rpclogo

 

Email accounts at risk from not-so-secret questions

The "secret questions" used to secure online bank accounts and email services are worryingly easy to crack. So says Joesph Bonneau of the University of Cambridge, whose team has calculated the chances of an attacker correctly guessing secret answers.

Using data from sources such as national censuses and pet registries, the team calculated that if allowed three guesses, the norm for many websites, an attacker could correctly guess 1 in 80 answers.

That's too low to target a specific individual. But it is more than enough to allow a hacker to build software to compromise online accounts, such as webmail services, by attempting to guess questions in large volumes, says Bonneau.

An attacker who knows where accounts are based has an even higher chance of success, Bonneau adds, since they could restrict their guesses to names that are common in that region.

Twelve per hour

Bonneau and colleagues say that this weakness could lead to criminals gaining access to large numbers of personal accounts. This is particularly true for webmail accounts, which often rely on secret questions when a person forgets their password. For example, US vice-presidential hopeful Sarah Palin had her Yahoo email account compromised by someone who worked out her secret answers.

Banking sites require an extra security check before revealing a password. But some email services, including Gmail and Yahoo, will allow a user to choose a new password if one or more secret questions are answered correctly. An attacker that does this can then simply login to the account. "Email accounts increasingly have enough financial information in them to make it worth trying to take them over," says Bonneau.

Both Gmail and Yahoo require users to solve a CAPTCHA – blurred text designed to foil automated attacks – when recovering a password. However, a motivated hacker could work through 1000 in an hour, says Bonneau, enough to allow secret-question guessing software to break into around 12 accounts.

No more secrets

A spokesperson for Google noted that the company's secret questions are more secure than those used by rivals. This is partly because they include questions that are harder to guess, such as a person's library card or frequent flyer number.

When asked for comment, Yahoo! would not reply to Bonneau's specific concerns. A spokesperson said: "We have many security measures built into the registration and sign-in processes to protect our users and make every effort to educate them on how they can stay safe online."

But Bonneau says that websites should consider abandoning secret questions altogether. One option, already offered by Google, is for users to provide a cellphone number when registering an account. Passwords can then only be reset using a code sent to that number.

This method fails when a phone is lost or stolen, though, so Bonneau suggests using a more time-consuming but safer technique known as "social back-up". Each user provides the addresses of five trusted friends, who are sent unique codes when a password reminder request is made. To retrieve their password, a user must obtain codes from three of their contacts.

Courtesy Computer Crime

 

 

 

  HOW DOES THIS WORK ?
call1 Call our agents at 209-642-4483 and log your issues to us
age Our agent gets connected to your system remotely
che Sit back and relax or watch out our service
kno Once the issues are solved, the agent feeds you the knowledge transfer and disconnects from your computer
comm You can send your feedback / comments / expereince to support@remotepccure.org

 

Virus Removal Tool Names
Vcleaner
Removes the following viruses:
I-Worm/Stration, Worm/Generic.FX, Agent.A-AN, BackDoor.Agent.A-Z, BackDoor.Agent.AA-BG, Downloader.Agent.AS, I-Worm/Atak.A-I, Bagle.DA-IU, I-Worm/Bagle.A-Z, I-Worm/Bagle.AA-JD, I-Worm/Bugbear.D, I-Worm/Mytob.A-GC, I-Worm/Netsky.A-Z, Worm/Netsky.AA-AD, I-Worm/Sasser.A-F, I-Worm/Zafi.A-E, PSW.Bispy.A-E, Win32/Gaelicum, Win32/Hidrag
Worm/Downadup (Worm/Conficker)
Removes the following viruses:
Worm/Downadup (Worm/Conficker)
Downloader.Stubby.A
Removes the following viruses:
Downloader.Stubby.A
I-Worm/Bugbear.C
Removes the following viruses:
I-Worm/Bugbear.C )
I-Worm/Ganda
Removes the following viruses:
I-Worm/Ganda, papaDog Download remover:
rmganda.exe
Win32/Expiro
Removes the following viruses:
Win32/Expiro
I-Worm/Happy99
Removes the following viruses:
I-Worm/Happy99
I-Worm/Lovgate.C
Removes the following viruses:
I-Worm/Lovgate.C
I-Worm/Luder
Removes the following viruses:
I-Worm/Luder
Win32/Dundun
Removes the following viruses:
Win32/Dundun
I-Worm/Mydoom.A and B
Removes the following viruses:
I-Worm/Mydoom.A and I-Worm/Mydoom.B
I-Worm/Mydoom.F
Removes the following viruses:
I-Worm/Mydoom.F
I-Worm/Navidad
Removes the following viruses:
I-Worm/Navidad
I-Worm/Nimda
Removes the following viruses:
I-Worm/Nimda
I-Worm/Pretty_Park
Removes the following viruses:
I-Worm/Pretty_Park
I-Worm/Sircam.A
Removes the following viruses:
I-Worm/Sircam.A
I-Worm/Sober.A
Removes the following viruses:
I-Worm/Sober.A
I-Worm/Swen
Removes the following viruses:
I-Worm/Swen
I-Worm/Verona.B
Removes the following viruses:
I-Worm/Verona.B
LOP.AH/Backdoor.Generic3.SVX
Removes the following viruses:
LOP.AH/Backdoor.Generic3.SVX
Packed.Protector.C
Removes the following viruses:
Packed.Protector.C
Win32/Vampiro
Removes the following viruses:
Win32/Vampiro
VBS/Iloveyou
Removes the following viruses:
VBS/Iloveyou
Win32/Alman
Removes the following viruses:
Win32/Alman
Win32/Delf.2.B
Removes the following viruses:
Win32/Delf.2.B
Win32/Dupator
Removes the following viruses:
Win32/Dupator
Win32/Elkern, variants A, B and C
Removes the following viruses:
Win32/Elkern.A, Win32/Elkern.B, Win32/Elkern.C
Win32/Gaelicum
Removes the following viruses:
Win32/Gaelicum
Win32/Kriz
Removes the following viruses:
Win32/Kriz
Win32/Mabezat
Removes the following viruses:
Win32/Mabezat
Win32/Magistr, variants A and B
Removes the following viruses:
Win32/Magistr.A, Win32/Magistr.B
Win32/Parite
Removes the following viruses:
Win32/Parite
Win32/Prepender
Removes the following viruses:
Win32/Prepender
Win32/Sality
Removes the following viruses:
Win32/Sality
Win32/Tanatos, variants A, H, I and M
Removes the following viruses:
Win32/Tanatos A, Win32/Tanatos H, Win32/Tanatos I, Win32/Tanatos M
Win32/Valla.2048
Removes the following viruses:
Win32/Valla.2048
Win32/Virut
Removes the following viruses:
Win32/Virut
Worm/Lovsan
Removes the following viruses:
Worm/Lovsan

 

 

SERVICES FROM RPC

Antivirus Software

Computer Troubleshooting

Dell Computer Support

Toshiba Computer Support

Other Articles