Super Bowl Wi-Fi password credentials broadcast in pre-game security gaffe
zdnet.com
zdnet.com
Of course I tried it, of course it worked. There was a nice "motd" to the effect: be cool, don't break stuff.
I'm sure this breach was nowhere near as deliberate.
As a hacker in MIT's AI laboratory, Stallman worked on software projects such as TECO, Emacs for ITS, and the Lisp machine operating system (the CONS of 1974-1976 and the CADR of 1977-1979—this latter unit was commercialized by Symbolics and LMI starting around 1980). He would become an ardent critic of restricted computer access in the lab, which at that time was funded primarily by the Defense Advanced Research Projects Agency. When MIT's Laboratory for Computer Science (LCS) installed a password control system in 1977, Stallman found a way to decrypt the passwords and sent users messages containing their decoded password, with a suggestion to change it to the empty string (that is, no password) instead, to re-enable anonymous access to the systems. Around 20% of the users followed his advice at the time, although passwords ultimately prevailed. Stallman boasted of the success of his campaign for many years afterward.[15]
It's not a new concept, but it's worth repeating, considering that we're still using the term "password" in 2014.
http://www.codinghorror.com/blog/2005/07/passwords-vs-pass-p...
"Most people use passwords. Some people use passphrases. Bruce Schneier uses an epic passpoem, detailing the life and works of seven mythical Norse heroes."
Jokes aside, I'd really prefer if we'd ignore passwords and passphrases (and passpoems) altogether, leaving them for emergencies, and generally switch to keypairs and, preferably, hardware security tokens.
Edit: keypairs works too. Doesn't change the advice.
They're quite common. Many laptops have TPM modules, popular SoCs (like nVidia Tegra) have them too, and most modern motherboards at least have a socket for one. Yet, the only use of them I've ever seen is validating the boot chain's integrity.
Also, USB tokens are not common in users' possession, but if necessary I believe you could get one within a day.
It just need a little push from software vendors. Imagine your OS or browser says "Hey, do you want to secure your credentials? Here's how...". Or just start with an option "use hardware security token" somewhere under settings - while of less impact than active suggestion, it will still strike users curiosity and start things moving bit by bit.
Imagine a 6 word phrase.
7776^6 = 2.2107391972073e+23
That's pretty good and that's only six words from a list of published words.
If you want phrases to work properly, just put 1 (or many) non-dictionary word in them. This means the attack has to go to an alphabetic one instead of a phrase one, making it _much_ more painful.
A lot of staffers are likely in and out of that room in the weeks leading up to today, with the instructions probably posted by some exhausted sysadmin being asked "how to I get on the wifi again?" for the thousandth time.
A honeypot?
Plenty. Anybody with ill intentions could set up a similar wifi network or tamper with the existing one and suddenly thousands of people's traffic/passwords are all being sent via MITM.
(Sorry, but I tend to be skeptical about this kind of thing)
They would have been better off using 12 random lowercase letters. It would have more entropy and be easier to type on mobile devices.
What they really shouldn't have done is put it on a screen that was broadcast on national tv.