http://trace5.com/fb/fb/0F365CE6ECE11D44AA96CC4B1441D016ECD54962070B0526C755486C0D97C488/show.aspx

The answer: “Not much”.
That’s what’s wrong with a “put everything in the cloud” architecture.
# # # # #
http://trace5.com/fb/fb/0F365CE6ECE11D44AA96CC4B1441D016ECD54962070B0526C755486C0D97C488/show.aspx

The answer: “Not much”.
That’s what’s wrong with a “put everything in the cloud” architecture.
# # # # #
Greetings from XXXXX – Alive and Well in Singapore
Posted by: “XXXXX”
Sat Apr 9, 2011 12:01 am (PDT)
HI Guys, Saturday, April 9th, 2011.
Greetings from Singapore.
I understand that on March 22nd an “Emergency Help!!!” SCAM e-mail was sent in my name to the Manhattan Prep 1964 Yahoo Group.
My apologies if it created any alarm.
However, I am sure that any Prepster who received this e-mail would have realized that the exaggerated emotional tone and piss poor grammar gave it away as a scam…
Here is the background on the scam…
On the evening of March 22nd, someone hacked into my Yahoo/Prodigy Account, hijacked my address book, which contained about 1,400 addresses and then proceeded to send out an “Emergency Help” E-mail asking for money. The hacker even changed my password and set up a forwarding address edward1.coll@yahoo.com to which all my incoming e-mails went so he could try and continue to perpetrate this scam.
Within a few minutes of the scam e-mail being sent, I started receiving phone calls and e-mails from all over the world from people on my contact list enquiring if I was O.K. and whether they should send money to me via a Western Union Office in London .
I told them that this was a big SCAM and to just ignore the e-mail and not even reply as the hacker had arranged to have all the replies forwarded to him. What an operator !!!
It was really frustrating as this hacker also changed my password so I could not initially access my account to see what was going on
I was finally able to get in touch with Yahoo’s Customer Service Department and spent about two hours on the phone with them to get my password reset so I could access the account and cancel out all the forwarding addresses that the hacker had set up.
The worst thing was that he erased my Yahoo Address book and the 1,400 names it contained. Fortunately, I had backed up the address book so I was able to re-import the contacts to my yahoo account.
I hope this matter is settled now. and that no one was duped into sending this hacker any money.
My e-mail address, {Privacy Invoked} should be secure now.
Best regards,
# – # – #
I’m glad you’re OK. It’s not that we have any fellow alum to spare.
On a technical note, were you able to determine, how the hack was accomplished? I’m interested from an InfoSec pov. The default assumption was that someone kept “knocking on the door” with passwords until it opened. It’s not hard to imagine a bot (software robot) doing that. But, it’s also possible that it was malware on your computer or malware on a site you visited with an old browser.
Interesting?
May I suggest that you, or anyone, have your own domain? The common wisdom, or is that common whizdumb, is to own your own name as a domain name. I own “reinke.cc”. (I like saying “sea sea me at reinke.cc”! me@reinke.cc will actually work!)
I can send you some links to stuff that I’ve posted on my blog “Reinke Faces Life” about how to “do” email to avoid such unpleasantries. It’s neither hard not expensive.
Unfortunately, having a yahoo, gmail, or hotmail account makes you are target for the black hats. Eventually they find everyone who has one of those “free accounts”.
At the very least, one can hide by using a very long random string password. I use twenty characters. Of course, I use tools like roboform, last pass, and even the infamous yellow stickie to remember them.
But I doubt anyone has as many unique ids and passwords as I do. I’m a little nuts about it.
I’m now off to change my Yahoo password to something longer. I’m sure someone is listening.
:-)
# – # – # – # – #
http://www.schneier.com/blog/archives/2011/04/epsilon_hack.html
Schneier on Security
A blog covering security and security technology.
April 5, 2011
Epsilon Hack
*** begin quote ***
I have no idea why the Epsilon hack is getting so much press.
Yes, millions of names and e-mail addresses might have been stolen. Yes, other customer information might have been stolen, too. Yes, this personal information could be used to create more personalized and better targeted phishing attacks.
*** end quote ***
You should shift to your own domain. Sorry, but yahoo, gmail, and hotmail make you a sitting duck for this hack.Your own domain just moves you out of the target zone.
Alpha spammers just keep trying every id from AA@yahoo.com to ZZZZZZZZZ@hotmail.com and then they turn around and repeat.
So you get “MYDOMAIN.COM”. (You can even push all the email to GMAIL for free.)
Then you create a spreadsheet or use a tool like LASTPASS, ROBOFORM, or such.
Now you assign email addresses to your correspondents. And, add a magic random string to the name, like, k7sa yk2k3 ggfn a2zq
Best Buy ==> BestBuy_k7sa @ MYDOMAIN.COM
Target ===> Target_yk2k3 @ MYDOMAIN.COM
Verizon ===> Verizon_ggfn @ MYDOMAIN.COM
Walgreens ==> Walgreens_a2zq @ MYDOMAIN.COM
You can then write email filters that will quarantine emails that arrive without the proper address.
If Best Buy messages come without the “k7sa”, you know that it’s not the address that you gave them.
If non-Best Buy messages come in with the “k7sa”, you know that it’s a compromised email address.
Go change your address at Best Buy and write a filter to trash any “k7sa” email.
It’s just like having unique passwords for all accounts.
# # # # #
A good reason to use unique email addresses for each of your “special” correspondents. Just like passwords, unique. A little bit of trouble to administrate, but it certainly isolates the trouble. And, it’s trivial to do when you have your own domain. You can even subcontract the email to GMAIL if you want by repointing a few records. It also automagicaly detects financial spam, when a message purporting to be from “your bank” arrives on the “wrong email” account. Wish I could teach this technique to more people. We could have email “security” even if the ISPs don’t want to do IPv6 or email providers, like Yahoo, won’t authenticate when email arrives from outside labeled as if originated from Yahoo itself. (I even tried to sell them a consulting engagement but they said “it wasn’t their problem”. With an attitude like that, no wonder we have problems.)
# – # – #
|
# – # – #
|
# – # – #
|
|||||
|
|||||
|
|
|||||
|
|||||
| ©2011 Verizon. All Rights Reserved. Privacy Policy Verizon Online – PO Box 33056 / St Petersburg, FL 33733 |
# # # # #
I knew it, I knew it. “Cloud Services” are subject to network and hosting issues.
AMAZON CLOUDPLAYER just had a “brain fart”. For at least three minutes.
For me listening to music sadly, who cares. For folks betting their ranch on a cloud strategy, they better care.
It’s back now. Let the finger pointing begin.
# – # – # – # – # 2011-Mar-30 @ 10:59

