TikTok Update: Dangerous Viral Challenges & Age Restrictions

TikTok Update: Dangerous Viral Challenges & Age Restrictions

It’s popular. It’s uplifting. It’s creative. It’s entertaining. It can also be risky.

All these words equally describe TikTok, the wildly popular social network that allows teens to create and share videos and find critical connections during isolating times. So what makes TikTok both amazing and potentially risky at the same time? It isn’t the app itself but, rather, the way some kids choose to use it.

Several of those risky behaviors making headlines lately include the all-too-familiar topic of viral challenges. The secondary risk? Underage users’ common practice of bypassing TikTok’s age restrictions, which can put them in harm’s way. In 2020, TikTok classified more than a third of its 49 million daily users in the U.S. as being 14 years old or younger.

A recent webinar hosted by Cyberwise featuring Rick Andreoli, Editor-in-Chief at Parentology, and Pamela Rutledge, director of the Media Psychology Research Center, highlighted the risks of some of the latest challenges. (Listen to the full discussion here). Here are just a few of the many challenges parents should know about.

Popular TikTok Challenges

The blackout challenge. The draw to this challenge is somewhat new to TikTok but familiar in the online challenge realm. It involves users live-streaming themselves as they cut off their air supply to the point of losing consciousness. Sadly, this challenge recently had deadly consequences for a 10-year-old TikTok user, according to Newsweek reports. The incident prompted an outcry for the platform to ban users with unconfirmed ages.

Skullbreaker/trip jump challenge. TikTok users carry out this challenge in various ways, but one of the most common includes three friends side-by-side. As the video begins, everyone jumps or dances as pre-planned, only one kid is targeted to go down as the other two swipe the legs out from under them, causing either a face plant or a backward fall. This popular challenge has resulted in several medical emergencies.

The outlet or penny challenge. Fire officials have issued public cautions around this challenge, which involves sliding a penny into a partially plugged-in phone charger or cord. The goal? See who can record and post the biggest sparks or, yes, flames.

Coronavirus challenge. Here’s a challenge that thankfully didn’t gain too much traction before TikTok banned it. It was created by several “influencers” and encouraged TikTok users to post videos of themselves defying the Coronavirus by licking public objects — such as toilets and grocery store items.

TikTok Safety Basics  

  • Oversee apps, add parental controls. TikTok advises parents to “oversee your teen’s internet use, including any apps they may download . . . the full TikTok experience is for users 13 and over . . . use parental controls to simply block our apps from your child’s phone.” (We couldn’t agree more, TikTok!)
  • Adhere to TikTok age restrictions; explore options. Kids may view age restrictions as just another silly rule standing in the way of their fun. This is where you can talk about the very real dangers being reported and why the age restriction exists. Too, explore other connection options on TikTok designed to equip younger users. For instance, TikTok has an “under 13” section of the app that restricts access to mature content. Another option is to open a parent/child-owned TikTok account using the new Family Safety Mode. This will allow you to teach a younger child how to use the app safely — and talk about potential danger zones.
  • Adjust Settings. Consider requiring your child to keep their account private (circle back to ensure it stays private). To make an account private, change the Settings for comments, duets, reactions, and messages to “friends” instead of “everyone.”
  • Open a TikTok account. To gain a better understanding of the TikTok culture, open your own account and look around. Let your child know you have an account but think about refraining from following them or commenting — this is their hangout. A personal account allows you to monitor video content, friend groups, and comments, often where cyberbullying or other red flags tend to surface. This will give you the understanding, context, and specifics you need to talk with your child if needed. Remind them regularly where to report any issues.

A final reminder for parents is this: Challenge yourself to let go of the assumption that your child won’t try foolish things online. Smart kids also make unwise choices — a possibility that’s easily provoked in an environment where influencers, likes, and peer comments can disguise danger. It’s easy to forget that during the teen years, reason and evolving identity are at constant odds, which means emotion can suddenly commandeer logic. For parents, this means that by getting involved in your child’s digital world, you have the chance influence and guide them when they need it most.

To stay updated on all things McAfee and on top of the latest consumer and mobile security threats, follow @McAfee_Home  on Twitter, subscribe to our email, listen to our podcast Hackable?, and ‘Like’ us on Facebook.

The post TikTok Update: Dangerous Viral Challenges & Age Restrictions appeared first on McAfee Blogs.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

How 2020 Helped Parents Understand Their Kids’ Digital Lives

How 2020 Helped Parents Understand Their Kids’ Digital Lives

Over the last 12 months, technology has featured in our lives in a way I don’t think any of us would have predicted. Whether you were in lockdown, choosing to stay home to stay well or quite simply, out of other option – technology saved the day. It helped us work and learn from home, stay connected with friends and family, entertain ourselves, shop and essentially, live our lives.

For many parents, this was a real ‘aha’ moment. A moment when technology went from being an annoying distraction to incredibly critical to the functioning of our day to day lives. Of course, many of us had always considered technology to be useful to help us order groceries and check Facebook but to experience first-hand that technology meant life could go on during a worldwide pandemic was a real game changer.

2020 Forced Many Parents to Truly Get Involved in Their Kids Online World

Whether it was downloading video calling apps like Zoom or Facetime, setting up a Twitter account to get updates from the Health Department, using Google Doc to work collaboratively or experiencing what online gaming really is via a few sessions on the Xbox, 2020 means many parents had to get up to date, real fast! And you know what – that’s a good thing! I’ve had so many parents remark to me that they know finally understand why their kids are so enamoured with technology. There really is nothing like walking in someone’s shoes to experience their world!

I’m a big believer in parents taking the time to truly understand the world in which their kids exist. For years, I’ve advised parents to download and use the apps and games their kids play so they can understand the attraction and complexity of their kids’ digital life. Well, it may have taken a global pandemic, but I am delighted to report that, anecdotally at this stage, more parents are now embracing their kids’ online world.

Don’t Forget About Online Safety!

When we first become enamoured with something, we often enter the ‘honeymoon’ phase. As a married woman of 28 years, this was many years ago for me!! The honeymoon phase is when everything is wonderful and rosy, and negatives are not always considered. And our relationship with technology can be much the same. And I’ve been there – there’s nothing quite so wonderful as discovering a new app or piece of software and almost being joyous at just how transformational it could be for your life. And this often means we gloss over or even ignore the risks because we are in love!!!

Here’s What You Need to Know

So, as Cybermum, I’m here to cheer you on and pat you on the back for embracing and using new apps and software. Yes, I’m very proud! But I also want to share with you just a few steps that you need to take to ensure you are not taking on any unnecessary risks with your new favourite app. Here are my top tips:

1. Passwords
Every app, online account or piece of software needs it own individual password. Yes, I know that it is a real pain, but it is one of the most important things you will do to protect yourself online. I’m a big fan of password managers that not only generate the most incredibly complex passwords for each of your accounts but remember them for you. McAfee’s password manager, True Key, is a free option which has completely helped me manage my 80 plus collection of passwords!! Very grateful!

2. Software Updates
The main purpose of a software update is to protect the user from security threats. Yes, you may also get some new features and possibly have a glitch or 2 removed but it is all about the user’s safety. So, if you don’t update your software, it’s a little like leaving windows open when you go out. And the longer you leave between updates – the more windows you leave open!

So, automate these updates if you can or schedule them in your diary. Why not earmark the first day of the month to check and see what you need to download to protect yourself? And don’t forget about your operating system on your phone or laptop too!

3. Be Wi-Fi Wary
Dodgy wi-fi is where so many people come unstuck. Regardless of what app or software you are using, anything you share via unsecured wi-fi could be intercepted by a hacker. So, if you find yourself using wi-fi regularly, you might want to consider a Virtual Private Network or VPN. A VPN creates an encrypted tunnel so anything you share via Wi-Fi cannot be intercepted. Genius, really! Check out McAfee’s Safe Connect for peace of mind.

So, please keep going! Keep exploring new ways technology can work for you in our new COVID world. But remember to take a break too. There is no doubt that technology has saved the day and has ensure we can all still function but there must be a balance too. So, walk the dog, play a board game or having a cuppa outside. Remember you manage the technology; it doesn’t manage you!

Till next time

Stay safe online.

Alex xx

 

To stay updated on all things McAfee and on top of the latest consumer and mobile security threats, follow @McAfee_Home  on Twitter, subscribe to our email, listen to our podcast Hackable?, and ‘Like’ us on Facebook.

The post How 2020 Helped Parents Understand Their Kids’ Digital Lives appeared first on McAfee Blogs.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

True Security Requires a Holistic Approach

True Security Requires a Holistic Approach

Driving along the coast, I sometimes wonder what makes a boat reliably float. After all, a leak can sometimes cripple even the largest vessel. This seems to me like a fitting metaphor for our digital lives: there is a sea of potential danger around us, and always the chance of a leak. However, like shipbuilders, we know how to secure our devices and data as we traverse the digital landscape, combining ease of use and protection.

This is especially important when it comes to our privacy and personal information as we spend more time doing essential tasks online. Every time we give our information online, we give a puzzle piece that someone could potentially use to help access our more sensitive data. Just think about how much information can be gained with just your email address combined with your home address, birthday, or even your mother’s maiden name, much less your actual passwords, Social Security Number or PIN codes.

And while recent surveys have shown that consumers are very concerned about their privacy, nearly half feel that they cannot adequately protect their information. This may seem alarming, however, there are effective and easily accessible ways to better protect our identity online, with a holistic approach and the right set of tools.

What do we mean by holistic protection?

Studies show that people are more worried about having their personal information stolen than having their devices infected, probably because they have less control of their financial or banking data when it gets into the hands of a third party, like an e-commerce website.

This is one key benefit of using a holistic security solution: additional layers of protection proactively keep your personal data out of the wrong hands. It can also detect if your data has already leaked, and helps you regain control of your information.

For example, let’s say you want to order dinner while you are out and about, so that you’ll receive it by the time you get home. A holistic solution, such as McAfee Total Protection includes:

  • A virtual private network (VPN), allowing you to connect securely on a public Wi-Fi network by encrypting, or scrambling, your data while in transit so no one else sees it.
  • Safe browsing that warns you if the restaurant’s website is risky, before you enter your information.
  • An integrated password manager to create and store unique passwords so you don’t reuse passwords. This way if one of your accounts is hacked, your other accounts won’t be at risk.

Let’s go even further and say that long after you’ve ordered and enjoyed your dinner, the restaurant’s website gets hacked. This is when the detection tools come in handy:

  • McAfee Total Protection also includes extensive Dark Web Monitoring which keep constant watch, monitoring your sensitive information. If your data leaks, with breach alerts you’re notified upon finding so you can change your credentials and reduce any risk.

A holistic, or comprehensive, security solution uses a multi-layered approach to help protect your personal information and keep your identity private.

Many Dangers, A Unified Solution

We recognize that consumers face a sea of potential threats, but it’s important to remember that by choosing a holistic security solution for your personal protection, you can minimize your exposure.

Antivirus on your PC is not enough – it has not been enough for many decades now. And this becomes more evident as we continue to spend more time online, with the average person spending 6 hours and 54 minutes online each day.

While standalone apps like a password manager, a VPN app, and an identity solution from different vendors can be piecemealed together with your device security, these are difficult to keep track of and burdensome to maintain.

We have combined the important tools you need into a seamless and comprehensive experience because good security software is something that you use daily to feel safer online. This is why we are working on your behalf to redefine security, so you can live your connected life .

To stay updated on all things McAfee and on top of the latest consumer and mobile security threats, follow @McAfee_Home  on Twitter, subscribe to our email, listen to our podcast Hackable?, and ‘Like’ us on Facebook.

The post True Security Requires a Holistic Approach appeared first on McAfee Blogs.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Settlement Reached Over Data Breach Impacting 24 Million Americans

Settlement Reached Over Data Breach Impacting 24 Million Americans

A multi-state settlement has been reached over a 2019 data breach that may have exposed the personal information of up to 25 million Americans. 

The breach took place from August 1, 2018, through March 30, 2019, when an unauthorized user gained access to the internal computer system of the American Medical Collection Agency (AMCA) by hacking into a web payment portal.

Once inside the system, the user was able to access a variety of sensitive data that included Social Security numbers, payment card information, and the results of medical tests. 

On June 3, 2019, AMCA issued a security notice regarding the breach. The company contacted impacted customers, offering them two years of complimentary credit monitoring. 

It later transpired that at least 23 different healthcare organizations had been impacted by the AMCA breach.

After paying costs associated with the breach notification and remediation, AMCA filed for bankruptcy on June 17, 2019. The company later received permission from the bankruptcy court to settle with the multi-state coalition and on December 9, 2020, filed for dismissal of the bankruptcy.

Under the terms of the settlement, Retrieval-Masters Creditors Bureau, doing business as AMCA, may be liable for a $21m total payment to the states. However, the payment has been suspended in light of AMCA’s financial struggles and will only be activated if the company violates certain terms of the settlement agreement.

As part of the settlement AMCA must implement various data security practices to protect consumers from future cyber-attacks. These include employing a chief information security officer, hiring a third-party assessor to perform an information security assessment, and creating and implementing an information security program with detailed requirements, including an incident response plan.

The settlement was reached between AMCA and the attorneys general of Arizona, Arkansas, Colorado, the District of Columbia, Connecticut, Florida, Georgia, Hawaii, Idaho, Illinois, Indiana, Iowa, Kansas, Kentucky, Louisiana, Maine, Maryland, Massachusetts, Michigan, Minnesota, Missouri, Nebraska, Nevada, New Hampshire, New Jersey, New Mexico, New York, North Carolina, Ohio, Oklahoma, Oregon, Pennsylvania, Rhode Island, South Carolina, Tennessee, Texas, Utah, Vermont, Virginia, Washington, and West Virginia.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Utah Company Stored Passport Scans on Unsecured Server

Utah Company Stored Passport Scans on Unsecured Server

A Utah company has exposed the sensitive information of more than 50,000 customers by storing data on an unsecured server.

The breach at Premier Diagnostics was discovered on February 22 by cybersecurity expert Bob Diachenko at consumer privacy watchdog Comparitech. Sensitive customer data stored in a publicly accessible database included scans of passports, health insurance ID cards, and driver’s licenses. 

Researchers found that the data of around 52,000 customers may have been impacted in the security incident. Based on the data seen by researchers, affected persons are mostly from Utah, Nevada, and Colorado.

“This data could be in anyone’s hands now,” said Comparitech’s Paul Bischoff. “So, your ID and your medical card are probably somewhere on the dark web.”

Premier Diagnostics, which is based in Lehi, operates 11 COVID-19 testing sites scattered across the northern section of the Beehive State. Before testing can take place, an individual who suspects that they have been infected with the novel coronavirus must provide a form of ID, which is then photographed and stored.

“They take a photo of your ID, the front and back of your ID and the front and back of your medical insurance card,” said Bischoff. “They had stored all that data on a server that was publicly accessible online without a password.” 

After being alerted to the security breach, Premier Diagnostics took steps to secure the data, which has been unavailable to the public since March 1. 

“We don’t know for sure that any malicious parties got to it, but we’ve run honeypot experiments before where we see activity on that sort of unsecured data within a matter of hours,” said Bischoff.

He added that by using equipment that scans for unsecured databases, cyber-criminals could have easily accessed and exfiltrated the data. 

“It’s low-hanging fruit; it’s really easy,” said Bischoff. “They use the same tools that we do, that we use to find the database in the first place, they use the same tools to find it and steal it.”

In total, more than 200k images of ID scans were exposed in the data breach. However, no payment information was stored in the unsecured database.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Apple Sues Employee for Stealing Trade Secrets

Apple Sues Employee for Stealing Trade Secrets

Apple is suing a former employee who it claims leaked company trade secrets to a media outlet for over a year for his own personal gain.

Former advanced materials lead and product design architect Simon Lancaster is accused of abusing his position to access information outside of his job scope. He allegedly exchanged the data he stole for payment and positive media coverage of a startup business.

Court documents unsealed in federal court in California on March 11 state: “Despite over a decade of employment at Apple, Lancaster abused his position and trust within the company to systematically disseminate Apple’s sensitive trade secret information in an effort to obtain personal benefits. 

“He used his seniority to gain access to internal meetings and documents outside the scope of his job’s responsibilities containing Apple’s trade secrets, and he provided these trade secrets to his outside media correspondent.”

Court documents alleged that Lancaster was first contacted by the media correspondent on November 29, 2018. Over the course of the next ten months, Lancaster exchanged multiple emails and calls and messages with the correspondent about Apple trade secrets. 

The pair allegedly began meeting in person by September 2019, exchanging physical documents and information.

Data allegedly leaked by Lancaster was published in articles by the media outlet, which attributed it to an anonymous Apple “source.”

Trade secrets allegedly divulged by Lancaster include updates to existing Apple products and unannounced plans for new devices. 

Apple Insider reports that Apple examined company devices that had been issued to Lancaster for evidence of a connection with the media outlet. The investigation revealed that Lancaster “took specific steps to obtain additional Apple trade secrets.”

Lancaster worked for Apple for nearly 12 years before handing in his resignation on October 15, 2019, and joining materials research and development company Arris Composites.

Lancaster is accused of downloading a “substantial number” of confidential Apple documents from the company’s corporate network onto his own personal computer during his last day of employment at Apple. The information he allegedly stole would be of benefit to him in his new role at Arris. 

Apple alleges that Lancaster was in violation of the Defend Trade Secrets Act and the California Uniform Trade Secrets Act, and that he was in breach of a written contract.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

NCSC: Install Latest Microsoft Exchange Server Updates Urgently

NCSC: Install Latest Microsoft Exchange Server Updates Urgently

The National Cyber Security Center (NCSC) is encouraging all UK organizations to install the latest Microsoft Exchange Server updates as a matter of urgency.

The urgent advisement comes after Microsoft released out-of-band patches to fix multiple zero-day Exchange Server vulnerabilities believed to be being exploited by Chinese state-sponsored actors last week.

A week later, ESET claimed that more than 10 different advanced persistent threat (APT) groups have been detected exploiting the vulnerabilities, with the security firm having identified more than 5000 global email servers affected by malicious activity.

The NCSC’s updated alert provides advice that will help reduce the risk of future ransomware and other malware infections. 

NCSC director for operations, Paul Chichester, said: “We are working closely with industry and international partners to understand the scale and impact of UK exposure, but it is vital that all organizations take immediate steps to protect their networks.

“Whilst this work is ongoing, the most important action is to install the latest Microsoft updates.

“Organizations should also be alive to the threat of ransomware and familiarize themselves with our guidance. Any incidents affecting UK organizations should be reported to the NCSC.”

All organizations are advised to proactively search systems for evidence of compromise, in line with Microsoft’s public advice, the NCSC added.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Netflix Introduces Measures to Prevent Password Sharing

Netflix Introduces Measures to Prevent Password Sharing

Netflix has introduced trial measures to try and prevent the practice of password sharing with multiple households, it has been reported by the BBC.

In the trial, users can verify if they are eligible to access a particular account according to Netflix’s terms of service, via a code sent via text or email. In addition, a number of users have reported seeing a message come up on their screen stating: “If you don’t live with the owner of this account, you need your own account to keep watching.”

The steps have been introduced to try and enforce Netflix rules which stipulate that while account holders can create multiple accounts, they should only be used by members of the same household. The BBC quoted a Netflix spokesperson who commented: “This test is designed to help ensure that people using Netflix accounts are authorized to do so.”

It is understood that the company has not yet decided whether to rollout this approach across its network.

Evidence suggests that password sharing among friends and family for different types of accounts, such as streaming services, is a regular occurrence. This has worrying implications from a security point of view as it increases the chances of accounts being compromised and personal details accessed or stolen.

