SECURITY: A scammer almost got me; I must be ready for the home!

Monday, August 3, 2026

*** begin quote ***

On Thu, Jul 30, 2026 at 12:20 PM Harold Kane <{Extraneous Deleted}> wrote:

I need to get an Amazon eGift card by email on Amazon, but I can’t do this now because all my effort purchasing it online proved abortive. I intend to buy it for a friend of mine who is diagnosed with breast cancer. Could you get it on Amazon online and have it sent to her email? I’ll reimburse you bask as soon as possible, Please let me know if you can handle this, so I can provide you with her email address.

Thanks,
Harold

*** end quote ***

Since the email looked legit, I << ALMOST >> fell for it.

I did think to ask the sender something, a shared secret, that could be used to prove identity.

Argh! 

Hard to believe that some                                        one as cynical as me <<ALMOST>> took the bait.

Stay sharp my friends the ne’er-do-wells are getting better!

— 30 —


SECURITY: One has to admire the swiftness of the criminal’s response

Saturday, March 28, 2026

https://www.schneier.com/blog/archives/2026/03/south-korean-police-accidentally-post-cryptocurrency-wallet-password.html

South Korean Police Accidentally Post Cryptocurrency Wallet Password
Posted on March 17, 2026 at 6:01 AM • 1 Comments

*** begin quote ***

An expensive mistake:

Someone jumped at the opportunity to steal $4.4 million in crypto assets after South Korea’s National Tax Service exposed publicly the mnemonic recovery phrase of a seized cryptocurrency wallet.

*** end quote ***

Wish I’d seen it first.

Hopefully the crook used a VPN and no cookies.

I’m jealous.  Sort of like a reverse lotto?

— 30 —


SECURITY: The old style secondary security authorization questions are dumb

Friday, February 27, 2026

I’ve often heard people struggle with the old style secondary security authorization questions.  You know: “What’s your favoite color”, or pets name, or school street.

I, long ago, decided that it was a “stupid control”.  So, in my passwrd manager, I’d record the questions and give absurd answers.  So, “what’s your favorite color”, became red158, pet’s name, red247, and street, red532.

Solved that problem.  

I still object to 2FA that rely on an SMS message and prefer Google Authenticator.  

But what do I know.

And, I don’t care for PASSKEYS either.  Not good for sites where I may have multiple ids or different Users.

Argh!

I also don’t like using my email for a User id.

Argh!

— 30 —


SECURITY: “Wo sind Ihre Papiere?” – Make the universal identifier to NOTHING!

Sunday, February 22, 2026

https://www.ecoticias.com/en/all-u-s-social-security-numbers-may-need-to-be-changed-following-a-massive-breach-that-is-already-being-investigated-as-a-national-threat/27158/?utm_source=tldrinfosec

By ECONEWS
Published On: February 13, 2026 at 6:30 PM

All US Social Security numbers may need to be changed following a massive breach that is already being investigated as a national threat (4 minute read)

*** begin quote ***

A whistleblower alleges a federal tech team improperly cloned the master Social Security database into a poorly governed cloud, potentially exposing rich identity data on 300+ million Americans and enabling long‑term fraud. Lawmakers have demanded criminal investigations. Officials insist that core systems remain secure.

*** end quote ***

Might be a blessing in disguise.  Time to change from SSN as the universal identifier to NOTHING!

Anything that uses SSN should be eliminated.  

We don’t need a Gooferment controlled registry.  Maybe I’ve watched too many Nazis in movies demanding “Wo sind Ihre Papiere?”  “Where is your papers?” There doesn’t seem to be a over whelming Gooferment “need” for such!

Maybe this is a perfect opportunity to end social security number, Social Security Insurance itself, and ALL the Gooferment welfare programs that hang off of it.

Time to cut the Gordian Knot!

— 30 —


SECURITY: Microsoft will provide BitLocker recovery keys to the FBI

Friday, January 30, 2026

https://www.ghacks.net/2026/01/24/microsoft-confirms-it-can-share-windows-11-bitlocker-keys-with-law-enforcement/

Microsoft Confirms It Can Share Windows 11 BitLocker Keys With Law Enforcement
Arthur K
Jan 24, 2026

*** begin quote ***

Microsoft has confirmed that it will provide BitLocker recovery keys to the Federal Bureau of Investigation if presented with a valid legal request. The confirmation follows reporting that Microsoft supplied encryption keys to law enforcement during a criminal investigation in 2025.

The situation is tied directly to how Windows 11 handles device encryption by default. When a user signs in with a Microsoft Account, the operating system automatically backs up the device’s BitLocker recovery key to Microsoft’s cloud unless the user explicitly chooses another option during setup.

*** end quote ***

This is “an upsetting disclosure”. 

Computer noobs, and average Users will incorrectly assume that their “keys” are only theirs to control.

Like the bitcoin admonition, “not your keys; not your coins”, if anyone has your “encryption keys” they have your data.

The important part to be aware of is that the technology company who gives up your keys is under no obligation to inform you.  Then may even be “silenced” by the court order.

The internet, a while ago, developed the “warrant canary”, which is displayed on their website. When served with a gag order, they take the canary down.  You can be silenced but you can not be forced to display it.  Your Users can infer from its absence that you have been served.

When the Gooferment exceeds its Constitutional role, our liberty is at risk.  Hence I urge every one to display the “warrant canary” to demonstrate their commitment to the First Amendment and free speech.

“The Founders knew that a democracy would lead to some kind of tyranny. The term democracy appears in none of our Founding documents. Their vision for us was a Republic and limited government.” — Walter E. Williams  

— 30 —


SECURITY: Personal lesson make your User Id random

Tuesday, January 27, 2026

OK so I’ve become very lazy —  security wise.

My Frau version 2 recently got “hacked”.  Not exactly sure what or how it happened BUT, (and there is always a BIG butt), she was getting text code to confirm a password change on a financial account’s website.  She attributed to yet another credit card being “stolen”. Not sure if I agree with that. Given that she uses a childhood nickname as her User Id, then I suspect maybe the financial institution or one of its many contractors or data handlers has had a leak.

Anyway, I’ve begun changing all my User Ids from something easily know or guessable to some random string generate by my password manager. For example, instead of “myname@myemailprovider.com”, I’m now know as “Unthread1-Batch7”.

Belt and suspenders?  Maybe.  But who can tell!

— 30 — 


SECURITY: OpenTable isn’t just for customers — it shares ALL your data from ALL venues

Saturday, December 6, 2025

https://www.theverge.com/report/822110/opentable-ai-assisted-data-restaurants

Your online reservations are telling restaurants all about you

  • OpenTable is sharing your dining habits, both good and bad.

by Dominic Preston
Nov 17, 2025, 1:59 PM EST

*** begin quote ***

Your Online Reservations Are Telling Restaurants All About You [theverge.com]

If you make reservations through OpenTable, restaurants may be getting more information about you than you realize. Because OpenTable isn’t just for customers…it’s “billed to restaurants as a one-stop shop” that can integrate with restaurants’ payment and order management systems. When you make a new reservation, OpenTable gathers information “based on the orders you’ve made and money you’ve spent at other restaurants in the past” and shows it to restaurants using AI-assisted tags. According to an OpenTable representative, “what [they] share with restaurants is guided by the choices you’ve made in your privacy preferences,” but The Verge found the platform’s privacy policy “actually a little opaque on this.”

Want to opt out of this data sharing? “You can do so by logging into your account, heading to your profile, and then going to the ‘Preferences’ page. You’ll find six options related to the privacy policy, but the one that matters most is the last one: ‘Allow OpenTable to use Point of Sale information.’ Untick that, and your order history should be your own again.”

*** end quote ***

Surprise, surprise.  And, you thought OpenTable was wearing a “white hat”!  Argh!

I remember a Law & Order episode where a Mafia informant was killed when a special cake was delivered to a fancy restaurant in lower Manhattan.  (The Shearson data center was near by and I was familiar with it and the area.). So is OpenTable a security risk.  Maybe is your looking over your shoulder for a hitman, process server, or a jealous ex-lover.

More common reason would be that your treatment at a restaurant may be related to your spending habits (i.e., big spender gets special treatment; poor tipper gets spit in their food).  YMMV!

And like most tracking done by your phone, it may subject you to unexpected intrusions. 

Consult the Electronic Freedom Foundation for more horror stories.

