passwords


Don't let them paste passwords...
2fa

Don't let them paste passwords...

After months of tweets, emails & articles from eminent figures like Troy Hunt & the NCSC, it's about time I weighed in on the debate surrounding sites which disable a user's ability to paste passwords. The general consensus amongst many experts, including those mentioned above, is that disabling paste on password fields reduces security; the NCSC went one step further, calling it "completely pointless" and "damaging". So without further ado, allow me to explain why I believe disabling pas
PwnPhone: Default passwords allow covert surveillance.
snom

PwnPhone: Default passwords allow covert surveillance.

A few weeks ago, I was asked to observe an installation of several wireless access points & VoIP phones, with a view to making recommendations on how best to improve security while maintaining ease of deployment. It didn't take long for several trends to appear; chief amongst which was the use of We'll just use defaults, for now. That password will do, for now. Of course, as soon as the device burst into life, it's on to the next one. At which point, "now" becomes a distant memory, alo
Roboform Security Revisited: Lies, Deception & Misnomers.
aes

Roboform Security Revisited: Lies, Deception & Misnomers.

You may recall, I recently published an article entitled "How secure is Roboform: The 5 Minute Challenge". Well, 6 months have passed and although there's been no official public response from Siber Systems, they have made a number of comments to journalists and customers by email/Facebook and support tickets; during which I've been labelled as "misinformed", "unpleasant" and "sarcastic". There were no bugs in the first place. Roboform on Facebook Hmm. They edited the post.
Password Managers: Facts, Fallacies & FUD
1password

Password Managers: Facts, Fallacies & FUD

Ah, passwords. The thought of choosing, remembering and inevitably resetting them is enough to make your blood boil. As a fundamental part of our digital lives and despite several reports claiming they're dead, our dependence on them shows little sign of slowing. A password manager is a great way to virtually eliminate the stress & hassle associated with passwords; itself sufficient reason to give them a whirl. Pick a good one though, and you'll almost certainly be safer too. What do t
hacked

The difference between two-factor and two-step authentication.

No lengthy article this time folks, just a flow diagram to demonstrate the differences between two-factor authentication and two-step verification. (full size) Why isn't an OTP via SMS a 2nd factor? At first glance, the mobile phone appears to be "something we have" (one of 3 factors necessary to be multi-factor), but that's not quite true. The device itself isn't key to successfully authenticating, but rather the OTP delivered to it. If it were truly a 2nd factor, it would be impos
decryption

Virgin Media: You're only as secure as your weakest link.

Avid followers will know, I've long been an advocate of password managers... specifically 1Password. So much so, I'm often criticised for treating it as a panacea. With that in mind, it's about time I outlined another risk which isn't immediately obvious; one which allows me access to almost any site you use and renders your long, unique & immensely-strong password redundant. I am, of course, referring to the security of your email provider. Preface On August 27th, I received a tweet
banking

cyberstreetwise.com - Really bad #infosec advice.

Be Cyber Streetwise is a cross-government campaign, funded by the National Cyber Security Programme, and delivered in partnership with the private and voluntary sectors. The campaign is led by the Home Office, working closely with the Department for Business, Innovation and Skills and the Cabinet Office. On January 13th 2014, I read an article on the BBC website about a new government initiative on cyber security called cyberstreetwise.com. With the above description in mind, I had a qui
cashplus

CashPlus: "It is secure" - Ooooh no it isn't.

As part of a wider research project, I joined CashPlus in June (18th to be precise), which is purportedly... better than a business bank account So I paid the £29.99 annual membership fee and waited for the card to arrive. Less than a week later, the card arrived and I headed over to MyCashPlus.co.uk to register & activate the card.  For those of you that don't follow me... I use AgileBits' 1Password to generate and manage my passwords.  If you're still trying to think up and remember pass
1password

Forgot your password? You're doing it wrong.

Have you ever struggled to remember a username or password?  Join the club. Wouldn't it be great if you could log in to every site using the same password, without compromising your security?  Now you can! Introducing AgileBits 1Password, the gold standard in decentralized identity & password management for Windows, Mac, iPhone, iPad, Android and unofficially, Linux. So, what's it do? In short, it removes all the hassle from any sign in/sign up process. Next time you're scratching
acl

MyDish.co.uk Security - Missing a vital ingredient?

Update as of 15/03/13: I have received a number of emails asking for further comments on the situation @ MyDish. I firmly believe that every effort is being made to rectify the issues I've identified - and the insinuation that Carol or the team at MyDish have ignored the problem is entirely without merit.  Beyond that, I'm not prepared to discuss the matter any further at this stage.  If there are any updates, I will update this post accordingly. MyDish.co.uk is the brainchild of Carol Sav
companies house

Companies House Security Review - Part 2

Update(s): 18/Dec/2012 - One SSL bug now fixed (might want to put security testing out to tender next time!) - but still a few to go.  Directory traversal still possible... hint encode/escape or strip, don't add slashes!  Significant improvements have been made to the SSL implementation - now scoring a healthy Grade A @ Qualys SSL Labs.  At least progress is being made...  can't fault them for that. 17/Dec/2012 - WebCheck now uses cookies - but still not secure!  At this point, I'm not sure wh