<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Tricerion Security Blog</title>
	<atom:link href="http://blog.tricerion.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.tricerion.com</link>
	<description></description>
	<lastBuildDate>Tue, 17 Jan 2012 14:02:41 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Zappos insight, direct from Twitter</title>
		<link>http://blog.tricerion.com/2012/01/zappos-insight-direct-from-twitter/</link>
		<comments>http://blog.tricerion.com/2012/01/zappos-insight-direct-from-twitter/#comments</comments>
		<pubDate>Tue, 17 Jan 2012 14:02:41 +0000</pubDate>
		<dc:creator>Eugen</dc:creator>
				<category><![CDATA[Cyberthieves]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Retail]]></category>
		<category><![CDATA[Usability]]></category>
		<category><![CDATA[Vulnerabilities]]></category>

		<guid isPermaLink="false">http://blog.tricerion.com/?p=151</guid>
		<description><![CDATA[Scanning Twitter for responses to the Zappos breach, we have a few favourites that are awfully telling: From @jjmartucci: I bet 99% of the stolen Zappos passwords were &#8220;shoes&#8221;. // Fact: most passwords are frighteningly easy to guess. We bet that those passwords aren&#8217;t &#8220;shoes&#8221; at all, but rather &#8220;password&#8221;, &#8220;abc123&#8243; and others from the [...]]]></description>
			<content:encoded><![CDATA[<p>Scanning Twitter for responses to the Zappos breach, we have a few favourites that are awfully telling:</p>
<p>From @jjmartucci: I bet 99% of the stolen Zappos passwords were &#8220;shoes&#8221;. // Fact: most passwords are frighteningly easy to guess. We bet that those passwords aren&#8217;t &#8220;shoes&#8221; at all, but rather &#8220;password&#8221;, &#8220;abc123&#8243; and others from the list of too-often-used passwords. Alphanumeric passwords just aren&#8217;t as safe as we think they are.</p>
<p>From @dombenoit: receive @zappos email asking to change password after hack, can&#8217;t change password because i&#8217;m outside the US&#8230; good thinking guys.// Fact: American may be in the center of some poorly conceived maps, but it is not the center of the universe. Corporations, don&#8217;t forget that the majority of the world lives outside of the US, and they need customer service too.</p>
<p>From @kimfouroffive: In order to change my Zappos password I would have to remember my Zappos password and that&#8217;s not going to happen. // Fact: Tons of consumers rely on the &#8220;cookies&#8221; on their computer to remember their passwords. There&#8217;s no need to delve into all the reasons that&#8217;s poor practice. But let&#8217;s face it &#8211; many users either don&#8217;t remember their passwords, or they have them written on a post-it in their desk.</p>
<p>From @Kevbo1111: Wait, you&#8217;re telling me a company whose office looks like this, has lax security? #Zappos http://pic.twitter.com/pr9SrfCF // Fact: If we could see inside the workings of all the places that hold our &#8216;secure data&#8217; we wouldn&#8217;t feel so secure.</p>
<p>From @Tuna999: Im confused, is that zappos security email real? // Fact: This is actually a very smart question, that many wouldn&#8217;t think to ask (or research before clicking through). A phishing attempt can look much the same, and confuse consumers into handing over their credentials to fraudulent sites.</p>
<p>From @justAK: Had someone try to acces my bank info a few times. Could this be cause of the #zappos #hacking ? I hope not. #worried // Fact: Too many users have the same password for all online accounts. It&#8217;s not hard to believe that hackers would use information from one site to try to access others.</p>
<p>From @andishehnouraee: Zappos hacked, &#8220;sensitive&#8221; customer info stolen. Before I&#8217;m outed, I&#8217;ll confess here: I&#8217;m a size 12. // Fact: sensitive information is a lot more sensitive than shoe size. That said, great sense of humor!</p>
<p>From @Tontiella: Zappos why are your accounts being hacked into?? Who is not doing their job to prevent this?  // Fact: Strong security measures are fabled to be more expensive than responding to data breaches. Time will tell how this affects Zappos in the long term, but let&#8217;s just say that resetting passwords doesn&#8217;t instill a sense of trust. (And, for the record, strong mutual authentication is well worth the investment)</p>



