January 2021 Newsletter
Does the 'Presidential Peloton' pose a threat to national security?
How devices on the Internet of Things (IoT) complicate security from the White House to your house.
Your data may not be quite as prized as, say, the President of the United States, but hackers love low-hanging fruit. In other words, although you might not have national secrets hiding in your Peloton, it doesn’t mean hackers won’t try to obtain personal information, which for you can be just as detrimental.
What is the IoT?
The Internet of things is described as “a network of physical objects—“things”—that are embedded with sensors, software, and other technologies to connect and exchange data with other devices and systems over the Internet.”
Anything connected to the internet, despite security protocols, can be hacked if the cybercriminal possesses the skills to do so. As smart devices grow in popularity, from light bulbs and refrigerators to now exercise equipment, the IoT makes possible a more personalized and realistic user experience.
What’s the problem with the Presidential Peloton?
Currently, it’s impossible to Google ‘Peloton’ without running into headline after headline regarding President Joe Biden’s bike blunder. The passionate outcries of fellow “Peloton-ers” claiming that no true lover of the exercise bike could live without it, and many major news articles dissecting the many ways that the Peloton can reside in the White House.
The Peloton exercise bike offers classes hosted by real fitness trainers and allows riders to compete with other users from their homes. It’s equipped with a microphone and camera, and just like with any connected device, with this luxury of a real-time experience comes vulnerability. Even Peloton recognizes that the bike is vulnerable to threats, stating on their Security & Compliance page, “no matter how much effort we put into system security, there can still be vulnerabilities present.”
Not only is the bike connected to Wi-Fi, but it’s also connected to other smart devices (fitness trackers and apps); if a hacker accesses one, there’s very little stopping them from accessing another and another. Cybercriminals could take control of microphones and cameras to listen in and even watch the inner workings of the White House day-to-day gym sessions or install malware that could spread throughout the White House network.
Many exceptions have been made for past Presidents when it comes to their prized possessions. Trump’s golf simulator, Obama’s personal Blackberry, and the list goes on. Security experts have said that for the bike to be completely secure, the Secret Service will be required to strip the bike of its most glorious features (the microphone and camera in the tablet) to make the moving truck.
Whether or not the bike has a new home in the White House gym is yet to be determined, so will you be “ridin’ with Biden” in your next Peloton class? We may never know.
How do I protect my Peloton and other IoT devices?
No matter the device, anything connected to Wi-Fi is at risk of being compromised by cybercriminals. Once they’re in the door (regardless of the “thing” on the IoT), it’s an easy jump to the next “thing” and eventually to your personal data like passwords and banking information. So how do you protect your devices?
In the case of securing your personal data, the devil is in the default settings. The first step to securing your home network is to change the default settings of your connected devices. Here are some things you can do to make sure your network is as safe as possible:
- Often the easiest thing to hack is your home router, as it comes equipped with virtually no built-in security measures. Rename your router and other IoT devices to something that doesn’t reflect personal details about yourself, like your name or home address.
- Change the default passwords. For example, most default router passwords may differ from the next by one number or letter. Many cybercriminals already know these default passwords, making it easy for them to gain access. Create strong, complicated passwords using special characters, numbers, and letters, again with no personal identifiers.
- Check default security and privacy settings, turning off unnecessary features like remote access, voice control, or Bluetooth connectivity.
- Don’t put off software updates as they may contain a necessary patch to protect against a security flaw.
- Use two-factor authentication (2FA) wherever possible as an added layer of protection. Enabling 2FA requires additional proof of identity upon logging in. This can be in the form of a one-time pin (OTP) or via a verification code sent to your phone or email address.
- Create a separate Wi-Fi network for your IoT devices, specifically separating them from your computers and smartphones where your most sensitive data is stored.
In the connected world we live in, the threat of vulnerability is always present. The ever-growing IoT has many advantages, as long as you take all necessary precautions to safeguard your data and remain aware of the risks. Never leave the security of your devices in the hands of the manufacturer.
Common social engineering scams and how to avoid them
A common misconception most people have about cyber attackers is that they use only highly advanced tools and techniques to hack into people’s computers or accounts. This is simply not true. Cyber attackers have learned that often the easiest way to steal your information, hack your accounts, or infect your systems is by simply tricking you into making a mistake. In this newsletter, you will learn how these attacks, called social engineering, work and what you can do to protect yourself.
What Is Social Engineering?
Social engineering is a psychological attack where an attacker tricks you into doing something you should not do. The concept of social engineering is not new; it has existed for thousands of years. Think of scammers or con artists, it is the very same idea. What makes today’s technology so much more effective for cyber attackers is you cannot physically see them; they can easily pretend to be anything or anyone they want and target millions of people around the world, including you. In addition, social engineering attacks can bypass many security technologies. The simplest way to understand how these attacks work and protect yourself from them is to take a look at two real-world examples.
You receive a phone call from someone claiming to be from a computer support company, your ISP, or Microsoft Tech Support. The caller explains that your computer is actively scanning the Internet. They believe it is infected and have been tasked with helping you secure your computer. They then use a variety of technical terms and take you through confusing steps to convince you that your computer is infected.
