<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Security Musings &#187; users</title>
	<atom:link href="http://securitymusings.com/article/category/users/feed" rel="self" type="application/rss+xml" />
	<link>http://securitymusings.com</link>
	<description>Rants and raves from information security professionals</description>
	<lastBuildDate>Mon, 07 May 2012 21:31:18 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Poor Promotional Practices</title>
		<link>http://securitymusings.com/article/3129/poor-promotional-practices</link>
		<comments>http://securitymusings.com/article/3129/poor-promotional-practices#comments</comments>
		<pubDate>Fri, 16 Dec 2011 19:11:14 +0000</pubDate>
		<dc:creator>Tim Donaworth</dc:creator>
				<category><![CDATA[general]]></category>
		<category><![CDATA[rants]]></category>
		<category><![CDATA[users]]></category>

		<guid isPermaLink="false">http://securitymusings.com/?p=3129</guid>
		<description><![CDATA[Sometimes emails aren't always what they seem. Sometimes they promise great things. Sometimes they follow through with these, but most times they do not. Read on for an example of what not to do in promotional emails and learn how you can further protect yourself from email fraud. ]]></description>
			<content:encoded><![CDATA[<p>I’m not too ashamed of myself to whore out a few select email addresses for personal gain, or even promote a certain company by liking or retweeting something if it will benefit me more than the actions required, but I always keep a hesitant nature towards most of these promotions. I mean who doesn’t like free money?</p>
<p>I received an email the other day supposedly sponsored by a reputable programmer-related site. What it entailed was signing up for a big vendor’s developer program. If I did so, they would send me a $15 gift certificate to one of the major online retailers. I’m trying to keep all parties in this matter anonymous simply because I do not want to promote anything involved in this so-called promotion, and the actual parties involved are irrelevant. The email went something like this:</p>
<blockquote><p>&nbsp;</p>
<p>Happy Holidays Developers!</p>
<p>Get a $15 [online retailer] Gift Certificate by joining the [vendor] Developer Program (no charge!)</p>
<p>Thanks to your [programmer site] participation, here’s all you have to do!</p>
<p>1.	Visit The [hyperlink to vendor site] and register at no cost!</p>
<p>2.	[vendor] will send you a validation email: confirm your registration following the URL provided in the email which will prompt you to choose a password</p>
<p>3.	Once you have chosen a password, [vendor] will then send you a password reset email: forward the password reset email and the sign up email address used to [promotional site email]</p>
<p>4.	Once verified on our end, a gift certificate will be sent to you promptly after the program ends!</p>
<p>Hurry! This is limited to the first 600 respondents, one per person.</p>
<p>For full terms and conditions please visit [marketing link to promotional site]</p></blockquote>
<p>Step 3 is the one that caught my eye here. You want me to forward you an email sent to me that allows me to reset my password? By doing this I would essentially be sending the promoter an email that contained a link with an embedded token allowing them to authenticate as myself and then change my password, essentially gaining access to my account at this vendor site. Mind you, this isn&#8217;t exactly a critical account. But still these are very poor security practices.</p>
<p>So, what&#8217;s to be learned from this? Pay attention to what&#8217;s being asked of you. If it seems slightly out of the ordinary, it probably is. Inboxes are being filled with more and more spam these days, some make it through, and some even seem legitimate. It&#8217;s up to the users to educate themselves on how to detect and avoid these types of situations. In closing, I&#8217;ll leave you with a list of things you can do to help protect yourself.</p>
<ul>
<li>If it seems too good to be true, it probably is. So use common sense people!</li>
<li>Do not click on links in emails &#8211; period! Just because it says it&#8217;s a link to SiteA doesn&#8217;t mean it&#8217;s actually going there.</li>
<li>Enable spam controls on your email client &#8211; if you&#8217;re using Outlook, Thunderbird, or even Gmail&#8217;s web interface &#8211; they are all pretty good at detecting what may or may not be spam.</li>
<li>Use multiple emails or use gmail&#8217;s &#8216;+&#8217; email features or mailnull to help sort out those mailing list emails and let you know which emails are being distributed to others.</li>
<li>Do not load images by default or at all.</li>
<li>Do not enable scripting at all!</li>
</ul>
<p>These are just the tip of the iceberg, but you get the idea. Help protect yourself and you&#8217;ll be helping to protect all of us.</p>
<p>&nbsp;</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Poor+Promotional+Practices+http%3A%2F%2Fsecuritymusings.com%2F%3Fp%3D3129" title="Post to Twitter"><img class="nothumb" src="http://securitymusings.com/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter2.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://securitymusings.com/article/3129/poor-promotional-practices&amp;t=Poor+Promotional+Practices" title="Post to Facebook"><img class="nothumb" src="http://securitymusings.com/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook.png" alt="Post to Facebook" /></a></p></div>]]></content:encoded>
			<wfw:commentRss>http://securitymusings.com/article/3129/poor-promotional-practices/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Maximize Facebook Privacy</title>
		<link>http://securitymusings.com/article/1905/maximize-facebook-privacy-6</link>
		<comments>http://securitymusings.com/article/1905/maximize-facebook-privacy-6#comments</comments>
		<pubDate>Tue, 01 Jun 2010 16:44:11 +0000</pubDate>
		<dc:creator>Nick Staples</dc:creator>
				<category><![CDATA[privacy]]></category>
		<category><![CDATA[Tutorial Tuesday]]></category>
		<category><![CDATA[users]]></category>

		<guid isPermaLink="false">http://securitymusings.com/?p=1905</guid>
		<description><![CDATA[In celebration of Facebook&#8217;s recent privacy control revamp, I present a very informative tutorial video from the Electronic Frontier Foundation that gives a brief rundown of the changes, the highs, and the lows. This might also be something beneficial to share with friends or relatives on Facebook who may not be in-the-know about the increased [...]]]></description>
			<content:encoded><![CDATA[<p>In celebration of Facebook&#8217;s recent privacy control revamp, I present a very informative <a href="http://www.youtube.com/watch?v=TGkUA84ftYU">tutorial video</a> from the Electronic Frontier Foundation that gives a brief rundown of the changes, the highs, and the lows. This might also be something beneficial to share with friends or relatives on Facebook who may not be in-the-know about the increased focus on privacy control in social networking and social media.</p>
<p>Enjoy:<br />
<object width="480" height="385"><param name="movie" value="http://www.youtube.com/v/TGkUA84ftYU&#038;hl=en_US&#038;fs=1&#038;rel=0"></param><param name="allowFullScreen" value="true"></param><param name="allowscriptaccess" value="always"></param><embed src="http://www.youtube.com/v/TGkUA84ftYU&#038;hl=en_US&#038;fs=1&#038;rel=0" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="480" height="385"></embed></object></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Maximize+Facebook+Privacy+http%3A%2F%2Fsecuritymusings.com%2F%3Fp%3D1905" title="Post to Twitter"><img class="nothumb" src="http://securitymusings.com/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter2.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://securitymusings.com/article/1905/maximize-facebook-privacy-6&amp;t=Maximize+Facebook+Privacy" title="Post to Facebook"><img class="nothumb" src="http://securitymusings.com/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook.png" alt="Post to Facebook" /></a></p></div>]]></content:encoded>
			<wfw:commentRss>http://securitymusings.com/article/1905/maximize-facebook-privacy-6/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>On Password Breaches and Trends</title>
		<link>http://securitymusings.com/article/1665/on-password-breaches-and-trends</link>
		<comments>http://securitymusings.com/article/1665/on-password-breaches-and-trends#comments</comments>
		<pubDate>Fri, 29 Jan 2010 16:43:50 +0000</pubDate>
		<dc:creator>Nick Staples</dc:creator>
				<category><![CDATA[data theft]]></category>
		<category><![CDATA[passwords]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[users]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[password]]></category>

		<guid isPermaLink="false">http://securitymusings.com/?p=1665</guid>
		<description><![CDATA[Recently, Imperva released a study (pdf) of the passwords extracted from the December 2009 RockYou security breach that resulted in the compromise of over 32 million user accounts. This study examined some statistics of the passwords retrieved, including the number and variation of characters use to construct them. The results were pretty bad. Here are [...]]]></description>
			<content:encoded><![CDATA[<p>Recently, <a href="http://www.imperva.com/download.asp?id=239">Imperva released a study</a> (pdf) of the passwords extracted from the December 2009 <a href="http://www.techcrunch.com/2009/12/14/rockyou-hacked">RockYou security breach</a> that resulted in the compromise of over 32 million user accounts. This study examined some statistics of the passwords retrieved, including the number and variation of characters use to construct them. The results were pretty bad. Here are the highlights:</p>
<p>-30% of users had passwords made up of 6 characters or less. Most brute force attempts are moderately successful against short passwords.</p>
<p>-Over 50% of passwords were all lowercase, or all numbers. This is bad because the keyspace is reduced. Even a password that is longer than 6 characters is weakened if it has a small character set distribution.</p>
<p>On the surface, these two statistics aren&#8217;t a good look at all, especially considering the ease with which an attacker could successfully guess simple passwords.</p>
<p>Also, in many cases, a password breach may not just make a user&#8217;s account vulnerable on the breached site, but can also lead to their account being compromised on other sites as well (plenty of people use the same password on multiple sites).</p>
