Security Corner


October 30, 2012  11:05 PM

A cryptography contest

Ken Harthun Ken Harthun Profile: Ken Harthun

Huge kudos (and an as-yet-unspecified major award) go to the first person who deciphers the following message (hint–the photo is the key to the source of the message):

53‡‡†305))6*;4826)4‡.)4‡);806*;48†8¶60))85;1‡(;:‡*8†83(88)5*†;46(;88*96*?;8)*‡(;485);5*†2:*‡(;4956*2(5*—4)8¶8*;4069285);)6†8)4‡‡;1(‡9;48081;8:8‡1;48†85;4)485†528806*81(‡9;48;(88;4(‡?34;48)4‡;161;:188;‡?;

Post your comment with the cleartext here. The solution will be posted tomorrow on Halloween.

October 30, 2012  4:31 PM

Update on physical security failure

Ken Harthun Ken Harthun Profile: Ken Harthun

Hollering on the right channels seems to have gotten results. Here’s the update on the physical security problem I mentioned in my last post. These are excerpts from emails.

Us: We are experiencing another issue with our network cable in the Phone/Data Closet.  Our server was down again this morning.  Our Network Administrator, Ken, noticed that our network cables were not plugged into the correct jack.  He is extremely concerned about this.  Ken placed a sign in the Phone/Data Closet near our network cables stating for no one to touch our cables.

Building Management: To my knowledge, no one has been in the data closet. The key for the closet is secured and to my knowledge, have not provided access to the closet recently. On Monday, I will talk with Steve and see what we can do to improve security of your equipment.

Us: We are taking extra precautions to ensure that the cables will not be easily removed, however I glad to hear that  building management is making an effort in securing the closet.  So thank you for your immediate response.

My response to the above: They need to change the code for the key vault kept on the third floor and provide a list of people who have access to the code. Ms. <redacted>  may not have knowledge of who was in there, but someone surely knows who has the code. Tampering with data communications equipment is a federal offense, but I cannot take appropriate action unless I have some documentation as to who has access to the equipment and I do intend to report it to the proper authorities if this happens again.

Building Management: Maintenance changed the code on the key box this morning. As of right now, <redacted> is the only one with the new code. We will log any tenant/vendor requests to access the data closets. Keep in mind that we have a tenant expansion on the second floor that just commenced and you will be expanding your premises shortly, so there will be contractors accessing these closets periodically during construction. Upon the completion of these projects, we will change the access code again .


October 27, 2012  12:50 PM

Tale from the trenches: Physical security failure

Ken Harthun Ken Harthun Profile: Ken Harthun

Last Friday, a trouble ticket came in saying someone from our satellite campus could not access our database application. I immediately attempted to log in remotely and was unable to do so. The next check revealed that our NLAN link was down and had been since approximately 7 p.m. the night before. Our service provider checked the circuit and found no problems, but did not see a link to our router. An on-site investigation was in order.

Upon arrival, I checked the router and there was no link on the WAN port. Our closet is on the third floor and the connection runs to the phone/data closet on the second floor. The key to the closet is locked in a key vault with (supposedly) limited access to the code. The key opens all doors on all electrical and phone/data closets in the building. When I opened the door, the problem was obvious — someone had unplugged both cables to our third floor closet. I replaced them in the demarcation box and the network link was back.

Yesterday, while attempting to log into the remote server for user account maintenance, I discovered that the link was down again. This time, I had someone on site go to the closet and verify that the cables had not been unplugged again. I was told they were in place. I made another trip to the site.

Again, no link light on the router. I checked the closet and, sure enough, the cables were in place, but they had been moved to different (inactive) ports. I won’t print here the string of choice expletives that reverberated down the hallway! Once again, I corrected the problem. Then I placed a sign on the demarcation point that informs whoever is responsible for this that I will report further incidents to Federal authorities.

Several outpoints are present in this physical security failure:

  1. Anyone who has the key vault code can access critical infrastructure equipment;
  2. There is no list of who has been given access to the code;
  3. There is no way to log who accesses the key vault;
  4. There are no security cameras in the building, and;
  5. In both instances, the network went down on a Thursday evening.

It’s not likely that I will discover who did this (or who continues to do it, if it happens again) without cooperation of the building management. They don’t seem to be too concerned, but if it happens again, you can bet I will be making their lives miserable and withholding some lease payments until they put tighter security measures in place. For my part, I will be installing patchcord locks as soon as I can get them (see photo below).

 


October 25, 2012  1:54 AM

The 25 most popular (and most insecure) passwords of 2012

Ken Harthun Ken Harthun Profile: Ken Harthun

Halloween is only a week away and everyone is breaking out their scariest costumes. No doubt there will be plenty of fright going around on October 31 — all in good fun, of course — but there is some real-life scary stuff out there that would make Beelzebub squirm. I’m talking about the list of the 25 most popular passwords of 2012 published by Yahoo! on their Plugged In blog. It’s true horror at its best, at least for we Net Admins. Imagine the digital carnage that will certainly ensue, heaven forbid on our own networks.

