It's US Cyber Security Month and the key themes I've been discussing here for years are very bit as relevant today. In honor of Cyber Security Month I'm re-running a post from 2016. The more things change, the more they stay the same. Happy Cyber Security Month!
Well, I was trying for something catchy like Stop, Drop and Roll. That's a saying we learned in school, back in the day, for what you should do if your clothes catch on fire.
Fortunately, it seems like everyone has heard that saying and it rolls off the tongue.
Unfortunately, my three word phrase Patch, Vault and Fob, is not nearly as catchy.
Fortunately, the odds of your clothes catching on fire is low.
Unfortunately, the odds of your software, browsers or accounts being compromised is very high.
A couple of weeks ago the internet was hit with the highly impact-full and publicized distributed denial of service (DDoS) attack on Dyn, a DNS provider. I won't go into the details here but I think I will cover DDoS in a future post. Anyway, shortly after that I was chatting with someone at a dinner who asked me about this attack, internet safety in general and what they could do. To keep it simple and because, as a math person I like things in 3's!, I provided these 3 simple (well, maybe straight-forward is more accurate) things that absolutely everyone should do at home...
A place to talk about information security, Internet safety and, of course... coffee!
Thoughtful, sometimes controversial, but not following the crowd unless I'm in line at the coffee shop.
Showing posts with label password. Show all posts
Showing posts with label password. Show all posts
Tuesday, October 31, 2017
Tuesday, October 17, 2017
Still Can't Live With 'Em
It's US Cyber Security Month and, like clockwork, we have Yahoo! in the news again telling us that the worst case from the past just keeps getting worster (I can make up words, can't I??? :-). They are now counting their breached accounts at over 3 billion! How many people are there in the world these days?... Last year at this time, they announced the breach of 500 million Yahoo! account passwords and other info (while announced in 2016, the breach actually took place in 2014, and is not the same as the password breach they had in 2012! - yes, I know... it's hard to keep up!). In honor of both Cyber Security Month and Yahoo!, I'm re-running a post I wrote in... wait for it... 2012! Not only is everything I wrote in that post 100% relevant today, but I even commented on that 2012 Yahoo! breach. The more things change, the more they stay the same. Happy Cyber Security Month!
They're dead. They're here to stay.They're safe. They're breached.
They're encrypted. They're visible.
They're complex. They're too simple.
Once again, the topic we love to hate... Passwords! And, you know what else??? It's also that greatest of holiday celebrations... US Cyber Security Month!
Passwords are a mess! A "good" password has these features:
- hard to create
- hard to remember
- hard to enter
- probably has to be changed as soon as you memorize it
- plus other inconsistent, random rules depending upon the site
Perfect!
Labels:
2-factor,
account,
breach,
complexity,
cyber,
cybersecurity,
encryption,
length,
month,
October,
password,
passwords,
reuse,
secret,
vault,
yahoo
Tuesday, September 19, 2017
Equi-Fail!
Or maybe we should say Equi-Fiasco!By now you've certainly heard about the Equifax breach including leaked social security numbers and other personal information on over 143 million people. And there's plenty more info to come with this one as the facts continue to get uncovered.
I certainly don't mean to be jumping on the bandwagon here. There has already been so much coverage of this breach, but it is a big deal. And, while I've seen a number of articles on what to do now, I haven't seen any that really cover everything you must do to protect yourself.
Let's do that now!
The bottom line is this... it's 2017... no one can or will protect your personal information. You must take appropriate steps to protect yourself. And here they are... in no particular order... the top-10 things you should do to protect your personal and financial information:
Labels:
account,
alert,
breach,
complexity,
credit,
credit bureau,
credit report,
Equifax,
freeze,
incident,
IRS,
multi-factor,
online,
password,
social security,
vault
Tuesday, August 8, 2017
You Gotta Be You
I just received an update from the Social Security Administration. Yes, it was real! :-) It was a reminder to log in to the SSA website to check my information online. That also made me think about advice I've written about in the past... it's critical that you connect and establish your presence on critical government websites before someone else can create an account in your name.
Here's a rewind of a 2016 post with all the information...
I recently received a letter from the SSA (Social Security Administration). It provided instructions for me to finish setting up my online account. As I've written in the past you can, and need to, create personal accounts on the SSA and IRS websites. The key issue is that you need to reserve and establish your identity on these critical government websites before someone else does it for you! This is ID Fraud is still a big issue.
