Monday, May 15, 2017

Get Your Guard Up! We're in the Data Surveillance Age

Get Your Guard Up! We're in the Data Surveillance Age

Remember back in the day when we were worried about Big Brother government's intrusiveness into our personal affairs? Well nothing's changed. We know this, thanks in part to Edward Snowden's heroic disclosures. It's just been made much easier to tap us because of our online lifestyles.   


In my opinion, though, as for spying and privacy violations, the average citizen has more to worry from the private sector. (Unless of course you're Muslim, affiliated with one of our enemies du jour, or cross swords with government policies.) 


Your browsing habits are now for sale

Case in point: If you've been following the news, President Trump signed a bill in April that permits ISPs (Internet service providers), like Oceanic Time Warner and Hawaiian Telcom, to sell your browsing habits to marketers. This is akin to your phone service provider listening to your phone conversations, then selling those transcriptions to telemarketers. 

Here are some tips to protect your privacy in this age of exploitation and plunder of personal data.


Use a VPN

If you don't want ISPs or others (like governments or hackers) to examine the details of your Internet usage, you can surf anonymously by using a VPN (Virtual Private Network) service. Of course, you have to trust the VPN provider. Here's one site that recently reviewed VPN services: https://goo.gl/jVqcrB. (I'm currently test-driving a VPN service called NordVPN.) 
Here 10 reasons to hide your IP with a VPN: https://goo.gl/n39uE9

Use HTTPS Everywhere

This browser extension is provided freely by the Electronic Frontier Foundation. When installed, it forces encrypted connections to https (encrypted) websites you visit, and when fully enabled, will block all unencrypted requests. You can read about this tool and get it here: https://www.eff.org/https-everywhere

Disable Third-party cookies

Be aware cookies are little pieces of data sent by a website and stored in your browser. Third-party cookies are cookies placed in your browser by a website other than the one you're visiting. This occurs when you visit a website and their advertiser(s) set a cookie, which allows that advertiser to track your visits to other websites. Here's a link explaining how to block third-party cookies. https://goo.gl/PnAXt3 

Read provider privacy and data use policies

Do this for any service you use, including Google, Facebook, travel booking services, your ISP, etc. They all BADLY want to know as much about you as possible so they and/or their partners can get you to open your wallet and spend, spend, spend! As an example, here's what Google does with their users' data: https://goo.gl/LPEHv2

Of course whatever measures we take to shield our privacy will be met with countermeasures. There's too much money at stake to expect otherwise. So if data privacy is important to you, you've got to stay current with protection measures.  


Wishing you an inconspicuous day in cyberspace!


Thanks for reading.

Sam

---


If you haven't already, you can subscribe to our email tips by visiting www.kokuadigital.com and entering your name, email, and "add to email list" in the request form, then click Send. 

Wednesday, March 15, 2017

Boost Your Email Security or Suffer

Boost Your Email Security or Suffer

For years now the electronic mail system of the Internet (email) has been a victim of annoying advertising spam and virus attacks. 

The latest threats to email include hacking to take control of the account, spam with links that when clicked infect a computer with ransomware, and tracking/spying on email usage by email providers and their affiliates.   


Below are some suggestions for boosting email security. Remember though, networking and the Internet were not designed from the ground up to be a secure communication system, nor was email. 
Whenever you send something via email it can be compromised somewhere along the communication chain. 
  • Use separate accounts for business and personal use. In my opinion, it's generally more likely a personal email account will be compromised. You don't want your business contacts exposed by a hack. 
  • Ditch Yahoo email. Use Gmail instead. True, there are privacy concerns with Gmail. But I believe Google does a much better job at security than Yahoo. Just read the recent news on the hacks of Yahoo's system and their failure to take action and disclose. 
  • Use 2-step verification. This requires that someone trying to access your email from a device you haven't previously used/approved will need to enter a code sent by text to your phone to gain access. 
  • Use unique, complex passwords for each account, and make sure passwords are not used for any other online accounts. 
  • Don't send anything confidential by email. As mentioned earlier, email isn't inherently secure. So don't email account numbers, passwords, social security numbers, etc. If you must share this stuff via email, find a means to encrypt the data, such as zipping an attachment with the 7-zip program and using a password/encryption. This is not perfect security, but raises the bar. 
  • Set your spam scanner on aggressive and check the spam folder often for valid email. You can white-list the wrongly labeled "spam" email so the filter won't screen it out next time. 
  • Use Antivirus software to scan all email if you use a program like Outlook, Thunderbird, Windows Mail, etc. 
  • If your email is hacked, changed your password immediately and monitor the account for oddities. If the hacker sent email from you to your contacts, immediately notify your contacts about the hack - tell them to be careful about suspicious content, including asking them to click links.
Bottom line, whenever you check your email, pretend you're walking in a strange city at night. Keep your guard up! Criminals and miscreants are trying every trick in the book to get to you via email. 

Wishing you a safe day in cyberspace!


Thanks for reading.
Sam

---


If you haven't already, you can subscribe to our email tips by visiting www.kokuadigital.com and entering your name, email, and "add to email list" in the request form, then click Send. 

Wednesday, February 15, 2017

Beware of Click and Tap Fever

Beware of Click and Tap Fever

Living much of our lives on digital devices has programmed us to be adept clickers of the mouse or tappers of the finger. Kids especially do this at lightning speed!

But we have become so adept that we're clicking and tapping way too fast, too reflexively. It would behoove us to be more deliberate, especially when selecting weblinks.

Weblinks from Hell
Selecting weblinks without thinking can get us into big trouble, as one click or tap can cause a computer infection, or worse yet, a completely hijacked machine. (This is more common on Windows computers than on Macs or mobile devices – at least for now!)

So, best practice is to NOT open emails, links, or attachments from strangers, or even people you know if something seems suspicious about the email. When in doubt, delete.  If the message is important enough, the person will call, or you can call them.

Careful on Facebook
This applies also on social media sites like Facebook, where clicking a link in a poisoned advertisement can lead to infection.

Don't get Phished!
Phishing is big business in the cybercrime world. Phishing (a twist on the word fishing) is all about trying to hook computer users by clicking/tapping links to infect a computer, scam with a product or service, or hack a computer in various other ways.

The US government created a campaign to promote more careful web use. It’s called Stop.Think.Connect. I recommend you check out their site. (Yes, this link is safe)

Training is key
If you’re an employer, you can print out material from the site or show a video clip to your staff. Education is key to reduce risk of getting hacked.

I give cybersecurity presentations to businesses and community groups. You can contact me to schedule on Hawaii Island.

Last, I’m recommending Malwarebytes Anti-malware 3.0, the paid version, to my clients these days. Training and knowledge is primary, second is good security software. 

Here's the site: https://www.malwarebytes.com

After you buy and install it, close all programs on your computer and run a full scan, including your external drives. 


Wishing you a safe day in cyberspace!

Thanks for reading.
Sam

---

If you haven't already, you can subscribe to our email tips by visiting www.kokuadigital.com and entering your name, email, and "add to email list" in the request form, then click Send. 

Sunday, January 15, 2017

Tech Magic Comes with a Price

Tech Magic Comes with a Price

So, did Santa give you the new Internet-connected gadget you hoped for at Christmas? Remember, as they say in fairy tales, all magic comes with a price!

The magic in modern times is technology. One of the prices in the cyber realm is the security vs. pleasure trade off.

This shows up when we get or buy a new gadget like a web cam for home "security", then hear on the news they're getting hacked left and right due to poor protections built in by the manufacturers.

Assume the worst!
Assume the worst when you set up a new device! Check with one of your techie friends about it. Or do a web search, inquiring about security and privacy concerns.

There are ways to fix some of the known security holes in vulnerable web devices, such as updating software/firmware, changing default settings, and turning off any unwanted features.

Amazon Echo Dot - can be too convenient
Like web cams, the Echo Dot is a cool web toy. If you haven't experienced it yet, you can check it out on YouTube. One downside is it can be set for easy ordering from amazon.com. Hence there are many stories of kids ordering stuff without their parents' permission. Ouch$!

Keep a close eye on your devices and users
If you want to be security-minded and keep control of your devices - lest they control or jeopardize your bank account or worse - make a list of the devices you have and who has access to them. Keep the devices updated, and set desired controls (such as parental controls). If you're unsure about the vulnerability of any device, unplug it from the Internet until you research it or get some help from a techie.

Trust sparingly
It can be a painful lesson to "trust the company" who made it to have your security and privacy interests at heart. In my opinion, most don't. They want a fast turnaround on their investment.

Web cams (yes, I'm picking on them again) are notoriously unsafe in this regard. I recently unplugged security cameras for one of my clients due to the uptick in remote hacking of such systems. We can still see the cameras in operation and record video to a hard drive, but we have the system unplugged from the web.

Unplug to be safe
Along these lines, a good rule of thumb when leaving your home for travel is to unplug all your equipment, including your Internet modem/router. This is a good practice due to electrical surges from stormy weather, but also ensures no one can access or hack any of your devices while you're away.

And if you ever suspect a device has been hacked, turn it off immediately and get tech support from someone local or the vendor. Be sure to go directly to the vendor's website - don't just “google” for help on that device. There are plenty of scammers who prey on people searching online for tech support.

Wishing you a safe new year in cyberspace!

Thanks for reading.
Sam

---
If you haven't already, you can subscribe to our email tips by visiting www.kokuadigital.com and entering your name, email, and "add to email list" in the request form, then click Send. 

Thursday, December 15, 2016

New Year's Resolution Challenge - Change your Passwords

New Year's Resolution Challenge - Change your Passwords

Happy Holidays!

I’ve got a geeky suggestion for one of your 2017 New Year’s resolutions: Make a commitment to change all your online passwords to something unique and complex. 

“Oh, what a pain!” you may say.  And yes, it is.  But it just may save you from an even more painful hack of your account. 

Weak Password, Easier Hack
Cybercrooks take advantage of weak passwords to hack a variety of accounts from email to banking to social networking sites.  And if they hack a vault of online passwords that includes one of your accounts, you are vulnerable even if you have a strong password. (But as long as that compromised password is unique, the creeps won’t be able to access your other accounts.) 

So, to reduce the risk of making your accounts an easy exploit, do these two things:

1. Make sure each password you have is unique, that is, don’t use the same password for any two or more accounts. The password for each of your email accounts, your computer login, your phone, tablet, social networking accounts, financial accounts, etc. should be exclusive.  

2. Make each password complex.  I recommend at least 12 characters, with a mix of letters, numbers, and characters like # or * o ^.  You can also use a phrase as a password, such as Ilovemilkandcookies.  But make the “I’ a “1”, the “m” in milk an “M” and the “s” in cookies a “$”.  You can also use a random password generator, like the one at this site: 

https://www.grc.com/passwords.htm.  (In this case, you can just pick out the number of characters you’d like to use, such as 8, 10, or 12 from the character string.)

Password vault
How to keep track of your new, brain-boggling password system? Use a password manager like lastpass.com.  

For heaven’s sake do not keep the passwords on your phone in a notes file.  If someone breaks into your phone, it’s game over. They will "own" you. 

If you’re old school, you can type or write the passwords on paper, then store in a locked safe or very safe place.  Share the location with a trusted person.  (If you want to up your game, you can also encrypt the file on your computer containing your password list.)

Break down the job
This password management task may seem daunting. So in the New Year (or earlier for you fast starters) just commit to changing one password each week, starting with your online financial accounts.  

Wishing you safe computing this holiday season and in 2017.

Thanks for reading.
Sam

---
If you haven't already, you can subscribe to our email tips by visiting www.kokuadigital.com and entering your name, email, and "add to email list" in the request form, then click Send. 

Tuesday, November 15, 2016

Ransomware is Infecting the Aloha State too

Ransomware is Infecting the Aloha State too

Ransomware attacks are escalating, as indicated in various recent news reports. 

But this is not just happening "out there", somewhere else, like on the mainland or overseas. One of my small business clients on Hawaii Island was hit last week by a ransomware attack. 

Email link from Hell 
My client had clicked on a bogus email link*, then his computer was infected. The infection encrypted his files, effectively locking them up. 

He got a note from the criminals promising to unlock his files if he paid the equivalent of $450 in bitcoin. He consulted with me and we decided to not pay. 

His rationale? He had all his files backed up online. Plus he wanted to set up a new computer anyways, so he proceeded to download all his backed up files to the new laptop. 

Later we'll wipe his infected hard drive and reload his operating system, Windows. This should clean out the infection. 

Online backup salvation 
He was lucky. He was using an online backup service, which I can't recommend highly enough for all my clients, especially businesses. I recommend Mozy.com. 

Test your backups 
Be sure to test your online backup at least monthly by restoring one or more of the backed up files. 

You can read more about ransomware on my blog post here
https://cybersecurity808.blogspot.com/2015/06/watch-out-for-ransomware-attacks-theyre.html

And here's a recent article on a ransomware attack in Indiana:
http://arstechnica.com/security/2016/11/indiana-county-government-shut-down-by-ransomware-to-pay-up/

Thanks for reading.
Sam

---
If you haven't already, you can subscribe to our email tips by visiting www.kokuadigital.com and entering your name, email, and "add to email list" in the request form, then click Send.

*93% of all phishing emails contain encryption ransomware, per PhishMe, Q1 2016 Malware Review, June 2016.

Saturday, October 15, 2016

We Have Met the Enemy and He is Us

We have met the enemy and he is us

If you're doing your best to keep your computer protected from cyber attacks - using a router firewall, running security software, keeping software current, etc. - please be aware, the main threat is closer at hand. 

That threat is you. And by you, I mean all of us end users, sitting between the system and the keyboard. In most attacks, we are the primary means of exploit. 

Social engineering
In many cases, cybercriminals prey upon our good nature to gain access to our computers and/or our private information. A term used to describe this is "social engineering." 

Examples of social engineering include: phone calls to our homes or businesses offering bogus computer tech support; calls pretending to be an institution we belong to; or even calls supposedly from charities. These approaches are tried via email too, in which case they're called "phishing" attacks.  

Don't be polite
Suspicion is the name of the defensive game here. Don't feel the need to be polite when you sense you're being probed in this manner. Disengage from the phone call. Delete the email. Close the webpage. 

Take action
If you feel you may have been scammed, contact the actual institution or business immediately to notify them. If you feel an online account has been compromised, change your password at once. If your computer has been hacked turn it off, unplug from the Internet, and call trusted local tech support asap. 

In sum, to quote that famous Pogo cartoon line: "We have met the enemy and he is us." We have to change our behavior to keep ourselves safer from cybercrooks. All the software and hardware filters we use are just aids and deterrents, not final solutions.   

Thanks for reading.
Sam

---
If you haven't already, you can subscribe to our email tips by visiting www.kokuadigital.com and entering your name, email, and "add to email list" in the request form, then click Send.