Aug 30, 2013

The Number of TOR Users Has Doubled Since Snowden's NSA Leak

English: Tor Logo
English: Tor Logo (Photo credit: Wikipedia)
I have been telling people to use TOR to protect their browsing privacy since SOPA and PIPA started snaking their way through Congress, but people didn't really get the gravity of online privacy, and government abuse until Edward Snowden spilled the beans about the NSA's PRISM program.

Now apparently the TOR Project has seen the usage of TOR in the United States double!

From RT:
Internet users throughout the world have signed up in droves for anonymity software that allows them to live and interact online without international governments being able to monitor their activity.

The Tor Project reported that the number of people subscribed to its service has doubled since June, when former National Security agency contractor, Edward Snowden, revealed that United States intelligence analysts were secretly tracking global internet activity. Short for “The Onion Project,” which implies of layers anonymity, Tor conceals a computer’s location and relays an individual’s messages, search queries, and other functions through a series of encryptions.

While the numbers have not been directly attributed to the NSA leak, the number of Americans using Tor jumped 75 percent between June 1, just days before the Snowden leak, and August 27, 2013. US citizens now make up 17.54 percent of the daily Tor traffic, making Americans the only nationality to surpass 10 percent of the networks’ user base. 
Like I said before, I'm a huge proponent of online anonymity, and have even put TOR on Bauer-Puntu Linux by default to help keep "the man" out of your business.

Do you use TOR? Why or why not? Let us know in the comments.

Enhanced by Zemanta

Aug 29, 2013

Popular Free Hash Cracker Can Now Break Passwords Up To 55 Characters

Hacker inside
Hacker inside (Photo credit: Wikipedia)
How many of you think your systems are secure because you use complex passwords of 8 characters or more? How many of you think that passwords in your applications are safe because they are stored using a complex hash algorithm? If you think you are secure, you are wrong.

The popular hash cracking program oclHashcat-plus now has the ability of cracking the hashes for passwords or passphrases of up to 55 characters!

From Ars:
Until now, ocl-Hashcat-plus, the Hashcat version that can use dozens of graphics cards to simultaneously crack huge numbers of cryptographic hashes, has limited guesses to 15 or fewer characters. (oclHashcat-lite and Hashcat have supported longer passwords, but these programs frequently take much longer to work.) Released over the weekend, ocl-Hashcat-plus version 0.15 can generally accommodate passwords with lengths of 55 characters. Depending on the hash that's being targeted and the types of cracking techniques being used, the maximum can grow as high as 64 characters or as low as 24. The long sought-after improvement targets one of the last remaining defenses people employ to make their passwords resistant to cracking.

"This was by far one of the most requested features," Jens Steube, the lead Hashcat developer who also goes by the handle Atom, wrote in the release notes for the new version. "We resisted adding this 'feature' as it would force us to remove several optimizations, resulting in a decrease in performance for most algorithms. The actual performance loss depends on several factors (GPU, attack mode, etc.), but typically averages around 15 percent."

As leaked lists of real-world passwords proliferate, many people have turned to passwords and passphrases dozens of characters long in hopes of staying ahead of the latest cracking techniques. Crackers have responded by expanding the dictionaries they maintain to include phrases and word combinations found in the Bible, common literature, and in online discussions. For instance, independent password researcher Kevin Young recently decoded one particularly stubborn hash as the cryptographic representation of "thereisnofatebutwhatwemake." Such cracks are known as "offline attacks" because they target the hashes leaked as a result of a database compromise, allowing the person who recovers the hashes to try an unlimited number of guesses until the correct plaintext passwords are found. Once the underlying credentials are revealed, a hacker can use them to compromise the online account they secure.

Yiannis Chrysanthou, a security researcher who recently completed his MSc thesis on modern password cracking, was able to crack the password "Ph'nglui mglw'nafh Cthulhu R'lyeh wgah'nagl fhtagn1." That's the fictional occult phrase from the H.P. Lovecraft short story The Call of Cthulhu. It would have been impossible to use a brute-force attack or even a combined dictionary to crack a phrase of that length. But because the phrase was contained in this Wikipedia article, it wound up in a word list that allowed Chrysannthou to crack the phrase in a matter of minutes.

Until now, hackers and security consultants who cracked such words had to use software controlling the central processing unit of their computer or that used one or more graphics cards to crack a single hash. This weekend's update means that for the first time, Hashcat users can achieve speeds as high as eight billion guesses per second on a virtually unlimited number of compromised hashes. Breaking the 15-character limit is just one of several improvements designed to bring increased speed and precision to the password cracking program.

So what options do you have to fight this? You can make even longer passwords that are even harder to remember, or you can implement two factor authentication.

Here is a video I did for Tech Chop talking about a really cool free two factor authentication program called Phone Factor that might do the trick for you.



What do you think about this? What are you doing to keep your network safe? Let us know in the comments.
Enhanced by Zemanta

Aug 28, 2013

Dumping DSL? Making the Switch to 4G Internet



Simply thinking about switching your Internet services can lead to information overload as you take note of the dozens of available options. Dial-up, DSL, 3G service, 4G service, fiber optic technology: there are so many technical terms involved in establishing a new Internet service, it can be tough to know which one is best for you. For households with numerous mobile devices, switching to 4G Internet might make the most sense.

What is 4G Internet Anyway?

The “G” in the 4G label refers to "generation" of wireless technology. At its most basic level, 4G simply means 4th generation wireless Internet service. But what does that get you? Well, the first generation of wireless technology refers to old analog cell phones primarily used in the ‘80s and ‘90s, according to PC Mag. 2G technology brought basic digital technology to mobile devices -- these are now dubbed “feature phones” and typically offer voice and texting services. With 3G technology, mobile devices took a leap forward, connecting to the Internet and running apps.
The advent of 4G Internet technology may render 3G service obsolete, according to Huffington Post (2). The primary advantage of 4G wireless service is its blazing fast speeds. With more users on 3G networks, data traffic has slowed 3G service considerably. Most 4G Internet users get speeds of 10 to 30 Mbps, significantly higher than DSL or 3G connections.

Consider Your Coverage Area

Although Sprint, CLEAR, Verizon, T-Mobile, AT&T, and other carriers now offer 4G service, coverage varies by provider. Before making your choice, check out coverage maps offered by each Internet provider in your area. Most providers offer 3G service even if 4G is not yet available in your region. People living in very rural areas may not yet have access to 4G coverage, making DSL a better choice.

Deciding on an Internet Service That Is Best for You

Before making the switch to 4G service, consider key factors that may influence your choice:
  • Type of mobile devices: Manufacturers are in an arms race to come up with the best devices to offer 4G service. Check the technical specs on your laptop, smartphone, tablet, and other mobile devices. Nearly all of the latest devices offer 4G access, but those that are several years old may not be compatible with 4G service.
  • Typical Internet use: Think about your patterns of Internet use. Are you a heavy gamer? Someone who loves to stream Netflix, Hulu, or YouTube videos from your phone? Or do you mostly just send emails and surf the web? Individuals who frequently stream video, download songs, or upload pictures online will notice significant improvements in their Internet experience with 4G service.
  • Where do you need Internet access? Consider where you typically use the Internet and the places you need access the most. If you spend most of your online time at home, check out home 4G Internet solutions. People who love to browse the web while on the go may be content with mobile access.
  • Budget considerations: Keep in mind how much you’re willing to spend on Internet service. Faster 4G service might cause you to burn through data more quickly, resulting in higher bills. Comparison shop for the best rates in your area, paying close attention to data caps and overage charges before making the switch.
Enhanced by Zemanta

Aug 27, 2013

Handy GUI Tool To Configure SSL on Your Windows Server For PCI/DSS or FIPS 104-2 Compliance

I've written a number of posts on making your servers PCI compliant. It's one of the many duties I'm tasked with at my day job. The hardest part in my opinion is getting your SSL certificates squared away.

In Windows 2003 you had to manually edit the registry to disable ciphers and protocals. In Windows 2008 and above you have to set a local security policy to modify the cipher suite order. It's all a bit of a pain.

Well I found a free tool that lets you make the necessary changes with the click of a button. It's called IIS Crypto! From their page:
IIS Crypto is a free tool that gives administrators the ability to enable or disable protocols, ciphers, hashes and key exchange algorithms on Windows Server 2003, 2008 and 2012. It also lets you reorder SSL/TLS cipher suites offered by IIS and mitigate the BEAST attack. 
Here is a screen shot:


I originally found this tool because I was looking to see if there was a way to avoid restricting all ciphers to 128 bit RC4 on Windows 2003. I was hoping this tool would allow me to change the cipher order, but sadly it just isn't supported in Server 2003, so restricting all ciphers to 128 bit RC4 is still the only way to mitigate against The BEAST.

In Windows Server 2008 R2 at least it makes changing the SSL Cipher Suite order super easy.

All-in-all it's still a great tool for making your servers compliant, and more secure.
Enhanced by Zemanta

Aug 26, 2013

Four Light Linux Distributions For Older PC's

I received several free Powered By Ubuntu stickers requests in the mail over the weekend, and in one of them a guy wrote a letter saying that he was starting a non-profit where he re-purposed older machines and put Linux on them. He wanted to know what Linux distributions I recommended for older machines.

I mean a lot of people like standard Ubuntu, but with Unity it can be a resource hog on Pentium 4 machines right? So here are the four distributions I recommended for older hardware:

  • Lubuntu - Lubuntu is a fast and lightweight operating system developed by a community of Free and Open Source enthusiasts. The core of the system is based on Linux and Ubuntu . Lubuntu uses the minimal desktop LXDE, and a selection of light applications.

  • Puppy Linux - Linux is a free operating system, and Puppy Linux is a special build of Linux meant to make computing easy and fast.
  • Xubuntu - Xubuntu is an elegant and easy-to-use operating system. Xubuntu comes with Xfce, which is a stable, light and configurable desktop environment. Xubuntu is perfect for those who want the most out of their desktops, laptops and netbooks with a modern look and enough features for efficient, daily usage. It works well on older hardware too.
  • DSL (Damn Small Linux) - Damn Small Linux is a very versatile 50MB mini desktop oriented Linux distribution. DSL has a nearly complete desktop, and a tiny core of command line tools. All applications have been chosen for the best balance of functionality, size and speed.
With so many distros out there to choose from I'm sure there are many more that are light-weight and perfect for older machines. What do you suggest? Let us know in the comments!
Enhanced by Zemanta

Aug 20, 2013

Windows Evolution Shown Using Houses



[Via Imgur]

Aug 19, 2013

It's About Time: 5 of the Newest, Coolest Apps for BlackBerry Q10

It may have been a slow start, but app developers have finally started creating great apps for BlackBerry devices. With a full offering of smartphones, BlackBerry has shown itself to be serious about remaining at the top of the mobile phone game, and now with the release of the BlackBerry Q10, the apps are appearing in an ever-increasing flow. Those who've steadfastly remained true to their first cell phone love might be overwhelmed with the choices, so here's cream of the BlackBerry Q10 app crop.

BlackBerry Q10 image by Janitors via Flickr.

360 Panorama

BlackBerry Q10 phones come with an excellent high-def resolution camera on board. But for less than $3 you can turn that already highly functional camera into one that takes spectacular panoramic shots as simply and easily as taking a normal picture. The 360 Panorama app gives you the capability to save or instantly send and post your panoramic pics, to preserve and share breathtaking vistas and landscapes or even capture the whole gang at the class reunion for posterity.

Pacemaker

Be the DJ you always knew you could be with the Pacemaker app for BlackBerry Q10. You'll feel like a musical wizard as you alter tracks and tempos, bend the pitch, craft synchronized loops midstream and sync the tempo of two different tracks to blend them into your own marvelous audio creation. With a cross fader and other pro-level features, the sky's the limit. The best part is how user-friendly Pacemaker is. The app does all the work, you take all the credit.

Backup Contacts

Never worry about losing a contact from your list when you have the Backup Contacts app. With just one click all your contacts get backed up — yes, all contacts on your BlackBerry Q10, the SD card and even email. You can send, view and restore your backup via email and there's a feature to automate a daily backup so your list is always up to date.

Blaq

The best description of the Blaq app: a Twitter cloud for your BlackBerry Q10. It's a necessity for those with multiple Twitter accounts because Blaq takes the place of various Twitter apps you needed in the past to wrangle all the accounts. Blaq will sign you into your complete list of accounts and allow you to Tweet from them simultaneously or just from one, plus it has direct messages, mentions and real-time streaming. The Blaq app is a power Tweeter's dream come true.

Skype

Skype for BlackBerry is the app users have been anticipating most. Available since the BlackBerry Q10 was launched, Skypers can now make video and voice calls from their BlackBerry Q10 and message family and friends anywhere in the world regardless of the receiver's device.
That's just for starters. Now that the developers are on a roll bringing BlackBerry Q10 apps to the masses, they're not likely to stop. The field is wide-open for usable applications that make your already essential BlackBerry even more indispensable.
Enhanced by Zemanta



Twitter Delicious Facebook Digg Stumbleupon Favorites More

 
Design by Free WordPress Themes | Bloggerized by Lasantha - Premium Blogger Themes | stopping spam