Walmart denies hack occurred

14,600 emails addresses and passwords posted – Walmart denies hack occurred

Walmart denies hack occurred
Incident Communication Plan

Walmart denies hack occurred after email address and passwords were posted.   – Over 14,600 email addresses and plain-text passwords associated with Sam’s Club’s online store were dumped on Pastebin, a text sharing site. Walmart denied a hack occurred.

The title of the password dump said that the accounts listed belonged to the retail giant. The company which has over 650 locations across the US and tens of millions of members.

Walmart said “.. looked into this issue and there is no indication of a breach of our systems. It is most likely a result of one of the past breaches of other companies’ systems. Because customers often use the same usernames and passwords on various sites, bad actors will typically test the credentials they obtain across many popular sites. Unfortunately, this is an industry-wide issue,” said a Walmart spokesperson.

Order PolicySample Policy

That is no way to inspire confidence in the security of an enterprise’s website.

To survive an incident such as a business interruption, security breach, or a product recall, organizations need more than a successful communication strategy – they need an incident communication plan.

The overall objectives of a incident communications plan should be established at the outset. The objectives should be agreed upon, well understood, and publicized. For example, will the primary objective of the communications plan be for communications only to employees, and only during a disaster? Or is the intent to advise customers of interruptions to service? Or is it for investors and stockholders? Or regulatory agencies? Or is it some combination of these?

Top 10 Technology Travel Tips – International

Top 10 Technology Travel Tips – International

Travel, Electronic, and Off-Site Meeting Policy
Top 10 Travel Tips

Top 10 Technology Travel Tips – When people traveling, especially internationally, not only is technology at risk but also sensitive personal and work information.  Below are 10 tips taken from Janco’s Travel, Electronic, and Off-Site Meeting Policy.

  1. If it’s not necessary, don’t travel with a computer or tablet.
  2. Whenever possible, arrange to use loaner laptops and handheld devices while traveling.
  3. If you are bringing a laptop with you, make sure you have the proper plug adapter.
  4. Install a host-based firewall, and configure it to deny all inbound connections.
  5. Disable file, printer sharing, and Bluetooth. Apply full disk encryption, picking a long, complex password
  6. Update all software immediately before travel.
  7. Always clear out browser cache before you leave.
  8. Backup your computer
  9. If you are bringing private data, not on a computer, copy the data onto an encrypted USB memory device
  10. Change the password for your accounts email, Gmail, Facebook, etc.
    1. Utilize complex passwords – Assume the workstation or medium will be lost or stolen.
    2. Memorize the password, or keep it in a secure location on your person.
    3. Password protect the login, and require the password after screen-saver.
    4. NEVER set browser to remember passwords.

Order Policy Download Selected Pages

SEnuke definition of poor service management

SEnuke definition of poor service management

SEnuke an adventure into poor service management.  We have  just spent a week of our lives working to get SEnuke – an SEO google search tool to work and have been frustrated beyond belief.

They came out with a new version that looked like the best thing since sliced bread.  Here are the problems that we encountered.

  1. Day 1 when when they launched the site was “down” in that you could not download the program.  The page said try back in 30 minutes.  It took a full day to get the download to work.
  2. When it installed, it did not uninstall the older version but left traces of it on so that “mysteriously” over the next week at times the older version executed confusing the heck out of me.
  3. The marketing material said that Captcha was included – however the SEnuke Captcha did not work for the better part of a week so that I had to purchase a service for that.
  4. When tried  purchasing Captcha, all of the listed companies did not work.  Links were to sites that were disable or not there.  In addition each of the sites had their own userids and passwords.  By the time that I was done shopping I have over 7 sets of them.
  5. The application was to create links and URLs.  It did not do that.  The help, which was via a blog forum, after two days told me I had to get the update.
  6. I got the update.  However, it could not be installed because it was classified as an UNSAFE publisher.  The certificate they had from GODADDY.com had been REVOKED.
  7. When I posted on the SEnuke forum the response I got was that I had to put an exclusion in my Norton.   I had already done that and even turned off Norton, but it still did not install.
  8. I posted that we would PAY for support to get it to work.  No response from them.

Considering they want close to $150 a month for their product it is not worth it.  Finally after almost a week of effort I cancelled the service and created this review of the product.

Top 10 Worst Passwords

Top 10 Worst Passwords

Security PoliciesUsers have continued to use the same worst passwords to access secure systems for several years

Top 10 worst passwords – Passwords are the first line of defense in securing systems, yet users continue to circumvent that basic security by using the same easily hacked passwords.

Below is a list of the historic top 10 worst passwords that Janco has found users continue to use.  As can see the same ones appear year after year.

 

2016

2015

2014

2013

2012

#1

123456

123456

123456

password

password

#2

password

password

password

123456

123456

#3

12345678

12345

12345678

12345678

12345678

#4

qwerty

12345678

qwerty

abc123

qwerty

#5

12345

qwerty

abc123

qwerty

abc123

#6

123456789

1234567890

123456789

monkey

monkey

#7

football

1234

111111

letmein

1234567

#8

1234

baseball

1234567

dragon

letmein

#9

1234567

dragon

iloveyou

111111

trustno1

#10

baseball

football

adobe123

baseball

dragon

In order to counter this here are 5 easy rules that can be implemented in your password routines. This will minimize the risk that your users will use these easily hacked weak passwords.

  1. Include in the list of unacceptable passwords the ones list above.
  2. Move towards biometric passwords or dual step authorization for access to systems.
  3. Do not allow users to use a previous password when a password reset is done.
  4. Do not allow the same password to be used by multiple users in the organization.
  5. Once an employee leaves see that his/her password is eliminated and see that all of the passwords in that “area” are changed in a timely manner.
Weak Passwords - Security Policy
Weak Passwords – Security Policy
Order Security ManualDownload Selected Pages