Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Attacks/Breaches

Study: Users Have False Sense of Security

Over 90% think they're pretty safe on the Internet, but about half of them are at risk, Verizon says

Despite almost daily reports of security breaches and identity theft, most end users still think their systems are pretty safe. But they're wrong, according to study results released last week by Verizon.

Working with research firm iTracks, Verizon asked 545 end users how secure their systems were from common threats such as viruses and spyware. Some 92 percent said they felt "safe" or "somewhat safe," and many of them cited the presence of antivirus or anti-spyware tools as a key reason.

Verizon then conducted a vulnerability assessment of the respondents and found that 58 percent of them were at risk of harboring spyware and 45 percent were at risk of contracting viruses.

"Internet security protection is like a smoke alarm," said Bill Heilig, vice president for Verizon broadband services. "As long as it works, it's great. But with a dead battery, it's worse than no smoke alarm at all, because it creates a false sense of security. That's the position that most Internet consumers find themselves in today, and what they don't know is definitely hurting them."

About 19 percent of the respondents had turned their personal firewalls off, Verizon said.

The study is part of Verizon's effort to promote its new Verizon Security Advisor service, which offers a free security assessment to end users.

— Tim Wilson, Site Editor, Dark Reading

  • Verizon Communications Inc. (NYSE: VZ)

    Tim Wilson is Editor in Chief and co-founder of Dark Reading.com, UBM Tech's online community for information security professionals. He is responsible for managing the site, assigning and editing content, and writing breaking news stories. Wilson has been recognized as one ... View Full Bio

    Comment  | 
    Print  | 
    More Insights
  • Comments
    Newest First  |  Oldest First  |  Threaded View
    When It Comes To Security Tools, More Isn't More
    Lamont Orange, Chief Information Security Officer at Netskope,  1/11/2021
    US Capitol Attack a Wake-up Call for the Integration of Physical & IT Security
    Seth Rosenblatt, Contributing Writer,  1/11/2021
    IoT Vendor Ubiquiti Suffers Data Breach
    Dark Reading Staff 1/11/2021
    Register for Dark Reading Newsletters
    White Papers
    Video
    Cartoon
    Current Issue
    2020: The Year in Security
    Download this Tech Digest for a look at the biggest security stories that - so far - have shaped a very strange and stressful year.
    Flash Poll
    Assessing Cybersecurity Risk in Today's Enterprises
    Assessing Cybersecurity Risk in Today's Enterprises
    COVID-19 has created a new IT paradigm in the enterprise -- and a new level of cybersecurity risk. This report offers a look at how enterprises are assessing and managing cyber-risk under the new normal.
    Twitter Feed
    Dark Reading - Bug Report
    Bug Report
    Enterprise Vulnerabilities
    From DHS/US-CERT's National Vulnerability Database
    CVE-2021-3113
    PUBLISHED: 2021-01-17
    Netsia SEBA+ through 0.16.1 build 70-e669dcd7 allows remote attackers to discover session cookies via a direct /session/list/allActiveSession request. For example, the attacker can discover the admin's cookie if the admin account happens to be logged in when the allActiveSession request occurs, and ...
    CVE-2020-25533
    PUBLISHED: 2021-01-15
    An issue was discovered in Malwarebytes before 4.0 on macOS. A malicious application was able to perform a privileged action within the Malwarebytes launch daemon. The privileged service improperly validated XPC connections by relying on the PID instead of the audit token. An attacker can construct ...
    CVE-2021-3162
    PUBLISHED: 2021-01-15
    Docker Desktop Community before 2.5.0.0 on macOS mishandles certificate checking, leading to local privilege escalation.
    CVE-2021-21242
    PUBLISHED: 2021-01-15
    OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, there is a critical vulnerability which can lead to pre-auth remote code execution. AttachmentUploadServlet deserializes untrusted data from the `Attachment-Support` header. This Servlet does not enforce any authentication or a...
    CVE-2021-21245
    PUBLISHED: 2021-01-15
    OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, AttachmentUploadServlet also saves user controlled data (`request.getInputStream()`) to a user specified location (`request.getHeader("File-Name")`). This issue may lead to arbitrary file upload which can be used to u...