InfoSec Links March 28, 2014

How To Disable Twitter Photo Tagging - Jerry Gamblin

This setting has been turned on by default. Here's how to turn it off if you wish to do so.

Thinking Beyond The Password When Protecting Your Online Accounts - Lee Munson - BH Consulting

Following my 'watch what you put on the internet post' is a link that talks about security questions. If you're using security questions that can be searched on social media, you're doing it wrong.

Windows XP will continue receiving security support in China - Michael Kan - PC World

Windows XP support ends next month, April 2014, but it looks like Microsoft will make bank by providing China with special support.

This post first appeared on Exploring Information Security.

Information can be a powerful thing

Check out this article:

Trolling Wrong number style

Information, even something as simple as a phone number on Facebook, is a very powerful thing. What gets put on the internet stays there and can potentially be used against you.

Here's another article:

How Social Media Networks Facilitate Identity Theft and Fraud - by Kent Lewis - Entrepreneurs' Organization

Social networks are a powerful tool that we use on a day to day basis. Misuse can cause significant harm not only to yourself, but also to your family and friends.

Be careful what you're putting online.

This post first appeared on Exploring Information Security.

Information Security Is More Than Electronic Security

15 years ago I worked at a movie theater. It was one of the best jobs I've ever had. A couple of days ago I got this letter in the mail:

On January 7, 2014, Carmike was notified by the IRS that certain Carmike employee W-4 cards were located during a search and seizure. The IRS believes the W-4 cards were stolen from Carmike's warehouse in Alabama. On February 7, 2014, the IRS provided Carmike with a copy of the W-4 cards that were seized. Your W-4 card was not one of the seized cards, but we believe additional W-4 cards were stolen. We have conducted an investigation and have been unable to determine which additional W-4 cards were stolen from our warehouse. We are providing you with this notice out of an abundance of cautions since you W-4 card included your name, address, and social security number.

15 years ago I worked at Carmike Cinemas and filled out a W-4 form. Now my information might not have been compromised, but there's no certainty of that. They have a piece of paper that has my social security number, one of my old address' and my name. They can find my current address pretty easily with a little bit of searching and they can find out I work in information security, which pays fairly well.

This wasn't some hacker getting past firewalls and intrusion prevention systems and segmented networks. These were guys who walked out of a warehouse with stacks of W-4 forms or found a bag of W-4's that hadn't been disposed of properly. In this digital age of identity theft it's easy to forget that a piece of paper from your past could potential hurt you financially.

There are some valuable lessons here:

  • Always ask why you're providing this information and if it's necessary for whoever to complete their job (a W-4 form is necessary).

  • Shred all documents with your personal information when you don't need them anymore. This includes those unsolicited credit card applications.

  • Sometimes there is nothing you can do to prevent your personal information out there. Make sure you're checking your bank account a regular basis for unknown charges.

This post first appeared on Exploring Information Security.

Safety Starts With Strong Passwords

This is a post I wrote for work talking about how to create a strong password.

Creating a strong password is one of the best things you can do to keep both yourself and your accounts safe, both at work and at home. However, creating a strong password is not the easiest thing to do and requires a little bit of thought.

If you choose a long string of random characters, the password is strong but easy to forget. If you choose a much shorter password without any random characters, then it’s easy for someone to guess. The idea is to find a balance between the two. A recent study of passwords that had been compromised, showed the top 10 worst used passwords were:

  1. 123456

  2. password

  3. 12345678

  4. qwerty

  5. abc123

  6. 123456789

  7. 111111

  8. 1234567

  9. Iloveyou

  10. adobe123

Fortunately, most places have a set of password requirements designed to keep your information safe. That does create a bit of a challenge for users because you are required to change your passwords every three months. Here are some tips that will help make the seemingly daunting task of creating strong and memorable passwords, a little easier.

Pick a Theme

Most organizations will require a password to be at least eight characters—with  at least one special character and one number. Try to think of something in your life, non-work related, that has all three of those elements.

Some examples include:

  • Restaurant menu

  • Retail stores

  • Hardware stores

  • Legal documents

  • Food stores

Once you have a theme, start mixing and matching numbers in a way that you can remember. For example, Chicken Strips for 14.99 from a restaurant could be ChSt14.99 or ChcktRips14.99 or Ch1ck4Nst9i9s!

There are thousands of different passwords waiting to be thought up from everyday life. The one caveat is, that if you create a password from your everyday life, make sure you’re not posting it all over your social media site. It’s pointless to use chicken strips as part of a password if you’re tweeting about it for the world to see.

Pick a Phrase

Pick a phrase and then use a combination of letters, numbers and special characters to craft your password. For example, Take The Bull By The Horns could be T-tB-b-TH0 or T8k-7@buLL-bi*7-h0rns or T-T@8’8@T-H0. Be intuitive about it and craft it in a way that you can easily remember it. The same rule applies here; don’t use your own personal catchphrase that’s on your social media profile. Don’t use anything obvious because phrases are easily searchable, especially if they’re popular.

Other Ideas
The two suggestions above are only a couple of ways to create strong and easy- to-remember passwords. It just takes a little thought on the front end. Find something that works for you, and once you do it’s much easier to change and improve on a regular basis.

This post first appeared on Exploring Information Security.

Information Security Link March 7, 2014

Surveillance by Algorithm: https://www.schneier.com/blog/archives/2014/03/surveillance_by.html

Bruce Schneier is one of industry leaders in information security and more specifically cryptographer. He is a very very intelligent individual and you will become smarter reading his works, guaranteed. In this particular blog post he takes some quotes made by the NSA and Google to task, in regards to how they handle people’s personal data.

The TL;DR version is:

The NSA version of the term ‘collect’:

“So, think of that friend of yours who has thousands of books in his house. According to the NSA, he's not actually "collecting" books. He's doing something else with them, and the only books he can claim to have "collected" are the ones he's actually read.”

Google says it’s algorithms, that read your email, is like your dog
“To wit: when you're watched by a dog, you know that what you're doing will go no further than the dog. The dog can't remember the details of what you've done. The dog can't tell anyone else. When you're watched by a computer, that's not true. “

This post first appeared on Exploring Information Security.