Showing posts with label CyberSafety. Show all posts
Showing posts with label CyberSafety. Show all posts

Thursday, 23 April 2020

All about Facial Recognition Technology

Facial Recognition Technology
Srinivas Chintakindi, Manager – Technology/Products at PamTen

WHAT IS FACIAL RECOGNITION?

Facial recognition is the least intrusive and fastest-growing field of biometric technology. Biometrics, in general, is the body’s measurements and calculations – the metrics of the human body and characteristics.  The study of the body’s measurements and relationships goes back throughout humankind, but the technology to quantify it has been significantly advanced by current technology.
There are several forms of biometric technology:
  • Retinal and/or Iris scans
  • Fingerprint recognition
  • Palm scan
  • DNA matching
  • Facial Recognition
Focusing on Facial Recognition, with the latest developments in technology, systems are now able to identify a person’s face and verify who that face belongs to from any digital image.

HOW DOES IT WORK?

Facial recognition analyzes the characteristics of a person’s face through the input of a digital image. It measures the overall facial structure, including certain measurements of distance and depth that create the hills, peaks, and valleys of a face. These measurements are retained in a database as a faceprint and are compared when a user stands before the camera or sends another digital image. It is estimated that biometric facial recognition technology will soon overtake fingerprint biometrics as the most popular form of security for user authentication. Currently, Apple’s iPhone X and some Android phones include Face ID technology that lets users unlock their phone with a Faceprint mapped by the Phone’s camera.
There are a variety of facial recognition methodologies, but in general, they work by comparing selected facial features from the given image with already stored facial data within a data source. When the image is fed into the software, it maps the individual’s facial features mathematically and stores the data as a faceprint. Then the software uses machine/deep learning algorithms to compare a live capture or digital image to the stored faceprints to verify an individual’s identity.
Every face has numerous, distinguishable landmarks; the different peaks and valleys that make up unique facial features. Each human face has approximately 80 nodal points that are measured for verifications. Some of these measured by the Facial Recognition Technology are:
  • Distance between the eyes
  • Width of the nose
  • Distance between nose and lips
  • Depth of the eye sockets
  • The shape of the cheekbones
  • Eye shape
  • Skin texture
  • The length of the jaw line
These nodal points are measured creating a numerical code, the faceprint, representing the face in the database.
Have you posted a picture to Facebook and noticed that the system often automatically asks if you’d like to tag other friends that are in the picture? That’s because Facebook uses facial recognition software to tag individuals in photographs. Each time an individual is tagged in a photograph, the software stores mapping information about that person’s facial characteristics. Once enough data has been collected, the software can use that information to identify a specific individual’s face when it appears in a new photograph. As the largest social media platform in the world, it’s building quite an extensive data base of faces.

WHAT CAN IT BE USED FOR?

Facial recognition is getting more popular and being used in many commercial and governmental industries. Below are some of examples of how facial recognition is currently being used.
  • Law enforcement is using this software more frequently for a variety of reasons: to scan crowds for wanted men and women, check suspects against mug shots, and protect the nation borders. It can also be used to find missing children and victims of human trafficking. In the event of missing child or person, their image can be added to the database and security systems at public places like airports, train stations, and bus terminals that can scan the crowd continuously. It can alert the law enforcement if any matching Face is found.
  • For large events and concerts, facial recognition software can be used to identify the guests at the gate and can decide whether the person purchased the tickets for that event or not. If they did it can check-in the guest automatically.
  • Facial recognition can be used to diagnose diseases that cause detectable changes in appearance.
  • Face recognition is currently being used to instantly identify when known shoplifters, organized retail criminals, or people with a history of fraud enter retail establishments. Photographs of individuals can be matched against large databases of criminals so that loss prevention and retail security professionals can be instantly notified when a criminal that prevents a threat enters a store.
  • Dating sites match the people with similar features, because some people are most attracted to those that look like them.
  • Social media sites use this technology to tag the people automatically every time images are uploaded.
  • Casinos can use the facial recognition software to help addictive gamblers. It can also help the casinos by identifying the cheaters or advantage gamblers. It can identify members of voluntary exclusion lists and alerts the casinos. These people can cost casinos big fines if they are caught gambling. Along with casinos, bars can also use this technology to identify the underage drinkers.
  • Mobile companies can use the Face as an authentication mechanism to unlock a phone or smart mobile device. Mobile purchases can also be purchased with facial recognition.
  • Face recognition surveillance systems can instantly identify when expelled students, dangerous parents, drug dealers, or other individuals that pose a threat to school safety enter school grounds. By alerting school security guards in real-time, face recognition can reduce the risk of violent acts. In addition to making the schools/universities safer, this technology can also be used to take student attendance automatically.
  • Advertising companies can use Facial recognition technology to identify the age and gender of people by making educated guesses based on previous biometrics and provide targeted advertisements in open spaces like gas stations.
  • Face recognition can work as a means of access control to ensure that only authorized individuals get into facilities like labs, boardrooms, bank vaults, training centers for athletes, and other sensitive locations.
Facial recognition technology has many positive applications. But it also raises many questions about personal privacy and governmental and commercial intrusion. How do you feel about the growing incorporation of facial recognition technology in our lives?

