Showing posts with label Information Security. Show all posts
Showing posts with label Information Security. Show all posts

Thursday, October 27, 2011

The Financial Turmoil and Business Continuity

‘Eurozone at tipping point’, ‘Greece may be forced to default’, ‘Is the euro doomed?’ The headlines alone make you want to pull the covers over your head.

The Governor of the Bank of England, Mervyn King, tells the BBC: “This is the most serious financial crisis at least since the 1930s, if not ever.”

He then went on to call for a calm reaction to the crisis; which led to a few wry smiles!

If the financial crisis does get appreciably worse or, heaven forbid, the euro were to fail, what does this mean for business continuity professionals? Because, call the eurozone meltdown what you like, it’s certainly a crisis: and crisis is what we do isn’t it?

Contingency planning makes us all gaze into a crystal ball from time to time in an attempt to predict what might happen so we can plan accordingly and provide contingencies. But inevitably: ‘All plans imply an attempt to impose the values of the past...on the future.’

So it doesn’t mean we always get it right. But if the world’s economy or ‘just’ the eurozone does take a serious dive then at some point organizations are going to look to us to help get them out of this mess.

So what can we, as business continuity professionals, do to help: and how can our specialist knowledge be leveraged to help those trying to overcome the financial crisis?

We have a responsibility to understand as much as we can about the financial situation, but clearly it’s not our job to solve it.

For that there are leaders and governments; though some might argue it is just such people and institutions that got us into the crisis and of course within companies, particularly banks, there are experts assigned to investments, governance, auditing and PR who are trying to mitigate risk.

We stray into those fields at our peril. But what about the aftermath of a crisis? Many predict that inflation will go through the roof and this could spark further looting or civil unrest on the streets.

There could also be lengthy utility failures, fuel shortages, disruption to public transport and pressure on supply chains.

Perhaps staff won’t be able to travel to work or prefer to stay at home to look after their families. The fallout from these kinds of problems has our name written all over them.

The job of the business continuity professional is to identify risks and impacts to critical processes.

For each critical process we have to identify ways of providing a structure that enables these processes to be performed during or in the wake of a crisis.

Once the resources needed to perform these actions are identified this can form the basis of a plan, which can then be tested to see whether core critical processes really can continue to operate in extreme circumstances; and it doesn’t get more extreme than the uncharted territory that we would enter should the European banking system or the euro fail.

Unravelling a financial crisis may be way outside our skill set, but our business as usual is business as unusual and crisis our stock in trade.

Perhaps it’s a good time to review business continuity plans in the light of the societal impacts that could occur.

Monday, October 10, 2011

German hackers find government sponsored malware - R2D2

A group of German hackers say they have discovered trojan software developed by their government that can be used to spy on computer users without their knowledge.

The Chaos Computer Club (CCC) gained access to a copy of the "Bundestrojaner" (State Trojan) and found the program could be used to activate a computer's microphone or camera as well as log a user's online activity.

Since 2008 German police forces have been legally allowed to to install wiretapping software on a suspect's computer in order to monitor voice-over-IP communications through services such as Skype, but they are forbidden from accessing or installing other programs. The CCC analysis suggests the police software is capable of much more than is legally allowed.

"Our analysis revealed once again that law enforcement agencies will overstep their authority if not watched carefully. In this case functions clearly intended for breaking the law were implemented in this malware: they were meant for uploading and executing arbitrary code on the targeted system," say the CCC.

Security firm Sophos has confirmed that the trojan is able to eavesdrop on instant messaging software, log internet browser keystrokes and take screenshots of what appears on user's screens, while also attempting to communicate with a remote website.

Sophos consultant Graham Cluley also says there is no way to confirm the software was written by the German state.

Regardless of who wrote the software, it seems installing it on someone's computer leaves them wide open to any attacker.

The trojan's commands are unencrypted, making it possible for anyone to access an infected system and retrieve or upload data.

"The security level this trojan leaves the infected systems in is comparable to it setting all passwords to '1234'," says the CCC.

Wednesday, June 22, 2011

Four easy-to-remember passwords that will protect your accounts

The recent security breach at the beloved online storage service, Dropbox, has reminded us of the weakness of the Web.

Founded in 2007 Dropbox that uses cloud computing to allow us to store all kinds of large files on the Web, and across a variety of operating systems, that are then easily shared with others.