— 30 —


SECURITY: New Hampshire cold case should be a warning

Friday, December 5, 2025
https://nypost.com/2025/11/26/us-news/new-hampshire-judith-lord-cold-case-solved-half-a-century-later-identifying-ernest-gable-as-killer/
 
New Hampshire cold case is solved half a century after flawed FBI report allowed killer to escape
By Nicholas McEntyre
Published Nov. 26, 2025, 1:25 a.m. ET
 

*** begin quote ***

Despite Gable being identified as a suspect, he could not be properly accused because “the case was severely hindered by a flawed forensic report issued by the FBI in 1975,” Formella said.

“At the time, microscopic hair analysis techniques led to an incorrect conclusion that the suspect could not have contributed the hairs found at the scene,” the report found.

Other evidence contradicted the analysis results, with Gable’s fingerprints being found at the scene and witnesses revealing that Lord had feared him.

During their investigation, detectives discovered Lord had been afraid of both her husband and Gable for some time because of his “persistent and unwanted advances.”

“Judith told her sister she was afraid of both her husband and her African American neighbor next door, indicating Mr. Gable, because he ‘had made remarks to her about wanting to see her nude,’” the attorney general’s report found.

*** end quote ***

​A solved cold case that should be a warning to everyone.  Don’t stay where there are creepy neighbors.
 
And maybe this is not the only “mistake” due to the FBI incompetence?
 
#endtheFBI
 
— 30 —
 
 
 

SECURITY: Bitcoin mining hardware exec falls for sophisticated crypto scam

Sunday, November 30, 2025

https://arstechnica.com/information-technology/2025/11/bonkers-bitcoin-heist-5-star-hotels-cash-filled-envelopes-vanishing-funds/

Bitcoin mining hardware exec falls for sophisticated crypto scam to tune of $200k
Joel Khalili – Nov 18, 2025 1:37 PM 

*** begin quote ***

As Kent Halliburton stood in a bathroom at the Rosewood Hotel in central Amsterdam, thousands of miles from home, running his fingers through an envelope filled with 10,000 euros in crisp banknotes, he started to wonder what he had gotten himself into.

Halliburton is the cofounder and CEO of Sazmining, a company that operates bitcoin mining hardware on behalf of clients—a model known as “mining-as-a-service.” Halliburton is based in Peru, but Sazmining runs mining hardware out of third-party data centers across Norway, Paraguay, Ethiopia, and the United States.

As Halliburton tells it, he had flown to Amsterdam the previous day, August 5, to meet Even and Maxim, two representatives of a wealthy Monaco-based family. The family office had offered to purchase hundreds of bitcoin mining rigs from Sazmining—around $4 million worth—which the company would install at a facility currently under construction in Ethiopia. Before finalizing the deal, the family office had asked to meet Halliburton in person.

*** end quote ***

Sorry, but NO ONE gets cash filled envelopes in an honest transaction.

That should have been the first clue to a scam.

Then to “prove a capability or a holding” of bitcoin transfer some to a strange wallet?

Just reading the story, my ex-CISO “spydee senses” were on high alert.

And inputing a key “seed phrase” into an unknown software wallet you just downloaded was just the height of stupidity.

Sorry to pile on and beat a “dead horse”, but the warning signs were there.

Who knew if “wealthy Monaco-based family office” was even a real entity.  Or if they even knew what was going on in their name.

Argh!

“You can’t cheat an honest man.” — W. C. Fields

— 30 —


SECURITY: Germany may dictate no end-to-end encryption

Tuesday, October 14, 2025

https://digitalchew.com/2025/10/05/chat-control-could-break-encryption-warns-signal/

Chat Control Could Break Encryption, Warns Signal
Reginald Edward
October 5, 2025

*** begin quote ***

Key Takeaways

  • Signal’s president warns Germany that Chat Control could destroy user privacy.
  • Chat Control forces apps to scan messages before encryption.
  • The plan would weaken secure chats and allow mass surveillance.
  • Signal says it will leave the EU if Chat Control becomes law.
  • Germany’s vote on Chat Control could shape global privacy rules.

*** end quote ***

And what happens when one Gooferment does it —  whatever the particular “it” is, other Gooferments think “what a great idea” and do it too.

Argh!

— 30 —