We are working with a security policy that treats two passwords of equivalent strength: 8 character password with two character sets represented (pick two of upper/lower/number/symbol) 6 character password with three character sets represented (pick three of upper/lower/number/symbol) The question arises, how equivalent (or not) are they? Well, it’s time to do some math. Total Possible Passwords One way to measure password strength is in the total number of passwords that one might be able to generate that meet that criteria. More would be better. There are 26 uppercase, 26 lowercase, 10 digit, and 33 ASCII-printable symbols available on the average keyboard (totaling 95 options). If we simply asked how many possible 6 character passwords are there, you can multiply 95 for[…]
An attack on the South Carolina Department of Revenue exposed 3.6 million social security numbers, and about 387,000 credit and debit card numbers of South Carolina residents. Data breaches like this are so common, they are barely newsworthy… and we certainly try not to cover every single data breach event on this blog. However, today’s followup to the story is what made it interesting. Governor Nikki Haley went on the record in a press conference trying to defend their lack of good practices. I’ve embedded the video below and hopefully it will start at the good part, 12:43 into the video: This is a really good example of sending the wrong kind of message. I understand her desire to defend[…]
Yesterday, this story on Wired was making the rounds: How a Google Headhunter’s E-mail Unraveled a Massive Net Security Hole. Sure, the title is probably hyperbole, but it is an interesting story. At a high level, mathematician Zach Harris noticed that emails from Google – and from several other prominent domains including eBay, PayPal, Yahoo, Amazon, etc. – could be spoofed. Anyone who has ever run telnet to port 25 and sent an email from santaclaus@northpole.net or billgates@microsoft.com knows that email has always been pretty easy to spoof. Given the rise in unsolicited emails also known as spam, something had to be done. In 2006, a working group was founded to try and create a standard that would make email harder to[…]
Data leaks in very interesting ways. The other night I was watching one of the political conventions, and the camera crew of the station I was watching loved to cut away from the speaker to catch glimpses of the crowd reactions. When I saw this image, I thanked %deity% for my TiVo, paused, and rewound a bit. Then, I took a picture of the TV with my cellphone. Sure enough, this woman – Edith Byrd – is proudly showing the camera her Medicare card. And, the broadcaster is sending out a full 1080p high definition signal, meaning that I could read every detail of the woman’s card. (It’s far more readable on my TV than in this picture.) I see[…]
It’s a little embarrassing to admit, but it seems that the mistakes of one person globally syndicated columnist have led to a rapid increase in the acceptance and use of two-factor authentication technologies for authentication. Within the last week, I have set up both my Dropbox account and this very blog with two-factor authentication. Mat Honan’s sordid tale did a lot to raise awareness of how passwords are imperfect as an authentication mechanism, as have the many password breaches that have occurred over the years. Most interesting, though, is how Google created and freely released Google Authenticator as an open source application and how quickly organizations have begun to embrace it. While I’ve traditionally been a PKI guy (I know,[…]
We’re located in the northern Virginia area – where Friday night brought a derecho which is basically a hurricane on land. Unfortunately, our county lost 911 service, and 3 days later, it’s still not quite back up. The 911 service is run by Verizon, which said that both primary and backup power was lost. Amazon Web Services lost Netflix, Foursquare, Pinterest, and other sites. So – assuming that these services were in a traditional data center, what happened? These buildings are supposed to have backup generators – why didn’t they kick in? Did they not test the generators, or the ATS (automatic transfer switch)? People pay data centers for continuous power – and most offer 5 9s of power (~5[…]