Thursday, November 13, 2008

Newsletter Article 2

Security and Passwords

By Karl Wenger
Dir. Network Services

I had someone ask me why we always send out notes about passwords and wanted to know what we are hoping to accomplish. I thought this was a good question. Let me explain. With all the news stories about hackers, worms, and breaches involving personal information, it's easy for the security message to sound over-used and tired. It's also easy for people to say, "it won't happen here." Yet, studies and surveys repeatedly show that the "Human Factor" (what employees do or don't do) is the biggest threat to information systems and assets.

Our IT infrastructure is very complex. We have a lot of systems centered around security and we spend a considerable amount of time making sure our systems are secure and compliant. But this isn't enough. This infrastructure is useless without the employees of our company watching out for our data and protecting their passwords and the data on their systems. The only secure system is one that's unplugged, turned off, and in a locked room. Since it's not practical to leave our systems turned off, we need to understand the risks to our systems and prepare ourselves to defend them. Preparation begins with understanding - and that's where awareness comes in. Employee and contractor behavior is the primary source of costly data breaches. It's also the best way to prevent loss.

Total number of records containing sensitive personal information involved in security breaches in the U.S. since January 2005 - 230,505,892 as of June 27, 2008.

Some of the major threats to our company can include or involve social engineering, hacking, email related attacks, loss of confidential or proprietary data and viruses. To prove a point on security, a security consulting company had a group of people stand out on numerous street corners and ask passers-by to give them their computer password in exchange for a chocolate bar. A huge number of people gave up the information. The security company then targeted a number of these people at random and had them followed and tried to see what information they could find out about them including their identity, where they worked, etc. Some of the people had obviously given false information, and out of those poeple they followed, some didn't pan out. But some of the people had actually given up their real password! Out of these people, it turned out that on some level most of them had used the same password for multiple systems, sharing their login password with the password they use at their bank, email, etc. (None of us have ever used the same password for multiple systems, right???) I don't think I need to say, "Don't give up your password for a chocolate bar."

The basic goals of social engineering are the same as hacking in general: to gain unauthorized access to systems or information in order to commit fraud, network intrusion, industrial espionage, identity theft, or simply to disrupt the system or network. Even for technical people, it's often much simpler to just pick up the phone and ask someone for his password - and most often that is just what a hacker will do. If you think a caller is after your information here are some things to look out for. A refusal to give contact information, rushing, name-dropping, intimidation, and requesting forbidden information just to mention a few. Look for things that don't quite add up. In the event that you detect something fishy, please report the incident to your supervisor or the helpdesk immediately. The sooner you act, the sooner we may stop an intruder.

No comments: