Showing posts with label Browsers. Show all posts
Showing posts with label Browsers. Show all posts

Friday, June 7, 2013

Why I’m Afraid For You

Okay, I just got back from my first day at the Ethical Hacker class. First, let me give you a background from where I come from.

See, my very first formal IT class was for Security+. And, like many other industries, the first class you take tends to color everything you do in that field. As an example, my first martial arts school was Taekwondo, so I tend to use more kicking than, say, a karateka. So when we deal with networking, I tend to think more on how to secure them, rather than implement or fix them.

So, I’m already scared of networks and the Internet. Of course, it’s necessary to use in today’s world as an IT technician, but a certain amount of trepidation accompanies what I do at work. Keep that in mind:  a small amount of trepidation.

Today’s class was quick, and spent more on legality of ethical hacking. We spent about 15 minutes of just looking at publicly accessible items, breaking no laws, and not even TOUCHING our target site. With about five minutes, we had:

  • The webmaster’s name
  • His work phone
  • His personal mobile phone
  • His direct employer (hint: he does NOT work directly for the company)
  • How long he’s been in that position
  • What type of server the website is hosted on
  • What types of technologies were used in the website (like javascript, Java, active server pages, etc.)

Okay, it took all of about half an hour to show us this. That’s half an hour WITH explanations and questions. That means all this information could be found within less than five minutes – and the attacker would never even be detectable at this stage by the target. And would not have broken any laws at all within that period.

So keep this in mind when the world starts talking about protecting your GMail with two-factor authentication, or when your IT department requires larger and more complex passwords.

Monday, December 17, 2012

Why all the big hubub about passwords?

1/5/12 - 45,000 Facebook passwords compromised
2/13/12 - Millions of passwords compromised from Microsoft India's site
6/6/12 - Six million passwords were stolen from LinkedIn website, compromising these users.
6/6/12 - 1.5 million passwords were compromised of dating site, eHarmony
11/14/12 - Millions of Skype passwords compromised
11/21/12 - One password stolen, causing the state of South Carolina to "lose" tax details for over 700,000 businesses statewide
5/12/12 - Stolen password allows a compromise of 1.1 Million users' data with Nationwide Insurance
And Experian has apparently had 80+ known security breaches of passwords, causing an ongoing investigation into all three major credit reporting companies.

These are a mere fraction of the ongoing attacks worldwide to online accounts. And these are just a tiny bit of the successful ones. Passwords are big business for the unethical computer geek. 

And the weakest link? YOU.

That's right - the weakest part of any security system is the users, both administrative and end-user alike. Don't take this an an insult; take it as a lesson you need to learn, and implement NOW. You see, there's a special type of computer attack, called "Social Engineering". And the interesting part is that it doesn't actually have to use a computer at all, though it often does, as we'll see later.

The movie-myth version of a hacker (actually properly known as a "cracker") sitting in front of a keyboard, typing furiously for hours to break into a Gibson computer and bring down the company is generally erroneous. But the Hackers movie has two things right: the weak password ("God"), and when Zero Cool/Crash Override calls the security guard and gets the number to the dial-up modem.

Whoops.

Social Engineering is defined on Wikipedia as:
"...the art of manipulating people into performing actions or divulging confidential information. While it is similar to a confidence trick or simple fraud, it is typically trickery or deception for the purpose of information gathering, fraud, or computer system access; in most cases the attacker never comes face-to-face with the victims."

In other words, they trick you into giving up some vital piece of information, often your password, or details to figure it out. Or they get you to reveal private details like your username. They might call you, email you, or text you.

In the movie, Crash Override tricks the guard into giving up a vital piece of information, allowing him to take over the TV network.

Okay, so that's Social Engineering. What about the title of this post (Passwords)?

See, passwords are often the only thing that separates crackers from getting into your account. Once that's gained, it's way too easy. 

So, you need a strong password. But what's considered "strong"? Basically, if any part of the password is found in the dictionary, it's a bad password. But you can't have a random string of characters and expect to remember it (well, most people can't, anyway). So you need a password that's hard to guess - even if the cracker has access to a 25-GPU Cluster that can make 63 billion guesses per second.

That's why it's important to make a STRONG password, not just an "okay" one.

What makes a strong password?

