Showing posts with label password. Show all posts
Showing posts with label password. Show all posts

Wednesday, August 6, 2014

Unique Passwords for Internet Accounts

With the widely publicized compromise of 1.2 billion user accounts from almost a half a million different websites, one very popular question is what can the average internet user do to protect themselves.

The common recommendations are straightforward:
  • Use long, strong, and complex passwords
  • Use different passwords for every website
  • Change your passwords often, at least every six months
  • Avoid storing sensitive information (passwords, social security numbers, or other identity information) online
These are the same, proactive recommendations that have been made for several years in response to password and credential breaches. However, historically users have been lax. For instance, among users directly affected by a large password attack, one survey found more than 1/3 of those users did not change their password at all. In 2013, the passwords “123456”, “12345678”, “password”, “qwerty”, and “abc123” continued to be the five most common passwords, just as they were in 2012 (see 2013's report here), even after many large, significant, and well publicized password thefts.

The challenge for users continues to be that secure practices are difficult to do, impact their productivity, and make useful resources harder to access anytime, anywhere. Users continue to make the tradeoff towards speed, productivity, ease of use, and universality — even as the risks and costs dramatically increase.

Ohanae believes that total cloud privacy protection is the solution to this epidemic. Although traditional password management is part of cloud privacy protection, it is not enough alone. Cloud privacy protection must include security of the password manager, so that it does not become a single point of failure, where all passwords can be compromised through it. Cloud privacy protection must include authentication that goes beyond a simple password, preferably by using multi-factor authentication to safeguard access to website credentials.Cloud privacy protection must safeguard data as well as credentials — enabling storage of sensitive, identity related data without risk of trickle-down account compromises if that data is accessed without authorization.

The Ohanae suite for Cloud Privacy Protection implements a password management function called Ohanae 1-Tap. Ohanae 1-Tap does not store passwords anywhere (on your device, on Ohanae’s servers, or in the cloud). Passwords are generated dynamically only when they are used, and generated by two factor authentication based on device and passphrase.

Ohanae’s Cloud Privacy Protection encrypts files stored in cloud storage providers — at creation on your device, during transmission across the Internet, and once stored in the cloud storage provider. The data is protected by strong, multi-factor authentication to dynamically generate decryption keys only on use — industrial strength technology to keep sensitive information in your files from the prying eyes of cyber criminals.

Finally, Ohanae knows that users have the need to securely share data with other collaborators, and supports secure transmission and use.

With Ohanae, it’s easy to establish unique, strong, lengthy passwords for every website, change them as often as you’d like, and have those passwords available on every device you use — whether desktop, laptop, or mobile. You can feel secure storing sensitive files online, and sharing them with others. And, in the unlikely event of a compromise, you have the confidence that the breach is limited — to just a single website, or a single cloud storage provider.

We can defeat the cybercriminals of the world and make epic password theft a news story of the past, and complete Cloud Privacy Protection is the way to do it! To get started, download Ohanae from http://www.ohanae.com today!

Wednesday, July 23, 2014

Two Factor Authentication Strength

Recent articles have suggested that password strength in some situations is not important. For instance, a recent Network World article asserted that the weakest and most well known password “123456” could have a place in an overall password strategy.

Another area where weak passwords are sometimes advocated is in combination with a two factor authentication (2FA) scheme. Two factor authentication combines two different pieces of information in order to establish access for a user. Typically, the two pieces come from two of the categories: something the user knows, something the user has, and something the user is. In most common, widely used schemes, the two factors are something the user knows (either a password or a PIN) and something the user has (a magnetic card, a secure token, or a specific device).

Adding a second factor certainly increases the security of a system. One could argue that you could decrease the first factor to offset that gain if the original system was secure enough. Taken to the extreme, if the second factor was stronger than the first, you could make the first trivially easy and still be better off. In that case, you would essentially be using a single factor system, just with the stronger factor.

Those are the keys to determining how much relaxation of one factor you can accommodate by adding a second factor: how strong is the second factor, how resilient is the system, and how independent are the two factors? How important is increasing the overall security of the system?

The classic two factor authentication system - a bank card and associated PIN works well. Both factors are strong. The card requires theft of a physical item to compromise it. The PIN (although only a 4-6 digit code) is usually strong because there is a lack of automated methodologies for attacking the PIN — it requires manually entering codes over and over at a banking machine. Furthermore, limitations on the number of wrong entries in a time period prevent effective brute forcing of the PIN. Systems are typically resilient — because there are not other attack modes beyond actual use of the card.

However, the card system can be compromised by poor choices. For instance, selecting trivial PINs like 1234, 0000, or other easily determined information makes it so that theft of the card is the only real attack required. Trivial PINs turn the two factor system in one factor, where possession of the card is the only block. Similarly, writing the PIN on the card so that the two factors are no longer independent (by compromising the card, you gain the PIN) also negates the benefits of the two factor system.

The final question is how important is increasing the overall security of the system. At Ohanae, we feel that passwords should always be strong, secure, and unique. If you need a password, then you want the best — whether it’s to secure less important websites, or as one piece of a multi-factor authentication scheme. Password compromise inevitably leads to information that can make secondary identity attacks easier and more successful. Your identity, accounts, and data integrity rest on preventing all attacks, and a weak password can be the proverbial weakest link that unravels the strongest chain of protection.

Ohanae’s cloud privacy protection solution gives users on all their devices the ability to quickly and easily use strong, secure, unique passwords on each website and application they use.

Monday, June 9, 2014

Singapore IDA Recommends Complex, Secure Passwords

Last week’s news about unauthorized password resets in the SingPass system (see the story here) reinforced the main cautions around passwords. Jacqueline Poh, Managing Director of Singapore’s Infocomm Development Authority recommended that all individuals use strong complex passwords with a variety of characters, including letters and numbers. The IDA went on to recommend other security best practices, including clearing browser caches after use, and changing passwords on a regular basis.

Ohanae software helps protect passwords against compromise. Ohanae users may select long passwords with upper case letters, lower case letters, numbers, and special characters and can be easily changed on a regular basis. Furthermore, Ohanae generates unique passwords for each site or application. Since Ohanae generates these passwords on use, they are never stored on any device, and users are spared the challenge of remembering many complex passwords. Finally, Ohanae implements browser cache and history clearing on laptop and desktop devices.

Ohanae’s Cloud Privacy Protection offering provides password security, but also provides secure encryption of files on device, in transit, and in the cloud as well as secure file sharing. This three-fold offering provides strong protection of both data and logins in the cloud, and is available now for Macintosh, Windows, Android and iOS.

Wednesday, May 21, 2014

Password Compromises of Large User Repositories

Today’s breaking news of the theft of eBay’s password and customer database highlights the danger implicit in the favored target of cyber criminals: large corporate repositories with millions of consumer records.

The eBay compromise poses particular business problems for eBay. Some of the highest costs for businesses with data compromise and theft include loss of customer trust and remediation of possible, unauthorized transactions. With eBay’s quick and informative disclosures, and thorough transaction audit, these are challenges that primarily affect eBay.

However, for customers in a breached database, the effects can extend beyond these corporate type of problem. The customer information in the database is a gateway for criminals to additional data. 

First, when passwords are contained in the compromised information, these passwords are often reused as credentials for other websites. A 2013 Ofcom study reported that 55% of users used a single password for the majority of web sites they accessed, only a slight improvement from 60% in 2011.  When passwords are stolen, and combined with other identifying information in the same database (such as user IDs or email addresses), a breach of a single website like eBay can be extended to breaches of a much wider universe of websites for affected consumers.

Second, the compromise of passwords often leads to the critical problem that an attacker can appear to be an authorized user. This lets the attacker gain access to the resources protected by the password. In the case of eBay, this is a user’s auction activity, but it varies depending on the compromised website. For example, a similar breach to a file sync and share website would result in attackers gaining access to user data files stored in the cloud.

Cloud privacy protection requires protecting both login credentials and the data stored in the cloud. Securing login credentials with unique, strong passwords limits exposure to the single compromised website. Securing cloud based data adds a second level of protection, even when the login credentials are compromised, to prevent data loss.