Computer users are in big trouble, and the threat is faced by consumers and the business community alike, writes ARTHUR GOLDSTUCK.
Almost all users of online business sites and tools are potentially in big trouble – they just don’t know it.
When hackers broke into the most popular social network for professionals this year and the most popular file storage service a few years ago, they didn’t just make off with the passwords for their own use. They published their lists of stolen user names and passwords on hacker sites and on what is know as the Dark Web: an Internet underground that is accessed with specialised browsers.
The biggest problem is not so much that hackers managed to get to the passwords. The average person is simply not worth targeting by the hacker looking for a big payday.
There are two bigger issues, says Stefan Tanase, senior security researcher in Kaspersky Lab’s global research and analysis team. At Kaspersky’s annual Cyber Security Weekend in Malta last week, he offered a sobering perspective on just how easy the hackers have it.
First, he says, most people don’t change their passwords even when they have been compromised in this way – precisely because they feel these particular accounts wouldn’t interest anyone.
Second, once such details have been made available to others, there are armies of potential wrongdoers scouring these lists and testing accounts to exploit vulnerabilities. These can be as mundane as the opportunity to damage people’s reputation by posting vile content in their names.
But even if a password has been changed, a deeper threat remains.
“Since it is so difficult to keep track of one’s passwords across multiple sites, many people use the same standard password wherever they log on,” says Tanase. The sharp criminal mind – and there are many of those – uses publicly-posted stolen log-on credentials to try logging onto various other sites.
Sooner or later, they find their way into people’s Facebook, Twitter or Gmail accounts. Here they harvest profile information, combine it with the log-in credentials that have already proven fruitful, and proceed to break into anything from PayPal to online bank accounts. Where they have access to the victim’s email, it is a simple matter to alter security credentials, and begin transacting in that person’s name.
That is a worst-case scenario – but one that is all too real. There is a word for it: “pwned”. That’s hacker/youth/hipster slang for being “owned” by someone, or conquered.
Most of us have already been pnwed, but don’t know it. Visit the website https://haveibeenpwned.com and type in your email address. It will tell you exactly which stolen passwords lists include your details. If nothing comes up, you’ve kept your online registrations to a minimum. If something does come up, make sure you change your passwords on any sites mentioned – as well as on any other site where you use the same passwords.
“Whenever hackers publish a hacked database, the people at haveibeenpwned collect it and put it in a searchable database where the public can check for their email addresses,” says Tanase. “Don’t worry, it doesn’t make passwords available. But it includes an incredible number of accounts – from 152 leaked databases and 1,8-billion accounts ‘pwned’ by hackers.”
Tanase himself, an affable Romanian who has been analysing threats for Kaspersky Lab for much of this decade, admits he has been pwned.
“Even though I’m a security expert, and done everything right, I’ve been massively pwned. My information was leaked from at least five providers who were hacked.
“Even if you do everything right from a security standpoint, with two-factor authentication, complex passwords, don’t reuse passwords, don’t click on phishing links, you’re still vulnerable when a website gets compromised.”
There is little people can do to prevent one-off theft of passwords after an intrusion, but they can close the hole quickly by changing the password as soon as it has been compromised, If they don’t reuse passwords, then the blow to the ego of getting pwned will be the worst of the damage. If they do reuse passwords, then some serious maintenance suddenly becomes a priority.
For those who are deeply concerned about email and messaging privacy, Tanase has one simple piece of advice: “Crypto is your friend.” By this, he means that using encryption tools will generally safeguard you from personally targeted intrusions. “It is mathematics; it will never lie to you,” he says.
“There are tools you can use, you just need to know about them and also get your friends to use them because, if you’re the only one using it, its not encrypted.
“Let’s imagine every site you use is 100 per cent secure with 100 per cent customisable privacy controls, flawless platform with bulletproof protection. But what happens if one of your friends gets infected? They have access to your private emails sent to the friend, and access to all the information that contact has.
“I want to encourage people to explore the privacy and security settings that are available on all the big platforms, settings that were not available a few years ago, but you still need to enable them from your settings.
“Another important thing is two-factor authentication, where you need both a password and a device where you receive a one-time pin or password. It’s the easiest and quickest thing you can do to massively improve security of your online accounts, online banking security for your Facebook or email or Twitter account. It’s not available by default for simplicity sake, but if you really want security, look for it in the settings. The moment you do that, you make it twice as hard for hackers to access your account.
“Use a password manager to manage all your different passwords. And make sure you keep everything up to date to massively increase your level of security. If you want more security, you have to be okay with less convenience.”
