Showing posts with label Cybersecurity. Show all posts
Showing posts with label Cybersecurity. Show all posts

Tuesday, January 5, 2010

Cell Phone Security


Usually, when we talk about cell phone safety the conversation is about sexting, cyberbullying or the dangers of texting while driving (Don't do that!). However, CNET published a good article today about a different type of Smart Phone safety. It is a look at the most frequently asked questions about the biggest security threats for mobile phones including:
  • Theft/loss
  • Malware delivered through email or text message
  • Phishing text messages
According to security experts, the biggest threat for a mobile device is loss or theft. They suggest that if you store any personal or sensitive data on your phone that you should keep your device password protected. Also, just like with your regular computer, you should be very careful about who you give personal information to. Social security numbers, credit card numbers and PIN numbers should not be sent via text or email from your phone, especially if you received an unsolicited message asking for that information.

Monday, November 23, 2009

'Tis the Season for Cyber Safety

With the holiday season upon us, a lot of cybersecurity blogs and websites are publishing strategies for people to utilize in order to stay safe online. As more people are using the internet to shop during the months of November and December, there are a lot of scams out there designed to steal your personal financial information. Here are some helpful articles with tips that you can use to keep your identity and other data safe online.
  • This article from CNET.com is about how you can recognize and avoid phishing e-mails. Phishing attcks attempt to trick a person into giving up their personal information such as bank account passwords and credit card numbers. Phishing emails can sometimes be hard to spot, so it is important to know what to look for.
  • Computerworld security offers a look at five things that people do to put themselves at risk to hackers and other online criminals.
  • OnGuard Online , a site maintained by the Federal Trade Commission, has a helpful tip guide for shopping online anytime throughout the year.
  • Internet security company, McAfee, is warning users of the "12 Scams of Christmas" in this article posted by CNET.com.
The internet is a fantastic way to keep in touch with family and friends during the holidays. It is also great for avoiding the mall crowds by shopping from the comfort of your own home, just remember to follow the safety guidelines that were published in the above articles. Have a safe and Happy Thanksgiving!

Friday, October 16, 2009

President Obama on CyberSecurity

Earlier this month, President Barack Obama released a video about Cyber Security Awareness Month. In the video, the president stresses the importance of keeping our computer networks safe. President Obama also states that he has created a new white house cyber security office which will be led by a cyber security coordinator he will appoint in the future.



During cybersecurity month, some websites are stepping up their efforts to provide quality cybersafety materials. Stay Safe Online has an entire section of their site dedicated to October being cyber security awareness month. They have links to resources, ideas on how to educate your students and schedules of cybersafety events across the country. Google is also celebrating cyber security awareness month. They have recently created the Google Cyber Security Awareness Channel on YouTube with videos dedicated to internet safety. They have also written various blog posts with cyber safety tips including choosing a smart password. Also, be sure to check out the Boston Public School's cyber safety website and resources!

Tuesday, September 29, 2009

Avoiding Scareware.


You have probably seen it on your computer at one time or another. You are surfing the internet and then a window pops up and says something to the effect that your computer has been infected with a virus and to click here for a free scan. The windows look legitimate, and it looks like you are using a real antivirus program to scan your system, but it is not. It is a piece of software called "scareware". Scareware is defined as a type of malware designed to trick victims into purchasing and downloading useless and potentially dangerous software. Usually, when a person's computer is infected with this type of program, pop-ups will plague the screen until you download their supposed anti-virus software. This type of malicious program is also called "ransomware" because it will slow down your computer and cause all kinds of problems until you pay the money for the download. Some of these fake anti-virus programs look very legitimate and professional. They have names and graphics that look just like authentic anti-virus programs. The best way to protect yourself from this situation is to not click anywhere on the pop up window. Close the entire browser instead of clicking the "x" in the pop up. Even clicking that "x" can cause an infection in some cases. If you can't close the entire browser, use "ctrl-alt-delete" to quit out of the browser. Make sure your computer has legitimate anti-virus software installed, know the name of the software and know how it is updated. For example, the BPS uses Symantec AntiVirus for all of the computers. The updates are automatically pushed through the network. If you get a pop up for any other anti-virus software, it is probably going to be a scam.

