News: 1715333414

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

UK's National Cyber Security Centre entry code cracks up critics

(2024/05/10)


Rolling hot off the heels of World Password Day (groan), every May 2 we hacks generally receive hundreds of emails from PR companies repping their respective infosec pros, all espousing their expert opinions on how to create an "iron-clad" or "military-grade" password, or something equally cringey.

We didn't write anything about it because, quite frankly, it's all a bit dull. We know what is and isn't a good password – national security agencies tend to all agree with one another to a certain extent and anyone with an iota of cyber literacy knows the good from the bad and the downright terrible. There's no "password123" nonsense here at Vulture Central.

However, according to a Xeet from the UK Daily Mail's political editor, Jason Groves, journalists attending the headquarters of the UK's National Cyber Security Centre (NCSC) on Thursday were told some information that appeared to fly in the face of conventional password hygiene.

[1]UK opens investigation of MoD payroll contractor after confirming attack

[2]UK lays down fresh legislation banning crummy default device passwords

[3]Your password hygiene remains atrocious, says NordPass

[4]CISA reveals 'Admin123' as top security threat in cyber sloppiness chart

The NCSC still stands by its password guidance of creating a string out of three random words, an idea it may or may not have [5]swiped from our readers , but it doesn't appear to have been in use when reporters attended the NCSC where foreign secretary David Cameron was delivering an address.

Groves said reporters were told the security code for the doors at the UK's cybersecurity agency was – drum roll please – 1234.

[6]

Sounding way too funny to be true, we caught up with Groves who confirmed to us that the Xeet wasn't a joke as it initially seemed at first glance. Reporters were told the code on arrival and then the head of events blasted it out loud from a stage later on.

[7]

We've since been made aware that these passcodes were only temporary and wouldn't have allowed access to any of the really interesting rooms in Nova South where the serious action goes down (boring).

Regardless, it still gave the vultures something to cackle and crow about on a Friday morning, and weren't the only ones.

[8]

Responding to Groves on X, someone [9]asked "is the WiFi password password?" Another [10]said : "No doubt someone will randomly try 1234, and be told that they 'hacked' their way in." ®

Get our [11]Tech Resources



[1] https://www.theregister.com/2024/05/08/uk_opens_investigation_into_contractor/

[2] https://www.theregister.com/2024/04/29/uk_lays_password_legislation/

[3] https://www.theregister.com/2023/11/20/your_password_hygiene_is_still/

[4] https://www.theregister.com/2023/10/06/cisa_top_10_misconfigurations/

[5] https://www.theregister.com/2021/04/09/ncsc_secure_passwords_three_words_advice/

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/bootnotes&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Zj3wQYb0GBuBA4yyQbi8sQAAABY&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/bootnotes&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Zj3wQYb0GBuBA4yyQbi8sQAAABY&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offbeat/bootnotes&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Zj3wQYb0GBuBA4yyQbi8sQAAABY&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[9] https://x.com/keiranpedley/status/1788519313655144878

[10] https://x.com/DavidJEastman1/status/1788519588272971973

[11] https://whitepapers.theregister.com/



Chloe Cresswell

Physical hygiene on digital locks can be as important too. Had a client move into an office building temporarily.

Digital pad locks for the doors. I said to the office owners they needed to clean them.

They said it's secure, there's so many combinations.

I pointed out there were 4 "clean" patches with dirty surrounds.

2 of them were the number 1 and 9. Given the chance of someone using a date as the code, that changed the number of options from $LOTS to 2.

I opened the door on the first attempt.

They cleaned the pads and made sure to clean them regularly after that.

Doctor Syntax

The smart thinking would have been to leave the pads uncleaned but change the code to something that didn't used only two of fewer of the four.

Mike 137

I get the impression that there's a pretty effective firewall between the infosec experts and general corporate management at the NCSC. While their public guidance generally meets current best practice, their business practices don't always seem to (as this report suggests). But not only this. The NCSC online presence is entirely a javascript "app" although it's almost entirely a collection of static pages. You can't even see any content at all, not even the emergency contact number, with scripting disabled and this has been the case for quite a few years despite myself (hopefully, not alone) pointing it out several times.

Equal bytes for women.