One of my very favorite podcasts in the world is called Reply All.
It is ostensibly, a podcast "about the internet", but they get into many, many different subjects.
Anyway, for the sake of investigation... one of the two co-hosts allowed the other to put "spyware" on a android phone, and then use that phone... to see what the other person could see, and what could they access.
It was really interesting, and worth your while to listen to, particularly if you are interested in security, and knowing what type of data is at risk when using an "infected" device.
Here is a LINK to the show page on the Gimlet website.
-You can listen to it directly on the page, or you can download it from there, as well.
Also, typically Reply All posts their shows on Soundcloud, but this episode hadn't posted when I wrote this blog post.
Showing posts with label security. Show all posts
Showing posts with label security. Show all posts
Thursday, May 4, 2017
Thursday, March 23, 2017
Website to check for account hacks
I heard about this website yesterday while listening to a podcast.
https://haveibeenpwned.com/
It is a site that keeps track of some "major" data breaches from some major companies, and it will tell you if your username or e-mail address has been hacked.
(some websites give you a "username" some have you use an "e-mail address" as your username)
You just put your username in the box and click the button.
And then you get your results
If you are like me, you have a lot of different usernames and e-mail accounts that you have used throughout the years.
So, it is definitely a good idea to search for all your different usernames and e-mails.
https://haveibeenpwned.com/
It is a site that keeps track of some "major" data breaches from some major companies, and it will tell you if your username or e-mail address has been hacked.
How to use the site:
It's a pretty simple site, to check if any of your accounts have been hacked.(some websites give you a "username" some have you use an "e-mail address" as your username)
You just put your username in the box and click the button.
And then you get your results
If you are like me, you have a lot of different usernames and e-mail accounts that you have used throughout the years.
So, it is definitely a good idea to search for all your different usernames and e-mails.
What to do if they find a breach?
What this means is that your account information for that specific site (it lists all the sites that information was taken from) has been taken. You should go to that account and change your password ASAP.
Where this could become a BIG PROBLEM is if you are a person who uses the same password for the majority of your accounts. The hackers would now have your password for all the possible sites that you use that particular username/e-mail address with.
A word of caution
This website does not have a comprehensive listing of all the possible data breaches. You could certainly get the "Good news - no pwnage found!" message, and some of your accounts could still have had a data breach. It is just a tool to see that if some of the major/well known data breaches have reached any of your accounts.
Best Practices
- Use different passwords and credentials for every online account you have. (That way if there is a data breach it will only affect that one account.)
- The most effective passwords are random numbers, letters and symbols.
- Do NOT use your kids names
- Do NOT use your last name or Maiden name.
- Do NOT use anything that can be tracked to you, like your phone number, city, school attended, workplace, etc, etc...
- EXAMPLE: g8xSy2Ji - would be an EXCELLENT password. It is completely random, and connects back to nothing.
- How to remember your passwords?
- I would recommend using a "password manager", such as LastPass.
- A password manager is a software application or hardware that helps a user store and organize passwords. Password managers usually store passwords encrypted, requiring the user to create a master password: a single, ideally very strong password which grants the user access to their entire password database.
- Here is an article on Password Managers, for more information
- If you don't want to use a Password Manager some ideas?
- Use a "base group" of random numbers letters "g8xSy2Ji"
- Then, for each website make a Subtle Change...
- Examples:
- For Google: g8xSy2JiG
- For Facebook: g8xSy2JiF
- For Banking: Bg8xSy2Ji
- For Yahoo: Yg8xSy2Ji
- In addition... you should Change Your Passwords Every Year! - just like the K12 data Center has us do with our K12 credentials. I know it's a pain, but it's a good practice.
- Even if you follow ALL of these suggestions... it's possible that a hacker could cause a data breach of a site and steal your current data. Which is why you should stay active in following the best practices.
Subscribe to:
Posts (Atom)