It's US Cyber Security Month and the key themes I've been discussing here for years are very bit as relevant today. In honor of Cyber Security Month I'm re-running a post from 2016. The more things change, the more they stay the same. Happy Cyber Security Month!
Well, I was trying for something catchy like Stop, Drop and Roll. That's a saying we learned in school, back in the day, for what you should do if your clothes catch on fire.
Fortunately, it seems like everyone has heard that saying and it rolls off the tongue.
Unfortunately, my three word phrase Patch, Vault and Fob, is not nearly as catchy.
Fortunately, the odds of your clothes catching on fire is low.
Unfortunately, the odds of your software, browsers or accounts being compromised is very high.
A couple of weeks ago the internet was hit with the highly impact-full and publicized distributed denial of service (DDoS) attack on Dyn, a DNS provider. I won't go into the details here but I think I will cover DDoS in a future post. Anyway, shortly after that I was chatting with someone at a dinner who asked me about this attack, internet safety in general and what they could do. To keep it simple and because, as a math person I like things in 3's!, I provided these 3 simple (well, maybe straight-forward is more accurate) things that absolutely everyone should do at home...
A place to talk about information security, Internet safety and, of course... coffee!
Thoughtful, sometimes controversial, but not following the crowd unless I'm in line at the coffee shop.
Showing posts with label authentication. Show all posts
Showing posts with label authentication. Show all posts
Tuesday, October 31, 2017
Tuesday, August 8, 2017
You Gotta Be You
I just received an update from the Social Security Administration. Yes, it was real! :-) It was a reminder to log in to the SSA website to check my information online. That also made me think about advice I've written about in the past... it's critical that you connect and establish your presence on critical government websites before someone else can create an account in your name.
Here's a rewind of a 2016 post with all the information...
I recently received a letter from the SSA (Social Security Administration). It provided instructions for me to finish setting up my online account. As I've written in the past you can, and need to, create personal accounts on the SSA and IRS websites. The key issue is that you need to reserve and establish your identity on these critical government websites before someone else does it for you! This is ID Fraud is still a big issue.
These accounts are straightforward to set up. One thing you will need to do is go through an Identity Proofing process. That process asks you for some personal information that, in theory, only you should know. I list info about the irs.gov account creation process in this post.
Here is some info from the ssa.gov website:
I highly recommend that you create accounts on these sites and use 2FA where available. Here are the instructions for SSA. Here for the IRS. You can enable 2-factor authentication on the SSA site when you create your account. Here's a link to a previous post looking at other sites where 2FA is available. Double up wherever you can!
Here's a rewind of a 2016 post with all the information...
These accounts are straightforward to set up. One thing you will need to do is go through an Identity Proofing process. That process asks you for some personal information that, in theory, only you should know. I list info about the irs.gov account creation process in this post.
Here is some info from the ssa.gov website:
You can create a my Social Security account if you’re age 18 or older, have a Social Security number, a valid email, a U.S. mailing address, and a cell phone that can receive text messages. You’ll need to provide some personal information to confirm your identity; you’ll be asked to choose a username and password; and then provide your cell phone number. You’ll then receive a security code via text that you will be required to enter when you first create an account. We’ll send your cell phone a new security code each time you log in with your username and password. The security code is part of our enhanced security feature to protect your personal information. Keep in mind that your cell phone provider's text message and data rates may apply.Now SSA has increased their security by offering two-factor authentication (2FA) on their site. We've written about 2FA a number of times in the past. SSA had said this was coming and now it's available.
I highly recommend that you create accounts on these sites and use 2FA where available. Here are the instructions for SSA. Here for the IRS. You can enable 2-factor authentication on the SSA site when you create your account. Here's a link to a previous post looking at other sites where 2FA is available. Double up wherever you can!
Labels:
2-factor,
account,
authentication,
fix,
identity,
identity proofing,
IRS,
password,
social,
SSA,
vault,
vulnerability
Tuesday, April 25, 2017
World Password Day and Teen Power
Thurs May 4, 2017 is World Password Day! I know that's coming up fast, but don't worry, you stillhave time to plan your celebration. No, that's not the day when you share your password with the world. Nor is it about changing your bank password from 123456 to 1234567.
