07/11/2022
Reduce phishing attack effectiveness
This is a subset of the human factor. A phishing email is a legitimate looking email, often from a seemingly trusted source, but it cons you into sending personal information or it contains a malicious link or file. The most endorsed advice from the security seminar I attended was to never click on a link from an unsolicited email or message. Even the savviest people fall for them. Have your company set up an email inbox rule that only allows known senders. It will still tell you when you receive one from an unknown sender, but you’ll be more aware of a possible phishing attempt.
Hash and season your passwords
Most websites and databases store your passwords as hashed passwords, which is different from encryption. A hashed password is like a baked cake and the password is like the cake recipe. With just the baked cake, you can’t determine the exact recipe. But with the recipe, you can bake the same cake.
So, if a website stored your recipe, someone who breached the website could steal your recipe and pretend to be you. But if the website stores your baked cake, then they don’t know your recipe. To verify it’s you, the website asks your computer to bake your recipe before sending it to the website. The website then compares the freshly baked cake to the one they have in storage. If they taste the same, then they know it’s you, all without knowing your password. It should be noted that no amount of baking can save a weak password.
A secure website is one that does not know their users’ passwords. However, with modern hacking tools, just hashing a password is no longer acceptable, as common passwords are cracked instantly. In microseconds. The best solution is to have the website put some seasoning on your cake. If the seasoned cake is stolen, it’s even harder for the thief to determine the actual recipe because they can’t separate the seasoning from the cake. The simplest and most effective form of seasoning is called a salt. Ask your IT team to check you are hashing and salting your passwords. It’s a simple concept, but ensure you give them enough time to implement it securely.