Showing posts with label Passwords. Show all posts
Showing posts with label Passwords. Show all posts

Wednesday, 30 August 2017

Phishing and passwords - 3 years on

Nearly three years ago, I wrote a blog piece about the compromise of iCloud accounts aka "The Fappening".  In the last 3 years there have been little improvement to the users interacting with phishing attacks, and it's disappointing to hear of the Fappening 2017.

Phishing
I've been guilty in the past to blame users for not checking the constructs of an email, and detecting incorrect domain names, etc, but with the technology available today, this shouldn't be the job of an email users.  Using a mainstream web-based email solution, these checks are done for you:


In a commercial environment, there are email filtering solutions to prevent the user from ever seeing these in the first place.

Passwords
The previous advice around regularly changing passwords may not have been the best, as people will just increment numbers, and typically the password will become weaker.  The advice now is to use stronger passwords and use a password manager to secure these passwords.

2-Step Verification
Many websites, including Facebook, LinkedIn, Twitter, WhatsApp and many more, support the use of 2-step verification.  This is a process where you log into one of these websites with your username/email address and your password.  Before you can gain access to the site or application, it will text your nominated mobile number with a code, which will need to be entered into the website before you can gain access.

Even if your login details were compromised, a hacker would be unable to gain access to the site or application without access to your mobile phone.

These solutions are provided free of charge, so it would make sense to enable this wherever possible.

So what?
So some people's iCloud accounts were compromised due to falling for a phishing attack... so what?

Well looking at security and the principles in play, this also makes corporate networks susceptible to these sorts of hacks.  Phishing attacks happen to gain access to corporate credentials, in fact worse so, as there are also spearphishing attacks.  Phishing attacks are typically broad brush attacks, spreading the net (excuse the pun) wide.  Spearphishing is targeting an individual, such as a member of the senior management team, or someone with administrative credentials, enabling access to personal information.

Privileged Access Management
The priority for any organisation, is the protection of administrative passwords, typically known as Privileged Access.  Depending on the analyst's reports you read, 80-100% of data exfilration compromises have required administrative credentials.

Privileged Access Management is a technology to grant administrative access to a user, without them knowing the password.  The technology will securely store the password, and is also able to change the password once the user is done with that session.  What could be more secure than a user unaware of the administrator password?  

Some other benefits include the ability to record the screen of the user session, as well as in depth analytics.

Securing passwords
Whether you are a home user, or a corporate user, passwords have always been important, but password security is more important than ever.  Whatever the situation, there are ways to secure the password and minimise the damage a hacker can do.

Saturday, 25 June 2016

Is the character password finally dead? [Link - IT ProPortal]

I was asked to write an article about passwords as organisations were looking to use more secure passwords, for IT ProPortal: http://www.itproportal.com/2016/06/25/is-the-character-password-finally-dead/

=============================

Passwords have been an essential part of our lives for a long time now, ensuring all our personal details are locked safely away from prying eyes. But, as recent hacks such as Mark Zuckerberg’s social media accounts have shown us, they are not infallible or, in some cases, even that secure.

The Facebook founder’s hack is an interesting case study of the dangers simple passwords pose, especially for high-profile individuals. While numerous, complicated passwords are difficult to remember, a simplified password used across multiple platforms leaves them very vulnerable to being hacked.

So Mr Zuckerberg might just welcome Google’s recent announcement that it is developing a new log-in method for smartphones. Called the Trust API, this latest security method could see the typical character based password rendered obsolete and replaced by an algorithm that learns a user’s behaviour.

No more characters


This is a massive step forward for online security, replacing passwords with a ‘trust-based’ system that monitors the way a user typically uses a smartphone.

According to Google, it checks personal indicators such as how you type and swipe as well as your location to continually monitor that it is definitely you holding and using the device, which makes it much harder to break into a lost or stolen phone.

Behavioural technologies such as this have been in development for some time and are already used in sectors that handle extremely sensitive materials, such as financial services industry. The unique activities of a user – such as keyboard typing patterns – are mapped out by the system, which is then matched every time that user tries to access data before entry is allowed.

While this is a fantastic move towards ensuring we do not become a victim to hacks and keep confidential materials behind closed doors, it raises questions about emergency access.

Behavioural monitoring can be quite tricky for the user, especially as people’s usual habits change in times of high stress, such as in an emergency situation, which could result in users being locked out of devices at the moment they desperately need to get in.

The acceptance of Google’s Trust API will most likely be dependent on finding a way to solve this issue without compromising security.


Faster, cheaper…secure?


