Showing posts with label Cybersecurity. Show all posts
Showing posts with label Cybersecurity. Show all posts

Saturday, December 10, 2022

What to Know About Lensa AI Selfies

Lensa AI Selfies: What to Know About the Photo-Editing App Everyone's Using

Another filter craze that's all over social media is turning your friends' photos into artwork. It's called Lensa AI, and the viral photo-editing app takes your uploaded photos and creates "magic avatars" using your face. However, the photo editor doesn't come without privacy concerns. We'll explain below. 

https://www.msn.com/en-us/news/technology/lensa-ai-selfies-what-to-know-about-the-photo-editing-app-everyone-s-using/ar-AA152Tf1

Data Privacy Tips from Digital Security Experts

The Data Privacy Tips Digital Security Experts Wish You Knew

Seven pro tips to keep iPhone and Android apps from spilling your data.

https://www.cnet.com/tech/services-and-software/the-data-privacy-tips-digital-security-experts-wish-you-knew/ 

Saturday, December 14, 2019

GOOGLE and FACEBOOK OWN YOU

We never realized how intrusive GOOGLE was until our  GOOGLE TIMELINE popped up per chance.  We knew that the cellphone is constantly sharing one's location.  That's the price one pays to enjoy the features of cell service.  But how about GOOGLE showing where we have been when the phone was off, such as the places in Europe and Asia.

Of course, there is this blogger app.  It is great, easy to use, and we have dozens of blogs for which we do not pay anything.  As frequently told, "If you aren't paying for a service; YOU are the service."  We don't use FACEBOOK for that reason.  Instead we naively and freely give all that information to GOOGLE.

We aren't terrorists or fanatics.  No need to be paranoid, until of course, someone uses all that free information to cause to trouble. We are going to turn off a lot of that give-away.  The details are on our new PRIVACY page.

Sunday, February 17, 2019

Website Breach Info

      "Have I been Pwnd" website came about after what was, at the time, the largest ever single breach of customer accounts — Adobe. The website creator often did post-breach analysis of user credentials and kept finding the same accounts exposed over and over again, often with the same passwords which then put the victims at further risk of their other accounts being compromised.
      His FAQs page goes into a lot more detail, but all the data on this site comes from "breaches" where data is exposed to persons that should not have been able to view it.

Identity Leak Detector

      Everyday personal data is stolen in criminal cyber attacks. A large part of the stolen information is subsequently made public on Internet databases, where it serves as the starting point for other illegal activities.

      With the HPI Identity Leak Checker, it is possible to check whether your email address, along with other personal data (e.g. telephone number, date of birth or address), has been made public on the Internet where it can be misused for malicious purposes.

CONSUMER and CYBERCRIME NEWS

Technology has hidden side effects -- BobSullivan.net reveals them and provides interesting commentary about:

Saturday, March 31, 2018

Another Way FACEBOOK Spies on You

      We're all used to seeing "Log in with Facebook" or "Log in with Google" at sites around the Internet, such as CNN.com, the Guardian newspaper, Spotify, and tens of thousands of other online retailers, apps and games. Facebook gets 62% of all social log-ins across the tens of thousands of sites and Google is used 24% of the time. 
      It should be obvious that every time this is done, one is surrendering personal information to FACEBOOK's or Google's dossier on the user. Logging in to a website using a service such as Facebook or Google allows the website to make a request for data about you -- your birthday, friends list, email address, employment, colleges attended, photos and information that your friends have posted about you.  This data covers your habits and preferences, your Facebook Likes, products or articles you've liked. and which of your friends already use a particular website or what you do while on the site. 
      This can have serious repercussions. Allowing another account who has weak security practices means if this account is hacked, your data may be compromised and you will never know or be notified.
     People who use Facebook and Google log-in trade away some data privacy.
  • Personal data is shared between the social network and the third-party app.
  • Don't link a social profile to sensitive info like your Social Security number or financial details. Always use a separate account and password.

Wednesday, March 28, 2018

The Weakest Security Link on your Computer - the Web Browser

How Criminals Can Build a “Web Dossier” from Your Browser

All kinds of personal information, from your location, work hours, habits, banks, applications, and even passwords are there for the taking. 

