Showing posts with label protection. Show all posts
Showing posts with label protection. Show all posts

Friday, February 1, 2013

Online Child protection : CEOP UK Video



'The Parents' and Carers' Guide to the Internet', from CEOP, is a light hearted and realistic look at what it takes to be a better online parent. The show covers topics such as, talking to your child about the technologies they use and the things they might see, such as pornography.

With interviews from leading experts such as, Professor Tanya Byron, Dr Linda Papadopoulos and Reg Bailey, as well as key industry players from Facebook, Club Penguin and Moshi Monsters , this online guide aims to equip you with the tools to have those tricky conversations with your children and keep your family safe online.

Friday, March 23, 2012

Data Security not a Priority - The Information Risk Maturity Index

Data breaches will continue to expose European businesses to unnecessary risk and damage business reputations unless action is taken now to improve the management and protection of sensitive business information, says a new report by Iron Mountain and PwC.

The study highlights an urgent need for a change in employee behaviour and a cultural shift among senior executives if organizations are to overcome the complacency, negligence and lack of shared responsibility uncovered by the study.

PwC surveyed senior managers at 600 leading European businesses to compile the Information Risk Maturity Index.

The scores, assessed for France, Germany, Hungary, the Netherlands, Spain and the UK, suggest that many businesses are woefully unprepared to address and manage information risks such as data breaches, data loss and non-compliance.

The average score for European companies was 40.6 against an ideal score of 100.

The report, launched at Iron Mountain’s first European Information Risk Summit, reveals that:
  • Only around half of mid-sized businesses consider the loss of sensitive information as one of their top three business risks.
  • Less than a quarter (24 percent) of the companies surveyed were aware as to whether or not they had experienced a data breach in the last three years.
  • A mere 1 percent of respondents consider information risk to be the responsibility of every employee, while nearly two thirds (60 percent) concede that they do not know whether their employees have the right tools to protect information.
  • Only 13 percent consider information risk to be a boardroom issue, while around a third (35 percent) view all information risk – whether related to paper or digital information – as the responsibility of the IT department. This tendency to view information risk as an IT issue was found to be widespread, with 59 percent responding to a data breach by installing additional technology.
  • Just a third (36 percent) of companies have assigned responsibility for information risk to a specific individual or team whose effectiveness is monitored.
Marc Duale, President of International at Iron Mountain, said the report was a wake-up call for European businesses: “It is time for businesses to move from a culture of information apathy and neglect to a culture of information responsibility. Fail to act and you expose your customers to serious information risk while potentially leaving your company open to the risk of irreparable reputational damage.”

Read the report (PDF)

Wednesday, June 22, 2011

Four easy-to-remember passwords that will protect your accounts

The recent security breach at the beloved online storage service, Dropbox, has reminded us of the weakness of the Web.

Founded in 2007 Dropbox that uses cloud computing to allow us to store all kinds of large files on the Web, and across a variety of operating systems, that are then easily shared with others.

For about four hours on June 19 anyone could get access to any account with a dummy password. “It was like our skirt got lifted for hours.”

This is what Dropbox wrote on their blog yesterday:
Yesterday we made a code update at 1:54pm Pacific time that introduced a bug affecting our authentication mechanism. We discovered this at 5:41pm and a fix was live at 5:46pm. A very small number of users (much less than 1 percent) logged in during that period, some of whom could have logged into an account without the correct password. As a precaution, we ended all logged in sessions.

We’re conducting a thorough investigation of related activity to understand whether any accounts were improperly accessed. If we identify any specific instances of unusual activity, we’ll immediately notify the account owner.

This should never have happened. We are scrutinizing our controls and we will be implementing additional safeguards to prevent this from happening again.

This is a serious issue for Dropbox—a company valued at $1.5 to $2 billion—since trust is the number one value they offer over their competition. Until we hear more about the “additional safeguards” they intend to implement it does give us pause about our chosen passwords.

We live in a password era, and we all have our passwords that range from the ridiculously simple and cheesy like “love” to impossible-to-get-straight gobbledigook. Apparently a shocking 50% of passwords are “based on names of a family member, spouse, partner, or a pet,” according to this book “Perfect Password: Selection, Protection, Authentication.”

We also learned recently that 75% of us use the exact same password for everything. This is a huge mistake. All it takes is one hacker and one weakly protected site and your key to everything, including email and banking, is up for grabs.

When you use the same password for everything it is only as strong as the weakest site and, unfortunately, there are plenty of weak sites. Ninety-three percent of organisations have been hacked at least once in the past two years, according to the US State of Web Application Security Survey, Ponemon Institute.

You can use the same series of numbers and letters but do mix them up (upper case, lower case, order, creating what may be a near limitless variety) for different sites, banking, discount shopping, online publications, airlines, etc. and change them up regularly.

There is a better, simpler way, according to Christopher Mims at MIT Tech Review. He suggests that you create only four passwords and use them in a tiered system.

Low-tier password: Something you may already be using that is so easy to get that it might as well be your middle name. Use this for low level importance sites. One's you don’t care about, like commenting sites for online magazines or music streaming sites. If you get hacked the worst that can happen is that your username suddenly likes Lady GaGa!

Second-tier password: “For sites on which you have personal data and definitely don’t want to be impersonated (Twitter, Facebook, etc.),” says Mims. Here you need something longer as long as you are comfortable with recalling complex phrases. Remember to use at least one special character, especially inserting it into the middle of the phrase, not at either end.

Never, ever use what is called a “dictionary password” i.e. any real word that will exist in a dictionary. A classic tactic that hackers use to break into sites uses a fast program that repeatedly inserts real words until it finds a match.

Third-tier password: This is your second highest level of security and can be used for email accounts and your cell phone. It needs to be unique, long and interspersed with special characters. Your email account is where you might hold information about your other passwords, so it must be highly guarded. It is the “master key” of passwords.

Fourth-tier password: The gold standard of passwords should be used to protect your wealth i.e. your bank and financial information. This password should be unique and can only be used for your banking, nothing else.

So we don’t need to have 30+ passwords memorised, or worse, documented in email or on scraps of paper, we just need four — or at least three — that are tiered for importance and security.

As for tips on creating a vice-like, gold standard password we suggest reading an informative post on the worst passwords of all time, and avoid them.

Even a cryptic string like “abgrtyu” is on the list, so be wary. The hard part is following the paradoxical mantra of password creation: Easy to remember, hard to guess.

Once you’ve mastered that statement, try measuring your password strength using this useful Microsoft test. I used to get angry and hurt when my passwords were noted as “weak” as if it were a personal affront. Now I know it can be part of an entire strategy of protection.

Saturday, January 23, 2010

The Most Popular Password Remains '123456'

Despite all the reports of Internet security breaches over the years, including the recent attacks on Google’s e-mail service, many people have reacted to the break-ins with a shrug.

According to a new analysis, one out of five Web users still decides to leave the digital equivalent of a key under the doormat: they choose a simple, easily guessed password like “abc123,” “iloveyou” or even “password” to protect their data.

“I guess it’s just a genetic flaw in humans,” said Amichai Shulman, the chief technology officer at Imperva, which makes software for blocking hackers. “We’ve been following the same patterns since the 1990s.”

Mr. Shulman and his company examined a list of 32 million passwords that an unknown hacker stole last month from RockYou, a company that makes software for users of social networking sites like Facebook and MySpace. The list was briefly posted on the Web, and hackers and security researchers downloaded it.

RockYou, which had already been widely criticised for lax privacy practices, has advised its customers to change their passwords, as the hacker gained information about their e-mail accounts as well.

The trove provided an unusually detailed window into computer users’ password habits. Typically, only government agencies like the F.B.I. or the National Security Agency have had access to such a large password list.

For the full article click here ..........

Friday, October 16, 2009

Recession hit Cyber-crime just doesn't pay like it used to.

Recession hits Cybercrime! With botnets everywhere, DDoS attacks get cheaper $30 will buy a one-day DDoS attack now!

Security researchers say the cost of criminal services such as distributed denial of service, or DDoS, attacks has dropped in recent months. The reason? Market economics. "The barriers to entry in that marketplace are so low you have people basically flooding the market," said Jose Nazario, a security researcher with Arbor Networks. "The way you differentiate yourself is on price."

Criminals have gotten better at hacking into unsuspecting computers and linking them together into so-called botnet networks, which can then be centrally controlled. Botnets are used to send spam, steal passwords, and sometimes to launch DDoS attacks, which flood victims' servers with unwanted information. Often these networks are rented out as a kind of criminal software-as-a-service to third parties, who are typically recruited in online discussion boards.

DDoS attacks have been used to censor critics, take down rivals, wipe out online competitors and even extort money from legitimate businesses. Earlier this year a highly publicised DDoS attack targeted U.S. and South Korean servers, knocking a number of Web sites offline.

Are botnet operators having to cut costs like other businesses in these troubled economic times? Security researchers don't know if that's been a factor, but they do say that the supply of infected machines has been growing. In 2008, Symantec's Internet sensors counted an average of 75,158 active bot-infected computers per day, a 31 percent jump from the previous year.

DDoS attacks may have cost hundreds or even thousands of dollars per day a few years ago, but in recent months researchers have seen them going for bargain-basement prices.

Nazario has seen DDoS attacks offered in the US$100-per-day range, but according to SecureWorks Security Researcher Kevin Stevens, prices have dropped to $30 to $50 on some Russian forums.

And DDoS attacks aren't the only thing getting cheaper. Stevens says the cost of stolen credit card numbers and other kinds of identity information has dropped too. "Prices are dropping on almost everything," he said.

While $100 per day might cover a garden-variety 100MB/second to 400MB/second attack, it might also procure something much weaker, depending on the seller. "There's a lot of crap out there where you don't really know what you're getting," said Zulfikar Ramzan, a technical director with Symantec Security Response. "Even though we are seeing some lower prices, it doesn't mean that you're going to get the same quality of goods."

In general, prices for access to botnet computers have dropped dramatically since 2007, he said. But with the influx of generic and often untrustworthy services, players at the high end can now charge more, Ramzan said.

Friday, July 17, 2009

Surf the Internet Freely and Safely: Care of Symantec

Everything you wanted to know about safety and security on the Internet but were afraid to ask!
Symantec have created a really friendly easy to use web page that provides basic information and advice on Internet and Credit card security, etc.