NZ Herald
  • Home
  • Latest news
  • Herald NOW
  • Video
  • New Zealand
  • Sport
  • World
  • Business
  • Entertainment
  • Podcasts
  • Quizzes
  • Opinion
  • Lifestyle
  • Travel
  • Viva
  • Weather

Subscriptions

  • Herald Premium
  • Viva Premium
  • The Listener
  • BusinessDesk

Sections

  • Latest news
  • New Zealand
    • All New Zealand
    • Crime
    • Politics
    • Education
    • Open Justice
    • Scam Update
  • Herald NOW
  • On The Up
  • World
    • All World
    • Australia
    • Asia
    • UK
    • United States
    • Middle East
    • Europe
    • Pacific
  • Business
    • All Business
    • MarketsSharesCurrencyCommoditiesStock TakesCrypto
    • Markets with Madison
    • Media Insider
    • Business analysis
    • Personal financeKiwiSaverInterest ratesTaxInvestment
    • EconomyInflationGDPOfficial cash rateEmployment
    • Small business
    • Business reportsMood of the BoardroomProject AucklandSustainable business and financeCapital markets reportAgribusiness reportInfrastructure reportDynamic business
    • Deloitte Top 200 Awards
    • CompaniesAged CareAgribusinessAirlinesBanking and financeConstructionEnergyFreight and logisticsHealthcareManufacturingMedia and MarketingRetailTelecommunicationsTourism
  • Opinion
    • All Opinion
    • Analysis
    • Editorials
    • Business analysis
    • Premium opinion
    • Letters to the editor
  • Politics
  • Sport
    • All Sport
    • OlympicsParalympics
    • RugbySuper RugbyNPCAll BlacksBlack FernsRugby sevensSchool rugby
    • CricketBlack CapsWhite Ferns
    • Racing
    • NetballSilver Ferns
    • LeagueWarriorsNRL
    • FootballWellington PhoenixAuckland FCAll WhitesFootball FernsEnglish Premier League
    • GolfNZ Open
    • MotorsportFormula 1
    • Boxing
    • UFC
    • BasketballNBABreakersTall BlacksTall Ferns
    • Tennis
    • Cycling
    • Athletics
    • SailingAmerica's CupSailGP
    • Rowing
  • Lifestyle
    • All Lifestyle
    • Viva - Food, fashion & beauty
    • Society Insider
    • Royals
    • Sex & relationships
    • Food & drinkRecipesRecipe collectionsRestaurant reviewsRestaurant bookings
    • Health & wellbeing
    • Fashion & beauty
    • Pets & animals
    • The Selection - Shop the trendsShop fashionShop beautyShop entertainmentShop giftsShop home & living
    • Milford's Investing Place
  • Entertainment
    • All Entertainment
    • TV
    • MoviesMovie reviews
    • MusicMusic reviews
    • BooksBook reviews
    • Culture
    • ReviewsBook reviewsMovie reviewsMusic reviewsRestaurant reviews
  • Travel
    • All Travel
    • News
    • New ZealandNorthlandAucklandWellingtonCanterburyOtago / QueenstownNelson-TasmanBest NZ beaches
    • International travelAustraliaPacific IslandsEuropeUKUSAAfricaAsia
    • Rail holidays
    • Cruise holidays
    • Ski holidays
    • Luxury travel
    • Adventure travel
  • Kāhu Māori news
  • Environment
    • All Environment
    • Our Green Future
  • Talanoa Pacific news
  • Property
    • All Property
    • Property Insider
    • Interest rates tracker
    • Residential property listings
    • Commercial property listings
  • Health
  • Technology
    • All Technology
    • AI
    • Social media
  • Rural
    • All Rural
    • Dairy farming
    • Sheep & beef farming
    • Horticulture
    • Animal health
    • Rural business
    • Rural life
    • Rural technology
    • Opinion
    • Audio & podcasts
  • Weather forecasts
    • All Weather forecasts
    • Kaitaia
    • Whangārei
    • Dargaville
    • Auckland
    • Thames
    • Tauranga
    • Hamilton
    • Whakatāne
    • Rotorua
    • Tokoroa
    • Te Kuiti
    • Taumaranui
    • Taupō
    • Gisborne
    • New Plymouth
    • Napier
    • Hastings
    • Dannevirke
    • Whanganui
    • Palmerston North
    • Levin
    • Paraparaumu
    • Masterton
    • Wellington
    • Motueka
    • Nelson
    • Blenheim
    • Westport
    • Reefton
    • Kaikōura
    • Greymouth
    • Hokitika
    • Christchurch
    • Ashburton
    • Timaru
    • Wānaka
    • Oamaru
    • Queenstown
    • Dunedin
    • Gore
    • Invercargill
  • Meet the journalists
  • Promotions & competitions
  • OneRoof property listings
  • Driven car news

Puzzles & Quizzes

  • Puzzles
    • All Puzzles
    • Sudoku
    • Code Cracker
    • Crosswords
    • Cryptic crossword
    • Wordsearch
  • Quizzes
    • All Quizzes
    • Morning quiz
    • Afternoon quiz
    • Sports quiz

Regions

  • Northland
    • All Northland
    • Far North
    • Kaitaia
    • Kerikeri
    • Kaikohe
    • Bay of Islands
    • Whangarei
    • Dargaville
    • Kaipara
    • Mangawhai
  • Auckland
  • Waikato
    • All Waikato
    • Hamilton
    • Coromandel & Hauraki
    • Matamata & Piako
    • Cambridge
    • Te Awamutu
    • Tokoroa & South Waikato
    • Taupō & Tūrangi
  • Bay of Plenty
    • All Bay of Plenty
    • Katikati
    • Tauranga
    • Mount Maunganui
    • Pāpāmoa
    • Te Puke
    • Whakatāne
  • Rotorua
  • Hawke's Bay
    • All Hawke's Bay
    • Napier
    • Hastings
    • Havelock North
    • Central Hawke's Bay
    • Wairoa
  • Taranaki
    • All Taranaki
    • Stratford
    • New Plymouth
    • Hāwera
  • Manawatū - Whanganui
    • All Manawatū - Whanganui
    • Whanganui
    • Palmerston North
    • Manawatū
    • Tararua
    • Horowhenua
  • Wellington
    • All Wellington
    • Kapiti
    • Wairarapa
    • Upper Hutt
    • Lower Hutt
  • Nelson & Tasman
    • All Nelson & Tasman
    • Motueka
    • Nelson
    • Tasman
  • Marlborough
  • West Coast
  • Canterbury
    • All Canterbury
    • Kaikōura
    • Christchurch
    • Ashburton
    • Timaru
  • Otago
    • All Otago
    • Oamaru
    • Dunedin
    • Balclutha
    • Alexandra
    • Queenstown
    • Wanaka
  • Southland
    • All Southland
    • Invercargill
    • Gore
    • Stewart Island
  • Gisborne

Media

  • Video
    • All Video
    • NZ news video
    • Herald NOW
    • Business news video
    • Politics news video
    • Sport video
    • World news video
    • Lifestyle video
    • Entertainment video
    • Travel video
    • Markets with Madison
    • Kea Kids news
  • Podcasts
    • All Podcasts
    • The Front Page
    • On the Tiles
    • Ask me Anything
    • The Little Things
  • Cartoons
  • Photo galleries
  • Today's Paper - E-editions
  • Photo sales
  • Classifieds

NZME Network

  • Advertise with NZME
  • OneRoof
  • Driven Car Guide
  • BusinessDesk
  • Newstalk ZB
  • Sunlive
  • ZM
  • The Hits
  • Coast
  • Radio Hauraki
  • The Alternative Commentary Collective
  • Gold
  • Flava
  • iHeart Radio
  • Hokonui
  • Radio Wanaka
  • iHeartCountry New Zealand
  • Restaurant Hub
  • NZME Events

SubscribeSign In
Advertisement
Advertise with NZME.
Home / Business

Juha Saarinen: How to protect yourself from phishers

Juha Saarinen
By Juha Saarinen
Tech blogger for nzherald.co.nz.·NZ Herald·
16 Aug, 2022 05:00 PM4 mins to read

Subscribe to listen

Access to Herald Premium articles require a Premium subscription. Subscribe now to listen.
Already a subscriber?  Sign in here

Listening to articles is free for open-access content—explore other articles or learn more about text-to-speech.
‌
Save

    Share this article

    Reminder, this is a Premium article and requires a subscription to read.

Plug one of these keys into your device to foil phishers. Photo / Juha Saarinen

Plug one of these keys into your device to foil phishers. Photo / Juha Saarinen

Juha Saarinen
Opinion by Juha Saarinen
Tech writer for NZ Herald.
Learn more

OPINION:

One piece of feedback on my column about CERT NZ's advisory on how to create strong passwords was that the most effective defence we have against phishing is too complicated for most people to use.

That's hardware security keys. And it is true that plugging in what security geeks call multi-factor authentication or MFA, with a little USB, near field communications, or a secondary device to log in adds complexity.

Losing a key and trying to get back in through an alternative method if you don't have a spare security device with you can also be a lengthy chore.

Despite all that, now's the time to seriously consider adding that layer of protection.

Advertisement
Advertise with NZME.

The reason for that are four recent high-profile phishing attacks, three of which succeeded.

Network equipment vendor Cisco had some staffers successfully phished, ditto communications provider Twilio. In both cases, the phishing techniques used were really advanced, cleverly designed to appear as legitimate messages, with infrastructure like websites set up last minute before the attacks, to avoid detection.

Security journalist Dan Goodin of Conde Nast-owned Ars Technica was also hit recently.

Advertisement
Advertise with NZME.

Goodin's very experienced and knowledgeable about "business email compromise" or BEC, and other phishing techniques. Even so, he fell for a phish.

