<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Advanced Password Cracking - Insight &#187; Tips &amp; Tricks</title>
	<atom:link href="http://blog.crackpassword.com/category/tips-tricks/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.crackpassword.com</link>
	<description>«...This blog is about &#60;a href=&#34;/?s=password+recovery&#34;&#62;cracking passwords&#60;/a&#62;, &#60;a href=&#34;/?s=forensic&#34;&#62;forensics solutions&#60;/a&#62;,&#60;br&#62;&#60;a href=&#34;/?s=security&#34;&#62;computer and network security&#60;/a&#62;, &#60;a href=&#34;/?s=system+recovery&#34;&#62;system recovery&#60;/a&#62; and other things...»</description>
	<lastBuildDate>Thu, 09 Feb 2012 07:23:11 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>Elcomsoft iOS Forensic Toolkit highlighted in SANS Information Security Reading Room</title>
		<link>http://blog.crackpassword.com/2011/08/elcomsoft-ios-forensic-toolkit-highlighted-in-sans-information-security-reading-room/</link>
		<comments>http://blog.crackpassword.com/2011/08/elcomsoft-ios-forensic-toolkit-highlighted-in-sans-information-security-reading-room/#comments</comments>
		<pubDate>Mon, 15 Aug 2011 13:07:05 +0000</pubDate>
		<dc:creator>Olga Koksharova</dc:creator>
				<category><![CDATA[Cryptography]]></category>
		<category><![CDATA[Did you know that...?]]></category>
		<category><![CDATA[General]]></category>
		<category><![CDATA[Tips & Tricks]]></category>
		<category><![CDATA[Elcomsoft iOS Forensic Toolkit]]></category>
		<category><![CDATA[Elcomsoft Phone Password Breaker]]></category>
		<category><![CDATA[iOS]]></category>
		<category><![CDATA[iOS Forensic Toolkit]]></category>
		<category><![CDATA[passcode]]></category>
		<category><![CDATA[SANS]]></category>

		<guid isPermaLink="false">http://blog.crackpassword.com/?p=1751</guid>
		<description><![CDATA[SANS Information Security Reading Room has recently publicized a whitepaper about iOS security where they mentioned our software &#8211; Elcomsoft iOS Forensic Toolkit &#8211; in a section about encryption. Kiel Thomas, the author of the whitepaper, explained one more time the main principles of iOS 4 encryption, which became stronger in comparison with iOS 3.x [...]]]></description>
			<content:encoded><![CDATA[<p>SANS Information Security Reading Room has recently publicized a <a href="http://www.sans.org/reading_room/whitepapers/pda/security-implications-ios_33724">whitepaper </a>about iOS security where they mentioned our software &#8211; <a href="http://http://www.elcomsoft.com/eift.html">Elcomsoft iOS Forensic Toolkit</a> &#8211; in a section about encryption. Kiel Thomas, the author of the whitepaper, explained one more time the main principles of iOS 4 encryption, which became stronger in comparison with iOS 3.x and how our toolkit can bypass new strong algorithms.</p>
<p>In its next part about iTunes Backups Kiel touches upon<a href="http://www.elcomsoft.com/eppb.html"> Elcomsoft Phone Password Breaker</a> which virtually crunches backup passwords at speed of 35000 passwords per second (with AMD Radeon HD 5970) using both brute force and dictionary attacks, here are some <a href="http://http://www.elcomsoft.com/eppb.html">benchmarks</a>.</p>
<p>It seems the paper does not miss out on any nuance about iOS 4 and provides practical advice to either avoid or prevent from the depressing outcomes, such as loss of data. Closer to the end of the paper you will also find several sagacious tips for using the devices within organizations, including passcode management, a so called &ldquo;first line of defense&rdquo; which according Kiel&rsquo;s view &ldquo;can be matched to existing password policies&rdquo;, however he inclines to use passwords instead of 4 digit passcodes.</p>
<p>And in conclusion the author discovers that smartphone and tablet security measurements resemble the ones of laptops, because they all belong to mobile devices.&nbsp; Find out more details in the source itself: <a href="http://www.sans.org/reading_room/whitepapers/pda/security-implications-ios_33724">http://www.sans.org/reading_room/whitepapers/pda/security-implications-ios_33724</a><br />
&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.crackpassword.com/2011/08/elcomsoft-ios-forensic-toolkit-highlighted-in-sans-information-security-reading-room/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Firefox, Safari, Opera, and Chrome Passwords Cracked</title>
		<link>http://blog.crackpassword.com/2010/11/firefox-safari-opera-and-chrome-passwords-cracked/</link>
		<comments>http://blog.crackpassword.com/2010/11/firefox-safari-opera-and-chrome-passwords-cracked/#comments</comments>
		<pubDate>Thu, 11 Nov 2010 12:38:26 +0000</pubDate>
		<dc:creator>Olga Koksharova</dc:creator>
				<category><![CDATA[Elcom-News]]></category>
		<category><![CDATA[General]]></category>
		<category><![CDATA[Industry News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[Tips & Tricks]]></category>
		<category><![CDATA[Chrome]]></category>
		<category><![CDATA[DES]]></category>
		<category><![CDATA[DPAPI]]></category>
		<category><![CDATA[EINPB]]></category>
		<category><![CDATA[Elcomsoft Distributed Password Recovery]]></category>
		<category><![CDATA[Elcomsoft Internet Password Breaker]]></category>
		<category><![CDATA[Firefox]]></category>
		<category><![CDATA[Network Security Services]]></category>
		<category><![CDATA[Opera]]></category>
		<category><![CDATA[plist]]></category>
		<category><![CDATA[Safari]]></category>
		<category><![CDATA[SQLite]]></category>
		<category><![CDATA[Web Browser]]></category>

		<guid isPermaLink="false">http://blog.crackpassword.com/?p=1446</guid>
		<description><![CDATA[What is a Web browser for you? It&#8217;s virtually a whole world, all together: web sites, blogging, photo and video sharing, social networks, instant messaging, shopping&#8230; did I forget anything? Oh yes, logins and passwords.&#160;:) &#160;Set an account here, sign in there, register here and sing up there &#8211; everywhere you need logins and passwords [...]]]></description>
			<content:encoded><![CDATA[<p>What i<a href="http://blog.crackpassword.com/2010/11/firefox-safari-opera-and-chrome-passwords-cracked/%d1%82%d0%b8%d1%806/" rel="attachment wp-att-1449"><img align="left" alt="" border="8" class="alignleft size-full wp-image-1449" height="298" hspace="8" src="http://blog.crackpassword.com/wp-content/uploads/2010/11/тир6.jpg" title="тир6" vspace="8" width="300" /></a>s a Web browser for you? It&rsquo;s virtually a whole world, all together: web sites, blogging, photo and video sharing, social networks, instant messaging, shopping&hellip; did I forget anything? Oh yes, logins and passwords.&nbsp;:) &nbsp;Set an account here, sign in there, register here and sing up there &ndash; everywhere you need logins and passwords to confirm your identity.</p>
