GDPR – Eraser https://eraser.heidi.ie Secure Erase Files from Hard Drives Mon, 28 Sep 2020 10:09:19 +0000 en-US hourly 1 https://wordpress.org/?v=6.8.2 https://eraser.heidi.ie/wp-content/uploads/2019/07/cropped-eraser-avatar-32x32.png GDPR – Eraser https://eraser.heidi.ie 32 32 Excel Password Unlockers https://eraser.heidi.ie/excel-password-unlockers/ Thu, 02 Apr 2020 14:42:11 +0000 https://eraser.heidi.ie/?p=1242

Let’s take a look at some Excel Password Unlocker Software out there, most of them free! Note: some may impose file size restrictions, e.g. Password-Find does not support files larger than 10MB.

LostMyPass

SIMPLE TO USE: No need to install any software; you upload your file onto their website.
COST: Outlined below
FILE FORMATS: PDF, Ms. Word, Ms. Excel, Ms. PowerPoint, 7z, WinRAR, WinZip
RECOVER METHODS:
Weak Password Recovery: FREE
Weak password recovery is free and fast (a few minutes). It uses a dictionary of 3 million weak passwords. Chances of recovery are around 22%.
Strong Password Recovery: Pay on Success – current price $29
You only pay for a successful recovery. It can take up to 24 hours. It uses a dictionary of 20+ billion real passwords. The password is recovered successfully in more than half of cases; around 61%
Brute Force with a Mask: Price on request
Brute force attacks or brute force cracking are when all possible characters that exist are tried until it hits on a combination that works. 100% success rate if correct mask (set of characters) is given.
For example, if you can remember that your password consisted of 8 or 9 characters, perhaps starts with “444,” and the remaining characters are lowercase letters (English alphabet), then that makes the search process a lot easier.

Passcovery Suite

SIMPLE TO USE: Safe and regular Windows installation kits digitally signed by the company. All installation data remain on the computer and are not transmitted online.
COST: from 60USD per one Office-compatible module
FILE FORMATS: supports all versions of Microsoft Office/OpenOffice/LibreOffice, Adobe PDF, RAR/WinRAR, Zip/WinZip, TrueCrypt, Apple iOS backups, WPA/WPA
RECOVERY METHODS:
Instant removal of weak passwords of all Microsoft Office versions
Searching for Excel/Word 97 decryption key
Three standard password attacks: brute-force attack, mask attack, dictionary attack
Extended (positional) mask attack that enables generating passwords from charsets individually defined for each position in the password
Mutating and blending of dictionaries to increase efficiency of dictionary attack
GPU acceleration on AMD/NVIDIA graphics cards to enable dramatic increase of the speed of brute-force attack

AccessBack

SIMPLE TO USE: Online service that guarantees decryption of password-protected Excel/Word 97-2003 files. No third-party software
COST: from $5 per one Excel/Word document decrypted online
FILE FORMATS:  guaranteed decryption of doc/xls files with a short (40-bit) encryption key
RECOVER METHODS:
Rainbow tables for guaranteed decryption of Excel/Word 97 files

Password Online

SIMPLE TO USE: No need to install any software; you upload your file onto their website.
COST: 10 EUR – only payable if recovery is successful.
FILE FORMATS: doc, docx, xls, xlsx, ppt, mdb, pdf, rar, zip, 7zip, eoc etc.
RECOVERY METHODS:
Instant Password Recovery
For weak passwords.
Password Reset
Sometimes, it is possible to reset the password inside the actual file itself.
Dictionary Attack
This method uses a dictionary. Every word in the dictionary is tried. This method is usually faster than Brute Force Attack.
Brute Force Attack
This type of attack tries every possible character combination in a given set, in the hope of password recovery. This method is usually very successful, if the correct set of characters is given.
Variation in Password
This method uses the possibility of the password having been mistyped or a missing character.
Plain Text Password Attack
This method is used mostly with Zip files.

Password-Find

SIMPLE TO USE: No need to install any software; you simply upload your file onto their website.
COST: Payment is only upon successful recovery.
FILE FORMATS: It works with Ms. Excel, Ms. Word, Ms. PowerPoint files and VBA Projects.
SERVICE STATISTICS:
MS Office 97-2003 100%
MS Office 97-2003 CSP 81%
MS Office 2007-10 80%
MS Office 2013-19 78%
RECOVERY METHODS: They don’t seem to outline their recovery methods on their website.
]]>
How to stay Anonymous online https://eraser.heidi.ie/how-to-stay-anonymous-online/ Thu, 28 Feb 2019 18:04:16 +0000 https://eraser.heidi.ie/?p=1135 Using the internet was once considered to be a way to ensure free speech while remaining anonymous. Sadly, this is not the case today. In this day and time, being online generally means being susceptible to mass surveillance and being snooped on around every corner.

Popular sites like Facebook have paved the way for outsiders to delve into our personal lives. Privacy scandals are a daily occurrence, and user information-driven commerce is the new definition of social media sites.

Online anonymity is essential now, more than ever. We all have some form of personal information we would not want the world to know about. It can be a disregard for the law, an interest in unique videos or a simple desire to stay out of the probing eyes of snoopers. Having a public profile online usually means:

Your right to free speech is hindered
If you are not anonymous online, you cannot truly exercise your freedom of speech. Your opinions can always be traced back to you. Your opinions might induce judgement, backlash or worse yet, a direct attack in your personal life.

Your safety is questionable
Do you ever stop and ponder how your online activities can compromise your safety? Can you do whatever you want online without the fear of others finding out and possibly inflicting physical injury to you? If both your answers are a big NO, you probably need to stay anonymous online.

Your freedom of movement is limited
You cannot shop for an item, comment on a video, express support for a cause or become a member of an online community without being observed. Having a traceable, public profile usually means that your freedom of movement is limited.

Your data is compromised
Your personal data is one of your most valuable assets. This data can be your banking transactions, credit card information or your passwords. With a public, non-anonymous profile, you make it easier for malicious people to obtain your personal data easily.

To prevent your personal data from being tampered or from your safety to be compromised, follow one or more steps mentioned below to stay anonymous online. The steps you follow depends on how nitpicky you are about online privacy.

Live in a country that values privacy

It all starts with the country you live in. A country that values privacy protects its citizens from government spying and limits personal data from being commercialized.

We can expect many countries around the world to adopt policies like the European Union’s General Data Protection Regulation (GDPR) soon. However, there still are countries that do not value privacy as an individual’s asset.

It is not possible for everyone to simply switch countries, but you can do your part on bringing about change in your country. Contribute and raise your voice for laws that value privacy.

Use an anonymous operating system

When talking about maintaining anonymity, most people tend to overlook the operating system they use and focus on their web browsers instead. It is important to understand that a web browser is not the only spy in your computer. Your operating system and the software you install on your computer also stores information that can be used against you.

The hardware reports from your computer can leak information like your hard-drive serial number and the software on your computer can show if you have accessed a web resource from your computer.

The question that comes up now is, is it actually necessary to use a real computer? Why not use a virtual machine?

Virtual machines do not have real hardware. The operating system and the browser used on a virtual machine reports the fake hardware configurations. Upon deleting a virtual machine, all of its records are deleted, and nobody can figure out things about you.

The hardware you use should be a resettable virtual machine running on a secure, portable media. The media should use hardware-based encryption. One good example is IronKey Workspace which supports Windows to Go, Microsoft’s portable OS.

Live Oses need to boot from removable media, and Linux Live distro such as Tails or ZeusGuard are the best options out there. Other options worth trying are Whonix and Qubes OS, the free operating systems built with the objective to ensure security.

Secure your connection

Securing your connection from malicious attacks is the next best thing you can do to ensure anonymity. To do this:

Secure your router
A router is an interface between the internet and all your computing devices. It can hence be thought of as an interpreter. If the interpreter itself is malicious, then one can only imagine the things that can go wrong.
The good news is; you can just change some basic settings like changing your router password and using a strong Wi-Fi password to protect your data and your identity. The list of things you can do is really long. However, it is important to at least do something in order to secure your router.

Build a firewall
Hackers constantly bombard IP addresses to get into systems. If you connect to the internet directly through a modem, then you are susceptible to malicious attacks.
A firewall is a hardware or software which has a set of rules that determines if an external connection should be rejected or allowed. Installing a firewall essentially means that any hacker trying to access and control your router hits a solid wall.
You can use the built-in firewall of your router, or the firewall software installed on your PC, to stop direct network attacks dead on its tracks.

