By Coenraad De Beer
Viruses and spyware is no strange thing to computer users these days. Everyday we need to update our anti-virus and anti-spyware programs to keep our computers protected against these threats. A scan once a week or more is required to reveal any nasty pests, which infiltrated your system without being detected. While it is imperative to have software protecting our computers against these threats, is it just as important to know how these infections occur and where they come from.
I think it is safe to assume that the places you visit on the Internet will determine which programs are installed on your PC. Let me put it this way, the software installed on your computer will have some relevance to the sites you often visit. Lets take a few examples, when you are using Gmail, chances are good that you will have Gmail Notifier or GoogleTalk installed on your PC. When you often visit Yahoo.com or take part in their social networks, chances are good that you will have Yahoo! Toolbar or Yahoo! Messenger installed on your PC. Lets take a more practical example, users visiting Microsoft.com most probably have packages like Microsoft Office and Microsoft Windows XP installed on their computers. It is likely for supporters of the Open Source Initiative to hang out on sites like OpenSource.org, OpenOffice.com, Linux.org or SpreadFirefox.com. So your software preferences play a huge role in the type of web sites you visit and vice versa.
But what has this to do with malware infections? To be honest, everything! Let me show you what the top culprits of malware infections are and it will soon be clear to you what the connection is between the web sites you visit and the malware found on your PC.
Top culprit number 1: Pornographic web sites
Download Spyware Blaster by JavaCool Software and have a look at all the porn related web sites blocked by this program. It is also remarkable to see how many computers with traces of pornographic web sites in their browser history, are often infected with spyware and trojan horses. Unfortunately you will have innocent victims of malware infections, also with traces of pornographic web sites in their browser history, but only because the malware redirected them to these sites. However, people with pornographic material on their computers are not that innocent in this case, pornography does not go out looking for people, people go out looking for pornography.
Top culprit number 2: Illegal music (MP3) and movie downloading sites
These sites normally force you to install special downloading software on your computer so that you can download files from them. These download managers are often bundled with spyware and are trojan horses themselves, downloading tons of other spyware programs while you cheerfully download your illegal MP3's. They sometimes place tracking cookies on your PC to monitor your browsing habits and hijack your browser to make sure you return to their site or a site of a partner.
Top culprit number 3: Software Piracy web sites
If you love using illegal software, cracks, serial numbers or license key generators (keygens) then you most probably had to remove some malware infections in the past after visiting one of these sites. Most of the people using these cracks are normally technical wizards and know how to disinfect their computers. Many of these sites do not only contain harmful scripts but also fake cracks and key generators, which are nothing else but malware. Some crack developers create a working crack but distribute it with spyware or a trojan horse to make your PC their slave.
Top culprit number 4: Peer-to-peer file sharing programs and networks
The file sharing community is loaded with pornography, pirated software, music and movies. Is it not amazing that everywhere these guys make their appearance you also find spyware, viruses, trojan horses and all kinds of malware? The client software is also often bundled with spyware (or adware as they call it).
The culprits discussed so far are those connected with illegal and indecent activities. People visiting these sites and using these services deserve getting infected with malware. These culprits are also some of the biggest sources of malware epidemics. What flows from the mouth, comes from within the heart. The same rule applies to your computer, those nasty little programs crawling inside your computer is, in the case of culprits 1 to 4, the direct result of your own sinful actions and activities.
The next couple of culprits are caused by negligence and a lack of knowledge about how malware are distributed.
Top culprit number 5: Pop-up and pop-under advertisements
Another culprit that wants to caught you off guard. A pop-up window may appear out of the blue or a concealed pop-under window my load in the background without you even knowing it. These windows can start downloading malicious programs and install them on your computer. They can appear on any web site, not just illegal and other bad web sites. You can prevent these windows from opening by using a secure browser like Firefox with a built-in pop-up blocker.
Top culprit number 6: Fake anti-virus and anti-spyware tools
You visit a legitimate looking web site and suddenly a banner appears telling you that your computer is infected with spyware. You can scan your computer with all the anti-spyware software in the world, over and over again until you are blue in the face, but that banner will keep telling you that your computer is infected with spyware. This is because it is a plain image banner. The site never does a scan of your computer, it is a fixed message that will display on any computer, no matter how clean it is. Simply put, it is a blatant lie! They want you to believe that your computer is infected and that only their software can remove this spyware. If you download and install their software you will only find that it is spyware itself. You may end up infecting a completely clean system with a dirty program, trying to remove the so-called spyware.
A system scan is not a three second process, it takes time, so no scanner can tell you instantaneously that your system is infected with spyware. I do not believe in online scanners, rather use software with a good reputation, a local scan is much more faster. Most online scanners are no online scanners at all, you actually download the whole scanning engine and end up doing a local scan anyway. A real scanner will tell you the name of the malware and its location on your hard drive, if it does not give you this information, then it is fake. Even if it gives you this information, it still does not mean that the software is legitimate. Do not trust everything you see online and stick to well known anti-malware brands.
Top culprit number 7: Free games, screen savers, media players, etc.
No, not every free program comes bundled with spyware, but spyware (once again the developers prefer to call it adware, but it is still the same thing) is often the price you have to pay for the free software. It is normally a ploy to monitor your use of the program, to send the creators statistical data or to collect data about your online behaviour in order to send you targeted ads. If you try to remove the spyware you normally render the main application useless. Read the EULA (End User Licence Agreement) very carefully before installing the application. But everyone knows that nobody reads those tedious, long licence agreements, so use EULAlyzer by JavaCool Software to check for specific keywords and phrases that might reveal any spyware programs being installed or privacy breaching practices that may occur if you install the free software.
Top culprit number 8: Malicious web pages with harmful scripts
But you already mentioned this one in culprits 1 to 3. No, culprits 1 to 3 often have harmless web sites and it is the content you download from the sites that is harmful. But you also get web pages containing malicious scripts, totally innocent looking web sites, like a site donating money for cancer. You go to their homepage and suddenly a script virus strikes your computer. This is what an anti-virus shield was made for, that unexpected attack. Firefox is also designed to prevent harmful scripts and browser hijackers from accessing the system and taking advantage of flaws and weak spots in your operating system.
Top culprit number 9: E-mail
Virus worms spread themselves by forwarding a copy of the virus to all the contacts in your address book. Those contacts that are unaware of these worms will most likely open the e-mail and the file attached to it. But when you open a strange infected e-mail from an unknown sender, then you are guilty of double negligence. For the virus to be activated you need to open the e-mail and in most cases you need to deliberately open the file attachment too. By using a little common sense you will know that strange e-mails from unknown senders are dangerous, especially when they have executable attachments with file names ending with the "exe", "com", "bat" or "scr" extensions. Even dangerous e-mails from known, trustworthy contacts can easily be identified if the contents of the e-mail seems strange and out of character. By being careful and responsible when opening your e-mails, you will not only prevent your own computer from getting infected, but you will also prevent the worm from spreading any further.
Top culprit number 10: You the Internet user
What? Me? How on earth can I be a culprit? Well, you are an accomplice in the spread of malware if you do not have an active and updated anti-virus package installed on your computer, if you do not scan your computer for viruses and spyware on a regular basis, if you do not use shields like the TeaTimer tool from SpyBot (which is free by the way), the Ad-Watch shield of Ad-Aware or the resident shield of AVG Anti-spyware (all of which you have to pay for, unfortunately), if you spend your time browsing pornographic and illegal web sites and take part in the sharing of pirated software and copyrighted material (culprits 1 to 4), if you fail to be responsible with the software you install on your PC and the e-mails you open (culprits 6, 7 and 9) and if you refuse to use a secure web browser (like Firefox) built to prevent malware infections (culprits 5 and 8). Yes, I will go so far to say, that if you stay away from culprits 1 to 7 and 9, you probably won't need any virus and spyware protection at all. Culprit 8 is the only reason why you should have anti-virus and anti-spyware protection, for those unexpected attacks, over which you have no control.
Culprits 1 to 8 are the main sources of malware. Infections caused by them led to the creation of culprits 9 and 10, which distribute the malware even further. Do not turn your computer into a malware paradise or a malware distribution centre. Take responsibility, protect your computer against these threats and prevent the spread of malware.
About the Author
Coenraad is webmaster and founder of Cyber Top Cops, leaders in Internet security, prevention of online fraud and educating users against online scams and malicious software. Visit our Malicious Software Removal Assistance page for advice and personal assistance with the removal of stubborn and unknown malware infections.
Wednesday, January 03, 2007
Tuesday, January 02, 2007
Online Safety Of Your Children Starts With You As A Parent
By Coenraad De Beer
Parental control software is far from perfect and your kids are smarter than you may think, they will always find a way around them. Companies developing this software make millions out of parents neglecting their responsibility as a parent. What is the use of restricting the access on their computer, if they can find other ways of accessing the sites they want? You cannot use a computer program to prevent them from watching indecent TV shows and movies, you cannot use a computer program to prevent them from reading indecent magazines and books, you cannot use a computer program to help them choose their friends or prevent them from using drugs, you cannot use a computer program to protect them from predators.
