Tilted Forum Project Discussion Community

Tilted Forum Project Discussion Community (https://thetfp.com/tfp/)
-   General Discussion (https://thetfp.com/tfp/general-discussion/)
-   -   Biggest hole in network security (https://thetfp.com/tfp/general-discussion/1394-biggest-hole-network-security.html)

meanSpleen 04-20-2003 11:58 AM

Give Me Your Password
 
Well well well, looks like the idea of protecting your password can be defeated by free handouts. How free? How about a cheap pen.

From http://www.theregister.co.uk/content/55/30324.html

"Workers are prepared to give away their passwords for a cheap pen, according to a somewhat unscientific - but still illuminating - survey published today.

The second annual survey into office scruples, conducted by the people organising this month's InfoSecurity Europe 2003 conference, found that office workers have learnt very little about IT security in the past year.

If anything, people are even more lax about security than they were a year ago, the survey found.

Nine in ten (90 per cent) of office workers at London's Waterloo Station gave away their computer password for a cheap pen, compared with 65 per cent last year.

Men were slightly more likely to reveal their password with 95 per cent of blokes, compared to 85 per cent of women quizzed, prepared to hand over their password on request.

The survey also found the majority of workers (80 per cent) would take confidential information with them when they change jobs and would not keep salary details confidential if they came across them.

If workers came across a file containing everyone's salary details, 75 per cent of workers thought they would be unable to resist looking at it, again up from 61 per cent in 2002. A further 38 per cent said they would also pass the information around the office.

Naughty.

The survey was undertaken by the organisers of Infosecurity Europe 2003 in a quest to find out how security conscious workers are with company information stored on computers.

Workers were asked a series of questions which included: What is your password? Three in four (75 per cent) of people immediately gave their password.

If they initially refused they were asked which category their password fell into and then asked a further question to find out the password.

A further 15 percent were then prepared to give over their passwords, after the most rudimentary of social engineering tricks were applied.

One interviewee said, "I am the CEO, I will not give you my password it could compromise my company's information".

A good start, but then the company boss blew it. He later said that his password was his daughter's name.

What is your daughters name the interviewer cheekily asked.

He replied without thinking: "Tasmin".

D'oh.

Of the 152 office workers surveyed many explained the origin of their passwords.

The most common password was "password" (12 per cent) and the most popular category was their own name (16 per cent) followed by their football team (11 per cent) and date of birth (8 per cent).

Two thirds of workers have given their password to a colleague (the same as last year) and three quarters knew their co-workers passwords.

In addition to using their password to gain access to their company information two thirds of workers use the same password for everything, including their personal banking, Web site access, etc.

This makes them more vulnerable to financial fraud, personal data loss or even identity theft, the InfoSecurity team point out.

Meanwhile two thirds of workers admitted they had emailed colleagues illicit, unsavoury pictures or "dirty jokes", up slightly from 62 per cent in 2002. Men were twice as likely to indulge in this activity with 91 per cent of men sending unsavoury emails compared to only 40 per cent of women.

InfoSecurity's organisers say this behaviour could expose their employer to expensive litigation for sexual discrimination, low morale and even be viewed as allowing bullying.

Tamar Beck, Director of InfoSecurity Europe 2003, said: "Employees are sometimes just naïve, poorly trained or are not made aware of the security risk. Employers therefore need to create a culture of protecting their information and reputation with policies on information security backed up with training to support the security technology"."

Lebell 04-20-2003 12:17 PM

Hehe,

Really, if you offered me a pen for a password, I would give you one, it just wouldn't be the real one. I'm a security freak on networks and my passwords reflect that, with mixed case, numeric and non-numeric characters.

But I'll tell you what,

I'll give you all my list of password hints:


My WindowsXP Admin account: Mom's state
My Hotmail: My State
My TFP password: Arfcom Modified


There Ya go! Have fun Crackers!

richeee 04-20-2003 12:24 PM

Quote:

Originally posted by Lebell

My WindowsXP Admin account: Mom's state
My Hotmail: My State
My TFP password: Arfcom Modified

There Ya go! Have fun Crackers!

California
Colorado
Marcof

Johnny Rotten 04-20-2003 12:32 PM

Sure, I'll be glad to take a pen from you in exchange for what I claim is a password.

Lebell 04-20-2003 12:36 PM

Quote:

Originally posted by richeee
California
Colorado
Marcof

Hehe,

Did you really think it would be that easy?

cdwonderful 04-20-2003 12:52 PM

I would give it out and just change my password. You are supposed to change it periodically anyway right?

Xixox 04-20-2003 12:53 PM

Seriously, people are dumb like that sometimes.

I had to set up a cow-orker's pc at work with network access to one of our drives. I asked him what his login for Win2k was, and he gave me login and password.

This is the day before April 1st, mind.

The next day he came in to find his mouse swapped to left-handed, oriented so that up = right, and set to super-mega-slow speed.

I could have done oh so much more, but it wasn't worth losing my job over. I think at least he is a little more educated about security now, though.

spectre 04-20-2003 04:11 PM

This isn't surprising, but it's very disturbing that people don't take basic security seriously. All of my passwords are a mix of letters (upper and lower case) and numbers chosen randomly.

reconmike 04-20-2003 04:16 PM

ok if you insist,
mine is whatthehellstinksinhere I know kinda lomg but I dont think anyone will figure it out

Downtownat10 04-20-2003 04:18 PM

Well, for me it all depends. For some of my nonsense items that require passwords, like hotmail accounts and so forth, I just use something basic, so I will always know it, and I really never change it. Everything else, though, such as computers, laptops, regular e-mails, etc, I use a mix of letters and numbers, and change it bi-weekly. I have too much stuff at risk to have an easy password.

Evan 04-20-2003 04:22 PM

I use the same password for everything, but its just a simple phrase with no connection whatsoever to myself., no football teams, no my name, no "password". I find it just as effective as mixed passwords with numerals and mixed capitalization with random letters, especially seince i find it easier to remember...

phoenix1002 04-20-2003 04:29 PM

I generally have the same password, or variations of the same password, for most of my stuff. The way I see it, I don't have anything important right now that would matter if someone messed with. Besides, my password has letters and either numbers or symbols in it, and is the name of an obscure planet from a sci-fi book I read a few years back. Don't ask me why I chose it, I just did... but I bet you can't figure it out :p

sbscout 04-20-2003 05:14 PM

my password is....

XXXXXXXXXXX

now where's my pen?

BobDFish 04-20-2003 05:53 PM

My personal favorite remains an acquaintance who thought they were being clever by actually making there password all asteriks (*'s), because it actually was what came up on screen. However another acquaintance noticed that it was just one key being hit rapidly, and from there it was all down hill. ::shake head:: Yay for having goatse as the background image and the password changed. . .

PorscheBunny 04-21-2003 10:25 AM

Biggest hole in network security
 
http://www.theregister.com/content/55/30324.html

Quote:

Nine in ten (90 per cent) of office workers at London's Waterloo Station gave away their computer password for a cheap pen …
Your co-workers are morons, but you already knew that.

phoenix1002 04-21-2003 10:43 AM

I think this thread is already up... but its still pretty funny.

Daval 04-21-2003 10:45 AM

I saw a show on this on 20/20, it was pretty scary how fast some people are willing to give up their security unverified to strangers.

scapegoat 04-21-2003 11:28 AM

Its sad but true unforutunatly.... ive tried it myself at my workplace, and no one seems to understand a sence of secturity

dvorak 04-21-2003 11:35 AM

Um, I can see going balls out with your password security (mixed case, letters, numbers, etc., changing every week) if it protects something of real value that you can expect someone to want unauthorized access to...

But just the login to your windows environment at work? What's the big deal? Set your password to your old girlfriend's last name or some other dumbass, easy to remember word... No one cares about getting in, and the "enter password" prompt is enough to stop anyone from messing with your desktop wallpaper.

It's better to have a slight risk of someone getting to your insignificant data than it is to bother the tech department every time you forget your login.

But as I said, if you are protecting something that the average cracker might want access to... then by all means, be careful!

asdf1001 04-21-2003 12:46 PM

I guess this answers the ultimate question: Just HOW stupid are people?

Mad_Gecko 04-21-2003 01:06 PM

Not surprised at this.

I know people who Don't Know their own passwords.. They have someone else log them in and leave it logged in. Always generates problems when there is an unexpected power outage hehe.

Cynthetiq 04-21-2003 01:11 PM

why ask them when you can just look for the post-it on their monitors?

PorscheBunny 04-21-2003 01:24 PM

{comment withdrawn}

meanSpleen 04-21-2003 02:00 PM

hey, uh, porschebunny - Check the *date* i posted it. Not just the time. :)

SecretMethod70 04-21-2003 02:31 PM

This isn't too surprising to me. If people actually took security seriously then they'd update their boxes when they're supposed to - but they don't. And then we get things like that worm that crippled the internet for a weekend awhile back.

K-Billy 04-21-2003 02:58 PM

ooh cheap pen, who could resist?

Fearless_Hyena 04-22-2003 08:51 PM

Kickass article MeanSpleen, I saw that in the news too! When I read your post subject, my immediate response was "the human factor!"

All the firewalls and security technology in the world are worthless if you can talk someone into simply giving you the information you need or doing something for you, which they wouldn't otherwise do.

This isn't a plug (borrow it from your public library if you need to :D) but I think everyone interested in this thread should read The Art Of Deception by Kevin Mitnick. Check it out, that's a link to an excerpt.

It's the best book I've read in a while, it brilliantly describes exactly what we're talking about. Everyone, even non-techie types can learn a whole lot from from it....I wish I could think of another example but this thread and that excerpt pretty much cover the basic idea.

mokle 04-22-2003 10:01 PM

Quote:

Originally posted by Lebell
I'll give you all my list of password hints:


My WindowsXP Admin account: Mom's state
My Hotmail: My State
My TFP password: Arfcom Modified


There Ya go! Have fun Crackers!

: sane
: insane
: Arfcom Modified


All times are GMT -8. The time now is 12:53 PM.

Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2024, vBulletin Solutions, Inc.
Search Engine Optimization by vBSEO 3.6.0 PL2
© 2002-2012 Tilted Forum Project


1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219 220 221 222 223 224 225 226 227 228 229 230 231 232 233 234 235 236 237 238 239 240 241 242 243 244 245 246 247 248 249 250 251 252 253 254 255 256 257 258 259 260 261 262 263 264 265 266 267 268 269 270 271 272 273 274 275 276 277 278 279 280 281 282 283 284 285 286 287 288 289 290 291 292 293 294 295 296 297 298 299 300 301 302 303 304 305 306 307 308 309 310 311 312 313 314 315 316 317 318 319 320 321 322 323 324 325 326 327 328 329 330 331 332 333 334 335 336 337 338 339 340 341 342 343 344 345 346 347 348 349 350 351 352 353 354 355 356 357 358 359 360