract organizations from addressing real identity security risks, like credential theft, over-privileged access, and phishing attacks.

Outdated cybersecurity advice is risky because it can give organizations a false sense of security while leaving modern attack paths exposed. Attackers now focus on compromising identities through stolen credentials, excessive privileges, and non-human identities, etc. rather than exploiting networks directly. Relying on legacy guidance often means ignoring the identity risks that lead to real breaches today.

Organizations can identify real identity security risks by gaining visibility into all identities—human and non-human—and understanding where excessive privileges, stale credentials, and hidden paths to privilege exist. Identity security risk assessments help replace assumptions with measurable insight into where attackers are most likely to succeed.

About the Author

White chain icon to symbolize the ability to copy a link
Link copied
Check mark to visually show text has been copied
James Maude Headshot 2024
James Maude
Field Chief Technology Officer

James Maude is the Field Chief Technology Officer (FCTO) at BeyondTrust. With his broad experience in security research, both in academia and industry, James has spent the past decade analyzing cyber threats to identify attack vectors and trends in the evolving security landscape. He is an active member of the security community and hosts Adventures of Alice and Bob, a podcast that shines a light on the people making a difference in security. As an expert voice on cybersecurity, he regularly presents at international events and hosts webinars to discuss threats and defense strategies.

Learn More

White chain icon to symbolize the ability to copy a link
Link copied
Check mark to visually show text has been copied
Blog
BeyondTrust’s Top Tech Integrations of 2025: Advancing Unified Identity Security Across the Ecosystem
Blog
Identity Security Cannot Be Solved in Silos
Blog
The Spooky Privilege Pathways Lurking in your IT Environment... and How to Fight Back
Blog
Top Cybersecurity Trend Predictions for 2026+: BeyondTrust Edition
Blog
Closing The Agentic AI Security Gap: Why Identity Protection Must Evolve Now
Blog
True Privilege™: BeyondTrust Sets New Standard for Privileged Access and Identity Security
Resources
Paths to Privilege Explained
Research
Guide to Identity Security Defense-in-Depth
Latest Posts
  • The Most Common & Most Dangerous Types of Shadow IT
    Jun 5, 2026 The Most Common & Most Dangerous Types of Shadow IT
    Blog
    19m
  • 14 Password Management Best Practices
    May 28, 2026 14 Password Management Best Practices
    Blog
    12m
  • A Security Researcher’s Guide to Understanding Copilot Studio AI Agents
    May 26, 2026 A Security Researcher’s Guide to Understanding Copilot Studio AI Agents
    Blog
    3m
  • How to Secure Cloud-Native Infrastructure at Scale and Speed: A Conversation with Madhu Adireddi
    May 21, 2026 How to Secure Cloud-Native Infrastructure at Scale and Speed: A Conversation with Madhu Adireddi
    Blog
    5m
  • Cybersecurity as a Boardroom Priority for Major African TelCos
    May 12, 2026 Cybersecurity as a Boardroom Priority for Major African TelCos
    Blog
    8m
Related
  • Why Service Desks Need Privileged Identity Management
    Oct 12, 2012 Why Service Desks Need Privileged Identity Management
    Blog
    1m
  • Privilege Management SaaS Hardens Windows & Mac Endpoint Security, Protecting On-Prem & Remote Workers & Systems
    May 26, 2020 Privilege Management SaaS Hardens Windows & Mac Endpoint Security, Protecting On-Prem & Remote Workers & Systems
    Blog
    1m
Share this Article
  • Link
Tags
  • cybersecurity advice
  • cybersecurity hacklore
  • cybersecurity myths
  • cybersecurity myths and misconceptions
  • holiday cybersecurity
  • Identity Security Risks
  • identity-based attacks
  • password rotation best practices
  • public Wi-Fi security myths
  • Security Awareness
Stay up to Date
Get the latest news, ideas, and tactics from BeyondTrust. You may unsubscribe at any time.

Keep up with BeyondTrust

Customer Support Get Started
  • LinkedIn
  • X
  • Facebook
  • Instagram
  • Add BeyondTrust as a preferred source on Google
  • Privacy
  • Security
  • Manage Cookies
  • Do Not Sell My Data
  • WEEE Compliance

Copyright © 2003 — 2026 BeyondTrust Corporation. All rights reserved. Other trademarks identified on this page are owned by their respective owners. BeyondTrust Corporation is not a chartered bank or trust company, or depository institution. It is not authorized to accept deposits or trust accounts and is not licensed or regulated by any state or federal banking authority.

Prefers reduced motion setting detected. Animations will now be reduced as a result.
MS Vulns Report 2026 orange background 1

New: 2026 Microsoft Vulnerabilities Report

Access the report for expert analysis of Microsoft's vulnerability and security landscape, breaking down key trends, security shifts, emerging risks—and what it all means for you.

Get the Report

New: 2026 Microsoft Vulnerabilities Report: Access the report for expert analysis of Microsoft's vulnerability and security landscape, breaking down key trends, security shifts, emerging risks—and what it all means for you.

Get the Report