Friday, April 13, 2018

Campus Security Campaign - April 2018

As you upgrade your personal devices to the newest options, do you recycle the old equipment? Being green shouldn't make you blue. Take steps now to remove anxiety later that forgotten sensitive files on your last laptop could become a source of embarrassment or identity theft. Trying to securely delete data at the time you decommission equipment can turn into a multihour chore and a source of stress, but it doesn't need to be that way.
Make sure saved copies of your tax filings, personal photos, and other sensitive files can't be retrieved by the next person with access to your computer's drive by making the drive unreadable to anyone else. Dragging files to the trash or recycle bin doesn't remove data—it just removes the retrieval path to the file and marks that storage space available for other data to occupy sometime in the future. Your pirate treasure is still buried, but the map is missing. "Secure file deletion" functions go a step further to overwrite the data in those locations with random bits immediately.
The introduction and growth of solid state drives in consumer electronics, however, makes overwriting the data in these spaces less dependable than in the standard hard drives of the past. Today's "delete/overwrite" protection comes most reliably from full disk encryption (aka whole disk encryption), which encrypts all data on the machine—including the operating system and temporary files you weren't even aware you created. Follow the motto of a famous infomercial to "set it [full disk encryption] and forget it [the password/key]!" Even if someone removes the drive and puts it into a different machine, the encryption remains in place.
  • Plan A: Encrypt the full disk now using built-in functionality. Create a strong passphrase or password, since this becomes the decryption key! Everything will be encrypted, including the operating system, so you will have to "unlock" the encrypted drive with your personal passphrase every time you start or boot up your computer. Save the generated recovery key somewhere secure (like a password manager or printout stored in a secure office), in case you forget your password and need to access the data on that machine. Here are instructions for some of the most common built-in encryption functions:
  • Plan B: If full disk encryption wasn't a built-in option, find a free or fee version of full disk encryption software that works with your operating system and personal capability. Check your favorite review sites or try Slant for recommendations.
  • Failsafe: Hammer time! Remove and destroy the drive (Geek Squad offers a three-minute tutorial on hard drive disposal). Most retail stores that accept computer donations for safe recycling will remove the drive and give it to you for secure destruction—just ask them to do that. Smash it, drill it, or hold onto the drive until there's a secure shredding event at work or in your community.

Friday, March 30, 2018

Campus Security Campaign - March 2018

Due to enhanced security measures in most countries, travelers with tech should be prepared for possible disruptions or additional wait times during the screening process. Here are some steps you can take to help secure your devices and your privacy.
Good to know:
  • While traveling within the United States, TSA agents at the gate are not allowed to confiscate your digital devices or demand your passwords.
  • Different rules apply to U.S. border patrol agents and agents in other countries. Federal border patrol agents have broad authority to search everyone entering the U.S. This includes looking through any electronic devices you have with you while you are traveling. They can seize your devices and make a copy for experts to examine offsite. Learn more from the Electronic Frontier Foundation about digital privacy at the U.S. border.
Protect your tech and data when traveling:
  • Travel only with the data that you need; look at reducing the amount of digital information that you take with you. This may mean leaving some of your devices at home, using temporary devices, removing personal data from your devices, or shifting your data to a secure cloud service. Authorities or criminals can't search what you don't have.
  • Most travelers will likely decide that inconvenience overrides risk and travel with electronic devices anyway. If this is the case, travelers should focus on protecting the information that they take with them. One of the best ways to do this is to use encryption. Make sure to fully encrypt your device and make a full backup of the data that you leave at home.
  • Before you arrive at the border, travelers should power off their devices. This is when the encryption services are at their strongest and will help resist a variety of high-tech attacks that may attempt to break your encryption. Travelers should not rely solely on biometric locks, which can be less secure than passwords.
  • Make sure to log out of browsers and apps that give you access to online content, and remove any saved login credentials (turn off cookies and autofill). This will prevent anyone from using your devices (without your knowledge) to access your private online information. You could also temporarily uninstall mobile apps and clear browser history so that it is not immediately apparent which online services you use.
Get your device travel ready:
  • Change your passwords or passphrases before you go. Consider using a password manager if you don't use one already.
  • Set up multifactor authentication for your accounts whenever possible for an additional layer of security.
  • Delete apps you no longer use.
  • Update any software, including antivirus protection, to make sure you are running the most secure version available.
  • Turn off Wi-Fi and Bluetooth to avoid automatic connections.
  • Turn on "Find My [Device Name]" tracking and/or remote wiping options in case it is lost or stolen.
  • Charge your devices before you go.
  • Stay informed of TSA regulations and be sure to check with the State Department's website for any travel alerts or warnings concerning the specific countries you plan to visit, including any tech restrictions.
  • Clear your devices of any content that may be considered illegal or questionable in other countries, and verify whether the location you are traveling to has restrictions on encrypted digital content.
  • Don't overlook low-tech solutions:
    • Tape over the camera of your laptop or mobile device for privacy.
    • Use a privacy screen on your laptop to avoid people "shoulder surfing" for personal information.
    • Physically lock your devices and keep them on you whenever possible, or use a hotel safe.
    • Label all devices in case they get left behind!
These guidelines are not foolproof, but security experts say every additional measure taken can help reduce the chances of cybertheft.

Tuesday, February 6, 2018

Campus Security Campaign - February 2018

"The Internet is a powerful and useful tool, but in the same way that you shouldn't drive without buckling your seat belt or ride a bike without a helmet, you shouldn't venture online without taking some basic precautions." This is an important reminder from the National Cyber Security Alliance that cybersecurity is everyone's responsibility as an individual and a member of our ever-growing online community. Here are some tips to keep in mind as we work together to create a better, safer digital world for ourselves and others.
  • Own your online presence. To keep yourself safe, set privacy and security settings on web services, apps, and devices to your comfort level. You do not have to share everything with everyone. It is your choice to limit what (and with whom) you share personal information.
  • Be a good digital citizen. The things that you would not do in your physical life, do not do in your digital life. If you see crime online, report it the same way that you would in real life. Keep yourself safe and assist in keeping others safe on the Internet.
  • Respect yourself and others. Practice good netiquette, know the law, and do not do things that would cause others harm. The Golden Rule applies online, as well.
  • Practice good communications. Never send an e-mail typed in anger. Put it in your draft folder and wait. Keep in mind that digital communications do not give the reader the same visual or audio cues that speaking in person (or by video or phone) does.
  • Protect yourself and your information. Use complex passwords or passphrases, and don't reuse the same password or variations of a simple phrase. Better yet, enable two-factor authentication or two-step verification whenever possible.

Wednesday, January 3, 2018

Campus Security Campaign - January 2018

Everyone in our community is responsible for the protection of our customers' privacy and their personal information. However, you don't need to understand the nuances of every privacy regulation currently affecting higher education to tackle data privacy issues on campus. Whether you are working on a data breach response plan, updating institutional policies, collaborating with researchers on a new project, or educating students, faculty, and staff about data privacy, consider teaming up with your institution's privacy officer(s). The privacy officer(s) will be more than happy to lend expertise and help make sure privacy, risk, and information security considerations are carefully weighed.
Know and understand your privacy policies.
  • Most institutions have a standard privacy policy, statement, or notice on their website to help visitors understand the practices related to the collection, use, or disclosure of information. Two examples are Indiana University and University of California, Berkeley. 
  • Additional privacy statements or notices may be included in third-party contracts or services offered to students, faculty, and staff (e.g., learning management systems used for classes).
  • Also consider any third-party privacy policies or terms and conditions you may have agreed to as an individual (e.g., Facebook or any other third-party services or apps that aren't officially hosted by the institution through a signed contract).
Always start with privacy.
  • Include privacy in the planning phase of all new projects.
  • If you don't need personal information, don't collect it. You can always ask for more information later.
  • Inform your customers about why you're collecting their personal information.
Keep and use data securely.
  • Keep personal information confidential and limit access to the data.
  • Make sure you're only using the data the way you said you'd use it. Ensure you get the customer's consent before you use it otherwise.
  • Destroy or deidentify private information when you no longer need it.
  • Know your data breach response plan.

Monday, December 11, 2017

Reminder for Lab Computers - 12/11/17

As a reminder, when finished working on a lab or library computer, please make sure to log out of all programs such as mail, and MyCCC. The best way to ensure a previous user is completely logged out is to restart the computer before you use it.

Thank you, 
CCC IT

Tuesday, November 7, 2017

Scam of the week - 11/6/2017


Netflix Scam!
There is a massive scam campaign going on, this time a very well executed Netflix phishing attack. 
The scam targets subscribers telling them that their account is about to be canceled. The well-designed, personalized fake email convinces customers to update their account information to avoid suspension. This results in stolen personal and credit card information.
The email has the subject line “Your suspension notification” and includes a link where the subscriber is taken to a fake Netflix page which requires their log-in information as well as credit card number.
The scam was detected Sunday and it targets nearly 110 million Netflix subscribers. As mentioned, the fake site includes Netflix’s logo as well as popular Netflix shows like “The Crown” and “House of Cards” to make it seem legitimate. 
I suggest you send employees, friends and family an email about this Scam Of The Week, feel free to copy/paste/edit:
"Heads-up! Bad guys are emailing you that your Netflix account has been suspended, and it looks just like the real thing. They are trying to get your login information and your credit card data.
Don't fall for this type of scam. If you want to change the settings of subscription services like this, never click on links in any email and just type the name of the site in your browser or use a bookmark that you set. 
Whatever email about Netflix you see in the coming weeks... THINK BEFORE YOU CLICK.

For KnowBe4 customers, we have a new phishing template in Current Events titled: "Netflix: Your suspension notification (Link)". Send this to your employees to inoculate them against phishing scams like this.  

Sunday, October 29, 2017

Payroll Scam - 10/27/2017

SUNY has made the college aware of a payroll scam that is being sent out. The scam is being sent from a ".edu" address and the subject line states "URGENT: Message from Payroll Department". The message tells the user that their October pay stub is ready for online review and provides a link to review the pay stub to correct a webtime entry error. Please be aware of this scam that is going around. Our payroll department does send out pay reminders but does not provide a link and if there is a pay error a member of our payroll office will directly contact you. If the link was clicked please contact the IT Department for further action.  

Thank you,
CCC IT