Showing posts with label Passwords. Show all posts
Showing posts with label Passwords. Show all posts

Friday, April 18, 2014

Heartbleed: Are you bleeding out?

So you have heard about the Heartbleed bug that is affecting the Internet, but what is it really and what does it mean to you? Should you really be concerned?

Some reports say that it is the worst bug discovered on the Internet so far and others seem to brush it off as just another tech mumbo jumbo.  But I'm betting that you'd like someone to explain it so you know what the heck this thing is and if you really should be concerned, right? Well, as your Nerd friend, let me say that you need to be a little concerned about all this and here is why.

What this whole thing is about is allowing someone, who is not you, to snoop, or "read", your secure Internet communications.  Let's see if I can explain; let's say you log into Amazon.com to do a bit of shopping. You find the items you want to buy and add them to your card. You then go to your shopping cart to check out. Now you notice the little green pad Lock up in the address bar (if you're using Chrome, otherwise it might be elsewhere depending on your browser). This means that you have a secure connection with the Amazon server, i.e. Only you and the Amazon server can read the communication between the two of you. This is because there is an SSL, or Secure Socket Layer, connection between your browser and the server. Think of it as a pipe, an encrypted pipe, between your browser and the server. Anyone trying to intercept and read messages sent along this secure pipe only can see garbley gook because everything inside it is encrypted.

Now, this connection is kept alive with what is known as a heartbeat message. The purpose of the heartbeat message is to tell each side that the other is still there and not to close the connection. This Heartbleed bug allows someone outside the pipe to intercept this heartbeat message and with a slight modification, request the original heartbeat message but also request additional bytes of data from server memory for that connection. This means that anything in memory for that connection could be exposed. That could be the encryption keys or even username & passwords. If the encryption keys are exposed, this is then bad because the attacker could use that information to read all communications in that secure pipe.  

Ok... So what, Right?  You might ask, "How does this effect me? And am I really at risk?"
Well the short answer is: Yes you are at risk. Why? Because over half of the internet, and maybe as much a three quarters (or 75%), might have been at risk of having their secure communications read.  Most small services like eRetailers or online service providers use OpenSSL to secure their sites. But even the big companies like Google, Yahoo, Facebook, and Twitter use OpenSSL and had to take steps to secure against this bug.  The real kicker about this bug is that it was introduced to the internet back in January of 2011, if the reports can be believed.  This means that for about 2 years, anyone that might have known about this bug could have been intercpting all of your secure online communications.  We do know that the NSA was exploiting this bug to spy on all of us.  But what we don't know is who else might have been exploiting it also.

So, what can you do about it? Well, the only real answer is to change your passwords on all affected sites and services.  Now, how do you know if a site was affected or not? Well, the best way is to check their website to see if they mention applying a patch for Heartbleed or reissuing the security certificates for their site. But really the easiest way is to use a tool like the one provided by LastPass.com to check each of the sites you use to see if you need to change your password or not (Click here to find out).

But doing this might seem like a monumental task, especially if you have a lot of sites.  Well, this is yet another reason for using a password manager, or password safe as sometimes termed, to store and manage your passwords.     

This article by  from CNET, entitled: "Beyond Heartbleed: Why you need a password manager", really provides great insight into how to go about cleaning up your accounts after a major internet event like this.  Even if you have been reluctant to try a password manager in the past, the shear effort of remembering all the passwords to each site you need to change can be daunting.  These tools help make that task a little easier.

So, what lessons should we take away from this event?  Well the first is to make sure that you change the passwords for all of you accounts once your service providers have patched their systems.  Then going forward, make sure you change your passwords on a regular basis.  For some of you, that might be every 90 days, as some security professionals suggest.  But for the rest of us, let's try to do better and try to change those passwords at least once a year!

Tuesday, February 4, 2014

Why worry online? You're safe right?

Like many IT professionals, I get questions all the time from friends and family about their computers or devices. I seem to be constantly giving advice and assistance on what they should buy, why their computer or device doesn't seem to be working properly, or how to fix a problem they are having.

All this is great and I truly love helping my friends and family when I can. But, like most of my techie friends, there is only so much time in the day and at some point being a free tech support becomes too much.  So, I thought I might write a couple things here to help answer some of these techie type questions and give a techie perspective on things.  Hopefully someone might find these useful and make both their digital and physical lives better in the process. 

Ok, to that point, the first topic I thought I'd share some thoughts on is being safe online.
First let me ask you a question, how safe do you consider yourself online? Is your version of safety like these two youngsters shown here?

Maybe you use multiple passwords for all your accounts, you try to stay away from shady websites, when viewing an email from an unknown sender you don't open attachments, and you run anti-virus software. Does that sum up your view on online security? Maybe you also have firewall software running too. All these things are good. Do you also have the thought that, "this is good enough, why would anyone want to hack into my accounts anyway?  I don't have anything important." 

That's one of the biggest farce's that we tell ourselves. The truth is that anyone and everyone who is online is a potential target. The question is, how temping of a target are you? The more important you become, the easier it is to "hack" into your accounts do to lax security on your part, or the more valuable the information is which is associated with your accounts then the higher the likelihood is that you will become the target of an attack attempt.

Attacks are not always just about gaining access to your financial information.  An attack could be to gain access to your account for purposes of gathering information about you or your contacts, they could target specific accounts in order to find out a very specific piece of information they could then use to access another of your accounts which contains more valuable information, say your email or your credit card.  This is called a Social Engineered Hacking.  In this case they are not cracking a password but circumventing the system by gaining access to your other less secured accounts to gain information like the last 4 digits of your credit card, your mailing zip code, or even answers to your security questions.  With this kind of information they could then reset your password on the account they want to access and then gain access to that account.  Once in, they can do whatever they want.  Delete information stored online, send malicious emails, deface websites in your name, post hate blogs, etc.

With weak passwords, hackers do not even need to go to these extreme methods to gain access to your email.  You might think that your email is safe because you don't have anything in it that is worth reading.  But the truth is that hackers don't care about your email.  They do want your email address in order to use it to send bulk spam out to all your contacts, as well as whomever else they want.  This is one way that spamming gets out of control and why it is so hard to catch spammers.

So what can you do?  Is all a lose?  Should you bury your proverbial head in the proverbial internet sand?  or maybe even go cold turkey and cut off the online addition all together?  While going cold turkey is probably the safest, it really isn't practical these days.  So the question really is what to do, and the answers really aren't all that hard.  Well, I say that, but the truth is that you can take some relatively simple steps to keep yourself relatively safe online.  But nothing will keep you 100 percent safe from digital threats as long technology is a part of your life.  Don't believe me, go do a little research on the Stuxnet virus (http://en.wikipedia.org/wiki/Stuxnet) and ask Iran how that worked out for them.

So what can you do to be safe?  Well here are a few simple things to do:
1) Have a unique 20+ character password for each of your sites or applications.  Anything below this is easily hacked.  I could bore you with the details, but trust me when I say this.  And those of you with the password of "Password123", just stop it, ok?

2) Store your password in a secure online password safe, like LastPass (http://www.LastPass.com).  No one can have a unique 20+ character password for every site or application and hope to possibly remember what each and every password is, so instead, remember a single password and let a password safe remember them for you.

3) Use a Sandbox tool like Sandboxie (http://www.Sandboxie.com) to browse the web in a more secure way.  Using something like this will wrap your browser in a sandbox and this will in turn keep any malicious code running from a website or attachment from accessing your computer and infecting it.  This offers much better protection then an antivirus which attempts to "clean up" the virus after the infection has already occurred.

4) Follow the Elmer Fudd approach to opening attachments, Be w'ery w'ery careful, we're huntin' w'iruses!  Remember that ANY attachment, even those from known contacts, could contain viruses or malicious code.  If at all possible, open all attachments in a secure browser or in a sandboxed environment.

5) Do not browse to any suspicious websites.  If something looks strange or you think you are being taken to a website that isn't where you expected to go, don't hang around and click on things.  The best thing is to close the page and open a new page in a known/familiar location, like (http://www.google.com).

6) Do not trust free or open public WiFi.  Feel free to use it to check the latest sports scores or traffic status, but never ever access your financial information over a free or open public WiFi.  These networks are very easily hacked and are a huge source for theives to steal your ID, passwords, or financial information.  Be careful and just assume that on these types of networks someone is always reading or watching every single thing you do.

7) Last but not least, please also remember that Email is NOT secure.  Do not send anything of a sensitive nature via email, EVER!  Email is always sent in pain text mode, meaning that anyone who intercepts that message can view the contents of that message.  Nothing that is sent via email should ever be considered private.  Emails are constantly being intercepted and read, and not just by the NSA.  So if you don't want unknown people reading your private stuff, then don't send it in an email.

So there are 7 simple things that you can do to be a little safer and more secure online, starting today.
Enjoy!