You, as a parent have the responsibility to educate your children, when they are old enough to understand, about what is right and what is wrong in life. Many kids buy their own books, computer games, they rent their own DVD’s, some even have their own TV set, so it is useless, in fact foolish, to control only one source of bad influence on your children? You are only treating the symptoms and not the root of the problem and the root is lack of proper education and raising your children without good moral values. People do not take it serious when they are warned against the damaging effects of exposing children to all the explicit sex, nudity, violence and bad language through all the different mediums available to us today. When these immoral acts negatively affect adults and offend them, what effect do you think does it have on young children? I know that immoral material on the Internet sometimes make an appearance through unsuspected pop up windows, but these pop ups normally appear on sites where children should not have been in the first place. Our moral values have degraded so much that indecent web sites are not seen as "bad" anymore. The adults consuming this content today are the product of a previous generation of people who threw all moral values overboard.
The online safety of your children is not only about maintaining high moral values, it is also about keeping them away from online predators. These people are active on IRC channels (chat rooms), forums and may even contact your child via e-mail. So many teenagers have walked into the trap of deception. There is no way of verifying the identity of the person on the other side of your computer screen. An adult online predator, pretending to be a teenager, can easily mislead your teenager into believing that he/she has found a good online friend. This is why online dating is so dangerous, not only for children but adults as well. Online predators can behave well, they can be friendly and kind, they can be sympathetic to the problems of your child and you child can easily find comfort in that. Never let your child meet an online friend without your presence and tell them how dangerous it is meeting or talking to total strangers without parental guidance.
Educate your children not to give personal details, addresses and telephone numbers to anyone online, you should determine whether it is safe to provide these details by assessing the situation. There may be circumstances where these details are required for subscriptions to safe online services your child might want to use. You should be the judge of which services are suitable for your children and which ones are not. If you are unsure of the safety of a certain service, ask for the opinion of an expert or someone else already using it. Do not give your children too much power if they cannot use it responsible, too much control is not good either and you should find a balance between the two. If you fail to find a balance, you will end up compromising the safety of your child in the online and as well as the offline world.
Trust goes both ways and the trust showed by the one party will help win the trust of the other party. You need to be able to trust your children, trusting that they will stick to the rules you make. You should make it clear what the consequences will be if they disobey and misbehave, be consequent with your actions and make no exceptions to your own rules. They should also be able to trust you, knowing that you will not invade their privacy. Breaking into their e-mail accounts and reading their e-mails, or installing spyware to spy on their online activities is not the right way of protecting your children. Both parties should be open and honest towards each other with everything they do. Your child should have enough confidence in you, to turn to you when he or she is unsure of something or did something wrong. Not taking your child serious in such a case will break down the trust built up between the two of you and you will end up being the direct cause of his or her mistakes. Children are a gift from God, never neglect your responsibility as a parent.
About the Author
Coenraad is webmaster and founder of Cyber Top Cops, leaders in Internet security, prevention of online fraud and educating users against online scams and malicious software.
Parental control software is far from perfect and your kids are smarter than you may think, they will always find a way around them. Companies developing this software make millions out of parents neglecting their responsibility as a parent. What is the use of restricting the access on their computer, if they can find other ways of accessing the sites they want? You cannot use a computer program to prevent them from watching indecent TV shows and movies, you cannot use a computer program to prevent them from reading indecent magazines and books, you cannot use a computer program to help them choose their friends or prevent them from using drugs, you cannot use a computer program to protect them from predators.
You, as a parent have the responsibility to educate your children, when they are old enough to understand, about what is right and what is wrong in life. Many kids buy their own books, computer games, they rent their own DVD’s, some even have their own TV set, so it is useless, in fact foolish, to control only one source of bad influence on your children? You are only treating the symptoms and not the root of the problem and the root is lack of proper education and raising your children without good moral values. People do not take it serious when they are warned against the damaging effects of exposing children to all the explicit sex, nudity, violence and bad language through all the different mediums available to us today. When these immoral acts negatively affect adults and offend them, what effect do you think does it have on young children? I know that immoral material on the Internet sometimes make an appearance through unsuspected pop up windows, but these pop ups normally appear on sites where children should not have been in the first place. Our moral values have degraded so much that indecent web sites are not seen as "bad" anymore. The adults consuming this content today are the product of a previous generation of people who threw all moral values overboard.
The online safety of your children is not only about maintaining high moral values, it is also about keeping them away from online predators. These people are active on IRC channels (chat rooms), forums and may even contact your child via e-mail. So many teenagers have walked into the trap of deception. There is no way of verifying the identity of the person on the other side of your computer screen. An adult online predator, pretending to be a teenager, can easily mislead your teenager into believing that he/she has found a good online friend. This is why online dating is so dangerous, not only for children but adults as well. Online predators can behave well, they can be friendly and kind, they can be sympathetic to the problems of your child and you child can easily find comfort in that. Never let your child meet an online friend without your presence and tell them how dangerous it is meeting or talking to total strangers without parental guidance.
Educate your children not to give personal details, addresses and telephone numbers to anyone online, you should determine whether it is safe to provide these details by assessing the situation. There may be circumstances where these details are required for subscriptions to safe online services your child might want to use. You should be the judge of which services are suitable for your children and which ones are not. If you are unsure of the safety of a certain service, ask for the opinion of an expert or someone else already using it. Do not give your children too much power if they cannot use it responsible, too much control is not good either and you should find a balance between the two. If you fail to find a balance, you will end up compromising the safety of your child in the online and as well as the offline world.
Trust goes both ways and the trust showed by the one party will help win the trust of the other party. You need to be able to trust your children, trusting that they will stick to the rules you make. You should make it clear what the consequences will be if they disobey and misbehave, be consequent with your actions and make no exceptions to your own rules. They should also be able to trust you, knowing that you will not invade their privacy. Breaking into their e-mail accounts and reading their e-mails, or installing spyware to spy on their online activities is not the right way of protecting your children. Both parties should be open and honest towards each other with everything they do. Your child should have enough confidence in you, to turn to you when he or she is unsure of something or did something wrong. Not taking your child serious in such a case will break down the trust built up between the two of you and you will end up being the direct cause of his or her mistakes. Children are a gift from God, never neglect your responsibility as a parent.
About the Author
Coenraad is webmaster and founder of Cyber Top Cops, leaders in Internet security, prevention of online fraud and educating users against online scams and malicious software.
Friday, December 29, 2006
Strange E-mails Without Attachments Are Not Necessarily Harmless
By Coenraad De Beer
A couple of years ago it was safe to assume that e-mails without attachments are completely harmless, whether from a trusted source or not. Computer criminals became more advanced over the years, causing this simple rule to become less applicable to e-mail security. Spam is more than just senseless e-mails cluttering your Inbox, whether they have attachments or not.
Even e-mails from trusted sources cannot be trusted these days. What we never know is whether the PC of the trusted source is infected with e-mail worms and spam bots sending out these e-mails without the consent of the PC owner. So your e-mail may come from a trusted source but is the source still trustworthy? By that I do not imply that your best friend turned against you and is sending you harmful and indecent e-mails. Your best friend may be totally innocent and unaware of the fact that a virus turned his/her computer into a spamming zombie. The problem we are facing here is to determine whether a human or an infected PC sent the e-mail. A spam bot normally sends e-mails that are totally out of character, e-mails that no decent human will send, especially not your best friend.
But you need to open the e-mail to determine its contents. The perception still exists that e-mails without attachments are harmless and that it is safe to open them. But it is much safer to view the source of the e-mail in order to view its contents without opening it. This is not always possible with web based e-mail services but it is possible with e-mail clients like Outlook, Outlook Express and Mozilla Thunderbird. Viewing the source of an e-mail enables you to read the body of the e-mail without any trouble, just like when you actually opened it. The biggest advantage of this method is that any harmful scripts or attachments embedded into the e-mail cannot be run or executed while viewing the source of the e-mail. Some e-mails may appear scrambled when viewing its source, this is when the e-mail only consists of an image embedded into it and most e-mails compiled this way are normally spam. Disabling JavaScript in your e-mail client will also make it safer to open e-mails, in fact very few people use JavaScript in their e-mails, so I do not even see any sense in enabling something that is never really used.
Many people may argue that they open hundreds of spam e-mails, without attachments, on a daily basis without any harm done to their PC. This is true, but it is not only about the harm it can do to your PC, some of these e-mails contain content that is offensive to sensitive people and harmful to minors. Other e-mails may not contain offensive content, but they can easily make you a victim of advance fee fraud and phishing scams if you are not familiar with the characteristics of these scams. They play with your mind, abuse your feelings, it is a case of psychological warfare, brainwashing. They want you to step into their trap, but they need to deceive you first, gain control over your mind in order to achieve it.
It is not hard to identify spam these days, but people still go through the trouble of opening them while knowing that they are spam. Why open something if you know for a fact that it contains useless information? Have you ever thought of it as the spammer exercising control over your actions? Why do you think do they send you so many senseless e-mails everyday, e-mails that seem to be completely harmless? The only way of making you comfortable with something is to bombard you with thousands of the same kind of e-mail over and over again until you are so conditioned that you no longer can distinguish legitimate e-mails from fraudulent ones.
