65
Security Awareness Month: Security Tips for Protecting Ourselves Online Friday, October 30th, 2009 Brian Allen [email protected] Network Security Analyst, Washington University in St. Louis http://nso.wustl.edu/presentations/

Security Awareness Month: Security Tips for Protecting Ourselves Online Friday, October 30th, 2009 Brian Allen [email protected] Network Security Analyst,

Embed Size (px)

Citation preview

Page 1: Security Awareness Month: Security Tips for Protecting Ourselves Online Friday, October 30th, 2009 Brian Allen ballen@wustl.edu Network Security Analyst,

Security Awareness Month:Security Tips for Protecting Ourselves Online

Friday, October 30th, 2009

Brian Allen [email protected]

Network Security Analyst,Washington University in St. Louis

http://nso.wustl.edu/presentations/

Page 2: Security Awareness Month: Security Tips for Protecting Ourselves Online Friday, October 30th, 2009 Brian Allen ballen@wustl.edu Network Security Analyst,

Let’s Talk About…• Home Wireless Router Security:• Facebook/Social Network Security:• Password Security:• AV Products:• Laptop Security:• Parental Control software:• Browsing with Firefox Addons:• Online Banking:

Page 3: Security Awareness Month: Security Tips for Protecting Ourselves Online Friday, October 30th, 2009 Brian Allen ballen@wustl.edu Network Security Analyst,
Page 4: Security Awareness Month: Security Tips for Protecting Ourselves Online Friday, October 30th, 2009 Brian Allen ballen@wustl.edu Network Security Analyst,
Page 5: Security Awareness Month: Security Tips for Protecting Ourselves Online Friday, October 30th, 2009 Brian Allen ballen@wustl.edu Network Security Analyst,
Page 6: Security Awareness Month: Security Tips for Protecting Ourselves Online Friday, October 30th, 2009 Brian Allen ballen@wustl.edu Network Security Analyst,
Page 7: Security Awareness Month: Security Tips for Protecting Ourselves Online Friday, October 30th, 2009 Brian Allen ballen@wustl.edu Network Security Analyst,
Page 8: Security Awareness Month: Security Tips for Protecting Ourselves Online Friday, October 30th, 2009 Brian Allen ballen@wustl.edu Network Security Analyst,
Page 9: Security Awareness Month: Security Tips for Protecting Ourselves Online Friday, October 30th, 2009 Brian Allen ballen@wustl.edu Network Security Analyst,
Page 10: Security Awareness Month: Security Tips for Protecting Ourselves Online Friday, October 30th, 2009 Brian Allen ballen@wustl.edu Network Security Analyst,
Page 11: Security Awareness Month: Security Tips for Protecting Ourselves Online Friday, October 30th, 2009 Brian Allen ballen@wustl.edu Network Security Analyst,
Page 12: Security Awareness Month: Security Tips for Protecting Ourselves Online Friday, October 30th, 2009 Brian Allen ballen@wustl.edu Network Security Analyst,

pics1

Page 13: Security Awareness Month: Security Tips for Protecting Ourselves Online Friday, October 30th, 2009 Brian Allen ballen@wustl.edu Network Security Analyst,
Page 14: Security Awareness Month: Security Tips for Protecting Ourselves Online Friday, October 30th, 2009 Brian Allen ballen@wustl.edu Network Security Analyst,

Twitter Phish 1 of 2

Page 15: Security Awareness Month: Security Tips for Protecting Ourselves Online Friday, October 30th, 2009 Brian Allen ballen@wustl.edu Network Security Analyst,

Twitter Phish 2 of 2

Page 16: Security Awareness Month: Security Tips for Protecting Ourselves Online Friday, October 30th, 2009 Brian Allen ballen@wustl.edu Network Security Analyst,

Password Topics

Page 17: Security Awareness Month: Security Tips for Protecting Ourselves Online Friday, October 30th, 2009 Brian Allen ballen@wustl.edu Network Security Analyst,

Parents’ Password Cracked On First Try The Onion News Feb 27, 2002

• REDONDO BEACH, CA – Nick Berrigan, 14, successfully hacked into his parents’ AOL account on the first try Tuesday, correctly guessing that “Digby” was their password. “They actually used the dog’s name,” said Berrigan, deactivating the parental controls on his AOL account.

• Experts advise parents to secure Internet accounts with any password besides the name of a family pet

Page 18: Security Awareness Month: Security Tips for Protecting Ourselves Online Friday, October 30th, 2009 Brian Allen ballen@wustl.edu Network Security Analyst,

Free Password Managers

1. Password Safe: www.schneier.com/passsafe.html– Bruce Schneier’s Project

2.KeePass: keepass.info3.LastPass: lastpass.com

- Firefox Plugin4.Mac KeyChain:5.PassPack: www.passpack.com

– An online password manager

Page 19: Security Awareness Month: Security Tips for Protecting Ourselves Online Friday, October 30th, 2009 Brian Allen ballen@wustl.edu Network Security Analyst,

Commercial Password Managers

● 1Password - 1passwd.com● Keeps track of all web passwords, automates

sign-in, guards from identity theft for $39.95

● Roboform - www.roboform.com● $29.95 for the Professional version

Page 20: Security Awareness Month: Security Tips for Protecting Ourselves Online Friday, October 30th, 2009 Brian Allen ballen@wustl.edu Network Security Analyst,

Some Key Threats to Passwords

● Brute force or dictionary attacks

● Keystroke loggers

● Social engineering/Phishing

Page 21: Security Awareness Month: Security Tips for Protecting Ourselves Online Friday, October 30th, 2009 Brian Allen ballen@wustl.edu Network Security Analyst,

Three KeePass Features

1. Require two factor authentication to access your keepass database

Page 22: Security Awareness Month: Security Tips for Protecting Ourselves Online Friday, October 30th, 2009 Brian Allen ballen@wustl.edu Network Security Analyst,

KeePass – Opening the Database

Page 23: Security Awareness Month: Security Tips for Protecting Ourselves Online Friday, October 30th, 2009 Brian Allen ballen@wustl.edu Network Security Analyst,

KeePass – The Main Interface

Page 24: Security Awareness Month: Security Tips for Protecting Ourselves Online Friday, October 30th, 2009 Brian Allen ballen@wustl.edu Network Security Analyst,

KeePass – Individual Entry

Page 25: Security Awareness Month: Security Tips for Protecting Ourselves Online Friday, October 30th, 2009 Brian Allen ballen@wustl.edu Network Security Analyst,

A Few KeePass Features

1. Require two factor authentication to access your keepass database

2. Drag and drop username and passwords into forms

Page 26: Security Awareness Month: Security Tips for Protecting Ourselves Online Friday, October 30th, 2009 Brian Allen ballen@wustl.edu Network Security Analyst,

Drag & Drop

Page 27: Security Awareness Month: Security Tips for Protecting Ourselves Online Friday, October 30th, 2009 Brian Allen ballen@wustl.edu Network Security Analyst,

A Few KeePass Features

1. Require two factor authentication to access your keepass database

2. Drag and drop username and passwords into forms

3. Autotype username and passwords into forms – a bit advanced

Page 28: Security Awareness Month: Security Tips for Protecting Ourselves Online Friday, October 30th, 2009 Brian Allen ballen@wustl.edu Network Security Analyst,

Some Solutions● You really need two factor authentication to protect the

password database

● Don't trust any machine other than your own to enter a password that protects anything sensitive

● Using a machine you don’t trust? Carry a Live CD of your favorite flavor of linux and boot off that

Page 29: Security Awareness Month: Security Tips for Protecting Ourselves Online Friday, October 30th, 2009 Brian Allen ballen@wustl.edu Network Security Analyst,

Long Password ExpirationsCan Be Good

1. Prevention of brute force password theft primarily comes from having strong passwords, not from regularly changed passwords

2. Strong passwords are more likely to be remembered if they are not changed often

Page 30: Security Awareness Month: Security Tips for Protecting Ourselves Online Friday, October 30th, 2009 Brian Allen ballen@wustl.edu Network Security Analyst,

Extra Long Password Expirations Could Be Bad

● We assume users will share their passwords:● with Students● with Staff● with Friends● with Family, etc.

● Putting a ceiling on the life of a password will keep these from lasting forever

Page 31: Security Awareness Month: Security Tips for Protecting Ourselves Online Friday, October 30th, 2009 Brian Allen ballen@wustl.edu Network Security Analyst,
Page 32: Security Awareness Month: Security Tips for Protecting Ourselves Online Friday, October 30th, 2009 Brian Allen ballen@wustl.edu Network Security Analyst,

Antivirus

• I look for:– the fastest– update themselves automatically– have an easy to use interface

• Symantec Endpoint• AVG = http://free.avg.com• AntiVir = http://www.free-av.com• Avast = http://www.avast.com

Page 33: Security Awareness Month: Security Tips for Protecting Ourselves Online Friday, October 30th, 2009 Brian Allen ballen@wustl.edu Network Security Analyst,

Symantec Endpoint (Symantec 11)

Page 34: Security Awareness Month: Security Tips for Protecting Ourselves Online Friday, October 30th, 2009 Brian Allen ballen@wustl.edu Network Security Analyst,

From CNET.com Editor ReviewsAVG Popularity: * Total downloads 227,792,675 * Downloads last week 1,737,919AntiVir Popularity: * Total downloads 61,994,231 * Downloads last week 905,902 Avast Popularity: * Total downloads 60,978,532 * Downloads last week 737,028

Page 35: Security Awareness Month: Security Tips for Protecting Ourselves Online Friday, October 30th, 2009 Brian Allen ballen@wustl.edu Network Security Analyst,

Avira Interface

Page 36: Security Awareness Month: Security Tips for Protecting Ourselves Online Friday, October 30th, 2009 Brian Allen ballen@wustl.edu Network Security Analyst,

AVG Interface

Page 37: Security Awareness Month: Security Tips for Protecting Ourselves Online Friday, October 30th, 2009 Brian Allen ballen@wustl.edu Network Security Analyst,

AVG Will Check Every Email

Page 38: Security Awareness Month: Security Tips for Protecting Ourselves Online Friday, October 30th, 2009 Brian Allen ballen@wustl.edu Network Security Analyst,

AVAST Interface

Page 39: Security Awareness Month: Security Tips for Protecting Ourselves Online Friday, October 30th, 2009 Brian Allen ballen@wustl.edu Network Security Analyst,

Home Wireless Router Tips

• Change Default Password• Firewall is on by Default• WPA2, not WPA or WEP• MAC Address Filtering• Leave SSID on• No personal info in SSID like Smith_Family

Page 40: Security Awareness Month: Security Tips for Protecting Ourselves Online Friday, October 30th, 2009 Brian Allen ballen@wustl.edu Network Security Analyst,

Change The Default Password

Page 41: Security Awareness Month: Security Tips for Protecting Ourselves Online Friday, October 30th, 2009 Brian Allen ballen@wustl.edu Network Security Analyst,

Firewall Is On By Default

Page 42: Security Awareness Month: Security Tips for Protecting Ourselves Online Friday, October 30th, 2009 Brian Allen ballen@wustl.edu Network Security Analyst,

WPA2

Page 43: Security Awareness Month: Security Tips for Protecting Ourselves Online Friday, October 30th, 2009 Brian Allen ballen@wustl.edu Network Security Analyst,

MAC Address Filtering

Page 44: Security Awareness Month: Security Tips for Protecting Ourselves Online Friday, October 30th, 2009 Brian Allen ballen@wustl.edu Network Security Analyst,

Home Wireless Router Tips

• Change Default Password• Firewall is on by Default• WPA2, not WPA or WEP• MAC Address Filtering• Leave SSID on• No personal info in SSID like Smith_Family

Page 45: Security Awareness Month: Security Tips for Protecting Ourselves Online Friday, October 30th, 2009 Brian Allen ballen@wustl.edu Network Security Analyst,
Page 46: Security Awareness Month: Security Tips for Protecting Ourselves Online Friday, October 30th, 2009 Brian Allen ballen@wustl.edu Network Security Analyst,

Laptop Tracking Software

Page 47: Security Awareness Month: Security Tips for Protecting Ourselves Online Friday, October 30th, 2009 Brian Allen ballen@wustl.edu Network Security Analyst,

Key Questions to Consider

• How hard is it to disable or remove the software?

• Who will have access to the collected data?– A department?– The company?– Individuals?

• What type of data is collected?• How many laptops are lost or stolen every year?

