News: 1627626426

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

We can't believe people use browsers to manage their passwords, says maker of password management tools

(2021/07/30)


It seems some of us are, in the year of our lord 2021, still reusing the same password for multiple sites, plugging personal gear into work networks, and perhaps overly relying on browser-managed passwords, judging from this poll.

ThycoticCentrify, formed from a merger between two computer access management firms, said it surveyed about 8,000 people, and [1]reports just under a quarter admitted they reuse passwords across multiple websites – a cybersecurity no-no because it opens you up to [2]credential stuffing .

Meanwhile, about half of those working for large (5,000+ headcount) companies said they hadn't received cybersecurity training in the past 12 months, even as the vast majority of all those polled said they'd seen an increase in the volume of phishing messages their org had received over the past year.

[3]

Joseph Carson, chief security scientist and advisory CISO at ThycoticCentrify, said: "People working in the cybersecurity sector know how their colleagues should behave when it comes to keeping their devices safe and protecting the wider company. But are these messages getting through?"

[4]

[5]

Research carried out by Sapio Research for the biz found that a global sample (including a thousand people from each of the UK, US, Germany, Australia and New Zealand) were doing potentially risky things, such as connecting personal devices to corporate networks – something that a quarter (23 per cent) of respondents said they had done. Coincidentally, 21 per cent of respondents said they were C-suite execs, company owners, or managing-director level.

[6]Spam is Chipotle's secret ingredient: Marketing email hijacked to dish up malware

[7]Israeli authorities investigate NSO Group over Pegasus spyware abuse claims

[8]Here's a list of the flaws Russia, China, Iran and pals exploit most often, say Five Eyes infosec agencies

[9]'Woefully insufficient': Biden administration's assessment of critical infrastructure infosec protection

Whether this included BYOD devices wasn't made clear in the resulting study. Nonetheless, uncontrolled personal devices certainly represent a level of risk.

The use of browser-stored passwords was also called out as a potential security risk by ThycoticCentrify, with a third of respondents apparently saying they rely on their web browser to manage their passphrases. It argued these stored credentials would be a jackpot prize for anyone compromising a PC, phone, or tablet.

"More than a third of employees continue to save passwords within their internet browsers on all of their personal and work devices," said Carson. "By cracking only one of those devices, an attacker can easily access all the passwords stored within the user’s browser. This makes it so much easier for an attacker to elevate privileges without being detected and gain access to the user’s email, company cloud applications, or even sensitive data.

[10]

"If the employee has saved multiple passwords within the internet browser, an attacker can readily see whether they are all the same or simple variations such as one character difference."

Using a password manager, even one built into a browser, with complex, randomly generated passwords is arguably better than asking people to memorize weak or guessable ones or reuse the same credentials over and over for multiple services. That said, ThycoticCentrify's argument appears to be that companies should move beyond relying just on passwords: they should consider better ways to reliably and securely authenticate users when accessing resources, using things like multi-factor authentication.

Again, ThycoticCentrify is a password and access management outfit. This is like a lock maker telling you to buy better locks and keys, like the ones it sells. Each organization should devise its own threat model with regard to passwords, authentication, and scope of access.

[11]

Finally, though most people responding to the survey acknowledged their business could be targeted by cyber-criminals, a mere 16 per cent of respondents felt their business was at a "very high risk" of catching the wrong end of a cybersecurity attack. The spray-and-pwn tactics of ransomware gangs, such as the crews who targeted [12]ageing Accellion file-transfer appliances , hasn't quite sunk in for all. ®

Get our [13]Tech Resources



[1] https://thycotic.com/company/blog/2021/07/27/cyber-security-global-research-report-remote-workers-face-tough-choices/

[2] https://owasp.org/www-community/attacks/Credential_stuffing

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YQPNtKNPwYYeeG8pI@MqSwAAAJU&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YQPNtKNPwYYeeG8pI@MqSwAAAJU&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YQPNtKNPwYYeeG8pI@MqSwAAAJU&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://www.theregister.com/2021/07/29/mailgun_chipotle_malware_spam/

[7] https://www.theregister.com/2021/07/29/israel_probes_nso_group/

[8] https://www.theregister.com/2021/07/29/top_vulns_list/

[9] https://www.theregister.com/2021/07/29/biden_memo_on_critical_infrastructure_control_systems_security/

[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YQPNtKNPwYYeeG8pI@MqSwAAAJU&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[11] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YQPNtKNPwYYeeG8pI@MqSwAAAJU&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[12] https://www.theregister.com/2021/03/03/qualys_ransomware_clop_gang/

[13] https://whitepapers.theregister.com/



Mixed model

DrXym

I use the browser for sites for forums and things of that nature. I use Password Safe for everything else. Aside from that I enable 2FA whenever it's available so even if someone does somehow get my password it's not necessarily going to help them.

