What 'Have I been Pwned?' taught DHS’s internal cyber chief about passwords
Full article627 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
"I get emails from this website on a monthly or basis,” DHS CISO Paul Beckman said Tuesday.
A website that informs users if their email address has been swept up in a data breach isn’t just popular with vigilant business owners or private security sleuths. The man charged with protecting the Department of Homeland Security’s systems from hackers also maintains an account on the “Have I been Pwned?” website, and it regularly reminds him of the risks passwords pose.
“I get emails from this website…on a monthly or bimonthly basis,” DHS CISO Paul Beckman said Tuesday at the Zero Trust Security Summit presented by Duo and produced by FedScoop and CyberScoop. “That is how often my username and password is getting compromised.”
Beckman said he registered both his personal and DHS email addresses on the website. The good news for him is that he uses a “second factor” — something like a SMS message or an authentication app — to log into his accounts and keep hackers out of them.
The anecdote shows the security mess that, some security professionals argue, passwords have wrought, and how one more layer of verification can be a saving grace.
Because computer users the world over are guilty of reusing passwords, hackers will often use credentials stolen from one account to unlock another. Making it easier for people to log in with unique credentials can go a long way toward cutting down on breaches, security analysts say.
“We need to get to a better way to consolidate that and make it easier to manage our credentials,” Beckman said.
Beckman, of course, isn’t the first to urge agencies to, at a minimum, adopt multi-factor authentication to help secure their systems. Last February, the General Services Administration began requiring administers of .gov domains to use two-factor authentication. For some agencies, the bar began pretty low: a 2018 assessment from GSA found that the State Department had enhanced security controls, including multi-factor authentication, on just 11 percent of required agency devices.
Awareness of multi-factor authentication’s importance within the federal government has grown in the year since the GSA directive. But standards like WebAuthn and FIDO2, which allow users to easily authenticate to services on their mobile and laptop devices, hold even more promise for security.
“It is things like WebAuthn and FIDO2 that I do believe are going to be the future,” Beckman said.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/dhs-passwords-zero-trust-duo/