Blog Feed

Password Manager KeePass Is Vulnerable

Posted by on 19:28 in Industry News | 0 comments

Password Manager KeePass Is Vulnerable

It is not news that a fair amount of threats waits for the user in the vast global network. And it is clear that the best way out is to keep valuable information in encrypted form and protect it with a strong password. But the fact that it is possible to “pull” out in a form of a simple text file all the data from the password manager – the program which encrypts and generates passwords – became a surprise for many. A well-known cross-platform free password manager KeePass appeared to be under the threat. Password Manager KeePass has demonstrated its vulnerability This password manager came into service in 2003. At first, there was only a version for Windows, but later the password manager started support of other operating systems: starting from Linux and Max OS X for the desktops and laptops and to the mobile platforms Android and Pocket PC. Until recently KeePass has been considered almost invulnerable and its users could feel safe. If to take into account that it a free cross-platform solution, which had a good reputation for a long time, you can imagine the number of users who have entrusted the storage of their passwords to this program. This problem can touch almost everyone. Fortunately, the person who discovered the vulnerability is not a hacker. It is a Security Assessment employee Denis Andzakovic. He posted on GitHub a free tool called KeeFarce able to decrypt all data (usernames, passwords, notes) stored in the KeePass Password database. The operating principle of this tool is based on the introduction of the DLL-injection to the victim’s computer. During the KeePass runtime, an application-cracker exports currently open database decrypts it and creates a text file, which the hacker will be able to pick up later on his own (in the case of physical access to the victim’s computer) or get remotely. Andzakovic notes that the vulnerability of the KeePass data protection is not a problem only of this program. DLL-injection may be introduced (by using a Trojan virus, for example) into any password manager. How to protect your data if your password manager was hacked So how the data protection should be carried out taking into account the identified risks? Which means should we use to secure our data against a password attack? The answer is quite simple and clear to everyone: it is two-factor authentication. Such means of authentication as tokens, special smartphone applications or one-time passwords delivery via SMS, act as a second “defense line” for the user’s account. Their advantage is that every generated password is valid only for a short period of time. And even if the hacker intercepts OTP password, in a minute he needs to intercept a new one. There are even further ways to secure one-time password. For example, the CWYS function (transaction data signing). Modern authentication methods can help to protect your account even if somebody stills the password. You need only to set up 2FA (two-factor authentication) on any account, where it is possible. The confidence that the attackers would not be able to take control of your account even if an encrypted password is stolen will offset some time expenditures and inconveniences related to the two-factor...

read more

Cybersecurity Lesson from T-Mobile and Experian

Posted by on 17:33 in Industry News | 2 comments

Cybersecurity Lesson from T-Mobile and Experian

Recently, the whole world and especially the U.S. citizens have been stirred up by the news about the leakage of credit history data of 15 million subscribers of the international mobile operator T-Mobile. What is notable in this story is that the information was not stolen directly from T-Mobile’s database but from the servers of its partner – Experian. Considering this example in details gives a valuable cybersecurity lesson, so let’s review it now. The popular proverb says, ‘No man is an island’. It is much easier to solve any task together. Not everyone and not always has a possibility, time and enough knowledge to solve the specific problem personally and comprehensively. Thus, to reach success in business, large companies often cooperate with other companies that provide them with certain types of services. Depending on the type of services, some providers may ask the registration data of the company or the personal data of its employees and customers. It is to be noted that two-factor authentication provider Protectimus is not among such partners. During the authentication process, Protectimus does not require and doesn’t transfer any users’ personal data. It is reasonable, since often we enter the requested information automatically, without giving due attention to how and where these data will be stored, who can get this information, and what consequences this may entail. How T-Mobile users’ data have been stolen A good example of such carelessness became the cooperation between the T-Mobile Company, working in the field of mobile communications, and global information service Experian, which assessed the customers’ credit history before they signed a contract with T-Mobile. This partnership resulted in a large scandal – personal information of 15 million T-Mobile customers was stolen by unknown violators from Experian server. The stolen data included names, dates, birthdays, addresses of the clients, as well as encrypted social security numbers, passport details and driver’s license numbers of people who used or intended to use the T-Mobile service in the period from September 01, 2013 to September 16, 2015. This sensational event demonstrated the basic lesson of cyber security – each and everyone should take care of data security. Hackers are crafty, and if they can’t find a gap in the system of one company, then they’ll find it in a partner’s company and will get all the information they need. Thus, everyone should think whether their data is in reliable hands, whether they don’t let their partners down, and their partners don’t let them down. So, we cleared up that the main lesson of cybersecurity is that both partners are obliged to take care of the data protection, and keep information on resources carefully protected from compromise. For example, Experian’s mistake led to a chain of troubles for its innocent partner and its clients. It is still unknown how the hackers managed to gain access to the Experian servers, and moreover, to gain access to the T-Mobile encrypted files. But it is clear that the company did not fully take care of the security of confidential information, which should be stored under lock and key. In connection with the situation, it is our duty to remind you that one of the key elements of data protection is two-factor authentication of users via hardware tokens or special applications for smartphones, which generate one-time...

read more

How to Make the Internet of Things Safe

Posted by on 16:22 in Industry News, R&D | 4 comments

How to Make the Internet of Things Safe

In recent years, the Internet of Things has been developing rapidly. Today, not only computers and smartphones can access the network. Many kinds of home appliances, including refrigerators and washing machines, are also connected to the World Wide Web. The idea of such devices is certainly good: Internet connection allows you to manage them even at a considerable distance. It’s comfortable to use a smartphone on your way home to ‘order’ the microwave to warm up dinner for your arrival and coffee machine – to make a cup of refreshing beverage. But such innovations also have a downside. Every network communication attracts hackers with new viruses attempting to take over other people’s secrets. Is the modern Internet of Things safe? In the case of computers and smartphones, data protection is one of the main concerns of developers and device manufacturers. But the security of the Internet of Things is obviously not up to par. Here are some facts proving this: Not long ago, HP has conducted a research of ten home video surveillance systems from different manufacturers, and only one used two-factor authentication to gain access to the system! All these systems had other serious security breaches: from the absence of blocking after repeated incorrect password entering – to the possibility of watching streaming video from cameras without authentication. During this year’s experiment, a Jeep Cherokee was brought under control by a simple netbook while moving on the highway. The person who controlled the car remotely could turn the cooling on maximum and turn on the wipers, as well as change the radio wave. The attempts by a driver, who participated in the experiment, to cancel these orders manually were of no success. Later, during a test in the garage, the researchers distantly blocked jeep wheels. Had it happened on the track, it would lead to a serious accident and even death. Samsung TVs with Smart TV function are capable not only to collect data about the user’s behavior but also to send this information to the third person. An example that at first glance seems absurd. Trojan viruses written specifically for the coffee machine were detected. Just a few years ago, such stories existed only on the pages of science fiction novels. Nowadays, they have ceased to be the fruit of creative people’s imagination and moved to the subjects of news feeds. Do manufacturers of “smart” things know about the serious problems with data protection in their devices? Of course, they do! But at the current stage of Internet of Things development manufacturers give preference to the introduction of new functions and to the speed with which the items are brought to the market. Thus, they don’t care about security, which requires a large investment and does not bring quick profit. Customers also rarely think about the dangers lurking in the Internet of Things and often do not even use the available protection means. The temptation to seize new opportunities prevails over the caution. How to protect the Internet of Things against hacking In reality, the IoT (Internet of Things) security doesn’t need much to cover most of the ‘holes’. It needs only reliable means of user authentication. A simple 2-factor authentication will not allow an unauthorized person to get access to the remote control of cars, cameras,...

