None of Google's 85,000 employees have been successfully phished in over a year — and it's because of a simple $20 product anyone can use
- Google told Business Insider that none of its employees had been successfully phished since it started requiring them to use security keys to log in.
- Phishing, or using misleading emails to steal passwords, is one of the most common ways people get hacked.
- Google attributes its success to products called security keys, or USB devices that you need in addition to a password to log in to a protected account.
One of the most common ways that people get hacked is called phishing or spearphishing.
Basically, attackers craft an email that looks just like something you'd normally click on, like a bill or an email telling you to change your password. Unsuspecting people click on the link in the phishing email, leading them to a site designed to look legitimate. The victim plugs in their username and password, unwittingly giving it to the attacker. Now there's a good chance that account will be hacked.
Spearphishing was one of the main ways Russian spies were able to break into the Democratic National Committee's network before the 2016 US election, the Justice Department says.
It's a big problem for businesses. You can make sure your computers are as secure as possible, but all it takes is one employee with access to sensitive data who gets fooled by an email to cause a bad breach.
One company, however, seems to have solved the phishing problem: Google. And it's all because of a $20 gadget called a security key, which Google requires its employees to use.
None of Google's 85,000 employees have been successfully phished on their work accounts since it started requiring security keys to log in, the company said.
"We have had no reported or confirmed account takeovers since implementing security keys at Google," Google told Business Insider.
Google started requiring employees to use physical security keys in early 2017, according to Brian Krebs, the security journalist who first reported Google's success against phishing attempts.
Your company may already require you to have two-factor authentication turned on, meaning that when you log in with a username and password, you have to enter a second code, usually texted to you or delivered through an app.
Google took this one step further and required all employees to start using security keys, according to Krebs. Instead of getting a text after entering your password, you merely plug the security key into a USB port on your computer and press a button.
That's a pretty big success for such a large company. Google has a lot of sensitive user data, so it's very encouraging to know its employees aren't getting phished.
You can use a security key with your own Gmail account. YubiKey models compatible with USB, USB-C, and mobile devices are available from Yubico.
In October, Google launched an advanced-protection program involving security keys for people at the highest risk of being phished, including journalists, business leaders, and activists. Google has also worked with various industry groups, such as the FIDO Alliance, to develop security-key technology called U2F.
A 2016 Google study found that text-message or app-based two-factor authentication, sometimes called "one-time password," had an average failure rate of 3%, while the U2F or security-key approach had a 0% failure rate.
There are more details about how Google's approach to authentication and login security is starting to pay off at Krebs on Security.
- Google Cloud Data Engineer
- Up to £90,000 Base
Google Cloud Data Engineer London Salary: Up to £90,000 Base We are currently working with a leading Google Cloud partner who are currently looking for a Google Cloud Data Engineer in London. The Google Cloud Data Engineer will be responsible for projects designing and implementing data cataloguing platforms using Google Cloud. Current Experience Required: Google Cloud (MUST be Google Cloud Professional Engineer Certified and worked on recent GCP/Google Cloud Projects). Data Analytics (Data Engineering, Data Mining, Data Cataloguing etc.) Cloud PUB / SUB Candidates must be UK based and commutable to London. Candidates outside of the EU can not be sponsored Apply for more information or call Peter Georgiou on 02086634030. Ref: PG7692
- Microsoft Azure Sales Consultant
- Up to £100,000 Base + OTE
DCL are currently working on behalf one of the fastest growing service providers in London who are on the lookout for a consultative Microsoft Azure Sales Consultant. The Microsoft Azure Sales Consultant will be responsible for selling (opening and closing new business opportunities new business) and being the SME in all things Cloud providing support to other members in the sales team. Preference will be given to the Microsoft Azure Sales Consultant who possesses Exceptional knowledge of Cloud Technology (Public / Private / Hybrid.). Current experience with technology such as Azure, AWS, Office 365 is required Proven sales experience of identifying and closing new business within the Cloud market. Must be currently selling into the enterprise market. Consistency on tenure in current and past roles. New business background is a must In return you will be working for a successful, growing SME organisation with excellent training and sales support from pre-sales, post-sales, project management, service management, bid management, pricing and customer service. Candidates must be UK Based. sponsorship can not be provided for this role. Reference Number: BD7690 (Cloud Sales Jobs, Cloud Computing Jobs, Cloud Computing Sales)
- Senior Incident Cyber Response Consultant
- Up to £75,000 Base
Senior Incident Cyber Response Consultant with Forensic experience is needed to join a global consultancy whose cyber business unit are continuing to their investment in the growth of their team. From my perspective, as a recruitment partner, this is a particularly interesting and exciting opportunity. Not only is the team in an active growth mode, but they have varied, high profile and interesting projects for their team. Globally recognised. This is an opportunity to drive and grow a career. Experienced Senior Incident Cyber Response Consultant is needed to help take clients through the complete IR / triage process. The position is be client facing and will be expected to engage with clients at a commercial level. Proactive IR planning is also key to the position. The Senior Incident Cyber Response Consultant will not hold a sales target, but any previous experience in identifying and generating revenue is highly sort after. A broad forensic background would be highly desirable also. An ideal Senior Incident Cyber Response Consultant will be CREST CCIR, CCIM certified. Experience with forensics is highly desirable. Any of the following are very desirable also CREST Certified Network Intrusion Analyst (CCNIA) CREST Certified Host Intrusion Analyst (CCHIA) CREST Certified Malware Reverse Engineer (CCMRE) CREST Practitioner Intrusion Analyst (CPIA) An individual must be London commutable Key attributes should also include; stakeholder engagement, mentoring of team members, a collaborative working style. Technical experience must include; demonstrable experience within cyber incident response, Forensic, cyber etc. Additional certifications could / should include GIAC certified (Intrusion analyst, incident handler, forensic handler) The opportunity for an individual to conduct malware research and analysis is actively promoted. Career development and the opportunity to influence, apply today for more information or call Chris Holt on 07884666351 or 02086634030 or email firstname.lastname@example.org Unfortunately, our client are unable to provide sponsorship for this opportunity. Candidates must be UK based. Ref: CH7679 (Incident Response Jobs, CREST Jobs, Digital Forensics Jobs, IR Jobs)
- Principal Electrical Engineer
- Salary: Up to £90,000 Base + Bonus
Principal Electrical Engineer Location: London Salary: Up to £90,000 Base + Bonus A Principal Electrical Engineer is needed for a state of the art, London based Data Centre provider. The Principal Electrical Engineer will be responsible for all of the Mechanical & Electrical components (support, development/design etc.) within our clients Data Centre’s. Other responsibilities include but not limited to; Commissioning, approving, design & review/improvement of new data centre infrastructure Commercial’s (Contract negotiation, project finances etc.) Project management Training/Development of other staff General engineering tasks Requirements HND / Degree in Engineering or equivalent. Must have current/recent experience (ideally in a senior position) within a mechanical & electrical position within a Data Centre environment Candidates must be UK based and unfortunately, our client are unable to provide sponsorship Ref: PG7600 (M&E Jobs, Mechanical & Electrical Jobs, Engineering Jobs, Data Centre Jobs, Data Center Jobs)