"a marketing and SEO company"
Critical infrastructure then.
/sarcasm
PWNED Welcome back to PWNED, the weekly column where we lovingly poke fun at other organizations' security screw-ups, in hopes the rest of us can learn a valuable lesson. This week’s story involves an IT department that ought to know better putting user credentials in the precisely wrong place. Have a story about someone …
"They had a strong password policy and even made users take security training. Then they moved offices, and that's when basic security hygiene went out the window."
I bet the users hated their "strong password policy" -- and possibly the (canned?) "security training" as well. There is no security measure so ineffective as one that everyone has been taught to hate. Finger pointing right on cue.
It depends on your definition of a ‘strong password’. The classic Correct Horse Battery Staple is a far better password than efhiuoh^$%£, because no fucker will be able to remember the latter and will write it down somewhere. So one and only one password policy, just length, minimum 20 characters - and if they complain say use the first line of your favourite book, etc.*
* yes I know a person’s favourite book could be gleaned from social media posts, and first line/sentence could be inferred, but better than most other methods. Also do not use ‘In the beginning God created the Heaven and the Earth’, because although that may well be someone's favourite book; but it’s a bit obvious. See social media posts. I don’t know what the first line of the Torah or the Quran are, but similar would apply.
The oblig XKCD is interesting, but given contemporary tech...it's a bit dated. A password made out of 4 random words would take about 32 minutes to crack with current tech (assumptions being the password isn't salted, or the salt is known). There are 171,000 actively used words according to the Oxford English, which seems like a fair number and prevents us breaking our own "ease of memorability" theory by introducing overtly purple prose into our passwords. E.g. Dave in the warehouse isn't going to remember "Sufficiently Succinct Perfunctory Pangolin"...100% hes fat fingering that one...so a reasonable subset is...reasonable. Based on that, we get eight hundred and fifty-two trillion permutations (if we go with 4 words)...you'll have to forgive me if my maths starts getting a bit "rounded", the numbers here are insane and I'm running out of paper...an RTX 4090 can do around 25GH/s (which is 25 billion a second), which means you can churn through 825 trillion hashes in approx 32 minutes.
The reality is, the word pool would be much smaller and therefore the permutations significantly fewer, since we need to ensure that all the words in the pool are simple and not flowery.
For bruteforcing, it doesn't actually matter the format of your password, only the character length matters, because whether your password is hard or easy to remember is irrelevant for a bruteforcing algorithm. All passwords are the same...only the length matters.
Memorable passwords only benefit the user, a long random password is fucking annoying for the user, because they will forget it, but it does lead to a side effect that also strengthens passwords...and that is rotation...you as a sysadmin will have to reset it so often that you won't have to worry about breaches and data leaks as much. Double edged innit?
@A/C
So your billions of calculations a minute are...well useless if you have a lockout policy of say 5 to 10 attempts.
Conflating stolen credentials and login passwords on a post-it note are completely different things.
Ref XKCD link,
Non-techy Luser here, sorry.
I've always been puzzled by the way that the "Horse Battery Staple" thing splits the words which feels to me like turning a 30-something character problem into several much smaller (& therefore more easily solved) problems. Presumably the answer is "hashes"? & I should just nod, smile sweetly and accept what those who understand such things tell me, & not cling onto my Bletchley Park-vintage concepts of code-breaking?
Using first line of book as pass phrase.
I can only remember the first lines of two books:
"Omnia Gallia divisa est in partes tres."
and
"It was a dark and stormy night..."
Which should I use?
> "Omnia Gallia divisa est in partes tres"† and "It was a dark and stormy night..."
> Which should I use?
Omnia was a Gallia dark in partes stormy tres – would be favourite.
Omnia was also the theocratic state founded by worshippers of Om on the Discworld continent of Klatch. The Omnian Quisition if not universally unexpected was feared.
† "Gallia est omnis divisa in partes tres"
That was certainly true. I was responsible for a number of earlier Novell Netware networks. Novell were based in Utah, and seemed partial to religious themes, like being forced to change user passwords after 40 days. Post-it notes had become a thing, and most of the systems that I saw had a few on screen bezels with passwords, and occasionally the account name as well. I "counselled" the relevant users and managers. It worked - No Post-its on bezels. I pretended that I didn't know that they were now under their keyboards.
My memory may be at fault here, but at one place I worked a while back, the new laptops did have sticky notes with employee name on them. But only enough info to turn them on first time. You then had to choose a Bitlocker PIN.
