Asus Tech Support

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg
Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Thursday, 21 February 2013

Updates to know about (Wed, Feb 20th)

Posted on 09:00 by Unknown
from SANS Internet Storm Center, InfoCON: green
via SysAdmin
Update Palooza, (Wed, Feb 20th):




UPDATE 2






Adobe Acrobat Reader 11.0.02 was published today as a fix for CVE-2013-0640 and CVE-2013-0641. More information at http://www.adobe.com/support/security/bulletins/apsb13-07.html.






Wireshark 1.9.0 was published today. Its an experimental release for testing new features for the upcoming 1.10 version.






UPDATE






More updates arrived:





Thunderbird 17.03 arrived yesterday. It fixes 8 security vulnerabilities.



Apple released yesterday iOS 6.1.2, which can be downloaded fast as it is small (12.8 MB). So far, this update seems to be only related with a bug on echange calendars that increases network utilization causing battery drain. Better to have last version installed as apple does not always list in a detailed way all the fixes contained in an operating system update.








Manuel Humberto Santander Pelez




SANS Internet Storm Center - Handler




Twitter:@manuelsantander




Web:http://manuel.santander.name




e-mail: msantand at isc dot sans dot org






=========== ORIGINAL DIARY BY JOHANNES ULLRICH ===========



If you are easily confused like me, you may appreciate this quick summary as to the different updates released the last couple of days:



Oracle Java:





Java 7 Update 15



Java 6 Update 41





Mozilla



Firefox 19



Apple



(in addition to Apples Java update to the versions shown above)



iTunes 11.0.2.25



Adobe





Flash Player Windows 7 and earlier 11.6.602.168 (Windows 8 and OS X is still use 167)



Acrobat/Reader 11.0.02 (went live on Adobes FTP server Wed. 20th morning)





Probably the most dangerous thing you can do when applying patches is to rush. You may not only end up with a broken system, but worse, the patch may not be applied correctly. Take the time to test that you are all up to date. Encourage your coworkers and relatives to visit browsercheck.qualys.com to test if all plugins are installed correctly.



(we may update this diary for a day or two)



------




Johannes B. Ullrich, Ph.D.




SANS Technology Institute




Twitter










(c) SANS Internet Storm Center. http://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
Read More
Posted in Security | No comments

Friday, 19 October 2012

Bad passwords are worse than you think

Posted on 02:00 by Unknown
Bad passwords are worse than you think:
from BetaNews by David Harley
I spend a lot of time defending educational as opposed to purely technical solutions to security. Not that I don’t believe in the usefulness of technical solutions. However, there are many people in the security business who believe that education is a waste of time because it isn’t 100-percent effective. Unfortunately, you can make the very same argument against any technological solution. Randy Abrams and I discussed that conflict of ideas at some length in a paper for AVAR: see People Patching: Is User Education Of Any Use At All? And Robert Slade made some excellent points more recently in post Security unawareness.
Static passwords are a pretty good example of a technology that’s proved to be less than 100-percent effective time and time again, yet is considered effective enough to remain the authentication mainstay of many a web service. Well, I could argue that it’s not so much about effectiveness, as a trade-off between effectiveness in terms of privacy, and the cost of implementing better authentication mechanisms. But that’s a discussion for another time.
There’s a proverb to the effect that "if you give a man a fish, you feed him for a day: teach him to fish, and you feed him for a lifetime". While the provenance of that saw is obscure, it’s worth examining more closely in the context of security, though in that context it might be better recast as "If you show a man a phish, you prevent him from falling for that one: if you teach him to recognize phishing, you save yourself and him a lot of hassle". And, in fact we’ve written quite a lot about phishing in the past: "A Pretty Kettle of Phish"; "Phish Phodder: Is User Education Helping or Hindering?"
Quite a Few Pairs of Breaches
However, right now I’d like to apply that thought to password practice, an area of security (or, more accurately, privacy) that’s probably of more immediate concern to many of us. In a year that’s so far been most notable for the number of major password breaches. On more than one occasion I’ve quoted Mark Burnett’s top 500 and one or two similar lists of the most-overused passwords, and recently I’ve noted quite a few journalists citing their own lists, but what does this teach the man-in-the-street (especially if he’s doing his on-line banking on his smartphone as he wanders down to the pub) about password choices?
Well, it isn’t entirely useless, or I wouldn’t have bothered in the first place (or, to be precise, the second place, i.e. at the time of the Yahoo! debacle. Sometimes a service uses the ‘three strikes and out’ approach to regulating password or passcode authentication, suspending an account after three failed attempts to supply the correct password, so avoiding the top 25  (say) most over-used passwords may be good enough to secure the account from an opportunistic attack using common passwords, and even where the suspension is automatically lifted after a preset time, that does at least reduce the potential effectiveness of a dictionary or guessing attack. But simply listing the top umpteen bad passwords isn’t really teaching anyone anything about password selection except to avoid a tiny handful of the billions of possible passwords and passphrases.
Horrific Heuristic
And in fact, that tiny handful, whether it’s 25 or 10,000, remains tiny even when you measure it against the millions of combinations that will be tried in a determined dictionary attack. In a recent Securiteam blog, I compared the two approaches in these terms. If you simply offer a list of bad passwords ordered by prevalence, you are effectively offering a series of micro-heuristics like this:
Don’t use ‘a’

Don’t use ‘aa’

Don’t use ‘aaa’

…

Don’t use ‘aaaaaaaaaaaaaaaaaaaaaaa’

Don’t use ‘b’

Don’t use ‘bb’
Valid heuristics, yes, but it saves an awful lot of typing just to say: "Don’t use any password consisting of a single character repeated N times". Or even "password is a really, really bad choice of password: it’s so obvious that everyone uses it, and letmein isn’t much better".
So let’s look again at that list of 25 passwords again. But rather than ranking them by how commonly they’re used (the sorted by prevalence column) let’s look at the alphanumeric order and see if that enables us to extract any heuristics more useful than "don’t use any of these 25 strings".
Sort of Sorted
Original Ranking Sorted by prevalence Sorted alphanumerically
1 password 111111
2 123456 1234
3 12345678 12345
4 1234 123456
5 qwerty 1234567
6 12345 12345678
7 dragon 2000
8 pussy 696969
9 baseball abc123
10 football baseball
11 letmein dragon
12 monkey football
13 696969 harley
14 abc123 jennifer
15 mustang jordan
16 michael letmein
17 shadow master
18 master michael
19 jennifer monkey
20 111111 mustang
21 2000 password
22 jordan pussy
23 superman qwerty
24 harley shadow
25 1234567 superman
Well, that’s interesting and maybe a little unexpected. In fact, it demonstrates the dangers of (1) using too small a dataset and (2) making assumptions about how applicable those data are in different contexts. Having done some analysis on purely numeric data as well as with larger password datasets, I know that the rule I mentioned above -- "Don’t use any password consisting of a single character repeated N times" -- is pretty sound in the context of both alphanumeric passwords and purely numeric strings (especially PINs -- Personal Identification Numbers: see Hearing a PIN drop and PIN Holes: Passcode Selection Strategies), but that heuristic isn’t specifically supported by this small dataset, where only one such password, 111111, is represented. So you’ll have to take my word for it that in larger datasets, other single character passwords (numeric and alphabetical) are indeed (over-)used and therefore bad choices.
Rules are Rules
A rule that does hold, however, is that passwords consisting of an ascending series of numbers starting at 1 are not a great or unique and original idea. The following all appear in our list above, all but one being in the top 6.
  • 1234
  • 12345
  • 123456
  • 1234567
  • 12345678
Curiously, 1234567 comes in at number 25. That may be related to the fact that many authentication mechanisms enforce (or used to enforce) a minimum of only six characters: people who take this easy route to selecting a password are not likely to go to seven characters if they only need six. A seven-character minimum is pretty unusual. However, when services started to get more password-conscious (or entropy-conscious), many started to use an eight-character minimum, which probably explains why 12345678 ranks so highly. 1234 is also very highly ranked in PIN prevalence data, by the way.
There may actually be two reasons why people favor this group of numeric strings.
  1. It’s not difficult to remember a simple increment-by-one series like this: all you have to do is remember when to stop.
  2. But you hardly need to remember the series at all: all you have to do on most computer keyboards is finger-step your way along the appropriate row of the keyboard. Which certainly also explains the presence of QWERTY, the first six alphabetical characters on the next row down on a standard keyboard. And yes, people do user QWERTYUIOP or a subset thereof when they need a longer password. In countries that use a slightly different layout on that row -- AZERTY, for example -- we see reports of the modified string or substring being used instead of a QWERTYUIOP substring. (See PIN Holes: Passcode Selection Strategies.)
What about 2000? Well, that’s too popular to be a good choice, of course. But why 2000? Probably because people quite often use memorable dates, even just a year where they can get away with 4 digits, as in the context of many PINs. However, it’s pretty safe to assume that memorable years (1066, 1492, 2000, 2001, any recent Olympic year) will be high on a password guesser’s list, and where an automated attack can be implemented, it doesn’t take long to cycle through all the possible 4-digit combinations.
Then there’s 696969. I have a theory about why that one is so popular, and while the popularity of pussy (which is also in this top 25) is no doubt because cat lovers need passwords too, there are several other words and phrases likely to be sex–related, including four-letter words, that aren’t in this list, but do turn up in several others. I’m not particularly prudish myself, but I would suggest that if you think that no one else ever used an obscenity or a word related to sexual practices as a password, you should think again.
There is just one mixed alphanumeric string in this list, abc123, but there are several others that turn up in other lists, including such venerable items as NCC1701, better known as the USS Enterprise. Well, you might want to avoid those two.
Back to the Drawing Board
So we have several sport-related passwords: clearly baseball and football are too popular to be a good idea, but you’ll find that other popular sports also make over-popular passwords (Michael and Jordan? Hmm…). But then, any word you’re likely to find in a dictionary is going to be guessed eventually (i.e. sooner rather than later) in an automated attack. We could look at the psychology behind the other choices of dictionary words that make up the rest of this list, but there doesn’t seem to be a lot of point to it.
Clearly, there isn’t much potential for useful heuristics in a top 25. So in an upcoming post, I’m going to abandon the Top Umpteen approach altogether and start again from the basics of sound password selection. If you’d like to try a more flippant approach, though, you might want to take a look at A Torrent of Abuse for an attempt at password advice through parody.
Remember, though, that any password is only as good as the service to which it gives access: it doesn’t matter how hard to guess it is, if the service provider is incapable of providing competent security to keep a competent password secure.
A Teasing Conclusion
So here’s a quick summary of the little that we can learn from this top 25:
  • Avoiding the most popular passwords is safer than using one of them, especially the top three. But avoiding even the top 100, 1,000, or 10,000 is only good enough if the authentication mechanism is well-implemented and your passwords are well-protected by the provider on its own systems.
  • Passwords, passphrases and PINs consisting of a single character repeated are very, very unsafe.
  • Any numeric or digital series ascending in increments of one or more is vulnerable to a guessing attack, a dictionary attack, or an algorithmic attack. So any substring of 0123456789 or abcdefghijklmnopqrstuvwxyz is likely to fail pretty quickly.
  • Any password – or passphrase – that can be found in a dictionary is easily crackable if the authentication mechanism allows a dictionary attack.
  • Passwords with a sexual connotation or using swearwords are very widely used, and therefore highly vulnerable to a guessing or dictionary attack.
In addition, a decent password manager saves you a lot of thinking in terms of generating a hard-to-crack password and reduces the temptation to re-use passwords and risk a cascade of breaches when one of your providers slips up, as so many have done recently. I’m looking at password management software at the moment, and while I’m reluctant to make too-specific recommendations, I’ll be trying to give you some idea of what to look for in password management in another forthcoming article.
Reprinted with permission
Photo Credit: Vlue/Shutterstock
David Harley BA CITP FBCS CISSP is an English IT security researcher, author/editor and consultant known for his prolific blogs and articles and his books on and research into topics like malware, Mac security, anti-malware product testing and management of email abuse. He works closely with ESET, where, since 2011, he has held the position of Senior Research Fellow.
Read More
Posted in Security | No comments

Sunday, 7 October 2012

Ask Slashdot: Actual Best-in-Show For Free Anti Virus?

Posted on 02:00 by Unknown
Ask Slashdot: Actual Best-in-Show For Free Anti Virus?:
from Slashdot by samzenpus



First time accepted submitter paperclipman writes "I'm on the college student budget and want to make sure that my recent investment in an Acer laptop will last me a good long while. I like to think of myself as a reasonably competent CPU user so I'm no adventurous link-clicker, but I do download some music as a recent SoundCloud devotee. My Kaspersky antivirus will be expiring shortly and I don't particularly care to renew with that steep of a fee — any advice from fellow thrifts?"









Read more of this story at Slashdot.
Read More
Posted in Security | No comments

Wednesday, 5 September 2012

Time-based One-Time Passwords with an Arduino

Posted on 03:00 by Unknown
Time-based One-Time Passwords with an Arduino:
from Hack a Day by Mike Szczys

Get your feet wet with Time-based One-Time Password (TOTP) security by building your own Arduino OATH system. OATH is an open standard authentication system that provides a platform to generate tokens, making your login more secure than a password alone would.
The TOTP approach is what is used with many companies that issue hardware-based dongles for logging in remotely. This security may have been compromised but it’s still better than passwords alone. Plus, if you’re building it around an Arduino we’d bet you’re just trying to learn and not actually responsible for protecting industrial or state secrets.
The hardware setup requires nothing more than the Arduino board with one button and a screen as a user interface. Since the board has a crystal oscillator it keeps fairly accurate time (as long as it remains powered). It will push out a new token every thirty seconds. The video after the break shows that the Arduino-calculated value does indeed match what the test box is displaying.



Filed under: arduino hacks, security hacks
Read More
Posted in Security | No comments

Thursday, 12 July 2012

Yahoo! Voices Website Breached 400,000+ Compromised

Posted on 08:03 by Unknown
Yahoo! Voices Website Breached 400,000+ Compromised:
Few details are known at this point however, a recent post over 400,000 plus accounts that have clear text passwords were posted online. The passwords contained a wide variety of email addresses including those from yahoo.com, gmail.com, aol.com, and much more. The affected website was only named as a subdomain of yahoo.com however digging through and searching for the hostname, the attacker forgot to remove the hostname “dbb1.ac.bf1.yahoo.com” (credit to Mubix for the hostname find). Looking through a variety of sources, it appears that the compromised server was likely “Yahoo! Voices” which was formally known as Associated Content (credit to Adam Caudill for the linkage).

