Showing posts with label Password. Show all posts
Showing posts with label Password. Show all posts

Thursday, February 14, 2013

MyTalk network security breached

“Jambox wireless speaker creator Jawbone is singing the blues today. It alerted users early this morning to a hack on its MyTalk network that left names, email addresses, and encrypted passwords compromised.”



The MyTalk network is platform where they can update, find and download apps for Jawbone devices. A customer has voluntarily reported he has received this message on twitter. It reads “Based on our investigation to date, we do not believe there has been any unauthorized use of login information or unauthorized access to information in your account.”


Jawbone says that “because your password was taken was encrypted and none of “the actual letters and numbers in your password” were revealed, hackers have ways to decrypt information”.



Blowfish13@2013 blowfish12.tk Author: Sudharsun. P. R.




Sunday, January 20, 2013

[Tech] Electronic ring or USB drive as password

Google Plans to implement a secure way to login into your accounts by using USB drives or electronic rings as password rather than the traditional text passwords.

As revealed by Wired, Google VP of security Eric Grosse and engineer Mayank Upadhyay have outlined several ways to rethink the traditional password. The two are responding to the problem of password security. Passwords often don’t provide enough protection as we saw when tech journalist Mat Honan had many of his accounts hacked last August.

“Along with many in the industry, we feel passwords and simple bearer tokens such as cookies are no longer sufficient to keep users safe,” Grosse and Upadhyay write in an upcoming paper for IEEE’s Security & Privacy magazine.

Two ways the Googlers imagine changing the password?

  • A smartphone or smart-card ring that you wear that can authorize a new computer to give you access to certain sites or to the machine itself.

  • Plugging a customized USB drive into the computer while you are browsing that automatically logs you in to sites. When you take out the USB drive, the sites no longer give you access.


While these are just a few ideas, it’s hard to say if they will see the light of day soon or far in the future. In the meantime, security experts agree that you should turn on multi-factor authentication (if you’re offered the chance) to protect your accounts.




Blowfish12@2012 blowfish12.tk Author: Sudharsun. P. R.

How to make a good password

Along with birthdays, names of pets and ascending number sequences, add one more thing to the list of password no-nos: good grammar.


An algorithm developed by Ashwini Rao and colleagues at Carnegie Mellon University in Pittsburgh, Pennsylvania, makes light work of cracking long passwords which make grammatical sense as a whole phrase, even if they are interspersed with numbers and symbols. Rao's algorithm makes guesses by combining words and phrases from password-cracking databases into grammatically correct phrases. While other cracking programs make multiple guesses based on each word in a database, putting in "catscats" and "catsstac" as well as just the word "cats", none of the programs make the jump to combine multiple words or phrases in a way that makes grammatical sense, like "Ihave3cats", for instance.


Ten per cent of the long passwords that Rao and her team tested were cracked exclusively using their grammar-sensitive methods, unyielding in the face of other well-known cracking algorithms such as John the Ripper and Hashcat.


As processing power continues to fall in price, choosing passwords that are easily memorised but secure is getting harder and harder. A $3000 computer running appropriate algorithms can make 33 billion password guesses every second.
In a paper due to be presented at the Conference on Data and Application Security and Privacy in San Antonio, Texas, next month, the researchers suggest that other types of familiar structures like postal addresses, email addresses and URLs may also make for less secure passwords, even if they are long.






Blowfish12@2012 blowfish12.tk Author: Sudharsun. P. R.




Friday, July 13, 2012

Was YOUR Yahoo password hacked? Here’s how to find out

Last night the news broke that Yahoo had a security breach and 435,000 usernames and passwords had been hacked. Particularly troubling? The login credentials are in plaintext, not even encrypted. The biggest question users have when this happens: have MY username and password been released?


A number of services can answer that. One is Should I Change My Password, which has two great features that differentiate it from some others.


One is the ability to check anonymously based on email address, which many people have as their username for online services. This is helpful, because you don’t have to enter your password into the service (which you don’t know if you can trust or not) to check if your password has, indeed, been compromised. Secondly, you can sign up to receive notifications in the future if your email address is ever involved in another hacking incident.


Simply go to Should I Change My Password, and enter your email address:



The site automatically checks you against millions of emails and passwords leaking innumerous security breaches. If your email address is among those that have been hacked and released, this is what you’ll see. (I checked it myself with an old email address that I knew had been previously compromised.)



While investigating the breach and writing my story last night, I personally downloaded a few hundred thousand of the usernames and passwords and tried (unsuccessfully) to log into a number of Yahoo accounts.  This service can give you some confidence that others won’t be trying the same with your private accounts.






Blowfish12@2012 blowfish12.tk Author: Sudharsun. P. R.

Thursday, July 12, 2012

Hackers post 450K credentials apparently pilfered from Yahoo


Credentials posted in plain text appear to have originated from the Web company's Yahoo Voices platform. The hackers say they intended the data dump as a "wake-up call."



Yahoo appears to have been the victim of a security breach that yielded more than hundreds of thousands of login credentials stored in plain text. The hacked data, posted to the hacker site D33D Company, contained more than 453,000 login credentials and appears to have originated from the Web pioneer's network. The hackers, who said they used a union-based SQL injection technique to penetrate the Yahoo subdomain, intended the data dump to be a "wake-up call."


"We hope that the parties responsible for managing the security of this subdomain will take this as a wake-up call, and not as a threat," the hackers said in a comment at the bottom of the data. "There have been many security holes exploited in webservers belonging to Yahoo! Inc. that have caused far greater damage than our disclosure. Please do not take them lightly. The subdomain and vulnerable parameters have not been posted to avoid further damage."


The hacked subdomain appears to belong to Yahoo Voices, according to a TrustedSec report. Hackers apparently neglected to remove the host name from the data. That host name -- dbb1.ac.bf1.yahoo.com -- appears to be associated with the Yahoo Voices platform, which was formerly known as Associated Content.


Because the data is quite sensitive and displayed in plain text, Blowfish12 has elected not to link to the page, although it is not hard to find. However, the page size is very large and takes a while to load.


The disclosure comes at a time of heightened awareness over password security. Recent high-profile password thefts at LinkedIn, eHarmony, and Last.fm contributed to approximately 8 million passwords posted in two separate lists to hacker sites in early June. Yesterday, Formspring announced it had disabled the passwords of its entire user base after discovering about 420,000 hashed passwords that appeared to come from the question-and-answer site were posted to a security forum.






Blowfish12@2012 blowfish12.tk Author: Sudharsun. P. R.




Infolinks In Text Ads