Even then, you couldn't log into the network without separately provided credentials.
The general policy should, if you want the security to be reasonably tight, be a secret and a token of some description that together get you into the account.
So, username, password and 2fa token system like a dongle or a mobile phone (provided that the mobile phone has some sort of security on it too).
A fingerprint isn't enough. The Sci-Fi author Michael Marshall Smith, in one of his stories details why. The protagonist is a small-time criminal engaged in a less than legal but highly lucrative trade. One morning this trade goes sideways and he is forced to request a loan from a colleague. Said colleague cannot provide said loan so offers an alternative. This consists of a finger attached to a small life support device, said finger giving access to the bank account of its former owner (who was deprived of his life around the time he was deprived of his finger). The lesson is simple: fingerprints can be stolen, secrets are more difficult to steal.
"So a shelf of new laptops with biometrics and a finger taped to each of them?"
Tempting... but no. Consumer-grade fingerprint scanners, and even fingerprint scanners that claim to be better than consumer grade, are notoriously easy to fool. They are designed as bolt-on module, designed to be made as small and cheap as possible rather than as secure as possible. See the Mythbusters episode from 2006 for a demo; things have not improved much since then.
What I don't get is why equally inexpensive webcams aren't used more often for biometric security. Computing power and software have evolved more than sufficiently for this. I live in South Africa where technology is hardly cutting-edge, but one of the local banks requires a selfie with a smartphone prior to certain transactions to verify the account holder's identity. Even on the most inexpensive devices this works well: the data is obviously sent to a back-end server, not processed on the device, so all you need is a camera that's good enough to determine the position of eyes, ears and other biometric features. So pretty much any laptop built in the past 20 years can do that. And even desktops have webcams these days more often than not, what with Zoom, Meet and Teams having become a staple of the modern office. Biometric security should have been as pervasive by now as well. But no.
I don't know what the SA bank system uses, bur every time I have used my camera as a 'log-in' or self-identifying device, part of the schtick has been an instruction to "Smile", or to "Turn your head" ("Left" or "Right" also being specified in that case).
Incidentally, 'gurning' works just as well - any physical displacement of features can indicate 'not-photograph' - but gurning somehow seems much more satisfying, at least to me.)
At Uni, late 70s, user accounts were of the form AAAAnnnn, and each year a new set was generated for the roughly-expected student intake. Passwords formed a similar sequential pattern. If we knew that the year's intake was 160 students, we could guess that 200 accounts were pre-generated, so by starting at the far end we had ~40 accounts with easily guessable usernames & passwords which would never be allocated. Since each had storage & CPU quotas this was a very handy way to get access to more resources, we just had to divvy-up the accounts between those in the know, and change the passwords.
Were I worked a long time ago. The someone wrote a program for the mainframe that let people do a kind of Usenet communication.
There was much discussion about it's security as it required a sign in with a password. The writers claimed the passwords were encrypted.
Well I knew how to see which files you used when running a program. So I eventually looked up which file was used. Then I made a copy of the file and then I changed my password.
Looking at the two files I found my user-id record (I have a unique name). I couldn't read either password at first. But they didn't seem to be totally random when I changed my password several times. But then I remembered that the nice raw file viewing program I was using let you view the file in several different encodings, like binary, octal, ASCII... and EBCDIC. Yes, the "encryption" was to store the passwords in EBCDIC. These were not IBM mainframes so better than nothing, but not much better.
With a pile of laptops stored insecurely, it would be trivial for someone to lift two or three, and they even have valid login credentials for them!
The secure way to handle this would be to have the staffers individually come to IT, show ID, collect their laptop, and enter their new password on the spot, so IT can verify they've done it without needoing to know the new password.
Yes, this is tedious, but not as tedious as a data breach.
To be fair, it's not them you have to convince, it's me. Some guy claiming to be my boss turned up 3 times today with what I think is a fake passport. He definitely looked like my boss, threatened me like my boss...but his passport looked a bit clean, so I told him to fuck off and had security kick him out of the building.
I got summoned to my bosses office to ask why I had him thrown out and had all his credentials revoked...I wasn't falling for that, so I asked for his passport again...it was only the same fucking one, so I had him thrown out again.
The "Papier Bitte" protocol has never failed me.
Lol this is so stupid I don't know where to begin. I put another post it over the top to cover the credentials. For those of you that don't have the kingly budget I have, you can simply fold one post it note in half...just remember to write the password on the inside after you fold it.
We had a junior once who wrote the passwords on before folding and sometimes it would be on the outside. Oh how we lol'd. The good old days.
In my hospital, the security is high because the sticky label, is *under* the keyboard.
Sometimes with additional security.There may be 2 or 3 old labels to obfuscate the real one…
Oh, and all the door access codes for the wards are written clearly above, but in high risk areas, it’s down the side of the wooden door frame.
Similar with a major UK airport, the door to the airside crew areas was in a public area but was secured with a six digit code
It had been carefully scratched into the plaster next to the keypad in a public area.
Obviously when it was spotted and reported by security facilities painted over it.
Leaving the impression of the code still visible but nicely painted.
Hide the password by taping it underneath your keyboard or mouse connected to your docking station, place the sticky note into your wallet, or write it on the back of your boss’s business card in said wallet, or even write it on the piece of tape placed over your camera, then cover that with a decoy piece of tape. Genius. Follow me for more super secure security tips.
I remember working with one of the test team, and as I was talking to him - he gave me "the Paddington stare". He said he was working out the password
You take the 3 letters of the month, move them forward by 3 letters, so Jan -> KBO, take the year and add 1 so 2026 becomes 2027 and put a ! or a ? depending on the parity of the month.
Wow I said - no wonder you were giving me the stare as you worked it out. No he said, I was looking past your right ear at the white board, where is is written down - it is the middle 8 characters of the 10 character string at the top, and I didnt have the right glasses on.
You say "Many years ago" but I can assure you that not that long ago, we were asked to do exactly that whilst the system was 'upgraded'. When I eventually regained control of my laptop, security was so tight that I was unable to open any file at all, never mind run a suite of programs necessary to perform my set tasks. The new company handling our systems couldn't believe that anything other than 'Office' might be required. "What do you need a data-acquisition system for?"
My customer, his consultant, the end-user and their associated entourage, visiting to inspect the (very expensive) machine operating as the specification demanded, witnessed the slow restoration of my hitherto esteemed status.
My wife still works at a company where IT expect her to hand her laptop over now and then along with her password, so that they can log in as her to install updates.
I told her that was F'ing nuts and no company on the planet has done anything remotely like that since at least 2002, and anyway there's no excuse for any IT dept anywhere to ask for your password.
Their reply?
"If your husband works in IT, then he'll know about User Profiles"
The adduser shell script at one place, actually emailed to the manager the added user's name username, cleartext password etc so he could send the password to any user who had forgotten his/her password. The new user entered the new password at the script's prompt in the manager's office when the account was being set up which as ok up to that point.
The script captured the password in a shell variable and used it on the command line (ie ps visible) to separately set the Unix and Windows passwords.
IT departments aren't typically staffed by sharpest tools nor the most consistent. Imagination definitely isn't top of the list of mandatory requirements.
(What tripped me up on my first day was that the script truncated my proffered password at the first white space [IFS]. )
This does annoy me "Even the IT department should not know your password, should someone in IT themselves turn rogue.". Making it 1000s times harder to support people with that. Yes, I understand but when you get some fuckwhit who's incapable of using their fucking fat fingers to type their login details into the fucking MFD to register their card, I end up just doing it myself so I can move on to the next ticket. So yes, sometimes, I do have to get them to give me their details.
Had one person insist "I'm doing it right, I'm doing anything wrong, the MFD just isn't working". OK, let me try, working with my details. Let me watch you "See, its not working, its not letting me in". OK, well way to test it is if you give me your login and I'll try. So I do. Doesn't work. I try to login to Windows with same details, doesn't work "This password is def wrong then".... "No it isn't" she bleets. "Look....oh...erm, there maybe a . at the end".
Oh look, now the fucking printer works.
Cunt!
Yes but then you can never prove "No, nothing was wrong with the MFD, you were just putting your password in". Sick of users blaming their fuck ups on IT so sometimes, you want to gently, without being an arse, show them without words that "You were putting your password in wrong".
for over 4 years a certain fruity phone maker had an EXTERNALLY ACCESSIBLE HR System.
Username was a type of fruit the company was named after
Password was the same fruit
This was a system showing employee names, addresses, job titles, contact details and whilst bank account were redacted to asterisks, it had the ability to "update" them with NEW bank details.
There was a rumor someone VERY famous at the company had their details changed, didn't notice for 2 months and the company glossed over it for reputation, paid the employee what they were due and never went after the thief. Because suing them would have exposed how incompetent they were behind the scenes and cost them a lot more