For example, they may ask you to check if you have certain files on your computer and walk you through how to find them. When you locate these files, the caller assures you that these files prove that your computer is infected, when in reality they are common system files found on almost every computer in the world. Once they have tricked you into believing your computer is infected, they pressure you into buying their security software or giving them remote access to your computer so they can fix it.
However, the software they are selling is actually a malicious program. If you purchase and install it, not only have they fooled you into infecting your computer, but you just paid them to do it. If you give them remote access to your computer, they are going to take it over, steal your data, or use it for their bidding.
Another example is an email attack called CEO Fraud, which most often happens at work. This is when a cyber attacker researches your organization online and identifies the name of your boss or coworker. The attacker then crafts an email pretending to be from that person and sends the email to you. The email urgently asks you to take an action, such as conducting a wire transfer or emailing sensitive employee information.
Quite often, these emails pretend there is an emergency that urgently requires you to bypass standard security procedures. For example, they may ask you to send the highly sensitive information to a personal @gmail.com account. What makes targeted attacks like these so dangerous is the cyber attackers do their research beforehand. In addition, security technologies like anti-virus or firewalls cannot detect or stop these attacks because there is no malware or malicious links involved.
Keep in mind, social engineering attacks like these are not limited to phone calls or email; they can happen in any form, including text messages on your phone, over social media, or even in person. The key is to know what to look out for-you are your own best defense.
Detecting/Stopping Social Engineering Attacks
Fortunately, stopping such attacks is simpler then you may think—common sense is your best defense. If something seems suspicious or does not feel right, it may be an attack. The most common clues of a social engineering attack include:
- Someone creating a tremendous sense of urgency. They are attempting to fool you into making a mistake.
- Someone asking for information they should not have access to or should already know, such as your account numbers.
- Someone asking for your password. No legitimate organization will ever ask you for that.
- Someone pressuring you to bypass or ignore security processes or procedures you are expected to follow at work.
- Something too good to be true. For example, you are notified you won the lottery or an iPad, even though you never even entered the lottery.
- You receive an odd email from a friend or coworker containing wording that does not sound like it is really them. A cyber attacker may have hacked into their account and is attempting to trick you. To protect yourself, verify such requests by reaching out to your friend using a different communications method, such as in person or over the phone.
If you suspect someone is trying to trick or fool you, do not communicate with the person anymore. If the attack is work related, be sure to report it to your help desk or information security team right away. Remember, common sense is often your best defense.
Common sense is your most powerful defense in identifying and stopping most social engineering attacks.
Client Corner: Spotlight on YOU
Data Privacy Week 2021:
February 1st - February 4th
The Public Service Information Community Connection (PSICC.ca) is proud to support Data Privacy Day with this 4-day event that will focus on the potential of DATA ANALYTICS/AI DATA PRIVACY, and some of the most pressing DATA SECURITY concerns facing our public service.
Can Privacy and Data Analytics co-exist? Should we be concerned about the potential RISKS associated with increased rates of DATA SHARING? Are we exposing ourselves to larger CYBER SECURITY threats as we digitize?
They can. Yes we should be concerned, and yes, we most certainly are.
Now is the time for PRIVACY to take a front seat. As our public institutions harness new technologies, “ways of doing business”, and continue to innovate at unprecedented rates, the opportunity exists to truly collaborate to eliminate the old mindset of Privacy and Security being a barrier to innovation instead of an enabler.
The 2021 Data Privacy Week is a virtual conference dedicated to discussing our most current and pressing issues.
Newberry + AHA
Newberry's Client Referral Program: Cash in on this!
Newberry has just rolled out a Client Referral Rewards Program!
Existing clients, that refer companies to Newberry that result in the execution of a Monthly Managed Services Agreement with the referred client, shall have their recurring monthly managed services fee waived for one (1) billing period. The waived fee will be credited to your invoice after the referred client has met its one (1) month anniversary with Newberry.
To qualify:
- Referring Client has to be registered ahead of time with [email protected]
- New referred prospect must be signing up for one of our Managed Monthly reoccurring services, including but not limited to Mission Control, Managed +, SIEMaaS, Cybersecurity as a Service, etc.
The Newberry Grill:
Cynthia Beebe's Go-to Chocolate Brownies
- 2 cups sugar
- 6 tablespoons of Cocoa
- 4 eggs
- 1 teaspoon vanilla
- 1 1/2 cups flour
- 1 cup melted butter
- Powdered sugar (optional)
Instructions
Mix all ingredients by hand!
- Preheat oven to 350 degrees
- Mix 2 cups of sugar and 6 tablespoons of Cocoa
- Add and mix 4 eggs and 1 teaspoon of vanilla
- Add and mix 1 1/2 cups of flour
- Add and mix 1 cup of melted butter
- Pour into a greased 9×13 baking pan
- Bake at 350 degrees for 30 minutes
- When cool sprinkle with powdered sugar
