Showing posts with label Passwords. Show all posts
Showing posts with label Passwords. Show all posts

Thursday, August 30, 2007

Passwords Written Down, Real Life Real Risk



I sound like a broken record sometimes. I get sick of hearing myself speak too. I will say it again because it is of utmost importance:

People, please STOP writing passwords down!

Here is a real-life example of a written down password that could have very easily led to over $500,000 in theft.

The Incident
I get the call all of the time. Someone calls to report (anonymously) that they have found a password written down on a laptop. As always, I initiate an investigation to determine the extent of the risk to the company I am contracted to work for. Upon arrival at the site of the laptop, I notice various passwords written down on stickers just to the right of the mouse/thumbpad.



Typically, the passwords I find pose more risk to the company (i.e. Active Directory passwords, VPN passwords, etc.) than they do to the individual at fault, but this one was different. My eye was immediately drawn to one written password entry, it read:

E-TRADE: etrade.com
EXERCISE PASSWORD: 88946571335
USER ID: jdoe
PASSWORD: jdoeDoneB4d

NOTE: These user IDs and passwords have been modified for the sake of this article. The actual user IDs and passwords on the stickers were different.

Naturally, I want to find out who this person is. After searching everywhere within the company and interviewing numerous people I had run out of options. I think to myself, self “The user name and password can’t still be valid, can they?” I decide to try. I go to http://www.etrade.com/. Oh %^$*@! They are valid! Upon login, I get confronted with the “Complete View” account page.



$492,640.25 worth of risk! Now I can find the user however, which is my main motivation. Obviously the first thing to do is have the user change their password, which they did. I spent a good amount of time with the user explaining what could have happened if this information fell into the wrong hands and gave them some alternative methods for password management. I am not sure if it sunk in or not, but it felt good to help for now!

How did the laptop end up where it was?
This is the question I would be asking myself. Through investigation it was discovered that the laptop was turned in to the help desk for normal hardware rotation. The user basically sends their old laptop to the help desk for a new one, which is common every couple of years. The help desk placed the old laptop in storage then brought it out as a loaner for a contractor.

Why didn’t the help desk remove the stickers and inform Information Security personnel when the laptop was returned for recycling?
Another good question. Because sometimes people forget that information security is EVERYONES job. People need to understand what role they play because we all play one. I have found through experience that an effective training and awareness program goes a long way. Training and awareness conducted correctly could have stopped the user from writing their passwords down in the first place and may have reminded help desk to remove and report.

Conclusion
I have given this much thought over that last few days. It really bugs me when people fall victim to scams, thieves, and the like. There is no sense in making it easy for them! People write down passwords because they typically do not know of a better way to manage all of their passwords. Can we blame them? See my previous article "Passwords Part 3/3 - Password Management" for some suggestions.

In hind sight I should have not logged into the account to find the username. This poses a risk to myself. Next time I will call eTrade and inform them of the username and password found on the laptop. I hope there won't be a next time, but I would to too naive to believe so.

Read more!

Thursday, June 7, 2007

Password on a Post-It Note

Sheesh! This is the song that never ends, it just goes on and on my friends...

I don’t think anything in this business torques this ISO more than a user that blatantly writes their password on a Post-It note and prominently displays it somewhere around their workstation. I could preach this until I am blue in the face, but people are people.

I bring this up again and again, but this week I encountered a couple of things that got my blood boiling again on this very topic.

The Survey
Early this week I was reading a recent survey from Cyber-Ark, an authentication management company. Obviously the section in the article titled “Post-It Notes: The IT Favorite for Storing Passwords” caught my eye immediately. The IT favorite? You have to be kidding me.

“It seems that very little changes year over year - more than half of people still keep their passwords on a Post-It note, in spite of all the education and reminders to do differently. What's shocking about this year's annual survey was that the 50% number now applies to IT Professionals as well! More than half of respondents admitted to using Post-It notes to store administrative passwords, the super-powerful codes pre-built into every system such the Administrator ID on your local workstation.” - Survey Reveals Scandal of Snooping IT Staff, 5/30/07 Cyber-Ark

50% of IT Professionals admitted that they store passwords (or have) on a Post-It note! How many do and didn’t admit it? Should I be surprised? I have to admit that I was a little taken aback.

An Incident
The same day I read the article mentioned above, I received a phone call from one of our IT staff in one of our offices. He was calling me to report a suspected incident that may have happened over the weekend. A computer was logged into after-hours and used to commit acts that are against our policy. I will leave it at that.

When I receive a call of a potential incident, I begin the incident response process and an investigation. During the course of the investigation it quickly becomes evident that I will not be able to prove who did what during the time in question. For one, all of the people who use(d) the computer in question use a shared account (another separate no-no out of the scope of this article), and two the shared username and password were written on a Post-It note next to the computer.

Physical security i.e. access card controls, CCTV, etc. aside; there is little that can be done to hold anyone accountable for the actions that took place during this incident.

Essentially, case closed with many possible ramifications.

What to do? Policy, Education, and Enforcement
If you do not have a password policy, you need one. In your password policy it must be clearly stated (simple terms) what actions are acceptable and what are not in regards to password creation, usage, re-use and destruction. Your policy must be endorsed by executive management of your company if you have any hope to educate your users and enforce with action.

If I have learned one thing in security, training and awareness cannot be understated. People are creatures of habit. People with bad habits need to learn good ones. The only way people learn good habits is through constant, consistent training and reinforcement. Your training and awareness program should constantly remind people what you have written in policy with real-world examples of how it applies to them.

Enforce your policy. Your password policy should be viewed as management’s expectations of acceptable behavior from your users. If management has truly endorsed your password policy, they should expect you to enforce it as well. Enforcement can range from a friendly reminder to termination, depending on the nature of the offense. No matter which method you attempt to use to enforce your policy, be consistent and include your human resources and legal department as necessary.

Keep in mind that policy, education and enforcement all go “hand-in-hand”. If you are lacking in one, the others will suffer.
Read more!

Friday, April 13, 2007

Top 10 Free security-related programs for every home user

There are certain security-related programs that all home users should have installed on their computers. Installing, configuring, and maintaining programs from each category listed in this article will provide a good base of protection for most.

This list and accompanying suggestions are based with Windows 2000 and XP operating systems in mind. Many of the suggested programs in this article will not work with Vista.

Did I mention free? I like free. Don’t get me wrong I also like to do my part in supporting the economy, but why pay for something if I don’t have to (legally).

1. Anti-Virus Software
Effective, up-to-date anti-virus software is a critical cog in your home information security machine. I would not suggest anyone using a Windows (or Mac and maybe Linux) computer without it, unless you want to lose your information, have your computer participate in a “bot” network, or send not-so-nice emails to everyone in your contacts list.

Free Programs
My favorite is Grisoft’s AVG Anti-Virus Free. AVG has all of the options to ensure “good” virus protection, the performance is above-average, and it has a pretty good detection rate. The only beef I have with AVG is the clunky interface, but it IS free. Other free programs worth checking out include avast! 4 Home Edition and PC Tools AntiVirus Free Edition

2. Anti-Spyware Software
The question I get often is “If I am using anti-virus do I still need anti-spyware, and if so why?” The answer is always yes, and the reason is because of the difference in the way viruses and spyware (and adware) operate. Virus spreads, spyware imbeds. Your anti-virus software will not protect you adequately from spyware.

Free Programs
CRAWLER, LLC’s Spyware Terminator – Spyware and adware have evolved so much that I don’t think any of the free anti-spyware applications on the market should be relied upon solely. Although my favorite free anti-spyware application is Spyware Terminator, I would suggest that you supplement its protection with another (AVG Anti-Spyware Free, Spybot Search and Destroy, Ad-Aware SE Personal, etc.)

3. Personal Firewall
Personal firewalls are an important complement to your home computer information security. They are especially important if you have an “always on” cable or DSL connection at home. You should expect a “good” personal firewall to perform well in monitoring each connection into and out of your computer and tie it to the application (process) making the request.

Free Programs
Far and away, my favorite free personal firewall is Comodo Firewall Pro. Comodo performs well in leaktests, has all of the necessary options, and comes with good support in the form of updates, forums, and email. Other good free personal firewall products include ZoneAlarm Free, PC Tools Firewall Plus, and Jetico Personal Firewall (the best performer in leaktests).

4. Browser
There is always plenty of contention and discussion when talking about which browser is best. Whether you choose Internet Explorer, Mozilla Firefox, Opera, or any other browser, each will have its advantages and disadvantages. I can say one thing from experience; I am not at all pleased with IE7 on Windows XP SP2. The performance is horrendous.

Free Programs
All of the major browsers are free now and there are well over 100 available online. Trying to determine which one is the most secure is a very hotly debated topic. The most secure browser depends on the person using it. My favorite browser for security is Opera 9.20 for Windows. Opera is fast, can be made relatively secure, and has plenty of options. Other popular browsers include Internet Explorer, Mozilla Firefox and Netscape Browser 8.1.3.

5. Anti-Spam
Most home users use web-based email. Many of these web mail solutions employ some anti-spam technology. For home users that use an email client such as Outlook or Outlook Express, an anti-spam program is a very good idea. Convergence between spam, virus, and spyware is predicted in coming months and years (we have seen some already), which makes an anti-spyware solution that much more valuable.

Free Programs
My favorite anti-spam program for Windows is SPAMfighter. SPAMfighter does an admirable job of filtering spam and has features out its ears. Other good anti-spam programs include SpamAware V4.5 and Agnitum Spam Terrier. Spam Terrier looks very promising. I have not fully tested it yet.

6. Password Management (see “Passwords”)
I don’t know about you, but I have way too many passwords to keep track of! I won’t right them down (because you aren’t supposed to, duh). I use different passwords for different logins. In order to maintain control of my passwords securely, a password management program is absolutely necessary.

Free Programs
RoboForm has emerged as a market leader in easy-to-use, secure password management. I use RoboForm daily and I would be lost without it. Another good password management program that I use is PasswordSafe made by renowned crypto-expert Bruce Schneier

7. Anti-Phishing Software
As the number and sophistication of phishing attacks grow, so will the number of victims that fall prey. As the number of victims that fall prey grows, so will the number of phishing attacks. A vicious cycle. There are programs designed to help identify probable phishing attacks and it’s a good idea to check them out. Personally, I have received phishing emails that have gotten through both Internet Explorer’s and Gmail’s built-in protection.

Free Programs
Phishing is a social engineering attack, so the best free tool you can use is in your head (:o .

Using a browser and web-based email that provide built-in phishing protection is a good idea, but if you still want additional protection take a look at the Netcraft Anti-Phishing Toolbar or Phishing Detector v.1.0.

8. Backup Software
I am not going to suggest any free backup software other than what you already have on your computer. Use Microsoft’s backup program that was included with your operating system (assuming Windows 2000 or XP). Click Start, Run, type “ntbackup” (no quotes) and click OK.


9. File Recovery Tool
A case could be made whether or not a good file recovery tool is essential to the security of your computer. Too many times have I been called by someone in a panic because they had deleted their important information. The more time that passes between the time your files were deleted and the time you attempt to recover them, the less chance there is to recover them without a significant amount of expense. Having a tool “at the ready” will help to avoid confusion and diffuse the situation somewhat.

Free Programs
Be careful which file recovery tool you choose. Choosing the wrong one can make your problems worse. Also, install your program and test it out before a crisis. This way you will be that much more prepared. Convar’s PC Inspector File Recovery 4.x is one of my favorite free file recovery programs and their Smart Recovery program works well for flash media (i.e. photos from camera or video recorder).

WARNING: If your files are absolutely critical to you and you do not feel comfortable using a program on your own, call a professional.

10. Encryption Program
Being an information security guy, I do love me some good encryption! Encryption used properly will protect the confidentiality and integrity of your data. Essentially, your files will not be understood to anyone not authorized by you. If you store highly confidential data (i.e. tax documents, electronic bank statements, etc.), I would strongly suggest you encrypt it.

