Showing posts with label password. Show all posts
Showing posts with label password. Show all posts

Wednesday, October 24, 2018

Protect Your Digital Self: Tech Brawta

It’s a mad, mad, mad, mad world.

Until that changes, and I strongly recommend no breath holding, we have to take the securing to our digital identity into our own hands.

There is no foolproof way to protect our digital identity, but every step towards tighter security is a step further away from digital danger.  So, let’s take a few steps together.

Step 1:  Strong, Unique Passwords

By now, you’ve heard it a million times, but it is clear that some of us, including Kayne West, simply do not listen.  Having a strong, unique password for every account and every device is both necessary and effective.

I no longer expect you to remember every password.  I expect you to use a good password manager like Last Pass or 1Password.  If you’re a Mac, consider using Keychain.  Each of these options will help you create long and complex passwords, keep track of account login information, and add an extra layer of protection for your data.

Step 2: Turn On 2FA

Two Factor Authentication requires you to use a secondary, separate verification method to access your account.  Often, an access code is generated by, or sent to, your mobile phone.  Alternately you may have a dedicated physical device, often called a token.  There are even further options.

Regardless of the 2FA methodology, the short version is, it makes it harder for bad guys to get into your account because it is less likely that they would have both your password and access to your secondary authentication method.

Step 3: Use a Secondary Email Account

Speaking of secondary, do not use your primary email for social media and other non-mission critical website or accounts.

Take the time to set up an alternate email address specifically for registrations.  This account would not be for friends and family, nor would it be for correspondence with your financial institutions.  This account would be exclusively for the ‘other stuff’.

Step 4: Keep Your Devices Updated

You don’t need the latest device, but you do need the latest Operating System (OS) and apps.  Developers are always on the hunt for bugs and vulnerabilities.  They fix these with updates.  Without updates, you may be leaving your system open to hackers.  Close up all possible loopholes by updating your OS, your anti-virus software, your firmware and your applications across all devices.

Step 5: Review and Refresh Settings

Something else developers do, change privacy policies, terms and settings.  Often, without telling you.

So, you may think your profile is private and unable to be shared with third parties, only to find out the hard way that six months after you took nearly an hour to perfectly tweak your privacy settings that the website you visited is using your clever content in a not so clever marketing campaign.

Put to stop to this, or at least try, by periodically reviewing your settings and refreshing where necessary.  Look closely to ensure you didn’t 'opt-in' to something you wish you’d never heard of. Double check to make sure that the privacy policies match your expectations.

These five steps are the first steps, to maintaining the credibility of your identity online.  Execute.  Repeat.




Tune in to @RJR94FM every Wednesday morning at 8:15 AM for #Tech4Life

Saturday, July 15, 2017

Digital Dangers - Quizzes and Memes

It all seems so cute and innocent.  A friend posts a list of all the great concerts they attended to their timeline and encourages you to do the same.  Or maybe, you saw a friend post results from a quiz that revealed something new and you consider trying it too.

STOP.

Be very wary of Facebook quizzes and memes!  It’s true, they may seem fun, but they can also be dangerous.  Yes, dangerous!  Think about the information that you share - Pages you like/places you do business. Mom’s name in the About Me section/security question and answer.

These unassuming quizzes may deliberately, or unwittingly, reveal your personal data to third parties like marketers or hackers.  They are not necessarily as harmless as they purport to be.  At worst, they are click bait, designed to lead users to other sites.  At best, they reveal personal information that in the wrong hands, can be extremely damaging.

Spotting the Danger

Let’s start with the third party quizzes that are prolific on Facebook and that FB is actively trying to limit.  Some of these quizzes do ask permission before posting in your name to the platform.  When they did, did you read their privacy policy?  I’d be willing to bet you didn’t.  If they have access to post on your behalf, what else could they post as you?  How would friends know that you didn’t really initiate the post?

Let’s look at the memes.  Unlike the third party apps, memes just appear as a post from a friend with lots of personal information on them and an invitation for you to share as well and “continue the chain”.  But take a closer look; the answers being revealed are often closely related to common security questions or can provide clues for an effective spear phishing attack.

Steering Clear

If you’d like to avoid unnecessary exposure to hacking and targeted marketing, I highly recommend that you stop using Facebook, Twitter or Google to log into third party apps.  Also, take a moment to review, and as necessary revoke, third party app access to your accounts.  I know it’s tedious, but it is recommended that you have a separate username and a strong, long, unique password for every account.  No short cuts (unless of course, you consider a password manager as a short cut, in which case, go right ahead).

Be vigilant in the protection of your privacy.

Tech4Life airs every Wednesday morning at 8:15 AM


Wednesday, June 22, 2016

T4L: Pass On Passive Passwords

Advisory: Change all your critical account passwords (email, bank, social media) immediately and often.

I agree, it is troublesome to come up with complex and unique passwords for every online account or service (in my case, 82 and counting), but I believe (from anecdotal experience only thank God) that it is less troublesome than having your data, PC, money and or identity stolen, held at ransom, revealed or deleted.

The Problem
So, here is the background, way back (in tech terms at least) in 2012, there was a data breach.  LinkedIn, Tumblr, MySpace (remember them?) and other sites were hacked, releasing some 117 million login details including passwords into the wild.  I can’t say why the data remained underground so long; I can say, however, that the data is available for sale and is being sold to some bad people (yup, that is a technical term).

This affects you (and me), if you haven’t changed your password in a couple of years or if you re-use passwords across different platforms.  The hackers are, right this minute, using the data to attack your accounts.  And, they have succeeded.  High profile celeb accounts like Mark Zuckerberg's were among those compromised this week.  Think about it, he’s one of the world’s greatest programmers, and he was hacked.  Still feel you’re immune?

The Option
You can check if you've been compromised at: haveibeenpwned.com, but personally, I’m busy.  So, I’d rather skip this step, assume all old passwords have been compromised and set new ones.  Even “the leader of the free world” resets his nuclear launch codes periodically, why can’t you reset a few passwords?

So real is the threat, that several sites forced subscribers to reset their passwords to gain access.  They completely denied access with old passwords.  Why not take their lead and take a moment to reset all your passwords.

The Solution
Before you start to complain about the brain power required to compute and mentally store scores of unique passwords, consider a password manager.  Check out cross-platform options like 1Password and LastPass.  Apple ecosystem dwellers can rely on Keychain.  Trust me, this is not the time to skimp; pay for the best service you can afford and enjoy convenient features and options.

While you're at it, going through all your accounts individually and setting up UNIQUE passwords for EACH account, why not take another moment to enable two-factor authentication (2FA) on every account that supports it.  Recently Google made 2FA simpler and other will follow suit, but that is for another post.

The combination of strong, unique passwords and 2FA is , currently, the best protection against hacking.

Tech4Life airs every Wednesday morning at 8:15 am on @RJR94FM

Monday, March 14, 2016

Dare I Be Invisible?

I’ve thought about it.  Stepping off the grid and becoming completely invisible; online at least.

No identity theft.  No public shaming.  No big data marketing manipulation.  No government intrusion.  And yet still, no utopia.

Being invisible is not interchangeable with being private.  Even in this digital age, we can get up, stand up and fight for our right to privacy while still enjoying the spoils of a connected world.  Ready? Set. Fight!

Just as we would not walk down a dark alley without putting up our guard and tightening our awareness of our environment, we should not traverse the digital domain without consciously monitoring our actions.  To maintain our privacy, we must constantly analyze our browsing habits, social media interactions email practices, mobile use and our passwords to maintain our privacy.

Weak Spots

Let’s start with email.  Sure, instant message (IM) services and social media dominate cyber communications, but email is still the bedrock of the online world.  Phishing scams abound!  Be suspicious of password reset notifications (that you never initiated), requests for money or personal info and viruses as each of these can be an assault on your privacy.

Social media, by its very nature, is the antithesis of privacy.  'Social' is designed for interaction, for sharing, for connections.  Yet, this is the space we must be most vigilant in protecting our identity.  For some, it is easy to forget that chatting on the internet is like chatting with a friend at a bus stop; everyone within earshot can hear.  Even if personal data is exchanged in a Direct Message (DM) versus a feed/timeline, the data is “out there”, in a public space for the world to see if they wish.

Assuming you don’t maintain fake accounts, it is certainly important to review, tweak and update your privacy settings regularly.  Facebook, Instagram (IG), LinkedIn, Pinterest, Twitter, Swarm, Snapchat, Periscope and countless other social media sites are known to change their policy, occasionally with little notification to users.

Then, there are the competitions, promotions and third party apps which are cleverly and specifically designed to mine your data under the guise of the chance at a reward.

Firewalls, anti-virus and anti-malware software, private browsing settings, cookie and ad blockers are all tools in the arsenal against prying eyes, but like a .22 calibre bullet on a meth-head, they are limited in scope if your ISP is tracking your browsing habits.  Advanced weapons like Virtual Private Networks (VPNs), Tor browsers and IP spoofing are not for the technologically challenged.

The myriad of devices collecting, collating and processing our personal data is not limited to laptop and desktop computers.  Think smaller.  Think mobile.  Tablets and phones are arguably the greatest tracking tools ever invented.  Their prominent place in our daily lives simply increases their potency. GPS tracking and tagging, insecure apps, ridiculously simple PINs, improper disposal all threaten our personal security.

A Stitch In Time

Here is the cold hard truth.  Your privacy is your right, but rights are not absolute.  That said, there are some steps you can take to defend your rights.

These days, almost everything has a password … your laptop, tablet and mobile phone, your websites and apps, hell - even your front door!  Start with a strong, unique password.  If there is even the whisper of a hack, change it.  In fact, change it every three months just to be safe.

Then, support (never remove) the password.  Two-factor authentication (2FA) is becoming a lot more popular.  When it is available, take it.  Just be sure that you keep your mobile safe too.

Think seriously about encrypting your data … your email, your IM messages … keep the contents between you and your recipient.

And always make a backup, or three.  Yes, three.  If your data is held at ransom, if there is a physical threat or if it is lost or stolen without any discernible reason, you’ll be glad you have a physical backup, an off-site backup and a cloud backup.  And remember, the backup has got to be encrypted too.

I admit, I am addicted to the many benefits of the grid - online shopping, streaming entertainment, seamless video chats with the family overseas.  So I won’t be stepping off soon.  But, I will be stepping up my privacy protocols and you should too.

Sunday, February 15, 2015

T4L - New Age Protection

I am updating my being safe online tips.  After all, it is a new year and there are new threats out there.  What worked last year simply may not be enough for 2015.  So here goes; make some time to not only read but action these safety steps.



Step 1: Back up, run anti-virus, back up again
Do it now, do it again and again.  Only the first back up is hard, each subsequent back up is incremental and therefore doesn’t take much time.  Backing up is your first and best defense against data loss which can happen for more reasons than I have space to mention.  Many systems can automate the process to an external drive or cloud service, so your only excuse is .. none.

Make sure that you download, install, run and update a good anti-malware programme, even for your mobile device.  Get rid of or prevent viruses, adware, spyware and other wares designed to destroy your life.

Step 2: Set Strong Unique Passwords
Passwords can be a pain, but they are also your first line of defense against attacks.  Forget the old rules, passwords now need to be longer than eight characters, need not be a recognizable word and need to be unique for each account.  Yes, you read that right - each account.  Since remembering scores of complicated passwords would be too much, it is time to breakout a good password manager to keep things in check.

Step 3: Secure Everything
It can be tempting to jump on a free WiFi hotspot, skip the hassle of configuring a firewall or browsing quickly through unsecured websites, but try to remember how temptation worked out for Eve.

Take a moment to set up a new password on your home wireless router and all internet enabled devices like IP cameras.  Take a moment to set up a firewall on your ‘outer, turn off Discovery and disable file sharing, especially if you plan to log on to public WiFi.

Step 4: Avoid Scams
Certainly it is not recommended that you click on links in email, but if you do, make sure there is a little lock showing in your browser window confirming that the site is secure.

Speaking of security, secure your credit card by using a dedicated ‘online card’ issued by your bank, a one time/pre-paid card or a service like Paypal to create a safety zone around your prized plastic.

Online email services like Google, Yahoo! and Outlook all offer built in virus scanners to reduce the likelihood of nefarious downloads, but it is good to remain vigilant.

Step 5: Repeat
Yes, repeat.  Continuous protection requires continuos updating.

Here’s to a safe 2015!

Tech4Life airs every Wednesday @ 8:15am on RJR94FM

Thursday, July 15, 2010

Tech: IT Easy - Get a life | And your phone is not it


When the realisation dawns on you that all your contacts, pictures and emails are gone, it can be devastating. Admit it, our phones are an integral part of our lives. Personally, I can't even remember what life was like before the BlackBerry phone. But it is not the phone that is so important, it's the information contained within that is truly part of the fabric of our lives.

Yet, we treat our phone with such scant regard. We leave them at the bank, the restaurant and our friends' house. We keep them out in the open and thieves steal them. We simply forget where they are. Fortunately for us, technology can find our phones for us.


Send feedback to: techiteasy@carlettedeleon.com