Showing posts with label passwords. Show all posts
Showing posts with label passwords. Show all posts

Tuesday, 12 April 2011

Wireless Security – Choosing the Best Wi-Fi Password

Running through some tests for an upcoming wireless security book and it really brings home the importance of choosing a good password for your Wi-Fi network.

Currently, the best security setting for your home or office Wi-Fi is WPA2.

WPA2 Enterprise is the best if your organization supports it, but WPA2 Personal is great for home and small offices.

Do not use WEP. It has been cracked a long time ago, and an attacker does not even have to crack it, the WEP key can be passed just like NTLM passwords.

The most common technique used for WPA/WPA2 hacking is a dictionary attack.

The attacker captures a WPA password handshake and passes this through a program that will try numerous passwords from a word list.

Here is the key, if the password is not in the word list, they hacker does not get into your system.

Using a lengthy complex password goes a long way in keeping your WPA2 network secure.

A combination of upper/lower case letters, numbers and special characters is the best bet.

Some prefer using a short sentence that means something to them, while replacing some of the letters with numbers and adding in a few extra characters.

I just ran one common word list attack against my WPA2 password. It tried over 1 million word combinations from the list with no dice. My network is still secure!

The more un-dictionary looking your password is, the better!

Building More Secure Passwords

The problem of weak, guessable security passwords isn’t a new one, but it’s not going away.
In fact it’s getting worse, despite pleading from IT professionals to choose tough-to-guess passwords.

Workers are still disconcertingly likely to come up with something like “password1!” or simply attach a few numbers like “123,” to the end of a word.

As users have to create several passwords for different systems and change them every 60 or 90 days, it’s little wonder they default to the least complicated password their systems allow and make only minor variations when forced to change them.

Unfortunately, such passwords are easy to guess. At the other end of the scale are passwords software programs randomly generated, which are difficult for users to remember (leading them to write these passwords down which defeats the effort).

In a recent paper coauthored by Cisco, Florida State University, and Redjack LLC, researchers examined how different password requirements affect password strength — such as requiring a minimal password length or the addition of a special character.

The researchers discovered that such policies usually don’t provide greater security since hackers are well-versed in these tactics and can use them to guess passwords and access accounts.

For instance, hackers know that when users are required to use a special character in a password, they can simply append that character to the end of the password.

A better practice say the researchers, is an external password creation tool that changes a password after it’s created to add a guaranteed amount of randomness — for example, adding two random digits to the end of a password.

This allows users to choose a password that they are likely to remember while making it difficult for hackers to guess.

Another option is to implement a “judgmental” password policy which will reject a password instantly based on its estimated strength and suggest a stronger one.

Or administrators could implement password protection software, which lets users remember only one strong master password, leaving the application to store encrypted passwords.


Excerpted and adapted from the Cisco 2010 Annual Security Report


[infosecIsland]

Friday, 1 April 2011

How to Create and Remember Super-Secure Passwords

How many websites did you visit today that required a password? Probably quite a few.

Do you need a password to access data or email at work? You likely do.

In fact, you may have even needed a password to log on to the computer you’re reading this on right now.

Passwords are the front line of defense in protecting the data on your computer. They keep your kids from hijacking your Twitter account, and keep cybercriminals from gaining access to your bank account.

The problem is that because we need so many passwords today, many of us take the easy way out. We either use the same password for everything, or use very simple, easy-to-remember passwords.
And that’s where we can get into trouble.




The risks of weak or multiple-use passwords

“Let’s say you fall for a phishing attack on Facebook,” explained Beth Jones, senior threat researcher for the information-security firm SophosLabs North America. “They can see your email address and try that same password there.

“If you have sensitive information in your email, such as bank statements or credit-card statements, then the attacker can try that password to access bank accounts or credit-card accounts as well,” Jones said.

“They would have several key pieces of [personal] information… so in theory they could try the ‘forgot username’ on other accounts, such as Twitter, or online games,” she said. “You can see how this snowballs quickly.”