Generally, it's not complexity (though that's still a factor). It's LENGTH. Many systems still require only six character minimum. Some require eight. With today's technology, that's not nearly enough. Aim for TWELVE if you can. Maybe more. While most systems do have a maximum amount of characters, this number is very high (like 45+ characters), so you rarely need to worry about having too much.

The general requirements for complexity are that you need three out of the following four categories:
  • Upper case letters (A-Z)
  • Lower case letters (a-z)
  • Numbers (0-9)
  • Special Characters (@, #, !, &, *, and so on...)
You should have all four of these categories, even if your system doesn't require it. Also, don't make semi-obvious replacements (using @ for "a", as an example). 

What other items should I avoid when making a password?

Well, avoid keyboard patterns. I work as a desktop technician, and there was one point we had to gather every field users' passwords. Since they don't handle highly sensitive data, this wasn't a major issue, but we got to see what types of passwords are being used. Here are some examples:
  • Password4
  • Password9
  • Password99
  • P@ssword1
  • <usersname>1
  • <companysname>1
  • <dogsname>1
  • Poiuytrewq1
  • pl,okmijn
So they get from absurdly simple (and UNBELIEVABLY easy to crack), to relatively easy-to-find information (user name, company's name, pet's name), to...wait...what are those last two? They appear sufficiently random, don't they?

Nope. Look at any US keyboard, and check those keys in the order given. See any patterns emerging? We saw a lot of this, and people think they're being clever. The problem is that crackers are generally more so.

So let's avoid easily-guessable patterns and standard words as password bases, mkay?

Okay, so what can we do to get a strong, but memorable password?

First off, forget the word "password". Try to think in terms of "passphrase". In fact, many Linux systems are already thinking in this capacity.

Instead of a word, try thinking of a nonsense phrase. An example is "Correct horse battery staple". That's from a now-famous strip on XKCD, talking about how what seems to be a complex password might not be. It also shows how to make something nonsensical and somehow easy to remember. Throw in a number or special character, and now it's relatively impossible to crack (I say "relatively", because no password is truly impossible to crack - it just takes a LOT longer). 

So if I choose a nonsense phrase as my password (er...sorry, passphrase), why do I need to change it periodically?

Well, this is a two-part deal. 

First, if a cracker gets access to your account and you don't know, changing your password will immediately cut them off of access. This is generally not a big issue, as most crackers won't sit around silently, allowing you to retain your access. They'll dive in, get their information, cause whatever damage they want, and get out. But the process is still sound.

The second part has to do with how long it takes to crack a password. Remember that XKCD comic? They said it could take 550 years at 1000 guesses per second. But with advanced technology, crackers have significantly reduced that time to months or weeks - perhaps even less.

So if your systems password database is stolen, the encryption takes a while to crack, but not forever. If you change your password after the database is stolen, but before it is cracked, the cracker has just wasted a large amount of his/her time, and gotten nowhere. 

But with that huge 25-GPU machine you mentioned earlier, doesn't that make all this pointless?

Yes...and no. As I mentioned, passwords are often the only line of defense for your account - but they don't have to be. We can enable (on many, but not all, sites) 2-Factor Authentication. But that's a topic for the next post.

Monday, September 10, 2012

Monday Beginners: What is a Browser?

Many people confuse “internet” and “browser”.  In fact, many business users of computers seem to not know the term, “browser”.  As a helpdesk analyst, I would frequently ask users to open their browser, and they’d have no idea what I was talking about.  Once I finally explained it to them, they almost invariably respond with “Oh, you mean open the ‘Internet’!”.

No.  I said browser, and I meant browser.  Today’s post is dedicated to answering that distinction.


The Internet

The Internet is a collective term for all things online, across the world.  Wikipedia defines it as follows:

The Internet is a global system of interconnected computer networks that use the standard Internet protocol suite <snip> It is a network of networks that consists of millions of private, public, academic, business, and government networks, of local to global scope <snip>. The Internet carries an extensive range of information resources and services, such as the inter-linked hypertext documents of the World Wide Web (WWW) and the infrastructure to support email.