Wednesday, 22 April 2020

Quick Tip to Strengthen Your Password

Cybersecurity Tip
There are certain applications and websites that you use on a regular basis. Do you cringe every time that application you are logging in to says, “Time to Change Your Password”?  Most people do. Trying to figure out a new password AND remember it is a challenge to almost everyone trying to practice better cybersecurity.
One thing you can do to help make your password more secure is to make it longer. Passwords that are only 4 or 5 characters long can be cracked by hackers in seconds. The strongest passwords are now 8 to 12 characters long and contain capital and lower case letters, numbers, and characters. If the system you’re using allows it, upwards of 15 characters provide even better protection.
If you’re worried that a longer password will be harder to remember, there are ways to overcome that and make it memorable but not easily recognizable.
For example:   I<32b@t8Ec#  That’s 11 characters long, using all the components for a strong password. How is it memorable? If you look closely it says I love to be at the beach. Memorable, but not easily recognizable.
You can also use a phrase and turn it into a password. Think of a phrase or song lyric that you can associate with the website. For example: Don’t stop believing.  If you do some substitutions and use underscores for the spaces, you can get D0n+_$tOp_b31i3viNg. That would definitely be more challenging for a hacker to crack. It’s a phrase you’ll remember and will likely remember the substitutions after a time or two.
Cybercriminals are getting smarter and their code-breaking systems are starting to recognize some of the substitutions: @ for a or at, 3 for e.  Long passwords, though, are still your best protection.
It’s also extremely important to change your password on a regular basis and do not repeat a password on a given website or across accounts.

Monday, 20 April 2020

Make Two Step Verification Part of Your Cybersecurity Routine



An extra coat helps keep you warm. A deadbolt lock on your door, along with your regular lock, makes the door harder to break into. Doesn’t it make sense to up your cybersecurity and give your personal data the same level of protection?
Two Factor Authentication (often abbreviated to 2FA) adds that extra layer of protection to your online presence.  Sites like Google, Twitter, Facebook, Apple, PayPal, and others have been using it for a long time. More and more websites and applications are adding it as an additional way to protect the information that users share with them.
Many of the apps you use frequently might have been asking you if you’d like to activate Two Factor Authentication. Don’t think of it as another annoying thing to enter, but think of the extra protection it adds. Hackers are actively looking at ways to acquire your personal data and everyone is a target.  
Entering your user name and password is one step of verifying your identity. 2FA typically comes in 3 methods:
  • Something common that you set such as a password, PIN, zip code or answer to a question
  • A code or response sent to a phone, credit card or fob
  • A biometric response, such as a fingerprint, retina, face or voice
After entering your user name and password, you’ll be asked for authentication based on the method used by the system you are logging into. The most common is a code texted to your Smartphone. That code must then be entered to gain access. Typically there is a very specific time frame to enter the information. This is important because it also limits the amount of time a cybercriminal would have to gain access.
There are several benefits to using Two Factor Authentication. It improves general security by making it harder for attackers to impersonate you. In doing so it helps reduce fraud and identity theft. This builds a more secure online relationship for businesses and consumers.
Two-factor authentication comes in various shapes and sizes with varying levels of protection.  While 2FA is an added layer of protection it is only as good as the owner’s security. If the owner shares the authentication information, misplaces the physical token, or stores the authentication information in an unsecured manner, then no two-factor authentication technology is going to be able to protect your accounts. 2FA is a great way to improve your security if you follow best practices and stay alert.
Adding extra security to your online life does require an extra step, but the protection it provides is as cozy as that extra winter coat.

