Thursday, October 13, 2011

Cyber Security and You!

Cyber Security and You!
 "Why you're 'virtually' always a target."




 Why should I be worried, I have bad credit?
 
  Well I'm sorry about that. Maybe in Tarp II they'll line Equifax's pockets to raise everyone with a sub-standard credit score to 780 above most of middle class America. Or better yet maybe they'll just line Equifax's pockets. Either way, believe it or not, you're still a good target for a Cyber Predator - maybe even a better target. Here's why: people with bad credit are able to get access to many different programs through credit agencies, banks, and even the government to gain access to minimal amounts of high interest credit from banks that usually lack the security to protect your interests. While most Americans with a good score are subject to harsh post Tarp credit checks that usually either deny them or lower their available credit limit. Those of us that have excellent credit, however, tend to gain access to better banks and agencies with higher standards and security. So why does my credit score have anything to do with the possibility that someone might Hack my Hotmail account or stalk me through MySpace? Well, 7 times out of 10 that's what their after, your credit. The more sources of it you have and the easier it is to access...the bigger target you are. Most Cyber Criminals don't typically charge $1000s at a time, they do it in smaller increments so you won't notice it at first - so a high limit isn't an issue - and most credit companies won't pursue little charges like that since it's not cost effective. So Script_Kiddy#5 can buy all the $20 Xbox games he wants as long as he bounces from card to card. But, this is just one type of Cyber Criminal and the most common. Out there in the deep dark reaches of Cyber-Space is a professional credit killing - identity stealing Hacker that 'will' charge $1000s, open up new cards, loans, and even sell your information to others just like him. Scenarios like this can make you a victim for life. The Cyber Security threat is real and more profound than most people seem to realize. With a market just figuring out what Cyber Security is - let alone protect itself, and a government that has yet to really address the problem to help its citizens recoup after an attack and prevent it from happening again, the only one who can stop such a threat is -You-; and the only way you can do this is through educating yourself on what Cyber Security is and who the villains are.



 
Who are these Villains and how do I become a Masked Crusader!!
-POW- -BAM- -BIFF-

  First off, I hate being the bearer of bad news, but I won't be handing out stylish velour masks today; instead I'll be showing you how to better protect yourself from Cyber Attacks and hopefully identify when one may be occurring. But first let's take a look at who the enemy is. In the lower spectrum you have weirdos called "Script Kiddies", "Phishermen", and a plethora of one time wonders that line up like obscure 80s love metal bands. These are either curious teens or college students who just want to feel big-and-bad and use Google Search and Hacker: how-to guides to break into your email and send mom and dad a super-imposed picture of you dry humping the neighbors dog while double fisting Heineken. This group tends to be the less damaging, but most annoying. Typically they'll be that obscurely named user on MySpace with something like "Phreaker.Ghost_Face5432" that will out-of-nowhere be eagerly wanting your friendship because you guys have just soo much in common. Little known fact, sites like Facebook and MySpace are the first stop for most Cyber Criminals regardless of intent because its like a smorgasbord of free and easy to get information about anyone they might be interested in. To explain this further I'd like to pose a question to you: "With regards to social media sites like Facebook, who is the customer?" Who? First lets define who a customer is in a store or business. The customer is the one who is interested in buying your product or service right?! So in essence the customer is the one who pays; are you paying for Facebook? If not, who is? Maybe large third party agencies that collect information for complex data analysis reports to help other business' and retailers be more efficient with marketing and providing the goods and services consumers want?! I'd say so. Ever wondered how Gillette just seems to come out with all those new 5-bladed wonder shavers with trendy names and stylish looks that makes you want to go out and buy one right away? No, well good that'd be revealing, but I think you get the picture. So, naturally, websites that already collect the data that Identity Thieves want is a great first stop, and its free! Ya-ay! The next stop is either using the phone number you unwisely listed or your address along with your email that you were required to provide to set-up the account you wanted just so you could keep up with cousin Chrissy's sexually explicit relationships. Criminals of the lower threat levels won't go too much further, they'll just make your life miserable for a short period. But the big dogs out there are just starting at this point - a few moves later and they'll be going straight for the jugular.

