Showing posts with label email. Show all posts
Showing posts with label email. Show all posts

Monday, August 23, 2010

More SPAM

I've recently received lots of email SPAM from friends, mainly about "Fanbox" and "Tubely." (See below for examples.)
Just from the look of the emails and through a quick Google search, these sites definitely look sketchy/fake.

Delete these emails.
Do not register on these sites.
And definitely do not supply your email password to these sites!

See my previous post about this. 

Fanbox SPAM: This site tries to get you to click to their site by pretending your friend has shared photos with you.
Tubely SPAM: This site tries you get you to click to their site by asking you to add a friend to your friends network on this new "social networking site."

Tuesday, January 19, 2010

Gmail turns on https by default for all users

Before, I had blogged about how you an make your connection to gmail a little more secure.

Gmail is now turning on that setting by default. Nice! This basically protects your email as it travels between your browser and google's mail server.

Saturday, November 21, 2009

Why you should disable automatic loading of email images

Many email clients today have an option to disable automatic loading of images in your email. Many even have this feature enabled by default. Why is this a good thing to do?

1. You may want to protect your eyes (or yours kid's eyes) from images you'd prefer not to see. This way you can open an email without also loading its images, and then decide whether you'd like to display the images.

2. In the past, there was some worry that "images" you load might contain viruses. I don't think this really happens, especially as computer software is much more robust now.

3. The main reason images are often blocked by default is to protect your privacy from spammers. Images you see in your email can be one of two kinds - (1) the local kind where the image files are actually attached to your email, or (2) the externally linked kind where your email references files that are stored on an external server. If it is the second kind, your computer will have to contact an outside server to get the pictures to be displayed. When it does this, it may log a message on the server that you have opened the email that was sent. This lets spammers know that your email address indeed is a real address, and they may spam you more!

Here's links about how to enable this feature for your mail:
- In Yahoo! mail or Yahoo! mail classic: I believe Yahoo's default is to initially block all images.
- Gmail doesn't automatically load externally linked images, unless it is received from a someone you have emailed twice. You can customize this setting.

Wednesday, November 11, 2009

Scams, example 3

The below text is from an email addressed from a good friend of mine:


I was immediately suspicious because (1) the style is definitely not the way my friend would write, (2) there are tons of typos, and (3) I'm suspicious of anyone trying to get me to buy products/wants my money.

I contacted my friend, who said she did NOT send that message. I asked if she experienced any other side effects, and she said all of her contacts in her email account had been deleted, but that luckily her virus/malware scanner found nothing.

I'm guessing that the intruder obtained her password somehow, perhaps by just trying to guess her password. The intruder then spammed everyone in her contact list. Wouldn't that take a lot of work? Not really, some people hire folks to do this. Plus people can write programs that aid in the attack.

I did some search online, and it looks like this web site is a fake site that sells consumer electronics for "really cheap." You buy your cheap, "authentic" iPod or whatever, submit your payment, and wait a while until you realize maybe they're never going to send you anything, or they send you something fake. But you can't really do anything about it because this "company" is based in China (we think.)

Reminders:
1. Be careful where you shop online - you can't just trust any shop.
2. Use a strong password, and avoid falling for phishing attacks.
3. If this happens to you and your email account has been compromised, (1) immediately change your password to a new password. (2) Run your (up-to-date) virus scanner to make sure there's nothing bad installed on your computer. (3) Alert friends who may have been spammed through your account so they don't fall for it.

Friday, November 6, 2009

Avoiding scams - another example

The below message got by my SPAM filter and landed in my email inbox: (BTW, I normally do not allow automatic display of images in emails, or even open suspicious emails, but captured the below image for educational purposes, after doing some research.)


The email looks like it is from a social networking site, asking me to join/accept a new friend. This is not uncommon - we often get/send messages to people inviting them to join Facebook, LinkedIn, or some other social networking site.


However, the email immediately looked fishy because (1) I've never heard of "Jhoos" and was suspicious of it. (2) I didn't know the person whose name was listed in the email who supposedly "wants to be my friend." I did a search on that person's name in my email inbox and we were once both cc'ed on a message. (3) It's funny there is both a "Yes - Accept" and "No - Reject" button. Why would I click No to reject a friend on a site that I don't even belong to (instead of just deleting the email.)

Reminder 1 - Don't click on links if you're not sure of the site it is taking you to, especially if it is given to you by someone you don't know!
Reminder 2 - Just because an email says it was sent to you by John Smith does not mean it was sent by John Smith. Even if it is (supposedly) your best friend asking you to join some site, I'd double check with your friend, and double check the site (if I haven't heard of it.)

I did a google search on "jhoos" and supposedly it is a free online dating service. BUT, I also found many other google results (such as McAfee's SiteAdvisor site) that WARN AGAINST that site, which will install things on your computer without you knowing, send "invitations" to everyone in your address book (it asks you to enter in your email password so that you can supposedly connect with other friends), and perhaps other things. I didn't try it out myself, but seems pretty clear to me the social networking/dating thing is a front.

Reminder 3 - Don't ever give your email account password to anyone!
I know some sites will ask you to enter your email account info, and I really dislike it. (Facebook has it as a feature for inviting/connecting with friends.) Sure, maybe it's convenient. But do you really wanna give that much access to your account to some stranger? It's like giving someone the keys to your house. Not a good habit.

Monday, June 22, 2009

Avoid phishermen. Don't get tricked!


According to various sources (such as Symantec), spam accounts for 90% of all email. Pretty crazy, huh? Luckily my email providers have pretty good spam filters, so I don't have to deal with junk mail too much. (BTW, looks like spam makes up about 45% of my mail, so I guess I'm doing pretty well..?)

Whether you have a good spam filter or not, it is a useful skill to be able to tell whether an email is "real" or "fake." There are some people who send emails that look like they are from some trustworthy entity (such as your bank), in order to try to get you to enter sensitive information, such as your password, credit card number...
This is called "phishing." Don't get caught! Think twice before clicking on any link or entering in sensitive information.

Try taking SonicWALL's Phishing and Spam IQ Test.

Saturday, May 16, 2009

Make your connection to Gmail a little more secure

For those of you who use Gmail, check off this little box "Always use https" in your email settings (click on "Settings" and go to the bottom of the "General" tab) to make your connection to Gmail a little more secure:



About a year ago (see this Gmail blog entry,) Google made this feature available - it is NOT on by default, and so YOU have to turn it on. (I'm surprised they don't have it on for everyone by default! They really should!)

What does this help protect against? Well, say you are at Starbucks using their free Wi-Fi (or just using any nonsecure network) - someone could easily "listen in" on your connection to Gmail and see the emails sent between Gmail's servers and your computer. This feature helps to protect against that.

Instead of seeing your message "Hi Joe, my account number is 23443212334. Can you transfer me the $20 you owe me?" someone attempting to view your mail will see junk like this: "k1q4w!mjherptjh7eff3kjahdnfxwweitunyxqwkhr8ej k5n3j875nsozj1j&h.3mi"

Note that this ONLY helps protect the connection you have between your computer and Gmail's computer. (Your message itself is NOT encrypted for the recipient.) It protects against those people at coffee shops and other nonsecure networks listening in on your connection with gmail.
It has NO effect at all upon the rest of the path your email must travel to get to your recipient. (Your email administrator could still read your mail. If your email is stored on an insecure server along the way, it could be read. Mr. Stranger could listen in when your friend retrieves the message you sent him on if he's using an insecure connection, etc.)

More on using "free public internet" later.

Wednesday, May 13, 2009

The importance of a good password (especially for your email account)


Imagine if some key/lock maker only made a few different keys - square, circular, and triangular. These locks would not provide good security at all - Mr. Stranger could easily try each possible shape and then get into your house, car, etc.

It's the same with passwords. Is your password easily guessable? Is it "password123"? If I tried every word in the dictionary could I get it? Is it your username (or some permutation of it)? Your username + your birth year? If you have a guessable password, Mr. Stranger could probably guess it eventually, after some number of tries.

Let's see what Mr. Stranger could do if he guessed the password to your main email account:
Obviously, he would be able to read ALL of your email. If you have any confidential information, such as other passwords, credit card numbers, social security number (which you shouldn't store on your email server anyway), Mr. Stranger would be able to see it.

He might be able to see where/when/with whom you are having dinner this weekend. A lot of personal information (how much email do you have stored?) could be extracted.
He would also have access to your contact list and all their email addresses (perhaps he'll make a copy for himself and sell this list to someone). He could send mail to them from your account without you ever knowing. (Hopefully he says something nice.)
If you use gmail, your gmail password would also provide access to any of the other Google applications you use - Mr. Stranger could view your calendar. He could see all your calendar events, read your google documents, make changes, etc.
If you use the same password for any other sites, Mr. Stranger now knows the password to your other accounts and could try using it.

Mr. Stranger could easily change your password and log into your account on any of those sites that use an email-based password recovery mechanism. Even if you use a different password for other sites, many other accounts are linked to your email address. For example, if you forget your password on Facebook, Xanga, Amazon, etc., you can ask them to send you an email with a temporary password or link so that you may reset your password.

Once Mr. Stranger gets into Xanga, he could read your private entries or read your friend's entries, write/delete/etc. any of your entries. He could do some pretty mean things.
If Mr. Stranger gets into Facebook, he would be able to see all your friends and their info (like telephone number, address, pictures..), and send them all messages (hopefully nothing mean or misleading), post pictures, delete stuff, etc. Just imagine the possibilities.
If Mr. Stranger logs into your Amazon account, and you have your credit card information stored and linked to your Amazon account, Mr. Stranger could order some items and have them delivered. (Luckily Amazon limits using saved credit card data to addresses you have used before.) He could delete emails/change the listed email address so you notice the purchases later than sooner.
If Mr. Stranger can find out your social security number, account number, or other information stored in your email somewhere, he might also be able to use it to log into your online bank account (he knows what accounts you have because he scanned your inbox) and do some damage there.

Pretty scary huh? (I don't mean to scare you, just showing you what's possible.)
Hopefully you don't have a square-shaped password.

Saturday, May 9, 2009

Email is not encrypted (so it's not private)!

Chances are, you use email. And chances are, you don't use encrypted email.

Gmail, Yahoo mail, etc. are all not encrypted!

Sending an email is like sending a letter in the mail. Between the time you put it in the mailbox to when your recipient finally receives it, your letter will be handled by many different people and go through different mail hubs and delivery vehicles. Anywhere along the path someone could potentially open your letter and read it. Similarly, email is sent through various hubs and handled by different servers, and anyone along the way could potentially read it. And say a delivery truck or storage facility (or computer system/hardware device in the case of email) is left open and unlocked, that makes your mail even more open. Just because you have to type a password to get to your mail, or because your email is delivered to your blackberry which only you access, does not mean it was safe during its journey.

Actually, sending an email is more like sending a postcard. When you send a letter in an envelope, the recipient is likely able to see if the envelope has been tampered with. However, with a postcard, anyone can read it along the way. You cannot tell if the message on your postcard has been kept private. Email is like that. If someone (or multiple people) reads your email, there's no way you can tell.

Email is also like a telephone call. Anyone who can listen on the line can find out what your email is about. Worse, the message in your email is likely "played" multiple times while it’s being delivered – between each node in which it is transferred.

Furthermore, copies of your email are probably made along the way to being delivered. If anyone can gain access to any of the systems holding a copy of your email, then it can be read. (BTW, your email administrator could easily read your mail.)

The moral of the story is when using [unencrypted] email, you should NOT send information considered private (such as account numbers, passwords, SSN, personal information, etc.) (Would you send cash through regular snail mail?)