<p>However, there is an alternative way to interpret this data. Although there is no way to verify this, it could be the case that users are starting to give value to the importance of some accounts AND the security of the website associated with it. And those accounts that are of low significance (like a site they just sign up on to play a game) get simple, easy-to-remember passwords, while accounts of greater personal significance (banks, primary email, etc.) get the more robust passwords. Similarly, it could be the case that users think sites like RockYou are sketchy anyway, and thus more likely to get hacked than other more-serious sites.</p>
<p>So, in a way, the user could be protecting themselves from a site breach. I know I wouldn&#8217;t care if I had a RockYou account and the site got breached since I wouldn&#8217;t really use that same password anywhere else important. It may be annoying, but it is much better than knowing that my super-secret 28-character password is sitting on some stranger&#8217;s computer simply because somebody left the door open.</p>
<p>So if you think of this report from the perspective of users managing risks reasonably instead of users being victimized, it almost makes sense that 29,000 people had &#8217;123456&#8242; as a password.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=On+Password+Breaches+and+Trends+http%3A%2F%2Fsecuritymusings.com%2F%3Fp%3D1665" title="Post to Twitter"><img class="nothumb" src="http://securitymusings.com/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter2.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://securitymusings.com/article/1665/on-password-breaches-and-trends&amp;t=On+Password+Breaches+and+Trends" title="Post to Facebook"><img class="nothumb" src="http://securitymusings.com/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook.png" alt="Post to Facebook" /></a></p></div>]]></content:encoded>
			<wfw:commentRss>http://securitymusings.com/article/1665/on-password-breaches-and-trends/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Using Facebook Privacy Settings</title>
		<link>http://securitymusings.com/article/816/using-facebook-privacy-settings</link>
		<comments>http://securitymusings.com/article/816/using-facebook-privacy-settings#comments</comments>
		<pubDate>Wed, 11 Mar 2009 01:00:17 +0000</pubDate>
		<dc:creator>Mike Markiewicz</dc:creator>
				<category><![CDATA[privacy]]></category>
		<category><![CDATA[Tutorial Tuesday]]></category>
		<category><![CDATA[users]]></category>
		<category><![CDATA[Facebook]]></category>

		<guid isPermaLink="false">http://securitymusings.com/?p=816</guid>
		<description><![CDATA[A couple years ago, Facebook.com revealed just how much information is shared on social networking sites when they introduced news feeds to the home page and user profile pages. These feeds made users nervous perhaps because they had thought that their personal information was safe as long as it was not broadcast to everyone on [...]]]></description>
			<content:encoded><![CDATA[<p>A couple years ago, Facebook.com revealed just how much information is shared on social networking sites when they introduced news feeds to the home page and user profile pages. These feeds made users nervous perhaps because they had thought that their personal information was safe as long as it was not broadcast to everyone on their friend lists. In reality, it was a new way of distributing information that had always been available to them. Since then, Facebook has added a wide array of privacy options, yet we still find stories of people <a href="http://nfl.fanhouse.com/2009/03/09/eagles-fire-employee-after-he-calls-team-retarded-on-facebook/">being fired</a> because of something they said online.</p>
<p>How do you prevent this from happening to you? I guess one option could be to start removing Facebook friends until you are only connected to people that you completely trust, but then why use the site at all? You could instead make all of your not-so-close friends into “limited profile” friends who can only see certain parts of your information, but you will find that it is very difficult to separate your many friends into just two groups.<span> </span>There is another way, and that is what today’s tutorial is about.<br />
<span id="more-816"></span>
<ol>
<li>Click on “Friends” in the top menu bar.</li>
<li>Notice the “Make a New List” option on the left under your friend lists.<span> </span></li>
<li>Use this option to create groups for your friends (“Family,” “Best Friends,” “Acquaintances,” etc.)</li>
<li>Click “Everyone” at the top of your list of friends to display all of them.</li>
<li>For each friend, click the empty space by their name and picture to expand their box, click the little arrow next to “View Friends,” and choose a list to put them in.</li>
<li>If they don’t belong in any list, create a new one or consider removing them.</li>
</ol>
<p>Now that everyone is categorized, you can begin to set your privacy rules.</p>
<ol style="margin-left: 30px; margin-top: 5px; margin-bottom: 5px; line-height:100%">
