Many times, perhaps most of the time, the first step in a company getting hacked is an email message. That's why this is the first topic.
You never know who sent an email message, so think carefully before taking action based on a single message. It is fairly easy to forge the FROM address of an email. Be especially careful about doing anything involving money, passwords or personal information based on one lousy email message. Techies can look at the hidden email headers to get an idea who really sent a given message, but this is not a skill taught in nerd school. If you can figure out how to display the header of an email message, you can copy/paste it into www.iplocation.net/trace-email which will parse the header and tell you the sending/source IP address, country, ISP and organization. A similar tool is Email Header Analyzer by MxToolbox. Might help.
In light of the above, victims might trust that an email was legit, if it knew something about us. However, our personal information has leaked time and time again, so including information about you, specifically, is no indication that the sender is who they claim to be or that the message is legit. For example, Starwood was hacked, so an email about the time you stayed at the Westin hotel in Cleveland in the summer of 2018, may not be from Starwood. Bad guys know you stayed there too.
It is easy to assume that when you reply to an email message, the reply goes to the person that sent the message. Sure, this is the case almost all the time - but not all the time. Internet email has a rarely used ReplyTo feature that lets the sender specify an email address to receive replies. An email message from DonaldDuck@gmail.com might have a ReplyTo address of DonaldDuck@hotmail.com or DonaldDuck@aol.com or DonaldDuck@anyfreeservice.com. The ReplyTo address can be anything, but copying the sender's name while changing the domain makes it more likely the scam will not be noticed. If the ReplyTo is used in conjunction with a spoofed sender email address, then a victim can be fooled into an ongoing conversation with bad guys.
Maybe your email software will display the ReplyTo field, maybe it won't. Gmail hides the ReplyTo address until you actually reply.
Links: Links in email and web pages are complicated. Unless you are a techie it can be almost impossible to know where you will end up after clicking on a link. If an email message has a link to login to a service, DO NOT click it. Go to the website of the service on your own and login there.
The more urgent the plea for you to take action, the more likely the message is a scam. Bad guys don't want you to have a chance to think
about the issue or check with others.
An email password is more important than many people think. In that light, make sure it is at least 12 characters long and that you do not use the password for anything else. If you use password manager software, do not keep the email password in the password manager. Keep it on paper instead.
When bad guys learn your email password, they are likely to send scam messages to everyone in your address book. So that you see these messages as soon as possible, consider having both your own email address and a secondary one that also belongs to you, in your email address book.
Terminology: "Phishing" means scam. A phishing email is lying to you about something. "Spear Phishing" is a scam specifically targeted at you. In a spear phish, the bad guys will have researched you and they use the information about you as the part of the lure in their scam. For example, they might learn who does the money transfers in a company, then pretend to be the boss and order a fake money transfer.
Email attachments: Word documents, spreadsheets and PDF files are often malicious. The safest way to open any file attached to an email message is on a Chromebook running in Guest mode. The next safest option is to open it on an iOS device. The third safest environment is from Google Drive (hopefully from a Chromebook or an iOS device). Upload the attachment to Google Drive and open it from Google Drive. The least safe environment to deal with email attachments is Windows. If you must use Windows or macOS, download the attached file and go to VirusTotal.com to scan it with many different anti-virus programs before opening it. Any type of attached file can be dangerous.
Secure Email: The only two companies offering this, that I know of, are ProtonMail and Tutanota. Neither company can read your email while it is stored on their servers. Messages sent between their customers are also safe from prying eyes. Email from either company to any other email provider can either be secure or not, but it is a very different type of security. In October 2021, I wrote about this: Using ProtonMail encrypted messages with a normal email account. Both companies offer free limited accounts. Both can be used with software on your computer but webmail lets the browser prove that encryption is being used in transit. Webmail can also be used on a Chromebook running in Guest mode to insure that no trace of your actions is left behind. Episode 149 of the Privacy, Security, & OSINT podcast was on Secure Email with a comparison of ProtonMail and Tutanota. Interesting point in the podcast: you may want to configure each service not to automatically save every email address you correspond with in the your Contacts list.
If you use webmail, you should have a local (on your computer) backup of your contacts/address book. For Gmail, go to contacts.google.com and look for "Export" in the left side vertical column. Google offers three possible formats for the backup file, it can not hurt to make three backups, one in each format. Make a note to do this backup every few months.
An email with a password protected attachment, that has the password in the body of the email message, is surely malicious. This is a trick bad guys use to prevent anti-virus programs from detecting malicious software. If you try to open an attached file on Windows and it fails to open, you can still get infected with a virus.
An email that asks you to logon to read an encrypted message is a scam.
REPORTING: Emails that pretend to be from a trusted organization for the purpose of stealing passwords or other personal information can be reported to Cisco PhishTank, SpamCop and the Anti-Phishing Working Group. Registration is required. You can also report any and all SPAM to SpamCop.
Links from Daniel Aleksandersen. Sophos is also willing to accept SPAM and malicious emails on their
Submit a Sample page.
If the scam came from Hotmail or Outlook, report it to email@example.com. If the scam came from Gmail, then report it to firstname.lastname@example.org.
If you have an email account with a recovery email address (Gmail does this) you should check every now and then (yearly?) that the recovery email address is still valid. It is used for things like resetting the password.
Taking a step back, it seems to me like we are living in a time much like the one before seat belts were required in cars. The current norm, reading email on a computer with sensitive or important files (or LAN based access to such files), is much too risky. If you are not reading email on a Chromebook or an iOS device, you are doing it wrong. Using any other OS, in a corporate environment, is job security for the IT department and the assorted security companies they employ. I say this as someone who does not work in corporate IT.
There are two big issues with passwords: how to create the dozens that we all need and how to retrieve them after they are created.
It is tempting to avoid both problems by re-using a password. NEVER re-use passwords. This is the most important thing about passwords for two reasons. First, companies are hacked all the time, leaking passwords that bad guys then try at other systems/websites. This is made worse by the fact that so many different websites/companies use an email address as a userid. So, if a re-used password leaks it can open up access to multiple accounts. This article, Credential stuffing explained: How to prevent, detect and defend against it (Lucian Constantin Oct 2019) explains that the automated use of stolen usernames and passwords to access accounts is low risk, high reward for cybercriminals.
There are millions of articles on the best way to deal with passwords. Almost every one of them is wrong. Typically, the author offers the best solution for them, not for you. There is no single approach to the two basic problems (creating and retrieving) that is appropriate for everyone.
Computer techies always recommend a software solution. This is stupid on many levels. There is nothing wrong with storing passwords on paper. Even someone who uses a password
management program, should still store a small number of their passwords on paper.
Another piece of bad advice that is frequently repeated is that random passwords are good. They are not, because they ignore the human factor - they are impossible to remember and hard to type. Specifically, passwords such as "kdnH54#sadweD" and "mkJy$sCFqw" should be avoided in favor of something akin to "99HeavyRedbaseballs" or
"reallyoldLemon$$trees". String together a few words (no mis-spellings needed) and add a number or a special character and use mixed case. Good enough. Typically, the length
of a password is far more important than its randomness.
Almost every computer nerd recommends password management software. I disagree. Techies that say this are thinking inside the box and over valuing
the need for randomness in passwords. They also underestimate the hassle of new software for non techies.
"I was never able to find a way to set people up on a password manager in the time available. Let me be very clear: I would like all people to use a password manager ... But I never found a way to get people onto 1password in a single training session. The setup process has a lot of moving parts, involving the desktop app, browser plugin, online service, mobile app, and app store. It requires repeatedly typing a long master passphrase. And then, once it is all set up, you have to train people on the unrelated skill of how to use the thing, starting with their most sensitive accounts. And then you leave. In the end, I told candidates to generate unique passwords and save them in the notes app on their phone, or write them down on a card they kept in their wallet."
John Opdenakker is a rare techie willing to admit that password managers are not the best solution for everyone. He writes: "Knowing that many online services give password manager users a hard time, it's not very likely that non tech savvy people will be able to use them ... for a lot of users, like my mum or dad ... I recommended them to use different passwords for their accounts and write them down in a password book."
Try using a formula to generate your passwords. A simple formula is to start every password with the same string of characters. Then, you can chose very simple passwords to append to the constant beginning. For example, a baseball fan might start every password with "BaseballRules!" Then, if "jungle" was their password for Amazon.com, the actual password is "BaseballRules!jungle" And, all you would have to remember would be that your Amazon password is "jungle". Pretty easy. Amazon. Jungle. And, the miserable password "book" for Barnes and Noble, becomes a good password ("BaseballRules!book") when run through the formula. Perhaps the worst password is the word password. But, as Leo Notenboom points out, "1234 password 1234" is a pretty good password. And, while I would not use this particular password, it can illustrate a simple formula: start and end every password with the same number, then put a word in the middle surrounded by spaces.
You can check if any of your passwords have leaked in a data breach at haveibeenpwned.com/Passwords. Of course, someone else may have been using the same password. The best passwords have never leaked and a formula (above) should produce globally unique passwords fairly easily.
Storing passwords: Using a formula lets you write down just the easy/right part of the password and still be secure. If someone saw your password list and read that "book" was your Barnes and Noble password, it would be useless without the formula. Passwords written on paper can not be hacked; just be sure to xerox the list every now and then in case you lose it.
Traveling passwords: Paper passwords work everywhere, no matter the device, the Operating System or the software being used. I use a password manager for a small number of passwords and its useless on a Chromebook running in Guest mode which is where I do my sensitive transactions.
Some passwords are much more important than others. Which, of your many passwords, would be the worst for bad guys to obtain? Keep those passwords off your computers. Store them on multiple pieces of paper in multiple places. Or, store them on a USB flash drive which is rarely connected to a computer.
VERIFIED WEBSITE IDENTITY
(Last update: Jan 20, 2021) top
Everyone is told there are two types of websites: secure (HTTPS) and not secure (HTTP). In fact there are three types of websites. The third type is a "secure" site that has gone the extra mile and offers proof of its identity.
In another type of attack, a web browser may display the correct something.citi.com, and yet, the website could still be a fake. To prevent this, companies that take this stuff seriously pay extra to have their identities verified. It used to be easy and obvious to tell the difference between websites with a verified identity and those site, like this one, without one. For example, citi.com used to say "Citigroup Inc. (US)" just to left of online.citi.com in the address bar. Bank of America does the same thing as you would expect any financial company to do (see example). Different browsers handle this differently but the one constant is that a verified identity is no longer any of your business. It still exists, but only for those who know where to look for it in the particular browser they are using.