read more

Biometric Authentication Pros and Cons

Posted by on 14:39 in Engineering | 3 comments

Biometric Authentication Pros and Cons

If someone steals your password, you can change it. But if someone steals your thumbprint, you can’t get a new thumb. The failure modes are very different. – Bruce Schneier The popularity and availability of information technologies are constantly increasing. And at the same time increases the number of threats associated with their use. The main one is the danger of critical information leakage – both personal and corporate. Thus, today data protection is the most important area of computer security experts’ work. The first and foremost method to prevent unauthorized access to any confidential information is to keep a wary eye on the legitimacy of users who have an access to it. The modern level of technology development allows solving this problem quite efficiently. More and more often different companies introduce two-factor authentication. In 2FA entering the login and password is just the first step. The additional step of authentication is the use of the one-time password. But to put an insurmountable barrier for hackers, we need one more obligatory component: the users’ desire to apply the experts’ achievements and to follow their recommendations. Yet, modern users want authentication to be not only reliable but also easy. That is why they not always activate 2FA on their accounts. Biometric authentication has become one of these easy ‘magic’ tools, which can make 2-factor authentication more popular. It seems what could be easier and more reliable? Each person has unique fingerprints, voice, facial features. They are always with us, we cannot lose them. And modern gadgets are advanced enough to read and analyze these identifiers. Not only ordinary people but also serious organizations fall for biometric magic. British banks have introduced biometric fingerprints for customer’s login. This technology has long been used to unlock the Apple’s smartphones. Now, this feature is being introduced into new Android smartphones models. Master Card is working hard to introduce selfies as the authentication method. Among other popular biometric authentication methods are the retina or iris scanning, authentication by a finger or palm venous patterns, by voice, pulse or even selfie. Is it convenient? Yes. Is it reliable? Well, this needs further investigation. What dangers can we meet using biometric authentication? Imperfect equipment. Since any biometric parameters are usually checked with average smartphones, which differ in quality, there is a probability of false negative result. For example, the system may consider the fingerprint suspicious because of a simple cut on a finger. Thus, it may refuse to recognize the authenticity of the owner of the account. In the case when the system uses multifactor authentication, and biometric data is just one of its components, the identification can be realized by an OTP (one-time password). But when biometric authentication is used as the second factor of 2FA (two-factor authentication) there is no possibility of one-time password check. The user will never be able to sign in because of this false alarm. Not only law-abiding citizens use the fruits of technical progress. Attackers quickly become aware of the latest technological innovations. For example, several years ago there was a program that allowed you to add to a video a virtual replica of the person’s photo in real time. Today hackers can use such program to cheat the face scanner. They can show the dynamic moving video clone...

read more

Two-Factor Authentication 2015: Opportunities and Prospects

Posted by on 19:43 in Engineering, Protectimus Products | 16 comments

Two-Factor Authentication 2015: Opportunities and Prospects

Modern technologies have brought a lot of conveniences and opportunities into our lives, but also sharply reduced the chances of complete privacy. Photos that are not intended for prying eyes, credit card numbers, passwords for accounts in social networks and e-mail services, business documents stored in cloud services, the hand of a hacker is able to reach all this with little to no effort. Traditionally one of the most vulnerable aspects of computer security is strong authentication. Therefore, multifactor authentication methods are constantly being improved and developed. The usual two-factor authentication, when temporary passwords are delivered by a text message, is far from being the only option. Let’s see what means of security authentication exist nowadays and what means are being developed? 1. Applications for smartphones. According to recent studies, smartphones are used by about 50% of inhabitants of the Earth. If we take into account only the developed countries, where the problem of data protection is most acute, the numbers are even more impressive. That is why applications that can turn the smartphones of the users into an OTP token are increasingly distributed. In ‘Google Play’ and ‘App Store’ you can download Protectimus‘ mobile authentication application for Android and iOS smartphones and for Android Smart Watch. The Protectimus SMART application allows you: to select OTP (one-time password) generation algorithm, (HOTP, TOTP, OCRA); to set the length of the 2 step verification code (6 or 8 characters); to use the data signing function (CWYS), which protects from banking trojans and data modification; to create multiple tokens on a single device. The system of data protection with the help of a software application, however, has one drawback. If the signing in the account takes place from another device (PC, laptop), the software token properly fulfills its functions. But if you go to a site with the same device on which the mobile authentication app is installed, the effectiveness of the protection will be reduced. 2. Hardware tokens. Hardware OTP tokens can provide a higher level of information security. These devices operate autonomously; they don’t require an internet connection. In addition, one-time password token can be protected by a PIN-code to avoid unauthorized use in the case of loss or theft. Hardware tokens may look different, but they are always quite compact and small in size. For example, the ‘Protectimus Slim’ has a stylish design in the form of a credit card and TOTP token ‘Protectimus One’ is designed as a convenient key fob that can be worn together with the keys. The ‘Protectimus Ultra’ token stands out for its reliability. Its main feature is that the secret key is generated only during the activation of the token, which means that even the developers of the OTP token don’t know the secret key in advance. ‘Protectimus Ultra’ uses the OCRA algorithm (OATH Challenge-Response Algorithm), which is currently the most reliable one-time passwords generation algorithm. 3. Biometric methods. The previously described two-factor authentication methods are based on the one-time passwords generation while biometric techniques use different biometric parameters of the person instead of OTP passwords. Identification happens by the unique, peculiar to the only person’s individual parameters: voice, fingerprints, retina, or even selfie can act as identifiers. However, such ‘tools’, although very attractive in terms of ease of use, are not as...