<li>Hover over “Settings” in the top menu bar then click “Privacy Settings.”</li>
<li>Click “Profile.”</li>
<li>You will see a lot of drop-down menus. Each one gives you a few options including “Customize…”</li>
<li>If you do not like the other options, choose “Customize…” This is where you get to use your lists. You can decide to allow access to only some friends (specific people or lists), or you can decide to deny access to certain people.</li>
<li>Save your changes when you’re finished and continue the process with “Search,” “News Feed and Wall,” and “Applications” under “Privacy Settings.”</li>
</ol>
<p>You can set privacy options for individual applications by clicking “Application Settings” under “Settings.” Then, click “Edit Settings” for any application. In the popup, choose the “Profile” tab. Use the drop-down list to choose which friends can see that application.</p>
<p>You might need to set aside some time to do everything, especially those of you who have hundreds and thousands of friends.  It’s worth it for the sake of privacy and security, and once you have your lists set up, you will only need to make tweaks here and there as your relationships evolve. Don’t lose your job or identity because you added everyone you ever met as a friend. Facebook has added a lot of tools for keeping your information private. Be smart and use them.</p>
<p><em>Each Tuesday, Security Musings features a topic to help educate our readers about security. For more information about Gemini Security Solutions’ security education capabilities, <a href="http://geminisecurity.com/company/contact/">contact us</a>!</em></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Using+Facebook+Privacy+Settings+http%3A%2F%2Fsecuritymusings.com%2F%3Fp%3D816" title="Post to Twitter"><img class="nothumb" src="http://securitymusings.com/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter2.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://securitymusings.com/article/816/using-facebook-privacy-settings&amp;t=Using+Facebook+Privacy+Settings" title="Post to Facebook"><img class="nothumb" src="http://securitymusings.com/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook.png" alt="Post to Facebook" /></a></p></div>]]></content:encoded>
			<wfw:commentRss>http://securitymusings.com/article/816/using-facebook-privacy-settings/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Security vs Usability (again)</title>
		<link>http://securitymusings.com/article/556/security-vs-usability-again</link>
		<comments>http://securitymusings.com/article/556/security-vs-usability-again#comments</comments>
		<pubDate>Wed, 29 Oct 2008 15:31:12 +0000</pubDate>
		<dc:creator>Walt Turnes</dc:creator>
				<category><![CDATA[software]]></category>
		<category><![CDATA[users]]></category>
		<category><![CDATA[Vista]]></category>

		<guid isPermaLink="false">http://securitymusings.com/?p=556</guid>
		<description><![CDATA[This from BetaNews (link opens in new window): Giving a nod to developers who&#8217;ve apparently given a lot of feedback, as well as &#8220;certain commercials,&#8221; Microsoft&#8217;s platform chief Steven Sinofsky acknowledged that perhaps User Account Control in Windows Vista may have been&#8230;a little annoying. In turn, Windows 7 has additional UAC settings. Fortunately for my [...]]]></description>
			<content:encoded><![CDATA[<p>This from <a title="Vista UAC" href="http://www.betanews.com/article/PDC_2008_Sinofsky_acknowledges_Vista_UAC_is_a_problem/1225211844" target="_blank">BetaNews</a> (link opens in new window):</p>
<blockquote><p><strong>Giving a nod to developers who&#8217;ve apparently given a lot of feedback, as well as &#8220;certain commercials,&#8221; Microsoft&#8217;s platform chief Steven Sinofsky acknowledged that perhaps User Account Control in Windows Vista may have been&#8230;a little annoying. In turn, Windows 7 has additional UAC settings.</strong></p></blockquote>
<p>Fortunately for my own sanity, I haven&#8217;t had to jump through any hoops with UAC to get my code working, but that&#8217;s mostly because I deal with server-side code now.  While the developer perspective is interesting, it&#8217;s really the user perspective that&#8217;s important to me, as someone who is concerned with the overall state of desktop security.  Developers are not only in the minority, we also don&#8217;t have the option of just turning UAC off on client machines&#8230;we have to deal with it or simply not write software for Vista.  In the current incarnation of Vista, however, UAC is so obtrusive that many users opt to disable it entirely to get the warnings to stop.</p>
<blockquote><p>Sinofsky said that with UAC, Microsoft had what he described as &#8220;the best intentions&#8221; in mind. But its attention to informing the user about what&#8217;s going on and getting consent &#8220;possibly went too far.&#8221;<br />
&#8230;<br />
For now, in the Pre-Beta version of Windows 7, there are now four settings for configuring how intrusive UAC will be: <strong>Never notify me, Only notify me when programs try to make changes, Always notify, and Notify and wait for my approval.</strong></p></blockquote>