The most alarming part to the entire story was the fact that the passwords were stored completely unencrypted and the full 400,000+ usernames and passwords are now public. The method for the compromise was apparently a SQL Injection attack to extract the sensitive information from the database.
Below is a small snippet of what the passwords looked like from the leaked document (email addresses redacted):
If you are concerned about your password and for a full list of all of the usernames and passwords compromised; head over to the below link. Note that the filesize is large and will take quite a long time to load.
http://d33ds.co.nyud.net/archive/yahoo-disclosure.txt
There has been no official confirmation from Yahoo or any other sources as of yet.
UPDATE: Note, fixed the title and body to reflect “Yahoo! Voices” not “Voice”. They are two separate applications
Read More
Posted in Security | No comments

Friday, 29 June 2012

KeyScrambler Personal protects Firefox and Internet Explorer from keyloggers

Posted on 14:03 by Unknown
KeyScrambler Personal protects Firefox and Internet Explorer from keyloggers:
The best way to protect yourself from malware is of course to prevent it ever reaching your PC, but if something does slip through your defences then this doesn’t have to be the end.
KeyScrambler Personal, for instance, will encrypt any keystrokes within Internet Explorer and Firefox. And as a result it’ll keep your logon and other details safe, even if a keylogger breaches your system.
The program is straightforward to install, adding just a couple of browser addons and an extra system tray icon to your PC. But after a reboot, whatever you type within IE and Firefox is encrypted at the keyboard driver level, then decrypted when it reaches the application. Everything looks the same to you, but if a keylogger is running then it won’t be able to capture your keystrokes.
That’s the theory, at least: it’s at least possible that malware could bypass KeyScrambler’s protection (though that wouldn’t be easy). Right now, though, it does seem to be doing a very good job. We pitted the program against three commercial keyloggers, and KeyScrambler won every time, properly keeping everything we typed safe from interception.
We did have one small problem with the program, though. On a couple of occasions, as we switched to Internet Explorer and started typing, we saw only garbage: presumably the encrypted text, which hadn’t been correctly decrypted.
If KeyScrambler regularly failed this way then that would clearly be a major nuisance, probably enough to make it unusable. But we only saw it on two occasions, both with IE, and in each case everything was fine immediately afterwards (we just retyped our text and it appeared correctly). So while it seems at least possible that the program can introduce some browsing problems, they don’t appear to be common, or major, and you shouldn’t let them put you off: KeyScrambler really does add a useful extra layer of protection to your PC.
Of course the Personal build does have its limitations, in only protecting IE and Firefox. But if you need more then there are two considerably more powerful commercial editions available. KeyScrambler Professional ($29.99) protects everything you type in more than 140 browsers and apps, while KeyScrambler Premium ($44.99) extends this support even further to more than 200 applications. The KeyScrambler site has more.
Photo Credit: Liv friis-larsen/Shutterstock
Read More
Posted in Security | No comments

Encrypted drive attack hints at original Xbox hacking

Posted on 13:53 by Unknown
Encrypted drive attack hints at original Xbox hacking:

[Thice] discovered a vulnerability in encrypted portable storage a few years ago. He’s just pointing about the exploit now. He mentions that he notified manufacturers long ago and we’d guess the wait to publish is to give them a chance to patch the exploit.
He calls it the Plug-Over Attack and for those who were involved with original Xbox hacking, this technique will sound very familiar. The Xbox used hard drive keys to lock the device when not in use. When you booted up the console it checked the hardware signature to make sure it was talking to the right motherboard. But if you booted up the device, then swapped the IDE cable over to a computer without cutting the power you could access the drive without having the password.
This attack is pretty much the same thing. Plug in a drive, unlock it on the victim system the normal way, then replug into the attacking system. In the image above you can see that a USB hub will work for this, but you can also use a hacked USB cable that patches a second jack into the power rail. For some reason the encryption system isn’t able to lock itself when the USB enumerates on the new system, only when power is cycled. Some of them have a timer which watches for drive idle but that still doesn’t protect from this exploit.

Filed under: security hacks
Read More
Posted in Security | No comments

Penetration testing with the Raspberry Pi [and PwnPi Linux distribution]

Posted on 13:50 by Unknown
Penetration testing with the Raspberry Pi:

PwnPi is a penetration testing distribution rolled up for the Raspberry Pi platform. This should come as no surprise to anyone. The RPi board has a beefy processor, it’s relatively low power, has the option of the on-board NIC or a USB WiFi dongle, and it already has Linux kernel and desktop sources available to start from.
Now we will admit we’re a bit disappointed from this tip. Don’t get us wrong, the distro looks like it’s well done, and we’re sure there are a lot of folks out there who will be happy to have these tools to help test their network security. But this is a software only hack and we were expecting to see a nice little covert package that could be plugged into an outlet (SheevaPlug style), or a battery-powered module that can be plugged into an Ethernet port and hidden away.
Now you know what we want, don’t forget to send in a link once you pull it off.
[Thanks Scott]

Filed under: Rasberry pi, security hacks
Read More
Posted in Security | No comments

Secunia PSI 3 keeps your PC software up to date

Posted on 13:46 by Unknown
Secunia PSI 3 keeps your PC software up to date:
Danish software developer Secunia ApS has released a brand new version of its free security audit tool for Windows users. Secunia PSI (Personal Software Inspector) 3.0 allows users to automatically scan their computer for missing Windows updates and outdated software, and, in many cases, the program can then automate the update process where necessary.
Version 3.0 boasts a cleaner, simpler user interface, automated patching support, localization support and improvements to underlying features.
Secunia PSI 3.0 aims to make the patching and updating process as painless and as simple as possible, and its new streamlined interface makes it abundantly clear what’s going on. After launching, the application provides a security rating for the user’s computer, then lists outdated software and missing patches as easily identifiable program icons.
Secunia PSI then automatically attempts to update any outdated software and patches automatically on behalf of the user – if it can’t do so (the user needs to pick a language, for example, or the application in question can’t be closed automatically), those programs are clearly labelled and the user can manually click them to update. Similarly, the user can right-click an entry and opt to exclude it from the list -- perfect for software that is up to date, but has been superseded by a newer version.
Secunia PSI is also configured out of the box to sit in the background, automatically providing updates as soon as they appear -- these options can be configured from the program’s Settings button, while a History button lets users see what apps and updates have been patched through Secunia previously.
Other changes in version 3.0 include support for five major languages -- English, French, German, Spanish and (understandably given the program’s origins) Danish -- as well as what Secunia describes as “enhancements” to existing features, all designed to help simplify the updating process further.
In simplifying the interface, Secunia has made the program more attractive to less experienced users, but fans of previous versions may be disappointed at the lack of manual tweaks or advanced settings on offer.
Secunia PSI 3.0 is available now as a freeware download for PCs running Windows XP or later.
Photo Credit: sheelamohanachandran2010/Shutterstock
Read More
Posted in Security | No comments

Monday, 11 June 2012

Use a 'code book' to protect (and to recall) your online passwords

Posted on 12:03 by Unknown

Use a 'code book' to protect (and to recall) your online passwords

from BetaNews by Aryeh Goretsky
via SysAdmin

With the recent announcements of password breaches at LinkedIn, and warnings from Google about state-sponsored attacks on Gmail accounts, it seems like a good idea now to review some password security basics. Then there is report today that someone hacked presidential candidate Mitt Romney's Dropbox and Hotmail.
In this post, we’re going to take a look at a rather low-tech solution to a decidedly high-tech problem: How to guard against password reset attacks, and where to securely store the answers to your password reset questions.
Even if you use highly secure passwords, it is possible someone might still be able to compromise your account if they were able to gather enough information about you to know -- or at least guess -- the answers to your password reset questions. Many services use the same questions, e.g., your mother's maiden name, the name of the town you were born in, the name of first pet and so forth. Because similar questions are used over and over again to reset passwords, it can be fairly easy, even somewhat boring, for an attacker who gathers this type of information to use it to gain access to all sorts of accounts one might have, across services ranging from those which are purely social to financial institutions, or even identity theft. The reported Romney hack is about someone guessing the answer to one of his security questions.
Password Reset Hack Attacks
Sometimes, though, it’s even simpler than that: An example of this is former Alaskan governor Sarah Palin, whose personal Yahoo! mail account was compromised via password reset using data about her available from public resources. Of course, most people are not going to have enough biographical data available online to make such an attack easy. Or do they?
With the rise of social networking has come a kind of blurring of the sorts of personal information it’s okay, and safe, to put online. Eager to generate more revenue, social media sites encourage, and in some cases may even require, people to share information about themselves such as birthdays, hometowns, where they went to school and so forth. While this is the sort of information we readily share with friends and family, social media companies request it because it allows for more targeted advertising. The fact that it is the same type of information needed to perform an attack or an impersonation is not something those companies typically tell you about when asking you to fill out your profile, or warn you that profile is not complete.
To date, I cannot recall any criminals going after aggregate personal data en masse in order to perform password reset attacks. Data breaches typically provide the password themselves or other information that can be readily used for identify theft, such as birth dates, information about credit cards and, in some cases, even social security identification numbers.
Defending Your Passwords
But even if you are not a politician, celebrity or somewhere between the two, you should still take steps to safeguard your privacy and, these days that means some creativity is needed when filling out online forms, such as when filling in the answers to questions used to reset a password.
One of the largest problems is, of course, deciding exactly what to enter. In the case of birthdates, some websites, such as online stores, might require you to enter your birthdate so they can send you a birthday offer or as the answer to a password reset question. They have no other reason for asking for this information, though, and there’s no guarantee they will keep this information secure or use it for other purposes, including selling it to marketing firms. On the other hand, there are plenty of web sites -- financial, insurance and government all come to mind -- where you may not only need to enter your correct birth date but you may be obligated to give them the correct information.
There’s also another issue to consider, both for you and the website, and that’s the issue of ethical behavior. Knowingly providing false data to a website is something of a gray area, even if there is no legal requirement not to do so. How does your obligation to provide a website with correct information balance with your right to freedom from the theft of that data, let alone the issue of privacy? Measuring these competing, and often contradictory, needs is something everyone has to do for themselves, and we cannot make the decision for you. You will need to decide if breaking this social contract is justified as a matter of practical protection.
If you have made the decision not to enter your actual birthdate, than what should you enter? The correct month and day of your birthdate, but the wrong year? The correct year, but with January 1st as your date of birth? The date of your favorite holiday? Making the answers to your password reset questions as unique as your passwords is the key to protecting against attacks on them, so using the same answer over and over again is out: That simply provides another widely-disseminated piece of information for a criminal to collect during the data aggregation phase of the attack.
One Low-Tech Solution
There is a solution, though, and it is a decidedly low-tech one: Write them down in a small notebook (that is, the kind you write in with a pen or pencil, not a laptop computer). Or, if you are not partial to keeping a little black (or orange) book, a business card or recipe card holder filled with index cards works just as well, too. Store your little “code book” in the area near, but not directly at, the computer, preferably in a location where it is at least out of site. The ubiquitous junk drawer works well for this purpose. Of course, if you use a computer in a shared area, you might want to look at storing your code book in a locked desk drawer, filing cabinet or safe.
Now that we have discussed what to use your code book for and where to place it for safekeeping, exactly what sort of information should you write in it? I would recommend something along the following lines:
  • name of website
  • username
  • date you signed up for the service
  • answer(s) to password reset questions
  • date of last password change (and/or date of next password change)
For additional security, do not store the actual answers to your password reset questions, but rather mnemonics or clues that will tip you, but not an attacker, to the answers.
During the course of writing this blog post, I came across the rather descriptively-named Personal Internet Address & Password Log Book, which, as the name implies, is a place to store information about your website and email accounts. It does, however, contain fields to enter the actual passwords, and not the answers to the questions used to reset those passwords.
Regardless of whether you choose to store password reset questions or the actual passwords, it’s important to keep in mind, though, that the physical security of any written-down information in your notebook -- whether it be the passwords themselves or just the responses password reset challenges -- is paramount: Writing down that information is the equivalent to putting your passport, driver’s license, social security card, check book, credit cards and debit cards (and their PINs) all together in one convenient bundle.
If you do not have a place that is physically secure enough to store a password reset notebook in, you should not use one for this purpose. Keep in mind that an accident or disaster could result in the notebook being destroyed or unavailable, and plan accordingly. Another thing to keep in mind is that as a tangible, physical object, your password reset notebook is subject to loss. Making a copy of it with a photocopier and storing that offsite in a secure location like a safe deposit box is far less risky than scanning it and storing the copy on your PC where an attacker can access it.
Reprinted with permission.
Photo Credit: urfin/Shutterstock
Aryeh Goretsky is distinguished researcher for security provider ESET. He is responsible for a variety of activities, including threatscape monitoring, investigating new and emerging technologies, working with ESET's developers, QA and support engineers, and liaising with other research organizations. He was the first employee at McAfee Associates and is a veteran of several software and networking companies. A Microsoft MVP since 2004, he runs the C-SQUAD mailing list for law enforcement and IT professionals.
 

Read More
Posted in Security | No comments
Older Posts Home
Subscribe to: Posts (Atom)
Economy Hosting just Rs. 109/month for 12 months!

Popular Posts

  • Serangoon Road
    HBO's pioneer Asian series premiers this weekend By Nico Erle Ciriaco SINGAPORE CITY – Home Box Office (HBO) Asia announced in a press c...
  • se l/e i ;ertoi' toi';t894t'4343
     EYAGA;P98 GTY;O' 98G/O; i; aiygt;a 90ghkhbkdhsl tie[ q[4890'8ihgxdhfs ;oa'9t hk4l ty'ae4t4 EYAGA;P98 GTY;O' 98G/O; i; a...
  • Bio-Oil
    A ‘Precious’ secret By Demi Braque                                 “If the eyes are the windows of the soul, then the skin is the canvass of...
  • BD singer Porshi Scandal video download online
    BD singer Porshi BD singer Porshi video online BD singer Porshi  online Bangladeshi Chaneel I superstar singer Porshi recently released her ...
  • Powering the Possible (Dell)
    Affording chances and other life skills By Earl D.C. Bracamonte Total solutions company Dell announced very recently that it will support t...
  • Attahama Cheewanitchaphan
  • Katrina Hot
     
  • Ken Follett: World Without End
    Yihaaa! Just  finished reading this one. It took me weeks to do it because I've been busy lately and I had to steal few minutes here and...
  • IT Positions Some of the Toughest Jobs To Fill In US
    IT Positions Some of the Toughest Jobs To Fill In US : coondoggie writes "Forty-nine percent of U.S. companies are having a hard time f...
  • Evelyn Sharma

Categories

  • 1964
  • 3D frame resolution
  • 44th season
  • 4K technology
  • 60s theme
  • 84-inch LED
  • Abarat
  • Abbey Clancy
  • accessories
  • acqua
  • action
  • Aditi Gowarkar
  • Aditi Rao
  • adventure
  • agnes locsin
  • airlines
  • airplanes
  • Aisha
  • Aishwarya Rai
  • aklan
  • Alexandria Eissinger
  • Alia Bhatt
  • Alicia Machado
  • all-day
  • altro mondo
  • Amalia
  • american cuisine
  • Amisha Patel
  • Amrita Rao
  • Amy Jackson
  • Andrea Jeremiah
  • Aneh
  • anemia
  • Anika Kabir Shokh
  • Anjana Sukaani
  • Ankitha
  • Annelise Marie
  • anti-ageing
  • Anu Mehta
  • Anushka Sharma
  • apparel
  • Apple
  • appliances
  • Archana
  • Arpita Paul
  • art
  • art of dance
  • arte contemporanea
  • Asha Saini
  • asia pacific
  • asian
  • asians five nations tournament
  • aspen
  • Attahama Cheewanitchaphan
  • australian broadcasting corp
  • autumn
  • ayala center
  • Bag of Bones
  • ballet philippines
  • Bangladeshi Model
  • Bangladeshi Sexy Model
  • Bangladeshi Singer
  • bb pilipinas
  • bb. pilipinas
  • BD Model
  • beauty
  • beauty in giving
  • beddings
  • beds
  • Belarus
  • belt
  • beverly hills 6750
  • bgc
  • Bhavana
  • Bhuvaneshwari
  • biki
  • bikini
  • bio-oil
  • Bipasha Basu
  • Bisnis Lokal Go Online
  • bit.ly
  • blood disorder
  • book review
  • boracay
  • bp
  • bpci
  • breakfast
  • campaign
  • car seats
  • carriers
  • cause
  • ccp
  • cebu
  • Celina Jeitly
  • Certification
  • chef
  • childhope asia
  • children's joy foundation
  • Chitrangada Singh
  • christmas carol
  • cinema
  • cjfi
  • classical
  • Clive Barker
  • clothing
  • co-production
  • Cobie Smulders
  • collection
  • colors
  • comedy
  • competition
  • competitions
  • computer literacy
  • contact sports
  • contemporary
  • contest
  • contests
  • conveyances
  • coronation night
  • corporate social responsibility
  • corporate value
  • cqgq
  • CSR
  • cuisine
  • dance
  • Deeksha Seth
  • Deepika Padukone
  • deficiency
  • Dell
  • destination
  • destinations
  • detective noir
  • devices
  • Dhallywood Actress
  • Diana Monteiro
  • Diana Penty
  • digital products
  • dining
  • dive spots
  • Divya Bharathi
  • dockers
  • edna vida
  • elan awards
  • electronics
  • Elisha Cuthbert
  • Elle Evans
  • Emma Watson
  • Eragon
  • Erin Andrews
  • Evelyn Sharma
  • events
  • exhibit
  • f & b
  • fall
  • fashion
  • festivals
  • fila
  • filapinas
  • Filipina
  • film
  • foam
  • food
  • formulation
  • foundation
  • furnishings
  • gallery
  • garcia college of technology
  • gct
  • Geeta Basra
  • German brand
  • gianfranco pirrone
  • giselle
  • giselle sanchez
  • gkmbq
  • glorietta 5
  • gma 7
  • goo.gl
  • Google
  • grant
  • greenbelt 5
  • gusto kong maging beauty queen
  • H2O hotel
  • Hansika Motwani
  • hanupriya
  • Hazel Keech
  • hbo
  • hboasia
  • HD
  • Heera
  • high chroma texture
  • history
  • holiday
  • home
  • hot
  • iBT
  • IFBS
  • indigenous people
  • Indonesia
  • Indraja
  • initiative
  • installation art
  • international pageants
  • IPK
  • iron
  • Isha Chawla
  • italian
  • Japanese brand
  • jeff bridges
  • Jinri Park
  • john robert powers
  • Kajal Agarwal
  • Kajo
  • kalibo
  • kallery.net
  • Kamalini Mukharjee
  • Kamna Jatmalini
  • Kareena Kapoor
  • Katrina Kaif
  • Katy Perry
  • Kausha
  • Ken Follett
  • khaki
  • Kitami Masao
  • KLM
  • kristen stewart
  • kuh ledesma
  • Lambert Academic Publishing
  • LAP
  • Laura Baca
  • leather
  • Lee-Ann Roberts
  • lena gercke
  • life wear
  • linear atrophy
  • Lisa Haydon
  • mactan shangri-la
  • Mahima Chowdary
  • makati
  • malampaya
  • malaria
  • MAM
  • Mandakini
  • manila ocean park
  • Manjari
  • margie moran
  • Marian Rivera
  • Marika Baldini
  • marvel comics
  • Mary Elizabeth Winstead
  • mattresses
  • Maxim
  • mcjim
  • men
  • men's fashion
  • merck serono
  • Mette Munkø
  • Mila
  • minerals
  • Minisha Lambha
  • Minka Kelly
  • Minsk
  • Miss Supranational
  • miss world philippines
  • model
  • modern
  • modern art
  • moisturizer
  • Mounica Bedi
  • movie
  • movie review
  • mr jones
  • mutya johanna datul
  • mutya ng pilipinas
  • mvp bossing awards
  • mwp
  • My life
  • Nargis Fakhri
  • Natalie Pack
  • Navneet Kaur
  • Nayanatara
  • nbc tent
  • Neelam
  • Neha Jhulka
  • niccolo jose
  • Nikisha Patel
  • Nikitha
  • Nisha Kotari
  • nonoy froilan
  • nude
  • online voting
  • original
  • outreach
  • P2SMTP-LIPI
  • pageant
  • pageantry
  • pageants
  • painting
  • palawan
  • pants
  • Paris Hilton
  • paul morales
  • philippine volcanoes
  • pilipinas shell
  • Pillars of the Earth
  • planes
  • platinum award
  • poll
  • Pooja Bhatt
  • Pooja Gupta
  • Poonam Bajwa
  • popularity contest
  • Porshi
  • Porshi Scandal
  • Poses
  • powering the possible
  • Prachi Desai
  • precious lara quigaman
  • Preeti Jhingania
  • pret-a-porter
  • Priyanka Kotari
  • program
  • project
  • psfi
  • puerto princesa
  • PurCellin
  • quests
  • Raasi
  • Rachana Mourya
  • raffles hotel
  • raintree
  • Rambha
  • Ramya Krishna
  • Ramya Krishnan
  • range
  • readers digest
  • reality TV
  • Refaeli Bar
  • referrer spam
  • regza
  • rest in peace department
  • restaurant
  • restaurants
  • ripd
  • robert schwentke
  • Robin Scherbatsky
  • rock supremo
  • RTW
  • rugby
  • ryan renolds
  • SAKA
  • salagubang
  • salaminkera
  • Salli Villefrance
  • Saloni
  • Sam Kellet
  • Sameeksha
  • Sana Khan
  • sandra bullock
  • sangobion
  • Sara Carbonero
  • scarlett johansson
  • sculpture
  • sea air
  • search
  • Security
  • serangoon road
  • series
  • Sheela
  • shell
  • sheridan group
  • sheridan spa resort
  • Shireen
  • Shokh
  • Shradda Das
  • Shreya Saran
  • Shruthi Hassan
  • Shwetha Tiwari
  • sicily
  • Silk Smitha
  • Simran
  • SINAG
  • Sindu Tulani
  • singapore
  • skin damage
  • Sneha Ullal
  • social responsibility
  • solar entertainment
  • Sonam
  • Sonia Agarwal
  • sports palace
  • Stephen King
  • Stine Fabech
  • streetchildren
  • stretch marks
  • Sunny Leone
  • supplements
  • Susan
  • Swordless Samurai
  • technology
  • television
  • Thailand
  • the wicked
  • theater
  • Thomas Agatz
  • tiger air
  • tiger airways
  • Tim Clark
  • TOEFL
  • topical
  • toshiba
  • tourism
  • Tracy Chevalier
  • Translation
  • travel
  • treatment
  • tubbataha reef
  • Tulip Joshi
  • TV
  • Uditha Goswami
  • uip
  • Under The Dome
  • Uniqlo
  • Unknown
  • uratex
  • Urvashi Sharma
  • UT
  • Valentina Zambrotta
  • Varvara
  • Veda
  • Vedika
  • very hot
  • vijaya
  • Virgin Blue
  • visual arts
  • vitamins
  • well being
  • western philippines university
  • western visayas
  • wolverine
  • wood
  • world cup sevens
  • World Without End
  • x-men

Blog Archive

  • ▼  2013 (137)
    • ▼  September (15)
      • se l/e i ;ertoi' toi';t894t'4343
      • Powering the Possible (Dell)
      • Bio-Oil
      • Serangoon Road
      • Attahama Cheewanitchaphan
      • Katrina Hot
      • Alicia Machado
      • Lee-Ann Roberts
      • Elle Evans hot
      • Miss Supranational 2013
      • Pilipinas Shell Foundation Inc. (PSFI)
      • Uratex
      • Remnants
      • Mutya Johanna Datul
      • Batas Tipis
    • ►  August (21)
    • ►  July (8)
    • ►  June (12)
    • ►  May (8)
    • ►  April (6)
    • ►  March (13)
    • ►  February (33)
    • ►  January (21)
  • ►  2012 (321)
    • ►  December (1)
    • ►  November (7)
    • ►  October (49)
    • ►  September (32)
    • ►  August (44)
    • ►  July (69)
    • ►  June (113)
    • ►  April (3)
    • ►  February (1)
    • ►  January (2)
  • ►  2011 (42)
    • ►  December (2)
    • ►  November (4)
    • ►  September (1)
    • ►  August (21)
    • ►  July (2)
    • ►  June (1)
    • ►  May (5)
    • ►  April (6)
Powered by Blogger.

About Me

Unknown
View my complete profile