Tuesday, January 4, 2022

The Future of Cyber Attacks

The Future of Cyber Attacks

The need for cybersecurity has existed ever since the emergence of the first computer virus. The ‘creeper virus’ was created in 1971 and could duplicate itself across computers. Also, the threat landscape is emerging with the evolution of new technologies such as AI, Immersive Experience, Voice Economy, Cloud computing, and others. Threat actors upgrade their tools and tactics by designing new strategies to perpetrate their nefarious aims.

Cyberthreats are growing in both scale and complexity, and the need to secure critical infrastructure by businesses and public organizations has never been as urgent as now.

This article examined how cyberattacks have evolved in the past 12 months, the big lessons, what threats will look like in the future, and strategies companies can deploy to secure their endpoints and data against cyberattacks.

Key Cyberattacks in the last 12 months

1. Phishing attack in the era of Covid-19

Threat actors send a message to deceive people into downloading or clicking a malicious link. During the Great Lockdown of 2020, many people were working from home. Cybercriminals leverage this opportunity as businesses and communication entirely depend on the internet. A report by the FBI revealed phishing to be the most popular form of cybercrime in 2020, and the incident reported nearly doubled ( 241,324) what was recorded in 2019, which was 114,702.

2. The Notorious Ransomware Attack

The ransomware attack was profitable for threat actors in the last 12 months. Ransomware locks files on the victims’ system and redirects them to a page to pay a ransom to have their files returned. A notable example was the Cyrat ransomware which was masked as software for fixing corrupted DLL files on a computer system. According to Reuters, over 1500 businesses have been affected so far.

3. Attacks on IoT and IIoT

The adoption of the Internet of Things(IoT) and the Industrial Internet of Things at both the individual and industrial levels also leads to concerns around cybersecurity. These connected devices make our lives easier, and when not properly configured and secured, they could also leak our sensitive data to the bad guys.

In 2020, an IoT botnet employed vulnerable access control systems in office buildings. As a result, someone accessing the building by swiping a keycard may be ignorant that the system has been infected.

4. Password Compromise

A security survey conducted by Google revealed that about 52% of people reuse passwords across different sites. It means a cybercriminal can successfully access all accounts by breaching a single account. As a result, password attacks remain a top attack vector for most organizations. In the same survey, 42% of the people ticked security breaches due to a password compromise.

A notable example was a list of leaked passwords found on a hacker forum. It was said to be the most extensive collection of all time. About 100GB text file which includes 8.4 billion passwords collated from past data breaches.

You can type your details in https://bit.ly/3zqlSL6 to know if your email or password has been breached.

5. Identity Theft

Cases of Theft doubled from 2019 to 2020 based on a report by the Federal Trade Commission of the United States. The commission received around 1.400.000 cases. Most cases include threat actors targeting individuals affected by the pandemic financially. Cybercriminals also leveraged the unemployment benefits reserved for those affected by the pandemic. The fraudsters claimed these benefits using information stolen from thousands of people. Suppose we merge this with what recently occurred on Facebook and Linkedin, where users’ data were scraped off public APIs by malicious actors. In that case, one could imagine how privacy is becoming a subject of concern for both individuals and companies.

6. Insider Threat

Insider Threat is a form of attack that is not as popular as others yet affects both small and big businesses. Anyone familiar with a company’s internal operations and structure can be a suspect. A Verizon report of 2019 revealed about 57% of database breaches are caused by insiders.

One of the best approaches to limiting the impact of this threat is restricting the privileges of staff to critical areas.

What Are The Lessons From The Biggest Cyberattack?

The attacks mentioned above and others have consequences and lessons to avoid a repeat. Let’s explore some of them:

1. There’s nothing new about the threats

There was a similar attack like Wannacry, which affected Sony in 2014. With regular patching and firewall, organizations can still prevent infiltration or exploitation.  Interestingly, the actual patch of the vulnerability exploited by Wannacry was released two months before the event, but many organizations failed to patch it. Those who did not patch had their critical infrastructures impacted by the attacks.

2. Several organizations are unbelievably vulnerable

NotPetya cyberthreat exploited Microsoft vulnerability (SMB-1) by targeting businesses that failed to patch. As a result, organizations have to develop cyber-resilience against attacks by constantly downloading and installing patches across their systems.

3. Prioritize Data Backup

Even if you lose your critical data to a ransomware attack, a backup will help you keep your operations running. Therefore, organizations must back up their data outside of the network.

4. Develop an Incident Response Plan

Proactive response to incidents and reporting enabled most companies to halt the spread of Wannacry even before the incident. Regulators expect companies to issue warnings within 72 hours or get penalized.

5. Paying Ransom only create an opportunity for more attacks

While it is easier to pay the ransom with the expectation of having your files restored, as long as the communication link is maintained, the threat actors will always come back. Also, it is like empowering them to continue the chain of attacks.

What Would Cyberattacks Look Like In The Future?

Cybersecurity experts predicted the financial damages caused by cyber threats to reach $6 trillion by the end of 2021.  Cyber Attack incidents are also expected to occur every 11 seconds in 2021. It was 19 seconds in 2019 and 40 seconds in 2016. In the future, we would have cyberattacks possibly happening every second. As a result, we would see a surge in frequency and significant financial damages to victims.

Deepfake and Synthetic Voices

Deepfake trended in 2019 as threat actors innovate means of improving their tools and technologies for malicious and entertaining purposes such as illegal pornography featuring. In the future, cybercriminals will call into customer call centers leveraging synthetic voices to decipher whether organizations have the tools and technologies to detect their operations. One of the major sectors that will be targeted will be the banking sector.

