Christmas is coming, don’t let the hackers get fat

Christmas is nearly here, people are beginning the big “wind down” and it would be so easy to let your guard down too.

Andy, checking out websites as part of his work

Well, let me tell you, the hackers and cyber criminals won’t – it anything they’ll be ratcheting up their activity because they know that our minds will be on other things.

You know, things like Christmas parties, gifts, food, television and everything else that’s associated with the season of goodwill.

So, vigilance must remain high, both in the office and when working from home. Keep your eyes open for suspicious looking emails, especially those coming from unexpected quarters, with messages that promise much, such as tax refunds or deliveries of items you don’t remember ordering. Also beware of emails with links to websites that look OK but in reality will do harm.

It’s also a good idea to take a fresh look at your password security. SplashData have just released their ninth annual “Worst Passwords of the Year” list which has been compiled from more than 5m passwords that have ended up on the Dark Web after being purloined by hackers.

Unfortunately, not a lot has changed over previous lists

  1. 123456 (same place as 2018)
  2. 123456789 (up 1 place)
  3. qwerty (a return to the top 5 for this old favourite)
  4. password (slips two places)
  5. 1234567 (up 2)
  6. 12345678 (falls out of the top 5)
  7. 12345 (falls by 2 places)
  8. iloveyou (this perennial is up 2 places from 10 in 2018)
  9. 111111 (yes, people do use this although it’s fallen 3 places from last year)
  10. abc123 (up 7 and breaking in to the top 10)

You can see passwords from 11 to 25 here.

SplashData estimates that at least 1 in 10 people have used at least one of these poor passwords.

Data breaches are inevitable but by using strong, unique passwords for each individual account that you have makes the theft of one password much less of a disaster than if you use the same (or close variant) across all of your accounts.

3 simple tips to make your digital life more secure

  1. Use passphrases (random word combinations) of 12 characters or more with mixed character types
  2. Use a different password for each of your log-ins so if you loose one password you haven’t lost all of the keys to your digital empire
  3. Use a password manager to secure your digital assets, to generate random password combinations, store them securely and make them available across all of your devices

And PLEASE, if this applies to to you – STOP USING PASSWORD or 12345678 and use one of these instead

Top Password Managers (in no particular order)

Have a great Christmas, a happy new year and I look forward to communicating with you in the new year. If you need any help, please, just ask. You can reach me by phone – 01793 238020 – email – andy@enterprise-oms.co.uk or just hunt me down on Social Media.

However, I hope to enjoy Christmas too so may be slower than normal in responding to your requests. I’ll be back in the office on January 2nd.

Yes, it’s “Password Madness” time

USer name and password box

Government Communications Head Quarters (GCHQ)- where the UK spooks provide signals intelligence to the UK’s government, military and Military Intelligence and the Department for Digital, Media and Sport (DCMS) carried out their first UK Cyber Survey and the results didn’t make for great reading.

Apparently

  • 42% of us Brits expect to lose money to on-line fraud
  • 23.2 million worldwide victims of cyber breaches used 123456 as their password
  • 15% say they know how to properly protect themselves from harmful on-line activity
  • 33% rely on friends and family for help with their cyber security
  • Young people are the most likely to be cyber aware, privacy concious and careful of the details they share on-line
  • 61% of internet users check Social Media daily, 21% say they never look at it
  • More than 50% use the same password for their email that they use elsewhere
Hacker Inside

Dr Ian Levy, NCSC Technical Director said “Using hard-to-guess passwords is a strong first step and we recommend combining three random but memorable words. Be creative and use words memorable to you, so people can’t guess your password.” whilst Margot James, DMCS Minister said “We shouldn’t make their (cyber criminals) lives easy so choosing a strong and separate password for your email account is a great practical step. “

Most Regularly Used Passwords

RankPasswordTimes Used PasswordTimes Used
1.123456 23.2m ashley432,276
2.1237567897.7m michael425,291
3.qwerty3.8m daniel368,227
4.password3.6m jessica324,125
5.11111113.1m charlie308,939

It’s a shame that the top password list hasn’t really changed for at least 10 years – it shows how complacent a lot of us are with our on-line security.

