Better PHP Security Learning from Adobe
Bill Condo @mavrck Drupal Camp Ohio 2013 PHP Security: Adobe Hack
Learning from Adobe Bill Condo @mavrck PHP Security: Adobe Hack - - PowerPoint PPT Presentation
Better PHP Security Learning from Adobe Bill Condo @mavrck PHP Security: Adobe Hack Drupal Camp Ohio 2013 Quickly, about me Consultant Senior Engineer Developer Senior Developer Director of Tech Hosting Manager Support
Bill Condo @mavrck Drupal Camp Ohio 2013 PHP Security: Adobe Hack
Consultant Senior Engineer Developer Senior Developer Director of Tech Hosting Manager Support Tech
Bill Condo @mavrck Drupal Camp Ohio 2013 PHP Security: Adobe Hack
Lunne Marketing Group
Bill Condo @mavrck Drupal Camp Ohio 2013 PHP Security: Adobe Hack
Bill Condo @mavrck Drupal Camp Ohio 2013 PHP Security: Adobe Hack
accessed their network and all passwords have been reset. They believe 3 million accounts are included.
million, and with additional data (names, password hints, etc.), the total file size is 10GB.
Bill Condo @mavrck Drupal Camp Ohio 2013 PHP Security: Adobe Hack
was probably in error and what they really meant is that it was hashed... and the experts were wrong.
hints and encrypted password hashes. Additionally, credit card data was also accessed and is said to use similar encryption.
that the data is unsalted and likely uses 3DES.
private key, however it’s only a matter of time before it’s found.
Bill Condo @mavrck Drupal Camp Ohio 2013 PHP Security: Adobe Hack
passwords for other sites, and because Adobe uses emails for login, those will most likely match too. (Hello banking/Facebook/etc)?
Cloud customer and people who have purchased other products.
dataset for commonly used passwords than lists from Gawker and others.
Bill Condo @mavrck Drupal Camp Ohio 2013 PHP Security: Adobe Hack
everything else
Bill Condo @mavrck Drupal Camp Ohio 2013 PHP Security: Adobe Hack
Bill Condo @mavrck Drupal Camp Ohio 2013 PHP Security: Adobe Hack
Bill Condo @mavrck Drupal Camp Ohio 2013 PHP Security: Adobe Hack
Bill Condo @mavrck Drupal Camp Ohio 2013 PHP Security: Adobe Hack
Bill Condo @mavrck Drupal Camp Ohio 2013 PHP Security: Adobe Hack
Bill Condo @mavrck Drupal Camp Ohio 2013 PHP Security: Adobe Hack
Bill Condo @mavrck Drupal Camp Ohio 2013 PHP Security: Adobe Hack
Bill Condo @mavrck Drupal Camp Ohio 2013 PHP Security: Adobe Hack
Bill Condo @mavrck Drupal Camp Ohio 2013 PHP Security: Adobe Hack
Things that are fast.
Bill Condo @mavrck Drupal Camp Ohio 2013 PHP Security: Adobe Hack
Bill Condo @mavrck Drupal Camp Ohio 2013 PHP Security: Adobe Hack
Things that are slower.
Bill Condo @mavrck Drupal Camp Ohio 2013 PHP Security: Adobe Hack
Bill Condo @mavrck Drupal Camp Ohio 2013 PHP Security: Adobe Hack
$algo [, array $options ] )
string $hash )
twitter.com/ircmaxell blog.ircmaxell.com
Anthony Ferrara
Bill Condo @mavrck Drupal Camp Ohio 2013 PHP Security: Adobe Hack
Bill Condo @mavrck Drupal Camp Ohio 2013 PHP Security: Adobe Hack
user) that helps keep the password hashes different for users that have the same password.
may be the same value on ALL of the sites that you use.
Bill Condo @mavrck Drupal Camp Ohio 2013 PHP Security: Adobe Hack
Bill Condo @mavrck Drupal Camp Ohio 2013 PHP Security: Adobe Hack
‘123456’.
Bill Condo @mavrck Drupal Camp Ohio 2013 PHP Security: Adobe Hack
must by upper case” and “must end in a special character”. Allows masking.
for lower case, upper case, numeric, and special characters.
Bill Condo @mavrck Drupal Camp Ohio 2013 PHP Security: Adobe Hack
Bill Condo @mavrck Drupal Camp Ohio 2013 PHP Security: Adobe Hack
Bill Condo @mavrck Drupal Camp Ohio 2013 PHP Security: Adobe Hack
The opportunity cost is minimal compared the reduction in risk. Cost * Risk = Likelihood Cost
passwords, scan the servers, added support calls/ requests, etc…
Bill Condo @mavrck Drupal Camp Ohio 2013 PHP Security: Adobe Hack
minimize unexpected security response events.
Bill Condo @mavrck Drupal Camp Ohio 2013 PHP Security: Adobe Hack
user-level salt.
Bill Condo @mavrck Drupal Camp Ohio 2013 PHP Security: Adobe Hack
to talk about #drupalcampohio
Bill Condo @mavrck Drupal Camp Ohio 2013 PHP Security: Adobe Hack