Stay Safe Online

Identity theft is a rapidly growing threat, and it thrives on poor security practices. Your best defense is to build good security habits and encourage everyone you know to do the same.

While computers and online services have become a familiar and ordinary part of our work and daily life, the Internet has many perils.

  • Information you post on the Internet and records of sites you have visited can be used for targeted advertising and less savory purposes.
  • Scam artists attempt to trick you into giving away your money, or giving away information that will let them steal your money.
  • If your computer is connected to the Internet, it is under constant attack, not by hackers engaged in sport but by criminal enterprises seeking to exploit computing resources to steal information, send spam emails, distribute illicit material, or attack other computers.

In this section

Security & Policy Blog Posts

  • Tens of thousands of Twitter accounts have been compromised in a recent hack attack in which more than 55,000 passwords were leaked and posted to Pastebin by anonymous hackers. You should probably change your Twitter password today.
  • A mistake by Apple can cause Mac OS X 10.7.3 (Lion) to store your login password on the hard drive in clear text.
  • Adobe Flash Player Security Update
  • A memo has been sent to the President's Cabinet to help raise awareness of the Information Security and Privacy Program.

    Recent Security Bulletins

  • A remote code execution vulnerability exists such that an attacker who successfully exploited this vulnerability could run abitrary code on the target system, then install programs; view, change, or delete data; or create new accounts with full rights.
  • "Flashback" is Mac-specific malware that is currently spreading via a recently patched Java vulnerability
  • A remote code execution vulnerability exists such that an attacker who successfully exploited this vulnerability could run abitrary code on the target system, then install programs; view, change, or delete data; or create new accounts with full rights.
  • Warning about phone calls requesting information or requesting users to take action to compromise computers.