Showing posts with label Two Step Authentication. Show all posts
Showing posts with label Two Step Authentication. Show all posts

Friday, 24 July 2015

Research: Smart Watches Full Privacy And Vulnerabilities


Smart Watches are full privacy and security holes, so that information users may end up with all kinds of parties and the devices are vulnerable to various types of attacks. That set of HP researcher who examined ten popular smart watches ( pdf ).

The researchers ran during the investigation against all kinds of problems. For example, information collected often sent to multiple destinations at the watch, including third parties. The information also appears to intercept simple. Something that was possible in nine of the ten models. Furthermore, the firmware of seven aircraft is sent unencrypted. The impact of this problem is limited because many watches only allow signed firmware updates. Five watches offer also no way to activate a screen lock.

HP has not disclosed to the watch models and manufacturers involved. The computer giant advises consumers not to use smart watches for opening of housing and cars, unless there is strong authorization is offered. In addition, consumers should always set strong passwords and make maximum use of two-factor authentication. Finally have no requests from unknown devices and applications are permitted who want to link the smart watch.

Tuesday, 21 July 2015

Expert: Strong Password, Better Than Two-Factor Authentication



Regular security experts advise to set two-factor authentication in online accounts, which should be introduced additional code next to the password, but according to one expert, it is better to use only a strong password in combination with a password manager.

An example of two-factor authentication is a code sent by SMS and logging in, beside the password must be entered. If the user's password is stolen, the attacker can not join login here unless he has the phone user in his possession. Yet it according to security expert and researcher Egor Homakov not a panacea and its users better off with just a strong password.

Entering a second code when logging according Homakov namely waste of time. In addition, most codes are limited to six numbers, so that the second factor is too Brute Force. The measure does not stop malware and viruses, such as Bruce Schneier several years ago already announced. Furthermore, the expert that no plausible attack scenario is where a simple password, two-factor authentication is better than a strong password. An attacker who for example has the user's computer infected with malware can wait a few days until the user enters his second code somewhere.

In case an attacker to access a user's mailbox has, he can then reset the password. According Homakov it is therefore wiser to use a password manager that generates strong passwords, two-factor authentication. In addition, users should not have to ask or websites they are going to support two-factor authentication, but that option is added which allows the "forgot my password" option off.