joomla templates

Expert Witness

Directory and Magazine

Thu02232012

Last update03:31:51 PM GMT

anti PREMATURE EJACULATION viagra Buy lasix cheap metformin 500 mg tablets Buy viagra cheap levaquin drug manufacturer buy from pharmacy us viagra plavix and aggrenox together valtrex drug good aldara celebrex patanol nexium Buy doxycycline cheap lexapro discussion amoxil online cipro generic manufacturer synthroid without prescription buy nolvadex research zithromax vertabral infection vigrasolutions viagra blogspot generic Order lipitor rash from lipitor reviews on clomid for men viagra without prescription kamagra for sale lexapro and lost libido cheapest kamagra sale how to buy viagra bristol Order accutane buy cheap p viagra levitra viagra or cialis Buy zithromax cheap cheap levitra u.s zithromax diarrhea zithromax purchase 100 mg clomid side effects plavix generic release difference between prilosec and nexium can lexapro help health anxiety propecia pro cons valtrex online us metformin 500 mg and weight loss zithromax herx viagra sale recommended dosage of levitra finasteride b propecia b Buy metformin cheap viagra price using rogaine with propecia prednisone 5 mg uses nexium price nascar viagra appeared on his car how to buy valtrex online best kamagra website buy kamagra buy kamagra Seroquel

SecurEnvoy says Stratfor user credential analysis shows that password security is now dead in the water

 

 

Commenting on reports that Utah Valley University researchers have analysed the many hundreds of thousands of Stratfor user account credentials which were hacked by Anonymous late last year due to weak passwords, SecurEnvoy says this proves the fact that the human element in security is now the weakest link.

Steve Watts, co-founder of the tokenless™ two-factor authentication specialist, says that, after crunching the data on its 120-strong computer network, the University found that the users of Stratfor Global Intelligence – many of whom are actively involved in the IT security industry – were using weak passwords.

“Put simply, they really should have known better, as the user list of the hacked accounts reportedly included US military personnel, IT staff at the Bank of America and JP Morgan, as well as IT professionals with IBM and Microsoft,” he said.

“And if these professionals cannot get their password security sorted, then what hope is there for the rest of the Internet user community? This revealing analysis proves our constant mantra that conventional passwords are dead in the water on the security front - especially with powerful password crunching technology so readily available,” he added.

The SecurEnvoy co-founder went on to say that is interesting that the Utah University researchers – who crunched their way through the MD5 password hashes for the Stratfor user account credentials revealed by the Anonymous hacktivists - were able to decode more than 160,000 passwords for various users.

Through the use of freely available cracking software such as John-the-Ripper and Oclhashcat-Plus, he explained, the researchers were able to generate some eight million passwords per second, and 62 million passwords per second – respectively - using their network of computers.

In theory, says Watts, if account holders had strong enough passwords, then even the use of Oclhashcat-Plus - which harnesses the number-crunching capability of a PC’s graphics processor(s) – then a brute force attack would not have been possible.

But, he adds, as this research proves, human nature means that many people are lazy, and elect to use eight digit or less character passphrases, making the task of the researchers very easy.

“And if the Utah University researchers have been able to crunch these records, then you can bet your bottom dollar that their criminal counterparts have also been conducting similar analyses. This proves that ID/password security really is out-moded, and that Internet users now need to be thinking in terms of two-factor authentication,” he said.

“The problem with most authentication systems seen to date, however, is that they require the use of a hardware token. Our approach is to use the power of the users’ smartphones (something you have) and an answer to a known question (something you know) to ensure that only the person entitled to access the account is allowed to use the online facility,” he added.

“The use of tokenless authentication makes the process of stepping up from out-moded ID/password security all the more easier. The use of authentication significantly raises the security bar and remediates the shortcomings of the human element when logging in.”

Last Updated on Wednesday, 11 January 2012 15:17

Add comment


Security code
Refresh

Expert Witness
Expert Witness
Expert Witness
Expert Witness
Expert Witness
Expert Witness
Expert Witness