Here’s the full list, along with how the popularity of the phrase has increased or decreased in the past year:

1. password (Unchanged)
2, 123456 (Unchanged)
3. 12345678 (Unchanged)
4. abc123 (Up 1)
5. qwerty (Down 1)
6. monkey (Unchanged)
7. letmein (Up 1)
8. dragon (Up 2)
9. 111111 (Up 3)
10. baseball (Up 1)
11. iloveyou (Up 2)
12. trustno1 (Down 3)
13. 1234567 (Down 6)
14. sunshine (Up 1)
15. master (Down 1)
16. 123123 (Up 4)
17. welcome (New)
18. shadow (Up 1)
19. ashley (Down 3)
20. football (Up 5)
21. jesus (New)
22. michael (Up 2)
23. ninja     (New)
24. mustang (New)
25. password1 (New)

I wonder how long “password” has been a popular password (probably forever). Will people never learn? Cripes! How hard is it to remember to at least pad it with some random characters. 89password(* is so much more secure and not at all difficult to remember. Send anyone you know who is guilty of using such weak passwords to Steve Gibson’s Password Haystacks page so they can learn how to create a personal padding pattern. Then, they can use all the simple (padded) passwords they want.


October 20, 2012  10:22 PM

Distributed passwords: A simple security precaution that works

Ken Harthun Ken Harthun Profile: Ken Harthun

Everyone of us has one: A user who has a “book” of passwords sitting in plain view at their workstation. This person absolutely insists on keeping passwords written down in longhand and refuses to use any type of password manager software. Yes, the book is usually closed and it’s not obviously labeled Passwords! in 72 pt. Arial Bold, but this means little in the way of true security. Any determined person could sneak in and look around. It’s a bad idea. Keeping the password list in your wallet is significantly more secure, but if you have a large list of passwords, this can be cumbersome. There is, however, one simple security precaution that works for those persons who insist on having a written list: Distributed passwords.

Distributed passwords derive from Public-key cryptography where there are two keys, one private, one public. Applying this principle to the password book, one simply splits the passwords into two sets of characters, writes one set down in the “public” book that remains visible and writes the other set down in a “private” book that is kept secret (perhaps by locking it up when not in use). This is extremely simple to implement and results in a much greater level of security. Here’s how:

Book 1                Book 2
Bank: 1234            Bank: 5678
Credit: 9876          Credit: 5432

You get the idea. The bank password is 12345678 and the Credit password is 98765432

This could be implemented with stored notes or spreadsheets as well, but if you are going to go through the effort of typing them and storing them securely, you may as well just use a password manager like KeePass or my favorite, LastPass.

In a future post, I’ll apply this principle to password succession in estate planning. Stay tuned.

 


October 20, 2012  1:35 PM

All credit card PIN numbers in the World leaked

Ken Harthun Ken Harthun Profile: Ken Harthun

Yes, it’s true. Every single credit card PIN number in the  World is known to the hackers, including yours. Don’t expect any notification from your credit card company, though because of course, I’m joking here.

There are only 10,000 possible combinations of four digits so, given any credit card in the world, the owner’s PIN will certainly have to be one of those numbers; moreover, it is absolutely guaranteed that you will share your PIN number with countless others. There’s nothing wrong with this because that will be the only thing you have in common: The credit card numbers themselves are all unique. The problem is that people are as bad at choosing random PIN numbers as they are at choosing strong passwords. It would follow, then, that some PIN numbers would be more common than others.

This post on the DataGenetics.com blog presents a PIN number analysis based on published tables of hacked password databases. 3.4 million four digit passwords were found by filtering the data. Every single one of the of the 10,000 combinations of digits from 0000 through to 9999 were represented in the dataset.

The most common four digit password was 1234. No surprise there. The least common four digit password was 8068 which showed up only 25 times in the 3.4 million passwords. Number 2 and number 3 were 1111 and 0000 respectively. The analyst found many passwords beginning with 19, likely corresponding to birth years with 1972 leading the pack.

It’s a fascinating, in-depth analysis that even seasoned Geeks like me will find enlightening.


October 12, 2012  5:45 PM

Don’t make these five security mistakes

Ken Harthun Ken Harthun Profile: Ken Harthun

Everyone knows it’s not safe out there in cyberspace. Your privacy and your money are at risk all the time if you don’t know and practice safe computing. In particular, five security mistakes can really set you up for disaster. This article from MakeUseOf goes into greater detail, but I wanted to give you my take on them, since I have been advocating safe computing practices here for years. Here’s the list:

  • Running without and/or not updating Anti-malware software
  • Running without a firewall
  • Poor email security habits
  • Weak passwords and/or passwords used more than once
  • Sharing personal information

No computer in existence should be running without anti-malware software and it’s absolutely unthinkable to let it run without updating. I recommend Microsoft Security Essentials for a worry-free solution.

