Personal CyberSecurity Protecting Yourself from the Evils of the - - PowerPoint PPT Presentation

personal cybersecurity
SMART_READER_LITE
LIVE PREVIEW

Personal CyberSecurity Protecting Yourself from the Evils of the - - PowerPoint PPT Presentation

Personal CyberSecurity Protecting Yourself from the Evils of the Internet Steve McEvoy March 6 th , 2020 Austin, TX The Internet has some scary s**t going on This is a self defense course Goals What is the #1 Security Risk to your


slide-1
SLIDE 1

Personal CyberSecurity

Protecting Yourself from the Evils of the Internet

Steve McEvoy March 6th, 2020 Austin, TX

slide-2
SLIDE 2

The Internet has some scary s**t going on This is a self defense course

slide-3
SLIDE 3

Goals

slide-4
SLIDE 4

What is the #1 Security Risk to your Practice?

slide-5
SLIDE 5

Holiday Ransomware Attacks

slide-6
SLIDE 6
slide-7
SLIDE 7

Title

slide-8
SLIDE 8
slide-9
SLIDE 9

The Dental Record

slide-10
SLIDE 10

How did it Happen?

Dental Office

Backup Vault in Percsoft Office Your In Office File Server with your Data

slide-11
SLIDE 11

How did it Happen?

Un- Dental Office Over 400 !!

Opened the Vault and Deleted Everyones Backups, Then Sent a Ransomware commend to each clients server Server was then encrypted and all your files locked up and held for Ransom

slide-12
SLIDE 12

Discovered Monday Aug 26th

slide-13
SLIDE 13

9 Days Later – Sept 3rd

slide-14
SLIDE 14

17 Days Later – Sept 11th

slide-15
SLIDE 15

Thanksgiving Weekend

slide-16
SLIDE 16

Christmas Eve

slide-17
SLIDE 17
  • Have your own LOCAL backup strategy in

addition to a Cloud based backup

  • Talk about this to your IT Person and ask

them if this can happen to them/you

  • Care about this!

What Should You Do?

slide-18
SLIDE 18
  • Stop and Think Hard about their own

security measures

  • Store your passwords in a secure

database

  • Require any form of remote

access/control of your computers needs 2 factor authentication

  • Train their staff on phishing scams and

good security Practices

What Should They Do?

slide-19
SLIDE 19

What about your Phone?

slide-20
SLIDE 20

Always Update Your Phone

slide-21
SLIDE 21

How can you know if your username & password have been leaked into the wild?

slide-22
SLIDE 22
  • Security Expert from Microsoft
  • Searched the Dark Web
  • Compiled a list of ~8 Billion hacked

accounts

  • Created “Have I been pwned?” website

– ‘Pwned’ is a slang term

  • Securely check if your username and

passwords has been stolen

Troy Hunt

slide-23
SLIDE 23

www.HaveIBeenPwned.com

slide-24
SLIDE 24

Have I Been Pwned?

slide-25
SLIDE 25

Is your Password Pwn’d?

(starwars)

slide-26
SLIDE 26

Pre-check your new passwords

(MyReallyHardPassword)

slide-27
SLIDE 27
  • Get notified if your email(s) show up in

the future

Get Notified of pwnage

slide-28
SLIDE 28

I was Notified of pwnage

slide-29
SLIDE 29

How long will it take for a Hacker to break through my password?

slide-30
SLIDE 30

www.howsecureismypassword.net

(starwars)

slide-31
SLIDE 31

What makes a GOOD Password??

slide-32
SLIDE 32
  • Recently updated their recommended

digital identity standard (SP 800-63)

  • Troy Hunt canvased NIST and others to

derive what the collective wisdom is thinking

slide-33
SLIDE 33
  • 12 or more characters
  • We can use short dictionary words
  • 3 or 4 random words

Length Matters

slide-34
SLIDE 34

dog beer hat red tree bill head

slide-35
SLIDE 35

Nothing Personal

spouse kids food movie birthday address date pets phone

slide-36
SLIDE 36

dog beer hat red tree bill head

3 or 4 Short Random Words

doghatbeerhead

slide-37
SLIDE 37

Make ‘em Memorable

  • Think up something about the site
  • i.e. Wells Fargo

– dumb wagon horses – ripping off clients – stashing my cash

slide-38
SLIDE 38
  • dumbwagonhorses

– 15 characters – 3 random words – dumbwagonhorses is better than Sj7$qq#56

But what is wrong with this?

slide-39
SLIDE 39
  • They ‘Evolve’
  • Websites, banks, etc. will need to learn

and adopt these standards

  • dumbwagonhorses wouldn’t meet their

current ‘complexity checker’

Standards Don’t Change Overnight

slide-40
SLIDE 40

Starting TODAY! (2020 and on)

– Three or Four unassociated dictionary words – At LEAST 12 characters in length – Capitalize First Letters – Add a 2 digit year to the end (reminder)

Steve’s Recommendation (Simple Complexity)

DumbWagonHorses20

slide-41
SLIDE 41
  • DumbWagonHorses20

– 2 Trillion Years to Hack – Should meet the Banks requirements – Much easier to remember

Simple Complexity Works

slide-42
SLIDE 42

Where to Save Passwords?

slide-43
SLIDE 43

Bad Ideas

My Passwords Bank … Starbucks … Credit Cards ….

slide-44
SLIDE 44

Password Manager App

slide-45
SLIDE 45
  • Available Everywhere we are:

– Phones (iOS and Android) – Computer (Windows, Mac, Web)

  • Sync’d across all my devices

– Means linked to Cloud

Features for a Password Manager

slide-46
SLIDE 46
  • Secure!

– Especially if Cloud! – Encrypted – Smart Company – Reliable Company

  • Free! ?

– Free is bad – Affordable is good.

Features for a Password Manager

slide-47
SLIDE 47
slide-48
SLIDE 48
  • Personal
  • Family
  • Teams

1Password.com Versions

slide-49
SLIDE 49
  • “Vaults” hold your passwords
  • You control who has access to a specific

vault

Vaults

slide-50
SLIDE 50
  • Three Keys to access

– Username – Password – Encryption Key

  • 2 Factor Authentication
  • Notifications of Access

1Password Security

slide-51
SLIDE 51
  • They cannot see your data - ever

– Encrypted blob on their servers

  • Travel Mode

– Prevents border inspection access to your private data

1Password Security

slide-52
SLIDE 52
  • $3 per month
  • 1 Vault
  • Unlimited items

1Password Personal

slide-53
SLIDE 53
  • $5 per month for whole family
  • Up to 5 Family Members included

– More Kids? $1 extra per month

  • Private and Shared Vaults

1Password Family

slide-54
SLIDE 54

Shared Vaults

Shared

Netflix Amazon Spotify WiFi Code Bike Lock Code

Private (only you can see contents)

slide-55
SLIDE 55
  • $4 per month per user
  • Up to 5 Guest Accounts

– A guest can only access one vault

  • Unlimited Vaults

1Password Teams

slide-56
SLIDE 56

Using Teams

HR

Payroll Services Indeed Job Postings

Private Finance

QuickBooks Banks

Clinical

Invisalign Patient Reward Hub

Shared

WiFi Netflix PM Login Windows Login

slide-57
SLIDE 57

Demo

slide-58
SLIDE 58
  • iPhones and iPads
  • Android Phones and Tablets
  • Windows PCs
  • Mac’s

Apps for Everything

slide-59
SLIDE 59
  • Talk to your IT people about the possibility of

them being the weak link.

  • Update your Phones when prompted
  • Check if you’ve been Pwned
  • Use new Simple Complexity Passwords
  • Use a Password Manager

Take Aways…..

slide-60
SLIDE 60

Thank You!

steve@mmeconsulting.com

Presentation online at

www.mmeconsulting.com/Presentations