{"id":2965,"date":"2016-10-31T10:05:36","date_gmt":"2016-10-31T16:05:36","guid":{"rendered":"http:\/\/www.whitefirdesign.com\/blog\/?p=2965"},"modified":"2016-10-31T10:05:36","modified_gmt":"2016-10-31T16:05:36","slug":"sitelock-provides-a-good-example-of-how-security-companies-are-working-against-improving-cybersecurity","status":"publish","type":"post","link":"https:\/\/www.whitefirdesign.com\/blog\/2016\/10\/31\/sitelock-provides-a-good-example-of-how-security-companies-are-working-against-improving-cybersecurity\/","title":{"rendered":"SiteLock Provides A Good Example of How Security Companies Are Working Against Improving Cybersecurity"},"content":{"rendered":"<p>Looking at the news recently you wouldn&#8217;t have to look hard to see that cyber security isn&#8217;t in good shape and that isn&#8217;t a new problem.\u00a0A big part of the problem is the security companies, the organizations that are supposed to be improving things are in a lot of cases making things worse instead. For example, on the one hand we have a situation where many people are not doing the basics, while security companies are pushing more advanced security products and services, which they don&#8217;t provide evidence that would provide any value over doing the basics (or even evidence they would provide the protection to same degree as doing the basics). What make this issue stand out so much is that even the companies themselves are often failing to the basics, we recently looked at one cybersecurity company that claims to have \u201cclients in the intelligence community,\u00a0DoD\u00a0and nearly every cabinet agency\u201d and <a href=\"http:\/\/www.whitefirdesign.com\/blog\/2016\/10\/10\/cyber-security-companys-poor-website-security-reminder-of-industrys-lack-of-focus-on-actually-improving-security\/\">isn&#8217;t bothering to keep the software running the various parts of their website up to date while telling the public they need to take advanced measure to protect their websites<\/a>.<\/p>\n<p>October is\u00a0National Cyber Security Awareness month, which\u00a0unfortunately isn&#8217;t a time\u00a0when these companies consider that they are not having a positive impact, but instead yet another chance to hock their wares. Case in point is SiteLock, over at their at their WordPress focused blog, The District, they have a post,\u00a0<a href=\"https:\/\/wpdistrict.sitelock.com\/blog\/national-cyber-security-awareness-wordpress\/\">National Cyber Security Awareness Month \u2013 What it Really Means for WordPress Users<\/a>. In that post they include a list of simple security steps. Since the post\u00a0is WordPress focused you would expect that making sure WordPress and it plugins\u00a0are up to date would be one of them, but it isn&#8217;t. Here is what they listed below:<\/p>\n<blockquote>\n<h3>Simple Security Steps to Implement\u00a0Today<\/h3>\n<p>Some of these may sound simple, but if not implemented can put you at risk.<\/p>\n<ul>\n<li>Never write down your username and passwords. Use a password manager tool like LastPass, 1password or others.<\/li>\n<li>Use anti-virus software on your computer.<\/li>\n<li>Always use a Virtual Private Network when connecting to public wifi. Learn <a href=\"https:\/\/wpdistrict.sitelock.com\/blog\/go-for-the-gold-in-security-while-traveling\/\" target=\"_blank\">more about VPNs here<\/a>.<\/li>\n<li>Install a <a href=\"https:\/\/wpdistrict.sitelock.com\/products\/?prod=waf\">Web Application Firewall<\/a> on your website.<\/li>\n<\/ul>\n<\/blockquote>\n<p>Instead of updating the software they suggested using a web application firewall and they linked to their service that includes that. If you go to the page with the <a href=\"https:\/\/www.sitelock.com\/web-application-firewall\">details of their WAF<\/a>\u00a0you will find that they don&#8217;t provide any evidence, much less independent third-party evidence, that this provides any protection at all (not even from rigged testing, like they recently <a href=\"http:\/\/www.whitefirdesign.com\/blog\/2016\/10\/05\/would-you-be-surprised-to-hear-that-sitelocks-idea-of-independent-testing-doesnt-involve-actual-independence\/\">did for another part of their service<\/a>).<\/p>\n<p>Actually updating your WordPress plugins would actual make you more secure, as vulnerabilities are frequently fixed in new versions, but telling you that wouldn&#8217;t make them money.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Looking at the news recently you wouldn&#8217;t have to look hard to see that cyber security isn&#8217;t in good shape and that isn&#8217;t a new problem.\u00a0A big part of the problem is the security companies, the organizations that are supposed to be improving things are in a lot of cases making things worse instead. For &hellip; <a href=\"https:\/\/www.whitefirdesign.com\/blog\/2016\/10\/31\/sitelock-provides-a-good-example-of-how-security-companies-are-working-against-improving-cybersecurity\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;SiteLock Provides A Good Example of How Security Companies Are Working Against Improving Cybersecurity&#8221;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[25],"tags":[39],"class_list":["post-2965","post","type-post","status-publish","format-standard","hentry","category-bad-security","tag-sitelock"],"_links":{"self":[{"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/posts\/2965","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/comments?post=2965"}],"version-history":[{"count":3,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/posts\/2965\/revisions"}],"predecessor-version":[{"id":2994,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/posts\/2965\/revisions\/2994"}],"wp:attachment":[{"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/media?parent=2965"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/categories?post=2965"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/tags?post=2965"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}