November 24, 2009

Password, safety and Social Engineering for beginners

One of the many ways to protect our information is that of blind with the passwords. These can be of varying complexity and managed by our memory (safest ever, but limited :) in time and in the number of different passwords to remember) or software that allow you to manage, store and / or generate new keys.
Examples of applications are 1Password, KeePass for Mac and Windows or Roboform.

When you surf the web or you are prompted for a password should always pay attention to who is asking us our credentials: it is a trusted site or are about to bite a phishing scam?

Nothing can be safe also using the best cryptex to encrypt our information if we leave our passwords written on post-it or we fall in a phishing site. Social Engineering is well known act aimed to manipulate people and get their information, passwords and so on.

Always check whether you are accessing via HTTPS or via simple HTTP.
In one case the password is transferred from client to server in encrypted manner, so do not be deciphered by any sniffer in the second case (HTTP), the password is transferred in "clear", then a sniffer to read quietly in the information and we are potentially an unsafe condition.

Another IMPORTANT rule is to NOT store anywhere you access codes for your online bank account. Remember that each system is potentially unsafe and can be "hacked" :)

Thanks for reading :-)

No comments:

Post a Comment