Government Web Developers (long rant)

Jul 29, 2013 20 Replies

I have worked as a government contractor so I know how these things happen. You see something wrong and pass that info back upstream, but there are few incentive to actually make things work well, rather problems are considered,... well, problems. Not altogether different from commercial settings, except in that case the emphasis is on the bottom line, so there *is* an incentive to fix things that affect the bottom line.



So I'm trying to use a government site to file paperwork (etherwork?) relating to international shipments. My extremely complex password is forgotten (not supposed to write them down right?) So I am going through the process of setting it up again which involves a fax, two phone calls (one to me which I didn't get and a return call) and an email. I have to be on the web site so they can tell me to push the buttons that have always been there, so I assume they didn't enable the recovery function until I called although it could have been done with the email, no?



So before I get the second email with the activation code the person on the phone tells it to me and says I should write it down (not type it in), so I do. I enter it and get the next screen. When I tell her that, she is *off* the phone like wasps were chasing her.



So now I have to type a new password and I realize why I couldn't get my usual passwords to work. I have a junk pw for junk yahoo accounts and the like, a moderate complexity pw for most "high" security sites (or anal ones that want to pretend they have decent security, but no one cares) and a highly complex pw for bank accounts and the like. Although you aren't supposed to use the same pw for multiple accounts, it is just too hard to do otherwise.



So I'm on the government page and they want a password that is 12 chars long, not 11, not 13, 12 chars. It says it needs at least one alpha and at least one non-alpha character. It also needs 6 of those chars to not be repeated. The pw may not contain a "string" from the username (how long is a piece of string?). The pw may not contain any "common strings" such as 1234, 2468.



I'm all set, I type in my new, uber secure password meeting all the above criteria and I get an error that my pw contains dictionary words! I didn't think that was what they meant by "common strings"... So I change a char so the four letter dictionary word is no longer a dictionary word. It now tells me I still have the dictionary word error plus now I am getting an error about a lack of complexity with a new rule about using 3 of 4 character classes! They didn't say anything about needing uppercase chars before. So I throw in a couple of special chars... what? I'm now using chars that are not allowed???



WTF!!!??? It took me a couple more tries to eliminate anything of three or more letters that *might* be a word and to use just one of the *four* special chars listed on the error page and to include an upper case letter just to make sure... and success, I'm in.



The entire process has been complicated by the fact that they want the pw typed twice in a password boxes where you can't see what you are typing. For 8 chars, not a big deal, but by the time I'm getting to 12 chars I need to see it. So I use the browser search edit box as a convenient text editor and cut and paste. I've always wondered about the need to hide the pw I'm typing. Then when I get to the end they conveniently display a new page with my user name and my newly entered password so I can print it out!!!!!



Is it just me or are these people insane!!!???


Rick

And, no doubt, they implement password aging -- so you'll have to come up with *another* password in two weeks!! :> And it will have to be completely orthogonal (in some bizarre sense of the word!) to your old one and every combination of 12 characters that you might consider memorable!

(Did I mention I don't do things "on-line"? :< )

I can't say I was ever required to use exactly 12 chars, but I have cut and paste passwords using this website that had no problem with the feds.

Not knowing your physical security, it is hard to comment, but you could keep the password on a phone that is always in your possession, a safe, a computer that is not routinely online, etc. Air gapped computers are common in code generation.

Back when I worked a Cadence, I had the exact same type of problems. They kept changing the rules on the passwords, which had to be updated on a special site every 90 days. You couldn't use ANY previous password, or anything LIKE any previous password. The rules for length and characters/special characters/case/numbers seemed to change about every second password. It was not uncommon for it to take half a day just to update your password.

I got a couple of reprimands for foul language when talking to the Mordocs about the process...

I worked at a place that had similar password rules - at least 8 characters , at least one each of lower case, upper case, numeric and special characte rs; updated every 90 days (you would get warnings for a week and then had t o call the security officer if you failed to update). I found that I could generate acceptable with simple mechanical operations, so one month my pas sword would be 12wq!@WQ, and the next quarter 23ew@#EW. I pasted a little arrow on my keyboard pointing to the start of the current sequence, which w orked as long as I was logging in from there.

You know thiese requirements work up to a point, but really if you think ab out it mathematically, too many restrictions will actually make the passwor ds easier to hack. For example I have one password that is only four chatac ters. Sure it could be easily broken by brute force but then what cracker w ould start with four characters ? NOBODY uses a four character password any more. Mainly because mose of the time you can't. So if they start with five characters which I would recommend, they would miss mine completely.

Shorter passwords are also easier to remember while having them completely disassociated with anyhing else in your life, so there can be clues that on ly come from some kindergarten sweetheart's last name or some s*it. Things NOBODY else would know.

Isn't that the goal of a password ?

I went through this s*it with the gas company. they were NEVER going to get my bank accout numbers, I just wanted to check my account because I was un sure of my balance after slipping in and out of the budget plan like alot o f people do.

After a time I just sent them a check for what I "felt" was appropriate and the gas stayed on. Fukum.

Your really need a two factor scheme. The Verisign football for instance. The rule is "something you know and something you have." There is an open source standard for generating the 2nd factor on a computer or even a phone, though I only trust air gapped schemes.

I'd buy a Verisign dongle from any company I use willing to pay for the service. [They need to pay verisign.]

Some banks will give you one for free. Ebay/Paypal sold them for $5. This still doesn't stop anyone from social engineering past the security. [Trust me on that one, though paypal has changed their password reset scheme since I got hacked.] My bank has instructions that I will be there in person if there is any issue with the Verisign dongle. Do not reset the password without me showing up to a branch. Period, end of story. Paypal/Ebay, not having a physical presence, can't provide the same service, but I have notifications set up for credit card purchases where the card is not physically present.

This is the open source version for you phone. It still seems to me to be insecure since the phone is not airgapped, especially if you load any apps.

Still it is better than nothing.

On the topic of security, if you have one of those ATM/Credit/Debit card combos, you can set the credit and debit limits to zero. I can't imagine why banks think people want all their eggs in one basket.

That depends largely on *where* you are using the password and how the resource is accessed.

E.g., use it as a password on an XP machine and it can be cracked in seconds (think: rainbow tables) whether it's

4, 6, 8, etc. characters. (my XP passwords are 14 characters and contain lots of "special" characters since its harder to find rainbow tables prebuilt for that set of characters)

Many brute force crackers just have large dictionaries. Unless your sweetheart's name was "Gh5^[[-", it's probably in such a dictionary. (and, if the crack can be done "offline", it's a lead-pipe cinch!)

E.g., someone offers a service that breaks WiFi passwords for $50 in 24/48 hours (IIRC).

Passwords are a terrible concession to convenience over security. The premise is that it's a "guarded secret". But, it's devolved into a *convenient* secret. Because people are forced to remember so *many* of them, nowadays.

"Sex" "Passw0rd" (oh, how clever! use '0' instead of 'o') "God" "qwerty"

etc.

At the very least, use pass *phrases*.

Short passwords are trivial to crack.

The general scheme these days is, hash the password, store the hash. When the user logs in, hash that password (at the client, preferably), and compare the hash codes. If they match, you're in; else, try again.

The basic vulnerability is if a database of user names and associated hash codes is leaked or hacked. The attacker now need know only what type of hash is used (often something like SHA-whatever), and to run billions and billions of hashes on test cases.

Including mixed case and punctuation, there are, what, around 60 characters that can be used for a 4 character password. 60^4 (~10 billion) is easy to brute force. A couple of seconds, for a complete exhaustive search. It's so cheap, hackers aren't going to simply skip over it (and you're fooling yourself if you think so!).

The more sophisticated crackers use vast databases of passwords and keywords, and use various permutations of each combination, including mixed case, substituted caps or punctuation, additions or omissions, allowing them to crack even rather long passwords -- a naive cracker might be stymied by a 30 character password, but a wiser one will appreciate that no human will remember (or take the time to enter) that many mixed characters with high entropy. It's highly likely to be an English phrase, maybe with some caps and punctuation substituted for good measure. It could even be further narrowed down given some vague knowledge of the user; who needs the entire dictionary? Such passwords aren't much harder to crack than, say, 10 or 15 high entropy characters, and might take minutes to hours.

Tim

Deep Friar: a very philosophical monk. Website: http://seventransistorlabs.com

Government??? Try working as a contractor for [major telecom giant].

Not only do the rules you mention apply, BUT, you have to have at least (4) four separate passwords -- that I know of, at least for the type of work w e do.

And for one of these, you have to prepend the password in front of a 6-digi t numeric code that comes off one of those RSA keychain type LCD dongles.

The amusing part (to me, anyway) is that even with all this security in pla ce, their I.T. Dept granted us carte-blanche network access to highly sensi tive resources that we truly have no business having . When we brought thi s to their attention, we made several changes which, on balance, ended up g iving us even more network privileges than when we started. We ended up pu tting in our own safeguards to prevent our staff from doing something stupi d...

But like Rick says... Complicated passwords must be written down, which to me, makes them vulnera ble to prying eyes. Why not just use a 4 or 6 character PIN, and lock out system access if not entered correctly by the 4th or 5th attempt. Then, re lease the lock only when identity is re-verified via some other means?

There is practically zero chance someone here could correctly guess the 6-c haracter password I'm thinking of right now. I'll give you five guesses. Six, if you count "STUPID", which I will attest is not the correct answer. :)

-mpm

So, the trick is to severely limit cracking attempts. There is denyhosts on Linux, and it can be set as strict as you like. Every failed login attempt leaves a record in the system log (exact name varies by distribution flavor). denyhosts reads the log for these by originating IP, and keeps a record of past login failures. After a couple failures in a row from the same IP, it adds that IP to the list in hosts.deny

I assume there is a similar facility on Windows systems.

Anyway, even with a huge botnet of compromised computers to attack from, they only get 2 or 3 attempts per IP, and then are kicked off for several months. If your password is just reasonably non-obvious, they won't get through. On systems that need to stay secure, I only have ONE user that can log in from outside, and I have a tough password for it. Two words that are totally unrelated (wind mill would be a bad choice, for example) one of the words is misspelled, and a 4 digit number, and make it like 15 characters long. Come up with something that is fairly easy to type, you'll be typing it a LOT.

When I started using denyhosts, it was less-well known, I had to seek it out and complie from source. It is now part of standard Linux distros.

Jon

Oh, I went out to Los Alamos a few years ago. How carefully do they scrutinize visitors to the lab? Just wave at the guard, and they cheerfully wave you through! (Hmm, but I'll be there's more to it, they are just so good you never know about the face recognition software that printed your name and approval status on their screen before you even approached the guard shack!)

Anyway, there was a totally non-classified computer system there acquiring nuclear signals from a detector, through some of our electronics. There was a guy from Taiwan working there, and as a non-US national, he was not allowed to touch any lab computer. There was literally a masking tape line across the floor, he could not step across it. So, when he needed to do something, he used his personal laptop, logged into the lab computer as root, and did whatever he wanted. If he needed a hard reboot, he'd ask one of us to go push the reset button. This was considered TOTALLY kosher by their IT folks! We all had a good laugh about this sort of insanity. This is a place that has mailboxes outside the buildings where you are supposed to leave your cell phones and just about anything more sophisticated than a wristwatch, to keep people from photographing/recording anything classified. Their lab email won't accept any attachments of any sort, so you email code to people's personal gmail accounts, then they call up their gmail account from a web browser and download the files, ON the lab computer. There is probably more, but we were only there a couple days.

Jon

How about sites that only allow a couple errors before locking your account? So what if you have a database of billions of possible codes.

Anyone wanting to run for any political office in the US should have to have a DD214, and a honorable discharge.

I gave the I.T. drones hell for creating a boot disk to pre install software on one of our products, with my network password in a plain text batch file. Their first comment was, Who would see it? How about every tech on that product line? How hard was it to see the contents of a batch file? They wouldn't do anything, till I went to the head of engineering and threatened to contact corporate over the incident.

Anyone wanting to run for any political office in the US should have to have a DD214, and a honorable discharge.

  • You are LUCKY that the paste worked! I have had sites that only allow hand-typed entry for the password.
  • You are allowed to print out what they give, but NOT print/copy anything that _you _ generate.

Why a specialized app? Just edit /etc/hosts.deny:

PORTMAP:ALL ALL: ALL

/etc/hosts.allow:

ALL:127.0.0.1

"Design is the reverse of analysis" (R.D. Middlebrook)

eg: start by replacing the on-screen keyboard app with cmd.exe

This like the equivalent attacks againt *nix requires physical access to the machine

?? 100% natural --- news://freenews.netfront.net/ - complaints: news@netfront.net ---

Also "fail2ban", which can also be used to protect other services (IMAP, SMTP, FTP, HTTP, etc) too.

I've used it to stop dictionary attacks against IMAP accounts.

I've at work we're using something, but since we only run win servers behind linux routers It'd probbly probably be better to get windows to log to the router via syslog and use fail2ban

?? 100% natural

Yes but can be done "passively". E.g., boot an OPHCRACK CD and wait a few minutes... Remove CD when done and there is no sign that you've hacked the system (assuming it was powered off or at a login -- with no current users -- prompt when you started).

[Handy tool if you are suspicious of a spouse, etc.! Esp if they have configured their browser to "remember passwords"...]

XP machines have an "Administrator" account -- even though the first "user" you specify during installation is intended to be the administration account. It isn't shown on the login screen, by default. However, you can access it from safe mode with it's default "empty" password (unless folks like me have intentionally set up the account and given it a *different* password! :> )

There are also tricks to reset the Administrator password to "empty". Etc. See, for example:

Because most PC's are "personal" machines, gaining physical access isn't usually that hard -- the machine is often in an unsecured location (e.g., back with mainframes, the physical hardware sat behind a locked door).

And, if you want to get creative, you can mount the internal drive as a secondary filesystem on an OS booted from a CD and go poking around with the tools offered by that OS without leaving a "fingerprint" on the original drive (i.e., Windows never executes any code).

But, this is all predicated on finding the machine in a state to which you can return it *without* the user noticing (i.e., if he's currently logged in and "doing something", you'd need to be able to re-log him in after you are done with your exploit and make it look like he was still "doing" ).

[EFS significantly compounds these problems!]

They are not insane, they are not up to the necessary capability level to have sanity to be a detectable property. I know from way too many years of direct association.

?-((

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required