I've written about this in the past. World Password Day is a day to learn and it's yet another opportunity to take a look at what is protecting your personal information, your financial information, your medical information as well as your internet presence and reputation. Most passwords provide a thin veil of protection
On World Password Day, we should at the 4 main problems we can very easily fix:- People choose weak or easily guessable passwords - the simple fix is to choose better passwords! As I've said many times in the past, when it comes to passwords, size matters! Make 'em long. But even if you choose a good password...
- Passwords get reused among sites - this is a major problem because the attackers will try stolen passwords at other sites. And it works. So choose a unique password for every site on which you have an account. But...
- We can't remember all our passwords - so, as we've discussed in the past, use a password vault. The vault is a program that will help you choose great passwords, recall those passwords and protect them. But sometimes that's not enough because...
- Even well-chosen passwords can be guessed or hacked - so for extra protection use two-factor authentication (also called multi-factor authentication). Typically this means using an app on your smartphone as part of the login process. That means, to break into your account, an attacker would need both your (long, strong) password AND your smartphone. That's hard for the attacker to do. And using multi-factor is easy! Setting up 2-factor authentication is easier than ever before and is in use on many mainstream sites including Google, Facebook and Twitter. Here's some info on sites offering 2-factor authentication.

The WPD website has some high level guidance on each of these as well as those great Betty White videos!
And if those all aren't enough reasons to move to 2-factor authentication, now... that pinnacle of journalism... Teen Vogue, has put out a really good article on the subject! You can read it here.
In addition to really good coverage of 2-factor methods and websites, the article also goes into more advanced topics like the use of a physical fob called a Yubikey.What is really significant is that this article is directed at a population who both grew up with technology and is used to sharing everything. The key message is that there are good reasons for protecting your information and reputation, even if you don't yet have financial assets or a job.
So, are you ready to take the World Password Day challenge? Start slowly. Get a password vault and start with your most important sites: banks, insurance, investment and social media. Change the passwords to unique long strong ones.
Tuesday, November 8, 2016
Patch, Vault 'n Fob
Well, I was trying for something catchy like Stop, Drop and Roll. That's a saying we learned in school, back in the day, for what you should do if your clothes catch on fire.
Fortunately, it seems like everyone has heard that saying and it rolls off the tongue.
Unfortunately, my three word phrase Patch, Vault and Fob, is not nearly as catchy.
Fortunately, the odds of your clothes catching on fire is low.
Unfortunately, the odds of your software, browsers or accounts being compromised is very high.
A couple of weeks ago the internet was hit with the highly impact-full and publicized distributed denial of service (DDoS) attack on Dyn, a DNS provider. I won't go into the details here but I think I will cover DDoS in a future post. Anyway, shortly after that I was chatting with someone at a dinner who asked me about this attack, internet safety in general and what they could do. To keep it simple and because, as a math person I like things in 3's!, I provided these 3 simple (well, maybe straight-forward is more accurate) things that absolutely everyone should do at home...
Fortunately, it seems like everyone has heard that saying and it rolls off the tongue.
Unfortunately, my three word phrase Patch, Vault and Fob, is not nearly as catchy.
Fortunately, the odds of your clothes catching on fire is low.
Unfortunately, the odds of your software, browsers or accounts being compromised is very high.
A couple of weeks ago the internet was hit with the highly impact-full and publicized distributed denial of service (DDoS) attack on Dyn, a DNS provider. I won't go into the details here but I think I will cover DDoS in a future post. Anyway, shortly after that I was chatting with someone at a dinner who asked me about this attack, internet safety in general and what they could do. To keep it simple and because, as a math person I like things in 3's!, I provided these 3 simple (well, maybe straight-forward is more accurate) things that absolutely everyone should do at home...
Labels:
2-factor,
authentication,
browser,
fob,
LastPass,
multi-factor,
password,
passwords,
patch,
software,
tools,
vault
Tuesday, August 9, 2016
News you Need Now (NNN)
These accounts are straightforward to set up. One thing you will need to do is go through an Identity Proofing process. That process asks you for some personal information that, in theory, only you should know. I list info about the irs.gov account creation process in this post.