Spam is no longer aimed at damaging your computer, no those days are long gone. On the contrary spammers need your PC to help them distribute their unwanted e-mails, so they will not harm it, they will rather infiltrate it. They infiltrate your PC to steal your information, invade your privacy and involve you in their devious crimes. Next time you receive a strange looking e-mail think twice before opening it, whether it has attachments or not.
About the Author
Coenraad is webmaster and founder of Cyber Top Cops, leaders in Internet security, prevention of online fraud and educating users against online scams and malicious software.
A couple of years ago it was safe to assume that e-mails without attachments are completely harmless, whether from a trusted source or not. Computer criminals became more advanced over the years, causing this simple rule to become less applicable to e-mail security. Spam is more than just senseless e-mails cluttering your Inbox, whether they have attachments or not.
Even e-mails from trusted sources cannot be trusted these days. What we never know is whether the PC of the trusted source is infected with e-mail worms and spam bots sending out these e-mails without the consent of the PC owner. So your e-mail may come from a trusted source but is the source still trustworthy? By that I do not imply that your best friend turned against you and is sending you harmful and indecent e-mails. Your best friend may be totally innocent and unaware of the fact that a virus turned his/her computer into a spamming zombie. The problem we are facing here is to determine whether a human or an infected PC sent the e-mail. A spam bot normally sends e-mails that are totally out of character, e-mails that no decent human will send, especially not your best friend.
But you need to open the e-mail to determine its contents. The perception still exists that e-mails without attachments are harmless and that it is safe to open them. But it is much safer to view the source of the e-mail in order to view its contents without opening it. This is not always possible with web based e-mail services but it is possible with e-mail clients like Outlook, Outlook Express and Mozilla Thunderbird. Viewing the source of an e-mail enables you to read the body of the e-mail without any trouble, just like when you actually opened it. The biggest advantage of this method is that any harmful scripts or attachments embedded into the e-mail cannot be run or executed while viewing the source of the e-mail. Some e-mails may appear scrambled when viewing its source, this is when the e-mail only consists of an image embedded into it and most e-mails compiled this way are normally spam. Disabling JavaScript in your e-mail client will also make it safer to open e-mails, in fact very few people use JavaScript in their e-mails, so I do not even see any sense in enabling something that is never really used.
Many people may argue that they open hundreds of spam e-mails, without attachments, on a daily basis without any harm done to their PC. This is true, but it is not only about the harm it can do to your PC, some of these e-mails contain content that is offensive to sensitive people and harmful to minors. Other e-mails may not contain offensive content, but they can easily make you a victim of advance fee fraud and phishing scams if you are not familiar with the characteristics of these scams. They play with your mind, abuse your feelings, it is a case of psychological warfare, brainwashing. They want you to step into their trap, but they need to deceive you first, gain control over your mind in order to achieve it.
It is not hard to identify spam these days, but people still go through the trouble of opening them while knowing that they are spam. Why open something if you know for a fact that it contains useless information? Have you ever thought of it as the spammer exercising control over your actions? Why do you think do they send you so many senseless e-mails everyday, e-mails that seem to be completely harmless? The only way of making you comfortable with something is to bombard you with thousands of the same kind of e-mail over and over again until you are so conditioned that you no longer can distinguish legitimate e-mails from fraudulent ones.
Spam is no longer aimed at damaging your computer, no those days are long gone. On the contrary spammers need your PC to help them distribute their unwanted e-mails, so they will not harm it, they will rather infiltrate it. They infiltrate your PC to steal your information, invade your privacy and involve you in their devious crimes. Next time you receive a strange looking e-mail think twice before opening it, whether it has attachments or not.
About the Author
Coenraad is webmaster and founder of Cyber Top Cops, leaders in Internet security, prevention of online fraud and educating users against online scams and malicious software.
Saturday, December 23, 2006
The Perfect Password Practice
By Coenraad De Beer
Our lives are filled with passwords, security questions, personal identification numbers (PINs) and security codes. Almost every digital device and software package has some security feature involving a password. We have hundreds of shopping accounts, email accounts, banking accounts, you name it and each and every one of these accounts has a user name and a password associated with it. Sometimes you feel you are loosing your mind keeping the security of all your accounts and devices together. Here are a few tips to make the job a bit easier and your accounts more secure.
With all the accounts we own and all of the places where we need to use user names and passwords, it becomes a full-time job keeping it all together. The easiest way for most people is to use the same user name and password for all their accounts when possible. Most of the times it is only the user name that differs, but the password often stays the same for every new account they open or device they use. This is extremely dangerous and I will explain why.