If the website of your financial institution has this extra identity protection, get in the habit of looking for it. If this information is not provided, take that as a bad sign about the company and its website. In techie terms, this website is Domain Validated (DV), the Citigroup and Bank of America websites have Extended Validation (EV). The home office of incompetence, Equifax, does not offer identity verification. Not a surprise. What is surprising is that neither does Amazon.com (shown in the screen shots).
Web browsers have always been inconsistent in how they indicate that a site has had its identity verified. Worse still, each browser constantly fiddled with their padlock display. As an illustration, this Aug. 2019 image, from Twitter user Cryptoki, shows eight different browsers indicating this in eight different ways. Internet Explorer was, by far, the best. It turned the entire address bar green, a visual clue that no one could miss. Most browsers displayed the verified company name in green, somewhere on the address bar.
An inconsistent User Interface is the good old days. As of September 2019 (give or take) there will be no user interface, at least, not one that is visible by default.
The two major web browsers, Chrome and Firefox have decided to hide this. Already, many web browsers fail to indicate a verified identity in any way. Why have Google and Mozilla decided to remove the indicators of a verified identity? Because you are stupid. They won't say that directly, but that is clearly what they are thinking. They point out that non-techies do not understand what it means for a website to have a verified identity. Never mind that, in no small part, this is their own fault for not having a standard indicator. Given this lack of understanding, rather than try to educate the public, they are taking their ball home so we can't play the game. Nerds at their worst.
Browsers will always be changing. As of January 2021, on Windows, you can tell the difference between a site with a verified identity and one without by clicking on the lock on the address bar (just left of the website name). In Chrome, Brave, Edge and Opera, if it just says "Certificate (Valid)" then there is no verified identity. However, if underneath this, it also says "Issued to: companyname" then the identity of the site has been verified. See a Chrome 87 screen shot showing it both ways.
With Firefox, if it just says "Connection Secure" that is bad. However, if underneath this it also says "Certificate issued to: companyname" that is good. With Vivaldi (version 3.5.2115.87) there is no need to click, it displays a verified company identity in green on the address bar. The Vivaldi lock is also black without a verified identity and green with one. Whew.
As with email messages, the content of a fake website can look exactly like the real thing. Anyone can copy images and text and fonts from the real site and use them to make a fake site.
If you visit a web page, everyone knows that HTTPS encrypts the content of the page. But that's not the whole story. As this blog by DuckDuckGo points out, parts of the URL are not encrypted. For example, if you visit https:// cancer.mayoclinic.org /isitcontagious.html
the fact that you visited the Mayo Clinic website and were interested in cancer will be visible to anyone watching network data transmissions. However, that you wondered whether cancer was contagious is not visible. In techie terms, everything after the domain name (isitcontagious.html) is encrypted in transit, however the domain name (mayoclinic.org) and sub-domains (cancer) are not encrypted.
The concept of secure websites, indicated by HTTPS or a lock icon, is, in many ways, a scam. The security that people tout refers to a small piece of a large pie. Specifically, it refers to in-flight data; data being transmitted back and forth between your computer and a website. If, while traveling over the Internet, the data/web page is encrypted, then the entire site is said to be secure. Fact is, dozens of things can still leak your sensitive data. Take the just-discussed EV/DV validation of websites. Without real identity verification (EV), you could "securely" send passwords to bad guys. Another scam is that encryption is a binary thing, that it is either on or off. In reality, it is quite complicated. So much so, that there are security rating websites (next topic). Perfect Forward Secrecy (PFS) is another factor, one that is hardly every discussed. Without PFS spy agencies can very likely (no one knows for sure) decrypt the encrypted data traveling over the Internet. Another factor is keeping private encryption keys private. If they leak (its just a string of bits), encrypted data can, again, be decrypted. No one knows how well any website protects its private keys. Then too, many websites continue to support older security/encryption protocols with known flaws (TLS 1.0 and 1.1). And, websites have different sections, each section has its own security profile; one section may be more secure than another. For example, in 2016, I blogged about how www.ssa.gov was secure while secure.ssa.gov was not (since fixed). And, nothing about encryption in transit tells you anything about the strength of the security on the back end (think Facebook storing passwords in plain text) or
whether software running on the back end is being updated with bug fixes (think Equifax), how good their defenses are against attacks, who they share your data with or whether the data is left publicly available to anyone who knows where to look, no attacking needed (this happens a lot). I could go on. Anyone who tells you to trust a website because it is secure, is either un-informed or lying on purpose because it serves their needs.
A great website for evaluating the encryption used by a website is the Qualys SSL Server Test. Ironically, it does not have extended identity protection. Still, it offers both a ton of technical information about encryption and a simple letter grade at the top. I suggest testing your most important sites: banking, email and any website holding your sensitive information. Every site should get either and A or A+. Anything else is a failure. The orange horizontal stripes under the letter grade are security failures. To be thorough, you need to check each section of a website. For example, at the US Social Security Administration, you would check both www.ssa.gov and secure.ssa.gov. To put this in perspective, again, encryption is a small piece of a large pie. Nothing about the strength of the encryption used to send/receive data tells you anything about whether passwords are stored in plain text, or whether bug fixes are applied to the software running the website, or any other aspect of security.
Some websites use secret questions as a way to identify you should you forget your password. Never answer these truthfully. You don't want
the answer to be anything that someone could either guess or learn about you. In fact, don't even give reasonable answers. If it asks for the name of a person, use the name of a place instead. You never know if the answers are case sensitive or not, so it is safer to only use lower case. In my opinion, it is also safer to avoid spaces and special characters too. Just like passwords, these questions and answers need to be saved somewhere that you can find them later. Nothing wrong with paper and pencil.
Any website that you can access with just a userid/password is not really secure. Stepping up the security requires a second factor/thingie. See the topic on Two Factor Authentication for more.
To take money from an ATM requires both a plastic card and a password. Two things. Two factors. In computing "two factors" refers to needing a password and something else to gain access to a system. Thus, a stolen password becomes useless as its only half the story. The robotic response from every computer nerd is to use Two Factor Authentication (2FA). But, it is not that simple. In the topic on SIM Swaps there are links to articles by people who became vulnerable by using 2FA. First they had their cellphone number stolen, but that was done to abuse 2FA text messages and change the passwords on many accounts. No 2FA text messages, no password changes. And, everything breaks, so you need to be up to speed on the fallback system for when 2FA breaks. There are different types of 2FA and no one right answer for everyone.
Perhaps the least secure type of 2FA, is a temporary code sent in a text message to a cellphone. It is very popular. Less popular, is the use of email for the exact same purpose. In the US, the Social Security Administration does this. Still another option is a phone call where a temporary code is spoken aloud. Or, a phone call where all you need to do is touch a button on the phone.
A more secure type of 2FA involves a Time Based Onetime Password (TOTP) generated by an app running on a mobile device. Two such apps are Authy and Google Authenticator.
A problem with both of these types of 2FA is a scam website. If you enter both your password and the temporary code into a scam website, the bad guys have it. This is exactly how Twitter was hacked in July 2020. According to the Twitter Investigation Report from the New York State Department of Financial Services (Oct. 2020), the bad guys called Twitter employees claiming to be from the IT department. "The Hackers claimed they were responding to a problem the employee was having with Twitter's VPN. Since switching to remote working, VPN problems were common at Twitter. The Hackers then tried to direct the employee to a phishing website that looked identical to the legitimate Twitter VPN website and was hosted by a similarly named domain. As the employee entered their credentials into the phishing website, the Hackers would simultaneously enter the information into the real Twitter website. This false log-in generated an MFA notification requesting that the employees authenticate themselves, which some of the employees did." To not be fooled by similarly named domains, see the topic here on Understanding Domain Names.
The most secure option involves a physical thingy you connect to a computer/tablet/phone that verifies your identity. No thingy no access. Some downsides: the thingies cost money, different computing devices require different thingies, not many systems support this type of 2FA and the software on the thingies might be buggy.
To check if the companies you deal with offer 2FA, see 2fa.directory.
When someone calls you, you NEVER know who they are. Callerid can be spoofed just like the FROM address in email. With so many companies being hacked and leaking data, the caller may know things that, at first, it seems only a legitimate caller would know. As with email: think carefully before taking action based on a single phone call, especially any action involving money, passwords or personal information.
If anyone calls you, and their story ends with you paying them with a gift card or by wiring money, it is a scam.
When someone calls you, you NEVER know who they are
The more urgent the need to send money, the more likely the call is a scam. Bad guys don't want to give you a chance to think about their made-up situation.
When someone calls you, you NEVER know who they are
Apple does not call their customers out of the blue. Neither does Microsoft or Windows. Some scammers pretending to be Apple make calls that display an Apple logo, address and their real phone number. More here and here. Contact Apple at
See the iOS topic, specifically, the sub-section for iOS 13, for two ways to block callers that are not in the address book
One problem with blocking unwanted calls, is that the definition of "unwanted" changes over time. If a loved one is having medical issues, you certainly want anyone involved in their care
to be able to reach you at any time. Other times too, you may want to disable any call blocking you have in place.
Unwanted calls can be reported to the US Government. Probably a waste of time.
In the news: Voice Phishers Targeting Corporate VPNs by Brian Krebs (Aug. 2020). The headline is wrong it is not voice phishing, just normal scams targeting employees of large corporations. In large part these scams depend on fake corporate websites, so understanding the rules for domain names (above) is a critical defense.
Considering the many data breaches of personal information, along with the legal sharing of it, ID theft is all too likely. Here are some things to do to in preparation.
Bad guys might try to open a credit card in your name. To prevent this, you can get a credit freeze with
Bad guys might use your credit card to buy themselves stuff. You can be alerted to this by having your credit card company notify you, in real time, about charges on your account.
The US Federal Trade Commission runs identitytheft.gov where you can both report the identity theft and learn how to recover from it.
Americans should open an account with the IRS (irs.gov) to prevent bad guys from opening
an account in your name and getting your tax refund. Even if you never use this account, it is safer to have it. Brian Krebs: has more (January 2018).
The IRS also offers an Identity Protection PIN (IP PIN), a six-digit number that prevents a bad guy from filing a tax return using your Social Security number. The IP PIN helps the IRS verify your identity when you file your tax return.
Americans should also open an account with the Social Security Administration (ssa.gov) regardless of their age. This prevents bad guys with your stolen information from opening an account as you, and, for many people, is the only way to verify that their earnings are correctly reported.
When you logon to the My Social Security website, it reports the last time you logged on. If you can track this yourself, then you can be sure no one has stolen
your identity and logged on as you.
According to this article, the Social Security Administration has greatly curtailed the number of paper statements it mails. It now mails statements only to people over 60 who are not yet getting benefits and who have not set up digital accounts.
