Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Wednesday, September 12, 2007

WiFi Nightmares

If you like a good fright, here are a few of my worst WiFi nightmares for you.
  • Homeowners sometimes feel that they have nothing to steal and nothing to hide on their home computers, and so they install WiFi networks without any security measures. But there is a wealth of information on any computer that bad guys can use to steal someone's identity, and thats only the beginning.

    Homeowners who leave their WiFi networks unprotected may have their data and applications erased. They may have spambots or other malicious hacker applications installed. Their machines may be employed to share illegal music files or distribute kiddie porn. Then, one day, the FBI will come knocking.

  • Students spend a lot of time on the Internet, much of that connected to wireless networks at school, at home or anywhere else they happen to be. Music file sharing, like underage drinking, is illegal, but it happens. When it does, students can compromise the performance and security of the networks they are using and they can get arrested and/or get kicked out of school.

  • Business executives usually need to have file and print sharing enabled on their laptops for when they are in the office. On the road, many of these men and women check their email and surf the web in airport lounges, at Starbucks, in their hotel rooms, or anywhere else they find an open WiFi network.

    Unless a road warrior takes steps to protect him/herself, anyone else on an open WiFi network can scan his/her shared files and folders, looking for credit card numbers, usernames and passwords, trade secrets, and other confidential information. On line and on the road, opportunities for identity theft, insider trading, industrial espionage, blackmail or just plain embarrassment abound.

  • Professional people -- doctors, lawyers, accountants, investment managers, etc. -- have ethical responsibilities to exercise care and judgment in the conduct of their affairs. If they don't, they may face sanctions including disbarment, client outrage, fines, and even jail.

    Down the street from me, near a hospital, there is "Professional Building" with offices for doctors et al. Standing outside the office building, wardriving, you can pickup several unencrypted, open network signals. Doctors' offices have lots of valuable information that bad guys would love to have for the purposes of committing identity theft, credit card fraud, prescription forgery, et al.

    WiFi security is a dicey proposition. It is not something that many lay-people understand. All they know is that implementing security complicates matters both in terms of initial network setup and ongoing operation So, many people forgo security entirely, preferring to think that nothing bad is going to happen to them.

  • Troubleshooting WiFi networks is a time-consuming process which does not always yield a positive outcome. A positive outcome is defined as a happy ending that doesn't cost a lot. A happy ending is fast, reliable Internet/network access.

    But, if there are dead spots in your WiFi coverage area or if your Internet access is slow or intermittent, it could cost you a lot in terms of dollars and frustration to identify the cause and resolve the problem.

    Let's say you live in an apartment and one of your neighbors has an old cordless phone that operates in the 2.4 GHz frequency range. Whenever that phone is in use, your WiFi network crashes. Let's assume that you know nothing about the neighbor's phone. You only know that your network keeps crashing.

    So you summon a technician to resolve the problem. The first (and only?) thing a technician can do is undertake a process of elimination to isolate any hardware or software issues that might be causing the problem.

    Imagine that the network crashes while the technician is there because the neighbor makes a phone call. While the network is down, the technician swaps out your access point. Meanwhile your neighbor gets off the phone, so when the new access point is installed, your WiFi is working. The technician declares victory, gives you a bill and leaves. This temporary "solution" has cost you a couple of hundred dollars.

    There are tools (radio frequency spectrum analyzers) that can identify WiFi interference from cordless phones, Bluetooth devices, microwave ovens, radio jammers and other sources of electromagnetic noise. But these tools are expensive, and they work better in the lab, in the hands of radio engineers, than they do in the field, operated by your average computer technician.

WiFi, when it behaves, it is a pleasure to be around. But very often, WiFi is like a difficult child who does not always behave. It doesn't care who you are, or how much you've spent on your laptop. "You are not getting an IP address from me today, mister!"

If you have a WiFi nightmare you want to share, please post it here. TIA.

Friday, March 02, 2007

Gimme KeePass!

Following up on my recent post, OpenID Is Not For Me, here is a better solution...

If you are like most people, you have a default user name and password combination that:

  • You can easily remember
  • You use almost everywhere to log on to computers, networks and web sites.

You may also have a post-it note somewhere with user names and passwords that you cannot remember because they are different than your default combination.

Few people do what the experts recommend:

  • Use "secure" passwords (long strings made up of upper and lower-case letters, numbers, and special characters).
  • Use different passwords to access different networks, different services and different hosts.
  • Change your secure passwords regularly.

Here is a solution that I designed to get me on the path of goodness and righteousness. I have been using it for a few weeks now, and I am prepared to recommend it to you. Here's how it works for me...

  • I got a U3 USB flash drive which I keep on my key ring, so I always have it handy.
    • U3 allows a flash drive to store and, when plugged into any Windows PC, securely run applications -- without leaving a trace of data on the host computer. For more info, see http://www.u3.com/.
  • I loaded KeePass on the U3 drive.

Features of KeePass include:

    • Download the Windows Keepass 1.06.U3P file from here: http://keepass.info/download.html.
      • Save it to your hard disk.
      • It saves as KeePass-1.06.zip. Rename it to KeePass-1.06.u3p.
      • Start the U3 Launchpad from the System Tray
      • Select Add Programs, then Install from My Computer
      • Browse to find KeePass-1.06.u3p.
      • Click Open and the Windows version of KeePass is installed in the Launchpad of the U3 USB flash drive.
    • If you need access to your passwords and data on non-Windows platforms (Mac & Linux), like I do, download KeePassX from here: http://keepassx.sourceforge.net/downloads/.
      • I got the Application bundle (I need the Linux functionality only).
      • Save it to your hard disk, unpack it and copy the KeePassX folder/directory to the /media/usbdisk/ location (NOT the media/U3 System/ location).
      • To run KeePassX from the flash drive, navigate to the KeePassX folder and run the shell script.
  • Create a new database and start changing your passwords!
    • Use KeePass (i.e.,the Windows version) to initially create your password database. The default KeePass database categories were a little better for me than the default categories in KeePassX.
      • It doesn't matter which version of KeePass you use to create (or update) a database, it interoperates with both KeePass and KeePassX.
    • Different web sites, hosts and services have different conventions regarding acceptable passwords -- the allowable character set (e.g., upper and lower-case letters, numbers, and special characters), password length and password complexity. Use the random password generator, setting it to be as long as allowed and using the largest character set allowed.
    • When adding user names and passwords for web sites, put in the URI for the https: login page, so you can jump from the database entry to the place where you will paste your new password.
      • This will save you having to drill down to the log in page.
  • Here are a couple of other recommendations:
    • Don't save your KeePass database to a USB flash drive only. You need to have a backup copy to protect yourself in case the drive is lost or broken.
      • Keep a copy of the database on the hard disk of your PC and remember to update the copy periodically.
    • I selectively let my home and office PCs remember user names and passwords, so I am not always having to go to my KeePass database.
      • The issues here are the probability of unauthorized access of those machines and the potential harm that could come from anyone accessing the sites/services as me.

You are ready to go now. You can take your U3 USB flash drive to almost any Windows or Linux PC, plug it in and access your services, hosts and web sites safely and securely. All your passwords can now be random and highly secure. And you can change them frequently, like you are supposed to do.

Go forth in the path of goodness and righteousness!

Thursday, March 01, 2007

5 Reasons: OpenID Is Not For Me

You may be willing to trust your online identity to an OpenID service provider or ID broker; not me. Here are five good reasons why I want to stick with user names and passwords to identify myself to parties I deal with on the Internet.
  1. I understand user names and passwords. OpenID is an evolving open standard. It will be implemented differently by different ID brokers. It will also be implemented differently by web sites for authentication and security purpose. There is a lot I don't understand about OpenID.
  2. I don't want security to be transparent and unobtrusive (see below). I want to log in as I move about the Internet, so I know when I am more or less anonymous versus when I am a client or customer. I want to fill out a form to register on web sites so that I control what different organizations know about me. If security is transparent and unobtrusive, I won't be able to tell when security is on, and I won't know who knows what about me.
  3. The OpenID authentication process is vulnerable to man-in-the-middle phishing schemes. If one of your OpenIDs is stolen, the potential for harm to you is substantial.
  4. People are probably going to have more than a few OpenIDs, each with several profiles, with different ID brokers (AOL, Yahoo!, VeriSign, et al.). Keeping track of these ids and profiles will be no simpler than managing user names and passwords. Unless and until OpenIDs replace user names and passwords, OpenIDs will be an extra layer of complexity for users to contend with.
  5. Having users with multiple OpenIDs presents real challenges for organizations doing business on the Internet. One individual's data at a given organization may be associated with multiple OpenIDs. This will complicate that organization's data mining and customer service efforts.

Unobtrusive Security: One of the promises of OpenID is that it will make it easier for users to gain access to web sites (originally blogs). No more filling out forms to register to use a site. Just use your OpenID. Web sites may request your OpenID and check with your ID Broker to register and authenticate you. Once you log in with your ID broker, your OpenID is verified and certain authentication and demographic information that you have provided to your ID broker is passed to the requesting web site.

If you have an active session with your ID broker, all you have to do is give your OpenID, and the authentication and demographic information is passed to the web site. No login required. To further simplify the process, a web site may unobtrusively read your OpenID, register you and log you in without your involvement in the process.

Friday, January 26, 2007

Password Q&A

Jim from Moline writes, "All the banks, merchants, websites, etc. that I deal with online limit the number of times I (or anybody else) can try (and fail) to log in to my accounts. Why do I need to be concerned about the vulnerability of my online data to "brute force" or other trial-and-error hacker attacks on my password?"

Interesting question, Jim. There's more to it than meets the eye.

For example, some users don't understand what's wrong with using their wedding date as a password. Afterall, if they have a hard time remembering their anniversaries, what are the chances a hacker will be able to figure it out?

A hacker won't have any trouble. A hacker will simply try every mm/dd/yy combination to crack those passwords (before trying every possible combination of numbers, letters and symbols to crack any password).

Similarly, Jim's concept of what a hacker can do is dangerously limited. Jim is assuming that the hacker is outside the network wall, looking at the secure sign-in dialog box.

Unfortunately, there are lots of "holes" in most network walls. And it is not uncommon for hackers to gain access to files containing thousands and thousands of usernames and encrypted passwords controlling access to the networks and systems of banks, merchants, websites, etc.

Your system administrators are some of the biggest violators their organizations' password policies. Administrative passwords are often easy to crack or discover via "social" means.

It is not unreasonable to imagine a disgruntled employee gaining administrative access to his/her company's systems and copying a file of usernames and encrypted passwords. That person can then misuse the information or release it to others to misuse it.

Given that people often use the same username and password combination for many online accounts, imagine that somebody steals the file of usernames and encrypted passwords at a website where you got something once. They crack the passwords, then go to all the major banks and see which username and password combinations open accounts at each bank. If they hit your bank with your stolen username and password, would they get access to your bank account? I'd say yes, unless you can tell me otherwise.

Here's a link to a clear and concise Users Guide to Password Security: http://comm.ncifcrf.gov/security/password.html. It provides a good explanation of the issues and risks. It also endorses certain practices for password security that would greatly improve online security.

But, I am afraid that these practices are too complicated for most users and most situations.

There is a "missing link" needed to enable these practices for ordinary users. It is a class of products to generate, store and properly present unique, secure passwords at each place a user has accounts.

Like a wallet or keychain, it is a product that people could use to keep their valuable account information safe and handy. It could be a piece of software residing on a user's PC or PDA; (see http://www.download.com/3120-20_4-0.html?tg=dl-20&qt=password%20wallet&tag=srch). It could be a database stored on an "ID provider's" secure website in cyberspace (see http://en.wikipedia.org/wiki/OpenID), or it could be an encrypted USB thumb drive a user carries everywhere they go (see http://en.wikipedia.org/wiki/TrueCrypt).

Until you start following recommended password security practices, your online information and accounts at banks, merchants and websites really are vulnerable to hackers. Your privacy could be compromised. Your identity and/or your money could be stolen.

If you are a senior executive in your organization, here's a service you can do for your company and your community. Implement this policy that they have at the National Cancer Institute/Ft. Detrick:

"In order to keep up security on our systems, we run a program called Crack on your password. We figure that if we can find out your password, so could an Evil Cracker. If we discover your password that way, we'll freeze your account to keep anyone else from abusing your account. You will be notified that you have to change your password to a more secure password. He/She will make sure you understand everything discussed in this write-up before unfreezing your account."