read more

One-Time Passwords: Generation Algorithms and Overview of the Main Types of Tokens

Posted by on 19:32 in Engineering, Protectimus Products | 0 comments

One-Time Passwords: Generation Algorithms and Overview of the Main Types of Tokens

The use of one-time passwords Amid the constantly growing online business segment, data protection has to be particularly reliable. If you still can ‘survive’ the hacking of your personal page on social networks (though it’s extremely unpleasant too), the loss of business information can lead not only to the loss of reputation and income but even to the closure of the company. One of the most defenseless points in the information security is the reliable user authentication of everyone attempting to access his or her account on a particular website. Common reusable passwords are well known to everyone and are pretty useless at the present level of hacker threats. They are unable to withstand the pressure of attackers, equipped with such ‘tools’ as keyloggers, interception of the data, and methods of social engineering. Much higher level of protection can be provided by using one-time passwords. How one-time passwords are generated The most convenient and secure one-time passwords generation tool at the present moment is a token. It can be either a software token – an application for a tablet or Android/iOS smartphone or hardware token in the form of USB flash drive, trinket or credit card. For extra protection, each token can function along with the PIN-code, which should be used while entering the one-time password. One-time passwords are usually generated by using one of three algorithms: HOTP – HMAC-based one-time password algorithm. Server and OTP token keep count the number of authentication procedures performed by the user, and then generate the password, using this number in the calculations. The mismatch in the calculations between the server and the token may cause a problem. Such situation is possible, for example, if the user repeatedly presses the button for generation of an OTP password and doesn’t use the password later. TOTP – time-based one-time password algorithm. In this case, the password is created taking into account the internal clock of the token. TOTP is convenient, because the time of OTP password’s functioning is limited, which means it can’t be created in advance or used after the expiration term. OCRA – OATH challenge-response algorithm. This is a very reliable algorithm, assuming, however, a bit more steps than the previous ones. The mutual authentication of the user and the server occurs during its work. Unlike other algorithms, it uses a random number issued by the server as an input. It is worth mentioning that if you use the TOTP and OCRA algorithms, sort term passwords are produced, which significantly complicates the process of hacking. The tokens provided by Protectimus use all three algorithms. Protectimus ONE and Protectimus Slim tokens generate passwords according to TOTP algorithm, but particularly reliable Protectimus ULTRA tokens create the most secure OTP algorithm by using OCRA. Threats and risks of using one-time passwords No matter how reliable is the two-factor authentication with the one-time passwords, there are some dangers, which can be avoided, if you take care of the precautions. Interception of the OTP password. In this situation, which is often called ‘a man in the middle attack’, a hacker intercepts the authorized password and authorizes in the system. To avoid this, you can use 2FA with data signing function (CWYS), available in Protectimus SMART token. It allows considering not only the password, but also some other parameters...

read more

Two-Factor Authentication with Background Noise: Is It Safe or Not

Posted by on 14:45 in Engineering, Industry News | 0 comments

Two-Factor Authentication with Background Noise: Is It Safe or Not

The term two-factor authentication is known for the majority of active users of the Internet. It is available on a variety of well-established websites conducting the work with the data of users: in social networks, email services, online banking.  But unfortunately, not all the users use the benefits of this type of authentication. The most frequently this occurs because of some inconvenience with the standard 2FA procedure. The main reason for the inconvenience is that for getting a one-time password a user has to receive an SMS on his phone or to generate it with the help of software or hardware token. If you are using SMS authentication it is required: to have the phone by your side; to gave a stable signal of mobile connection (which is available not always and not everywhere); some efforts from the user: to unlock the phone, to read the message, to enter the received OTP code in the browser and to send the confirmation form.   If you are using tokens, there are a number of other inconveniences: to get the token you must go to the bank; you always need to have the device with you; the PIN-code of the token should be kept in mind (or written down in a safe place); you have to make sure that the token will not be lost.   As the practice shows, not everyone is ready for such sacrifices – even for their own safety. Therefore, software developers and experts on data protection are constantly improving the means of authentication, in every way trying to make the process easier for the owners of the accounts. For example, biometric authentication methods (retinal scans, fingerprints, selfie authentication) are actively developed. And not so long ago a team in Zurich, working in the ETH, invented a new way in which the two-factor authentication is performed automatically and does not require any effort, except the installation of a single application on a smartphone. This technology is called ‘Sound-Proof’, and it is based on the recording and further comparison of background noise at the location of the user. How the protection of data by this method is implemented? When there is an attempt to enter the site that supports the ‘Sound-Proof’ method, the application installed on the phone is recording the background noise for three seconds at the place where the user is located. At the same time, the computer microphone is also recording the noise. Then the recordings are being matched on the server. If the background noises are the same, this means that both devices (the computer and the smartphone) are in one place, and data protection system allows entry into account. To navigate the system it is not necessary to install any software on the computer, you just must have the application on your phone or tablet and permit your browser to use the microphone. That means that you can carry out authorization from someone else’s laptop or computer (for example, in a cafe). Even the phone itself does not need to be taken with you: the app works independently in the background. However, the smartphone or tablet should be connected to the network by the Wi-Fi or mobile internet. Judging by the number of users, the efforts spent for the authentication process (or rather,...