These accounts are straightforward to set up. One thing you will need to do is go through an Identity Proofing process. That process asks you for some personal information that, in theory, only you should know. I list info about the irs.gov account creation process in this post.
Here is some info from the ssa.gov website:
I highly recommend that you create accounts on these sites and use 2FA where available. Here are the instructions for SSA. Here for the IRS. You can enable 2-factor authentication on the SSA site when you create your account. Here's a link to a previous post looking at other sites where 2FA is available. Double up wherever you can!
Here's a rewind of a 2016 post with all the information...
These accounts are straightforward to set up. One thing you will need to do is go through an Identity Proofing process. That process asks you for some personal information that, in theory, only you should know. I list info about the irs.gov account creation process in this post.
Here is some info from the ssa.gov website:
You can create a my Social Security account if you’re age 18 or older, have a Social Security number, a valid email, a U.S. mailing address, and a cell phone that can receive text messages. You’ll need to provide some personal information to confirm your identity; you’ll be asked to choose a username and password; and then provide your cell phone number. You’ll then receive a security code via text that you will be required to enter when you first create an account. We’ll send your cell phone a new security code each time you log in with your username and password. The security code is part of our enhanced security feature to protect your personal information. Keep in mind that your cell phone provider's text message and data rates may apply.Now SSA has increased their security by offering two-factor authentication (2FA) on their site. We've written about 2FA a number of times in the past. SSA had said this was coming and now it's available.
I highly recommend that you create accounts on these sites and use 2FA where available. Here are the instructions for SSA. Here for the IRS. You can enable 2-factor authentication on the SSA site when you create your account. Here's a link to a previous post looking at other sites where 2FA is available. Double up wherever you can!
Labels:
2-factor,
account,
authentication,
fix,
identity,
identity proofing,
IRS,
password,
social,
SSA,
vault,
vulnerability
Tuesday, May 9, 2017
Google Docs and the Mailinator
You're minding your own business, just checking email, when you get an email from a "friend" inviting you to get a shared Google Doc file.
You're a student of security, or at least a fan, so you're always skeptical when you receive an email with a link or attachment. This one appears to come from someone you know. The subject and body of the message seem consistent with a Google doc sharing message.
Problem clue #1 - look at the "To:" line. Clearly, this message wasn't sent to you.
Problem clue #2 - were you expecting this email and file? Has this sender sent you Google docs in the past? Did this email arrive at work or home - and do you normally use Google docs there?
But, you are rushed and don't have time to send your friend a message to see if this email is legit. So you click. If you're not already logged in to your Google account, you're asked to log in. What you see next is...
You're a student of security, or at least a fan, so you're always skeptical when you receive an email with a link or attachment. This one appears to come from someone you know. The subject and body of the message seem consistent with a Google doc sharing message.
Problem clue #1 - look at the "To:" line. Clearly, this message wasn't sent to you.
Problem clue #2 - were you expecting this email and file? Has this sender sent you Google docs in the past? Did this email arrive at work or home - and do you normally use Google docs there?
But, you are rushed and don't have time to send your friend a message to see if this email is legit. So you click. If you're not already logged in to your Google account, you're asked to log in. What you see next is...
Tuesday, February 28, 2017
Seriously, You Can't Make This Stuff Up!
Fake news and alternative facts aside, the truth really is stranger than fiction.
We finally get to the point where the only thing left to talk about concerning Yahoo! is their upcoming turbulent buyout by Verizon. But noooo...
They're back, with another breach announcement. This one is from sometime in the 2015/2016 timeframe (am I the only one who is concerned that they can't pin it down better than that????). It seems to be more limited in scope (i.e. less than the 500 Million users affected last time!).
We seriously just "finished" talking about this issue. Normally when an old problem comes back again (like always do), I consider re-running an older post with any needed updates (and rarely are any major updates needed). But I just posted about Yahoo!'s problems TWO MONTHS AGO!
This time around the root cause is supposed to be a forged cookie that could be used to access an account without using a password. Yahoo! is saying that the attackers must have had access to the source code and that a similar method may have been used in the previous attacks. Maybe... maybe not.
In other news... the price for Verizon to buy Yahoo! keeps dropping. Could "free" be far behind?
You know, the funny thing is that I really like the Yahoo! home page layout with its news summaries. If they could just protect my account data for more than a month or two we might actually have a service worth salvaging.
Vote... are you dumping your Yahoo! account or keeping it?
We finally get to the point where the only thing left to talk about concerning Yahoo! is their upcoming turbulent buyout by Verizon. But noooo...
They're back, with another breach announcement. This one is from sometime in the 2015/2016 timeframe (am I the only one who is concerned that they can't pin it down better than that????). It seems to be more limited in scope (i.e. less than the 500 Million users affected last time!).We seriously just "finished" talking about this issue. Normally when an old problem comes back again (like always do), I consider re-running an older post with any needed updates (and rarely are any major updates needed). But I just posted about Yahoo!'s problems TWO MONTHS AGO!
This time around the root cause is supposed to be a forged cookie that could be used to access an account without using a password. Yahoo! is saying that the attackers must have had access to the source code and that a similar method may have been used in the previous attacks. Maybe... maybe not.In other news... the price for Verizon to buy Yahoo! keeps dropping. Could "free" be far behind?
You know, the funny thing is that I really like the Yahoo! home page layout with its news summaries. If they could just protect my account data for more than a month or two we might actually have a service worth salvaging.
Vote... are you dumping your Yahoo! account or keeping it?
Tuesday, January 17, 2017
(Browser) Caching Fire
Someone recently asked me a question about the safety of allowing your web browser to save, and then auto-fill, passwords. That's a very timely question because that issue has been in the news lately.
Web browsers have all kinds of built-in capabilities. One "feature" that is only a few years old is the ability to save information you might put into forms such as: your name and address, phone number and other contact info, credit card information. Browsers can also save your userids and passwords for sites, then automatically fill in that info when you visit the site.
I've always said that security-minded people should not allow web browsers to save this kind of personal and security info. This is primarily because all browsers have a track record of having many vulnerabilities. I've always "said" this but, as it turns out, I've never written about it! It's about time! [Note... or so I thought! While looking for some other info, I found that I did talk about this issue back in 2013!]
There are two primary reasons why allowing the browser to save sensitive information is a bad idea:
Web browsers have all kinds of built-in capabilities. One "feature" that is only a few years old is the ability to save information you might put into forms such as: your name and address, phone number and other contact info, credit card information. Browsers can also save your userids and passwords for sites, then automatically fill in that info when you visit the site.
I've always said that security-minded people should not allow web browsers to save this kind of personal and security info. This is primarily because all browsers have a track record of having many vulnerabilities. I've always "said" this but, as it turns out, I've never written about it! It's about time! [Note... or so I thought! While looking for some other info, I found that I did talk about this issue back in 2013!]
There are two primary reasons why allowing the browser to save sensitive information is a bad idea:
- Copycat and phishing websites can grab information directly your browser has stored without your knowledge. This is the problem that was recently announced.
- As I just mentioned, browsers have many vulnerabilities and exploits. At this year's Pwn2Own contest (a 2-day event at which teams compete to exploit software vulnerabilities for cash prizes), all of the major browser fell victim!
Tuesday, December 20, 2016
Ya-How?
Just a few months ago, in September 2016, Yahoo announced that they had uncovered a breach that leaked passwords for 500 million accounts. The actual breach took place in 2014 but took years to discover. This breach was different than the prior breach announced in 2012. We discussed this here.
This announcement came at a time when Yahoo was deep into talks to be acquired by Verizon. That September announcement led to speculation about effects to the purchase price.
Well, truth is stranger than fiction, and Yahoo is back in the news again. Now on December 14, 2016 it appears that yet another breach has been discovered. This is different from the previous issues and seems to date from August 2013. This latest discovery affects... wait for it... one billion accounts! You'll recall that the 2014 breach discovered in Sept 2016 hit "only" half that many accounts!
So if we look at the timeline, Yahoo had major breaches in 2012, 2013 and 2014 with discoveries in 2015 and 2016! Good times. Here is the latest announcement from Yahoo as well as some articles covering the details.
This whole thing is a major issue (issues?) for a number of reasons, and it has to do with our dependence on email in our online world and Yahoo's role as major provider of free email.
This announcement came at a time when Yahoo was deep into talks to be acquired by Verizon. That September announcement led to speculation about effects to the purchase price.Well, truth is stranger than fiction, and Yahoo is back in the news again. Now on December 14, 2016 it appears that yet another breach has been discovered. This is different from the previous issues and seems to date from August 2013. This latest discovery affects... wait for it... one billion accounts! You'll recall that the 2014 breach discovered in Sept 2016 hit "only" half that many accounts!
So if we look at the timeline, Yahoo had major breaches in 2012, 2013 and 2014 with discoveries in 2015 and 2016! Good times. Here is the latest announcement from Yahoo as well as some articles covering the details.
This whole thing is a major issue (issues?) for a number of reasons, and it has to do with our dependence on email in our online world and Yahoo's role as major provider of free email.
- We all use email daily for wide variety of reasons. We have a need to trust email. Of course, using email has made our lives easier... Not!
- Spam and Phishing - when you receive a spam or phishing message from a "friend", you are more likely to click on the links. Similarly, having your account taken over endangers your friends and contacts.
- Password reuse - most people reuse passwords among internet sites because it's easier to remember fewer passwords
- Linked accounts - as a convenience, you can connect accounts together so that you can use multiple services with one login. This is most common with Facebook ("login with Facebook") but this is also available with Yahoo, Google and others.
- Password resets and other verifications - often, password reset info or alerts or warnings are sent to an email address you specify. If you specified your Yahoo account to receive these from your bank or other important site, and you account was compromised in any of the attacks we're discussing, the attackers could intercept this alert information.
Tuesday, November 8, 2016
Patch, Vault 'n Fob
Well, I was trying for something catchy like Stop, Drop and Roll. That's a saying we learned in school, back in the day, for what you should do if your clothes catch on fire.
Fortunately, it seems like everyone has heard that saying and it rolls off the tongue.
Unfortunately, my three word phrase Patch, Vault and Fob, is not nearly as catchy.
Fortunately, the odds of your clothes catching on fire is low.
Unfortunately, the odds of your software, browsers or accounts being compromised is very high.
A couple of weeks ago the internet was hit with the highly impact-full and publicized distributed denial of service (DDoS) attack on Dyn, a DNS provider. I won't go into the details here but I think I will cover DDoS in a future post. Anyway, shortly after that I was chatting with someone at a dinner who asked me about this attack, internet safety in general and what they could do. To keep it simple and because, as a math person I like things in 3's!, I provided these 3 simple (well, maybe straight-forward is more accurate) things that absolutely everyone should do at home...
Fortunately, it seems like everyone has heard that saying and it rolls off the tongue.
Unfortunately, my three word phrase Patch, Vault and Fob, is not nearly as catchy.
Fortunately, the odds of your clothes catching on fire is low.
Unfortunately, the odds of your software, browsers or accounts being compromised is very high.
A couple of weeks ago the internet was hit with the highly impact-full and publicized distributed denial of service (DDoS) attack on Dyn, a DNS provider. I won't go into the details here but I think I will cover DDoS in a future post. Anyway, shortly after that I was chatting with someone at a dinner who asked me about this attack, internet safety in general and what they could do. To keep it simple and because, as a math person I like things in 3's!, I provided these 3 simple (well, maybe straight-forward is more accurate) things that absolutely everyone should do at home...
Labels:
2-factor,
authentication,
browser,
fob,
LastPass,
multi-factor,
password,
passwords,
patch,
software,
tools,
vault
Tuesday, October 25, 2016
Lock Before You Leap
Most organizations have some kind of requirement to protect data. Sometimes it's regulatory, for example organizations in healthcare or financial or retail need to protect personal data on individuals. But for sales, manufacturing or other industries like medical devices, their "secret sauce" could be intellectual property like formulas or proprietary processes, or customer lists.Whether it's critical data on people, processes or things, what most organizations have in common is that, if they cannot protect this information, the results could be fines or inability to do business and that can directly translate to harm to people and organizations.
There are so many ways to protect information (or to fail at protecting information), some more complicated than others.
One very simple way that information can be breached, disclosed or otherwise lost is through unattended, unlocked devices. For example, someone leaves a laptop logged in, screen unlocked and walks away - someone else can take that laptop and would have access to any data it has. This is also true for desktop workstations. In this case the computer won't likely be taken, but if the workstation is unattended and unlocked, anyone else can access the data on that machine leading to potential breaches and regulatory problems.
Tuesday, October 4, 2016
Can't Live with 'em, Can't Live without 'em
They're dead. They're here to stay.They're safe. They're breached.
They're encrypted. They're visible.
They're complex. They're too simple.
Once again, the topic we love to hate... Passwords! And, you know what else??? It's also that greatest of holiday celebrations... US Cyber Security Month!In honor of US Cyber Security Month and the recently announced breach of 500 million Yahoo! account passwords and other info (while announced in 2016, the breach actually took place in 2014, and is not the same as the password breach they had in 2012! - yes, I know... it's hard to keep up!), I'm re-running a post I wrote in... wait for it... 2012! Not only is everything I wrote in that post 100% relevant today, but I even commented on that 2012 Yahoo! breach. The more things change, the more they stay the same. Happy Cyber Security Month!
-----------------
Passwords are a mess! A "good" password has these features:
- hard to create
- hard to remember
- hard to enter
- probably has to be changed as soon as you memorize it
- plus other inconsistent, random rules depending upon the site
Perfect!
Tuesday, August 9, 2016
News you Need Now (NNN)
These accounts are straightforward to set up. One thing you will need to do is go through an Identity Proofing process. That process asks you for some personal information that, in theory, only you should know. I list info about the irs.gov account creation process in this post.
Here is some info from the ssa.gov website:
You can create a my Social Security account if you’re age 18 or older, have a Social Security number, a valid email, a U.S. mailing address, and a cell phone that can receive text messages. You’ll need to provide some personal information to confirm your identity; you’ll be asked to choose a username and password; and then provide your cell phone number. You’ll then receive a security code via text that you will be required to enter when you first create an account. We’ll send your cell phone a new security code each time you log in with your username and password. The security code is part of our enhanced security feature to protect your personal information. Keep in mind that your cell phone provider's text message and data rates may apply.Now SSA has increased their security by offering two-factor authentication (2FA) on their site. We've written about 2FA a number of times in the past. SSA had said this was coming and now it's available.
I highly recommend that you create accounts on these sites and use 2FA where available. Here are the instructions for SSA. Here for the IRS. You can enable 2-factor authentication on the SSA site when you create your account. Here's a link to a previous post looking at other sites where 2FA is available. Double up wherever you can!
Labels:
2-factor,
account,
authentication,
fix,
identity,
identity proofing,
IRS,
LastPass,
NIST,
password,
social,
SSA,
vault,
vulnerability
Tuesday, May 31, 2016
YAPF (Yet Another Password Fail)
It's another week and password problems are in the news again!In the July 10, 2012 edition of this blog I wrote about the 2012 LinkedIn password breach. A month earlier, LinkedIn confirmed that a Russian attacker exploited a website vulnerability and downloaded 6.5 million encrypted passwords. You can read my old post to see why that's a problem.
Well, some gifts just keep on giving! Now, nearly 4 years later, a newly posted password dump from this same breach was advertised for sale on a dark web site. Except that information on over 167 million accounts were for sale! Of those, over 117 million had both the email and password. Slightly different math!!!
So why is this a problem? Actually it's an old problem and a new problem. Here are the key issues:
- Poor password choices - once again, this latest set of stolen passwords shows weak passwords - the top five found passwords were: 123456 (used on over 1 million accounts!), linkedin, password, 123456789 and 12345678
- Password reuse - since people have accounts on so many sites that need passwords, they tend to reuse them. The one million people who used 123456 as their LinkedIn password likely reuse that on other sites.
- Back to Work - are some of these same poor password choices being made on work systems? Or are some work passwords being used on sites like LinkedIn and potentially included in this breach?
Labels:
2-factor,
bad,
breach,
complexity,
encryption,
LinkedIn,
long,
news,
office,
password,
passwords,
reuse,
vault,
vulnerability,
work
Tuesday, May 17, 2016
National Betty White's Password Day
So apparently May 5, 2016 was World Password Day. Who knew? Not me... I missed this one. But Betty White didn't! Here's a great video:
It's not exactly clear to me how May 5 was chosen. I thought that was Cinco De Mayo! Apparently this is the 3rd annual World Password Day on the first Thursday in May. However, for years before that, Feb. 1 has been National Change Your Password Day.
I don't know about the date change but I definitely support the name change. The point here is that changing your password is not the key thing to do... I've written about this plenty of times before... when it comes to passwords, size matters! And multi-factor authentication is a great choice for your personal accounts.
But don't take it from me... Let's hear from Betty White!
It's not exactly clear to me how May 5 was chosen. I thought that was Cinco De Mayo! Apparently this is the 3rd annual World Password Day on the first Thursday in May. However, for years before that, Feb. 1 has been National Change Your Password Day.
I don't know about the date change but I definitely support the name change. The point here is that changing your password is not the key thing to do... I've written about this plenty of times before... when it comes to passwords, size matters! And multi-factor authentication is a great choice for your personal accounts.
But don't take it from me... Let's hear from Betty White!
Labels:
2-factor,
authentication,
holidays,
information,
infosec,
MFA,
password,
passwords,
security,
vault
Wednesday, March 9, 2016
How To Vault (part 2)
A few posts ago I wrote an overview of why you may want to use a password vault. This was in answer to reader question to provide more specifics about vaults.
We've talked about passwords and password vaults a number of times in the past including here, here and here.
If you haven't read part 1 of this discussion, it's here.
Hopefully you are now convinced that you should be using a password vault, also called a password manager. Now what...?
Products & Costs.
A few years ago there were just a few key players in this field, but the list of products has grown and there are a number of good choices. I'll briefly mention four of the best known and provide some links where you can get more info.
- LastPass - the basic product is free. It has most of the features you'd want, but the free version only supports use in a web browser. If you want a mobile app and to support password fills in mobile apps then you need to get LastPass Premium, $1/month or $12/year.
- DashLane - this is another very popular product. It's free to download and use on any device. However to have your passwords synced across devices, a very important feature, you need to use the Premium product which costs $40/year.
- KeePass - this is well known and solid product. It always has been free and is open source. It was designed to support an exportable vault. That means the primary way to use this tool is to keep it on a thumb drive and plug it in to the computer you use it on. That can be either handy or inconvenient depending upon how many computers you have and how you do your work. With KeePassX you can store the vault in free cloud storage like GoogleDrive, OneDrive, Dropbox, etc. and can connect with apps on mobile devices.
- 1Password - many people like this product and consider it easy to use. It's design is similar to KeePass in that it's basic use is on a single system and you can share your vault using free online cloud storage services. It's free to download and there is a one-time license fee. There is also mobile support and that requires a valid license.
Tuesday, February 9, 2016
How To Vault (part 1)
I was recently asked to provide more information on vaults. I think this is a memorable one :-).
Well, to be more precise, the question was about password vaults...
But why do we even need something like a password vault. There are a few reasons, and they have to do with the problems passwords pose:
Well, to be more precise, the question was about password vaults...
you've talked about password vaults and it seems like something should do, but I'm not sure how to start and it still seems a bit scary.That is a great question. We've talked about passwords and password vaults a number of times in the past including here, here and here.
But why do we even need something like a password vault. There are a few reasons, and they have to do with the problems passwords pose:
Tuesday, December 22, 2015
What's in Your Home Computer Security Toolkit?
It's always great to get questions and comments from readers. I received this question recently:
Thanks for the great question! You’ve got some good bases covered:
My home recipe is Windows Defender, Malwarebytes and KeePass. Is that a good approach or should I be thinking about adding something to my security toolkit in 2016?
Thanks for the great question! You’ve got some good bases covered:- Anti-malware (I also use defender)
- Malware removal (I also use malwarebytes), and
- A password vault (I use LastPass)
- Backups – you’ve got irreplacable pictures, tax returns, music and info of all sorts. There are many of good online products available that encrypt your data before cloud storage. I use CrashPlan, but there are many others. For extra bonus points, you can both backup one computer to another computer and to the cloud. That way you have more than one way to recover.
- Next, 2-factor authentication should be added for any sites and accounts where available. This nicely complements your password vault so that even if an attacker stole individual or multiple passwords, they still couldn't log in to your accounts without your phone or other second authentication device. I wrote about this recently.
Labels:
2-factor,
anti-malware,
authentication,
backups,
defender,
laptop,
malware,
password,
passwords,
portable,
router,
smartphone,
tablet,
tools,
updates,
vault,
windows
Monday, November 23, 2015
Do the Amazon 2-Step... Now!
