Adobe credentials and the serious insecurity of password hints
troyhunt.com
troyhunt.com
Troy wondered if there might be a security risk to announcing having found these matches (I suppose the reasoning is that if passwords are reused once, they are probably reused more than once, and so looking for such notices might help crackers track down easily compromised accounts), but decides there is not. Given the low-key way FB have gone about this, I guess this is right, and maybe this should be best practice for future password leaks. I wonder if anyone else has done this?
For convenience, the announcement by Chris Long, of FB (from his comment on Brian Krebs' blog, at http://krebsonsecurity.com/2013/11/facebook-warns-users-afte...):
> I work at Facebook on the security team that helped protect the accounts affected by the Adobe breach. Brian’s comment above is essentially spot on. We used the plaintext passwords that had already been worked out by researchers. We took those recovered plaintext passwords and ran them through the same code that we use to check your password at login time.
> Like Brian’s story indicates, we’re proactive about finding sources of compromised passwords on the Internet. Through practice, we’ve become more efficient and effective at protecting accounts with credentials that have been leaked, and we use an automated process for securing those accounts.
Use case is to implement the FB-style security escalation for high-value accounts at my businesses, without requiring an on-call security team. If a dentist loses their client database because they reused the password on a PHPBB somewhere I'm likely in for a lot of headaches even if eventually found to not be at fault.
I.e. lots of organizations don't quite realize they have a need for this and would have a hard time understanding why its useful.
I know I know, I just shouldn't use Ghostery but I like to have a little privacy online.
Sorry I won't return to your site again...
Try disconnect.me or blacklisting the sites directly from the hosts file.
Thanks for disconnect.me, I'll give it a shot :)
how many hosts entries would you say it is before the negative impact is significant? 20? 100?
Going to go have a look at disconnect.me now.
As far as other products, heres a handy chart we generate monthly to see which extension protects better: http://www.areweprivateyet.com/
I'm going to give disconnect.me a try and see how that works out.
1. This reminds me of a funny thing I did at big name university that shall remain nameless. On the CS network which used NIS, I ran getent passwd as a regular user and received everyone's hashed passwords! Then, I piped that through john the ripper.... Say hello to 50 user's passwords in 30 seconds with nothing more than the standard English dictionary. (In an era just before shmoo, et. al. rainbowtables.). Dept chair, ~20 profs and some students. Drop a cron to start xeyes every 30 minutes anyone? }:)
They could just be using email addresses, but that seems rather blunt.
I'm not a huge fan of Facebook, but what they're doing does seem like an excellent idea.
Edit: oh it's the same guy who has this beast of a cracking cluster! http://arstechnica.com/security/2012/12/25-gpu-cluster-crack...
Edit2: more details about how the decoding works http://nakedsecurity.sophos.com/2013/11/04/anatomy-of-a-pass...
Facebook wants to determine if facebook_password == adobe_password. Without the key, that's impossible. And I think 112 bit keys as provided by 3DES are still secure, even considering an adversary with the resources of Facebook.
A lot of the articles analyzing the adobe passwords seem to be comparing known-common passwords, passwords hints, and the insecurities of ECB-mode, which doesn't really scale. It seems like it would be better for facebook to just have a blacklist of common passwords (123456, password, etc), although then I suppose they don't get credit for pro-actively responding to a password leak (note: I'm not claiming that's why they're doing it - it seems like a good response, and I'm genuinely curious how they're doing it).
Edit: I just thought of way they could do it. Generate a histogram over the first 8 bytes of each encrypted password. Pick a threshold (e.g. 2, or 10, but you'd have to look at the data to get a good number) above which the password is considered "common" and therefore insecure. Go through the list of email addresses in the adobe dump that have a "common" password, and if there's a facebook account with that email address force a password reset. That seems like it would work fairly well, and doesn't require any knowledge of the plaintext passwords.
Ultimately, password hints are evil and they add nothing to an online system that can’t be achieved with a secure password reset feature.
It's a classic case of someone criticizing one important feature without suggesting viable alternatives. He might as well have said,
Gasoline engines are evil and they add nothing to a world that can't be achieved with a more efficient propellant.
Yeah, okay - but what's the more efficient propellant?!?!
Password hints aren't "evil" just because (a) Adobe happened to store theirs in plain text, and (b) some users do use seriously identifying information in theirs. Password hints make it fast and easy for an actual user who genuinely needs to reset their password to be able to do so quickly and efficiently. What's the secure password reset feature that Troy alludes to? I missed it.
I've seen a few concepts. One I liked was the selection of two or three images from a gallery. If the user correctly identified the ones he had selected at sign-up then a new password was sent to the registered e-mail address.
But any password reset process should ensure that it never links back to the original password. Reset, not recover.
It isn't going to happen.
http://www.troyhunt.com/2012/05/everything-you-ever-wanted-t...
I think the point about password hints is that, like secret questions, they typically reduce the security of the account when used by actual users. Alternative approaches protect users from themselves.
"Ultimately, password hints are evil and they add nothing to an online system that can’t be achieved with a secure password reset feature."
Secure password reset.
Password hints have multiple uses. For identity management and verification systems, it's used as an additional identity check after the password if the host seems to have changed. For password recovery, it's a "need to know" factor you have to pass before you get to the "need to have" of e-mail account access. Since it's trivial to bruteforce, multiple hints of different categories are usually deployed.
In the real world, hackers compromise accounts by finding out the personal details they need to subvert password-recovery steps. Find the last four of the social, their birth date, address, and phone number, and you can basically hijack any bank, telephone, utility or government account a person has. Password hints are (when properly implemented) more secure because they can leverage other access methods.
Did they need to keep the hint plaintext? No; they can hash it just like any other password. But as the complexity requirement of the hint is much lower than that of passwords, it should be required to use another factor (such as an e-mailed confirmation code, SMS, or many more hints or sensitive information) to allow the hint to succeed.
You seem to be talking about stuff of the form, "What is my mother's maiden name?"
A password hint is exactly what it says: a hint for what your password was, to help you avoid forgetting it. If your password is "lassie", then your password hint might be something like, "That dog you like from TV." The problem, of course, is that just about any hint that helps you remember your password also helps an attacker guess it.