Seems like Amazon has scooped Google and Apple. It appears to work.
Just as you should buy your ebooks for Kindle, seems like you music should be from Amazon. (The buying process is clunky! imho)
# – # – # – # – # 2011-Mar-29 @ 19:31
Ahh, yes, a plaxo competitor, but not as obnoxious, is going down.
First they stopped performing the service in January. Then, they told folks at the end of March.
It was a useful service (i.e., update your email once and it told every one who had your card). It was originally tied to the business card scanner. No word if they are going to stop selling those. (Who uses business cards today?) I doubt it.
Sigh, an idea who’s time has past.
BTW, their product still had the same fatal flaw it’s always had: YOUR data was locked in their database with no way to extract it.
I blogged that they needed to be open. Interact with Google contacts. Instead of keeping their own database, use people’s GMAIL contacts as their database. Require some innovative business and technical thinking, sure.
Go to Google and offer to make GMAIL’s contacts “social”.
I think their problem was in their thinking — memes and paradigms again — they thought they were selling business card scanners. What they should have been thinking was “we enable communication”.
They could have been LinkedIn, ACT / Salesforce, or something else.
Their thinking did them in.
RIP CARDSCAN. “Ya coulda been a contender”
# – # – #
This message contains graphics. If you do not see the graphics, click here to view.
| To ensure you receive e-mails from DYMO, please add email@dymo.messages4.com to your address book. Wrong language? Please complete your profile to receive future emails in the language of your choice. |
![]() |
DYMO.com | Support | Forward to a Friend |
|
|
Dear At Your Service user, We are contacting you because, after careful consideration, DYMO CardScan has decided to discontinue our At Your Service program effective Dec 31, 2011. Due to the cost of the hardware and network bandwidth up keep, a business decision was made to discontinue the no cost CardScan At Your Service online database program. The first step in this process was to stop sending out the update service email notifications which just happened at the end of January 2011. We apologize for the inconvenience but users of AYS can continue to use it to back up their contacts, as well as to access their contacts remotely over the web, until the service is completely shut down at the end of this year. Just as a reminder, our End User License Agreement specifically states that services provided in addition to the CardScan software application can be modified or discontinued at any time. Sincerely, The DYMO team |
|
# # # # #
EMAIL TO A VENDOR EMAIL CAMPAIGN SOFTWARE
I’m interested in offering my 100 chapter book by email.
I want to set up a sequence of 100 emails that will form up what I would call a “campaign”. When I get a victim, I want to put in that email address and forget it. I want the software to every day fire out the appropriate day’s email.
At any given point in time, I could (hopefully) have lots of them at different points in the process.
Every time I have spent time investigating a software product or web offering, I eventually found out it couldn’t. Sometimes I was told it could, installed the software and tried a test. Fail.
Hence the email message before I waste everyone’s time.
If yours doesn’t, do you know something that does?
Thanks,
fjohn
AND THEIR PROMPT RESPONSE
Hello fjohn,
Mailings can not send out a schedule of separate emails, but it can send out one specific message at a specific scheduled time, and then repeat that using a specified time interval:
I am not aware of other products that do exactly what you want.
Ciao
Joe
# – # – #
How expensive is an Indian Programming Project?
Do it myself? Argh, that sounds like work.
# # # # #
It’s not just you! http://kodakgallery.com looks down from here.
# – # – #
Argh!
# – # – # – # – # 2011-Mar-20 @ 23:09
*** begin quote ***
Hi – thanks for sending me a message. I am using Boxbe to manage my email inbox. Once you’re on my Guest List, your email to me will be delivered with priority.
*** end quote ***
BOXBE doesn’t present the challenge for me to “solve”.
So there is no way for my message to get thru.
Anyone ever test these things?
And, when you use spam filters, what are you missing?
Argh!
BOXBE, and all spam filters as a general rule, NOTRECOMMENDED!
I “wash” email though gmail for a spam filter.
Argh!
Sorry, but the ISPs could stop this in a heartbeat if they wanted to spend the effort of implementing email authentication.
# # # # # posted 2011-03-08 07:53
You must be logged in to post a comment.