Google Search

Showing posts with label exposed. Show all posts
Showing posts with label exposed. Show all posts

Friday, August 3, 2012

The worst passwords you could ever choose exposed by Yahoo Voices hack

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Login form. Image from ShutterstockToo many internet users are making poor decisions when choosing their passwords.

We've spoken time and time again about the importance of choosing hard-to-crack, unguessable, unique passwords that (provided the website you are using looks after its databases properly) will make life very difficult for password crackers.

And yet, people continue to use passwords that are - quite frankly - dumb, and then compound the problem by using the same simple password in multiple places.

Scandinavian security blogger Anders Nilsson spent a little time with the Pipal password analysing tool, running it against the 450,000 plaintext passwords snatched by hackers from Yahoo Voices.

And what he found doesn't inspire much confidence that users are getting the message about password security.

Poor passwords being used on Yahoo Voices

Repeat after me.

"A password of 'password' isn't actually a password."

And neither is "123456" or "welcome" or "qwerty" going to prove anything of a challenge to a hacker.

The fact is that every time password lists are stolen and published on the internet, hackers add them to their own databases for their password crackers to try next time they want to break into an account or crack a hashed password.

Your passwords need to be unique, and hard-to-crack. That means not using dictionary words anymore, and not imagining that no-one else in the world has thought of "qwertyuiop" or "password1234".

The typical response from the average internet user is "But how will I remember all these different, complicated passwords?"

Simple. Use a decent password management program.

1PasswordThere are a few to choose from, and some of them are even free. Software like 1Password, KeePass and LastPass can remember all your different passwords on your behalf, store them securely, and even generate complicated passwords for the next website you join.

Clearly the responsibility isn't all in the court of the user, however.

Not only should websites take greater care about securing users' information (for instance, not storing passwords in plain-text or as unsalted hashes), but they could also do more to ensure that users choose trickier passwords.

I'd like to see more websites check the passwords chosen by their new users, by running them against a database of commonly used passwords and a dictionary.

If the password users enter is too common, or an obvious sequence, or doesn't obey sensible password rules about complexity or length, then it should be rejected and the user told to try again.

When websites tell you to change your password following a security breach, they should also tell you to choose a hard-to-crack, unique password. Otherwise, what's to stop the new password being "abcdefg"?

It would be a safer world if websites policed the passwords that are submitted by users, and weak choices thrown out.

And it's not just users who need to have strong passwords. The website's staff need to have sensible, hard-to-crack passwords as well.

In early 2009, for instance, a hacker was able to break into Twitter accounts belonging to celebrities because he had broken into Twitter's administrator's console.

How did the hacker manage that?

The Twitter employee was using a password of "Happiness".

Here's a YouTube video I made a while back showing how to choose a hard-to-crack but easy-to-remember password. It also explains how password management software programs like 1Password, KeePass and LastPass can help you remember all your different passwords.


(Enjoy this video? Check out more on the SophosLabs YouTube channel.)

If you already know this about passwords - great! But be a good samaritan, and share the advice with your family and friends.

We need to get everyone to understand the importance of better password security.

Yes, even the "princesses" and "ninjas".

Follow @gcluley

Login form image, courtesy of Shutterstock.


View the original article here

Sunday, April 15, 2012

Facebook Confidential: How the Craigslist killer manhunt exposed personal details of the innocent

Over 100,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

When The Boston Phoenix was researching an article about the manhunt for the notorious "Craigslist killer", they were granted access to all the case files released by Boston Police Department.

Among transcripts of interviews, crime scene photos and recordings, was - in printed form - the entire Facebook account of the suspect, Philip Markoff.

What Facebook sent the police

From Markoff's wall posts, photos he had uploaded and been tagged in, to his Facebook friends and a list of IP and login information that detailed the photos, groups and even the individual profiles Markoff had visited. You might say that the data released by the police subpoena of Facebook is extensive...

Here's what Facebook says about working with law enforcement:

Facebook FAQs

According to a The Boston Phoenix blog entry, Boston Police decided to release the printed-out data collected from Facebook without redacting any information.

Which meant that Markoff's online friends risked having their Facebook details, including their names, photographs, and conversations made public.

Fortunately, The Boston Phoenix obscured the names of individuals when it published the Facebook data. We've gone one step further in the example screenshot below, and also obscured the faces in a photograph.

Facebook photo

You cannot help but feel sorry for Markoff's innocent friends and associates, who presumably knew nothing of his crimes, and yet could have ended up having their personal information exposed. We know the police do a fantastic job, and hats off to them for the investigation which led to the arrest of Markoff, but they do need to careful with the data they share.

The Boston Phoenix has published some of the information they looked at online.

It's scary to see how comprehensive it is, and further illustrates just how much information Facebook holds about you.

Now, it's not like Facebook go around releasing this kind of information willy-nilly, but it shows just how much the bad guys would be able to access should they - eek - hack into Facebook's servers.

Follow @NakedSecurity

View the original article here

Tuesday, October 25, 2011

iPhone security flaws exposed - 9NEWS.com

DENVER - Telly, who asked us not to reveal her last name, assumed that her iPhone 3 was secure. Then she says her phone was hacked and her personal information was compromised.

She sent 9NEWS a newstip, asking us to look into how this security breach could have happened.

Telly was having dinner with her family Thursday when her husband pointed out that her phone appeared to be "possessed."

"I was like it is Halloween time. Maybe the ghosts are out. Maybe the ghosts are taking over my telephone," Telly said. "It was pretty creepy. I felt pretty violated."

Telly soon realized a hacker had taken control of her iPhone.

"They would go to my contacts and find a contact, and then go to my facebook account and find the profile associated with that contact," Telly said. "I typed capital WTF?? And he typed back LOL."

Telly's iPhone 4 is out of commission with a shattered screen after one of her children dropped it on the floor. She recently began using her old iPhone 3.

Tom Bridge, an Apple expert and co-founder of Washington DC-based Technolutionary, says older model iPhones that do not have updated software could be targeted by hackers.

"If you've got an older iPhone, your iPhone is definitely potentially vulnerable," Bridge said. "This is one of the reasons that we highly recommend that everybody keep up to date with the software on their iPhone."

Bridge says hackers can use a text message or PDF to break into your phone, but only if you haven't updated your operating system, or OS.

Bridge recommends using iTunes to check and make sure your OS is up to date. He also says "jailbreaking" your iPhone, which is essentially unlocking it to allow unapproved apps, can put you and your contacts at risk for identity theft.

Telly says she had not updated the software on her iPhone 3, but planned to do so immediately. She hopes updating her software will keep her older iPhone safe from hackers.

"There are pictures of my kids that I don't want just anyone to see," Telly said. "I still don't know if it's harmless or what they were after."

Just this week, experts uncovered a security flaw with the latest iPhone 4S, which features a new voice command personal assistant called Siri.

Sharon Vaknin with CNET says somebody who takes your phone can use Siri to send a text message, get your friend's phone numbers, and even find out where you live.

"If your phone ever gets in the wrong hands, anyone can activate Siri, even with if your phone is locked with a passcode," Vaknin said.

Changing your iPhone security settings takes about 10 seconds.

LEARN HOW TO CHANGE YOUR SETTINGS

Bridge says iPhones are actually more secure than other types of smart phones. He says the number one thing to remember is not to lose your phone.

He says don't put it down at a restaurant, bar, or other public place. If someone grabs it, they can easily find out a lot about you.

Also, there is new technology called remote wipe. If someone takes your phone, you can wipe out all the information on it, protecting you and your contacts from identity theft.

If you don't have a smart phone already, you may soon be in the minority.

The research company Nielsen says more than 40 percent of U.S. adult cell phone customers have a smart phone.

Global technology researcher IDC expects 472 million smart phones will be sold worldwide in 2011, and that number is expected to rise to 982 million in 2015.

9NEWS learned about this story through a news tip. If you have a story you think we should know about it, you can email us at newstips@9news.com.

(KUSA-TV © 2011 Multimedia Holdings Corporation)

Comments  | Share your thoughts » What's this? Close TooltipPaid Distribution An Outbrain customer paid to distribute this content. We do our best to ensure that all of the links recommended to you lead to interesting content. To find out more information about driving traffic to your content or to place this widget on your site, visit outbrain.com. We welcome your feedback at feedback@outbrain.com. View our privacy policy here.

View the original article here