SlideShare ist ein Scribd-Unternehmen logo
1 von 29
Keep IT safe!
AGM Maribor
workshop
Damian Bulira
IT Committee
Identify a sensitive data
• What do you want to protect
Identify applications that you store information
in
• Where do you want to store it
Identify parties that have access to the data
• Who do you want to share it with
Secure and constrain access
• How do you want to protect it
IT security in a nutshell
AGM Maribor - Security Workshop | Damian Bulira - ESN IT Committee | damian@bulira.pl
IT security in a nutshell
Identify a sensitive data
• Personal data
• Financial data
• Photos ;)
• Password file
AGM Maribor - Security Workshop | Damian Bulira - ESN IT Committee | damian@bulira.pl
IT security in a nutshell
Identify applications that you store information
in
• Local files
• Locally stored on your hard drive
• How not to loose them?
• Mobile devices
• Laptops, smartphones, USB drives
• What if you loose them?
• Cloud services
• Google docs, Facebook, e-mail
AGM Maribor - Security Workshop | Damian Bulira - ESN IT Committee | damian@bulira.pl
Identify parties that have access to the data
• Family
• Friends
• Co-workers
• Internet provider
• Service providers
• Public
Secure and constrain access
• Access only to people that needs it
• Protect your passwords, tokens, digital IDs
AGM Maribor - Security Workshop | Damian Bulira - ESN IT Committee | damian@bulira.pl
IT security in a nutshell
How would you store and share it?
ESN case
AGM Maribor - Security Workshop | Damian Bulira - ESN IT Committee | damian@bulira.pl
Protecting local files
Password protection
• Office / OpenOffice -> embdedd function
• Password archive protection
• TrueCrypt protection
Remote copy
• Dropbox folders
• Scheduled backups
AGM Maribor - Security Workshop | Damian Bulira - ESN IT Committee | damian@bulira.pl
Backups
Avoid single point of failure
• Store sensitive data in more than 1 place
• Archive data (you never know when you want to bring
back some of it)
Dropbox, Google Drive
• Store but remember about encryption
• Easy sharing
AGM Maribor - Security Workshop | Damian Bulira - ESN IT Committee | damian@bulira.pl
AGM Maribor - Security Workshop | Damian Bulira - ESN IT Committee | damian@bulira.pl
AGM Maribor - Security Workshop | Damian Bulira - ESN IT Committee | damian@bulira.pl
CORRECT!
AGM Maribor - Security Workshop | Damian Bulira - ESN IT Committee | damian@bulira.pl
Sharing is caring
Similar stuff with Google Drive (docs)
• Even better – more detailed control
Why?
• Control over the contributors
• Someone leaves the organization
• A „black sheep” problem
• Version control – change tracking
• You share with the people that you explicitly invite
AGM Maribor - Security Workshop | Damian Bulira - ESN IT Committee | damian@bulira.pl
Mobile devices problem
Common scenario – lost smartphone:
• Stored passwords to FB, Google etc.
• All accounts and data have been took over!
• Always lock your phone – pattern lock, password
Laptop
• Hard disk fully encrypted
USB drive
• Vault partition on flash drive with sensitive data
AGM Maribor - Security Workshop | Damian Bulira - ESN IT Committee | damian@bulira.pl
Password protection
How easy is to crack your password
• Strong password policy
Never don’t share your password
• No shared accounts!
Don’t repeat the password in different
applications
• Password system
• PIN codes
AGM Maribor - Security Workshop | Damian Bulira - ESN IT Committee | damian@bulira.pl
AGM Maribor - Security Workshop | Damian Bulira - ESN IT Committee | damian@bulira.pl
How to pick a good password
Bad ideas
• Dates
• Names
• Common words
• „Pallomeri” ;)
Good ideas
• First letters of a poem, song
• P4770.m3r1
• Don’t reuse the passwords
TOP 2012
