Monday, October 28, 2013

Handout from Today's Password Management Lunch 'n Learn

If you couldn't make it today's Lunch 'n Learn, don't worry!  We'll be doing another one of these sessions in the near future. In the meantime, here's the handout on KeePass, the FREE password management software that we use here in Information Security.  We highly recommend it! 

It works on PC, Mac and mobile devices so you can have your passwords at your fingertips when you need them.  With KeePass, you just need to remember your master password to get into the password database.  It can even generate passwords for you and log you into websites securely.

We highly recommend it! 
Click on the picture to open the file.

Join Us for Lunch Today: Got (Too Many) Passwords?

We're kicking our celebration of National Computer Security Awareness Month into high gear this week with contests, prizes and 4 Lunch 'n Learns on topics that affect all of us in our online lives.  Want to know more about upcoming events and how to win?  Check out the main NCSAM post.

Why not join us for today's Lunch n' Learn topic on managing all those passwords you have to keep track of?



Everyone gets 2 entries into the prize raffle for each session they attend, so this is a great way to really rack up the points and increase your chance for winning one of our great prizes.

Hope to see you there!
 
p.s.  The online contest starts later today.  Check back here for more details on how you can get an additional entry into the prize raffle.

Friday, October 25, 2013

Spam, Spam, Spam and SPAM!


The number one email or call that we get in Information Security is about how to deal with the volume of annoying spam messages. So we thought we'd devote today's post to what spam is, how to avoid getting on the dreaded "spammler's list" and what you should do if you think you receive too much spam.

What is Spam?

Well, some might say it's a delicious, canned meat-like product.  We're talking about a different type of spam - the unsolicited commercial or bulk e-mail that you didn't request and that clutters up our mailboxes on a daily basis.  Spam usually contains advertisements for services or products but there can be other types as well:
  • Phishing scams that ask for personal information or passwords
  • Foreign bank scams or advance fee fraud schemes (click here to see one of these)
  • Payroll or IRS scams (click here to see one received at KUMC)
  • Pyramid and other "Get Rich Quick" or "Make Money Fast" schemes
  • Quack health products and remedies
  • Ads for adult web sites
  • Chain letters
 
 
How can I avoid getting spam in work or personal email?

There are several things you can do to avoid getting on the spammer's list of addresses.  The first is perhaps the most important:

  1. It may not seem like the right thing to do, but DO NOT respond to spam "Remove Me" e-mail addresses. This just confirms to the spammer that your email address belongs to a real, live human and their messages are getting through.  The effect is that they sell your email address to other spammers and you get even more spam!
  2. Subscribe only to product emails or discussion lists that you are sure you want to receive. 
  3. Check the Privacy Policy on the website before you give them your email address to subscribe to receive updates.  If it doesn't say they won't sell your information, think carefully about whether or not you really want to give them your personal information or email address.
  4. Use one email address for communication with family or friends and a separate email address for receiving product updates, emails from websites, newsgroups or bulletin boards, or unmoderated discussion lists.  You'll be amazed how much spam that second account will receive, but it will keep your important email "clean".
  5. If you receive only a small amount of spam, you may want to simply delete the messages and forget about it.

What does KUMC do to keep spam out of your mailbox?

KUMC has deployed Barracuda spam firewalls to identify and block approximately 96% of all inbound e-mail messages.  Yes!  96% of all the email we receive is spam!

The system can learn what is unwanted email and you can train it by clicking on the "Mark as Spam" button in Outlook when you receive a spam or phishing email.  The more messages that you mark as spam, the faster the system learns what is unwanted in your mailbox.  You can also block certain senders from sending you email.  For more information on how to change your Barracuda spam settings, click here.

And, as always, if you receive a phishing email that is asking for personal information or a password, or you're just not sure if an email is legitimate or not, forward it to Information Security at kumc-security@kumc.edu.

Thursday, October 24, 2013

Prize Announcement!

The wait is over.  And now for the good stuff ... prizes!  Information Security has some really great stuff to give away next week as our National Computer Security Awareness Week celebration really ramps up.  Here's just a partial list of the goodies that you can win*:

 * Must be a an employee or student of KUMC, UKP, RI or other University-affiliated organization to win. 

How can you enter to win?

On Monday, October 28th, we'll be posting an online scavenger hunt and everyone that completes the game successfully will get one entry into the prize raffle.

And, if you want some extra tries at the prizes while learning some cool info at the same time, it's not too late to sign up for any of the four great Lunch n' Learn sessions that are planned for next week.  Attendees will get 2 entries into the raffle pool.  Here's a summary of each session:

Monday, October 28th: Got (Too Many) Passwords?
Description: Passwords, passwords, passwords for your bank site, your personal and work email, Facebook, and on and on. How do you keep track of all of them? Bring your lunch and learn about a FREE and secure way to manage your passwords, including how to make sure they're always available when you need them.
 
Description: A new computer taken out of the box and connected to the Internet is easily taken over by a hacker within minutes. If you've got a computer, you need to arm yourself with the right tools to fight this constant battle. Bring your lunch and learn about the FREE security tools that are a must-have for any PC owner.
 
Description: Social media sites like Facebook and Instragram are great for keeping track of friends and sharing your everyday life with those you love. But there's also a dark side to sharing your information on these types of sites. Bring your lunch and find out how companies and criminals use the information and photos that you share on these sites and what YOU can do to protect yourself on social media.
 
Description: Smartphones, iPads, tablets and other mobile devices are literally changing the way we work and play. But do you know how to protect your shiny new device from hackers? And just what does it mean to store your data "in the cloud"? Bring your lunch and your questions as we discuss security issues related to mobile devices and storing data in the cloud.

You can sign up by clicking on the link above or by clicking on the thumbnail for each session on the bar to the right.

We hope you'll join us in the celebration!

Wednesday, October 23, 2013

Safe Shopping Online

Cyber Monday (the Monday after Thanksgiving) and online shopping throughout the entire holiday season have become increasingly popular in recent years, and the trend is expected to continue this season. According to MarketLive, an e-commerce software and solutions provider, online shoppers in the U.S. are projected to spend more than $54 billion this holiday season, nearly a 17 percent increase over the $47 billion spent last year. The increase in online shopping coincides with an increase in mobile device use, and more shoppers will be using special holiday smartphone apps to find the best deals.
Before you click or tap to buy that "must have" item on your holiday list, check out these tips below to make sure you're doing everything you can to avoid becoming a victim of cyber crime:


  1. Secure your mobile device and computer. Be sure to keep the operating system and application software updated/patched on all of your computers and mobile devices. Be sure to check that any anti-virus/antispyware software installed is running and receiving automatic updates. Confirm that your firewall is enabled.
  2. Know and trust your online shopping merchants. Limit your online shopping to merchants you know and trust. If you have questions about a merchant, check with the Better Business Bureau or the Federal Trade Commission. Confirm the online seller's physical address and phone number in case you have questions or problems.

  3. Look for “https” when making an online purchase. The "s" in “https” stands for "secure” and indicates that communication with the webpage is encrypted. If you submit your credit card information through an organization's website, be sure to look for indicators that the site is secure. Look for a padlock or key icon in the browser's status bar and be sure “https” appears in the website’s address bar before making an online purchase. You should also make sure that your browser software is current and up-to-date.
  4. Password protect your mobile device and computer. It’s the simplest and one of the most important steps to take to secure your mobile device and computer. If you need to create an account with the merchant, be sure to use a strong password. Use at least eight characters, with numbers, special characters, and upper and lower case letters. Adhere to the tenant “a unique password for every unique site.”
  5. Do not respond to pop-ups. When a window pops up promising you cash or gift cards for answering a question or taking a survey, close it by pressing Control + F4 for Windows and Command + W for Macs.
  6. Avoid scams and fraud. Don’t ever give your financial information or personal information over e-mail or text. Be aware of unsolicited communications purporting to represent stores or charities. Always think before you click on e-mails you receive asking for donations and contact the organization directly to verify the request. Information on many current scams can be found on the website of the Internet Crime Complaint Center, a partnership between the Federal Bureau of Investigation and the National White Collar Crime Center.
  7. Do not use public computers or public wireless for your online shopping. Public computers may contain malicious software that steals your credit card information when you place your order. Additionally, criminals may be intercepting traffic on public wireless networks to steal credit card numbers and other confidential information.
  8. Pay by credit card, not debit card. The safest way to shop on the Internet is to pay with a credit card rather than debit card, as credit cards are protected by the Fair Credit Billing Act and may reduce your liability if your information was used improperly.
  9. Print your online transactions. Print or save records of your online transactions, including the product description and price, the online receipt, and the e-mails you send and receive from the seller. Carefully review your credit card statements as soon as you receive them to confirm that all charges are legitimate. Contact your credit card company immediately if you have unauthorized charges on your account.
  10. Review privacy policies. Review the privacy policy for the website/merchant you are visiting. Know what information the merchant is collecting about you, how it will be stored, how it will be used, and if it will be shared with others.
What to do if you encounter problems with an online shopping site?

Contact the seller or the site operator directly to resolve any issues. You may also contact the following:
 
 Your State Attorney General's Office - www.naag.org/current-attorneys-general.php
 The Better Business Bureau - www.bbb.org
 The Federal Trade Commission - http://www.ftccomplaintassistant.gov

For additional information about safe online shopping, please visit the following sites:
 Privacy Rights Clearinghouse - https://www.privacyrights.org/Privacy-When-You-Shop
 Internet Crime Complaint Center - http://www.ic3.gov/media/2010/101118.aspx
 Smartphone Security - Android vs. iOS
 
This material has been adapted from an original article by the MS-ISAC.

Tuesday, October 22, 2013

Dealing with Cyberbullying

Cyberbullying refers to practice of using technology to harass, or bully, someone else. Bullies used to be restricted to methods such as physical intimidation, postal mail, or the telephone. Now, developments in electronic media offer forums such as email, instant messaging, web pages, and digital photos to add to the arsenal. Computers, cell phones, and PDAs are current tools that are being used to conduct an old practice.

Forms of cyberbullying can range in severity from cruel or embarrassing rumors to threats, harassment, or stalking. It can affect any age group; however, teenagers and young adults are common victims, and cyberbullying is a growing problem in schools.

Why has cyberbullying become such a problem?
The relative anonymity of the internet is appealing for bullies because it enhances the intimidation and makes tracing the activity more difficult. Some bullies also find it easier to be more vicious because there is no personal contact. Unfortunately, the internet and email can also increase the visibility of the activity. Information or pictures posted online or forwarded in mass emails can reach a larger audience faster than more traditional methods, causing more damage to the victims. And because of the amount of personal information available online, bullies may be able to arbitrarily choose their victims.

Cyberbullying may also indicate a tendency toward more serious behavior. While bullying has always been an unfortunate reality, most bullies grow out of it. Cyberbullying has not existed long enough to have solid research, but there is evidence that it may be an early warning for more violent behavior.

How can you protect yourself or your children?
  1. Teach your children good online habits. Explain the risks of technology, and teach children how to be responsible online (see Keeping Children Safe Online for more information). Reduce their risk of becoming cyberbullies by setting guidelines for and monitoring their use of the internet and other electronic media (cell phones, PDAs, etc.).
  2. Keep lines of communication open.  Regularly talk to your children about their online activities so that they feel comfortable telling you if they are being victimized.
  3. Watch for warning signs. If you notice changes in your child's behavior, try to identify the cause as soon as possible. If cyberbullying is involved, acting early can limit the damage.
  4. Limit availability of personal information. Limiting the number of people who have access to contact information or details about interests, habits, or employment reduces exposure to bullies that you or your child do not know. This may limit the risk of becoming a victim and may make it easier to identify the bully if you or your child are victimized.
  5. Avoid escalating the situation.  Responding with hostility is likely to provoke a bully and escalate the situation. Depending on the circumstances, consider ignoring the issue. Often, bullies thrive on the reaction of their victims. Other options include subtle actions. For example, you may be able to block the messages on social networking sites or stop unwanted emails by changing the email address. If you continue to get messages at the new email address, you may have a stronger case for legal action.
  6. Document the activity.  Keep a record of any online activity (emails, web pages, instant messages, etc.), including relevant dates and times. In addition to archiving an electronic version, consider printing a copy.
  7. Report cyberbullying to the appropriate authorities. If you or your child are being harassed or threatened, report the activity. Many schools have instituted bullying programs, so school officials may have established policies for dealing with activity that involves students. If necessary, contact your local law enforcement. Law enforcement agencies have different policies, but your local police department or FBI branch are good starting points. Unfortunately, there is a distinction between free speech and punishable offenses, but the legal implications should be decided by the law enforcement officials and the prosecutors.
 
Additional information:
The following organizations offer additional information about this topic:

National Crime Prevention Council

This information was produced by US-CERT and republished for non-commercial use as outlined in their Privacy & Use policy.

Monday, October 21, 2013

Test Your Phishing Knowledge

We're a little over halfway through National Computer Security Awareness Month, so how about a game to test your knowledge of phishing and other email scams? 

It only takes a couple of minutes and it's lots of fun.  Who knows - you might learning something as well!