Wednesday, 15 April 2020

Don’t Get Caught by a SMiShing Scam

What’s SMiShing scam?


What’s SMiSh?
People are becoming wiser and more vigilant about checking where emails are coming from, or whether that link in social media should be clicked. Unfortunately, hackers and cyber thieves are getting smarter too. The latest entry into identity and data theft is SMiShing.
SMiShing is a phishing scam using Short Message Service (SMS) text messages. With the proliferation of cell phone use, personal emailing is declining. Criminals are looking for the next open window to access information. Even if you have security on your phone like pin numbers, facial recognition, or scanners, responding to a wayward text could give the scammer an all access pass to the information on your phone.
What does SMiShing look like?
These texts can take on several different forms. They can be looking for several different responses. Have you gotten any messages like this?
“Your Gmail account has been compromised and deactivated for your protection. Text back SENDNOW in order to reactivate your account.”
“We have identified some unusual activity on your online banking. Please log in via http://bit.wi/tAkU4 to secure your account.”
“Final Notification: Your Apple ID is about to expire. Prevent this by confirming your Apple ID at http://update-apple.us”
“Your Bank Alert: Your CARD starting with 4278 has been deactivated. Contact us immediately at – 206-497-2211”
“CollegeU has a new way to connect with Alumni like you. Please reply YES to confirm, or STOP to cancel. Msgrates may vary.”
These types of texts play on your fears and take advantage of the immediacy of text messaging. At first glance, they might seem genuine. But always be cautious of messages that come uninvited or from places that you aren’t familiar with.
What Can You Do?
There are some precautions that you can take when you get a text from your bank or other numbers that are suspicious or make you concerned for your cyber security.
  • Start by taking your time. SMiShing texts count on the fast response reflex. But don’t rush to answer if you have the slightest inkling there’s something false about the email. Do the research first before responding.
  • Most banks do not text customers. Never click on a link or call a number in the text. Instead, call the customer service number on their website or on your statement. If it’s something genuine, they’ll know and be able to advise you. If it’s a scam, let the bank know you’ve received it and delete the text.
  • Do a search on the web and look up the number and message. You’ll see if there are other posts with this message or scams with the number.
  • If the message is from a legitimate company, call the company directly first. Talk to their customer service team and ask if this is a legitimate text. If they don’t know or they aren’t familiar with it, delete the text.
  • Any link in a text should meet the same criteria as an email link. If it doesn’t say https://, it’s not real.
  • Look for suspicious numbers that don’t look like real mobile phone numbers, like “5000“.These numbers link to email-to-text services, which are sometimes used by scam artists to avoid providing their actual phone numbers.
  • Don’t store your credit card or banking information on your smartphone. If the information isn’t there, thieves can’t steal it even if they do slip malware onto your phone.
Other precautions you can take to make sure your phone is secure is to have  a good antivirus program installed and turn on a Text Alias or “Block texts from the internet” feature if your service provider supports these features. Always remember to turn off Bluetooth, wi-fi, and location services if you don’t need them.
Don’t Get SMiShed – but if you do…
If you think that you are a victim of smishing, you should contact law enforcement to report the scam. You can also file a complaint with the FCC at no cost. 
Scammers and hackers are always trying to find their way into your data. Make sure you don’t give them a way in!