		<!-- Added by WP-DragToShare-eXtended Plugin -->
		<script type="text/javascript">
			dtsv.dtse_post_151_permalink = 'http://blog.tricerion.com/2012/01/zappos-insight-direct-from-twitter/';
			dtsv.dtse_post_151_title = 'Zappos insight, direct from Twitter';
		</script>
		<!-- End of WP-DragToShare-eXtended Plugin -->]]></content:encoded>
			<wfw:commentRss>http://blog.tricerion.com/2012/01/zappos-insight-direct-from-twitter/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Zappos breach: What not to do</title>
		<link>http://blog.tricerion.com/2012/01/zappos-breach-what-not-to-do/</link>
		<comments>http://blog.tricerion.com/2012/01/zappos-breach-what-not-to-do/#comments</comments>
		<pubDate>Mon, 16 Jan 2012 14:37:29 +0000</pubDate>
		<dc:creator>Eugen</dc:creator>
				<category><![CDATA[Banking]]></category>
		<category><![CDATA[Cyberthieves]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Retail]]></category>
		<category><![CDATA[Vulnerabilities]]></category>

		<guid isPermaLink="false">http://blog.tricerion.com/?p=148</guid>
		<description><![CDATA[Zappos has remained tight-lipped about the nature of their data breach this week. As many as 24 million consumer accounts may have been accessed through an attack on their server in Kentucky. That is as detailed as they&#8217;re willing to go. Full credit card numbers were not stolen, since those were stored separately. It would [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignright dtse-img dtse-post-148" title="Zappos" src="http://buildinternet.s3.amazonaws.com/images/more-popular-logos/zappos_logo.jpg" alt="" width="270" height="203" />Zappos has remained tight-lipped about the nature of their data breach this week. As many as 24 million consumer accounts may have been accessed through an attack on their server in Kentucky. That is as detailed as they&#8217;re willing to go. Full credit card numbers were not stolen, since those were stored separately. It would seem that they expect that security measure to reassure consumers of their multi-tier, rock solid security system, but as far as we&#8217;re concerned, perceived security does not equal actual security, and the breach that disclosed passwords for user accounts breaches actual security.</p>
<p>Some facts that the typical ecommerce consumer should be aware of:</p>
<ol>
<li>Too many users have a single set of login credentials (username and password) for all their online accounts. That means, when someone gets their info from Zappos, they can use it to access Facebook, Amazon, online magazine subscriptions, PayPal, email, gaming sites, online banking, and more.</li>
<li>&#8220;Fixing&#8221; an alphanumeric password breach with new alphanumeric passwords doesn&#8217;t actually &#8220;fix&#8221; anything. If I know the guy trying to break into my house is a locksmith, I don&#8217;t just cut a new key &#8211; I install security measures that a locksmith isn&#8217;t an expert in.</li>
<li>Zappos has chosen the path of least resistance &#8211; deploying consumers themselves to fix the breach. Zappos users have to follow instructions given in an email (which may have gone into spam folders), change their passwords, and email Zappos with any questions or concerns. Anyone with an email address they don&#8217;t regularly check, an overactive spam filter, or the &#8216;grandma&#8217; syndrome (not computer savvy, and likely suspicious of &#8216;official&#8217; email communication) may fall through the cracks.</li>
<li>Changing the Zappos password doesn&#8217;t change all the other similar or identical passwords the consumer uses on other accounts, leaving their customer base open to further attack elsewhere.</li>
</ol>
<p>One of the key takeaways from this is that ecommerce systems should not be based on &#8216;security&#8217; systems that rely on users&#8217; unreliable alertness. Users expect the systems that hold their sensitive information to bear the burden of iron-clad security for their data. Strong, two-factor authentication systems aren&#8217;t just an option in today&#8217;s online environment &#8211; they are where the market is heading by default and by necessity. Zappos has shown us exactly how not to handle a data breach. Of course, if more systems used strong mutual authentication, we&#8217;d see decidedly fewer breaches like the one this weekend.</p>



		<!-- Added by WP-DragToShare-eXtended Plugin -->
		<script type="text/javascript">
			dtsv.dtse_post_148_permalink = 'http://blog.tricerion.com/2012/01/zappos-breach-what-not-to-do/';
			dtsv.dtse_post_148_title = 'Zappos breach: What not to do';
		</script>
		<!-- End of WP-DragToShare-eXtended Plugin -->]]></content:encoded>
			<wfw:commentRss>http://blog.tricerion.com/2012/01/zappos-breach-what-not-to-do/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows’ Touch Screen Image Authentication</title>
		<link>http://blog.tricerion.com/2012/01/windows-touch-screen-image-authentication/</link>
		<comments>http://blog.tricerion.com/2012/01/windows-touch-screen-image-authentication/#comments</comments>
		<pubDate>Thu, 05 Jan 2012 02:10:34 +0000</pubDate>
		<dc:creator>Eugen</dc:creator>
				<category><![CDATA[Mobile]]></category>
		<category><![CDATA[Usability]]></category>

		<guid isPermaLink="false">http://blog.tricerion.com/?p=145</guid>
		<description><![CDATA[As mobile devices flood the market and consumers increase their browsing time on small screens with smaller keyboards, the alphanumeric password is seeming less and less user friendly. Windows, trying to appeal to the mobile savvy user, is initiating an authentication system that is based on a picture – but with a twist. Their system [...]]]></description>
			<content:encoded><![CDATA[<p>As mobile devices flood the market and consumers increase their browsing time on small screens with smaller keyboards, the alphanumeric password is seeming less and less user friendly. Windows, trying to appeal to the mobile savvy user, is initiating an authentication system that is based on a picture – but with a twist. Their system will incorporate the sensitivity of a touch screen, allowing the user to ‘draw’ a gesture on an image to log in. Swipe the eyebrows, pinch the nose, pet the puppy – you get the idea.</p>
<p>The new<a href="http://www.bbc.co.uk/news/technology-16247659" target="_blank"> image- and gesture-based sign-on system</a> to be incorporated into Windows 8 is nifty at best, but leaves much to be desired. The sensitivity of touch screens may prove too sensitive for users’ taste. Being off by a few pixels, or hesitating in the wrong place could end up in a failed authentication. To compensate for this type of confusion, there’s a traditional password system in place as a backup.</p>
<p>But what happens when we relegate an alphanumeric password to ‘backup’ status? It becomes superfluous in our minds – not worth the brain cells to remember. And easily forgotten passwords worse than no passwords. Next, allowing users who can’t authenticate with the image-gesture system to bypass the system with an alphanumeric password nullifies the actual security of the system against keyloggers and other malware sources.</p>
<p>Nifty? Yes. Secure? Unfortunately not. While we’d all like to live in a world where security concerns are secondary to user experience, as my grandpa used to say, that’s just not in the cards.  Need we mention that Tricerion’s strong mutual authentication system could run circles around Windows’ new “nifty” toy? Check it out for yourself, and you’ll see why.</p>



		<!-- Added by WP-DragToShare-eXtended Plugin -->
		<script type="text/javascript">
			dtsv.dtse_post_145_permalink = 'http://blog.tricerion.com/2012/01/windows-touch-screen-image-authentication/';
			dtsv.dtse_post_145_title = 'Windows’ Touch Screen Image Authentication';
		</script>
		<!-- End of WP-DragToShare-eXtended Plugin -->]]></content:encoded>
			<wfw:commentRss>http://blog.tricerion.com/2012/01/windows-touch-screen-image-authentication/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Safeguarding, as attacks evolve</title>
		<link>http://blog.tricerion.com/2011/12/safeguarding-as-attacks-evolve/</link>
		<comments>http://blog.tricerion.com/2011/12/safeguarding-as-attacks-evolve/#comments</comments>
		<pubDate>Fri, 09 Dec 2011 14:41:23 +0000</pubDate>
		<dc:creator>Eugen</dc:creator>
				<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Trends]]></category>
		<category><![CDATA[Vulnerabilities]]></category>

		<guid isPermaLink="false">http://blog.tricerion.com/?p=140</guid>
		<description><![CDATA[These days it seems that while hackers evolve with trends in technology, the general computer user is no more identity savvy than he was before Facebook made identities a virtual open book. Data breaches, hacks, and attempted hacks are in the news regularly, and yet Joe Consumer still uses &#8220;password&#8221; or &#8220;password1&#8243; for all his [...]]]></description>
			<content:encoded><![CDATA[<p>These days it seems that while hackers evolve with trends in technology, the general computer user is no more identity savvy than he was before Facebook made identities a virtual open book. Data breaches, hacks, and attempted hacks are in the news regularly, and yet Joe Consumer still uses &#8220;password&#8221; or &#8220;password1&#8243; for all his accounts, keeps them written in a little black book, and uses FourSquare, Facebook, and Twitter to tell would-be burglars exactly how far from home he is at any given time.</p>
<p>Those in the business know that December is a notoriously risk-ridden time for identity theft, as hackers take advantage of escalating ecommerce around the holidays. How are merchants and business owners to safeguard identity when customers like Joe Consumer make identity theft child&#8217;s play? One of the keys in identity protection is anticipating the evolution of technology. Responding reactively to current and past attacks only leaves users highly vulnerable.</p>
<p>A recent two-pronged <a href="http://www.theregister.co.uk/2011/10/11/rsa_securid_breach_keynote/" target="_blank">RSA security breach </a>hows just how deep hackers will go, uniting efforts across nations to attack secure data. Tokens are out of reach for many, with their high cost of maintenance. SMS authentication is cumbersome at best, and the most user-friendly solutions require nothing other than the user himself. That said, biometrics are excessively expensive.</p>
<p>Strong mutual authentication systems, like that of Tricerion, offer secure protection against assault while maintaining accessible affordability in comparison with biometric or token-based systems.  Picture-passwords have been found more memorable and harder to crack than alpha numeric passwords in <a href="http://etd.ohiolink.edu/view.cgi?acc_num=bgsu1194297698" target="_blank">multiple studies</a> . Details on our authentication systems can be found on <a href="http://www.tricerion.com/" target="_blank">our website</a>.</p>



