The Macrosite for News, Analysis and Opinion about the Future of the Internet
Comments
Current display:       newest comments first       chronological order   threaded
< Previous   Page 2 of 2
mnt.code
IQ Crew
Wednesday November 4, 2009 9:28:18 AM
no ratings

I tried to remember all my user names and passwords until it got totally unmanageable. Now I use long mangeled passwords for most sites, keeping the username/passwords in an encrypted file on a usb stick. Now I just have to remember the pass phrase for the file, and unencrypt the file when I'm working, and and destroy the uncrypted file when I'm done. I keep the encrypted file in my regular backups in case I lose my usb stick. I'm sure that there are hundreds of ways to do what I'm doing, if my system doesn't suit. Now I don't have my dog's name as a password unless my dog is named 7Uye$nn297Tt.

Ken Owen
www.eowen.com

Mike Acker
Rank: Web master
Wednesday November 4, 2009 7:46:15 AM
no ratings

This morning's Suggested Reading:

Corporate bank accounts targeted in online fraud

Until we have effective Computer Security it is un-wise to conduct commercial business over the net. As the Net is becomming de rigueur as a business tool it may become necessary to enact government regulations mandating security. none of us want that. so let's clean up the mess ourselves. Correct the thinking for over-the-air or over-the-net program updates from "anything goes" (Cowboy Programming) to require all program updates to be authenticated using a digital trust model and digital certificates

Today we often see a pop-up message like: "This website wants to install (...)"

The next thing we should see is a UAC dialog indicating whether the proposed update can be authenticated.  Is it what is says it is?  Has it been tampered with? Is it really from the source that claims to have sent it?

all of these questions can be answered using the digital certificates in a Trust Model -- and the required processing should be an automatic function of UAC

Due Date: NLT Win7/SP2

There's a time and a place for everything. But if you are going to use a computer for commercial business -- either at home or at work -- Cowboy Programming cannot be tolerated. Perhaps you might use a Virtual Machine to experiment with -- if you are into that.

smkinoshita
IQ Crew
Tuesday November 3, 2009 1:39:11 PM
no ratings

Sadly enough this is true.  And more people need to be aware of (and understand to some degree) this fact.  It should be part of public school or high-school curriculums.

 

Mike Acker
Rank: Web master
Tuesday November 3, 2009 8:21:34 AM
no ratings

TSA: ="Let's face it - malware is everywhere and using a locked-down systems, as Michael mentions in the previous comment, is simply not practical for every-day use. "

Let's face it: if your computer is infected you don't have security. you don't even know what your computer is doing.

it's like I cut the shaft that connects your steering wheel to your steering mechanism.  You can turn the wheel -- but it no longer controls your car...

so it is with malware

malware can

  • see your screen (even hidden fields )
  • type on your keyboard (enter keystrokes as though they were typed)

What this means: Until malware is stopped computers should not be used to conduct business over the web.

Authentication is the key to stopping malware. Malware is basically just un-authorized programming.

In order to stop malware all software updates must be authenticated.

and if you think this is going to inhibit your your use of your computer, think again: it will only deny the use of your computer to the attackers -- which will leave the use of your computer to you.  As it should be.

UAC is a huge step in the right direction.  All they need to add is an automatic trust model so that UAC can authenticate updates and present the result of that to the user when it throws a dialog.

 

tsaleem
Rank: Web master
Tuesday November 3, 2009 5:42:09 AM
no ratings

Good tips on password management, Tom. Using pass phrases instead of passwords is also something I utilise to keep easy to remember passes. 

However, I think the use of passwords alone as a challenge-response auth system is too outdated for today's security requirements. Let's face it - malware is everywhere and using a locked-down systems, as Michael mentions in the previous comment, is simply not practical for every-day use. 

Multiple-factor authentication may be the answer. It doesn't have to be biometrics or tokens - simple techniques such as use of graphical symbols helps! Simplicity is the key after all. 

DavidSilversmith
Thinkernetter
Monday November 2, 2009 11:37:48 PM
no ratings

So many web sites fail to truly support password security.  They have nice little messages saying that you should create a secure password but them they don't enforce anything more than basic rules like a minimum number of characters.  More importantly - they do not enforce regular password changes.

If you want to talk real security their should be rules (PCI - Payment Credit card industry would be a great place to start) that required any site that stores credit card data to require password changes at least every 6 months.

I appreciate the few websites that enforce password changes - I momentarily curse them - but after the few seconds of work - I truly appreciate their real efforts to endorse good security.

tdstamulis
Thinkernetter
Monday November 2, 2009 4:22:09 PM
no ratings

Michael,

I agree there are a number of good password management solutions available that can greatly assist you with your day to day activities. However, the first point I am trying to accomplish is to get individuals to at least change their passwords twice a year. The second point is that regardless of whether you take advantage of a password management system, it does not mean you should not change your personal passwords on a scheduled basis.

Michael P. Kassner
Thinkernetter
Monday November 2, 2009 3:50:46 PM
no ratings

As having a malware-free computer. You can have the best passwords in the world and if crimeware like Zeus or URLZone are installed on your computer you are in deep trouble. They both start after the user has logged into the financial portal.

Experts are recommending only using a known malware-free computer with a Linux OS, iPhone, or LiveCD (Linux-based) to do any on-line transactions.

On another note, why not use one of the many open-source password safes to manage passwords. I use Password Safe. It portable as well, so it works on any computer.

Mike Acker
Rank: Web master
Monday November 2, 2009 3:40:37 PM
no ratings

look up commonly used passwords (google)

if you use one of the common passwords an attacker can break in within a few hundred tries, likley at most

so you want to make the password odd enough that it isn't found on the common passwords list and you will force the attacker into brute force mode

which will likely not be used

instead arttacker will plant a keyboard logger on your machine and let you tell him what your password is. that way his botware can proceed on automatic

note that if you have a 3 strikes and out policy: 3 successive invalid passwords and the account is disabled the odds of an attacker hacking a decent password go astronomically off scale

users will persist in using common use passwords unless you put a stop to it

so it is not nearly so critical to change passwords all the time as it is to avoid common use passwords and keep malware out

if we would implement SINGLE LOGON users would be MUCH MORE COOPERATIVE

Single Logon: you give your user id and password ONCE: when you open your Desk-top.  After that each launch ICON uses a RUN AS to change the USER ID -- and hence the permissions -- creating effective security and single logon in 1 move.  why does Microsoft ignore us all the time

like Johnny Cash said in his shoe-shine song: This world needS a lot more shining and a lot less poppin!

< Previous   Page 2 of 2


The ThinkerNet does not reflect the views of TechWeb. The ThinkerNet is an informal means of communication to members and visitors of the Internet Evolution site. Individual authors are chosen by Internet Evolution to blog. Neither Internet Evolution nor TechWeb assume responsibility for comments, claims, or opinions made by authors and ThinkerNet bloggers. They are no substitute for your own research and should not be relied upon for trading or any other purpose.
a moderated blogosphere of internet experts
Dan Cypra
Dan Cypra   11/20/2009   4 comments
A picture is worth a thousand words, or so the old saying goes. So understanding how to use images in e-newsletters effectively is quite important. Here are a few tips to ensure that your images in email newsletters work to your advantage.
Gordon Haff
Gordon Haff   11/20/2009   1 comment
Arms merchant or army? That's a fundamental question for vendors in the cloud computing space. Do they just sell their tooling to any and all comers, who then become the actual purveyors of hosted infrastructure, developer platforms, and software? Or do they offer their own cloud-based services, perhaps even keeping much of their technology in-house for competitive advantage?
Mary E. Shacklett
With the value of toxic assets on the rise, large U.S. and European banks face many challenges on the road to recovery. Sharing key information may help these firms effectively track the way forward.
Matthew Fraser
Matthew Fraser   11/19/2009   5 comments
Most of us go through life knowing that we’re expected to learn from our mistakes and improve. Those who are more conscientious about learning and personal improvement usually reap greater rewards.
Mike Moran
Mike Moran   11/19/2009   12 comments
Marketers are known for exaggerated claims and stretching the truth just a wee bit. But most marketers I know truly believe in what they sell. Their aggressiveness is based on a confidence that what they are promoting truly benefits the customer.
IETV: the thinkerNet on film
5
of
2pm EST
Tue
Dec 1st
an IBM information resource
sponsored content
big blue blog
Todd Watson
Todd Watson   11/20/2009   Post a comment
While Google introduces its new Chrome OS (which I'm hearing will be widely available in one year?  Did I mishear that?), IBM announced 10 new products today to help companies using IBM System z mainframe technology.
white papers & case studies
an IBM information resource
sponsored content
Smarter Collaboration: How to Thrive in a Challenging Business Environment
Market conditions are changing faster than ever, and organizations need to improve their agility and adaptability in order to provide better service and improve processes. The ability to work with customers, business partners, and employees as effectively as possible - while at the same time holding down costs - is a key to success.

READ THIS eBOOK
your weekly update of news, analysis, and
opinion from Internet Evolution - FREE!

REGISTER HERE
Wanted! Site Moderators
Internet Evolution is looking for a handful of readers to help moderate the message boards on our site – as well as engaging in high-IQ conversation with the industry mavens on our thinkerNet blogosphere. The job comes with various perks, bags of kudos, and GIANT bragging rights. Interested?

Please email: moderators@internetevolution.com
Copyright © 2009 United Business Media Limited - All rights reserved.      About Us  |  Privacy Policy and Terms of Use  |  Contact Us
CMP Media LLC
Internet Evolution – not for thickies
what.the.ferraro
Facebook Lacks Social Skills

11|20|09   |   1:53   |   1 comment


Facebook's 'Suggestions' for users demonstrate how little social networking sites understand about true social relationships.
Singer at C-Level
Smart Grid Opportunities

11|20|09   |   2:49   |   No comments


Industry initiatives and government stimulus funds are giving enterprise software vendors a great opportunity to help build out and manage smart grid technologies.
Tom Nolle
Total Telephony Transcends Telepresence

11|20|09   |   2:11   |   2 comments


The problem with telepresence is that it's not universally accepted, because video calling isn't. While we can all do video calling, we also apparently worry too much about how we look. If we want HD telepresence in our future, we have to dress down, mess up our hair, and dive into our online life.
what.the.ferraro
ThinkerNet Wins Min's Award for Best Blogs!

11|19|09   |   1:13   |   4 comments


ThinkerNet wins the Min's award for 'Best Blogs' – Internet Evolution's fifth award this year!
Full Nelson
SanFran.gov

11|19|09   |   8:51   |   No comments


Fritz has an exclusive talk with the mayor and CTO of San Francisco about that city's latest e-government efforts.
Robert D. Atkinson
America Has Much to Learn About Digital Piracy

11|18|09   |   2:09   |   No comments


The US loses about $20 billion a year on pirated software, movies, and music. But public policy can help stem the tide of digital theft. For example, France has recently passed a 'three strikes and you’re out' law, whereby if after two warning letters an individual continues to download pirated software then his Internet access will be cut off. US policy makers should consider adopting similar policies.
Singer at C-Level
Connecting Stakeholders: Part 3

Part 3 of 3   |  
See complete series
11|18|09   |   2:09   |   No comments


Financial management planning does not need to include Voodoo economics, but it does help to tap into the knowledge base of your team through some sort of real-time system. We explore your options.
Reiter's Block
Tweeting for Customer Support

11|18|09   |   2:20   |   No comments


When Reiter gets incensed over incompetent Verizon FiOS order-taking and support, he broadcasts it via Twitter. Did it do any good? How should your company offer Twitter support? Watch this for all the answers.
what.the.ferraro
Dogster.com More Popular Than Gov 2.0

11|17|09   |   2:05   |   1 comment


A lot of attention is being paid to launching Gov 2.0 Websites, but these sites aren't attracting a lot of visitors.
Reiter's Block
Is the BlackBerry 9700 'Bold' Enough?

11|17|09   |   3:07   |   4 comments


The successor to the BlackBerry Bold 9000 – the Bold 9700 – will be available soon in the US. Is it worth upgrading? Reiter's got one, and offers advice.
TechWeb The Global Leader In Technology Media