<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-8400370148915075091</id><updated>2012-01-27T08:47:28.260+01:00</updated><title type='text'>Security Nirvana</title><subtitle type='html'>Personal research and opinions.</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://securitynirvana.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://securitynirvana.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><link rel='next' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default?start-index=101&amp;max-results=100'/><author><name>Per Thorsheim</name><uri>https://profiles.google.com/113848325212589987956</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-skpoP167x04/AAAAAAAAAAI/AAAAAAAAAVU/RWc12nir74w/s512-c/photo.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>134</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-8400370148915075091.post-2900672903259001020</id><published>2012-01-24T00:35:00.002+01:00</published><updated>2012-01-24T00:35:45.083+01:00</updated><title type='text'>Kommentar: sikring av iPad</title><content type='html'>&lt;a href="http://hanspetter.info/"&gt;Hans Petter Nygård-Hansen&lt;/a&gt;&amp;nbsp;har skrevet en veldig bra bloggpost med tittelen "&lt;a href="http://hanspetter.info/2012/01/11-tips-for-a-jobbe-sikkert-pa-din-ipad/"&gt;11 tips for å jobbe sikkert på din iPad&lt;/a&gt;". Jeg vil så absolutt anbefale alle med iPad (eller iPhone for den saks skyld) å lese denne bloggposten. Det er vel verdt det, og den er ikke bare aktuell for de som bruker iPaden sin i jobbsammenheng.&lt;br /&gt;&lt;br /&gt;Jeg vil bare gi noen små kommentarer og tips til de som ønsker å gjøre disse anbefalte tiltakene:&lt;br /&gt;&lt;br /&gt;&lt;a name='more'&gt;&lt;/a&gt;&lt;b&gt;Først en kommentar til p&lt;/b&gt;&lt;b&gt;kt 3: Krev bruk av passord for å åpne iPad-en&lt;/b&gt;&lt;br /&gt;Noe av det som er positivt med iPad &amp;amp; iPhone er at de benytter AES datakryptering som standard. På godt norsk: alle programmer og informasjon på iPad-en din er rimelig godt sikret, men det avhenger allikevel av at du bruker et godt passord.&amp;nbsp;Hans Petter anbefaler bruk av passord med bokstaver og tall.&lt;br /&gt;&lt;br /&gt;&lt;u&gt;En liten faktaopplysning:&lt;/u&gt;&lt;b&gt;&amp;nbsp;&lt;/b&gt;&lt;br /&gt;&lt;b&gt;Det er mulig å "knekke" en 4-sifret PIN kode på maksimalt 1 time&lt;/b&gt; &lt;b&gt;på en iPad&lt;/b&gt; ved hjelp av spesiell programvare. Det har ingen betydning om du har begrenset antall forsøk eller tilsvarende, alt dette kan forbigås. Med en gang du passerer lengde 6 så begynner vi å snakke svært lang tid.&lt;br /&gt;&lt;br /&gt;Et tips er å bruke en lang PIN kode. PIN koden 64604723 blir faktisk passordfrasen "&lt;b&gt;min ipad&lt;/b&gt;" når du ser de små bokstavene under tallene på talltastaturet:&lt;br /&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-zWSlIDYpQpE/Tx3nFc2t2OI/AAAAAAAAAig/aVgNwpsygW0/s1600/ipad_keypad.PNG" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="133" src="http://1.bp.blogspot.com/-zWSlIDYpQpE/Tx3nFc2t2OI/AAAAAAAAAig/aVgNwpsygW0/s200/ipad_keypad.PNG" width="200" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;i&gt;(Klikk for å zoome)&lt;/i&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;Uansett er det viktigste at du finner din egen metode som fungerer for deg, og som gir et-eller-annet passord på minst 6-7 tegns lengde.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;--&lt;/b&gt;&lt;br /&gt;Som jeg skrev innledningsvis så er det en utrolig god bloggpost skrevet av Hans Petter. Jeg foreslår følgende tillegg:&lt;br /&gt;&lt;br /&gt;&lt;b&gt;12. Eierskapsinformasjon på låseskjermen&lt;/b&gt;&lt;br /&gt;Slik ser min "låseskjerm" ut:&lt;br /&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-2Kh-WAjnaXs/Tx3n2DuawZI/AAAAAAAAAio/xpv6xFMZDZ4/s1600/laaseskjerm_uten_billedgalleri_liten.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="200" src="http://2.bp.blogspot.com/-2Kh-WAjnaXs/Tx3n2DuawZI/AAAAAAAAAio/xpv6xFMZDZ4/s200/laaseskjerm_uten_billedgalleri_liten.png" width="149" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;i&gt;(Klikk for å zoome)&lt;/i&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;Selvforklarende antar jeg? Enkel og grei "tyverimerking", dersom jeg glemmer den noe sted. Jeg bare skrev teksten inn i keynote, tok en "screenshot" (trykk strømknappen + hjemknappen samtidig), og satte bildet som bakgrunn på låseskjermen. Dette gjør du under &lt;b&gt;Innstillinger - Lysstyrke og bakgrunn:&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-jieU2YzkcXs/Tx3q9kGI03I/AAAAAAAAAi0/Oy5HgVVldXc/s1600/iPad_endre_bakgrunn_laaseskjerm_liten.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="192" src="http://2.bp.blogspot.com/-jieU2YzkcXs/Tx3q9kGI03I/AAAAAAAAAi0/Oy5HgVVldXc/s320/iPad_endre_bakgrunn_laaseskjerm_liten.png" width="320" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;i&gt;(Klikk for å zoome)&lt;/i&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;Klikk på bakgrunnsblidet som vist over, bla deg frem til det bildet du vil bruke, og velg deretter "Bruk på låst skjerm" som vist under:&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-yLazS5u2MUc/Tx3q-lqjeFI/AAAAAAAAAi8/2GljvXZmEbk/s1600/sett_laaseskjerm_bakgrunn_liten.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="166" src="http://4.bp.blogspot.com/-yLazS5u2MUc/Tx3q-lqjeFI/AAAAAAAAAi8/2GljvXZmEbk/s320/sett_laaseskjerm_bakgrunn_liten.png" width="320" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;i&gt;(Klikk for å zoome)&lt;/i&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;b&gt;13. Fjern tilgang til billedramme fra låseskjermen&lt;/b&gt;&lt;br /&gt;Hvem vet - du kan ha bilder på iPad-en som ikke skal være tilgjengelig for alle. Private bilder eller bilder tatt i jobbsammenheng, spiller forsåvidt liten rolle. På låseskjermen er det som standard mulighet for å trykke på et ikon slik at iPad-en begynner å vise bilder fra billedgalleriet. Det vil du unngå, og du gjør det enkelt under &lt;b&gt;Innstillinger - Kodelås&lt;/b&gt;, og sørger for at innstillingen står som vist under:&lt;br /&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-oaU3QD1GR5g/Tx3tbrnvvzI/AAAAAAAAAjM/DInTOm2RLL8/s1600/ipad_exchange_1_liten.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="225" src="http://2.bp.blogspot.com/-oaU3QD1GR5g/Tx3tbrnvvzI/AAAAAAAAAjM/DInTOm2RLL8/s320/ipad_exchange_1_liten.png" width="320" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;i&gt;(Klikk for å zoome)&lt;/i&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;b&gt;Helt til slutt: &lt;/b&gt;dersom du har koblet din iPad opp mot jobben, f.eks. ved at du har e-post, kontakter og kalender synkronisert, så kan det være at IT-avdelingen har satt restriksjoner på enkelte av de valg som her beskrevet. Er det enkelte valg du ikke kommer inn på eller får endret slik du ønsker, så kontakt IT-avdelingen. Det er ikke skrive- eller bildefeil hverken fra meg eller Hans Petter. :-)&lt;br /&gt;&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8400370148915075091-2900672903259001020?l=securitynirvana.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securitynirvana.blogspot.com/feeds/2900672903259001020/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://securitynirvana.blogspot.com/2012/01/kommentar-sikring-av-ipad.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/2900672903259001020'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/2900672903259001020'/><link rel='alternate' type='text/html' href='http://securitynirvana.blogspot.com/2012/01/kommentar-sikring-av-ipad.html' title='Kommentar: sikring av iPad'/><author><name>Per Thorsheim</name><uri>https://profiles.google.com/113848325212589987956</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-skpoP167x04/AAAAAAAAAAI/AAAAAAAAAVU/RWc12nir74w/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-zWSlIDYpQpE/Tx3nFc2t2OI/AAAAAAAAAig/aVgNwpsygW0/s72-c/ipad_keypad.PNG' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8400370148915075091.post-4828299477011447712</id><published>2012-01-22T22:06:00.001+01:00</published><updated>2012-01-22T22:06:58.450+01:00</updated><title type='text'>Password Change Frequency</title><content type='html'>&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://mathcircle.berkeley.edu/images/CliffStoll.jpg" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="320" src="http://mathcircle.berkeley.edu/images/CliffStoll.jpg" width="296" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;i&gt;(Picture of Cliff Stoll, linked from&lt;a href="http://mathcircle.berkeley.edu/index.php?options=bmc%7Cpeople%7Cpeople"&gt; Berkeley website&lt;/a&gt;)&lt;/i&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;Professors are nice people. Seriously. They can be a challenge too, as I got to experience firsthand during my 3,5 hour lecture on &lt;a href="http://www.slideshare.net/perthorsheim/passwords-security"&gt;password security&lt;/a&gt; at the &lt;a href="http://www.nisnet.no/index.php/divarrangementer11/winterschool2011"&gt;NISNET winter school&lt;/a&gt;, 22-27 May 2011. Paranoid as I am, I even suspect two of them agreeing into a secret pact to have some fun on my behalf. ;-)&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Note:&lt;/b&gt; I started writing this blog post in May 2011. Dropped some of my ideas, and have spent another 8 months to think, read and discuss the issues of password change frequencies. Now, at the time of publishing, I still haven't made up my mind. The "simple" question of &lt;b&gt;How often should I change my passwords? &lt;/b&gt;isn't all that easy to answer.&lt;br /&gt;&lt;br /&gt;&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;First of all, I have the utmost respect for &lt;a href="http://www.ansatt.hig.no/patrickb/"&gt;Professor Patrick Bours&lt;/a&gt; and &lt;a href="http://www.christoph-busch.de/"&gt;Professor Christoph Busch&lt;/a&gt;, so no hard feelings in this blog post guys. I'll take this as a challenge, without doubt. ;-)&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Here's what happened:&lt;/b&gt;&lt;br /&gt;During my lecture, I said that in general I would recommend a password policy to require a minimum password length of &lt;b&gt;10&lt;/b&gt; characters, and give users a &lt;b&gt;13&lt;/b&gt; month change frequency as a reasonable tradeoff. I forgot to say that I've asked a lot of people if they would accept that, and almost everyone has considered that to be reasonable.&lt;br /&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;br /&gt;Somewhere else during my lecture, I showed password statistics based on data from a Windows domain, where LM as well as NTLM hashes were available. Naturally, LM hashes made things easy, so my statistics were based on having cracked 100% of the passwords.&lt;br /&gt;&lt;br /&gt;I also said that I had successfully cracked a password of length 32 (or somewhere in that area), based on the NTLM hash and a user who had chosen a passphrase found on wikipedia with 2 digits applied to the end. A simple dictionary-hybrid attack using &lt;a href="http://www.oxid.it/"&gt;Cain&lt;/a&gt;&amp;nbsp;overnight, using the popular wiki-wordlist by&amp;nbsp;&lt;span class="Apple-style-span" style="line-height: 15px;"&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;a href="http://blog.sebastien.raveau.name/2009/03/cracking-passwords-with-wikipedia.html"&gt;Sébastien Raveau&lt;/a&gt;&amp;nbsp;recovered the password.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="line-height: 15px;"&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="line-height: 15px;"&gt;&lt;b&gt;This is where Professor Christoph Busch raised his hand for some questions:&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="line-height: 15px;"&gt;First question was how long time it took me to crack that length 32 password. I said "I was sleeping at the time, but maybe 8 hours?". His response got stuck in my brain:&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;span class="Apple-style-span" style="line-height: 15px;"&gt;"&lt;i&gt;If your window of opportunity to crack a users password like this is - say 4 hours - why do you suggest a change frequency of 13 months, when it probably should be &amp;lt;4 hours?&lt;/i&gt;"&lt;/span&gt;&lt;/blockquote&gt;.... Being a password geek, waking up in the middle of the night with that question hammering your head is NOT pleasant at all. Damn you Christoph! ;-)&lt;br /&gt;&lt;br /&gt;Now lets move to another part of the world, a long time ago during a penetration test, another guy came with some arguments regarding password change frequencies. Lets just call him "anonymous" for now, but he's yet another one of those guys that I really respect in terms of security knowledge. He simply said:&lt;br /&gt;&lt;blockquote class="tr_bq"&gt;&lt;i&gt;"If my password sufficiently strong in regard of length &amp;amp; complexity and stored with a reasonable hash algorithm, &lt;b&gt;why would I ever need to change my password?&lt;/b&gt;"&lt;/i&gt;&lt;/blockquote&gt;Oh; and at his organisation at the time, they didn't do mandatory password change for anyone. EVER. In fact, he said that starting mandatory frequent password changes would be over his dead body. He's still alive (...), and now they do frequent password changes. :-) Partially based - I guess - on the fact his Windows password got cracked in minutes.&lt;br /&gt;&lt;br /&gt;Now if you spend a couple of minutes thinking about reasons for &lt;b&gt;why&lt;/b&gt; you should change one or more of your passwords on something that even resembles some short of frequency (days, months, years) or other reasons, you'll probably come up with quite a few:&lt;br /&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;(Corporate) policy enforces it - can't convince them into anything else&lt;/li&gt;&lt;li&gt;Some external experts told me/us to do so &lt;i&gt;(insert name/organization/url here....:-))&lt;/i&gt;&lt;/li&gt;&lt;li&gt;I don't believe in &lt;a href="http://dl.acm.org/citation.cfm?id=1866328"&gt;research&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;&lt;a href="http://research.microsoft.com/apps/pubs/?id=154077"&gt;I haven't opened my eyes&lt;/a&gt;.&lt;/li&gt;&lt;li&gt;&lt;i&gt;Oops. Sorry. Got a little carried away there. :-)&lt;/i&gt;&lt;/li&gt;&lt;/ol&gt;&lt;div&gt;No, I'm not going to reveal my stance on this topic quite yet. I need to read that last paper there thoroughly. Twice.&amp;nbsp;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;i&gt;However I would really like to hear your opinion:&amp;nbsp;&lt;/i&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;How often, if ever, should we change our passwords?&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;I would be really happy if you reply with references to research, blog posts, articles, papers or anything else that can shed some more light on this subject. Yes, you can link to your own blogs and opinions. :-)&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8400370148915075091-4828299477011447712?l=securitynirvana.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securitynirvana.blogspot.com/feeds/4828299477011447712/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://securitynirvana.blogspot.com/2012/01/password-change-frequency.html#comment-form' title='7 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/4828299477011447712'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/4828299477011447712'/><link rel='alternate' type='text/html' href='http://securitynirvana.blogspot.com/2012/01/password-change-frequency.html' title='Password Change Frequency'/><author><name>Per Thorsheim</name><uri>https://profiles.google.com/113848325212589987956</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-skpoP167x04/AAAAAAAAAAI/AAAAAAAAAVU/RWc12nir74w/s512-c/photo.jpg'/></author><thr:total>7</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8400370148915075091.post-934009211198487446</id><published>2012-01-10T23:32:00.001+01:00</published><updated>2012-01-10T23:32:44.350+01:00</updated><title type='text'>Passwords^12</title><content type='html'>&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://farm4.staticflickr.com/3072/5814671141_0e8ab3f47f_m.jpg" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" src="http://farm4.staticflickr.com/3072/5814671141_0e8ab3f47f_m.jpg" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;i&gt;(Picture is (C) &lt;a href="http://www.flickr.com/photos/kluzz/5814671141/in/set-72157626922118872"&gt;KluZz&lt;/a&gt;&amp;nbsp;- aka my friend/colleague Jan Fredrik Leversund)&lt;/i&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;I have received many questions about the two first Passwords^XX conferences that I arranged in cooperation with professor Tor Helleseth at the university here in Bergen, Norway. The most frequent question after Passwords^11 in June 2011 is of course "when and where will the next conference be?". So here is some preliminary information from me, as well as a quest for sponsors for doing the conference somewhere in the US as well! :-)&lt;br /&gt;&lt;br /&gt;&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;1. FREE, as in FREE&lt;/b&gt;&lt;br /&gt;I want the conference to be open for anyone to participate (limited seats though), and FREE to attend. At least as free as possible. No, I'm not interested in making any money of it. Attendees will eventually have to pay for food and their own drinks in the evening of course.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;2. ACADEMICAL PERSPECTIVE&lt;/b&gt;&lt;br /&gt;I want to learn something, and I sure hope the audience want the same. The best way to do it in my opinion: a mix of people from public, private and academic sectors. Public as police, military, not for profit organisations (ISC)2, ASIS, ISACA etc, private as in commercial companies or single persons, and academics (professors and perhaps PhD's... :-))&lt;br /&gt;&lt;br /&gt;&lt;b&gt;3. SPONSORSHIPS&lt;/b&gt;&lt;br /&gt;Sure. But I won't give you time to talk during the conference, unless to solve problems without selling your own products. Food, drinks, facilities, pamphlets, parties, whatever. Bring it. What do I need sponsors for? Well, first and foremost to pay travel and accomodation for selected speakers. At &lt;a href="http://securitynirvana.blogspot.com/2010/12/videos-and-presentations-now-online.html"&gt;Passwords^10&lt;/a&gt; and &lt;a href="http://securitynirvana.blogspot.com/2011/06/passwords11-video-archive.html"&gt;Passwords^11&lt;/a&gt; we had speakers that came on their own, with no commercial support backing them. Travelling halfway around the world to speak about passwords, they deserve some help getting there. Each of the two previous conferences had budgets &amp;lt;= USD 9000,-, so it's not that much of a big deal I think.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;4. CONFERENCE CONTENT&lt;/b&gt;&lt;br /&gt;This is, was, and will be a conference focusing on passwords and PIN codes only. Period. No biometrics, 2-factor authentication or any other solutions. Why? Because we won't get rid of passwords or pin codes any time soon. Better make the best of it - I belive a lot can still be done to improve the situation.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;5. SPEAKERS&lt;/b&gt;&lt;br /&gt;Yes, I will of course do a &lt;b&gt;call for papers&lt;/b&gt;. That said, let me give you a few ideas on who I would like to have thee as a speaker, and why (in no particular order):&lt;br /&gt;&lt;br /&gt;I would love to have&lt;a href="http://www.blogger.com/goog_569962472"&gt; &lt;/a&gt;&lt;b&gt;&lt;a href="http://research.microsoft.com/en-us/people/cormac/"&gt;Cormac Herley&lt;/a&gt; &lt;/b&gt;from Microsoft Research there. He can bring his co-authors as well, I think I could spend a full day without breaks listening to them presenting their published papers. If &lt;a href="http://www.cl.cam.ac.uk/~fms27/"&gt;Frank Stajano&lt;/a&gt; has any updates for PICO, or if he has been looking more into security usability, I'd like to hear about it. Oh, and on the topic of security usability, I would like to listen to &lt;a href="http://www.markus-jakobsson.com/"&gt;Markus Jakobsson&lt;/a&gt; from PayPal as well. More suggestions for speakers from the academic world is of course most welcome. Oh; and if anybody knows Bruce Schneier: Yes, I'll accept any talk on passwords from him - preferably with the phrase "security theater" somewhere in the headline.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.passware.com/"&gt;Passware&lt;/a&gt; and &lt;a href="http://www.elcomsoft.com/"&gt;Elcomsoft&lt;/a&gt; scared us all at the previous conferences. I'd like to invite them back again for updates and live demonstrations, eventually also bringing in &lt;a href="http://www.oxygen-forensic.com/en/"&gt;Oxygen Software&lt;/a&gt; to show us forensics of smart phones. (People still get amazed when I talk about iOS forensic toolkit and what kind of information you can get access to, or the firewire attacks from Passware....). Focusing on smart phone/pad security, these guys should be able to give us a fun show to watch - and a few ideas for our next audits of corporate Activesync policies.&lt;br /&gt;&lt;br /&gt;We would have to invite back quelrods, or&lt;b&gt; James Nobis&lt;/b&gt; if you like. He knows his stuff on rainbowtables. Eventually also &lt;b&gt;Sc00bz&lt;/b&gt; and &lt;b&gt;Powerblade&lt;/b&gt; from the &lt;a href="http://www.freerainbowtables.com/"&gt;Freerainbowtables&lt;/a&gt; project to present on the latest developments there. That project continues to prove that you need to salt your passwords, period.&lt;br /&gt;&lt;br /&gt;As for password crackers, &lt;b&gt;atom&lt;/b&gt;&amp;nbsp;would be an obvious speaker, presenting .. anything... about &lt;b&gt;&lt;a href="http://hashcat.net/"&gt;hashcat&lt;/a&gt;&lt;/b&gt;. In fact I would like to hear lots of stuff about it, and by bringing in Solar Designer from &lt;a href="http://www.openwall.com/john/"&gt;Openwall&lt;/a&gt;&amp;nbsp;or some of the hard-core guys from the JtR mailing list on advanced rule creation with JtR/hashcat, we're talking serious stuff. A presentation from Bitweasil at &lt;a href="http://www.cryptohaze.com/"&gt;Cryptohaze&lt;/a&gt;&amp;nbsp;would of course be of interest as well, while &lt;a href="http://3.14.by/en/"&gt;Michail&lt;/a&gt; could eventually give us some interesting perspectives from a completely different side of our world. Not to forget we should have &lt;a href="http://reusablesec.blogspot.com/"&gt;Matt Weir&lt;/a&gt; (@lakiw) talk a little about NIST SP800-63 and his PhD work. And in the second corner: &lt;a href="http://www.its-blog.de/"&gt;Norbert Schmitz&lt;/a&gt; (@nidshce) from Germany, who have plans on improving the attacks as outlined by Matt in his work.&lt;br /&gt;&lt;br /&gt;We should also look at all the statistics we've got, based on the ever-increasing number of leaks found all over the Internet. I presume &lt;a href="https://twitter.com/#!/purehate_"&gt;Martin Bos&lt;/a&gt; (@purehate_) and &lt;a href="http://www.troyhunt.com/"&gt;Troy Hunt&lt;/a&gt;&amp;nbsp;would have both statistics and opinions to share. :-)&lt;br /&gt;&lt;br /&gt;Remembering Howard Smith from Oracle UK, and his suggestion for a panel discussion at Passwords^10 (which we did do, right there and then), if somebody knows a lawyer who can present on the legal side of downloading, cracking, distributing, PIPAL'ing and commenting on leaked passwords - I'd love that.&lt;br /&gt;&lt;br /&gt;I would also like to see somebody talk about the usability aspects of passwords and pins. How do we assign them, side-channel transfers of username/pass/url/system name , password resets, service account management, why the annoying asterisks when I type my password (&lt;a href="http://www.darkreading.com/authentication/167901072/security/news/232400013/passphrases-a-viable-alternative-to-passwords.html"&gt;Good article at darkreading here&lt;/a&gt;).&lt;br /&gt;&lt;br /&gt;Hey; Microsoft could present on "&lt;a href="http://blogs.msdn.com/b/b8/archive/2011/12/16/signing-in-with-a-picture-password.aspx"&gt;picture password&lt;/a&gt;" in Windows 8! (I guess they will still be using NTLM though... *doh!*), while somebody else could talk on PBKDF2, bcrypt and scrypt. Or perhaps &lt;a href="http://keccak.noekeon.org/"&gt;Joan Daemen&lt;/a&gt; would like to update us on the status of SHA-3?&lt;br /&gt;&lt;br /&gt;Last but not least - any chance we could try to work out some "best practices" that we - as "password experts" - can agree on, and pass on to all those who need it?&lt;br /&gt;&lt;br /&gt;--&lt;br /&gt;I guess the above would easily cover 2 full days, right? :-)&lt;br /&gt;&lt;br /&gt;Comments are most welcome. Feel free to contact me by e-mail for personal inquiries.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8400370148915075091-934009211198487446?l=securitynirvana.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securitynirvana.blogspot.com/feeds/934009211198487446/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://securitynirvana.blogspot.com/2012/01/passwords12.html#comment-form' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/934009211198487446'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/934009211198487446'/><link rel='alternate' type='text/html' href='http://securitynirvana.blogspot.com/2012/01/passwords12.html' title='Passwords^12'/><author><name>Per Thorsheim</name><uri>https://profiles.google.com/113848325212589987956</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-skpoP167x04/AAAAAAAAAAI/AAAAAAAAAVU/RWc12nir74w/s512-c/photo.jpg'/></author><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8400370148915075091.post-4521677575940805438</id><published>2012-01-06T11:04:00.002+01:00</published><updated>2012-01-06T11:13:38.523+01:00</updated><title type='text'>Errata for Errata security</title><content type='html'>Sorry about the title, best I could come up with late at night.&lt;br /&gt;&lt;br /&gt;The blog post&amp;nbsp;&lt;span style="font-family: inherit; font-size: small;"&gt;&lt;a href="http://erratasec.blogspot.com/2012/01/passwords-uniqueness-not-complexity.html"&gt;Passwords: uniqueness, not complexity&lt;/a&gt;&lt;/span&gt;&amp;nbsp;from Robert David Graham (@ErrataRob) at Errata Security isn't bad, but it is not all that good either. Based on the recent - should I say ongoing - breach of #stratfor, Robert recommends unique passwords instead of having complex passwords. I would ask "why not both?". Let me explain...&lt;br /&gt;&lt;br /&gt;&lt;a name='more'&gt;&lt;/a&gt;Let us begin with the .. rumor .. that #stratfor got hacked due to lack of proper hardening and system maintenance. &lt;i&gt;No, a blank password is not a bad password, it is evidence of incorrect installation and hardening, and a strong sign of weak computer security audits.&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;1. Long, complex, case-senstive passwords with multiple characters&lt;/b&gt;&lt;br /&gt;That advice in the&lt;a href="http://www.msnbc.msn.com/id/45871509/ns/technology_and_science-security/#.Twa719RvuRo"&gt; MSNBC article&lt;/a&gt;&amp;nbsp;comes from Morgan Slain, CEO of &lt;a href="http://www.splashdata.com/"&gt;SplashData&lt;/a&gt;. He actually recommend the &amp;nbsp;"use a short sentence" trick, which I've been saying for quite some time already. Actually I say "use a positive sentence, something that you WANT to remember". Passwords are a mandatory pain to most of us, something that users normally doesn't want to remember. Use something that you want to remember.&lt;br /&gt;&lt;br /&gt;Robert David Graham says "That's wrong advice", saying that passwords should be unique instead. I'd say Robert is 50% correct. Why not do both long, complex &amp;amp; unique?&lt;br /&gt;&lt;br /&gt;With a password manager (LastPass, Keepass, or your selection of similar software), you can create long, complex and unique passwords. Bonus point: you don't need to remember them anymore. Not that password managers are for everyone; mom would most certainly reject the idea of downloading, installing, and learn how to use one for starters. "Give me something that I don't need to learn anything about, just make it work for me".&lt;br /&gt;&lt;br /&gt;&lt;b&gt;My password for Facebook is both long &amp;amp; strong! &lt;/b&gt;but really not that difficult to remember, right?&lt;br /&gt;&lt;br /&gt;&lt;b&gt;2. "...little to lose if hackers guess it."&lt;/b&gt;&lt;br /&gt;Except for the embarrassment of course, which in some cases should be seen as part of overall reputation risk. "If person X uses &lt;b&gt;password&lt;/b&gt; as his password at hacked site X, who knows how that person will handle &amp;nbsp;&amp;amp; secure confidential data at other places?". Trust is hard to get, but easy to loose.&lt;br /&gt;&lt;br /&gt;Another aspect is the eternal discussion of "&lt;a href="http://papers.ssrn.com/sol3/papers.cfm?abstract_id=998565"&gt;I've got nothing to hide&lt;/a&gt;" (San Diego Law Review, Professor Daniel Solove examines the argument).&lt;br /&gt;&lt;br /&gt;&lt;b&gt;3. Three tiers of websites&lt;/b&gt;&lt;br /&gt;&lt;b&gt;First&lt;/b&gt;; I've got multiple e-mail addresses. Even if you compromised all of them, you would not be able to get access to all my accounts. There are services out there that doesn't (entirely) rely upon e-mail for account verification and passwords resets you know... Although very common of course, and an area of security where many do step into pitfalls.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Second (fact)&lt;/b&gt;: MANY e-mail providers, including large ISPs, does not support encryption for pop3/imap/smtp communication, so no matter what your e-mail password might be, it is easily sniffed off your network. If you happen to use https to reach your e-mail it gets harder of course, but of course SSL is not broken, and we all trust every CA on the planet, right?&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Third:&lt;/b&gt; the definition of tiers used. My primary e-mail is not accessed using webmail, I'm part of the old POP3 generation, although encrypted these days. I think the same applies to many others, if not running it off Microsoft Exchange or similar services.&lt;br /&gt;&lt;br /&gt;Ranking e-commerce sites like Amazon etc as second on your list is .. weird. I say that from my Norwegian point of view: unless I'm acting as a complete idiot and give away my pin/password or OTP for my online bank on purpose, I WILL GET MY MONEY BACK&lt;b&gt;&amp;nbsp;&lt;/b&gt;if hacked. &lt;b&gt;Heck, the technical implementation at my bank even allows me to use my username as my password.&lt;/b&gt; Pretty cool, huh?&lt;br /&gt;&lt;br /&gt;The important thing you forgot with your tier definition is the sites that carry sensitive information about you as a person. Think privacy laws. At least here in Norway, my salary, my bank statements etc are "secrets", but we have 2 levels of personal information here. Top level: Race, sexual preferences, political view and memberships, religious views and a little more. Lower level: anything that can be used to identify a single citizen of Norway. IP address, phone number, you name it.&lt;br /&gt;&lt;br /&gt;Based on those definitions, &lt;b&gt;Facebook&lt;/b&gt;&amp;nbsp;keeps more sensitive information about me than my bank. Who should have the better security? (&lt;i&gt;and what does reality look like?&lt;/i&gt;)&lt;br /&gt;&lt;br /&gt;--&lt;br /&gt;&lt;br /&gt;Now this is very important for me to say: I completely agree with you @ErrataRob on your conclusion: "Your first password policy shouldn't be complexity, but uniqueness".&lt;br /&gt;&lt;br /&gt;Using sentences you want to remember, I think one would be able to do both uniqueness, and complexity comes from length. &lt;i&gt;(Password entropy calculation on anything up to length 8 is a lost case - length 8 can be rather easily broken, period).&lt;/i&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8400370148915075091-4521677575940805438?l=securitynirvana.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securitynirvana.blogspot.com/feeds/4521677575940805438/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://securitynirvana.blogspot.com/2012/01/errata-for-errata-security.html#comment-form' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/4521677575940805438'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/4521677575940805438'/><link rel='alternate' type='text/html' href='http://securitynirvana.blogspot.com/2012/01/errata-for-errata-security.html' title='Errata for Errata security'/><author><name>Per Thorsheim</name><uri>https://profiles.google.com/113848325212589987956</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-skpoP167x04/AAAAAAAAAAI/AAAAAAAAAVU/RWc12nir74w/s512-c/photo.jpg'/></author><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8400370148915075091.post-392382654746133532</id><published>2012-01-02T15:35:00.000+01:00</published><updated>2012-01-02T15:35:11.741+01:00</updated><title type='text'>Short comments on #STRATFOR</title><content type='html'>Lots of articles popping up on the #&lt;a href="http://www.stratfor.com/"&gt;stratfor&lt;/a&gt; leaks all over the web. Some good, some not that good. Just a few comments from me, until I eventually get the time to do a bigger blog post on the subject.&lt;br /&gt;&lt;br /&gt;&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;1. Written policies&lt;/b&gt;&lt;br /&gt;Lots of websites has a written password policy. Many of them are just *stupid*, others are better. Very few are what I would call good policies, in terms of both usability and security. Example from the stupid side of password policies: "&lt;i&gt;&lt;b&gt;do not use any word from any wordlist. ever!&lt;/b&gt;&lt;/i&gt;".&lt;br /&gt;&lt;br /&gt;&lt;b&gt;2. Technical implementation&lt;/b&gt;&lt;br /&gt;If they have a written policy, there is a rather high probability they haven't implemented it. Some "requirements" just cannot be implemented, try implementing the example above. For English you would have to block words like&amp;nbsp;&lt;a href="http://en.wikipedia.org/wiki/Pneumonoultramicroscopicsilicovolcanoconiosis" style="background-attachment: initial; background-clip: initial; background-color: #f9f9f9; background-image: none; background-origin: initial; color: #0b0080; line-height: 19px; text-decoration: none;" title="Pneumonoultramicroscopicsilicovolcanoconiosis"&gt;&lt;span style="font-family: inherit;"&gt;Pneumonoultramicroscopicsilicovolcanoconiosis&lt;/span&gt;&lt;/a&gt;&amp;nbsp;from being used as whole or part of a password. More ideas on what to block?&lt;a href="http://en.wikipedia.org/wiki/Longest_word"&gt; Look at wikipedia&lt;/a&gt;&amp;nbsp;for long passwords.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;3. Choice of password hash algorithm&lt;/b&gt;&lt;br /&gt;Many sites still does plaintext storage of passwords. In many cases they are easy to discover (password sent to you be plaintext e-mail), but site owners way too often doesn't care at all. IF they do implement some sort of hash algorithm to protect your password, it will probably be something "default", like MD5 without salting. This happens because the techies installing your shiny new website doesn't think but use default configurations. Nobody told them to do otherwise, they are on a strict budget, with strict deadlines. The damage potential of leaked passwords being reused by their customers at other sites probably never struck their minds at all.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;4. Change of password hash algorithm&lt;/b&gt;&lt;br /&gt;We have seen leaks where password hashes has been found to be in different formats. This suggests a change of algorithm has occured at some point in time, but little/no action has been carried out in order to move all users passwords from old (weak?) to new (strong?) algorithm.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;5. Password change frequency&lt;/b&gt;&lt;br /&gt;Directly connected to the change of password hash algorithm, but there are many other aspects to this as well. I'll get back to this in a planned blog post later on.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;u&gt;Summarized:&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;Read the article "&lt;a href="http://www.infoworld.com/t/password-security/dont-blame-users-dumb-passwords-970"&gt;Don't blame users for bad passwords&lt;/a&gt;" by Robert Lemos at for Infoworld. &lt;a href="http://www.troyhunt.com/"&gt;Troy Hunt&lt;/a&gt;, myself and Cormac Herley with Microsoft research. If the hacker's can't crack your password - so what? They've got everything they need after a complete compromise such as #stratfor. I do not believe that #stratfor will be able to keep the hackers out again. Customers are bound to reuse their passwords, eventually just do a +1 update to their passwords - and so the hackers will gain access to multiple accounts again - at least.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8400370148915075091-392382654746133532?l=securitynirvana.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securitynirvana.blogspot.com/feeds/392382654746133532/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://securitynirvana.blogspot.com/2012/01/short-comments-on-stratfor.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/392382654746133532'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/392382654746133532'/><link rel='alternate' type='text/html' href='http://securitynirvana.blogspot.com/2012/01/short-comments-on-stratfor.html' title='Short comments on #STRATFOR'/><author><name>Per Thorsheim</name><uri>https://profiles.google.com/113848325212589987956</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-skpoP167x04/AAAAAAAAAAI/AAAAAAAAAVU/RWc12nir74w/s512-c/photo.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8400370148915075091.post-1957181386743038012</id><published>2011-12-29T23:08:00.001+01:00</published><updated>2011-12-29T23:08:10.274+01:00</updated><title type='text'>Review: [hiddn] USB Crypto Adapter</title><content type='html'>&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-uMnuCN_l7EA/TvzH01Tf3OI/AAAAAAAAAiU/9VSe6OewXmE/s1600/Crypto_med_h_nd_liten21.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="194" src="http://4.bp.blogspot.com/-uMnuCN_l7EA/TvzH01Tf3OI/AAAAAAAAAiU/9VSe6OewXmE/s200/Crypto_med_h_nd_liten21.png" width="200" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;i&gt;[Picture from www.hiddn.no]&lt;/i&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;A representative from &lt;a href="http://www.hiddn.no/"&gt;High Density Devices&lt;/a&gt;&amp;nbsp;(HDD) participated at &lt;a href="http://securitynirvana.blogspot.com/2010/12/videos-and-presentations-now-online.html"&gt;Passwords^10&lt;/a&gt;, and after that I've been talking to them from time to time. Especially their marketing manager Tormod Fjellgård has been very forthcoming, and granted me the chance to do a review of 2 of their crypto adapters. This is my first review of their USB crypto adapter, and I've warned Tormod that I just might have some critical comments for them. So here we go:&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;/div&gt;&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;&lt;div&gt;The adapter comes in a small box, here's a picture of the contents:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-Kv5ulRRCFbU/TvzHMxSAyNI/AAAAAAAAAh0/Jxd7sUtbxp8/s1600/USB_adapter_box_contents.jpg" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="215" src="http://3.bp.blogspot.com/-Kv5ulRRCFbU/TvzHMxSAyNI/AAAAAAAAAh0/Jxd7sUtbxp8/s320/USB_adapter_box_contents.jpg" width="320" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;i&gt;[Sorry for blurring the PIN &amp;amp; PUK codes there.. Bad habit. :-)]&lt;/i&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;Here you can see the crypto adapter itself, USB cable with optional 1xUSB connector for more power, a small paper manual, primary and backup user chip card, a zeroing card and a small piece of paper with PIN, PUK and instructions.&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;For my testing I used my own Windows 7 x64 system, standard USB 2.0 ports, a Kingston DataTraveler G3 8GB usb stick, and a LaCie 250GB external USB2 disk. 8 files of equal size, for a total of 3GB were copied to the external device, with and without using the crypto adapter.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Now I won't do this review plastered with screenshots of performance numbers from PCmark, Atto or other benchmark tools. I'm interested in the &lt;b&gt;security &lt;/b&gt;as well as&amp;nbsp;&lt;b&gt;usability &lt;/b&gt;of the product. Although performance is nice, security can sometimes be of preference over performance. :-)&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;u&gt;First looks:&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;Military grade 90's style. Period. It's big, awkward buttons that you need to press rather hard, and certainly takes up space in any modern ultrabook bag. Simple manual, prints on smartcards clearly states their mission, PIN &amp;amp; PUK printed on the same small piece of paper - in the same box - part of the same shipment... Hmmm. Skeptical.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;&lt;u&gt;Installation:&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;Easy. &amp;lt;1 minute, and you are ready to go. Connect, insert smartcard, type PIN and #, wait a few seconds. Insert Kingston G3, and Windows says a new device has been connected, but needs formatting first. Ok, so I did a &lt;b&gt;quick format&lt;/b&gt;, finishing in a few seconds. Hm. I would say that in order to "securely" format any device, you should always to a "slow" format. Oh well, the data that will be saved with AES encryption, according to HDD.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;&lt;u&gt;Usage:&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;I actually did try running Atto for disk benchmarking. It worked as expected &lt;b&gt;without &lt;/b&gt;the adapter, but &lt;b&gt;with&lt;/b&gt;&amp;nbsp;the adapter &lt;b&gt;the entire test crashed, and I had to reformat the G3. Not good&lt;/b&gt;&amp;nbsp;- I wonder if it is a problem that can be recreated - say if you actually were to move a lot of small files back and forth and you end up with crash/reformat?&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;I also tried connecting the LaCie disk, but no luck. Windows didn't see anything, and the disk didn't spin up. Too low power from the crypto adapters USB port? (Yes, I tried with both usb cables connected to my computer for the extra power...)&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;&lt;u&gt;Performance:&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div&gt;Sorry, but I have to say this... &lt;b&gt;Without the adapter&lt;/b&gt;, I get approximately 11,5MB/second write speed, using my 8 files totalling 3GB. &lt;b&gt;With&lt;/b&gt;&amp;nbsp;the adapter, write speed is down to approximately 7.6MB/second. Not that much in this setting, but my gut feeling says that the adapter doesn't perform much better with faster devices either? In that case I'm all &lt;a href="http://www.truecrypt.org/"&gt;Truecrypt&lt;/a&gt; or Bitlocker, putting my trust into my own passwords.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div class="separator" style="clear: both; text-align: -webkit-auto;"&gt;&lt;b&gt;&lt;u&gt;(Security) Usability:&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: -webkit-auto;"&gt;Where to begin...&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: -webkit-auto;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: -webkit-auto;"&gt;&lt;b&gt;1)&lt;/b&gt; I can't change the 6-digit PIN or the 16-digit PUK.&amp;nbsp;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: -webkit-auto;"&gt;I wonder how HDD&amp;nbsp;generate the PINs and PUKs? Separate &amp;amp; isolated environment, true random generator, no people ever get to see the printed codes etc?&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: -webkit-auto;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: -webkit-auto;"&gt;&lt;b&gt;2)&lt;/b&gt; PIN &amp;amp; PUK printed on the same piece of paper inside the package.&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: -webkit-auto;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: -webkit-auto;"&gt;&lt;b&gt;3)&lt;/b&gt; Backup card, zeroing card, PIN and PUK "must be kept in a secure place". Uh. Yeah, I can do that. But I still need to bring the user card, and what if I forget my PIN or lose my user card while travelling?&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: -webkit-auto;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: -webkit-auto;"&gt;&lt;b&gt;4)&lt;/b&gt; Data encryption bound to chip + PIN. Data cannot be accessed by others without them.&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: -webkit-auto;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: -webkit-auto;"&gt;&lt;b&gt;5)&lt;/b&gt; The chip cards cannot be used for anything else and sticks out - why not just leave it in there permanently? (I've seen cut off chip cards inside card readers many times before)&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: -webkit-auto;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: -webkit-auto;"&gt;&lt;b&gt;6) &lt;/b&gt;Manual isn't really end-user friendly - unless you are a G33k of course.&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: -webkit-auto;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: -webkit-auto;"&gt;The manual says that HDD offers a &lt;b&gt;Key Management System&lt;/b&gt;, delivered as a dedicated workstation. I guess that system is just a bit more expensive than the adapter itself, and not something I would purchase for personal use anyway.&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: -webkit-auto;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: -webkit-auto;"&gt;&lt;b&gt;&lt;u&gt;Summary:&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: -webkit-auto;"&gt;I can hardly see this USB crypto adapter as part of any standard equipment for anyone travelling around with a laptop. It's just too ... bulky.&amp;nbsp;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: -webkit-auto;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: -webkit-auto;"&gt;It's a "single user" product - but why would I use this at home or at the office for myself, when I have Bitlocker, Truecrypt and other similar technologies at hand? The alternatives offer better performance, multi-factor authentication, and at least (non-certified) compliance with a bunch of standards?&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: -webkit-auto;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: -webkit-auto;"&gt;I'm sorry guys. It's a nice idea doing hardware encryption combined with multi-factor authentication, but the wrapping is all wrong. To me this USB adapter is costly, slow &amp;amp; bulky. I can't see how this can give me any better security than other cheaper or even free alternatives available. Go back to square 1 and start over.&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: -webkit-auto;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: -webkit-auto;"&gt;--&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: -webkit-auto;"&gt;&lt;i&gt;Oh; and for the FIPS-140 and Common Criteria / &lt;a href="http://dilbert.com/strips/comic/2007-11-16/"&gt;Mordac&lt;/a&gt; fans out there - &lt;b&gt;this product is for you&lt;/b&gt;. ;-)&lt;/i&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8400370148915075091-1957181386743038012?l=securitynirvana.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securitynirvana.blogspot.com/feeds/1957181386743038012/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://securitynirvana.blogspot.com/2011/12/review-hiddn-usb-crypto-adapter.html#comment-form' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/1957181386743038012'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/1957181386743038012'/><link rel='alternate' type='text/html' href='http://securitynirvana.blogspot.com/2011/12/review-hiddn-usb-crypto-adapter.html' title='Review: [hiddn] USB Crypto Adapter'/><author><name>Per Thorsheim</name><uri>https://profiles.google.com/113848325212589987956</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-skpoP167x04/AAAAAAAAAAI/AAAAAAAAAVU/RWc12nir74w/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-uMnuCN_l7EA/TvzH01Tf3OI/AAAAAAAAAiU/9VSe6OewXmE/s72-c/Crypto_med_h_nd_liten21.png' height='72' width='72'/><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8400370148915075091.post-5205547596714723256</id><published>2011-12-04T22:10:00.000+01:00</published><updated>2011-12-04T22:11:21.153+01:00</updated><title type='text'>Når "anonym" har en arbeidsgiver</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-8xUR22o1808/TteXlokZh_I/AAAAAAAAAeA/puGqEgwfhZ4/s1600/VG_kommentar_header.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/-8xUR22o1808/TteXlokZh_I/AAAAAAAAAeA/puGqEgwfhZ4/s1600/VG_kommentar_header.png" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;i&gt;(Screenshot tatt fra www.vg.no)&lt;/i&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;VG Nett har nylig endret sine regler for å kunne legge inn kommentarer til saker de publiserer. De tillater ikke lengre anononyme innlegg, og forsvarer dette valget gjennom plakaten som vist over. En god kollega av meg, som ønsker å forbli anonym, stilte meg et spørsmål i dag som ga meg grunnlag for å kommentere denne endringen hos VG. Det gjelder nok også en rekke andre medier, så bloggposten er ment å være generell i så måte.&lt;br /&gt;&lt;br /&gt;&lt;a name='more'&gt;&lt;/a&gt;Først av alt vil jeg påstå at jeg har brukt Internett såpass lenge at jeg for lengst har sluttet å tro at jeg kan være anonym på Internett. Graden av anonymitet kan alltids diskuteres, men dersom noen vil spore meg og mine aktiviteter, så lar det seg gjøre i de fleste tilfeller.&lt;br /&gt;&lt;br /&gt;Spørsmålet jeg fikk fra min kollega var hvorvidt bedrifter flest hadde noen policy eller prinsipiell holdning til at ansatte, på jobb eller på egen fritid kommenterer saker hos VG gjennom bruk av sin Facebook profil. Den initielle tanken er jo selvfølgelig at i vårt frie og demokratiske Norge så skal ikke arbeidsgiver legge seg opp i dine private meninger eller ytringer. Ei heller skal arbeidsgiver nekte deg å gjøre dette selv i arbeidstiden, så lenge du gjør jobben din.&lt;br /&gt;&lt;br /&gt;Min kollega kom ikke bare med sitt spørsmål, men også med et skjermbilde fra VGs nettsider. Jeg vil ikke bruke enkeltstående eksempler her, så bildet vil jeg ikke gjengi her. Hele poenget fra min kollega var at en rekke kommentarer inneholder navn og profilbilde fra Facebook, samt &lt;b&gt;arbeidsgivers navn&lt;/b&gt;. Slike kommentarer finnes på mange saker, fra musikkanmeldelser til alvorlige straffesaker.&lt;br /&gt;&lt;br /&gt;Nå er ikke farlige eller ulovlige ytringer på Internett noen ny oppdagelse. Har man levd noen år i vårt digitale samfunn så vet man også at ankomsten av SMS her til lands gjorde sitt til statistikken hos politiet for sjikane og trusselsaker.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Den interessante konsekvensen av VGs endring er at arbeidsgiverne blir synlige.&lt;/b&gt;&amp;nbsp;Veldig synlige faktisk. Et kjapt søk via Google mot VG avslører mange sinte mennesker med harde utsagn, ferdig innlagt med arbeidsgivers navn klistret på. Tidsstemplingen sier sitt i forhold til hvor innlegget ble skrevet også - etter all sannsynlighet i arbeidstiden.&lt;br /&gt;&lt;br /&gt;Nå er det ikke slik at arbeidsgivere skal stilles til ansvar for hva deres ansatte skriver på Internett. Overhodet ikke. Problemet er bare at det er det som skjer. Mer enn en gang har jeg opplevd tilfeller hvor arbeidsgivere blir kontaktet, med spørsmål om de er klar over hva ansatt X hos dem faktisk skriver. Akkurat den typen henvendelser kommer som oftest overraskende på arbeidsgiver, og kan medføre både unødvendig og overilte reaksjoner. Jeg mener at NSR nylig uttalte at de bare venter på den første oppsigelsessaken som skyldes en ansatts uvettige bruk av sosiale kanaler.&lt;br /&gt;&lt;br /&gt;Jeg antar jo her at langt de fleste av oss har oppgitt hvor de jobber, og gjerne også hvor de har jobbet tidligere:&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-1JZJ5humKcE/Ttvgt3hP1RI/AAAAAAAAAeI/HUXwl9IYkic/s1600/FB_profil.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/-1JZJ5humKcE/Ttvgt3hP1RI/AAAAAAAAAeI/HUXwl9IYkic/s1600/FB_profil.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;Når det gjelder VG, så er jeg rimelig sikker på at deres endring vekk fra anonyme kommentarer skyldes et svært enkelt fakta: &lt;b&gt;økonomi&lt;/b&gt;. Mengden irrelevante kommentarer på Internett er overveldende. Legger man til hatefulle, rasistiske og alle andre typer truende kommentarer, så blir det enda verre. Ved å tillate anonyme kommentarer blir det et enormt arbeid å moderere dem - redaktørene må jo ta et visst ansvar for hva som publiseres på deres nettsider.&lt;br /&gt;&lt;br /&gt;Ved å koble kommentarer mot brukerprofiler på Facebook får man frem navn, profilbilde og f.eks. arbeidsgiver tilknyttet kommentarene som legges inn.&lt;b&gt; Uten tvil en bevisst handling fra VG&lt;/b&gt; for å nyttiggjøre seg Internettets iboende evne til å regulere seg selv - og jeg vil tro at VG håper på at dette vil redusere deres behov for å moderere innlegg. Mange vil nok holde litt tilbake på de aller verste ytringene når man tvinges til å stå frem i lyset med navn og annen informasjon om seg selv.&lt;br /&gt;&lt;br /&gt;Til alle arbeidsgivere som har en policy rundt sosiale medier - jeg tror kampen er tapt. Dine ansatte vil ytre seg i åpne rom, og det de sier vil bli koblet mot deg og din virksomhet. Det er lite til ingenting du kan gjøre for å stanse det. Da blir mitt avsluttende spørsmål: &lt;b&gt;hva gjør vi nå?&lt;/b&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8400370148915075091-5205547596714723256?l=securitynirvana.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securitynirvana.blogspot.com/feeds/5205547596714723256/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://securitynirvana.blogspot.com/2011/12/nar-anonym-har-en-arbeidsgiver.html#comment-form' title='5 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/5205547596714723256'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/5205547596714723256'/><link rel='alternate' type='text/html' href='http://securitynirvana.blogspot.com/2011/12/nar-anonym-har-en-arbeidsgiver.html' title='Når &quot;anonym&quot; har en arbeidsgiver'/><author><name>Per Thorsheim</name><uri>https://profiles.google.com/113848325212589987956</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-skpoP167x04/AAAAAAAAAAI/AAAAAAAAAVU/RWc12nir74w/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-8xUR22o1808/TteXlokZh_I/AAAAAAAAAeA/puGqEgwfhZ4/s72-c/VG_kommentar_header.png' height='72' width='72'/><thr:total>5</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8400370148915075091.post-4868274319303000345</id><published>2011-11-30T23:37:00.001+01:00</published><updated>2011-11-30T23:39:42.544+01:00</updated><title type='text'>I'm not dead...</title><content type='html'>As you can probably see from my Twitter feed. I'm just drowning in work as a security consultant at the moment. My head is full with blog posts that I have to get out soon... For the password stuff, which still is my primary focus here, I'm pretty close to start releasing some never seen before statistics. In close cooperation with my friend and colleague Jan Fredrik (@KluZz). Keep watching this space!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8400370148915075091-4868274319303000345?l=securitynirvana.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securitynirvana.blogspot.com/feeds/4868274319303000345/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://securitynirvana.blogspot.com/2011/11/im-not-dead.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/4868274319303000345'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/4868274319303000345'/><link rel='alternate' type='text/html' href='http://securitynirvana.blogspot.com/2011/11/im-not-dead.html' title='I&apos;m not dead...'/><author><name>Per Thorsheim</name><uri>https://profiles.google.com/113848325212589987956</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-skpoP167x04/AAAAAAAAAAI/AAAAAAAAAVU/RWc12nir74w/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8400370148915075091.post-3689093888367219408</id><published>2011-11-14T21:26:00.001+01:00</published><updated>2011-11-14T22:21:36.970+01:00</updated><title type='text'>Hotel TV Infochannel Security</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-iwLz90sDwLU/TsF5vZP6BGI/AAAAAAAAAds/KKNczMB_gqk/s1600/Comfort_Hotel_Stavanger_10.11.2011.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="356" src="http://2.bp.blogspot.com/-iwLz90sDwLU/TsF5vZP6BGI/AAAAAAAAAds/KKNczMB_gqk/s640/Comfort_Hotel_Stavanger_10.11.2011.jpg" width="640" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;i&gt;[A rather static show at the hotel tv infochannel...]&lt;/i&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;Life as a security advisor, or just consultant if you prefer, can be very interesting. Working with a large variety of clients, tasks and situations is challenging, exactly the way I like it! To me it also includes going to other cities here in Norway, at the moment I'm at yet another hotel in &lt;a href="http://maps.google.com/maps?q=stavanger&amp;amp;hl=no&amp;amp;sll=37.0625,-95.677068&amp;amp;sspn=46.677964,107.138672&amp;amp;vpsrc=0&amp;amp;hnear=Stavanger,+Rogaland,+Norge&amp;amp;t=m&amp;amp;z=12"&gt;Stavanger&lt;/a&gt;, Norway.&amp;nbsp;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;During the past couple of weeks I've got a renewed interested in hotel television systems. No, not that kind of activity that you may have heard of, or seen demonstrated by &lt;a href="http://www.wired.com/politics/security/news/2005/07/68370"&gt;Major Malfunction&lt;/a&gt;&amp;nbsp;in Las Vegas many years ago. I'm just curious about the risk analysis - if any - performed by the hotels, finding it acceptable to put their infochannel systems directly onto the Internet?&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;/div&gt;&lt;a name='more'&gt;&lt;/a&gt;The picture on top of this blog post was taken from &lt;a href="http://maps.google.no/maps/place?q=comfort+hotel+stavanger&amp;amp;hl=no&amp;amp;cid=5724024312996613034"&gt;Comfort Hotel Stavanger&lt;/a&gt; on Nov 10, 2011. Obviously, this system is connected to the Internet, running Windows 7, Adobe Flash, Logmein, Smartsign Player 7 and some HP support software on an HP system. No presentation were running in the background, with HP, Adobe Flash and Windows *begging* for security updates to be installed and reboot the system in order to reboot. Please also note that there doesn't seem to be any antivirus software running, at least from the series of icons present in the lower right. Even my mother knows by now that's a stupid thing to do.&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;--&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;Moving forward to where I'm right now (Nov 14, 2011); at &lt;span id="goog_1781030861"&gt;&lt;/span&gt;&lt;a href="http://maps.google.no/maps/place?q=Park+Inn+Stavanger,+Lag%C3%A5rdsveien,+Stavanger&amp;amp;hl=no&amp;amp;ie=UTF8&amp;amp;cid=14922846320737852815"&gt;Park Inn Hotel (by Radisson) Stavanger&lt;/a&gt;&lt;span id="goog_1781030862"&gt;&lt;/span&gt;. Came into the reception, and was pleasantly surprised to get a room almost at the top. "One of the refurbished rooms of this autumn" I was told. Excellent.&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;Got to my room, turned on the lights, and... WOW:&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-SQ2H0JxGDsg/TsF5rWoLvNI/AAAAAAAAAdY/uEe4SU489Hk/s1600/2011-11-14+18.23.36.jpg" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="400" src="http://2.bp.blogspot.com/-SQ2H0JxGDsg/TsF5rWoLvNI/AAAAAAAAAdY/uEe4SU489Hk/s400/2011-11-14+18.23.36.jpg" width="210" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;[Deluxe Philips/Otrum Retro Design 20" CRT television!]&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;Yeah, well, at least there's the parquet floors, as promised in the reception. Time to watch the news, turning the thing on usually gets you right to the hotel infochannel at channel #1:&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-ZbN9XHEpl7U/TsF5q-GW7CI/AAAAAAAAAdU/54gwJb6zxd4/s1600/2011-11-14+16.50.32.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="300" src="http://2.bp.blogspot.com/-ZbN9XHEpl7U/TsF5q-GW7CI/AAAAAAAAAdU/54gwJb6zxd4/s400/2011-11-14+16.50.32.jpg" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Windows XP at VERY low resolution, and nagging about it. More interesting? Norman Antivirus is running, but complaining about missing updates. There's also a VNC icon there... Hm.... Oh, and a License Wizard wants to say something as well.&amp;nbsp;Fabulous!&lt;br /&gt;&lt;br /&gt;Or perhaps I should just a post a picture taken with my Samsung Galaxy S2, to summarize everything with their own words:&lt;br /&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-nKCHU6VWvCQ/TsF5ow11oXI/AAAAAAAAAdM/fLeEHdUcONE/s1600/2011-11-14+16.49.00.jpg" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="300" src="http://2.bp.blogspot.com/-nKCHU6VWvCQ/TsF5ow11oXI/AAAAAAAAAdM/fLeEHdUcONE/s400/2011-11-14+16.49.00.jpg" width="400" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;i&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;["The essence of a great hotel experience".&amp;nbsp;&lt;b&gt;Love it!&lt;/b&gt;]&lt;/span&gt;&lt;/i&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&amp;nbsp;I'm pretty sure there doesn't exist any risk analysis at these hotels whatsoever, concerning the installation, configuration and maintenance of these infochannel systems. Furthermore I fully believe that they have never even&amp;nbsp;considered&amp;nbsp;the reputation consequences of pr0n rolling over their infochannel, in the middle of conservative country here in Stavanger. As far as I can remember, people didn't complain after Major Malfunction displayed "pr0n wants to be free!" on all room tvs at his hotel in Vegas many years ago.&lt;br /&gt;--&lt;br /&gt;As we like to say here in Norway; any media coverage is good coverage?&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8400370148915075091-3689093888367219408?l=securitynirvana.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securitynirvana.blogspot.com/feeds/3689093888367219408/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://securitynirvana.blogspot.com/2011/11/hotel-tv-infochannel-security.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/3689093888367219408'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/3689093888367219408'/><link rel='alternate' type='text/html' href='http://securitynirvana.blogspot.com/2011/11/hotel-tv-infochannel-security.html' title='Hotel TV Infochannel Security'/><author><name>Per Thorsheim</name><uri>https://profiles.google.com/113848325212589987956</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-skpoP167x04/AAAAAAAAAAI/AAAAAAAAAVU/RWc12nir74w/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-iwLz90sDwLU/TsF5vZP6BGI/AAAAAAAAAds/KKNczMB_gqk/s72-c/Comfort_Hotel_Stavanger_10.11.2011.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8400370148915075091.post-6235682841075233805</id><published>2011-11-10T20:51:00.000+01:00</published><updated>2011-11-10T20:51:06.408+01:00</updated><title type='text'>Kjære kunde / Dear Customer</title><content type='html'>This one is for @Questback, as a reply after the last couple of tweets between myself (@thorsheim), and @HopeMears, partially also @Ronnie_Ostgaard. Both have been most helpful in replying to my blog posts and tweets, and I hope this will be my last blog post regarding our "controversies". :-)&lt;br /&gt;&lt;br /&gt;&lt;a name='more'&gt;&lt;/a&gt;&lt;b&gt;Kjære kunde,&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;Dette er for å informere deg om at Questback den xx.yy.zz vil gjøre en forbedring av sikkerheten for alle eksisterende avtaler. Dette brevet inneholder viktig informasjon til deg som kunde, og gir deg muligheten til å stanse denne endringen dersom den ikke er ønskelig. Merk at endringen er kostnadsfri for deg som kunde.&lt;br /&gt;&lt;br /&gt;Questback har innført bruk av &lt;b&gt;HTTPS&lt;/b&gt; som standard for våre undersøkelser. Dette betyr at alle undersøkelser blir utført av sluttbruker via en kryptert forbindelse, som også er standard for bruk ved &lt;b&gt;sikker innlogging&lt;/b&gt; og elektronisk betaling på Internett.&lt;br /&gt;&lt;br /&gt;Dette gir &lt;b&gt;økt sikkerhet&lt;/b&gt; både for sluttbruker og for deg som kunde, da det reduserer sannsynligheten for uautorisert avlytting eller manipulering av undersøkelser. Det gir&lt;b&gt; økt personvern&lt;/b&gt;, og vi har også indikasjoner på at dette bidrar til å &lt;b&gt;øke svarprosenten&lt;/b&gt; i gjennomføringen av undersøkelser.&lt;br /&gt;&lt;br /&gt;I praksis vil sluttbrukere nå få en link som begynner med HTTPS, istedenfor tidligere HTTP. Dette medfører &lt;b&gt;ingen endring i brukervennlighet&lt;/b&gt; eller prosedyre for å gjennomføre undersøkelser på noen måte.&lt;br /&gt;&lt;br /&gt;Dersom du skulle ha spørsmål om denne endringen så kan du ta kontakt med navn1, navn2 eller navn3. Vi ser frem til et fortsatt godt og trygt samarbeid om markedets sikreste løsning for spørreundersøkelser.&lt;br /&gt;&lt;br /&gt;--&lt;br /&gt;Dear customer,&lt;br /&gt;&lt;i&gt;... argh. use Google translate. It's just marketing talk in Norwegian.&lt;/i&gt;&lt;br /&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;br /&gt;-----&lt;br /&gt;&lt;br /&gt;For @Ronnie_Ostgaard and @HopeMears at @Questback:&lt;br /&gt;Thank you for your replies and follow-ups. My employer is a paying customer, at least for easyresearch. I don't get the periodically news &amp;amp; tips e-mails from you, so I don't know if you have put out the recommend info on turning on HTTPS (SSL encryption) in your latest info. Although a good idea, I do not believe all recipients will read, understand or implement your suggestions given there.&lt;br /&gt;&lt;br /&gt;That's why I wrote the above for you, to make it *dead simple* to make a marketing pitch out of improving your default security for agreements already running. I hope and believe that you can easily script something that will turn on HTTPS for all existing agreements, and with the above electronic letter, you really shouldn't run into much negative feedback either.&lt;br /&gt;&lt;br /&gt;Do this, and I promise I won't bother you anymore - until I find something else to complain about. ;-)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8400370148915075091-6235682841075233805?l=securitynirvana.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securitynirvana.blogspot.com/feeds/6235682841075233805/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://securitynirvana.blogspot.com/2011/11/kjre-kunde-dear-customer.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/6235682841075233805'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/6235682841075233805'/><link rel='alternate' type='text/html' href='http://securitynirvana.blogspot.com/2011/11/kjre-kunde-dear-customer.html' title='Kjære kunde / Dear Customer'/><author><name>Per Thorsheim</name><uri>https://profiles.google.com/113848325212589987956</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-skpoP167x04/AAAAAAAAAAI/AAAAAAAAAVU/RWc12nir74w/s512-c/photo.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8400370148915075091.post-2319892163399912826</id><published>2011-10-21T11:57:00.001+02:00</published><updated>2011-10-21T12:47:20.616+02:00</updated><title type='text'>Adgangskort og PIN koder</title><content type='html'>&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-Evy5hNc9jbg/TqEZxm9FXhI/AAAAAAAAAa0/ZG1pEvDVAXk/s1600/PostIT-pins.jpg" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="174" src="http://3.bp.blogspot.com/-Evy5hNc9jbg/TqEZxm9FXhI/AAAAAAAAAa0/ZG1pEvDVAXk/s200/PostIT-pins.jpg" width="200" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;[PINs på Post-it.&lt;i&gt; Er det noe problem?&lt;/i&gt;]&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;Denne bloggposten skrives etter veldig mange års frustrasjon med fysisk adgangskontroll. Bildet over bør være god nok forklaring på min frustrasjon, det er Post-it lapper jeg har fått utlevert sammen med ulike typer adgangskort, både magnetstripe og RFID baserte kort. Med et ønske om å bidra med "enkle sikkerhetstips i hverdagen", så har jeg noen spørsmål og tips rundt slike løsninger for adgangskontroll.&lt;br /&gt;&lt;br /&gt;&lt;a name='more'&gt;&lt;/a&gt;Jeg tror på &lt;b&gt;forenkling av sikkerhet.&lt;/b&gt;&amp;nbsp;Forstå meg rett; jeg vil &lt;b&gt;forenkle&lt;/b&gt;&amp;nbsp;sikkerheten, slik at det blir &lt;b&gt;enklere for oss alle&lt;/b&gt;&amp;nbsp;å overholde faktiske sikkerhetskrav. På den måten tror jeg at &lt;b&gt;sikkerheten&lt;/b&gt; &lt;b&gt;vil forbedres.&lt;/b&gt;&lt;br /&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;br /&gt;Jeg har hatt denne bloggposten i hodet i mange år, og dagens lille "æddabædda" nyhet om &lt;a href="http://sikkert.no/"&gt;sikkert.no&lt;/a&gt;, som rapportert i &lt;a href="http://www.tu.no/it/article292661.ece"&gt;Teknisk Ukeblad&lt;/a&gt;, fikk meg til å skrive litt. Denne nyheten om sikkert.no i seg selv fortjener gjentakelsen av noen enkle anbefalinger:&lt;br /&gt;&lt;br /&gt;1. &lt;b&gt;Still skriftlige sikkerhetskrav til leverandøren din&lt;/b&gt;, inkludert din rett til å foreta kontroller.&lt;br /&gt;2. Kontroller at krav er oppfylt FØR løsninger settes i produksjon.&lt;br /&gt;3. Kontroller selv, eller via tredjepart, at leverandøren overholder kravene jevnlig.&lt;br /&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;br /&gt;&lt;b&gt;Uansett, tilbake til adgangskontrollen.&lt;/b&gt; Det jeg har opplevd utallige ganger, er blant annet følgende:&lt;br /&gt;&lt;br /&gt;&lt;b&gt;1. Adgangskort utleveres sammen med 4-sifret PIN kode på en lapp&lt;/b&gt;&lt;br /&gt;Det gjelder både ved utlevering av vanlige adgangskort, samt besøkskort av ymse slag. I enda verre tilfeller, så er PIN kodet faktisk trykket på kortet, eller klistret på, slik dette bildet viser:&lt;br /&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;br /&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-W56-TX7olLQ/TqEpSQdFqTI/AAAAAAAAAa8/BM3w2V-DYBk/s1600/IMAG0106.jpg" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="191" src="http://3.bp.blogspot.com/-W56-TX7olLQ/TqEpSQdFqTI/AAAAAAAAAa8/BM3w2V-DYBk/s320/IMAG0106.jpg" width="320" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;i&gt;[Adgangskort fra et hotell i Norge. Her har du ALT du trenger...]&lt;/i&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;b&gt;2. Jeg blir sjelden - nesten aldri - spurt om å velge PIN selv&lt;/b&gt;&lt;/div&gt;Det kan jo forsåvidt være fornuftig, tenk på koden du får tilsendt i posten (...), til VISA kortet og de øvrige kredittkortene du har. Hadde nå bare disse resepsjonistene og vekterne delt ut tilfeldige PIN koder i lukket konvolutt eller noe slikt, men du får nok 1234, 0000 eller 2011 tildelt som din PIN kode.&lt;br /&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;br /&gt;&lt;b&gt;3. Får jeg velge selv, så må jeg skrive ønsket kode på en lapp og gi den til adgangskontrollen&lt;/b&gt;&lt;br /&gt;At sikkerhetspolicy i stort sett alt av selskaper og organisasjoner sier at du aldri skal oppgi ditt passord eller PIN kode til andre virker å være totalt neglisjert i enhver resepsjon og vekterfirma.&lt;br /&gt;&lt;br /&gt;Kunne de ikke bare hatt &lt;a href="http://www.komplett.no/k/ki.aspx?sku=581446"&gt;en ekstern keypad&lt;/a&gt; på resepsjonsdisken?&lt;br /&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;br /&gt;&lt;b&gt;4. På spørsmål om hvor mange forsøk jeg har før kortet sperres, så er svaret "Æhhh...."&lt;/b&gt;&lt;br /&gt;Sannheten er at jeg aldri har opplevd noe sted som har en max begrensning på antall forsøk. Selv jeg, som feilet i matte valgfag i tredje på videregående, vet at det er 10,000 kombinasjoner å prøve. Med 5 sekunder pr PIN, mat &amp;amp; pissepause, så har du testet dem før det er gått 15 timer. Fin helgeaktivitet med andre ord.&lt;br /&gt;&lt;br /&gt;På passordsiden opererer man normalt med max antall forsøk før konto blir sperret i &lt;i&gt;N &lt;/i&gt;sekunder/minutter/timer, om ikke permanent til kontoen blir åpnet igjen manuelt. Ikke bare det, men for store nettsteder på Internett har man også for lengst innført &lt;i&gt;rate limiting&lt;/i&gt;, dvs en eskalerende tidsforsinkelse mellom hvert feilede forsøk. Dette gir en mer fornuftig og ikke minst mer kostnadseffektiv håndtering av eksterne passordangrep, og reduserer behovet for 24x7 helpdesk som kan åpne kontoer manuelt og så videre.&lt;br /&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;br /&gt;&lt;b&gt;5. Ved glemt PIN kode, så får jeg utlevert min kode på lapp eller muntlig&lt;/b&gt;&lt;br /&gt;Gå direkte videre til pkt 6:&lt;br /&gt;&lt;br /&gt;&lt;b&gt;6. Kan resepsjonist/vekter se min PIN kode?&lt;/b&gt;&lt;br /&gt;&lt;b&gt;JA. &lt;/b&gt;Helt spesifikt har jeg utallige ganger sett at løsninger fra &lt;a href="http://www.securitas.com/no/no/Tjenester/Resepsjonstjeneste/"&gt;&lt;b&gt;Securitas&lt;/b&gt;&lt;/a&gt;&amp;nbsp;for fysisk adgangskontroll enten viser PIN kode på skjerm direkte, eller maskert (&lt;b&gt;****&lt;/b&gt;). Imidlertid har lokal operatør selv mulighet til å fjerne denne maskeringen. Det er ikke meningen å "henge ut" Securitas mer enn noen andre, men nå er det engang sånn at det er de jeg har absolutt førstehåndskjennskap til. Hva har du å tilby &lt;a href="http://twitter.com/#!/tabalizer"&gt;@tabalizer&lt;/a&gt;? :-)&lt;br /&gt;&lt;br /&gt;&lt;b&gt;7. Tvunget/regelmessig skifte av PIN kode på adgangskort?&lt;/b&gt;&lt;br /&gt;PIN er passord. Passord skal skiftes regelmessig. Passord skal skiftes umiddelbart etter at du har fått nytt (glemt passord), eller første gang du får tildelt en konto. Skjer tilsvarende for adgangskort? Gjett &lt;b&gt;EN &lt;/b&gt;gang.&lt;br /&gt;&lt;br /&gt;At man ikke vil skifte PIN regelmessig på adgangskort kan jeg ha forståelse for. Det ville gjort hverdagen enda vanskeligere for oss alle&lt;b&gt;. &lt;/b&gt;Imidlertid sliter jeg med å se at kompenserende tiltak er på plass for å tillate oss denne luksusen, jfr punktene over, og og jeg har enda ikke sett en skriflig risikoanalyse eller aksept for avvik i adgangskontrollen i forhold til gjeldende sikkerhetspolicy.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;8. "...adgangskort skal bæres synlig..."&lt;/b&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;Kravet finnes i nesten alle sikkerhetspolicyer i det vidstrakte land. Men... øh....:&lt;br /&gt;&lt;br /&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-X692b4pC4d0/TqE5Xkec3iI/AAAAAAAAAbM/GyqRT_3VL1E/s1600/Ser_du_likheten.jpg" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="320" src="http://1.bp.blogspot.com/-X692b4pC4d0/TqE5Xkec3iI/AAAAAAAAAbM/GyqRT_3VL1E/s320/Ser_du_likheten.jpg" width="240" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;i&gt;[Bruker og adgangskort. Ser du likheten?]&lt;/i&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;Sannheten er at policykravet eksisterer de fleste steder, samtidig som noen med økonomisk forståelse har funnet ut at dersom man dropper store adgangskort med fargetrykk og istedenfor bruker &lt;i&gt;RFID &lt;/i&gt;brikker, så blir kostnadene lavere. Evne til å se forbi nesetippen ser også ut til å reduseres kraftig, men det er ofte irrelevant for kvartals- og årsbudsjettet. De som er ansvarlige for valg av adgangskontrollsystemer bør blafre seg gjennom de nyeste &lt;a href="http://www.amazon.co.uk/gp/search/ref=sr_nr_p_n_binding_browse-b_mrr_0?rh=k%3Akevin+mitnick%2Cn%3A266239%2Cp_n_binding_browse-bin%3A492563011&amp;amp;bbn=266239&amp;amp;keywords=kevin+mitnick&amp;amp;ie=UTF8&amp;amp;qid=1319190124&amp;amp;rnid=492562011"&gt;bøkene til Kevin Mitnick&lt;/a&gt;&amp;nbsp;før de tar flere beslutninger.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;En liten utfordring til NSM, NorSIS og leverandører av adgangskontrollsystemer og resepsjons/vektertjenester her i landet:&lt;/b&gt;&lt;br /&gt;Hører gjerne fra dere i forhold til kost/nytte og risikoanalyser foretatt, som forsvarer ett eller flere av de punkter som beskrevet over. Jeg har ikke sett noe slikt foreløpig.&lt;br /&gt;&lt;br /&gt;Så helt til slutt, siden det er fredag og man gjerne spøker litt før man tar helg: la oss returnere til bildet av Post-it lappene på toppen av bloggposten her.&lt;br /&gt;&lt;br /&gt;3M har lansert "&lt;a href="http://www.post-it.com/wps/portal/3M/en_US/Post_It/Global/Offers/PopNotes/"&gt;Post-it Popnotes&lt;/a&gt;" som gratis app for iPhone og iPad, kommer også for Android og Windows Phone. Foreløpig bare i USA, men appen kommer nok hit også. Ta en kikk på beskrivelsen; du kan lage "Post-it" lapper med geotagging, og gjøre dem offentlig tilgjengelig slik at du kan få frem alle "lapper" postet innen en radius på 500 yards, altså ca 450 meter. Skal vi poste en lapp på hvert sted hvor ovenstående punkter blir observert, og se hvordan Norgeskartet blir seende ut etter en måned eller to?&lt;br /&gt;&lt;br /&gt;Ha en riktig god helg!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8400370148915075091-2319892163399912826?l=securitynirvana.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securitynirvana.blogspot.com/feeds/2319892163399912826/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://securitynirvana.blogspot.com/2011/10/adgangskort-og-pin-koder.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/2319892163399912826'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/2319892163399912826'/><link rel='alternate' type='text/html' href='http://securitynirvana.blogspot.com/2011/10/adgangskort-og-pin-koder.html' title='Adgangskort og PIN koder'/><author><name>Per Thorsheim</name><uri>https://profiles.google.com/113848325212589987956</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-skpoP167x04/AAAAAAAAAAI/AAAAAAAAAVU/RWc12nir74w/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-Evy5hNc9jbg/TqEZxm9FXhI/AAAAAAAAAa0/ZG1pEvDVAXk/s72-c/PostIT-pins.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8400370148915075091.post-3917766991257717527</id><published>2011-10-18T23:02:00.001+02:00</published><updated>2011-10-18T23:02:17.975+02:00</updated><title type='text'>More STARTTLS support!</title><content type='html'>&lt;br /&gt;&lt;pre style="white-space: pre-wrap; word-wrap: break-word;"&gt;&lt;span class="Apple-style-span" style="font-family: 'Times New Roman'; white-space: normal;"&gt;&lt;pre style="white-space: pre-wrap; word-wrap: break-word;"&gt;&lt;div style="text-align: center;"&gt;&lt;br /&gt;&lt;b&gt;RFC 3207:&lt;/b&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;br /&gt;&lt;b&gt;SMTP Service Extension for&lt;/b&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;br /&gt;&lt;b&gt;Secure SMTP over Transport Layer Security&lt;/b&gt;&lt;/div&gt;&lt;br /&gt;&lt;/pre&gt;&lt;/span&gt;&lt;/pre&gt;&lt;pre style="white-space: pre-wrap; word-wrap: break-word;"&gt;&lt;br /&gt;&lt;/pre&gt;&lt;pre style="white-space: pre-wrap; word-wrap: break-word;"&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;In a previous blog post entitled "&lt;a href="http://securitynirvana.blogspot.com/2010/09/starttls-support-in-hotmailgmail.html"&gt;STARTTLS support in Hotmail/Gmail&lt;/a&gt;", I requested these services to implement support for RFC 3207, in order to use automatic and transparent security at the "back side" of their services, when available. I doubt I'm the reason here, but Google now has support in place! &lt;i&gt;&lt;b&gt;(Hooray!)&lt;/b&gt;&lt;/i&gt;&lt;/span&gt;&lt;/pre&gt;&lt;pre style="white-space: pre-wrap; word-wrap: break-word;"&gt;&lt;a name='more'&gt;&lt;/a&gt;&lt;/pre&gt;&lt;pre style="white-space: pre-wrap; word-wrap: break-word;"&gt;&lt;span class="Apple-style-span" style="font-family: Arial, Helvetica, sans-serif;"&gt;The blog post referred to here also has a link to the survey conducted by my friend and colleague Jan Fredrik Leversund (@KluZz) and myself, regarding the use of STARTTLS across mailservers on the Internet. &lt;a href="http://www.edb.com/no/Konsern/Aktuelt/Aktuelt/Taushetsbelagt-informasjon-sendes-ukryptert-via-e-post-i-Norge/"&gt;You can still find it here&lt;/a&gt;, although still only in Norwegian...&lt;/span&gt;&lt;/pre&gt;&lt;pre style="white-space: pre-wrap; word-wrap: break-word;"&gt;&lt;br /&gt;&lt;/pre&gt;&lt;pre style="white-space: pre-wrap; word-wrap: break-word;"&gt;&lt;b&gt;Proof #1: sending an e-mail from my work account to my Gmail account, then looking at the e-mail header of the mail received at Gmail:&lt;/b&gt;&lt;/pre&gt;&lt;pre style="white-space: pre-wrap; word-wrap: break-word;"&gt;Received: from Mail17.edb.com (mail17.edb.com. [212.18.128.233])&lt;/pre&gt;&lt;pre style="white-space: pre-wrap; word-wrap: break-word;"&gt;        by mx.google.com with &lt;b&gt;ESMTPS&lt;/b&gt; id r11si2077637bkd.114.2011.10.18.12.26.22&lt;br /&gt;        (&lt;b&gt;version=TLSv1/SSLv3 cipher=OTHER&lt;/b&gt;);&lt;br /&gt;        Tue, 18 Oct 2011 12:26:22 -0700 (PDT)&lt;/pre&gt;&lt;pre style="white-space: pre-wrap; word-wrap: break-word;"&gt;&lt;br /&gt;&lt;/pre&gt;&lt;pre style="white-space: pre-wrap; word-wrap: break-word;"&gt;&lt;b&gt;Proof #2: Replying from Gmail back to my work account:&lt;/b&gt;&lt;/pre&gt;&lt;pre style="word-wrap: break-word;"&gt;&lt;span class="Apple-style-span" style="white-space: pre-wrap;"&gt;Received: from mail-ww0-f44.google.com ([74.125.82.44])  by Mail34.edb.com&lt;br /&gt; with &lt;b&gt;ESMTP/TLS/RC4-SHA&lt;/b&gt;; 18 Oct 2011 21:29:53 +0200&lt;/span&gt;&lt;span class="Apple-style-span" style="white-space: pre-wrap;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/pre&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;*NICE*&lt;/b&gt;. Thanks Google!&lt;/div&gt;&lt;div&gt;&lt;b&gt;-------------------&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;Going&lt;/span&gt; further back in time, I've also pointed a finger at&lt;a href="http://securitynirvana.blogspot.com/2010/09/thanks-to-isaca-still-room-for.html"&gt; ISACA and Lyris Inc&lt;/a&gt;, recommending them to improve their security.&amp;nbsp;I am now happy to see that&lt;a href="http://www.isaca.org/"&gt; ISACA&lt;/a&gt; and &lt;a href="http://www.lyris.com/"&gt;Lyris&lt;/a&gt; now supports the STARTTLS command through SMTP connections, which is proof of RFC 3207 support. While I was at it, I checked&lt;a href="http://www.isc2.org/"&gt; (ISC)2&lt;/a&gt; and&lt;a href="http://www.asisonline.org/"&gt; ASIS&lt;/a&gt; as well.Yup, they've got STARTTLS available as well. As a member of ISACA, (ISC2)2 and ASIS, this makes me a little bit happier. &lt;i&gt;Do as you preach.&lt;/i&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Oh... and &lt;b&gt;Microsoft&lt;/b&gt;, with their Hotmail service? Still no support for RFC 3207. &lt;b&gt;Come on guys!&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="font-weight: normal;"&gt;&lt;b&gt;-------------------&lt;/b&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="font-weight: normal;"&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div&gt;And now for Ivan Ristic at Qualys (SSLlabs); I've e-mailed you, look forward to any positive news you might have! :-)&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8400370148915075091-3917766991257717527?l=securitynirvana.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securitynirvana.blogspot.com/feeds/3917766991257717527/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://securitynirvana.blogspot.com/2011/10/more-starttls-support.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/3917766991257717527'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/3917766991257717527'/><link rel='alternate' type='text/html' href='http://securitynirvana.blogspot.com/2011/10/more-starttls-support.html' title='More STARTTLS support!'/><author><name>Per Thorsheim</name><uri>https://profiles.google.com/113848325212589987956</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-skpoP167x04/AAAAAAAAAAI/AAAAAAAAAVU/RWc12nir74w/s512-c/photo.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8400370148915075091.post-3001761327767588489</id><published>2011-10-14T10:45:00.000+02:00</published><updated>2011-10-14T10:45:15.381+02:00</updated><title type='text'>Facebook password history...</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-f1o4gBxMoYg/Tpf0zsyM6hI/AAAAAAAAAak/UMIHp4zW1FY/s1600/FB-password-history-reminder.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/-f1o4gBxMoYg/Tpf0zsyM6hI/AAAAAAAAAak/UMIHp4zW1FY/s1600/FB-password-history-reminder.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;"Unfortunately you have provided an old password. Your password was last changed yesterday at 07:52. If you don't remember making this change, please click here".&lt;br /&gt;&lt;br /&gt;First thought: WTF does Facebook tell me this????&lt;br /&gt;&lt;br /&gt;Second thought: Good, they seem to have some password history going on. Got to test that later on, by trying to change back to my old password. I guess they don't block that quite yet.&lt;br /&gt;&lt;br /&gt;Third thought: This is good from a usability perspective. They've got quite a few users (...), this will make it easier for them to actually change their passwords whenever they feel the need to do so, and handle it afterwards.&lt;br /&gt;&lt;br /&gt;Fourth thought: A bruteforce attack against known logins will eventually succeed, but it may also reveal one or more previously used passwords, enabling several methods of pattern-based password analysis to improve the chances of an attacker figuring out the correct password faster and with less attempts then from a blind start.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Not good.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Any opinions?&lt;/b&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8400370148915075091-3001761327767588489?l=securitynirvana.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securitynirvana.blogspot.com/feeds/3001761327767588489/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://securitynirvana.blogspot.com/2011/10/facebook-password-history.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/3001761327767588489'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/3001761327767588489'/><link rel='alternate' type='text/html' href='http://securitynirvana.blogspot.com/2011/10/facebook-password-history.html' title='Facebook password history...'/><author><name>Per Thorsheim</name><uri>https://profiles.google.com/113848325212589987956</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-skpoP167x04/AAAAAAAAAAI/AAAAAAAAAVU/RWc12nir74w/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-f1o4gBxMoYg/Tpf0zsyM6hI/AAAAAAAAAak/UMIHp4zW1FY/s72-c/FB-password-history-reminder.png' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8400370148915075091.post-661584851149678926</id><published>2011-10-11T21:51:00.002+02:00</published><updated>2011-10-11T21:51:14.152+02:00</updated><title type='text'>En ROSA bloggpost!</title><content type='html'>&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-pX3PESru8AU/TpSMzP7ZPbI/AAAAAAAAAaA/5i6w9A9t478/s1600/2011-10-11+15.00.47.jpg" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="200" src="http://1.bp.blogspot.com/-pX3PESru8AU/TpSMzP7ZPbI/AAAAAAAAAaA/5i6w9A9t478/s200/2011-10-11+15.00.47.jpg" width="149" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;i&gt;[Bilde fra &lt;a href="http://www.wahwah.no/"&gt;WahWah&lt;/a&gt; brosjyre]&lt;/i&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;b&gt;Jeg er gammeldags.&lt;/b&gt; &lt;i&gt;Jeg har passert 40.&lt;/i&gt; Jeg har en tåpelig tendens til å ta i mot utfordringer fra jenter. &lt;a href="http://chrispy.blogg.no/"&gt;Kristin&lt;/a&gt;&amp;nbsp;er en av dem. Utfordringen kom for noen måneder siden; hun utfordret meg til å skrive et blogginnlegg om mote &amp;amp; skjønnhet og sånn. Jeg svarte at det var liksom ikke helt min greie, men dersom jeg gjorde det så måtte hun kvittere med en bloggpost om sikkerhet &amp;amp; sånn. Jeg gleder meg allerede! ;-)&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;/div&gt;&lt;a name='more'&gt;&lt;/a&gt;Så jeg ble altså 40 år den 10 september. Stor fest, og mye morro på selve dagen. Kortversjonen oppsummeres slik, uten å nevne noen navn.. :-)&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-5uIAhPGgLLY/TpSO1SUahCI/AAAAAAAAAaU/bup_ir9DXyo/s1600/IMG_3577.jpg" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="213" src="http://4.bp.blogspot.com/-5uIAhPGgLLY/TpSO1SUahCI/AAAAAAAAAaU/bup_ir9DXyo/s320/IMG_3577.jpg" width="320" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;i&gt;[Happy birthday to me!]&lt;/i&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;Som vanlig hadde jeg forsøkt å gi noen hint om at elektronikk alltid står på ønskelisten. Tradisjonen tro er det nok noe av det siste familien vil gi meg, de vet hvordan jeg prioriterer penger uansett. Om et rykte har spredd seg vites ei, men det dukket opp blant annet følgende i en fantastisk bunke med gaver:&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-MCBHjU9jwBQ/TpSMyzVn9OI/AAAAAAAAAZ4/n-WgfFGvX3s/s1600/2011-10-11+15.00.26.jpg" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="228" src="http://4.bp.blogspot.com/-MCBHjU9jwBQ/TpSMyzVn9OI/AAAAAAAAAZ4/n-WgfFGvX3s/s320/2011-10-11+15.00.26.jpg" width="320" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;i&gt;[Gavekort fra WahWah]&lt;/i&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;Noen mente nok at jeg kunne ha godt av det, og sant skal sies; kvinner til stede på festen sukket mer enn en gang da de hørte de magiske ordene "Gavekort fra WahWah!". Mulig de fikk samme følelsen som jeg får når noen sier "OCZ Revodrive 3 X2" til meg altså. :-D&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;Første gavekort var på en "007" ansiktsbehandling. Resultatet:&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-NBNDICnu7to/TpSZ57J9BuI/AAAAAAAAAac/ITXPR7Lojwk/s1600/Trynefaktor.jpg" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="320" src="http://3.bp.blogspot.com/-NBNDICnu7to/TpSZ57J9BuI/AAAAAAAAAac/ITXPR7Lojwk/s320/Trynefaktor.jpg" width="240" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;i&gt;[Et tryne så glatt at det var nesten litt nifst...]&lt;/i&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;Anyways; vi går fremover til dagen i dag, dvs tirsdag 11 oktober. Tid for ryggmassasje klokken 09:15. En litt roligere morgen enn normalt, og en glimrende mulighet til å stikke innom &lt;a href="http://galleriet.com/kategori/spisesteder/augustins-kaffelade/"&gt;Augustins Kaffelade&lt;/a&gt;&amp;nbsp;først:&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-ouoPZhFGjTQ/TpSMxUDUvfI/AAAAAAAAAZg/xJuXqHJhFZk/s1600/2011-10-11+08.45.51.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="240" src="http://2.bp.blogspot.com/-ouoPZhFGjTQ/TpSMxUDUvfI/AAAAAAAAAZg/xJuXqHJhFZk/s320/2011-10-11+08.45.51.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;i&gt;[Kaffelade har muligens byens beste kaffe. Lite og rolig sted...]&lt;/i&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;Her kan sette seg ved vinduet, og se på folk som stresser til jobb i regnværet i Bergen:&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-yfRlzEDKyNc/TpSMxMU9GcI/AAAAAAAAAZY/T-70oz3_Zm8/s1600/2011-10-11+08.45.29.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="240" src="http://3.bp.blogspot.com/-yfRlzEDKyNc/TpSMxMU9GcI/AAAAAAAAAZY/T-70oz3_Zm8/s320/2011-10-11+08.45.29.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;Mens man nyter en deilig kaffe mocca:&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-1KiZ_4xVamA/TpSMxmqT2FI/AAAAAAAAAZo/hwT-T2ZZ0jQ/s1600/2011-10-11+08.47.52.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="320" src="http://1.bp.blogspot.com/-1KiZ_4xVamA/TpSMxmqT2FI/AAAAAAAAAZo/hwT-T2ZZ0jQ/s320/2011-10-11+08.47.52.jpg" width="240" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;Før man stiller til massasjetime hos Caroline hos WahWah. En utrolig hyggelig - og FLINK - dame. "Hu kjeme i frå Etne" - og når man selv kommer fra Tysvær så finner man tonen gjennom dialekten. Flirte litt av Bergensernes bruk av "ansikt", når man selv bare er vant til å si "tryne". :-)&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-3pFyA4gpDU8/TpSMyWPNuHI/AAAAAAAAAZw/dJ599ze5VVA/s1600/2011-10-11+10.12.59.jpg" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="240" src="http://2.bp.blogspot.com/-3pFyA4gpDU8/TpSMyWPNuHI/AAAAAAAAAZw/dJ599ze5VVA/s320/2011-10-11+10.12.59.jpg" width="320" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;i&gt;[Caroline hos WahWah. Hyggelig og flink ung dame!]&lt;/i&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;Jeg skal tilstå at jeg har vært hos WahWah 2 ganger tidligere, også da etter å ha fått gavekort. Sovnet begge gangene, og i så måte fristet til å si at det føltes rart å betale såpass med penger for å få sove 40 minutter med litt "plinkiplonk" musikk i bakgrunnen. Sånn ble det ikke denne gangen!&lt;br /&gt;&lt;br /&gt;Caroline ser og høres ut som den snille unge damen, men hun har avslørt både en fortid i forsvaret, guttejente &amp;nbsp;holdninger og bilinteresse. Et uheldig latterutbrudd i forbindelse med "gakkgakk" uniform, og jeg er litt usikker på om et velplassert tommelpress forkortet livet med noen år der og da. Det føltes ihvertfall slik. :-)&lt;br /&gt;&lt;br /&gt;Uansett, for å avslutte den kanskje mest meningsløse bloggposten jeg noen gang har skrevet på min egen blogg, så var Caroline så hyggelig at hun "dekorerte" litt med varme steiner og foreviget bildet av en oljesmurt &amp;amp; bleikfeit 40-åring på massasjebenken. God fornøyelse! :-)&lt;br /&gt;&lt;br /&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-6udDOjf5XPA/TpSM7tYJ0sI/AAAAAAAAAaM/f_v6y0YkreE/s1600/2011-10-11+10.05.29.jpg" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="320" src="http://4.bp.blogspot.com/-6udDOjf5XPA/TpSM7tYJ0sI/AAAAAAAAAaM/f_v6y0YkreE/s320/2011-10-11+10.05.29.jpg" width="240" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;i&gt;[.... og de steinene der var .... VARME! :-)]&lt;/i&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8400370148915075091-661584851149678926?l=securitynirvana.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securitynirvana.blogspot.com/feeds/661584851149678926/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://securitynirvana.blogspot.com/2011/10/en-rosa-bloggpost.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/661584851149678926'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/661584851149678926'/><link rel='alternate' type='text/html' href='http://securitynirvana.blogspot.com/2011/10/en-rosa-bloggpost.html' title='En ROSA bloggpost!'/><author><name>Per Thorsheim</name><uri>https://profiles.google.com/113848325212589987956</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-skpoP167x04/AAAAAAAAAAI/AAAAAAAAAVU/RWc12nir74w/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-pX3PESru8AU/TpSMzP7ZPbI/AAAAAAAAAaA/5i6w9A9t478/s72-c/2011-10-11+15.00.47.jpg' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8400370148915075091.post-6887127111310897700</id><published>2011-09-28T12:54:00.001+02:00</published><updated>2011-09-28T12:54:03.786+02:00</updated><title type='text'>Comments on tablet/smartphone security</title><content type='html'>My friends - and competitors - at &lt;a href="http://www.watchcom.no/"&gt;www.watchcom.no&lt;/a&gt;&amp;nbsp;- has &lt;a href="http://www.watchcom.no/?v=f8175"&gt;published a report on tablet security&lt;/a&gt;&amp;nbsp;&lt;i&gt;(Warning: Norwegian!)&lt;/i&gt;, evaluating 3 different tablets. Conclusion? iPad2 as the winner with the best out-of-the-box security features. While I do agree on the conclusion, Norwegian media has given this report a lot of coverage that I need to comment on. "Out-of-the-box" security, or default security parameters, are *rarely* to be considered "good enough" in most cases.&lt;br /&gt;&lt;br /&gt;&lt;a name='more'&gt;&lt;/a&gt;Watchcom did an analysis of iPad2 (iOS 4.3.5), Acer Iconia Tab A500 (Android 3.0.1) and the BlackBerry PlayBook (OS 1.0.7), looking at security features such as:&lt;br /&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;&lt;b&gt;Security&lt;/b&gt;&lt;/li&gt;&lt;ul&gt;&lt;li&gt;Authentication&lt;/li&gt;&lt;li&gt;Encryption &amp;amp; communication&lt;/li&gt;&lt;li&gt;Blocking various features&lt;/li&gt;&lt;li&gt;Secure sync of critical applications&lt;/li&gt;&lt;/ul&gt;&lt;li&gt;&lt;b&gt;Administration&lt;/b&gt;&lt;/li&gt;&lt;ul&gt;&lt;li&gt;Administration and policy&lt;/li&gt;&lt;/ul&gt;&lt;li&gt;&lt;b&gt;Application security&lt;/b&gt;&lt;/li&gt;&lt;ul&gt;&lt;li&gt;Application security&lt;/li&gt;&lt;li&gt;Security extensions&lt;/li&gt;&lt;/ul&gt;&lt;li&gt;&lt;b&gt;Security evaluations and certifications&amp;nbsp;&lt;/b&gt;&lt;/li&gt;&lt;/ol&gt;&lt;div&gt;&lt;i&gt;I think their PDF files with evaluation criteria and point scale system (1-3) should be fairly easy to understand, even when written in Norwegian.&lt;/i&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;As for my comments&lt;/b&gt;; I am both surprised of the media not asking any obvious and critical questions to this evaluation, as well as Watchcom seemingly not saying anything about the limitations surrounding their evaluation.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;u&gt;A few comments from me, that organisations should consider before making their decision &amp;amp; purchase:&lt;/u&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;1. iPad (iOS) security&lt;/b&gt;&lt;/div&gt;&lt;div&gt;Using the &lt;a href="http://www.elcomsoft.com/ios-forensic-toolkit.html"&gt;Elcomsoft iOS Forensic Toolkit&lt;/a&gt;, any 4-digit PIN on an iPad (or iPhone) can be bruteforced within &amp;lt;1 hour. Default security parameters in iOS and Microsoft Activesync requires a 4-digit PIN, while there are options available for requiring longer PINs and/or complex passwords.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;While a 4-digit PIN will protect your data from the casual prying eyes (random theft/loss of your device), an organized and targeted attack will most likely succeed with a rather low cost compared to the data possibly stored on the device. I'll leave it to you to do the risk analysis including the value of your on-device stored data such as MS Exchange calendar including telephone conference numbers and codes, meeting attachments (word, excel, powerpoint, pdf files) and more.&amp;nbsp;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;With Apple and iOS so obviously in the lead above all else, there's no doubt they will draw even more attention to their security - or lack of it - in the very near future. From my perspective they really don't have that much of a reputation so far on discussing, disclosing and admitting security bugs and weaknesses found. Usually not a good sign to me, but I won't to the full open vs responsible vs closed disclosure discussion here.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;2. Remote device management security&lt;/b&gt;&lt;/div&gt;&lt;div&gt;Remote wipe, as well as a wide range of other security features will actually require the tablet to connect to a wlan or gsm/3g connection in order to "phone home" and receive instructions such as "the device has been lost or stolen. Please wipe the entire contents of the device and set it back to its factory default".&amp;nbsp;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;While a GSM/3G jammer is illegal to operate here in Norway, it can still be obtained for pocket money from other countries. This will effectively block such communication, prohibiting any remote wipe command to ever reach the device. All this of course, in cases where the attacker can't simply remove the SIM card from the device of course. :-)&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;A simple "faraday cage" will additionally block any wlan connections, easily allowing an attacker to gain more time to successfully break the security of the device in order to gain information access. Evaluating your employees ability to actually report lost or stolen devices will be of high importance, as the timeframe needed for a successful compromise of your device could be as little as &amp;lt;= 1 hour. (This is something I will blog and talk about more in the near future.)&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;3. The gaping password hole left by Microsoft Activesync&lt;/b&gt;&lt;/div&gt;&lt;div&gt;Yes, I know I am a fanatic on passwords. I took the &lt;a href="http://en.wikipedia.org/wiki/Red_pill_and_blue_pill"&gt;red pill&lt;/a&gt; a long time ago on this, and it keeps expanding. When you configure Activesync on your smartphone or tablet, the default configuration is to use a SSL (https) connection to a website providing Outlook Web Access (OWA). Default login here is username and password from the internal Active Directory, with password policy being whatever you have configured in your domain. Again; the default is nowhere good enough in this situation as well.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;While many discussions have been raised on the security of the sync &amp;amp; storage of activesync data (contacts, calendar, mail), I haven't seem much talk regarding that fact of such a configuration opening up 1-factor password guessing (or pure bruteforcing) against OWA. As I have said before, like many others like me that are "excessively" interested in passwords, allowing for 1-factor access to internal systems from the Internet is generally not a good idea any longer. In fact, many security policies of large organisations disallow it.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;From an attackers perspective; why waste time tracking down your CEO in order to steal or "borrow" his or hers tablet for a few hours, when finding the username and guessing the password of the CEO directly towards https://webmail.some.domain can be even faster and easier?&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;i&gt;(Yes Watchcom, I already know that you provide solutions for VPN access and 2-factor authentication to secure this stuff. I have yet to see any evidence of acceptable usability on this :-) )&lt;/i&gt;&lt;/div&gt;&lt;div&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;4. Android vs Android security&lt;/b&gt;&lt;/div&gt;&lt;div&gt;Watchcom has tested the Acer Iconia Tab A500 with Android 3.0.1. Fair enough.&amp;nbsp;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;I've got a Samsung Galaxy S II smartphone, featuring on-device hardware encryption of both internal storage as well as my inserted memory card. According to Samsung's commercial, it supports more Activesync policies than any other product on the market (or something like that). Working on verifying that, but at least it seems to be working. The same applies to the Galaxy Tab tablets, as well as other tablets now available in the stores.&amp;nbsp;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;I would say that Watchcom should consider updating their report ASAP with at least one or more Android based tablets from other vendors, say Samsung and the Lenovo Thinkpad, where the Thinkpad is specifically targeted at corporate business use.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;As for the media: did you ask anyone to comment or question the findings from Watchcom? I'd sure as h**l appreciate it if you &lt;u&gt;continue&lt;/u&gt; doing that every time you quote me on anything, thank you. :-)&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8400370148915075091-6887127111310897700?l=securitynirvana.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securitynirvana.blogspot.com/feeds/6887127111310897700/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://securitynirvana.blogspot.com/2011/09/comments-on-tabletsmartphone-security.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/6887127111310897700'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/6887127111310897700'/><link rel='alternate' type='text/html' href='http://securitynirvana.blogspot.com/2011/09/comments-on-tabletsmartphone-security.html' title='Comments on tablet/smartphone security'/><author><name>Per Thorsheim</name><uri>https://profiles.google.com/113848325212589987956</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-skpoP167x04/AAAAAAAAAAI/AAAAAAAAAVU/RWc12nir74w/s512-c/photo.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8400370148915075091.post-3586557458842703704</id><published>2011-08-22T21:59:00.002+02:00</published><updated>2011-08-22T22:05:37.009+02:00</updated><title type='text'>Cryptohaze GPU Rainbow Cracker - test 1</title><content type='html'>Well, not exactly my very first test, but my first blog post about Bitweasil's sweet little piece of software, which can be found at his site &lt;a href="http://cryptohaze.com/"&gt;cryptohaze.com&lt;/a&gt;. First of all: it seems *FAST*. Second: MUCH needs to be done, which is the reason for this short little blog post. I'll start out with just a single request: HEX display of all found passwords, in addition to the standard display on screen. Here's what I did:&lt;br /&gt;&lt;br /&gt;&lt;a name='more'&gt;&lt;/a&gt;Using the hash generator at &lt;a href="http://insidepro.com/"&gt;insidepro.com&lt;/a&gt;, I created 2 NTLM hashes, one for &lt;b&gt;Passord&lt;/b&gt;, and one for &lt;b&gt;Passor &amp;nbsp;&lt;/b&gt;(a single space character replacement - ASCII Hex20 - for the letter &lt;b&gt;d&lt;/b&gt;&amp;nbsp;at the end there).&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="font-weight: normal;"&gt;&lt;b&gt;Passord&lt;/b&gt;&amp;nbsp;:&amp;nbsp;72892f1b58f8708c3f07639f6c08daea&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;&lt;b&gt;Passor &lt;/b&gt;&amp;nbsp;:&amp;nbsp;42ae7b3af2c5c22514b89355dfa8b3be&lt;br /&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;br /&gt;Using GRTCrack.exe -h NTLM -s (hashvalue) GRT-NTLM-len7-fullcharset-perfect\*.grt --threads 512 --blocks 512 -m 500, my GTX580 goes to 99%. Tables are stored on a 2x1TB soft striped array on SATA, i7 cpu, 24GB memory and W7x64.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Passord &lt;/b&gt;is found in the second table, while &lt;b&gt;Passor &amp;nbsp;&lt;/b&gt;is found in the first table after a few seconds. Here are screenshots of the output:&lt;br /&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-sJLqadRyLYU/TlKxmst6hKI/AAAAAAAAAYc/sOf6zH7bQwU/s1600/Passord_output.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="320" src="http://3.bp.blogspot.com/-sJLqadRyLYU/TlKxmst6hKI/AAAAAAAAAYc/sOf6zH7bQwU/s320/Passord_output.png" width="279" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;i&gt;GRTCrack output for &lt;b&gt;Passord)&lt;/b&gt;&lt;/i&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;br /&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-02OT6dEQbQQ/TlKxmaEUR8I/AAAAAAAAAYY/Q9H0tkGYAIk/s1600/Passor_output.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="193" src="http://2.bp.blogspot.com/-02OT6dEQbQQ/TlKxmaEUR8I/AAAAAAAAAYY/Q9H0tkGYAIk/s320/Passor_output.png" width="320" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;i&gt;GRTCrack output for &lt;b&gt;Passor )&lt;/b&gt;&lt;/i&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;As you can see: 2 different passwords, different hash values, but you can't trust the output in case of HEX20 padding at the end. One out of several tricks I've told some of those with an genuine interest in blocking me from cracking their passwords in "the early days". (You are not alone; Cain from &lt;a href="http://www.oxid.it/"&gt;www.oxid.it&lt;/a&gt; doesn't show any hex values either, and that's just one example.)&lt;br /&gt;&lt;br /&gt;Chances are rather slim for finding a Windows domain controller with LM disabled and no LM hashes available. Add to that one or more users "padding" their password with one or more HEX20's at the end up to and including length 7, and charset limited within full US ASCII (or 8, with the &lt;a href="http://cryptohaze.com/gpurainbowtables.php"&gt;Terabyte NTLM tableset&lt;/a&gt; that Bitweasil offers to ship to you for USD 500,-)... Well, not many does that.&lt;br /&gt;&lt;br /&gt;However; I NEED to see the HEX output of the passwords as well Bitweasil! :-)&lt;br /&gt;Even better: As soon as the password is found, calculate its hash value and compare it to the original input value - for added confidence in the results. Allow me to output the results to a TAB separated file (optional parameter?), making it easier to work with the results when users have used those darn &lt;b&gt;::::: &lt;/b&gt;colons in their passwords - for the fun of seeing me get angry. :-)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8400370148915075091-3586557458842703704?l=securitynirvana.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securitynirvana.blogspot.com/feeds/3586557458842703704/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://securitynirvana.blogspot.com/2011/08/cryptohaze-gpu-rainbow-cracker-test-1.html#comment-form' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/3586557458842703704'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/3586557458842703704'/><link rel='alternate' type='text/html' href='http://securitynirvana.blogspot.com/2011/08/cryptohaze-gpu-rainbow-cracker-test-1.html' title='Cryptohaze GPU Rainbow Cracker - test 1'/><author><name>Per Thorsheim</name><uri>https://profiles.google.com/113848325212589987956</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-skpoP167x04/AAAAAAAAAAI/AAAAAAAAAVU/RWc12nir74w/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-sJLqadRyLYU/TlKxmst6hKI/AAAAAAAAAYc/sOf6zH7bQwU/s72-c/Passord_output.png' height='72' width='72'/><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8400370148915075091.post-1774795873573359635</id><published>2011-08-17T14:44:00.000+02:00</published><updated>2011-08-17T14:44:21.583+02:00</updated><title type='text'>New comments for older posts</title><content type='html'>Quick note to say that&amp;nbsp;&lt;span class="Apple-style-span" style="background-color: white; color: #444444; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 13px; font-weight: bold; line-height: 18px;"&gt;&lt;a href="http://blog.streambur.se/" rel="nofollow" style="color: #3778cd; text-decoration: none;"&gt;Erik Brännström&lt;/a&gt;&amp;nbsp;&lt;/span&gt;&lt;span class="Apple-style-span" style="background-color: white; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 13px; line-height: 18px;"&gt;has added an interesting comment to the "&lt;a href="http://securitynirvana.blogspot.com/2010/02/never-trust-password-meters.html"&gt;Never Trust Password Meters&lt;/a&gt;" blog post, while "Anonymous" (No, not those guys, but a PhD in Vein biometrics) has added comments to the "&lt;a href="http://securitynirvana.blogspot.com/2011/02/about-biometrics.html"&gt;About Biometrics&lt;/a&gt;.." post. Both worth reading.