Tuesday, February 09, 2016

Protecting Your Data is Your Responsibility @Home and while @way—Be Smart!

Even if you don't work in the Information Technology/Information Security space, it's important to understand the risks posed how and where you access the Internet.  From hospitals to airports to departments stores to fast food restaurants, Wi-Fi access is available for free just about everywhere.  But make no mistake, these "free" services almost always come at some cost.  And the risks are plenty.  Here are a few of the problems and risks, and what you can do to protect yourself.

• Problem: FWAP.  No, that acronym is not an abbreviation for an obscure hip-hop artist, but stands for "Faux Wireless Access Point."  The SSID (Service Set Identifier) is the Wi-Finame you connect to when at home or (via hot spot) when on the go.  To be clear, there's nothing sacred about SSIDs and anyone can walk into an airport and establish an access point called "Free Wi-Fi."  And there are even instructions on the internet for setting up a FWAP.

The Risk:  The probability and impact are both moderate to high that you’ve connected to such a connection unknowingly. This is considered a variation on a man-in-the-middle (MITM) scenario where an attacker secretly relays and/or records communication between two parties who think they’re communicating directly.

What can I do about it?  Start by thinking.  Before connecting to the first random open SSID available, think!  Look to find some publicly posted information that 
1. Substantiates the offering of the service, 
2. Identifies what the legitimate SSID is, and 
3. Clarifies whether the service is free--yes, there are still tightwads that charge for wireless service, mostly in the hotel industry

Additionally, be sure to pay attention to spelling of SSIDs.  The number zero(0) can sometimes look a lot like the character, capital “O,” when displayed in proportional fonts; thus, while McDONALDS and McD0NALDS may look similar, they are not the same.

• Problem: Unencrypted public access point. These would be legitimate access points you’re likely familiar with at coffee shops, airports, etc.  While convenient, you should be aware that ANY data you transmit when connected to such sites is visible to anyone who chooses to listen.  Let me repeat:  Your data is visible to anyone who chooses to listen.  By contrast, most informed users are well aware that at home, their WAPs should utilize strong encryption (e.g., WPA2) and a well-constructed, alpha-numeric access key to shield their data from prying eyes.   While on the go, however, people expect and relish in the fact that wireless access is free, but think nothing of the fact that the service provided typically has no encryption. 

For instance, If you use one of Starbucks’ free AT&T-provided Wi-Fi networks at one of their coffee shops, you must agree to their Terms and Conditions. Like most of us, you probably didn’t read them. But if you did, buried in these Terms and Conditions is the following sentence:  “If you have a VPN, AT&T recommends that you connect through it for optimum security.”

The Risk:  The probability and impact are both moderate depending on where you are. Companies utilize Terms and Conditions to defer liability, and whether you know it or not you explicitly “accept” by clicking a button to connect.
What can I do about it?  If you have the privilege of occasionally working from home, then you’re likely familiar with Virtual Private Networks (VPN).  A VPN connects two computers securely (and privately) via the Internet, even if utilizing a public network.  Now connecting to work is one thing, but connecting for general surfing while protecting your own privacy is another.  There are plethora of service options for VPN services, some of which are free.  
Just keep in mind:  You get what you pay for!


• Problem:  Poor Authentication.  Administrators everywhere just made a collective sigh, because even with enforcement policies in place people manage to select passwords that are not sufficiently complex.  In fact, every year there are organizations that publish the worst of the worst passwords, and inevitably the same passwords float to the top of the list.  Whether you’re using Wi-Fi or a hardwire connection, poor authentication—characterized by short, easily-compromised passwords—are a substantial risk.

The Risk:  By definition, simple passwords are easy to compromise.  The impact is high to very high depending upon the nature of sensitive data you’ve “secured” via simple authentication methods.  Don’t make it easy on those who might be looking to do your reputation, finances, or personal data harm.  Fortunately, there are some things you can do to protect your data better.