Conversational Economy Breach

As companies begin to deploy voice technology and individuals adopt digital assistant technologies like Alexa and Siri, fraudsters will also not relent in discovering the potential opportunities locked up in the voice economy. According to Pin Drop Statistics, 90 voice attacks took place each minute in the United States. 1 out of 796 calls to the call center was malicious. Now that we are all migrating to Clubhouse, we should also expect voice data breaches around voice-based applications.

Some challenges companies would have to deal with include protecting voice interaction, privacy concerns, and supporting call centers with tools and solutions for detecting and preventing fraud.

Security Cam Video Data Breach

In March 2021, Bloomberg reported a breach of surveillance camera data. The breach gave the hackers access to live feeds of over 150,000 security cameras located in companies, hospitals, prisons, police departments, and schools. Major companies that were affected include Cloudflare Inc. and Tesla Inc. Not only that, the hackers were able to view live feeds from psychiatric hospitals, women’s health clinics, and offices of Verkada. These Silicon Valley Startup sourcing data led to the breach.

This scenario paints a vivid picture of what a security cam video data breach looks like and the consequences- privacy breach.

Apple/Google Pay Fraud

Cybercriminals are utilizing stolen credit cards to purchase via Google and Apple pay. Recently, over 500, 000 former Google+ users had their data leaked to external developers. Google offered to pay US$7.5m in a settlement to address a class-action lawsuit against it.

3 Things To Do To Stay Protected

If you are concerned about the growing rates at which these cyber-attacks occur, here are three important things you can do:

Secure Your Hardware

While it is exciting to acquire the latest equipment, securing them with the best cyber threat prevention measures is also essential. For instance, you can use a complex password and reset the default passwords established by the hardware manufacturers. After setting up a password, it is also essential to set up two-factor authentication as an additional security layer. You can also use strong endpoint security tools to secure your systems and network.

Encrypt and Backup Your Data

A formidable cyberthreat prevention measure incorporates two elements: Blocking access to confidential data and rendering the data useless peradventure it falls into the hand of cybercriminals. The latter can be actualized by encrypting the data. Encryption is one of the best solutions to protect against data breaches. Ensure you encrypt your customer information, employee information, and other essential business data.

Educate Your Employees

While banning your staff can be a security measure five years ago, the pandemic and the adoption of remote working have necessitated the “bring your own device(BYOD) approach. And security has to be fashioned in the light of this new development. One best way to achieve this is to plan a simulation on detecting and avoiding phishing links and fake websites.

It is also vital to foster a security culture in the workplace. For example, “If you see something —  say something.”

Conclusion

As new technologies continue to emerge, so will the sophistication of cyberattacks be. Trends such as hackers snooping on a conversation with Siri, Alexa will increase significantly. They can manipulate IoT devices and recruit them into an army of weaponized bots to take critical assets down, or shut down smart homes and cities. Threat actors can also leverage deep fake technology and synthetic voices in social engineering and various scams.

Thus, enterprises that want to stay protected always need to prioritize their people’s cybersecurity, data, and infrastructure.


Originally published at ReadWrite

The Future of Cyber Attacks – ReadWrite
Cyberthreats are growing in both scale and complexity and the need to secure critical infrastructure by businesses and public organizations has never been as urgent as now.
The Future of Cyber Attacks

https://bit.ly/3qL9bH8
https://bit.ly/3pPV5VE


https://guptadeepak.com/content/images/2021/12/Cyber-Attack-825x500.jpg
https://deepakguptaplus.wordpress.com/2022/01/04/the-future-of-cyber-attacks/

Thursday, December 30, 2021

3 Steps to Maintain Total Data Visibility

3 Steps to Maintain Total Data Visibility

We live in an era where data is progressively becoming the essential and the only fuel for thriving business success. And the rapidly growing volumes of data have raised several security concerns that can’t be overlooked. Though managing the in-house data stored locally wasn’t really a tough nut to crack, cloud computing has made data visibility and monitoring a more significant dilemma.

Undoubtedly, cloud monitoring is trickier than monitoring local data centers and private cloud environments, since the sheer volume of data from diverse sources can’t be easily monitored to derive valuable insights.

Hence, today’s security leaders should put their best foot forward to improve data security and enhance overall efficiency by following best data visibility practices. Let’s have a look at some of these fruitful practices.

What Is Data Visibility? Why Is It Important?

Before we inch towards understanding the aspects of data visibility best practices, let’s first understand what data visibility is.

Data visibility can be defined as the ease of monitoring, analyzing, and displaying data from different sources. Gaining data visibility within an organization is quite beneficial for multiple reasons since the gathered data can be easily used to make more informed business decisions.

Moreover, data visibility helps organizations improve capacity planning and identify the risks associated with data thefts and security breaches.

Apart from this, data visibility and monitoring also help remove network performance-related issues that further prevent application outages.

How to Maintain Total Data Visibility in Your Organization

Now that we understand what data visibility is and what its significance is, let’s look at three ways to maintain data visibility of business data.

1. Real-Time Data Reporting

Most legacy systems and programs are designed to deliver monthly or annual reports that offer valuable insights regarding the performance of the data stored in diverse areas.

However, reporting and analytics should be real-time since your business collects, processes, and stores data in real time.

A reliable analytics system can be deployed on your cloud servers to monitor data storage and provide real-time details related to data access to ensure your data isn’t in the wrong hands.

Once a business has complete control over data stored in different areas, it helps create winning strategies to ensure that consumer data is secure and organized.

2. Robust System

Admit it: The more users, the more data storage there will be, and hence the slower the systems will be.

The market is flooded with several reporting systems that work flawlessly for multiple users, but there’s a catch. Most of them weren’t designed in a way to meet the ever-surging needs of enterprises.

So, the need for a robust system increases quickly. Businesses must consider deploying a modern data analytics solution that seamlessly accommodates company-wide use systems and multiple end-user devices, including mobile, tablets, and laptops.

This would surely help in fetching better insights from data without hampering the overall user experience since the system is designed to scale even if the demand increases automatically.

3. Third-Party Tools

Unlike in-house deployment, enterprises can leverage third-party tools that can offer the deepest data visibility, which helps information security professionals to track every movement of their sensitive data, including business information and consumers’ details.

A number of tools can help organizations secure and monitor data stored on local servers or in the cloud and eventually report the IT administrators regarding any unauthorized access or movement of data in real time.

Moreover, these tools also offer protection against malware and other malicious attacks to ensure the highest level of security.

Final Thoughts

In a digitally advanced world where security breaches are becoming more common and sensitive information is being distributed across multiple servers, total visibility over the enterprise’s data becomes the need of the hour.

Since a small loophole may compromise crucial information, businesses should immediately consider choosing a reliable system or third-party tool that keeps track of data stored in diverse locations.

The ones relying on robust security systems can always ensure maximum security for their consumer data and their organization’s critical information.

The aspects mentioned above can help businesses secure their data and ensure their sensitive information isn’t compromised during storage and transit.


Originally published at Dataversity

3 Steps to Maintain Total Data Visibility – DATAVERSITY
Maintaining data visibility should be the biggest priority for any business embarking on a journey to secure data storage for the cloud.
3 Steps to Maintain Total Data Visibility

https://bit.ly/3mLQnWT
https://bit.ly/3FJDynm


https://guptadeepak.com/content/images/2021/12/AdobeStock_321999244.jpeg
https://deepakguptaplus.wordpress.com/2021/12/30/3-steps-to-maintain-total-data-visibility/

Wednesday, December 29, 2021

In-Store Tracking: Is It A Threat To Consumer Privacy?

In-Store Tracking: Is It A Threat To Consumer Privacy?

The amount of data/information collected by retailers is anticipated to surpass 175 zettabytes by 2025, according to Deloitte. With this much data being collected, the complications from even a fraction of this data and information being leaked or compromised by cybercriminals are severe.

Today, cybercrimes have increased to unprecedented levels. As digital crimes surpass a 600% increase, Deloitte warned that a single security incident that exposes even 5% of a retailer's data and information could result in complications such as $5 billion to $10 billion in civil fines apart from recovery costs and any other legal complications, in accordance with the CCPA. Retailers must implement safe data-collection measures that do not violate shoppers' privacy and do not pose any implications in the case of a data breach.

Implications Of Using In-Store Tracking Platforms

The tracking of retail shoppers is increasing at a rapid pace as retailers continue to leverage advanced tracking and monitoring technologies to record and study the behaviors of shoppers. Face analysis software, in-store high-tech cameras and sensors equipped with facial recognition technologies, as well as smart tracking systems that capture the voices of shoppers and track their geo-locations are some of the methods by which major retailers are capturing and tracking consumer behavior analytics and data.

Retailers using such tracking technologies to capture consumers' data usually justify the in-store customer tracking and data/information collection by giving reasons like:

• Learning more about the needs and wants of the shoppers.

• Understanding the behaviors of shoppers in order to develop more personalized and intimate relationships with them.

• Tailoring a customized/individualized shopping experience according to the preferences of each shopper.

• Enhancing the service delivery experience.

• Making the store operations more efficient.

In-store data and information collection may benefit retailers in many ways. However, the growing consumer privacy concerns as well as tightening privacy laws and regulations are posing a myriad of complications for retailers. A past Forrester survey that Quartz referenced (subscription required) revealed that roughly half of the respondents reported they would discontinue shopping in stores that track their behaviors. Deloitte also found that 55% of shoppers believe that retail stores are selling their data/information to third parties. The study also revealed that not all shoppers are tech-savvy and understand how retail stores use advanced technologies to track their behaviors and collect their data. This results in violating many data/privacy laws and regulations, as the collection of some data and information requires the consent of the individuals.

Many retailers also lack transparency about what type and how much data and information is being collected from shoppers and how it is being used. Lack of privacy policies, personalized marketing and notifications, lack of data/information usage transparency and other similar aspects can cause many implications for retailers.

Examples of such implications can include:

• Loss of customers' trust.

• Declining in-store shoppers' rate.

• Loss of revenue.

• Legal complications and fines by regulatory authorities.

• Reputation damage.

Key Data And Privacy Tips For Safer Data Collection

Retailers need to implement a comprehensive data protection strategy that includes appointing internal cybersecurity representatives, training employees across departments, vetting third-party partners, safely transferring data and deleting unnecessary consumer data. Here are some key tips for retailers to implement safer data collection.

• Secure payment methods. Setting standards and conventions for payment methods and third-party suppliers is essential for businesses. Due to the fact that customer payment information is regularly the target of data breaches in the retail business, retail firms are implementing more secure payment systems.

• Default encryption in transit and at rest. Data in transit, such as between a server and a mobile phone, is vulnerable to retail security hazards. Using data encryption, the data is protected while traveling and can only be decrypted at the endpoint with the decryption key. A delicate balance must be struck between privacy and simplicity of use while using encrypted data.

• Mandatory security training. Employees might also be the source of a data breach. Security training is often lacking in the workplace due to carelessness in the handling of sensitive data, team member incompetence and/or laziness. Customers' credit card data should likewise be restricted to employees, and employees should not be providing financial information via email. Additionally, corporations need to incorporate cybersecurity awareness into the culture of their organizations in order to avoid common threats like phishing emails.

