Showing posts with label encryption. Show all posts
Showing posts with label encryption. Show all posts

Tuesday, May 16, 2017

Beware: the WannaCrypt / WannaCry Ransomware

What is WannaCrypt Ransomware? 
WannaCrypt Ransomware, also known by the names WannaCry, WanaCrypt0r or Wcrypt is a ransomware which targets Windows operating systems. Discovered on May 12, 2017, WannaCrypt was used in a large Cyber-attack and has since infected more than 230,000 Windows PCs in 190 countries.

How does WannaCrypt ransomware get into your computer?

As evident from its worldwide attacks, WannaCrypt first gains access to the computer system via an email attachment and thereafter can spread rapidly through your LAN network. The ransomware can encrypt your systems hard disk and attempts to exploit the SMB vulnerability to spread to random computers on the Internet via TCP port and between computers on the same network.

The best thing you can do it to avoid clicking on any attachments sent to you via email, even if they appear to be legitimate!


Although the first wave of this ransomware was stopped, we are already seeing new variations of it hitting computers around the world. Be sure your systems are consistently backing up. If you are unsure, contact your assigned IES agent.


Lastly, if you see the message below - or a similar one - it’s already too late for you. IMMEDIATELY SHUT DOWN YOUR COMPUTER and call IES at 781-816-9437.

 

Monday, April 4, 2016

Cryptowall / Cryptolocker virus update.

We want to alert you to a very urgent threat to the data on your network called Cryptowall / Cryptolocker.

You should immediately advise your staff to
not open ANY files that are sent to you through e-mail. This new virus/trojan arrives as an e-mail that contains a zip, doc, xls, or pdf file that pretends to be an invoice, purchase order, bill, complaint, UPS or USPS shipment or other business communication. If you receive such a message, you should verify with the sender that they did in fact send this message prior to opening the attachment.

This threat is specifically designed to defeat firewalls, anti-virus and anti-malware software. There is presently no known way to block these threats. If you open such an attachment, you won't even know you have been infected until you attempt to access data on your network. Once infected, your critical data is inaccessible and current recovery steps are time consuming and expensive. We cannot stress the severity of this threat enough.

We are actively monitoring this situation and working with our security partners to implement updates as soon as they are available. In the meantime, we recommend that you and your team adopt a very conservative posture toward this threat by not opening any e-mail attachments you have not personally verified. We expect this threat to remain active for the foreseeable future.

If you have any questions or concerns related to this, please do not hesitate to contact our office. 

IES, Inc.
781-816-9437
www.iesAdvisors.com

Monday, June 1, 2015

The hackers are coming! The hackers are coming!

Hacking: it’s not just for Anonymous and the U.S. government anymore.

Cybercrime is ever-encroaching and can happen to anyone. Including you and your business. In fact, it’s cost the global economy more than $400 billion, and it’s increasingly hurting smaller operations.

The problem goes far beyond the leaking of sensitive emails and sexy selfies. Targeted attacks against small businesses nearly doubled in 2013. And of the one in five that experience a cyber attack annually, 60% will close their doors within six months as a result (source: Symantec).

But not you. Protect your business with these three tips:

1. Be password savvy. If your password is still “Password123,” it’s time to get serious. Create unique codes for each of your accounts, and make sure they’re at least 8 characters long (with a few special ones thrown in). Use password managers like LastPass 3.0 or Dashlane 3 to keep track.

2. Encrypt emails and valuable information. If a hacker does breach your system, encryption makes it that much harder to get away with critical data. Voltage, DataMotion, and Proofpoint are industry leaders worth checking out. 

3. Back up your data. Copying your key company data onto a cloud based system, such as Dropbox or Carbonite, or a USB hard drive takes minutes, and will save you time and anxiety if your system is ever compromised.

For professional help, call IES today at 781-816-9437. We can have you safe and secure in hours, not days!

Wednesday, June 4, 2014

Google now testing super secure email.

It's called "End-to-End" encryption, and it's the best way to stop anyone from snooping on your emails. Google would turn your emails into jumbled code, and the only person who can see the email in plain text is the trusted person on the other end.

Hackers don't stand a chance. In fact, neither does the National Security Agency. It's the kind of encryption ex-NSA contractor Edward Snowden used to communicate with journalists before he went public last year with damning documents proving the extent of U.S. government surveillance. It's what spies use...it's that good.

But End-to-End is not available just yet. In a blog post, Google said the program is in a public testing phase. After that, you'll be able to download the app and add it to your Google Chrome Web browser. If you use the browser, it'll work with any Web-based email provider.

"We recognize that this sort of encryption will probably only be used for very sensitive messages or by those who need added protection," wrote Stephan Somogyi, a Google product manager who oversees security and privacy, in the blog. "But we hope that the End-to-End extension will make it quicker and easier for people to get that extra layer of security should they need it."

Here's how Google's super encryption would work: Imagine you want to send a sensitive letter by mail. You can't just lick the envelope shut. Postal workers might open it. But they can't open a lock.
Your friend buys a padlock, opens it and sends it to you. He keeps the key. You receive his lock, place your letter inside a box and close it with your friend's lock. You send it. Now only he can open it with his private key, which never left his possession.

Google will let you share locks, but never keys. So far, End-to-End encryption has proven tamper-proof.

This is only the latest move by Silicon Valley giants to beef up their security since last year's revelations that the U.S. government is gathering our emails and phone calls without warrants. In December, executives at the world's largest technology firms called on the U.S. government to respect Internet privacy rights, dial back its intelligence gathering and make spying programs more transparent.

Since then, Microsoft and Yahoo have been working on encrypting the information they house and transmit. Facebook CEO Mark Zuckerberg called President Obama directly to complain about the NSA. And they've all shed light on the scope of secret data requests.

Source: CNN Money

Tuesday, July 30, 2013

5 simple methods to improve your privacy online.

It wasn't long after the Internet came into widespread use that online privacy became a growing concern. After all, anytime people are connected through their computers and sharing resources online, there's the potential for prying and abuse.

1). Browser Settings
There are some easy things that can be done to configure a browser for better security and privacy. Among the basics, go into your Web browser's preference settings and set the browser not to accept cookies from sites you haven't visited, also known as third-party cookies. Generally, you'll want to accept cookies from the sites you visit.

Apple's Safari blocks third-party cookies by default; Mozilla intends to make this the default setting soon in Firefox, but for now you'll need to opt for the setting. You have to choose these settings in Microsoft's Internet Explorer and Google's Chrome.

Also, the newest versions of Internet Explorer, Mozilla Firefox, Google Chrome and several others offer settings for "Do Not Track," a proposed header field that requests that a Web application disable its site and/or cross-site tracking of user activity.

Consider setting your browser preferences to automatically clear cookies when you close the browser.

2). Cloud Storage
Storage of anything private and personal in the cloud should use the strongest form of encryption possible. Strengths of encryption come in various standards. RSA 2048-bit key encryption provides the best possible strength when used with public key infrastructure. The chance of cracking an RSA 2048-bit private key is not nil, but it would take so long that attempting it is not practicable using today's raw computing power.

A strong cipher is the most important consideration. Close behind, however, are the questions of where you should use encryption and with what method.

If you have any data stored on the Internet that you would like to ensure never gets seen by anyone other than yourself, then this is a good candidate for encryption.

The strongest and safest method today for encryption of cloud data is Zero Knowledge. Zero knowledge means that your cloud ISP will have no knowledge of what is being stored on their site. The private key to unlock your data will be created by you on your local drive. Thus only you will have the ability to unlock the data -- not even the cloud ISP will be able to do so.

SpiderOak and Wuala are two examples of ISP Software as a Service sites that offer ZK data encryption.

There are now quite a few SaaS encryption vendors from which to choose, but those that support Zero Knowledge are the safest bet for those with privacy in mind.

3). Two-Factor Authentication
The use of hack-prone password-based access is being gradually replaced by technologies like fingerprint scan, keyfob-generated keys and two-factor authentication methods.

If your ISP uses password-based access, make sure you maintain strong passwords. A password's strength is measured by its ability to avoid being guessed. Many ISPs and portals will test the strength of your password as you create it. Pay attention and be sure that the test returns "strong."

Do not use the same password for multiple accounts. Instead, use strong passwords that are unique to each account - and that's particularly important for your most sensitive online accounts, such as for banking, email, and social networks.

Two-factor authentication is another method that's growing in popularity. Google Gmail now offers a free two-step authentication service. The goal is to avoid having your login stream (which includes your password) from being intercepted by a "man-in-the-middle" attack. Criminals equipped with programs called packet analyzers (also known as "sniffers") can see your streaming data and steal your password.

With two-factor authentication, in addition to entering a password, the system will send to your phone a unique ID number that must be input for authentication as well. Using such a method means the "man-in-the-middle" cannot and will not know what is on your personal phone and so cannot intercept such information.

If your ISP offers two-step authentication, you'd be wise to use it.

4) Encryption for Chat and Email
With Google Talk and Google Hangouts, one can set the chat session to "off the record" to ensure that the chat session is never permanently stored on Google's chat servers.

Also, installing Pidgin for both Windows and Linux - it's a popular multiprotocol messaging software application - along with its "off the record" plugin will ensure that your chat session will remain encrypted and private. This ensures that an additional encryption layer is added to the stream using OTR, regardless of what the underlying protocol provides.

The same encrypted vs. nonencrypted concept applies to email. If you don't want your email read, then it is imperative that you encrypt it. The good news is that encrypting email is technically feasible using GnuPG, PGP or S/MIME standards, for example. The bad news is that few software applications are in circulation that make preparing and sending encrypted email "drop-dead" simple and foolproof in terms of usability by the general public.

5) Surf the Internet Anonymously
Finally, if you really feel strongly about keeping your Internet surfing habits anonymous, you may consider using a proxy for your Internet surfing - though even that won't guarantee complete anonymity.

A more difficult-to-trace method for surfing the Web is called Tor. Essentially, when you install Tor software, you log onto a peer-to-peer (P2P) network representing millions of people, much in the way BitTorrent works. It is encrypted and fully decentralized, meaning not only that it is self-sustainable but also that there is no central server which, if shut down, will stop its Internet activities.

What happens in the Tor scenario is that your IP travels in a random path along the Tor encrypted tunnel and reaches a random endpoint, where your traffic then jumps on the Internet using one of the P2P computing devices as its proxy. That endpoint proxy could be a node anywhere in the world.
If you do try Tor, just go to Google and note which country shows. It will vary from minute to minute - an indication of Tor's anonymity at work.