Showing posts with label Passwords. Show all posts
Showing posts with label Passwords. Show all posts

Friday, January 5, 2018

Network Security: Passwords and Human Error

A past IBM cyber security intelligence index report concluded that 95% of security breaches are caused by human error. Human error definitely includes password choices by users. It also includes password requirements and password storage by systems administrators. Passwords are a large part of network security. Hackers can use a technique called "password guessing" in which they manually enter passwords at a log-in prompt to gain access to an account when they have a valid user name. There are tools to automate this guessing process, known as an online attack, including Medusa, Ncrack, and Hydra.

These tools were built to help companies secure their networks as security specialists can test hosts and networking devices for poor passwords. These tools are used to audit devices as well. Online attacks can also be used to check that your firewalls, IDSs, and IPSs detect when a server gets bombarded with unsuccessful log-in attempts and that accounts lock in a short period when this happens. Password guessing through manual or automated means is obviously very noisy, so hackers need a better way to do it. Passwords should never be stored in plain text in databases. Storing passwords in plain text allows them to be used immediately after they're stolen. Passwords should be stored in a strong hash format since hashing is a one-way function. 

In many of the data breaches of recent years, stolen password databases contain passwords that were either stored in plain text or hashed with weak algorithms like MD5 or SHA-1. The current standards of hashing include SHA-256 and SHA-512, both forms of SHA-2.

On Linux systems, password hashes are stored in the etc/shadow file. Most Linux distros use SHA-512 with something called "SALT".

On Windows systems, password hashes are stored in the SAM file located at C:windows\system32\config\SAM. Some Microsoft documentation expands SAM to Security Account Manager while other Microsoft documentation expands SAM to Security Accounts Manager. On Windows domain controllers running Active Directory, password hashes are stored in the NTDS.dit file located at C:windows\NTDS\NTDS.dit. The Windows NTLM, Lan Manager Protocol Suite, actually uses MD4 without SALT for storing Windows hashes.

Websites that we log into store passwords in a backend database likely using the MySQL relational database management system. If a hacker enters the stolen hash into the password field, the hash itself would be hashed, so the attacker won't do that. What happens when a database containing hashed passwords are stolen? The hackers have three attack options after they steal the hashed password database. The first is called a "brute force attack" which uses a tool that generates a file containing all possibilities of letters, numbers, and symbols given a minimum and maximum length. The second is a dictionary attack which uses common words and their variations instead of trying all possibilities like a brute force attack does. The third is a rainbow table attack which requires more processing but less storage than a dictionary attack.

Tuesday, July 26, 2016

INTRODUCTION TO CYBER SECURITY: Two-factor authentication


So, if a password isn’t secure enough, perhaps having two pieces of information is more secure? This is known as two-factor authentication and you’ve almost certainly used it without realising.

When you take money out of an ATM you have to give the bank two pieces of information – the first is the data stored on your bank card, the second is the PIN. Individually, neither can access your account, but when brought together they allow you to withdraw money.

Some banks have given similar two factor authentication to online banking customers – in this case accounts need to be unlocked with the combination of a password and a four or six digit number generated on a hardware security token. If you use online banking and don’t have a hardware token it will be well worth finding out if your bank offers them to customers, and if they do not, consider switching to a more secure banking service.

 Course-specific creative-Learn To Code by Making Games - The Complete Unity DeveloperCourse-specific creative-Learn and Understand AngularJSCourse-specific creative-The Complete Android Developer Course - Build 14 Apps

Hardware security tokens
These devices contain a clock and a number generator which creates a new one-time password every minute or so. The bank synchronises the token with a master computer before issuing it to customers so the token and the master computer generate new passwords in time with one another. When the user is asked to enter the one-time password into their browser, they press a button on the token and enter the four or six digit number shown on the screen. The master computer will have also generated the same number. The two values are compared, if they match, the user is allowed into their account.

Two factor authentication on the web
A number of companies, including Apple, eBay, Google and Microsoft support two factor authentication to improve the security for their web users. Rather than a single password, two-factor authentication requires the user to enter two pieces of information – their password and a changing value which is either sent by the website to their mobile phone, or generated by a companion application on the user’s own computer.

Depending on the site, it might be necessary to enter the two values every time (which is inconvenient), or after a period of inactivity, or it may be possible to tell the site that the computer which has already been authenticated should be trusted in future and a single password will be sufficient to allow you to use the site (although this raises a security weakness if the machine should be stolen).

Another place where you might have come across two-factor authentication is if you’ve ever connected to a virtual private network (VPN), which is a type of encrypted network connection.

Instructor Quote - iOS 8 and Swift - How to Make a Instructor Quote - KiCad like a ProInstructor Quote - The Complete Java Developer Course

The organisation that owns the network you are connecting to will give you a card or device, often called a VPN token, that can be used to generate a sequence of random characters. When you try to connect to the VPN, you will first be asked for your password (the secret based on something you know) and then will be challenged to provide some information from the VPN token (the secret based on something you have).

© The Open University
https://www.futurelearn.com/courses/introduction-to-cyber-security/8/steps/83054

INTRODUCTION TO CYBER SECURITY: Password Manager and Open Authentication


Using a password manager makes your life much simpler because, rather than having to remember a multitude of passwords, you only need to remember a single password and the computer does the rest.

But what if you forget that password? All of a sudden all of your passwords are unavailable. And what if your password manager’s data file falls into the wrong hands? You’d better hope your password is strong, otherwise all of your passwords are accessible to an attacker. But, what are the alternatives?

Course-specific creative-Learning Python for Data Analysis and Visualization   Course-specific creative-iOS 9 and Swift 2: From Beginner to Paid Professional   Course-specific creative-Pianoforall - Incredible New Way To Learn Piano & Keyboard
For an increasing number of websites it is possible to use your existing online accounts, such those provided by Google or Facebook, to register and log in. This approach for managing users’ account details depends on an authentication mechanism called OAuth (i.e. Open Authentication).

This method of checking a user’s identity requires the website to ask the user’s computer for some proof that the user’s identity has been authenticated by the OAuth provider (e.g., Google). This requires the user’s computer to first contact the OAuth provider where the user can input their username and password. The OAuth provider provides a digitally signed token that confirms the user’s identity.

For now it is sufficient to understand that in this case the digitally signed token cannot be created or modified by anyone other than the OAuth provider. Once it receives the token all the website needs to do is to check that the signature on this token is valid to confirm the identify of the user.

So using OAuth can simplify your password management because all you need to remember is the username and password for your account with the OAuth provider. However, just as with password managers, if you forget this password you will no longer have access to any of the accounts. Additionally, if an attacker gets access to this password, they will be able to access all the online systems you are able to access using your OAuth account details.

So password managers and online authentication services like OAuth can simplify the management of your online accounts, they are not complete solutions. Next, we will look at another way of improving the security of the authentication mechanisms we use like two factor authentication

© The Open University
at Futurelearn

INTRODUCTION TO CYBER SECURITY: Password Manager


While it is possible to create your own strong passwords, it can sometimes be difficult to remember each one, especially if you use a number of online services.


A password manager is an application running on your computer that stores passwords for you. Very simple password managers allow stored passwords to be copied and pasted into log-in boxes. More sophisticated managers let users launch and log in to an application or website by clicking on their entry in the manager itself, while some password managers include browser ‘plug-ins’ so that you can complete a log-in on a web page simply by pressing a button.

Course-specific creative- The Complete Java Developer Course     Course-specific creative-The Complete iOS 9 Developer Course - Build 18 Apps   Course-specific creative-The Complete Ethical Hacking Course: Beginner to Advanced!

The majority of password managers also offer password generation facilities. Since computers can remember arbitrarily long pieces of nonsense text, say MHpKQCvpYoouTAaPiiWuFKjpNe7qnsbwkrvq3s3cX password managers have no problems with creating passwords that are highly resistant to both brute force and dictionary attacks. Since a password manager contains a great deal of extremely valuable information it represents an attractive target for an attacker. Before choosing a manager you should check that:
  • The password manager itself requires a password to use it. This prevents an attacker simply starting the password manager and accessing your passwords.
  • The password manager should lock itself after a period of inactivity. This stops an attacker accessing the passwords if you have previously used the password manager and then left your machine unattended.
  • The passwords themselves should be encrypted on your computer. This prevents an attacker reading your passwords without needing to open the password manager.
Course-specific creative-Building a Personal Brand by Gary Vaynerchuk   Course-specific creative-JavaScript: Understanding the Weird Parts   Course-specific creative-The Complete Web Developer Course - Build 14 Websites

Most modern web browsers offer to remember passwords when you enter them into web forms, providing password management for websites you visit using the browser. This can be very convenient for frequently visited sites where you regularly have to enter details. The security of this password storage is strong and your data will not be visible to casual inspection, but you should be extremely careful using them on any computer that you do not own or have sole control of, since your data will be stored on the machine and could be misused by another user or an administrator.

