Wednesday, June 17, 2015

How to change your LastPass password in wake of site hack




LastPass users are advised to change their master password in the wake of a recent hack attack, especially if that master password is weaker than it should be.
On Monday, LastPass disclosed That IT WAS The Victim of A hack That Compromised email addresses, password Reminders and Other information . However, The hackers Were not Able to Access Accounts The actual users Store Where Their Website passwords, The Company Said. LastPass Uses Encryption to secure passwords so they can only be read on your indivdual Web browser. 
As a manager password, LastPass can generate passwords for each of the protected websites you use. Plugged in your browser, the software can then automatically fill in the proper password for each site, saving you the effort of having to remember and manually enter the password for the scores of sites you potentially use.
To protect and access all your passwords, LastPass requires you to set up a single master password. But what if someone obtains that master password? Though the master passwords themselves are secured with a high level of encryption and were untouched in the data breach, the hackers gained access to the clues, or reminders, used to remember those passwords. As such, the right clue could help a hacker potentially guess your master password, especially if you've used one that's particularly easy to guess.
"If you've used a weak, dictionary-based master password (eg: robert1, mustang, 123456799, password1!), Or if you used your master password as the password for other websites you need to update it," LastPass CEO Joe Siegrist Said in A blog Post Monday. 
Okay, so how do you change your master password, and are there further steps you can take to lock down your account? Let's tackle that first question.
Changing your master password
  • First, log in to The LastPass Website with your username and password.  
  • After logging in, you'll see a LastPass page with a left sidebar menu of various options. Select the option for Account Settings.
  • In the Account Settings page, look at the section for Login Credentials and click the button to Change Master Password.
  • At the Password Reset form, type your current (old) password. Type your new master password, then type it again for confirmation. Finally, type a password reminder that can help you remember your master password should you ever forget it.
Your master password should be as strong as possible to make it difficult to crack. For example, you can use a combination of alphanumeric characters with both uppercase and lowercase text. You may also want to throw in non-alphanumeric characters, including underscores or dashes. You can also use a single lengthy phrase that may be easier to remember, such as MyCatLikesToSnuggleOnMyLap. As you type your master password, LastPass visually shows you its relative strength or weakness.
  • Click the button to Save Master Password.
  • Assuming all went well, LastPass congratulates your for changing your password and offers a link for you to log back in with your new password.
  • Log in with the new password to confirm that it's working.
  • You should receive an email from LastPass confirming that your password was changed.
As Siegrist said in his blog, if you used your LastPass password on any other websites, you may want to change those as well.
Setting up multifactor authentication
Using beyond A strong password Master, are There Other Measures Can you take to secure your LastPass Better Data; Yes, you Can set up multifactor Authentication . Such Authentication Requires an Additional mode of verification in order to Access your account information. Here's how that works: 
  • Return to the LastPass Account Settings page and click the link at the top for Multifactor Options.
  • Here you can choose from a number of multifactor options both for free and premium accounts.
  • For Example, you Could Use The Google Authenticator to send A One-Time verification code to your smartphone, Which Would you Then Type AT The LastPass Website Access to your account.  
  • Click the method of authentication you wish to use and follow the instructions to set it up.
"We ALWAYS suggest using multifactor authentication for added security," a LastPass spokeswoman said in an email. "And we go without saying that we encourage folks to create strong, unique master passwords."
At this point, LastPass is also requiring users to verify their account by email when logging in from an unknown IP address or device

LastPass users with weak master passwords should change them following the recent data breach.


Monday, June 15, 2015

Encrypted connections coming soon for all Wikipedia readers


As of right now, the data that moves between Wikipedia.com and most users is unencrypted, which increases the chances that someone else may be eavesdropping on you. That, however, is about to change: On Friday, the Wikimedia Foundation announced that it’s moving its sites toward HTTPS by default, so that all data transferred between you and its servers will be encrypted.

Wikimedia says it has been working on the move toward HTTPS for all users since 2011, but that it stepped up its efforts in 2013 in the wake of government surveillance revelations. It did take the organization some time to complete its HTTPS project, however, is it needed to update its back-end systems to support encrypted connections for everyone.
Encrypted connections aren’t a guarantee against data theft—after all, they won’t necessarily keep a determined cybercriminal from trying to break into a server. But at the very least, they do help ensure that your data will at least get to the site you’re visiting without causal snoops eavesdropping on your browsing.


Tuesday, June 2, 2015



Google unifies your privacy and security settings in one spot

privacysecuritygooglehub

More than three years ago, Google unified its privacy policy. Now it's unifying your privacy (and security) information. The company recently announced an overhaul to the Google account dashboard that puts nearly every privacy and security feature in one place. The new My Account section includes Google's privacy and security checkups, the ability to mange ad settings, your search and browsing history, location history via Google Maps, and password changes. Google Wallet is still separate from the My Account dashboard.
To get to the new privacy and security hub, open Gmail or a Google search page while signed in. Then click on your account picture and select Account from the drop down menu. You can also access the new dashboard at myaccount.google.com.
The new dashboard has three major sections: sign-in & security, personal info & privacy, and account preferences. Each section has all the services you're familiar with if you've ever delved into the deep settings of your account before.
Under sign-in & security, you can do things like change your password, manage app-specific passwords and connected apps, set a recovery email address and phone number, and check how many devices are connected to your Google account.
The privacy section controls your account history, lists the Google services you use, and lets you download your personal data via Google Takeout. You can even set an account trustee to manage your account in the case of death, long-term imprisonment, or any other situation where you can't get online for an extended period of time.
Finally, you've got your account preferences to set your preferred language, manage Google Drive storage, delete your account, and so on.
This is the second major privacy announcement from Google recently. During Google I/O the company also announced that Android M, the next major version of Google's mobile operating system, would provide granular permissions for third-party apps. In addition to the new privacy hub, Google also rolled out a new FAQ site on Monday to answer privacy- and security-related questions.
The impact on you at home: With so much anxiety about the amount of data Google has on you, it's good the company is making it easier to get at that information. This will become even more important for Android M users with upcoming features like Now on Tap—Google Now context for mobile apps—that will require Google to store even more information about how you use your device, your personal information, and the content you consume.

Contributor, PCWorld





 Meet Batteriser

A $2.50 gadget that extends disposable battery life by 800 percent


   

Microsoft has set a release date for Windows 10 to arrive in the summer


Microsoft has announced that it will begin offering its newest software to power PCs and tablets as a free upgrade on July 29. Windows 10 Mobile, the company's companion software designed to power smartphones, is expected to arrive later this year. Windows 10 will be free for users who have bought a computer in the past six years or so, powered by Windows 7 or later, or tablets running Windows 8.1.
Users running Windows 7 or 8.1 with the latest updates can reserve the upgrade, which is available until July 29, 2016
Windows 10 marks the next iteration of the one of the world's most ubiquitous pieces of software. Microsoft's operating system powers a majority of personal computers and acts as the backbone of many of the world's businesses. Despite its dominance, Microsoft critics see the company and its products as a tech titan in decline, as mobile phones and competing, cheaper software have chipped away at Windows. The company's goal with Windows 10 is both to repair the damage done by the ill-received Windows 8 and to convince consumers that upgrading is worth the time and effort.

Thursday, May 28, 2015

Attackers use email spam to infect point-of-sale terminals with new malware


Cyber ​​criminals are targeting employees who browse the Web or check their email from point-of-sale (PoS) computers, a risky but unfortunately common practice.
Researchers from security firm FireEye recently came across a spam campaign that used rogue email messages masquerading as job inquiries.
The emails HAD Fake resumes Attached That Were Actually Word Documents with an Embedded Malicious Macro. If Allowed to Run, The Macro Installed A Program That Downloaded Additional malware from A Remote Server.
Among those Additional Programs, The FireEye Researchers  Identified A new Memory-scraping malware Threat That Steals PAYMENT Card Data from PoS Terminals. They've dubbed The new Threat NitlovePOS.
PoS malware HAS Become commonplace over The past FEW years and HAS LED to Some of The Largest Credit Card breaches to date. This Kind of Malicious Program WAS Used to Steal 56 Million PAYMENT Card Records from Home Depot last year and 40 Million from Target in Late 2013.
Once they are installed on PoS terminals, these programs scan the system's memory for card data while it's being passed from the card reader to the specialized merchant application-hence the term "memory-scraping." Criminals can use the stolen data to create fraudulent copies of the compromised cards.
Attackers typically Infect PoS Systems with malware by Using Stolen Or Easy-to-guess Remote Access credentials. Another method Is First to Compromise on Other Computers The SAMe as The Network Terminals and Then to Attack Them.



Organizations should educate their employees to follow best security practices, such as using POS systems for what they are intended for and not to browse the web, check email, play video games, etc., 

Offline access: Google's plan to attract the next billion users



Not everyone enjoys the constant connectivity that First World users take for granted. So, for developing countries-and, possibly, the US? -Google Said it will allow many of its apps to be accessible offline. 
"Making the world's information accessible to users everywhere has been at the heart of what Google does, right from the start," said Jen Fitzpatrick, vice president of engineering, on stage at the Google I / O developer conference keynote on Thursday. 
"More and more People are Getting A new smartphone, and for MANY of These People, BE IT Will Their very First Computer," Fitzpatrick Said. She That Just Added Six Countries, Including China, Mexico, and Brazil, Will BE Responsible for 1.2 billion smartphone sales by 2016, But MANY of Them Lack pervasive Internet Access. "These People Will Have A ProFound Impact on Mobile computing, Both as users and as creators," Fitzpatrick Continued. "So we're Thinking very carefully How we Evolve our products, and our platforms, to address their particular needs. "

Fitzpatrick Said " And Yes, There Will BE acceess offline ". "This MEANS That you'll BE Able to Save Any page you'll visit ... for Later," 

YouTube Offline:  In India, Indonesia, The Philippines, and Vietnam, Google HAS Launched YouTube Offline, users Where Can Cache A video for up to 48 hours on YouTube Their phone Without an active Internet connection.

Source