Here is some info from the ssa.gov website:
You can create a my Social Security account if you’re age 18 or older, have a Social Security number, a valid email, a U.S. mailing address, and a cell phone that can receive text messages. You’ll need to provide some personal information to confirm your identity; you’ll be asked to choose a username and password; and then provide your cell phone number. You’ll then receive a security code via text that you will be required to enter when you first create an account. We’ll send your cell phone a new security code each time you log in with your username and password. The security code is part of our enhanced security feature to protect your personal information. Keep in mind that your cell phone provider's text message and data rates may apply.Now SSA has increased their security by offering two-factor authentication (2FA) on their site. We've written about 2FA a number of times in the past. SSA had said this was coming and now it's available.
I highly recommend that you create accounts on these sites and use 2FA where available. Here are the instructions for SSA. Here for the IRS. You can enable 2-factor authentication on the SSA site when you create your account. Here's a link to a previous post looking at other sites where 2FA is available. Double up wherever you can!
Labels:
2-factor,
account,
authentication,
fix,
identity,
identity proofing,
IRS,
LastPass,
NIST,
password,
social,
SSA,
vault,
vulnerability
Tuesday, May 17, 2016
National Betty White's Password Day
So apparently May 5, 2016 was World Password Day. Who knew? Not me... I missed this one. But Betty White didn't! Here's a great video:
It's not exactly clear to me how May 5 was chosen. I thought that was Cinco De Mayo! Apparently this is the 3rd annual World Password Day on the first Thursday in May. However, for years before that, Feb. 1 has been National Change Your Password Day.
I don't know about the date change but I definitely support the name change. The point here is that changing your password is not the key thing to do... I've written about this plenty of times before... when it comes to passwords, size matters! And multi-factor authentication is a great choice for your personal accounts.
But don't take it from me... Let's hear from Betty White!
It's not exactly clear to me how May 5 was chosen. I thought that was Cinco De Mayo! Apparently this is the 3rd annual World Password Day on the first Thursday in May. However, for years before that, Feb. 1 has been National Change Your Password Day.
I don't know about the date change but I definitely support the name change. The point here is that changing your password is not the key thing to do... I've written about this plenty of times before... when it comes to passwords, size matters! And multi-factor authentication is a great choice for your personal accounts.
But don't take it from me... Let's hear from Betty White!
Labels:
2-factor,
authentication,
holidays,
information,
infosec,
MFA,
password,
passwords,
security,
vault
Tuesday, December 22, 2015
What's in Your Home Computer Security Toolkit?
It's always great to get questions and comments from readers. I received this question recently:
Thanks for the great question! You’ve got some good bases covered:
My home recipe is Windows Defender, Malwarebytes and KeePass. Is that a good approach or should I be thinking about adding something to my security toolkit in 2016?
Thanks for the great question! You’ve got some good bases covered:- Anti-malware (I also use defender)
- Malware removal (I also use malwarebytes), and
- A password vault (I use LastPass)
- Backups – you’ve got irreplacable pictures, tax returns, music and info of all sorts. There are many of good online products available that encrypt your data before cloud storage. I use CrashPlan, but there are many others. For extra bonus points, you can both backup one computer to another computer and to the cloud. That way you have more than one way to recover.
- Next, 2-factor authentication should be added for any sites and accounts where available. This nicely complements your password vault so that even if an attacker stole individual or multiple passwords, they still couldn't log in to your accounts without your phone or other second authentication device. I wrote about this recently.
Labels:
2-factor,
anti-malware,
authentication,
backups,
defender,
laptop,
malware,
password,
passwords,
portable,
router,
smartphone,
tablet,
tools,
updates,
vault,
windows
Monday, November 23, 2015
Do the Amazon 2-Step... Now!
It's not a new song or a new dance... Amazon has just announced 2-step, aka 2-factor or multi-factor, authentication for online logins! It's overdue but I'm glad it's here.
Here's an overview article and here's a great step-by-step with screen shots. I set this up for my account and it was really easy using my phone and Google Authenticator. You can also use text messaging, or setup text messaging as a backup method.
We've talked about 2-factor authentication in the past so I won't go deeply into it in this post. The important take-away is that Amazon now offers this service and you should use it!
Here's an overview article and here's a great step-by-step with screen shots. I set this up for my account and it was really easy using my phone and Google Authenticator. You can also use text messaging, or setup text messaging as a backup method.
