Play it safe during FIFA 2018 0 1331

We do realize that you’ve been caught up in the hurly-burly of the FIFA World Cup, but surely you have a few minutes to spare and peruse our roster of tips to stay safe online not only during the soccer spectacle. While you’re at it, recognize that no single player, no matter how stellar, is enough to put you on a path to success. In fact, being even one player short can be enough to trip you up. What should the pillars of your cybersecurity game plan be, then?

#1 A stitch in time saves nine

Last year went down in history for two serious cyber-incidents – the WannaCryptoroutbreak and the Equifax hack – that served up powerful reminders of the merits of swiftly squashing security bugs. 2017 also saw the highest number of  vulnerabilities reported.

So the number one player in you security team is updates. In your home settings, making sure that automatic updates are enabled for your operating system and software is an easy step to take to keep attackers away.

 

#2 Prune your team

Get rid of that disgruntled bench-warmer who ends up sapping your team’s morale. Software that you hardly ever use can become a liability simply by increasing your attack surface. To further reduce the possible entry points for cybercriminals, you may also want to disable unused services and ports, and ditch programs that have a track record of vulnerabilities.

For your browser, consider blocking ads and removing all but the most necessary of browser add-ons and plugins. While you’re at it, shut down the accounts that you no longer need and use your high-privilege, or admin, account only for administrative tasks.

#3 Practice strong password hygiene

One of the easiest ways to protect your online identities consists in using a long, strong and unique password or better still, passphrase, for each of your online accounts. It may well come in handy if your login credentials leak, for example due to a breach at your service provider – which, in fact, is far too common a scenario. Further, just as you’d never share your teams tactics with your opponents, you should never share your password with anybody.

If you’re like most people and find the need to remember many username/password combinations overwhelming, consider using a password manager, which is intended to store your passwords in a “vault”.

#4 Look before you leap

Even if you have the most complex of passwords or passphrases, be aware of where you input them.

Online, everything is just a click away, and scammers are keenly aware of that. In their pursuit of your personal information, they use social engineering methods to sucker you into clicking a link or opening a malware-laden attachment.

5 questions to ask yourself before clicking on a link are:

  1. Do you trust the sender of the link?
  2. Do you trust the platform?
  3. Do you trust the destination?
  4. Does the link coincide with a major world event like the FIFA worldcup? (Cyber criminals tend to be opportunistic this way)
  5. Is it a shortened link?

#5 Add a factor

When aiming for secure accounts, you need to up your ante by using two-factor authentication, particularly for accounts that contain Personally Identifiable Information (PII) or other important data. The extra factor will require you to take an extra step to prove your identity when you attempt to log in or conduct a transaction. That way, even if your credentials leak or your password proves inadequate, there is another barrier between your account and the attacker.

#6 Use secure connections

When you connect to the internet, an attacker can sometimes place himself between your device and the connection point. To reduce the risk that such a man-in-the-middle attack will intercept your sensitive data while they are in motion, use only web connections secured by HTTPS (particularly for your most valued accounts) and use trusted networks such as your home connection or mobile data when performing the most sensitive of online operations, such as mobile banking. Needless to say, secure Wi-Fi connections should be underpinned by at least WPA2 encryption (or, ideally, WPA3as soon as it becomes available) – even at home – together with a strong and non-default administrator password and up-to-date firmware on your router.

Be very wary of public Wi-Fi hotspots. If you need to use such a connection, avoid sending personal data or use a reputable virtual private network (VPN) service, which keeps your data private via the use of an encrypted “tunnel”. Once you’re done, log out of your account and turn off Wi-Fi.

#7 Hide behind a firewall

A firewall is one of your key defensive players. Indeed, it is often thought of as the very first line of defense. It can typically be a piece of software in your computer, perhaps as part of anti-malware software, or it can be built into your router – or you can actually use both a network- and a host-based firewall. Regardless of its implementation, a firewall acts as a brawny bouncer that, based on predetermined rules, allows or denies traffic from the internet into an internal network or computer system.

#8 Back up

A backup is the kind of player who doesn’t get much time on the pitch, but when he does get the nod, he can “steal the show”. True, we might have spoken ill of bench warmers earlier, but a reliable backup is definitely not the kind of player to spoil your team’s chemistry.

Your system cannot usually be too – or completely – safe from harm. Beyond a cyber-incident, your data could be compromised by something as unpredictable as a storage medium failure. A backup is an example of a measure that is corrective in nature, but that is fully dependent on how hard you “practiced”. Or, as Benjamin Franklin put it, “by failing to prepare, you are preparing to fail”. It will cost you some time and possibly money to create (time and time again) your backups, but when it comes to averting (data) loss, this player may very well save the day for you.

#9 Select security software

Even if you use your common sense and take all kinds of “behavior-centered” precautions, you need another essential addition to your roster. At a time when you’re pitted against attackers who are ever more skilled, organized and persistent, dedicated security software is one of the easiest and most effective ways to protect your digital assets.

