Category Archives: Cyber Security

Security best practice, patterns & architecture links from AWS, GCP & Azure – Part 1

Herewith I am providing a curated list of links for security best practices, patterns & architecture for AWS, GCP & Azure – Part 1.

AWS:

GCP:

AZURE:

Also, check out security as code products like oak9:

Email me: Neil@HarwaniSystems.in

Cyber Security Keywords & Concepts – Part 1

Here is a list of keywords & concepts in Cyber Security that technology professionals should be aware of. This is part 1 of the series.

  • CSP
  • XSS
  • ISO 27001
  • OWASP
  • Encoding / decoding
  • Encryption and it’s types
  • CSRF
  • CORS
  • Hashing
  • Authentication
  • Authorization
  • IAM
  • SSO
  • SAML
  • OAuth
  • Tokens
  • HTTPS / SSL
  • DOS / DDOS
  • Backdoor
  • Malware
  • Secure coding
  • Threats, Vulnerabilities, Controls & Mitigation
  • VAPT
  • Social Engineering
  • Spoofing
  • Proxy servers
  • Phishing
  • SQL injection
  • Buffer overflow
  • Viruses, Worms, Keyloggers, Spywares
  • Identity theft
  • RootKits
  • Zero Day
  • VPN / Firewall / IPS / UTM
  • Digital Certificates
  • Anti-Virus

References:

  • https://en.wikipedia.org/wiki/Cybersecurity_information_technology_list
  • https://en.wikipedia.org/wiki/Computer_security
  • https://en.wikipedia.org/wiki/List_of_computer_security_certifications

Security tips for Google Drive & Android

Google Drive:

  • Open Google Drive on web based browser like Chrome
  • On each of the folders if you see a person symbol it’s shared, if you don’t see the symbol its not shared
  • For each folder -> click SHARE -> Advanced -> Check which user has view rights and which user has edit rights -> Disable options to download, print, and copy for commenters and viewers -> Prevent editors from changing access and adding new people.
  • For each folder -> click SHARE -> Advanced -> SHARE SETTINGS -> Change -> Check settings there are 4 to 5 options
  • Note -> Even if your folder is not shared, files inside it can be in shared mode – This seems to be a big missing feature in Google Drive. There is no clear way to check this in one go for all files and we individually need to check each file. Workaround: Write Java code using Google Developers API to check this: https://developers.google.com/drive/

Android security settings to explore:

  • Emergency info – Settings -> Users -> Emergency info -> INFO & CONTACT – Note: Can be seen on locked screen
  • Settings -> Security -> Screen Lock
  • Encryption ON – at-least Android 6 required, by default it’s on from 6/7 onward – Settings -> Security
  • Settings -> Security -> Screen Lock -> Gear button -> Lock message
  • Security -> Install from unknown locations -> Should be OFF
  • Settings -> Users -> Guest user -> Turn on phone calls -> OFF
  • Settings -> Users -> Add users while screen is locked -> OFF
  • Settings -> Security -> Make password visible -> OFF
  • Settings -> Security -> Set up SIM card lock

Information security tips while working with digital sources and internet

  • Setup OTP and recovery emails for all your accounts
  • Check permissions that various apps have on your phone
  • When you get an option – TRUST THIS DEVICE in Gmail or similar accounts, only select this option on your personal devices not public devices
  • Keep your desktop, laptop & mobiles password protected & encrypted if possible
  • Use standard Anti-Virus like McAfee, Windows Defender, Symantec, Norton, etc. Note: Android phones also have anti-virus
  • Explore and use a good VPN service
  • Go to your ACCOUNT settings regularly in Linkedin, Facebook, Gmail, etc. and see the logged in sessions (Who is using your account) and check which apps are integrated with your account, what information they are taking out – typically they take your friend’s list / relatives, age, email, phone number, etc.
  • Learn to backup your data in Cloud or external Hard Disk or both
  • Setup locate your phone, remote wipe, virus scan, link check, capture pic on wrong password attempts, etc. especially on Android via Anti-Virus or other means.
  • Update your devices across laptop, desktop and mobiles regularly using the official update process
  • Do not root your mobile devices
  • In Android don’t switch on the feature to TRUST UNKNOWN APPS to install APKs. Always install APPs from Android Play Store and Apple App Store only
  • Keep Bluetooth, WIFI, NFC off when not in use
  • When you leave your home switch off your WIFI
  • Change your passwords of WIFI, emails, accounts once in 6 months at-least. Your WIFI at home via router should be on encrypted network not non-encrypted, check the ADMIN page. Change the ADMIN password of your router at home, mostly many don’t change the username/password from admin/admin which is an easy entry point for wrong use. Update your router software also regularly via the official update option
  • For storing your passwords either use a diary / notebook OR there are encrypted software like password managers / wallets which store your passwords safely as an APP in your mobile – use them. See their ratings in PLAY STORE / APP STORE and then install or use. Don’t store passwords in plain text on computer or mobile.
  • Don’t keep same passwords across all your accounts – if you do so and one gets compromised all others get compromised