Page 1 of 2 12 LastLast
Results 1 to 10 of 12

Thread: Password Security Trivia

  1. #1
    Join Date
    Jan 1970
    Location
    Ferny Grove, Brisbane
    Posts
    757
    Total Downloaded
    0

    Password Security Trivia

    I went to a seminar a couple of weeks ago on Identity Management and one of the speakers from a US University runs a group whose sole purpose it is to compromise their own University's IT security, to find holes and then have them fixed.

    So one day they decided to try something a little low tech. They sent out some students with chocolates and stuffed toys to select students and staff members at random to see if they could entice out of them their username and passwords.

    Results:
    Stuffed toys worked better than chocolates
    Females garnered more details than males
    Females had a 100% success rate with males

    I am not sure exactly what they were wearing but that is scary.

  2. #2
    VladTepes's Avatar
    VladTepes is offline Major Part of the Heart and Soul of AULRO Subscriber
    Join Date
    Feb 2004
    Location
    Bracken Ridge, Qld
    Posts
    16,055
    Total Downloaded
    0
    An exercise was conducted along these lines by an IT firm some time back. It was all done with pens.

    The firm dressed up in their corporate shirts and went around to people saying " We are checking the password security of the system, to make sure people are constructing their passwords properly". Oh and here's a pen to thank you for your help.

    HEAPS of people just TOLD THEM THEIR PASSWORDS OUTRIGHT>

    Too bloody trusting.

    An after hours survey also revealed that many people had their passwords written under their keyboards !

    Just proves that technology is rarely the problem. People are the problem.
    It's not broken. It's "Carbon Neutral".


    gone


    1993 Defender 110 ute "Doris"
    1994 Range Rover Vogue LSE "The Luxo-Barge"
    1994 Defender 130 HCPU "Rolly"
    1996 Discovery 1

    current

    1995 Defender 130 HCPU and Suzuki GSX1400


  3. #3
    Join Date
    Jan 1970
    Location
    Ermington, NSW, Au
    Posts
    444
    Total Downloaded
    0
    Scary.

    I can recommend a book called "The Art of Deception" by Kevin Mitnick. He was on the FBI's most wanted list for awhile for a long list of "hacking" exploits.

    In his book he lists various ways of gaining access to other people's systems. Most of them are very low tech and exploit social engineering. In most cases people are the weak link.
    2012 110 Defender

  4. #4
    VladTepes's Avatar
    VladTepes is offline Major Part of the Heart and Soul of AULRO Subscriber
    Join Date
    Feb 2004
    Location
    Bracken Ridge, Qld
    Posts
    16,055
    Total Downloaded
    0
    Kevin Mitnick - that's the guy I was trying to think of. The bloke is a genius.

    (Evil genius perhaps, but genius nonetheless)
    It's not broken. It's "Carbon Neutral".


    gone


    1993 Defender 110 ute "Doris"
    1994 Range Rover Vogue LSE "The Luxo-Barge"
    1994 Defender 130 HCPU "Rolly"
    1996 Discovery 1

    current

    1995 Defender 130 HCPU and Suzuki GSX1400


  5. #5
    Tombie Guest
    Quote Originally Posted by VladTepes View Post
    Kevin Mitnick - that's the guy I was trying to think of. The bloke is a genius.

    (Evil genius perhaps, but genius nonetheless)
    Did he get to them by their number plates???

  6. #6
    Join Date
    Apr 2008
    Location
    Adelaide SA
    Posts
    2,517
    Total Downloaded
    0
    Quote Originally Posted by Tombie2 View Post
    Did he get to them by their number plates???
    There is one in every crowd...

  7. #7
    VladTepes's Avatar
    VladTepes is offline Major Part of the Heart and Soul of AULRO Subscriber
    Join Date
    Feb 2004
    Location
    Bracken Ridge, Qld
    Posts
    16,055
    Total Downloaded
    0
    No he probably reasearched it meticulously for hours on online forums.
    It's not broken. It's "Carbon Neutral".


    gone


    1993 Defender 110 ute "Doris"
    1994 Range Rover Vogue LSE "The Luxo-Barge"
    1994 Defender 130 HCPU "Rolly"
    1996 Discovery 1

    current

    1995 Defender 130 HCPU and Suzuki GSX1400


  8. #8
    Join Date
    Jan 1970
    Location
    Ferny Grove, Brisbane
    Posts
    757
    Total Downloaded
    0
    Quote Originally Posted by Tombie2 View Post
    Did he get to them by their number plates???
    Funny you should say that because I remembered this story after replying to the number plate thread. People sometimes worry too much about the unlikely and miss the easy vulnerability.

  9. #9
    Join Date
    Mar 2008
    Location
    Melbourne
    Posts
    572
    Total Downloaded
    0
    I have worked in IT for nearly 30 years and what really gives me the irrits is idiots forcing me to change my password every 90 days. St George bank does it for business accounts. I have tried explaining to the numbskulls in the tech dept that it is actually less secure as eventually you end up writing it down to help you remember it.

    Had the same user name and password with the nab ever since they started internet banking.

    I have one password for anything not money related which is simple and I couldn't care if it gets compromised and one more complex for secure sites except St Bloody George.

  10. #10
    Join Date
    Jan 1970
    Location
    Ferny Grove, Brisbane
    Posts
    757
    Total Downloaded
    0
    Quote Originally Posted by martinozcmax View Post
    I have worked in IT for nearly 30 years and what really gives me the irrits is idiots forcing me to change my password every 90 days. St George bank does it for business accounts. I have tried explaining to the numbskulls in the tech dept that it is actually less secure as eventually you end up writing it down to help you remember it.

    Had the same user name and password with the nab ever since they started internet banking.

    I have one password for anything not money related which is simple and I couldn't care if it gets compromised and one more complex for secure sites except St Bloody George.
    Security mechanisms can be broken given enough time so there are clever people out there who work out the average time it would take for a password being guessed by a password generator etc. Then we set the password change frequency to be less than that. We have a 60 day cycle here at the uni.

Page 1 of 2 12 LastLast

Bookmarks

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
Search AULRO.com ONLY!
Search All the Web!