Showing posts with label Phishing. Show all posts
Showing posts with label Phishing. Show all posts

Tips to protect your personal information


Tips to protect your personal information - The Social Security number is the gateway to your identity, but criminals also want your account numbers as well as other pieces of personal information useful for committing identity theft.

Limiting the exposure of your personal information will help guard against potential fraud, and in the process cut down on unwanted marketing in some cases.


http://resbak.com/blog/wp-content/uploads/2009/03/danger-internet.jpg


Screen charities

If someone claiming to represent a charitable organization calls you, ask the caller to send you written information about the charity instead of giving out credit card information over the phone. "If you get any pushback whatsoever, say, 'You know what? If it wasn't important enough to send in writing so I have a right to review it, then it's not important enough for me to respond to this phone call,'" says Adam Levin, chairman of Identity Theft 911.


Avoid marketing

People unnecessarily give out personal information when they apply for supermarket club cards and fill out product warranty cards. "Warranty cards ask for date of birth, educational level, income level, number of children living in the home, sometimes occupation -- you don't need to give that information to get warranty protection for your clock radio," says Jack Vonder Heide, president and CEO of Technology Briefing Centers. "That information is used for marketing purposes."

Experts also caution against providing your telephone number when prompted at a retail point of sale, unless it's necessary to place an order. While phone numbers are typically used for marketing, it might be possible for someone to find your store charge account with a phone number, says Vonder Heide.


Don't share too much on social networking sites

Criminals can use social networking sites to commit identity theft if enough personal information gets posted -- not to mention that the personal information you post makes it easier to be stalked. Besides your address, avoid putting your full date of birth on your profile, suggests Vonder Heide, because that's a piece of information that a thief needs to steal your identity.


Job hunt online safely

Until a company is ready to hire you, don't furnish a potential employer with your Social Security number. Do a thorough background check on companies before submitting your resume and check the privacy policies of online job boards before posting your information. "You may put your information out on a Web site and they may have a privacy policy that says that they're allowed to sell that information to anyone they choose for any purpose they choose," says Vonder Heide.

Make sure your computer is secure before surfing the Web.


Limit physical access to your SSN

Don't store your Social Security number or card in easy-access places, such as your wallet, in your cell phone or in the glove compartment of your car. Make sure you don't have your SSN printed on your checks or used as your driver's license number.


Don't flag important mail

If you're mailing something that contains sensitive information, don't leave it in an unsecured mailbox. "When you put up that little red flag, that's a magnet. Either get a locking mailbox, where the only people that have a key are you and the post person, or take it to the big secure mailbox on the corner," says Levin.


Shred documents using a crosscut shredder

Make confetti of "anything that you have that is a document that has any information on you whatsoever that might be considered personal that you're not interested in keeping around anymore," says Levin. ( bankrate.com )

READ MORE - Tips to protect your personal information

Five Online Security Don'ts


Five Online Security Don'ts - When it comes to protecting their finances from cybercriminals, most consumers have heard the online security basics before: Avoid entering financial information at a public computer, and don't repeat passwords across multiple sites.

The same experts also warn against using public Wi-Fi hotspots to conduct transactions on your own computer. "You never know who's sitting next to you at Starbucks when you log on to pay your bills or check your bank statement," says Eric Friedberg, co-founder of Stroz Friedberg, a security firm in New York City.

And just to beef up online security, all security experts advise consumers to take advantage of extra layers of protection, such as secondary passwords, security questions or tokens, if their financial institutions offer those services. But as our daily lives grow more intertwined with technology and cybercriminals become more sophisticated, there's always more you can do to make sure you aren't the next victim.


http://l.yimg.com/bt/api/res/1.2/3SPjWbXvgenALFLw5K0xcg--/YXBwaWQ9eW5ld3M7cT04NTt3PTI2MA--/http://globalfinance.zenfs.com/en_us/Finance/US_AFTP_BANKRATE_LIVE/5-online-security-donts-1-intro.jpg


Don't Take Social Media Offers at Face Value

For years, scammers have been using email to dupe their victims into sending money or divulging sensitive information. While that's still a problem, scammers are increasingly turning to social networks, such as Facebook, and using your friends against you, says Joe Ferrara, president and CEO of Wombat Security Technologies in Pittsburgh.

"To ensure safe social networking, never connect with anyone you haven't met, verify the identity of new friends and look out for scam messages, even from trusted friends, which could indicate an imposter," Ferrara says.

Spotting an imposter may be tough at first. The message, which can appear as a direct message or a post on your Facebook wall, is designed to look like it came from your friend's profile. A free treat from your favorite store presented by a friend can be a tempting offer, but before you click, Ferrara says you should ask yourself a few questions.

  • Is the offer too good to be true?
  • Is this really something my friend would write?
  • Does the language have awkward phrasing or a lot of typos?

If any of those questions raise a red flag for you, don't click the link. And, if you want to verify the message, try contacting your friend directly about the offer.

Don't Ignore Updates

You may not realize it, but keeping your software up-to-date isn't just a question of adding new features to your programs; it can also be a critical part of protecting yourself online.

"Cybercriminals can get in through holes in unpatched computers," says Marian Merritt, a Los Angeles-based author of "Family Online Safety Guide," written for Symantec, the makers of Norton AntiVirus.

But updating software doesn't just mean making sure you have the latest version of your chosen anti-virus program, Merritt says.

"You also have to keep your computer's operating system and the programs that run on your computer up-to-date," Merritt says. "Don't ignore prompts to update your operating system or applications with critical security fixes."

But when you do update, you need to be careful. If you use a Microsoft operating system, you can safely update through Windows or Microsoft Update, which is a program that comes preinstalled on your computer. Macs have a similar updating program that prompts users when it's time to make an update. For other software programs, experts say it's a good idea to update through the company's website to ensure safety.

Don't Forget to Eye the URL

When you visit a new website, you should always take a moment to scan the site's Uniform Resource Locator, or URL, which is displayed in a bar at the top of your Internet browser. That URL is the address of the website, and online security experts have been warning consumers for years to look out for typos or other irregularities to make sure they really are connecting to a legitimate website and not just a clever imposter.

Most URLs will begin with the familiar "http" before the site's address. News, entertainment and other general interest websites all use this format for their URLs.

But these days, if money is about to change hands or you're asked to share sensitive information such as your Social Security number, it's a good idea to look for a URL with an extra letter, says Andrea Eldridge, CEO and co-founder of Nerds On Call, a computer and electronics repair service based in Redding, Calif.

"Make sure that anytime that you are putting in sensitive information that the Web address starts with 'https' instead of 'http,'" Eldridge says. "That little 's' stands for secure, so the website has to have additional security precautions on the page keeping you safer and a whole lot less likely to have your information stolen."

Don't Assume Mobile Apps Are Safe

For sheer convenience, it's hard to beat the allure of banking with your smartphone. But before you download an app that promises to turn your phone into a wallet, it's a good idea to ask yourself if you're trading convenience for security.

"Smartphone users who want to use mobile banking should only use apps from their financial institution," says Eldridge, who warns third-party apps may not have the same privacy protections as apps offered by your bank.

But Albert Thiel, president of Your Data Center Incorporated, a website hosting and network security company based on Long Island, N.Y., says consumers shouldn't be too quick to adopt mobile banking until there's better security across the board for mobile apps.

"Don't ever use a cellphone to connect to your bank," Thiel says. "(Many of) those apps you have loaded continue to run, even when you exit them," which may put users at risk for having keystrokes and touch screen selections intercepted.

According to Thiel, security on mobile devices will get better as anti-virus and anti-spyware packages evolve, but for now, he cautions, "Just don't do it."

Don't Click on Shortened URLs

If you use Twitter, you're probably familiar with so-called shortened URLs, which are a method for streamlining a link so it can fit in Twitter's 140-character limit. While shortened URLs are handy for sharing information via Twitter, they're also dangerous, according to Gary Bahadur, CEO of Miami-based KRAA Security and author of "Securing the Clicks: Network Security in the Age of Social Media."

Even if you know the person who has posted the link, it's a good idea to proceed with caution. When you see a shortened link "you do not know what the actual Web address is until you click," Bahadur says.

According to Bahadur, scammers often use shortened URLs to lead victims to a malicious software, or "malware," website.

Thankfully, you don't have to skip the links your friends share. But you should take the extra step of expanding the link to see the full address before clicking on it, Bahadur says. But that's not as simple as a mouse click.

Many of the services that provide shortened URLs have stepped up their efforts to guard against scammers, but it's also a good idea to have a tool that allows you to safely open the shortened URL, Bahadur says. TinyURL.com can help, but there are others. ( Bankrate.com )

READ MORE - Five Online Security Don'ts

Protect Your Online Privacy


Protect Your Online Privacy - Visitors to almost every major website are tracked online, a Journal investigation has found. But there are ways to limit the snooping.

Web browsing activity is tracked by use of "cookies," "beacons" and "Flash cookies," small computer files or software programs installed on a user's computer by the Web pages that are visited. Some are useful. But a subset ("third party" cookies and beacons) are used by companies to track users from site to site and build a database of their online activities.

Simple Steps


Major browsers including Microsoft Corp.'s (NasdaqGS: MSFT - News) Internet Explorer, Mozilla Foundation's Firefox, Google Inc.'s (NasdaqGS: GOOG - News) Chrome and Apple Inc.'s (NasdaqGS: AAPL - News) Safari, have privacy features. To have the most privacy options, upgrade to the latest version of the browser you use.

Check and Delete Cookies: All popular browsers let users view and delete cookies installed on their computer. Methods vary by browser.

For instance on Internet Explorer 8 (the most widely used browser), go to the "Tools" menu, pull down to "Internet Options" and under the "General" tab there are options for deleting some or all cookies. There might be hundreds, so deleting all might be easiest. But the next time you visit a favorite site, you may need to retype passwords or other login data previously stored automatically by one of those cookies.

Adjust Browser Settings: Once you've deleted cookies, you can limit the installation of new ones. Major browsers let you accept some cookies and block others. To maintain logins and settings for sites you visit regularly, but limit tracking, block "third-party" cookies. Safari automatically does this; other browsers must be set manually.

There are downsides to blocking all cookies. If you frequent sites that require logins, you will have to log in each time you visit.

Internet Explorer lets you set rules for blocking cookies based on the policies of the cookie-placer. One option blocks cookies that don't include a privacy policy; another blocks cookies that can save your contact information without your approval. The control is under "Tools/Internet Options/Privacy."

No major browsers let you track or block beacons without installing extra software known as "plug-ins," as described under advanced steps.

Turn On "Private" Browsing: All major browsers offer a "private browsing" mode to limit cookies. Chrome calls it "Incognito." Internet Explorer calls it "InPrivate Browsing," but this option is available only in the latest version, IE8.

Private browsing doesn't block cookies. It deletes cookies each time you close the browser or turn off private browsing, effectively hiding your history.

Private browsing isn't selective. It deletes all cookies, whether useful or not. So you might want to use private browsing selectively, such as when looking at health-related information.

Monitor "Flash Cookies": Another kind of cookie uses Adobe Systems Inc.'s popular Flash program to save information on your computer. Flash is the most common way to show video online. As with regular cookies, Flash cookies can be useful for remembering preferences, such as volume settings for videos. But marketers also can use Flash cookies to track what you do online.

To identify the Flash cookies on your computer and adjust your settings, you need to go to an Adobe website: www.macromedia.com/support/documentation/en/flashplayer/help/settings_manager.html. You can delete Flash cookies stored on your computer and specify whether you want to accept future third-party Flash cookies.

