Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Friday, May 6, 2011

Today's 10 Security Threats



From Alan Calder :






There is never a time for complacency in information security. All users remain under the permanent threat of cybercrime, so the most important thing is to know your enemy. If you do, you greatly increase the strength of your protection. Here are the main information security threats right now.




1. Vulnerable web apps






First on the list are website attacks that exploit poorly secured web applications. Finding the open door of an insecure application is the essential first step in any website attack.
I expect a sharp rise in this mode of entry by cybercriminals. Apart from practising good website security, such as regular application of all relevant patches, it is a good idea to have a basic understanding of common hacking techniques, such as SQL injection and cross-site scripting.



2. Sophisticated phishing and pharming






Fake emails and scams for money from 'banks' or 'HMRC' have become increasingly difficult to tell from the real thing. There is a clear rise in interest among criminals in online identity theft.
Antivirus software and spyware removal software cannot protect against these attacks single-handedly. Effort must go into user education in this area to cut exposure to risk.




3. Spam






We have seen huge increases in spam, almost to levels of denial of service. About 90 percent of all email messages are either spam or phishing attempts, according to computer security software provider Symantec. Staff opening an infected attachment can easily unleash a worm or virus onto your corporate network.




4. Social media attacks






There has been an increase in social media attacks, exploiting inadequate password security and insecure free apps. The security settings for personal and sensitive data on social networking sites are not transparent, meaning individuals are not always aware of how much personal information is accessible to possibly undesirable third parties.




5. Sharp jump in identity theft






Identity fraud involves someone pretending to be somebody else to steal money or gain other benefits. Even seven years ago, the Home Office was estimating that this type of electronic burglary was costing the UK at least £1.3bn per annum. By 2006 the Home Office increased that figure to £1.7bn, and observers now believe the real annual figure could be significantly higher.




6. Theft of credit-card details






Perhaps only five percent of e-commerce websites are PCI DSS-secure. The payment card industry is seeing frightening increases in the hacking of merchant security systems to obtain card data, particularly with merchants that accept cardholder information over the internet.




7. Exploiting the latest technology






New technologies such as voice over internet protocol, virtualisation and even the iPhone all introduce security risks, as hackers immediately start finding ways to exploit inherent vulnerabilities.
One example is the exploitation of IP-based telephone systems to perform 'vishing' campaigns. Vishing makes calls from a compromised phone system that appears to be a trusted source to the receiver of the call, enticing the receiver to divulge confidential information.



8. Increased outsourcing






Many companies — large and small — have turned to outsourcing services as a cost-saving strategy but, consequently, large amounts of sensitive data, including customer and employee personal information, are being shared with outside vendors.




It is imperative that any partner of you or your business, with access to sensitive customer information, deploys adequate safeguards to protect that information.




9. Rise in super-portable data






Every week there seems to be a report of data loss because of a stolen laptop or misplaced portable data. USB devices that hold 64GB of data make it very easy for employees to transport massive amounts of information out the door — potentially to your rivals.




10. Complacency






You can have all the latest technology to secure your internet perimeter but if your employees are not trained in how to follow and enforce your security policies, you may not be prepared to stop an enemy walking in the front door to gain access to your data.




Compared with many of the investments made by organisations, data protection compliance comes at a bargain price. Any organisation not addressing information security with a formal compliance regime is not only risking financial penalties; if you let your customers down, your very survival will be on the line.

How to Protect you Email from Being Hacked



From ZDNET and Rik Ferguson




Late in March, thousands of consumers had their email addresses stolen by cybercriminals who hacked into TripAdvisor and Play.com. Many of these consumers are now reporting an influx of spam and phishing attacks, leaving them concerned about the safety of their information online.
Hacking attacks are becoming more commonplace in the news today. Although varying in severity, there is one constant: people are left wondering why their information was open to such breaches, what is really being done to protect their information, and what should they be comfortable with sharing online?
In reality, hacks will always take place. As businesses improve their security, a hacker will always try to find a way round it. But it would certainly be advisable for companies to communicate such breaches in a more effective manner.
While no credit card details were stolen in either of these cases, it's important to get reassurance from the victimized companies to ensure people still part with their email addresses or other personal information, so practical advice is vital.



Vague and unhelpful post-breach advice




The emails both TripAdvisor and Play.com issued to announce their breaches were not only vague, but also provided little advice on what a customer should do beyond "ignore spam emails".
I would never advocate a boycott of people giving out their email addresses. It's unrealistic: many websites and businesses, quite legitimately, request an address before you can access their content.
With two high-profile hacks taking place in the space of a week, naturally consumer confidence is beginning to erode. But I would never advocate a boycott of people giving out their email addresses. It's unrealistic to advise against providing email account details because so many websites and businesses, quite legitimately, request an address before you can access their content.
With that in mind, it is important that we stay ahead of the game and mitigate the possibility of much more than our email address being stolen. I would urge people to use different email addresses for different websites. For example, Yahoo allows you to create a certain number of disposable email addresses under one account so they can be used for various online activities.
You could have an email address for Amazon and another for eBay. That way, if one of those websites were breached, you would know which one and can simply delete the compromised email address. Another option, if you have your own domain — I know, this isn't for everyone — is to set up named email addresses for example, play@yourdomainname.com.




Avoiding interlinked emails and passwords




The more active you are in ensuring your emails and passwords aren't all interlinked, the more likely you are able to stop an online hack becoming much more than the pilfering of your email address.

With specific reference to the most recent hacks, I would like to see further details from the companies in question on what exactly was breached and what is being done to ensure the same thing won't recur. It is important for them and their customers to be certain measures are being put in place.
If recognizable targets such as TripAdvisor and Play.com are more forthcoming with their advice and information on security breaches, and consumers become more proactive with how they manage their email accounts, the threat of serious attacks should be diminished.
There is always the chance that someone can get hold of your information without your knowing. But as long as you take control and make sure you are as secure as you can be, and websites are ensuring they have the correct measures in place, there is certainly less to worry about.

Users Forced to Change Passwords due to LastPass hack threat






From Tom Espiner and ZDNET :




Password management company LastPass is forcing customers to change their master passwords after detecting a possible breach.


On Tuesday, LastPass noticed that anomalous traffic had left one of its database servers, and also that anomalous traffic had flowed from one of its non-critical machines. While the company occasionally sees such anomalies, it was unable to track down the root cause in these instances.
"We're going to be paranoid and assume the worst: that the data we stored in the database was somehow accessed," the company said in a security advisory on Wednesday. "We know roughly the amount of data transferred and that it's big enough to have transferred people's email addresses, the server salt and their salted password hashes from the database."
Virginia-based LastPass provides tools that store and manage passwords for people who have multiple online logins. The consumer product allows users to encrypt a set of passwords and allocate a master password for use with browsers, while the enterprise version allows a single sign-on for websites and applications.
The company said hackers could potentially apply brute force to salted password hashes using a dictionary attack to reveal master passwords. As a consequence, the company has forced users to reset their master passwords and, in a number of cases, to validate their email addresses.
Security company Netcraft said the breach was potentially serious for people who had weak master passwords.
If a hacker can recover a single password, then all [the user's] passwords will be compromised, including webmail and Paypal.
– Paul Mutton, Netcraft
"If a hacker can recover a single password, then all [the user's] passwords will be compromised, including webmail and Paypal," said Paul Mutton, a security analyst at Netcraft. "People would be wise to change their passwords."
Email validation proved difficult for at least one user, who could not log in to validate their email address.
"Quick question; LastPass seems to be unusable until I change my master password, but I can't log in to Gmail without LastPass giving me my Gmail password," said a user called Yansky said in the comments below LastPass's security advisory. "So how do I reset my LastPass master password if I can't log in to my email?"
The company suggested logging into Gmail in offline mode to circumvent the problem.