For about four hours on June 19 anyone could get access to any account with a dummy password. “It was like our skirt got lifted for hours.”

This is what Dropbox wrote on their blog yesterday:
Yesterday we made a code update at 1:54pm Pacific time that introduced a bug affecting our authentication mechanism. We discovered this at 5:41pm and a fix was live at 5:46pm. A very small number of users (much less than 1 percent) logged in during that period, some of whom could have logged into an account without the correct password. As a precaution, we ended all logged in sessions.

We’re conducting a thorough investigation of related activity to understand whether any accounts were improperly accessed. If we identify any specific instances of unusual activity, we’ll immediately notify the account owner.

This should never have happened. We are scrutinizing our controls and we will be implementing additional safeguards to prevent this from happening again.

This is a serious issue for Dropbox—a company valued at $1.5 to $2 billion—since trust is the number one value they offer over their competition. Until we hear more about the “additional safeguards” they intend to implement it does give us pause about our chosen passwords.

We live in a password era, and we all have our passwords that range from the ridiculously simple and cheesy like “love” to impossible-to-get-straight gobbledigook. Apparently a shocking 50% of passwords are “based on names of a family member, spouse, partner, or a pet,” according to this book “Perfect Password: Selection, Protection, Authentication.”

We also learned recently that 75% of us use the exact same password for everything. This is a huge mistake. All it takes is one hacker and one weakly protected site and your key to everything, including email and banking, is up for grabs.

When you use the same password for everything it is only as strong as the weakest site and, unfortunately, there are plenty of weak sites. Ninety-three percent of organisations have been hacked at least once in the past two years, according to the US State of Web Application Security Survey, Ponemon Institute.

You can use the same series of numbers and letters but do mix them up (upper case, lower case, order, creating what may be a near limitless variety) for different sites, banking, discount shopping, online publications, airlines, etc. and change them up regularly.

There is a better, simpler way, according to Christopher Mims at MIT Tech Review. He suggests that you create only four passwords and use them in a tiered system.

Low-tier password: Something you may already be using that is so easy to get that it might as well be your middle name. Use this for low level importance sites. One's you don’t care about, like commenting sites for online magazines or music streaming sites. If you get hacked the worst that can happen is that your username suddenly likes Lady GaGa!

Second-tier password: “For sites on which you have personal data and definitely don’t want to be impersonated (Twitter, Facebook, etc.),” says Mims. Here you need something longer as long as you are comfortable with recalling complex phrases. Remember to use at least one special character, especially inserting it into the middle of the phrase, not at either end.

Never, ever use what is called a “dictionary password” i.e. any real word that will exist in a dictionary. A classic tactic that hackers use to break into sites uses a fast program that repeatedly inserts real words until it finds a match.

Third-tier password: This is your second highest level of security and can be used for email accounts and your cell phone. It needs to be unique, long and interspersed with special characters. Your email account is where you might hold information about your other passwords, so it must be highly guarded. It is the “master key” of passwords.

Fourth-tier password: The gold standard of passwords should be used to protect your wealth i.e. your bank and financial information. This password should be unique and can only be used for your banking, nothing else.

So we don’t need to have 30+ passwords memorised, or worse, documented in email or on scraps of paper, we just need four — or at least three — that are tiered for importance and security.

As for tips on creating a vice-like, gold standard password we suggest reading an informative post on the worst passwords of all time, and avoid them.

Even a cryptic string like “abgrtyu” is on the list, so be wary. The hard part is following the paradoxical mantra of password creation: Easy to remember, hard to guess.

Once you’ve mastered that statement, try measuring your password strength using this useful Microsoft test. I used to get angry and hurt when my passwords were noted as “weak” as if it were a personal affront. Now I know it can be part of an entire strategy of protection.

Saturday, March 5, 2011

ENISA: EU cyber security agency warns of new cookies risk

The EU’s cyber security agency ENISA has published a position paper on the security and privacy concerns regarding new types of online cookies.

The advertising industry has led the drive for new, persistent and powerful cookies, with privacy-invasive features for marketing practices and profiling.

The Agency recommends that both the user browser and the origin server must assist informed consent; that users should be able to easily manage their cookies; and that users should be provided with another service channel if they do not accept cookies.

The Agency recommends a thorough study of different interpretations in the Member States, once the Directive 2009/136/EC has been implemented, by 25 May 2011.

The new Agency Position Paper identifies and analyses cookies in terms of security vulnerabilities and the relevant privacy concerns. Cookies were originally used to facilitate browser-server interaction.
 
Lately, driven by the advertising industry, they are used for other purposes; e.g. advertising management, profiling, tracking, etc. The possibilities to misuse cookies both exist and are being exploited.

The new type of cookies support user-identification in a persistent manner and do not have enough transparency of how they are being used. Therefore, their security and privacy implications are not easily quantifiable.

The Executive Director of ENISA, Prof. Udo Helmbrecht states:
”Much work is needed to make these next-generation cookies as transparent and user-controlled as regular HTTP cookies, to safeguard the privacy and security aspects of consumers and business alike”.

Consultation on new UK CCTV code of practice

The Home Office is running a consultation into a proposed new UK code of practice related to CCTV usage.


The consultation is the first step towards establishing a formal Code of Practice as promised in the Government's Protection of Freedoms Bill.

The proposals include:
* Establishing a checklist of actions to be carried out by CCTV operators before installing new cameras to check whether they are absolutely necessary;
* Developing industry standards for equipment to ensure it is reliable, effective and gathers images that are of sufficient quality and in a useable format;
* Improving public knowledge about systems in communities through consultation by police and local authorities and better public information; and
* Considering whether further guidance is needed on how long data collected by CCTV should be retained.

Crime Prevention Minister James Brokenshire said that the code would be introduced on an incremental basis, with local authorities and police required to have due regard to it straightaway. The Government will consider whether the code should be extended to other organisations, such as businesses and private security firms, in due course.

The consultation will run for 12 weeks. For further information click here.

NIST Publication on Information Security - March 2011


The US National Institute of Standards and Technology (NIST) has published the final version of a special publication that can help organisations to more effectively integrate information security risk planning into their mission-critical functions and overall goals.

‘Managing Information Security Risk: Organization, Mission, and Information System View’ (NIST Special Publication 800-39) provides the groundwork for a three-tiered, risk-management approach that "fundamentally changes how we manage information security risk," according to Ron Ross, NIST Fellow and one of the principal authors of the publication.

For decades, organisations have managed risk at the information system level that resulted in a very narrow perspective that constrained risk-based decisions by senior management, Ross explains.

SP 800-39 calls for a holistic approach in which senior leaders determine what needs to be protected based on the organization's core missions and business functions. 

For example, managers of a power plant tied to the distribution grid need to ensure that its computer security keeps hackers from interfering with the plant's power generation or getting into the power grid to wreak greater havoc.

The publication is the fourth in the series of risk management and information security guidelines being developed by the Joint Task Force Transformation Initiative, a joint partnership among the Department of Defense, Intelligence Community, NIST and the Committee on National Security Systems.

SP 800-39 can be downloaded from here (PDF) or by clicking on the picture.

Monday, August 9, 2010

Laptop engineer jailed after Sky News sting


A laptop engineer has been jailed for nine months after being caught out by a Sky News sting.

Grzegorz Zachodni, who was working at Laptop Revival, pleaded guilty to fraud after he attempted to hack into a Sky reporter’s bank account using details stolen from her computer.

"Hopefully this conviction will be a warning to the computer repair industry that the copying or use of customers' private and personal information is not acceptable and the Metropolitan Police Economic and Specialist Crime Directorate will endeavour to prosecute any person found to have committed offences regarding these abuses," said DC Chris Young, the investigating officer.

The reporter was looking into the quality of service at laptop repair shops and took in her computer with a loose memory chip to be fixed.

The laptop contained hidden software in it that recorded which files were viewed and what websites were visited, while taking images through an integrated webcam.

Personal photos of the reporter, including ones of her in a bikini, were stored on the computer along with login details to eBay, Facebook and NatWest.

The shop called her to tell her the laptop required a new motherboard, but she declined the repair.

When she returned to Laptop Revival, the reporter was told the computer had been fixed but she would not be charged as no permission was given for the alterations.

The covert software found Zachodni had only worked on the computer for 20 minutes and in that time had viewed various files and saved passwords and login details. He also took two of the bikini snaps.

Police are cracking down hard on cyber crime and last week saw six arrested in relation to a phishing network which is thought to have compromised 20,000 bank accounts and credit cards.

Saturday, August 7, 2010

Consumer Password Worst Practices

The dispiriting lack of originality that many online users display in choosing passwords has been on display in recent months.

In January, researchers at Web security firm Imperva announced the results of an in depth analysis (shown in the picture above - Click to view).

Imperva examined a trove of 32 million passwords belonging to customers of RockYou, a developer of social networking software, that had been hacked.

The most popular password, they found, was "123456" - the choice of almost 300,000 RockYou users. The second most popular password was "12345." "Password" was the fourth most popular choice.

Twitter, also, has blocked 370 "obvious" passwords from being used to secure its users' accounts, while others have studied and written about the illusory security of the all-too-common challenge questions used by many financial and e-commerce Web sites.

Herley and his colleagues found that such easy-to-guess passwords are vulnerable to statistical guessing attacks, in which dictionaries of common or popular passwords are used in automated attempts to break into an account.

Limiting the number of log in attempts users are granted is the easiest way to block such attacks, but getting users to pick unusual passwords is also part of the solution.

But ensuring that users actually choose secure passwords is harder than it sounds, the researchers wrote in their paper, which is available on Microsoft Research's Web site.

Features that are common on many Web sites to enforce password security may be having the opposite effect, the researchers argue. For example, features that measure password strength or enforce strong password policies (such as length of password, use of non-standard characters) are indirect means to produce secure passwords that often merely force users into a different set of predictable choices that can also be easily guessed.

Thursday, August 5, 2010

Phishers compromise 10,000 bank accounts

Five men and one woman were arrested this week in relation to an investigation into a phishing network, police have confirmed.

The alleged cyber gang are thought to have compromised 10,000 online bank accounts and are also believed to have taken control of 10,000 credit cards, from which it is estimated they gained over £3 million, the Metropolitan Police Service (MPS) said.

The suspected scammers also allegedly stole £358,000 by taking over bank accounts.

“A great deal of personal information was compromised and cleverly exploited for substantial profit,” said Detective Inspector Colin Wetherill, from the MPS' Police Central e-Crime Unit (PCeU).

“By disrupting the operation we have hopefully prevented further loss to individuals and institutions across the UK.”

The investigation was part of the PCeU’s anti-phishing initiative, otherwise known as Operation Dynamophone.

PCeU Officers made the arrests after carrying out five searches across London and an address in Navan, Ireland, with the assistance of the MPS Territorial Support Group and the Irish Garda Siochana Fraud Investigation Bureau.

It is thought the gang behind the illicit operation had been sending a large amount of unsolicited spam emails, asking recipients to visit specially-created websites claiming to be legitimate banking webpages.

Victims were then asked to enter personal data, in the classic phishing style, which was taken by the suspected fraudsters to access online bank accounts and move funds. Credit card info was obtained in the same way.

How much the phishing network managed to acquire in total is yet to be ascertained.

Saturday, July 3, 2010

Sun Tzu and Information Security

InfoSec and Sun Tzu

"The (Sun Tzu) Art of War teaches us to rely not on the likelihood of the enemy's not coming, but on our own readiness to receive him; not on the chance of his not attacking, but rather on the fact that we have made our position unassailable."

"Know your enemy and know yourself; in a hundred battles, you will never be defeated. When you are ignorant of the enemy but know yourself, your chances of winning or losing are equal. If ignorant both of your enemy and of yourself, you are sure to be defeated in every battle."

Sun Tzu - The Art of War


"Sun Tzu was an ancient Chinese military general and strategist who is traditionally believed to have authored The Art of War, an influential ancient Chinese book on military strategy considered to be a prime example of Taoist thinking."

Tzu's treatise on strategy, "The Art of War" is available in all shapes and sizes, translated by dozens of scholars. Further, it has been translated or adapted to be made relevant to all walks of life including managerial strategy, achieving life goals, spirituality, writing and more.

Given the writing deals more with the mindset, logistics and strategy of war, it is possible to apply many of its concepts to almost any facet of life. The book is a fascinating read and highly recommended for people of all ages, profession or culture.

Tuesday, June 1, 2010

Facebook and The Money Mule Farm

Scammers and phishers are continuing to adapt their recruitment tactics, now going so far as to create special Facebook groups for their work-at-home scams.

Phishers have been using social networks such as Facebook, MySpace and Twitter for years now as fertile hunting grounds not only for new victims but as a way to find new participants in their scams, as well. Now, the scammers have taken to creating Facebook groups specifically dedicated to the work-at-home scams that often serve as recruitment schemes for money mules. One such group that's being tracked by researchers has nearly 225,000 members on Facebook.

