Friday, April 19, 2013

Passwords: A Little Reminder



Background Story


A relative and a couple of friends have had email or their Facebook account hacked recently. Over the past eight weeks, I have been taking a Network Penetration Testing class for my final three credits of my degree. One of the things that I have learned is that the resources to do this kind of hacking is far too easily obtained. One of the tasks that I have done in a hands on was to extract password hashes and account information from a remote computer and run a cracking program to get the passwords.

For those that are not savvy, when someone attacks your system or a website like Facebook, the passwords are "hashed". Hashing is a cryptographic means of encrypting the passwords on the computer so that they do not appear in plain text.

For example:

The common password used in school labs tends to be:
"Pa$$w0rd."

When an attacker gets your account info they see the hashed version which is:
"3cc31cd246149aec68079241e71e98f6"

So, the hacker uses a "cracking" tool to make that hash value into your password. There are various types of cracks including but not limited to:


  • Dictionary - uses a word list of common words and common misspellings.
  • Hybrid - like a dictionary crack but adds more symbols and "l33t" spellings.
  • Brute Force - every combination of characters is tried until the entire password is revealed.
  • Rainbow Tables - the hash is compared to a huge list of passwords found on other systems.



How do I defend myself? 

The complete answer to this is far too much for this blog. The solution includes hardware (routers and firewalls), software (antivirus suites and intrusion detection), best practices (what not to do on the web), and general user education. So for today, we will focus on good password practices.

The following are tips and not to be considered a complete solution.


Jack.... I hate you....

You haven't said this yet, but you will. Why? Because the tips I give you today will make your passwords as much of a pain in the ass to you as it is for the hackers!


Password Re-Use.

Passwords should be different for every single site and program that you use. If that is too much for you, at least make sure that passwords for your bank accounts and financial dealings are different than your email and social media passwords.

Passwords should be changed any time there is a compromise, every 30 days on important sites, and every 90 days on lesser sites. You should not recycle a password that you used on another site, and you should not use any of your previous 10 passwords.


Password blunders.

Passwords should not actually be a word. Dictionary attacks make very short work of a password like "Mustang" and this would be horribly bad if you are posting pictures of your sporty car on your social media site. It would be only slightly better if you vary it up with special characters like "Mu$t@nG", but this is still not very secure.

Passwords also should not be keyboard combos like "qwerty" or "1234wert". I guarantee that these will be quickly cracked like any dictionary word.


Size Matters Ladies!

The more characters in the password the better! The more characters in the password the better! The more characters in the password the better!

No, that was not a copy & paste error. That was me making an annoying point. Many companies have figured this out, and require 8-10 character passwords. Some of the jobs I have had required 15 character passwords. 

Is there a max? 

There is no maximum for the purpose of this guide. That said, some programs or sites will have a maximum. In that case, use that maximum whenever possible. If you can use a 48-character password, do it! XKCD comics made a comical poke at this.



The Passphrase

Some folks will tell you that a passphrase is the way to go. In this method, you would make your password something like "HowNowBrownCow" or "SometimesYou FeelLikeANut".  This is better than a single word because you are using more characters, but still not the best solution because dictionary words are being used still. Replacing some letters with special characters and numbers will help, but only a little.

Okay Jack, enough! WTF do you want me to do?


The PassPhrase Hybrid

Here we go. This is how we make a long password that you can remember and will slow down a password cracker.....



Step 1: Come up with a memorable phrase.

Don't ask what your country can do for you, ask what you can do for your country!


Step 2: Add a header piece. (Pretend your last name is Robinson here.)

At Casa de Robinson Don't ask what your country can do for you, ask what you can do for your country!

This is the phrase you will repeat in your mind to remember the password!


Step 3: Take the initials of each word....

ACDRDAWYCCDFYAWYCDFYC!


Step 4: Mix upper and lower case.

ACdRdawyccdfyAwycdfyc!


Step 5: Substitute numbers for like sounding words.

ACdRdawyccd4yAwycd4yc!


Step 6: Get some more special characters in there.

@CdR*dawyccd4y^Awycd4yc!

Ta-da!



Try it out.

Now that I have given some tips, come up with five passwords that you feel are strong.

Then go to http://www.passwordmeter.com/ and see how you rate!

Even my example above has room for improvement!





Be safe in cyberspace everyone!


Comment below! See you soon!


Thursday, April 4, 2013

The Probable Return of Thin-Client Business Networks.

INTRODUCTION


Many years ago, when the home computer was not a common household item, neither was the server-client architecture that many business networks use today. Ethernet was in its fledgling stages - thin-net and thick-net. Many networks were comprised of token-ring networks, mainframes, and terminals. Anyone that is old enough to remember the days I speak of likely just got an image in their mind's eye of those horrible monochromatic terminal screens with their black backgrounds and choice of green or orange characters. No graphical interfaces to be found, most terminals gave you a lovely numbered list to choose from. I even witnessed systems like this in some smaller companies all the way up to 1999.
(Did you just gag a little?)


What if I told you that business networks will soon return to those concepts?

Well, don't fret. We will not be regressing back that far. But we are going to borrow a lot from those old mainframes of years past. As companies try to improve economic, technological, and ecological concerns, we see many tech companies moving toward a new technology based on an old concept.

So let us first examine what is typical today:

SERVER-CLIENT ETHERNET



If you could take a tour of every company you would most often find that they utilize an Ethernet star or mesh topology, one or more servers running Windows Server or Linux, and a slew of client machines that will usually be Windows based. I realize this is a gross generalization, but the fact remains that this is the most common business network in existence.

