Home Blog Page 265

How to Recover from a Data Breach With ID Assist

DEO data breach

By ID Assist

As businesses continue to welcome digital transformation with open arms, the challenges they face are increasing. Electronic data is being widely used for daily operations. Small scale organizations are using Big Data for analyzing customer trends and maximizing profits. In this era where data is costlier than oil, growing pools of personal and financial information are being shared and stored online. These growing numbers have also directed the eyeballs of cybercriminals towards financial institutions and individuals, with an intent of data breach and identity theft.

Data breach and Identity Theft Overview in Numbers

Data breach and identity theft are the major contributors to cybercriminals’ growing pockets. They have continued to evolve and develop new mechanisms to commit financial fraud. A Data Breach Report from Risk Based Security and Identity Fraud Study from Javelin Strategy & Research for 2019 shows a few interesting figures:

  • There were 5,183 breaches reported in the first nine months of 2019 exposing 7.9 billion records.
  • Compared to Q3 2018, the total number of breaches was up 33.3% and the total number of records exposed more than doubled, up 112%.
  • 70 percent of data breaches happen against companies with fewer than 100 employees.
  • The cost of a data breach has risen 12% over the past 5 years to US$3.92 million per incident on average.
  • Healthcare sector was the most expensive industry for data breach costs, with the total cost of a data breach in 2019 averaging US$6.45 million.
  • In Q3 alone, six breaches exposed 100 million or more records, accounting for 3.1 billion records exposed between July 1 and September 30, 2019.
  • Identity theft numbers have fallen from 16.7 million in 2017 to 14.4 million in 2018.
  • However, the same study revealed that the identity fraud costs for the victims has nearly doubled to US$1.7 billion in 2018 as compared to 2016.
  • Mobile phone account takeovers are major contributors to the rising identity theft numbers. Reason – these takeovers have nearly doubled to 680,000 victims in 2018, compared to 380,000 in 2017. Having a hostile mobile phone account takeover empowers users to bypass two (2FA) and multi-factor (MFA) authentication techniques.
  • Good news – The study shows that using embedded chip cards is helping to keep attackers at bay for card frauds. It has shown the steepest decline as compared to other fraud types in 2018, with losses recorded at US$14.7 billion in 2018, down from US$16.8 billion in 2017.

Personal information is not just valuable to hackers because they gain access to an individual’s financials through Identity theft, but also because every record holds a price tag on the dark web. These records are sold on a scale of a few dollars per credit card details to a few thousand dollars for medical records. Due to the kind of money involved and personal privacy at stake, nations around the globe are now taking data breaches rather seriously and Canada is not far behind.

Canada’s PIPEDA

The Personal Information Protection of Electronic Documents Act (PIPEDA) has undergone some changes with effect from November 1, 2018 and has significantly impacted the compliance requirements and data breach reporting of Canadian businesses. Since the implementation of the improved PIPEDA version, the Office of the Privacy Commissioner of Canada (OPC) has seen reporting of 446 data breaches between November 2018 and June 2019, which has affected around 19 million Canadians. This is a drastic rise of nearly six times in the number of reports received during the same period of November 2017 and June 2018.

Of the 446 breaches reported to the OPC,

  • 59 percent reported the reason as hacking mainly due to “internal bad actors”.
  • 22 percent were from accidental disclosures, such as information being sent to the wrong person or being left behind.
  • 13 percent of reports accounted for the physical loss of data. This includes and is not limited to USB drive, corrupt hard drives and even paper files.
  • 6 percent of the breaches were due to physical theft of things like computers, drives or paper files.

Data Breach and Identity Theft, ID Assist

There are a number of steps that an organization can take to mitigate and manage data breaches.

Best practices to mitigate data breach risks

  • Training & awareness: The most important and often overlooked entity is employee training. As the above data suggests, most breaches occur due to internal bad actors. Thus, spreading awareness across various levels of the organization is of utmost importance.
  • Vulnerability assessment: Find loopholes and secure IT infrastructure/architecture. Regular IT audits, vulnerability assessment of entire system architecture and patching the identified threats should be carried out thoroughly and regularly.
  • Budget allocation: Include cybersecurity in your company’s annual budget for allocating and hiring the necessary resources.
  • Outsource cybersecurity: So that unforeseen security risks are mitigated, and data breach response is handled by respective domain experts. This reduces the risk of future attacks as well.

Managing a Data Breach

We can take adequate measures and follow best practices, however being 100 percent secure is a “Myth.” Even the heavyweight corporates such as Capital One, Marriot, and Desjardins (we will elaborate more on the Desjardins data breach later) have not been spared from data breaches and identity theft scares after pouring in millions in cybersecurity. What businesses of today need to be ready with is a solid plan of action after the data breach security and prevention measures have failed.

