LITTLEBLACKDOG.COM Forum Index LITTLEBLACKDOG.COM

 
LWD LWD   FAQ FAQ   Memberlist Memberlist   Usergroups Usergroups   Active Topics Active Topics   Register Register  
  Profile Profile   Log in to check your private messages Log in to check your private messages   Log in Log in  
  Who is Online Who is Online   Image Gallery Image Gallery   Chat Chat   Search Search  
  LWDGear       LBDGear  

View next topic
View previous topic
Post new topic     Reply to topic   LITTLEBLACKDOG.COM Forum Index » Information Security
Author Message
Pakiii
Tail-Wagger
Tail-Wagger


Joined: 22 Jul 2002
Posts: 2055
Location: KS, USA

Post Posted: Tue Mar 04, 2008 6:38 am   Post subject: Stupid Security Rules Reply with quote Back to top  

Looking to see if people have some suggestions for stupid computer security rules that people have run across as examples. I've been asked to speak at a local university about computer security and business (The Technical Administration department). I am approaching this from the angle of business people and technical people need to talk before making security rules. IE don't let computer geeks randomly make business impacting changes, and don't let managers dictate computer policy without everybody having a clear understanding of what will really happen.

What originally got me roped into this, and where I am starting off from, was a discussion on password rules. Department of Homeland Security has a rule that passwords will be at least 9 characters, one upper case, one lower case, one special character, not be any word forwards, or backwards, not be any name forwards or backwards, and not begin or end with any year or month value (ie the first or last 2 characters can not be a number). By the way, this must be enforced through technology, not just a policy. If a system can not force compliance for all of these rules, then it fails.

If the password is too complicated, in an attempt to make the system more secure, then the users will write down the password, and make the system drastically less secure. Combine this with a system failing security if it can not enforce those rules, makes for a rule that technically would be good, but when reality is brought in is stupid.

I'm going to talk about that, and stupid 2 factor authentication rules as well. IE a USB, or card, that requires a 15 character password, that gets written down on the device.

Also a bit on SPAM filtering, IE don't block the word VIAGRA if working for a pharmecutical company (I did that one myself). Challenge response for corporate email. IE 2 person challenge response loop.

I could speak all day on TSA and their rules, but I am focusing on computer rules specifically, and wanted to see if any others had some thoughts.

_________________
"Because men know that the conquest of one's own weakness is a far, far, more difficult task than any other, they tend to believe that he who can conquer himself can also conquer whatever problem is at hand" - Rear Admiral Harley Cope
View user's profile Send private message AIM Address
squashman
Big Dog
Big Dog


Joined: 08 Oct 2001
Posts: 3429
Location: 1265 Lombardi Ave.

Post Posted: Tue Mar 04, 2008 8:13 am   Post subject: Reply with quote Back to top  

Not necessarily a stupid security rule but something stupid. Our corporation out sources the helpdesk to Accenture, who then outsources to a company in India. Takes you about an hour to get your password reset. They don't know what a mainframe is or even what Novell Netware is. They ask you if a file server being down is a high priority problem. Hmm, let me see here, no shit Sherlock. Then they will ask you how high of a priority is it. Hmm, lets see here, everybody has been sitting on their ass for an hour not doing their job.

Do we really think we should even trust our network security to some idiots in India! That should be a good topic to cover in your speech.
View user's profile Send private message Send e-mail
ThunderDawg
Alpha Dog
Alpha Dog


Joined: 14 Apr 2002
Posts: 16270
Location: In a Godda da Vita, Honey

Post Posted: Tue Mar 04, 2008 9:31 am   Post subject: Reply with quote Back to top  

The stupidest security rule I can think of immediately was one that dictated screen savers must launch after 60 seconds of non-use, and be pass-protected. That meant that in real life you had to type your password about 200 times a day. It cut poductivity in half.

_________________
The ONE thing EVERYONE has in Common is that they think they are Above Average Drivers.
View user's profile Send private message
CMTG
Leg Humper
Leg Humper


Joined: 23 Feb 2002
Posts: 4822
Location: On average, Cheltenham.

Post Posted: Tue Mar 04, 2008 11:18 am   Post subject: Reply with quote Back to top  

It was once proposed at our place to write down all passwords for every machine to be placed inside an envelope in the safe, in case the worst should happen. Considering we have customer machines permanently on site that we don't have access to and Internal Support have access to all business critical things anyway, it seemed a bit pointless. We shot that fucker right down in the most surprisingly civilised fashion at the quarterly team brief.

_________________
Pie. I wish I could
constrain my hungry greed but...
Sadly, defeated.


So I'm cruising in my '91 Daihatsu blasting Vanessa Carlton's rockin' smash hit "A Thousand Miles," when it suddenly occurs to me:
"Am I
too gangsta? Am I too hardcore and menacing for this world?" I just might be.
- Tatsuya Ishida
View user's profile Send private message Send e-mail Visit poster's website
Pakiii
Tail-Wagger
Tail-Wagger


Joined: 22 Jul 2002
Posts: 2055
Location: KS, USA

Post Posted: Thu Mar 06, 2008 12:45 pm   Post subject: Reply with quote Back to top  

Good stuff everyone, thank you. I know there has got to be more stupid security tricks out there than just this though. Security people tend to do some stupid things. Very Happy

_________________
"Because men know that the conquest of one's own weakness is a far, far, more difficult task than any other, they tend to believe that he who can conquer himself can also conquer whatever problem is at hand" - Rear Admiral Harley Cope
View user's profile Send private message AIM Address
GibsonSG
Tail-Wagger
Tail-Wagger


Joined: 26 Aug 2003
Age: 27
Posts: 2858
Location: Lubbock, TX

Post Posted: Thu Mar 06, 2008 1:20 pm   Post subject: Reply with quote Back to top  

Pakiii wrote:
Good stuff everyone, thank you. I know there has got to be more stupid security tricks out there than just this though. Security people tend to do some stupid things. Very Happy


When I was working for Cox Communications (Now Suddenlink) and went through training for their technical support department I ran into this one. I don't remember exactly what the exercise was, but it involved a windows 2000 test machine and needing an administrator password, which was given to us.

You see IT used Norton Ghost to ghost new machines to a standard OS image. We had test machines, so they had one for Windows 95, 98, ME, 2k, and XP.

At the time, the computers on the call center floor were running windows 98, and as you can imagine, security was pretty much non-existant on them. A few months after I started they built a new call center and we each got new computers, running Windows 2000. All we heard from IT staff was how they were going to lock down these machines, and we wouldn't be able to play games and do the other stuff we were used to doing on them due to group policies and whatnot.

So moving day comes, we roll into the new callcenter, everybody gets on their new computers... and sure enough they're locked down pretty tight. So I'm sitting there thinking about the situation... and something occurs to me.... "Surely not" I say to myself. Then I proceed to log off the computer, change the login to local machine instead of the domain.... put in Administrator for the user name, and then put in the password that was given to us for the Win2k machine in training those many months ago. Badda bing, badda boom.... logged in as Admin locally. They used the same Ghost image.

Surprisingly enough... it took them a good month to figure out what we were doing to accomplish this before it was changed. Smile

_________________
This pan will kill your whole family, dig them up and eat them, and then vomit them back into their graves! Ctrl-Alt-Del
View user's profile Send private message Visit poster's website
Sparrow
Tail-Wagger
Tail-Wagger


Joined: 28 Sep 2004
Age: 32
Posts: 2547
Location: I could tell you but you would hate me.

Post Posted: Sun Jun 29, 2008 4:14 am   Post subject: Reply with quote Back to top  

Well I was told to change my password at first login and I did like a good security person (EX) and locked myself out of everything for 2 days.

No-one in the entire company, 5 years old, has tried to change their password at first login and they have discovered through me that it doesn't work.

Also they have a password policy but no-one knows what it is so everyone has a standard password.

_________________
"A fine example of the kind of negotiating approach you should take can be found in the excellent corporate training film The Godfather.
"

View user's profile Send private message
Display posts from previous:   
Post new topic     Reply to topic

View next topic
View previous topic
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum


Powered by phpBB © 2001, 2002 phpBB Group
phpBB SEO
All times are GMT - 8 Hours

Help us keep advertisements off this site. Donate today!