Showing posts with label dangers. Show all posts
Showing posts with label dangers. Show all posts

December 3, 2019

FaceApp: How Dangerous Is It?

FaceApp: Should I Delete It?


Updated: December 3, 2019

Screenshot From FaceApp.com

You may have seen the slew of "What would I look like as an old person" photos that have been shared to Social Media recently. You may also have seen warnings in the media that this app is "Bad News." Just how bad is it? Should you delete the app and reset your phone? Or is it really as harmful as much of the media is saying?

What is FaceApp?


FaceApp is a photo app available for Android and iPhone.  It basically allows one to apply filters to photos.  You can do things like swap genders, add makeup, add tattoos, and otherwise enhance all of your selfies. The latest app update added the ability to "age" or "de-age" selfies as well.

FaceApp is not a new app. It has been around since 2017. However, it recently became viral, thanks to its ability to age you in selfies, as well as share side-by-side photos to social media.

What Are the Concerns with FaceApp?


November 12, 2019

New USPS Scam Arrives in Inboxes, Just in Time for the Holiday Season

New USPS Scam Arrives in Inboxes, Just in Time for the Holiday Season

Do NOT Open The Attached File


scam image


Today, I had a couple of USPS delivery notifications land in my inbox. 2 of these notices were legitimate. However, the third was not.  The fake e-mail was so good, I almost thought it was real.. Were I not an "Informed Delivery" user, I might have fallen for it.

August 22, 2019

Do NOT Return That Call

Phishing Calls May Leave International Call Back Numbers:
Do NOT Return that Scam Call


do not phone graphic


Today, I received an old scam call with a new twist.  The caller ID showed 833-539-8666, and when I let the call go to voicemail, I received the following message:

Attention this is from Social Security Administration to inform you that your social security number is going to be suspended for committing some fraudulent and suspicious activity. Please call 335-309-8666.  Thank you.

So I googled the callback number. The first page of Google results were all in Chinese characters.

Chinese Characters in Google Results


August 14, 2019


Malvertising: Not All Browser-Based Security Warnings are Legit


McAfee has expired warning


This is NOT a real Security Warning; It is an Ad!


If this suddenly popped up while you were browsing, would you think it is legit?

Several days in a row, I have had the Bradenton Herald open in another tab, reached by following a link to read an article. By the time I switched over to the tab, I actually had to use the "Back" button to read the article.

Folks, this is just an ad in disguise. DO NOT be fooled and click on the actual link. This is why so many of us surf using ad-blockers. And in fact, my ad-blocker is being re-enabled on this site, as I am sick of scam ads interupting my news reading.

I do not even use McAfee or recommend it to others. I am not sure if clicking the link would actually bring you to a legit security product. More likely, it would lead to malware, the exact opposite of software that protects your PC.

Do NOT fall for this adware scam!

July 26, 2018

You DO NOT Owe for an Overdue Invoice

Billing Scams are a Common Form of Spear Phishing

Do NOT Click Through or Open the Attached File




It's time to take a look at a few of the e-mail scams that have been filling inboxes recently. Some of these were sent to me personally; others were forwarded to me by some of my customers, who wanted to know if they were legitimate or not.  These e-mails are cut and pasted from the originals. In any case an e-mail contains an inline URL, I have changed that URL so it will NOT "work" if you click on it by mistake.  I have NOT stripped out links completely, so that readers may use the "hover trick" to see that the links, in fact, do NOT lead to where you'd expect. (Remember, you can hover your mouse over ANY link, and a program will show its true destination in either the status bar or in a pop-up tooltip.)

You DO NOT Owe for an Outstanding Invoice from a Company Whose Name You Do Not Recognize


This spear-fishing e-mail claims you owe money, and tells you to click a link to settle your bill.  Clicking on the link will take you to a site where they will trick you into disclosing personal info, and most likely will plant malware on your system while doing so.

June 29, 2018

Data Breaches: What Do They Mean For You?

How to Safeguard our Information
in a World of Security Breaches


What Can We Do when Our Data Gets Out?


Yesterday, all of the tech publications were warning of another major data breach.  Another popular Facebook App exposed users' personal data, and this time, over 120 million users were possibly affected.    Who was careless with our data this time? Nametests.com, a site Techlaurels warned users about over a year ago.

In a nutshell, Nametests had this hole where if you knew the right JavaScript commands, you could potentially access any users' personal information.  A website could exploit this, or any individual who knew how to grab and use a "token."  The "good guy" who discovered this used the flaw to set up a data mining program and subsequently reported the bug to Facebook. The security hole was supposedly closed.

