Showing posts with label Bruce Schneier. Show all posts
Showing posts with label Bruce Schneier. Show all posts

Tuesday, 21 July 2015

Expert: Strong Password, Better Than Two-Factor Authentication



Regular security experts advise to set two-factor authentication in online accounts, which should be introduced additional code next to the password, but according to one expert, it is better to use only a strong password in combination with a password manager.

An example of two-factor authentication is a code sent by SMS and logging in, beside the password must be entered. If the user's password is stolen, the attacker can not join login here unless he has the phone user in his possession. Yet it according to security expert and researcher Egor Homakov not a panacea and its users better off with just a strong password.

Entering a second code when logging according Homakov namely waste of time. In addition, most codes are limited to six numbers, so that the second factor is too Brute Force. The measure does not stop malware and viruses, such as Bruce Schneier several years ago already announced. Furthermore, the expert that no plausible attack scenario is where a simple password, two-factor authentication is better than a strong password. An attacker who for example has the user's computer infected with malware can wait a few days until the user enters his second code somewhere.

In case an attacker to access a user's mailbox has, he can then reset the password. According Homakov it is therefore wiser to use a password manager that generates strong passwords, two-factor authentication. In addition, users should not have to ask or websites they are going to support two-factor authentication, but that option is added which allows the "forgot my password" option off.

Saturday, 30 May 2015

Schneier: Most People Will Never Use Tor Or PGP



Despite all the fuss about the revelations of Edward Snowden and the NSA surveillance in practice most people will never take anti-surveillance measures. In fact, most surveillance tools such as Facebook, Google and a smartphone are voluntarily used by people because they are like "handy", says security expert Bruce Schneier opposite Wired .

When asked how he ordinary, honest Internet users would convince tools like Tor or PGP or use your own mail server, he says this is not possible. The surveillance tools, he says, convenient and free. "That's why we use them. Most technical solutions to avoid surveillance to use tedious and difficult. And they only work to a certain level."

Schneier gives as an example the cell phone, which he describes as an "incidental tracking device". "If that was not the case, the system could not deliver phone calls. Metadata is very intimate and the surveillance data can not be encrypted." When it comes to addressing surveillance should therefore not be given to technical solutions, Schneier says.

The important thing is just to talk about it with each other, he says. "These are political issues that require political solutions, and it will be no political issues if we do not make Currently surveillance yet not showy,. We do not notice it because it happens automatically in the background Snowden left us. see what happens when people notice it. People should notice whatsoever of the lake. "

Monday, 8 December 2014

"More openness required --> Antivirus companies on government spyware"

Regin Malware

Anti-virus companies have to be more open about the government spyware that they find, says security expert Bruce Schneier . Schneier reigns on the discovery of the highly advanced Regin malware , which would be by the US and British intelligence developed .

Anti-virus companies have known for some time of the malware, but made ​​the existence of Regin until the end of November to the public. It was the first that Symantec came out with a publication because it knew that another party would reveal the malware. This party was news The Intercept. After the report, Symantec also followed F-Secure and Kaspersky Lab with their own findings. All three follow the anti-virus companies said Regin years, where she copies of years ago found.

"Why were all these companies Regin long secret and why they showed us all this time vulnerable?" Schneider asked. Self thinks the expert that the anti-virus companies no incomplete picture wanted to express. Unlike malware cybercriminals is the effect of government spyware much more complex. In addition, Regin was only used against specific targets, which makes it difficult to obtain copies.

"If you're big in the press comes with a newly discovered malware copy you want to have the whole story. Apparently no one thought they had it with Regin," said Schneier. The expert, however, find this no excuse. "Now government malware more often will come we will often not have the whole story." As long as nations will fight each other over the internet, according to the expert, some individuals or organizations are the target and the residual risk to be hit inadvertently by this type of malware.

Even more

Schneier believes that anti-virus companies are at the moment even more incomplete stories on all government malware. "But they should not do. We want and need that our anti-virus companies us all about these threats tell as soon as they can, and not wait for the appearance of a political story so they can no longer remain silent."