Posts

Showing posts with the label security convention

CCS Paper Part #2: Password Entropy

Image
This is part #2 in a (mumble, cough, mumble) part serious of posts discussing the results published in the paper I co-authored on the effectiveness of passwords security metrics. Part #1 can be found here . I received a lot of insightful comments on the paper since my last post, (one of the benefits of having a slow update schedule), and one thing that stands out is people really like the idea of password entropy. Here’s a good example: “As to entropy, I think it would actually be a good measure of password complexity, but unfortunately there's no way to compute it directly. We would need a password database comparable in size (or preferably much larger than) the entire password space in order to be able to do that. Since we can't possibly have that (there are not that many passwords in the world), we can't compute the entropy - we can only try to estimate it in various ways (likely poor)” First of all I want to thank everyone for their input and support as I really apprec...

New Paper on Password Security Metrics

Image
I'm in Chicago at the ACM CCS conference , and the paper I presented there: "Testing Metrics for Password Creation Policies by Attacking Large Sets of Revealed Passwords", is now available online. Direct Download of PDF View Online Since I had the paper and presentation approved through my company's public release office I was given permission to blog about this subject while the larger issue of my blog is still going through the proper channels. Because of that I'm going to limit my next couple of posts to this subject rather than talking about the CCS conference as a whole, but let me quickly point you to the amazing paper " The Security of Modern Password Expiration: An Algorithmic Framework and Empirical Analysis ", written by Yinqian Zhang, Fabian Monrose and Michael Reiter. In short, they managed to obtain a great dataset, their techniques were innovative and sound, and there's some really good analysis on how effective password expiration poli...

Defcon Crack Me if You Can Competition

I'd be remiss if I didn't spend a little time talking about the "Crack Me if you Can" competition at Defcon. It's really been amazing the amount of interest that this contest is drumming up. People are excited; it seems like everyone is refining their mangling rules, putting together new wordlists, and finishing up various password cracking tools. The impact that this is having on the password cracking community as a whole is hard to overstate. Needless to say, I'm a fan of that, and I have a ton of respect for Minga and the folks at KoreLogic for putting this together. I'll be participating, though I certainly don't plan on winning. What I'm really looking forward to though is the chance to meet with everyone else and learn what other people are doing. I'm hoping this turns into an event like the lockpicking village with the contest being almost besides the point. Of course I might be saying that because I'm going to get creamed as well......

Defcon 17 Videos Posted Online

The title says it all. You can get all of the videos here . Just a warning, I may have used some inappropriate language in my talk on password cracking , so you might not want to watch it in front of small children. Also, my writeup of a couple of the talks can be found here , and here if you are having trouble deciding what to watch.

Defcon Roundoup Part II

Saturday: Started out at Hacker vs. Disasters , but I bailed on the first speaker and instead went to the talk by Joe Grand on hacking parking meters . It just further reinforced my belief that society functions because there are not many talented bad guys. Or I should say, the effort to hack these systems outweighs the cost of using them legitimately. Still the ability to frame other people is scary. Also, you can buy ANYTHING on E-Bay. Then went back to Hacker vs. Disasters to see Renderman talk. Didn't learn much but had a great time. Favorite quote: "Most people will be absolutly useless in a disaster. Actually that's not true. They are mostly made of meat..." Of course I went to the Mythbusters talk . I was blown away by how good a speaker Adam Savage was, along with the great topic "Failure". Like everything else in his life, Adam's failures truely were epic, and I think they need to show a copy of that speach to every kid in Intermediate/High Scho...

Defcon 17 Roundup

Image
It hardly seems like Defcon 17 was only a week ago. Right now it alternately feels like I just got back from it, or it happened a million years ago . Ok, I admit it. That link has nothing to do with this post, defcon, or even the idea of "a million years ago", but I stumbled across it in my Google search for something more appropriate and I thought I should share. Librarian hackers: need I say more? As I was saying, Defcon 17 occurred at some point in the past. I won't detail the parties that went on, though there were a few . The exception I will mention is the Toxic BBQ which was held on Thursday. Having skipped it the last two years due to various reasons, most of which involved the words "108 degrees", "outside", "off-site", and "laziness", I was truly amazed at how fun this event was. It also was the one event where you could relax, drink a few beers, (making sure to drink plenty of water as well - let me reference that 10...

Shmoocon Roundup

Shmoocon has to be my favorite computer security conference. Everyone's actually happy smart and nice which is amazing. As far as the content goes, you see a lot of work in progress, and initial findings which is a plus. Many of these talks will probably be polished up and the final product displayed in August when Defcon rolls around, but here you can get a rough snapshot of where the security community will be going in the next 6 months or so. Then there's the Shmoo staff who as one person put it, is the only hacker group nobody hates, which says a lot. They really do their best to make the conference accessible , and ensure the conference helps the security community as a whole. As far as the talks go, here is my take on the ones that stood out Building an All-Channel Bluetooth Monitor by Michael Ossmann and Dominic Spill This was the rockstar talk in my opinion. I've done a lot of wireless security, and the lack of tools to audit bluetooth has always worried me...