The downside of blocking third-party Flash cookies: Some sites won't let you watch videos or other content.

Advanced Steps

Install Privacy "Plug-ins": Small programs called "add-ons" or "plug-ins" can help maintain privacy. Some let you monitor trackers that can't be seen through the browser; others allow you to delete cookies on a regular schedule.

Not all browsers can use all plug-ins. And some plug-ins can be tricky to set up. With those caveats, some plug-ins may be worth a look:

Abine: Developed by a Cambridge, Mass., start-up of the same name, it attempts to control several types of trackers. Once installed, the program will warn you when a site is placing cookies or Flash cookies on your machine. You can also see and block a third type of tracker called a Web "beacon" (sometimes called a "bug"). This is an invisible object embedded in a page that can interact with cookies. It's available only in "test" versions, so this is only for people who don't mind experimenting a bit with software. For Firefox, go to addons.mozilla.org/en-US/firefox/addon/11073/. For Internet Explorer, users need to request an invitation at getabine.com.

Better Privacy: This plug-in offers control over Flash cookies. It doesn't block them, but lets you set rules for deleting them—a distinction that can be helpful if you frequent sites that require you to use third-party Flash cookies to see their content. Better Privacy (available only for Firefox) is at addons.mozilla.org/en-US/firefox/addon/6623/.

Ghostery: Available at ghostery.com, it helps control beacons. It alerts you when there's a beacon on a page you're viewing, tells you who placed it and details the company's privacy policy. With Internet Explorer or Firefox, you can then block the beacon from capturing information on your computer. That feature isn't available for Chrome.

Controlling Ads


Users troubled by targeted advertising can block or limit the ads being shown. Note: These tools don't necessarily restrict tracking. Some ad networks may still collect data on your browsing behavior and share it with others, even if you instruct them not to show you targeted ads.

The Network Advertising Initiative, an industry group of marketing companies, lets computer users opt out of targeted ads from about 50 ad networks at networkadvertising.org.

If you opt out, you won't be shown ads tied to your browsing behavior from the member networks. But you'll still see ads, which may be placed based on criteria such as your location.

PrivacyChoice LLC, an independent group, maintains a Web site (privacychoice.org/choose) that covers 152 ad networks. You can opt out of most by clicking a button there. For some, you'll need to download a plug-in, but it works only with Firefox.

Ironically, these opt-out systems work by installing a cookie on your computer. That cookie tells ad networks to stop sending targeted ads to your computer. Because these systems rely on a cookie to work, you'll need to opt out all over again any time you delete cookies from your machine. ( The Wall Street Journal )

READ MORE - Protect Your Online Privacy

New digital eraser software deletes personal Facebook photos after a set period of time


New digital eraser software deletes personal Facebook photos after a set period of time - It promises to answer the prayers of many social network users.

New software that automatically erases photos uploaded to websites such as Facebook and MySpace after a certain time has been launched.

German firm X-Pire claims to have identified a gap in the market - the fear of loading your personal photos online in case they are used against you at a future date.


Privacy protector: Software that automatically erases photos uploaded to websites such as Facebook and MySpace after a certain time has been launched
Privacy protector: Software that automatically erases photos uploaded to websites such as Facebook and MySpace after a certain time has been launched


The software prevents the increasingly frequent occurrence of someone being refused a job or running into other embarrassing difficulties after posting a photo that should have been kept private.

But Michael Backes, the founder of X-Pire, claims his company offers a solution to the problem.

Before the user posts a photo, all he has to do is drag it into the X-Pire programme which assigns it an electronic key that is valid only for a set time period.

If someone wants to view the photo at a later date, the server checks whether the key has expired. If it has, the photo is blocked and cannot be displayed.

Mr Backes said that while social network users currently have the ability to delete photos from sites like Facebook, most 'don't get round to it'.

'Most Facebook users, for example, are passive users,' he said.

'They go on, they put on a lot of private information and almost never come back on or they forget their password.

'The software is not designed for people who understand how to protect their data but rather for the huge mass of people who want to solve the problem at its core and not to have to think about it any more.'

However, Mr Backes warned that third parties can still view and save users' photos while they are in the valid time period.

He added: 'When people put photos on line, it's so they can be seen. Our software is not a panacea, not absolute protection.' ( dalymail.co.uk )

X-Pire costs two euros (£1.67) per month.


READ MORE - New digital eraser software deletes personal Facebook photos after a set period of time

"Verify Your Account Info"? It's Phishing


"Verify Your Account Info"? It's Phishing. How to Recognize Fraudulent E-mail Solicitations Known as Phishing and Keep Your Accounts Safe. If you have received an e-mail from the Internal Revenue Service or the Federal Deposit Insurance Corporation, chances are it was a phishing attempt. If you received e-mail from your bank, PayPal, or Facebook urging you to immediately verify information or risk having your account suspended, it was undoubtedly phishing.




(AP / CBS)

Phishing attacks have spiked this year, according to recent reports. The Anti-Phishing Working Group reports that there were more than 55,600 phishing attacks in the first half of 2009 alone. Phishing is particularly dangerous because once criminals get a victim's password for one Web site they can often use it to get into other accounts where people have re-used the password.

And anyone can be at risk. The wife of FBI Director Robert Mueller banned him from doing online banking after he came close to falling for a phishing attempt.

Here is some basic information that can help people avoid being tricked by phishing attacks.

What is phishing?

Phishing is an attempt, usually via e-mail, to trick people into revealing sensitive information like usernames, passwords, and credit card data by pretending to be a bank or some other legitimate entity. The e-mails typically include a link to a Web site that appears to be legitimate and which prompts users to provide information. Sometimes, the phishing e-mail will include a form in an attachment to fill out. One common tactic phishers use is to pretend to be from the fraud department of a financial institution or online retailer like PayPal and ask for information to be provided to prevent identity fraud. In one case, a phishing e-mail purporting to be from a state lottery commission asked recipients for their banking information so their "winnings" could be deposited into their accounts.

Phishers also are increasingly exploiting interest in news and other popular topics to trick people into clicking on links. One e-mail purportedly about swine flu asked people to provide their name, address, phone number, and other information as part of a survey on the illness. And users of social networks are becoming popular targets. Twitter users

Attackers are also turning to instant messaging to lure people into their traps. In one recent scam a live chat window was launched via the browser. The scammer communicated to victims via the chat window, pretending to be from a bank and asking for additional information

What are other recent examples of phishing attacks?

A recent e-mail scam asks PayPal customers to provide additional information or risk getting their account deleted because of changes in the service agreement. Recipients are urged to click on a hyperlink that says "Get Verified!"

E-mails that look like they come from the FDIC include a subject line that says "check your Bank Deposit Insurance Coverage" or "FDIC has officially named your bank a failed bank." The e-mails include a link to a fake FDIC site where visitors are prompted to open forms to fill out. Clicking on the form links downloads the Zeus virus, which is designed to steal bank passwords and other information.

E-mails that look like they come from the IRS tell recipients that they are eligible to receive a tax refund and that the money could be claimed by clicking on a link in the e-mail. The link directs visitors to a fake IRS site that prompts for personal and financial information.

A legitimate-looking Facebook e-mail asks people to provide information to help the social network update its log-in system. Clicking the "update" button in the e-mail takes users to a fake Facebook log-in screen where the user name is filled in and visitors are prompted to provide their password. When the password is typed in, people end up on a page that offers an "Update Tool," but which is actually the Zeus bank Trojan.

What are some tell-tale signs of a phishing attempt?

Many phishing attempts originate from outside the U.S. so they often have misspellings and grammatical errors. Some have an urgent tone and they seek sensitive information that legitimate companies don't typically ask for via e-mail.

What should I look for in an e-mail?

Check the sender information to see if it looks legitimate. Criminals will choose addresses that are similar to the one they are faking. For instance, phishers have used "Alerts@Paypal.co.uk." However, legitimate PayPal messages in the U.S. come from Service@paypal.com" and include a key icon. Most phishing e-mails come from outside the U.S. so an address ending in ".uk" or something other than ".com" could indicate it's a phishing attempt.

The e-mail address may also be obscured. Hitting "reply all" may reveal the true e-mail address. You can also set your e-mail preferences to show "full header" to see the full e-mail address and other information. If you are at all unsure whether the e-mail is legitimate, go to the company's Web site to see the address listed.

Legitimate companies tend to use customer names or user names in the e-mail, and banks often will include part of an account number. Phishing emails typically offer generic greetings, like "Dear PayPal customer."

Inspect the hyperlinks inside the body of the e-mail. Phishers typically will use subdomains or letters or numbers before the company name, and sometimes the words in the links are misspelled. For example, www.BankA.security.com would link to the 'BankA' section of the 'security' Web site. Often, it's difficult to tell if the link is legitimate just by looking at it. By mousing over the link you can see the real address on the bottom of most Web browsers.

In addition, PayPal, Amazon, banks, and many other businesses use the SSL (Secure Sockets Layer) protocol which is designed to ensure that customers are visiting the real site. That means https:// will be seen in the URL address bar instead of just http:// and usually there will be some other change in the address bar. For instance, PayPal displays a "P" and its name is highlighted in green at the front of the URL. The major browsers have antiphishing measures designed to detect malicious sites. Some phishers also try to hide the real Web address they are sending victims to by using URL shortening services.

If the e-mail has an attachment, be wary of .exe files. Scammers like to hide viruses and other malware there so it executes when opened.

Do not be fooled by the look of the Web site you may be directed to. The Web site may look just like a real bank or PayPal page, including the use of the real logos and branding. It could be a good fake page or it could be a legitimate page with a phishing pop-up window on top.

How can phishing attacks be avoided?

-Try to stay off spam lists. Don't post your e-mail address on public sites. Create an e-mail address that is less likely to get included in spam lists. For instance, instead of bobsmith@xyz.com, use bob.smith.az@xyz.com.

-If an e-mail looks reasonable contact the company directly if you receive an e-mail asking you to verify information. Type the address of the company into the address bar directly rather than click on a link. Or call them, but don't use any phone number provided in the e-mail.

-Don't give out personal information requested via e-mail. Legitimate companies and agencies will use regular mail for important communications and never ask customers to confirm log-in or passwords by clicking on links in e-mail.

-Look carefully at the Web address a link directs to and type in addresses in the browser for businesses if you are uncertain.

-Don't open e-mail attachments that you did not expect to receive. Don't open download links in IM. And don't enter personal information in a pop-up window or e-mail.

-Make sure you are using a secure Web site when submitting financial and sensitive information.

-Change passwords frequently. Don't use the same password on multiple sites.

-Regularly log into online accounts to monitor the activity and check statements.

-Use antivirus, antispam, and firewall software and keep your operating system and applications up-to-date.

(My colleague Larry Magid has more tips and a podcast interview with Symantec on avoiding phishing attacks.)

What can I do if I think I've been victimized by phishing?

The Anti-Phishing Working Group has a comprehensive site explaining exactly what steps people should take based on what type of information they have given out.

Where can I report phishing attempts?

You can forward suspected phishing e-mails to reportphishing@antiphishing.org and spam@uce.gov. Companies typically have an address to forward phishing examples to, such as "spoof@company.com." Always include the entire phishing e-mail. Complaints can be lodged with the Internet Crime Complaint Center at the FBI. ( cbsnews.com )


READ MORE - "Verify Your Account Info"? It's Phishing