-
-
Linked: Top Password List of 2021 Proves You Need a Password Manager
I mean, you really should use one for the obvious reason listed here, it lets you create a ton of different passwords, and make them complicated enough that they are hard to crack, since you no longer have to remember them, but they also make it easy for you to help someone gain access to important information and accounts when you are unable to. Because believe me, it happens.
-
Linked: Over 1 million GoDaddy WordPress accounts breached
The breach of the WordPress credentials is bad, as is the sFTP credentials. Sure, if you are still using the same WordPress password that GoDaddy assigned to you when you started the account, you really need to step up your game.
WordPress is an inviting target, because getting admin access to a WordPress install, or really any other content management system, makes it super easy to lock out the original owner and inject anything you want into the site. Want a place to spread malware in drive-by injections? Nothing like an already existing, and maybe even trusted, WordPress site, eh?
-
Shared Links (weekly) Nov. 21, 2021
-
Most organizations had an unknown or unmanaged internet-facing asset exploited
-
The Most Important eDiscovery Phase is the One That Drives All the Other Phases
-
Embedding social media posts can be considered copyright infringement…but is it?
-
5 Reasons Why Networking Training Is the Antidote to The Great Resignation
-
Linked: Windows 10 is a security disaster waiting to happen. How will Microsoft clean up its mess?
Ed Bott raises an interesting question about people using PCs that don’t meet the requirements in terms of hardware security for Windows 11 but who own otherwise perfectly fine computers. In 2025, when Microsoft stops patching Windows 10, how many computers will still be out there, in use, connected to the internet, and vulnerable.
But in the quote above, Ed raises another point that maybe we should be thinking about more. What happens to all the hardware that is no longer supported as technology advances? It ends up in a landfill. That’s not good. That’s not even acceptable.
-
Linked: You know how to identify phishing emails – a cybersecurity researcher explains how to trust your instincts to foil the attacks
And so, I wonder if those yearly, semi-annual, quarterly, video training would be a lot more effective if we also shared specific examples of people who got phished, and how they fell for it?
Like most things in life, it’s one thing to hypothetically know that something could happen, but it’s quite another to know that it did happen to someone we know. Someone just like us. That makes it so much more real in our minds, and it appears to make a huge difference in how users might approach phishing attempts.
