Showing posts with label login. Show all posts
Showing posts with label login. Show all posts

Tuesday, October 25, 2016

Lock Before You Leap

   Most organizations have some kind of requirement to protect data.  Sometimes it's regulatory, for example organizations in healthcare or financial or retail need to protect personal data on individuals.  But for sales, manufacturing or other industries like medical devices, their "secret sauce" could be intellectual property like formulas or proprietary processes, or customer lists.

   Whether it's critical data on people, processes or things, what most organizations have in common is that, if they cannot protect this information, the results could be fines or inability to do business and that can directly translate to harm to people and organizations.

   There are so many ways to protect information (or to fail at protecting information), some more complicated than others.

   One very simple way that information can be breached, disclosed or otherwise lost is through unattended, unlocked devices.  For example, someone leaves a laptop logged in, screen unlocked and walks away - someone else can take that laptop and would have access to any data it has.  This is also true for desktop workstations.  In this case the computer won't likely be taken, but if the workstation is unattended and unlocked, anyone else can access the data on that machine leading to potential breaches and regulatory problems.

Tuesday, October 4, 2016

Can't Live with 'em, Can't Live without 'em

   They're dead.  They're here to stay.

   They're safe.  They're breached.

   They're encrypted.  They're visible.

   They're complex.  They're too simple.

   Once again, the topic we love to hate... Passwords!  And, you know what else???  It's also that greatest of holiday celebrations... US Cyber Security Month!

   In honor of US Cyber Security Month and the recently announced breach of 500 million Yahoo! account passwords and other info  (while announced in 2016, the breach actually took place in 2014, and is not the same as the password breach they had in 2012! - yes, I know... it's hard to keep up!), I'm re-running a post I wrote in... wait for it... 2012!  Not only is everything I wrote in that post 100% relevant today, but I even commented on that 2012 Yahoo! breach.  The more things change, the more they stay the same.  Happy Cyber Security Month!
-----------------
   Passwords are a mess!  A "good" password has these features:
  • hard to create
  • hard to remember
  • hard to enter
  • probably has to be changed as soon as you memorize it
  • plus other inconsistent, random rules depending upon the site
   Perfect!

Monday, November 23, 2015

Do the Amazon 2-Step... Now!

   It's not a new song or a new dance...  Amazon has just announced 2-step, aka 2-factor or multi-factor, authentication for online logins!  It's overdue but I'm glad it's here.

   We've talked about 2-factor authentication in the past so I won't go deeply into it in this post.  The important take-away is that Amazon now offers this service and you should use it!

   Here's an overview article and here's a great step-by-step with screen shots.  I set this up for my account and it was really easy using my phone and Google Authenticator.  You can also use text messaging, or setup text messaging as a backup method.

   The main reason that 2-factor is good and important is that it prevents an attacker, who has stolen your userid and password, from logging in as you.  This is because they would need to have your smartphone in addition to the userid and password! (yes, there are other methods as well).

Tuesday, January 6, 2015

The Secret Life of Passwords

   I've written about passwords plenty of times in the past.  Passwords are one of the main security touch-points for people, and it's often not a pleasant experience.

   As we've discussed, it's hard for people to pick good passwords and remember them.  So users need "tricks" to help the memory.  One way I've told people to construct a password is to base the password on an embarrassing moment in your life - that way you won't forget the password and you also won't tell it to anyone else.

   Apparently people have been using that, and similar, methods.  NY Times reporter Ian Urbana wrote a great piece on this called "The Secret Life of Passwords".  He asked people to tell him their passwords - yes, you shouldn't do that - but also the story behind the passwords.  There are some very interesting stories.  People seem to memorialize a part of their life in their passwords!  You can read the full story here.  Leo Laporte did a great interview with Ian in the Triangulation podcast.  You can hear that here.

   I'd like to focus to two aspects of this story that jumped out at me.

   First is the story of Cantor Fitzgerald.  They are a large financial firm who were headquartered at the World Trade Center in 2001.  When the terrorist attacks hit the towers, Cantor Fitzgerald over two-thirds of their employees were killed.  That was tragic.

Tuesday, May 13, 2014

The Best (First Good) Password Policy Ever!



In the past I've discussed a number of aspects of the password dilemma.  Among the key issues are
  • good passwords are hard to remember, and;
  • passwords you can remember are easy for attackers to guess.
   But, maybe one of the key issues is that password policies are universally so bad that consumers can't do the right thing because they can't figure out what that is!  We've been living with that old dogma of.... say it with me...
  • 8 characters;
  • upper/lower case;
  • numbers;
  • special characters.
   That's been around since the 60's.  Perhaps it worked in a world when people had only one password, when systems weren't all networked together, and attacking systems wasn't the lucrative business it is now.

Tuesday, February 11, 2014

Bad Policies = Bad Passwords

   It seems that passwords are in the news again.  In the past I've discussed a number of aspects of the password dilemma.  Among the key issues are:
  • good passwords are hard to remember, and;
  • passwords you can remember are easy for attackers to guess.
   Adding to this mess is that many organizations do a poor job of protecting their storage of your password.  And now we have some new information...
Many organizations allow you to pick poor passwords on their websites by enforcing few or weak password construction requirements.
   We call these password policies, and these specify things like: how long the password can be; the minimum length it must be; what kinds of characters can or must be used; if the password needs to change, and; if there are some passwords that can't be chosen.

Tuesday, December 10, 2013

Password Problems Again

   So here we go again... more problems with breached passwords.  But this time there is a different wrinkle.

   By now, most of you have probably heard about the recent discovery of hackers getting around 2 million userid's and passwords to online services like Facebook, Gmail, Yahoo, LinkedIn and Twitter.  Notable on the list of sites is ADP, the payroll processor.

   It's "just" 2 million sets of ID's and passwords.  That's not really big news these days when the new record of over 152 million stolen passwords was recently set by the Adobe breach.  But there is a difference here.  For most of the big password breaches, the service provider's website or password store is hacked.  Then the encrypted password file or database is downloaded.  The attackers can take their time analyzing the encrypted data to come up with userid's and passwords.  This work is made easier because so many sites use poorly implemented encryption.  And some sites use no encryption at all.

   But that's not what happened here.

   This time the passwords were stolen from the users of the sites.  That's you and me (well... hopefully not you or me!).

Tuesday, November 12, 2013

Rhymes with Assword

   Here we go again with more password-related problems.  You can't make this stuff up.  Well, you can but the truth is stranger.

   By now, most people have heard about the Adobe website breach.  I won't go into too many details but you can read Adobe's summary here, and here is a detailed review by Sophos.

   And, after I wrote this post I see that the This Week In Tech (TWIT) show on the great Twit TV network did a show of the same name (go to 1:56:20 in the show). Great minds think alike!  If you read the Sophos report you will see that someone used the phrase "rhymes with assword" as their password hint.

   There are a few key points to review:
  • A new record!  This breach has now set the new record for largest number of compromised accounts, 152,000,000, beating previous noteworthy large breaches including those from Sony, TJX and Heartland.

Tuesday, October 22, 2013

Online Self Defense - Don't Click!

   This week I'm presenting at the Cyber Security Summit in Minneapolis.  I hope to see you there!

   It's Cyber Security Month!  And the more things change, the more they stay the same.  The key advice for online self-defense I've given in the past is just as true now.  So to help us all celebrate, I'm "re-featuring" a few articles I've run in the past.


   This is the third post in my series on Online Self-Defense.  We've covered malware and passwords, two key issues effecting your online privacy and security.  If you've tried the simple tips I gave on those two subjects then you are now safer than most web surfers.

   Now, to keep you and your computer safe... don't click on that link!

Tuesday, October 15, 2013

Online Self Defense - Passwords

   Next week I'll be presenting at the Cyber Security Summit in Minneapolis.  I hope to see you there!

   It's Cyber Security Month!  And the more things change, the more they stay the same.  The key advice for online self-defense I've given in the past is just as true now.  So to help us all celebrate, I'm "re-featuring" a few articles I've run in the past.


   Last week I started a series on themes I covered in a talk entitled "Online Self-Defense".  In part 1 of that series, posted here, I talked about protecting your computer. This week we'll look at passwords.

   Passwords are a mess!  A "good" password has these features:
  • hard to create
  • hard to remember
  • hard to enter
  • probably has to be changed as soon as you memorize it
  • plus other inconsistent, random rules depending upon the site
   Perfect!

Tuesday, May 7, 2013

So Long and Thanks for All the Passwords!

   If you've been following any online news lately you read about the recent Living Social breach.  They reported "unauthorized access" of their systems resulting in a download of customer data including name, email address and encrypted passwords.

   We have heard of many similar instances over the past few years.  I've written about this in previous posts and will be giving a talk at Secure360 in St. Paul, MN in a couple of weeks talking about authentication and passwords.

   In their defense, Living Social did do a couple of things well.  First of all, fortunately, they did store only encrypted passwords.  Unfortunately many organizations don't.  Unfortunately they used an older, weaker encryption algorithm.  And, of course, unfortunately they got breached and had the file downloaded.

Tuesday, February 19, 2013

So What's the Authentication Answer? - 3 Factors of Fail (part 7 - last!)

   We've been discussing the authentication problem for the better part of two months, and now it's time to wrap things up.  If you've gotten to this post through a link but haven't read the rest of the series, it starts with part 1 here.

   Each of the 3 factors of authentication have serious issues when used individually.  The challenge is that we need to log a person into a system or application in a way that reasonably assures the person is who they say they are and has rights to the system.  And, perhaps most importantly, any method we use has to work well for people!

   So, how do we find a solution?

   The key is to think about the user and the use.

Tuesday, February 12, 2013

Multi-Factor Fail - 3 Factors of Fail (part 6)


from: brainyquote.com
   In December I was at the NG Security Conference in Austin, TX.  We had a fantastic discussion with a group of key security leaders focusing on this "quote" and how it applies to information security.  I say "quote" because there is some question as to who said this or if anyone actually did!

   As I've been saying throughout this series of posts, it seems that this statement is exactly what we are doing in the world of authentication!  None of the typical factors of authentication have really solved our authentication and access problems, yet we continue to use the same mechanisms over again.

Tuesday, February 5, 2013

The 4th Factor? - 3 Factors of Fail (part 5)

   Welcome to the next installment of my ramblings on authentication, 3 Factors of Fail.  So far we have discussed the classic 3 factors of authentication in parts 1, 2, 3 and 4.

   In recent years some additional authentication assurance methods have been grouped to form what some call the 4th factor of authentication.  This is also called risk-based, location-based or adaptive authentication.  It could also be called "somewhere you are" or "something you are doing".

   The basis of this method is in establishing a rich profile of the user.  This can include:
  • the machine used for access;
  • software used;
  • time or day of accesses;
  • IP address(es) used;
  • what country the connection comes from, or;
  • what actions the user attempts.

Tuesday, January 15, 2013

Something You Forgot - 3 Factors of Fail (part 2)

   Last week we started talking about authentication and listing the 3 factors of authentication.  This 2nd in the 5-part series will look at the 1st factor.

   The 1st factor of authentication is "something you know".  We usually think of this as passwords, but there can be other forms like: PINs; lock combinations; "secret" phrases (the phrase that pays!); picture identification; and secret pattern (like on your smartphone).

   There are a few fundamental problems here.  And they are mostly caused by something we can't change... we're trying to authenticate a human! (usually)  So, rather than something we know, these authentication methods rapidly deteriorate into something you forgot.  Here's why...

Tuesday, January 8, 2013

3 Factors of Fail - The Authentication Problem

   Authentication is one of the biggest challenges in information security. We can have all kinds of technical security measures in our systems. There are various controls we can have at the data level. But we still need to allow people to use the systems and get to the data. I should say... we need to allow the right people to use the systems and get to the data! Authentication is how we decide who the right people are.

   Federal regulations like HIPAA, PCI, IRS 1075 and others have major focus on minimum necessary.  That is, giving a user the minimum access they need to do their job.

   Wikipedia defines authentication as: (from Greek: αὐθεντικός; real or genuine, from αὐθέντης authentes; author) is the act of confirming the truth of an attribute of a datum or entity. This might involve confirming the identity of a person or software program, tracing the origins of an artifact, or ensuring that a product is what its packaging and labeling claims to be.  And Webopedia has: The process of identifying an individual, usually based on a username and password.  Interesting that this latter definition directly refers to username and password.

   There has been plenty of news in the past couple of years of breaches involving theft of a password file (encrypted or unencrypted) and customer/citizen personal data. Example like: eHarmony, LinkedIn, South Carolina Dept. of Revenue, and Utah. Many of these attacks involved exploiting authentication.

Tuesday, October 23, 2012

Online Self Defense - Part 3 - Don't Click!

   This is the third post in my series on Online Self-Defense.  We've covered malware and passwords, two key issues effecting your online privacy and security.  If you've tried the simple tips I gave on those two subjects then you are now safer than most web surfers.

   Now, to keep you and your computer safe... don't click on that link!

Tuesday, October 16, 2012

Online Self Defense - Part 2 - Passwords

   Last week I started a series on themes I covered in a talk entitled "Online Self-Defense".  In part 1 of that series, posted here, I talked about protecting your computer. This week we'll look at passwords.

   Passwords are a mess!  A "good" password has these features:

  • hard to create
  • hard to remember
  • hard to enter
  • probably has to be changed as soon as you memorize it
  • plus other inconsistent, random rules depending upon the site
   Perfect!