Showing posts with label passwords. Show all posts
Showing posts with label passwords. Show all posts

Tuesday, August 12, 2014

Nerd News: LastPass Back Up

LastPass has been down for a while, but according to LastPass and other reports it should be back up, though there may still be some issues.

Sounds like they only use 2 datacenters, or maybe even only single primary one with a "backup".
"Update: 1:28 pm EST

Though one of our data centers remains completely down, the service is generally stable and should be available to the majority of users (with the exception of login favicons). Some users may see connection errors but should still be able to access their data. We continue to work as quickly as possible to get the service back to 100%. "
       Source http://blog.lastpass.com/


"Aug 12, 2014 - One of LastPass' datacenters has been down since 3:57am EDT. The service is now running fully off one Herndon VA datacenter and we have been engaged with our provider all morning. Currently favicons/sprites are impacted. We are doing what we can to minimize the impact and apologize for the inconvenience. "

       Source https://lastpass.com/status.php


Also http://www.isitdownrightnow.com/lastpass.com.html 

For LastPass users that want an offline solution to prevent this type of problem in future consider LastPass Pocket

This is LastPass link specifically about offline access https://helpdesk.lastpass.com/password-manager-basics/your-lastpass-vault/offline-access-to-your-lastpass-vault/ 


Wednesday, October 2, 2013

Steve Gibson's Secure Login (SQRL) Concept

Documentation https://www.grc.com/sqrl/sqrl.htm

Security Now Episode 424:  Steve Gibson introduces the idea (Video & Audio Podcast, or streaming) http://twit.tv/show/security-now/424

This looks very very interesting, I am looking forward to seeing how this works out.

SQRL is pronounced "Squirrel" ^_^

I lack the expertise to vet this idea, but it sounds very good to me, would solve a lot of problems for average users, while providing very strong security that would be difficult to compromise.

Looking forward to the development of SQRL, and hats off to Steve for making it public domain!!

From Practical Considerations section of first page of documentation:
"Did I invent anything? I don't care. Even if some aspects of this system are novel, and might be subject to intellectual property protection, this is too important and much bigger than me. It should be made free for the world to use without encumbrance. With this publication of every detail, I hereby release and disclaim any and all proprietary rights to any new ideas developed and presented herein. This work is thereby added to the public domain."

Monday, August 26, 2013

Updated oclHashcat-plus v0.15

Main link:  http://hashcat.net/oclhashcat-plus/

oclHashcat-plus v0.15 "Added support for cracking passwords longer than 15 characters," lot of other improvements see https://hashcat.net/forum/thread-2543.html for full details.

I am still digging through the changes, and I have been sick, so it will probably take me a while, but it looks like some big improvements have been made.

They have also added support for several algorithms, including TrueCrypt 5.0+, Lastpass, & MacOSX v10.8 that are of particular interest to me.



Saturday, March 2, 2013

Evernote Hacked forces Password Reset

Articles all over the Net about Evernote Hack:
Evernote is an app I have stayed away from, despite or maybe because of it's great utility, once you start using it, your going to use it for everything.

Which will expose way to much useful information to attacker if the data ever gets compromised, including information that could compromise physical security (my background).

Additionally, with the type of cloud based system used for Evernote, there is no way to make it really secure IMO.


Brian, from Krebs on Security article link at top, mentions this really good interview he did about password encryption http://krebsonsecurity.com/2012/06/how-companies-can-beef-up-password-security/

Explains the difference, in simple terms, between password hash & cryptographic hash.

Friday, January 11, 2013

More on Passwords & Password Keepers

 I may have mentioned Brian Kreb's password article before, http://krebsonsecurity.com/password-dos-and-donts/, but wanted to make sure I linked to this article http://krebsonsecurity.com/password-dos-and-donts/

He mentions three Password Keepers:  Roboform, Passwordsafe, & Keepass.

Keepass is the only one of those three I know a bit about, have a computer nerd friend that has used that for years.

It is good and free.

I am trying to provide a good selection of quality Password Keepers for people to chose from, not everyone's needs and wants are the same.

I prefer mSecure, partly because it has stronger encryption than many others, but it is also one of the most expensive consumer options.

