Showing posts with label Live CD. Show all posts
Showing posts with label Live CD. Show all posts

Friday, January 18, 2013

PSA Security & Hacking: Shylock Banking Trojan now spreading via Skype

Primary source https://www.csis.dk/en/csis/blog/3811

As someone that is computer security conscious, I avoid online banking completely.

For friends, family, & others that insist on online banking I suggest either of the following:

  • Use a Live CD, Brian Kreb has excellent articales on how to do this http://krebsonsecurity.com/2012/07/banking-on-a-live-cd/ or http://krebsonsecurity.com/banking-on-a-live-cd/
  • Use a recent iOS device, iPhone 4S or newer, iPad 2 or newer, iPod Touch 5th generation or newer.  There are significant hardware security improvements that started with those respective devices. 
I also strongly suggest if using the iOS devices, to turn off Simple Passcode, and use a Pass Phrase, even if you don't lock your iOS device all the time, this will enable whole device encryption.

Clear instructions & screenshot for turning off Simple Passcode http://www.computerworld.com/s/article/9231627/Kenneth_van_Wyk_Shutting_down_security_gotchas_in_iOS_6?taxonomyId=17&pageNumber=1

The reason for this, is that a hacker with right software, can use a computer to try passwords, they can also bypass the 10 try feature.

So if your using the Simple Passcode, which is just a 4 digit number, they will probably be able to hack it in less than an hour.

However, if you use a Pass Phrase, like I <3 my iPad.  I hate green beans! the hacker will have a much more difficult time.  [Note, don't use that pass phrase, it is just to illustrate the concept.]

Since instead of only 4 numbers, there are 34 characters, counting the blank spaces, plus your using uppercase letters , lowercase letters, numbers, special characters, and blank spaces.

The hacker won't have any idea how long your password is, and by using at least one of all possible upper/lower case, numbers, symbols, and blank spaces you make hackers job a lot harder.

For more on passwords see http://cliffsesportcorner.blogspot.com/2012/05/steve-gibsons-haystacks-needles.html

Additional links:


Thursday, May 24, 2012

Diablo 3 Account Security & Hacking compared to Online Banking Hacks

I have seen lot of people posting about getting their accounts hacked, and some people want to blame Blizzard.

I have been focusing on Computer Security issues with all the time & energy I can since late last year, when someone managed to hack my Credit Card.

I have learned a lot since then about computer security, though I feel I am a long way from being an expert, I have certainly learned some important things.

One of those things is that Malware and/or weak passwords are almost always the problem.

Here is a story about small business losing lots of money because of this, if you read the story you will see how it matches exactly with what people are experiencing with D3.


The author of that article has had lots of small business owners contact him because of his story asking what they should do, he recommends Live CD's, which is similar to VM but runs from CD/DVD.

There are also Live USB's.

The point of using these is that most Malware isn't designed to run on Linux, and the Live CD runs separated from the computer in many ways.

Bear in mind many of these people that Brian Krebs talks about lost $100k or more in money!  So they were and are taking this very seriously, and more than a couple were using two factor authentication, lot of banks require than for customers that have large amounts of money.

But with malware on your computer, they can block or delay your log in and use the authentication that you enter to log in.

Additional Links
http://en.wikipedia.org/wiki/Live_CD

Hope that helps.

I really do know what it is like to have stuff hacked, been there done that, don't want it to happen again, but it might no matter what I do.  T_T

Stay Safe,

Cliff