“Their intention is to infect your computer so that you don’t even know you’ve been infected.”
Hardly reassuring words for computer users or business owners. Cybercrime continues to flourish for one simple reason: it’s profitable.
Hackers use two broad approaches: Either they sneakily install malicious software on your computer to control it or steal your information, or they trick you into giving up your information voluntarily.
The malicious software can enter your system when you visit a shady website, or open an e-mail attachment carrying a virus. If it infects your machine, it might hand control of your computer over to networks that will rent it out to spammers, who will use it as a junk-mail-sending machine.
Or worse, it might install “key-logger” software that takes careful note of every word you type – usernames, passwords and all – and sends it back to hackers, who can co-opt your online accounts, take your money, and even represent themselves as you to your friends.
None of these things bode well for small businesses, which are often focused on the job at hand more than they are on information security. But there are new responses to these threats. In increasingly perilous seas, how do you stay on course without giving in to paranoia?
Here are some suggestions:
1. Don’t open unexpected attachments, even if they come from friends.
E-mail attachments are a great source of malware. But nowadays, they don’t just come from dodgy strangers, they can come from your best friends.
When certain malware infects computers, it will scan e-mail address books and send malicious messages to every contact, making it appear that the message comes from a friend. Oftentimes, they’ll contain messages such as “Here’s the PDF I said I’d send,” but they’re getting more clever and more subtle all the time.
If someone you know sends you an e-mail with attached files that you weren’t expecting, or that seem strangely generic (“Hey, check out these pictures!”), make contact with the sender first to make sure it’s genuine.
“If it sounds unbelievable, it totally is,” says David Mirza Ahmad, a cyber-security veteran and one of the founders of Subgraph, a Montreal-based security start-up. “Look for cues in the e-mail: Is the e-mail worded a little differently? Is it normal to receive random files from this person? If there’s a file, there should be context.”
In fact, any unexpected behaviour from friends on social networks should be taken with a grain of salt. Social networks are the latest frontier for hackers because they engender so much trust. If a Facebook friend starts posting items they wouldn’t normally post, be careful: their account might have been compromised, and the items might be a trap.
2. Update, update, update.
Even if you never opened another attachment in your life, you can still let viruses in, even by doing something as simple as visiting the wrong website at the wrong time.
The software that runs modern computers is enormous and labyrinthine, and hackers are always finding new holes that they can use to sneak malicious software onto computers – usually by injecting. And software makers such as Microsoft, Apple, and anti-virus makers, are constantly rushing to patch those holes. It’s a never-ending game of cat-and-mouse.
This is why it’s essential to keep your software up-to-date, and up to the minute. You need to update three things: First, your operating system (such as Windows or Mac OS), which receive updates to plug security holes as they’re found. By default, these will install automatic updates – it’s important to let them. Second, your web browser (Internet Explorer, Firefox, Chrome) needs to be up-to-date for the same reason. New versions are free to download. This goes expecially for users of Internet Explorer 6, an older version of the popular browser that was well-known as a security nightmare.
Finally, your virus-checking software needs constant updates to know which malware to look for today.
3. Be very careful about following login links from e-mails.
The next trick is to keep from getting tricked. Increasingly, scammers will try to convince you to give away your login and password for a phony web page that’s set up to look like a real one.
It’s called “phishing” – as in, going fishing for victims. You’ve probably already received some that use banks as bait: An e-mail arrives, prompting you to visit your bank’s website to “verify your login information.” It will direct you to a page that looks like your bank’s website, but it is really a false front that passes your login information on to hackers.
So far, these have been fairly easy to spot. But scammers are getting smarter: they’re now sending e-mails that look like new-friend or message-waiting notices from social networks such as Facebook or LinkedIn.
Always be cautious. Watch out for vague-seeming notifications. Pay careful attention to the URL at the top of the web page. If there’s any doubt, don’t follow the link from the e-mail, but visit the social network’s page directly and log in there.
4. Use different passwords.
Password safety isn’t the be-all and end-all of security, but it’s an important rudiment. You’ve probably been regularly warned not to use simple or easy-to-guess passwords. But it’s probably even more important (and, yes, more annoying) not to use the same password for every online service you use.
The reason is simple: If, by installing a key-logger, or tricking you with a phishing trick, a hacker gets the username and password for one site, you can bet he’ll turn around and try it on every other service you’re signed up with. You could wind up being locked out of everything at once.
If remembering a dozen different passwords is unwieldy (and it is), consider using at least two groups of passwords – one for not-so-important sites, and different ones for the really sensitive logins. Or, Mr. Mizra suggests using desktop software that uses one master password to access all the individual passwords - software such as the Mac OS Keychain or PasswordSafe for Windows.
5. Don’t think you’re smarter than the criminals.
So you know the ropes on the Internet. You know a malicious e-mail when you see one. Still, sometimes curiosity gets the best of you, and you click, thinking that you’re not going to divulge any personal information or download any suspicious files. Surprise: the bad guys have anticipated that, too.
“People believe that the operating system will protect them from everything they want to do; that by clicking on this link they’re smarter than the criminal,” Mr. Masiello says. “The criminals have got smart to this kind of thing.”
Tricks such as interstitial pages, pop-ups, and unpatched browser exploits can infect a computer before the user has clicked a single button or typed a word on a malicious web page.
And if you’re reading this on a Mac – don’t get too smug. For all of Apple’s marketing, Macs aren’t actually more secure, they’re just targeted less because fewer people own them. Malware comes for everyone, and – unfortunately - the only real solution is diligence.
News, Cyber Security, Cars, Music, Health and Fitness, Anime, Manga, Technology, lolinternets and random
Showing posts with label Cyber Security. Show all posts
Showing posts with label Cyber Security. Show all posts
Tuesday, October 12, 2010
Friday, October 8, 2010
Starbuck's Free Wi-Fi Opens the Door for Hackers and Crackers
Hackers and crackers are everywhere, looking for easy marks. Believe me when I say they're just as likely to hang out at your favorite Starbucks as you are, Ms. Entrepreneur. They could be sitting with a latte and a laptop on the sofa right next to you. And don't look for Boris- and Natasha-style cartoon characters here. ("Fearless Leader say we steal computer access from moose and squirrel!") They are far more subtle than that.
So for an entrepreneur who considers Starbucks -- or any other coffee shop for that matter -- his home office, what options are available to ensure the privacy and security of his or her data when accessing the internet on a free Wi-Fi connection?
One of the best ways is to use a Virtual Private Network to connect to the net. Until very recently, VPN was the stuff of corporations and large businesses. Small businesses, startups and independent entrepreneurs avoided VPN because it's highly technical to set up and administer.
Today, anyone can access the internet from a PC or Mac using what I call a "consumer grade" VPN. But don't let "consumer grade" fool you -- this is the same exact thing large corporations use. Think of a VPN as a secure tunnel that you use to connect to the internet -- a tunnel that's impervious to a hacker or cracker's attempt to see what you're doing and gain access to your data.
One provider of affordable and turnkey VPN is Connect In Private, which offers a secure offshore backchannel for internet surfing, e-mails and more on computers and mobile devices. CIP protects you from identity theft and fraud by providing a fully encrypted network that is impenetrable to hackers.
For about $15 a month (based on an annual contract), CIP provides a secure line for accessing the internet from anywhere you choose. This week, the company began offering a one-week account for $10, which gives you a chance to test-drive the service.
If you're accessing the net via a free and unsecured Wi-Fi spot, and you're working on something critical to the success of your startup, $10-$15 is a small price to pay to guarantee your data is secure!
Read Moar Here
So for an entrepreneur who considers Starbucks -- or any other coffee shop for that matter -- his home office, what options are available to ensure the privacy and security of his or her data when accessing the internet on a free Wi-Fi connection?
One of the best ways is to use a Virtual Private Network to connect to the net. Until very recently, VPN was the stuff of corporations and large businesses. Small businesses, startups and independent entrepreneurs avoided VPN because it's highly technical to set up and administer.
Today, anyone can access the internet from a PC or Mac using what I call a "consumer grade" VPN. But don't let "consumer grade" fool you -- this is the same exact thing large corporations use. Think of a VPN as a secure tunnel that you use to connect to the internet -- a tunnel that's impervious to a hacker or cracker's attempt to see what you're doing and gain access to your data.
One provider of affordable and turnkey VPN is Connect In Private, which offers a secure offshore backchannel for internet surfing, e-mails and more on computers and mobile devices. CIP protects you from identity theft and fraud by providing a fully encrypted network that is impenetrable to hackers.
For about $15 a month (based on an annual contract), CIP provides a secure line for accessing the internet from anywhere you choose. This week, the company began offering a one-week account for $10, which gives you a chance to test-drive the service.
If you're accessing the net via a free and unsecured Wi-Fi spot, and you're working on something critical to the success of your startup, $10-$15 is a small price to pay to guarantee your data is secure!
Read Moar Here
Friday, October 1, 2010
US military Cyber Command
The US military's central Cyber Command will not become operational as had been planned tomorrow, according to Pentagon spokesmen. Issues responsible for the delay include difficulties finding suitably qualified staff among America's uniformed legions, and also the fact that it isn't even clear what "operational" means for a cyberforce.
“I don’t know that the 1 October deadline is holding strong and fast,” military spokeswoman Lieutenant Colonel Rene White told the military paper, asked if Cyber Command would indeed be operational as US defence secretary Robert Gates had specified it should be.
Asked what "fully operational" would actually mean for the cyber command, the colonel replied: “That’s a good question."
Cyber Command, which is bossed by the head of America's feared National Security Agency (NSA) and has its headquarters at the same complex (Fort Meade in Maryland) was created to bring the nascent cyberwar forces of the separate American armed services together. These include the US 24th Air Force, Fleet Cyber Command, Army Forces Cyber Command and Marine Forces Cyber Command.
The US air force alone nowadays considers that it has 30,000 personnel assigned to "cyber" duties, though most of these are simply previously existing communications and electronics troops whose jobs are now deemed to be cyber ones. Only a few thousand are in the specialist 24th Air Force cyber formations.
Cyber Command HQ itself at Fort Meade is expected to have around 1000 staff eventually, mostly uniformed service people as opposed to the largely civilian-staffed NSA (though the NSA is formally speaking a "combat support agency of the Department of Defense"). Finding suitable military people to man up the Cyber Command is apparently a serious issue. Briefing politicians last week, NSA/Cyber Command chief General Keith Alexander said: “If you were to ask me, what is the biggest challenge that we currently face? It’s generating the people that we need to do this mission."
Some US officers considering this problem have said that military culture doesn't value technical skills and its many other requirements - that personnel should be physically fit, able to shoot straight, will be expected to command others if they are to have decent status and pay etc etc - mean that Cyber Command can never be properly manned from the existing services. A pair of cyber colonels recently argued for the creation of a fifth service, the Cyber service, which would be deliberately set up to appeal more to tech geeks, though in fact this might already be said to exist in the form of the NSA.
Another factor in the Cyber Command delays is the issue of what its job is. General Alexander's confirmation as boss was held up for some time by puzzled politicians trying to get more detail on this, and indeed judging by Colonel White's comments even the Pentagon remains unsure. Of course the command has a formal mission statement - inscribed on its crest in the form of an MD5 hash, though one needs to leave out a crucial hyphen to get the right value - but this doesn't seem to have resolved the matter.
Much debate has revolved around the issue of whether the Command will mount network attacks in other countries, and if so what the legal mechanisms for ordering it to do so might be. There's no doubt that it will be capable of making such attacks, however: the 24th AF alone contains an entire unit, the 67th Network Warfare Wing, dedicated to nothing else. Furthermore the left-field military research agency, DARPA, is known to be working on a digital "cyber range" in which to test the fearful network artillery and code missiles of tomorrow.
But for now, anyway, it appears that the Cyber Command will remain only at "initial operational capability" while it gets itself sorted out.
Read the Stars & Stripes piece here.
“I don’t know that the 1 October deadline is holding strong and fast,” military spokeswoman Lieutenant Colonel Rene White told the military paper, asked if Cyber Command would indeed be operational as US defence secretary Robert Gates had specified it should be.
Cyber Command, which is bossed by the head of America's feared National Security Agency (NSA) and has its headquarters at the same complex (Fort Meade in Maryland) was created to bring the nascent cyberwar forces of the separate American armed services together. These include the US 24th Air Force, Fleet Cyber Command, Army Forces Cyber Command and Marine Forces Cyber Command.
The US air force alone nowadays considers that it has 30,000 personnel assigned to "cyber" duties, though most of these are simply previously existing communications and electronics troops whose jobs are now deemed to be cyber ones. Only a few thousand are in the specialist 24th Air Force cyber formations.
Cyber Command HQ itself at Fort Meade is expected to have around 1000 staff eventually, mostly uniformed service people as opposed to the largely civilian-staffed NSA (though the NSA is formally speaking a "combat support agency of the Department of Defense"). Finding suitable military people to man up the Cyber Command is apparently a serious issue. Briefing politicians last week, NSA/Cyber Command chief General Keith Alexander said: “If you were to ask me, what is the biggest challenge that we currently face? It’s generating the people that we need to do this mission."
Some US officers considering this problem have said that military culture doesn't value technical skills and its many other requirements - that personnel should be physically fit, able to shoot straight, will be expected to command others if they are to have decent status and pay etc etc - mean that Cyber Command can never be properly manned from the existing services. A pair of cyber colonels recently argued for the creation of a fifth service, the Cyber service, which would be deliberately set up to appeal more to tech geeks, though in fact this might already be said to exist in the form of the NSA.
Another factor in the Cyber Command delays is the issue of what its job is. General Alexander's confirmation as boss was held up for some time by puzzled politicians trying to get more detail on this, and indeed judging by Colonel White's comments even the Pentagon remains unsure. Of course the command has a formal mission statement - inscribed on its crest in the form of an MD5 hash, though one needs to leave out a crucial hyphen to get the right value - but this doesn't seem to have resolved the matter.
Much debate has revolved around the issue of whether the Command will mount network attacks in other countries, and if so what the legal mechanisms for ordering it to do so might be. There's no doubt that it will be capable of making such attacks, however: the 24th AF alone contains an entire unit, the 67th Network Warfare Wing, dedicated to nothing else. Furthermore the left-field military research agency, DARPA, is known to be working on a digital "cyber range" in which to test the fearful network artillery and code missiles of tomorrow.
But for now, anyway, it appears that the Cyber Command will remain only at "initial operational capability" while it gets itself sorted out.
Read the Stars & Stripes piece here.
Labels:
Cyber Security
Subscribe to:
Posts (Atom)