Skip to main content

Posts

Protect Personal Information - Present and Future Value

Dear Mothers, We understand you are proud of your child. You can shout to the world that you are but please do not share your child's personal information online.

How To Detect Phishing - The Very Important Basic

You've probably already read us saying we prefer browsers over custom apps. And there's a really good reason for it. And today we'll dive into one those reason. Less than twelve hours of the time that this post is written, waves of articles online warned users that there is a widespread Phishing scam targeting Gmail users. The reality is that it's not only Gmail that is subject to this attack. All emails are. But for the time being, we'll use Gmail as a sample to illustrate a core problem. Yes, you may have guessed it already. People's mindset, misunderstanding technology and its wrong use.

Why Do People Care Less About Cybersecurity?

Imagine trying to remember 10 to 50 passwords or access credentials just to get access to things you need to work done. People do not really care less about cybersecurity. The problem is that oftentimes security implementations makes the system less usable for people. That is one of the reasons why it seems that people care less about cybersecurity. People don't really care less about cybersecurity, they are simply overwhelmed with the amount of decisions that they have to make to access their own data. People experience what is called 'decision fatigue'. It turns out, this is a known phenomenon in Psychology. This is exactly what people are experiencing and a research paper calls it 'security fatigue'

Like Farming - Not All You Like Is What It Is

Only a few people will really believe warnings such as the one we're about to quote. It goes like this:

Internet of Things is Unsafe.

We never liked the thought of having smart things. It's uncomfortable to think that something that one could carry on a palm could accomplish something far better than us humans could. Sadly, there are things that we created that could outperform our limited physical and weary souls. Yes, we acknowledge limitations because that is also the very foundation of what we are trying to achieve at Net Safety PH. There's only so much we can do to help inform people on how to better protect themselves against the dangers an increasingly connected world. We talked about things that we created or designed to outperform us, but it doesn't really start out that way. At first, it's simply to make our lives easier. Sometimes, it also starts out as some personal automation for a personal problem but all of a sudden gets applied to everybody else's somewhat related problem. Most of them are fantastic features that makes it our daily lives. Instead of visiting a friend's home...

Human Element of Cybersecurity - A Hard Case

By no means the articles in this site have tackled or discussed deeper or technical aspects of cybersecurity simply because it is not its primary purpose. As you can read in our side panel, our purpose and goal for this is: Dedicated to providing Filipinos general information about online & offline security practices and how to better protect their data & privacy. As you can clearly read, we simply aimed at providing general information to the public, specifically our fellow Filipinos. In short, our goal was to partly address the human element of cybersecurity or information security. We approached this by deliberately/consciously NOT using technical terms in our writing, avoiding lingo specific to a work culture, and keeping it generally understandable. There's an old hyped web app in social media, Facebook in this instance, happening here in PH that once again gained attention among the general public. It's the type of web app that with a person's selfie/portra...

Selfies and Vanity - Social Engineering Data Collection - Prefetching Biometric Data

How many of you would like to know what your age is according to a computer? How many of you would like to know who your celebrity look-a-like is? Did you try one of those web app? How about the mobile app? Wow! you look like that actor?! Congratulations! Wait, we have ten other friends who look like that actor? What a boring world if thousands of you actually look-a-alike one famous actor! Seriously though, it is just sad how guillible people are. It didn't even actually try to properly score similarity factor. It is sad that people just gave some other people one of the most identifiable factor about them. And the most common excuse, it is just harmless fun. Fun, Vanity - among the many of our frailties that threat actors (hackers, scammers) can exploit or use against us. Yes, our search for fun and validation can be easily used against us. Biometric authentication is gaining ground in everyday use. The commonplace fingerprint authentication is ... well, commonplace. It's n...

What is HTTPS, Encryption, and Cipher?

By now you may have heard that a secure website starts with HTTPS and not just HTTP. And you have been making sure the site is secure when you access certain resources or post sensitive data. That is well and good but there seems to be a misconception that secure automatically means legitimate or authenticate site. It is not. Just because a website uses HTTPS doesn't automatically make it the authentic and legitimate site. So what is the difference? To understand the difference let us first make sure HTTPS is understood in its basic meaning.

Vulnerability Alert - Smart TV - Spy On You

If you are one of those Smart TV owners, you may have heard already that someone can hack your TV and use it to spy on you. Haven't heard of it before?! Now you have and the only redeeming thing about the previous hack is that it required hackers physical access to your Smart TV. That poses an entirely different problem together.

Cloud VM Vulnerability - Stealing from Cache

Cloud has been the buzz for several couple of years now. Cloud server, distributed networking, automatic redundancy, and all the other stuff promoted with the adoption of "Cloud." But there really is no cloud. To us, it's just a marketing lingo. The underlying technologies used to implement "cloud" has been there for a long time, they are system administrator and network engineer domain technologies. To us, the cloud is just another rack of servers managed by someone else. To us, it's just somebody else's computer.

Scam Alert - Credit Card - Methodology is Part of Social Engineering

Just the other day, we posted Attack Example - Phishing - SMS Based - Smishing and yesterday someone in Cagayan de Oro using facebook alerted people of a Scam Modus Operandi (M.O.) Do we think it's a scam? Yes it is.

One of the Many Reasons Why Encryption is Important

Many of us don't know the standards used in implementing the complex communication technologies that enables us today. Many of us do not know or even care about encryption or its use. We may not even know about the groups or companies that fight or go against governments to ensure that people have their right to privacy. Some will say that what you don't know can't hurt you but that is more often false. Just because you don't know gravity exists doesn't make gravity harmless. Just because you don't know fire burns mean you won't be burnt. Just because you don't know that effects of a hacking vulnerability doesn't mean you won't be hacked or be affected by it.

Attack Example - Phishing - SMS Based - Smishing

What exactly is Phishing? It smells fishy, sounds like fishing, and it is exactly fishing. Knowing how social Filipinos are, almost everyone doesn't like being late in knowing who's an item in the office or who likes who, or what successful neighbors are doing to be successful. And so, we non-chalantly fish for information about it. That is exactly the core function of Phishing. It is to gather Personally Identifiable Information (PII) or information which can be used to identify individuals.

Information Security 101: Uncommon Sense

The only thing constant in this world is change and common sense is actually not common.

200M Plus iOS Accounts in Possible Danger - Back Up Now

Last March 21, 2017 - Turkish Crime Family on twitter issued a warning that 200 Million iCloud accounts will be factory reset on April 7, 2017 . By 4:02am of March 22, it reported on twitter that the number of accounts has grown to 627M. They are currently improving their infrastructure to be able to effectively cause the maximum damage it can do. The amount of 75,000 USD was initially reported to be the price for them to back-off or cancel their attack but has since refuted those reports.

Principle of Least Privilege - Basics - Explained

Let's say that one day you needed to hire a househelp. You go through the process of having that person apply for legal documentation and clearances. The person dutifully submits them in due time and come interview period, the person passed the rigorous entry process you setup. You offered and actually agreed in contract the roles the person have to do for a compensation. Then what? Do you give the person all the keys to the doors in your house?

Security Reminder: Uninstall Flash.

What exactly is Flash and why do I need to uninstall it? Flash has in the past years provided a lot of visual treat that wasn't entirely possible with other web tools or technology. For web developers back then using Flash also meant that they are at the top of their game. Unfortunately, as its use and adoption became very common, it also meant that it's a very good attack surface for malicious software or malware. Indeed it was and still is since it also became web page's video player of choice. It became so because it was a commonly installed plugin in most computers and the competing technologies weren't able to match its ubiquity or "common-ness."

Advocacy, Profession, and Association - Safe and Secure Cyber World

Did you know that there is a worldwide association focused on inspiring a safe and secure cyber world?