&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="background-color: white; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: 13px; line-height: 18px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8400370148915075091-1774795873573359635?l=securitynirvana.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securitynirvana.blogspot.com/feeds/1774795873573359635/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://securitynirvana.blogspot.com/2011/08/new-comments-for-older-posts.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/1774795873573359635'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/1774795873573359635'/><link rel='alternate' type='text/html' href='http://securitynirvana.blogspot.com/2011/08/new-comments-for-older-posts.html' title='New comments for older posts'/><author><name>Per Thorsheim</name><uri>https://profiles.google.com/113848325212589987956</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-skpoP167x04/AAAAAAAAAAI/AAAAAAAAAVU/RWc12nir74w/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8400370148915075091.post-6261756726919283671</id><published>2011-08-16T23:51:00.001+02:00</published><updated>2011-08-16T23:57:04.952+02:00</updated><title type='text'>xkcd 936 - the discussion continues</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://imgs.xkcd.com/comics/password_strength.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="259" src="http://imgs.xkcd.com/comics/password_strength.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;WOW. That was my immediate thought &lt;i&gt;(We use &lt;b&gt;wow&lt;/b&gt; in Norwegian as well)&lt;/i&gt;&amp;nbsp;when I saw xkcd 936. WOW. That is pretty close to exactly what I've been trying to tell people for the last 10+ years, while &amp;nbsp;researching passwords. Hat off, kudos and whatnot to Randall Munroe for this one! Now for some of the discussions in the wake of &lt;b&gt;936&lt;/b&gt;....&lt;br /&gt;&lt;br /&gt;&lt;a name='more'&gt;&lt;/a&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt;1. Password Entropy&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;Stop using mathematical entropy to measure the strength of passwords! You are most probably doing it wrong anyway. I'll be the first to say that I &lt;b&gt;*suck* &lt;/b&gt;in math &lt;i&gt;(WolframAlpha to the rescue!), &lt;/i&gt;so for starters on entropy I would suggest you to read Matt Weir's blog at &lt;a href="http://reusablesec.blogspot.com/"&gt;reusablesec.blogspot.com&lt;/a&gt;, and his paper&amp;nbsp;&lt;b&gt;&lt;a href="http://reusablesec.blogspot.com/2010/10/new-paper-on-password-security-metrics.html"&gt;Testing Metrics for Password Creation Policies&amp;nbsp;by Attacking Large Sets of Revealed Passwords&lt;/a&gt;&amp;nbsp;&lt;/b&gt;(Weir, Aggarwal, Collins, Stern). NIST SP800-63 says something about password strength through resistance to online cracking, and to quote from his blog:&lt;br /&gt;&lt;blockquote&gt;"&lt;span class="Apple-style-span" style="background-color: white; color: #333333; font-family: Georgia, serif; font-size: 13px; line-height: 20px;"&gt;&lt;b&gt;Our findings were that the NIST model of password entropy does not match up with real world password usage or password cracking attacks.&lt;/b&gt;"&lt;/span&gt;&lt;/blockquote&gt;Now, I could poke Matt with saying that their analysis were done towards revealed passwords in the form of leaks from sites like &lt;a href="http://reusablesec.blogspot.com/2010/01/more-analysis-of-rockyou-password-list.html"&gt;Rockyou&lt;/a&gt;&amp;nbsp;etc. Having cracked almost nothing else than passwords from Microsoft Windows systems of real corporations and organisations for 10+ years, I think I've got evidence enough to say that "my" passwords are better in almost any measurement compared to the Rockyou, Hotmail lists and more. &lt;i&gt;(Matt; what about applying your metrics to my data? ;-))&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt;2. Never Trust Password Meters&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;&lt;a href="http://securitynirvana.blogspot.com/2010/11/revisiting-password-meters.html"&gt;This link&lt;/a&gt; will take you to an earlier blog post from me, and then back to the first one, based on an infographic that &lt;a href="https://twitter.com/#!/mikkohypponen"&gt;Mikko Hypponen&lt;/a&gt; made a tweet about. I hope and believe those 2 blog posts will widen your horizon in regard to password meters, password entropy and more.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt;3. xkcd 936 - related websites&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;Sure, they appeared very fast.&amp;nbsp;&lt;a href="http://simplestrongpasswordgenerator.com/"&gt;simplestrongpasswordgenerator&lt;/a&gt;&amp;nbsp;and&amp;nbsp;&lt;a href="http://passphra.se/"&gt;passphra.se&lt;/a&gt;&amp;nbsp;are just 2 examples that I've seen. Unfortunately they will &lt;b&gt;fail&lt;/b&gt;&amp;nbsp;in many situations, especially corporate environments. Simplestrongpasswordgenerator gave me this:&amp;nbsp;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;span id="word1" style="color: #aa4488;"&gt;widely&lt;/span&gt;&lt;span id="word2" style="color: #44aa88;"&gt;order&lt;/span&gt;&lt;span id="word3" style="color: #aa4488;"&gt;private&lt;/span&gt;&lt;span id="word4"&gt;&lt;span class="Apple-style-span" style="color: #44aa88;"&gt;established&lt;/span&gt;. Huh? &lt;b&gt;Am I supposed to remember that?&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;Here's a good place to quote&lt;a href="https://twitter.com/#!/troyhunt"&gt; Troy Hunt&lt;/a&gt; and his blog post on the subject: "&lt;a href="http://www.troyhunt.com/2011/08/im-sorry-but-were-you-actually-trying.html"&gt;I'm sorry, but were you actually trying to remember your comical passwords?&lt;/a&gt;". Although I do not agree on everything he writes, he sure does have many good points in his blog post.&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;Although difficult sometimes, we should remember the difference between protecting our personal accounts, and (personal) accounts at corporations and organisations where a security breach can have a much wider impact than that of your own privacy.&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;span id="word4"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt;&lt;b&gt;4. Mixing it all&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;Mikko Hypponen really do impress me. Never met him, but his information, in any channel, is precise, short and informative. He also does a terrific job with his tweets, including all the retweets from others. And suddenly today, he retweeted this &lt;a href="http://twitpic.com/673t76"&gt;image from @ly_gs&lt;/a&gt;. &lt;b&gt;Right back at the entropy calculations :-)&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt; Melvin&lt;/b&gt;; We have 29 characters in our Norwegian alphabet, make your infographic with various charsets and/or languages applied. :-)&lt;br /&gt;&lt;br /&gt;&lt;a href="http://twitter.com/phadej"&gt;Phadej&lt;/a&gt;&amp;nbsp;and &lt;a href="http://twitter.com/davienthemoose"&gt;davienthemoose&lt;/a&gt;&amp;nbsp;followed up (among others) with some objections. Lets take a look:&lt;br /&gt;&lt;br /&gt;&lt;a href="https://gist.github.com/1149737"&gt;Phadej posted this feedback&lt;/a&gt;:&lt;br /&gt;&lt;span class="Apple-style-span" style="background-color: white; font-family: 'Bitstream Vera Sans Mono', 'Courier New', monospace; font-size: 12px; line-height: 16px; white-space: pre;"&gt;We actually need more words, as entropy of the words is less than characters. &lt;/span&gt;&lt;span class="Apple-style-span" style="background-color: white; font-family: 'Bitstream Vera Sans Mono', 'Courier New', monospace; font-size: 12px; line-height: 16px; white-space: pre;"&gt;Suppose there is about 50000 words (There is 301 000 main entries in OED).&amp;nbsp;&lt;/span&gt;&lt;span class="Apple-style-span" style="background-color: white; font-family: 'Bitstream Vera Sans Mono', 'Courier New', monospace; font-size: 12px; line-height: 16px; white-space: pre;"&gt;Than &lt;/span&gt;&lt;span class="Apple-style-span" style="background-color: white; font-family: 'Bitstream Vera Sans Mono', 'Courier New', monospace; font-size: 12px; line-height: 16px; white-space: pre;"&gt;50000^x &amp;gt; 94^13 =&amp;gt; x =&amp;gt; 5.5&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="background-color: white; font-family: 'Bitstream Vera Sans Mono', 'Courier New', monospace; font-size: 12px; line-height: 16px; white-space: pre;"&gt;So i would say that &lt;/span&gt;&lt;span class="Apple-style-span" style="background-color: white; font-family: 'Bitstream Vera Sans Mono', 'Courier New', monospace; font-size: 12px; line-height: 16px; white-space: pre;"&gt;"balloons are very nice" &amp;lt; "@$XsBv2JMc473"&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="background-color: white; font-family: 'Bitstream Vera Sans Mono', 'Courier New', monospace; font-size: 12px; line-height: 16px; white-space: pre;"&gt;Also entropy of word like "are" is almost zero, so predictable. &lt;/span&gt;&lt;span class="Apple-style-span" style="background-color: white; font-family: 'Bitstream Vera Sans Mono', 'Courier New', monospace; font-size: 12px; line-height: 16px; white-space: pre;"&gt;And xkcd strip actually kind of takes this into account. &lt;/span&gt;&lt;span class="Apple-style-span" style="background-color: white; font-family: 'Bitstream Vera Sans Mono', 'Courier New', monospace; font-size: 12px; line-height: 16px; white-space: pre;"&gt;I will stick with pronounceable/memorizable passwords &lt;/span&gt;&lt;span class="Apple-style-span" style="background-color: white; font-family: 'Bitstream Vera Sans Mono', 'Courier New', monospace; font-size: 12px; line-height: 16px; white-space: pre;"&gt;like pwgen kindly generates for me.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;WolframAlpha says there are &lt;b&gt;600,000&lt;/b&gt; words in the Oxford English Dictionary, 2nd edition. Lets take a shot at WolframAlpha: 600000^4 (4 simple words) = 129600000000000000000000 combinations. No offence, but I REALLY think we should drop this blind entropy discussion for measuring password strength.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Davienthemoose&lt;/b&gt;&amp;nbsp;tweeted &lt;i&gt;"until you use a dictionary set for cracking by word to break passphrases. Then each word becomes a char of 1"&lt;/i&gt;.&lt;br /&gt;&lt;br /&gt;Nice idea. After the &lt;a href="http://contest.korelogic.com/"&gt;CrackMeIfYouCan&lt;/a&gt; competition at this years &lt;a href="http://www.defcon.org/"&gt;Defcon&lt;/a&gt;, somebody said something like "we are now actually able to crack '4 simple word passphrases'&amp;nbsp;&lt;i&gt;(Can't remember exactly who, where and when, sorry!). &lt;/i&gt;&lt;b&gt;Sure we/they can!&lt;/b&gt;&amp;nbsp; On the other hand; being able to so is closer to blind luck, IMHO. Why? Well, back to the entropy, corporate password policies and just plain common language.&lt;br /&gt;&lt;br /&gt;We've said &lt;b&gt;password&lt;/b&gt;&amp;nbsp;for decades, and we've tried to convert people to use '&lt;b&gt;passphrases&lt;/b&gt;' instead. Is&amp;nbsp;&amp;nbsp;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;span id="word1" style="color: #aa4488;"&gt;widely&lt;/span&gt;&lt;span id="word2" style="color: #44aa88;"&gt;order&lt;/span&gt;&lt;span id="word3" style="color: #aa4488;"&gt;private&lt;/span&gt;&lt;span id="word4"&gt;&lt;span class="Apple-style-span" style="color: #44aa88;"&gt;established &lt;/span&gt;a good passphrase? Not in my opinion. Maybe the &lt;b&gt;sentence&lt;/b&gt;&amp;nbsp;"&lt;span class="Apple-style-span" style="color: red;"&gt;I live in New York, USA.&lt;/span&gt;" (without the quotes)&lt;span class="Apple-style-span" style="color: red;"&gt;&amp;nbsp;&lt;/span&gt;could be better? At least it should be easy to remember for quite a few people over there.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;No, do NOT look at the contents of the password and say "Duh! DORK!". You have absolutely no idea what the password is before you actually crack it. See "Please crack my password" below.&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;Davienthemoose: Nice idea, and you should talk to some of the hardcore John the Ripper (JtR) guys to learn more. From my point of view:&amp;nbsp;&lt;/span&gt;we're right back at the entropy stuff again, SP800-63, and much more. Please go back to Matt Weirs paper. :-)&lt;br /&gt;&lt;br /&gt;I'll leave it for the evening right here, it's 23:47 and I've got to sleep. again. Just this last one, just for the fun of it:&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt;&lt;b&gt;5. Please Crack My Password&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;Please crack my NTLM hash:&lt;b&gt;&amp;nbsp;DD1E31A5C1709A9CF54893B89E24CA09&lt;/b&gt;&lt;br /&gt;It is 4 words, and it complies with probably most (reasonable) common corporate password policies. It is very personally related to me, making it easy to remember. &lt;b&gt;Good luck, you've got 14 days&lt;/b&gt;.&lt;br /&gt;&lt;i&gt;I'll donate some money to freerainbowtables.com or any other password related open-source project of your liking through PayPal, if you can crack my ... password/phrase/sentence above. I'd really appreciate an explanation on how you did it, and of course you can mock me for a LONG time afterwards.&lt;/i&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8400370148915075091-6261756726919283671?l=securitynirvana.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securitynirvana.blogspot.com/feeds/6261756726919283671/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://securitynirvana.blogspot.com/2011/08/xkcd-936-discussion-continues.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/6261756726919283671'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/6261756726919283671'/><link rel='alternate' type='text/html' href='http://securitynirvana.blogspot.com/2011/08/xkcd-936-discussion-continues.html' title='xkcd 936 - the discussion continues'/><author><name>Per Thorsheim</name><uri>https://profiles.google.com/113848325212589987956</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-skpoP167x04/AAAAAAAAAAI/AAAAAAAAAVU/RWc12nir74w/s512-c/photo.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8400370148915075091.post-6153794021913216211</id><published>2011-08-12T14:03:00.001+02:00</published><updated>2011-08-12T14:20:53.878+02:00</updated><title type='text'>Webmercs Password Security</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-TH5WeCTZWgE/TkGLf-PyaMI/AAAAAAAAAX8/Eg2bb-k47LU/s1600/Webmercs_logo.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/-TH5WeCTZWgE/TkGLf-PyaMI/AAAAAAAAAX8/Eg2bb-k47LU/s1600/Webmercs_logo.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Vacation is over, time to take a look at the password security of another online webshop software solution. This time named &lt;a href="http://www.webmercs.no/"&gt;Webmercs&lt;/a&gt;, from a Norwegian company named Data Design. I got triggered to do this blog post after visiting &lt;a href="http://www.avshop.no/"&gt;www.avshop.no&lt;/a&gt;, where I am a registered customer. Lets take a look at Webmercs...&lt;br /&gt;&lt;br /&gt;&lt;a name='more'&gt;&lt;/a&gt;On July 4, 2011, I released a&amp;nbsp;&lt;a href="http://securitynirvana.blogspot.com/2011/07/passordsikkerhet-fra-multicase.html"&gt;blog post&lt;/a&gt;&amp;nbsp;&lt;i&gt;(in Norwegian)&lt;/i&gt;&amp;nbsp;about password security in a software solution for logistics and online sales from a Norwegian company named&amp;nbsp;&lt;a href="http://www.multicase.no/"&gt;MultiCase&lt;/a&gt;. Their solution sent passwords by unencrypted e-mail, and either stored passwords in plaintext or using reversible encryption. Their response came quickly, time will show if, and how they follow up.&lt;br /&gt;&lt;br /&gt;Webmercs seems to be a hosted solution, lots of domains link to&lt;b&gt; secure.webmercs.com&lt;/b&gt;. Running that site through ssllabs gives us unsatisfactory results:&amp;nbsp;&lt;i&gt;(MITM, SSL 2.0, 40-bit support etc)&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-JmgPKfn119E/TkOI41qqxsI/AAAAAAAAAYE/O6bDKYgEEL0/s1600/ssllabs_results_secure_webmercs_no.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="149" src="http://1.bp.blogspot.com/-JmgPKfn119E/TkOI41qqxsI/AAAAAAAAAYE/O6bDKYgEEL0/s320/ssllabs_results_secure_webmercs_no.png" width="320" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;i&gt;(Click to view full size, or visit &lt;a href="https://www.ssllabs.com/ssldb/analyze.html?d=secure.webmercs.com"&gt;SSLLABS&lt;/a&gt;)&lt;/i&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;Now there are lots of sites which doesn't have their SSL configurations in order, although that is no excuse for Webmercs. Being a hosted solution, where their customers will completely or partially have their services running through secure.webmercs.com, it becomes more of a &lt;b&gt;Single Point Of Failure&lt;/b&gt;.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.webmercs.no/clients"&gt;They have a bunch of customers&lt;/a&gt;, which is always good to display - until something goes wrong.&lt;br /&gt;&lt;br /&gt;----&lt;br /&gt;As a small side-step before continuing, here are two opposite views on security, which I am constantly facing in my daily work:&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Customers:&lt;/b&gt; &lt;i&gt;"We trust our service provider. We have to trust our provider. We see no reason not to trust our provider. Of course our provider will be give us an acceptable security level. Our providers security is of course at an acceptable level. Our provider knows what an acceptable security level is, has implemented it, and maintains it&amp;nbsp;continuously. &lt;b&gt;Our provider is (solely) responsible for designing, implementing and maintaining an acceptable (best practice) level of security.&lt;/b&gt;&amp;nbsp;We do not&amp;nbsp;possess the necessary skills and experience to design such security ourselves, which is partially why we choose to buy this service from an external provider."&lt;/i&gt;&lt;br /&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;br /&gt;&lt;b&gt;(Software) Providers:&lt;/b&gt;&lt;br /&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="background-color: white;"&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;span class="Apple-style-span" style="font-weight: normal;"&gt;THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL &lt;/span&gt;&lt;insert company="" here="" name=""&gt;&lt;span class="Apple-style-span" style="font-weight: normal;"&gt; BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.&lt;/span&gt;&lt;/insert&gt;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;My point is simple:&lt;/b&gt; most (software) providers will provide an absolute minimum of security by default, leaving it all to you to decide what kind of security you want to configure. However; they will provide lots of buttons, parameters, flags and options that you may change to improve (or weaken) the default security level. Few of them will provide an additional "best practices" document, with recommendations on how you *&lt;b&gt;should*&lt;/b&gt;&amp;nbsp;configure those parameters...&lt;br /&gt;&lt;br /&gt;As I've seen over and over and over again, default security parameters are often left right there - at &lt;b&gt;default.&lt;/b&gt;&lt;br /&gt;----&lt;br /&gt;&lt;br /&gt;Well, that was my general complaint for the day. Let's get back to Webmercs. Here's a screenshot from an e-mail I received, after changing my password and then going through the "forgotten password" procedure at &lt;a href="http://www.avshop.no/"&gt;www.avshop.no&lt;/a&gt;, where I am a registered customer. They use Webmercs:&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-F-cGntQabTk/TkUGAgfzMLI/AAAAAAAAAYM/02HI74v6xNg/s1600/webmercs_mail.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="50" src="http://2.bp.blogspot.com/-F-cGntQabTk/TkUGAgfzMLI/AAAAAAAAAYM/02HI74v6xNg/s400/webmercs_mail.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Even though its Norwegian, I guess you do understand what it says. (&lt;i&gt;Oh, and that password is not my default one! :-)&lt;/i&gt;)&lt;br /&gt;&lt;br /&gt;Lots of evidence there already, showing that the Webmercs solution sends my existing password, username and all the info you need to access my account through unencrypted e-mail. If they do any kind of password encryption at Webmercs, it still is nowhere near what I would call "best practice".&lt;br /&gt;&lt;br /&gt;I have also looked at &lt;a href="http://www.webmercs.no/clients"&gt;a few other sites that are using Webmercs&lt;/a&gt;, and some seem to have at least somewhat better minimum password requirements configured. Obviously the choice of password policy is left to the customer to decide, and I do fear that the default from Webmercs is length 1, obviously without any type of complexity thrown in.&lt;br /&gt;&lt;br /&gt;Do we need any more? To me I've got all the evidence of bad password practices I need. I'll uphold my recommendation on focusing on software developers &amp;amp; providers first for increasing password security &amp;amp; awareness, before bashing end-users for bad password behavior. I will of course get back to this in future blog posts as well.&lt;br /&gt;--&lt;br /&gt;FYI:&lt;br /&gt;I have sent information to support@webmercs.no to inform them about this blog post, in accordance with their ..&lt;a href="http://www.webmercs.no/support"&gt; interesting stand on how to provide support&lt;/a&gt;. No online ticketing system for your support requests there, but at least they are honest about it.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8400370148915075091-6153794021913216211?l=securitynirvana.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securitynirvana.blogspot.com/feeds/6153794021913216211/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://securitynirvana.blogspot.com/2011/08/webmercs-password-security.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/6153794021913216211'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/6153794021913216211'/><link rel='alternate' type='text/html' href='http://securitynirvana.blogspot.com/2011/08/webmercs-password-security.html' title='Webmercs Password Security'/><author><name>Per Thorsheim</name><uri>https://profiles.google.com/113848325212589987956</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-skpoP167x04/AAAAAAAAAAI/AAAAAAAAAVU/RWc12nir74w/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-TH5WeCTZWgE/TkGLf-PyaMI/AAAAAAAAAX8/Eg2bb-k47LU/s72-c/Webmercs_logo.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8400370148915075091.post-2270419271731717808</id><published>2011-07-06T19:52:00.001+02:00</published><updated>2011-07-06T19:52:01.269+02:00</updated><title type='text'>Securing your passw^H^H^H^Hgp private key</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/_qyUrb02hPrA/TPLRdLjvhjI/AAAAAAAAAPE/a0BUL4dte3s/s1600/426px-Public_key_making.svg.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="288" src="http://2.bp.blogspot.com/_qyUrb02hPrA/TPLRdLjvhjI/AAAAAAAAAPE/a0BUL4dte3s/s320/426px-Public_key_making.svg.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;I saw &lt;a href="http://nakedsecurity.sophos.com/2011/07/05/can-simple-google-searches-reveal-your-secrets/"&gt;this article&lt;/a&gt; today by &lt;a href="http://twitter.com/DSchwartzberg"&gt;@DSchwartzberg&lt;/a&gt;&amp;nbsp;at Sophos about Google indexing PGP private keys, easily found if you know what to search for. It reminded me that I had to finish this old blog post which has been waiting in line for some months now.&amp;nbsp;Lets get straight to the point: &lt;b&gt;How do you protect your GPG/PGP &lt;span class="Apple-style-span" style="color: red;"&gt;private&lt;/span&gt; key?&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;a name='more'&gt;&lt;/a&gt;I use GPG/PGP myself, both at work as well as at home, even though Bruce Schneier says in his book "Secrets &amp;amp; Lies": "&lt;span class="Apple-style-span" style="-webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px;"&gt;&lt;span class="Apple-style-span" style="color: red;"&gt;&lt;i&gt;Digital certificates provide no actual security for electronic commerce; it's a complete sham.&lt;/i&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="-webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px;"&gt;" Made me smile when I read it. Of course there are many ways to interpret that statement by itself, with perhaps an interesting view being that a digital certificate identifies an electronic &lt;/span&gt;&lt;span class="Apple-style-span" style="-webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px;"&gt;&lt;i&gt;identity&lt;/i&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="-webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px;"&gt;, and not necessarily a physical person. DNA testing does that these days. Even more; identifying somebody really doesn't tell you much if they are Alice, Bob or &lt;span class="Apple-style-span" style="color: red;"&gt;Eve&lt;/span&gt;. Well, unless they already have a&lt;a href="http://www.fbi.gov/wanted/topten"&gt; record&lt;/a&gt;, or become subjects of &lt;i&gt;&lt;a href="http://legal-dictionary.thefreedictionary.com/Ethnic+profiling"&gt;Ethnic Profiling&lt;/a&gt;&amp;nbsp;&lt;/i&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="-webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px;"&gt;of course.&lt;/span&gt;&lt;br /&gt;&lt;i&gt;&lt;span class="Apple-style-span" style="-webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/i&gt;&lt;br /&gt;&lt;i&gt;&lt;span class="Apple-style-span" style="-webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px;"&gt;We have a law here in Norway that says that I am legally bound by anything signed by my #BankID, and similar solutions. BankID is a bank-issued digital certificate, where a single commercial company - owned by various banks - keeps my private keys in their&amp;nbsp;possession,&amp;nbsp;and will NOT give it to me electronically!&lt;/span&gt;&lt;/i&gt;&lt;br /&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="-webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="-webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px;"&gt;Anyway, lets not wake up &lt;/span&gt;&lt;span class="Apple-style-span" style="-webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px;"&gt;&lt;a href="http://en.wikipedia.org/wiki/Kerckhoffs's_Principle"&gt;Auguste Kerckhoff&lt;/a&gt;&lt;/span&gt;&lt;/b&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="-webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px;"&gt; from the dead.&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="-webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="-webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px;"&gt;What I am curious about - of course this blog post is about passwords - is how people go about protecting their GPG/PGP secret keys? Do people use strong passphrases? Do they ever change them? What about the password/phrase for shared secret keys, such as those belonging to various CERTs, IRTs, CSIRTs and so on? What if somebody leaves such a team - do they create a brand new key, do they just change the password (Now that's a risk!), or what?&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="-webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="-webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px;"&gt;Allow me to quote from the &lt;a href="http://www.gnupg.org/gph/en/manual.html#AEN513"&gt;gnupg manual&lt;/a&gt;:&lt;/span&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;i&gt;"Protecting your private key is the most important job you have to use GnuPG correctly. If someone obtains your private key, then all data encrypted to the private key can be decrypted and signatures can be made in your name. If you lose your private key, then you will no longer be able to decrypt documents encrypted to you in the future or in the past, and you will not be able to make signatures. Losing sole possession of your private key is catastrophic."&lt;/i&gt;&lt;/blockquote&gt;If you use PGP Microsoft Windows in a corporate environment, the default configuration will store your keyring, including your private key, under "My Documents". That folder will again probably be stored centrally on a server, making your keyring more easily available 24x7 to lots of other people. Oops - replace "other people" with "&lt;span class="Apple-style-span" style="color: red;"&gt;unauthorized people&lt;/span&gt;" in that last sentence there. It's your secret key, it should be kept in safe storage by you, nobody else (at least not Google's search engine :-))&lt;br /&gt;--&lt;br /&gt;&lt;br /&gt;(I'm sorry #BankID, but I want my private key!)&lt;br /&gt;&lt;br /&gt;I'd like to hear your opinion, ideas, challenges or risk analysis on this subject. Shoot!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8400370148915075091-2270419271731717808?l=securitynirvana.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securitynirvana.blogspot.com/feeds/2270419271731717808/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://securitynirvana.blogspot.com/2011/07/securing-your-passwhhhhgp-private-key.html#comment-form' title='5 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/2270419271731717808'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/2270419271731717808'/><link rel='alternate' type='text/html' href='http://securitynirvana.blogspot.com/2011/07/securing-your-passwhhhhgp-private-key.html' title='Securing your passw^H^H^H^Hgp private key'/><author><name>Per Thorsheim</name><uri>https://profiles.google.com/113848325212589987956</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-skpoP167x04/AAAAAAAAAAI/AAAAAAAAAVU/RWc12nir74w/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_qyUrb02hPrA/TPLRdLjvhjI/AAAAAAAAAPE/a0BUL4dte3s/s72-c/426px-Public_key_making.svg.png' height='72' width='72'/><thr:total>5</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8400370148915075091.post-7229409262466501441</id><published>2011-07-04T08:45:00.000+02:00</published><updated>2011-07-04T08:45:08.799+02:00</updated><title type='text'>Passordsikkerhet fra MultiCase</title><content type='html'>&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-mevuLlKjOKI/Tg-OXXYFwOI/AAAAAAAAAWI/msrqQGVGHX8/s1600/Logo.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/-mevuLlKjOKI/Tg-OXXYFwOI/AAAAAAAAAWI/msrqQGVGHX8/s1600/Logo.png" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;i&gt;men hvordan er sikkerheten?&lt;/i&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;Multicase AS er et selskap som leverer et komplett forretningssystem til en lang rekke bedrifter i Norge. En av mange moduler er en løsning for netthandel. Selskapet oppgir selv en rekke&lt;a href="http://www.multicase.no/Avdelinger/Referanser-MultiCase-forretningssystem.aspx"&gt; referansekunder&lt;/a&gt; på sine nettsider, blant annet &lt;a href="http://www.bergans.no/"&gt;Bergans&lt;/a&gt;, &lt;a href="http://www.fotovideo.no/"&gt;FotoVideo&lt;/a&gt; og &lt;a href="http://www.netshop.no/"&gt;NetShop&lt;/a&gt;.&lt;i&gt; &lt;a href="http://www.google.no/#hl=no&amp;amp;pq=webshopen%20er%20levert%20av%20multicase%20norge%20as%20-site%3A.no&amp;amp;xhr=t&amp;amp;q=Webshopen%20er%20levert%20av%20MultiCase%20Norge%20AS&amp;amp;cp=41&amp;amp;pf=p&amp;amp;sclient=psy&amp;amp;tbo=1&amp;amp;biw=1920&amp;amp;bih=1085&amp;amp;tbs=qdr:m&amp;amp;source=hp&amp;amp;aq=f&amp;amp;aqi=&amp;amp;aql=&amp;amp;oq=Webshopen+er+levert+av+MultiCase+Norge+AS&amp;amp;pbx=1&amp;amp;bav=on.2,or.r_gc.r_pw.&amp;amp;fp=63a4b805b4e8c33d&amp;amp;bs=1"&gt;Flere kunder er lett å identifisere via Google&lt;/a&gt;&lt;/i&gt;.&amp;nbsp;&lt;b&gt;Sikkerheten rundt lagring og sending av passord i løsningen til Multicase er ikke i tråd med anbefalt god praksis.&lt;/b&gt;&amp;nbsp;&lt;i&gt;I ytterste konsekvens kan det få store konsekvenser for dem selv, deres kunder, og sluttbrukerne selv.&lt;/i&gt;&lt;br /&gt;&lt;i&gt;&lt;/i&gt;&lt;br /&gt;&lt;a name='more'&gt;&lt;/a&gt;&lt;b&gt;&lt;u&gt;Bakgrunn&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;Denne&amp;nbsp;historien startet med at en venn av meg tipset meg om at han hadde glemt sitt passord på NetShop, og gjennom "glemt passord" funksjonen der fikk han tilsendt brukernavn + passord i ubeskyttet e-post. Han fortalte meg også at store deler av nettsidene deres ikke benyttet SSL etter innlogging, slik at &lt;i&gt;sesjonskapring &lt;/i&gt;og uautorisert innsyn i hans aktiviteter hos NetShop kan være enkelt å utføre.&lt;br /&gt;&lt;br /&gt;På skriftlig henvendelse til NetShop fikk han til svar at hans passord lå lagret kryptert &lt;i&gt;(ikke &lt;b&gt;hashet&lt;/b&gt;), &lt;/i&gt;men at de hadde nevnt for systemleverandøren (Multicase) at de ønsket dette endret.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;u&gt;Verifisering&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;På bakgrunn av den informasjonen jeg fikk, samt min egen erfaring med FotoVideo (&lt;a href="http://securitynirvana.blogspot.com/2011/06/fy-til-fotovideo.html"&gt;som beskrevet i tidligere bloggpost&lt;/a&gt;), så har jeg brukt en god del tid på å vurdere hvorvidt jeg burde skrive denne bloggposten eller ikke. Jeg ønsker virkelig ikke å gi "hackerne" noen oppskrifter eller tips om hvordan de kan ødelegge enda mer enn de allerede gjør på Internett. Det ser for meg ut som om lagringen av passord i reverserbar kryptert form går igjen på tvers av deres kunder, og at utsendelse av brukernavn + passord i ukryptert passord også er en "standard" funksjon. Sistnevnte kan visstnok endres i systemoppsettet.&lt;br /&gt;&lt;br /&gt;Det at passordet blir sendt i ukryptert e-post er i seg selv en verifisering av at passordet enten lagres i klartekst (&lt;i&gt;=ubeskyttet)&lt;/i&gt;, eller at det lagres i en kryptert form. Dersom det lagres i en kryptert form, så er applikasjonene utstyrt med det nødvendige passordet for å kunne dekryptere passordet ved behov.&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;Jeg har ingen informasjon om hvorvidt passord faktisk blir lagret i kryptert form, ei heller om denne krypteringen på noen måte overholder anbefalte nøkkellengder og algoritmebruk pr dags dato. Det jeg vet er at testede nettbutikker basert på deres løsning ikke stiller de krav til brukernes passord som anses som minimum ift god praksis anbefalinger.&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;b&gt;&lt;u&gt;Anbefaling&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;Dersom du er kunde hos f.eks. FotoVideo eller Netshop, så vil jeg anbefale deg å kontakte selskapet og si at du forventer at de endrer sitt standard systemoppsett slik at de ikke sender ut brukernavn + passord i ubeskyttet e-post. Videre kan du også oppfordre dem til å gå over til &lt;i&gt;hashing&lt;/i&gt;&amp;nbsp;av lagrede passord, og at dette gjøres i tråd med god praksis anbefalinger. Hele prosessen rundt oppsett av nye brukere, endring av brukerinformasjon, lagring, verifisering og sending av passord med mer bør gjennomgås.&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;b&gt;Til Multicase&lt;/b&gt;: Merkelig nok så finner jeg ikke ordet &lt;b&gt;sikkerhet&lt;/b&gt;&amp;nbsp;brukt på noen av deres websider. Ovenstående kan ses på som et tips om å implementere sikkerhet på en enda bedre måte, og deretter bruke også det som et salgsargument for deres løsning?&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8400370148915075091-7229409262466501441?l=securitynirvana.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securitynirvana.blogspot.com/feeds/7229409262466501441/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://securitynirvana.blogspot.com/2011/07/passordsikkerhet-fra-multicase.html#comment-form' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/7229409262466501441'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/7229409262466501441'/><link rel='alternate' type='text/html' href='http://securitynirvana.blogspot.com/2011/07/passordsikkerhet-fra-multicase.html' title='Passordsikkerhet fra MultiCase'/><author><name>Per Thorsheim</name><uri>https://profiles.google.com/113848325212589987956</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-skpoP167x04/AAAAAAAAAAI/AAAAAAAAAVU/RWc12nir74w/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-mevuLlKjOKI/Tg-OXXYFwOI/AAAAAAAAAWI/msrqQGVGHX8/s72-c/Logo.png' height='72' width='72'/><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8400370148915075091.post-5310905414838585987</id><published>2011-07-01T11:36:00.001+02:00</published><updated>2011-08-26T18:48:13.002+02:00</updated><title type='text'>One Spam To Spam Them All!</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;b&gt;This is a plain boring blog post.&lt;/b&gt; In fact, it's a blog post that in a &lt;i&gt;perfect&lt;/i&gt; world would be completely unnecessary to write. In my world,&lt;b&gt; this blog post is necessary&lt;/b&gt; in order to make Microsoft Exchange admins, as well as mailgateway/antispam operators and operations security people aware of a very simple, but highly important configuration issue in Microsoft Exchange.&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;/div&gt;&lt;a name='more'&gt;&lt;/a&gt;&lt;b&gt;&lt;u&gt;I'll make this short:&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;A &lt;i&gt;Distribution list&lt;/i&gt;&amp;nbsp;in Microsoft Exchange is a group of users that will receive all e-mail sent to that list. In the screenshot below I've highlighted a distribution list, and added that list to the recipient list:&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-S_pOKq4OpIM/Tg192Y8iflI/AAAAAAAAAWE/sBTf1_p3c2U/s1600/Global_address_list_distrolist.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="244" src="http://1.bp.blogspot.com/-S_pOKq4OpIM/Tg192Y8iflI/AAAAAAAAAWE/sBTf1_p3c2U/s320/Global_address_list_distrolist.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;By double-clicking on the list, you get to see the properties of the lise, including its owner, and members of the list:&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-z0AYMbigNZA/Tg191TkAn3I/AAAAAAAAAV8/nRip92l5peA/s1600/distrolist_properties.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="206" src="http://4.bp.blogspot.com/-z0AYMbigNZA/Tg191TkAn3I/AAAAAAAAAV8/nRip92l5peA/s320/distrolist_properties.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Moving on to the &lt;b&gt;E-mail Addresses&lt;/b&gt;&amp;nbsp;tab, you get to see any and all SMTP addresses that has been automatically created for that distribution list upon creation &lt;i&gt;(sorry about all the blurring here, but you do understand why, right?)&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-6RC31CTCaK4/Tg191prFOOI/AAAAAAAAAWA/7C-AXbVLzpo/s1600/distrolist_smtp_address.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="206" src="http://4.bp.blogspot.com/-6RC31CTCaK4/Tg191prFOOI/AAAAAAAAAWA/7C-AXbVLzpo/s320/distrolist_smtp_address.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;b&gt;&lt;u&gt;Now for the "fun" part of this:&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;As far as I know, such lists will by default not be "protected" by default. Effectively that means a single e-mail from the Internet to this SMTP address will distribute to all members of the list. Suddenly having the &lt;i&gt;&lt;b&gt;all&lt;/b&gt; at &lt;b&gt;yourdomain.com&lt;/b&gt;&amp;nbsp;&lt;/i&gt;available for the CEO and the internal &lt;i style="font-weight: bold;"&gt;Pravda &lt;/i&gt;&lt;i&gt;(info)&lt;/i&gt;&amp;nbsp;department for internal announcements didn't seem like a good idea after all.&lt;br /&gt;&lt;br /&gt;Spam mail is filtered in many ways, such as looking for mail of equal size and contents, sent to a large number of e-mail adresses within a certain (short) time frame. As we've read about lately about &lt;b&gt;&lt;i&gt;APT&lt;/i&gt;&amp;nbsp;&lt;/b&gt;attacks, targeted &amp;nbsp;e-mail with malicious attachments have been sent to specific individuals and/or small groups of people.&lt;br /&gt;&lt;br /&gt;A single malicious e-mail sent to such a distribution list could very likely bypass several levels of antispam/antivirus controls, while reaching potentially every employees mailbox through Exchange and Outlook. &lt;b&gt;You don't want that to happen.&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;So before going on vacation for the summer, please ask your Exchange admins if they have read, understood and implemented the default setting of "From authenticated users only" for all existing and new distribution lists (&lt;a href="http://support.microsoft.com/kb/827616"&gt;MSKB827616&lt;/a&gt;). &lt;b&gt;This will effectively block such an attack. &lt;/b&gt;&lt;i&gt;(And as I've experienced first-hand many times if you don't block it; a lot of people calling you, asking W%&amp;amp;T¤%&amp;amp;#F?!?!?! ARE YOU DOING?&lt;/i&gt;)&lt;br /&gt;&lt;br /&gt;This is a quickwin. The only little problem; some distribution lists, perhaps like&lt;i&gt; info at yourdomain.com&lt;/i&gt;, are actually there to receive e-mail from unauthenticated users on the Internet. Take that into account before you set some poor Exchange admin into clicking his way through a few thousand distribution lists. :-)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8400370148915075091-5310905414838585987?l=securitynirvana.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securitynirvana.blogspot.com/feeds/5310905414838585987/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://securitynirvana.blogspot.com/2011/07/one-spam-to-spam-them-all.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/5310905414838585987'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/5310905414838585987'/><link rel='alternate' type='text/html' href='http://securitynirvana.blogspot.com/2011/07/one-spam-to-spam-them-all.html' title='One Spam To Spam Them All!'/><author><name>Per Thorsheim</name><uri>https://profiles.google.com/113848325212589987956</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-skpoP167x04/AAAAAAAAAAI/AAAAAAAAAVU/RWc12nir74w/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-S_pOKq4OpIM/Tg192Y8iflI/AAAAAAAAAWE/sBTf1_p3c2U/s72-c/Global_address_list_distrolist.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8400370148915075091.post-3402589662897072308</id><published>2011-06-30T00:29:00.000+02:00</published><updated>2011-06-30T00:29:02.732+02:00</updated><title type='text'>Passwords^11 - video archive</title><content type='html'>Finally, the video recordings in 720p HD MP4 format are now available for direct download through http/ftp at &lt;a href="http://ftp.ii.uib.no/pub/passwords11/"&gt;http://ftp.ii.uib.no/pub/passwords11/&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;At &lt;a href="http://ftp.ii.uib.no/pub/finse2011/"&gt;http://ftp.ii.uib.no/pub/finse2011/&lt;/a&gt; you will find some video recordings from the NISNET winter school at &lt;a href="http://www.finse1222.no/en"&gt;Finse&lt;/a&gt; (Norway). They are pretty long lectures (several hours), but still worth watching, depending on your interests of course. :-)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8400370148915075091-3402589662897072308?l=securitynirvana.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securitynirvana.blogspot.com/feeds/3402589662897072308/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://securitynirvana.blogspot.com/2011/06/passwords11-video-archive.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/3402589662897072308'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/3402589662897072308'/><link rel='alternate' type='text/html' href='http://securitynirvana.blogspot.com/2011/06/passwords11-video-archive.html' title='Passwords^11 - video archive'/><author><name>Per Thorsheim</name><uri>https://profiles.google.com/113848325212589987956</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-skpoP167x04/AAAAAAAAAAI/AAAAAAAAAVU/RWc12nir74w/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8400370148915075091.post-5641039969613466482</id><published>2011-06-27T23:30:00.000+02:00</published><updated>2011-06-27T23:30:15.652+02:00</updated><title type='text'>FY! til FotoVideo!</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-faN5UKGAeOo/TgjbMMwnfNI/AAAAAAAAAUc/46ArgHHZ1ys/s1600/fotovideo_logo.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/-faN5UKGAeOo/TgjbMMwnfNI/AAAAAAAAAUc/46ArgHHZ1ys/s1600/fotovideo_logo.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Å komme inn på FotoVideo butikken i Oslo var en drøm. Profesjonelle folk som virkelig tok seg tid til å lytte til mine behov (om enn aldri så urealistiske), og forklarte meg om smått og stort før jeg tok mine valg. En butikk som virkelig kan anbefales! &lt;i style="font-weight: bold;"&gt;Det vil si...&lt;/i&gt;&amp;nbsp;&lt;b&gt;inntil jeg oppdaget at it-sikkerhet overhodet ikke er deres fag. &lt;/b&gt;Faktisk såpass ille at jeg velger å påpeke det gjennom en offentlig bloggpost, i den tro at det vil føre til raskere endringer enn ellers. &lt;i&gt;Slemt?&lt;/i&gt; Ja. &lt;i&gt;Nødvendig?&lt;/i&gt; Etter å ha tenkt over det en god stund..&lt;b&gt; JA&lt;/b&gt;.&lt;br /&gt;&lt;br /&gt;&lt;a name='more'&gt;&lt;/a&gt;La oss begynne. Jeg var fysisk innom butikken for første gang, og kjøpte noen produkter der. I kassen ble jeg registrert som kunde, og oppga navn, adresse, telefonnummer og mailadresse. Ikke ulikt det man gjør de fleste steder i dag.&lt;br /&gt;&lt;br /&gt;For kort tid siden var jeg innom nettsidene til FotoVideo for å bestille noen minnekort til fotoapparat før ferien. Jeg ble rimelig overrasket da jeg skulle registrere meg som kunde på nettsiden deres at mailadressen min var i bruk allerede som brukernavn, jeg hadde jo ikke registrert meg der før? Så jeg gikk gjennom "glemt passord" funksjonen, og fikk tilsendt - SURPRISE! - en e-post i klartekst (=totalt ubeskyttet) som oppga nettsidens navn (&lt;i&gt;FotoVideo&lt;/i&gt;), mitt brukernavn (&lt;i&gt;min mailadresse&lt;/i&gt;) og mitt mobilnr som PASSORD. Til å være såpass interessert og erfaren ift passord så kan jeg vel ikke si at jeg ble nevneverdig overrasket, men like fullt: &lt;b&gt;DETTE ER UTROLIG DÅRLIG AV FOTOVIDEO!&lt;/b&gt;&lt;br /&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;br /&gt;Jeg kan overhodet ikke huske om de opplyste meg over disken at de la inn mitt mobilnr som mitt passord ved registrering av kjøp da jeg var der. Hadde de gjort det, så hadde jeg garantert protestert - og gitt de et gratis-på-stedet obligatorisk sikkerhetskurs. Det jeg frykter er at dette er "standard" rutine hos dem, og at det i så måte kan gjelde svært mange av deres kunder.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;i&gt;Men er det så galt da?&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;&lt;b&gt;Ja.&lt;/b&gt;&amp;nbsp;FotoVideo har denne fine beskrivelsen av sikkerhet på sin hjemmeside &lt;i&gt;(min understreking)&lt;/i&gt;:&lt;br /&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-ZEf-WX2aOUo/TgjbMa41OLI/AAAAAAAAAUg/ErG6gOWDyuQ/s1600/FotoVideo_Sikkerhet_27_06_2011.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="206" src="http://1.bp.blogspot.com/-ZEf-WX2aOUo/TgjbMa41OLI/AAAAAAAAAUg/ErG6gOWDyuQ/s320/FotoVideo_Sikkerhet_27_06_2011.png" width="320" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;i&gt;(Klikk for full størrelse)&lt;/i&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;b&gt;1. &lt;/b&gt;"&lt;i&gt;All informasjon som samles inn oppbevares på en sikker og fortrolig måte.&lt;/i&gt;"&lt;br /&gt;Feil. De samler inn informasjon, men unnlot, ihvertfall i mitt tilfelle, å informere om at de brukte mitt mobilnummer som mitt passord. Dersom min mistanke stemmer, så kan det være enkelt å få tilgang til kundeopplysninger, inkl. ordrehistorikk, servicehistorikk og så videre for deres kunder. At passordet og kanskje også øvrig kundeinformasjon enten lagres kryptert eller enda verre - i klartekst - er absolutt et brudd på anbefalt praksis.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;2. &lt;/b&gt;"&lt;i&gt;Etter vår mening er dette ikke sensitive eller kritiske data som kan misbrukes på noen måte&lt;/i&gt;".&lt;br /&gt;Jeg er uenig, og jeg tror mange andre vil være enig med meg. Hvilke varer jeg har kjøpt, til hvilken pris og på hvilket tidspunkt er i seg selv informasjon som kan misbrukes. Navn, adresse, mailadresse og mobilnummer er også informasjon som kan misbrukes. Her er noen av mine kundedata, lett sensurert (mine uthevinger i rødt):&lt;br /&gt;&lt;br /&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-CThxUHMLLFs/TgjbL_eKWQI/AAAAAAAAAUY/f1eyIqEb_zM/s1600/Dine_Kundedata.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="320" src="http://2.bp.blogspot.com/-CThxUHMLLFs/TgjbL_eKWQI/AAAAAAAAAUY/f1eyIqEb_zM/s320/Dine_Kundedata.png" width="314" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;i&gt;(Klikk for full størrelse)&lt;/i&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;Det interessante her er jo muligheten for å endre leveringsadresse, samt få tilsendt varene med faktura pr. 14 dager. Denne ordningen er i praksis en kredittkjøpsordning gjennom Gothia Finans AS. Selv om ordningen tilsier at bestilte varer blir sendt til adressen som er registrert på meg i folkeregisteret, så byr ikke en postkasse på særlige problemer. Det står ingenting om bruk av rekommandert sending her, og fakturaen sendes til min registrerte e-post adresse. Sistnevnte er jo også registrert hos FotoVideo, og kan lett endres. Om ikke annet så kan utenforstående få opprettet dyre kredittkjøpsavtaler og gjennom det inkassosaker på meg gjennom denne løsningen.&lt;br /&gt;&lt;blockquote&gt;&lt;b&gt;&lt;i&gt;Det er naivt å tro at personopplysninger, selv så uskyldige som de registrert hos FotoVideo, ikke kan misbrukes.&lt;/i&gt;&lt;/b&gt;&lt;/blockquote&gt;&lt;b&gt;Til FotoVideo:&lt;/b&gt;&lt;br /&gt;Dersom dere bruker kunders mailadresse og mobilnummer som standard brukernavn og passord, så bør dere endre den praksisen øyeblikkelig. Husk også å informere kundene om at dere gjør dette når de handler hos dere. Dere bør også vurdere å endre nettbutikk løsningen slik at brukernavn, passord og nettadresse ikke sendes ut i ukryptert e-post. Det er brudd på god praksis, og det er alt for enkelt å misbruke. Det gavner ingen dersom deres kunder blir svindlet, og dere mister kunder pga svak sikkerhet i nettløsningen deres.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8400370148915075091-5641039969613466482?l=securitynirvana.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securitynirvana.blogspot.com/feeds/5641039969613466482/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://securitynirvana.blogspot.com/2011/06/fy-til-fotovideo.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/5641039969613466482'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/5641039969613466482'/><link rel='alternate' type='text/html' href='http://securitynirvana.blogspot.com/2011/06/fy-til-fotovideo.html' title='FY! til FotoVideo!'/><author><name>Per Thorsheim</name><uri>https://profiles.google.com/113848325212589987956</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-skpoP167x04/AAAAAAAAAAI/AAAAAAAAAVU/RWc12nir74w/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-faN5UKGAeOo/TgjbMMwnfNI/AAAAAAAAAUc/46ArgHHZ1ys/s72-c/fotovideo_logo.png' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8400370148915075091.post-2885176982084727945</id><published>2011-06-16T21:18:00.000+02:00</published><updated>2011-06-16T21:18:15.813+02:00</updated><title type='text'>Passwords^11 - Thank you all!</title><content type='html'>&lt;b&gt;Oh boy, that was a *lot* of fun!&lt;/b&gt; Yes, I know I wouldn't probably say anything else since I was more or less the sole organizer of the conference, but I've received nothing but very positive feedback. Speakers and participants; all very positive and asking for another round. Here's my own summary of the conference, with some pictures, name dropping and loads of links you can click on. :-)&lt;br /&gt;&lt;br /&gt;&lt;a name='more'&gt;&lt;/a&gt;&lt;b&gt;First of all&lt;/b&gt; I will of course say a big thank you to &lt;a href="http://www.ii.uib.no/~torh/"&gt;Professor Tor Helleseth&lt;/a&gt;&amp;nbsp;at the &lt;a href="http://www.uib.no/rg/selmer"&gt;Selmer Center&lt;/a&gt;, part of the &lt;a href="http://www.uib.no/en"&gt;University of Bergen&lt;/a&gt;, as well as &lt;a href="http://www.nisnet.no/"&gt;NISNet&lt;/a&gt;. Altogether they believed in me, gave me a budget for the conference, let us all use their facilities at the university as well as buying us lunch, coffee and &lt;i&gt;&lt;a href="http://www.brodogkorn.no/oppskrifter/bergenske-skillingsboller/"&gt;Skillingsboller&lt;/a&gt;&lt;/i&gt; inbetween. Thank you!&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;Second &lt;/b&gt;I have to thank all the speakers who submitted speaking proposals and/or accepted my invitation to present at the conference. Without&amp;nbsp;&lt;a href="http://www.cl.cam.ac.uk/~fms27/"&gt;Professor Frank Stajano&lt;/a&gt;, &lt;a href="http://josefsson.org/"&gt;Simon Josefsson&lt;/a&gt;,&amp;nbsp;&lt;a href="http://www.nordrekalstad.com/kirsi"&gt;Professor Kirsi Helkala&lt;/a&gt;, &lt;a href="http://no.linkedin.com/in/bendikmjaaland"&gt;Bendik Mjaaland&lt;/a&gt;,&lt;a href="http://no.linkedin.com/pub/erlend-dyrnes/1/574/45"&gt; Erlend Dyrnes&lt;/a&gt;, &lt;a href="http://www.carmaa.com/site/Carsten_Maartmann-Moe.html"&gt;Carsten Maartmann-Moe&lt;/a&gt;, &lt;a href="http://quelrods.blogspot.com/"&gt;James Nobis&lt;/a&gt;, &lt;a href="http://www.elcomsoft.com/"&gt;Dmitry Sklyarov&lt;/a&gt;, and partially&amp;nbsp;&lt;a href="http://www.markus-jakobsson.com/"&gt;Markus Jakobsson&lt;/a&gt; &amp;amp; &lt;a href="http://www.cs.indiana.edu/~rakavipa/"&gt;Ruj Akavipat&lt;/a&gt; (presented by Frank Stajano), I would have to speak about passwords just a little longer than anybody would be interested in listening. Thank you all!&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;Third &lt;/b&gt;I must say thank you to my friends in our "&lt;a href="http://securitynirvana.blogspot.com/2011/04/security-think-tank.html"&gt;security think tank&lt;/a&gt;" (more formal name &amp;amp; logo to appear sometime in the future...). Great discussions on different security topics, closely and loosely related to passwords, lots of ideas for the conference! I should also include the assistance from &lt;a href="http://www.uib.no/persons/Alexander.Kholosha"&gt;Oleksandr Kholosha&lt;/a&gt; and &lt;a href="http://no.linkedin.com/pub/skibenes-elisabeth/5/a02/470"&gt;Elisabeth Skibenes&lt;/a&gt; for the many practical tasks you carried out before and during the conference. Highly appreciated!&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Fourth, A BIG THANK YOU&lt;/b&gt;&amp;nbsp;to all the participants at the conference, those (few) of you who dropped by our live stream at ustream.tv, and all others who in various ways participated in making Passwords^11 happen.&lt;br /&gt;&lt;br /&gt;Here are &lt;a href="http://www.flickr.com/photos/kluzz/sets/72157626922118872/with/5815247034/"&gt;some pictures&lt;/a&gt; from the conference taken by our very own KluZz, as well as &lt;a href="http://www.flickr.com/photos/57048029@N07/sets/72157626921995732/with/5814619115/"&gt;a few pictures&lt;/a&gt; from me while showing the city to Dmitry Sklyarov, Andy Malyshev (both with &lt;a href="http://www.elcomsoft.com/"&gt;Elcomsoft&lt;/a&gt;), as well as&lt;a href="http://www.its-blog.de/"&gt; Norbert Schmitz&lt;/a&gt;, our visiting Master student ("Guessing Passwords!") from Germany.&lt;br /&gt;&lt;blockquote&gt;&lt;i&gt;Just know this; I did ask KluZz to make me look young, smart and sexy, but he failed. ;-)&lt;/i&gt;&lt;/blockquote&gt;&lt;b&gt;Now for the cool news:&lt;/b&gt; Our little panel discussion (not available as video, sorry) ended up with no belief in getting rid of passwords anytime soon. Based on that, Passwords^XX will most probably happen once every year for the next three or four years here in Bergen.&lt;br /&gt;&lt;br /&gt;For those who prefer the US, there is a small chance you will see Passwords^XX happening over there as well, sometime during 2012. Currently starting discussions on that, so we'll see. Watch this blog for more news! :-)&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8400370148915075091-2885176982084727945?l=securitynirvana.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securitynirvana.blogspot.com/feeds/2885176982084727945/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://securitynirvana.blogspot.com/2011/06/passwords11-thank-you-all.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/2885176982084727945'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/2885176982084727945'/><link rel='alternate' type='text/html' href='http://securitynirvana.blogspot.com/2011/06/passwords11-thank-you-all.html' title='Passwords^11 - Thank you all!'/><author><name>Per Thorsheim</name><uri>https://profiles.google.com/113848325212589987956</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-skpoP167x04/AAAAAAAAAAI/AAAAAAAAAVU/RWc12nir74w/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8400370148915075091.post-8625242534497774972</id><published>2011-06-15T20:08:00.000+02:00</published><updated>2011-06-15T20:08:56.294+02:00</updated><title type='text'>Padding_____Haystacks</title><content type='html'>@itinsecurity asked me for a blog post regarding &lt;a href="https://www.grc.com/haystack.htm"&gt;Haystack&lt;/a&gt;, described as an&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&amp;nbsp;interactive brute force search space calculator. Haystack comes from&amp;nbsp;&lt;/span&gt;&amp;nbsp;from Gibson Research Corporation (&lt;a href="http://twitter.com/sggrc"&gt;@sggrc&lt;/a&gt;). I did retweet, asking &lt;a href="http://twitter.com/purehate_"&gt;@purehate_&lt;/a&gt;, @&lt;a href="http://twitter.com/iagox86"&gt;iagox86&lt;/a&gt;, @&lt;a href="http://twitter.com/lakiw"&gt;lakiw&lt;/a&gt;, @&lt;a href="http://twitter.com/quelrods"&gt;quelrods&lt;/a&gt;, @&lt;a href="http://twitter.com/CrackMeIfYouCan"&gt;CrackMeIfYouCan&lt;/a&gt; and&amp;nbsp;@&lt;a href="http://twitter.com/d3ad0ne_"&gt;d3ad0ne_&lt;/a&gt; &amp;nbsp;for their opinions as well. Since we're all above average interested in passwords, why not see if we have any opinions in common? :-)&lt;br /&gt;&lt;br /&gt;&lt;a name='more'&gt;&lt;/a&gt;@purehate_ replied with a link to a blog post from @d3ad0ne_ called "&lt;a href="http://ob-security.info/?p=351"&gt;Does password padding make your passwords more secure?&lt;/a&gt;", which I guess directly relates to the podcast from @sggrc and Haystack.&lt;br /&gt;&lt;br /&gt;@quelrods (James Nobis) has also written his &lt;a href="http://quelrods.blogspot.com/2011/06/grc-haystack.html"&gt;opinion on Haystack&lt;/a&gt;, as his very first blog post! (woohoo!)&lt;br /&gt;&lt;br /&gt;There's probably no point in writing much more;&lt;b&gt; I'll agree&lt;/b&gt; with purehate_, d3ad0ne_ and quelrods. Padding your password to lower the chances of crackers breaking it is not the best of ideas, as with probably ... oh.. a LOT of similar suggestions.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Lets talk a little psychology and security awareness instead.&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;I think we - as humans - are better at remembering positive things than the negative ones. Sure, there are some events way back there in your brain that won't go away anytime soon, but for most parts I think we're better at the positive things. I can still remember what color and type of clothes my wife was wearing the very first time I saw her. &lt;b&gt;Black trousers, black shoes, red sweater, oval green sign with "Smash" written in white.&lt;/b&gt; (she worked at a clothing store at the time). Could that sentence be my password^H^H^H^Hphrase? I'd love to see somebody crack that, with no prior knowledge of either password policy restrictions or my preferred choices of passwords.&lt;br /&gt;&lt;br /&gt;Obtaining a written password policy, as well as the various technical implementations, is "piece of cake". It's easy. It is so easy that calling it "social engineering" is.. well... an overstatement.&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;i&gt;On the other hand, you really don't need to talk to many users before they will curse you from here to anywhere, when you ask them about password policies and password construction schemes. Try your mother, probably a good place to start.&lt;/i&gt;&lt;/blockquote&gt;&lt;br /&gt;See; there are way too many security people out there trying to teach people advanced password construction schemes in order to create - AND REMEMBER - advanced passwords. Suddenly the poor end-users must not only try to remember their password, but the construction rules instead. It just doesn't work in most cases - at least not in the scenarios I've tried out. (I have to admit this sure is something I'm going to dig deeper into, along with psychologists and other people studying human behavior etc).&lt;br /&gt;&lt;br /&gt;That's why I've been telling my mom - and others - to write a sentence in normal language as their password. &lt;b&gt;Hey, it's summertime, barbeque and margueritas, here we come! &lt;/b&gt;Positive sentence, shouldn't be that hard to remember.&lt;br /&gt;&lt;br /&gt;Drop 99% of your written password policy and construction guidelines. It's pretty useless. People are just not interested. Breaks my securityheart, but not much to do about that. Tell them to use sentences. Positive ones. &lt;i&gt;Deploy electrical treatment to all programmers and sysadmins who refuses to implement UTF-8 length 255 password support.&lt;/i&gt;&lt;br /&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;br /&gt;&lt;b&gt;A large part of the problem is on our side. The security folks, the sysadmins, helpdesk who mess up everything, the haystacks of old and&amp;nbsp;&lt;/b&gt;&lt;b&gt;ridiculous policies stowed away in something called "QMS".&amp;nbsp;&lt;/b&gt;&lt;br /&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;br /&gt;Stop blaming the end-user every time something goes kaboom. To you they keep you with a job. Don't fight them, help them!&lt;br /&gt;&lt;br /&gt;--&lt;br /&gt;And that's it from the happy-shiny-people's department today.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8400370148915075091-8625242534497774972?l=securitynirvana.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securitynirvana.blogspot.com/feeds/8625242534497774972/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://securitynirvana.blogspot.com/2011/06/paddinghaystacks.html#comment-form' title='5 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/8625242534497774972'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/8625242534497774972'/><link rel='alternate' type='text/html' href='http://securitynirvana.blogspot.com/2011/06/paddinghaystacks.html' title='Padding_____Haystacks'/><author><name>Per Thorsheim</name><uri>https://profiles.google.com/113848325212589987956</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-skpoP167x04/AAAAAAAAAAI/AAAAAAAAAVU/RWc12nir74w/s512-c/photo.jpg'/></author><thr:total>5</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8400370148915075091.post-1952680063828531552</id><published>2011-06-10T12:42:00.000+02:00</published><updated>2011-06-10T12:42:15.985+02:00</updated><title type='text'>Password T-shirts</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-sVTfLziVwug/TfHzgCTBjRI/AAAAAAAAAUM/rodKtHBgFjY/s1600/123456.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="200" src="http://1.bp.blogspot.com/-sVTfLziVwug/TfHzgCTBjRI/AAAAAAAAAUM/rodKtHBgFjY/s200/123456.png" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;b&gt;James Nobis&lt;/b&gt; (&lt;a href="http://twitter.com/quelrods/"&gt;@quelrods&lt;/a&gt;) asked me about my password related t-shirts at &lt;b&gt;Passwords^11&lt;/b&gt;, ie if I had the designs available. Here are my own "designs" - it's just text - feel free to copy, print, use, sell as much as you like. :-) (Absolutely No Rights Reserved!)&lt;br /&gt;&lt;br /&gt;&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-ddSueJNeP-g/TfHzf1vv3iI/AAAAAAAAAUI/kVJkFnbgZdE/s1600/2factor.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="320" src="http://4.bp.blogspot.com/-ddSueJNeP-g/TfHzf1vv3iI/AAAAAAAAAUI/kVJkFnbgZdE/s320/2factor.png" width="320" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;i&gt;Thanks to Jan Fredrik Leversund (@KluZz) for this one. :-)&lt;/i&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;br /&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-sVTfLziVwug/TfHzgCTBjRI/AAAAAAAAAUM/rodKtHBgFjY/s1600/123456.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="320" src="http://1.bp.blogspot.com/-sVTfLziVwug/TfHzgCTBjRI/AAAAAAAAAUM/rodKtHBgFjY/s320/123456.png" width="320" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;i&gt;If you don't know the meaning of this one, you're not into passwords at all.&lt;/i&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;br /&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-5RGCi8my8Qw/TfHzgdvSxXI/AAAAAAAAAUQ/Z79Li9p1iv0/s1600/Incorrect.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="320" src="http://4.bp.blogspot.com/-5RGCi8my8Qw/TfHzgdvSxXI/AAAAAAAAAUQ/Z79Li9p1iv0/s320/Incorrect.png" width="320" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;i&gt;Based on a tweet from comedian Will Ferrell. :-)&lt;/i&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;br /&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-bno8hzc9csg/TfHzg8CVYyI/AAAAAAAAAUU/fnQRmVVbcF0/s1600/TBA.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="320" src="http://4.bp.blogspot.com/-bno8hzc9csg/TfHzg8CVYyI/AAAAAAAAAUU/fnQRmVVbcF0/s320/TBA.png" width="320" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;i&gt;My first t-shirt attempt to poke fun at the biometrics fans...&lt;/i&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8400370148915075091-1952680063828531552?l=securitynirvana.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securitynirvana.blogspot.com/feeds/1952680063828531552/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://securitynirvana.blogspot.com/2011/06/password-t-shirts.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/1952680063828531552'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/1952680063828531552'/><link rel='alternate' type='text/html' href='http://securitynirvana.blogspot.com/2011/06/password-t-shirts.html' title='Password T-shirts'/><author><name>Per Thorsheim</name><uri>https://profiles.google.com/113848325212589987956</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-skpoP167x04/AAAAAAAAAAI/AAAAAAAAAVU/RWc12nir74w/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-sVTfLziVwug/TfHzgCTBjRI/AAAAAAAAAUM/rodKtHBgFjY/s72-c/123456.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8400370148915075091.post-4214192404423758629</id><published>2011-06-05T00:37:00.005+02:00</published><updated>2011-06-05T00:41:59.903+02:00</updated><title type='text'>Passord - 2 Eksempler til #DLD &amp; Advarsel</title><content type='html'>7-8 Juni arrangerer jeg for andre gang det jeg tror er verdens eneste konferanse som utelukkende handler om passord og PIN koder, kalt &lt;b&gt;Passwords^11&lt;/b&gt;. Dette gjøres i samarbeid med &lt;a href="http://www.ii.uib.no/~torh/"&gt;Professor Tor Helleseth&lt;/a&gt; ved &lt;a href="http://www.uib.no/fg/selmer"&gt;Selmer senteret&lt;/a&gt;,&amp;nbsp;Universitetet i Bergen, og med finansiell støtte fra &lt;a href="http://www.nisnet.no/"&gt;NISNET&lt;/a&gt;&amp;nbsp;(Fra Norges Forskningsråd). Din første tanke etter de to første setningene er kanskje "&lt;i&gt;er det mulig?&lt;/i&gt;". Det er det, og det er en sikkerhetskonferanse som &amp;nbsp;er mer aktuell enn noensinne å arrangere. Her skal du få 2 konkrete eksempler fra min hverdag som forhåpentligvis aktualiserer konferansen også for deg.&lt;br /&gt;&lt;br /&gt;&lt;a name='more'&gt;&lt;/a&gt;&lt;b&gt;1. Bergen Bompengeselskap (Bro- og Tunnelselskapet AS)&lt;/b&gt;&lt;br /&gt;Jeg bor i Bergen, og kjører til jobb daglig. Det samme gjør kjæresten min, og innebærer daglige passeringer gjennom bompengeringen i Bergen. Bro- og Tunnelselskapet AS er ansvarlig selskap for bompengesystemet, og de benytter &lt;a href="http://www.q-free.com/"&gt;Q-Free&lt;/a&gt;&amp;nbsp;sine løsninger. &lt;a href="https://bergen.csautopass.no/"&gt;På websidene til Bro- og Tunnelskapet AS&lt;/a&gt;&amp;nbsp;kan jeg logge inn for å se og endre mine abonnementsdetaljer, samt se alle mine passeringer de siste 6 måneder. Ja, jeg kan til og med se alle passeringene som min kjæreste har foretatt også, om ønskelig. Akkurat det kan jo naturlig nok unngås ved at hun har egen avtale, men det er en annen historie.&lt;br /&gt;&lt;blockquote&gt;Bro- og Tunnelselskapet har en &lt;b&gt;SKREMMENDE&lt;/b&gt;&amp;nbsp;&lt;b&gt;DÅRLIG&amp;nbsp;&lt;/b&gt;sikkerhet tilknyttet passord i sin løsning. Det er &lt;b&gt;svært enkelt&lt;/b&gt; for andre å oppnå &lt;b&gt;uautorisert tilgang&lt;/b&gt;&amp;nbsp;til &lt;b&gt;ditt abonnement&lt;/b&gt;, inkludert registrere andre kjøretøy på ditt abonnement, slik at&lt;b&gt; du betaler for dem.&lt;/b&gt;&amp;nbsp;Ikke minst, som et innlegg til debatten om Datalagringsdirektivet: &lt;b&gt;De kan få sett alle dine passeringer de siste 6 måneder.&lt;/b&gt;&lt;/blockquote&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;Jeg har tatt skjermbilder for å illustrere tydelig hva jeg mener &lt;i&gt;(du kan klikke på bildene for å full størrelse)&lt;/i&gt;:&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-xNpyScuVsKE/TeqTctnI_yI/AAAAAAAAATo/LYyQ7fzVMeg/s1600/01_Login.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="134" src="http://1.bp.blogspot.com/-xNpyScuVsKE/TeqTctnI_yI/AAAAAAAAATo/LYyQ7fzVMeg/s320/01_Login.png" width="320" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;i&gt;Standard innloggingsbilde for Bergen Bompengeselskap AS&lt;/i&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;Bildet over viser standard pålogging når man skal logge seg inn hos Bro- og Tunnelselskapet AS. Her klikker jeg på "Forgot password" (glemt passord), og får opp bildet under:&lt;br /&gt;&lt;br /&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-4Y63g1bvLGc/TeqTdIcOvbI/AAAAAAAAATs/UkgJ8rzxb-M/s1600/02_Forgot_password.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="109" src="http://2.bp.blogspot.com/-4Y63g1bvLGc/TeqTdIcOvbI/AAAAAAAAATs/UkgJ8rzxb-M/s320/02_Forgot_password.png" width="320" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;i&gt;Skriv inn e-post adresse eller kundeID ved glemt passord&lt;/i&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;Jeg skriver inn min e-post adresse, alternativt kundenummer, &lt;b&gt;&lt;i&gt;for å få tilsendt&lt;/i&gt;&lt;/b&gt; &lt;b&gt;&lt;i&gt;mitt eksisterende brukernavn og passord via ukryptert e-post!&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-cqsi0gvAoLg/TeqTdV7QWsI/AAAAAAAAATw/9Ekf9zGrVdo/s1600/03_Forgot_password.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="87" src="http://4.bp.blogspot.com/-cqsi0gvAoLg/TeqTdV7QWsI/AAAAAAAAATw/9Ekf9zGrVdo/s320/03_Forgot_password.png" width="320" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;i&gt;Bekreftelse etter å ha tastet inn min e-post adresse&lt;/i&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;Etter å ha skrevet inn min e-post adresse, så får jeg bekreftelsen over om at jeg får en e-post ganske straks. Og helt riktig, e-post kommer på få sekunder:&lt;br /&gt;&lt;br /&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-TUl_tmq6CDY/TeqTeR9_FXI/AAAAAAAAAT4/HHoQ8xmpgpo/s1600/E-mail_with_customer_id_and_password_cleartext.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="58" src="http://1.bp.blogspot.com/-TUl_tmq6CDY/TeqTeR9_FXI/AAAAAAAAAT4/HHoQ8xmpgpo/s320/E-mail_with_customer_id_and_password_cleartext.png" width="320" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;i&gt;Ukryptert mail fra Bro- og Tunnelselskapet...&lt;/i&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;b&gt;E-posten som kommer er ubeskyttet. Den inneholder min brukeridentitet (kundenummer), mitt passord og all annen informasjon som gjør andre i stand til å misbruke mitt abonnement, samt overvåke mine bompasseringer (samt min kjæreste). Det er ikke mulig for meg å undersøke hvor mange mennesker som ulovlig og uten spor kan plukke opp denne e-posten og misbruke informasjonen. Svært snill gjetting tilsier noen titalls personer. Minst. &lt;/b&gt;&lt;i&gt;(Ja, passordet som vises i bildet over er faktisk det passordet jeg brukte tidligere hos Bro- og Tunnelselskapet AS...)&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-MLFk0tNdYGQ/TeqTd0v7dwI/AAAAAAAAAT0/DhuapGv6hik/s1600/04_Forgot_Customer_ID.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="130" src="http://4.bp.blogspot.com/-MLFk0tNdYGQ/TeqTd0v7dwI/AAAAAAAAAT0/DhuapGv6hik/s320/04_Forgot_Customer_ID.png" width="320" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;i&gt;Alternativt skriv inn registreringnr + brikkeID&lt;/i&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;Dersom du ikke husker hverken kundenummer, passord eller din egen e-post adresse, eventuelt har fått ny eller har aldri registrert noen e-post adresse hos Bro- og Tunnelselskapet, så kan du skrive inn registreringsnummeret på bilen, samt BrikkeID. &lt;i&gt;Men vent nå litt; hvor finner jeg det?&lt;/i&gt; &lt;b&gt;Her:&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-3o0V1wZ-l54/TeqWEvwfYnI/AAAAAAAAAT8/PyoEhIiltEo/s1600/Q-Free_1.jpg" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="320" src="http://1.bp.blogspot.com/-3o0V1wZ-l54/TeqWEvwfYnI/AAAAAAAAAT8/PyoEhIiltEo/s320/Q-Free_1.jpg" width="291" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;i&gt;Plassering av Q-Free brikke i frontvindu på bil&lt;/i&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;Eller nærmere bestemt, når jeg flytter meg nærmere med kameraet:&lt;br /&gt;&lt;br /&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-OvqQtLNA0b4/TeqWE1RaAJI/AAAAAAAAAUA/tquRAhxNxK4/s1600/Q-Free_Serial_2.jpg" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="191" src="http://3.bp.blogspot.com/-OvqQtLNA0b4/TeqWE1RaAJI/AAAAAAAAAUA/tquRAhxNxK4/s320/Q-Free_Serial_2.jpg" width="320" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;i&gt;Q-Free BrikkeID lett synlig gjennom frontvindu på bil&lt;/i&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;div style="text-align: left;"&gt;Det å finne registreringsnummeret på en bil er jo ingen kunst, for å si det enkelt. Ei heller er det noe vanskelig å identifisere eieren når du har registreringsnummeret. Sist men ikke minst noterer man seg brikkeID'en, slik den er trykket klart og tydelig på brikken slik du ser på bildet over.&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;Dersom eieren ikke har registrert en e-post adresse, eller du kontakter selskapet på telefon, så kan du få tilsendt alle nødvendige opplysninger i et vanlig brev. En antatt enda enklere metode for enhver skurk som ønsker å utnytte de muligheter denne mangelen på sikkerhet faktisk gir.&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;Det er svært vanskelig for meg å tro at det er gjort noen skriftlig risikoanalyse som tilsier at denne måten å gjøre det på er innenfor akseptable grenser. Det er lite - om noe - i deres løsning som tilfredsstiller dokumentert god praksis fra anerkjente og nøytrale institusjoner på Internett, inkludert den Norske stat selv (&lt;a href="http://norsis.no/"&gt;NorSIS.no&lt;/a&gt; og &lt;a href="http://nettvett.no/"&gt;Nettvett.no&lt;/a&gt;).&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;Bro- &amp;amp; Tunnelselskapet AS er eid av Hordaland Fylkeskommune (ca 27%) og Bergen Kommune (ca 24%), øvrige 49% av andre finansielle institusjoner. Jeg vil varsle både kommune og fylkeskommune om ovenstående.&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;Jeg kunne skrevet enda mer, men ovenstående bør være mer enn nok for å få Datatilsynet på banen. Det er fristende å tro at dette også har interesse for &lt;a href="http://stoppdld.no/"&gt;Stopp Datalagringsdirektivet&lt;/a&gt;? Et søk i &lt;a href="http://oep.no/nettsted/fad"&gt;Offentlig Elektronisk Postjournal&lt;/a&gt;&amp;nbsp;på søkeordet &lt;b&gt;passord&lt;/b&gt;&amp;nbsp;avdekker flere konkrete tilfeller av samme type - og fortsatt finnes det utallige tilsvarende eksempler bare innen Norges grenser.&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;----&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;b&gt;2. Selvbetjente innsjekkingsautomater på Norske flyplasser&lt;/b&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;Bildet under har jeg fått fra en venn som tok bildet på &lt;a href="http://www.avinor.no/lufthavn/bergen"&gt;Bergen Lufthavn Flesland&lt;/a&gt;, høsten 2010. Det viser skjermen på en selvbetjent innsjekkingsautomat i avgangshallen som har startet på nytt, og hvor man må trykke Ctrl+Alt+Delete for å logge på. Skjermbildet i bakgrunnen har en tabell oppe til høyre med brukernavn, passord og tidligere brukte passord.&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;Jeg vil ikke gi her noen ideer eller utdype hvordan dette kunne blitt utnyttet, av naturlige årsaker. Det er bare å slå fast at en slik praksis, dersom den stemmer overens med skjermbildet, ikke er i tråd med regulatoriske krav til en slik løsning. Det verste er at jeg ikke vet hvem som er ansvarlige for disse innsjekkingsautomatene, men antagelig ikke Avinor selv.&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-gPhOsNQiIno/TeqwuZK8rkI/AAAAAAAAAUE/GOx71GfTpYM/s1600/Innsjekkingsautomat_Flesland_2010.jpg" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="320" src="http://1.bp.blogspot.com/-gPhOsNQiIno/TeqwuZK8rkI/AAAAAAAAAUE/GOx71GfTpYM/s320/Innsjekkingsautomat_Flesland_2010.jpg" width="302" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;i&gt;Skjermbilde fra innsjekkingsautomat på Flesland, Bergen.&lt;/i&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8400370148915075091-4214192404423758629?l=securitynirvana.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securitynirvana.blogspot.com/feeds/4214192404423758629/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://securitynirvana.blogspot.com/2011/06/passord-2-eksempler-til-dld-advarsel.html#comment-form' title='5 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/4214192404423758629'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/4214192404423758629'/><link rel='alternate' type='text/html' href='http://securitynirvana.blogspot.com/2011/06/passord-2-eksempler-til-dld-advarsel.html' title='Passord - 2 Eksempler til #DLD &amp; Advarsel'/><author><name>Per Thorsheim</name><uri>https://profiles.google.com/113848325212589987956</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-skpoP167x04/AAAAAAAAAAI/AAAAAAAAAVU/RWc12nir74w/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-xNpyScuVsKE/TeqTctnI_yI/AAAAAAAAATo/LYyQ7fzVMeg/s72-c/01_Login.png' height='72' width='72'/><thr:total>5</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8400370148915075091.post-6197849239418667506</id><published>2011-05-16T23:39:00.000+02:00</published><updated>2011-05-16T23:39:24.142+02:00</updated><title type='text'>Sony #PSN Password Resets: Inconsistent &amp; Inadequate?</title><content type='html'>Sony's Playstation Network (PSN), has been offline for a long time. You know the reason for that by now. Following @mikkohypponen and others on Twitter, I saw that #PSN would open up again, territory by territory. I downloaded and installed the mandatory v3.61 update, eagerly awaiting some serious pwning in MW2:Black Ops again. Just had to change my password first, according to tweets and &lt;a href="http://uk.playstation.com/home/news/articles/detail/item369506/PlayStation-Network-Restoration-Begins/"&gt;Sony themselves in a blog post&lt;/a&gt;. You know; for my own security. Thanks to Sony for taking care of me!&lt;br /&gt;&lt;br /&gt;&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;As most people I know, RTM or RTMF just doesn't stick to the top&amp;nbsp;&lt;span class="Apple-style-span" style="font-family: sans-serif; font-size: 13px; line-height: 19px;"&gt;&lt;b&gt;&lt;a href="http://en.wikipedia.org/wiki/Polytetrafluoroethylene"&gt;polytetrafluoroethylene&lt;/a&gt;&lt;/b&gt;&lt;/span&gt;&amp;nbsp;coating. Try first, try a few more times, than eventually cave in and RTM. Easy.&lt;br /&gt;&lt;br /&gt;Whoa... Wait a minute. Passwords first, MW2:Black Ops second. Lets take a look at the process for my multiple password resets using my PS3 as well as the web, and look for differences and weaknesses.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;First of all: the PS3 process&lt;/b&gt;. Screenshots using my HTC Desire against my 100" and a Sony (!) VPL-HW15 projector.&lt;br /&gt;&lt;br /&gt;Updated to v3.61. Request to logon to #PSN, this is what I get:&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-4EftmJEGHAk/TdGDiAiIYfI/AAAAAAAAAS4/9kUU4Za6x8A/s1600/01.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="224" src="http://2.bp.blogspot.com/-4EftmJEGHAk/TdGDiAiIYfI/AAAAAAAAAS4/9kUU4Za6x8A/s320/01.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&amp;nbsp;Ok, sure. If your organisation and/or your customers has been pwned: &lt;b&gt;DO A COMPLETE PASSWORD RESET FOR ALL ACCOUNTS.&lt;/b&gt;&amp;nbsp;(Sorry for the bold capital text there, but hey; it's important!). So far, so good.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-d4TVotFRAic/TdGDiqUZcPI/AAAAAAAAAS8/o3Fl-P1jrRg/s1600/02.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="247" src="http://2.bp.blogspot.com/-d4TVotFRAic/TdGDiqUZcPI/AAAAAAAAAS8/o3Fl-P1jrRg/s320/02.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Ah. Password requirements. At least length eight, numbers and letters. Ok. Lets try out the most common of them all &lt;i&gt;(remember RockYou?)&lt;/i&gt;&lt;b&gt;&lt;i&gt;: &lt;/i&gt;123456&lt;/b&gt;.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-M5LQtwGiXt4/TdGDi8WUOUI/AAAAAAAAATA/n7HLMDyaNjM/s1600/03.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="176" src="http://2.bp.blogspot.com/-M5LQtwGiXt4/TdGDi8WUOUI/AAAAAAAAATA/n7HLMDyaNjM/s320/03.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Nope, that didn't work, and they do tell me which requirements my attempt didn't fulfill. GOOD! Some complexity and pattern matching rules here as well; PLEASE notice the last one: "&lt;b&gt;The password must be different than your previous password&lt;/b&gt;". Ahhh. Password history I see, good that might be. Well: lets try the &lt;a href="http://securitynirvana.blogspot.com/2010/02/criticism-of-pci-password-requirements.html"&gt;PCI DSS compatible password&lt;/a&gt; then: &lt;b&gt;password1 &lt;/b&gt;&lt;i&gt;(That's a single digit at the end there...)&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-YXdeZDaLUNg/TdGDjAFetII/AAAAAAAAATE/-zxSVRDNCXc/s1600/04.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="260" src="http://4.bp.blogspot.com/-YXdeZDaLUNg/TdGDjAFetII/AAAAAAAAATE/-zxSVRDNCXc/s320/04.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Hrmf. Well, say whatever you want: &lt;b&gt;password1 &lt;/b&gt;is NOT what I would consider a good password. As far as most recommendations from non-commercial organisations goes, the minimum requirement today is for a &lt;b&gt;MixAlphaNumeric&lt;/b&gt;&amp;nbsp;minimum &lt;b&gt;length 8&lt;/b&gt;&amp;nbsp;password. Not that &lt;b&gt;Password1&lt;/b&gt;&amp;nbsp;would be much better, but again: my own research shows that as much as 50% of users that are forced to comply with a mixalphanumeric policy will use the pattern of UPPERlowerlowerlowerlowerlowerdigitdigit (or 2 additional digits). The keyspace is considerable, while reality is not. But hey; you'll learn more about such things at &lt;a href="http://securitynirvana.blogspot.com/2011/04/passwords11-register-now.html"&gt;Passwords^11&lt;/a&gt;. :-)&lt;br /&gt;&lt;br /&gt;Just a final screenshot to show a heavily censored version of which data you could get access to using my PS3 and knowing my password. &lt;i&gt;(Card number: first4 as well as last 4 digits, no security code)&lt;/i&gt;:&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-gyTh5bFNM4I/TdGDjdrrZMI/AAAAAAAAATI/jR5OzoNCbOU/s1600/05.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="215" src="http://3.bp.blogspot.com/-gyTh5bFNM4I/TdGDjdrrZMI/AAAAAAAAATI/jR5OzoNCbOU/s320/05.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Well. So far so good. Or not? Well, &lt;b&gt;password1&lt;/b&gt;&amp;nbsp;for sure is not acceptable to me. Entering that password using my PS3 controller was more than enough, can't imagine too many people enter a length 12+ MixAlphaNumericSpecials password using their PS3 controller, even if the password gets stored locally after entering it.&lt;br /&gt;&lt;br /&gt;So I had to do a another round or two - or three - of "lost password", just to see what that looked like. Back down to my home office and my computers. &lt;b&gt;Pleasant surprise:&lt;/b&gt;&amp;nbsp;DoNotReply@ac.playstation.net had sent me an e-mail with the subject: &lt;b&gt;PlayStation(R)Network Password Change&lt;/b&gt;. Nice. I think that a default opt-out option should be available in online services, where the default setting will send you some kind of confirmation if/when security settings related to your account are changed in any way.&lt;br /&gt;&lt;br /&gt;Browsing to www.playstation.com, "Sign in", "Forgot password", and voila:&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-NsJTqJJOasY/TdGOOrpL1EI/AAAAAAAAATM/JGOKBFXTYXU/s1600/00_Lost_password_web.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="183" src="http://4.bp.blogspot.com/-NsJTqJJOasY/TdGOOrpL1EI/AAAAAAAAATM/JGOKBFXTYXU/s320/00_Lost_password_web.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;Date of birth? Hm. Not too difficult to remember for most of us, and just a little bit more programming to do for an attacker to bypass. Nice. &lt;i&gt;(Forgive me again for the heavy censorship, I'm sure you understand...)&lt;/i&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-TRJ03TxXqkE/TdGOPFB8zMI/AAAAAAAAATQ/2gT35rNgTRA/s1600/01_Select_password_reset_option.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="58" src="http://1.bp.blogspot.com/-TRJ03TxXqkE/TdGOPFB8zMI/AAAAAAAAATQ/2gT35rNgTRA/s320/01_Select_password_reset_option.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Only one method for resetting my password available, but I've got to say I really hope to see more and better alternatives here in the future.&lt;i&gt; "Please dial this premium number in Japan. If your callerID matches the number entered into your profile using your PS3, we'll give you a 10-digit OTP valid for 30 minutes to reset your password". &lt;/i&gt;Ah well, got carried away there, replacing Sony's losses over #PSN downtime.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-b43FlegiImI/TdGOPfMToLI/AAAAAAAAATU/gTOff--TTW4/s1600/02_Pwd_reset_mail_confirmation.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="17" src="http://3.bp.blogspot.com/-b43FlegiImI/TdGOPfMToLI/AAAAAAAAATU/gTOff--TTW4/s320/02_Pwd_reset_mail_confirmation.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Getting a confirmation on screen telling me that an e-mail has been sent to my e-mail address, which is also my logon id. Some comments here:&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;I've written about &lt;a href="http://securitynirvana.blogspot.com/2009/11/guarding-your-usernames.html"&gt;Guarding your usernames&lt;/a&gt; earlier. I'll stand by that, pointing my finger at Sony as well as others for not giving me any alternatives.&lt;/li&gt;&lt;li&gt;The way Sony has implemented this&lt;b&gt;&amp;nbsp;may&lt;/b&gt;&amp;nbsp;enable easier identification of correct e-mails and birth dates. Another take, which I've seen at some sites, is to say something like "An e-mail has now been sent to your registered address, as long as the data entered are correct". Not sure about the usability vs security aspect there yet, still spending time thinking about it.&amp;nbsp;&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;Anyway; the e-mail from &lt;b&gt;DoNotReply...&lt;/b&gt;&amp;nbsp;came within seconds, containing an &lt;b&gt;https&lt;/b&gt;&amp;nbsp;link to &lt;b&gt;store.playstation.com&lt;/b&gt;/(something...), with a &lt;b&gt;timeout value of 3 hours&lt;/b&gt; from the time it was sent. There are other variations around of that timeout, IF they have one at all.&lt;br /&gt;&lt;br /&gt;For those paranoid among us: clicking the link gives me a case-sensitive &lt;a href="http://en.wikipedia.org/wiki/CAPTCHA"&gt;CAPTCHA&lt;/a&gt;. Wow. Well, I did it in 3 attempts. :-) &lt;i&gt;(Always a good idea to be a bit careful with capital i and so on in captchas...)&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-jc4z3jt2R9w/TdGOPr2yU2I/AAAAAAAAATY/xF93x2P96wc/s1600/04_password_reset_CAPTCHA_case_sensitive.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="156" src="http://3.bp.blogspot.com/-jc4z3jt2R9w/TdGOPr2yU2I/AAAAAAAAATY/xF93x2P96wc/s320/04_password_reset_CAPTCHA_case_sensitive.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Lets see if the web interface will allow me to use &lt;b&gt;a&lt;/b&gt;&amp;nbsp;as my password. &lt;i&gt;(A favorite test of mine for sure!)&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-KRt3OFCMGiA/TdGOP_wxq0I/AAAAAAAAATc/IJikuqg-n-I/s1600/05_reset_pwd_testing_a.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="156" src="http://1.bp.blogspot.com/-KRt3OFCMGiA/TdGOP_wxq0I/AAAAAAAAATc/IJikuqg-n-I/s320/05_reset_pwd_testing_a.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Nope, didn't work. Instead I get a banner stating the password policy:&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-U7kO_fS70M0/TdGOQIB7ytI/AAAAAAAAATg/eQID0sQD_i4/s1600/06_pwd_policy_on_web.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="95" src="http://3.bp.blogspot.com/-U7kO_fS70M0/TdGOQIB7ytI/AAAAAAAAATg/eQID0sQD_i4/s320/06_pwd_policy_on_web.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;Hey! There's something wrong here! Compare this image above to the one below. Seems like Sony #PSN isn't completely consistent in their password policy, differentiating between passwords entered through the web or using the PS3s own interface? Hmmmm.... &lt;b&gt;Could there be more weaknesses here? &lt;/b&gt;&lt;i&gt;(Please continue to read below...)&lt;/i&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-M5LQtwGiXt4/TdGDi8WUOUI/AAAAAAAAATA/n7HLMDyaNjM/s1600/03.jpg" imageanchor="1" style="display: inline !important; margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="176" src="http://2.bp.blogspot.com/-M5LQtwGiXt4/TdGDi8WUOUI/AAAAAAAAATA/n7HLMDyaNjM/s320/03.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-kSpMFR5DFNM/TdGOQsgJC9I/AAAAAAAAATk/ekbFIQzi1ls/s1600/07_Account_pwd_updated.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="19" src="http://2.bp.blogspot.com/-kSpMFR5DFNM/TdGOQsgJC9I/AAAAAAAAATk/ekbFIQzi1ls/s320/07_Account_pwd_updated.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;b&gt;There are.&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;See that last sentence there? &lt;b&gt;"The password must be different than your previous password?"&lt;/b&gt;. Doesn't seem to be implemented. I've changed away from &lt;b&gt;password1&lt;/b&gt;, then back again, then away from it again. Not much sign of any password history being kept there. Could be a good thing, as I've written about in an earlier blog post entitled &lt;b&gt;&lt;a href="http://securitynirvana.blogspot.com/2009/11/why-history-may-be-bad-for-you.html"&gt;Why History May Be Bad For You&lt;/a&gt;. &lt;/b&gt;I really don't like to see written password policies &lt;b&gt;not&lt;/b&gt;&amp;nbsp;getting implemented to the word. It just make things harder for end users. The policy says one thing, the system apparently require something else.&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;b&gt;My main concern with this:&lt;/b&gt; If Sony #PSN doesn't enforce this policy requirement, how many of their 70+ million customers will eventually type in the same previous password as they've used all along? The password that apparently has been compromised already? Any chance Sony would do a limited NDA based release of their user database, so that others could take actions to protect their own customers, like Linkedin did after the Gawker compromise? I guess not.&lt;/blockquote&gt;&lt;br /&gt;If you get compromised, you are compromised and you will basically remain compromised unless you change everything, including your users.&lt;br /&gt;&lt;br /&gt;Now if you'll excuse me, I'm going to play Modern Warfare 2 : Black Ops on #PSN. I just have to delete my credit card details from my #PSN profile first.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8400370148915075091-6197849239418667506?l=securitynirvana.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securitynirvana.blogspot.com/feeds/6197849239418667506/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://securitynirvana.blogspot.com/2011/05/sony-psn-password-resets-inconsistent.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/6197849239418667506'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/6197849239418667506'/><link rel='alternate' type='text/html' href='http://securitynirvana.blogspot.com/2011/05/sony-psn-password-resets-inconsistent.html' title='Sony #PSN Password Resets: Inconsistent &amp; Inadequate?'/><author><name>Per Thorsheim</name><uri>https://profiles.google.com/113848325212589987956</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-skpoP167x04/AAAAAAAAAAI/AAAAAAAAAVU/RWc12nir74w/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-4EftmJEGHAk/TdGDiAiIYfI/AAAAAAAAAS4/9kUU4Za6x8A/s72-c/01.jpg' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8400370148915075091.post-5096868877380297376</id><published>2011-05-05T21:49:00.002+02:00</published><updated>2011-05-13T23:25:45.197+02:00</updated><title type='text'>Passwords^11 - Program &amp; abstracts are ready!</title><content type='html'>The program as well as abstracts for the academic talks at Passwords^11 are now available!&amp;nbsp;I have added them to the &lt;a href="http://securitynirvana.blogspot.com/2011/04/passwords11-register-now.html"&gt;registration blog post&lt;/a&gt;, or you can get them directly here: &lt;a href="http://home.online.no/~putilutt/passwords11/Passwords11_Final_Program.pdf"&gt;Program (pdf, 200kb)&lt;/a&gt;, &lt;a href="http://home.online.no/~putilutt/passwords11/Passwords11_abstracts.pdf"&gt;Abstracts (pdf, 172kb)&lt;/a&gt;. I hope to see you at Passwords^11!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8400370148915075091-5096868877380297376?l=securitynirvana.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='enclosure' type='application/pdf' href='http://home.online.no/~putilutt/passwords11/Passwords11_Final_Program.pdf' length='0'/><link rel='enclosure' type='application/pdf' href='http://home.online.no/~putilutt/passwords11/Passwords11_abstracts.pdf' length='0'/><link rel='replies' type='application/atom+xml' href='http://securitynirvana.blogspot.com/feeds/5096868877380297376/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://securitynirvana.blogspot.com/2011/05/passwords11-program-abstracts-are-ready.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/5096868877380297376'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/5096868877380297376'/><link rel='alternate' type='text/html' href='http://securitynirvana.blogspot.com/2011/05/passwords11-program-abstracts-are-ready.html' title='Passwords^11 - Program &amp; abstracts are ready!'/><author><name>Per Thorsheim</name><uri>https://profiles.google.com/113848325212589987956</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-skpoP167x04/AAAAAAAAAAI/AAAAAAAAAVU/RWc12nir74w/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8400370148915075091.post-8136493086901193425</id><published>2011-04-26T00:00:00.004+02:00</published><updated>2011-04-26T00:08:57.340+02:00</updated><title type='text'>Dynamic Prevention of Common Passwords</title><content type='html'>Remember the 370 passwords you were not allowed to use on Twitter? If not, &lt;a href="http://techcrunch.com/2009/12/27/twitter-banned-passwords/"&gt;here's the story&lt;/a&gt;, as told by &lt;a href="http://www.twitter.com/TechCrunch/"&gt;@TechCrunch&lt;/a&gt;. You have probably experienced - maybe even implemented - the same kind of static blacklisting in other online services, in your corporate network or at your personal workstation. I have. Doesn't really help much in the long run, unless &lt;a href="http://nakedsecurity.sophos.com/2009/01/16/passwords-conficker-worm/"&gt;blocking Conficker from gaining access&lt;/a&gt;&amp;nbsp;&lt;i&gt;(List by Sophos - &lt;a href="http://www.twitter.com/gcluley/"&gt;@gcluley&lt;/a&gt;)&amp;nbsp;&lt;/i&gt;is your ultimate goal. Here I suggest another and more dynamic approach to the problem of commonly used and eventually also &lt;b&gt;bad&lt;/b&gt;&amp;nbsp;passwords.&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;a name='more'&gt;&lt;/a&gt;Many years ago I made a developer create a &lt;a href="http://msdn.microsoft.com/en-us/library/ms722439(v=vs.85).aspx"&gt;custom password filter for Microsoft Windows&lt;/a&gt;, based on the passfilt.dll source code example. For obvious reasons I will not go into the specifics about when, where, why, how, what etc about that specific implementation. :-)&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;I've written before about being careful with &lt;a href="http://securitynirvana.blogspot.com/2009/11/guarding-your-usernames.html"&gt;disclosing your user/logon name&lt;/a&gt;, &lt;a href="http://securitynirvana.blogspot.com/2009/11/why-history-may-be-bad-for-you.html"&gt;why your password history may be bad for you&lt;/a&gt;, &lt;a href="http://securitynirvana.blogspot.com/2010/02/whats-wordlist.html"&gt;what exactly do you/they mean by "wordlist"&lt;/a&gt;, and even an old article entitled "&lt;a href="http://www.securitydocs.com/library/3410"&gt;Experiences with password policies&lt;/a&gt;" back in 2005. I could list more, but these are highly relevant for this blog post.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Here's the thing: &lt;b&gt;I don't think implementing static blacklists for passwords really help.&lt;/b&gt;&amp;nbsp;On the contrary, I think it is counterproductive as it will just be of annoyance to end-users, and will easily be circumvented. In the long run you will end up with users whispering behind your back about words NOT caught by the filter. Of course they will not tell you, as you are &lt;a href="http://search.dilbert.com/comic/Mordac%20The%20Preventer"&gt;Mordac&lt;/a&gt;, the preventer of information services.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;However there is another problem that may be of even greater risk than those end-users poking around with easy-to-guess passwords. &lt;b&gt;Helpdesk&lt;/b&gt;. Yup, that's right. The people who has their performance measured by the number of support calls they can open and close in 45 seconds or less. &lt;b&gt;Do you really think they are so creative they give out unique and easy-to-read length 15+&amp;nbsp;passphrases&amp;nbsp;to every caller? &lt;/b&gt;No way buddy, no way. Most likely they will use a very limited set of "default" passwords, that change only every few years or so. If there's a bunch of new people starting at your company on Monday, they probably get the same password for starters, all of them. Sure, they will have to change it upon first logon, but with default Microsoft Windows, you can't really set a time limit for disabling the accounts if the password doesn't change in &lt;i style="font-weight: bold;"&gt;n&lt;/i&gt;&amp;nbsp;days. That's too bad.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;So here is my quick and dirty suggestion. I've given this a bit of thought, I have already attacked my own idea and have some objections, but I'd like to hear your comments first. Based on my primary experience within the corporate world filled with Windows desktops and valuable data stored on Windows servers, I'm kind of biased here (forgive me...):&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt;Dynamic Prevention of Common Passwords&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div&gt;We'll implement a custom password filter (passfilt.dll) that uses a good &lt;a href="http://en.wikipedia.org/wiki/HMAC"&gt;HMAC&lt;/a&gt;&amp;nbsp;to create a value for the new requested password by the user. This value will get stored either locally or in a centralized file/database, along with a count value. &lt;i&gt;(In all honesty, as long as Microsoft continues using LANMAN and NTLM (no salting), it doesn't take much to do better....). &lt;/i&gt;This filter will be deployed to all domain controllers, to enable the filter for domain accounts.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Using a configuration file &lt;i&gt;(no hardcoding, thx!)&lt;/i&gt;, we'll set a threshold value &lt;b&gt;&lt;i&gt;N&lt;/i&gt;&lt;/b&gt; for how many&amp;nbsp;simultaneous&amp;nbsp;occurrences of the same password we'll accept among all accounts.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;As soon as the filter receives a cleartext username + password for control, the filter will first check the bare minimums (length, complexity, similarity to username etc, if applicable), then proceed to hash the password, and check that specific hash value for number of occurences in the file/database that is dynamically updated. If there already exists &lt;i style="font-weight: bold;"&gt;N &lt;/i&gt;occurences of that hash value in our file/database, the password will be rejected.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;The main purpose of this is to prevent a high number of accounts having the same password at the same time, with the most common passwords in corporate environments being tied to date/day/month/year and seasons. However, with such a dynamic filter in place, we'll effectively block any and all attempts to set the same (bad) password across multiple accounts, no matter the source.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;In combination with a decent password policy and the removal of the LANMAN hash values, we'll have a better and wider selection of passwords in use at any given time. We'll effectively increase the time needed to successfully recover &lt;i&gt;(crack)&lt;/i&gt;&amp;nbsp;&lt;i style="font-weight: bold;"&gt;X &lt;/i&gt;&amp;nbsp;passwords, while reducing the maximum number of accounts that can be compromised through the successful recovery of a single password (NTLM hash value).&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;--&lt;/div&gt;&lt;div&gt;Now, this is just some stuff I've been thinking about during easter, so be gentle with your comments. As I said earlier, I've attacked my own proposal already, and have some objections. Before I eventually expand this idea and lay out my own objections, &lt;b&gt;I would really appreciate your comments. &lt;/b&gt;Fire away. :-)&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8400370148915075091-8136493086901193425?l=securitynirvana.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securitynirvana.blogspot.com/feeds/8136493086901193425/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://securitynirvana.blogspot.com/2011/04/dynamic-prevention-of-common-passwords.html#comment-form' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/8136493086901193425'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/8136493086901193425'/><link rel='alternate' type='text/html' href='http://securitynirvana.blogspot.com/2011/04/dynamic-prevention-of-common-passwords.html' title='Dynamic Prevention of Common Passwords'/><author><name>Per Thorsheim</name><uri>https://profiles.google.com/113848325212589987956</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-skpoP167x04/AAAAAAAAAAI/AAAAAAAAAVU/RWc12nir74w/s512-c/photo.jpg'/></author><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8400370148915075091.post-4537810599920091403</id><published>2011-04-22T19:26:00.001+02:00</published><updated>2011-04-22T19:32:13.450+02:00</updated><title type='text'>Consolidate my posterior...</title><content type='html'>&lt;table cellpadding="0" cellspacing="0" class="tr-caption-container" style="float: right; margin-left: 1em; text-align: right;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-DbTd9ZL3j-c/TbG3mJEfu7I/AAAAAAAAAGA/k2Jelv01084/s1600/grabbe.png" imageanchor="1" style="clear: left; margin-bottom: 1em; margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="200" src="http://1.bp.blogspot.com/-DbTd9ZL3j-c/TbG3mJEfu7I/AAAAAAAAAGA/k2Jelv01084/s200/grabbe.png" width="170" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;While I was asleep...&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;div style="text-align: justify;"&gt;As I'm sure many of you are aware of by now, Apple iOS 4.x contains a database file named &lt;b&gt;consolidated.db&lt;/b&gt;, in which your every move (or at the very least, the movements of your device) are recorded. This, according to conspiracy buffs and privacy advocates, is done to make life easier for Gil Grissom or whoever your local CSI representative is. As a&lt;strike&gt;n international black market arms dealer&lt;/strike&gt; security professional, I've been curious about how useful the collected data really is, especially since a lot of the comments on the subject claims that the coordinates and time stamps are wildly inaccurate. So I decided to figure this out for myself, and proceeded to crank up &lt;a href="http://www.google.com/earth/index.html"&gt;Google Earth&lt;/a&gt;...&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;a href="http://www.google.com/earth/index.html"&gt;Google Earth&lt;/a&gt; has this neat feature that lets you import (and export) data via an XML-based file format named &lt;a href="http://code.google.com/apis/kml/documentation/kml_tut.html"&gt;KML&lt;/a&gt;, so I've wrote a perl script that reads the &lt;b&gt;consolidated.db&lt;/b&gt; file and outputs a KML file. &lt;b&gt;The script can be found &lt;a href="http://pastebin.com/CiS1Wdse"&gt;here&lt;/a&gt;.&lt;/b&gt; What you need to run the script is perl (obviously), and the DBI and DBD::SQLite modules (the database is in &lt;a href="http://www.sqlite.org/"&gt;sqlite3&lt;/a&gt; format).&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Now, the procedure for extracting the &lt;b&gt;consolidated.db&lt;/b&gt; file from backups have been described elsewhere, so I won't get into that. For this exercise, I'll just assume you've figured out that part already.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;When everything is ready, simply run the script with the database file as the single argument:&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;b&gt;perl xonsolidated.pl consolidated.db&lt;/b&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;b&gt; &lt;/b&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;If everything went well, there should be no output other than a new file with the .kml extension tacked onto the end of the original database file name (&lt;b&gt;consolidated.db&lt;/b&gt; becomes &lt;b&gt;consolidated.db.kml&lt;/b&gt;). This file can be loaded into Google Earth, and the result should be a big list of timestamps (one point and one path for each time stamp, and each pair with a different color).&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;If it didn't run properly... Well, happy debugging.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;So, what did the Google Earth representation of my location data show me?&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Well, it certainly didn't show a complete record of all my movements. In fact, before I separated each time segment into different colors, it looked a lot like a big plate of spaghetti. It seems that the location data is only dumped to the database every now and then (sometimes several times a day, sometimes as rare as every fortnight), all the data points are given same time stamp.&amp;nbsp; From what I can tell, the coordinates corresponds more closely with which cell tower my cell phone was talking to than any actual phone location.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;One of the more recent time stamps (see the picture up top) indicated my presence at dozens of locations with several square kilometers around my apartment, at a time that I'm quite certain I was sound asleep in my bed.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Another thing I found is that the collected can be vastly incomplete at times. Case in point; I spent a week in Angola last November, more precisely in the central district of the capital Luanda (which has surprisingly good cell phone coverage). The database contains tracking information all the way down to Frankfurt airport (in Germany), but after that, there's a 10 day gap where absolutely nothing is recorded. The next tracking dump occurs after I had been back home for several days.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;So, are these data useful for anything at all?&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;It should be quite clear that it's not a reliable source of evidence; The data is written at way too irregular intervals, the coordinates are all over the place, and it is likely that vast chunks of data are missing (like my trip to Angola). In all likelihood, the cellular network providers already have much more accurate data on your device's movements.&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;So if it's not useful for auditing purposes, why does your device record these data at all? To be honest; I have no idea. Hopefully, someone who cares a lot more than me about these things, will figure it out, or Apple will decide to be a bit more open about what goes on under the hood of their devices (yeah, that's gonna happen).&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8400370148915075091-4537810599920091403?l=securitynirvana.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securitynirvana.blogspot.com/feeds/4537810599920091403/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://securitynirvana.blogspot.com/2011/04/consolidate-my-posterior.html#comment-form' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/4537810599920091403'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/4537810599920091403'/><link rel='alternate' type='text/html' href='http://securitynirvana.blogspot.com/2011/04/consolidate-my-posterior.html' title='Consolidate my posterior...'/><author><name>Jan Fredrik Leversund</name><uri>http://www.blogger.com/profile/08568234597906404307</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='29' height='32' src='http://3.bp.blogspot.com/_yZd6JB7bTNo/SXR9ZicGbkI/AAAAAAAAACI/999Zaep8U44/S220/meme-1-thumbnail.