loader from loading.io

Microsofts Newest BIG Problem -- Zero Logon plus more on this Tech Talk with Craig Peterson Podcast

Craig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity

Release Date: 10/02/2020

eSIM Exposed: Safeguarding Mobile Privacy & Combatting Hacks show art eSIM Exposed: Safeguarding Mobile Privacy & Combatting Hacks

Craig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity

  Chris's $10,000 smartphone hack is just one instance of a concerning trend of cyberattacks. Today, we're delving deep into eSIM technology, a game-changer in mobile privacy and security. Cybersecurity Concerns: The rise in hacking incidents highlights the urgent need for robust cybersecurity measures, especially in the mobile space. eSIM Technology: Exploring the intricacies of eSIMs reveals both their potential and the security challenges they present. Online Privacy: With eSIMs becoming more prevalent, understanding their impact on online privacy is crucial for users. Combatting...

info_outline
Disappear Online: Expert Tips for Digital Cleansing! show art Disappear Online: Expert Tips for Digital Cleansing!

Craig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity

  In today's digital age, our online presence can become cluttered and overwhelming, affecting not just our digital identity but also our cybersecurity and privacy. Let's delve into the expert secrets of digital cleansing to ensure a safer and more secure online journey: Understanding Digital Clutter: Learn how digital clutter impacts your life and why it's essential to tidy up your online presence. Cybersecurity Concerns: Uncover the risks posed by unchecked emails, unused accounts, and shares, and how they can compromise your cybersecurity. The Importance of Online Privacy:...

info_outline
Defend Your Digital Domain: Transforming Home Networks for Cybersecurity show art Defend Your Digital Domain: Transforming Home Networks for Cybersecurity

Craig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity

Hey there! Is your home Wi-Fi a potential cyber threat? Let’s bolster your network's defenses! Here's what you'll find in this guide: Privacy Concerns: Understand the risks associated with a vulnerable home network and the importance of safeguarding your personal information. Wi-Fi Security: Learn how to secure your home Wi-Fi network to prevent unauthorized access and protect your devices. Smart Devices: Explore the security challenges posed by smart devices and how to mitigate these risks effectively. Network Segregation: Delve into the concept of dividing your home network for...

info_outline
Unlocking the Secrets of Online Privacy: Cracking the Code to Secure Chats show art Unlocking the Secrets of Online Privacy: Cracking the Code to Secure Chats

Craig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity

Have you ever paused mid-message, wondering who might be lurking in the digital shadows? I've delved deep into the realms of online privacy, spam prevention, encryption, and the intricacies of organizing your digital life to keep your conversations secure. Join me on this thrilling journey through cyberspace as we unravel the secrets of safeguarding your chats. Here's what you'll discover in our expedition: Privacy in the Digital Age: Uncover the nuances of online privacy and learn how to navigate the digital landscape confidently. Combatting Cyber Threats: Dive into the world of...

info_outline
Defend Your Inbox: The Ultimate Plus Addressing Privacy Solution! show art Defend Your Inbox: The Ultimate Plus Addressing Privacy Solution!

Craig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity

Hey there! Ever find yourself drowning in a sea of spam emails? πŸ“§ Fret not! I've got the perfect solution to not only declutter your inbox but also fortify your online privacy and cybersecurity. πŸ›‘οΈ Introducing the ultimate guide to digital clean up, with a focus on plus addressing for enhanced privacy and organization. No more sifting through unwanted emails – this guide is your ticket to a streamlined and secure email experience. πŸ“₯ Here's what you'll find in this comprehensive guide: Privacy Reinforcement: Learn how plus addressing can act as a shield, allowing you to...

info_outline
Online Advertising Transformed: Google's Move Beyond Cookie Dependency show art Online Advertising Transformed: Google's Move Beyond Cookie Dependency

Craig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity

Hold onto your hats, tech enthusiasts! πŸŽ©πŸ’» Get ready for a seismic shift in the digital landscape as Google bids farewell to cookies, ushering in a new era where privacy is more than just wishful thinking. Say goodbye to the cookie craze! πŸͺ🚫 In my latest deep dive, "Digital Clean Up: Navigating Google's Game-Changing Shift in Online Advertising," I'm unraveling the intricacies of this groundbreaking move and what it means for all of us navigating the vast realms of the internet. πŸŒπŸ” Here's what you can expect in this enlightening journey: Advertising Evolution: Explore...

info_outline
Crack the Code: Mastering Windows Security and Digital Clean-Up Tactics show art Crack the Code: Mastering Windows Security and Digital Clean-Up Tactics

Craig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity

In the fast-paced world of technology, your Windows device needs the ultimate defense against cyber threats. I've revamped the guide, diving deep into the realms of anti-virus protection, cybersecurity, and online privacy. Here's your roadmap to a digitally clean and secure future: Windows Defender vs. Norton vs. Malwarebytes: Uncover the strengths and limitations of each superhero in the battle against cyber villains. The War Against Malware: Arm yourself with knowledge on the latest malware trends and the tools to combat them effectively. Guarding Your Cyber Fortress: Explore...

info_outline
Boost Online Privacy: A Cyber Spring Clean show art Boost Online Privacy: A Cyber Spring Clean

Craig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity

Is your digital realm resembling a messy attic? Files overflowing like forgotten knick-knacks, an inbox resembling a confetti blizzard, and social media feeds choked with digital dust bunnies? Fear not, fellow data denizens, for spring cleaning season has arrived – and this year, we're reclaiming our online peace of mind! But unlike dusting cobwebs and decluttering drawers, taming our digital wilderness requires a different arsenal. Forget brooms and vacuum cleaners – we're talking AI-powered assistants, data-detective hounds, and even a digital shredder for those long-dormant devices...

info_outline
Beyond Delete: The Ultimate Guide to Shredding Sensitive Digital Trails show art Beyond Delete: The Ultimate Guide to Shredding Sensitive Digital Trails

Craig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity

Hey there cyber enthusiasts! Ever wondered how to transform your digital space into a fortress of security? Well, buckle up, because we've crafted the ultimate guide to help you declutter, fortify, and defend your digital realm. Our mission: to make cybersecurity engaging and effective, without drowning you in techno-jargon. Check out these key points we've covered: Wi-Fi Wonders: Unveiling the mysteries of Wi-Fi security to ensure your online activities remain secure from prying eyes. Password Power: Dive into the world of password protection, unlocking the secrets to crafting...

info_outline
Securing Your Digital Realm: The Ultimate Cybersecurity First-Aid Kit Unveiled! show art Securing Your Digital Realm: The Ultimate Cybersecurity First-Aid Kit Unveiled!

Craig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity

In the vast landscape of the digital world, safeguarding your online presence is paramount. Welcome to another episode of TechTalk with Craig Peterson, where today, we unravel the secrets to fortifying your digital realm with "The Ultimate Cybersecurity First-Aid Kit." Decrypting Wi-Fi Woes Our journey begins with the cornerstone of your digital fortress: Wi-Fi encryption. No secret stays safe forever, and that includes your Wi-Fi password. We delve into the importance of encrypting your Wi-Fi, ensuring that your digital stronghold remains impenetrable. Password Party Extravaganza "abc123"...

info_outline
 
More Episodes

Craig discusses a big problem right now. This particular vulnerability is called a zero log-on vulnerability.  What that means is your computer is vulnerable to attack without the bad guy, actually having to log on to the computer. Very, very, very. Bad. Okay. Known as an escalation-of-privilege problem. Microsoft has come out and issued some patches. Apparently, it's not going to be fully fixed for a while. Thanks, Microsoft (said firmly with my tongue in my cheek!)

For more tech tips, news, and updates, visit - CraigPeterson.com

---

Traders set to don virtual reality headsets in their home offices

What's on Your Enterprise Network? You Might Be Surprised

Malware Attacks Declined But Became More Evasive in Q2

One of this year’s most severe Windows bugs is now under active exploit

The VPN is dying, long live zero trust

Shopify's Employee Data Theft Underscores Risk of Rogue Insiders

Microsoft boots apps out of Azure used by China-sponsored hackers

WannaCry Has IoT in Its Crosshairs

Love in the time of Zoom: Why we’re in the midst of a dating revolution

---

Automated Machine-Generated Transcript:

Craig Peterson: [00:00:00] We are right now under attack. This is the windows vulnerability that I mentioned live on the air here a couple of weeks ago, it's not patched up by most people and it's really, really bad.

Hey everybody, you're listening to Craig Peterson.

Well, this is a big problem right now. This particular vulnerability is called a zero log on vulnerability.  What that means is your computer is vulnerable to attack without the bad guy, actually having to log on to the computer. Very, very, very. Bad. Okay.

Now, this is an escalation-of-privilege problem. Microsoft has come out and issued some patches. Apparently, it's not going to be fully fixed for a while, from everything that I was reading.

This is crazy because what's happening is they are using domain controllers and remote procedure call login servers in order to get in. So if you're just running a regular windows machine in your house, obviously you want to keep it up to date.

But this particular exploit is against these servers that are out there. The servers specifically are those that have exposed domain controllers and remote procedure calls also called RPC login servers.

Why do you use those? Well, most businesses use those types of servers to allow people to log in remotely. Who logs in remotely? Well, its employees, right? We're there in our homes, we're trying to get into the office. So we use a domain controller. We are sending RPC calls here for the login servers. You may not know what's actually going on behind the scenes, but that's what it actually is. Now there's a search that you can do on a line. There's a couple of different searches to find. These exposed servers, very, very big binary edge.io. There's a couple of others also let you know about it, but okay. They show more than 33,000,000 million networks that are exposing domain controllers. This is absolutely crazy here.

In the event, a single network has both resources exposed, the combination can leave the network-wide open with no other requirements. Okay. It's very, very, very, very bad. I don't want to go much more into this. It is absolutely catastrophic. If you are a person who's responsible for the IT resources within a business. You have to take care of this. Right, right, right away.

The cybersecurity arm of the Department of Homeland security mandated all agencies will over the weekend. They put the mandate out on Friday and then they had to be done by Monday. They had to apply the patch by Monday night or remove the controllers from the internet. Take that as a little bit of a hint that maybe it's something you should do too.

So if you are a business owner, make sure you check with your managed security services provider and or your employees who are responsible for it. Okay. Cause it's very, very big. It's the year's most severe Windows bug that we've seen this year and who knows maybe more on the way. So I'm not going to say is the best or the worst.

Now let's move on to another subject here that I think is worthy of the news here and that is that VPNs are a risk.

Now, one of the legitimate reasons to use a VPN would be, so you don't expose those services on your server. In other words, they're not exposed to the whole internet. If they're not exposed to the internet, some guy or gal somewhere else in the world, can't get to them. So how do you let your employees get to those services and keep them locked down for everybody else?

 You could do it by having your firewall only allow certain internet addresses to get through to those services. That's what I would advise as a quick stop-gap for you. Make sure that only the home computers that are supposed to be able to get at it can get at it.

But remember too, that it is just a quick stop-gap because those home computers could be infected and could be used as a launching point to come after your services. So you're letting that home computer through your firewall to get to the RPC services, the login services they need. If that computer is infected, that home computer, it could be used now to attack you. So it's just a stop-gap.

Another way to do it is to use a VPN. Now, you know what I've been saying about VPNs for the longest time, where VPNs are, frankly, a little on the hazardous side, particularly for your security. There's a difference between privacy and security. At least if you ask me.

The biggest difference is privacy means that advertisers don't know where you go and that means your internet service provider doesn't know where you go. That's privacy.

Security is where you don't want that information sold, but even more so you don't want to have your bank account information stolen or other things that really need to be secured. Okay.

So that's a big difference here. If you get a VPN for your business so that people can connect to these log-in services, or maybe connect to your file server, that's a bit of a problem as well, because remember the VPN can be used both ways.

It's like that saying, I love this old saying, but tracers work both ways. Right?

 You use tracer rounds when you're shooting at the enemy so that you can see where the bullets are going.  By the way, that means the enemy can see where the bullets are coming from. The same thing's true with VPNs you put a VPN in place so that home users can connect to those login services or maybe your SMB CIFS here, your file servers, right, the file shares.  You open it up the VPN so they can get through, but now potentially the bad guys can use it to get through as well. So it is a big problem.

Because of that, VPNs need to be tracked very closely in your firewalls.

We run all the VPNs that we have for clients or that are requiring security. We run them all through not just a basic firewall, but one that reassembles everything. Examined all files that are being downloaded, et cetera, et cetera. Okay. That's what we do now.

There is a new technique in place right now that is gaining a lot of momentum and frankly, within the next few years, all businesses should be using this. We're doing this already and it's something called zero-trust and zero trust means in the case of a VPN. Okay, great. There's a VPN in place, but I don't trust that home computer to have full access to my network. In fact, not only mine, do I not trust it to have full access to the network, but I don't even want to have full access to this particular server.

I only want it to have web access, let's say. Even then I want to go to the next level. I want to make sure that that home computer is not being used to grab my client list. That an employee is about to take with them as they walk out the door to my competitor.

That's where you start getting into zero-trust and what that's all about. We're going to talk a little bit about that. What Gartner's predicting is going to happen here by 2023 and how you can use it and how you shouldn't be using it right now, in fact, so stick around because we'll be right back. We got a couple more segments left and of course, a bunch more to talk about, and don't forget, visit me online.

Hopefully, you got my email on Wednesday with that three-minute training. Go to Craig peterson.com/subscribe right now and make sure you get all of my newsletters.

Stick around. We'll be right back.

---

More stories and tech updates at:

www.craigpeterson.com

Don't miss an episode from Craig. Subscribe and give us a rating:

www.craigpeterson.com/itunes

Follow me on Twitter for the latest in tech at:

www.twitter.com/craigpeterson

For questions, call or text:

855-385-5553