personal cybersecurity
play

Personal CyberSecurity Protecting Yourself from the Evils of the - PowerPoint PPT Presentation

Personal CyberSecurity Protecting Yourself from the Evils of the Internet Steve McEvoy March 6 th , 2020 Austin, TX The Internet has some scary s**t going on This is a self defense course Goals What is the #1 Security Risk to your


  1. Personal CyberSecurity Protecting Yourself from the Evils of the Internet Steve McEvoy March 6 th , 2020 Austin, TX

  2. The Internet has some scary s**t going on This is a self defense course

  3. Goals

  4. What is the #1 Security Risk to your Practice?

  5. Holiday Ransomware Attacks

  6. Title

  7. The Dental Record

  8. How did it Happen? Backup Vault in Percsoft Office Dental Office Your In Office File Server with your Data

  9. How did it Happen? Opened the Vault and Deleted Everyones Un- Backups, Then Sent a Ransomware commend to each clients server Over 400 !! Dental Office Server was then encrypted and all your files locked up and held for Ransom

  10. Discovered Monday Aug 26th

  11. 9 Days Later – Sept 3rd

  12. 17 Days Later – Sept 11th

  13. Thanksgiving Weekend

  14. Christmas Eve

  15. What Should You Do? • Have your own LOCAL backup strategy in addition to a Cloud based backup • Talk about this to your IT Person and ask them if this can happen to them/you • Care about this!

  16. What Should They Do? • Stop and Think Hard about their own security measures • Store your passwords in a secure database • Require any form of remote access/control of your computers needs 2 factor authentication • Train their staff on phishing scams and good security Practices

  17. What about your Phone?

  18. Always Update Your Phone

  19. How can you know if your username & password have been leaked into the wild?

  20. Troy Hunt • Security Expert from Microsoft • Searched the Dark Web • Compiled a list of ~8 B illion hacked accounts • Created “Have I been pwned?” website – ‘Pwned’ is a slang term • Securely check if your username and passwords has been stolen

  21. www.HaveIBeenPwned.com

  22. Have I Been Pwned?

  23. Is your Password Pwn’d? (starwars)

  24. Pre-check your new passwords (MyReallyHardPassword)

  25. Get Notified of pwnage • Get notified if your email(s) show up in the future

  26. I was Notified of pwnage

  27. How long will it take for a Hacker to break through my password?

  28. www.howsecureismypassword.net (starwars)

  29. What makes a GOOD Password??

  30. • Recently updated their recommended digital identity standard (SP 800-63) • Troy Hunt canvased NIST and others to derive what the collective wisdom is thinking

  31. Length Matters • 12 or more characters • We can use short dictionary words • 3 or 4 random words

  32. dog bill red beer hat tree head

  33. Nothing Personal address spouse movie food kids date birthday phone pets

  34. 3 or 4 Short Random Words bill dog red beer hat tree head doghatbeerhead

  35. Make ‘em Memorable • Think up something about the site • i.e. Wells Fargo – dumb wagon horses – ripping off clients – stashing my cash

  36. But what is wrong with this? • dumbwagonhorses – 15 characters – 3 random words – dumbwagonhorses is better than Sj7$qq#56

  37. Standards Don’t Change Overnight • They ‘Evolve’ • Websites, banks, etc. will need to learn and adopt these standards • dumbwagonhorses wouldn’t meet their current ‘complexity checker’

  38. Steve’s Recommendation (Simple Complexity) Starting TODAY! (2020 and on) – Three or Four unassociated dictionary words – At LEAST 12 characters in length – Capitalize First Letters – Add a 2 digit year to the end (reminder) DumbWagonHorses20

  39. Simple Complexity Works • DumbWagonHorses20 – 2 Trillion Years to Hack – Should meet the Banks requirements – Much easier to remember

  40. Where to Save Passwords?

  41. Bad Ideas My Passwords Bank … Starbucks … Credit Cards ….

  42. Password Manager App

  43. Features for a Password Manager • Available Everywhere we are: – Phones (iOS and Android) – Computer (Windows, Mac, Web) • Sync’d across all my devices – Means linked to Cloud

  44. Features for a Password Manager • Secure! – Especially if Cloud! – Encrypted – Smart Company – Reliable Company • Free! ? – Free is bad – Affordable is good.

  45. 1Password.com Versions • Personal • Family • Teams

  46. Vaults • “Vaults” hold your passwords • You control who has access to a specific vault

  47. 1Password Security • Three Keys to access – Username – Password – Encryption Key • 2 Factor Authentication • Notifications of Access

  48. 1Password Security • They cannot see your data - ever – Encrypted blob on their servers • Travel Mode – Prevents border inspection access to your private data

  49. 1Password Personal • $3 per month • 1 Vault • Unlimited items

  50. 1Password Family • $5 per month for whole family • Up to 5 Family Members included – More Kids? $1 extra per month • Private and Shared Vaults

  51. Shared Vaults Netflix Amazon Spotify WiFi Code Bike Lock Code Shared Private (only you can see contents)

  52. 1Password Teams • $4 per month per user • Up to 5 Guest Accounts – A guest can only access one vault • Unlimited Vaults

  53. Using Teams PM Login Payroll Services Windows Indeed Job Postings Login HR Private QuickBooks Banks WiFi Finance Netflix Invisalign Patient Reward Hub Shared Clinical

  54. Demo

  55. Apps for Everything • iPhones and iPads • Android Phones and Tablets • Windows PCs • Mac’s

  56. Take Aways….. • Talk to your IT people about the possibility of them being the weak link. • Update your Phones when prompted • Check if you’ve been Pwned • Use new Simple Complexity Passwords • Use a Password Manager

  57. Thank You! Presentation online at www.mmeconsulting.com/Presentations steve@mmeconsulting.com

Download Presentation
Download Policy: The content available on the website is offered to you 'AS IS' for your personal information and use only. It cannot be commercialized, licensed, or distributed on other websites without prior consent from the author. To download a presentation, simply click this link. If you encounter any difficulties during the download process, it's possible that the publisher has removed the file from their server.

Recommend


More recommend