jQuery

elevateZoom (Requires jQuery)

Microsoft Store (Donation)


Facebook Messenger (Donation)


Many donors of this blog prefer to donate their money through Facebook Messenger!

Click here to go to this blog's Facebook Page!

Thank you!

Activation Code - Donation (Multiple Options)



Donate

Request Web\PHP\JavaScript\HTML Project !

Contact us if you want us to develop a Web\PHP\JavaScript\HTML project for you!

Advertise On This Blog!

If you want a Product\Service\Event to be advertised on this blog, feel free to contact us!

Ads (Reserved)

Showing posts with label InfoSec. Show all posts
Showing posts with label InfoSec. Show all posts

Thursday, September 15, 2022

[JavaScript] Random Codes Generator! (Function)








www.StraightTips.blogspot.com


Length =

Random_Code(Function) v1.0: Test code below (Click here)



Thursday, August 25, 2022

Online Text Crypter - Encrypt\Decrypt Messages In Real Time!







"Cryption Key" can either be Password, Passphrase, Passcode, etc!









Friday, March 11, 2022

Oops, Tom Cruise Was Caught!!!


Well, one thing to learn from this "Craziest Drug Bust Ever" is that "Biometrics are identity, not security" (Twitter: @dragonshardz)!

That's why password managers like "JEMPass" must be avoided at all costs!

Another reason to avoid password managers like "JEMPass" is that, you can't change your finger, eyes or face if your biometric data get stolen or breached!

Yes, password managers like JEMPass are The Worst!

As an alternative to JEMPass, we recommend "Multi One Password", a "Real" and "The Most Secure Password Manager" because it does not store passwords neither locally in the users devices nor in the cloud! (Click here!)


Saturday, October 30, 2021

The Best Protection For Your Email Account!


Believe it or not, the best protection for your email account is to not make its "main email address" public by any means, only you should know about its existence!

The "main email address" should be used only to login into your email account, never share it with nobody, never use it to sign up or create accounts in websites, etc!

In the other hand, create 1 or multiple "alias email address\es" in your email account and use it\them to share with people, sign up or create accounts in websites, etc!

Finally, always make sure that none of your "alias email addresses" have the permission to login into your email account!

That's it! If hackers don´t know the door to your email account, so they can't try any keys!



Friday, May 21, 2021

"Password + Passcode" Login! (Passcode-Factor Authentication)


Password Reuse is proving to be a real and a big security problem these days, which is already forcing a lot of websites to implement ridiculous 2FA\MFA security measures! Two-factor or Multi-factor Authentication is a Waste of Time! (Click here to know more!)

The current way 2FA\MFA is being implemented is not the solution for Password Reuse, it's just another problem!

The solution for Password Reuse should\must be simple, practical and safe, thus, we propose a "Passcode-Factor Authentication" (PFA) solution, which would require "Password + Passcode" for users to login into their accounts!

What would be this "Passcode-Factor Authentication"?

Well, password is something that the user can choose, the user chooses whatever password he\she wants, weak, strong, random, reused, etc!

In the other hand, passcode would be something that the user can't choose, it should\must be a "Strong Long Random Code" generated by the website itself!

Then, both "Password + Passcode" would be required for users to login into their accounts, to change account settings, etc!

With this "Passcode-Factor Authentication" implemented, a Website should\must recommend its users to store the passcodes into a password manager!

The website should also recommend its users to use "Strong Long Random Passwords" by using their password manager's password generator and to never reuse passwords! (Strong Long Random Password + Strong Long Random Code = Hackproof)

This way, "Passcode-Factor Authentication" would prevent hackers to login into users accounts with reused passwords found in other websites data breaches!

Almost all accounts are hacked because of Password Reuse, thus, a simple solution like "Passcode-Factor Authentication" would be enough! Proposed solutions like 2FA Authenticator apps with 30 seconds input limit are neither simple, practical nor safe solutions, so almost all people will keep rejecting them!

2FA\MFA solutions that force people to be chained\dependent to emails, sms, authenticator apps\devices, etc, should\must be avoided at all cost!




Saturday, May 1, 2021

Two-factor or Multi-factor Authentication is a Waste of Time!

The image above basically says it all, Two-factor or Multi-factor Authentication is just a Waste of Time!

Instead of complicating and wasting time with 2, 3, 4, 1000, Multi or Infinite-factor Authentication, we must keep things as simple as possible, we need to make a strong and secure "One-factor Authentication", or, 1FA, if you prefer!

In order to use a strong and secure "One-factor Authentication" (1FA), you just need to use a real password manager like Multi One Password (Click here), a password manager that does not store passwords neither locally in the users devices nor in the cloud! (Note that, almost all password managers available out there are not really password managers, they are Note managers!)

Saying that, let's go back to Two-factor or Multi-factor Authentication, some big companies, like Google for example, are trying to make them standard since 2009 or 2010, but still almost all people refuse to use them because they bring too much unnecessary problems and headaches, and they are absolutely right for not using them!

As already said above, these big companies have been putting big money in 2FA/MFA since 2009/2010, now they want "Return on Investment" (ROI), so they want to force 2FA/MFA on everybody, even though 2FA/MFA is proving to be a Waste of Time and a Big Failure!

2FA/MFA is not the answer! If hackers can steal your passwords, they can steal your 2FA/MFA information as well!

There are a lot of people living nightmares because they decided to use 2FA/MFA, and now they regret for doing it so!

2FA/MFA makes use of backup codes! Backup codes can either be stolen or breached, thus, 2FA/MFA is just an extra headache that causes a lot of unnecessary problems!

If hackers ask you for your passwords and you give them your passwords, they will also ask you for your 2FA/MFA backup codes and you will give them the backup codes!

If Passwords can be breached from servers, 2FA/MFA backup codes can also be breached from servers!

If a data breach from a server contains passwords, it will certainly contain 2FA/MFA backup codes as well!

A data breach can also contain active-sessions, active-logged-in-devices, etc data, and hackers can use them to bypass 2FA\MFA as well!

If you use public wifi\wired networks with some frequency, hackers could easily intercept the data your devices send\receive in the network (cookies, active-session, etc) and use that data to bypass 2FA\MFA! (Especially public wifi networks that don't require passwords to access)

Websites decide if backup codes are used or not, and almost all of them use backup codes for their 2FA/MFA implementation, and if they don't, pray to GODS to never lose your 2FA/MFA devices or physical keys, because if you do, well, you must prepare yourself to live Nightmares after Nightmares, being locked from your accounts for 1, 2, 3 or even more months/years, and like in many cases, For Ever!

"Passcode-Factor Authentication", a Perfect Solution for Password Reuse! (Click Here)





Tuesday, October 13, 2020

Browser Encryption Based On Browser's Unique Id

First of all, this is not about preventing cookie stealing, this is about making cookie stealing useless! (Stolen cookies will have no use at all!)

For secure purpose, browsers need an encryption option based on browser's Unique Id, see the demonstration below and comment what you think about it:

- Every time at browser execution, an "Unique String Hash Id" is generated based on the browser "compilation random code" and several system info! (Compile_Random_Code + OS name + user name + browser name + devices mac address + etc + ...)

- The above "Unique String Hash Id" will be used for many situations, cookies encryption, for example. Before sending an encrypted cookie to the server, the browser must decrypt it first with the "Unique String Hash Id"

- Since every browser have a different "Unique String Hash Id", it means that if encrypted cookies from one browser are stolen and are about to be used in another browser, they will not work because the decryption key will be different than the encryption key.

Note that, it will not even be necessary to send the browser "Unique String Hash Id" to the server because all the encryption\decryption process occurs in the browser itself.

The browser "Unique String Hash Id" can be used to encrypt and store important returned values from server in javascript variables as well, and the values can only be decrypted while being sent back to the server.

The way "cookies, session id, local storage, etc" currently work are really not secure, what do you think?

Sunday, February 23, 2020

Iterations and Extra Salt - Multi One Password


First of all, hashed passwords generated with default random settings of "Multi One Password" tool can't be cracked without their correspondent settings neither in 2020 nor in the next zillion years!

Saying that, if hackers happen to have access to the users hashed passwords, in which is very unlikely because legit websites will probably re-hash the already pre-hashed passwords with bcrypt or other hash function, and their correspondent settings, in which is very unlikely as well because the settings are in the possession of their users only, the hashed passwords will still be extremely difficult to impossible to be cracked because of "Iterations" and "Extra Salt" parameters!

"Iterations" is basically the number of times that the computer is required to call and use the SHA512 hash function! The higher the iteration value, the more computational power and time is required for the hashed passwords to be generated\cracked!

"Multi One Password" tool uses by default 15000 to 16000 iterations required to generate the "Default_Extra_Salt", in which is a SHA512 hashed string based on "User_Unique_Password + Random Code (Salt)"!

SHA512 hashed strings are 128 characters long strings that contain only the 16 hex symbols! There are in total 16^128 SHA512 hashed strings!

16^128 = 1.340781e+154 = below

13407810000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000

So, hackers are basically forced to iterate 15000 to 16000 times for each guess in order to crack the hashed passwords, otherwise, they will be forced to iterate 16^128 times for each guess, in which makes the cracking of the hashed passwords really impossible!

So, why not using 16^128 instead 15000 to 16000 iterations? Because 16^128 would take your computer an eternity to generate the hashed passwords! In the other hand, 15000 to 16000 iterations take average computers 1 second to generate the hashed passwords!

Now, what is the "Extra Salt" parameter for?

Well, there will come a time, maybe in the next Big Bang, in which 16^128 iterations will not be enough!

"Extra Salts" are SHA512 hashed strings based on "Default_Extra_Salt + The Extra Salt Index Number"!

"Multi One Password" tool uses by default 0 "Extra salt"!

For 1 "Extra salt", hackers will be forced to iterate 2 x (16^128) times for each guess!
For 2 "Extra salt", hackers will be forced to iterate 3 x (16^128) times for each guess!
For 3 "Extra salt", hackers will be forced to iterate 4 x (16^128) times for each guess!
and so on ...!

Bcrypt (vs) Multi One Password! (Click Here)

CrackQ "Hundreds of Billions of Guesses per Second" is not a threat at all for "Multi One Password" tool! (Click here!)





Friday, February 21, 2020

Bcrypt (vs) Multi One Password

https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjlqk8YzfC2_A8OxmYQ-P3csqxHNTrB3kStw6GFJrhWMc6PRiRPghd1-c-NtDuA6jEq6sJ_f8LQR5cuhASwbku4cfeh3HlIxwQRNe1Q35cRALQP2p27c6y_dMxwSacMosac5MITFzsr_70/s1600/Terahash+-+448+x+GeForce+RTX+2080+GPUs+%2528Alphanumeric%2529.jpg
Click Image to Zoom

Terahash $1.4 Million configuration of 448 x GeForce RTX 2080 GPUs, take (1 Week + 5 Days = 1.714 Weeks) to crack length 10 SHA512 alphanumeric hashed passwords! (Click Here)

"Multi One Password" uses by default 15000 to 16000 iterations, so, it takes 1.714 x 15000 = 25710 weeks = 493 years (with Salt)!

"Multi One Password" 1.714 x 75000 iterations = 128550 weeks = 2465 years = 2.465 millennium (with Salt)

Without salt, it takes an eternity!

Note that, "Multi One Password" default 15000 to 16000 iteration values are very secure, but if you want it to be equivalent or even more secure than "bcrypt $2*$, Blowfish (Unix)", use 75000 or higher iteration values!

Multi One Password (Click Here!)

Iterations and Extra Salt - Multi One Password (Click Here)

CrackQ "Hundreds of Billions of Guesses per Second" is not a threat at all for "Multi One Password" tool! (Click here!)

#passwordmanager #Infosec #cybersecurity #netsec #hashcat #crackq



Thursday, January 30, 2020

Windows Must Hash Users Passwords More Securely!

Microsoft needs to step up its game in what concern hashing users passwords more securely!

First,
Windows must provide an "iteration" option!
(Users will choose the computational power and time required for their passwords to be hashed!)

Second,
Windows must provide a list of "Random Codes" at login, so users can use strategies like shown in the image below:


Note that, each installed Windows must provide an unique list with at least, lets say, 20k lines of random codes!

Know more about the image above! (Click Here)


Wednesday, December 18, 2019

VirusTotal - Report False Positives Contacts!

At this point, it's safe to say that VirusTotal is not reliable and not recommended anymore!

All VirusTotal does is misinform people with the False Positives detection Plague from all those antivirus aggregated in its website!

SentinelOne, Trapmine, CrowdStrike, Rising, McAfee-GW-Edition, BitDefender are the worst!

For example, SentinelOne even requires people to be their customers in order to be able to report False Positives detection! (Wow, that's Extortion!)

As an alternative, "Microsoft: Submit a file for malware analysis" is recommended!

After a file is submitted, the "Final Determination" is marked as "Pending"! After the file has been analyzed by Microsoft technicians, the "Final Determination" is marked as "Malware" or "Not Malware"!

Example here: Multi One Password (v1.4) - Microsoft "Final Determination"!

As you can see, there is no misinformation here at all!

VirusTotal should (or must) follow the same procedure as Microsoft!

ENGINE
Contact
360
Acronis
AegisLab
Agnitum
Ahnlab
Alibaba
Alyac (Estsoft)
Antivir
Antiy
Avast
AVG
Babable:
Baidu
BitDefender
Bkav
ByteHero
ClamAV
CleanMX
CMC
Comodo
CRDF
CrowdStrike
Cybereason
Cylance
CyRadar
Cyren
DNS8
DrWeb
eGambit (Tehtris)
Emsisoft
Endgame
ESET
F-Prot
F-Secure
FireEye
Forcepoint (websense)
Fortinet
GData
Hacksoft:
Hauri:
Ikarus
Invincea:
Jiangmin
K7
Kaspersky:
Kingsoft (Cheetah)
MAX (SaintSecurity)
MaxSecure
McAfee
McAfee-GW
Microsoft
Microworld
NANO
Norman
nProtect (Inca)
Palo Alto
Panda
Rising
Qihoo-360
QuickHeal
SecureAge Apex
Sentinel One
Sophos
Symantec
Tencent
TheHacker

Trapmine

TrendMicro
Webroot
Trustwave
VBA32
VirusDie
Yandex
Zillya
Zoner

ADS - Multi Share Calculator

https://windowsportableapps.blogspot.com/2019/03/multi-share-calculator.html