A strong standard password is supposed to have at least 10 characters, made up of upper and lower case letters alongside numbers and symbols. Admin passwords are often even more complex.

With technology advancing at such a rate while simultaneously becoming cheaper, hackers can now harness more processors to crack even the toughest passwords.

This is why a two-way authentication process is so important. By backing up a standard character or pattern-based password with a unique, personal form of identification it becomes more difficult to be hacked.

This will be fundamental for admin systems, as once they are cracked open, hackers are free to take anything from a company’s electronic safe, including all the sensitive information stored there.

As the most frequently exploited attack surface, passwords assigned to local administrators should be the top priority for introducing a two-tiered security system.

Fight for your (admin) rights


Currently, introducing a password-based policy enforces something known as principle of least privileged. Essentially, this gives a user account only those privileges which are essential to their work.

This makes access to information dependent on fallible, character based passwords. Instead, businesses should introduce privilege control at the server and application level, which will enable IT departments to manage and control which applications run on endpoints and servers to prevent malicious applications from penetrating the system.

This is a very effective way to address the problem of password cracking, providing deeper defences against administrator hacks.

So while Google’s Trust API is only designed for smartphones at the moment, this could be the first step in wider usage, especially for enterprises who are most likely to be at target.

Future perfect?


While this technology certainly ensures greater security, it isn’t the silver bullet needed for a perfect IT security system. For example, while it prevents strangers hacking a network, people are still able download a virus or transfer files outside the proper channels.

Due to the influence and involvement of Google, a tech giant with huge prestige, it’s likely people in the near future will come to see behavioural monitoring as the new normal, and businesses will have to take up the practice as the trend proliferates, or be left behind.

Maybe Facebook will be one of the early adopters?

Wednesday, 25 May 2016

Microsoft seeks to mitigate laziness by banning popular passwords [Link - SC Magazine]

I was asked to comment on Microsoft banning people from using popular passwords, for SC Magazine: http://www.scmagazineuk.com/microsoft-seeks-to-mitigate-laziness-by-banning-popular-passwords/article/498670/

========================
I was asked to answer four questions:

Are there any security risks associated with Microsoft analysing passwords like this?
There is very little risk, as we are trusting Microsoft to store and secure that password, as it will need to be check every time it’s used.  Like all other systems, it’s just an algorithm to check how the password is structured.

Why is Microsoft doing this now and not a long time ago?
Insecure passwords have been a problem since there was a need for passwords.  SplashData do an annual review of the worse passwords people use and typically users will be blamed for using these sorts of passwords.  It is the provider/administrator that sets the stipulation of the password structure, so insecure passwords are due to bad standards.  Cybersecurity and data compromises are more common place, so it is good that Microsoft is taking action.

Is this a good idea?
It is definitely a good idea to increase the security of passwords, but if Microsoft were taking security more seriously, I’d want to see the use of two factor authentication.

Won't people just forget complex passwords more easily?
If the complexity increases too much then passwords will be written down.  The user needs to consider a move to a secure password vault, or the supplier needs to look to two factor authentication.

Thursday, 19 May 2016

100 Million LinkedIn Accounts for sale

It was reported in the news that 100 million LinkedIn Accounts were for sale on the Dark Web.

LinkedIn previously reset the passwords of those accounts they believed were compromised in 2012, but it seems many more accounts were compromised than previously believed.

LinkedIn's response should have been to reset all the users passwords and implemented better protection for the new passwords.

From a user perspective, we need to ensure we are using different passwords for each of our web services.  Why?  Well if your LinkedIn password is the same as your email provider, other social media accounts, cloud storage, etc, then the compromised password could be replayed into a number of websites and services to gain access to those.

Although it's not two-factor authentication, two-step verification will give some additional security to your LinkedIn account.  Not only will this add security to your account, it's also free.  The instructions to switch on two-step verification for LinkedIn is relatively straightforward.

Don't forget your other web accounts, as two step verification is available for Google, Facebook, Microsoft, Twitter and many other site.  If the websites and services you use aren't taking your security seriously, should you be using them?

Monday, 7 September 2015

Multi-factor authentication – a smart approach to IT security [Link - MTI Bytes]

Here is a repost of a piece I wrote for our work blog: http://www.mtibytes.com/post/Multi-factor-authentication-a-smart-approach-to-IT-security

=================

Last week, I wrote about the need for businesses to rethink the use of secret questions as a security measure. The Web and social media create a goldmine of user information, which astute hackers can access to answer security questions.

So, what is a preferable alternative for proving a user’s identity? One of the more effective methods is multi-factor authentication.

What is multi-factor authentication? 

Multi-factor authentication is a security system that requires two or more independent credentials to verify a user’s identity.

A user might, for example, be required to provide information that they already know, such as a username, password or PIN. Combined with this, they may be asked to provide information given to them from a token or device – a passcode sent via SMS to a known mobile phone, for instance.

Other authentication methods rely on something on the user or where the user is located, through measures such as biometrics, iris scans, fingerprint readers and geo-location.

A combination of any of these methods results in multi-factor authentication. It is currently widely used for personal services such as emails and banking. And in the US, there have been calls for the method to be issued directly for all forms of Internet banking. Such is the confidence in this form of security.

What are the benefits of multi-factor authentication? 

1. Proof and compliance 

With multiple authentication methods in place, it becomes more difficult for hackers to access the service or website. It also makes it harder to deny an action.

For example, many online banking systems use a combination of passwords, PINs, tokens, SMS and unique codes, to ensure transactions are genuine. By using multi-factor authentication, banks can tie their compliance processes to specific users so the actions cannot be denied.

2. Protection can be free 

Service providers such as Apple's iCloud, Gmail, eBay and Facebook have options to switch-on a two-step verification process. If a user tries to login from a new device, browser or different country, they will be prompted to enter a code, sent to their registered mobile phone number.  The security is there and it is free in many cases!

3. Cloud support

As more cloud-based applications like Salesforce and Microsoft Office 365 enter the workplace, security will become a more complex concern for IT decision-makers. Multi-factor authentication has a critical role to play in addressing some of these concerns. In fact, there are already products available, such as SAML, which offer multi-factor authentication and are designed specifically to support cloud applications.

What are you waiting for? 

Multi-factor authentication presents a very clear upgrade from the simple security question method. The shift to a multi-factor authentication method will add an extra layer of protection against security breaches. - See more at: http://www.mtibytes.com/post/Multi-factor-authentication-a-smart-approach-to-IT-security#sthash.2rXvOi3R.dpuf

Friday, 4 September 2015

4 simple tips for bolstering your business’ security [Link - MTI Bytes]

Here is a repost of a piece I wrote for our work blog: http://www.mtibytes.com/post/4-simple-tips-for-bolstering-your-business-security

=================

High-profile breaches continue to dominate the news agenda. Stories of compromises to email systems, retail outlets, Internet auction sites and Apple's iCloud service, show no online service is safe from hackers.

Many of these incidents are the result of accounts being far too easily accessible to hackers. Nowadays, these types of hacks are commonplace, and they will likely increase as social media uptake grows further. The more that users share personal information online, the more insecure security questions will become.

There are several issues associated with security question authentication that all businesses should address, through educating employees, as well as reviewing current security protocols and processes.

1. Avoid simple passwords

Despite repeated warnings from the IT industry, the most commonly used passwords in 2014 were ‘123456’ and ‘password’!  With the use of relatively simple passwords, IT security can be compromised within seconds using a dictionary attack.

2. Secret questions aren't so secret

On the surface, a personal security question may seem like a secure way to reset a password. However, what is often overlooked is the huge volume of personal information accessible via the Internet.

Consider, for example, the amount of information that Facebook alone archives about a user’s personal relationships, education, location, employment history and interests. Once a user’s information is out there, there is no way to control, edit or delete it.

A great example of this is the Paris Hilton phone-hacking scandal of 2005. In that case, the T-Mobile Sidekick device had an internet-facing dashboard. To recover their password, users had to answer security questions including what their date-of-birth and pet’s name was. In reality, all of Paris’ security questions could be answered via an Internet search engine!

3. Mix it up

There is always a balance between usability and complexity. We encourage people to use a mixture of upper and lower case letters, special characters and numbers. In reality, this usually results in more password resets, as complex passwords are easier to forget.

4. Be streetwise – does it seem phishy?

Users often receive emails that appear to be from their service provider. The email will stipulate an issue with their account and require an immediate password reset, change or confirmation.

The user will enter their password and be presented with a failed message screen or a confirmation. If the hacker is especially clever, they will synchronise the password with the service provider, so that everything appears normal.

Even with strong and complex passwords, users can still be victims of phishing.  To prevent phishing attacks, users should always check the legitimacy of emails before opening them. If it seems fishy (excuse the pun), ignore it or delete it.

Moving beyond security passwords

Security passwords were once a relatively secure concept. That was until the proliferation of digital technologies and social media took full effect. As security solutions become more complex, the methods of authentication will need to follow suit. In the next blog post, we’ll discuss how multi-factor authentication may be the way forward.