Tag Archives: security

Phishing Awareness

Cypher Security stock image

We would like to remind everyone to remain vigilant against phishing emails, which are becoming increasingly sophisticated and pose serious risks.

Key Risks to Watch Out For:

* Urgent Requests: Be cautious of emails that create a false sense of urgency, pressuring you to take immediate action.
* Credential Theft: Avoid entering usernames or passwords in response to unsolicited emails or suspicious links.
* Account Security: Configure and enable Two-Factor Authentication (2FA) to add an extra layer of protection against attacks.

Tips to Stay Safe:
1. Verify the sender before clicking on any links or attachments.
2. Look for unusual language, spelling errors, or unexpected requests.
3. Mark any suspicious emails as Junk or Delete them immediately
4. Do verify with the sender that they have sent an email by using a known telephone number but DO NOT reply back to the email you have received

The below is information from Action Fraud

How to report suspicious emails and text messages:

If you’ve received an email or text message that doesn’t feel right, STOP!

– break the contact – don’t reply, click on any links, call any phone numbers or make any payments
– check if it’s genuine: contact the organisation directly using an email address or phone number you know is correct, e.g. from your utility bills, via a search engine, on the back of your card or by calling 159 for banks
– Report suspicious emails by forwarding them to: report@phishing.gov.uk
– Report suspicious text messages by forwarding them to: 7726 (it’s free of charge)

How to report suspicious phone calls:

If you’ve received a phone call that doesn’t feel right, STOP!
– hang up
– check if it’s genuine: contact the organisation directly using contact details you know are correct, such as those on a utility bill, official website, the back of your card or by calling 159 for your bank
– don’t trust the Caller ID display on your phone – it’s not proof of ID
– report it by sending a text to 7726 with the word ‘Call’ followed by the scam caller’s number

If you have been a victim of cyber crime or fraud, tell the police at www.reportfraud.police.uk.

Remember, staying alert is the first line of defence against cyber threats.

Migrating to Ente Auth – Export TOTP tokens from Authy

Authy Logo

I’ve recently had to migrate all my 2FA codes (TOTP tokens) from Authy.  For those that don’t know, Authy had a breach (here, and here)  a while ago, and since then seemingly put a stop to development of their desktop apps, and also migrating and /or syncing newly added tokens. They were essentially taking our tokens hostage. It became a bit of a precarious situation, as the only app that would still work was the mobile app, but at the same time it wouldn’t let you download and configure the new app on another device (I don’t think…) or have tokens backed up and syncing across multiple devices.

The primary reason for me to use Authy before was so that I could access my 2FA codes from multiple computers and mobile devices. Without this functionality, it was pretty pointless.  Even when they ended their native support of the desktop apps, you could still run the iPad version on Apple Silicone until they blocked that too. A real shame!

I had a couple of options to get round this.

1. Reset all my 2FA sessions and generate new tokens all over. This is a pain as I had well over 20 and this would take some time.

2. Find a way of exporting the tokens using various methods worked on in the open source community. These involve many technical steps but the processes are documented. They involve man in the middle snooping and Python scripts. All in all, a bit of fun.  I’m technically minded so no problem!

I had done some research and found Ente to be a great open-source alternative to migrate to.  The new solution also features end to end encrypted backup, as well as multi-platform and device support.

Ente Logo

The migration itself took some time and some prior preparation.

The steps I followed are on the following GitHub Gist – https://gist.github.com/gboudreau/94bb0c11a6209c82418d01a59d958c93

Not every scenario will work for you, so read the documentation fully.

The exact steps I followed are these: https://gist.github.com/gboudreau/94bb0c11a6209c82418d01a59d958c93?permalink_comment_id=5298931#gistcomment-5298931

Since I followed the steps, there has been a revised and simplified version, which I would probably recommend you follow instead: https://github.com/BrenoFariasdaSilva/Authy-iOS-MiTM

All in all this was an interesting experience, which allowed me to learn something new, play with Python, and man in the middle proxy, to catch data being transferred and intercepting it. The software MITMProxy, can be used for a multitude of other things.  Something to write about another day!

Ente also develop an alternative to Apple Photos or Google Photos, worth checking out if you’re not a fan of either.

2FA – Secure your accounts now!

2FA generic image

Following on from some recent work undertaken, it’s worth posting a little reminder that a simple account password is no longer sufficient to secure your most important accounts.

It’s always a good idea to check and secure your passwords from time to time. Some simple steps to assist with this are listed below:

1. Do not use simple passwords, shorter than 8 characters. Try and use special characters where possible, and lower and upper case characters too.

2. Do not use family names, pets names, dates of birth, or anything that could be pinpointed to your place of residence.

3. Use a 2 factor authentication (2FA) solution where you have the option to. A good introduction to this can be viewed here: https://go.frantik.it/2intro

For further assistance with account security or online safety, please take a look at the Frantik web site and get in touch!

You can also sign up for our Newsletter where we’ll occasionally share important updates such as this. You can sign up here.

To help remember longer and harder to remember passwords, we would also recommend  using a password vault. We wrote a post on that recently: Time to get a Password Manager – 1Password tested!

Thanks for reading 🙂

Why you shouldn’t pay for PC security

We are firm believers that you shouldn’t have to pay for antivirus security for your PC or Mac.

If the manufacturers of the operating system have left it vulnerable in any way then they should be the ones that pay or there should be free alternatives. So, without further a do, here is some great free software you can use to keep your computer secure.

With Mac, viruses aren’t so much the issue as is malware, this is generally due to the way the OS is developed (and based on Unix).

PC:

For a little while now Microsoft have provided free software in the form of Microsoft Security Essentials, and now Windows Defender, which is built in and updates when Windows updates. So cancel your annual Anti-virus subs and download this instead!

Link: http://go.frantik.it/mse

Note; this is for Windows 7. If you have 8 or newer it’s built in and you don’t need to worry.

Mac: We have provided links to a couple of great AV packages for Mac previously! See the following: Free Antivirus For Mac

On checking these are probably still on top. Don’t hang around and test either today!

Alternatives:

We always recommend using Malwarebytes Free too to use in addition to the above and this can be used once a week or month just to make sure your computer is protected.

Link:  http://go.frantik.it/mbam

 

Remain vigilant about Malware!

malware

Many people get so used to being warned about suspicious files they may receive via email that they become bored with it. I know that we almost get too curious about certain things sent to us, or links that crop up on social media.

It is important to remember though, that if you don’t recognise the sender, or web site you are about to visit, it’s probably best not to click on such links. This is in the same way you’d do with junk mail sent through your letterbox in that you’d probably bin it straight away… you have to do the same thing with digital media. Take a step back before clicking or opening anything and think twice beforehand.

Unfortunately, Windows systems are still more frequently targeted compared with Mac or Linux but that doesn’t mean we should be any less vigilant!

Get yourself protected by downloading antivirus protection; see the following page for more info!

And if in doubt trash it, don’t open the attachment, or click on the link. If it’s really important the sender will contact you again.