Lot of my gamer friends though don't want to, or can't afford, to spend much on computer software.

Something to remember when using Password Keepers, is that you want to have that Data backed up VERY well.

You can use Dropbox or similar cloud storage, but you can also use Password Keepers on multiple devices (ie Smartphone, Tablet, & PC) I also like using a quality Flashdrive with hardware encryption.

I also like using written backup stored securely, I have physical items I have to keep secure, so I have ready storage for that.

I have written about Passwords & Password Keepers before, I specifically recommend reading Steve Gibson's Haystacks & Needles (Understanding Passwords) and "Lessons Learned from Cracking 2 Million LinkedIn Passwords."

For more posts click one of the these Labels:


Those Labels and more can be found at bottom left of Blog post, selected Labels can be found in Label Cloud at left side of blog, space limitations there, but I open to feedback for labels that should be added or removed from the Label Cloud.

Stay Safe,

Cliff



Friday, October 26, 2012

Security & Hacking: How to Crack WPA & WPA2

Good, though somewhat technical, article on cracking WiFi http://www.smallnetbuilder.com/wireless/wireless-howto/31914-how-to-crack-wpa-wpa2-2012

Though not mentioned in that article, related to strong passwords, I really think everyone should be using a good password keeper.

So the only password you need to remember is the one needed to unlock your password keeper, I would use Steve Gibson's advice for that password, blogged about here http://cliffsesportcorner.blogspot.com/2012/05/steve-gibsons-haystacks-needles.html

Then use random passwords, generated by the password keeper, for everything else.

There are many good password keepers out there, I like and recommend mSecure https://msevensoftware.com/

For free I believe Strip Lite is good, their website http://getstrip.com/ or iTunes.

Another free one I might suggest is KeePass, I have heard good things about it, and have a friend that uses it.


See Also:

Tuesday, August 28, 2012

Security & Hacking: "How I cracked my neighbor's WiFi password without breaking a sweat"

http://arstechnica.com/security/2012/08/wireless-password-easily-cracked/

Very good article, though written for average person, there is higher level information available in many of the Comments, it clearly shows how easy it is to hack many things average people think are secure.

Also, since the author of that Ars article was using online software services (ie software that ran on servers, not on author's computer) he didn't need much of a computer to do this.

For those new to Pen Testing and Password Strength (Security?) he was basically using a dictionary of words and common passwords.

The term "Dictionary" sometimes throws people, they don't mean Websters or OED, rather it is a list based on previously cracked passwords.

Millions of cracked passwords, so current Hacker's Dictionaries tend to be pretty representative of any password that a person picks out!

If you can remember it, it is a very bad password, you should be using some tiype of password keeper, and using the generate random password feature that all the good password keepers offer.

I plan to do a post in the near future on Password Keepers, but there are a lot of choices out there, many are free.

For similar Blog Posts, click on one of these labels:  Security, Hacking, Password Cracking, or Pen Testing.

Selected Labels can be found in label cloud at left side of blog, and every blog post has labels at bottom left of post.

Specific posts on Cliff's Esport Corner (aka Cliffs_esports_corner in some chat rooms) can be found best by using Google with query term and Cliff's Esport Corner in your Google search.


Sunday, August 26, 2012

Security & Hacking: "Dropbox two-step verification security option"

Sounds like Dropbox has Two Factor Authentication available via Beta, full story at http://www.theverge.com/2012/8/26/3269423/dropbox-two-step-verification-security-beta

If you use Dropbox this is probably a good idea, but if they are hacked from inside again, it might not do much good, I don't recommend Dropbox for critical data, there are a lot better choices available for that, and honestly Dropbox is about easy access not security.

If you are worried about security of items stored on Dropbox, encrypt first with Truecrypt or similar first.

And USE A STRONG PASSWORD!

Tuesday, August 21, 2012

Security & Hacking: "Why passwords have never been weaker—and crackers have never been stronger"

Really good article from Ars http://arstechnica.com/security/2012/08/passwords-under-assault/, and as always with Ars articles, you can find some exceptional bits of information buried in comments section.

Another password cracking you should read is Lessons Learned from Cracking 2 Million LinkedIn Passwords.

For more click one of the these Labels:

Those Labels and more can be found at bottom left of Blog post, selected Labels can be found in Label Cloud at left side of blog, space limitations there, but I am always open to feedback for labels that should be added or removed from the Label Cloud.

If your looking for something specific on my blog, best way is just to add query term to Cliff's Esport Corner in a google search.

I tested the google search widget for the blog but it didn't work as well as normal google so I removed it.

Monday, August 13, 2012

Thursday, August 9, 2012

PSA: Blizzard NA Bnet change your passwords

http://us.blizzard.com/en-us/securityupdate.html

See link for full details, short version, Blizzard has found determined some information was hacked, and are suggesting NA accounts to change passwords.

Secret Questions may have been compromised as well.


For more on good passwords see Steve Gibson's Haystacks & Needles (Understanding Passwords)

I would also strongly suggest Two Factor Authentication.

Monday, August 6, 2012

Security & Hacking: Mat Honan Targeted

VOD interview/discussion at http://twit.tv/show/this-week-in-tech/365

Mat Honan also talks about it on his Blog at http://www.emptyage.com/post/28679875595/yes-i-was-hacked-hard

Take the time to look at this, and think about structuring your accounts & etc to protect yourself from this, Hackers will certainly take note of this.

Couple of Basic Points:

Backup critical data, you need at least 3 copies of important data, the "working" copy, plus two separate backups in different locations/companies.

Don't interlink all your accounts.  That leads to domino effect of a single vulnerability being exploited, perhaps something out of your control like happened to Honan, that gives Hacker access to one of your accounts, and that one account will let them in to all the others.


Tuesday, July 31, 2012

PSA: Dropbox Reports on Customer Spam/Hacking Complaints

See Dropbox's Blog Post http://blog.dropbox.com/index.php/security-update-new-features/ for the full story.

Short version, they say one Dropbox employee account was compromised, and that user emails were available because of that.

Also that some people are using password on multiple sites, and some of those passwords were Hacked from other sites. 

They say they will be improving security, and list a few of the improvements, Two Factor Authentication being the most useful IMO.

For those looking for deeper understanding on (good strong)passwords, see Steve Gibson's Haystacks & Needles (Understanding Passwords).

For more about Hacking or Cracking Passwords, see "Lessons Learned from Cracking 2 Million LinkedIn Passwords".

You can also see all my posts about Passwords or Hacking, by clicking on the Labels Passwords or Hacking respectively, Labels can be found at bottom left of every Blog post, and selected Labels can be found in the cloud at left side of Blog.

Monday, July 23, 2012

PSA: Gamigo 11 Million Passwords Hacked

See Ars article, also Forbes, the Forbes article links http://pwnedlist.com/ for checking if your email has been leaked.

I haven't heard about http://pwnedlist.com/ before, but shows as green with McAfee.

For more on Password Cracking, or Hacking, and what you should do see "Lessons Learned from Cracking 2 Million LinkedIn Passwords" and/or Steve Gibson's Haystacks & Needles (Understanding Passwords).

But if you have a Gamigo account, you should change your password, the Steve Gibson link above provides good advice on passwords.

Saturday, July 14, 2012

NVIDA Hack update


Posted July 13, 2012
A small proportion of users’ hashed passwords for DevZone has been posted publicly.
We continue to strongly recommend that you change any identical passwords that you may be using elsewhere, as noted below. 

~http://www.nvidia.com/content/devzone/index.html

NVIDIA has also shut down their online store in addition to Devloper forum that was shut down yesterday. 

Friday, July 13, 2012

PSA: NVIDIA Devloper Zone Hacked

http://nakedsecurity.sophos.com/2012/07/13/nvidia-android-forums-hackers/

I saw this first on Sophos blog linked above.

Cut and paste from NVIDIA's warning post below, see their link for complete message, http://www.nvidia.com/content/devzone/index.html,
NVIDIA suspended operations today of the NVIDIA Developer Zone (developer.nvidia.com). We did this in response to attacks on the site by unauthorized third parties who may have gained access to hashed passwords.
We are investigating this matter and working around the clock to ensure that secure operations can be restored.
As a precautionary measure, we strongly recommend that you change any identical passwords that you may be using elsewhere.
NVIDIA does not request sensitive information by email. Do not provide personal, financial or sensitive information (including new passwords) in response to any email purporting to be sent by an NVIDIA employee or representative.

