SECURITY: Email is NOT secure; password resets by email is just stupid!

Wednesday, May 3, 2023

https://www.ghacks.net/2023/04/28/protect-your-money-att-email-accounts-under-attack-by-hackers/

Protect your money: AT&T email accounts under attack by hackers
Onur Demirkol
Apr 28, 2023

*** begin quote ***

A recent report says that hackers have been breaking into email addresses provided by AT&T and stealing huge amounts of cryptocurrency.

According to a report from Tech Crunch, unknown hackers have been hacking email addresses provided by AT&T to steal cryptocurrency from users. The report says that the attacks started at the beginning of April by a gang of cybercriminals. They found a way to hack into email addresses and steal people’s money on crypto.

The hackers have gained access to a section of AT&T’s internal network, allowing them to generate mail keys for any user. Mail keys are used by AT&T users to log into their accounts with third-party apps like Outlook without using their passwords. In other words, they are a kind of “secure measure” that allows log-ins from third-party apps.

*** and ***

If you own an email account provided by AT&T, you might want to improve your security measures or the different precautions. The affected email addresses include att.net, sbcglobal.net, bellsouth.net, and other AT&T email addresses.

*** end quote ***

As a former Wall Street InfoSec guy, I never allowed my enterprises passwords to be reset by email.

Guess I was a little ahead of my time and a lot of good it did me.

Argh!

—30—


SECURITY: Passkeys don’t solve every security problem

Tuesday, March 21, 2023

https://www.reviewgeek.com/148254/why-you-should-start-using-passkeys/

Why You Should Start Using Passkeys
Danny Chadwick
Mar 16, 2023, 2:55 pm EDT | 5 min read

*** begin quote ***

Passwords have been our first line of defense against hackers since the 1960s. But, now they’re showing their age and limitations in the 21st-century data wars. Not even password managers are safe. Passkeys are now here to help. Here’s why you should switch and enjoy a more secure digital future.

*** end quote ***

Passkeys solve the “password” problem for only one use case.

Use cases are programmer speak for how the application interacts with the User.

If you’re the average plain vanilla User, then they are fine. 

But, if you access the application from different hardware, then you can’t use a passkey.  

Apple shares the passkeys in its walled garden, so that is another use case addressed.

I’m not sure how Google / Android addresses the use case of a different platform usage.

Having password managers storing the passkey may solve the problem but defeat the concept.

IMHO

—30—


SECURITY: PARKMOBIL has been cracked

Sunday, March 12, 2023

ATTENTION: ParkMobile

I use dedicated email addresses from my own domain. Yours is “parkmobile@reinke.cc”. I just received a spam message addressed to my unique email address for you. That means it was sent after someone got your data. Please investigate the hack.

# – # – # – # – # 

Anyone bet that no one responds?  And probably no one, other than me, cares.

This demonstrates the value of your own domain and using unique emails.

—30—


SECURITY: And why should I trust “PLAID”?

Thursday, November 24, 2022

BY EMAIL FROM COINBASE

*** begin quote ***

Hi Ferdinand J,

As part of our continued effort to ensure the safety and security of our customers, we’re updating the payment method linking system for all banks that support instant verification system (Plaid). Any customer bank accounts that support Plaid will no longer be allowed to use the older, test deposit method.

For those customers whose bank accounts have already been unlinked from their Coinbase account, we understand this may have caused some confusion. Your bank account will need to be relinked using our instant verification system to ensure your payment method utilizes the safest, most reliable service.

If your current bank account is supported by Plaid, but your bank was originally linked via test deposit, please be aware that your account may be unlinked in the near future to support instant verification.

For relinking a Plaid supported bank account, you can verify your account by entering your online banking credentials with the instant verification process – you may either complete this during a Buy or Deposit, or by navigating to your Settings > Payment Methods in your Coinbase account.

For more information on payment methods, please see our help center article here.

Your banking credentials are never sent to Coinbase, and are shared with an integrated, encrypted, trusted third-party called Plaid Technologies Inc. More info about how your bank account information is secured can be found here.

The Coinbase Team

*** end quote ***

And why should I trust “PLAID”?

—30—


SECURITY: BBC reporter creates fake Americans.

Thursday, November 10, 2022

https://apnews.com/article/us-elections-misinformation-social-media-BBC-americast-6749e362c3b3a5c8db7b3276a8a5bd91?utm_source=join1440&utm_medium=email

BBC tries to understand politics by creating fake Americans
By DAVID BAUDER — November 1, 2022

*** begin quote ***

NEW YORK (AP) — Larry, a 71-year-old retired insurance broker and Donald Trump fan from Alabama, wouldn’t be likely to run into the liberal Emma, a 25-year-old graphic designer from New York City, on social media — even if they were both real.

Each is a figment of BBC reporter Marianna Spring’s imagination. She created five fake Americans and opened social media accounts for them, part of an attempt to illustrate how disinformation spreads on sites like Facebook, Twitter and TikTok despite efforts to stop it, and how that impacts American politics.

That’s also left Spring and the BBC vulnerable to charges that the project is ethically suspect in using false information to uncover false information.

“We’re doing it with very good intentions because it’s important to understand what is going on,” Spring said. In the world of disinformation, “the U.S. is the key battleground,” she said.

*** end quote ***

This is easily prevented by requiring a credit card and charging for access.  Elon’s 8$/month will do more to eliminate, or down grade bots, than can be imagined.

The fee would eliminate fakes PDQ.  Surprising that no one mentions it in the article.

Of course, there’s no way to comment on the site, because they are just interested in attracting eyeballs.

—30—


SECURITY: CVS site won’t work with a VPN; so much for medical privacy

Wednesday, March 2, 2022

Thank you for contacting CVS.com.

We are writing in regard to the issue you are experiencing with not being able to login into CVS.com and have received a response from our IT department. 

At this time we advise not using a VPN (Virtual Private Network) when also trying to access the CVS.com website as this can cause issues with connectivity.
If you have further questions or require additional assistance, please contact us by email at customercare@cvs.com or by phone at (888) 607-4287. Reference number ******

As always, thank you for choosing CVS.com.

Sincerely,

 

Derek

BICDAW

Customer Care Department

# – # – # – # – #

Sigh, YET ANOTHER clueless IT organization!

(Maybe I should send in my resume?)

—30—


SECURITY: Gooferment can be “trusted” to misuse “passports”

Wednesday, February 2, 2022

https://articles.mercola.com/sites/articles/archive/2022/02/27/nick-corbishley-vaccine-passport.aspx

What You Need to Know About Vax Passports, Digital IDs, CBDCs
Analysis by Dr. Joseph Mercola — February 27, 2022

*** begin quote ***

“The passports essentially function as a gateway to allow government to herd us into a totally new reality where our actions, our movements, our thoughts, our behavior are tracked and surveilled,” Corbishley says.

*** end quote ***

There is no reason to permit Gooferment, any level of Gooferment, to treat us like their cattle.

When will “We, The Sheeple” object?  When they are loading up the trains!

—30—


SECURITY: SMS should NOT be used for 2FA

Monday, October 18, 2021

*** begin quote ***

“The company that routes SMS for all major US carriers was hacked for five years. It isn’t revealing whether or not messages were exposed, but it’s just another reason not to use SMS for 2FA.”

*** end quote ***

So for the average layman, it means that if any service provider texts codes to your phone as a way of security your account, they are at risk of a security breach.

I’ve begin communicating with the providers I use putting them on notice that (1) they are using a insecure technology to secure my account; and (2) when do they plan to switch to a phone based authentication technology or something better.

Now, if they say they use GOOGLE or APPLE authenticator, you can point out that those too are insecure by design.  Since a hack of either high profile target, will make you vulnerable.

Using the “home grown” authenticator, (something written by the service provider like IDME), doesn’t have the transparency of the source code to assure security.

Any “home grown” authenticator, Google, orApple authenticators does NOT separate the necessary sufficient controls for good Information Security.

Suggest you tell them support AUTHY or other third party authenticators.  This is more secure because the “key” is only held by them and by you locally on your phone.

Or if they really want to protect you, they can give you are hardware token like YUBIKEY or a hardware authenticator like SECURE_ID.

—30—


SECURITY: Is all secure in the Apple ecosystem

Friday, May 28, 2021

Someone hit my Apple Card for 150 $ in music so I had to change its number.

No one has access to my phone. And I mean no one!

So the implication is that they have an info sec problem.

—30—


SECURITY: Use an authenticator app; not a phone call

Wednesday, November 25, 2020

https://www.lifewire.com/why-phone-based-authentication-can-be-insecure-5087935

Why Phone-Based Authentication Can Be Insecure
Cyber criminal’s delight?
by Sascha Brodsky
Published November 17, 2020

*** begin quote ***

Key Takeaways

Hackers can steal phone-based multi-factor authentication (MFA) codes, experts say.
Phone companies have been tricked into transferring phone numbers to allow criminals to get the codes.
A simple, low-cost way to increase security is to use the authenticator app on your phone.

*** end quote ***

I don’t understand why corporate CSOs don’t insist on authenticator apps versus some lame alternative.

And, if you don’t want to “mandate” it to Customers, then their services should support it.

Argh!

—30—