Showing posts with label hackers. Show all posts
Showing posts with label hackers. Show all posts

Thursday, August 23, 2012

Passwords Are Becoming Our Own Worst Enemy

Recent report shows we are not as secure as we think we are.


passwords
It seems that this year has been one of hackers gaining access to people's accounts because they have hacked into a server or some other activity like that. But, the reality may be much simpler than that and be tied to security and just how accounts we have and how many of those accounts have the same or very similar passwords. If you do not have some software which holds all your passwords for web accounts, you have a herculean task to remember all the passwords for each and every online account you have.

We have talked in the past about rethinking your password strategies because of all the hacking that is going on. Reusing passwords is something you should never do. If they get your password, they can try that on other online accounts they can figure out. Longer passwords are harder to crack and the complexity of the password is very important. But with all the online accounts we have, it makes it difficult to follow through on all of this.

According to a research study done back in 2007, they looked at users, online accounts and passwords. Back then, the study information determined that the average number of online accounts per user was about 25. Of those 25 online accounts, they determined that of those 25 accounts, a user had 6.5 passwords to access them. That means that passwords are being reused and that is very startling news to hear. And you have to remember that this is from back in 2007. I know that I have probably double or triple that number from 2007. And it continues to increase.

As the number of online accounts increase, the number of reused passwords is probably going to increase as well.

If you are not using complex passwords, you are probably in trouble already and do not know it. Hackers are getting far more sophisticated and can crack simple passwords like the ones shown above. Just how quickly can be debated, but will not be weeks, probably not days and be done to hours. In some cases, using dictionary lists for common passwords is will be less than a minute every time. That should scare all of us to change our password habits.

On the web, we keep hearing to not reuse passwords. That is the first thing to do. But human nature and just the sheer volume of accounts makes that pretty much impossible. The next thing to do is make sure that your passwords are complex. Do not using English words that dictionaries can look up and match. Even changing some characters to special characters or numbers is becoming easier to hack.

The best thing that you can do for yourself is to make your password long. Most people thought that a password of 6 characters would keep you safe. Not any more. Once you get to 8 characters, you have increased the amount of time for a hacker to brute force guess your password by at least 10 days, if not longer. Each character that you add after that increases the time significantly as long as it is not a recognizable word.

Given where things are at with hackers and everything that we are hearing in the news, your password should be longer than 8 characters. You should really try to not repeat passwords across online accounts or even variations of the same password across sites. You are asking for trouble if you are. If a hacker gets your password and you are doing that, odds are they are going to figure out how to access other online accounts you have.

We have to try and stay a few steps ahead of those trying to get access to our online accounts and what was consider safe a few years ago is no longer the case. Time to rethink how you are going to create complex passwords and not reuse them across online accounts.

Tuesday, August 7, 2012

Password Protection Is The Topic Of The Day

It seems that everyone is talking password security


Locks
This week, the big news seems to be how to make sure that you are protected. So much of that is because of the reports of Social Engineering of Apple support which allowed a hacked to gain control of someone else's account. They subsequently did a remote wipe of his iPhone, iPad and MacBook Air. On top of that, there are reports that Reuters news was hacked twice over the weekend. All of this brings the idea of security and passwords to the top.

Most of us really do not want to deal with passwords. To be good, they have to be hard to remember. And, you should not use the same password on more than one site. This is especially true for email. If you use online financial sites, your logon name and password cannot be duplicated anywhere else. One of the big items today is the two step authentication available in GMail. Not everyone takes advantage of it, but in the event that someone tries to do social engineering on a support person, this would go much further in stopping someone from getting your password that way.

Other reports have similar reports, such as one from PC World talking about your password risk. Even the security questions that most of us just breeze through can create problems for us. Things such as your mothers maiden name in this day of easily obtained information is not very secure. The name of your first school is probably something that you might have on Facebook already. People can comb the web and find this kind of information without too much trouble.

It seems that what worked a few years ago is no longer how you should do things. Things are now changing much faster than they were previously. And they look like they are going to continue to change at a rapid pace. Hackers are coming up with new ways to do things to get your password. We are now forced to pay far more attention to passwords and the need to change them on a periodic basis. We have to watch everything more closely.

Welcome to technology.

Saturday, August 4, 2012

Dropbox Admits Breach After Weeks Of Silence

Details review an employee logon was breached at Dropbox.


Dropbox Full
Dropbox is a great product and one that so many people have on their computers and mobile devices. They make it so easy to use and have versions for just about every computer and mobile device. And they are far ahead of all the others in this market in support different devices. So, it was a surprise when we started to hear about spam emails being sent to Dropbox customers, some with email addresses which are not used anywhere else. Then the concerns about a security breach of the company started coming out.

