Showing posts with label Data Breach. Show all posts
Showing posts with label Data Breach. Show all posts

Sunday

Breaking up (with Facebook) is hard to do: Here’s how


NEW YORK — Every relationship has a breaking point. Even yours with Facebook.

There’s a way out, though the social network will try to win you back with promises to do better. Maybe even flowers.

For some users, though, the past two years of privacy scandals, election manipulation by Russian trolls, executive apologies and even the political disagreements with friends and relatives have become too much.

The latest: an alarming New York Times report detailing the massive trove of user data that the company has shared with such companies as Apple, Netflix and Amazon.

A growing number of people say they are deleting Facebook, or at least considering it.

While Facebook has tried to address some of these problems, it’s not enough for some users.

Hard as it might seem to quit, especially for those entwined with it for years, it can be done.

Mostly.

Goodbye forever

Before deleting your account, rescue your posts and photos.

Facebook lets you download the data you’ve shared with Facebook since you joined. This includes your posts and photos, as well as the “activity log”—the history of everything you’ve done on Facebook, such as likes and comments on posts, use of apps and searches.

The download also includes your profile, messages, list of friends and ads you’ve clicked on.

This process should give you a good—perhaps scary—idea of what Facebook has on you.

What you won’t get are photos other people shared with you, even if you’ve been tagged. You need to save those individually.

And some stuff will remain, including what others have posted about you, your chats with others and your posts in Facebook groups (though your name will be grayed out).

To delete all this, you’ll need to sift through your “activity log,” accessible through your profile page, and delete each item individually.

Once you’ve saved everything and gone through your activity log, sign in one last time. Go to http://bit.ly/198wIoI and click on the blue button. Facebook says the process could take a few days.

Your delete request will be canceled if you log back in during this time. Facebook says it may take up to 90 days for all the data associated with your account to be wiped, but you can’t change your mind after the first few days are up.

If you used your Facebook account for third-party apps and sites, you’ll need new usernames and passwords for each.

Trial separation

If you’re not quite ready for a divorce, deactivating your account is an option. To do this, go to your account settings.

Deactivating means other people won’t be able to see your profile, but if you log back in, the whole thing is canceled and you are “active” again. Ditto if you log into an outside app or site using your Facebook account.

Fomo (Fear of missing out)

Depending on whether you were a full-time Facebook addict or an occasional lurker, the psychological separation could prove harder or easier than the physical one.

Facebook has become a one-stop shop for so many things. You can keep up with friends and family, find out about or create local events, buy and sell stuff, keep up with the news, raise money for a cause or join groups of like-minded people such as parents, porch gardeners and people with a rare disease.

There are other places to do many of these things. There’s Eventbrite for events, Letgo for buying and selling stuff, Peanut for moms to connect, Meetup to find and meet like-minded people, GoFundMe for raising money and Twitter, or, gasp, your local newspaper’s website for the news.

The difference is there’s no single other place to do all these things, and your friends might not be there.

If you find your mind wandering back to Facebook as you go through your day, thinking how you might craft a post about a thought you’ve just had or an article you came across, it’s OK. Let it go. It’s all part of the breakup process.

And while you may not see updates about near-forgotten schoolmates or that random person you met six years ago, the people who matter most will stick around. For them, there’s e-mail, the phone, and meeting in person for coffee.

About those other apps

If your boycott of Facebook has more to do with your view of the company than with tiring of the Facebook service, you might consider deleting Instagram, WhatsApp and Messenger as well—they are all owned by Facebook.

Deleting your Facebook account won’t affect your Instagram or WhatsApp account. If you want to keep using Messenger, you can create an account using your phone number instead of your Facebook profile.

source: technology.inquirer.net

Friday

The Hidden Costs of Data Breaches and How to Avoid Them


Today’s society has grown all too accustomed to hearing yet another well-known company listed in the headlines as the latest victims of a massive data breach. By the time we hear this news, the company-and often its customers-have already suffered losses. Some of these losses are obvious, like the loss of data stolen by hackers. There are also significant hidden costs of data breaches that were recently calculated as high as $350 million in a July 2018 global study conducted by IBM.

The hidden costs of data breaches include:

Lost business:
While a company is recovering from a data breach, their systems might be down or compromised. Some companies elect to cease operations all together until security can be restored. The cost of this lost business adds up by the second. Most of these breaches stem from a malicious or criminal attach (instead of a glitch or human error) so in addition to repairing the damage, cybersecurity professionals must also shore up the vulnerabilities that allowed the attack to happen in the first place.

Lost time:
While the damage accrues quickly, the process to identify and contain a breach often does not. According to this latest report, companies took an average of 197 to identify a data breach. Once identified, it takes an average of 69 days to contain the breach. If companies were able to contain a breach faster (i.e. in less than 30 days), they saved over $1 million dollars. There’s also the hidden cost of shifting employee resources and time during a breach or containment period. Work and focus on current projects often shuts down as all hands on deck address the crisis. In the cast of a large company, this can also demand an entire marketing campaign to message the results of the breach and company response to customers.

Lost reputation:
The reputational damage caused by a data breach can be the most painful to bear for companies. These costs are often hidden because it’s difficult to capture clients who would have been had they not heard of a company’s breach. Customers also seem to react and respond differently depending on the type of data lost in a breach. In a 2011 study on the impact of data breach on company reputation, most people surveyed were more concerned if their personal, confidential information was lost or stolen compared to their employee files. They also estimated that it would take 8 months to 1 year for a company to recover from the damage caused by a breach. Communicating a breach early, thoroughly, and providing updates to customers were noted as best practices to preserve and regain reputation following a breach.

Recognizing the hidden costs of data loss should provide additional motivation to pursue a dedicated data loss prevention strategy. Whether you own a company or have your data saved by hundreds of companies, we’re all impacted by data breaches. Challenge the companies that you trust your data with to protect it as if it was their own.

source: securedatarecovery.com

Thursday

Zuckerberg says regulation inevitable. Is Congress up to it?


WASHINGTON — Facebook CEO Mark Zuckerberg acknowledged Wednesday that regulation of social media companies is “inevitable” and disclosed that his own personal information has been compromised by malicious outsiders. But after two days of congressional testimony, what seemed clear was how little Congress seems to know about Facebook, much less what to do about it.

House lawmakers aggressively questioned Zuckerberg Wednesday on user data, privacy settings and whether the company is biased against conservatives. As they did in the Senate a day earlier, both Republicans and Democrats suggested that regulation might be needed, but there was no consensus and few specifics about what that might look like — or even what the biggest problems are.

New Jersey Rep. Frank Pallone, the top Democrat on the panel and a 30-year veteran of the House, said at the beginning of the hearing that he plans to work on legislation but is pessimistic that Congress will pass anything.

“I’ve just seen it over and over again — that we have the hearings, and nothing happens,” he said.

For Zuckerberg, who often found himself explaining what his company does in rudimentary terms to lawmakers twice his age, the hearings could be considered a win: Facebook shares rose more than 1 percent after climbing 4.5 percent on Monday. And his company regained more than $25 billion in market value that is had lost since it was revealed in March that Cambridge Analytica, a data-mining firm affiliated with Donald Trump’s presidential campaign, gathered personal information from 87 million users to try to influence elections.

Still, Facebook’s stock remains 10 percent below where it stood before the scandal, a decline that has wiped out about $50 billion in shareholder wealth.

Zuckerberg agreed to the hearings as pressure mounted over the Cambridge Analytica scandal and the company’s own admission last year that it had been compromised by Russians trying to influence the 2016 election. Earlier this year, special counsel Robert Mueller charged 13 Russian individuals and three Russian companies in a plot to interfere in the 2016 presidential election through a social media propaganda effort that included online ad purchases using U.S. aliases and politicking on U.S. soil. A number of the Russian ads were on Facebook.

Zuckerberg told the Senate on Tuesday that the company has been working with Mueller in his Russia probe and apologized over and over again for the company’s handling of data privacy.

“I started Facebook, I run it, and I’m responsible for what happens here,” he said.

House lawmakers were a bit tougher on Zuckerberg than their colleagues in the Senate, many of whom seemed confused by the company and what it does. Some of the House members curtly cut him off in questioning, trying to make the most of their four minutes each.

Zuckerberg mostly held his composure, repeating many of the same well-rehearsed answers: He is sorry for the company’s mistakes. He is working on artificial intelligence technology to weed out hate speech and at the same time ensure that they don’t block people for the wrong reasons. People own their own data, as far as he sees it. And he’s come a long way since he created the platform in his dorm room almost 15 years ago.

Some of the lawmakers talked to Zuckerberg, 33, as they would their children or grandchildren, and were occasionally befuddled by the complexities of his company.

Wrapping up his four minutes, Rep. Gus Bilirakis, R-Fla., commended the platform, saying “it’s wonderful for us seniors to connect with our relatives.”

By the close of Wednesday’s hearing, Zuckerberg had spent roughly 10 out of the previous 24 hours testifying before Congress.

On regulation, Zuckerberg said he was open to it.

“The internet is growing in importance around the world in people’s lives and I think that it is inevitable that there will need to be some regulation,” he said.

Still, he said, lawmakers need to be careful, noting that new rules or laws could hurt smaller businesses more than a behemoth like Facebook.

House Energy and Commerce Chairman Greg Walden said the committee will look at what could be done.

“While Facebook has certainly grown, I worry it has not matured,” Walden, R-Ore.,  told Zuckerberg. “I think it is time to ask whether Facebook may have moved too fast and broken too many things.”

Many questions focused on Cambridge Analytica, which gathered data several years ago through a personality quiz created by an academic researcher. The app vacuumed up not just the data of the people who took it, but also — thanks to Facebook’s loose restrictions — data from their friends, too, including details that they hadn’t intended to share publicly. Cambridge Analytica then obtained the data and was said to have used it to try to influence elections around the world.

Zuckerberg said at the House hearing that his own Facebook data was part of that sweep. He told the Senate that Facebook had been led to believe Cambridge Analytica had deleted the user data it had harvested and that had been “clearly a mistake.” He assured senators the company would have handled the situation differently today.

That may be enough to satisfy lawmakers for now. But that could change if Democrats take control of Congress in midterm elections this year.

Pallone said that if Democrats were in charge, “then we would push all the more.”   /muf

source: technology.inquirer.net

Sunday

Iran hit by global cyber attack that left US flag on screens


DUBAI - Hackers have attacked networks in a number of countries including data centers in Iran where they left the image of a US flag on screens along with a warning "Don't mess with our elections", the Iranian IT ministry said on Saturday.

"The attack apparently affected 200,000 router switches across the world in a widespread attack, including 3,500 switches in our country," the Communication and Information Technology Ministry said in a statement carried by Iran's official news agency IRNA.

The statement said the attack, which hit internet service providers and cut off web access for subscribers, was made possible by a vulnerability in routers from Cisco which had earlier issued a warning and provided a patch that some firms had failed to install over the Iranian new year holiday.


Cisco did not immediately respond to requests for comment.

A blog published on Thursday by Nick Biasini, a threat researcher at Cisco's Talos Security Intelligence and Research Group, said: "Several incidents in multiple countries, including some specifically targeting critical infrastructure, have involved the misuse of the Smart Install protocol...

"As a result, we are taking an active stance, and are urging customers, again, of the elevated risk and available remediation paths."

Iran's IT Minister Mohammad Javad Azari-Jahromi posted a picture of a computer screen on Twitter with the image of the US flag and the hackers' message. He said it was not yet clear who had carried out the attack.

Azari-Jahromi said the attack mainly affected Europe, India and the United States, state television reported.

"Some 55,000 devices were affected in the United States and 14,000 in China, and Iran's share of affected devices was 2 percent," Azari-Jahromi was quoted as saying.

In a tweet, Azari-Jahromi said the state computer emergency response body MAHER had shown "weaknesses in providing information to (affected) companies" after the attack which was detected late on Friday in Iran.

Hadi Sajadi, deputy head of the state-run Information Technology Organization of Iran, said the attack was neutralized within hours and no data was lost. — Reuters

Saturday

Massive data breach has cost Equifax nearly $90 million


SAN FRANCISCO — A massive security breach that hit Equifax has cost the US credit bureau nearly $90 million so far, a figure that is set to rise further, its chief financial officer said on Thursday.

The company, which gathers data on consumers to help lenders determine borrowers’ creditworthiness, revealed in September that hackers had stolen the personal details, including names, dates of birth and social security numbers, of nearly 146 million people.

In the third quarter, “we incurred a one-time charge related to the cybersecurity incident of $87.5 million,” John Gamble said during a conference call on quarterly results.

Equifax is forecasting between $60 and $75 million in spending that will include information technology security in the fourth quarter, he said.

In addition to the expenses, the group’s earnings have also been affected, particularly due to customer dissatisfaction, Equifax said.

Its net income fell 27 percent to $96.3 million in the third quarter.

Equifax also said in a document sent to the US Securities and Exchange commission that it is the subject of 240 class-action lawsuits in the US and Canada as well as more than 50 investigations in the US, Canada and Great Britain.

It did not quantify the possible financial impact of the lawsuits.

Equifax interim CEO Paulino do Rego Barros said that following the security breach, its senior leadership will not receive bonuses this year.

Its CEO Richard Smith resigned in late September, as did two other Equifax executives, its chief information officer and chief security officer.

source: business.inquirer.net

Sunday

5 Ways Small Businesses Must Protect their Data



Cyber security is a new concern for all businesses. Big hacks, like the Target, Home Depot, and Sony attacks, have only emphasized how much small businesses need to protect themselves. Large businesses have a lot of resources to do this, but small businesses often do not have the budget or knowledge to perform due diligence against cyber security attacks. Here are 5 ways a small business can protect itself from data threats.

Protecting Small Business Data: Backup
The new threat on the block is ransomware. Symantec estimates that 60% of small businesses face significant financial hardships after being attacked by ransomware. Some of these businesses even discontinue service or go out of business as a result of the attacks. Ransomware encrypts important files, like documents, pictures, and CAD files, on a PC. The local PC isn’t the only victim either. Ransomware will also attempt to reach out to other PCs on the network, especially mapped network drives. Once the ransomware finishes encrypting files and drives, the software demands money to un-encrypt the data that the business can no longer access. The ransom can be expensive.

Small business can’t afford that kind of monetary hit. However, if a system gets attacked by ransomware and the business has a quality backup, the business can simply wipe the PC and start over. Re-imaging a PC and restoring data only takes a day or two and saves the business thousands of dollars. Backing up and protecting small business data is easy. There are a lot of good, online services that automate this process for an affordable yearly fee. Likewise, it’s easy enough to setup on your own. The important thing is to keep 3 different backups for the 3 different time periods for each PC. Each backup set needs to be kept on-site, off-site but local, and not local. This ensures that data is saved in case a business goes up in flames or the offsite backup is hit by a natural or man-made disaster. Data storage is cheap today so there’s a backup is an easy choice..

Protecting Small Business Data: Switch to the Cloud
The cloud is still a scary thing for businesses. I understand why. Using a cloud infrastructure means that businesses have to hand over control of their IT systems and depend on another business to stay in business. Think of it this way, though, cloud businesses build their business on reliability, speed, and security. Microsoft’s Azure and Amazon’s S3 services are incredibly powerful. They both have over a 99% uptime guarantee in their Service Level Agreements. Both replicate data in servers throughout the country. Both backup data. Microsoft has the advantage of adding their entire Office Suite in the cloud, too. Best of all, cloud services can lower ownership expenses.

Protecting Small Business Data: Purchase, Update Quality AV
Antivirus protection is still needed in today’s environment. By now we shouldn’t have to warn anyone to install a quality antivirus program and keep it up-to-date. So many businesses still don’t follow this basic rule, though. This is something that any small business can implement in a few hours and automate.

Protecting Small Business Data: Restrict Admin Accounts
Most small businesses buy a few PCs and attach them to a small local area network. They don’t use domain services or group policies. That’s okay. It’s not always appropriate for a small business to utilize these kinds of services. It is important to make sure that employees aren’t using admin accounts on their PCs, though. Admin accounts are setup by default. Changing a user’s profile from being an admin to a standard user eliminates 90% of virus and attack-ware threats. Employees can always elevate privileges on the PC when they need to install software.

Protecting Small Business Data: Education
Nothing is more important than education. Employee education can significantly reduce the threat of cyber attacks. Even simple reminders to avoid opening links or attachments in email will significantly reduce the chances of an attack. Hold monthly education meetings or assign a “security guru” to send out weekly or monthly newsletters for employees to read and act on. These are basic steps but speaking to the last point, awareness and education is a significant part of the battle against data breach and data corruption. Please let us know if you have other questions. The needs of our customers frequently grow in one area or the other, such as the recent spike in ransomware. We might bring your concerns to the blog to help others, as well.

source: securedatarecovery.com