Did you have fun this weekend? If so, did you post photos of this fun to your Facebook account? And if you did that, did you (hopefully) stop to consider whether those photos could get you into trouble with your significant other, your boss, or your mom? Maybe you think you don't have to worry about that, because your S.O., boss, or mom were with you (so you've got still more photos to ensure they will withhold any judgement), or because the fun was so innocent (or within their definition of innocent) that they wouldn't care. Maybe you don't care, because such opinions have no influence in your life, or because you've locked your Facebook account down so the only people who can see your photos are the friends you've approved (and therefore will presumably approve of you).
If you think no one whose opinion could literally change your life might see your Facebook photos, you're probably wrong.
If you think no one other than the friends you have approved can see your Facebook photos, you're wrong. Period.
And if you think you don't care who sees your Facebook photos, ask yourself if you'd care if your insurance company saw them - and then dropped you.
The story above concerns health insurance, but raises questions about what else insurance companies might find useful out there on the intarwebs. If your fun this weekend was marred by a fender-bender and you took pictures of it, I would strongly suggest you hold off on posting those pictures to your Facebook page...at least until you get those pictures to your auto insurance company, and you are sure of their judgement.
And if you took pictures that could be in any way be construed as you having the remotest bit of fun at the scene of the accident, I would strongly suggest not posting those pictures to your Facebook page at all.
Period.
Monday, November 23, 2009
Wednesday, November 18, 2009
Loyalty can be bought - has yours?
There's a few reasons why I have one credit card designated solely for online shopping, but up until now having to beware of being surreptitiously signed up for some fee-charging "loyalty program" wasn't one of them. This definitely makes my "WHOA!!" list.
Read the above linked article thoroughly, and more than once if the first time doesn't make you mad enough. Then check the statements of any credit cards you've used online - thoroughly. If you find you've been getting charged for "loyalty" you didn't definitively declare, I'd suggest you make some "customer noise" with the volume cranked up to max. Yeah, buyer beware, caveat emptor, RTFP (that's my acronym for Read The Fine Print, before anyone thinks I got it wrong), and all that, but even in the grey area of letting people hang themselves with their own rope there's a difference between someone sticking their head in a noose that's more or less visible, and a noose that gets slipped over a person's head while a sleazy advertiser distracts them by hollering "HEY LOOK, OVER THERE - CASH BACK AND A COUPON!!".
For myself, I've never made a purchase via Classmates.com either directly or through an ad on their website, but I'm nixing my account there ASAP. I check it only once in a blue moon, and any true classmates of mine who haven't already found me via other (and better) channels are probably people I don't care to hook back up with anyway.
Yes, it's a jungle out there. That still doesn't give supposedly legitimate online businesses (or their affiliates) a free pass to act like starving jackals.
p.s. Techcrunch has a got plenty of scoop here. Many of the comments are as enlightening as the article itself, so settle back with a favorite beverage if you have time for a bit of reading.
Oh, and have some aspirin handy.
Read the above linked article thoroughly, and more than once if the first time doesn't make you mad enough. Then check the statements of any credit cards you've used online - thoroughly. If you find you've been getting charged for "loyalty" you didn't definitively declare, I'd suggest you make some "customer noise" with the volume cranked up to max. Yeah, buyer beware, caveat emptor, RTFP (that's my acronym for Read The Fine Print, before anyone thinks I got it wrong), and all that, but even in the grey area of letting people hang themselves with their own rope there's a difference between someone sticking their head in a noose that's more or less visible, and a noose that gets slipped over a person's head while a sleazy advertiser distracts them by hollering "HEY LOOK, OVER THERE - CASH BACK AND A COUPON!!".
For myself, I've never made a purchase via Classmates.com either directly or through an ad on their website, but I'm nixing my account there ASAP. I check it only once in a blue moon, and any true classmates of mine who haven't already found me via other (and better) channels are probably people I don't care to hook back up with anyway.
Yes, it's a jungle out there. That still doesn't give supposedly legitimate online businesses (or their affiliates) a free pass to act like starving jackals.
p.s. Techcrunch has a got plenty of scoop here. Many of the comments are as enlightening as the article itself, so settle back with a favorite beverage if you have time for a bit of reading.
Oh, and have some aspirin handy.
A Phew Phishing Phacts
Hopefully by now, everyone who's had an email account for any length of time has not only heard the term "phishing", but actually knows what it is. Almost certainly anyone who's had an email account for any length of time has gotten at least a few phishing emails (for varying values of "a few").
