Retail News CRM

Tag: passwords

  • 26 million devices are infected by malware that steals bank card data including passwords

    26 million devices are infected by malware that steals bank card data including passwords

    25 million device users were targeted by a certain type of malware attack in 2023 and 2024. Infostealer malware does exactly what its name would suggest it does and grabs important information such as bank card numbers, passwords, and other sensitive data. Cyber security firm Kaspersky estimates that 2.3 million bank cards were leaked on the dark web in 2023-2024. The company says that every 14th infostealer infection ends up with the attacker scoring stolen bank card data.

    Including the 9 million devices infected by infostealers in 2024 alone, a total of 26 million have been, in the words of Kaspersky, “compromised” by such malware. While only 1% of bank cards issued globally have been leaked on the dark web, 95% of the card numbers spotted are “technically valid” according to the report. But there’s more to this type of malware that goes beyond stealing bank card account numbers.

    Kaspersky’s report goes on to state that this malware also steals credentials which is information used to verify a user’s identity. And that includes passwords. This data, along with cookies, are distributed to the dark web community. Victims can get into trouble without realizing that they are about to infect their phone, tablet, or computer. An infostealer is often disguised as legitimate software. Kaspersky’s report uses a game cheat as an example. The victim typically downloads the software and runs a malicious file.

    The malware is then spread to other devices via phishing links, malicious email attachments, infected websites, and other methods. Last year, Redline was the most widespread infostealer as it accounted for 34% of infections. The fastest growing of the infostealers was Risepro whose share of infections rose from 14% in 2023 to 23% last year. Another rapidly growing infostealer is Stealc which debuted in 2023 with a 3% share of infections. That number grew to 13% in 2024.

    Kaspersky says that if you do find yourself the victim of an infostealer, monitor your bank accounts and notifications. Have your bank card reissued and change the passwords for your bank app and website. Enable two-factor authorization and set spending limits if your bank allows you to do so. Be on the lookout for phishing attacks, fake texts, and bogus phone calls. If you’re not sure if a notification, email, or text is legit, call your bank. Kaspersky also suggests running security scans on your devices making sure to remove any detected malware.

  • 1Password boosts account security with new recovery codes feature

    1Password boosts account security with new recovery codes feature

    1Password, the popular password management app, has announced a new feature called recovery codes designed to make it easier for users to recover their accounts. This new feature is part of the company’s ongoing commitment to improve the user experience.

    The new recovery codes will allow users to regain access to their 1Password account even if they forget their master password or lose their Secret Key. Before recovery codes, if users forgot their master password or lost their Secret Key, they would be locked out of their account and unable to access their data. This caused frustration and stress for both users and 1Password support.

    With recovery codes, users can create a unique code that can be used to regain access to their account. The code can be generated from within the 1Password app for Mac, Windows, Linux, iOS, Android, or 1Password.com, and should be stored in a safe and secure location.

    Recovery codes are reusable and will remain valid after they’re used. If a user recovers their account with a recovery code, they will be asked to create a new master password and will receive a new Secret Key. The new Secret Key will be used to log in to the 1Password account on all devices.

    1Password has stressed that the introduction of recovery codes does not change the security of 1Password accounts. The company claims that the recovery process is safe and requires two separate steps to complete: email verification and the recovery code. That said, Secret Keys are not going away, and recovery codes are intended to be used only if the user forgets their master password and/or loses their Secret Key.

    Family Organizers of 1Password Families accounts will still be able to recover accounts for other family members. However, recovery codes will give family members an additional option to regain access to their accounts themselves.

    According to 1Password, millions of people trust the company with their sensitive information. As such, the introduction of recovery codes is a welcome addition to provide peace of mind to its users.

  • Are We Heading Towards Passwordless Log-In?

    Are We Heading Towards Passwordless Log-In?

    Technology is constantly evolving, and new innovation is taking place. Firstly, the users had a password to protect their accounts; multi-factor authentication was created to give an extra layer of protection. However, with time, new requirements emerged. For instance, keeping a strong password or changing the password at regular intervals which then became a matter of inconvenience. Now with new changes, we are heading towards passwordless sign-in. 

    Why Passwordless Log-In?

    Passwords once considered secure are no longer secure enough to protect different accounts. Passwords can be guessed and hacked. For instance, a laptop whose password is guessable can be operated by anyone, which can have many dangers, especially when IP addresses can be easily tracked. If you do not know the IP address of your device, use What Is My IP platform. Finding the IP address can be this easy!

     

    Also, most users do not follow any digital hygiene while creating or securing their passwords. It is common to find users one or two passwords for all the accounts simply because it is easier to remove. The downside is that if one account is compromised, all accounts are at risk. 

    Therefore, big companies like Google, Apple and Microsoft are moving towards Fast ID Online Alliance (FIDO) or passwordless sign-in, which is considered both secure and convenient for everyone, especially if it becomes industry standard. 

    The Problem With Passwords 

    Every account requires a password. An average internet user will have plenty of accounts, a few important ones like an online bank account and a few unimportant ones like a gaming account. However, the accounts’ passwords are almost similar for easy remembrance. This makes passwords extremely unsafe. 

    There are plenty of other issues with passwords. With the brute force method, it is easy to generate a common username and password combination that can compromise an account. With credential stuffing, the information available in one account can be used to compromise another account. Phishing, one of the most common ways of carrying out a cyberattack, can leak a victim’s credentials. Keylogging can capture the username and password keystrokes of the users. Hence, there are many problems, which is why passwordless log-in is in the picture now. 

    Passwordless Log-In And Its Types

    Passwordless log–in allows passwordless authentication. In other words, it can verify the identity of the user without the need of the password. There are plenty of ways through which password log-in can be supported. 

    Firstly, biometrics like fingerprint or retina scans and behavioural traits will play a key role in identifying a person without needing a password. We already have a fingerprint and face scanner that enables the user to login into a device like a laptop or a smartphone without entering a password. However, its application is not still widely used in the software. 

    A second way to support passwordless log-in is through the possession factor. In this approach, the identity can be verified with authentication of something the user carries. It can include OTP through SMS and even codes generated by a smartphone authenticator app. We mostly see its usage in multi-factor authentication. 

    Further, there is an option of running magic links to the users. In this method, the user receives a magic link in their email address through which they can access their account. 

    The Benefits Of Passwordless Log-In 

    Passwordless log-in is beneficial, especially for the users who use risky passwords for their accounts. Further, it enhances the user experience by eliminating the need to keep and remember different passwords. This increases the convenience of the users. Few of the major benefits of password-less authentication come in the form of improved user experience, strengthened security and simplification of IT operations. 

    Apple, Google And Microsoft Are Supporting FIDO 

    All three prominent companies have joined together to show their support for FIDO. With the development in this segment, it will become possible for consumers to engage in passwordless sign-ins across all platforms and devices. If implemented, the user will need to sign into different services individually, on their devices. This will also enable switching passwords. 

    With the expansion of the services, the users will further be able to sign in without passwords both in their new and old devices via FIDO. it will eliminate the need for individual login to the different accounts. FIDO is further trying to enhance the smartphone sign-in option. If the development follows the plan, the smartphone will act as a universal key for all the users’ accounts. 

     

  • Instagram introduces new security feature against hackers

    Instagram introduces new security feature against hackers

    Instagram is taking a powerful new step to combat account hacking and malicious activity on their social media platform. If you yourself haven’t experienced your Instagram account getting compromised, you probably know at least a couple of friends who have. It’s a fairly widespread phenomenon, as unpleasant as it may sound, and it’s about time something is done about it.

    As of Tuesday, Instagram is introducing a new feature on the platform called Security Checkup, which is aimed to maximize account security and facilitate recovery for anyone whose personal account may be at risk.

    No matter whether they have already been compromised or are simply vulnerable in some way, Security Checkup will prompt users to go through all the necessary steps to secure their account, which includes updating necessary profile information and account settings.

    In a recent news post, Instagram announced that “Security Checkup will guide people, whose accounts may have been hacked, through the steps needed to secure them. This includes checking login activity, reviewing profile information, confirming the accounts that share login information and updating account recovery contact information such as phone number or email.”

    Even if you haven’t necessarily been hacked, Security Checkup will prompt you to take all the important measures to ensure there is an infinitesimal chance of that ever happening in the future.

    Instagram already strongly encourages you to have two-factor authentication, which drastically decreases the chances of that and can be easily set up by going to Profile > Settings > Security > Two-factor authentication.

    With 2FA enabled, anytime there is a login attempt from an unrecognized location, you’ll be immediately alerted with the option to approve or deny the request from your personal device. Instagram also keeps track of all devices which have recently logged into your Instagram, and which can be viewed by going to Settings > Security > Login Activity. From there, you can remotely log out of any devices you don’t recognize on the list.

    You should also make sure your e-mail and phone number are the ones you are using currently, as keeping that info up to date will ensure smooth verification should any suspicious activity be detected.

    Instagram also emphasizes that one of the most common ways in which malicious parties gain entry into personal accounts is through impersonating Instagram itself, and sending out DM’s pretending they are working for the platform.

    “They may tell you that your account is at risk of being banned, that you are violating our policies around intellectual property, or that your photos are being shared elsewhere,” the post warns. These are apparently fairly common tactics scammers use in an effort to bully people into sharing their login credentials.

    Instagram stresses that it will never, ever try to contact users of the platform via Direct Messages. This means that if you see such a message claiming it’s from Instagram or asking for any personal info, you should automatically know it is malicious and immediately report the message to Instagram and block the account.

    • To report an Instagram post, tap on the three dots appearing at the top right
    • To report a message, tap and hold on it until a menu appears
    • To report an account, go to the profile and tap on the three dots at the top right

    If Instagram ever needs to contact you for any reason, rather than DM-ing you, they can reach you through an “Emails from Instagram” tab in the app’s settings. That is “the only place you will find direct and authentic communication from Instagram on the app,” the company says.

    Thanks to some new updates to the Support Inbox on Instagram, you can now easily view the status of any and all messages, posts, or accounts you have reported, and find out whether or not Instagram has taken any action. You can also keep track of your own posts’ status, to see if they are breaking any rules—and if they are, you can directly repeal them from there.

  • Apple previews tech for passwordless website sign-up using just Face ID or Touch ID

    Apple previews tech for passwordless website sign-up using just Face ID or Touch ID

    Apple is set on making things simple for its users and now, a new feature announced during a developer session will make it possible for your to sign up on websites using just Face ID or Touch ID, no passwords required.

    The developer session is part of the WWDC 2021, and introduces the new technology in order to make the user experience more intuitive while at the same time, assuring security.

    The new tech is called Passkeys and will make it possible for you to sign up for services and websites without the need for a password. Of course, the website will have to support this new tech, and when you enter your username of choice during the signup process, you will be able to use Face ID or Touch ID to authenticate yourself.

    iPhone, iPad, and Macs will have this tech in a preview coming later this year, and it will be off by default.

    Passkeys is a part of the iCloud keychain, providing a secure method for authentication and at the same time, protecting you against phishing attacks. However, if you use other devices apart from Apple ones, you may still need to use passwords.

  • Google’s latest build allows Android users to forget some passwords forever

    Google’s latest build allows Android users to forget some passwords forever

    Google announced that starting with the Pixel handsets, you can verify your identity with some Google services on the web by using your fingerprints or a screen lock instead of a password. While the Pixels will get this new feature today, over the next few days it will be pushed out to Android devices running Android 7 Nougat and higher. Using the FIDO2 standard, designed to improve authentication on the web (as opposed to on an Android app) users will only have to register their fingerprint or screen lock on their phone once to use it for a native app or the compatible Google services sites on the internet.

    Google points out to those worried about privacy, that fingerprints are never sent to Google’s servers and are stored securely on the user’s phone. Google’s servers do receive proof that you correctly scanned your fingerprint via a message that is disguised using cryptography. And you can test out how well this new system works by running a little test on your Android device. First, your device must be running Android Nougat or higher and contain your Google Account. The device must have a valid screen lock like a fingerprint scanner, a PIN or a pattern lock. Then, you follow these directions:

    • Open the Chrome browser on your device and go to  https://passwords.google.com.
    • Choose a site to view or a password to manage
    • Follow the instructions to verify that it is you signing in.

    So what is the advantage for Android users? Glad you asked. You won’t have to worry about having to remember a password when signing onto certain Google services sites on the web. That means that the part of your brain that stored these passwords can be freed up for more important things like pop culture trivia.

    “An important benefit of using FIDO2 versus interacting with the native fingerprint APIs on Android is that these biometric capabilities are now, for the first time, available on the web, allowing the same credentials be used by both native apps and web services. This means that a user only has to register their fingerprint with a service once and then the fingerprint will work for both the native application and the web service.”-Google

    There is nothing you need to do to set this up on your Android phone. So just sit back and clear your mind of some passwords that you won’t need to remember any longer.