And of course Nametests wanted that hole closed as soon as it was discovered. Who is going to buy a candy bar if there is a bowl sitting next to the register that says "Yours for the taking."  Or to borrow from an old cliche, if you're in the business of selling cows, you don't want to be giving the milk away for free.

June 26, 2018

No Microsoft Refunds, No Camera Hacks: New Scams

The Latest Attempts to Scam You
By Email and by Phone



Microsoft Has NOT Been Ordered to Issue Refunds, No One Has Hacked Your Webcam, and No One is Coming to Arrest You


It has been a while since we've looked at e-mail you should just ignore and voice mail phishing attempts.  A couple of new attempts to separate you from your money have cropped up lately, all involving scare tactics designed to make you act without thinking.  First comes a junk call scam, telling you you're owed a rebate, next comes an e-mail that reports someone is spying on you, and last comes an arrest threat based on a non-existent debt.  Keep reading to find out the details of each, so you'll recognize them and not panic should they come your way.

April 3, 2018

Disconnect Your Facebook Apps to Protect Your Personal Data

Facebook Apps May Treat Your Personal Information Like a Commodity



Remove Facebook App Connections to Protect Your Personal Data


We are still reeling from the fallout of the Cambridge Analytica scandal.  Cambridge Analytica purchased data from Facebook App Developers, and then they used it to try to influence us politically.  If you are interested in reading more about the hows and the whys of this breech, please see our previous post, The Facebook Kerfuffle and What it Means For You, as well as all of our previous articles on privacy and protecting your data.  Your data was compromised because you trusted the wrong apps with it.

Now you are aware of why the data miners are creating all of these apps, it is time to disconnect them so that they will no longer have access to your personal information or the contents of your Facebook Profile.  Removing apps used to be quite a tedious process, so many of us just ignored it or put it off, until our Facebook Account was cloned, a rogue app started posting on our behalf, or friends started complaining of receiving messages we never sent.  Thankfully, in response to this catastrophe, Facebook has streamlined the process of app removal, making it much easier. They have also made it easier to see just what kinds of permissions the apps request, as well as to selectively remove permissions. Today, we're going to look at how to do this.  We'll guide you through finding your connected apps, purging those you no longer use or recognize, and examining the permissions the remaining apps require.

February 15, 2018

Telephone Phishing: Voicemail Messages You Should NOT Return

Phishing Phone Calls:
No, There is No Warrant for your Arrest,
and the Police are NOT on Their Way



DO NOT Return a Scammer's Call


Today's world is full of people who are fraudulently trying to separate you from your hard earned money.  Phishing has become a real problem on the Internet, something we've talked a lot about on this blog in the past.  Spoofed e-mails. bad links, text message spam, and malicious Facebook Posts are common ways in which the fraudsters attack.  

But what about offline? Are you safe from phishing attacks if you do not use the Internet at all? Unfortunately, the answer to that question is no.  As people get wiser about online attack strategies, the Bad Guys have begun to attack you offline.  And one of the most prevalent methods of offline phishing uses your telephone.

Today, we're going to look at Phone Phishing.  We are also going to look at two phishing attempts, both employing voicemail.  In both cases, these are examples of voicemails you should NOT return.

January 18, 2018

E-Mail Deactivation Scams


No, Your E-Mail Account Is NOT About to be Closed

Account Closure E-Mails are Another Form of Phishing

 




Account Deactivation E-Mails

Have you received an e-mail stating your ISP is going to deactivate your e-mail account? Did you panic?  Well, you can relax, as these "Account Closure" e-mails are just another form of phishing, and they can safely be junked.

To review, phishing is a form of spam. in which the bad guys try to steal your personal information by impersonating someone trustworthy.  We've talked about phishing many times in the past.  The Bad Guys use sophisticated tactics to try to separate you from your personal information, often so they can impersonate you and/or steal your identity.  E-mails threatening to close your e-mail account if you do not click on a link are no different.

November 30, 2017

Delivery Notification Scams

Holiday Shopping Season Brings Out
the Delivery Notification Scammers


Do NOT Get Phished by a Bogus Delivery Notice


Black Friday and Cyber Monday set online ordering records this year.  US shoppers spent over $1.59 billion on Cyber Monday alone. Millions of online orders were placed during the past week. And of course, that means millions of packages will be delivered by UPS, USPS, and FedEx. That also means these companies will be sending out millions of delivery notification e-mails.  But does that mean all of these delivery notices are legit? Of course not. 

The scammers do not discriminate. They pretend to be from UPS, The Us Postal Service (USPS), FedEx, and even DHL.  They may claim to need more information from you in order to deliver a package, or they may claim to hold tracking information.  They may claim there is postage due, and you need to click on a link to arrange payment. They may use official looking graphics, or they may be sent in plain text.  And they may or may not be caught by a junk mail filter.

