Skip to main content

TomsTekTips-Vol1

Page 1


Tom’s Tek Tips

For Asset Protection Professionals

ABOUT TOM

Tom is a nationally recognized asset protection expert who actively writes and speaks on the subjects of security, cybersecurity and shrink reduction. Tom serves as chief strategy officer and chief security information officer for CONTROLTEK, an emerging leader in product protection. He also serves as the chair of the Loss Prevention Research Council’s LP Innovations working group and is the organization’s senior technology advisor. He is a contributing writer for LP Magazine and D&D Daily.

Prior to joining CONTROLTEK, Tom was director of technology and investigations at Bloomingdale’s, where he was responsible for physical security, internal investigations, asset protection systems and data analytics. Before his 13-year tenure at Bloomingdale’s, he worked for Home Depot in loss prevention, and has had various technology, loss prevention, and operational roles at several other companies.

Tom’s Tek Tips

For Asset Protection Professionals

Volume 1

Dedicated to those who do the hard work of protecting their organization’s people and assets.

FIGHTING E-MAIL SPOOFING

WITH VPN

Recently a colleague of mine told me his organization fell victim to an email spoofing scam. His corporate email login was compromised while using public WiFi at a hotel, and the crooks successfully conned his finance department into changing a wire transfer to their account, all the while impersonating him.

Public WiFi hotspots like the ones we use at hotels, airports or Starbucks offer no encryption security. Someone with very little computer skills can easily eavesdrop on your communications (or your team members’) and even steal your log in credentials.

One possible solution? VPN – Virtual Private Network. If your company currently does not use one, you can purchase it for as little as $5 a month per user. A VPN will encrypt your activities and keep you safe on the go.

HOW TO PROTECT YOURSELF

FROM RANSOMWARE FOR ONLY $2 A MONTH

Cyber criminals have increased their use of ransomware attacks in the past couple of years. The WannaCry attack affected more than 200,000 users in 150 countries, and yes – it made many of them cry.

Ransomware is a piece of malicious code that encrypts all your files and locks you out of them. Cyber criminals then attempt to extort money from you – either pay them or you’ll never see your files again. It is estimated that 4,000 ransomware attacks occur each day. By the end of 2017 global loss will reach $5 billion.

A good preventive measure is an automated backup solution. However, if you’re using a physical external drive to back up your files, it will most likely be infected with the ransomware, too. The solution? An online backup service, which costs a little as 2 dollars a month. If you aren’t using one – start today.

BEING SMART ABOUT SMART

PHONE APPS

Just got an invitation via text message to download a hot new app for your phone? It’s free and it does some really cool stuff. But is it real?

It may not be. Scammers have been sending text messages lately convincing people to install apps that turn out to be malicious. They even use names of reputable companies to try to fool you in believing that it’s a genuine offer.

Never install anything from a text message unless you initiated the search. Always download your smart phone apps from the official app stores like iTunes and the Google Play store, and skip unknown sites no matter how great they sound.

DO YOU KNOW IF YOU HAVE BEEN A VICTIM OF SPEAR-PHISHING?

In the past two years a lot the cyber-incidents have one major similarity – they started with a spear-phishing email. Spear-phishing involves very targeted spoof messages where cyber criminals impersonate someone you know, hoping that you will click on a link or open an attachment.

For instance, you get an email from a co-worker who asks you to proofread something. You click the link and you are asked to login to your OneDrive account. But the email really wasn’t from your coworker, it only looked that way. And now the bad guys have your OneDrive credentials.

In the example above it was easy to miss that the message came from john.smith@abc.co instead of john. smith@abc.com (note that only one letter is different in the domain extension). So take an extra moment to look more closely at the emails you receive and where they are actually coming from. More than 35% of all cyber incidents start with a human error.

THE BASIC WAY TO SEARCH THE DARK WEB

The Dark Web is the hidden section of the Internet that requires specific software, like TOR, to access it. It allows users and website owners to be anonymous and difficult to trace. The Dark Web is generally not indexed, which makes it difficult to search. You can search some of the Dark Web via Google. For example, if you want to search the word ‘shoplift’ you can type the following in the Google search box: “shoplift inurl:.onion.to”. Your search results would show in Google same as in a basic search, but keep in mind you will need TOR to view the results in detail. If you use a more complex search method like “shoplift + YOUR COMPANY name” you would get more refined results. This method won’t find everything but can be useful in fraud and ORC investigations.

TWO-STEP VERIFICATION: DO YOU HAVE

IT TURNED ON?

Recently I was with a friend and former colleague who keeps getting locked out of his Gmail account. When I asked him if he has two-step verification turned on, he said – no.

Two-step verification is a secondary authentication method when logging onto email, social media, or corporate accounts. Most, if not all, of the major online service providers of email, banking and social media offer two-step verification free of charge. When logging in from an unrecognized computer or mobile device the service provider sends a text message or push notification to an application, like messaging. This ensures no one can access your account even if they have your password.

Check out this site for the instructions on enabling twostep verification on most major sites: twofactorauth.org

WHO HAS YOUR LOGIN CREDENTIALS?

I’m sure you’ve seen the news about the security breaches of different web service providers. Yahoo, LinkedIn, Adobe and Dropbox, just to name a few, have all been compromised by hackers. Regardless of how old the breaches are, once the information is out on the web it’s available to the bad guys pretty much forever.

Are you wondering if your login credentials have been compromised? Here is where you can check: haveibeenpwned.com

Follow the instructions by entering your email, and this site will tell you if your credentials are at risk. If it turns out your information has been a part of one of the many breaches, be sure to change your password immediately.

DELETE DOESN’T ALWAYS MEAN

IT’S GONE

Every wonder what happens when you delete a tweet, public Facebook post, or comment on a news story?

In theory, once you delete it should be gone. However, search engines, like Google and Bing for example, index the web to make searches quicker. Indexing essentially means saving all the data the search engine comes across. So even after you deleted something that was publicly visible, it will remain visible in the cached (indexed) search results. To complicate matters further, there are also services, both paid and free, that index and store information from the web for marketing purposes.

The basic rule of thumb is that once something is posted it out there forever. Therefore, don’t post anything you wouldn’t want to defend in court or at work.

TAKE CONTROL OF YOUR SOCIAL MEDIA IDENTITY

Recently I attended a conference about cyber security. After exchanging business cards with several people, I started to add folks to my LinkedIn network. One of the individuals sitting at the table with me made it a point to say how he didn’t have a LinkedIn account and he didn’t like social media.

I still searched his name on LinkedIn and lo and behold – a profile appeared. I showed it to him and he was shocked – the profile had all his information but it wasn’t him. Someone was impersonating him.

Social engineers and hackers look to assume security professionals’ identities. It starts simply with creating a social media profile. So whether you like social media or not, you probably should create an account on popular networks using your email and name. You can make the account private, which will make it more difficult for people to assume your identity this way.

WHAT’S THE DIFFERENCE BETWEEN

ACTIVE AND PASSIVE RFID?

Passive RFID systems use tags with no internal power source. They are powered by the electromagnetic energy transmitted from an RFID reader. Passive RFID tags are used for applications like access control, file tracking, retail, race timing, supply chain management, smart labels, and more. The lower price point per tag makes employing passive RFID systems economical for many industries.

Active RFID systems use battery-powered RFID tags that continuously broadcast their own signal. Active RFID tags are commonly used as “beacons” to accurately track the real-time location of assets or in high-speed environments such as tolling. Active tags provide a much longer read range than passive tags, and they are also much more expensive.

APP?

Citizen helps people stay safe by providing real time notifications of nearby emergencies and incidents.

The Citizen app is available for iOS and Android. It only has emergencies and incidents in New York City and the San Francisco Bay Area at this time. However, you don’t have to be in these two cities to download or use the app.

More cities will be added soon, so keep an eye on this app. It is a great free resource for real time emergencies and incident management.

www.d-ddaily.net

WINDOWS 10 SECURITY: HOW

TO PROTECT YOUR FILES FROM RANSOMWARE

Ransomware is a type of malicious software designed to block access to a computer files by encryption. A hacker will request a sum of money to be paid to get your files back.

In Windows Defender Security Center app, you can enable Controlled folder access by clicking the shield icon and toggling on Controlled folder access. This will help protect Windows system folders and default locations such as Documents, Pictures, Movies, and Desktop.

A BRIEF HISTORY OF RFID

The first use of RFID technology was in WWII for help identifying aircraft. Further development occurred in the 60’s and 70’s, extending the use of the technology into civilian space. The first patent for RFID was in 1973 for door card readers. By the 80’s RFID was used for tracking nuclear material, cattle, toll payments and many other applications.

Faster data transfer was achieved for transmission over longer distances in the early 90’s. This is the UHF RFID period. In the late 90’s UHF RFID tags started interacting with the Internet. Between 1999 and 2003 the EPC (Electronic Product Code) introduced.

Finally, after more than 50 years, a standardization occurred and now a wider adoption of the technology is happening.

WHAT ARE CRYPTOCURRENCIES?

Cryptocurrencies are a subset of digital currencies that may also be called virtual currencies. In simple terms, a cryptocurrency is money that exists only in the digital world. The most well-known cryptocurrency is Bitcoin

Cryptocurrencies use cryptography and advanced mathematical principles with data to achieve three objectives: (1.) secure transactions, (2.) control the creation of additional units of currency, and (3.) verify the transfer of value. They use a peer-to-peer decentralized system to conduct transactions and protect the anonymity of users. The entire process is online.

WHAT IS BLOCKCHAIN?

Blockchain is a decentralized, distributed and public digital ledger that can be used to track just about any type of data. The records in it cannot be altered easily.

Blockchain is decentralized so there is no one authority that maintains the ledger. This means that everyone can see and track movement and changes. When used for a cryptocurrency (like Bitcoin) it proves who owns the currency and how much it’s owned. When used for data, it can keep track of the true owner and who has rights to the data.

Blockchain uses cryptography and advanced mathematical principles together with data to achieve three objectives: (1.) secure transactions, (2.) control the creation of additional units of currency, and (3.) verify the transfer of value. It uses a peer-to-peer decentralized system to conduct transactions and protect the anonymity of users. The entire process is online.

WHAT IS GENERAL DATA PROTECTION REGULATION

(GDRP)?

The General Data Protection Regulation (GDPR) is an European Union (EU) regulation intend to enhance data protection for all individuals within the EU. It addresses the export of personal data outside the EU. The intent of the GDPR is to give control back to people of their own personal data and to simplify the regulatory environment for international business. The GDRP becomes enforceable in May 2018. It applies to controllers and processors of data. International retailers will be affected.

THE RISK OF DEFAULT PASSWORDS

Most network and Internet of Things devices (IoT) have default passwords. A default password is usually used to allow the device to be accessed during its initial setup, or after resetting to factory defaults. The biggest risk is the fact that default passwords are ready available. All you need is the model and manufacturer to easily find the default password on the internet. There are even lists of these passwords available to the public as a hacking or technical support resource.

Routers and IP cameras have recently been in the news a lot due to the risk of default passwords. Network switches, IP phones and many other devices have the same risk. Both commercial and consumer devices are at risk. Some manufacture requires that the default password is changed at setup.

At home, check your router and change the default password. At work, check IP cameras, network switch and other network devices.

WHAT IS DE-IDENTIFIED DATA?

De-identified data is data that’s considered direct & known. Generally, it contains indirect identifiers – some data points are removed or manipulated to break the linkage to a real-world identity. For example, you may remove an address from an exception report but leave a customer number. In this example you would be able to relink the address to the customer number. Deidentified differs from anonymous data because the identity may be re-acquired in most instances.

Don’t miss the new Tom’s Tek Tips! Follow CONTROLTEK USA on LinkedIn and Twitter to stay current on all of Tom’s writings every week.

HOW TO MAKE GOOGLE ALERTS

WORK FOR YOU

Do you read the news daily? If you want to get the most up to date news try Google Alerts. You can set up an alert for just about anything. For example you can set up an alert for your company name + shoplift. Once the alert is set up you can get the news directly sent to your inbox. Its free and easy to set up. Go to google.com/alerts to get started.

IMAGE TO TEXT?

Have you ever been at a meeting or conference and wanted to transcribe a slide or document? If you are like most folks nowadays, you snap a picture with your smart phone. But did you know that there are now apps that can convert your picture to text? Yes, actual text! Optical Character Recognition (OCR) has gotten very advanced in the last few years. Search the Google Play or Apple App store for OCR apps. My favorite one is Prizmo, and there are a lot of other good ones.

HOW TO LISTEN TO THE POLICE LIVE

ON YOUR SMARTPHONE DURING

AN INCIDENT

The use of smart phones and social media has changed the way we can monitor an incident. If you live or work in a major metropolitan city, there is a good chance that there is a live feed available of your police department and emergency services. Broadcastify and RadioReference are both good sources for live feeds.

If your company has a Special Operations Command (SOC) or Emergency Operation Center (EOC) you should get the links to the feeds prior to an incident. There are several iPhone and Android apps that have live feeds from Broadcastify preloaded.

WHAT ARE GAIT VIDEO ANALYTICS?

Gait analysis refers to the study of human motion (as in one’s gait, or the manner of walking). Gait analytics, as related to video and security, measure body movements and body mechanics, and are used to verify or match someone by the way someone walks. Gait analytics are somewhat similar to facial recognitions, except that they uses the body’s movement rather than face features.

WHAT IS A DENIAL-OF-SERVICE (DOS) ATTACK?

Denial-of-Service Attack (DoS attack) is a form of cyber-attack in which the hacker attempts to make a computer or network resource unavailable by temporarily or indefinitely disrupting services connected to the Internet. Denial of service is often accomplished by overloading the targeted computer or website with requests. This can effectively render the target system inaccessible to legitimate users, disrupting its normal operation.

THAT’S NOT YOU IN THAT VIDEO

If you receive a message on Facebook thats says check out this video of you, don’t click on it. Messages like this have been circulating on Facebook and the web for several years now, and they are almost always malicious in nature. Even when they seem to come from a friend or family member, they can be from a hacker. Before clicking on it, ask the sender what it is, preferably by phone or text.

WHAT IS THE “INTERNET OF THINGS” (IOT)?

When we think of the Internet, we usually think websites and how we connect to them via browsers on our computers. An easy way to think of IoT is that it consists of any device that turns on and can be connected to the internet. This can include everything from cellphones, headphones, lights, wearable devices like the Fitbit and almost anything else you can think of. IoT exists in both the commercial and consumer space. It is estimated by 2020 there will be 26 billion IOT devices out in the wild.

Have a question for Tom?

Reach him directly on Twitter: @tomsitlogic or on LinkedIn by looking up Tom Meehan, CFI

ABOUT CONTROLTEK

We are innovators. We are listeners. We are doers. And for over 40 years we’ve been helping companies solve their asset protection challenges in new, efficient and secure ways.

Our EAS and RFID solutions help some of the biggest retail chains protect their merchandise better and run their operations more efficiently.

And our tamper-evident security packaging is relied on by the nation’s leading banks, armored couriers and retailers for transporting cash safely and securely.

As a second-generation family owned business, with a history of stable growth and a reputation for strong customer focus, CONTROLTEK continues to deliver on its core promise every day: provide solutions that protect and be the people that deliver.

Tom’s Tek Tips are bite-sized lessons on technology for busy asset protection professionals. Each tip is written so that it can be read in under 30 seconds.

Tom’s Tek Tips are published every Tuesday in D&D Daily, which you can subscribe to for free at www.d-ddaily.net

You can also stay current on Tom’s writings about asset protection and technology by following CONTROLTEK USA on LinkedIn and Twitter.

Turn static files into dynamic content formats.

Create a flipbook
TomsTekTips-Vol1 by controltekusa-catalogs - Issuu