Posts

RFID explained

Image
When non-tech savvy people think about security, they may picture security cameras, guards, or even biometric security measures. Cybersecurity professionals may think of firewalls or intrusion monitoring when asked about their idea of security, and physical security is pushed to the side. Recently, I’ve been testing the physical security measures of my employer and one interesting thing I found is that RFID copying tools are available and cost as little as 20 dollars. I purchased one of these tools and began testing our RFID cards and, while it wasn’t able to copy our cards, it can be difficult to understand. RFID may not be new, but it’s a complex technology that tends to go unnoticed. Radio Frequency Identification (RFID) utilizes electromagnetic fields to track a corresponding device (card, tag, etc.). There are two main kinds of RFID tags; active and passive. Passive tags do not have their own power source, and pulls energy from the reader. Since the tag does not have its own...

NIST Cybersecurity Framework

Image
The National Institute of Standards and Technology (NIST) cybersecurity framework is a policy framework to guide users in the private sector to assess and improve their prevention, detection, and response abilities when it comes to cyber-attacks. It is primarily used in the United States, however, it has been translated to many different languages and is used by the Japanese and Israeli governments. The version 1.0 framework was originally published in 2014 to be used by managers and operates of critical infrastructure elements. Now, it is widely used by businesses and organizations to assist with becoming more proactive with risk management. Version 1.1 of the framework was drafted in 2017 and made public on April 16 th , 2018. This version included changes regarding self-assessments, interactions with stakeholders, supply chain risk management, and the vulnerability disclosure process. The core material of the NIST cybersecurity framework is divided into five main categories wh...

Explain a Technology - Self-driving Cars

Image
While attending a family reunion, the conversation went from the latest town gossip to new cars which devolved into a heated debate about self-driving cars. One of my aunts stated, “Did you hear? A few weeks ago, another person got killed in a self-driving car. How do those death machines even work?”. Of course, being the only tech person in the family, all of their questions were directed to me. After answering their questions to the best of my ability, the general consensus was that this new technology shouldn’t be trusted and was just going to result in people getting hurt. But, is this really the case? How do self-driving cars actually work and are they safe or deadly? Levels of Autonomy Self-driving cars are fully autonomous vehicles. It's important to note that most vehicles are semi-autonomous with features such as self-parking. There are several levels of autonomy which includes: Level 0: An automated system has no control but can notify the driver of hazards. Level 1...

Privacy vs. Security

Privacy and security are terms that are very similar and are often used interchangeably. Many people believe that the terms are closely related, and one cannot exist without the other, however, these terms can stand alone and have their own definitions and their own meaning when it comes to how they apply to technology. Security is one’s personal freedom from external forces that may harm the individual. Security, or being secure, is a state of being removed from a situation that has potential threats or present dangers. It refers to protective measures that are in place to protect you, your belongings, and your data from attackers, threatening events, or criminals. The goal of security is for information to maintain integrity, availability, and confidentiality. It relies on the strength of internal controls to restrict the effects of external factors. Privacy is the freedom to do as you wish without any intrusions or interruptions. It’s the ability to do as you wish without draw...

Explain a Technology - Biometric Security

When it comes to information security, there have been many methods to creating user validation. Most commonly, this is done with passwords, but they are unreliable due to the users. Passwords can be easily stolen or an attacker could guess the correct password by utilizing a brute force or dictionary attack. Users also have bad habits of setting their passwords as dates, names, or events in their lives that could easily be guessed after gathering some information about the person. To avoid these password issues, many organizations have begun to use biometric security features. Biometrics use human characteristics or traits to validate a person’s identity. There are two main categories of biometrics; behavioral and physiological. Behavioral biometrics are based on a user’s decisions and traits related to their thoughts and how they think. Examples of behavioral biometrics include signatures and voice recognition. Physiological biometrics are the most common and are related to phy...