A place to talk about information security, Internet safety and, of course... coffee! Thoughtful, sometimes controversial, but not following the crowd unless I'm in line at the coffee shop.
It's not a new song or a new dance... Amazon has just announced 2-step, aka 2-factor or multi-factor, authentication for online logins! It's overdue but I'm glad it's here.
We've talked about2-factorauthenticationinthepast so I won't go deeply into it in this post. The important take-away is that Amazon now offers this service and you should use it!
The main reason that 2-factor is good and important is that it prevents an attacker, who has stolen your userid and password, from logging in as you. This is because they would need to have your smartphone in addition to the userid and password! (yes, there are other methods as well).
An interesting topic came up the other day. The question was whether to accept random social media
requests. Does your "friend" need to be your friend?
Your answer to that question might vary based on the social network and how you use that social network.
There's also an important Security Awareness angle here. Social networks can be a vector for malicious links, phishingattempts, malware and scams. These malicious techniques often work better when the link/attachment/request comes from a "friend", rather than via a random email or connection.
As seems to often be the case in the fall, I'm doing a number of Internet Safety talks lately. Maybe it's the tie-in with October US Cybersecurity month, and I did somepostscelebratingthat. Maybe it's that fall makes us think about back to school (though maybe safety should be a "hotter" topic in the summer when kids have more free time!).
I've been presenting to groups about Internet Safety and related topics for over 12 years. I've got a few events coming up at work, so I'm updating my material. I've got a number of talks on these "consumer" issues. You can see my slides on my slideshare page. I regularly update my material. But what's really amazing to me is that the core, key messages have substantially remained the same.
For example, I recently did a presentation and blog post on bullying. The biggest change in online bullying in the past few years has been the news media attention. But what happens, how it happens and options for victims, unfortunately, hasn't changed much.
As I talk with people about these issues, and research and update my presentation material, I think there are 3 main areas in which things have substantially changed.
The rise and expansion of social media. In the early 2000's, we were talking about things like email, Chat like AOL Instant Messenger (AIM) and web surfing. Xanga.com was around, but MySpace and Facebook weren't even invented until around 2003! And, needless to say, there's been an explosion of social media sites with the latest trends favoring pictures and video. While kids had the ability to share too much information since the beginning, social media sites really drove the norms.
Technology. In particular... mobile technology. I used to recommend that families keep their computer (singular) in a common place like the family room or kitchen so kids' use could be seen. While that is still good advice, most families have more than one computer. And most teens, and many younger kids, carry a powerful computer with them wherever they go... their smartphone. While we still have options available for monitoring, and good communication is key, portable devices are really a game-changer.
Kids get it. During my Internet Safety talks of the mid-2000's, we used to play a little game. It was a live demo in which I would bring up a social media site, typically MySpace. The game was to see how few clicks it would take us to get to some inappropriate content (like kids/teens sharing too much personal information or posting pictures parents would wish they didn't). When I first started doing this demo it would only take a few clicks. Then, by around 2008, it took more. Then I would just save a few URLs of TMI pages. Then I gave up the game altogether! It's not that we can't still find inappropriate content, or examples of kids sharing far more than parents might want. But kids are doing a much better job of protecting their information online. Of course, kids, teens and young adults - actually digital natives in general - do have different ideas, definition and expectations of privacy compared to their parents!
One final thought... another thing that has changed is that the oldest digital natives - people who do not know of a time without pervasive digital media and technology - are now having their own kids and showing up at Internet Safety talks! But some things don't change and their kids still know more about technology!
What surprises you about changes in our online world over the past decade? What do you think has changed, or has not changed?
Here we go again with more password-related problems. You can't make this stuff up. Well, you can but the truth is stranger.
By now, most people have heard about the Adobe website breach. I won't go into too many details but you can read Adobe's summary here, and here is a detailed review by Sophos.
And, after I wrote this post I see that the This Week In Tech (TWIT) show on the great Twit TV network did a show of the same name (go to 1:56:20 in the show). Great minds think alike! If you read the Sophos report you will see that someone used the phrase "rhymes with assword" as their password hint.
There are a few key points to review:
A new record! This breach has now set the new record for largest number of compromised accounts, 152,000,000, beating previous noteworthy large breaches including those from Sony, TJX and Heartland.
As can happen in a month whose name contains an "a", "e" or "u" :-), Facebook has once again made
changes to its privacy policy and practices. And, as always we all have two choices: accept the changes (and adjust our settings and practices appropriately), or; leave Facebook.
Of course most people won't leave Facebook, and if anything they will add more users than those that leave.
As I look through the changes (see Facebook's notice here with links to the details), I think there are three things to know...
I regularly speak with people about Internet/Online Safety. One message I frequently give about free online services is:
You're not the Customer... You're the Product.
We often see people upset about changes in social networks like Facebook. Folks complain about "customer service", not realizing that they are not the customer! It's often the advertisers, or other backers, who are the real customers. And what those customers want is information... about the users of the service.
I'm a big fan of free online services, but it's important that people realize what's going on. It starts with the privacy policy, which explains how an online service intends to use your data and information about you.
But I want to talk about cloud storage services. These services allow you to backup files, sync files between systems and devices, and have files available from anywhere. How are your files protected?
As the saying goes... the more they stay the same. In our ever-changing world of technology and security, it always amazes me how things often don't change!
Let me clarify... there's always a totally new technology, programming language or social network to learn. Of course, computing power has changed drastically. Many of the techniques used by attackers to gain improper access to our information have changed.
Though many have not. And the advice we give to consumers and business users to protect themselves has not changed! Consider...
Phishing is simply any kind of communication intending to extract (typically) personal information from someone. The scam usually tries to either get the victim to visit a malicious website or directly provide their information, via a reply to the attacker or in an online form. Years ago, phishing emails were easy to spot. They typically used obvious From: addresses, poor grammar and spelling, clearly misleading url's, and overall poor imitation of a legitimate organization's communication. But, as is often the case, the phishers have gotten better. The emails look legit, the grammar and use of language is good, and the links often go to realistic-looking, but malicious, sites. And email isn't the only delivery method. So, how do we avoid, and help others avoid, these attacks?
Last week I avoided talking about Prism, the supposed NSA wiretapping issue that has been all over the news.
However, in the past week I've read or heard 3 different highly insightful analyses and I'd like to comment on them.
First, on the possible techniques used. Major data collection organizations including Facebook and Google have denied providing any information to the US Feds as has been alleged. But the NSA is getting information.
As you may have read, and hopefully enabled, Twitter added a 2-factor authentication capability lastweek.
If you haven't yet turned this on, here's how. Log in to Twitter; select Settings; select Mobile; add and activate your phone. Here are the detailed instructions for adding your phone number. To enable 2-factor authentication, select Account, then check the box labeled: Account security
Here's the good news... as I've discussed in the past, I am a fan of using some kind of 2-factor auth for website authentication. I also like the use of a smartphone for delivering that one-time-use PIN or code. While we still have a digital divide in the US, most people do have a cell phone, and most of those have a smartphone.