Showing posts sorted by relevance for query reuse. Sort by date Show all posts
Showing posts sorted by relevance for query reuse. Sort by date Show all posts

27 September 2018

Another security breach: NewsNow. Another reason not to reuse passwords!


Online news aggregation service NewsNow has admitted that it has suffered a security breach.

It’s a shame that they didn’t include more technical details on how the passwords are stored, even if only for those readers who might understand them.

What is clear is that you should ensure that you are not using the password you were using on NewsNow anywhere else on the web.

Furthermore, NewsNow appears to be so burnt by the experience that it has decided it never wants to store passwords (hashed or otherwise) again.

In an age of “toxic data”, the site has declared that it has revamped its login system. In future users will simply enter their email address into a form, and will then need to wait for a message to be sent to their email address containing a link that will log them into the NewsNow system.

So, puhleaze: choose your passwords carefully, no simple ones, complexity is the key, and no reuse of passwords either! 
If you need help: contact Donline.


29 August 2018

No, eight characters, some capital letters and numbers is not a good password policy


Bad passwords are one of those problems that never goes out of fashion, and sure enough, in a recent audit (26 per cent) of  Active Directory passwords were found to be somewhere between easily guessed and downright lamentable.

Among these, ‘Password123’ was in use by 1,464 accounts, ‘Project10’ by 994, ‘support’ by 866, ‘password1’ by 813, and ‘October2017’ by 226, to pick only the top five worst offenders in popularity order.

In one particularly epic fail, the auditors said they were able to remotely access a test environment for the agency’s web system using the password ‘Summer123’.

So, puhleaze: choose your passwords carefully, no simple ones, complexity is the key, and no reuse of passwords either! If you need help: contact Donline.


12 August 2026

Laptops without power adapters from 2026

From 28 April 2026, new EU regulations will noticeably change the notebook market: laptops must be chargeable via USB-C. The goal is to allow users to reuse existing power adapters instead of buying a new one with every device. This is the core of the EU Common Charger regulation, which will apply to laptops from this date onward.

At the same time, the scope of delivery will change. Manufacturers must offer devices without power adapters and will increasingly ship notebooks without one by default. The background is the same sustainability and interoperability approach: less electronic waste, fewer duplicate chargers, and more standardization.

USB-C” initially refers only to the connector shape. For charging, the relevant standard is USB Power Delivery (USB-PD). A notebook may have a USB-C port, but charging capability, charging speed, and compatibility depend on which USB-PD profiles are supported.

Confused? Contact Donline.

www.dev.to


25 July 2019

Synology urges all users to take immediate action to protect data from ransomware attack



TAIPEI, Taiwan - July 23, 2019 Synology recently found that several users were under a ransomware attack, where admins' credentials were stolen by brute-force login attacks, and their data was encrypted as a result. We investigated and found that the causes of these attacks were due to dictionary attacks instead of specific system vulnerabilities. This large-scale attack was targeted at various NAS models from different vendors; therefore we strongly recommend users check network and account settings to protect data from ransomware.

"We believe this is an organized attack. After an intensive investigation into this matter, we found that the attacker used botnet addresses to hide the real source IP," said Ken Lee, Manager of Security Incident Response Team at Synology Inc. "After collecting admin account passwords with brute-force attacks, the attack was launched on July 19 and caught users off guard. We therefore informed TWCERT/CC and CERT/CC immediately of this matter in hopes of accelerating the collaborative efforts to resolve this incident."

Since this attack is not related to system security vulnerabilities, it is recommended that Synology users utilize built-in network and account management settings to enhance system security level, preventing malicious attacks from the Internet.

"We urge all Synology users to take immediate action to protect their NAS from the ransomware attack," said Hewitt Lee, Director of Product Management at Synology Inc. "Users' data security is always our priority. For those who are not using Synology NAS, we still recommend you take corresponding actions to protect your precious data."

Synology are a great company with fantastic NAS devices. However, any piece of IT is only as secure as it's weakest link. Use a trivial password & expect to lose control of your device and data! ALWAYS use complex passwords & never reuse passwords!


06 May 2020

We beg, implore and beseech thee. Stop reusing the same damn password everywhere!


Two-thirds of people recycle the same password or use variations on the same basic one, according to LogMeIn.

Even though more than 90 per cent of people surveyed by the password manager biz said they knew it was risky to recycle passwords or light variations on a theme, 66 per cent of respondents admitted they "always or mostly use the same password or a variation".

These findings came from LogMeIn's Psychology of Passwords report, released recently, that quizzed 3,250 people and discovered that half of them across the world hadn't changed their passwords over the past 12 months "even after hearing about a breach in the news".

Depressingly, that number rose to 58 per cent for Britons specifically who did not change their passwords after reading about a breach on the news. A whopping 92 per cent of Brits reuse passwords despite being aware of the risks.

Click here to find out more about the risks in poor password hygiene, and advice on how to stay safe.


