10 ms·
German university issues 38k passwords by hand after malware infection
- plumeria 7y agoWhy no simply reset the passwords and enforce 2FA?
- pc86 7y agoIt's in the article.
- theandrewbailey 7y agoIt would violate a (stupid) law.
- ashildr 7y agono, it has nothing to do with a “stupid” law, it seems to me the article is misleading. It has to do with being a trusted source of identity information and fscking up very thoroughly: The university of Giessen is providing it’s members identity services for the DFN Network (German Research Network) with a high degree of reliance called _advanced_. This degree requires that „for identification, users must present themselves in person with an official ID. The enrolment and recruitment procedures established by the universities are considered as equivalent.“ ( see https://doku.tid.dfn.de/en:degrees_of_reliance https://doku.tid.dfn.de/en:degrees_of_reliance ) It seems to me that this university’s services are a very interesting target.
- imInGoodCompany 7y agoWhat you write is true, but generally the support and use of electronic identification in Germany is very poor, partially a result of complex and (at times) overly restrictive legislation. Especially compared to the Nordic countries where people use some sort of eID for practically everything. I have no stats on hand for this, but my work is in developing integrations towards major eID providers in Europe.
- Tomte 7y agoI've had an Estonian e-Residency card. I had to pick it up at an Estonian police station and show my official government ID. I don't see why a German university demanding the same for a comparable cryptographic certificate is bad.
- angry_octet 7y agoGiven the inevitable slow and steady loss of such credentials to adversaries, it seems like they need more than a single factor. Like, a backup password (on paper) that can be used to reset the account password, or similarly a TOTP seed (2D barcode). Otherwise rolling passwords becomes incredibly expensive. I'm almost surprised they haven't gone the same route as Estonia, but there are lots of federated systems so it might just be inertia.
- Tomte 7y agoI love what Estonia is doing, but we need to keep in mind that (a) Estonia is a very young country, so they could start from scratch (b) Estonia has very few citizens. At a guided tour in Tallinn the guide said that many of us came from cities more populous than their country. :-) (c) Estonia is more... adventurous in some regards. They have a National DNA Database, for example. Try selling that in the country of the Gestapo and the Stasi. (d) But first and foremost, it is great that there is a smallish country experimenting with all kinds of new stuff. The rest of Europe will benefit a lot, just by watching them and picking some of the things they already implemented and tested.
- angry_octet 7y agoI ought to have googled! Of course they have an electronic ID card project, they have just been testing it from 2006-2010 and slowly issuing it since 2010 with 'turn on' in 2017 with a goal of 2020. The Gemalto overview is fantastic: https://www.gemalto.com/govt/inspired/eid-in-germany https://www.gemalto.com/govt/inspired/eid-in-germany https://www.bsi.bund.de/EN/Topics/ElectrIDDocuments/German-eID/german-eID_node.html https://www.bsi.bund.de/EN/Topics/ElectrIDDocuments/German-e... Edit: trying to submit the Gemalto Dec 2019 update as a new story but I seem to be banned from submitting stories. Merry xmas HN.
- 0b0001 7y agoThe university website mentions student ID cards with chip. Is that not sufficient to provide strong authentication towards a self-service portal for password reset?
- ashildr 7y agoWe have no real information on the systems targeted or the vector(s), so it’s possible that JLU is currently carefully running a black start scenario. It is possible that even if the ID cards or something else could be used as a factor, what we don’t know, systems or certificates vouching for the student ID cards are now considered not trusted. This now seems like a painful but responsible way to hand out new credentials. While a lot more information would be interesting, I gather the sysadmins involved have to priotitize as they are right now. I hope that there will be an interesting post mortem, though.
- datenwolf 7y ago> The university website mentions student ID cards with chip. Is that not sufficient to provide strong authentication towards a self-service portal for password reset? In theory it should be sufficient. In practice there is very little awareness of the capabilities of these smartcards and that they could, in theory, be used as a 2FA token. These cards are mostly used for physical access control, library pass and cafeteria payment. There's left a lot to be desired in most (german) university networks. Yes, there is usually some sort of Radius and 801.1X infrastructure in place, but it's only used for WiFi login and eduroam, not for machines plugged into wall sockets. Yes, there usually is some sort of Active Directory and/or Kerberos infrastructure in place (yes, I am aware that AD is essentially LDAP + Kerberos), but it's often used only for the student computer pools, but not office workstations. There seems to be zero awareness, that if you have AD and/or Kerberos authentication working in place (one can only dream of it being coupled to the student / staff smartcards), you can use it GSSAPI for web single sign-on which would instantly neuter any attempts of phishing. Also you will still often find the preconception of there being such a thing as a "secure network" and an "insecure, hostile" internet. The notion of lateral movement and treating every network segment as insecure, no matter where or how it's managed in your org, is more or less nonexisting.
- ga-vu 7y agoIt's a university email, not Pentagon backend accounts. It is a stupid law because they're being way too thorough and abrasive when they shouldn't. How much do you wanna bet the German parliament is not protected in the same way... actually don't answer that... here's an article published today about a stupid vulnerability in the Bundestag's internal chat app: https://zero.bs/osintrecon-vs-pentestschwachstellenscan.html https://zero.bs/osintrecon-vs-pentestschwachstellenscan.html
- kaybe 7y agoDepending on the permissions on the accounts they can be pretty powerful. Not just access to eduroam (which all of them have and which is extremely convenient) and full course records including results (also from teacher side!) but also access to many resources such as supercomputer clusters, scientific literature behind paywalls, software licenses (also for expensive things) and many more. Note that institutions such as ESA, CERN or the local space agencies are also involved in the network. There absolutely are very interesting targets, even if you are a state actor.
- pro_zac 7y ago"As an added precaution, the university computing center decided to issue new passwords for all 38,000 JLU email accounts. However, the university was unable to do this online because of a quirk of German law, whereby the German National Research and Education Network (DFN) requires, in this case, JLU students and staff to obtain their new passwords in person from the university's IT staff, using as ID card to prove their identity."
- SamuelAdams 7y agoI'm curious to know what law this is and why other organizations in Germany do not have to resort to a similar tactic to reset passwords.
- ryacko 7y agoPossible it has to do with cards that can be used for purchases, though usually schools in America have a photo on file. Something is being miscommunicated probably.
- wongarsu 7y agoI think this might be a misquote. DNF is a registered association/charity which is providing network services for universities and research facilities (originally German, but spreading across Europe and beyond). They are the ISP of most German Universities, and more relevant to the topic they operate Eduroam, a wifi where any student or staff member can access their internet using their login credentials (username/password login via WPA 2 Enterprise). It's really handy because even if you are at another university you can still access the wifi, and any misuse (==people getting sued for torrenting) is easy to track. As such it stands to reason that they set rules for how credentials used to authenticate to their wifi are handled. And basically always those are the credentials for your university account. tl;dr: almost certainly not a law, but rules most Universities have to abide to if they want to keep their ISP and wifi.
- TazeTSchnitzel 7y agoMaybe a contractual provision they're legally bound by but which isn't itself a law?
- iforgotpassword 7y agoSo they're just running some av software from a live system on all systems and call it a day.... Dec 8th has been a while and there's no information around which malware this actually was. If it's really a targeted attack with some previously unknown malware, I wouldn't really feel like that's sufficient. Most companies have policies that require a full reinstall of infected systems or even just go ahead and replace the physical machine.
- mimischi 7y agoI would bet my money on a lack of funding. The IT at other universities in Germany are completely understaffed. They are probably working hard, but its only a few people?
- ozim 7y agoMost companies you know... For IT systems it is quite easy if you have money required. For OT-operational technology, I just got to know they keep infected machines running, they wall those off. Because you cannot just replace physical machine that is running some complicated chemical process just like that. Some factories also do not have money to replace some Win XP or they cannot replace Win XP because all the drivers for specific hardware are not working on new stuff. Life time of systems in OT is 20 years not like IT 5 years.
- deleted 7y ago[deleted]
- ptah 7y agotypically, better security practices tend to lead to more discomfort for users
- ChrisSD 7y agoThat's not entirely true. Adding too much discomfort to users reduces security by encouraging people to workaround or otherwise undermine the system. Many of the best security practices ideally make doing the secure thing easy. When this is not possible you have to try to at least limit the discomfort caused and make it resistant to subversion by even trusted individuals.
- StavrosK 7y agoDoes anyone know whether password+key is a supported WebAuthn use case? I don't mean whether the standard supports it (it does), but whether it's planned. I would love to use my Yubikey + PIN to log in to sites passwordlessly, but it seems that so far the only thing that anyone uses WebAuthn for is as a second factor.
- acheron9383 7y agoMicrosoft has been making some progress on this front, allowing the use of only a security key to log in. https://www.yubico.com/solutions/passwordless/ https://www.yubico.com/solutions/passwordless/
- StavrosK 7y agoVery interesting, they do use WebAuthn passwordlessly. I'll see if I can try it out, thanks! Here's the whitepaper, if anyone is interested (the download form was broken): https://www.yubico.com/wp-content/uploads/2018/11/going-passwordless-wp-final-2.pdf https://www.yubico.com/wp-content/uploads/2018/11/going-pass...
- tialaramex 7y agohttps://www.passwordless.dev/usernameless https://www.passwordless.dev/usernameless lets you try this flow out but I'd be surprised to see any significant adoption for the Web generally unless FIDO itself takes off first, because FIDO2 capable devices are more expensive. I can't justify telling people to pay extra when the core feature is not yet widely used.
- StavrosK 7y agoThanks, that's very useful! I've been trying for ages to get my Yubikey to ask me for my PIN that I've set on it when authenticating, to no avail. It doesn't seem reasonable to have a site authenticate me with no PIN, since someone could just steal my yubikey and log in as me everywhere. Would anyone happen to know how I can force asking for a PIN?
- myself248 7y agoHonestly, I think this is pretty smart. If someone has compromised your electronic systems, they can probably solve whatever electronic recovery means you've implemented, and they can probably do so on a large scale, re-compromising all the new accounts. Adding an in-person step makes things harder for the attackers in two ways: 1: It relies on existing ID cards, which presumably the attackers can't telekinetically change while they sit in people's pockets or something. 2: It's hard to attack at scale. Conceivably someone could make a fake ID and pose as a staff member or something, but the same person wouldn't get away with that more than a few times before someone in the office noticed that they looked familiar. And it's slow -- humans work at a finite speed, so brute-forcing 38,000 visits to an office isn't as practical as spawning a bunch of threads to attack login sessions or something. I think despite the inconvenience, this is a sane way to respond to a compromise, if your users are local and can visit an office to pull it off. At a major automaker who I won't name, they have an interesting way of handling password resets: They generate a new random password for you, and send half of it by SMS to the mobile phone in your employee record. Then they email the other half to your manager. Managers have instructions that when an employee calls to retrieve this (or if the manager has a moment to call the employee first), they should spend a moment in conversation first, really make sure they recognize the employee's voice and stuff, and if there's any doubt, ask them to meet at the personnel building badging office, where the administrative folk can check IDs and stuff. It works pretty well -- it would be _very_ hard to attack this system, especially at scale.
- cesarb 7y ago> It's hard to attack at scale. Conceivably someone could make a fake ID The "make a fake ID" step by itself is already hard. The identity card is not just a piece of paper. Take a look at https://en.wikipedia.org/wiki/German_identity_card#Security_features https://en.wikipedia.org/wiki/German_identity_card#Security_... to see how many anti-counterfeiting features it has.
- iancarroll 7y agoNearly every feature in that list, save for maybe security strands, is commoditized and mass-produced in the USA's fake ID market. It would be kind of silly to exploit here, though.
- duxup 7y agoIs there any more detail on this "quirk of German law" really is?
- fh973 7y agoI think it is just policy of the German Research Network (DFN) for accounts. These accounts are valid Europe-wide for WLAN access in educational institutions for example.
- duxup 7y agoThat's kinda how it reads. I didn't think of that as "law" and that is what sort of piqued my interest, that there would be a law about this specifically.
- kaybe 7y agoThey also work in some airports, as I've been happy to discover. (Mainly Scandinavia, though it appears to be at other locations as well.)
- PeterStuer 7y agoThing is as far as I can Google they have not identified how the network got compromised in the first place? So they are issuing bootable USB sticks for scanning computers and manually providing new email (I guess University account) passwords, but how would that prevent the same thing happening again in the same unpatched way next week?
- darkhorn 7y agoI thought that this is always the case. At METU when you register to the university they give you password by hand (printed inside of a letter). In case your account is compromised they block your account and you have to go to the computer center so that they give you a new password. There is no "I forgot my password" button. It is like this for at least from early 2000s. Probably from 1990s.
- thalassos 7y agoSomehow with my german bank account I undergo through the same process. If I happen to fail the online banking password 3 times, I must go in person to the bank to unlock my account.
- acd 7y agoBeen in a similar password reset situation at a university and it’s pain! I hope they implement 2fa two factor authentication since that will stop between 70-99% of password attacks.
- franek 7y agoI'm a student at that university, though I don't have any contacts to the IT department or other sources of inside information. I went to collect my new password already. The process was pretty smooth with only a little confusion where the queue split up alphabetically (not quite enough room, although it took place in a large gym; I guess they rightly prioritized giving the people behind the desks enough room to work). It's interesting to see which systems of the university are more or less robust to the network blackout. Email is down, which has the nice side effect that people who would otherwise only communicate in written form now make calls or physical visits (as they cannot look up phone numbers on the web) to each others' offices. The library catalogue is not working, though apparently they successfully switched to a paper-based system for lending books after a few days (haven't tried it yet). The electronic payment system of the canteens appears completely unaffected. (I read on a sign recently that it is considered "obsolete" and subject to renewal – good thing they hadn't done that yet, I guess). The web platform with reading material for seminars is down. In some cases seminar presentations have to be given without slideshow projection because the designated presentation laptop got a red sticker. I don't now how labs with data on the central servers are doing (I'm in the humanities).
- slynn12 7y agoYou can't hack pen and paper :) - I don't hate it.