Showing posts with label two factor authentication. Show all posts
Showing posts with label two factor authentication. Show all posts

Wednesday, 30 August 2017

Phishing and passwords - 3 years on

Nearly three years ago, I wrote a blog piece about the compromise of iCloud accounts aka "The Fappening".  In the last 3 years there have been little improvement to the users interacting with phishing attacks, and it's disappointing to hear of the Fappening 2017.

Phishing
I've been guilty in the past to blame users for not checking the constructs of an email, and detecting incorrect domain names, etc, but with the technology available today, this shouldn't be the job of an email users.  Using a mainstream web-based email solution, these checks are done for you:


In a commercial environment, there are email filtering solutions to prevent the user from ever seeing these in the first place.

Passwords
The previous advice around regularly changing passwords may not have been the best, as people will just increment numbers, and typically the password will become weaker.  The advice now is to use stronger passwords and use a password manager to secure these passwords.

2-Step Verification
Many websites, including Facebook, LinkedIn, Twitter, WhatsApp and many more, support the use of 2-step verification.  This is a process where you log into one of these websites with your username/email address and your password.  Before you can gain access to the site or application, it will text your nominated mobile number with a code, which will need to be entered into the website before you can gain access.

Even if your login details were compromised, a hacker would be unable to gain access to the site or application without access to your mobile phone.

These solutions are provided free of charge, so it would make sense to enable this wherever possible.

So what?
So some people's iCloud accounts were compromised due to falling for a phishing attack... so what?

Well looking at security and the principles in play, this also makes corporate networks susceptible to these sorts of hacks.  Phishing attacks happen to gain access to corporate credentials, in fact worse so, as there are also spearphishing attacks.  Phishing attacks are typically broad brush attacks, spreading the net (excuse the pun) wide.  Spearphishing is targeting an individual, such as a member of the senior management team, or someone with administrative credentials, enabling access to personal information.

Privileged Access Management
The priority for any organisation, is the protection of administrative passwords, typically known as Privileged Access.  Depending on the analyst's reports you read, 80-100% of data exfilration compromises have required administrative credentials.

Privileged Access Management is a technology to grant administrative access to a user, without them knowing the password.  The technology will securely store the password, and is also able to change the password once the user is done with that session.  What could be more secure than a user unaware of the administrator password?  

Some other benefits include the ability to record the screen of the user session, as well as in depth analytics.

Securing passwords
Whether you are a home user, or a corporate user, passwords have always been important, but password security is more important than ever.  Whatever the situation, there are ways to secure the password and minimise the damage a hacker can do.

Monday, 11 July 2016

EU General Data Protection Regulation (GDPR)

Before I start on this blog piece, I have to make it clear that I'm not a lawyer and I have no legal training.  The blog piece below does not constitute as law, but these are areas I have researched and may make some assumptions along the way, especially with the uncertainty in the UK and it's relationship with the EU.


Data Protection Directive

The EU Commision were looking at replacing the Data Protection Directive.  So we are clear, an EU directive is a goal that the EU must achieve, but it's up to the individual countries to devise their own laws on how to reach the goal.

In January 2016, a draft form of the EU General Data Protection Regulation was released.  The difference between a directive and a regulation, is that an EU regulation is a binding act, that is applied in its entirety across the EU.

Why GDPR important?

GDPR is there to strengthen and unify data protection for individuals in the EU.  It addresses the export of personal data outside of the EU.

When will GDPR happen?

The regulation has now been released and enters into force on 25th May 2018


What is the impact of GDPR?

  • A Data Protection Officer is needed if an organisation processes 5000+ EU data subjects; or employs more 250+ employees
  • Mandatory disclosure of incidents within 72 hours to the national authority
  • Maximum fines of up to €20 million or 4% of worldwide revenue
  • “Right to be forgotten”: The data subject will have the right to retract consent, request data erasure or portability
  • EU Referendum has no impact to organisations – If you hold personal data on an EU citizen, GDPR still applies
  • Live May 2018 – Two budget cycles left

The Data Protection Officer

If the core activities of an organisation involves “systematic monitoring of data subjects on a larger scale”, or large scale processing of "special categories", such as racial/ethnic origin, political opinions, religious/philosophical beliefs, biometric data, heath/sex life or sexual orientation, then a Data Protection Officer is required.

The function is also there to advise on, and the monitoring of GDPR compliance, as well as representing the organisation when contacting supervising authorities.

Disclosure and Notification

The controllers are required to notify the appropriate supervisory authority of a personal data breach within 72 hours (at the latest) on learning about the exposure if it results in risk to the consumer. But even if the exposure is not serious, the company still has to keep the records internally.

According to the GDPR, accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data, the EU’s term for PII is considered a breach.

The GDRP notification is more than just reporting an incident, there is a need to include categories of data, records touched, and approximate number of data subjects affected. This will require detailed intelligence on what the hackers and insider were doing.

There is a term known as "Dwell time", which is the period of time that someone malicious is on your network and systems undiscovered.  Most people are shocked to learn that this on average is 206 days (from Cost of a Data Breach Study: Global Analysis, Ponemon Institute, 2015)

Fines

The GDPR has a tiered fine structure, so a company can be fined up to 2% for not having their records in order, not notifying the supervising authority and data subject about a breach or not conducting impact assessments, while more serious infringements merit a 4% fine. This includes violation of basic principles related to data security and conditions for consumer consent. 

The EU GDPR rules apply to both controllers and processors that are in “the cloud”. So cloud providers are not off the hook when it comes to GDPR enforcement.

"Right to be Forgotten"

Individuals can request the erasure of their personal data without undue delay by the data controller in certain situations. 

Consent can be withdrawn and no other legal ground for processing applies. This topic has attracted a huge amount of interest, particularly following the CJEU decision in the Google vs. Spain case.

Alongside this obligation is one to take reasonable steps to inform third parties that the data subject has requested the erasure of any links to, or copies of, that data.

Outside of the EU

The law applies to your company, even if it markets goods or services in the EU zone.  If you don’t have a formal presence in the EU zone but collect and store the personal data of EU citizens, GDPR still applies and the extra-territoriality requirement is especially relevant to ecommerce companies.

Is GDPR still required now that Brexit may happen?