These networks have endured due to the flexibility of hardware, availability of software, and the adapting security they offered (but not always properly configured.) Applications usually run on the clients in this scenario with any data shared as needed on a server. This meant less stress on servers as long as they were configured correctly and there were enough servers to load balance.

However, many companies are finding that the money they are spending on hardware life-cycles is getting prohibitive as are utility bills for the HVAC and power consumption needed to run so many client systems - each of which are capable of standing on their own. You also need an appropriate number of technicians to handle upkeep and user error.


So if this worked for so long, what could be better?














THIN CLIENT


Technically, thin clients (also known as slim clients or dumb terminals) have been around for years. An article in The Wall Street Journal by Christopher Lawton appeared in 2007 talking about the viability of such a network.

Doesn't that look better!
"Since the early 1980s, corporate computing power has shifted away from the big central computers that were hooked to "dumb terminals" on employees' desks and toward increasingly powerful desktop and laptop computers. Now, there are signs the tide is turning back." - Christopher Lawton



Thin clients have existed since the late 1990's. Initially, they were not well received, and many businesses opted to keep the architecture they were familiar with. Early thin client solution bids were more likely beat out by PC bids than other thin client offerings. However, sales of thin clients have started to take an upturn. By 2002 thin client sales growth was 13 times more than PC sales growth.

Example of a possible thin client logical configuration.

Thin client architecture addresses a few large issues that companies face in this ever-changing economic stew:


Costs


  • Life-cycle on full client systems average three years. Thin clients can go two or three times longer.
  • Servers can be consolidated in to fewer locations.
  • Less moving parts like fans and drives mean less maintenance costs.
  • Greatly reduced energy cost are realized from clients that use far less power to run.

Administration


  • One data center in most cases means increased central management less hands-on work at client locations.
  • Applications are run from the server which saves money on software licensing and less labor installing new software or updates.
  • Data storage is all server-based and easily automated - centralizing backup strategies. No data loss due to HDD failure on a client PC.

Security


  • Terminals hold no sensitive data which makes theft pointless.
  • Less need for host-based intrusion protection.
  • Security centralized and easier to plan.
  • Decreased risk of "sneakernet" attacks.

Aesthetics


  • Smaller hardware means more room on the desk.
  • Easy to hide.


THE SHIFT

Q: Is anyone really going to make this drastic move from the fully-functional "fat client" PC?


Some will read this and say to themselves, "I have hardly heard of this. Are enterprises really considering this?" The short answer is yes. The details are that while thin clients aren't ideal for every enterprise, more and more are going to be looking at this solution. Increasing energy costs, a declining economy that affects sales, increased cyber attacks, and the flux in hardware costs all make thin clients more attractive.

Still skeptical? The fact is that while thin client is more easily implemented in new networks, even some existing large networks are looking at making the switch. Wait..... did I say large? I meant HUGE. The U.S. Air Force is looking to make the jump by 2014. Federal Business Opportunities, a website used to solicit contracts for the Department of Defense, allows us to see the the expected capabilities. To paraphrase greatly, they want a thin client solution that supports two networks: one network would need to support up to 1 million users (700,000 concurrent at up to 400 locations) and the other supporting 220,000 users (75,000 concurrent at over 100 locations!)

THE IMPACT / CHANGES

1. Networking / Infrastructure



As the pendulum swings back toward thin clients, be prepared for some changes in the way the network is structured and maintained. Companies that may have housed servers in multiple locations will likely opt for a consolidated server farm. The type of network hardware may not see drastic changes, but there may be a need for more nodes to help load balancing and speed. This also means more servers, as load balancing and fail-over are going to be critical in such a centralized environment. Network hardware configuration will change as thin clients will require fewer open ports and likely will use stronger authentication methods. The critical part of this network design is ensuring speedy communications between the terminals and the centralized servers. This means that both the LAN and the WAN have to be appropriate for the increased network traffic that is generated. This may also mean upgrading the ISP service to a corporate plan that guarantees bandwidth and up time.

2. Restructured I.T. Departments


All the great hardware in the world doesn't eliminate the need for personnel to interact with it. In the PC fat-client system that many are used to, there is a requirement for a larger department that dealt with end-users usually referred to as a "Customer Service Center" or "Help Desk." In larger networks, there may be "tiers" of technicians based on their experience and the complexity of the issue. The server administrators and network technicians are generally smaller departments comprised of employees that are responsible for specific aspects of the infrastructure. Security specialists may be part of those departments, or a separate office of their own.

In the thin client solution, however, these departments will need a shakeup. Since the scaled-back hardware used by clients require less maintenance, the Help Desk would need to be much smaller. What remains of that office would be a first tier staff that can walk users through basic questions, but would mostly be a call center that entered work orders. Security personnel levels would not change greatly, as the possible attack vectors would be limited to the server farm and perimeter network.

The largest change would be in the number server administrators. Like the help desk in a fat client system, this department would need to be larger and have different tiers. Since all the applications, files, and backups are centralized - server farms must be adequately staffed to protect a potential single-point failure.

All of these changes could present a very different job market for new I.T. professionals. If the thin client infrastructure continues to show growth, the number of entry-level jobs could shrink greatly and cause a large demand for experienced professionals. Companies will no longer have a gradual progression from Tier I Help Desk up to Chief information Officer. The degree or technical certifications needed to get into I.T. may take more time and money than it does today.



Supporting Sources: