Most browsers allow autofill or similar functions. After enabling this feature the browser will fill in fields the browser has seen from one of your sessions.
A researcher found a site that captured all user's personal information and sent this information to the requesting site. This information included that person's name, mail address, email address, credit card number, credit card expiration date, credit cart CCV etc. The web site displayed the autofill-ed information with a negative offset on the user's screen. Thus the user would be unaware that information was being sent since the negative offset fields was not seen on the screen.
The feature is handy and is different from a browser asking if the user wishes to have the browser save credit card information.
If you wish to disable this feature you will need to do this for each and every browser you might use.
Use each browser's help function to disable this setting (autofill, auto complete or similar) if you wish to add this protection.
Friday, January 27, 2017
Wednesday, January 25, 2017
Identity Theft - IRS version
Noticed this story on the news recently. I know several people who have been victims. All of those victims have been working for years to get their federal tax issues from identity theft resolved.
The issue, with 3 items of Personal Identifiable Information (PII) anyone can file a federal tax return and get a check or debit card with a large refund. Victims of other identity theft breaches may not realize how PII can be cumulative (add up) to enough information to create multiple cases of identity theft.
Think of standing in line at the pharmacy. You over hear other's name and date of birth. Add their SSN and you can file a federal tax return. Those 3 items are available in oh so many places. Every other item of information needed to file a return can be falsified.
So, how to prevent this type of IRS fraud? File early with the IRS and invest in identity theft protections was on the news article. Until the IRS has a better and speedier method of validation of the items needed to file a tax return we are all at the mercy of thieves.
Use a WEB search engine to gleam further detail
The issue, with 3 items of Personal Identifiable Information (PII) anyone can file a federal tax return and get a check or debit card with a large refund. Victims of other identity theft breaches may not realize how PII can be cumulative (add up) to enough information to create multiple cases of identity theft.
Think of standing in line at the pharmacy. You over hear other's name and date of birth. Add their SSN and you can file a federal tax return. Those 3 items are available in oh so many places. Every other item of information needed to file a return can be falsified.
So, how to prevent this type of IRS fraud? File early with the IRS and invest in identity theft protections was on the news article. Until the IRS has a better and speedier method of validation of the items needed to file a tax return we are all at the mercy of thieves.
Use a WEB search engine to gleam further detail
Tuesday, January 24, 2017
Monday, January 23, 2017
Administrator
In presentations i mention to use a non-Administrator account for normal day-to-day use to avoid malware infections. Most malware runs as the current user. If that user is not an administrator the depth and scope of the malware byte (sic) may be lessened.
Administrator has almost full privilege on a Personal Computer (PC). Normal (non-admin) accounts have lesser privilege and rights. When a function or request requires administrator rights or privileges the Operating System (OS) will ask for an administrator account's passphrase. We will cover this in more detail at a Cyber Security SIG meeting.
Now to tell if your account is an administrator? How to add a non-administrator account? How to spot check that malware as not added or changed an account to add or remove administrator rights and/or privilege?
Microsoft Windows.
Bring up the Control Panel. Cortiana - Control Panel
Click on User Accounts:
By default the Control Panel User Accounts shows the current logged in user. john in this case.
Note john is a Local Account.
Now by using the Manage another account you should get a User Account Control (UAC) pop-up window. This pop-up window will blank the background windows so it is more difficult to ignore.
By supplying the cited administrator's passphrase the system will display a window with all known accounts. Accounts can be local, workgroup, homegroup or domain. We will cover those types in a SIG session.
Note jpj is an Administrator.
If your current login account is an Administrator you can use the Add a user account at the bottom of the window to add a non administrator accounts to use for day-to-day.
For Windows 10 you will get a pop-up asking for an email address to add a Microsoft account by specifying an email address for a Microsoft account. This is handy for visiting relatives so they can have their cloud or Microsoft content available while on your PC. For our purposes we want to add a local non-administrator account.
Click on the Sign in without a Microsoft account (not recommended) which i recommend.
Supply the requested information for the new non-Administrator account and click Next. This adds the local non-Administrator account to the system. Use the User Accounts Control Panel to verify the new account is a non-Administrator account.
Now you have an local account for day-to-day use and an Administrator account to use as required for Administrator functions. You can have more than one of each type of account.
For some functions you will get the User Account Control pop-up. Supply an Administrator passphrase and continue with the required function.
