Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Careers & People

2/25/2016
10:30 AM
Adam Shostack
Adam Shostack
Commentary
Connect Directly
Twitter
LinkedIn
RSS
E-Mail vvv

Security Lessons From My Doctor

Why it's hard to change risky habits like weak passwords and heavy smoking, even when advice is clear.

By Lewis Hine - Lewis Hine: Newsies smoking at Skeeter's Branch, St. Louis, 1910, based on file from Library of Congress, Public Domain, https://commons.wikimedia.org/w/index.php?curid=11158385
By Lewis Hine - Lewis Hine: Newsies smoking at Skeeter's Branch, St. Louis, 1910, based on file from Library of Congress, Public Domain, https://commons.wikimedia.org/w/index.php?curid=11158385

Comment  | 
Print  | 
Comments
Newest First  |  Oldest First  |  Threaded View
Page 1 / 2   >   >>
Joe Stanganelli
50%
50%
Joe Stanganelli,
User Rank: Ninja
2/29/2016 | 7:00:30 PM
Re: PW mgrs.
Well, it's all risk management, let's not forget.  Security and accessibility are at constant odds at each other.  Sacrifice the one for the enhancement of the other.  The real issue is balancing both so that people are educated in terms of engaging in "best practices" -- or, at least, if they're going to ignore those best practices, that they do so knowing the consequences and the risks.

And a related best practice: Minimizing the data you 1) collect and 2) put out onto others' systems about yourself.
Joe Stanganelli
50%
50%
Joe Stanganelli,
User Rank: Ninja
2/28/2016 | 10:48:57 PM
Re: Change is difficult
Baby steps.  Start walking for 15 minutes every other day.  Build it into your habit over a few weeks.  Then increase the lengths of the walks or frequency.  Take steps to make vegetables more accessible.  Try vaping instead of smoking (it's how two family members and several friends of mine have quit!).  Is BIG change difficult?  Sure -- if you try to do it all at once.

But as the adage goes: How do you eat an elephant? One bite at a time.

So too with security habits in user behavior.
Joe Stanganelli
50%
50%
Joe Stanganelli,
User Rank: Ninja
2/28/2016 | 10:46:33 PM
Re: PW mgrs.
While we can all agree that putting your password on a sticky note on your monitor or in your top desk drawer is a terrible idea, many security experts have over the past few years reversed conventional wisdom and suggested that people DO write down their passwords -- on the condition that the password is lengthy, has a lot of entropy, and is otherwise nothing on the order of what a human would naturally select for him- or herself (i.e., the password is pseudorandom if not truly random) -- and then put the piece of paper somewhere truly secure, like your wallet.

Of course, even better -- should the piece of paper get compromised somehow anyway -- is to write down a hint that is meaningful to you but not meaningful to anyone else.

Doing this in a password manager is simply another approach to this thinking.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
2/27/2016 | 6:54:48 PM
Re: PW mgrs.
Good question. I would suggest to anybody, if they could not manage putting a hint into a password manager they should not be online. Also agree, security is less of problem for many, they are concern on privacy.
Dr.T
0%
100%
Dr.T,
User Rank: Ninja
2/27/2016 | 6:52:26 PM
Re: PW mgrs.
Agree. This is a good idea. Do not write your whole password anywhere. Or you can keep all those hints in your brain. 
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
2/27/2016 | 6:50:59 PM
Re: Thank you for educating your readers about the importance of online security
Agree. The change is difficult. Starting using a password manager would be a change too. Ultimate goal should be getting rid of whole username/password.
Dr.T
0%
100%
Dr.T,
User Rank: Ninja
2/27/2016 | 6:48:42 PM
Re: Thank you for educating your readers about the importance of online security
1Password is good, some others are good too. But I suggest nobody should be using any password manager. If one could not manage a password they could not manage a password manager, they would put themselves in more risks.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
2/27/2016 | 6:45:27 PM
Change is difficult
Agree with the article. We could not stop smoking or start eating more vegetables or going to 30 minutes' walk every day or having a complex password since all these things are changes in our life styles. And change is difficult.
adamshostack
50%
50%
adamshostack,
User Rank: Apprentice
2/27/2016 | 5:39:32 PM
Re: PW mgrs.
Joe--that's an interesting approach.  Would you suggest it to someone who's busy or forgetful?

 

For many folks I've talked to, security is a side effect: the real win is it's easier to use.
Joe Stanganelli
50%
50%
Joe Stanganelli,
User Rank: Ninja
2/27/2016 | 5:36:04 PM
PW mgrs.
I great piece of advice I got recently regarding password managers: Don't put your actual passwords in them; instead, put your hints in them.
Page 1 / 2   >   >>
Why Cyber-Risk Is a C-Suite Issue
Marc Wilczek, Digital Strategist & CIO Advisor,  11/12/2019
Unreasonable Security Best Practices vs. Good Risk Management
Jack Freund, Director, Risk Science at RiskLens,  11/13/2019
6 Small-Business Password Managers
Curtis Franklin Jr., Senior Editor at Dark Reading,  11/8/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Navigating the Deluge of Security Data
In this Tech Digest, Dark Reading shares the experiences of some top security practitioners as they navigate volumes of security data. We examine some examples of how enterprises can cull this data to find the clues they need.
Flash Poll
Rethinking Enterprise Data Defense
Rethinking Enterprise Data Defense
Frustrated with recurring intrusions and breaches, cybersecurity professionals are questioning some of the industrys conventional wisdom. Heres a look at what theyre thinking about.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-14869
PUBLISHED: 2019-11-15
A flaw was found in all versions of ghostscript 9.x before 9.28, where the `.charkeys` procedure, where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. An attacker could abuse this flaw by creating a specially crafted PostScript file that could esc...
CVE-2019-18987
PUBLISHED: 2019-11-15
An issue was discovered in the AbuseFilter extension through 1.34 for MediaWiki. Once a specific abuse filter has (accidentally or otherwise) been made public, its previous versions can be exposed, thus potentially disclosing private or sensitive information within the filter's definition.
CVE-2019-18986
PUBLISHED: 2019-11-15
Pimcore before 6.2.2 allow attackers to brute-force (guess) valid usernames by using the 'forgot password' functionality as it returns distinct messages for invalid password and non-existing users.
CVE-2019-18981
PUBLISHED: 2019-11-15
Pimcore before 6.2.2 lacks an Access Denied outcome for a certain scenario of an incorrect recipient ID of a notification.
CVE-2019-18982
PUBLISHED: 2019-11-15
bundles/AdminBundle/Controller/Admin/EmailController.php in Pimcore before 6.3.0 allows script execution in the Email Log preview window because of the lack of a Content-Security-Policy header.