Showing posts with label passwords. Show all posts
Showing posts with label passwords. Show all posts

Monday, October 15, 2018

Use 2 Factor Authentication to Decrease Your Risk of Getting Hacked

Use 2 Factor Authentication to Decrease Risk of Getting Hacked


If you're even vaguely aware of the news these days about online account hacks - like the recent Facebook breach - then you know the importance of changing your password immediately if you're at risk.
 

Post breach, change password!
Changing your password asap after such a breach prevents a hacker from accessing your account, as long as you change it before the hacker logs in! Otherwise, you have to go through an often-stressful password reset process, during which you have to prove your identity by some other means such as email, phone, or security question answers.
 

Password reset game is no fun
I have helped many clients through this reset process and it's not fun. It's not hard, it just takes time and costs money: my billable time. Believe me, it's not a preferred IT task for either me or my clients. We get painfully reminded about the importance of locking down account access using multiple layers of identification.        
 

Use unique passwords 
While strong and unique passwords raise the bar for anyone trying to hack your account directly, they don't prevent the types of hacks Facebook disclosed. Yet if your Facebook password or any other online password is unique, and you change it right away after a reported breach, then your vulnerability is reduced.

Don't give the keys to the kingdom!
If, however, you use the same password on multiple sites and a hacker obtains info on you, such as your name, email location, and a precious password, you can bet they will try that same identify combination to crack your other accounts. That's why it's critical to have unique and complex passwords, not just variations of a theme like "mydogbruno" and "mydogbruno1".
 

2 Factor authentication boosts security
So, the first line of defense is strong and unique passwords for EVERY online account. The second line is two-factor authentication (2FA), which requires access to something besides the knowledge of a password, like a cell phone. (The password is considered something you know, a first factor. The phone is something you have, a second factor.) The phone lets you receive a call or a text with a code to unlock your account, so it authenticates you beyond your password.
 

2-Step Verification in Gmail
Not all accounts provide two-factor authentication, but for the ones that do, I highly recommend it. Gmail is one. Google calls it 2-Step Verification. Here is a simple scenario after you set this up in Gmail: You get a new device, you try to log in to your Gmail account on it, and Gmail won't let you until you receive a code texted to your phone. You type into your browser or Gmail app that one-time-only code, then you're given access to Gmail on that new device. You won't be asked again, unless something changes on that device to make Google not recognize it.  
 

After setting up 2-step in Gmail, if someone elsewhere tried to log in to your Gmail you'd receive a code on your phone. As long as that phone is with you, that person would have more difficulty accessing your email.
 

Set up 2 Factor where available
Besides Google, here is a short list of sites offering two-factor authentication: Facebook, Microsoft, Yahoo, AOL, and Twitter. If you have an account with any of these sites, take the time to set up 2FA.

Thanks for reading!
-Sam

Sunday, October 15, 2017

Are You Over Exposed?

Are You Over Exposed? 

I'm not referring to what you do or don't wear in public. Here I'm talking about what personal data you expose online. 


Take stock of your exposure

How many email accounts do you have? How many social networking accounts? How many media outlets do you subscribe to? These are things to take stock of. 

Your risk of getting hacked

The more software services you have running on your computer (programs you have installed) that connect to the Internet, and the more accounts you have with various online entities, the greater your risk of getting hacked or exploited. 

Why is this? Because it’s a numbers game – sooner or later one of the services you run or access will be hacked. Depending on what information you gave them, you may become a target on hacked data black market. 


How to reduce your exposure?


My suggestions are as follows:


1. Give careful thought to whom you give your email and contact info. Imagine what would happen if they got hacked. What data would the hacker have of yours? 


2. Uninstall any software on your computer you no longer use. Software programs are reaching more than ever out to servers for updates and other communication. These programs can be a beachhead into your computer if compromised.


3. Close online accounts of any sort that you no longer use. If you have an old email that you might occasionally need to reference, then at least suspend the service so no new mail comes in.


4. Use a strong spam filter for your email, and unsubscribe to any services you no longer use that show up on your spam list. (You can label anything that comes in as spam and sort it out when convenient.)


5. Use a unique password for EVERY SINGLE ONLINE ACCOUNT. If you share passwords between accounts and one account gets hacked, the bad guys and gals will try that password on any other accounts linked to you that they can locate. (You may like to read my July blog post about passwords.)


6. Pay attention to news reports related to any accounts you have—email, banking, social networking, etc.—and act promptly if their system has been compromised. Usually the most critical action to take is changing your password. Then start monitoring the account for unusual activity. 


One last note: Parents, be nosy about what your kids are doing on their devices, and teach them about safety and security. They rely on us for such things in the offline world; we should help protect them online as well.   


Thanks for reading!

Sam

Friday, July 14, 2017

Best Practices for Passwords

Best Practices for Passwords

One of the distractions these days to smoothly using computing devices and online resources is the dung heap of passwords one accumulates. Yeah, we all know the stench.

Password management
Some of my clients have made their lives easier by using a password manager, like lastpass.com, which I recommend. Others keep their passwords in a notes type of program which is viewable to anyone if the device is accessed locally or by online hack. This is NOT safe! Still others resort to old school means - writing credentials on paper and keeping that handy, or unfortunately sometimes, misplacing the paper.

This is one area of your life where you have to give latitude to the OCD part of yourself. You can’t be too careful with password storage. 

Make them Unique
Whatever system you use - and I strongly recommend something that’s secure against theft or loss – is to make sure each password is unique. Why? Because if a hacker gains access to an account by cracking and revealing a password, she/he will attempt that same password on any other accounts you own that can be discovered. We don’t have the same key to our car, home, and office – the same prudent approach should apply to software keys.

NIST Guidelines
Where to begin when creating passwords? The National Institute of Standards and Technology (NIST) recently published guidelines that alleviate some of the difficulties. Here’s what they recommend based on research:

  • Minimum length of eight characters; maximum length of 64 characters
  • No need to create complexity with numbers and characters like $*&
  • No need to periodically change passwords (although some online systems may still require this)
  • Avoid common words, found in the dictionary
  • Avoid anything associated with you as an individual - like maiden names, birth dates, children’s names, etc.

Strong Passphrases
Here are some examples of strong passphrases I generated with an Android app called Diceware Password Generator: “Graveness shallot relative tassel untried”. Yes, all those words together are the passphrase including the spaces. To break this would require 164 days of effort from a sophisticated hacker, like the NSA. A simpler passphrase created by this app is “banister extinct evict rejoin”. It would take 30 minutes to crack this one.  

Dumbledore
Yes, these passphrases are complex. However, if you create one that you can memorize, then you can use it for a password manager like Lastpass as your master password. Thereafter follow NIST guidelines above for your online accounts - in my opinion, using long unusual words like Dumbledore or Beatlemania, or combos of words and spaces like Queen of Hearts or Stairway to Heaven.

Be creative!
Of course, some websites will require you to use their system of password lengths and combos of upper-case letter and special characters; but for everything else, get creative, break free, and have some fun with the drudgery of passwords! And again, keep them unique to each system.


Thanks for reading.
Sam

---


If you haven't already, you can subscribe to our email tips by visiting www.kokuadigital.com and entering your name, email, and "add to email list" in the request form, then click Send. 


Thursday, December 15, 2016

New Year's Resolution Challenge - Change your Passwords

New Year's Resolution Challenge - Change your Passwords

Happy Holidays!

I’ve got a geeky suggestion for one of your 2017 New Year’s resolutions: Make a commitment to change all your online passwords to something unique and complex. 

“Oh, what a pain!” you may say.  And yes, it is.  But it just may save you from an even more painful hack of your account. 

Weak Password, Easier Hack
Cybercrooks take advantage of weak passwords to hack a variety of accounts from email to banking to social networking sites.  And if they hack a vault of online passwords that includes one of your accounts, you are vulnerable even if you have a strong password. (But as long as that compromised password is unique, the creeps won’t be able to access your other accounts.) 

So, to reduce the risk of making your accounts an easy exploit, do these two things:

1. Make sure each password you have is unique, that is, don’t use the same password for any two or more accounts. The password for each of your email accounts, your computer login, your phone, tablet, social networking accounts, financial accounts, etc. should be exclusive.  

2. Make each password complex.  I recommend at least 12 characters, with a mix of letters, numbers, and characters like # or * o ^.  You can also use a phrase as a password, such as Ilovemilkandcookies.  But make the “I’ a “1”, the “m” in milk an “M” and the “s” in cookies a “$”.  You can also use a random password generator, like the one at this site: 

https://www.grc.com/passwords.htm.  (In this case, you can just pick out the number of characters you’d like to use, such as 8, 10, or 12 from the character string.)

Password vault
How to keep track of your new, brain-boggling password system? Use a password manager like lastpass.com.  

For heaven’s sake do not keep the passwords on your phone in a notes file.  If someone breaks into your phone, it’s game over. They will "own" you. 

If you’re old school, you can type or write the passwords on paper, then store in a locked safe or very safe place.  Share the location with a trusted person.  (If you want to up your game, you can also encrypt the file on your computer containing your password list.)

Break down the job
This password management task may seem daunting. So in the New Year (or earlier for you fast starters) just commit to changing one password each week, starting with your online financial accounts.  

Wishing you safe computing this holiday season and in 2017.

Thanks for reading.
Sam

---
If you haven't already, you can subscribe to our email tips by visiting www.kokuadigital.com and entering your name, email, and "add to email list" in the request form, then click Send. 

Sunday, March 15, 2015

More Conscious Clicking

More Conscious Clicking

What's the issue?
Living much of our lives on computers has programmed us to be adept clickers of the mouse. But we have become so adept we're clicking reflexively when it would behoove us to be more deliberate, especially clicking weblinks. 

Why should you care?
Clicking weblinks without thinking can get us into big trouble, as one little click can cause a computer infection, or worse yet, a completely hijacked machine. 

How to protect yourself?
Stop.Think.Connect. This is a campaign run by the federal government to help citizens be safer online. It's managed by US-CERT, the United States Computer Emergency Readiness Team. 

Here are some security tips I have culled and adapted from their website. The tips go beyond mouse clicking, which is a form of connecting, to other considerations. 
  • Do NOT open emails, links, or attachments from strangers. When in doubt, delete. If the message is important enough, the person will call. 
  • Make your passwords complex. Use a combination of numbers, symbols, and letters (uppercase and lowercase). Use at least 8 characters. Some can be word or phrase conversions to help you remember. For example, "I love Fido" (your dog, named Fido) becomes iL@v51do. Get creative, but be sure to remember your passwords. I recommend lastpass.com to help with the chore of creating and storing passwords.  
  • Change your passwords regularly (every 45 to 90 days). If you access a server at work, consult with your network administrator.
  • Do NOT give any of your usernames, passwords, or other computer/website access codes to anyone.
  • Do NOT install or connect any personal software or hardware to your organization's network without permission from your IT department. This includes USB jump drives, which can contain viruses. 
  • Make electronic and physical back-ups or copies of all your important work. You can scan documents. You can copy docs and keep a copy stored somewhere securely off-site. 
  • Report all suspicious or unusual problems with your computer to your IT department or consultant ASAP. The sooner security breaches are dealt with, the less damage will be done. 
When should you do it?
Start your more careful computing habits right away. Implement one new security tip or practice each day. Forming good habits will help prevent bad things from happening to your confidential data and your computer. 

Where can you find more info on this topic?
For more details, please check the CERT website.

Who can help?
If some of the recommendations are too techie for you, it may be best to hire an IT consultant to get the job done. You'll sleep better after. 

In Sum
We are not completely at the mercy of computer criminals. We can up the odds of security by making many small changes in our computer use. One place to start is being more careful before clicking any weblink. 

Thanks for reading. You're feedback is appreciated!

Aloha, Sam

You can subscribe to email tips by visiting www.kokuadigital.com and entering your name, email, and "add to email list" in the request form, then click Send.  

Wednesday, October 15, 2014

Offline Data Security - A Very Good Place to Start

Offline Data Security - A Very Good Place to Start

What's the issue?
All the buzz these days in computer security is about protecting your digital data (computer-generated data) from hackers, which is a very important concern. But confidential digital data that can be exploited online (on the Internet) can actually originate offline. 

Why care?
It can be even easier for a criminal to steal your confidential information offline instead of trying online, and then use that info online to cause you much grief.

Take the contents of your wallet for example. Your identity and your financial assets can be exploited by a crook who obtains the items in your wallet--namely, your drivers license, bank and credit cards, membership cards--then finds a buyer for these items on the Internet. (There is a thriving online market to exploit these assets.)

With the info on your precious plastic cards a cyber (computer) criminal can open new accounts in your name, make purchases, and impersonate you. Depending on the creativity of the cyber thief you could be in for a long struggle to mitigate damage to your identify, reputation, and/or finances.

How to protect yourself?
A good habit is to take stock of the confidential items in your wallet. Photocopy and/or write down all pertinent information on the front and back of each card. Then store this record in your home safe. In the event your wallet goes missing you can refer to this record to notify the appropriate institutions and authorities immediately to stymie criminal activity. 

Also, the fewer items in your wallet the better. And don't carry your Social Security card, account numbers, or passwords in your wallet. Let’s not give the bad guys extra ammunition.

When should you do it?
A monthly check and update of your wallet's contents is best. After you first make the record it only takes about five minutes to note what's been added or removed from your wallet. When done, put the record back in your safe.

Where can you find more info on this topic?
The Better Business Bureau of Hawaii website has some good tips about identity and financial theft. Click here to learn more.

Who can help?
If you are elderly, ask a trusted friend or family member to assist. Seniors are frequently the victims of identity theft and financial scams. You can also ask your bank and credit card companies how they can help protect you in the event of theft.

In Sum
The bottom line is to be wary of theft in the offline and online world, and minimize our information exposure so cyber criminals can't use the latest tricks to their advantage and our anguish.

Thanks for reading. You're feedback is appreciated!

Aloha, Sam

P.S. You can subscribe to emailed computer tips by visiting www.kokuadigital.com and entering your name, email, and "add to email" in the request form.