Showing posts with label crack. Show all posts
Showing posts with label crack. Show all posts

Tuesday, October 4, 2016

Can't Live with 'em, Can't Live without 'em

   They're dead.  They're here to stay.

   They're safe.  They're breached.

   They're encrypted.  They're visible.

   They're complex.  They're too simple.

   Once again, the topic we love to hate... Passwords!  And, you know what else???  It's also that greatest of holiday celebrations... US Cyber Security Month!

   In honor of US Cyber Security Month and the recently announced breach of 500 million Yahoo! account passwords and other info  (while announced in 2016, the breach actually took place in 2014, and is not the same as the password breach they had in 2012! - yes, I know... it's hard to keep up!), I'm re-running a post I wrote in... wait for it... 2012!  Not only is everything I wrote in that post 100% relevant today, but I even commented on that 2012 Yahoo! breach.  The more things change, the more they stay the same.  Happy Cyber Security Month!
-----------------
   Passwords are a mess!  A "good" password has these features:
  • hard to create
  • hard to remember
  • hard to enter
  • probably has to be changed as soon as you memorize it
  • plus other inconsistent, random rules depending upon the site
   Perfect!

Tuesday, February 9, 2016

How To Vault (part 1)

   I was recently asked to provide more information on vaults.  I think this is a memorable one :-).


  Well, to be more precise, the question was about password vaults...
you've talked about password vaults and it seems like something should do, but I'm not sure how to start and it still seems a bit scary.
   That is a great question.  We've talked about passwords and password vaults a number of times in the past including here, here and here.

   But why do we even need something like a password vault.  There are a few reasons, and they have to do with the problems passwords pose:

Tuesday, January 6, 2015

The Secret Life of Passwords

   I've written about passwords plenty of times in the past.  Passwords are one of the main security touch-points for people, and it's often not a pleasant experience.

   As we've discussed, it's hard for people to pick good passwords and remember them.  So users need "tricks" to help the memory.  One way I've told people to construct a password is to base the password on an embarrassing moment in your life - that way you won't forget the password and you also won't tell it to anyone else.

   Apparently people have been using that, and similar, methods.  NY Times reporter Ian Urbana wrote a great piece on this called "The Secret Life of Passwords".  He asked people to tell him their passwords - yes, you shouldn't do that - but also the story behind the passwords.  There are some very interesting stories.  People seem to memorialize a part of their life in their passwords!  You can read the full story here.  Leo Laporte did a great interview with Ian in the Triangulation podcast.  You can hear that here.

   I'd like to focus to two aspects of this story that jumped out at me.

   First is the story of Cantor Fitzgerald.  They are a large financial firm who were headquartered at the World Trade Center in 2001.  When the terrorist attacks hit the towers, Cantor Fitzgerald over two-thirds of their employees were killed.  That was tragic.

Tuesday, December 10, 2013

Password Problems Again

   So here we go again... more problems with breached passwords.  But this time there is a different wrinkle.

   By now, most of you have probably heard about the recent discovery of hackers getting around 2 million userid's and passwords to online services like Facebook, Gmail, Yahoo, LinkedIn and Twitter.  Notable on the list of sites is ADP, the payroll processor.

   It's "just" 2 million sets of ID's and passwords.  That's not really big news these days when the new record of over 152 million stolen passwords was recently set by the Adobe breach.  But there is a difference here.  For most of the big password breaches, the service provider's website or password store is hacked.  Then the encrypted password file or database is downloaded.  The attackers can take their time analyzing the encrypted data to come up with userid's and passwords.  This work is made easier because so many sites use poorly implemented encryption.  And some sites use no encryption at all.

   But that's not what happened here.

   This time the passwords were stolen from the users of the sites.  That's you and me (well... hopefully not you or me!).

Tuesday, November 12, 2013

Rhymes with Assword

   Here we go again with more password-related problems.  You can't make this stuff up.  Well, you can but the truth is stranger.

   By now, most people have heard about the Adobe website breach.  I won't go into too many details but you can read Adobe's summary here, and here is a detailed review by Sophos.

   And, after I wrote this post I see that the This Week In Tech (TWIT) show on the great Twit TV network did a show of the same name (go to 1:56:20 in the show). Great minds think alike!  If you read the Sophos report you will see that someone used the phrase "rhymes with assword" as their password hint.

   There are a few key points to review:
  • A new record!  This breach has now set the new record for largest number of compromised accounts, 152,000,000, beating previous noteworthy large breaches including those from Sony, TJX and Heartland.

Tuesday, October 15, 2013

Online Self Defense - Passwords

   Next week I'll be presenting at the Cyber Security Summit in Minneapolis.  I hope to see you there!

   It's Cyber Security Month!  And the more things change, the more they stay the same.  The key advice for online self-defense I've given in the past is just as true now.  So to help us all celebrate, I'm "re-featuring" a few articles I've run in the past.


   Last week I started a series on themes I covered in a talk entitled "Online Self-Defense".  In part 1 of that series, posted here, I talked about protecting your computer. This week we'll look at passwords.

   Passwords are a mess!  A "good" password has these features:
  • hard to create
  • hard to remember
  • hard to enter
  • probably has to be changed as soon as you memorize it
  • plus other inconsistent, random rules depending upon the site
   Perfect!

Tuesday, June 4, 2013

How crackers ransack passwords - Sort of...

   I am not trying to make this the password rant blog.  But we just can't go a full week without more news about password problems!

   Last week the excellent tech new site, Ars Technica, did a feature article in which they had first a journalist, then three different password hacking experts, try to decrypt passwords from an encrypted password file.  They were all quite successful... frighteningly so.
   Steve Gibson discussed this for a bit in Security Now episode 406.

   But, I think there were some critical flaws in the test.  And there were also some excellent lessons.

   I'll comment on the article using the sandwich method, starting with what was good...

Tuesday, January 22, 2013

Something You Lost - 3 Factors of Fail (part 3)

   As you can tell if you read my last post, I have some pretty strong opinions about the failure of passwords as an authentication mechanism.

   To review, the 3 factors of authentication are referred to as: something you know, something you have and something you are.  Today, in part 3 of this series, we'll talk about the failure of the second factor of authentication, "something you have".  Here are links to parts 1 and 2 of the series.

   While not the oldest form of authentication, this factor of authentication has been around for a long time.  Think about a key, or perhaps some kind of scroll with the symbol from a leader, or even the sword in the stone!  A driver's license, ID card, credit card or passport is also something you have.  These are all things someone can have and can be used identify them or grant access.

   Today, the term "2-factor authentication" can the use of any two different factors of authentication.  But most commonly it refers to the combination of password or PIN that you know, with a single use 6-digit number from some kind of token.

   Here are the three most common single use string/token delivery methods:

Tuesday, October 16, 2012

Online Self Defense - Part 2 - Passwords

   Last week I started a series on themes I covered in a talk entitled "Online Self-Defense".  In part 1 of that series, posted here, I talked about protecting your computer. This week we'll look at passwords.

   Passwords are a mess!  A "good" password has these features:

  • hard to create
  • hard to remember
  • hard to enter
  • probably has to be changed as soon as you memorize it
  • plus other inconsistent, random rules depending upon the site
   Perfect!

Tuesday, August 28, 2012

And the Password is... Monkey!

   If you've been following the news about hackers and cracked passwords, then you know that one of the most often used passwords for online sites and services is: Monkey.  Who would have guessed?!

   All the buzz is about an article appearing in ArsTechnica, Why passwords have never been weaker - and crackers have never been stronger, by Dan Goodin.  It's an eye-opening piece about how the state of the art in password cracking has been greatly advanced by the security information intelligence gained from recent hacks, and password file disclosures, from LinkedIn, eHarmony, Battle.net and others.

   Everyone "knows" they should be using strong passwords - yet passwords like 123456, password and Monkey are routinely on the top of the list of the most used passwords on hacked sites.  Similarly, everyone "knows" they should not reuse passwords between sites (is your Facebook password the same as your online banking password???).  But the article refers to a 2007 Microsoft study which reports that the average web user has accounts on 25 different sites, but protected by only 6.5 unique passwords!

   Here's my take...