(I’ve snipped a couple of points because those parts don’t contribute to this discussion)

So, let’s take the above cited paragraph, and make a few key notes:

  • It is a global system, meaning it’s not just your home network, and it’s not your company’s network.
  • It uses the Internet Protocol (or, IP) suite – this is the system it uses as a sort of “address” for computers and networks.  It’s like a street address for your computer and/or network.
  • It is an extensive range of information resources and services – it is NOT just email, or just Google, or just a place to download illegal music and movies.  It is NOT the World Wide Web.  It is ALL of these, and much, much more.

The Internet uses a variety of methods, but in short, it is  what was noted above; a network of networks.  Your computer and router and/or modem at home is a network, connected to the Internet.  Your company’s system is probably a network.  All of these are part of the Internet.  The Internet is everything “online” that goes beyond the building in which you’re sitting/working.


The Browser

So, then, what is a browser?

A browser is a program, a tool that users and technicians alike use to view the World Wide Web (www) and Intranets alike (more on the difference between intranets and the Internet in a later post).  The browser itself is not the Internet, but it is how a person views the Internet.

If a person were to look at a web page in its raw form, it would be mostly unintelligible to all except the geekiest of geeks:

1:     
2:  <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "
http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">  
3:  <html lang="en" dir="ltr" class="client-nojs" xmlns="
http://www.w3.org/1999/xhtml">  
4:  <head>  
5:  <title>Internet - Wikipedia, the free encyclopedia</title>  
6:  <meta http-equiv="Content-Type" content="text/html; charset=UTF-8" />  
7:  <meta http-equiv="Content-Style-Type" content="text/css" />  
8:  <meta name="generator" content="MediaWiki 1.20wmf10" />  
9:  <link rel="apple-touch-icon" href="//en.wikipedia.org/apple-touch-icon.png" /> 
10:  <link rel="shortcut icon" href="/favicon.ico" /> 
11:  <link rel="search" type="application/opensearchdescription+xml" href="/w/opensearch_desc.php" title="Wikipedia (en)" /> 
12:  <link rel="EditURI" type="application/rsd+xml" href="//en.wikipedia.org/w/api.php?action=rsd" /> 
13:  <link rel="copyright" href="//creativecommons.org/licenses/by-sa/3.0/" /> 
14:  <link rel="alternate" type="application/atom+xml" title="Wikipedia Atom feed" href="/w/index.php?title=Special:RecentChanges&amp;feed=atom" />

All that code, and NONE of that actually shows anything on the screen yet (that’s only about 5% of the Wikipedia page I quoted above).  But it is code for your browser to process and do different things with it.  Some of that code allows it to show up better when searching for the page.  Some changes how the page looks on the screen.  Some simply point to other parts that process portions of the website.

What to take away from this, however, when a technician or analyst asks you to open the browser, they don’t necessarily mean “the Internet”.  They mean the browser.  The reasons for the distinction vary, but it is important for an end user to understand and apply the difference.


Types of Browsers In Use Today

Internet Explorer

This is by far the most common browser used today.  Why?  Because it come standard on all forms of Windows since 1995.  And most people don’t change their browser if they’ve already got one that works.

Internet Explorer’s (IE) icon looks like this: 

Safari

This is the most common browser in use by Mac users.  Like Internet Explorer in use for Windows computers, Safari comes standard with Macs.

Safari’s icon looks like this:

Mozilla Firefox

Also just referred to as “Firefox”, this is probably the 2nd-most used browser in the world today.  It is highly customizable, very effective, and free.  It is also included in many distributions of Linux operating systems. 

Firefox’s icon looks like this:

Opera

A growing browser, this is another free alternative to Internet Explorer and is also available on Linux and Mac computers, as well as Windows.

Opera’s icon looks like this:

 

Google Chrome

My current choice in browsers.  Available for most all major operating systems (Windows, Mac, Linux, and even some mobile platforms).  It is fast, customizable, and like all the others – Free.

Chrome’s icon looks like this:

 


There are hundreds of other browser options in the world today, each can be downloaded from the Internet.  Feel to try them.  So far, no browser worth using has ever cost money to download, so feel free to download, install and try them out!  The only one you can’t uninstall is Internet Explorer (And even that can mostly be removed, but I won’t show you how…yet).

 

If you have any comments or questions, comment on this page, or email me at jakcrockblc+blog@gmail.com.