So how do we manage a data breach and minimize the damages? We can divide it into 7 steps:

  1. Don’t Panic: Pressing the panic button often leads to chaos. Instead, sit back, assess the damages. Be sincere and admit your company’s mistakes and shoulder responsibility.
  2. Communicate: Inform both your internal stakeholders (employees, managers, PR team, etc.) and external stakeholders (clients, end-users, press and media).
  3. Provide details: After conducting cyber forensics, provide accurate data breach details to all stakeholders. Explain what went wrong.
  4. Provide solutions: Designate a team to provide solutions for affected users. Guide them through and provide them solution from the ongoing problem.
  5. Provide monitoring services: Your customers are already troubled and tensed, but a helping hand in times of crisis helps regain their trust in your company. As a value add and confidence-building measure give them an offer that they can’t resist. Along with 24/7 assistance provide users secure solutions such as identity protection and credit monitoring for free.
  6. Train and educate: The biggest mistake that company’s often make is they neglect the fact that this can happen again. Train your employees and explain how to prevent similar issues in the future.
  7. Discuss: Involve everyone, your C-suite, clients, experts, analysts, media and general public. You never know who might just end up giving you a million-dollar solution.

As mentioned earlier let’s consider the Desjardins data breach and its incidence response. It is one of the prime examples of how an incidence response can be handled efficiently. They ticked off almost all the boxes of data breach management. Have a look:

  • Maintained transparency (with internal and external stakeholders)
  • Went public (Reported it to the OPC and gave a press release)
  • Provided unconditional support to government authorities and its customers
  • Found the root cause of data breach (breach took place due to an internal employee)
  • Got it fixed (Fired the employee and notified OPC about it).
  • With new findings, Desjardins updated the data breach records number and kept OPC and press in the loop (number of records stolen went from 2.9 million to 4.2 million)
  • Provided credit monitoring to all members who do banking with Desjardins, current and past — an estimated 8 million people across Canada.

Executing such a systematic incidence response plan not only shows transparency of processes to your clients but also reinstates their trust in your company, which is the basis of PIPEDA. As we have already seen: The question isn’t about if your data will be compromised. The question is when? So, what should you look for in a solution?

A solution like ID Assist has all the features to protect your company from identity theft and data breaches.

What is ID Assist?

ID Assist is the 911 for data breaches. It’s a turnkey solution that can be deployed immediately to limit the damage for your customers―and brand― in the event of a crisis. Canada has two primary credit reporting agencies — Equifax® and TransUnion® who record information received from creditors. A single lender may use one or both credit reporting bureaus to check your customers’ creditworthiness. Thus, ID Assist holds the upper hand over here as it provides dual bureau credit monitoring to its customers. It also acts as an early warning system that alerts the customers and helps limit the damages caused by identity theft and financial fraud.

At times just monitoring is not enough and if your identity has already been stolen then ID Assist will still be there for you. How? It provides full expert restoration assistance to all its customers along with a certain degree of legal assistance through a limited power of attorney. This means all your bases are covered and you may now heave a sigh of relief!

Conclusion

From the above narrative, we can conclude that data breach and identity theft can affect all types of businesses and individuals whose data is shared or stored online. It means that having a data breach prevention plan for defense and an incident response plan as an offense to such attacks is no longer an option; it’s a must-have and unique service providers such as ID Assist perfectly fit the bill for being an integral part of this plan. Frequent security assessments, IT audits, patch fixes and having a set of fixed guidelines in the form of an incidence response plan helps in minimizing loss of data and more importantly, your clients’ trust.

Start your breach readiness plan today – make sure your organization is ready with ID Assist.

Green Padlocks Used as Phishing Baits

Phishing Campaign on FINRA

A green padlock followed by the organization name (also in green color) means that website uses an Extended Validation (EV) certificate. Green padlocks without the following organization name in green color, means that website uses a TLS/SSL certificate and not EV certificate. An EV certificate is a special website certificate that requires a significantly more stringent identity verification process than other types of certificates. To verify and prove exclusive rights to use a domain, the domain owner must confirm its legal, operational and physical existence, and prove the entity has authorized the issuance of the certificate. This verified identity information is included within the certificate, with business name and country, presented directly in the browser window. But with free and open certificate issuing authorities like Let’s Encrypt, who are providing the same level of encryption and certificates for small organizations, cybercriminals are using them for impersonating phishing sites as legitimate ones.

“Year over year, month over month, phishing is becoming more prevalent,” says Bob Maley, NormShield’s CSO. “The bad actors are getting these phishing domains and registering them. Then they are standing up phishing sites on those domains that are essentially clones of the various e-commerce sites to fool the end user into believing they’re on a legitimate e-commerce site.”

NormShield’s report also threw up a few surprising numbers related to phishing attacks carried out in the past few years:

  • The number of potential phishing domains for top 50 ecommerce sites has multiplied 6x times in the last four years. While it was under 1,000 in 2016, it now stands well above 6,000 so far in 2019.
  • The number of phishing domains registered in the first 9 months of 2019 is 11% higher than during the same period in 2018.
  • 30 percent of the possible phishing domains registered in 2019 have certifications. When compared with 2018, the number of certified phishing domains are three times higher in 2019.

Experts still are and recommend users to look for the domain registrars of suspicious websites and not just the green padlock icons in the URL box. Cybercriminals have a tendency of using free and low-cost registrars for setting up phishing domains. They further advice to avoid random clicking on URLs that come in holiday seasons’ promotional emails and to be careful with typo mistakes that leads to typosqautting/URL hijacking. refusing to provide saved credentials for sites also can be a strong indicator of an illegitimate phishing website.

In a similar research done earlierby Venafi, a cybersecurity software company which secures and protects cryptographic keys and digital certificates, the company said it had uncovered nearly 100,000 typosquatting/fake domains with valid TLS certificates impersonating as major retailers.

Corporate Email is a Root for Accidental Data Breaches: Survey

Business Email Compromise Attacks

According to a survey, titled Current Status of Data Privacy Compliance, from Email security provider Egress, around 44 percent of employees admit that they’ve mistakenly exposed personally identifiable information (PII) or business-sensitive information using their corporate email accounts. Over 70 percent of respondents have experienced this type of breach during the last five years, with half of these incidents occurring in the previous 12 months.

The survey also highlighted that accidental internal breaches are rising. Based on the responses from 500 IT security decision-makers in the U.S., accidental employee breaches are ranked as one of the top three security concerns (46 percent), behind external hacks (55 percent), and malware attacks (53 percent).

Egress helps enterprises with its human layer security solutions to receive, share, and manage sensitive information securely, meeting compliance requirements. The company claims that it uses contextual machine learning to ensure information is protected against the risk of data breaches. Egress said it commissioned a web-based survey to verify the current status of data privacy compliance.

Emails Pose Major Risk

Both corporate and personal emails are the main cause for accidental data leaks, according to survey results. The other risks include file-sharing services (39 percent), collaboration tools (34 percent), and SMS instant messaging (33 percent).

Despite awareness of these risks, one in four respondents (26 percent) stated that employees share sensitive data outside of the organization without encryption. Also, internal data sharing has become a risky task, with 65 percent of respondents revealing that their organization does not use encryption for internal data sharing.

The security leaders stated that around 93 percent of organizations have already taken steps to comply with regulations like GDPR (General Data Protection Regulation) and the pending CCPA (California Consumer Privacy Act).

And the results include improved use of security technologies (58.8 percent), better data handling practices (55.8 percent), investment in new security technologies (55.2 percent), staff education (39.6 percent), and hiring new security personnel (29.2 percent).

“We’re only human and people are always going to make mistakes. But as the workforce has become more reliant on digital communication, and is increasingly remote and flexible, it has also become more difficult for traditional network perimeter security technologies to protect data,” said Tony Pepper, Chief Executive Officer at Egress. “People are now the new security perimeter in most organizations, and as a result, businesses need to evolve the way they protect themselves. This research highlights the growing imperative to detect abnormal human behavior – including accidental data leaks – to stop breaches before they occur.”

Amazon’s Blink Smart Security Cameras Vulnerable to Attacks

Researchers from vulnerability detection firm Tenable discovered seven critical vulnerabilities in Amazon-owned Blink XT2 security camera systems. If exploited, the vulnerabilities could allow hackers to remotely view the camera footage, listen to audio output, and use the infected device to launch distributed denial of service (DDoS) attacks.

In response, Amazon rolled out patches for the vulnerabilities and urged its users to update their devices to firmware version 2.13.11 or later.

Vulnerability Details

Of the seven vulnerabilities identified by Tenable two are critical. These include command injection flaws CVE-2019-3984, which exist in Blink’s cloud communication endpoints, and CVE-2019-3989, which exist in helper scripts on the device. The other five vulnerabilities include CVE-2019-3983, CVE-2019-3985, CVE-2019-3986, CVE-2019-3987, and CVE-2019-3988.

“Connected devices, like Blink cameras, are everywhere. Precisely for that reason, cybercriminals are focused on compromising them,” said Renaud Deraison, co-founder and chief technology officer, Tenable. “Manufacturers of IoT devices have an opportunity and an obligation to ensure that effective security is baked into the overall design from the start and not bolted on as an afterthought.”

“This is especially critical when the device in question is a security camera. We thank Amazon for collaborating with us in this disclosure to ensure patches were released in a timely manner. Tenable Research continues to identify and disclose vulnerabilities across enterprise and consumer technology to keep everyone more secure,” Deraison added.

In a similar kind of discovery, researchers uncovered a flaw in Amazon’s Ring Video Doorbell Pro IoT device that could give hackers unauthorized access to the user’s Wi-Fi network and potentially to other connected devices on it. The vulnerability was discovered by researchers at cybersecurity firm Bitdefender. The researchers stated that all Ring Doorbell cameras have now received a security patch from Amazon to mitigate the issue.

Ring Doorbells are internet-connected doorbells that provide motion-sensing and video surveillance capabilities. It allows users to see and communicate with people outside their doors via an app, even if they’re outside.

According to researchers, the vulnerability stems when the Ring smartphone app sends wireless network connections to the Amazon Ring servers in the cloud. It’s found that this process is taking place in an insecure manner, which can be exploited by bad actors.

Wearable Tablet Prone to a Cyber-Attack?

Wearable

Deny or accept, but technology has always been a part of our lives and now it’s almost become one with our bodies too. Wearables have become more practical, easy to use and more affordable than ever. But the rising popularity means hackers and bad actors are taking notes of the same.

Wearable smart glasses and headgear such as Google glasses, Samsung’s Gear VR, RealWear HMT-1, etc. have seen a steep rise in sales as they are not just providing Augmented Reality (AR) solutions but enterprise level solutions. For example, RealWear’s HMT-1 wearable Android tablet (headgear) has a wide offering – Voice based operating system, integrated speaker, four digital microphones, noise cancellation, video streaming, image zooming and many more. But with it comes the security quotient–is it cyber secure?

Consider a scenario where an employee brings his own headgear or smart glasses to work, which are connected to his smartphone. His phone, in turn, is connected to a company or private (for on-fieldworkers) network where sensitive customer data is stored, such as credit card and account numbers. A hacker intercepts the Bluetooth feed from the wearable and steals a customer’s login credentials to drain the bank accounts. That’s it, gone in 60 seconds! Thus, the answer is “Yes,” wearables can be hacked, and they are going to be targeted sooner or later.

So, what must organizations do to mitigate this?

Define organizational level policies to safeguard and protect customers and internal stakeholders from cyber threats via wearables. Apply latest software and firmware upgrades on timely basis as and when they are released.

In a similar firmware upgrade announcement RealWear has announced the upcoming availability of HMT Release 11. With the release of this firmware, CIOs and IT managers will have a complete control over foundational level enterprise-ready security and performance of RealWear’s flagship HMT-1 wearable computer.

“Ease and confidence of secure integration is everything to an IT professional looking to support the growing demand for RealWear HMT-1s in the enterprise. “This release will be included in all new purchases early next year as well as for thousands of existing customers worldwide as an over-the-air update, free of charge,” said Patrick Neise, Chief Information Security Officer, RealWear.

This release is touted as very important for CIOs and IT directors since it gives them the liberty of treating RealWear’s wearable device HMT-1 and HMT-1Z1, just like any other approved mobile phone or tablet in their enterprise. It adapts robustness and allows them to manage everything centrally. In addition to a full voice-controlled user interface, RealWear’s HMT Release 11 includes specialized features such as:

Device Management – A central administrator can now own and manage the devices in their workforce.

Light Touch Enrollment – A user or administrator can perform a one-time scan of a QR code to quickly provision an HMT into an enterprise network.

Multi-User Support – HMT Release 11 sets the foundation for supporting multi-user environments included in coming releases.

RealWear is a knowledge transfer platform provider that helps companies in providing information and on-field training using software and hardware, thereby, improving the safety and productivity at workplace. Its flagship product, the HMT-1, is a revolutionary head-mounted, wearable, tablet computer that frees a worker’s hands while performing hazardous work.

Earlier in August, RealWear acquired Kopin’s Golden-i Infinity. Kopin Corporation is a provider of innovative wearable technologies and critical components for integration into wearable computing systems for military, industrial, and consumer products. This acquisition helped RealWear further strengthen its R&D and market share as Kopin’s technology portfolio includes ultra-small displays, optics, speech enhancement technology, voice-interface and hands-free control software, low-power ASICs, and ergonomically designed smart headset reference systems.

Rewind: Biggest Cyber Incidents We Saw in 2019

By Rudra Srinivas

 If there is a thing or two that we can learn from the year that went by, it is the fact that our data is never safe and can be compromised at any given point.  All sorts of cyber-attacks, be it data breaches, ransomware attacks, phishing campaigns, advanced attacks, and even state-backed hacking campaigns hogged limelight throughout the year in its entirety.

It is given that cyber threats are ever-evolving but before we start to analyze what will scare us the most in the future, it is important to hark back on the major security incidents that we already witnessed this year. This is a quick rundown.

Leaky Elasticsearch Server

Security researchers discovered an open Elasticsearch server that contained unique data records of around 1.2 billion users. According to security analysts Bob Diachenko and Vinny Troia, the server held more than 4 terabytes of data, without password protection or authentication.

The exposed data included names, email addresses, phone numbers, LinkedIn, and Facebook profile information. It was believed that the exposed data appeared to have originated from two different data enrichment companies—People Data Labs (PDL) and OxyData.Io (OXY).

“The data discovered on the open Elasticsearch server was almost a complete match to the data being returned by the People Data Labs API. The only difference being the data returned by the PDL also contained education histories. There was no education information in any of the data downloaded from the server. Everything else was the same, including accounts with multiple email addresses and multiple phone numbers,” the researchers said in a statement.

JustDial Data Breach

A security flaw in JustDial systems, an Indian-based local search services provider, left data of around 156 million of its users vulnerable. However, the company managed to patch the bug after a security researcher Ehraz Ahmed flagged the issue.

The researcher explained in a video that how a hacker could use any JustDial user’s phone number as username and gain access to the account by exploiting the bug. Ahmed also revealed the bug allowed hackers to change account details for JustDial’s payment option — JD Pay, allowing them to redirect all the money into their account.

JustDial clarified that no loss of data or money was reported. “We at JustDial take security seriously. There was a bug in one of our APIs which could potentially be accessed by an expert hacker. This bug has been fixed. We work with various security researchers to strengthen our platform and would like to thank Ehraz Ahmed for bringing this out to us,” JustDial said in a statement.

Capital One Data Breach

Capital One Financial Corporation, a bank holding company, disclosed a data breach in July which affected approximately 100 million individuals in the United States and nearly 6 million in Canada. The company stated that the attacker exploited a specific configuration vulnerability in its digital infrastructure and allegedly accessed the data.

The compromised information included names, addresses, phone numbers, and dates of birth, along with 140,000 Social Security numbers, 80,000 bank account numbers, credit scores, and transaction data. However, Capital One clarified that no credit card account numbers or log-in credentials were compromised in the incident.

The FBI charged a suspect, Paige A. Thompson, with computer fraud and abuse. Thompson, who went by the hacker name ‘erratic’, allegedly exploited a misconfigured firewall to access the Capital One cloud repository and exfiltrate the data in March 2019.

Facebook Data Leak

An unprotected server which hosted a Facebook database leaked millions of Facebook users’ phone numbers online. According to reports, the server wasn’t password-protected, allowing anyone to access it. The database contained more than 419 million records of Facebook users across the globe, including 133 million records of U.S. users, 18 million records of U.K. users, and more than 50 million records of Vietnamese users. The records contained unique Facebook IDs and the phone numbers linked to their accounts.

In April 2019, researchers also discovered a massive trove of Facebook user account information being exposed on Amazon cloud servers. The security team at UpGuard stated that they found two data breach incidents in different regions. Facebook also admitted to another data breach involving roughly 100 third-party app developers who had improper data access. This incident exposed around 146 GB of data that contained over 540 million records detailing comments, likes, reactions, account names, FB IDs, and other sensitive information.

Canva Hack

Canva, an Australian online design tool, revealed that hackers breached its network systems and stole data of nearly 140 million users in May 2019. The company stated that the usernames and email addresses of customers were accessed in the incident.

According to Canva, encrypted personal data like usernames and passwords were accessed by hackers. And, no credit card details or designs were exposed/accessed in the attack.

DoorDash Hack

DoorDash, a San Francisco-based food-delivery service provider, faced a massive data breach that affected data of around 4.9 million people (its customers, delivery workers, and merchants), who were using its service platform.

The company said that an unauthorized third-party accessed its user data on May 4, 2019. DoorDash clarified that users who joined its services platform on or before April 5, 2018, were affected in the incident and the ones who joined after April 5, 2018, weren’t.

Ecuador Data Breach

Almost everyone in Ecuador became a victim of a massive data breach that exposed the personal information of over 20 million individuals. This included the country’s president and WikiLeaks founder Julian Assange, who was granted asylum by Ecuador in 2012.

Security firm vpnMentor discovered the breach on a Miami-based Elasticsearch server owned by an Ecuadorian company Novaestrat. It’s said that the exposed data appears to have come from various sources, including the Ecuadorian national bank, Ecuadorian government registries, and an automotive association called Aeade. The exposed information included names, date of birth, contact information, National identification numbers, bank account details, taxpayer-identification numbers, and driving records.

Instagram Data Breach

The Facebook-owned photo-sharing application Instagram had discovered that an unsecured server containing personal information of millions of Instagram influencers, celebrities, and brand accounts have been found online.

According to the security researcher Anurag Sen, who discovered the leak and notified TechCrunch, the database had over 49 million records exposed online, allowing anyone to access the data. The exposed data included users’ biodata, profile picture, the number of followers they have, their location by city and country, and contact information like the Instagram account owner’s email address and phone number.

The researcher stated the leaky database belonged to a social media marketing firm Chtrbox, which was based in Indian city, Mumbai. The database was taken offline and an investigation was led toward the incident, Chtrbox stated.

With these examples, it is well-established that our data has never secure. There’s nothing consumers and companies can do except practice preventive security measures and adopt policies that better protect the data.

Download CISO MAG December 2019 to read about the biggest news events of the year, Cybersecurity startups of the year, CISO MAG Editor’s choice for the best security technology, and the Cybersecurity Persons of the year.

Rudra Srinivas is part of the editorial team at CISO MAG and writes on cybersecurity trends and news features. 

Why CDNs Should be Staple for Web and Apps

Content Delivery Network

By Joshua Blackborne

The world is going mobile. Statista reports that mobiles account for more than half of the global online traffic including 48 percent of all web page views, 62 percent of all video plays, and 64 percent of all retail visits worldwide. It’s evident that smartphones and tablets are the people’s new choice for browsing the Internet.

Though it’s beneficial to the online retailers and service providers in terms of growing traffic, however, it brings various challenges as well. Among them, the biggest challenge is the need for superfast websites. Since mobile networks are slow and unreliable, mobile users may experience slow page-loading times, which shackles their experience. Then, if the user isn’t happy, he may just close the web page, switch to a competitor, or skip buying the product.

In either case, it’s a big loss for you as an online retailer or a service provider. That’s why Content Delivery Networks are important — they help speed up your web apps or websites. However, that’s not all, there are many more reasons for using CDNs. But first, let’s get to know the fundamentals of Content Delivery Network (CDN).

What is Content Delivery Network?

A CDN refers to the geographically distributed platforms of servers (usually data centers) that work together to provide fast content delivery. The content usually includes HTML pages, CSS stylesheets, JavaScript files, images and videos, documents, and more.

