computer security seminar: protect your internet account information

61
Online Safety & Security April-May 2014 Epiphany Technology Committee Jeff Squyres, Jim Cabral

Upload: church-of-the-epiphany

Post on 08-May-2015

228 views

Category:

Technology


0 download

DESCRIPTION

Slides from the Computer Security seminar presented by the Epiphany Technology Committee on 21 April 2014.

TRANSCRIPT

Page 1: Computer Security Seminar: Protect your internet account information

Online Safety & Security

April-May 2014Epiphany Technology CommitteeJeff Squyres, Jim Cabral

Page 2: Computer Security Seminar: Protect your internet account information

Clickable links to additional information are included at the end

of this presentation

Page 3: Computer Security Seminar: Protect your internet account information

Agenda

● Why Should I Care About Security?● Who Is Attacking Me?● What Do I Need to Protect?● What Can Happen?● What Increases My Risk?● How Can I Protect Myself?● What If I Get Hacked?

Page 4: Computer Security Seminar: Protect your internet account information

Disclaimer

● We’re Just Trying to Help● Don’t blame us if things go bad● We’re volunteers (with day jobs)

Page 5: Computer Security Seminar: Protect your internet account information

Why Should I Care About Security?“Just like any other public environment, the Internet requires awareness and caution. Just as you use locks to keep criminals out of your home, you also need safeguards to secure your computer. Many of the crimes that occur in real life are now done - or

at least facilitated - through the Internet. Theft, abuse, and more can be and are being done online. Many scammers target older Americans via emails

and websites for charitable donations, dating services, auctions, health care, and prescription

medications.”US Department of Homeland Security.

Page 6: Computer Security Seminar: Protect your internet account information

The “Heartbleed” bug

Page 7: Computer Security Seminar: Protect your internet account information

The “Heartbleed” bug: Fun facts

● Only 38% of users have changed their passwords○ 6% have changed all○ 16% changed “some”○ 16% changed “a few”

Page 8: Computer Security Seminar: Protect your internet account information

The “Heartbleed” bug

● The Internet depends on encryption○ “https” → S = secure (encryption)○ Encryption between computers

Encrypted connection

Page 9: Computer Security Seminar: Protect your internet account information

The “Heartbleed” bug

● This encryption is known as “SSL”○ “Secure Sockets Layer”

SSL encrypted connection

Page 10: Computer Security Seminar: Protect your internet account information

The “Heartbleed” bug

● ⅔ of web sites use the same software for SSL○ OpenSSL

SSL encrypted connection OpenSSL

Page 11: Computer Security Seminar: Protect your internet account information

● Software bug in OpenSSL since March 2012

The “Heartbleed” bug

OpenSSL

Page 12: Computer Security Seminar: Protect your internet account information

● Software bug in OpenSSL since March 2012

The “Heartbleed” bug

OpenSSL

Page 13: Computer Security Seminar: Protect your internet account information

The “Heartbleed” bug

It’s like walking through a crowded restaurant with a video camera.

Joe Smith: your total is $98.17Here’s my

credit card

Please log me in; my username is “bobcat371”, my password is “LouCardsRule”You catch snippets of

conversations and images.

Most aren’t important.

But some are.

Page 14: Computer Security Seminar: Protect your internet account information

● Most web sites have fixed the problem○ It is now safe to go change all your

passwords

● You can’t know if your password was stolen○ (there was no way to track the guy

with the video camera)

The “Heartbleed” bug

Page 15: Computer Security Seminar: Protect your internet account information

Who Is Attacking Me?

Albert Gonzales: stole 170M credit / ATM cards from TJ Maxx

Page 16: Computer Security Seminar: Protect your internet account information

Who Is Attacking Me?

Nigerian (“419”) scammers

Also related:● Guaranteed loan/credit scams● Lottery scams● Overpayment / refund scams● Disaster relief scams● Travel scams● Tech/computer help scams

Page 17: Computer Security Seminar: Protect your internet account information

Who Is Attacking Me?

Dating, foreign bride, sex scams

Page 18: Computer Security Seminar: Protect your internet account information

Who Is Attacking Me?

State-sponsored

Page 19: Computer Security Seminar: Protect your internet account information

“I’m not important”

● “No one cares about my Facebook account…”

● Wrong○ They care a lot

Page 20: Computer Security Seminar: Protect your internet account information

“I’m not important”

● They’ll use the same username / password to login elsewhere

● They’ll impersonate you

Page 21: Computer Security Seminar: Protect your internet account information

What Do I Need to Protect?

Page 22: Computer Security Seminar: Protect your internet account information

What Can Happen?

Page 23: Computer Security Seminar: Protect your internet account information

Identity and Data Theft

Page 24: Computer Security Seminar: Protect your internet account information

Surveillance/Spying

Page 25: Computer Security Seminar: Protect your internet account information

Inappropriate Content

Source: http://feminspire.com/cyberbullying-a-new-age-in-teenagers-quest-for-power/

Page 26: Computer Security Seminar: Protect your internet account information

What Increases My Risk?

Page 27: Computer Security Seminar: Protect your internet account information

Poor Passwords

● Simple passwords● Old or reused

passwords● Lack of 2-factor

authentication

Page 28: Computer Security Seminar: Protect your internet account information

“Do I really need a different password on every web site?”

Yes(sorry)

Page 29: Computer Security Seminar: Protect your internet account information

“But I can’t remember all those passwords!”

● Use a password-keeper program● Two good ones:

○ LastPass○ DashLane

● Both are“Freemium”

Page 30: Computer Security Seminar: Protect your internet account information

Sidenote: What is 2-factor authentication?

