I have nothing to hide

How often do you hear this simple, at first glance, phrase from your acquaintances, friends, and colleagues?

As governments and corporate giants implement increasingly sophisticated methods of information control and user surveillance, the percentage of misguided individuals grows who take the seemingly obvious statement that "if I'm not breaking the law, I have nothing to fear" as gospel.

Indeed, if I haven't done anything wrong, the fact that governments and corporate giants want to collect all my data, emails, phone calls, webcam images, and search queries doesn't matter at all, as they won’t find anything interesting anyway.

After all, I have nothing to hide. Isn't that right?

I have nothing to hide

What's the problem?

I am a system administrator. Information security is deeply integrated into my life, and due to the nature of my job, the length of any password I create is usually at least 48 characters.

Most of them I know by heart, and when an unsuspecting person happens to see me entering one of them, they usually have a reasonable question — "Why is it so... lengthy?"

"For security? But not that long! For example, I use an eight-character password, after all, I have nothing to hide.».

Lately, I've been hearing this phrase more frequently from people around me. What’s particularly disheartening is that sometimes it comes even from those who are more closely connected to information technology.

Okay, let’s rephrase that.

I have nothing to hide, because...

...everyone already knows my bank card number, its password, and CVV/CVC code.
...everyone already knows my PINs and passwords.
...everyone already knows my salary.
...everyone already knows where I currently am.

And so on.

Sounds a bit implausible, doesn't it? Yet when you say "I have nothing to hide" once more, that is what you mean. Perhaps you don't realize it yet, but the truth does not depend on your will.

It’s important to understand that this is not about concealment, but about protection. Protecting your inherent values.

You can hide nothing if you are completely sure there is no threat to you and your data from the outside.

However, absolute security is a myth. "Only those who do nothing make no mistakes." It would be a huge mistake not to consider the human factor when creating information systems closely related to ensuring the safety and security of user data.

Any lock implies the presence of a key to it.. Otherwise, what is the point? A lock was originally designed as a means to protect property from unauthorized interaction with it.

You would hardly be pleased if someone gained access to your social network account and began sending out inappropriate messages, viruses, or spam in your name. It is important to understand that we do not hide the facts.

Indeed: we have a bank account, email, and a Telegram account. We do not hide these facts from the public. We protect the above from unauthorized access.

Who would want me?

Another equally common misconception often used as a counterargument.

We say: "Why would a company want my data?" or "Why would a hacker want to hack me?" ignoring the fact that hacking may not be selective — the service itself may be hacked, and in this case, all users registered in the system will suffer.

It is important not only to follow information security rules yourself but also to choose the tools you use correctly.

Let me give you a few examples to make it clear what we are talking about.

They had nothing to hide.

  • MFC
    In November 2018, there was a leak of personal data from Moscow's multifunctional centers for providing state and municipal services (MFC) "My Documents."

    Many scanned copies of passports, SNILS, questionnaires with mobile phone numbers, and even bank account details were found on public access computers in the MFC, which could be accessed by anyone.

    Based on the obtained data, microloans could have been taken or even access to people's bank account funds obtained.

  • Sberbank
    In October 2018, there was a data leak.The names and email addresses of more than 420,000 employees were publicly available.

    Customer data was not included in this leak, but the mere fact that such a volume of data appeared indicates that the hacker had high-level access rights in the bank's systems and could have accessed customer information as well.

  • Google
    An error in the Google+ social network API allowed developers to access data from 500,000 users such as: usernames, email addresses, workplaces, birthdates, profile photos, and more.

    Google claims that none of the 438 developers who had access to the API were aware of this error or could exploit it.

  • Facebook
    Facebook officially confirmed the data leak of 50 million accounts, potentially affecting up to 90 million accounts.

    Hackers were able to access the profiles of the owners of these accounts due to a chain of at least three vulnerabilities in Facebook's code.

    In addition to Facebook itself, services that used this social network for authentication (Single Sign-On) were also affected.

  • Again Google
    Another vulnerability in Google+ led to the data leak of 52.5 million users.
    The vulnerability allowed applications to retrieve information from user profiles (name, email address, gender, birthdate, age, etc.), even if this data was private.

    Additionally, through one user's profile, data from other users could be accessed.

Source: ‘The most significant data breaches of 2018’

Data breaches occur much more frequently than you might think.

It is fair to say that not all data breaches are publicly announced by the perpetrators or the victims.

It is important to understand that any system that can be hacked will be hacked. Sooner or later.

Here are some actions you can take right now to protect your data.

    → Change your mindset: remember that you are not hiding your data, but protecting it.
    → Use two-factor authentication.
    → Do not use easy passwords: passwords that may be associated with you or found in a dictionary.
    → Do not use the same passwords for different services.
    → Do not store passwords in plain text (for example, on a sticky note attached to your monitor).
    → Do not share your password with anyone, not even support staff.
    → Avoid using free Wi-Fi networks

What to read: useful articles on information security

    → Information security? No, haven't heard of it
    → A primer on information security today
    → Basics of information security. The cost of a mistake
    → Friday: Security and the survivor's paradox

Take care of yourself and your data.

Only registered users can participate in the survey. Please log in, please.

Alternative Voting: We value the opinions of those who do not have a full-fledged account on Habr.

439 users voted. 137 users abstained.

Source: habr.com

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster