{"id":9335,"date":"2022-04-07T12:07:23","date_gmt":"2022-04-07T00:07:23","guid":{"rendered":"https:\/\/kinetics.co.nz\/?p=9335"},"modified":"2022-04-07T12:07:23","modified_gmt":"2022-04-07T00:07:23","slug":"is-nothing-safe-fake-logins","status":"publish","type":"post","link":"https:\/\/new.kinetics.co.nz\/?p=9335","title":{"rendered":"Is nothing safe?  Fake logins!"},"content":{"rendered":"<p>[et_pb_section fb_built=&#8221;1&#8243; _builder_version=&#8221;4.16.1&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_row _builder_version=&#8221;4.16.1&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_column type=&#8221;4_4&#8243; _builder_version=&#8221;4.16.1&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_text _builder_version=&#8221;4.16.1&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;]<\/p>\n<h3>Every day, there is a new cyber-threat to watch out for, and to warn friends and colleagues about.<\/h3>\n<p>I\u2019m frequently stunned when talking to friends and colleagues that these threats are abstract and academic.<\/p>\n<p>&nbsp;<\/p>\n<h2>For the sake of absolute clarity, these cyber risks are real and face us every day. Even small kiwi businesses are targets for hackers.<\/h2>\n<p>They either want to steal your data, and blackmail you into paying them, on the off-chance that you would trust someone that is fundamentally untrustworthy, or they want to use your data as a pathway to attack someone else.<\/p>\n<p>The threat today is called \u201cBITB\u201d and that stands for \u201cBrowser in the Browser\u201d. That isn\u2019t as double-dutch as it sounds.<\/p>\n<p>What\u2019s happened is that we have become used to tools that ask us to login using our credentials from something else.<\/p>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][et_pb_row column_structure=&#8221;3_5,2_5&#8243; _builder_version=&#8221;4.16.1&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_column type=&#8221;3_5&#8243; _builder_version=&#8221;4.16.1&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_text _builder_version=&#8221;4.16.1&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;]<\/p>\n<p>You\u2019ve seen boxes like these before: (thanks LinkedIn &amp; TripAdvisor!) I\u2019m sure these are both perfectly secure, and the idea of logging in using trusted credentials from something like Google or Facebook makes perfect sense because it is less to remember, and it is better than having a simple password that you repeat across loads of sites.<\/p>\n<p>It is called SSO (Single Sign-On) and it\u2019s a huge help for most of us. In fact, these are so common that developers share their code with each other so they don\u2019t all have to reinvent the wheel and write the same modules.<\/p>\n<p>[\/et_pb_text][\/et_pb_column][et_pb_column type=&#8221;2_5&#8243; _builder_version=&#8221;4.16.1&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_image src=&#8221;http:\/\/kinetics.co.nz\/wp-content\/uploads\/2022\/04\/SSOLogins.png&#8221; title_text=&#8221;SSOLogins&#8221; align_tablet=&#8221;center&#8221; align_phone=&#8221;center&#8221; align_last_edited=&#8221;on|desktop&#8221; _builder_version=&#8221;4.16.1&#8243; _module_preset=&#8221;default&#8221; transform_scale=&#8221;104%|104%&#8221; transform_scale_tablet=&#8221;104%|104%&#8221; transform_scale_phone=&#8221;104%|104%&#8221; transform_scale_last_edited=&#8221;on|desktop&#8221; transform_translate=&#8221;7px|26px&#8221; transform_translate_tablet=&#8221;7px|26px&#8221; transform_translate_phone=&#8221;7px|26px&#8221; transform_translate_last_edited=&#8221;on|tablet&#8221; transform_translate_linked=&#8221;off&#8221; transform_rotate_tablet=&#8221;&#8221; transform_rotate_phone=&#8221;&#8221; transform_rotate_last_edited=&#8221;on|desktop&#8221; transform_skew_tablet=&#8221;&#8221; transform_skew_phone=&#8221;&#8221; transform_skew_last_edited=&#8221;on|desktop&#8221; transform_origin_tablet=&#8221;&#8221; transform_origin_phone=&#8221;&#8221; transform_origin_last_edited=&#8221;on|desktop&#8221; transform_styles_last_edited=&#8221;on|tablet&#8221; transform_styles_tablet=&#8221;&#8221; transform_styles_phone=&#8221;&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][\/et_pb_image][\/et_pb_column][\/et_pb_row][et_pb_row column_structure=&#8221;1_2,1_2&#8243; _builder_version=&#8221;4.16.1&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_column type=&#8221;1_2&#8243; _builder_version=&#8221;4.16.1&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_text _builder_version=&#8221;4.16.1&#8243; _module_preset=&#8221;default&#8221; hover_enabled=&#8221;0&#8243; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221; sticky_enabled=&#8221;0&#8243;]Unfortunately, the forces of darkness, the hackers, are starting to take advantage of our familiarity with these kinds of screens and they are creating fraudulent log in screens, even faking the URL. We haven\u2019t seen an example ourselves so the attached image is borrowed from <a href=\"https:\/\/www.techrepublic.com\/article\/browser-in-the-browser-attacks-arise\/\">TechRepublic<\/a>. You can see a distantly Eastern European flavour in this image, reflecting comments we\u2019ve made in earlier posts.<\/p>\n<p>The hackers still have to compromise a website and add their malicious code to it, then wait for you to happily login and enter your details. Alternatively, they will lure you to a fake website with a fake login screen that you will grant access to with your Google\/Facebook etc credentials.[\/et_pb_text][\/et_pb_column][et_pb_column type=&#8221;1_2&#8243; _builder_version=&#8221;4.16.1&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_image src=&#8221;http:\/\/kinetics.co.nz\/wp-content\/uploads\/2022\/04\/BITB.jpg&#8221; title_text=&#8221;BITB&#8221; _builder_version=&#8221;4.16.1&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][\/et_pb_image][\/et_pb_column][\/et_pb_row][et_pb_row _builder_version=&#8221;4.16.1&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_column type=&#8221;4_4&#8243; _builder_version=&#8221;4.16.1&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_text _builder_version=&#8221;4.16.1&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;]<\/p>\n<h2 style=\"text-align: left;\">Your first lines of cyber defence:<\/h2>\n<ul>\n<li style=\"text-align: left;\"><strong>Alert<\/strong> \u2013 be on your guard, as always<\/li>\n<li style=\"text-align: left;\"><strong>MFA<\/strong> \u2013 multi-factor authentication<\/li>\n<li style=\"text-align: left;\"><strong>Password<\/strong> <strong>manager<\/strong> \u2013 like KARE Password Vault.<\/li>\n<\/ul>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][\/et_pb_section]<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Every day, there is a new cyber-threat to watch out for, and to warn friends and colleagues about. I\u2019m frequently stunned when talking to friends and colleagues that these threats are abstract and academic. &nbsp; For the sake of absolute clarity, these cyber risks are real and face us every day. Even small kiwi businesses [&hellip;]<\/p>\n","protected":false},"author":5,"featured_media":9336,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_et_pb_use_builder":"on","_et_pb_old_content":"","_et_gb_content_width":"","footnotes":""},"categories":[4,5],"tags":[],"class_list":["post-9335","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","category-security"],"_links":{"self":[{"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/posts\/9335","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=9335"}],"version-history":[{"count":0,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/posts\/9335\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/"}],"wp:attachment":[{"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=9335"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=9335"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=9335"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}