Last year I commented on the analysis of leaked passwords from hotmail, gmail and yahoo. The results were rather depressing.
The social networking site Rockyou.com was hacked late last year, resulting in the exposure of some 32 million passwords from their own site and from partner social networking sites such as MySpace and facebook. Rockyou's policies of not requiring complex passwords and then storing said passwords in the clear was a ticking time bomb, and should be a lesson to other sites and to end users who may not understand the danger of sharing passwords between sites.
Well an analysis of the passwords revealed in the hack has been completed and the results are unsurprisingly, not dissimilar to the hotmail passwords revealed last year.
The top passwords revealed were:
1. 123456
2. 12345
3. 123456789
4. Password
5. iloveyou
6. princess
7. rockyou
8. 1234567
9. 12345678
10. abc123
Compared to the previous analysis of hotmail passwords:
1. 123456
2. 123456789
3. alejandra
4. 111111
5. alberto
6. tequiero
7. alejandro
8. 12345678
9. 1234567
10. estrella
And the results of an analysis of other recent password breaches showed a similar pattern with '123456' being incredibly popular....
The complete report is available here (pdf) and is worth a look.
No Microsoft haven't released a sucessor to Internet Explorer 8 (yet!)
The Australian is reporting that the French and German governments have warned people against using Internet Explorer due to the (as yet unpatched) security vulnerabilites that were allegedly exploited by the Chinese Government in cyberattacks against Google.
While I applaud any government effort to help ensure their citizens are provided with information on how to stay safe online, how to detect and avoid phishing attacks etc, I'm not sure I can agree with a Government picking out (or picking on) a particular piece of software.
Microsoft certainly has had a number of long running legal battles with the European Union, the most recent over their alleged browser monopoly, that was dropped after Microsoft agreed to include up to 12 other browser choice in European versions of Windows. Has this recent case and previous legal entanglements coloured the judgement of certain European government officials?
Microsoft are always the bad guys, the evil empire, the 800-pound gorilla, the easy target. It's something that comes with the territory of being so dominant in an industry. Windows and Internet Explorer have a less than stellar security record, but one that has been improving greatly since the start of their 'Trustworthy Computing' major security inititives back in 2002.
Are they perfect? No. But no software vendor is (or is even close!), as every major vendor regularly releases security patches. Will these same governments recommend users stop using Acrobat next time Adobe faces a 0-day vulnerability? Or stop using Safari? Or Firefox?
The high profile nature of the Google-China standoff (and I don't know what's worse, Google withdraws and the chinese people are punished, or China backs down to Google...) has thrust browsers and vulnerabilities back into the limelight for 5 minutes and I think some politicians want to have their soundbyte heard. I think their time and effort would be better used in continuing education for their end-users and letting them decide for themselves what software they want to use once they understand all of the risks involved.
The danger in pointing the finger at Microsoft and Internet Explorer is that it doesn't address the fact that these sort of attacks are out there and all software has flaws. It may give those people who do swap to Firefox or Safari a false sense of security 'because they're not using IE' (in much the same way I am critical of Apple's security attacks on Microsoft that paint OSX/Safari as being free of security problems). It seems to me to be a pretty shortsighted approach (but we are dealing with politicians right?).
Or maybe it's an EU thing and they want everyone using Opera instead?
*EDIT*
While there seems to have been plenty of hysterical articles about dropping IE and changing over to (insert favourite browser) NOW!, this one is much more balanced and sensible.
The Australian is reporting that the French and German governments have warned people against using Internet Explorer due to the (as yet unpatched) security vulnerabilites that were allegedly exploited by the Chinese Government in cyberattacks against Google.
While I applaud any government effort to help ensure their citizens are provided with information on how to stay safe online, how to detect and avoid phishing attacks etc, I'm not sure I can agree with a Government picking out (or picking on) a particular piece of software.
Microsoft certainly has had a number of long running legal battles with the European Union, the most recent over their alleged browser monopoly, that was dropped after Microsoft agreed to include up to 12 other browser choice in European versions of Windows. Has this recent case and previous legal entanglements coloured the judgement of certain European government officials?
Microsoft are always the bad guys, the evil empire, the 800-pound gorilla, the easy target. It's something that comes with the territory of being so dominant in an industry. Windows and Internet Explorer have a less than stellar security record, but one that has been improving greatly since the start of their 'Trustworthy Computing' major security inititives back in 2002.
Are they perfect? No. But no software vendor is (or is even close!), as every major vendor regularly releases security patches. Will these same governments recommend users stop using Acrobat next time Adobe faces a 0-day vulnerability? Or stop using Safari? Or Firefox?
The high profile nature of the Google-China standoff (and I don't know what's worse, Google withdraws and the chinese people are punished, or China backs down to Google...) has thrust browsers and vulnerabilities back into the limelight for 5 minutes and I think some politicians want to have their soundbyte heard. I think their time and effort would be better used in continuing education for their end-users and letting them decide for themselves what software they want to use once they understand all of the risks involved.
The danger in pointing the finger at Microsoft and Internet Explorer is that it doesn't address the fact that these sort of attacks are out there and all software has flaws. It may give those people who do swap to Firefox or Safari a false sense of security 'because they're not using IE' (in much the same way I am critical of Apple's security attacks on Microsoft that paint OSX/Safari as being free of security problems). It seems to me to be a pretty shortsighted approach (but we are dealing with politicians right?).
Or maybe it's an EU thing and they want everyone using Opera instead?
*EDIT*
While there seems to have been plenty of hysterical articles about dropping IE and changing over to
I came across an article recently that had me doing a double-take when I saw the date it was published. It seems the jokes we aussies like to tell about our neighbours 'over the ditch' being behind the times may be true, as in December the Waikato District Health Board over in Aotearoa was ground to a halt by.....conficker!
You read that right, December 2009. To refresh your memory, Conficker exploited a vulnerability that Microsoft released the MS08-067 patch for back in October 2008.
To put that in perspective, some other events from October 2008 were:
To make matters even worse (if that's possible) the NZ Ministry of Health was hit by Conficker 12 months earlier! Obviously there were no lessons learned from this earlier outbreak...
Good security is hard. It takes planning, organization and hard work. Unfortunately for the patients of the Waikato DHB, bad security is easy. It requires nothing more than apathy and ignorance. In this case it took not doing what even the most computer illiterate user knows are 'the basics' (patching and AV).
One can only hope that this is a wake up for organizations and Government departments, not only in NZ, but everywhere.
You read that right, December 2009. To refresh your memory, Conficker exploited a vulnerability that Microsoft released the MS08-067 patch for back in October 2008.
To put that in perspective, some other events from October 2008 were:
- Sarah Palin and Joe Biden have their only scheduled debate for the vice presidency of the United States
- U.S. President George W. Bush signs the US$ 700,000,000,000 bailout bill after it is passed by the House.
- Head of International Monetary Fund says the US Financial Crisis threatens to send the world into a recession.
To make matters even worse (if that's possible) the NZ Ministry of Health was hit by Conficker 12 months earlier! Obviously there were no lessons learned from this earlier outbreak...
Good security is hard. It takes planning, organization and hard work. Unfortunately for the patients of the Waikato DHB, bad security is easy. It requires nothing more than apathy and ignorance. In this case it took not doing what even the most computer illiterate user knows are 'the basics' (patching and AV).
One can only hope that this is a wake up for organizations and Government departments, not only in NZ, but everywhere.
No this post isn't about the cost of security - at least not in direct dollars!
I've been meaning to make this post for a while. Recently I read a great paper from Microsoft Research titled So Long, And No Thanks for the Externalities: The Rational Rejection of Security Advice by Users
Some of the points in this paper really hit home about challenging the common wisdom about why users reject or bypass security and the indirect cost to them for something from which they're unlikely to suffer.
Applying ecomomic ideas such as externialities to Information Security is not new, Bruce Schneier has commented on it in the past in regards to software development and it is also mentioned in a chapter in Beautiful Security (which I don't have handy to pull the reference from).
Despite the old gag definition of economics being "The science of explaining tomorrow why the predictions you made yesterday didn't come true today" it is sadly still a step up from much of the FUD, voodoo and magic numbers pulled out of the air by some IT and IT Security folk.
