Showing posts with label Target hack. Show all posts
Showing posts with label Target hack. Show all posts

Friday, October 3, 2014

JP Morgan Chase admits to a significant data breach.

Today, JP Morgan Chase revealed that information on 76 million households and 7 million businesses was stolen from their systems due to malware on an employee laptop. This is added to the Home Depot and Target breaches. Here are a few things you can do to protect your personal information...
  • Change all banking passwords
  • Do not reuse passwords amongst banks
  • Monitor all of your accounts (even those not with JP Morgan)
  • Ask for alerts:
    • Daily balance via email & text message
    • Alerts for transactions over $500 (or whatever level you desire)
    • Alerts for number of daily transactions
    • Alerts when balance falls below a certain amount
  • Use 2-factor authentication
  • Avoid using debit cards
  • Minimize online banking
Demand Chase hold it’s software and security vendors accountable for their lapses - after all, they spend millions (if not billions) of dollars on this software. We as individuals cannot force Microsoft, Adobe, Oracle, Cisco, and other software manufacturers to improve their security. It will take a large customer like JP Morgan Chase to force the software industry to deliver secure, hardened software.

Sources:
NYTimes.com
BusinessInsider.com

Friday, June 27, 2014

Here are five tips to protect your identity online.

1. Change passwords once a month. Passwords are the keys into your life. If a criminal gets access to your email or any of your online accounts, it's surprisingly easy for them to worm their way into other aspects of your life.

Assume your passwords will periodically get compromised. Adobe, AOL, eBay, Kickstarter and Yahoo have all had major security glitches in the past few months.

2. Give the wrong contact information at checkout. Recent data breaches, like last year's Target hack, show that companies aren't responsible enough to safeguard that information. Every time a store clerk asks for your zip code or phone number, that data gets aggregated. So retailers not only have databases that show where you live. They can find out much more about you, like your salary, credit history and birthday.

3. Need photo ID? Don't show your driver's license. This is a general rule for privacy. Don't reveal more than you have to. A driver's license shows your birthday and address.

Next time your doctor's office asks for identification with a photo, show them something else, like your office building badge.

4. No banking apps. Be particularly careful about access to your bank accounts. Although most credit cards have fraud protection, your checking and savings accounts don't.

Because of how easy it is for a computer to get infected with a malware that spies on you, we don't recommend shopping and banking on the same computer.

5. Keep one email account for junk mail only. When companies demand an email address, give them a dummy address. That way you don't have to be bothered with all the spam and annoying advertisements; and it shields your real email from junk. Plus, if those companies get hacked, your real account remains safe.

Tuesday, March 25, 2014

Target Hack: The Movie...coming soon to a theater near you.

Does the computer breach at Target have the makings of a movie? Throw in a shotgun-toting security analyst, Russian hackers, drugs and a SWAT team and Hollywood appears to think so.

Sony has bought the rights to a New York Times article about Brian Krebs, the security blogger who was the first to expose December's security breach at Target.

The article, "Reporting From the Web's Underbelly," was written by Nicole Perlroth and details how Krebs' blog about cybercrime has prompted criminals to hack him repeatedly, send heroin and excrement to his home and falsely accuse him of murder.

"A lot of what Brian does would scare the hell out of traditional newsroom editors," Russ Walker, Krebs's former editor at The Washington Post, said in the Times article. "I don't think he crossed the lines journalistically, but he was living a different type of experience."

The movie is expected to be a cyberthriller written by Richard Wenk, whose credits include "16 Blocks," "The Mechanic" and "The Expendables 2."

Krebs himself seems amused by the notion that his life and unglamorous work may soon be dramatized by Hollywood.

"Judging from accounts of the screenwriter's other movies, if this flick actually gets made someone vaguely resembling me probably will be kicking some badguy butt on the Silver Screen," he wrote Friday in a post on his security blog.

"I still have yet to work out the details with Sony, but beyond remuneration, I would be delighted if I could influence the selection of the leading man," he added.

"In the past week, I've been told I look like both Jim Carrey and Guy Pierce, but I'm not so sure. But if I had to pick one of my favorite actors, I'd love to see Edward Norton in the role."

As many as 40 million customers had their personal information compromised in the Target breach. Krebs found out about it through sources in the hacker underworld and was the first to contact Target about it.

Source: CNN