Blog

Data Privacy Week 2022: What Is Your Convenience Worth?

  • 25 January 2022
  • 48 replies
  • 666 views
Data Privacy Week 2022: What Is Your Convenience Worth?

Show first post

48 replies

Userlevel 5
Badge +4

If you use the same “fake” information for authentication and verification (“Your Pets Name”, What is the third number of the last four digits of your Social Security Number?”, etc) then you are still as much at risk for having other accounts of your hijacked. While they may not be able to buy a house with your bogus information, the damage they can do is still going to be considerable.

 

Userlevel 2
Badge +2

that you also aspire to lead a quiet life, to mind your own business, and to work with your own hands, as we commanded you,

Userlevel 5

I moved to using a password manager in my personal life. Took a couple of days picking away to fully migrate everything in and then change everything to stupidly long complex pass phrases and then to clear out saved passwords and log ins from browsers. It’s a process, just a bump to get through but once it’s done, that one single password for access makes life a little easier. Also, I do not use the password manager browser extensions. Like the old joke, I’m not being paranoid, I know people are out to get me.

Userlevel 3

Thank you for sharing. The memes are a nice added touch!

Userlevel 4

We have been pretty lucky with clients calling in before they click, but we still get a couple instances a month of someone clicking a bad link in an email. So far we have been lucky with that as well and our systems catching it before anything adverse can happen.

Userlevel 6
Badge +6

I have my doubts about the effectiveness of GDPR but it than that very well thought it and will written sucks. The advice about 2FA is sorry on. 

Userlevel 2

All this tap your card/phone/watch to pay without entering a PIN is scary. Is it really that difficult to spend a few seconds punching in a few numbers for a little security? I don’t care if unauthorized purchases will be refunded. I want to prevent the unauthorized purchases from happening in the first place. This feature should never be activated by default.

 

Also, smart homes and personal assistants. I don’t trust them. I can flip a switch to turn on the lights.

 

No thanks. I’m old school. It’s safer that way.

Userlevel 4

Really good article that focus more on people than business.

I’ve seen many bad handling of personal data at past customers and i sure ain’t doing business with them as an individual.

We, as IT people, have a responsibility to educate our customers/management on these risks and matters.

Userlevel 6
Badge +1

Create a fake identity and use that for all the bogus sites. Don't answer online quizzes with answers that really can identify you. Better yet, don't answer the question at all. E.g. if they ask for your favorite movie, fill in a car brand.

Userlevel 5

Very useful article, privacy is critical nowadays.

 

Userlevel 4
Badge +1

Useful info and something to think about. Still feel that users will always be the weakest link and people need a constant series of training to make sure they understand the risks and impact. People can just be to complacent these days.

Userlevel 3

Great article, and in this current age, we need to always be mindful of privacy.  Complex passwords are a must these days and fortunately there is a lot of password manager tools and most browsers will have this capability as part of their core functionality.  Another function for those in the Apple ecosystem is the hide my email option when signing up to websites.  A great way to hide your identity on those sites you won’t frequent regularly.

When all else fails Dark Web scanning for leaked credentials can give organisations some visibility in what credentials and personally identifiable information of their employees are on the web. As other posters mentioned end user training and awareness for identifying phishing scams is a great way to minimise credential leaks.

Userlevel 5
Badge +5

My kids are at the age when they start getting important online accounts (banking, subscriptions, etc.)  When they’re going through all the security questions options (what is your pets name, your first car, your zip code, etc.)  I tell them they can put anything they want for answers; they don’t have to match, just be remembered.  For example, Q: What is your first car? A: Mr. Peanutbutter. Q: What is your pets name? A: Toyota Corolla.

I try to get them to NOT participate in the your _____  is your birthday and the street you live on social engineering tricks.

So far the kids are ok. They know the dangers from being on the Internet their whole life. It’s the older co-workers that are naive babes oblivious to the danger they’re strutting into.

Userlevel 7
Badge +25

Thanks Keenan! Nice take on an “old topic”. And the gifs were a nice distraction from something so serious. My birthday is 01/01/00, and my mothers maiden name…. Oh, you didn’t need that?  😀

Userlevel 1

Thanks that was an interesting read. Definitely right about why does that website need access to my microphone, I’ve had several websites that have tried doing that and I never clicked yes. To think they’re trying to listen to me breathe, creepy…

 

On another note, having incredibly long passwords are good and will make it super hard to bruteforce, however some users most likely will use the same long password with a potentially different word somewhere in it, maybe they put the website name in? If that password was stolen, then the thieves will only need to guess on other websites. I suppose I’m trying to say that the user would make the password easy to guess, unless trained to not make it easy.

 

Obviously, a password manager would solve that, but the user may need one that is online or syncs between devices so its another cost of convenience on their end if they forget the master password or are not using a device with the password manager, which may cause them to use a much simpler master password.

 

The advice you gave was still very good and I’ll probably use it. Excuse my rambling on the subject above.

Userlevel 7
Badge +8

My views on GDPR are that they force companies to put good processes in place for data and be honest when there is a breach.

Userlevel 3

Great article . Thanks.

Userlevel 1

Very well written article. The age old debate of Privacy over convenience has been and will always be a major talking point.
But sadly too few people are really taking this stuff seriously until they get nailed by it. We here in South Africa have a piece of legislation similar to GDPR called POPIA (Protection of Personal Information Act)  I personally think it wont help as its too similar to GDPR plus the regulator here had its teeth removed so to speak.

 

My tips, they might be painful to follow they can help save your data in the long term

  1. Use a Password Manager to randomize your password just not one the cloud hosted ones, stay local.
  2. Enable MFA on all your accounts
  3. Clear Browser regularly.
Userlevel 4
Badge +8

Good Article and reminder to be dilligent! Human nature is to always look for the easiest way out and what is most comfortable and convenient. I like the idea of freezing your credit, even if you haven’t been compromised. The only problem is that in Australia it looks like you can only freeze your credit for 21 days, and then you can get an extension 😔.

 

Security I like putting in place for myself and my customers:

  • A Password Manager such as MYKI which is peer-to-peer and does not store any passwords in the cloud. 
  • Absolute must to NOT re-use passwords for any accounts!
  • Enable MFA or 2FA on all acccounts that supports it and avoid using SMS as 2FA where possible due to SIM swap attacks.
  • DNS protection. I love Webroot DNSP, wouldn’t want to be without it for myself, family or my customers!!! Just that exstra layer to avoid SCAM websites that tries to steal your identity!
  • I probably should apologise for saying this, but I ABSOLUTELY HATE SOCIAL MEDIA! It’s a hackers haven for gathering enough info to be used against you at some point in time in the future. People forget what they say on social media and you just need an AI tool to build a very detailed and powerful profile on someone that can be used against them at some point in time. Just my humble opinion!
Userlevel 4
Badge +1
I followed many courses a few years ago when the GDPR was introduced in Europe. Duie to the GDPR, our company has changed the ways in which we provided our services in the past. It is a fact that personal data and especially particular data, in the past called "sensitive data", are very important information for people and especially in the professional sphere. The GDPR was born with the desire to allow people to ask for their data to be forgotten and establishes that personal data is owned solely and exclusively by people. In the United States, for example, your data can be used by the "companies" that collect it, in some Asian countries it even becomes the property of government institutions. Having said that, it is certainly not the GDPR that can safeguard our data from cyber attacks. One of the rules of our company is to carry out in-depth assessments within companies to understand where the vulnerabilities are and correct them. The fact remains that breaches are usually created by users and therefore what we continue to do is training users on cyber-security. The priority for our company is training.
Userlevel 3

Great informative article, 10/10!

Userlevel 3
Badge

Convenience is always at odds with security, it seems. 

My main point of attack when this comes up is to advise clients, usually with a suitable example, of where the cost of a cleanup was far greater than the additional security that could have prevented a breach. 

I find if you can outline likely breaches (and most people will have heard of examples in their network) and the likely downtime and fallout then security becomes a more valued conversation. 

Userlevel 4

Very well articulated. The most impactful point is that nothing is actually free. To get something free, we usually end up selling ourselves (our data) in an ignorant Faustian bargain.

Reply