Showing posts with label cybersafety. Show all posts
Showing posts with label cybersafety. Show all posts

Friday, February 8, 2019

What is Phishing and How To Spot It


The blog Phishing.org defines phishing as



a cybercrime in which a target or targets are contacted by email, telephone or text message by someone posing as a legitimate institution to lure individuals into providing sensitive data such as personally identifiable information, banking and credit card details, and passwords.






We've all been exposed to phishing emails. It's easy to be taken in by them, although it is also possible to avoid them with a little knowledge and effort. The phishing scammers are getting more sophisticated but fortunately the basic rules for spotting these scams still work in most instances. This graphic has a lot of good advice.


https://www.knowbe4.com/what-is-social-engineering/

Notice that the graphic contains advice for business email users, not just personal ones. If you use email at work, please pay attention! This advice is related to another common fraud called spear phishing. That's an attempt to get insider information from a business--information like email addresses of top executives or access to customer data. Sometimes the data will be used directly, as in an order from the CEO to transfer money to a fraudulent account. At other times it will be used to breach the system and install malware, permitting long-term damage. In any event, this post focuses on the personal email user.

The basic advice for spotting phishing emails is:
  1. If it sounds too good to be true, it undoubtedly is.
  2. It is urgent; the recipient will miss out unless she responds immediately.
  3. It asks for personal information. Never reply to this type of email, even if (especially if) it purports to be from an institution like the IRS or your bank. Never. Period. Don't even confirm personal information sent to you in an email.
  4. The sender is unknown or looks fishy (pun intended :).
  5. There are hyperlinks that look strange--don't match the sender, for example. It's best not to even click on these links to check them out.
  6. It's poorly written with spelling and grammatical errors or awkward sentence structure.
  7. It has an attachment. Don't even bother to examine the attachment closely--if the email is in any way suspicious don't open the attachment. Malware lives there.
  8. WHEN IN DOUBT, JUST DELETE IT. 
The chances you are going to ignore a legitimate email that has any of these characteristics is pretty low. However, it you're a worrier, pick up the phone and call the supposed sender. That's safe!

All legitimate internet businesses are concerned about phishing; it makes the internet less trustworthy for all of us. Google has performed an excellent service with this exercise in spotting phishing emails. Use the link provided and give it a try!

https://phishingquiz.withgoogle.com/

Don't worry about being embarrassed by naivete. I missed a rather humiliating number of the 10-item quiz and Google was very nice about it!

Take the quiz and stay safe!

Tuesday, November 20, 2018

Toys That 'Do No Harm' - Holiday Gifts 2018

When my children were growing up we accessed a report on dangerous toys that had mechanical or usage issues that could cause unexpected harm. Now the scene has shifted. The question is, "Do the toys listen in on family conversations or otherwise invade privacy?"

It's an important question and maybe even harder to evaluate than the mechanical issues I was hopeless at. Mozilla is the non-profit developer of the open-source browser Firefox, which many of use in preference to a commercial browser. Their second annual report on connected toys that do not have serious privacy issues is a welcome addition to the 2018 holiday season.


Here's a link to the report. Note that users can include their own ratings to further increase the quality of the recommendations.

Most of us will include some connected electronics products on our gifts lists, so this should be required reading for all!

Stay Safe this holiday season!

Friday, October 26, 2018

The Future of Fake News

We have seen the future of fake news and it's Artificial Intelligence. MIT Technology Review did a series on AI and disinformation and here's a quote from their newsletter:

The big change: AI now makes it possible for anyone with a decent computer and a few hours to spare to do what only used to be possible at a big-budget movie studio: create believable, but totally fake video footage. Further machine-learning advances will make even more complex deception possible--and make fakery harder to spot.
Deep fakes and politics: Convincing AI enabled face swaps—called deepfakes—that threaten to further blur the line between truth and fiction in politics. “Deepfakes have the potential to derail political discourse,” says Charles Seife, a professor at NYU. “Technology is altering our perception of reality at an alarming rate.”
Easy to fake: Tools for creating these false videos are becoming increasing easy to use. Our own Will Knight easily stitched Ted Cruz's face onto Paul Rudd. As he writes, perhaps the greatest risk is that the technology will further undermine truth and objectivity. It’s not that the truth won’t still be out there—it’s that we might not know it when we see it.
 

            
Here are a couple of videos that illustrate the issues.



The first one allows any klutz to superimpose cool dance moves onto his or her frame. That's fun! And the authors explain how they did it.


This presents an unsettling view of the future. Is there anything that can be done? Or more specifically, can technology rescue us from the danger it has created?

There is a possibility that technology can come to the rescue. Wired describes a Darpa program called MediFor—Media Forensics. Remember, the Defense Advanced Research Programs Agency (DARPA) gave us the initial structure of the internet. The program is a national security effort, so that suggests it is well funded. 


The DARPA effort includes many complex technologies like facial recognition, but the Wired article is easily comprehensible to the layperson. I urge you to read it in its entirety--it has good news as well as bad.

That's a fitting note on which to end my #CyberAware posts. But I'll be following up on many of these topics in the very near future.

I hope you've enjoyed this month of posts and

Stay Safe!

Related Content:
Deep fake of Mark Zuckerberg 

Tuesday, October 23, 2018

How Can You Tell It's Fake News?

Fake news is not new. Apparently the Ancient Greeks were masters of it. However, the Ancient Greeks didn't have the internet. We all know that fake news flourishes there. Problem is, how do we spot it.

Here's an infographic from the IFLA with 8 good tips. And the infographic itself provides several good lessons.

https://www.ifla.org/publications/node/11174

Lesson 1. It's from the International Federation of Library Institutions and Associations. That's a mouthful, so the acronym is much appreciated. But it's easy to look up (search for) with almost 3 million results. The first ten, at least, look entirely reputable.

Lesson 2. The infographic has the name of the organization as part of the graphic. That's not a solid clue because some fake news organizations like to promote their names and make it easy to find their content also. However, checking on the origin of the publication is important if you have any doubt at all, and making it easy is good.

Lesson 3. I've put the URL for the link in the caption anyway. It's a .org, not some kind of flaky URL. That's super important. That's the key issue, but the name of the organization in the link is also correct and straightforward. No deception here.

Lesson 4.  The website itself is solid, not a thrown-together mishmash. It has a really interesting set of pages on their vision for the future of libraries. More relevant to the current issue, the article has a link to FactCheck.org, which is a well-known fact-checking group.

Lesson 5.  Finally, I'll give the advice I've been giving my students for years. Use the golden rule of journalism. Two sources are necessary. Three is the gold standard. If three reputable publishers agree on the facts, there's a good chance they are true.

If there are opposing arguments, keep on reading. That's one thing we do too little of these days--listening to arguments from opposing sides. 

Hint: it gets more difficult from here on in. Tomorrow I'm going to tackle how to identify fake news on social media feeds.

Stay Safe!

Related Updates
Good example of fake news targeting the Red Cross
How fake news happens 

Sunday, October 21, 2018

Sunday Advice: What's a Suspicious Email?


A suspicious email is any message designed to get the recipient to provide personal data. Phishing is the most common method. Here is a definition of phishing from StaySafeOnline:

A phishing attack is a form of social engineering by which cyber criminals attempt to trick individuals by creating and sending fake emails that appear to be from an authentic source, such as a business or colleague.

Their advice on how to spot phishing emails is:
  1. The email asks you to confirm personal information
  2. The web and email addresses do not look genuine
  3. It’s poorly written
  4. There’s a suspicious attachment
  5. The message is designed to make you panic.
It often takes a technical specialist to conclusively determine whether an email is a phishing attack or just something stupid. The layperson should not worry about being sure it is phishing. Just being suspicious is enough to take the appropriate action

When in doubt, throw it out! 

Don't want to run the risk of alienating a friend or colleague? Compose a new message using your own contact information. Briefly explain that the email looked funny and you discarded it to be on the safe side. If it was important, they can reply to your email. 

Watch for suspicious emails
and
Stay Safe!

Thursday, October 4, 2018

Good Online Safety Resources

This site is part of the sponsoring organization for #CyberAware month and has safety tips that everyone ought to check out. Access the Resources Library from the Stay Safe Online home page.
Most will want to use the Stay Safe Online tab shown in the graphic for personal safety tips. If you are a business owner, by all means investigate the tips for business safety.




And if you are just looking for a little light reading on the subject, scroll down to the bottom on most of those pages and look at the tips for safely planning a wedding in the Cyber Age. Yes, that's where we live!

Stay Safe!

Tuesday, October 2, 2018

Safety in Cyberspace Starts at Home


Here's a great infographic summarizing steps we should all take to  Stop  Think  Connect.

A good way to get involved, as the infographic suggests, is to share on social media. One way to do that would be to email a friend or family member with the link to this post or to the DHS toolkit in the previous post . I'd be very happy if you gave them the link to this blog and encouraged them to follow it by email so they will get all of this month's #CyberAware posts. I'd be even happier if you'd put the blog link on your Facebook page and share it with all your friends!

Stay Safe!




Friday, September 28, 2018

Why I'm Writing A Blog About Personal Data Protection

The subhead states the mission of the blog. I want to make key methods for protecting user data privacy and identify comprehensible to the m...