The Wages of Password Re-use: Your Money or Your Life

When normal computer users fall into the nasty habit of recycling passwords, the result is most often some type of financial loss. When cybercriminals develop the same habit, it can eventually cost them their freedom.

Our passwords can say a lot about us, and much of what they have to say is unflattering. In a world in which all databases — including hacker forums — are eventually compromised and leaked online, it can be tough for cybercriminals to maintain their anonymity if they’re in the habit of re-using the same unusual passwords across multiple accounts associated with different email addresses.

The long-running Breadcrumbs series here tracks how cybercriminals get caught, and it’s mostly through odd connections between their online and offline selves scattered across the Internet. Interestingly, one of the more common connections involves re-using or recycling passwords across multiple accounts.

And yes, hackers get their passwords compromised at the same rate as the rest of us. Which means when a cybercrime forum gets hacked and its user databases posted online, it is often possible to work backwards from some of the more unique passwords for each account and see where else that password was used.

SWATTING THE FLY

Of all the stories I’ve written here over the last 11 years, probably the piece I get asked most to recount is the one about Sergey “Fly” Vovnenko, a Ukrainian man who in 2013 hatched and executed a plan to buy heroin off the dark web, ship it to our house and then spoof a call to the police from one of our neighbors saying we were dealing drugs.

Fly was the administrator of a Russian-language identity theft forum at the time, and as a secret lurker on his forum KrebsOnSecurity watched his plan unfold in real time. As I described in a 2019 story about an interview Fly gave to a Russian publication upon his release from a U.S. prison, his propensity for password re-use ultimately landed him in Italy’s worst prison for more than a year before he was extradited to face charges in America.

Around the same time Fly was taking bitcoin donations for a fund to purchase heroin on my behalf, he was also engaged to be married to a young woman. But Fly apparently did not fully trust his bride-to-be, so he had malware installed on her system that forwarded him copies of all email that she sent and received.

But Fly would make at least two big operational security mistakes in this spying effort: First, he had his fiancée’s messages forwarded to an email account he’d used for plenty of cybercriminal stuff related to his various “Fly” identities.

Mistake number two was the password for his email account was the same as his cybercrime forum admin account. And unbeknownst to him at the time, that forum was hacked, with all email addresses and hashed passwords exposed.

Soon enough, investigators were reading Fly’s email, including the messages forwarded from his wife’s account that had details about their upcoming nuptials, such as shipping addresses for their wedding-related items and the full name of Fly’s fiancée. It didn’t take long to zero in on Fly’s location in Naples.

POOR PASSWORDS AS GOOD OPSEC?

While it may sound unlikely that a guy so enmeshed in the cybercrime space could make such rookie security mistakes, I have found that a great many cybercriminals actually have worse operational security than the average Internet user.

Countless times over the years I’ve encountered huge tranches of valuable, dangerous data — like a botnet control panel or admin credentials for cybercrime forums — that were full of bad passwords, like password1 or 123qweasd (an incredibly common keyboard pattern password).

I suspect this may be because the nature of illicit activity online requires cybercrooks to create vast numbers of single- or brief-use accounts, and as such they tend to re-use credentials across multiple sites, or else pick very poor passwords — even for critical resources.

Regardless of their reasons or lack thereof for choosing poor passwords, it is fascinating that in terms of maintaining one’s operational security it actually benefits cybercriminals to use poor passwords in many situations.

For example, it is often the denizens of the cybercrime underground who pick crappy passwords for their forum accounts who end up doing their future selves a favor when the forum eventually gets hacked and its user database is posted online.

SOME ADVICE FOR EVERYONE

It really stinks that it’s mid-2021 and we’re still so reliant on passwords. But as long as that’s the case, I hope it’s clear that the smartest choice for all Internet users is to pick unique passwords for every site. The major Web browsers will now auto-suggest long, complex and unique passwords when users go to set up a new account somewhere online, and this is obviously the simplest way to achieve that goal.

Password managers are ideal for people who can’t break the habit of re-using passwords, because you only have to remember one (strong) master password to access all of your stored credentials.

If you don’t trust password managers and have trouble remembering complex passwords, consider relying instead on password length, which is a far more important determiner of whether a given password can be cracked by available tools in any timeframe that might be reasonably useful to an attacker.

In that vein, it’s safer and wiser to focus on picking passphrases instead of passwords. Passphrases are collections of multiple (ideally unrelated) words mushed together. Passphrases are not only generally more secure, they also have the added benefit of being easier to remember. Their main limitation is that countless sites still force you to add special characters and place arbitrary limits on password length possibilities.

Finally, there’s absolutely nothing wrong with writing down your passwords, provided a) you do not store them in a file on your computer or taped to your laptop, and b) that your password notebook is stored somewhere relatively secure, i.e. not in your purse or car, but something like a locked drawer or safe.

Further reading: Who’s Behind the GandCrab Ransomware?

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Contact Tracer Breach Hits the Keystone State

Contact Tracer Breach Hits the Keystone State

Personal health information (PHI) belonging to tens of thousands of Pennsylvanians has been exposed following a data breach at a Department of Health vendor.

Atlanta-based company Insight Global was contracted by the Keystone State’s DOH in 2020 “to provide contact tracing and other similar services” following the outbreak of COVID-19. Now the Department is accusing the company of exposing the data of 72,000 individuals by willfully disregarding security protocols.

Pennsylvanians contacted by Insight Global in a contact tracing data collection operation reported to have cost $28.7m shared their information on the understanding that it would be kept confidential. 

Department of Health spokesperson Barry Ciccocioppo stated “certain employees of Insight Global—a vendor contracted by DOH in 2020 to provide contact tracing and other similar services—disregarded security protocols established in the contract and created unauthorized documents outside of the secure data systems created by the Commonwealth. 

“These documents existed separately from the official data that Insight Global employees were collecting and providing to DOH within secure data platforms.”

Information exposed in the data breach reportedly included names, phone numbers, and medical information. The DOH said that their data systems were not impacted by the breach. 

“From the briefing I got this morning from the Governor’s Office, there were several employees of Insight Global that ignored or purposefully avoided security protocols, I don’t know whether to make their job easier or what,” said State Representative Jason Ortitay, who serves portions of Washington and Allegheny counties.

He added: “They were basically putting information and people’s names into Google documents and then they were sharing them amongst each other.”

A spokesperson for Insight Global told WXPI that contact tracing information “may have been made accessible to persons beyond authorized employees and public health officials.”

The company has launched an investigation into the security incident and taken steps to secure the PHI that was exposed. Free credit monitoring and identity protection services will be offered by the company to individuals affected by the breach. 

Insight Global’s contract with the Department of Health expires on July 31. The Department has stated that it will not be renewed.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Online Child Abuse Platform with 400k Users Taken Down

Online Child Abuse Platform with 400k Users Taken Down

A website through which more than 400,000 users accessed child sexual abuse material (CSAM) has been taken down in an international operation led by German police.

The Boystown site had existed on the Darknet since at least June 2019 and had users all over the world. After creating an account, users could download videos and images depicting the sexual abuse of children, exchange content of this nature with one another, and also chat together via voice channels.

“Among the images and video recordings shared were also recordings of the most severe sexual abuse of young children,” German prosecutors said on Monday.

DW reports that administrators of the platform sent advice to users on how to access the site securely to avoid criminal prosecution. 

Four German citizens have been arrested on suspicion of being involved with the Boystown platform. Three of those people are accused of operating and maintaining the site.

During mid-April raids on seven properties, police took into custody a 40-year-old man residing in Paderborn in western Germany, a 49-year-old man from the Munich area, and a 58-year-old man from northern Germany who has been living in Paraguay for several years. 

The fourth suspect, a 64-year-old man living in Hamburg, is accused of creating an account on the Boystown platform in July 2019 and using it to post over 3,500 pieces of content to the site. If proven to be true, his alleged activity would make this man one of the site’s most active users. 

An international taskforce set up by the German Federal Criminal Police (Bundeskriminalamt) to target Boystown and its users included Europol and law enforcement agencies from the Netherlands, Sweden, Australia, Canada, and the United States. 

Europol said that several other chat sites on the dark web that were used by child sexual offenders were also seized as part of the Boystown takedown operation. 

“The image and video data seized during this investigation will be used for Victim Identification Taskforces organized on a regular basis at Europol,” stated Europol. 

“More arrests and rescues are to be expected globally as police worldwide examine the intelligence packages compiled by Europol.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

US Mulling Domestic Spying Partnership with Private Companies

US Mulling Domestic Spying Partnership with Private Companies

The Biden administration is reportedly considering teaming up with private companies to monitor American citizens’ private online activity and digital communications.

According to news source CNN, multiple sources have said that the Department of Homeland Security (DHS) is actively seeking a way to monitor citizens online without having to first secure a warrant or prove that such monitoring is an essential part of an ongoing investigation.

The sources said that a plan is being formed for the DHS to circumvent these established checks to the government’s power by working directly with private firms.

Currently, only the unprotected information that Americans share on social media sites and public online platforms can be accessed by federal authorities. 

However, the alleged plan being formed by the DHS would allow authorities to see what Americans are writing and sharing online in access-restricted spaces such as private Facebook groups. 

The plan is reportedly not centered on the decryption of data belonging to Americans but is instead focused on getting outside entities with legal access to the information being shared online to report what is being said to the government.

Limits are also in place at the Central Intelligence Agency (CIA) and National Security Administration (NSA) when it comes to domestic espionage. 

After WikiLeaks published data in 2017 that Julian Assange said included evidence that the CIA may have hacked smartphones to spy on US citizens, the CIA denied that such activity had taken place.

“It is . . . important to note that CIA is legally prohibited from conducting electronic surveillance targeting individuals here at home, including our fellow Americans, and CIA does not do so,” said CIA spokesperson Jonathan Liu.  

“CIA’s activities are subject to rigorous oversight to ensure that they comply fully with US law and the Constitution.”

The alleged new DHS plan comes after the PRISM domestic surveillance program, in which the NSA, FBI, and CIA gathered and searched through Americans’ international emails, internet calls, and chats without obtaining a warrant, came under criticism from the American Civil Liberties Union.

ACLU described the program as “violating the Fourth Amendment on a massive scale” and “one of the NSA’s worst spying programs.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk