+ Reply to Thread
Results 1 to 1 of 1
  1. #1
    A1 VIP Member
    Join Date
    Apr 2008
    Posts
    234
    Thanks
    25
    Thanked 34 Times in 23 Posts

    Default Security in The Cloud - how to avoid getting hacked like Twitter's Evan Williams

    Twitter co-founder Evan Williams’ e-mail account getting hacked has got a lot of coverage this week. And it’s reaised a lot of questions about just how secure The Cloud, hosted business applications and Web 2.0 services are.


    I write this as the former managing director of an information security company, long time hosted applications user and founder of a Web 2.0 company — and I have to say, the biggest threat to online security is ignorance and laziness!


    First off, let’s be clear, it was not Twitter the Application that was hacked, but Twitter the Staff — it was actually Williams’ e-mail account that was hacked and that provided the hacker all he needed to then get into the Twitter company’s instance of Google Apps, giving access to the documents now in circulation. Twitter staff got targeted because they are high profile and the hacker knew the press would be interested in the story.


    How did this happen? Simple: Williams’ password was guessed. Or to put it another way, he simply didn’t set a strong enough password and has now paid the price.


    There are very obvious benefits to using web based services, not least of all in their convenience and availability. Because they are web based, so available to any member of the public, they are at greater risk that an application or data store on a stand alone server in a locked office that you need to walk over to to use; but that isn’t very convenient. Broadly speaking, the risks of attack are offset by the convenience of the services — there is risk, but it’s worth taking for the upside.


    But whether you use Cloud based applications or on-premise, it pays to follow these basic rules on password security:
    1. NEVER write your passwords down — make them easy to remember but personal to you so you don’t need to write them down
    2. Use a password system no one could ever guess. Here’s a suggestion: take the first letters of a sentence you can easily remember, e.g. Ian Watches Formula 1 Every Other Sunday would become IWF1EOS — who is ever going to guess that as a password? Factor in that the sentence could be about ANY aspect of your life and it becomes harder still for anyone to guess
    3. Never use the same password on more than one website — introduce just the smallest change between them, inspired by something about the site or service, e.g. add BA at the start or end for your online Barclays account, HO for Hotmail, WE for your WeCanDo.BIZ login etc.
    4. If you are asked to set a password reminder question, make it the most obscure option offered (things like your date of birth or mother’s maiden name may not be hard to find out) — make it something very few, if any people at all, know about you. You might even want to lie about the answer, but if you do make the answer memorable!
    If you are concerned your WeCanDo.BIZ password may not be secure enough you can reset it here.


    IH
    Ian Hendry
    Check out the A1BF Network on WeCanDo.BIZ - make your business network WORK!

  2. The Following User Says Thank You to wecando.biz For This Useful Post:

    Indizine (17-07-2009)

Similar Threads

  1. Hacked Facebook account!
    By PremierPDS in forum IT, Internet, Web Hosting and Communications
    Replies: 38
    Last Post: 27-05-2009, 19:34
  2. Flash Tag Cloud .. any good?
    By sally in forum IT, Internet, Web Hosting and Communications
    Replies: 3
    Last Post: 19-03-2009, 17:30
  3. IT Cloud Formation - the next stage for businesses and ISV?
    By MikeSierra in forum IT, Internet, Web Hosting and Communications
    Replies: 5
    Last Post: 05-01-2009, 16:49
  4. Keyword density cloud -SEO
    By AccountingBasics in forum SEO Advice and Help for Search Engine Optimisation
    Replies: 10
    Last Post: 06-10-2008, 12:28

Tags for this Thread

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
Member Controls

Our Advertisers
Side Column
Text
Text
Text
Text
-->