For more on Passwords see More D3 Account Security or Computer & Password Security: Salting & Hashing explained clearly or Steve Gibson's Haystacks & Needles (Understanding Passwords).

Thursday, July 12, 2012

PSA: Yahoo Accounts Hacked? Perhaps Gmail & others as well?


Read this on Ars http://arstechnica.com/security/2012/07/yahoo-service-hacked/

Ars avoided linking anything direct (ie hacked file) in the article, but there are links in the comments section, including this text list http://d33ds.co.nyud.net/archive/yahoo-disclosure.txt

I am not sure if that file is legit or not, or if it contains data from more than one exploit?  It seems to list information for Gmail, Yahoo, and more.

I would (I did) change passwords any Yahoo accounts that you have, might consider for Gmail and others in that text file linked above as well.

If you want to understand more about passwords and computer/Net Security see Steve Gibson's Haystacks & Needles (Understanding Passwords).

For more on what a Hacker can do see "Lessons Learned from Cracking 2 Million LinkedIn Passwords"

Edited to add this link shows other Blogs & News Sites covering this issue http://www.blogrunner.com//snapshot/D/2/1/hackers_expose_453000_credentials_allegedly_taken_from_yahoo_service/

Wednesday, June 13, 2012

Bruce Schneier: Teaching the Security Mindset (Teach people to Cheat)

Bruce Schneier is an interesting person, for those of you that don't know who he is, he has worked with Truecrypt, and is considered a crypto and computer security expert.

I have been following him for a while now, very educational and useful IMO even if your not a computer geek. 


Today, he has a great post that covers Security Mindset, and points to a great paper "Embracing the Kobayashi Maru: Why You Should Teach Your Students to Cheat" by Gregory Conti and James Caroland.

Just wish I would have had a class like that when I was in college!


Tuesday, June 12, 2012

"Lessons Learned from Cracking 2 Million LinkedIn Passwords"

This blog post on Qualys Security Labs blog, shows what someone using John The Ripper can do on a old machine.

Francois Pesce spent a little time using John The Ripper with some password dictionaries, and in the first 5 hours, he cracked 1.4 million of the ~6.458 million passwords in the data base.

That is over 21% in 5 hours on an old machine that was using CPU for the work, instead of a newer machine using more efficient GPU cracking.

GPU (Graphics Processing Unit/Graphics Card) are not more powerful than the CPU (Central Processing Unit) in your computer, but they are optimized for different types of work.

And with modern software GPU's work a lot better for password cracking.

If you want an analogy, or even if you don't, you can think of CPU & GPU like a Race Car and a Semi, they both might have similar horsepower, but they lot of differences in transmissions, gearing, torque, etc because they are designed for different types of driving.

If you want to learn more about CPU's & GPU's in connection to password cracking, read the excellent article "Password cracking, mining, and GPUs".

Back to Francois Pesce's password hacking, one he cracked the first 1.4 million passwords, he was able to use those passwords to fine tune his password cracking.

Part of the reason this works is that people tend to follow patterns, and lot of people still rely on passwords they can remember, so they tend to follow similar decision trees when they chose a password.

So with that tweaking, and some additional refinement after the first pass with the passwords already cracked, he got another 572 thousand passwords, bringing the total to ~1.972 million cracked passwords from the total ~6.458 million.

That works out to about 30.5%, and those were all done with Dictionary attack, not brute forcing!

So read Pesce's "Lessons Learned from Crakcing 2 Million Linkedln Passwords"

If that leaves you wondering about passwords, read my post "Steve Gibson's Haystacks & Needles (Understanding Passwords)" which covers the basic of good passwords in a clear way.

If you read these article you will realize you should use a password keeper!  That is only way to reliably and securely keep very many long & strong passwords.

Resources at bottom for finding a good password keeper, below I recommend a few.

For paid ones I like mSecure, that is what I have my family members using.

For free I believe Strip Lite is good, their website http://getstrip.com/ or iTunes.

Another free one I might suggest is KeePass, I have heard good things about it, and have a friend that uses it.

Stay Safe,

Cliff


See Also: