Sunday, May 12, 2019

Seven behaviors that make you vulnerable to fraud

AARP Magazine regularly publishes extremely useful content about scams conducted by phone and email. Recently, AARP released a relevant article about what makes us vulnerable to fraudsters. Here are those seven personality traits:
  1. You respect authority.
  2. You like to please people.
  3. You are cocky.
  4. You slipped up once.
  5. You're friendly.
  6. You are under stress.
  7. You're lonely.
In a nutshell, we are vulnerable because we are human. The best way to avoid becoming victim to fraud is not to believe everything you hear or see, and to put a stop to the bad habit of clicking links and opening attachments without first thinking and validating the source.

For the full article, see https://www.aarp.org/money/scams-fraud/info-2019/vulnerable-to-fraud.html, by consumer fraud experts Amy Nofziger and Mark Fetterhoff.

Sunday, February 10, 2019

Free cyber security training videos for family & friends

KnowBe4 is an organization with expertise in cyber security exploits that use social engineering tactics to trick everyday folks like yourself into clicking a link, opening an attachment or replying to a suspicious email. Recently, they developed some basic online cyber security courses targeted for families and children.

I stepped through some of the modules, and what I saw is quite useful. The videos are brief yet informative enough to keep you engaged.

To complete the courses, go to https://www.knowbe4.com/homecourse, and enter password homecourse. The courses are free and you don't have to provide a shred of personal information to complete them. Way to go, KnowBe4!

Maybe you and your family can plan on stepping through one module each night after dinner. You'll be more cyber savvy for it! Here are the topics offered:

  • Passwords
  • Online banking security
  • Protecting your identity
  • Avoiding malware
  • Keeping personal info confidential
  • Protecting kids online
  • Securing your home network
  • Email and attachment safety




Tuesday, January 1, 2019

How to be cyber safe (and keep your identity secure) in 2019

I've been meaning to blog for weeks, but life gets hectic around the holidays.

Today on LinkedIn, a fellow cyber security pro posted a link to an article that neatly outlines the habits you should adopt in 2019 if you haven't done so already.

In summary

Do these:
  • Update your passwords. 
    • Personal tip: also consider modifying your username on sites that hold your most sensitive data - like your bank, for example. Don't use the same screen name that you use for your email and social media posts. Append it with a few characters that you associate with that site.
  • Stop oversharing.
  • Restrict yourself to secure web sites.
  • Stay updated.
  • Back up [your data], not down.
  • Take extra care with emails.
  • Use a VPN. [See article link below for VPN comparison info.]

Details

For more information, go to Seven cyber security resolutions to boost your security at https://securethoughts.com/cyber-security-new-years-resolutions/.

Happy New Year, all! May God bless you and keep you today and always.

Tuesday, November 20, 2018

Thanksgiving Day phishing emails with .doc attachments

There's a phishing scheme in the wild that invites the email recipient to click an attached Word document (.doc) file.

The subject line resembles one of these:
  • Thanksgiving Day congratulation
  • Thanksgiving Day Greeting Card

If you've been following this blog, it goes without saying that you should never (ever!) open unexpected attachments—even if the sender appears to be someone you know.

Always be skeptical of any message that contains hyperlinks or attachments, and be wary of unexpected messages or those that contain out-of-the-ordinary language.

It's the holidays. Be extra alert and remember this motto:

Stop. Think. Don't click!

Thursday, November 8, 2018

Online holiday shopping: How to stay safe out there

A few nights ago I logged in to Amazon to order a couple of household items. A banner quickly caught my eye, enticing me to view the "early Black Friday deals." I did. And I spent $150. It was three weeks before Thanksgiving.

The holiday shopping season comes earlier every year. This season, we'll spend over $700 billion. With the rise in spending comes an increase in online scams. In 2017, holiday scams were up 20% over the previous year. Expect even more this year.

Cyber thieves are forever devising more clever schemes to get us to click. And they can be very convincing. You don't need to be a victim.

Instead, outsmart them by changing one online behavior: Stop clicking links in emails and text messages. Instead, navigate to the site you want to visit online by typing the URL in the address bar of your browser.

Until you learn to be skeptical of every single attachment and hyperlink that you receive in a digital message, you are more likely to fall prey to a phishing scam or fake web site.

If you absolutely must click a link, first hover over the text to view the real destination behind the link. Make doubly sure it points to a domain that is both legitimate and trustworthy. Blindly clicking on a link is like walking unarmed down an unlit urban alley alone late at night. You do not know what is lurking.

Next time you log in to do some shopping, repeat this mantra:

Stop. Think! Don't click.

Friday, October 26, 2018

Top 10 ways of keeping kids safe online

Sophos is a security company in the UK that offers up some great security awareness content. Below is a list of ten short and simple tips to share with your children. For more information, see https://nakedsecurity.sophos.com/2014/02/11/safer-internet-day-dont-be-an-online-sheep-our-top-10-tips-help-you-think-before-you-act/.

  1. Limit your Facebook profile to your friends only.
  2. Accept online friend requests only from people you already know, and like, and trust.
  3. Only upload things you are happy for the whole world to see, including your parents, friends and even your enemies.
  4. Never give out your address or agree to meet in person someone you’ve “met” online.
  5. Set a password lock on your phone or any other device you use, and make sure it locks automatically when you aren’t using it.
  6. Don’t click on suspicious-looking links.
  7. Tell your friends in person if you receive unusual messages from them. (Someone could have stolen their passwords.)
  8. Always log out – don’t leave any account open when you go away from your computer, phone or other device.
  9. Don’t pick easy passwords – mix up letters, numbers and funny characters so other people can’t guess what you chose.
  10. If you see something upsetting, or dangerous, or dishonest, speak up! Tell a parent or a teacher.

Saturday, September 29, 2018

Use Facebook? Time to change your password

This week there was a Facebook breach that affected 50 million users. Three days later, on Friday September 28, 2018, all of those users were forced to change their Facebook passwords. Even if you were not required to change your password, it's a good idea to do it anyway. Do it this weekend.

A Forbes article about the breach also recommends that you log out of any other web sites where you authenticate using your Facebook credentials. To access this information in Facebook, click apps and web sites, then logged in using Facebook. Remove the apps that you've used your Facebook account to log in to.

Go to settings and click security and login. Select the single-click option to log out of Facebook and every app or site where you are logged in using Facebook.

If you haven't enabled two-factor authentication on Facebook, do it today. Employ the same protection for any site holding sensitive information about you. This should include your email account (if multi-factor authentication is offered by your email provider), your banking and insurance web sites, your retirement and investment sites/apps, etc.

And, finally, if you are not using a password manager to store and encrypt all of your app passwords, start doing that today. LastPass, 1Password and KeyPass are just a few password managers available. Most have a free option. Writing down passwords and re-using them across various web sites or apps is a huge risk that is easily avoided by using password manager software.

For more information about the vulnerability that was exploited,  see https://www.forbes.com/sites/kateoflahertyuk/2018/09/29/facebook-data-breach-what-to-do-next/#b7fe4852de35.