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-DbTd9ZL3j-c/TbG3mJEfu7I/AAAAAAAAAGA/k2Jelv01084/s72-c/grabbe.png' height='72' width='72'/><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8400370148915075091.post-8567965043719346121</id><published>2011-04-13T23:35:00.004+02:00</published><updated>2011-07-04T11:03:05.927+02:00</updated><title type='text'>Security Think Tank</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-vBrbaSOI4Iw/TaYW88o57vI/AAAAAAAAASw/kdtTUFUAS2w/s1600/questionmark.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/-vBrbaSOI4Iw/TaYW88o57vI/AAAAAAAAASw/kdtTUFUAS2w/s1600/questionmark.png" /&gt;&lt;/a&gt;&lt;/div&gt;On Monday April 4, I did a presentation at the Scandinavian &lt;a href="http://www.isaca.org/"&gt;ISACA&lt;/a&gt; conference, held in Oslo, Norway. The title was "&lt;a href="http://www.slideshare.net/perthorsheim/board-member-security"&gt;Board Member Security&lt;/a&gt;" (Link to Slideshare), and were part of the governance track. I will get back to the contents of the presentation later, first of all I would like to introduce the people behind the presentation.&lt;br /&gt;&lt;br /&gt;&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;I have set up a local "think tank" on security with some friends here in Bergen, Norway. Most of us have known each other for many years already, personally from school and by working together.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://no.linkedin.com/pub/erlend-dyrnes/1/574/45"&gt;Erlend Dyrnes&lt;/a&gt; is the Security Manager of Norwegian ISP &lt;a href="http://www.nextgentel.no/"&gt;NextGenTel&lt;/a&gt;. (&lt;i&gt;I should probably say triple-play provider or something to be more correct&lt;/i&gt;).&amp;nbsp;A former pentester and auditor at Ernst &amp;amp; Young, he now has to face the consequences of his previous recommendations. With a bright mind, he manages to bring the important aspect of &lt;b&gt;ROSI&lt;/b&gt; (&lt;i&gt;Return On Security Investment&lt;/i&gt;) into our discussions. He also holds the &lt;b&gt;CISA&lt;/b&gt; and &lt;b&gt;CISM&lt;/b&gt; certifications from ISACA.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://no.linkedin.com/pub/odd-terje-karlsen/2/383/840"&gt;Odd-Terje Karlsen&lt;/a&gt; is our "&lt;b&gt;Grand Old Man"&lt;/b&gt;, and one of my work colleagues. He actually remembers the introduction of IBM PC's with MS-DOS! :-) With more years of experience from the IT industry then any other in the group, he can thoroughly draw the lines from the introduction of IBM PC's to one of the hotter topics in the business today: &lt;b&gt;BYOPC&lt;/b&gt; (&lt;i&gt;Bring Your Own PC&lt;/i&gt;). "Been there, done that" is natural for him to say whenever the rest of us has a new, bright and shiny new idea to discuss. Being able to benefit from earlier failures, pitfalls and success stories is of great value to us all. Oh, and he's a fan of Maltego. :-)&lt;br /&gt;&lt;br /&gt;&lt;a href="http://no.linkedin.com/in/alexh"&gt;Alexander Hoogerhuis&lt;/a&gt; is our "foreign guy". Not just being a citizen form the Netherlands, as an independent consultant, he travels the world for his clients, installing and fixing networking problems (and more!) all over. He never did the final lab exam for &lt;b&gt;Cisco CCIE&lt;/b&gt;, but the written exam as well as other certifications were a breeze. Through his work he sees a lot of challenges as well as solutions for a wealth of different enviroments, across borders and cultures. He is pretty creative on describing attack scenarios that involves social engineering in combination with exploitation of commonly known defaults and bad habits.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://no.linkedin.com/pub/lars-erik-bratveit/0/872/82"&gt;Lars Erik Bråtveit&lt;/a&gt;&amp;nbsp;is our true &lt;b&gt;CCIE&lt;/b&gt;, pentester and social engineering expert. At the time of writing this, it's just a week ago since he told me that he just won the CTF at a SANS course on pentesting in the US. Congrats! I do consider him a little paranoid, but then again.. doing social engineering and pentesting almost on a daily basis should make many people paranoid. Creativity on both the attacker as well as the defenders side of the table is of great value to our discussions.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://no.linkedin.com/pub/thomas-tj%C3%B8stheim/0/982/40"&gt;Thomas Tjøstheim&lt;/a&gt; probably represent the strongest academic side of our group.With a Ph.D in computer security, he represents the analytic mind who organize lots of information very fast, if needed. He even take notes from our conversations! :-) With a passing score on the CISSP exam and working with risk analysis during work hours, he is also my &lt;b&gt;nemesis&lt;/b&gt;&amp;nbsp;in our highly informal "&lt;a href="http://securitynirvana.blogspot.com/2011/03/pwnd-again.html"&gt;Pwn2Own&lt;/a&gt;" competition.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://no.linkedin.com/in/perhoff"&gt;Per-Arne Hoff&lt;/a&gt;&amp;nbsp;works in the&lt;b&gt; public sector&lt;/b&gt;, just like Thomas has done for a couple of months now. With a positive attitude and perspectives from the public sector, he helps us see challenges as well as solutions from a different perspective than the rest of us. Supporting a very large organisation that needs to be &lt;b&gt;open and available to anyone&lt;/b&gt;, he faces other challenges in his daily work that we - luckily - don't have to worry too much about on a daily basis. Oh, and he knows his firewalls, wlans, vlans, routers and switches pretty well. :-)&lt;br /&gt;&lt;br /&gt;&lt;a href="http://no.linkedin.com/in/thomasmethlie"&gt;Thomas S. Methlie&lt;/a&gt; is our (secure) programmer. With a master in informatics, looking at different security aspects, he's one of those guys who usually have something really smart to say every time he speaks. He's also part of the "Thomas &amp;amp; Thomas" team (see above), my nemesis in our "Pwn2Own" competition. He passed his CISSP exam with ease, and practices confidentiality every day by being married to a journalist. ;-)&lt;br /&gt;&lt;br /&gt;&lt;a href="http://no.linkedin.com/in/oddbjorn"&gt;Oddbjørn Steffensen&lt;/a&gt; is also one of my colleagues. &lt;b&gt;I usually refer to him as the inventor of PERL&lt;/b&gt; (&lt;i&gt;he doesn't really like me saying that...&lt;/i&gt;). I think he can actually figure out the question that will give you "42" in less than 42 lines of PERL code, but that wouldn't be any fun, right? he can do mind mapping faster than you are capable of speaking, he eats any log format for breakfast and will tell you exactly who did it in minutes. And that with a complete profile, including a Google Street View of where the culprit lives by night. (&lt;i&gt;If you try to hire him, I'll shoot you)&lt;/i&gt;. Maybe I should say that he passed the CISSP exam many years ago, but didn't bother to report his CPEs. Too bad, but I'd hire him any day, no matter his price.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://no.linkedin.com/in/kluzz"&gt;Jan Fredrik Leversund&lt;/a&gt;&amp;nbsp;is another colleague, and yet another consultant in our group. Oddbjørn says that his own PERL code just works, while Jan Fredrik &lt;b style="text-decoration: underline;"&gt;documents his code&lt;/b&gt; (!) in addition to making it work through a more structured approach. I have never ever met anyone more capable of turning down any and all suggestions that I can come up with, replacing them with either nonsense or even better ideas than what I thought of initially. I like that. :-) A programmer, risk analyst and pentester, he's a fan of Apple products and like Oddbjørn has a genuine interest in &lt;a href="http://www.flickr.com/photos/kluzz"&gt;photography&lt;/a&gt;. He currently holds the CISSP-ISSAP certifications from &lt;a href="https://www.isc2.org/"&gt;(ISC)2&lt;/a&gt;, and needs to do a bit of paper work before officially becoming a CISA as well. He's also the mastermind behind quite a few lines of PERL code that does password analysis for me.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://no.linkedin.com/in/thorsheim"&gt;Yours truly&lt;/a&gt;? Well, you probably have an idea about me already, based on this blog and other sources. I'll leave it to somebody else to give a description of me, I'm really not objective here. :-)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8400370148915075091-8567965043719346121?l=securitynirvana.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securitynirvana.blogspot.com/feeds/8567965043719346121/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://securitynirvana.blogspot.com/2011/04/security-think-tank.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/8567965043719346121'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/8567965043719346121'/><link rel='alternate' type='text/html' href='http://securitynirvana.blogspot.com/2011/04/security-think-tank.html' title='Security Think Tank'/><author><name>Per Thorsheim</name><uri>https://profiles.google.com/113848325212589987956</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-skpoP167x04/AAAAAAAAAAI/AAAAAAAAAVU/RWc12nir74w/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-vBrbaSOI4Iw/TaYW88o57vI/AAAAAAAAASw/kdtTUFUAS2w/s72-c/questionmark.png' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8400370148915075091.post-8441812263773830045</id><published>2011-04-09T01:36:00.006+02:00</published><updated>2011-05-05T22:17:41.912+02:00</updated><title type='text'>Passwords^11 - REGISTER NOW!</title><content type='html'>&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/-d6R7b0uyS10/TZ-H4DDOYLI/AAAAAAAAASs/VFw7ZkD5Zao/s1600/Header.png" style="margin-left: auto; margin-right: auto;" /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;Twitter hashtag: #passwords11&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-d6R7b0uyS10/TZ-H4DDOYLI/AAAAAAAAASs/VFw7ZkD5Zao/s1600/Header.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;span class="Apple-style-span" style="color: #444444; line-height: 18px;"&gt;We are getting ready. You can now register for participation at Passwords^11, a 2-day conference on passwords &amp;amp; PINs. Free for all, at the University in Bergen (Norway), on June 7-8. Limited seats available. Quite possibly the very first-ever conference *only* about passwords &amp;amp; PIN codes! :-)&lt;/span&gt;&lt;span class="Apple-style-span" style="color: #444444; line-height: 18px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="color: #444444; line-height: 18px;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;a name='more'&gt;&lt;/a&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;span class="Apple-style-span" style="color: #444444; line-height: 18px;"&gt;&lt;b&gt;Where?&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;Just like in December 2010, we'll do the conference at&lt;a href="http://www.uib.no/rg/selmer"&gt; the Selmer Center&lt;/a&gt;, part of the University of Bergen. The exact address is Thormøhlensgate 55, 5008 Bergen. &lt;a href="http://maps.google.no/maps?f=q&amp;amp;source=s_q&amp;amp;hl=no&amp;amp;geocode=&amp;amp;q=h%C3%B8yteknologisenteret&amp;amp;aq=&amp;amp;sll=59.915225,10.727592&amp;amp;sspn=0.010348,0.033023&amp;amp;g=Bergen,+Hordaland,+Norway&amp;amp;ie=UTF8&amp;amp;ll=60.3819,5.331947&amp;amp;spn=0,0.008256&amp;amp;t=h&amp;amp;z=18&amp;amp;layer=c&amp;amp;cbll=60.381922,5.331647&amp;amp;panoid=U452pTdBBN_d3RcoxIYIDQ&amp;amp;cbp=12,192.14,,0,-7.31"&gt;The building looks like this&lt;/a&gt; (Google street view). &lt;a href="http://maps.google.no/maps?f=d&amp;amp;source=s_d&amp;amp;saddr=Torgallmenningen,+Bergen&amp;amp;daddr=Thorm%C3%B8hlens+Gate+55,+5008+Bergen+(H%C3%B8yteknologisenteret+Drift+AS)&amp;amp;geocode=FbyFmQMdTT1RAClftDE9qP48RjEsQo5QKA85kQ%3BFRtZmQMdU1pRACF0qg1ou6Gpaymb51g_U_k8RjGftGSm_sILww&amp;amp;hl=no&amp;amp;mra=ls&amp;amp;dirflg=w&amp;amp;sll=60.389137,5.325451&amp;amp;sspn=0.020399,0.066047&amp;amp;ie=UTF8&amp;amp;ll=60.38725,5.328841&amp;amp;spn=0.0204,0.066047&amp;amp;t=h&amp;amp;z=15"&gt;Walking distance&lt;/a&gt; from the city center (Torgalmenningen) to the Selmer Center is estimated to 21 minutes, thanks to Google. :-)&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #444444; line-height: 18px;"&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;span class="Apple-style-span" style="color: #444444; line-height: 18px;"&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="color: #444444; line-height: 18px;"&gt;&lt;b&gt;Why?&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #444444; line-height: 18px;"&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;We'll record all presentations on video and make them &lt;a href="http://ftp.ii.uib.no/pub/passwords10/"&gt;available on the Internet&lt;/a&gt;&amp;nbsp;for free as soon as possible after the conference. We're even planning to do live streaming of it all through &lt;a href="http://www.ustream.tv/channel/passwords11"&gt;ustream.tv&lt;/a&gt;. Cannot guarantee that will work out yet, we need to test it first. &lt;b&gt;Anyway;&lt;/b&gt;&amp;nbsp;by participating onsite you get the chance to ask questions, chit-chat, get to know new people with similar interests and probably some&amp;nbsp;Übergeeky discussions over lunch and dinner.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #444444; line-height: 18px;"&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;span class="Apple-style-span" style="color: #444444; line-height: 18px;"&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="color: #444444; line-height: 18px;"&gt;&lt;b&gt;Who?&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;span class="Apple-style-span" style="color: #444444; line-height: 18px;"&gt;Who should participa&lt;/span&gt;&lt;span class="Apple-style-span" style="color: #444444; line-height: 18px;"&gt;te you may ask. Well, last year we had students (masters, PhDs), professors and post-docs from the academic side, and security professionals from&lt;/span&gt;&lt;span class="Apple-style-span" style="color: #444444; line-height: 18px;"&gt; the private side. It will be part academic stuff, part very applicable to you as a security professional or hard-core web/app developer. You do not have to be on level with &lt;a href="http://www.ii.uib.no/~torh/"&gt;Professor Tor Helleseth&lt;/a&gt; of course, but some basic knowledge is probably a good idea. Others may find it interesting too of course. :-)&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #444444; line-height: 18px;"&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #444444; line-height: 18px;"&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;Program?&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #444444; font-family: inherit;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;&lt;a href="http://home.online.no/~putilutt/passwords11/Passwords11_Final_Program.pdf"&gt;Here is the program&lt;/a&gt;, as well as &lt;a href="http://home.online.no/~putilutt/passwords11/Passwords11_abstracts.pdf"&gt;the abstracts&lt;/a&gt; (academics are much better at providing abstracts, I'll give'em that!)&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #444444;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #444444; line-height: 18px;"&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;Price, flights &amp;amp; accomodation?&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #444444; line-height: 18px;"&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;Participation is for free. Hey, we'll even buy you lunch in the university cafeteria in the same building! Travel, accomodation, breakfast and dinner - and something you drink - is on you. Several airlines have direct routes to Bergen airport Flesland. Airport bus or taxi is approximately 20-35 minutes to the city center. Hotel standards are good in Norway, but June is also tourist season so I recommend that you book your hotel as soon as possible.&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #444444; line-height: 18px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #444444; line-height: 18px;"&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="color: #444444; line-height: 18px;"&gt;Feel free to join in for dinner on Monday, Tuesday and Wednesday evening. &lt;b&gt;If you have any questions&lt;/b&gt;, like where to go, what to see before or after the conference, feel free to e-mail me, and I'll try to answer ASAP.&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #444444; line-height: 18px;"&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #444444; line-height: 18px;"&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;Great! Register! Register!&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;span class="Apple-style-span" style="color: #444444; line-height: 18px;"&gt;Register by sending an&amp;nbsp;&lt;/span&gt;&lt;span class="Apple-style-span" style="color: #444444; line-height: 18px;"&gt;e-mail to me&lt;/span&gt;&lt;span class="Apple-style-span" style="color: #444444; line-height: 18px;"&gt;&amp;nbsp;&lt;/span&gt;&lt;span class="Apple-style-span" style="color: #444444; line-height: 18px;"&gt;&lt;b&gt;(per at thorsheim dot net&lt;/b&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="color: #444444; line-height: 18px;"&gt;), with the following information:&lt;/span&gt;&lt;span class="Apple-style-span" style="color: #444444; line-height: 18px;"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #444444; line-height: 18px;"&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;span class="Apple-style-span" style="color: #444444; line-height: 18px;"&gt;-&lt;/span&gt;&lt;span class="Apple-style-span" style="color: #444444; line-height: 18px;"&gt;&amp;nbsp;&lt;/span&gt;&lt;span class="Apple-style-span" style="color: #444444; line-height: 18px;"&gt;&lt;b&gt;Full name&lt;/b&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="color: #444444; line-height: 18px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="color: #444444; line-height: 18px;"&gt;-&lt;/span&gt;&lt;span class="Apple-style-span" style="color: #444444; line-height: 18px;"&gt;&amp;nbsp;&lt;/span&gt;&lt;span class="Apple-style-span" style="color: #444444; line-height: 18px;"&gt;&lt;b&gt;Title / position&lt;/b&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="color: #444444; line-height: 18px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="color: #444444; line-height: 18px;"&gt;-&lt;/span&gt;&lt;span class="Apple-style-span" style="color: #444444; line-height: 18px;"&gt;&amp;nbsp;&lt;/span&gt;&lt;span class="Apple-style-span" style="color: #444444; line-height: 18px;"&gt;&lt;b&gt;Company / Organisation (if applicable)&lt;/b&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="color: #444444; line-height: 18px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="color: #444444; line-height: 18px;"&gt;&lt;b&gt;&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #444444;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="color: #444444; line-height: 18px;"&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="color: #444444; line-height: 18px;"&gt;We will confirm your registration back to your e-mail address. No, we're not using Epsilon for mail distribution, and we will not give out any mail addresses to anyone else. Since this is a free conference, attendees may drop attending in the very last minute. Please, if you register and then find out you can't participate anyway, let me&amp;nbsp;know ASAP.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;span class="Apple-style-span" style="color: #444444; line-height: 18px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #444444; line-height: 18px;"&gt;Best regards,&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #444444; line-height: 18px;"&gt;Per Thorsheim&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #444444; line-height: 18px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #444444; line-height: 18px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #444444; line-height: 18px;"&gt;We also have a media partner in PenTest Magazine:&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #444444; line-height: 18px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://www.pentestmag.com/"&gt;&lt;img border="0" height="178" src="http://1.bp.blogspot.com/-AM0OqOPBGC4/TcBykv1Lw7I/AAAAAAAAAS0/QsQCRwAC5f4/s320/pentest_logo.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;span class="Apple-style-span" style="color: #444444; line-height: 18px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #444444; font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-size: x-small;"&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8400370148915075091-8441812263773830045?l=securitynirvana.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securitynirvana.blogspot.com/feeds/8441812263773830045/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://securitynirvana.blogspot.com/2011/04/passwords11-register-now.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/8441812263773830045'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/8441812263773830045'/><link rel='alternate' type='text/html' href='http://securitynirvana.blogspot.com/2011/04/passwords11-register-now.html' title='Passwords^11 - REGISTER NOW!'/><author><name>Per Thorsheim</name><uri>https://profiles.google.com/113848325212589987956</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-skpoP167x04/AAAAAAAAAAI/AAAAAAAAAVU/RWc12nir74w/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-d6R7b0uyS10/TZ-H4DDOYLI/AAAAAAAAASs/VFw7ZkD5Zao/s72-c/Header.png' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8400370148915075091.post-462345399791942902</id><published>2011-04-02T01:45:00.000+02:00</published><updated>2011-04-02T01:45:26.930+02:00</updated><title type='text'>Sikkerhetsansvaret</title><content type='html'>&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;Jeg er litt overrasket over at Janne Hagen i FFI på siste FFI-FORUM skal ha påpekt at vi har &lt;i&gt;&lt;a href="http://www.blogger.com/goog_986874137"&gt;"...&lt;/a&gt;&lt;/i&gt;&lt;span class="Apple-style-span" style="color: #333333; line-height: 24px;"&gt;&lt;a href="http://blogg.nsm.stat.no/archives/467" style="font-style: italic;"&gt;et fragmentert statlig ansvar for IT-sikkerhet"&lt;/a&gt;&lt;i&gt;&amp;nbsp;&lt;/i&gt;(NSM bloggpost, 1 April 2011. Tviler på det er noen aprilspøk). Jeg regner med hun da uttaler seg om den reelle etterlevelsen av sikkerhet i det offentlige, plasseringen av ansvar bør det da ikke være noen tvil om? &lt;b&gt;Styrelederen heter Harald, adm.dir heter Jens, og generalforsamlingen heter Stortinget. De har ansvaret for sikkerheten.&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;span class="Apple-style-span" style="color: #333333; line-height: 24px;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;a name='more'&gt;&lt;/a&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;Tilgi meg for introduksjonen, temaet er svært viktig. Bloggposten fra Kjetil Veire i NSM er da også umulig å la være å kommentere.&amp;nbsp;&lt;/span&gt;&lt;span class="Apple-style-span" style="color: #333333; line-height: 24px;"&gt;&lt;b&gt;Plasseringen av ansvaret for sikkerhet synes å være et evig diskusjonstema.&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;i&gt;&lt;span class="Apple-style-span" style="color: #333333; line-height: 24px;"&gt;(&lt;/span&gt;&lt;span class="Apple-style-span" style="color: #333333; line-height: 24px;"&gt;Definisjonen av&lt;/span&gt;&lt;span class="Apple-style-span" style="color: #333333; line-height: 24px;"&gt;&amp;nbsp;&lt;/span&gt;&lt;span class="Apple-style-span" style="color: #333333; line-height: 24px;"&gt;&lt;b&gt;tilstrekkelig sikkerhet&lt;/b&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="color: #333333; line-height: 24px;"&gt;... Vel, DER har vi noe å diskutere til evig tid, men det er da også en helt annen diskusjon enn plassering av ansvar.)&lt;/span&gt;&lt;/i&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #333333; line-height: 24px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;i&gt;&lt;span class="Apple-style-span" style="color: #333333; line-height: 24px;"&gt;&lt;/span&gt;&lt;/i&gt;&lt;span class="Apple-style-span" style="color: #333333; line-height: 24px;"&gt;La oss &amp;nbsp;ta utgangspunkt i børsnoterte selskaper. Styret er meg bekjent kollektivt ansvarlig for at sikkerhet blir tilstrekkelig ivaretatt i en virksomhet. De vil normalt nøye seg med å gi det daglige ansvaret for sikkerheten til administrerende direktør, og &amp;nbsp;verifisere at dette blir ivaretatt gjennom enten en internkontrollfunksjon og/eller lovpålagt ekstern revisjon. Det er naturlig at man derunder bygger et organisasjonskart som også har en linje- eller virtuell organisasjon hvor noen er utpekt til ha det daglige ansvaret for å ivareta sikkerhet innen ulike områder.&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #333333; line-height: 24px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #333333; line-height: 24px;"&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="color: #333333; line-height: 24px;"&gt;Det å la en minister få øverste ansvar for sikkerheten i staten tror jeg er en dårlig ide. Det kan vel ha skjedd at både Kongen, Statsministeren og Stortinget har overkjørt hverandre i ulike saker, men at en skarve minister skal ha mulighet til å toppe dem? Neppe. Jeg har da heller ikke møtt på mange sikkerhetssjefer som har talt styret eller administrerende direktør midt i mot, om de i det hele tatt har talerett fremfor disse.&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #333333; line-height: 24px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #333333; line-height: 24px;"&gt;&lt;b&gt;Utfordringen ligger ikke i plasseringen av ansvaret&lt;/b&gt;, men i&amp;nbsp;&lt;b&gt;mandat&lt;/b&gt;, &lt;b&gt;budsjett&lt;/b&gt;&amp;nbsp;og &lt;b&gt;myndighet.&lt;/b&gt;&amp;nbsp;Gjennom mandatet vet du hva du skal gjøre. Med budsjettet får du muligheten til å gjøre det. Gjennom myndigheten får du &amp;nbsp;muligheten til ulike sanksjoner dersom tilstrekkelige tiltak faktisk ikke blir gjennomført innenfor definerte rammer.&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #333333; line-height: 24px;"&gt;&lt;i&gt;Selv må jeg innrømme at jeg flere ganger har skyldt på fraværet av ett eller flere av de 3 nevnte elementer når sikkerheten blir veiet og funnet for lett.&lt;/i&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #333333;"&gt;&lt;span class="Apple-style-span" style="line-height: 24px;"&gt;--&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #333333;"&gt;&lt;span class="Apple-style-span" style="line-height: 24px;"&gt;&lt;b&gt;Erland Løkken&lt;/b&gt;, direktør i &lt;a href="http://www.nsr-org.no/"&gt;Næringslivets Sikkerhetsråd&lt;/a&gt;, sier at &lt;i&gt;"d&lt;/i&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="color: #333333; line-height: 24px;"&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;i&gt;et må etableres et senter med mandat til å koordinere private og offentlige aktører for forebyggende og avgrensende tiltak".&lt;/i&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #333333; line-height: 24px;"&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #333333; line-height: 24px;"&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;NorSIS har ikke det mandatet, &lt;a href="http://www.norsis.no/omsis/"&gt;men de har allikevel et mandat som kanskje er et steg i riktig retning&lt;/a&gt;.&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #333333; line-height: 24px;"&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #333333; line-height: 24px;"&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;Jeg har tidligere kritisert &lt;a href="http://www.norsis.no/"&gt;NorSIS&lt;/a&gt; og &lt;a href="http://www.nettvett.no/"&gt;Nettvett&lt;/a&gt; (Post- og teletilsynet) for å ha &lt;a href="http://securitynirvana.blogspot.com/2010/08/statlige-passordanbefalinger.html"&gt;vidt sprikende anbefalinger&lt;/a&gt;&amp;nbsp;i forhold til passord. Slik jeg ser det har de svært overlappende oppgaver, og de har også jevnlig kontakt seg imellom. Jeg tror at min bloggpost kan ha påvirket dem til å koordinere sine anbefalinger på området, slik at staten fremstår med ett sett anbefalinger i en daglig utfordring de fleste av oss må forholde seg til.&amp;nbsp;La meg her få presisere at jeg har en god dialog med spesielt NorSIS, og synes at de gjør et godt og ikke minst viktig stykke arbeid.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #333333; line-height: 24px;"&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #333333; line-height: 24px;"&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;Jeg liker forslaget fra Erland Løkken, men trengs det virkelig enda et senter for å koordinere private og offentlige aktører? &lt;b&gt;Kan vi ikke redusere litt istedenfor?&lt;/b&gt; Om jeg ikke tar feil, så har vel dette landet uoffisiell verdensrekord i antall organisasjoner i forhold til folketall.&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #333333; line-height: 24px;"&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #333333; line-height: 24px;"&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;Som jeg påpekte i forhold til Norsis og Nettvett, så er det en stor utfordring at &lt;b&gt;ulike organisasjoner ser ikke ut til å snakke sammen&lt;/b&gt;. De overlapper hverandre innenfor "ansvarsområder", men har vidt forskjellige anbefalinger. Jeg vil helst unngå noen monolittisk tilnærming fra staten til alle aspekter innen sikkerhet, men de ulike departementer, direktorater og tilsyn har vel rimelig klart definerte mandater og ansvarsområder? Hva om vi fikk dem til å faktisk holde seg til dem, og kreve bedre koordinering dem imellom? Der har du muligens det senteret Erland Løkken burde etterspør: &lt;b&gt;et senter som skal sørge for at alle tar sikkerhetsansvar innenfor sitt eget ansvarsområde, og koordinerer tversgående regler, aktiviteter og kontroller.&lt;/b&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #333333; line-height: 24px;"&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #333333; line-height: 24px;"&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;i&gt;Et slikt senter kaller jeg ofte for "sikkerhetsavdeling".&lt;/i&gt;&lt;/span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8400370148915075091-462345399791942902?l=securitynirvana.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securitynirvana.blogspot.com/feeds/462345399791942902/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://securitynirvana.blogspot.com/2011/04/sikkerhetsansvaret.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/462345399791942902'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/462345399791942902'/><link rel='alternate' type='text/html' href='http://securitynirvana.blogspot.com/2011/04/sikkerhetsansvaret.html' title='Sikkerhetsansvaret'/><author><name>Per Thorsheim</name><uri>https://profiles.google.com/113848325212589987956</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-skpoP167x04/AAAAAAAAAAI/AAAAAAAAAVU/RWc12nir74w/s512-c/photo.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8400370148915075091.post-7083803868733671178</id><published>2011-04-01T10:32:00.003+02:00</published><updated>2011-04-01T10:41:08.360+02:00</updated><title type='text'>The end of passwords</title><content type='html'>After more than 9 years of research on passwords, there is no doubt anymore: we should get rid of them. No, not by implementing any so-called alternatives such as biometrics or 2-factor token authentication. Be smart, use a blank password on your account. It's much easier, we can downsize customer support with at least 50%, it's completely free and every CFO will be ecstatic. Who would ever think that you would be so stupid to not use any passwords at all? Based on this, I will discontinue my research into passwords, as it is neither fun, interesting or useful anymore.&lt;br /&gt;&lt;br /&gt;&lt;a name='more'&gt;&lt;/a&gt;Oh. And happy Aprils Fools Day everyone, have a fantastic weekend, and I'll probably see many of you at #passwords11. :-)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8400370148915075091-7083803868733671178?l=securitynirvana.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securitynirvana.blogspot.com/feeds/7083803868733671178/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://securitynirvana.blogspot.com/2011/04/end-of-passwords.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/7083803868733671178'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/7083803868733671178'/><link rel='alternate' type='text/html' href='http://securitynirvana.blogspot.com/2011/04/end-of-passwords.html' title='The end of passwords'/><author><name>Per Thorsheim</name><uri>https://profiles.google.com/113848325212589987956</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-skpoP167x04/AAAAAAAAAAI/AAAAAAAAAVU/RWc12nir74w/s512-c/photo.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8400370148915075091.post-1430466152290305814</id><published>2011-03-20T18:02:00.001+01:00</published><updated>2011-03-20T19:56:52.579+01:00</updated><title type='text'>Security Gone South</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://lh3.googleusercontent.com/-Jd3fmS68eq4/TYYJUU1nfGI/AAAAAAAAASY/7ZeTdSWlp-c/s1600/Hotel_overview.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="213" src="https://lh3.googleusercontent.com/-Jd3fmS68eq4/TYYJUU1nfGI/AAAAAAAAASY/7ZeTdSWlp-c/s320/Hotel_overview.JPG" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;I've been on vacation with my wife and our daughter for one week at &lt;a href="http://maps.google.com/maps?f=q&amp;amp;source=s_q&amp;amp;hl=no&amp;amp;geocode=&amp;amp;q=Gran+Canaria,+Spania&amp;amp;aq=0&amp;amp;sll=37.0625,-95.677068&amp;amp;sspn=67.042676,135.263672&amp;amp;ie=UTF8&amp;amp;hq=&amp;amp;hnear=Gran+Canaria&amp;amp;z=11"&gt;Gran Canaria&lt;/a&gt;&amp;nbsp;(Spain). The picture on the left here shows parts of the hotel we stayed at. The tour operator as well as the hotel name shall remain anonymous in this blog post, as I don't think my observations are unique for this hotel only.&lt;br /&gt;&lt;br /&gt;Being on vacation doesn't mean leaving my interest in security &amp;amp; safety at home, hence this blog post.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a name='more'&gt;&lt;/a&gt;&lt;b&gt;First an interesting observation regarding the use of credit cards for payment. &lt;/b&gt;Almost all stores required an extra piece of identification, preferably passport, before accepting payment by card. Having my picture and name on the card was not enough. I guess the problem of skimming and stolen cards has been, or still is a big problem in Spain, as it is in many other European countries as well. Good thing to see that such a simple control seem to be in place to protect end-users.&lt;br /&gt;&lt;br /&gt;Anyway; as soon as we arrived at the hotel and our room (or "apartment", as they like to call it), I had a look at the emergency exit information, the location of fire fighting equipment and so on. Hopefully not needed, but being prepared is usually a good idea. We were situated on the second floor, with a small balcony, and here is a picture of the door leading out to the balcony:&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://lh3.googleusercontent.com/-HQce9jsW0do/TYYcvYlTcuI/AAAAAAAAASc/m9mzggSczcc/s1600/Balcony_door_no_lock.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="320" src="https://lh3.googleusercontent.com/-HQce9jsW0do/TYYcvYlTcuI/AAAAAAAAASc/m9mzggSczcc/s320/Balcony_door_no_lock.jpg" width="184" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;b&gt;Notice the absence of a lock. &lt;/b&gt;We could not lock the sliding door, and it was just as easy to open it from the outside as it was from the inside.&amp;nbsp;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;b&gt;Warning number 1: &lt;/b&gt;If you have kids who get up early in the morning, you probably want to block that door to prevent them from going out (and start climbing on the chairs for a better view...)&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;b&gt;Warning number 2:&lt;/b&gt;&amp;nbsp;afraid of strangers - thieves - entering the room at any given time? You have a problem. If you take a look at the top image, it is fairly easy to climb from balcony to another, at least sideways.&lt;b&gt; Even worse&lt;/b&gt;: most of the rooms on the ground floor had the same problem - no lock on the balcony doors. That's beyond stupid, if you ask me.&amp;nbsp;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;Talking to another family, they said they asked in the reception about this, and were told that they had to ask the owners of that part of the hotel, as "their" part did in fact have locks on the balcony doors. No further resolution of the problem, they "surrendered" to the in-room safety box. This of course gives the obvious question: which hotel did we stay at? (Since the entire building/area had one name, and apparently one reception etc..). I'd guess any insurance company would *love* this...&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;But of course, if you were actually afraid of any valuables, you could deposit 10,- Euros and pay another 2,- Euros per day to use the in-room safety box (which I did). Here are the instructions, &lt;b&gt;please read carefully:&lt;/b&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/div&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="https://lh3.googleusercontent.com/-jLyT28zgm5k/TYYcx9vpz5I/AAAAAAAAASk/UsyWPu_oc3w/s1600/In-room_Deposit_box_Terms.jpg" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="202" src="https://lh3.googleusercontent.com/-jLyT28zgm5k/TYYcx9vpz5I/AAAAAAAAASk/UsyWPu_oc3w/s320/In-room_Deposit_box_Terms.jpg" width="320" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;i&gt;(Instructions for in-room safety box. Click to enlarge)&lt;/i&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;Unfortunately I didn't take a picture of the safety box, which was located inside the wardrobe in the bedroom. &amp;nbsp;A rather small box, height and width suitable for an iPad, a camera and some other stuff. The box was attached to the wardrobe, but I'm a little unsure if it was also connected to the concrete wall behind the wardrobe. My guess; a decent crowbar should do the job.&amp;nbsp;&lt;i&gt;(Good observation though; a 20 minute delay between every 4 attempts to enter the correct PIN is good!)&lt;/i&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;So, could I deposit the rest of our clothes, suitcases and other stuff in the reception? Yes, but without any responsibility or penalties for the hotel if lost/stolen/damaged. I guess going on vacation does involve a bit of simple risk analysis, usually ending up with &lt;i&gt;"Either we go on vacation, or we don't, ok?".&lt;/i&gt;&amp;nbsp;Damn.&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;b&gt;Speaking of hotel reception&lt;/b&gt;, here's a picture I took from the reception area:&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://lh5.googleusercontent.com/-vfSG4_zPBeI/TYYcxdSlyWI/AAAAAAAAASg/RrwP0u9xXpw/s1600/42_Inch_Facebook.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="260" src="https://lh5.googleusercontent.com/-vfSG4_zPBeI/TYYcxdSlyWI/AAAAAAAAASg/RrwP0u9xXpw/s320/42_Inch_Facebook.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;b&gt;Yup, that's Facebook on a 42 inch screen.&lt;/b&gt;&amp;nbsp;No wireless access, it was either GSM/3G &lt;i&gt;(at insane prices!)&lt;/i&gt;, or tossing Euro coins onto the computer/PS3 residing inside that cabinet you see there. Absolutely no privacy there if you wanted to check out Facebook or your company webmail (which I observed several people do..) Oh, and the PC inside were running Windows XP, and had a full keyboard as well as a card reader (CF, SD etc..) available. &lt;b&gt;NOT&lt;/b&gt;&amp;nbsp;the best place to ask for either security or privacy. :-)&lt;br /&gt;&lt;br /&gt;It's 2011. People go on holiday, but still want Internet access wherever they go. This was supposedly a 4-star hotel. Give people what they want - and try to make it just a little secure as well. &lt;b&gt;You know; safeguarding your customers just might be a good idea after all.&lt;/b&gt;&lt;br /&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;br /&gt;&lt;b&gt;--&lt;/b&gt;&lt;br /&gt;What do you know: I forgot an interesting piece of information at the end here.. Here's a bottle of water and a box of mixed fruits juice:&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://lh4.googleusercontent.com/-LHRjN_aDCHU/TYZM-2qO00I/AAAAAAAAASo/tL0tWuRMF3w/s1600/Airport_security_fail.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="320" src="https://lh4.googleusercontent.com/-LHRjN_aDCHU/TYZM-2qO00I/AAAAAAAAASo/tL0tWuRMF3w/s320/Airport_security_fail.jpg" width="191" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Both were purchased at Gran Canaria and placed in our hand luggage before entering the security control at the airport of Las Palmas, Gran Canaria. I found them when we got home and unpacked everything. Luckily water and fruit juice are not the most explosive or combustible liquids available.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8400370148915075091-1430466152290305814?l=securitynirvana.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securitynirvana.blogspot.com/feeds/1430466152290305814/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://securitynirvana.blogspot.com/2011/03/security-gone-south.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/1430466152290305814'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/1430466152290305814'/><link rel='alternate' type='text/html' href='http://securitynirvana.blogspot.com/2011/03/security-gone-south.html' title='Security Gone South'/><author><name>Per Thorsheim</name><uri>https://profiles.google.com/113848325212589987956</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-skpoP167x04/AAAAAAAAAAI/AAAAAAAAAVU/RWc12nir74w/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='https://lh3.googleusercontent.com/-Jd3fmS68eq4/TYYJUU1nfGI/AAAAAAAAASY/7ZeTdSWlp-c/s72-c/Hotel_overview.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8400370148915075091.post-4517744717781723468</id><published>2011-03-08T23:50:00.003+01:00</published><updated>2011-03-09T00:00:56.023+01:00</updated><title type='text'>Call for Papers: Passwords^11</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://lh4.googleusercontent.com/-6qTsMuKe94w/TWBAZwkAWHI/AAAAAAAAARU/SJFrQGxWmkE/s1600/header.png" imageanchor="1"&gt;&lt;img border="0" src="https://lh4.googleusercontent.com/-6qTsMuKe94w/TWBAZwkAWHI/AAAAAAAAARU/SJFrQGxWmkE/s1600/header.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;b&gt;"Passwords^10 is probably the best security conference I have ever attended"&lt;/b&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;i&gt;- Note on evaluation form after Passwords^10, Dec 8-9, 2010&lt;/i&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;After a&lt;b&gt; &lt;a href="http://securitynirvana.blogspot.com/2010/12/videos-and-presentations-now-online.html"&gt;fantastic&lt;/a&gt;&amp;nbsp;&lt;/b&gt;conference with &lt;b&gt;38 participants (!)&lt;/b&gt;&amp;nbsp;in December last year, we have received many many requests from participants as well as others world-wide to do another conference on &lt;b&gt;passwords only.&lt;/b&gt;&amp;nbsp;So with the same close-to-zero budget as last year,&lt;b&gt; I am happy to announce our &lt;u&gt;Passwords^11 : Call for Papers!&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;b&gt;&lt;/b&gt;&lt;/div&gt;&lt;a name='more'&gt;&lt;/a&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;div class="PlainText" style="line-height: 18px;"&gt;&lt;div style="font-family: Arial, Tahoma, Helvetica, FreeSans, sans-serif; font-weight: normal; text-align: center;"&gt;&lt;b&gt;ANNOUNCEMENT &amp;amp; CALL FOR PAPERS : PASSWORDS^11&lt;/b&gt;&lt;/div&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;b style="font-weight: normal;"&gt;PASSWORDS^11&lt;/b&gt;&lt;span class="Apple-style-span" style="font-weight: normal;"&gt;&amp;nbsp;will be held at the University in Bergen (Norway), on June 7-8, 2011. The 2-day conference will be&lt;/span&gt;&lt;b&gt; free&lt;/b&gt;&lt;span class="Apple-style-span" style="font-weight: normal;"&gt; and &lt;/span&gt;&lt;b&gt;open for everyone&lt;/b&gt;&lt;span class="Apple-style-span" style="font-weight: normal;"&gt; to attend. Primary audience will be &lt;/span&gt;&lt;b&gt;academics&lt;/b&gt;&lt;span class="Apple-style-span" style="font-weight: normal;"&gt; and &lt;/span&gt;&lt;b&gt;security professionals&lt;/b&gt;&lt;span class="Apple-style-span" style="font-weight: normal;"&gt; with &lt;/span&gt;&lt;b&gt;deep technical knowledge&lt;/b&gt;&lt;span class="Apple-style-span" style="font-weight: normal;"&gt;. Limited seats available. &lt;/span&gt;&lt;b&gt;Passwords &amp;amp; PINs, nothing else.&lt;/b&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-weight: normal;"&gt;&lt;a href="http://www.blogger.com/post-edit.g?blogID=8400370148915075091&amp;amp;postID=4517744717781723468" name="more"&gt;&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="PlainText" style="font-weight: bold; line-height: 18px;"&gt;&lt;span class="Apple-style-span" style="font-weight: normal;"&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="PlainText" style="line-height: 18px;"&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;b&gt;== DATES ==&lt;/b&gt;&lt;br /&gt;&lt;b&gt;March 9&lt;/b&gt; - Public CFP&lt;br /&gt;&lt;b&gt;April 17&lt;/b&gt; - CFP submission ends&lt;br /&gt;&lt;b&gt;April 24&lt;/b&gt;&lt;span class="Apple-style-span" style="font-weight: normal;"&gt; - All notifications sent to speakers (accept / reject)&lt;br /&gt;Registration opens at - TBA&lt;br /&gt;&lt;br /&gt;&lt;b&gt;== ABOUT THE CONFERENCE ==&lt;/b&gt;&lt;br /&gt;The conference will be held at the University in Bergen (uib.no), with help and participation from The Selmer Center (&lt;a href="http://www.blogger.com/redir.aspx?C=f3a91658911c465e93f1589e299b0b32&amp;amp;URL=http%3a%2f%2fwww.uib.no%2frg%2fselmer" style="text-decoration: none;" target="_blank"&gt;www.uib.no/rg/selmer&lt;/a&gt;) and NISNet (&lt;a href="http://www.blogger.com/redir.aspx?C=f3a91658911c465e93f1589e299b0b32&amp;amp;URL=http%3a%2f%2fwww.nisnet.no" style="text-decoration: none;" target="_blank"&gt;www.nisnet.no&lt;/a&gt;). We'll start tuesday at 09:00, ending wednesday 17:00. We'll sleep somewhere in the middle. Like in December, we'll probably only do a single track of talks, everybody get to attend all presentations.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;== CALL FOR PAPERS ==&lt;/b&gt;&lt;br /&gt;We are looking for relevant content within ATTACKS, DEFENCE and USABILITY towards passwords &amp;amp; PIN codes. Presentations will be either 1 hour (45-50 minutes + questions), or 2 hours including a break.&amp;nbsp;&lt;/span&gt;&lt;b&gt;We are especially interested in:&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="PlainText" style="font-weight: bold; line-height: 18px;"&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="PlainText" style="line-height: 18px;"&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;b&gt;Protecting &lt;/b&gt;against online attacks, such as detecting, rate-limiting and blocking them, implementing&amp;nbsp;&lt;b&gt;hashing schemes&lt;/b&gt;&amp;nbsp;such as PBKDF2, Bcrypt and PBMAC, and attacks against passwords on &lt;b&gt;mobile devices&lt;/b&gt;. If you mention &lt;b&gt;forensics &lt;/b&gt;or &lt;b&gt;PCI-DSS&lt;/b&gt;&amp;nbsp;somewhere in there as well, you just might be a winner.&lt;/span&gt;&lt;/div&gt;&lt;div class="PlainText" style="line-height: 18px;"&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="PlainText" style="line-height: 18px;"&gt;&lt;b&gt;&lt;u&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;Cool Guy Challenge:&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="PlainText"&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="line-height: 18px;"&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;We'd like to see a presentation on the probability &amp;amp;&amp;nbsp;feasibility&amp;nbsp;of *ever* getting rid of passwords.&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="PlainText" style="line-height: 18px;"&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;Business cases, even crazy ideas suggesting that leaving passwords for something better could be a good thing to do (faster, cheaper &amp;amp; better).&amp;nbsp;&lt;i&gt;(Blizzard protects their &lt;u&gt;games&lt;/u&gt; using 2-factor authentication, while many &lt;u&gt;banks&lt;/u&gt; still uses usernames &amp;amp; passwords only....)&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="PlainText" style="line-height: 18px;"&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;br /&gt;&lt;b&gt;ATTACKS&lt;/b&gt;&amp;nbsp;include online and offline attacks against all types of passwords and &amp;amp; PINs, where the purpose is to gain access to, circumvent or recover a password in some form. (Mind reading is out of scope). New &amp;amp; updated tools &amp;amp; techniques are most welcome.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;DEFENCE&lt;/b&gt;&lt;span class="Apple-style-span" style="font-weight: normal;"&gt;&amp;nbsp;includes ways to defend against online/offline attacks against passwords, including IDS, logging, ciphers, policies, awareness etc.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;USABILITY&lt;/b&gt;&lt;span class="Apple-style-span" style="font-weight: normal;"&gt;&amp;nbsp;includes user interaction designs, password policies, security awareness, password reset / recovery from a user perspective, statistics and so on.&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;b style="font-weight: normal;"&gt;&amp;nbsp;&lt;/b&gt;&lt;b&gt;== HOW TO SUBMIT ==&lt;/b&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-weight: normal;"&gt;Send your suggestions to per@thorsheim.net. Submissions will be reviewed by people from the Selmer Center and me (Per Thorsheim). Submissions &lt;/span&gt;&lt;b&gt;MUST&lt;/b&gt;&lt;span class="Apple-style-span" style="font-weight: normal;"&gt; include the following information:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-weight: normal;"&gt;1. Speaker(s) name&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-weight: normal;"&gt;2. Bio (short, should include link to online profile, website, blog etc)&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-weight: normal;"&gt;3. Title and short abstract of your presentation&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-weight: normal;"&gt;4. List of facilities required beyond the usual equipment available&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-weight: normal;"&gt;5. If you will allow materials, presentation and video to be made available online after the conference&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;All papers and presentations must be in English&lt;/b&gt;&lt;span class="Apple-style-span" style="font-weight: normal;"&gt;. With free participation and a very limited budget, we can't offer much more than the fun and usability of talking to other experts in this area, as well as free lunch both days.&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;== IMPORTANT INFORMATION FOR SUBMISSIONS ==&lt;/b&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-weight: normal;"&gt;No product marketing will be accepted. Materials presented should be your own work. No limits to technical depth - expect &lt;/span&gt;&lt;b&gt;well educated&lt;/b&gt;&lt;span class="Apple-style-span" style="font-weight: normal;"&gt; and &lt;/span&gt;&lt;b&gt;highly experienced&lt;/b&gt;&lt;span class="Apple-style-span" style="font-weight: normal;"&gt; security professionals in the audience. We will do video recordings of all presentations and make them available for free after the conference, unless you disagree. (We may even consider live streaming!)&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="PlainText" style="line-height: 18px;"&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="PlainText" style="line-height: 18px;"&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;span class="Apple-style-span" style="font-weight: normal;"&gt;&lt;/span&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;== ADDITIONAL INFORMATION ==&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="PlainText" style="line-height: 18px;"&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;We will make arrangements for an official conference hotel, preferably with a price discount available. We will also try to help those who would like to &lt;a href="http://www.fjordnorway.com/en//"&gt;see the fjords&lt;/a&gt;&amp;nbsp;before or after the conference. Of course we'll try to gather everyone for dinner on monday evening (before we start), as well on tuesday evening. There will be plenty of sightseeing opportunities available at this time of year. If anyone would like to sponsor the conference in any way, please contact me ASAP, we're open to any suggestions you might have. &lt;b&gt;We MAY be able to do limited travel reimbursements for 1-2 speakers, but only for people attending privately (not representing any commercial organisation)&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="PlainText" style="line-height: 18px;"&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-weight: normal;"&gt;Questions and comments are of course most welcome.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-weight: normal;"&gt;Best regards,&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-weight: normal;"&gt;Per Thorsheim&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-weight: normal;"&gt;CISA, CISM, CISSP-ISSAP&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8400370148915075091-4517744717781723468?l=securitynirvana.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securitynirvana.blogspot.com/feeds/4517744717781723468/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://securitynirvana.blogspot.com/2011/03/call-for-papers-passwords11.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/4517744717781723468'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/4517744717781723468'/><link rel='alternate' type='text/html' href='http://securitynirvana.blogspot.com/2011/03/call-for-papers-passwords11.html' title='Call for Papers: Passwords^11'/><author><name>Per Thorsheim</name><uri>https://profiles.google.com/113848325212589987956</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-skpoP167x04/AAAAAAAAAAI/AAAAAAAAAVU/RWc12nir74w/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='https://lh4.googleusercontent.com/-6qTsMuKe94w/TWBAZwkAWHI/AAAAAAAAARU/SJFrQGxWmkE/s72-c/header.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8400370148915075091.post-5248102991515771355</id><published>2011-03-07T23:31:00.000+01:00</published><updated>2011-03-07T23:31:49.294+01:00</updated><title type='text'>Tell me your password...