Organizations Should Use Psychology to Promote Secure Behavior Among Staff

Organizations Should Use Psychology to Promote Secure Behavior Among Staff

Organizations should improve their understanding of the human mind to establish more secure behaviors among employees, according to the Information Security Forum (ISF).

The group has published a new report entitled Human-Centred Security: Positively Influencing Security Behavior, which aims to help organizations develop the right psychological techniques to ultimately empower their staff to engage in more secure behaviors.

This issue of individual errors leading to security incidents has been exacerbated by the recent shift to remote working during COVID-19, with employees more distracted and stressed and with less access to IT personnel.

The new digest sets out guidance for senior leaders on managing this risk, using psychological theory to help them understand the key drivers of human behavior and how to influence people in a positive way through education, awareness and training. The guidance also details how systems, applications, processes and the physical environment can be designed to account for human behaviors.

Daniel Norman, senior solutions analyst at the ISF, explained: “Errors and acts of negligence can cause significant financial and reputational damage to an organization, with many security incidents and data breaches originating from a human source.

“A human-centred security program helps organizations to understand their people and carefully craft initiatives that are targeted at behavior change, reducing the number of security incidents related to human error and negligence.”

Commenting on the research, Lisa Plaggemier, chief strategy officer at MediaPro, said: “There are some simple initiatives organizations can engage in to design secure behavior into everyday activities. For developers, there are plenty of tools that don’t interrupt their workflow that help them to ‘design’ security into their code. Some of them also include ‘teachable moment’ training when they scan their code and are ready to check it in. I’m a huge fan of tools that don’t ask people to do things differently, but rather help them to be more secure in a way that is designed around their function.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Apple’s Head of Global Security Facing Bribery Charges

Apple’s Head of Global Security Facing Bribery Charges

Apple’s head of global security, Thomas Moyer, has been charged with bribery in relation to obtaining concealed firearms licences.

As reported by the BBC, Moyer is accused of offering $70,000 worth of iPads to police officers in return for the licenses, which are required to lawfully carry a concealed weapon in California.

Two police officers – county undersheriff Rick Sung and sheriff’s captain James Jenson – have also been charged for requesting bribes for concealed firearms licenses.  

The charges, which were brought on Monday by a California grand jury, allege that Sung refused to issue concealed weapons permits to Apple’s security team unless Moyer donated $70,000 worth of iPads to the sheriff’s office. According to the charge sheet, the deal was scuppered when Sung and Moyer learned of a search warrant to seize the Santa Clara County police’s concealed weapon license records.

The two-year investigation concluded that Sung held back on issuing licenses unless the applicants offered something of value. They found that he was assisted in this by Jensen in one instance.

Jeff Rosen, Santa Clara County District Attorney, said: “Call this quid pro quo. Call it pay-to-play. Call it give to get. It is illegal and deeply erodes public confidence in the criminal justice system.

“When high-ranking members of a law enforcement agency are at the heart of a bribery scheme, it tarnishes the badge, the honor, the reputations and – tragically – the effectiveness of all law enforcement agencies.”

In a statement to CNBC, an Apple spokesperson commented: “We expect all of our employees to conduct themselves with integrity. After learning of the allegations, we conducted a thorough internal investigation and found no wrongdoing.”

If found guilty, the accused may face a custodial sentence.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

#BlackFriday: 84% of Consumers Willing to Risk Personal Data in Search of Bargains

#BlackFriday: 84% of Consumers Willing to Risk Personal Data in Search of Bargains

More than four in five (84%) consumers are willing to share personal information with retailers in order to save money on their Christmas shopping, according to new research from Kaspersky.

Ahead of Black Friday later this week, the study found that the vast majority of shoppers are willing to risk sending data such as email addresses and telephone numbers to take advantage of bargains they receive or see online. Fraudsters are therefore likely to take advantage of this increased desire to save money, which is partly fuelled by the economic crisis and job losses caused by the COVID-19 pandemic.

Worryingly, just a quarter (25%) of consumers surveyed said they were aware scams are more frequent during Christmas and other sales shopping periods and will not risk sharing data for a discount.

In addition, just 17% would only shop with large brands to avoid security risks while only a third (33%) were unwilling to use a website that looks illegitimate. Under a third (29%) said they were aware that unknown brands offering major discounts could pose significant security risks.

David Emm, principal security researcher at Kaspersky, commented: “Online shopping is a tempting and easy way to part with our hard-earned cash. Emails with bargains and offers land in our inbox and with just a few clicks the goods can be winging their way to our homes without us having to ever leave the sofa. This can be a risky business at the best of times. As brands launch seasonal sales over the next few weeks ahead of what is predicted to be one of the busiest Black Friday and sale shopping periods ever for online retailers, scammers are more primed than usual to take advantage of unwitting consumers.

“Given the year we have had, any bargains or major discounts will be very tempting as many people try to make the most of the festive period. However, we encourage shoppers to be mindful and think about the data they are handing over in a bid for a bargain. Think about whether it’s absolutely necessary to share your personal information for each purchase and if it’s not, is it just a trick to lure you into disclosing your data. By ensuring deals are genuine before making any purchases, consumers can reduce the risk of potential pitfalls and enjoy their Christmas.”

Yesterday, the National Cyber Security Centre (NCSC) issued refreshed guidance for online shopping ahead of this week’s Black Friday in light of the increased number of online shopping transactions in the run-up to Christmas this year.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Smart Doorbells Are Wide Open to Security Flaws

Smart Doorbells Are Wide Open to Security Flaws

A consumer rights group has found security vulnerabilities in 11 popular smart doorbell products available on two of the world’s biggest online marketplaces.

Which? enlisted the help of researchers at NCC Group to run tests on the smart devices they found on eBay and Amazon, many of which had scores of five-star reviews, were recommended as “Amazon’s Choice,” or on a bestsellers list.

Typical issues included: weak password policies, meaning hackers could guess the factory defaults to hijack the device; excessive data collection and lack of data encryption, meaning attackers could lift Wi-Fi password details to hijack other devices on the home network.

The Victure VD300 was found to be sending unencrypted info including Wi-Fi name and password to servers in China, while the Qihoo 360 D819 stored video recordings in unencrypted format and could even be physically removed from the wall with a SIM-card ejector tool, Which? said.

The Ctronics CT-WDB02 and Victure devices contained a critical vulnerability enabling attackers to steal network passwords, while an unbranded V5 Wifi Ring doorbell featured a flaw allowing attackers to take it offline by reverting it to a “pairing” mode.

Another unnamed device tested by NCC Group featured the infamous KRACK vulnerability, which could enable attackers to break WPA-2 security to grab home network passwords.

The UK government is introducing new legislation intended to improve baseline security of consumer IoT products sold in the country. This includes a mandate for manufacturers to ensure they all have unique passwords out-of-the-box, a public point of contact for vulnerability management and a clear time frame in which security updates will be offered.

However, not all of the faults listed above would be fixed by the law. Which? is also calling for strong enforcement of the law to ban any non-compliant products.

In the meantime, Amazon claimed it requires all products offered online to comply with applicable laws and regulations and has “developed industry-leading tools to prevent unsafe or non-compliant products from being listed in our stores.”

E-commerce giant eBay said it immediately removes any products found to violate its safety standards.

“These listings do not violate our safety standards but represent technical product issues that should be addressed with the seller or manufacturer,” it said of the report. “We have and will continue to facilitate discussions between Which? and the sellers so the concerns can be addressed.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

TikTok Patches Bugs Enabling One-Click Account Takeover

TikTok Patches Bugs Enabling One-Click Account Takeover

TikTok has patched two common types of vulnerability which a researcher combined to create a “one-click” account takeover attack.

Submitted by Muhammed Taskiran via HackerOne back on August 26, the bugs were originally labelled medium severity before being upgraded to high (CVSS 8.2) a few days later.

“While fuzzing, I discovered a URL parameter reflecting its value without being properly sanitized. Thus, I was able to achieve reflected [Cross-Site Scripting] XSS. In addition, I found an endpoint which was vulnerable to [Cross-Site Request Forgery] CSRF,” he wrote.

The endpoint allowed Taskiran to set a new password on accounts which had used third-party apps in sign-up.

“I combined both vulnerabilities by crafting a simple JavaScript payload — triggering the CSRF — which I injected into the vulnerable URL parameter from earlier, to archive a ‘one click account takeover,’” he continued.

The issue was finally resolved on September 18 and Taskiran was awarded $3860 for his efforts.

Jayant Shukla, CTO and co-founder of K2 Cyber Security, explained that XSS and CSRF are a regular feature of the OWASP Top 10 web application security risks.

“Reflected XSS is part of the XSS category of risks and CSRF is part of the injection category. The fact that these types of vulnerabilities continue to exist in web sites and applications like TikTok shows that not enough organizations test and protect their websites and applications against the OWASP Top 10,” he added.

“NIST recently updated its SP800-53 Security and Privacy Framework to add focus on these issues by including the requirement for RASP (Runtime Application Self-Protection) and IAST (Interactive Application Security Testing). These types of security solutions specifically target the risks outlined by the OWASP Top 10.”

It’s not the first time this year TikTok has been forced to patch a critical vulnerability. In January, Check Point revealed multiple bugs which could have been exploited to hijack user accounts and steal personal data.

These included another XSS flaw, this time in an ads subdomain of the main TikTok site, and an SMS link spoofing bug in a feature on the main TikTok site.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Up to 350,000 Spotify Users Targeted by Credential Stuffers

Up to 350,000 Spotify Users Targeted by Credential Stuffers

Security researchers have helped Spotify tackle a potentially serious credential stuffing campaign after spotting an unsecured cloud database containing hundreds of millions of user records.

The team at vpnMentor found the database, hosted on a completely unsecured Elasticsearch server, back on July 3.

The 72GB data trove contained over 380 million records, including email addresses, countries of residence and usernames and passwords for Spotify users. It claimed around 300,000-350,000 users were affected.

Spotify responded to vpnMentor’s outreach immediately, on July 9.

“The exposed database belonged to a third party that was using it to store Spotify login credentials. These credentials were most likely obtained illegally or potentially leaked from other sources that were repurposed for credential stuffing attacks against Spotify,” vpnMentor noted.

“In response to our inquiry, Spotify initiated a ‘rolling reset’ of passwords for all users affected. As a result, the information on the database would be voided and become useless.”

As well as use the breached credentials to target other sites in credential stuffing campaigns, any malicious actors that discovered the database could have sought to sell Spotify premium account access, or launch follow-on phishing and identity theft attempts using these details and user emails.

“Credentials are a particular area in which users are left exposed because they either choose weak passwords, or reuse them across different sites,” argued Javvad Malik, security awareness advocate at KnowBe4.

“It is why it is important that users understand the importance of choosing unique and strong passwords across their accounts and where available enable and use MFA. That way, even if an account is compromised, it is not possible for attackers to use those credentials to breach other accounts.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk