SECURITY: Time to end credit card number and social security numbers

Tuesday, February 18, 2025

https:///174085/cyber-crime/google-tag-manager-gtm-e-skimmer-software-in-magento.html

https://securityaffairs.com/

Crooks use Google Tag Manager skimmer to steal credit card data from a Magento-based e-stores

Pierluigi Paganini

February 11, 2025 

*** begin quote ***

Crooks use Google Tag Manager skimmer to steal credit card data from a Magento-based e-stores

Threat actors are using Google Tag Manager (GTM) to install credit card skimmer malware on Magento-based e-stores, according to Sucuri researchers. The malware hides in a website’s database and steals credit card information entered during the checkout process, sending it to the attackers’ server. This sophisticated attack demonstrates how criminals are using legitimate platforms like GTM to deploy malicious code that is difficult to detect. 

*** end quote ***

Isn’t it about time to retire the concept and strategy of using numbers for identification?

Social Security Numbers, credit card numbers, account numbers, or any kind of numbers are just not secure enough any more.  I even have my doubts about crypto keys used for “wallets”.

The Gooferment and Visa are the primary actors that we need to lead the change. 

Medicare transitioned from a number to an alphameric string to stop the frauds.  Why can’t social security?  

I’m not sure what should take its place but how about a secure hash of your name?

“John Q Public” could easily become “9YWJSN0BSVR3IKNV11A2HZM 8X70I24JXUA6REACFTXYD7WC436”!

Go ahead hackers guess that!

—30—


SECURITY: Why doesn’t the Gooferment mandate not using SMS for 2FA?

Saturday, January 25, 2025

https://www.makeuseof.com/why-sms-2fa-insecure/?user=cmVpbmtlZmpAZ21haWwuY29t&lctg=7e6c3cd411d6a815afa18582d54bd455914c43c5f69df1448b8ec20ee4959f71

Why I Don’t Use SMS for 2FA (and What I Use Instead)
By John Awa-abuon
Published Dec 14, 2024

  •     SIM Swaps Allow Hackers to Steal Your Phone Number
  •     SMS Messages Can Be Intercepted
  •     SMS Is Tied to Your Phone Number
  •     What I Use Instead: Authenticator Apps

Two-factor authentication (2FA) adds a vital layer of security to your online accounts, but unfortunately, not all methods are created equal. Many people rely on SMS-based 2FA, assuming it’s a safe choice. Unfortunately, SMS is far from foolproof. Here’s why I’ve stopped using SMS for 2FA and what I use instead…

*** begin quote ***

What I Use Instead: Authenticator Apps

Rather than relying on SMS for 2FA, I’ve switched to 2FA authenticator apps. Apps like Google Authenticator, Microsoft Authenticator, and Authy generate time-based one-time passwords (TOTP) directly on your device, offering a much safer and more reliable alternative to SMS.

The first major advantage of authenticator apps is security. Unlike SMS, these apps generate codes locally on your phone, meaning they’re not transmitted over networks that could be intercepted or exploited. They’re also protected by additional layers of security—many apps require a passcode, fingerprint, or face scan to access the codes.

Another reason I prefer authenticator apps is their offline functionality. Since the codes are generated directly on the device, you don’t need a cellular connection to use them. Whether you’re in a remote area with no service or simply indoors with poor reception, you can still access your codes as long as you have your device.

I prefer Authy over other authenticator apps because it offers cloud backups, making it easy to recover my accounts if I lose my phone. At the same time, it secures these backups with encryption, ensuring that only I can access them. Google Authenticator is another popular choice. Both options are free, widely supported, and easy to set up.

Using an authenticator app is straightforward. Once you’ve set it up, usually by scanning a QR code provided by the website during the 2FA setup process, you simply open the app to access a code whenever you log in. The codes refresh every 30 seconds, so even if someone manages to steal one, it becomes useless almost immediately.

Two-factor authentication is essential for keeping your accounts secure, but the method you use matters. While SMS-based 2FA might seem convenient, it’s riddled with vulnerabilities—from SIM swaps to interception methods and even practical issues like poor cellular reception. These risks make SMS an unreliable safeguard for your online security.

*** end quote ***

The Gooferment politicians and bureaucrats have warned that the phone networks have been hacked.

So why not MANDATE better security.   

Seems simple to me?

—30—


SECURITY: Got a pin for an Affirm account I don’t have?

Thursday, January 9, 2025

You have to be kidding me!  They “are aware of the issue”?  I went into full “identify theft” mode.  

“BATTLE STATIONS.  All hands report.  Stand by to fire at any available target.  Notify CIC of any intruders.  You are authorized to fire at any unidentified objects.  THIS IS NOT A DRILL.”

I was ready to trigger password reset on all financial and email accounts.

Argh!

But they “are aware of the issue”!

*** begin quote ***

Dear Fedinand,

Thank you for contacting Affirm!

I’m Alejandra from the Customer Care team, and I hope you are doing well.

If you don’t have an Affirm account, please ignore the text message that you received. We are aware of this issue and working on a fix. Be sure to not give your pin out to anyone. Do not click on any links sent referring to OTP (one-time passwords) if you did not request it.