read more

Out-of-Band Authentication

Posted by on 13:23 in Engineering, Protectimus Products | 4 comments

Out-of-Band Authentication

Out-of-band authentication (OOB) is one of the most popular types of two-factor authentication in the financial sector. It presupposes sending the one-time password to the user via a communication channel other than the main one, which is used for transactions on the Internet. Most often, during the OOB authentication, the OTP (One Time Password) is sent to the clients in the form of a text message via SMS or email and the company does not have to spend money to buy tokens or to require from users to install additional software on their smartphones. It must be noted that the Protectimus company also develops a new technology for out-of-band authentication – two-factor authentication with Push messages. This method is much cheaper than SMS authentication. Out-of-band authentication is widely used in financial, banking institutions, and other organizations with high security requirements for the transaction. This type of protection significantly complicates the process of hacking, since for a successful theft of money or data a hacker should compromise two separate independent channels. This method of protection from unauthorized access is quite widespread and easy to use, but its security is under a great doubt because there is always the threat of man-in-the-middle attack Man-in-the-middle attack According to the results of surveys of financial institutions staff, the man-in-the-middle attack is the most serious threat to online banking, e-business and payment gateways. Zeus, Sinowal, Carberp, and Clampi are the most widespread maleficent programs for this type of attack. The method of the man-in-the-middle attack involves compromising of the intermediary link, the penetration in data transfer protocol, the interception and substitution of correspondents’ messages, deletion or falsification of data while both sides are sure of the legality of the operations. Scenarios of such an attack can vary – the change in the connection parameters between the client and the server, the interception and substitution of public key exchange links between the client and server, the introduction of SQL-injection to grab an authorized session, data modification, Automated Transfer Systems, malware like banking trojans, but they are all aimed at gaining access to the customer’s account and conducting financial fraud behind his back. To protect transactions from some of these attacks, such as data modification and Automated Transfer System, the best solution is a function of transaction data signing called CWYS (Confirm What You See). In the tokens that support this function, while generating one-time passwords, not only the secret key and the parameters of time / event / challenge-response (depending on the algorithm) are used, but also some additional information – the currency, the recipient, the amount of the transfer, etc. Thus, an attacker cannot use the one-time password generated for a particular transaction, to initiate another transaction. This feature is supported in such tokens as Protectimus SMS, Protectimus Mail, and Protectimus Smart. It is worth noting that the weak link for the out-of-band authentication is the use of smartphones for making online payments. Making a payment with the same phone, which receives a message with an OTP password, the user literally ‘puts all his eggs in one basket’. Two-factor authentication, in this case, has no efficiency, because if the virus is already on your phone and the attacker conducts an illegal operation, penetrated to this smartphone, nothing will prevent him from intercepting the one-time password...

read more

Microsoft Patents Hard-to-Mimic Gesture-Based Authentication

Posted by on 12:06 in Industry News | 0 comments

Microsoft Patents Hard-to-Mimic Gesture-Based Authentication

It’s hard to imagine the modern rhythm of everyday life without gadgets, to which we are so accustomed. The first computer could perform only a limited number of functions. Its length was about 17 meters, the height of more than 2.5 meters, it weighed 4.5 tons and covered an area of several dozen square meters. Half a century later multifunctional gadgets became a thousand times smaller in size and instantly perform tasks that the original creators of computers could not even imagine possible. Twenty years ago, mobile phones were introduced on store shelves for the first time, and now this device/gadget has become an inseparable part of everyday life. Recently, the era of smartphones began and turned mobile phones in the so-called mini-computers, the use of which makes possible to open the car, unlock the doors and carry out contactless payments without any additional devices. Smartphone – a gadget that replaced computers For example, branded smartphones authorized by MasterCard for NFC-payments MTS 965 give owners the opportunity to make payments by simply holding the phone to the payment terminal which supports the technology of wireless payments MasterCard PayPass. Only if one wants to buy expensive goods, a PIN code is required. Modern technologies allow the usage of smartphones for such important tasks as two-factor authentication, turning them into full-fledged tokens. A striking example is a free app for smartphones Protectimus SMART, which is available for iOS and Android platforms, and was created to protect accounts on the Internet websites. The app makes possible to select the algorithm for generating and creating multiple OTP tokens on one device and supports data signing function CWYS (Confirm What You See), which allows protecting the payments from the latest hacker attacks such as replacement, Automated Transfer System, data modification. However, while all the forces were thrown to the technological progress chase, little attention is paid to the critical issue of the universal mobile devices protection from unauthorized access. But if you do not take care of protecting your smartphone from unauthorized access, you can lose a lot – from the money in the bank account to personal photographs and correspondence. Authentication through fingers gestures In August 2015, Microsoft patented a new system for the authentication on electronic gadgets with touch screens through the gestures of four fingers (except the thumb) or, in other words, gesture-based authentication. To be more precise, the authorization of users would be hold with the help of secret gesture which is stored in the device memory. While making it, the system detects a number of different factors: duration of touching the screen, the force of pressing, the size of the contact area with a display, the length and arrangement of the fingers, the angles between them, and other biometric data of the person. During re-authorization, the system correlates the data with the stored user’s unique digital pattern of a gesture and allows or denies the access to the device. Microsoft claims that this technology can be used for any device, such as mobile phone, TV with the touch screen, etc. This authentication system can prove itself a reliable armor for touchscreen phones, and bundled with the app for smartphones Protectimus SMART – to minimize the risk of compromising your device to protect personal information and restrict access to your...

read more

Information Security – the Aspect You Should Not Save On

Posted by on 18:23 in Engineering, R&D | 1 comment

Information Security – the Aspect You Should Not Save On

Not so much time has passed since the meaning of the word «computer» was familiar only to employees of certain research laboratories and information security was a concern of special services. But those days are gone. Information technologies have drastically changed our lives. Using a computer, we have a rest, make friends, work, and do shopping. Very often the cost of convenience to do a lot of things, without getting up from a favorite chair, is a number of our secrets, which are available to anyone who wants to know them. Our credit card numbers, place of residence, friends and beloved ones, jobs, hobbies – all this information is available on the web. Definitely, you can simply not enter a part of the information, and thus protect it from prying eyes. But without another part which includes email addresses, card numbers, passwords we cannot even log in to many sites. Moreover, you will not be able to buy or sell things. The companies that are operating online get into an even more complicated situation: they have to keep the lists of employees and partners, and other official documents on servers that can be easily hacked. If such information is not there, the company is unable to operate properly. That is why information security has become a more important question now than ever before. Moreover, the experts on data protection are the most important employees of any modern company, along with accountants, web developers, and commercial directors. The famous idiom ‘forewarned – is forearmed’ is relevant to the field of data protection. As the threat of data loss can affect anyone, it would be beneficial to get familiar with risks and how they can be minimized.     Information security threats In short, the information security threats are divided into four main groups: Violation of the integrity – information corruption. The simplest example: the virus that penetrated the computer deletes or alters important system files, which violates or completely stops the work of the operating system. Violation of authenticity – some experts often combine this group with the previous one, and some of them consider it as a separate species of threat (and rightly so). When a user enters the desired site but gets on a phishing one, there is a clear violation of the information authenticity. Violation of accessibility – this option generally relates to failure and damage of the equipment aimed at information exchange. Not so long ago all network public was concerned about temporal Skype disconnection. Although it did not last for a long, it caused a lot of unrest. Breach of confidentiality – this is a case when data becomes available for those for who shouldn’t see it at all. Publication of stars’ personal photos is a good example. How information security can be compromised There are three main sources through which information security can be violated: Targeted attacks from the outside – the machinations of the notorious hackers. Equipment failure (in some cases, also as a result of external attacks, for example, DDoS-attack). The human factor – the negligence or deliberate damage caused by the staff itself. Based on the sources of threat, information security system is built in order to work with such groups of risk. How to provide the reliable information security While...

read more
Share This