Hide your Internet Protocol (IP) Address

Your IP address is your identity, and it can easily be used to track you. The ISP you use keeps track of the IP address assigned to you and can drill-down your activities back to you. Every ISP maintains logs of its connected IP addresses for about 6 months to 2 years, making your data easily accessible by hackers or government agencies.

It is also important to note that every time you access a website; your IP address is transmitted. The websites you visit also keep logs of your IP address for years. You are legally liable for the websites visited and information shared through your connection. Needless to state, hiding your IP address and securing your connection is absolutely necessary if you want to stay anonymous. Here’s how you can do it:

Use a reliable VPN service
A VPN (Virtual Private Network) enables you to access the web safely by hiding your online actions and routing your connection through a server. It creates a secure tunnel between two or more devices and allows you to access the web anonymously.
There are hundreds of VPNs currently available in the market with different price ranges, encryption mechanisms, and jurisdictions. Make sure that you choose a non-logging, paid VPN that actually offers what it advertises.

Use Tor
The Tor is a system of APIs, network, tools and browsers that lets you access the web by hiding your IP Address. It routes traffic through a worldwide network of random nodes thus concealing the user’s location and usage. When you use a Tor browser, it is difficult to trace your internet activity. Tor can be used in combination with a VPN to make it extremely difficult for hackers to access your personal data.

Use an anonymizing device
Devices like Anonabox and ProxyGambit are explicitly designed to protect your privacy. Anonabox can use Tor or VPN services to protect your connection. ProxyGambit fractures your traffic from the internet by tunneling it through a long-distance radio link or through a reverse tunneled GSM bridge.

Browse securely

Using a secure connection, hiding your IP address or using an anonymous operating system does not make you anonymous if your browser still saves all of your personal data and cookies. You can follow a number of methods to browse securely and ensure that the websites you visit do not pose a threat to your personal security:

Go incognito
Going incognito is the simplest yet the most effective way you can make your internet usage a bit more anonymous.
Whenever you visit a website, you leave cookies behind. These cookies are stored in your computer and allow other websites to deliver a surfing experience tailored for you.
Have you ever searched for a new MacBook on Google, and a MacBook advertisement has miraculously appeared on Facebook? This is the simplest example of how cookies are used to create a unique fingerprint based on the collected data. To avoid your searches on the web from being collected, analyzed and used back on you, simply go incognito whenever possible. Almost all browsers today have private browsing features which can also be used in your smartphone.

Surf Safely
Even when you are not using the incognito mode to browse, you can still tweak your browser settings to stay anonymous. The key is to limit the information that your browser saves.
In the Settings menu of your browser, turn off password storage, image storage, surfing history, download history, and cookie storage. Turn on the Do Not Track option too. You can also install the Ghostery browser, which blocks all sorts of trackers.

Turn off your location
A website can obtain your location data from your PC, identify you and target ads at you. You can eliminate this by turning off your location in your Operating System. Clear the location history frequently in your browser too.

Block Javascript
JavaScript has been known to be a privacy invader, allowing web servers to collect information about the plugins that you use, the size of your monitor, etc. Your behavior can be tracked easily because of JavaScript used in your web servers. The simple solution to this is to disable JavaScript. However, this might be tricky as you can turn it off on some websites and you cannot turn it off on others. Use browser-specific extensions to help you decide which sites should use JavaScript and which sites should not.

Avoid using plugins
The most famous browser plugins today collect clues to reveal your location and identity. Avoid using plugins in order to maintain anonymity.
However, the exception to this case are plugins that are specifically designed to enhance privacy.

Secure your email

You have a secure VPN that connects to the internet and a browser that does not log your browsing history. What is the use of having an anonymous IP when your email address itself showcases your name to the world?

Sending emails presents you with a different anonymity challenge. To obscure your email, follow the steps mentioned below:

Use an alias
The first thing you can do to remain anonymous on the internet is to use an alias email. An alias is a forwarding address. When you send an email through an alias, the recipient can see the forwarding address but not your real email address. This will not save you from being spammed, however.

Use a disposable/ burner email account
You can use a disposable fake email account for the duration of your needs. After signing up to some services or commenting on a site, you can delete the fake email account completely.
You can also use a burner service to create an email account. Burner services create a temporary forwarding address that is deleted after a certain amount of time. Nobody will be able to figure out the origin of the message. This also prevents your inbox from being flooded with spam messages.

Encrypt your emails
You can also encrypt your emails to prevent a middleman from getting access to your vital information. Encrypt all your outgoing emails and send them using HTTPS from your web-based email client. The web-based email client adds an extra layer of SSL/TLS encryption to your emails.
You can also use encrypted chat services like TOR chat or Cryptochat to communicate your vital information.

Anonymize your smartphone

No matter how secure your computer/laptop and your connection might be, you still need to follow a number of steps to anonymize your smartphone and prevent it from storing data that can be used to track you.

Audit your apps and their permissions
Everyone has smartphones that are filled to the brim with unnecessary apps. We tend to download a huge number of apps and forget about it. If you don’t watch what you do with your applications, there might be serious consequences when it comes to your personal privacy.
Delete applications that you do not use. Be critical of what is installed on your smartphone. Keep track of the permissions that you give your apps. Keep in mind that a calculator app that asks permission to access your phone storage and contacts is certainly a suspicious app. Also, keep track of application updates and the new permissions that come along with it.

Remote wipe your device
We store a huge amount of intimate and valuable information on our smartphones. Smartphones are expensive, but the data they store is even more valuable.
We take our smartphones where ever we go, and the possibility of them being stolen is huge. It is scarier than having our wallet or passport stolen.
It is a good idea to set a remote wiping mechanism for your device. Some phones allow you to set a maximum number of tries at a passcode, before nuking your phone’s data. Your phone’s anti-theft systems can also be used to remote wipe your data in case of theft.

Read privacy policies before committing to it.

Many of us tend to commit to privacy policies without even glancing at it. The I Agree button is easy to find and click, but the consequences of not reading the privacy policies can be extreme.

If you are actually interested in maintaining anonymity, you should thoroughly read and understand the privacy policies put forward to you before clicking on the I Agree button.

Some privacy policies allow you to be selective about the policies implemented. In such cases, try to get away with the least number of policies. If some policies seem uncomfortable to you, it is best to walk away from the service altogether. Do not compromise your personal privacy over the greed of using a service.

Install anti-malware software

No matter how immune you appear to be from computer attacks, malware infections can happen even to the best of us. Simply visiting an unsavory site or connecting to a public network is enough to get you infected with malware that spies on your activities. A malware can:
• record your keystrokes,
• watch your screen,
• track the sites you visit and the content you oversee, and
• send this information to the malware owner with ease.

It is hence important to install anti-malware software or anti-virus apps to prevent your anonymity from being compromised.

Avoid cloud storage and social media

Remember a simple rule. If you are not paying for something, then you are the product. Social media like Facebook, Twitter, and Instagram, are not the exceptions to this rule. We do use these services for free but compromise our anonymity in return. Social media sites analyze our intimate data to target advertisements back at us.

Internet usage has become synonymous with social media usage. If you cannot eliminate social media from your life completely, at least make sure to optimize your security settings and be wary of the friends you have on your social media sites.

Think twice also about storing your intimate and personal details on cloud storage platforms like Google Photos, Google Drive, Dropbox, OneDrive or SharePoint. These companies have decent privacy policies, but it is also worth noting that they have full access to everything you put up on their platforms. If you cannot stop using cloud storage platforms altogether, you can at least make sure that you don’t upload something too important.

Use cryptocurrency instead of credit cards

When you buy something on the internet using a credit card, you lose your anonymity. Online money transfer services like PayPal also keep records that can be subpoenaed or stolen.

The better alternative to credit cards or money transfer services is cryptocurrency. Once you use your bank service to convert your money to cryptocurrency, the rest is easy. Many retail services and companies nowadays accept cryptocurrency as a method of payment. Payment using cryptocurrencies is anonymous as they are self-regulating and have no central bank behind it.

Can you be truly anonymous?

No. All of the anonymizing methods mentioned above can be defeated. But the more combinations you use, the harder will it be to track your personal details (unless you break the law and the government is involved).

Hackers rely on the mere fact that a huge population of the world does not give a second thought about anonymity, and uses the internet with default settings everywhere. Simply accepting the defaults makes it easier for malicious people to use your data for their benefit.

You can save yourself from trouble, and make it difficult for a hacker to break your anonymity by tweaking the default configurations on your OS, connection, smartphone or browser. Most hackers will not and cannot go to the trouble of opening one wall after the another to actually reveal your identity. Follow a combination of the steps mentioned above, to save yourself from being an easy target for hackers.

]]>
Router Security https://eraser.heidi.ie/router-security/ Fri, 11 Jan 2019 11:04:28 +0000 https://eraser.heidi.ie/?p=1128 There is no anti-virus software for routers. No matter how secure your mobile devices, desktop computers or other electronic devices might be, having an unsecured router still makes you susceptible to malicious attacks.

A router is an interface between the internet and all your computing devices. It can hence be thought of as an interpreter. If the interpreter itself is malicious, then one can only imagine the things that can go wrong.

Router Security is a less-talked-about topic but is as important as installing anti-virus software on your computer. A hacked router can let a malicious person:

• Hijack your DNS,
• Cause a denial of service attack,
• Download malicious copies of software,
• Spy on your activities,
• Slow down your internet connection,
• Hack files that are being transferred, and
• Ultimately access the computers connected via the LAN of the router.

There are many side effects of neglecting router security. It is hence crucial for every internet user to do the right thing by making router security an important concern and by applying whatever methods possible, to ensure privacy and online security.

Since it is now established that router security is essential for every internet user, let us go into the details of how you can ensure it.

Step 1: Picking the right Router

You cannot secure a router if it is not appropriately chosen. Picking the right kind of router is the first step you can take towards router security.

Most people tend to use the router provided by their Internet Service Provider (ISP). The only advantage of doing this is the fact that you can call your ISP for any issue that arises in your internet connection. The downsides to using it, however, are many:

• Devices shipped by ISPs are incompetent in their initial configuration and maintenance. A device installed with a default password is certainly not the right option for you
• Some ISPs can spy on your data for their own use or by co-operating with spy agencies and governments.
• Some ISPs do not allow you to update the firmware or change DNS servers of the router
• ISPs generally provide a single router; hence you will have no emergency backup in case of failures
• A common type of router, provided by an ISP to millions of customers is an easy target for malicious users

A consumer router is a better alternative to ISP provided routers but is still not the best option. The most secure option to choose is hence a commercial router meant for small businesses.

When choosing a router, think of the long-term benefits that you obtain by using it. While the upfront cost of the router might seem like a huge investment, it is still a better option than compromising your security.

A router can only get as secure as the features it offers. It is not recommended to buy used routers as the software might have been modified maliciously. When choosing the correct router, consider the inclusion of these security features:

WPS

WPS (Wi-Fi Protected Setup) is not as good as it sounds. It is easy to use and easy to bypass feature that allows malicious users to enter an eight-digit PIN to access the router. The PIN is printed on the router itself. Once someone gets access to your PIN, you can change the network password or network name, but the validity of the PIN still remains intact.

Therefore, anyone who gets access to the PIN printed at the base of your router can access your router forever.

If a router uses WPS, it is not good enough. Check if WPS can be turned off. Proceed only if WPS is absent or can be disabled in your router.

WPA2

WPA2 encryption is good. However, one must consider some other points when looking for a secure router. Keep the following points in mind:

• Verify if your router offers WPA2 exclusively and not the combination of WPA2 and WPA
• A router that uses AES or CCMP is also as secure as the one that uses WPA2 encryption
• Ensure that your router does not use TKIP
• Look out for routers that offer WPA2 Enterprise support. This usually means that the router allows every Wi-Fi user to set their own user id and password. A RADIUS server is required to handle these user ids/passwords. This option might be a high bar for most people, but it is the best encryption mechanism possible

Local administrative access

Another aspect of determining the security of a router is its local administrative access mechanisms. A secure router must:

• Limit access based on LAN IP address or by Mac Addresses
• Limit the number of logons and allow only a single computer to log into it at once
• Lockout after repeated failed login attempts
• Create audit logs for every login attempt
• Timeout and allow you to set a timeout period
• Restrict access based on the SSID
• Allow you to log out

Remote administrative access

Remote administrative access in your router should be off by default. A secure router must:

• Limit remote administrative access to HTTPS
• Allow you to change the port number
• Allow you to restrict access on the basis of the source IP address or source network
• Timeout the running session after a certain timeout time

Default passwords

Be wary of routers that employ default passwords. Default passwords can look random, but follow a specific formula to be created. Once someone understands this formula, the rest is easy.

Check if the router forces you to provide a new non-default password for logging into the router. Additionally, check if the router forces you to provide non-default passwords for each new Wi-Fi network. Choose the router only if the two conditions are met.

Wi-Fi

A secure router must allow the options to:

• Schedule turning off the Wi-Fi at night and turning it back on in the morning
• Use the Wi-Fi ON/OFF button

The bottom line is that the router should make it easier to disable a Wi-Fi connection when it is not required.

Monitoring Attached Devices

Another feature of a good router is the ability to monitor the devices connected to it. A good router:

• Lists all the attached devices
• Allows you to list both DHCP assigned devices and devices with static IPs
• Allows you to list devices by grouping it on the basis of the Wi-Fi network
• Allows you to monitor the bandwidth usage of each device

Firewall

A good router’s firewall should:

• Close all ports on the WAN/Internet side
• Allow you to create outgoing firewall rules

Listed below are other good to have features which can help you make the right choice.

Factory Reset
Look out for a router that allows you to factory reset it and erase all personal data from it.
Logging
A good router logs unsolicited incoming connections, failed login attempts, internet accesses and changes made to the configuration.
Firmware
Another parameter that can help you determine the right router for you is its ability to make firmware updates.
HNAP (Home Network Administration Protocol)
The HNAP has been the baseline for many router flaws. A secure router does not support HNAP.
Port Forwarding
Make sure that your router limits port forwarding by IP address. It is better if your router allows you to schedule port forwarding.
Router Admin Password
The router admin password should not be too short and must allow the maximum password length to be at least 17 characters. A router should also defend itself against brute force password guessing.

Step 2: Configuring the router securely

Once you select the right router of your choice, it is time to configure the router as securely as possible. The below mentioned short list of configuration tricks can do wonders for the security of your router:

  1. Change the default password of your router. Make sure that you do not use a dictionary word. Incorporate some numbers and special characters in your password. Also make sure that the password is not something as menial as the name of something you love, or the name of your hometown.
  2. Ensure that the encryption mechanism used is WPA2 with AES. The password of your Wi-Fi network should be at least 16 characters long. Again, make sure to set a password that is not easy to guess.
  3. Turn off UPnP (Universal Plug and Play). While UPnP was initially designed to be used on a LAN, some routers implement it on the Internet too. There have been security issues with routers in the past because of UPnP, hence turning it off is the best way to ensure that your router is secure.
  4. Choose a sensible SSID (Service Set Identifier). Using a default SSID makes it easier for malicious users to crack the WPA2 encryption. Choose a network name that does not give away your personal information.
  5. Turn off WPS. It is actually better to choose a router that does not support WPS at all. If it does have WPS encryption, make sure to run it off.
  6. Turn off Remote administration.
  7. Check for new firmware occasionally. If your router does not release new versions of firmware, it might be the right time to switch to a new router.
  8. Use a Guest Network. Use a password protected Guest Network for guests and also for IoT devices.
  9. Test your router. Use available online testers to test the port information of your router.

The steps mentioned above are just the basic things you can do to ensure that nobody accesses your router or installs malicious software in it. If you are actually a freak for security, there are a number of other methods that you can employ to make your home router a fortress that can guard the electronic devices that connect to the web through it. Choose and implement anything from the list below:

  1. Change the user id of the router. That is if your router lets you.
  2. Change the default DNS servers that your router provides you. ISP-assigned DNS servers are usually the worst when it comes to security. It is better to use the DNS of a company that specializes in it.
  3. Turn off unused features. This is a good way to reduce the attack surface. The features that are better turned off are remote administration, web access from WAN, Telnet, SNMP, NAT-PMP and Remote GUI.
  4. Change the router’s LAN IP address. It is better to change the subset of the LAN side as a whole. Doing this prevents router attacks.
  5. Lock down the access to the router from the LAN side.
  6. Turn off Ping reply. Test this implementation by having someone outside your network ping your public IP address.
  7. Block the ports used by Windows file sharing. It is also a good idea to prevent network printers from making outbound connections.
  8. Disable the analytics on your router. You would not want your router company spying on you, so it is better to turn off the analytics feature in your router’s firmware releases.
  9. Use a clean web browser session to administer routers with a web interface. Start the browser, work on the web interface of the router, and shut down the browser after you are done with the administrative activities. The better option would be to use a private browsing mode.
  10. Always backup your configurations. If you have to reset the router at some time, you can restore the last backed up state of the router.

Step 3: Ongoing care for the router

After initially configuring the router, it is also essential to monitor for your router configurations regularly. There are a number of methods that can be adopted to ensure that your router’s security has not been compromised.

  1. Updating the router
    Check if your router self-updates regularly or not. Check for the availability of new firmware updates every month. If your router has the self-updating feature, make sure that the system is actually working as expected and if the new updates are actually worth using. There can be major security loopholes in some security updates. It might be a good option to revert the updates in such cases.
  2. Rebooting the router
    When a router gets infected with malware, the infection is sometimes very difficult to get rid of. However, most infections are temporary and simply rebooting the router can help you get rid of the infection. Make sure that you reboot your router every week or every month, in order to remove such kind of malware on a regular basis.
  3. Checking the list of attached devices
    Every router has the functionality of displaying the attached devices. Make sure that you check this list now and then and validate the list against the number of devices that your network actually uses. Some routers also offer the capability of assigning names to these devices.
  4. Checking the status of DNS servers
    A common attack against routers is maliciously changing the DNS servers. It is hence important to continuously check and ensure that your DNS servers have not changed. You can configure a DNS server on your own computer. Doing this ignores the DNS configuration present in the router. This is especially useful when you use public Wi-Fi networks. However, some routers override the DNS configuration of the computer and force the computer/laptop to use its own configuration. Hence, it is important to know the kind of router you possess and periodically check the DNS server configuration of your devices.
  5. Checking the logs of the router
    If your router offers logging facilities, it is recommended that you continuously check the logs for unsolicited incoming connections, failed login attempts, internet accesses and changes made to the configuration.

All in all, router security is not limited to buying a good router and configuring it one-time. New router threats are emerging every day and are posing serious threats to personal privacy and security. It is essential to keep yourself updated with router flaws, and periodically check your router security parameters to avoid compromising your personal information.

]]>
The General Data Protection Regulation & The Duty to Encrypt https://eraser.heidi.ie/the-general-data-protection-regulation-the-duty-to-encrypt/ Mon, 06 Nov 2017 15:32:23 +0000 https://eraser.heidi.ie/?p=942 The General Data Protection Regulation, abbreviated to GDPR, raised a storm when it arrived. In reality, it merely tightened up on existing good practice according to digital security specialists Gemalto. The right to withhold consent and to be forgotten has always been there, for example. However, the GDPR brings a free enforcement service for consumers, thus avoiding the need for third party, paid assistance.

The GDPR Bottom Lines for Data Security
Moreover, the GDPR has penalties it can apply, of the order that might have a judge choking on his wig. Under it, data security measures such as pseudonymisation (substitution of identifying fields) and encryption (encoding including password protection) have become mandatory. Businesses must further respect their client data by:

a) Storing it in a secure environment supported by robust services and systems
b) Having proven measures to restore availability and access after a breach
c) Being able to prove frequent effectiveness testing of these measures.

The General Data Protection Regulation places an onus on businesses to report any data breaches. This places us in a difficult situation. We must either face at least a wrist slap upon reporting failures. Alternatively, pay a fine of up to €10 million, or 2% of total worldwide annual turnover.

The Engineered Weak Link in the System
Our greatest threat of breach is probably when the data leaves our secure environment, and travels across cyberspace to an employee, stakeholder, collaborator, or the client themselves. Since email became open to attack, businesses and individuals have turned to sharing platforms like Dropbox, Google Drive, Skydrive, and so on. While these do allow an additional layer of password protection, none of these has proved foolproof. The GDPR may still fine us heavily, whether or not we are to blame for the actual breach.

How Hacking is Approaching Being a Science
We may make a mistake we may regret, if we do not take hacking seriously. The 10 worst data hacks Identity Force lists are proof positive that spending lots of money does not guarantee security (any more than having the biggest stock of nuclear weapons). We have to be smart, and start thinking the way that hackers do.

Hacker heaven is finding an Experian or a Dun & Bradstreet that may have shielded 143 million, and 33 million consumer records respectively, behind a single, flimsy cyber-security door. Ignorance is no excuse for them. They should simply have known better. They should have rendered consumer data unreadable at individual record level. The hackers could have found this too demanding to unpick, and have looked elsewhere.

How Data Encryption Can Help Prevent Hackers Succeeding
Encrypting data is dashboard driven, and businesses need not concern themselves about it works. There are, however, a few basic decisions they must take:

a) Purge the database of all information held without explicit permission
b) Challenge the need for the remaining data and purge the nice-to-haves
c) Adopt a policy of encrypting access at business and customer interfaces
d) Register with three freemium encryption services that seem acceptable
e) After experimenting, sign up for a premium service and be prepared to pay

Factors to Consider When Reaching a Decision
Life Hacker suggests the following criteria although the list is a one-size-fits-all

a) Is the system fast, simple, and easy to operate
b) Can you encrypt hidden volumes within volumes
c) Can you mass-encrypt a batch of files easily
d) Do all other files remain encrypted when you open one
e) Do files automatically re-encrypt when you close them
f) How confident are you with the vendor, on a scale of 1 to 10

It may be wise to encrypt all the files on your system, and not just your customer data. We are always open to a hack by the competition after our strategic planning. If we leave the decision up to IT, then IT, being human may take the easy way out, and encrypt as little as possible.

]]>
Know Your Consumer Rights under the European Union GDPR https://eraser.heidi.ie/know-your-consumer-rights-under-the-european-union-gdpr/ Tue, 08 Aug 2017 14:58:04 +0000 https://eraser.heidi.ie/?p=890 European Union Regulations apply to all member states. We have to implement them in Ireland, and the regulations override any existing laws on the topic we may already have. The EU General Data Protection Act (GDPR) is no exception. Thus, it will be great news for consumers when it comes into force on 25 May 2018.

What the General Data Protection Act Aims to Protect

The GDPR affirms a very important principle for consumers. It says we are the owners of our personal information, and it is private to us until we choose to selectively share. Any government agency (outside of law enforcement) and all businesses must first ask our permission before they add it to their database. Moreover, we have the right to inspect it, correct it, and even remove it completely.
The responsibility to implement the GDPR in Ireland falls in the remit of the Data Protection Commissioner. They are making the process as transparent as possible, and have very sharp teeth to make sure businesses listen. We believe these consumer rights back-fit to any time in the past. Thus, you should also be able to interrogate your personal information captured before the GDPR inception date of 25 May 2018.

Why the European Union Decided We Need a GDPR

The European Union was increasingly concerned about breaches of consumer rights concerning handling of their personal information. Google, and the social media especially Facebook having been tracking our movements so they can influence our thinking. Every time you find a commercial message popping up during a Google search, or on your Facebook timeline about a product you are interested in, this is proof that this is happening.

Clear evidence is emerging that people from certain countries influenced the outcome of the U.S. President Election, and probably the UK Brexit, by targeting like-minded people with fake news that influenced their thinking. We believe the GDPR is an appropriate mechanism for controlling this centrally, and thus a step in the right direction.
Business has been up to something equally upsetting probably for longer. While it is quite okay for our supplier to use our purchasing history to suggest a related product, it is totally out of turn if it shares this with a third party. This is behind some of the unsolicited phone calls and emails that still occasionally pester us. Since the EU General Data Protection Act crosses Union boundaries, we will soon the able to help prevent cross-border violations too.

Our Rights as Consumers under the GDPR in More Detail

We will have a right to insist that banks, insurance companies, government bodies, medical professionals, telephone companies, and other service providers keep our personal details private, and in secure storage. They will also have a duty to tell us before they capture the information, and explain what they plan to do with it.

This is not something brand new. It has been good governance practice in larger organisations for some time. However, the weak link is often in the follow-through, for example, how they prevent a third party from hacking, and stealing what is rightfully ours. Some smaller companies have not seen customer data protection as a priority until now.

The GDPR regulates personal information on a computer, in a manual paper filing system, or in the form of video / voice recordings or photographs. From 25 May 2018, we will have a perfect right to check this personal information is correct, to know who has access to it, and to insist it is only used for purposes we agreed when providing it.

The Data Protection Commissioner will rule the event of a dispute once they decide who is right. They may also penalise the organisation holding the information if they were wilfully negligent. Here are their contact details you may like to keep on file:

Physical Address: Canal House, Station Road, Portarlington, Co. Laois
LoCall: 1890 252 231 / Tel: 057 868 4800 / Fax: 057 868 4757
Email: info@dataprotection.ie / Website: www.dataprotection.ie

]]>