Showing posts with label password. Show all posts
Showing posts with label password. Show all posts

Tuesday, October 26, 2010

Facebook one-time passwords

Facebook is enabling a feature that I wanted Gmail to have a long time ago: one-time use passwords. These are passwords that you can only use one time. This is helpful if you're using a not-as-secure computer and are worried that someone might have captured your password (and you don't want others to be able to use your password.) In order to use this, you have to register a mobile phone with your Facebook account, and send a text to Facebook to receive a one-time password (that must be used within 20 mins.)

From the Facebook blog:
First, we're launching one-time passwords to make it safer to use public computers in places like hotels, cafes or airports. If you have any concerns about security of the computer you're using while accessing Facebook, we can text you a one-time password to use instead of your regular password.

Simply text "otp" to 32665 on your mobile phone (U.S. only), and you'll immediately receive a password that can be used only once and expires in 20 minutes. In order to access this feature, you'll need a mobile phone number in your account. We're rolling this out gradually, and it should be available to everyone in the coming weeks.

I try not to use other computers/devices to access personal information unless absolutely necessary. And nowadays, with all the smartphones out there, you don't really need to use someone else's computer. But it's nice to know there's this feature for passwords.

Friday, September 17, 2010

Password reuse

An old xkcd comic about password reuse.
http://xkcd.com/792/

Wednesday, November 11, 2009

Scams, example 3

The below text is from an email addressed from a good friend of mine:


I was immediately suspicious because (1) the style is definitely not the way my friend would write, (2) there are tons of typos, and (3) I'm suspicious of anyone trying to get me to buy products/wants my money.

I contacted my friend, who said she did NOT send that message. I asked if she experienced any other side effects, and she said all of her contacts in her email account had been deleted, but that luckily her virus/malware scanner found nothing.

I'm guessing that the intruder obtained her password somehow, perhaps by just trying to guess her password. The intruder then spammed everyone in her contact list. Wouldn't that take a lot of work? Not really, some people hire folks to do this. Plus people can write programs that aid in the attack.

I did some search online, and it looks like this web site is a fake site that sells consumer electronics for "really cheap." You buy your cheap, "authentic" iPod or whatever, submit your payment, and wait a while until you realize maybe they're never going to send you anything, or they send you something fake. But you can't really do anything about it because this "company" is based in China (we think.)

Reminders:
1. Be careful where you shop online - you can't just trust any shop.
2. Use a strong password, and avoid falling for phishing attacks.
3. If this happens to you and your email account has been compromised, (1) immediately change your password to a new password. (2) Run your (up-to-date) virus scanner to make sure there's nothing bad installed on your computer. (3) Alert friends who may have been spammed through your account so they don't fall for it.

Friday, October 30, 2009

Don't get scammed on Facebook

Imagine this scenario: Mr. Stranger guesses/steals your password, hijacks your Facebook account, and sends messages to all your friends that you are in trouble, stuck in some foreign country, and need money to be sent to you immediately. Some of your friends may fall for it and actually send money to Mr. Stranger trying to help you.

This kind of Facebook scam has happened many times, and a couple friends I know have even been affected (but were smart enough not to believe it.)

A few basic principles to remember:
- Any person contacting you online (through Facebook, email, instant messaging...) may not be who you think it is. It could be an impersonator.
- Use a good password that others can't easily guess. Some suggestions on how to choose a password here.
- Don't enter your password into fake (phishing) look-alike sites or pretend emails, which are just waiting for you to put in your personal info.

Wednesday, May 13, 2009

The importance of a good password (especially for your email account)


Imagine if some key/lock maker only made a few different keys - square, circular, and triangular. These locks would not provide good security at all - Mr. Stranger could easily try each possible shape and then get into your house, car, etc.

It's the same with passwords. Is your password easily guessable? Is it "password123"? If I tried every word in the dictionary could I get it? Is it your username (or some permutation of it)? Your username + your birth year? If you have a guessable password, Mr. Stranger could probably guess it eventually, after some number of tries.

Let's see what Mr. Stranger could do if he guessed the password to your main email account:
Obviously, he would be able to read ALL of your email. If you have any confidential information, such as other passwords, credit card numbers, social security number (which you shouldn't store on your email server anyway), Mr. Stranger would be able to see it.

He might be able to see where/when/with whom you are having dinner this weekend. A lot of personal information (how much email do you have stored?) could be extracted.
He would also have access to your contact list and all their email addresses (perhaps he'll make a copy for himself and sell this list to someone). He could send mail to them from your account without you ever knowing. (Hopefully he says something nice.)
If you use gmail, your gmail password would also provide access to any of the other Google applications you use - Mr. Stranger could view your calendar. He could see all your calendar events, read your google documents, make changes, etc.
If you use the same password for any other sites, Mr. Stranger now knows the password to your other accounts and could try using it.

Mr. Stranger could easily change your password and log into your account on any of those sites that use an email-based password recovery mechanism. Even if you use a different password for other sites, many other accounts are linked to your email address. For example, if you forget your password on Facebook, Xanga, Amazon, etc., you can ask them to send you an email with a temporary password or link so that you may reset your password.

Once Mr. Stranger gets into Xanga, he could read your private entries or read your friend's entries, write/delete/etc. any of your entries. He could do some pretty mean things.
If Mr. Stranger gets into Facebook, he would be able to see all your friends and their info (like telephone number, address, pictures..), and send them all messages (hopefully nothing mean or misleading), post pictures, delete stuff, etc. Just imagine the possibilities.
If Mr. Stranger logs into your Amazon account, and you have your credit card information stored and linked to your Amazon account, Mr. Stranger could order some items and have them delivered. (Luckily Amazon limits using saved credit card data to addresses you have used before.) He could delete emails/change the listed email address so you notice the purchases later than sooner.
If Mr. Stranger can find out your social security number, account number, or other information stored in your email somewhere, he might also be able to use it to log into your online bank account (he knows what accounts you have because he scanned your inbox) and do some damage there.

Pretty scary huh? (I don't mean to scare you, just showing you what's possible.)
Hopefully you don't have a square-shaped password.