Moving Beyond Passwords with Tulane University’s Demetrice Rogers
Demetrice Rogers, adjunct professor for cybersecurity at the School of Professional Advancement within Tulane University, dives into why organizations need to move beyond simple passwords if they hope to prevent cyberattacks.
Transcript
This is Textron tv. Hey guys, thanks for the throw. We're here with Demetrius Rogers, who's an adjunct professor for the School of Professional Development at Tulane University, and we're talking about cybersecurity specifically, this trove of, uh, passwords and credentials that were found in numbered nearly a billion, I think, um, all in plain text.
And what are the implications thereof to meet you? Welcome to show. Hi.
Thank you. Thanks for having me. I think we all know that credential Stuffings been going on for a while, and I do believe that we're all aware that they're hoarding passwords out there, but did the number in this instance surprise you and what are the implications?
Oh, yeah, the number, uh, definitely surprised me in this, in this instance. So, of course, you know, rock U has been out since 2000, uh, nine initially, you know, with 32 million passwords or so. Um, but now they're up to nearly 10 billion passwords, uh, in this particular release.
So, to that end, are all those passwords active, relevant people, hopefully, theoretically changed their passwords from time to time. Probably not enough, but, um, you know, do, do we have any sense, uh, how many of these passwords actually are usable? So over the years, rock U adds onto their, uh, their database of passwords there.
So it's a, a culmination of, of the, you know, the past previous years. Um, and it's also from other breaches that have occurred over the last several years. Uh, basically they've taken passwords that have been found in those breaches, and then they compile 'em into this database.
Um, from the first initial glance, uh, many people are saying that they are seeing their passwords in this, uh, recent breach. Uh, several websites, of course, are now rushing to update their, uh, checkers to see if, uh, you know, your password has been leaked in this breach, allowing you to search that Rock U 2024 breach for your particular password. Whose responsibility is it to do that?
Is it me, the end user, or will each of the services that I'm using eventually get around to sending me an email saying, Hey, we noticed your password is in this file. So initially it's the end user. Um, I think that an, an organization checking to see if, uh, you know, their particular password hashes or a part of a database like this, uh, would be beneficial.
Um, but for the most part we've seen it's, it's usually on the end user. Well, that's a shame. Don't you think the responsibility kinda lies with some of the people who are providing the software that we're using to access with these here passwords?
They, they are the ones who gave us to 'em in the first place. A hundred percent. Yeah.
It's something, a a check or, uh, something like that, that the organization can do would be, would be great. Um, I think that it, it's even more concerning with, uh, you know, the recent at and t breach where call logs and pass or call logs and text logs were released combined with their recent breach in the earlier this year with social security numbers. Um, attackers are able to, to combine all this information together and then can start, you know, getting a profile on a particular user and then using that, uh, to basically go after a particular user and gain access to their, to their accounts.
Are we kinda misaligned in our cybersecurity efforts as a result of all this? Seems to me we have spent an inordinate amount of money on protecting the perimeter and all those good things, and yet we have all these username and passwords out there, and it's, we might as well just give people the keys to the car as it were, and then be surprised when it gets stolen. Um, do we need to kinda rethink our cybersecurity strategies?
I believe so when it comes to password, you, you still have organizations out in companies that still don't require two-factor authentication. Um, I think that, uh, enabling two-factor or multi-factor authentication is key. Um, or, or even getting away, you know, to the newer passkey technology and items like that to, uh, get away from a traditional password.
Uh, per se, We have been using passwords since, I don't know, the first caveman grunted who goes there. Um, is this a cultural issue? I mean, are we all kind like ingraining to use passwords?
And that's part of the problem? So I, I think that for the most part, people of course, they want to have a password that they can remember. They don't like using, you know, extensive passwords or, or password managers that could actually make it a little bit easier for them.
Um, and they wanna be able to use that same password across multiple websites so that way they don't have a different password. And, and that's one of the, you know, the big issues like you mentioned when we first started talking here about credential stuffing, so reusing of that password across multiple websites. Um, and, and that's just something that as a culture, we, we find most of our end users doing using that same password, you know, for their bank.
They also use it for their Facebook or their social media accounts. Um, they use that same password everywhere. So once an attacker gets that password, you know, they pretty much have free reign of their entire, uh, life, basically all of their accounts.
Is there a difference between variations of a password or might as well just be the same password because the bad guys have the tech to figure out the, so-called extensions of those passwords? So that's a good question. So a lot of people ask, you know, should we have special characters, you know, uppercase, lowercase, uh, spaces?
It does help. Um, however, once we start, if they have a, a hash of that password, they can do certain types of hash, the hash type of accounts or attacks where they actually take the hash of that password, and then they're able to authenticate, of course, with that hash where they don't even need the, uh, clear text of your password. So the special characters, uh, you know, spaces, all that stuff doesn't matter because they have the actual hash.
Is there something different about passwords and pins? And I'm asking this question because, um, a friend of mine was asking this. He said, you know, I get in notice is the change in my password every three weeks now it seems.
But he says, I've had the same pin with my bank with no issue for three decades. So what exactly is the, the difference here when we seem to be able to maintain some level of security around a pin but not a password? Right?
That, and that kind of gets after the, the pass key kind of technology that's coming out. I believe it's kind of the same technology, um, where you, you have a pin to your debit card, you have a certain pin or, or pass key that you set up for these websites. Um, but yeah, that, that's an excellent point.
Uh, you know, of course I've had my same pin now for years. You, it's not something you get prompted to do. You know, when you go to an ATM, it's not like, Hey, it's time to change your pin.
But, um, and then it's of course, it's only for that particular physical card, right? So, um, of course an attacker would have to have a, a clone of that card or that actual card. Um, and I think that that's kind of where the passkey technology is getting after.
What is your sense of, uh, will AI just make it easier for the bad guys to figure out what our passwords are and what should we be worried about? So yeah, AI is definitely changing, uh, changing the layout here. So, um, especially with, uh, open AI where you can basically ask, you know, AI to make these types of calculations for you.
Of course they have some general restrictions in place, but a lot of users are able to get around those, uh, restrictions that are in place by our, our modern o open AI solution. So, um, AI as, as our computational technology is starting to get stronger and faster, um, I think it's only a matter of time before, uh, attackers figure out that password. Um, you know, a lot of organizations do have brute force, uh, protection in place, but I've still found several businesses, several logins to webpages that they, they don't care how many times you try a password, um, which is bad for a, a release like the rock.
You, when you have, you know, that many passwords, um, especially when you start narrowing it down by the other, uh, breaches that we've had recently. You can, you can narrow it down to, you know, a a good little number of passwords for a particular user Who's in charge of all this. And I asked the question because theoretically it should be security people, but in my experience so far, we see developers are the one assigning passwords to folks.
And then when they build the app and it ops people assign passwords to folks when they give 'em cloud access services, it feels like kinda like everybody's in charge and nobody's in charge. What's going on here? Yeah, that, so the, the default passwords, you know, usually when a, a software gives you that default password, the first thing it always asks you to do is to reset your password.
So a lot of times the user will just use that same password that they're used to using for everything else because they're, you know, initially prompted to do that. Um, so I, I think we kind of enable that culture as, as, you know, system administrators by having them change that password to, you know, something easy. Um, I have seen some built-in checkers recently on websites that have been checking, uh, common password lists, not something extensive like, you know, the Rock U 2024 breach with the 10 billion passwords.
But, um, some websites are doing, you know, basic checking and to make sure you're not using baseball 1, 2, 3. Uh, but, um, like we in, uh, mentioned a little earlier, having some type of check where it's checking an extensive database for, uh, particular hash or particular password would definitely, uh, help in this type of scenario. We also see all these password managers that are out there.
Are they effective? Because sometimes I wonder if they're just not bigger targets. So, uh, I do like password managers, but I've always been on the fence behind password manager myself.
That's just personally, um, you know, a lot of security professionals, uh, they believe password managers are the way to go. Um, but my thing is, if somebody gets access to my password manager, they have keys to the kingdom, because of course, if you're using a different password for every website, like you're supposed to, you're storing it in your password database, password manager. Um, and you know, even if somebody gains physical access to your computer, my computer gets stolen, my laptop gets stolen, they happen to log into my laptop and gain access to my offline, you know, password manager, they have everything.
So I'm, I'm kind of in the middle when it comes to using a password manager. This may come as a shock to you, but people are actually sharing passwords even today, and whether it's to access Netflix or just 'cause the DevOps team doesn't want to be bothered learning a new password, there's one password for all. Um, do we kind of become our worst enemies when we start sharing passwords?
I, I, I believe so. So, um, I, I see it happening a lot when, uh, organizations have, uh, shared computers or, or limited resources, so users will share that same password to log into the computer. Uh, some organizations businesses will do the same thing, even with their QuickBooks logins.
You know, they'll start sharing the QuickBooks online logins with other employees just to save a little bit of money on, on adding an additional user. Um, and, and I think a lot of times it, it boils down, uh, for businesses and organizations to money. So, uh, it may cost, you know, 10, $15 more to, to add another user.
Um, so they rather just share that password and, and we see the same thing, you know, with Netflix and Hulu, it just costs money to, to add another account. So what's your best advice to folks? Are there a set of best practices or things that they should be thinking about here?
And, um, do those things get ranked in some way that, uh, makes it easier to implement? So the best practice that, that I can recommend is to have multi-factor authentication. Um, and recently, you know, with the, uh, with the at and t breach with the call and text log, I, I used to say, you know, uh, SMS is fine.