Web browsers store an incredible amount of sensitive information about you. Website developers have a variety of ways of using modern browsers to customize the experience for users. Advertisers also use these features to maximize the impact of ads shown on sites. The result is that a lot of information about you is stored deep in your browser, and it can potentially be exploited by cyber criminals in a number of ways. 

This blog will describe what we call the “web dossier” that can be created from these artifacts, how this profile can be exploited, and what you can do to protect yourself.

https://www.exabeam.com/security/criminals-can-build-web-dossier-browser/

What You are Worth on the Dark Web

Dark Web Market Price Index (Feb 2018 - US Edition)

Scammers are buying and selling your stolen personal info on the dark web and it's not just credit card details. With hacked dating profiles, streaming services, even Airbnb accounts for sale, we've created the Dark Web Market Price Index (US Edition) to monitor this illicit trade.

https://www.top10vpn.com/privacy-central/privacy/dark-web-market-price-index-feb-2018-us/

Sunday, March 25, 2018

FACEBOOK Data Treasure Trove

FACEBOOK never forgets.  It retains a remarkable amount of information about anyone who has ever logged in.  With the recent data breach by Cambridge Analytica,
https://arstechnica.com/tech-policy/2018/03/cook-county-illinois-sues-facebook-and-cambridge-analytica-over-data-breach/

users can kiss there personal records goodbye. Now how much does FACEBOOK have? EVERYTHING you or your "friends" have entered.  To find out just how much that might be
1) Open your FACEBOOK page
2) In the upper right hand-corner, click on the small black triangle
3) In the drop-menu select 'Settings"
4) On the page that opens locate Download a copy of your Facebook data.and click on it.

The data are sent to your email account associated with your FACEBOOK account in a very big zip file.
You recently requested a copy of your Facebook data. It's now ready for you to download.
Because this download may contain private information, you should keep it secure and take precautions when storing or sending it, or uploading it to another service.
Click the link below to go directly to your download. If the link redirects you to your account settings page, simply click "Download a copy of your Facebook data" to get redirected to the file we've prepared.
Please note: For security reasons, you can only download the copy we've prepared for you within a few days of this email being sent. You'll need to start the process again if you're unable to access your download.
 

7 Reasons Why Quitting Facebook Now Is Good For Your Future
https://www.lifehack.org/articles/productivity/7-reasons-why-quitting-facebook-now-good-for-your-future.html

What I Learned When I Quit Facebook
https://www.themuse.com/advice/what-i-learned-when-i-quit-facebook 

What to Look for in your Facebook Data—and How to Find It
https://www.wired.com/story/download-facebook-data-how-to-read/?CNDID=48648177&mbid=nl_032918_daily_list1_p3

Tuesday, December 8, 2015

The Dismal Data Security of the Medical Industry

    According to Baseline (12./8/15) the average price tag for the most desirable data includes most valued personal data passwords ($75.80), health records ($59.80), Social Security numbers ($55.70), and payment details ($36.60).  The most impacted industry for identity theft is healthcare at 29.8%.
    Also 90% of hospitals and clinics lose their patients' data at  http://money.cnn.com/2014/08/20/technology/security/hospitals-data/ 
    We reported on this blog about the dismal security practices of the medical industry.
http://mtskeptics.blogspot.com/2014/08/medical-insecurity-worse-for-identity.html
    One month ago we received a plain text e-mail from Blue Cross Blue Shield of Tennessee that listed the Social Security numbers of all our 200 employees.

Most Valuable Data

The average price tag for the most desirable data includes most valued personal data passwords ($75.80), health records ($59.80), Social Security numbers ($55.70) and payment details ($36.60).
- See more at: http://www.baselinemag.com/security/slideshows/data-breaches-myth-vs.-reality.html?utm_medium=email&utm_campaign=BL_NL_BB_20151208_STR1L1&dni=290055298&rni=29507635#sthash.FfZrYgrM.dpuf

Most Valuable Data

The average price tag for the most desirable data includes most valued personal data passwords ($75.80), health records ($59.80), Social Security numbers ($55.70) and payment details ($36.60).
- See more at: http://www.baselinemag.com/security/slideshows/data-breaches-myth-vs.-reality.html?utm_medium=email&utm_campaign=BL_NL_BB_20151208_STR1L1&dni=290055298&rni=29507635#sthash.FfZrYgrM.dpuf

Saturday, November 28, 2015

Is SkyNet Here?

