SECURITY: Don’t reuse the same password at ANY site

Saturday, December 17, 2016

http://www.nytimes.com/2016/12/14/technology/yahoo-hack.html

TECHNOLOGY
Yahoo Says 1 Billion User Accounts Were Hacked
By VINDU GOEL and NICOLE PERLROTHD
EC. 14, 2016

*** begin quote ***

SAN FRANCISCO — Yahoo, already reeling from its September disclosure that 500 million user accounts had been hacked in 2014, disclosed Wednesday that a different attack in 2013 compromised more than 1 billion accounts.

*** end quote ***

There are too many good password utilities that make this unnecessary. 

I have over three hundred sites where I have accounts and no site has the same password.

AND, my passwords are as long as the site allows and with whatever mix of character types they allow.

My financial sites (i.e., the banks and brokerage) have their passwords written down off line.

(Yeah, that a small PIA but I sleep better.)

Ask me if you need information security advice.

Otherwise, you’re just a target waiting for the random hacker or script kiddie.

Argh!

# – # – # – # – # 


SECURITY: TDAMERITRADE delayed reaction

Friday, July 1, 2016

2016-Jul-01

 

Dear Valued Client, 

The security of client information is a top priority for us. As part of routine monitoring, we have learned that client email addresses and passwords from a breach at LinkedIn® were compromised and recently published online. While the breach is not TD Ameritrade-related, we believe that the User ID on your TD Ameritrade Institutional account matches an email address from that breach. 

As a precaution, we have expired the password on your TD Ameritrade Institutional account. We know that many people reuse the same passwords on multiple websites, so it is important that we take this proactive step.* 

You will need to log in to your TD Ameritrade Institutional account to change your password. Please be sure that the new password you create is different from your previous one. 

If you have trouble accessing your account, or if you have any questions, please contact your Advisor or call TD Ameritrade Institutional at 800-431-3500 option 2. 

Sincerely,

John Tovar 
John V. Tovar 
Managing Director, Brokerage Services

 

# – # – # – # – # 

Argh!

So because they have Clients that are boobs, I have to be inconvenienced?

And, I hate to tell them the LinkedIn breech was a LONG time ago.

I guess they had to figure out how to expire all the old passwords OR they just heard about it.

Argh!

# – # – # – # – # 


SECURITY: Tell me that this is for MY benefit

Saturday, May 14, 2016
Dear Ferdinand,

As we move closer to joining together with Starwood®, we want you to continue taking advantage of everything the Marriott Rewards® program has to offer by making sure your account information is current and secure.

It is our ongoing priority to ensure your personal information is protected. For your continued security, we will be implementing enhanced password protections over the next few weeks. 

You are receiving this email because your account password needs to be updated to comply with our revised security measures. We encourage you to log in and follow the steps below as soon as possible to ensure uninterrupted access to your account when the new password requirements take effect.

As a reminder, experts recommend that you periodically change the passwords you use to access websites as a precaution. Changing your Marriott Rewards password is easy. All you will need to do is:

• Log in to your Marriott Rewards account on your desktop or laptop
 
• Select “My Account”
 
• Select “Profile”
 
• Select “Edit” in the Password section
 
• Enter current and new password
 
• Confirm your identity if you are not using a registered device
Log on now to your Marriott Rewards account to take action. Thank you very much for taking the time to update your password information. 

Sincerely,

Argh! I’m SURE that this id for MY benefit.

Argh! Laugh!

# – # – # – # – # 

 


SECURITY: United Airlines resets their security?

Monday, April 25, 2016

*** begin quote ***

To better protect your United MileagePlus® account, we’ll soon no longer allow you to use your PIN to sign in. Instead you’ll need to have security questions and a strong password.
If you haven’t done so already, please sign in to your account today. You’ll be asked to complete these steps:
(1)  
Validate your email address
(2)  
Choose and answer new security questions
(3)  
Update your password
For now, you will still need your PIN when you call the United® Customer Contact Center, so don’t lose track of that just yet.
Thank you for being a MileagePlus member and for taking the time to update your account.

*** end quote ***

I guess that someone has hacked United Airlines.

Didn’t hear about this in the media.

# – # – # – # – # 

 

 


SECURITY: Help wanted — an info sec person for an LA hospital

Tuesday, February 23, 2016

http://www.dailymail.co.uk/news/article-3452178/Los-Angeles-hospital-paid-17-000-ransom-hackers-regain-control-computers.html

Los Angeles hospital paid $17,000 ransom to hackers to regain control of computers

  • Hollywood Presbyterian Medical Center was hacked on February 5
  • The cyber criminals had demanded $3.4million to give them control back But the accepted a lower fee – the cash equivalent of 40 bitcoins 
  • CEO Allen Stefanek said patient care was not affected during the attack 

By WILLS ROBINSON FOR DAILYMAIL.COM and ASSOCIATED PRESSPUBLISHED: 20:17 EST, 17 February 2016 | UPDATED: 22:12 EST, 17 February 2016

# – # – # – # – # 

I guess they need to fire their current CEO, CIO, CTO, CISO, CDRP, and their IT audit leadership.

Some these should be working as clerks in Walmart or McDonalds. If they can make the cut!

Oh BTW where were “the regulators”?

Argh!

# – # – # – # – # 


SECURITY: Apple Tim Cook is wearing “the Emperor’s new clothes” with respect to “privacy”

Saturday, February 20, 2016

http://www.france24.com/en/20160219-usa-apple-plays-digital-privacy-hardball-with-fbi-but-not-china

Business – Apple plays digital privacy hardball with FBI, ‘but not China’ – France 24

*** begin quote *** 

Apple was hailed as a champion of digital privacy this week after refusing to help the FBI hack into an iPhone belonging to a suspect in the San Bernardino shooting. But the firm hasn’t always been so scrupulous about user data, especially in China.

*** end quote ***

FURTHER undermining the Apple argument!

# – # – # – # – # 


SECURITY: Email security STARTS with your own domain name

Thursday, January 7, 2016

http://www.pcmag.com/article2/0,2817,2497611,00.asp

Time Warner Cable Warns Users of Possible Data Breach
BY STEPHANIE MLOT JANUARY 7, 2016 02:24PM EST

# – # – # – # – # 

Here’s a reason NOT to use an ISP for your email address.

Another is that you’re locked into that ISP for email.

Argh!

May I suggest that you have your own domain?

The common wisdom, or is that common whizdumb, is to own your own name as a domain name. I own “reinke.cc”. (I like saying “sea sea me at reinke.cc”! me@reinke.cc will actually work!) I gives one quite a bit of control.

And, it’s very cheap. I know three solutions at 15$/year using wordpressdotcom with gmail, 25$/year email only with 1and1, and 60$/year for domain+email+webspace also at 1and1.

My point is not that you should use 1and1. http://www.1and1.com/?k_id=9113251 I could care less which one you use. It’s that getting on to your own domain with email is cheap and easy.

And, it’s not hotmail, yahoo, AOL, or gmail. It IS your own “personal brand”.

# – # – # – # – # 


SECURITY: Multiple questions are secondary passwords

Wednesday, January 6, 2016

Argh!

Why do I get frustrated when people insist on being insecure?

# – # – # – # – # 

To our eService Customers:
 
On December 21, 2015, Washington Gas launched its new eService portal in an effort to improve the overall online customer experience. We have expanded the online self-service options, provided you with energy consumption information and month-to-month usage comparisons, as well access to billing and payment options, such as our Budget Billing and Auto-Pay programs. 
 
Since the launch, we have experienced some technical issues, particularly related to log on and password reset. During log on, please be aware  that you may encounter delays as you are: 1) directed to the page where you are required to change your password; and 2) answer three brief security questions, both of which conform to sound security practices. We apologize for any delays you may experience during this process.
 
During the next few weeks, we will remain focused on identifying, addressing and resolving deficiencies in the new system. By the time you receive your next bill and log onto our system, we expect that your online experience on our new site will have improved significantly as we approach the level of service you expect and deserve.
 
Until we resolve all issues, please consider using your mobile device to access the eService site. Customers accessing the site in this way are experiencing faster site performance.
 
As a reminder, the following payment options are still available to you:
 

  • Call our automated payment line at 703-750-7944 to make a phone payment with a check or credit card. 
  • Contact our customer service center at 703-750-1000 for assistance with a payment. Customer service hours are 8 AM to 9 PM on weekdays and 8 AM to 4:30 PM on Saturday. The center is closed on Sundays.

