Showing posts with label email. Show all posts
Showing posts with label email. Show all posts

Saturday, May 30, 2015

Microsoft's "Wow" Factor

It's been a long time coming, but Microsoft is "getting groovy." I read nearly daily news about new software, improved software, new hardware, new partnering, new acquisitions, and more key apps for more operating systems.
  • Office 365
    • Office Now
    • Office Monitor
    • Delve
    • Mix for PowerPoint
    • Editing via multiple OS
    • Office Now
    • OneClip
  • Cortana
  • Flow
  • Revolve
  • Hello
  • Sway
  • Hyperlapse
  • Continuum
  • Hololens
  • Music app improvements on the way
  • Acquisitions (September 2014 - May 2015)
    • Wunderlist. German To Do list app.
    • Datazen. Mobile business intelligence leader
    • Sunrise. Creator of an innovative calendar app for mobile devices
    • Revolution Analytics. Helps customers find big data value with advanced statistical analysis (R programming language)
    • Equivio. Israeli text analysis company
    • HockeyApp. Leading mobile crash analytics and beta distribution service for iOS, Android, and Windows Phone
    • Acompli. Provider of innovative mobile email apps
    • Aorato. Israeli Cybersecurity Firm
    • Mojang. Minecraft developer

Wednesday, November 13, 2013

Security tips of the Day

A shield with Microsoft Office colors in its quadrants
The international SANS organization offers excellent "Security Awareness Tip of the Day" posts. You can subscribe to them (an RSS feed) if you like. Some have links to more information. A few recent topics:
  • E-mail is insecure by default
  • Turn off your wireless AP when it's not in use
  • Don't accept offers for "Free PC Scans" that pop up
  • Avoid Spam in your IM email account
  • Don't let Spammers see your out-of-office replies
  • Four tips to keep your computer secure

Tuesday, November 12, 2013

Thieves steal 113 smartphones every minute -- Is yours next?

A Windows 8 Phone
The ZoneAlarm Security Blog has some great tips for safe computing. A recent post deals with smartphone theft. Many people have no password to their smartphone. If you lose or even just temporarily misplaced your smartphone, anyone can do business "in your name" as well as gather up contact information and much, much more.

Adding a strong password (not just a simple PIN) to use the phone may be a slight inconvenience while using it, but it protects your data. This is crucial if you do any online [shudder] financial transactions with your smartphone.

Protection tips also apply to tablets and similar portable computing devices.

Saturday, November 09, 2013

Fun games foster security awareness

Phishing Scams - avoid the bait
The U.S. government has a great site to learn more about being smart and safe online. It's called OnGuard Online. The site includes some simple online games that let you check your "smarts" about safe computing.

You may learn something new or maybe just reinforce good habits. Either way, visit the site.

Below are links to some interactive video quizzes:

Thursday, April 30, 2009

Scrapers hit social networking sites

A recent article in Windows Secrets newsletter, "Viral inviters want your email contact list", stated, "The arms race between the script builders and big-name Web services is just beginning. The massive data collections that the scrapers are able to accumulate are simply too valuable to pass up.

The problem will only get worse as social-networking sites create linked systems. For example, the Facebook Connect service that launched last year allows members to use their Facebook account to sign in to hundreds of third-party sites, such as CNET and MoveOn.org."

Unfortunately, too many people are lured by friends and acquaintances that tell them, that having a Facebook page makes them "cool". But they don't tell them (perhaps because they don't know or don't believe) about the pitfalls, the need for locked down tight security, the need to keep data you share to an absolute minimum, and the real need to be skeptical of emails you get.

Criminals can only flourish in such a naively trusting environment. Here's hoping that future tightening of the world's email system underpinnings will reduce the ability of Spammers and other Criminals to pretend to be a "friend" and sucker people into hurting themselves.

Saturday, March 21, 2009

Does that email pass the smell test?

We get lots of email messages every day. How do you tell what's a fake (and likely to try to hurt you) and what's not? Carnegie Mellon's Software Engineering Institute produced a set of checks that are still valid. It's the KREVS "test".
  • The Know test. Do you already know the sender?
  • The Received test. Have you received safe emails from the sender before?
  • The Expect test. If the email has an attachment, were you expecting to get it?
  • The Virus test. Does the message pass a virus-check? (Make sure your Antivirus program also checks your email messages).
  • The Sense test. Does it look right? Are there unexpected misspellings? Does it "smell" in any way?

If an email messages fails any of the above tests, delete it. Even if an email messages passes all 5 tests above, it still might be malicious. Be paranoid; the "bad guys" really are out to get you. Criminal attack attempts using email are increasing rapidly.

If the email is from a person you already know, still be careful. Call them and see if they really sent any unexpected attachment.