</title><content type='html'>And I'll tell you who you are, where you work, and what kind of work you do. Not that you would ever lie about your password of course. :-)&lt;br /&gt;&lt;br /&gt;I saw an online article on March 4 at Computerworld Norway, entitled "&lt;a href="http://www.idg.no/computerworld/article199413.ece"&gt;&lt;b&gt;Bryter seg inn i norske bedrifter&lt;/b&gt;&lt;/a&gt;" (&lt;i&gt;&lt;a href="http://translate.google.com/translate?js=n&amp;amp;prev=_t&amp;amp;hl=no&amp;amp;ie=UTF-8&amp;amp;layout=2&amp;amp;eotf=1&amp;amp;sl=no&amp;amp;tl=en&amp;amp;u=http://www.idg.no/computerworld/article199413.ece"&gt;Google translated to English&lt;/a&gt;&lt;/i&gt;). At a recent security seminar held by &lt;a href="http://www.isf.no/"&gt;Norwegian ISF&lt;/a&gt;, a previous colleague of mine held an interesting presentation. Read the 2-page article at Computerworld first, notice some of the statements from Christian Jacobsen (now at &lt;a href="http://www.secode.com/"&gt;Secode&lt;/a&gt;).&lt;br /&gt;&lt;br /&gt;&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;Although his presentation was on social engineering, he mention seeing passwords that can somewhat &lt;i&gt;identify what type of organisation they originate from and things like gender balance among employees&lt;/i&gt;. A high percentage of men will show "men" words (hunting, fishing, sports), while with women one will see names of children, birth dates and names of spouses.&lt;br /&gt;&lt;br /&gt;Of course I'd like to challenge Christian with&lt;b&gt; "&lt;u&gt;show me some proof&lt;/u&gt;, or at least some statistics!".&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;I've thought about doing word analysis related to gender, age, type of position/role/organisation etc myself, and now I see that I've got to move forward on this subject. I've got data to analyze on this, and then some.&lt;br /&gt;&lt;br /&gt;As for the readers of this blog, if any, do you have or know about any statistics ever done on something like this? &lt;i&gt;And please, no questionnaires or simple surveys but hard facts based on real data?&lt;/i&gt;&lt;br /&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;br /&gt;&lt;i&gt;--&lt;/i&gt;&lt;br /&gt;It's late. Time to sleep. Good night.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8400370148915075091-5248102991515771355?l=securitynirvana.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securitynirvana.blogspot.com/feeds/5248102991515771355/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://securitynirvana.blogspot.com/2011/03/tell-me-your-password.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/5248102991515771355'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/5248102991515771355'/><link rel='alternate' type='text/html' href='http://securitynirvana.blogspot.com/2011/03/tell-me-your-password.html' title='Tell me your password...'/><author><name>Per Thorsheim</name><uri>https://profiles.google.com/113848325212589987956</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-skpoP167x04/AAAAAAAAAAI/AAAAAAAAAVU/RWc12nir74w/s512-c/photo.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8400370148915075091.post-4285858976909635247</id><published>2011-03-03T21:49:00.000+01:00</published><updated>2011-03-03T21:49:00.414+01:00</updated><title type='text'>Pwnd. Again.</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://lh3.googleusercontent.com/-ULfbDrYlJHY/TW_-ONCr7NI/AAAAAAAAASU/5BArnvHUGXQ/s1600/header.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="109" src="https://lh3.googleusercontent.com/-ULfbDrYlJHY/TW_-ONCr7NI/AAAAAAAAASU/5BArnvHUGXQ/s320/header.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;In October 2010 I wrote the blog post &lt;b&gt;&lt;a href="http://securitynirvana.blogspot.com/2010/10/can-you-see-my-password.html"&gt;Can You See My Password?&lt;/a&gt;&amp;nbsp;&lt;/b&gt;I wrote that as a result of a near-successful "hack" against me, and as part of a little "competition" I'm running with friends and colleagues. Unfortunately I have to write another post, this time stating the&amp;nbsp;embarrassing&amp;nbsp;fact: I&lt;b&gt; GOT PWND&lt;/b&gt;. (again).&lt;br /&gt;&lt;br /&gt;&lt;a name='more'&gt;&lt;/a&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;br /&gt;You really should read the older blog post first, to get the rules for this little competition. Basically it is about "hacking" each other in a way not done before, in order to uphold and increase security awareness. Quite simple really.&lt;br /&gt;&lt;br /&gt;Anyway; I went out with some good friends (...) for dinner and a beer. We eat, drink and talk about security topics of common interest. We even have a couple of projects we're working on - lets call it research for now. I brought my HTC Desire as well as my iPad. Err... make that the iPad I bought for my wife, our daughter and myself for christmas. Quite handy for doing quick notes, looking up stuff on the Internet and so on.&lt;br /&gt;&lt;br /&gt;Flash forward to leaving the restaurant, going to a pub. I put my phone and iPad on the table, and went to the bar to get something to drink. Several friends stayed at the table, so leaving my stuff there shouldn't be risky, right?&amp;nbsp;&lt;i&gt;(you have probably figured out where this is going already?)&lt;/i&gt;&lt;br /&gt;&lt;b&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;&lt;i&gt;&lt;/i&gt;&lt;b&gt;&lt;i&gt;If you do this kind of competition, you are never safe. You do not have any friends. You cannot trust anyone.&amp;nbsp;&lt;/i&gt;&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;i&gt;&lt;/i&gt;&lt;/b&gt;So back at the table. Pick up the iPad. Slide left-to-right. Enter PIN code. &lt;b&gt;WT...?&lt;/b&gt;&amp;nbsp;several friends around the table - smiling. Pwnd. &lt;b&gt;Again.&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;/b&gt;So here's my confession, with congratulations to my ... well... and &lt;i&gt;Anonymous&lt;/i&gt;&amp;nbsp;is taken... hm.... *&lt;i style="font-weight: bold;"&gt;friends*.&lt;/i&gt;&amp;nbsp;You know who you are. Revenge will be sweet.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8400370148915075091-4285858976909635247?l=securitynirvana.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securitynirvana.blogspot.com/feeds/4285858976909635247/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://securitynirvana.blogspot.com/2011/03/pwnd-again.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/4285858976909635247'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/4285858976909635247'/><link rel='alternate' type='text/html' href='http://securitynirvana.blogspot.com/2011/03/pwnd-again.html' title='Pwnd. Again.'/><author><name>Per Thorsheim</name><uri>https://profiles.google.com/113848325212589987956</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-skpoP167x04/AAAAAAAAAAI/AAAAAAAAAVU/RWc12nir74w/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='https://lh3.googleusercontent.com/-ULfbDrYlJHY/TW_-ONCr7NI/AAAAAAAAASU/5BArnvHUGXQ/s72-c/header.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8400370148915075091.post-4179562220409454818</id><published>2011-02-24T14:32:00.000+01:00</published><updated>2011-02-24T14:32:22.055+01:00</updated><title type='text'>Oppdater din PC del 1 (Java)</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-QpqBDRPGlFI/TWZQEt28BDI/AAAAAAAAARo/PK9OgoeGMtE/s1600/header.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="42" src="http://3.bp.blogspot.com/-QpqBDRPGlFI/TWZQEt28BDI/AAAAAAAAARo/PK9OgoeGMtE/s400/header.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Ovenstående bilde er tatt fra nettbanken min, men det kunne selvfølgelig vært tatt fra en rekke andre steder også. Det er nok av sikkerhetsfolk og andre som skriver og sier dette - du kan simpelthen ikke ha unngått å lese det. &lt;b&gt;Men hva betyr det i praksis?&lt;/b&gt; Jeg skal lage noen enkle guider med skjermbilder for å forklare hva du bjør gjøre, og jeg begynner med &lt;b&gt;oppdatering av Java Runtime Environment&lt;/b&gt;.&lt;br /&gt;&lt;br /&gt;&lt;a name='more'&gt;&lt;/a&gt;På godt norsk er Java et lite program som igjen gjør at andre programmer, spill og reklame (!) kan vises på datamaskinen din og på nettsider.&lt;br /&gt;&lt;br /&gt;Du har mest sannsynlig Java på din Windows datamaskin allerede. I de fleste nettbanker bruker man nå &lt;b&gt;&lt;a href="http://www.bankid.no/"&gt;BankID&lt;/a&gt;&amp;nbsp;&lt;/b&gt;for å logge seg på, og BankID bruker Java. Java har en logo som ser slik ut (du vil se denne mange steder når Java brukes, i ulike farger og størrelser):&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-lNJaw3Go0Fg/TWZSizpueQI/AAAAAAAAARs/BY1XPyJ_L3w/s1600/java_logo.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/-lNJaw3Go0Fg/TWZSizpueQI/AAAAAAAAARs/BY1XPyJ_L3w/s1600/java_logo.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Java sjekker automatisk for oppdateringer, &lt;b&gt;men dette skjer ikke før du faktisk starter Java&lt;/b&gt;, f.eks. når du skal logge deg på nettbanken din. Java vil også se etter oppdateringer en gang pr måned, men du kan selv manuelt søke etter oppdateringer. I tillegg bør du også fjerne eldre versjoner av Java, dersom dette finnes på din maskin. Slik gjør du det &lt;i&gt;(skjermbildene er basert på Windows XP, men alle bilder utenom det første skal være helt lik på Vista og Windows 7)&lt;/i&gt;:&lt;br /&gt;&lt;br /&gt;&lt;b&gt;1. Gå via START menyen til Kontrollpanelet i Windows:&lt;/b&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-7C90uAoAN8o/TWZXTzCDyyI/AAAAAAAAARw/kjJ8xGFHi1U/s1600/01_Startmeny.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="280" src="http://2.bp.blogspot.com/-7C90uAoAN8o/TWZXTzCDyyI/AAAAAAAAARw/kjJ8xGFHi1U/s320/01_Startmeny.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;b&gt;2. Finn JAVA ikonet, og dobbeltklikk på dette:&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-xmk-y_eQb9U/TWZXu8__hNI/AAAAAAAAAR0/nNyYl7mB0f0/s1600/02_JAVA_ikon.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/-xmk-y_eQb9U/TWZXu8__hNI/AAAAAAAAAR0/nNyYl7mB0f0/s1600/02_JAVA_ikon.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;b&gt;3. Du får da opp dette kontrollpanelet for Java:&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/--6dUNdB0nig/TWZXvGSFBJI/AAAAAAAAAR4/3lobaSZxWJM/s1600/03_JAVA_control_panel.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="320" src="http://4.bp.blogspot.com/--6dUNdB0nig/TWZXvGSFBJI/AAAAAAAAAR4/3lobaSZxWJM/s320/03_JAVA_control_panel.png" width="283" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;b&gt;4. Derfra går du inn på "Update" delen:&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-n3CyCfPB8sc/TWZXvQvYaBI/AAAAAAAAAR8/Chc-rP8-eF4/s1600/03_JAVA_control_panel_update.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="320" src="http://2.bp.blogspot.com/-n3CyCfPB8sc/TWZXvQvYaBI/AAAAAAAAAR8/Chc-rP8-eF4/s320/03_JAVA_control_panel_update.png" width="283" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;b&gt;&lt;i&gt;Her skal du klikke en gang på "Update Now" knappen.&lt;/i&gt;&lt;/b&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;br /&gt;&lt;b&gt;5. Java vil nå sjekke etter oppdateringer.&lt;/b&gt; Dersom det er noen oppdateringer tilgjengelig, så skal du si ja til å laste den ned og installere oppdateringen. Installasjonsbildet ser slik ut:&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-mSnU8C9j_SI/TWZXzEX1_3I/AAAAAAAAASA/2-2Oh_0XIFo/s1600/05_JAVA_installer_oppdatering.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="244" src="http://1.bp.blogspot.com/-mSnU8C9j_SI/TWZXzEX1_3I/AAAAAAAAASA/2-2Oh_0XIFo/s320/05_JAVA_installer_oppdatering.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Når Java er ferdig oppdatert så er du litt sikrere i forhold til bruk av nettbank og Internett generelt.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Imidlertid kan det også ligge gamle versjoner av Java på maskinen din, som oppdateringsprogrammet ikke fjerner automatisk. Dette kan du sjekke på følgende måte:&lt;/b&gt;&lt;br /&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;br /&gt;&lt;b&gt;6. I Windows kontrollpanelet skal du dobbeltklikke på dette ikonet:&lt;/b&gt;&lt;br /&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-X5SaW0fOPwM/TWZZMmSkxII/AAAAAAAAASM/WfzI2nc5EoA/s1600/04_Legg_til_eller_fjern_programmer_ikon.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/-X5SaW0fOPwM/TWZZMmSkxII/AAAAAAAAASM/WfzI2nc5EoA/s1600/04_Legg_til_eller_fjern_programmer_ikon.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;br /&gt;&lt;b&gt;7. Du får da opp et vindu som viser installerte programmer på din Windows maskin:&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-mpcVejjZ6-s/TWZZMoQmTGI/AAAAAAAAASI/KFYmhnicDA4/s1600/04_Legg_til_eller_fjern_programmer_2_java_oppdatert.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="186" src="http://4.bp.blogspot.com/-mpcVejjZ6-s/TWZZMoQmTGI/AAAAAAAAASI/KFYmhnicDA4/s400/04_Legg_til_eller_fjern_programmer_2_java_oppdatert.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Her ser du at jeg har Java(TM) 6 Update 24 installert, og du ser Java logoen (en kaffekopp...) til venstre for navnet. Dersom du har flere versjoner installert, vist gjennom flere linjer i bildet over (f.eks. kan det stå &lt;i&gt;Java(TM) 6 Update 7&lt;/i&gt;), så klikker du på disse og deretter Avinstaller/remove knappen som vises.&lt;br /&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;br /&gt;&lt;b&gt;Versjon 6 oppdatering 24 &lt;/b&gt;er den nyeste versjonen av Java, og du bør helst ikke ha noen eldre versjoner installert på maskinen din. Neste versjon av Java er planlagt å komme om kvelden den 7. juni 2011. Da er det på tide å gjenta denne prosessen - for å være sikrest mulig.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;u&gt;Så en liten advarsel til slutt:&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;Du bør ikke gjøre dette selv på maskinen du benytter på jobb, uten først å sjekke med IT-avdelingen. De bør ha en sentralisert styring av slike oppdateringer, og installasjon/fjerning av andre Java versjoner kan forårsake problemer. Så er det sagt. :-)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8400370148915075091-4179562220409454818?l=securitynirvana.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securitynirvana.blogspot.com/feeds/4179562220409454818/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://securitynirvana.blogspot.com/2011/02/oppdater-din-pc-del-1-java.html#comment-form' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/4179562220409454818'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/4179562220409454818'/><link rel='alternate' type='text/html' href='http://securitynirvana.blogspot.com/2011/02/oppdater-din-pc-del-1-java.html' title='Oppdater din PC del 1 (Java)'/><author><name>Per Thorsheim</name><uri>https://profiles.google.com/113848325212589987956</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-skpoP167x04/AAAAAAAAAAI/AAAAAAAAAVU/RWc12nir74w/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-QpqBDRPGlFI/TWZQEt28BDI/AAAAAAAAARo/PK9OgoeGMtE/s72-c/header.png' height='72' width='72'/><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8400370148915075091.post-2101214029493809474</id><published>2011-02-22T23:57:00.004+01:00</published><updated>2011-02-23T08:01:47.423+01:00</updated><title type='text'>Far Out Dude!</title><content type='html'>This is a blog post specifically for Davey Winder (&lt;a href="http://happygeeknewmedia.blogspot.com/"&gt;@happygeek&lt;/a&gt;), after I read your article "&lt;a href="http://www.itpro.co.uk/blogs/2011/02/21/the-password-cracking-software-enigma/"&gt;The password cracking software enigma&lt;/a&gt;". I came across the article through &lt;a href="http://twitter.com/WeldPond"&gt;@WeldPond&lt;/a&gt;, who retweeted a message from &lt;a href="http://twitter.com/L0phtCrackLLC"&gt;@L0phtCrackLLC&lt;/a&gt;&amp;nbsp;saying "&lt;i&gt;&lt;b&gt;so why is exposing weak passwords and weak hashing bad again?&lt;/b&gt;&lt;/i&gt;"&lt;br /&gt;&lt;br /&gt;&lt;a name='more'&gt;&lt;/a&gt;&lt;b&gt;You must be joking.&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;You are referring to&lt;a href="http://www.lostpassword.com/kit-enterprise.htm"&gt; Passware Kit Enterprise&lt;/a&gt;, any person capable of doing copy &amp;amp; paste from your article into their Google search bar can figure that out. You almost make it sound like this is nothing more than a commercialized "hacking" application, bashing their marketing of this as a forensic toolkit. There are others like them, but you could easily have contacted them to give them a fair opportunity to explain their product, pricing and target audience for their products. You probably didn't, and I guess you didn't inform them about your article afterwards either. At least according to Norwegian press standards, that's not a nice thing to do.&lt;br /&gt;&lt;br /&gt;Just like you can use ANY car to drive from A to B &lt;b&gt;&lt;i&gt;or&lt;/i&gt;&lt;/b&gt; to kill people, you can use this software for doing good (legal forensics, exposing bad passwords), or doing bad (Cracking other peoples passwords unlawfully, with malicious intent). This really is legal software, and their latest version actually got released during &lt;a href="http://securitynirvana.blogspot.com/2010/12/videos-and-presentations-now-online.html"&gt;Passwords^10&lt;/a&gt;, a 2-day conference ONLY about passwords in December 2010. We did discuss password cracking, and we also discussed the ethics on doing exactly that. &lt;b&gt;You should have been there.&lt;/b&gt;&lt;br /&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;br /&gt;I'm not going to make a long list of situations where such software can be very useful, you've already mentioned law enforcement agencies. If an employee dies suddenly, and his laptop holding valuable business data is using Bitlocker FDE, we might need this. To analyze our true risk exposure, &lt;a href="http://blog.crackpassword.com/2010/02/why-you-should-crack-your-passwords/"&gt;cracking our passwords is a good idea&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;I am very well aware about the dangers of letting anyone purchase this software, as it may be used for illegal activity. That doesn't mean that all of us purchasing this type of software intend to do so. On the contrary in fact.&lt;br /&gt;&lt;br /&gt;To finish off, you wrote: &lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;i&gt;"&lt;span class="Apple-style-span" style="color: #222222; line-height: 16px;"&gt;But surely most enterprises have a proper password management system up and running, a system which enforces enterprise password policy and manages identity without fuss and which therefore means there is no problem in recovering ‘lost’ passwords in the first place."&lt;/span&gt;&lt;/i&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;i&gt;&lt;span class="Apple-style-span" style="color: #222222; line-height: 16px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/i&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #222222;"&gt;&lt;span class="Apple-style-span" style="line-height: 16px;"&gt;&lt;b&gt;Uh... No. Sorry, you're wrong.&lt;/b&gt; Nice assumption, but you are wrong. Ask any IT security auditor that have been working with this stuff for at least a couple of years, they should be able to confirm that &lt;b&gt;BAD passwords are everywhere&lt;/b&gt;. Password auditing/forensic software will help to find, document and &lt;b&gt;FIX&lt;/b&gt; such weaknesses. Just as it helps law enforcement agencies and others to do proper forensics even on data where others have tried to hide their illegal activity using seemingly strong passwords.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #222222;"&gt;&lt;span class="Apple-style-span" style="line-height: 16px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: #222222;"&gt;&lt;span class="Apple-style-span" style="line-height: 16px;"&gt;Let me repeat myself: I do understand your concern. Don't take it out on the vendors or those of us who actually use this type of software for good purposes. What do you know, I've even used such software to uncover ILLEGAL use of similar types of software!&lt;/span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8400370148915075091-2101214029493809474?l=securitynirvana.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://happygeeknewmedia.blogspot.com/2011/02/password-cracking-software-enigma.html#links' title='Far Out Dude!'/><link rel='replies' type='application/atom+xml' href='http://securitynirvana.blogspot.com/feeds/2101214029493809474/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://securitynirvana.blogspot.com/2011/02/far-out-dude.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/2101214029493809474'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/2101214029493809474'/><link rel='alternate' type='text/html' href='http://securitynirvana.blogspot.com/2011/02/far-out-dude.html' title='Far Out Dude!'/><author><name>Per Thorsheim</name><uri>https://profiles.google.com/113848325212589987956</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-skpoP167x04/AAAAAAAAAAI/AAAAAAAAAVU/RWc12nir74w/s512-c/photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8400370148915075091.post-711716772868740777</id><published>2011-02-21T22:48:00.000+01:00</published><updated>2011-02-21T22:48:59.266+01:00</updated><title type='text'>About Biometrics...</title><content type='html'>&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-KfjSXZvas2g/TWLNq071JNI/AAAAAAAAARg/hgGPDHFnjlo/s1600/Vein_header.jpg" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/-KfjSXZvas2g/TWLNq071JNI/AAAAAAAAARg/hgGPDHFnjlo/s1600/Vein_header.jpg" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;i&gt;(ATM with vein scanner technology)&lt;/i&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;As mentioned earlier, I had the pleasure of attending the opening of the &lt;a href="http://www.nislab.no/biometrics_lab/opening"&gt;Biometrics lab&lt;/a&gt; at NISLAB, part of Gjøvik University College. I was invited by &lt;a href="http://english.hig.no/employee/faculty_of_computer_science_and_media_technology/christoph_busch"&gt;Professor Christoph Busch&lt;/a&gt;&amp;nbsp;to participate in a panel discussion on biometric authentication. Now I am&amp;nbsp;definitely not an expert on biometrics, but I believe I'm rather good at playing the role of being the Devils advocate. While on the train from Oslo to Gjøvik early tuesday morning (that's a 2 hour trip), I scribbled down some thoughts on &lt;b&gt;Attacking Biometrics.&lt;/b&gt;&amp;nbsp;Partially as a simple brain dump for myself, partially as a possible introduction from my side. After 10 slides I decided I had too many questions and concerns, but here are some simple questions.&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;/div&gt;&lt;a name='more'&gt;&lt;/a&gt;Oh, and &lt;a href="http://english.hig.no/employee/faculty_of_computer_science_and_media_technology/bian_yang"&gt;Bian Yang&lt;/a&gt;: you sure answered several of my questions with your presentation! :-)&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;b&gt;&lt;u&gt;Here's a simple one:&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;i&gt;Introducing biometric authentication to my credit card, my wife suddenly can't go shopping with my card anymore.&lt;/i&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;Mr Hisao Ogata of &lt;a href="http://www.hitachi-omron-ts.com/"&gt;Hitachi-Omron Terminal Solutions&lt;/a&gt; explained that in Japan they've used ATMs with biometric authentication for some 5 years already (see top picture). They still support authentication using chip/magstripe/pin, but with lower withdrawal limitations compared to full biometric authentication. This way a stolen card can only be used to withdraw a smaller amount, either set by the owner or the card issuer. Really elegant solution!&lt;/div&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: 1em; margin-right: 1em; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-itw55rmhqkM/TWLL1HH-BcI/AAAAAAAAARc/BLc8bULGKjI/s1600/Vein_header.jpg" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/-itw55rmhqkM/TWLL1HH-BcI/AAAAAAAAARc/BLc8bULGKjI/s1600/Vein_header.jpg" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;i&gt;(Using special light, a vein scanner can see your unique blood vein patterns)&lt;/i&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;br /&gt;&lt;div class="" style="clear: both; text-align: left;"&gt;One of the things I expressed concerns about was the lack of end-to-end security, where a hardware biometric authenticator is attached typically using USB to a Microsoft Windows system inside an ATM. The operating system will be equipped with hardware drivers (most probably not digitally signed, and the application will then talk to the drivers, and the drivers talk to the hardware. With an attack towards the operating system, a concern would be that an attacker can intercept and record the biometric data being sent from the hardware to the operating system/application, and use this in a replay attack. &lt;i&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;a href="http://www.imdb.com/title/tt0105435/quotes?qt0448965"&gt;(&lt;span class="Apple-style-span" style="color: #333333; line-height: 17px;"&gt;Hi, my name is Werner Brandes. My voice is my passport. Verify Me.)&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/i&gt;&amp;nbsp;&lt;/div&gt;&lt;div class="" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="" style="clear: both; text-align: left;"&gt;Not the easiest attack of course, but I've seen ATMs running Windows with easily accessible Ethernet and power cables, without camera coverage. Never say never.&lt;/div&gt;&lt;div class="" style="clear: both; text-align: left;"&gt;&lt;i&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="" style="clear: both; text-align: left;"&gt;&lt;b&gt;Thomas Bengs &lt;/b&gt;from &lt;a href="http://www.fujitsu.com/emea/products/"&gt;PFU Imaging Solutions&lt;/a&gt; &lt;i&gt;(part of Fujitsu) &lt;/i&gt;answered this one for me: they are working on removing as many steps as possible in the process of authentication, lowering the possible entry points for any hacker wanting to break, see or even manipulate the process. I can't see that happening overnight, but still a good answer to my concern.&lt;/div&gt;&lt;div class="" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="" style="clear: both; text-align: left;"&gt;&lt;b&gt;Bian Yang&lt;/b&gt;&amp;nbsp;mentioned the use of biometric templates, which could be used for (too me) the obvious question:&lt;/div&gt;&lt;div class="" style="clear: both; text-align: left;"&gt;&lt;i&gt;What happens if somebody can steal my biometric password, be it my fingerprint or the digital representation of either my fingerprint or vein pattern?&lt;/i&gt;&lt;/div&gt;&lt;div class="" style="clear: both; text-align: left;"&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class="" style="clear: both; text-align: left;"&gt;I've got to be honest here: I need to get this explained again. And again. I can hear what you're saying, but I can't see this being any better than resetting a password to something *completely* different than the last one. &amp;nbsp;&lt;i&gt;(Edit-distance metrics of password generations contributed to this concern...)&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;Now Mr Waldemar Grudzien of &lt;a href="http://www.bankenverband.de/"&gt;Bundesverband deutscher Banken&lt;/a&gt;, as well as Andreas Ewig of&amp;nbsp;&lt;span class="Apple-style-span" style="line-height: 16px;"&gt;&lt;span class="Apple-style-span" style="font-family: inherit;"&gt;&lt;a href="http://www.dsgv.de/de/"&gt;Deutscher Sparkassen- und Giroverband&amp;nbsp;&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;had some realistic views of this technology. Nicely summarized, they wanted this technology to be faster, more secure and cheaper than current technology for it to become widely adopted and deployed. Probably easier said than done at present time, but they were also very realistic on something else: Current losses are increasing due to fraud. Still not at a level that is "unacceptable" financially, and certainly not enough to defend the adoption of biometric authentication for ATMs yet.&lt;br /&gt;&lt;br /&gt;Their very best statement though: &lt;b&gt;This is a question about trust. If people loose their trust in current systems, banks (and others) may not have any alternatives than to migrate to new technologies that may not really be needed now.&lt;/b&gt;&lt;br /&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;br /&gt;&lt;b&gt;Fear, Uncertainty and Doubt.&lt;/b&gt;&amp;nbsp;Most certainly some of the more powerful business drivers in our society today.&lt;br /&gt;&lt;i&gt;(More to come in the future)&lt;/i&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8400370148915075091-711716772868740777?l=securitynirvana.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securitynirvana.blogspot.com/feeds/711716772868740777/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://securitynirvana.blogspot.com/2011/02/about-biometrics.html#comment-form' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/711716772868740777'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/711716772868740777'/><link rel='alternate' type='text/html' href='http://securitynirvana.blogspot.com/2011/02/about-biometrics.html' title='About Biometrics...'/><author><name>Per Thorsheim</name><uri>https://profiles.google.com/113848325212589987956</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-skpoP167x04/AAAAAAAAAAI/AAAAAAAAAVU/RWc12nir74w/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-KfjSXZvas2g/TWLNq071JNI/AAAAAAAAARg/hgGPDHFnjlo/s72-c/Vein_header.jpg' height='72' width='72'/><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8400370148915075091.post-8154919878692836071</id><published>2011-02-21T08:00:00.066+01:00</published><updated>2011-02-21T08:00:07.550+01:00</updated><title type='text'>Speaking &amp; writing schedule</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-dj47svg5YsY/TWF-Wxi2pwI/AAAAAAAAARY/xBy5Lw9fsq4/s1600/header.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/-dj47svg5YsY/TWF-Wxi2pwI/AAAAAAAAARY/xBy5Lw9fsq4/s1600/header.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;I am sorry for not doing any blog posts about my password research for a long time. I'll try to do something about that in the near future. I'm running my cpu's and gpu's at 100% most of the time, at least when I'm not doing analysis and charting and whatever... Anyway; here's a short update of what I've done and plan to do in the very near future.&lt;br /&gt;&lt;br /&gt;&lt;a name='more'&gt;&lt;/a&gt;I've talked about mobile security issues at one of my employers events here in Bergen. I spoke about GSM security at the DND "hackers Pub" on January 31st, and then about (the lack of) security in social media in front of some 350+ people at&lt;a href="http://www.firsttuesdaybergen.com/"&gt; First Tuesday Bergen&lt;/a&gt; on February 8th. In between there, at work, I've done .. 3? 1,5 hour sessions on CISSP preparations for colleagues in and Ukraine (Hooray to video conferencing systems!).&lt;br /&gt;&lt;br /&gt;On Tuesday 15th I had the pleasure of attending the opening of the&lt;a href="http://www.nislab.no/biometrics_lab"&gt; biometrics lab&lt;/a&gt; at Gjøvik university college, as well as being part of a panel discussion on biometric authentication. A big THANK YOU to &lt;a href="http://english.hig.no/employee/faculty_of_computer_science_and_media_technology/christoph_busch"&gt;Professor Christoph Busch&lt;/a&gt; for asking me to participate (and play the role of the Devil's advocate). Not exactly "Minority report" biometrics, but very interesting to hear that most ATMs in Japan have been equipped with biometric vein authenticaiton for some 5 years now. German banks are considering the technology, while it haven't even been discussed between Norwegian banks so far. Got to get hold of one of those vein scanners to play with.... Also check out PhD student &lt;a href="http://www.derawi.com/"&gt;Mohammad Derawi&lt;/a&gt;, his work which includes a prototype app for Android that will recognize and authenticate you based on your movement/walking pattern. Cool idea, cool guy! :-)&lt;br /&gt;&lt;br /&gt;On March 3 I will be speaking at the &lt;a href="http://www.uis.no/nyheter/article30912-12.html"&gt;University of Stavanger&lt;/a&gt;, trying to provoke them a little on openness of a university vs the need for information protection. My title: "Does the University have something to hide?". Hint; they are situated right in the middle of our major Oil &amp;amp; Gas industry.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.isaca.no/default.asp?V_ITEM_ID=799"&gt;ISACA Norway Chapter&lt;/a&gt;&amp;nbsp;is hosting this years Scandinavian conference on April 4-5. I will be speaking about security issues specifically related to organisational "Codes of Conduct" and their applicability to members of the board. This is an area I've been looking into for the last 2+ years, a long with a nice group of good friends here in Bergen. Yes, our very own little "Think Tank". Truly incredible what a diverse group of security people can come up with over dinner and a few beers. :-) Personally I'm looking forward to hear the CSO of eBay, as well as many others on the current agenda.&lt;br /&gt;&lt;br /&gt;I would also like to give a pointer to my colleague Gleb Paharenko (&lt;a href="http://www.infopulse.com.ua/"&gt;Infopulse&lt;/a&gt;, Ukraine). He passed his CISSP exam in Moscow in December, currently waiting for endorsement approval. He's part of the &lt;a href="http://sites.google.com/site/uisgua/"&gt;Ukraine Information Security Group&lt;/a&gt;, organizing events to improve knowledge in this important area. I will probably bring along more links to work they're doing there in the future.&lt;br /&gt;&lt;br /&gt;By far the coolest thing so far this year for me personally: participating and speaking at the &lt;a href="http://www.nisnet.no/"&gt;NISNET&lt;/a&gt; winter school at Finse, May 22-27. Yes, NISNET provided the funding for the Passwords^10 conference, and will probably do so for &lt;a href="http://securitynirvana.blogspot.com/2011/02/passwords11.html"&gt;yet another conference on passwords only&lt;/a&gt;. Joan Daemen on hash functions (he's 50% of Rijndael, maybe better known now as AES), Ed Dawson on access control, Peter Ryan on electronic voting, Patrick Bours on authentication, Katrine Franke on digital forensics and Chunming Rong on cloud computing security. And me. on passwords. For 3-4 hours.&amp;nbsp;&lt;b&gt;*shivers* &lt;/b&gt;That is NOT an audience made up of idiots, on the contrary. Can't sleep, can't eat, can't breathe... Got to prepare for this with all I've got.&lt;br /&gt;&lt;br /&gt;Well, that was the self bragging blog post of today. Something more useful will probably appear soon. :-) Good night from Bergen, Norway.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8400370148915075091-8154919878692836071?l=securitynirvana.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securitynirvana.blogspot.com/feeds/8154919878692836071/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://securitynirvana.blogspot.com/2011/02/speaking-writing-schedule.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/8154919878692836071'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/8154919878692836071'/><link rel='alternate' type='text/html' href='http://securitynirvana.blogspot.com/2011/02/speaking-writing-schedule.html' title='Speaking &amp; writing schedule'/><author><name>Per Thorsheim</name><uri>https://profiles.google.com/113848325212589987956</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-skpoP167x04/AAAAAAAAAAI/AAAAAAAAAVU/RWc12nir74w/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-dj47svg5YsY/TWF-Wxi2pwI/AAAAAAAAARY/xBy5Lw9fsq4/s72-c/header.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8400370148915075091.post-4527986680953856223</id><published>2011-02-19T23:47:00.000+01:00</published><updated>2011-02-19T23:47:58.958+01:00</updated><title type='text'>Passwords^11?</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-6qTsMuKe94w/TWBAZwkAWHI/AAAAAAAAARU/SJFrQGxWmkE/s1600/header.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="34" src="http://3.bp.blogspot.com/-6qTsMuKe94w/TWBAZwkAWHI/AAAAAAAAARU/SJFrQGxWmkE/s200/header.png" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;b&gt;Quick and dirty:&lt;/b&gt;&lt;br /&gt;I've talked with Professor Tor Helleseth, and he's got a budget to sponsor another password conference. IF we do it, we'll have to do it before end of June 2011, according to budgets, grants etc. I've been asked to provide some suggestions for main topics that we can include in a CFP. I would like to know your opinion.&lt;br /&gt;&lt;br /&gt;&lt;a name='more'&gt;&lt;/a&gt;I learned at lot about organizing a security conference. :-) If we do this again, I will make arrangements for a "official" conference hotel, preferably with a discount package. Especially for foreign participants I will also try to arrange, or at least get some reasonable info for sightseeing before or after the conference. And I PROMISE; I will provide maps with the exact location of the University building for the conference. ;-)&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Anyway; the important stuff:&lt;/b&gt;&lt;br /&gt;In order to progress from Passwords^10 (which got a 4.6/5 overall rating!), I've been thinking about the following areas, in addition to those that got covered last time:&lt;br /&gt;&lt;br /&gt;1. "Best practice", real-life war/success stories on using various hash algorithms (This F-Secure blog post is an interesting reference:&amp;nbsp;&lt;a href="https://webmail.edb.com/OWA/redir.aspx?C=21950b99b7124bcab8282bc1bce857c8&amp;amp;URL=http%3a%2f%2fwww.f-secure.com%2fweblog%2farchives%2f00002095.html" target="_blank"&gt;http://www.f-secure.com/weblog/archives/00002095.html&lt;/a&gt;)&lt;br /&gt;&lt;span&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span&gt;2. &lt;span style="font: 7pt 'Times New Roman';"&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;Self-reset password solutions. People do forget their passwords. How do you handle that?&lt;br /&gt;&lt;br /&gt;3. Out-of-Band password authentication : does it work? risks? SMS? Voice? Snail mail?&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;u&gt;A few entries for my own wishlist of talks I'd like to see:&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;1. Using statistical analysis to improve password guessing attacks (Matt Weir? ;-))&lt;br /&gt;2. Hybrid Rainbow Tables - evolution beyond length 8 (FreeRainbowTables - Quel?)&lt;br /&gt;3. Howard Smith from Oracle - Ethics part two: responsible disclosure (yes, seriously!)&lt;br /&gt;4. Passware : "First we'll take Firewire - then we'll take PCMCIA/Expresscard" (reference:&amp;nbsp;&lt;a href="http://arstechnica.com/tech-policy/news/2011/02/black-ops-how-hbgary-wrote-backdoors-and-rootkits-for-the-government.ars"&gt;http://arstechnica.com/tech-policy/news/2011/02/black-ops-how-hbgary-wrote-backdoors-and-rootkits-for-the-government.ars&lt;/a&gt;)&lt;br /&gt;5. Elcomsoft : Evolution of EDPR and EPPB (naturally) - Andrey: some of the iOS backup stuff we've discussed so far. Working on a blog post + PPT on deploying iTunes/iPhone "securely" with ActiveSync in an organisation.&lt;br /&gt;6. Already talked to Kirsi Helkala - her "3 simple words" was kinda cool - I'd like to see more statistics! :-)&lt;br /&gt;7. KoreLogic: *anything*: I'm interested. :-)&lt;br /&gt;8. PCI-DSS: passwords and encryption (covering latest version of PCI-DSS)&lt;br /&gt;9: HIDDN hardware AES encryption, protected by smart cards. Would love to ask you questions on your products.&lt;br /&gt;10. The ultimate John the Ripper walkthrough&lt;br /&gt;11. Pass-the-Hash / Pass-the-Ticket (Kerberos) attacks - do, detect, block (?), improve. TrueSec in Sweden; you are most welcome. :-)&lt;br /&gt;12. CSO of PlentyofFish or anyone else who got compromised : what happened, what to do, lessons learned?&lt;br /&gt;13. The researchers who compared 2 lists of compromised services and found password reuse to be more than a myth.&lt;br /&gt;14. Anyone who studies human nature behavior, patterns etc: why do we choose simple passwords? Why do we forget them? (Psychologists wanted...)&lt;br /&gt;&lt;br /&gt;I'd like to hear your opinion. :-)&lt;br /&gt;&lt;br /&gt;Best regards,&lt;br /&gt;Per&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8400370148915075091-4527986680953856223?l=securitynirvana.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securitynirvana.blogspot.com/feeds/4527986680953856223/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://securitynirvana.blogspot.com/2011/02/passwords11.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/4527986680953856223'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/4527986680953856223'/><link rel='alternate' type='text/html' href='http://securitynirvana.blogspot.com/2011/02/passwords11.html' title='Passwords^11?'/><author><name>Per Thorsheim</name><uri>https://profiles.google.com/113848325212589987956</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-skpoP167x04/AAAAAAAAAAI/AAAAAAAAAVU/RWc12nir74w/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-6qTsMuKe94w/TWBAZwkAWHI/AAAAAAAAARU/SJFrQGxWmkE/s72-c/header.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8400370148915075091.post-4289939886384449828</id><published>2011-02-12T13:22:00.000+01:00</published><updated>2011-02-12T13:22:22.771+01:00</updated><title type='text'>Facebook, sikkerhet og apper</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-Q99KlUaiiZ8/TVEDhNVlDgI/AAAAAAAAARE/D07e3tksJJY/s1600/Header.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="17" src="http://1.bp.blogspot.com/-Q99KlUaiiZ8/TVEDhNVlDgI/AAAAAAAAARE/D07e3tksJJY/s320/Header.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;Min kollega Terje Karlsen leste mitt blogginnlegg &lt;a href="http://securitynirvana.blogspot.com/2011/02/bedre-sikkerhet-nar-du-bruker-facebook.html"&gt;Bedre sikkerhet når du bruker Facebook&lt;/a&gt;, og sendte meg en kommentar på den. Etter avtale med Terje har jeg valgt å publisere hans kommentar som et eget innlegg, et innlegg som spesielt apputviklere til Facebook bør merke seg.&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;/div&gt;&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;Hei Per!&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;Muligheten for å alltid kjøre HTTPS når en benytter Facebook  – dersom tilgjengelig er vel og bra, men undertegnede er grunnleggende skeptisk  til første versjon av all programvare og da spesielt ift sosiale medier som  tilbyr bedre sikkerhet.&amp;nbsp;Jeg utførte dine anbefalte endringer og fikk mail da jeg  logget på med jobb-pc første gang. Navnet jeg oppga ble også registrert på  profilen min:&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-LBuwYjJ8cMM/TVZ5EjxLOOI/AAAAAAAAARI/w4QAjfqOl1g/s1600/Bilde_1.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="146" src="http://2.bp.blogspot.com/-LBuwYjJ8cMM/TVZ5EjxLOOI/AAAAAAAAARI/w4QAjfqOl1g/s320/Bilde_1.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;Mange brukere benytter Facebook til spill, og det viser seg  at dersom en etter å ha logget inn på Facebook velger et spill vil en få opp  denne meldingen:&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-hSW-mAPOnfw/TVZ5E8MF-uI/AAAAAAAAARM/QAy6le6-csQ/s1600/Bilde_2.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="98" src="http://1.bp.blogspot.com/-hSW-mAPOnfw/TVZ5E8MF-uI/AAAAAAAAARM/QAy6le6-csQ/s320/Bilde_2.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;De fleste brukere vil da tenke at ok, jeg er på et sikkert  nett så det spiller ingen rolle, og velge &lt;b&gt;fortsett&lt;/b&gt;. Det man imidlertid IKKE  får beskjed om er at Facebook da fjerner krysset for sikker nettsurfing:&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-gSno34MFeIc/TVZ5FJpG4vI/AAAAAAAAARQ/WP5iOmgChPo/s1600/Bilde_3.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="136" src="http://4.bp.blogspot.com/-gSno34MFeIc/TVZ5FJpG4vI/AAAAAAAAARQ/WP5iOmgChPo/s320/Bilde_3.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;Med andre ord har en fått endret sin sikkerhetsinnstilling  uten å få tydelig melding om dette. Endringen vil da påvirke all bruk av  Facebook, ikke bare i denne sesjonen eller på denne maskinen, og urutinerte  brukere vil tro at de benytter HTTPS hver gang.&amp;nbsp;Ikke bra Facebook!!!&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8400370148915075091-4289939886384449828?l=securitynirvana.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securitynirvana.blogspot.com/feeds/4289939886384449828/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://securitynirvana.blogspot.com/2011/02/facebook-sikkerhet-og-apper.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/4289939886384449828'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/4289939886384449828'/><link rel='alternate' type='text/html' href='http://securitynirvana.blogspot.com/2011/02/facebook-sikkerhet-og-apper.html' title='Facebook, sikkerhet og apper'/><author><name>Per Thorsheim</name><uri>https://profiles.google.com/113848325212589987956</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-skpoP167x04/AAAAAAAAAAI/AAAAAAAAAVU/RWc12nir74w/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-Q99KlUaiiZ8/TVEDhNVlDgI/AAAAAAAAARE/D07e3tksJJY/s72-c/Header.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8400370148915075091.post-8592889603850264808</id><published>2011-02-08T10:10:00.000+01:00</published><updated>2011-02-08T10:10:13.812+01:00</updated><title type='text'>Bedre sikkerhet når du bruker Facebook</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/_qyUrb02hPrA/TVEDhNVlDgI/AAAAAAAAARE/2ITMVX9YYV0/s1600/Header.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="17" src="http://2.bp.blogspot.com/_qyUrb02hPrA/TVEDhNVlDgI/AAAAAAAAARE/2ITMVX9YYV0/s320/Header.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;Endelig har den kommet. Muligheten for at jeg i Facebook innstillingene mine kan skru på valget for å alltid bruke Facebook via en kryptert forbindelse. En bitteliten endring med STOR effekt for ditt personvern og konto på Facebook. Dette bør du ta i bruk øyeblikkelig.&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;/div&gt;&lt;a name='more'&gt;&lt;/a&gt;Facebook har en lang historikk hvor de gang etter gang har snevret inn vårt personvern. Dette har gjort ved å la våre opplysninger i stadig større grad være tilgjengelig for absolutt alle på Facebook, og så har det vært opp til oss som brukere å begrense denne informasjonsdelingen med fremmede.&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;Mange har også fått med seg debatten om mobbing blant både barn, ungdommer og voksne som for lengst også har spredd seg til sosiale medier slik som Facebook. Selv kjenner jeg flere som har vært utsatt for slikt. I tillegg skjer det også at andre stjeler tilgang til Facebook kontoer. Dette gjøres i forbindelse med mobbing, informasjons- og ID-tyveri og en lang rekke typer økonomisk kriminalitet. Tyveri av andres Facebook kontoer ble gjort ekstremt enkelt for en tid tilbake, i form av et programtillegg kalt "Firesheep". Tyveri og misbruk av andres Facebook kontoer steg kraftig på grunn av dette.&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;Denne nye muligheten fra Facebook er i så måte svært velkommen. Dessverre har de valgt å gjøre det slik at du selv må gå inn i oppsettet for din Facebook konto og skru på funksjonen. Heldigvis er det en engangsjobb, og går svært raskt å utføre. Her er min lille steg-for-steg guide:&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;b&gt;1. Logg deg inn på Facebook&lt;/b&gt;&lt;/div&gt;&lt;br /&gt;&lt;b&gt;2. På meyen "Brukerkonto" oppe til høyre velger du "Kontoinnstillinger":&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/_qyUrb02hPrA/TVEDQeVOm5I/AAAAAAAAAQ4/RTUefEPXDjk/s1600/Meny_1.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/_qyUrb02hPrA/TVEDQeVOm5I/AAAAAAAAAQ4/RTUefEPXDjk/s1600/Meny_1.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;b&gt;3. Neste bilde ser slik ut &lt;/b&gt;&lt;i&gt;(klikk bildet for å se full størrelse)&lt;/i&gt;:&lt;br /&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/_qyUrb02hPrA/TVEDQuPHxkI/AAAAAAAAAQ8/47pI05NW77k/s1600/Meny_2.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="297" src="http://3.bp.blogspot.com/_qyUrb02hPrA/TVEDQuPHxkI/AAAAAAAAAQ8/47pI05NW77k/s320/Meny_2.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Her skal du klikke deg inn på valget &lt;b&gt;Kontosikkerhet&lt;/b&gt;.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;4. Du skal da på neste bilde se blant annet dette:&lt;/b&gt;&lt;br /&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/_qyUrb02hPrA/TVEDQwTQqiI/AAAAAAAAARA/7fHreS10WDo/s1600/Surf_med_HTTPS.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="181" src="http://3.bp.blogspot.com/_qyUrb02hPrA/TVEDQwTQqiI/AAAAAAAAARA/7fHreS10WDo/s320/Surf_med_HTTPS.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Her skal du sette kryss i boksen for &lt;b&gt;Surf Facebook på en sikker tilkobling (https) når mulig&lt;/b&gt;. Deretter klikker du på &lt;b&gt;Lagre&lt;/b&gt;, og så er du ferdig.&lt;br /&gt;&lt;br /&gt;Det du nå har gjort er å sørge for at alle data mellom deg og Facebook vil gå &lt;b&gt;kryptert&lt;/b&gt; (&lt;i&gt;=uleselig for andre&lt;/i&gt;) når dette er mulig. Stort sett vil det bety hele tiden. Det er straks blitt mye vanskeligere for andre å kunne avlytte din trafikk mot Facebook, du slipper ulovlig innsyn og reduserer risikoen for at andre klarer å stjele Facebook kontoen din.&lt;br /&gt;&lt;br /&gt;Enkelt og greit! :-)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8400370148915075091-8592889603850264808?l=securitynirvana.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securitynirvana.blogspot.com/feeds/8592889603850264808/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://securitynirvana.blogspot.com/2011/02/bedre-sikkerhet-nar-du-bruker-facebook.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/8592889603850264808'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/8592889603850264808'/><link rel='alternate' type='text/html' href='http://securitynirvana.blogspot.com/2011/02/bedre-sikkerhet-nar-du-bruker-facebook.html' title='Bedre sikkerhet når du bruker Facebook'/><author><name>Per Thorsheim</name><uri>https://profiles.google.com/113848325212589987956</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-skpoP167x04/AAAAAAAAAAI/AAAAAAAAAVU/RWc12nir74w/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_qyUrb02hPrA/TVEDhNVlDgI/AAAAAAAAARE/2ITMVX9YYV0/s72-c/Header.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8400370148915075091.post-8297227120874090225</id><published>2011-02-06T18:50:00.001+01:00</published><updated>2011-02-11T10:03:37.970+01:00</updated><title type='text'>Jeg_VilVite!</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;object width="320" height="266" class="BLOG_video_class" id="BLOG_video-d84a6a6584a15370" classid="clsid:D27CDB6E-AE6D-11cf-96B8-444553540000" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"&gt;&lt;param name="movie" value="http://www.youtube.com/get_player"&gt;&lt;param name="bgcolor" value="#FFFFFF"&gt;&lt;param name="allowfullscreen" value="true"&gt;&lt;param name="flashvars" value="flvurl=http://v3.nonxt8.googlevideo.com/videoplayback?id%3Dd84a6a6584a15370%26itag%3D5%26app%3Dblogger%26ip%3D0.0.0.0%26ipbits%3D0%26expire%3D1329976141%26sparams%3Did,itag,ip,ipbits,expire%26signature%3D8A7A8E7A84523448039E8DDDEE1E31C4C87625D.32881375E89CB47DF1DACF55A80CB0E597C37AD7%26key%3Dck1&amp;amp;iurl=http://video.google.com/ThumbnailServer2?app%3Dblogger%26contentid%3Dd84a6a6584a15370%26offsetms%3D5000%26itag%3Dw160%26sigh%3D90rmZ2I4tgqjj7vxepS_knKAnv0&amp;amp;autoplay=0&amp;amp;ps=blogger"&gt;&lt;embed src="http://www.youtube.com/get_player" type="application/x-shockwave-flash"width="320" height="266" bgcolor="#FFFFFF"flashvars="flvurl=http://v3.nonxt8.googlevideo.com/videoplayback?id%3Dd84a6a6584a15370%26itag%3D5%26app%3Dblogger%26ip%3D0.0.0.0%26ipbits%3D0%26expire%3D1329976141%26sparams%3Did,itag,ip,ipbits,expire%26signature%3D8A7A8E7A84523448039E8DDDEE1E31C4C87625D.32881375E89CB47DF1DACF55A80CB0E597C37AD7%26key%3Dck1&amp;iurl=http://video.google.com/ThumbnailServer2?app%3Dblogger%26contentid%3Dd84a6a6584a15370%26offsetms%3D5000%26itag%3Dw160%26sigh%3D90rmZ2I4tgqjj7vxepS_knKAnv0&amp;autoplay=0&amp;ps=blogger"allowFullScreen="true" /&gt;&lt;/object&gt;&lt;/div&gt;&lt;br /&gt;&lt;b&gt;Merk: VilVite har respondert på dette blogginnlegget, se kommentarer på slutten. Stor takk til god og rask respons fra VilVite!&lt;/b&gt;&lt;br /&gt;Søndag 6 februar var jeg på &lt;a href="http://www.vilvite.no/"&gt;VilVite&lt;/a&gt; senteret i Bergen, med min datter og en av hennes venninner. Et fantastisk sted for både store og små, med leker og aktiviteter av den typen som er både morsomme og lærerike. I tillegg har de alle en flott forankring i vitenskapens verden. Så gøy at vi forlengst har anskaffet oss årskort. Men så var det dette med sikkerhet da....&lt;br /&gt;&lt;br /&gt;&lt;a name='more'&gt;&lt;/a&gt;VilVite senteret bruker RFID brikker som adgangskort, både for dagsbesøk og for årskort, slik vi har. Ved å bruke disse elektroniske kortene kan man registrere seg med navn og e-post adresse, og deretter registrere sin innsats på flere ulike aktiviteter. &lt;i&gt;(Videoen over er fra dagens kjøring av &lt;b&gt;Sentrifugalskapen&lt;/b&gt;, en sykkel hvor du tråkker deg rundt til bildet går i svart, eller de ansatte stopper deg. Hva gjør man ikke for sin datter?)&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;Jeg ble gjort oppmerksom på muligheten for registrering og uthenting av video fra &lt;i&gt;Sentrifugalskapen&lt;/i&gt;&amp;nbsp;i dag, og registrerte meg rett etter på en av de mange utplasserte terminalene deres. Enkelt og greit, e-post adresse og passord (krav: minimum 8 karakterers lengde).&lt;br /&gt;&lt;br /&gt;Da jeg kom hjem hadde jeg fått e-post fra Vilvite, &lt;b&gt;med mitt passord oppgitt i klartekst&lt;/b&gt;, og beskjed om at jeg kunne logge meg inn på websidene deres. Allerede litt irritert går jeg inn på www.vilvite.no, og derfra videre til&amp;nbsp;&lt;a href="http://minside.vilvite.no/mp/index.php"&gt;minside.vilvite.no&lt;/a&gt;. Jahaja. &lt;b&gt;Ingen bruk av SSL kryptering ved innlogging&lt;/b&gt;.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;u&gt;Enkelt oppsummert:&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;VilVite senteret, sammen med sine 2 utviklere, &lt;a href="http://www.expology.no/expose/sites/expology_no/?s=1"&gt;Expology&lt;/a&gt;&amp;nbsp;og &lt;a href="http://www.fuggibaggidesign.com/"&gt;FuggiBagi Design&lt;/a&gt;, bryter altså to av de aller mest elementære regler for sikkerhet i Internett løsninger:&lt;br /&gt;&lt;br /&gt;1. Bruk alltid SSL kryptering for å beskytte minimum innlogging, helst alt innhold av personlig karakter.&lt;br /&gt;2. ALDRI ALDRI ALDRI lagre eller sende brukeres passord i klartekst, men implementere en enkel løsning for å resette passord dersom brukeren har glemt det.&lt;br /&gt;&lt;br /&gt;Tålmodigheten ble ikke bedre da det ikke var noen mulighet for å slette enkeltelementer fra min profil (f.eks. dagens video), eneste alternativ jeg fant var å slette hele min profil.&lt;br /&gt;&lt;br /&gt;Så jeg vil gjerne vite om &lt;b&gt;VilVite &lt;/b&gt;vil endre på sin løsning, slik at den bedre ivaretar personvernet til barn og voksne som benytter deres mange muligheter?&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8400370148915075091-8297227120874090225?l=securitynirvana.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securitynirvana.blogspot.com/feeds/8297227120874090225/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://securitynirvana.blogspot.com/2011/02/jegvilvite.html#comment-form' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/8297227120874090225'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/8297227120874090225'/><link rel='alternate' type='text/html' href='http://securitynirvana.blogspot.com/2011/02/jegvilvite.html' title='Jeg_VilVite!'/><author><name>Per Thorsheim</name><uri>https://profiles.google.com/113848325212589987956</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-skpoP167x04/AAAAAAAAAAI/AAAAAAAAAVU/RWc12nir74w/s512-c/photo.jpg'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8400370148915075091.post-5542317652674666511</id><published>2011-01-31T00:03:00.000+01:00</published><updated>2011-01-31T00:03:59.897+01:00</updated><title type='text'>Høyre og #DLD</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_qyUrb02hPrA/TUXjMcAVAII/AAAAAAAAAQw/4awpmDWFC58/s1600/Header.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_qyUrb02hPrA/TUXjMcAVAII/AAAAAAAAAQw/4awpmDWFC58/s1600/Header.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;I anledning Nasjonal Sikkerhetsdag 2010 lanserte min arbeidsgiver en rapport om hvordan &lt;a href="http://www.edb.com/no/Konsern/Aktuelt/Aktuelt/Taushetsbelagt-informasjon-sendes-ukryptert-via-e-post-i-Norge/"&gt;taushetsbelagt informasjon sendes ukryptert via e-post i Norge&lt;/a&gt;. Rapporten var utarbeidet av meg sammen med min kollega Jan Fredrik Leversund, og fikk &lt;a href="http://www.dagensit.no/article1881581.ece"&gt;tydelig oppmerksomhet i media&lt;/a&gt;. Nå er snart ett år gått, og spørsmålet kommer naturlig: Har det skjedd noe siden sist?&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a name='more'&gt;&lt;/a&gt;&lt;b&gt;Svaret er JA.&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;Først av alt: denne bloggposten er og blir mine private meninger. Nummer 2: denne bloggposten er ikke ment å fremheve noe ståsted fra min side ift Datalagringsdirektivet. Imidlertid vil jeg bare påpeke overfor Høyre at i forhold til at de enda ikke har bestemt seg ift Datalagringsdirektivet, så kan de jo uansett rydde litt i eget hus før endelig standpunkt blir tatt?&lt;br /&gt;&lt;br /&gt;&lt;b&gt;I forbindelse med fjorårets undersøkelse så vi selvfølgelig på hvordan våre politiske partier hadde satt opp håndtering av innkommende e-post til seg selv.&amp;nbsp;&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;Vi smilte litt når distriktsvennlige Venstre viste seg å ha outsourcet kontroll av all innkommende e-post til et firma i Danmark. Dette betød i praksis at stort sett alle i Norge som sendte e-post til Venstre ville få sin e-post sendt gjennom Sverige til Danmark, og så tilbake til korrekt mottaker i Venstre via Sverige, etter antivirus kontroll i Danmark. Jahaja. Venstre, som var så tydelig i &lt;a href="http://www.datatilsynet.no/templates/article____3230.aspx"&gt;debatten rundt den Svenske FRA-loven&lt;/a&gt;, sendte selv sin mail via Sverige til Danmark og tilbake? Jeg skal ikke fremsette noen påstand om forskjell mellom liv og lære, men selvfølgelig; det frister.&lt;br /&gt;&lt;br /&gt;Uansett; i løpet av de 9 månedene som har gått nå, så har Venstre "flyttet hjem". Sender jeg e-post til Venstre i dag, så får ihvertfall ikke svenskene uten videre mulighet til å lese hva jeg skriver til dem. De andre partiene på stortinget i dag er allerede trygt forankret her hjemme i Norge. Med unntak av ett:&lt;br /&gt;&lt;br /&gt;Høyre derimot, de har fortsatt outsourcet til utlandet. De benytter fortsatt en leverandør i Danmark, men har skiftet leverandør minst en gang siden forrige sjekk i april 2010. Nå ser det slik ut (i prioritert rekkefølge fra topp til bunn):&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;hoyre.no mail is handled by 10 gw1-sec.net.comendo.com&lt;br /&gt;hoyre.no mail is handled by 20 gw2-sec.net.comendo.com&lt;br /&gt;hoyre.no mail is handled by 30 gw3-sec.net.comendo.com&lt;br /&gt;&lt;br /&gt;Slik jeg leser det, og oversatt til godt forståelig Norsk, så har Høyre inngått en avtale med &lt;a href="http://www.comendo.no/"&gt;Comendo Norge AS&lt;/a&gt; om at de skal håndtere e-post sikkerhet for partiet. Comendo Norge benytter imidlertid &lt;a href="http://www.comendo.com/"&gt;morselskapet i Danmark&lt;/a&gt; for å håndtere det tekniske. Dermed vil e-post sendt fra nesten hvem-som-helst i Norge til Høyre gå via Sverige til Danmark for antivirus kontroll før det returneres samme vei til korrekt mottaker i partiet her hjemme i Norge.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Nå stoler jo vi på søta bror. Ingen ville jo finne på å tro at de ville ha noen interesse av å kunne lese e-post mellom Høyre og de aller fleste personer, organisasjoner og virksomheter i Norge. Ikke et dumt ord om Høyre, dette har de selvfølgelig risikovurdert og funnet akseptabelt i forhold til alle typer risiko. Eller?&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8400370148915075091-5542317652674666511?l=securitynirvana.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securitynirvana.blogspot.com/feeds/5542317652674666511/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://securitynirvana.blogspot.com/2011/01/hyre-og-dld.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/5542317652674666511'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/5542317652674666511'/><link rel='alternate' type='text/html' href='http://securitynirvana.blogspot.com/2011/01/hyre-og-dld.html' title='Høyre og #DLD'/><author><name>Per Thorsheim</name><uri>https://profiles.google.com/113848325212589987956</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-skpoP167x04/AAAAAAAAAAI/AAAAAAAAAVU/RWc12nir74w/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_qyUrb02hPrA/TUXjMcAVAII/AAAAAAAAAQw/4awpmDWFC58/s72-c/Header.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8400370148915075091.post-8624280386487231437</id><published>2011-01-11T18:12:00.001+01:00</published><updated>2011-01-11T18:30:08.017+01:00</updated><title type='text'>Now Recruiting: Password Mules!</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_qyUrb02hPrA/TSxje8IJwmI/AAAAAAAAAQo/Q5I2LFujvZM/s1600/100M-SHA256.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="62" src="http://1.bp.blogspot.com/_qyUrb02hPrA/TSxje8IJwmI/AAAAAAAAAQo/Q5I2LFujvZM/s320/100M-SHA256.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;The above announcement originates from a web forum where users submit password hashes for cracking. Other users reply with recovered passwords. Recovering your own? well, why not. Recovering 100 million? A reasonable question would be:&amp;nbsp;&lt;b&gt;Where did you get those? &lt;/b&gt;It's about time to talk about ethics.&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;/div&gt;&lt;a name='more'&gt;&lt;/a&gt;I frequently visit forums and websites that discuss password cracking in many forms. Many people participates in such forums either out of personal interests, research or commercial purposes. I've become increasingly aware of users posting large amounts of password hashes, asking for help to crack them without any explanation about their origins, the purpose of posting &amp;amp; cracking them. &lt;b&gt;NOTHING. &lt;/b&gt;There is no information available about the user either, happily hiding behind the "anonymity" the Internet provides them with.&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;At the &lt;a href="http://securitynirvana.blogspot.com/2010/12/videos-and-presentations-now-online.html"&gt;#Passwords10 conference&lt;/a&gt;&amp;nbsp;I got challenged after my talk to do a debate on password cracking ethics by Howard Smith of Oracle:&lt;/div&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/_qyUrb02hPrA/TSxyiWjjDZI/AAAAAAAAAQs/oex42DxJ1XY/s1600/Howard_Smith_from_Oracle.JPG" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="320" src="http://4.bp.blogspot.com/_qyUrb02hPrA/TSxyiWjjDZI/AAAAAAAAAQs/oex42DxJ1XY/s320/Howard_Smith_from_Oracle.JPG" width="213" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;i&gt;(Howard Smith during his talk at #Passwords10)&lt;/i&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;div style="text-align: left;"&gt;I think my presentation, previous blog posts as well as my guest blog post for Elcomsoft entitled "&lt;a href="http://blog.crackpassword.com/2010/02/why-you-should-crack-your-passwords/"&gt;Why you should crack your passwords&lt;/a&gt;" clearly presents my point of view.&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;Howard's opinion, which was pretty opposite (&lt;i&gt;correct me if I'm wrong Howard&lt;/i&gt;), is that there is no point in doing password cracking for research purposes, since we pretty much know that passwords haven't improved much during the last 10-15 years or so. People are still using simple passwords, they are still personally related, they are still easy to crack. If we still need to do it, we shouldn't have to actually &lt;b&gt;display&lt;/b&gt;&amp;nbsp;the found passwords, as this may violate privacy and the entire point of keeping passwords secret. Compare them "automagically" to a predefined set of rules, list those accounts that doesn't comply, and enforce a new password. Howard also said that one should question the legality of cracking password hashes with unknown origins, found on anonymous blog posts and shady forums on the Internet.&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;b&gt;It's hard to disagree.&lt;/b&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;b&gt;&lt;/b&gt;However; we do know that the bad guys are doing this. In fact, it seems to me as if there is an increasing trend in releasing large hash-only lists onto various web forums, asking other participants - even site owners - to participate freely in cracking those password hashes.&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;I'm afraid those participating are effectively becoming &lt;b&gt;free password mules&lt;/b&gt;, aiding the bad guys in increasing the value of their stolen data. These data are of course obtained through illegal hacking activity against websites, compromising parts of, or entire user databases. By stealing user names and cracking their associated passwords, they suddenly have data with a monetary value attached to it in the black market.&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;b&gt;Now here's a dilemma&lt;/b&gt; (&lt;i&gt;back to Howard&lt;/i&gt;): As ... I don't know... &lt;i&gt;password security professionals? &lt;/i&gt;can we aid in saving both users and service providers by monitoring such forums, by downloading such lists and try to identify their origins before the bad buys start selling the valuable data - informing the service provider about what we've found (under closed/responsible disclosure?) Or is that a job for the police or other government agencies to do?&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;We've seen cases before where service providers have no clue about being compromised long after their data has been put out on the Internet for sale by criminals. It will happen again. And again. And again.&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;The Gawker compromise also showed what could be a possible first; Chris Wysopal (CTO at Veracode, Twitter: &lt;a href="http://twitter.com/WeldPond/"&gt;@WeldPond&lt;/a&gt;) pointed out in a tweet that other service providers (Linkedin and others) used the list of compromised accounts (e-mail addresses) from Gawker to disable any of their own users with the same e-mail addresses. This &lt;i&gt;just in case&lt;/i&gt;&amp;nbsp;the users had broken one of the many laws of passwords: &lt;b&gt;Never use the same password across multiple services. &lt;/b&gt;What Linkedin and others did, he&amp;nbsp;saw as a possible new best practice. I fully agree to that!&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;So here we are, with a discussion that has been going on "forever", and it doesn't really have an ending either: &lt;b&gt;ethics.&lt;/b&gt;&amp;nbsp;At the same time &lt;b&gt;password mules&lt;/b&gt;&amp;nbsp;are unknowingly (or wittingly?) helping criminals increase the value of their stolen data, creating even more damage to providers as well as end-users. &lt;b&gt;What next?&lt;/b&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;--&lt;/div&gt;&lt;div style="text-align: left;"&gt;I'll end this blog post by quoting "Barsmonster", or &lt;a href="http://3.14.by/"&gt;Michail Svarychevski&lt;/a&gt; as he's named in real life, when he were asked why he quit developing his GPU based tool for high-performance password cracking &lt;a href="http://3.14.by/forum/viewtopic.php?f=8&amp;amp;t=1333#p8974"&gt;at his own forum&lt;/a&gt;:&lt;/div&gt;&lt;div style="text-align: left;"&gt;"&lt;span class="Apple-style-span" style="color: #333333; font-family: 'Lucida Grande', 'Trebuchet MS', Verdana, Helvetica, Arial, sans-serif; font-size: 13px; line-height: 18px;"&gt;&lt;i&gt;The complexity &amp;amp; danger - is due to risks to help someone to violate the laws, especially if you do this for money - you may be liable.&lt;/i&gt;"&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: 'Lucida Grande', 'Trebuchet MS', Verdana, Helvetica, Arial, sans-serif; font-size: 13px; line-height: 18px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: 'Lucida Grande', 'Trebuchet MS', Verdana, Helvetica, Arial, sans-serif; font-size: 13px; line-height: 18px;"&gt;--&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: 'Lucida Grande', 'Trebuchet MS', Verdana, Helvetica, Arial, sans-serif; font-size: 13px; line-height: 18px;"&gt;&lt;i&gt;My definition of&amp;nbsp;&lt;b&gt;Password mule:&lt;/b&gt;&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: 'Lucida Grande', 'Trebuchet MS', Verdana, Helvetica, Arial, sans-serif; font-size: 13px; line-height: 18px;"&gt;&lt;i&gt;&lt;b&gt;&lt;/b&gt;A person that willingly or unknowingly aids in cracking passwords obtained through illegal or questionable actions, and where the purpose is to increase the criminal monetary value of the data obtained.&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: 'Lucida Grande', 'Trebuchet MS', Verdana, Helvetica, Arial, sans-serif; font-size: 13px; line-height: 18px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8400370148915075091-8624280386487231437?l=securitynirvana.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securitynirvana.blogspot.com/feeds/8624280386487231437/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://securitynirvana.blogspot.com/2011/01/now-recruiting-password-mules.html#comment-form' title='7 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/8624280386487231437'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/8624280386487231437'/><link rel='alternate' type='text/html' href='http://securitynirvana.blogspot.com/2011/01/now-recruiting-password-mules.html' title='Now Recruiting: Password Mules!'/><author><name>Per Thorsheim</name><uri>https://profiles.google.com/113848325212589987956</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-skpoP167x04/AAAAAAAAAAI/AAAAAAAAAVU/RWc12nir74w/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_qyUrb02hPrA/TSxje8IJwmI/AAAAAAAAAQo/Q5I2LFujvZM/s72-c/100M-SHA256.png' height='72' width='72'/><thr:total>7</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8400370148915075091.post-5175694620293683638</id><published>2011-01-09T11:06:00.022+01:00</published><updated>2011-01-10T21:06:34.338+01:00</updated><title type='text'>No good security @StepStone Solutions!</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;b&gt;ERRATA:&lt;/b&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/_qyUrb02hPrA/TSmH8DzHQyI/AAAAAAAAAQg/jnaoLFgEy2w/s1600/StepStone-logo.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_qyUrb02hPrA/TSmH8DzHQyI/AAAAAAAAAQg/jnaoLFgEy2w/s1600/StepStone-logo.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;b&gt;I've received a reply to this blog post by private e-mail &lt;/b&gt;&lt;i&gt;(Thx Pål!)&lt;/i&gt;&lt;b&gt;, and I will update it to reflect the difference between the two separate companies StepStone and StepStone Solutions. &lt;/b&gt;Erroneous text/links has been changed to &lt;s style="font-style: italic;"&gt;strikethrough italics&lt;/s&gt;, while new text &lt;span class="Apple-style-span" style="color: blue;"&gt;is written in blue.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;I got an e-mail just before the new year from &lt;b&gt;noreply@easycruit.com&lt;/b&gt;, a service from &lt;a href="http://www.easycruit.com/index.html?page=about" style="font-style: italic; text-decoration: line-through;"&gt;StepStone&lt;/a&gt;&amp;nbsp;&lt;span class="Apple-style-span" style="background-color: white;"&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;&lt;a href="http://www.stepstonesolutions.com/solutions/talent-acquisition.html/"&gt;StepStone Solutions&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;.&amp;nbsp;It reminded me that I hadn't changed or updated my CV in their database for 6 months. They recommended that I updated it, otherwise they would delete it in two weeks. The e-mail also gave me my current username and password - &lt;b&gt;in cleartext:&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_qyUrb02hPrA/TRuIW0DZ0bI/AAAAAAAAAP8/NAmq05i47Do/s1600/easycruit_mail.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="155" src="http://1.bp.blogspot.com/_qyUrb02hPrA/TRuIW0DZ0bI/AAAAAAAAAP8/NAmq05i47Do/s400/easycruit_mail.png" width="400" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;i&gt;(Forgive me for my censorship here :-) Click for full size. Text in Norwegian.)&lt;/i&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;a name='more'&gt;&lt;/a&gt;Now, for those of you who have been following this blog for some time, you might have seen some references to RFC3207, an RFC specifying the use of STARTTLS for automated, opportunistic and user-transparent encryption of SMTP traffic between mail servers. With the incredible help and efforts from my friend and colleague Jan Fredrik (&lt;a href="http://twitter.com/KluZz/)"&gt;KluZz&lt;/a&gt;), we (our employer) even r&lt;a href="http://www.edb.com/no/Konsern/Aktuelt/Aktuelt/Taushetsbelagt-informasjon-sendes-ukryptert-via-e-post-i-Norge/"&gt;eleased a survey in April 2010&lt;/a&gt; that made some headlines in Norway.&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Not that this one matters much, but inspection of the mailheader showed what is still the standard for most Internet mail today, namely clear-text transmission:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/_qyUrb02hPrA/TSjpEWsKgdI/AAAAAAAAAQc/QPa2k5EmyhI/s1600/easycruit_mailheader.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="40" src="http://4.bp.blogspot.com/_qyUrb02hPrA/TSjpEWsKgdI/AAAAAAAAAQc/QPa2k5EmyhI/s400/easycruit_mailheader.png" width="400" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;i&gt;(E-mail received from sending-only SMTP server with ESMTP, no SSL/TLS encryption)&lt;/i&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;div&gt;To save you the lookup, the 62.209.53.0/25 is used by Stepstone, as a customer of Telecity.com.&lt;/div&gt;&lt;div&gt;So here I am, without forgetting my password or any other action that could somehow justify sending my complete login credentials and all necessary information required to compromise my account at Easycruit / StepStone through unencrypted e-mail.&lt;/div&gt;&lt;div&gt;&lt;b&gt;Now, lets do the game of risk analysis first.&lt;/b&gt;&lt;br /&gt;Of course, as a security professional, I would hope and believe that StepStone are doing their part in this area. My CV isn't that valuable, is it? At least not worth protecting like a secret, right? You can find parts of it publicly available at &lt;a href="http://linkedin.com/in/thorsheim"&gt;Linkedin.com/in/thorsheim&lt;/a&gt; anyway? Somebody messing it up, would that be a much of a problem? Well, as many other online things, NO, not really, just ... annoying. At least for me. On the other side: Many Human Relations departments love to say that their most important asset are their employees, so do they really want all CVs from applicants and employees to be easily accessed, copied and stolen?&lt;br /&gt;&lt;br /&gt;&lt;b&gt;How do my employer - any employer - look, when recruiting security professionals (and others), asking them to register their application through a system that is fundamentally flawed on the security side? &lt;/b&gt;It may be hard to set a monetary value to your public appearance, but this doesn't really help on the positive side, that's for sure.&lt;br /&gt;&lt;br /&gt;--&lt;br /&gt;&lt;br /&gt;Easycruit is an online recruitment tool, a product, that corporations can purchase and custom fit for their own purposes, at least as far as I can interpret their &lt;a href="http://www.stepstonesolutions.com/solutions/talent-acquisition.html/"&gt;info page&lt;/a&gt;. I got this e-mail because my employer uses easycruit, and I've registered my CV there earlier.&lt;br /&gt;&lt;br /&gt;&lt;s&gt;&lt;i&gt;Looking at &lt;a href="http://www.stepstone.no/Om-StepStone/sikkerhet-pa-stepstone.cfm"&gt;bullet 11, data security&lt;/a&gt;, in their privacy policy (&lt;a href="http://translate.google.com/translate?js=n&amp;amp;prev=_t&amp;amp;hl=no&amp;amp;ie=UTF-8&amp;amp;layout=2&amp;amp;eotf=1&amp;amp;sl=no&amp;amp;tl=en&amp;amp;u=http://www.stepstone.no/Om-StepStone/sikkerhet-pa-stepstone.cfm"&gt;translation from NO to EN&lt;/a&gt;), they are using SSL, firewalls, monitoring and manual security procedures to safeguard my privacy.&lt;/i&gt;&lt;/s&gt;&amp;nbsp;&lt;span class="Apple-style-span" style="color: blue;"&gt;Looking at their &lt;a href="http://www.stepstonesolutions.com/privacy-policy"&gt;privacy policy&lt;/a&gt;&amp;nbsp;(under "Data Security"), they seem to have copied the policy from StepStone, removed parts of it&amp;nbsp;and we're left with even less details that they can be held responsible for. Unlike Stepstone, they do not list any particular person or mail address as responsible for any questions on their privacy policy.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;&lt;/span&gt;For registration and password reset issues, I can understand the need for sending a one-time-password (OTP) in unencrypted e-mail. Not the best way, but sometimes the easiest, cheapest and only solution available.&amp;nbsp;But I have changed my password, and without any reasonable sense they seemingly store it unencrypted in their systems, or at least decrypt it before sending it to me!&lt;br /&gt;&lt;br /&gt;&lt;b&gt;So dear StepStone &lt;/b&gt;&lt;span class="Apple-style-span" style="background-color: white; color: blue; font-weight: bold;"&gt;Solution&lt;/span&gt;&lt;span class="Apple-style-span" style="background-color: white; font-weight: bold;"&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;s&lt;/span&gt;&lt;/span&gt;&lt;b&gt;: With this blog post I ask you to remove my profile and any associated data ASAP, including removing me from any mailing lists or other services where you have registered me. I will of course also notify you about this in accordance with your privacy policy&lt;span class="Apple-style-span" style="color: blue;"&gt;, by calling you by phone since you don't have a specific e-mail address listed.&lt;/span&gt;&lt;/b&gt;&lt;s&gt;&lt;i&gt;, &lt;/i&gt;&lt;/s&gt;&lt;s&gt;&lt;i&gt;and send the same request using unencrypted e-mail to to the contact listed by you&lt;/i&gt;&lt;/s&gt;&lt;b&gt;.&lt;/b&gt;&lt;br /&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;br /&gt;I will also notify my employer about these issues, and highly recommend them to demand a meeting with you, requesting actions and time frames for these actions to be implemented. If this cannot be done within reasonable time and free of charge to my employer, I will recommend ending any agreements they may have with you, and seek other providers of similar services - AND a better security level.&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;--&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;&lt;b&gt;Addendum Monday 10, january 2011:&lt;/b&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;In the reply I got by e-mail, I also received a link to this page at StepStone:&lt;a href="http://www.stepstone.no/content/dk/upload_dk/campaigns/B2C-security_account_1010_no_web.html"&gt; Fordi din sikkerhet teller&lt;/a&gt;&amp;nbsp;("Because your security matters").&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Basically they are saying that from now on (unknown date, probably somewhere in 2010), you won't be able to log in if your password was less than 3 characters in length. From this point on your password must now be at least 4 characters in length, passwords will be case-sensitive, and their service now has a password strength meter for you when you change your password. (Read my earlier blog post:&amp;nbsp;&lt;a href="http://securitynirvana.blogspot.com/2010/02/never-trust-password-meters.html"&gt;Never trust password meters!&lt;/a&gt;).&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;Of course I couldn't resist (today; Jan 10, 2011), so I chose to reset my password from the link provided on this web page. After typing in my correct e-mail address, I got an e-mail with a HTTPS link valid for 30 days to change my password.&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;They only require 4 characters (1234 is accepted), but it's labeled "insecure". They also have low-medium-strong-very strong, and my PCI-DSS compliant super-duper password &lt;b&gt;&lt;a href="http://securitynirvana.blogspot.com/2010/02/handmade-graphics.html"&gt;Password1&lt;/a&gt;&lt;/b&gt;&amp;nbsp;gets a STRONG rating:&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/_qyUrb02hPrA/TStlqo481QI/AAAAAAAAAQk/dlHTP_5mAXw/s1600/Stepstone_Password1.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="95" src="http://2.bp.blogspot.com/_qyUrb02hPrA/TStlqo481QI/AAAAAAAAAQk/dlHTP_5mAXw/s320/Stepstone_Password1.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;No wonder I say you shouldn't trust password meters.&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: blue;"&gt;As for the clarifications received by e-mail I'm thankful for that. Considering the additional information provided as well, I'd say my overall impression of StepStone's password security didn't change much for the better. As for StepStone Solutions.... Well, I'm looking forward to any reply you may provide.&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8400370148915075091-5175694620293683638?l=securitynirvana.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securitynirvana.blogspot.com/feeds/5175694620293683638/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://securitynirvana.blogspot.com/2011/01/no-good-security-stepstone.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/5175694620293683638'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/5175694620293683638'/><link rel='alternate' type='text/html' href='http://securitynirvana.blogspot.com/2011/01/no-good-security-stepstone.html' title='No good security @StepStone Solutions!'/><author><name>Per Thorsheim</name><uri>https://profiles.google.com/113848325212589987956</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-skpoP167x04/AAAAAAAAAAI/AAAAAAAAAVU/RWc12nir74w/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_qyUrb02hPrA/TSmH8DzHQyI/AAAAAAAAAQg/jnaoLFgEy2w/s72-c/StepStone-logo.png' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8400370148915075091.post-1271932232462843686</id><published>2011-01-06T17:15:00.000+01:00</published><updated>2011-01-06T17:15:46.528+01:00</updated><title type='text'>Facebook places - ny runde med sikkerhet</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/_qyUrb02hPrA/TSW9wZeNOXI/AAAAAAAAAQA/HRJ2idHfi8M/s1600/Header_image.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="175" src="http://2.bp.blogspot.com/_qyUrb02hPrA/TSW9wZeNOXI/AAAAAAAAAQA/HRJ2idHfi8M/s400/Header_image.png" width="400" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;I går, det vil si onsdag 5. januar, ble endelig Facebook "Places" tjenesten også tilgjengelig for bruk i Norge. Personverninnstillingene relatert til denne funksjonen har vært tilgjengelig lenge, men dagens lille test (skjermbildet over) viser at ihvertfall mange av mine kontakter enda ikke har endret på dette. Det må vi få gjort noe med.&lt;br /&gt;&lt;br /&gt;&lt;a name='more'&gt;&lt;/a&gt;Jeg har tidligere skrevet om Facebook sikkerhet (&lt;a href="http://securitynirvana.blogspot.com/2010/09/playing-passwords-with-facebook.html"&gt;passord&lt;/a&gt;) og personvern (&lt;a href="http://securitynirvana.blogspot.com/2010/05/facebook-personvern.html"&gt;del 1&lt;/a&gt; og &lt;a href="http://securitynirvana.blogspot.com/2010/06/facebook-personvern-del-2.html"&gt;del 2&lt;/a&gt;), og ikke minst om såkalte "geolokasjonstjenester" i bloggposten "&lt;a href="http://securitynirvana.blogspot.com/2010/09/hvor-er-du.html"&gt;Hvor er du?&lt;/a&gt;". Med introduksjonen av "Places" vil jeg anbefale at du først leser bloggposten "Hvor er du?", og deretter anbefaler jeg at du gjør følgende i Facebook oppsettet ditt &lt;i&gt;(klikk på bildene for full størrelse)&lt;/i&gt;:&lt;br /&gt;&lt;br /&gt;1. Velg "&lt;b&gt;Personverninnstillinger&lt;/b&gt;" under menyvalget "Brukerkonto" som du har øverst til høyre i Facebook bildet. Du vil da få et bilde som ser slik ut (nedenstående er mitt eget oppsett):&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/_qyUrb02hPrA/TSXBX9rqVkI/AAAAAAAAAQI/Ydo9yNv4Zfc/s1600/Mine_personverninstillinger_1.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="213" src="http://2.bp.blogspot.com/_qyUrb02hPrA/TSXBX9rqVkI/AAAAAAAAAQI/Ydo9yNv4Zfc/s320/Mine_personverninstillinger_1.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;2. Her velger du "&lt;b&gt;Tilpass innstillinger&lt;/b&gt;" nederst, og får da opp en rekke ulike valg, som vist under (nok en gang; mine innstillinger, som jeg også anbefaler andre å benytte):&lt;br /&gt;&lt;br /&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/_qyUrb02hPrA/TSXBYN18elI/AAAAAAAAAQM/kN24-wv8ofo/s1600/Mine_personverninstillinger_2.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="314" src="http://2.bp.blogspot.com/_qyUrb02hPrA/TSXBYN18elI/AAAAAAAAAQM/kN24-wv8ofo/s320/Mine_personverninstillinger_2.png" width="320" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&amp;nbsp;Merk at jeg bevisst ikke har aktivert funksjonen "Ta meg med i Folk som er her nå når jeg har sjekket inn". Denne funksjonen gjør nemlig at ikke bare vennene dine, men også andre og helt eksterne personer kan se at du har sjekket inn et sted når de er i nærheten. (Jeg har ikke sett noen definisjon på "i nærheten" enda...)&lt;br /&gt;&lt;br /&gt;Fortsetter du nedover på listen, så får du opp disse valgene også:&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/_qyUrb02hPrA/TSXBYogYx0I/AAAAAAAAAQQ/fgCeWfehqoA/s1600/Mine_personverninstillinger_3.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="320" src="http://3.bp.blogspot.com/_qyUrb02hPrA/TSXBYogYx0I/AAAAAAAAAQQ/fgCeWfehqoA/s320/Mine_personverninstillinger_3.png" width="289" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;Som du ser av bildet over, så har jeg satt opp Facebook profilen min slik at det stort sett bare er mine venner som kan se og evt gjøre endringer ift min profil. Funksjonen "&lt;b&gt;Venner kan sjekke meg inn på steder&lt;/b&gt;" er den interessante i forhold til "Places" funksjonen. Når du klikker på "Endre innstillinger" (som markert over), så før du opp en dialogboks slik den du ser under:&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_qyUrb02hPrA/TSXBZJFYrBI/AAAAAAAAAQU/1Q78R2xsH00/s1600/Mine_personverninstillinger_4.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="166" src="http://1.bp.blogspot.com/_qyUrb02hPrA/TSXBZJFYrBI/AAAAAAAAAQU/1Q78R2xsH00/s320/Mine_personverninstillinger_4.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;Her er det da jeg anbefaler at dette valget settes til "&lt;b&gt;Deaktivert&lt;/b&gt;", og deretter trykker du Ok. Da var de nødvendige endringene gjort, og du har fortsatt noenlunde kontroll over din Facebook profil. :-)&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;--&lt;br /&gt;I en senere bloggpost skal jeg skrive litt om hvordan du kan sikre deg bedre dersom noen skulle stjele tilgangen til din Facebook konto, slik at du enklere og raskere kan få tilbake kontrollen. Her vil jeg også vise litt om hvordan du kan sjekke hvorvidt andre har vært innlogget på din Facebook profil.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8400370148915075091-1271932232462843686?l=securitynirvana.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securitynirvana.blogspot.com/feeds/1271932232462843686/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://securitynirvana.blogspot.com/2011/01/facebook-places-ny-runde-med-sikkerhet.html#comment-form' title='7 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/1271932232462843686'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/1271932232462843686'/><link rel='alternate' type='text/html' href='http://securitynirvana.blogspot.com/2011/01/facebook-places-ny-runde-med-sikkerhet.html' title='Facebook places - ny runde med sikkerhet'/><author><name>Per Thorsheim</name><uri>https://profiles.google.com/113848325212589987956</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-skpoP167x04/AAAAAAAAAAI/AAAAAAAAAVU/RWc12nir74w/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_qyUrb02hPrA/TSW9wZeNOXI/AAAAAAAAAQA/HRJ2idHfi8M/s72-c/Header_image.png' height='72' width='72'/><thr:total>7</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8400370148915075091.post-2289277461080040082</id><published>2010-12-16T22:24:00.000+01:00</published><updated>2010-12-16T22:24:48.709+01:00</updated><title type='text'>Hvem stoler du på?</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/_qyUrb02hPrA/TPismq-yUqI/AAAAAAAAAPU/mQm10u03_cU/s1600/ClientCardSample.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_qyUrb02hPrA/TPismq-yUqI/AAAAAAAAAPU/mQm10u03_cU/s1600/ClientCardSample.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;b&gt;Hvem stoler du på egentlig?&lt;/b&gt;&lt;br /&gt;Din bedre halvdel? Dine barn? Naboen? Politiet? Banken? Kommunen? NSM?&lt;br /&gt;&lt;br /&gt;For kort tid siden ble jeg gjort oppmerksom på en liten detalj rundt bankenes avtalevilkår for betalingskort, derav denne bloggposten. (&lt;i&gt;Tusen takk til "R"!&lt;/i&gt;)&lt;br /&gt;&lt;br /&gt;&lt;a name='more'&gt;&lt;/a&gt;Jeg er kunde i 3 ulike banker i Norge. Av flere gode årsaker vil jeg ikke oppgi hvilke, og jeg gjør her en antagelse om at bruksvilkårene for betalingskort er de samme i alle banker, ihvertfall på papiret.&lt;br /&gt;&lt;br /&gt;Denne bloggposten gjelder selvfølgelig passord (...), her i form av PIN koder. Disse skal du nemlig ikke gi til noen andre i følge avtalevilkårene. PIN koden er din personlig, punktum. Nå er det sånn at jeg stoler på min kjæreste (offisielt titulert som ektefelle eller kone), og hun har fått låne mine kort til f.eks. shopping tidligere. Så der; jeg har oppgitt at jeg bryter avtalevilkårene. Så får vi se om det skjer noe i etterkant av dette.&lt;br /&gt;&lt;br /&gt;Jeg ble litt nysgjerrig, og laget en enkel spørreundersøkelse på nett, og spurte familie/venner/kontakter via Facebook om de kunne ta seg 2 minutter til å besvare den. Med 37 personer som har gjennomført pr 16 desember så er det ikke mye grunnlag, men her er resultatene &lt;i&gt;(klikk for full størrelse)&lt;/i&gt;:&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/_qyUrb02hPrA/TQp_afhcz7I/AAAAAAAAAPc/c9CykhoflNA/s1600/spm1.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="278" src="http://2.bp.blogspot.com/_qyUrb02hPrA/TQp_afhcz7I/AAAAAAAAAPc/c9CykhoflNA/s320/spm1.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/_qyUrb02hPrA/TQqBZOCxiQI/AAAAAAAAAPg/RoyzWrV-JDU/s1600/spm2.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="278" src="http://2.bp.blogspot.com/_qyUrb02hPrA/TQqBZOCxiQI/AAAAAAAAAPg/RoyzWrV-JDU/s320/spm2.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_qyUrb02hPrA/TQqBZZInqBI/AAAAAAAAAPk/n_PrdEiiJkQ/s1600/spm3.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="291" src="http://1.bp.blogspot.com/_qyUrb02hPrA/TQqBZZInqBI/AAAAAAAAAPk/n_PrdEiiJkQ/s320/spm3.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/_qyUrb02hPrA/TQqBZvjiuqI/AAAAAAAAAPo/ui7zEsB2I9I/s1600/spm4.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="280" src="http://3.bp.blogspot.com/_qyUrb02hPrA/TQqBZvjiuqI/AAAAAAAAAPo/ui7zEsB2I9I/s320/spm4.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/_qyUrb02hPrA/TQqBaHdcXSI/AAAAAAAAAPs/yP4Ha_65enc/s1600/spm5.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="291" src="http://4.bp.blogspot.com/_qyUrb02hPrA/TQqBaHdcXSI/AAAAAAAAAPs/yP4Ha_65enc/s320/spm5.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Selv med små forskjeller så er det jo fascinerende at man stoler noe mindre på egne/partners barn enn personer utenfor nærmeste familie (spørsmål 3-4 vs spørsmål 5).&lt;br /&gt;&lt;br /&gt;Uansett synes jeg at det er et klart og tydelig gap mellom bankenes avtalevilkår og hvordan "folk flest" gjør sin personlige risikovurdering i forhold til personlige PIN koder. Mitt spørsmål blir egentlig om dette bruddet på avtalevilkårene i seg selv er nok til reaksjoner fra banken, selv om ingen hendelse har inntruffet så langt?&lt;br /&gt;&lt;br /&gt;Jeg hører svært gjerne din mening.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8400370148915075091-2289277461080040082?l=securitynirvana.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securitynirvana.blogspot.com/feeds/2289277461080040082/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://securitynirvana.blogspot.com/2010/12/hvem-stoler-du-pa.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/2289277461080040082'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/2289277461080040082'/><link rel='alternate' type='text/html' href='http://securitynirvana.blogspot.com/2010/12/hvem-stoler-du-pa.html' title='Hvem stoler du på?'/><author><name>Per Thorsheim</name><uri>https://profiles.google.com/113848325212589987956</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-skpoP167x04/AAAAAAAAAAI/AAAAAAAAAVU/RWc12nir74w/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_qyUrb02hPrA/TPismq-yUqI/AAAAAAAAAPU/mQm10u03_cU/s72-c/ClientCardSample.png' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8400370148915075091.post-2094656223813279975</id><published>2010-12-14T13:21:00.001+01:00</published><updated>2010-12-14T13:30:57.419+01:00</updated><title type='text'>Videos and presentations now online!</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/_qyUrb02hPrA/TLwYB00-tnI/AAAAAAAAAOk/y52uGX7fVFU/s1600/CFP_logo.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/_qyUrb02hPrA/TLwYB00-tnI/AAAAAAAAAOk/y52uGX7fVFU/s1600/CFP_logo.png" /&gt;&lt;/a&gt;&lt;/div&gt;Presentations as well as videos from the conference are now online. You can download the presentations as well as the video files (iPad friendly h.264 HD format) from &lt;a href="http://ftp.ii.uib.no/pub/passwords10/"&gt;http://ftp.ii.uib.no/pub/passwords10/&lt;/a&gt; , or download them through bittorrent from &lt;a href="http://home.online.no/%7Eputilutt/torrents/"&gt;http://home.online.no/~putilutt/torrents/&lt;/a&gt;. Just remember to seed them as well after downloading. :-)&lt;br /&gt;&lt;br /&gt;I would really like to thank the University of Bergen, especially &lt;a href="http://twitter.com/haakonnilsen/"&gt;@haakonnilsen&lt;/a&gt;, for providing FTP server space to these files for us. Also a big thank you to all the presenters for allowing us to record and publish the videos online after the conference. Thank you to all participants for being there, great discussions and exchanging of ideas!&lt;br /&gt;&lt;br /&gt;Last but not least; a personal big THANK YOU to &lt;a href="http://www.ii.uib.no/%7Etorh/"&gt;Professor Tor Helleseth&lt;/a&gt; for providing me with the opportunity as well as budget, advice and everything else to help Passwords^10 come true. I really hope we'll do it again. :-D&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8400370148915075091-2094656223813279975?l=securitynirvana.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securitynirvana.blogspot.com/feeds/2094656223813279975/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://securitynirvana.blogspot.com/2010/12/videos-and-presentations-now-online.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/2094656223813279975'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/2094656223813279975'/><link rel='alternate' type='text/html' href='http://securitynirvana.blogspot.com/2010/12/videos-and-presentations-now-online.html' title='Videos and presentations now online!'/><author><name>Per Thorsheim</name><uri>https://profiles.google.com/113848325212589987956</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-skpoP167x04/AAAAAAAAAAI/AAAAAAAAAVU/RWc12nir74w/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_qyUrb02hPrA/TLwYB00-tnI/AAAAAAAAAOk/y52uGX7fVFU/s72-c/CFP_logo.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8400370148915075091.post-4735549088633342376</id><published>2010-12-13T23:24:00.000+01:00</published><updated>2010-12-13T23:24:41.257+01:00</updated><title type='text'>Passwords^10 : Passware scared us all</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/_qyUrb02hPrA/TQaNWEt0N0I/AAAAAAAAAPY/yy52F7pWDQg/s1600/Passware_logo.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/_qyUrb02hPrA/TQaNWEt0N0I/AAAAAAAAAPY/yy52F7pWDQg/s1600/Passware_logo.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Originally my plan was to do several blog posts based on what I heard, saw and learned at Passwords^10. That still is my plan of course, but the president of &lt;a href="http://www.passware.com/"&gt;Passware&lt;/a&gt;, Dmitry Sumin, scared me. *A LOT*. So first things first; this blog post is highly necessary - and maybe time critical to some of us as well.&lt;br /&gt;&lt;br /&gt;&lt;a name='more'&gt;&lt;/a&gt;A short time before the conference Nataly Koukoushkina, the marketing manager of Passware told me that they would demo their newest version of Passware Kit Forensic (version 10.3) at Passwords^10. Dmitry made his presentation and demo on thursday 9th for the very first time, while they posted their &lt;a href="http://www.lostpassword.com/pdf/pr-101209.pdf"&gt;press release (direct link to PDF)&lt;/a&gt; at their website.&lt;br /&gt;&lt;br /&gt;Lets say you are using Microsoft Bitlocker, or perhaps Truecrypt, to do full hard disk encryption. If you EVER allow your computer to enter hibernation mode, Passware Kit Forensic can be used to extract the decryption key necessary to access your hard drive from the hiberfil.sys file. That file is basically your physical memory saved to disk when you choose to hibernate your computer. And no, the TPM chip present in some laptops (at least in corporate environments) won't help you. The extraction can be done in minutes. Even more frightening: you can't really make that hiberfil.sys go away using standard operating tools, as it is off-limits for you. To be really secure it can't just be deleted either, it has to be wiped.&lt;br /&gt;&lt;br /&gt;&lt;u&gt;&lt;b&gt;Recommendation:&lt;/b&gt;&lt;/u&gt;&lt;br /&gt;&lt;b&gt;NEVER EVER EVER EVER allow hibernation for any computer&lt;/b&gt;, at least those that are more exposed to theft or other types of unauthorized physical access! Use sleep mode (keeping data in memory on low power consumption), or do a complete shutdown. WiredPig (&lt;a href="http://twitter.com/WiredPig/"&gt;Twitter/WiredPig&lt;/a&gt;) has already a writeup on this stuff, &lt;a href="http://pgp.wiredpig.us/2010/bitlocker-truecrypt-vulnerability/"&gt;highly recommended reading&lt;/a&gt;. with more details to go.&lt;br /&gt;&lt;br /&gt;Does this change my risk evaluation? &lt;b&gt;Yes, it most certainly does.&lt;/b&gt;&lt;br /&gt;Probability of computer being stolen or accessed without authorization? &lt;b&gt;Probably no change.&lt;/b&gt;&lt;br /&gt;&lt;b&gt;Consequences if stolen?&lt;/b&gt; &lt;b&gt;Much higher than before.&lt;/b&gt; Flip your coin: a simple criminal wanting a new laptop, or a (targeted) attack to get access to everything you and your employer have on that computer. And more.&lt;br /&gt;&lt;br /&gt;Dmitry also showed an somewhat "old" trick; &lt;b&gt;using Firewire to do live memory dumps&lt;/b&gt;, thus gaining access to your decryption keys (and anything else) you might have in your computers memory. A trick that most certainly gave a few "WOWs" in the audience, with people afterwards saying "I need to use superglue on my Firewire ports, as well as PCMCIA ports in order to prevent insertion of Firewire cards".&lt;br /&gt;&lt;br /&gt;You can see all this, and more, by downloading the video recordings we've made available for free. They are currently hosted at the FTP server of the University in Bergen: &lt;a href="http://ftp.ii.uib.no/pub/passwords10/"&gt;http://ftp.ii.uib.no/pub/passwords10/&lt;/a&gt; (Big thank you to &lt;a href="http://twitter.com/haakonnilsen/"&gt;@haakonnilsen&lt;/a&gt; at UiB for that!). Torrents can also be found at http://home.online.no/~putilutt/torrents/ in case you would like to help us distribute the files. :-)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8400370148915075091-4735549088633342376?l=securitynirvana.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securitynirvana.blogspot.com/feeds/4735549088633342376/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://securitynirvana.blogspot.com/2010/12/passwords10-passware-scared-us-all.html#comment-form' title='8 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/4735549088633342376'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/4735549088633342376'/><link rel='alternate' type='text/html' href='http://securitynirvana.blogspot.com/2010/12/passwords10-passware-scared-us-all.html' title='Passwords^10 : Passware scared us all'/><author><name>Per Thorsheim</name><uri>https://profiles.google.com/113848325212589987956</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-skpoP167x04/AAAAAAAAAAI/AAAAAAAAAVU/RWc12nir74w/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_qyUrb02hPrA/TQaNWEt0N0I/AAAAAAAAAPY/yy52F7pWDQg/s72-c/Passware_logo.jpg' height='72' width='72'/><thr:total>8</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8400370148915075091.post-5223100756909264205</id><published>2010-12-02T11:40:00.002+01:00</published><updated>2010-12-02T11:54:30.308+01:00</updated><title type='text'>Passwords^10 : 2 dager om passord &amp; PIN koder</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/_qyUrb02hPrA/TLwYB00-tnI/AAAAAAAAAOk/y52uGX7fVFU/s1600/CFP_logo.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/_qyUrb02hPrA/TLwYB00-tnI/AAAAAAAAAOk/y52uGX7fVFU/s1600/CFP_logo.png" /&gt;&lt;/a&gt;&lt;/div&gt;Den 8 og 9 desember arrangeres det en 2-dagers konferanse om passord og PIN koder - og bare det! Arrangør er &lt;a href="http://www.linkedin.com/in/thorsheim"&gt;Per Thorsheim&lt;/a&gt; i samarbeid med Professor &lt;a href="http://www.uib.no/fg/selmer/kontakt/group-members"&gt;Tor Helleseth&lt;/a&gt; ved &lt;a href="http://www.uib.no/fg/selmer"&gt;Selmersenteret&lt;/a&gt;, Universitetet i Bergen, og med &lt;a href="http://www.nisnet.no/"&gt;Nisnet&lt;/a&gt; som sponsor. Per Thorsheim kan kontaktes på tlf 90 999 259 eller mail:&lt;br /&gt;per&lt;i&gt;krøllalfa&lt;/i&gt;thorsheim.net.&lt;br /&gt;&lt;br /&gt;Konferansen er gratis, og åpen for alle, også media :-)&lt;a href="http://home.online.no/%7Eputilutt/Passwords10_final_program.pdf"&gt; Komplett program finnes her&lt;/a&gt; &lt;i&gt;(PDF, 104KB, ingen javascript eller flash). &lt;/i&gt;Flere av presentasjonene vil inneholde mye matematikk/krypto, så er den advarselen gitt.&lt;br /&gt;&lt;br /&gt;Formålet med konferansen er å presentere og diskutere noe som de aller fleste av oss må forholde seg til i hverdagen: passord &amp;amp; pin koder. Facebook, nettbank, dørene på jobben, mobiltelefonen eller den PIN koden som forsvant ut av hodet akkurat i det du kom frem til kassen etter 20 minutter i julepresang køen.&lt;br /&gt;&lt;br /&gt;&lt;a name='more'&gt;&lt;/a&gt;Vi har stadig flere passord, og kvaliteten på dem har ikke blitt nevneverdig bedre de siste 10-15 årene. Mange har det samme passordet i bruk på ulike tjenester, selv om dette er hverken anbefalt eller "lovlig" i henhold til en del virksomheters interne regler.&lt;br /&gt;&lt;br /&gt;Teknologi og kunnskap om hvordan man knekker passord for å oppnå uautorisert tilgang til informasjon som er beskyttet har hatt en rivende utvikling i mange år, men kravene til passord har stort sett vært uendret i mange år. Det er også store sprik mellom hva sikkerhetseksperter anbefaler som minimum og hva som faktisk implementeres av organisasjoner og virksomheter. Gjennomsnittet tillater dessverre bruk av passord som lar seg knekke på få sekunder i mange tilfeller, og virksomheter flest virker ikke å være oppmerksom på denne trusselen i det hele tatt. &lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;u&gt;Litt om foredragene:&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Howard Smith&lt;/b&gt; kommer fra Oracle i USA, hvor han leder deres interne team for sikkerhetstesting. Han vil snakke om menneskers valg av PIN koder. De har gjort en analyse av slike PIN koder, og ikke overraskende viser det at vi har en tendens til å velge PIN koder som er dårlige. Han stiller da spørsmål om det også bør innføres regelverk også for valg av PIN koder for å bedre sikkerheten.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.hig.no/ansatte/avdeling_for_informatikk_og_medieteknikk/kirsi_helkala"&gt;&lt;b&gt;Kirsi Helkala&lt;/b&gt;&lt;/a&gt; kommer fra Universitetet på Gjøvik, hvor hun er stipendiat innen informasjonssikkerhet. Hun har sett nærmere på opplæring av studenter i hvordan man lager og husker gode passord, og hvor effektiv denne opplæringen har vært over tid. Ett av funnene viser at de fleste faller tilbake til "dårlige" passord i løpet av relativt kort tid dersom ikke opplæringen repeteres eller videreføres.&lt;br /&gt;&lt;br /&gt;Firmaet &lt;b&gt;&lt;a href="http://www.elcomsoft.com/"&gt;Elcomsoft&lt;/a&gt;&lt;/b&gt; ble spesielt godt kjent da en av deres forskere ble arrestert i USA i 2001, da han presenterte deres funn av svakheter i programvare fra Adobe. Saken ble bredt omtalt (mange linker på &lt;a href="http://www.freesklyarov.org/"&gt;www.freesklyarov.org&lt;/a&gt;), og resulterte i full frifinnelse. På konferansen vil adm.dir. + en av deres forskere snakke om bruken av grafikkort til å knekke passord stadig raskere, samt vise programvare som benyttes av bl.a. politi og myndigheter for å få tilgang til krypterte iPhone/Blackberry telefoner.&lt;br /&gt;&lt;br /&gt;Vi kan også legge til at Elcomsoft 30 November &lt;a href="http://www.elcomsoft.com/news/428.html"&gt;annonserte at de hadde funnet en svakhet i et spesielt tilbehør fra Canon for digitale speilrefleks kameraer&lt;/a&gt;. Dette tilbehøret brukes for å GPS/tidsstemple digitale bilder for bruk i juridisk sammenheng, og svakheten viser at slike bilder kan manipuleres uten å bryte den digitale "vannmerkingen" som skal sikre juridisk holdbarhet. Dette kan potensielt få konsekvenser i alle saker hvor slike bilder har blitt benyttet som bevismateriale, da det nå er bevist at man ikke kan stole på ektheten av disse bildene.&lt;br /&gt;&lt;br /&gt;James Nobis er bedre kjent som en av utviklerne på &lt;a href="http://www.freerainbowtables.com/"&gt;www.freerainbowtables.com&lt;/a&gt;, et gratisprosjekt med stadig flere deltakere. Disse kjører hver en distribuert programvare som lager "rainbowtables", en form for data som bidrar til å knekke passord mye raskere enn tidligere. Pr desember 2010 deltar rundt 1200 maskiner i dette arbeidet, med en samlet datakraft tilsvarende en respektabel superdatamaskin. Hans presentasjon vil ta for seg prosjektets bakgrunn, status og fremtidsplaner.&lt;br /&gt;&lt;i&gt;(Et annet prosjekt som også lager slike rainbowtables heter A5/1, bedre kjent som krypteringen som benyttes i svært mange mobiltelefoner. Det prosjektet har dokumentert behovet for at alle GSM mobiltelefonnett bør oppgraderes umiddelbart for å tilby tilstrekkelig sikkerhet mot ulovlig avlytting.)&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;Firmaet &lt;a href="http://www.passware.com/"&gt;&lt;b&gt;Passware&lt;/b&gt;&lt;/a&gt;&lt;i&gt; &lt;/i&gt;stiller med en helt ny versjon av sin "Passware Forensic Kit" programvare, og vil her gi den aller første demonstrasjonen av hvordan de kan hente ut krypteringsnøkler (=passord) fra&amp;nbsp; en maskin som i utgangspunktet er i såkalt hvilemodus ("hibernation"), og som benytter kryptering av hele harddisken. Dette er programvare som benyttes av politi og andre myndigheter for å få tilgang til maskiner som er kryptert, og det foreligger mistanke om kriminelle formål. For å sette dette i perspektiv så ble det for kort tid siden publisert en undersøkelse som sa at over 50% av virksomheter i England ikke benyttet harddisk kryptering på sine maskiner for å sikre dataene i tilfelle tyveri. Det er ingen grunn til å tro at situasjonen er spesielt bedre i Norge. Denne programvaren viser tydelig hvordan slik programvare ikke bare må tas i bruk, men det må også gjøres riktig på første forsøk.&lt;br /&gt;&lt;br /&gt;For å avslutte med et litt større perspektiv på verden, så kommer &lt;a href="http://www.uis.no/news/article16032-50.html"&gt;Professor Sigbjørn Hervik&lt;/a&gt; fra Universitetet i Stavanger. Han er professor i matematikk, men har sin utdannelse innen teoretisk fysikk. Han avslutter konferansen med et populærvitenskapelig foredrag om hvor universet kommer fra, hvor det er, og hvor det er på vei. Stort større perspektiv er det vanskelig å avslutte med. :-)&lt;br /&gt;&lt;br /&gt;--&lt;br /&gt;&lt;br /&gt;&lt;u&gt;Om meg selv i denne sammenhengen:&lt;/u&gt;&lt;br /&gt;Selv har jeg gjennom jobb og privat i over 9 år "forsket" på passord. Jeg har tidligere sagt at "&lt;i&gt;jeg har brutt meg inn i det meste hos de fleste, og fått lovlig betalt for å gjøre det!&lt;/i&gt;". Jeg er blant de best sertifiserte innen IT- og informasjonssikkerhet i Skandinavia, og jobber til daglig innen dette området.&lt;br /&gt;&lt;br /&gt;Nå er jeg utrolig glad og stolt over å få til en 2-dagers konferanse om passord &amp;amp; pin koder. I seg selv er det temmelig unikt å lage en slik konferanse, og det blir bare mer unikt når noe slikt har sitt utspring i, og arrangeres i Bergen. Faktisk kjenner jeg ikke til at det har blitt arrangert noe tilsvarende noe annet sted - noen gang.&lt;br /&gt;&lt;br /&gt;Det jeg er aller mest glad for, er alle de foredragsholderne som kommer. Flere av dem har jeg mye kontakt med, og da jeg sendte mail med spørsmål om de ville komme, så var svarene "Ja, selvfølgelig!". Og det på deres egen regning!&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Så med stor fare for at min bedre halvdel blir litt skuffet (ja, jeg er faktisk gift og har en datter på 4 år), så må jeg virkelig si at julen kommer tidlig i år for min del. Litt bursdag og nyttårsaften også, vil jeg påstå.&lt;br /&gt;&lt;br /&gt;mvh.&lt;br /&gt;Per Thorsheim&lt;br /&gt;Mobil: +47 90 999 259&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8400370148915075091-5223100756909264205?l=securitynirvana.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securitynirvana.blogspot.com/feeds/5223100756909264205/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://securitynirvana.blogspot.com/2010/12/passwords10-2-dager-om-passord-pin.