Driving Force Software

Solutions for the Small Business and Enterprise

Tuesday, April 16, 2019

Ransomware: The cost of rescuing your files is going up as attackers get more sophisticated

The average ransom demand is up to almost $13,000, compared with $6,700 just a few months ago.


The sharp increase in ransom payments is linked to the emergence of more expensive and more hands-on forms of ransomware like Ryuk, Bitpaymer and Dharma.

While ransomware attacks of the past generally relied on spamming out large numbers of phishing emails in the hope of getting a few hits, now cyber criminal groups are taking a more focused approach with attacks.

They are now attacking computers directly across the internet.  The new forms of ransomware rely on more direct attacks on computers.  They are exploiting security holes in remote desktop protocols (RDPs) to gain access to systems and once in they are attempting to infect and encrypt as many computers as possible on a network.  That is why it is so important to install updates on your system and not to use outdated operating systems that are no longer supported by manufacturers, see prior post below.

https://dforceatl.blogspot.com/2019/04/windows-updates-problems-and-new.html


Office 365 users are targets of phishing attempts attempting to steal their credentials.  It is easy to copy the underlying source code of a website, Office 365 portal for example and then publish it to create a fake website that looks like the genuine site (you must pay attention to URL).  The target will receive an email allegedly from Microsoft threatening to close the account unless action is taken.  The link to the phony site will then ask for your email and password.  If the info is supplied, the attacker will then take charge of your account, encrypting OneDrive, Sharepoint and using the compromised email to send phony financial documents and other attachments which will appear to come from a trusted source by the recipients.  Be careful.

If you are a victim of ransomware, the attackers can command ransom payments of six figure sums – which attackers demand in cryptocurrencies like Bitcoin.

While the authorities generally don't recommend that victims of ransomware attacks pay the ransom demand – it funds criminal activity and there is no guarantee it will work anyway – in some cases, organizations feel as if they don't have a choice.

It was last month that I wrote about Jackson County, Georgia paying $400,000 to criminals that had infected it's systems with ransomware.

https://dforceatl.blogspot.com/2019/03/georgia-county-pays-400000-to-hackers.html

To read more about the threats, use the links below.

https://www.zdnet.com/article/ransomware-the-cost-of-rescuing-your-files-is-going-up-as-attackers-get-more-sophisticated/

https://www.zdnet.com/article/ransomware-an-executive-guide-to-one-of-the-biggest-menaces-on-the-web/

- April 16, 2019 No comments:
Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Labels: BitCoin, bitpaymer, dharma, ransomware, ryuk

Friday, April 12, 2019

Windows Updates - problems and new Feature Release 1903 due soon.

Since Windows as a Service (SaaS) became the norm with the introduction of Windows 10, Microsoft has been making changes to the way it rolls out updates to end-users to keep the OS up to date.

The update process has not been a smooth one.  Microsoft's VP of Windows last week acknowledged that updating can be "disruptive".  It was in October of 2018 when Microsoft rolled out version 1809 and many users found that their files had been deleted due to a bug.  I'm not sure if the bug was part of the update or the new OS itself but Microsoft halted the update for 6 weeks until the issue had been resolved.

It's not an easy task for Microsoft.  There are over 800 million PCs running Windows 10 worldwide.  Unlike Apple which controls every facet of their products, there are hundreds if not thousands of PC hardware manufacturers.  Since some make only components to be used in a finished PC, this leads to innumerable variations in hardware.  Add to that all the available software that can be installed and user personalization that makes anticipating every outcome difficult if not impossible.

It is important that you update your Windows to ensure that security holes and bugs have been patched.  Not doing so leaves your computer exposed to hackers and criminals who are always evolving as well as the tools they use to attack your system and steal your data.

There is a new feature coming with the next Windows feature release called "SandBox" that will allow your computer to run in a secure lightweight environment to protect your computer from Malware without affecting the normal Windows installation.  Believe me, you will want this.

There are major updates available now for Windows version 1809 and we are on the cusp of the first major Windows feature release of 2019, version 1903 due for release any day now.

https://medium.com/@win10tricks/windows-10-1903-april-2019-update-release-date-new-features-and-improvements-f49953f6f595

If you are unsure which version you are on, execute the command "Winver" in the Search Box


or use run (Win +R), then type Winver.  Your version will appear similar to below;




to read more, check the links below and Thanks for reading!

https://www.zdnet.com/article/windows-10-updates-why-microsofts-battle-isnt-over-yet/


Microsoft's April Patch Tuesday comes with fixes for two Windows zero-days

https://www.zdnet.com/article/microsofts-april-patch-tuesday-comes-with-fixes-for-two-windows-zero-days/?ftag=TRE-03-10aaa6b&bhid=2219791


Windows 7 problems: Microsoft blocks April updates to systems at risk of freezing

Microsoft has blocked this week's monthly and security-only Windows 7 and Windows 8.1 updates for Sophos antivirus users after widespread reports that computers failed to boot after installing them. 

The problems are caused by Microsoft's Tuesday Windows 7 and Windows 8.1 monthly rollup and security-only updates KB4493467, KB4493446, KB4493448, KB4493472, KB4493450 and KB4493451. 

https://www.zdnet.com/article/windows-7-problems-microsoft-blocks-april-updates-to-systems-at-risk-of-freezing/?ftag=TRE-03-10aaa6b&bhid=27630927001468733386426006914379

https://www.forbes.com/sites/daveywinder/2019/04/12/microsoft-confirms-latest-updates-are-freezing-windows-heres-how-to-fix-it/#4e025fb84d99


New Intel 8th and 9th Generations Workstations.




- April 12, 2019 No comments:
Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Labels: Microsoft Update, patch tuesday, version 1809, version 1903, Windows 10, windows as a server, Windows update

Wednesday, April 3, 2019

GA Tech 1.3 million data breach, Albany NY, latest victim of Ransomware. Is your Office 365 OneDrive and SharePoint safe?