A firewall running on your PC will prevent common internet malware from being able to access your PC’s open ports.

Never click on a link in an email if you don’t know the source of the email. In fact, never click on any link in any unsolicited email regardless of who it’s from, even if it appears to be from someone you know.

It goes without saying that you should always use strong passwords and never use them more than once. Yes, it’s a pain in the hindquarters, but the alternative is much worse.

Be very careful about sharing personal information with anyone, especially people you don’t know. For example, never let a credit or debit card leave your sight. Take your tab to the cashier and hand her your card so you can see it being scanned.

 

 


September 30, 2012  9:41 PM

Humor: How to destroy a hard drive in three easy steps

Ken Harthun Ken Harthun Profile: Ken Harthun

Couldn’t resist a bit of Sunday humor…

If you are looking to thoroughly and securely wipe a hard drive, here’s how to do it:

  1. Build a huge Tesla coil (a least 1 million volts);
  2. Place hard drive as shown in illustration below;
  3. Run Tesla coil for at least one minute.

 


September 29, 2012  2:15 PM

Honest Geek prevents potentional personal data disaster

Ken Harthun Ken Harthun Profile: Ken Harthun

Source: Internet

Had it not been for an honest Geek, a fellow Geek’s personal data could have been compromised. Here’s the story.

The honest Geek, calling in sick with the flu, was informed that one his sites had lost internet access. After some preliminary troubleshooting by phone, he attempted a remote access session and could not connect. Another phone call to the site to have someone reboot the server and the person reports the server says “Missing operating system.” Oh, oh. Same message after reboot. Oh, no! Makes trip to site (hasn’t been able to take a sick day for real in 15 months because of stuff like this). Walks into server room. Sees orange light glowing at USB port on front of server. Dawns on him that server rebooted over weekend due to updates. Removes thumb drive. Reboots server. All is well.

The thumb drive in question is not encrypted and contains some very sensitive personal information and was left in the slot by a consultant who was working on a telephone system upgrade. The good news is his data is safe.

The honest Geek will return the thumb drive upon receipt of further instructions from the owner who has been notified that his data is safe.

The honest Geek wonders what a fair ransom might have been, but figures that the lesson learned is sufficient. For those who wonder, the lesson is this: Personal information has no business being kept on a thumb drive that carries your Geek Toolkit. It’s simply too easy to forget to remove it when you are working in the field. If you simply must carry personal information with you, make sure the drive is encrypted.

Be careful out there.


September 29, 2012  12:38 AM

Send private data securely

Ken Harthun Ken Harthun Profile: Ken Harthun

In my job as a Network Administrator, I’m constantly called upon to reset passwords to email, network shares and sensitive corporate resources. Up to now, it has been my standard procedure to transmit passwords and other login information only by phone, but this is tedious and time-consuming and often becomes downright onerous as a rousing game of phone tag ensues. I found a better way, though, one that anyone can use to send any kind of sensitive information to anyone without fear of disclosure to the darker denizens of the interwebs.

What if you could compose a message, “Mission Impossible” style that would self-destruct after being accessed? Here are three different, free, web-based applications that allow you to create self-destructing messages.

Privnote – https://privnote.com – “Just write your note, and you’ll get a link. Then you copy and paste that link into an email (or instant message) that you send to the person who you want to read the note. When that person clicks the link for the first time, they will see the note in their browser and the note will automatically self-destruct; which means no one (even that very same person) can read the note again. The link won’t work anymore.” Privnote allows you to add a reference ID and choose to be notified when your note is read – a nice feature.

Burn Note – https://burnnote.com – “Each Burn Note can be viewed only once and then it is deleted. Deleted Burn Notes are completely erased from the Burn Note servers so it impossible for anyone to retrieve them.”

OneShare.es – https://oneshar.es – This is the simplest one of the three. You type your message, specify how long it lives before self destructing if it goes un-viewed and create the link. Similar to the other apps, the link can only be accessed one time before it dies. This is the one I have been testing in my job and I haven’t had anyone complain about it so far.

If I had a lot messages to send, I think I would prefer Privnote so I could keep track of them. Burn Note has some extra features that do a bit more than I need, but if I wanted to be really secretive about something, that would be the one I would use. OneShare.es is just right and the one that I plan to continue to use day to day.


Forgot Password

No problem! Submit your e-mail address below. We'll send you an e-mail containing your password.

Your password has been sent to: