By Ray Birch
CHICAGO—Skilled hackers only need a day to break into a CU, according to one security expert who shared one password he said he “knows” at least one person is using in every CU.
That’s why banks and credit unions should be moving staff to passwords that are 14-characters long, which makes it significantly tougher for a criminal to solve, asserts one security expert.
“With the computer power I have, I can break any eight-character password in 24 hours,” said David Anderson, a manager and information security consultant for CliftonAllenLarson. “Hackers have very strong computers, which means they can gain access to one employee’s computer, and within a day they are inside the credit union. I strongly recommend moving all of your users with eight-character passwords to 14 characters.”
Anderson made that recommendation during the 2016 NASCUS/CUNA Cybersecurity Symposium here, and when the audience of IT professionals got the news, it was clear by the group’s reaction that they thought the change could be challenging to implement.
“I know, said Anderson, noting that staff may push back. “But again, any Windows users should move to 14-character passwords now.”
Simple Mistakes Produce Problems
Anderson performs and provides project management for network penetration testing, internal vulnerability assessments, and social engineering engagements within a wide range of industries. He has firsthand knowledge and experience using leading edge hacking/testing methods, including in external and internal network penetration designed to gain access to high value targets. He shared other tips he has learned from years of penetration testing on companies and credit unions.
Anderson said that as concerns grow over the increasing sophistication of hacking techniques, often simple mistakes lead to the problems.
“I can tell you, there are some common things we see over and over again when we do our penetration testing,” said Anderson.
Anderson thinks many credit unions are doing a poor job of email filtering and blocking phishing attacks.
“Something that is not well known is that by default a majority of SPAM filters do not block crooks from impersonating a staff member and reaching out to employees. I can pick anyone in the organization, use their legitimate address, and send a message from them to other employees,” said Anderson, citing the rise in such scams. “You can’t just use email programs and SPAM filters out of the box. You have to do a lot of configuration. So look closely at your email and spam filter gateways.”
Another big issue: “Anything that touches remote users should require two-factor authentication,” stressed Anderson.
He said it is easy for hackers to construct proper email addresses for employees by gathering information from the company and social media.
“And then we have a list of employee names and we can try one password throughout the employee base—and all we have to do is get lucky once,” he said. “The first password I would try right now is ‘Summer2016.’ I guarantee there is one of your employees using that password.”
Password in hand, crooks can log in to webmail and gain VPN access.
“You cannot rely just on credentials for remote access,” he said. “You need that second factor, like a token.”
Anderson, too, is concerned about credit unions’ lack of filtering on the perimeter.
“Credit unions are blocking a lot of traffic coming to the organization, but they are not blocking a lot of the egress traffic,” he said. “You need to tighten down what users can go to.”
Tune Up Filters
He said web content filters do a good job of catching and blocking employees going to gambling and pornography sites, for example.
“But there is a dangerous category of sites out there that most credit unions are not blocking, and that is ‘unknown,’” said Anderson. “You need to look at blocking that category of sites.”
Turning back to passwords, Anderson said that staff cannot use shared passwords—passwords they use on their user accounts as well as on their personal accounts at home or on their mobile device. He said that is particularly important to stop for employees who have admin rights to the system.
“You can patch all you like within your system,” said Anderson. “But you can’t patch an end user. So educate your team. Train them on security best practices. Let them know why this is important. Your employees are not dumb, they will listen if you work with them.”