<p>I think this is the right approach.  UAC doesn&#8217;t really bother me too much as an end user, but then again, I know what it means and what it&#8217;s actually doing.  I think that Microsoft took a big step in the right direction security-wise with UAC, but those pop up windows can be a real turn-off.  I&#8217;m glad to see that rather than abandoning the model and starting over from scratch, they&#8217;re trying to make the &#8220;security vs. usability&#8221; tradeoff for users less of an all-or-nothing proposition.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Security+vs+Usability+%28again%29+http%3A%2F%2Fsecuritymusings.com%2F%3Fp%3D556" title="Post to Twitter"><img class="nothumb" src="http://securitymusings.com/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter2.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://securitymusings.com/article/556/security-vs-usability-again&amp;t=Security+vs+Usability+%28again%29" title="Post to Facebook"><img class="nothumb" src="http://securitymusings.com/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook.png" alt="Post to Facebook" /></a></p></div>]]></content:encoded>
			<wfw:commentRss>http://securitymusings.com/article/556/security-vs-usability-again/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Economic Uncertainty Affects Security Too</title>
		<link>http://securitymusings.com/article/510/economic-uncertainty-affects-security-too</link>
		<comments>http://securitymusings.com/article/510/economic-uncertainty-affects-security-too#comments</comments>
		<pubDate>Fri, 17 Oct 2008 23:27:46 +0000</pubDate>
		<dc:creator>Nick Staples</dc:creator>
				<category><![CDATA[users]]></category>

		<guid isPermaLink="false">http://securitymusings.com/?p=510</guid>
		<description><![CDATA[An article from Dark Reading touched on some very valid points with regards to the security at financial institutions. According to the article: Penetration testers who work with bank clients say the fragile state of the banking community is making it easier for them to dupe understandably anxious bank employees. Bank employees are overly eager [...]]]></description>
			<content:encoded><![CDATA[<p>An <a href="http://www.darkreading.com/document.asp?doc_id=165537">article</a> from Dark Reading touched on some very valid points with regards to the security at financial institutions. According to the article:</p>
<blockquote><p>Penetration testers who work with bank clients say the fragile state of the banking community is making it easier for them to dupe understandably anxious bank employees. Bank employees are overly eager or easily coerced into cooperating with “auditors,” or into clicking on links purportedly from the bank about its own financial welfare.</p></blockquote>
<p>Even though this is very bad from a security standpoint, it seems like a natural human response. However, if someone is able to walk into a bank merely posing as an auditor and without having their credentials checked or challenged, it&#8217;s possible for them to make off with a lot of sensitive information.</p>
<p>This type of behavior isn’t limited to just bank employees. Economy-induced anxiety can also affect the judgment of regular users. The most successful phishing attacks prey on a user&#8217;s familiarity or interest in the subject presented as bait. So a phishing email claiming to request important information from a bank customer might be more likely to succeed when the economy and specific financial institutions are in a state of flux.</p>
<p>In fact, it would be wise for both bank employees and bank customers to be MORE cautious during times of economic uncertainty, as attackers are notorious for taking advantage of such situations. It just goes to show&#8211; when it comes to security, we can&#8217;t afford to be careless.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Economic+Uncertainty+Affects+Security+Too+http%3A%2F%2Fsecuritymusings.com%2F%3Fp%3D510" title="Post to Twitter"><img class="nothumb" src="http://securitymusings.com/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter2.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://securitymusings.com/article/510/economic-uncertainty-affects-security-too&amp;t=Economic+Uncertainty+Affects+Security+Too" title="Post to Facebook"><img class="nothumb" src="http://securitymusings.com/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook.png" alt="Post to Facebook" /></a></p></div>]]></content:encoded>
			<wfw:commentRss>http://securitymusings.com/article/510/economic-uncertainty-affects-security-too/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Time to Re-Think CAPTCHA?</title>
		<link>http://securitymusings.com/article/480/time-to-re-think-captcha</link>
		<comments>http://securitymusings.com/article/480/time-to-re-think-captcha#comments</comments>
		<pubDate>Fri, 03 Oct 2008 19:15:42 +0000</pubDate>
		<dc:creator>Mike Markiewicz</dc:creator>
				<category><![CDATA[users]]></category>

		<guid isPermaLink="false">http://securitymusings.com/?p=480</guid>
		<description><![CDATA[This week, reports have surfaced that spammer activity is increasing on Microsoft and Google sites that employ CAPTCHA. CAPTCHA is a method for distinguishing between human users and programs used to automatically enter information. Those who would like to create large amounts of e-mail accounts or efficiently add SPAM content to blog comments or message boards [...]]]></description>
			<content:encoded><![CDATA[<p>This week, reports have surfaced that spammer activity is increasing on <a href="http://securitylabs.websense.com/content/Blogs/3063.aspx">Microsoft</a> and <a href="http://agha.st/2008/10/xrumer-50a---google-captcha-cracked.php">Google</a> sites that employ CAPTCHA. <a href="http://en.wikipedia.org/wiki/CAPTCHA">CAPTCHA</a> is a method for distinguishing between human users and programs used to automatically enter information. Those who would like to create large amounts of e-mail accounts or efficiently add SPAM content to blog comments or message boards are constantly scheming new methods for circumventing CAPTCHAs.  Meanwhile, web site administrators continue to invent creative techniques for detecting computers masquerading as human.</p>
<p>As the battle continues, though, it’s humans who are having more trouble reading CAPTCHAs. Speaking for myself, I find that many CAPTCHA challenges are not very easy to decipher. If it is case-sensitive, for example, there are many capital letters that can be mistaken for lower-case if distorted the right way, and there is no feedback that allows me to correct myself if I can’t read it.</p>
<p>Now, I’m not saying that I have ever been completely fooled by a CAPTCHA to the point that I wasn’t able to create an account or post a comment.  Humans will eventually get through, but if users find them difficult, and they no longer effectively prevent spamming, maybe more thought needs to be applied to the problem. Here are some suggestions I have found for methods to weed out spamming programs.<span id="more-480"></span></p>
<ul>
<li> <strong>Pick the cats – </strong>Given a set of pictures, choose the ones that are of cats. Another variation has the user choose the person judged hottest on HOTorNOT. This might be a little more work than someone would like to do especially if there are twenty images to judge. Also, the authors of the Google CAPTCHA crack claim to be able to crack these as well.</li>
<li> <strong>Solve the math problem – </strong>Examples of these are normally complex-looking problems that, upon further inspection, are not so difficult. Unfortunately, many people don’t remember what a derivative is or what sin(-π/2) equals. Another problem is that a lot of these problems come out to some simple answer like one or zero, and spammers might eventually figure that out.</li>
<li> <strong>Decipher the hieroglyphics – </strong>Another method uses an image with symbols that can be deciphered using the key at the bottom. I think this is the best of the ones I’ve mentioned so far. It might slow you down some, but it’s not too hard. I can’t say it’s perfect though because I think a determined spammer could develop an automated solution to these.</li>
</ul>
<p>Before today, I had not put much thought into the subject, but now that I have pondered it some, I have an idea. Have users follow instructions or answer a question in which each word has been randomly modified by adding, removing, or transposing letters. People have to read through typos every day. Computers would be fooled, and the time lost to solving the problem would be minor.</p>
<p>Sgo, waht do oyu tink? Ad a commnet if yuo ave ayn thouhgts or idetas.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Time+to+Re-Think+CAPTCHA%3F+http%3A%2F%2Fsecuritymusings.com%2F%3Fp%3D480" title="Post to Twitter"><img class="nothumb" src="http://securitymusings.com/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter2.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://securitymusings.com/article/480/time-to-re-think-captcha&amp;t=Time+to+Re-Think+CAPTCHA%3F" title="Post to Facebook"><img class="nothumb" src="http://securitymusings.com/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook.png" alt="Post to Facebook" /></a></p></div>]]></content:encoded>
			<wfw:commentRss>http://securitymusings.com/article/480/time-to-re-think-captcha/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Internet Code of Conduct</title>
		<link>http://securitymusings.com/article/409/internet-code-of-conduct</link>
		<comments>http://securitymusings.com/article/409/internet-code-of-conduct#comments</comments>
		<pubDate>Fri, 22 Aug 2008 03:37:44 +0000</pubDate>
		<dc:creator>Nick Staples</dc:creator>
				<category><![CDATA[data protection]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[regulations]]></category>
		<category><![CDATA[standards]]></category>
		<category><![CDATA[users]]></category>

		<guid isPermaLink="false">http://securitymusings.com/?p=409</guid>
		<description><![CDATA[In 2007 a handful of companies (including Google, Microsoft, and Yahoo) decided to draft a set of guidelines influencing the behavior of online businesses when it comes to the subject of policies and regulations dealing with human rights. It was to be a kind of unofficial voluntary code of conduct initiative thing. According to this [...]]]></description>
			<content:encoded><![CDATA[<p>In 2007 a handful of companies (including Google, Microsoft, and Yahoo) decided to draft a set of guidelines influencing the behavior of online businesses when it comes to the subject of policies and regulations dealing with human rights. It was to be a kind of unofficial voluntary code of conduct initiative thing.</p>
