Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Monday, 22 December 2014

Phishing: Message Options

Many people are investing lots of time and energy in pretending to be who they're not through e-mail: looking for Internet users who will give them sign-on details, account numbers, PINs and so on that they can use to strip bank accounts or run up unpayable credit card debts. 

No single method will protect - in the end, you have to be suspicious of any request for personal details or even opinions.  How many of us have answered a phone call that was apparently a survey and ended up being asked for details that could open us up to further unwanted phone calls or given details about our address, postcode or buying habits? 

If you use a Windows computer, you may also have Microsoft Office.  This is a fantastic tool for organising your e-mail, but the latest version has made it harder to look closely at incoming messages before you actually open them.  The trick is to look at the Message Options and see if the addresses in the mail headers actually look anything like the apparent sender. 

In Outlook 2003 and later versions, it used to be possible to right-click on a message in the Inbox and look at the headers directly.  The latest version, Outlook 2013 (also part of Office 365) doesn't allow this unless you first do a little customisation.  Here's how to do it.

I haven't yet found a way to restore the right-click function but you can still use it if you customise the Quick Access Toolbar of Outlook 2013.  That's the very top of the window, where the Outlook application icon, the Send/Receive All button and the Undo button can be found.  It looks like this:






Right-click on the ribbon (that's the feature with the tab names and icons just below the Quick Access Toolbar).  You'll be offered the option to customise the Quick Access Toolbar.  Set the top drop-down box to Commands Not in the Ribbon.  It looks like this:

Select Message Options and then click Add, and move it up one place using the buttons on the far right.  When you click OK, the Quick Access Toolbar should look like this:






When you receive a message that looks suspicious - as examples, a bill you weren't expecting, a receipt for a charity donation, a request to confirm your details, a notification of a failed payment, in your Inbox, select but don't open the message.  Then click on the fourth icon from the left at the top of the window (Message Options).   If when you scroll down, you see evidence of spoofing of addresses, just delete the message - don't open it, and certainly not its attachments.  Here's an example of a spoof e-mail with some of the tell-tale signs:


This was supposed to be from NatWest Bank.  Why would it send an e-mail from a belgacom.be address, relayed through skynet.be?  And then why would its From address be nto.com.  Who?

Use this tip and your own intelligence to cut down your risk of being hacked by evil people. 

Wednesday, 14 May 2014

Credit card security blown wide open on postal transactions



(Originally made this post on Ecademy.com, now Sunzu.com, on 11 Dec 2007)

I'm becoming increasingly worried by suppliers that ask for your debit or credit card security number in writing, along with the card number and expiry date, for postal transactions. This blows the security system wide open. Anyone that intercepts your instructions, either before or after your legitimate payment is made, has everything needed to rip off suppliers (and you).

Why are suppliers doing this? Simply, it's because their banks are demanding these details for Customer Not Present transactions that are entered through merchant machines such as the PDQ.
When you enter card details onto a secure supplier website or a proper payment service such as PayPal, the possible number of fraudsters is quite limited, and collusion or fraudulent action by the owner of the site is a strong suspicion if anything goes wrong. The chain is pretty clear. But just like a pair of CD-ROMs, if a piece of paper goes astray, it could be in anyone's hands, it can be photocopied and sent anywhere in the world, and huge amounts of damage can be done.

Signature as confirmation of identity should be enough for 'cold' transactions where no goods are shipped within 24 hours. When a PDQ machine is used, the bank now seems to require the security number. Specific cases in the last two weeks: NatWest demanded this from a charity for a donation that I wanted to make by card (I sent a cheque instead, along with my Gift Aid form) and a UK passport application where the payment must accompany the application form (I used the Check and Send service at a Post Office which allowed me to make the payment electronically).

This is really dangerous stuff. Barclaycard told me definitely not to send the card security number in writing along with other card details, but I wouldn't be surprised if their merchant people are following the same protocol as NatWest and the Home Office. Is this a general problem? I'd like to gather evidence and to hear of any other cases where this practice has been introduced. And then make some noise in the right places.


