ss_blog_claim=8bb4a7b19e24f394c9547210ae911b81
Showing posts with label Cyber Security. Show all posts
Showing posts with label Cyber Security. Show all posts

Wednesday, February 1, 2023

Use LastPass? Change Every Password Now

A significant data breach at popular password manager LastPass has put customers' data and internet passwords at risk.

LastPass CEO Karim Toubba confirmed in a blog post published in late December that a security problem the company previously disclosed in August had ultimately resulted in the theft of sensitive vault data and customer account information by an unauthorized person. The problem is the most recent in a long, worrying line of security occurrences involving LastPass that go all the way back to 2011.



It gets to be more concerning as this goes on.

According to Toubba, unencrypted subscriber account data like LastPass usernames, company names, billing addresses, email addresses, phone numbers, and IP addresses were accessible to an unauthorized party. The data from client vaults, which includes both encrypted and unencrypted information including usernames and passwords for all the websites that customers have saved in their vaults, was also stolen by the same unauthorized entity. While they say the encrypted should remain safe, it is better to expect that a risk still remains there.

If you use LastPass, you should consider switching to a new password manager due to the seriousness of this breach, which puts your passwords and personal information at danger.

The number of users who were impacted by the breach was not disclosed by the company. However, if you use LastPass, you must assume that your user and vault data are in the possession of an unauthorized person who has bad intents. Despite the fact that the most critical information is encrypted, the threat actor can still conduct powerful assaults on the stolen local files. If you've adhered to LastPass's best practices, it would reportedly take "millions of years" for someone to guess your master password.

If you haven't changed your individual passwords as of yet, you better get started on it this week.

Thursday, May 5, 2022

Password Security Tips for World Password Day 2022

 It may seem like every year you hear of a crazy new holiday or themed day, well today may be no different than that to you. Today marks World Password Day, a day where we try to raise Internet awareness on cyber security and how you can protect yourself from being hacked. So in honor of today, I decided it is time to share some tips to help you all in making sure that you are as secure as you can be.



1. Never Reuse Passwords

This one should be considered common sense, but we all do get our lazy sides going and sometimes it is easier just to reuse the same one or a variation of it again and again. This should be a huge no, as if that account gets hacked, you can bet your Xbox S or Playstation 5 that those hackers will attempt to use that password to gain access to other accounts.

2. Use a Phrase or 10+ Characters

The longer the password, the hard to crack it - or at least that is what this one is all about. Yes, it does make it harder on you, but at the same time it makes it harder for a hacker and that is a good thing! You can also use a password manager to store these passwords for you, and many of them do offer a password generator that can help you to create a longer, random password if you don't want to use a phrase. This can also be helpful where they cannot use AIs to crack into a random password, as the longer it is, the longer it takes to crack.

3. Don't Share Accounts

I can promise this is not sponsored by Netflix, but sharing accounts and passwords can be a security concern. Most services and websites should do better by allowing everyone who is sharing a service to create their own login, but alas, that doesn't appear to be a concern to them. Perhaps we can remind them of this security liability on World Password Day?

4. 2-Factor Authentication (2FA)

As we approach to a more digital age, 2FA is a growing and popular option for many. It makes it harder for those to gain access to your account as most want to send you a random, generated code to your phone where you can see it and then enter it. It can feel like a real pain, but it can be a good thing as well especially for accounts that may house personal information.

What are some of your tips regarding password security? Is this the first time you have heard of World Password Day?

Monday, May 2, 2022

Google May Allow You To Vanish from Search Engine

 Google is adding phone numbers and email addresses to the list of personal information that you can request to be deleted from the search engine.

They finally have announced that they are modifying their policy to allow consumers to have more control over their personal information, by allowing you to request it to be removed from search results.

Contact information, such as a phone number, email address, or physical location, is now included in the revised policies, as well as information that could enhance the risk of identity theft, such as log-in credentials.

Google's policy lead, Michelle Change released this statement: 



"The availability of personal contact information online can be jarring — and it can be used in harmful ways, including for unwanted direct contact or even physical harm...And people have given us feedback that they would like the ability to remove this type of information from Search in some cases."

While this is a step in the right direction, you as a user must manually submit the request. Even then, Google claims to have the right to make the final call if they will or will not remove. So sadly, you will still not have total control over your personal details.

What do you think about Google allowing users to request to remove their details from the search engine?

Sunday, May 1, 2022

Google Announces Cyber Threat in Chrome

If you use Google Chrome as your web browser, please be aware that your data may be at risk of being stolen.



Google published an alert informing billions of Chrome browser users that they may have been successfully targeted by hackers, listing 30 security issues, seven of which were classified as "High" risk.

According to the company's announcement, an update will be released in the coming days to solve the bugs that leave you at risk, which affect Windows, macOS, and Linux users.

It's unknown who is responsible of the hacking, or whether any users' privacy was jeopardized.

Further attack data are presently being withheld by Google "until the bulk of customers have been updated with a patch," according to the company.

They will keep limits in place if the flaw is in a third-party library that other projects rely on but haven't resolved yet, the business added.

Users of Chrome can manually upgrade their browsers via the settings menu, although the browsers will update automatically in a few days. Click the three dots in the upper right corner of the browser and scroll down to locate options.