Those pesky complex passwords are more important than ever.
With reports of identity theft running rampant these days it's not shocking to hear about hackers getting into business servers and wreaking havoc with their data. You see it all the time in the movies with both the good guys and the bad guys. In fact, they make it look so easy. It only takes minutes to get into a highly secured government site. Even though the movies are mostly fantasy, it makes you wonder how safe your data really is.
New reports of "Chinese hackers" making co-ordinated and targeted attacks on systems are sending alert waves through overseas governments and international companies. McAfee, a leading computer security firm, has been tracking these hackers for a while, ever since they intruded on the systems of five major oil and gas firms to steal propriety information - some of them their clients.
Why is this important to you? A company just like yours using a Microsoft Dynamics product was attacked by Chinese Hackers. Getting in wasn't too hard. A user didn't log out of Terminal Server correctly. How did they get into the Dynamics product? They found a user name without a complex password. It was pretty simple to crack that password.
What's a complex password you ask? Well, for those of you who aren't forced to use one, you need to start using one. Basically, according to Microsoft, a complex password should meet the following guidelines:
- Should not contain any or part of the account name of the user.
- Should be at least eight characters long
- Contain three of the following four categories:
- uppercase characters
- lowercase characters
- base 10 digits (0 through 9)
- nonalphanumeric characters: ~!@#$%^&*_-+=`|\(){}[]:;"'<>,.?/
We all complain about that complex password (except that IT guy who forces it on us) and we especially complain when we have to change it every 45 to 90 days. But in today's world, it's necessary. I can see why hackers would want to tap into the big oil companies. But there isn't anything real special about the company mentioned earlier using Microsoft Dynamics that was attacked. They’re not a huge player in the banking industry or in the oil and gas business. They were just vulnerable.