You cannot be serious….

…yes you can and you must be. But serious about what? About your passwords, that’s what. Like many others, I’ve been banging on about passwords for years and years and years. From a company that would put a new laptop on a desk for the user with the password on a post-it note attached to the lid to companies that shared passwords by email to people using easily guessable passwords the whole issue of password security is not going away.

And it’s causing major problems and financial loss.

In 2019, 80% of all data breaches which resulted in financial loss, were the result of compromised passwords whilst IBM have stated that the average cost of a data breach to businesses in 2020 was $3.86m so you can see stealing passwords (and other information) is big business.

But this post is not about the physical stupidities like leaving passwords lying around it’s about the passwords you and I use that are part and parcel of our day-to-day web access.

Every year a company called NordPass* evaluates the latest password data across 50 countries. They get this by examining a database of 4TB of data, all of these passwords have been nicked, stolen, and hacked. These security breaches are the result of hacking, phishing and other “nocturnal” cyber activities.

Passwords, credit card numbers, bank account details, usernames, dates of birth and other details are made available for sale on the Dark Web and this is where NordPass gets their seed data.

The Most Common Passwords 2021

And it seems that in 2021 little has changed. The most common passwords they found were

  1. 123456 (used a staggering 103 million times)
  2. 123456789 (46m uses)
  3. 12345 (33m uses)
  4. qwerty (22m uses)
  5. password (21m)
  6. 12345678 (15m)
  7. 111111 (13m)
  8. 123123 (10m)
  9. 1234567890 (10m)
  10. 1234567 (9m)

All of the above would be cracked in under one second. That’s how secure these passwords are

Apparently a “stunning” number like to use their own name – “Charlie” being the 9th most popular password in the UK whilst popular music acts and sports also have their own claim to fame. “Onedirection” being popular, along with “Liverpool” whilst in Canada “hockey” was the top sports related password and “dolphin” was number one amongst animal related passwords.

NordPass have mapped the data too and, according to their data 187,219,153 passwords have “leaked” from the UK, that’s an average of 2.785 passwords per capita.

How should you formulate your passwords?

Passwords should be 16 characters or more – a M1xture! of UPPER case, lower case, numbers and characters and should NOT be used for more than one account. They should not use ANY personal information, no address details, no phone numbers, no pets names in fact nothing that can be gleaned from social media and day to day interactions

Challenge to remember? You bet. Difficult to crack? Most certainly. According to How Secure is my Password 45Erp!VBN?1869y& will take 41 trillion years to crack.

I have over 250 passwords that I use so I have to use a Password Manager to store them. I use LastPass but many others are available, including NordPass’ own, and some are free. I suggest, though , that you use one that can synchronise across all of your devices, PCs, Macs, tablets, phones etc so that you always have your passwords with. A good Password Manager will not only store your passwords very securely but should also create secure passwords for you.

Go ahead and test your passwords using their secure tool.

I might not be a cyber security expert – but I know quite a bit and know some very good ones so if you need some help with your cyber security, your SEO or any other element of your online marketing activities then why not kick things off with a free consultancy session, drop me an email or just give me a call on 01793 238020 or 07966 547146.

In the meantime, be safe out here. The World Wide Web can be a dangerous place

*NordPass have a vested interest in password security – they sell a Password Manager

National Cyber Security Month

October is National Cyber Month.
What is National Cyber Security Month?

National Cyber Security Week

Threats of Cyber Crime from Cyber Criminals continue to increase and we all need to be increasingly alert and focussed on the threats, the impact they could have on our lives AND the things we can do to minimise the risk to ourselves and our businesses.

National Cyber Security Month 2021 has the overarching theme “Do your part. #BeCyberSmart” and looks to empower individuals and businesses to own their role in protecting their part of cyberspace.

If we all do our part then we will all benefit from a safer place to live and be in a safer place to do business. Not only that but we’ll also be denying the cybercriminals the space they need to extort, employ fraud and generate the money they lust after.

USer name and password box

How can we contribute?

We can all look to implement stronger/better security practices such as not clicking links in emails, not opening emails from people we don’t know or even opening emails we weren’t expecting. We can install security software on our phones, our tablets and our computers. We can use stronger passwords, and make sure we use unique passwords for EVERY application.

Each week, National Cyber Security Month will have a different focus, starting with Week 1 – Be Cyber Smart

Week 1, Starting October 4 – Be Cyber Smart

Hacker, tilting his hat

Our lives are increasingly intertwined with the internet and the World Wide Web. Pretty much all personal and business information is stored on internet connected platforms, from banking to social media, from email to SMS, from phone and video calling to watching TV and listening to music and beyond. The internet simplifies some areas of our lives and makes it more complex in others but the one, overarching common factor, is the need for a strong level of security to keep our data safe.

That’s why Week 1 of National Cyber Security Week focuses on the best security practices and “cyber hygiene” to keep our data safe, owning our role in Cyber Security and starting with the basics. That includes using unique, strong, passwords and making sure that we use multi-factor authentication (2FA) where it’s available, preferably avoiding SMS (text Message) authentication where possible.

Week 2, Starting October 11 – Fight the Phish – Trust No One

Phishing attacks, where emails and text messages are sent containing web links encouraging you to click the link, visit a website set up by cyber criminals and enter your user names and passwords are still on the increase. Why are they on the increase? Because they work. People see an email that purports to come from their bank, HMRC, DVLA, Post Office, BT etc. and are given a warning claiming that the recipient needs to do something NOW or they will be locked out of their account, will be arrested, won’t have an order delivered …. or one of many other ruses. You click the link and either have malicious software sent to your computer without your knowledge and approval or give away user names and passwords to cyber criminals, enabling them to access your personal accounts and to steal from you.

The X-Files mantra of “Trust No one” applies here. Any email that contains a request for such information should always be approached with caution and, if you have even a small inkling of concern, then simply open your web browser and visit the website of the sender to check out the veracity of the email.

Week 3, Starting October 18 – Explore, Experience, Share

Week three focuses on the National Initiative for Cyber Security Education (NICE), inspiring and promoting the exploration of careers in the cybersecurity sector. Whether you are a student or a veteran or seeking a career change, this week is all about the exciting, ever changing, field of cyber security, a rapidly growing business sector with something for everyone

Week 4, Starting October 25 – Cybersecurity First

The last week of National Cybersecurity Month looks at making security a priority. Actually taking a Cyber Security First approach to designing and building new products, developing new software, creating new Apps.

Make Cyber Security Training a key part of onboarding when taking on new employees (and, at the other end, making sure that technology rights are revoked when people leave organisations).

Ensure that your employees are equipped with the cyber secure tools that they need for their jobs. If you practice a BYOD (Bring Your Own Device) policy, allowing employees to use their own phones, tablets and computers then you need to ensure that the cyber security deployed is as strong as that on equipment that you provide.

Before buying new kit, or signing up to a new service, do your research, check the security. Is it secure enough? Can it be made more secure? Can it be remotely wiped? Who has control? All of these questions, properly answered, will ramp up your cyber security defences and help keep the cyber crims at bay

When you set up new equipment, that new phone, tablet or laptop, I know it’s exciting but please invoke the Cyber Security first, don’t leave it until last – it might be too late. Make sure default passwords are replaced with something secure and lock down those privacy settings.

Cyber Security MUST NOT be an afterthought. If it is, you could find yourself paying the price

And if you need some help, you can always ask me. I might not know the answer but I know people in the Cyber Security industry that I can put you in touch with. Email andy@enterprise-oms.co.uk, phone/message me 07966 547146, call 01793 238020 or message me on Social Media and we’ll get it sorted.

New Password Guidance from the National Cyber Security Centre

15 years ago Bill Gates, yes that Bill Gates, predicted the death of the password, presuming that a much more secure alternative method of securing data be adopted, But it hasn’t and passwords are still the default method of securing access to data and systems.

And, with the rapid rise of Cloud Services, Smartphones, tablets and much greater use of the world wide web passwords are seen as an easily-implemented, low-cost security method that users have become familiar, and comfortable with.

Logging On

However, with the sound advice of using a different password at every instance that requires a password has lead to “password overload”, more so when the instruction is to make then increasingly complex to reduce the chance of password theft or accounts being hacked. This has lead to a small range of different strategies to remembering passwords. From writing them down in a “little black book”, saving them on a spreadsheet or using a password Manager [with over 300 passwords, the latter is my choice]

However, a lot of people develop a strategy that is simply based on incrementation. HardPassword1, HardPassword2 etc. The danger being that in a data breach, once your strategy is uncovered it’s just a matter of time before hackers gain access to a range of your accounts.

Recent advice from the UK’s National Cyber Security Centre (NCSC, based in London and part of the UK’s Cyber Security HQ at GCHQ) has suggested making passwords up simply from three random words. Their advice is to be creative and use words that are memorable to you – but not words that can be easily associated with you, such as

  • Your children’s names
  • Favourite Sports team
  • Current partners’ name
  • Names of other family members
  • Pet’s name
  • Place of Birth
  • Favourite Holiday
  • Etc

So, that makes it harder to think of 3 random words but I’ve got an idea. And it’s based on geography. Before you run away thinking I’m going to suggest capital cities, rivers or mountain ranges stay with me. I suggest using some places that are close to your heart, but randomised -by using the navigation app/website What Three Words.

What Three Words is able to define a precise location, down to a 3 metre square. Simply visit the What Three Words website, or install their free app on your phone and navigate to your favourite place. Here’s one of mine (not used for any of my passwords so I’m giving nothing away)

St Catherine’s By The Sea in Map View and Google Earth View

Whether you use the Map View or Google Earth type view, you’ll see the map is overlaid by little squares.

Now, just click on a square and it will be identified by three unique words, so you could click on the entrance to the church, for example, or even a grave stone in the grave yard and What Three Words will give you a code that is unique to that square.

I’ve clicked on the church door and the unique code is remarking however stubble. You could make it harder by adding hyphens, or a different symbol and perhaps capitalising Remarking-However&Stubble for example.

Now all you have to do is either remember your password or use a decent Password Manager -and there are many to choose from, and I’ve written about them in the past.

And PLEASE, if this applies to to you – STOP USING PASSWORD or 12345678 and use one of the above instead

If you need any help, please, just ask. You can reach me by phone – 01793 238020 – email – andy@enterprise-oms.co.uk or just hunt me down on Social Media.

What’s the Difference between the WWW and the Internet?

Although people seem to use the terms WWW and Internet interchangeably, the two are actually very different beasts

The Internet

There is a belief that the Internet came about through military research. The US government needed to find a way to send the “launch” message to ICBM silos in the event of the telephone network being disabled.

Although the US military contributed to the formation of the internet it was a lot more than this, and was mainly in the academic domain.

In the early 60s various projects in the US, UK and France had the aim of building, and interconnecting, computer networks, particularly the Super Computers of the day, for data sharing and data transmission.

A visual representation of the Internet by The Opte Project
A visual representation of the Internet by The Opte Project

In 1974 research was published that evolved in to the Transmission Control Protocol (TCP) and the Internet protocol (IP), the basic technologies that are used to send computer data from one location to another.

In the early 80s the American National Science Foundation funded a number of supercomputers at several US universities, provided interconnectivity between them and also built a network that allowed by other academic institutions for research. This marked the beginning of the internet.

The first Internet Service Providers emerged in the USA & Australia in 1989 and in 1990 a small number of commercial entities in the USA were provided with private connections to this network. Connectivity increased rapidly, and the Internet as we know it, was born.