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/5223100756909264205'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/5223100756909264205'/><link rel='alternate' type='text/html' href='http://securitynirvana.blogspot.com/2010/12/passwords10-2-dager-om-passord-pin.html' title='Passwords^10 : 2 dager om passord &amp; PIN koder'/><author><name>Per Thorsheim</name><uri>https://profiles.google.com/113848325212589987956</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-skpoP167x04/AAAAAAAAAAI/AAAAAAAAAVU/RWc12nir74w/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_qyUrb02hPrA/TLwYB00-tnI/AAAAAAAAAOk/y52uGX7fVFU/s72-c/CFP_logo.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8400370148915075091.post-1865613569831739838</id><published>2010-11-30T00:31:00.000+01:00</published><updated>2010-11-30T00:31:43.719+01:00</updated><title type='text'>Why Passwords^10?</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/_qyUrb02hPrA/TPQ3YHiUoaI/AAAAAAAAAPQ/lEG1L7I6Now/s1600/why.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="142" src="http://2.bp.blogspot.com/_qyUrb02hPrA/TPQ3YHiUoaI/AAAAAAAAAPQ/lEG1L7I6Now/s200/why.jpg" width="200" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;I've been asked this many times: "&lt;i&gt;Why would you do a 2-day conference on passwords &amp;amp; PIN codes?&lt;/i&gt;". I'm being told that passwords are lame and old-fashioned. Biometrics and 2-factor authentication are much better at providing better security. Some even refer to &lt;a href="http://xkcd.com/538/"&gt;xkcd 538&lt;/a&gt; to describe to me why password-only authentication is stupid. Allow me to explain a little...&lt;br /&gt;&lt;br /&gt;&lt;a name='more'&gt;&lt;/a&gt;I've been researching passwords for more than 9 years now. I've got more passwords now than I had 9 years ago. Many more, in fact. Not that I've asked for them voluntarily, but it's the only option available from most services. Some services, like my online banks (I'm using 3), uses a solution named &lt;a href="https://www.bankid.no/"&gt;BankID&lt;/a&gt; to authenticate me. It runs using Java (hooray...). Among other factors, it also uses a password for authentication. The technical password policy implementation currently allows anything as your password, as long as it is minimum 6 characters in length. Yes, that allows &lt;b&gt;123456&lt;/b&gt; to be used as a password, although they do suggest to pick a stronger one to protect your financial life. I would suggest so too.&lt;br /&gt;&lt;br /&gt;I'm using Twitter, Facebook, Google, and a WIDE variety of online services. I'm even using Microsoft Windows, but I guess there's nothing special about that. &lt;i&gt;"Windows? You can get 2-factor and biometrics for Windows!"&lt;/i&gt;. Sure.&lt;b&gt; I even know some organisations who actually authenticates all their users using RSA Securid 2-factor authentication when logging on locally to Windows.&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Problem number 1:&lt;/b&gt;&lt;br /&gt;Fixed 4-digit PIN codes manually selected by their users is what you need to obtain (See xkcd 538 again), in addition to stealing that SecurID token. If the PIN isn't taped to the back of the token, that is. I've seen that before. &lt;i&gt;&lt;b&gt;Oh; and a PIN code is a&lt;u&gt; password&lt;/u&gt; to me.&lt;/b&gt;&lt;/i&gt; I presume there are probably even more people in the world dependant on PIN codes in their daily life than there are people dependant on computers. Honestly; do you know anyone above age 16 that doesn't use or depend on PINs or passwords in their daily life? And when did you last change your PIN codes? Can't remember? aha. Thought so.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Problem number 2:&lt;/b&gt;&lt;br /&gt;Of course using 2-factor like SecurID is a good idea. Usability is probably better, with less fuzz and "lost password" support calls. Well, here's a wild guess from me: I don't think all those service accounts used for monitoring, anti-malware, backup/restore, databases and similar services uses 2-factor authentication to log on. I don't even believe that shared accounts, test or demo/training accounts are equipped with SecurID tokens (I'm excluding the possibility of &lt;a href="https://secure.wikimedia.org/wikipedia/en/wiki/Skynet_%28Terminator%29"&gt;Skynet&lt;/a&gt; being present here). Unfortunately those are the accounts with the highest access levels in your Windows domain and individual systems in most cases, AND the most interesting targets for any attacker who wants full access while concealing their activities. Passwords win. Or loose. Depending on how you look at it of course.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;I'm using GPG/PGP. Come get some.&lt;/b&gt;&lt;br /&gt;I like AES. I like other algorithms as well. And your encrypted files and e-mails are protected through a private/public key system. Only you have your private key, and of course its protected by an amazing - you guessed it - PASSWORD. Without a centralized password policy for those GPG/PGP passwords, I believe many people will be using rather simple passwords to protect their private key. At least, my research shows exactly that - maybe as many as 50% will be on the absolute minimum of technical requirements implemented.&lt;b&gt;&amp;nbsp;&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;So where do you store your private key then?&lt;/b&gt; On your personal home area on some server somewhere in the organisation? In the cloud perhaps? Where domain admins, backup administrators, helpdesk and many others can easily find and copy the file for further offline processing and brute-force attacks? Many organisations uses shared private PGP keys for a single department or function. If one person leaves, who knows whether that person made a copy-to-go of that private key? Would you consider that to be a potential risk?&lt;br /&gt;&lt;br /&gt;&lt;b&gt;I'm using superduper hard drive encryption.&lt;/b&gt;&lt;br /&gt;Probably with pre-boot authentication (search for "evail maid attack" on Google), or direct boot into your OS-of-choice (probably Windows), with transparent full disk encryption, perhaps coupled with a TPM chip inside your computer. The evil maid attack will capture your password. Live memory dumps will give almost instant access to decryption keys stored in memory. Use your patience, wait for a new TCP/IP level&amp;nbsp; remote exploit to appear that allows you to attack and seize control of that computer with the encrypted disk and password/biometric protected screensaver.&lt;br /&gt;&lt;br /&gt;--&lt;br /&gt;...And I could go on for a long time with attacks and defences. Passwords are some of the oldest authentication methods we have to control access to some sort of resource - at least for computer systems. They were bad 5, 10, 15 and 20 years ago, and passwords created by humans are still bad. Almost no development in our password selections in 20 years, yet the techology to crack them have improved. Massively. And those bad passwords won't go away in the very near future.&lt;br /&gt;&lt;br /&gt;At &lt;a href="http://securitynirvana.blogspot.com/2010/11/passwords10-register-now.html"&gt;&lt;b&gt;Passwords^10&lt;/b&gt;&lt;/a&gt; we will talk about passwords and PINs because they are everywhere. They won't go away. We all use them in our daily lives. How we create them or crack them - both sides will be up for discussions at the conference. Many things can be done to improve the security passwords provide us with, while maintaining or perhaps even improving their usability for all of us.&lt;br /&gt;&lt;br /&gt;I hope you will be able to join us at the conference. We're planning to make the presentations available very shortly after the conference, as well as video recordings of all presentations.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8400370148915075091-1865613569831739838?l=securitynirvana.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securitynirvana.blogspot.com/feeds/1865613569831739838/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://securitynirvana.blogspot.com/2010/11/why-passwords10.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/1865613569831739838'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/1865613569831739838'/><link rel='alternate' type='text/html' href='http://securitynirvana.blogspot.com/2010/11/why-passwords10.html' title='Why Passwords^10?'/><author><name>Per Thorsheim</name><uri>https://profiles.google.com/113848325212589987956</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-skpoP167x04/AAAAAAAAAAI/AAAAAAAAAVU/RWc12nir74w/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_qyUrb02hPrA/TPQ3YHiUoaI/AAAAAAAAAPQ/lEG1L7I6Now/s72-c/why.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8400370148915075091.post-2725910410503397109</id><published>2010-11-29T00:10:00.000+01:00</published><updated>2010-11-29T00:10:48.197+01:00</updated><title type='text'>Revisiting password meters</title><content type='html'>&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/_qyUrb02hPrA/TPLUCjgB6gI/AAAAAAAAAPI/n6F47ZXXF6w/s1600/Swedish_PTS_statistics_28_11_10.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="180" src="http://4.bp.blogspot.com/_qyUrb02hPrA/TPLUCjgB6gI/AAAAAAAAAPI/n6F47ZXXF6w/s320/Swedish_PTS_statistics_28_11_10.png" width="320" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;i&gt;(Screenshot from Swedish PTS on Sunday 28, Nov 2010)&lt;/i&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;br /&gt;In February this year I wrote a blog post named "&lt;a href="http://securitynirvana.blogspot.com/2010/02/never-trust-password-meters.html"&gt;Never Trust Password Meters&lt;/a&gt;", after a tweet from &lt;a href="https://twitter.com/mikkohypponen"&gt;@mikkohypponen&lt;/a&gt; at F-Secure. One of the password meter services I commented on was "testalosenord" (&lt;i&gt;test your password&lt;/i&gt;) from the &lt;a href="http://www.pts.se/en-gb/"&gt;Swedish Post and Telecom Agency&lt;/a&gt;. I e-mailed them the same day, just to inform them about my blog post. On November 18 I received a reply.&lt;br /&gt;&lt;br /&gt;&lt;a name='more'&gt;&lt;/a&gt;Not that I expected any answer of course, I write about my personal opinions and I'm just happy whenever I get any feedback. It's a short reply from PTS, but they gave me a link to a page displaying statistics about the passwords tested through their online service. Oh, and they use &lt;a href="http://cracklib.sourceforge.net/"&gt;Cracklib&lt;/a&gt; for testing all passwords submitted. &lt;a href="https://www.testalosenord.pts.se/statistik.php"&gt;The statistics are interesting&lt;/a&gt;, the screenshot on top of this blog post is taken from this page.&lt;br /&gt;&lt;br /&gt;Yes, I know it's in Swedish. I'm here to help. :-)&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Passwords shorter than 8 characters (90.27%)&lt;/b&gt;&lt;br /&gt;No surprise really. My guess: most people will test one or more of their passwords, most probably personal passwords not used at work. Even if they do test their work passwords, very few organisations are at length 8 or higher in their password policies.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Passwords without digits (88.07%)&lt;/b&gt;&lt;br /&gt;Well, digits doesn't have to be a requirement for making "secure" passwords. I guess this really cannot be interpreted as "bad" passwords, as we do not have any info on length, use of upper/lower and/or specials.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Passwords without UPPERCASE letters (90.56%)&lt;/b&gt;&lt;br /&gt;To&amp;nbsp;&lt;b&gt; &lt;/b&gt;me&lt;b&gt; &lt;/b&gt;this really indicates that passwords tested are personal passwords, not subject to a "professional" password policy, that will usually require complexity requirements (3 of 4 characters groups must be used). The typical outcome of such complexity requirements are easily illustrated by me this way:&lt;br /&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/_qyUrb02hPrA/TPLaTIrSDYI/AAAAAAAAAPM/0QnCUn_VqWg/s1600/password_policy.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="126" src="http://3.bp.blogspot.com/_qyUrb02hPrA/TPLaTIrSDYI/AAAAAAAAAPM/0QnCUn_VqWg/s400/password_policy.png" width="400" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;i&gt;(Click image to see full size)&lt;/i&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;b&gt;Passwords without lowercase letters (86.05%)&lt;/b&gt;&lt;br /&gt;Now this is really surprising! In a real corporate environment I would expect lowercase letteers in pretty close to ... 99.9% of all passwords or something like that. Of course, &lt;a href="http://reusablesec.blogspot.com/2009/12/rockyou-32-million-password-list-top.html"&gt;with 123456 probably being the most common passwords out there&lt;/a&gt;, you could blame some of the statistics on that one, but 86.05% is still surprising!&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Passwords without special characters (92.25%)&lt;/b&gt;&lt;br /&gt;In a corporate environment I would usually expect this percentage to be lower, meaning more specials in passwords. However, for personal passwords most probably not originating from corporate environments with complexity requirements turned on, this makes sense to me.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Passwords found in the PTS wordlist (16.58%)&lt;/b&gt;&lt;br /&gt;Well, I don't know if they are using a standard Cracklib wordlist, or if PTS has edited such a list themselves. I have also questioned what we all consider to be a "wordlist" in a previous blog post named "&lt;a href="http://securitynirvana.blogspot.com/2010/02/whats-wordlist.html"&gt;What's a wordlist?&lt;/a&gt;". In any way I really can't see much usefulness in this one, at least for my purposes.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Passwords without any letters (4.65%)&lt;/b&gt;&lt;br /&gt;Could simply be user clicking Testa! (submit), or the common &lt;b&gt;123456 &lt;/b&gt;password, or the slightly less common &lt;b&gt;12345&lt;/b&gt; password of course. In a complexity environment I will usually expect most "complex" passwords to be on the format UllllllDD (Uppercase, multiple lowercase, 2 or 4 digits at the end).&lt;br /&gt;&lt;br /&gt;Again; interesting statistics, but I'm afraid statistics LIE. A lot. In fact, not only should you never trust password meters, but I would suggest that you should be very skeptical of password statistics as well.&lt;br /&gt;&lt;br /&gt;--&lt;br /&gt;Oh.... Seems as if I just told you not to trust my statistics either. Well, be skeptical at least. Ask questions, like I do. For &lt;a href="http://securitynirvana.blogspot.com/2010/11/passwords10-register-now.html"&gt;Passwords^10&lt;/a&gt;, I'll try to use the &lt;a href="http://www.get-tedpad.com/"&gt;tedPAD&lt;/a&gt; in order to create a fantastic presentation with my password statistics. :-)&lt;br /&gt;&lt;i&gt;(If you haven't seen the 6-minute talk on tedPAD, &lt;a href="http://www.ted.com/talks/lang/nob/lies_damned_lies_and_statistics_about_tedtalks.html"&gt;you should do so now&lt;/a&gt;! It's fantastic!)&lt;/i&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8400370148915075091-2725910410503397109?l=securitynirvana.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securitynirvana.blogspot.com/feeds/2725910410503397109/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://securitynirvana.blogspot.com/2010/11/revisiting-password-meters.html#comment-form' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/2725910410503397109'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/2725910410503397109'/><link rel='alternate' type='text/html' href='http://securitynirvana.blogspot.com/2010/11/revisiting-password-meters.html' title='Revisiting password meters'/><author><name>Per Thorsheim</name><uri>https://profiles.google.com/113848325212589987956</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-skpoP167x04/AAAAAAAAAAI/AAAAAAAAAVU/RWc12nir74w/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_qyUrb02hPrA/TPLUCjgB6gI/AAAAAAAAAPI/n6F47ZXXF6w/s72-c/Swedish_PTS_statistics_28_11_10.png' height='72' width='72'/><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8400370148915075091.post-733784561201495782</id><published>2010-11-28T22:32:00.000+01:00</published><updated>2010-11-28T22:32:38.648+01:00</updated><title type='text'>Nokas og Datalagringsdirektivet</title><content type='html'>&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_qyUrb02hPrA/TPKvhweeW_I/AAAAAAAAAPA/UPJbXlSI4CY/s1600/Nokas_promo_bilde.jpg" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" src="http://1.bp.blogspot.com/_qyUrb02hPrA/TPKvhweeW_I/AAAAAAAAAPA/UPJbXlSI4CY/s1600/Nokas_promo_bilde.jpg" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;i&gt;&lt;a href="http://www.filmweb.no/smn/kino/article252972.ece"&gt;(Bildet er hentet fra promoteringen av &lt;b&gt;Nokas&lt;/b&gt; filmen)&lt;/a&gt;&lt;/i&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;I Dagens Næringsliv lørdag 27. desember står at at Kripos henlegger saken på piraten som la en kopi av Nokas-filmen ut på The Pirate Bay. Datasporene etterforskerne trenger for å finne piraten er slettet. Jeg hadde bestemt meg for å ikke uttale meg høyt om datalagringsdirektivet. Jeg vil fortsatt forsøke å unngå det, men dette blogginnlegget kan nok oppfattes som et innlegg i debatten.&lt;br /&gt;&lt;br /&gt;&lt;a name='more'&gt;&lt;/a&gt;Versjonen av filmen som ble spredd via fildelingsnettverk viste seg å stamme fra en intern dataserver hos produksjonsselskapet Alligator, hvor en del magasinjournalister fikk tilgang til å laste ned filmen for å kunne anmelde den. Med anmeldelsen fulte en liste på under fem navn som hadde fått tilgang til filmen, samt IP-adressene som hadde lastet ned filmen fra produksjonsselskapets server.&lt;br /&gt;&lt;br /&gt;Saken henlegges, og ut i fra artikkelen synes det å være mangelen på data som binder IP-adresser mot bruker/eier på angitte tidspunkter for nedlasting som gjør at man ikke lengre kan spore opp den eller de som initielt utførte uautorisert nedlasting, kopiering og spredning på internett. Disse dataene har blitt slettet av internett leverandørene i henhold til tidsfrister for lagring av slike opplysninger, og Advokatfirmaet Simonsen reagerer naturlig nok på dette. Advokat Rune Ljostad&amp;nbsp; mener sågar at denne saken er et godt argument for forlenget lagring av slike data, uavhengig av om eventuelt datalagringsdirektivet blir innført eller ikke.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Jeg skal da altså ikke skrive noe om egne meninger ift innføring av datalagringsdirektivet.&lt;/b&gt; Imidlertid har jeg noen kommentarer - og spørsmål - som ikke synes belyst i artikkelen. Selvfølgelig blogger jeg i vei uten å kjenne alle saksdetaljer, og de er vel heller ikke offentlig tilgjengelig.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Sikkerhet og nedlasting av film&lt;/b&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: left;"&gt;&lt;/div&gt;Produksjonsselskapet Alligator la filmen ut for nedlasting for "noen magasinjournalister". Hvor mange? Hvem? Frilansere, eller ansatte i aviser/blader? Kall meg slem og forutinntatt her, men jeg satser på at noen års erfaring gir grunnlag for kvalisert gjetning:&lt;br /&gt;&lt;br /&gt;&lt;b&gt;(1) Filmen som ble lagt ut for anmeldelse var ikke digitalt vannmerket, synlig eller usynlig&lt;/b&gt;&lt;br /&gt;&lt;b&gt;(2) Det var ingen unik identifikator (vannmerking) pr person/redaksjon som fikk filmen &lt;/b&gt;&lt;br /&gt;&lt;b&gt;(3) Serveren hadde ingen begrensninger på tidsperiode for når filmen kunne lastes ned&lt;/b&gt;&lt;br /&gt;&lt;b&gt;(4) Serveren hadde ingen begrensninger for hvilke IP-adresser som kunne laste ned filmen&lt;/b&gt;&lt;br /&gt;&lt;b&gt;(5) Det ble ikke brukt kryptering av data (inkl. brukernavn/passord) ved filoverføring&lt;/b&gt;&lt;br /&gt;&lt;b&gt;(6) Tilgang til filmen ble "annonsert" via ukryptert e-post&lt;/b&gt;&lt;br /&gt;&lt;b&gt;(7) Det ble benyttet felles brukernavn/passord for tilgang&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;Jeg vil tro at ovennevnte anses som irrelevant for Advokatfirmaet Simonsen. Det ville være urimelig å ikke stole 100% på anmelderne eller redaksjonene eller frilanserne eller IT-avdelingene til mediehusene eller vennene til anmelderne som vet at anmelderne har lastet nettopp denne filmen på sin private pc uten noen god sikkerhet, pent plassert i en privat stue og lett tilgjengelig for enhver venn med en USB minnepinne til kr 179,- for kopiering. Man forventer jo selvfølgelig at filmen kun blir sett av anmelderen, og det på en pc som er kryptert og avskåret fullstendig fra omverden, inkludert egen redaksjon, samboer og barn. Filmen slettes selvfølgelig på en sikker måte øyeblikkelig etter at anmelder har sett gjennom den. &lt;b&gt;Hva skjedde med lukket pressevisning egentlig?&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Velkommen til 2010.&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;Jeg spurte Georg Apenes for noen år tilbake om hvem jeg kunne egentlig stole på. Han trakk på skuldrene, og sa at det var et ubehagelig godt spørsmål. Noe å lære av i denne situasjonen kanskje?&lt;br /&gt;&lt;br /&gt;Som sagt; jeg kjenner ikke sakens detaljer. Jeg tviler på at de er tilgjengelig, og at hverken Kripos, Advokatfirmaet Simonsen eller Alligator vil gjøre dem tilgjengelig heller. Dermed kan jeg ikke påstå at det kunne ha blitt gjort mer for å sikre tilgang til, samt distribusjon av anmelderutgaven. Jeg bare TROR at man kunne ha gjort det, og antagelig for en lavere sum enn det som nå har blitt brukt på en tapt sak og ringvirkningene av dette.&lt;b&gt; Sikringstiltak som nevnt over er fullt lovlige og tilgjengelige i dag, og jeg tror personlig at de også ville bidratt mye bedre enn ethvert datalagringsvedtak til å oppklare saken.&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;--&lt;br /&gt;Ut i fra artikkelen i Dagens Næringsliv så fremgår det ingen beskrivelse av noen sikringstiltak overhodet, ei heller er ordet tillit nevnt. Det som fascinerer meg i alle saker hvor elektroniske data/informasjon er kommet på avveie, er at det svært sjelden snakkes om alle de som har&lt;b&gt; teknisk&lt;/b&gt;, men ikke&lt;b&gt; rettslig tilgang&lt;/b&gt; til dataene som overføres og lagres elektronisk. Det er et tema som jeg akter å skrive mer om fremover.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8400370148915075091-733784561201495782?l=securitynirvana.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securitynirvana.blogspot.com/feeds/733784561201495782/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://securitynirvana.blogspot.com/2010/11/nokas-og-datalagringsdirektivet.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/733784561201495782'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/733784561201495782'/><link rel='alternate' type='text/html' href='http://securitynirvana.blogspot.com/2010/11/nokas-og-datalagringsdirektivet.html' title='Nokas og Datalagringsdirektivet'/><author><name>Per Thorsheim</name><uri>https://profiles.google.com/113848325212589987956</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-skpoP167x04/AAAAAAAAAAI/AAAAAAAAAVU/RWc12nir74w/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_qyUrb02hPrA/TPKvhweeW_I/AAAAAAAAAPA/UPJbXlSI4CY/s72-c/Nokas_promo_bilde.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8400370148915075091.post-6254661277958105677</id><published>2010-11-15T23:38:00.002+01:00</published><updated>2010-11-15T23:41:29.436+01:00</updated><title type='text'>Malware Authors: Show Me Your Passwords!</title><content type='html'>I'm baffled. &lt;i&gt;And that doesn't happen too often&lt;/i&gt;. In February I wrote a blog post over at Elcomsofts official blog, entitled "&lt;a href="http://blog.crackpassword.com/2010/02/why-you-should-crack-your-passwords/"&gt;Why you should crack your passwords&lt;/a&gt;". I'm long overdue for a follow-up on that post, with another angle at the same statement. Do you remember &lt;a href="https://secure.wikimedia.org/wikipedia/en/wiki/Conficker"&gt;Conficker&lt;/a&gt; (also known as Downadup)? I guess you do. And that's the primary reason for this blog post, and me being baffled.&lt;br /&gt;&lt;br /&gt;&lt;a name='more'&gt;&lt;/a&gt;At work one of my regular tasks is to coordinate joint efforts on security patch management. We've got quite a few systems to keep updated, but that would be a different story to tell. I remember the MS08-067 patch, and how we deployed it faster than anything else we had ever deployed earlier. (To those of my colleagues reading this: I'm proud of your efforts!).&lt;br /&gt;&lt;br /&gt;As soon as Conficker went into action across the Internet, security professionals started analyzing it. The "B" version of Conficker, first discovered December 29, 2008, used a simple dictionary to conduct bruteforce authentication attempts against the default ADMIN$ share on Windows systems. This was done in order to increase the probability of successful infections and higher speed of distribution.&lt;br /&gt;&lt;br /&gt;A nice summary of how Conficker did this can be found in the article "&lt;a href="http://www.symantec.com/connect/blogs/downadup-locking-itself-out"&gt;Downadup: Locking Itself Out&lt;/a&gt;" by Eric Chien at Symantec, while a more extensive list of passwords used by Conficker can be found at &lt;a href="http://www.f-secure.com/v-descs/worm_w32_downadup_al.shtml"&gt;F-Secure's virus description of W32/Downadup&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Back to me being baffled.&amp;nbsp;&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;I've been playing, working, researching - dreaming - about passwords for more than 9 years now. One of the things that I requested as soon as I heard Conficker/Downadup did dictionary attacks, was a complete list of all the passwords it had in its wordlist. I think I laughed for quite some time when I saw it: it was BAD. As in not good, if your purpose is to get access to accounts and shares with a low number of guesses before locking out accounts (which happened all over where Conficker gained initial entry).&lt;br /&gt;&lt;br /&gt;So of course I did another round of password audits in order to be sure NONE of these passwords would succeed for Conficker. And I were correct, none of those passwords would give access to anything that I were responsible for at that time.&lt;br /&gt;&lt;br /&gt;The original reason for doing this blog post was to do a follow-up from the previous blog post by me at the Elcomsoft blog. Not only should you crack your passwords in order to check compliance between your written password policy and its various technical implementations across platforms. You should also do it to measure compliance between real-life passwords and the technical and written policy as well.&lt;br /&gt;&lt;br /&gt;This blog post were supposed to talk about the passwords found in various malware like Conficker, their authors who obviously (to me) didn't know much about statistically popular passwords or policy implementations. This blog post were supposed to give you more background info that you could use when doing your own password audits, in order to protect yourself from such automated malware attacks.&lt;br /&gt;&lt;br /&gt;&lt;u&gt;&lt;b&gt;Instead, I end up with what really baffles me:&lt;/b&gt;&lt;/u&gt;&lt;br /&gt;I've asked Norman, Sophos and F-Secure if they have ever compiled any lists of passwords being used by various types of malware for password guessing. NONE of them have done something like that, all I've got are links to old blog posts on Conficker. I've even googled for it several times, but no luck so far.&lt;br /&gt;&lt;br /&gt;So in case none of my readers have made such a list, all I can say is:&lt;br /&gt;&lt;b&gt;Malware Authors: Show Me Your Passwords!&lt;/b&gt;&lt;br /&gt;&lt;b&gt;&amp;nbsp;--&lt;/b&gt;&lt;br /&gt;&lt;i&gt;O&lt;/i&gt;&lt;i&gt;h, and if anyone of you decide to attend &lt;a href="http://securitynirvana.blogspot.com/2010/11/passwords10-register-now.html"&gt;Passwords^10&lt;/a&gt;, please notify me upon arrival.&lt;/i&gt;&lt;b&gt; &lt;/b&gt;:-)&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8400370148915075091-6254661277958105677?l=securitynirvana.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securitynirvana.blogspot.com/feeds/6254661277958105677/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://securitynirvana.blogspot.com/2010/11/malware-authors-show-me-your-passwords.html#comment-form' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/6254661277958105677'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/6254661277958105677'/><link rel='alternate' type='text/html' href='http://securitynirvana.blogspot.com/2010/11/malware-authors-show-me-your-passwords.html' title='Malware Authors: Show Me Your Passwords!'/><author><name>Per Thorsheim</name><uri>https://profiles.google.com/113848325212589987956</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-skpoP167x04/AAAAAAAAAAI/AAAAAAAAAVU/RWc12nir74w/s512-c/photo.jpg'/></author><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8400370148915075091.post-5555452959815312012</id><published>2010-11-14T20:28:00.000+01:00</published><updated>2010-11-14T20:28:00.740+01:00</updated><title type='text'>Usikrede trådløse nettverk</title><content type='html'>&lt;b&gt;Til alle tilbydere av trådløse nettverk i Norge, både i kommersiell og offentlig regi, samt alle andre som har åpne trådløse nettverk for egne ansatte, gjester, naboer og hvem det ellers måtte være.&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;Jeg håper og tror at de fleste av dere fikk med dere lanseringen av "Firesheep", et tillegg til nettleseren Firefox som ble lansert for noen uker tilbake. Media har allerede dekket dette grundig som en nyhetssak, selv om det egentlig ikke presenteres noen nyhet. Dette tillegget gjør det ekstremt enkelt å stjele tilgang til andres Facebook kontoer, samt en rekke andre kjente steder som Twitter og Amazon.com. Teknikken er altså "gammel", dette tillegget er lansert "&lt;i&gt;for å få ulike tjenesteleverandører til å tenke seg om en gang til&lt;/i&gt;".&lt;br /&gt;&lt;br /&gt;&lt;a name='more'&gt;&lt;/a&gt;...Og her kommer altså mitt ønske til dere: vær vennlig og vurder et prosjekt som har til hensikt å innføre kryptering av deres trådløse nettverk som standard. Dette for å kraftig redusere sannsynligheten for misbruk av deres trådløse nettverk, samt skjerme deres kunder fra hverandre ved bruk av deres nett.&lt;br /&gt;&lt;br /&gt;Eksempel: sitter man på Gardermoen og bruker Avinors trådløse nettverk (valgfri leverandør), så benytter man altså et åpent trådløst nettverk. Dette gir i seg selv ingen sikkerhet overhodet, noe også Avinor selv opplyser om i sine bruksvilkår. All bruk av f.eks. Facebook, Amazon eller Twitter på dette trådløse nettverket, f.eks. via pc, iPad eller mobiltelefon, kan svært enkelt avlyttes og misbrukes av andre på samme nettverk. Faktisk kan man med dette verktøyet ta eierskap til andres kontoer på nevnte tjenester, samt en rekke andre. Dette igjen kan gi tilgang til personsensitive data (ref §POL), forretningshemmeligheter, og andre sensitive opplysninger.&lt;br /&gt;&lt;br /&gt;Jeg skal ikke påstå at ingen leser vilkårene før de tar tjenesten i bruk, men jeg tror ikke det er mange som leser dem heller. Hvor mange som faktisk forstår konsekvensene av vilkårene er jo også relevant, men det kan jo ikke Avinor eller samarbeidspartnere holdes ansvarlig for regner jeg med.&lt;br /&gt;&lt;br /&gt;Nå er ikke mitt ønske noe jeg har funnet på selv. Jeg vil ikke ta æren for noe som andre har kommet opp med, så jeg vil anbefale dere følgende lesning. Jeg føyer meg til rekkene som er enig i disse vurderingene, og anbefaler tiltak fra dere.&lt;br /&gt;&lt;br /&gt;1. &lt;a href="http://www.computerworld.com/s/article/9194159/Is_it_legal_to_use_Firesheep_at_Starbucks_"&gt;Is it legal to use Firesheep at Starbucks?&lt;/a&gt; (Computerworld)&lt;br /&gt;Denne artikkelen er svært interessant, da den tar opp 2 motsetningsforhold i en juridisk kontekst: "&lt;i&gt;det finnes ingen rimelig forventning til personvern i et offentlig tilgjengelig og åpent/usikkert trådløst nettverk&lt;/i&gt;"&lt;i&gt;. &lt;/i&gt;Dette settes opp mot "&lt;i&gt;Når mennesker bruker sin konto på sosiale nettverkstjenester, så har man en forventning om at ens personvern blir ivaretatt&lt;/i&gt;". At sistnevnte tilgang gjøres via et åpent/usikret nettverk anses dermed som irrelevant.&lt;br /&gt;&lt;br /&gt;2. &lt;a href="http://nakedsecurity.sophos.com/2010/11/09/dear-starbucks-the-skinny-on-how-you-can-be-a-security-hero/"&gt;Dear Starbucks: The skinny on how you can be a security hero&lt;/a&gt; (nakedsecurity)&lt;br /&gt;Chester Wiesniewski i Sophos Labs skrev denne artikkelen som en anbefaling om å sikre sine løsninger til ulike leverandører av trådløst nettverk. Han fikk umiddelbart respons av teknisk karakter; nettopp at hans anbefalinger allikevel kunne forbigås gjennom mer avanserte og målrettede angrep. Han oppdaterte saken sin med å si at dette kanskje ikke var en så god ide allikevel. Jeg har selv kommunisert med ham og flere andre, og konsensus virker å være at &lt;b&gt;det er bedre å gjøre noe, enn å gjøre ingenting. &lt;/b&gt;I så måte inneholder artikkelen alt dere måtte ha behov for å vite ift sikring av dagens løsninger. &lt;br /&gt;&lt;br /&gt;Det er mange måter dette kan løses på, og for de store leverandørene kan det nok innebære en del arbeid. For alle bedrifter og andre mindre organisasjoner som tilbyr såkalte "gjestenett" i form av trådløse nettverk; vær oppmerksom på at dere utsetter deres gjester for unødig risiko ved å tilby slike gjestenett i ukryptert og ubeskyttet form. Sannsynligheten for at egne ansatte også benytter slike gjestenett er stor, mens de nødvendige tiltak bør ikke representere mer enn noen timers arbeid pluss et oppslag på intranett og i resepsjonen om innføring av felles tilgangspassord til det trådløse nettverket.&lt;br /&gt;&lt;br /&gt;Når dette er sagt så bør det vel også sies at forbrukere flest har en forventning til at de sikkerhetsmekanismer som måtte eksistere i et produkt er skrudd på som standard ved kjøp. Man forventer jo at sikkerheten er godt ivaretatt de fleste steder. Allikevel selges det meste av slikt trådløst utstyr med et standard oppsett hvor de fleste sikkerhetsfunksjoner er skrudd av, og det overlates til sluttbruker å ta dem i bruk dersom dette er ønskelig.&lt;br /&gt;&lt;br /&gt;Lykke til.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8400370148915075091-5555452959815312012?l=securitynirvana.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securitynirvana.blogspot.com/feeds/5555452959815312012/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://securitynirvana.blogspot.com/2010/11/usikrede-tradlse-nettverk.html#comment-form' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/5555452959815312012'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/5555452959815312012'/><link rel='alternate' type='text/html' href='http://securitynirvana.blogspot.com/2010/11/usikrede-tradlse-nettverk.html' title='Usikrede trådløse nettverk'/><author><name>Per Thorsheim</name><uri>https://profiles.google.com/113848325212589987956</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-skpoP167x04/AAAAAAAAAAI/AAAAAAAAAVU/RWc12nir74w/s512-c/photo.jpg'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8400370148915075091.post-1048804003351760579</id><published>2010-11-08T20:35:00.002+01:00</published><updated>2011-03-10T10:46:24.796+01:00</updated><title type='text'>Passwords^10 : REGISTER NOW!</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://lh4.googleusercontent.com/-6qTsMuKe94w/TWBAZwkAWHI/AAAAAAAAARU/SJFrQGxWmkE/s1600/header.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="https://lh4.googleusercontent.com/-6qTsMuKe94w/TWBAZwkAWHI/AAAAAAAAARU/SJFrQGxWmkE/s1600/header.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt;&lt;b&gt;Announcement:&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt;&lt;b&gt;Passwords^11 is coming. June 7-8. &lt;a href="http://securitynirvana.blogspot.com/2011/03/call-for-papers-passwords11.html"&gt;CFP is here!&lt;/a&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;We are ready. You can now register for participation at Passwords^10, a 2-day conference on Passwords &amp;amp; PINs. Free for all, at the University in Bergen (Norway), on December 8-9. Limited seats available.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a name='more'&gt;&lt;/a&gt;Register now by sending an e-mail to me &lt;b&gt;(per at thorsheim dot net&lt;/b&gt;), with the following information: &lt;br /&gt;- &lt;b&gt;Full name&lt;/b&gt;&lt;br /&gt;- &lt;b&gt;Title / position&lt;/b&gt;&lt;br /&gt;- &lt;b&gt;Company / Organisation (if applicable)&lt;/b&gt;&lt;br /&gt;&lt;b&gt;&lt;/b&gt;&lt;br /&gt;- &lt;b&gt;Participate in joint event Yes/No&lt;/b&gt; (Wednesday evening Dec 8, location/program TBA, you pay for yourself)&lt;br /&gt;&lt;br /&gt;&amp;nbsp;&lt;i&gt;... and any additional info that shows you are not a bot, but a human interested in Passwords &amp;amp; PINs are most welcome as well of course. :-)&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;We will confirm your registration back to your e-mail address. No, we have no intentions of using it ever after, unless you specifically ask for it. Since this is a free conference, attendees may drop attending in the very last minute. Please, if you register and then find out you can't participate anyway, let us now ASAP.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Oh.. And maybe you would like to &lt;a href="http://home.online.no/~putilutt/Passwords10_preliminary_program.pdf"&gt;have a look at the preliminary program&lt;/a&gt;? &lt;/b&gt;(PDF, 173KB&lt;b&gt;, &lt;/b&gt;no embeded javascript or flash, stored at home.online.no). There you will also find additional and useful info on how to get to the conference, where to stay and so on. Usability you know.&lt;br /&gt;&lt;br /&gt;All speakers confirmed, schedule may change, more contents to be filled in (check back later). Please contact me if you have any questions, comments or just want to say "Sorry I can't be there, maybe next year?". :-)&lt;br /&gt;&lt;br /&gt;Best regards,&lt;br /&gt;Per Thorsheim&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8400370148915075091-1048804003351760579?l=securitynirvana.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securitynirvana.blogspot.com/feeds/1048804003351760579/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://securitynirvana.blogspot.com/2010/11/passwords10-register-now.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/1048804003351760579'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/1048804003351760579'/><link rel='alternate' type='text/html' href='http://securitynirvana.blogspot.com/2010/11/passwords10-register-now.html' title='Passwords^10 : REGISTER NOW!'/><author><name>Per Thorsheim</name><uri>https://profiles.google.com/113848325212589987956</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-skpoP167x04/AAAAAAAAAAI/AAAAAAAAAVU/RWc12nir74w/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='https://lh4.googleusercontent.com/-6qTsMuKe94w/TWBAZwkAWHI/AAAAAAAAARU/SJFrQGxWmkE/s72-c/header.png' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8400370148915075091.post-5141278243093290474</id><published>2010-11-05T12:50:00.001+01:00</published><updated>2010-11-05T13:12:51.291+01:00</updated><title type='text'>Usikkert Norgespass</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/_qyUrb02hPrA/TNPjaiU6hAI/AAAAAAAAAOw/8Vy-bOwxYNY/s1600/Samsung_Galaxy_Tab.jpg" imageanchor="1" style="clear: left; cssfloat: left; float: left; margin-bottom: 1em; margin-right: 1em;"&gt;&lt;img border="0" px="true" src="http://3.bp.blogspot.com/_qyUrb02hPrA/TNPjaiU6hAI/AAAAAAAAAOw/8Vy-bOwxYNY/s1600/Samsung_Galaxy_Tab.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;Jeg har VELDIG lyst på en Samsung Galaxy Tab. I likhet med mye annen elektronikk selvfølgelig, men det kan vi ta litt nærmere jul. Ofte er det imidletid slik at man bare må gjøre noe øyeblikkelig, så også i dette tilfellet (Nei kjæresten min, jeg har ikke kjøpt denne dingsen - enda!)&lt;br /&gt;&lt;br /&gt;&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Jeg besøkte Nettavisen.no i dag, og så en liten reklame som sa at jeg kunne vinne akkurat en slik Galaxy Tab dingseboms. Selvfølgelig bare ved å registrere meg. Vanligvis holder jeg meg langt unna de fleste reklamer og slike konkurranser, men her ble jeg fristet:&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/_qyUrb02hPrA/TNPlCpmgFNI/AAAAAAAAAO0/Ea1nSCWrhN4/s1600/konkurranse_reklame.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" px="true" src="http://3.bp.blogspot.com/_qyUrb02hPrA/TNPlCpmgFNI/AAAAAAAAAO0/Ea1nSCWrhN4/s1600/konkurranse_reklame.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Så jeg klikker, og havner på nettsidene til &lt;a href="http://www.norgespasset.no/index.php"&gt;Norgespasset.no&lt;/a&gt;. Setter i gang registrering, og får underveis selvfølgelig beskjed om at de skal tyte meg full av reklame i alle kanaler som gratis medlem, men til gjengjeld kan jeg jo vinne en Samsung Galaxy TAB! WOOHOO! (Utrolig hvordan sunt vett forsvinner ut på et blunk når man har satt seg et urealistisk mål: vinne i en konkurranse på nett....)&lt;br /&gt;&lt;br /&gt;Så gjør jeg gjennom hele registreringen da, innkludert kravet om å liste opp minst ett tema som jeg er interessert i, slik at de kan "skreddersy" reklamen de vil sende meg. Mjo.. SKEPTISK.&lt;br /&gt;&lt;br /&gt;Men så tar jo sikkerhetshalvdelen av hjernen over igjen da, og man tenker litt rasjonelt igjen etter at den forskuddterte seiersrusen begynner å gi seg. Hm... Hadde ikke disse en brukeravtale som jeg såvidt skumleste deler av? Var det ikke noe om personvern der? Joda, det var det. &lt;a href="http://www.norgespasset.no/index.php?show=16&amp;amp;expand=16&amp;amp;topmenu_2=16"&gt;Betingelsene deres finner du her&lt;/a&gt;. Tjenesten tilhører Mediehuset Nettavisen AS og Barlind Solutions AS. Se på pkt 13 i betingelsene deres, spesielt andre paragraf:&lt;br /&gt;&lt;br /&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/_qyUrb02hPrA/TNPnvzZqULI/AAAAAAAAAO4/mZW5oUcIXdQ/s1600/Betingelser_passord.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="76" px="true" src="http://3.bp.blogspot.com/_qyUrb02hPrA/TNPnvzZqULI/AAAAAAAAAO4/mZW5oUcIXdQ/s400/Betingelser_passord.png" width="400" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;em&gt;(Klikk for full størrelse)&lt;/em&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;br /&gt;Så ser vi også på hvilke opplysninger de ber om at du registrerer på profilen din (mange av disse er riktignok frivillige å oppgi):&lt;br /&gt;&lt;br /&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/_qyUrb02hPrA/TNPoM59tCJI/AAAAAAAAAO8/_4M7GcBo2C4/s1600/Profile_data.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="320" px="true" src="http://1.bp.blogspot.com/_qyUrb02hPrA/TNPoM59tCJI/AAAAAAAAAO8/_4M7GcBo2C4/s320/Profile_data.png" width="272" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;em&gt;(Klikk for full størrelse)&lt;/em&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;Mye data for å skreddersy reklame rettet mot meg, og definitivt også en god porsjon personopplysninger som kan brukes til f.eks. &lt;a href="http://idtyveri.info/"&gt;ID-tyveri&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Vel vel. Kjære Mediehuset Nettavisen AS og Barlind Solutions AS, i henhold til betingelsene for bruk av deres tjeneste så vil jeg med dette opplyse om at jeg mistenker at andre kan ha fått tak i mitt brukernavn og/eller passord. Årsakene til dette er som følger:&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;1. Dere bruker min mailadresse som brukernavn. &lt;/strong&gt;&lt;br /&gt;Det skal virkelig ikke noen spesiell ekspertise til for å finne ut hvilke mailadresser jeg bruker til vanlig, og jeg er faktisk over gjennomsnittet paranoid på sikkerhet. For mer normale mennesker tror jeg det er enda enklere.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;2. Dere har ingen passordpolicy eller -krav!&lt;/strong&gt;&lt;br /&gt;Passordet mitt i det jeg skriver denne teksten er tallet 1 (en). Ikke noe mer. &lt;strong&gt;EN ENKELT KARAKTER!&lt;/strong&gt; Jeg har &lt;strong&gt;ALDRI FØR&lt;/strong&gt; sett så dårlig passordsikkerhet i noen løsning med brukernavn/passord på Internett &lt;strong&gt;OVERHODET!&lt;/strong&gt; Og jeg har da altså brukt Internett siden høsten 1992!&lt;br /&gt;&lt;em&gt;(Overdreven bruk av store bokstaver, fet tekst og utropstegn for å gi avsnittet et mer journalistisk sensasjonspreg, tilgi meg for det....)&lt;/em&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;3. Dere bruker HTTP og cookies for sesjonsstyring!&lt;/strong&gt;&lt;br /&gt;&lt;a href="http://www.nettavisen.no/it/article3013548.ece"&gt;Nettavisen har selv skrevet om "firesheep" den 26.10.10.&lt;/a&gt;&amp;nbsp;La gå, teknikken har jo vært kjent i noen år allerede, men firesheep gjør det elementært enkelt for de fleste å stjele andres tilganger til nettsteder der hvor disse benytter hettopp HTTP og cookies for sesjonsstyring - akkurat slik dere gjør. Kaste stein i glasshus er det jo mange som gjør, men det rekker knapt nok som noen forklaring i de fleste tilfeller.&lt;br /&gt;&lt;br /&gt;Jeg skal ikke spekulere i hvorvidt dere har gjort noen risikoanalyse som tilsier at deres nåværende sikkerhetsnivå er tilfresstillende for dere eller ikke. Ei heller om dere har benyttet interne eller eksterne sikkerhetsressurser for å kvalitetssikre løsningen før den settes i produksjon.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Jeg vil egentlig bare melde i fra om at jeg tror mitt brukernavn og passord kan ha kommet på avveie.&lt;/strong&gt; Jeg melder i fra på denne måten (ukryptert via Internett), så reduserer vi sannsynligheten for at sikkerhet vil komme i veien for det viktige budskap som skal formidles.&lt;br /&gt;&lt;br /&gt;Med vennlig hilsen,&lt;br /&gt;Per Thorsheim&lt;br /&gt;&lt;br /&gt;--&lt;br /&gt;&lt;br /&gt;PS: det finnes ingen mulighet inne på sidene deres for at jeg skal kunne slette min konto på en enkel måte. Faktisk måtte jeg søke på ordet "slett" i betingelsene deres for å finne ut hvordan jeg kan gjøre det. Enten ved å sende et fysisk brev til dere, eller gjennom en mail til &lt;a href="mailto:norgespasset@nettavisen.no"&gt;norgespasset@nettavisen.no&lt;/a&gt;. Virkelig enkelt, det må jeg si.&lt;br /&gt;&lt;br /&gt;PS #2: tolker jeg betingelsene deres at dersom jeg laster opp hva-som-helst til dere, og så ber om å få slettet min konto, så vil allikevel alle data om meg tidligst bli slettet om 3 år? (punkt 5, siste avsnitt, siste setning). &lt;em&gt;(Håper det er greit for dere at jeg tipser Datatilsynet om den der.)&lt;/em&gt;&lt;br /&gt;&lt;br /&gt;PS #3: Jeg tar det for gitt at jeg ikke vinner noen Samsung Galaxy Tab nå, selv om jeg har registrert meg. For ordens skyld sender jeg dere også en mail med beskjed om at jeg vil slettes som bruker hos dere.&lt;br /&gt;&lt;br /&gt;PS #4: Jeg ser at dere sender brukernavn, passord og navn på tjenesten i en og samme mail, uten noen sikkerhet. Anbefaler en tidligere bloggpost fra meg på dette temaet: &lt;a href="http://securitynirvana.blogspot.com/2010/10/how-not-to-send-account-info-by-mail.html"&gt;http://securitynirvana.blogspot.com/2010/10/how-not-to-send-account-info-by-mail.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;PS #5: Passordet dere sendte meg umiddelbart etter registrering samsvarer ikke med det jeg oppga ved registrering. Ikke er det "godt nok" heller i forhold til anbefalt god praksis.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8400370148915075091-5141278243093290474?l=securitynirvana.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securitynirvana.blogspot.com/feeds/5141278243093290474/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://securitynirvana.blogspot.com/2010/11/usikkert-norgespass.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/5141278243093290474'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/5141278243093290474'/><link rel='alternate' type='text/html' href='http://securitynirvana.blogspot.com/2010/11/usikkert-norgespass.html' title='Usikkert Norgespass'/><author><name>Per Thorsheim</name><uri>https://profiles.google.com/113848325212589987956</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-skpoP167x04/AAAAAAAAAAI/AAAAAAAAAVU/RWc12nir74w/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_qyUrb02hPrA/TNPjaiU6hAI/AAAAAAAAAOw/8Vy-bOwxYNY/s72-c/Samsung_Galaxy_Tab.jpg' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8400370148915075091.post-6319612398861770528</id><published>2010-11-03T23:39:00.000+01:00</published><updated>2010-11-03T23:39:22.371+01:00</updated><title type='text'>CFP for Passwords^10 has ended</title><content type='html'>&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/_qyUrb02hPrA/S3CDq-kP-gI/AAAAAAAAACI/NfZNixSq7QE/s1600/password_policy_800.png" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="100" src="http://2.bp.blogspot.com/_qyUrb02hPrA/S3CDq-kP-gI/AAAAAAAAACI/NfZNixSq7QE/s320/password_policy_800.png" width="320" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;&lt;i&gt;(Click for full size)&lt;/i&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;Short notification; the public CFP is now closed. Speakers have been notified, we're currently working out the details for the program. Public registration opens up on monday morning 08:00 (Norway/Oslo time). Limited seats available. Free participation including lunch. Wednesday evening we'll meet for the usual fun, including a competition with prizes to be won! (A big thank you to Elcomsoft for sponsoring us with those!)&lt;br /&gt;&lt;br /&gt;This will be *COOL*. Passwords &amp;amp; PINs for 2 full days. &lt;a href="http://www.elcomsoft.com/"&gt;Elcomsoft&lt;/a&gt;.&lt;a href="http://www.passware.com/"&gt; Passware&lt;/a&gt;. &lt;a href="http://www.oracle.com/"&gt;Oracle&lt;/a&gt;. The &lt;a href="http://www.freerainbowtables.com/"&gt;freerainbowtables.com&lt;/a&gt; project. And more!&lt;br /&gt;&lt;br /&gt;Hey, we'll even try to make video recordings available afterwards for those unable to attend.&lt;br /&gt;&lt;br /&gt;More to come, stay tuned. :-)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8400370148915075091-6319612398861770528?l=securitynirvana.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securitynirvana.blogspot.com/feeds/6319612398861770528/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://securitynirvana.blogspot.com/2010/11/cfp-for-passwords10-has-ended.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/6319612398861770528'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8400370148915075091/posts/default/6319612398861770528'/><link rel='alternate' type='text/html' href='http://securitynirvana.blogspot.com/2010/11/cfp-for-passwords10-has-ended.html' title='CFP for Passwords^10 has ended'/><author><name>Per Thorsheim</name><uri>https://profiles.google.com/113848325212589987956</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='//lh6.googleusercontent.com/-skpoP167x04/AAAAAAAAAAI/AAAAAAAAAVU/RWc12nir74w/s512-c/photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_qyUrb02hPrA/S3CDq-kP-gI/AAAAAAAAACI/NfZNixSq7QE/s72-c/password_policy_800.png' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8400370148915075091.post-6564282926694984664</id><published>2010-10-18T11:49:00.002+02:00</published><updated>2010-10-18T12:01:34.661+02:00</updated><title type='text'>Passwords^10</title><content type='html'>&lt;div class="PlainText"&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/_qyUrb02hPrA/TLwYB00-tnI/AAAAAAAAAOk/y52uGX7fVFU/s1600/CFP_logo.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/_qyUrb02hPrA/TLwYB00-tnI/AAAAAAAAAOk/y52uGX7fVFU/s1600/CFP_logo.png" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;b&gt;ANNOUNCEMENT &amp;amp; CALL FOR PAPERS :  PASSWORDS^10&lt;/b&gt;&lt;/div&gt;&lt;br /&gt;&lt;b&gt;PASSWORDS^10&lt;/b&gt; will be held at the University in Bergen  (Norway), on December 8-9, 2010. The 2-day conference will be free and open  for everyone to attend. Primary audience will be academics and  security professionals with deep technical/crypto knowledge. Limited  seats available. Passwords &amp;amp; PINs, nothing else.&lt;br /&gt;&lt;a name='more'&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="PlainText"&gt;&lt;b&gt;--== DATES  ==--&lt;/b&gt;&lt;br /&gt;October 18 - Public CFP&lt;br /&gt;November 1 - CFP submission ends&lt;br /&gt;November  5 - All notifications sent to speakers (accept / reject)&lt;br /&gt;November 8 - Public  registration opens&lt;br /&gt;&lt;br /&gt;&lt;b&gt;--== ABOUT THE CONFERENCE ==--&lt;/b&gt;&lt;br /&gt;The  conference will be held at the University in Bergen (uib.no), with help and  participation from The Selmer Center (&lt;a href="http://www.blogger.com/redir.aspx?C=f3a91658911c465e93f1589e299b0b32&amp;amp;URL=http%3a%2f%2fwww.uib.no%2frg%2fselmer" target="_blank"&gt;www.uib.no/rg/selmer&lt;/a&gt;) and NISNet (&lt;a href="http://www.blogger.com/redir.aspx?C=f3a91658911c465e93f1589e299b0b32&amp;amp;URL=http%3a%2f%2fwww.nisnet.no" target="_blank"&gt;www.nisnet.no&lt;/a&gt;). Start Dec 08 10:00, ending Dec 9 16:00.  We'll sleep somewhere in the middle. 1 or more tracks, depending on  quality, number and length of presentations.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;--== CALL FOR PAPERS  ==--&lt;/b&gt;&lt;br /&gt;We are looking for new and relevant content within ATTACKS, DEFENCE  and USABILITY towards passwords &amp;amp; PIN codes. Presentations will be either  1 hour (45-50 minutes + questions), or 2 hours including a  break.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;ATTACKS&lt;/b&gt; can include online and offline attacks against all types  of passwords and &amp;amp; PINs, where the purpose is to gain access to, or  recover a password in some form. (Mind reading is out of scope). New &amp;amp;  updated tools, techniques are welcome.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;DEFENCE&lt;/b&gt; includes ways to defend  against online/offline attacks against passwords, including IDS, logging,  ciphers, policies, awareness etc.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;USABILITY&lt;/b&gt; includes user interaction  designs, password policies, security awareness, password reset / recovery  from a user perspective, statistics and so on. &lt;br /&gt;&lt;br /&gt;&lt;b&gt;-- == HOW TO  SUBMIT ==--&lt;/b&gt;&lt;br /&gt;Send your suggestions to per@thorsheim.net. Submissions will  be reviewed by people from the Selmer Center and me (Per Thorsheim).  Submissions MUST include the following information:&lt;br /&gt;&lt;br /&gt;1. Speaker(s)  name&lt;br /&gt;2. Bio (short, should include link to online profile, website, blog  etc)&lt;br /&gt;3. Header and abstract of your presentation&lt;br /&gt;4. List of facilities  required beyond the usual equipment available&lt;br /&gt;5. If you will allow materials,  presentation and video to be made available online after the  conference.&lt;br /&gt;&lt;br /&gt;All papers and presentations must be in English. With a free  conference and a limited budget, we're still working on finding a way to  reward our speakers. Lunch will be for free.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;--== IMPORTANT  INFORMATION FOR SUBMISSIONS ==--&lt;/b&gt;&lt;br /&gt;No product marketing will be accepted.  No marketing managers will be accepted.