Re: Mixed model

Piro

Same here, but KeepAss instead of Password Safe

Re: Mixed model

Dan 55

ExpertSexChange error.

Re: Mixed model

Ozan

Yes, fixed method. I dont savepassword to browser (I dont even trust firefox for that.) I use bitwarden for it. I went selfhosted for it. I dont know I should have or not at this point. KeePass might be better for self hosting using dime a dozen could storage systems outthere.

Re: Mixed model

Headley_Grange

Same here, and my password manager synchs over my local WiFi only. It's a bit mandraulic, but I don't want my important passwords in the cloud. Finance passwords are in my head only.

Re: Mixed model

Sgt_Oddball

Ditto, if its something that can cost me money then I don't save it to browser. If it's something with personal info that isn't important then I use slightly off data (think changing a year, being one street over or a non-existent number, wrong phone number) and then save password to browser.

That said i do have a cypher book, written in fountain pen with my left hand whilst drunk for certain passwords on infrequently visited sites. I wonder if I should consider burning... Especially since even I can't make out what I attempted to write.

Re: Mixed model

Martijn Otto

2FA wherever possible here too, but I go one step further and use [1]pass together with a Nitrokey on all my devices. That makes it very unlikely that the encryption key ever leaks.

[1] https://www.passwordstore.org/

Re: Mixed model

big_D

I just use a password manager these days, it is easier than faffing around and keep telling the browser never to ask to store a password for a specific site. I just disable it completely.

I use 2FA everywhere, never SMS, and preferably a Yubikey.

bolac

The whole industry only exists because Microsoft has no sane solution for Windows. On the other side, Mac users save their passwords in the Keychain, Linux users do the same with gnome-keyring and KDE kwallet for literal decades now.

Halfmad

Why on earth would I want to entrust my info to MS or save in a MS keychain?

Eggs in one basket much?

There's little difference between the use of something like kwallet and say bitwarden.

Disgusted Of Tunbridge Wells

> Eggs in one basket much?

Downvote for that horrific American use of "much" that I thought had died a death (much).

AndrueC

So people moan at MS when it pushes other companies out of the market and moan when it leaves a gap in the market.

A Non e-mouse

That's the joy of being in the audience: You're free to criticize as much as you want safe in the knowledge that you won't actually have to come up with an answer yourself.

A Non e-mouse

The problem is for those of us who don't work in an OS monoculture. We need cross platform tools.

bolac

This is bullshit. Cross-platform software always sucks. Always. No exception. A tool should integrated into the system conventions as well as possible. A Windows application should follow Windows conventions, a Mac application should follow Mac conventions, and so on.

This is particularly true for a password manager, so you don't need insecure dirty clipboard tricks to enter passwords into forms. The only cross-platform thing we need in this area is a portable format for export/import and backups of password databases.

Dan 55

Control Panel > User Accounts > Credential Manager?

Oh Matron!

You missed the "No sane solution"

A bit like giving the local fox your chickens and saying, "I'm off to benedorm for a week. Be a love and look after the clucks for me."

katrinab

Doesn't store website passwords. Chromium Edge I think stores them in OneDrive.

Dan 55

There is a Web Credentials 'tab', at least in my version of Windows. Can't say I remember it always being there, it might just be the most recent versions of W10.

It does work with IE at least. In my case it's full of intranet passwords for stuff which won't work with anything else.

teomor

Exactly. Windows needs a built-in password manager if we want this to stop.

This is one of the main reasons I am using a Mac (both at home and at work). Also, integration with Keychain across all Apple devices is a godsend.

big_D

I use a mix of macOS, Linux, iOS, Android and Windows. Therefore Apple Keychain is useless, as are gnome-keyring. For those not using just one platform, it has to be a platform independent solution.

Disgusted Of Tunbridge Wells

I use the browser because I have more important things to do with my life, like watching TV.

I trust Google to be secure more than I trust TrustworthyPasswordManager.

Also any sites that are of any importance ( eg: banking, email, even social media ) have 2FA.

Training

Anonymous Coward

"Meanwhile, about half of those working for large (5,000+ headcount) companies said they hadn't received cybersecurity training in the past 12 months"

But I bet they've all received 'Unconscious Bias training", "Diversity training", "Personal Pronoun training", "Cultural Competency training", "Preventing Discrimination and Harassment training", and of course "Creating an Inclusive Workspace training."

All far, far more important than any old IT security nonsense. That's IT's job, innit.

Potemkine!

as connecting personal devices to corporate networks

We use 802.1X to avoid this. We also get alerts when some jerk user connects his/her smartphone on a professional computer to charge it. I would love to practice kneecapping on them, alas company policies doesn't allow it.

Since this database is not used for profit, and since entire works are not
published, it falls under fair use, as we understand it. However, if any
half-assed idiot decides to make a profit off of this, they will need to
double check it all...
-- Notes included with the default fortunes database