Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Thursday, August 23, 2012

What is Phishing? (Part 1: Online)

Phishing, pronounced "fishing," is becoming a popular phrase in mainstream media. It's this strange, indistinct danger that threatens to take your information and give it to goodness-knows-who. The real problem though is that this threat, while very real, is completely avoidable and needn't be a constant source of worry. What phishing is is simply someone tricking you into giving them the information they want.

That's right. You give them your sensitive information. Of course right now you're thinking "I'd never do that," but every year thousands, if not millions, of people fall for phishing scams. That's because even the most security-conscious people need to be careful- some of the scams are just that good. One of the most common types of scams is an email from your bank asking you to log in to their website and change your password. Changing passwords is something people do often enough that they rarely think twice about doing it, but in this case, you're not really changing your password, but giving away your current one.

Here's how this particular one happens: The "phisher"makes up a fake email address that looks like it could be official. They send this email to a large batch of people who's email address they've acquired through other shady means. Of these people, a certain percentage of them will bank with the one the phisher is trying to replicate. Of those people, a certain percentage will click the convenient link in the email to go to the webpage to change their password instead of navigating to it using a bookmark. If a person reaches this point, they're greeted by a webpage that looks like their bank's webpage, and even has a URL (web address) that's almost identical to the real name. At that point, they simply fill in the password change form, submit, and that's it. Their log in name and password is sent to the phisher's database.

So how can you avoid this? Here are some simple steps you can use to avoid digital phishing scams:

  1. Don't open emails from people you don't know. Too often phishers will make their emails look like they were sent to the wrong person, or the email address will be slightly off from what your bank really uses. For example: If you bank usually emails you from customer_service@bank.com, and you receive an email from customer_service@bank.ca, it's probably not really from your bank.
  2. Most companies will NEVER ask you for your password. If you ever receive an email from any company you do business with asking for your password, call them and verify that they sent the email.
  3. If you receive an email asking for you to reset your password, do not use the link provided in the email. Navigate to the company's password change webpage using bookmarks you already have. Using the link given to you means you could end up on a fraudulent site if the email is, in fact, not from the real company.
  4. If, for whatever reason, you are unable to do the above steps and you must use an email-provided link, verify the webpage it takes you to. Check for things like misspellings, substituting numbers for letters in the name, or having a different ending like ".ca" or ".lb" instead of ".com" These are all ways people can make webpage names look official at first glance.
Practical Tip of the Day:
Not all phishing scams are like the one I outlined, and not all of them are digital. Phishing scams are as plentiful and diverse as scams and cons before the digital age, and some of them are based on those old tricks. There is no way to protect yourself 100% from scams and phishing, but being mindful of your information and who you give it to is the best defense.

Tuesday, July 24, 2012

How Can I Protect My Laptop from Theft?

Have a new laptop or planning on getting one in the new future? While laptop computers can be great for the extra portability, that can also pose problems if your laptop "walks away" from you. Whether you're a college student, traveling professional, or somewhere in between, there are three basic ways to help prevent laptop theft.

The first is laptop locks. These are very much like bike locks in that it's a durable cable that you wrap around something that can't be moved and then lock into your computer. The one pictured here is from Kensington and uses a combination. There are locks that use keys, but I usually recommend combination locks since you can't loose a combination. Also note that it's plugged directly into the computer. Most laptop computers nowadays have a slot specifically for use with laptop locks. Check the specifics of your computer to verify whether you have one or not.


Another step against laptop theft is anti-theft software. Companies like LoJack (the car anti-theft company) are starting to branch out into the computer field, but there are also new start-ups and even free anti-theft software out on the market now. They all work slightly differently, so be sure to read carefully before you get any of them, but my personal favorite for Mac laptops is called Undercover by a company called Orbicule that specializes in technology security.

Lastly, and most effectively, if you don't want your laptop to get stolen, don't leave it laying around! Far too often I've heard college students crying because their laptop with all their finals got stolen at the library when the student got up to get a book. Leaving your laptop on your table while you use the bathroom at Starbucks? Just as bad. Having a house party where you don't personally know everyone in attendance? Put the computer away in a room people won't go into.

