Showing posts with label Twitter. Show all posts
Showing posts with label Twitter. Show all posts

Monday, October 26, 2015

The Celebration Continues - Building the Next Generation

  We have arrived at our last week of celebration of US Cyber Security Awareness month!

   I've been posting comments in line with the weekly themes put together by DHS.  This week the theme is Building the Next Generation of Cyber Professionals.

   Whenever information security managers get together, one of the topics is often the talent crunch.  In almost any metro area in the US there is close to zero unemployment in security.  Add to that the coming brain drain as the baby boomers retire, and we have a looming problem.

   On the positive side, we're seeing more university and community college infosec programs.

   But there is more work than people.  The federal government estimates that they need 10,000 new infosec professionals in the coming years.  How is that going to work?

Tuesday, December 3, 2013

Is Your "Friend", Your Friend?

   An interesting topic came up the other day.  The question was whether to accept random social media
requests.  Does your "friend" need to be your friend?

   Your answer to that question might vary based on the social network and how you use that social network.

   There's also an important Security Awareness angle here.  Social networks can be a vector for malicious links, phishing attempts, malware and scams.  These malicious techniques often work better when the link/attachment/request comes from a "friend", rather than via a random email or connection.

Tuesday, July 2, 2013

Want someone's password? Just ask!

   SC Magazine recently put out an article entitled: More users than ever experiencing phishing attack attempts.  According to the article, phishing attacks are on the rise.

   Phishing is simply any kind of communication intending to extract (typically) personal information from someone.  The scam usually tries to either get the victim to visit a malicious website or directly provide their information, via a reply to the attacker or in an online form.

   Years ago, phishing emails were easy to spot.  They typically used obvious From: addresses, poor grammar and spelling, clearly misleading url's, and overall poor imitation of a legitimate organization's communication.

   But, as is often the case, the phishers have gotten better.  The emails look legit, the grammar and use of language is good, and the links often go to realistic-looking, but malicious, sites.  And email isn't the only delivery method.

   So, how do we avoid, and help others avoid, these attacks?

Tuesday, May 28, 2013

Twitter 1-and-a-half Factor Authentication

   As you may have read, and hopefully enabled, Twitter added a 2-factor authentication capability last week.

   If you haven't yet turned this on, here's how.  Log in to Twitter; select Settings; select Mobile; add and activate your phone.  Here are the detailed instructions for adding your phone number. To enable 2-factor authentication, select Account, then check the box labeled: Account security

   Here's the good news... as I've discussed in the past, I am a fan of using some kind of 2-factor auth for website authentication.  I also like the use of a smartphone for delivering that one-time-use PIN or code.  While we still have a digital divide in the US, most people do have a cell phone, and most of those have a smartphone.

   But there are some issues.

Tuesday, March 12, 2013

lnk.shrtnrs (Link Shorteners) and Safety

   Recently I was speaking with a group about online safety.  Keeping to the basics, we discussed two main sources of problems: passwords and clicking on links.  I've discussed passwords a number of times here, here, here and here.

   One great way to avoid problems online is simply to not click on links!  Of course, that would probably render the web all but useless to you (well... I guess you could just type in url's but that would get old very quickly).  You probably followed a link to get to this post.  Actually, you probably followed a shortened link to get to this post.