Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

McAfee warns about '12 Scams of Christmas'

Tuesday, November 24, 2009

Retailers aren't the only ones gearing up for the holiday season. Criminals are also out in force.

To highlight the increased crime during the holidays, security company McAfee has come up with the "12 Scams of Christmas" ranging from bogus electronic greeting cards that deliver malware instead of cheer to fake charities that steal your money and your identity.



It's especially important to be extra careful this time of year, says McAfee's David Marcus. "The bad guys know people are spending more time online, they're paying more bills online so [the criminals] stand a chance of being a bit more successful this time of year.

In a podcast interview (scroll down to listen), Marcus counted down the 12 scams of Christmas starting with:
  1. Charitable phishing scams: Marcus warns consumers to be wary of e-mails that appear to be from legitimate charities. Not only will they take your money and deprive charities of needed funds, but they will also steal your credit card information and identity.
  2. Fake invoices from delivery services: During this period, scammers will send out fake invoices and delivery notifications appearing to come from Federal Express, UPS, the U.S. Postal Service or even the U.S. Customs Service saying that they were unable to deliver a package to your address. They ask you to confirm your address and give them credit card information to pay for delivery.
  3. Social networking friend requests: Bad guys take advantage of this social time of year by sending out authentic looking friend requests via e-mail. Marcus recommends that you not click on those links but sign into Facebook and other services and look for friend requests from the site itself. Clicking on a link could install malware on your computer or trick you into revealing your password.
  4. Holiday e-cards: Be careful before clicking on a holiday e-card, especially if it's from a site you haven't heard of. This is a way to deliver malware, pop-ups, and other forms of unwanted advertising. Some fake e-cards will look like they come from Hallmark or other legitimate companies, so pay close attention and make sure it's from someone you know. If you're going to send an e-card, be sure you're dealing with a reputable service lest you risk infecting yourself and your friends.
  5. Fake "luxury" jewelry: If you see an offer for luxury gifts from companies like Cartier, Gucci, and Tag Heuer at a price that's too good to be true, it probably isn't true. These links could lead you to malware and take your money or merchandise that will probably never arrive (or be fake if it does). Some of these sites, according to McAfee, even display the logos of the Better Business Bureau.
  6. Practice safe holiday shopping. Make sure your wireless network is secure and be sure you're shopping on sites that are secure. Though it isn't an iron clad guarantee, you should look for the lock icon in the lower right corner of your browser and make sure the Web page starts with https. The "s" stands for "secure."
  7. Christmas carol lyrics can be dangerous: Bad guys know that people are searching for holiday related sites for music, holiday graphics, and other festive media. During this time, they create fraudulent holiday related sites.
  8. Job search related scams: With the unemployment rate at 10.2 percent, there are plenty of job seekers looking for work. Beware of online offers for high paying jobs or at-home money making schemes. Some of these sites ask for money up front, which is a good way for criminals not only to steal your "set up fee" but misuse your credit card too. Marcus said that some "get rich quick" sites are all about money laundering, asking you to accept an inbound financial transfer and pay them.
  9. Auction site fraud: McAfee has observed a rise in fake auction sites during the holidays. Make sure you're actually going to eBay or whatever site you plan to deal with.
  10. Password stealing scams: Criminals use low-cost tools to uncover passwords, in some cases planting key logger software to record keystrokes. Once they get your passwords, they gain access to bank accounts and credit card accounts and send spam from your e-mail accounts.
  11. E-mail banking scams: A common type of phishing scam is sending out official looking e-mails that appear to come from your bank. Don't click on any links but type in your bank's Web address manually if you need to access your account.
  12. Files for ransom: Hackers use malware to gain control of your computer and lock your data files. To access your own data you have to pay them ransom.
Bottom line--Don't let the eggnog and holiday cheer keep you from using your critical thinking skills when you go online during the holiday season. And, of course, make sure your operating system is updated and that you're using up-to-date security software.

credit:news.cnet

[Read More...]

The Best Security for Wireless Networks

Wednesday, October 21, 2009

Securing a wireless network isn't a hard task. The cheat sheet is relatively small. However, the technical press continues to be flooded with articles and blogs containing technical mistakes.

Take, for example, everyone's trusted information source, Consumer Reports Magazine. I'm a big fan of the magazine, having subscribed to the hard copy edition for years. But they seem out of their league, when it comes to computers.



On August 6, 2009 a blog posting at the magazine's website suggested using WEP security for wireless networks. This is very poor advice. A week after the posting, an editor corrected it, to say they recommend WPA security. This too, is not the best option. Even after being shamed into a correction, they still got it wrong.

So, let me try to offer up just what most people (and Consumer Reports) need to know about securing a wireless network.

Starting at the Beginning

To begin with, there are four types of Wi-Fi networks (A, B, G and N). But the security is not tied to any one type.

If you can connect to a wireless network without entering a password, then there is no security. In this context, the term "security" refers to encrypting data as it travels over the air.

The idea being to prevent a bad guy from capturing all the information coming into and out of a victims' computer and, in effect, looking over their shoulder despite being a few hundred feet away.

