Results 1 to 10 of 23

Thread: Creating strong passwords and keeping them secret.

Threaded View

  1. #11
    Gonzo District BOFH westin's Avatar
    Join Date
    Jan 2006
    Location
    SW MO
    Posts
    1,187
    This is turning into a very interesting thread. Thanks for the good dialog guys. Metguru made some great points. I tried to give him [guessing you are a male, sorry if I am wrong] some APs, but it said I must spread them around.

    I would definitely agree that passwords can be bypassed as an authentication method with various exploits, but what do you guys suggest as far as good precautionary measures. Obviously, keep your systems patched, implement layered security, kill unneeded services [decrease your attackable surface], keep an eye on your logs... etc. What other measures do you guys implement to secure your systems against the attacks discussed in this thread?

    Metguru brought up sniffing unencrypted traffic, which depending on what service you are providing, includes some sort of user education. Working for a school district, I usually have a really hard time trying to educate the teachers. Their skill levels range from moderate to [no kidding] "Where is the enter key?". [Yes, that actually happened at the beginning of the school year]. I send out examples of phishing/fraudulent emails as often as I get them. I highlight the things to watch out for... but when you start telling them to make sure that their session is encrypted, their eyes glaze over. It isn't as simple as telling them to look for the little lock icon, because SSLStrip adds that as the favicon. I usually tell them to look for the https, but even that is beyond some of them. They largely rely on bookmarks, and don't really even know what a URL is. We have had several teachers lose their bookmarks, and all of a sudden they have no idea how to check their mail, get to the school website, etc. So, telling them to look at the address bar can often times put them into dummy mode.

    By the way... sorry for the rant... 'Tis the season!
    Last edited by westin; December 23rd, 2010 at 07:30 AM.
    \"Those of us that had been up all night were in no mood for coffee and donuts, we wanted strong drink.\"

    -HST

Similar Threads

  1. Tips
    By XTC46 in forum Site Feedback/Questions/Suggestions
    Replies: 15
    Last Post: August 24th, 2005, 07:52 PM
  2. The history of the Mac line of Operating systems
    By gore in forum Operating Systems
    Replies: 3
    Last Post: March 7th, 2004, 08:02 AM
  3. Tcp/ip
    By gore in forum Newbie Security Questions
    Replies: 11
    Last Post: December 29th, 2003, 08:01 AM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •