Tuesday, May 31, 2016

YAPF (Yet Another Password Fail)

   It's another week and password problems are in the news again!

   In the July 10, 2012 edition of this blog I wrote about the 2012 LinkedIn password breach.  A month earlier, LinkedIn confirmed that a Russian attacker exploited a website vulnerability and downloaded 6.5 million encrypted passwords.  You can read my old post to see why that's a problem.

   Well, some gifts just keep on giving!  Now, nearly 4 years later, a newly posted password dump from this same breach was advertised for sale on a dark web site.  Except that information on over 167 million accounts were for sale!  Of those, over 117 million had both the email and password.  Slightly different math!!!

   So why is this a problem?  Actually it's an old problem and a new problem.  Here are the key issues:
  • Poor password choices - once again, this latest set of stolen passwords shows weak passwords - the top five found passwords were: 123456 (used on over 1 million accounts!), linkedin, password, 123456789 and 12345678
  • Password reuse - since people have accounts on so many sites that need passwords, they tend to reuse them.  The one million people who used 123456 as their LinkedIn password likely reuse that on other sites.
  • Back to Work - are some of these same poor password choices being made on work systems?  Or are some work passwords being used on sites like LinkedIn and potentially included in this breach?

Tuesday, May 17, 2016

National Betty White's Password Day

   So apparently May 5, 2016 was World Password Day.  Who knew?  Not me... I missed this one.  But Betty White didn't!  Here's a great video:


   It's not exactly clear to me how May 5 was chosen.  I thought that was Cinco De Mayo!  Apparently this is the 3rd annual World Password Day on the first Thursday in May.  However, for years before that, Feb. 1 has been National Change Your Password Day.

   I don't know about the date change but I definitely support the name change.  The point here is that changing your password is not the key thing to do... I've written about this plenty of times before... when it comes to passwords, size matters!  And multi-factor authentication is a great choice for your personal accounts.

   But don't take it from me... Let's hear from Betty White!


Tuesday, May 3, 2016

Secrets Your Phone Told Me

   You may remember that earlier this year we were all talking about the standoff between the FBI San Bernadino attack.  This specific problem was "solved" when the FBI said they were able to decrypt the phone and no longer needed Apple's help.  The assumption by many is that the FBI purchased an exploit used to break into the phone.
and Apple about the decryption of an iPhone used by one of the shooters in the

   This leads us to an important consideration and question... can any phone be hacked?  Is any information on your smartphone really private?

   We have become completely dependent upon our phones.  According to a 2015 Pew Research Center study, in the US over two-thirds of the population uses a smartphone.  We keep all of our personal information on there: passwords and accounts, photos and videos, credit card data, tax data; we shop and set many preferences (travel, food, dating, real estate); we track our workouts, our weight our food and all our movements.  Today's smartphone is the key to far more information about you than you can imagine!

   We can, of course, watch TV on our phone.  And on 4/17/2016, 60 Minutes aired a show about smartphone security and privacy.  You can view it here.

   In the episode, they talked about the SS7 (Signaling System 7) protocol and how it works.  SS7 was designed in 1975 and it is the protocol that allows phone systems to pass calls between them.  For mobile, it handles maintaining connections as you move between cell towers, for example as you are driving down the road (using hands-free calling of course! :-).  This particular exploit is not new at all.  In fact, this has been a topic at the Black Hat Briefings and other security conferences for years.

   But all this aside, there is no need for exploits or vulnerabilities to track people or glean personal information through their phones.  Disclosing this information is simply how phones and apps work!  Let me explain...

Tuesday, April 19, 2016

Ad Where?

   The first website debuted on Dec. 20, 1990 at CERN in Switzerland.  And less than four years later, the first banner ad.  The idea was simple... if people are reading information on a website, why not hit them with an ad?  Media has traditionally been either for-pay or ad-supported and the model for the web included that.  Of course, back then people had no idea the extent to which other screens like laptops, tablets and smartphones, and binge-watching would displace traditional TV watching.

   And shortly after website ads arrived, so did the malware. Ad-ware, also called "malvertising", was born.

   There are a few different ways website ads can cause problems:
  • virus code in the ad itself - so clicking on the ad downloads or executes the malware
  • malicious code that executes based on a mouse action - such as clicking on a flash animation or even just moving your mouse over an ad (called a "drive-by download")
  • a link in the ad brings you to a different page that can have malware, asks for personal information or exploits your browser to grab information from another tab (kind of like phishing)
   You may ask... why would someone allow a virus in an ad on their site?  That's a great question.   The issue is that most sites don't have a direct relationship with the people creating the ads.  The way it typically works is that sites sell space on their pages to ad brokers, who resell that space either to someone wanting to place an ad, or even to other ad brokers.  And often the ads rotate.  It becomes pretty easy for crooks to insert malware into these ad spaces without detection.

   This led to the creation of ad blockers.  These are programs that work in your browser to block content from the 3rd party ad brokers.  There was a big controversy about this in 2015.  On one hand, websites that offer free content need to have a way to monetize.  On the other hand, web and banner ads are annoying, collect our information, and can contain malware.  Some businesses block ads on corporate systems as a way to cut down on malware... and it works.

   To fight back, some sites block people who block ads!

   And that's where things get interesting.

    Let's look at Forbes.com for example.  Many websites simply show their ads along with each page.  If the ads are blocked, then those parts of the pages just don't load, or show a broken image icon.  But when you go to the Forbes website, you first see a welcome page that counts down until you can click to the main page.  While that is happening, the page loads hundreds of those 3rd party ad sites.

   And earlier this year, the Forbes site was serving malware through ads!

   So there's the bind... allow sites to display their ads, including those full sites that only display if ads are allowed; or open the enterprise to malware!

   But shouldn't the responsibility for this malware be with the website that displays the ads?  Shouldn't they test to make sure there isn't executable code in those ads?  I think so.

   I also understand that sites display content that is worth something and they deserve to be compensated.

   There are some compromises.  Some sites ask you to register to see additional content.  You are "paying" by providing information about yourself that they can sell.  Some sites charge nominal subscription fees (some sites charge high subscription fees!).

   There is perhaps some middle ground with Google Contributor.  With this consumer service you pay a nominal monthly fee.  Then google distributes that to sites based upon your usage patterns.

   What are your thoughts?  Is there a middle ground?  Should consumers have to pay for content?  Do we need to be bombarded with ads?  And who should be responsible when sites serve up malware or malicious links?

Tuesday, April 5, 2016

It's Not If, but When

   Have you heard???  2015 was the "Year of the Breach".  Of course, 2014 was the year of the breach.  And, 2013 was the year of the breach.

   2016 is shaping up to be quite a year as well.

   Of course, when we talk about breaches, we're usually talking about someone "stealing" data.  It's not actually "stolen" because you still have it.  It's more accurate to say that in a breach the data is exfiltrated.  This is also called an attack on the confidentiality of the data.

   In security, we talk about the C-I-A triangle, Confidentiality, Integrity and Availability.  Confidentiality is about the secrecy of data.  Integrity is about the accuracy of data.  Availability is about being able to properly access data when it's needed.  A well-rounded security program needs to consider all these aspects.

   What is somewhat different this year is the crypto-/ransom-ware attacks.  In these cases, the attack is a virus that typically gets in as an email attachment.  Someone opens the attachment and the virus executes.  It finds files in network shared directories and encrypts them.  Now, encryption is often a good thing, but that's when you (or your organization) has the decryption key.  In a crypto-ware attack, only the attacker has the key.  That's a problem.  It becomes ransom-ware when the attacker offers to provide the key for a "small" consulting fee, usually paid via the anonymous crypto-currency, bitcoin.
   These are basically attacks to the availability of data.  We've seen instances of hospitals or other organizations temporarily shutting down as a result.  These could also be considered attacks to the integrity of the data - though I think we have not yet seen the real integrity attacks... and they are coming.

Tuesday, March 22, 2016

Credit Cards Calling

   So I'm driving down the road, out of state but heading toward home, when I received a text message.  The message said it was from a credit card company asking me whether a charge was legit.  I did not recognize this charge!

   Receiving this kind of message may concern some of you, but for me this is awesome!  The credit card companies have, by necessity, become really good at detecting fraud.  That could be because of the huge amount of credit card fraud out there!  Fraud is big money and it's both in our, and the credit card companies', best interests to try to get a handle on it.

   Detecting this kind of fraud is basically about big data analytics and anomaly detection.  That's just a fancy way of saying it's kind of like finding a needle in a stack of needles!  It's complex and expensive.  Luckily(?) credit card companies have lots of money!  They have to figure out what might be fraud so they can appropriately allow or block transactions.  If they allow too much then there can be a lot of fraud.  If they block too much then there can be unhappy customers.

   Back to our story... the charge was not legit and I responded "2".  As you can see in the image, the credit card company said they would call me.  I did receive a call and was immediately put into a hold loop!  Wait...

   If I did speak to someone they would first have asked me to identify myself.  However, they called me.  I don't actually know who they are!  This whole event could have been a scam to collect personal information from me.  Had someone connected with me that way, I would not have given them any identifying information.  They called me... at my registered (with them) phone number.  They already know who I am.  They need to positively identify themselves to me!

Wednesday, March 9, 2016

How To Vault (part 2)

   A few posts ago I wrote an overview of why you may want to use a password vault.  This was in answer to reader question to provide more specifics about vaults.

   We've talked about passwords and password vaults a number of times in the past including here, here and here.

   If you haven't read part 1 of this discussion, it's here.

   Hopefully you are now convinced that you should be using a password vault, also called a password manager.  Now what...?

Products & Costs.
   A few years ago there were just a few key players in this field, but the list of products has grown and there are a number of good choices.  I'll briefly mention four of the best known and provide some links where you can get more info.
  • LastPass - the basic product is free.  It has most of the features you'd want, but the free version only supports use in a web browser.  If you want a mobile app and to support password fills in mobile apps then you need to get LastPass Premium, $1/month or $12/year.
  • DashLane - this is another very popular product.  It's free to download and use on any device.  However to have your passwords synced across devices, a very important feature, you need to use the Premium product which costs $40/year.
  • KeePass - this is well known and solid product.  It always has been free and is open source.  It was designed to support an exportable vault.  That means the primary way to use this tool is to keep it on a thumb drive and plug it in to the computer you use it on.  That can be either handy or inconvenient depending upon how many computers you have and how you do your work.  With KeePassX you can store the vault in free cloud storage like GoogleDrive, OneDrive, Dropbox, etc. and can connect with apps on mobile devices.
  • 1Password - many people like this product and consider it easy to use.  It's design is similar to KeePass in that it's basic use is on a single system and you can share your vault using free online cloud storage services.  It's free to download and there is a one-time license fee.  There is also mobile support and that requires a valid license.
   Here are a few review articles that go into more detail about the features of these, and some other, products.