Showing posts with label lastpass. Show all posts
Showing posts with label lastpass. Show all posts

Friday, January 6, 2023

A Breach at LastPass Has Password Lessons for Us All, Who is using your Home WIFI, Patch Tuesday

 

LastPass Password Manager suffers a Breach.

I always hear gripes about passwords, their complexity and the need to change.  This is not a subject to be taken lightly.  A password is all that stands between your personal/financial info and bad guys trying to steal your info or monies.

Everyone needs some system to record these keys and protect this information.  I personally use a contact located in an Outlook PST file that is password protected.  You could also use an Excel spreadsheet to record your passwords and then password protect it.  However, this is another password you need to remember.  Also, there are utilities available for purchase that will break Excel password protection.

Some people use the password managers built into browsers.  These too are vulnerable and if anyone knows your login password, they can expose your saved passwords in a browser.  please see my prior post from 2019 about this,  Browser Password Security

So what is one to do?  Many have paid for online password managers such as LastPass.  LastPass is an online password manager with a personal Premium version available for $3/month billed annually.

There have been many online credit card, bank, credit union as well as other breaches of user information.  Why would an online password manager be any different?  It's not, LastPass has been breached exposing tens of millions of customer credentials and keys.

In other words, the hackers hit the lottery.  From an article on the NY Times;

When you use a password manager like LastPass or 1Password, it stores a list containing all of the user names and passwords for the sites and apps you use, including banking, health care, email and social networking accounts. It keeps track of that list, called the vault, in its online cloud so you have easy access to your passwords from any device. LastPass said hackers had stolen copies of the list of user names and passwords of every customer from the company’s servers.

If you are a LastPass customer, please read the article in the link below to determine what steps you need to take to safeguard your valuable information.

LastPass Hack-NY Times


Keeping your Home WIFI/internet connection secure.

If the above doesn't shake you, there is more good news.

You need to keep your home internet connection secured.  There are courses available online that teaches how to expose and connect to WIFI networks.  These are the ones that can be seen via available networks.  Has anyone watched the TV series, Mr. Robot?  In the series, the main character/hacker uses Kali Linux to break into networks and computers to fight big (overreaching industry).

Kali Linux is a hacker's dream OS and is loaded with tools for breaching systems.

Anytime you are in public and connect to a Mall's WIFI or any guest WIFI, be aware that all your info is being transmitted without encryption including user name and password.  So don't access bank or credit card info while using these networks.  I get dragged to Perimeter mall by Boss Lady and I am usually stuck outside the coffee bar at Nordstrom's waiting. I have witnessed many times the same 2 characters armed with a notebook and an external WIFI adapter which is needed by Kali to intercept internet traffic.  The internal WIFI adapters built into computers aren't any good for hacking.

With that warning said, back to your home internet, please see the info in the following link;

How To Tell If Someone Is Using Your WiFi, And How Remove Them (msn.com)


FYI, Next Tuesday is Microsoft Patch Tuesday.








Thursday, March 7, 2019

Password Security, why 'ji32k7au4a83' is a common and terrible password

The last defense of your business and personal financial information against compromise is your online and/or computer passwords.  Choosing a good password is essential to prevent your confidential information from being stolen, sold and exploited on the internet.

More often than not, people don't put a lot of thought into their passwords.  They use some combination of birthdays, child or pet name and street address to cobble up a password.  In doing so, they haven't thought that a lot of this information is unprotected and readily available on the internet.

When you are online, you are shoulder to shoulder with people from all over the world.  This thought segues perfectly into the title of today's post and the accompanying article behind it,

"why 'ji32k7au4a83' is a common and terrible password"

It is not a long article but gives insight into the need for complex passwords and that people in the U.S. are not the only ones with password security issues.

Remember people have used the following examples for their passwords;  password, abc123, 1999 and variations of the word "password" such as P@$$w0rd.  A large client of mine used this regularly or some variation until recently, and they had a full time IT department, several hacks as well as I recall.

https://www.zdnet.com/article/the-reason-why-ji32k7au4a83-is-a-common-password/?ftag=TRE49e8aa0&bhid=27630927001468733386426006914379

No one said online security is easy but at the very least please apply these basic rules when it comes to safeguarding your information and ensuring a pleasant online experience;

1.  When choosing your password, use unrelated complex random sequences of letters/numbers and special characters (if they are allowed).

2.  Do not use the same password for different accounts.

3.  Change your password annually if not more frequently.

If you are typical of most people, this can be a lot of passwords.  The use of a password manager is one option for you.  Password managers such as Dashlane and LastPass are good solutions but you must make sure that your computer is free of malware before installing a password manager and that you protect and keep it clean afterward.  A password manager cannot provide security on a machine that is compromised.

Thanks for reading and stay safe!!!





Friday, March 16, 2018

Office 365 and Cloud Security - Passwords

Office 365 is a great product and the subscription model provides services and up to date software on an affordable monthly basis.  It like other cloud services have become the norm for a lot of businesses as internet speed approaches what use to be the standard for in-house LANs, 100 Mbps.

It is this connection speed that has allowed the "cloud" to become ubiquitous in today's business climate.  But the cloud is not some magical new device, it is actually a server owned by someone else located somewhere else.  In the past it was imperative we protect a business server from attack via strong passwords, firewalls and/or virus software.  Hackers were searching public IP addresses for Exchange, SQL and other servers to attack.  They still are and Office 365 is a prime target.  Although the online services scan the incoming email for malicious content, not all is prevented from getting through.  Users constantly receive email phishing attempts trying to coerce them out of their login info by verifying the account to a bogus link.

I have one client who I provide accounting software/services who use Office 365 purchased by their in-house IT department.  He told me the phishing/spam seemed to increase when they switched to the online service.  They too had an account hacked in an attempt to steal money.

In the past month, 2 different clients of mine had their Office portal passwords compromised.  These were not obvious passwords either.  In one case the hacker worked silently and studied the email in the inbox gleaning the firm's banker information and other data that could be used for financial gain.  The hacker then created inbox rules so that any incoming emails that contained information related to the banker's email address or containing words such as "wire transfer" was forwarded to a Gmail account and then deleted so the compromised account holder wasn't aware of his actions.  The information gathered allowed the hacker to act on behalf of the compromised user for certain actions.  The hacker then attempted a wire transfer which the alert banker was suspicious of because the signature block was normal and it was not the standard operating procedure for the firm.

When I was contacted we immediately changed her portal password and upon analysis of the email determined the origin of the IP address was Nigeria.  Changing the password stopped any further meddling by the hacker but we still did not know about the rules the hacker had created.

The company also used an online recruiting firm to fill positions in the firm.  The hacker had created a rule to divert email from the recruiting agency to the Gmail account and then delete the email to hide his actions.  Next, the hacker requested a password reset which was forwarded to the Gmail account.  The password was changed thus allowing the attacker access to the firm's account with the recruiting firm.

This was discovered when an applicant contacted the firm about a position that was advertised online.  When the administrator attempted to log in the password did not work.  After multiple requests for a password reset the administrator discovered the password reset emails in her deleted items.  The hacker's reward was a charge to a credit card with funds diverted to the hacker.

In the second case, the compromised account was used to spam email containing a link to a malicious payload to anyone who clicked on it.  It was disguised as a Purchase Order needing approval.  In this attack, the hacker had created rules to delete any returned emails marked as "Undeliverable" to hide the fact that the account was being used to send spam.

Solutions:

Since the attack. we have changed all passwords at the first client using passwords generated by Microsoft and reimplemented the policy of changing passwords every 90 days.

I hear a lot of complaints about having to use/change passwords but in today's online environment it is imperative that you use strong passwords, change them periodically and do not use the same password for everything.  If you have your email account hacked, I know you do not want to run the risk your banking account is now vulnerable.

If you have a lot of passwords and find the task too frustrating to maintain, consider a password management software such as dashlane or Lastpass to help.  For an annual fee, you will only have to remember 1 password, the master password to the password manager itself.  Below is a link to an article about the best password managers for 2018.

https://www.tomsguide.com/us/best-password-managers,review-3785.html


Crypto-currency News

oh man! crypto-currencies continuing to tank. Be careful trying to catch a falling knife. I'm looking to get back in, it's hard to get into Ripple XRP, my experience.

https://www.cnbc.com/2018/03/15/bitcoin-price-over-60-billion-wiped-off-value-of-cryptocurrencies.html

https://www.politico.com/magazine/story/2018/03/09/bitcoin-mining-energy-prices-smalltown-feature-217230

https://www.msn.com/en-gb/news/world/a-new-york-town-just-placed-a-moratorium-on-crypto-mining/ar-BBKiZdv


New Intel Gen 7 & Gen 8 computers!

Cloud PBX services

TEST