Showing posts with label Week 4. Show all posts
Showing posts with label Week 4. Show all posts
Anonymous
According to a research done by Information Week on an analysis of 28,000 passwords from a popular website, 16% of users using name such as their own name, spouse’s name or children’s name, 14% use like “1234” or “123456”, 4% uses “password” or “password1”. Some other common passwords include “qwert” (English keyboard letters below the numeric keys), popular tv show stars such as hannah or pokemon, and iloveu. Most of the users are using these kinds of passwords because they are familiar with all these words and it is easy to remember. However, a simple password may harm decline the security. Passwords are the keys use to access personal information that have stored on computer and in online accounts. If criminals or hackers steal this information, they can use your name to open new credit card accounts, steal your money in bank account, apply for a mortgage, or pose as you in online transactions for making money purposes. Therefore, create and use strong passwords are very important for everyone.

First of all, make the passwords lengthy. Each character that adds to the password increases the protection that it provides many times over. The passwords should be 8 or more characters in length. The ideal and stronger length of the passwords is 14 or more characters. In order to remain the secure, users can combine letters, numbers, and symbols in the passwords. The greater variety of characters in the password increases the hardness to guess. Nowadays, many systems support the use of space bar in passwords, so user can create a pass phrase made of many words. A pass phrase is longer and harder to guess as well as easier to remember than a simple password. Besides that, users are suggested to change passwords regularly to increase the security of information.

According to www.microsoft.com, there are six steps to develop a strong password
  1. Think of a sentence that you can remember.

  2. Check if the computer or online system supports the use of the space bar in passwords, so you can create a phrase made of many words (a "pass phrase").

  3. If the computer or online system does not support pass phrases, convert it to a password such as take the first letter of each word of the sentence that you have created to create a new password.

  4. Add complexity by mixing uppercase and lowercase letters and numbers such as substituting the word "three" for the number 3.
  5. Finally, substitute some special characters. You can use symbols that look like letters, combine words (remove spaces) and other ways to make the password more complex.

  6. Test your new password with Password Checker Password Checker is a non-recording feature on this website that helps determine your password's strength as you type.

To avoid weak, easy-to-guess passwords, users should avoid sequences or repeated characters "12345678," "222222," "abcdefg," or adjacent letters on your keyboard such as “qwert” that do not help make secure passwords. Besides that, do not using only look-alike substitutions of numbers or symbols such as 1 as I and @ as a which is easy guessed by criminals. Users have to avoid their login name contains any part of their name, birthday, social security number, or any similar information. Moreover, users should not use dictionary words in any language to create their passwords. Criminals use sophisticated tools that can rapidly guess passwords that are based on words in multiple dictionaries, including words spelled backwards, common misspellings, and substitutions. Users are advice to use more than one password everywhere and avoid using online storage to store the passwords.
References:
Labels: 2 comments | edit post
tow

What is phishing?

Phishing is pronounced like 'fishing' but please not be confused with fishing. Phishing is a type of social engineering attack in an attempt to trick individuals to reveal their sensitive information. It scams users by sending an e-mail or instant messaging with an established legitimate enterprise that has been misrepresented.

The common scenario is that the e-mail will direct the users to visit a Web site where they are asked to update personal information, such as passwords and credit card, and bank account numbers that the legitimate organization already has. Customers of banks and online payment services are usually the common targets.

There are many methods of phishing. The common form is to make a link in an e-mail that appears to belong to the spoofed organization such as the use of subdomains. For example, the URL, http://en.wikipedia.org/wiki/Genuine, appears to take user to an article entitled “Genuine”, in fact it will take the user to the article entitled “Deception” when clicked on it.

Another form of phishing is the use of subjects lines worded to arouse anxiety. For example, the subject “to restore access to your bank account …” in an e-mail will usually get instant attention and most people will fall into the trick by clicking to read what happened. Another example of phishing is requiring users to update their information or change their passwords.






Methods to avoid being phished:
  • Do not trust e-mails that requesting personal information especially financial information. The phishers will include upsetting statements that will trigger fear or happiness so that users can react immediately. Therefore, do not click on the link attached in the email or give any account information on the web as no bank or internet commerce will ask for account information.
  • A link that has a name you recognize doesn't mean it links to the real orgaization. Roll your mouse over the link and seeif it matches what appears in the email. Do not click on the link if there is a discrepency. Also, websites begin with "https" are safe to enter personal information ("s" stands for secure).