Comments received on Sunzu.com:

John, I agree with you and I will not write down a security number. I also agree with S - suppliers keeping written records of credit card numbers also provides a security loophole for dishonest employees and theft from suppliers premises. What's the point of shredding all your documents at home if suppliers have such details in their filing cabinets ! My advice (which I will now take myself in future) is not to write down my credit / debit card numbers on any paper form. Regards, G (UK)


John, I totally agree, you should never give out all these details in writing. The point of the security code, well is.... security. The best practice on this is never to have the card details in writing..... as soon as there is a record, there is a risk towards the data protection rules. As e-retailers, we make 3 important points: 1- all online purchases are managed through secure services so we never have access to the customer's card details 2- for transactions over the phone, we always carry out the transaction live and do not take notes of the card numbers. Once the transaction is finished we (and any other mischievous party) have no way of retrieving the card details. this is quite an effective way of preventing credit card fraud. 3- we never ask for card details in writing I now demand the same type of security from my suppliers, so no employee could take note of the card number in passing. Many organisations do not realise their responsibilities in that area... how many are ensured against employee dishonesty???  S (France)


Agreed

It always makes me think about it on line, I am not sure that is good practice even with the security that wraps around it. K (UK)


I agree with you John, I think there is very little personal safety as regards our financial details. I hate to think how many companies have our details of cards, dob, NI numbers etc. You are right - so much damage can be done in a short space of time. When the CD's went missing I think it gave everyone a shake up. And yet will any of these things stop? I think not. I recently watched a movie. It was called 'The Lives of Others' . It was in German with subtitles. It was set in East Germany just before the wall came down. It really exposed just how thorough the Stasi were in gathering information on everyone. It was a society where people had no freedom, no secrets, no comeback.Nowhere to go to talk about injustice. Anyone who spoke out or argued against the State were imprisoned or worse. Is this what is happening over here. One has to ask - 'What exactly is going on'? L (UK)

Friday, 28 October 2011

Solution for the Global Tech scam?

Getting really fed up with the interruptions to my working day caused by calls from the Microsoft Windows Global Tech scammers. They phone up and try to convince you that your computer is infected (by getting you to look at the Event Log, which they reckon will scare you).

They ignore Telephone Preference Service registrations.  They claim to be operating from Baker Street in London but the phone calls sound as though they're coming from a very long way away.  A legitimate company working in the UK would not be making unsolicited sales calls to a TPS registered line.  The scammers don't take any notice of polite requests to desist from making these nuisance calls.

They offer to help by taking control of your computer, in return for a credit card charge.

Since we can't send a jolt of current back up the line to them, another solution is needed. It seems to me that the credit card companies are the critical link and by accepting payments for the scammers, they are facilitating the scam.  If people who've been caught out then report the scam to their credit card company, we may see some progress (and fewer annoying calls).

There's more useful information about other peoples' experiences on the Conflict International site (the blog is closed for comments).

You can register your phones with the Telephone Preference Service free of charge at http://www.tpsonline.org.uk/ - don't be misled by others who offer you a paid service that purports to do the same thing.

Wednesday, 30 March 2011

No to 'Outbound telesales'

At home, we seem to suffering a new spate of unsolicited sales calls - spam telephony, if you like (or don't). Even though both of the numbers are registered with the Telephone Preference Service (http://www.tpsonline.org.uk), the companies that are doing this just don't care. They're calling on what are clearly long distance circuits, with pre-dialling (sometimes several seconds delay after you answer before a human voice comes on the phone), and connect you to someone with a distinctly non-British accent, who doesn't know who they're really trying to contact.

This can be dangerous. Even when the caller identifies the name of the company she or he represents, there's no way to know whether or not this is for real. Someone called me today, she said, on behalf of a company whose services I've used for years. But she got the number of years wrong, and that says to me that she was doing the telephone equivalent of phishing.

I don't want to give any details to an unknown caller to enable them to offer me 'advice'. Nor do I do want to invite a high-pressure salesman into my home just because they happen to have 'someone in the area' next week; what area, planet Earth?

Telephone companies are bothersome at best when they phone to try and sell something. When they ask you at the end of a 20 minute call, "by the way, the contract is for 18 months, is that all right?", that doesn't feel like trustworthy practice. When you say, "I'd like to see the offer in writing", and they say it's only available today over the phone, is that a strong reason buy anyway? And if they send the key details, and they're in grey 4-point on the back of the brochure, is someone trying to hide something?

Frankly, I can find the products I want using Google, a newspaper, or even a flyer through the post. And then visit the website or make the call to Inbound Telesales, knowing who I'm calling, to do the deal. That's exactly what I did regarding buildings and contents insurance recently. Outbound Telesales is only for things you don't really want. Be brave - don't tick the box allowing them to contact you.

Thursday, 16 April 2009

Goodbye Norton 360


I've used Norton Antivirus and related products exclusively for the PCs that I control for the last 10 years. Laptops arrived with Norton products pre-installed, and these did the job adequately.

Norton 360 was included with the Toshiba Tecra (Vista) laptop that I bought about 15 months ago. Though I didn't like it very much, I renewed the subscription before the 90 days' trial was complete. Now that 12 months' renewal has expired and guess what! All protection seems to have stopped - the product doesn't carry on checking for viruses, firewall, intrusion protection, e-mail scanning, virus and spyware scan. The whole lot seems to have been switched off (if I understand the messages correctly) now that the date has been reached. Other Norton products carry on protecting with the versions of the virus signatures up to the date of the renewal. This doesn't; it's abdicated completely.

Goodbye Norton 360. I won't accept such a business policy. It's AVG for me.

Friday, 22 June 2007

Unsolicited calls

Two unsolicited calls today on my home phone, which is registered with the Telephone Preference Service (TPS). One caller identifies himself as working for 'various financial companies', the other for 'different financial companies'. They pronounce the 'various' and the 'different' very indistinctly to try and cover up the fact that they haven't introduced themselves properly. They want to make an offer regarding mortgage interest rates. Both are using a very low quality connection and refuse to state who they represent. They won't say who asked or told them to call me.

A UK regulated financial services company should not be making unsolicited outbound calls. It knows that this carries penalties, and increasingly will ask customers to sign up to receive a regular call from an adviser or an account manager. Product design may include a provision for calls from time to time. So a company may sometimes make a mistake, but it will try hard to avoid repeating it. If you don't want to be bothered, just tell them clearly that you don't want to hear from them again.

An unregulated company based abroad has few constraints apart from penalties that may arise if any misuse of the telephone system is proven. The best thing to do is to tell these people to get lost - and don't call again.

TPS advice is as follows

Companies based abroad who call into the UK and who are making calls on behalf of a UK based company, must comply with UK regulations and screen their call lists against TPS before making an unsolicited sales and marketing call to a UK telephone number. We do make the file available to overseas based companies under licence for the purpose of suppression so they know whom not to telephone but many overseas companies who telephone the UK on their own account from overseas do so to avoid legal and self regulatory restrictions. We would advise caution in responding to unsolicited sales and marketing telephone calls from overseas especially if they are asking you to send them money or using a premium rate phone line (numbers beginning with 09). If you are receiving unsolicited sales and marketing calls from overseas you should contact the overseas company who is making the call.

Just ask - which company's products are you selling? If there's no straight answer, it's either a scam or a very stupid sales approach. In either case, you really want nothing to do with them.

Monday, 2 April 2007

Report phishing attempts

Fed up with phishermen? If you're a customer of a UK bank, and assuming you spotted the bogus e-mail before you clicked a link and compromised your bank accounts, there's a way to fight back. Give the banks the information they need to close the scams down! Some banks use an umbrella method such as BSO, others have their own arrangements. In either case, the sooner they hear from the public, the sooner action can be taken. The list below shows reporting contacts for fraudulent e-mail attempts.
BankSafe Online (operated by APACS*): reports@banksafeonline.org.uk
Anti-Phishing Working Group (APWG):reportphishing@antiphishing.org
A&Lfrauddepartment@alliance-leicester.co.uk
Barclays:internetsecurity@barclays.co.uk
Halifax Bank/HBOS:onlineemailinvestigations@hbosplc.com with the subject 'Report'
HSBC:Gives links to APWG and BSO
Lloyds TSB:EmailScams@lloydstsb.co.uk
Nationwide Building Society:phishing@nationwide.co.uk
NatWest:nwolb@natwest.com
Royal Bank of Scotland:digitalbanking@rbs.co.uk
Abbey National:E-Banking helpdesk on 0845 600 4388, open 7am-11pm, seven days a week
Clydesdale Bank:links to APWG
Yorkshire Bank:links to APWG
Northern Bank:links to APWG

Forwarding your suspect email

Select the suspect email (don't double click to open it), right click and select the Forward action, and send it to the appropriate email address

Attaching the suspect email to a new email

Create a new email in your PC or Mac based email software, and drag and drop the suspect email from your inbox into the body section of the new email. Please note that this method will not work for web based email services e.g. Hotmail, Yahoo! Mail etc.

*APACS is the UK trade association for payments and for those institutions that deliver payment services to customers.