Showing posts with label Facebook. Show all posts
Showing posts with label Facebook. Show all posts

Wednesday, December 29, 2010

I Pwn You! Part I: Hiding The Keys To The Kingdom

pass·word [pas-wurd, pahs-wurd] (noun) - 1. a secret word or expression used by authorized persons to prove their right to access, information, etc. 2. a word or other string of characters, sometimes kept secret or confidential, that must be supplied by a user in order to gain full or partial access to a multiuser computer system or its data resources.

“Computers have enabled people to make more mistakes faster than almost any invention in history, with the possible exception of tequila and hand guns.” (Mitch Radcliffe)

-----

This is the first of a series of articles designed to provide you with the common sense to survive the digital age that we live in. This does not imply that you are an idiot, but I've been wrong before.

There are many traditions that are celebrated for the New Year. Many of us sit in front of the TV and watch the immortal Dick Clark (I think I will die before he does) count us down into the New Year. Some will be in church, getting in that last-minute Hail Mary to make up for that little thing they did the hour before they got there.

But I'm sure that many millions of people will be on their computers, buried in Facebook status updates wishing everyone of their Friends a Happy New Year or tweeting it to their vast legion of followers. So, for those of you who live on the Net or pay it the occasional visit, here’s your new New Year’s tradition in three words:

Change.
Your.
Password.
Now.

Okay, that’s four. Sue me. Glad to see that kindergarten paid off for you.

I can hear the groans now. And, oh, the complaints. I’ve heard them all:

“I’ve used this for years.”
“I don’t have time.”
“I might forget this one.”
“I don’t wanna!”


I don’t care. I really don’t. Take Nike’s advice: Just do it.

Let’s face it, kiddies. We live in a digital world now. Almost everyone is online now. I’m sure that days ago, many people just got their first computer for Christmas and, like a kid who just got his new bike, went squealing feet first into the internet so they could tweet and Friend everyone.

But the Net is but a digital mirror image of real life. Like real life, the internet is fraught with hidden dangers. I’ll go through them as this series progresses, but nothing irritates me more than people who use simple passwords on their accounts. Your password is the first line of defense that most black hat hackers (aka The Bad Guys, who will now be referred to as BHHs) have to breach to get access to those bytes of information that stand between you and your bank accounts and credit cards.

Fun Fact #1: The most common password used today is “123456”.

Think of it like this: using a simple password is the equivalent of putting your spare house key under the carpet on the porch just before you go on vacation, then yelling to the top of your lungs to the neighborhood that you’ll be gone for a week.

Most of the time, BHHs will try simple passwords to break into user accounts. If there are, for example, 1 million people who have a username and password on a web site, maybe 1% of those people will use a simple password like “123456”. That would mean that 10,000 people risk having their accounts hacked.

I know. Not a lot of people, right? But keep in mind that BHHs will use faster-than-average computers to do this. So, something that would take several weeks for one person to do can be done in minutes.

Fun Fact #2: The second most common password in use today is (surprise) “password”.

Statistically, many users will use the same password to access their e-mail as well as their online bank accounts and credit card accounts. This would mean that a determined BHH who acquires that one simple password has the keys to your kingdom. Usually, they will not only run through the kingdom unchecked, but they’ll bring their friends along to play, too. Before you know it, you’ll be getting calls from creditors about the $5,000 you owe on a credit card you never knew you had.

Scared yet? Good.

The good news is that you can still do something about it. So here are the rules that you will follow from now on regarding your rules. Note that if you don’t follow them and something happens, it’s all your fault, so pay attention.
  1. Never use a password shorter than seven characters.
    It’s tempting to use short words as passwords, but here’s why you should not do it. Let’s say you create a password for your account that uses lower-cases letters, like “fluffy” because that’s the name of your cat. Using a standard PC, a BHH can crack this in less than 30 seconds. Make it as long as possible, preferably seven or more characters.

  2. Never use personal information as a password.
    Another temptation, which I used in the above example, is to use a name of a favorite something or other. Why not? After all, it’s easy to remember. But if I wanted to find out personal information on you, I could go into your Facebook page, click through your information and photos and use those to make some pretty good guesses about what your password might be. And I would have you to thank for it.

    Never, ever, ever use the following as a password: your name, your spouse’s name, your parent’s name, your kid’s name, your pet’s name, your best friend’s name, your boss’ name, anybody’s name, your phone number, your license plate, your birth date, anybody’s birth date, or any part of your social security number.

  3. Whether it’s foreign or domestic, don’t use the dictionary.
    What’s wrong with using “purple”, as an example? It’s your favorite color, right? Beside breaking rule #2 above, it’s a common word in the dictionary, which BHHs love to use in their brute force attacks. In fact, it is also one of the 500 worst passwords.

    How about “fiesta”? It’s a Spanish word, right? It shouldn’t be that easy to crack, right? Wrong. Maximum time to crack “fiesta”? Thirty seconds.

  4. Never use the same password for every place you log into.
    In this day and age, it’s a pain to have different passwords for everything. So, to keep this simple, use different passwords for different categories. For example, use one password for your financial information. Use another for your newsletters. And another for your e-mail. That way, if you are compromised, the damage will be minimized and contained to one area.

  5. Do not use letters that are next to each other on the keyboard.
    An example of this is “qwerty”, which is the first six letters on your keyboard. This is also in the top five commonly used password list. “123456” fits this bill. So does “kkkkkk”.

  6. Do not use an account number as a password.
    This is common sense. Just don’t.

  7. Use as many characters as possible, including capital letters, small letters, numbers & symbols.
    The more characters you use, the harder it will be to crack. Be as creative as possible.

