Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Comments
Security Lessons From My Doctor
Threaded  |  Newest First  |  Oldest First
AgileEva
50%
50%
AgileEva,
User Rank: Apprentice
2/25/2016 | 12:23:36 PM
Thank you for educating your readers about the importance of online security
Hi Adam,

I'm Eva and I work for AgileBits, the makers of 1Password.

I wanted to thank you for taking the time to educate your readers on the importance of password managers and online security, and for including 1Password in your discussion!

In this day and age, it is so important that we all use strong and unique passwords for every site that we visit, and password managers can help make it much more convenient to be secure.

Keep sharing the secure word!

Eva Schweber
Good Witch of the Pacific Northwest @ AgileBits
support.1password.com

 
adamshostack
50%
50%
adamshostack,
User Rank: Apprentice
2/25/2016 | 8:32:10 PM
Re: Thank you for educating your readers about the importance of online security
AgileEva: You're welcome!  And while I do like your product, the goal of my post was to talk about why people resist change, and what we can do about it.   (Also, let me be clear: I pay the same price as anyone else.)
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
2/27/2016 | 6:50:59 PM
Re: Thank you for educating your readers about the importance of online security
Agree. The change is difficult. Starting using a password manager would be a change too. Ultimate goal should be getting rid of whole username/password.
Dr.T
0%
100%
Dr.T,
User Rank: Ninja
2/27/2016 | 6:48:42 PM
Re: Thank you for educating your readers about the importance of online security
1Password is good, some others are good too. But I suggest nobody should be using any password manager. If one could not manage a password they could not manage a password manager, they would put themselves in more risks.
Joe Stanganelli
50%
50%
Joe Stanganelli,
User Rank: Ninja
2/27/2016 | 5:36:04 PM
PW mgrs.
I great piece of advice I got recently regarding password managers: Don't put your actual passwords in them; instead, put your hints in them.
adamshostack
50%
50%
adamshostack,
User Rank: Apprentice
2/27/2016 | 5:39:32 PM
Re: PW mgrs.
Joe--that's an interesting approach.  Would you suggest it to someone who's busy or forgetful?

 

For many folks I've talked to, security is a side effect: the real win is it's easier to use.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
2/27/2016 | 6:54:48 PM
Re: PW mgrs.
Good question. I would suggest to anybody, if they could not manage putting a hint into a password manager they should not be online. Also agree, security is less of problem for many, they are concern on privacy.
Joe Stanganelli
50%
50%
Joe Stanganelli,
User Rank: Ninja
2/29/2016 | 7:00:30 PM
Re: PW mgrs.
Well, it's all risk management, let's not forget.  Security and accessibility are at constant odds at each other.  Sacrifice the one for the enhancement of the other.  The real issue is balancing both so that people are educated in terms of engaging in "best practices" -- or, at least, if they're going to ignore those best practices, that they do so knowing the consequences and the risks.

And a related best practice: Minimizing the data you 1) collect and 2) put out onto others' systems about yourself.
Joe Stanganelli
50%
50%
Joe Stanganelli,
User Rank: Ninja
2/28/2016 | 10:46:33 PM
Re: PW mgrs.
While we can all agree that putting your password on a sticky note on your monitor or in your top desk drawer is a terrible idea, many security experts have over the past few years reversed conventional wisdom and suggested that people DO write down their passwords -- on the condition that the password is lengthy, has a lot of entropy, and is otherwise nothing on the order of what a human would naturally select for him- or herself (i.e., the password is pseudorandom if not truly random) -- and then put the piece of paper somewhere truly secure, like your wallet.

Of course, even better -- should the piece of paper get compromised somehow anyway -- is to write down a hint that is meaningful to you but not meaningful to anyone else.

Doing this in a password manager is simply another approach to this thinking.
Dr.T
0%
100%
Dr.T,
User Rank: Ninja
2/27/2016 | 6:52:26 PM
Re: PW mgrs.
Agree. This is a good idea. Do not write your whole password anywhere. Or you can keep all those hints in your brain. 
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
2/27/2016 | 6:45:27 PM
Change is difficult
Agree with the article. We could not stop smoking or start eating more vegetables or going to 30 minutes' walk every day or having a complex password since all these things are changes in our life styles. And change is difficult.
Joe Stanganelli
50%
50%
Joe Stanganelli,
User Rank: Ninja
2/28/2016 | 10:48:57 PM
Re: Change is difficult
Baby steps.  Start walking for 15 minutes every other day.  Build it into your habit over a few weeks.  Then increase the lengths of the walks or frequency.  Take steps to make vegetables more accessible.  Try vaping instead of smoking (it's how two family members and several friends of mine have quit!).  Is BIG change difficult?  Sure -- if you try to do it all at once.

But as the adage goes: How do you eat an elephant? One bite at a time.

So too with security habits in user behavior.


Edge-DRsplash-10-edge-articles
I Smell a RAT! New Cybersecurity Threats for the Crypto Industry
David Trepp, Partner, IT Assurance with accounting and advisory firm BPM LLP,  7/9/2021
News
Attacks on Kaseya Servers Led to Ransomware in Less Than 2 Hours
Robert Lemos, Contributing Writer,  7/7/2021
Commentary
It's in the Game (but It Shouldn't Be)
Tal Memran, Cybersecurity Expert, CYE,  7/9/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
The State of Cybersecurity Incident Response
In this report learn how enterprises are building their incident response teams and processes, how they research potential compromises, how they respond to new breaches, and what tools and processes they use to remediate problems and improve their cyber defenses for the future.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-37436
PUBLISHED: 2021-07-24
Amazon Echo Dot devices through 2021-07-02 sometimes allow attackers, who have physical access to a device after a factory reset, to obtain sensitive information via a series of complex hardware and software attacks. NOTE: reportedly, there were vendor marketing statements about safely removing pers...
CVE-2021-32686
PUBLISHED: 2021-07-23
PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In PJSIP before version 2.11.1, there are a couple of issues found in the SSL socket. First, a race condition between callback and ...
CVE-2021-32783
PUBLISHED: 2021-07-23
Contour is a Kubernetes ingress controller using Envoy proxy. In Contour before version 1.17.1 a specially crafted ExternalName type Service may be used to access Envoy's admin interface, which Contour normally prevents from access outside the Envoy container. This can be used to shut down Envoy rem...
CVE-2021-3169
PUBLISHED: 2021-07-23
An issue in Jumpserver 2.6.2 and below allows attackers to create a connection token through an API which does not have access control and use it to access sensitive assets.
CVE-2020-20741
PUBLISHED: 2021-07-23
Incorrect Access Control in Beckhoff Automation GmbH & Co. KG CX9020 with firmware version CX9020_CB3011_WEC7_HPS_v602_TC31_B4016.6 allows remote attackers to bypass authentication via the "CE Remote Display Tool" as it does not close the incoming connection on the Windows CE side if t...