Showing posts with label security. Show all posts
Showing posts with label security. Show all posts
Friday, March 22, 2013
Downloading
This is by far one of my biggest pet peeves. Fake Download Buttons. It bothers me that so many people are unaware of which ones to avoid (they're usually the biggest and flashiest!), and it bothers me that it works. I would love to be able to help others to learn to differentiate between fake and legitimate downloading buttons. One of my favorite places to download programs is cnet.com, as they keep everything verified and you're less likely to accidentally click on a download button that takes you to a malicious site or downloads a malicious program. This article definitely has some good pointers of how to avoid clicking on those dreaded fake downloads: http://www.pcworld.com/article/2012958/how-to-avoid-fake-download-buttons.html. I suggest EVERYONE go and check this out. It's worth it.
Monday, March 18, 2013
Data, Security Pros, Scary
I read this article because of the title: "Why IT security pros can be scarier than the 'bad guys'". I could understand why they can be, but this article took it in a direction that I wasn't expecting. Our data is always being used and mined for information, to the point where businesses can target us better. Even this post about the article will be used in some way. Because our information is being collected, we could always ask the companies to not track us, but sometimes that defeats the purpose of why you're using them in the first place. For example the article mentioned Pinterest, due to the growing usage of pinners. I have plenty of information, and I know data about me is being collected. However, I love the use of Pinterest in my life, from recipes to inspirational quotes, so I willingly give them my information. I don't think we need to be scared at the way information is being collected, I think we all just need to be aware that we are willingly giving them that information about us by utilizing their products.
http://www.pcworld.com/article/2029705/why-it-security-pros-can-be-scarier-than-the-bad-guys.html
http://www.pcworld.com/article/2029705/why-it-security-pros-can-be-scarier-than-the-bad-guys.html
Labels:
big data,
pcworld,
privacy,
security,
social media
Tuesday, March 5, 2013
Windows 8
This was definitely an interesting article to read. For one, I am not rushing to get a computer with Windows 8. Once it's been more fine-tuned and worn-in, then maybe, but I'm not itching for it. This article was discussing the "hidden" security features built in with Windows 8, and that if you are thinking of getting it then you should purchase a new computer with updated hardware rather than just updating your OS. I understand where they're coming from, but it also felt like they were trying to "sell" the reader on upgrading their computer and spending more money (when we all know that this will be outdated quickly). I've had my laptop since the beginning of college, and my goal is to make it until graduation (whether from grad school or just with my undergrad is a different matter...). I've succeeded so far in my goal, but it's also 'cause I'm trying to take care of it and I won't be sucked in to buying a brand new laptop that'll be outdated immediately. Technology is growing at a rapid rate, and unless you have your heart set on one particular computer and have had it set on it for months, you have to be willing to bide your time before upgrading. Kind of like with cell phones... I really want a Galaxy SIII or SIV, but I also realize that by the time I need a new phone, there will be plenty of even greater options out there and it's not worth my money right now.
http://www.pcworld.com/article/2027593/windows-8-put-its-hidden-security-features-to-work-.html
http://www.pcworld.com/article/2027593/windows-8-put-its-hidden-security-features-to-work-.html
Saturday, March 2, 2013
Evernote was Hacked!
Oh no! Evernote is my favorite ever! They are requiring every single user to go in and change their password, which is a smart move on their part. It seems that it was a coordinated attack and that Evernote blocked the attacked when it noticed the suspicious activity. According to their blog, none of the data was accessed, changed, or lost, and none of the payment information was accessed either. Evernote posted in their blog some basic steps that you can take to protect yourself, for those who don't have any experience with security, and they've made it so you have to login and change your password before you can access your data and sync it up again. For more information about this exploit, you just need to check out their blog and any articles that may be about it!
http://evernote.com/corp/news/password_reset.php
http://www.techhive.com/article/2029974/evernote-reports-hack-attack-tells-users-to-reset-passwords.html
http://evernote.com/corp/news/password_reset.php
http://www.techhive.com/article/2029974/evernote-reports-hack-attack-tells-users-to-reset-passwords.html
Wednesday, February 27, 2013
I Love Twitter
So this article about Twitter implementing a standard to fight phishing is good news for me. I appreciate it (and applaud it) when companies implement strategies and software so that their consumers can have a better experience. I use twitter a lot, and I would prefer to not receive emails that could potentially hack my account. DMARC - the technology being used by Twitter now - is also being used by Gmail, Hotmail, Yahoo, AOL, Facebook, Paypal, and Amazon. I was excited to see this news, which is why I am sharing it with you all. Going along with my security focus in this blog, be sure to always check thoroughly who is sending you an email, especially if they're asking you to re-login on a site. If you ever have any doubts about the email, contact the company directly and get verification. It's not worth losing access to your accounts and the data that you may have shared with any of them!
http://www.pcworld.com/article/2028993/twitter-implements-dmarc-standard-to-fight-phishing.html
http://www.pcworld.com/article/2028993/twitter-implements-dmarc-standard-to-fight-phishing.html
Thursday, February 21, 2013
Younger Attackers
Not surprisingly, more malware and viruses are being created by children and teenagers. According to an article on PCWorld, an 11-year old Canadian boy was the creator of a piece of malware that was being used to acquire passwords to games. There are easy interfaces being created that allow children and teenagers to learn how to program and engineer these pieces of malware, so of course they're going to take advantage of it. Being so young, they may not have any real malicious intent, but that will be most likely to change as they get older. Children play more and more games that require higher skills, and so they're tempted to try something with a little more "thrill" to impress their friends. Again, we all need to be sure that we are keeping our devices protected from all different types of threats.
Tuesday, February 19, 2013
Big Data...
It's all the rage, and this article points out the challenges that are being faced by companies when it comes to collecting data. Consumers (like me!) are realizing that they don't always want their data being collected and tracked, and they are limiting what companies will collect. However, some companies are starting to take advantage of that, by allowing customers to have control and willingly share information that they are comfortable with giving the company. It's brilliant, in my mind, because then companies will be able to gain more specific information that pertains to the consumer, and it will allow the company to focus more directly on what matters to the customer. The article mentioned that, and I think it's a great idea. Consumers are looking to keep their data private and secure, and they want to make sure that information about them isn't being used in a way that's not acceptable. I recommend reading the article, because as much as there is a demand for data analysts, I feel like it's going to subside at least a little bit due to consumers protecting themselves.
http://www.pcworld.com/article/2027789/big-data-collection-collides-with-privacy-concerns-analysts-say.html
http://www.pcworld.com/article/2027789/big-data-collection-collides-with-privacy-concerns-analysts-say.html
Sunday, February 17, 2013
Protecting Your Wi-Fi
This article gave instructions of how you should change your wi-fi password. The nitty-gritty details weren't what I was too interested in, but I did enjoy that they pointed out that even the password to your network will need to be changed often, not just the ones to your accounts on online sites. People can still cause damage to you if you're not protecting the access to your network, so it's good to make sure that you have taken every necessary precaution to protecting yourself. It's not easy to have everyone in your household go and change their password, and they may all get really annoyed with you, but the protection that you gain from it is worth it.
http://www.pcworld.com/article/2026340/change-your-wi-fi-password-on-various-devices.html
http://www.pcworld.com/article/2026340/change-your-wi-fi-password-on-various-devices.html
Wednesday, February 6, 2013
Jailbreak
For the longest time, I never quite understood what "jailbreaking" your phone was. And I didn't really care about it, as I was perfectly fine with using my iPhone with only iPhone apps, and I felt it was other people's choices to jailbreak their phones or not. I came across an article on Wired about how Apple was trying to prevent federal regulators from legalizing jailbreaking. They stated that it could bring about "'potentially catastrophic' cyberattacks", however all of the cell towers are still up and working. Jailbreaking allows users to run whatever apps they would like, rather than being limited to just that particular App Store, by giving root access to your device.
I can definitely see the potential for attacks that this enables, but the jailbreak is able to be done by exploiting five bugs that are already in the code for iOS. I feel like if a person is serious about attacking others, then they wouldn't do it through their mobile phone or even their tablets. They would most likely want to use their laptop or desktop computers, but that's my opinion and I feel like I have more flexibility and control over my laptop than over my cell phone.
Apple has stated that they have put in these protection measures in the iOS devices to help prevent jailbreaking and the potential threats that accompany it. However, I feel like this needs to be treated similar to our computers. I have protective measures in place to help prevent myself from being attacked/exploited/damaged. I am sure that if I truly had the desire to attack others (which I don't), then I could. I don't have that desire, so instead I take protective and preventative measures to protect myself from those attacks. I would be okay with doing the same thing for my phone, honestly, if that would be what could help protect my data.
http://www.wired.com/threatlevel/2013/02/cell-towers-survive-jailbreak/
I can definitely see the potential for attacks that this enables, but the jailbreak is able to be done by exploiting five bugs that are already in the code for iOS. I feel like if a person is serious about attacking others, then they wouldn't do it through their mobile phone or even their tablets. They would most likely want to use their laptop or desktop computers, but that's my opinion and I feel like I have more flexibility and control over my laptop than over my cell phone.
Apple has stated that they have put in these protection measures in the iOS devices to help prevent jailbreaking and the potential threats that accompany it. However, I feel like this needs to be treated similar to our computers. I have protective measures in place to help prevent myself from being attacked/exploited/damaged. I am sure that if I truly had the desire to attack others (which I don't), then I could. I don't have that desire, so instead I take protective and preventative measures to protect myself from those attacks. I would be okay with doing the same thing for my phone, honestly, if that would be what could help protect my data.
http://www.wired.com/threatlevel/2013/02/cell-towers-survive-jailbreak/
Labels:
mobile,
operating system,
protect,
security,
wired
Wednesday, January 30, 2013
Encryption
I found some really fun articles (when browsing through PC World) about how to encrypt your data and protect your laptop. They recommend passwords, but passwords can be easily broken, so even that shouldn't be your only protection. It's a basic protection procedure, much like locking your door in your home; it's not perfect, but it's a good first step.
There are some really great backup software possibilities out there, too! They mentioned Dropbox, and that is a great way to keep some documents safe. Again, though, that's typically protected by only passwords. Some other great backup software is Carbonite and Acronis. They're both going to cloud storage data, and I have heard amazing reviews for Carbonite. Check 'em out if you're looking for backup options!
My favorite back-up plan: I have an external 2TB hard drive that I use only for my backups of all my data. Only problem is when I forget to update it, which is when the cloud backups like Carbonite and Acronis come in handy.
Anyway, I hope that you guys have fun, and you should check out these articles!
http://www.pcworld.com/article/2025462/how-to-encrypt-almost-anything.html
http://www.pcworld.com/article/2025897/a-road-warriors-guide-to-locking-down-your-laptop.html
There are some really great backup software possibilities out there, too! They mentioned Dropbox, and that is a great way to keep some documents safe. Again, though, that's typically protected by only passwords. Some other great backup software is Carbonite and Acronis. They're both going to cloud storage data, and I have heard amazing reviews for Carbonite. Check 'em out if you're looking for backup options!
My favorite back-up plan: I have an external 2TB hard drive that I use only for my backups of all my data. Only problem is when I forget to update it, which is when the cloud backups like Carbonite and Acronis come in handy.
Anyway, I hope that you guys have fun, and you should check out these articles!
http://www.pcworld.com/article/2025462/how-to-encrypt-almost-anything.html
http://www.pcworld.com/article/2025897/a-road-warriors-guide-to-locking-down-your-laptop.html
Monday, January 28, 2013
Zombies
Yes, zombies. We all love them (and if you don't, you still know the hype). But there's a different type of zombie - that a really great article pointed out to me - that we should all be aware of. These are "Zombie Accounts". This article pointed out how many of use create accounts, or link websites/applications, that has access to a lot of personal information. We all try to be safe, but I think we tend to forget about these accounts and that they exist. The author of the article used MySpace as an example, and how he doesn't use it anymore but it still has a lot of information about him stored in it.
I love these types of articles where it's reminding us of different ways we can improve on securing our information. There are a lot of obvious ways that most of us don't seem to realize, and it's good to keep up on how to protect yourself. This particular article is an easy and great read, and the comments after the article are also worth reading. As one comment mentioned, all we need now is a program to help us find all of our lost and zombified accounts!
http://www.pcworld.com/article/2026090/how-to-prevent-zombie-accounts-from-haunting-your-digital-identity.html
I love these types of articles where it's reminding us of different ways we can improve on securing our information. There are a lot of obvious ways that most of us don't seem to realize, and it's good to keep up on how to protect yourself. This particular article is an easy and great read, and the comments after the article are also worth reading. As one comment mentioned, all we need now is a program to help us find all of our lost and zombified accounts!
http://www.pcworld.com/article/2026090/how-to-prevent-zombie-accounts-from-haunting-your-digital-identity.html
Wednesday, January 23, 2013
The Java Problem
It's been a little while since the zero-day exploit, but I decided to look up some articles about it now that Oracle has released an update. There were two vulnerabilities that created the opportunity for the exploitation, and Oracle released an update fixing only one of them. If attackers can find another vulnerability then we are right back where we started. There is always the opportunity for more threats, so while it should be safe for users to have an updated Java (Java 7 Update 11), I have continued to leave my Java browser plug-ins disabled on my computer. I'd prefer to be a safe than sorry.
http://www.pcworld.com/article/2025797/oracles-java-patch-contains-new-holes-researchers-warn.html
http://www.pcworld.com/article/2025797/oracles-java-patch-contains-new-holes-researchers-warn.html
Tuesday, January 15, 2013
Facebook & Twitter!
Fun news! There are some filter-type software and monitoring programs for Facebook and Twitter! They will monitor and alert you to any malicious activity, such as when your friends' updates are spam and scams and what-not. There's also programs now to help monitor your child's Facebook and Twitter accounts to make sure that they are posting appropriate content (if you are a parent).
These seemed to point out to me that the attacks really can originate from anywhere, including your social networking sites. It's also a good reminder that you shouldn't put all of your information ("overshare" was the term they used in the article) up on your profiles, as some of it may be critical and can open your accounts to a higher chance of being compromised. One of those friendly articles that reminds you of how dangerous the internet really can be, and yet how wonderful and useful it is, too.
http://www.pcworld.com/article/2010916/lock-down-your-social-media-with-essential-security-add-ons.html
These seemed to point out to me that the attacks really can originate from anywhere, including your social networking sites. It's also a good reminder that you shouldn't put all of your information ("overshare" was the term they used in the article) up on your profiles, as some of it may be critical and can open your accounts to a higher chance of being compromised. One of those friendly articles that reminds you of how dangerous the internet really can be, and yet how wonderful and useful it is, too.
http://www.pcworld.com/article/2010916/lock-down-your-social-media-with-essential-security-add-ons.html
Monday, January 14, 2013
The FBI should have hackers?
I was reading through wired.com today, originally I was working on another assignment for a different class, and I saw the article "The FBI Needs Hackers, Not Backdoors". It caught my attention, so I decided to read through it.
The FBI is saying that there should be "mandatory wiretap backdoors" in all of our new technological devices such as smart phones, tablets, etc. According to the article, "For the last few years, the FBI’s been warning that its surveillance capabilities are "going dark," because internet communications technologies — including devices that connect to the internet — are getting too difficult to intercept with current law enforcement tools". However, what the authors' of the article suggested is that the FBI should use the vulnerabilities that are in place already instead of creating new vulnerabilities with a mandatory backdoor. AKA the FBI should get better at hacking - or they should hire hackers - to solve their problem. There's a lot more information contained within the article regarding it, and you can find it here: http://www.wired.com/opinion/2013/01/wiretap-backdoors/
Happy reading!
The FBI is saying that there should be "mandatory wiretap backdoors" in all of our new technological devices such as smart phones, tablets, etc. According to the article, "For the last few years, the FBI’s been warning that its surveillance capabilities are "going dark," because internet communications technologies — including devices that connect to the internet — are getting too difficult to intercept with current law enforcement tools". However, what the authors' of the article suggested is that the FBI should use the vulnerabilities that are in place already instead of creating new vulnerabilities with a mandatory backdoor. AKA the FBI should get better at hacking - or they should hire hackers - to solve their problem. There's a lot more information contained within the article regarding it, and you can find it here: http://www.wired.com/opinion/2013/01/wiretap-backdoors/
Happy reading!
Sunday, January 13, 2013
Security of IS and What It Means to Me...
I needed to start a journal for my Security of Business Information Systems class, so I decided a blog would be appropriate for me. Now that I've attended class, here's some clips of what I thought about the subject during the first day, near the beginning, during, and after it finished (bottom to top):
Then I got my textbook, I read through the chapters, and I absolutely love it. I even took a picture of my "textbook" (it doesn't feel like a textbook to me) the day that I started reading it:
I love this subject, and I'm so excited to learn more. It's taken me a little bit to get this journal/blog up and going, but I'm aiming to post on Tuesdays and Thursdays about security and news articles and any of my thoughts regarding it. I loved learning about the different types of attacks (malware and everything else) that can happen to a computer, and I am looking forward to learning how to protect it better. I haven't felt this excited about a subject in a long time... and I think that this may be the start of something really good. Maybe the start of what I want to focus on, even, during my career. We'll see how the semester goes, but - as it is - I am so excited/passionate about this class, and I want to learn as much as I can during it. So until my next awesome post... have a great day!
Then I got my textbook, I read through the chapters, and I absolutely love it. I even took a picture of my "textbook" (it doesn't feel like a textbook to me) the day that I started reading it:
I love this subject, and I'm so excited to learn more. It's taken me a little bit to get this journal/blog up and going, but I'm aiming to post on Tuesdays and Thursdays about security and news articles and any of my thoughts regarding it. I loved learning about the different types of attacks (malware and everything else) that can happen to a computer, and I am looking forward to learning how to protect it better. I haven't felt this excited about a subject in a long time... and I think that this may be the start of something really good. Maybe the start of what I want to focus on, even, during my career. We'll see how the semester goes, but - as it is - I am so excited/passionate about this class, and I want to learn as much as I can during it. So until my next awesome post... have a great day!
Subscribe to:
Posts (Atom)