  8. Change your passwords frequently.
    At the very least, change your password every 90 days. At most, every 30 days. Keep them guessing.
Fun Fact #3: Never, ever use the following as a password: “God” (or “god”), “love”, “sex”, “iloveyou”, “tron”, “ncc1701”, “thx1138”, “8675309”, “rosebud”, “letmein”, “7779311”, “666666”, “7777777”, “ou812” or any vulgar word. If you do, I will personally come over and paint the word “IDIOT” on your door.

One method I recommend for creating a tough password is to think of a long phrase, take the first letter of each word, and apply rule #7 to it. So, for example, take the sentence “The quick brown fox jumps over the lazy dog”. Using rule #7, I can get many passwords out of this. The following shows the variations as well as how long it would take to crack:
  • “tqbfjotld” (initials): 6 days
  • “Tqbfjotld” (initials, first letter capital): 8 years
  • “Tqbfj0tld” (initials, first letter capital, zero replacing “o”): 42 years
  • “Tqbfj0t!d” (initials, first letter capital, zero replacing “o”, exclamation point replacing “l”): 237 years
Don’t make it overly complicated. It should be easy enough for you to remember without having to write it down. You should also be able to type it in quickly, which prevents someone from looking over your shoulder and guessing it by what you typed.

So there’s your assignment for the new year. Get to it. And if you’re out there trying to guess what my password is, I wish you good luck. If you’re lucky, it’ll only take you 700 million years, give or take. By then, I won't need it.

Maybe I should give it to Dick Clark.

Thursday, June 3, 2010

It's My Privacy & I'll Tweet It If I Want To

pri·va·cy [prahy-vuh-see; Brit. also priv-uh-see] (noun) - (1.) the state of being private; retirement or seclusion. (2.) the state of being free from intrusion or disturbance in one's private life or affairs. (3) secrecy.

"Relying on the government to protect your privacy is like asking a peeping tom to install your window blinds." (John Perry Barlow)

-----

We are in the age of information, where knowledge is power and your profile is king/queen. The internets (that one's for you, Dubya) is vast and ever-expanding. If you have access to technology, more than likely you will have one, some or all of the following:
  • An e-mail address (or five)
  • A web site
  • A blog
  • A Facebook page (if you're over twenty)
  • A MySpace page (if you don't know better)
  • A Twitter account
Google or Bing can find anything you're looking for with a few keystrokes. The world is yours for the viewing. And all it costs is your privacy.

Yes, your privacy. Everything you are, translated into bytes of raw data and sold off as a commodity.

It's unavoidable. It's already happened.

That's not right, you say. The Constitution guarantees my right to privacy.

Nuh-uh.

I did a bet with someone regarding that very same statement. You can do this, too, kids. Do a Google search on the word Constitution and pick one of the links (I went here). Use the Find command on your browser (you can press Ctrl+F on your keyboard to bring it up). Type in the word "privacy."

It didn't find anything? Surprise, surprise.

(By the way, I got two lunches for winning the bet.)

Privacy is not a guaranteed right. It is somewhat implied, since the Declaration of Independence gives us "certain unalienable Rights, that among these are Life, Liberty and the pursuit of Happiness."

We, the People, like privacy. It makes us feel safe and secure to know that things we like to do is not on display for the public to know. If you like to walk around naked, it's great as long as you do it in your own home. I personally don't want to know about it, which makes privacy a beautiful thing. What you read, write, and do that makes you happy should be personal and sacred, which is what privacy affords all of us.

But in this day and age, privacy is no longer the precious commodity it used to be. With a click of a mouse, a user willingly (but without their knowledge -- what a paradox, huh) leaves bread crumbs behind that can tell people who can interpret those bread crumbs all they need to know about you. Where you shop, what kind of clothes you like to buy, what color you like, and many other assorted information that, in whole, describes you.

Want a 10% discount coupon? Subscribe to this newsletter. Then you wonder what caused your mailbox to get 25 spam messages... an hour.

Want to know when the special sales begin? Subscribe here. Oh, boy. Spam went up to 60 messages now.

You did it.

That's not even mentioning the fact that everyone and their mother is looking for their 15 minutes of fame. Or 140 characters, in Twitter's case. Minute after minute, second after second, someone's telling everyone about their business. TMI taboos are being broken in megabits-per-second speed. C'mon, do I really need to know about the really embarrassing things that celebrities want to let their followers know?

Fun fact #1: The Library of Congress is now archiving Twitter feeds so that future generations can view the social culture of the 21st century. Run. Hide. Now. The Terminators are coming.

Fun fact #2: As of May 2010, Britney Spears has more followers (4,952,552) than Ashton Kutcher (4,945,544).

In the age of information, knowledge is money. And you are worth a lot. Companies pay for this information. Think about it: if you knew that a certain product you sold is desired by 30% of all internet users out there, you can make a killing.

They pay for it. You give it away for free.

Common sense says that because who you are is worth something, you should have some control over how that information is distributed. After all, knowledge is power, right? Oftentimes, the problem is that most common users don't have the knowledge, hence they lack the power to fix the problem.

One of the most recent offenders against privacy is Facebook, which has 400 million active users. Over the years, Facebook has changed their policy several times. Now, they are getting ready to roll out yet another change that would force all of its users to opt-in for privacy instead of automatically having it and getting a lot of heat for it. In layman's terms, it's like renting an apartment, then having to tell the landlord that you need a door and closable windows.

Fun fact #3: Facebook's privacy policy is 5,830 words long. The Constitution, without the amendments, is 4,543.

I found an article that helps to navigate the treacherous waters of Facebook privacy settings. It's a good read and will help provide you, the user, with knowledge (which equals power) to help yourself. Then I order you to Google search ways to keep your electronic privacy.

Take back what is yours. I double dare you.

Oh, and in case you need motivation:
And tell your Friends. Or Followers. Or... whatever they're called.