Have you seen the news? Scary, huh! So if you are a small business and you use consultants ask them if they use two factor authentication in order to
[See the full post at: Patch Lady – ransomware attacks]
Susan Bradley Patch Lady/Prudent patcher
![]() |
Patch reliability is unclear. Unless you have an immediate, pressing need to install a specific patch, don't do it. |
SIGN IN | Not a member? | REGISTER | PLUS MEMBERSHIP |
Home » Forums » Newsletter and Homepage topics » Patch Lady – ransomware attacks
Tags: Patch Lady Posts
Have you seen the news? Scary, huh! So if you are a small business and you use consultants ask them if they use two factor authentication in order to
[See the full post at: Patch Lady – ransomware attacks]
Susan Bradley Patch Lady/Prudent patcher
Having a quick look at Duo it seems to be a 3rd party site (Cisco) through which you connect to your site. Effectively you block external access except from the Duo site.
cheers, Paul
Not really, Duo adds an additional layer to specific services/protocols such as RDP which enforces a 2FA prompt. For example, if you install the Duo RDP component on a Windows box and configure it in the Duo web panel, anyone who subsequently connect to that box using RDP will be prompted to complete 2FA before they are allowed access.
I use the free tier on all my home servers so now I can get a 2FA prompt on my phone whenever I RDP on, it’s a great free way to add some extra security.
If you have a paid up subscription you can do more advanced stuff like geofencing e.g. “deny connections from all countries except US/UK”.
Duo is great and one of my clients uses it for DoD stuff, but most services offer 2FA natively. Our business is basically built around Teamviewer, and we enforce 2FA and whitelisting to guarantee our clients will not get hacked with it (which has happened prior that policy). We also rely on Dropbox, and it also supports 2FA natively. All of these work off the Google Authenticator app, so they’re all quickly accessible from the same place. Very handy.
Here is a link to the article – it doesn’t appear to be included in your post, Susan.
https://www.npr.org/2019/08/20/752695554/23-texas-towns-hit-with-ransomware-attack-in-new-front-of-cyberassault
I think they are going after small towns because the small towns are likely less vigilant on IT issues such as doing regular backups.
On the bright side (if there is a bright side), a really small town could scrap the compromised system and start over from scratch, because there aren’t a huge number of people who would be affected. That might be cheaper than paying the ransom; and as a bonus, they could build a more secure system from the ground up.
On the bright side (if there is a bright side), a really small town could scrap the compromised system and start over from scratch, because there aren’t a huge number of people who would be affected. That might be cheaper than paying the ransom; and as a bonus, they could build a more secure system from the ground up.
That’ll work as long as they have some sort of data backup; otherwise, they’re going to get sued time & time again by folks who seek to make money off the fact that they can’t comply with their legal obligation to fulfill public records requests.
Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.
AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments.
Welcome to our unique respite from the madness.
It's easy to post questions about Windows 11, Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.
Want to Advertise in the free newsletter? How about a gift subscription in honor of a birthday? Send an email to sb@askwoody.com to ask how.
Mastodon profile for DefConPatch
Mastodon profile for AskWoody
Home • About • FAQ • Posts & Privacy • Forums • My Account
Register • Free Newsletter • Plus Membership • Gift Certificates • MS-DEFCON Alerts
Copyright ©2004-2025 by AskWoody Tech LLC. All Rights Reserved.