		<!-- Added by WP-DragToShare-eXtended Plugin -->
		<script type="text/javascript">
			dtsv.dtse_post_140_permalink = 'http://blog.tricerion.com/2011/12/safeguarding-as-attacks-evolve/';
			dtsv.dtse_post_140_title = 'Safeguarding, as attacks evolve';
		</script>
		<!-- End of WP-DragToShare-eXtended Plugin -->]]></content:encoded>
			<wfw:commentRss>http://blog.tricerion.com/2011/12/safeguarding-as-attacks-evolve/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>At $560M, losses from online crime nearly doubled in 2009</title>
		<link>http://blog.tricerion.com/2010/03/2009_losses_report/</link>
		<comments>http://blog.tricerion.com/2010/03/2009_losses_report/#comments</comments>
		<pubDate>Wed, 17 Mar 2010 15:21:53 +0000</pubDate>
		<dc:creator>Eugen</dc:creator>
				<category><![CDATA[Cyberthieves]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Trends]]></category>

		<guid isPermaLink="false">http://blog.tricerion.com/?p=135</guid>
		<description><![CDATA[The Internet Crime Complaint Center (IC3) recently released their report on 2009 Internet crime statistics.  As you can probably guess, there were more complaints, more losses, higher average loss per incident.  IC3 is a federally funded non-profit, a joint operation between the FBI and the National White Collar Crime Center (NW3C). In brief: Complaints received:  [...]]]></description>
			<content:encoded><![CDATA[<p>The <a href="http://www.ic3.gov">Internet Crime Complaint Center</a> (IC3) recently released their report on 2009 Internet crime statistics.  As you can probably guess, there were more complaints, more losses, higher average loss per incident.  IC3 is a federally funded non-profit, a joint operation between the FBI and the National White Collar Crime Center (NW3C).</p>
<p>In brief:</p>
<ul>
<li>Complaints received:  336,655</li>
<li>Total loss:  $559.7 million</li>
<li>Increase from 2008 by 22.3 percent</li>
<li>Median dollar loss of $575</li>
<li>Average dollar loss: $1,633</li>
</ul>
<p><a href="http://blog.tricerion.com/wp-content/uploads/2010/03/IC3_data_2009.png"><img class="aligncenter size-full wp-image-136 dtse-img dtse-post-135" title="IC3 Report - Online Losses in 2009" src="http://blog.tricerion.com/wp-content/uploads/2010/03/IC3_data_2009.png" alt="" width="624" height="640" /></a></p>
<p>Top five categories of offenses:</p>
<ol>
<li>Non-delivered merchandise and/or payment &#8211; 19.9%</li>
<li>Identity theft &#8211; 14.1%</li>
<li>Credit card fraud &#8211; 10.4%</li>
<li>Auction fraud &#8211; 10.3%</li>
<li>Computer fraud &#8211; 7.9%</li>
</ol>
<p>Find lots more data and demographic information by reading the <a title="IC3 Report 2009" href="http://www.ic3.gov/media/annualreport/2009_IC3Report.pdf" target="_blank">full report at IC3</a>.</p>



		<!-- Added by WP-DragToShare-eXtended Plugin -->
		<script type="text/javascript">
			dtsv.dtse_post_135_permalink = 'http://blog.tricerion.com/2010/03/2009_losses_report/';
			dtsv.dtse_post_135_title = 'At $560M, losses from online crime nearly doubled in 2009';
		</script>
		<!-- End of WP-DragToShare-eXtended Plugin -->]]></content:encoded>
			<wfw:commentRss>http://blog.tricerion.com/2010/03/2009_losses_report/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>1024-bit RSA encryption cracked by carefully starving CPU of electricity</title>
		<link>http://blog.tricerion.com/2010/03/1024-bit-rsa-encryption-cracked-by-carefully-starving-cpu-of-electricity/</link>
		<comments>http://blog.tricerion.com/2010/03/1024-bit-rsa-encryption-cracked-by-carefully-starving-cpu-of-electricity/#comments</comments>
		<pubDate>Tue, 09 Mar 2010 15:01:04 +0000</pubDate>
		<dc:creator>Eugen</dc:creator>
				<category><![CDATA[Banking]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Vulnerabilities]]></category>