One of the great challenges is, as always, getting useful metrics...
Another major point in the Microsoft paper that really made me sit up and think was their assertation that "Thus, to a good approximation, 100% of certificate errors are false positives. Most users will come across certificate errors occasionally. Almost without exception they are the result of legitimate sites that have name mismatches, expired or self-signed certicates."
Thinking back over many years of surfing the 'net, I had to agree. I couldn't think of a particular instance where I encountered an SSL certificate error that wasn't a false positive.
The bad guys don't use SSL certificates....why bother when you can fool end users by placing a padlock as a favicon or just using an image of a padlock next to the login box on your phishing site?
Developers of legitimate sites don't help the situation either, by mixing secure and nonsecure content on the same page that brings up warning dialog boxes. What's your average end user to do? Assume the legitimate page is bad and deny themselves access to a service, or click on and further reinforce the message that it's alright to click OK on those boxes that appear and nothing bad will happen.
I visited two websites recently, both owned by major IT companies, that had mixed their secure and nonsecure content in this manner.
What's the solution? SSL everywhere and browsers that won't allow non-SSL verified connections?
Training end users is hard. Bringing them onside as allies in your security efforts without overburdening them with externialities or overstating the actual likely harm by using worst-case harm (ie: introducing FUD) is even harder.
I've been meaning to make this post for a while. Recently I read a great paper from Microsoft Research titled So Long, And No Thanks for the Externalities: The Rational Rejection of Security Advice by Users
Some of the points in this paper really hit home about challenging the common wisdom about why users reject or bypass security and the indirect cost to them for something from which they're unlikely to suffer.
Applying ecomomic ideas such as externialities to Information Security is not new, Bruce Schneier has commented on it in the past in regards to software development and it is also mentioned in a chapter in Beautiful Security (which I don't have handy to pull the reference from).
Despite the old gag definition of economics being "The science of explaining tomorrow why the predictions you made yesterday didn't come true today" it is sadly still a step up from much of the FUD, voodoo and magic numbers pulled out of the air by some IT and IT Security folk.
One of the great challenges is, as always, getting useful metrics...
Another major point in the Microsoft paper that really made me sit up and think was their assertation that "Thus, to a good approximation, 100% of certificate errors are false positives. Most users will come across certificate errors occasionally. Almost without exception they are the result of legitimate sites that have name mismatches, expired or self-signed certicates."
Thinking back over many years of surfing the 'net, I had to agree. I couldn't think of a particular instance where I encountered an SSL certificate error that wasn't a false positive.
The bad guys don't use SSL certificates....why bother when you can fool end users by placing a padlock as a favicon or just using an image of a padlock next to the login box on your phishing site?
Developers of legitimate sites don't help the situation either, by mixing secure and nonsecure content on the same page that brings up warning dialog boxes. What's your average end user to do? Assume the legitimate page is bad and deny themselves access to a service, or click on and further reinforce the message that it's alright to click OK on those boxes that appear and nothing bad will happen.
I visited two websites recently, both owned by major IT companies, that had mixed their secure and nonsecure content in this manner.
What's the solution? SSL everywhere and browsers that won't allow non-SSL verified connections?
Training end users is hard. Bringing them onside as allies in your security efforts without overburdening them with externialities or overstating the actual likely harm by using worst-case harm (ie: introducing FUD) is even harder.
A while ago I came across an interesting story on the register where Wikipedia have banned an IP address for posting racist comments - the catch? The IP address belongs to Volvo's IT division.
Wikipedia is a site that I imagine is not blocked or banned in many companies, as it's used as a major source of information by people all through business (the merits or accuracy of which is a discussion for another time).
Volvo aren't the first organization to be caught wikifiddling, when the Wikiscanner was released a few years ago a range of organizations were found to be questionably editing information, including the then-Australian Prime Minister's department and the CIA.
As far as I know the previous organization's 'outed' were mainly revealed to be engaging in pointless vandalism, such as changing Wolf Blitzer's name or adding 'jerk' multiple times to George W. Bush's profile.
A charge of racism is, however, a whole different situation, and one that can certainly bring extremely damaging attention to an organization.