What can I do about it?  
o Manage your passwords better!  Here’s how…
▪ Make your everyday passwords more complex.  Passwords should be a minimum of 8 characters in length, be case-sensitive, and include letters, numbers, and special characters to the extent the latter is supported by the system
▪ Never, ever, ever, write your passwords down or share them with anyone.  Not with family, friends, or with the HelpDesk Admin guy at your job.  No one.  No password is secret if stored where it can be easily accessed by bad actors.
▪ Don’t use the password cache functions in popular browsers.  Sure, most use some form of encryption, but anyone who has access to your machine will also have access to your credentials!
▪ Don’t overlap your work passwords with those you use for personal and home devices.  If your credentials are compromised in one area, you don’t want to put the other area at risk for the sake of convenience.
▪ Don’t use the same passwords for multiple sites.  It’s like having the same key to every door, car, suitcase, and storage area you have access to.  A better way is to obtain a password vault from a reputable source such as CNET or PCMagazine.  A good password vault will also have a utility for creating distinct, complex passwords for the sites you visit.  Create a master password that is complex, and store all other passwords in your vault.
▪ Change your passwords (at least) annually.  Password vaults are particularly handy for making this task easy.
o Create a complex password.  Simple passwords—particularly those using words from the dictionary, sports teams, pet’s names, etc.—are easy to crack.  Do yourself a favor and get in the habit of using a complex password.  Here’s how…
a) Start with a simple phrase you can remember easily:  “The Dodge Challenger and Jeep Wrangler are my two favorite cars.”
b) Take the first letter of each of those words:  TDCAJWAMTFC
c) Make the password case sensitive: TDCaJWamtfc
d) If the site or tool accepts them, add complexity by incorporating numbers and special characters:  TDC&JWam2fc!
e) You can add additional complexity by padding your passwords with a prefix or suffix of characters.  For instance, you could use your graduation year, but hold the shift key.  1987 becomes "!(*&"   which would produce: TDC&JWam2fc!!(*&
o Use Multi-Factor Authentication.  If a site offers multi-factor authentication (MFA), which requires you to enter a) something you know (e.g., a password or passphrase), and b) something you have (e.g., a code from a token or mobile phone, a pattern, a fingerprint) use it!  Most banks, stock trading sites, e-commerce sites (e.g., eBay, Amazon), and even Facebook support MFA.  And while MFA alone is not a panacea, it still a sufficient deterrent to get malicious users looking at someone else’s data instead of yours because of the difficulty to compromise.

• Problem: Questionable sites.  Steer clear of them.  Sounds obvious, I know; but even the most trustworthy of sites can steer you to obscure places via links and ads.  
The Risks:  Too many to list.  Here are just a few:
o Malware – Malware (Malicious Software) is software developed to compromise data, bypass access controls, or harm the host computer.  Malware is a broad term thatcharacterizes several categories of malicious programs.
o Viruses – A form of malware that is capable of copy itself and spreading to other computers.  Viruses often spread by attaching to an executable file, but can also be spread through documents, script files, and cross-site scripting (XSS) vulnerabilities in web applications.
o Adware - Adware (Advertisement-supported software) is a type of malware that automatically delivers advertisements. Common examples of adware include pop-up ads on websites and advertisements that are displayed by software. Software and applications offer “free” versions that come bundled with adware.
o Bot – Bots (or ‘Bots) as you may have guessed is a play upon the word, robot.  Bots are used for harmless tasks in gaming and internet auction sites; however, they can also be used for malicious purposes—e.g., Distributed Denial of Services (DDoS) attacks, and for sending spam email (spambots).
o Rootkit – Rootkits are designed to provide remote access to a computer without being detected.  Once installed, it’s possible for the malicious user to remotely execute files, modify system configurations, and access information.
o Worm – A worm is a type of virus, but worms have the ability to self-replicate.  Worms are typically spread via mass emails with infected attachments.
o Ransomware – A form of malware that effectively locks your access down and holds your data hostage until you comply with demands.
What can I do about it?  
o Anti-Virus (AV) Software – There is plenty of coverage on anti-virus software comparisons—commercial and free.  If you don’t already have an AV package installed, pick one, get it installed, and set for daily signature updates.  Pronto!
o Patch Management – Windows and Mac OS users alike are familiar with operating system patches that download and (sometimes) self-update if you permit.  What about all of that other software you have?  Some package update only upon use.  Others do so in the background—and eat precious resources in the process.  How can you be sure you’re current?  Secunia—now Flexera Software—offers a free Personal Software Inspector (without adware) that inspects your system for applications and monitors the patch status for every software title installed.  If the software is out of date, it prompts with a notice indicating the update available (or sunset date if the software is no longer supported).  It’s never been easier to keep your software current.
o Personal Firewall – Personal firewalls are like the virtual moat around your data in your castle.  You typically have one on your operating system, and another on your router/switch at home.  Be sure the former is enabled, and test the settings that most stringent that still allow you to do things you typically do—web surf, stream video, play networked games, etc.
o (For Crying Out Loud,) Be Smart!  You shouldn’t have to get burned to know that blue flames are hot.  Similarly, questionable sites have a look and feel that are all too obvious—typos, no brick & mortar address, no contact information are all telltale signs.  It’s (sometimes) okay to look around.  But don’t be like the kids in a horror movie who go inside the home after they’ve heard or seen something strange.  When a site you’ve never heard of starts pumping you to enter your credit card information, run for the hills!!!
 Peace,
+Thinker 

