6.4.21

Are you prepared to prevent data loss?

 


From losing cherished memories to missing deadlines, the impact of not having backups when a data disaster strikes can hardly be overstated

By Amer Owaida

Losing valuable data is one of the worst things that can happen to anyone – digitally, at least. Imagine losing critical data that you need to deliver a time-sensitive project with a deadline looming, like a school assignment – or documents needed when you’re applying for a grant, or even a freelance job you’ve taken on.

World Backup Day, was envisioned as a way to help raise awareness of the fact that data loss costs people dearly and that it pays to be prepared. To mark this special day, we’ve dissect the various aspects of not having a backup when experiencing data loss, and what to do in case that happens to you.

What are the impacts of data loss?

Imagine you have lost that critical, not backed-up data for a time-sensitive project. The time you spend trying to either recover the information by some miracle, or having to go through researching, compiling, and rewriting it – this all translates into being less productive and maybe even delivering an inferior product. You also can’t make up for the time lost doing that and therefore you’d be operating on a tight deadline and possibly miss out on an opportunity in the end. And some opportunities don’t come around that often, do they?

The impact of data loss may vary depending on what kind of data is lost, and when during your process it happens. Had you regularly backed up all the important data during your workflow, most of your stress and headaches could have been avoided simply by jumping back into the process where you left off after restoring the lost data from your backup. Besides losing data instrumental to your work, such losses can be even more gut-wrenching if you lose pictures, or videos capturing cherished memories that you won’t be able to recreate. These may range from marriage proposals to childhood memories, or even photos of family members who have long passed on.

How does your data get lost?

There are multiple ways you could lose your precious data; some are avoidable while others are more difficult to predict and prevent. Getting your device infested with malware is one way you could lose your data; depending on the malicious code, your computer could either get entirely wiped, your data corrupted, or –  if you stumble upon ransomware – your data could get locked up. This specific cause of data loss belongs in the realm of the avoidable if you use a full-featured security solution and apply cybersecurity best practices.

Meanwhile, on the other end of the spectrum, we have unforeseeable events or accidents. Your device could get stolen, or it could suffer mechanical damage like spilling liquids on it or falling from a significant height. Beyond mechanical damage, it isn’t uncommon for devices to malfunction, either due to age or a manufacturing defect affecting a specific component, like your hard disk overheating. Power outages are also a thing that can occur, which means if you’re working on a desktop, you could lose the data you’re working on in the blink of an eye. Then you also have to factor in human error, which could result in critical data being accidentally deleted, or set off a chain of events that could possibly even lead to your device being completely wiped.

I don’t have a backup – what do I do?

If your data has been accidentally deleted, stop using the device immediately, but do not turn it off. If it is battery-powered, put it on its charger. Now disable all network connectivity – if it has a “flight mode” or similar, enable that and then put it in “sleep mode”.

However, if your device has suffered an accidental liquid spill, immediately turn it off and try to quickly dry it with a soft dry cloth and if any external media is connected it plug it out and dry that off too. Leave it a few days to dry completely; depending on the amount of liquid damage you may have to consult a professional service.

Fortunately, even if one of the aforementioned scenarios happens, you’re not totally out of luck yet. There are ways you can try to recover your data. If your device was compromised with ransomware, you may be able to find free decryptors created by security companies to address various strains. You can also try to get your data back by using various recovery software that was specifically developed for this purpose. These utilities can either be from the manufacturer of your device or developed by the producer of the components, or alternatively, you can rely on third-party software that can be specific to certain operating systems or devices.

If you’ve run out of DIY options or feel that you are out of your depth, then you can call in the cavalry in the form of a data recovery specialist. However, consider that to be the nuclear option that may set you back hundreds or even thousands of dollars, to get your data back. It’s also worth mentioning that if you attempt to do any DIY recovery and it doesn’t work, you may reduce the chances of a professional being able to help you.

Depending on the type of device and type of damage, such services may be offered by remotely connecting to your device or require you to take or ship the device to the recovery service. If considering this option, contact the service as soon as possible as its staff will have advice on exactly what is best to do with your device following the data loss event.

Summary

One thing is for sure: “prevention is better than cure”. In this context, backing up your sensitive and important data at regular intervals, so you always have something to fall back on is preferable to frantically trying to recover lost data. When it comes to planning your backups, it is better to have several mediums where you have saved any precious memories or mission-critical data.

The best thing you can do is use multiple forms of storage like a reputable cloud solution so you have the data on hand whenever you need it and offline physical storage devices like external drives. For good measure, you should always encrypt all your data as well before you store it anywhere, so that even if someone steals your cloud backups or your external drives, your data is protected.

26.3.21

When repairing things you own may make you an outlaw

 

 How do you balance the right to repair with the requirements to remain secure?

Cameron Camp


Images of jackbooted, militarized cops descending into dimly-lit basements where appliance techs slap grimy, roughshod parts of doubtful lineage together come to mind in the still-simmering fight – yes, it’s a fight – to allow people to work on the tech they already bought and own. You’d think this wouldn’t be a thing: If you buy a device, it’s yours, hopefully you won’t need to repair it or can have it easily repaired and the manufacturer can get on with making more new technology for when you’re ready for their next gizmo or gadget. Not so.

Step away from that screwdriver, back away from the digital gizmo, you may be breaking the law. Want to fix a security issue because the manufacturer won’t? That just might be criminal.

Aside from the pseudo-obvious dark imagery of hardened criminals hastily etching out makeshift tattoos in a somewhat non-sterile fashion in the prisons of the world being joined by a fresh batch of fix-it smartphone techs from our malls, the tech industry, in some parts, is arguing that if you lift a screwdriver or 3D print a replacement gear for the drive on your printer that you risk doing time.

It’s part of a weird dystopian view of what the future might look like, where you really only rent-with-license some new e-doodad and then when it fails you buy new stuff and don’t ask questions.

Well, really, you re-rent the objects you already “bought” via smarmy licensing from the manufacturer. And once they fail, you merely rinse-and-repeat. It’s as if Phillip K. Dick met Wall Street, trying to find the bleakest way to increase shareholder value.

But this fills the world with hordes e-junk in a cycle that shows no promise of slowing. Except the world is fighting back.

Two years ago you bought a dishwasher; now there are no parts to be had for simple, typical appliance repair items like water pumps, drives, or gears. Sometimes they’re glued together so you have to chisel them apart and hope for the best. Open a shop to help others and you’re doomed – watch for the coppers to come lock up your ratchet sets if you step too far into the seedy world of black-market repairs.

But the planet is fighting back; sometimes winning, sometimes not so much.

·       In Norway, a one-man repair shop lost a multi-year legal battle against Apple. His crime? Importing recycled iPhone screens to repair phones, which Apple claimed were “counterfeits.”

·       Farmers are learning how to reverse engineer their own tractors so they can perform repairs in the field, ranging from trading information in private Ukrainian forums to downloading debugging tools from a CalPoly student project.

·       In New York City, independent Apple repairman Louis Rossman has testified before government multiple times about the right to repair.

EU legislators think high-tech goods should have a 10-year service life with widely available parts, tools and perhaps even repair documentation and are spearheading laws to enforce this. Oh, the sacrilege, if you ask some manufacturers; they say the EU shouldn’t meddle.

Pitting repairability against security

While the right to repair seems like a classic black-and-white situation pitting consumers against manufacturers, it is actually a more nuanced discussion, particularly if the device in question is meant to be attached to a network of some kind.

If so, there are several additional issues that come into play: Any device that utilizes a network connection in some fashion is, by definition, going to be exploitable over that connection.

As technology improves, flaws may be found in cryptographic protocols (or in their implementations), digital signatures may expire, and vulnerabilities may be found in operating systems or the applications that run on top of them. It may be possible to engineer a device with enough processing power, storage and other resources to last for ten years’ worth of updates to fix these types of issues, but there is a larger question of whether the device will still work well after a decade of updates and security patches. And that’s ignoring any additional code required to integrate with new standards, which still may cripple performance.

For IoT devices, these problems are manifest. These types of devices are typically manufactured with the bare amount of computing power to get the job done today, and rely heavily on the device manufacturer’s cloud for management. Control of the device may be performed by an app on a smart phone. All of these must not just continue to be maintained, but secured as well. And with all of that comes an increasing drain on processing and storage resources.

For devices powered by them, battery technology becomes an issue as well: Rechargeable batteries have finite charge cycles and as they degrade, so does their ability to store energy. This occurs even when they are sitting on a shelf and not being used. Having to keep manufacturing replacement batteries (and storing them in inventory) for a decade may cause an increase in the amount of electronic waste of these types of devices, which can be more difficult and hazardous to recycle than other types of components.

There’s still hope

So, how do we balance the right to repair with the requirement to remain secure? The answer might not be to just allow for devices to be repaired, but to be modular enough that they can be easily upgraded or have various parts reused. This has been common with desktop and server computers since they were introduced. Memory, expansion cards, storage and even processors could be replaced over time as usage demands and requirements change. This used to be true of laptops as well, although the gimmick of making them thinner every year like smartphones and using glue and other repair-unfriendly assembly methods is cause for concern. There are some hopeful signs, though.

For example, in 2016, Google, which owned Motorola at the time, announced Project Ara, a plan to make modular smartphones that could be upgraded in various ways. No products ever shipped, but Motorola eventually released their Moto Z family, which could be expanded by snapping on various backplates called Moto ModsFairPhone is selling a modular platform, including smartphones you can assemble yourself, and PINE64 has released a smartphone capable of running different versions of Linux. A company called Framework has announced a modular laptop that can be upgraded and repaired, although it is unclear at this time if they will release the technical schematics needed to perform detailed troubleshooting.

While none of these products have achieved mainstream fame, and represent less well-known vendors (with the exception of Motorola), they do show that there is demand for electronic devices that are repairable, recyclable and upgradeable.

Will it eventually become mainstream? That will be driven by a combination of consumer sentiment and thresholds of infuriation. Stuck in the middle of a field with your e-tractor? You might just find yourself going rogue and reaching for the toolbox. And while we hope you don’t wind up doing time, we also hope manufacturers will focus on the future of innovation, not rearguard actions designed to thwart innovation, experimentation and progress, all while making the devices less secure and speeding their trajectory to the ever-bulging landfills in the name of bogus progress.

 

5 défi des entreprises financières (et bien d’autres) en matière de cybersécurité

Pourquoi de nombreuses organisation ont-elles du mal à suivre l’évolution du paysage des menaces et à gérer efficacement leurs cyberrisques ?

Amer Owaida

Les sociétés de services financiers sont depuis longtemps une cible populaire pour les cybercriminels. Ce n’est pas sans raison, puisqu’en plus de travailler avec de l’argent, les sociétés financières traitent un grand nombre de données sensibles sur leurs clients, que les criminels utilisent dans diverses fraudes ou vendent sur le dark web. Selon le rapport 2020 Data Breach Investigations Report, de Verizon, l’année dernière uniquement, le secteur financier a subi plus de 1 500 incidents, avec 448 divulgations de données confirmées.

En plus des menaces de longue date, la plupart des entreprises ont dû faire face à la transition rapide vers le travail à distance. Cette transition s’est faite dans un délai extrêmement court, laissant aux entreprises peu de temps pour déployer des mesures de cybersécurité adéquates ou pour préparer les employés aux cybermenaces imminentes. Et si la pandémie finit par s’estomper, le travail à distance, lui, est là pour rester. Il vient s’ajouter à la liste des défis que les entreprises doivent relever lorsqu’elles préparent leurs plans et politiques de cybersécurité. Il s’agit d’un problème auquel elles sont souvent déjà confrontées en raison de divers facteurs – nous en avons rassemblé cinq :

