Wednesday, 30 August 2017
Phishing and passwords - 3 years on
Monday, 11 July 2016
EU General Data Protection Regulation (GDPR)
Data Protection Directive
Why GDPR important?
When will GDPR happen?
What is the impact of GDPR?
- A Data Protection Officer is needed if an organisation processes 5000+ EU data subjects; or employs more 250+ employees
- Mandatory disclosure of incidents within 72 hours to the national authority
- Maximum fines of up to €20 million or 4% of worldwide revenue
- “Right to be forgotten”: The data subject will have the right to retract consent, request data erasure or portability
- EU Referendum has no impact to organisations – If you hold personal data on an EU citizen, GDPR still applies
- Live May 2018 – Two budget cycles left
The Data Protection Officer
Disclosure and Notification
Fines
"Right to be Forgotten"
Outside of the EU
Is GDPR still required now that Brexit may happen?
Adopting GDPR
- Locate the critical data for GDPR
- Protect the data (and the applications that access it) through segmentation and/or encryption
- If encryption is used, ensure the encryption keys are secured
- Use strong Access Controls to servers holding the data, such as two factor authentication
- Use DLP/Insider Threat technology to prevent data exfiltration
- Monitor all exfiltration data channels, including web and email
- Collate logs from the network, so they can be analysed
- Secure domain and local administrator accounts
- Penetration test the environment
Final Thoughts
Saturday, 25 June 2016
Is the character password finally dead? [Link - IT ProPortal]
=============================
No more characters
Faster, cheaper…secure?
Fight for your (admin) rights
Future perfect?
Wednesday, 25 May 2016
Microsoft seeks to mitigate laziness by banning popular passwords [Link - SC Magazine]
========================
I was asked to answer four questions:
Are there any security risks associated with Microsoft analysing passwords like this?
There is very little risk, as we are trusting Microsoft to store and secure that password, as it will need to be check every time it’s used. Like all other systems, it’s just an algorithm to check how the password is structured.
Why is Microsoft doing this now and not a long time ago?
Insecure passwords have been a problem since there was a need for passwords. SplashData do an annual review of the worse passwords people use and typically users will be blamed for using these sorts of passwords. It is the provider/administrator that sets the stipulation of the password structure, so insecure passwords are due to bad standards. Cybersecurity and data compromises are more common place, so it is good that Microsoft is taking action.
Is this a good idea?
It is definitely a good idea to increase the security of passwords, but if Microsoft were taking security more seriously, I’d want to see the use of two factor authentication.
Won't people just forget complex passwords more easily?
If the complexity increases too much then passwords will be written down. The user needs to consider a move to a secure password vault, or the supplier needs to look to two factor authentication.
Thursday, 19 May 2016
100 Million LinkedIn Accounts for sale
LinkedIn previously reset the passwords of those accounts they believed were compromised in 2012, but it seems many more accounts were compromised than previously believed.
LinkedIn's response should have been to reset all the users passwords and implemented better protection for the new passwords.
From a user perspective, we need to ensure we are using different passwords for each of our web services. Why? Well if your LinkedIn password is the same as your email provider, other social media accounts, cloud storage, etc, then the compromised password could be replayed into a number of websites and services to gain access to those.
Although it's not two-factor authentication, two-step verification will give some additional security to your LinkedIn account. Not only will this add security to your account, it's also free. The instructions to switch on two-step verification for LinkedIn is relatively straightforward.
Don't forget your other web accounts, as two step verification is available for Google, Facebook, Microsoft, Twitter and many other site. If the websites and services you use aren't taking your security seriously, should you be using them?
Monday, 7 September 2015
Multi-factor authentication – a smart approach to IT security [Link - MTI Bytes]
=================
Last week, I wrote about the need for businesses to rethink the use of secret questions as a security measure. The Web and social media create a goldmine of user information, which astute hackers can access to answer security questions.
So, what is a preferable alternative for proving a user’s identity? One of the more effective methods is multi-factor authentication.
What is multi-factor authentication?
Multi-factor authentication is a security system that requires two or more independent credentials to verify a user’s identity.
A user might, for example, be required to provide information that they already know, such as a username, password or PIN. Combined with this, they may be asked to provide information given to them from a token or device – a passcode sent via SMS to a known mobile phone, for instance.
Other authentication methods rely on something on the user or where the user is located, through measures such as biometrics, iris scans, fingerprint readers and geo-location.
A combination of any of these methods results in multi-factor authentication. It is currently widely used for personal services such as emails and banking. And in the US, there have been calls for the method to be issued directly for all forms of Internet banking. Such is the confidence in this form of security.
What are the benefits of multi-factor authentication?
1. Proof and compliance
With multiple authentication methods in place, it becomes more difficult for hackers to access the service or website. It also makes it harder to deny an action.
For example, many online banking systems use a combination of passwords, PINs, tokens, SMS and unique codes, to ensure transactions are genuine. By using multi-factor authentication, banks can tie their compliance processes to specific users so the actions cannot be denied.
2. Protection can be free
Service providers such as Apple's iCloud, Gmail, eBay and Facebook have options to switch-on a two-step verification process. If a user tries to login from a new device, browser or different country, they will be prompted to enter a code, sent to their registered mobile phone number. The security is there and it is free in many cases!
3. Cloud support
As more cloud-based applications like Salesforce and Microsoft Office 365 enter the workplace, security will become a more complex concern for IT decision-makers. Multi-factor authentication has a critical role to play in addressing some of these concerns. In fact, there are already products available, such as SAML, which offer multi-factor authentication and are designed specifically to support cloud applications.
What are you waiting for?
Multi-factor authentication presents a very clear upgrade from the simple security question method. The shift to a multi-factor authentication method will add an extra layer of protection against security breaches. - See more at: http://www.mtibytes.com/post/Multi-factor-authentication-a-smart-approach-to-IT-security#sthash.2rXvOi3R.dpuf
Friday, 4 September 2015
4 simple tips for bolstering your business’ security [Link - MTI Bytes]
=================
High-profile breaches continue to dominate the news agenda. Stories of compromises to email systems, retail outlets, Internet auction sites and Apple's iCloud service, show no online service is safe from hackers.
Many of these incidents are the result of accounts being far too easily accessible to hackers. Nowadays, these types of hacks are commonplace, and they will likely increase as social media uptake grows further. The more that users share personal information online, the more insecure security questions will become.
There are several issues associated with security question authentication that all businesses should address, through educating employees, as well as reviewing current security protocols and processes.
1. Avoid simple passwords
Despite repeated warnings from the IT industry, the most commonly used passwords in 2014 were ‘123456’ and ‘password’! With the use of relatively simple passwords, IT security can be compromised within seconds using a dictionary attack.
2. Secret questions aren't so secret
On the surface, a personal security question may seem like a secure way to reset a password. However, what is often overlooked is the huge volume of personal information accessible via the Internet.
Consider, for example, the amount of information that Facebook alone archives about a user’s personal relationships, education, location, employment history and interests. Once a user’s information is out there, there is no way to control, edit or delete it.
A great example of this is the Paris Hilton phone-hacking scandal of 2005. In that case, the T-Mobile Sidekick device had an internet-facing dashboard. To recover their password, users had to answer security questions including what their date-of-birth and pet’s name was. In reality, all of Paris’ security questions could be answered via an Internet search engine!
3. Mix it up
There is always a balance between usability and complexity. We encourage people to use a mixture of upper and lower case letters, special characters and numbers. In reality, this usually results in more password resets, as complex passwords are easier to forget.
4. Be streetwise – does it seem phishy?
Users often receive emails that appear to be from their service provider. The email will stipulate an issue with their account and require an immediate password reset, change or confirmation.
The user will enter their password and be presented with a failed message screen or a confirmation. If the hacker is especially clever, they will synchronise the password with the service provider, so that everything appears normal.
Even with strong and complex passwords, users can still be victims of phishing. To prevent phishing attacks, users should always check the legitimacy of emails before opening them. If it seems fishy (excuse the pun), ignore it or delete it.
Moving beyond security passwords
Security passwords were once a relatively secure concept. That was until the proliferation of digital technologies and social media took full effect. As security solutions become more complex, the methods of authentication will need to follow suit. In the next blog post, we’ll discuss how multi-factor authentication may be the way forward.
Monday, 31 August 2015
Cloud services, Multi-factor authentication and the death of the security question
Accounts Compromised
Simple Passwords
Security (?) Questions
Complex Passwords, hard to remember?
Phishing
Multi Factor Authentication
Proof and compliance
Free protection
Consumerisation
Cloud Support
Impact to the business
Thursday, 15 January 2015
Death of the password? [Link - ITProPortal]
http://www.itproportal.com/2015/01/15/two-factor-authentication-death-p4ssw0rd/
Thursday, 4 September 2014
iCloud Compromise...
Accounts Compromised...
Simple Passwords...
Security (?) Questions...
Complex Passwords, hard to remember?
Phishing...
Two Factor Authentication...
Free protection...
Increase your security posture
Wednesday, 25 June 2014
Two Factor Authentication Revisted
Passwords are not secure
I talk about two factor authentication (or 2FA, as the kids and marketing people are calling it) a lot and with good reason, passwords are not secure!Sites like this give you an insight into how secure your password is:
https://howsecureismypassword.net
It also rightly states that sites can steal your password, and if they have it, it doesn't matter how strong it is they know it. It doesn't matter if my password takes seconds or years to crack, if the bad guys have it, they don't need to crack it.
What are the factors for authentication?
Authentication can be made up of multiple factors, and by using more than one of them (hence the term, two factor authentication) you are adding security and making it difficult for the bad guys to log in as you. The following are the factors:- Something you know
- Something you are given
- Something you are
- Somewhere you are
Something you know
This will include usernames, passwords, PINs, patterns, etc. This is information you could give to someone else and they could login as you.
Something you are given
If you have a bank account with one of the major banks, you will probably have a physical token or software token, which generates a seemingly random string of number. This is creating an OTP (or One Time Password) which has a limited lifespan before becoming invalid. This means that it can only be used in that moment in time. The OTP can also be delivered via SMS or telephone call.
Something you are
This is where we move into the realms of biometrics, where fingerprints, iris scans, voice scans, etc are used to authenticate you.
Somewhere you are
There are solutions that work in conjunction with GPS devices to locate you in the world, so that you are only able to login if you are in a specific area.
Two Factor Authentication as we know it
For two factor authentication, we traditionally work with the first two; Something you know and Something you are given. This is where to access the solution, you would need to provide a username, a password and an OTP. This is something I have been advocating for over eight years, as if I have your password I can login as you. With two factor authentication running, I would also need access to the device or software that is generating the OTP.Many high profile hacks have been done using administrative passwords, but if these were coupled with a OTP, it would have made it a lot more difficult to achieve.
Why use two factor authentication?
We understand the importance of it when it comes to money, so it's a given we should be using it for banking. In fact, many online gaming sites can issue tokens to secure your gambling or your online gaming persona.I use social media, where I use Facebook for family and friends, I have two Twitter accounts (one for work and one for play) and I use LinkedIn for work. All of these outlets say something about me, so if they were compromised, there would be a reputation issue I would need to tackle. Like most people have web based email and although there is nothing too precious there, I wouldn't necessarily want it opened up to all!
Who can offer two factor authentication?
Google: With the Google ecosystem, you have one password for a number of applications, so Google offer two factor authentication, whereby they will send a code to you via SMS. This is used in tandem with your username and password. It will mean that you will need your mobile with you to access the applications, but it saves having to carry additional tokens. http://www.google.com/landing/2step/LinkedIn: My professional profile is on this site, so the last thing I'd want is for it to be tampered with, so fortunately LinkedIn also offer the SMSing of a code to your mobile phone before you can login as you. http://blog.linkedin.com/2013/05/31/protecting-your-linkedin-account-with-two-step-verification
Facebook: Although this is less critical, I won't want people being able to manipulate my profile. I know Facebook have some good measures in place around logging in from countries you don't traditionally login from, but you can add two factor authentication for browsers that you haven't login from before. https://www.facebook.com/note.php?note_id=10150172618258920
These are just some examples of commonly used sites, but remember passwords are not secure. If we know this as a fact, why aren't more sites offering two factor authentication?
If you are looking to protect remote access solutions, internal applications, operating systems or even public cloud application, all of these can be protected with third party solutions provided by MTI.
Wednesday, 21 May 2014
eBay compromised...
Thursday, 26 January 2012
Is Two-Factor Authentication a commodity?
Thursday, 20 October 2011
“To The Cloud…”
- How do users connect to the solution?
- Are they using a username and password?
- How is your data protected?
- Who has access to your data?
- Is the data backed up?
- Is the data archived?
- Where can you access the data from?
- Are there multiple servers hosting your service?
- Are there multiple datacentres hosting your service?
Monday, 27 September 2010
Two Factor Authentication on GMail
This technology has been available for a while, but this should create greater awareness of two factor authentication, and in turn make more companies realise this is required for their websites, services, applications and SaaS/Cloud offerings.
Vasco can provide two factor authentication to remote access solutions, such as traditional IPSEC VPNs as well as SSL-VPNs. Vasco can provide two factor authentication to a whole network, using uniquely generated one time passwords to log into Windows instead of traditional passwords. More importantly Vasco can be used to protect web services and web applications. The one time passwords can be generated by hardware tokens, software tokens, tokens for mobile and smartphones, and even sent one time passwords via SMS.
Cloud maybe the next big thing as a delivery method, but what will you be using to secure it?
Wednesday, 17 February 2010
Two factor authentication tokens on iPhone
The other day after some prompting from the UK Vasco Technical Account Manager, I installed a Vasco Digipass for the iPhone. (Thanks Dan)
So now I have a demo Digipass on my phone, where I can use it for demonstration purposes. It was fairly straight forward, you need to download the app from the Apple AppStore and tap in a couple of codes to make it work. Obviously I need a Vasco server installed somewhere and install the relevant DPX file on it, so the token can be used.
Off the back of this success, I took the opportunity to install a Celestix HOTPin client on my iPhone as well.
Again, just download the iPhone client software from the Apple AppStore. You will need to ensure that the Celestix HOTPin server is running somewhere. Currently it can run on the Celestix WSA appliance, which negates the need for an additional server hardware. Once the server component is configured and users added to the system, it is ready to go.
I used the HOTPin client on the iPhone to communicate with my Celestix WSA appliance which is hosting the HOTPin server. It downloads the client.dat file onto the iPhone and the client then allows the phone to generate the one time passwords.
The Vasco token required a bit more information to set up and they have the advantage of being able to provide your users with hard tokens, software tokens, mobile phone tokens and OTP via SMS, all through a single server element and manage them from one console.
The Celestix is a more cost effective solution as the HOTPin server software can run on the Celestix WSA appliance and there is no server software cost as such. The only down side is that there is no hard token option, so you may encounter some friction from users as they will not want the HOTPin client installed on their own personal mobile devices, although you have the option for a software client on Windows or using OTP vis SMS.
Although both solutions support receiving the one time password via SMS, what happens if your users are in a mobile telephone blackspot?
- Posted using BlogPress from my iPhone
Wednesday, 16 September 2009
HA deployment of IAG, using CLB
We started by configuring the Celestix Load Balancer (also known as CLB), after configuring the solution we were informed that the internet lines would be a number of weeks away, and we would not know whether the IPs that would be provided would be either external internet facing IP addresses, or NAT'd internal addresses. Why would this be an issue?
Well the customer wanted four IAG portals to be created, and as each portal would have to be created on both appliances. With the CLB in front of the IAG appliances, the way the IP addresses are presented will impact on how to deploy the solution.
If the addresses are external facing, we would need 12 external IP address, three for each portal (one on each appliance, and one for the virtual IP). If the addresses are NAT'd, then there would only be a need for one external address as the virtual IP on each portal.