Potentially 1.3 million current and former students affected by Georgia Tech data breach

Although world renowned for its computer science programs, Georgia Tech has exposed the second data breach to occur at the school in less than a year.  The news was announced yesterday and the potential fallout of exposed names, addresses, SSNs, and birth dates could affect 1.3 million current and former students.

Read all the details in the following link;

https://www.ajc.com/news/breaking-news/breaking-data-breach-exposes-georgia-tech-faculty-students/zAUUNWy5hoHQ8bNvMxcsWL/

New York capital hit by ransomware attack, taking services offline

Albany, NY is just the latest city to become a victim of ransomware, the city announced Saturday, 03/30/19.  City services impacted so far is limited to its ability to offer birth, death and marriage certificates.  People seeking these services are having to visit state vital records offices.

Albany police are said to have no access to any service or program that relies on internet connection.
The situation is still being assessed and inquiries to the Mayor's office on Monday were not being responded to.

Ransomware attacks on cities have been increasing due to lax security and that the attack is more likely to be successful.  Citizens depend on city government services thus city official feel more pressure to resolve the situation.

Gregory McGee, the Police union's vice president, said that the ransomware was also affecting computers in patrol cars related to "incident and accident reports."  "One has to ask the question of why a police department with sensitive information is on the same network that was so easily attacked."

In March of 2018, Atlanta, GA was targeted.  City officials refused to pay and recently the ongoing recovery process has been estimated to cost $17 million.

Two Iranian hackers have been charged by the Justice Department with using malware to attack targets with critical infrastructure or that offer critical services.  Hospitals have been targetted and in many cases, the victims could not pay but the alleged hackers have still taken in $6 million.  The Iranians remain at large since there is no extradition treaty with Iran.

https://www.bleepingcomputer.com/news/security/new-york-albany-capital-hit-by-ransomware-attack/

https://www.cnet.com/news/new-york-capital-hit-by-ransomware-attack-taking-services-offline/


Office 365, OneDrive and SharePoint folders.  Are you safe from Ransomware?

Many companies today have Office 365 and use OneDrive and Sharepoint to synchronize their onsite server and Cloud services.  This is a backup in the traditional sense.  However, ransomware encrypts the files on your system, rendering them unusable.  They cannot be opened or viewed without the key to decrypt them.  Hence the term ransomware because the attacker generally will request a payment be made in cryptocurrency to obtain the key.

If your server or computer is attacked by ransomware and it syncs with your cloud then it will overwrite the files in the cloud.  Fortunately, OneDrive has a feature called versioning.  Up to 50 previous versions of any Microsoft Office file exists and you can revert to the good version that was overwritten.

Unfortunately, this works only for MS Office files.  Ransomware will encrypt jpegs, PDFs and all files located on a computer.  So all non-related Microsoft Office files are subject to be lost.  It will also be time-consuming and troublesome to have to reversion all your Office data.

It is therefore imperative that you keep multiple day backups of your data.  You should keep multiple days in case the attack happens and goes undetected for a day or two.  If you have only a single day backup, say the same backup occurs to the same external drive daily and you get attacked, you could end up with a backup of the encrypted data.

Redundant backups are a good insurance policy in the event of a Malware attack.  Hardware failure is no longer the main threat to your data.  Organizations and staff must protect against the constant threat of malware and ransomware in today's IT climate.  A good backup plan is essential to safeguard your data.

Start examining your backup and security needs today before it's too late.



Support for Windows 7 ending 01/14/2020.

If you are still using XP based systems then there has not been any security patches or updates to your computer since 04/08/2014.  Experts agree that you should not use Windows XP based computers to access information and email on the internet.  There aren't any modern browsers or AV software for these computers available any longer and the risks to your data and personal info is exponential.

In approximately 8 months support for Windows 7 ends.

Plan today to upgrade your systems to a new DForce Intel based computer with the newest Generation 8 and 9 Intel processors running Windows 10.






- April 03, 2019 No comments:
Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Labels: Albany, Albany New York, Albany NY, Backup, cloud, data, data breach, GA Tech, Georgia Tech, MS Office 365, office 365, Onedrive, ransomware, SharePoint

Tuesday, April 2, 2019

Software glitches, Fatal results. Boeing 737 Max and now Tesla Autopilot hacked.

Everyone I'm sure has heard about the awful fate of the 2 Boeing 737 Max crashes.

The crashes were linked to a faulty device called the angle-of-attack sensor which incorrectly activated an automated system that caused a nosedive that the pilots could not recover from.  As of yesterday 4/1/19 the fleet remains grounded.

Boeing’s software update for its troubled 737 Max jetliners has been delayed after the company deemed further work was needed on the fix before it was submitted to the Federal Aviation Administration.

The Max, Boeing’s newest plane, was grounded by regulators around the world in March after the crashes of two Max aircraft within five months.

As part of its process to return the Max to the air, Boeing has been working on a software update to new anti-stall system, known as MCAS, that was included in the Max.

https://www.nytimes.com/2019/04/01/business/boeing-737-max-software-fix.html

and now this;

Hackers reveal how to trick a Tesla into steering towards oncoming traffic

It's bad enough when your computer crashes due to a faulty update or glitch in the software.  Hell, I was mad when Sony updated my Android TV and it crashed daily until I got another update.  However, I don't want to think about such errors threatening my well being and health or that of others.

The latest thing to worry about is autopilot on your car.  Hackers have now revealed that they were able to trick Tesla's autopilot feature to steer into the wrong lane remotely.

The team of hackers was able to insert malicious code into the steering wheel controls and connect it to a Bluetooth gamepad controller.

The Autosteer mode of the vehicle use camera feeds and computer vision to navigate traffic lanes.  The researchers were able to tamper with how the vehicle recognizes traffic lanes.

Tencent researchers tested out their theory by applying some simple stickers to a road surface, and this confused the machine vision system enough to go AWOL and, theoretically, could be used to divert these cars into oncoming traffic.

Tesla reports that this is not a real concern of theirs since the driver can simply override Autopilot at any time by using the steering wheel or brakes.   However, Boeing said the same thing about the override for the pitch control on the 737 Max only some pilots had not been trained on this.  I hate to think about the average Tesla driver's abilities, not paying attention or panic overriding correct actions.

Technology is a wonderful thing but when it comes to certain things, people should not become overly reliant upon technology.  Tencent researchers, the hacker group who brought this to light, did so in the name of safety.  I'd hate to think what a teenager would do with the knowledge and capability to execute this.

When it comes to Tesla, the company is not exempt from the same security concerns -- having recently been hacked at Pwn2Own -- but the vehicle range's computer systems can also come in useful, too, beyond Autopilot. Earlier this week, the Tesla's Model 3 new Sentry Mode caught a vandal in the act while she was scratching up the car, leading to her arrest. 

Read the entire article at;

https://www.zdnet.com/article/hackers-reveal-how-to-trick-a-tesla-into-steering-towards-oncoming-traffic/?ftag=TRE-03-10aaa6b&bhid=27630927001468733386426006914379
- April 02, 2019 No comments:
Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Labels: 737 max, autopilot, autosteer, malware, pwn2own, tesla, tesla hacked

Thursday, March 21, 2019

Testing your Internet. Are you getting what you pay for and is it enough?

Internet connectivity, now and in the near future.

We are constantly being pitched sales ads about entertainment and internet connectivity options.  Dish versus cable, WiFi, Fiber, and streaming.  Your bandwidth is a constant and with the increasing demands being placed on it by more and more connected devices you may be seeing some performance degradation in your online experience.

Although the theoretical peak bandwidth of a network connection is fixed according to the technology used, the actual amount of data that flows over it (called "throughput") varies over time and is affected by higher and lower latencies.

If you only Facebook, email or surf the internet, you can probably get by with a low-end plan from your internet service provider (ISP).  However, if you have multiple TVs streaming Netflix, Prime, Hulu, and other entertainment services and more than 1 computer, you need all the bandwidth you can get.  Don't forget the smartphones, Alexa(s), Google Home, and Ring doorbells live streaming video to your phones, Alexa devices, and computers.

Bandwidth is analogous to the plumbing in your house.  Just like larger plumbing pipes have the ability to increase the flow of water in your house, increased bandwidth allows for a larger flow of data to and from your connected devices.  Too little bandwidth can cause slow performance, choppiness even stoppage on your TVs, computers, and devices.

How to test your Internet Speed.  The following link is to a site that will accurately measure your internet speed and give you an idea of your present bandwidth.  It also measures latency.

https://speedof.me/

Excessive latency creates bottlenecks that prevent data from filling the network pipe, thus decreasing throughput and limiting the maximum effective bandwidth of a connection. The impact of latency on network throughput can be temporary (lasting a few seconds) or persistent (constant), depending on the source of the delays.

https://www.lifewire.com/latency-on-computer-networks-818119


- March 21, 2019 No comments:
Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Labels: internet connectivity, ISP, latency., throughput

Tuesday, March 12, 2019

Georgia County pays $400,000 to hackers, why you shouldn't buy a new Apple Mac now

Georgia county pays a whopping $400,000 to get rid of a ransomware infection


Are you still complaining about the cost of anti-virus and firewall protection for your computer systems?  Still got the free version of AVG, Avast, Malwarebytes as your main protection?  You have no backup software or disaster plan in place?  I know firms that do not take backup seriously, don't have time.

It used to be the crooks robbed the banks because that's where the money was.  Today, most firms and people conduct some if not all their financial activity on the internet.   Criminals know this too and engage in less risky but no less lucrative activities by trying to steal your credentials and financial information.

There is another segment of cyber-crime that affects businesses, data hijacking.  If your firm is the victim of a ransomware attack, the malicious payload is the encryption of all your data files and it turns your data into useless files halting the ability to continue ongoing operations.

It happened recently to Jackson County Georgia and cost the county $400,000.  On March 1st the local government's computer systems were hit by the ransomware that forced local law enforcement and government to work the way they did prior to computers, by paper.   The Sheriff said they continued to function, it was just more difficult.

The county consulted with the FBI and a cyber-security expert.  After negotiations with the ransomware hackers, $400,000 was paid to get the decryption key to free the county's data.

It was just under a year ago that the city of Atlanta paid $3 million in contracts to recover from a ransomware attack on its systems.

Click on the link below to read the entire story.

https://www.zdnet.com/article/georgia-county-pays-a-whopping-400000-to-get-rid-of-a-ransomware-infection/?ftag=TRE-03-10aaa6b&bhid=27630927001468733386426006914379

The downsides of buying a new Mac

The hefty price tag is only the beginning of the pain that comes as a result of buying a new Mac.

Mac users, what to say.  You would think that anyone who pays that kind of money must do a lot of transaction crunching or have a need for computational power not found outside Cray computers.  Not true.  Until 2005 Apple used the Power PC manufactured by Motorolla/IBM and we were told how superior these were to Intel processors, but then they switched to Intel???

Most Apple users surf the internet, open e-mail and use Microsoft Office.  A complaint I hear from current and former PC users, it is not as efficient or intuitive to manage multiple instances of Office Apps at the same time.

And the choices are?

How insane is the purchase of optional items when buying a Mac?  Look at the prices on these options;

Core i7 to Core i9 processor, $300

a bump in RAM from 16 GB to 32 GB, an extra $400

need more storage, upgrading from the base 1 TB drive to a 4 TB drive for $3200.  Yes, you can add a 4 TB option to your base $2,799 model for an extra $3200.

My gamer clients and friends in the PC world laugh at this because Apples use the same components that are found and offered for PCs.  The difference is PC users don't need the Apple store to work on their computers (notebooks are an exception since they are not as accessible as desktops but RAM and hard drives can be accessed and upgraded on many Windows notebooks).