Wednesday, May 6, 2009

H1N1 Virus Attention Attracts Scammers and Phishers

It seems that whenever there is a high impact news story that captivates the world, there are always criminals in the background waiting to prey on people's fears. So, with all the attention being given to the H1N1 Virus (Swine Flu), you also need to be wary of spam email and phishing attacks. There have been numerous reports of scammers sending out emails with titles about the Swine Flu. These emails can contain links or files that infect the user's computer with malware that will either damage the computer or steal personal data that is stored on the computer. Some emails that are being sent out claim to sell vaccines and exotic cures for the Swine Flu. While some scams are easy to spot, others are more difficult for people to pick up on including this example:

Another attack, reported by researchers at Symantec (NSDQ:SYMC), informed recipients of the swine flu disaster by incorporating a linked news headline from reputable news agencies. Users are asked whether they are in the U.S. or Mexico and whether or not they know anybody who is affected by the outbreak. Victims are then requested to share their experiences by filling in Web application forms or replying back with their e-mails and phone numbers. However, the online questionnaire is a way for scammers to steal identifying information from unsuspecting victims.

security experts recommend that users go directly to trusted news sources for information on the swine flu virus and avoid opening unsolicited e-mail messages and links.

You need to be careful about what information you are submitting about yourself online. Cnet.com recently published a very informative article titled, "FAQ: Demistifying ID Fraud" about identity fraud which answers these important questions:
  • How does the data get stolen from my computer?
  • If I don't use my credit or debit card on the Internet, how does the data get stolen?
  • What do the criminals do with the data when they get it?
This is a very informative article and also includes some links of sites to go to if you think you are a victim.

Monday, March 30, 2009

60 Minutes Report on Cyber Security

60 Minutes ran a story last night about computer viruses and the notorious Conficker worm that has been spreading to networks across the world.


Watch CBS Videos Online

Wednesday, March 18, 2009

ID Theft - True Life Story


Okay, here is a true life story. The other day a friend of mine answers the phone. I hear him say to the caller, "No, I didn't make that purchase, nope, that one wasn't mine either." He talks for a few more minutes and then hangs up the phone. I asked him who called and he told me that his credit card company called because they noticed some irregular purchases on his account. Apparently, someone had gotten his credit card number and began to go on an online shopping spree. Luckily, the credit card company was on top of it, they notified my friend, put a stop on his card and notified the bank. After speaking to the bank, my friend decided to put a fraud alert with the major credit bureaus and file a complaint with the FTC. After an hour or two all of the work was done, and major damage to his credit was avoided. He does not know how his credit card account got into the hands of criminals, but he is very thankful that the credit card company was able to identify the issue and move quickly to stop it.

Identity theft rose by 22% in 2008, according to an article from CNET.com. A report on id theft was released last in February by Javelin Research. In the report it shows that electronic identity theft accounts for 22% of of reported cases. This data only reflects case of identity theft in which the victims know how their identity was stolen. Low tech methods of identity theft are still the most prevalent, with lost or stolen wallets the top method of identity thieves.

What can you do to protect yourself from electronic identity theft? Eric Esteves, from TechBoston sent a link to an article by Hiawatha Bray, who is an excellent technology reporter from the Boston Globe. He wrote this very helpful article about keeping your computer safe. The article explains antivirus software and how to keep Windows up to date. One piece of advice we never hear enough is not to download any software online unless it is from a reliable source! There are places online, such as download.com, that test programs for malware before they offer them to the public.

Sometimes, as is the case of data breaches, you have no control over if your personal data is stolen. Therefore, it is always a good idea to regularly monitor your credit report, and if you do see a problem, to contact your bank, credit card companies and credit bureaus immediately. The FTC website has a lot of great resources about identity theft and what you can do if you are a victim.

Wednesday, February 11, 2009

Julie Amero Interview on Good Morning America

The Julie Amero story has gained much national attention over the last few years. Julie was the substitute teacher from Connecticut who was convicted of child endangerment after pop-up windows containing pornographic material were visible on the computer in the classroom in which she was substituting for the day. Eventually, the conviction was overturned after it was proven that the culprit was spyware on the computer. Recently, Julie and her husband told their story of the experience to Robin Roberts of Good Morning America. The six minute interview is definitely worth watching.

The BPS does have filtering software in place to block pornographic sites, but no software is 100% effective. If your classroom computer is infected with malware (a virus, spyware, trojan horse, etc...), you could be putting your students and your files at risk. Make sure that the anti-virus software is up to date by having your TST run the login procedure that will update your desktop computer. If your TST does not know what the login procedure is to run an antivirus update, have them call the help desk. If you want to make sure that your L4L MacBook software is up to date, see the following video tutorial.

Tuesday, December 16, 2008

Heads Up Internet Explorer Users

If you use Internet Explorer for your web browsing, you may want to switch to Firefox for a little while. According to published reports, there is a serious security flaw that has been exploited in Internet Explorer. The security flaw can make a user's computer vulnerable to being hijacked. This can happen when the user is tricked into clicking on to a website that contains some malicious code. When the user clicks on a link to the site, they may inadvertently allow hackers to take over their system without even knowing it. Internet security software company, Trend Micro, reports that as many as 10,000 websites have been compromised since last week. Microsoft released some work arounds for the problem which includes changing the security settings in your browser to "high". In order to change your security settings in Explorer, you need to go to the tools section of the menu bar and choose internet options. This should help to limit any attacks on the computer. You could also switch to a different browser including, Firefox or Google's new browser, Chrome, while Microsoft fixes the problem.

Thursday, December 4, 2008

Three High Profile Internet Safety Cases


Conviction in Megan Meier Case

There has been a conviction in the closely watched cyberbullying trial of Lori Drew. You can read about the Lori Drew case in an earlier post in this blog. The synopsis of the story is that a young girl named Meghan Meier committed suicide after being duped on MySpace by a former friend and her mother. Megan had a falling out with her friend, so her former friend and her friend's mother, Lori, and another woman created a fake profile on MySpace to trick Megan. They created a boy named Josh who befriended Megan and then abruptly ended their relationship. Megan, who was already battling depression, committed suicide shortly after the incident. Lori Drew was convicted on three misdemeanor counts of identity fraud.

The conviction, if it stands, could have far-reaching implications for all kinds of websites on the internet. While the act of the Drew family is considered "cyberbullying", Lori Drew wasn't actually convicted of cyberbullying. The conviction is for computer fraud and stems from her breaking the agreement of the terms of service from MySpace for misrepresenting her identity. One of the defenses' main arguments is that Lori Drew checked the Terms of Service box when she created the MySpace account, but never actually read the terms of service and therefore didn't know what she was doing is illegal. There is also an interesting article in which the forewoman of the jury from the case states that the majority of jurors wanted to convict Lori Drew on felony charges.

Julie Amero Spyware Case is Closed

You may remember the case of Julie Amero. She was the substitute teacher who was convicted and sentenced to 40 years in prison for endangering minors in 2004. Prosecutors argued that Amero had put students at risk by exposing them to pornographic images that were popping up on a classroom computer. After reading about the case, some computer security professionals came to Julie's defense, saying that she was a victim of Spyware on a poorly configured computer. Amero was granted a new trial and recently decided to settle out of court. She pled guilty to a misdemeanor charge of disorderly conduct and has had her teaching credentials revoked. You can read an interview with Amero about the entire incident from Computerworld.

Harvard Law Professor takes on the RIAA

Well known Harvard Law professor Charles Nesson has decided to take on the way the Recording Industry prosecutes college students for illegaly downloading music. The RIAA will usually send a letter to the college student asking for between $3000 - $5000 and an assurance that the illegal downloading will stop. If they do not comply, they will be prosecuted to the fullest extent of the law. At least one judge is finding that these students and their families do not have lawyers and do not know their full legal rights, and therefore pay the settlement. Nesson and his law students contend that the RIAA is using civil litigation to punish alleged criminal activity, which in their view is unconstitutional. It should be very interesting to see how this case pans out.

Monday, November 10, 2008

Phishing Video Explanation

Common Craft is a company that creates videos that help to educate the public about different types of technology. They try to make the videos as straightforward as possible with little high tech jargon so that they are easy to understand. They do a fantastic job of explaining things like blogs, wikis, social networking and other web 2.0 technologies with a set of videos called "In Plain English". They recently posted a video entitled Phishing Scams in Plain English. The video does a nice job of explaining what some phishing scams are and who to contact if you are being targeted.


Phishing Scams in Plain English from leelefever on Vimeo.

Monday, October 27, 2008

Superintendent's Bulletin Warns of Phishing Scheme

The Superintendent's Bi-Weekly bulletin had a warning for people that are receiving emails that claim to be from the City of Boston Credit Union. These emails are NOT from the City of Boston Credit Union. These emails are an example of phishing, which are emails sent to try and get the user to provide their personal information such as account numbers, passwords and social security numbers. According to the bulletin, these emails have been in several forms including the following:
  • Surveys with a cash reward if you enter your personal information
  • Implications that your account is in jeopardy of being closed unless you enter your information
  • A notice that we are updating our security enhancements, so please enter your personal information
  • Plus, many other schemes to entice people to enter their personal and confidential information.
All of these emails are fraudulent. This is a classic example of a phishing scheme. Once you input your personal information it is sent to a criminal who may use that information to commit identity fraud. They may also sell your information to a third party who may use it to open up credit cards or obtain loans in your name. Banks, credit unions, brokerage firms and other types of financial institutions will not send an email to ask you to input personal information! If you ever have any questions about whether or not your financial institution is looking for something from you, give them a call using the phone number from one of your financial statements.

Remember, it is always a good idea to periodically check your credit report with one of the three major credit agencies just to make sure you have not fallen victim to identity theft. By law, you are entitled to a free credit report once every twelve months from these agencies. The Federal Trade Commission website about identity theft is full of helpful information about strategies to avoid a problem and what to do if someone does steal your identity.

Wednesday, September 10, 2008

BBB Warns of Identity Theft Through Voter Registration Fraud


Have you registered to vote for the 2008 presidential election yet? It will be an historic election that may draw out over a million new voters, and scammers are hoping to cash in. The Better Business Bureau has issued a warning that ID thieves are using the election as a means to steal personal information from people registering to vote. The thieves are using email, phone calls and even face to face encounters to try and trick people into giving away important personal information such as social security numbers, bank account numbers and passwords. According to a press release from the BBB, unsuspecting individuals are receiving phishing emails:

"that appear to be from a government agency and claim that the recipient must click on a link in the message to register to vote or resolve a registration issue. These links will actually redirect recipients to Web sites that install viruses or malware on their computers or ask for personal information such as Social Security or bank account numbers."

Potential voters are also getting phone calls with claims that there is a problem with the person's voter registration and that they need to confirm their identity with a social security number or credit card number. Do not give unsolicited callers any sensitive, personal information of any kind. The BBB has also posted a video explaining the ways scammers are trying to steal the identity of voters. If you have not registered to vote, do so by following the instructions from you state's election office.

Voter registration rules vary by state, so it is important to know how your state properly registers its voters. To find out you can go to the website for the Election Assistance Commission and look up your state. In Massachusetts, you must register within 20 days of the election and the official federal or state registration form. You have until October 15th to mail in your form. To learn more about how to register to vote in Massachusetts, go to the Massachusetts Election Division website for the correct procedures and forms. If you need to register to vote in another state, click this link to find the website for your state election office.


Friday, May 23, 2008

P2P File Sharing - Be Careful!


Just about any teenage student who uses a computer knows how to use Peer to Peer software to share and download songs, movies, tv shows and software. They probably also know that it is illegal to distribute copyrighted material over the internet, whether or not they think it is wrong. This is also true of adults. Many adults know that it is illegal to share copyrighted material online, however, many still choose to do it. Channel 5 recently did a story that shows how the movie industry is tracking down people who are sharing movies illegally online. The video shows an interview with a UMASS Amherst administrator who says that 600 students this year have been reprimanded for having pirated copies of movies on their computers. While the initial punishment is basically a warning, if students are caught again they will have to pay a fine or risk being sued.

Not only do P2P programs put you in danger financially if you are illegally sharing copyrighted materials, but they can also put you in a cybersecurity danger. Check out this article from CNET.com last month. A man was sentenced to four years in prison for stealing personal data off the computers of users using P2P software. He was able to get into their personal files and steal information from tax returns and bank statements. Think about some of the personal information you have in the files on your computer. Using P2P software may offer the opportunity for someone to gain access to those files. Another danger that you can face is downloading an Mp3 with a virus, trojan horse or other type of Malware that can infect and damage your computer.

Another recent example of P2P danger is a music file that infects the computers after it is downloaded. Yahoo Tech reports that an MP3 file that is being shared actually contains a trojan horse program that has attacked half a million computers in a week! It is a fake Mp3 file that actually tries to install malware on your computer which causes constant pop ups on the computer screen. Luckily, only 10 percent of the people who downloaded the file actually installed the malicious software.

OnGuard online has some helpful tips if you do choose to use a P2P file sharing program. Make sure that you set up the software to only share one certain folder, not your entire hard drive. You should also scan anything you download with updated security software to make sure it is clean. Just realize that even if you scan it, there is a chance that it may contain a virus that infects your computer.

Saturday, May 3, 2008

Don't Get Scammed


With the economic stimulus checks being sent out from the IRS, there is an opportunity for phishers and other scam artists that try and steal your personal information. There are several reports that identity thieves are sending are making phone calls posing as the IRS and asking for personal information. Phishing emails are also being sent out, telling people that if they "click here" they will get their rebate check even faster. Do not fall for either of these scams, the IRS will not call you or contact you by email. If you are getting a tax rebate check, it will be sent to you in the mail. If you had your tax return directly deposited into your bank account, then you rebate check will also be directly deposited into your bank account.

You can always contact the IRS yourself with questions. If you get a suspicious email claiming that it is from the IRS, do not call the phone number included in the email. Go to the IRS website for the government agency's contact information. You can also report the fraudulent email to the IRS by following these procedures. The site also has additional resources about phishing sites and identity theft, including sample phishing emails.

Thursday, April 24, 2008

What is a Botnet Anyway?

The National Cyber Security Alliance released a study earlier this month that states 88% of the participants surveyed do not know what a “botnet” is and that 71% had never heard of the term “botnet” before. Why is this important? Well, according to some security experts, botnets may be the biggest security threat online right now. A botnet refers to a a large network of computers that have been compromised by malicious software and are controlled by a cyber criminal. A botnet can consist of hundreds of thousands of computers that are used to send spam to mail servers or launch denial of service attacks on web severs. The owners of the infected computers, also called zombies, will often times be unaware that their computer has been infected with a malicious program such as a trojan horse and therefore do not know that their computer’s resources are being used in criminal acts. In the video below Ron Teixeira, executive director of the National Cybersecurity Alliance talks about how there needs to be a mixture of education and technology to defeat the botnet threat.


One very important thing you can do to make sure you do not have any malicious software on your computer that may contribute to a botnet is to run updated antivirus, firewall and spyware prevention programs on your computer. The best protection is a multilayer of security that is up to date and always running. You should also run a virus scan on your computer at least once a week. If you are not sure which type of software you should have, here are two articles that may assist you. The first comes from PC Magazine which published a review of different internet security programs on the market. The second is a slideshow of some free security applications that you may want to install on your computer. Remember, you may not even know that someone has even infected your computer and made it part of their botnet!

Sunday, April 6, 2008

CyberSafety Resource Spotlight - OnGuard Online

OnGuard Online is a website provided by the federal government that provides practical tips to prevent internet fraud, secure your computer, and protect your personal information. One of the helpful resources the website offers is a video and tutorials section. Here is an example of one of the videos that are on the website that help to explain what phishing is.



Another really neat resource that this site offers are some interactive quiz games that you can take online. The identity theft quiz offers really good tips and links about identity theft and personal data protection. There are also quizzes about shopping safely online and laptop security. There is a section on the site that explains to users how and where to file a complaint if they are a victim of an internet crime. You can also view the site in Spanish.

There are many more resources and features on this site, it is definitely worth a little exploration.

Monday, March 31, 2008

Identity Theft Protection?


Identity theft is a crime that continues to grow and grow and no matter what precautions you take, you personal data can fall into the hands of cyber criminals as evidenced by the recent incident with Hannaford Supermarkets. The growing media attention on identity theft and the negative impact it can have on a person’s credit has highlighted companies that claim to protect consumers from identity fraud. Services such as Identity Guard and Life Lock can provide monitoring of your credit reports and place fraud alerts for you with the three major credit bureaus. They will also request that you do not receive credit card applications in the mail, call your credit card companies for you if your wallet is stolen and assist you if you do become a victim of id theft. This seems very helpful if you are a busy person and worried about becoming a victim, however, these are all things you can do yourself without having to pay a company to do it for you.

Two articles recently published by the Wall Street Journal and Kiplinger.com explain how to do most of the same things that these companies will do for a fee. Both of the articles provide helpful tips on how to obtain your credit report and place fraud alerts with the three major credit bureaus. The articles also point out the fact that no company can guarantee safety from identity theft, but there are things you can do to minimize your risk and you do not necessarily have to pay for some other company to do it for you.

After reading both of these articles, I was able to get my credit report free online from annualcreditreport.com. It was very easy to do, and gave me some peace of mind to know that everything looked correct. My wife also checked on hers. If you want to order one for a child under 13 years of age, you are going to need to send in additional documentation.

I am in no way discouraging anyone from using credit monitoring and protection services like the ones mentioned above, in fact, they look extremely helpful for people who do not want the hassle of having monitor their credit themselves. I am merely trying to drive home the point that you should monitor your credit information on a regular basis and you can do it yourself, if you so choose.

Thursday, March 27, 2008

McAfee Introduces Internet Safety Plan for Families


Antivirus and internet security software company, McAfee, has created a 10 step internet safety plan designed to help protect families online. It is a nice guide filled with step by step information on how parents can keep their children safe online. While most of the information is common sense for some, it is nicely organized and easy to follow. The steps include computer placement in the home, boundaries and rules for internet use and even includes an online safety pledge that can be printed out and signed by both parent and child.

The guide also includes three sections that guide parents on ways to talk to their kids about internet safety. The sections are set up by age group starting with kids ages 3-7, then tweens, ages 8-12 and finally teens, ages 13-19.

The guide is located on McAfee’s security advice site which also has a lot of internet security information and resources including webcasts and videos.

Tuesday, March 18, 2008

Hannaford Bros. Confirms "Data Intrusion"


Add Hannaford supermarkets to the latest list of retailers victimized by hackers who have stolen credit card and debit card information of its customers. According to an article in the Boston Globe, Hannaford came forward yesterday to confirm that possibly 4.2 million credit and debit card numbers have been exposed and that this data intrusion is linked to 1,800 fraud cases already to date. According to the Hannaford website, the data that was stolen did not include names or addresses of card holders, but did include the card numbers and expiration dates. The data was illegally accessed from the Hannaford computer systems during transmission of card authorization. This data breach has affected customers from all Hannaford supermarkets, so if you shop at a Hannafords, it is strongly recommended that you review your credit card and bank statements. If you see anything out of the ordinary, immediately alert your financial institution of the problem. You then may need to place a fraud alert with one of the three major credit bureaus. If you have any questions for Hannaford supermarkets, call their customer care center at 866-591-4580.

Sometimes, no matter how safe you are with your personal information, you can still fall victim to identity theft. This story is a reminder that even if you are very protective with your personal financial information, you need to keep a close eye on credit card statements and bank statements. It is also a good idea to order a credit report for everyone in your family, including your children. The Federal Trade Commission website is an excellent resource on identity theft. There are videos about identity theft and information about what to do if you think you are a victim.