We only configured one IAG appliance, and then backed up and restored the configuration on the second IAG appliance. Obviously the IP addressing needs to be changed, and the certificate information to be modified, but that was pretty much it.
We were deploying OWA, Sharepoint, Citrix, Mapped Drives, File Access, RDP and an IIS based intranet site.
From an authentication perspective, we looked at AD, AD & HOTPin, AD & Vasco Middleware (RADIUS) and just HOTPin. As expected the authentication methods were straight forward and I got a chance to use HOTPin a bit more. We configured HOTPin on the primary box, and had the secondary box referencing the primary box. You only have to allow port 10000 access between the appliances, and using local administration credentials is fine. The only pain was HOTPin not scanning AD correctly in subtrees, which means each OU would need to be defined when importing users, but I'll let Celestix know about that.
We also encoutered the Java issue, so that was resolved using the fix from one of my previous blog posts.
We can only complete the deployment, once we know how the IPs will be presented.... which will also impact the way we can balance the load (do we use DSR or not, VRRP, Loopback adapter configuration, etc, etc).... Let's see!
Tuesday, 8 September 2009
IAG & VASCO?
Yes, IAG will work with VASCO!
VASCO Middleware and Identikey use the RADIUS protocol, and RADIUS can be configured as one of the authenication methods on IAG.
You will need to define the VASCO server, along with the correct ports and shared secret.
I would configure Windows AD authentication and VASCO, so the user would need to login with AD username, AD password and VASCO one time password.
In the past, I have installed VASCO Middleware on the IAG appliance, but this would be subject to the number of users/tokens required. Unless you are looking at single figures of VASCO tokens, I would recommend that the VASCO server be installed somewhere else.
Thursday, 27 August 2009
HOTPin.... two factor authentication from Celestix
As you may have a gathered I do a lot of work with the Celestix WSA appliance, deploying numerous solutions as well as carrying out proof of concepts and web demonstrations.
I've been trailing Celestix HOTPin for a little while on my demo Celestix WSA applaince. What is Celestix HOTPin?
Celestix HOTPin is a two factor authentication solution. Just to reitterate what different factors of authenication there are, we can provide:
- Something you know - Passwords, PINs, etc.
- Something you are given - One time passwords, tokens, etc.
- Something you are - Fingerprint, iris scan, etc.
To have a two factor authenication solution, you should ensure that your users utilise two of these methods as authenication.
Celestix HOTPin is a one time password (OTP) solution, but rather than use the traditional method of hardware tokens, the passwords are generated on soft tokens. A soft token, is a piece of code that can run on other hardware, rather than require a dedicated piece of hardware such as a token.
Celestix HOTPin will run on Blackberry, iPhone and Smartphone/Windows Mobile devices, as well as 32-bit Windows machine. The software can be protected with a PIN, so even if your mobile telephone or laptop is found, the PIN should protect the OTP from being generated.
If you have an SMS gateway (a device that can send text messages from your network) then OTP can be generated by Celestix HOTPin and SMS'd over to the mobile device. A great back up solution, which does not require software to be loaded on a mobile device, but no so great is your are in a reception blackhole unable to get a mobile signal!!
The Celestix HOTPin software currently integrates with the Celestix WSA appliance, which saves the need to additional hardware to run this solution. The software is managed centrally on the Celestix WSA appliance, via a very familiar interface if you are use to the Celestix products.
As mentioned before I have been running this on my trial appliance, where I have deployed both the 32-bit Windows client, and the Blackberry client. Both of them do exactly what you expect, they generate a OTP!!
In my demostration environment, I check for a number of items at the login page, including:
- Windows AD Username
- Windows AD Password
- Celestix HOTPin (PIN & OTP)
- CAPTCHA
I'm so happy with how easy it is to install and manage, I will be deploying this into my live environment that we use at e92plus.
If you want to see a demostration of the Celestix WSA appliance with the various authentication methods running, please contact www.e92plus.com and we organise a web demo.