  The real threats out there are the ones we've all heard of: Identity Thieves and "Hackers". Well Black Hackers anyways. Wait! What?! Isn't that racial profiling! Well if you jumped to that conclusion you're either suffering from some guilt or its a great example as to why you should be reading this article. In a quick to blame culture that loves blanket statements "Hackers" have been mislabeled and targeted. The truth is "Hackers" more times than not are the ones stopping Identity Theft and helping secure network connections. "Holy super Security+ Mr. Fiebs!" That's right Boy Wonder, and now we all know why you wear those tights and green slippers with a capitol "R" on your chest. There are 3 classes of Hackers and 2 divisions. On side no. 1 we have the champions of justice and tech righteousness: the White-Hat Hackers and the mysterious Grey-Hat Hackers! These first 2 classes make-up the good side, the ones with blue lightsabers, who are interested in securing networks by exposing their weaknesses. Every year the co-founder of Facebook (ironically enough), Mark Zuckerberg, hosts the Defcon convention which celebrates Hacker culture, and big companies actually let them "Hack-in" and test their security. You can consider this the League of Justice and Marky-Marky is like Aquaman except with an annoying voice and way more socially awkward - despite the purpose of his creation. Next up, we have the Legion of Doom "The Black-Cat/Hat Hackers" these are the guys with 'red' lightsabers - just in case I lost you there for a bit. Now these guys are the above average-to-professional Cyber Criminals who know how to get what they want and will go all the way to use it. They also put alot of work in to securing things like your address and phone numbers so they can either get a hold of your phone bill, or some other piece of information. Once they have your phone bill they can start calling people that you call the most and play it off like their some creep from the IRS, or some other agency that we all trust soo much, so that eventually we give them whatever info they ask for - even a Social Security number. From there you're history - your little credit rating too. 




  So ok, I get some of that, but when do we get to learn the campy crime fighter skills you promised?! Right now! The first thing to do is a-not-so obvious one - STOP putting all your information out there! At least make it hard for them! Take your personal stuff off Facebook and MySpace and get an account at Fiebs Place - I'm much nicer. Secondly stop using your name, birth date, favorite color, and the first name of that hot blonde from that TV show - you might as well use your social security number. Every data-hack, identity theft, or network security breach started somewhere with cracking a password. Professionals of this caliber have special "Brute Force" programs, which they usually program themselves, that sit and guess passwords using common words and built in dictionaries. These programs can process more than several thousand combinations in a single day. So you might ask yourself "well then why try?" Simple answer, no Hacker wants to let his resources sit for a day or more trying to crack the same password that might not even yield anything, so they'll typically try for just a few hours and then move onto something else. So, the goal is to make it hard enough for a program like that to be able to break in within a few hours - which means there goes every 4 digit year from 1800 to 2050, every major color, and all three Charlies Angels. Pick a password that looks to mean absolutely nothing like "Z34TH674HGYT@FU". Again while this looks to mean nothing and be hard to remember, it'll stump that expensive machine from hacking your accounts. Also, don't store this password in your browser, I could pull those out for you and give them to you by hacking the browser. Do the old fashion thing a write them down so there's no trace. 

  The next step is to be 'Pro-Active' - and stop thinking about acne commercials with Jessica Simpson. If you receive some obscure text messaging saying thanks for that $9.99 subscription from "Love Tips 4 Life.com" immediately call your provider to have them refund the money and report that service as fraudulent. The best defense is a good offense, get pro-active. Never assume something random, in regards to technology, is just that - random. Nothing within the Computer Industry is random; its all neatly programmed out to perform very specific functions - like steal your information. A great step to take is to pay for Identity Theft protection with a reputable company like Identity Guard or Life Lock. These services monitor your credit and tell you when you've been hit and stop it before it becomes a bigger issue. Then they work with you to replace your credit cards and file all the paperwork for the SSA and the FBI. Identity Theft is a federal crime and seen similar to terrorism, so the FBI investigates most cases. If you walk away with anything take this: keep as little information on the Internet as possible, and what little you do put out there make sure it's safe, secure, and always use hard encrypted passwords.

~Mr. Fiebs


 
References:
http://www.zdnet.com/news/facebook-users-open-to-cyberattacks-id-theft/157855
http://www.us-cert.gov/cas/tips/
http://en.wikipedia.org/wiki/Computer_security
http://www.dhs.gov/cyber
http://www.govtech.com/policy-management/Michigan-Plans-Cyber-Defense-Squads.html
http://www.marketwatch.com/story/older-americans-a-growing-presence-online-need-to-learn-how-to-guard-against-cyberattacks-2011-10-13 
Cybershock: Surviving Hackers, Phreakers, Identity Thieves, Internet Terrorists and Weapons of- Mass Disruption by Winn Schwartau

2 comments:

  1. Wow you really took time on this.. I learned a few things.. It reminds me of that movie Deception with Hugh Jackmen because he had access to private illegal money bank accounts and he used an IRS agent who had lvl 4 security entrance (has full right to take, transfer or add money without the company's permission) into the company's money accounts and had the IRS guy transfer all the money to a hidden account in Spain.. It was about $20 million dollars! The time the IRS guy did the transfer was on the weekend so the money transfer wouldnt of been noticed until monday so the next day they flew out to spain got their money and closed the account before anyone noticed!

    ReplyDelete
  2. That's exactly why we need to better our Cyber Security and information habits...TO STOP HUGH JACKMAN!!!

    ReplyDelete