Wi-Fi networks offer three security options: WEP, WPA and WPA2. As a simplistic introduction, think of WEP as bad, WPA as just fine and WPA2 as great.

WEP is the oldest security option and it has been shown to be very weak. It may be better than no security at all, but not by much. Don't use it. Other than Consumer Reports magazine, the last recommendation to use WEP was issued in 2005.

WPA is technically a certification, not a security standard, but since it includes only one security protocol, TKIP, they are often confused. When people refer to WPA security, they are really referring to the TKIP protocol.

The combination of WPA and TKIP is not the best, but it's reasonably good. If you have a choice, you should opt for the best security (next topic), but if you don't have a choice (more later) TKIP is reasonably strong.

WPA2 is also, technically, a certification rather than a security standard. WPA2 includes two security standards: TKIP and CCMP. If you are using TKIP, it doesn’t matter whether the router is WPA or WPA2. TKIP is TKIP either way.

The best security option is CCMP and it's only available in WPA2, so, here again, the security protocol is often confused with the certification. When people refer to WPA2 security, they are really referring to CCMP.

But no one refers to CCMP (don't ask what it stands for). For whatever reason, the CCMP security protocol is referred to, incorrectly, as AES. So, when you are configuring a router, you need to first select WPA2, then you need to select AES (rather than TKIP) to get the best possible security and encryption.

WPA TKIP Flaws

The TKIP security protocol (often referred to as WPA) is flawed. The first flaw came to light in November 2008, the second one just last month. But neither flaw is serious.

The first flaw can be defended against simply by disabling Quality of Service (QOS) in your router. Very few people make use of QOS.

The second flaw was described by security expert Steve Gibson as mostly theoretical. For example, it requires that the victim’s computer be out of radio reception range from the router. The bad guy has to connect to the router on one side and the victim on the other side. The bad guy has to be logically and physically positioned between the victim and the router.

Neither flaw lets the bad guy recover the password and they only support decrypting very small data packets. None of these small packets will contain any of your data.

[Read More...]

Know Fraud and Identity Theft Online

Monday, October 12, 2009

Jakarta - The theft online is one of the crime in a virtual world that uses email, websites, chat rooms or message in your account page.

There are several types of this crime, that is phishing and pharming scams, using email or websites to trick the recipient of a message to terayu to provide personal data such as credit card data, social security numbers, and their important account password.



However, although the movement is growing guerrilla thief, not that hard to avoid it. Learn basic tips to deal with it so we do not fall this cyber world of fraud that mixed Symantec:

What to Do:

* Consider to disable file sharing on your computer.
* Be careful when opening file attachments, especially from unknown senders.
* Familiarize yourself to mamahami privacy policy on the internet, especially if you are asked to provide sensitive data or personal.
* Control the existing provisions in the bank and credit cards regularly.
* Install and regularly update the software firewall, antivirus, and anti-spyware you. We recommend using Norton Internet Security for a more comprehensive protection.
* To maintain the habit of updating the Windows operating system and other applications with the latest patches.
* Strengthen and secure passwords carefully, or consider using password protection software. Norton Internet Security is also able to encrypt passwords to better secure data storage, access to the computer so much to avoid the use of hand nosy. In addition, this software will also notify users if there are sites that offer need to login.
* Lock your mailbox.
* Mash or shredded recap or information obtained from the use of credit card or bank before discharge.
* Check your bank account and your credit card every month.
* Take advantage of free reports on your credit card transactions.
* If you feel you've become victims of identity theft or other cyber crimes, report to the authorities immediately.

What to Avoid:

* Do not provide personal data to anyone via phone or directly (including for purposes of seeking employment, applying for loans, etc.) unless you're absolutely sure that the person or institution can be trusted.
* Do not easily believe it and then reply to incoming email by providing your personal data, including the site obtained from the links, or pop-up ads that suddenly appear on the screen. Better, open a new browser page and type in URLs directly addressed in the address bar to make sure that the site is legitimate.
* Do not store financial data on a laptop unless absolutely necessary. Because portable computers more easily and frequently stolen than a desktop computer.

[Read More...]

Almost So FBI Director Online Fraud Victim

Jakarta - FBI Director Robert Mueller admitted he almost caught online fraud. As a result, Mueller prohibited access internet banking.


Mueller recognition so before the Commonwealth Club in California, United States, as quoted from SMH.co.au, Friday (9/10/2009).

Mueller said the experience showed how dangerous fraud on the internet today. Although she knew about online fraud, he was almost stuck because they do not care.

At that, Mueller said, he got an email that appears to come from the bank where she kept the money. Email it asked Mueller to verify a few things about the bill.

He has started to answer some questions from emails that when starting to suspect something was wrong. Finally he went to change internet banking passwords and deliver it to his wife.

Although not to lose money, because of the incident Mueller's wife was forced to forbid him to do internet banking transactions again.

The FBI on that occasion also says it has arrested 33 people in the U.S. and 47 people in Egypt who are involved in a network of online fraud. This is the result of the combined U.S. operations - Egypt called 'Phry Phish'.

credit: anthneic

[Read More...]
 
 
 
 
Copyright © Digital World
Template Modified by aNtH Blog