Posts

Olympic Games Breach Disclosure Window Opens

Image
The London Olympic 2012 Games has finally arrived, and will dominate media headlines around the world for the next couple of weeks. This is a great time for sports fans, but also a great time for firms to disclose data breaches. Yes, I know I'm being really cynical but let's see what breach notifications occur during this festival of sport.  As I write this post Google have just announced they are in breach of a UK Privacy agreement -  http://www.bbc.co.uk/news/technology-19014206 , admitting to have not deleted personal data gathered as part of their Street View surveys. This personal data should of have been wiped over 18 months ago! But back to my main point with this post today, as with this awkward privacy announcement, the media coverage of it will be swiftly buried within the media's frenzy of Olympic headlines, hence why companies PR teams choose specific dates to publicly announce their data breaches. 

How to Protect Your Gmail Account from Hackers

Image
Hackers target online Email accounts for a reason, they know if they can 'own' a webmail account, they can access it from anywhere and at any time, to use it as a tool and to harvest information of value. Fraudsters will often rifle through compromised Email accounts looking for information which will grant them access to more lucrative web accounts. A quick search of pretty much any Email inbox reveals information about various online accounts used by the user, many of which will have potential fraudulent earning revenue to a hacker. Typically Emails containing information about e-commerce websites and online banking accounts will light up a hacker's eyes. In this post I'm going to explain typical techniques employed by online fraudsters, to highlight the vital importance of protecting your main Email account. No Account Username, No Problem As a security feature some website accounts don't use an Email address as a username, but invites account ho...

Flame Culprit Fingered

Image
Flame, also known as Flamer and Skywiper, is a highly sophisticated espionage focused malware, which targets and infects Microsoft Windows systems. Flame is known to spread over the network and by USB thumb drives, and this malware is centrally controlled by 'those' who created and released it onto the world, more on 'those' later. To say Flame is an extremely sophisticated piece of malware is not an understatement,  it can covertly can grab screenshots, log all keyboard entry (think usernames, passwords), record Skype voice calls and even monitor network traffic,  returning all this information is sent covertly to "those" who created it. Those controlling Flame infections can even send specialised control commands, which includes a "kill command", which makes the Flame malware stop running and delete itself, so covering up any evidence of it ever being present on the PC. Flame: Commendable Malware Flame is not the product of cyber criminals...

LinkedIn Password Breach: Change Your Password Now

Image
Yesterday we learnt a hacker posted 6.5 Million LinkedIn passwords onto a Russian forum. These passwords were weakly encrypted (that's an unsalted SHA-1 hash for the techies), which means the actual passwords can be recovered by the bad guys with very little technical ability. Advice to LinkedIn Members 1. Change your LinkedIn Password Right Now 6.5 Million accounts may only be a portion of the total LinkedIn membership, and you may not consider your account as being affected because you have yet to receive a warning message from LinkedIn.  However in my view it is highly likely the bad guys will have ALL the LinkedIn account details and passwords for all LinkedIn users. So assume your account login (Email) and password is known by the bad guys, given this it is essential to change your LinkedIn password as soon as possible. 2. If your LinkedIn password is the same password you use on any other websites, Change Those Passwords Most people use the same password on different ...

The problem of Securing the New iPad 3 within Business

Image
Apple announced the latest edition of their fantastic iPad today, not only is this device irresistible for consumers, but it has become irresistible for business.  This presents a new challenge for information security professionals, as the iPad has been bred for consumerization not for business usage, yet the business application capability of tablets are undeniable. Within main stream businesses up and down the land a change is afoot, it is no longer about giving the odd few magpie like senior executes the latest shinny new toys, as there is an unquenchable thirst for Apple’s latest tablet gadget emanating across entire businesses. This is not a time to have heads buried in the sand and wishing for risk aspects of business usage of tablets to go away, the tablet is coming to a business near you. In a few years from now they will be as common place on office desks as laptops, and will be smugly grasped by the majority of attendees within meeting rooms. But let us not forget, a ...

SmartPhone App Security Advice

Image
Smartphones really are a fraudster’s paradise, there are so many opportunities for fraudsters to monetise from them. From Rogue Malicious Apps sending premium rate text messages costing up to £6 a text, to stealing the personal information and passwords held on them. And there are even further fraud opportunities with smarphones being increasingly used for making Payments and with Online Banking. These factors together with a general smartphone user security naivety, are a major incentive for the bad guys to target these little handheld cash cows. So it is no surprise cyber attacks targeting smartphones are rapidly increasing in the UK, "800% increase in cyber attacks on smartphones" (Nov 11)  http://www.mirror.co.uk/news/top-stories/2011/11/07/800-increase-in-cyber-attacks-on-smartphones-115875-23543307/ .    In this post we will look at how to go about protecting against one of the most commonly successful attacks a...

Why PCI DSS is good for Information Security

Image
There is a growing consensus within the Information Security Community that the Payment Security Industry Data Security Standard (PCI DSS), is actually proving to be detriment to the general information security across the business. One point regularly made is the Payment Card Industry standard is responsible for diverting precious funding and resource away from the overall business information security strategy, where the breach risks can be much greater for the overall business.  That well maybe the case in larger enterprises which rightly regard best practice information security as a business priority, but consider the medium to small businesses, this is the land where information security ignorance is bliss. Within such SMEs  PCI can be a real InfoSec wake up call, as in merely attempting to comply with the many PCI DSS requirements, it can provide benefits across the business, where before the business were previously completely unaware of the risks...