The discussion around the usual suspects of web application security (XSS, CSRF, injections, etc) hasn’t changed much in the last decade. Even high-profile website security incidents that get media attention often boil down to a clever application of one or more of these “basic” vulnerabilities. Part of the reason these techniques don’t seem to go out of style is a result of the speed at which the underlying technologies emerge. In other words, as technology changes, the vulnerabilities enabled by that technology also change. With the quick rise (and rapid acceptance) of HTML5 as the next generation markup language, we are sure to see some interesting new ways that web apps can be bent and broken or otherwise convinced to[…]
Many information security blogs, including this one, have discussed the recent data breach of gossip site Gawker and problems associated with leaked passwords. The story has demonstrated some of the risks associated with password storage. Gawker did store passwords using a form of encryption, but it was a weak algorithm and thus the encrypted data could be cracked. It’s important to remember that you should never simply rely on “encryption” to protect information – that’s sort of like say a bicycle is protected with a combination lock. Some locks are easier to open than others, and if the lock is attached to a weak cable or not properly looped through the frame of the bike, its strength doesn’t even matter. With[…]
As Peter touched on when relating his story about the Gawker password database compromise (in addition to numerous other mentions on this blog), maintaining secure passwords for all of your various online identities is not something to take lightly. In addition to secure passwords, you should also use passwords unique to each site you are visiting. You may not care if someone compromises the account you use to comment on Gizmodo, but if you also use that password for e-mail, banking, Facebook, or other sites you may value, you leave yourself open to a painful security breach. In a perfect world, websites would just use OpenID or other roaming credential, so that everyone would only have one secure password to[…]
I received the following email on Monday morning: You don’t know me. I’m nobody. My name is Steve. I came across a database dump from Gawker.com earlier this evening. It’s making its rounds around the internet. Besides just the code dump from gawker.com among other sites, it also contains email addresses and passwords for over 1.3 million accounts. I’m sending this email to the 200,000 or so people who’s passwords were included, in plain text, in this archive. I have your password. However, I have 0 interest in it. Obviously i’m anonymous so how can you trust me – you can’t. But trust me, if I had interest in your password, I wouldn’t be emailing you saying I have it. That’s just[…]
For a while, it looked like the crypto wars had been won. The victory in the crypto wars didn’t last long. Today, there are a slew of laws in place in various countries controlling the use of strong encryption.
A number of our employees are currently spending a fairly large amount of their time helping a customer with a task. In a perfect world, this task would be completely unnecessary. Suffice it to say that there is some maintenance that must be performed on a number of systems before the year is out, and they are having trouble getting responses from the system administrators who are responsible for the systems. When we perform assessments, we often ask our customers about whether they have a configuration management database (CMDB) or something similar. While CMDB systems may be useful for performing a physical inventory of your systems, that isn’t the real benefit. The real power of a CMDB comes in being[…]