Showing posts with label password. Show all posts
Showing posts with label password. Show all posts

Tuesday, May 8, 2012

New Technology Protects your Storage Devices

We previously discussed USB flash drive security and how to protect it. ThumbDrive has developed a new technology to prevent unauthorized access to the information stored on your USB by using a fingerprint authorization.


This USB has some advantages and disadvantages. Aside from securing your data, the advantages of this USB is that you can configure it to grant access to at most three users. You can also partition the USB flash drive to divide the storage capacity into secured data and open or unsecured data. It is a small, easy to set up and easy to access USB with an interface that reads your fingerprint.

Unfortunately, this USB has two major disadvantages, cost and storage capacity. Storage capacity is an essential issue when buying storage devices. The ThumbDrive flash drive is available in 16, 32, 64 and 128MB, which is relatively small compared to our day-to-day flash drives. The reason behind this issue is that the flash drive is mainly designed to hold confidential files, and these files are usually personal files, legal documents, and financial or accounting data that don’t require huge storage capacity. So capacity isn’t really an issue here. Another major disadvantage is cost. The ThumbDrive touch 16MB costs $160, 128 MB $465, which is really a major concern for the buyer.

Another solution for securing sensitive data on your flash drive is by using the newly designed “Voicelok Voice Authenticating USB drive”. This USB uses “voicecode”, in other words, it uses voice recognition to secure your data. The USB’s software detects precise frequencies and shades in the user’s voice. The advantages of this flash drive is that its price is much more reasonable than the fingerprint flash drive and has a better storage capacity, around $46 for a 8GB USB. Unfortunately this USB is still not reliable as the reviews indicate.

If you want my advice, the best solution is to check the “Lenovo ThinkPad USB Portable Secure Hard Drive”. The hard drive protects the data from unauthorized access by requiring the user to enter a code into the numeric pad located on the hard drive. It allows up to ten different users and an administrator. It has a huge storage capacity compared to the fingerprint flash drive and its price is perfect, $179 for 160GB and $219 for the 320GB. The size of the hard drive is similar to the size of any other normal hard drive.
Paying a little extra money to protect your information that can cost you a lifetime is worth it. If you have sensitive information and don’t want it falling in the wrong hands, I suggest you go for reliable technology like fingerprint flash drives or the numeric pad hard drive.

Tuesday, April 10, 2012

Look for the S in The HTTP

We are all familiar with the word HTTP, Hyper Text Transfer Protocol. It is an application protocol that functions as a request/response protocol in the client/server computing model. Basically, most of what you see in your browser is transferred to your computer over HTTP. Our topic is not about HTTP and its functions, it is about HTTP and security.

Some of us are familiar with HTTPS, Hyper Text Transfer Protocol Secure. As you can see, the letter ‘S’ stands for secure. The ‘S’ comes from SSL/TLS protocol, which provides communication security over the Internet. A combination of HTTP and SSL/TLS produces HTTPS. The main objective of HTTPS is to provide a secure connection over an insecure network. Not all pages have HTTPS since it is very expensive. Pages that communicate personal data like passwords and credit cards use the HTTPS.

A page who’s URL begins with “https://” means that this page is secured and the current connection between you and the server is secured, since it provides an encrypted communication and secure identification. Payment transactions on the Internet often use HTTPS communication in order to prevent any third part interception.
You can now easily differentiate between HTTP and HTTPS. HTTP starts with “http://” :

It is an unsecured connection that is subject to third party interception, which can allow attackers to gain access to sensitive information. On the other hand, HTTPS starts with “https://”  
It is a secured connection that is designed to resist attacks or interception or even eavesdropping.

To conclude, always look for the ‘S’ in HTTP when providing secure and confidential data, this will ensure that this page is secure and nothing is suspicious about it. In my next post I will address more about HTTPS.

Sunday, April 1, 2012

Protecting your USB flash drive


Flash drive, a typical USB mass storage device, commonly known as the USB. The USB is a mobile device that stores our day-to-day data. As common mobile device users, we should understand the importance of password protecting a USB. USB's are vulnerable, as they are likely to be lost because of their small size, stolen, or can be simply corrupted.

Imagine you have some important data on the USB stick, not music or videos, however people often put something like business presentation, coursework, and contract draft in the USB. In order to avoid data theft from the USB we need to protect our USB by using USB encryption software, in other words, a PASSWORD. Common USB encryption software is Wondershare USB Drive Encryption. This software can provide your USB stick with password protection. In addition, it provides you with a read-only option- an option that allows you to read data from the USB ONLY rather than altering the data - to protect the encrypted data on the USB flash drive. 

Here are some tips that will help you increase you protection rate: 
  • Keep personal and business USB flash drives separate.
  • Use anti-virus software, a firewall and anti-spyware software to make you computer less vulnerable to attacks, as you know, USB flash drives can easily be infected with a virus that might corrupt the data in the USB. Also, make sure to keep the virus definitions up to date.
  • Do not attach your USB flash drive to an infected or public computer, since the virus will be transferred to the USB in no time infecting all the data in your USB. This data maybe not be recovered depending on the nature of the virus.
  • It is good practice to backup your data on daily basis. If not daily, then weekly basis is enough. This will help you recover your data since you have a copy of your data in case your USB flash drive is corrupted or lost.
  • Always make sure you unplugged your USB flash drive wherever you are. People are likely to forget to unplug it.
  • Do not put your USB anywhere you might forget later. Put it with your keys or in a safe drawer.

Thursday, March 29, 2012

No! I'm Not Falling For That One!

I received an E-mail message informing me that someone had posted something about me on twitter; the message came with a “click here”in order to view the twitter mention.

Although the email feels suspicious, I decided to play along; when I clicked on the “click here” link I was directed to the Twitter Sign On page with the message “Your session has timed out, please re – login.”

As I looked at the URL address this site has, I got the whole idea.
Another Lame method to steal accounts

Before you type in your credentials to login to any website, look closely at the URL. Don’t fall for these silly tricks.

facebook , twitter, hotmail and many other websites use https and not http in their “Login Page”.
It is a very good idea to look for https before you login.

Friday, February 3, 2012

Password Security: The Main Vein

What are Passwords
Passwords are unique strings of characters that users provide in conjunction with a User ID, to gain access to an information resource. Passwords are critical in ensuring privacy and security on the computers you use every day, whether at home or at work.
People use passwords to access various resources. These resources include but not limited to: access to personal computers, applications, networks, internet services: Hotmail, Gmail, Facebook, etc... User IDs and passwords are used to authenticate users to a particular resource and sometimes are used to track user activity while using that resource.
Your passwords should be treated as "high sensitive information", and you are responsible for taking the appropriate steps to select and secure this information.
General Password Guidelines
Information system users should be aware of the characteristics of weak and strong passwords in order to ensure adequate protection of their information. If someone obtains your User ID and password, that individual can imitate or impersonate you, and the system will not detect any anomaly. Identity theft, credit card compromise, loss or inappropriate use of your webmail or your social networking account could happen as a result of poor password management.
Poor passwords have any of the following characteristics:
·  Less than eight characters.
·  A word found in a dictionary.
·  Match or includes your username
·  A common usage word such as:
o Names of family members, friends, co-workers, sports teams, movies.
o Computer terms and names, sites, companies, hardware, software.
o Word, number or keyboard patterns like "aaabbb," "qwerty," "123321"
·  Consist of repetitive patterns such as " ahmahm", "passpass"
·  Any of the above cases preceded or followed by a digits (i.e. "qwerty123", "111aaabbb")
·  Consist of all same characters or digits, or other commonly used or easily guessed formats.
Strong passwords have at least three of the following characteristics:
·  8 or more characters long; (I personally recommend 10 characters)
·  Contain both upper and lower case letters.
·  Include digits and special characters as well as letters. (special characters: ()*&$#@ )
·  Should not be word in any language.
·  Should not be based on personal information, names of family, hobbies…etc.
One of the best practices in creating a password is to utilize the first letters found in each word of a well remembered sentence. For example "I spend more than seven hours online per day" the password would be: i5Mt7H0pD (notice the 5 instead of the s and the 0 instead of the o).
Security Tip: refrain from writing down the password. Instead, you should create passwords that you do remember. A good password is easy to be remembered yet hard to be guessed.
Password Protection
Handle your username and password with as much care as your credit card. Do not use the same password for all your online services and activities: i.e. Facebook password ≠ twitter Password ≠ hotmail password ≠ Gmail Password ≠ Online Banking password, especially if these services depend on each other to perform password recovery (forgotten or stolen passwords).
The following is a list of things that you should abide by to protect your password:
1.      Don't reveal your password to anyone.(Not even individuals who claim to be from support)
2.      Don't reveal your password in an email message.
3.      Don't talk about your password in front of others.
4.      Don't hint at the format of a password (i.e. "my family name").
5.      Don't reveal your password on questionnaires or security forms.
6.      Don't share your password with family members.
7.      Don't reveal your password to your friends.
8.      Don't leave your written password anywhere accessible by other people.
9.      Use a well known updated antivirus to insure that your system is not infected by any "password capturing malicious application". (Virus, worm, Keylogger etc...)
10. Although systems and application hide the password characters you type from your screen display, you are responsible to insure that no one is watching while you type that password on your keyboard.
Changing Passwords
Passwords should be changed on regular basis, some systems remind users that they should change their password; other systems expire your password validity and force you to change it.
But you should keep in mind, when changing your current password; you should not use a previously utilized password even if it has the characteristics of a strong password.
If a password has been compromised or forgotten, the user may obtain a new password or have their password reset by utilizing the "forgot password" option. This option is usually found within the login area on WebPages. This process saves the day by sending reset instructions to:
·         Recovery email (Much like what Hotmail, Facebook and Gmail do).
·         Mobile phone via SMS. (Gmail)
Finally: If at any time, you suspect that your password has been compromised, change it immediately. Better safe than sorry!!