<p>Yesterday, we recovered login and password information to Internet Explorer only, but it was yesterday&hellip; Now, Mozilla Firefox, Apple Safari, Google Chrome and Opera Web browsers are at your disposal.</p>
<p>Let&rsquo;s plunge into some figures&hellip;</p>
<p><span id="more-1446"></span></p>
<p>Imagine, just a couple of years ago there was no Chrome at all and now it captivates <a href="http://www.w3schools.com/browsers/browsers_stats.asp ">more than 19% of users </a>and is the third most popular Web browser. Safari appeared first in 2003 under Mac OS and in 2007 under Windows, now it&rsquo;s the fourth popular Web browser.</p>
<p>A curious scene unfolds before us, IE is constantly losing its followers to the advantage of FireFox and rapidly spreading newcomers like Chrome. However, in spite of all these browser wars, any statistical data can only be relatively true and I&rsquo;m sure we all use more than one Web browser (I use three at least).</p>
<p>Some of them are at hand because they are default browsers like Safari on iPhones and iPads, some of them are more convenient for Web designing, and some run under Linux and Mac OS X as well.</p>
<p>That&rsquo;s why we decided to crack other browsers as well. BTW, our CTO Andy Malyshev claims that compared to IE 8 protection all the other browsers were just &ldquo;a piece of cake&rdquo;. <img src='http://blog.crackpassword.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>Just if you&rsquo;re curious, different Web browsers store their data (including logins and passwords to web sites) in different formats. In Apple Safari, it is <a href="http://en.wikipedia.org/wiki/Property_List">Property List (plist</a>), in versions up to 3.x (incl.), that was just a plain XML which is easy to parse. In Safari 4 and 5, it is in binary form (though organized very similar internally). Encryption is done with <a href="http://msdn.microsoft.com/en-us/library/ms995355.aspx">DPAPI</a>.</p>
<p>Mozilla Firefox: up to version 3.5, they stored everything in plain text; starting with version 3.5 &ndash; in <a href="http://en.wikipedia.org/wiki/SQLite">SQLite</a> databases. Everything is encrypted there (yes, in old text files, too) using their own API called<a href="http://en.wikipedia.org/wiki/Network_Security_Services"> Network Security Services (NSS).</a></p>
<p>In Google Chrome SQLite is used as a storage and DPAPI for encryption.</p>
<p>Opera: proprietary (binary) file format whereas encryption is done with <a href="http://en.wikipedia.org/wiki/DES">DES</a>.</p>
<p>Now it&rsquo;s easy to get back account information, logins, passwords and cached forms in all browsers like IE, Apple Safari, Google Chrome, Opera, and Mozilla Firefox, as well as Microsoft Outlook, Outlook Express, Windows Mail and Windows Live Mail.</p>
<p>However, there is a trick with Mozilla Firefox&hellip;if it has a master password, your only prey will be URLs, unless you know the required master password&hellip;OR have <a href="http://www.elcomsoft.com/edpr.html">Elcomsoft Distributed Password Recovery </a>which deals with such passwords. <img src='http://blog.crackpassword.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>One more trick with Firefox (quite a tricky browser, isn&rsquo;t it?) is that unlike the others it should be installed itself, because EINPB refers to some of its dll-files.</p>
<p>As we&rsquo;ve seen, the tendency is to use several browsers, or better said switching from IE to other ones, which implies some problems with switching some details (such as name, address, or whatever else) cached in your previous Web browser and happily forgotten. This is a frequent scenario &ndash; I personally found myself in similar situation a couple of days ago, when I had to reach an online account (which login and password are cached) from another browser and couldn&rsquo;t&hellip;but my situation was even worse because I used different computers. Anyway, this won&rsquo;t bother you anymore, because EINPB can pull all data from your old browser and gather it in one file.&nbsp;</p>
<p>So, let us not dampen our joy over browser wars as they are not finished yet and appease our hunger for new browsers (?) We also get influenced by popular opinion, so tell us your browser preferences and maybe we&rsquo;ll crack them too. <img src='http://blog.crackpassword.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
]]></content:encoded>
			<wfw:commentRss>http://blog.crackpassword.com/2010/11/firefox-safari-opera-and-chrome-passwords-cracked/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Hacking For Dummies, 3rd Edition by Kevin Beaver</title>
		<link>http://blog.crackpassword.com/2010/11/hacking-for-dummies-3rd-edition-by-kevin-beaver-2/</link>
		<comments>http://blog.crackpassword.com/2010/11/hacking-for-dummies-3rd-edition-by-kevin-beaver-2/#comments</comments>
		<pubDate>Tue, 02 Nov 2010 09:54:06 +0000</pubDate>
		<dc:creator>Olga Koksharova</dc:creator>
				<category><![CDATA[Did you know that...?]]></category>
		<category><![CDATA[General]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[Tips & Tricks]]></category>
		<category><![CDATA[Advanced Archive Password Recovery]]></category>
		<category><![CDATA[Elcomsoft Distributed Password Recovery]]></category>
		<category><![CDATA[Elcomsoft System Recovery]]></category>
		<category><![CDATA[Elcomsoft Wireless Security Auditor]]></category>
		<category><![CDATA[Encryption]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[Hacking for Dummies]]></category>
		<category><![CDATA[Kevin Beaver]]></category>
		<category><![CDATA[password]]></category>
		<category><![CDATA[password recovery]]></category>
		<category><![CDATA[Proactive Password Auditor]]></category>

		<guid isPermaLink="false">http://blog.crackpassword.com/?p=1421</guid>
		<description><![CDATA[Although this new book is on sale from January this year, we are happy to officially say our words of gratitude to Kevin Beaver and advise it to you. In his book Kevin insists that the best way to really understand how to protect your systems and assess their security is to think from a [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://blog.crackpassword.com/2010/11/hacking-for-dummies-3rd-edition-by-kevin-beaver-2/attachment/0470550937/" rel="attachment wp-att-1424"><img align="left" alt="" border="5" class="alignleft size-full wp-image-1424" height="250" hspace="8" src="http://blog.crackpassword.com/wp-content/uploads/2010/11/0470550937.jpg" title="0470550937" vspace="8" width="200" /></a>Although this new <a href="http://www.amazon.com/reader/0470550937?_encoding=UTF8&amp;ref_=sib_dp_pt#reader-link">book</a> is on sale from January this year, we are happy to officially say our words of gratitude to Kevin Beaver and advise it to you.</p>