We reported on the hiring of security experts after the spam emails were being reported by many users in Europe. It was less than a week later where Dropbox reported they have not found any intrusions into systems which was supposed to put people at ease. In reality, it seem to cause far more concerns for those who were vocal about having private emails receiving spam.

For some, they had created an email specifically to be used for logging on to Dropbox and no where else. So, when they started receiving spam emails, the first thought was that Dropbox had been hacked. And that was a very reasonable conclusion. So, we finally have Dropbox reporting on what they found. They are admiting they were hacked. They point the finger at usernames and passwords stolen from other sites resulted in "some users accounts" being accessed by the hackers.

A much bigger revelation is that one of those stolen passwords from another site was used to gain access to the account of a Dropbox employee. And it was that logon which contained a marketing spreadsheet which contained a pretty good size list of names and email addresses. We had speculated that the user names came possibly from a single employee who was trying to make some money from selling them. We were off base on that, but pretty close that it involved a single employee.

We have been talking for several months about the need to have strong passwords in place because the skills of hackers are getting more sophisticated. The other item we have talked about is to not use the same logon and password across multiple sites. If one site gets hacked, they are going to try to use what they have gathered on many other sites to see if they can get in. And that is exactly what has happened in this situation. You need to reevaluate your passwords and strategies

Exactly what this will mean for Dropbox and how the public views them is an unknown. Given all the sites which have been hacked over the last year, everyone needs to step up their efforts to protect themselves. While Dropbox was hacked last month, it may be one of their competitors which will be hacked next month. It seems that hackers are going all out to try and gain access to companies to get logons and passwords. That has become the new reality for everyone. So your best defense is a strong password which is not duplicated across other sites.

Sunday, June 10, 2012

Password Strategies Being Improved On Sites

To stay ahead of hackers, security strategies must continue to improve


Password strategies changingWe have been talking about making sure that you take responsibility for your passwords for online accounts because you are the last line of defense against hackers. It is important to make sure that you do not duplicate the same passwords across online accounts because if they get your password on one account, they now have an advantage to gain access to another online account. But, with all the recent news of sites being hacked and files of passwords being taken, it causes one to be concerned as to what is being done to protect our online information beyond your having a unique and complex password to protect your online information. So, what are the companies doing to protect my password further than they are currently doing?

With the recent hacking of LinkedIn and eHarmony, exactly what are sites doing to protect our passwords from being taken and then used against us? Fortunately, there are things which can be done in this effort by companies. There are probably a few sites out there which continue to store a password in clear text. That is where it is stored in a database which if you could see it, would look exactly like you type it in. That is the worst situation, but not to fear as reputable sites are way beyond that. Just about every site on the web today is employing some form of hashing.

The idea of hashing is to combine the password with some other value (hash value) and come up with a fixed length value which is stored in the database. When you log on, the password you entered is combined with the hash and then compared with what is in the database. If they match, you are given access. The hash value is stored in code and not accessible by hackers. If hackers are able to get to the hashed password, they are going to have to figure out the hash value to unlock the password value. This has worked great for years, but as computer equipment gets faster and the hackers learn new skills, this method needs to be enhanced to protect us further.

With secure SSL (HTTPS) logons, we stop hackers from grabbing things from the Internet and using them. So hackers have to resort to hacking, either your local device or the servers where the passwords are stored. One the changes to the password storage is the use of encryption to protect your password further. This is accomplished by applying a private key to the password and changing every value in the file based on the private key. There are a number of variations of this, but you have to have the key to unencrypt the password to then be able to begin the validation process of authentication.

With the recent hacking of LinkedIn, they are working on new strategies for protecting passwords for their users. This includes a new technology called Salted Passwords. This one looks to hold the most promise for web sites to protect passwords from being stolen and then used. If you can make a stolen password from a site's database virtually unusable, you have protected your site's users and that is key. Notice that I said "virtually". At this point in the world, there is nothing which is 100% guaranteed as being unbreakable. Just look at all the hacking being done to some of the security agencies around the world.
There are many ways in which passwords can be stored, with varying levels of security. Salted password hashing uses a non-reversible hashing algorithm with the inclusion of a randomised element to make it more difficult to obtain user passwords.

One of the things which makes the salted passwords harder to crack is that another separate entry is stored along with the password for the salt value. This means that hackers are going to have to figure out how to crack the password, however it is changed to unreadable characters, and crack the salt value, however that was set to unreadable characters. This makes it much harder for a password to be cracked, though not impossible.

For now, the "Salt Passwords" provide hope to make it much more difficult for hackers to figure out your password. Once a company identifies they have been hacked, the salt passwords could give them far more time to notify all their users to change their passwords and prevent hackers from gaining access to individual logons. We can hope that even more methods are determined and employed to further stop hackers from taking advantage of passwords taken in mass from websites. Technology has to continually work to stay one step ahead of hacking and stolen password files.