CNET recently posted sort of "phishing primer" article that's worth the read. In a nutshell, phishing is, in its most common form, that scary/shrieking/somber missive in your inbox that proclaims to be from ->insert official organization and logo here<- and tells you to click the embedded link and log in to verify your information now or risk having your PayPal/eBay/CheckFree/Amazon/whatever account shut down.
Alternatively you may be facing an audit (or a refund!) from the IRS, or your bank has just been declared "failed" (I got one of these the other day, which made me smile - I've already given my bank a "FAIL" many times over the years, so I hardly need an email notice about it); the list goes on and on. One of my personal recent favorites is the one proclaiming to be from the email provider itself, warning that the "servers" are due to be "upgraded", so all user account information needs to be verified beforehand. Yeeeeah...so I guess they're not planning on backing up all that "account info" themselves prior to the "upgrade", and in fact have never stored or backed it up at all. C'mon, folks, if your email provider has to email you to provide them with your basic email account information via an email reply...think about it. Have some aspirin handy.
There's a few more phishing facts worth elaborating on:
The warnings to be wary of .exe file attachments are all well and good. Problem is, malicious code can be embedded in .doc files, .xls files, .ppt files, .zip files, .gif files, .pdf files - bascially any kind of file that can have executable code embedded in it. So be wary of any attached file you aren't specifically expecting. And do yourself a favor - turn off the preview pane in your email client. Now. The days when you had to explicitly open an attachment for it to deliver its payload are long gone; just opening the email it's attached to can be enough. The content of the email itself can be enough, if it's got Evile Dancing Bunnies in it and you have your email client set to render .html when you open a message. Guess what the preview pane for your inbox does?
If you feel irresistibly compelled to call a phone number contained in a suspicious email, do not call from your cell phone. Call from a land line you don't care about, or borrow a cell phone from someone you don't like. The scammers will happily settle for a working phone number they can sell off to telemarketers or use for SMS spam if they can't get the goods via email.
If you've clicked on an embedded link and been directed to a website, it's too late to worry about being fooled. Chances are good you already have. Shut down your web browser, kick off a complete virus scan, and go play outside while it runs. If you don't have a working and updated antivirus installed on your computer, slap yourself sharply across the face and then go shopping for one. When you get back, start looking for those restore CDs that came with your computer. You might need them.
Finally, as always, never EVER respond to any sort of spam, even to give the spammer what-for and demand they blot your email address forever from their consciousness. All you're doing is confirming for them that A) your email account is in fact active, and B) you opened their email. Jackpot for them, but no cookies for you. Well, except the ones they may have scattered all over your hard drive while they sold your verified email address to fellow spammers for the highest bid.
Time for me to wrap up a post that's turned waaaay longer than I intended...I need to go check my email. :)
CNET recently posted sort of "phishing primer" article that's worth the read. In a nutshell, phishing is, in its most common form, that scary/shrieking/somber missive in your inbox that proclaims to be from ->insert official organization and logo here<- and tells you to click the embedded link and log in to verify your information now or risk having your PayPal/eBay/CheckFree/Amazon/whatever account shut down.
Alternatively you may be facing an audit (or a refund!) from the IRS, or your bank has just been declared "failed" (I got one of these the other day, which made me smile - I've already given my bank a "FAIL" many times over the years, so I hardly need an email notice about it); the list goes on and on. One of my personal recent favorites is the one proclaiming to be from the email provider itself, warning that the "servers" are due to be "upgraded", so all user account information needs to be verified beforehand. Yeeeeah...so I guess they're not planning on backing up all that "account info" themselves prior to the "upgrade", and in fact have never stored or backed it up at all. C'mon, folks, if your email provider has to email you to provide them with your basic email account information via an email reply...think about it. Have some aspirin handy.
There's a few more phishing facts worth elaborating on:
The warnings to be wary of .exe file attachments are all well and good. Problem is, malicious code can be embedded in .doc files, .xls files, .ppt files, .zip files, .gif files, .pdf files - bascially any kind of file that can have executable code embedded in it. So be wary of any attached file you aren't specifically expecting. And do yourself a favor - turn off the preview pane in your email client. Now. The days when you had to explicitly open an attachment for it to deliver its payload are long gone; just opening the email it's attached to can be enough. The content of the email itself can be enough, if it's got Evile Dancing Bunnies in it and you have your email client set to render .html when you open a message. Guess what the preview pane for your inbox does?
If you feel irresistibly compelled to call a phone number contained in a suspicious email, do not call from your cell phone. Call from a land line you don't care about, or borrow a cell phone from someone you don't like. The scammers will happily settle for a working phone number they can sell off to telemarketers or use for SMS spam if they can't get the goods via email.
If you've clicked on an embedded link and been directed to a website, it's too late to worry about being fooled. Chances are good you already have. Shut down your web browser, kick off a complete virus scan, and go play outside while it runs. If you don't have a working and updated antivirus installed on your computer, slap yourself sharply across the face and then go shopping for one. When you get back, start looking for those restore CDs that came with your computer. You might need them.
Finally, as always, never EVER respond to any sort of spam, even to give the spammer what-for and demand they blot your email address forever from their consciousness. All you're doing is confirming for them that A) your email account is in fact active, and B) you opened their email. Jackpot for them, but no cookies for you. Well, except the ones they may have scattered all over your hard drive while they sold your verified email address to fellow spammers for the highest bid.
Time for me to wrap up a post that's turned waaaay longer than I intended...I need to go check my email. :)
Thursday, November 5, 2009
Oldies but goodies
Who says legacy hardware can't still be useful in production? And I've had people point and laugh because I run a MacIntoaster...
Traffic Signal Computer On The Blink.
"This is a rather old computer. It's probably 25 to 30 years old. It's a 1980s-vintage Data General main frame computer. Parts are not really available."
Well, okay perhaps in this instance it's not exactly useful - at least not at the moment - but, still in production. Better than I expected, actually; I was thinking maybe they had a 20+ year old workstation running OS/2. And while security by obscurity is definitely not a recommended approach, I know my PPC 7100 is secure, certainly as long as there's no land line handy for connecting the modem. ;-)
(bonus question for anyone under 30 reading this: what's a land line, anyway?)
Okay, back to watching my Cube's bouncing beach ball. :-P Hey, so it's slow at times, but it is still both in production AND useful.
Traffic Signal Computer On The Blink.
"This is a rather old computer. It's probably 25 to 30 years old. It's a 1980s-vintage Data General main frame computer. Parts are not really available."
Well, okay perhaps in this instance it's not exactly useful - at least not at the moment - but, still in production. Better than I expected, actually; I was thinking maybe they had a 20+ year old workstation running OS/2. And while security by obscurity is definitely not a recommended approach, I know my PPC 7100 is secure, certainly as long as there's no land line handy for connecting the modem. ;-)
(bonus question for anyone under 30 reading this: what's a land line, anyway?)
Okay, back to watching my Cube's bouncing beach ball. :-P Hey, so it's slow at times, but it is still both in production AND useful.
Thursday, September 10, 2009
Facebook: Why I'm even on it
Yes, after so long of scowling, scolding, and even snarling at friends, family, users, and random people I've stopped in the street (okay, I don't do that, at least not that I'm aware of), I have finally gone to the Darkside. Predictably, the response from those who know me has been comparable to catching Jane Fonda on a wild midnight binge at Krispy Kreme. I have also promptly been the recipient of various requests, invites, and gifts (I intend to speak privately to the old friend who offered me a goat - there is a hidden message there, I am sure of it), none of which I have accepted. I do appreciate the spirit in which these communiques are made (sometimes perhaps more than the sender intended), and I certainly don't want to hurt anyones feelings, but that's not why I joined Facebook.
I actually joined Facebook after being reunited with a longtime BFF, who urged me to sign up to see her family photo album. So no, I didn't finally lose it, I got conned by pictures of cute kids. I do have a soft spot here and there (I keep trying to patch them, but duct tape gets expensive). Once I had set foot on Enemy Territory, I figured I might as well do some reconnaissance and get a better feel for this wildly popular phenom that, coincidentally, is often a source of business for hubby 'n me. Anyone who knows what we do for a living ought to stop and think about that for a moment.
Although I don't try to hide the fact that my tinfoil hat may be a little tight, I'm not saying Facebook is going to infest your home computer with a dozen backdoor trojans and browser hijackers hosted by identity-stealing cyber-criminals the minute you sign in. I'm also not saying you're immediately going to get run off the road on the I-264 interchange by distracted, iPhone texting teens in beat up SUVs. However, both of these environments are inherently hazardous.
