60
Personal CyberSecurity Protecting Yourself from the Evils of the Internet Steve McEvoy March 6 th , 2020 Austin, TX

Personal CyberSecurity - Protecting yourself from the ... McEvoy Dolphin Users Meeting 2020...if your username & password have been leaked into the wild? •Security Expert from Microsoft

  • Upload
    others

  • View
    3

  • Download
    0

Embed Size (px)

Citation preview

Page 1: Personal CyberSecurity - Protecting yourself from the ... McEvoy Dolphin Users Meeting 2020...if your username & password have been leaked into the wild? •Security Expert from Microsoft

Personal CyberSecurityProtecting Yourself from the Evils of the Internet

Steve McEvoyMarch 6th, 2020

Austin, TX

Page 2: Personal CyberSecurity - Protecting yourself from the ... McEvoy Dolphin Users Meeting 2020...if your username & password have been leaked into the wild? •Security Expert from Microsoft

The Internet has some scary s**t going on

This is a self defense course

Page 3: Personal CyberSecurity - Protecting yourself from the ... McEvoy Dolphin Users Meeting 2020...if your username & password have been leaked into the wild? •Security Expert from Microsoft

Goals

Page 4: Personal CyberSecurity - Protecting yourself from the ... McEvoy Dolphin Users Meeting 2020...if your username & password have been leaked into the wild? •Security Expert from Microsoft

What is the #1 Security Risk to your Practice?

Page 5: Personal CyberSecurity - Protecting yourself from the ... McEvoy Dolphin Users Meeting 2020...if your username & password have been leaked into the wild? •Security Expert from Microsoft

Holiday Ransomware Attacks

Page 6: Personal CyberSecurity - Protecting yourself from the ... McEvoy Dolphin Users Meeting 2020...if your username & password have been leaked into the wild? •Security Expert from Microsoft
Page 7: Personal CyberSecurity - Protecting yourself from the ... McEvoy Dolphin Users Meeting 2020...if your username & password have been leaked into the wild? •Security Expert from Microsoft

Title

Page 8: Personal CyberSecurity - Protecting yourself from the ... McEvoy Dolphin Users Meeting 2020...if your username & password have been leaked into the wild? •Security Expert from Microsoft
Page 9: Personal CyberSecurity - Protecting yourself from the ... McEvoy Dolphin Users Meeting 2020...if your username & password have been leaked into the wild? •Security Expert from Microsoft

The Dental Record

Page 10: Personal CyberSecurity - Protecting yourself from the ... McEvoy Dolphin Users Meeting 2020...if your username & password have been leaked into the wild? •Security Expert from Microsoft

How did it Happen?

Dental Office

Backup Vault in PercsoftOffice

Your In Office File Server with your Data

Page 11: Personal CyberSecurity - Protecting yourself from the ... McEvoy Dolphin Users Meeting 2020...if your username & password have been leaked into the wild? •Security Expert from Microsoft

How did it Happen?Un-

Dental OfficeOver 400 !!

Opened the Vault and Deleted EveryonesBackups, Then Sent a Ransomware commend to each clients server

Server was then encrypted and all your files locked up and held for Ransom

Page 12: Personal CyberSecurity - Protecting yourself from the ... McEvoy Dolphin Users Meeting 2020...if your username & password have been leaked into the wild? •Security Expert from Microsoft

Discovered Monday Aug 26th

Page 13: Personal CyberSecurity - Protecting yourself from the ... McEvoy Dolphin Users Meeting 2020...if your username & password have been leaked into the wild? •Security Expert from Microsoft

9 Days Later – Sept 3rd

Page 14: Personal CyberSecurity - Protecting yourself from the ... McEvoy Dolphin Users Meeting 2020...if your username & password have been leaked into the wild? •Security Expert from Microsoft

17 Days Later – Sept 11th

Page 15: Personal CyberSecurity - Protecting yourself from the ... McEvoy Dolphin Users Meeting 2020...if your username & password have been leaked into the wild? •Security Expert from Microsoft

Thanksgiving Weekend

Page 16: Personal CyberSecurity - Protecting yourself from the ... McEvoy Dolphin Users Meeting 2020...if your username & password have been leaked into the wild? •Security Expert from Microsoft

Christmas Eve

Page 17: Personal CyberSecurity - Protecting yourself from the ... McEvoy Dolphin Users Meeting 2020...if your username & password have been leaked into the wild? •Security Expert from Microsoft

• Have your own LOCAL backup strategy in addition to a Cloud based backup

• Talk about this to your IT Person and ask them if this can happen to them/you

• Care about this!

