ISHPI

Footprints in the Cloud
ISHPI CyberBytes Newsletter Vol 2 Issue 2
Read all CyberBytes Newsletters

As we look to spring and the warmer weather, it is a great time to talk about the footprints we all leave behind as part of our daily activities and how to be better and reduce them. “Rob, what does the environment and carbon footprints have to do with Cyber Security?” Oh, my apologies for that misleading opening sentence, not our carbon footprint, our Digital Footprint! “What is a digital footprint?” Good question and ironically it is a little like that other one, it is the residual of your digital activity that remains after you engage in anything digital. A more formal definition:

Digital Footprint – The unique trail of data pertaining to a user’s activities, actions, communications, and transactions on the internet.

Active: When you intentionally share information on social media or other websites (i.e., online forums Reddit, Tumblr, Yelp, Facebook, Tik-Toc, X, etc…)
Passive: Information collected without your knowledge or awareness
(i.e., cookies left and read by websites you visit)

Want to see where you fall in the digital footprint area? Take this quick quiz (from CDSE.edu), each Y = 1 point:

  1. Do you make purchases online?
  2. Have you signed up for coupons by creating an account?
  3. Have you registered or subscribed to newsletters or blog updates?
  4. Have you downloaded and used shopping apps?
  5. Have you opened a new credit card account?
  6. Do you use a mobile banking app?
  7. Have you bought or sold stocks?
  8. Have you ever registered your email address with a gym?
  9. Do you receive health care?
  10. Have you ever used apps to track your activities and workouts?
  11. Do you subscribe to an online publication or news source?
  12. Have you ever reposted articles and information you’ve read?
  13. Do you use social media on your computer or devices?
  14. Do you interact with friends online?
  15. Have you ever shared information, data, and photos with your online connections?
  16. Have you ever joined a dating site or app?

Results:
<5 = A digital footprint that is less complex than most internet users
5-11 = A digital footprint that is average for most internet users
12+ = A digital footprint that is more complex than most internet users

So, what does this mean for you? Well, the higher the score the more likely the risks of being a target of social engineering, phishing, foreign information collection, targeted disinformation, and identity theft. “OK Rob, so yeah, that is not good, how can I protect myself?” I’m glad you asked, here is a list of things you should do regularly:

  1. Limit the amount of data intentionally placed on the internet.
    • Limit shared information on social media – more information shared = more information others have about you (including people you don’t know)
    • Occasionally clean browser cookies and other tracking files on your personal devices – You can configure your browser to delete after each session, see the image below on how much passive tracking is happening every time you are on the internet.
  2. Tighten up privacy settings on social media – Limit who can see and share information you post.
  3. Do not open attachments or access links from unknown or questionable sources– I know, duh! But it still happens so it is on the list.
  4. Anonymize, disallow, or restrict location access of tracking by applications – Have a look at using the duckduckgo browser, very good at blocking and protecting (see 1b above).
  5. Install and keep antivirus software updated on personal devices.
  6. Periodically review both financial/credit and medical/health information.
  7. Setup credit reporting and card activity notifications.
  8. Continually update passwords and password protections, especially after being informed of a data breach.

As a reference for 1b and 4 above, here is what the different sites TRIED to track, without my knowledge this week, this is only showing the last 6 site visits:

In closing, feel free to leave as much or little footprint as you like. I’m not saying all the information is dangerous or not actually benefiting the app or browsing experience, I’m just saying be aware and know that the ability to piece information together about you by reading your ACTIVE and PASSIVE footprint information is there, very easy to do, and not everyone is looking to use that info about you for your benefit.

Newsletter By:  Rob Collings, ISHPI’s VP of Cybersecurity | CISO

April 1, 2024

Share this Newsletter