1. password
2. 123456
3. 12345678
4. abc123
5. qwerty
6. monkey
7. letmein
8. dragon
9. 111111
10. baseball
AGM Maribor - Security Workshop | Damian Bulira - ESN IT Committee | damian@bulira.pl
How to share passwords
Password shall be a private and unique
Share passwords only when it is necessary
DON’Ts
• Send whole passwords by e-mail
• Never send website, login and password together
DOs
• Share wisely – you share the responsibility
• Store passwords encrypted!
• Share passwords on a regular basis
AGM Maribor - Security Workshop | Damian Bulira - ESN IT Committee | damian@bulira.pl
The biggest EVIL!
AGM Maribor - Security Workshop | Damian Bulira - ESN IT Committee | damian@bulira.pl
Plaintext passwords
Thank you for signing up to Our Webpage, we hope that you
will have a great time here! Please click the link below to
authorise your username and password for use on the Our
site.
http://www.site.com/register.php?action=auth&email=damian@b
ulira.pl&auth=dnyhxn
***IF THIS LINK DOES NOT WORK, LOGIN AS NORMAL AND ENTER
THE DETAILS BELOW***
Your username that you used to sign up with is: dbulira
Your password you used to sign up with is: password12#
The email that you signed up with is: damian@bulira.pl
AGM Maribor - Security Workshop | Damian Bulira - ESN IT Committee | damian@bulira.pl
PGP mail encryption
AGM Maribor - Security Workshop | Damian Bulira - ESN IT Committee | damian@bulira.pl
Single Site Login
Being able to log in to any website through
existing proxy account
AGM Maribor - Security Workshop | Damian Bulira - ESN IT Committee | damian@bulira.pl
The security question
Helps with the password recovery, mostly to e-
mail boxes
Extremely important thing!
Treat it as the second password
Cool story…
http://www.foxnews.com/entertainment/2012/12/17/hollywood-hacker-honed-his-
skills-for-years/
AGM Maribor - Security Workshop | Damian Bulira - ESN IT Committee | damian@bulira.pl
Identity dependency
ESN use case ;)
• A jealous geeky boyfriend wants to spy on her
girfriend, he captures a google password (how?)
• Later on he discovers some fishy e-mails so he goes
deeper
• He changes the Google password and using lost
password feature generates a new password to
Facebook (SSO!), Twitter, etc.
• He discovers even more… :>
• Imagine what happens later…
AGM Maribor - Security Workshop | Damian Bulira - ESN IT Committee | damian@bulira.pl
Other day-to-day ESN security
cases
PC in the ESN office
• Private user accounts
• Guest account
ESN Office key access
• A case similar to password handling
• Track usage
• Access list (checked regularly)
AGM Maribor - Security Workshop | Damian Bulira - ESN IT Committee | damian@bulira.pl
Internet privacy
When you upload something to the Internet, it
stays there forever
Think before you post!
Restrict you privacy in social media
• Application access
Respect others privacy and don’t let people to
desrespect yours
AGM Maribor - Security Workshop | Damian Bulira - ESN IT Committee | damian@bulira.pl
AGM Maribor - Security Workshop | Damian Bulira - ESN IT Committee | damian@bulira.pl
Exercise
Sending credit card credentials
• You’ve forgot a credit card from your apartment and
urgently need to book a flight, fortunately your trustful
roommate can send you all the necessary data, how do
you proceed?
AGM Maribor - Security Workshop | Damian Bulira - ESN IT Committee | damian@bulira.pl
Join the IT Committee!
We always look for:
• Programmers
• Designers
• Documentation Writers
• Tutorial Makers
• System Administrators
• Linux Experts
• Drupal Developers
AGM Maribor - Security Workshop | Damian Bulira - ESN IT Committee | damian@bulira.pl
AGM Maribor - Security Workshop | Damian Bulira - ESN IT Committee | damian@bulira.pl

Weitere ähnliche Inhalte

Andere mochten auch

Knowledge transfer nbm 2013
Knowledge transfer nbm 2013Knowledge transfer nbm 2013
Knowledge transfer nbm 2013Salih Odabasi
 
Italian social erasmusweek seep12
Italian social erasmusweek seep12Italian social erasmusweek seep12
Italian social erasmusweek seep12Salih Odabasi
 
mediterranean international event
mediterranean international eventmediterranean international event
mediterranean international eventSalih Odabasi
 
Exchange ability gr seep12
Exchange ability gr seep12Exchange ability gr seep12
Exchange ability gr seep12Salih Odabasi
 
Esn greece general info for es_ners
Esn greece general info for es_nersEsn greece general info for es_ners
Esn greece general info for es_nersSalih Odabasi
 
Esn house istanbul 2009
Esn house istanbul 2009Esn house istanbul 2009
Esn house istanbul 2009Salih Odabasi
 
Esn yeditepe tanıtım
Esn yeditepe tanıtımEsn yeditepe tanıtım
Esn yeditepe tanıtımSalih Odabasi
 
Erasmus tanıtım bim
Erasmus tanıtım bimErasmus tanıtım bim
Erasmus tanıtım bimSalih Odabasi
 
Esn turkey sunumu isparta - april 2013
Esn turkey sunumu   isparta - april 2013Esn turkey sunumu   isparta - april 2013
Esn turkey sunumu isparta - april 2013Salih Odabasi
 
Section partnership seep12
Section partnership seep12Section partnership seep12
Section partnership seep12Salih Odabasi
 
Social erasmus seep11
Social erasmus seep11Social erasmus seep11
Social erasmus seep11Salih Odabasi
 
It committee agm budapest2011
It committee agm budapest2011It committee agm budapest2011
It committee agm budapest2011Salih Odabasi
 
Nbm standing orders esn finland cnr zagreb
Nbm standing orders esn finland cnr zagrebNbm standing orders esn finland cnr zagreb
Nbm standing orders esn finland cnr zagrebSalih Odabasi
 
Galaxy satellite rp 2012
Galaxy satellite rp 2012Galaxy satellite rp 2012
Galaxy satellite rp 2012Salih Odabasi
 

Andere mochten auch (20)

Knowledge transfer nbm 2013
Knowledge transfer nbm 2013Knowledge transfer nbm 2013
Knowledge transfer nbm 2013
 
Esn galaxy agm13
Esn galaxy agm13Esn galaxy agm13
Esn galaxy agm13
 
Se cs rp12
Se cs rp12Se cs rp12
Se cs rp12
 
Italian social erasmusweek seep12
Italian social erasmusweek seep12Italian social erasmusweek seep12
Italian social erasmusweek seep12
 
mediterranean international event
mediterranean international eventmediterranean international event
mediterranean international event
 
Exchange ability gr seep12
Exchange ability gr seep12Exchange ability gr seep12
Exchange ability gr seep12
 
Esn greece general info for es_ners
Esn greece general info for es_nersEsn greece general info for es_ners
Esn greece general info for es_ners
 
Esn house istanbul 2009
Esn house istanbul 2009Esn house istanbul 2009
Esn house istanbul 2009
 
Esn yeditepe tanıtım
Esn yeditepe tanıtımEsn yeditepe tanıtım
Esn yeditepe tanıtım
 
Erasmus tanıtım bim
Erasmus tanıtım bimErasmus tanıtım bim
Erasmus tanıtım bim
 
Esn tanitim 2009
Esn tanitim 2009Esn tanitim 2009
Esn tanitim 2009
 
Esn turkey sunumu isparta - april 2013
Esn turkey sunumu   isparta - april 2013Esn turkey sunumu   isparta - april 2013
Esn turkey sunumu isparta - april 2013
 
Section partnership seep12
Section partnership seep12Section partnership seep12
Section partnership seep12
 
It tools rp12
It tools rp12It tools rp12
It tools rp12
 
Social erasmus seep11
Social erasmus seep11Social erasmus seep11
Social erasmus seep11
 
It committee mar12
It committee mar12It committee mar12
It committee mar12
 
It committee agm budapest2011
It committee agm budapest2011It committee agm budapest2011
It committee agm budapest2011
 
Nbm standing orders esn finland cnr zagreb
Nbm standing orders esn finland cnr zagrebNbm standing orders esn finland cnr zagreb
Nbm standing orders esn finland cnr zagreb
 
Co meet utrecht
Co meet utrechtCo meet utrecht
Co meet utrecht
 
Galaxy satellite rp 2012
Galaxy satellite rp 2012Galaxy satellite rp 2012
Galaxy satellite rp 2012
 

Mehr von Salih Odabasi

Google Partners - Certification
Google Partners - CertificationGoogle Partners - Certification
Google Partners - CertificationSalih Odabasi
 
AGM Ankara Update_CNRKrakow20140608
AGM Ankara Update_CNRKrakow20140608AGM Ankara Update_CNRKrakow20140608
AGM Ankara Update_CNRKrakow20140608Salih Odabasi
 
Workshop how to apply for an int event-updated
Workshop   how to apply for an int event-updatedWorkshop   how to apply for an int event-updated
Workshop how to apply for an int event-updatedSalih Odabasi
 
Mediterranean international event
Mediterranean international eventMediterranean international event
Mediterranean international eventSalih Odabasi
 
mediterran international event
mediterran international eventmediterran international event
mediterran international eventSalih Odabasi
 
Responsible Party Assailly
Responsible Party AssaillyResponsible Party Assailly
Responsible Party AssaillySalih Odabasi
 
Uluslar arası etkinlikler, toplantılar, komiteler np yeditepe2011
Uluslar arası etkinlikler, toplantılar, komiteler np yeditepe2011Uluslar arası etkinlikler, toplantılar, komiteler np yeditepe2011
Uluslar arası etkinlikler, toplantılar, komiteler np yeditepe2011Salih Odabasi
 
Ulusal web projeleri update spm2012
Ulusal web projeleri update spm2012Ulusal web projeleri update spm2012
Ulusal web projeleri update spm2012Salih Odabasi
 
Treasurers session nbm12
Treasurers session nbm12Treasurers session nbm12
Treasurers session nbm12Salih Odabasi
 
Strategic priorities cnr may2012
Strategic priorities cnr may2012Strategic priorities cnr may2012
Strategic priorities cnr may2012Salih Odabasi
 
Social erasmus turkey_eesc_sept2012
Social erasmus turkey_eesc_sept2012Social erasmus turkey_eesc_sept2012
Social erasmus turkey_eesc_sept2012Salih Odabasi
 
Social erasmus esn_maribor seep12
Social erasmus esn_maribor seep12Social erasmus esn_maribor seep12
Social erasmus esn_maribor seep12Salih Odabasi
 
Social erasmus esn_bilkent_spm11
Social erasmus esn_bilkent_spm11Social erasmus esn_bilkent_spm11
Social erasmus esn_bilkent_spm11Salih Odabasi
 
Social erasmus esn_bilkent_eng
Social erasmus esn_bilkent_engSocial erasmus esn_bilkent_eng
Social erasmus esn_bilkent_engSalih Odabasi
 

Mehr von Salih Odabasi (20)

Google Partners - Certification
Google Partners - CertificationGoogle Partners - Certification
Google Partners - Certification
 
AGM Ankara Update_CNRKrakow20140608
AGM Ankara Update_CNRKrakow20140608AGM Ankara Update_CNRKrakow20140608
AGM Ankara Update_CNRKrakow20140608
 
Esn quiz
Esn quizEsn quiz
Esn quiz
 
Story r ps
Story   r psStory   r ps
Story r ps
 
Workshop how to apply for an int event-updated
Workshop   how to apply for an int event-updatedWorkshop   how to apply for an int event-updated
Workshop how to apply for an int event-updated
 
Culturalawareness
CulturalawarenessCulturalawareness
Culturalawareness
 
Mediterranean international event
Mediterranean international eventMediterranean international event
Mediterranean international event
 
mediterran international event
mediterran international eventmediterran international event
mediterran international event
 
Garagerasmus
GaragerasmusGaragerasmus
Garagerasmus
 
Responsible Party Assailly
Responsible Party AssaillyResponsible Party Assailly
Responsible Party Assailly
 
Uluslar arası etkinlikler, toplantılar, komiteler np yeditepe2011
Uluslar arası etkinlikler, toplantılar, komiteler np yeditepe2011Uluslar arası etkinlikler, toplantılar, komiteler np yeditepe2011
Uluslar arası etkinlikler, toplantılar, komiteler np yeditepe2011
 
Ulusal web projeleri update spm2012
Ulusal web projeleri update spm2012Ulusal web projeleri update spm2012
Ulusal web projeleri update spm2012
 
Treasurers session nbm12
Treasurers session nbm12Treasurers session nbm12
Treasurers session nbm12
 
To be it cnr zagreb
To be it cnr zagrebTo be it cnr zagreb
To be it cnr zagreb
 
Strategic priorities cnr may2012
Strategic priorities cnr may2012Strategic priorities cnr may2012
Strategic priorities cnr may2012
 
Squid oct12
Squid oct12Squid oct12
Squid oct12
 
Social erasmus turkey_eesc_sept2012
Social erasmus turkey_eesc_sept2012Social erasmus turkey_eesc_sept2012
Social erasmus turkey_eesc_sept2012
 
Social erasmus esn_maribor seep12
Social erasmus esn_maribor seep12Social erasmus esn_maribor seep12
Social erasmus esn_maribor seep12
 
Social erasmus esn_bilkent_spm11
Social erasmus esn_bilkent_spm11Social erasmus esn_bilkent_spm11
Social erasmus esn_bilkent_spm11
 
Social erasmus esn_bilkent_eng
Social erasmus esn_bilkent_engSocial erasmus esn_bilkent_eng
Social erasmus esn_bilkent_eng
 

Kürzlich hochgeladen

The Ultimate Guide to Choosing WordPress Pros and Cons
The Ultimate Guide to Choosing WordPress Pros and ConsThe Ultimate Guide to Choosing WordPress Pros and Cons
The Ultimate Guide to Choosing WordPress Pros and ConsPixlogix Infotech
 
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptx
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptxThe Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptx
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptxLoriGlavin3
 
How AI, OpenAI, and ChatGPT impact business and software.
How AI, OpenAI, and ChatGPT impact business and software.How AI, OpenAI, and ChatGPT impact business and software.
How AI, OpenAI, and ChatGPT impact business and software.Curtis Poe
 
DevoxxFR 2024 Reproducible Builds with Apache Maven
DevoxxFR 2024 Reproducible Builds with Apache MavenDevoxxFR 2024 Reproducible Builds with Apache Maven
DevoxxFR 2024 Reproducible Builds with Apache MavenHervé Boutemy
 
From Family Reminiscence to Scholarly Archive .
From Family Reminiscence to Scholarly Archive .From Family Reminiscence to Scholarly Archive .
From Family Reminiscence to Scholarly Archive .Alan Dix
 
"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii Soldatenko"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii SoldatenkoFwdays
 
TeamStation AI System Report LATAM IT Salaries 2024
TeamStation AI System Report LATAM IT Salaries 2024TeamStation AI System Report LATAM IT Salaries 2024
TeamStation AI System Report LATAM IT Salaries 2024Lonnie McRorey
 
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024BookNet Canada
 
Dev Dives: Streamline document processing with UiPath Studio Web
Dev Dives: Streamline document processing with UiPath Studio WebDev Dives: Streamline document processing with UiPath Studio Web
Dev Dives: Streamline document processing with UiPath Studio WebUiPathCommunity
 
The Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptx
The Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptxThe Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptx
The Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptxLoriGlavin3
 
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek SchlawackFwdays
 
Connect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck PresentationConnect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck PresentationSlibray Presentation
 
DevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platformsDevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platformsSergiu Bodiu
 
TrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data PrivacyTrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data PrivacyTrustArc
 
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptx
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptxMerck Moving Beyond Passwords: FIDO Paris Seminar.pptx
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptxLoriGlavin3
 
How to write a Business Continuity Plan
How to write a Business Continuity PlanHow to write a Business Continuity Plan
How to write a Business Continuity PlanDatabarracks
 
Take control of your SAP testing with UiPath Test Suite
Take control of your SAP testing with UiPath Test SuiteTake control of your SAP testing with UiPath Test Suite
Take control of your SAP testing with UiPath Test SuiteDianaGray10
 
Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdf
Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdfHyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdf
Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdfPrecisely
 
Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?Mattias Andersson
 
Scanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL CertsScanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL CertsRizwan Syed
 

Kürzlich hochgeladen (20)

The Ultimate Guide to Choosing WordPress Pros and Cons
The Ultimate Guide to Choosing WordPress Pros and ConsThe Ultimate Guide to Choosing WordPress Pros and Cons
The Ultimate Guide to Choosing WordPress Pros and Cons
 
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptx
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptxThe Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptx
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptx
 
How AI, OpenAI, and ChatGPT impact business and software.
How AI, OpenAI, and ChatGPT impact business and software.How AI, OpenAI, and ChatGPT impact business and software.
How AI, OpenAI, and ChatGPT impact business and software.
 
DevoxxFR 2024 Reproducible Builds with Apache Maven
DevoxxFR 2024 Reproducible Builds with Apache MavenDevoxxFR 2024 Reproducible Builds with Apache Maven
DevoxxFR 2024 Reproducible Builds with Apache Maven
 
From Family Reminiscence to Scholarly Archive .
From Family Reminiscence to Scholarly Archive .From Family Reminiscence to Scholarly Archive .
From Family Reminiscence to Scholarly Archive .
 