Whereas in the past phishing and social engineering attempts have been quite crude and relied on volume rather than sophistication, they're now really good. They have every chance to succeed,

What are the phishers after then? In the case of Twilio, the follow-up attack on a small number of the open source, encrypted messaging app Signal seems to have been one motive.

Signal is very security oriented and hard to break into, which is why it's popular with users in exposed positions. That includes politicians, activists, journalists, hell, even the occasional opinion columnist uses Signal.

In other cases, it could be someone either wanting to empty your online-accessible bank account or laundering money through it, after phishing your login credentials. Either scenario would cause you a world of pain.

Other phishing phun include getting access to social media accounts to dent someone's reputation, spying in general, or working out someone's whereabouts for a beating or worse. You can do lots with information gleaned from phishing and what attackers are after on any given occasion is anyone's guess.

Where the phishers' attack failed was against another company whose network you most probably have connected to without realising, one which is very security oriented too, namely content delivery network and reverse proxy provider Cloudflare.

Cloudflare was also hit by the Twilio hackers who had got hold of employees' phone numbers and sent them text messages to check new schedules on what appeared to be a legitimate site.

Advertisement
Advertise with NZME.

"This was a sophisticated attack targeting employees and systems in such a way that we believe most organisations would be likely to be breached," Cloudflare wrote in its post-mortem of the attack.

Even though some employees were fooled and provided their credentials to the phishing site, which was also able to capture short-lived two-factor authentication codes generated by special apps and relay them to attackers who could then try to log in to Cloudflare staff accounts.

Despite that well-thought out attack, they couldn't get past Cloudflare staff using hardware keys.

I wouldn't go as far as Goodin and say hardware keys are unphishable. However, as Google, which also provides them to employees and which uses the security devices for its Advanced Protection Programme for journalists, politicians and other exposed people says, no staffer who uses hardware keys has been phished yet.

Sensibly enough, Cloudflare did not penalise the staff who fell for the phish. Doing so is counterproductive as it can not only get in the way of legitimate communications, but can also deter people from reporting phishing.

So yes, while we still email and message each other links and attachments, adding that hardware, multi factor authentication protection is totally worth the additional hassle.

The threat landscape has shifted, and you need to move along with it.

Save

    Share this article

    Reminder, this is a Premium article and requires a subscription to read.

Latest from Business

Media Insider

TVNZ boss on the future of the 6pm news, Shortland Street - and a move into pay TV

19 Jun 09:37 AM
Premium
Shares

Market close: GDP beats forecasts but NZ sharemarket dips

19 Jun 06:24 AM
Premium
Business

Innovation milestone: NZ approves lab-grown quail for consumption

19 Jun 04:34 AM

Audi offers a sporty spin on city driving with the A3 Sportback and S3 Sportback

sponsored
Advertisement
Advertise with NZME.

Latest from Business

TVNZ boss on the future of the 6pm news, Shortland Street - and a move into pay TV

TVNZ boss on the future of the 6pm news, Shortland Street - and a move into pay TV

19 Jun 09:37 AM

Will this be Simon Dallow's swansong year as the 6pm newsreader?

Premium
Market close: GDP beats forecasts but NZ sharemarket dips

Market close: GDP beats forecasts but NZ sharemarket dips

19 Jun 06:24 AM
Premium
Innovation milestone: NZ approves lab-grown quail for consumption

Innovation milestone: NZ approves lab-grown quail for consumption

19 Jun 04:34 AM
$162k in cash, almost $400k in equipment seized in scam crackdown last year

$162k in cash, almost $400k in equipment seized in scam crackdown last year

19 Jun 04:29 AM
Gold demand soars amid global turmoil
sponsored

Gold demand soars amid global turmoil

NZ Herald
  • About NZ Herald
  • Meet the journalists
  • Newsletters
  • Classifieds
  • Help & support
  • Contact us
  • House rules
  • Privacy Policy
  • Terms of use
  • Competition terms & conditions
  • Our use of AI
Subscriber Services
  • NZ Herald e-editions
  • Daily puzzles & quizzes
  • Manage your digital subscription
  • Manage your print subscription
  • Subscribe to the NZ Herald newspaper
  • Subscribe to Herald Premium
  • Gift a subscription
  • Subscriber FAQs
  • Subscription terms & conditions
  • Promotions and subscriber benefits
NZME Network
  • The New Zealand Herald
  • The Northland Age
  • The Northern Advocate
  • Waikato Herald
  • Bay of Plenty Times
  • Rotorua Daily Post
  • Hawke's Bay Today
  • Whanganui Chronicle
  • Viva
  • NZ Listener
  • Newstalk ZB
  • BusinessDesk
  • OneRoof
  • Driven Car Guide
  • iHeart Radio
  • Restaurant Hub
NZME
  • About NZME
  • NZME careers
  • Advertise with NZME
  • Digital self-service advertising
  • Book your classified ad
  • Photo sales
  • NZME Events
  • © Copyright 2025 NZME Publishing Limited
TOP