If Article 50 is initiated in July 2016 & UK exits July 2018; GDPR will apply from May 2018. Also the UK were instrumental to writing and strengthening the GDPR.  Receiving personal data from EU member states would need to demonstrate to the European Commission that the law provides an adequate level of protection through its domestic laws or international commitments.

Source: Absolute Strategy Research Ltd

As you can see from the chart above, with many of the options open to the UK, compliance with EU regulation is required in order to trade with Europe.  In my opinion, GDPR will be relevant to the UK, and will need to be in place with UK organisations holding data of EU citizens.

Adopting GDPR

I believe there are some steps that will need to be taken with all organisations that wish to comply with GDRP:
  • Locate the critical data for GDPR
  • Protect the data (and the applications that access it) through segmentation and/or encryption
    • If encryption is used, ensure the encryption keys are secured
  • Use strong Access Controls to servers holding the data, such as two factor authentication
  • Use DLP/Insider Threat technology to prevent data exfiltration
  • Monitor all exfiltration data channels, including web and email
  • Collate logs from the network, so they can be analysed
  • Secure domain and local administrator accounts
  • Penetration test the environment

Final Thoughts

GDPR goes live in May 2018, which means there are two budget cycles left to get the education, processes, workflow and technology in place.  One of those budget cycles are underway already, so if GDPR planning hasn't begun, start it now, so you'll be ready for next years budget.

Saturday, 25 June 2016

Is the character password finally dead? [Link - IT ProPortal]

I was asked to write an article about passwords as organisations were looking to use more secure passwords, for IT ProPortal: http://www.itproportal.com/2016/06/25/is-the-character-password-finally-dead/

=============================

Passwords have been an essential part of our lives for a long time now, ensuring all our personal details are locked safely away from prying eyes. But, as recent hacks such as Mark Zuckerberg’s social media accounts have shown us, they are not infallible or, in some cases, even that secure.

The Facebook founder’s hack is an interesting case study of the dangers simple passwords pose, especially for high-profile individuals. While numerous, complicated passwords are difficult to remember, a simplified password used across multiple platforms leaves them very vulnerable to being hacked.

So Mr Zuckerberg might just welcome Google’s recent announcement that it is developing a new log-in method for smartphones. Called the Trust API, this latest security method could see the typical character based password rendered obsolete and replaced by an algorithm that learns a user’s behaviour.

No more characters


This is a massive step forward for online security, replacing passwords with a ‘trust-based’ system that monitors the way a user typically uses a smartphone.

According to Google, it checks personal indicators such as how you type and swipe as well as your location to continually monitor that it is definitely you holding and using the device, which makes it much harder to break into a lost or stolen phone.

Behavioural technologies such as this have been in development for some time and are already used in sectors that handle extremely sensitive materials, such as financial services industry. The unique activities of a user – such as keyboard typing patterns – are mapped out by the system, which is then matched every time that user tries to access data before entry is allowed.

While this is a fantastic move towards ensuring we do not become a victim to hacks and keep confidential materials behind closed doors, it raises questions about emergency access.

Behavioural monitoring can be quite tricky for the user, especially as people’s usual habits change in times of high stress, such as in an emergency situation, which could result in users being locked out of devices at the moment they desperately need to get in.

The acceptance of Google’s Trust API will most likely be dependent on finding a way to solve this issue without compromising security.


Faster, cheaper…secure?


A strong standard password is supposed to have at least 10 characters, made up of upper and lower case letters alongside numbers and symbols. Admin passwords are often even more complex.

With technology advancing at such a rate while simultaneously becoming cheaper, hackers can now harness more processors to crack even the toughest passwords.

This is why a two-way authentication process is so important. By backing up a standard character or pattern-based password with a unique, personal form of identification it becomes more difficult to be hacked.

This will be fundamental for admin systems, as once they are cracked open, hackers are free to take anything from a company’s electronic safe, including all the sensitive information stored there.

As the most frequently exploited attack surface, passwords assigned to local administrators should be the top priority for introducing a two-tiered security system.

Fight for your (admin) rights


Currently, introducing a password-based policy enforces something known as principle of least privileged. Essentially, this gives a user account only those privileges which are essential to their work.

This makes access to information dependent on fallible, character based passwords. Instead, businesses should introduce privilege control at the server and application level, which will enable IT departments to manage and control which applications run on endpoints and servers to prevent malicious applications from penetrating the system.

This is a very effective way to address the problem of password cracking, providing deeper defences against administrator hacks.

So while Google’s Trust API is only designed for smartphones at the moment, this could be the first step in wider usage, especially for enterprises who are most likely to be at target.

Future perfect?


While this technology certainly ensures greater security, it isn’t the silver bullet needed for a perfect IT security system. For example, while it prevents strangers hacking a network, people are still able download a virus or transfer files outside the proper channels.

Due to the influence and involvement of Google, a tech giant with huge prestige, it’s likely people in the near future will come to see behavioural monitoring as the new normal, and businesses will have to take up the practice as the trend proliferates, or be left behind.

Maybe Facebook will be one of the early adopters?

Wednesday, 25 May 2016

Microsoft seeks to mitigate laziness by banning popular passwords [Link - SC Magazine]

I was asked to comment on Microsoft banning people from using popular passwords, for SC Magazine: http://www.scmagazineuk.com/microsoft-seeks-to-mitigate-laziness-by-banning-popular-passwords/article/498670/

========================
I was asked to answer four questions:

Are there any security risks associated with Microsoft analysing passwords like this?
There is very little risk, as we are trusting Microsoft to store and secure that password, as it will need to be check every time it’s used.  Like all other systems, it’s just an algorithm to check how the password is structured.

Why is Microsoft doing this now and not a long time ago?
Insecure passwords have been a problem since there was a need for passwords.  SplashData do an annual review of the worse passwords people use and typically users will be blamed for using these sorts of passwords.  It is the provider/administrator that sets the stipulation of the password structure, so insecure passwords are due to bad standards.  Cybersecurity and data compromises are more common place, so it is good that Microsoft is taking action.

Is this a good idea?
It is definitely a good idea to increase the security of passwords, but if Microsoft were taking security more seriously, I’d want to see the use of two factor authentication.

Won't people just forget complex passwords more easily?
If the complexity increases too much then passwords will be written down.  The user needs to consider a move to a secure password vault, or the supplier needs to look to two factor authentication.

