Showing posts with label passwords. Show all posts
Showing posts with label passwords. Show all posts

Friday, February 8, 2013

Your Password is Obsolete. Now What?

Be sure to check out this infographic about passwords which describes the hack of Wired writer Mat Honan, explains how hackers are able to get a person's data, discusses alternatives to passwords, and provides password advice. It's really worth a few minutes of your time.

Here's the introduction:
Some say 2012 may have been the year the password broke. With password leaks and dumps becoming common occurrences our lives are simply too easy to crack. That string of characters you use as a password can't protect you anymore.

Tuesday, January 15, 2013

Judge rejects party's offer to hand over blog credentials (login/password) instead of documents during discovery

In the highly contentious realm of electronic discovery where login passwords are zealously guarded, one plaintiff had no qualms about granting such access if it meant evading her burden of production in an acceptable format.

In German v. Micro Elecs., 2012 U.S. Dist. LEXIS 4594 (S.D. Ohio 2013), the trial court held it impermissible for a party to shift its burden of production due to the party’s refusal to produce the sought after electronically stored information (ESI) in an acceptable format.

In a discovery dispute arising from an employment action, the plaintiff offered to provide the defendants with her login credentials and passwords to her blogs and websites she frequented in lieu of producing responsive ESI. The defendants refused the offer due to the risk of being accused, or found to have altered relevant evidence.

Although it was an unusual offer, the defendants’ attorney employed commendable dexterity in effectively forecasting the risk associated with accepting the plaintiff’s offer to hand over her passwords.  

During the course of discovery, the defendants requested that the plaintiff produce all online postings, blogs and similar online activities that addressed the plaintiff’s workplace, health condition, or other issues raised in her complaint. 

The plaintiff responded by sending over a hundred pages of portions of blogs and websites that she had copied and pasted without any source attribution. The defendants rejected the submission because it considered the production deficient as it did not capture the original and complete text, formatting, and images of a blog or website. The defendants suggested that the plaintiff utilize a portable document format (PDF) or any format that is reviewable and that captures the documents in their original format. 

Although the plaintiff characterized herself as an extensive blogger and sophisticated user of the Internet, she stated that defendants’ request for production of screen shots or PDF was particularly too burdensome.  As an alternative, she offered the defendants direct password access to all her online journals, blogs, and social media websites.

The court found the plaintiff's excuse and suggestions to be unacceptable and noted that despite the defendants not requesting a specific form for producing the ESI, the plaintiff had a burden to produce the requested information in a form that the information is ordinarily maintained or in a reasonably usable form. The court ruled that the copied and pasted excerpts were neither an acceptable nor reasonable form of production. 

Tuesday, September 25, 2012

IEEE information disclosure disaster - if you thought LinkedIn was bad...

Update: Not unexpectedly (always assume a breach occurred - my liar to truth ratio on these subjects hovers around 1:90, respectively) ieee.org has confirmed the breach, per ZDNET - see here: IEEE admits password leak, says problem fixed.

A Russian computer programmer claims to have had access to logs from the IEEE ftp server, logins and passwords, and additional information. If the claim is true, this incident raises the bar on institutional negligence. See more information about the story, here. The users of the site are quite unique (and if the disclosure is true, the revealing of such information is scary):
Among the users who's [sic] information was exposed are researchers at NASA, Stanford, IBM, Google, Apple, Oracle and Samsung. IEEE's membership of over 340,000 is roughly half American (49.8 percent as of 2011). Other members reside in India, China and the Pacific Rim (23.4 percent) and Europe, the Middle East and Africa (18.3 percent). Some 8 percent of IEEE's membership constitute government employees, including the military. Most work in the private sector and academia.
The website www.ieeelog.com has been set up to provide aggregate information regarding accounts from ieee.org - including password distribution, who accessed the site, and a whole bunch of other information. Assumedly this was set up by the discoverer, or someone associated with that person.

IEEE is, for the uninitiated, a very well known entity - the Institute of Electrical and Electronics Engineers.

To say this is "plumber with leaky pipes" problem would be an understatement.  The IEEE has come up with many standards, not the least of which is 802.11. Yet they can't secure this type of information?


Friday, January 27, 2012

Fifth Amendment held not violated by forced disclosure of unencrypted drive

The Colorado District Court is the latest to weigh in on the popular issue of whether a person can be forced to disclose a password or unencrypted files. In United States v. Fricosu, the court found that the defendant's Fifth Amendment right is not implicated by requiring production of an unencrypted version of the files. 2012 U.S. Dist. LEXIS 11083 (D. Colo. 2012).

After law enforcement seized six computers from the defendant's home, they were unable to break the encryption on one of the computers. The defendant refused to provide the password, arguing that such a requirement would violate her Fifth Amendment right against self-incrimination.

Two prior cases have dealt with this issue. In In re Grand Jury Subpoena to Boucher, 2007 WL 4246473 (D. Vt. 2007), the court required the defendant to provide either a password or an unencrypted copy of the specified files. However, as the EFF (Electronic Frontier Foundation) noted in their amicus brief to Fricosu, Boucher involved specific files identified as child pornography. Investigators could see the filenames but were unable to open the files. That is distinguishable in Fricosu because investigators only know of the types of files that will be on the computer. On that issue, the Fricosu court held, "The fact that [the government] does not know the specific content of any specific documents is not a barrier to production."

Also, in United States v. Kirschner, 2010 U.S. Dist. LEXIS 30603 (E.D. Mich. 2010), the court found that the defendant could not be compelled to disclose his password. The government argued in Fricosu that Kirschner does not apply they are providing the alternative of allowing production of decrypted files instead of the password.

In Fricosu, the EFF had argued that forcing Fricosu to provide the password or unencrypted files “would be an admission that she had control over the computer and the data stored on it before it was seized from her residence—which are critical admissions” and would therefore violate her Fifth Amendment rights.

In a recent post, I discussed TrueCrypt, a popular open-source software package that allows users to create hidden, encrypted volumes.