<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>withoutfire &#187; Passwords</title>
	<atom:link href="http://withoutfire.com/category/passwords/feed/" rel="self" type="application/rss+xml" />
	<link>http://withoutfire.com</link>
	<description>helping you look after your data</description>
	<lastBuildDate>Fri, 26 Feb 2010 12:59:48 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Users divulge their passwords to strangers</title>
		<link>http://withoutfire.com/2009/05/users-divulge-passwords/</link>
		<comments>http://withoutfire.com/2009/05/users-divulge-passwords/#comments</comments>
		<pubDate>Mon, 11 May 2009 22:19:34 +0000</pubDate>
		<dc:creator>John</dc:creator>
				<category><![CDATA[Passwords]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Training]]></category>

		<guid isPermaLink="false">http://withoutfire.com/?p=18</guid>
		<description><![CDATA[This won&#8217;t be a surprise to anyone who works in IT security, but last week the BBC reported how easy it was for an experienced security consultant doing some pretty basic &#8217;social engineering&#8217; to:

Walk into buildings unchallenged and steal data from a company
Get users to divulge their password over the telephone to someone who claimed [...]]]></description>
			<content:encoded><![CDATA[<p>This won&#8217;t be a surprise to anyone who works in IT security, but last week the <a href="http://newsvote.bbc.co.uk/1/hi/technology/7843206.stm">BBC reported</a> how easy it was for an experienced security consultant doing some pretty basic &#8217;social engineering&#8217; to:</p>
<ul>
<li>Walk into buildings unchallenged and steal data from a company</li>
<li>Get users to divulge their password over the telephone to someone who claimed &#8216;to be from IT&#8217;</li>
</ul>
<p>The video is about 90 seconds long &mdash; and really worth watching.</p>
<p><object width="512" height="400"><param name="movie" value="http://news.bbc.co.uk/player/emp/external/player.swf"></param><param name="allowFullScreen" value="true"></param><param  name="allowScriptAccess" value="always"></param><param name="FlashVars"  value="config_settings_showUpdatedInFooter=true&#038;playlist=http://news.bbc.co.uk/media/emp/8030000/8035600/8035618.xml&#038;config=http://news.bbc.co.uk/player/emp/config/default.xml?1.3.105_2.10.7938_7967_20090406152952&#038;config_settings_language=default&#038;config_settings_showFooter=true&#038;config_plugin_fmtjLiveStats_pageType=eav6&#038;config_settings_showPopoutButton=false&#038;config_settings_showPopoutCta=false"></param><embed src="http://news.bbc.co.uk/player/emp/external/player.swf" type="application/x-shockwave-flash" allowfullscreen="true" allowScriptAccess="always" width="512" height="400"  FlashVars="config_settings_showUpdatedInFooter=true&#038;playlist=http://news.bbc.co.uk/media/emp/8030000/8035600/8035618.xml&#038;config=http://news.bbc.co.uk/player/emp/config/default.xml?1.3.105_2.10.7938_7967_20090406152952&#038;config_settings_language=default&#038;config_settings_showFooter=true&#038;config_plugin_fmtjLiveStats_pageType=eav6&#038;config_settings_showPopoutButton=false&#038;config_settings_showPopoutCta=false"></embed></object></p>
<p><H2>What lessons we can learn from this?</h2>
<p>All security programmes tell users not to divulge their password to anyone &mdash; not even people in IT. However this doesn&#8217;t work: when it comes to their computer systems, users see IT as &#8216;authority figures&#8217; and so will divulge their password &mdash; especially if they are coerced.</p>
<p><strong>What you need to do is:</strong></p>
<h3>1. Train the IT team not to ask users for passwords</h3>
<p>Put a process like this in place so if an IT person needs to login as a user they should:</p>
<ol>
<li>Raise a ticket / case in the organsiation&#8217;s help desk &mdash; which should ideally to be authorised by someone else</li>
<li>Confirm with the user that they are about to login using the user&#8217;s account</li>
<li>Login as a system administrator and change the user&#8217;s password to something that only they know</li>
<li>Now the IT person can login as the user <em>(the time of the login and the activcity carried out whilst logged in should be logged with the original ticket)</em></li>
<li>Once completed, they should login as a system administrator and set the user&#8217;s password to a one time password which is communicated to the user</li>
<li>The user can now login and must be forced to reset their password to one of their own choosing</li>
</ol>
<p>This is a long process, so it&#8217;s no wonder that IT people take a short-cut and just ask a user for their password, <strong>so you also have to:</strong></p>
<h3>2. Train all staff that if anyone &#8220;from IT&#8221; asks for their password, it&#8217;s a security incident</h3>
<p>As part of your awareness training, emphasise that the only people who would ask for their password are:</p>
<ul>
<li>Data pirates (criminals)</li>
<li>Rogue IT people</li>
</ul>
<p>So if someone rings up and asks them for their password, they should refuse to give it and report it to the Information Security Manager (or their equivalent).</p>
<blockquote><p>Of course it&#8217;s rare nowadays that IT should need to login as a user, there are better ways to diagnose a problem such as remotely sharing a user&#8217;s screen (once the appropriate authorisation has been given).</p></blockquote>
<p>Here&#8217;s a little cartoon I&#8217;ve used in training and included in internal newsletters.</p>
<p><img src="http://withoutfire.com/wp-content/uploads/2009/05/phonepass.jpg" alt="Data Pirates stealing a password" title="phonepass" width="595" height="420" class="size-full wp-image-33" /></p>
<p>(if you want a print-quality version, or one customised to your company then just send me an email)</p>
]]></content:encoded>
			<wfw:commentRss>http://withoutfire.com/2009/05/users-divulge-passwords/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

