Tuesday, December 12, 2017

Week 3 - Uber’s Big Secret

On November 21st, Uber disclosed that they hid a security breach that occurred a year ago, and that they paid the hacker who did it $100,000 to keep quiet. The breach exposed 57 million driver and rider accounts, which included driver licenses, telephones, email addresses, and names. It seems that Uber’s coding site was compromised and the credentials were taken to access an Amazon Web Services account which had the account information.

This incident not only broke federal and state laws but further ruin the reputation of Uber who plan to go public in 2019. It seems the company has not learned their lesson after their data breach in 2014. It’s also surprising because Uber has Joe Sullivan, a seasoned chief security officer who used to head up security at Facebook for seven years. From words of former employees, it seems that Mr. Sullivan and his chief executive Travis Kalanick decided made the decision to pay the hacker (Isaac, Benner, & Frenkel, 2017).

As outlined in FBI’s news article, paying the hackers is never the right move (2016). Even when paid, the attackers might not honor the agreement. In Uber’s case, the hacker allowed Uber access to his computer and signed a non-disclosure agreement. However, he might not have destroyed all the copies of the data and could have passed the data to another party. Also, paying off a hacker means also funding criminal activities. The hacker could use the funds to start another attack.

For drivers that had their data compromised, Uber will provide free credit and identity theft protection (Newcomer, 2017). For the rest of us, this is a learning experience. If you are the target of a ransomware attack, do not pay the ransom. No good would come out of the payment. Remember to routinely back up your data and be on the lookout for malicious links or attachment in emails. Stay vigilance, and you won’t be the next victim of an attack.

References

FBI News. (2016, April 29). Incidents of Ransomware on the Rise. Retrieved from
https://www.fbi.gov/news/stories/incidents-of-ransomware-on-the-rise/incidents-of-ransomware-on-the-rise

Issac, M., Benner, K., & Frenkel, S. (2017, Nov 21). Uber Hid 2016 Breach, Paying Hackers to Delete Stolen Data. Retrieved from https://www.nytimes.com/2017/11/21/technology/uber-hack.html

Newcomer, E. (2017, Nov 21). Uber Paid Hackers to Delete Stolen Data on 57 Million People. Retrieved from https://www.bloomberg.com/news/articles/2017-11-21/uber-concealed-cyberattack-that-exposed-57-million-people-s-data

Tuesday, December 5, 2017

Week 2 - PayPal's Subsidiary TIO Security Breach

It was recently announced that TIO Networks, owned by PayPal was breached on November 10th exposing 1.6 million customer's personal information. In this modern age, companies have to protect not only themselves but also all their subsidiaries. It is a lot of responsibility. Luckily, PayPal's data was not affected, because they were not using the TIO system of processing bill payments.  It is unknown what personal information was stolen, but credit cards and social security numbers were said to be compromised (Kovacs, 2017). TIO suspended its operation on November 10th because of security vulnerabilities in their system, but their parent company, PayPal did not issue a statement until December 1st. Since TIO is not a well-known company, PayPal should have announced the news earlier so it could bring attention to consumers who might be affected.

If you are a PayPal customer, it seems that you are safe. None of the personal data on the PayPal network were compromised. However, if your password has not changed for a while, it’s time to change it. Customers of TIO Networks who were infected by the breach will be contacted by email. They will receive a free year subscription to Experian. If their social security were compromised, they would receive two years of service (TIO Networks, 2017). The notification of the free service is just a notification, nothing more. Registering for the service is essential. Experian will provide a free credit report, active monitoring for fraud/identity theft, and theft insurance. It’s a great deal, but action needs to be taken to join the service. Don’t put it off for another day.

It must be frustrating for a publicly traded company such as TIO to have their daily business indefinitely suspended, all because of a security compromise.  Today, it's more important than ever to manage security data effectively.

References

Kovacs, E. (2017, Dec 4). Breach at PayPal Subsidiary Affects 1.6 Million Customers. Retrieved from http://www.securityweek.com/breach-paypal-subsidiary-affects-16-million-customers

TIO Networks. (2017, Dec 1). TIO Networks Provides Update on Suspension of Operations. Retrieved from http://tio.com/#consumerfaq

Zacks Equity Research. (2017, Dec 4). PayPal's Newly Acquired Unit TIO Networks Suffers Data Breach. Retrieved from https://finance.yahoo.com/news/paypal-apos-newly-acquired-unit-150303417.html

Tuesday, November 28, 2017

Week 1 - Imgur Data Breach of 1.7 Million Accounts


This Thanksgiving, when people were enjoying their turkey feast, Imgur, a popular image sharing site found out their data was compromised in 2014. This breach affected 1.7 million accounts which exposed email addresses and passwords. Fortunately, it seems that personal information such as real name, addresses, and phone numbers was not exposed. Imgur does not require private information for account registration. The breach was reported by an industry expert, Troy Hunt, from the website HaveIBeenPwned.com on Nov 23rd (Spring, 2017).The next day, Imgur sent out an email to all users to change their password, and the organization was applauded for its quick response to the situation.

If you have an account with Imgur, its important to log in to the website and change your password. The account could have been potentially compromised, and be used for malicious activity. Large image sharing sites such as Imgur can reach a broad audience. Compromised accounts could be used to spread propaganda or criminal mischiefs. Once the password is changed, the account will be secured. In 2014, passwords were stored using an old SHA-256 hashing algorithm which could be cracked by the MD5Decrypt service (Kovacs, 2017). Since then, Imgur has changed their hashing algorithm to a more secure bcrypt algorithm.

When creating an account on websites, it is important to use strong passwords which makes it tougher for brute force attacks. Take the time, and use passwords that are 8-12 characters with a mix of upper/lower case characters, numbers, and special characters. Its okay not to be able to remember the password. The secure password can be stored in an encrypted password software. Thankfully, this data breach did not disclose personal information.

References
Kovacs, E. (2017, Nov 27). Imgur Discloses 2014 Breach Affecting 1.7 Million Users.  Retrieved from http://www.securityweek.com/imgur-discloses-2014-breach-affecting-17-million-users

Sehgal, R. (2017, Nov 24). Notice of Data Breach. Retrieved from https://blog.imgur.com/2017/11/24/notice-of-data-breach/

Spring, T. (2017, Nov 27). Imgur Confirms 2014 Breach of 1.7 Million User Accounts. Retrieved from https://threatpost.com/imgur-confirms-2014-breach-of-1-7-million-user-accounts/129006/