- Arthur Goldstuck is founder of World Wide Worx and editor-in-chief of Gadget.co.za. Follow him on Twitter and Instagram on @art2gee
Sidebar: Compromised web sites, courtesy haveibeenpwned
Adobe: In October 2013, 153 million Adobe accounts were breached with each containing an internal ID, username, email, encrypted password and a password hint in plain text. The password cryptography was poorly done and many were quickly resolved back to plain text. The unencrypted hints also disclosed much about the passwords adding further to the risk that hundreds of millions of Adobe customers already faced.
Compromised data: Email addresses, Password hints, Passwords, Usernames
Dropbox: In mid-2012, Dropbox suffered a data breach which exposed the stored credentials of tens of millions of their customers. In August 2016, they forced password resets for customers they believed may be at risk. A large volume of data totalling over 68 million records was subsequently traded online and included email addresses and salted hashes of passwords (half of them SHA1, half of them bcrypt).
Compromised data: Email addresses, Passwords
Last.fm: In March 2012, the music website Last.fm was hacked and 43 million user accounts were exposed. Whilst Last.fm knew of an incident back in 2012, the scale of the hack was not known until the data was released publicly in September 2016. The breach included 37 million unique email addresses, usernames and passwords stored as unsalted MD5 hashes.
Compromised data: Email addresses, Passwords, Usernames, Website activity
LinkedIn: In May 2016, LinkedIn had 164 million email addresses and passwords exposed. Originally hacked in 2012, the data remained out of sight until being offered for sale on a dark market site 4 years later. The passwords in the breach were stored as SHA1 hashes without salt, the vast majority of which were quickly cracked in the days following the release of the data.
Compromised data: Email addresses, Passwords
Win a Poster Heater with Gadget and Takealot.com
This winter Gadget and Takealot.com are giving away three Poster Heaters, which look like posters but become heaters when you plug them in.
Three Gadget readers will each win a unit, valued at R550 each. To enter, follow @GadgetZA and @Takealot on Twitter and tell us on the @GadgetZA account how many Watts the heater consumes.
What’s the big deal about these heaters? Many of us are struggling to keep the balance between soaring electricity costs and the need to keep warm this winter.
However, the recently launched Poster Heater by EasyHeat and distributed in South Africa by Takealot.com is not only one of the most cost effective electric heaters currently on the market, it is also easy to setup and use.
As the name indicates, it is a poster similar to one you would hang on a wall. But, plug it in and it turns into a 300 Watt heater. The Poster Heater isn’t designed to heat hallways or large rooms, but rather smaller ones like a bedroom or a baby’s nursery or a dressing room.
It uses radiant heating, which means that it heats up in a couple of minutes and the heat is directed at the objects or people around it, quickly taking the chill out of the air and providing a comfortable ambient temperature.
The other advantage of radiant heating is that it doesn’t dry out the air like infrared or gas heaters. Users also don’t have to worry about their children or pets getting too close to it because, even though it gets hot, it can be touched.
To enter the competition follow the steps below:
Competition entry details:
3. The competition closes on 31 July 2018.
4. Winners will be notified via Twitter on 1 August and Takealot.com will be in touch to organise delivery.
5. The competition is only open to South African residents.
Happy Emoji Day! Here’s 10 reasons to be cheerful
First created by Shigetaka Kurita in 1999, the emoji has become a huge part of everyday communication. Whether you love them or hate them, flying dollar bills, applauding hands and rolling eyes are here to stay.
Scientist suggest that the use of emojis will help us gain the same satisfaction from digital interactions as we enjoy from personal contact.
Almost two decades later, and we have over 2600 unique emojis to perfectly express what we feel, thank you Mr Kurita! Join HMD, the home of Nokia phones as we celebrate World Emoji Day on the 17th of July with these interesting emoji facts:
The most popular emoji used is “Person Shrugging”
1. The Nokia 3310 was chosen as one of the first 3 “National” emojis for Finland… it represents unbreakable!
2. South Africa’s favourite emoji is the “Kiss and wink”… how sweet SA!
3. French is the only language where a ‘smiley’ does not top the list for its use
4. On average, over 60 billion emojis are sent on Facebook every day
5. For the first time ever, the Oxford Dictionaries Word of the Year was a pictograph! The “Face with Tears of Joy” was crowned word of the year in 2015
6. According to Emojipedia, some of the most requested emoji’s include afro, a bagel and hands making a heart
7. To include all races, a diversity pack was released in 2017
8. It has become so trendy that the Museum of Modern Art displays the original emoji collection on canvas
9. In 2009, Herman Melville’s classic Moby Dick was completely translated into emoji’s