*** end quote ***

YMMV

—30—


SECURITY: Do NOT use the “Go to Apple ID.” link

Wednesday, November 27, 2024

https://www.tomsguide.com/computing/online-security/new-scam-says-your-apple-id-is-suspended-watch-out-for-this-attack?lrh=20fd2805ce1d1131c95034f150bb97a3971479cbf1c94537a55e6a39cfe362aa

New scam says your Apple ID is suspended — watch out for this attack
News
By Amber Bouman
last updated 16 hours ago

  • Don’t let hackers get their hands on your Apple ID with these tips

*** begin quote ***

Another day, another attempt to steal your log in credentials – this time courtesy of a phishing email that claims to be from Apple Support. Don’t be fooled however, this isn’t from Cupertino. It’s actually an attempt to get you to click on a link so hackers can steal your login credentials and other sensitive information.

This email, like many other phishing attempts, uses look-a-like formatting and other details to make you think it’s coming from a legitimate source. This latest threat says that your Apple ID has been suspended due to unusual activity or missing or invalid information. The email looks remarkably similar to actual emails from Apple Support and contains a blue button that says “Go to Apple ID.”

*** end quote ***

It is really amazing that this <synonym for excrement> still works.

Browsers should not automatically make emails clickable.

Argh!

—30—


SECURITY: Once again, a warning to “firewall” and “air gap” personal technology from your employer

Thursday, October 17, 2024

https://www.macrumors.com/2024/10/09/do-not-use-iphone-mirroring-corporate-mac/

Here’s Why You Shouldn’t Use iPhone Mirroring on a Corporate Mac

Wednesday October 9, 2024 4:31 am PDT by Tim Hardwick

*** begin quote ***

Apple’s new iPhone Mirroring feature in macOS Sequoia might seem like a convenient way to access your phone from your work computer, but security firm Sevco has uncovered a significant privacy risk that should make employees think twice before enabling this feature on company-owned Macs, at least for now.

*** and ***

When executed in a Terminal window that has been granted full disk access without setting up iPhone Mirroring, the command returns a normal list of macOS applications. But when executed in that same Terminal window after setting up iPhone Mirroring, it also returns personal iOS applications and metadata.

For employees, this means that apps they use privately could become visible to their employer’s IT department without their knowledge or consent. This could potentially reveal sensitive personal information, such as dating apps, health-related apps, or VPNs used in countries with restricted internet access.

*** end quote ***

Your employer, their network, and their tools should NEVER be used for your private purposes.  

The easiest way to ensure that separation is to maintain a strict “air gap” (i.e., strictly never connecting anything by wire, bluetooth, or network wifi to something “corporate”).  

If for no other reason than when your employer gets hit with a virus, ransomware, or some corporate security “tool”, then it would get your hardware in its grasp.

Argh!

Don’t forget that the employer can claim your hardware is suspect of having their data on it!

—30—


SECURITY: A static social security number is the flaw in EVERY financial security scheme

Saturday, October 12, 2024

https://www.theregister.com/2024/10/04/comcast_fcbs_ransomware_theft/

Cybersecurity Month
About a quarter million Comcast subscribers had their data stolen from debt collector

  • Cable giant says ransomware involved, FBCS keeps schtum

Connor Jones
Fri 4 Oct 2024 // 20:13 UTC

*** begin quote ***

Among the data types stolen were names, addresses, Social Security numbers, dates of birth, and the Comcast account numbers and ID numbers used internally at FBCS. The data pertains to those registered as customers at “around 2021.” Comcast stopped using FBCS for debt collection services in 2020.

*** end quote ***

As with ALL problems, digging down for who’s at fault, eventually end at the Gooferment.

I remember n=my original Social Security card as saying in big red font all caps “NOT FOR IDENTIFICATION PURPOSES”.

I’m sure that the tin foil hats of that era would have opposed it for either “THE MARK OF THE DEVIL” or “where is your papers please” or just the enumeration of privacy concerns.  And they, like almost all Conspiracy Theorists, would have been correct.  Look what a mess SSN has created.

At the root of the problem is the SSN.  

Fundamentally insecure!  Medicare abandoned the SSN on its own medicare cards.  Never explained but probably due to fraud.  Which still is a huge problem.

I suggest that the SSN be abandoned.  Credit cards use a 16 digit number with error correction in it and the “secret” card code on the back.  Why can’t the same be done to replace SSN.

Sure “credit reporting agencies”, banks, brokers, and all would have to retool.  

So what.

No one ever voted to approve this Universal Identifier.  

So let’s unvote it out.

Surely SCIENCE can come up with a better one.  Maybe based on our DNA, or biometric, or maybe nothing is best.

Google and Apple now have passkeys based on their device’s “biometric”.  

Even that would be better than SSN!

# – # – # – # – # 

FOOTNOTE: The word schtum means to remain silent. Specifically, it means not sharing any information, or telling anyone what you know. Schtum is most often used when referring to information that is harmful or sensitive in nature.

—30—


SECURITY:  YubiKeys are vulnerable to cloning attacks

Wednesday, September 4, 2024

https://tldr.tech/infosec/2024-09-04

TLDR Information Security 2024-09-04

https://arstechnica.com/security/2024/09/yubikeys-are-vulnerable-to-cloning-attacks-thanks-to-newly-discovered-side-channel/

YubiKeys are vulnerable to cloning attacks thanks to newly discovered side channel (3 minute read)

The YubiKey 5 hardware token for two-factor authentication has a cryptographic flaw that makes it vulnerable to cloning attacks when physically accessed by an attacker. Yubico has confirmed that all YubiKey 5 models are susceptible to cloning due to a side channel vulnerability in the Infineon microcontroller used in various authentication devices. Updating firmware on affected YubiKeys is not possible, leaving them permanently vulnerable to potential attacks.

# – # – # – # – # 

Guess that you can toss these in the trash can or trash bin!

Still think that the authenticator app of a phone is the best two factor authentication technique.

—30—


SECURITY: A lesson in what phishing looks like

Wednesday, July 10, 2024

https://www.amazon.com/gp/video/detail/B0CQCDMY2V/ref=atv_dp_share_r_em_5605dba96bbd4

The Beekeeper

A retired military operative, who now serves as a Beekeeper in a secret organization that protects the world like bees in a hive, is forced into a campaign of revenge when his neighbor’s finances are wiped out after a phishing scam.

# – # – # – # – # 

The beginning of this movie should be required watching BEFORE anyone gets a personal computer.  

The ‘nice old lady” gets scammed out of everything she has by calling in after a pop up on her computer.  Been there getting pop ups, spam emails, and whatever.

Lesson Number 1 is have yourself some “tech support” relative.  Or at least, don’t trust anyone online.

The lady has a flash of insight to call her bank but gets talked out it when the nice man on the phone says “he’ll lose his job.”

The rest of the movie is mission impossible type hokum but enjoyable to see the “bad guys” get karma visited upon them.

All in all, the part about scammers is very believable and should serve as a warning to all computer Users.

—30—

https://nypost.com/2024/07/07/us-news/scammers-get-away-with-billions-from-elderly-americans-every-year/

—30—


SECURITY: PASSKEYS appears to be NOT the secuirty “silver bullet””

Sunday, April 28, 2024

https://fy.blackhats.net.au/blog/2024-04-26-passkeys-a-shattered-dream/

*** begin quote ***

The Enshittocene Period

Since then Passkeys are now seen as a way to capture users and audiences into a platform. What better way to encourage long term entrapment of users then by locking all their credentials into your platform, and even better, credentials that can’t be extracted or exported in any capacity.

Both Chrome and Safari will try to force you into using either hybrid (caBLE) where you scan a QR code with your phone to authenticate – you have to click through menus to use a security key. caBLE is not even a good experience, taking more than 60 seconds work in most cases. The UI is beyond obnoxious at this point. Sometimes I think the password game has a better ux.

The more egregious offender is Android, which won’t even activate your security key if the website sends the set of options that are needed for Passkeys. This means the IDP gets to choose what device you enroll without your input. And of course, all the developer examples only show you the options to activate “Google Passkeys stored in Google Password Manager”. After all, why would you want to use anything else?

A sobering pair of reads are the Github Passkey Beta and Github Passkey threads. There are instances of users whose security keys are not able to be enrolled as the resident key slots are filled. Multiple users describe that Android can not create Passkeys due to platform bugs. Some devices need firmware resets to create Passkeys. Keys can be saved on the client but not the server leading to duplicate account presence and credentials that don’t work, or worse lead users to delete the real credentials.

The helplessness of users on these threads is obvious – and these are technical early adopters. The users we need to be advocates for changing from passwords to passkeys. If these users can’t make it work how will people from other disciplines fare?

Externally there are other issues. Apple Keychain has personally wiped out all my Passkeys on three separate occasions. There are external reports we have recieved of other users whose Keychain Passkeys have been wiped just like mine.

Now as users we have the expectation that keys won’t be created or they will have disappeared when we need them most.

In order to try to resolve this the workgroup seems to be doubling down on more complex JS apis to try to patch over the issues that they created in the first place. All this extra complexity comes with fragility and more bad experiences, but without resolving the core problems.

It’s a mess.

*** end quote ***

So this ends my interest in “passkeys”.  Too bad.  It had a lot of promise.

Argh!

—30—


SECURITY: PSEG is behind the times

Sunday, November 12, 2023

https://pseg.mypreferencecenter.com/Global/StandardEmailView?subscriberId=0b431ab7-81ba-4b16-a2c5-64639c48d2fb&campaignSendId=85b7bcf6-ed43-40f1-8b1c-874631f58ed8&isTest=False

*** begin quote ***

Lastly, you’ll be required to enter a phone number where you will receive an authentication code.

*** end quote ***

I guess PSEG hasn’t gotten the message that codes via text is NOT secure.

Argh!

And, no where to complain.

BPU? Maybe!

—30—