 
There are no transaction fees for payments made through these two alternative methods. Late fees will be waived for eService customer payments delayed by the implementation of the new portal.
 
Thank you for your patience and for being a valued Washington Gas customer. Again, we apologize for the inconvenience these technical issues may cause. Our continued goal is to provide the best possible online experience and we will continue to provide updates and share information on the www.washgas.comhome page in the coming weeks.
 
Tanya Hudson
Division Head, Consumer Services

# – # – # – # – # 


SECURITY: How to spot a fake email?

Wednesday, November 25, 2015

http://www.foxnews.com/tech/2015/11/22/tech-q-spy-apps-fake-email-and-bluetooth-speakers.html?intcmp=hpff

How to spot a fake email?

*** begin quote ***

Q. I got an email from Amazon that was a security alert about my account. How can you tell if it’s legit or not?

A. The fake email is a favorite of scammers trying to steal your information. Major companies don’t send out emails that haven’t been checked by a team of professional writers and editors, so poor writing is a dead giveaway. They also won’t ask you to click on anything or download an attachment.

*** end quote ***

I have a better way. GET YOUR OWN DOMAIN!

May I suggest that you have your own domain? The common wisdom, or is that common whizdumb, is to own your own name as a domain name. I gives one quite a bit of control. And, it’s very cheap. I know three solutions at 15$/year using wordpressdotcom with gmail, 25$/year email only with 1and1, and 60$/year for domain+email+webspace also at 1and1. My point is not that you should use 1and1. http://www.1and1.com/?k_id=9113251 I could care less which one you use. It’s that getting on to your own domain with email is cheap and easy. And, it’s not hotmail, yahoo, or gmail. It IS your own “personal brand”.

https://reinkefaceslife.com/2010/02/27/service-your-isp-email-address-is-a-trap/

And you don’t want your ISP, like comcast, twc, or aol, to lock you into their service.

https://reinkefaceslife.com/2007/07/14/productivity-changing-email-addresses/ 

And you don’t want the hassle of changing your email and risk “losing” people.

Use my trick of assigning specific emails to your correspondents. For example, XRAY0001 at my domain is American Express. If I EVER get an email from Amex that doesn’t come in on that address, I know it’s a fraud and I delete it right away. Easy peasy!

Simple!

For cheap protection. Do it now. Lest a Nigerian Prince catch you “asleep at the switch”.

# – # – # – # – # 

 


SECURITY: Why not require photo id?

Monday, May 11, 2015

http://www.unionleader.com/article/20150506/NEWS03/150509580&source=RSS

Woman advocates vigilance after thieves took wallet and spent $20,507 in 2 hours
By CASSIDY SWANSON
Union Leader Correspondent

*** begin quote ***

BEDFORD — After having her wallet stolen out of her shopping cart at the Bedford Mall and more than $20,000 charged to her credit cards, a Manchester woman is cautioning women and seniors to be more vigilant about their belongings while out shopping.

*** and ***

“Why isn’t it mandatory to ask for an ID? You know, we’re talking 15 seconds here,” she said.

*** and ***

Fellbaum said at Best Buy, the thieves tried to use Fellbaum’s Chase Visa card for the two transactions. It was declined, so the store allowed them to use her Bank of America card.

The thieves also paid in two transactions at the Apple Store.

The Bank of America card was denied at the Apple Store, and that store allowed the thieves to use Fellbaum’s Citizens Bank card. On the second transaction, the thieves used her Sam’s Club MasterCard.

At Finish Line, Fellbaum’s Bank of America card was declined, but the store allowed the thieves to use her Citizens MasterCard.

“Nobody asked for ID,” she said. Fellbaum also said she was told by a manager at Best Buy that credit card companies prohibit the store from asking customers for identification when paying with a card.

“I don’t believe that’s true,” she said.

*** end quote ***

It would seem that this type of crime would immediately be reduce by requiring photo id.

Need it to get on a plane.

So why not to vote or to charge?

And, I’m sorry, after a decline, why not take some extra precautions.

Multiple declines?

Argh!

“Photo id required” goes on all my cards!

# – # – # – # – #