You should only consider using a browser’s password storage on a machine that you are the sole user of, or one where you entirely trust the other users. Under no circumstances should you store passwords in the browsers of public machines in places such as cafes, libraries and workplaces.

Course-specific creative-Learn To Code by Making Games - The Complete Unity Developer   Course-specific creative-Learn and Understand AngularJS   Course-specific creative-The Complete Android Developer Course - Build 14 Apps

When using a password manager check that the password manager’s security functionality has been evaluated by a reputable independent organisation. Additionally, make sure you select a very strong password for controlling access to the password store. This will minimise the risk of attackers having access to your passwords, even if they do manage to steal the encrypted password store, either from your machine or from online storage provided by the password manager software.

© The Open University

https://www.futurelearn.com/courses/introduction-to-cyber-security/8/steps/83051

Thursday, July 7, 2016

Introduction to Cyber Security - Attacking passwords

The obvious ways that attackers can find or steal passwords, such as looking over your shoulder when you’re using an ATM or credit card machine or trying obvious passwords such as ‘abc123’ and ‘password’, are familiar to us.

Almost as long as there have been passwords there have been people attempting to break passwords. One of the oldest methods of automatically breaking into computers is to perform a dictionary attack. As its name suggests, a computer will attempt to log into an account by working its way through one or more dictionaries – each entry in the dictionary is one possible password and if it doesn’t work, the computer moves on to the next.

Discover Data Science with Coursera

Dictionaries need not be the familiar A–Z references that we are familiar with: a concerted dictionary attack will also include more specialised reference works such as atlases, lists of astronomical bodies and characters from literature, as well as lists of the most commonly used passwords and lists of stolen passwords that are in widespread circulation.

Dictionary attacks can also be performed on the hashed values of words; they may take a little longer, but they will work. Some system administrators might set up dictionary attacks on their own users’ passwords to try to identify weak passwords that should be changed.

An alternative, simple attack is a brute force attack where a computer will methodically work through all possible passwords (so beginning with ‘A’, then ‘AA’, ‘AB’ and so on …) trying each in turn until it stumbles upon an actual password.

Dictionary and brute force attacks can be foiled by having computers watch for unsuccessful attempts to log in to accounts. Almost all computer systems restrict the number of unsuccessful log-ins after which the account is locked and can only be accessed after the intervention of an administrator.

Another type of attack on passwords is based on the incorrect configuration of the hashing technique used to store the passwords on the server, which is discussed in the next step.

Learn Algorithmic Programming Techniques with UCSD/HSE and Coursera. Prepay and receive a 10% discount.  

Salt to protect
The security of stored passwords can be increased by a process known as salting – in which a random value (called the salt) is added to the plaintext password before the hashing process.

This greatly increases the number of possible hash values for the password and means that even if two people choose identical passwords, their hashed passwords have completely different values.

The hashed password and the relevant salt are stored by the password server. When the user attempts to log in to the computer, their password and the salt are added together, hashed and compared to the stored, hashed value.

Salting is only effective if:
  • truly random salts are used for each password (some systems have either used a single salt for all passwords, or have only changed the salt when the computer is restarted)
  • the salt is long enough that, when added to a password, it will create enough possible hashed values that an attacker cannot generate a table containing all possible hashes from a salted dictionary. For instance, the passwords used by UNIX in the early 1970s were restricted to eight characters and used a 12-bit salt. When released this was secure enough – it was not feasible to generate the hashes for every possible password each of which had been salted with all 4096 possible salts. However, the rapid advance in computer power and storage capacity meant that longer salts are required. A typical piece of advice is that the salt should be the same length as the output of the hashing function – so if your hashing function generates 256-bit hashes, a 256-bit salt should be used.
New Skills, New You: Transform your career in 2016 with Coursera  

Case study: LinkedIn
In the middle of 2012, the hugely successful social networking site LinkedIn was attacked by Russian hackers. The passwords to some 6.5 million accounts were stolen, but although they were stored as hashed values, the passwords had not been salted.

The hashing had been performed using the relatively old SHA-1 hashing algorithm which can be performed at very high speed (a desktop computer can calculate several tens of millions of SHA-1 hashes per second).

It was therefore not surprising that within a day, decrypted passwords were being published on the internet and LinkedIn was forced to ask all users to change their passwords.

Preventing the attacks described above depends on the online service taking steps to encrypt the transmission and storage of passwords. As users, we can help in this protection by choosing passwords that are difficult to attack.

  Bienvenidos a Coursera en Espa̱ol