<p>According to this letter(<a href="http://ycorpblog.com/files/yahoocodeletter.pdf">pdf</a>) from Yahoo to Senators Durbin and Coburn:</p>
<blockquote><p>Principles on Freedom of Expression and Privacy [...] provide direction and guidance to the ICT industry and its stakeholders in protecting and advancing the enjoyment of freedom of expression and privacy globally. The Principles describe key commitments in the following areas: Freedom of Expression; Privacy; Responsible Company Decision Making; Multi-Stakeholder Collaboration; Governance, Accountability &amp; Transparency</p></blockquote>
<p>Along with censorship and freedom of speech, the idea was also to provide general requirements for privacy. The idea also calls for a way to determine if a company is compliant with the code and a way to hold companies accountable if they violate it.</p>
<p>This is important because it shows that some of the most relevant internet-based companies are taking the rights of their users seriously. So seriously, in fact, that they are willing to sponsor a set of guidelines that help other companies protect THEIR user&#8217;s rights as well. If more companies get on board, this could be a step in the right direction in helping to strengthen the trust between service provider and user.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Internet+Code+of+Conduct+http%3A%2F%2Fsecuritymusings.com%2F%3Fp%3D409" title="Post to Twitter"><img class="nothumb" src="http://securitymusings.com/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter2.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://securitymusings.com/article/409/internet-code-of-conduct&amp;t=Internet+Code+of+Conduct" title="Post to Facebook"><img class="nothumb" src="http://securitymusings.com/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook.png" alt="Post to Facebook" /></a></p></div>]]></content:encoded>
			<wfw:commentRss>http://securitymusings.com/article/409/internet-code-of-conduct/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Train Your Users To Think Like The Mafia</title>
		<link>http://securitymusings.com/article/332/train-your-users-to-think-like-the-mafia</link>
		<comments>http://securitymusings.com/article/332/train-your-users-to-think-like-the-mafia#comments</comments>
		<pubDate>Wed, 09 Jul 2008 10:11:07 +0000</pubDate>
		<dc:creator>Anil Polat</dc:creator>
				<category><![CDATA[users]]></category>

		<guid isPermaLink="false">http://securitymusings.com/article/332/train-your-users-to-think-like-the-mafia</guid>
		<description><![CDATA[Smart security people learn from their adversary’s tactics, not shun them. Despite modern technology, broad operations, and publicity, the Mafia (particularly Italian mob) continues to survive. While the crimes they commit are deplorable, the security of the organization works using tried and true methods. Here are some you can teach your employees and enforce without [...]]]></description>
			<content:encoded><![CDATA[<p>
<img class="alignright" title="Godfather" src="http://upload.wikimedia.org/wikipedia/en/thumb/2/21/Godfather15_flip.jpg/175px-Godfather15_flip.jpg" alt="" width="175" height="240" align="right" /><br />
Smart security people learn from their adversary’s tactics, not shun them. Despite modern technology, broad operations, and publicity, the Mafia (particularly Italian mob) continues to survive. While the crimes they commit are deplorable, the security of the organization works using tried and true methods.<br />
<br />
Here are some you can teach your employees and enforce without having a baseball bat.</p>
<ul>
<li><strong>“Don’t Trust Nobody”</strong> – A good place to start; employees should never give any company information to anyone except the people they’re told to. Social engineering, spoofed emails, and enticing links all apply. Your firewalls should allow <em>what you tell them to allow</em> and nothing else. Start by having it lock down everything and work from there. Give your users the least amount of privileges they need to do their work and log as much as you can.</li>
</ul>
<ul>
<li><strong>“Talk to Me, Directly”</strong> – An email from some executive you’ve never heard of, being intimidated by someone in HR who wants your <span class="caps">SSN</span> (which they should already have), and any other strange requests should be verified. Employees should do directly to their immediate supervisor when in doubt. Unencrypted emails containing important information shouldn’t be sent – if possible get up and relay the message in person, refuse to send documents if they can’t be encrypted and signed with a digital signature (non-repudiation).</li>
</ul>
<ul>
<li><strong>“Keep Outsiders Out”</strong> – All business partner connections, 3rd party maintenance, and external developers should have an independent security assessment performed of them <em>by security experts</em>. Create separate network segments, monitor maintenance and hardware changes,  and always escort visitors on your premises. Smaller companies, make sure to lock the doors to the office and secure any network closets and servers.</li>
