EP 282: SpecOps Makes Password Auditor Free To Help WFH
With so many working from home (WFH), security is being tested perhaps like it never has before. The good folks at SpecOps have made their password auditor product free during this trying time.
We spoke with Darren James of SpecSoft about this release and some other tools they have released to help people through the rough spots. Darren had some good insights he shared and we discussed. Have a listen
Transcript
Hi, everyone,it's Alan Shimel, and you're listening to a DevOps chat today's DevOps chat features a company called SpecOps. And we're joined by Darren James, SpecOps. Darren, welcome.
Thanks very much, Alan. So, Darren, I don't think we've done any spec ops podcast before and so on. I don't know how much our audience is familiar with SpecOps.
Why don't we start with maybe just a quick kind of what SpecOps is, what you guys do, where you play? Sure. Absolutely.
So we we're a company software company that's based in Stockholm, in Sweden. We've got offices all around the world, around the world. We've been running since 2001.
D.. Interesting. Interesting.
So it's an area you know, a little bit about. It's you know, I agree. D.
not not to get too far off track, but, you know, Darren Hédi was one of the unspoken. You know, monopolies of Microsoft, if you will, it really. Absolutely the standard that we all use for.
For identity access management. And one of the things we're seeing is with the proliferation of cloud. And cloud based apps, sass and remote working.
More people using Macs and stuff like that is a deal having to respond. D. comes.
I'm curious. Are you guys seeing that or is it still the 85 percent in the market, 90 percent of the market? I think yeah.
What you've just said there, the latter. I think unless you're a brand new start up who's sort of born on cloud apps, it's very unlikely that you've not got an active directory. It's in your organizations that's really managing your users and groups and policies.
And sure, you're absolutely right. The advent in the last few years of bring your own device type technologies, that's probably lessened a lot of the reliance on active directory when it comes to managing workstations. But still, we all use a management.
D. or Office 365 or some other sort of metadata entry. It always seems to be easier to manage at the moment, or it still seems to be easier to manage or a lot of organizations within.
With that on Prem Active Directory, that's up. Yeah. Who knows what happens in the future.
I'm sure Microsoft themselves want everybody to move to Azure idea at some point in the future. But I'd say ninety nine point nine percent of the customers that we speak to all have a reliance on there on primary day. Interesting.
You know, in my Nekrasov office, 365 is going to Microsoft 365, which I guess is I don't know if it's just wording or something else behind that. T. is code.
And it's really aimed at that idea. T. generalists, the people who were responsible for those 8D servers and are responsible for those 80 servers and not just the servers, but the interaction that employees and users have with it as well.
As you know, for so long, the exchange server was the was the go to for e-mail and still is for many, many organizations. Well, we're seeing that also migrate up into Azure and as part of this SAS world. But, you know, John, we find ourselves in in interesting times around this Kovil 19.
Situation. You know, no matter where we are in the world, Asia, Europe, North America, South America, Africa, Middle East, Australia, many, many of our listeners are listening to this while working from home. And this has especially for organizations that have sort of on Prem a D.
You know, maybe had it moved to the cloud or weren't, you know, we really have a remote worker. Workforce in mind. You're right.
It's put it's put in a little bit of a curve in the road, fly into the superior to the ointment. Absolutely. Yeah.
What do you what are you guys seeing and how are you responding? Well, I think one of the biggest problems that a lot of organizations said is that they really haven't got any sort of plan for managing their users off sites for an extended period, period of time that we're seeing at the moment. So you have all of those issues that you had with the with your kind of road warrior workers where maybe their password would expire, you know, while they're on the road.
They didn't get any notifications about that R-squared expiring. And of course, it then becomes very hard for them to change their password because they might not be able to get a VPN connection in because their passwords expired or they're logging on with a cache credential and that's causing account lockouts and all sorts of other things. So having to manage that kind of situation on a much larger base now can be a real challenge for a lot of the customers that we see.
Another issue as well is that you've also also had a lot of people with, you know, password one with a capital P as their password. Since the year dots. And now they're having to log in from their home computer for a murmur from our remote computer that that doesn't really have a lot of protections that you might normally see inside an internal network.
So you might be entering that password into, you know, your your personal computer, which may have a key logger or some other nasty piece of malware on there. So, again, you've got those challenges of lots and lots of weak passwords out there that ideally should be changed. And again, form targets for hacking and and various attacks from from nefarious sources out on the Internet.
So it's those sorts of weaknesses that we're seeing come to the fore at the moment, and especially a lot of phishing attacks based on Kovik, 19 people saying no, click here. You're getting an email saying click here to receive your free corona virus testing kits and enter your username and password. We've seen a few of our customers mentioned that.
T. community through that kind of or through this difficult time at the moment. So we've released a couple of tools.
And over the last week or so, that should help people in that respect. You know, Daryn, it's goes back to something I said before, which is this is exactly why we can't have nice things, right? Yeah.
You know, there could be such a help here during these these surreal times. And there's so much that we can do. And we were kind of stymied because.
Because they had people do bad things and, you know, the same way we're having a pandemic of Cobian 19. We're having a pandemic of Copely Cauvin 19. Cyber.
Yes. Yeah. You know, phishing is one aspect of it.
I think you mentioned. Right. And to a lot of our audience at these times where it's not just our usual core audience who's listening to this, don't to know very well what phishing is and, you know, things, but we might have some people maybe aren't familiar with phishing, especially from the aspect of working from home on different.
No device or what have you. What is some of the kind of Corbitt 19 phishing scams that you've seen? Well, typically, as I say, the one I just mentioned.
So your your being sent an email from a what looks like an official source because it's very easy to scam an email or send a scam email out from for many. Any email address you like. And then it may have a link inside it.
And that link, again, may look official. But of course, if you hover over that link and you look at the URL a little bit closer, you might see that that goes off to some less than respectable Web sites. And when you click on that link, that may well look like an Office 365 log in, or it might look like a government, Web sites or whatever it may be.
But at that point, it may ask you to create an account or into your logging details if it's let's say it's pretending to be Office 365 and your type, your credentials in there. And of course, you're not actually logging into Office 365 with those credentials. Your you're giving those credentials to that nefarious character.
S. government 100 hours or so. And already we're seeing phone scams, too.
Yeah. Purporting to be the IRS saying, hey, we want to we want a direct deposit your money and you give us your bank info. Absolutely.
Absolutely. I mean, we've seen that as well with with our service desk, you know, because typically working in an organization, you contact the service desk from an internal number. Now, your service desks are having to field calls from external numbers.
And so someone pretending to be Darran calling up the spec ops service desk. How does that service. There's actually no that is, Daryn, at the other end of the phone.
So you have all of these very unusual circumstances, particularly that scenario. It's quite easy to turn to, you know, to lure that to the service desk agent into resetting a password or or giving over information that they shouldn't necessarily give information over to you. So you're absolutely right.
All of those things are now at the forefront of to recognize ransomware. Yes, absolutely. Yeah.
Clicking on links and downloading some nasty piece of software. Again, that's why we can't have nice things. Yep.
I mean, you know, it amazes me. I mean, I was somewhat heartened, Daryn, when I when this first started breaking out, we saw some, you know, criminal. Cyber gangs saying they were going to stay away from health care and hospitals and that's all fine and dandy.
Well, it's very nice, very sad. The life you save may be your mom's, but. But, you know, in spite of that, it's just awful that with everything else and all the anxiety and stress that this whole situation brings, we've got to worry about people trying to fish us and.
Not just withdrawals went, as you said, even the service does not yet who are under pressure to keep the wheels off. Exactly. And that's the biggest problem, is that everybody is now under pressure to try and generate or keep our businesses running as smoothly as they possibly can.
So everybody's fighting for every last last scrap. So, you know, having to put in that delay to try and authenticate somebody or at the other end of the phone, it's very easy to put pressure on that on that service desk agent. So, yeah, it really is.
It's it's input. But, you know, it's still very important to maintain that security because I don't know what it's like in America. Well, I've got in fact, I've got a pretty good idea.
But of course, if if you do start getting away sensitive information, then your company is is criminally responsible for that. So as well as, you know, financially responsible. So is too interconnected to have borders around cyber privacy and things.
Yeah. So Ma, we all have customers and connections in Europe then. Exactly.
California has. Why we've done more of a piecemeal thing. You know, you're right.
I also wanted to just highlight though that. Spec ops can help you in this. Crazy time that we find ourselves in.
Not at all, if you're a specs on spec ops commercial goes, you have some freeware stuff you're making available to people. Absolutely. So, you know, one of the problems that we mentioned earlier, I mentioned earlier about having weak passwords and account lockout's.
We actually have a tool called spec ops password auditor. You can download for free from our website. And up until a week ago, it would tell you how many users have got compromised passwords in your network.
So you could see how big the problem was, but it didn't really give you allow you to do anything about it. A week ago, what we decided to do, though, is completely change that process. So now you can download the full version of spec ops password auditor and it will give you the names of every single user in your day in your active directory that is running a compromised password based on a 719 million word database that you can download for free from us.
So I don't know if you've ever seen how I've impound the website. I'm sure you have to, yeah. So Troyes database with 555 million passwords in it, we've used effectively all the same sources as that, but choise just the one guy who's done a fantastic job.
We have a team of DevOps guys that are building up this database all the time. So we've just got there. Well, nearly 200000 more hashes in our database at the moment.
So if you are worried about things like that, you're worried about your users typing in their very weak passwords into lots of, you know, externally facing portals these days. You can now identify those users, get in touch with those users and encourage them to change their passwords to something a bit better and then run their report again. You know, you can run as many times as you want.
And so you weed out all of those things. And where do people get that down? It's on our website.
You just head over to spec ops off dot com. Look for spatchcocked password auditor. You don't need to sign up.
You know, marketing. That's what they like to do these days. But it is completely free.
And, yeah, there's no sort of ad where it can be run off line if people are worried about, you know, running this tool. You can download the database, run it off line. Doesn't need to be on a on Internet connected computer.
So. And it doesn't crack anybody's password. It just compares the hashes.
So it runs within seconds even on a huge environment. So it's not there sort of it's not like a loft crack or John the Ripper or any of those sorts of tools. It's just comparing hashes.
One of the things and there's got to be a pony in here. There's a solution waiting to be found, as you know. So someone I mean, the average person today has actually gone ahead.
Read something maybe a year or two ago. The average person today probably has about 80 different plus sites that he has or he or she has passwords for show. And in some case, I know in my case it's closer to one hundred and fifty.
And I try to keep it's a different password for each one. So there's a lot of variation. And so when you go run against the password ordinary like that, and it says, okay, you know, these 50 pantsuits need to be changed or these 20, even 25 as we need to be changed.
It's somewhat daunting to go to 25 different sites at once and change those passwords. I wish there was some automated way of taking that to the next stop, saying these are the sites where your passwords are compromised or maybe compromised. And click here, you know, give me 25 different passwords and, you know, any password manager.
Yeah. I mean, yeah. I mean.
I mean, password audits will only look at your active directory passwords. So look at it would look at all of your users and it'll tell you which idea, which shady passwords a compromised and give you the names of the users of using those. But you're absolutely right.
When you know, when you're trying to manage all of these identities and all of those passwords associated to those identities, having to update passwords across twenty five thirty under different sites is crazy. But again, what I always try and encourage if someone asked me, you know, what what sort of what should I do with a password? How should I.
What sort of password should I type in? I always try to encourage people to use pass phrases rather than passwords. And then they go, Oh, but I don't stand a chance just typing in a 20 character, you know, what do I get around that?
And again, my advice would be and it's the same advice that the British government, the NTSC has been giving out, trying to think of three random words that mean something to you, but nothing to anybody else. So it might be the first call. You have a bought the first school you went to your mother's maiden name.
Those three words are very easy for you to remember and very easy for you to type. So it doesn't need to be complex. You could add some numbers or digits or dashes or, you know, special characters in there somewhere if you wanted to.
But it's not that important. As long as those three words together, that's fine. And then every now and again, particularly for the different sites I like to check in, may be something to do with that site as my fourth word.
And that way I've got a very long password that's very easy for me to remember on a per site basis. But that's my that's just the way I like to do it. And sure, you know, I chuck a few extra characters in there as well.
But but it's that's, I think, quite a nice way of getting getting across the pass. So you shouldn't use things like, you know, the first line of a song or the title of a movie or a famous quotes or phrase. It's a bit of a misnomer passphrase.
But just having those three random words, I think is a great way of dealing with that problem, certainly for me anyway. Absolutely. Kevin, that's great advice.
Great, great, great advice right there, Daryn. When we started, I said, you know, the the the double edged sword here is that we keep these to about 15 minutes. We're probably closer to 20.
And I know you have to get off. So we're going to we're going to call a break right here. But you know what?
For those listening, we've been doing our tech strong TV every day. And I invited Darren on maybe next week to record a video segment for that with us. So, Darren, we'd love to have you on here again or not on DevOps chat, but on tech, strong TV.
Perfect. I'll put my makeup on for that day. Yeah.
Call me. I've got a face for radio. But anyway, I want to thank you for joining us on this episode of DevOps chat.
Thanks Spec Ops for making this part. The full version of specked password ordered are available for free to people during this crazy time. And best of luck and stay healthy.
Yeah, you too. Thanks, Alan. Good to talk to you.
All right. Darren James for SpecOps here on DevOps chat. This is Alan Shimel.
And you just listened to another DevOps chat. Stay well and healthy, everyone.