		<guid isPermaLink="false">http://blog.tricerion.com/?p=132</guid>
		<description><![CDATA[Several researchers the University of Michigan have succeeded in cracking  the RSA security technology which protects all ecommerce and online banking transactions. The university scientists found that they could deduce tiny pieces of a private key by injecting slight fluctuations in a device&#8217;s power supply as it was processing encrypted messages. In a little more [...]]]></description>
			<content:encoded><![CDATA[<p>Several researchers the University of Michigan have succeeded in cracking  the RSA security technology which protects all ecommerce and online banking transactions.</p>
<p>The university scientists found that they could deduce tiny pieces of a private key by injecting slight fluctuations in a device&#8217;s power supply as it was processing encrypted messages. In a little more than 100 hours, they fed the device enough &#8220;transient faults&#8221; that they were able to assemble the entirety of its 1024-bit key.</p>
<p><a href="http://blog.tricerion.com/wp-content/uploads/2010/03/3-8-10-rsahardwarefaultattackgraphic.jpg"><img class="aligncenter size-full wp-image-133 dtse-img dtse-post-132" title="1024-bit RSA encryption cracked" src="http://blog.tricerion.com/wp-content/uploads/2010/03/3-8-10-rsahardwarefaultattackgraphic.jpg" alt="" width="544" height="352" /></a></p>
<blockquote><p>&#8220;The RSA algorithm gives security under the assumption that as long as the private key is private, you can&#8217;t break in unless you guess it. We&#8217;ve shown that that&#8217;s not true,&#8221; said Valeria Bertacco, an associate professor in the Department of Electrical Engineering and Computer Science.</p></blockquote>
<p><a href="http://www.ns.umich.edu/htdocs/releases/story.php?id=7551" target="_blank">Read the full statement here</a>.</p>



