Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Comments
Security Lessons From My Doctor
Newest First  |  Oldest First  |  Threaded View
Page 1 / 2   >   >>
Joe Stanganelli
50%
50%
Joe Stanganelli,
User Rank: Ninja
2/29/2016 | 7:00:30 PM
Re: PW mgrs.
Well, it's all risk management, let's not forget.  Security and accessibility are at constant odds at each other.  Sacrifice the one for the enhancement of the other.  The real issue is balancing both so that people are educated in terms of engaging in "best practices" -- or, at least, if they're going to ignore those best practices, that they do so knowing the consequences and the risks.

And a related best practice: Minimizing the data you 1) collect and 2) put out onto others' systems about yourself.
Joe Stanganelli
50%
50%
Joe Stanganelli,
User Rank: Ninja
2/28/2016 | 10:48:57 PM
Re: Change is difficult
Baby steps.  Start walking for 15 minutes every other day.  Build it into your habit over a few weeks.  Then increase the lengths of the walks or frequency.  Take steps to make vegetables more accessible.  Try vaping instead of smoking (it's how two family members and several friends of mine have quit!).  Is BIG change difficult?  Sure -- if you try to do it all at once.

But as the adage goes: How do you eat an elephant? One bite at a time.

So too with security habits in user behavior.
Joe Stanganelli
50%
50%
Joe Stanganelli,
User Rank: Ninja
2/28/2016 | 10:46:33 PM
Re: PW mgrs.
While we can all agree that putting your password on a sticky note on your monitor or in your top desk drawer is a terrible idea, many security experts have over the past few years reversed conventional wisdom and suggested that people DO write down their passwords -- on the condition that the password is lengthy, has a lot of entropy, and is otherwise nothing on the order of what a human would naturally select for him- or herself (i.e., the password is pseudorandom if not truly random) -- and then put the piece of paper somewhere truly secure, like your wallet.

Of course, even better -- should the piece of paper get compromised somehow anyway -- is to write down a hint that is meaningful to you but not meaningful to anyone else.

Doing this in a password manager is simply another approach to this thinking.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
2/27/2016 | 6:54:48 PM
Re: PW mgrs.
Good question. I would suggest to anybody, if they could not manage putting a hint into a password manager they should not be online. Also agree, security is less of problem for many, they are concern on privacy.
Dr.T
0%
100%
Dr.T,
User Rank: Ninja
2/27/2016 | 6:52:26 PM
Re: PW mgrs.
Agree. This is a good idea. Do not write your whole password anywhere. Or you can keep all those hints in your brain. 
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
2/27/2016 | 6:50:59 PM
Re: Thank you for educating your readers about the importance of online security
Agree. The change is difficult. Starting using a password manager would be a change too. Ultimate goal should be getting rid of whole username/password.
Dr.T
0%
100%
Dr.T,
User Rank: Ninja
2/27/2016 | 6:48:42 PM
Re: Thank you for educating your readers about the importance of online security
1Password is good, some others are good too. But I suggest nobody should be using any password manager. If one could not manage a password they could not manage a password manager, they would put themselves in more risks.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
2/27/2016 | 6:45:27 PM
Change is difficult
Agree with the article. We could not stop smoking or start eating more vegetables or going to 30 minutes' walk every day or having a complex password since all these things are changes in our life styles. And change is difficult.
adamshostack
50%
50%
adamshostack,
User Rank: Apprentice
2/27/2016 | 5:39:32 PM
Re: PW mgrs.
Joe--that's an interesting approach.  Would you suggest it to someone who's busy or forgetful?

 

For many folks I've talked to, security is a side effect: the real win is it's easier to use.
Joe Stanganelli
50%
50%
Joe Stanganelli,
User Rank: Ninja
2/27/2016 | 5:36:04 PM
PW mgrs.
I great piece of advice I got recently regarding password managers: Don't put your actual passwords in them; instead, put your hints in them.
Page 1 / 2   >   >>


AI Is Everywhere, but Don't Ignore the Basics
Howie Xu, Vice President of AI and Machine Learning at Zscaler,  9/10/2019
Fed Kaspersky Ban Made Permanent by New Rules
Dark Reading Staff 9/11/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
7 Threats & Disruptive Forces Changing the Face of Cybersecurity
This Dark Reading Tech Digest gives an in-depth look at the biggest emerging threats and disruptive forces that are changing the face of cybersecurity today.
Flash Poll
The State of IT Operations and Cybersecurity Operations
The State of IT Operations and Cybersecurity Operations
Your enterprise's cyber risk may depend upon the relationship between the IT team and the security team. Heres some insight on what's working and what isn't in the data center.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-16319
PUBLISHED: 2019-09-15
In Wireshark 3.0.0 to 3.0.3 and 2.6.0 to 2.6.10, the Gryphon dissector could go into an infinite loop. This was addressed in plugins/epan/gryphon/packet-gryphon.c by checking for a message length of zero.
CVE-2019-16320
PUBLISHED: 2019-09-15
Cobham Sea Tel v170 224521 through v194 225444 devices allow attackers to obtain potentially sensitive information, such as a vessel's latitude and longitude, via the public SNMP community.
CVE-2019-16321
PUBLISHED: 2019-09-15
ScadaBR 1.0CE, and 1.1.x through 1.1.0-RC, has XSS via a request for a nonexistent resource, as demonstrated by the dwr/test/ PATH_INFO.
CVE-2019-16317
PUBLISHED: 2019-09-14
In Pimcore before 5.7.1, an attacker with limited privileges can trigger execution of a .phar file via a phar:// URL in a filename parameter, because PHAR uploads are not blocked and are reachable within the phar://../../../../../../../../var/www/html/web/var/assets/ directory, a different vulnerabi...
CVE-2019-16318
PUBLISHED: 2019-09-14
In Pimcore before 5.7.1, an attacker with limited privileges can bypass file-extension restrictions via a 256-character filename, as demonstrated by the failure of automatic renaming of .php to .php.txt for long filenames, a different vulnerability than CVE-2019-10867 and CVE-2019-16317.