• Enforce zero-trust security. Employees need to be verified, authorized and continuously evaluated for security configuration and posture before being permitted access to apps and data. As a result, a zero-trust architecture necessitates constant user and device monitoring and verification to ensure that the proper privileges and attributes are being used. Aside from that, retailers must periodically check on their staff members regarding how they handle file data and avoid malware. Moreover, employees should have limited access to websites outside of their everyday activities in order to reduce the risk of allowing a hacker to gain access.

As data/privacy laws and regulations become more strict and consumer-focused, retailers must implement fair and anonymous modes of data/information collection that do not raise privacy concerns and do not creep out the shoppers. Today's internet users are more aware and concerned about their data and privacy; therefore, retailers must respect shoppers' privacy and must cultivate a data-safe environment to boost business profitability and consumer loyalty.


Originally published at Forbes

Council Post: In-Store Tracking: Is It A Threat To Consumer Privacy?
The tracking of retail shoppers is increasing at a rapid pace.
In-Store Tracking: Is It A Threat To Consumer Privacy?

https://bit.ly/3pA7GMv
https://bit.ly/348gkJV


https://guptadeepak.com/content/images/2021/12/https---specials-images.forbesimg.com-imageserve-61af659747abf8fcb93e57db-3d-rendering-Neon-Colored-wavy-Abstract-background--futuristic-texture-design-for-960x0.jpg-fit-scale-1.jpeg
https://deepakguptaplus.wordpress.com/2021/12/29/in-store-tracking-is-it-a-threat-to-consumer-privacy/

Cookie-based vs. Cookieless Authentication: What’s the Future?

Cookie-based vs. Cookieless Authentication: What’s the Future?

Securing communications between a client and a server often requires credentials to identify both parties. That is where the different authentication techniques comes in. Two popular authentication methods are cookie-based and cookieless authentication. However, choosing any one of them depends on the organization's requirements. Both come with their benefits and challenges. This article will give a quick walkthrough of cookie-based and cookieless authentication along with their advantages and disadvantages.

Cookies are pieces of data used to identify the user and their preferences. The browser returns the cookie to the server every time the page is requested. Specific cookies like HTTP cookies are used to perform cookie-based authentication to maintain the session for each user.

The entire cookie-based authentication works in the following manner:

  1. The user gives a username and password at the time of login. Once the user fills in the login form, the browser (client) sends a login request to the server.

The server verifies the user by querying the user data. If the authentication request is valid, the server generates the following:

  • A session by utilizing the user information
  • A unique ID, known as the session IDThe server then passes the session ID to the browser that keeps it. The server also keeps track of the active sessions.
  1. The browser has to submit this generated session ID while sending a subsequent request. Every time the server validates the session ID. The session ID helps the authentication process identify the user and provides access accordingly.
  2. When the user logs out of the application, the session gets destroyed from both client (browser) and the server. It discontinues the authentication process from happening again through the respective session ID.
  • Availability: In cookies-based authentication, cookies can be made available for an extended period, maintaining a session for a long time.
  • Easy Configuration: Websites can deliver cookies by configuring them as per requirement. For example, a website can send cookies that will expire as the users close the browser tab. It is also possible to configure cookies for a specified length of time on the client-side.
  • User-friendly: Cookie-based authentications are simple, and the cookies used in this method are user-friendly. Users can choose what to do with cookie files that have kept user credentials. All modern browsers come with settings to clear the cookies. Users can find cookies in the hard drive and delete them manually.
  • Vulnerable to CSRF: Cookie-based authentications are prone to Cross-site Request Forgery (CSRF) attacks. Hence, they often require additional security postures for protection.
  • Less Mobile-friendly: Cookie-based authentication does not work well with all native applications.
  • Limitations: There are certain limitations and concerns such as size limit (not more than 4KB of information per cookie), browser limitations on cookies, user privacy, etc., come with cookies and cookie-based authentication.
  • Less Scalable: Cookie-based authentication is less scalable, and the overhead rises when the user count increases on a particular site.

What is Cookieless Authentication?

Cookieless authentication, also known as token-based authentication, is a technique that leverages JSON web tokens (JWT) instead of cookies to authenticate a user. It uses a protocol that creates encrypted security tokens. These tokens allow the user to verify their identity. In return, the users receive a unique access token to perform the authentication. The token contains information about user identities and transmits it securely between the server and client. The entire cookieless authentication works in the following manner:

  1. The user logs into the service by providing their login credentials. It issues an access request from the client-side by sending the credential and API key (public key) to the application server.
  2. The server verifies the login credentials that checks the password entered against the username. Once approved, the server will generate a unique session token that will help authorize subsequent actions.
  3. This access token is sent back to the client via URL query strings, post request body, or other means. The server-generated signed authentication token gets assigned with an expiration time.
  4. The token gets transmitted back to the user's browser. On every subsequent request to the application server or future website visits, the access token gets added to the authorization header along with the public key. If there is a match from the application server against the private key, the user can proceed. If a given token expires, a new token gets generated as an authentication request.

Benefits of Cookieless Authentication

  • Scalable and Efficient: In cookieless authentication, the tokens remain stored on the user's end. The server only needs to sign the authentication token once on successful login. That makes the entire technique scalable and allows maintaining more users on an application at once without any hassle.
  • Better Performance: Cookie-based authentication requires the server to perform an authentication lookup every time the user requests a page. You can eliminate the round-trips with tokens through the cookieless authentication technique. In cookieless authentication, the access token and the public key are added to the authorization header on every page request.
  • Robust Security: Since cookieless authentication leverages tokens like JWT (stateless), only a private key (used to create the authentication token) can validate it when received at the server-side.
  • Seamless Across Devices: Cookieless authentication works well with all native applications. Tokens are much easier to implement on iOS, Android, IoT devices, and distributed systems, making the authentication system seamless.
  • Expiration Time: Usually, tokens get generated with an expiration time, after which they become invalid. Then a new token needs to be obtained for reauthentication. If a token gets leaked, the potential damage becomes much smaller due to its short lifespan.

Challenges with Cookieless Authentication

  • Single-key Token: One of the significant challenges with cookieless authentication is that these access tokens rely on just one key. Tokens that use JWT leverages a single key for authentication. If the developers/administrators handle the key poorly, it can lead to severe consequences that can compromise sensitive information.
  • Data Overhead: Storing a lot of data increases the overall size of the token. It slows down the request impacting the overall loading speed. This slowing down ultimately hampers the user experience. Thus proper development practices need to be followed, regulating minimum but essential data into the token.
  • Vulnerable to XSS and CSRF: Cookieless authentications are susceptible to XSS and CSRF attacks. So, the best practice is to have a short expiration time for access tokens. Keeping a longer expiration time might allow the attackers to hijack the access token and use it to gain unauthorized authentication.

How does LoginRadius have Native Support for Cookieless Authentication?

LoginRadius provides multiple methods to implement a cookieless login workflow leveraging industry and security best practices. As a consumer-centric Identity platform, LoginRadius ensures that modern implementation methodologies comply with the changing security landscape. The cookieless authentication workflows detailed below are systems that LoginRadius has developed support for even before the recent browser-based privacy policies and are a core part of the LoginRadius platform.

LoginRadius APIs

The LoginRadius API has been architected and designed to function as a cookieless authentication system. Once authentication occurs, a session token gets returned to the requesting client in the form of an access token which can be leveraged to take further authorized actions against the Consumer account. It is a core part of the LoginRadius authentication workflows, and APIs developed based on Oauth 2.0 protocols.

These APIs provide flexibility in generating access tokens based on consumer authentication requests and are automatically validated and signed leveraging the LoginRadius API Key and Secret. Detailed API documentation is available here.

JSON Web Tokens

In addition to the LoginRadius APIs, JWTs are a standard method to handle cookieless login. Once authentication is completed and verified, a signed token can be generated(leveraging LoginRadius APIs) to pass the consumer session to the client.

JWTs are a standard industry mechanism leveraged by various service providers and tools, making them ideal for interoperability with multiple applications. Find additional details on how to use JWT as part of your authentication workflows here.

Additional Options

In addition to the above two options, LoginRadius provides flexibility and support for various authentication and authorization standards that support a cookieless authentication approach. Outbound authentication workflows such as OIDC and Oauth 2.0 allow for a modern standardized approach to authentication.

These are industry-recognized and recommended authentication and authorization protocols that comply with security and privacy best practices, including supporting a cookieless authentication approach. Check out our dedicated documentation on outbound workflows.

Conclusion

Cookieless authentication can facilitate more secure and scalable authentication. You should decide how to authenticate consumers considering your requirements and the benefits and challenges of cookie-based and cookieless authentication.


Originally published at LoginRadius

Cookie-based vs. Cookieless Authentication: What’s the Future?
Understand how cookie-based and cookieless authentication methods work. And learn their major differences, advantages, and disadvantages.
Cookie-based vs. Cookieless Authentication: What’s the Future?

https://bit.ly/3pzQWF0
https://bit.ly/3eyPsoi


https://guptadeepak.com/content/images/2021/12/coverImage-1.png
https://deepakguptaplus.wordpress.com/2021/12/29/cookie-based-vs-cookieless-authentication-whats-the-future/

Tuesday, December 28, 2021

Understanding PII Compliance: A Key to Enterprise Data Security

Understanding PII Compliance: A Key to Enterprise Data Security

When you visit a website, it may store some basic information about you, such as your IP address, the operating system on your computer, the browser you use, ISP used to connect, location, screen resolution, etc. Some websites store login cookies on your computer, so you don't have to log in every time you visit them.

But this is not all. When browsing online, you also leave enough breadcrumbs for websites and web applications to identify you.

We often talk about personally identifiable information (PII), but few users know precisely what it is.

Besides, there are many ways to manage personal information. Having said that, it is one thing when you protect your PII from potential exploitation, and it's entirely different when a third party manages it for you.

So, let us take a deep dive to discover the term personally identifiable information or PII.

What is Personally Identifiable Information

Data that helps identify a specific individual is called personally identifiable information, or PII in short. For example, your social security number is a good example of** **PII Compliance because it is unique, and the number itself will lead someone to find you directly.

In addition to this, your full name, driver's license ID, email address, bank account information, password, or phone number can also be considered personally identifiable information.

PII has a principal role in network security, especially when it comes to data breaches and identity theft. For example, if a company that manages personal information encounters a data breach, its customers will likely suffer personal identity theft because the company-managed data will be stolen.

The information related to this is stored with online marketers and brokers who trade your data to various companies that "want to show you appropriate ads" and provide you with an "improved user experience."

Key takeaways

  • Personally identifiable information (PII) can identify a person when used alone or with other relevant data.
  • Confidential identifying information can include your full name, social security number, driver's license, financial information, and medical records.
  • Non-confidential personally identifiable information is easily accessible from public sources and may include your zip code, race, gender, and date of birth.

Importance of PII Compliance

Advanced technology platforms have changed the way companies operate, government legislation, and personal contact. With the help of digital tools such as mobile phones, the Internet, e-commerce, and social media, the supply of all kinds of data has surged.

Such data is collected, analyzed, and processed by enterprises and shared with other companies. The large amount of information enables companies to gain insights into how to better interact with customers.

However, the emergence of big data has also increased the number of data breaches and cyberattacks by entities that realize the value of this information. As a result, people are concerned about how companies handle sensitive information about their customers. Regulators are seeking new laws to protect consumer data, and users are looking for more anonymous ways to stay digital.

Protection of Personally Identifiable Information

Many countries/regions have adopted multiple data protection laws like the GDPR, CCPA to create guidelines for companies collecting, storing, and sharing customers' personal information. Some basic principles outlined in these laws stipulate that certain sensitive information should not be collected except in extreme circumstances.

In addition, the regulatory guidelines also stipulate that if the data is no longer needed for its intended purpose, it should be deleted, and personal information should not be shared with sources whose protection cannot be guaranteed. Moreover, supervision and protection of personally identifiable information may become a significant issue for individuals, companies, and governments in the coming years.

Selling the stolen data

Cybercriminals compromise data systems to access PII and then sell it to buyers willing to buy in the underground digital market. For example, the Internal Revenue Service (IRS) in the US suffered a data breach that resulted in the theft of the personally identifiable information of more than 100,000 taxpayers. Criminals used quasi-information stolen from multiple sources to access the IRS website application by answering personal verification questions that should belong only to taxpayers.

Adopting PII compliance

Without considering the type or size of any company, all organizations must have some detailed and comprehensive knowledge of PII compliance it collects and how it can be utilized. The companies must have legal knowledge about which among the various country and state regulations related to PII is applied to some specific situation related to them. Also, it is important to consider that adopting acceptable use of privacy policies associated with this particular data can be advantageous.

Conclusion

The security of personal identity and other details is at increasing risk today, with hackers finding new ways to hack into websites. Therefore, enterprises of all sizes must maintain PII compliance to protect the information of the company and its users. With PII compliance, businesses can maintain improved data security.


Originally Published at LoginRadius

Understanding PII for Enterprise Data Security
PII Compliance is a highly valuable asset for any enterprise that needs to be protected. Read to understand the need for PII compliance in today’s advanced world.
Understanding PII Compliance: A Key to Enterprise Data Security

https://bit.ly/3qs0yAV
https://bit.ly/314Ukyh


https://guptadeepak.com/content/images/2021/12/pii-compliance-enterprise-cover.jpg
https://deepakguptaplus.wordpress.com/2021/12/28/understanding-pii-compliance-a-key-to-enterprise-data-security/

Sunday, December 26, 2021

DNS Cache Poisoning: Why Is It Dangerous for Your Business

What is DNS Cache Poisoning

DNS Cache Poisoning: Why Is It Dangerous for Your Business

DNS cache poisoning, also known as DNS spoofing, is a cyber-attack that exploits the weaknesses in the Domain Name System (DNS) servers. It enables the attacker to poison the data in DNS servers, including your company server, by providing false information to your internet traffic and diverting it to fake servers. This is done by redirecting the data in DNS to their IP address.

DNS cache poisoning utilizes the vulnerabilities in the DNS protocols' security to divert internet traffic away from legitimate servers to the wrong address.

DNS cache poisoning is effectively used for phishing attacks, often referred to as Pharming, for spreading malware. In the background, the malware runs and connects with legitimate servers to steal sensitive information.

When the DNS server is attacked, users may be requested to login into their accounts, and the attacker finds its way to steal the sensitive and financial credentials.

Moreover, phishing attacks also install viruses on the client's computer to exploit the stored data for long-term access.

How Does DNS Cache Poisoning Works

DNS spoofing is a threat that copies the legitimate server destinations to divert the domain's traffic. Ignorant of these attacks, the users are redirected to malicious websites, which results in insensitive and personal data being leaked.

It is a method of attack where your DNS server is tricked into saving a fake DNS entry. This will make the DNS server recall a fake site for you, thereby posing a threat to vital information stored on your server or computer.

The cache poisoning codes are often found in URLs sent through spam emails. These emails are sent to prompt users to click on the URL, which infects their computer.

When the computer is poisoned, it will divert you to a fake IP address that looks like a real thing. This way, the threats are injected into your systems as well.

What Are the Different Stages of Attack of DNS Cache Poisoning

DNS Cache Poisoning: Why Is It Dangerous for Your Business
  • First Stage

The attacker proceeds to send DNS queries to the DNS resolver, which forwards the Root/TLD authoritative DNS server request and awaits an answer.

  • Second Stage

The attacker overloads the DNS with poisoned responses that contain several IP addresses of the malicious website.

To be accepted by the DNS resolver, the attacker's response should match a port number and the query ID field before the DNS response.

Also, the attackers can force its response to increase their chance of success.

  • Third Stage

If you are a legitimate user who queries this DNS resolver, you will get a poisoned response from the cache, and you will be automatically redirected to the malicious website.

How to Detect DNS Cache Poisoning

Now that we know what is DNS cache poisoning let's understand how to detect it.

One way is to monitor the DNS server for any change in behavior patterns. Also, you can apply data security to DNS monitoring.

Another way is to look for a potential birthday attack. This occurs when there is a sudden increase in DNS activity from a single source in a single domain. When there is an increase in the DNS activity from a single source, querying your DNS server for multiple domain names without recurring shows that the attacker is looking for a DNS entry for poisoning.

Monitor the file system behavior and active directory events for any abnormal activities. You can use analytics for correlating activities among three vectors to add important information to your cybersecurity strategy.

Why Is DNS Cache Poisoning Dangerous for Your Business

When the DNS server is poisoned, it will start spreading towards other DNS servers and home routers. Computers that lookup DNS entries will get the wrong response by causing more users to end up as victims of DNS poisoning.

This issue will be resolved only when the poisoned DNS cache is cleared on each affected DNS server; you are at risk of losing your precious information until then.

One of the major reasons DNS cache poisoning is highly dangerous is that it can spread from one DNS server to another.

Here are a few DNS poisoning attack examples-

A DNS poisoning event had resulted in the Great Firewall of China's temporary escape from China's national borders by censoring the internet in the USA till the problem was resolved.

Recently, attackers targeted WikiLeaks, who used a DNS Cache poisoning attack for hijacking traffic to their WikiLeaks-like version. This intentional attack was created to divert the traffic away from WikiLeaks and was implemented successfully.

How To Protect Against DNS Cache Poisoning

For DNS server providers and website owners

If you are a DNS service provider or a website owner, you have a huge responsibility for safeguarding your users by using various tools and protocols to manage the threats.

Some of the resources we have specified will help you in this regard.

  • Just like endpoint user security products, you can proactively use DNS spoofing detection tools to scan before you send or receive the data.
  • Using DNSSEC (Domain Name System Security Extensions) helps to keep DNS lookup fool-proof and authentic.
  • You can use end-to-end encryption to send DNS requests and replies. Hackers will not be able to duplicate the unique security certificate that is present on the legitimate website.

For endpoint users

To avoid making your users vulnerable to a DNS poisoning attack, you can use the specified tips.

  • Do not click on the links that you don't recognize; these include text messages, emails, or social media links. To be safe, you can opt for entering the URL manually in the address bar.
  • Regularly scan your computer for any malware. Your security software will help and remove any secondary infections. As the poisoned sites deliver malicious programs, you need to scan for spyware, viruses, or any other hidden issues.
  • Flush your DNS cache to solve the problem of poisoning. Nevertheless, cache poisoning remains in your system for a long time until you clean the infected area.
  • Use the virtual private network (VPN), a service that offers an encrypted tunnel for your web traffic. You can use a private DNS service exclusively for end-to-end encrypted requests; as a result, your servers are tougher against DNS spoofing.

Final Thoughts

DNS cache poisoning can be summarised as an attacker controlling the DNS server to send fake DNS responses. As a result, when the user visits the counterfeit domains, they will be directed to a new IP address selected by the hacker.

This new IP address might be from a malicious phishing website, where the users are prompted to download malware, or they might be asked to provide their financial or login details.

Hence, understanding what is DNS cache poisoning, how to detect it, and ways to prevent it is crucial so you can protect your business against it.


Originally published at LoginRadius

Why DNS Cache Poisoning is Dangerous for Your Business
Read this blog to understand what is dns cache poisoning and what should organizations do to avoid this cyberattack.
DNS Cache Poisoning: Why Is It Dangerous for Your Business

https://bit.ly/3pspZmP
https://bit.ly/3qp6jzx


https://guptadeepak.com/content/images/2021/12/dns-cache-poisoning-is-dangerous-for-your-business.jpeg
https://deepakguptaplus.wordpress.com/2021/12/26/dns-cache-poisoning-why-is-it-dangerous-for-your-business/

How to Set Up Two-factor Authentication on All Your Online Accounts

How to Set Up Two-factor Authentication on All Your Online Accounts

How to set up 2FA on your accounts? And why is it important in the first place? As social media is becoming increasingly popular, security is becoming something of supreme importance.

Even though choosing a strong password helps you in certain ways, by adopting 2FA, you can improve and enhance security further. So, let's know more about this extra layer of protection and how to set up 2FA on your accounts.

First stop.

What is Two-Factor Authentication

2FA is one of the best security methods that use two layers to verify a consumer's identity. This means, rather than simply entering the password to log into an account, two-factor authentication requires a code to be sent via text message to the consumer's phone number or generated through an app.

This type of verification code helps and ensures that only the authorized consumer can access their account. Similarly, multi-factor authentication (MFA) offers two or more authentication layers to approve account access for consumers.

What is Authenticator Apps

Authenticator apps are meant to be installed on your smartphones to obtain passcodes to sign in to your accounts. They are intended to be more secure than texting; they provide flexibility if you are traveling to a place where there is no mobile service.

Some of the options include Google Authenticator, Microsoft Authenticator Authy, or HDE OTP.

All these apps follow the same procedure – when you are adding a new user account, you need to scan a QR code associated with the account, and it is saved in the app.

The next time you sign in to your app or service, it will ask for a numerical code. You need to open up the authenticator app and check the randomly generated authentication code to access your account securely.

How to Set up 2FA on Your Social Media Accounts

How to Set Up Two-factor Authentication on All Your Online Accounts

A lot of applications offer 2FA currently, especially if you are storing important and sensitive data, financial information, emails, social media, files, contact details, etc.

2FA needs more than one factor to login. This might include parameters like "something you are," for example, biometrics in the form of iris scan or fingerprints, "something you know," a password, and "something you have," like a smartphone or hardware key.

Find out how to set up 2FA on your accounts:

1. Google

If you want to set up an authenticator on the Google account, first you need to download the Google Authenticator app available on the Play Store. Once downloaded, do the following:

  • Go to Gmail and click the profile icon.
  • Choose My account and click on Sign-in & Security.

You can add the two-step verification process here.

How to Set Up Two-factor Authentication on All Your Online Accounts

Source: Google

2. Snapchat

To set up 2FA on your Snapchat account, you will need to:

  • Go to the app’s main camera screen and tap on the profile icon.
  • Find the gear icon to access Settings.
  • Tap on Two-Factor Authentication and choose whether to obtain verification via a text message or an authenticator app.

