Saturday, January 28, 2012

Today is Data Privacy Day

Have you thought about how your personal information is collected, shared, and stored online as your surf the Internet? Here are some tips on how to keep your information secure:

Smartphones and Mobile Devices
  •  Your smartphone contains a host of personal information about you. Secure your phone with a strong passcode or other privacy feature.
  • Think before you text. Keep in mind how the message might be read before you send it. Be aware that texts can be forwarded.
  • Only give your mobile number out to people you know and trust and never give anyone else's number out without their permission. When in doubt, don’t respond. Text and call only the people and businesses you know in real life.
  • Make sure you know how to block others from calling your phone. Using caller ID, you can block all incoming calls or block individual names and numbers.
  • Make sure you have someone’s permission before taking pictures or videos of them with your phone. Likewise, make sure you’re comfortable before allowing someone to take pictures or videos of you.
  • Learn how to disable the geotagging feature on your phone at icanstalku.com.
  • Smartphones store and transmit a wide range of personal data which third parties can obtain access to – often without the user’s awareness or consent ‐‐ including contact lists, pictures, browsing history, certain identifying information and stored location data.
  • Research apps before you download them. Apps on smartphones can transfer unique IDs (essentially supercookies), phone numbers, demographic information and location data to ad companies without users’ consent. Your unique ID, together with your location, age and sex, are valuable information to marketers. Most apps do not have privacy policies. Consumers who download apps often don't know what information they are revealing about themselves, to whom and for what purpose.
  • If your phone is lost or stolen, report it to your local police station and your network operator immediately.
  • Learn about Privacy in the Age of the Smartphone offered by Privacy Rights Clearinghouse.

Social Networking (Facebook, Twitter, FourSquare, LinkedIn, etc.)
  •  STOP. THINK CONNECT. Think carefully about the kinds of information, comments, photos and videos you share online.
  • Know your audience: Consider who may have access to your profile: family, friends, friends of friends, your school, college admissions officers, potential employers. Use available privacy settings to manage your audience.
  • Own your online presence: When available, set the privacy and security settings on websites to your personal comfort level for information sharing. Do not rely on “recommended” settings or default settings. Make your own decisions. It's okay to limit who you share information with. It is okay to not accept a friend request.
  • Your online reputation can be a good thing: Recruiters often respond to a strong, positive personal brand online. So show your smarts, thoughtfulness, and mastery of the digital environment.
  • Your privacy is only as protected as your least reliable friend allows it to be: Keep in mind that privacy settings protect information from people you choose to exclude from your personal networks. When you choose to share information with friends, those friends can make their own decisions about forwarding your content. Avoid sharing compromising photos and information. Think carefully before sharing.
  • Make passwords long and strong: Combine capital and lowercase letters with numbers and symbols to create a more secure password. To protect your privacy, don’t share your passwords with others.
  • As a general rule, do not share the following information on a profile page: your phone numbers, home address, full date of birth, travel plans, social security number, passwords, family financial information, bank or credit card numbers.
Want more?  Visit http://bit.ly/A8dHCK for more details on how to keep your information secure.

Thursday, January 26, 2012

Using pcAnywhere? STOP NOW!

If you're not familiar with pcAnywhere, it's a software package that allows you to remote control a computer.  The manufacturer, Symantec, has announced that the source code for the software has been stolen by a hacker group and that there are some serious issues that they need to address.  The company's recommendation is that you stop using the software immediately until they can issue a patch.  For the full story, go here.

Friday, January 13, 2012

Fun Friday: Can You Spot What's Wrong?

It's Friday the 13th and what better way to celebrate than with a fun quiz.  CSO Magazine has published the "Clean Desk Test".  Can you spot the 20 violations of a good clean desk policy in the photo below?  Click on the photo to get started and to see the answers.

Tuesday, January 10, 2012

Microsoft Patch Notifications for January 2012

Microsoft released 7 patches today designed to address 20 vulnerabilities, including the one exploited by the Duqu worm. There are two patches that have been given a "PATCH NOW" rating by SANS:  one of them, MS12-004 or KB2636391, addresses a currently exploited issue in Windows Media Player . Windows, Office and Internet Explorer are all affected and many of the updates will require you to restart your computer.

Members of the KUMC community will have these patches deployed automatically to your on-campus computers, so no further action is needed. However, you should ensure that your personal computer is  updated as soon as possible.

Tuesday, December 27, 2011

Update to Firefox 9 and 3.6.25

Earlier today, the Mozilla Foundation released Firefox 9 and Firefox 3.6.25 to address multiple vulnerabilities that would allow an attacker to execute arbitrary code, cause a denial-of-service condition, or perform a cross-site scripting attack.  (In other words, they could control your browser or PC, cause it not to function, or steal information.)   Campus computers will be updated automatically; however, you are encouraged to update your Firefox installations on personal devices as soon as possible

For additional information, review the Mozilla Foundation Security Advisories for Firefox 9 and Firefox 3.6.25.

Android Devices are High on the Target List

For those of you who own an Android device:  you might want to take a look at these two recent news releases.  Unfortunately, Android's lack of review\approval for Android apps that are available for download plays a huge part in the potential for malicious apps making their way onto your phone or tablet.  There is still no known malware attack against stock iPhones (although jailbroken iPhones are vulnerable).

McAfee:  Nearly All New Mobile Malware in Q3 Targeted at Android  (you can read the full McAfee Threat report here)

Researcher Develops Remote Access Android Exploit

Monday, December 19, 2011

Funny New Phishing Video: "Phishing Bells"

Thanks to our talented friends at the University of Rochester for posting their most recent production of "Phishing Bells", a video about the do's and don'ts when it comes to spam email.  Enjoy!