Does “ThingBot” excist? [----> Read More]
Blog about the latest in Mobile Commerce, Mobile Devices, Mobile Security and Social Media.
Showing posts with label Data Security. Show all posts
Showing posts with label Data Security. Show all posts
Friday, January 31, 2014
Internet of Things: BotNets exist. ThingBots do not
Sunday, April 28, 2013
4 Ways To Increase Password Security for SMB's
![]() |
| gigaom.com |
While establishing a password policy and educating workers are good first steps, they are not sufficient to convince users to select good passwords.
SMBs frequently inherit their employees' selection of passwords, and while three-quarters of workers choose passwords for security, they also compromise to more efficiently gain access to their accounts.
"A business is only as strong as its weakest link, or weakest password connected to that business, whether belonging to a customer, partner or employee," CSID stated in the report.
Here are 4 Ways for businesses to increase password security
![]() |
| Mozakdesign.com |
SMBs generally have no idea the strength of the passwords that their employees are using on internal systems, whether they are reusing the passwords on external services or how many different passwords they have. The first step for businesses to gain visibility should be to adopt a central system for managing employees credentials, whether a password-management service in the cloud or full identity and access management (IAM) solution.
Without such a system, companies will be blind as to the degree of risk they have, LastPass's Siegrist says.
"The scary thing is that most people don't know any better, so if you don't have any tools or procedures in place, you just have no shot of getting to a safe place," he says.
"The scary thing is that most people don't know any better, so if you don't have any tools or procedures in place, you just have no shot of getting to a safe place," he says.
LastPass for instance, gives each employee's account a security score based on their currently stored passwords. While company administrators cannot access the passwords themselves, they can discover when a worker is not following policy.
Even for companies that do not need a full IAM system, the centralized management of employees' passwords goes beyond just gaining insight into workers' password habits. Companies that have administrative control over their employees' accounts can add new workers and delete old ones who no longer work at the firm, heading off the risk from disgruntled employees.
"As companies grow, even to 50 or 100 users, tracking where they've added users have added accounts into different applications not only becomes a burdensome process, but can also become expensive," says Patrick Harding, chief technology officer of Ping Identity, a cloud identity provider.
Ping's product eliminates passwords for many cloud applications by using a single sign-on approach that replaces passwords with Security Assertion Markup Language (SAML) to securely access online accounts.
![]() |
| Liebsoft.com |
In addition to centralizing the administration of the identity storage, companies can benefit from simplifying a user's need to enter in a credential to a single login event. By limiting the number of times a user has to enter in a password, companies can make their workers more efficient and focus on a single channel to secure, Harding says.
"If you only have to authenticate once a day, make that authentication stronger than a password, even a strong password," he says.
Using two-factor authentication for an e-mail account can double as the log-in credentials for the single sign-on system.
4. Change employee behavior
Finally, companies should use any improvements in their management of passwords to educate them about good passwords selection, LastPass's Siegrist says. When employees reuse a password, remind them of company policy against reuse. If workers have not updated old passwords, then remind them to do so, he says.
Finally, companies should use any improvements in their management of passwords to educate them about good passwords selection, LastPass's Siegrist says. When employees reuse a password, remind them of company policy against reuse. If workers have not updated old passwords, then remind them to do so, he says.
"You can set policies to perfectly customize how safe you want your employees to be, and know that they are doing it,"Siegrist says.
Labels:
Cloud,
Data Security,
Password,
Security,
Small Medium Business
Friday, March 1, 2013
Top 5 Mobile Security Threats 2013
Today I will expand further on Security threat for specifically mobile devices using Andriod's Operating System.
A quick refresher from my last blog where I discussed the most likely security threats for anybody using a mobile device (Smartphone or Tablet)

TOLL FRAUD:
(SMS Text) Everybody with a mobile or smartphone receives txt message like "Text 3030 to get your daily weather forecast on your phone" you want it? You text back the number and you receive your daily weather forecast.
This is called PREMIUM SMS as in this figure >>>>>>
Toll Fraud occurs as displayed in the below graph. It is successfull and it happens to more and more users
1. A customer downloads an app that sends out an SMS message to that same ringtone provider.
2. The ringtone provider sends the confirmation message, but instead of reaching the smartphone owner, the malware blocks and confirms the text message before the user ever knows.
3. The malware writers further jumps in between the wireless carrier and the ringtone provider, pretending to be an aggregator, and collects the money you just paid through your bill.
A quick refresher from my last blog where I discussed the most likely security threats for anybody using a mobile device (Smartphone or Tablet)
- Toll Fraud
- Ransomware
- Bring Your Own Devices (BYOD)
- "Drive-by Exploits"
- Mobile Payments via NFC
- Ransomware
- Bring Your Own Devices (BYOD)
- "Drive-by Exploits"
- Mobile Payments via NFC

TOLL FRAUD:
(SMS Text) Everybody with a mobile or smartphone receives txt message like "Text 3030 to get your daily weather forecast on your phone" you want it? You text back the number and you receive your daily weather forecast.
This is called PREMIUM SMS as in this figure >>>>>>
Toll Fraud occurs as displayed in the below graph. It is successfull and it happens to more and more users
1. A customer downloads an app that sends out an SMS message to that same ringtone provider.
2. The ringtone provider sends the confirmation message, but instead of reaching the smartphone owner, the malware blocks and confirms the text message before the user ever knows.
3. The malware writers further jumps in between the wireless carrier and the ringtone provider, pretending to be an aggregator, and collects the money you just paid through your bill.
Ransomware:
What is Ransomware? Ransomware traditionally would infect PC's (via a trojan) and demand a ransom to unlock. For Hackers it is a proven business model on pc's and now has set its sights on Mobile Devices Users.
Thursday, February 21, 2013
2013 Rising Mobile Security Threats
After my last blog I started to brainstorm about the level and what type of security risks M-Commerce and Social Commerce need to mitigate or assure. Given the rise of sales in Smartphones and Tablets and the immense volume of downloadable applications and increasing volume of apps being developed, (personal) data and the protection of it will be key for any business to succeed.
In this blog I will provide a bit more background on the type of security issues M-Commerce & M-Users are exposed.
Furthermore I will try to provide some information on who are what creates those threats and what the key drivers are. To finalize a current overview of the business practices and which security gaps need to be closed fast.
In this blog I will provide a bit more background on the type of security issues M-Commerce & M-Users are exposed.
Furthermore I will try to provide some information on who are what creates those threats and what the key drivers are. To finalize a current overview of the business practices and which security gaps need to be closed fast.
Subscribe to:
Posts (Atom)