It's not a new song or a new dance... Amazon has just announced 2-step, aka 2-factor or multi-factor, authentication for online logins! It's overdue but I'm glad it's here.
Here's an overview article and here's a great step-by-step with screen shots. I set this up for my account and it was really easy using my phone and Google Authenticator. You can also use text messaging, or setup text messaging as a backup method.
We've talked about 2-factor authentication in the past so I won't go deeply into it in this post. The important take-away is that Amazon now offers this service and you should use it!
Here's an overview article and here's a great step-by-step with screen shots. I set this up for my account and it was really easy using my phone and Google Authenticator. You can also use text messaging, or setup text messaging as a backup method.
The main reason that 2-factor is good and important is that it prevents an attacker, who has stolen your userid and password, from logging in as you. This is because they would need to have your smartphone in addition to the userid and password! (yes, there are other methods as well).
Labels:
2-factor,
Amazon,
authentication,
Facebook,
fob,
Google,
ID,
identification,
identity,
login,
Microsoft,
password,
passwords,
Paypal,
phone,
security,
smartphone
Tuesday, September 29, 2015
Do Strong, Unique Passwords Matter?
Labels:
authentication,
browser,
complexity,
cyber,
cybersecurity,
October,
online,
password,
passwords,
safety,
security,
strong,
unique,
vault,
video,
website
Tuesday, September 1, 2015
The XORcist (aka Get Rid of Bad Encryption)
I remember when the movie version of the Exorcist came out. I was in high school and it was probably the scariest, most graphic movie released by that time. Parents didn't want their kids to see it. There were all kinds of media discussions about the potential detrimental effects to roller-skating Linda Blair, who played the possessed Regan. It was a freaky movie, at least for it's day, though it was way surpassed in gore by the slasher movies of the 80s.
I recently read the book (well, you know... audiobook!). It's well written and I recommend it. But it is graphic, and there's plenty that wasn't in the movie.
Easily as scary is the way many systems and sites handle encryption! For those who don't get the title... XOR is a basic mathematical function that all computers can do easily and quickly. It's critical for computer operations, and is used in some encryption operations, but is not really a strong encryption method by itself. If you want to learn more about XOR, look here or here.
I've covered problems with passwords many times here. One of the problems that has allowed password breaches to work is poor encryption of the password file. XOR is not a strong encryption method!
So what does this all mean? I have two messages... one for programmers and one for everyone else.
Programmers. Don't invent your own encryption. There are fantastic, freely available encryption routines out there that you can use in your code. Or, your organization may already have standard encryption methods you can use. Bottom line is that 2000 years of mathematics has led us to some pretty solid encryption algorithms. Use them! Friends don't let friends use bad encryption! Here are some great references.
Everyone else. Password storage should use something we call a "one-way hash". Not a tasty dish, but a method of encrypting data so it can't be decrypted. That means that no one should be able to tell you your password! So, if you call customer support or the help desk because you forgot your password, and they can tell you your actual password... run!
Can you think of any examples of bad encryption? Do you know of any websites that can show you a forgotten password?
I recently read the book (well, you know... audiobook!). It's well written and I recommend it. But it is graphic, and there's plenty that wasn't in the movie.
Easily as scary is the way many systems and sites handle encryption! For those who don't get the title... XOR is a basic mathematical function that all computers can do easily and quickly. It's critical for computer operations, and is used in some encryption operations, but is not really a strong encryption method by itself. If you want to learn more about XOR, look here or here.I've covered problems with passwords many times here. One of the problems that has allowed password breaches to work is poor encryption of the password file. XOR is not a strong encryption method!
So what does this all mean? I have two messages... one for programmers and one for everyone else.
Programmers. Don't invent your own encryption. There are fantastic, freely available encryption routines out there that you can use in your code. Or, your organization may already have standard encryption methods you can use. Bottom line is that 2000 years of mathematics has led us to some pretty solid encryption algorithms. Use them! Friends don't let friends use bad encryption! Here are some great references.
Everyone else. Password storage should use something we call a "one-way hash". Not a tasty dish, but a method of encrypting data so it can't be decrypted. That means that no one should be able to tell you your password! So, if you call customer support or the help desk because you forgot your password, and they can tell you your actual password... run!Can you think of any examples of bad encryption? Do you know of any websites that can show you a forgotten password?
Subscribe to:
Posts (Atom)





