Spice Corps of Western Chicagoland Suburbs Spice Corps
Spice. Corps of Western Chicagoland Suburbs @Spice. Corps. WCS #SPICECORPS
Agenda • Review recently added/updated Spiceworks features • Passwords vs. Passphrases • Ransomware stats • Internet of Things security • Malware tools & resources • Sponsor presentation: Webroot • Raffles! • Q&A #SPICECORPS
Daily Challenge Test your tech IQ and have a break during your workday with a single IT question. Answer your first challenge, build your streak, and up your IT knowledge. Use the dashboard to track your progress, see which topics you excel at, and earn badges along the way! Take the challenge here: community. spiceworks. com/daily-challenge #SPICECORPS
New Community Feed Your New Feed The best of the start and feed pages, with even more functionality and customization. Personalized content, top news of the day, and the Daily Challenge. And you can read everything in-line! Check it out here: community. spiceworks. com/my-feed #SPICECORPS
Spiceworks Community Mobile App Spiceworks Mobile App All the power of Spiceworks, personalized, faster, and now on your mobile device. Download on Android and i. OS phones here: www. spice. ly/mobilefeed #SPICECORPS
Cloud Helpdesk Spiceworks Help Desk – Cloud Edition We’ve made a few updates to help IT pros get things done even quicker: ü Updated user portal (AD/LDAP Integration, custom attributes, custom forms, Knowledge Base) ü SLA/Ticket Alerting (to allow you to get notifications when tickets have not been worked/closed in a given amount of time) ü App Center Integration Check it all out here: spiceworks. com/free-help-desk-software User portal #SPICECORPS
Connectivity Dashboard With the Spiceworks Connectivity Dashboard, you can see all users’ connectivity and view speed to their applications. Figure out if there’s an issue with: ü ISP ü Application ü Other issues onsite like floor switch, wifi access point, etc Check it all out here: spiceworks. com/it-troubleshooting #SPICECORPS
Network Monitor 1. 5 Historical Data See what’s happening on your network over time Maintenance Windows Turn off alerts for regularly scheduled maintenance Watch More Devices Add devices to your Online Watchlist on your dashboard Check it out and learn more here: community. spiceworks. com/blogs/products/2400 #SPICECORPS
Spice. World Come to the most happenin’ IT conference around, Spice. World! Hang out with fellow IT pros, attend useful tech sessions… and have blast while you’re at it. Learn more and register here: spiceworks. com/spiceworld/ Locations & dates: • Austin, TX | Nov. 1 – 3, 2016 • London, UK | 23 – 24 May, 2017 #SPICECORPS
Passwords vs. Passphrases #SPICECORPS
xkcd. com/936 #SPICECORPS
Common Password Practices • Minimum length 8 -12 characters • Complexity requirements • Required change every 30/60/90 days • Leads to difficult-to-remember passwords • Users forget password more often • Password post-its on monitors • Users use easy-to-guess passwords • Users reuse passwords, incrementing a number #SPICECORPS
Password cracking • New password cracking cluster – 350 b guesses/second • 25 AMD Radeon card cluster + Virtual Open. CL cluster platform and ocl-Hashcat Plus • Examines around 50 hash algorithms • Can try every possible 8 -character Microsoft password in 5. 5 hrs • Crack 20 char passphrase • Numeric only: 3. 5 trillion years • Lowercase only: 1 sextillion years • Alphanumeric + symbols: 295 quintillion years #SPICECORPS
Passphrase Benefits • 20 character passphrases impossible to brute force • Easy for users to remember • Easier to type without complexity requirements • Password post-its won’t make sense to passersby • Less need to unlock user accounts or reset passwords • Can lessen password change interval – 6/12 months #SPICECORPS
Ransomware #SPICECORPS
Spiceworks surveyed over 300 IT pros about ransomware… here’s what we found. . . #SPICECORPS
#SPICECORPS
Internet of Things #SPICECORPS
Statistics • More than 21 billion devices by 2020 • IDC estimates 90% of all IT networks will have Io. T security breach in next 5 years • 70% of most commonly used Io. T devices contain vulnerabilities (HP) • 40% IT pros believe their network is unprepared to find connected Io. T threats • 37% of IT pros unable to determine number of connected Io. T devices on network #SPICECORPS
Top Device Threats 2016 • BYOD and customization of corporate hardware • Mobile hotspot vendors • Insecure, misconfigured, or vulnerable Io. T devices • 56% of HP printers deployed “open by default” • Insecure devices used as backdoor into network • Unauthorized or misconfigured APs • 35% of APs in last 6 -12 months show weak or no encryption #SPICECORPS
Malware Tools & Resources #SPICECORPS
• Spiceworks Outbreaks Guide • https: //community. spiceworks. com/security/threats-vulnerabilities -malware • Spiceworks SNAP! • https: //community. spiceworks. com/originals/snap • Virus. Total • http: //virustotal. com • Sandboxie ($52/yr commercial, $21 personal) • http: //sandboxie. com #SPICECORPS
Webroot #SPICECORPS
- Slides: 23