Cybersecurity & Privacy
Don't fall victim to cyber crime this holiday season
[caption id="" align=“alignnone” width=“2500”] Image by Tex Texin used under Creative Commons License [/caption] The holidays are almost here and present a wonderful excuse to kick back and enjoy some great moments with family & friends. Too bad criminals never take time off and love the holiday period. Expect an increase in cyber-attacks against regular online netizens trying to shop for that perfect gift. Expect cyber criminals to use their full arsenal of tools in an attempt to trick you into divulging your personal information (address, Date of birth, Social security number, banking, etc).
Apple Messages most secure messaging platform
[caption id="" align=“alignnone” width=“2500”] Image by Daniel Dudek-Corrigan used under Creative Commons License [/caption] The Electronic Frontier Foundation has released an interesting comparison chart showing how well the most common instant messaging platforms compete on security. The EFF analysis looked at these criteria: Encrypted in transit Encrypted so the provider can't read it Can you verify contacts identity Are past communication protected if keys are stolen Is the code open to independent review Is security design properly documented Has the code been audited
The biggest mistake CIOs are making today
[caption id="" align=“alignnone” width=“2500”] “more than they can chew” Image by JD Hancock used under Creative Commons License [/caption] First we saw digitization, then came appification, then gameification, then personalization and now we enter the era of hyper-personalization. Every consumer wants to feel loved, understood and wants to feel special. Being understood and being special means companies must understand the individual likes/dislikes of each consumer then tailor the consumer's experience during each interaction. This is done through signals and large companies have spent billions building and buying heavily used apps/service so that they can collect more.
The BIG security risk lurking in your email
Many of our most valuable assets are now online (banking, backups, social media, etc). Losing control of these means weeks of work to rectify the situation. Most internet users often forget that their security is only as good as the weakest link and in most cases the weakest link is email. If a hacker gains access to your primary email account, they can then go through you emails, figure out what services you use and request a password reset from those services (which will most often send the reset link to your email account).
IOS 8 means Apple can't unlock your device for law enforcement
The slow and consistent Snowden leaks about how everything we do is monitored, recorded and analysed is freaking some people out. And this extra customer push may be what was needed to finally improve on-device security for our most personal devices (aka smartphones). Apple announced (link) that IOS 8 is a big move for IOS device security because it is now "technologically impossible" to access data stored on a passcode or TouchID locked device. Apple says they can no longer bypass device security.
Check if your accounts have been hacked
Another day, another hack. It seems there is another media story every week talking about a site getting hacked and thousands (or millions) of account being compromised. Companies have Information Security teams that track these breaches to protect their users, but how does an average user protect himself? As an average user, you are on your own but there are sites that can help. One of these sites is called haveibeenpwned.com (link) <img src="https://ekiledjian2.micro.blog/uploads/2025/dae5e9461d.jpg" alt=""> You enter your address and the site will check if it was included in any of the breach leaks they track.
Russian government offer $111,000 to de-anonymise TOR
The Russian government has released a tender worth $US111,000 (4 million rubbles) to device and implement a technology to decrypt TOR traffic and to de-anonymize users. The Russian government says this will help their law enforcement efforts by catching criminals using TOR to hide their tracks. You can read the official procurement notice from the Russian Ministry of Internal Affairs here (link). Contest is only open to Russian organizations (application fee is about $US5,500) and contest closes August 20.
Thousands of Wordpress sites compromised
WordPress is an extremely popular blogging platform that makes extensibility easy through thousands of third-party plug-ins. Now one of those plug-ins, called MailPoet (link), is causing issues for thousands of sites (some estimate the number to be between 50,000-100,000). A MailPoet vulnerability has been discovered and exploited in the wild that allows attackers to inject malware, spam or defacement webpages into any site running the vulnerable plug-in without authenticating. CEO of Sucuri, a security research firm, has seen a huge spike in sites being compromised by cybercriminals to install and deploy backdoors.
Scan that file
[caption id="" align=“alignnone” width=“2500”] Image by Surian Soosay used under Creative Commons License [/caption] This blog is a hobby and in my day job (as the Chief Information Security Officer of a major international company) I see all kinds of attacks and malware. A considerable amount of infections are caused by users who run files that subsequently infect your machine. Doing so is as foolish as having unprotected sex. Before you run any file, make sure you scan it first. You should always scan files using the antivirus on your computer first but there are also 2 very good services that scan your file using over a dozen different scanners (since no one scanner detect every malware),
Protect your online accounts from compromise before its too late
[caption id="" align=“alignnone” width=“2500”] Image by David Goehring used under Creative Commons License [/caption] As more and more of our services are delivered through cloud services, it becomes increasingly important to protect our accounts. As a security professional there are a handful of steps I perform regularly that many of you don't so here they are: Install a well respected antivirus/antimalware software on your PC with real-time protection enabled and regular automatic updating of its database. There are hundreds of online posts discussing which one is "