Help

My Pictures Online: New System

Click a Topic (Label)

Search This Blog

Showing posts with label Caution. Show all posts
Showing posts with label Caution. Show all posts

15 October 2017

Phishing on the iPhone

The bad people are at it again.

This time, it is "phishing" <https://en.wikipedia.org/wiki/Phishing> on the iPhone--attempts to get you to give them your Apple account credentials. For clarity: This is not malware residing on your device; it is a message that came in piggyback with something else.

Occasionally, iPhone (or any iOS device) will need your credentials (ID and password), and will make its request by putting up a "slip" containing the notification. You may be able to dismiss without complying, but the request would return the next time the OS needed access to Apple services. We become accustomed to just doing what is needed without thinking about context--and this is what the jerks are counting on. They display such a request (looking more or less identical to the legitimate one), and we pass them our credentials (username and password).

The article below suggests that such request be dismissed immediately, but then one should go to System Settings to see if the request is there--and if so only there to supply the password being requested.

This would be similar to our _not_ using the convenient link in e-mail from [someone posing as] a bank; instead we use the links previously stored in our Contacts address books.


I hope this helps.


Mark_ 
15 October 2017 21:46 

24 March 2017

Apple ID - Hacked

A few days ago, it was reported that a hacker group was claiming that they had obtained millions of Apple's user credentials: both usernames and passwords, apparently.







We are advised to enable _two-factor authentication_ for login to Apple's services (iCloud, etc.).

Oddly, as of Friday morning 24 March 2017, a day or so after the hack was announced (and some allegedly stolen IDs confirmed), Apple's web site seems completely silent on the subject.  It is worth noting that in other places Apple has denied that _it_ was hacked; speculated that the materials came from elsewhere.

Even so, bad enough.  The suggestion is that users engage _two-factor authentication_ (2FA), which means that each time you log into an Apple service, a second device must be used to verify your identity.  

This is not the same as having to involve the second device each time a service is _used_; most of our interactions occur without having to log in again; a login session can persist for days or weeks.  (Consider your email client; it can silently check for mail in the background because it remains logged into the mail server over days or weeks or more.)

Even so, it can seem like a minor additional hassle, because it requires ready access to two modern Apple devices simultaneously.  A code will be sent to the "other" one, which must then be entered into the one being signed in.  I assume that the two must be on the same Apple ID (and that having the spouse's device/s on that ID could be even more problematic than it already is).  (Spouses should have their own Apple IDs, to keep network things from tangling.)


Engaging 2FA
------------


• Modern devices (things that can run the latest Macintosh OS or iOS): <https://support.apple.com/en-us/HT204915>
• Less-modern (vintage; legacy) devices: <https://support.apple.com/en-us/HT204152>

We should all do this.  I will have made the change by the time the ink has dried on this post.


Mark_
24 March 2017

17 March 2017

E-mail warning (real fake)

I have just received this "helpful" e-mail:


| From: GoogleReminder
| Subject: Message you sent blocked by our bulk email filter Socrates
|
| Lauren Collins (Gmail Support) sent you a message:
|
| 3/17/2017
| Message status: undeliverable
|
| <Learn more>
|
| <View Messages>
|
|
| Don't want occasional updates about Gmail activity? <Change> what email Gmail Service sends you.


The return address nor any of the links is real; they all lead to places that aren't anything Google.  (This is easily checked; ask me, if needed.)  (They had not used my Gmail eddress, either.)  


My microwave/camera was of no help at all.


Mark_
17 March 2017 @ 14:30

06 January 2017

Reminder: "Spear Phishing" (Warning)

I post this as a timely reminder that an e-mailed convenience can be used to compromise your online accounts.  The technique is referred to as "spear phishing"; it works like this:

You receive an e-mail message informing you of the need to go change your password, and a convenient link to the necessary settings page is provided right on the message.  This link goes not to where you are being told it does, but to a lookalike page that delivers your information to the criminals.

The safe solution is simple: Take the alert seriously--don't even bother considering the other alternative.  However, use the links you should have entered into your own address book software for that institution or web service.  In this way, you use your IQ to divert _bad luck_ away from yourself (and, alas, toward other people).

I wrote "timely" because this is apparently the technique that got [someone] into Democratic e-mails during the period before the 2016 presidential election.  


I have said this before:  Most of us have lived our entire lives in neighborhoods (both our domiciles and our retail and other business activities) in places where criminal activity was more a matter of news reportage than of experience.  Now the criminality--the actual threats--come(s) right into our homes.

Welcome to the constantly-connected future.

Mark_
06 January 2017 (a date that still seems like it belongs to The Future)

14 October 2016

Heatproof Glass Risk

In a thrift store a couple of days ago, a pretty large and heavy piece of glass broke a couple of aisles over from where I was browsing.  It was loud, and the resulting fragments were oddly small (in the bin after cleanup).  

Apparently, a patron reported that it had broken (in the aisle where she was standing) for no apparent reason; nothing else was happening at the time--nobody had touched it, nor had it somehow fallen from the shelf.  It had just exploded.

It was a large glass baking pan.

This reminded me of stories I had begun hearing a few years back of problems with heatproof kitchen glassware (cookware) after a switch from borosilicate to [some other glass formulation].  

It has made me wonder about the glassware we have here.  A Snopes article has caused me to worry that I would not be able tell with certainty which of two kinds of glass kind we have, and therefore to consider doing away with it all.  (White Corning stuff is a different material; I may keep that.)


Apparently there are several (many?) such vids @ YouTube.

Corning cookware @ Wikipedias:


We have some white Corning cookware: Some is over 40 years old, and is marked "for range and microwave"; one piece is newer and lacks the "range" marking.  We use these pieces in the microwave oven only.

• We have this tableware (in plain white): <https://en.wikipedia.org/wiki/Corelle>.  Apparently its composition is largely unchanged.  (We have broken one piece, but others have been dropped and smacked without damage.)

• We also have one of these Visions glass saucepans: <http://www.discusscooking.com/forums/f89/stovetop-cooking-with-pyrex-visions-cookware-3174.html>.  Although we have used it on the stovetop without incident, it may not be so safe, either.  We use it frequently in the microwave oven.

We have several pieces of clear glass bakeware, which I will examine for clues about whether they are suitable for use: big and small cake pans, loaf pans, etc.

Researching this has been (will be) kind of a lot of work, but if it keeps even one pan of brownies from being wasted (or one eye from being put out)....


And more reading is needed.

Mark_ 
14 October 2016

06 November 2013

Extremely ugly Windows malware

A new piece of Windows malware has been in the news.  This one is pretty scary.

CryptoLocker arrives as a Trojan Horse--an executable disguised as something else, such as a PDF or picture file--that when opened silently encrypts your files using "military-grade" encryption that has been characterized as "infeasible" to decrypt without the key. Your stuff is still there, but unreadable. Permanently.

On completion of the encryption process, you will be presented with a _demands_ screen: Within some fairly limited amount of time, pay hundreds of dollars using any of several methods, or the key will be "destroyed". (Turns out that this "destruction" may not be without appeal, but the second chance is worth _thousands_ of dollars.) Pay up (an act as galling as it is expensive in a couple of ways), and the key will be returned and files decrypted. (Some report success, others report otherwise, apparently. The perpetrators are criminals, after all.)

For information, Google "cryptolocker", and read the Wikipedia article first.

A Windows user should do (at least these) three things:
1. Set your anti-virus on _kill_. (Make certain that it is engaged and that it is using the latest definitions.)
2. Back up to an external drive. Check the backup to see that its files are readable.
2. Be extremely vigilant about opening files that have been e-mailed to you. Open _nothing_ about which you can have the slightest doubt as to provenance. It is at this point that the infection occurs, and it does so silently. One is aware that one has troubles only when the damage has already been done.

Power users have other tools, but they are arcane and _unlikely_.

Note that this exploit runs on "social engineering"; getting the victim to participate by scamming him. The user is the line of defense; knowing what to expect and how to recognize the threat before it is put into play are key to staying safe.

There is one more way of staying out of harm's way, but I won't mention it because it can make a Macintosh user seem far too pleased with himself--and besides, his own safety may not be permanent.


Mark_

06 November 2012

Another E-Mail Scam

A friend just received an e-mail message from Comcast saying that his credit card had been declined on attempting the automatic payment that keeps him connected. It included a convenient link to where he could provide the information needed to guarantee uninterrupted service.

This friend was smart enough to call the telephone number in his personal address book--instead of using that very convenient Web link--so that Comcast could assure him that there was no such trouble.

What makes this one even more scary is that one of the data being requested was his social security number. Linking the two might have permanently unlocked his identity to some terrible person.

Interesting that that same friend had recently lost control of his credit card number--without having actually lost control of the card itself. He had done nothing wrong--nothing out of the ordinary--but had he not noticed the trouble soon after its occurrence, he might have been out quite a sum of money.  (The malefactors had already charged hundreds to it.)

At present, there seems to be no reason for concluding that the two incidents are related. There is so much criminal activity of this sort that it is inevitable that we might encounter more than one attack over short periods of time.

(And now I must go double-lock my doors and close my drapes. Not sure what I'll do when night falls....)


Mark_
13:31 06 November 2012



29 May 2012

Rachael, from Member Services (Scam!)


A persistent scam involving telemarketing calls from "Rachael, from Member Services" has continued to be active despite official attempts to stop it. I have just received one of these calls.

It's a minor inconvenience, of course--I always disconnect as soon as I realize that I am hearing a recorded message--but it's also illegal, and irritating in principle--because all of my telephones are registered with the national Do Not Call list.

I filed a complaint on the List's web site, but while there learned yet another bit of somewhat disheartening news: Some scammers are calling people, claiming to represent Do Not Call, and offering to put your numbers on that very list that should prevent their calling you. Of course, two things would follow from your having given your telephone number(s) to these horrible people: You are not on the Registry despite your believing that you are, and a scammer has just gotten your telephone number(s) from your own lips.

From the Do Not Call page:
Scammers have been making phone calls claiming to represent the National Do Not Call Registry. The calls claim to provide an opportunity to sign up for the Registry. These calls are not coming from the Registry or the Federal Trade Commission, and you should not respond to these calls. To add your number to the Registry you can call 888-382-1222 from the phone you wish to register, or go click on “Register a Phone Number” in the left column of [the Registry's] page.   
Your registration will not expire. Telephone numbers placed on the National Do Not Call Registry will remain on it permanently due to the Do-Not-Call Improvement Act of 2007, which became law in February 2008. Read more about it at <http://www.ftc.gov/opa/2008/04/dncfyi.shtm>.

It's all enough to make one feel more or less completely surrounded.

(And this, doubters, is why we need big government.)


Mark_
29 May 2012