It’s back! October is here! Fall is…on its way…eventually? Mountain Day has come and gone. It is Cybersecurity Awareness Month and Information Security has all the cybersecurity awareness activities and goodies ready to go. The Virtual Scavenger Hunt begins today (if you are reading this on October 5th)! Prizes await a few lucky adventurers who attempt it. Cybersecurity awareness training started last week. We’ll have a prize for one lucky student who completes the training and ongoing bragging and shaming rights for the faculty and staff. Departments and schools will face off against all the other departments and schools for the title of Highest Completion Percentage. It will convey bragging rights until next semester when we do training again. The month is full of activity, with weekly articles on cybersecurity awareness topics, an opportunity to opt-in to a rich source of cybersecurity tips and wisdom, Fall Break, and of course, Halloween.
October is always busy. More than a full month of classes have passed and advising for next semester starts in a few weeks. Midterm exams for students are here, but the “exam” I am most concerned about this month is the Cybersecurity Awareness Training course that is now open, but closes on October 31st. As of the time I write this, over 150 of you have already completed the training and I thank you for your promptness and eagerness to knock it out. Starting on Wednesday, I will post the departmental rankings here on the site, with a quick email reminder to check in and see how your department is doing. That way you will know if you need to rally the troops to get their training done. If you can’t find your email invitation for the training you can go to https://game.hoxhunt.com and enter your email into the login field. Once you do that, it will either take you straight to your personal dashboard or ask you to log in with your Berry credentials before taking you there. You should then see the assigned training.
Once again, there is a Virtual Scavenger Hunt (VSH) to conquer during Cybersecurity Awareness Month. The hunt opens on Monday the 5th, which might be today if you jumped right in to reading this. There will be one phase per week, with phases opening up at 8AM on each Monday. There will be weekly prize drawings for those who participated during that week, giving you five chances to win a prize – one each week and the grand prize at the end. All of the information you need about the hunt is on the Virtual Scavenger Hunt Start Page. Good luck!
This Cybersecurity Awareness Month we will discuss ways to make life difficult for cybercriminals. The actual theme is “Don’t Make It Easy For Them”. The specific topics we will discuss will be:
- The perennial favorite – strong passwords (with a sprinkling of passkey discussion)
- Another favorite – multifactor authentication
- Software updates and why they are important, especially in the age of AI
- Phishing/Social Engineering – another of our favorite topics
This year, I am leaning heavily on materials from the National Cybersecurity Alliance (which is the organization behind Cybersecurity Awareness Month) that include short, true stories related to each of these topics. Let’s dive into the first topic for this month!
First, the story – Dariy Pankov, known among hackers as “dpxaker,” paid for his lavish lifestyle by selling password-cracking software to criminals for just $250 – no subscription required. Powered by his program, hackers don’t have to sit in a dark room guessing passwords one at a time – dpxaker’s software and AI tests thousands of password combinations every second. These hackers love pet names and birthdays – they really love short passwords and reused passwords!
DON’T MAKE LIFE EASY FOR DPXAKER
Now, the application:
- Every password should be at least 16 characters long (we require 14, so we’re almost there!)
- Every password needs to be unique to the account
- Every password should be a random mix of letter, numbers, and symbols
- Use a password manager to create and store awesome passwords – they are safe, easy to
use, and many are even free!
An 8-character password can be cracked in seconds, no matter how many &s and !s you use. A complex 16-character password takes billions of years to crack – and hackers don’t have that kind of time!
Want to make it even harder for cybercriminals? Use passkeys for your login accounts, whether social media, shopping sites, even financial sites like banks, as passkeys can’t be phished from you. We are working to make passkeys a viable alternative here at Berry, but there are challenges in an environment like ours. For your personal accounts, passkeys are the way to go.
However, if you don’t want to learn yet another way to log into a site, get yourself a password manager – there’s a Quick Info page about them on this site – and stop reusing passwords that are probably weak and definitely hard to remember.
That’s week 1 of Cybersecurity Awareness Month and the October newsletter. I hope you come back each Monday to read about the other topics and make progress through the scavenger hunt. Also, be sure to complete your cybersecurity awareness training as soon as possible.
All Berry students, faculty and staff have MFA enabled on their Berry account, and you should use it in the most secure way via the Microsoft Authenticator app on your smart phone. But don’t stop there! Use the Microsoft Authenticator as your second factor on any site that supports Google Authenticator. Turn on MFA/2FA everywhere you can. Yes, it will take you another few seconds to log in, but your data and account will be safer.
Please continue to report those phishing emails! Avoid using “unsubscribe” links and report both spam and phishing via the “Report” button.
If I’m not covering a topic of cybersecurity you are interested in or concerned about, please let me know. I want to be your first and best resource on cybersecurity information, so tell me how I can help and inform you.
Check out https://support.berry.edu for more information about OIT and the services we provide. You can always check back here for warnings about current phishing emails, confirmations of valid emails you might have a question about, and data breach notifications.
Food For Thought
I had so much fun with last month’s LEGO build video that I found another one. In this video, the builder keeps iterating and expanding on a theme that becomes a large and incredibly flexed construction. I never built objects like this for two reasons – I didn’t have that many LEGO blocks and I treasured the ones I had. I would never flex them like this builder does. If the groaning of the blocks in these videos bothers you, believe me, it bothers me, too! But it is still amazing…



May News from Information Security


CAM Week 4 – Security Awareness Training and The Future of Connected Devices