7 Common Online Mistakes That Put Your Privacy at Risk

7 Online Mistakes Almost Everyone Makes

It’s the everyday habits that put you at risk.

There are two types of people who go online.

  1. Those who have run into trouble or have been hacked
  2. Those who have (luckily) managed to avoid any issues

We say “lucky” because the majority of people are “guilty” of online behavior that tends to put them at risk, even if they don’t realize it. It’s not that they are going to dangerous websites or falling for every scam they get in an email—most people know how to avoid those situations.

Here are the simple, innocent online habits you may have that could put you at risk.

Browsing on public Wi-Fi without protection

Danger: Unsecured networks are open to hackers.

Using an unsecure network at a coffee house or airport can be somewhat like reading a book or writing in your diary or personal journal with someone looking over your shoulder. We ALL love and appreciate free Wi-Fi and most of us need Internet access wherever we go. But with a few pieces of hidden hardware and software, a hacker sitting nearby can read all of your traffic.

If you use a hotspot, make it a point never do any important or private online transactions. The best advice? Sign up for a personal VPN account and use it every time you go online, especially when using free Wi-Fi.

Falling behind on browser updates

Danger: Hackers exploit browser flaws when they know of them.

Your Internet browser (Chrome, Firefox, Safari, etc.), is susceptible to hacks by bad guys, just like any other program. Here was the scary, and very real, headline on a security website in Dec. 2016: “Mozilla and Tor Warn of Critical Firefox Vulnerability, Urge Users to Update.” When there’s a weakness in any program, including browsers, hackers are there to jump on it. The good news is that browsers try to stay a step ahead of trouble by releasing updates regularly. When was the last time you updated the browsers you use? Probably not recently enough. Don’t wait for update alerts. Get the latest versions and updates now.

Sharing too many details on social media

Danger: It hands over personal information to those who might exploit it.

There are some people who totally avoid having any exposure on social media. They tend to be looked at as out of touch and behind the times. But one thing is for sure: they’re protecting themselves and limiting the amount of information that someone—anyone—could use to build a social profile on them and exploit their identity. Is that a stretch and a little paranoid? Maybe. But cybercrime consultants DO suggest you limit how much you tell the world about life, travels, interests and family online. Why? Because there are some out there who will use that information to impersonate you, trick you, or steal your identity…or your money.

Using the same password for different online accounts

Danger: If a hacker steals one password, he has access to the other accounts.

This is probably one area where almost everyone is guilty to some degree. The problem isn’t with a small-time hacker; it’s with the major hacks (Target, Home Depot, Yahoo, JP Morgan, for example) where thousands of usernames and emails are stolen at one time. Systematically, the same hackers will use the stolen “credentials” to unlock other accounts. For people who use the same password, their other accounts are at risk too. Are you using the same password for different accounts today? If so, change that.

Using passwords that are easy to break

Danger: It will be broken in a sophisticated hack attack.

There are two levels of simple passwords that hackers love. The first category is filled with “password,” “abcde,” “12345,” and the like. Oh, and your name or nickname. The second category is the simple words or common terms that sophisticated hackers can get to in a matter of minutes, using fancy programs. A long password with a combination of letters, symbols and numbers (that makes no sense!) is virtually unbreakable.

Not installing program updates automatically

Danger: A virus that could have been blocked sneaks into your unprotected system.

Because Microsoft Windows has the highest market share, and it has many versions in operation, it is the operating system most probed for vulnerabilities…and attacked. That’s why Microsoft continuously makes updates and “patches” available for Windows. In fact, all program developers send out updates to combat any flaws in their code that could be exploited. You can set your PC on “automatic update” to ensure that you get every Windows’ update automatically. However, if you fail to update your operating system routinely—or if you forget to check for and download updates manually—you’re putting your computer at risk. Get into the habit of updating your system’s software when the manufacturer sends an update prompt or alert.

Opening links from e-mails without taking a close look

Danger: You can allow a virus into your computer with just a click.

Imagine receiving a package in the mail containing a poisonous chemical intended to hurt you. (Thankfully, that’s a rare occurrence.) But most of us would be eager (or curious) simply to see what’s inside a box on our doorsteps, and that’s where we’d get hurt. Every day, millions of people get email (electronic letters) that contain a link to a file that is intended to infect our computer. The tricksters use emails or subject lines that sound normal, and they count on you being distracted, or busy or curious. Millions of people, every day, click on those links and download malware, viruses and more. These days, it’s very important to take a close look at any emails that arrive in your inbox.

5 Essential Network Security Steps for Protecting Your Business

Every week, publications such as The Wall Street Journal and business sections of major city newspapers report the latest incidents of corporate hacking. As it turns out, the problem isn’t caused exclusively by a growing number of hackers armed with new tools and strategies.

The companies being hacked make their own contributions to their security problems.

According to research and statistics, too many American companies—of all sizes—fail to follow some basic, or at least simple, security principles like IP security. Those oversights give hackers the opportunity to do their dirty work.

An article published in a special WSJ report entitled “What Companies Should be Doing to Protect Their Computer Systems—but Aren’t” revealed the common mistakes companies make that increase their risk of attack.