Thursday, 19 May 2016

100 Million LinkedIn Accounts for sale

It was reported in the news that 100 million LinkedIn Accounts were for sale on the Dark Web.

LinkedIn previously reset the passwords of those accounts they believed were compromised in 2012, but it seems many more accounts were compromised than previously believed.

LinkedIn's response should have been to reset all the users passwords and implemented better protection for the new passwords.

From a user perspective, we need to ensure we are using different passwords for each of our web services.  Why?  Well if your LinkedIn password is the same as your email provider, other social media accounts, cloud storage, etc, then the compromised password could be replayed into a number of websites and services to gain access to those.

Although it's not two-factor authentication, two-step verification will give some additional security to your LinkedIn account.  Not only will this add security to your account, it's also free.  The instructions to switch on two-step verification for LinkedIn is relatively straightforward.

Don't forget your other web accounts, as two step verification is available for Google, Facebook, Microsoft, Twitter and many other site.  If the websites and services you use aren't taking your security seriously, should you be using them?

Monday, 7 September 2015

Multi-factor authentication – a smart approach to IT security [Link - MTI Bytes]

Here is a repost of a piece I wrote for our work blog: http://www.mtibytes.com/post/Multi-factor-authentication-a-smart-approach-to-IT-security

=================

Last week, I wrote about the need for businesses to rethink the use of secret questions as a security measure. The Web and social media create a goldmine of user information, which astute hackers can access to answer security questions.

So, what is a preferable alternative for proving a user’s identity? One of the more effective methods is multi-factor authentication.

What is multi-factor authentication? 

Multi-factor authentication is a security system that requires two or more independent credentials to verify a user’s identity.

A user might, for example, be required to provide information that they already know, such as a username, password or PIN. Combined with this, they may be asked to provide information given to them from a token or device – a passcode sent via SMS to a known mobile phone, for instance.

Other authentication methods rely on something on the user or where the user is located, through measures such as biometrics, iris scans, fingerprint readers and geo-location.

A combination of any of these methods results in multi-factor authentication. It is currently widely used for personal services such as emails and banking. And in the US, there have been calls for the method to be issued directly for all forms of Internet banking. Such is the confidence in this form of security.

What are the benefits of multi-factor authentication? 

1. Proof and compliance 

With multiple authentication methods in place, it becomes more difficult for hackers to access the service or website. It also makes it harder to deny an action.

For example, many online banking systems use a combination of passwords, PINs, tokens, SMS and unique codes, to ensure transactions are genuine. By using multi-factor authentication, banks can tie their compliance processes to specific users so the actions cannot be denied.

2. Protection can be free 

Service providers such as Apple's iCloud, Gmail, eBay and Facebook have options to switch-on a two-step verification process. If a user tries to login from a new device, browser or different country, they will be prompted to enter a code, sent to their registered mobile phone number.  The security is there and it is free in many cases!

3. Cloud support

As more cloud-based applications like Salesforce and Microsoft Office 365 enter the workplace, security will become a more complex concern for IT decision-makers. Multi-factor authentication has a critical role to play in addressing some of these concerns. In fact, there are already products available, such as SAML, which offer multi-factor authentication and are designed specifically to support cloud applications.

What are you waiting for? 

Multi-factor authentication presents a very clear upgrade from the simple security question method. The shift to a multi-factor authentication method will add an extra layer of protection against security breaches. - See more at: http://www.mtibytes.com/post/Multi-factor-authentication-a-smart-approach-to-IT-security#sthash.2rXvOi3R.dpuf

Friday, 4 September 2015

4 simple tips for bolstering your business’ security [Link - MTI Bytes]

Here is a repost of a piece I wrote for our work blog: http://www.mtibytes.com/post/4-simple-tips-for-bolstering-your-business-security

=================

High-profile breaches continue to dominate the news agenda. Stories of compromises to email systems, retail outlets, Internet auction sites and Apple's iCloud service, show no online service is safe from hackers.

Many of these incidents are the result of accounts being far too easily accessible to hackers. Nowadays, these types of hacks are commonplace, and they will likely increase as social media uptake grows further. The more that users share personal information online, the more insecure security questions will become.

There are several issues associated with security question authentication that all businesses should address, through educating employees, as well as reviewing current security protocols and processes.

1. Avoid simple passwords

Despite repeated warnings from the IT industry, the most commonly used passwords in 2014 were ‘123456’ and ‘password’!  With the use of relatively simple passwords, IT security can be compromised within seconds using a dictionary attack.

2. Secret questions aren't so secret

On the surface, a personal security question may seem like a secure way to reset a password. However, what is often overlooked is the huge volume of personal information accessible via the Internet.

Consider, for example, the amount of information that Facebook alone archives about a user’s personal relationships, education, location, employment history and interests. Once a user’s information is out there, there is no way to control, edit or delete it.

A great example of this is the Paris Hilton phone-hacking scandal of 2005. In that case, the T-Mobile Sidekick device had an internet-facing dashboard. To recover their password, users had to answer security questions including what their date-of-birth and pet’s name was. In reality, all of Paris’ security questions could be answered via an Internet search engine!

3. Mix it up

There is always a balance between usability and complexity. We encourage people to use a mixture of upper and lower case letters, special characters and numbers. In reality, this usually results in more password resets, as complex passwords are easier to forget.

4. Be streetwise – does it seem phishy?

Users often receive emails that appear to be from their service provider. The email will stipulate an issue with their account and require an immediate password reset, change or confirmation.

The user will enter their password and be presented with a failed message screen or a confirmation. If the hacker is especially clever, they will synchronise the password with the service provider, so that everything appears normal.

Even with strong and complex passwords, users can still be victims of phishing.  To prevent phishing attacks, users should always check the legitimacy of emails before opening them. If it seems fishy (excuse the pun), ignore it or delete it.

Moving beyond security passwords

Security passwords were once a relatively secure concept. That was until the proliferation of digital technologies and social media took full effect. As security solutions become more complex, the methods of authentication will need to follow suit. In the next blog post, we’ll discuss how multi-factor authentication may be the way forward.

Monday, 31 August 2015

Cloud services, Multi-factor authentication and the death of the security question

Mainstream news has covered many compromises of internet facing services over the last five years.  This has included compromises of email systems, retail outlets, Internet auction sites and last year Apple's iCloud service, which led to a number of private photographs being exposed to the public.  The first assumption was that iCloud was hacked or compromised, which Apple denied.

Accounts Compromised

Rather than iCloud in its entirety being compromised, the compromise was to individual accounts.  It is assumed that the celebrity accounts were compromised with a brute force attack, allowing multiple tries of various passwords to each account.  This meant with the right software toolset which could be acquired cheaply, meant that numerous passwords could be tried against each account.

Simple Passwords

Despite education from service providers and IT departments, the most commonly used passwords in a recent 2014 survey are "123456" and "password"!  With relatively simple passwords or common words, the password can easily be compromised quickly using a dictionary attack in a matter of seconds.

Security (?) Questions

There are many ways to recover a password.  It may be to request a new password and the service delivers the new password or asked for confirmation via an out of bound method, such as the registered email address or registered mobile number via SMS.  There may be a need to telephone a call centre and provide details over the telephone to reset your password.  The least secure is the ability to answer security questions that the user has the answer. 

It may seem like a secure way of resetting a password, as how many people would know your mother's maiden name, where you were born, what your favourite football team is, etc?  The internet and social media has been great in many respects, but it exposes a lot of information about an individual out into the wild.  Once it's out there, there is no way to control, edit or delete it.  Bear this in mind if you have to use to methodology for any website or application.

It would seem that this current compromise is a new thing, but something very similar happened over ten years ago when Paris Hilton's mobile phone was hacked in 2005.  How was this done?  The T-Mobile Sidekick device had an internet facing dashboard.  If you forgot your password, you could answer some security questions including date of birth and your pet's name.  All the security questions could be answered with an internet search engine.

Even before then, hackers were wise to how to gather this sort of personal information.  Around 15 years ago, there were email chains on how to generate your pornstar name.  You took your first pet's name and combine it with your mother's maiden name.  Information such as "Fido Jones" would have been very useful!

Complex Passwords, hard to remember?

As the levels of security have to rise, so this can only make it more difficult to use the services or applications.  There is always a balance between usability and complexity.  We can encourage people to use a mixture of upper and lower case, special characters and numbers, but will only mean more password resets these complex passwords will be forgotten more easily.

Also common advice is not to use the same password over multiple applications and services.  This only increases the users capacity to forget a password!

Phishing

Even with strong and complex passwords in place, the user can still be a victim of a phishing attack.  We are reminded to check the legitimacy of an email before acting on it, and if it seems fishy (excuse the pun) to ignore it or delete it. Many people have fallen for one of the simplest tricks, as the email looks so legitimate.

The bad guy sends out emails that looks like an email from the service provider.  It tells the user that there is some sort of issue with the account that requires a password reset/change/confirmation.  The user will enter their password which is stored by the bad guy.  The user will be presented with either a failed message screen, a confirmation all is OK and if they were clever, even synchronise the password with the service provider, so all seems right for the user.

Multi Factor Authentication

There are various ways or factors, when authenticating users.  So one form this can take is "Something you know", where the information is known, such as username, password, PINs and patterns.  

Another form this information can take is "Something you're given", where the information is provided to the user through technology, such as a passcode from a token, a passcode from a device such as a smartphone or computer, or a passcode set via SMS to a known mobile telephone number.  If the known information and the provided information are different types of information, or factors, it becomes clear where the term two factor authentication comes from.  

Other factors can include "Something you are" through the use of biometrics, through iris scans, fingerprint readers, voice recondition and other forms tied to the physicality of the user.  There also ways of analysing "Somewhere you are" through the use of geolocation, thereby allowing or denying access by the users location.

A combination of these authentication methods, or factors create Multi Factor Authentication (MFA)

Proof and compliance

With the factors of authentication described above, it would be harder for a hacker to access the service or website, but would also make it hard to deny an action.  Many online banking systems uses a combination of passwords, PINs, tokens, SMS and unique codes to ensure transactions are genuine.  By using multi factor authentication, the processes within compliance processes can be tied to specific users and the actions cannot be denied.

Free protection

Service providers such as Apple's iCloud, GMail, eBay and Facebook give the option to switch on two-step verification, where if you try to login from a new device, a new browser or a different country, the user will be prompted to enter a code that is sent to the registered mobile phone number.  The security is there and it's free.

The use of multi factor authentication is accepted as commonplace and widely used for by users for personal services, such as email and banking.

Consumerisation

Recent technology adoption within a corporate environment has been driven by domestic technology.  The rise of wireless, tablet and mobile computing has been driven from the use of these technologies within the domestic environment.

There is often a concern that the user community with an organisation struggles with new technology, but it's often the enforcement of unfamiliar technology that causes the user to become disengaged.

The use of multi factor authentication can only strengthen a network or website, and with this technology used for personal consumption, the use corporately will offer less resistance from the user community, especially if there is a familiarity with the technology.

Cloud Support

As more corporate applications move to the Internet, cloud security becomes the concern of every IT Manger, IT Director, CSO, CISO, and in fact every member of an executive team.

As cloud based applications such as Salesforce and Microsoft Office 365 become popular, it is essential to remember these applications are the very lifeblood of an organisation.  The need for security and multi factor authentication become more apparent when looking to protect these web based applications. There are protocols such as SAML designed to support cloud applications, and offer multi factor authentication.

Impact to the business

A poorly designed or poorly designed solution will impact the user adoption of any technology, but a familiar system will offer acceptance and executive sponsors.  Security is high on the executive boards agenda, so the impact of a compromise or a disgruntled employee is greater than financial considerations such as return on investment. 

Multi factor authentication is not new, but is an obvious solution the the many security challenges for organisations, whether the data and applications are located on premise, in data centres, in public cloud, in private cloud or a hybrid approach.  Security is no longer the concern of technical sponsors, but of the Executive Board.

Familiar security solutions such as Multi Factor Authentication, can only increase the security posture of an organisation, protecting the data and reputation of an organisation. 

Thursday, 15 January 2015

Death of the password? [Link - ITProPortal]

I was asked to write an article about two factor authentication and the death of the password.  It was an edited version of an old blog post, but still as relevant as ever.

http://www.itproportal.com/2015/01/15/two-factor-authentication-death-p4ssw0rd/

Thursday, 4 September 2014

iCloud Compromise...

The mainstream news has covered the compromise of iCloud, which led to a number of private photographs being exposed to the public.  The first assumption was that iCloud was hacked or compromised, but Apple denies this.

Accounts Compromised...

Rather than iCloud in its entirety being compromised, the compromise was to individual accounts.  It is assumed that the celebrity accounts were compromised with a brute force attack, allowing multiple tries of various passwords to each account.  This meant with the right software toolset which could be acquired cheaply, numerous passwords could be tried against each account.

Simple Passwords...

It would seem that celebrities are very much like the general public when it comes to passwords.  There are commonly used passwords, the top 25 of 2013 can be found here.  From that article you see the commonly used passwords are "123456" and "password"!  With relatively simple passwords or common words, they can easily be compromised using a dictionary attack

Security (?) Questions...

There are many ways to recover a password.  It may be requested a new password which the site or application will ask you to subsequently change.  There may be a need to telephone a call centre and provide details over the telephone to reset your password.  The least secure in my opinion, is the ability to answer security questions that the user has the answer.

This would seem like a secure way of resetting a password, as how many people would know your mother's maiden name, where you were born, what your favourite football team is, etc?  The internet and social media has been great in many respects, but it exposes a lot of information about an individual out into the wild.  Once it's out there, there is no way to control, edit or delete it.  Bear this in mind if you have to use to methodology for any website or application.

It would seem that this current compromise a is new thing, but something very similar happened over nine years ago when Paris Hilton's mobile phone was hacked in 2005.  How was this done?  The T-Mobile Sidekick device had an internet facing dashboard.  If you forgot your password, you could answer some security questions including date of birth and your pet's name.  All the security questions could be answered with an internet search engine.

Complex Passwords, hard to remember?

As the levels of security have to rise, so this can only make it more difficult to use the services or applications.  There is always a balance between usability and complexity.  We can encourage people to use a mixture of upper and lower case, special characters and numbers, but will only mean more password resets these complex passwords will be forgotten more easily.

Also common advice is not to use the same password over multiple applications and services.  This only increases the users capacity to forget a password!

Phishing...

News has come to light this morning that rather than a brute force attack, it may have been a phishing attack.  We are reminded to check the legitimacy of an email before acting on it, and if it seems fishy (excuse the pun) to ignore it or delete it.  Some celebrities may have fallen for one of the simplest tricks.

The bad guy sends out emails that looks like an email from Apple.  It tells the user that there is some sort of issue with the account that requires a password reset/change/confirmation.  The user will enter their password which is stored by the bad guy.  The user will be presented with either a failed message screen, a confirmation all is OK and if they were clever, even synchronise the password with Apple, so all seems right for the user.

Two Factor Authentication...

I have written a few blog posts in the past regarding passwords and multi-factor authentication, but it's relevant to re-cap it.  It we look at the different types of information that can be used to log a user in, we can take different types of information in order to increase security.  So one form this can take is information the user knows, such as username, password, PINs and patterns.  Another form this information can take is information a piece of technology gives the user, such as a passcode from a token, a passcode from a device such as a smartphone or computer, or a passcode set via SMS to a known mobile telephone number.  If the known information and the provided information are different types of information, or factors, it becomes clear where the term two factor authentication comes from.

Free protection...

I've mentioned it before, but service providers such as Apple's iCloud, GMail, eBay and Facebook give the option to switch on two-step verification, where if you try to login from a new device, a new browser or a different country, the user will be prompted to enter a code that is sent to the registered mobile phone number.  The security is there and it's free!

Increase your security posture

Be aware of the security questions you choose to to use.  Are the answers to your security questions available from the likes of Facebook and Twitter?

Be aware of emails asking for password changes.  Double check with the service provider.

If you want to use more complex passwords, but are worried about remembering them all, use a password vault to store these passwords securely.

Although two factor authentication may add a slight delay to using the service, it gives a level of protection that will make it a lot more difficult to compromise your personal information, your data and in this case, your personal photos.

Wednesday, 25 June 2014

Two Factor Authentication Revisted

Passwords are not secure

I talk about two factor authentication (or 2FA, as the kids and marketing people are calling it) a lot and with good reason, passwords are not secure!

Sites like this give you an insight into how secure your password is:
https://howsecureismypassword.net

It also rightly states that sites can steal your password, and if they have it, it doesn't matter how strong it is they know it.  It doesn't matter if my password takes seconds or years to crack, if the bad guys have it, they don't need to crack it.

What are the factors for authentication?

Authentication can be made up of multiple factors, and by using more than one of them (hence the term, two factor authentication) you are adding security and making it difficult for the bad guys to log in as you.  The following are the factors:

  • Something you know
  • Something you are given
  • Something you are
  • Somewhere you are

Something you know
This will include usernames, passwords, PINs, patterns, etc.  This is information you could give to someone else and they could login as you.

Something you are given
If you have a bank account with one of the major banks, you will probably have a physical token or software token, which generates a seemingly random string of number.  This is creating an OTP (or One Time Password) which has a limited lifespan before becoming invalid.  This means that it can only be used in that moment in time.  The OTP can also be delivered via SMS or telephone call.

Something you are
This is where we move into the realms of biometrics, where fingerprints, iris scans, voice scans, etc are used to authenticate you.

Somewhere you are
There are solutions that work in conjunction with GPS devices to locate you in the world, so that you are only able to login if you are in a specific area.

Two Factor Authentication as we know it

For two factor authentication, we traditionally work with the first two; Something you know and Something you are given.  This is where to access the solution, you would need to provide a username, a password and an OTP.  This is something I have been advocating for over eight years, as if I have your password I can login as you.  With two factor authentication running, I would also need access to the device or software that is generating the OTP.

Many high profile hacks have been done using administrative passwords, but if these were coupled with a OTP, it would have made it a lot more difficult to achieve.

Why use two factor authentication?

We understand the importance of it when it comes to money, so it's a given we should be using it for banking.  In fact, many online gaming sites can issue tokens to secure your gambling or your online gaming persona.

I use social media, where I use Facebook for family and friends, I have two Twitter accounts (one for work and one for play) and I use LinkedIn for work.  All of these outlets say something about me, so if they were compromised, there would be a reputation issue I would need to tackle.  Like most people have web based email and although there is nothing too precious there, I wouldn't necessarily want it opened up to all!

Who can offer two factor authentication?

Google: With the Google ecosystem, you have one password for a number of applications, so Google offer two factor authentication, whereby they will send a code to you via SMS.  This is used in tandem with your username and password.  It will mean that you will need your mobile with you to access the applications, but it saves having to carry additional tokens. http://www.google.com/landing/2step/

LinkedIn: My professional profile is on this site, so the last thing I'd want is for it to be tampered with, so fortunately LinkedIn also offer the SMSing of a code to your mobile phone before you can login as you. http://blog.linkedin.com/2013/05/31/protecting-your-linkedin-account-with-two-step-verification

Facebook: Although this is less critical, I won't want people being able to manipulate my profile.  I know Facebook have some good measures in place around logging in from countries you don't traditionally login from, but you can add two factor authentication for browsers that you haven't login from before. https://www.facebook.com/note.php?note_id=10150172618258920

These are just some examples of commonly used sites, but remember passwords are not secure.  If we know this as a fact, why aren't more sites offering two factor authentication?

If you are looking to protect remote access solutions, internal applications, operating systems or even public cloud application, all of these can be protected with third party solutions provided by MTI.

Wednesday, 21 May 2014

eBay compromised...

Today, eBay made the news as it was announced that their database had been compromised.  Personal information had been stolen, including names, addresses, email address, phone numbers, date of birth and an encrypted copy of the users password.  The breach was believed to have occurred between late February to early March.

If you have an eBay account, the first thing to is change your password.  

Depending on the level of encryption, all that is needed to crack the password is time and processing power.  Although the PayPal database is separate and has not been compromised, I would highly recommend changing that password, if it matches your eBay account.

Although my PayPal account rarely has much money left in it, it was only protected with a password.  After today, this was changed to send me a code via SMS when I log in, so I require my password and my mobile phone to gain access to the account now.  You can activate that on your account here,

How was eBay compromised?  Some of the eBay user credentials were obtained and used to carry out the compromise.

We've yet to find out how, but I suspect that it was either someone aware of the eBay way of working, or it obtained via a spear-phishing attack.  Spear-phishing is where specific people are targeted, where the people are either known, or information has been gathered from public sources, such as social media.  Once aware of information relating to the user, they can be targeted by many means, including email.  Typically when the user falls for the trap, software will be deployed onto their computer and the target monitored.  Credentials can be gathered and then used against the organisation the hacker is targeting.

Lockheed Martin pioneered the Cyber Kill Chain where there are seven steps to the potential compromise, and the aim is to break the chain at any one of the seven points.  The sooner, the better.

Another concern is that most organisations would require users to have privileged (such as system administrator) access to be able to access such information.  There are solutions out that that can could have prevented this by managing the password on behalf of the user. 

I'm sure more information regarding the compromise will come to light over next few weeks.  It's surprising that more protection and prevention hasn't been deployed, but being a large organisation like eBay they will always be targeted.


Thursday, 26 January 2012

Is Two-Factor Authentication a commodity?

The complexity with passwords

We all know we need secure passwords, or at least keep them secret.  The problem is that we are asked to increase the complexity of passwords, either with the addition or inclusion of upper case characters, lower case characters, special characters or numbers.    Making the passwords more complex must increase security… or does it lead to users writing the passwords down or recycling the same passwords for a number of environments?

“Something you know, Something you are given, Something you are”

Obviously one of the downsides with passwords is that they can be passed from person to be person, but you lose the accountability of the actions from the user who has logged in.  This is where the requirement for multi-factor authentication arose, so there would be a number of elements to confirm the validity of the person and action.

Multi-factor authentication is said to be made up with two of the follow three elements.  “Something you know”, such as passwords and PINs, “Something you are given”, such as one time passwords, and “Something you are”, such as iris and fingerprint scans.

Some people will such that using multiple of the same type of authentication, such as the use of multiple passwords and PINs, would make it multi-factor.  I disagree, and would call that “Strong authentication” or I’ve heard of it referred to as “1.5 factor authentication”. 

Two-Factor Authentication requires a specialist?

In the past, there was a high level of complexity associated with two-factor authentication and should only be tackled by specialists within the field.  In the past, there were complicated multi-server implementations to build resiliency, administering more databases, managing a variety of tokens and that even before anything is deployed or secured!!

Hacked… June 2011!

Undoubtedly, most people reading this will be aware of a compromise that was reported in June 2011, where one of the world’s largest token vendor had (reportedly) 40 million tokens compromised.  Suddenly all that hard works seems to have been for nothing.  What did all the complexity bring, other than complexity for complexities sake?

Commoditised market?

There are a number of vendors offering two-factor authentication, but most organisations see it as a must have, rather than a want to have.  The barriers to entry were not only complexity, but security, administration time and in the current economic climate, cost.

Cloud or On-premise?
A cloud service will reduce the hardware cost, the running cost, power, energy, and all the other benefits associated with moving to a host solution.  There is always a concern about physical security, so ensure the provider meets the right criteria and standards.  There will be concerns around uptime, so ensure there is a good SLA in place.  With data security, ensure data is encrypted and not sent to the internet in clear text.

If these concerns are insurmountable, then look at an on-premise solution, but ensure the solution is highly available, if the access is business critical.  Ensure that the administrators looking after the solution can manage it correctly, or have the relevant support contracts to provide this.

It would be useful to have a choice of platforms, whether it is cloud or on-premise.

Ease of use?
In most IT environments we have to manage multiple systems, so we all want an easy to use system.

An intuitive, simple to use management console, with good help features, as well platform parity between the cloud and on-premise solution would be the way forward.

Token options?
Some providers will only offer hardware tokens, some will offer software tokens, some will offer tokens to run on mobile devices, some will offer SMS and/or email tokens, some will offer OATH tokens, and some will offer grid tokens.

What does your user base need?  What mix of tokens is required?  Will there be a company policy to define the type of tokens that will be offered?  What sort of mobile phones need to run tokens?

The preference would be to have all the token types available, but have them at an attractive price point.

