04-11-2018, 11:58 AM
So are you saying that Sophos is rubbish?
How about https://www.grc.com/passwords.htm ?
What do you use, Nick?
How about https://www.grc.com/passwords.htm ?
What do you use, Nick?
|
Panic messages about Viruses
|
|
04-11-2018, 11:58 AM
So are you saying that Sophos is rubbish?
How about https://www.grc.com/passwords.htm ? What do you use, Nick?
04-11-2018, 12:19 PM
Cheesy as it may seem, I can't say the end-point product that we use as no business in their right mind would disclose that information... except I can say that we use Darktrace as an AI tool on the network (rather than end-point) side. A bit of Googling will get the names of the main end-point AI tools.
Darktrace does almost the same as our end-point solutions, but for network traffic. I'm allowed to mention them as we have agreed that they can use our name in their publicity. However, Darktrace is a SERIOUSLY expensive product, but it's seriously good at what it does - the company was set up out of Cambridge University (UK) with a bunch of Security Service, Secret Intelligence Service & GCHQ folk. Cunning stuff. I'm not knocking Sophos - it is what it is. The thing is that all domestic AV is a compromise, and Sophos, AVG, ... etc. are all in that bracket. The basic rules on risk management are: Identify, analyse & understand the risks; reduce the attack surface; of the remaining risks, mitigate those you can and formally accept the remainder. Companies serious about malware protection would never accept the risks associated with a deterministic scanner. You need a structured approach where every risk is understood (assuming you've identified all the risks, the main one being people). Regarding GRC (Gibson Research) - that is exactly the same as the information theory stuff I just wrote about, except he's using really long strings, so you'd have to use a password manager. The HEX string he provides has a full 256 bits of entropy, the second one about 388 bits out of a maximum possible 504, and the third string (reduced character choice compared to the second one) has about 375 bits of entropy. All these are stupidly high numbers and largely pointless. 388 bits of entropy means that a brute force attack would take up to 2^388 attempts before a hit was found (in practice, the number is 50% of that value). As there are "only" about 2^265 atoms in the universe, you can see the silliness of all this.
sıʌǝɹq ɐʇıʌ `ɐƃuol sɹɐ
ʞɔıu
04-11-2018, 12:30 PM
OK - I accept the confidentiality argument - I've been a board member of several companies so I understand exactly where you are coming from.
So - how do you protect your domestic computing? I assume that is not confidential ;-)
04-11-2018, 12:38 PM
(04-11-2018, 12:30 PM)Craig Wrote: OK - I accept the confidentiality argument - I've been a board member of several companies so I understand exactly where you are coming from. It's not confidential, except that I use the same end-point solution that I do at work... As mentioned, do a bit of Googling and you'll see what's there. In a year or so, I suspect the normal domestic stuff will be a lot lot better. Not only that, the hardware and operating systems will be too. Actually, there's an error on the GRC page (unlike him) - the site states "Every one is completely random (maximum entropy) without any pattern", however as a PRNG is used, by definition whilst the result may be very random, it's NOT "completely random", hence the "without any pattern" bit is also not strictly true as it's deterministic. It's good enough, for sure. These sorts of distinctions are important in security. Also the "maximum entropy" bit needs qualification - that should really be "maximum entropy for the choices available". As only the HEX string uses all 8 bits (2 characters at a time, i.e. 32 bytes of 8 bits), that's the only one with "maximum entropy" - all the others are compromises. Harumph!
sıʌǝɹq ɐʇıʌ `ɐƃuol sɹɐ
ʞɔıu
04-11-2018, 01:26 PM
(This post was last modified: 04-11-2018, 01:27 PM by ppppenguin.)
Of course there's a need for decent passwords but many organisations don't exactly help you do this. Things I've seen include:
Paaswords emailed back to you in open email. This happens with some forums when you become a new user. Maximum PW lengths, sometimes as short as 8 characters Requirement to include a number/capital letter/special character. This can actually reduce entropy Not allowing special characters Not allowing PW to start with other than a letter Some of these are from financial institutions where if your PW was hacked you'd lose money. Also even with good PWs and good PW policies, it only prevents brute force attacks. There are side channels, inculding human engineering, that can offfer much easier routes. For example the replacement SIM fraud: https://www.theguardian.com/money/2018/f...d-security This is an example of a fraud over which we have little or no control as end users.
www.borinsky.co.uk Jeffrey Borinsky www.becg.tv
04-11-2018, 01:36 PM
I agree about the detail regarding strong password generation on Gibson's site. In fact back in the day I used a hardware PRNG to add noise to, well something I actually can't say even 30-odd years later. That was the traditional multiple feedback shift register. I used a design with a massively long sequence that was well outside the computing capability of the day to latch onto the year long repeat length.
But I use the utilities on his site to probe my computer's ports and vulnerabilities to check I don't have any leaks.
04-11-2018, 01:42 PM
(04-11-2018, 01:36 PM)Craig Wrote: ...In fact back in the day I used a hardware PRNG to add noise... Normal to use Zener (shot) noise now, or radioactive decay - truly random sources.
sıʌǝɹq ɐʇıʌ `ɐƃuol sɹɐ
ʞɔıu
04-11-2018, 02:06 PM
(04-11-2018, 01:42 PM)Nick Wrote:(04-11-2018, 01:36 PM)Craig Wrote: ...In fact back in the day I used a hardware PRNG to add noise... Absolutely. Originally patented by my good friend and business mentor Gordon Edge (RIP) in 1963. Filed in 1961. GB942289A attached
04-11-2018, 09:08 PM
I haven't got a clue what all this geektalk is about.
Changing the subject back, I wonder what happened with Garry, if he has cleared his problem yet. Where are you Garry, have you got your PC back yet? Mike
04-11-2018, 09:37 PM
(This post was last modified: 04-11-2018, 09:39 PM by Murphyv310.)
Hi Mike.
It's scary out there, last night I couldn't sleep thinking about what new passwords I'd generate, I came up with some beauties but forgot them by the time i did eventually fall asleep and woke up again. Then I said "Oh well things are not so bad on Linux" I then did the latest Kernel update only to loose CubicSDR So I reverted back to the old one and all was well but then I got paranoid about passwords again. Next to come was a new oven as our old one decided to blow its forth element, only to discover the cooling fan was noisy and I couldn't get the clock to set. So possibly when Currys deliver a replacement oven with a quiet fan the clock will set. So tonight I'll not be thinking about viruses at bed time just our Gary's Shingles he contracted last week which I believe is a virus. Oh and I shut the PC & Laptop down and not to sleep, as it's less likely to get a virus that way...... so I've been told. What a day it's been. Night Night
|
| Users browsing this thread: |
| 1 Guest(s) |