Wednesday, January 25, 2012

The Top 25 Worst Passwords

"To err is human, to really foul things up requires a computer."
~Bill Vaughan, 1969
Web site Internet Crime Complaint Center's (IC3) and other sites have published a list of the worst passwords. A study was done on a list of millions of stolen passwords posted on-line by hackers and here are the top 25 passwords found in the list.

1. password
2. 123456
3. 12345678
4. qwerty
5. abc123
6. monkey
7. 1234567
8. letmein
9. trustno1
10. dragon
11. baseball
12. 111111
13. iloveyou
14. master
15. sunshine
16. ashley
17. bailey
18. passw0rd
19. shadow
20. 123123
21. 654321
22. superman
23. qazwsx
24. michael
25. football
Bottom Line

If you use any of these passwords, change it now. Here's some advice on creating a good password:
http://perpetualpreparedness.blogspot.com/2011/05/passwords.html

Labels: , , , ,

Friday, December 2, 2011

(Lack of) Computer Security

Treat your password like your toothbrush. Don't let anybody else use it, and get a new one every six months.
~Clifford Stoll
If you use Google news you can customize it to include specialized topics of interest. One of my news "extras" is Computer Security and recently it was full of depressing news about serious security violations

Medical Record Theft At Sutter Health
Information stolen on more than 4 million patients of a major Northern California health care provider. What's unusual about this incident is not some clever hacker but a thief who broke a window with a rock and stole a PC containing patient records.
"Over the last two years, health care organizations have reported 364 incidents involving the loss or theft of information ranging from names and addresses to Social Security numbers and medical diagnoses on nearly 18 million patients – equivalent to the population of Florida."
Water utility hackers destroy pump, expert says
Hackers may have destroyed a pump used by a US water utility after gaining unauthorized access to the industrial control system. Many industrial control systems rely on passwords that are hard-coded and it looks like Russian hackers stole the password from the company that made the equipment. The hackers (after much experimenting) managed to burn out a water pump by rapidly turning it on and off. One expert noted, “These things are connected to the Internet in ways they shouldn't be.”

This is "a really big deal".

Hackers attack Norway's oil, gas and defence businessesIndustrial secrets and information about contract negotiations had been stolen from at least 10 firms according to Norway's National Security Agency (NSM). Normally attacks like this would be kept secret but the NSM wants to world to know about these very skillful hackers.
"The attackers won access to corporate networks using customised emails with viruses attached which did not trigger anti-malware detection systems. ...  the email messages had been sent to specific named individuals in the target firms and had been carefully crafted to look like they had come from legitimate sources."
Facebook admitted that hackers are breaking into hundreds of thousands of Facebook accounts every day.
"Don’t use the same password and username combination for multiple websites. Use an online password manager to keep track of your different accounts."

Bottom Line

Hacking is not just nerdy teens having fun at your expense. There is money to be made selling identity information and there are government sponsored hackers (Russia, China) seeking weakness for cyber-warfare or corporate espionage.

Check out this article on the 25 worst passwords
http://www.telegraph.co.uk/technology/news/8898482/25-worst-web-passwords.html

Update
Recent news is claiming that the Utility pump was a false alarm. No proof that hackers destroyed it. Perhaps. But the risk is real and it is only a matter of time before real damage is done by hackers.

Labels: , , ,

Thursday, May 5, 2011

Passwords

"Some users will provide their password to a stranger who says he is from their company's IT department."
-Amir Lubashevsky
If you use computers than you'll be asked to supply a "secure" password. When I wrote about this two years ago, I recommended using the initial letters of a phrase like "tbontbtitq" for "To be or not to be, that is the question" as something not found in a dictionary yet easy to remember. Sometimes it is possible to be too clever. When physicist Richard Feynman worked on the Manhattan Project to create the first nuclear bomb, he found that many safes could be cracked at the super-secure site with combinations based upon PI = 3.14159 or e = 2.7182818.

This morning I read an article on baekdal.com that suggests we are looking at passwords the wrong way. Reliable security it argues, comes from password length, not password complexity. Yes complexity helps. A password like "jskerv" with only characters can be cracked in 1 month using brute force. But "J4fS<2" with mixed case, symbols and numbers would take 219 years to crack. The problem with complex passwords is remembering them. A password at the office is defeated if you post it on the wall of your cube.

Baekdal recommends a three word password like "this is fun". A pure brute-force attack for 11 characters would take over 1 million years. An attack combining common words would take over 2000 years, still very secure. If spaces are not allowed in your password, try "this-is-fun".

Since most password algorithms measure complexity, not length, you may find a password like this rated as "weak." And yes a single word from a dictionary with 11 characters would be weak. But not three words. Imagine how many three word sentences exist!

Some passwords require symbols, numbers, etc. I find this annoying and occasionally forget the new password for some bank that requires two numbers or some other pattern different from what I use. This results in keeping a list of passwords which in itself weakens security.

Bottom Line

Find a password that is easy to remember but long and either multi-words or letters taken from some phrase you remember. Can you guess this phrase?  "hb2yhb2y"

Labels: , ,

Sunday, April 19, 2009

Espionage & Passwords

“Every one is a moon, and has a dark side which he never shows to anybody” - Mark Twain
Here is an unsettling story published in the Wall Street Journal, Electricity Grid in U.S. Penetrated By Spies.

Cyberspies have penetrated the U.S. electrical grid and left behind software programs that could be used to disrupt the system, according to current and
former national-security officials. The spies came from China, Russia and other countries, these officials said, and were believed to be on a mission to navigate the U.S. electrical system and its controls. The intruders haven't sought to damage the power grid or other key infrastructure, but officials warned they could try during a crisis or war.
As a computer programmer I understand that hackers would try to break into our infrastructure systems. But what concerns me is that they succeeded and could leave behind sleeping programs waiting for activation. “Many of the intrusions were detected not by the companies in charge of the infrastructure but by U.S. intelligence agencies, officials said.”

The WSJ reports, “Intelligence officials worry about cyber attackers taking control of electrical facilities, a nuclear power plant or financial networks via the Internet.” I cannot for the life of me understand why a nuclear power plant should be accessible via the Internet. Perhaps workers want to push buttons from far away in case the plant starts to meltdown? I’ve worked at several companies with restricted Internet access. At one, there was no access, period. At two others they used VPN (Virtual Private Networks) to restrict access. VPN uses a token that displays a new “random” number every minute. To login I need my password and the current number on the token registered to me.

Sadly in many secure systems the weakest link is the human element. At one of my internships, the top executives (with the most data access) hated to memorize long passwords and asked for an exception so they could use two letter passwords. One hacker trick I’ve read about includes getting inside a company and then sitting down at computers where workers have left for lunch but left the PC logged on and connected to the company network. (Screen savers with passwords help protect against this). Another clever hacker passed out a survey to workers asking for names of pets, children, spouse, etc. He then checked to see if any worker had used a family name as their password; very common unfortunately. (A solution to this is requiring numbers and or special symbols in the password.)

Now it would be nice to think espionage would never happened but the WSJ describes two recent cases outside the US:
  • In 2000, a disgruntled employee rigged a computerized control system at a water-treatment plant in Australia, releasing more than 200,000 gallons of sewage into parks and rivers.
  • Last year the CIA told utility company representatives that a cyberattack had taken out power equipment in multiple regions outside the U.S. The outage was followed with extortion demands.
Bottom LineTwo points I’d like to emphasize here.
1. Water or electricity could fail at a moments notice with a hostile attack. Do you have backup water and a power generator or means to cook/light without electricity? ABC News did a follow-up story called What if Russia or China Cut Off Your Electricity? It goes through a typical day showing how pervasive electricity is...
  • Your alarm clock
  • Your laptop (when the batter dies) & wireless router
  • Your landline phone perhaps work but not VOIP
  • Your hot water heater (if not gas)
  • Your gas oven (most have an electric starter instead of a pilot light)
  • Traffic lights
  • Gas station pumps
  • Frozen/refrigerated food at the grocery store
  • Cash Registers, Credit Cards
2. Always use a strong password. Studies have shown that longer is better. Password hackers are well aware of L33T, the trick of substituting letters with symbols like 9ary or G@ry for Gary. So don’t think you are safe with a short but clever password. One easy password method is to use the letters from a favorite hymn, bible verse, poem, etc. For example “tbontbtitq” for “To be or not to be, that is the question” (but please choose something less obvious). You can strengthen this by creating a personal pattern where you always capitalize the same letters (say 2nd and 3rd) “tBOntbtitq”

Labels: , , , , , , ,