Attacks/Breaches

Yahoo Mail Passwords: Act Now

Yahoo suffers hack attack, eyes third-party database and reused credentials as likely culprits, may enforce two-factor authentication to help users recover accounts.

Comment  | 
Print  | 
Comments
Newest First  |  Oldest First  |  Threaded View
Page 1 / 3   >   >>
M_Gordon
50%
50%
M_Gordon,
User Rank: Apprentice
2/3/2014 | 1:08:32 PM
Re: Password managers
Kristin,

You should check out LastPass, it's a really useful password manager. It allows to use many different and strong passwords without having to remember each one. They also have an security add-on option, Toopher, which adds another layer of security to each of your accounts in LastPass. It's extremely user friendly and uses location awareness of your smartphone to automate the authentication process. Check out this video, it helped me better understand what Toopher does. http://www.youtube.com/watch?v=k78xDTpy7PU
Susan Fourtané
50%
50%
Susan Fourtané,
User Rank: Apprentice
2/3/2014 | 6:00:59 AM
Re: Password managers
Kristin, 

"I choose the option to have my browser remember most of my passwords, too. But it's the worst when you're required to clear cookies and other settings for some reason and all your passwords are cleared. Password hell all over again."

I know! I went through password hell this past weekend. I had to reset my FB password, which is always easier that trying all the password formula alternatives and all the possible combinations I can think of I used for a FB password.

I am still waiting one my online libraries to send me a new password. :( 

-Susan

 
Li Tan
50%
50%
Li Tan,
User Rank: Apprentice
2/3/2014 | 1:45:14 AM
Re: Password managers
The best practice to my experience is using the same password with sufficient complexity for all your internet accounts. This sounds nothing new but sometimes it's difficult to handle it in this way due to various constraints from different web sites. Furthermore, I normally chose not let web browser to remember my password - it does not take me long to enter the password everytime and it helped me to remember it. 
Kristin Burnham
50%
50%
Kristin Burnham,
User Rank: Apprentice
2/1/2014 | 9:20:08 AM
Re: Password managers
I choose the option to have my browser remember most of my passwords, too. But it's the worst when you're required to clear cookies and other settings for some reason and all your passwords are cleared. Password hell all over again.
jgherbert
50%
50%
jgherbert,
User Rank: Apprentice
1/31/2014 | 9:51:24 PM
Re: Password managers
@Shane M. O'Neill:

"I don't trust that a password manager can't be hacked. So I continue on in the living hell that is memorizing passwords and keeping them on a piece of paper hidden in my house. "

That's _so_ 1980s. Anybody with any self respect would use Post-Its stuck to their monitor, surely?

I must confess that I am about at explosion point with passwords, especially with every site having different requirements for password strength. SSO has issues but I gotta tell you, right now I am all about some kind of federated SSO across web sites. 

I do use a password manager by the way, but there isn't a single product that I've yet found that works consistently across (in my case), windows, linux, OSX and iOS, and integrates with the web browser so that I don't have to jump between applications all the time to find and then paste in a password. Especially on a smartphone that's a huge pain.

 
Susan Fourtané
50%
50%
Susan Fourtané,
User Rank: Apprentice
1/31/2014 | 6:37:16 PM
Re: Just one password?
anon, 

"The likely culprit in this case of Yahoo was probably not a very secure site."

Exactly. Yahoo! Mail has never been secure. It has had plenty of hacking problems. I am not surprised about this new one at all. 

-Susan
Susan Fourtané
50%
50%
Susan Fourtané,
User Rank: Apprentice
1/31/2014 | 6:26:00 PM
Re: Password managers
Kristin, 

I can see how the habit of using the same password for multiple sites could have started for many.

If you have to sign in to ten, or more sites daily you may well forget some of the passwords. One password for all can solve the problem. It brings others, as we know. 

Chrome offers the option of remembering passwords. I choose this option to certain sites. Some other times I ask for a new password. This is handy for sites I don't use frequently. It's faster and easier than trying to remember a password I use a few times a year. 

For the important passwords I don't use a password manager at the moment. I have a password formula. 

-Susan 
Drew Conry-Murray
50%
50%
Drew Conry-Murray,
User Rank: Ninja
1/31/2014 | 5:01:29 PM
Re: Just one password?
I'm not sure it's better, but if I need to create an insanely complex password to protect my password manager, why not just use that insanely complex password everywhere and save myself the trouble of the password manager?
anon7244892334
100%
0%
anon7244892334,
User Rank: Apprentice
1/31/2014 | 4:47:27 PM
Re: Just one password?
Yes of course, but the probability that someone will hack your password manager versus hacking any of a multiple of sites/accounts where you're using the same UN/PW is substantiall lower.  The likely culprit in this case of Yahoo was probably not a very secure site.
anon7244892334
100%
0%
anon7244892334,
User Rank: Apprentice
1/31/2014 | 4:44:36 PM
Re: Just one password?
What's so shocking about someone using AOL mail?  It's reliable, doesn't have hacking issues, and filters spam well.  Seems like a smart service to use.
Page 1 / 3   >   >>
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading Tech Digest, Dec. 19, 2014
Software-defined networking can be a net plus for security. The key: Work with the network team to implement gradually, test as you go, and take the opportunity to overhaul your security strategy.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-2188
Published: 2015-02-26
The Authentication Proxy feature in Cisco IOS does not properly handle invalid AAA return codes from RADIUS and TACACS+ servers, which allows remote attackers to bypass authentication in opportunistic circumstances via a connection attempt that triggers an invalid code, as demonstrated by a connecti...

CVE-2015-0594
Published: 2015-02-26
Multiple cross-site scripting (XSS) vulnerabilities in the help pages in Cisco Common Services, as used in Cisco Prime LAN Management Solution (LMS) and Cisco Security Manager, allow remote attackers to inject arbitrary web script or HTML via unspecified parameters, aka Bug IDs CSCuq54654 and CSCun1...

CVE-2015-0632
Published: 2015-02-26
Race condition in the Neighbor Discovery (ND) protocol implementation in Cisco IOS and IOS XE allows remote attackers to cause a denial of service via a flood of Router Solicitation messages on the local network, aka Bug ID CSCuo67770.

CVE-2015-0651
Published: 2015-02-26
Cross-site request forgery (CSRF) vulnerability in the web GUI in Cisco Application Networking Manager (ANM), and Device Manager (DM) on Cisco 4710 Application Control Engine (ACE) appliances, allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuo99753.

CVE-2015-0882
Published: 2015-02-26
Multiple cross-site scripting (XSS) vulnerabilities in zencart-ja (aka Zen Cart Japanese edition) 1.3 jp through 1.3.0.2 jp8 and 1.5 ja through 1.5.1 ja allow remote attackers to inject arbitrary web script or HTML via a crafted parameter, related to admin/includes/init_includes/init_sanitize.php an...

Dark Reading Radio
Archived Dark Reading Radio
How can security professionals better engage with their peers, both in person and online? In this Dark Reading Radio show, we will talk to leaders at some of the security industry’s professional organizations about how security pros can get more involved – with their colleagues in the same industry, with their peers in other industries, and with the IT security community as a whole.