Friday, April 25, 2014

Can you be a bigot without being a racist? Sure, it also goes by the term, “ignoramus”

For those not paying attention, Mr. Cliven Bundy is a Nevada rancher whose cattle have been illegally grazing on government land.  For twenty years.  At a cost to Uncle Sam totaling over a million dollars and counting.  This is the same man who denies the existence of the United States, but uses the Internet as a personal sounding board.  Contradictory?  Perhaps.  Outrageous?  Definitely.  While there’s an argument to be made about the righteousness of the grazing law, defying the law while placing government officials at gunpoint will get you arrested at best or killed at worst.  Don't think so?  Watch the acclaimed film, “Fruitvale Station”.

 If you’re listening, Mr. Bundy, the “Fruitvale” reference is apropos.  When Uncle Sam attempted to (literally) repo your cattle, turning it into a 21st century version of the showdown at O.K. Corral with the Bureau of Land Management (BLM) was not wise, to say the least.  You won the battle, but I’m perplexed at how that in any way relates to subsequent comments you’ve made.  Your response in invoking the name of Martin Luther King, Jr. and Rosa Parks—note the “s”—in a recent interview with CNN only reinforces how ill-informed you are.  Suggesting that you have, “often wondered, are (African Americans/negroes) better off as slaves, picking cotton and having a family life and doing things, or are they better off under government subsidy?” is tantamount to saying that jewish people were better off being exterminated by the Germans, that native Americans were better off being placed on reservations, or that women are better off barefoot, pregnant, and out of the workplace!  Such “thoughts” are repugnant by any stretch of the imagination and best kept to one self.

To use your lingo, what really “chaps my hide” is that your statement perpetuates some radical belief that most (if not all) black folks are somehow taking government subsidies.  Yet, by not paying for your cattle grazing, you’re guilty of what you suggest others are doing.  And do you honestly believe that negro lives during the slavery era could be construed as some warped version of a wholesome “family life”?  Really???  If so, go ahead and take that boot you displayed for the camera during that interview and have a good meal.  To be clear: no one is infringing on your right to your use your (limited) vocabulary.  To wit, you are free to use the terms “negro”, “black boy”, “slave”, and “those people” however you wish.  That said, be advised that there are consequences for such free speech in the same manner that people who yell  “fire” in movie theaters (without cause) can attest.  Recall:  Freedom is not free.  It comes at (some) cost.


In conclusion, I want you to understand that I, for one, don’t believe you are racist, sir; however, I do believe that all of your synapses may not be firing on all cylinders if you don’t have enough good sense to self-censor in public.  For us mere mortals, we call that “ignorance.”  More important, though, you might consider taking inventory of your views and seeing things from others’ perspectives.  

Just food for thought…

Peace,
+THINKER

Friday, April 11, 2014

Heartbleed is out there...Here's what you need to know and do now...

A message from your friendly neighborhood Information Security Manager:  

Unless you’ve been living in a cave, you’ve probably been hearing a lot about the “Heartbleed” bug on the Internet.  While users are generally oblivious to these sorts of notices, here’s why you need to be paying attention to this one…

What is Heartbleed?  Heartbleed is a bug that has made servers that utilize OpenSSL encryption vulnerable to attack.

Why is it an issue?  The issue lies in the fact that the vulnerability has made the recovery of user credentials a trivial exercise for hackers.  Reputable sources estimate that approximate 20-60% of all websites may have been exposed.   A report from Kaspersky Lab indicates there is evidence that there are cyber espionage groups running scans.

What web sites are affected?   According to tech website Mashable, several major banks are not affected because they do not use OpenSSL encryption software. The website released a list of major sites that were infected by the heartbleed bug and have since been updated, including Facebook, Pinterest, Tumblr, Gmail, Yahoo, Amazon and Dropbox.


When was this discovered?  Evidence of the bug surface on Monday, April 7, 2014

How is it fixed?  Administrators of affected servers must both patch each individual server as well as obtain new digital certificates from a certificate authority.

What can I do about it?  Contrary to some reports, changing your password now will not bring you any extra security unless the server has been patched.  And tools have popped up and purport to help you “test” web sites have also been identified as having malware.   Your best bet is to avoid logging in to services for the next week or so, after which you should then log in and change your password that is complex.  In the event you receive a message from what appears to be a service you use, go to the web site directly--without clicking on links in messages to be on the safe side.

How should I manage my passwords? 
·      Never, ever, ever, write your passwords down or share them with anyone.  Not with family, friends, or with the HelpDesk Admin guy at your job.  No one.
·      Don’t use the password cache functions inherent in popular browsers.  Sure, most use the latest encryption algorithms, but anyone who has access to your machine will also have access to your accounts.
·      Don’t use the same passwords for multiple sites.  It’s like having the same key to every door, car, suitcase, and storage area you have access to.  A better way is to obtain a password vault from a reputable source such as CNET—don’t worry, this software is free (search: “free password safe”).  A good password vault will also have a utility for creating distinct, complex passwords for the sites you visit.
·      Create a master password that is complex.  Should be (at least) 12 characters in length, have upper & lower case letters, numbers, and special characters if the site allows.  Store all other passwords in your vault.
·      If the site offer multi-factor authentication—requiring you to enter a code from a token or from your mobile phone—use it!
How do I create a complex password?
Simple passwords—particularly those using words from the dictionary, sports teams, pet’s names, etc.—are easy to crack.  Do yourself a favor and get in the habit of using a complex password.  Here’s how…
1.     Start with a phrase you can remember easily:  “The Range Rover Sport and Jaguar XF are my two favorite cars.”
2.     Take the first letter of each of those words:  TRRSAJXAMTFC
3.     Make the password case sensitive: TRRSaJXamtfc
4.     Add complexity by incorporating numbers and special characters:  TRRS&JXam2fc!
5.     You can add additional complexity by padding your passwords with a prefix or suffix of characters.  For instance, you could use your graduation year, but hold the shift key.  1983 à !(*#  Which now gives you TRRS&JXam2fc!+!(*# 

Peace,
+THINKER



Wednesday, December 18, 2013

Shop safely this holiday season

A message from your friendly neighborhood Information Security Manager:

Here are just a few tips for shopping safely and keeping your personal data safe this holiday season...

Shopping in the physical world
- Don't leave purchased items in plain sight in your vehicle.  If you're going back-and-forth to your vehicle to store packages, make sure that the gifts you’ve bought aren't in plain sight. Lock gift purchases in your trunk or in the back with a tarp over them if you have an SUV.
- When shopping at night, try to park under a street lamp even if it means walking a little further.  Would-be thieves are more prone to do their dirt where the lighting is low--and it will be safer for you, too.
- Make it a point to show your identification card when paying by credit card, even if the court does not ask for it.  Clerks are supposed to check this for purchases over a specific amount--typically $50.  Showing your identification card is a good precautionary step to authenticate your use of your own cards and encourages retailers to prevent fraudulent use.
- Take inventory of the cards that you have in your wallet or purse.  In the event that you should lose your wallet or purse while shopping, you'll have a list correlating to the lender you should call. 
- If you're purchasing (or using) gift cards, be aware of the use limitations on them.  For instance, restaurants will typically put a hold on a card for an amount that includes the bill total plus an anticipated tip.  Also, some prepaid cards require the use of a PIN to use--recipients should be made aware of this and have guidance in the event the debit card is lost.
- Protect your personal information like your life depends on it.  Some retailers (e.g., Best Buy) are now asking for a swipe of your driver’s license in order to return product. While a VISUAL inspection of your government identity card--drivers license, passport, etc.--is fine, swiping the magnetic stripe or photocopying is not as it allows the retailer to retain personal data they NOT need to do a simple return.  Assuming you have the original receipt and/or the original card used, simply ask the cashier to verify identity the old fashioned way to protect your personal data.

Shopping online
Additional tips for shopping online à click here


'Nough said,

+THINKER