Wednesday, February 04, 2009

Malware worms its way into social networking

Social network site users tend to be more trusting than they should be about emails from "friends". They seem to assume that since they have to login to the account that messages from others are "safe". Criminals know that.

So with increasingly sophisticated social engineering, criminals are successfully attacking social networking services. Angry Facebook members created a special facebook page for victims of the Koobface worm.

Malicious software "scrapes" Facebook for all the user data it can find. People who give out real names, addresses, email addresses, and other information may find it cropping up in the hands of criminals. We teach kids to be wary of strangers, but then we turn around are and much too trusting in our online behavior ourselves. Parents, schools, and churches all need to start educating kids and even other adults about being wary of online personas and of being careful not to release personal information. Criminals now "mine" data from multiple sites to "fill in the picture" about victims identities and personal information.

Government agencies normally let their employees do personal surfing, yet they are starting to block access from the government offices to social networking sites. Why? It just too unsafe, at least for now.

Part of the challenge is that in order for social networking sites to be "fun", they have to encourage their members to share information. The default for most social networking sites is to be "open" rather than to have tight security. And most people are much more gullible online than in the "real world". So social networking sites like FaceBook and MySpace may continue to be a rich feeding ground for criminals.

If you insist on risking use of a social networking site, it might be a good idea to subscribe to a service that tracks your credit card actions as well as actions taken that relate to your credit rating. For example, you'd get an alert if someone was applying for a loan or credit card and using your credit record. And make sure to keep your Antivirus, AntiSpyware, and Firewall software up to date. You might also want to add prayer to the list. You may need it.

Friday, December 28, 2007

Scammers target eBay names

Anti-scammer tips:

  • Use a different name on eBay than on your webmail. Scammers target an email name on gmail, hotmail, and similar online webmail apps.
  • If it sounds too good to be true, it's not true.

- Based on a blurb in the December 28th SANS emailed newsletter (not online yet). You can subscribe to get security "NewsBites" by email.

Saturday, October 20, 2007

Malicious emails contain fake Youtube link

US-CERT says that new variations of the Storm Worm have been appearing in email messages as fake YouTube video links.

The emails arrive with headers such as, "LOL, that is too cool..."

The email claims to be a video of you that has been discovered. The message contains a fake link to youtube.com. The link acually sends you to a malicious website that downloads and runs malware.

Friday, September 14, 2007

Identifying hoaxes and legends

The US-CERT site has some excellent Cyber Security tips. A recent one is "Identifying hoaxes and urban legends". The article is in clear English, not geek language, and covers:
  • Why hoaxes are a problem
  • Types of chain letters
  • Deciding if an email is a hoax (or legend)

Saturday, April 21, 2007

New email version from Mozilla

Thunderbird 2.0 email software is now available from Mozilla -- the folks who bring you the FireFox web browser. I have in the past used Outlook Express, Outlook, and Eudora email clients. But my current choice is Thunderbird.

My fast take on version 2.0:
  • Spiffied up icons (in general)
  • Weird looking sideways folder icons
  • Some nice new features
  • One big disadvantage: Mozilla still has not built in the needed ability to delete a message and return to the message list. The only action built into Thurderbird is to automatically display the nest message. This is a horrible program behavior for security reasons. What if the next message is malicious? What if it contains an invisible GIF web bug? You have no chance to just not open it -- Thunderbird will open that message anyway. As a result, some Thunderbird 2.0 users are reverting back to version 1.5 and using the "Unselect message" add-in.
  • Another downer: The "Unselect message" add-in (extension) that I used with version 1.5 does not work with version 2. I used this as a workaround for the terrible lack of that capability in Thunderbird (as mentioned above). Hopefully the author will revise the code so it's compatible with version 2.x.

Thursday, January 25, 2007

Eudora email becomes Penelope

Qualcomm is going to cease development of its popular email client software, Eudora. Instead, it is giving its code to the Mozilla folks, who also produce Thunderbird.

At first I thought that Eudora would get merged into a slightly changed Thunderbird. But no. The aim by Mozilla, with the help of current Eudora staff, is for the new open-source email client program to maintain the "Eudora user experience". The name for this project is Penelope.

I have been using Eudora Pro, but decided to try out Thunderbird. Caution - the Thunderbird importers for Eudora's mailboxes, folders, messages, and address books are very "rough". I had to heavily edit the imported address book data, though the Eudora 7 messages and "Personalities" did import OK. Thunderbird is a different user experience, but mostly rewarding. I really appreciate the spell check as you type. But I was annoyed that there was no option to change the default message action upon delete -- it pops up the next unread message, which could be malicious. No thank you!

If you want to try Thunderbird, I recommend also installing the "Unselect message" add-on, which changes the default action to one that deletes an open message and then returns to the message list without opening the next unread one. That should have been the Thunderbird default anyway, just for security reasons.