Practical Tip of the Day:
Most frequently, people will use a combination of the three of these methods to protect their laptop. Personally, I don't frequent public places so I use an anti-theft program and keep my computer on my person when I am out and about with it. Consider your lifestyle when looking at anti-theft options, and remember that while having a complete and recent backup of your computer doesn't make the monetary loss any less, it will make it easier to start up where you left off if you end up needing a new computer.

Tuesday, April 17, 2012

Can You Be Tracked By Your IP Address?

With people around the world being arrested by their governments for things they write on the Internet, children in the US being expelled for Twitter remarks, and the general lack of privacy the Internet affords us nowadays, there is increasing concern about whether you can be physically tracked by your computer or smart phone's IP address.

First of all, what is an IP address? IP stands for "Internet Protocol" and is the address of your Internet-enabled device. (Read: computer, smart phone, Wii, or anything that accesses the Internet) While IP addresses can and do change, you can also tell them to stay the same. An IP address is four sets of number ranging from 0-255 and is separated by periods, for example: 127.0.0.1, and there are two different kinds: public and private. The public one is the one used when you access the Internet, so this is the one I'll be using in this discussion.

In the TV shows, the high tech cop simply hops on a computer, goes to a complicated looking screen with a black background and green text, types in some cryptic commands, and a detailed map pops up showing the person's street, building, and then their apartment. This is almost, kind-of-sort-of, but not really how it happens. What really happens is this:
  •  The police acquire a suspect's public IP address
  •  The police can figure out the ISP (Internet Service Provider) from that.
  •  They go to the company that gave out that IP address, and request/subpoena the information linked to that address
  • They now have the billing information for that IP address.
Here are some catches, though:
  • That's only the billing address, it doesn't prove who was using that computer.
  • It can take days for an ISP to get the information to the police.
  • If someone's tech-savvy, and knows what they're doing is bad, they're probably masking their IP via a proxy.
Which leads me to the PTD- what is a proxy?

Practical Tip of the Day:
If you're concerned about your privacy, or being tracked, there are plenty of websites that let your surf the web via a proxy. A proxy jumps you around a bit and gives your a different IP address so when you visit a webpage, it sees that you're in London, not in Chicago. While this can be helpful for those concerned with Internet privacy, it is not a necessary step for most people, and regularly using a proxy can be viewed as a sign that you do things online that you "don't want people to know about."

Thursday, April 5, 2012

What is Bluetooth?

Your phone has it, your computer has it, your car has it, it seems like just about everything nowadays has it. Bluetooth has become so ubiquitous that it seems a given for any electronic device to have it, but what is Bluetooth? I've been asked this many times, especially in how it's different from WiFi.

Hedy Lamarr. Bet you weren't expecting her in here, were you? This famous actress was actually one of the people that helped invent Bluetooth, though it wasn't called that at the time, and it certainly wasn't invented so you can control your toaster with your computer. She helped invent a way for radio signals to be sent in such a way that they couldn't be blocked or intercepted as part of the wartime effort, but the military simply filed the technology away.

Modern Bluetooth is, in the simplest terms, a way for a wireless signal to be sent in such a way that it "bounces around" various frequencies. Think of it as if you were trying to have a secret conversation over walkie-talkies. You'd hop on one channel, say a couple words, switch to another, some some more words, etc. for your whole conversation. Electronics do this using short-wavelength radio signals, and by using this technology, you can use multiple wireless devices at once with no ill effect.

Even if you have twenty Bluetooth devices turned on and working at once (you have a Bluetooth headset on your phone, wireless mouse and keyboard on your computer, wireless printer, etc.) you'll get no interference between them because they're jumping around on their signals enough that it's highly unlikely that any two objects will be using the same wavelength at the same time, and even if they do, they use it for such a short amount of time you won't notice it.

Practical Tip of the Day:
Most phones and computers that have Bluetooth capabilities have it turned on by default. Having this running if you're not using it can not only drain your battery, but can also be a security hazard. If you see the Bluetooth symbol (see right), go into your settings and turn it off until you do need it.

Tuesday, April 3, 2012

How Do I Know if a Webpage is Secure?