"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii Soldatenko"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii Soldatenko
 
TeamStation AI System Report LATAM IT Salaries 2024
TeamStation AI System Report LATAM IT Salaries 2024TeamStation AI System Report LATAM IT Salaries 2024
TeamStation AI System Report LATAM IT Salaries 2024
 
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
 
Dev Dives: Streamline document processing with UiPath Studio Web
Dev Dives: Streamline document processing with UiPath Studio WebDev Dives: Streamline document processing with UiPath Studio Web
Dev Dives: Streamline document processing with UiPath Studio Web
 
The Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptx
The Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptxThe Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptx
The Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptx
 
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
 
Connect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck PresentationConnect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck Presentation
 
DevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platformsDevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platforms
 
TrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data PrivacyTrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data Privacy
 
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptx
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptxMerck Moving Beyond Passwords: FIDO Paris Seminar.pptx
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptx
 
How to write a Business Continuity Plan
How to write a Business Continuity PlanHow to write a Business Continuity Plan
How to write a Business Continuity Plan
 
Take control of your SAP testing with UiPath Test Suite
Take control of your SAP testing with UiPath Test SuiteTake control of your SAP testing with UiPath Test Suite
Take control of your SAP testing with UiPath Test Suite
 
Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdf
Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdfHyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdf
Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdf
 
Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?
 
Scanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL CertsScanning the Internet for External Cloud Exposures via SSL Certs
Scanning the Internet for External Cloud Exposures via SSL Certs
 

Keep it safe agm13

  • 1. Keep IT safe! AGM Maribor workshop Damian Bulira IT Committee
  • 2. Identify a sensitive data • What do you want to protect Identify applications that you store information in • Where do you want to store it Identify parties that have access to the data • Who do you want to share it with Secure and constrain access • How do you want to protect it IT security in a nutshell AGM Maribor - Security Workshop | Damian Bulira - ESN IT Committee | damian@bulira.pl
  • 3. IT security in a nutshell Identify a sensitive data • Personal data • Financial data • Photos ;) • Password file AGM Maribor - Security Workshop | Damian Bulira - ESN IT Committee | damian@bulira.pl
  • 4. IT security in a nutshell Identify applications that you store information in • Local files • Locally stored on your hard drive • How not to loose them? • Mobile devices • Laptops, smartphones, USB drives • What if you loose them? • Cloud services • Google docs, Facebook, e-mail AGM Maribor - Security Workshop | Damian Bulira - ESN IT Committee | damian@bulira.pl
  • 5. Identify parties that have access to the data • Family • Friends • Co-workers • Internet provider • Service providers • Public Secure and constrain access • Access only to people that needs it • Protect your passwords, tokens, digital IDs AGM Maribor - Security Workshop | Damian Bulira - ESN IT Committee | damian@bulira.pl IT security in a nutshell
  • 6. How would you store and share it? ESN case AGM Maribor - Security Workshop | Damian Bulira - ESN IT Committee | damian@bulira.pl
  • 7. Protecting local files Password protection • Office / OpenOffice -> embdedd function • Password archive protection • TrueCrypt protection Remote copy • Dropbox folders • Scheduled backups AGM Maribor - Security Workshop | Damian Bulira - ESN IT Committee | damian@bulira.pl
  • 8. Backups Avoid single point of failure • Store sensitive data in more than 1 place • Archive data (you never know when you want to bring back some of it) Dropbox, Google Drive • Store but remember about encryption • Easy sharing AGM Maribor - Security Workshop | Damian Bulira - ESN IT Committee | damian@bulira.pl
  • 9. AGM Maribor - Security Workshop | Damian Bulira - ESN IT Committee | damian@bulira.pl
  • 10. AGM Maribor - Security Workshop | Damian Bulira - ESN IT Committee | damian@bulira.pl
  • 11. CORRECT! AGM Maribor - Security Workshop | Damian Bulira - ESN IT Committee | damian@bulira.pl
  • 12. Sharing is caring Similar stuff with Google Drive (docs) • Even better – more detailed control Why? • Control over the contributors • Someone leaves the organization • A „black sheep” problem • Version control – change tracking • You share with the people that you explicitly invite AGM Maribor - Security Workshop | Damian Bulira - ESN IT Committee | damian@bulira.pl
  • 13. Mobile devices problem Common scenario – lost smartphone: • Stored passwords to FB, Google etc. • All accounts and data have been took over! • Always lock your phone – pattern lock, password Laptop • Hard disk fully encrypted USB drive • Vault partition on flash drive with sensitive data AGM Maribor - Security Workshop | Damian Bulira - ESN IT Committee | damian@bulira.pl
  • 14. Password protection How easy is to crack your password • Strong password policy Never don’t share your password • No shared accounts! Don’t repeat the password in different applications • Password system • PIN codes AGM Maribor - Security Workshop | Damian Bulira - ESN IT Committee | damian@bulira.pl
  • 15. AGM Maribor - Security Workshop | Damian Bulira - ESN IT Committee | damian@bulira.pl
  • 16. How to pick a good password Bad ideas • Dates • Names • Common words • „Pallomeri” ;) Good ideas • First letters of a poem, song • P4770.m3r1 • Don’t reuse the passwords TOP 2012 1. password 2. 123456 3. 12345678 4. abc123 5. qwerty 6. monkey 7. letmein 8. dragon 9. 111111 10. baseball AGM Maribor - Security Workshop | Damian Bulira - ESN IT Committee | damian@bulira.pl
  • 17. How to share passwords Password shall be a private and unique Share passwords only when it is necessary DON’Ts • Send whole passwords by e-mail • Never send website, login and password together DOs • Share wisely – you share the responsibility • Store passwords encrypted! • Share passwords on a regular basis AGM Maribor - Security Workshop | Damian Bulira - ESN IT Committee | damian@bulira.pl
  • 18. The biggest EVIL! AGM Maribor - Security Workshop | Damian Bulira - ESN IT Committee | damian@bulira.pl
  • 19. Plaintext passwords Thank you for signing up to Our Webpage, we hope that you will have a great time here! Please click the link below to authorise your username and password for use on the Our site. http://www.site.com/register.php?action=auth&email=damian@b ulira.pl&auth=dnyhxn ***IF THIS LINK DOES NOT WORK, LOGIN AS NORMAL AND ENTER THE DETAILS BELOW*** Your username that you used to sign up with is: dbulira Your password you used to sign up with is: password12# The email that you signed up with is: damian@bulira.pl AGM Maribor - Security Workshop | Damian Bulira - ESN IT Committee | damian@bulira.pl
  • 20. PGP mail encryption AGM Maribor - Security Workshop | Damian Bulira - ESN IT Committee | damian@bulira.pl
  • 21. Single Site Login Being able to log in to any website through existing proxy account AGM Maribor - Security Workshop | Damian Bulira - ESN IT Committee | damian@bulira.pl
  • 22. The security question Helps with the password recovery, mostly to e- mail boxes Extremely important thing! Treat it as the second password Cool story… http://www.foxnews.com/entertainment/2012/12/17/hollywood-hacker-honed-his- skills-for-years/ AGM Maribor - Security Workshop | Damian Bulira - ESN IT Committee | damian@bulira.pl
  • 23. Identity dependency ESN use case ;) • A jealous geeky boyfriend wants to spy on her girfriend, he captures a google password (how?) • Later on he discovers some fishy e-mails so he goes deeper • He changes the Google password and using lost password feature generates a new password to Facebook (SSO!), Twitter, etc. • He discovers even more… :> • Imagine what happens later… AGM Maribor - Security Workshop | Damian Bulira - ESN IT Committee | damian@bulira.pl
  • 24. Other day-to-day ESN security cases PC in the ESN office • Private user accounts • Guest account ESN Office key access • A case similar to password handling • Track usage • Access list (checked regularly) AGM Maribor - Security Workshop | Damian Bulira - ESN IT Committee | damian@bulira.pl
  • 25. Internet privacy When you upload something to the Internet, it stays there forever Think before you post! Restrict you privacy in social media • Application access Respect others privacy and don’t let people to desrespect yours AGM Maribor - Security Workshop | Damian Bulira - ESN IT Committee | damian@bulira.pl
  • 26. AGM Maribor - Security Workshop | Damian Bulira - ESN IT Committee | damian@bulira.pl
  • 27. Exercise Sending credit card credentials • You’ve forgot a credit card from your apartment and urgently need to book a flight, fortunately your trustful roommate can send you all the necessary data, how do you proceed? AGM Maribor - Security Workshop | Damian Bulira - ESN IT Committee | damian@bulira.pl
  • 28. Join the IT Committee! We always look for: • Programmers • Designers • Documentation Writers • Tutorial Makers • System Administrators • Linux Experts • Drupal Developers AGM Maribor - Security Workshop | Damian Bulira - ESN IT Committee | damian@bulira.pl
  • 29. AGM Maribor - Security Workshop | Damian Bulira - ESN IT Committee | damian@bulira.pl