<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:creativeCommons="http://backend.userland.com/creativeCommonsRssModule"
>

<channel>
	<title>ISIS &#187; Social Engineering</title>
	<atom:link href="http://isisblogs.poly.edu/category/soceng/feed/" rel="self" type="application/rss+xml" />
	<link>http://isisblogs.poly.edu</link>
	<description>Information Systems and Internet Security</description>
	<lastBuildDate>Mon, 20 Oct 2008 17:57:50 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.5</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<creativeCommons:license>http://creativecommons.org/licenses/by/3.0/us/</creativeCommons:license>
		<item>
		<title>Security Awareness Posters</title>
		<link>http://isisblogs.poly.edu/2008/09/01/security-awareness-posters/</link>
		<comments>http://isisblogs.poly.edu/2008/09/01/security-awareness-posters/#comments</comments>
		<pubDate>Mon, 01 Sep 2008 23:27:10 +0000</pubDate>
		<dc:creator>dan</dc:creator>
				<category><![CDATA[Events]]></category>
		<category><![CDATA[Meta]]></category>
		<category><![CDATA[Press Release]]></category>
		<category><![CDATA[Psychology of Security]]></category>
		<category><![CDATA[Social Engineering]]></category>

		<guid isPermaLink="false">http://isisblogs.poly.edu/?p=208</guid>
		<description><![CDATA[Every year, as part of CSAW, we hold a Security Awareness Poster contest where we ask students to convey a simple message regarding any current issue in information security. These posters always turn out amazing and are among the most impressive, if non-technical, entries we get. Unfortunately, we haven&#8217;t been so good at sharing these [...]]]></description>
			<content:encoded><![CDATA[<p>Every year, as part of <a href="http://isis.poly.edu/csaw">CSAW</a>, we hold a Security Awareness Poster contest where we ask students to convey a simple message regarding any current issue in information security. These posters always turn out amazing and are among the most impressive, if non-technical, entries we get. Unfortunately, we haven&#8217;t been so good at sharing these posters with others and usually only make a few printouts for ourselves in the lab.</p>
<p>Today, that is going to change. I uploaded my hand-picked favorites from the last 3 years to my web site for the entire web to enjoy! I tried to mark who made what poster in the title but please leave me a message if I missed yours.</p>
<div id="attachment_209" class="wp-caption aligncenter" style="width: 241px"><a href="http://isisblogs.poly.edu/wp-content/uploads/private-information-is-worth-keeping-hidden.jpg" rel="lightbox[208]"><img class="size-medium wp-image-209" title="private-information-is-worth-keeping-hidden" src="http://isisblogs.poly.edu/wp-content/uploads/private-information-is-worth-keeping-hidden-231x300.jpg" alt="" width="231" height="300" /></a><p class="wp-caption-text">Amanda Morante&#39;s 1st place entry from 2006</p></div>
<p><a href="http://cryptocity.net/files/awareness_posters/">View the full library of awareness poster images here</a>.</p>
<p>Registration for <a href="http://isis.poly.edu/csaw">CSAW 2008</a> is still open and we will be having the <a href="http://isis.poly.edu/csaw/awareness">Security Awareness Poster</a> contest again, in addition to 6 other contests. If you know any graphic designers, convince them to join!</p>
]]></content:encoded>
			<wfw:commentRss>http://isisblogs.poly.edu/2008/09/01/security-awareness-posters/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	<creativeCommons:license>http://creativecommons.org/licenses/by/3.0/us/</creativeCommons:license>
	</item>
		<item>
		<title>Fall Penetration Testing and Exploit-Dev course</title>
		<link>http://isisblogs.poly.edu/2008/08/24/fall-penetration-testing-and-exploit-dev-course/</link>
		<comments>http://isisblogs.poly.edu/2008/08/24/fall-penetration-testing-and-exploit-dev-course/#comments</comments>
		<pubDate>Sun, 24 Aug 2008 17:00:05 +0000</pubDate>
		<dc:creator>dan</dc:creator>
				<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Meta]]></category>
		<category><![CDATA[Reverse Engineering]]></category>
		<category><![CDATA[Social Engineering]]></category>
		<category><![CDATA[Targeted Attacks]]></category>
		<category><![CDATA[Web]]></category>

		<guid isPermaLink="false">http://isisblogs.poly.edu/?p=158</guid>
		<description><![CDATA[This year&#8217;s Penetration Testing and Exploit Development course (Fall 2008) will contain completely rewritten course material, guest lectures from leading security professionals, and free access to commercial tools provided by Fortify Software and Matta (thank you!). Additionally, the class will be held on-campus rather than online as it has been.