There are several ways of leaking out your password. You may just, accidentally, say the password out loud while entering it. If someone was standing nearby, he/she could have easily picked it up and may use it later to gain access to the restricted area protected by the password. Key-loggers installed on your computer can log your password and send it to their owners and spyware programs can extract saved passwords from your cookies or from the saved password list stored in your browser settings. People sometimes write their passwords on a piece of paper and do not keep it in a safe place. What is the use of a key if you leave it in the door? The same principle applies to passwords. A password is the key to a restricted area, you should not let that key lie around for anyone to use. Sending passwords via e-mail is not so wise either and it is 99% of times a sign of a fraudulent activity. You should be careful when people request your password to be sent over the Internet via e-mail. Companies often sent your login details via e-mail. You should print out the details, store the printed copy in a safe place and delete the e-mail. E-mail worms and viruses can easily scan your e-mails for passwords. The different ways of loosing your passwords are endless.
Now what happens when someone steals your password? Chances are good that the perpetrator will break into the account guarded by the password, cause damage and maybe change the password so that you cannot gain access to the account in the future. If you use the same password for all your accounts, you should regard all your other accounts as compromised. The only missing piece of the puzzle for the password theft is to obtain the user name of your other accounts and the chances are good that most of them will also accept the same user name as the breached one. The only comforting thing is to know that the theft has to figure out what other accounts you own. One cannot break into something one does not know the existence of. It is not always possible to change your user name, but it is always possible to change your password. When a widely used password is compromised, you should change the passwords of all your other accounts as quickly as possible to avoid further security breaches. You should also try to regain control of your breached account as soon as possible, by contacting the service provider of the account and explaining the situation to them. This is most important for bank and online shopping accounts.
How should I prevent my password from being stolen?
About the Author
Coenraad is webmaster and founder of Cyber Top Cops, leaders in Internet security, prevention of online fraud and educating users against online scams and malicious software.
Our lives are filled with passwords, security questions, personal identification numbers (PINs) and security codes. Almost every digital device and software package has some security feature involving a password. We have hundreds of shopping accounts, email accounts, banking accounts, you name it and each and every one of these accounts has a user name and a password associated with it. Sometimes you feel you are loosing your mind keeping the security of all your accounts and devices together. Here are a few tips to make the job a bit easier and your accounts more secure.
With all the accounts we own and all of the places where we need to use user names and passwords, it becomes a full-time job keeping it all together. The easiest way for most people is to use the same user name and password for all their accounts when possible. Most of the times it is only the user name that differs, but the password often stays the same for every new account they open or device they use. This is extremely dangerous and I will explain why.
There are several ways of leaking out your password. You may just, accidentally, say the password out loud while entering it. If someone was standing nearby, he/she could have easily picked it up and may use it later to gain access to the restricted area protected by the password. Key-loggers installed on your computer can log your password and send it to their owners and spyware programs can extract saved passwords from your cookies or from the saved password list stored in your browser settings. People sometimes write their passwords on a piece of paper and do not keep it in a safe place. What is the use of a key if you leave it in the door? The same principle applies to passwords. A password is the key to a restricted area, you should not let that key lie around for anyone to use. Sending passwords via e-mail is not so wise either and it is 99% of times a sign of a fraudulent activity. You should be careful when people request your password to be sent over the Internet via e-mail. Companies often sent your login details via e-mail. You should print out the details, store the printed copy in a safe place and delete the e-mail. E-mail worms and viruses can easily scan your e-mails for passwords. The different ways of loosing your passwords are endless.
Now what happens when someone steals your password? Chances are good that the perpetrator will break into the account guarded by the password, cause damage and maybe change the password so that you cannot gain access to the account in the future. If you use the same password for all your accounts, you should regard all your other accounts as compromised. The only missing piece of the puzzle for the password theft is to obtain the user name of your other accounts and the chances are good that most of them will also accept the same user name as the breached one. The only comforting thing is to know that the theft has to figure out what other accounts you own. One cannot break into something one does not know the existence of. It is not always possible to change your user name, but it is always possible to change your password. When a widely used password is compromised, you should change the passwords of all your other accounts as quickly as possible to avoid further security breaches. You should also try to regain control of your breached account as soon as possible, by contacting the service provider of the account and explaining the situation to them. This is most important for bank and online shopping accounts.
How should I prevent my password from being stolen?
- Memorise it. A password or PIN is useless if you need to carry it around with you on a piece of paper, or written on the back of your debit or credit card. Do not share it with anyone, not even your loved ones. Not out of lack of trust, but to limit the number of people knowing your password to one. When there is only one person who knows the password, there can be only one source of leaking it out. More people knowing your password, means more possible sources of leaking.