According to "The Week" (11/27/15) 
Google just made an announcement that will send ripples throughout the technology industry for years to come... The company has built a new learning system for machines called TensorFlow"
Lifehacker calls TensorFlow a game changer (original article)
The development of smarter and more pervasive artificial intelli- gence (AI) is about to shift into overdrive with the announcement by Google that TensorFlow, its second-generation machine-learning system, will be made available free to anyone who wants to use it. This has the potential to shape the future of artificial intelligence (AI).
KDnuggets reports that not everyone is impressed, TensorFlow Disappoints – Google Deep Learning falls shallow
Look, Google is at the forefront of technological innovation, there is no denying that...Google is 5+ years ahead of everyone. In everything. All the time.  It's like a new pizzeria opening on the block, except it has pretty much the same menu as other shops, doesn't taste quite as good, and costs a little more, too. You might try it out, but something tells me you and your friends end up back at your favorite spot soon enough. 
I'm not saying don't use TensorFlow. I'm not even saying that I won't use it. It's just that, well, I'm struggling to figure out when or why I would use it, to be honest.

Thursday, April 9, 2015

Tennessee WORST for Data Breaches of Medical Records

It’s believed that Chinese hackers were responsible for the data breach earlier this year of 4.5 million records held by Community Health Systems in Tennessee putting the state in first place, just ahead of California). Five Alabama residents have filed a class action lawsuit as a result of the breach.

Saturday, February 7, 2015

Latest Scam - Identity Theft Insurance

Numerous time we have been asked, "Should I buy about Identity Theft Insurance." My answer is always "No."  It is much like "Extended Warranty."  It does very little to protect the one insured, but it does a lot to fatten the wallet of the "insurance" company.  The Anthem hack again has everyone scrambling for "ID Insurance."  While scanning the various posts about the Anthem hack I found the following very insightful note among the comments.
You suggested buying credit card insurance protection in your linkedin. That doesn't work and merely incur additional cost without real benefits. Like buying extended warranty offered by many retailers for purchased merchandise. Or buy GAP insurance during purchase of a new car. These are unnecessary options designed to add profits to the sellers.
In addition, credit card monitoring is not effective. First, the frauds must occur. The damage is already done. It is not preventive. 2nd, the frauds discovered is too late b/cos the fraudster is long gone and probably used the same info to commit more related frauds not discovered by the victims. Example banking frauds, auto frauds, etc. using the identity theft. 3rd, to detect the frauds, all the info relating to the victims must be correct or accurate and match exactly to the info in the credit card report! That's difficult!!. Example, if the fraudster use a space between the name or alter some info slightly, the frauds are NOT detected by credit monitoring. (I'm in forensic acctg, believe it or not, it's difficult to detect).

The best protection is to be proactive. Check your accts (banking, credit card transactions, credit report, insurance, etc) regularly. Use pre-set alert as tools.
We have been the victim of ID theft on several occasions and confirm these comments. For years I fought with insurance companies with no success trying to get them not to use my employee's SS# as an ID's that they plastered all over their monthly statements and invoices.  Yes, their security practices are horrible.  Likewise the security practices of about every medical office is equally bad.  With the forced computerization of medical offices we can expect more hacks like Anthem.

Sunday, December 21, 2014

Tech Service Scam

We are frequently requested to repair both corporate and private computers that have been infected with malware.  In the last three years the most prevalent problem has been the "Tech Service" Scam.  It is where some alarm appears on a computer that warns that it is infected and to call a certain tech service company with assistant to remove the infection.  Surprisingly, sometimes these warnings arrive by a telephone call from people claiming to be from an ISP or from Microsoft.  The warnings often are so dire that the "pigeon" reacts without thinking.
     The Anti-Malware Company that produces free and subscription Malwarebytes discussed this risk in greater detail in their post Beware of US-based Tech Support Scams found here
https://blog.malwarebytes.org/fraud-scam/2014/08/beware-of-us-based-tech-support-scams/