I used to have 3 passwords, a simple one that I used really casually for newspaper sign-ups etc – name123 (not my real passwords, merely examples) a medium security one that I used on shopping sites, n@m3123 and a more secure one, used for banking etc – c3ler0n! (and all of the ones that I used feature on the Have I Been Pwned list).

About 5 or more years ago I switched to a Password Manager. I have 801 log-ins and 801 different passwords. All of them are at least 16 random characters long and comprise upper & lower case letters, numbers and symbols (where permitted).

Logging On

My Password database is stored securely in the cloud and is replicated on my PC, Phone and Tablet and accessible from my Chromebook too. I use LastPass but others exist and here’s a review of some of the top ones.

As you can see, I do my best to stay on top of my security but if you feel adrift, or need some help, just give me a call on 01793 238020 or email andy@enterprise-oms.co.uk for a free chat.

What the FA is 2FA and do you need it?

Let’s answer the easy question first, “do you need 2FA”? The simple answer is “yes”, you do need Two Factor Authentication (2FA). Now read on to learn more about what it is, how it works and how it can secure your data and online activity

I’ve written in previous posts about passwords, hacking, identity theft and the threat to our privacy, data and businesses from cyber criminals. As you might imagine, the number of attacks is increasing, as is the sophistication.

Why are Cyber Attacks increasing

Simple! The number of websites that we log-in to continues to increase and many people use one password across many websites. As you can see from the list on the right a lot of people use passwords that are less than ideal. The cyber criminals know this which makes it a gift for them.

Some people think they are safe because they have 3 passwords. A simple one for common sites where they don’t see a threat (posting comments to newspaper websites for example), a medium one that they use for on-line shopping and Cloud storage sites (DropBox for example) and a really complicated one for their “secure” sites, such as bank access etc. 

After all, just trying to remember pWa#eeAS7uNggK49 is a challenge but if you have to remember a different one for every single website it becomes a real challenge. You might jot them down in a notebook or diary but what happens if you loose your book, or just leave it on a train. Not only have you been frozen out of your accounts (until you work your way through all those “forgotten password” routines) but your security has been seriously compromised.

Some people, like me for example, use password manager. These apps create a secure password for ever site that you log in to and make it available across desk-tops, lap-tops, phones and tablets and don’t cost very much at all. But even if you use one how secure are you, actually?

chocolate teapot

If a site that you use your super strong password on is penetrated and data stolen, your strong password is about as much use (from a security perspective) as the infamous chocolate teapot.

And if you have used this super-strong password on more than one site you are at an even greater risk of becoming a victim of data theft. With more than 6,474m email addresses in the wild for cyber criminals to use and 551m passwords stolen in security hacks the criminals job gets ever easier.

Use the Have I been Pwned website to see whether your passwords have been stolen by cyber criminals or nabbed in a data breach and read more about the risk, and how the criminals use this stolen data in a previous post.

What’s the Solution

It’s actually fairly simple. It’s called two factor authentication [2FA] or multi-factor authentication. This is where another layer of authentication is required, beyond your user name and password.

In the early days of 2FA sites would send you a text with an access code so you could only log-in if you had your phone with you [and had a mobile signal]. This extra layer of security hit the cyber-criminals hard, until they realised that intercepting text messages was not particularly difficult if you were tech-savvy so something else was required.

Image result for hsbc internet banking device

The banks solved this problem by providing you with a device like the one to the right, this one’s from HSBC. At the website you enter your user-name and pass-code as normal, enter a PIN in the device and then enter the displayed number from the device in to your banks website. It may feel like a pain but it really does have a positive effect on the security of your on-line banking. A criminal needs a your user name/password, access to a device as well as your device PIN

Microsoft Authenticator

Having a device for every website is pretty clunky so Microsoft and Google released authentication apps for Android and iPhones. The way they work is they generate a six digit code, as can be seen in the image on the right, and the website that you are looking to access requests this code after you have entered your user-name and password – as demonstrated in this screen-shot of my LastPass password manager.

Two Factor Authentiaction

All I have to do is launch my Authenticator App and enter the six digit password. For additional security, the code changes every 30 seconds or so

Hardware Security

Hardware 2FA security solution

The final security solution is the physical “Key” such as this one from Yubikey. This is a USB device that simply plugs in to a USB port on your computer and allows you access to secured sites – or even your computer itself.

If you are worried by your security, or need any help with your internet activity, from a new website through social media and on to other online marketing opportunities then just send me an email – andy@enterprise-oms.co.uk or give me a call on 01793 238020

 

Have you had your electronic ID stolen?

In other words, have you been pwned*. There have been millions of email addresses and passwords stolen in hack attacks and millions more that have been left exposed by incompetent website owners. However, it’s not just your email address that’s been stolen, your name will have gone with it, possibly your address and maybe even credit card (and other) data.

The stolen information is then made available for sale on the dark web and here’s a sample of the prices it can fetch

  • Credit/debit card number – $5-$11
  • With the CVV (3 digit) security code – + $5
  • “Fullz” (card, CVV, name, address, date of birth etc.) – $30
  • Bank account access – 10% of the credit balance in the account
  • Online Payment Services, such as PayPal – $20-$200

But how do you know whether your information is “out there” just waiting to be abused by cyber criminals? Well, I don’t know but I know a man who does, and he’s set up a rather useful website

Have I been Pwned?

There’s a website called Have I Been Pwned. This has been created by Troy Hunt, a Microsoft Regional Director & MVP (Microsoft Most Valuable Person for developer security). After data from a major cyber incident was “found” on the Dark Web Troy decided to put a database together – in his own time & at his own cost – as a way of allowing people to check whether their data was amongst stolen information and to “keep his hand in” from a programming perspective.

The site is now a comprehensive source of information about data hacks and data loss and is simple to use. All you have to do is enter your email address to see whether you have been “pwned”

And if you have been, as shown in the image above, it will also tell you which data breach (breaches) your email address has been found in.

Not every data breach leads to passwords being available. Some databases have encrypted passwords, making them worthless to the cyber criminal. However, many don’t and, like email addresses, there are millions (over 550) of passwords available on the Dark Web.

As he’s done with email addresses, Troy has now gathered all the stolen passwords that he can find and has created another searchable database dedicated to stolen passwords.

Why it’s important to know whether your passwords are available to cyber criminals.

At this point, all the criminals have is a list of emails and and another list of passwords. They may not know which ones go together and they also don’t know which websites these email addresses and passwords relate to.

But, from our perspective, there’s a significant weakness. This comes in to play because a lot of people use the same password for many websites simply because it’s easier to remember one password than many. This use of the same password makes things a lot easier for the cyber criminals to put our data to fraudulent use.

Let’s say, for example, that the criminals target Amazon. You might have your credit card details already stored against your account so if a cyber criminal can gain access, all they have to do is change a delivery address and Bob’s their uncle.

They’ll use a “Credential Stuffing Attack” which means that they’ll load all the email addresses in to one database and the passwords in to another and start the attack. First they pick their target (Amazon in my example) and use software that will add an email address to the log-in box. They’ll then turn to different software to try all the passwords in the password database to see whether there’s a match.

And once they’ve tried one email address they’ll automatically move on the next one. Once they’ve tried all combinations, and flagged those that work, they’ll move on to another site.

This sounds like a long, slow process but they’ll probably use a “Botnet” – a network of tens, hundreds or possibly thousands of hacked computers around the world that they have control over.

So, you should check “Have I Been Pwned” for both email addresses and passwords and if you’ve got a compromised password you should find the sites you use it on and change it – remembering to use a different one for each site.

Top 10 Passwords of 1018

Different, not similar – Password, PassWord, PAssword1960 and Pa55W0rd are NOT different to a cyber criminal. Criminals will also use these, and other variants of the world’s most popular passwords (2018’s shown in the image to the right) in their attempts to hack your accounts.

If you are concerned about your digital security, or need some help with your website, SEO or anything else online then just drop me an email, andy@enterprise-oms.co.uk , or give me a call on 01793 238020 for a free, no obligation conversation about your requirements

*Pwned – When a map designer in the online game called Warcraft beat another player he wanted to say “Player x has been owned”. Unfortunately, he mis-typed and actually said “Played x has been Pwned”. This is now a “thing”

The Deep Web and Dark Web. What are they?

Browser Address bar

The Deep Dark Web

The “Dark Web” has been in the press frequently over the past couple of years, associated with tales of hacking, the sale of personal information, credit card data, drugs, weapons and other illicit items. However,  there’s been very little by way of explanation as to what the dark web is and how you go there and this item looks to answer that, purely for research purposes of course.

A number of news stories have also referred to the “Deep Web” which has lead to a degree of confusion, as if the media consider the two to be interchangeable.

So, just to clear up any confusion here’s an explanation of the differences between the Deep and the Dark Web.

Let’s start at the top

The “Surface Web” is the web we all know and love, the websites we visit and the sites/pages that we find using Google/Bing/Yahoo and other search engines. And there’s the key, it’s only the parts of the internet that the search engines know about.

Just visit any website and click a few links, you’ll be doing the same thing that the search engines do, visiting websites and following links to find pages that they can present to you when you’re looking for things.

Steps leading down to represent the Deep Web

What is The Deep Web

Simply put, the Deep Web is just the area of the internet that is beyond the reach of the major search engines.

As an example, just go to www.britishairways.comand try to find a holiday to the Nautic Hotel between 7th and 14th October in Mallorca without using the search facilities.

It’s not that easy, in fact it you might find it confusing/difficult/impossible. You’re not alone, the search engines do to because they can’t get much further down than the first 3-4 layers. At least this is getting better because Google, Bing and the like are always looking to improve the way they manage such challenges but it’s still a struggle for them. 

Websites can use code, called robots.txt, to actually block the search engines from certain pages so that they are difficult to find, deliberately. Websites with members only pages may choose to do this, for example.

As you can see, the Deep Web is neither illicit nor scary, it’s just out of reach of the major search engines.

What is the Dark Web

This is where things get really interesting. The Dark Web is a small portion of the web that is intentionally hidden and encrypted and which cannot be accessed through your typical web browser.

TOR logo representing the Dark Web

To access the Dark Web you need a specialised web browser that enables you to tap into the the TOR network. TOR, short for ‘The Onion Router’, so called because it uses many layers to both encrypt the data that moves around and to make it almost impossible for the authorities to trace internet activity back to a particular user and location. Great for security and anonymity which is why TOR was originally designed by US Intelligence agencies to enable American spies to securely communicate with their parent organisation and not reveal their location and identity. 

The code was officially released to the public in 2004, and it’s still used by human rights groups and the like in repressive and unsafe countries to communicate with the outside world, but like almost everything it has also been subverted by those with criminal tendencies and put to a darker use.

You might recall that a couple of years ago the media was full of stories about a Dark Web website called Silk Road. This was like an eBay for criminals, a place where you could buy illegal items such as drugs & weapons and engage criminals to carry out illegal activities on your behalf, hacking for example.

The Silk Road was eventually closed down by the authorities but similar sites still exist if you know where to look and how to access them.

The first step is to download the TOR software, it’s free and pretty easy to find. However there’s no Dark Web version of Google – you have to know your way around if you want to find the illegal stuff – I don’t and wouldn’t broadcast it even if I did know.

I may not be able to help with your journey to the Dark Web but if your Surface Web needs improving or your Deep Web needs surfacing to make it easy to find, then get in touch, andy@enterprise-oms.co.uk or give me a call- 01793 238020 and I’ll dive in and see what I can do.

Do you use a .EU domain?

MAshup of Union and EU flags, Image result for brexit

Brexit was always going to have problems and issues for businesses but none expected it to have an impact on business domain names.

Well, until Easter 2018 anyway, which was when a major problem for businesses was announced in well known and respected technology news site, The Register.

You probably chose your .EU domain for a really good reason, you want the world to know that either you are an EU-based business or your market is the EU, for example.

Brexit and the .EU domain

However, as a result of Brexit, the EU has announced that all .EU domains registered by UK businesses (and individuals) will be revoked on B-Day (Brexit Day) 31st March 2018

What this means is that if you are one of the 300,000 UK organisations or individuals who has registered a .EU domain you might well see your website disappear overnight.

Obviously, continental domain registrars may well take advantage of this, offering to take on your domain and “fix” the problem for a (presumably large) fee, but that also has issues. The European Commission has hinted it is unhappy with that arrangement too; they will no longer allow you to own an .eu domain (that’s their whole point), so you are putting yourself at some commercial risk (similar to not owning IP in any products you make), and the EU is legally bound to prefer “the good of the EU” in any contractual dispute. Thankfully though, there are alternatives:

What’s in a (domain) name?

It’s not just your web site that could be affected, your email system, security certificates for encryption and e-commerce, and possibly even remote access to company assets for sales staff might be impacted too.

It will vary, obviously, depending on how you are set up, but checking this now is very sensible.

Perhaps the best approach is to do two things

  1. Immediately register a suitable .UK domain, and
  2. Point your .EU web traffic to it as soon as possible.

You have a choice of .uk domain name, and you can still represent your EU connection in it, if that’s crucial. For example,

bloggs-transport.eu

might change to,

bloggs-transport-eu.uk

We realise this isn’t ideal, but the second name is safe as it can’t be affected by any disruption the EU Commission might cause. You would have normal rights to the name, under English law, and, if it’s done right, there’s almost a whole year for your clients to get used to your new URL. Thus the risk is minimised, and it becomes one aspect of Brexit that can’t hurt you further commercially.

If this change goes ahead—and this is much more likely than unlikely in our opinion—you have less than a year for clients to become used to the change. This isn’t something to hesitate over: the implication is that no redirection will be possible after 31st March 2019, so at that point your site will simply vanish off the internet. People may even think you’ve gone bust!

Right now, you have enough time for this NOT to become an expensive issue. The longer you leave this one, the more electronic business disruption is likely to cost you come Brexit day.

If you have a .eu domain and you are worried, please get in touch: 01793 238020 andy@enterprise-oms.co.uk, the fixes are mostly straightforward and inexpensive to implement (without disruption, if you act quickly enough).

007 in ‘For your GDPR Only’

MI6 headquartersWhen “M” has finished spymastering for the day, or pops out for a cheeky Nandos, we always see M locking the “Top Secret” files away in the office  safe. We know that’s so that no secrets will be discovered, even if an enemy spy (or the tea person) manages to gain access to the empty office.

In business, we need to be like “M”.

In a previous post I looked at Data Protection and the forthcoming General Data Protection Regulations (GDPR). However, I didn’t make it clear that the regulations don’t just apply to digital data stored on your IT systems and network but also apply to paper records too.

Anything that contains personal data, whether paper or digital, falls under the auspices of the Act, including the recordings from your CCTV cameras, phone systems (think “this call may be recorded for training purposes”) and biometric data – such as fingerprint or iris recognition systems used to unlock systems or grant access.

Keyboard with the word 'Privacy' overlaid

This means the files on your desk, the files in your filing cabinet, your paper archives as well as your electronic records, anything that includes personal data.

To start with, you need to ask yourself

  • Who has overall responsibility for the data you have and/or use?
  • What data are you holding, why are you holding it and where is it held?
  • Are your Privacy and Data Use Policies as good as they need to be?
  • How long do you need to keep data & how will you securely destroy it when you no longer need to keep it?
  • Who has legitimate access to it and who else can access it?
  • How secure is your building, your paper records and IT systems?
  • What happens out of normal business hours?
  • Can data be exported and removed without authorisation (to a USB key for example)?
  • Is your network connected to the internet and how secure is your connection?
  • Can your network be accessed remotely – is this secure?
  • Is your electronic data encrypted so, in the event of a breach, data cannot be accessed and used?
  • Can your network prevent unauthorised intrusion (hacking)?
  • How do you manage Subject Access Requests, (when someone requests to see the data you hold about them)?
  • How will you manage a data breach, whether it’s a hack, unauthorised file copy or unauthorised removal of paper records?

So, how can I help?

I can put you in touch with reliable IT companies and trusted partners

  • Blob figure staring, "James Bond like" down the barrel of a gunthat will be able to inventory all of your IT and data assets.
  • who’ll test your network to see how secure it is and whether hackers are likely to be able to gain access
  • who will secure your network from external threats (hacking) and ensure that your remote access requirements are reliable, easy to use and secure.
  • who will help you secure your data inside the organisation and set things up so that only appropriately authorised employees can access the data they need to do their job and no more.
  • who will secure your network so that it’s almost impossible for data to be copied onto a USB key or external hard drive and removed from the organisation
  • who will put transparent encryption in place which means that it doesn’t slow anything down but is so strong that only GCHQ or the NSA would be likely to crack it.

Take the first step now, by giving me a call on 01793 238020 or emailing andy@enterprise-oms.co.uk to find out how I can help mitigate data security risks and start preparing for GDPR guidelines.

WannaCry, Ransomware and Bitcoin

The recent “WannaCry” Ransomware attack that hit the NHS (and more than 200,000 other victims across 150 countries) has focused attention on the CryptoCurrency called Bitcoin.

There have been numerous calls to outlaw Bitcoin and other CryptoCurrencies but there’s a lot of mis-understanding and a belief that they are only used to fund criminal activities.

In fact, over the last couple of years there have been numerous articles in the mainstream media about Bitcoin. Most have focused on their use by the criminal fraternity, whether for the payment of Ransomware ransoms to decrypt company data through to the purchasing of illegal weapons and drugs on the Dark Web, including The Silk Road, a dark web site where drugs, weapons and illegal services were traded online – before the site was taken down by the FBI in 2014.

However, Bitcoin, and other digital currencies, are now experiencing a significant uplift in their use for legitimate purposes and we thought that this is an ideal time to send out an explanatory email so that you can be better informed.

We’ll be looking at

  • What is a digital/virtual currency?
  • What is a Bitcoin?
  • What is Distributed Ledger Technology / Blockchain?
  • How do I get digital money?
  • How can I spend digital money?
  • Where do I keep my Bitcoin?
  • How safe/secure is my digital money bank?

What is a digital/virtual currency?

A virtual currency is simply a digital form of money for online transactions. Virtual currencies only exist electronically, there’s no bank notes or coins and no bank deposits, hence their description as a Virtual Currency.

Virtual Currencies bring innovation and benefits to more traditional forms of banking and financial systems. Transactions are much cheaper and faster with international payments being much simplified due to freedom from exchange rate worries and bank transfer fees.

This means there are no currency exchange barriers, digital currencies are genuinely international, unaffected by national boundaries and traditional currency issues and associated exchange rate issues – until you want to exchange them for traditional cash.

The most well known Virtual Currency is Bitcoin although other examples include Dogecoin, Ether, Dash, Litecoin and Stellar.

In the early days, Virtual Currencies were seen as a way to pay for online transactions but these days you can use them as a form of payment in physical stores. There are even Bitcoin ATMs where you can buy and sell Bitcoins from your account – there are 20 in London alone and a total of 60 across the UK

What is a Bitcoin

All digital currencies only exist in the virtual form, being recorded in a public Distributed Ledger which is basically a secure database of digital currencies and which holds a record of every Bitcoin transaction

Bitcoins were one of the earliest forms of virtual currency, first introduced in 2008. In 2013 Bloomberg effectively endorsed the legitimacy of Bitcoin by testing Bitcoin on its trading terminals and later that year the US Federal Reserve gave their apparent blessing, stating that Bitcoin “may hold long-term promise, particularly if the innovations promote a faster, more secure and more efficient payment system” and is the most well known form of Digital Currency.

In 2014 our own HMRC classifies Bitcoin as assets or private money which means that no VAT will be charged on the mining of, or exchange of Bitcoin.

Later that year, Microsoft started accepting payment made by Bitcoin and a 2015 HMRC report on digital currencies further marked the acceptance of Virtual Currencies by mainstream financial services.

What is the Blockchain

The Blockchain is a database that records all Bitcoin transactions. It’s basically a distributed database, is totally separate from the banking industry and free from central interference.

Transactions are recorded in the form of payer x sends y bitcoins to payee z and payments are verified and validated and added to the Blockchain

How do I get digital money

Bitcoin Mining in IcelandBelieve it or not, it’s possible to make your own, legitimate, Bitcoin through a technique called “mining” which uses high performance computers to carry out sophisticated cryptological processing to effectively make new currency that’s then added to the Blockchain.

However, it’s not as easy at it sounds and most people simply buy their Bitcoins, and other virtual currencies, through more traditional routes – including the Bitcoin ATMs mentioned earlier in this article

How can I spend digital money

You can use Bitcoins to purchase traditional currencies, products and services and you can acquire Bitcoins in a similar manner.

Small amounts of Bitcoin can be traded. They are the millibitcoin (0.001 bitcoin), microbitcoin (0.0000001 bitcoin) and the satoshi which is the smallest amount and named after the inventor (0.00000001 bitcoin)

As noted earlier, transactions follow payer x sends y bitcoins to payee z formatAlthough transactions on the Blockchain are open to inspectionthe reason why Bitcoin is so attractive to criminals is that transactions are pseudonymous. This means that “payer x” is only identified by his or her Bitcoin address.

In 2014, Bitcoin Payment Service Provider (A PayPal for Bitcoin) started accepting Bitcoin payments for tickets and concession sales at the St. Petersburg Bowl in the USA and in 2015 Barclays started to accept Bitcoin, the first UK high street bank to do so. Over 100,000 establishments were accepting payment by Bitcoin by the end of 2015.

You can buy technology from Aria and Dell, pre-owned technology, media and games from CeX around the UK, you can sign up for language courses, buy a beer and a meal in a pub, book theatre tickets, accommodation, home and garden furniture, new windows and much more – full list of UK companies accepting Bitcoin here.

In 2013 a Bitcoin was worth $13 and at the time of writing a Bitcoin would cost $1,033.43 ( £830.81) having peaked in 2017 at $1216.73.

The downside is the lack of protection because virtual currencies lien outside of the established banking regulations, Bitcoin users are not protected by refund rights or chargebacks and transactions are non-reversible.

Where do I keep my Bitcoin?

Your Digital Wallet stores all the information required to transact bitcoins. Although they’re frequently described as a place to hold, or store your Bitcoins, the reality is that Bitcoins ONLY exist in the Blockchain and your Digital Wallet simply stores your credentials to access your Bitcoin holdings.

It’s similar to the way your debit card doesn’t store your money but allows you to access your account and arrange for the transfer for funds from your account to that of the seller.

How safe/secure is my digital money bank

Because your Virtual Currency is held centrally, there’s actually nothing to steal, in the conventional sense.

However, your Wallet needs to be secured. You need to use a strong password – and don’t forget it because there’s no password recovery routine. Lose your password and you lose your Bitcoin. You should keep your Wallet backed up, preferably in a number of locations, online, USB etc. Just as you would for your other computer data

Is traditional money dead?

Far from it, and it’s probably a long way from dying simply because each country likes to have it’s own currency regulations in place and the fear associated with the disruption that Virtual Currencies will cause.

As a result, banks are making it easier for customers to spend their traditional money. We say the introduction of cheques – now on the decline.

Credit and payment cards that facilitate the easy transfer of money. Internet banking, making it easier to manage our own funds.

Contactless payments speeding up transactions, Apple and Android Pay., facilitating payment by simply tapping your phone on a payment terminal and the migration of these services to Smart Watches.

Soon, you’ll have contactless payment capability added to pieces of jewellery (A payment wedding ring anyone?) followed by the embedding of a suitable chip under the skin of a fingertip.


However, as world governments become more centralised, the benefits of Virtual Currencies may begin to outweigh the pressures (and costs involved) to maintain more traditional Fiat based monetary systems and all we can suggest is that you watch this space.

And if you want some help, than give me a call on 01793 238020 or send an email to andy@enterprise-oms.co.uk and I’ll do everything I can to help/

How much did your last cup of coffee cost?

Cybercrime is everywhere these days, in 2016 the cost to the UK was over £1bn with more than 5.5m cyber offences taking place in the UK every year. That’s almost 50% of ALL UK crime.

Cup of coffee and coffee beansThere’s lots of advice on passwords, I regularly write about them, and other security measures that you can take but did you know that even a trip to your favourite coffee shop could end up being far more expensive than the price you pay for your Triple Grande Decaf Soy Latte Macchiato and blueberry muffin.

Imagine the scene, you’re between meetings and decide to drop into your favourite coffee shop for a cup of coffee, a cake and to tap into their Wi-Fi to read your emails, refresh your knowledge in time for your next meeting or simply to surf the web.

Spoof Wi-Fi Hotspot


Sign fro free wifi hotspot
When you sit down and try to log-on to the Wi-Fi there’s frequently a selection of hot-spots to choose from. How do you know which is the free service provided by the venue and which is a spoof.

It’s very easy to set up a Wi-Fi hot-spot using a mobile phone, Mi-Fi type of device or laptop and allow other users to connect through this free connection. This means that all of the traffic can then be intercepted by the person providing the spoof account. What sort of important information is passed from your laptop through this connection? It could be your details to access your online banking, the log-in to your company network or the necessary information required to access your corporate email account.

Time for a comfort break

Laptop and cup of coffeeThen the urge hits, you look around and see that everybody seems respectable enough so you head off to the toilet thinking that your laptop is safe on the table. After all, nobody would nick in sight of all those customers, staff and CCTV cameras would they?

You’d be wrong. Laptop tracking service provider, Prey, found that areas offering free Wi-Fi were the second most common target for  opportunistic laptop thefts, the only riskier place being left in a visible place in your car.

If stolen, it’s not only the inconvenience of replacing the laptop, reinstalling your applications and copying back your data [you do back-up your data don’t you?] it’s the additional costs that aren’t covered by your insurance.

The Ponemon Institute, a US cyber crime consultancy, put the real cost of the loss of a laptop and it’s data at nearly £31,000. This was broken down into £4,000 for the loss of Intellectual Property, forensics and legal bills adding around £1,500 with a staggering £24,500 attributable to the loss of income, customers and competitive advantage associated with a data breach

So, the next time you stop off for a cup of coffee and decide to log-on using their free Wi-Fi, just make sure you know which network that you’re connecting to and that you don’t leave your laptop unattended.

And if you want to talk about your cyber security, just give me a call on 01793 238020 or drop an email to andy@enterprise-oms.co.uk

Bluetooth Beacons

Belisha BeaconThe most well known type of beacon is probably the Belisha, the orange ball, containing a flashing light mounted on a striped pole and drawing attention to a zebra crossing.

Well, there’s a new type of beacon in town – the Bluetooth Beacon and businesses can use them in interesting and exciting ways.

What is a Bluetooth Beacon?

Basically, a Bluetooth Beacon is a low energy device (using button batteries that last for up to a year), that can be fixed almost anywhere and which transmits data and/or information to nearby portable electronic devices within 40-100 mtrs. Mobile phones and tablets in other words.

Major retail stores are starting to use Beacons to track customers as they move through the store. The Beacon can push marketing messages as customers get within range of relevant displays. Your iPhone may use a beacon to determine what section of a grocery store you’re in, see if anything on your shopping list is in that area, so you don’t forget it, and even push a discount voucher to encourage you to buy a particular brand.

Your Android phone could use a beacon to show on a map where you are and provide directions to where you want to go – in your language.

It’s not just for retail outlets though. If you are in business to business you could use a Beacon to push a message out to visitors offering a subscription to your newsletter or encourage a visitor to install your App. Museums could use Beacons to trigger pictures, audio tracks or videos as you walk past particular displays and exhibits.

You can even use Beacons to provide keyless access, your phone could use a beacon in your car to know it’s your vehicle and send an unlock signal to it, for example.

How do you use a Bluetooth Beacon

The first thing you need to do is decide what you are looking to achieve. You could

  • Push deals and offers
  • Share news
  • Encourage Newsletter Subscriptions
  • Drive engagement at events and shows
  • Help blind people explore locations
  • Push visitor information
  • Unlock doors

Use is only limited by your imagination!

At a trade show, for example – simply place your Beacon on your stand and push your message to any attendee who comes within range of your Beacon.

What’s the likely cost

Avvel X BeaconBeacons can be pretty inexpensive – the Avvel X Beacon (left) for example –

  • runs off a CR2477 button cell which lasts for up to 30 months,
  • has a range up to 100m,
  • is waterproof,
  • is easily programmable
  • 42mm square and 13.4mm thick
  • From £20.00 + VAT


The Next Step

Well, I’ve just ordered one of the Avvel X Beacons to see how it works and what can be done and as soon as I’ve learned how to get the most from it, I’ll post an update here.

In the meantime, if you need any help – get in touch. Give me a call on 01793 238020 or drop me a line, andy@enterprise-oms.co.uk

And remember.

Beacons just send out information, they don’t know who you are, don’t connect to your device, can’t harvest mobile phone numbers and don’t steal any data