Sunday, April 19, 2020

ZOOM! Slow Down, Your Info was Stolen

Welcome back readers!  It has been about a month, but it is time for another CYBR 650 course post.  Just to recap, last month I gave you some information about those jerks capitalizing on the COVID-19 pandemic by sending Coronavirus spam and phishing messages and setting up bogus websites, all trying to steal your information.  That leads us to the related, but not new topic of stolen account credentials.

tl;dr

Social distancing has changed the way we do business and interact with our friends and family.  Software designed to help bring us closer together while far apart is a bigger target than ever.  How can you keep your account secure, even if it is part of a breach?  A strong, complex password is the first step to keeping your account safe.

Working and Being with Family While Socially Distanced

If you are anything like me lately, you have been working from home and rely on collaboration and video conferencing software to interact with coworkers, friends, and family.  In this time of social distancing, we use software to “feel” close to those we need to interact with.  The video conferencing software provider Zoom recently suffered a breach where more than half a million account credentials were stolen.  On April 13, Forbes reported credentials for more than 530,000 Zoom accounts were being sold on an underground hacking forum.  These 530,000 accounts were purchased by Cyble, a group of cyber risk assessment experts.  The thing I find most shocking about their purchase is that they did it for next to nothing.  Basically, the account information was being sold for extremely cheap, less than a penny each or, in some cases, given away for free.  These accounts were stolen and then sold for less than $5,000.

Part of the problem with these credentials is the same with any other time an account has been stolen, people tend to reuse the same passwords for multiple accounts.  I won’t preach about the importance of creating a strong, complex password…I’ve already done that and you can read all about it here: http://cyberschopp.blogspot.com/2016/03/pesky-passwords.html.  Take a read, and then start changing your password 😊


Ensuring you have a strong password is a critical way to keep your accounts safe.  One other thing you should do is to check if the e-mail addressed used to register for accounts has been flagged as a stolen account.  The site haveibeenpwned.com can help you check that.  Checking my e-mail address, the site tells me that I have accounts on 11 breached sites.  Fortunately, I already knew this an changed the passwords associated with those breaches.  Some of the breaches my e-mail has been affected by are the 2013 Adobe breach, Collection #1 in 2019, and Lord of the Rings Online (don’t judge me).

Password Manager

One recommendation I did not give in 2016 when I jumped on my password soapbox is the use of a password manager.  A password manager keeps track of login information, including username and passwords, for sites and services you have accounts for.  Google Chrome has this built in, as well as the nicety of suggesting a complex password when creating a new account or changing your password on an existing account.  The advantage of this is the creation of an incredibly complex password that will make your account very secure.  The disadvantage of this is that the password is usually so complex and does not make sense, so remembering it would be next to impossible.  This is okay as long as you have access to your password manager, or are willing to change it often when you need to access the account from a different system.

Multi-factor Authentication

Another option for securing accounts is to use multi-factor authentication.  You are probably already using this to some extent but let me creak it down for you.  You login to your bank account with your username and password.  Your bank website then prompts you to select either your e-mail or phone to receive a message with a one-time PIN to get into your account.  Since you have your phone right next to you, you select text message and wait for a moment.  Sure enough, you just got a text with a number you need to enter into the bank website.  Once you do, you no have access to all your monies!  That is multi-factor, using information from two or more devices to access one site.

Hopefully this hasn’t left you feeling hopeless.  The first step after finding out your information has been stolen is to change your password.  You should also really consider if you actually need that account.  If not, change the password to something complex and meaningless that you’ll never use again, then disable or delete the account.  This ensures that if the account information is stolen later, the credentials cannot be used on another site.

Be safe out there!


REFERENCES:
https://www.cyble.io/
https://www.forbes.com/sites/leemathews/2020/04/13/500000-hacked-zoom-accounts-given-away-for-free-on-the-dark-web/#7ef72e6758c5
https://haveibeenpwned.com/

Sunday, March 22, 2020

Your Computer has a (Corona) Virus

Welcome back everyone!  It has been quite some time since I last posted, I hope you have all been well!  I am now in a new Bellevue Univeristy course (CYBR 650) which requires posts

tl:dr
First, let me say that the title of this post is not intended to be a joke.  With everything going on in the world related to the COVID-19 pandemic, we all need to be cautious and make decisions that are in the best interest of ourselves and our families, and to do so without harming others (I'm looking at you toilet paper hoarders).

Looking for current information on Coronavirus has become a part of our lives, and hackers know this and are trying their best to take advantage of this international emergency.  Different actors are performing a variety of attack vectors from phishing to entire malicious domains.

The increase of coronavirus related phishing has increased drastically recently.  These messages are similar to other phishing attempts in that they are used to try and get your personal information, account numbers, social security number, and even account login credentials.  Additionally, some messages are laced with ransomware.  The ransomware (or other software) appears to be something useful.  Instead, this software is there to encrypt your hard drive and keep all of your information away from you until you pay the hacker their ransom to unlock the system.  Another piece of software parades itself as a Coronavirus map, tracking the pandemic.  This software also contains malware that focuses on stealing your passwords.

More workers are also being directed to telework in order to increase social distancing, which increases the attack surface for hackers to hit.  Rather than an organization controlling information in and out of their networks, their employees are now working on their home networks.  Most likely, these home networks do not have the same level of protection as their work environment.  Unsuspecting users working from home, in an attempt to make their connections more secure, may find themselves with a VPN (Virtual Private Network) that is nothing more than malware written by someone with evil intentions.

Individuals are not the only targets of malicious actors taking advantage of this horrible situation.  Hackers successfully attacked the US Department of Health and Human Services just one week ago (15 Mar 20).  The thought is that the attackers are attempting to slow down the agencies response and spread misinformation to the public.  After successfully breaching the system, the attackers spread a false message of a government plan to implement a nationwide lockdown.

Now that I have properly scared you more than COVID-19 already has, what can you do to protect your digital life?  In my previous posts, I have made recommendations for things such as regularly patching your systems, removing unnecessary software, and using a complex password.  While these things will help you protect your system, you may want to think about the following:

  • Don’t open e-mails from unknown senders
    • While James Veitch shows how much fun it can be to toy with spam senders, some messages can activate malware simply by opening the message.  Better to leave them be and just delete them.
  • Ask your tech support what they recommend for a VPN
    • Some organizations have a VPN you can connect to already, but it most likely has limited bandwidth and number of users.  If they recommend using a VPN, ask which one.  Some VPN providers offer a free service with limited data, but others offer pay services.  For example, I used Windscribe while travelling abroad last year to keep my Internet connection secure.  It was a limited data use, but it did the trick to keep me safe while checking on personal business, like banking data.  See the link below to checkout Windscribe.
    • I can’t recommend any other VPNs because I have not personally used them, but others out there are NordVPN, ExpressVPN, and CyberGhost.  See the TechRadar list below!
  • Don’t give info out to someone over the phone
    • This is probably common knowledge, especially if you are reading this blog, but malicious actors still call people trying to get their info.  Why?  BECAUSE IT WORKS!  Just like phishing, people still give their info to callers.  Stop.  Seriously, just stop it.
  • Be wary of sites you get information from about COVID-19 (or anything for that matter)
    • Domain registrations with a coronavirus theme are 50% more likely to be malicious in nature.  This means you have a pretty good chance of going to a site for info and then having something bad happen.  Be careful, don’t trust corona-virus-info.biz (which I just made up…if you are the owner of corona-virus-biz and are a legitimate business, contact me and I’ll make something else up).

Stay safe out there! See you next time.

Schopp

REFERENCES:
https://fortune.com/2020/03/18/hackers-coronavirus-cybersecurity/
https://www.consumer.ftc.gov/blog/2020/03/ftc-coronavirus-scams-part-2
https://www.infosecurity-magazine.com/news/us-health-department-hacked/
https://www.marketwatch.com/story/hackers-are-using-coronavirus-concerns-to-trick-you-cybersecurity-pros-warn-2020-03-12
https://windscribe.com/
https://www.techradar.com/vpn/best-vpn

James Veitch, More Adventures in Replying to Spam - https://www.youtube.com/watch?v=C4Uc-cztsJo

Sunday, May 29, 2016

Annoying Ask-Agains

Hello reader!  Ready for my Week 11 post?  Are you sure?  Are you sure you're sure?

That was fun, right?  Right?  Right.

You hate the dreaded Windows "Are you sure" boxes, and I'm sure you equally hate the "This programs wants to access your system, will you let it?" boxes too.  Guess what, those are actually a good thing!

Have you ever accidentally deleted an important file, or clicked no too quickly on for something you meant to click yes for?  Of course you have, you're a person with a computer.  Don't be offended, I've done it more than you.

When the operating system asks you if you're sure about an action, it's not trying to be a jerk (contrary to common belief).  It is making sure you meant to do it and keep you safe all at the same time.

Most of the time when you are asked if you want to let so-and-so program run, it's because you asked it to run.  But, what if you didn't ask it to run?  Wouldn't you want the OS to keep you safe and not run a random malicious software you accidentally downloaded along with the latest bootleg of Civil War?  (I'm looking at you Henry, be ashamed)

As annoying as it might be, those pop-ups from Windows are there to keep your system and your information safe.  If random malware was able to run, you would blame Microsoft for not protecting your dirty Internet activity.  Instead, you curse them for making it too difficult to navigate and execute peacefully.

But I digest...digress...something like that.

Thanks for reading for the past few months.  Looking at what is due next week, I probably won't post for a little bit.  However, if you really like to read my randomness all that much, post a comment!  I'm here to support you and will be happy to keep going if you want me to...at least until my next class requires it.  Again, thank you for the support.  Stay safe on the Internet, it's a dangerous place!

REFERENCES:
http://www.howtogeek.com/173478/10-important-computer-security-practices-you-should-follow/
http://www.digitalcitizen.life/uac-why-you-should-never-turn-it-off
http://windows.microsoft.com/en-us/windows/what-is-user-account-control#1TC=windows-7

Sunday, May 22, 2016

Eerie Emergency Prep

Hey reader!  Welcome back to Week 10!

A few weeks ago we talked about backing up your system.  If you don't remember, here is the link: http://cyberschopp.blogspot.com/2016/04/baffling-backups.html

However, there is more to preparing for an emergency than backing up your system.  If something were to happen in your home, how would you know what to do to get your computer(s) up and running again?

Having a plan, sharing it with your family, and updating it regularly are necessary parts of an emergency action plan.  Another step is exercising the plan.  Simulating a loss of data integrity or availability and following your plans' checklist is a great way to make sure you haven't missed anything.

Some of the things you want to consider in your network emergency plan include (but are not limited to):
- reactions to specific events, such as discovered malware or hardware failure
- checklists covering broad responses as well as specific events with special actions
- notification lists, i.e. call Dad if..., or call police if...

Thinking of situations, or pulling crazy ideas from TV or movies is a great way to think about what your reactions would be in a variety of situations.

Thanks for reading!  See you next week.

Sunday, May 15, 2016

Disturbingly Disposal E-mail Addresses

Welcome back for my Week 9 post!

Do you love spam?  I know I do!  Actually, I really don't know because my spam filter gets rid of most of it.

I only have one personal, one business, and one school e-mail address.  So, 3 in all.  Amazingly, I don't see all that much spam...except for what my Gmail filters out that I peruse through on occasion. All that aside, there is much to be said for creating and maintaining an arsenal of disposal e-mail addresses.

If you sign up for more than one service out there, you are bound to come across a company who has no problem selling your e-mail to Hank, the lowly Burger King employee.  Hank will gladly send you spam in hopes you will click on a link of give him a million likes on Facebook.  Nothing against Hank, but ain't nobody got time for that!

Using a disposable address for signing up for site is a great way to not care about what random correspondence you get.

This also clears up your main e-mail to make sure the cookie recipe from Mom doesn't get lost in the crap!

Thanks for reading...if you don't normally look at my references, please look at the second one about responding to a spam e-mail.  It is totally worth the 10 minutes.

REFERENCES:

https://www.google.com/webhp?sourceid=chrome-instant&ion=1&espv=2&ie=UTF-8#q=disposable%20email%20address
https://www.youtube.com/watch?v=_QdPW8JrYzQ

Sunday, May 8, 2016

Inconceivable Identity Theft

Hello reader, welcome to my Week 8 post!

If you had just stolen a few million passwords, how much would you sell them for?  I'm making a big assumption that you are some kind of criminal seeking a profit from someone else's info.  So, how much would you make off this score?

This past week a Russian hacker was selling 272 million unique e-mail addresses and passwords for the whopping price of 50 rubles.  Folks, that about $0.75.  The hacker was quoted as saying, "I am just getting rid of it but I won't do it for free."

This story got me thinking, was my e-mail and/or password one that he was selling?  I took the opportunity to see if I had been "pwned" at the fittingly named https://haveibeenpwned.com/.  It turns out, I have been, but not too recently.  My data was potentially taken during two different breaches in 2013.

So, what should I do?

The Federal Trade Commission has authored a handy guide to help you along if you are unfortunate enough to have your identity stolen, so I won't pretend I can help other than giving you the link below.  But here's the short-and-sweet:

1. Plan ahead - if you have a personal recovery plan to help you through, the process will be much much smoother.
2. Update and track your plan - if a step in your plan doesn't work, or something changes, it won't do you much good at all.  Updating it with current info will be your lifeline if you ever have to use it.
3. Contact - you need to get in touch with the credit bureaus and your banking institutions.  Having preprinted letters for each establishment, again, will help you in the process.

I hope you never have to deal with a full identity theft.  If you do, follow the guide and be committed to clearing your name.  Good luck!!!


REFERENCES:
http://www.vocativ.com/315608/russian-hacker-email/
https://haveibeenpwned.com/
https://www.consumer.ftc.gov/articles/pdf-0009-taking-charge.pdf

Sunday, May 1, 2016

Perplexing Power

Hello reader!  Welcome to my Week 7 post.

When you are done with your computer at the end of the day, do you turn it off or leave that sucker running into the wee hours of the night?  Does it matter?  This weeks post will touch on some benefits for both and then I will give you my recommendation on what you should do.

Leaving it on.  If you leave your system on between uses, this can be used for other tasks.  System updates can be applied at scheduled times during the night when you are less likely to be using the system.  You can also schedule backups, virus scans, or disk defragmentation.  These tasks are necessary to keep your system running optimally, but doing them when you aren't actively using your system keeps you from interrupting your work.  Additionally, you can donate your unused computing power for the greater good.  The World Community Grid will use your computers power to assist their research a variety of problems, such as drugs to fight ebola or mapping cancer markers.  For a more comprehensive list, see the references below.

Turning it off.  Shutting your system down each night will do one thing really well...not use electricity!  If your system is in the same place as you or someone else sleeps, they will not be disturbed by any noises, such as the fan, while they are trying to sleep.  Also, your system does need a reboot occasionally anyway, so you are just helping along the process, but on a more daily basis.

As promised, here is my recommendation.  Turn it off...or leave it on.  Honestly, it depends on how often you use your system.  If you use it everyday for several hours, leave it on.  You won't have to wait for the start up.  If you rarely use it, turn it off after use, or donate your computing power.  The choice is yours, you have the power.

REFERENCES:
http://www.digitaltrends.com/computing/should-you-turn-off-your-computer-at-night/
http://motherboard.vice.com/read/7-ways-to-donate-your-computers-unused-processing-power
https://boinc.berkeley.edu/wiki/Project_list
https://www.worldcommunitygrid.org/discover.action
and just for fun, yet not related at all ;)
http://fivethirtyeight.com/features/the-worst-board-games-ever-invented/