Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Saturday, October 27, 2007

(Potentially relevant link)

When you look up a word that 'may be inappropriate for children' ('cunt' and 'shit'. Not 'bitch'), Webster's Online Dictionary: Rosetta Edition requires that you enter a 'password':

The answer to any of these questions is a valid password for this page:


1. Cher's former partner's last name (4 letters)

2. The cube root of twenty seven (5 letters)

3. The "incident" before the Vietnam War (6 letters)

4. The theory that physiology and physics are drivers of economics (15 letters)

5. A good mustard (5 letters)

Because no child can figure out the cube root of 27, right?

By the way, if you can't figure out any of the answers, don't worry. Doing so simply forwards you to the definition of the word followed by '1', so you can circumvent it by looking up 'cunt1', 'shit1', 'cock1'...

Friday, June 08, 2007

For years I've wondered why we don't have encrypting phones.

Five or ten years ago, phones may not have had great processors, and some would argue there wasn't much need. The first issue is quickly dying and the other is thoroughly obsolete.

Demand exists. Maybe it's not huge, but it exists.

Interoperability should be simple. Your phone initiates conversation with a quick 'Know such-and-such encryption?' and if the other phone says 'yes', you trade keys and encrypt (or, I suppose, send your pubkey and subsequently encrypted AES key1). Maybe this means older phones get a couple tones at the beginning of a call. Probably not, but I don't know how they operate.

Phone companies probably like lock-in, so a lone company creating an encryption protocol and releasing a phone probably isn't sufficient. Get some big players on board. Get them all together, create a free, open standard for encryption and agree to all to start supporting it at least on the fast enough models.

Until you do this, I see no need to buy a mobile phone. (If they did this, I'd have a need: to support the concept. Actually, why not release a landline phone for this as well?)

1 Can you get deniability with AES? I've always thought making it illegal to record people talking to me on the phone is really stupid, but if it's something we want, this could be a way to handle it. Maybe doesn't work so well with voice data.

Saturday, May 05, 2007

Bank of America. Oh oh oh!

Logging in to their online banking system is a pain. Why? Because I know my SSN (used as the username) and I know my password, but they've decided that's not good enough, no. I enter my SSN and then they ask me 'What's your maternal grandmother's maiden name?' Now, I know the answer to this. You could probably figure it out too. Sadly, Bank of America doesn't have a clue, and I don't recall telling them anything but the truth.

So how do I log in? I try answering a few times, and finally it asks my father's middle name. This one I know. This one I know you can find in a matter of minutes using Google. My father goes by his middle name. And Bank of American knows the correct answer to this one. So finally I manage to get in.

By 'in' I mean I'm to the point where I can enter my password.

By the way, if you ever want to be annoying, all you need to do is get to this point and then enter the wrong password a few times.They'll shut down online access to my account until I dig up some silly information and fill it in. Could be worse. My brother had to call them with his account number and a recent transaction--and he was in Germany at the time, meaning he couldn't unless he wished to spend lots of money.

So long as I'm explaining how Bank of America's security sucks, I should mention SiteKey. SiteKey is an image you choose that they show you after you supply your SSN and the answer to the security question. If you see the SiteKey image that you chose when setting up your account, you know it's really Bank of America and you can safely enter your password.

Either that or it's a phishing site that took your SSN and security question answers soon as you provided them, showed them to the real Bank of America, got your SiteKey image, and then showed it to you, defeating this brillant security measure in a matter of seconds.

Okay, so maybe they'll notice if a single phishing site is sending these requests to BoA for every person they fool, but how many of you think this isn't easy to hide sufficiently well to avoid any automatic detection BoA may have set up? Yet another example of fake security. it makes you feel safe, unless you're competent and actually think it through.

Wednesday, May 02, 2007

I used to tell people to not write down their passwords.

Then I started helping out at a website that only stores hashes of user's passwords, and no password-resetting mechanism. If someone loses their password, I can reset it manually, given proof that they're the actual owner, but I hate doing that, in part because my idea of proof is that you have the password to the account. A site where 0.469980026% of all accounts have the password 'password' and 0.403889085% have the password '1'. A site where there are 34179 passwords among 68088 accounts. Okay, really, these statistics are better than I expected. In fact, I cannot believe I got those queries right. Must be all those people who register and then never log on. They have strong, distinct passwords. The active users don't.

Anyway, they use weak passwords and still they forget their passwords a lot. So now I tell them to write their password down. There are betters ways of doing it. Personally, I want a secure hash I can calculate in my head--and there are some good ideas on how to do something along those lines--but most of these people are youngish kids.

Anyway, this person presented a good argument that struck me. In my pocket, I have 43.19 USD (often over 100USD) and 0.11 Euroes, 47.11 USD on a Barnes and Noble gift card, three credit cards with a total credit line of over 10 000 USD, and keys to my house, van, and truck. Most people probably have much more than that.

If my pocket is secure enough for all that, it's secure enough for my password. Not my GPG passphrase, perhaps, but most passwords aren't worth more than the rest of my wallet. You don't even need to write it down in plaintext. A shift cypher will stop casual thieves. Or a different font (I sometimes take notes in Tolkien's Elvish Tengwar script. I also know most of the Greek alphabet. Studied Russian? Arabic? Mix a couple alphabets together. Use a shorthand of your own. (I have quite a few symbols I made up for taking notes. Surely you have some too?)

If you're really paranoid, encrypt your password with a one-time pad and store the password list somewhere secure and the one-time pad somewhere independently secure. (IE, finding a way to access one will not help me access the other.) Yeah, you still have to memorise your passwords to use them, but the cost of not remembering is now that you only temporarily lose access--just until you go to these two secure areas and combine them--freeing you to use a stronger password than if memorisation was your only recourse. But what I'm mostly concerned with here are the non-security-minded users. Most people don't consider how long it takes the bad guy to guessing their password using a computer. They just think about whether they can remember the password and whether typing it in each time takes too long. Security means keeping unauthorised users out and letting authorised users in. If the security-minded ignore the second half, we miss the priority of the average user, so they ignore our advice.