The PuritanBoard  

Go Back   The PuritanBoard > General Forums > Computers & Technology

Computers & Technology Bible software, computer support questions and other helpful technology matters

» Online Users: 47
8 members and 39 guests
Bookworm, CNJ, JennyG, Knight, satz, SolaScriptura, StainlessThroughGrace
Most users ever online was 856, 07-06-2007 at 12:19 AM.
Closed Thread
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 07-22-2009, 02:04 PM
Jerusalem Blade's Avatar
Puritanboard Junior
 
Join Date: Jun 2006
Location: Middle East
Posts: 1,515
Blog Entries: 6
Thanks: 311
Thanked 929 Times in 353 Posts
Anatomy of Twitter Attack

The Washington Post has a great story: The Anatomy Of The Twitter Attack. Reading how this guy compromised the Twitter staff, their email accounts (and many other accounts, including PayPal, iTunes store, and Amazon), office documents, communications, etc. has made me rethink how I do my passwords and related stuff.
__________________
Steve Rafalsky
Elder, International Evangelical Church (Reformed)
Limassol, Cyprus

"I am set for the defense of the gospel" (Philippians 1:17)

"Strengthened with all might, according to His glorious
power, unto all patience and longsuffering with joyfulness...
" (Colossians 1:11)

Blog: A Great and Terrible Love
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
The Following 3 Users Say Thank You to Jerusalem Blade For This Useful Post:
Backwoods Presbyterian (07-22-2009), Herald (07-22-2009), Rangerus (07-22-2009)
  #2 (permalink)  
Old 07-22-2009, 04:00 PM
Augusta's Avatar
Puritanboard Doctor
 
Join Date: Mar 2004
Location: Washington
Posts: 6,904
Thanks: 2,583
Thanked 1,001 Times in 632 Posts
That was eye-opening. Everyone should read this to keep your info safe on the web. We put so much of our personal info out there now with FB etc that someone can know the answer to your "secret question" just by hanging out on your FB for a while.
__________________
Traci
Lynnwood OPC

"I have taken all my good deeds, and all my bad deeds, and cast them through each other in a heap before the Lord, and fled from both, and betaken myself to the Lord Jesus Christ, and in him I have sweet peace."--David Dickson
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
  #3 (permalink)  
Old 07-22-2009, 04:12 PM
Rich Koster's Avatar
Puritanboard Senior
 
Join Date: Jan 2009
Location: Browns Mills NJ
Posts: 2,328
Blog Entries: 3
Thanks: 621
Thanked 703 Times in 405 Posts
Somebody already hacked my credit card. I'm waiting on the picture from the MAC machine.
__________________
Rich Koster
1689'er
Browns Mills NJ USA
Often Goofy Reformed Eccentric
Romans 7:14-25
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
  #4 (permalink)  
Old 07-22-2009, 05:37 PM
fredtgreco's Avatar
Vanilla Westminsterian
 
Join Date: Oct 2002
Location: Katy, Texas
Posts: 10,525
Thanks: 335
Thanked 3,503 Times in 1,413 Posts
This is useful information. WHile not foolproof (a long way from it) there are two very simple methods that go a long way toward avoiding this kind of attack:

1. Never, never, never use the typical "remember my password" question. That was how Sarah Palin's Yahoo account was compromised. You don't want your password security hinging on your mother's maiden name, or your dog's name, etc. Instead, come up with a completely random nonsense answer to that question. For example, the answer to every question could be "going6734house98dogBabylon."

2. Never use the same passwords for sites. If you can't afford a password keeper like Roboform to randomize your passwords, then at least do not use the same passwords for different types of sites (i.e. Gmail and banks)
__________________
Fred Greco
Senior Pastor, Christ Church PCA (Katy, TX)
Christ Church Blog

"The heart is the main thing in true religion...It is the hinge and turning-point in the condition of man's soul. If the heart is alive to God and quickened by the Spirit, the man is a living Christian. If the heart is dead and has not the Spirit, the man is dead before God." (J.C. Ryle)
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
  #5 (permalink)  
Old 07-22-2009, 05:38 PM
Semper Fidelis's Avatar
Dux Tyrranus
 
Join Date: Oct 2005
Location: Northern Virgnia
Posts: 17,854
Blog Entries: 1
Thanks: 2,464
Thanked 6,038 Times in 2,450 Posts
...and having a Mac isn't going to protect you.

I can't agree Fred enough on using Roboform (they're developing a Mac Version BTW and have an online version now). Don't re-use passwords.
__________________
Rich
PCA, Northern VA
Student, New Geneva Theological Seminary

WebsiteMaven - Web Hosting Reviews, Guides, and Advice to build and promote your web site.
SoliDeoGloria.com - A Community for Reformed Thought and Discussion

Click to get: Board Rules -- Signature Requirements -- Suggestions?
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
  #6 (permalink)  
Old 07-22-2009, 05:47 PM
fredtgreco's Avatar
Vanilla Westminsterian
 
Join Date: Oct 2002
Location: Katy, Texas
Posts: 10,525
Thanks: 335
Thanked 3,503 Times in 1,413 Posts
Quote:
Originally Posted by Semper Fidelis View Post
...and having a Mac isn't going to protect you.

I can't agree Fred enough on using Roboform (they're developing a Mac Version BTW and have an online version now). Don't re-use passwords.
There really is no reason not to use Roboform. It's pretty cheap now, and with the online backup, you can get to all your passwords easily. $30 is nothing to pay for your safety.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
  #7 (permalink)  
Old 07-22-2009, 05:49 PM
glorifyinggodinwv's Avatar
Puritanboard Freshman
 
Join Date: Jan 2008
Location: Gilbert, WV
Posts: 410
Thanks: 189
Thanked 62 Times in 51 Posts
Quote:
Originally Posted by Semper Fidelis View Post
...and having a Mac isn't going to protect you.

I can't agree Fred enough on using Roboform (they're developing a Mac Version BTW and have an online version now). Don't re-use passwords.
This is very true. 1Password for Mac will generate random passwords for your Mac and store them. Many Mac IT folks recommend it. It also enables you to only have to remember one password to access the other passwords and will automatically log into sites for you.
__________________
Chris
Teaching Elder (PCUSA)
West Virginia
"Although the fig tree shall not blossom, neither shall fruit be in the vines; the labour of the olive shall fail, and the fields shall yield no meat; the flock shall be cut off from the fold, and there shall be no herd in the stalls: Yet I will rejoice in the LORD, I will joy in the God of my salvation." (Habakkuk 3:17-18)
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
The Following User Says Thank You to glorifyinggodinwv For This Useful Post:
KMK (07-22-2009)
  #8 (permalink)  
Old 07-22-2009, 06:02 PM
fredtgreco's Avatar
Vanilla Westminsterian
 
Join Date: Oct 2002
Location: Katy, Texas
Posts: 10,525
Thanks: 335
Thanked 3,503 Times in 1,413 Posts
and it goes without saying that the one password you should remember for these types of programs should be something random, like f4tY@qP*

Once you use almost anything enough, you can remember it. And you can always write it down and put it in a safe.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
The Following User Says Thank You to fredtgreco For This Useful Post:
glorifyinggodinwv (07-22-2009)
  #9 (permalink)  
Old 07-22-2009, 06:26 PM
AThornquist's Avatar
Puritanboard Postgraduate
 
Join Date: Sep 2008
Location: Ukiah, California
Posts: 4,001
Thanks: 1,460
Thanked 1,109 Times in 696 Posts
Twitter is so unspeakably fortunate that the hacker was not in it to tear them apart. Yeesh!
__________________
Andrew Thornquist My Photo Album
Calvinistic Baptist
Ukiah, California
To follow Christ was the best decision God made for me!
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
  #10 (permalink)  
Old 07-22-2009, 09:20 PM
Semper Fidelis's Avatar
Dux Tyrranus
 
Join Date: Oct 2005
Location: Northern Virgnia
Posts: 17,854
Blog Entries: 1
Thanks: 2,464
Thanked 6,038 Times in 2,450 Posts
Quote:
Originally Posted by fredtgreco View Post
and it goes without saying that the one password you should remember for these types of programs should be something random, like f4tY@qP*

Once you use almost anything enough, you can remember it. And you can always write it down and put it in a safe.
Now I know Fred's password to hack Roboform!!!!

BUWAHAHAHAHA!
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
  #11 (permalink)  
Old 07-22-2009, 10:45 PM
fredtgreco's Avatar
Vanilla Westminsterian
 
Join Date: Oct 2002
Location: Katy, Texas
Posts: 10,525
Thanks: 335
Thanked 3,503 Times in 1,413 Posts
Quote:
Originally Posted by Semper Fidelis View Post
Quote:
Originally Posted by fredtgreco View Post
and it goes without saying that the one password you should remember for these types of programs should be something random, like f4tY@qP*

Once you use almost anything enough, you can remember it. And you can always write it down and put it in a safe.
Now I know Fred's password to hack Roboform!!!!

BUWAHAHAHAHA!
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
  #12 (permalink)  
Old 07-22-2009, 11:24 PM
tgoerz's Avatar
Puritanboard Freshman
 
Join Date: Dec 2008
Location: Alvord, TX
Posts: 89
Thanks: 12
Thanked 20 Times in 11 Posts
[QUOTE=fredtgreco;658759]and it goes without saying that the one password you should remember for these types of programs should be something random, like f4tY@qP*

Once you use almost anything enough, you can remember it. And you can always write it down and put it in a safe.[/QUOTE]


Pardon me, but isn't this a bit much? If you have to put something like a password in a safe, I mean, it's almost conspiracy theorist type stuff.

Are people really going to break in and look for our on-line passwords that we might have on a sticky note on our desk?
__________________
"Be killing sin or it will be killing you."--John Owen

Tim Goerz
Weatherford Presbyterian(PCA)
Alvord, Texas
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
  #13 (permalink)  
Old 07-22-2009, 11:34 PM
fredtgreco's Avatar
Vanilla Westminsterian
 
Join Date: Oct 2002
Location: Katy, Texas
Posts: 10,525
Thanks: 335
Thanked 3,503 Times in 1,413 Posts
Quote:
Originally Posted by tgoerz View Post
Quote:
Originally Posted by fredtgreco View Post
and it goes without saying that the one password you should remember for these types of programs should be something random, like f4tY@qP*

Once you use almost anything enough, you can remember it. And you can always write it down and put it in a safe.

Pardon me, but isn't this a bit much? If you have to put something like a password in a safe, I mean, it's almost conspiracy theorist type stuff.

Are people really going to break in and look for our on-line passwords that we might have on a sticky note on our desk?
No. It is as much about being misplaced as being stolen. How many post-it notes have you lost in your life? Leave it in your wallet instead? That actually could get stolen.

But if I put that paper in my small safe, I always know where it is, no kid will move it or lose it, I won't accidentally throw it away, and anyone who steals it already likely has access to much more than it. And to secure it, I don't need to go to herculean heights. It basically takes me about 5 minutes to solve the password dilemma. That sounds good to me.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
  #14 (permalink)  
Old 07-22-2009, 11:48 PM
gene_mingo's Avatar
Puritanboard Junior
 
Join Date: Mar 2006
Location: Cottonwood, AZ
Posts: 1,443
Thanks: 897
Thanked 151 Times in 120 Posts
Not to mention, now we are seeing the death of SSL.

The ‘SSL strip’ exploit

It is much more refined than ettercap or dsniff/monkey in the middle.
__________________
Josh Taylor
Verde Valley Reformed Chapel, OPC
Cottonwood, AZ
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Closed Thread

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Powered by vBadvanced CMPS v3.2.0

All times are GMT -5. The time now is 04:46 AM.


Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.3.2 ©2009, Crawlability, Inc.
Copyright © 2002-2008 PuritanBoard.com
Hosted by WebsiteMaven - helping ministries with web hosting advice, reviews, and design.
67 Westminster Abbey © Confessional Presbyterian Presses - used with permission.
Add Our Custom Button to your Google Toolbar

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69