Not only should you have a unique password for each site you log into online, but, as Gunther Ollmann, vice president of research at the Atlanta-based computer-security firm Damballa, pointed out, you should also avoid recycling old passwords.

“Criminals — and unethical web masters — often try to use the passwords that have been taken from one site and use them against other sites, especially if your email address is also known to them,” Ollman explained.

“Each website or application you use should have a different password, and ideally you should not use a predictable algorithm for generating them,” he said. “For example, a bad practice is to use a password that contains the particular website’s name or address in it.”


How to create perfect passwords

So what makes a good, strong password?

“Password strength is measured by two characteristics — length and complexity,” said Josh Shaul, chief technology officer with New York-based Application Security, Inc. and author of Practical Oracle Security: Your Unauthorized Guide to Relational Database Security. “In general, the longer the password, the more difficult it is to guess and the stronger it is.”

Password complexity, he added, means avoiding passwords that can be easily guessed.

“The easiest passwords to remember are simple words, places, dates or easy-to-type text strings,” Shaul said. “Favorite sports teams, cities, names, birthdays and even strings like ‘12345‘ or ‘qwerty‘ are very commonly used. These are all weak passwords.”

Most experts agree on the basics of creating strong passwords. Here are some tips from the Identity Theft Resource Center:
  • A password should contain at least eight characters (some experts say 10 or 14 characters is the minimum).
  • The password should have at least three of the four following types of characters — upper-case letters (ABC), lower-case letters (abc), numerals (123), and punctuation marks or other special characters (!#$%&*_=+? ).
  • If you’re using only one capital letter or special character, don’t make it the first or last character in the password.
  • Avoid common names, slang words or any words in the dictionary. Computers can run through entire dictionaries in minutes.
  • Don’t include any part of your name or any part of your email addresses.
  • Choose an especially strong password for websites that hold especially sensitive personal information — for example, banks or online retailers that store your credit-card information.
  • Don’t ever refer to anything that can be learned from your social networking profiles or an Internet search. In other words, don’t make it your favorite band or movie, your pet’s name, your nickname, your phone number or, especially, your birth date.
Here’s a good way to create a strong password. Pick a phrase you’ll remember. Take the first letter of each word and run them together into a “word.” Capitalize some letters and substitute numerals where it would make sense to.

For example, the phrase “I hate to work late” could become “iH82wkl8.”

Or tweak that formula and don’t abbreviate all the words. "This little piggy went to market" might become "tlpWENT2m."

Not sure, even after following those tips, whether your password is strong enough? Go to one of the many websites that will check it for you.

Can’t think of a good password? There are also websites that generate them.


Should you write them down?

So if we need a unique, strong password for nearly everything we do online — check multiple email accounts, use Facebook and Twitter, make comments on CNN, buy something from Amazon — how can we remember them all? Is it okay to write them down somewhere?

Several years ago, the conventional wisdom was to never write down passwords — but that was when most of us only had a few to remember.

Some experts have since changed their minds.

“With today's threat landscape being dominated by password-stealing malware, physically writing down your passwords is becoming more acceptable,” Damballa’s Ollman said.

“The probability of someone breaking into your house and stealing your written-down passwords is considerably more remote than the 1-in-3 to 1-in-4 probability that your computer will fall to a criminal’s malware,” Ollman said.

Jones of SophosLabs sticks to the old advice — don’t write them down.

“This is really not a great idea, particularly for work,” Jones said. “Physical security is just as important as online security.

“Anyone walking by could see the sticky note next to your machine and then break into your accounts (especially if you use the same password for everything),” she added. “The risk is even greater if, as a user, you log into more than one location and have your password written at all those locations.”

Web browsers often ask if they can remember your password for you. Is that safer than writing down your password?

“For some passwords, it may be okay to let the browser remember your password on your personal laptop or home PC,” said Chris Burchett, founder and chief technology officer with Addison, Texas-based information-security firm Credant.

“In general, if the information on the website that requires your password is what you consider to be public, then it may be okay to let the browser remember the password,” Burchett said. “But be careful. 

Never let the browser remember passwords to banking websites or other sites where private personal identity information is used or available.”

“Also be careful when using a public-kiosk computer like the ones at the airport. Never let browsers on computers you don't own store passwords,” he added. “In fact, it would be best not to log into any website requiring a password from a computer you don't own.”


Password-management software

Instead, the experts suggest using third-party password-management software, which stores all your passwords in one place and protects them with one very strong master password — the only one you’ll have to remember.

“Managing passwords is a challenge because there are so many online accounts requiring passwords these days,” Burchett said. “Using a password manager to securely generate, store, rotate and supply passwords on demand may be worth considering as long as you remember to make the master password strong enough.”

There are dozens of password managers, both free and inexpensive (none cost more than $30). Some of the better-known ones include Web Confidential, LastPass, KeePass and its Mac/Linux sibling KeePassX. Some run on PCs, others on smartphones, while some are browser plug-ins.

As for the password managers that come with browsers, most of them aren’t very secure. Only Opera and Mozilla Firefox use master passwords, and Firefox’s is turned off by default. (Here’s how to turn it on.)

Now that you’ve read all this, do yourself a favor this weekend. Go through all your online accounts and use these tips to create strong, unique passwords for each one, and then use a password manager to remember them all.

It’ll take less time than you think. Next time a friend or relative has an email account hijacked or gets charged for dozens of iTunes songs he didn’t buy, you’ll be glad you did.

[SecurityNewsDaily]

Friday, 25 March 2011

Password Security - The Only Secure Password Is the One You Can’t Remember

Let's assume you log onto a bunch of different websites; Facebook, Gmail, eBay, PayPal, probably some banking, maybe a few discussion forums, and probably much, much more. Consider a couple of questions:

  • Do you always create unique passwords such that you never use the same one twice? Ever?
  • Do your passwords always use different character types such as uppercase and lowercase letters, numbers and punctuation? Are they "strong"?
If you can't answer "yes" to both these questions, you've got yourself a problem. But the thing is, there is simply no way you can remember all your unique, strong passwords and the sooner you recognize this, the sooner you can embrace a more secure alternative.


Let me help demonstrate the problem; I'll show you what happens when you reuse or create weak passwords based on some real world examples which should really hit home. I'll also show you how to overcome these problems with a good password manager so it's not all bad news, unless you're trying to remember your passwords.

The tyranny of multiple accounts

Think about it; how many accounts do you have out there on the internet? 10? 20? 50? I identified 90 of mine recently and there are many more I've simply forgotten about. There is absolutely no way, even with only 10 accounts, you can create passwords that are strong, unique and memorable.

What happens is that people revert to patterns including family names, pets, hobbies and all sorts of natural, somewhat predictable criteria. Patterns are a double-edged sword in that whilst they're memorable, they also predictable so even if the pattern might seem obscure, once it's known, well, you've got a bit of a problem.

Patterns and predictable words are bad, but what's even worse is password reuse. Because we simply end up with so many of the damn things, the problem of memorising them gets addressed by being repetitive. Easy? Yes. Secure? No way.

Continue reading the full article: http://lifehacker.com/#!5785420/the-only-secure-password-is-the-one-you-cant-remember

[Lifehacker]

Friday, 4 March 2011

Simple protection steps from credit card fraud

Every year, cybercriminals steal billions of dollars from unsuspecting computer users and companies by committing credit card fraud.



Although this activity was once relegated to pick-pocketers and mailbox thieves, today roughly half of all credit card fraud starts with online attacks ranging from phishing and email scams to spyware programs such as adware, keyloggers, Trojans, system monitors, browser hijackers, and dialers.

Fortunately, if you know what to watch for – and have good online protection – you can avoid becoming a victim of these fraudsters and keep your personal information safe.

The first step to ensuring that you're able to catch any form of credit card fraud (online or otherwise) early is to closely monitor your credit card activity. You can do this the old-fashioned way via your credit card company's official website, or you can find a security program that monitors your credit cards for you and alerts you to suspicious activity.

Here are a few additional tips from Webroot to help you safeguard your personal information online:
  • Use varied and complex passwords for all your accounts, including online shopping accounts, bank accounts, social networking sites, etc. (You may want to try using a security software program with a password manager to help you keep them straight.)
  • Only provide personal information on secure sites. (Look for "https" in the web address or the lock icon at the bottom of the browser.)
  • Do not respond to unsolicited requests for personal information – they are often a sign of phishing.
  • Avoid questionable Web sites, such as adult sites and file sharing sites.
  • Only download software from sites you trust.
  • Practice safe email protocol by not opening messages from unknown senders. Immediately delete messages you suspect to be spam.
Some signs and symptoms that your PC may be infected and require cleanup (as well as updated spyware and virus protection) include:
  • Sluggish performance
  • Increased number of pop-ups
  • New toolbars you can't delete
  • Unexplained changes to homepage settings
  • Puzzling search results
  • Frequent computer crashes.

Tuesday, 22 February 2011

Anonymous hack showed password re-use becoming endemic


Computer scientists have discovered that password re-use is far more prevalent than previously thought after comparing a sample of matched passwords that spilled out at a result of the revenge attack by Anonymous against security researchers HBGary with the earlier Gawker password breach sample set.
Hackers affiliated with Anonymous used one of the stolen credentials, and some social engineering trickery, to gain root access a site established by HBGary, rootkit.com. The subsequent release of 81,000 hashed passwords from rootkit.com’s SQL databases has allowed researchers to compare the databaset with the much larger sample of hashed passwords from the earlier Gawker tech blog breach. Both HBGary and rootkit.com were hit by hackers affiliated with Anonymous.

By comparing passwords associated with email addresses registered at both Gawker and rootkit.com, computer scientists at Cambridge have been able to find out whether these users picked the same passwords for both sites.
A total of 522 email addresses were registered at both HBGary and rootkit.com. Eliminating throwaway and dubious addresses whittled the sample down to 456 pairs.
Gawker and rootkit.com use different hashing functions, so a brute force attack had to be used to extract the passwords used in both cases before any comparison could be attempted. This process involved generating a rainbow table of hashes created from a dictionary of 10 million widely used passwords. One rainbow table was created for Gawker, using its hashing algorithm, and another for rootkit.com, using its hashing algorithm. It was them possible to look for hits from the hashed passwords spilled by the breaches and the rainbow tables.
Joseph Bonneau, the Cambridge University researcher who carried out the exercise, found that in many cases the tech-savvy combined users of both Gawker and rootkit.com were using the same weak passwords on both sites.
"Of the 456 common users, 161 had their password cracked in both datasets, 46 only had their rootkit.com password cracked and 77 only had their Gawker password cracked, leaving 172 with neither password cracked," Bonneau writes on the Light Blue Touchpaper blog. "Of the accounts for which passwords were cracked at both sites, 76 per cent used the exact same password. A further 6 per cent used passwords differing by only capitalisation or a small suffix (eg ‘password’ and ‘password1′)."
Taken overall this leads to a password re-use rate of at least 31 per cent. This figure rises to 49 per cent if users of cracked passwords from one site are assumed to have used a minor variant (not in the dictionary) on the other site and if some of the users of untracked passwords also re-used their more secure login credentials between the two sites.
But even with the most conservative estimate of password re-use - 31 per cent - from real world data of the users of the two tech sites is much lower than previously published studies, which suggest somewhere between 12 and 20 per cent. Sampling error of 5 per cent either way doesn't explain the discrepancy, so Bonneau concludes that either password re-use has become more prevalent in the five years since these earlier academic studies were completed or else users were less careful to pick secure passwords for access to rootkit.com and Gawker. Users at both sites, after all, register to post comments in their respective forums rather than to transfer money or access private email correspondence.
"It would also be very interesting to study the password overlap between higher-value accounts, such as those with a large email provider or an online bank, with low-security accounts like Gawker and rootkit.com which are more likely to be compromised," Bonneau concludes. A blog post by Bonneau explaining his password re-use research in greater depth can be found here. ®
Reposted from The Register