Since its advent in the late ’90s, the popularity of CDNs has ever grown, thanks to the ever-growing size of websites and shrinking users’ patience levels. Even if you don’t know, this web page and the majority of web content is served using CDNs. For example, the videos you view on YouTube or the shows you watch on Netflix — all are quickly served to you via Content Delivery Networks.

How does it help speed up your website? Let’s suppose your website is hosted in London, England, and your user is located in Jakarta, Indonesia; then the content has to travel all throughout London to Jakarta. But if you opt for a CDN, and its servers are located in Singapore, then the content only requires to travel from Singapore to Jakarta, thus the website is loaded a lot faster than earlier.

3 Reasons to Use CDN for a Website

Since now you know about the fundamentals of Content Delivery Networks, let’s learn the key benefits of or the reasons for delivering content via CDNs.

1. Boost the Page-load Speed

Since we looked at mobile page speeds last year, the average time it takes to fully load a mobile landing page has dropped by seven seconds. The bad news is that it still takes about 15 seconds, according to our new analysis. That’s far too slow when you consider that 53 percent of mobile site visits leave a page that takes longer than three seconds to load. Our data shows that while more than half of overall web traffic comes from mobile, mobile conversion rates are lower than desktop. In short, speed equals revenue,” according to a post by Think with Google.

As it’s told, mobile page speeds are slow and 53 percent of site visitors leave a page if it loads slowly, i.e., 53 percent of site visitors usually leave a loading page. So, you must opt for CDNs to improve the page-load speeds, which lead to faster performance and lower latency, which further helps in pledging better user experience.

2. Improve the Website SEO

Speeding up websites is important — not just to site owners, but to all Internet users. Faster sites create happy users and we’ve seen in our internal studies that when a site responds slowly, visitors spend less time there. But faster sites don’t just improve user experience; recent data shows that improving site speed also reduces operating costs. Like us, our users place a lot of value in speed — that’s why we’ve decided to take site speed into account in our search rankings,” according to Google Webmaster Central Blog. That means if your website is not fast enough, it loses its ranking in the search engine result pages on Google Search.

So, what’s the solution? Content Delivery Network is the answer to solving the speed problem of any website. As it’s already told above, CDNs help to speed up content delivery. And when a website is fast, Google Search ranks it higher on its search engine result pages. It’s not just Google, but many major search engines use page-loading time in their formulas for ranking websites.

In short, if your website has faster page-load times, it helps in boosting Search Engine Optimization (SEO). Also, if you opt for CDNs, your website becomes fast, meaning your images load fast as well. That means Google will crawl your site and its images frequently, letting them get indexed faster by Google.

3. Secure the Infrastructure

Since the Content Delivery Networks live at the front of your website, i.e., most of your web traffic passes through CDNs. So, if the CDN supports any security features, your website is double secure against online threats. For example, Imperva’s CDs is integrated with a DDoS attack and failover features — one of the worst attacks for any website, especially when such attacks or threats are on the rise.

What are the reasons? First of all, CDNs bear the most load of your website, so they help to keep your website up and running — even if your primary web host is down or failing to attend to the heavy load (i.e., a large number of incoming web requests). Then, if the origin web host is directly attacked, CDNs still keep your website up and running, thanks to the replication of website data.

That’s not all; “In 2016, about 29 percent of website traffic came from bad bots. We’re not going to delve much into what bad bots are, but suffice to say, they’re not doing your website any good. The typical bad bots are either impersonators, sites which mimic legitimate tools to try and attack your website, or straight up malicious hacking tools. Most CDNs have built-in mechanisms to implicitly block bad bots, which will not only reduce the load on your server but also prevent many of attacks from happening in the first place,” according to a post by WPMU DEV.

That’s all about Content Delivery Networks (CDNs) and their primary benefits for any web app or website — traditional or modern.

Disclaimer: CISO MAG did not evaluate the advertised/mentioned product, service, or company, nor does it endorse any of the claims made by the advertisement/writer. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

2.7 Billion Email Addresses Exposed Online

Data breach in 100 U.S. cities

Researchers noticed a huge database containing email addresses and passwords left online without password protection.

A joint investigation by cybersecurity firm Comparitech and security researcher Bob Diachenko revealed that a database of more than 2.7 billion email addresses exposed online, allowing anyone to access identity information. It also stated that around one billion of those records contained a plain-text password list related to exposed email addresses. The leaky database was taken down on December 9, 2019, after Diachenko alerted the U.S. ISP that hosted the database on December 04, 2019.

According to reports, the majority of exposed emails were from Chinese domains including qq.com, 139.com, 126.com, gfan.com, and game.sohu.com, which belonged to China’s popular internet firms Tencent, Sina, Sohu, and NetEase.

“Comparitech immediately took steps to take down the database upon discovering in order to mitigate harm to end-users, but we don’t know if anyone accessed it in the meantime,” researchers said in a statement.

Risks with Exposed Data

Cybercriminals make use of the stolen data in credential stuffing attacks. In credential stuffing attack, a hacker tries to log into various user accounts with known email and password combinations. Attackers take advantage of the fact that most people reuse email ids and passwords for multiple accounts. Once hackers gain access to an account, they try hacking other accounts by changing password combinations. The compromised accounts are used for a variety of purposes including spam, phishing, fraud, and identity theft attacks.

Earlier, a similar leaky database left around 773 million email addresses and more than 21 million passwords unprotected online. According to security researcher Troy Hunt, the person behind the breach notification service website Have I Been Pwned, a huge database that includes records from more than 2,000 hacked databases was exposed online.

The breached data, which Troy Hunt dubbed as Collection #1, include around 773 million (772,904,991) unique email addresses and 21 million (21,222,975) unique passwords. Sized around 87 GB, the breached records also included 1,160,253,228 unique combinations of breached email addresses and passwords. Hunt stated the data breach is made up of various individual data breaches from thousands of other sources.

Previous Security Vulnerabilities Still Exist in New Android Applications

PhantomLance Targets Android App Store to Spread Malware and Spyware, message encryption for Android

Security experts have observed that Android app makers have not patched the old security flaws, many of which even dates back to 2014. According to Check Point Software Technologies, most of these vulnerabilities exist in popular Android apps on the Google Play Store, including Facebook, WeChat, Facebook Messenger, Instagram, and Yahoo.

Source of Security Flaws

The researchers stated that app developers manage to copy code from vast code libraries while developing an application. Here, security bugs which existed in these code libraries get carried over to new Android apps.

“A popular mobile app typically uses dozens of reusable components written in a low-level language such as C. These components, called native libraries, are often derived from open-source projects, or incorporate fragments of code from open-source projects. When a vulnerability is found and fixed in an open-source project, its maintainers typically have no control over the native libraries which may be affected by the vulnerability, nor the apps using these native libraries. This is how an app may keep using the outdated version of the code even years after the vulnerability is discovered,” Check Point said in a statement.

“It may be overstating matters a bit to declare such an app vulnerable, as its flow may never reach the affected library code, but it certainly warrants an in-depth investigation by the app maintainers,” the statement added.

Check Point opined that while mobile app stores and security researchers scan applications for malware, they often give less attention to long-known critical flaws.

In its similar research, Check Point discovered that more than half of modern Android smartphones, including models by Sony, LG, Samsung, and Huawei are vulnerable to a text-based phishing attack.

Malicious actors are using fake phone provisioning messages to trick Android phone users into accepting new settings that provide access to attackers. The researchers stated that the phishing attack is performed through a process called over-the-air (OTA) provisioning, according to Check Point.

Check Point detailed the attack process as OMA CP (Open Mobile Alliance Client Provisioning) instructions, which is a special SMS sent by a mobile operator to new devices for network connection. Attackers sending fake OMA CP messages to users, which allow them to allegedly access the victim’s email and web traffic.

Is Penetration Testing the Answer to Big Data Security?

Digital Transformation

“Big Data” – In recent times, these two words are enough to get people all excited. However, the first word, “Big” doesn’t mean that big data is limited to just “bigger” companies or for organizations catering services to even “bigger” audiences. Big Data means gathering large sets of data, processing and analyzing them as per our business needs, and then systematically putting it to use for maximizing business opportunities and subsequent profits.

Statistics show that revenue generated from big data has skyrocketed, and we have proof. In 2015, it was responsible for profits amounting to US$122 billion. It’s expected to generate US$189.1 billion by the end of 2019. Hold on, and we’re not done yet–these numbers are expected to reach a whopping US$274.3 billion by 2022. Woah! Now that’s an enormous number.

Big data is helping businesses from various domains like healthcare, banking, media, retail, energy, and utilities grow at an unprecedented rate. But in the middle of all this happiness of having limitless power in our hands, we often overlook the pitfalls associated with it.

Companies working on big data handle vast chunks of user data and personalized information to analyze certain trends. This introduces some pitfalls that we were talking about; data breach, cybersecurity compromises, and privacy lapses are the biggest challenges of having a secured big data environment. Let’s have a look at the challenges by assessing the security implications in various phases of the data science lifecycle.

Security Concerns in Data Science Lifecycle

The data science lifecycle doesn’t follow a set guideline as such. While this “wheel” generally moves through the phases in a set order, it may be possible to move in either direction (forward, backward) at any stage in the cycle. Work can take place simultaneously in several phases, or you can skip over an entire phase if required. In addition, if new information is discovered, work may return to an earlier or the first phase of the data science lifecycle.

A simplified data science lifecycle typically encompasses five phases, each of which will have unique security implications, while also being supported by a foundation of strong organizational security policies and practices. Let’s have a look at them.

Collection

Have you empowered the appropriate legal, privacy and compliance controls for employees who are authorized to acquire data?

Ex. Data Engineers have received privacy and data security training.

Preparation

Have you validated the data, labeled it effectively, and documented it as part of your data inventory?

Ex. The Privacy Impact Assessment (PIA) has been updated to align with the organization’s EU General Data Privacy Regulation (GDPR) compliant processes, which may be a targeted subset of your overall data inventory.

Analysis

Do the authorized employees know when there is an outlier and how to engage the necessary process to adhere to data handling practices?

Ex. A free form field or unstructured data that should be encrypted is surfacing sensitive customer details in clear text, and your analyst knows how to communicate, and to whom.

Action / Insights

Are access and authorization controls adequate to manage the distribution of a report?

Ex. Distribution of artifacts is through ChatOps, Email, or Shared Links that are updated through automated processes; of these processes are reviewed every quarter.

Monitoring

Have you deployed automated capabilities, which analyze actual data through Collaboration Tools, Applications, APIs, Services for passing data that had not previously been authorized?

Ex. Third-Party Plug-ins have been enabled through click-through software agreements by the marketing team in the organization’s Customer Relation Management software, but access is granted to read-all data.

Security Controls for Big Data Security

As seen above, in each phase of the lifecycle, there are security loopholes that need to be monitored, assessed, and plugged correctly to prevent an explicit and highly sensitive data breach and loss. There’s a whole bunch of security controls that specifically support big data security that should be reviewed from time to time, and potentially strengthened, as part of big data security review. Here are a few of them:

Access Control and Authorization

Organizations with valuable data need to monitor who has access to what data where. Implementing role-based access control, using strong authentication methods, and maintaining robust and auditable access control policies and procedures is a critical part of mitigating insider threats.

Personnel Security

Reducing the potential for unauthorized data usage by trusted insiders is particularly crucial for any company working with big data, given the high value of the information individuals are authorized to work with. Standard due diligence during the hiring process is one mitigating factor. However, the assurance process should continue even after onboarding as both personal circumstances of employees can change, as well as their access levels and roles. 

Endpoint Security

Compromised endpoints are often the primary vehicle for data leaks. Sensitive data can be exposed through device loss or theft, as well as users intentionally or accidentally not following security policies, for instance, accessing information via unsecured wireless networks. As such, extending data protection to the endpoint is critical. This is often accomplished by creating personas for the data team coupled with authentication profiles and insider threat monitoring. 

Maintaining Data Hygiene

As data science moves into a more strategic business function, data scientists and business managers are asking for more and more access to the data and the systems that support its collection, analysis and reporting. Security teams seeking to both enable the business and protect its data need to apply appropriate data hygiene practices to empower the data science team without compromising security or the integrity of the data they use.

Data Encryption

Data should be encrypted, both at rest and in motion, and the encryption must extend to endpoint devices. Security teams should follow encryption best practices for sensitive information and be mindful of ensuring proper key management as a poorly performing key management system will compromise even the most robust encryption algorithms.

Use Penetration Testing to stay one step ahead of hackers

Infrastructure penetration testing helps in giving critical insights into your business database and associated processes and helps keep hackers at bay. Penetration testing is a simulated malware attack against your computer systems and network to check for exploitable vulnerabilities. It is like a mock-drill exercise to check the capabilities of your existing networks and processes. Penetration testing has become an essential step to protect IT infrastructure and business data.

Penetration Testing as a Solution for Big Data Security

Penetration testing involves six stages:

  • Preparation: Scope definition of the pen test to be performed takes place in this stage. Accordingly, all the parties involved in the engagement are prepared.
  • Kick-Off: The kick-off call is generally a brief 30-minutes call between the customer and the pen testing team. It’s a confirmation that everyone involved has understood their roles and good to begin the pen-testing.
  • Testing: The first two stages are necessary for having a clear scope definition. But this is the moving stage. Here experts analyze the vulnerabilities and try to exploit the security flaws.
  • Reporting: Pen testers have done their job. It’s now time to formally put down all the findings together and report them to the customer’s system administrator or product manager. This should be an interactive and on-going process. Changes should be updated along with recommendations for the fix.
  • Re-Testing: Once the Customer is aware of the security issues identified during the pen test, addressing each issue happens over the course of the next few weeks and months. A re-test should be carried out to measure the effectiveness of the preventive measures. If any issues are still persistent, then go back to the reporting stage. Continue the last two stages until the vulnerability is completely fixed. Marking the issue(s) as closed, completes the sixth and final stage of penetration testing.

Sometimes vulnerabilities are there in plain sight of the system and network administrators and yet go unnoticed due to a large amount of big data. Thus, your company needs specialized services to fill in the cybersecurity vulnerability holes that exist.

Cobalt is one such solution provider that offers penetration testing as a service for modern SaaS businesses.

Cobalt offers a modern application security platform that provides a find-to-fix workflow for all penetration testing and vulnerability assessments carried throughout your organization. The ease with which it provides a clear, detailed, and actionable report of its findings through the Cobalt Central app is quite impressive. It also displays vital data in a visual format to convey different types of critical vulnerabilities. Not just that, Cobalt specializes in providing constant support and evaluation of issues reported until they are fixed by your system administrators or other responsible IT personnel.

Conclusion

Businesses are evolving and proliferating by using big data as a tool for achieving their goals and profitability. With the advent of artificial intelligence (AI) and machine learning (ML), there seems to be no stopping for this gentle giant called “Big Data.” You also need to consider the big data security implications. Frequently monitoring and improvising processes will bring in both monetary and cybersecurity benefits for your company. Periodic penetration testing can help ensure that your big data program is working efficiently and optimally. For this, security platforms like Cobalt, that have a robust and dynamic penetration testing and vulnerability assessment services on offer should be implemented to fill in any possible gaps and bulletproof your business from cyberthreats. 

See the Full Guide for more information on Big Data Lifecycle.