		<!-- Added by WP-DragToShare-eXtended Plugin -->
		<script type="text/javascript">
			dtsv.dtse_post_132_permalink = 'http://blog.tricerion.com/2010/03/1024-bit-rsa-encryption-cracked-by-carefully-starving-cpu-of-electricity/';
			dtsv.dtse_post_132_title = '1024-bit RSA encryption cracked by carefully starving CPU of electricity';
		</script>
		<!-- End of WP-DragToShare-eXtended Plugin -->]]></content:encoded>
			<wfw:commentRss>http://blog.tricerion.com/2010/03/1024-bit-rsa-encryption-cracked-by-carefully-starving-cpu-of-electricity/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>9 ways to make your enterprise secure</title>
		<link>http://blog.tricerion.com/2010/03/9-ways-to-make-your-enterprise-secure/</link>
		<comments>http://blog.tricerion.com/2010/03/9-ways-to-make-your-enterprise-secure/#comments</comments>
		<pubDate>Thu, 04 Mar 2010 14:30:52 +0000</pubDate>
		<dc:creator>Kathy</dc:creator>
				<category><![CDATA[Cyberthieves]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://blog.tricerion.com/?p=129</guid>
		<description><![CDATA[Small business or large, studies show that all companies are at risk of attack by hackers. Government agencies including the FBI have suggested using a separate computer for all transactions involving money or sensitive information, but from a business view, that isn&#8217;t scalable or practical. So we&#8217;re gonna spill the beans for you. We&#8217;re not [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: center;"><img class="alignnone dtse-img dtse-post-129" title="Enterprise security" src="http://nksoft.com/images/security.jpg" alt="" width="377" height="148" /></p>
<p>Small business or large, studies show that all companies are at risk of attack by hackers. Government agencies including the FBI have suggested using a separate computer for all transactions involving money or sensitive information, but from a business view, that isn&#8217;t scalable or practical. So we&#8217;re gonna spill the beans for you. We&#8217;re not claiming to bullet-proof your enterprise, but a few minor tweaks may deflect attack, because &#8211; as we&#8217;ve seen &#8211; the lowest hanging fruit is usually what gets picked off. Let&#8217;s raise up your proverbial tree and get that fruit out of reach, shall we?</p>
<ol>
<li>Beware the man (or woman) behind the curtain. Spear phishers are looking for quality, and they&#8217;ll do their research well. Often though, they won&#8217;t go for the high profile target directly, they&#8217;ll go to someone who pushes the buttons for that person &#8211; an executive assistant, general counsel, staff attorney. They are more likely to be phished than, say, the CEO or CFO. These folks need to be super vigilant about the links they click on and the sites they login to, in a sense, expecting that someone will try to dupe them. And that is why they should follow the next advice.</li>
<li> Look for non-obvious clues. Anyone can duplicate a logo or make a look-alike login page. But a vast number of attacks come from non-English speaking countries. If an &#8216;official&#8217; communication uses rotten grammar and is overly casual, be suspect. Hover over links and read the entire link source before clicking &#8211; is the format what it should be? Trust your gut. If something seems odd, don&#8217;t click. And just like dad always told you, if it seems to good to be true, it probably is.</li>
<li>Be cautious of downloads. Certain people &#8211; like lawyers &#8211; deal with downloads all day. PDF&#8217;s and other documents are sent back and forth, passed around, read and re-read. Are you aware that PDF&#8217;s can contain malicious payload that compromises your computer? Don&#8217;t download PDFs thinking they&#8217;re just harmless documents. Note the sender (or host), make certain it&#8217;s something you requested or critically need. And if you&#8217;re unsure, confirm the credentials before downloading.</li>
<li>Use unique email addresses if you can, only giving out your &#8216;real&#8217; email address to people you trust. It&#8217;s easy if you have your own domain &#8211; myspace@jennycramer.com, travel@jennycramer.com, amazon@jennycramer.com. If you don&#8217;t have your own domain, you can at least set up a public email address and a private email address. The public one would be the one you use on websites that require opt-ins, on forms for store loyalty programs, etc. And you would know that anyone can gain access to that account.</li>
<li>Don&#8217;t click on anything in an email. If you think about it, you hardly ever receive something vitally important in an email that requires a click. There&#8217;s the occasional &#8220;click to verify your account&#8221; message, but let&#8217;s be honest &#8211; you expect those, they come right on time, and you were told in advance when and where it would come. So if you didn&#8217;t ask for it, don&#8217;t click on it.</li>
<li>You know those patches for software? Ever wonder if they&#8217;re for real? Well, they are. Use them. They&#8217;re there to protect you, so let them.</li>
<li>Avoid P2P &#8211; person to person &#8211; download applications. BitTorrent, Rapidshare, you know what I&#8217;m talking about. If you want to do it at home, go for it. But there&#8217;s no place for it on an enterprise computing network. Those things are rife with malware.</li>
<li>Switch your company and your home router&#8217;s DNS resolver to use <a href="http://www.pcworld.com/businesscenter/article/162072/use_opendns_to_protect_your_business_network.html">OpenDNS</a>. Do it right now, I&#8217;ll wait. There&#8217;s no reason to use the default DNS provided by your Internet service provider. <a href="http://www.opendns.com/">OpenDNS</a> has a gigantic cache that will speed up your queries and a free Website filtering service that might interest some companies. Even if you don&#8217;t want the filtering, its robust and secure DNS infrastructure can shield you from well-known attacks at the DNS level.</li>
<li>&#8220;Bob&#8221; saying so doesn&#8217;t make it so. We&#8217;ve all had that experience where &#8216;Bob&#8217; says that if we download that patch or install the new version or upgrade the antivirus software, application <em>xyz</em> will fail to work and the entire business will crash. Are you really going to let &#8216;Bob&#8217; put your entire network at risk? If the mission-critical application needs to be tweaked for upgrades, tweak it. And silence Bob &#8211; your enterprise security is more important than Bob&#8217;s personal opinion. Sorry, Bob.</li>
</ol>
<p>We have to thank CIO magazine for the tips here &#8211; many of them came from their informative article on <a href="http://ow.ly/1cMR0">enterprise security</a>. And to conclude, if you have influence over your business&#8217; security procedures, make sure you have policies in place to inform your people about what&#8217;s acceptable and what&#8217;s not. It doesn&#8217;t take militant enforcement &#8211; your people want their computers to be safe. They just need to know how.</p>



		<!-- Added by WP-DragToShare-eXtended Plugin -->
		<script type="text/javascript">
			dtsv.dtse_post_129_permalink = 'http://blog.tricerion.com/2010/03/9-ways-to-make-your-enterprise-secure/';
			dtsv.dtse_post_129_title = '9 ways to make your enterprise secure';
		</script>
		<!-- End of WP-DragToShare-eXtended Plugin -->]]></content:encoded>
			<wfw:commentRss>http://blog.tricerion.com/2010/03/9-ways-to-make-your-enterprise-secure/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>First Direct serves up more than just no-fee banking</title>
		<link>http://blog.tricerion.com/2010/03/first-direct-serves-up-more-than-just-no-fee-banking/</link>
		<comments>http://blog.tricerion.com/2010/03/first-direct-serves-up-more-than-just-no-fee-banking/#comments</comments>
		<pubDate>Mon, 01 Mar 2010 17:40:51 +0000</pubDate>
		<dc:creator>Kathy</dc:creator>
				<category><![CDATA[Banking]]></category>
		<category><![CDATA[Cyberthieves]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Bank]]></category>
		<category><![CDATA[fraud]]></category>
		<category><![CDATA[passwords]]></category>
		<category><![CDATA[Twitter]]></category>

		<guid isPermaLink="false">http://blog.tricerion.com/?p=126</guid>
		<description><![CDATA[First Direct bank in the UK has been the first British bank to embrace Twitter. Does that really surprise anyone? As a 100% online bank, they&#8217;ve maintained a business pace a few clicks ahead of competitors in online services. But last weekend their clients and colleagues got a little surprise. First Direct&#8217;s Twitter account was [...]]]></description>
			<content:encoded><![CDATA[<p>First Direct bank in the UK has been the first British bank to embrace Twitter. Does that really surprise anyone? As a 100% online bank, they&#8217;ve maintained a business pace a few clicks ahead of competitors in online services.</p>
<p>But last weekend their clients and colleagues got a little surprise. First Direct&#8217;s Twitter account was duped, sending direct messages &#8211; the Twitter equivalent to short emails &#8211; to contacts. What&#8217;s more? These weren&#8217;t just any direct messages &#8211; they were pornographic. I don&#8217;t think that boosted their image of professionalism. The direct messages sent out tantalizing links, and upon clicking, users were asked to login to Twitter. Of course, it was a phishing attack where the users were actually divulging their password to hackers.</p>
<p>The next day First Direct sent out a series of tweets that did little to allay fears &#8211; they mentioned twice that they&#8217;d been hacked, then tried to reassure clients that only the Twitter account had been hacked &#8211; not the bank &#8211; and that no user passwords were involved.</p>
<p style="text-align: center;"><a href="http://blog.tricerion.com/wp-content/uploads/2010/03/Picture-1.png"><img class="size-full wp-image-127 aligncenter dtse-img dtse-post-126" title="First Direct Twitter" src="http://blog.tricerion.com/wp-content/uploads/2010/03/Picture-1.png" alt="UK Bank Twitter Account is Compromised" width="475" height="309" /></a></p>
<p style="text-align: left;"><em>The Register</em><em></em> reader Paul Eagles comments in Twitter style of 140 characters or less: &#8220;Let&#8217;s hope they are more secure with their banking systems than their twitter account,&#8221; he writes. Here&#8217;s the deal. This attack phished bank users and convinced them to give away their passwords for Twitter. The problem is that a large number of users have the same passwords for all their accounts, giving hackers potential access to more than just Twitter accounts.</p>
<p style="text-align: left;">So, a note to all users on all platforms. If a link sent to you looks suspect, it probably is. Clicking on it is unwise, and entering any information about yourself is plain foolishness. Your bank won&#8217;t send you porn. I promise.</p>



		<!-- Added by WP-DragToShare-eXtended Plugin -->
		<script type="text/javascript">
			dtsv.dtse_post_126_permalink = 'http://blog.tricerion.com/2010/03/first-direct-serves-up-more-than-just-no-fee-banking/';
			dtsv.dtse_post_126_title = 'First Direct serves up more than just no-fee banking';
		</script>
		<!-- End of WP-DragToShare-eXtended Plugin -->]]></content:encoded>
			<wfw:commentRss>http://blog.tricerion.com/2010/03/first-direct-serves-up-more-than-just-no-fee-banking/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New attack reveals user identities</title>
		<link>http://blog.tricerion.com/2010/02/new-attack-reveals-user-identities/</link>
		<comments>http://blog.tricerion.com/2010/02/new-attack-reveals-user-identities/#comments</comments>
		<pubDate>Fri, 26 Feb 2010 01:23:09 +0000</pubDate>
		<dc:creator>Eugen</dc:creator>
				<category><![CDATA[Phishing]]></category>

		<guid isPermaLink="false">http://blog.tricerion.com/?p=124</guid>
		<description><![CDATA[Browsing on the web just became a little more scary.   A group of researchers found a way to deploy an attack that can “de-anonymize” the users behind the browser (research paper available in PDF format).  Focusing on the users of social networking sites (LinkedIn.com, Facebook, Xing.com, etc.), these security researchers show how to de-anonymize a [...]]]></description>
			<content:encoded><![CDATA[<p>Browsing on the web just became a little more scary.   A <a href="http://www.iseclab.org/index.html" target="_blank">group of researchers</a> found a way to deploy an attack that can “de-anonymize” the users behind the browser (<a href="http://www.iseclab.org/papers/sonda-TR.pdf" target="_blank">research paper available in PDF format</a>).  Focusing on the users of social networking sites (LinkedIn.com, Facebook, Xing.com, etc.), these security researchers show how to de-anonymize a user taking a “browser fingerprint“ – a JavaScript queries the color of various links to find out whether the user has visited those sites in the past – information that is used to essentially “triangulate” the user.  Taking Xing.com as an example and proof-of-concept, this business networking site allows its users to join a variety of groups.  Since many of these groups have open lists of their members, it is possible to build a service that will correlate user data with these publicly available lists of social networking groups, thus pinpointing the users based on their browsing history.  Having this kind of relevant personal information, it then becomes easy to build effective spear phishing attacks.</p>
<p>At <a href="http://www.xing.com" target="_blank">Xing.com</a>, the site that was used to test this theory, it is impressive how quickly the technical team <a href="http://blog.xing.com/2010/02/de-de-anonymizing-in-four-days/">implemented the appropriate safeguards</a> to protect their users from this type of attacks (it took 3 days from learning about the potential threat for Hotfix deployment).</p>
<p>Now that the whole world knows how to launch this type of attack it may be wise to adjust the privacy settings of your browsers so that your browsing history is either not recorded or is erased fairly often.  Alternatively, use this plug-in for Firefox – <a href="http://www.safehistory.com/">Stanford SafeHistory</a>.</p>



		<!-- Added by WP-DragToShare-eXtended Plugin -->
		<script type="text/javascript">
			dtsv.dtse_post_124_permalink = 'http://blog.tricerion.com/2010/02/new-attack-reveals-user-identities/';
			dtsv.dtse_post_124_title = 'New attack reveals user identities';
		</script>
		<!-- End of WP-DragToShare-eXtended Plugin -->]]></content:encoded>
			<wfw:commentRss>http://blog.tricerion.com/2010/02/new-attack-reveals-user-identities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Phishing is Phutile!</title>
		<link>http://blog.tricerion.com/2010/02/phishing-is-phutile/</link>
		<comments>http://blog.tricerion.com/2010/02/phishing-is-phutile/#comments</comments>
		<pubDate>Fri, 19 Feb 2010 18:03:07 +0000</pubDate>
		<dc:creator>Kathy</dc:creator>
				<category><![CDATA[Cyberthieves]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[strong authentication]]></category>

		<guid isPermaLink="false">http://blog.tricerion.com/?p=121</guid>
		<description><![CDATA[I was in a conversation this week with someone else in the online security space and I happened to mention that I think Tricerion&#8217;s Safe Login is pretty darn sweet. He was a proponent of a keyfob token that additionally used a USB chord and a card too. Yikes. That&#8217;s too complicated for me. In [...]]]></description>
			<content:encoded><![CDATA[<p>I was in a conversation this week with someone else in the online security space and I happened to mention that I think Tricerion&#8217;s Safe Login is pretty darn sweet. He was a proponent of a keyfob token that additionally used a USB chord and a card too. Yikes. That&#8217;s too complicated for me. In the course of our conversation he told me that Tricerion&#8217;s system is very user-friendly and elegant for enterprises, but&#8230; (so he said) it doesn&#8217;t protect against trojans or malware. WHAT?</p>
<p>Ahem. I&#8217;m here to clear up that awful myth that Tricerion strong mutual authentication is less secure than those irritating tokens. So here it is folks, the cold, hard facts.</p>
<p>Malware and trojans are all about stealing passwords. They steal them by capturing typed in passwords and login names. With Safe Login, passwords are never typed in &#8211; they&#8217;re entered on an on-screen keyboard using the mouse to select either alphanumeric characters or pictures that make up a password. To malware, it&#8217;s like grasping at air &#8211; there&#8217;s nothing for them to catch.</p>
<p>What makes Safe Login even more special is that it anticipates and protects against something that has never happened. See, virtually every (secure) login everywhere is protected by 128-bit encryption. No one has figured out how to crack it, but that doesn&#8217;t mean hackers aren&#8217;t trying. And if someone did crack it, the world would be their oyster. They&#8217;d have all logins and passwords in open text, able to hack just about anything, anywhere. Tricerion has this really elegant, intuitive system that separates data streams, so that if SSL 128-bit encryption were ever cracked, anyone using Tricerion&#8217;s system would be protected.</p>
<p><img class="alignnone dtse-img dtse-post-121" title="phishing is futile" src="http://www.safelogin.co.uk/images/trialogue.gif" alt="phishing is phutile" width="371" height="309" /></p>



		<!-- Added by WP-DragToShare-eXtended Plugin -->
		<script type="text/javascript">
			dtsv.dtse_post_121_permalink = 'http://blog.tricerion.com/2010/02/phishing-is-phutile/';
			dtsv.dtse_post_121_title = 'Phishing is Phutile!';
		</script>
		<!-- End of WP-DragToShare-eXtended Plugin -->]]></content:encoded>
			<wfw:commentRss>http://blog.tricerion.com/2010/02/phishing-is-phutile/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