Commenting on the initiative, Jake Moore, cybersecurity specialist at ESET, said: “If I were to ask people if they share their email account password with anyone else, the vast majority would probably say ‘absolutely no chance!’…but when it comes to media services such as Netflix, Amazon Prime and Spotify, such password sharing is actually quite common. It may sound innocent, but when people are using the same password for their media service that they use for other accounts, it starts to become dangerous, and the risk of account compromises increases.

“We ran some research that found that over a quarter of people surveyed had willingly given away their passwords to someone else. This may not sound worrying when you know the other party with whom you are sharing the password, with but what if they pass it on to someone without thinking?

“However, it is unrealistic to expect that people are going to stop sharing their accounts completely, so my advice would be to regularly change your passwords in order to flush out anyone who has gained access over the last year who shouldn’t have. Creating complex passwords, combined with a password manager, will reduce your risk of compromise.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

SailPoint Appoints Heather Gantt-Evans as New CISO

SailPoint Appoints Heather Gantt-Evans as New CISO

Enterprise identity security firm SailPoint has appointed Heather Gantt-Evans as its new CISO.

Gantt-Evans joins SailPoint from retail giant The Home Depot, where she served as the company’s senior director of security operations and resilience. Prior to The Home Depot, Gantt-Evans held various strategic security roles at Ernst & Young and Booz Allen Hamilton, along with spending six years as an all-source threat intelligence analyst in the US Army.

Commenting on her appointment, Gantt-Evans said: “As a former SailPoint customer, I’ve seen the enormous influence identity has on the security of the business first-hand. It’s an exciting time to join SailPoint as the company is on a clear and committed path to meeting the dynamic needs of our customers around the world.

“I look forward to leading the company into a new chapter of maturity in how we protect our products, systems, data, and ultimately, how all of this translates to helping our customers stay secure.”

SailPoint’s EVP product, Grady Summers, added that Gantt-Evans brings a depth of cyber-transformation and security experience to the company as it continues to expand its cybersecurity strategy.

“Given her security experience in the military, as a consultant and as an enterprise practitioner, Heather brings a diverse skill set to SailPoint, and I’m eager to see her positive impact on our business.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Darkside 2.0 Ransomware Promises Fastest Ever Encryption Speeds

Darkside 2.0 Ransomware Promises Fastest Ever Encryption Speeds

Threat intelligence experts are warning of a new version of the Darkside ransomware variant which its creators claim will feature faster encryption speeds, VoIP calling and virtual machine targeting.

Israeli outfit Kela shared with Infosecurity information posted by the Russian-speaking group to dark web forums XSS and Exploit.

They claim that the Windows version of Darkside 2.0 encrypts files faster than any other ransomware-as-a-service (RaaS) and is twice as speedy as the previous iteration. This will mean victims have even less time to pull the plug if they find their network has been infected.

Darkside 2.0 now also features multithreading in both Windows and Linux versions.

The Linux version of the ransomware is now able to target VMware ESXi vulnerabilities, meaning it can hijack virtual machines and encrypt their virtual hard drives.

It’s also been designed to target network-attached storages (NAS), including Synology and OMV, for even more pervasive encryption of victim systems, said Kela.

Finally, Darkside 2.0 features a “call on us” function enabling affiliates to make VoIP calls for free to victims, partners and even journalists. The aim here is to exert extra pressure on victims to pay up.

Interestingly, the gang has apparently deposited over $1m in Bitcoin (23 BTC) on XSS, “intended for solving any financial issues.”

Darkside is somewhat unusual in RaaS operations in that its rules to affiliates specify no targeting of healthcare and vaccine distribution facilities, schools, public sector and non-profit organizations.

It also mandates no targeting of former Soviet states grouped under the Commonwealth of Independent States (CIS) coalition, including Georgia and Ukraine, hinting at the origins of the group.

In October last year the Darkside group grabbed headlines after donating $10,000 stolen from corporate victims to charities, although some experts claimed it was merely trying out a new way to launder funds.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk