Showing posts with label privacy. Show all posts

Cyber Security Awareness Fair Coming to CI This Week!

by in , , , , , , , , , , , , , , , , , ,

Dear Campus Community,

In celebration of National Cyber Security Awareness Month (NCSAM) 2019, CSU Channel Islands Information Security is hosting a Cyber Security Awareness Fair on Tuesday, October 29th and Thursday, October 31st, 2019 and you are invited! Come join us for a two-day event that will provide insights from security professionals on the latest cyber threats and landscape, and the opportunity to collaborate across the university.

The Cyber Security Awareness Fair will take place on the main Camarillo campus at the Broome Library in rooms 1310 and 1320 from 9:00 AM - 5:00 PM on each day and will include a pizza lunch on both days until the food runs out.

This is a free event that is open to the entire CI campus community!

Please share this information with your friends and we hope to see you there!

Agenda

Tuesday 10/29/2019

09:30 AM - 10:30 AM Cybersecurity Education at CI
11:00 AM - 12:00 PM Nation State Attacks: You are a Target!
12:00 PM - 01:00 PM Scams Targeting CI Students
01:00 PM - 02:30 PM Diversity in Cybersecurity Panel
02:30 PM - 03:30 PM Securing your Home Router
03:30 PM - 04:30 PM Multi-Factor Authentication is Coming…
04:30 PM - 05:30 PM CI Cyber Security Club

Thursday 10/31/2019

09:00 AM - 10:00 AM How Secure is the Internet: Developing Secure Elliptical Curve Cryptography
10:00 AM - 11:00 AM Using a Raspberry Pi for Home Security
11:30 AM - 12:30 PM Cyber Security Jeopardy
12:30 PM - 01:30 PM The Cyber Threat Landscape and You…
01:30 PM - 02:30 PM The DARK Web…




Equifax Breach Advisory

by Anonymous in ,

Given the recent announcement regarding the data exposure at Equifax we wanted to share some good “cyber hygiene” and some resources with you. With 143 million U.S. consumers affected it’s a good chance many of us are impacted.

Equifax has said there is no evidence of unauthorized activity in their credit reporting data bases but that there was potentially unauthorized access to information it stored from mid-May to July of this year. That information included social security number (SSN), dates of birth (DOB), addresses and in some cases Driver’s License numbers. Also reported is that approximately 209,000 consumers credit card numbers were exposed as well as other “dispute documents” for 182,000 consumers.

What can you do?

  1. One of the first things typically suggested after a breach is to access credit reporting agencies and request your records to be sure there are no unauthorized accounts or charges. In this case you may want to consider the other agencies, Experian and TransUnion. Also check your online and credit card accounts for suspicious activity. You can check free credit reports from annualcreditreport.com. Check for any accounts or charges you don't recognize.
  2. Be extra wary of scam emails and links. Avoid clicking on links or downloading attachments from suspicious emails. Equifax will send paper mail to consumers but hackers are sure to use this to conduct Phishing campaigns.
  3. Change your passwords, especially if you have/had an account with Equifax and use similar or the same password elsewhere.
  4. You can check at Equifax here to get information and to check and see if your records are impacted. You can also access your Equifax credit report here which is probably a good idea so you can compare with the ones you get from Experian and/or TransUnion.

Who Owns Your Computer?

by Anonymous in , , ,

I recently received a question from a faculty member that gave me the opportunity to explain better CI's responsibilities and obligations for campus-owned computers. To paraphrase her question:

If I use my faculty startup funds to purchase a laptop or iPad, does that become property of the university? And, is the entire computer searchable under the Freedom of Information Act, or only the files/documents pertaining to work and the university? I am looking to use start-up money to replace my home laptop, which I use 99% of the time for teaching and research. However, I do store personal items on the computer (family photographs, music,  personal email, etc.), so I would like to understand the nuances of university ownership of any computers I purchase with my research start-up money. 
Here's my reply, which is valid for any computer purchased with California State University funds, regardless of the source.

Start up funds are state resources, so any equipment purchased with them is property of the State of California. Technically, you are not using the funds to purchase a laptop or iPad – you are requesting that the funds be used to purchase a computer which is then assigned to you for your use. It’s probably more than you want to read, but if you’re interested, the full policy that addresses the use of any campus computer is here - https://www.calstate.edu/hrs/policies/policies_internet_use.shtml. Bottom line - for most purposes you can treat it as your computer, but really it’s a university resource as long as university funds are used to purchase it. Storing some photos or using your computer to buy something on Amazon is not a problem – It’s called “incidental use” and it’s explicitly permitted under CSU policy.

There are a few ways documents could be searched on your computer. The California Public Records Act (our version of the federal “Freedom of Information”) states that nearly anything you create as part of your employment is available upon request (including email and other things you might consider private, with just a few exceptions). However, these requests generally have to be somewhat specific, e.g “Every document that Professor X has regarding her Intro to Algebra Class”). So I’m not aware of any case where your personal items like family photos would be part of the search.  Caroline Doll is our campus expert on CPRA so she may have additional comments.