Free Programs
I have been using Axantum Software AB’s AxCrypt File Encryption Software for a long time and I have been very pleased with it. Another good free file encryption program is Cypherix Cryptainer LE. For those of you wanting to encrypt the entire drive for free, you can try CE-Infosys’ FREE CompuSec. If you are going to go for the “full disk” option, be sure to read the manual first (i.e. disable anti-virus during install)!

BONUS - Diagnostics
Sometimes a problem crops up and it gets misdiagnosed. In order to help determine what the root cause of a problem is, I need to gather as much pertinent information as I can about the problem. A good diagnostics tool helps accelerate this process.

Free Programs
There are hundreds of free diagnostic programs out there. Picking one as my favorite will surely draw some fire. Not being faint of heart, my favorite free diagnostic utility is System Information for Windows (SIW 1.67) written by Gabriel Topala. Much of what you will be looking for in a diagnostic program will be dependent upon your circumstances.


So there is my top ten, which is subject to change of course!

Keep in mind that this software is what I would recommend to a home computer user on a budget. The toolset I use in my work is more vast (i.e. audit tools, scanners, sniffers, compilers, etc.).

To the best of my knowledge, all of the software listed here is offered free to home users (i.e. non-commercial). Check with each individual developer to make sure you are using their software in compliance with their license.
Read more!

Thursday, April 5, 2007

Passwords Part 3/3 - Password Management

Too many times have I seen passwords written on a Post-it note. Too many times have I heard one person give another person their password. Too many times have I been asked for my password from Help Desk personnel.

Oooooh Boy! I have to tell you that nothing tans my hide or boils my blood more than a password written down on a piece of paper! Then I tell myself to calm down and take the ISO hat off for a minute. Many people don't know any better. Others may know better, but how else will they remember 10, 20, 30 or more passwords? Especially if they are all supposed to be "strong"? To make matters worse, I suggest using a different password for each different login.

Why do I suggest a different password for each different login?
Simple answer, to limit the damage. If one of my passwords is compromised only that account is compromised, not all my accounts.

I suppose I should also mention what I mean by "password management". In a nutshell, password management is ensuring the confidentiality of your passwords from their creation through to disposal. Basically, keeping a password secret from the time I think of it until I no longer use it and everything in between.

I have a lot of accounts! I have 59 passwords that I need to keep track of, and each one needs to be "strong". Can you imagine how bad it would look if the "security guy" had his password disclosed? I have a very limited memory as surely my wife would agree. There is no way I will remember 59 passwords. I'm lucky to remember one! Is there something I can use to store my passwords securely and allow me to access them when I need to?

Yep, enter personal password management programs. A good personal password management program will:

  • Be easy to use
  • Store my passwords using encryption. If implemented correctly, this measure will prevent someone else from accessing my passwords.
  • Give me the ability to copy and paste passwords. I like this feature because it is quicker and defeats simple keyloggers.
  • Have the built-in ability to make secure backups of my passwords. Secure backups mean that the backup data will be encrypted.

So, which programs do I use?

I use a combination of two programs for personal password management. I use RoboForm for the management of my Web site/browser-based usernames and passwords and I use Password Safe for the management of all other passwords. I can recommend either or both of these programs because I have used them extensively. As with most things, you may find something you like better.

Through the use of a secure password management program, I can store all of my passwords safely. I only need to remember the one password that opens access to all of the others. Easy, right?

Well, there you go. Passwords are a necessary evil for us all, but the pain can be reduced somewhat. Remember to make backups your passwords!

Read more!

Wednesday, April 4, 2007

Passwords Part 2/3 - Strong Passwords

Let's begin where we left of yesterday. As you might recall, I mentioned two factors that are important to ensuring password confidentiality. One of which was using "strong" passwords. Also from yesterday's post we learned that maintaining confidentiality of our passwords is paramount to maintaining authentication (proof of identity) integrity.

A few questions come to mind when I think of strong passwords. What is a "strong" password? How does a "strong" password help to protect the confidentiality of the password? How do I choose a "strong" password that I can remember? The answers to these three questions is in essense the meaning of this article. So, let's get some answers then!