After an account is opened, you can block all electronic access to it. Of course, this blocking is only as good as the defenses against bad guys unblocking it and I don't know what those defenses are.
The phone number of the Social Security Administration is 800-772-1213
The Social Security Administration does not threaten to arrest people. Social Security numbers can not be suspended. These are common scams.
Neither the IRS nor Social Security does a good enough job of identifying people. They both know where you live, they could send a code via postal mail to verify who you are ... but, no. The Social Security Administration uses Equifax data to verify your identity and we all know that Equifax was hacked in 2017 and lost their crown jewels (our personal information). If you have a credit freeze with Equifax, then you can not open a Social Security account. You can't make this stuff up.
A free annual credit report, available at annualcreditreport.com can't hurt. However, two things about the site are a sham. For one, it says that
you can order reports online. When I last tried this in December 2018, it was not true, reports had to be ordered via postal mail, and, I was not told this until
after I entered all my personal information. Also, the site has not opted for extra identity validation for itself (see topic on VERIFIED WEBSITE IDENTITY).
Requests on paper are the way to go.
Credit Monitoring Services (CMS), such as Experian Idworks, are of iffy value. Far better to freeze your credit with as many credit reporting agencies as you can find (there are 3 big ones and at least 3 small ones). Someone told me they were being monitored by three Credit Monitoring Services when they opened a new credit card, and it took over a month, until the CMS companies notified him about the new card.
Verizon ad targeting is now called Custom Experience Plus, it used to be called Verizon Selects. See Verizon Custom Experience programs FAQs from Verizon. To opt out on their website, go to Privacy preferences page and look for the Custom Experience and Custom Experience Plus sections. To opt out in the My Verizon app, go to "Edit Profile and Settings" -> Preferences -> Manage Privacy Settings. (as of Aug 2022)
Verizon Wireless customers can review their marketing settings at vzw.com/myprivacy or by calling 800-333-9956. I suspect that most people will not want
their CPNI shared with Verizon "affiliates and agents".
December 2021: Verizon had a program called "Verizon Selects" where they spied on their customers. It has been renamed "Verizon Custom Experience" seemingly to let them spy on everyone who opted out of the first program. Details on how to opt out here: Verizon overrides users' opt-out preferences in push to collect browsing history by Jon Brodkin of Ars Technica. The best solution is to use a VPN which blocks Verizon from seeing anything.
AT&T calls their ad targeting "relevant advertising" and "enhanced relevant advertising". You control this on their website at the cmpchoice page which has a section for both the regular and enhanced "relevant advertising". While on the page, also look for
the "Third Party Services" section where you can stop some data sharing. Finally, review the "External Marketing and Analytics Reports" section too. Here is a
screen shot of the relevant section of the AT&T website. (Verified Aug 2022)
To opt out of T-Mobile’s ad business, in their app: More -> Advertising & Analytics -> turn off "Use My Data To Make Ads More Relevant To Me". To opt out on their website: My Account -> Profile -> Privacy and Notifications -> Advertising and Analytics -> turn off "Use My Data To Make Ads More Relevant To Me." (As of August 2022)
T-Mobile: How to opt out of T-Mobile's creepy ad tracking campaign by Jason Cipriani for ZDnet. July 2022. The T-Mobile App Insights program collects information about the apps installed on a phone, how often they are used, the Wi-Fi networks the phone connects to and a web browsing history. You have to install a Magenta app on each device. Recommended even for non-customers of T-Mobile.
T-Mobile's 5G Home Internet: I tried it, and it tried me
by Mitchell Clark for The Verge (Dec 2021). The reporter found that the service was not sufficiently reliable. The provided router (made by Nokia Solutions & Networks) almost always had a weak cellular signal. The app showed two bars of service, but this was not reliable as it showed two bars even during service outages. The setup instructions were poor. That said, "The thing about cellular internet, though, is that my experience won’t necessarily be the same as yours, even if you live a few blocks away from me."
Public Wi-Fi is always dangerous, whether a password is required or not.
If possible, keep your main/regular computing devices away from public networks. A Chromebook is a great substitute.
Even with all the protection in the world, like that described below, there are some things best avoided on any public network.
Wi-Fi networks are like children, the people who create it can give it any name at all. Bad guys can create wireless networks with the same
name (SSID) as a legitimate network. The official term for this is an Evil Twin network. Non techies can not distinguish an Evil Twin from the legit network it is
pretending to be. Neither can a computer/phone/tablet, which will happily connect to the evil twin network. Techies might look at the MAC address of a
wireless network, but even that can be spoofed if the bad guy knows how.
Typically, we focus on the fact that public Wi-Fi networks provide Internet access. This, however, ignores the other thing they provide, DNS. DNS is the system
that translates a website name (cnn.com) into an IP address. Malicious DNS can send you to scam copies of websites or all sorts of malicious websites. The fake
CNN site says you need to download software and bingo, your computer is hacked. Eating food found in the street is as safe as using DNS from strangers. More on
DNS and links to check the DNS servers currently in effect, see my RouterSecurity.org site.
In the old days, the fear with public Wi-Fi was limited to people intercepting plain text HTTP. Most websites now use HTTPS which encrypts data in transit.
However, HTTPS is both flawed and complicated and should not be your sole defense. The Qualys SSL Server Test
is an excellent site for illustrating both the complexity of HTTPS and that many websites do it poorly. Also, you can not tell if a mobile app is using HTTPS or not.
The solution to Evil Twin, DNS and HTTPS problems is to use either a VPN or Tor. Both hide your Internet activity from the router creating the public network and the ISP providing it Internet access. For more on VPNs, see the
VPN topic here. To insure they are working, check your Public IP address before and after connecting. Also, check your DNS
servers before and after. A VPN should provide its own DNS servers, check with your VPN company to learn what their policy is. Many provide DNS on the VPN server itself which is especially easy to validate.
If a VPN or Tor is too much for you, then on mobile devices, use the Cloudflare 126.96.36.199 app available on Android
and iOS. Originally, it only provided DNS, now it can also, optionally, provide
Another danger with public networks (both wired and wireless) is on the LAN side. Your computing device can be attacked by other users of the same network. Local bad guys might attack open TCP/IP ports on your device or take advantage of bugs in the operating system. I blogged about this in August 2021: Hiding on a Wi-Fi network. Some VPN software offers a defense against this, a feature that will block LAN side access while the VPN is connected. Bad guys can not attack a computer they can't see. In my experience, however, this is a very rare feature.
Disable Wi-Fi when you are not using it. It is not sufficient to simply disconnect from a public network.
Many Wi-Fi devices will automatically re-join a network (SSID) they have seen before. To prevent this, after using a public Wi-Fi network, tell the operating system to Forget about it. - iOS instructions are in the iOS topic. -
Windows 10: System Settings -> WiFi Settings -> Manage known networks -> click on an SSID, then the gray Forget button. -
macOS: Wi-Fi symbol -> Network Preferences -> Advanced -> Preferred Networks -> Click on an SSID -> click the minus sign -> OK -
Android systems vary, search in the Settings for "Saved networks"
One way to avoid public Wi-Fi is to use the 4G/LTE data connection on a smartphone. With the hotspot feature, this data connection can be shared with a laptop. To do this, the phone creates a Wi-Fi network that the laptop connects to. One, or both, of the devices should be connected to a VPN.
A public Wi-Fi network will always learn the MAC address of the Wi-Fi adapter in your computing device, even when using a VPN. To prevent this being tracked, you need to modify the MAC address (see Networking topic) before enabling Wi-Fi. To be really anonymous, use a computing device that was purchased with cash.
If you often use a public network, then consider a privacy screen protector. This limits the field of view for the screen to hopefully block someone sitting nearby from seeing what you are doing. 3M sells privacy screens for laptops, tablets and phones. Both Dell and Lenovo sell them for their laptops. See Laptop Privacy Filters: What to Look For and Why You Need One b Brett Nuckles (June 2018)
Router: I have a whole website devoted to Router Security. At the least, try to make the eight router configuration changes in the short list on the home page.
When it comes to making router changes, the first step, logging into the router, is likely to be the hardest. To make this easier, I suggest writing down the necessary info (router IP address or vendor-supplied name, router userid, router password) on a piece of paper and taping it to the router face down. Maybe include Wi-Fi passwords on the paper too.
Networking equipment (router or combination modem/router) provided by Internet Service Providers is typically insecure and low quality. Anything you buy at retail is likely to be more secure. It may also be cheaper in the long run and makes you a lesser target (a million people are not using the same router model).
Ethernet is more secure than Wi-Fi, so whenever possible connect via Ethernet for sensitive work. It's also faster. USB to Ethernet adapters cost about $15.
Use a Guest Wi-Fi network both for visiting humans and for IoT devices. Better yet, if your router supports it, use VLANs to further segregate devices (requires a techie). More here.
At this point, it is common knowledge that Wi-Fi encryption should use WPA2 rather than the ancient WPA or WEP. If given a choice, WPA2 AES is more secure than WPA2 TKIP. Note that a long Wi-Fi password can prevent a brute force guessing attack; passwords should be 14 characters or longer. More here.
All of the smart assistants (from Amazon, Google and Apple) sometimes record at the wrong time. That is, they record without a person having said the wake word. And, since
all three companies send some recordings to contractors, to help improve the system, strangers may hear your embarrassing conversations. Tony Soprano would not have allowed Siri in his home.
Google lets you access your history, delete past recordings and automatically delete your data every couple of months. Amazon lets you manually delete past recordings and disable human review of
Alexa recordings. Initially, Apple lost at this privacy game, they did not have any way to opt out. In early Aug 2019 they took their first step and did more in iOS 13.2.
Disaster: Alexa and Google Home abused to eavesdrop and phish passwords by Dan Goodin October 2019. Everyone's worst fear came true. Malicious apps were developed that listened all the time. Wake word? We don't need no [expletive] wake word. Germany's Security Research Labs developed the apps and they passed the Amazon and Google security-vetting process. Some of the apps logged all conversations within earshot of the device and sent a copy to the app developer. Others mimicked the voice used by Alexa and Google Home to falsely claim a device update was available and prompted the victim user for a password to enable the update. Yikes. More: Malicious Apps on Alexa or Google Home Can Spy or Steal Passwords by Ionut Ilascu Oct. 2019.
Another privacy issue with Alexa is that the devices phone home to Amazon and to others, even when they are not being used. No one knows why.
Article: Alexa has been eavesdropping on you this whole time by Geoffrey Fowler May 2019. Amazon keeps a copy of everything Alexa records after it hears the wake word. Fowler listened to 4 years of his recordings and found that dozens of times it recorded when it should not. It even picked up some sensitive conversations. There are instructions for deleting these recordings via the Alexa app. Hear your archive at www.amazon.com/alexaprivacy.
