Posts Tagged ‘password security’

Smartphone Forensics: Cracking BlackBerry Backup Passwords

Thursday, September 30th, 2010

BlackBerry dominates the North American smartphone market, enjoying almost 40 per cent market share. A 20 per cent worldwide market share isn’t exactly a bad thing, too. The total subscriber base for the BlackBerry platform is more than 50 million users.

Today, we are proud to present world’s first tool to facilitate forensic analysis of BlackBerry devices by enabling access to protected data stored on users’ BlackBerries.

One of the reasons of BlackBerry high popularity is its ultimate security. It was the only commercial mobile communication device that was ever allowed to a US president: Barack Obama has won the privilege to keep his prized BlackBerry despite resistance from NSA. (On a similar note, Russian president Dmitry Medvedev was handed an iPhone 4 a day before its official release by no one but Steve Jobs himself. No worries, we crack those, too).

 

(more…)

Password masking: myths and truths

Tuesday, July 7th, 2009

Password masking: myths and truthsEver heard of password masking problem? To be honest, I have not – until I’ve read the Stop Password Masking article by Jakob Nielsen (somewhere referred to as "usability guru"), followed by a lot of other publications, blog posts and comments (see ‘em all); so-called security guru Bruce Schneier wrote even two essays on that. 

Well, that reminded me of a very funny stupid CAPSoff Campaign

In brief, here is the "problem": for years (I think starting from Windows 3.0 released almost 20 years ago), the passwords are being masked as you type them (in most programs what have any kind of password protection, and an operating system itself), i.e. replaced with asterisks or black circles. What for? To prevent the password from being read by someone who stands behind you.

(more…)

More than 100.000 websites are in ‘safe hands’ now

Wednesday, June 10th, 2009

The Register reports VAServ.com has been attacked and now more than 100.000 websites have gone forever because of company’s poor password policy. The attackers are unknown and Rus Foster, (former?) VAServ.com director claims that anonymous messages indicated nonexistent passwords. I wouldn’t like to sound sarcastic but their description at AboutUs.org reads quite funny now, what do you think? 

Password Usage Behavior Survey Announced

Wednesday, June 3rd, 2009

ElcomSoft is launching a survey intended to collect more information on how people handle their passwords, which remain a major way for user authentication. Whether you are ElcomSoft customer or haven’t seriously thought about password security, we hope you will answer our questions.

The questionnaire is well designed and if you have no time you can simply tick the matching answers which are prepared for your convenience. If you have a special experience to share or lots of thoughts on passwords, please take a while and use empty spaces provided for your own answers.

The survey is set to run for several weeks in order to cover more people, for we understand that summer is the best season for vacations. After the survey is completed and results calculated, we will release a full report with facts and figures. We tried to put sensible questions in the belief that results’ analysis will help us find out which questions should be better and more deeply highlighted in our articles, whitepapers, as well as in our blog.

This is the first our empirical research and we hope you will find it interesting and enjoyable. You definitely have your own opinion on passwords, and as you understand this survey is a perfect way for you to share that opinion. So what do you think? Be frank and open, take the questionnaire, and help us let others know about it.

 

Week of Scams

Friday, May 15th, 2009

This week has witnessed several scams involving social sites. On Tuesday Twitter users posted answers to their online security questions for everyone to see. On Wednesday Twitter account of the New York Times was hacked, and on Thursday we witnessed a phishing attack on Facebook. (more…)