Friday, May 5, 2023

Here's something you never want to see: intruder alert, intruder alert. So catch it before it's too late!

Great news coming out of IES today. We are now taking preorders for the IES HoneyPot. Now you can setup a "sting" operation 24/7 on your network, often alerting you - and us - of an issue before it becomes a real problem.

What is a honeypot you ask? "It's a sacrificial computer system that’s intended to attract cyberattacks, like a decoy. It mimics a target for hackers, and uses their intrusion attempts to gain information about cyber criminals and the way they are operating or to distract them from other targets".

Despite the compact size of our honeypot device, it looks like a real computer system to hackers - with applications and data, fooling cyber criminals into thinking it's a legitimate target. For example, a honeypot could mimic a company's customer billing system, a frequent target of attack for criminals who want to find credit card numbers. Once the hackers are in, they can be tracked, and their behavior assessed for clues on how to make the real network more secure.

It is important to note that a honeypot isn't set up to address a specific problem, like a firewall or anti-virus software. Nor is it meant to replace these network necessities. Instead, it's an information tool that can help you understand existing threats to your business and spot the emergence of new threats. With the intelligence obtained from a honeypot, security efforts can be prioritized and focused.

WE ARE GIVING THESE DEVICES AWAY for a limited time to any of our clients that are interested. We just ask that you cover the annual subscription fee of $365...yes, just $1 per day. Contact us today (781-816-9437 or contactus@iesadvisors.com) to learn more about our devices and see how they can help add a layer of security to your network. Since the devices are plug and play, we can ship it right to your location. Simply plug it into power & Ethernet so IES can do the rest!



Wednesday, March 3, 2021

Visa Announces Non-EMV Compliant Fees

The nationwide shift to EMV-enabled cards - also known as chip or smart cards - began in 2015 with the liability shift, making the party with the least secure technology responsible for chargebacks and fraudulent transactions. Since then, EMV transactions have become a way of life, and consumers have grown more comfortable with the seamless checkout process and security they receive. 

Major card brands have continued to push EMV transactions over swipe. Together we must continue to remain vigilant against the threat of fraud and ensure our shared customers continue to operate in a secure transaction environment.

As a trusted Heartland partner, we wanted to make you aware of two new programs that will be implemented starting with transactions processed on April 1, 2021 to encourage broader adoption of EMV technology in the marketplace...

Visa has announced that they will be issuing a non-EMV Fallback fee beginning in April. If an EMV card is swiped instead of using the EMV chip a fallback fee will be assessed per transaction. These fees will be displayed on the merchant statement in the Visa portion of the Fee Summary section. It is important to note that Visa is the only one that can control this fee and there is no way to bypass it.

We have been urging our clients to upgrade their credit card systems, if necessary. Now may be your last opportunity to do so before being assessed with extra fees.

Give us a call or reach out to your account representative today.

IES, Inc.
781-816-9437
www.iesAdvisors.com

Thursday, August 13, 2020

Lies You Shouldn't Tell the People Fixing Your Computer

The following are common lies that we hear from clients. Please don't say any of these thing when we go to fix your computer! 😀

1). "I've restarted my computer."

We hear this constantly. The first thing we typically ask when someone calls in for help is "have you restarted your computer lately"? The caller always answers yes, but we usually know they haven’t, because the majority of minor tech support issues are resolved with a restart. Rebooting your computer clears out all the minor software hiccups that occur as your computer processes all those millions of lines of code that make it run.

2). "Everything is plugged in."

You might be positive you’ve plugged everything in and are certain there is some other reason you don’t have internet, or your keyboard isn’t working, or your printer isn’t printing. You are wrong. It’s okay. It happens to everyone - even us. Just answer our questions honestly.

Just tell us you have no idea if everything is plugged in. This is especially important if you do not know what an Ethernet cable, USB cable, or power cable are.

3). "I have no idea how I got that ransomware / virus / malware on my computer."

How do you get malware? Well, you go to sites you shouldn’t go to and click on links you shouldn’t click on and download apps you shouldn’t download. Sometimes you hit an OK button you have no business clicking.

It’s very easy to avoid getting malware in most cases. If a Windows looking OK button appears on your computer, don’t click it. If you’re on a free porn site and see a neat ad, if the site promises super expensive software for free, or if it all seems to good to be true, don’t click it. But people click all the time...it's like dangling candy in front of a toddler.

4). "My teenage son has been using my computer."

This is more common than you think. When someone says that, we know where it’s headed. Although, it doesn’t necessarily mean a computer is infected with malware, ransomware, or viruses.

It’s just something people say as they deliver a computer - as if to prep the tech support agent for all the porn they might come across in the course of their repair. But any techie is accustomed to finding porn on a computer.

5). "There's sticky stuff on my computer? I have no idea why. Oh, there's no way it is alcohol."

Do you know how your computer got covered in apple schnapps? You were making an appletini. You drank that appletini. You made another appletini. You drank that appletini. You made another appletini. You spilled that appletini.

We get it, those Zoom meetings from home make us want to drink too! But we can guarantee, as soon as we open the machine -maybe even beforehand - we know what is wrong. It doesn’t matter who spilled it or if you were present at the time, the liquid residue/corrosion voids your warranty and lying about it is just going to waste everyone’s time.

6). "It must have come broken."

Tech agents are not idiots, so trying to con us into giving you a free repair is usually not going to work. If we hear "I opened the box and it was already broken," it's an immediate red flag. We’ll notice that the keys are shiny from days of use, or the scuff on the side that only comes from the laptop getting tossed in a bag.

Over all...

We love helping our customers. But if we hear these any of these six things, there is an immediate damper put in our day. So please, please, please - refrain from saying them!

Friday, June 12, 2020

Client Update: Post COVID-19 Shutdown

We hope you have all been able to begin recovering from the COVID pandemic. We realize businesses have taken a big hit over the last couple months, ours being one of them.

Since 2011 we have been able to avoid rate increases while maintaining our outstanding customer service levels. Infact, we have done extensive research and have found that we are one of the most affordable tech companies in the state of Massachusetts. Unfortunately, with the recent business climate we are in, we have been forced to make some changes. Effective 6/15/20, hourly rates will increase by $25. This minimal increase will help us to continue providing the best service possible to all of our clients in these troubling times.

Please feel free to reach out if you have any questions or concerns. We thank you for your understanding in this matter. 


Please remember our address change as of 1/1/2020.

As of January 1, 2020 we have moved our office to 2277 State Road, Suite C1, Plymouth, MA 02360. Payments should be sent to this address only.

Monday, March 23, 2020

COVID-19 Update For Massachusetts Clients

Governor Charlie Baker has ordered all non-essential businesses to close, effective noon Tuesday, March 24. "Baker said non-essential businesses shall close their physical workplaces and facilities to all workers, customers, and the public."
The governor also stated  "Everyone is advised to stay home and limit all unnecessary activities," while announcing that he and state health officials are issuing a stay at home advisory for the residents of Massachusetts.
Both will remain in effect until April 7.

Source:
CBS
What does this mean for our clients?
Businesses that provide essential services are exempt. Among the businesses that will remain open are grocery stores and businesses that support them, gas stations, pharmacies and all medical facilities, and manufacturers of medical equipment, pharmaceuticals, and restaurants. Governor Baker is expected to release a full list of businesses defined as essential later today.

If your business does not fall under an essential category and you would like to get your office setup for remote working, please email us immediately.

We have resources in place to allow us to continue to provide you with the level of service, responsiveness, and support you have come to expect from IES. We are considered an essential business and are available for you, even with these orders in effect. However, effective Monday, March 23 at 10pm, all IES agents will be working remotely to support our clients and will only be legally allowed to go onsite to provide support if your business falls under an essential category.

As always, we are reachable using any of the following methods:

Phone: 781-816-9437
Email: contactus@iesadvisors.com
Live Chat:
iesAdvisors.com
(click the chat icon that appears in the lower right corner of every page)Request Remote Login Setup

Here are some cyber security tips you should know when working remotely.

One of the key preventative measures for the spread of COVID-19 is social distancing. Luckily, in this increasingly connected world we can continue our professional and private lives virtually. However, with huge increases in the number of people working remotely, it is vital that we also take care of our cyber "hygiene".

Awareness and preparedness are both vital - you'll want to be sure you have the following basics:
 
  • Secure wifi connection. Most wifi systems at home these days are correctly secured, but some older installations might not be. With an insecure connection, people in the near vicinity can snoop your traffic.
  • Fully updated antivirus system in place.
  • Up to date security software. Security tools such as privacy tools, add-ons for browsers etc need to be up to date. Patch levels should be regularly checked.
  • Remember to back up periodically. All important files should be backed up regularly. In a worst case scenario, staff could fall foul of ransomware for instance. Then all is lost without a backup.
  • Lock your screen if you work in a shared space. (You really should be avoiding co-working or shared spaces at this moment - social distancing is extremely important to slow down the spread of the virus).
  • Make sure you are using a secure, encrypted connection to your work environment.
Things employers should do: 
  • Provide initial and then regular feedback to staff on how to react in case of problems. Who to call, hours of service, emergency procedures and how they evolve.
  • Give suitable priority to the support of remote access solutions. Employers should provide at least authentication and secure session capabilities (essentially encryption).
  • Ensure adequate support in case of problems.
  • Define a clear procedure to follow in case of a security breach.
  • Consider restricting access to sensitive systems where it makes sense.
If you have any questions about these tips or need to setup remote login to your office, give us a call at 781-816-9437.

Friday, March 13, 2020

Coronavirus COVID-19 Readiness: Work from virtually anywhere, anytime.


Like you, we're monitoring the latest news about the Coronavirus. That's why we're doing all we can to make sure our staff is standing by to aid with all your technology needs.

We want you to have confidence that you can contact us anytime. In the event of a government mandated quarantine, not much will change. You can still:
•Call our office 24/7 at 781-816-9437 to reach a tech
•Open a support ticket 24/7 at iesAdvisors.com/portal
•Chat live instantly with a tech from 9am - 10pm Monday - Saturday via our website
•Email contactus@iesadvisors.com for a same day response

Thankfully we are able to service most of our customers' issues remotely via the Internet using the latest in technology.

Working Remotely

One of the many services available to our clients is the ability to remote into your work computer from another location. Some clients are already utilizing this service. Best of all, there is one low yearly cost.

Here’s what we need to know to setup your account:
•The business owner or manager needs to authorize us to setup your remote access account.
•The name of each computer you want to access remotely and who will access it.
•Each user’s email address. (Once the accounts are setup, we send instructions on how to use the system via email).
•A secure password for each user to access the portal.

Click the button below to launch the request using your default email application. We’ll reach out to setup your remote access up ASAP!
Request Remote Access Now
 

Friday, February 28, 2020

Phishing is real...Just ask Shark Tank host Barbara Corcoran.

Shark Tank judge Barbara Corcoran lost nearly $400,000 in an elaborate email scam that tricked her staff.
Corcoran said someone acting as her assistant sent an invoice to her bookkeeper earlier this week for a renovation payment. Staff believed there was "no reason to be suspicious" about the email because she invests in real estate, so the bookkeeper wired $388,700 to the email address. 
The problem was that the email address didn't belong to her assistant. The scammer imitated her assistant's email address and misspelled it with one letter. The mistake wasn't caught until the bookkeeper emailed the assistant's correct address for a follow-up.
Corcoran fell for a phishing scam, which is common: Nearly 30,000 people reported being a victim of that type of scam last year. Together they reported nearly $50 million in losses, according to the FBI's 2018 Internet Crime Report.
Phishing attacks are common methods of stealing usernames, passwords and money. Hackers pretend to be a trustworthy source to convince you to share personal data. To be safe, it's important to make sure the sender is authentic before clicking on a link.
Source: CNN Business

Wednesday, January 15, 2020

Yes, the NSA discovered a major security threat in the Windows 10 operating system. No, the Russians are not suddenly hacking you.

The IT world was waiting on pins and needles yesterday for a high profile Microsoft Windows 10 security patch, and the US National Security Agency (NSA) has enlightened us as to why. Apparently the government agency has discovered a serious flaw in Windows 10 that could expose users to surveillance or serious data breaches.

The NSA confirmed (link) that the vulnerability affects Windows 10 and Windows Server 2016. It said that it flagged the dangerous bug because it "makes trust vulnerable." However, it wouldn't say when it found the flaw and declined to discuss it further until Microsoft released a patch.

The vulnerability was found in a Windows component called crypt32.dll, which handles "certificate and cryptographic messaging functions," according to Microsoft. An exploit in that area could affect authentication on Windows desktops and servers, sensitive data on Microsoft's Internet Explorer and Edge browsers and many third-party applications. Hackers could also use it to spoof digital signatures, making malware look like a legitimate app.

A software patch was released yesterday to critical Windows 10 clients including the US military and managers of key internet infrastructure. Microsoft has since released updates for all customers, urging them to install them "as quickly as practical." as this flaw is being noted the second most severe in Microsoft's rating system. Microsoft has confirmed it has not yet been exploited, but is still a major security issue.

Tuesday, September 17, 2019

Venmo Scam Alert

If you use the app Venmo, be aware there is a scam going around.

With this scam, you will receive a text message telling you your Venmo account is about to be charged and If you want to cancel the withdrawal, you need to log on and decline it.

The message allows you to log on with any phone number and password. (The password we used to test this scam was wrong, but it had me continue on). It then asks you to verify who you are by entering the bankcard number and other personal/financial info.

The scam uses the same same colors and fonts as the Venmo App.

Do not use the pages provided by the text to enter into your account. Go directly to your Venmo app or use their Internet website.

If you have fallen victim to this scam and entered your personal information, contact your bank or credit card company immediately.

Thursday, February 7, 2019

Is your business PCI compliant? Avoid fines for breaches!

Major breaches like TJMaxx and Target have been widely publicized in the past, but breaches at smaller businesses have received very little attention. This is mainly because information about these smaller occurrences have been very hard to come by due to two reasons.

First, not all states have disclosure laws requiring merchants to disclose breaches and secondly, card associations are not required to disclose individual cases.

According to a Wall Street Journal article, most breaches come from small businesses who are not up to date with technology or compliance laws. Here are some of the article highlights:
  • More than 80% of the credit card breaches have occurred at small businesses.
  • Visa levied $3.3 million in fines for non compliance against small businesses in just one year.
  • MasterCard did not disclose their fines.
  • Any business that accepts credit cards must agree to be PCI complaint.
Take for example the case study of Lodi Beer, a microbrewery and restaurant in California who unknowingly stored 11,728 credit card records in their point of sale system. (Track data from the credit card's magnetic strip cannot be stored according to PCI standards). When that data was breached, Visa and MasterCard fined Abanco, the restaurant's merchant account provider, $27,000. Abanco then in turn passed that fine onto the restaurant. In addition to the fines, this merchant has spent over $50,000 in remediation costs, legal fees, upgrades, etc. That is a huge amount of money for a small business. Had they been up to date with their technology, this situation could have been avoided.

Here are some interesting facts that you should know about PCI compliance standards:
  • Visa, MasterCard and the other card brands have put the responsibility  of maintaining compliance status on the processor or merchant account provider. They've successfully done this with a policy of making them responsible for paying fines when breaches occur.
  • While these processors are responsible for fines, they will almost always pass whatever they're fined onto the merchant.
  • If merchants are ultimately responsible for the fines, it is their responsibility to maintain PCI standards and stay up to date with their technology.

IES would love to help you become compliant. Give us a call at 781-816-9437 or check us out online at iesAdvisors.com.

Thursday, August 2, 2018

"Site Not Secure" warnings - the latest Google problem for many website owners.

Starting last week, Google Chrome browsers begin flagging every website that doesn't have "HTTPS" in their URL as "Site Not Secure". With about 60% of all Internet traffic utilized through Google Chrome, a change like can affect almost every website on the Internet.


This is the latest in the web’s massive shift from non-secure HTTP to the more secure, encrypted HTTPS protocol. All web servers use one of these two protocols to get web pages from the server to your browser. HTTP has problems that make it vulnerable to eavesdropping and content hijacking. HTTPS fixes most of these problems.

Avoiding this alert and enabling HTTPS is easily done by adding a trusted SSL certificate to your site. To help small business owners get up to speed, IES is offering some great pricing on this product along with our years of experience. If you host your site with us, your SSL certificate can be up and running within hours.

Contact us today for assistance.

iesAdvisors.com
781-816-9437

Wednesday, May 30, 2018

FBI warning: Russians hacked hundreds of thousands of routers.

The FBI warned on Friday that Russian computer hackers had compromised hundreds of thousands of home and office routers and could collect user information or shut down network traffic.

The U.S. law enforcement agency urged the owners of many brands of routers to turn them off and on again and download updates from the manufacturer to protect themselves.

Infections were detected in more than 50 countries, though the primary target for further actions was probably Ukraine, the site of many recent infections and a longtime cyberwarfare battleground.

In obtaining the court order, the Justice Department said the hackers involved were in a group called Sofacy that answered to the Russian government.

Sofacy, also known as APT28 and Fancy Bear, has been blamed for many of the most dramatic Russian hacks, including that of the Democratic National Committee during the 2016 U.S. presidential campaign.

Earlier, Cisco Systems Inc said the hacking campaign targeted devices from Belkin International’s Linksys, MikroTik, Netgear Inc, TP-Link and QNAP.

An FBI official told Reuters that the kinds of devices known to be affected by the hack were purchased by users at electronic stores or online.

However, the FBI was not ruling out the possibility that routers provided to customers by internet service companies could also be affected, the official added.

If you own one of the above brand of routers you MUST restart it. To restart it, unplug your router for 30 seconds and then plug it back in.

We have no indication currently that routers from Verizon, Comcast or Cox have this vulnerability, but it wouldn't hurt to restart them anyway.

Thursday, April 5, 2018

PSA: That Facebook quiz may be hackers mining your personal information.

Social media quizzes – especially popular on Facebook – seem innocent enough. But taking the quiz might mean you are giving away more about yourself than you originally thought, and may extend to your friends as well.

These quizzes ask seemingly silly or useless questions, but hackers can use that information to penetrate your social accounts and gain access to your personal information or the information of your friends and family.

Some quizzes are designed to steal your data in an outright scam. Once answered, hackers can easily hijack personal accounts and use them to lure in more victims. The hackers will include links embedded in the quiz that can cause a security breach of your personal accounts.

But the latest news shows that it isn’t just scammers who are interested in your quiz answers. It turns out, your personal information is big business.

Not all social media quizzes are about unprincipled data collection, but the Better Business Bureau cautions users to be careful about what they share online. Profile data, quiz answers, and more can be used to used to steal your money, or let a scammer pretend to be you in order to steal someone else’s money.

Monday, March 19, 2018

The battle of the dating apps...Tinder sues Bumble!

Match Group, the company that holds a large portfolio of dating services, such as Tinder, Match.com, OkCupid, PlentyOfFish, to name a few, and was in talks last year to purchase the dating service Bumble. Match is still looking to acquire the service, but it’s going about it in an unconventional way: by suing it for patent infringement.
On Friday, Match filed a lawsuit that accuses Bumble of infringing on a pair of patents held by Tinder: one called “Matching Process System and Method,” in which users swipe cards and mutually select one another, as well as “Display Screen or Portion Thereof With a Graphical User Interface of a Mobile Device,” which it describes as an “ornamental aspect” of Tinder’s App. The lawsuit also points to similarities between each companies’ apps, and Bumble’s descriptions of “swiping” run afoul of Tinder’s registered trademarks.
In a statement to The Verge, a Match spokesperson said that the company has “invested significant resources and creative expertise in the development” in its products, and was working to enforce its property rights.
Last November, TechCrunch reported that Bumble had turned down the $450 million offer, but that talks were still ongoing, which could leverage for Match to encourage Bumble to join its portfolio: accept the buyout, and the lawsuit goes away.

Friday, March 9, 2018

Alexa is alive!

It's quiet in the house. Not a creature is stirring, not even a mouse. Suddenly you hear a woman's laughter...but where is it coming from?

No, you're (probably) not being haunted, it's just Amazon's Alexa voice assistant malfunctioning in a profoundly creepy way.

Some Alexa users have reported hearing an unprompted laugh from their smart speaker devices in the last day. The laugh is three short "Ha" sounds in a female voice that actually doesn't sound like Alexa's normal voice. It happens randomly, when nobody is using the device, or in response to request to turn on or off lights.

Amazon is aware of this and working to fix it. The company has not elaborated on what was causing the laugh or how widespread it is.

Alexa's laugh isn't the only thing that's freaking out users. Others have claimed Alexa has stopped responding to requests. One Twitter user said their Amazon Echo suddenly began listing names of local funeral homes and cemeteries, also unprompted.

Of course, when voice assistants start acting on their own, it also raises concerns about what artificial intelligence might be capable of. But it's unlikely that Alexa has become sentient and is intentionally frightening users with the laughs.

Thursday, December 28, 2017

Providing WiFi to renters...why you should and how to protect yourself.

WiFi has become one of the most popular amenities requested by rental guests – ahead of a dishwasher or cable TV. Plain and simple: if you do not offer free WiFi, you are losing business.

Think about it...do you work when you travel? Most people reading this will answer "yes" or "I try not to, but unfortunately I do". What do you need in order to work? An Internet connection. (And a descent one at that). But it's not just for work – kids love Netflix, grandparents love to Skype, and that cat video of Fido just needs to be posted to YouTube this very second.

Did you know that rental property owners are legally responsible for everything their renters do online? If your renter engages in any illegal activities online, it is the owner who pays the price. IES has the perfect solution to your liability issue while still offering renters a seamless WiFi experience...

Our system features:
•Plug & play out of the box – 5 minute automatic activation
•Custom branded sign in page with your logo, contact information, and legal disclosure (exempting you from wrongdoing); option to add form to collect data such as email addresses, phone numbers, and birthdays for marketing purposes
•Online dashboard to get statistics such as use history, block users, generate passwords, set time limits, set speed limits, and more
•Option to charge for WiFi, or upgraded WiFi option, if desired
•Visit iesAdvisors.com/wifi for a full list of features.

Ready to learn more or make a purchase? Call 781-816-9437 or click here to email us.

Monday, October 16, 2017

Security Notice: Key Reinstallation Attack

Background

On October 16, a WPA2 exploit was disclosed known as Key Reinstallation Attack (KRACK) that affects all WPA2 protected WiFi networks. This exploit could lead to user's WiFi traffic becoming compromised.

Impact

  • This exploit affects any wireless product using WPA2 encryption, which includes all IES access point products.
  • Those using 802.11r or mesh repeaters are most susceptible.
  • Client devices that have not received a security update specifically addressing this issue are also susceptible.
  • The exploit requires physical proximity to the network.

Fix

  • A new firmware version is currently under test, and we expect to qualify and publish the new version of 6.3 by end of day Tuesday, October 17. An update to 6.4 will be available at that time or shortly after.
  • Once new firmware is available, all networks will begin upgrading during their scheduled maintenance window automatically
  • We will also be patching older versions of our WiFi software, including 481, 590, 6.1 & 6.2, with availability end of this week.

Mitigation

  • In the meantime, we have turned off 802.11r on all IES WiFi devices until they have received the firmware update
  • End users should contact their WiFi client device manufacturers for security updates related to their specific client devices.

Questions / Feedback

If you have any questions or concerns about this vulnerability or the upgrade process, please reach out to IES support

Sunday, September 10, 2017

Welcome to 2017 where hacking is what seems like an everyday occurrence. Cough, cough - Equifax.

Target, CNN, HBO, Chipotle, Gamestop, Equifax - what do all these companies have in common? They have all been hacked this year.

But why, in our opinion, is the Equifax hack the worst? Well, many know Equifax as one of the top three credit reporting agencies. Ever applies for a home loan or an auto loan? Chances are the bank you are using has run your credit through Equifax. Equifax is reporting that sensitive information, such as Social Security numbers and addresses, of up to 143 million Americans has been exposed. The data breach is among the worst ever because of the amount of people affected and the sensitive type of information exposed.

Unlike other data breaches, those affected by the breach may not even know they're customers of the company, as the company gets its data from credit card companies, banks, retailers and lenders - sometimes without you knowing.

When did this happen?
Equifax said the breach happened between mid-May and July. It discovered the hack on July 29. It informed the public on September 7.

How did this happen?
Equifax said criminals "exploited a U.S. website application vulnerability to gain access to certain files."

Am I at risk, and what is Equifax doing to help?
Equifax is proposing that customers sign up for credit file monitoring and identity theft protection. It is giving free service for one year through its TrustedID Premier business, regardless of whether you've been impacted by the hack.

To enroll and / or check whether you were affected, visit www.equifaxsecurity2017.com and click on the Check Potential Impact tab. You'll need to provide your last name and the last six digits of your social security number. Once submitted, you will receive a message indicating whether you've been affected. (Giving your personal information to a company that was just hacked...ironic, we know). Then, you have the option to enroll in the program, but you can't actually sign up for the service until next week. Each customer is provided an enrollment date starting earliest on Monday.

Can I sue Equifax?
If you sign up for Equifax's offer of free identity theft protection and credit file monitoring, you may be limiting your rights to sue and be forced to take disputes to arbitration. But you can opt out of that provision if you notify the company in writing within 30 days. In addition, some attorneys argue that even if you don't opt out, the arbitration provision does not cover suits related to this breach.

It seems like companies are getting hacked a lot. Is this the biggest ever?
The Equifax breach is one of the largest breaches ever. Another high-profile examples include two breaches at Yahoo - the bigger one involved 1 billion accounts, the lesser impacted 500 million.

Wednesday, August 2, 2017

The FBI has issued a security warning about IoT toys.

IoT toys have the potential to violate children’s privacy and safety, given the amount of pertinent information the toys can collect and store, the Federal Bureau of Investigation (FBI) warned this week in an advisory.

The sensors, microphones, data storage capabilities, cameras and other features of Internet of Things (IoT) toys are able to vacuum up extensive details about a child’s name, school, activities and even their physical location.

And if those toys are hacked, criminals could use the stolen information to harm a child, the FBI warned.

What Makes IoT Toys Vulnerable?

Data collected from interactions or conversations between children and toys are typically sent and stored by the manufacturer or developer via a server or a cloud service. In some cases, data are also collected by third party companies that manage the voice recognition software used in the toys.

Voice recordings, toy Web application passwords, home addresses, WiFi information, and sensitive personal data could be exposed if the security of the data is not sufficiently protected with the proper use of digital certificates and encryption when it is being transmitted or stored.

Smart toys connect to the Internet either directly, through WiFi to an Internet connected wireless access point; or indirectly, via Bluetooth to an Android or iOS device that is connected to the Internet.
Key factors affecting the user’s security include: the cyber security features, the toy’s partner applications and the WiFi network through which the toy connects.

Superior communications connections - where data is encrypted between the toy, WiFi access points, and Internet servers that store data or interact with the toy - are crucial to mitigate the risk of hackers exploiting the toy or eavesdropping on conversations or audio messages.

The FBI notes that Bluetooth connected toys that do not have authentication requirements (such as PINs or passwords) pose risks for unauthorized access, enabling criminals to communicate with children.

What You Can Do To Protect Your Child
  • Choose IoT toys very carefully by doing lots of research. Look for any known reported security issues regarding a toy.
  • Find out if a toy can receive firmware or software updates and security patches - and ensure the toy is running on the latest version.
  • Closely monitor your child’s activities with each toy through the toy’s parent application, if such a capability exists.
  • Ensure the toy is turned off when it is not in use.
  • Create a strong and unique login password when establishing a user account. For extra strong passwords, use lower and upper case letters, numbers and special characters.
  • Provide only what is minimally required for creating a user account.