White Collar Handyman
In-Home and In-Office Technology Concierge Services
Lessons & Tutoring • Repair • Troubleshooting • Upgrades & Installation
Fast Response • Reasonable Rates • In Your Home or Office • Same Day Service Available
(781) 989-2373
Hey! We've moved to a new URL to better reflect who we are and what we do! Please visit Rob Falk Technology Concierge Services at http://robfalk.net and update your bookmarks.
Showing posts with label Passwords. Show all posts
Showing posts with label Passwords. Show all posts

Monday, November 23, 2015

Safer Computers, Tablets, and Phones in Minutes

From time to time, I speak at community centers and social groups on easy and inexpensive ways to tighten up security on electronic devices. It's a 45 minute session that is both entertaining, informative and immediately useful.

I cover:

  • Password Managers
  • using HTTPS
  • OpenDNS & crowd sourced trusted sites
  • 2 Factor Authentication
  • Virtual Private Networks
  • Finding lost devices
  • Hard drive encryption
  • Phishing
  • Scams
  • Malware
Here is a link to the resources I discuss in the body of the talk.

If you think your club, group or community center might enjoy this talk, please send me an email.

Monday, May 18, 2015

Improve your iPhone Security by more than 1 Million Percent?

I like using the Simple Passcode option on my iPhone, but I've always been kind of bugged by the idea that there are only 10,000 possible passwords under that scheme. Since it's always 4 numbers, lots of people tend to use a month/day combination which makes guessing a fairly easy task for many people. Is your first digit 0 or 1? Do your 3rd and 4th digits add up to no more than 31? Is your combination your birth year? Last 4 of your phone number?

If you would like a longer simpler password, here's a cool and easy trick I just learned:

  1. Open Settings on your iDevice and go to "Touch ID & Passcode."
  2. Turn off "Simple Passcode"
  3. Next, change your passcode to something longer, using all numbers.
  4. Enjoy your new improved security!
Look what happens when you get to the lock screen now! Instead of needing to enter your long password with the keyboard (really kind of a drag) you just punch it in on the keypad (not too shabby!) The only difference between this and the simple passcode option is that you need to tap the "OK" after entering your code.

OK, I lied. The only difference is you have to tap OK, and your password is now more than 111,000%  harder to crack! (Assuming you have used 7 digits.) You've gone from 10,000 combinations to 11,111,110. Add one more digit and you've increased the number of combinations to over 100,000 which is more than a One Million Percent increase!

I really like the idea that the length of my passcode is no longer known. While I'd never recommend a 1, 2 or 3 character code, a would be thief/hacker would have to try all of them in order to rule them out. They also need to try all the 5, 6, 7 and so on combos, thereby increasing the amount of time it will take to unlock your phone.

Yes, you may have set your phone to erase all data after 10 failed passcode attempts, so perhaps you're not too worried. Then again, you may have a kid or a wise guy friend who just loves wiping out all your data every so often. Me? I'd rather not have to restore from a backup. And if you're one of those people who says "Back… what?" or doesn't know how to restore from a backup or one of those who knows how long it takes to restore from a backup, maybe you would like to make your password a little bit longer and less obvious than a sentimental date.

Tuesday, August 5, 2014

The Argument for Phony Security Question Answers (Again)

A seventeen year old kid in Australia recently bypassed Paypal's two factor authentication. This should be troubling news to anyone who engages in financial transactions on the Internet. I've written a thing or two about password management and security on line and have been a strong advocate of two-factor authentication, hailing it as "state of the art" consumer level security.

Two-factor authentication is supposed to mean that "even if someone succeeds in hacking your
password, they won't be able to log in to your account from a device that you haven’t already approved. The log in won’t be allowed until after you receive a text message on your cellphone with a code, which must then be entered in addition to the password." But, not so at Paypal, according to our junior jackaroo.

What happened at PayPal?

As many are aware, PayPal is owned by eBay. As a convenience for their users (i.e., to encourage their users to use PayPal for everything) eBay provides their users with a direct link to their PayPal accounts. Here's the fly in that ointment: apparently eBay does not check to see whether two-factor authentication is enabled before allowing anyone who manages to log in to eBay to shoot right into the linked PayPal account with just a username/password combo.

That may not seem like such a big security hole, since it requires the crook to have your username/password combination at two sites, but that's really not that far fetched if a hacker has been able to gain access to the victim's computer.

It gets worse. According to PCWorld, "The payment processor’s two-factor authentication could potentially be defeated in other ways. For example, if a user doesn’t have a way to receive the six-digit code, PayPal allows them to skip it and instead answer two security questions." Given that most security questions involve questions like "Where were you born?" and "Where did you go to high school?" the illusion of two-factor authentication becomes more and more mirage-like.

I've shared the answer before, but it's time to share it again: How about using your random password generator to come up with a short but random string of characters, and saving it in your password management app?

Mother's maiden name? oL-eF-yeph

Wednesday, May 28, 2014

Need another reason to use strong passwords and two-factor authentication? iPhones Held Hostage!

One of the of the security features offered by Apple for its computers, iPhones and iPads has turned around and bitten several Australian users who found that they were suddenly locked out of their devices and asked to pay a ransom of up to $100 to a hacker holding access to their devices hostage. 

Find My Phone is a great security feature that allows an iPhone owner to remotely lock his or her device should it be lost or stolen, thereby securing all the data on the phone and rendering it useless without the entry of a security code. But, problems arose for the Aussies when a hacker going by the name of Oleg Pliss somehow obtained usernames and passwords, and locked the rightful owners out. Apple says it has not been the victim of any security breach and suggests that credentials were gained either by phishing or because of password reuse.

Phishing attacks are just a modern form of film flam and trickery. A scammer sends an email that looks authentic, and the dupe dutifully responds with all kinds of information that is best not shared with bad guys. Phishing can be thwarted by never clicking on links in emails. If a legitimate web site needs information from you, you will be able to find their inquiry on their website. If you get an email asking for any information:

1. Make note of what website it is supposedly from.
2. Delete the email.
3. Go to the subject website by opening your browser and using your own bookmark. If you do not have a bookmark, enter the URL for the website you are trying to reach, or use a trusted search engine to bring you to the genuine site.
4. Log in and look for a message to you.

Follow this method for dealing with emailed information requests and you will avoid falling prey to almost all phishing attacks.

I've discussed Password Reuse before. In a word, it's bad. If you use the same username and password at more than one site, once a hacker gets information from one web site breach, he has access to every account you have that uses that username/password combo.

Finally, Two-Factor Authentication: In a word, it's great! Here is a large list of websites indicating which do and which do not have 2-Factor Authentication. In short, without rehashing what's been said before, if a provider offers 2-Factor Authentication, use it, and if they don't, encourage them to do so.