One can purchase a 4 TB Samsung EVO 860 on Amazon for $549, this is an SSD, solid state Top of the line in performance.

https://www.amazon.com/Samsung-860-Inch-SATA-Internal/dp/B07L3CLM2B?psc=1&SubscriptionId=AKIAILSHYYTFIVPWUY6Q&tag=duckduckgo-d-20&linkCode=xm2&camp=2025&creative=165953&creativeASIN=B07L3CLM2B


It's incredulous, Ridiculoussness and more!  Read the entire article and if you upgrade every year, buy that Apple Mac.

Read more at;

https://www.zdnet.com/article/the-downsides-of-buying-a-new-mac/?ftag=TRE-03-10aaa6b&bhid=27630927001468733386426006914379










- March 12, 2019 No comments:
Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Labels: Apple, atlanta ransomware, encrypted files, encryption, jackson county, Mac, ransomware, ransomware attack

Thursday, March 7, 2019

Password Security, why 'ji32k7au4a83' is a common and terrible password

The last defense of your business and personal financial information against compromise is your online and/or computer passwords.  Choosing a good password is essential to prevent your confidential information from being stolen, sold and exploited on the internet.

More often than not, people don't put a lot of thought into their passwords.  They use some combination of birthdays, child or pet name and street address to cobble up a password.  In doing so, they haven't thought that a lot of this information is unprotected and readily available on the internet.

When you are online, you are shoulder to shoulder with people from all over the world.  This thought segues perfectly into the title of today's post and the accompanying article behind it,

"why 'ji32k7au4a83' is a common and terrible password"

It is not a long article but gives insight into the need for complex passwords and that people in the U.S. are not the only ones with password security issues.

Remember people have used the following examples for their passwords;  password, abc123, 1999 and variations of the word "password" such as P@$$w0rd.  A large client of mine used this regularly or some variation until recently, and they had a full time IT department, several hacks as well as I recall.

https://www.zdnet.com/article/the-reason-why-ji32k7au4a83-is-a-common-password/?ftag=TRE49e8aa0&bhid=27630927001468733386426006914379

No one said online security is easy but at the very least please apply these basic rules when it comes to safeguarding your information and ensuring a pleasant online experience;

1.  When choosing your password, use unrelated complex random sequences of letters/numbers and special characters (if they are allowed).

2.  Do not use the same password for different accounts.

3.  Change your password annually if not more frequently.

If you are typical of most people, this can be a lot of passwords.  The use of a password manager is one option for you.  Password managers such as Dashlane and LastPass are good solutions but you must make sure that your computer is free of malware before installing a password manager and that you protect and keep it clean afterward.  A password manager cannot provide security on a machine that is compromised.

Thanks for reading and stay safe!!!





- March 07, 2019 No comments:
Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Labels: change password, dashlane, lastpass, online security, password, password manager, security

Thursday, February 14, 2019

Your Google+ account is going away on April 2, 2019. Learn more

Your Google+ account is going away on April 2, 2019. Learn morWow!  Google fails to capture the FaceBook market.




Who remembers MySpace?  It was the original Social Networking site that was supplanted by Facebook.  Now Google+ faces the same fate.  Google+ for personal use will end on April 2, 2019 due to low useage rates.

Read more the entire story at;  https://support.google.com/plus/answer/9195133?hl=en&authuser=0



- February 14, 2019 No comments:
Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Labels: Google+
Password-stealing phishing attack comes disguised as a fake meeting request from the boss

I believe that most of my Office 365 cloud-based clients are now wary of the many different phishing attempts to steal login credentials via fake Microsoft login sites.  Phishing emails arrive using different tactics to entice you into surrendering your information.

Some examples;  you receive an email with an attached phone message, PDF attachment or a fax document.  When you click on the attachment or link it takes you to either a realistic replica of the Microsoft portal or a not so realistic page that require you to log in with your Office 365 or Outlook credentials.  These criminals have started including all major email services including Gmail, Yahoo, and other services on the landing page.  In many cases, they have already included your email address since they know who the phishing attempt was sent to.  All that is required to wreak havoc on you is your password.

If the email requires you to log in using your email and password to retrieve the document or attachment then assume it is a scam.  In either case, your login information is captured and then used to generate spam or steal your personal and financial information.

This week I have assisted 2 compromised clients.  Fortunately, in both cases damage was minimal.  The first client alerted me quickly when she started receiving email replies and phone call from contacts regarding spam sent from her  email.  In this instance, the hacker did not hide his tracks and I was able to retrieve IP info and track back to Lagos, Nigeria, not like there is any retribution for the perp.

The latest attempt shows an advancement in sophistication and tactics.

It just so happened I was doing some work for the client when the email arrived.  It was from the client's legit email address, but what got my interest was no address listed under the To:  field.


I opened my secure browser and copied and followed the link, it took me to a fake landing page and asked for my Office 365 credentials to retrieve the document.  Suspecting that the client had been compromised, I replied to the email and asked if he had sent it.  I received a reply almost instantly,

Yes, I sent it. It's quite a good read and definitely the most insightful I have read on. It's something that you will be more interested in.

Thanks

I logged into the Office Portal as the Global Admin and checked the Inbox Rules for the affected account.  There was a rule in place to delete all incoming emails.  This is done to prevent the victim from receiving emails like mine asking if the email was sent by them.  Often you will find that a forwarding email has been set up so incoming emails are sent to the hacker before deleting.  In this case, there wasn't a rule for forwarding.  However, I know there was a forward in place somehow since the perp was responding to my email, perhaps an autoreply with a standard message.

I was unable to reach the client by phone so after conferring with the office manager we decided it was best to change the password of the affected account.  She too had received the email.  When I was able to talk to the client by phone it turns out he was busy fielding calls from contacts who had received the email.

My next step was to ascertain the source of the email. This led to a new surprise.  This is the first example of this I've found, there were no internet headers.