The criminals promise that their potential mules will get more than $ 6,000 USD per month and will only need to work no more than 18 hours a week. The mule site has a GeoIP javascript, which customizes some parts of the offer according to your current geographical location. So, it’s another old, but in some cases, effective trick to lure more potential mules.

Money mules are an integral part of the phishing and credit-card theft ecosystem, effectively serving as the money launderers for the actual phishing gangs on the back end. The money mules are recruited through these work-from-home or easy money scams that promise high payments for very little effort. What they usually end up doing is accepting deposits and wire transfers of thousands of dollars a day, then transferring the money to other accounts designated by the phishing gang.

For their trouble, the money mules typically earn a small commission on each transaction. In one sense, it is pretty easy money. But the reality is that the money mules are the ones in the phishing scams who are most exposed to discovery, arrest and prosecution. In some cases the money mules don't actually know what the end result of their activities is, they just know that they're moving money from one account to another.

But that's not enough to protect them from prosecution, so the phishers are always in need of new mules for their scams. And Facebook is turning into their recruitment scheme of choice.

The nature and content of these recruiting scams on Twitter, Facebook and other sites has evolved and improved over time as the scammers have seen what works and what doesn't. The gangs behind these scams also move around the Internet quite a bit, changing domains often and using multiple URL redirects to obfuscate the ultimate destination site when potential victims click on one of their links.

It's the same kind of tactic that has worked so well on the front end of phishing scams, disguising malicious domains, redirecting victims through a series of hops and using digital sleight-of-hand to make their scams look more attractive.

Thursday, May 13, 2010

Stolen Serco Laptop Exposes 207,000 Army Reservists

A Serco laptop stolen from a government contractor last month contained more than 207,000 names, addresses and Social Security numbers of U.S. Army reservists.

The U.S. Army Reserve Command began alerting affected reservists on May 7 via e-mail. Col. Jonathan Dahms, chief public affairs for the Army Reserve, said the personal data was contained on a CD-Rom in a laptop that was stolen from the Morrow, Ga. offices of Serco Inc., a government contractor based in Reston, Va.

The laptop was one of three stolen from the Serco offices, but it was the only one that contained sensitive personal information, Dahms said.

Serco held the data on reservists as part of its contract with the U.S. Army’s Family and Morale, Welfare and Recreation division. As a result, Dahms said, some of the data on the missing laptop may belong to dependents and spouses of U.S. Army reservists.

The e-mail sent to affected service members expresses regret over the incident, but offers little other consolation. From the letter:

The US Army takes this loss very seriously and is reviewing current policies and practices with a view of determining what can or must be changed to preclude a similar occurrence in the future.

At a minimum, we will be providing additional training to personnel to ensure that they understand that personally identifiable information must at all times be treated in a manner that preserves and protects the confidentiality of the data.
Dahms said, however, that the US Army is looking at further steps to protect the identities of those whose personal information was potentially exposed by the theft, although he declined to name any specific solutions.

“We did have an extensive meeting with all key staff at U.S. Army Reserve Command to see what we can implement to make sure our soldiers and families are protected,” he said.

More than seven million consumer records have been exposed in at least 264 data breaches so far this year, according to the latest figures from the Identity Theft Resource Center, a San Diego nonprofit.

The ITRC has tallied some 38 other incidents of data loss or theft involving the government and/or the military so far this year, breaches that exposed nearly 300,000 records.

Saturday, May 8, 2010

Warning! How I’d Hack Your Weak Passwords - by Lifehacker

Note: This isn't intended as a guide to hacking *other people's* weak passwords. Instead, the aim is to help you better understand the security of your own passwords and how to bolster that security.

If you invited me to try and crack your password, you know the one that you use over and over for like every web page you visit, how many guesses would it take before I got it?

Let's see… here is my top 10 list. I can obtain most of this information much easier than you think, then I might just be able to get into your e-mail, computer, or online banking. After all, if I get into one I'll probably get into all of them.

