Beware Keyloggers at Hotel Business Centers
krebsonsecurity.com
krebsonsecurity.com
1) My usual technique is to type the last three chars, mouse to the beginning of the field, type the next to last 3, mouse to the beginning, next 3 repeat till done.
Using a second factor for authentication provides some extra security, but a well-configured trojan might intercept your logout request, display a fake logout confirmation and store your session data for their botmaster to peruse.
If you need to regularly use untrusted machines (and have access to usb ports or a cd drive), you could bring a hardened browser with you. That should defeat most "Man-in-the-Browser" tricks. Or, even better, a live CD or USB drive. At this point, you should still assume your keyboard and screen to be compromised, but the OS should be safe enough to cautiously use.
Maybe this should be a feature request to the web-app devs.?
Use this site to support web apps with 2FA, or request 2FA for unsupported sites: http://twofactorauth.org/
[Application $DATE_TIME]
key that ii[backspace]s b[backspace]ein pressed
[Other Application $DATE_TIME]
Keys being pressed in other applicationI have an "unsecure email account" that I mail boarding passes to (to print them at hotels).
You should never have to log in to a secure account on an untrusted computer. Why would you have to? Bad corporate policies or something?
We have a winner. When I try to explain keylogging to them, they assure me that the vendor is first rate thanks to the money we pay and the webmail security is "unbreakable" on our system.
I've also found machines at VRBO rentals that were compromised. So far I've not found any that had their wireless routers replaced with MiTM routers but I expect that isn't too far down the road.
Deleted comment
Short of a VPN, HTTPS Everywhere (https://www.eff.org/https-everywhere) and maybe something like Little Snitch (http://www.obdev.at/products/littlesnitch/index.html) so you can tell when non-browsers are attempting to connect to non-HTTPS sites.
https://docs.openvpn.net/how-to-tutorialsguides/virtual-plat...
Sure, it's a paid product, but you get to run 2 concurrent users for free and you can use any of the Amazon datacentres and any of the instance types… t2.micro's are just fine for quite a large number of users.
For the tech-savvy, use VPN, it's free[1]. And there's pre-built images[2].
[1] http://www.reddit.com/r/VPN/comments/11vmnf/how_to_use_a_fre...
[2] http://openvpn.net/index.php/access-server/cloudmachines/513...
You should assume any computer you don't own is keylogged, period.
However, as "Who is surprised!" has become a standard meme in security/privacy related threads, I want to point out a few things that may be interesting:
- the actual extend of the threat (numbers?)
- the extend to which the general public has come to terms with this problem
- the reactions around the web and proposed solutions ("use this kiosk linux distro")
- discussion of similar/related threats (like "also watch for public wifi")
It would be great to re-hash the information to the general public, however.
Extend: https://www.google.co.in/search?q=define%3AExtend
They are not the same.
A keylogger just "logs" keystrokes, either locally or remotely, for later use. While this is a valid threat, using two-factor authentication basically makes this a non-issue. On the other hand, malware that targets specific login fields is usually smart enough to also steal session cookies, or with most banking trojans, inject requests into your live browser session.
The latter is used to literally transfer money in/out of your account, or make automatic purchases, while you browse the web. There is no protection from these trojans. If you're infected, you're fucked. The only thing 2FA saves you from here is repeated attacks once your session expires. (Luckily i've never personally seen a trojan like this built for Linux, but that's just a matter of time/market share)
I am starting to think that security people should stop using the term "keylogger" altogether. It is unhelpful, and damn right dangerous.
When people read "keylogger" they often envision malware which sits there and grabs your keystrokes, so then people assume (see posts elsewhere in this HN thread even) that using on-screen keyboards or jumping back and forth between fields saves them.
Classical literal "keyloggers" are now mostly gone. Grabbing a long series of keystrokes is extremely hard to automatically utilise (which is the goal now). Instead malware will either inject itself into the TCP/IP stack, HTTP stack, or directly into the browser (most popular) itself to steal credentials after the form is submitted but before it is encrypted and sent over the network.
The advantage to the "bad guys" of doing things this way is that they get contextual information (e.g. form name, form destination URL, as well as username/password). Once you have login information AND contextual information you can automate it entirely and ignore a lot of stuff you aren't interested in (e.g. steal Google accounts, but ignore Hacker News accounts).
Other than spouses spying on one another or a parent spying on their kid, a "keylogger" is pretty much dead in the classical sense. No organise crime gang wants a few gigabytes of keystrokes they have to sort through in order to get to the good stuff.
I still wouldn't login to them, or any other financial account, on an untrusted device, though.
Sqrl looks to have some pretty bad flaws.
Does this sqrl improve on the existing security offered by alternatives? Likely not. It just offers convenience and keeps many of the existing downsides.
Honestly 2/3 of those criticisms can be leveled at ANY single-sign-on scheme (Facebook, Google, Microsoft, etc). And the password reset issue would be trivial to engineer around.
So using it to explain why sqrl is a bad idea is a little confusing, are Google accounts also a bad idea?
I don't know about most. Certainly many people do, and it's fairly convenient to have one.
On the other hand, the input capabilities of smartphones are so limited that I find it hard to imagine finding anybody - even otherwise computer-savvy people - whose smartphone data is encrypted using a reasonably secure keyphrase.
At the end of the day, as you said, phones are easier lost and stolen, but there is barely a difference now in the functionality of security between a phone, laptop, and desktop; they're all the same. Now, for convenience, many users don't bother having a password on their phone. That's not functionality though, that's just how a user has decided to protect their phone's content...
Or three factors: biometric / password on phone, show OTP to site, then enter some password in site
Anyone knows of a website actually implementing this? [0]: http://blog.bitpay.com/2014/07/01/bitauth-for-decentralized-...
I often have to print something from my email from untrusted computer (boarding pass, some documents, etc). When it's possible, I save the thing to print to PDF, upload to S3 and make a memorable short URL using bit.ly. Whenever possible, works very smoothly :)
The added benefit is that you can do this from mobile, which may not be possible with S3!
I suppose the relevance of my entire comment hinges on the presumption that anyone reading HN only uses hotel PCs for printing stuff. Valid?
While installing Go, I found Prey Anti-Theft on my HDD. Nice little bit of camera snapping, location and such. Was never told about it, which also annoyed me.
In short, if it's not your machine, assume it's compromised. LiveUSB's FTW.
If you're building a website, you can help mitigate keyloggers with One Time Password support, eg login via cellphone app (which doesn't have to have a signal but can store a million random codes a la the RSA dongle) unless that's somehow patented - is it?
But fake auth forms are equally egregious. For this, you simply need the user to enter (or receive) a relatively unique (1 in 10,000) phrase or icon that they remember when signing up. Then show this phrase when one of your input fields in your domain security context (iframe or popup) is focused. There is no way for other websites to grab that phrase or icon, and therefore the user is trained to check that YOUR field on YOUR domain is the one receiving keyboard focus.
I once wrotr a letter to Steve Jobs saying the iOS should also have something similar - that the system dialogs where you enter your admin username and password to authorize something should show you a familiar phrase or icon which userland apps can't screenshot, similar to how they protect copyrighted video. But he never replied or implemented it.
After all, Vista did it by darkening the screen... Any app can do that!
Specialized keyloggers ought to be cheaper.
Keyloq make a range of products.
Any computers that allow access to the public are going to be keylogged, if not with software then with physical keyloggers.
Same as LAN Centers use to be all keylogged as well.
While that's a noble question, you might as well ask why can't the universe simply not advance to its entropic heat death... or why cars and homes are still sold with locks on the doors.
Think of it like playing DOOM. There are 2 options :
1) something is moving. Quick ! Shoot it !
2) something is not moving. Therefor it must be thinking about moving. Quick ! Shoot it !
Exploring process names is sub-optimal on modern OSes.