Also from Fowler: Amazon collects data about third-party devices even when you do not use Alexa to operate them. For example, Sonos keeps track of what albums, playlists or stations you listen to and shares that information with Amazon. You can tell Amazon to delete everything it has learned about your home, but you can not look at this data or stop Amazon from continuing to collect it.
Amazon has policies for skills published in the Alexa Skills Store. But, they are not enforced. In an academic study that lasted a full year, researchers created 234 skills that all violated a policy.
They all got approved. From Academics smuggle 234 policy-violating skills on the Alexa
Skills Store by Catalin Cimpanu for ZDNet (July 2020). They also identified 52 problematic skills already available on the Alexa store, all targeted at children.
Alex initial configuration: the app wants to "periodically upload your contacts" - say Later (there is no NO). The app also wants to verify your phone number when first configured, there is no need for this, skip it.
Alexa Defenses in the Settings of the Alexa app:
Amazon Sidewalk started rolling out in Nov. 2020. It is on by default. To turn if off from the Alexa app: -> More tab (at the bottom) -> Settings -> Account Settings -> Amazon Sidewalk. Toggle off the Enabled button
Turn off voice purchasing: Menu -> Settings -> Alexa Account -> Voice Purchasing. If you want to use Voice Purchasing then perhaps disable one-click payments. Or, set a spoken pin to stop anyone else from shopping using your account.
Settings -> Alexa Privacy -> "Manage How Your Data Improves Alexa". This may have changed to "Manage Your Alexa Data". There are two options to prevent humans from
listening to your recordings.
Settings -> Alexa Privacy -> Review Voice History. Enable the deletion by voice option. Then delete saved recordings. After enabling this option, you can say "Alexa, delete everything I said today" or "Delete what I just said"
Settings -> Alexa Privacy -> Manage Skill Permissions. Control which, if any, skills should have access to your name, your location, your street address, etc.
Notifications -> Amazon shopping. Turn off "Receive personalized recommendations and deals based on your shopping activity." if you don't want Alexa to nag you to buy stuff. Maybe also disable "requests to rate products you’ve purchased" and "Order Updates (Inc. Subscribe & Save)"
APPLE (Siri, Apple Watch and HomePod smart speakers)
If an Apple Watch detects it has been raised and then hears speech, Siri is activated. To prevent this, disable the Siri side button on the iPhone: Settings -> Siri & Search -> toggle off "Press Side Button for Siri".
Defense as of mid-Aug 2019: If both Siri and dictation are disabled, Apple will delete your data and recent voice recordings. To disable Siri: Settings > Siri & Search -> Turn off both the Listen and Press Button options. To disable dictations: Settings -> General -> Keyboard -> turn off Enable Dictation.
This process will change.
Defense added in iOS 13.2: When upgrading to 13.2, which was released at the end of Oct. 2019, users see a pop-up message offering the ability to opt-out of having their voice commands stored and saved. It is called "allowing Apple to store and review audio of your Siri and Dictation interactions". Later, this can be adjusted in the Privacy settings under "Analytics & Improvements" where there are multiple options about sharing Analytics as well as the option to "Delete Siri & Dictation History" and an option to stop sharing voice recording with Apple. Also in Settings -> Siri, you can tell Apple to delete all the Siri voice recordings that it has stored.
Again from Fowler article: Google used to record conversations with its Assistant ("Hey Google") but in 2018, they stopped doing so by default on new setups. You can check the settings of your Assistant at myaccount.google.com /activitycontrols/audio. Look to Pause recordings. This How-ToGeek article adds instructions for deleting the previously saved recordings.
The Nest thermostat, made by Google, phones home every 15 minutes, reporting the climate in the home and whether there is anyone moving around. The data is saved forever. (also from the Fowler article)
Google Defense: in the Google Home app: Account -> More settings (under Google Assistant) -> Your data in the Assistant -> turn off Voice & Audio Activity. While there, also go to Manage Activity to review and/or delete voice recordings.
To delete Google Assistant voice recordings, start at myaccount.google.com /intro/activitycontrols. Scroll to "Voice & Audio Activity" where Paused means disabled. Or, you can use these voice commands: "Hey Google, delete what I just said" or "Delete what I said on [date]" or "Delete my last conversation". This only works for the last 7 days.
You can use the Voice Match function to insure your personal results are only available to you. See how.
MICROSOFT: SKYPE, CORTANA and XBOX
In Aug. 2019, Joseph Cox of Motherboard revealed that"Contractors working for Microsoft are listening to personal conversations of Skype users conducted through the app’s translation service ... [and] ... Microsoft contractors are also listening to voice commands that users speak to Cortana, the company's voice assistant." Shortly thereafter, Cox revealed that Microsoft Contractors Listened to Xbox Owners in Their Homes. As with all the other companies, recordings were sometimes triggered by mistake. At the Microsoft Account Privacy Settings page you can delete any recordings Microsoft has of you.
General Defense: I own a smart speaker and it is powered off 99% of the time. When I want to use it, I plug it in and wait 30 seconds for it to start up.
There are four approaches here, and I am the very rare person suggesting the fourth one.
The first approach is to play whack-a-mole; to configure access to location data on an app-by-app basis. This strikes me as ridiculous.
Android 9: Settings -> Biometrics and security -> App permissions -> Location -> configure each app.
Android 10: Settings -> Location -> App permission and configure each app.
Android 12: Settings -> Location. If Use Location is off, turn it on. You then see the apps with Location permission and those that have recently used it. When done with your review, turn Use Location back off (if desired).
From Google: Choose which apps use your Android device's location.
New permission in Android 10: only let an app know your location when the app is open. Also new, periodic reminders about apps that are accessing your location in the background. Configure: Settings -> Apps and Notifications -> pick an app -> Permissions and Location. Or, Settings -> Privacy -> Permission manager -> Location ->
click an app. If upgrade from v9 to v10, all existing apps need to be checked.
iOS: see the iOS topic for more on Location Tracking
iOS13: Settings -> Privacy -> Location Services and then choose, for each app, when it can access your location. While there, also configure "Share My Location" as you prefer. And, still more: configure each of the 13 System Services and the 4 Product Improvement services - whether they can access your location.
iOS 13 added a new Location permission: share your location with an app just once. The next time the app wants it, it has to ask. iOS 12 only allowed sharing always, never or when the app was in use. iOS 13 also added periodic pop-ups when apps use your location in the background. A sort of FYI.
iOS 13 Location: iOS 12 let you grant an app permission to track your location all the time when the app was installed. iOS 13 limits install-time location permissions to while the app is in use. To let an app track your location at all times, you have to go into the System Settings. iOS 13 treats this as a bad thing a periodically warns you about how often your location was used and lets you disable it. Sound good? But Apple does not warn customers about their own location tracking. By default, iOS users agree to 18 separate location-tracking system services during setup, including Apple's own location-based advertisements. Apple can add new features that utilize location tracking without asking for permission. From here: Apple says recent changes to operating system improve user privacy, but some lawmakers see them as an effort to edge out its rivals by Reed Albergotti in WaPo (Nov 2019).
For iOS version 12, do Settings -> Privacy -> Location Services to see a list of apps. Each app is assigned one of three rules: never see your location, always see your location or only see it while using the app. Also here is a link to System Services and their location usage.
Does a weather app really need your current location? Maybe just give it a couple zip codes where you often are instead, and only give it access to your current location when traveling.
A second approach, is to still let the phone know where you are now, but tell Google not keep a history of where you have been.
Disable Location History: Location history is a Google account thing, not an Android thing. At least with Android 12, there is no system setting for this. It is controlled at
myaccount.google.com/ activitycontrols/location. More from Google: Manage your Location
This April 2019 article says to go to myactivity.google.com, select "Activity Controls" and turn off both "Web & App Activity" and "Location History" While there, also turn off YouTube History and configure it
to auto-delete activity older than three months. This May 2019
article by David Nield in Wired covers all the bases both for a Google account and on a mobile device.
Keep a Location History but Automatically Delete it after a while: Start at myactivity.google.com, click on Activity controls, scroll to Location history, click Manage Activity, look for an icon shaped like a nut and then click Automatically delete location history. Whew.
First find the Location section of system Settings (see the 3rd approach below). Then click on Google Location History to pause it (it can not be disabled, only paused). On Android 10, Location History is buried under "Advanced"). Note: this is done for a Google account, not for a device, thus you must be on-line to make changes. You may also want to click on Show All Activity Controls to see the Web and App Activity and pause that too. From Google: Manage your Android device's location settings. The article states that, with Location disabled, you can still get local search results and ads based on your public IP address. You can test this with a VPN.
A third approach is to disable Location Services entirely. On Android, the "Use Location" option is the master on/off switch for Location services. Here are some paths to find it.
Android 7 and 10 and 12: Settings -> Location
Android 9: Settings -> Biometrics and security -> Location
Android 8 and 9: Settings -> Security and Location -> Location
On iOS13 there is only one path: Settings -> Privacy -> Location Services -> Turn Location Services OFF
My advice, the fourth approach, is to prevent iOS and Android from knowing your location in the first place. To do this:
Turn off 4G/LTE Internet
Turn off Wi-Fi
Turn off Bluetooth
Turn off GPS by disabling "Location" (Android) or "Location Services" (iOS)
With these four things disabled, a phone can still make/receive calls and text messages. A dedicated GPS app can be used to confirm the status of GPS. Note that your location can still be tracked by the cell tower the phone is talking to, but, this only provides a general idea of where you are rather than a precise location. The next step would be to enable airplane mode, and the step after that, is to turn the phone off.
For ages, I was the only person suggesting this. Then, some allies showed up:
In Dec. 2019, Proton (the company behind ProtonMail and ProtonVPN) said that a basic principle of using any smartphone is "...turn off all the connectivity you do not need. This goes for whatever smartphone, and whichever operating system, you have."
Note that even with Bluetooth and Wi-Fi disabled, an Android device may still use either or both to determine your location. For more, see the topic on Mobile Scanning and Sharing.
Taking a step back, consider who is the enemy here? That is, who is it we don't want tracking us. Some people/articles focus on apps. But, it also the Operating System vendors, Apple and Google, that learn our location. And, of course, the cell phone companies, who are being being sued for selling location data. Another reason for my approach to defense.
When possible, tell Android to share an approximate location rather than the precise location with apps
Cameras: On many computing devices the camera may embed the current location of the device in a photograph. I am no expert on disabling this in every operating system, so ... when you are away from home and posting photos on social media, people can tell you are away from home. If you are far, it is an invitation to rob your home. If you post photos taken at home, people can learn where you live. Spend the time to learn how to stop the camera from doing this.
On iOS 13, I am pretty sure this can not be disabled but if you use the OS to share a photo there is an option to remove the location information. If you copy the photo on iOS 13 the location information is included. IrfanView on Windows reveals all the hidden information in pictures.
It's bad. Real bad. The only real defense is a VPN that blocks trackers, and for good luck, ads too. Also see the Location Tracking topic.
Android Defense: Turn off Ad Personalization and periodically reset the Android advertising ID. On Android 7, 8, 9, 10, and 12 both options are at: Settings -> Google -> Ads. On Android 12 you can go further and delete the Advertising ID at: Settings -> Privacy -> Ads -> Delete advertising ID.
Android Defense: At Settings -> Google. Google Account is the master list of everything Google. In Networking, maybe disable the Wi-Fi assistant. Check Nearby to see if any apps are sharing data. In Search, Assistant & Voice: Under General, look at Recent pages, Discover and Personal results. Under Voice, consider not allowing Bluetooth requests with the device locked (may be called Bluetooth headset). Also review Google Assistant.
Things are bad: Android, iOS beam telemetry to Google, Apple even when you tell them not to – study by
Thomas Claburn for The Register (April 2021). According to an academic study, Android and iOS phones transmit telemetry back to Google and Apple, even when users have chosen not to send analytics data. iPhones even rat out your LAN buddies when using Wi-Fi. They phone home the MAC addresses of other devices on a LAN. Yikes. Apple said nothing when pressed for comment. The defense is to use VLANs.
Things are bad: iPhone Privacy Is Broken…and Apps Are to Blame by Joanna Stern in the Wall Street Journal (May 2019). Most apps are tracking you in ways you cannot avoid. Privacy controls are a scam. Interesting tidbit: paid apps spied the same as their free siblings. Defense: Privacy Pro SmartVPN from Disconnect.
Things are bad: In a tweet thread Robert G. Reeve explains how, after spending a week with his mother, he is seeing ads for her brand of toothpaste. (May 2021)
iOS Defense: The above two articles both suggested partial defenses: Disable "Background App Refresh" (Settings -> General) and Enable "Limit Ad Tracking" (Settings -> Privacy -> Advertising). While there, I would also suggest clicking on Reset Advertising Identifier.
iOS Defenses: From 7 iPhone privacy settings you should enable now (Jack Morse June 2019). Review apps that have Camera (Settings -> Privacy -> Camera) and Microphone (Settings -> Privacy -> Microphone) access. Maybe turn Live Photos off. Turn off lock screen message previews (Settings -> Notifications -> Messages -> Show Previews). Reset your Advertising Identifier (Settings -> Privacy -> Advertising). Use a long (up to 9 digits) voicemail password (Settings -> Phone -> Change Voicemail Password).
Stop Apple from spying on you. Details are in the iOS topic. As of iOS14: Settings -> Privacy -> Analytics & Improvements. While there, take a look at the Analytics Data.
Things are bad: Perhaps the most damning article: I spy: How Android phones keep tabs on our every move (March 2019) is about the security hole that are the pre-installed Android apps. Based on an academic study that analyzed 1,742 phones from 214 manufacturers. 91% of the pre-installed apps are not in the Google Play store. No defense offered.
Defense: Some VPNs can block tracking and/or ads. For more, see the VPN topic.
iOS Defense: What should be a great defense against apps and web pages that track iOS users is the Guardian Mobile Firewall from Sudo Security. I say "should" because the app is new, it was released Aug. 1, 2019. Terminology, however, is being abused. It is not a firewall. It is a VPN that does tracker blocking. The VPN part is free, tracker blocking is $100/year or $10/month. It does not block ads and it does not offer a whitelist or blacklist that you can manually update. Everything points to the people behind the app being trustworthy. Read more from Glenn Fleishman (March 2019) Lily Hay Newman (July 2019) and Sudo Security (June 2019) and me (August 2019).
Things are bad on Android: Thousands of Android Apps Break Google's Privacy Rules by Paul Wagenseil Feb. 2019. Researchers examined 24,000 Android apps and found that 70 percent were breaking the rules by sending out permanent IDs that ad networks can use to track you. The researchers notified Google of the policy violations and got no response.
More bad on Android: TikTok Tracked User Data Using Tactic Banned by Google from The Wall Street Journal (Aug 2020). The article is about TikTok but that one app is not important. What is important, is that the app was able to learn the MAC address of an Android device even though Google had tried to prevent apps from doing so. Google's first attempt at blocking access to the MAC address was not foolproof and when told about this, Google did nothing to improve their blocking.
My Defense: Use a phone and a tablet. Let most of the spying happen on the tablet, keeping the phone relatively clean. Each should use a different account be it an Apple or Google Apple account. The tablet account should use a throw-away email address. The phone should, as much as possible, be limited to apps needed while traveling. The tablet can have everything. For example, I will not install the MLB (baseball) app on my phone as it wants way too many permissions.
Both Android and iOS want you to keep Wi-Fi and Bluetooth enabled for a number of reasons. Android may well use them both even if they appear to be disabled. And, if they really are disabled, each Operating System has a number of ways to automatically turn them back on. I suggest checking an Android device by searching the Settings for the words "scan" and "scanning". Plus, there are many other options for sharing data, that you might want to disable, at least as a starting point, to reduce your attack surface.
IOS CONTROL CENTER SCAM
iOS 11 and 12 have two ways to disable Wi-Fi and Bluetooth. One works, the other is a scam. The Control Center, which is what you see when swiping up from the bottom of the screen is the scam. The Settings app is the real deal. That is, when you disable these in Settings they are really disabled and stay that way until you re-enable them.
In September 2017, Lorenzo Franceschi-Bicchierai wrote about this: Turning Off Wi-Fi and Bluetooth in iOS 11's Control Center Doesn’t Actually Turn Off Wi-Fi or Bluetooth. Quoting: "Apple wants the iPhone to be able to continue using AirDrop, AirPlay, Apple Pencil, Apple Watch, Location Services, and other features, according to the documentation". As of iOS 12, the Wi-Fi message is "Disconnecting nearby Wi-Fi until tomorrow." When tomorrow? Doesn't say (its 5 AM local time). And, "nearby"? There is no such thing a near and far Wi-Fi.
Noted hacker Samy Kamkar tweeted on May 19, 2019: "This is so deceptive. When you 'disable' WiFi and Bluetooth in iOS Control Center and they gray out, they're technically still enabled. Even with Airplane Mode on, your device continues to transmit and your name can even be discovered nearby via AirDrop!". He later added "It's deceptive because it remains active after saying 'Disconnected until tomorrow'. Only the 'normal' Bluetooth functionality returns the following day, the phone itself keeps transmitting privacy-evading, identifiable BLE packets.".
ULTRA WIDE BAND (UWB)
Intro: While Wi-Fi and Bluetooth were designed to transfer data, UWB lets devices locate themselves in three dimensions. UWB radios are in newer (as of Jan. 2022) Android phones from Google, Samsung and others. On the Apple, side, it was introduced with the iPhone 11 (2019) and Apple watch Series 6 (2020). Perhaps the biggest use of UWB so far, is in Apple AirTags and AirDrop.
Pixel 6 Pro: The Pixel 6 Pro now lets you disable a wireless tech you hardly need by Jay Bonggolto (Jan 2022). Starting Dec. 2021, you can turn UWB on and off if you have a Pixel 6 Pro. Other phones? It does not say. UWB is used by Nearby Share and a digital car key feature. The article does not say if this applies to Android 11 or 12 or both. Settings -> Connected Devices -> Connection preferences. And how nice of Google to add a feature that could not be turned off.
iPhone 11: From What Is Ultra Wideband, and Why Is It In the iPhone 11? by Chris Hoffman Sept. 2019. iOS 13.1 on the iPhone 11 has a new Ultra Wideband radio. It is the first smartphone to offer UWB which only works over a short distance, shorter than Bluetooth. UWB allows an iPhone to precisely detect where objects are in physical space. AirDrop will suggest sharing with other iPhones that you point at. Longer term, it could be used to locate lost objects. Can you turn it off? Don't know.
ANDROID SCAN EVEN WITH BLUETOOTH OFF
Android 9: Settings -> Security and Location -> Location -> Advanced -> Scanning -> Bluetooth scanning. Description: "Allow apps and services to scan for nearby devices at any time, even when Bluetooth is off. This can be used, for example, to improve location-based features and services.".
Android 8.1: Settings -> Connections -> Location -> Improve accuracy -> Bluetooth scanning. Description: "Improve location accuracy by allowing apps and services to scan for and connect to nearby devices automatically via Bluetooth, even while Bluetooth is turned off."
Android 8.1: Settings -> Security and Location -> Location -> Scanning -> Bluetooth scanning. Description: "Improve location by allowing system apps and services to detect Bluetooth devices at any time."
Android 7.0: Settings -> Location -> Scanning -> Bluetooth scanning. Pretty much same description.
Nearby Device Scanning: I have seen an Android 8.1 Samsung tablet use Bluetooth scanning to find nearby devices, again, with Bluetooth seemingly disabled. The feature was called Nearby Device Scanning and it was enabled by default. The description said "Scan for and connect to nearby devices easily. Available devices will appear in a pop-up or on the notification panel. Nearby device scanning uses Bluetooth Low Energy scanning and the microphone. Bluetooth Low Energy scanning can be used even while Bluetooth is turned off on this device." The path to the setting was: Settings -> Connections -> More connection settings -> Nearby device scanning.
ANDROID SCAN EVEN WITH WIFI OFF
Android 12: Search settings for "Wifi scanning". Text says "Allow apps and services to scan for Wi-Fi networks at any time, even when Wi-Fi is off. This can be used, for example, to improve location-based features and services". See a screen shot of the setting and a warning about it from Android itself. Warning: turning off this option does not stick. That is, when you do something (I don't know what) it turns itself back on and Android is again scanning WiFi networks when Wi-Fi seems to be off, but is not.
Android 9: Settings -> Security and Location -> Location -> Advanced -> Scanning -> Wi-Fi scanning. Description: "Allow apps and services to scan for Wi-Fi networks at any time, even when Wi-Fi is off. This can be used, for example, to improve location-based features and services."
Android 8.1 Samsung: Settings -> Connections -> Location -> Improve accuracy -> Wi-Fi scanning. Description: "Improve location accuracy by allowing apps and services to scan for Wi-Fi networks automatically, even while Wi-Fi is turned off."
Android 7.0: Settings -> Location -> Scanning -> Wi-Fi scanning. Pretty much same description.
Android 6 in the Advanced WLAN section, look for Scanning Always available. Description: "Let Google's location service and other apps scan for networks even when WLAN is off."
Android 9: Network and Internet -> Wi-Fi -> Wi-Fi preferences -> Turn on Wi-Fi automatically. Description: "Wi-Fi will turn back on near high quality saved networks, like your home network." This requires both Location and Wi-Fi scanning to be enabled.
Android 8.1: Settings -> Connections -> Wi-Fi -> Advanced -> Turn of Wi-Fi automatically. Description: "Turn on Wi-Fi in places where you use Wi-Fi frequently".
ANDROID WIFI AND OPEN NETWORKS
Google wants you on-line even if it means using an insecure Open Wi-Fi network. To that end, Android might automatically connect to an open network, or, notify you when it finds one. See Connect automatically to open Wi-Fi networks.
Samsung v9 tablet: Settings -> Connections -> Wi-Fi -> Advanced -> turn off Network notification ("Receive notifications when open networks in range are detected").
Google v9 Pixel phone: Settings -> Network and Internet -> Wi-Fi -> Wi-Fi preferences -> disable Open network notification ("when automatic connection isn't available"). There may also be an option here to Connect to open networks.
Android v8: Settings -> Network & Internet -> Wi-Fi -> Wi-Fi preferences -> Open network notification
This 2017 article does not say what version of Android it applies to. At Settings -> Wireless -> Gear icon -> are two relevant optons: Network Notification and Use open Wi-Fi automatically. Disable each.
ANDROID WIFI AUTO-CONNECT
Android 8.1 AT&T phone: Settings -> Connections -> Wi-Fi -> Advanced -> Auto connect to AT&T Wi-Fi.
Android 8.1 AT&T phone: Settings -> Connections -> Wi-Fi -> Advanced -> Hotspot 2.0. Description: "Automatically connect to Wi-fi access points that support Hotspot 2.0"
NFC (Near Field Communication) is yet another wireless option for sharing data, but only between devices that are two inches apart.
On Android, search the Settings for "NFC". On Android 9, its at: Settings -> Connected devices -> Connection preferences -> NFC. The description is "When this feature is turned on, you can beam app content to another NFC-capable device by holding the devices close together. For example, you can beam web pages, YouTube videos, contacts and more. Just bring the devices together (typically back to back) and then tap your screen. The app determines what gets beamed." NFC is the basis for Android Beam (aka NFC Beaming), yet another sharing protocol. Not every Android phone supports NFC. Another reason to disable NFC: Android bug lets hackers plant malware via NFC beaming by Catalin Cimpanu (Nov. 2019). An excellent article. Android 8, 9 and 10 are impacted. The bug was fixed in October 2019 but so few Android devices will get the fix. If NFC is needed, you can leave it enabled, just be sure to disable NFC file beaming as explained in the article.
On iOS, NFC is used for Apple Pay and reading NFC tags. iOS 12 added background tag reading, where the system automatically looks for nearby tags whenever the screen is illuminated. In Settings, tap "Wireless and Networks" then "More" to see the NFC option. More here and here. This June 2019 article, Apple Expands NFC on iPhone in iOS 13, says there are enhancements to Apple Pay for NFC in iOS 13 and new support for peer-to-peer pairing. That is, just like Android Beam, NFC can be used to transfer movies or music between devices.
Wi-Fi Direct allows two Wi-Fi devices to directly communicate without a router in the middle.
It is popular on HP printers and some smart TVs as I always see some of each, when scanning from an Android device. HP printers create SSIDs like "DIRECT-xx-HP OfficeJet 4650" Sony TVs create SSIDs like "Direct-xx-BRAVIA". Wi-Fi Direct is also enabled on Roku Express devices. Background: What is Wi-Fi Direct? (June 2019).
Android: I have checked a few Android devices and they all enable Wi-Fi direct without a way to disable it. It seems, however, that Wi-Fi direct scanning does not happen until you ask for it.
Android 9: Settings -> Network and Internet -> Wi-Fi -> Wi-Fi preferences -> Advanced -> Wi-Fi Direct
Android 8.1: Settings -> Connections -> Wi-Fi -> Wi-Fi Direct
Android 8.1: Settings -> Network and Internet -> WLAN -> WLAN Preferences -> Advanced -> WLAN Direct
Android 7.0: Settings -> Wi-Fi -> Advanced -> Wi-Fi Direct
October 24, 2019: Wi-Fi Direct just became a very big
deal. A bug in the Wi-Fi Direct driver from Realtek (RTLWIFI) lets bad guys crash or hack a Linux/Android device that has Wi-Fi enabled; even if the device is not connected to any Wi-Fi network. The bug is specific to Wi-Fi Direct but since Android users can not disable Wi-Fi Direct, Android devices are vulnerable whenever Wi-Fi is enabled. Many Android devices will never be patched.
iOS: iOS has supported Wi-Fi Direct since version 7. It is part of AirDrop, Airplay and AirPrint.
iOS 12: There are no settings for Wi-Fi Direct. When I scanned for nearby Wi-Fi networks, none of the Wi-Fi Direct networks that I could see from Android showed up. When I tried to print a web page, Safari found no AirPrint enabled printers. Perhaps because of the way my iOS device was configured? Don't know.
AirDrop on iOS is used for easily sharing files between iOS devices. It is configured at: Settings -> General -> AirDrop. The safest option is to disable it ("Receiving Off"). The most dangerous option is enable anyone in the world to send you files ("Everyone"). The third option only lets people in your Contacts send you files via AirDrop ("Contacts Only"). I suggest leaving it off and only enabling it when needed. In July 2021 an airplane was delayed for hours when a teenager used AirDrop to send passengers a picture of a gun.
AirDrop uses both Bluetooth and Wi-Fi. Bluetooth is used to find sharing partners and Wi-Fi, because it's faster, is used to transfer large files. The Wi-Fi is a form of Wi-Fi Direct, thus the two Apple devices do not have to be on the same Wi-Fi network to exchange data. In fact, they don't have to be connected to any Wi-Fi network or to the Internet. See a
How To. WARNING: With Wi-Fi and Bluetooth off, if you enable AirDrop, it turns on both of them without notification. See The feature Apple needs to change in AirDrop (April 2019) and When Grown-Ups Get Caught in Teens' AirDrop Crossfire (June 2019).
Bluetooth on iOS: It was previously known that Bluetooth allowed anyone nearby to learn the current status of the device, device name, Wi-Fi status, iOS version and more. In July 2019 it was revealed that Bluetooth can leak the phone number when using AirDrop or sharing Wi-Fi passwords. The leaking of phone numbers has been observed in iOS 10, 11, 12 and the beta of 13. You can disable AirDrop but have to remember not to share Wi-Fi passwords. More here and here and here.
One of the Privacy Settings in iOS v12 is Bluetooth Sharing. Apps that are enabled for Bluetooth Sharing can share data even when you are not using them.
Android Direct Share: Description: "Share content with specific people directly from the sharing panel in any app. The Direct Share icons will appear at the top of the sharing panel if an app supports this function." Find it on Android 8.1 with: Settings -> Advanced Features. Not sure if this uses Bluetooth, Wi-Fi or what.
iOS 13: has a new "Find My" feature. When an Apple device is offline and sleeping, it sends out a secure (says Apple) Bluetooth beacon that can be detected by any nearby Apple device. These nearby devices (even those that are not yours) phone home to Apple to help you find a lost device. I have read that the Bluetooth beacons are even sent in Airplane mode. Not sure yet how to defend against this (turn off Bluetooth?) or if we even need to defend against it. Too new as of June 8, 2019.
There have been many bugs and data leaks involving Bluetooth, so its best to turn on it when needed, then turn it off when done. Be aware though, as I describe here in the
Mobile Scanning and Sharing section, that both iOS and Android may not turn off Bluetooth when you think its off. Another reason to have it off:
If you leave a laptop, tablet or phone in a car, bad guys can scan for cars with Bluetooth devices in them as per: Thieves Are Using Bluetooth to Target Vehicle Break-Ins by Wes Siler (Dec 2019).
Bluetooth devices have names and the names may identify the device which is not a good thing to do in public. Give your Bluetooth devices names that do not identify them or you to people nearby. how you do this will be different on different devices.
Android 12 on a Pixel phone: Settings -> Connected Devices -> Connection preferences -> Bluetooth -> Device name. Bluetooth must be on to do this.
Android 10 on Pixel phone: same as above
iOS 15.6 on iPad: Settings -> General -> About -> Name
Below are some articles about the many bugs in Bluetooth.
Sept 2020: Billions of devices vulnerable to new 'BLESA' Bluetooth security flaw by
Catalin Cimpanu for ZDNet. The BLESA (Bluetooth Low Energy Spoofing Attack) vulnerability impacts devices running the Bluetooth Low Energy (BLE) protocol. It turns out that the official BLE specification did not contain strong-enough language to describe the reconnection process. When previously connected devices, re-connect, they are supposed to re-authenticate but the re-authentication was optional, not mandatory. Many devices, such as Android and IoT will never be patched. iOS and Windows devices are not vulnerable.
Sept 2020: Bluetooth Unveils Its Latest Security Issue, With No Security Solution by Shoshana Wodinsky in Gizmodo. The bug is called BLURtooth and there is no patch. When a mobile device links to a Bluetooth-powered device, such as speakers, the connection can be hijacked to give an attacker access to any bluetooth-powered app or service on the phone.
The most secure Operating Systems in widespread use are iOS and ChromeOS (the system on Chromebooks).
Do not use Windows. Windows is a cesspool of hacking, ransomware, bugs and vulnerabilities. Has been for decades. With Windows 8 Microsoft lost all credibility. With Windows 10 Microsoft spies on you and has taken control over the installation of bug fixes. And, the quality of the bug fixes to Windows 10 is disgraceful, sometimes causing more problems than they solve. There is no Windows topic here because the best defense is avoiding it.
Leo Laporte, aka, the Tech Guy is a bona fide techie. For years, he used all three desktop OSs (Windows, macOS, Linux) and now, he also uses Chromebooks. He has always fairly judged the pros and cons of each operating system. But, as of March 2020, he has given up on Windows. Too many bugs, flaws and problems. In discussing a Windows bug on the March 24, 2020 episode of the Security Now podcast he said "I swear to god, I don't run Windows on any machines anymore. It's just ridiculous."
Windows 10 makes it clear that the corporate mind set at Microsoft has changed - they view Windows 10 as their computer, not yours. It is crammed full of junky software that very few people care about, much of which can not be removed. And, even the removal is a scam, as the crapware comes back if you logon with a different userid. Likewise, the spying (aka telemetry, customization) can only be partially disabled. Home edition users are forced to beta test bug fixes and even Professional edition users have limited options for delaying or preventing the installation of bug fixes. Microsoft know whats best for you and its bug fixes all the time. Only the largest of corporations can fully opt out of the spying, junky software and forced "updates" in Windows 10. How? Microsoft has a clean version of Windows 10 called LTSC (or LTSB) that the public can not get. See a screen shot of the difference.