If you're careful and alert, you CAN safely navigate both Facebook and rush hour traffic. Like just about anything else, a little common sense goes a long way. Me, I can't avoid the interchange no matter how hard I try, so I'll just keep driving defensively with my seatbelt on and my thumb hovering over my horn. At this point I can't completely avoid Facebook either (not without missing out on future cute kid pictures), but like all lanes on Al's Information Superhighway, I'll be driving defensively there as well. ;-)
I actually joined Facebook after being reunited with a longtime BFF, who urged me to sign up to see her family photo album. So no, I didn't finally lose it, I got conned by pictures of cute kids. I do have a soft spot here and there (I keep trying to patch them, but duct tape gets expensive). Once I had set foot on Enemy Territory, I figured I might as well do some reconnaissance and get a better feel for this wildly popular phenom that, coincidentally, is often a source of business for hubby 'n me. Anyone who knows what we do for a living ought to stop and think about that for a moment.
Although I don't try to hide the fact that my tinfoil hat may be a little tight, I'm not saying Facebook is going to infest your home computer with a dozen backdoor trojans and browser hijackers hosted by identity-stealing cyber-criminals the minute you sign in. I'm also not saying you're immediately going to get run off the road on the I-264 interchange by distracted, iPhone texting teens in beat up SUVs. However, both of these environments are inherently hazardous.
If you're careful and alert, you CAN safely navigate both Facebook and rush hour traffic. Like just about anything else, a little common sense goes a long way. Me, I can't avoid the interchange no matter how hard I try, so I'll just keep driving defensively with my seatbelt on and my thumb hovering over my horn. At this point I can't completely avoid Facebook either (not without missing out on future cute kid pictures), but like all lanes on Al's Information Superhighway, I'll be driving defensively there as well. ;-)
Facebook: Why I don't answer
Just a quick post here, and a link to a good (IMHO) article on Facebook:
Facebook May Not Be For Everyone
I've gotten a few offers of pets, glitz, and farm animals myself, and I too will appreciate the thought while politely declining to accept.
I don't have time for farming via Facebook anyway; when I do have the rare few minutes of free time to play, I'm working on my mage level in Runescape. My farming level there ain't bad, either. ;-)
Facebook May Not Be For Everyone
I've gotten a few offers of pets, glitz, and farm animals myself, and I too will appreciate the thought while politely declining to accept.
I don't have time for farming via Facebook anyway; when I do have the rare few minutes of free time to play, I'm working on my mage level in Runescape. My farming level there ain't bad, either. ;-)
Tuesday, June 30, 2009
URLs in short
There's an old saying that "a shortcut is the longest distance between two points". When it comes to "tiny" URLs, this is literally true. If you like to share interesting links with friends and family, you may find URL shortening services quite useful. If you like to send links via Twitter, SMS, etc., they are invaluable, due to the character length restrictions on messages. Of course, it hasn't taken long for bad guyz (and galz) to find these services invaluable in other ways. It only makes sense: why bother trying to scatter links to your malware all over a bunch of websites if you can hack one shortening services server and point ALL their hosted links somewhere else?
This approach also neatly addresses (bad pun not intended) the problem of canny websurfers who use anti-phishing tools, or who simply hesitate to clink a link that shows its true destination as "http://www.hacks4u" at the bottom of their web browsers.
Since URL shortening services require that you hand off control of where the shortened URL points to, and trust that your intended destination remains the actual one, the best defense is a good offense. If you send, choose your carrier carefully. If you receive, be aware of (and wary of) the delivery guy. The wrapping may be pretty, but as another saying goes, "beauty is only skin deep - ugly goes to the bone".
Update: More news keeps popping up on nefarious uses of shortened URLs. Tiny URL does offer a preview feature, and for one extra click, I would recommend its use. Do yourself, and the people you send links to, a favor. ;-)
This approach also neatly addresses (bad pun not intended) the problem of canny websurfers who use anti-phishing tools, or who simply hesitate to clink a link that shows its true destination as "http://www.hacks4u" at the bottom of their web browsers.
Since URL shortening services require that you hand off control of where the shortened URL points to, and trust that your intended destination remains the actual one, the best defense is a good offense. If you send, choose your carrier carefully. If you receive, be aware of (and wary of) the delivery guy. The wrapping may be pretty, but as another saying goes, "beauty is only skin deep - ugly goes to the bone".
Update: More news keeps popping up on nefarious uses of shortened URLs. Tiny URL does offer a preview feature, and for one extra click, I would recommend its use. Do yourself, and the people you send links to, a favor. ;-)
Subscribe to:
Posts (Atom)
