Off Topic: Online Privacy News
Two news items that are off our main topic, but feed our obsession with online privacy:
1) Michelle Malkin blogs about how people are accidentally sharing more than their mp3s — using LimeWire, “within a few minutes, I had access to scores of tax returns that included names, addresses, social security numbers, and bank account numbers.” It seems people are either sharing their entire home or user directory, or saving their tax returns into a shared folder.
2) The Washington Post has an article today about how the Secret Service is breaking encryption on suspects files using a distributed network. Ordinarily, they would still have essentially no chance of decoding the contents, but:
Armed with the computing power provided by DNA (the distributed computing network) and a treasure trove of data about a suspect’s personal life and interests collected by field agents, Secret Service computer forensics experts often can discover encryption key passwords.In each case in which DNA is used, the Secret Service has plenty of “plaintext” or unencrypted data resident on the suspect’s computer hard drive that can provide important clues to that person’s password. When that data is fed into DNA, the system can create lists of words and phrases specific to the individual who owned the computer, lists that are used to try to crack the suspect’s password. DNA can glean word lists from documents and e-mails on the suspect’s PC, and can scour the suspect’s Web browser cache and extract words from Web sites that the individual may have frequented.
“If we’ve got a suspect and we know from looking at his computer that he likes motorcycle Web sites, for example, we can pull words down off of those sites and create a unique dictionary of passwords of motorcycle terms,” the Secret Service’s Lewis said.
Hansen said AccessData has learned through feedback with its customers in law enforcement that between 40 and 50 percent of the time investigators can crack an encryption key by creating word lists from content at sites listed in the suspect’s Internet browser log or Web site bookmarks.
“Most of the time this happens the password is some quirky word related to the suspect’s area of interests or hobbies,” Hansen said.
While we hope no reader has to be concerned about the Secret Service trying to decrypt their files, this points out the need to go beyond pet’s names and kid’s birthdays when you create your online passwords.
Similar Independent Sources posts:
- Weekend Edition: How Vulnerable Is Your Password?: This page estimates how long it would take different classes of computer to crack passwords based on a brute force generation of all possible combinat ...
- Double-Slaying Suspect David Ludwig “a really good guy”: Yahoo/AP: Double murder and kidnapping suspect, David Ludwig, is "a really good guy" according to friends. When not kidnapping 14-year old ...
- Weekend Edition: Fathers Won’t Like These Odds: Readily available DNA tests are revealing an interesting and possibly disturbing factoid: 1 in 25 men are bringing up children they mistakenly believe ...
- Congress to Accidentally Ban (Some) Teen Bloggers?: Kids and young teens won't be able to use school or library computers to access MySpace -- or much of anything else, if recently introduced legislatio ...
- Los Angeles Times To Intro Ad-Cluttered RSS Feeds: This morning L.A. Observed reported that the Los Angeles Times will launch a new online service, "Los Angeles Times Newspoint," in August. The company ...