11 April 2023

Terrifying study shows how fast AI can crack your passwords

 

Along with the positive aspects of the new generative AI services come new risks. One that’s surfaced is an advanced approach to cracking passwords called PassGAN. Using the latest AI, it was able to compromise 51% of passwords in under one minute with 71% of passwords cracked in less than a day. 

Last month, Microsoft brought attention to the security concerns that will come with the quick advancement of AI by announcing its new Security Copilot suite that will help security researchers protect against malicious use of modern technology.

Now Home Security Heroes has published a study showing how scary powerful the latest generative AI is at cracking passwords. The company used the new password cracker PassGAN (password generative adversarial network) to process a list of over 15,000,000 credentials from the Rockyou dataset and the results were wild:

51% of all common passwords were cracked in less than one minute, 65% in less than an hour, 71% in less than a day, and 81% in less than a month.

To stay safe: stick with at least 12 characters with a mix of upper, and lowercase letters plus numbers. Never reuse passwords - a unique one per service / account. Need help securing your accounts? Contact Donline.


17 December 2018

Received an email claming that your PC has been hacked & they have your passwords? It's probably a scam...


Here’s a clever new twist on an old email scam that could serve to make the con far more believable. The message purports to have been sent from a hacker who’s compromised your computer and used your webcam to record a video of you while you were watching porn. The missive threatens to release the video to all your contacts unless you pay a Bitcoin ransom. The new twist? The email now references a real password previously tied to the recipient’s email address.

The basic elements of this sextortion scam email have been around for some time, and usually the only thing that changes with this particular message is the Bitcoin address that frightened targets can use to pay the amount demanded. 

But how did they get your password? Chances are, from an already compromised site & not from a direct hack on your PC. Check if your credentials are available online HERE. As always: DO NOT REUSE PASSWORDS!!! 

If you have received one of these emails & are worried / unsure what to do next - contact Donline.


12 July 2022

Come back old fashioned keys - all is forgiven!

Hackers have uncovered ways to unlock and start nearly all modern Honda-branded vehicles by wirelessly stealing codes from an owner's key fob. Dubbed "Rolling Pwn," the attack allows any individual to "eavesdrop" on a remote key fob from nearly 100 feet away and reuse them later to unlock or start a vehicle in the future without owner's knowledge.

Despite Honda's dispute that the technology in its key fobs "would not allow the vulnerability," The Drive has independently confirmed the validity of the attack with its own demonstration.

Older vehicles used static codes for keyless entry. These static codes are inherently vulnerable, as any individual can capture and replay them at will to lock and unlock a vehicle. Manufacturers later introduced rolling codes to improve vehicle security. Rolling codes work by using a Pseudorandom Number Generator (PRNG). When a lock or unlock button is pressed on a paired key fob, the fob sends a unique code wirelessly to the vehicle encapsulated within the message. The vehicle then checks the code sent to it against its internal database of valid PRNG-generated codes, and if the code is valid, the car grants the request to lock, unlock, or start the vehicle.

The database contains several allowed codes, as a key fob may not be in range of a vehicle when a button is pressed and may transmit a different code than what the vehicle is expecting to be next chronologically. This series of codes is also known as a "window," When a vehicle receives a newer code, it typically invalidates all previous codes to protect against replay attacks.

This attack works by eavesdropping on a paired keyfob and capturing several codes sent by the fob. The attacker can later replay a sequence of valid codes and re-sync the PRNG. This allows the attacker to re-use older codes that would normally be invalid, even months after the codes have been captured.

www.thedrive.com


20 November 2018

Top 5 ways to pick a secure password


Oh, passwords. Someday the FIDO alliance or somebody will save us from them. Until that heady day, we still need them and we need to choose ones that are really hard to guess. Even if you have two-factor authentication turned on—which you should—secure passwords are still a good idea. Fire up your Horse Battery Staple, here are five things to know to pick a good password:

1) Never reuse one. Ever. Data breaches are very common. When your password is breached at a service, that service will usually make you change it. But the service where you re-used it doesn't know that, so you just made that password very insecure.

2) Choose a long and strong passphrase. Yes, it is possible to remember your password and make it secure. Don't choose dictionary words. Security researcher Bruce Schneier suggests taking a sentence like: "When I was seven, my sister threw my stuffed rabbit in the toilet." And using the first letters numbers and punctuation to make "WIw7,mstmsritt."

3) Let a password manager do it for you. Yes, password managers are a single-point of failure, so be honest with yourself. Are your passwords more secure if you let a manager that is 2FA-protected pick really good ones for you? Or do you want to manage all that yourself? And is the way you manage it, more secure than a password manager? Be honest—nobody else needs to know.

4) Don't update it regularly unless you're forced to. It used to be that it took 90 days to crack a password, so if you changed it every 90 days, you could stay ahead. Now it takes seconds, unless you've picked a strong one.

5) Skip the secret question. If that's not an option, answer it like you're making a second password. There's no point in having a really secure password only to have it backed up by a dictionary word in your secret question that's easily guessable.