Passwords: Difference between revisions

Back up to the Configuring Category
From AAISP Support Site
mNo edit summary
mNo edit summary
(5 intermediate revisions by 2 users not shown)
Line 10: Line 10:
|-
|-
|
|
===About===
==About==
The DSL login is used to access the Control Pages as well as what you use in your DSL router to log in to the Internet. This uses the xxx@a or xxx@a.1 style username.
The DSL login is used to access the Control Pages as well as what you use in your DSL router to log in to the Internet. This uses the xxx@a or xxx@a.1 style username.


Line 17: Line 17:
As with the accounts password, the associated email is crucial and someone with access to the email could use a password change request to change the password and access the control pages. This then gives access to all of the other control pages passwords.
As with the accounts password, the associated email is crucial and someone with access to the email could use a password change request to change the password and access the control pages. This then gives access to all of the other control pages passwords.


===Notes===
==Notes==
*Staff cannot see the password you have picked, it is hashed internally.
*Staff cannot see the password you have picked, it is hashed internally.
*Staff cannot set a password for you, you have to use the password change process (described below).
*Staff cannot set a password for you, you have to use the password change process (described below).
*Staff are able to invalidate your password if you request, and you should advise staff if you think the password is compromised.
*Staff are able to invalidate your password if you request, and you should advise staff if you think the password is compromised.


===Changing Password===
==Changing Password==
A new password can be requested via: [https://control.aa.net.uk/newpass.cgi https://control.aa.net.uk/newpass.cgi]
A new password can be requested via: [https://control.aa.net.uk/newpass.cgi https://control.aa.net.uk/newpass.cgi]
*Enter in your email and login (Staff can send you a reset email manually if you ask them)
*Enter in your email and login (Staff can send you a reset email manually if you ask them)
Line 31: Line 31:


==Two factor authentication==
==Two factor authentication==
2FA is available, see https://www.aaisp.net.uk/kb-broadband-2fa.html
2FA is available, see below.


|}
|}
Line 38: Line 38:
|-
|-
|
|
===About===
==About==
The accounts system login and password are used to allow access to the accounts, statements, and invoices. This is a very important password as we trust that any orders placed with the correct account number and password are genuinely from you or your organisation, and more importantly, from someone that is authorised to spend money with us. This password can be used to order services as well as changing or ceasing existing services.
The accounts system login and password are used to allow access to the accounts, statements, and invoices. This is a very important password as we trust that any orders placed with the correct account number and password are genuinely from you or your organisation, and more importantly, from someone that is authorised to spend money with us. This password can be used to order services as well as changing or ceasing existing services.


Line 47: Line 47:
The username is your Account Reference - typically AnnnnA, where nnnn are numbers.
The username is your Account Reference - typically AnnnnA, where nnnn are numbers.


===Notes===
==Notes==
*Staff cannot see the password you have picked, it is hashed internally.
*Staff cannot see the password you have picked, it is hashed internally.
*Staff cannot set a password for you, you have to use the password change process (described below).
*Staff cannot set a password for you, you have to use the password change process (described below).
*Staff are able to invalidate your password if you request, and you should advise staff if you think the password is compromised.
*Staff are able to invalidate your password if you request, and you should advise staff if you think the password is compromised.


===Changing Password===
==Changing Password==
The password change process is used to set a password, and can be used if you have forgotten your password or simply want to change it. You can use the forgotten password link to request the password change email, or you can ask a member of staff to send it to you.
The password change process is used to set a password, and can be used if you have forgotten your password or simply want to change it. You can use the forgotten password link to request the password change email, or you can ask a member of staff to send it to you.


Line 63: Line 63:
#*We strongly recommend using the passwords we suggest as they are random and avoid any association with you or the account. You can, if you wish, enter your own password. If you want to do this, please ask staff and they will show you how. However, entering a password can lead to poor passwords, and password re-use which are not a good idea.
#*We strongly recommend using the passwords we suggest as they are random and avoid any association with you or the account. You can, if you wish, enter your own password. If you want to do this, please ask staff and they will show you how. However, entering a password can lead to poor passwords, and password re-use which are not a good idea.
#You will then get a second email confirming that the password has been changed. (The password is not included in the email)
#You will then get a second email confirming that the password has been changed. (The password is not included in the email)

==Two factor authentication==
2FA is available, see below


|}
|}
Line 73: Line 76:
The username used for a line is in the form of xx@a.n where n is the line number, typically 1 where there is just a single line. e.g.: abc@a.1
The username used for a line is in the form of xx@a.n where n is the line number, typically 1 where there is just a single line. e.g.: abc@a.1


===Notes===
==Notes==
*The password can be viewed on the control pages.
*The password can be viewed on the control pages.
*The password is printed and included on information packs and router information cards.
*The password is printed and included on information packs and router information cards.
*The password can be set as you wish, but a generate password button is provided for convenience.
*The password can be set as you wish, but a generate password button is provided for convenience.