What Should You Do?

Page 18: Personal CyberSecurity - Protecting yourself from the ... McEvoy Dolphin Users Meeting 2020...if your username & password have been leaked into the wild? •Security Expert from Microsoft

• Stop and Think Hard about their own security measures

• Store your passwords in a secure database

• Require any form of remote access/control of your computers needs 2 factor authentication

• Train their staff on phishing scams and good security Practices

What Should They Do?

Page 19: Personal CyberSecurity - Protecting yourself from the ... McEvoy Dolphin Users Meeting 2020...if your username & password have been leaked into the wild? •Security Expert from Microsoft

What about your Phone?

Page 20: Personal CyberSecurity - Protecting yourself from the ... McEvoy Dolphin Users Meeting 2020...if your username & password have been leaked into the wild? •Security Expert from Microsoft

Always Update Your Phone

Page 21: Personal CyberSecurity - Protecting yourself from the ... McEvoy Dolphin Users Meeting 2020...if your username & password have been leaked into the wild? •Security Expert from Microsoft

How can you knowif your username & password have been

leaked into the wild?

Page 22: Personal CyberSecurity - Protecting yourself from the ... McEvoy Dolphin Users Meeting 2020...if your username & password have been leaked into the wild? •Security Expert from Microsoft

• Security Expert from Microsoft• Searched the Dark Web• Compiled a list of ~8 Billion hacked

accounts

• Created “Have I been pwned?” website– ‘Pwned’ is a slang term

• Securely check if your username and passwords has been stolen

Troy Hunt

Page 23: Personal CyberSecurity - Protecting yourself from the ... McEvoy Dolphin Users Meeting 2020...if your username & password have been leaked into the wild? •Security Expert from Microsoft

www.HaveIBeenPwned.com

Page 24: Personal CyberSecurity - Protecting yourself from the ... McEvoy Dolphin Users Meeting 2020...if your username & password have been leaked into the wild? •Security Expert from Microsoft

Have I Been Pwned?

Page 25: Personal CyberSecurity - Protecting yourself from the ... McEvoy Dolphin Users Meeting 2020...if your username & password have been leaked into the wild? •Security Expert from Microsoft

Is your Password Pwn’d?

(starwars)

Page 26: Personal CyberSecurity - Protecting yourself from the ... McEvoy Dolphin Users Meeting 2020...if your username & password have been leaked into the wild? •Security Expert from Microsoft

Pre-check your new passwords

(MyReallyHardPassword)

Page 27: Personal CyberSecurity - Protecting yourself from the ... McEvoy Dolphin Users Meeting 2020...if your username & password have been leaked into the wild? •Security Expert from Microsoft

• Get notified if your email(s) show up in the future

Get Notified of pwnage

Page 28: Personal CyberSecurity - Protecting yourself from the ... McEvoy Dolphin Users Meeting 2020...if your username & password have been leaked into the wild? •Security Expert from Microsoft

I was Notified of pwnage

Page 29: Personal CyberSecurity - Protecting yourself from the ... McEvoy Dolphin Users Meeting 2020...if your username & password have been leaked into the wild? •Security Expert from Microsoft

How long will it take for a Hacker to

break through my password?

Page 30: Personal CyberSecurity - Protecting yourself from the ... McEvoy Dolphin Users Meeting 2020...if your username & password have been leaked into the wild? •Security Expert from Microsoft

www.howsecureismypassword.net

(starwars)

Page 31: Personal CyberSecurity - Protecting yourself from the ... McEvoy Dolphin Users Meeting 2020...if your username & password have been leaked into the wild? •Security Expert from Microsoft

What makes a GOOD Password??

Page 32: Personal CyberSecurity - Protecting yourself from the ... McEvoy Dolphin Users Meeting 2020...if your username & password have been leaked into the wild? •Security Expert from Microsoft

• Recently updated their recommended digital identity standard (SP 800-63)

• Troy Hunt canvased NIST and others to derive what the collective wisdom is thinking

Page 33: Personal CyberSecurity - Protecting yourself from the ... McEvoy Dolphin Users Meeting 2020...if your username & password have been leaked into the wild? •Security Expert from Microsoft

• 12 or more characters

• We can use short dictionary words

• 3 or 4 random words

Length Matters

Page 34: Personal CyberSecurity - Protecting yourself from the ... McEvoy Dolphin Users Meeting 2020...if your username & password have been leaked into the wild? •Security Expert from Microsoft

dog

beerhat

red

tree

bill

head

Page 35: Personal CyberSecurity - Protecting yourself from the ... McEvoy Dolphin Users Meeting 2020...if your username & password have been leaked into the wild? •Security Expert from Microsoft

Nothing Personal

spouse

kidsfood

movie

birthday

address

date

petsphone

Page 36: Personal CyberSecurity - Protecting yourself from the ... McEvoy Dolphin Users Meeting 2020...if your username & password have been leaked into the wild? •Security Expert from Microsoft

dog

beerhat

red

tree

bill

head

3 or 4 Short Random Words

doghatbeerhead

Page 37: Personal CyberSecurity - Protecting yourself from the ... McEvoy Dolphin Users Meeting 2020...if your username & password have been leaked into the wild? •Security Expert from Microsoft

Make ‘em Memorable• Think up something about the site• i.e. Wells Fargo

– dumb wagon horses– ripping off clients– stashing my cash

Page 38: Personal CyberSecurity - Protecting yourself from the ... McEvoy Dolphin Users Meeting 2020...if your username & password have been leaked into the wild? •Security Expert from Microsoft

• dumbwagonhorses– 15 characters– 3 random words– dumbwagonhorses is better than Sj7$qq#56

But what is wrong with this?

Page 39: Personal CyberSecurity - Protecting yourself from the ... McEvoy Dolphin Users Meeting 2020...if your username & password have been leaked into the wild? •Security Expert from Microsoft

• They ‘Evolve’

• Websites, banks, etc. will need to learn and adopt these standards

• dumbwagonhorses wouldn’t meet their current ‘complexity checker’

Standards Don’t Change Overnight

Page 40: Personal CyberSecurity - Protecting yourself from the ... McEvoy Dolphin Users Meeting 2020...if your username & password have been leaked into the wild? •Security Expert from Microsoft

Starting TODAY! (2020 and on)– Three or Four unassociated dictionary words– At LEAST 12 characters in length– Capitalize First Letters– Add a 2 digit year to the end (reminder)

Steve’s Recommendation(Simple Complexity)

DumbWagonHorses20

Page 41: Personal CyberSecurity - Protecting yourself from the ... McEvoy Dolphin Users Meeting 2020...if your username & password have been leaked into the wild? •Security Expert from Microsoft

• DumbWagonHorses20– 2 Trillion Years to Hack

– Should meet the Banks requirements– Much easier to remember

Simple Complexity Works

Page 42: Personal CyberSecurity - Protecting yourself from the ... McEvoy Dolphin Users Meeting 2020...if your username & password have been leaked into the wild? •Security Expert from Microsoft

Where to Save Passwords?

Page 43: Personal CyberSecurity - Protecting yourself from the ... McEvoy Dolphin Users Meeting 2020...if your username & password have been leaked into the wild? •Security Expert from Microsoft

Bad IdeasMy Passwords

Bank …Starbucks …Credit Cards ….

Page 44: Personal CyberSecurity - Protecting yourself from the ... McEvoy Dolphin Users Meeting 2020...if your username & password have been leaked into the wild? •Security Expert from Microsoft

PasswordManager App

Page 45: Personal CyberSecurity - Protecting yourself from the ... McEvoy Dolphin Users Meeting 2020...if your username & password have been leaked into the wild? •Security Expert from Microsoft

• Available Everywhere we are:– Phones (iOS and Android)– Computer (Windows, Mac, Web)

• Sync’d across all my devices– Means linked to Cloud

Features for a Password Manager

Page 46: Personal CyberSecurity - Protecting yourself from the ... McEvoy Dolphin Users Meeting 2020...if your username & password have been leaked into the wild? •Security Expert from Microsoft

• Secure!– Especially if Cloud!– Encrypted– Smart Company– Reliable Company

• Free! ?– Free is bad– Affordable is good.

Features for a Password Manager

Page 47: Personal CyberSecurity - Protecting yourself from the ... McEvoy Dolphin Users Meeting 2020...if your username & password have been leaked into the wild? •Security Expert from Microsoft
Page 48: Personal CyberSecurity - Protecting yourself from the ... McEvoy Dolphin Users Meeting 2020...if your username & password have been leaked into the wild? •Security Expert from Microsoft

• Personal

• Family

• Teams

1Password.com Versions

Page 49: Personal CyberSecurity - Protecting yourself from the ... McEvoy Dolphin Users Meeting 2020...if your username & password have been leaked into the wild? •Security Expert from Microsoft

• “Vaults” hold your passwords• You control who has access to a specific

vault

Vaults

Page 50: Personal CyberSecurity - Protecting yourself from the ... McEvoy Dolphin Users Meeting 2020...if your username & password have been leaked into the wild? •Security Expert from Microsoft

• Three Keys to access– Username– Password– Encryption Key

• 2 Factor Authentication

• Notifications of Access

1Password Security

Page 51: Personal CyberSecurity - Protecting yourself from the ... McEvoy Dolphin Users Meeting 2020...if your username & password have been leaked into the wild? •Security Expert from Microsoft

• They cannot see your data - ever– Encrypted blob on their servers

• Travel Mode– Prevents border inspection access to your

private data

1Password Security

Page 52: Personal CyberSecurity - Protecting yourself from the ... McEvoy Dolphin Users Meeting 2020...if your username & password have been leaked into the wild? •Security Expert from Microsoft

• $3 per month

• 1 Vault

• Unlimited items

1Password Personal

Page 53: Personal CyberSecurity - Protecting yourself from the ... McEvoy Dolphin Users Meeting 2020...if your username & password have been leaked into the wild? •Security Expert from Microsoft

• $5 per month for whole family

• Up to 5 Family Members included– More Kids? $1 extra per month

• Private and Shared Vaults

1Password Family

Page 54: Personal CyberSecurity - Protecting yourself from the ... McEvoy Dolphin Users Meeting 2020...if your username & password have been leaked into the wild? •Security Expert from Microsoft

Shared Vaults

Shared

NetflixAmazonSpotifyWiFi CodeBike Lock Code

Private(only you can see contents)

Page 55: Personal CyberSecurity - Protecting yourself from the ... McEvoy Dolphin Users Meeting 2020...if your username & password have been leaked into the wild? •Security Expert from Microsoft

• $4 per month per user

• Up to 5 Guest Accounts– A guest can only access one vault

• Unlimited Vaults

1Password Teams

Page 56: Personal CyberSecurity - Protecting yourself from the ... McEvoy Dolphin Users Meeting 2020...if your username & password have been leaked into the wild? •Security Expert from Microsoft

Using Teams

HR

Payroll ServicesIndeed Job Postings

Private

Finance

QuickBooksBanks

Clinical

InvisalignPatient Reward HubShared

WiFiNetflix

PM LoginWindows Login

Page 57: Personal CyberSecurity - Protecting yourself from the ... McEvoy Dolphin Users Meeting 2020...if your username & password have been leaked into the wild? •Security Expert from Microsoft

Demo

Page 58: Personal CyberSecurity - Protecting yourself from the ... McEvoy Dolphin Users Meeting 2020...if your username & password have been leaked into the wild? •Security Expert from Microsoft

• iPhones and iPads

• Android Phones and Tablets

• Windows PCs

• Mac’s

Apps for Everything

Page 59: Personal CyberSecurity - Protecting yourself from the ... McEvoy Dolphin Users Meeting 2020...if your username & password have been leaked into the wild? •Security Expert from Microsoft

• Talk to your IT people about the possibility of them being the weak link.

• Update your Phones when prompted

• Check if you’ve been Pwned• Use new Simple Complexity Passwords• Use a Password Manager

Take Aways…..

Page 60: Personal CyberSecurity - Protecting yourself from the ... McEvoy Dolphin Users Meeting 2020...if your username & password have been leaked into the wild? •Security Expert from Microsoft

Thank You!

[email protected]

Presentation online at www.mmeconsulting.com/Presentations