We can't believe people use browsers to manage their passwords, says maker of password management tools
- Reference: 1627626426
- News link: https://www.theregister.co.uk/2021/07/30/infosec_risky_behaviours_study/
- Source link:
ThycoticCentrify, formed from a merger between two computer access management firms, said it surveyed about 8,000 people, and [1]reports just under a quarter admitted they reuse passwords across multiple websites – a cybersecurity no-no because it opens you up to [2]credential stuffing .
Meanwhile, about half of those working for large (5,000+ headcount) companies said they hadn't received cybersecurity training in the past 12 months, even as the vast majority of all those polled said they'd seen an increase in the volume of phishing messages their org had received over the past year.
[3]
Joseph Carson, chief security scientist and advisory CISO at ThycoticCentrify, said: "People working in the cybersecurity sector know how their colleagues should behave when it comes to keeping their devices safe and protecting the wider company. But are these messages getting through?"
[4]
[5]
Research carried out by Sapio Research for the biz found that a global sample (including a thousand people from each of the UK, US, Germany, Australia and New Zealand) were doing potentially risky things, such as connecting personal devices to corporate networks – something that a quarter (23 per cent) of respondents said they had done. Coincidentally, 21 per cent of respondents said they were C-suite execs, company owners, or managing-director level.
[6]Spam is Chipotle's secret ingredient: Marketing email hijacked to dish up malware
[7]Israeli authorities investigate NSO Group over Pegasus spyware abuse claims
[8]Here's a list of the flaws Russia, China, Iran and pals exploit most often, say Five Eyes infosec agencies
[9]'Woefully insufficient': Biden administration's assessment of critical infrastructure infosec protection
Whether this included BYOD devices wasn't made clear in the resulting study. Nonetheless, uncontrolled personal devices certainly represent a level of risk.
The use of browser-stored passwords was also called out as a potential security risk by ThycoticCentrify, with a third of respondents apparently saying they rely on their web browser to manage their passphrases. It argued these stored credentials would be a jackpot prize for anyone compromising a PC, phone, or tablet.
"More than a third of employees continue to save passwords within their internet browsers on all of their personal and work devices," said Carson. "By cracking only one of those devices, an attacker can easily access all the passwords stored within the user’s browser. This makes it so much easier for an attacker to elevate privileges without being detected and gain access to the user’s email, company cloud applications, or even sensitive data.
[10]
"If the employee has saved multiple passwords within the internet browser, an attacker can readily see whether they are all the same or simple variations such as one character difference."
Using a password manager, even one built into a browser, with complex, randomly generated passwords is arguably better than asking people to memorize weak or guessable ones or reuse the same credentials over and over for multiple services. That said, ThycoticCentrify's argument appears to be that companies should move beyond relying just on passwords: they should consider better ways to reliably and securely authenticate users when accessing resources, using things like multi-factor authentication.
Again, ThycoticCentrify is a password and access management outfit. This is like a lock maker telling you to buy better locks and keys, like the ones it sells. Each organization should devise its own threat model with regard to passwords, authentication, and scope of access.
[11]
Finally, though most people responding to the survey acknowledged their business could be targeted by cyber-criminals, a mere 16 per cent of respondents felt their business was at a "very high risk" of catching the wrong end of a cybersecurity attack. The spray-and-pwn tactics of ransomware gangs, such as the crews who targeted [12]ageing Accellion file-transfer appliances , hasn't quite sunk in for all. ®
Get our [13]Tech Resources
[1] https://thycotic.com/company/blog/2021/07/27/cyber-security-global-research-report-remote-workers-face-tough-choices/
[2] https://owasp.org/www-community/attacks/Credential_stuffing
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YQPNtKNPwYYeeG8pI@MqSwAAAJU&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YQPNtKNPwYYeeG8pI@MqSwAAAJU&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YQPNtKNPwYYeeG8pI@MqSwAAAJU&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[6] https://www.theregister.com/2021/07/29/mailgun_chipotle_malware_spam/
[7] https://www.theregister.com/2021/07/29/israel_probes_nso_group/
[8] https://www.theregister.com/2021/07/29/top_vulns_list/
[9] https://www.theregister.com/2021/07/29/biden_memo_on_critical_infrastructure_control_systems_security/
[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YQPNtKNPwYYeeG8pI@MqSwAAAJU&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[11] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YQPNtKNPwYYeeG8pI@MqSwAAAJU&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[12] https://www.theregister.com/2021/03/03/qualys_ransomware_clop_gang/
[13] https://whitepapers.theregister.com/
Re: Mixed model
Same here, but KeepAss instead of Password Safe
Re: Mixed model
ExpertSexChange error.
Re: Mixed model
Yes, fixed method. I dont savepassword to browser (I dont even trust firefox for that.) I use bitwarden for it. I went selfhosted for it. I dont know I should have or not at this point. KeePass might be better for self hosting using dime a dozen could storage systems outthere.
Re: Mixed model
Same here, and my password manager synchs over my local WiFi only. It's a bit mandraulic, but I don't want my important passwords in the cloud. Finance passwords are in my head only.
Re: Mixed model
Ditto, if its something that can cost me money then I don't save it to browser. If it's something with personal info that isn't important then I use slightly off data (think changing a year, being one street over or a non-existent number, wrong phone number) and then save password to browser.
That said i do have a cypher book, written in fountain pen with my left hand whilst drunk for certain passwords on infrequently visited sites. I wonder if I should consider burning... Especially since even I can't make out what I attempted to write.
Re: Mixed model
2FA wherever possible here too, but I go one step further and use [1]pass together with a Nitrokey on all my devices. That makes it very unlikely that the encryption key ever leaks.
[1] https://www.passwordstore.org/
Re: Mixed model
I just use a password manager these days, it is easier than faffing around and keep telling the browser never to ask to store a password for a specific site. I just disable it completely.
I use 2FA everywhere, never SMS, and preferably a Yubikey.
The whole industry only exists because Microsoft has no sane solution for Windows. On the other side, Mac users save their passwords in the Keychain, Linux users do the same with gnome-keyring and KDE kwallet for literal decades now.
Why on earth would I want to entrust my info to MS or save in a MS keychain?
Eggs in one basket much?
There's little difference between the use of something like kwallet and say bitwarden.
> Eggs in one basket much?
Downvote for that horrific American use of "much" that I thought had died a death (much).
So people moan at MS when it pushes other companies out of the market and moan when it leaves a gap in the market.
That's the joy of being in the audience: You're free to criticize as much as you want safe in the knowledge that you won't actually have to come up with an answer yourself.
The problem is for those of us who don't work in an OS monoculture. We need cross platform tools.
This is bullshit. Cross-platform software always sucks. Always. No exception. A tool should integrated into the system conventions as well as possible. A Windows application should follow Windows conventions, a Mac application should follow Mac conventions, and so on.
This is particularly true for a password manager, so you don't need insecure dirty clipboard tricks to enter passwords into forms. The only cross-platform thing we need in this area is a portable format for export/import and backups of password databases.
Control Panel > User Accounts > Credential Manager?
You missed the "No sane solution"
A bit like giving the local fox your chickens and saying, "I'm off to benedorm for a week. Be a love and look after the clucks for me."
Doesn't store website passwords. Chromium Edge I think stores them in OneDrive.
There is a Web Credentials 'tab', at least in my version of Windows. Can't say I remember it always being there, it might just be the most recent versions of W10.
It does work with IE at least. In my case it's full of intranet passwords for stuff which won't work with anything else.
Exactly. Windows needs a built-in password manager if we want this to stop.
This is one of the main reasons I am using a Mac (both at home and at work). Also, integration with Keychain across all Apple devices is a godsend.
I use a mix of macOS, Linux, iOS, Android and Windows. Therefore Apple Keychain is useless, as are gnome-keyring. For those not using just one platform, it has to be a platform independent solution.
I use the browser because I have more important things to do with my life, like watching TV.
I trust Google to be secure more than I trust TrustworthyPasswordManager.
Also any sites that are of any importance ( eg: banking, email, even social media ) have 2FA.
Training
"Meanwhile, about half of those working for large (5,000+ headcount) companies said they hadn't received cybersecurity training in the past 12 months"
But I bet they've all received 'Unconscious Bias training", "Diversity training", "Personal Pronoun training", "Cultural Competency training", "Preventing Discrimination and Harassment training", and of course "Creating an Inclusive Workspace training."
All far, far more important than any old IT security nonsense. That's IT's job, innit.
as connecting personal devices to corporate networks
We use 802.1X to avoid this. We also get alerts when some jerk user connects his/her smartphone on a professional computer to charge it. I would love to practice kneecapping on them, alas company policies doesn't allow it.
Mixed model
I use the browser for sites for forums and things of that nature. I use Password Safe for everything else. Aside from that I enable 2FA whenever it's available so even if someone does somehow get my password it's not necessarily going to help them.