It's US Cyber Security Month and the key themes I've been discussing here for years are very bit as relevant today. In honor of Cyber Security Month I'm re-running a post from 2016. The more things change, the more they stay the same. Happy Cyber Security Month!
Well, I was trying for something catchy like Stop, Drop and Roll. That's a saying we learned in school, back in the day, for what you should do if your clothes catch on fire.
Fortunately, it seems like everyone has heard that saying and it rolls off the tongue.
Unfortunately, my three word phrase Patch, Vault and Fob, is not nearly as catchy.
Fortunately, the odds of your clothes catching on fire is low.
Unfortunately, the odds of your software, browsers or accounts being compromised is very high.
A couple of weeks ago the internet was hit with the highly impact-full and publicized distributed denial of service (DDoS) attack on Dyn, a DNS provider. I won't go into the details here but I think I will cover DDoS in a future post. Anyway, shortly after that I was chatting with someone at a dinner who asked me about this attack, internet safety in general and what they could do. To keep it simple and because, as a math person I like things in 3's!, I provided these 3 simple (well, maybe straight-forward is more accurate) things that absolutely everyone should do at home...
A place to talk about information security, Internet safety and, of course... coffee!
Thoughtful, sometimes controversial, but not following the crowd unless I'm in line at the coffee shop.
Showing posts with label fob. Show all posts
Showing posts with label fob. Show all posts
Tuesday, October 31, 2017
Tuesday, November 8, 2016
Patch, Vault 'n Fob
Well, I was trying for something catchy like Stop, Drop and Roll. That's a saying we learned in school, back in the day, for what you should do if your clothes catch on fire.
Fortunately, it seems like everyone has heard that saying and it rolls off the tongue.
Unfortunately, my three word phrase Patch, Vault and Fob, is not nearly as catchy.
Fortunately, the odds of your clothes catching on fire is low.
Unfortunately, the odds of your software, browsers or accounts being compromised is very high.
A couple of weeks ago the internet was hit with the highly impact-full and publicized distributed denial of service (DDoS) attack on Dyn, a DNS provider. I won't go into the details here but I think I will cover DDoS in a future post. Anyway, shortly after that I was chatting with someone at a dinner who asked me about this attack, internet safety in general and what they could do. To keep it simple and because, as a math person I like things in 3's!, I provided these 3 simple (well, maybe straight-forward is more accurate) things that absolutely everyone should do at home...
Fortunately, it seems like everyone has heard that saying and it rolls off the tongue.
Unfortunately, my three word phrase Patch, Vault and Fob, is not nearly as catchy.
Fortunately, the odds of your clothes catching on fire is low.
Unfortunately, the odds of your software, browsers or accounts being compromised is very high.
A couple of weeks ago the internet was hit with the highly impact-full and publicized distributed denial of service (DDoS) attack on Dyn, a DNS provider. I won't go into the details here but I think I will cover DDoS in a future post. Anyway, shortly after that I was chatting with someone at a dinner who asked me about this attack, internet safety in general and what they could do. To keep it simple and because, as a math person I like things in 3's!, I provided these 3 simple (well, maybe straight-forward is more accurate) things that absolutely everyone should do at home...
Labels:
2-factor,
authentication,
browser,
fob,
LastPass,
multi-factor,
password,
passwords,
patch,
software,
tools,
vault
Monday, November 23, 2015
Do the Amazon 2-Step... Now!
It's not a new song or a new dance... Amazon has just announced 2-step, aka 2-factor or multi-factor, authentication for online logins! It's overdue but I'm glad it's here.
Here's an overview article and here's a great step-by-step with screen shots. I set this up for my account and it was really easy using my phone and Google Authenticator. You can also use text messaging, or setup text messaging as a backup method.
We've talked about 2-factor authentication in the past so I won't go deeply into it in this post. The important take-away is that Amazon now offers this service and you should use it!
Here's an overview article and here's a great step-by-step with screen shots. I set this up for my account and it was really easy using my phone and Google Authenticator. You can also use text messaging, or setup text messaging as a backup method.
The main reason that 2-factor is good and important is that it prevents an attacker, who has stolen your userid and password, from logging in as you. This is because they would need to have your smartphone in addition to the userid and password! (yes, there are other methods as well).
Labels:
2-factor,
Amazon,
authentication,
Facebook,
fob,
Google,
ID,
identification,
identity,
login,
Microsoft,
password,
passwords,
Paypal,
phone,
security,
smartphone
Tuesday, January 22, 2013
Something You Lost - 3 Factors of Fail (part 3)
As you can tell if you read my last post, I have some pretty strong opinions about the failure of passwords as an authentication mechanism.
To review, the 3 factors of authentication are referred to as: something you know, something you have and something you are. Today, in part 3 of this series, we'll talk about the failure of the second factor of authentication, "something you have". Here are links to parts 1 and 2 of the series.
While not the oldest form of authentication, this factor of authentication has been around for a long time. Think about a key, or perhaps some kind of scroll with the symbol from a leader, or even the sword in the stone! A driver's license, ID card, credit card or passport is also something you have. These are all things someone can have and can be used identify them or grant access.
Today, the term "2-factor authentication" can the use of any two different factors of authentication. But most commonly it refers to the combination of password or PIN that you know, with a single use 6-digit number from some kind of token.
Here are the three most common single use string/token delivery methods:

To review, the 3 factors of authentication are referred to as: something you know, something you have and something you are. Today, in part 3 of this series, we'll talk about the failure of the second factor of authentication, "something you have". Here are links to parts 1 and 2 of the series.
While not the oldest form of authentication, this factor of authentication has been around for a long time. Think about a key, or perhaps some kind of scroll with the symbol from a leader, or even the sword in the stone! A driver's license, ID card, credit card or passport is also something you have. These are all things someone can have and can be used identify them or grant access.
Today, the term "2-factor authentication" can the use of any two different factors of authentication. But most commonly it refers to the combination of password or PIN that you know, with a single use 6-digit number from some kind of token.
Here are the three most common single use string/token delivery methods:
Labels:
access,
authentication,
browser,
crack,
cybersecurity,
device,
encryption,
fob,
mobile,
password,
smartphone,
tokens
Subscribe to:
Posts (Atom)