The instructor for the course is [...]]]></description>
			<content:encoded><![CDATA[<p>This year&#8217;s Penetration Testing and Exploit Development course (Fall 2008) will contain completely rewritten course material, guest lectures from leading security professionals, and free access to commercial tools provided by <a href="http://www.fortify.com/">Fortify Software</a> and <a href="http://trustmatta.com/">Matta</a> (thank you!). Additionally, the class will be held on-campus rather than online as it has been.</p>
<p>The instructor for the course is Nasir Memon with TA&#8217;s Dan Guido (me) and Vikram Padman. The syllabus has been finalized and the guest professors as well as their respective topics are as follows:</p>
<ul>
<li> Sept 4th &#8212; Introduction and <a href="http://isis.poly.edu/csaw/">CSAW</a>, <a href="http://cryptocity.net/">Dan Guido</a></li>
<li> Sept 11th &#8212; Source Code Analysis, <a href="http://cryptocity.net/">Dan Guido</a><a href="http://cryptocity.net/" target="_blank"></a></li>
<li> Sept 18th &#8212; Reverse Engineering, <a href="http://twitter.com/s7ephen">Stephen A. Ridley</a><a href="http://www.sa7ori.org/" target="_blank"></a></li>
<li> Sept 25th &#8212; Reverse Engineering, <a href="http://twitter.com/s7ephen">Stephen A. Ridley</a><a href="http://www.sa7ori.org/" target="_blank"></a></li>
</ul>
<ul>
<li> October 2nd &#8212; Overflows, <a href="http://theta44.org/">Dino Dai Zovi</a></li>
<li> October 9th &#8212; Overflows, <a href="http://theta44.org/">Dino Dai Zovi</a></li>
<li> October 16th &#8212; TAKE-HOME MIDTERM</li>
<li> October 23rd &#8212; Fuzzing,Â <a href="http://schmoil.blogspot.com/">Mike Zusman</a><a href="http://schmoil.blogspot.com/" target="_blank"></a></li>
<li> October 30th &#8212; Fuzzing, <a href="http://schmoil.blogspot.com/">Mike Zusman</a><a href="http://schmoil.blogspot.com/" target="_blank"></a></li>
</ul>
<ul>
<li> November 6th &#8212; Client-side attacks, <a href="http://www.zerodaysolutions.com/">Dean De Beer</a><a href="http://www.zerodaysolutions.com/" target="_blank"></a></li>
<li> November 13th &#8212; Client-side attacks, <a href="http://www.zerodaysolutions.com/">Dean De Beer</a><a href="http://www.zerodaysolutions.com/" target="_blank"></a></li>
<li> November 20th &#8212; Web Hacking, <a href="http://erik.cabetas.com/">Erik Cabetas</a><a href="http://erik.cabetas.com/" target="_blank"></a></li>
<li> November 27th &#8212; Web Hacking, <a href="http://erik.cabetas.com/">Erik Cabetas</a><a href="http://erik.cabetas.com/" target="_blank"></a></li>
</ul>
<ul>
<li> December 4th &#8212; FINAL PROJECTS</li>
<li> December 11th &#8212; hack the planet/show off projects</li>
</ul>
<p>Students will have to complete one homework assignment every two weeks, a take-home midterm, and do a final project of their choosing. Each two week session will contain one full session of Q&amp;A to review the homework associated with it. Extra credit will be given for participating in <a href="http://isis.poly.edu/csaw/">CSAW</a> and <a href="http://www.cs.ucsb.edu/~vigna/CTF/">UCSB iCTF</a>.</p>
<p>Any questions about the course can be e-mailed to me at <a href="mailto:dguido@gmail.com">dguido@gmail.com</a>.</p>
<p>EDIT: The course will be held in room <strong>RH227</strong></p>
]]></content:encoded>
			<wfw:commentRss>http://isisblogs.poly.edu/2008/08/24/fall-penetration-testing-and-exploit-dev-course/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
	<creativeCommons:license>http://creativecommons.org/licenses/by/3.0/us/</creativeCommons:license>
	</item>
		<item>
		<title>Cute + Malicious == Deadly</title>
		<link>http://isisblogs.poly.edu/2008/06/28/cute-malicious-deadly/</link>
		<comments>http://isisblogs.poly.edu/2008/06/28/cute-malicious-deadly/#comments</comments>
		<pubDate>Sat, 28 Jun 2008 09:46:50 +0000</pubDate>
		<dc:creator>aleksey</dc:creator>
				<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Physical Security]]></category>
		<category><![CDATA[Social Engineering]]></category>
		<category><![CDATA[Targeted Attacks]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://isisblogs.poly.edu/?p=114</guid>
		<description><![CDATA[In a recent (experimental only) project, I followed one of the multiple guides such as this one on how to make a Lego case for a USB stick. To top it off, I loaded the Hak5 Switchblade packages on the sticks. When used with U3 USB autorun technology, these packages allow automatic theft of various [...]]]></description>
			<content:encoded><![CDATA[<p>In a recent (experimental only) project, I followed one of the multiple guides such as <a href="http://www.instructables.com/id/Lego-USB-Stick/">this one</a> on how to make a Lego case for a USB stick. To top it off, I loaded the <a href="http://wiki.hak5.org/wiki/Switchblade_Packages">Hak5 Switchblade</a> packages on the sticks. When used with U3 USB autorun technology, these packages allow automatic theft of various personal data upon insertion of the stick into a Windows computer. Now, doesn&#8217;t this just crush the competition (a regular USB stick lost in the parking lot)?</p>
<p><a href="http://isisblogs.poly.edu/wp-content/uploads/sticks_small.png" rel="lightbox[114]"><img class="aligncenter size-full wp-image-115" src="http://isisblogs.poly.edu/wp-content/uploads/sticks_small.png" alt="The Mona Lisa" width="384" height="285" /></a></p>
<p><span id="more-114"></span></p>
<p>As far as the creation of the case goes, I didn&#8217;t really follow any guides. Pretty much all you have to do is buy a mix of legos and strip a USB stick (leaving only the chip and the metal connector). Then, you have to pick a few legos (I used 3, in two different configurations) the combination of which will house the chip.  You need to cut out some of their insides with a box cutter to place the chip. Then, you need to glue them together with <a href="http://solutions.3m.com/wps/portal/3M/en_US/3M-Super-77/Super77/">3M glue</a>, fill them with transparent construction <a href="http://www.alibaba.com/product-gs/205652014/A_6700_Neutral_Silicone_Structural_Sealant.html">silicone</a> and place the chip inside. Finally, you need to place some more silicon on the chip and cover the bottom hole with flat lego pieces. The color of lego pieces matters. Yellow allowed the USB LED to shine through it. Selection of the USB stick also matters &#8211; I used &#8220;SanDisk Cruzer Micro&#8221; which are medium in size and come loaded with U3.</p>
<p>As far as the Hak5 package goes,  well, I&#8217;m not giving a guide for that. But basically, it works by modifying the U3 binaries and autorun configuration files to execute windows batch files (that are also placed on the same stick) upon insertion of the USB. The scripts provided (payloads) vary form system password stealing to IE history viewing.  The information stolen is saved on the stick itself. Alternatively, there is a way to email it to yourself. Anyway, don&#8217;t pick these up on the street (not that I would part with any <img src='http://isisblogs.poly.edu/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  ).</p>
]]></content:encoded>
			<wfw:commentRss>http://isisblogs.poly.edu/2008/06/28/cute-malicious-deadly/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	<creativeCommons:license>http://creativecommons.org/licenses/by/3.0/us/</creativeCommons:license>
	</item>
		<item>
		<title>Social Engineering final presentations</title>
		<link>http://isisblogs.poly.edu/2008/05/14/social-engineering-final-presentations/</link>
		<comments>http://isisblogs.poly.edu/2008/05/14/social-engineering-final-presentations/#comments</comments>
		<pubDate>Wed, 14 May 2008 21:08:50 +0000</pubDate>
		<dc:creator>dan</dc:creator>
				<category><![CDATA[Academic Papers]]></category>
		<category><![CDATA[Psychology of Security]]></category>
		<category><![CDATA[Social Engineering]]></category>
		<category><![CDATA[Web]]></category>

		<guid isPermaLink="false">http://isisblogs.poly.edu/?p=88</guid>
		<description><![CDATA[Yesterday marked the end of our first-run Psychology of Security/Social Engineering course here at Poly. Every student made a presentation that described the research project they designed and attempted to run during the semester. I&#8217;ll upload the presentations as I get them so check this page often  .

The Effectiveness of Security Training / Graphical [...]]]></description>
			<content:encoded><![CDATA[<p>Yesterday marked the end of our first-run Psychology of Security/Social Engineering course here at Poly. Every student made a presentation that described the research project they designed and attempted to run during the semester. I&#8217;ll upload the presentations as I get them so check this page often <img src='http://isisblogs.poly.edu/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> .</p>
<ol>
<li><a href="http://isisblogs.poly.edu/wp-content/uploads/training-graphics-presentation.pdf">The Effectiveness of Security Training / Graphical Indicators of Security</a><br />Joint project by Dan Guido and Boris Kochergin</li>
<li><a href="http://isisblogs.poly.edu/wp-content/uploads/personalized_phishing_presentation.pdf">Personalized Phishing</a><br />Joint project by Brad Schonhorst and Jonathan Voris</li>
</ol>
<p>I&#8217;ve made an executive decision. The <a href="https://isis.poly.edu/mailman/listinfo/soceng">mailing list</a> that we used for the course will now be opened to the public for discussion of Social Engineering / Psychology of Security issues. I placed a link on the sidebar of this blog, please sign up if you&#8217;re interested!</p>
]]></content:encoded>
			<wfw:commentRss>http://isisblogs.poly.edu/2008/05/14/social-engineering-final-presentations/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	<creativeCommons:license>http://creativecommons.org/licenses/by/3.0/us/</creativeCommons:license>
	</item>
		<item>
		<title>Update to Single-Site-Browsers (SSBs)</title>
		<link>http://isisblogs.poly.edu/2008/04/28/update-to-single-site-browsers-ssbs/</link>
		<comments>http://isisblogs.poly.edu/2008/04/28/update-to-single-site-browsers-ssbs/#comments</comments>
		<pubDate>Tue, 29 Apr 2008 03:44:37 +0000</pubDate>
		<dc:creator>dan</dc:creator>
				<category><![CDATA[Psychology of Security]]></category>
		<category><![CDATA[Risk Analysis]]></category>
		<category><![CDATA[Security Engineering]]></category>
		<category><![CDATA[Security Industry]]></category>
		<category><![CDATA[Social Engineering]]></category>
		<category><![CDATA[Web]]></category>

		<guid isPermaLink="false">http://isisblogs.poly.edu/?p=86</guid>
		<description><![CDATA[I spent a lot more time thinking about SSBs over the last week or so and I&#8217;d like to use this blog to do a bit of a brain dump. A few days ago, Andrew Jaquith publicly posted the presentation that was sent me to privately. Here are links to his blog and to his [...]]]></description>
			<content:encoded><![CDATA[<p>I spent a lot more time thinking about SSBs over the last week or so and I&#8217;d like to use this blog to do a bit of a brain dump. A few days ago, Andrew Jaquith publicly posted the presentation that was sent me to privately. Here are links to his <a href="http://blogs.yankeegroup.com/2008/04/21/single-site-browsers/">blog</a> and to his <a href="http://blogs.yankeegroup.com/wp-content/uploads/2008/04/ssb-preso-reduced.pdf">presentation</a>.</p>
<p>His presentation makes a number of claims about the security benefits of SSBs. It lists protection against phishing, CSRF, some types of XSS (likely all non-persistent varieties), and domain whitelisting as a future improvement to harden those protections.</p>
<p>I don&#8217;t think [current] SSBs completely provide those security benefits unless you do two things:</p>
<ol>
<li>You block non-SSBs from accessing your website (blocking on user agent string would be enough)</li>
<li>You train users that an SSB is the only acceptable place to enter their password</li>
</ol>
<p>Without those two requirements satisfied, it is my opinion that SSBs give little security benefit.</p>
<p>If you still allow non-SSBs to access citibank.com, then when a user clicks an XSS&#8217;d link to citibank.com, the citibank.com page will still load, and they will still be XSS&#8217;d. Similarly, CSRF continues to function as it is likely that the &#8217;session cookie isolation&#8217; benefit of SSBs are negated by the user likely having duplicate cookies in both their SSB and in Firefox (you must ensure the user never logs into citibank.com with their normal browser and obtain a session cookie there, hence the first requirement).</p>
<p>In order for the phishing protection to be effective, users must be aware that they are only supposed to encounter Citibank content in their SSB and not in their normal browser. For instance, if an SSB user encounters a Citibank phishing website in Firefox, will they close their browser and open their SSB instead? It might be the case that users will behave in this way, but I haven&#8217;t seen any verifiable proof either way.</p>
<p>[This hasn't been reported on ISIS Blogs yet, but next week marks the end of our first run of "The Psychology of Security/Social Engineering", a first-run research course here at Poly. I'm writing up a research proposal to test the above hypothesis with a group of students in the Fall.]</p>
<p>Lastly, if a bank starts deploying SSBs to their customers, I see this as a first step towards successfully forcing client-side requirements on users where the end-game is fully trusted computing and the open commercial web starts to disappear. This actually goes back to our &#8220;<a href="http://isisblogs.poly.edu/2008/03/12/refusing-business-from-security-unaware-customers/">Refusing Insecure Customers</a>&#8221; debate. It&#8217;s an evolution of the same (<a href="http://isisblogs.poly.edu/pollsarchive/">bad</a>, according to readers) idea.</p>
<p>So, although I see where SSBs have some use and can positively affect your web security, let&#8217;s not kid ourselves, they don&#8217;t solve that much. To really be effective, they require major changes in the way you do business and [still] rely on an intelligent user. Rather, they look like avoidance of the base problem and an idealistic patch that isn&#8217;t going to work.</p>
<p>Oddly enough, I have been using a set of 4 <a href="http://wiki.mozilla.org/Prism">Prism</a> SSBs for the last 2 weeks and have actually grown fond of them, but not for security reasons at all. I like how they show up in my dock, that they rarely crash, and it seems natural to give such webapps &#8220;first-class&#8221; status as desktop applications. I&#8217;ll probably continue using them, but I don&#8217;t think I&#8217;ve gained any security from doing so.</p>
<p>That said, I think part of the problem here is that SSBs haven&#8217;t fully matured yet. I just heard about these things 2 weeks ago and I haven&#8217;t heard anyone else in the security community talking about them besides Andrew. They are a topic that deserves more attention and particularly more research from the security community as they embody a lot of <a href="http://wiki.mozilla.org/Prism#Prism_.2F_SSB_Objectives">attractive ideas</a>. Despite my harsh words, I&#8217;m not ready to give up on them yet.</p>
<p>Let&#8217;s brainstorm: how could SSBs be <em>more</em> useful to security? Could we change the way they work or change how they are deployed to give us additional benefits? If you&#8217;re an InfoSec student with no good topic to research, this is without a doubt a good avenue to explore.</p>
]]></content:encoded>
			<wfw:commentRss>http://isisblogs.poly.edu/2008/04/28/update-to-single-site-browsers-ssbs/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
	<creativeCommons:license>http://creativecommons.org/licenses/by/3.0/us/</creativeCommons:license>
	</item>
		<item>
		<title>Just wanted to get this out there</title>
		<link>http://isisblogs.poly.edu/2008/04/10/just-wanted-to-get-this-out-there/</link>
		<comments>http://isisblogs.poly.edu/2008/04/10/just-wanted-to-get-this-out-there/#comments</comments>
		<pubDate>Fri, 11 Apr 2008 03:04:38 +0000</pubDate>
		<dc:creator>dan</dc:creator>
				<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Social Engineering]]></category>
		<category><![CDATA[Targeted Attacks]]></category>

		<guid isPermaLink="false">http://isisblogs.poly.edu/?p=84</guid>
		<description><![CDATA[I&#8217;m sure most of you have read the article in BusinessWeek that turned up on Slashdot regarding the hacker attacks the US government has to deal with. If you haven&#8217;t, you really should read it because despite its obvious inaccuracies (journalists always get something horribly wrong) it&#8217;s got a ton of good information. I liked [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;m sure most of you have read the <a href="http://www.businessweek.com/print/magazine/content/08_16/b4080032218430.htm">article in BusinessWeek</a> that turned up on <a href="http://it.slashdot.org/article.pl?sid=08/04/10/2235215&#038;from=rss">Slashdot</a> regarding the hacker attacks the US government has to deal with. If you haven&#8217;t, you really should read it because despite its obvious inaccuracies (journalists always get <em>something</em> horribly wrong) it&#8217;s got a ton of good information. I liked how they explained exactly how the unknown attacker uses phishing (whaling?) so effectively.</p>
<p>But really, my alterior motive for posting this, was so I could point out this one particularly entertaining paragraph buried in the middle of it:</p>
<blockquote><p>Now, Senate Intelligence Committee Chairman John D. Rockefeller (D-W. Va.) is said to be discreetly informing fellow senators of the Byzantine operation, in part to win their support for needed appropriations, many of which are part of classified &#8220;black&#8221; budgets kept off official government books. Rockefeller declined to comment. In January a Senate Intelligence Committee staffer urged his boss, Missouri Republican Christopher &#8220;Kit&#8221; Bond, the committee&#8217;s vice-chairman, to supplement closed-door testimony and classified documents with a viewing of the movie <em>Die Hard 4</em> on a flight the senator made to New Zealand. In the film, cyber terrorists breach FBI networks, purloin financial data, and bring car traffic to a halt in Washington. Hollywood, says Bond, doesn&#8217;t exaggerate as much as people might think. &#8220;I can&#8217;t discuss classified matters,&#8221; he cautions. &#8220;But the movie illustrates the potential impact of a cyber conflict. Except for a few things, let me just tell you: It&#8217;s credible.&#8221;</p></blockquote>
<p>For the record:</p>
<blockquote><p>&#8220;Except for a few things, let me just tell you: It&#8217;s credible.&#8221;<br />- Senator Christopher &#8220;Kit&#8221; Bond (R-MO) on Die Hard 4</p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://isisblogs.poly.edu/2008/04/10/just-wanted-to-get-this-out-there/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	<creativeCommons:license>http://creativecommons.org/licenses/by/3.0/us/</creativeCommons:license>
	</item>
		<item>
		<title>We promise we won&#8217;t store your password</title>
		<link>http://isisblogs.poly.edu/2008/03/30/we-promise-we-wont-store-your-password/</link>
		<comments>http://isisblogs.poly.edu/2008/03/30/we-promise-we-wont-store-your-password/#comments</comments>
		<pubDate>Mon, 31 Mar 2008 04:16:39 +0000</pubDate>
		<dc:creator>dan</dc:creator>
				<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Psychology of Security]]></category>
		<category><![CDATA[Social Engineering]]></category>
		<category><![CDATA[Web]]></category>

		<guid isPermaLink="false">http://isisblogs.poly.edu/2008/03/30/we-promise-we-wont-store-your-password/</guid>
		<description><![CDATA[This is a short rant prompted by another student&#8217;s observation that Yelp actually asks for your Gmail password as part of their signup process&#8230;
Have you encountered a website that asks for the username and password to your e-mail provider? I&#8217;m talking about this:


LinkedIn asking for my Gmail password
Yelp asking for my Gmail password
This really needs [...]]]></description>
			<content:encoded><![CDATA[<p>This is a short rant prompted by another student&#8217;s observation that Yelp actually asks for your Gmail password as part of their signup process&#8230;</p>
<p>Have you encountered a website that asks for the username and password to your e-mail provider? I&#8217;m talking about this:</p>
<p><a title="Facebook asking for Gmail password" href="http://isisblogs.poly.edu/wp-content/uploads/facebook_gmail.png" rel="lightbox[76]"><img src="http://isisblogs.poly.edu/wp-content/uploads/facebook_gmail.png" alt="Facebook asking for my Gmail password" /></a><br />
<span id="more-76"></span><br />
<a title="LinkedIn asking for Gmail password" href="http://isisblogs.poly.edu/wp-content/uploads/linkedin_gmail.png" rel="lightbox[76]">LinkedIn asking for my Gmail password</a></p>
<p><a title="Yelp asking for Gmail password" href="http://isisblogs.poly.edu/wp-content/uploads/yelp_gmail.png" rel="lightbox[76]">Yelp asking for my Gmail password</a></p>
<p>This really needs to stop and people need to start using the <a href="http://googledataapis.blogspot.com/2008/03/3-2-1-contact-api-has-landed.html">Gmail Contacts Data API</a>.</p>
<p>I think it&#8217;s kind of needless to say that not only is this <a href="http://it.slashdot.org/article.pl?sid=08/03/11/1723206">unsafe</a>, but it helps users become victims of phishing at some point in the future. Socializing users into giving away their passwords to arbitrary 3rd parties is <strong>not OK</strong>.</p>
<p>So, thanks Facebook, LinkedIn, Yelp, and others for continuing to make the Internet just that much more dangerous; now start using the Contacts API.</p>
<p>If you know of any other websites that still ask for your Gmail password, list them in the comments!</p>
<p>UPDATE: This exact same issue was highlighted in <a href="http://www.codinghorror.com/blog/archives/001128.html?r=8029">Coding Horror</a> 2 months after my post went up.</p>
]]></content:encoded>
			<wfw:commentRss>http://isisblogs.poly.edu/2008/03/30/we-promise-we-wont-store-your-password/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
	<creativeCommons:license>http://creativecommons.org/licenses/by/3.0/us/</creativeCommons:license>
	</item>
		<item>
		<title>Refusing Business from Insecure Customers</title>
		<link>http://isisblogs.poly.edu/2008/03/12/refusing-business-from-security-unaware-customers/</link>
		<comments>http://isisblogs.poly.edu/2008/03/12/refusing-business-from-security-unaware-customers/#comments</comments>
		<pubDate>Wed, 12 Mar 2008 20:02:38 +0000</pubDate>
		<dc:creator>dan</dc:creator>
				<category><![CDATA[Legal]]></category>
		<category><![CDATA[Psychology of Security]]></category>
		<category><![CDATA[Social Engineering]]></category>
		<category><![CDATA[Web]]></category>

		<guid isPermaLink="false">http://isisblogs.poly.edu/2008/03/12/refusing-business-from-security-unaware-customers/</guid>
		<description><![CDATA[Late last year in an article titled &#8220;In Zombies We Trust,&#8221; Dan Geer suggested that there are two types of users &#8212; those who blindly say yes to everything and are probably infected with a dozen viruses and those who say no to most everything and likely escape most virus problems &#8212; and that it [...]]]></description>
			<content:encoded><![CDATA[<p>Late last year in an article titled &#8220;<a href="http://blogs.zdnet.com/security/?p=661">In Zombies We Trust</a>,&#8221; Dan Geer suggested that there are two types of users &#8212; those who blindly say yes to everything and are probably infected with a dozen viruses and those who say no to most everything and likely escape most virus problems &#8212; and that it could be a legitimate practice for websites to further scrutinize the actions of those who always say yes to prevent them from getting into trouble while using their site. The premise is that these virus-infected users end up costing the businesses they frequent a significant amount of money by being such persistent problems.</p>
<p>A member of our lab (I&#8217;ll leave it to him to take credit for this idea) suggested last week that maybe this should be taken a step further. If I know that one customer of mine is more likely to be infected with a virus (or has a higher susceptibility to phishing, pick your threat) now or in the future, is it reasonable for me to completely deny him my business?</p>
<p>This can be easily tested using either Dan Geer&#8217;s test or by sending my customers random phishing messages for my own business (there&#8217;s even a <a href="http://phishme.com/">phishing appliance</a> to do it for you!). Ie., Paypal sends you a phishing email for themselves (sent from another domain, self-signed certificate, graphics copied incorrectly, differently formatted e-mail, whatever) and if you fall for it, they calculate your future profitability and weigh it against the costs you&#8217;ll incur if you actually do get phished in the future. If you&#8217;ve got a negative balance after this calculation, your account will be canceled and PayPal will have saved money.</p>
<p>The observation was also made that this is standard practice in other industries. Insurance and, regrettably, healthcare come to mind. Would this be a bad thing for web services?</p>
Note: There is a poll embedded within this post, please visit the site to participate in this post's poll.
]]></content:encoded>
			<wfw:commentRss>http://isisblogs.poly.edu/2008/03/12/refusing-business-from-security-unaware-customers/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	<creativeCommons:license>http://creativecommons.org/licenses/by/3.0/us/</creativeCommons:license>
	</item>
		<item>
		<title>Harvesting credentials from a subscriber base</title>
		<link>http://isisblogs.poly.edu/2007/02/18/harvesting-credentials-from-a-subscriber-base/</link>
		<comments>http://isisblogs.poly.edu/2007/02/18/harvesting-credentials-from-a-subscriber-base/#comments</comments>
		<pubDate>Sun, 18 Feb 2007 04:13:09 +0000</pubDate>
		<dc:creator>Yan Ivnitskiy</dc:creator>
				<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Social Engineering]]></category>

		<guid isPermaLink="false">http://isisblogs.poly.edu/2007/02/18/harvesting-credentials-from-a-subscriber-base/</guid>
		<description><![CDATA[If one were the administrator/developer of a service that requires users to supply credentials, can you picture the amount of data one will receive if you:

Use an email as the username.
Provide tight restrictions on the password creation (Decent minimum length, requirements of alpha+digits)
Log unsuccessful logins and password changes

I&#8217;m sure you can see where I&#8217;m going [...]]]></description>
			<content:encoded><![CDATA[<p>If one were the administrator/developer of a service that requires users to supply credentials, can you picture the amount of data one will receive if you:</p>
<ol>
<li>Use an email as the username.</li>
<li>Provide tight restrictions on the password creation (Decent minimum length, requirements of alpha+digits)</li>
<li>Log unsuccessful logins and password changes</li>
</ol>
<p>I&#8217;m sure you can see where I&#8217;m going with this, but if the service is popular the users will always first try their other common passwords until they list their entire mental list of every password they generally use (which most likely do not match the ones they came up with to register with the site), thus collecting credentials of other services the users are members of (A few google searches of their emails, or just the user-name part of the email will reveal most services they are members of.) </p>
<p>I am going on the basis of the idea that most people (or the ones I&#8217;ve spoken to) believe that some data like failed authentication attempts, passwords that were changed, and accounts that were removed are erased from existence after the event, but in today&#8217;s world of virtually limitless storage and facile logging mechanisms, why <i>wouldn&#8217;t</i> administrators log everything that goes through their systems?</p>
<p>I have never heard of such a harvest vector and was thinking of ways to protect from this. Using a password manager like PassSafe can reduce failed attempts and randomly generate a fresh password, but careful attention has to be paid to keep that database secure. Whichever method you use, the goal is to not supply data to a third (or second) party without them needing-to-know.</p>
]]></content:encoded>
			<wfw:commentRss>http://isisblogs.poly.edu/2007/02/18/harvesting-credentials-from-a-subscriber-base/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	<creativeCommons:license>http://creativecommons.org/licenses/by/3.0/us/</creativeCommons:license>
	</item>
		<item>
		<title>Email Source Authentication through Network Services: An Open Question</title>
		<link>http://isisblogs.poly.edu/2007/02/09/source-authenticity-vs-network-services-an-open-question/</link>
		<comments>http://isisblogs.poly.edu/2007/02/09/source-authenticity-vs-network-services-an-open-question/#comments</comments>
		<pubDate>Fri, 09 Feb 2007 19:47:48 +0000</pubDate>
		<dc:creator>Michael Daniluk</dc:creator>
				<category><![CDATA[Social Engineering]]></category>
		<category><![CDATA[Spam]]></category>

		<guid isPermaLink="false">http://isisblogs.poly.edu/2007/02/09/source-authenticity-vs-network-services-an-open-question/</guid>
		<description><![CDATA[    Suppose you have an email that claims to be from a particular web destination (&#8221;Chase Bank&#8221;, &#8220;eBay&#8221;, &#8220;Middle of Nowhere Bank&#8221;, etc.) and directs you to a url purportedly at that location. Suppose further that you possess the capability of extracting both these pieces of information from any email if the [...]]]></description>
			<content:encoded><![CDATA[<p>    Suppose you have an email that claims to be from a particular web destination (&#8221;Chase Bank&#8221;, &#8220;eBay&#8221;, &#8220;Middle of Nowhere Bank&#8221;, etc.) and directs you to a url purportedly at that location. Suppose further that you possess the capability of extracting both these pieces of information from any email if the email falls into said category. So you have</p>
<p>A. Purported Web Destination of Email<br />
B. URL Email is Instructing you to Follow </p>
<p>    So here is an open-ended question: how can you use existing network services to determine that B is an authentic location in A? A subset of existing spam filtering heuristics work quite well towards this end (visible text of html link does not match actual url, href attribute is expressed as IP address, etc.), but using network services opens of a new dimension of validation, one in which the data gathered for heuristic application are outside the control of the email&#8217;s sender. So post any ideas you have. Kurt asked a similar question at an SFS meeting last semester pertaining to the parasitic storage project. Whereas his aim was using network services for caching, my aim is using them for source authentication. Thanks and please keep the discussion focused, at least primarily, on this particular method. </p>
]]></content:encoded>
			<wfw:commentRss>http://isisblogs.poly.edu/2007/02/09/source-authenticity-vs-network-services-an-open-question/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
	<creativeCommons:license>http://creativecommons.org/licenses/by/3.0/us/</creativeCommons:license>
	</item>
	</channel>
</rss>