Event or Time-based?
To simplify the way a one-time password is generated.  With time based, it take the time, encrypts it using a seed and an algorithm, to generate the one-time password.  With event base, it takes a pseudo-random value encrypts it using a seed and an algorithm, to generate the one-time password.

There are arguments for both solutions, with the time-based potentially going out of sync, or event-based where the password is valid until it is used.  More of a concern is the seed that are pre-populated onto the token, as if that were compromised; someone with it can potentially generate your one-time password!

Ideally, you want to ability to choose either time-based or event-based authentication, and have the ability to generate your own seeds, so even the two-factor authentication vendor would not know it.

Authentication Methods?
Most solutions support RADIUS; some will support Windows logon; some will support integration with OWA, SharePoint, IIS, Apache; some will support Citrix; and occassionally support SAML.
You don't want to be limited with what you can authenticate with, but want a solution that will support standards such as SAML, as this will be used more and more as cloud application usage increases.

Longevity?
With so many new start-ups and small organisations now around, and the largest two-factor authentication vendor being compromised, it is difficult to know who to trust!

We want a vendor with a good security history, but with the foresight to innovate, develop and implement solutions for the future.

Cryptocard
Offering a cost effective solution, with large variety of tokens, with the ability to choose either a cloud-based or on-premise platform, with an easy to use interface, the ability to have either time-based or event-based tokens, the ability to populate the tokens with your own seed, support a large number of applications and standards, from a company that has been around for over 21 years, makes Cryptocard the solution that should be considered first.

Thursday, 20 October 2011

“To The Cloud…”


For the last year or so, it seems marketing people have moved away from terms such as “... as a Service”, and replaced the words with Cloud.

We are seeing hosted applications, hosted infrastructure, hosted servers, hosted platforms, managed services, VPNs, MPLS networks, distributed networks, hosted virtual servers, remote VDI solutions, all termed with the phrase Cloud.

I understand the drivers that are used to move services out of your own server room, by lowering infrastructure costs, moving capital expenditure to operational expenditure, upgrading or downsizing by modifying your service plan, removing running costs (such as air conditioning, trained server administrators, etc.), having your systems monitored and changing applications on the fly.

I have a few issues with Cloud offerings, which include:

Authentication
  • How do users connect to the solution? 
  • Are they using a username and password?  

There are many issues around authentication, such as weak or insecure passwords, using common words, using easy to guess words (such as favourite bands, football teams, children’s names, car, etc.) and that’s before the fact the password can be told to someone else. 

People often talk about multi-factor authentication, but to surmise it, the factors are “something you know” such as passwords and PINs, “something you’re given” such as a one time passwords from a token, or “Something you are” where biometric devices are used to read fingerprints or iris scanners.

A combination of two of these will be known as two factor authentication, where passwords are coupled with a token generated one time password, offering much improved security.

Encryption
  • How is your data protected?
  • Who has access to your data?

With the Information Commissioner’s Office issuing fines of up to £500,000 for the loss of personal data, it is more critical than ever data is encrypted. 

I would expect the data to be encrypted with to a minimum level of 256-bit AES, although another consideration who has access to your data.  It may be encrypted, but if the key is held by the service provider, then they will have the ability to decrypt your data.

Backup and Archive
  • Is the data backed up?
  • Is the data archived?

Your data should be backed up regularly, giving a point in time that the data can be restored to.  The issue with back up is that it will back up current data, but the ability to roll back and restore can be more destructive and time consuming than working round the missing/lost/corrupted data.

If your data was archived, then it would offer the ability to manage and archive all versions of the data.  Archiving is driven by compliancy and traceability, rather than disaster recovery.

Access to the service
  • Where can you access the data from?

It would be great to be able to access your service from anywhere in the world, wouldn’t it?  A concern is that although this great for remote users, should everyone be able to have access?  Data security may dictate that the service or data should not be access from non-trusted IP addresses, or by specific users or during specific times.  If this level of control is required, ensure your provider is able to deliver this.

Disaster Recovery
  • Are there multiple servers hosting your service?
  • Are there multiple datacentres hosting your service?

One of the draws with a Cloud offering include having your applications and services available from anywhere, so there perfect disaster recovery solution.

The issue will be when the provider has a server failure.  Will they be able to move your service to a new server in a timely fashion?  Whether the services are being run on virtual or physical servers, ensuring your service up time is vital. 

Another concern will be if the provider only has one datacentre or one WAN connection, so if there service is delivered well I would expect multiple datacentres, with multiple links running an active/active configuration, along with an active/active or active/passive server configuration.

Conclusion
My concern with Cloud solutions is the number of providers who are “jumping on the bandwagon” offering cloud services as quickly as possible.  The issue is that some providers offer very favourable pricing, but the infrastructure may not be in place until there is some uptake.  This can only be a bad thing for the early adopter, especially if it is not making money and they stop the service or become bankrupt.

My advice is to proceed with caution, check the provider thoroughly and try not to be price driven.

Monday, 27 September 2010

Two Factor Authentication on GMail

An interesting article about Google protecting Google Apps, which includes GMail, with a one time password sent to your mobile phone:  http://www.scmagazineuk.com/google-adds-two-factor-authentication-to-gmail-via-sms-one-time-passwords/article/179266/

This technology has been available for a while, but this should create greater awareness of two factor authentication, and in turn make more companies realise this is required for their websites, services, applications and SaaS/Cloud offerings.

Vasco can provide two factor authentication to remote access solutions, such as traditional IPSEC VPNs as well as SSL-VPNs.  Vasco can provide two factor authentication to a whole network, using uniquely generated one time passwords to log into Windows instead of traditional passwords.  More importantly Vasco can be used to protect web services and web applications.  The one time passwords can be generated by hardware tokens, software tokens, tokens for mobile and smartphones, and even sent one time passwords via SMS.

Cloud maybe the next big thing as a delivery method, but what will you be using to secure it?

Wednesday, 17 February 2010

Two factor authentication tokens on iPhone

I've been playing with the iPhone recently and I've been very impressed with the amount of applications you can get for the phone.

The other day after some prompting from the UK Vasco Technical Account Manager, I installed a Vasco Digipass for the iPhone. (Thanks Dan)

So now I have a demo Digipass on my phone, where I can use it for demonstration purposes. It was fairly straight forward, you need to download the app from the Apple AppStore and tap in a couple of codes to make it work. Obviously I need a Vasco server installed somewhere and install the relevant DPX file on it, so the token can be used.

Off the back of this success, I took the opportunity to install a Celestix HOTPin client on my iPhone as well.

Again, just download the iPhone client software from the Apple AppStore. You will need to ensure that the Celestix HOTPin server is running somewhere. Currently it can run on the Celestix WSA appliance, which negates the need for an additional server hardware. Once the server component is configured and users added to the system, it is ready to go.

I used the HOTPin client on the iPhone to communicate with my Celestix WSA appliance which is hosting the HOTPin server. It downloads the client.dat file onto the iPhone and the client then allows the phone to generate the one time passwords.

The Vasco token required a bit more information to set up and they have the advantage of being able to provide your users with hard tokens, software tokens, mobile phone tokens and OTP via SMS, all through a single server element and manage them from one console.

The Celestix is a more cost effective solution as the HOTPin server software can run on the Celestix WSA appliance and there is no server software cost as such. The only down side is that there is no hard token option, so you may encounter some friction from users as they will not want the HOTPin client installed on their own personal mobile devices, although you have the option for a software client on Windows or using OTP vis SMS.

Although both solutions support receiving the one time password via SMS, what happens if your users are in a mobile telephone blackspot?


- Posted using BlogPress from my iPhone

Wednesday, 16 September 2009

HA deployment of IAG, using CLB

I spent the last couple of days in Wakefield, helping out a reseller with a high available deployment of Celestix WSA appliances using Celestix Load Balancers. Thanks for the company David!! :)

We started by configuring the Celestix Load Balancer (also known as CLB), after configuring the solution we were informed that the internet lines would be a number of weeks away, and we would not know whether the IPs that would be provided would be either external internet facing IP addresses, or NAT'd internal addresses. Why would this be an issue?

Well the customer wanted four IAG portals to be created, and as each portal would have to be created on both appliances. With the CLB in front of the IAG appliances, the way the IP addresses are presented will impact on how to deploy the solution.

If the addresses are external facing, we would need 12 external IP address, three for each portal (one on each appliance, and one for the virtual IP). If the addresses are NAT'd, then there would only be a need for one external address as the virtual IP on each portal.

We only configured one IAG appliance, and then backed up and restored the configuration on the second IAG appliance. Obviously the IP addressing needs to be changed, and the certificate information to be modified, but that was pretty much it.

We were deploying OWA, Sharepoint, Citrix, Mapped Drives, File Access, RDP and an IIS based intranet site.

From an authentication perspective, we looked at AD, AD & HOTPin, AD & Vasco Middleware (RADIUS) and just HOTPin. As expected the authentication methods were straight forward and I got a chance to use HOTPin a bit more. We configured HOTPin on the primary box, and had the secondary box referencing the primary box. You only have to allow port 10000 access between the appliances, and using local administration credentials is fine. The only pain was HOTPin not scanning AD correctly in subtrees, which means each OU would need to be defined when importing users, but I'll let Celestix know about that.

We also encoutered the Java issue, so that was resolved using the fix from one of my previous blog posts.

We can only complete the deployment, once we know how the IPs will be presented.... which will also impact the way we can balance the load (do we use DSR or not, VRRP, Loopback adapter configuration, etc, etc).... Let's see!

Tuesday, 8 September 2009

IAG & VASCO?

Another search phrase that I thought I could answer!

Yes, IAG will work with VASCO!

VASCO Middleware and Identikey use the RADIUS protocol, and RADIUS can be configured as one of the authenication methods on IAG.

You will need to define the VASCO server, along with the correct ports and shared secret.

I would configure Windows AD authentication and VASCO, so the user would need to login with AD username, AD password and VASCO one time password.

In the past, I have installed VASCO Middleware on the IAG appliance, but this would be subject to the number of users/tokens required. Unless you are looking at single figures of VASCO tokens, I would recommend that the VASCO server be installed somewhere else.

Thursday, 27 August 2009

HOTPin.... two factor authentication from Celestix

As you may have a gathered I do a lot of work with the Celestix WSA appliance, deploying numerous solutions as well as carrying out proof of concepts and web demonstrations.

I've been trailing Celestix HOTPin for a little while on my demo Celestix WSA applaince. What is Celestix HOTPin?

Celestix HOTPin is a two factor authentication solution. Just to reitterate what different factors of authenication there are, we can provide:

  • Something you know - Passwords, PINs, etc.
  • Something you are given - One time passwords, tokens, etc.
  • Something you are - Fingerprint, iris scan, etc.

To have a two factor authenication solution, you should ensure that your users utilise two of these methods as authenication.

Celestix HOTPin is a one time password (OTP) solution, but rather than use the traditional method of hardware tokens, the passwords are generated on soft tokens. A soft token, is a piece of code that can run on other hardware, rather than require a dedicated piece of hardware such as a token.

Celestix HOTPin will run on Blackberry, iPhone and Smartphone/Windows Mobile devices, as well as 32-bit Windows machine. The software can be protected with a PIN, so even if your mobile telephone or laptop is found, the PIN should protect the OTP from being generated.

If you have an SMS gateway (a device that can send text messages from your network) then OTP can be generated by Celestix HOTPin and SMS'd over to the mobile device. A great back up solution, which does not require software to be loaded on a mobile device, but no so great is your are in a reception blackhole unable to get a mobile signal!!

The Celestix HOTPin software currently integrates with the Celestix WSA appliance, which saves the need to additional hardware to run this solution. The software is managed centrally on the Celestix WSA appliance, via a very familiar interface if you are use to the Celestix products.

As mentioned before I have been running this on my trial appliance, where I have deployed both the 32-bit Windows client, and the Blackberry client. Both of them do exactly what you expect, they generate a OTP!!

In my demostration environment, I check for a number of items at the login page, including:

  • Windows AD Username
  • Windows AD Password
  • Celestix HOTPin (PIN & OTP)
  • CAPTCHA

I'm so happy with how easy it is to install and manage, I will be deploying this into my live environment that we use at e92plus.

If you want to see a demostration of the Celestix WSA appliance with the various authentication methods running, please contact www.e92plus.com and we organise a web demo.