Showing posts with label passwords. Show all posts
Showing posts with label passwords. Show all posts

Wednesday, December 12, 2012

Ransom hackers encrypt medical centre's entire database

An Australian medical centre is reported to be considering paying a ransom demand of $4,000 AUD (US$4215) after blackmailers broke into the organisation’s servers and encrypted its entire patient database.

 If crime doesn't pay, why is this clinic considering making it profitable? Paying ransom only perpetuates the problem. Instead they should be spending the money on securing their systems. The clinic should be asking themselves:


  1. Why should I make this crime profitable for the attacker? 
  2. How do I know they will provide the password and instructions for decrypting the data? 
  3. How do I know that if I decrypt the database, the data hasn't been tampered with? 
  4.  If I pay the ransom, what is to stop them from increasing the demand lest they publish the data online?
  5. What is a better plan for securing the systems and moving on? 


They already lost once. If they don't bite the bullet and move on, they risk losing again and again. They would also be giving the attackers valuable incentives for attacking more sites.

Monday, November 21, 2011

Illinois Water Utility Pump Destroyed After Hack

A cyber attack on a Springfield, Ill. public water utility resulted in the destruction of one of its pumps, according to a security expert.

While I would do away with alarmist statements like "This required almost no skill and could be reproduced by a two year old with a basic knowledge of Simatic", and find it hard to give any amount of credibility to people that make such stupid pronouncements, the situation described in this article points out once again how SCADA systems are still not being treated at the level of sensitivity they should be.

Saturday, June 18, 2011

Con artists pose as security companies in growing scam

Criminals posing as computer security engineers are having success in calling victims at home and stealing their money, according to a survey issued Thursday by Microsoft. Fifteen percent of 7,000 computer users polled in the United States, Canada, U.K. and Ireland said they have been been contacted by a phone scammer, and 22 percent of those were tricked into following the fraudsters' directions, which included giving them remote access to a computer or providing credit card information. Seventy-nine percent of those suffered a financial loss as a result. Victims were out an average $875 in the United States, the survey found.

Friday, March 4, 2011

During a recent password audit

During a recent password audit, it was found that someone was using the following password:
"MickeyMinniePlutoHueyLouieDeweyDonaldGoofySacramento"

When asked why she had such a long password, she said she was told that it had to be at least 8 characters long and include at least one capital.

I don't usually post jokes, but I think this is the first infosec joke I've ever heard. Feel free to post or send along some more if you know a good security joke.

Wednesday, February 16, 2011

HBGary pretty much calls it quits

The backlash caused by Anonymous' release of HBGary emails has caused the security consulting firm to cancel public speaking engagements and shut down their trade-show booth. I'm sure security companies all over the world are checking their own security posture and avoiding saying really stupid things in public.

Wednesday, April 21, 2010

Are you smarter than a 3rd grader?

In the 80's, my high school buddy Pob and I used to spend hours, days and weeks getting to know our school's computer network. We were asked to leave our grade 9 class and help teach computer science to the grade 10 students, and similarly help the grade 11 folks when we were in grade 10. For security purposes, our teacher used a longer password (stationwagon) than the lowest scoring student (bird).

Instead of punishing kids who realize at such a young age that people use such obvious passwords, its time to educate them so they get a chance at being the next information security guru. When they're ready, we need them.

Study: Frequent password changes are useless

One of the biggest problems with changing passwords too frequently is that users invariably will forget the new one. Wouldn't it be nice for administrators if they could simply teach users how to construct a stronger password, and then get them to stick to it? Constantly changing complicated passwords causes users to write them down on sticky-notes where others may see them. The reality is if an attacker has a system's password hashes to crack, they already have the access needed to steal data or whatever it is they are up to. Also, once a password has been cracked, the attacker is likely to use it right away - not three weeks down the road.


As Microsoft indirectly points out, companies would save enormous amounts of money if they didn't have to dedicate administrative hours to resetting passwords just as frequently as the policy requires them changed. 

However the reality is there are various industry standards that mandate policies on frequent password changes. The bigger your organization is, the more likely you are bound to one of them. This is unfortunate, and thus a well-meaning policy ends up costing companies more than the risks it supposedly mitigates.