Skip to main content

My InfoTech Journal!

My InfoTech Journal: Decoding the Networking Enigma: OSI vs. TCP/IP Reference Models

My InfoTech Journal: Decoding the Networking Enigma: OSI vs. TCP/IP Reference Models The OSI (Open Systems Interconnection) Reference Model and the TCP/IP (Transmission Control Protocol/Internet Protocol) Reference Model: The OSI Reference Model and the TCP/IP Reference Model are both conceptual frameworks used to understand and standardize how different networking protocols and technologies interact. Here are some areas of comparison: 1. Number of Layers: OSI Model : It consists of seven layers: Physical, Data Link, Network, Transport, Session, Presentation, and  TCP/IP Model : It has four layers: Network Interface, Internet, Transport, and Application. 2. L ayer Functionality: OSI Model : Tends to be more comprehensive and abstract, defining each layer's functions independently. TCP/IP Model : Reflects the actual implementation of the Internet and focuses on how protocols are used in practice. 3. Adoption / Use: OSI Model : Less commonly used in practice, but it is still valuab

Password Security: What are the Best Practices for Password Security

My InfoTech Journal:
Password Security 



This article is just a reminder on the importance of Password Security.

As we become more and more comfortable with using online services like banking, cloud drives for data repository, and other online services, we tend to be more relax and sometimes put our defences down. In most cases, we put our trust on the Service Provider’s security controls. 

We oftentimes forget or tend to ignore the fact that these service providers are usual targets by cybercriminals and may one day fall victim to data breach and data leaks. Data leaks may include your account, password, and other personal information.

We might not have control over the service provider’s security controls, but as End-Users we should at least take precautionary measures for the things we can control, most fundamental is to ensure a strong password for our accounts.




Best Practices for Password Security 

These are some best practices that can be useful to you. This article can also be a handy reference for keep your password secured. 

These best practices aims to provide some guidance on what you can do to put some fundamental security controls on your passwords. 

  • Use long passwords. 
    • Best practice is to have 12 to 15 characters for your password.
  • Use complex passwords. 
    • Complex passwords should be a combination of the following:
    • Letters (you can use upper and lower cases)
    • Numbers
    • Special Characters: !"#$%&'()*+,-./:;<=>?@[\]^_`{|}~"
  • Use easy to remember phrases. 
    • You can be creative with your password phrases.
    • Example: The quick brown fox jumped over five lazy dogs
    • Password: TqBfJ05L@zyD0g$
  • Passwords should not include personal information.
    • Personal information like, birthday, anniversary, address, phone numbers, your name or family member’s name, and other personally identifiable data. 
    • Some of these information may be in the forms you filled out on social media and possibly may already be available in public view. 
    • Hackers can easily access these information.
  • Passwords should be unique and not shared (not the same) in any other accounts.
    • If a Hacker cracked your password, then the same can be used to access your other accounts from the different service providers.
    • A Hacker can use the same login credentials to login to your bank online services, do fund transfers, and other online services.
    • Another scenario is to hack into your social media account and use your profile to solicit money from your trusting friends.
  • Passwords should not be shared with anyone. 
    • Sharing passwords with anyone exposes you to the risk of that person using your account to access your financial services portals and do transactions on your behalf.
    • Similar scenarios apply as if your account has been hacked.
  • Change passwords on a regular basis. 
    • You may already be familiar with your office account that requires you to change password on a regular schedule, so you are reminded to change passwords every so often. 
    • For those other accounts that don’t force you to change password, a good practice is to schedule this on your personal calendar so you can be reminded to change password every so often (quarterly or more frequent depends on the risk factors involved).
    • For financial online services, the best practice is to change password every month or two.
  • Do not write down your passwords on sticky notes 
    • Do not write down your passwords on sticky notes and post them under your keyboard or anywhere.
    • Dumpster-diving is a common source of information for cybercriminals.
    • Cybercriminals will do anything necessary to get into your systems.
    • They will try to get valuable information from anywhere.
    • Cybercriminals rummaging through garbage bins might one day find your sticky notes with your account and password and use this to access your systems.
  • Never use your account and password in somebody else’s computer.
    • Account and password may be stored on somebody else’s computer without your knowledge.
    • Web browsers nowadays prompts to store passwords as a default option when it detects an account and password forms. Unknowingly or as a force of habit. you might save the information on somebody else’s desktop profile.
    • I would also recommend to refrain from using your account and password in public computers like those available in coffee shops, business centres, airport computer kiosks, and similar settings. You will not know who else have used these computers and without you knowing, there may be a malware installed to gather personal information including your account and password.
    • Some computers may have key loggers that can store keystrokes including your account and passwords.
  • Precautions when using public wifi.
    • Do not access web sites or portals that require account and password when using your personal device on a public wifi.
    • There might be hackers with sniffing tools waiting for you to commit a mistake.
    • If you really need to access a site using your account and password from a public wifi, you can do so and still be secured by using a VPN tool (Virtual Private Network) to protect your session.
  • Use of Two-Factor Authentication (2FA)
    • Two-Factor Authenticate refers to another layer of authentication on top of your existing password, which requires combination with any of the following:
    • Something you know: your password or your PIN
    • Something you have: your ATM, your credit card, your security token, your mobile phone, or your email.
    • Something you are: using  biometric authentication like your fingerprint, your voice, or your face.
  • Two-Factor Authentication can also be compromised
    • Please take note and I have to say this over again, that cybercriminals will not stop until they got what they want.
    • Even if you have two-factor authentication, the second layer security can also be compromised.
    • You have to also understand what to do in case any of your two-factor authentication may have been compromised. 
    • If you lost your ATM, then you must report this immediately to your bank. Have your card revoked and replaced with a new one.
    • If your phone is lost, immediately report to your local telco provider and request for SIM card replacement. Change all passwords that are stored each application in your mobile phone and initiate to log off from all devices.
    • Review immediately any request for password change sent to your email address. Reject if you have not made any changes in your account. 


Disclaimer 

This article is a result of my personal research and is not a substitute for legal advise. 

Please consult your Legal Team, Ethics & Compliance, or Regulatory Team for the interpretation of  specific CyberSecurity requirements.





Support My InfoTech Journal








Comments

POPULAR: My InfoTech Journal

Fortifying the Digital Frontier: Unmasking Network Security Risks and Solutions

Fortifying the Digital Frontier:  Unmasking Network Security Risks and Solutions It has been a while since my last post. I have been busy with work and learning Microsoft PowerBI and Power Automate. These are very good tools for dashboard creation and automation. Very easy to learn and use. Kudos to Microsoft for coming up with these great tools! Fast forward, I have recently enrolled in a Master of Information Systems (MIS) program via Distance Education. I am excited to be an online distance education student. It has been a    very long time since I was a student. I know there will be adjustments needed from me… to be diligent, to be disciplined in balancing my work-studies-life, and to persevere to achieve my goal of getting my Master’s Degree. I have decided to share my research in  MyInfoTech Journal  hoping these information will also be able to help those researching for similar topics. Today, I am researching on the  Network Layer  and its Security Implications . The informatio

Information Security Tenets (The CIA Triad)

My InfoTech Journal:   Information Security Tenets The CIA Triad The   three tenets or fundamental principles of Information Security are  Confidentiality ,  Integrity , and  Availability .  This is also commonly known as the CIA Triad . The Information Security  programs refers to the controls designed and implemented to protect these three tenets:  Confidentiality ,  Integrity , and  Availability .   What is Confidentiality? Confidentiality ensures that private information remains private and that these private information can only be accessed or viewed by authorized individuals on need to know basis. Information Security controls must therefore be put in place to protect the data from unauthorized disclosure.  Examples of  Information Security controls  to ensure Data Confidentiality : Access Control List (ACL) Username and Password  Encryption  Two-Factor Authentication (Password, Token, PIN, Biometric, etc) What is Integrity? Integrity refers to the accuracy and completeness of t

MyInfoTechJournal: Never Let a Crisis Go to Waste: The Ultimate Business Continuity Plan (BCP) for Thriving in Any Situation (Part 3 of 3: EXAMPLE)

MyInfoTechJournal: Never Let a Crisis Go to Waste: The Ultimate Business Continuity Plan (BCP) for Thriving in Any Situation  (Part 3 of 3: EXAMPLE)

Are You Safe? The Shocking Truth About Privacy Risks and How to Protect Yourself

My InfoTech Journal: Are You Safe? The Shocking Truth About Privacy Risks and How to Protect Yourself

Network Security: How to minimize the Risk of your Wireless Network

My InfoTech Journal: What you can do to minimize the risk of your wireless network? Access Points are usually targets for unauthorized access. You have to ensure that your access points are secured to prevent unauthorized access.  There are several ways of securing your wireless access points.  Here is a Security Tip from the US CISA. Change default password. Restrict access. Encrypt the data on your network. Protect your Service Set Identifier (SSID). Install a Firewall. Maintain Anti-Virus software.I Use file sharing with caution. Keep your access point software patched and up to date. Check your internet provider’s router or router manufacturers wireless security options. Connect Using Virtual Private Network (VPN). A more detailed discussion of this tip can be found in this post:   US CISA: Security Tip (ST 005-003) Securing Wireless Networks End Notes  US CISA: Security Tip Disclaimer   This article is a result of my personal research and is not a substitute for legal advise.  Ple

Unlock the Secrets of the Top 10 Information Security Solutions and Safeguard Your Digital World!

{color: #000000; } My InfoTech Journal: Unlock the Secrets of the Top 10 Information Security Solutions and Safeguard Your Digital World!

The Ultimate Guide to Protecting Your Company's Secrets and Personal Information - Don't Get Hacked!

My InfoTech Journal: The Ultimate Guide to Protecting Your Company's Secrets and Personal Information - Don't Get Hacked!

Playbook for Conducting a Comprehensive IT Infrastructure Audit

Playbook for Conducting a Comprehensive IT Infrastructure Audit

My InfoTech Journal: Decoding the Networking Enigma: OSI vs. TCP/IP Reference Models

My InfoTech Journal: Decoding the Networking Enigma: OSI vs. TCP/IP Reference Models The OSI (Open Systems Interconnection) Reference Model and the TCP/IP (Transmission Control Protocol/Internet Protocol) Reference Model: The OSI Reference Model and the TCP/IP Reference Model are both conceptual frameworks used to understand and standardize how different networking protocols and technologies interact. Here are some areas of comparison: 1. Number of Layers: OSI Model : It consists of seven layers: Physical, Data Link, Network, Transport, Session, Presentation, and  TCP/IP Model : It has four layers: Network Interface, Internet, Transport, and Application. 2. L ayer Functionality: OSI Model : Tends to be more comprehensive and abstract, defining each layer's functions independently. TCP/IP Model : Reflects the actual implementation of the Internet and focuses on how protocols are used in practice. 3. Adoption / Use: OSI Model : Less commonly used in practice, but it is still valuab

Network Security: How to Secure Your Network

My InfoTech Journal: Network Security  To set the context of this domain, I have here several definitions from different service providers. Network Security  refers to the practices of protecting computer network from intruders, including both wired and wireless connections. - US CISA Network Security  is any activity designed to protect the usability and integrity of your network and data. It includes both hardware and software technologies. Effective network security manages access to the network. It targets a variety of threats and stops them from entering or spreading on your network. - Cisco Network Security  combines multiple layers of defenses at the edge and in the network. Each network security layer implements policies and controls. Authorized users gain access to network resources, but malicious actors are blocked from carrying out exploits and threats. - Cisco Network Security  are measures taken to protect a communications pathway from unauthorized access to, and accidenta