===Changing Password===
==Changing Password==
#Log in to the control pages with your Control Page credentials
#Log in to the control pages with your Control Page credentials
#Click on the line you want to change the password of
#Click on the line you want to change the password of
Line 90: Line 93:
|-
|-
|
|
===About===
==About==
The username for email is your full email address.
The username for email is your full email address.


Whilst the email password, used for POP3, IMAP, and authenticated SMTP, may seem relatively low importance, it is not. Email systems are the underpinning of most security as explained above. Unauthorised access to email can allow people to change and access a range or other system's passwords. As such the email passwords have some security.
Whilst the email password, used for POP3, IMAP, and authenticated SMTP, may seem relatively low importance, it is not. Email systems are the underpinning of most security as explained above. Unauthorised access to email can allow people to change and access a range or other system's passwords. As such the email passwords have some security.


===Notes===
==Notes==
*Staff cannot see the password you have picked, it is hashed internally.
*Staff cannot see the password you have picked, it is hashed internally.
*Staff can set a different password for you, although we'd suggest that customers set this themselves.
*Staff can set a different password for you, although we'd suggest that customers set this themselves.
*When a Mailbox is deleted passwords hashes are removed within 24 hours.
*When a Mailbox is deleted passwords hashes are removed within 24 hours.


===Changing Password===
==Changing Password==
You can set an email password on the control pages, but we recommend using the generate password link to pick one randomly when you do this, for added security.
You can set an email password on the control pages, but we recommend using the generate password link to pick one randomly when you do this, for added security.


Line 115: Line 118:
|-
|-
|
|
===About===
==About==
In order to register a VoIP phone against our servers you'll need a password.
In order to register a VoIP phone against our servers you'll need a password.


VoIP passwords are considered to be slightly higher security because they can be used with equipment to make chargeable calls. However, the main attack for VoIP passwords is to compromise terminal equipment and either use it directly or access the password and login details it is using. Unfortunately the underling protocol prohibits hashing this password internally. However it is usual for only one device to be configed with each VoIP login, and so reasonable that the password is settable but not visible. We also have in place a number of precautions and warning systems to track if VoIP passwords have been compromised.
VoIP passwords are considered to be slightly higher security because they can be used with equipment to make chargeable calls. However, the main attack for VoIP passwords is to compromise terminal equipment and either use it directly or access the password and login details it is using. Unfortunately the underling protocol prohibits hashing this password internally. However it is usual for only one device to be configed with each VoIP login, and so reasonable that the password is settable but not visible. We also have in place a number of precautions and warning systems to track if VoIP passwords have been compromised.


===Notes===
==Notes==
*The password can be viewed on the control pages, but it is not hashed in our internal systems.
*The password can be viewed on the control pages, but it is not hashed in our internal systems.
*The password can be set as you wish, but a generate password button is provided for convenience.
*The password can be set as you wish, but a generate password button is provided for convenience.


===Changing Password===
==Changing Password==
Log in to the [http://aa.net.uk/login-clueless.html Control Pages] with your main xxx@a login, you'll see the list of numbers, click on the one in question, click on the Incoming tab, and set the password there.
Log in to the [http://aa.net.uk/login-clueless.html Control Pages] with your main xxx@a login, you'll see the list of numbers, click on the one in question, click on the Incoming tab, and set the password there.


Line 134: Line 137:
|-
|-
|
|
===About===
==About==
If we host your web pages, then you use FTP to transfer files to our servers. Web pages are not often targeted on our systems but can be a target for attack to display political or other messages. As such we consider this to be a slightly higher security.
If we host your web pages, then you use FTP to transfer files to our servers. Web pages are not often targeted on our systems but can be a target for attack to display political or other messages. As such we consider this to be a slightly higher security.


The username is the full domain, e.g. www.example.com
The username is the full domain, e.g. www.example.com


===Notes===
==Notes==
*Passwords are part of our DNS control pages
*Passwords are part of our DNS control pages
*Staff cannot see the password you have picked, it is hashed internally.
*Staff cannot see the password you have picked, it is hashed internally.
*Staff can set a different password for you, although we'd strongly suggest that customers set this themselves.
*Staff can set a different password for you, although we'd strongly suggest that customers set this themselves.


===Changing Password===
==Changing Password==
Log in to the [http://aa.net.uk/login-clueless.html Control Pages] with your main xxx@a login, click on the Domain in question, and edit the 'DNS Record' called Password.
Log in to the [http://aa.net.uk/login-clueless.html Control Pages] with your main xxx@a login, click on the Domain in question, and edit the 'DNS Record' called Password.


Line 152: Line 155:
|-
|-
|
|
===About===
==About==
If you have a router supplied by AAISP then the WiFi password will be printed on the card on the base of the router and can also be found in the [[Information Pack]].
If you have a router supplied by AAISP then the WiFi password will be printed on the card on the base of the router and can also be found in the [[Information Pack]].


The router WiFi password is considered relatively low priority. It is possible for someone to attempt to hack your WiFi, so we do suggest a good password, and the system will try to generate a reasonably memorable password with additional digits to provide extra entropy.
The router WiFi password is considered relatively low priority. It is possible for someone to attempt to hack your WiFi, so we do suggest a good password, and the system will try to generate a reasonably memorable password with additional digits to provide extra entropy.


===Notes===
==Notes==
*The password can be viewed on the control pages.
*The password can be viewed on the control pages.
*The password is printed and included on information packs and router information cards.
*The password is printed and included on information packs and router information cards.
*The password can be set as you wish, but a generate password button is provided for convenience.
*The password can be set as you wish, but a generate password button is provided for convenience.


===Changing Password===
==Changing Password==
There are 2 ways of changing the password:
There are 2 ways of changing the password:
#Log in the router and change the password
#Log in the router and change the password
Line 173: Line 176:
|-
|-
|
|
===About===
==About==
The router admin password is considered relatively low priority. It is rare for any directed router attack using a password. The password is included in the information pack and printed on router information cards to make it easy to access the router even when no Internet connection.
The router admin password is considered relatively low priority. It is rare for any directed router attack using a password. The password is included in the information pack and printed on router information cards to make it easy to access the router even when no Internet connection.


===Notes===
==Notes==
*The password can be viewed on the control pages.
*The password can be viewed on the control pages.
*The password is printed and included on information packs and router information cards.
*The password is printed and included on information packs and router information cards.
Line 184: Line 187:
|}
|}





== Two factor authentication information ==
We have an optional system of two factor authentication (2FA) on our accounts and control web pages.

=== What does that mean? ===

What this means is that, if you set it up, in addition to a simple username (or account number) and password, we will request a code from you. Without the correct code you cannot log in to the web site.

The way to get the code is using a mobile phone app, there are many, but Authy, or the Google Authenticator seems a perfectly good ones.

It is nothing to do with google and does not need any google login. There are many apps, and if you want a different one you are looking for one that does OATH/TOTP to RFC6238, ideally one that will read an otpauth:// URL on a QR 2D barcode for the seed.
=== How does it work? ===

When you ask to set up 2FA there is a simple process that involves a QR 2D barcode shown on the screen which you scan with the app, and you are ready to go. Some apps allow a PIN or fingerprint to be set up to protect seeing the code (the Google one does not). Once the app is open it shows a new code every 30 seconds on the screen. You can usually set up multiple different accounts on the app. You can set up the same code on multiple devices, and some apps manage backup and sharing between devices. You don't need mobile coverage or internet access on your phone for the code to be shown. It really is that simple!

When you log in, you use your username and password and then we may prompt for the code - you simple enter the 6 digit number from the app screen.
=== When is a code required? ===
When you set up 2FA on the accounts system we also have a trust setting which you can change. This controls when we will ask for the code during a normal log in to the accounts web site. There are different settings which control when and if we will ask for the code. The standard setting will not normally ask for a code if you are using your usual browser but you can set it up to ask every time if you want.

If you have set up a code, then we will always ask on our normal order pages for services like Broadband, Telephony (VoIP), SIM cards, and so on, regardless of the trust level set. There may be some services which do not yet ask but we are aiming to update these as needed.

On the control pages, once set up, we always ask for the 2FA code on every login.

We also email you when we see a new browser used to login, just in case this is someone trying to compromise your account.
=== Will staff ask for the code? ===

Yes, staff may ask for the code if you have set up 2FA on the accounts pages - remember it is not actually your password and it changes every 30 seconds. Staff can check the accounts 2FA code, and so asking for the code can be an important security check. Staff can also see the trust setting you have applied on the accounts system, and if you have selected the highest security (paranoid mode) then additional checks be required. This could be over the phone, or irc, or the web-chat, or twitter, or whatever. You can actually use this to test staff (e.g. if we called you), giving a wrong code to confirm we see it as wrong.

Also, if you are asking staff to handle an on-line order for you over the phone, etc, they will need your code to proceed with the order. If you have a dealer that places orders for you, he too will need your code to place an order. But all of this only applies if you have set up two factor authentication on the accounts system - if not, then the normal username and password are used as now.

Staff cannot check the 2FA code you have set on the control pages, and so will not ask for this.
Setting up...

Setting up the code is simple - log in as normal and you will see an option to set up 2FA. Simple follow the instructions.

https://www.youtube.com/watch?v=Jr-d0m9wgcc&feature=youtu.be

Note the process has changed slightly since this video was made.

=== Losing your mobile ===

We know things can go wrong, but if you have set up two factor authentication this indicates you are taking security seriously. You will have to convince staff you are who you claim to be, which will, in part, depend on the trust setting you have selected. Setting the lowest trust means you will not be able to get the code cleared or reset over the phone or email and may need a letter sent! However, if you have set a more conservative trust setting then staff may text you a code, or call you back on your number, etc. Bear in mind, texting your code is often no good if you actually have lost your mobile!

This does not impact the router login to your broadband line or VoIP services, etc, only the accounts and control web pages and ordering systems.
Changing password

Once 2FA is set up you will need to use it when changing password, and on our control pages you also need your old password. If you need your password reset, which will also reset the 2FA, you will need to contact a member of staff.


[[Category:Configuring]]
[[Category:Configuring]]

Revision as of 11:37, 2 October 2019

This page describes the various account logins and passwords that apply to our various systems. Different systems have different levels of password security depending on the requirements.

When changing passwords always be sure to use a secure password! Most of our systems have a 'Generate Password' button which you can use if you wish. The Information Pack contains some of your account details.

Click the 'Expand' link to view the details.



Two factor authentication information

We have an optional system of two factor authentication (2FA) on our accounts and control web pages.

What does that mean?

What this means is that, if you set it up, in addition to a simple username (or account number) and password, we will request a code from you. Without the correct code you cannot log in to the web site.

The way to get the code is using a mobile phone app, there are many, but Authy, or the Google Authenticator seems a perfectly good ones.

It is nothing to do with google and does not need any google login. There are many apps, and if you want a different one you are looking for one that does OATH/TOTP to RFC6238, ideally one that will read an otpauth:// URL on a QR 2D barcode for the seed.

How does it work?

When you ask to set up 2FA there is a simple process that involves a QR 2D barcode shown on the screen which you scan with the app, and you are ready to go. Some apps allow a PIN or fingerprint to be set up to protect seeing the code (the Google one does not). Once the app is open it shows a new code every 30 seconds on the screen. You can usually set up multiple different accounts on the app. You can set up the same code on multiple devices, and some apps manage backup and sharing between devices. You don't need mobile coverage or internet access on your phone for the code to be shown. It really is that simple!

When you log in, you use your username and password and then we may prompt for the code - you simple enter the 6 digit number from the app screen.

When is a code required?

When you set up 2FA on the accounts system we also have a trust setting which you can change. This controls when we will ask for the code during a normal log in to the accounts web site. There are different settings which control when and if we will ask for the code. The standard setting will not normally ask for a code if you are using your usual browser but you can set it up to ask every time if you want.

If you have set up a code, then we will always ask on our normal order pages for services like Broadband, Telephony (VoIP), SIM cards, and so on, regardless of the trust level set. There may be some services which do not yet ask but we are aiming to update these as needed.

On the control pages, once set up, we always ask for the 2FA code on every login.

We also email you when we see a new browser used to login, just in case this is someone trying to compromise your account.

Will staff ask for the code?

Yes, staff may ask for the code if you have set up 2FA on the accounts pages - remember it is not actually your password and it changes every 30 seconds. Staff can check the accounts 2FA code, and so asking for the code can be an important security check. Staff can also see the trust setting you have applied on the accounts system, and if you have selected the highest security (paranoid mode) then additional checks be required. This could be over the phone, or irc, or the web-chat, or twitter, or whatever. You can actually use this to test staff (e.g. if we called you), giving a wrong code to confirm we see it as wrong.

Also, if you are asking staff to handle an on-line order for you over the phone, etc, they will need your code to proceed with the order. If you have a dealer that places orders for you, he too will need your code to place an order. But all of this only applies if you have set up two factor authentication on the accounts system - if not, then the normal username and password are used as now.

Staff cannot check the 2FA code you have set on the control pages, and so will not ask for this. Setting up...

Setting up the code is simple - log in as normal and you will see an option to set up 2FA. Simple follow the instructions.

https://www.youtube.com/watch?v=Jr-d0m9wgcc&feature=youtu.be

Note the process has changed slightly since this video was made.

Losing your mobile

We know things can go wrong, but if you have set up two factor authentication this indicates you are taking security seriously. You will have to convince staff you are who you claim to be, which will, in part, depend on the trust setting you have selected. Setting the lowest trust means you will not be able to get the code cleared or reset over the phone or email and may need a letter sent! However, if you have set a more conservative trust setting then staff may text you a code, or call you back on your number, etc. Bear in mind, texting your code is often no good if you actually have lost your mobile!

This does not impact the router login to your broadband line or VoIP services, etc, only the accounts and control web pages and ordering systems. Changing password

Once 2FA is set up you will need to use it when changing password, and on our control pages you also need your old password. If you need your password reset, which will also reset the 2FA, you will need to contact a member of staff.