For illustration, here are some of the statistics that show where many companies fall short. (Note: The numbers came from the 2015 “Verizon Data Breach Investigations Report.”) Of a select number of large American companies surveyed, the results found:

  • 37% of IT professionals say insufficient funding of IT security led to a breach.
  • Only 55% of companies say they encrypt their outgoing email.
  • Only half reported conducting security awareness training.
  • More than half (55%) admitted not being able to discover where the breach had occurred.
  • Just under half (44%) said malware was involved in the hack.

This information is unsettling to businesses and consumers alike. Most of the public would expect that companies would do everything they could to protect their data. After all, company data is often consumer data too: names, addresses, email addresses, account numbers, and so on. If companies are collecting your data, they should be doing as much as they can to protect it.

Five changes companies should make now.

Based on the opinions of security experts, the WSJ article listed five measures companies should consider to help reduce the threat or incidence of data attack. These are steps that every company should take, but simply don’t, for a variety of reasons:

Keep up to date with security patches.

All businesses rely on complex computer systems to manage their business data. Business software and computer operating systems are complex, and it’s common for software to have flaws that go unnoticed for long periods. In 2010, Microsoft released a fix, or “patch,” when a flaw was discovered in their operating systems. However, many businesses simply failed to update their software to fix the problem. Hackers who knew about the flaw exploited the software weakness and successfully attacked companies who hadn’t installed the patch. More than that, patches are released whenever problems are detected, so there are often multiple patches to install. If companies fall behind with their updates, that gives hackers more ways to get into a system. Simply keeping up with updates goes a long way toward keeping hackers on the outside, looking for easier targets.

Keep tabs on every device with an Internet connection.

It’s hard to imagine how many computers a large company might have. The problem is, companies simply don’t know how many they have and, more importantly, how many are connected to the Internet at any one time. The Verizon Security Survey reported that 25% of the security breaches occurred when hackers obtained system access through a device that didn’t need to be online, or online at the time. Last year the HealthCare.gov system was attacked through a Web-development server that wasn’t designated to be online; therefore, it didn’t have strong security protections in place. The hackers essentially came through a system door that was “left open” accidentally. These days, many devices such as printers, thermostats and lights have Internet connections, but not many have strong security safeguards in place because they’re “not computers.” That’s a mistake. Companies should make sure that any computer or device that has an Internet connection is secure and not easily hacked.

Encrypt all data.

Automatically scrambling and coding data to make it unreadable is called encryption. One security expert has been quoted to say, “You can’t rely on people. You have to rely on technology.” What he meant was this: It doesn’t matter if you have all the brightest IT talent if they aren’t doing everything to encrypt your company’s data. For example, in California from 2013—14, 25% of the data that was reported stolen was NOT encrypted. Everyone knows encryption works, so why don’t companies do it? Some reasons are cost, complexity and time. It’s not cheap to acquire and implement the latest technologies, and company executives might be slow to approve funding. That could be dangerous, as Home Depot, unfortunately, found out: They were in the process of implementing technology to encrypt customer credit/debit cards when hackers attacked, gaining access to 56 million account numbers. They weren’t fully aware of the hack for some time, either. The lesson to learn? Encrypt all sensitive customer and company data or face a real risk of losing it.

Educate staff on strong passwords.

Passwords are a pain to remember and annoying to change. It’s not uncommon for some people to have more than 100 passwords for different accounts. To make life easier, many people use the same (or very similar) passwords for different accounts. Facebook made many of their customers change passwords after Adobe was hacked…because it was discovered that many Adobe customers who had Facebook accounts used the same passwords for both websites. Hackers count on weak passwords, duplicate passwords, laziness and apathy. It works: They can often guess or determine passwords with simple programs. A company that requires employees to create new and unique passwords routinely is less likely to be a victim of the most basic of attacks.

Screen vendors. Choose wisely.

Because of recent high-profile attacks, more companies are discussing IT security at the highest levels and beefing up their defenses. That’s good news and a step in the right direction. However, large companies have working online relationships with hundreds of vendors, from lawyers and accountants to air-conditioning contractors. And often those third-party contractors don’t have the same level of security in their online systems. That gives hackers a chance to infiltrate a company through a “side door”—a vendor’s hacked connection. In fact, more than half of all large data breaches may be coming from vendors/third parties with online access to the real target. That’s how hackers breached the computer systems of Target, the Home Depot, and Goodwill Industries. The solution? You need to evaluate vendors on their security history, especially if you give them access to sensitive systems that hackers will target, such as accounts receivable. Don’t hesitate to ask vendors all of the tough IT questions and have a security consultant or expert examine their answers.

As the headline in the WSJ article read, “Sometimes the simplest things make all the difference.” So before your company takes on a huge security project, make sure the simplest security “checkboxes” are reviewed. Closing a few open doors is the best way to start your next security effort.

Information for this article was sourced from The Wall Street Journal.
Journal Report: INFORMATION SECURITY. April 20, 2015.

Conclusion

If you commit to not making any of the above mistakes, you will reduce the likelihood of falling into a hacker’s simplest traps. Remember, cybercrooks look for cracks in hardware and software. If you put up a solid defense, they’ll move on to the next computer and user, hoping to find an easy target.

Related Articles