Showing posts with label password. Show all posts
Showing posts with label password. Show all posts

Anatomy of a brute force attack - how important is password complexity?

You may have heard of the curate's egg.

It comes from a wry Punch cartoon from the late nineteenth century in which a curate (a junior cleric) is having breakfast with with the Bishop (a senior cleric), when the latter offers an apology, saying, "I'm afraid you've got a bad egg, Mr Jones."

Determined to salvage the situation by finding someting positive to say, the curate replies, "I assure you that parts of it are excellent." And it was in that vein that my friend, colleague and popular (though sadly only occasional) Naked Security writer,Ross McKerchar, waved in front of me a recent article on password security.

It was published on Redmondmag, a indepdent website about Windows that is well-read and reasonably influential, and it attempted to answer the question, "How Important Is Password Complexity?"

how important is password complexity?
Password Complexity

The good part of this curate's egg is that the author, Brien Posey, took a hands-on approach, and came up with a realistic Spy-vs-Spy password recovery scenario.

Facebook, the early years: handing out a master password like candy

http://nakedsecurity.sophos.com/2013/07/19/facebook-the-early-years-handing-out-a-master-password-like-candy/
Facebook founder had a master password
You are not paranoid about surveillance - at least, not as far as Facebook is concerned. It appears that Facebook founder Mark Zuckerberg and his minions, in the early days, had a master password with which they could sign in to any user account and poke at whatever data we entrusted to the site.
The Guardian gleaned this from Zuckerberg's former speechwriter, Katherine Losse. Losse told the media outlet that users should be guarded with their private data on the site - a timely warning, given the launch of Facebook's social search tool graph search. Losse - aka Facebook employee No. 51 - joined the company in 2005 as a customer support staffer and worked her way up to being Zuckerberg's ghostwriter. She left in 2010 and, according to the Guardian, is now regarded as a rogue former employee by Facebook itself.

Would you tell Google your Wi-Fi password? You probably already did..

US privacy and computer security advocate Micah Lee describes himself, amongst other things, as "a staff technologist for EFF and the project maintainer of HTTPS Everywhere." In other words, he has a healthily holistic view of the use of encryption on the internet.

So it wasn't surprising, earlier this week, to see him post a suggestion to the Android Open Source Project about security.

His suggestion was entitled "Backup and restore" should offer encrypted backups:
http://nakedsecurity.sophos.com/2013/07/18/would-you-tell-google-your-wi-fi-password/
Backup and restore

Sony to pay £250,000 fine for PlayStation Network breach

http://nakedsecurity.sophos.com/2013/07/16/sony-to-pay-250000-fine-for-playstation-network-breach/
Sony to pay for PlayStation network breach
Sony has thrown in the towel on its appeal of a £250,000 fine ($377,500) imposed after its PlayStation Network was hacked in April 2011.

The UK Information Commissioner's Office (ICO) imposed the fine in January after an investigation showed that the attack could have been prevented if Sony's software had been up to date.

On top of that, the ICO, finding that technical developments led to passwords not being secure, also charged Sony with negligence for failing to protect PlayStation Network (PSN) users.

Android and its password problems open doors for spies

http://www.h-online.com/security/news/item/Android-and-its-password-problems-open-doors-for-spies-1918596.html
Android password problems
The data stored on Google servers when the "Back up my data" option is selected on an Android device includes Wi-Fi passwords in plain text format. This is not in itself news, but businesses in particular may wish to reconsider its implications in the light of the latest surveillance scandal.

The backup function is, at least on Nexus devices, activated by default, with no password of any kind required for the service. In Google's favour, it has to be said that it does make it clear what users are letting themselves in for, with the description of this function stating "Back up ... Wi-Fi passwords ... to Google servers". Tests by The H's associates at heise Security showed that after resetting an Android phone to factory settings and then synchronising with a Google account, the device was immediately able to connect to a heise test network secured using WPA2. Anyone with access to a Google account therefore has access to its Wi-Fi passwords.

Tumblr security lapse - iPhone and iPad users update your passwords now!

Tumblr has released a "very important" update for their iPad and iPhone apps following what they describe as a "security lapse".It appears that passwords were being sent over the internet unencrypted, making it easy for anyone with bad intentions and a little technical knowledge to harvest Tumblr users' login details.

The short post by Derek Gottfrid, Tumblr's vp of product, gives very little away but does say that passwords may have been compromised by being "sniffed in transit"

http://nakedsecurity.sophos.com/2013/07/17/tumblr-security-lapse-iphone-and-ipad-users-update-your-passwords-now/
Short post by Derek Gotffrid

Quick Reversing - WebEx One-Click Password Storage

Cisco's WebEx is a hugely popular platform for scheduling meetings. You can conduct video and voice calls, screen sharing, and chat through the system. Meetings are usually created via a Web Portal were the user defines when the meeting starts, how long it goes for, and what services (e.g. screen sharing or just voice) their meeting will leverage. WebEx also provides a One-Click Client that offers standalone meeting scheduling and outlook integration so that users can avoid the Web Portal.

http://blog.opensecurityresearch.com/2013/07/quick-reversing-webex-one-click.html
Cisco
The One-Click Client has the ability to save a user's password, so Brad Antoniewicz decided to take a quick look at that functionality - in about an hour he was able to determine the storage, reverse the method it used to encrypt the password, and write a proof of concept tool to decrypt the local storage of the password. The aim of this blog post is to document that process and maybe encourage you to do some reversing!