  • Be sure not to call any number or use any link in the suspected email as this may put you in the hands of the phisher. It is generally safer to write the specific address field or call the banks specific number as found on their official pages.
  • Phishing emails are usually sent in large batches using generic names like "First Generic Bank Customer". If you do not see your name, be suspicious.

  • User should have a healthy control over the bank account by regularly check the credit and debit cards to ensure all transactions are legitimate. Contact your bank and all card issuers if found any suspicious.

  • Keep antivirus up to date and use anti-spyware software.








References:

- Avoid Phishing scams, hoax. Retrieved 28 June 2009, from http://www.anti-phishing.info/avoid-phishing.html
- Phishing. Retrieved 28 June 2009, from http://en.wikipedia.org/wiki/Phishing
- Phishing. Retrieved 28 June 2009, from http://www.webopedia.com/TERM/p/phishing.html
Labels: 0 comments | edit post
Anonymous
Online Security has become an enormous anxiety to people surfing the Internet and also people conducting business on the World Wide Web. The reason is fairly obvious with online viruses, scams, online identity theft and data misuse happening everyday. Hence, online security covers many aspects of our current online world.

We have to accept the fact that no technology is perfect. We might expect a privacy system to effectively to block the people from our private data as we ask it to, but sometimes there will be lapse. For example, recently Facebook’s privacy system failed to protect users’ items, like photos, which was meant only for closest friends.

By putting information in many places increases the chance that someone else will get hold of it.Many people are putting information about personal events on social network and blog sites. This increases the exposure to other party dramatically. Furthermore, backing up data by paying service provider isn’t safe after all. Carbonite, a large backup vendor, was reported to have lost data for a significant number of users. In the end, they claimed that it is due to defective equipment bought from one of its technology providers.

On top of that, there are some risks involved in keeping personnel information on email provider. If the sender or the recipient of email is not using secure connection when processing mail, anyone on their network can pry on the connection. Since most of the email provider has auto-login features, anyone who has access to the particular personal computer can access the mailbox in some cases.


When it comes to confidential data, reasonable care must be taken in order to safeguard our precious data from being exposed and avoid unwanted problems from happening.

References:
  • Facebook Bug Reveals Private Photos, Wall Posts. (2009, 20 March). Retrieved June 22, 2009, from http://www.techcrunch.com/2009/03/20/facebook-bug-reveals-private-photos-wall-posts/
  • Carbonite Loses Cloud Based Data, Sues Storage Vendor. (2009, 22 March). Retrieved June 22, 2009, from http://au.sys-con.com/node/887245
Labels: 0 comments | edit post
chuiting
Nowadays, people mostly keep their personal data or information in their computers because it is easy to manage. However, there are some users who abuse the convenient and try to steal others personal information especially those financial data in the computers. Hence, users should have some knowledge about how to protect their personal information and financial data.

Below are some tips to safeguard personal and financial data:
· Use passwords and encrypt sensitive files
Create passwords to prevent unauthorized user to access your personal data in the computer. You should create password which is not easy to be guess. Besides that, you may encrypt files to avoid other users to read your data although they can physically access it. But, if you forget your passwords and passphrases which is use to protect your data, your data will be miss.

· Use and maintain anti-virus software and firewall
Install an anti-virus and a firewall to prevent viruses such as Trojan horses which may steal or modify your data in the computer. Always update your anti-virus to ensure your computer has proper protection.

· Often scan your computer for spyware
Always scan your computer for spyware as it may be hidden in some software programs. Hackers will use spyware to access your data.

· Do not access financial information in public
It is better to use your own computer to access financial information. Avoid accessing financial information in the public because we do not know how well their firewalls are.

· Do not open mystery attachments
Viruses can be sent through any attachments in mails. Thus, do not open any mystery attachments or click on a link that connects you by an unknown party.

· Review your monthly statements
You may discover any possible fraudulent charges when u always assesses your monthly statements. Some charges or services which are no longer necessary or redundant may also misstated in your financial statement.


References:
Safeguard Your Financial Life. Retrieved June 28, 2009, from http://www.fool.com/personal-finance/general/2006/09/23/safeguard-your-financial-life.aspx

US-CERT Cyber Security Tip ST06-008: Safeguarding Your Data. Retrieved June 28, 2009, from http://www.us-cert.gov/cas/tips/ST06-008.html
Labels: 0 comments | edit post