1.Your partner, child, or pet's name, possibly followed by a 0 or 1 (because they're always making you use a number, aren't they?)
2.The last 4 digits of your social security number.
3.123 or 1234 or 123456.
4."password"
5.Your city, or college, football team name.
6.Date of birth – yours, your partner's or your child's.
7."god"
8."letmein"
9."money"
10."love"
Statistically speaking that should probably cover about 20% of you. But don't worry. If I didn't get it yet it will probably only take a few more minutes before I do…

Black Hats
Hackers, and I'm not talking about the ethical kind, have developed a whole range of tools to get at your personal data. And the main impediment standing between your information remaining safe, or leaking out, is the password you choose. (Ironically, the best protection people have is usually the one they take least seriously.)

Brute Force
One of the simplest ways to gain access to your information is through the use of a Brute Force Attack. This is accomplished when a hacker uses a specially written piece of software to attempt to log into a site using your credentials.


Insecure.org
has a list of the Top 10 FREE Password Crackers. Please use this information in a responsible manner. If you do use them, do so to improve your system security.

Security Breach
So, how would one use this process to actually breach your personal security? Simple. Follow my logic:

You probably use the same password for lots of stuff right?
Some sites you access such as your Bank or work VPN probably have pretty decent security, so I'm not going to attack them.

However, other sites like the Hallmark e-mail greeting cards site, an online forum you frequent, or an e-commerce site you've shopped at might not be as well prepared. So those are the ones I'd work on.

Software aids
So, all we have to do now is unleash Brutus, wwwhack, or THC Hydra on their server with instructions to try say 10,000 (or 100,000 – whatever makes you happy) different usernames and passwords as fast as possible.

Once we've got several login+password pairings we can then go back and test them on targeted sites.

Interrogating cookies
But wait… How do I know which bank you use and what your login ID is for the sites you frequent? All those cookies are simply stored, unencrypted and nicely named, in your Web browser's cache. Use cleaning software to remedy that problem.

Speed is relative
How fast can all this be done? Well, that depends on three main things, the length and complexity of your password, the speed of the hacker's computer, and the speed of the hacker's Internet connection.

Assuming the hacker has a reasonably fast connection and PC here is an estimate of the amount of time it would take to generate every possible combination of passwords for a given number of characters. After generating the list it's just a matter of time before the computer runs through all the possibilities – or gets shut down trying.

Lowercase and Uppercase
Pay particular attention to the difference between using only lowercase characters and using all possible characters (uppercase, lowercase, and special characters – like @#$%^&*). Adding just one capital letter and one asterisk would change the processing time for an 8 character password from 2.4 days to 2.1 centuries.

Remember, these are just for an average computer, and these assume you aren't using any word in the dictionary. If Google put their computer to work on it they'd finish about 1,000 times faster.

Now, I could go on for hours and hours more about all sorts of ways to compromise your security and generally make your life miserable – but 95% of those methods begin with compromising your weak password. So, why not just protect yourself from the start and we can all sleep better at night?

Believe me, I understand the need to choose passwords that are memorable. But if you're going to do that how about using something that no one is ever going to guess AND doesn't contain any common word or phrase in it.

Here are some strong password tips:
  • 1.Randomly substitute numbers for letters that look similar. The letter ‘o' becomes the number ‘0′, or even better an ‘@' or ‘*'. (i.e. – m0d3ltf0rd… like modelTford)
  • 2.Randomly throw in capital letters (i.e. – Mod3lTF0rd)
  • 3.Think of something you were attached to when you were younger, but DON'T CHOOSE A PERSON'S NAME! Every name plus every word in the dictionary will fail under a simple brute force attack.
  • 4.Maybe a place you loved, or a specific car, an attraction from a vacation, or a favorite restaurant?
  • 5.You really need to have different username / password combinations for everything. Remember, the technique is to break into anything you access just to figure out your standard password, then compromise everything else. This doesn't work if you don't use the same password everywhere.
  • 6.Since it can be difficult to remember a ton of passwords, I recommend using Roboform for Windows users. It will store all of your passwords in an encrypted format and allow you to use just one master password to access all of them. It will also automatically fill in forms on Web pages, and you can even get versions that allow you to take your password list with you on your PDA, phone or a USB key. If you'd like to download it without having to navigate their web site here is the direct download link. (Ed. note: Lifehacker readers love the free, open-source KeePass for this duty, while others swear by the cross-platform, browser-based LastPass.)
  • 7.Mac users can use 1Password. It is essentially the same thing as Roboform, except for Mac, and they even have an iPhone application so you can take them with you too.
  • 8.Once you've thought of a password, try Microsoft's password strength tester to find out how secure it is.
Guard email passwords
Another thing to keep in mind is that some of the passwords you think matter least actually matter most. For example, some people think that the password to their e-mail box isn't important because "I don't get anything sensitive there."

Well, that e-mail box is probably connected to your online banking account. If I can compromise it then I can log into the Bank's Web site and tell it I've forgotten my password to have it e-mailed to me. Now, what were you saying about it not being important?

Drive-by Hacking
Often times people also reason that all of their passwords and logins are stored on their computer at home, which is safe behind a router or firewall device. Of course, they've never bothered to change the default password on that device, so someone could drive up and park near the house, use a laptop to breach the wireless network and then try passwords from this list until they gain control of your network — after which time they will own you!

Pay attention
Now I realise that every day we encounter people who make a lot of noise and over-exaggerate points, to move us to action or for their own benefit, but trust me this is not one of those times. There are 50 other ways you can be compromised and punished for using weak passwords that haven't been mentioned.

I also realise that most people just don't care about all this until it's too late and they've learned a very hard lesson. But why don't you do yourself a big favour and take a little action to greatly strengthen your passwords. You know it makes good sense.

Saturday, January 23, 2010

The Most Popular Password Remains '123456'

Despite all the reports of Internet security breaches over the years, including the recent attacks on Google’s e-mail service, many people have reacted to the break-ins with a shrug.

According to a new analysis, one out of five Web users still decides to leave the digital equivalent of a key under the doormat: they choose a simple, easily guessed password like “abc123,” “iloveyou” or even “password” to protect their data.

“I guess it’s just a genetic flaw in humans,” said Amichai Shulman, the chief technology officer at Imperva, which makes software for blocking hackers. “We’ve been following the same patterns since the 1990s.”

Mr. Shulman and his company examined a list of 32 million passwords that an unknown hacker stole last month from RockYou, a company that makes software for users of social networking sites like Facebook and MySpace. The list was briefly posted on the Web, and hackers and security researchers downloaded it.

RockYou, which had already been widely criticised for lax privacy practices, has advised its customers to change their passwords, as the hacker gained information about their e-mail accounts as well.

The trove provided an unusually detailed window into computer users’ password habits. Typically, only government agencies like the F.B.I. or the National Security Agency have had access to such a large password list.

For the full article click here ..........

Saturday, January 16, 2010

DDoS Attacks Are Back and Bigger Than Before

DDoS Attacks Are Back and Bigger Than Before

Distributed denial-of-service (DDoS) attacks are certainly nothing new. Companies have suffered the scourge since the beginning of the digital age. But DDoS seems to be finding its way back into headlines in the past six months, in thanks to some high-profile targets and, experts say, two important changes in the nature of the attacks.

The targets are basically the same -- private companies and government websites. The motive is typically something like extortion or to disrupt the operations of a competing company or an unpopular government. But the ferocity and depth of the attacks have snowballed, thanks in large part to the proliferation of botnets and a shift from targeting ISP connections to aiming legitimate-looking requests at servers themselves.

In fact, said Andy Ellis, CSO of Cambridge, Mass.-based Akamai Technologies (AKAM), the botnets launching many of today's DDoS attacks are so vast that those controlling them probably lost track of how many hijacked machines they control a long time ago. (Listen to the full interview with Ellis in The Long, Strange Evolution of DDoS Attacks.)

Ellis has been watching the trend from a pretty good vantage point. Many people use Akamai services without even realizing it. The company runs a global platform with thousands of servers customers rely on to do business online. The company currently handles tens of billions of daily Web interactions for such companies as Audi, NBC, and Fujitsu, and organizations like the U.S. Department of Defense and NASDAQ. There's rarely a moment -- if at all -- when an Akamai customer IS NOT under the DDoS gun.

"We see a lot less of the fire-and-forget malware-based attacks designed to bog down the machines that were infected," Ellis said, referring to old-school worm attacks like Blaster, Mydoom and Code Red. "Now the malware is used to hijack machines for botnets and the botnets themselves are used as the weapon."

In the last year, Akamai has seen some of the largest DDoS attacks in recent memory, which Ellis described as "huge attacks of more than 120 gigabytes per second." If you are on the receiving end of that much punch, Ellis said, "It's not a pleasant place to be."

Saturday, November 28, 2009

Avoiding Botnets

Banging the drum for security awareness never gets old. As much as CSOs try to get folks to bone up on safe practices (both online and in the office), there are always going to be some who need reminding.