1. Something you know○ Your password

2. Something you have○ Your cell phone

Page 31: Computer Security Seminar: Protect your internet account information

Sidenote: What is 2-factor authentication?

Login: bobcat371, LouCardsRule

Page 32: Computer Security Seminar: Protect your internet account information

Sidenote: What is 2-factor authentication?

Text bobcat371’s phone: code is 998321

This code changes every time

Page 33: Computer Security Seminar: Protect your internet account information

Sidenote: What is 2-factor authentication?

Text bobcat371’s phone: code is 998321

This code changes every time

What’s the code?

Page 34: Computer Security Seminar: Protect your internet account information

Sidenote: What is 2-factor authentication?

Text bobcat371’s phone: code is 998321

bobcat371, code is 998321

This code changes every time

Page 35: Computer Security Seminar: Protect your internet account information

Sidenote: What is 2-factor authentication?

You’re logged in!

Page 36: Computer Security Seminar: Protect your internet account information

Why is that useful?

Text bobcat371’s phone: code is 796537

Login: bobcat371, LouCardsRule

Page 37: Computer Security Seminar: Protect your internet account information

Why is that useful?

Text bobcat371’s phone: code is 796537

What’s the code?

Page 38: Computer Security Seminar: Protect your internet account information

Why is that useful?

Text bobcat371’s phone: code is 796537

Uh...

Page 39: Computer Security Seminar: Protect your internet account information

Why is that useful?

Text bobcat371’s phone: code is 796537

Uh...

Page 40: Computer Security Seminar: Protect your internet account information

Who supports 2-factor?

Page 41: Computer Security Seminar: Protect your internet account information

Who supports 2-factor?

These are only a few

Many more support 2-factor authentication

Check your favorite web sites to see if they support 2-factor authentication

Page 42: Computer Security Seminar: Protect your internet account information

Back to:What Increases My Risk?

Page 43: Computer Security Seminar: Protect your internet account information

Unpatched Software

● Windows and MacOS● Applications (PDF, Office)● Mobile phones, tablets● Web Servers

(Heartbleed)● Others (Java)

Page 44: Computer Security Seminar: Protect your internet account information

Insecure Configurations

● Software not set to auto-update

● Open home WiFi

Page 45: Computer Security Seminar: Protect your internet account information

“I’m not important”

● “No one cares about my home wifi network”

● WrongThey care a lot

Page 46: Computer Security Seminar: Protect your internet account information

Wifi reaches outside of your home

Page 47: Computer Security Seminar: Protect your internet account information

With protected wifi

Your home / wifiBad guy

can’t get in your network

Page 48: Computer Security Seminar: Protect your internet account information

With protected wifi

Your home / wifiBad guy connects

from the street -- he’s in your network!

Page 49: Computer Security Seminar: Protect your internet account information

Unprotected wifi

“Unprotected wifi is not only like leaving your front door unlocked; it’s like leaving it wide open with a ‘Welcome’ mat out front.”

Page 50: Computer Security Seminar: Protect your internet account information

How Can I Protect Myself?

Page 51: Computer Security Seminar: Protect your internet account information

Use Safe Online Behaviors

● Change ALL your passwords now○ Use complex, unique

passwords for each site● Avoid suspicious emails,

messages, websites and public WiFi○ If it’s too good to be true, it

probably is● Monitor your credit cards

Page 52: Computer Security Seminar: Protect your internet account information

Get Help to Setup Security

● Set phones, tablets and computers to auto update

● Back up critical information

● Encrypt your home WiFi (use WPA2)

Page 53: Computer Security Seminar: Protect your internet account information

Get Help to Setup Security

Page 54: Computer Security Seminar: Protect your internet account information

Get Help to Setup Security

Everyone’s setup is

different; we can’t help you in this seminar

Get personalor

professional help

Page 55: Computer Security Seminar: Protect your internet account information

What If I Get Hacked?

Good Response Better Response

Page 56: Computer Security Seminar: Protect your internet account information

Recap

● The internet is a dangerous place○ BUT IT IS

MANAGEABLE!○ Be sensible, be safe○ Stop. Think. Connect.

Page 57: Computer Security Seminar: Protect your internet account information

Recap

● You can take actions NOW to protect yourself○ Change ALL your passwords

■ Use good passwords■ Get a password keeper■ Setup 2-factor where possible

○ Ensure your firewall / anti-virus is up to date○ Upgrade away from Windows XP○ Set all your software to auto-update○ Protect your home wifi○ Setup off-site backups

Page 58: Computer Security Seminar: Protect your internet account information

Questions?

Page 59: Computer Security Seminar: Protect your internet account information

Helpful links● STOP. THINK. CONNECT.: From the Dept. of Homeland Security

○ http://stopthinkconnect.org● Malwarebytes: Handy PC software to remove viruses

○ A good second line of defense○ https://www.malwarebytes.org/

● Lastpass: Password keeper○ https://lastpass.com/ ○ They also run a Hearbleed checker: https://lastpass.com/heartbleed

● Free annual credit report: From the US government○ https://www.annualcreditreport.com/

● XKCD: Simple cartoon showing how Heartbleed works○ http://imgs.xkcd.com/comics/heartbleed_explanation.png

Page 60: Computer Security Seminar: Protect your internet account information

Helpful links● OpenDNS: Parental controls for filtering web sites at home

○ http://www.opendns.com/● Microsoft Family Safety:

○ https://familysafety.live.com/● Reporting Computer Crime:

○ http://www.justice.gov/criminal/cybercrime/reporting.html

Page 61: Computer Security Seminar: Protect your internet account information

Thank you!