</ul>
<ul>
<li><strong>“Be Respectful”</strong> – Too often in mob movies we see some underling getting picked on by his superiors. The result is usually “ratting out to the Feds”, equivalent to an employee changing jobs to a competitor or leaking proprietary information. Treating your employees poorly reduces the overall security of an organization since it undermines loyalty. As we learned in “A Bronx Tale” it is better to be loved than feared.</li>
</ul>
<ul>
<li><strong>Use Your Head Instead of A Notepad</strong> – Mob guys never write anything down for fear of leaving behind evidence. Users should be trained never to write down passwords, leave company documents out on their desks, or store unencrypted sensitive files on unprotected devices.</li>
</ul>
<p>
Security professionals and auditors should remember to learn from tactics and be cautious with methods. Make sure you have, in writing, the scope of any assessment/audit and make sure that the tools and techniques you use are OK with the company in question or <em>you</em> might get whacked. A good strategy with questionable tactics may make <strong>you</strong> the criminal.<br />
<br />
What are some of the tricks you’ve learned from the bad guys?</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Train+Your+Users+To+Think+Like+The+Mafia+http%3A%2F%2Fsecuritymusings.com%2F%3Fp%3D332" title="Post to Twitter"><img class="nothumb" src="http://securitymusings.com/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter2.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://securitymusings.com/article/332/train-your-users-to-think-like-the-mafia&amp;t=Train+Your+Users+To+Think+Like+The+Mafia" title="Post to Facebook"><img class="nothumb" src="http://securitymusings.com/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook.png" alt="Post to Facebook" /></a></p></div>]]></content:encoded>
			<wfw:commentRss>http://securitymusings.com/article/332/train-your-users-to-think-like-the-mafia/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Blame IT!</title>
		<link>http://securitymusings.com/article/328/blame-it</link>
		<comments>http://securitymusings.com/article/328/blame-it#comments</comments>
		<pubDate>Wed, 18 Jun 2008 01:32:34 +0000</pubDate>
		<dc:creator>Peter Hesse</dc:creator>
				<category><![CDATA[users]]></category>

		<guid isPermaLink="false">http://securitymusings.com/article/328/blame-it</guid>
		<description><![CDATA[We&#8217;ve all heard about the stories involving EIBKAC such as using the CD-ROM drive as a coffee mug holder, and erasing the C:\Windows folder to free up space on your hard drive. InfoWorld has an informative article which turns these stories on their head, and provides stories about stupid IT administrator actions. The thing that [...]]]></description>
			<content:encoded><![CDATA[<p>We&#8217;ve all heard about the stories involving <acronym title="Error is between keyboard and chair">EIBKAC</acronym> such as using the <span class="caps">CD-ROM</span> drive as a coffee mug holder, and erasing the C:\Windows folder to free up space on your hard drive.  InfoWorld has <a href="http://www.infoworld.com/archives/emailPrint.jsp?R=printThis&#38;A=/article/08/06/16/25FE-stupid-users-part-3-admins_1.html">an informative article</a> which turns these stories on their head, and provides stories about stupid IT administrator actions.</p>
<p>The thing that struck me is that out of the six items they highlighted, four of them were directly security (or insecurity) related, and a fifth was related to disaster recovery, which is also a security concern.</p>
<ul>
<li>Preconfiguring PCs with stone-age malware</li>
<ul>
<li>Sending computers out from the factory with a virus circa 1994 which the built-in antivirus couldn&#8217;t repair</li>
</ul>
<li>Oh, you wanted to recover those backups?</li>
<ul>
<li>An entire issue of BusinessWeek was lost when a hard drive crashed</li>
</ul>
<li>Soup of the day: Social Security numbers</li>
<ul>
<li>A school&#8217;s database of folks to send the weekly cafeteria menu into was completely unprotected and contained SSNs</li>
</ul>
<li>The tool and the toolbar</li>
<ul>
<li>The Alexa toolbar was used to crawl and cache sensitive parts of a company website</li>
</ul>
<li>Paging Dr. Data Breach, please come to the IT morgue</li>
<ul>
<li>Company took down firewalls to ease (sensitive) data migration, and then inexplicably never turned them back on</li>
</ul>
</ul>
<p>Next time you blame users for lax security, remember that the IT staff can be brain-dead as well.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Blame+IT%21+http%3A%2F%2Fsecuritymusings.com%2F%3Fp%3D328" title="Post to Twitter"><img class="nothumb" src="http://securitymusings.com/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter2.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://securitymusings.com/article/328/blame-it&amp;t=Blame+IT%21" title="Post to Facebook"><img class="nothumb" src="http://securitymusings.com/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook.png" alt="Post to Facebook" /></a></p></div>]]></content:encoded>
			<wfw:commentRss>http://securitymusings.com/article/328/blame-it/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