However, there are at least 3 other situations that I can think of where we have to search computers. These are all pretty rare, but here you go. One is when there is litigation – a judge can require that we search a computer or even turn over the entire contents as part of the evidence in a legal case. Second, if for some reason the university police have cause to believe that the computer was used for a crime (even if not by you) they could ask us to search it or they could confiscate it. Third, if your computer got “hacked” we might need to search it to try to determine what had happened and also to see what information might have been compromised. As I say, these are rare, but they do occur now and then. And we would certainly do our best in such a case to respect the user’s privacy and just look for the information that we needed, but of course it’s not always easy to determine that until you look.

Thanks for offering me the opportunity to provide this clarification. When you’re ready to purchase you can find models and pricing here - http://www.csuci.edu/tc/compquotes/. Your department coordinator should be familiar with the process.

Apple patches security flaws with new versions of iOS, OS X

by in , , , , , , , , , , , , , ,

Apple has packed patches for dozens of security flaws into the new versions of its iOS and OS X operating systems.

The company noted Tuesday in a security advisory that just-released version 8.4 of the iOS mobile operating system contains more than 20 fixes for vulnerabilities that could lead to remote code execution, application termination and the interception of encrypted traffic, among other issues.


Read more about these updates here.

Celebrate International Password Day!

by in , , , , , , , , , , , , ,

There are all sorts of days to celebrate during the year such as Mother's Day and Father's Day, and even some more off-the-wall days such as National Fried Chicken Day, Talk Like a Pirate Day, and a personal favorite, National Pancake Day.  But today is an extra special day that should be added to everyone's calendars.  Today is International Password Day!

International Password Day gives us all the opportunity to stop and reflect on what makes a good password, and how we can best protect our work and personal data by using strong password concepts.

To help you along, there's even a website dedicated too helping you figure out what makes a good password, how to deal with keeping track of the never ending list of passwords, mobile device passwords, and even some funny stories about password catastrophes!

Please take the time in joining your information security team in making every day a strong password day!


Don't be a victim of identity tax theft! The IRS is helping to protect false tax claims.

by in , , , , , , , , , ,

One of the hot identity theft scams is submission of false tax returns in order to receive unearned or earned refunds. The IRS has a process to try and detect these false returns. If they suspect a false return they will mail a letter to the address the taxpayer listed in their previous year return. The IRS letter directs the taxpayer to visit an IRS site to verify the tax return submitted. Legitimate letters should direct taxpayers to idverify.irs.gov. More details are contained in this link:http://www.irs.gov/uac/Newsroom/Taxpayers-Receiving-Identity-Verification-Letter-Should-Use-IDVerifyirsgov.

The IRS also has a great website page detailing active tax scams: http://www.irs.gov/uac/Tax-Scams-Consumer-Alerts.

If taxpayers suspect they are a victim of tax fraud/identity theft, they should contact the Treasury Inspector General for Tax Administration at 1-800-366-4484 or via the web at:http://www.treasury.gov/tigta/contact_report_scam.shtml

Taxpayers can forward scam emails to phishing@irs.gov.

Computer Security and You.

by in , , , , , , , , , , ,

Scammers, hackers, and identity thieves are looking to steal your personal information – and your money. But there are steps you can take to protect yourself, like keeping your computer software up-to-date and giving out your personal information only when you have a good reason.


Visit our friends at OnGuardOnline.gov and see what you can do to better protect yourself and your personal information.

Ransomware Infections on the Rise.

by in , , , , , , , , , , ,

In a recent news release by US-CERT, the United States Computer Emergency Readiness Team, US-CERT stated they are aware of a malware campaign that surfaced in 2013 and is associated with an increasing number of ransomware infections. CryptoLocker, a new variant of ransomware, restricts access to infected computers and demands the victim provide a payment to the attackers in order to decrypt and recover their files.  As of this time the primary means of infection appears to be phishing emails containing malicious attachments.

Everyone who makes use of computer systems, including email, should be on guard for these types of malware infection attempts.  In many cases the email will appear to be legitimate and harmless but you need to ask yourself if you were expecting this communication, and if not, contact the sender to make sure it's legitimate.

To help mitigate any loss of data should you fall victim to this infection, you should take regular backups of your system and store your important files onto your file server which is backed up regularly.

To get more information about CryptoLocker, follow this link to the US_CERT website and think before you click!

October is National Cyber Security Awareness Month (NCSAM)!

by in , , , , , , , , , , , ,


Each and every one of us needs to do our part to make sure that our online lives are kept safe and secure. That's what National Cyber Security Awareness Month—observed in October —is all about!

Please take the time to review some of our resources available to help you become more aware of the current landscape for cyber-threats.




Think you deleted that file from your system? Think again!

by in , , , , , , , ,

new video released by SANS.org this month titled "Data Destruction" will help you learn just how difficult it is to truly delete data, and that it actually requires a process called wiping.

Beware of Texting Hacks and Scams

by in , , , , , , , ,

You get a text message claiming your email account has been hacked. The message asks you to text back in order to reactivate your account. Has your account really been hacked, or is this a scam?  Read this short article to see what you should do if this happens to you.

Protect Yourself When Using Cloud Services

by in , , , , , , , ,

In simplest terms, cloud computing is a subscription-based or free service where you can obtain networked storage space and other computer resources through via the Internet. While these systems may remove the need for owning physical components, they also introduce new risks to your information. Before you float your digital assets to the cloud, make sure you take the appropriate steps to protect yourself.

Know your needs. Before you start, make sure you carefully plan what your security and privacy needs are. This includes knowing what your legal and regulatory requirements are for protecting data.
Read the contracts. End User License Agreements and Service Level Agreements are important because they describe the terms and conditions of the cloud service. If you're not sure of what they do or do not provide, contact the provider to clarify the services.
Protect Your Machine. Enable your firewall, use anti-virus/malware and anti-spyware software.
Protect your data. Don't store unencrypted sensitive information in the cloud. You don't know with whom you're sharing the cloud!

Scan Your Computer

by in , , , , , , , ,


Once an anti-virus and/or anti-spyware package has been installed on your computer, you should scan your entire computer periodically. If your anti-virus package has the ability to automatically scan specific files or directories and prompt you at set intervals to perform complete scans, enable this feature.

What can I do to protect my computer?

  • Don't click on pop-up ads that advertise anti-virus or anti-spyware programs 
  • Use and regularly update firewalls, anti-virus, and anti-spyware programs 
  • Properly configure and patch operating systems, browsers, and other software programs. 
  • Turn off ActiveX and Scripting, or prompt for their use.
    For more information, please visit:

    New Cloud Security Awareness Video Now Available.

    by in , , , , , , , , ,

    new video released by SANS.org is available this month to help you learn what the cloud is and how you can use it securely.

    New Social Networking Security Awareness Video Now Available

    by in , , , , ,

    A new video released by SANS.org is available this month to help you learn some of the most common risks of online social networking and the steps you can take to protect yourself and your family.

    Wireless Hotspots... Limit Activity to Web Surfing Only!

    by in , , , ,

    View today's CI Information Security Awareness blog post to see why you should use caution before connecting and using a free open wireless hotspot!

    IRS Releases the Dirty Dozen Tax Scams for 2013

    by in , , , , , ,

    View today's CI Information Security Awareness blog post to read about the IRS "Dirty Dozen" Tax Scams for 2013.

    If your browser questions a website's security, stop, think, and verify.

    by in , , , ,

    When visiting "https://" secure sites of banks and online shopping retailers, you may see onscreen warnings such as "There is a problem with the website's security certificate" or "Secure Connection Failed." Don't just click through to continue, or make a "one time" exception. The warning may only indicate that there is a harmless temporary problem with the site or with the network, but it can also mean that the site is bogus or has been compromised by hackers, and someone is listening in on your conversation with your bank or retailer.

    Be smart. Contact your bank or retailer by phone and find out if they know about a problem with their website or the network. Don't be the next victim of fraud.

    How to Spot a Phishing Scam

    by in , , , ,

    We've all received them, emails from a seemingly trusted source like a bank, delivery company or even your own place of employment, claiming there was some type of issue or another requiring you to offer up some personal information or to click on a link or button to help clear the issue up. If you receive an email similar to this DO NOT CLICK ON ANY LINK OR OFFER UP ANY INFORMATION! 


    This is a common form of security attack called a phishing or spear phishing scam.

    Groups attempting to steal personal information will often use e-mails that appear to originate from a trusted source to try and trick a user into entering valid credentials at a fake website. Typically the e-mail and the web site look like they are part of a bank or some other organization the user is doing business with.

    For example, it could be a phishing email if...
    • There are misspelled words in the e-mail or it contains poor grammar. 
    • The message is asking for personally identifiable information, such as credit card numbers, account numbers, passwords, PINs or Social Security Numbers. 
    • There are "threats" or alarming statements that create a sense of urgency. For example: "Your account will be locked until we hear from you" or "We have noticed activity on your account from a foreign IP address." 
    • The domain name in the message isn't the one you're used to seeing. It's usually close to the real domain name but not exact. For example: 
      • Phishing website: www.regionsbanking.com 
      • Real website: www.regions.com
    If you receive an email like this and you think it may be fraudulent, please report it immediately to the T&C Helpdesk at X8552, helpdesk@csuci.edu, or infosec@csuci.edu. Our technicians will assist you and instruct you on how to effectively remove it.

    Please remember... nobody from T&C will ever ask you for any personal information, including your password!

    President Obama Signs Cybersecurity Executive Order

    by in , ,

    The executive order that President Barack Obama signed on February 12th in advance of his State of the Union Address contains a lot of provisions for information sharing on attacks and threats on critical infrastructure, and also calls for the development of a framework to reduce cybersecurity risks in federal agencies and critical infrastructure. 

    Read the executive order on cybersecurity and see what is identified as mandated and what is being classified aside as volunteer initiatives.

    ThreatPost has additional information about this executive order.