A reliable anti-malware solution uses many and various detection techniques and deploys multiple layers of defense that kick in at different stages of the attack process. That way, you’re provided with multiple opportunities to stymie a threat, including the latest threats, as attackers constantly come up with new malicious tools. This underscores the importance of always downloading the latest updates to your anti-malware software, which ideally are released several times a day. Top-quality security software automates this process, so you needn’t worry about installing the updates.

#10 Mobiles are computers, too!

Much of this article’s guidance also applies to smartphones and tablets. Due to their mobility, however, these devices are more prone to being misplaced or stolen. It is also of little help that users tend to view security software as belonging in the realm of laptops and desktops. But mobile devices have evolved to become powerful handheld computers and attackers have been shifting their focus to them.

There’s a number of measures you can take to reduce risks associated with mobile devices. They include relying on a secure authentication method to unlock your device’s screen, backing up the device, downloading system and app updates as soon as they’re available (preferably automatically, if possible), installing only reputable apps and only from legitimate stores, and making sure to use device encryption if it’s not turned on by default.

A dedicated mobile security solution will also go a long way towards enhancing your protection from mobile threats. This includes a scenario whereby your device goes missing, so you are then able to use the suite’s anti-theft and remote-wipe functionalities.

#11 Be aware

The final team member is, in fact, you – the keeper. Stay vigilant and cyber-aware and educate yourself on safe online habits. Don’t ever say, “it won’t/can’t happen to me”, because everyone is a potential target and victim. Recognize that one click is enough to inflict major damage on yourself and others, and that breaking good security practices for the sake of convenience may come back to bite you worse than Luis Suárez did in 2014. After all, how secure we are is largely dependent on how we use the technology.

So there you have it. You may want to enjoy the soccer now.

Previous ArticleNext Article

Coronavirus con artists continue to thrive 0 467

Man working on laptop

The scam machine shows no signs of slowing down, as fraudsters continue to dispense bogus health advice, peddle fake testing kits and issue malware-laced purchase orders

As the Coronavirus pandemic continues to escalate, more companies are now shifting to remote work as a way of containing the spread of the disease. Similarly, lockdowns and travel bans, among other stringent measures, have become the order of the day across several nations. And to worsen the situation, there is a massive shortage of the required medical kits.

Such a crisis provides fraudsters undue advantage over a vulnerable lot that is financially destabilized, as well as emotionally drained as a result of the pandemic. 

In this case, you would likely receive fake updates regarding the pandemic, as well as non-existent offers for personal protective equipment, among others. Likewise, if you’re a business, you would certainly receive faux purchase orders and payment information.

Fortunately, as a follow up to our previous article about the ways scammers are exploiting coronavirus fears, we provide you with a few examples of the new campaigns aimed at stealing your money or personal information. To enable you to keep your guard up. Shall we?

Fake news/information

As the virus continues to escalate, more people are currently searching for practical information on how they can protect themselves. As a result, scammers have conveniently positioned themselves as the true COVID-19 information “crusaders” by impersonating well-known health organizations, such as the World health organization.

Don’t act surprised if you receive an email (containing an attachment) supposedly coming from a reputable health organization offering you “vital information” on how you can protect yourself from the disease.

For instance, our research team identified one such file containing a Trojan designed to steal personal credentials.

Apart from the WHO, fraudsters are also impersonating the US Centers for Disease Control and Prevention (CDC). Accordingly, the FBI has given a warning about scummy emails mainly riddled with malware-infested attachments and links purporting to originate from the CDC.

 To reduce the number of people falling for such schemes, the WHO shares examples of its official email addresses and methods of communication on its website.

Urgent purchase orders and late payments

Owing to the increased pressure from governments to reduce the spread of the virus, Companies, as well as factories, have been forced to streamline their operations according to the current situation. As an example, companies to integrate work from home modules, while factories to either increase or reduce their production capacities depending on their products.

Such erratic changes have brought about a climate of uncertainty that offers fraudsters a thriving environment.

In this case, as a factory owner or executive, be on the lookout for “urgent purchase orders” from “company representatives.” Since this fake orders come from scammers who want to make a kill out of your desperation of making some revenue before things go south.

Sadly, if you download such “urgent orders” (usually in attachments), your PC will be installed with malicious code designed to steal your details.

Below is an excellent example of such an “urgent order”:

Similarly, you would receive a “proof of payment” for you to take care of the order. However, like the last example above, instead of receiving a bank statement, the attached document contains a Trojan injector.

High demand products

A massive increase in demand compounded with an inadequate supply for essential protective items, such face masks has created another avenue for scams.

A typical example of such a scam involves a fraudulent site that is offering “OxyBreath Pro” face masks at a reduced price. These can lure you since there is a shortage of masks, and what is available is highly-priced.

However, if you click on the provided links, you’ll be at risk of exposing your sensitive personal information to the scammers.

Bogus testing gear

The unavailability or short supply of medical kits for testing folks for the virus has also attracted fraudsters in droves.

For instance, the existent low supply of masks, respirators, and hand sanitizers, among other necessities, has prompted scammers to impersonate medical officials.  So that, they can provide non-existent or fake COVID-19 test kits, as well as illegitimate “corona cures.”

As an illustration, more than 2000, links associated with fake coronavirus products have already been identified. Similarly, law enforcement bureaus alongside other relevant bodies have been able to seize US$ 13 million worth of potentially hazardous pharmaceuticals.

To contain these despicable actions, the U.S. Food and Drug Administration (FDA) has issued warnings that it hasn’t allowed the sale or purchase of coronavirus self-testing kits; therefore, it is currently bursting such sellers.

Final thoughts

In a wrap, what we have shared is a representative of the many current fraudulent campaigns doing rounds in our media spaces due to the prevailing situation.

Thus, it is critical to maintaining high alertness to avoid falling victim to both the COVID-19 pandemic, as well as the ensuing scam epidemic escalating through the internet. To keep yourself safe from the scams, you can practice the following basics:

  1. Avoid downloading files or clicking on links from unknown sources
  2. Never fall for unrealistic offers or order goods from unverified suppliers. You may also make a point of checking out the purported vendor’s reviews
  3. Invest in an excellent endpoint solution which can shield you from phishing attacks, as well as other forms of scams
  4. If an email suggests coming from a reputable organization, double-check with the firm’s website to confirm its authenticity

If you require consultation, as well as endpoint solutions for your cybersecurity needs, then ESET has been here for you for over 30 years. We want to assure you that we will be here to protect your online activities during these uncertain times, too.

Protect yourself from threats to your security online with an extended trial of our award-winning software.

Try our extended 90-day trial for free.

How To Easily Set Up a VPN at Home 0 300

Woman working at home

As the COVID-19 pandemic has many organizations switching employees to remote work, a virtual private network is essential for countering the increased security risks

Probably, you have been forced to work from home due to the COVID-19 outbreak (recommended to reduce the spread of the virus). However, you are wondering how you will set up your VPN to enable secure communication.

Well, don’t agonize too much; we shall first explain to you what a VPN entails. And then, provide you with a step by step procedure for setting a basic Virtual Private Network. Here we go!

First, what is a Virtual Private Network (VPN)?

Essentially, a VPN is a private channel within a wider (open) network that enables you to communicate with your peers (other nodes with similar settings) without leaking your information through the use of encryption.

Besides, you can utilize a VPN to initiate communication through any network without revealing your location. In any case, a significant number of vendors deal with clients needing such services to avoid being tracked or be able to bypass particular network filters. 

However, in our case, we shall consider a home office VPN that will create a communication tunnel for your practical and secure home office communication.

Is it necessary to set up a virtual private network?

For there to be any communication between two endpoints ─ your pc and the computer in the main office –, they must be configured.

In this case, you’ll require the services of your IT department (if you have one), who will guide you regarding the applications to install, as well as provide you with VPN credentials depending on your needs. Upon installing and configuring the said app, you can automatically establish communication through the provided link. Easy-peasy, right?

On the other hand, if you don’t have an IT department behind your back, then you may have to do it yourself. These shouldn’t; however, scare you at all; it’s not as tough as you might imagine.

But before we explore the nitty-gritty of setting up the VPN, we first need to identify the options we have. In our case, we shall examine two options:

  • Open VPN: standard in small office/home office and business-class routers
  • IP Sec: Is Built-in and commonly used by desktops, smartphones, and laptops

The Open Virtual Private Network

This type of VPN has been around for a long time and has proved itself secure and reliable. It is ideal for small office/ house offices, as well as business-class routers, thanks to its open-source nature.

Procedure for installation

  1. On a contemporary device, go to the router’s configuration screen and click the relevant buttons to access your office network
  2. Download the configuration file generated by the router
  3. Use this file to configure/setup the OpenVPN in your pc, smartphone, or desktop that you want to use to access the Network behind that particular router. In case you get stuck somewhere, you can download or follow an online tutorial for your specific router.
  4. Download the required apps that will enable you to access your new home office VPN from this website.
  5. Install the downloaded applications and then configure them using the files generated when setting up the Open VPN on your office router.

In the event you find the going tough, you can always consult with an online tutorial or IT personnel.

Internet Protocol Security

IPsec is also another technology that has been in use for an extended period to provide reasonable security. It utilizes the same working principles as the OpenVPN; however, it is mostly used on lower-cost routers. Besides, it is a built-in technology in most desktops, laptops, and smartphones; therefore, it eliminates the need for installing another application on your device.

The installation process is similar to that one of OpenVPN. However, implementing a particular router IPsec can sometimes be a little more complicated compared to installing an open VPN.

Fortunately, with the use of native tools on your remote endpoints, you can offset this by just typing in a few things, such as the required IP address and credentials.

Final thoughts

Conclusively, these are some of the simplest virtual net protection options you can install on your home system without requiring massive/no input from IT experts.

Importantly, you will need a beefier than standard broadband for quick communication over the VPN. Also, you may experience slower connections due to the much horsepower required to keep the connection encrypted and tunneled. Nevertheless, this is a small price to pay in exchange for a secure home office communication.

In case you required any advice regarding VPN options or installation services, then ESET has been here for you for over 30 years. We want to assure you that we will be here to protect your online activities during these uncertain times, too.

Protect yourself from threats to your security online with an extended trial of our award-winning software.

Try our extended 90-days trial for free.