These scams are so ubiquitous that FedEx, USPS, UPS, and even DHL warn against them on their own websites.   UPS offers an 83 page PDF with examples of fraudulent e-mails.  Today, we're going to look at some of these bogus e-mails, so we can learn what to look out for and avoid getting scammed.

November 22, 2017

Black Friday: Don't Get Scammed


The Biggest Shopping Weekend Brings Out the Scammers



Shop Safely and Avoid the Cyber Shopping Scams



Black Friday, Cyber Monday, and basically the whole Thanksgiving Weekend are some of the biggest shopping days on the planet.  Almost every cyberstore has some kind of special, and our Inboxes and Social Media Feeds are full of discounted offers.  And although there are many legitimate sales, there are just as many scammers looking to rip you off on this big shopping weekend.  Don't be a fool, and look out for the Black Friday Shopping Scams.  Here are a few of the more popular ways to separate honest folks from their hard earned money.

Bogus Order Confirmations

Bogus order confirmations are a form of spear phishing. Scammers send hundreds of fake order confirmations, hoping you will click through to cancel an order.  Basically, the scammer steals official looking logos and graphics from a major retailer, then uses them in an order confirmation purporting to be from that retailer.  These phishing attacks multiply on Black Friday, as many folks are placing online orders during that time.  The e-mail may spoof Best Buy, Amazon, Ebay, Target, WalMart, Costco, etc.  If you click through the fake e-mail, you will be taken to a cloned log-in site.  The scammers are hoping to steal your shopping log-ins, so they can go on a shopping spree with your money, and even lock you out of your own account.

November 12, 2017

A New Way to Phish: Survey Spam


Beware of Phishing Attacks via Surveys



Scammers Can Use Surveys to Steal Your Personal Information;
That Survey Invitation May be a Phishing Attack in Disguise



The Scammers just keep getting more creative, finding new, seemingly legitimate ways to steal and misuse your personal information.  Survey spam is one of the latest methods Spear Phishers are using to trap their victims.

Spear Phishing refers to a targeted e-mail attack.  Spear phishers send you personalized spam e-mail that usually appears to be from a trusted contact.  That e-mail is intended to trick you into taking an action that will open you to harm. A Spear Phishing attack may try to plant malware, steal your information, and/or trick you into revealing log-ins and passwords.  A Spear Phisher's intentions are never good.

As cyberspace wisens up, the Phishers find new ways to steal your information. One of these ways is through survey spam.

Folks love to participate in surveys.  Often, surveys contain a sweepstakes component to help entice users to take it. "Five survey  participants will be randomly chosen to receive a $50 Amazon Gift Certificate" is a common come-on.  Many companies use legitimate surveys for market research and quality assurances.

June 16, 2017

Mail that Should NOT Be Opened

Not All E-Mail Should Be Opened

Avoid Malware by Avoiding Malicious E-Mail




The longer you have had an e-mail address, the more probability you'll receive spam. If you read any of our series on The Privacy Implications of Internet Quizzes, you know that there are many unscrupulous folks out there, eager to harvest your information. Facebook like scams, phony giveaways, and the like are all set up with the express purpose of harvesting your e-mail address. Once harvested, those addresses are often sold. That results in spam.

By definition, Spam means unsolicited commercial e-mail. It is usually sent to a large number of recipients.  It has come to connote scams and shams. It is actually illegal. The US passed the CAN-SPAM Act in 2003, regulating commercial e-mail. But the Bad Guys are not known for following the laws.  Legitimate companies always include opt-out information in order to comply with the law. Spammers use it to their advantage, often including links that look like legitimate opt-out links, but that only lead to malicious content. Additionally, unsubscribing from a SPAM e-mail only confirms to the bad guy that you read your e-mails, making your address even more valuable.


Now much spam is actually harmless. By harmless, I mean it's just attempting to sell you something. That something is probably counterfeit, if it even exists to begin with. More spam actually tries to cause harm to you or your equipment. That spam is not as harmless. It may plant malware on your computer. It may try to steal your credentials, so the crooks can steal your money and/or pose as you and ruin your reputation.

Today's post is going to focus on e-mail you should not open. ALL of this mail landed in my inbox within the last week. Some of these were correctly filtered by my spam filter; others landed in my inbox, and I had to manually mark them as junk. All e-mails have been converted to screenshots, due to their malicious content. (Remember, you can click on the images to open them larger, in an "overlay.")

May 22, 2017

Privacy Implications of Sweepstakes, Freebies, and Like-Farming Sites

Sweepstakes and Freebies are great for Marketing Purposes;
They're Also Great for Mining Your Information

Be Smart When Entering Contests or Requesting Freebies




Our last few posts have focused on the privacy implications of Internet Quizzes.  We are currently evaluating SAFE quiz sites, and that series will resume when we've had a chance to complete our research. (The bad sites are MUCH more numerous than the legit ones.) But quiz sites are not the only data miners out there.  You must be just as cautious when participating in sweepstakes and contests, as well as when signing up for freebies of any kind.

Playing the "Sweeps"


I have been an avid "sweepser" since the they went online.  (Those of us who enter contests and sweepstakes as a hobby affectionately call it "Sweepsing."  People who do this are "Sweepsters.") Before there was a World Wide Web, I returned the occasional sweepstakes card, figuring I might get lucky for the cost of a stamp.  I foolishly dropped my business card in bowls at restaurants, promising a drawing for a gift card or exotic vacation.  Then I wondered where all that junk mail and those time share calls were coming from.

May 19, 2017

More on Internet Quiz Sites and the Associated Dangers

What Are You Giving Up When You Use One Popular Facebook Quiz Engine?  Maybe More Than You Think...

A Review of Nametests.com





This is the third part in a series on what you also give up when you take an Internet Quiz.  Part 1 focused on General Dangers.  Part Two reviewed the terms of use for one popular Internet Quiz site. Today, we're going to look at nametests.com.  I think about 75% of the quiz results that come across my own Facebook timeline come from nametests.com.  I think few folks visit the sire directly.  Most click-through friends' shared results to take the same quiz.  While there, they often fall into a click-hole, taking other quizzes suggested at the end of the one they just took. How many readers have taken a test at nametests?  How many of you have actually looked at their terms of services?

May 12, 2017

Quick Tip: What "Refresh" Means in Windows 10

Refreshing Your Operating System is
NOT Similar to Refreshing Your Screen





The term "Refresh" has been around since the days of MS-DOS. We've learned that the circle with an arrow icon stands for refresh, and that refreshing or reloading may help when things go wonky.  If you keep getting that "more stories" link on Facebook, images aren't loading, or your desktop suddenly looks strange, refreshing your screen has become almost second nature.  If things just don't look right, refresh.  99% of the time, that fixes things. We right-click and select "refresh," hit the F5 key, or click that circle with an arrow icon all the time to fix issues.

Then along comes Windows 10. Windows 10 was the first Operating System distributed primarily by downloading an update.   Few users have install disks, even if they bought a PC with Windows 10 pre-installed.  And Windows 10 looks A LOT different, confusing a lot of users.  All of the Tech Gurus tell new Windows 10 users not to worry, because it operates just the same.  All of the things that worked in previous versions of windows work in Windows 10.  The same keyboard shortcuts and right-click commands are there, and they perform just like they always did.

And so your PC starts acting up, and you're sure you should try the same old tricks you've tried in the past to avoid a visit from your Computer Person.  You start exploring the settings menu,  You click on the settings menu to try a system restore, when you come across the option to refresh your system. "Okay, let's try that," you think.  You tell Windows to refresh your PC, thinking it will just log you out of everything and reload it, similar to the way refresh works in every other situation.  Your PC reboots itself, and EVERYTHING is gone.  You panic.  "Where is my Quicken?  Where is my Outlook and all of my e-mails...it's can't be just all gone?  My games are gone, and I'd just reached that impossible level.  UGH!"


May 9, 2017

The Dangers of Internet Quizzes

Are Facebook Quizzes Really Harmless?


People LOVE taking Social Media Quizzes.  Sites like Buzzfeed have entire sections devoted to quizzes.  Facebook timelines are filled with results shared from various quiz-hosting sites.  Quizzes and tests can be great traffic drivers, and from a marketing standpoint, they can be very beneficial to your site.  But what about from a user standpoint?  Are there any dangers of taking these internet tests and sharing the results?  The answer, unfortunately, is neither yes nor no.  There can be great dangers in taking these internet quizzes, or they may be completely harmless.  If you scrutinize before you click, you can easily learn the difference.

What Are Some of the Dangers of Taking a Quiz?

The dangers fall into several categories.  Again, a quiz site may be harmless, and none of these dangers may apply.  Or it may be a complete and total scam site, out to cause you harm.  Most quiz sites fall somewhere between these two extremes. The trick, as with any internet activity, is to be savvy.  You need to arm yourself with the knowledge to evaluate the risks of each individual quiz. This list is by no means inclusive.  It only describes SOME of the dangers you may encounter.