{"id":2336,"date":"2020-03-26T14:18:00","date_gmt":"2020-03-26T14:18:00","guid":{"rendered":"http:\/\/blogs.kent.ac.uk\/unikentcomp-news\/?p=2336"},"modified":"2020-05-14T10:17:44","modified_gmt":"2020-05-14T09:17:44","slug":"working-from-home-risks-online-security-and-privacy-how-to-stay-protected","status":"publish","type":"post","link":"https:\/\/blogs.kent.ac.uk\/unikentcomp-news\/2020\/03\/26\/working-from-home-risks-online-security-and-privacy-how-to-stay-protected\/","title":{"rendered":"Working from home risks online security and privacy \u2013 how to stay protected"},"content":{"rendered":"<figure><img src=\"https:\/\/images.theconversation.com\/files\/322916\/original\/file-20200325-168876-1vls1qj.jpg?ixlib=rb-1.1.0&amp;rect=0%2C0%2C7694%2C5132&amp;q=45&amp;auto=format&amp;w=754&amp;fit=clip\" \/><figcaption><span class=\"attribution\"><a class=\"source\" href=\"https:\/\/www.shutterstock.com\/image-photo\/pensive-female-freelancer-working-on-publication-1054751132\">GaudiLab\/Shutterstock<\/a><\/span><\/figcaption><\/figure>\n<p><a href=\"https:\/\/theconversation.com\/profiles\/jason-nurse-392784\">Jason Nurse<\/a>, <em><a href=\"https:\/\/theconversation.com\/institutions\/university-of-kent-1248\">University of Kent<\/a><\/em><\/p>\n<p>Remote working can be a blessing. More time with family, less commuting, and meetings from the comfort of your living room. But as millions across the world switch to working from home due to the <a href=\"https:\/\/www.who.int\/emergencies\/diseases\/novel-coronavirus-2019\">COVID-19 pandemic<\/a>, they may be putting the security and privacy of themselves, their families and their employers at risk.<\/p>\n<p>Many will be using online collaboration tools, such as <a href=\"https:\/\/zoom.us\/\">Zoom<\/a>, <a href=\"https:\/\/slack.com\/\">Slack<\/a>, and <a href=\"https:\/\/houseparty.com\/\">HouseParty<\/a> to stay connected to colleagues and friends now that physical contact is restricted.<\/p>\n<p>Zoom, the most popular of the video calling platforms, allows call hosts to <a href=\"https:\/\/www.eff.org\/deeplinks\/2020\/03\/what-you-should-know-about-online-tools-during-covid-19-crisis\">track attendee attention<\/a>, and in particular, whether you are in the Zoom window (as opposed to checking email or playing a game, for instance). Zoom also <a href=\"https:\/\/www.eff.org\/deeplinks\/2020\/03\/what-you-should-know-about-online-tools-during-covid-19-crisis\">collects a host of other personal information<\/a> such as each caller\u2019s location data, operating system, IP address, and what kind of device they\u2019re using, whether it\u2019s an Apple Mac, iPhone, Android or Windows device.<\/p>\n<p>Zoom has had its share of security problems. A now-fixed <a href=\"https:\/\/threatpost.com\/zoom-fixed-flaw-opening-meetings-to-hackers\/152266\/\">software bug<\/a> had allowed anyone to find and join a meeting. There <a href=\"https:\/\/www.theverge.com\/2019\/7\/9\/20688113\/zoom-apple-mac-patch-vulnerability-emergency-fix-web-server-remove\">was<\/a> also a problem <a href=\"https:\/\/medium.com\/bugbountywriteup\/zoom-zero-day-4-million-webcams-maybe-an-rce-just-get-them-to-visit-your-website-ac75c83f4ef5\">with its software<\/a> which could have resulted in any malicious website turning on your camera and watching you unawares. And <a href=\"https:\/\/techcrunch.com\/2020\/03\/17\/zoombombing\/\">Zoom Bombing<\/a> is now a thing. It involves trolls using Zoom\u2019s screensharing feature to display vile content, including violent videos and shocking pornography.<\/p>\n<figure class=\"align-center \"><img src=\"https:\/\/images.theconversation.com\/files\/322920\/original\/file-20200325-168907-1igdjeb.jpg?ixlib=rb-1.1.0&amp;q=45&amp;auto=format&amp;w=754&amp;fit=clip\" alt=\"\" \/><figcaption><span class=\"caption\">Video conferencing apps give colleagues a glimpse into your living space. But who else might be watching?<\/span><br \/>\n<span class=\"attribution\"><a class=\"source\" href=\"https:\/\/www.shutterstock.com\/image-photo\/woman-having-video-chat-colleagues-table-1390309433\">New Africa\/Shutterstock<\/a><\/span><\/figcaption><\/figure>\n<p>Another popular tool is Slack, which as <a href=\"https:\/\/slack.com\/intl\/en-gb\/\">it states<\/a>, \u201cis the place for remote work\u201d. A core feature of Slack is its channels. These are spaces to share messages and files with colleagues on particular topics and projects. While paid accounts have some control over how long their channel or private message data is kept by Slack, <a href=\"https:\/\/www.eff.org\/deeplinks\/2020\/03\/what-you-should-know-about-online-tools-during-covid-19-crisis\">free accounts are much more limited<\/a>. This could mean that your messages (including direct messages complaining about your boss or a colleague) are accessible to others, even if they aren\u2019t to you.<\/p>\n<p>For many people, working remotely is a completely new experience. Some are celebrating the novelty by using the <a href=\"https:\/\/twitter.com\/hashtag\/WorkFromHome\">#WorkFromHome<\/a> hashtag on social media, and sharing posts that include photos of home office setups, and friends and family members.<\/p>\n<p>This may seem benign, but it can actually expose <a href=\"https:\/\/arxiv.org\/pdf\/1811.06624.pdf\">a variety of sensitive personal information<\/a> about you and those around you.<\/p>\n<p>For instance, posting photos of homeworking setups, which happen to include letters, post or Amazon packages, can publicise your home address. Sharing photos and names of family members or pets may <a href=\"https:\/\/www.ncsc.gov.uk\/news\/most-hacked-passwords-revealed-as-uk-cyber-survey-exposes-gaps-in-online-security\">provide hints about your passwords<\/a> or even expose <a href=\"https:\/\/www.cs.ox.ac.uk\/files\/6632\/trustcom2012_CGNP.pdf\">your location<\/a>.<\/p>\n<p>The now popular practice of sharing <a href=\"https:\/\/blog.zoom.us\/wordpress\/2017\/11\/14\/how-zoom-employees-use-zoom\/\">screenshots of Zoom work group chats<\/a> or <a href=\"https:\/\/www.forbes.com\/sites\/thomasbrewster\/2020\/03\/23\/houseparty-is-the-hit-coronavirus-lockdown-app-safe\/\">HouseParty<\/a> <a href=\"https:\/\/twitter.com\/hashtag\/HouseParty\">video hangouts<\/a>, also has its privacy risks, given the fact that companies have been known to <a href=\"https:\/\/www.wired.com\/story\/clearview-ai-scraping-web\/\">indiscriminately gather the photos we share online<\/a> and use them without our permission. This means anyone could match offline photos of us directly to our online profiles on Twitter, Facebook or LinkedIn. Some companies have even been known to <a href=\"https:\/\/www.telegraph.co.uk\/technology\/2019\/04\/09\/facebook-plans-pass-photographs-advertisers-make-users-stars\/\">use our photos in adverts<\/a>.<\/p>\n<h2>Well-equipped cyber-criminals<\/h2>\n<p>Largescale remote working is <a href=\"https:\/\/threatpost.com\/working-from-home-covid-19s-constellation-of-security-challenges\/153720\/\">a security nightmare for employers<\/a>. As remote access to corporate networks is rolled out, cyber-criminals have their pick of places to attack.<\/p>\n<p>Cyber-criminals are well aware of this, and have already begun to launch targeted attacks. According to the <a href=\"https:\/\/www.actionfraud.police.uk\/alert\/coronavirus-related-fraud-reports-increase-by-400-in-march\">latest statistics<\/a>, coronavirus-related fraud reports have increased by 400% in March alone. There have been scams for <a href=\"https:\/\/www.bbc.co.uk\/news\/technology-51838468\">COVID-19 tax refunds<\/a> and others <a href=\"https:\/\/www.bbc.co.uk\/news\/technology-51838468\">impersonating the Centre for Disease Control to request donations<\/a>.<\/p>\n<p>Criminals have impersonated staff from the <a href=\"https:\/\/exchange.xforce.ibmcloud.com\/collection\/2f9a23ad901ad94a8668731932ab5826\">World Health Organization (WHO)<\/a> and there have been <a href=\"https:\/\/nakedsecurity.sophos.com\/2020\/03\/19\/dirty-little-secret-extortion-email-threatens-to-give-your-family-coronavirus\/\">extortion emails<\/a> that threaten to infect recipients with coronavirus unless they pay up. Even coronavirus outbreak and infection-tracking maps are <a href=\"https:\/\/www.weforum.org\/agenda\/2020\/03\/hackers-are-using-coronavirus-maps-to-spread-malware\/\">being used to spread malware<\/a>.<\/p>\n<p>These problems are made worse by the reality that many of us will be using personal, and potentially less secure home devices, such as laptops, phones and USB drives, for work tasks. Most people aren\u2019t accustomed to <a href=\"https:\/\/kar.kent.ac.uk\/67511\/1\/csss2015_bada_et_al.pdf\">maintaining workplace security practices<\/a> over long periods in our homes, with kids, distractions and other commitments.<\/p>\n<p>&nbsp;<\/p>\n<h2>How to stay safe<\/h2>\n<ul>\n<li>Be careful what you post publicly. Check that there is no potentially sensitive information in it. Once it\u2019s published online, it\u2019s there, forever.<\/li>\n<li>Check recent security and privacy reports about online collaboration tools before using them, and if in doubt, consult your employer. These tools can have access to details about your devices, your data and your video and audio conversations. The <a href=\"https:\/\/www.eff.org\/deeplinks\">Electronic Frontier Foundation<\/a> is a good source.<\/li>\n<li>Protect your devices. Install anti-virus software, update systems and apps, <a href=\"https:\/\/www.ncsc.gov.uk\/guidance\/setting-two-factor-authentication-2fa\">implement multi-factor authentication<\/a> (so that multiple pieces of evidence are needed for someone to use your login, such as username and password and a text message), and be on the <a href=\"https:\/\/nakedsecurity.sophos.com\/2020\/02\/05\/coronavirus-safety-measures-email-is-a-phishing-scam\/\">lookout for phishing scams<\/a>.<\/li>\n<li>Zoom Bombing and other forms of hijacking meetings can be prevented. Share meeting links with <a href=\"https:\/\/blog.zoom.us\/wordpress\/2020\/03\/20\/keep-the-party-crashers-from-crashing-your-zoom-event\/\">only invited parties<\/a>. <a href=\"https:\/\/techcrunch.com\/2020\/03\/17\/zoombombing\/\">Configure Zoom<\/a> to only allow the host to share screen, as appropriate. And <a href=\"https:\/\/nakedsecurity.sophos.com\/2020\/03\/20\/trolls-zoombomb-work-from-home-videocall-with-filth\/\">disable file transfers<\/a> to stop trolls sharing viruses to all attendees.<\/li>\n<li>More tips are available through the <a href=\"https:\/\/www.who.int\/about\/communications\/cyber-security\">WHO<\/a>, <a href=\"https:\/\/www.weforum.org\/agenda\/2020\/03\/covid-19-transition-to-remote-work\/\">WEF<\/a>, <a href=\"https:\/\/www.ncsc.gov.uk\/guidance\/home-working\">NCSC<\/a>, <a href=\"https:\/\/www.enisa.europa.eu\/news\/executive-news\/top-tips-for-cybersecurity-when-working-remotely\">ENISA<\/a> and <a href=\"https:\/\/www.consumer.ftc.gov\/blog\/2020\/03\/online-security-tips-working-home\">FTC<\/a>.<!-- Below is The Conversation's page counter tag. Please DO NOT REMOVE. --><img loading=\"lazy\" style=\"border: none !important;margin: 0 !important;max-height: 1px !important;max-width: 1px !important;min-height: 1px !important;min-width: 1px !important;padding: 0 !important\" src=\"https:\/\/counter.theconversation.com\/content\/134599\/count.gif?distributor=republish-lightbox-basic\" alt=\"The Conversation\" width=\"1\" height=\"1\" \/><!-- End of code. If you don't see any code above, please get new code from the Advanced tab after you click the republish button. The page counter does not collect any personal data. More info: https:\/\/theconversation.com\/republishing-guidelines --><\/li>\n<\/ul>\n<p><a href=\"https:\/\/theconversation.com\/profiles\/jason-nurse-392784\">Jason Nurse<\/a>, Assistant Professor in Cyber Security, <em><a href=\"https:\/\/theconversation.com\/institutions\/university-of-kent-1248\">University of Kent<\/a><\/em><\/p>\n<p>This article is republished from <a href=\"https:\/\/theconversation.com\">The Conversation<\/a> under a Creative Commons license. Read the <a href=\"https:\/\/theconversation.com\/working-from-home-risks-online-security-and-privacy-how-to-stay-protected-134599\">original article<\/a>.<\/p>\n<p>This article was also published in <a href=\"https:\/\/www.newsweekjapan.jp\/stories\/technology\/2020\/05\/zoomslackhouseparty.php.\">Newsweek Japan.<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>GaudiLab\/Shutterstock Jason Nurse, University of Kent Remote working can be a blessing. More time with family, less commuting, and meetings from the comfort of your &hellip; <a href=\"https:\/\/blogs.kent.ac.uk\/unikentcomp-news\/2020\/03\/26\/working-from-home-risks-online-security-and-privacy-how-to-stay-protected\/\">Read&nbsp;more<\/a><\/p>\n","protected":false},"author":5321,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[57908],"tags":[],"_links":{"self":[{"href":"https:\/\/blogs.kent.ac.uk\/unikentcomp-news\/wp-json\/wp\/v2\/posts\/2336"}],"collection":[{"href":"https:\/\/blogs.kent.ac.uk\/unikentcomp-news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blogs.kent.ac.uk\/unikentcomp-news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blogs.kent.ac.uk\/unikentcomp-news\/wp-json\/wp\/v2\/users\/5321"}],"replies":[{"embeddable":true,"href":"https:\/\/blogs.kent.ac.uk\/unikentcomp-news\/wp-json\/wp\/v2\/comments?post=2336"}],"version-history":[{"count":4,"href":"https:\/\/blogs.kent.ac.uk\/unikentcomp-news\/wp-json\/wp\/v2\/posts\/2336\/revisions"}],"predecessor-version":[{"id":2428,"href":"https:\/\/blogs.kent.ac.uk\/unikentcomp-news\/wp-json\/wp\/v2\/posts\/2336\/revisions\/2428"}],"wp:attachment":[{"href":"https:\/\/blogs.kent.ac.uk\/unikentcomp-news\/wp-json\/wp\/v2\/media?parent=2336"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blogs.kent.ac.uk\/unikentcomp-news\/wp-json\/wp\/v2\/categories?post=2336"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blogs.kent.ac.uk\/unikentcomp-news\/wp-json\/wp\/v2\/tags?post=2336"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}