Showing posts with label Passwords. Show all posts
Showing posts with label Passwords. Show all posts

Sunday, April 7, 2013

Passwords To Be Replaced With Biometrics & EyeVerify

EyeVerify PhonePasswords have been the primary means of securing computers, emails and web sites along with a large number of other things. And that has been the first line of defense for way too many years. As we gained more and more access points for web sites or emails, the goal of having a unique password for each one became a major problem and so many have duplicated passwords from time to time. There are even some who use the same password on every site or email account. And that is a bad thing if one site gets hacked and they have access to your password. Technology needs to evolve to something far better than what we currently have and Biometrics is the real answer for the future.

Things continually change as technology improves and a company called EyeVerify may be holding the most promise to moving us from the problems of remembering passwords and typing them in to a logon screen. Your eyes are unique to you as an individual and you do not have to remember a password. And with the technology they are using, they can prove who you are by combining several different features of your eyes. Those features include both the Iris in eye and the blood vessels of the eye.

Some have indicated that biometric scanning of the eyes can be fooled, but if the scanning process is looking at your eyes at different angles, fooling a scanner becomes far more difficult to accomplish. Scanners which can be fooled are not checking for what some refer to as "proof of life". By checking the location of blood vessels of the eyes, they are proving that it is a live person they are working with in combination with the angles of what they are recording.

It is the use of streaming video of your eye to move beyond the single picture for using biometrics which makes this method far more secure than previous methods which are being employed. And that video is key to what the future holds for moving us from the manual entry of passwords to the utilization of biometrics for validation of who you are. Just how soon we might see this kind of technology is not known as EyeVerify is partnering with various companies to move their product forward and into the market. This would be a big improvement over the current layers of security used to secure access to web sites and email. Or even access to your mobile device.

EyeVerify

Sunday, June 10, 2012

Password Strategies Being Improved On Sites

To stay ahead of hackers, security strategies must continue to improve


Password strategies changingWe have been talking about making sure that you take responsibility for your passwords for online accounts because you are the last line of defense against hackers. It is important to make sure that you do not duplicate the same passwords across online accounts because if they get your password on one account, they now have an advantage to gain access to another online account. But, with all the recent news of sites being hacked and files of passwords being taken, it causes one to be concerned as to what is being done to protect our online information beyond your having a unique and complex password to protect your online information. So, what are the companies doing to protect my password further than they are currently doing?

With the recent hacking of LinkedIn and eHarmony, exactly what are sites doing to protect our passwords from being taken and then used against us? Fortunately, there are things which can be done in this effort by companies. There are probably a few sites out there which continue to store a password in clear text. That is where it is stored in a database which if you could see it, would look exactly like you type it in. That is the worst situation, but not to fear as reputable sites are way beyond that. Just about every site on the web today is employing some form of hashing.

The idea of hashing is to combine the password with some other value (hash value) and come up with a fixed length value which is stored in the database. When you log on, the password you entered is combined with the hash and then compared with what is in the database. If they match, you are given access. The hash value is stored in code and not accessible by hackers. If hackers are able to get to the hashed password, they are going to have to figure out the hash value to unlock the password value. This has worked great for years, but as computer equipment gets faster and the hackers learn new skills, this method needs to be enhanced to protect us further.

With secure SSL (HTTPS) logons, we stop hackers from grabbing things from the Internet and using them. So hackers have to resort to hacking, either your local device or the servers where the passwords are stored. One the changes to the password storage is the use of encryption to protect your password further. This is accomplished by applying a private key to the password and changing every value in the file based on the private key. There are a number of variations of this, but you have to have the key to unencrypt the password to then be able to begin the validation process of authentication.

With the recent hacking of LinkedIn, they are working on new strategies for protecting passwords for their users. This includes a new technology called Salted Passwords. This one looks to hold the most promise for web sites to protect passwords from being stolen and then used. If you can make a stolen password from a site's database virtually unusable, you have protected your site's users and that is key. Notice that I said "virtually". At this point in the world, there is nothing which is 100% guaranteed as being unbreakable. Just look at all the hacking being done to some of the security agencies around the world.
There are many ways in which passwords can be stored, with varying levels of security. Salted password hashing uses a non-reversible hashing algorithm with the inclusion of a randomised element to make it more difficult to obtain user passwords.

One of the things which makes the salted passwords harder to crack is that another separate entry is stored along with the password for the salt value. This means that hackers are going to have to figure out how to crack the password, however it is changed to unreadable characters, and crack the salt value, however that was set to unreadable characters. This makes it much harder for a password to be cracked, though not impossible.

For now, the "Salt Passwords" provide hope to make it much more difficult for hackers to figure out your password. Once a company identifies they have been hacked, the salt passwords could give them far more time to notify all their users to change their passwords and prevent hackers from gaining access to individual logons. We can hope that even more methods are determined and employed to further stop hackers from taking advantage of passwords taken in mass from websites. Technology has to continually work to stay one step ahead of hacking and stolen password files.

Monday, May 7, 2012

Rethinking Your Password Strategies

As more sites are hacked and holes emerge in programs, changing how you think of passwords is critical.


 
The use of good passwords is the first line of defense you have to protect your information. It does not matter whether it is your password to log on to your computer, access your email over the web or your password to Social Networking sites. Each and everyone of them is your first line of defense to stop those who are up to no good. We have seen way too many breaches over the past 12 months making the whole idea of secure passwords far more important than they have ever been before.

Some parts of the problem are outside your control. As an example, when hackers gain access to a server which contains passwords of users, there is not much you can do about protecting yourself. The best thing is to change your password as soon as you hear about an event like this happening. Unfortunately, the trend is to not release information until days or weeks later and at that point, the damage has already been done. So, what are you to do to protect yourself. There are several strategies you can employee.

Do not reuse passwords

This is the first strategy you should employee. If you use the same password on your GMail account as you do on your Facebook account, you are asking for trouble. Some people use the same password across everything which requires one. That alone will cause you major problems if someone gets a list of passwords from a server and you are one of them. Hackers know that many people do not create unique passwords, but instead take the easy path. Keeping each password unique is very important.

Use a variety of characters to make a complex password

Some people only use letters to define their password. This makes it very easy for hackers to guess. You should include a variety of characters which includes letters (upper and lower case), numbers and special characters. I realize that some locations limit you on the special characters and some do not allow them at all. In those situations, you need to take other measures. Remember, you are trying to protect your information and that should make it critical to protect. So, do not use something that is easily guessed, like your first and last name put together.

Longer passwords are harder to crack

It used to be a password of 6 characters was consider to be safe. The number of characters necessary to protect your password is continuing to change. It used to be a lower length, but now a length of 12 characters is considered the minimum to be consider secure. That's right a minimum of 12. The majority of the population probably is not using a password that long. It makes it too hard to remember. The reason for the longer passwords is because the hackers tools have become more sophisticated, so you need to try and stay ahead of them. Software to maintain a list of your passwords may be something you should consider.

Password security questions

When you forget your password, there are many locations which give you the option of changing it. In those situations, they ask you questions when you set up your account. The key is to not create and answer questions which are easily guessed. Such as what elementary school did you go to is one that is seen a lot. If you put that information on your Facebook page, you just gave someone part of what they need to reset your password and log on to your account. It is important to create questions or provide answers which are not going to be easily guessed. One that I see a lot is what is your mother's maiden name. With so much information on the web, that one could probably be easily found and used. Do not put in a name that is easily found, but one that cannot be found. Yes, I am saying to not put in your mothers maiden name unless you want to have someone get into your account. Pick another name to put in so as to make it that much harder.

Password management software

There is a trend to use password management tools, such as RoboForm which has features to manage all your passwords and generate unique passwords for you. With something like this, you do not have to remember the logon and password once you set it up. You click on the item in the password management software and it goes to the site and logs you on. This is something which I see growing in need as longer passwords become the norm to protect your accounts. With this type of software, you only have to remember a single password rather than the passwords for each of your logons.

The landscape continues to change when it comes to passwords and you must adapt and adjust to protect yourself.

RoboForm: Learn more...