- Choose an arbitrary password, a combination of uppercase and lowercase letters combined with numbers and special characters. For instance the password "aS33@bH1" is a good example of one that cannot be guessed easily. You can quickly memorise it by repeating the password over and over in your head. Refrain from saying it out loud, because you can easily compromise it if someone else overhears you saying it. If your name is Ashley, for instance, you can use the password "@$l3y". Although it is more secure than "Ashley", someone can still guess it if the person is familiar with your first name. Your password should not be connected to something like your birthday, social security number or anything that will make it easier for a hacker to guess it.
- Change your password every now and then. It is not as important for individuals to change their password as it is for large organisations with hundreds of passwords and security codes protecting sensitive data and restricted areas, but it remains a good practice to change your password once in a while. After all, it can do no harm (unless you forget your password or the fact that you changed it).
- Get yourself a small data organiser (not a PDA or your mobile phone) with a password feature. Store all your account information and passwords under the secure area of this little organiser and put it in a safe place. I also recommend that you write down all the information stored on this organiser on a piece of paper and put it in a steel safe, just in case you loose your data due to battery or device failure. These little data organisers are very suitable for this task because they cannot be connected to the Internet and you cannot load any software on the device to bypass the password. Unfortunately these devices rarely, if ever, encrypt the information stored behind the password, so a clever hacker can easily read the data from the memory chip if he/she has the necessary equipment.
- Scan your computer regularly for spyware and viruses, preferably on a weekly basis. This will ensure that your computer is free from malicious software stealing your sensitive information or monitoring your activity while using the computer. If your anti-virus or anti-spyware software detects malicious software on your computer, do not enter any password on that specific computer until you are certain that all the threats are completely removed and destroyed.
- Never store your passwords in a text file, Word document or PDF file. Rather use a password manager if you need to store it on a computer. If possible store it on a computer that is never connected to a network or the Internet. As a rule of thumb, never store your passwords on any computer.
- Make sure that you enter your password on secure pages with a valid SSL (Secure Socket Layer) certificate. Entering your password on insecure pages could easily compromise the safety of your account.
- Try not to enter your password while someone is standing nearby. Even if the password is masked on your screen, some people have the ability to memorise the keyboard buttons you press, while watching as you enter it, no matter how fast you type.
About the Author
Coenraad is webmaster and founder of Cyber Top Cops, leaders in Internet security, prevention of online fraud and educating users against online scams and malicious software.
Wednesday, December 20, 2006
Safe Online Shopping Tips For Late Christmas Shoppers
By Coenraad De Beer
Because you are desperate for a gift you will not mind paying a little extra, but the price can be an expensive one to pay if you are not cautious when shopping online. Swindlers always bargain on the mistakes of their victims when they are under pressure. They want to strike when you are not paying attention to the finer details you normally pay attention too when you are not under pressure. The false sense of urgency in phishing attacks and advance fee fraud are examples of swindlers trying to force a victim to make a mistake while he/she is under pressure. With online shopping they bargain that you will not realise that their online shop is a fraud, that their products are fake or that they do not even possess these items. There are a couple of things to look out for when you do your shopping online, not only during the festive seasons, but each time when you transact online.
The very first thing you should do is to verify the legitimacy of the online shop. Make sure that their telephone number, physical address and postal address is valid. Make a phone call to the company and ask about their products. If you are shopping from a local online shop get into your car and visit their premises if possible, or ask a trustworthy person to verify their physical address for you. Write them a letter and request a product brochure. If the telephone number is valid, if you confirmed the physical address of their offices and if they reply to your letter, you will know how to get into touch with them should you have any queries after you made the purchase. If their web site does not supply a valid telephone number, postal and physical address, do not buy from them. If they want to sell products online they should make it easy for consumers to get in touch with them.
Make sure you read their privacy policy and terms of agreement. Read all the instructions and fine print carefully before clicking on the order and pay buttons. You want to make sure that you are familiar with all the procedures of the online shop before you bind yourself legally to a purchase contract. Make sure that you understand the way they calculate shipping and delivery costs, or any extra fees. If in doubt, request a quotation from their sales department. You do not want to get a surprise after you finalised the purchase. Find out if they have a refund policy. If they mess up your order or if you are not satisfied with their products, you want to be certain that you can get your money back.
Before you enter any personal and sensitive information, make sure that you enter this information on a secure web page with a valid SSL (Secure Socket Layer) certificate. You can verify this by looking for a little yellow padlock at the bottom of your browser window. If you double click on this padlock, you can see who issued the certificate and you can verify if the certificate is still valid. Ensure that the address in the address bar start with the letters "https". If they do not provide SSL protection, find another online shop. Any serious and professional online shop will give their customers peace of mind by providing a safe and secure environment where they can collect all the information they need about their customers, without compromising the safety of this information. Never reply to any e-mail requesting financial information. E-mail is very insecure and is not suitable for sending sensitive information over the Internet. A legitimate online shop will have a web site with safety mechanisms in place, protecting your personal and financial information from hackers and swindlers.
Maintain a thorough paper trail. Print every confirmation page, quotation, receipt, order summary and e-mail you receive from the company and remember to set your browser to include the date and time on the printouts to make it easier to see when you printed these documents. Always pay by credit card or a system like PayPal. You should never send the seller any cash. If you pay by cash you leave no paper trail and that makes it impossible to trace the payment or to prove that you already paid for the products. Leaving a proper paper trail makes it possible to trace the transaction back to the seller of the product.
There are many other things you can do stay safe while doing your shopping online. One of the safest ways to follow is to stick with well-known online shops like Amazon. Unfortunately Amazon does not cater for the needs of everyone and you may often find it necessary to buy from other online shops when you are looking for something specific. This is when tips like these come in very handy.
About the Author
Coenraad is webmaster and founder of Cyber Top Cops, leaders in Internet security, prevention of online fraud and educating users against online scams and malicious software.
Because you are desperate for a gift you will not mind paying a little extra, but the price can be an expensive one to pay if you are not cautious when shopping online. Swindlers always bargain on the mistakes of their victims when they are under pressure. They want to strike when you are not paying attention to the finer details you normally pay attention too when you are not under pressure. The false sense of urgency in phishing attacks and advance fee fraud are examples of swindlers trying to force a victim to make a mistake while he/she is under pressure. With online shopping they bargain that you will not realise that their online shop is a fraud, that their products are fake or that they do not even possess these items. There are a couple of things to look out for when you do your shopping online, not only during the festive seasons, but each time when you transact online.
The very first thing you should do is to verify the legitimacy of the online shop. Make sure that their telephone number, physical address and postal address is valid. Make a phone call to the company and ask about their products. If you are shopping from a local online shop get into your car and visit their premises if possible, or ask a trustworthy person to verify their physical address for you. Write them a letter and request a product brochure. If the telephone number is valid, if you confirmed the physical address of their offices and if they reply to your letter, you will know how to get into touch with them should you have any queries after you made the purchase. If their web site does not supply a valid telephone number, postal and physical address, do not buy from them. If they want to sell products online they should make it easy for consumers to get in touch with them.
Make sure you read their privacy policy and terms of agreement. Read all the instructions and fine print carefully before clicking on the order and pay buttons. You want to make sure that you are familiar with all the procedures of the online shop before you bind yourself legally to a purchase contract. Make sure that you understand the way they calculate shipping and delivery costs, or any extra fees. If in doubt, request a quotation from their sales department. You do not want to get a surprise after you finalised the purchase. Find out if they have a refund policy. If they mess up your order or if you are not satisfied with their products, you want to be certain that you can get your money back.
Before you enter any personal and sensitive information, make sure that you enter this information on a secure web page with a valid SSL (Secure Socket Layer) certificate. You can verify this by looking for a little yellow padlock at the bottom of your browser window. If you double click on this padlock, you can see who issued the certificate and you can verify if the certificate is still valid. Ensure that the address in the address bar start with the letters "https". If they do not provide SSL protection, find another online shop. Any serious and professional online shop will give their customers peace of mind by providing a safe and secure environment where they can collect all the information they need about their customers, without compromising the safety of this information. Never reply to any e-mail requesting financial information. E-mail is very insecure and is not suitable for sending sensitive information over the Internet. A legitimate online shop will have a web site with safety mechanisms in place, protecting your personal and financial information from hackers and swindlers.
Maintain a thorough paper trail. Print every confirmation page, quotation, receipt, order summary and e-mail you receive from the company and remember to set your browser to include the date and time on the printouts to make it easier to see when you printed these documents. Always pay by credit card or a system like PayPal. You should never send the seller any cash. If you pay by cash you leave no paper trail and that makes it impossible to trace the payment or to prove that you already paid for the products. Leaving a proper paper trail makes it possible to trace the transaction back to the seller of the product.
There are many other things you can do stay safe while doing your shopping online. One of the safest ways to follow is to stick with well-known online shops like Amazon. Unfortunately Amazon does not cater for the needs of everyone and you may often find it necessary to buy from other online shops when you are looking for something specific. This is when tips like these come in very handy.
About the Author
Coenraad is webmaster and founder of Cyber Top Cops, leaders in Internet security, prevention of online fraud and educating users against online scams and malicious software.
Subscribe to:
Posts (Atom)