<p>In his book Kevin insists that the best way to really understand how to protect your systems and assess their security is to think from a hacker&rsquo;s viewpoint, get involved, learn how systems can be attacked, find and eliminate their vulnerabilities.&nbsp; It all practically amounts to being inquisitive and focusing on real problems as in contrast to blindly following common security requirements without understanding what it&rsquo;s all about.</p>
<p>Kevin extensively writes on the questions of cracking passwords and weak encryption implementations in widely used operating systems, applications and networks. He also suggests Elcomsoft software, in particular <a href="http://http://elcomsoft.com/archpr.html">Advanced Archive Password Recovery</a>, <a href="http://http://elcomsoft.com/edpr.html">Elcomsoft Distributed Password Recovery</a>, <a href="http://elcomsoft.com/esr.html">Elcomsoft System Recovery</a>, <a href="http://elcomsoft.com/ppa.html">Proactive Password Auditor</a>, and <a href="http://elcomsoft.com/ewsa.html">Elcomsoft Wireless Security Auditor</a>, as effective tools to regularly audit system security and close detected holes.</p>
<p>In this guide Kevin communicates the gravity of ethical hacking in very plain and clear words and gives step &ndash;by- step instructions to follow. He easily combines theory and praxis providing valuable tips and recommendations to assess and then improve security weaknesses in your systems.</p>
<p>We want to thank Kevin for testing and including our software in his very &ldquo;digestible&rdquo; beginner guide to hacking and recommend our readers this <a href="http://www.amazon.com/reader/0470550937?_encoding=UTF8&amp;ref_=sib_dp_pt#reader-link">book</a> as a helpful tool to get all facts in order. <img alt=":)" height="20" src="http://blog.crackpassword.com/wp-content/plugins/fckeditor-for-wordpress-plugin/ckeditor/plugins/smiley/images/regular_smile.gif" title=":)" width="20" /></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.crackpassword.com/2010/11/hacking-for-dummies-3rd-edition-by-kevin-beaver-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ATI is at it. Again.</title>
		<link>http://blog.crackpassword.com/2010/05/ati-is-at-it-again-2/</link>
		<comments>http://blog.crackpassword.com/2010/05/ati-is-at-it-again-2/#comments</comments>
		<pubDate>Wed, 12 May 2010 10:37:42 +0000</pubDate>
		<dc:creator>Andrey Belenko</dc:creator>
				<category><![CDATA[Hardware]]></category>
		<category><![CDATA[Tips & Tricks]]></category>
		<category><![CDATA[ATI]]></category>
		<category><![CDATA[ATI Stream]]></category>
		<category><![CDATA[Catalyst]]></category>

		<guid isPermaLink="false">http://blog.crackpassword.com/2010/05/ati-is-at-it-again-2/</guid>
		<description><![CDATA[Two months ago I wrote a blog post &#34;ATI and NVIDIA: Making Friends out of Enemies&#34; where (among other things) I wrote: Developing software for ATI cards is (okay — was) a nightmare. In 2009 ATI quietly introduced two changes in their drivers which made previously perfectly functional and compatible applications to crash (if you [...]]]></description>
			<content:encoded><![CDATA[<p>Two months ago I wrote a blog post <a href="http://blog.crackpassword.com/2010/03/ati-and-nvidia-making-friends-out-of-enemies/">&quot;ATI and NVIDIA: Making Friends out of Enemies&quot;</a> where (among other things) I wrote:</p>
<blockquote><p>Developing software for ATI cards is (okay — was) a nightmare. In 2009 ATI quietly introduced two changes in their drivers which made previously perfectly functional and compatible applications to crash (if you are curious: with Catalyst 9.2 or 9.3 they&#8217;ve changed names of supporting DLLs bundled with drivers; with Catalyst 9.9 or 9.10 they&#8217;ve probably changed format of underlying binary so that anything compiled and linked in with earlier versions caused a driver to crash).</p>
</blockquote>
<p>Well, with the release of Catalyst 10.4 drivers ATI is again at it. This time problem only affects users who have display adapters from different vendors in their computer. Applications utilizing ATI Stream will work on such configurations just fine with Catalyst 10.3, but once you upgrade to 10.4, applications will crash with faulting module being aticaldd.dll, a part of ATI Display driver. Kinda embarrassing, I would say. Regression testing is really something one with millions of users should consider.</p>
<p>Users of our software relying on ATI hardware accelerations (as well as any other ATI Stream enabled applications) should not update to 10.4 if ATI Readeon is not the only card in their computer.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.crackpassword.com/2010/05/ati-is-at-it-again-2/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Advanced Office Password Recovery: customizing the preliminary attack</title>
		<link>http://blog.crackpassword.com/2009/08/advanced-office-password-recovery-customizing-the-preliminary-attack/</link>
		<comments>http://blog.crackpassword.com/2009/08/advanced-office-password-recovery-customizing-the-preliminary-attack/#comments</comments>
		<pubDate>Tue, 04 Aug 2009 20:10:23 +0000</pubDate>
		<dc:creator>Andrey Malyshev</dc:creator>
				<category><![CDATA[Software]]></category>
		<category><![CDATA[Tips & Tricks]]></category>

		<guid isPermaLink="false">http://blog.crackpassword.com/?p=963</guid>
		<description><![CDATA[&#160;Every time when you open a document in Advanced Office Password Recovery it performs the preliminary attack in case when the &#34;file open&#34; password is set. This attack tries all passwords that you recovered in past (which are stored in password cache), dictionary attack and finally the brute-force attack is running. The brute-force attack consists [...]]]></description>
			<content:encoded><![CDATA[<p>&nbsp;Every time when you open a document in <a href="http://www.elcomsoft.com/aopr.html">Advanced Office Password Recovery</a> it performs the <a href="http://www.elcomsoft.com/help/aopr/prelattack.htm">preliminary attack </a>in case when the &quot;file open&quot; password is set. This attack tries all passwords that you recovered in past (which are stored in password cache), dictionary attack and finally the brute-force attack is running.</p>
<p>The brute-force attack consists of two parts:</p>
<p>1. Trying digits and latin letters<br />
2. Trying national characters depending on code page set in Windows.</p>
<p>Before this time these parts were hardcoded in the program. The new version of Advanced Office Password Recovery has an option to customize the preliminary brute-force attack.&nbsp;</p>
<p>Look to the directory where AOPR is installed. There is <strong>&quot;attacks.xml&quot;</strong> file inside. The first section of this file is the language map:</p>
<p><img width="236" height="117" alt="" src="/userfiles/2009-08-04_235815.gif" /></p>
<p>The codes are Windows <a href="http://msdn.microsoft.com/en-us/library/aa912040.aspx">language identifiers</a>. You can link any LID to your custom name.</p>
<p>The next section contains predefined charsets:</p>
<p><img width="511" height="74" alt="" src="/userfiles/attack_xml_charsets(1).gif" /></p>
<p>All charsets are in unicode so you can define any national characters here.</p>
<p>And the final section is &quot;documents&quot;. All parts of this section has comments about document types. You can define the &quot;common&quot; charsets and charsets that are related to system language. Each &quot;attack&quot; record defines password length and charset.</p>
<p>In this XML file you can simply change the standard preliminary attack and define the custom charsets for your language. I hope this will help to recover your Office passwords faster.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.crackpassword.com/2009/08/advanced-office-password-recovery-customizing-the-preliminary-attack/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Password masking: myths and truths</title>
		<link>http://blog.crackpassword.com/2009/07/password-masking-myths-and-truths/</link>
		<comments>http://blog.crackpassword.com/2009/07/password-masking-myths-and-truths/#comments</comments>
		<pubDate>Tue, 07 Jul 2009 12:10:02 +0000</pubDate>
		<dc:creator>Vladimir Katalov</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Human Factor]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[Tips & Tricks]]></category>
		<category><![CDATA[Bruce Schneier]]></category>
		<category><![CDATA[Jakob Nielsen]]></category>
		<category><![CDATA[password masking]]></category>
		<category><![CDATA[password recovery]]></category>
		<category><![CDATA[password security]]></category>
		<category><![CDATA[passwords]]></category>
		<category><![CDATA[PGP]]></category>

		<guid isPermaLink="false">http://blog.crackpassword.com/?p=932</guid>
		<description><![CDATA[Ever heard of password masking problem? To be honest, I have not &#8211; until I&#8217;ve read the Stop Password Masking article by Jakob Nielsen (somewhere referred to as &#34;usability guru&#34;), followed by a lot of other publications, blog posts and comments&#160;(see &#8216;em all); so-called security guru Bruce Schneier wrote even two essays on that.&#160; Well, [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: left"><img height="185" alt="Password masking: myths and truths" width="250" align="right" src="http://blog.crackpassword.com/wp-content/uploads/logon1(1).jpg" />Ever heard of <em>password masking problem</em>? To be honest, I have not &#8211; until I&#8217;ve read the <a target="_blank" href="http://www.useit.com/alertbox/passwords.html">Stop Password Masking</a> article by Jakob Nielsen (somewhere referred to as &quot;usability guru&quot;), followed by a lot of <a target="_blank" href="http://news.google.com/news/more?um=1&amp;ned=us&amp;cf=all&amp;ncl=dwqAJ-C3YMdrX2M3vePtw0Aq773fM">other publications</a>, <a target="_blank" href="http://blogsearch.google.com/blogsearch?q=password%20masking">blog posts</a> and <a target="_blank" href="http://blogs.techrepublic.com.com/security/?p=1866#comments">comments</a>&nbsp;(see &#8216;em <a target="_blank" href="http://www.google.com/search?sourceid=navclient&amp;q=%22Stop+Password+Masking%22">all</a>); so-called <em><a target="_blank" href="http://www.securityfocus.com/archive/1/416873/30/0/threaded">security</a> <a target="_blank" href="http://www.securityfocus.com/archive/82/428738/30/450/threaded">guru</a></em> Bruce Schneier wrote even <a target="_blank" href="http://www.schneier.com/blog/archives/2009/06/the_problem_wit_2.html">two</a> <a target="_blank" href="http://www.schneier.com/blog/archives/2009/07/the_pros_and_co.html">essays</a> on that.&nbsp;</p>
<p style="text-align: left">Well, that reminded me of a very&nbsp;<strike>funny</strike> stupid <a target="_blank" href="http://capsoff.blogspot.com/">CAPSoff Campaign</a>&#8230;</p>
<p>In brief, here is the &quot;problem&quot;: for years (I think starting from Windows 3.0 released almost 20 years ago), the passwords are being masked as you type them (in most programs what have any kind of password protection, and an operating system itself), i.e. replaced with asterisks or black circles. What for? To prevent the password from being read by someone who stands behind you.</p>
<p><span id="more-932"></span>An implementation is really simple: all you have to do is set the <a target="_blank" href="http://msdn.microsoft.com/en-us/library/bb775458(VS.85).aspx">ES_PASSWORD style</a> for the given <a target="_blank" href="http://msdn.microsoft.com/en-us/library/bb775464(VS.85).aspx">Edit control</a>.</p>
<p>Does that feature add some security? Yes, I think so. Though it does not protect from keyloggers. Besides, the content of the masked edit control (i.e. the password) can be easily read by other software: e.g. look at <a target="_blank" href="http://www.elcomsoft.com/help/pspr/behindasterisks.htm">Behind asterisks</a> feature available in <a target="_blank" href="http://www.elcomsoft.com/pspr.html">Proactive System Password Recovery</a> &#8211; with it, you can &quot;unmask&quot; all controls in all programs currently running, and even enable disabled (grayed out) buttons and menu items.</p>
<p>However, Nielsen says that password masking causes more errors, and second, even <em>reduces</em> the security. I can see the first point: yes, if you don&#8217;t see what you type, it is easier to make a typo. But all well-designed programs (like <a target="_blank" href="http://blog.crackpassword.com/2009/04/what-does-the-only-way-to-break-into-pgp-mean/">PGP</a>) have an option to [un]mask the password field, or at least ask you to enter the password twice (I doubt you can make exactly the same typo two times).</p>
<p>The second point is much harder to understand:</p>
<p style="margin-left: 40px"><em>&quot;The more uncertain users feel about typing passwords, the more likely they are to (a) employ overly simple passwords and/or (b) copy-paste passwords from a file on their computer. Both behaviors lead to a true loss of security.&quot;</em></p>
<p>True? Yes, definitely. But no connection to password masking. I don&#8217;t feel uncertain when entering something into the masked box, really. And most users select short/simple passwords anyway, and/or write them down &#8211; regardless the usability issues discussed here <img src='http://blog.crackpassword.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p>I see another problem, though &#8211; related to non-US keyboards. You may have the keyboard layout switched to other (than default) language&#8230; Or the CapsLock switched on. However, well-designed systems will bring your attention about layout and CapsLock (e.g.: Windows logon prompt).</p>
<p>And finally&#8230; Most (if not all) email clients and instant messengers have an option to &quot;remember&quot; the passwords (and yes, it is convenient &#8211; you don&#8217;t have to enter it every time when you connect). And if the password is saved, you can see the asterisks only (in program options, or in &#8216;connection&#8217; window), so you feel secure &#8211; someone who get the physical access to your computer will be able to get your mail and connect to your IM account, but cannot get your password. Right? Wrong. Unfortunately, most programs save the plaintext passwords, or use &#8216;snake-oil&#8217; encryption, and so can be easily extracted by programs like <a target="_blank" href="http://www.elcomsoft.com/ambpr.html">Advanced Mailbox Password Recovery</a> and <a target="_blank" href="http://www.elcomsoft.com/aimpr.html">Advanced IM Password Recovery</a>. The only (good) exceptions are ICQ version 6 and higher, Yahoo! IM version 7.5 and up, and all versions of Skype &#8211; they save not the password itself, but its hash (which is really hard &#8211; and sometimes impossible &#8211; to recover the plaintext from). This (stroring the passwords) IS the real security problem. Password masking is NOT.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.crackpassword.com/2009/07/password-masking-myths-and-truths/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Disaster Recovery and its key objectives</title>
		<link>http://blog.crackpassword.com/2009/07/disaster-recovery-and-its-key-objectives/</link>
		<comments>http://blog.crackpassword.com/2009/07/disaster-recovery-and-its-key-objectives/#comments</comments>
		<pubDate>Mon, 06 Jul 2009 14:58:45 +0000</pubDate>
		<dc:creator>Olga Koksharova</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[Tips & Tricks]]></category>
		<category><![CDATA[Advanced EFS Data Recovery]]></category>
		<category><![CDATA[Disaster Recovery]]></category>
		<category><![CDATA[DRP]]></category>
		<category><![CDATA[Elcomsoft System Recovery]]></category>
		<category><![CDATA[NIST]]></category>
		<category><![CDATA[Security Standards]]></category>

		<guid isPermaLink="false">http://blog.crackpassword.com/?p=922</guid>
		<description><![CDATA[New statistics* shows disaster recovery (DR) is getting more attention, and more upper level execs become involved with DR issues. Ideally, each company should have an emergency plan in case of power/system failure, loss of access, outside attack, sabotage or else &#8211; called DRP (disaster recovery plan) or even DRRP (disaster response and recovery plan). [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: right"><img height="188" alt="Disaster Recovery and its key objectives" width="206" align="right" src="http://blog.crackpassword.com/wp-content/uploads/human.gif" /></p>
<p>New statistics* shows disaster recovery (DR) is getting more attention, and more upper level execs become involved with DR issues. Ideally, each company should have an emergency plan in case of power/system failure, loss of access, outside attack, sabotage or else &ndash; called DRP (disaster recovery plan) or even DRRP (disaster response and recovery plan). DRP is only a part of risk management practices which ensure emergency preparedness and risk reduction and include such initiatives as regular data backups, stocking recovery software, archiving, etc. &#8211; these activities are reflected in PMI and NIST standards.</p>
<p><span id="more-922"></span>Contrary to risk management DRP is meant for providing clear-cut instructions in case of emergency, indicating activities required to recover the critical data or services and optionally people responsible for these activities (if not mentioned in other directives) , and thus should be clear and concise, take a look at <a target="_blank" href="http://www.continuitycentral.com/images/siemens1large.gif">the DRP diagram</a>. There are two main recovery objectives.</p>
<p>First is <strong><em>the recovery time objectiv</em></strong>e meaning how long a business can continue to function without the critical data or services. And the survey results* show the recovery time objectives are currently reduced to 4 hours.</p>
<p>Second one is <strong><em>the recovery point objective</em></strong> which stands for from what time can an organization recover damaged or lost data, which practically means how often an organization should back up their data and how much info they are prepared to lose. In this respect Symantec survey* demonstrates that more than a third of virtual environments do not back up their data on a regular basis, explaining this by absence of good automation.</p>
<p>In a disaster recovery situation a formula &ldquo;time is money&rdquo; gets its critical point, as you have limited time not only to restore and get in order your data, but also to find necessary means for this. Hopefully, the DRP specifies all necessary contacts and services to help you avoid taking unwise steps in a rush.</p>
<p>Another time-dependent problem appears to be testing and absence of necessary resources for regular tests. According to the report results the most popular reason why companies are unwilling to do testing is because of a lack of resources in terms of people&rsquo;s time (48 % respondents)*.</p>
<p>Relying on their previous studies Symantec claims lack of resources is a general problem throughout many years. I agree with them that introducing tools for easy regular audit and recovery minimizes human involvement and reduces the need to turn to third party services. What I&rsquo;m also driving at is that our <a target="_blank" href="http://www.elcomsoft.com/products.html"><strong>tools</strong></a> are good both for regular password audit and urgent data recovery, e.g. <a target="_blank" href="http://www.elcomsoft.com/esr.html">Elcomsoft System Recovery</a> or<a target="_blank" href="http://www.elcomsoft.com/aefsdr.html"> Advanced EFS Data Recovery</a>.</p>
<p>*Symantec&rsquo;s fifth annual <a href="http://www.symantec.com/about/news/release/article.jsp?prid=20090630_01">IT Disaster Recovery survey</a></p>
<p>** <a target="_blank" href="http://www.continuitycentral.com/feature0524.htm">The IT disaster recovery plan</a></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.crackpassword.com/2009/07/disaster-recovery-and-its-key-objectives/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>The U.S. statutes on password related crimes &#8211; overview by states</title>
		<link>http://blog.crackpassword.com/2009/06/the-u-s-statutes-on-password-related-crimes-overview-by-states/</link>
		<comments>http://blog.crackpassword.com/2009/06/the-u-s-statutes-on-password-related-crimes-overview-by-states/#comments</comments>
		<pubDate>Thu, 18 Jun 2009 11:29:20 +0000</pubDate>
		<dc:creator>Olga Koksharova</dc:creator>
				<category><![CDATA[Did you know that...?]]></category>
		<category><![CDATA[General]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Tips & Tricks]]></category>
		<category><![CDATA[computer cryme]]></category>
		<category><![CDATA[computer fraud]]></category>
		<category><![CDATA[Computer password disclosure]]></category>
		<category><![CDATA[computer trespass]]></category>
		<category><![CDATA[identity theft]]></category>
		<category><![CDATA[password]]></category>

		<guid isPermaLink="false">http://blog.crackpassword.com/?p=829</guid>
		<description><![CDATA[In this entry I&#8217;d like&#160;to suggest a kind of a list of various legal decisions on password [ab]use I could find on the web. Your add-ins are welcome, just&#160;put in&#160;any other acts you know&#8230; Georgia Computer Systems Protection Act (e) Computer Password Disclosure. Any person who discloses a number, code, password, or other means of [...]]]></description>
			<content:encoded><![CDATA[<p>In this entry I&#8217;d like&nbsp;to suggest a kind of a list of various legal decisions on password [ab]use I could find on the web. Your add-ins are welcome, just&nbsp;put in&nbsp;any other acts you know&hellip;</p>
<div style="margin: 0pt 0pt 10pt"><b>Georgia Computer Systems Protection Act</b></div>
<div style="margin: 0pt 0pt 10pt">(e) <i>Computer Password Disclosure</i>. Any person who discloses a number, code, <i><u>password</u></i>, or other means of access to a computer or computer network knowing that such disclosure is without authority and which results in damages (including the fair market value of any services used and victim expenditure) to the owner of the computer or computer network in excess of $500.00 shall be guilty of the crime of computer password disclosure.</div>
<div style="margin: 0pt 0pt 10pt"><span id="more-829"></span>(2) Any person convicted of computer password disclosure shall be fined not more than $5,000.00 or incarcerated for a period not to exceed one year, or both.</div>
<div style="margin: 0pt 0pt 10pt">Georgia Code 16-9-90, 91, 92, 93, 93.1, 94 &#8211; Computer Crime, Computer Theft, Computer Trespass,</div>
<div style="margin: 0pt 0pt 10pt"><a target="_blank" href="http://www.legis.ga.gov/legis/2003_04/gacode/16-9-93.html ">http://www.legis.ga.gov/legis/2003_04/gacode/16-9-93.html </a></div>
<div style="margin: 0pt 0pt 10pt"><b>Hawaii</b> <b>Computer Crime Statute</b></div>
<div style="margin: 0pt 0pt 10pt">&sect;708 &#8211; <i>Computer fraud in the second degree.</i></div>
<div style="margin: 0pt 0pt 10pt">(1) A person commits the offense of computer fraud in the second degree if the person knowingly, and with the intent to defraud, transfers, or otherwise disposes of, to another, or obtains control of, with the intent to transfer or dispose of, any <i><u>password</u></i> or similar information through which a computer, computer system, or computer network may be accessed.</div>
<div style="margin: 0pt 0pt 10pt"><a target="_blank" href="http://www.hawaii.edu/infotech/policies/policyframes/appendixa.html ">http://www.hawaii.edu/infotech/policies/policyframes/appendixa.html </a></div>
<div style="margin: 0pt 0pt 10pt"><b>Kansas Statutes: Computer crime; computer password disclosure; computer trespass [Statute 21-3755]</b></div>
<div style="margin: 0pt 0pt 10pt">(c) (1) <i>Computer password disclosure</i> is the unauthorized and intentional disclosure of a number, code, <i><u>password</u></i> or other means of access to a computer or computer network.</div>
<div style="margin: 0pt 0pt 10pt">(2) <i>Computer password disclosure</i> is a class A nonperson misdemeanor.</div>
<div style="margin: 0pt 0pt 10pt"><a target="_blank" href="http://kansasstatutes.lesterama.org/Chapter_21/Article_37/21-3755.html ">http://kansasstatutes.lesterama.org/Chapter_21/Article_37/21-3755.html </a></div>
<div style="margin: 0pt 0pt 10pt"><b>Mississippi Code: Computer Crime and Identity Theft </b></div>
<div style="margin: 0pt 0pt 10pt">SEC. 97-45-5. Offense against computer users; penalties.</div>
<div style="margin: 0pt 0pt 10pt">&nbsp;(b) Use or disclosure to another, without consent, of the numbers, codes, <i><u>passwords</u></i> or other means of access to a computer, a computer system, a computer network or computer services.</div>
<div style="margin: 0pt 0pt 10pt">&hellip;(2) Whoever commits an offense against computer users shall be punished, upon conviction, by a fine of not more than One Thousand Dollars ($1,000.00), or by imprisonment for not more than six (6) months, or by both such fine and imprisonment. However, when the damage or loss amounts to a value of One Hundred Dollars ($100.00) or more, the offender may be punished, upon conviction, by a fine of not more than Ten Thousand Dollars ($10,000.00), or imprisonment for not more than five (5) years, or by both such fine and imprisonment.</div>
<div style="margin: 0pt 0pt 10pt"><a target="_blank" href="http://www.mscode.com/free/statutes/97/045/0005.htm ">http://www.mscode.com/free/statutes/97/045/0005.htm </a></div>
<div style="margin: 0pt 0pt 10pt"><b>Missouri Revised Statutes [Section 569.095]</b></div>
<div style="margin: 0pt 0pt 10pt">569.095. 1. A person commits the crime of tampering with computer data if he knowingly and without authorization or without reasonable grounds to believe that he has such authorization:</div>
<div style="margin: 0pt 0pt 10pt">&hellip;(4) Discloses or takes a <i><u>password</u></i>, identifying code, personal identification number, or other confidential information about a computer system or network that is intended to or does control access to the computer system or network;</div>
<div style="margin: 0pt 0pt 10pt"><a target="_blank" href="http://www.moga.mo.gov/statutes/c500-599/5690000095.htm">http://www.moga.mo.gov/statutes/c500-599/5690000095.htm</a></div>
<div style="margin: 0pt 0pt 10pt"><b>Pennsylvania Statute Title 18 &sect; 3933 &#8211; Unlawful use of computer.</b></div>
<div style="margin: 0pt 0pt 10pt">&nbsp;(a) Offense defined.&#8211;A person commits the offense of unlawful use of a computer if he, whether in person, electronically or through the intentional distribution of a computer virus:</div>
<div style="margin: 0pt 0pt 10pt">&hellip;3. intentionally or knowingly and without authorization gives or publishes a <i><u>password</u></i><b>,</b> identifying code, personal identification number or other confidential information about a computer, computer system, computer network or data base.</div>
<div style="margin: 0pt 0pt 10pt"><a target="_blank" href="http://www.cybertelecom.org/states/pa.htm">http://www.cybertelecom.org/states/pa.htm</a></div>
<div style="margin: 0pt 0pt 10pt"><b>South Dakota Statute</b></div>
<div style="margin: 0pt 0pt 10pt">CHAPTER 43-43B COMPUTER PROGRAMS</div>
<div style="margin: 0pt 0pt 10pt">43-43B-1. Unlawful uses of computer system. A person is guilty of unlawful use of a computer system, software, or data if the person:</div>
<div style="margin: 0pt 0pt 10pt">&hellip; (3) Knowingly copies or obtains information from a computer system, or compromises any security controls for the computer system, or uses or discloses to another, or attempts to use or disclose to another, the numbers, codes, <i><u>passwords</u></i>, or other means of access to a computer system without the consent of the owner;</div>
<div style="margin: 0pt 0pt 10pt"><a target="_blank" href="http://legis.state.sd.us/statutes/DisplayStatute.aspx?Type=Statute&amp;Statute=43-43B-1">http://legis.state.sd.us/statutes/DisplayStatute.aspx?Type=Statute&amp;Statute=43-43B-1 </a></div>
<div style="margin: 0pt 0pt 10pt"><b>Arkansas Code</b></div>
<div style="margin: 0pt 0pt 10pt">5-41-206. <i>Computer password disclosure</i>.</div>
<div style="margin: 0pt 0pt 10pt">(a) A person commits <i>computer password disclosure</i> if the person purposely and without authorization discloses a number, code, <i><u>password</u></i>, or other means of access to a computer or computer network.</div>
<div style="margin: 0pt 0pt 10pt">(b) Computer password disclosure is a Class A misdemeanor.</div>
<div style="margin: 0pt 0pt 10pt">(c) If the violation of subsection (a) of this section was committed to devise or execute a scheme to defraud or illegally obtain property, the person is guilty of a Class D felony.</div>
<div style="margin: 0pt 0pt 10pt"><a target="_blank" href="http://www.spamlaws.com/state/ar.shtml">http://www.spamlaws.com/state/ar.shtml</a></div>
<div style="margin: 0pt 0pt 10pt"><b>Colorado Statute</b></div>
<div style="margin: 0pt 0pt 10pt">18&minus;5.5&minus;102 &minus; Computer crime.</div>
<div style="margin: 0pt 0pt 10pt">(1) A person commits computer crime if the person knowingly:</div>
<div style="margin: 0pt 0pt 10pt">&hellip;(c) Accesses any computer, computer network, or computer system, or any part thereof to obtain, by means of false or fraudulent pretenses, representations, or promises, money; property; services; <i><u>passwords </u></i>or similar information through which a computer, computer network, or computer system or any part thereof may be accessed; or other thing of value;</div>
<div style="margin: 0pt 0pt 10pt"><a target="_blank" href="http://www.internetlibrary.com/statuteitem.cfm?Num=14">http://www.internetlibrary.com/statuteitem.cfm?Num=14</a></div>
]]></content:encoded>
			<wfw:commentRss>http://blog.crackpassword.com/2009/06/the-u-s-statutes-on-password-related-crimes-overview-by-states/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Using Passwords Online</title>
		<link>http://blog.crackpassword.com/2009/06/using-passwords-online/</link>
		<comments>http://blog.crackpassword.com/2009/06/using-passwords-online/#comments</comments>
		<pubDate>Mon, 01 Jun 2009 11:05:34 +0000</pubDate>
		<dc:creator>Olga Koksharova</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Human Factor]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[Tips & Tricks]]></category>
		<category><![CDATA[AIEPR]]></category>
		<category><![CDATA[online passwords]]></category>
		<category><![CDATA[password recovery]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[secret questions]]></category>

		<guid isPermaLink="false">http://blog.crackpassword.com/?p=711</guid>
		<description><![CDATA[&#160;Today&#8217;s technologies allow staying online practically 24 hrs a day, periodically falling into a sleeping mode. The Internet became easily accessible and numerous devices can connect us to the web from everywhere, and every time when we surf the web we are being registered, at least via IP address of our devices.&#160; I bet it [...]]]></description>
			<content:encoded><![CDATA[<p>&nbsp;Today&rsquo;s technologies allow staying online practically 24 hrs a day, periodically falling into a sleeping mode. The Internet became easily accessible and numerous devices can connect us to the web from everywhere, and every time when we surf the web we are being registered, at least via IP address of our devices.&nbsp;</p>
<p>I bet it was more than once that you had to fill out a sort of name-company-position-email-telephone-whatever form when registering or subscribing to something. Do you think about preserving privacy of your information when leaving such data on someone&rsquo;s website? <span id="more-711"></span>It is a common experience which gradually became an axiom that anything you leave in the Internet sooner or later becomes public. Hopefully you <strong>do not try your fortune and do not use your registration data anywhere in your passwords</strong>. Besides, when registering please be careful about your <a target="_blank" href="http://blog.crackpassword.com/2009/05/secret-questions-are-vulnerable-to-guessing-attacks-study-says/">&ldquo;secret questions&rdquo;</a> and your secret answers, because most of your answers (like mother&rsquo;s maiden name, favorite football team&hellip;) can be guessed in different ways.&nbsp;</p>
<p>The term <strong>phishing</strong> must be familiar to you as it became sort of buzz word, but still the meaning is that fake websites (usually copies of some popular existing ones) are being created to gather personal data like names, telephone numbers, e-mail addresses and sensitive information like passwords or credit card numbers. But they are not necessarily site-duplicates; it can be an absolutely new and original website which gathers users&rsquo; info under color of download resource or any service opportunity.&nbsp;</p>
<p>There is no such term as overcautiousness regarding user authentication. A password like <em>GxOxD#P$@$w0rD</em> may be good enough for a PDF file with 128-bit encryption, but bad for an online account for several reasons: first, an online account password can be tried for any other your accounts and/or protected files <em>(what if you used the same one?)</em>; second, you can easily forget such a difficult password yourself, while there is no need to make it so complex because there are no programs for online passwords&rsquo; recovery (provided they are not captured by the turned-on AutoComplete of your web browser, in this case our <a target="_blank" href="http://www.elcomsoft.com/aiepr.html">AIEPR</a> easily finds it). Thus, a normal password for an online account could be like <em>PisO&rsquo;Kake</em>!</p>
<p>What&rsquo;s worth remembering is that in particular Internet systems (fortunately, their number seems to decrease, but still they are) your password is being sent through the Internet totally unprotected, which means it is not a problem to capture it. In such cases passwords&#8217; managers like<em> KeePass</em> (keepass.info) can help &#8211; they keep passwords in an encrypted file, which opens only if you know <em>master</em> password and this one (contrary to online passwords) must be highly secure.&nbsp;</p>
<p>Please be careful with your <strong>online passwords and make them different from those that you use for protecting your files</strong>. Again, remember everything you leave in the Internet is no longer yours, at least not only yours, this is the sad truth.&nbsp;</p>
<p>To sum up, I&rsquo;ve outlined some basic tips for <u>online passwords</u>:&nbsp;</p>
<ul>
<li>They do not have to be as strong as offline passwords&nbsp;</li>
<li>They should not coincide with any other your passwords used in the Internet or elsewhere</li>
<li>They should not be guessable after gathering info about you:
<ol>
<li>never equal your personal info (name, birthday, car number, postal address&hellip;)</li>
<li>never equal any general info about you (your likes/dislikes, haves/have nots&hellip;)</li>
</ol>
</li>
</ul>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.crackpassword.com/2009/06/using-passwords-online/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Adobe PDF security</title>
		<link>http://blog.crackpassword.com/2009/05/adobe-pdf-security/</link>
		<comments>http://blog.crackpassword.com/2009/05/adobe-pdf-security/#comments</comments>
		<pubDate>Fri, 22 May 2009 08:30:11 +0000</pubDate>
		<dc:creator>Vladimir Katalov</dc:creator>
				<category><![CDATA[Human Factor]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[Tips & Tricks]]></category>
		<category><![CDATA[Acrobat]]></category>
		<category><![CDATA[Adobe]]></category>
		<category><![CDATA[AES]]></category>
		<category><![CDATA[exploits]]></category>
		<category><![CDATA[GPU acceleration]]></category>
		<category><![CDATA[PDF]]></category>
		<category><![CDATA[RC4]]></category>
		<category><![CDATA[vulnerabilities]]></category>

		<guid isPermaLink="false">http://blog.crackpassword.com/?p=619</guid>
		<description><![CDATA[Wow, Adobe rethinks PDF security. Curious why? Because of vulnerabilities in Abobe Reader (and so zero-day exploits), of course. From the article: According to Finnish security company F-Secure, patching 48.9% of all targeted attacks conducted this year involved a malicious PDF file attached to a legitimate-looking e-mail, a huge change from 2008, when PDFs made [...]]]></description>
			<content:encoded><![CDATA[<p>Wow, <a target="_blank" href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;articleId=9133348">Adobe rethinks PDF security</a>. Curious why? Because of vulnerabilities in Abobe Reader (and so zero-day exploits), of course. From the article:</p>
<p style="margin-left: 40px"><em>According to Finnish security company F-Secure, patching 48.9% of all targeted attacks conducted this year involved a malicious PDF file attached to a legitimate-looking e-mail, a huge change from 2008, when PDFs made up just 28.6% of targeted attacks.</em></p>
<p>But security model of PDF encryption/protection is not going to change, [un]fortunately. <span id="more-619"></span>It is still very easy to <a target="_blank" href="http://www.elcomsoft.com/apdfpr.html">remove restrictions (from printing, copying etc) from PDF files</a>. Moreover, <a target="_blank" href="http://www.elcomsoft.com/apdfpr.html">Advanced PDF Password Recovery</a> can clean PDF files from Form elements, digital signatures and JavaScript code (the last item is the most important, because the scripts inside PDFs may contain malicious code). The <strong>open</strong> password is harder to break: only if 40-bit encryption is used (obsolete, but still popular due to compatibility reasons), such protection can be removed almost instantly, thanks to <a href="http://blog.crackpassword.com/2009/05/thunder-tables/">Thunder Tables</a>.</p>
<p>Better/improved encryption (128-bit RC4) has been introduced in Acrobat 5 a long time ago; in next version, AES encryption has been added &mdash; so only brute-force and dictionary attacks were applicable, and recovery speed was low. However, we have found that <a href="http://www.prweb.com/releases/pdf/security/prweb1667424.htm">Adobe Acrobat 9 Is a Hundred Times Less Secure</a>&nbsp;compared to version 8). Moreover, <a target="_blank" href="http://www.elcomsoft.com/gpu_acceleration.html">GPU acceleration</a> is now possible, so achieving even better recovery speed.</p>
<p>Surprisingly, Adobe has responded in their blog: see <a target="_blank" href="http://blogs.adobe.com/security/2008/12/acrobat_9_and_password_encrypt.html">Acrobat 9 and password encryption</a>. Here is what they said:</p>
<p style="margin-left: 40px"><em>The current specification for password-based 256-bit AES encryption in PDF provides greater performance than the previous 128-bit AES implementation.</em></p>
<p>First, that&#8217;s not true (if you don&#8217;t trust me, make some bench. Second, the encryption (of the file&#8217;s data) is not related to password verification routine. You can use the strongest zillion-bit algorithm, but simple and fast password checking function, and so passwords can be effectively cracked (well, recovered <img src='http://blog.crackpassword.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> ) in a reasonable time.</p>
<p>Last but not least (also from Adobe&#8217;s blog):</p>
<p style="margin-left: 40px"><em>256-bit AES encryption is widely known to be stronger than 128-bit AES.</em></p>
<p>Of course it is. But first, it&#8217;s a pure marketing issue: 128 bit is more than enough (well, for next dozen years). Second, the password is still the weakest link.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.crackpassword.com/2009/05/adobe-pdf-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