The Internet is the structure along which data travels when going from A to B and can be likened to a road network. And, like a road network, there are some routes that are faster than others and even the fast routes suffer from occasional issues and blockages which slows things down.

The World Wide Web

In 1989-90 research at CERN, in Switzerland, by British computer scientist, Tim Berners Lee (now Sir Tim) saw the development of a technology that linked hypertext documents in to an information system which was then accessible from any node (connection) on the network. Sir Tim released his research in tot the world and allowed it to be used without any license fees and this allowed it to become the defacto document standard for the world wide web. This is why all web addresses start with HTTP, it defines the protocol to be used to transmit documents, Hypertext Transmission Protocol although we are now more familiar with HTTPS where the S adds Secure.

Basically, the Internet is the structure along which the data travels (the road system mentioned in the previous section) whilst the World Wide Web is the data that travels across that network, like traffic on a road.

If you need any help with your presence on the World Wide Web, from your website through Search Engien Optimisation (SEO), Advertising or anything else I’ll be more than happy to have a free chat to see how/where I can help your business. All you have to do is call me on 01793 238020, email andy@enterprise-oms.co.uk or just search Chief SEO Officer.

How much did your last cup of coffee cost?

Cybercrime is everywhere these days, in 2020 cybercrime cost UK businesses an estimated £21Bn* with an estimated 40% of UK businesses being subjected to to some kind of cybercrime in the previous 12 months. So, how can you minimise the risk to YOUR business?

There’s lots of advice on passwords, I regularly write about them, and other security measures that you can take but did you know that even a trip to your favourite coffee shop could end up being far more expensive than the price you pay for your Triple Grande Decaf Soy Latte Macchiato and blueberry muffin.

Imagine the scene, you’re between meetings and decide to drop into your favourite coffee shop for a cup of coffee, a cake and to tap into their Wi-Fi to read your emails, refresh your knowledge in time for your next meeting or simply to surf the web.

Spoof Wi-Fi Hotspot

When you sit down and try to log-on to the Wi-Fi there’s frequently a selection of hot-spots to choose from. How do you know which is the free service provided by the venue and which is a spoof.

It’s very easy to set up a Wi-Fi hot-spot using a mobile phone, Mi-Fi type of device or laptop and allow other users to connect through this free connection.

This means that all of the traffic can then be intercepted by the person providing the spoof account, what sort of important information is passed from your laptop through this connection? It could be your details to access your online banking, the log-in to your company network or the necessary information required to access your corporate email account.

Time for a comfort break

Laptop and cup of coffee

Then the urge hits, you look around and see that everybody seems respectable enough so you head off to the toilet thinking that your laptop is safe on the table. After all, nobody would nick in sight of all those customers, staff and CCTV cameras would they?

You’d be wrong. Laptop tracking service provider, Prey, found that areas offering free Wi-Fi were the second most common target for opportunistic laptop thefts, the only riskier place being left in a visible place in your car.

If stolen, it’s not only the inconvenience of replacing the laptop, reinstalling your applications and copying back your data [you do back-up your data don’t you?] it’s the additional costs that aren’t covered by your insurance.

The Ponemon Institute, a US cyber crime consultancy, put the real cost of the loss of a laptop and it’s data at nearly £31,000. This was broken down into £4,000 for the loss of Intellectual Property, forensics and legal bills adding around £1,500 with a staggering £24,500 attributable to the loss of income, customers and competitive advantage associated with a data breach

So, the next time you stop off for a cup of coffee and decide to log-on using their free Wi-Fi, just make sure you know which network that you’re connecting to and that you don’t leave your laptop unattended.

*Detica in partnership with the Office of Cyber Security and Information Security in the Cabinet Office Report, 2020

Passwords are not just for Chrismas

Wow, what a year. One thing’s for certain, 2020 is one year that will never be forgotten. Covid, Lockdown, Furlough, words that have been added to the canon of speech this year. And, to cap it all, Christmas is just around the corner and the world is still full of massive levels of uncertainty.

Whether you are working from home, #WFH, working in an office or still out and about I know that as Christmas approaches the big wind-down starts to feature in our minds.

Nothing wrong with looking forwards to Christmas but it’s important that you don’t allow your Cyber Security guard to fall too.

Andy, checking out websites as part of his work

Why not? Simply because the hackers and cyber criminals won’t – if anything they’ll be upping their activity because they know that our minds will be on other things. In previous years we’d have been looking forward to Christmas Markets, Christmas parties, gifts, food, television and everything else that’s associated with the season of goodwill.

Our vigilance MUST remain high, both in the office and when working from home. Keep your eyes open for suspicious looking emails, especially those coming from unexpected quarters, with messages that promise much, such as tax refunds or deliveries of items you don’t remember ordering. Also beware of emails with links to websites that look OK but in reality will do harm.

It’s also a good idea to take a fresh look at your password security. Turkish researcher Ata Hakcil analysed more than 742m passwords that have been revealed in data breaches (hacks) that turned up on the Dark Web. Ata went on to make a worrying number of discoveries.

Of the 742m only 169m were unique which just goes to show how frequently we reuse passwords and how many passwords are used by a lot of people.

Worst passwords of 2020

Unfortunately, not a lot has changed over previous lists

  1. 123456 (same place as 2018 & 2019)
  2. 123456789 (up 1 place) (same as 2019)
  3. passwords (up one place on 2019)
  4. qwerty (a fall of one place on 2019)
  5. password (slips two places)
  6. 12345678 (up 1 on 2019)
  7. 123123 (a new entry)
  8. 111111 (up from No. 10 in 2019)
  9. 1234 (yes, I kid you not, 1234)
  10. 1234567890 (a new entry in this Top 10)

Disturbingly, at least 1 in 10 people have used at least one of these poor passwords – I hope you’re not one of them.

Data breaches are inevitable. To be as secure as possible you need to use strong, unique passwords for each individual account that you have. This makes the theft of one password much less of a disaster than if you use the same (or close variant) across all of your accounts.

What’s a Strong Password?

A strong password isn’t a word at all. The best ones are passphrases comprising of a random combination of words with 12 characters or more, using mixtures of alphanumeric, UPPER & lower case characters and symbols.

Think of a nonsense phrase, or even a line from your favourite song. Science Friction Burns My Fingers for example. Noe, run the words together, use hyphens, underscores and number substitution.

Sc13nce-fricti0nBurnsMy_Finger5%

That’s one password – you need a unique one for EVERY account that you have. Now, that’s a challenge to remember so you need a password manager. Because of my work, I have access to 789 accounts of one sort or another and I have 789 different passwords. Obvious there’s no way I could remember all of those – I struggle to remember 4 important ones which his why I use a password manager. Not only does it store all of my passwords in a safe place it also generates new, random, ones for me.

Top 10 Password Managers

There are loads of great password managers out there. I use LastPass because it was one of the first to integrate with my browser AND be available across all of my devices, desktop, laptop, Chromebook, phone and tablet.

TechRadar recently reviewed Password managers and their top 10 free and paid-for password managers is as follows

  1. Dashlane
  2. NordPass
  3. RoboForm
  4. 1Password
  5. LastPass
  6. Keeper
  7. BitWarden
  8. LogMeOnce
  9. mSecure
  10. ZohoVault

You TechRadar’s reviews here. And don’t forget, your web browser probably has a password manager built in and may even generate new ones for you but it may not synchronise across all of your devices

And PLEASE, if this applies to to you – STOP USING PASSWORD or 12345678 and use one of the above instead

Have a great Christmas, a happy new year and I look forward to communicating with you in the new year. If you need any help, please, just ask. You can reach me by phone – 01793 238020 – email – andy@enterprise-oms.co.uk or just hunt me down on Social Media.

Safer Internet Day 2020

log on box

1,2,3,4 is the start of The Beatles “I saw her standing there”, it’s the way you “declare a thumb war” and it’s also the first 4 characters of the worst password of 2019 – which is 123456.

11th February 2020 is the 17th “Safer Internet Day” and I’d like to make it a day where people change their simple passwords for something much more secure.

Why is internet security important?

Safer Internet Day

Every day millions of websites come under attack, ranging from simple personal sites to complex e-commerce sites and online email service providers.

Just think about your information that’s out there, and what could happen if your business or personal security was breached.

What’s in your Gmail, Hotmail, Outlook.com mailbox, how valuable would that be to a cyber-criminal? What if they hacked your email account and sent emails to your contacts and connections, as you, then tried to use your email address for more nefarious purposes?

How about if, after hacking your email account, they used your credentials to try to

  • break into your bank account
  • hack in to your building society account
  • access your credit card account
  • use the info to set up fake accounts that they can then use to steal your identity, borrow money in your name and have it sent to their bank accounts,
  • buy products online that are delivered to them and billed to your address – the list goes on and becomes even worse if it’s business data that has been stolen.

Business bank accounts typically have more money in them with longer lines of credit, your servers may contain enough information for the cyber criminals to target your customers, there may even be ideas, designs and other pieces of Intellectual Property that could be sold or misused in a variety of other ways, all to your disadvantage.

You know it makes sense to have stronger passwords but a lot of people, as evidenced by this list, obviously can’t be bothered – maybe they deserve what comes their way?

Well I don’t think they do, which is why I’ve published this blog post as part of “Safer Internet Day” and I’d ask you to review your password policy, both internally and personally and follow these simple tips and guidelines to minimise your risk.

Password Box

What should you do?

Don’t use the same password on every site you log in to, ideally, each site that you have an account with should have its own, unique, password. I know that sounds hard but it’s remarkably easy if you use one of the many, secure, password creation and storage sites. There are loads to choose from, some hare subscription based whist others are free. You can read a review of the top ones here.

Personally, I use LastPass, I started using it a number of years ago and find it invaluable in matters of internet security. Your password manager will automatically create strong and unique passwords and save them in your databank and automatically fill in the boxes whenever you are on one of your sites that require secure access.

Many also come as Apps for installation on your phones and tablets so that you can always access the sites you need to, whenever and wherever you are.

Crowbar

They run in your browser so that you can access your passwords and other log-in data from any internet connected computer, at home or abroad, on holiday or business trip – just make sure you remember to logout if you’re using a public computer.

If you don’t want to use an App then make sure your passwords are at least 8 characters long and are comprised of a mix of UppEr cAse and loweR case, 1nclud3 a numb3r or 2 and m@ke use of spec!al character$ wherever possible. You can check the strength of your password at HowSecureIsMyPassword

If you are concerned about any of the security aspects for your business, then send me an email, andy@enterprise-oms.co.uk or give me a call on 01793 238020 for a hack free, zero obligation chat and I’ll be delighted to see whether I can help secure your business from cyber criminals and make sure that you don’t become a victim, like Capital One did in 2019 where a hacker stole 100 million records that included names, addresses, post codes, email addresses, phone numbers, dates of birth, bank details and social security numbers.

Christmas is coming, don’t let the hackers get fat

Christmas is nearly here, people are beginning the big “wind down” and it would be so easy to let your guard down too.

Andy, checking out websites as part of his work

Well, let me tell you, the hackers and cyber criminals won’t – it anything they’ll be ratcheting up their activity because they know that our minds will be on other things.

You know, things like Christmas parties, gifts, food, television and everything else that’s associated with the season of goodwill.

So, vigilance must remain high, both in the office and when working from home. Keep your eyes open for suspicious looking emails, especially those coming from unexpected quarters, with messages that promise much, such as tax refunds or deliveries of items you don’t remember ordering. Also beware of emails with links to websites that look OK but in reality will do harm.

It’s also a good idea to take a fresh look at your password security. SplashData have just released their ninth annual “Worst Passwords of the Year” list which has been compiled from more than 5m passwords that have ended up on the Dark Web after being purloined by hackers.

