Wednesday, December 19, 2007

Don't Trust the "Peek Squad"

Do you ever use the Geek Squad or drop-off your computer for repairs? How much do you trust the people who are doing the repairs?

In a recent news report, the Geek Squad found child pornography on a computer that was sent for repairs and the customer was turned over to the police. While a crime was committed in this case, don't assume that any of your data is safe when letting someone else look at your computer. Computer repair shops have been noted to steal all types of media (music, movies, photos, etc.) from computers entrusted to them and are known to some in cyberspace as the Peek Squad.

In this age of Identity Theft, anyone with physical access to your computer can easily log onto your online bank accounts or other financial institutions. If you use your web browser to store account ID and password information, a user can easily open your browser and log onto your web sites. The user can also download browser password-cracking tools so they can copy all of your ID and password information, even if you use a master password in Firefox to protect your password list.

A good way of combating this is to use an external password manager that integrates with your web browser. The password list is encrypted and protected by use of a master password. Password-cracking tools for the external password managers may be available, but are more difficult to find than the tools for cracking the web browser password managers. The external password managers automate form entry on multiple web browsers, similar to web browser password form automation. After installing the external password manager, it is recommended to disable web browser password functionality as it will now be available with the external tool. As an added benefit, an external password manager can also provide anti-keylogging and anti-phishing control.

Ensure you use solid password creation practices, making your passwords harder to crack. If you need to encrypt sensitive data, third-party encryption tools can also be used.


- - - -

References

The "Peek Squad"
http://www.schneier.com/blog/archives/2007/07/computer_repair_1.html
http://consumerist.com/consumer/geek-squad/were-always-looking-for-porn-on-customers-computers-techies-confirm-257309.php

Web Browser Password Manager Concerns
http://www.securityfocus.com/infocus/1882

Web Browser Password Recovery Tools
http://www.majorgeeks.com/SpotIE_Password_Recovery_d5662.html
http://www.tech-faq.com/internet-explorer-stored-password-recovery.shtml
http://www.darknet.org.uk/2006/06/firemaster-21-a-firefox-master-password-recovery-tool/

External Password Manager and Automation Tools
http://www.roboform.com/ (Windows)
http://1password.com (Mac)

How to Disable Web Browser Password Caching
http://support.microsoft.com/kb/229940 (IE)
http://www.mozilla.org/support/firefox/options

Anti-Keylogging and Anti-Phishing Control
http://www.roboform.com/anti-keylogger.html
http://www.roboform.com/anti-phish.html

Password Tips
http://www.buzzle.com/articles/computer-repair-cracking-passwords.html
http://www.firefoxtutor.com/61/securing-firefox-passwords/

Encryption Tools
http://na.pgpstore.com/product.aspx?sku=3118544
http://sectools.org/crypto.html

No comments: