Welcome to Week 2 of Cyber Month. This week we’ll be focused on a rapidly evolving area of cyber security: Identity and authentication.
Why are we talking about identity and authentication? You’ve got my username and password, right? What else do you need? Well, consider:
- Your digital identity is an online record of your personal information, be it something as simple as your email address or as sensitive as your SIN. Your identity says a lot about you, so you need to protect it.
- 80% of cyber breaches are identity-driven. The criminals want access to your identity so that they can impersonate you, raid your bank accounts, tax accounts, etc.
- As we saw in our look at phishing, cyber criminals are most often trying to steal your username (identity) and password (authentication).
- Use of your digital identity is becoming more widespread. Just think about how many sites /services allow you to log in with your Facebook or LinkedIn credentials. Just a few years ago that would have been unheard of.
Bottom line: you need to protect your digital identity.
How? Let’s start with the basics:
Passphrases, not Passwords
Using Passphrases
We’ve got a great video on the basics of using passphrases – here’s the link: |
|
| Credential Stuffing Attacks
Protecting yourself Cybersecurity journalist Kerry Tomlinson has an informative video on Credential Stuffing, with tips on how to protect yourself – check it out: https://www.youtube.com/watch?v=g_RVoNvx-9Y (2 min)
|
|
| Is my passphrase secure?
Good question! Yes, it’s very possible that the passphrase you come up with has been compromised in a data breach. So, how do you check it?
HIBP searches for compromised user data being sold on the internet and catalogues it in searchable databases. You can:
|
|
Next time, we look at Multi-factor Authentication (aka “MFA”), new to us here at RRU, and how the cyber criminals will try to bypass MFA.
As with all of our cybersecurity awareness materials, you are welcome to share this email with family and friends.
REMEMBER: STOP! THINK! CONNECT.
Leave a Reply