Tag: 2FA

  • STEPS TO SECURE YOUR WHATSAPP

    STEPS TO SECURE YOUR WHATSAPP

    WhatsApp Hijacking

    This is when malicious actors gain control of your WhatsApp account. This is a huge deal as the ubiquitous nature of the Metaverse (META’s ecosystem – Facebook, Instagram, WhatsApp) means a lot of our private information are shared on the platforms in text, images, audio and video formats. When compromised, it can have real damaging consequences. It becomes imperative to harden your defenses against unauthorized access. Portability and ease of access of technology, is also its biggest drawback.

    The following steps will help you add another layer of security to your personal information.

    • Ensure that you have activated 2FA on your WhatsApp, and you have added your email address to your WhatsApp account and verified it.
    • DO NOT share any code received via SMS or via WhatsApp with anyone, regardless of who they may be or what their intentions may be.
    • Be cautious of clicking on links promising giveaways or other mouth-watering, juicy deals. They are almost always phishing links that bad actors employ to spread malware with which they can steal your data.
    • If you didn’t apply for any grant, or competition, be wary of calls, text messages and broadcasts informing you of winnings and requiring you to fill out this or that to claim your prize.

    These apply to all your social accounts, including emails, messenger apps, and so on.

    As much as possible, do not re-use passwords across different services. If a service falls victim to hackers, usually, all the subscribers on that service will have their data compromised, including but not limited to passwords. These passwords are usually dumped on the Dark Web, and bad actors can then include those passwords in their hacking software, which can come in handy when they try to gain access to your online accounts. 2FA would be a worthy acquaintance in these kinds of situations.

  • HOW TO SECURE YOUR DATA

    HOW TO SECURE YOUR DATA

    1.   PASSWORDS

    Passwords are the first line of defense against unauthorized access to your data. You would be remiss to have your date of birth, your child’s name, your wedding date, or any other publicly available information about yourself as your password. Passwords must be complex to raise the level of difficulty for bad actors. A good password would comprise of upper- and lower-case alphabet, numbers, and special characters. You can use mnemonics to remember complex passwords. You can use passphrase instead of just a single word—yes, type the full sentence, with the space and punctuation. Some online services have character limits as part of their password requirements.

    Useful Links

    How Secure Is My Password – https://www.security.org/how-secure-is-my-password/

    Password Generator – https://passwordsgenerator.net

    2.   2FA (Second-Factor Authentication)

    This is an added layer of security in protecting your data, and it involves a random string of numbers that have been programmed to work with only your account and is generated every 30 seconds and expires at the end of the countdown. If your password gets compromised, the 2FA was introduced to keep out unauthorized access. Please note that if you lose your 2FA key, even you would not be able to access your data. You can use your phone number as 2FA via SMS or Phone call, you can also use any of the authenticator apps available on the mobile app stores.

    Useful Links

    Google Authenticator – https://play.google.com/store/apps/details?id=com.google.android.apps.authenticator2&hl=en

    https://apps.apple.com/us/app/google-authenticator/id388497605

    3.   OTP (One-Time Password)

    When signing up for a digital service or account, and you enter your email address or phone number, you would usually get an OTP (one-time password) which is basically a way for the service to verify that you are the owner of the email address or phone number, or at the very least, that the said credential is operational. Sometimes, when you need to make changes to the same accounts, an OTP is generated to be sure you are the one initiating the changes. DO NOT SHARE any OTP Code that comes into your phone or email with a third-party, especially if you did not initiate the said changes.

    4.   ENCRYPTION

    If you or your organization work with sensitive data, you should take encryption of all your data as priority. This involves rendering all data unreadable for anyone who does not possess the decryption key (think of it as a more complex password, usually a very long and random string of characters). If your computer or mobile device falls into unauthorized hands, the data on the devices will be useless as they can’t be read without a decryption key. Setting up a policy to ensure compliance in your organization would go a long way in keeping bad actors at bay, as there is a great benefit employing defense in depth.

    5.   SECURITY SOFTWARE

    Another layer in securing your data is security software, and these comprises of Internet Security, Anti-virus, Anti-Malware, Anti-Spyware, and Anti-Ransomware software. They all seek to address various aspects of bad actors’ point of attack on your devices and ultimately your data. Investing in the right security software to add another layer of protection for your data is good practice.