 In concluding, be wary of any email with an attachment that requires your email credentials to retrieve.  It is a scam.

The Dangers when surfing the Internet

Emails are not the only way a hacker can exploit your machine.  Websites can be used to deliver malicious payloads to your machine that can steal your information or exploit your machine for use by the attacker.

Some popular add-ins and programs have been exploited in the past to infect computers by fake updates or exploiting security holes and weaknesses.  Adobe Flash Player, Java come to mind.  Popular programs for creating web pages are also attacked.  WordPress due to its popularity is no exception.

https://www.zdnet.com/article/another-wordpress-commercial-plugin-gets-exploited-in-the-wild/


Macs too are always under attack.  The latest Trojan:  https://www.zdnet.com/article/macos-malware-disables-gatekeeper-to-deploy-malicious-payloads/


Laugh of the Day, poor Internet Explorer...






- February 14, 2019 No comments:
Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Labels: Apple, email, exploits, Mac, malware, phishing, scam, trojan, wordpress

Friday, January 18, 2019

2 billion logins affected in possible record-breaking data breach

2 billion emails and passwords on the compromised list.

A new data breach has the internet world sitting up and paying attention.  It is estimated that over 2 billion email addresses and passwords have been compromised.  If you use the same credentials, email/password on multiple sites you should consider changing your password.  It is recommended that you use at least 12 characters in a password, see this link about password security.  https://www.berylliuminfosec.com/unique-passwords-matter-here-is-why/

There are password keeper programs available but realize those can be hacked as well.

Another way of securing your information is using multi-factor authentication.  Google, Yahoo, and Microsoft provide this service.  I use this security feature on admin accounts for client Office 365 accounts.

There is a free website that allows you to check if any of your emails have been compromised.  I have written about this site in the past, and if you have not checked, please do so today.  It is HaveIbeenPwned.com.  Type in your email address and if it is on the list, change your passwords.

To read more, click on the following link;

http://www.fox9.com/news/2-billion-logins-affected-in-possible-record-breaking-data-breach

other recent data breach news,

Agency waited weeks before telling anyone about massive data breach


https://newsok.com/article/5620604/agency-waited-weeks-before-telling-anyone-about-massive-data-breach

Marriott Establishes New Loyalty Program After Massive Data Breach

http://fortune.com/2019/01/16/marriott-loyalty-program-data-breach/

Marriott: Hackers accessed more than 5 million passport numbers during November’s massive data breach

https://www.washingtonpost.com/technology/2019/01/04/marriott-hackers-accessed-more-than-million-passport-numbers-during-novembers-massive-data-breach/?utm_term=.7589793be0c4

Worst Data Breaches of 2018

https://securitytoday.com/articles/2018/12/27/worst-data-breaches-of-2018.aspx
- January 18, 2019 No comments:
Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Labels: change password, data breach, komando, Marriott, oklahoma data breach, password manager, password protection, passwords. haveibeenpwned, Stolen passwords
Newer Posts Older Posts Home
Subscribe to: Posts (Atom)

TEST

  • Pig Butchering. China cracks down on Internet scammers based in Myanmar
    The term Pig Butchering refers to the victims of scammers. The scammers nurture relationships with their targets before luring them in for t...
  • Google's $199 Chromebook. What is slowing Windows down?
    Acer C7 Chromebook from Google Play, $199 What can  you get for $199? Dual-core Intel Celeron Processor 2 GB DDR3 RAM 320 GB hard d...
  • (no title)
    Microsoft's Patch Tuesday to end beginning with Windows 10.  This change goes for both security updates and non-security updates. htt...

Search This Blog

  • Home

About Me

dforce
Atlanta, Georgia, United States
Free Radical, Ltd dba Driving Force Software. We are a 25 year old computer networking firm located in Atlanta, Georgia. Our senior tech has approximately 30 years experience in software design, system building and networking. Driving Force is on the forefront of implementing and securing systems and networks via hardware firewalls as well as intrusion detection. Free Radical, Ltd dba Driving Force Software is a Microsoft Dynamics GP Partner as well as an Intel Gold Partner.
View my complete profile

Blog Archive

  • ▼  2025 (2)
    • ▼  August (2)
      • TEST
      • October 14th; The end for Windows 10 (or is it?).
  • ►  2024 (3)
    • ►  September (1)
    • ►  August (1)
    • ►  January (1)
  • ►  2023 (12)
    • ►  December (1)
    • ►  November (1)
    • ►  October (1)
    • ►  September (2)
    • ►  July (1)
    • ►  June (2)
    • ►  March (1)
    • ►  January (3)
  • ►  2022 (13)
    • ►  November (1)
    • ►  October (3)
    • ►  September (2)
    • ►  August (1)
    • ►  July (2)
    • ►  May (1)
    • ►  March (1)
    • ►  February (2)
  • ►  2021 (10)
    • ►  December (3)
    • ►  November (1)
    • ►  June (1)
    • ►  May (2)
    • ►  April (2)
    • ►  March (1)
  • ►  2020 (10)
    • ►  October (2)
    • ►  September (2)
    • ►  July (1)
    • ►  June (2)
    • ►  March (1)
    • ►  February (2)
  • ►  2019 (30)
    • ►  December (2)
    • ►  November (2)
    • ►  October (2)
    • ►  September (2)
    • ►  August (2)
    • ►  July (2)
    • ►  June (1)
    • ►  May (3)
    • ►  April (5)
    • ►  March (3)
    • ►  February (2)
    • ►  January (4)
  • ►  2018 (27)
    • ►  December (3)
    • ►  November (3)
    • ►  October (2)
    • ►  August (6)
    • ►  July (1)
    • ►  June (1)
    • ►  May (1)
    • ►  April (5)
    • ►  March (2)
    • ►  February (1)
    • ►  January (2)
  • ►  2017 (17)
    • ►  December (1)
    • ►  November (1)
    • ►  September (1)
    • ►  August (1)
    • ►  June (1)
    • ►  May (2)
    • ►  March (3)
    • ►  February (2)
    • ►  January (5)
  • ►  2016 (16)
    • ►  December (3)
    • ►  November (2)
    • ►  October (3)
    • ►  September (1)
    • ►  July (1)
    • ►  June (1)
    • ►  April (3)
    • ►  February (2)
  • ►  2015 (7)
    • ►  November (3)
    • ►  July (1)
    • ►  June (1)
    • ►  May (1)
    • ►  March (1)
  • ►  2014 (9)
    • ►  October (1)
    • ►  August (2)
    • ►  April (4)
    • ►  March (1)
    • ►  January (1)
  • ►  2013 (13)
    • ►  November (1)
    • ►  October (3)
    • ►  September (2)
    • ►  July (1)
    • ►  March (1)
    • ►  February (3)
    • ►  January (2)
  • ►  2012 (15)
    • ►  November (2)
    • ►  October (2)
    • ►  September (1)
    • ►  August (2)
    • ►  July (4)
    • ►  June (2)
    • ►  April (2)
  • ►  2011 (2)
    • ►  May (1)
    • ►  April (1)
  • ►  2010 (9)
    • ►  September (2)
    • ►  June (1)
    • ►  May (1)
    • ►  April (4)
    • ►  March (1)

Labels

  • .lnk
  • "Weeping Angel"
  • $199 Chromebook
  • 1 800 scams
  • 15-inch Macbook Pro
  • 1809
  • 1903
  • 2016
  • 2018
  • 2020 election
  • 2022
  • 22H2 update
  • 23andMe
  • 2990WX
  • 35 days
  • 4690K
  • 4790K
  • 4G
  • 4G LTE
  • 5 rules for using the internet after heartbleed
  • 5G
  • 6th Gen
  • 737 max
  • 7th Gen
  • 7th Generation processors
  • 80211.ac
  • 87 million users
  • 8th generation
  • 8x8
  • 98.0.4758.102
  • 9th generation
  • Acer
  • Acer C7 Chromebook
  • Acer H340
  • Add-ons
  • Adobe
  • Adobe Creative Suite
  • AI
  • Airpods
  • Albany
  • Albany New York
  • Albany NY
  • Alexa
  • Amazaon
  • Amazon
  • Amazon Prime
  • Amazon S3 Server
  • amazon sidewalk
  • Amazon Web Services
  • amd
  • American Greed
  • american iphone
  • and CVE-2021-27065
  • Android
  • Android Apps
  • Android mini PC
  • android trojan
  • Aniiversary Edition
  • anti virus
  • antivirus
  • Apple
  • Apple DDos
  • Apple earnings
  • apple event 2020
  • Apple Event; iphone
  • Apple Fanbois
  • Apple homepod
  • Apple Macbook Pro
  • apple malware
  • apple market cap
  • Apple Music
  • apple pay
  • apple security
  • Apple sucks
  • Apple TV
  • apple tv app
  • Apple upgrade
  • apple watch
  • Apple Woes
  • Apple; desktops
  • Applie iCloud
  • arm
  • artifical intelligence
  • astaroth
  • atlanta
  • atlanta ransomware
  • ATM attack
  • Auto Mute
  • autopilot
  • autosteer
  • avast
  • AWS
  • Backdoor.AndroidOS.Obad.a
  • Backup
  • ban
  • banks hacked
  • banned from Airlines
  • bans
  • barrons
  • Basic Authentication
  • battery fires
  • bent ipads
  • best browsers
  • best buy
  • Bill Nye
  • BitCoin
  • bitdefender
  • bitpaymer
  • black screen
  • blueleaks
  • bot-nets
  • botnet
  • Brave
  • brave browser
  • breach
  • breaches
  • Britain Surveillance law
  • browser
  • browser bug
  • browser password
  • browser security
  • Browsers
  • bugs
  • BYOD
  • cambridge analytica
  • candy crush
  • capital one
  • captcha
  • carbanak
  • carbonite
  • casino
  • casino hacker
  • ccleaner
  • cernsorship
  • CES
  • CES 2017
  • change password
  • Cheaper iPhone
  • China
  • china search engine
  • chinese
  • Chinese OS
  • chip
  • Christmas
  • Chrome
  • Chrome 66
  • Chrome download
  • Chrome Http
  • chrome OS
  • Chrome Remote Desktop
  • chrome ui
  • chrome version 71
  • Chromebook
  • Chromebook Pro
  • Chromebooks
  • Chromecast
  • Chromium
  • Chromium Project
  • CIA
  • city of atlanta
  • clearnet
  • clorox hack
  • cloud
  • Cloud computing
  • cloud pbx
  • cloud providers
  • CNBC
  • CNBC American Greed
  • CNET
  • Cobalt Strike
  • colorado dot
  • Comcast Business
  • comodo
  • Comodo Dragon
  • compromised accounts
  • computer
  • Computer repair
  • computers
  • Consumer Electronics Show
  • controlled folder access
  • controls
  • Core 87
  • Core i3
  • Core i5
  • core i5 4670k
  • Core i7
  • core i9
  • countdown clock
  • covid scams
  • covid-19 scams
  • CPU
  • crackdown
  • crapware
  • Crash Wednesday
  • CrashPlan
  • Creators Update
  • credentials.
  • credit
  • CRM
  • crossloop
  • CrowdStrike
  • crypto
  • cryptolocker
  • crytolocker
  • cvd-2020-1472
  • CVE-2021-26855
  • CVE-2021-26857
  • CVE-2021-26858
  • CVE-2022-0609
  • Cyber Crime
  • Cyber-attack
  • cyber-security
  • cyberattack
  • cybersecurity
  • DaaS
  • dark mode
  • Dark Web
  • dashlane
  • data
  • data breach
  • Data breaches
  • data saver
  • DDoS
  • DDos Tibetan
  • Dead
  • death of MAC
  • Death of the PC
  • deepfake
  • deepfakes
  • Dell
  • Delta Air
  • desktop
  • dforce
  • dforce xtreme computer
  • dharma
  • digital security
  • Disney
  • districts
  • Dooble
  • Dragonfly
  • driving force
  • Driving Force Software
  • Dual Boot
  • duckduckgo
  • Dynamics
  • Dynamics GP
  • Echo
  • echo dot
  • Edge
  • efax malware
  • Electro-Quasistatic Human Body Communication
  • elon musk
  • email
  • emotet
  • encrypted files
  • encryption
  • enternalbule
  • Epic
  • EQS-HBC
  • Equation
  • Equifax
  • ETH
  • Ethereum
  • evil corp
  • Excel performance
  • Exchange
  • exchange zero day
  • experian
  • expiration dates
  • Exploit Wednesday
  • exploits
  • extension
  • extensions
  • external hard drive
  • face time
  • facebook
  • Fake Funeral Notice
  • fake tech support
  • fall creators update
  • FBI
  • FBI Virus
  • FBI.gov
  • Fiber
  • Files Deleted
  • Firefox
  • Fires
  • firewalls
  • fixes
  • Flash player
  • free credit monitoring
  • free cubby
  • free radical
  • free remote access
  • FruityArmor
  • FTC.gov
  • GA Tech
  • galaxy note 9
  • Gamer desktops
  • gamers
  • gaming
  • gcman
  • geek squad
  • Gen 7
  • Gen 8
  • Generation 8
  • Generation 9
  • Genius Bar
  • georgia digital id
  • georgia digital license
  • Georgia drivers license
  • Georgia Tech
  • Gigabyte Internet
  • GMail
  • Google
  • google chrome
  • Google Chrome browser
  • Google Docs
  • google extensions
  • Google Fiber
  • google home
  • google urls
  • Google+
  • gotomypc
  • Goverment urges users to switch browers
  • GP
  • GPUs
  • grade
  • GTX 1050
  • guest networks
  • Hack
  • hacked
  • hacker
  • hackers
  • Hafnium
  • hamas
  • hancitor
  • Haswell
  • Have I been
  • haveibeenpawned
  • Heartbleed
  • Hello Again
  • Hold Security
  • Home Internet
  • home internet lite
  • home network security
  • Homeland security
  • HomePod
  • honeypot
  • hospital
  • html5
  • HTTPS Everywhere
  • https://haveibeenpwned.com/
  • Hulu
  • ibm
  • Ice Dragon
  • IcedID
  • icloud
  • icloud password
  • identify theft
  • IDENTITY
  • IDENTITY THEFT
  • identity-theft
  • IDF malware
  • IE
  • IE Zero Day Bug
  • implantable medical devices
  • In a first
  • India
  • India cyberattack
  • indian call center
  • infected servers
  • Inspiron
  • Inspiron 15 7000
  • Intego
  • intel
  • intel 4th gen
  • Intel 6th Gen
  • Intel 8 Gen
  • intel computer
  • intel core i3
  • intel core i5
  • intel desktops
  • Intel Gen 8
  • Internet
  • internet connectivity
  • Internet Explorer
  • internet passwords
  • IOS
  • iOS 14.0.1
  • iOS bugs
  • IOS patch
  • ios watchos
  • IP phones
  • ipad
  • iPad 4
  • iPad 4 upgrade
  • ipad air
  • ipad air 4
  • iPad Mini
  • ipad pro
  • iPhone
  • iphone 11
  • iphone 11 pro
  • iphone 12
  • iphone a crappy device
  • iphone anniversary
  • iphone dud
  • iphone in india
  • iphone password
  • iphone sales down
  • iPhone X
  • iphone xs
  • iPhone5
  • iPod
  • ISP
  • israel
  • Israel responds to Hamas hackers with an air strike
  • IT
  • IT Outage
  • it security
  • iwatch
  • jackson county
  • java
  • july 29
  • Kaby Lake
  • kali
  • Kaspersky
  • Kaspersky ban
  • kaspersky safe money
  • KAV
  • Kindle scam
  • komando
  • kronos
  • Lacie
  • lastpass
  • latency.
  • Lenova Yoga
  • Lenovo Twist
  • Linux
  • Locky
  • log4shell
  • LogMein
  • logmein rate increase
  • louisiana
  • Mac
  • Mac anti-virus software
  • Mac malware
  • MAC mini
  • mac remote wipe
  • Mac Virus
  • MacBook
  • MacBook Pro
  • macros
  • Macs
  • MacWorld
  • maersk
  • malware
  • malware decryption tools
  • malware targets
  • malwarebytes
  • malwarebytes flaw
  • malwaretech
  • man in middle
  • market cap
  • Marriott
  • mcafee
  • McAfee for Mac
  • MEI
  • Meltdown
  • meta
  • metel
  • Metro
  • Metro UI
  • mfa
  • Michaels
  • Michaels stores
  • microsoft
  • Microsoft 365
  • Microsoft end of support
  • microsoft security scam
  • microsoft store
  • microsoft surface
  • Microsoft Update
  • Microsoft Windows 10
  • mikogo
  • millenials malware targets
  • minecraft
  • mining
  • mitm
  • Mobile Malware
  • Mozilla
  • MS Dynamics
  • MS Office 365
  • MS365
  • multi-factor authentication
  • muncipal railway
  • myanmar
  • myspace
  • Napster
  • netflix
  • Netlogon
  • new orleans
  • newspapers
  • nigeria
  • Nobellum
  • nola
  • norton
  • notebooks
  • notebooks kaby lake
  • notifications
  • notpetya
  • nvidia
  • Nvidia RTX 3090
  • NZXT
  • Obad.a
  • October 1
  • October Update
  • office
  • office 2007
  • Office 2010
  • office 2010 discount
  • office 2019
  • office 365
  • oklahoma data breach
  • One Tab
  • OneCare
  • Onedrive
  • onionland
  • online info
  • online privacy
  • online scams
  • online security
  • online shopping
  • Opera
  • Optane
  • Optane Memory
  • oracle
  • os exploits
  • OS market Share
  • Outage
  • Outlook.com
  • Panera
  • passcode
  • password
  • password expiring
  • password manager
  • password protection
  • passwords
  • passwords. haveibeenpwned
  • patch tuesday
  • pause update
  • Pawned
  • pc
  • PC performance
  • PC sales
  • PC Security
  • pcnow
  • pcs
  • personal information
  • phenom II
  • phishers
  • phishing
  • phone scam
  • Phorpiex
  • playboy
  • plus code
  • plus codes
  • portal
  • POS
  • POS malware
  • Prime
  • Prime Day
  • privacy
  • privacy essentials
  • privacy extensions
  • Priya Anand
  • problems
  • processors
  • project zero
  • protecting your info
  • protection.
  • pwn2own
  • qr codes
  • quick response codes
  • Quicktime
  • quishing
  • raging grannies
  • ransom
  • ransomware
  • ransomware attack
  • Raspberry Pi
  • RAT
  • red hat
  • red iphone
  • Remote access
  • Remote Access Trojan
  • remote desktop
  • remote work
  • remotepc
  • REvil
  • ring devices
  • rogue ware
  • router
  • routers
  • RTX 30 series
  • RTX 3070
  • RTX 3080
  • russia
  • Russian Hackers
  • Russians
  • ryuk
  • Ryzen
  • S.C. Tax
  • S3
  • Safari
  • safe money
  • sales
  • samsam
  • samsung
  • san francisco malware
  • sandbox
  • scam
  • scammers
  • scams
  • scattered spider
  • school
  • scorecard
  • search engines
  • Sears
  • Secure Boot
  • security
  • security patches
  • Server
  • settings
  • sextortion
  • SharePoint
  • shortage
  • sidewalk
  • Silence Hackers
  • silver sparrow
  • sites affected by heartbleed
  • sluggish performance
  • Smart devices
  • Smart Phone
  • smart speakers
  • smart TVs
  • smartphone
  • smartphone security
  • smishing
  • sms
  • Snip
  • snoopers' charter
  • social media
  • sodin
  • sodinokibi
  • software
  • SOL
  • Solana
  • SolarWinds
  • SonicWall
  • Sony DDOS attack
  • South Carolina DOR
  • South Carolina Tax Info Hack
  • spacex
  • Spam
  • Spammers
  • spectre
  • Spotify
  • Spring Creators Update
  • spyware
  • ssd
  • starlink
  • Starwood hack
  • Steve Jobs
  • Stock
  • Stolen passwords
  • streaming
  • Streaming Services.
  • strong passwords
  • stuxnet
  • sundar pichai
  • Surface
  • Surface Go
  • Surface Studio
  • suspicious emails
  • sync
  • sync password
  • T-Mo
  • T-Mobile
  • Tab Wrangler
  • Tablet
  • teamviewer
  • tech-support scammers
  • Technical Preview
  • tesla
  • tesla hacked
  • The great suspender
  • THEFT
  • Threadripper
  • Threshold
  • Threshold 2
  • throughput
  • tiktok
  • tile trackers
  • tips
  • Tor
  • Tor browser
  • totalav
  • Tribune Publishing
  • tricks
  • Trik
  • Trillion
  • trojan
  • trojans
  • Trump
  • Turkish Crime Family
  • twitter
  • Ubuntu
  • UEFI
  • Ukraine
  • unmineable
  • update
  • update Tuesday
  • updates
  • upgrade
  • upgrades
  • us firms pay cash to hackers
  • us marshals
  • USAID
  • user interface
  • version 1703
  • version 1803
  • version 1809
  • version 1903
  • virus
  • VISA
  • vmware
  • Voter Leak
  • VPNFilter
  • vulnerabilities
  • wannacry
  • wastedlocker
  • web shells
  • webcam
  • webex
  • wfh
  • WHS
  • WIDI
  • wifi security
  • WikiLeaks
  • Window 10
  • Windows
  • Windows 10
  • Windows 10 2004
  • Windows 10 compatibility
  • windows 10 deadline
  • Windows 10 Free
  • Windows 10 Release
  • windows 10 security
  • Windows 10 Technical preview
  • windows 10 upgrade
  • Windows 11
  • Windows 12
  • WIndows 1803
  • Windows 7
  • windows 7 support
  • Windows 8
  • windows 8 old PC
  • Windows 8 older computer
  • Windows 8 ready computers
  • Windows 8 special pricing
  • windows 8 upgrade
  • windows 8 upgrade offer
  • Windows 8 upgrade special
  • Windows 8 upgrade. Windows 8 features
  • Windows 8.1
  • Windows 8.1 Release Data
  • Windows 9
  • windows as a server
  • Windows build
  • windows defender
  • WIndows Home Server
  • windows lifecyle
  • Windows Performance
  • Windows Phone
  • windows settings
  • Windows update
  • windows updates
  • windows upgrade
  • Windows version
  • Windows XP
  • windowslatest.com
  • winver
  • wireless
  • wireless 80211ac
  • wmic
  • wordpress
  • Workstation
  • workstations
  • WPA
  • WPA2
  • WPA3
  • wsus
  • Xmas
  • XP support
  • xr
  • Yahoo hack
  • Yandex
  • YouTube
  • ZDNet
  • zero day
  • zero-day
  • zero-day bug
  • zero-day exploits
  • Zeus Trojan
  • Zeus Virus
  • zoom
  • zoominfo

Report Abuse

Followers

Subscribe Now: google

Add to Google Reader or Homepage

Add to My AOL

Powered by FeedBurner

Subscribe to Driving Force Software

Follow this blog
Awesome Inc. theme. Powered by Blogger.