{"id":3869,"date":"2015-10-24T13:51:34","date_gmt":"2015-10-24T13:51:34","guid":{"rendered":"http:\/\/really.zonky.org\/?p=3869"},"modified":"2015-10-24T14:00:47","modified_gmt":"2015-10-24T14:00:47","slug":"dont-take-your-security-advice-from-the-media","status":"publish","type":"post","link":"https:\/\/really.zonky.org\/?p=3869","title":{"rendered":"Don&#8217;t Take Your Security Advice From The Media"},"content":{"rendered":"<p>\n\t<a href=\"https:\/\/i0.wp.com\/really.zonky.org\/wp-content\/uploads\/Rusty_Padlock.jpg\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" alt=\"Rusty_Padlock\" class=\"aligncenter size-large wp-image-3872\" height=\"465\" src=\"https:\/\/i0.wp.com\/really.zonky.org\/wp-content\/uploads\/Rusty_Padlock-1024x685.jpg?resize=695%2C465\" width=\"695\" srcset=\"https:\/\/i0.wp.com\/really.zonky.org\/wp-content\/uploads\/Rusty_Padlock.jpg?w=1024&amp;ssl=1 1024w, https:\/\/i0.wp.com\/really.zonky.org\/wp-content\/uploads\/Rusty_Padlock.jpg?resize=300%2C201&amp;ssl=1 300w\" sizes=\"auto, (max-width: 695px) 100vw, 695px\" \/><\/a>Related to my rant regarding the TalkTalk hack that I&#39;ve just posted, is an associated rant about security advice from the media. It&#39;s spotty at best, and downright unhelpful or just plain wrong at worst.\n<\/p>\n<p>\n\tI&#39;ve been stuck indoors today waiting for someone to paint my front door, so amongst various household tasks that I&#39;ve reluctantly undertaken, I&#39;ve also had the BBC News 24 channel blaring out. And of course the TalkTalk hacking incident has been making a regular appearance. And on occasions the security advice has been less than stellar; in fact some of it stinks like a rhino&#39;s rancid rectum.\n<\/p>\n<h2>\n\tIt Was A DDoS<br \/>\n<\/h2>\n<p>\n\t(bang) as my head hits the table.\n<\/p>\n<p>\n\tNo, the TalkTalk hack had nothing at all to do with a distributed denial of service attack. There&nbsp;<em>may<\/em>&nbsp;have been a DDoS attack just before the hacking incident, but it was not related (even if it was done by the same people). A DDoS attack is the cyber equivalent of getting all your friends to shout at someone you don&#39;t like; it&#39;s noisy, stops you communicating, and is as annoying as hell.\n<\/p>\n<p>\n\tBut once it is over, things are back to normal (except for writing an incident report).&nbsp;\n<\/p>\n<p>\n\tBreaking into a server and stealing the personal data of customers is&nbsp;<em>not<\/em>&nbsp;any kind of denial of service attack. It&#39;s an intrusion, and an exfiltration; there are two seperate events there. Labelling either as a &quot;DDoS&quot; just makes you look like an idiot.\n<\/p>\n<h2>\n\tLook At The Email Headers<br \/>\n<\/h2>\n<p>\n\t(bang) as my head hits the table.\n<\/p>\n<p>\n\tEmail headers can be forged; those headers you see normally (&quot;From&quot;, &quot;Subject&quot;, &quot;Date&quot;, etc.) are&nbsp;<em>nothing<\/em>&nbsp;more than comments. They are not to be trusted. Even if you reveal the hidden headers (and there&#39;s a lot you don&#39;t see), the story they show can be mostly forged. It takes a&nbsp;<em>real<\/em>&nbsp;expert to distinguish between a phishing email and a legitimate email from just the headers.\n<\/p>\n<p>\n\tEven something geeky like PGP digital signatures can be forged&nbsp;<em>if<\/em>&nbsp;you are dealing with an organisation that has been compromised. And who uses PGP?\n<\/p>\n<p>\n\tDon&#39;t trust emails with the name of a compromised organisation on. &nbsp;\n<\/p>\n<h2>\n\tChange Your Passwords As Frequently As Possible<br \/>\n<\/h2>\n<p>\n\t(bang) as my head hits the table.\n<\/p>\n<p>\n\tChanging you password frequently doesn&#39;t actually accomplish that much. It is better to keep the same password for a year, if it is long and strong, than it is to change your password every month if it is simple and weak.\n<\/p>\n<p>\n\tLong and strong passwords are tedious to remember &#8211; especially for web sites you rarely use. So use a password manager like <a href=\"http:\/\/keepass.info\/\">KeePass<\/a>. If you want to use a different password manager, seek out a security geek and ask for their recommendations. And the geekier the application site looks, the better; the site should be droning on about 3DES, AES, and all sorts of inscrutable cryptogeek mathematics; you don&#39;t have to understand it all, but it&#39;s absence on a web site is a bad sign.\n<\/p>\n<p>\n\tUse different passwords on different sites. This is also tedious, and can be relaxed for less important web sites &#8211; that is those web sites that don&#39;t store more personal information about you than your name. And tedious is a good thing when it saves you from the stress of finding out your bank accounts are empty.\n<\/p>\n<h2>\n\tDon&#39;t Blame The Victim<br \/>\n<\/h2>\n<p>\n\tIt&#39;s all very well being sympathetic to those victims who have found their bank accounts emptied, but they are not necessarily related to this latest incident.\n<\/p>\n<p>\n\tAnd they&#39;re not entirely blameless.&nbsp;\n<\/p>\n<p>\n\tIf they hadn&#39;t shared information with hackers who already had some of their data, or they had not used the same password for their bank as TalkTalk, then they would not be victims.\n<\/p>\n<p>\n\tAnd this is hardly new advice.\n<\/p>\n<p>\n\tThe media should be sending the message that these victims have been dumb; yes there may be extenuating circumstances, but they have still been dumb. And dumb TalkTalk customers will likely end up with their money and\/or identity stolen.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Related to my rant regarding the TalkTalk hack that I&#39;ve just posted, is an associated rant about security advice from the media. It&#39;s spotty at best, and downright unhelpful or just plain wrong at worst. I&#39;ve been stuck indoors today waiting for someone to paint my front door, so amongst various household tasks that I&#39;ve <a href='https:\/\/really.zonky.org\/?p=3869' class='excerpt-more'>[&#8230;]<\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":false,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2},"_share_on_mastodon":"0"},"categories":[4,12,489],"tags":[],"class_list":["post-3869","post","type-post","status-publish","format-standard","hentry","category-it","category-media","category-security","category-4-id","category-12-id","category-489-id","post-seq-1","post-parity-odd","meta-position-corners","fix"],"share_on_mastodon":{"url":"","error":""},"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/p1f2KI-10p","_links":{"self":[{"href":"https:\/\/really.zonky.org\/index.php?rest_route=\/wp\/v2\/posts\/3869","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/really.zonky.org\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/really.zonky.org\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/really.zonky.org\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/really.zonky.org\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=3869"}],"version-history":[{"count":5,"href":"https:\/\/really.zonky.org\/index.php?rest_route=\/wp\/v2\/posts\/3869\/revisions"}],"predecessor-version":[{"id":3875,"href":"https:\/\/really.zonky.org\/index.php?rest_route=\/wp\/v2\/posts\/3869\/revisions\/3875"}],"wp:attachment":[{"href":"https:\/\/really.zonky.org\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=3869"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/really.zonky.org\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=3869"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/really.zonky.org\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=3869"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}