Unfortunately, not a lot has changed over previous lists

  1. 123456 (same place as 2018)
  2. 123456789 (up 1 place)
  3. qwerty (a return to the top 5 for this old favourite)
  4. password (slips two places)
  5. 1234567 (up 2)
  6. 12345678 (falls out of the top 5)
  7. 12345 (falls by 2 places)
  8. iloveyou (this perennial is up 2 places from 10 in 2018)
  9. 111111 (yes, people do use this although it’s fallen 3 places from last year)
  10. abc123 (up 7 and breaking in to the top 10)

You can see passwords from 11 to 25 here.

SplashData estimates that at least 1 in 10 people have used at least one of these poor passwords.

Data breaches are inevitable but by using strong, unique passwords for each individual account that you have makes the theft of one password much less of a disaster than if you use the same (or close variant) across all of your accounts.

3 simple tips to make your digital life more secure

  1. Use passphrases (random word combinations) of 12 characters or more with mixed character types
  2. Use a different password for each of your log-ins so if you loose one password you haven’t lost all of the keys to your digital empire
  3. Use a password manager to secure your digital assets, to generate random password combinations, store them securely and make them available across all of your devices

And PLEASE, if this applies to to you – STOP USING PASSWORD or 12345678 and use one of these instead

Top Password Managers (in no particular order)

Have a great Christmas, a happy new year and I look forward to communicating with you in the new year. If you need any help, please, just ask. You can reach me by phone – 01793 238020 – email – andy@enterprise-oms.co.uk or just hunt me down on Social Media.

However, I hope to enjoy Christmas too so may be slower than normal in responding to your requests. I’ll be back in the office on January 2nd.

Yes, it’s “Password Madness” time

USer name and password box

Government Communications Head Quarters (GCHQ)- where the UK spooks provide signals intelligence to the UK’s government, military and Military Intelligence and the Department for Digital, Media and Sport (DCMS) carried out their first UK Cyber Survey and the results didn’t make for great reading.

Apparently

  • 42% of us Brits expect to lose money to on-line fraud
  • 23.2 million worldwide victims of cyber breaches used 123456 as their password
  • 15% say they know how to properly protect themselves from harmful on-line activity
  • 33% rely on friends and family for help with their cyber security
  • Young people are the most likely to be cyber aware, privacy concious and careful of the details they share on-line
  • 61% of internet users check Social Media daily, 21% say they never look at it
  • More than 50% use the same password for their email that they use elsewhere
Hacker Inside

Dr Ian Levy, NCSC Technical Director said “Using hard-to-guess passwords is a strong first step and we recommend combining three random but memorable words. Be creative and use words memorable to you, so people can’t guess your password.” whilst Margot James, DMCS Minister said “We shouldn’t make their (cyber criminals) lives easy so choosing a strong and separate password for your email account is a great practical step. “

Most Regularly Used Passwords

RankPasswordTimes Used PasswordTimes Used
1.123456 23.2m ashley432,276
2.1237567897.7m michael425,291
3.qwerty3.8m daniel368,227
4.password3.6m jessica324,125
5.11111113.1m charlie308,939

It’s a shame that the top password list hasn’t really changed for at least 10 years – it shows how complacent a lot of us are with our on-line security.

I used to have 3 passwords, a simple one that I used really casually for newspaper sign-ups etc – name123 (not my real passwords, merely examples) a medium security one that I used on shopping sites, n@m3123 and a more secure one, used for banking etc – c3ler0n! (and all of the ones that I used feature on the Have I Been Pwned list).

About 5 or more years ago I switched to a Password Manager. I have 801 log-ins and 801 different passwords. All of them are at least 16 random characters long and comprise upper & lower case letters, numbers and symbols (where permitted).

Logging On

My Password database is stored securely in the cloud and is replicated on my PC, Phone and Tablet and accessible from my Chromebook too. I use LastPass but others exist and here’s a review of some of the top ones.

As you can see, I do my best to stay on top of my security but if you feel adrift, or need some help, just give me a call on 01793 238020 or email andy@enterprise-oms.co.uk for a free chat.

What the FA is 2FA and do you need it?

Let’s answer the easy question first, “do you need 2FA”? The simple answer is “yes”, you do need Two Factor Authentication (2FA). Now read on to learn more about what it is, how it works and how it can secure your data and online activity

I’ve written in previous posts about passwords, hacking, identity theft and the threat to our privacy, data and businesses from cyber criminals. As you might imagine, the number of attacks is increasing, as is the sophistication.

Why are Cyber Attacks increasing

Simple! The number of websites that we log-in to continues to increase and many people use one password across many websites. As you can see from the list on the right a lot of people use passwords that are less than ideal. The cyber criminals know this which makes it a gift for them.

Some people think they are safe because they have 3 passwords. A simple one for common sites where they don’t see a threat (posting comments to newspaper websites for example), a medium one that they use for on-line shopping and Cloud storage sites (DropBox for example) and a really complicated one for their “secure” sites, such as bank access etc. 

After all, just trying to remember pWa#eeAS7uNggK49 is a challenge but if you have to remember a different one for every single website it becomes a real challenge. You might jot them down in a notebook or diary but what happens if you loose your book, or just leave it on a train. Not only have you been frozen out of your accounts (until you work your way through all those “forgotten password” routines) but your security has been seriously compromised.

Some people, like me for example, use password manager. These apps create a secure password for ever site that you log in to and make it available across desk-tops, lap-tops, phones and tablets and don’t cost very much at all. But even if you use one how secure are you, actually?

chocolate teapot

If a site that you use your super strong password on is penetrated and data stolen, your strong password is about as much use (from a security perspective) as the infamous chocolate teapot.

And if you have used this super-strong password on more than one site you are at an even greater risk of becoming a victim of data theft. With more than 6,474m email addresses in the wild for cyber criminals to use and 551m passwords stolen in security hacks the criminals job gets ever easier.

Use the Have I been Pwned website to see whether your passwords have been stolen by cyber criminals or nabbed in a data breach and read more about the risk, and how the criminals use this stolen data in a previous post.

What’s the Solution

It’s actually fairly simple. It’s called two factor authentication [2FA] or multi-factor authentication. This is where another layer of authentication is required, beyond your user name and password.

In the early days of 2FA sites would send you a text with an access code so you could only log-in if you had your phone with you [and had a mobile signal]. This extra layer of security hit the cyber-criminals hard, until they realised that intercepting text messages was not particularly difficult if you were tech-savvy so something else was required.

Image result for hsbc internet banking device

The banks solved this problem by providing you with a device like the one to the right, this one’s from HSBC. At the website you enter your user-name and pass-code as normal, enter a PIN in the device and then enter the displayed number from the device in to your banks website. It may feel like a pain but it really does have a positive effect on the security of your on-line banking. A criminal needs a your user name/password, access to a device as well as your device PIN

Microsoft Authenticator

Having a device for every website is pretty clunky so Microsoft and Google released authentication apps for Android and iPhones. The way they work is they generate a six digit code, as can be seen in the image on the right, and the website that you are looking to access requests this code after you have entered your user-name and password – as demonstrated in this screen-shot of my LastPass password manager.

Two Factor Authentiaction

All I have to do is launch my Authenticator App and enter the six digit password. For additional security, the code changes every 30 seconds or so

Hardware Security

Hardware 2FA security solution

The final security solution is the physical “Key” such as this one from Yubikey. This is a USB device that simply plugs in to a USB port on your computer and allows you access to secured sites – or even your computer itself.

If you are worried by your security, or need any help with your internet activity, from a new website through social media and on to other online marketing opportunities then just send me an email – andy@enterprise-oms.co.uk or give me a call on 01793 238020