You’re on your own

September 2015 News & Events

I had a strange experience recently. I have been a ‘member’ of an online site for some time, a few years actually, in order to receive a weekly email from them. This was not an important site in that it held critical or sensitive information about me; all it had was an email address and a password.

The password I used was one I have been using for years and that I use on multiple unimportant sites simply because it’s easier to remember. My thinking is that all someone hacking that site would get was my email address and a password which would grant them access to many other unimportant accounts. The worst that could happen was I get a bunch of unwanted newsletters and spam, which I do anyway.

I recently decided to create a full profile on the site, which now includes more sensitive information about me, not bank details or anything like that, but personal details I would choose not to have floating around all over the world. And while the site has been well designed and thought through in terms of usability, when I decided I needed to change my password to something less easily guessable and also unique to the site, I couldn’t.

There was no way to change your password. And this is a commercial site that takes credit card numbers etc., but doesn’t offer you the option to change your password. I sent an email to the site’s support and received a response almost immediately – very impressive. The support person suggested I send my new password through to her and she would change it.

After all the breaches and exploits we hear of on an almost daily basis, why do companies that rely on online commerce in one form or another have no clue about security?

This got me thinking about my policy of using the same password for unimportant sites. Many people choose this option. Those who actually think about security use complex and unique passwords for banking or other important sites. But is that a good idea?

In today’s connected world there are few, if any sites of lesser importance. The reason criminal syndicates collect so much data, much of it irrelevant, is because every little bit of data they collect from one site can be linked to a little snippet of data from another site. A simple email address from an innocuous newsletter can, for example, be linked to a social media profile with work details or more personal information that can be used to build a profile of you.

Eventually all the little bits of data create a full profile of you and with this in hand, the syndicates have access to more than you would believe possible. And it’s not only your lack of security that puts you at risk. Just last week a site asked for my identity number, an unsecured, unencrypted site. Not only won’t they be getting my ID number, they won’t be making any revenue off me. It is inexcusable to put your clients’ data at risk.

Perhaps it’s because South Africa is not as litigious as America that companies don’t pay any attention to their customers’ information. After all, who is going to come after them when they put thousands of people at risk? There are some very smart people in various police departments, but there are too few of them to have a major impact. And with the country lacking a proper cyber security strategy, you and I are on our own.

So basically, look after your own information because nobody else will. Even if you’re an editor with a bank balance in single figures, money launderers still want your life because the Internet allows them to do their crime in bulk, damage many people, and get away with it.

Andrew Seldon

Editor



Credit(s)




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Highest increase in global cyberattacks in two years
Information Security News & Events
Check Point Global Research released new data on Q2 2024 cyber-attack trends, noting a 30% global increase in Q2 2024, with Africa experiencing the highest average weekly per organisation.

Read more...
From the editor's desk: We’ve only just begun
Technews Publishing News & Events
The surveillance market has expanded far beyond the analogue days of just recording and/or monitoring screens. The capabilities of surveillance technology today extend to black screen monitoring with ...

Read more...
The future of the surveillance channel
Duxbury Networking Technews Publishing Elvey Security Technologies SMART Security Solutions Surveillance
The video surveillance market has evolved from camera-based specifications to integrated solutions that solve customers’ problems. Moreover, the growth of AI and cloud has changed the channel even more, with more to come.

Read more...
AI means proactive surveillance
DeepAlert Technews Publishing SMART Security Solutions AI & Data Analytics Surveillance
SMART Security Solutionsasked DeepAlert for some insight into how AI is transforming video surveillance, even to the extent of it being taught to protect the privacy of those in the cameras’ view.

Read more...
The state of the VMS market
Arteco Global Africa Milestone Systems Cathexis Technologies Technews Publishing Surveillance
SMART Security Solutions asked three platform vendors in South Africa, one that is developed and maintained in the country with an international market, for their views on the state of the VMS market and where it is headed.

Read more...
SAFPS issues SAPS impersonation scam warning
News & Events Security Services & Risk Management
The Southern African Fraud Prevention Service (SAFPS) is warning the public against a scam in which scammers pose as members of the South African Police Service (SAPS) and trick and intimidate individuals into handing over personal and financial information.

Read more...
Strong industry ties set Securex South Africa apart
News & Events Training & Education
Securex South Africa, co-located with A-OSH EXPO, Facilities Management Expo, and Firexpo, is a meeting place of minds, where leading security, safety, fire, and facilities professionals come together, backed by strong ties with the industry’s most influential bodies.

Read more...
Connected commercial drone market to reach US$37.3 billion
News & Events Commercial (Industry) IoT & Automation
The global market for connected commercial drones is forecast to grow from US$18.6 billion in 2024 at a compound annual growth rate (CAGR) of 15% to reach US$37.3 billion in 2029

Read more...
Phishing attacks through SVG image files
Kaspersky News & Events Information Security
Kaspersky has detected a new trend: attackers are distributing phishing emails to individual and corporate users with attachments in SVG (Scalable Vector Graphics) files, a format commonly used for storing images.

Read more...
Fully-integrated browser AI
News & Events
Opera Mini now provides all its smartphone users with its own free built-in browser AI, Aria, including AI chat, Ask Aria and image generation. According to an Opera survey, 80% of South Africans want AI tools integrated into their browser.

Read more...