You can add trusted devices or request a recovery code for when you intend to be somewhere without cellular coverage once 2FA has been activated on your Snapchat account. Safety key logins do not currently appear to be supported by Snapchat.

3. Whatsapp

To set up 2FA on your WhatsApp account, you will need to:

  • Open WhatsApp on your device.
  • Under the upper-right hamburger icon, find the Settings menu.
  • Go to Look under Account > Two-step verification > Allow.
  • You will be prompted to end a six-digit PIN to verify your account. If you forget your PIN, you can optionally add an email address.
How to Set Up Two-factor Authentication on All Your Online Accounts

Source: lifewire

It is important to have an associated email with your WhatsApp account as the service will not allow you to reverify yourself if you have used WhatsApp and forgotten your PIN within the last seven days.

4. Outlook

To set up 2FA on your Outlook account, you will need to:

  • Sign in to your Outlook account.
  • Click on your name and then click View Account.
  • Under the Basic Options, click on the link that says Explore more security options.

If you have not set up 2FA yet, you can click on the link and proceed with that. You can switch to Microsoft Authenticator by clicking the Set up identity verification app if you already have it.

5. Facebook

To set up 2FA on your Facebook account, you will need to:

  • Sign in to your Facebook account.
  • Click on Settings and choose Security and Login.
  • Check for the use of two-factor authentication in the Setting Up Extra Security section.
  • Enable the code generator.

You can also use the Facebook mobile app for approving sign-ins on the web or set up a third-party authentication app for generating codes.

How to Set Up Two-factor Authentication on All Your Online Accounts

Source: Facebook

6. Twitter

To set up 2FA on your Twitter account, you will need to:

  • Sign in to your Twitter account.
  • Click on your Profile Icon and then click Settings and Privacy.
  • Click the checkbox next to Verify login requests, under the Security heading.
  • Verify your mobile number and then click Set up a code generator app.
  • Scan the QR code with the third-party authenticator app.
How to Set Up Two-factor Authentication on All Your Online Accounts

7. Apple iCloud

  • You can log in to your account at https://appleid.apple.com/, then search for Two-Factor Authentication under Security.
  • The next step would be to verify your location, and it will send a code to your other Apple devices.
  • iOS

To set up 2FA on your iOS account, the steps will be a bit different. Majorly, it will depend on how you have updated your iOS software.

  • For users using iOS 10.3 or later versions, click on Settings > your Name > Password & Security.
  • You can turn on 2FA to receive a text message with a code every time you log in.

For users using iOS 10.2 or earlier versions, go to Settings under iCloud > Apple ID > Password & Security.

  • macOS

Similar to iOS, a few of the steps may vary depending on the version of macOS.

  • If you are using Catalina, click the Apple icon, then click System Preferences > Apple ID.
  • The next step would be to click on Password & Security under your name and finally click Turn On Two-Factor Authentication.

8. Instagram

In 2017, two-factor authentication was added by Instagram to the mobile app, which can be activated via the web. If you want to activate 2FA on your mobile device, you need to go to Profile and click on the menu and look for Settings & Security. There you will find two-factor authentication.

With Instagram, you also get to choose between SMS-based verification and a code sent to the authentication app.

How to Set Up Two-factor Authentication on All Your Online Accounts

Source: Kaspersky

Why is 2FA important

As cybercriminals are getting smarter, 2FA has become more mandatory than ever. Without it, you might end up leaving your accounts vulnerable to hackers for sealing your personal information, hacking your online credit card details, and accessing your bank account. By adding the additional step to your account, you get the edge to prevent hackers from accessing your account.

Setting Up 2FA with LoginRadius Adaptive 2FA/ MFA solution

How to Set Up Two-factor Authentication on All Your Online Accounts

LoginRadius provides multi-factor authentication via SMS, email, automated phone calls, account security questions, and authenticator apps to allow you a customized user experience.

Based on your business, you can choose to use LoginRadius's Identity Platform's Multi-factor authentication, which is an easy process.

Currently, LoginRadius provides its support authentication methods via SMS workflow and Google Authenticator workflow.

For SMS Workflow

You can enable SMS verification from the LoginRadius admin console. There's also an option to choose your preferred SMS template and SMS provider.

As the first step, you'll need to apply a first verification factor, like standard email and password login, username and password, automated phone call, or access token. The second factor can be a one-time password or code sent via SMS.

Google Authenticator Workflow

For enabling Google Authenticator, the first step will be to set up your ID in the admin console for Google to identify your website or application on the authenticator.

Next, you will need to set up your QR code specifications or make MFA mandatory.

Similar to the SMS workflow, you can select standard email and password login, username, password, automated phone call, or access token as the verification factor.

Final Thoughts

With cybercrimes on the rise, it is essential to make your online security measures more robust. Hence, to protect your account and the history, you need to learn how to set up 2fa on your accounts for an additional safety cover. It not only protects your online social accounts but other accounts as well.


Originally published at LoginRadius

How to Set Up 2FA on All Your Online Accounts
Secure your accounts online by setting up 2FA. Know why two-factor authentication is the best way to securely verify login attempts and prevent data breaches.
How to Set Up Two-factor Authentication on All Your Online Accounts

https://bit.ly/311H3qk
https://bit.ly/3FvbFzu


https://guptadeepak.com/content/images/2021/12/how-to-setup-2fa-online-accounts.jpeg
https://deepakguptaplus.wordpress.com/2021/12/26/how-to-set-up-two-factor-authentication-on-all-your-online-accounts/

Palo Alto Networks + CyberArk: The $25 Billion Deal Reshaping Cybersecurity

Deal Overview Transaction Details : Palo Alto Networks announced on July 30, 2025, its agreement to acquire CyberArk for $45.00 in cash ...