Widespread Internet Social Media Outages Remain Unexplained
10 May 2017 San Francisco, USA. Users of popular Social Media platforms
including Facebook, WhatsApp, YouTube, QQ, WeChat, YouTube, and Sina Weibo, were
unable to connect this morning following widespread outages in the early hours of the
day (GMT +6) “Significant outages are being experienced and restoral times are
unavailable at present” stated a social media executive who asked to remain
anonymous as he was not authorized to comment on the matter.
Individual Social-Media operator’s industry-wide are declining to officially comment at
present regarding both the cause of the apparently major outages, as well as the
estimated time it will take to restore service to their tens of millions of users.
Experts have been warning for years that passwords should not be shared across
multiple platforms. The automated attacks, which are still ongoing, are said to have
taken advantage of single login and password pairs belonging to individuals to gain
access to multiple account platforms belonging to that same individual.
“Massive number of users affected” state unnamed government sources. It is estimated
that over 1 billion users are presently affected worldwide (with over 4.9 billion
individual accounts), this number is nearly 90% of all social media users globally.
A current list of affected social media sites includes Facebook, WhatsApp, YouTube,
Facebook Messenger, WeChat, QQ, Instagram, QZON, Tumblr, Twitter, Sina Weibo, and
Snap Chat among others, which represent over 90% of Social Media space on the
Internet.
The above “news release”, while entirely fictional, could very well be a foreteller of the
future. A quick survey of those around you will confirm that passwords are commonly
shared across platforms… and it is likely that only one or two folks in your immediate
circle keep a password used on all their “Social” accounts and then another different
password for their “serious” accounts such as banking logins.
Compromise of passwords on a single platform can affect that same user account on
many platforms when the same password is used, and while the larger social media
platforms have not been reporting huge break-ins (okay, a few have), many large
insurance companies and stores have. It goes without saying that once those passwords
reached the hacking community, criminals will try and use those same username/
password pairs on other account types (financial, etc.) to see if the account passwords
were shared.
What am I supposed to do about the above situation? I don’t even really
understand all the details…
-The short answer if that if you find your account on some platform (Social Media,
Banking, Municipal Payment Portal, whatever) is compromised, you should assume that
any other account where you used the same information can be or has been
compromised. If the password on your Facebook account is the same as your email
login, or your ATM password, or the password you use on the town web portal to pay
your water bill, and one of them is compromised by hackers, assume all are
compromised!
-Change all your passwords immediately
-Try to at least use a different password for social accounts (Snapchat, Facebook, email,
etc.) than the password you use for sensitive accounts such as your bank login. All
different passwords are ideal if you can manage it.
What else can I do to reduce my risk? I want to be able to use my social media
accounts…
-If possible, setup SMS Text alerts on financial accounts. (An example is setting it up so
that you receive a text message for any transaction on your account over $35.00). This
is a simple step you can take to increase your awareness if you bank offers it.
-Try to never enter a password on a webpage that is unencrypted… Most pages today
are encrypted by default.
-Keep your passwords at least 8 characters long, don’t let them be actual words (in any
language!) use special characters and numbers if possible.
-Watch your credit report and be on the watch for identity and financial theft.
-Some of my peers may disagree but I find it pointless to do monthly or even bi-
monthly password changes… every quarter is more than enough. Some accounts I
stretch to half a year. If you are changing complex passwords monthly, on multiple
accounts, you more than likely have them all written down somewhere which is not the
best practice.
I can’t remember my password if it resembles %^$bvhf(HYH
-Neither can I, and even though I am a “security” type person, it drives me nuts when some IT Nazi tries to make me… I always recommend short phrases and character substitution. Substitution like zero for the capital “O”, 3 for E, 5 for S, and 1/L/l etc. Try this example; coffee piped through the nose is redirected onto the keyboard. This is one example we came up with after telling jokes one day that were so funny, one of our group ended up with coffee on his keyboard. It looked like this: C0fFE| nO53>kbd! The trick is finding the substitutions that are easy to type-it should be easy to type… Take a short sentence, mangle it, and try it out on the keyboard and you will see what I mean. Try this as a template if you are still stuck…
I love my mother
Ilovemymother
1LoV3mYM0tHeR! (now type it quick on the keyboard… easy to type or not? Keep working at it-complex passwords are not so difficult!)
Passwords are just one area of security that we have trouble with today. Increased awareness of these individual areas will help make things more difficult for those trying to steal your credit card information or even your identity. While we may never be 100% when it comes to security, we definitely can be a bit better than we are right now!
On a recent NHPR show we tried to make it clear that while 100% security may not be attained, there is a middle ground between “that” person in IT who wants to force passwords like %^$bvhf(HYH down your throat and simply giving up at any attempt to be a bit more secure when online.
Consulting: Need independent analysis or security support? See AI & Cybersecurity Consulting.
