Tagged: security Toggle Comment Threads | Keyboard Shortcuts

  • Geebo 9:02 am on August 9, 2017 Permalink | Reply
    Tags: Bill Burr, , security   

    Man who invented P@$$w0rd guidelines regrets it 

    Man who invented P@$$w0rd guidelines regrets it

    Anyone who has held a job that required a computer in the past decade and a half has been subjected to the tedious practice of having to change their password every 30 to 90 days. Then that password has to have an uppercase letter, a number, a symbol, an Egyptian hieroglyph, some ancient Sanskrit, your DNA sequence and that unpronounceable icon Prince used to use as his name. This came about thanks to one man. That man was Bill Burr, a former manager at the National Institute of Standards and Technology. He came up with these guidelines in 2003 in order to better protect government systems. These procedures spread out into the corporate world where they became gospel. Now the man behind the guidelines says not only does he regret these guidelines, but they are no longer effective.

    Now it’s believed shorter passwords with these restrictions are easier to crack than longer passwords that are simple phrases. For example, a password along the lines of “safecommunityclassifieds” is harder to crack than “G33b0c0m”. (BTW, neither of those are used by Geebo.) The problem is a lot of employers and online services require you to use the restrictive password guidelines from 14 years ago, however, you can still use your personal passphrase with just a modicum of alteration to fit those requirements.

    The other problem is the frequency in which some places require you to change your password. In a number of cases, users will alter their previous password by one digit or letter. If one of your old passwords were to be discovered and used one of these one character changes, it would be an easy matter to determine your current password.

    So again, it’s now recommend you use a passphrase to use as your password and you should only change it if there has been some kind of security breach. You can check the security of passwords at this website.

  • Geebo 11:31 am on February 28, 2017 Permalink | Reply
    Tags: cloudpets, , , security   

    Cloud connected child’s toy leads to personal data breach 

    Cloud connected child's toy leads to personal data breach

    As seen on TV toy CloudPets is actually a pretty clever concept. By using a smart phone app a traveling parent or a relative that lives far away can leave a voice message to a child on one of the stuffed animals.

    Except there’s that one inherent problem that affects any device connected to the cloud, there’s a chance that personal data stored there could be compromised. CloudPets seems to be having that problem currently as reports say that an insecure database led to third-parties accessing the personal information of many of their users. This information includes names and dates of birth. This is made doubly disturbing considering that a lot of this information belongs to children, not to mention that their voice messages could possibly have been stolen as well. Some reports even state that it’s possible to send unauthorized messages to the devices if someone so desired.

    As with any device that’s connected to the cloud you have to assume a certain amount of risk that the data could be stolen, but when it comes to your children you should double that amount and take proper steps to try and keep that information secure such as using strong passcodes. Or you may want to consider not sharing your child’s personal information at all with a company that advertises on basic cable commercials.

  • Geebo 10:57 am on February 16, 2017 Permalink | Reply
    Tags: , security, ,   

    Yahoo reveals that hack was worse than previously thought 

    Yahoo reveals that hack was worse than previously thought

    It seems that getting any kind of vital information out of tech dinosaur Yahoo is like pulling teeth, from a rabid badger. It was made public recently that Yahoo’s infamous hack that compromised 500 million accounts was worse than just stolen passwords. Now Yahoo is revealing that some of the accounts were compromised using a forged cookie.

    A cookie is a piece of code that allows your browser to remember such information as your username for certain sites and in some cases your password. This means that someone with a forged cookie doesn’t even need your password to access your account. Yahoo claims that the hack was carried out by a state actor which means a government sponsored attack.

    This comes at a time where Verizon is still trying to negotiate a price to purchase Yahoo. Verizon just recently requested a $300 million price cut on the pending acquisition. Then again, if it wasn’t for this acquisition we may have never heard about these hacks at all.

    If anyone is still using any Yahoo services that deal with any kind of personal information you may want to think of deleting your account. While any online service can fall victim to a large-scale hack of this nature, Yahoo seems to be inordinately porous when it comes to user security.

  • Geebo 2:49 pm on January 27, 2017 Permalink | Reply
    Tags: , , security   

    Facebook offers new level of security 

    Facebook offers new level of security

    Recently, Facebook rolled out a new security feature designed to keep your account out of the hands of hackers and identity thieves. You can now purchase a USB key that will only allow someone with the key to access your account. This is a lot more secure than the regular two factor authentication as SMS messages can be intercepted.

    However, there are drawbacks to using this method of security. The first is that it only applies to using Facebook on your PC, a mobile version of this method has yet to be implemented. The second problem is that it will only work with the Chrome and Opera browsers, so if you’re a Firefox or Explorer user, you’re out of luck. Lastly, if you lose the key you’ll be locked out of your Facebook account.

    Unless you use Facebook for business purposes or are some kind of public figure you can probably get away with just the regular two factor authentication with no problem. However if your livelihood revolves around your Facebook, the security key may not be such a bad idea.

  • Geebo 10:24 am on January 18, 2017 Permalink | Reply
    Tags: , , security   

    New phishing attack targets GMail 

    New phishing attack targets GMail

    For those of you who may not know, phishing is a type of scheme where an entity casts a wide net to a number of users in order to obtain the personal information of a few random victims. It’s like fishing but with a ‘ph’ because the internet likes to misspell things.

    A new phishing attack has appeared throughout a number of GMail accounts. If you use Google’s free webmail service the phishing email appears to be from someone on your contact list. That probably means that their account has probably been compromised. The fake email will have an attachment included in the email and when you click the attachment a new tab or window will pop up asking you to reenter your GMail login info. However, the new tab or window does not take you to GMail but rather takes you to a webpage designed to look like GMail, but in actuality is a fake page waiting to steal your login info as soon as you enter it.

    Some of the tips to avoid phishing attacks include not clicking on random attachments from strangers and in some cases from your friends. If it’s an unsolicited attachment there’s a pretty good chance it could be part of a phishing attack. Also, when logging in to your account check the URL, or web address, in your browser’s address bar. If it doesn’t belong to the service you’re logging into you could be compromising your info.

  • Geebo 1:07 pm on December 8, 2016 Permalink | Reply
    Tags: car theft, , grand theft auto, security,   

    New device could make anyone a car thief 

    New device could make anyone a car thief

    Before cars became mostly electronic and computerized it took a skilled thief to steal or break into a locked car. Only a select few had the talent to be able to pick the lock or use a slim jim to gain access to the inside of a car without breaking the window. Then if they wanted to steal the car, in most case they had a tool that would pull off the ignition and they’d be able to start the car with a screwdriver. Now, the more electronic a car becomes the more points of failure it has when it comes to auto theft.

    If you have a car that either opens the car or can be started remotely there’s a pretty big chance that it could be stolen by just about anybody. Investigative reports have determined that there is a device used among thieves that relies heavily on your cars wireless remote features. For example if you lock your car using the wireless key fob that came with it, this new device can clone the wireless frequency your car uses then replicate it to gain access to your car’s doors and ignition.

    So outside of buying a car that predates these electronics what can you do to protect your car from being stolen this way? While many of these cars use sophisticated electronics many of them still use old-fashioned keys. Rely more on the physical keys themselves when locking or unlocking the car and the criminals have a less of a chance of cloning your signal.

    The odds that this device will be used around your car are slim but it’s better to be prepared than to have to deal with an insurance company over stolen car.

  • Geebo 9:51 am on October 10, 2016 Permalink | Reply
    Tags: Kim Kardashian, , security,   

    What Kim Kardashian can teach you about social media security 

    What Kim Kardashian can teach you about social media security

    One of the bigger entertainment stories last week was the armed robbery of reality TV presence Kim Kardashian. She was said to have been robbed of $10 million in jewelry while in her Paris hotel room. Some reports have alleged that the perpetrators may have used her ubiquitous presence on social media to plan the heist. The truth is that you don’t have to be famous to have your social media betray you like that.

    Apps like Twitter and Instagram are constantly trying to get you to post your location. If you’re out in public and away from home this can present a number of problems for your real world security. Mashable, has a great blog post about how to disable your location in several apps. Another safety issue is with check in apps that announce where you may be such as a restaurant or concert. Instead of checking in as soon as you get there you may want to wait until after you leave before checking in.

    The biggest security flaw that has come back to bite social media mavens is being on vacation. It’s become common place to announce your vacation plans on social media before documenting the entire trip. This has the potential to let one of your followers know that you may not be home for a while which has led to burglaries in the past.

    Instead of documenting every moment of your life on social media as it happens, maybe put some time aside at the end of the day to do more of a ‘day in review’ type of update. Your safety and security is not worth a handful of likes and emojis.

  • Geebo 11:08 am on September 23, 2016 Permalink | Reply
    Tags: , , security,   

    Yahoo hacked again. What you need to do 

    Yahoo hacked again. What you need to do

    Yesterday, Yahoo announced that 500 million accounts had been stolen by a state-sponsored hack back in 2014. So if you use Yahoo Mail, or any other of their services like Flickr, it’s time to change your password once again. Even if you’ve changed your password since the hack took place it is recommended that you update your password again. This inevitably brings out the articled and blog posts about how to keep your passwords secure, and this is one of them.

    First, you should try using a passphrase instead of a password. Also you should really consider enabling two-factor authentication for most of your accounts. Some tech experts also suggest using a password manager. Personally, I don’t care for password managers for one reason, they require a master password. That means that all your passwords can have a single point of failure. If you lose your password manager’s password then all your passwords could be lost. Conversely, if someone were to access your password manager’s password they’d have access to all your passwords. However, your results may vary.

    A great resource to see if any of your accounts have been hacked is the “have i been pwned?” website. At their website you can enter your email address to see if any of your accounts associated with your email address have been compromised in the most infamous hacks that have taken place on the internet.

    Lastly, and this one can’t be stressed enough, don’t use the same password for all your accounts. That is how most accounts get hacked. Hackers will get an email address and password from one hack, such as Yahoo’s, and then will try them on other services like Facebook to try to gain even more of your personal information.

  • Geebo 9:51 am on September 22, 2016 Permalink | Reply
    Tags: , , , school, security   

    Do you know how your kids’ school monitors them online? 

    Do you know how your kids' school monitors them online?

    These days a number of schools issue Chromebooks or iPads to their students to in order to assist the students with online learning. These programs are also often seen as a boon to families who may not necessarily be able to afford to provide their kids with electronic devices for school. But did you know that the schools can access those computers at almost any time?

    Usually when a school checks a child’s activity on a school issued device, it’s either to make sure the device isn’t being used improperly, or to make sure a student isn’t getting behind in their work. However, there have been incidents of abuse in the past where schools have used the devices’ cameras to allegedly spy on students in their homes.

    So what kind of privacy can you and your kids expect on these school issued devices. Well, according to TechCrunch, virtually none and the schools aren’t exactly forthcoming with that information. However this lack of privacy can be used as a teaching opportunity for your kids and how to behave online. It can teach them that their online activities can have real world repercussions and can prepare them to protect their own privacy for when they become adults.

  • Geebo 11:28 am on September 21, 2016 Permalink | Reply
    Tags: ATM, atm skimmer, , , , security   

    New type of ATM skimmers appear in US 

    New type of ATM skimmers appear in US

    In case you’ve never heard of an ATM Skimmer it’s normally a device that a suspect will insert into the card reader of an ATM. This device will read all the information off your ATM card,including your PIN. It’s not just ATMs though, these skimmers can also be attached to gas pumps and any other stand alone machine that accepts debit cards. These type of skimmers can be usually thwarted by firmly pulling on the slot where the card is inserted, If a part slides out, it’s probably not safe to use that ATM or other machine.

    Recently, the Secret Service released an announcement to financial institutions that a new type of skimmer has shown up in the US and isn’t as easy to spot. The skimmer, called a periscope, is a piece of hardware that is installed inside the ATM. According to the announcement, the suspects access the ATM from the top in order to install the skimmer. The Krebs on Security blog post that’s been linked to recommends that you should only use ATMs that are embedded into the bank’s walls and can’t be accessed from the top.

    Unfortunately, there’s no absolute way to always protect yourself from ATM and debit card fraud. However, you can avoid problems by just using some common sense and if a ATM machine or any other card reading machine feels shady or unreliable just pass it by.

Compose new post
Next post/Next comment
Previous post/Previous comment
Show/Hide comments
Go to top
Go to login
Show/Hide help
shift + esc