{"id":2103,"date":"2009-04-24T02:37:47","date_gmt":"2009-04-24T09:37:47","guid":{"rendered":"https:\/\/svapm.org\/?p=2103"},"modified":"2019-08-07T14:31:31","modified_gmt":"2019-08-07T21:31:31","slug":"administrative-security-controls","status":"publish","type":"post","link":"https:\/\/svapm.org\/?p=2103","title":{"rendered":"Administrative Security Controls"},"content":{"rendered":"<p>Administrative controls are perhaps most important, because they most directly impact your people.\u00a0 On the one hand, they are the simplest, since all it takes is education.\u00a0 On the other hand, education about the hazards of smoking or the possibility that having sex causes pregnancy hasn\u2019t done much to change behaviors in those realms.\u00a0 Well, rather than throw up our hands and give up, let\u2019s tackle administrative controls anyhow.<\/p>\n<p>Administrative controls are the hardest to implement because people must understand them, accept them, and implement them correctly\u2014again, and again, and again.<\/p>\n<p>Like the previous day\u2019s entry, there is SO MUCH to talk about.\u00a0 So I will limit this entry to a topic we all can relate to: passwords.\u00a0 If there is anything that causes grief in corporate America\u2014aside from blocking access to XM Radio\u2014it is the familiar monthly give-or-take ritual: I have to change my password again?\u00a0 I think we are all well versed in the basics of what makes a good, \u201cstrong\u201d password: the more characters the better, include numbers and special characters, don\u2019t allow words found in a dictionary, etc.<\/p>\n<p>But <em>why<\/em> do I have to change it?<\/p>\n<p>When teaching an information security course, I shock, amaze, impress, and horrify participants by demonstrating how easy it is to crack hashed passwords using a freeware program that is downloadable from the Internet.\u00a0 (I will not name it, but if you perform an online search for \u201cpassword cracker,\u201d it probably will come up, along with another 482,375 hits.)\u00a0 The file I employ contains four hashed (hashing is a function which, quite simply, takes a string of text and changes it into a fixed-length string which bears no resemblance to the original) passwords:<\/p>\n<p>TESTING<br \/>\nTESTIT2<br \/>\n2TESTIT<br \/>\n21_TEST<\/p>\n<p>Take a minute to think about the passwords.\u00a0 \u201cTesting,\u201d obviously is a word found in the English dictionary.\u00a0 Password-cracking tools typically include a dictionary of all words in the English dictionary, and other language dictionaries.\u00a0 Those words are the first it tries.\u00a0 Because of this, no one should expect a password that contains a recognizable word to be a secure password.<\/p>\n<p>When I first did this exercise, way back in grad school, using a Pentium 4, running at 1.69GHz, with 256MB of RAM, it cracked the first three in record time:<\/p>\n<p>TESTING: About one second.<br \/>\nTESTIT2:\u00a0 A little over three minutes.<br \/>\n2TESTIT: Two hours.<\/p>\n<p>I never did crack the last one, 21_TEST, because I had to shut down my computer and go to a job interview.\u00a0 But the person who showed me this tool claimed in took about three days, using a comparable system.<\/p>\n<p>So, if a cracker gets his hands on your organization\u2019s PASSWORD.TXT file, he can fire up the cracking program and check it every few days for the results.\u00a0 If your organization does not require strong passwords, he would not have to wait long.\u00a0 But a sufficiently complex password\u2014one that does not include any word found in any dictionary\u2014will take longer\u2026a lot longer.\u00a0 The problem is, \u201ca lot longer\u201d is not defined in years, but in months or even weeks.\u00a0 That\u2019s why the security-savvy organization\u2019s password policy requires that passwords be changed every 30 to 45 days, so that by the time the cracker gets his results, the passwords he has at his disposal will have expired.<\/p>\n<p>And that is why you have to change your password.<\/p>\n<p>I would like to leave you today with one final tip.\u00a0 I\u2019m sure (too) many of us have seen the sticky-note-on-the-monitor method for \u201cremembering\u201d passwords.\u00a0 Closely related to this oh-so-clever technique is the sticky-note-under-the-keyboard method.\u00a0 It doesn\u2019t work.\u00a0 Just as a burglar knows to look for a house key under the doormat, information thieves know to look under keyboards.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Administrative controls are perhaps most important, because they most directly impact your people.  On the one hand, they are the simplest, since all it takes is education.  On the other hand, education about the hazards of smoking or the possibility that having sex causes pregnancy hasn\u2019t done much to change behaviors in those realms.  Well, rather than throw up our hands and give up, let\u2019s tackle administrative controls anyhow&#8230;<\/p>\n","protected":false},"author":1483,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"give_campaign_id":0,"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[7,20,9,1],"tags":[572,571,583,585,261,570,584],"class_list":["post-2103","post","type-post","status-publish","format-standard","hentry","category-goals","category-quality","category-risk-management","category-miscellaneous","tag-infosec","tag-michael-seese","tag-password","tag-password-cracking","tag-scrappy","tag-scrappy-information-security","tag-strong-passwords"],"aioseo_notices":[],"jetpack_featured_media_url":"","_links":{"self":[{"href":"https:\/\/svapm.org\/index.php?rest_route=\/wp\/v2\/posts\/2103","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/svapm.org\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/svapm.org\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/svapm.org\/index.php?rest_route=\/wp\/v2\/users\/1483"}],"replies":[{"embeddable":true,"href":"https:\/\/svapm.org\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2103"}],"version-history":[{"count":1,"href":"https:\/\/svapm.org\/index.php?rest_route=\/wp\/v2\/posts\/2103\/revisions"}],"predecessor-version":[{"id":14247,"href":"https:\/\/svapm.org\/index.php?rest_route=\/wp\/v2\/posts\/2103\/revisions\/14247"}],"wp:attachment":[{"href":"https:\/\/svapm.org\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2103"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/svapm.org\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2103"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/svapm.org\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2103"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}