Ever been ready to fill out a form online and then pause, wondering who's actually getting your information? Most websites are public, and the information you share on them is unsecured, meaning people other than the intended recipient may be able to access it. How can you be sure if a website's form (the part you fill in) is secure or not?

Look up at your URL bar. The URL bar is where a website's address is displayed on your web browser's window. The text inside usually starts with "http://" See it? Now, go to a website where you need to type in your personal information like a bank's webpage. It's ok, I'll wait. Did you see it? The difference? The URL (URL is the technical name for a website's address) didn't say "http://", it said "https://" The little "s" makes all the difference! S stands for "secure".

When a website's address has that S at the end of "HTTP" it means that that website has special measures in place specifically to ensure that the information you type in to that webpage goes directly to them, and does so in a secure, safe way. While I'll spare you the techno-babble of the "how," just make sure you're more aware of the websites you visit, and their security status.

Practical Tip of the Day:
If, instead of outsiders, you're more concerned with people who share your computer getting your information, consider using your web browser's private browsing settings. Generally called things like "Private Browsing" or "Incognito Mode" (these are examples for Safari and Chrome respectively,) these modes allow you to browse the web without the history being recorded, cookies being saved, and various other tracking methods disabled.

Friday, January 20, 2012

Special Edition: What is a DDoS Attack?

The major news channels didn't give it much hype, but last night there was a significant attack on several major websites. Here's the list:

  • Department of Justice (Justice.gov)
  • Motion Picture Association of America (MPAA.org)
  • Universal Music (UniversalMusic.com)
  • Belgian Anti-Piracy Federation (Anti-piracy.be/nl/)
  • Recording Industry Association of America (RIAA.org)
  • Federal Bureau of Investigation (FBI.gov)
  • HADOPI law site (HADOPI.fr)
  • U.S. Copyright Office (Copyright.gov)
  • Universal Music France (UniversalMusic.fr)
  • Senator Christopher Dodd (ChrisDodd.com)
  • Vivendi France (Vivendi.fr)
  • The White House (Whitehouse.gov)
  • BMI (BMI.com)
  • Warner Music Group (WMG.com)
That's a lot, and a lot of very big, very important websites. The results of the attacks were that most, if not all, the sites were down for hours yesterday, being brought back online early this morning. I'm not going to go into detail on the politics of the attack, or who has taken credit credit for them, but I will try to explain exactly what happened.

"DDoS" stands for "Distributed Denial of Service", and "attack" stands for, well, attack. The name describes pretty well what the desired outcome of the attack is- to deny people the services of a website (usually by taking it offline). While there are several ways to do this, the most common, and the variant used in last night's attacks, is by overloading the servers that host those pages. Let's unpack that and translate it into normal-speak.

Let's say that you run a business, and you have a store front. If someone wants to look at what you sell, they come into your store and look. The person might leave and come back later, they might bring a friend, or they may never come back. Now, let's say that someone repeatedly came into your store and left it in a matter of minutes. One minute they're in, one minute they're out, one minute they're in, one minute they're out. That's odd, but not too dangerous, right?

Now, if that person brings three friends, and they each bring three friends, who each bring three friends.... You can see how it might become overwhelming very quickly. If enough people come into your store your real customers can't get in- they're being denied your services. (See what I did there?) In this analogy, the people coming into your store are computers, and the leaving and coming back are the computers repeatedly visiting the website very rapidly. (Usually several times a second.)

While a DDoS Attack does no long-term damage, it can take a website down and keep it down for as long as the attack continues if the attackers have enough "bots" (friends they brought to your store) attacking a site. Also, you can get 10 years in prison if you get caught, but more and more frequently, attackers are tricking people into becoming unknowing bots by getting them to either download a program or click a link under false pretenses.

Practical Tip of the Day:
Don't download a program or click a link you're not familiar with. The most common way for internet "bad guys" to get to your information is by tricking you into giving it to them. More and more often people are being tricked into giving their sensitive information away themselves instead of someone taking it by force. If you get an email from your bank asking for you to reset your password, don't follow the link in the email, go to the official site and do it there. It's very common for emails to look official, but be taking you to a website that will collect your information for someone else's use. This is called "phishing" (pronounced "fishing")