Le manque de main d’oeuvre de talent

Alors que de nombreuses entreprises sont à la recherche de professionnels de la cybersécurité, expérimentés ou en devenir, pour rejoindre leurs rangs et les aider à établir un périmètre défensif contre diverses menaces, ils ne sont tout simplement pas assez nombreux. En fait, bien que le déficit de main-d’œuvre en cybersécurité ait diminué pour la première fois depuis des années, il y a toujours une pénurie mondiale de 3,12 millions de travailleurs. En fait, pour combler la pénurie mondiale de talents, il faudrait que les niveaux d’emploi augmentent de 41 % aux États-Unis et de 89 % dans le monde entier. Ainsi, pour attirer les meilleurs et les plus brillants esprits de la cybersécurité, les entreprises devront offrir des salaires compétitifs et des opportunités de travail épanouissantes.

Des budgets insuffisants

L’insuffisance des budgets alloués à la cybersécurité est un facteur clé qui empêche les entreprises de s’attaquer de front aux cybermenaces. Selon une enquête menée par le cabinet de conseil Ernst and Young, 87 % des organisations interrogées ont déclaré qu’elles ne disposaient pas d’un budget suffisant pour atteindre les niveaux de cybersécurité et de résilience qu’elles visaient. Le manque de ressources signifie que les entreprises ne peuvent pas recruter suffisamment de talents en cybersécurité ou mettre en place les mesures techniques dont elles ont besoin pour être résilientes face aux diverses cybermenaces.

La surestimation de leur propre cybersécurité

Une erreur courante des entreprises est de surestimer la qualité de leurs mesures de cybersécurité. Bien qu’elles puissent croire qu’elles maîtrisent la situation, les entreprises n’ont peut-être pas mis en place les meilleures politiques de gestion des correctifs de vulnérabilité. Un bon – mais en même temps, malheureux – exemple est la vulnérabilité BlueKeep présente dans Windows. Le correctif a été publié en mai 2019, Microsoft exhortant tout le monde à procéder à cette mise à jour immédiatement. Un mois plus tard, la National Security Agency a publié son propre avertissement. Pourtant, en juillet, il y avait encore plus de 805 000 machines sensibles à cette faille de sécurité; le tout a culminé avec les premières attaques BlueKeep, en novembre de cette même année. Il va sans dire que la correction d’une vulnérabilité aussi grave ne devrait en aucun cas prendre six mois.

Le manque de formation à la sensibilisation

Le fait que les employés ne reçoivent pas suffisamment de formation de sensibilisation à la cybersécurité est un autre phénomène courant qui nuit à la cybersécurité d’une entreprise. Les risques que les employés soient incités à télécharger des logiciels malveillants ou à divulguer les informations d’identification de leur entreprise ont été amplifiés par le passage au travail à distance, alimenté par le COVID-19. Selon une étude menée par le Ponemon Institute, bien que les entreprises aient enregistré une recrudescence des cyberattaques pendant la pandémie (notamment des attaques de phishing et d’ingénierie sociale), 24 % des personnes interrogées estiment que leur organisation n’a pas dispensé une formation suffisante sur les risques liés au travail à distance. Fait inquiétant, l’étude a également révélé que plus de la moitié des entreprises n’avaient aucune politique de sécurité couvrant les besoins des employés à distance.

La sous-estimation de l’importance de la cybersécurité

Certaines organisations sous-estiment la valeur de la cybersécurité pour leur entreprise et choisissent plutôt d’investir dans d’autres aspects qu’elles jugent plus valables, comme le financement des expansions ou le développement de nouveaux produits. Elles pourraient faire valoir que les coûts sont supérieurs aux avantages, par exemple que le coût des mesures de cybersécurité est supérieur aux pertes potentielles résultant d’une violation des données. Toutefois, si les amendes et les pertes potentielles peuvent être moindres à court terme, l’atteinte à la réputation pourrait avoir des répercussions plus importantes, notamment la perte de confiance des clients, ce qui affecterait les flux de revenus. Par ailleurs, en cas de succès, les cybercriminels pourraient avoir accès à la propriété intellectuelle qu’ils pourraient vendre avec les données des clients sur le dark web. Par conséquent, la cybersécurité ne doit pas être envisagée après coup, car elle sert à protéger à la fois l’entreprise et ses clients.

Conclusion

Toute combinaison des facteurs susmentionnés pourrait constituer la tempête parfaite pour une pléthore d’organisations confrontées à une cyberattaque. Le bon côté des choses, c’est que les entreprises de services financiers ont commencé à prendre au sérieux les problèmes de cybersécurité au plus haut niveau. Le cabinet mondial de conseil en gestion McKinsey a constaté que 95 % des comités de conseil interrogés déclarent discuter des cyber-risques et des risques technologiques au moins quatre fois par an. Il convient toutefois de noter que la sensibilisation des cadres supérieurs doit aller de pair avec l’investissement de sommes suffisantes dans des solutions de cybersécurité et la formation du personnel aux meilleures normes possibles.

 

23.3.21

5 reasons why (not only) financial companies struggle with cybersecurity

 

Why do many organisations have a hard time keeping up with the evolving threat landcape and effectively managing their cyber-risks?

By Amer Oweida

Financial services companies have been a popular target for cybercriminals for a long time. Not without good reason, since beyond working with money, financial companies handle a slew of sensitive client data that criminals utilize in various fraud schemes or sell off on dark web bazaars. According to Verizon’s 2020 Data Breach Investigations Report, in the past year alone the financial industry has suffered more than 1,500 incidents, with 448 confirmed data disclosures.

In addition to the long-standing threats, most companies have had to contend with the rapid transition to remote work. The shift happened on extremely short notice, leaving companies with little time to deploy adequate cybersecurity measures or to prepare employees for looming cyberthreats. And while the pandemic will eventually subside, remote work is here to stay – adding to the list of challenges that companies need to cope with when they are preparing their cybersecurity plans and policies. This is something they often struggle with already due to various factors – we have rounded up five of them:

Talent gap

While many companies may be on the hunt for either seasoned or up-and-coming cybersecurity professionals to join their ranks and help them establish a defensive perimeter against various threats, there just aren’t enough of them to go around. In fact, although the cybersecurity workforce gap has shrunk for the first time in years, there is still a global shortage of 3.12 million workers. Actually, to make up the global talent shortfall, the employment levels would need to grow by 41% in the United States and 89% worldwide. So, to attract the best and brightest cybersecurity minds, companies will have to offer competitive salaries and fulfilling work opportunities.

Insufficient budgets

A key area that is preventing companies from tackling cyberthreats head-on is that they have insufficient budgets allocated to cybersecurity. According to a survey conducted by consulting firm Ernst and Young, 87% of surveyed organizations said that they did not have a sufficient budget to achieve the levels of cybersecurity and resilience they were aiming for. The lack of resources means that companies can’t hire enough cybersecurity talent or institute technical measures they need to be resilient when facing off against various cyber threats.

Overestimating their own cybersecurity

One common mistake companies make is that they overestimate how good their cybersecurity measures are. While they may believe that they are on top of things, companies may not have the best vulnerability patch-management policies in place. A good – but at the same time, unfortunate – example is the BlueKeep vulnerability present in Windows. The patch was issued in May 2019, with Microsoft urging everyone to patch immediately; a month later, the National Security Agency issued its own warning, yet in July there were still more than 805,000 machines susceptible to the security flaw and it culminated with the first BlueKeep attacks in November. It goes without saying that patching such a severe vulnerability should under no circumstances take six months.

Lack of awareness training

Another common occurrence that undermines a company’s cybersecurity is that employees do not receive enough cybersecurity awareness training. Arguably the risks of employees being tricked into downloading malware or parting with their company credentials have been amplified due to the COVID-19-powered shift to remote work. According to a study conducted by the Ponemon Institute, although companies have registered a surge in cyberattacks during the pandemic (including phishing and social engineering attacks), 24% of respondents felt that their organizations have not provided sufficient training about risks associated with remote work. Worryingly, the study also discovered that over half of the companies had no security policies at all covering requirements for remote employees.

Underestimating the value of cybersecurity

Some organizations underestimate the value of cybersecurity for their business and instead opt to invest in other aspects they deem more worthwhile, such as financing expansions or developing new products. They could argue that the costs outweigh the benefits, such as the cost of cybersecurity measures outweighing potential losses from a data breach. However, while the potential fines and losses may be lower in the short term, the reputational damage could lead to greater fallout including losing client trust, which would hit revenue streams. Alternatively, if successful, cybercriminals could gain access to intellectual property that they could sell along with the client data on the dark web. Therefore, cybersecurity shouldn’t be an afterthought, as it serves to protect both the company and its clients.

Conclusion

Any combination of the aforementioned factors could spell a perfect storm for most organizations when faced with a cyberattack. On the bright side, financial services companies have begun taking cybersecurity concerns seriously on the highest level. Global management consulting firm McKinsey found that 95% of the board committees that they surveyed say they discuss cyber-risks and tech risks at least four times a year. It’s worth noting, however, that building awareness in top management has to go hand in hand with investing adequate sums in cybersecurity solutions and training personnel to the best possible standards.

15.3.21

PayPal-fraude: wat handelaars moeten weten

 

Wat zijn enkele van de meest voorkomende bedreigingen waarop webhandelaars die PayPal gebruiken moeten letten? Enkele tips van ESET.

Met een betalingsvolume van 247 $ miljard (US$247 billion) blijft PayPal, onder grote merken en een verscheidenheid aan kleinere bedrijven en verkopers, een van de meest populaire online betalingsproviders. De gigant heeft 28 miljoen geregistreerde handelaren op zijn platform (boasts 28 million registered merchants).

Vergeleken met grote bedrijven als Sony of Microsoft, hebben kleinere leveranciers, voor wie vooral onlineverkoop een bijzaak is, niet de luxe een heel leger professionals erop na te houden voor hun cyberbeveiliging. Bijgevolg zijn ze vaker het doelwit van verschillende fraudevormen en aanvallen die cybercriminelen op hun pad kunnen gooien.

Te veel betaald?

Een van de populaire oplichtingen waarmee verkopers te maken krijgen, zijn deze door te hoge betalingen. In dit scenario zal de oplichter, die zich voordoet als een vaste klant, een PayPal-betaling sturen die hoger is dan de prijs van het product of de bestelling. Hij laat de verkoper dan weten dat hij een fout gemaakt heeft - meer geld hebben gestuurd dan ze hoefden te betalen - en vraagt de handelaar om het verschil terug te storten. Eens dat is gebeurd, wordt PayPal door de oplichter gecontacteerd en dient hij een klacht in voor verschillende redenen: het geleverde product was van mindere kwaliteit, zijn account werd gecontamineerd en hij heeft niets gekocht. In dit laatste geval, als de oplichter in aanmerking komt voor een volledige terugbetaling, kan de handelaar zowel geld als goederen verliezen.

De cybercrimineel kan, als alternatief, heel goed een gecompromitteerde PayPal-rekening of kredietkaart gebruikt hebben. Als de rekeninghouder/kaarthouder zich realiseert dat er ongeoorloofde activiteiten op zijn rekening plaatshadden, zal hij dit melden en raakt de handelaar het verzonden product en de betaling kwijt plus de verzendkosten.

Natuurlijk komen er af en toe wel fouten voor, maar in het geval van te veel betaalde bedragen is het beter voorzichtig te zijn. Een hogere betaling kan vaak een duidelijk teken van fraude zijn, de handelaar kan dan best die bestelling annuleren.

Is het al dan niet geleverd?

Er zijn diverse vormen van verzendtechnieken die fraudeurs gebruiken. Ze hebben allemaal één doel: geld binnen te halen. Zo kan een oplichter proberen de verkoper ervan te overtuigen het verzendaccount van de oplichter te gebruiken, omdat deze een korting kan geven of een betere prijs hanteert dan een van de gebruikelijke leveringsdiensten. Als een handelaar daarmee instemt, kan de oplichter de leveringsdienst vragen om de bestelling op een ander adres te leveren. Zo kan hij een klacht indienen en beweren dat de goederen nooit zijn geleverd. De handelaar heeft geen bewijs van levering wat betekent dat hij driemaal wordt beroofd - hij is zijn product kwijt, heeft de verzendkosten betaald en moet het gebrek aan levering compenseren, terwijl hij wel degelijk het product heeft verzonden.

Een andere veel voorkomende tactiek is het omleiden van de oplichting, waarbij de fraudeur opzettelijk het verkeerde verzendadres geeft en geduldig de online trackinginformatie opvolgt. Zodra het verzendbedrijf een melding plaatst dat het pakket niet kon afgeleverd worden, wordt deze door de oplichter gecontacteerd met zijn "juiste" adres en ontvangt hij het product. Vermits er geen bewijs van levering is, ontpopt zich hetzelfde scenario en krijgt de verkoper een drievoudige klap.

Om zich tegen dergelijke oplichtingen te beschermen, kan de verkoper zich best houden aan zijn verzendaccount en voorkomen dat hij geld overmaakt aan iemand die hij niet kent. Hij moet het product ook altijd verzenden naar het adres dat de koper op de pagina Transactiegegevens heeft opgegeven. Hij kan bovendien zijn transportbedrijf contacteren en de koper verbieden om leveringen op een ander adres te ontvangen.

Goeie ouwe phishing

Aangezien PayPal een van de meest nagebootste merken is in phishing-scams (PayPal being one of the most-spoofed brands in phishing scams), is het best mogelijk dat een verkoper het doelwit van een van deze merken wordt. Een veelvoorkomend scenario is dat de verkoper een e-mail ontvangt met de melding dat zijn PayPal-rekening geblokkeerd is. Als die rekening een van zijn belangrijkste inkomstenbronnen is, raakt hij zeker in paniek. De mail kan verschillende redenen aanhalen, waaronder ongebruikelijke activiteiten die op de rekening zouden hebben plaatsgehad. Die mail kan er in alle opzichten legitiem uitzien, met alle nodige toeters en bellen. Wil de verkoper zijn rekening weer laten werken, dan moet hij de stappen volgen die in de frauduleuze e-mail beschreven staan, wat meestal een truc is om gevoelige gegevens en rekeningreferenties te stelen. Loopt het doelwit in de val, dan legt de oplichter de hand op het mailadres, wachtwoorden en misschien meer, of als alternatief kan de mail een link bevatten die malware op het toestel van het slachtoffer zal downloaden.

Voor de verkoper is het altijd beter om elke ongevraagde mail die hij ontvangt, nauwkeurig te bekijken, vooral mails die lijken op vragen van de klantendienst. Als hij twijfelt, moet hij altijd rechtstreeks contact opnemen met het bedrijf via de officiële contactformulieren op diens website; voorkomen is beter dan genezen. Het gebruik van een spamfilter en een gerenommeerde, up-to-date beveiligingsoplossing zou de verkoper ook moeten beschermen tegen de meeste phishing-bedreigingen.

Conclusie

Hoewel dit misschien geen allesomvattende lijst is van de oplichtingen die men als verkoper op PayPal kan tegenkomen, zijn dit enkele van de meest voorkomende, die een algemeen beeld geven van waarop men moet letten. Het belangrijkste is om waakzaam te blijven en zijn gezond verstand te gebruiken als er iets ongewoons gebeurt. Het beste advies is om altijd alles te verifiëren als iets verdachts lijkt, of het nu een speciaal verzoek is of een ongevraagde e-mail.

Verneem meer over ESET’s oplossingen voor bedrijven op https://www.eset.com/be-nl/

9.3.21

Going dark: Service disruptions at stock exchanges and brokerages

 



Âre you a bull or a bear? If you can't access your data and money, do your sentiments about the market still matter?

I was recently asked about how software vulnerabilities in stock trading apps and platforms might put users’ finances and personal data at risk. Given the dependence of today’s societies and economies on technology along with the skyrocketing interest in day trading of late, it’s only natural that concerns about the increasing number and severity of security loopholes in all manner of software applications should rise in lockstep. And that’s on top of numerous other cyberthreats that require the continued attention of organizations and people, including those involved with stock trading.

Recently, a string of disruptions that have plagued stock exchanges and brokerages have thrown into stark relief another problem: an outage, too – even if it’s caused by a technical glitch – can ultimately impact the finances of people and organizations. While this issue typically commands less public attention, incidents that halt trading on platforms where billions of dollars normally move every day may even impact investor confidence and have knock-on effects for countries’ economies. Indeed, I spoke about the importance of ensuring the availability of trading technologies back in 2018; if recent history is any indication, things don’t appear to be improving.

The availability of data and systems is, along with their confidentiality and integrity, one of the pillars of the venerable CIA triad, the concept at the heart of information security and the guiding principle of any organization’s data security efforts. The impact of availability problems varies from industry to industry and from asset to asset; put bluntly, being unable to access a small social media analytics platform is not quite the same as having problems logging into your company’s Enterprise Resource Planning (ERP) application.

Common sense would lead us to assume that the technologies behind stock exchanges are robust, fail-safe, and would never fail under normal circumstances. 2020 proved us wrong – let’s look at how major stock exchanges and brokerages have struggled to keep their systems up and running recently.

Stock exchange blackouts

Tokyo Stock Exchange (TSE)

On Thursday October 1st, the TSE trading session was halted for an entire day. The TSE is the world’s third largest exchange with a market capitalization of about $6 trillion. The outage was attributed to a hardware malfunction in its stock trading system and auto-backup system. Two failures in a row. Nonetheless, the TSE resumed operations on the next day.

This system proved resilient against natural forces, having held up during a powerful earthquake and tsunami in 2011; on the other hand, it wasn’t the first time that its Arrowhead trading system experienced a glitch.

On November 5th, the Japan Exchange Group – the TSE’s owner – announced in a press release that the system had been upgraded. This update offers higher availability and speed.

I ask, were these systems tested regularly, either internally or by the vendor, or was this simply misfortune? Wrong day? Wrong time? Who knows.

Mexican Stock Exchange (BMV)

On October 9th, the trading session at Mexico’s oldest stock market halted at midday due to operational problems with the system used to process trading orders. The stock exchange blamed the outage on a connection cut out mistakenly caused by a technology provider. It’s worth noting that Service Level Agreements (SLAs) play an important role in these kinds of problems.

Even when a technology is resilient and the IT General Controls are audited on a regular basis, people will inadvertently make mistakes. Nonetheless, trading resumed the following Monday with all platforms working normally.

Still in October, trading on several major stock exchanges in Europe also came to a standstill.

Broker bottlenecks

Rush hours are at market opening and market closure (09:30-16:00 EST) are the most crucial moments for the market. There is massive buying and selling during these times, with orders being sent to the same API endpoints and the same servers at the same time.

Thousands of users from different brokerages have reported availability problems on their web, mobile, and desktop trading platforms. Angry users were not able to buy or to sell securities at the right price. Millions of dollars vanished in lost opportunities.

In my opinion, regulators should take action against such non-diligent behavior by brokerages.

Retail broker unavailability

After the COVID-19 pandemic caused a huge increase in their user numbers, many retail brokers now suffer from the same problem: availability at opening/closing hours.


Complete article :
Going dark: Service disruptions at stock exchanges and brokerages | WeLiveSecurity