The main reason that 2-factor is good and important is that it prevents an attacker, who has stolen your userid and password, from logging in as you. This is because they would need to have your smartphone in addition to the userid and password! (yes, there are other methods as well).
Labels:
2-factor,
Amazon,
authentication,
Facebook,
fob,
Google,
ID,
identification,
identity,
login,
Microsoft,
password,
passwords,
Paypal,
phone,
security,
smartphone
Tuesday, November 10, 2015
Hospital Held Hostage
A number of people alerted me that a recent episode of CSI:Cyber, which aired on 11/1/15, had as its theme a cyber attack on a hospital. The episode was entitled "hack E.R." (see what they did there??? :-) )
The episode begins with an ominous image showing up on computer screens and all systems in a fictional hospital being under the control of an online attacker. They threaten to kill a victim every four hours if not paid a ransom. They then kill a victim by causing an infusion pump to deliver a fatal dose of morphine while preventing the patient's heart monitor from alarming.
We then follow the CSI:Cyber team and the hospital staff as they try to solve the mystery and track down and stop the attacker. I won't give a full synopsis nor a review. You can find some of that here and here (spoiler alert - these linked articles do give away the ending).
Let's review what was potentially real and some of the deficiencies of the episode. First the realistic.
The episode begins with an ominous image showing up on computer screens and all systems in a fictional hospital being under the control of an online attacker. They threaten to kill a victim every four hours if not paid a ransom. They then kill a victim by causing an infusion pump to deliver a fatal dose of morphine while preventing the patient's heart monitor from alarming.
We then follow the CSI:Cyber team and the hospital staff as they try to solve the mystery and track down and stop the attacker. I won't give a full synopsis nor a review. You can find some of that here and here (spoiler alert - these linked articles do give away the ending).
Let's review what was potentially real and some of the deficiencies of the episode. First the realistic.
Labels:
attack,
authentication,
CSI,
cyber,
cybersecurity,
devices,
episode,
hacker,
hacktivism,
hardware,
healthcare,
hospital,
insider,
internet,
IoT,
medical,
network,
TV,
vulnerability
Tuesday, September 29, 2015
Do Strong, Unique Passwords Matter?
Labels:
authentication,
browser,
complexity,
cyber,
cybersecurity,
October,
online,
password,
passwords,
safety,
security,
strong,
unique,
vault,
video,
website
Tuesday, October 21, 2014
Dropbox Wasn't Hacked... This Time!
I'm sure that many of you have read the news about an apparent attack, and subsequent account breach at Dropbox this past week. There have been conflicting reports flying around, but Dropbox's own blog points out what appears to be the truth... Dropbox wasn't hacked.The story is that apparently the attackers got user IDs and passwords from attacks on other applications. They then tried these same credentials on a number of internet sites, including Dropbox. You can read the Dropbox blog post here.
This is a typical attack scenario, as I've discussed before. Among the value of stealing a password file from a site or organization is that people unfortunately reuse their IDs and passwords on other sites. This is because it's difficult to remember all those passwords! I won't go into that issue because I've covered it plenty of times in the past.
In this case, like many others, the attackers simply try the IDs and passwords on other sites. It's almost guaranteed that they will get some logins that work. That is apparently what happened here.
So... Dropbox wasn't hacked... this time! Of course, there have been a number of successful breaches of Dropbox in the past!
More on that in a moment, but I want to make a quick editorial comment on the use of the term "hacked".
Friday, April 11, 2014
Heartbleedbreaker
Well, I had no intention of talking about this topic! But there is so much confusion and misinformation out there. And the mainstream media is really having a field day.
So I'm jumping in with some facts, a few opinions, and some action steps that you be taking now.
First we'll look at the consumer/user side of things. Then the organization side. Finally, I'll talk a bit more about what this is and what this isn't.
If you use the Internet and enter any personal or financial information on any website, then you might be effected by this issue. To find out, follow these steps:
So I'm jumping in with some facts, a few opinions, and some action steps that you be taking now.
First we'll look at the consumer/user side of things. Then the organization side. Finally, I'll talk a bit more about what this is and what this isn't.
If you use the Internet and enter any personal or financial information on any website, then you might be effected by this issue. To find out, follow these steps:
Labels:
account,
authentication,
exploit,
Heartbleed,
open_source,
Open_SSL,
password,
passwords,
secure,
security,
ssl,
tls,
vulnerability,
websites
Tuesday, February 25, 2014
No, You Can't Have Local Admin!
If you have responsibility for security and/or access management for an organization, then there is a "simple" request that you have received, and will always receive... Users request local admin access to systems.
Most of you know what I mean. I'm referring to the local administrator or root account on a system. When a person has local admin, they can access any part of the system, change or disable settings (including deactivating anti-malware or other security software), and, perhaps most importantly, install and run any software. This last item is probably the primary reason people request this level of access.
We're talking about Minimum Necessary... the idea that everyone should have exactly the level of access needed to do their job, and no more. In most, if not all, organizations, far more people have local admin than really need it.
Security vendor Avecto recently released a new study showing that over 90% of the most serious vulnerabilities in Microsoft software products in 2013 could have been mitigated by simply removing administrator rights. Put another way, this means that only your systems administrators were vulnerable to all of the most critical Microsoft software vulnerabilities! And these are the people who have the most access on your systems! Here are a two good articles on the subject and here is a link to the full report.
Let's break this down...
Most of you know what I mean. I'm referring to the local administrator or root account on a system. When a person has local admin, they can access any part of the system, change or disable settings (including deactivating anti-malware or other security software), and, perhaps most importantly, install and run any software. This last item is probably the primary reason people request this level of access.
We're talking about Minimum Necessary... the idea that everyone should have exactly the level of access needed to do their job, and no more. In most, if not all, organizations, far more people have local admin than really need it.
Security vendor Avecto recently released a new study showing that over 90% of the most serious vulnerabilities in Microsoft software products in 2013 could have been mitigated by simply removing administrator rights. Put another way, this means that only your systems administrators were vulnerable to all of the most critical Microsoft software vulnerabilities! And these are the people who have the most access on your systems! Here are a two good articles on the subject and here is a link to the full report.
Let's break this down...
Tuesday, February 11, 2014
Bad Policies = Bad Passwords
- good passwords are hard to remember, and;
- passwords you can remember are easy for attackers to guess.
Many organizations allow you to pick poor passwords on their websites by enforcing few or weak password construction requirements.We call these password policies, and these specify things like: how long the password can be; the minimum length it must be; what kinds of characters can or must be used; if the password needs to change, and; if there are some passwords that can't be chosen.
Tuesday, December 10, 2013
Password Problems Again
So here we go again... more problems with breached passwords. But this time there is a different wrinkle.
By now, most of you have probably heard about the recent discovery of hackers getting around 2 million userid's and passwords to online services like Facebook, Gmail, Yahoo, LinkedIn and Twitter. Notable on the list of sites is ADP, the payroll processor.
It's "just" 2 million sets of ID's and passwords. That's not really big news these days when the new record of over 152 million stolen passwords was recently set by the Adobe breach. But there is a difference here. For most of the big password breaches, the service provider's website or password store is hacked. Then the encrypted password file or database is downloaded. The attackers can take their time analyzing the encrypted data to come up with userid's and passwords. This work is made easier because so many sites use poorly implemented encryption. And some sites use no encryption at all.
But that's not what happened here.
This time the passwords were stolen from the users of the sites. That's you and me (well... hopefully not you or me!).
By now, most of you have probably heard about the recent discovery of hackers getting around 2 million userid's and passwords to online services like Facebook, Gmail, Yahoo, LinkedIn and Twitter. Notable on the list of sites is ADP, the payroll processor.
It's "just" 2 million sets of ID's and passwords. That's not really big news these days when the new record of over 152 million stolen passwords was recently set by the Adobe breach. But there is a difference here. For most of the big password breaches, the service provider's website or password store is hacked. Then the encrypted password file or database is downloaded. The attackers can take their time analyzing the encrypted data to come up with userid's and passwords. This work is made easier because so many sites use poorly implemented encryption. And some sites use no encryption at all.
But that's not what happened here.
This time the passwords were stolen from the users of the sites. That's you and me (well... hopefully not you or me!).
Labels:
2-factor,
account,
Adobe,
anti-malware,
authentication,
breach,
browser,
computer,
crack,
encryption,
internet,
login,
malware,
password,
passwords,
patching,
pc
Tuesday, August 13, 2013
More Problems with Passwords???
keep coming up again and again.
Passwords, and in particular their use for online authentication, is a mess. I've written about this a number of times including here, here and here. My advice for online use of passwords has been the same all along. I've always said:
- choose good long passwords (long sentences are just fine)
- use a password vault, and
- use a unique password at each online site.
- (bonus) use 2-factor authentication for online sites when available (and complain if it isn't available yet!)
Tuesday, July 16, 2013
Are You the Customer... or the Product?
I regularly speak with people about Internet/Online Safety. One message I frequently give about free online services is:
I'm a big fan of free online services, but it's important that people realize what's going on. It starts with the privacy policy, which explains how an online service intends to use your data and information about you.
But I want to talk about cloud storage services. These services allow you to backup files, sync files between systems and devices, and have files available from anywhere. How are your files protected?
You're not the Customer... You're the Product.We often see people upset about changes in social networks like Facebook. Folks complain about "customer service", not realizing that they are not the customer! It's often the advertisers, or other backers, who are the real customers. And what those customers want is information... about the users of the service.
I'm a big fan of free online services, but it's important that people realize what's going on. It starts with the privacy policy, which explains how an online service intends to use your data and information about you.
But I want to talk about cloud storage services. These services allow you to backup files, sync files between systems and devices, and have files available from anywhere. How are your files protected?
Tuesday, June 4, 2013
How crackers ransack passwords - Sort of...
I am not trying to make this the password rant blog. But we just can't go a full week without more news about password problems!
Last week the excellent tech new site, Ars Technica, did a feature article in which they had first a journalist, then three different password hacking experts, try to decrypt passwords from an encrypted password file. They were all quite successful... frighteningly so.
Steve Gibson discussed this for a bit in Security Now episode 406.
But, I think there were some critical flaws in the test. And there were also some excellent lessons.
I'll comment on the article using the sandwich method, starting with what was good...
Last week the excellent tech new site, Ars Technica, did a feature article in which they had first a journalist, then three different password hacking experts, try to decrypt passwords from an encrypted password file. They were all quite successful... frighteningly so.
Steve Gibson discussed this for a bit in Security Now episode 406.
But, I think there were some critical flaws in the test. And there were also some excellent lessons.
I'll comment on the article using the sandwich method, starting with what was good...
Tuesday, May 28, 2013
Twitter 1-and-a-half Factor Authentication
As you may have read, and hopefully enabled, Twitter added a 2-factor authentication capability last week.
If you haven't yet turned this on, here's how. Log in to Twitter; select Settings; select Mobile; add and activate your phone. Here are the detailed instructions for adding your phone number. To enable 2-factor authentication, select Account, then check the box labeled: Account security
Here's the good news... as I've discussed in the past, I am a fan of using some kind of 2-factor auth for website authentication. I also like the use of a smartphone for delivering that one-time-use PIN or code. While we still have a digital divide in the US, most people do have a cell phone, and most of those have a smartphone.
But there are some issues.
If you haven't yet turned this on, here's how. Log in to Twitter; select Settings; select Mobile; add and activate your phone. Here are the detailed instructions for adding your phone number. To enable 2-factor authentication, select Account, then check the box labeled: Account security
Here's the good news... as I've discussed in the past, I am a fan of using some kind of 2-factor auth for website authentication. I also like the use of a smartphone for delivering that one-time-use PIN or code. While we still have a digital divide in the US, most people do have a cell phone, and most of those have a smartphone.
But there are some issues.
Tuesday, May 7, 2013
So Long and Thanks for All the Passwords!
We have heard of many similar instances over the past few years. I've written about this in previous posts and will be giving a talk at Secure360 in St. Paul, MN in a couple of weeks talking about authentication and passwords.
In their defense, Living Social did do a couple of things well. First of all, fortunately, they did store only encrypted passwords. Unfortunately many organizations don't. Unfortunately they used an older, weaker encryption algorithm. And, of course, unfortunately they got breached and had the file downloaded.
Subscribe to:
Posts (Atom)