But what to do? Blocking access completely is too draconian for most companies. Policies on blogging and editing online web 2.0 type sites (such as Wikipedia) are a start. Educating the workforce on the type of damage they can do and ensuring they know their access is monitored can act as a proactive deterrent. Combine this with web monitoring/auditing of access to enable follow-up on offenders can allow for quick follow-up in the event of an incident.
It often seems that even 'IT-savvy' staff can completely forget that their actions on the internet can be tracked, traced and may well leave a permanent imprint, especially when it comes to social networking. Adding some general awareness to Information Security education programs along with the usual 'don't click on attachments' may pay off in the long run.
Wikipedia is a site that I imagine is not blocked or banned in many companies, as it's used as a major source of information by people all through business (the merits or accuracy of which is a discussion for another time).
Volvo aren't the first organization to be caught wikifiddling, when the Wikiscanner was released a few years ago a range of organizations were found to be questionably editing information, including the then-Australian Prime Minister's department and the CIA.
As far as I know the previous organization's 'outed' were mainly revealed to be engaging in pointless vandalism, such as changing Wolf Blitzer's name or adding 'jerk' multiple times to George W. Bush's profile.
A charge of racism is, however, a whole different situation, and one that can certainly bring extremely damaging attention to an organization.
But what to do? Blocking access completely is too draconian for most companies. Policies on blogging and editing online web 2.0 type sites (such as Wikipedia) are a start. Educating the workforce on the type of damage they can do and ensuring they know their access is monitored can act as a proactive deterrent. Combine this with web monitoring/auditing of access to enable follow-up on offenders can allow for quick follow-up in the event of an incident.
It often seems that even 'IT-savvy' staff can completely forget that their actions on the internet can be tracked, traced and may well leave a permanent imprint, especially when it comes to social networking. Adding some general awareness to Information Security education programs along with the usual 'don't click on attachments' may pay off in the long run.
Looks like our govenment has decided to increase it's efforts in 'cyber-security' by retiring the old GovCERT and rolling the excellent AusCERT into the new CERT Australia (although they need a snappier name!).
It's encouraging to see the government making an effort to assist and encourage increased information security awareness, amongst both businesses and individuals. I can only hope it all works out better than the National Broadband Network and National Internet Filtering Scheme have so far...
Next week David Campbell, the Director of Australian Government Computer Emergency Readiness Team is speaking at the AISA Annual Seminar Day in Sydney, so I'm looking forward to hear what he has to say about this new body, it's mandate and goals.
It's encouraging to see the government making an effort to assist and encourage increased information security awareness, amongst both businesses and individuals. I can only hope it all works out better than the National Broadband Network and National Internet Filtering Scheme have so far...
Next week David Campbell, the Director of Australian Government Computer Emergency Readiness Team is speaking at the AISA Annual Seminar Day in Sydney, so I'm looking forward to hear what he has to say about this new body, it's mandate and goals.
Microsoft's Mark Russinovich (formerly of Winternals fame) has posted a great bit of information busting a popular myth about duplicate SIDs on cloned machines.
I admit, I always thought running something like NewSID was mandatory on cloned machines for correct Windows domain and WSUS functionality, but apparently that's not the case.
I can recall some product (it may have been Trend AV, but I could be wrong) that did seem to rely on the machine SID (ie: on cloned machines pre-NewSID there were problems), but then Mark does mention that while no Microsoft applications look at the machine SID, other 3rd party applications may still require the use of something along the lines of NewSID.
Also be wary of cloning machines after joining them to a domain as duplicate domain SIDs are a different thing entirely and can cause headaches...
I admit, I always thought running something like NewSID was mandatory on cloned machines for correct Windows domain and WSUS functionality, but apparently that's not the case.
I can recall some product (it may have been Trend AV, but I could be wrong) that did seem to rely on the machine SID (ie: on cloned machines pre-NewSID there were problems), but then Mark does mention that while no Microsoft applications look at the machine SID, other 3rd party applications may still require the use of something along the lines of NewSID.
Also be wary of cloning machines after joining them to a domain as duplicate domain SIDs are a different thing entirely and can cause headaches...
Subscribe to:
Posts (Atom)