Back in 2019 I started to make some materials to help people with some basic offensive security techniques. I made three eppisodes of training materials. Well I’ve decided to re-release these, they haven’t really been changed but I’ve updated a few graphics on episode 3 and removed a link to Cain and Abel because it’s no longer maintained. I will probably go through these at some point and re-factor them.
I’ve got more documents on active directory security, I’ve actually written hundreds of pages on the subject but the challenge I’ve had is there is just so much to write, so I’ve decided I’m going to chunk it up into small blogs on a specific technique or area.
Read more “Hacking 101”
The authentication dilemma
I’ve worked with a lot of organisations over the years and seen lots of ways of doing certain things. Policy implementation is one of those! I’m in a fortunate position where I get to see different people’s policy documents, their systemic implementations and even interview staff to see how these work on the ground. So, I thought I’d write about password policies!
Humans like to be efficient and people also struggle to deal with the huge volume of identify management and authentication solutions they are presented with. Just think, how many passwords are required in everyday life?
- Multiple 4-digit PIN codes for debit and credit cards etc.
- Online banking sign in credentials (more PINS)
- Gym padlock PIN combo (usually 4 characters)
- Passwords for home computer
- PIN code or password for mobile phone access
- Passwords of phrases for telephone services e.g. to access your mobile phone account services
- Social media credentials
The list goes on and on! Then let’s add in corporate IT services….
Anyone who’s worked in an office will have seen familiar sites of the following:
- Password on post it notes
- Password shared with colleagues
- Password sellotaped to keyboard (either on top or underneath)
- Passwords shouted across the office
- Passwords written down on white boards
Read more “How to write a bad password policy!”