Friday, April 1, 2011

Thieves now stealing kid's identities

An article on this website shows a study on theft and use of SSNs of minors. Horrible, but true. Not only are you as an adult, at risk, but your kids are too. The article does mention that some cases are parents using their kid's SSN to get stupid things like water and electricity, but that isn't always the case.

The author doesn't say if kids are more at risk, but the answer should be obvious. The bad guys are always looking for new ways to steal. When we catch on to something, they find a different avenue. Now that us adults have taken checking our credit into our own hands, thieves are targeting kids, who, well. . . let's face it, have no reason to even have a credit history, let alone check it. So, what's the answer?

Well, the web site provides a link to a site which says lookups are free, but registration is required, and it is a privately-owned "Identity Theft Protection" company, which means they may change their mind at any point and begin charging for this service, even though they say that it is free. Is there another solution?

Not sure. currently, we are allowed a free lookup of our credit history once per year, for all 3 credit bureaus. I'm assuming this is through an amendment to the Fair Credit Reporting Act (any lawyers out there?) Maybe another amendment is in order, allowing parents to perform credit lookups once per year on their credit history as well as the credit history of any dependents they may have. I think I'll be writing my congress representative this evening and hopefully putting the system to work for me.

Sunday, January 30, 2011

Might be a good idea to change your Amazon password

So, there' an alleged bug in Amazon's authentication mechanism. There's a fix in place. but the catch is you need to change your password to alleviate the problem. And, as the author states, please do not use the word password in your password. If you think the word 'password' is a secure password, well, then I've got more educatin' to do. Gotta go, there's password changin' to do.

Wednesday, January 12, 2011

Kama Sutra, Trojans, and I'm not talkin' bout the good kinds

So, apparently, there's a new trojan horse floating around in the form of a PowerPoint slide show, which promises to educate the user on the Kama Sutra. It may be called "Real kamasutra.pps.exe," but could have any name. While the slide show may actually have images of Kama Sutra positions, there is a malware program embedded inside the executable that allows an attacker to take control of your machine, at which point they can steal your info, or enlist your services in their botnet.

Attackers prey on weaknesses. People have two major weaknesses: money, and sex -- not necessarily in that order. Put them together (money-free sex) and it's the perfect storm of human weakness.

For some it may go without saying. For others, not so much. Just stay away from the "free sex." You may not pay for it now, but at some point, you will. And for g-d's sake, don't fool around with anything with a ".exe" extension, unless you know where it's been. . . and you've both been tested.

Safe Surfing!

Tuesday, January 11, 2011

Facebook scams hit mobile users

"What in the wide, wide world of sports is going on out there?"

In This post, the author cites statistics surrounding the percentage of scams on Facebook that hit mobile users. Approximately 24% of the hits to scam web pages came from mobile devices, e.g. Windows mobile phones, iPhones, Blackberrys, etc.. Unfortunately, scammers targeting mobile users will only increase as the number of people "going mobile" is increasing. Actually, it's not the "going mobile" aspect as much as it is the smart/droid/i phone aspect. More and more users are discovering the cool things that these powerful hand-held devices can do.

What's the fix? It's a simple one. Don't click on any links on your mobile device, which is easier said than done. It's very easy to hide a scam web page inside a HTML link that is legitimate. Here's an example:

I can say that I'm sending you to Google, but if you actually click on the link, it will take you to Microsoft's home page.

Friday, November 19, 2010

McAfee's 12 scams of Christmas

While my McAfee software has been pissing me off lately to the point of wanting to throw it through a window, I still think their 12 Scams of Christmas is a good warning to all users of the Interwebs. Remember, if it's free now, you'll pay for it later, maybe with the loss of your personal info.

PortKnocking

It's been a while since I've posted -- been busy with school.

A coworker mentioned something called portknocking and it sounded pretty interesting, so I did a little digging. check out this link for an in-depth description. Basically, it's a way to make your computer even more secure, sort of like adding a combination lock to your firewall. While not recommended for everyday users, it's an interesting concept. You start by configuring iptables/chains to drop all incoming packets. Then you add a rule to your chain that says something like "If I have a connection attempt on port 1024, 1025, and then 1026, then allow ssh connections." you can then ssh into your machine. When you're finished, you have a rule that says "If I have a connection attempt on port 1026, 1025, then 1024, close port 22." Done. Pretty nifty.

Saturday, August 21, 2010

KeePass

So, I've finally had some time to take a look at a few of the tools I learned about in the past few weeks of school, and one that even the home user can benefit from is call KeePass. Basically it is an application that can store all of your passwords (securely) for all of your applications, websites, etc...

A couple of features that I found handy were the ability to create a random password, and the ability to copy the password to your clipboard. Keepass has a feature that will create a pseudo-random password, which you can save for any of your applications so you don't have to remember it. It also has the ability to copy that password to your clipboard so you can just paste it into the login field of your particular application. There's a catch though. It only keeps the password stored in your clipboard for a few seconds, then wipes it. This is a good thing, as I'm sure I'm not the only one guilty of requesting a password reset from a web site, getting the email, and copying and pasting the new password into my login field. The problem with this? Well, the clipboard is just a small memory space that stores things until they get overwritten. So if the last thing you've copied to your clipboard is your banking password and I have access to your computer (by any means), I can grab it either from memory or, if I have phyical access, just hit ctrl-v.

...and if you're paranoid like me, you can run KeePass from an encrypted thumb drive using TrueCrypt, so your passwords will never be on your computer; and if you lose your thumb drive, well, you've lost your passwords, but a bad guy won't be able to recover the encrypted data -- at least not in our lifetime.

Check out KeePass here:
KeePass