For some functions you may need to right click on the function and click on the Run as Administrator.
For some functions you many need to CRTL-ALT-Delete and choose Switch User to use an Administrator account.
IMPORTANT: Use the Administrator account(s) with care. With great power comes great responsibility. If a User Account Control pop-up appears during day-to-day use and you have not requested any service requiring Administrator rights or privilege do not supply an administrator passphrase without research. Typically this is malware or similar attempting privilege escalation.
Then again it may be required for a function. Use care with the UAC pop-up.
MacOS
Similar concept. Multiple non-Administrator and multiple Administrator accounts can be added.
Launchpad -> System Preferences > Users & Groups
This window shows the current Users and an indicator of Administrator rights and privileges. With the Allow user to administer this computer check box you can control the desired account(s).
Functions that require administrator rights or privileges will require you click on the lock icon labeled Click the lock to make changes and supply an administrator passphrase.
MacOS is linux based. So from the command line or terminal window use the technique listed for linux.
linux
from a command shell search for User IDentification (UID) of 0.
for linux based PCs administrator is UID of 0. grep is a shell command to search for UID of 0.
Administrator has almost full privilege on a Personal Computer (PC). Normal (non-admin) accounts have lesser privilege and rights. When a function or request requires administrator rights or privileges the Operating System (OS) will ask for an administrator account's passphrase. We will cover this in more detail at a Cyber Security SIG meeting.
Now to tell if your account is an administrator? How to add a non-administrator account? How to spot check that malware as not added or changed an account to add or remove administrator rights and/or privilege?
Microsoft Windows.
Bring up the Control Panel. Cortiana - Control Panel
Click on User Accounts:
By default the Control Panel User Accounts shows the current logged in user. john in this case.
Note john is a Local Account.
Now by using the Manage another account you should get a User Account Control (UAC) pop-up window. This pop-up window will blank the background windows so it is more difficult to ignore.
By supplying the cited administrator's passphrase the system will display a window with all known accounts. Accounts can be local, workgroup, homegroup or domain. We will cover those types in a SIG session.
Note jpj is an Administrator.
If your current login account is an Administrator you can use the Add a user account at the bottom of the window to add a non administrator accounts to use for day-to-day.
For Windows 10 you will get a pop-up asking for an email address to add a Microsoft account by specifying an email address for a Microsoft account. This is handy for visiting relatives so they can have their cloud or Microsoft content available while on your PC. For our purposes we want to add a local non-administrator account.
Click on the Sign in without a Microsoft account (not recommended) which i recommend.
Now you have an local account for day-to-day use and an Administrator account to use as required for Administrator functions. You can have more than one of each type of account.
For some functions you will get the User Account Control pop-up. Supply an Administrator passphrase and continue with the required function.
For some functions you may need to right click on the function and click on the Run as Administrator.
For some functions you many need to CRTL-ALT-Delete and choose Switch User to use an Administrator account.
IMPORTANT: Use the Administrator account(s) with care. With great power comes great responsibility. If a User Account Control pop-up appears during day-to-day use and you have not requested any service requiring Administrator rights or privilege do not supply an administrator passphrase without research. Typically this is malware or similar attempting privilege escalation.
Then again it may be required for a function. Use care with the UAC pop-up.
MacOS
Similar concept. Multiple non-Administrator and multiple Administrator accounts can be added.
Launchpad -> System Preferences > Users & Groups
This window shows the current Users and an indicator of Administrator rights and privileges. With the Allow user to administer this computer check box you can control the desired account(s).
Functions that require administrator rights or privileges will require you click on the lock icon labeled Click the lock to make changes and supply an administrator passphrase.
MacOS is linux based. So from the command line or terminal window use the technique listed for linux.
linux
from a command shell search for User IDentification (UID) of 0.
for linux based PCs administrator is UID of 0. grep is a shell command to search for UID of 0.
Wednesday, December 14, 2016
New twist on ramsomware
Ransomware, malware that encrypts files and promises to give one the encryption key to regain access to the encrypted files, has a new twist.
Instead of paying the ransom, victims can send the ransomware to others. If those "others" fall victim to the ransomware link the original victim gets their decryption key "for free".
So, just knowing the sender of the email or link was never enough to prevent malware or ransomware. Now it may be those you know that cause you grief.
A twist to the twist: If someone has a grudge against others....
Instead of paying the ransom, victims can send the ransomware to others. If those "others" fall victim to the ransomware link the original victim gets their decryption key "for free".
So, just knowing the sender of the email or link was never enough to prevent malware or ransomware. Now it may be those you know that cause you grief.
A twist to the twist: If someone has a grudge against others....
Thursday, December 8, 2016
NFC Near Field Communications
I've spoken on the topic of near filed communications (NFC) as it relates to credit cards. To expand to other devices and NFC's other issues and problems:
NBC has been warning of a "mystery device" that allows cars to be easily stolen since June, 2013. It made the evening news again 12/7/016. Most newer cars have the device. A key fob you carry, when it is within close range of the vehicle you can unlock the doors, raise the trunk, etc. With the key fob on or near your person you can start the car and drive away. Convenient. Law enforcement noted a increase in auto thefts and did not know how the thefts were facilitated. Seems thieves are using the key fobs NFC capability to clone the key fob, to use just as the owner does. Convenient. Videos online show a demonstration of the mystery device. The thief just follows closely behind an owner for a few seconds with the device, gets an indication the key fob has been copied and cloned, goes to the car, opens the door, starts the car and drives away. The auto industry is working on a solution. Until then park in crowded areas (not a problem during holiday shopping) and be aware of people in close proximity (a problem during holiday shopping).
Credit and debit cards, smart phones and other devices use NFC. The "Tap and GO" point of sale terminals use NFC. A similar method of getting close to the card and/or phone, copying the devices information, making a clone, then using the device to "Tap and GO" with your bank information for their purposes is being widely used as well. The device information can be copied while the card or phone are near a point of sell terminal -- or on your person. You can buy metal shielded envelopes to add some protection.
Another method thieves use is loading malware on your NFC capable phone. Usually disguised as a game, the malware uses NFC to search near by for a NFC credit or debit card, copies the information, then sends the bank details via email to the thieves. Again protect yourself with a metal shield envelope for the cards and be aware of your surroundings.
Yet another vector is phone to phone infection. Vendors of NFC capable phones show the use of tapping two phones together to transfer contact info, etc. That same "tap" can load malware to the phone.
Be aware. Be careful, Be safer.
NBC has been warning of a "mystery device" that allows cars to be easily stolen since June, 2013. It made the evening news again 12/7/016. Most newer cars have the device. A key fob you carry, when it is within close range of the vehicle you can unlock the doors, raise the trunk, etc. With the key fob on or near your person you can start the car and drive away. Convenient. Law enforcement noted a increase in auto thefts and did not know how the thefts were facilitated. Seems thieves are using the key fobs NFC capability to clone the key fob, to use just as the owner does. Convenient. Videos online show a demonstration of the mystery device. The thief just follows closely behind an owner for a few seconds with the device, gets an indication the key fob has been copied and cloned, goes to the car, opens the door, starts the car and drives away. The auto industry is working on a solution. Until then park in crowded areas (not a problem during holiday shopping) and be aware of people in close proximity (a problem during holiday shopping).
Credit and debit cards, smart phones and other devices use NFC. The "Tap and GO" point of sale terminals use NFC. A similar method of getting close to the card and/or phone, copying the devices information, making a clone, then using the device to "Tap and GO" with your bank information for their purposes is being widely used as well. The device information can be copied while the card or phone are near a point of sell terminal -- or on your person. You can buy metal shielded envelopes to add some protection.
Another method thieves use is loading malware on your NFC capable phone. Usually disguised as a game, the malware uses NFC to search near by for a NFC credit or debit card, copies the information, then sends the bank details via email to the thieves. Again protect yourself with a metal shield envelope for the cards and be aware of your surroundings.
Yet another vector is phone to phone infection. Vendors of NFC capable phones show the use of tapping two phones together to transfer contact info, etc. That same "tap" can load malware to the phone.
Be aware. Be careful, Be safer.
Wednesday, December 7, 2016
New smartphone, smartwatch, or other mobile device for holidays? Be sure to secure the old device's personal information.
Perform a backup of the old device
Factory resets on Apple and Android. Windows phones need more effort.
iOS: Settings -> General -> Reset -> Erase All Content and Settings
Android: Settings -> Privacy -> Factory Data Reset
If you are keeping your old phone number, the SIM card will be transferred to the new device. If not destroy it.
Subscribe to:
Posts (Atom)