What is a strong password?
In the simplest terms, a "strong" password is one that is not easily guessed, and cannot be easily "cracked". Cracked!?!? What is "cracked"? There are numerous methods of cracking passwords (I won't elaborate, but can through email). In simplistic terms, traditional password cracking employs a program that continually tries combinations of letters, numbers, etc. until it makes a password match. This brings to mind another question, what makes a password strong?:

  • Length, the longer a password is the harder it is to guess. I recommend a password longer than 8 characters
  • Use letters, numbers, and symbols (!@#$%&^). A greater variety of letters, numbers, and symbols = less length required = same password strength.
  • Do not use words that you can find in a dictionary.

This might make better sense if I give you some examples of "strong" and "not so strong" passwords.

Not so strong password examples:
John1970 (could be easily guessed and not so hard to crack)
144WestMain (could be easily guessed and not so hard to crack)
ChelseaMichaelMarthaBob (nice and long, but still easy to guess and crack)

Strong password examples:
J0hnSm1th!97O
i44W3stM4!n
Ch3ls3a!Micha3l!Martha!Bob!

See the difference?

How does a "strong" password help to protect the confidentiality of the password?
Not taking into account what I do with the password (Next installment, Passwords Part 3/3 - Password Management), using a strong password reasonably assures the confidentiality of the password.

How do I choose a strong password that I can remember?
My best trick is to take a phrase that is easy for me to remember and make it into a strong password. A few examples:

  • My Dog's Name is Rover (phrase)
  • My!D0g!Rover (strong password)
  • My wife and four kids (phrase)
  • MyWife&4kids (strong password)
  • Account at Wells Fargo (phrase)
  • Acct.@Wells4go (strong password)

It takes a little creativity on your part to make a strong password that you will remember. Once you get the hang of it, it's a piece of cake.

Now a catch, I suggest using different passwords for different purposes (one for work, another one for eBay, another one for your bank, etc.). This can make for a lot of passwords! Learn why I suggest this, and how you can keep track of all these passwords in the last installment of this series, Passwords Part 3/3 - Password Management.

Feel free to post your comments, check out The Trusted Toolkit, or email me for more!

Read more!

Tuesday, April 3, 2007

Passwords Part 1/3 - Defending the IT Guys

Passwords. Ugh! If you are at all like most people I talk to, you don't like passwords. Actually, most of us security guys don't like them all that much either.

In "Passwords Part 1/3" we are going to explain some things. We will explore what a password is and why these IT guys are always on your case about them.

"Passwords Part 2/3" will dig into some detail about what a "strong" password is and detail some tips to help you to come up with your own.

Finally, in "Passwords Part 3/3" we'll outline some tips and tools to help you keep track of all your passwords. None of these tips or tools will include a pen, a piece of paper, or the underside of a keyboard!

So, let's get this ball rolling. Do you ever wonder why IT guys are such sticklers about passwords or why they have to make things so dag nab hard for you? In order to understand where the geeks are coming from you need to know a little bit about "identification" and "authentication". I won't go into a lot of detail on these two terms, but I will give you a general sense of what they mean.

Identification is what you present to a system to profess your identity. It tells the system who you are. Many times identification takes the form of a username or userid. Typically usernames are not secret. If my name is Bill Smith and my username is "bsmith", your name is John Doe and we both use the same system, I can make an educated guess that your username is "jdoe". Identification is important in order to define what it is that you can do in the system, called rights or privileges. Some people get to do more with a system, file, directory, etc. than others.

Authentication is what you present to a system to prove your identity. Anybody can say that they are me, but who can prove it? There are a variety of methods of proving your identity, but for the purpose of this writing we are talking about passwords. Once I have presented my credentials (identity + password) successfully to the system, then I am "authenticated" and I am given my assigned access to the system.

If I have a password that nobody else knows does this not prove my identity (at least theoretically)? What if someone else DOES know my password? Proof is gone. Someone else can impersonate as me and do what only I should be able to do. Protecting the confidentiality of passwords is paramount IF it is your method of authentication to a system. The IT guys don't care what your password is, they want to make sure that confidentiality is maintained. Period.

Maintaining the confidentiality of passwords means that they must be strong (Part 2/3) and stored securely (Part 3/3).

Check back tomorrow as we continue... Read more!