Showing posts with label Email spam. Show all posts
Showing posts with label Email spam. Show all posts

Thursday, October 12, 2017

Equifax Web-Page Goes Offline Amid Reports Of New Breach

Equifax has taken one of its web pages offline as its security team looks into reports of another potential cyber breach, the credit reporting company, which recently disclosed a hack that compromised the sensitive information of 145.5 million people, said on Thursday.






"We are aware of the situation identified on the equifax.com website in the credit report assistance link," Equifax spokesman Wyatt Jefferies said in an email.



"Our IT and security teams are looking into this matter, and out of an abundance of caution have temporarily taken this page offline."



As CBC reports, the move came after an independent security analyst on Wednesday found part of Equifax"s website was under the control of attackers trying to trick visitors into installing fraudulent Adobe Flash updates that could infect computers with malware, the technology news website Ars Technica reported.





When I clicked it (from Gmail on Android) I was redirected to a spam page shortly after seeing the Equifax credit file form.





I thought maybe it was an anomaly because it didn"t happen again. But after reading your article about how sometimes hacks will redirect randomly I tried the link again just now and sure enough I got a spam page again (lucksupply.club saying I won an iPhone X). This is Chrome-in-a-tab from Gmail so i don"t believe there"s any extensions or other malware on my device that could have caused this redirect.



EFX share price is tumbling...


Sunday, June 11, 2017

Tracking Hacking: Visualizing The World's Biggest Data Breaches

The graphic below shows a timeline of some of the biggest data breaches on record. As Visual Capitalist"s Chris Matei notes, each bubble represents the number of records lost in any given breach, with the most sensitive data clustered toward the right side.


This data visualization comes to us from Information is Beautiful. Go to their site to see the highly-recommended interactive format that visualizes the same data, while providing additional details on each specific hack.





Before 2009, the majority of data breaches were the fault of human errors like misplaced hard drives and stolen laptops, or the efforts of “inside men” looking to make a profit by selling data to the highest bidder. Since then, the volume of malicious hacking (shown in purple) has exploded relative to other forms of data loss.


FROM MILLIONS TO BILLIONS


Increasingly sophisticated hacking has altered the scale of data loss by orders of magnitude. For example, an “inside job” breach at data broker Court Ventures was once one of the world’s largest single losses of records at 200 million.


However, it was eclipsed in size shortly thereafter by malicious hacks at Yahoo in 2013 and 2014 that compromised over 1.5 billion records, and now larger hacks are increasingly becoming the norm.


SMALL BUT POWERFUL


The problems caused by hacks, leaks and other data breaches are not just ones of scale. For example, the accidental 2016 leak of information from spam/email marketing service River City Media stands out at an alarming 1.37 billion records lost. However, sorting by data sensitivity paints a different picture. The River City leak – represented by the larger blue dot below – is surpassed in severity by hacks at Yahoo, at web design platform Weebly, and even at adult video provider Brazzers.



Much of the data lost in the River City hack was made up of long lists of consumer email addresses to be used for spam email distribution, while the other hacks listed compromised items like account passwords, banking information, addresses, phone numbers, or health records. While having your email address become the target for spam exploitation is a serious annoyance, the hacking of much more sensitive personal data has quickly become the norm.


The fact that more and more of our data is being stored “in the cloud” and among devices on the Internet of Things means that increasingly sensitive types of data are now more vulnerable than ever to being hacked. This looks to be even more cause for concern than the rapidly rising volume of records that have been exposed, whether intentionally or by accident.

Saturday, June 3, 2017

Robocalling is out of control: End the robo call spam fraud virus attacks

(GLOBALINTELHUB.COM) - 6/2/2017 Robocalling is out of control.  Once the domain of sophisticated telemarketers, now it has spread to include cyber fraud, international telemarketing, and some unknown services that just "dial" numbers with no reason (this appears to be the most bizarre).


The spam phone calls have become so out of control, it"s even common now for people to get a landline or other number just to use as their phone number, in that case what"s the point of having a phone?  The issue here needs to be looked into at the network level, by telcos like ATT (T), Verizon (VZ), and others.  How spammers, fraudsters, and barely legal telemarketers (who often cross the lines of "regulation") use the networks to harass legitimate users needs to be stopped.  The "Do Not Call" list is a joke - it"s not enforced and not used.  Registration will stop a small percentage of legitimate telemarketers who use the lists and go through the compliance process, but the problem is that it doesn"t protect anyone from the "black" side of the robocalling industry, which is organized largely outside of the legal borders of USA.


Global Intel Hub interviewed our parent company about this issue, Elite E Services.  EES has many registered domains, for more than 15 years with a Godaddy reseller FX System Hosting (a brand).  Godaddy is now a public company Godaddy Inc (NYSE:GDDY), so they are subject to the same complaints and oversight as any public company.  And Godaddy needs to be careful, as this is a potentially toxic legal issue.


Godaddy sells "privacy" for each domain, making the owner of record "private" - showing only a proxy company operated by Godaddy "Domains by Proxy" - it"s possible to break this veil of privacy only in extreme cases such as a subpoena or matters of national security.  But why would the average domain owner want to keep their records private, especially since the idea of having a website at all is usually for the purposes of marketing (or at least, having your business information become public).  Recently, the answer has been in order to stop the spam calls and emails.  Godaddy makes the whois records public, which are somehow picked up by these foreign robocallers automatically, and the calls start.  They don"t know what is DNC and they don"t speak English.  Half of the time when you actually answer these calls they just disconnect.  Other times, a scratchy connection as one would hear when calling Afghanistan in the 80s from a phone booth, a man speaking broken English is asking if you need website design.  An agent of Elite E Services asked for this man"s name ansector 5d address to which he replied "Sector 5, Calcutta - Justin Smith" - with a little Google research at least Sector 5 really is a real place.  Justin Smith, doesn"t sound like an Indian name though.  When confronted with this fact he says "My fathers" name is Joseph Thomas Smith we are Christian" - maybe, but anyway who is to know?  And why are they calling a number that is on the Do Not Call list?


That"s not all.  Another "foreign" US caller, when asked that we be removed from their list, said "No, no no no.. no - NO .. no no no .. I WILL NOT remove you from my list (click)." at which point the really aggressive calls started, saying that we could be arrested due to an IRS issue, call this number immediately, 202 334 4562 (has been shut down).  "Sometimes we can get 20 or 30 spam calls a day," says an anonymous agent working for Elite E Services, "Sometimes, they will call 2 or 3 times in a row, you can"t block them - they use another number."


Supposedly, Trump"s appointee is doing something about this:



Ajit Pai, the FCC chairman appointed by President Trump, called robocalls a "scourge" in a blog post earlier this month. He noted that an estimated 2.4 billion robocalls are placed to Americans each month.


"There is no reason why any legitimate caller should be spoofing an unassigned or invalid phone number," Pai wrote. "It"s just a way for scammers to evade the law."


The FCC currently prevents phone companies from proactively blocking calls. The new rule would let phone companies block any robocaller that uses a number that has not been assigned to any customer or that has a nonexistent area code.


The FCC"s approach was developed in partnership with a "robocall strike force" of tech, cable and telecom companies formed last year. Members include Apple (AAPLTech30), Google(GOOGLTech30), Microsoft (MSFTTech30), Verizon (VZTech30) and AT&T (TTech30).


The rules probably won"t be finalized and approved for at least a few months.



Meanwhile, the calls continue.  And since most of the callers are hiding behind the international wall of stupidity erected around the USA"s legal system, there"s little US phone users can do except turn off their phones.


This is a bad sign for the telecom sector and for Godaddy, at a time when the "telephone" struggles for its place in a busy digital world.  


If you would like a free consultation from a consumer rights law firm, visit Fortis Law Group @ www.fortisconsumerlaw.com


For all your online shopping needs, bookmark www.pleaseorderit.com YOUR STOP for Amazon orders with great savings and special offers!

Friday, March 31, 2017

How To Protect Your Online Privacy Now That Congress Sold You Out

Authored by Eric Limer via Popular Mechanics


All your private online data—the websites you visit, the content of your chats and emails, your health info, and your location—just became suddenly less secure. Not because of hackers, but because Congress just blocked crucial privacy regulations. This will allow your internet service provider to collect all your data and sell that info to the highest bidder without asking you first. Welcome to a brave new world.


A pair of resolutions, which passed through the Senate and House with exclusively Republican votes, roll back rules proposed by the Democratic leadership of the Federal Communications Commission during the Obama administration which, though passed in October, had not yet gone into effect.


The rules—which will be completely dead following the expected signature of President Trump—would have required ISPs to get explicit opt-in approval from customers before selling the following "sensitive data":


Passwords


 


This doesn"t just mean that sharing that information without your explicit permission will be fine and dandy. Since the rules were rolled back through the Congressional Review Act, the FCC is also barred from creating any "substantially similar" rules down the line.


In theory, the information collected will be stored under some sort of ID separate from your actual name. But that"s a cold comfort considering the level of detail in this sort of information would make your identity a dead giveaway, and ISPs can hardly be trusted to keep your identifying information suitably safe from prying eyes. After all, they"ll be building dossiers any hacker would love to steal.


What to do? There are a few things you can do to try and keep your data safe, and while they aren"t necessarily easy or free, they"re worth it if you value your privacy.


Opt out with your ISP


Your ISP may not need your permission to sell your data, but you can still go to them and tell them not to do it. The catch, of course, is this requires you to be proactive, and there"s no real guarantee that this will protect you completely. Still, do it. Get on the phone or visit the website of your ISP and opt out of every ad-related thing—and into every privacy-related thing—you can find. The process can be a little arduous—often requiring the use of your ISP-given email address that you probably never use—and it may not take effect immediately either. All the better reason to do it now.


Time Warner/Spectrum customers can find their privacy dashboard here. Comcast customers can opt out of some targeted programs using these instructions. Verizon customers can find opt out options here. Remember, your phone company is technically an ISP too, so look up your options on that front as well.


Opting out is an important first step, but it is not enough to actually preserve your privacy. Your ISP is not necessarily giving you the opportunity to opt out of all its ad-targeting programs. As the policy counsel at the Open Technology Institute, Eric Null, told Gizmodo, it is "highly unlikely" the new FCC will go after ISPs that aren"t offering robust opportunities to opt-out.


Some smaller ISPs, which survive on small and satisfied customer bases as opposed to a large and captive audience, are more incentivized to protect your privacy with gusto. In fact, a whole host of small ISPs wrote a letter to Congress opposing this move. If you"re lucky enough to have the option of switching to one, now might be a good time.


Keep your data out of your ISP"s hands in the first place


Your ISP is uniquely suited to snoop on your information. Anything you put online has to pass through its hands. Email you send through Gmail, chats through Facebook Messenger—they all travel through your ISP before they reach the service that actually sends them on. But while it is impossible to cut your ISP out of this exchange entirely, you can hide the data as you are sending it.


Apps with end-to-end encryption can encrypt your private information on the phone or computer you"re using, ensuring that it is coded and protected through the entire delivery process. So while your ISP can see the data go by, they can"t make sense of it.


Secure chat apps like Signal will be crucial to keep your chats private not only from the government and hackers, but from your ISP. Just make sure these services have security measures that are open-source and trusted by experts who can help keep them honest. You can also encrypt data manually, using a standard like PGP, before you send it off into the web, but it can be an arduous process, because you have to ensure that the recipient has the means to decode that info and read it.


The most seamless solution is to pay for a Virtual Private Network—a VPN—which allows you to encrypt all the data that passes through your ISP. This means that while your ISP is still doing the work of hauling your data around, it can"t understand any of it. The downside to this is that VPNs (at least any VPNs you can trust) are not free. Most good ones will require a yearly subscription. Furthermore, you aren"t hiding your personal data from everyone, you are just entrusting it to the VPN instead of your ISP, so do your research and choose a VPN you trust not to sell you out. Fortunately, since VPNs exist exclusively to keep your data private, they are pretty incentivized to keep you happy.


The only one you can really trust to protect you is you.


The short and uncomfortable truth is this: Until more robust privacy protections are put in place, the burden of protecting your online data falls on you. Keep it in mind, do your research, and remember that your monopolized ISP has every reason in the world to sell you out and wring your data for every dime that it is worth. The only one you can really trust to protect you is you.

Wednesday, January 11, 2017

EU Proposal Would Kill Spam In All Forms (Phone & Email) Without Consumer Opt-In

Submitted by Mike Shedlock via MishTalk.com,


A new EU Privacy Ruling proposal would effectively kill all forms of spam unless people opt in.


The privacy ruling would also allow consumers to use ad-blockers, but publishers will be allowed to withhold content from consumers who do.
ad-block


Please consider EU Proposal on Ad Blockers Welcomed by Publishers.





Media companies will be allowed to ban customers who use ad blockers under new online privacy rules proposed by the European Commission.



More than 200 million people are estimated to use ad blockers, depriving publishers of revenues but relieving users of often intrusive adverts.



[In the ruling, people can use ad-blockers, but publishers can withhold content from those who do.]



Publishers welcomed the move. Paul Lomax, chief technology officer of Dennis Publishing, a UK publisher that owns The Week, said: “It is vital that we retain the right to protect our content from those who wish to circumvent that value exchange.”



Brussels rolled back plans to introduce “privacy by design” that would have required all browsers such as Firefox and Google’s Chrome to automatically use a “do not track” setting, stopping online advertisers from following people around the web.



Instead users will be asked whether they want to opt in to such tracking. Advertisers fear that many will not opt in to tracking, in a change that would upend industry practice.



Smaller advertisers complained that these new rules would favour the likes of Facebook and Google, who have the scale to gather permission from users more easily. “A few global tech companies already in possession of immense data pools would be able to circumvent the nature of the law anyway,” said Stevan Randjelovic from the European Association of Communications Agencies, a lobby group that represents advertising and media companies.



In a bid to reduce the number of so-called “cookie warnings” — the pop-ups on websites in the EU — the commission will allow browsers such as Firefox and Chrome to offer blanket settings that would approve all cookies. Likewise, simple cookies used for purposes such as measuring traffic on a website would not require permission.



Anti-Spam Measures


Diving into the Privacy Ruling we find a heavy dose of anti-spam rules consumers will like.


  1. All electronic communications must be confidential. Listening to, tapping, intercepting, scanning and storing of for example, text messages, emails or voice calls will not be allowed without the consent of the user. The proposed Regulation also specifies when processing of communications data is exceptionally permitted and when it needs the consent of the user.

  2. Confidentiality of users’ online behaviour and devices has to be guaranteed. Consent is required to access information on a user’s device – the so-called terminal equipment. Users also need to agree to websites using cookies or other technologies to access information stored on their computers or to track their online behaviour. The proposal clarifies that no consent is needed for non-privacy intrusive cookies improving internet experience (e.g. cookies needed to remember shopping cart history, for filling in online forms over several pages, or for the login information for the same session). Cookies set by a visited website counting the number of visitors to that website will no longer require consent.

  3. Processing of communications content and metadata is conditioned to consent. Privacy is guaranteed for content of communication as well as metadata – for example who was called, the timing, location and duration of the call, as well as websites visited. Metadata linked to electronic communications have a high privacy component and need to be deleted or made anonymous if users did not give their consent, unless the data is needed for billing purposes.

  4. Spam and direct marketing communications require prior consent. Regardless of the technology used (e.g. automated calling machines, SMS, or email), users must give consent before unsolicited commercial communications is addressed to them. This will in principle also apply to marketing phone calls unless a Member State opts for a solution that gives consumers the right to object to the reception of voice-to-voice marketing calls, e.g. by registering on a do-not-call list. Marketing callers will need to display their phone number or use a special prefix number that indicates a marketing call.

No-Spam


The big ruling is number 4. No one will opt in for phone or email spam. The US has “do not call lists”, but they do not work. I typically get 2-4 trash calls a day despite being on a no-call list.


I suspect such lists will work in the EU.


All in all, this is a mixed ruling that will please no one in entirety. But consumers, especially those badgered with phone solicitations, will get welcome relief.