However, with that attack, it's concerning because now attackers can see, uh, the short codes that you received, the password or the, the two factors from, so they can imitate, uh, that particular website and, and, you know, try to get you to give your code in that method. Uh, just by looking at those text logs, uh, they can identify, you know, what service you're using. So, um, I would recommend an, uh, a software based authenticator, uh, on your phone and an app versus a text-based authenticator.
Uh, for the moment, It also seems to me that the cyber criminals are getting a little more, shall we say cheeky in that they steal the password and then they log in and quote unquote live off the land and they act like they're part of the company and they, you know, generally helpful when it comes to facilitating a workflow that they're trying to learn about, and then, then they turn around one day and start dropping malware left, right and center. But, um, it doesn't, it feels to me like, you know, the days of smash and grab may be going going bye-Bye. I agree.
So I recently re recovered, uh, one company, one organization that, uh, uh, user had or password leaked on, uh, one of the popular password breaches. Uh, somebody logged into their account, they set on the account collecting emails for about two months. They were looking at the type of emails that were being sent out, and this individual was actually working in accounts receivable.
So, uh, they saw the invoices that were being sent out, different clients, uh, basically calculating what this individual does, and they were able to imitate that user to a legit client of theirs, uh, request that the, uh, bank account be updated. And they actually got $97,000 out of this other company to be sent to the wrong, uh, wire transfer, um, all before the other individual, the other, uh, the main company even knew it. So basically they were deleting their emails outta the send inbox, they were deleting it outta the deleted items, and nobody even knew that it had happened until several weeks later.
Ys, who should be held accountable when things go wrong with passwords? Is it the individual end user, or have we reached a point where, um, it's just too easy to steal? So even the most sophisticated end users are gonna get scammed by all this.
So, um, you know, we can't really hold them accountable no matter how much quote unquote training we can. Right? Yeah, that, that's a good question because, you know, we, we give all types of, of training, cybersecurity training to all of our employees organizations, but, um, I, I've seen even seasoned cyber professionals fall victim to a good phishing campaign in the email.
Um, so it, it's tough. I, I think the end user does bear some of the responsibility to make sure that they are doing what they can, uh, as far as having that multifactor authentication and, and not reusing that password. Uh, but it also is, is a little bit on that organization and that company, because if they don't have good password, uh, policies in place, such as brute force checking or, uh, something similar like what we mentioned a minute ago, checking those top databases for that password, that hash, um, I, I think they could share the responsibility in that case.
I don't know, speaking of, you talked about training, uh, bring you back to a pet peeve of mine, but it seems like the training cybersecurity is about as exciting as going to traffic school. So, um, do we need to fix that so that people are more engaged than they actually remember and learn? Because part of the issue, I think is, um, end users, much like the companies they work for are just trying to check a compliance box, Right?
And I think that that's what it is. It's mostly most people that are doing their cyber training nowadays, they just click through it. Um, you know, there, there's no checks to make sure they actually did it.
They're just clicking through it. Um, one way that I found an organizations is actually having a phishing simulation, uh, test. So, uh, that has been very productive, basically sending out, uh, simulated phishing emails, seeing who clicks those links, who opens those attachments, um, and then actually, you know, delivering, hey, you know, if this would've been a bad email, uh, this is what would've happened to you.
Uh, I feel like that has been very effective in most organizations. Um, and they actually learn something from it. Um, having quarterly, uh, phishing simulation tests, uh, in addition to, of course, still doing the cyber training, but for those people that actually click those links, uh, having more training, uh, that has been effective for, for most organizations that have asked me that same question.
In the way to Covid too, it seems like we're all using more applications than ever, particularly SaaS applications, and they each come with their own unique set of passwords. Do we just have too many platforms in play that 'cause each one of them is something that somebody can just hack into? I agree.
Um, you know, we use, uh, there's an application for everything. Um, I, I like the idea, you know, of of being able to log in with, you know, your Google account to multiple websites. So single sign-on, uh, you know, that that has been a, a thing that's been becoming more popular.
So organizations are helping with especially business applications inside their organization with the single sign on. Um, that is helpful. But at the same time, if an attacker gets a, a, a password that has single sign on enabled to multiple accounts, then you've still given them access to everything, uh, with that single sign on.
So I, I see it as a double edged sword. All right, folks. Well, if you work for an organization where that thin line between you and total chaos is a password, you're probably begging for trouble.
So take a minute, think about, hey, is there some other way to do this in a way that people will accept? 'cause I think the art of the thing is everybody wants better security. They just don't want to be inconvenienced to get it.
Hey, Dimitri, thanks for being on the show. Yes, sir. Thank you for having me.
All right. And back to you guys in the studio.