Page 48: Security Awareness Month: Security Tips for Protecting Ourselves Online Friday, October 30th, 2009 Brian Allen ballen@wustl.edu Network Security Analyst,

LoJack Pros

• Very difficult to disable• Asset tracking • The company, only with the user’s permission

can log in to:– Take pictures– Erase the hard drive

• Will work with police to recover the laptop

Page 49: Security Awareness Month: Security Tips for Protecting Ourselves Online Friday, October 30th, 2009 Brian Allen ballen@wustl.edu Network Security Analyst,

LoJack Bios Compatibility

AsusDellGammatechGetacGatewayGeneral Dynamics

HPFujitsuLenovo (IBM

Thinkpad)Motion ComputingPanasonicToshiba

Page 50: Security Awareness Month: Security Tips for Protecting Ourselves Online Friday, October 30th, 2009 Brian Allen ballen@wustl.edu Network Security Analyst,

LoJack Cons

• Bios compatibility does not include Macintosh– 40% student machines are Macs

• Most Expensive - $49 per laptop• The company can get access into laptops,

although it is only to be initiated by the owner after it is reported stolen

Page 51: Security Awareness Month: Security Tips for Protecting Ourselves Online Friday, October 30th, 2009 Brian Allen ballen@wustl.edu Network Security Analyst,

FireFox Addon: AdBlock Plus

Page 52: Security Awareness Month: Security Tips for Protecting Ourselves Online Friday, October 30th, 2009 Brian Allen ballen@wustl.edu Network Security Analyst,

The Top Firefox Addon (By Far)

Page 53: Security Awareness Month: Security Tips for Protecting Ourselves Online Friday, October 30th, 2009 Brian Allen ballen@wustl.edu Network Security Analyst,

Without AdBlock Plus

Page 54: Security Awareness Month: Security Tips for Protecting Ourselves Online Friday, October 30th, 2009 Brian Allen ballen@wustl.edu Network Security Analyst,

With AdBlock Plus

Page 55: Security Awareness Month: Security Tips for Protecting Ourselves Online Friday, October 30th, 2009 Brian Allen ballen@wustl.edu Network Security Analyst,

Laptop/USB Encryption

• USB Hardware Encryption – IronKey $$$

• Laptop/USB Encryption – TrueCrypt (Free!)

Page 56: Security Awareness Month: Security Tips for Protecting Ourselves Online Friday, October 30th, 2009 Brian Allen ballen@wustl.edu Network Security Analyst,

Parental Control Software

Page 57: Security Awareness Month: Security Tips for Protecting Ourselves Online Friday, October 30th, 2009 Brian Allen ballen@wustl.edu Network Security Analyst,

OpenDNS?

Page 58: Security Awareness Month: Security Tips for Protecting Ourselves Online Friday, October 30th, 2009 Brian Allen ballen@wustl.edu Network Security Analyst,

Don’t Take My Word For It

Page 59: Security Awareness Month: Security Tips for Protecting Ourselves Online Friday, October 30th, 2009 Brian Allen ballen@wustl.edu Network Security Analyst,

OpenDNS

Page 60: Security Awareness Month: Security Tips for Protecting Ourselves Online Friday, October 30th, 2009 Brian Allen ballen@wustl.edu Network Security Analyst,

OpenDNS Blocked A Site

Page 61: Security Awareness Month: Security Tips for Protecting Ourselves Online Friday, October 30th, 2009 Brian Allen ballen@wustl.edu Network Security Analyst,

Online Banking Tips

• Never type your bank url into a browser• Or click on a url that looks like your bank

• Always let Google find it for you– Should be the first link

Page 62: Security Awareness Month: Security Tips for Protecting Ourselves Online Friday, October 30th, 2009 Brian Allen ballen@wustl.edu Network Security Analyst,

MINT.COM - Discussion

Page 63: Security Awareness Month: Security Tips for Protecting Ourselves Online Friday, October 30th, 2009 Brian Allen ballen@wustl.edu Network Security Analyst,

Trends, Transactions, Etc.

Page 64: Security Awareness Month: Security Tips for Protecting Ourselves Online Friday, October 30th, 2009 Brian Allen ballen@wustl.edu Network Security Analyst,

Is It Safe?

• They Say:– Mint does not require any personally identifiable

information– Sensitive numbers are not sent to or stored by

Mint.com– Mint provides a strictly “read only” view of your

transaction information– VeriSign Security Seal

Page 65: Security Awareness Month: Security Tips for Protecting Ourselves Online Friday, October 30th, 2009 Brian Allen ballen@wustl.edu Network Security Analyst,

Thank You!

Brian [email protected]

http://nso.wustl.edu