Saturday, July 31, 2021
Cybersecurity wrap up
For the last six months, I've been writing about how to keep yourself safe online. I concluded the series -- for now -- last month, and for your convenience, I'm creating a index of all those articles here so you have one-handy place to reference all of them.
When it comes to Cybersecurity, humans are the weakest linkJust trying to using technology to protect data won't keep people safe from cyber criminals. In fact, it may actually make matters worse. Adding complexity to existing security systems will only make it harder for regular folks to use and understand it. The key to keeping people safe is to change their behavior.
Cybersecurity speak: Is it all geek to you?
When IT folks start talking about cybersecurity we often use many terms people don't understand. So in this article, I explain what much of that jargon means.
Is there something phishy going on in your inbox?
In this article, I show you how you can identify scam e-mails that enter your inbox. And the key to protecting yourself is deceptively easy – trust nobody. Assume every message you get is fake until you can confirm it’s not.
Pass the word about good passwords
You hear IT folks saying it all the time. You need to create complex passwords and should have a different one for every account you have. The problem is remembering them all. This article will give tips on how to do that.
2FA or not 2FA? That’s the question…
No matter how unguessable you think your password is or how careful you are about avoiding online scams, your credentials could still be stolen by hackers who target the companies who store those passwords. That’s why you need to further secure your important accounts by using something called Two Factor Authentication (2FA) or Multi-Factor Authentication (MFA).
Focus on the people, not the technology
IT folks need to get users to think about cybersecurity in same way they think about their safety and security in the real world. Because when it comes down to it, keeping safe online is nothing more than following the same common-sense safety procedures we were all taught as kids and no longer even have to think about.
Wednesday, June 30, 2021
Cybersecurity: Focus on the people, not the technology
Over the last few months, I’ve written a lot about cybersecurity, yet many of you may have noticed that I didn’t talk a lot about technological defenses such as software that you can install on your devices to detect and block viruses and malware, or things like VPNs, which can help anonymize you so hackers – or even the companies you do regular business with – can’t track you across the web.
Neither did I talk about rules you could set up to prevent spam and fraudulent e-mails from reaching your inbox or browser add-ins you could install to block you from going to malicious websites which try to trick you into revealing your personal information or downloading spyware.
It’s not that these things aren’t important – because they are – but I’ve noticed that when you start taking about stuff like that, a lot of people’s eyes start to glaze over. It all sounds very complicated, and many people don’t understand it or lack the confidence or competence to set it up themselves.
Another reason I avoided talking about these things is because having all the best security technology in the world doesn’t guarantee you won’t become a victim of cybercrime.
Just ask the folks who run the Colonial Pipeline and JBS Foods. Both these big companies have a
department full of IT folks equipped with some pretty sophisticated equipment, yet both got hit with ransomware attacks in May and both had to pay a huge amount of money to get their data back.
Look, I’m not laying the blame solely on intentionally careless users. Most folks I know try to be careful, but either don’t understand why they need to follow the guideless their IT folks say they should or find all the procedures and checklists too complicated or hard to remember. And frankly this is the fault of us IT folks for making things way more complicated than they need to be.
Instead of concentrating on the technical aspects of keeping people safe, we IT folks need to take a more people-centric approach to cybersecurity. We need to make its concepts more tangible to what people do in the real word without really thinking about it.
For example, if you asked most folks if they would leave the key to their house under the door mat where every burglar in the world knows to look for it, or ask them if they’d leave their wallet or purse unattended in a public place or if they’d give a complete stranger their credit card, social security number or bank account number, I’m sure 99.999999 percent of them would say no.
It’s just common-sense safety procedures we were all taught as kids and don’t think twice about. We just do it without thinking because it’s so ingrained in us.
And that should be the goal of every IT professional. Get users to think about cybersecurity in same way they think about their safety and security in the real world.
For example, no one would secure their valuables with a padlock which only had a one-digit combination. Anyone could open that lock in seconds by just trying every number from 0 to 9 until they got the right one. Furthermore, they wouldn’t use that same one-digit combination on every lockbox they owned. That would be crazy, right?
Yet in 2020, over 2 million people used “123456” as their password!
But having so many passwords is hard to remember, they’ll say. To which I’d answer: So, it is remembering what all the different keys on your keyring are for, but you don’t have a single key that opens all the doors in your house, car, office, or deposit box do you? It would be too dangerous if you lost it.
The key (if you’ll excuse the analogy) is to get people to see that cybersecurity isn’t some new nebulous thing they need to master but just an extension of their everyday, real-word safety habits that they’ve been practicing all their lives. There’s no need to master any new skills. They just need to apply the skills they already have to the virtual world as well as the physical.
I really believe that this people-centric approach to online security is vastly superior to any technological solution we could come up with. If we can get people to view that fake e-mail from a bank with the same suspicion they’d give to a stranger who just knocked on their door and claimed to be representative from their bank, then there would be little need for all that super-complicated technology.
I hope that this series has helped you to better understand this and see that keeping yourself safe out there in cyberspace isn’t as complicated as you might have thought.
Wednesday, March 31, 2021
Cybersecurity: Is there something phishy going on in your inbox?
![]() |
| SOURCE: Jeffrey L. Price, 2020 |
It’s because fish can’t resist them, and it seems we humans also have this same flaw. Send someone a flashy message promising them some reward or a vaguely worded threat and we just can’t resist clicking on the link or attachment in that message to see what it is.
Cybercriminals know this and depend on your trust and curiosity to make their scams work. And just like that poor trout who goes to investigate that shiny thing floating around in the water, it doesn’t end well.
So how do you avoid becoming some cyber-fisherman’s catch of the day?
The answer is deceptively easy. When it comes to e-mails -- and even text messages – trust nobody. Assume every message you get is fake until you can confirm it’s not.
And how do you go about confirming a message isn’t fake?
By following some simple precautions I outline below. While this list isn’t exhaustive and doesn’t guarantee you will never be fooled, you will be surprised how often it can save you from being hooked.
Skepticism is your best defense
Look closely at the display name and email address
Review the salutation
Be warry of urgent or threatening language
Guard your confidential information as if your life depended on it
Think before you click
![]() |
Note the link in the body says one thing, but when you hover over it, the real link shows a different address! |
hover your mouse over the link. If the link address looks weird, DON’T click on it. If you’re skeptical about the link, call an IT pro to have them check it out. If you don’t have a favorite IT person you can bug, then look up the business’ contact information via a google search or go old-school and use a phone book, and call the company and ask them about the message.
Don’t click attachments either
Texts messages aren’t any safer
Sunday, February 28, 2021
Cybersecurity speak: Is it all geek to you?
MALWARE
RANSOMWARE
Ransoms can be as “small” as $100 or range into the
millions. It’s often demanded in bitcoin, a type of virtual or electronic
currency that is hard to trace, and there is no guarantee that even if you pay
the ransom, the hostage taker will give you the key to unlock your data.
Most people have probably heard about the recent ransomware
attacks on big hospitals and municipal governments, but do not let that fool
you into thinking that cybercriminals only target big institutions with deep
pockets.
They don’t.
PHISHING
![]() |
| SOURCE: Jeffrey L. Price, 2020 |
your computer or lockup your data. It’s to trick you into willingly reveal your sensitive information or data to an attacker. Attackers will do this by trying to impersonate someone you know or an institution you trust to not only get you to reveal your usernames, passwords and/or financial information, but also trick you into sending money to some fake account they have control of. Phishers also use these types of attacks to gather other background information on you such as your birthdate, social security number, previous employers, salary, etc. so they can use that information to open fake credit accounts in your name.
SPEAR-PISHING
SMISHING
VISHING
SOCIAL ENGINEERING
AGE DOESN’T MATTER
![]() |
| SOURCE: Proofpoint 2020 State of the Phish report |
and older folks, you’d be dead wrong. “Digital natives” – the generation who has never known a world without all this technology – aren’t immune from falling victim to cybercrime.
2FA/MFA
Wednesday, November 25, 2020
Follow these online shopping tips to stay safe this holiday season
Cyber Monday is right around the corner and cybercriminals are gearing up to take advantage of unsuspecting people during the biggest online shopping day in the United States. It’s especially important this year, as many people will be foregoing their annual shopping trips to potentially crowded malls and stores to avoid the risks of contracting Covid 19.
As usual,
cybercrooks will try to lure you into giving up your personal information like
your credit card numbers, usernames and passwords, social security number and
even date of birth by doing the following:
- Creating fraudulent (but real-looking) web sites and
email messages
- Intercepting insecure transactions
- Targeting computers that are not running the latest
security patches, have minimal or no antivirus software on them or are
already infected with malware.
Fortunately,
with a little foreknowledge and some precaution, you can avoid many of these
cyber-threats. Think of these eight steps recommended by IT security
professionals, as the same type of common-sense things you’d do when shopping
in person: like locking the car and putting away your cash or credit card when
you’re done with your purchase.
Shop reliable websites and get there safely
If an offer
sounds too good to be true, it probably is. Don't be fooled by the lure of
great discounts from unfamiliar websites or companies you may not have heard
of. Most likely they are fake! Use the sites of retailers that you know
and trust, and get to their sites by directly typing a known, trusted
URL into the address bar instead of clicking on a link. Also look
closely at the names of the company and make sure they are who you think they
are. Many scammers may try to fool you by misspelling or using a look-alike
name of a better known company (for example Wallmart.com or Wal-Mart.com
instead of Walmart.com or Amazzon.com instead of Amazon.com)
Beware of seasonal scams
Fake package tracking emails, fake e-cards, fake charity donation scams, and emails requesting that you confirm purchase information are another common tactic cyber criminals use this time of year. Treat every message you get like this as suspicious and use known, trusted web address instead of clicking on the links in these messages. If you don’t know the URL of a charity or company look it up and confirm it across several websites. Which leads us to our next tip:
![]() |
| Graphic courtesy of Kaspersky Labs https://www.kaspersky.com/ |
Conduct research
When considering a new website or online company for your holiday purchases, read online reviews of it on other websites to see whether others have had issue with them. Never trust the reviews on the company’s web site itself. You can use sites like Yelp.com, Better Business Bureau and Consumer Reports to help you rate shopping sites, while the Federal Trade Commission recommends using BBB Wise Giving Alliance, Charity Navigator, CharityWatch, and GuideStar to check out charitable organizations .
And remember, if
a site looks suspicious, avoid it!
Think twice before clicking on links or opening
attachments
Even if links
appear to be from people you know, legitimate organizations, your favorite
retailers, or even your bank, messages can easily be faked. Use known,
trusted URLs instead of clicking on links. And only open known,
expected attachments. If in doubt, use a phone number you know to call your
bank, a store or your contact and find out if they really sent you that
attachment. I you can’t do that and still are in doubt, throw it out!
Make sure your device is patched and up-to-date
Before
shopping online at anytime of the year, you should always make sure your
device, apps, browser, and anti-virus/anti-malware software are patched and up
to date. Make sure automatic updates are turned on and periodically restart
your devices to ensure that updates are fully installed.
Protect your passwords
Never reveal
your passwords to anyone. Make them long, strong, unique, and use multi-factor
authentication (MFA) wherever possible. MFA requires you to have a second
device – most often a cell phone -- that a message can be sent to, to ensure
it’s really you trying to log into some website and not someone who may have
stolen your username or password.
Use different
passwords for different accounts and don’t use the same passwords you use at
home for work accounts and vise-versa. We IT pros know that doing that is
cumbersome and it’s hard to remember all those passwords, but that is what
cybercrooks count on! They know that if they crack one of your passwords they
will often be able to gain access to all your other accounts as well!
To help you
remember all those different passwords consider using a password manager such
as LastPass or RoboForm to store all
them. That way you only have to remember one master password. Better yet buy a
small notebook like an old-fashion address book and write down all your
usernames and password in that and always keep it in your desk at home.
And finally,
don’t let your apps and websites remember your passwords. If your device is
ever stolen or lost, whoever finds it will then have a record of all your
usernames and passwords.
Check your credit card and bank statements regularly
These are
often the first indicators that your account information or identity has been
stolen. If there is a discrepancy, report it immediately.
If you have
the option, turn on text alerts. Most banking apps and sites provide them and
allow you to create alerts for things like transactions over a specified dollar
amount or a daily text summary of your current balance. Getting these types of
alerts can help you to spot signs of unusual activity before thousands of
dollars are either charged or withdrawn from your accounts.
Lastly, check
your credit report at least annually. The
Federal Trade Commission provides information about getting free credit
reports and what to do if you find discrepancies.
Secure your home WiFi
To prevent
eavesdroppers and data thieves, ensure that you have a strong passphrase (12
characters or more with your wireless network set to WPA-2). Change your
network’s name (SSID) from the default to something that does not obviously
belong to you. Limit who has administrative access to your home network.
Finally, log into your wireless router periodically to check for software
updates (many home routers don’t auto-update).
Get savvy
about WiFi hotspots and public computers. Treat all WiFi hotspots and public
computers as compromised, even if they appear to be safe. Limit the type of
business you conduct on them, including logging in to key accounts, such as
email and banking, and shopping. And set your devices to “ask” before joining
new wireless networks so you don’t unknowingly connect to an insecure or
fraudulent hot spot.
Following all
these tips may sound like a lot to remember, but they’re really no different
than the precautions you’d usually take when planning a shopping trip to the
mall during the busy holiday season. And they are certainly easier than trying
to find that coveted parking spot close to the entrance in a crowded lot!










