Google Search

Showing posts with label bloggers. Show all posts
Showing posts with label bloggers. Show all posts

Wednesday, June 26, 2013

WordPress.com boosts security for bloggers with two-factor authentication

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Automattic, the company behind the wildly-popular blog hosting platform WordPress.com, has announced the immediate availability of 2FA (two-factor authentication) for WordPress.com account holders.

Like Apple, which recently did something similar but chose to call it two step verification, WordPress has gone for its own name, referring to the feature as two step authentication.

Whether you call it 2FA, 2SV or 2SA doesn't really matter, because the underlying idea is the same: introduce single-use passwords that are unique to each login.

As a result, attackers can't get anywhere simply by stealing your regular username and password combination.

? There are many ways that a long-term password can fall into the hands of the bad guys. If you use the same password on multiple websites, you risk losing it if any of those sites get hacked. If you are infected with malware, you risk having your password keylogged every time you enter it. If you share your password with someone else, for example when you are in a hurry to get a time-critical business blog posted, you run the risk that they might lose it for you.

One-time passwords aren't perfect - no security system is - but they raise the bar steeply for cybercrooks.

That's because the crooks can't just beg, steal or borrow your password today and use it at their leisure tomorrow.

They need to interpose themselves every time you login, in order to recover the one-time code.

And if the one-time code is generated by, or delivered to, a device that is separate from the computer or device on which you actually do your work, then the job is even harder for the crooks. (Not impossible, of course. But much harder.)

For WordPress, Automattic has introduced two options.

You can download and use the Google Authenticator software and use it to generate one-time login codes on iOS, Android or BlackBerry devices.

Or you can choose to have your login codes delivered to a mobile phone via SMS.

With Wikipedia estimating that WordPress powers more than 60 million websites worldwide, anything that might improve the safety and security of WordPress users is to be welcomed.

After all, if malcontents get hold of your WordPress login, they can use it to attack you, your reputation, your brand, and, by uploading malware or malicious links, to attack your users.

It doesn't really matter if you have a high-traffic server or a boutique website, since both represent a free ride to the crooks.

And that brings us to the $64,000 question: if you're a WordPress user, should you enable this feature, and does it get in the way?

As you may know: Naked Security itself is hosted by WordPress.com VIP; I'm a keen supporter of 2FA; and I like the guys at Automattic...so who better to answer those questions than Yours Truly?

For what it's worth, I decided to use the SMS-based version, thus ensuring that my login codes are delivered neither to my laptop nor my tablet, but to a vanilla mobile phone.

This turns what might otherwise be merely two step authentication (where I login on the same device to which the code was sent) into something I consider to be two factor authentication.

It was easy to set up.

I headed to the Security tab of my WordPress Settings page:

I chose the link offering Two Step Authentication via SMS:

Within about five seconds I received a one-time, digits-only, setup code.

(Judging by the list of countries in the configuration dialog, the SMS service is available everywhere.)

WordPress emailed me to confirm that someone had enabled this new feature:

And then I clicked through to the Printing out some backup codes option to get hold of ten codes that I can use in emergencies:

NB. Do not store the backup codes on your computer, phone or tablet. Copy them down onto a piece of paper and lock them up at home. If a crook stole them from your PC, he'd be able to bypass 2FA, and then to reconfigure it.

Obviously, I haven't been using the service for very long - less than a day! - so I can't promise you that the system is going to perform flawlessly for ever, but my immediate impression is that it is working very well.

I login as usual, with my username and password, and then wait for a verification code, which I enter as the second authentication step:

So far, the SMSes have been appearing on my phone within a second of the verification dialog popping up, so the inconvenience has been negligible.

Should you enable the feature, and does it get in the way?

Yes. No. Recommended.

Follow @duckblog


View the original article here

Tuesday, May 28, 2013

Hackers launch DDoS attack on security blogger's site, send SWAT team to his home

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Brian Krebs Brian Krebs

Thankfully, award-winning US computer security reporter Brian Krebs is safe.

Nobody was harmed. But they could have been.

Given a DOSed website, a fake and libelous FBI letter sent to his website host, and a dinner party delayed by a SWAT team training guns on him and ordering him to "Put your hands in the air!", Krebs last week surely endured the most dramatic retribution ever meted out to a security blogger.

Krebs has a good idea of the specific criminal element behind the trio of attacks. Since the dramatic events of Thursday, he's traced the denial-of-service attack to a common operator who apparently launched a similar attack on Ars Technica following its coverage of Krebs's victimization.

As described by his fellow security scribe Dan Goodin at Ars Technica, Krebs is known for work that includes:

In short, Krebs has enemies.

Last week, one or more of those enemies targeted him, likely in retaliation for his most recent investigation.

On Friday, Krebs detailed in a post how the ordeal started the day before, when his site was targeted with "a fairly massive denial of service attack."

That same afternoon, a technician from Prolexic called. Prolexic is a company that Krebs hired to protect his site, KrebsOnSecurity.com, from DOS attacks.

Prolexic forwarded a letter they'd received earlier that day, purporting to come from the US Federal Bureau of Investigation.

The letter, which Krebs reprinted here, falsely claimed that Krebs's site was "hosting illegal content, profiting from cybercriminal activity, and that it should be shut down," Krebs writes.

Fake FBI message

Both Prolexic and Krebs dubbed it a hoax - an assumption Krebs confirmed with a quick call to the FBI.

As Prolexic tidied up his DOSed site, Krebs got to work tidying up his home in anticipation of dinner guests. His office phone rang while he was vacuuming, but he ignored it.

That, it turns out, was an unfortunate choice, given that the call came from law enforcement who were trying to verify what would turn out to be a spoofed emergency call showing Krebs's number on caller ID.

As he was vacuuming, Krebs noticed plastic tape on the front-door threshold, left over from securing an extension cord. He opened the door to unpeel it.

He tells of what happened next:

"When I opened the door to peel the rest of the tape off, I heard someone yell, 'Don't move! Put your hands in the air.' Glancing up from my squat, I saw a Fairfax County Police officer leaning over the trunk of a squad car, both arms extended and pointing a handgun at me. As I very slowly turned my head to the left, I observed about a half-dozen other squad cars, lights flashing, and more officers pointing firearms in my direction, including a shotgun and a semi-automatic rifle. I was instructed to face the house, back down my front steps and walk backwards into the adjoining parking area, after which point I was handcuffed and walked up to the top of the street.

"I informed the responding officers that this was a hoax, and that I’d even warned them in advance of this possibility. In August 2012, I filed a report with Fairfax County Police after receiving non-specific threats. The threats came directly after I wrote about a service called absoboot.com, which is a service that can be hired to knock Web sites offline."

SWAT team. Image from Shutterstock

Krebs had filed a police report last year on the suspicion that he would be SWATted.

SWATting is the practice of falsely reporting an emergency, as a prank or as revenge against a victim upon whom descends emergency services - or, in Krebs's case, armed law enforcement.

Krebs' persecutors had, in fact, spoofed an emergency call to make it appear that it had come from his phone.

As Sophos's Chester Wisniewski noted last April when he wrote about fraudulent calls targeting US banks, caller ID spoofing can be particularly convincing in the US, given that the call display service used by most phone companies here does a reverse lookup for the name information based on the caller ID number provided by the call.

Once a criminal determines the phone number he wants to have fraudulently show up as his caller ID number - Krebs's phone number, in this case - it's trivial to display that number on the call recipient's display.

Caller ID spoofing has been around for years through various technologies: ISDN PRI circuits used by collection agencies, law enforcement, and private investigators, all of whom have used it with varying degrees of legality; spoofing services such as Star38.com; and through Voice over IP (VoIP) technology.

Given how trivial it is to spoof caller ID, it's surprising that people put any faith at all in the technology - most particularly that law enforcement do.

In fact, the police who took Krebs's report warning that he might be targeted by SWATting hadn't even heard of the practice.

Telephone. Image from Shutterstock

All too readily, we tend to put faith in appearances. We believe caller ID identifies the true identity of a caller.

Or somebody flashes a piece of silver and we obediently hand over our licenses or wallets, or we open a door and allow strangers inside our home or our cars, without verifying whether what we've seen was an authentic emblem or a plastic toy badge.

We - the police included - trust in the technology we use. Criminals will always exploit that trust.

Krebs's work, along with other security reporters and researchers, is to poke sticks into hornets' nests, to borrow a friend's analogy.

In this case, the sting from angry hornets could have had fatal consequences, as Krebs points out:

"I have seen many young hackers discussing SWATing attacks as equivalent to calling in a bomb threat to get out of taking exams in high school or college. Unfortunately, calling in a bomb threat is nowhere near as dangerous as sending a SWAT team or some equivalent force to raid someone’s residence. This type of individual prank puts peoples’ lives at risk, wastes huge amounts of taxpayer dollars, and draws otherwise scarce resources away from real emergencies. What’s more, there are a lot of folks who will confront armed force with armed force, all with the intention of self-defense.

"The local police departments of the United States are ill-equipped to do much to stop these sorts of attacks. I would like to see federal recognition of a task force or some kind of concerted response to these potentially deadly pranks. Hopefully, authorities can drive the message home that perpetrating these hoaxes on another will bring severe penalties. Who knows: Perhaps some of the data uncovered in this blog post and in future posts here will result in the legal SWATing of those responsible."

Well said, Brian. We all hope so too, for your sake and for the sake of all security researchers, law enforcement personnel and victims of attacks like the one you experienced.

Follow @LisaVaas
Follow @NakedSecurity

SWAT team and telephone image courtesy of Shutterstock.


View the original article here