Online, the biggest battle these days is against botnets: networks of infected computers which hackers can use -- unbeknownst to the machine's owner -- for online crimes including sending out spam or launching a denial of service attack.

Unfortunately, the black-hat techniques employed to snare users into a botnet web have evolved to a level that makes them often undetectable by even the most sophisticated security products. Combine that with a lack of user knowledge, and the threat of infection becomes very high. (See: Botnets: Why it's Getting Harder to Find and Fight Them).

"The frustrating thing is they can make their chances of getting infected much, much smaller," said Steve Santorelli, who sees how users fall prey to easily avoidable traps every day. Santorelli, director of global outreach with the non-profit security investigations firm Team Cymru, spends his days monitoring malicious online activity, particularly botnets.

Santorelli notes that while just one strategy probably won't cover you, with several tools in the tool box, the rate of infection within an organization significantly drops.

Tip 1: Have work AND home machines regularly updated with patches and antivirus software

The average user doesn't necessarily have a lot of technological knowledge, said Santorelli. They might not realize the importance of working with IT to ensure they are up to date with patching and software upgrades. This problem may be especially prevalent among workers who are exclusively remote.

In fact, a study conducted by security firm Sophos last year found most computer users ignore security updates and turn off their firewalls. Sophos scanned 583 computers for 40 days and found that 81 percent of the machines failed one or more basic security checks. Most machines, 63 percent, were lacking security patches for the operating system, office application and programs like Windows Media Player and Adobe Flash. More than half, 51 percent, had disabled their firewall and another 15 percent had outdated or disabled antivirus and anti-spam software.

Those are exactly the folks that criminals love.

"These people are going to go for the low-hanging fruit and unfortunately there is a lot of it out there," said Santorelli. "There are so many machines without updated AV on it."

If your patching system isn't automated, your users need to be made aware of the risks they are taking by working with unpatched and out-dated security technologies. And while security updates are not the cure-all for malware infection, Santorelli said they certainly serve as a strong deterrent.

"If you are walking down the street as a burglar and you see a house with a Rottweiler, and a visible sign from a security company, you probably won't attack that house," he noted.

Tip 2: Use the latest browser versions

Staying away from dubious sites and sticking to known brands used to offer reasonable online safety. Unfortunately, that's less and less foolproof.

"It used to be that if you surfed to places like CNN, or the Weather Channel, you weren't going to come across great deal of malware," said Santorelli. "That isn't the case anymore. We've seen a number of cases recently where people have gone to a legitimate web site and there is an advertisement up there hosting some kind of malicious code."

That is where the latest safe browsing technologies can help, said Santorelli. The latest versions of today's browsers will often flag potentially dangerous content.

"Browsers are so much more secure now that so many of the holes that existed in these browsers have been patched. There is also a great deal of anti-phishing and anti malware that goes into them now. So if you try and go to a link that contains malware, your AV might not pick it up. But your browser will say: "Are you sure?"

The good news is most browsers are free. You can download the latest version of Internet Explorer or Firefox fairly easily and quickly, too (See: IE or Firefox: Which is More Secure?).

"It will only take you five minutes to have the latest browser technology," said Santorelli. "It is just another string to your bow, so to speak."

Tip 3: Be a little more careful when you get a link or an attachment.

"Don't just blindly click on things and rely on other people to protect your computer," noted Santorelli. "You've got to take some responsibility for your own security."

Team Cymru research reveals that the most common attack vectors for installing malware continue to be links in emails, or drive-by downloads.

"We know from our recent investigations that there is a great deal of success to be had [for hackers] by just sending links out," he said.

Just because you receive the email from someone you know and trust, it doesn't mean it is safe. This includes friends and family, whose systems or accounts may have been compromised, and also well-known web sites you use, like social networking sites or banks. See Five More Facebook, Twitter Scams to Avoid for examples of current attempts to exploit social media sites. And large banks, such as Bank of America, often find their name is used in email phishing scams where thieves send out messages warning that customers their account has been compromised with a link that leads to a fake, but very legitimate-looking login screen.

Of course, whether or not you should click any link or attachment also depends on if you have complied with steps 1 and 2 above.

"You're going to have to take it on a case-by-case basis," said Santorelli "And my concern would be significantly raised if I didn't have my computer up to date with antivirus and browsing technologies."