twitter
    Find out what I'm doing, Follow Me :)
Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Tuesday, August 7, 2012

Terrifying Possibility of the new world.

It sounds like something from a Science Fiction movie.

Mat Honan was playing with his daughter on Friday August 3, when his iPhone died and then rebooted to the setup screen. This was irritating, Mat wasn’t concerned,  assuming it was simply a software glitch. As the phone automatically backs up every night. he just assumed it would be a "pain in the ass" [sic], and nothing more. Mat entered his iCloud login to restore, and it wasn’t accepted. Again, he was irritated, but not alarmed. 

Mat decided to restore the phone from his computer's backup. When he opened the laptop, an iCal message popped up telling Mat that his Gmail account information was wrong. Then the laptop's screen turned grey, and asked for a four digit pin number to access the laptop. Mat didn’t have a four digit pin. 

Now Mat, knew "something was very, very wrong". He walked to the hallway to grab his iPad. It had been reset too. Mat could not turn on computer, iPad or  iPhone.

Using his wife’s iPhone Mat called Apple tech support. While on hold, he grabbed her laptop and tried to log into his gmail account whereupon he discovered his password had changed. He couldn’t reset it either because the backup went to iCloud. Of course, the ICloud had already not let him in. 

Mat tried to log into Gmail again, but was told that his Google account had now been deleted. The way to restore it was to send a text message to my phone which Mat didn’t  have access to.

Apple tech support weren’t able to stop the wipe on the Macbook. Or provide the four number pin to log into it. Or give immediate access to my phone. 

What was going on?

At 4:50 PM on August 3rd, someone got into Mat's iCloud account, reset the password and sent the confirmation message about the reset to the trash. The backup email address for his Gmail account is that same .mac email address. At 4:52 PM, that person tried to log into Gmail by requesting a password recovery email. An email changing the Gmail password arrived two minutes later to the mac email account. 

At 5:00 PM Using ICloud,  the hacker remote wiped my iPhone. They then remote wiped the iPad at 5:01pm and followed that up with his MacBook Air at 5:05pm. A few minutes later, they had access to his Twitter account. Because Mat had linked his Twitter account to his ex employer's Twitter account years before, the hacker had access to that Twitter account too. A series of nasty tweets started being sent  from the ex-employer (Gizmodo).

Mat lost at least a year’s worth of photos, emails, documents, and more. 

Someone claiming to be the hacker got in touch to says “didnt guess ur password or use bruteforce. i have my own guide on how to secure emails.” Apple then confirmed that Apple tech support provided the hacker with access to the iCloud password. Before yelling too loudly at Apple, the hacker was able to use "
some clever social engineering that let them bypass  security questions"

My learnings:
  1. Have a company policy around passwords eg when changed, length. We need to emphasise how careful we must be with passwords
  2. do not write down passwords in public places
  3. do not use the same password on every account
  4. Have an email account that is only for backup password requests and the like. Give it out for no one and nothing
  5. Be aware of who has password access to your organisation's server, email, Facebook and Twitter accounts. Change common codes when an employee or volunteer leaves
  6. Do not use your Mother's real maiden name when asked that security question. This is the most common question asked. It does not take a genius to find out what most people's mother's maiden name is
  7. Think about the other common security questions asked by companies. Eg where born (Facebook tells me that). My First car? If your facebook timeline says: Got my first Volvo in 1996 or if you sent a tweet that said " said good bye to my first car today. will miss my Toyota" then anyone can get that information
  8. Do a password audit. What are all of the passwords in your organisation? In your personal life? Who knows what?


Enhanced by Zemanta

Tuesday, January 10, 2012

Facebook is NOT as evil and scary as you think!

There is a lot of paranoia and fear about Facebook. I accept that Facebook makes some dumb mistakes but Facebook has been blamed for so much and given so much more power than it has.

I see people who get  get angry at things that Facebook has shared that they themselves have inputted into the site!

 The one that amuses me is when people say "Facebook stole my password ..that is why I have sent junkmail, spam or viruses".

How about you clicked on a link that took you OUT of Facebook and you entered your own password on that link.

What also amuses me about the paranoia is that I can find out lots of information about you OUTSIDE Facebook.

You are not invisible anywhere..

Join a Yahoo group- then you have an online presence
Post a complaint on Trip Adviser?
Post your pic on your family web page?
Be interviewed by your local TV/Radio station/newspaper?

All of those things will put you online.

Protect yourself:

  • Don't share anything online, you dont want to see repeated. Anything, anywhere.
  • Be real
  • Don't post when angry, drunk or frustrated
  • Don't share your password
  • If you are ever asked for your Facebook password by any other program, page or individual, check it is legitimate.
  • Log out of your Facebook account when on shared computers

Enhanced by Zemanta