Security Corner

April 30, 2014  9:11 PM

Change all your passwords now

Ken Harthun Ken Harthun Profile: Ken Harthun

managing-passwords-2012_06This is something I have never advised anyone to do, but I’m doing it now: change all of your passwords. There have been so many breaches recently that I don’t trust any of my passwords to still be secure. I doubt that I’m even a serious target, but I’m not taking any chances. You shouldn’t take chances either.

I’m talking about things that matter, like banking and credit card sites and online bill payment sites – anything that may contain your credit card, bank info, or other payment information. Change PayPal, too, unless you are using two-factor authentication; even with 2FA, it’s not a bad idea to change the password.

With the recent Heartbleed, IE, Flash, and Apple vulnerabilities, it’s not safe to trust your information on any sites to an insecure password. When you change them, make sure they are at least 12 characters and don’t include any recognizable dictionary words. I’ve given you many ways to create a memorable secure password, so just search “password harthun” and you can find those.

April 30, 2014  8:20 PM

Apple Developer Center leaks developers’ & employees’ personal info

Ken Harthun Ken Harthun Profile: Ken Harthun

125px-Apple-logo.svgOn Sunday night, Apple took down its Developer Center to patch a security hole that allowed anyone to access personal contact information for any registered developer, any Apple Retail or corporate employee, and even some key partners.

According to 9to5Mac, a Macintosh-focused news venue, a tipster sent an email into its tips box “that contained the personal contact information – including cell phone numbers – of several of the publication’s staffers, as well as a few high-ranking Apple executives.” You can read the full article at the link above.

In a stellar example of responsible disclosure, 9to5Mac withheld any information until after Apple fixed the issue:

Due to the critical nature of the problem, we would never reveal this type of flaw to the public until it had been dealt with and we had contacted Apple . As of last night, the hole has been patched. Keep reading for the full details of how the breach was executed and exactly what information was at risk.

Good for them!

April 29, 2014  8:46 PM

AOL mail breached – users should change passwords

Ken Harthun Ken Harthun Profile: Ken Harthun

If you are (heaven forbid) an AOL mail user, change your password immediately. There has a been a large scale breach of AOL Mail accounts. Passwords, security questions, mail addresses and even contact lists were compromised, though the data were encrypted. According to AOL, no users’ financial information was compromised, and the encryption on passwords and security questions has not been broken.

There is, however, a big difference between encryption and hashing. It’s easy to implement a brute force attack against hash tables, not so easy (actually nearly impossible) to break encryption. Since we don’t know details here, it’s best to change your AOL Mail password and security question.

Sophos, in this blog post, says:

What to do if your account was compromised

If you’re an AOL Mail user, visit to change your password and security question immediately.

If you use the same password as your AOL account for other websites, change those passwords as well – and remember, you should use a unique password for each of your online accounts in case one of them is compromised.

Consider using a password manager such as LastPass or 1Password to generate and store complex passwords.

April 29, 2014  6:27 PM

Update Flash and switch to “click to play”

Ken Harthun Ken Harthun Profile: Ken Harthun

From Krebs on Security:

Adobe Systems Inc. has shipped an emergency security update to fix a critical flaw in its Flash Player software that is currently being exploited in active attacks. The exploits so far appear to target Microsoft Windows users, but updates also are available for Mac and Linux versions of Flash.

This is also tied in with the vulnerability in IE that I posted yesterday.

Flash is required on many web sites (I won’t rant about this now, but that is really pretty stupid, given Adobe’s dismal security record), but that doesn’t mean you have to allow it to run willy-nilly. Google Chrome, Mozilla Firefox and Opera allow you to block plugin activity, giving you the option to run it only when you trust the site. Krebs posted an article on how to do this here.

April 28, 2014  5:23 PM

Stop using Internet Explorer – for now

Ken Harthun Ken Harthun Profile: Ken Harthun

Stop using Internet Explorer and switch to an alternative browser immediately. Microsoft just announced a zero-day vulnerability in Internet Explorer that is being actively exploited in targeted attacks; they have not yet issued a fix. All versions of IE are affected.

According to security firm FireEye, the attack, dubbed “Clandestine Fox,” is a remote code execution vulnerability. The Microsoft security advisory, CVE-2014-1776 says this:

The vulnerability is a remote code execution vulnerability. The vulnerability exists in the way that Internet Explorer accesses an object in memory that has been deleted or has not been properly allocated. The vulnerability may corrupt memory in a way that could allow an attacker to execute arbitrary code in the context of the current user within Internet Explorer. An attacker could host a specially crafted website that is designed to exploit this vulnerability through Internet Explorer and then convince a user to view the website.

This means that you don’t have to do anything at all except visit a poisoned website to be affected. There is no patch, but Microsoft is recommending that Internet Explorer users install its free Enhanced Mitigation Experience Toolkit (EMET) to harden security of Windows systems.

I recommend you stay away from IE entirely and run an alternative browser.

Be on the lookout for an out-of-band patch from Redmond.

March 30, 2014  4:12 PM

Who supports 2FA (two-factor authentication)?

Ken Harthun Ken Harthun Profile: Ken Harthun

In light of the plethora of data breaches in the news, it behooves us to use two-factor authentication (2FA) where it is available. I use it for important accounts like LastPass, eBay and PayPal. Where it is offered on other financial accounts, I use it. You should, too. But how do you know who offers it? Here is a great website that shows who does and doesn’t offer 2FA and what methods they use:

I’m going to be setting up 2FA on all of the listed services I use and for which I don’t currently have 2FA enabled. I suggest you do the same. Can’t hurt and can only help by making it more difficult for the cybercriminals to get access to your information.

March 29, 2014  9:58 PM

Turn off email preview in your email client

Ken Harthun Ken Harthun Profile: Ken Harthun

In light of Microsoft Security Advisory 2953095, I am restating advice I first published in 2008. While this particular vulnerability may not be directly related to previewing email messages, it is still a viable attack vector.

Here is what I originally called “Security Maxim #6:”

Some of these tips may very well be “everybody knows” types of things, but I find that these are often the things that get overlooked. That’s why I’m publishing them as computer security maxims. Take a look at the recent furor surrounding the cold boot attack against disk encryption . That was an “everbody knows,” too.

I get questions all the over at Ask the Geek [site no longer active] about using a mail client’s message preview feature. Opinions vary, of course, but for this geek, it’s a bad idea. In order to preview a message, it has to be opened or rendered by the HTML engine. Think about how a PC can be infected by a malicious web site and you’ll immediately understand the danger: The same malicious programs can exist in scripts in HTML messages. It’s a serious security risk.

Security Maxim #6: Always disable any message preview or auto-open features in your e-mail client. View messages as text-only until you know they are safe.

March 29, 2014  9:36 PM

Oh no! Not another password post!

Ken Harthun Ken Harthun Profile: Ken Harthun

bad-passwordsYes, another post about passwords, choosing secure ones. Unfortunately, they aren’t going to go away anytime soon and, equally unfortunately, they are getting easier and easier to break. In a recent blog post, Bruce Schneier said: “As insecure as passwords generally are, they’re not going away anytime soon. Every year you have more and more passwords to deal with, and every year they get easier and easier to break. You need a strategy.”

Indeed. Agreed. I’ve written many posts about how to choose secure passwords. I’m not the only one. In addition to the blog post mentioned above, here are some other resources that have strategies designed to help you create secure passwords. Oh, and regardless of what any of these articles say is the best length for a password, I recommend no fewer than 12 characters and prefer 15 characters. This number is always a moving target, subject to adjustment upward as computing power increases. Here’s my top five list:

Steve Gibson’s Password Haystacks:
My article: Is your password “qeadzcwrsfxv1331?”
Sophos’ How to Choose a Strong Password:
Roger Grimes’ Creating strong passwords is easier than you think
Microsoft’s Tips:


March 26, 2014  1:55 AM

Thwart predators and social engineers with a passphrase

Ken Harthun Ken Harthun Profile: Ken Harthun

I don’t remember exactly where I saw it or heard it, but I recall a story about an incident where a child was approached by a (potential) sexual predator.  The child was told his mother wanted him home right away and — we’ll call him Mr. Friendly — Mr. Friendly was there to pick the child up. The child then asked Mr. Friendly for the password and was able to get away in the resulting delay caused by the confusion when Mr. Friendly couldn’t remember the password. The lesson learned here is that every child should have a secret passphrase and only trust those who can repeat that passphrase back to them. This could save countless lives. In fact, my wife had all our kids indoctrinated in this trick back in the day (she just reminded me). Thank heaven the kids never had to use it.

It could also save your corporate network.

Social engineers who call you pretending to be from Microsoft, your corporate office, or some other normally trusted entity are just the digital version of Mr. Friendly. And the same tactic will work on them.

Your organization should have a passphrase that is required to be known by every person on your help desk and any and all support personnel. Every staff member should be required to ask any caller who seeks sensitive information to repeat the passphrase. The passphrase should be changed on a frequency that is appropriate for your organization.

A typical scenario may go like this:

Caller: “Hello, this is Corporate Help Desk. We’ve noticed you have a virus. We can remove it, but we need your user name and password.”

You: “Sure, be happy to help you. What is the passphrase for today?”

Caller: “Ummmm.”

You: <click> <dial IT deparment>

IT: “Hello, IT.”

You: “I just received a call from 555-5555 asking for my login credentials. They didn’t know the passphrase.”

IT: “Well done. Just in case, we’re forcing a reset of your password.”

Trust No One on the internet…

March 17, 2014  2:49 AM

KrebsOnSecurity hit with massive WordPress pingback attack

Ken Harthun Ken Harthun Profile: Ken Harthun

In a March 14, 2014 blog post, Brian Krebs revealed that his site, KrebsOnSecurity, which runs on WordPress, was hit by a DDoS attack:

On Wednesday, KrebsOnSecurity was hit with a fairly large attack which leveraged a feature in more than 42,000 blogs running the popular WordPress content management system (this blog runs on WordPress). This post is an effort to spread the word to other WordPress users to ensure their blogs aren’t used in attacks going forward.

I covered the details of the attack method in my last post, but I also want to help spread the word to other WordPress administrators via the list of attacking sites that Mr. Krebs provided:

My hosting provider shared with me a list of the WordPress blogs that were used in the attack on this blog. I’m sharing it here to get the attention of WordPress administrators. I realize that some readers will view this as providing a roadmap for attacks, but I’m hopeful that making this information public will decrease the number of blogs that can be used in future such attacks.


Forgot Password

No problem! Submit your e-mail address below. We'll send you an e-mail containing your password.

Your password has been sent to: