Click Networks - IT Support Glasgow

Click Networks - IT Support Glasgow
Click Networks - IT Support Glasgow
Showing posts with label passwords. Show all posts
Showing posts with label passwords. Show all posts

Monday, 17 December 2012

How hackers exploit social media

The phenomenon of "social engineering" is behind the vast majority of successful hacking.
This isn't the high tech wizardry of Hollywood but is a good, old-fashioned confidence trick.
It's been updated for the modern age, and although modern terms such as "phishing" and "smishing" are used to describe the specific tricks used, they all rely upon a set of human characteristics which, with due respect to Hieronymus Bosch, you might picture as the "seven deadly sins" of social engineering.

Apathy:
To fall for a confidence trick, or worse, we assume others "must" have taken the necessary steps to keep us secure.

Sadly this leads to a lack of awareness, and in the world of the hacker that is fatal. When we stay in a hotel and we programme our random number into the room safe to keep our belongings secure, how many of us check to see if the manufacturers override code has been left in the safe?
It's nearly always 0000 or 1234 so try it next time.

Curiosity:
Humans are curious by nature. However, naive and uninformed curiosity has caused many casualties. Criminals know we're curious and they will try to lure us in. If we see an unfamiliar door appear in a building we frequent, we all wonder where it leads. 

We might be tempted to open it and find out, but in the online world that might just be a trap waiting for an innocent user to spring it. A colleague built a website that contained a button that said Do Not Press, and was astonished to find that the majority of people actually pressed it.
Be curious, but exercise a healthy degree of suspicion.

Gullibility: It is often thought of as a derogatory term, but we all suffer from this sin. We make assumptions.
We take others at face value, especially outside of our areas of expertise. Put a uniform on someone and we assume they have authority.

Give an email an official appearance by using the correct logo and apparently coming from the correct email address, and we might just assume it's real, regardless of how silly its instructions might be.

All of this can be easily forged online, so make no assumptions.

Courtesy: We quite rightly all teach our children to be polite. However, politeness does not mean you should not discriminate.

If you do not know something, or you feel something doesn't feel quite right, ask. This principle is truer than ever in the online world, where we are asked to interact with people and systems in ways with which we are quite unfamiliar.

If someone phones you out of the blue and says they are from your bank do you believe them?

No. Phone them back. 

And by the way, use a mobile phone as landlines can remain connected to the person who made the call in the first place and so whilst you might think you're phoning the bank on a valid number you're just talking to the person who called you.

Greed: Despite what we'd like to think we are all susceptible to greed even though it might not feel like greed.

Since its inception, the very culture of the web has been to share items for free.
Initially this was academic research, but as the internet was commercialised in the mid-1990s, we were left with the impression that we could still find something for nothing.

Nothing is ever truly free online. You have to remember that if you're not the paying customer, you're very likely to be the product. In the worst case, you might find that you have taken something onto your machine that is far from what you bargained for.

Many pieces of malware are actively downloaded by owners unaware that the "free" product contains a nasty payload, even if it also appears to do what you expected of it.
 
Diffidence:
People are reluctant to ask strangers for ID, and in the online world it is more important than ever to establish the credentials of those whom you entrust with your sensitive information.

Do not let circumstances lead you to make assumptions about ID.
For example, if someone from "IT support" calls you and asks for your password so they can help fix your problem, how do you know they haven't called everyone else in the building first until they found you who has really got a problem?

This is a well-known attack. If someone has a problem with proving who they are, you should immediately be suspicious.

Thoughtlessness:
 Thinking before you act is possibly the most effective means of protecting yourself online. It is all too easy to click that link.
Stop.

How many of us when reading an apparently valid link in an email would bother to check whether the link is actually valid or whether instead it takes you to a malicious site.
It's horribly easy to make links look valid so try hovering your cursor over the link for a few seconds before clicking to see what the real link is: the true link pops up if you give it a moment.
As cynical as it may sound, the only answer is to practise your A-B-C:
  • Assume nothing
  • Believe no one
  • Check everything
With more Christmas shopping expected to be done online this year than ever before, you should watch out for those that would exploit the deadly sins.
Don't give criminals the chance to ruin your holiday season, and remember that a little bit of paranoia goes a long way online.

View the whole story here: http://www.bbc.co.uk/news/technology-20717773

For more information about staying safe online contact the IT support experts at Click Networks today on 0141 530 9116 or email us at info@clicknetworks.co.uk today!

Friday, 7 December 2012

Don't struggle to remember passwords!

Should you be secure and use lots of different passwords? Or is it more convenient and easy to remember just one or two?

Almost everything online needs a password these days: shop accounts social networking sites, university and email logins, banks, credit cards, insurance, savings and more. I don’t know about you – but I suspect I’ve over 50 different accounts and all the passwords for these need remembering somehow – and unless you’re a memory maestro that’s impossible.
Yet not doing it is a nightmare too – we’re constantly nagged to use different passwords. Those who chose convenience and used the same password for their PlayStation Network account as for their bank or other secure code, now know why it’s so important to use different passwords. They need to immediately change the password on their other accounts otherwise the criminal hackers may well have enough of their ID to utilise it (see PlayStation hack news for more on self-protection).

How to marry security and convenience.

Over the years I’ve developed my own personal system for keeping an easy but secure track of my passwords. I’m not saying it’s perfect I just thought it worth jotting down. I’m sure many others do similar things in parallel and I’d love to know your systems. 
I’ve described similar principles to what I do below, though with some details and techniques changed slightly for my own security. It may seem a little complex but actually as it’s developed organically over the years, it’s become an easy natural progression, though I accept it’d be more difficult to do it all in one go.
  • Step 1: Establish a number of key words. 

    Pick words that mean something to you but aren’t obvious or guessable like relative’s names. The easy way to do this is to start with one or two, then once those are firmly embedded add more. But for the moment let’s say they’re established.  They should all start with different letters, for the sake of the example we’ll say they are:
    Random
    Spank
    Widget
    Acne
  • Step 2: Establish a few key numbers.

    Try not to have obvious dates such as your date of birth – though something like 1874 (Churchill’s birth year) is fine. So here you have: 1874
    5012
    0191
  • Step 3: Create passwords using a combination of both. 

    Use the words or numbers forwards or backwards, capitalised or not capitalised. This gives you a very large number of available different passwords even though you only need to remember a few words and numbers. For example: – Spank0191
    – 1874Widget
    – 2105acne
    – modnar5012
    – Random18
  • Step 4: Note the password down IN CODE somewhere safe and convenient.

    Now just store the password safely in code somewhere in case it’s ever needed – never write the full words or numbers down anywhere, you need to remember those yourself. For example, the above passwords could be stored as… -S0  (ie, the word beginning with S then the numbers beginning with 0)
    -1W
    -Rev5 a  (ie, the numbers beginning with 5 in reverse, then the word beginning with a – but not capitalised)
    -Revr 5
    -R half 1 (ie, word beginning with R then half the numbers beginning with 1)
That’s my way. An alternative is to simply create yourself a grid for each password such as:
A  B  C  D  E  F  G  H  I  J  K  L  M  N  O…..ETC
3  D  A  F  U 2   1  P  R A  V 9  C   I   F
Here you remember just one key word, for example FAKE and you use that to look up the numbers in the password grid – here you’ll see its 23VU. 
To set this up initially you just need to write the alphabet out then put the code in under your key word and fill in the others with random letters.
This is a bit chunky to do, but it does mean you only need to remember one password to get encoded access to all the others. It’s probably most useful as a way of writing down pin numbers rather than passwords though.
OK those are some techniques, what are your tips? Ensure you don’t compromise your security in your response.

For more information on passwords or how to password protect your business and information contact the experts at Click Networks IT Support Team Glasgow on 0141 530 9116 or visit the website here: http://www.clicknetworks.co.uk/ 

To read the full article please visit: http://blog.moneysavingexpert.com