Then too, there is incompetence. Examples abound. Consider the monthly bug fixes for Windows that were released in April 2019. As documented by Woody Leonhard,
nine different Windows patches conflicted with four different antivirus products, leading to multiple problems. Quoting Woody: "...whoever made the decision to release the six (now nine) problematic Windows patches either: Didn't know they'd wreak havoc on millions of computers, or Didn't care. You can choose which one's worse."
If you do use Windows, use portable software when available. A great source is PortableApps.com. Portable software is harder for malware to find and corrupt and, most importantly, can be easily backed up. Normal Windows apps can not be backed up because they, and their dependencies, are scattered all over.
I agree with the commonly held belief that an Apple Mac computer (macOS) is safer than Windows. However, it is slightly safer, not drastically safer. Both are ancient and the world has changed dramatically since they were designed. On the hardware side, Apple fans have been critical of the hardware in their laptops for many years, especially the keyboards. For more, see the macOS topic.
Start using a Chromebook. Chromebooks are laptop computers that are drastically safer than Windows and macOS. Their operating system, ChromeOS, is the newest available system and thus the most advanced. It was designed, by Google, with security in mind. There are no viruses on a Chromebook. In addition to security, Chromebooks are extremely reliable. In what is virtually a revolution in computing, Chromebooks require no care and feeding on your part. They self-update quickly and quietly. They don't ask you or even tell you about bug fixes. The just do it. Thus, end users (you) can not screw them up. Chromebooks are not for everyone and not for every purpose. They are perfect for kids, seniors and non techies. Chromebooks are the home office of Defensive Computing. You normally use a Google account to logon to a Chromebook, but there is also a Guest mode that anyone can use without logging on.
---------ADDITIONAL CHROMEBOOK INFO-----------
Guest mode starts and ends with a totally clean version of ChromeOS. That is, when Guest mode starts, there is no visible history of anything. Factory fresh if you will. When Guest mode ends, all activity is removed. Downloaded files, for example, are deleted. It's as if it never happened. Guest mode uses the Chrome browser, but without extensions. You can't even install an extension in Guest mode. It is the most secure environment available to non techies. It is perfect for online banking, opening suspicious email attachments and avoiding any and all website tracking.
Originally, Chromebooks just ran the Chrome web browser (simplifying a bit). Later, Google added the ability to run Android apps, and, just recently, added Linux apps too. With an Android based emulator app, some Windows programs can also run on a Chromebook (requires an Intel CPU). Guest mode does not run Android, Linux or Windows apps, just the Chrome browser native to ChromeOS.
Every computer company that makes Windows laptops, also makes Chromebooks. Most, but not all models have a touch screen. I suggest going for a touch screen. Models touted as 2-in-1 have a screen that can rotate fully around, letting them function as tablets too. Low end models start around $200. Mainstream models top out around $500 but there are some models that go up to $1,000.
Chromebooks are your best defense against malicious USB flash drives. See the Extra Credit section for more on this.
Google is up-front about how long a Chromebook will get software updates. Details for individual Chromebook models are in their Auto Update policy document. The latest models can get support for six years. For example, in June 2019, it showed the Acer Chromebook Spin 311 (R721T) would get updates until June 2025.
Chromebooks have a full range of remote control options where they are the controller. This might be used to give a Chromebook access to software that runs on another operating system. However, options are limited for the Chromebook being controlled remotely. The only option for full remote control that I know of is the Chrome Remote Desktop extension from Google. To me, it is a pain to setup and use. There is a Team Viewer Quick Start app for Android that, once its installed, is very simple to use. It gives view-only access to the entire Chromebook (not just to the Android side) to a remote person.
Linux: Linux on a desktop/laptop computer is relatively safe. Whether it is inherently more secure than Windows or MacOS is debatable. OS expert Daniel Micay
tweeted "The Linux kernel uses a fundamentally insecure architecture, insecure tools, and has a development culture treating correctness and especially security as an afterthought. It ultimately needs to replaced..." (Oct 2019). Either way, it is a lesser target which makes it more secure. In addition, Windows and macOS want to spy on your activity in ways that Linux does not. Typically, however, it is not a realistic option. Few computers ship with Linux pre-installed and installing it is too difficult for non-techies. Also, where does a non techie go with their inevitable Linux questions and problems? And, the many distributions (flavors of Linux) and package managers makes it even harder to get help. That said, for help picking a distro see Why I Switched From Ubuntu to Manjaro Linux by Dave McKay (Aug 2019).
As for hardware, ZaReason and System76 offer both laptops and desktops with Linux pre-installed.
At System76 the desktops and laptops both start at $1,000, but they also offer a micro sized computer with their Pop!_OS Linux starting at $520.
Purism, Star Labs and
Think Penguin make just laptops. In June 2022, HP released their DEV ONE laptop with Pop!_OS pre-installed for $1,100 (more). LAC Portland offered current Lenovo Thinkpads for those of us addicted to their keyboards. I say "offered" because as of June 2022 everything was out of stock. As for pricing, Linux laptops are often on the high side. For example, the Librem 13 laptop starts at $1,400. One exception is Pine64 which started taking orders for their $200 PineBook Pro laptop in July 2019. See reviews here and here and here. Since then, it has often been out of stock. As of early June 2022, Pine64 was planning on offering the Pinebook Pro at the end of June for $220. The Ministry of Freedom in England offers cheap, but older Lenovo laptops.
On both Windows and macOS, it is safer to logon to the computer as a restricted (a.k.a. limited, standard) user rather than an unrestricted (i.e. administrator, admin or root) user. In each system, restricted users are limited in the changes they can make to the system without approval from an unrestricted user. This limits the damage that malicious software, that makes its way onto your computer can do. Any computer with a single userid is just asking for trouble. On a new Windows or macOS computer, consider creating two users based on your first name: MichaelAdmin and MichaelRestricted, for example. On an existing computer, create a new admin user, logon to it and then modify the existing userid to be restricted. This does not apply on a Chromebook.
FYI: We can see the progression of Operating Systems in how they handle software updates. On ChromeOS all software is updated automatically. It is king of the hill in this regard. On Android and iOS, the apps can update automatically, but not the OS itself. On Windows, macOS and Linux, it's chaos.
For encrypting files on a computer running Windows, Mac OSX or Linux, I suggest using VeraCrypt. The software is free and open source. It offers an advanced mode that encrypts entire hard drive partitions, but most people should use the simple mode which creates a single large password-protected file. You then store your sensitive files inside this file. On Windows, you get access to this big file by "mounting" it, which is nerd lingo for assigning it to a drive letter. I have not used it on Linux or Mac OSX. VeraCrypt is a version of the discontinued TrueCrypt software. See Wikipedia for more.
Top of the line encryption, is end-to-end. It is offered by some messaging apps and by some cloud file storage services. Pretty much everyone and everything offers encryption in transit. File storage systems like Microsoft OneDrive, Apple iCloud, Dropbox and Google Drive offer encryption in transit and encryption at rest. However, these companies can still read your files. They do not offer end-to-end encryption. Some companies that always use end-to-encryption for file storage are Spider Oak, Tresorit, sync.com and Proton Drive. Backblaze offers it as an option.
One way to evaluate a file storage/backup service is to ask what happens if you lose/forget the password/key? If the answer is that they can not help you, that you have lost access to your data, then the vendor is using end-to-end encryption. For background, see iCloud: Who holds the key? by Matthew Green.
Not a big user of Instagram personally, so the recommendations below are from others.
To make your account private: Settings -> Privacy
The Security Checkup feature walks you through: checking login activity, reviewing profile information, confirming the accounts that share login information and updating account recovery contact information. Go to your Profile -> menu in the upper right corner -> Settings -> Security -> Security Checkup.
Enable These Instagram Privacy Settings Right Now by Pranay Parab for Lifehacker (August 2022). One suggestion is not to use the Instagram mobile app, but instead access the service from a web browser. This insures that Instagram can not access your photo library, contacts, and other data. As for the apps, the article has many configuration suggestions: don't give it access to your microphone, camera, location, photos or contacts, clear you Instagram browsing history, Clear recent searches, check who can message you, hide your activity status, stop people from using your photos in Remixes and enable two-factor authentication (more below).
To delete your stuff in bulk: go to your Profile, tap the menu in the upper right corner, then "Your activity"
How to Avoid the Worst Instagram Scams by Matt Burgess for Wired (July 2022). Limit who can
send you messages. Be aware that Instagram will never send you direct messages about your account. There are also scams on Instagram Stories. Research accounts to decide if they
can be trusted, stop accounts that do not follow you from messaging you.
Thousands lured with blue badges in Instagram phishing attack
by Bill Toulas for Bleeping Computer (September 2022). Instagram does not contact users out of the blue about account verification. The only way to install the blue badge to your handle is to apply for it yourself. Not knowing this, victims can be scammed. Emails started in July 2022 informing victims that Instagram had decided their account was worthy of a blue badge, but of course, users first have to provide their real name, email, phone number and password. Victims enter data on a domain named "teamcorrectionbadges" which is a clue to anyone familiar with Domain Name Rules.
How To Stop Instagram From Tracking Everything You Do by Matt Burgess (June 2020). There is very little you can do. To see the information you have given Instagram: App settings -> Security. But, its just an FYI. Delete contacts at instagram.com/accounts /contact_history. In the Settings tab you can see your ad activity and hide some of the ads. To really control ads on Instagram, you need to go to Facebook.
Defending against Google tracking involves changing options in your Google account, which can be done on a website, as well as configuring options on your mobile device(s), when doing Google searches, in Google Assistant and in Nest devices. There is a lot to it.
Google Account: Account settings -> People & sharing -> About me (under Choose what others see). Good is "Only you". Bad is "Anyone"
Google Account: See what Google knows about your travels using their Maps Timeline. Sometime in Oct or Nov 2019, Google will introduce a new Incognito mode in the Google Maps app. To turn it on: tap on the account icon in the upper-right corner, then click Turn on Incognito mode.
See what, if any, apps are connected to your Google Account: Account settings -> Security -> Third-party apps with account access -> Manage third-party access.
Turn off ad personalization at adssettings.google.com
Google Maps: is full of fake business listings. Big June 2019 story in the Wall Street Journal. More here and here. Hundreds of thousands of fake listings are created each month. Total scam businesses estimated at 11 million. In 2018, Google removed more than 3 million fake businesses. Google's PR response included this: "it's important that we make it easy for legitimate businesses to get their business profiles on Google". Translation: nothing will change. Here is where to report a fake.
If you have Nest Cam or Nest thermostat be aware that according to this April 2019 article in the Washington post, Nest security is sub-optimal. The article suggests using a unique password (always a good idea) and two factor authentication with the device.
Taking a step back ... Google? Really? In a camera in your home? Really?
Speaking of Nest: the Nest camera, Nest Hello doorbell and Dropcam cameras no longer (as of Aug 2019) let owners disable the status light that indicates the camera is on. Google did this for privacy reasons but some people don't like advertising the camera's existence to intruders in a dark room. Just cover the light with tape. And, be sure to apply bug fixes to the Nest Cam IQ (Aug 2019).
Google Calendar: A new type of SPAM. Bad guys can email invites to scam events and Google will add them to your calendar without your confirmation. To stop this, go to calendar.google.com, login, click the gear icon, go to Settings, then Event settings, then "Automatically add invitations" and select "No, only show invitations to which I have responded". Maybe also disable automatically adding events from Gmail to your calendar.
In March 2021, we learned of another way for bad guys to get your text messages. In this scheme, voice calls and 4G/LTE data still work. Only text messages are sent to the bad guy. The only way you know this has happened, is when, eventually, you don't get a text message that you were expecting. Bad guys simply fill out a Letter of Authorization form with fake information. From: A Hacker Got All My Texts for $16 by Joseph Cox for Vice and It's time to stop using SMS for anything by Lucky225.
Artificial Intelligence allows bad guys to learn someone's voice and vocal patterns and then manipulate it to scam people. Thomas Brewster has said "Once a technology confined to the realm of fictional capers like Mission: Impossible, voice cloning is now widely available." This scam is too new to have an official name yet. I have seen it referred to with all these terms:
Voice phishing or the shortened version: vishing
AI voice cloning and A.I.-generated audio
Synthetic Audio and Deepfake Audio and Audio Deepfakes
July 2021: A documentary about Anthony Bourdain includes three scenes with a fake voice. The director admitted to one scene, no one knows what the other two are.
The Ethics of a Deepfake Anthony Bourdain Voice
by Helen Rosner for The New Yorker
July 2019: Deepfake Audio Used to Impersonate Senior Executives (CPO Magazine). The attacks seen so far have used background noise to mask imperfections, for example simulating someone calling from a spotty cellular phone connection or being in a busy area with a lot of traffic.
How To Spot Deepfake Audio Fraud (Aug. 2019). The quality of the fake voice can be excellent for non-conversational audio, such as a statement. However, it suffers when engaged in a conversation. When in doubt, call the person back.
Another installation-time warning from Microsoft says "Office includes experiences that connect to online services ... When you use these experiences, Office collects service diagnostic data. In addition, some of these services analyze your content to deliver suggestions and recommendations. To adjust these privacy settings, go to File > Account > Account Privacy"
Connected Experiences in Office by Microsoft, applies to Office 365 and says Microsoft will " ... use your Office content to provide design recommendations, editing suggestions, data insights, and similar features ... If you'd like to turn these experiences off, go to any Office 365 application ... and go to File > Account > Manage Settings (In Outlook it's under Office Account). There you can disable or enable, either category (or both)".
Office 2016: In Word 2016, I did File -> Account and there was no option at all for Account Privacy. Instead, there was an option to "Sign in to Office". So, what level of spying is employed in this case? I don't know.
To improve the security and privacy of Twiiter, logon to twitter.com in a browser, then do: More -> Settings and Privacy -> Privacy and Safety and
Turn off Location information
Turn off Photo tagging
Turn off Personalization and data
Review options to "Receive messages from anyone" and "Discoverability and contacts"
Make it harder to reset the Twitter password. At twitter.com -> Settings -> Security and account access -> Security. Turn on the "Password reset protect" checkbox. This requires providing either the phone number or email address associated with your account in order to reset your password. Along with this, it would be best to have a dedicated email address that is only used with Twitter. See the section here on Email for a number of ways to create multiple email addresses.
How to Filter Out Twitter Trolls by Using Block Party by Yael Grauer for Consumer Reports (March 2021). The Block Party app can filter tweets according to a number of criteria and have the bad ones saved in a separate folder. It is a free service for those willing to apply and wait for an account. Or, for $8, you can get an account immediately.
Two Factor Authentication: As of Nov. 22, 2019, Twitter lets you get started with 2FA using an Authenticator app. In the old days you had to start with SMS first which meant giving them your phone number. From twitter.com do: Settings & Privacy -> Account -> Security -> Two-Factor Authentication.
TweetDelete is a service that can mass delete Twitter posts based on their age or specific text they contain.
If you care about privacy, you are probably better off using Twitter in a web browser, rather than the Twitter app.
FYI: You can download your data from Twitter. They will send you a ZIP file with an archive of your account information, history, apps and devices, activity, interests, and Ads data. From twitter.com (while logged in): Click More in the main navigation menu -> Settings and privacy -> Your Account -> Download an archive of your data ->
enter your password -> get a verification code and enter it -> click the blue Request Archive button -> Wait. They say it can take 24 hours or longer. If you use the app, you will be notified in the app when the data is ready. If you use the website, they email you when its ready. I was emailed a link, then had to enter my Twitter password and enter a temporary code they emailed. Then, I had to click a blue Download Archive button, then a second blue Download Archive button. This downloaded a file with a name like
twitter-yyyy-mm-dd-randomnoise.zip, that was 47MB and contained two folders and an HTML file. More: How to access your Twitter data from Twitter (undated as of Feb. 2022)
NAS stands for Network Attached Storage. Think external hard drive with an Ethernet port that plugs into a router. Two large vendors are Synology and QNAP.
Avoid using the default admin account. First, create a new admin account. Then, either disable the system default admin account, or, make the password for it very long and very random.
Don't allow direct access to the NAS from the Internet. On Synology, that means avoiding QuickConnect. Also, disable UPnP in the router to prevent the NAS from opening ports for itself. My Test your Router page links to many websites that offer tests of the firewall in a router.
If open ports are necessary, do not use the default ports.
If the NAS file system supports snapshots, take the time to get up to speed on the feature. This is a big deal. Speaking of snapshots, consider stepping up to a FreeNAS box from iXsystems that runs ZFS. The Mini is their entry level model.
Chances are the NAS is able to turn itself on and off. If the NAS is off at night, then no data can escape. If data is being stolen during the day, it is more likely to be noticed. Plus, this saves electricity.
As always, disable features not being used; perhaps SSH and Telnet access.
As always, avoid short passwords.
If there is lightning in your area, power off and unplug the NAS. No surge protector can stand up to lightning.
Western Digital (WD) has a very poor track record as far as security goes. Probably best to avoid their NAS devices.
Roku: Check these settings:
System -> Advanced System Settings -> Control by Mobile Apps -> disable "Network Access" (verified on Roku OS 9.1.0)
Privacy -> Advertising -> turn the Limiting of ad tracking on and reset the Advertising ID
Privacy -> Microphone -> Channel microphone access -> Never allow
System -> Screen Mirroring -> set Screen Mirroring Mode to either Prompt or Never Allow
Fire TV: Go to Settings -> Preferences -> Advertising ID. Then, disable Interest based ads. This may be old (I don't have a Fire TV). If so, try: Settings -> Preferences -> Privacy Settings. From there, disable Interest-based Ads, Device Usage Data and Collect App Data Usage. Also do: Settings -> Preferences -> Data Monitoring and turn it off.
Roku TV: From How to Disable Interactive Pop-Up Ads on Your Roku TV by Chris Hoffman October 2019. As of Roku OS 9.2, the TVs display pop-up advertisements over commercials on live TV. If an advertiser has partnered with Roku, that advertiser can display an interactive pop-up ad over the normal commercial. This only applies to Roku TVs, not the external sticks or boxes. To disable it: Settings -> Privacy -> Smart TV Experience -> disable "Use info from TV inputs".
Things are bad: You watch TV. Your TV watches back by Geoffrey Fowler for the Washington Post September 2019. No defense offered. Discusses ACR (automatic content recognition) on Smart TVs. Quote: "some TVs record and send out everything that crosses the pixels on your screen. It doesn’t matter whether the source is cable, an app, your DVD player or streaming box." They watched the data a TV transmits using IoT Inspector software from Princeton University.
Defense: The article above notes that a profile is formed based on the public IP address of your home. One defense is to connect the TV to a router running VPN client software. This hides your public IP address.
Defense: a router that supports outbound firewall rules, such as the Pepwave Surf SOHO, can block the TV from phoning home. First, watch where it sends data, then block these transmissions one a time (in case some of them are necessary). Using a Raspberry Pi running Pi-Hole for DNS should also be able to block a TV from phoning home. Or, a free account at OpenDNS lets you audit the DNS on your home network and block some domains.
Defense: one type of attack comes from the LAN. Roku, and perhaps competing devices, can accept commands using HTTP from the LAN. To prevent this, isolate the streaming box. If using Wi-Fi, connect it to a Guest network. Some, not all, routers will isolate Guest network users from each other, blocking this type of attack. More advanced users can put the streaming box in a VLAN. The first suggested Roku setting above, should also block this, but it only applies to Roku and may change in the future.
Defense: The ultimate defense is not to connect a Smart TV to the Internet (other than maybe to update the firmware).
There are many articles about blocking Roku monitoring by blocking access to assorted domains and sub-domains. For a long time now I have blocked all access from my LAN to scribe.logs.roku.com and cooper.logs.roku.com. My Roku box works just fine without these. I chose them because they were the most popular logs my Roku box was accessing.
Roku networking: I have seen a Roku 2XS running firmware 9.1.0 make outbound requests to the Google DNS server at 188.8.131.52, port 53, using TCP. This is suspicious for multiple reasons, one being that the router assigns other DNS servers. Thus, the use of 184.108.40.206 is hard coded into either the Roku system or one of the channels. One reason to do this is to avoid DNS based restrictions in the router. Also, UDP is the norm for DNS, not TCP. I have not captured the actual packets.
More Roku networking: I always see the same Roku 2XS box making outbound connections to IP address 172.29.243.255. This should never occur as this is a private IP address, one that can never exist on the Internet. These connections use UDP and both the source and destination port are always 1975. This seems to be part of the OS, I see it even when just powering on and not using any channels. I contacted Roku about this and they would not explain why this happens.
Netflix: login to netflix.com with your userid/password. Click on the profile icon in the top right corner, then click Account. To see all the info Netflix has on you, click on
"Download your personal information". To remove something from your viewing history: start at Account info, then click on a profile, then Viewing History. To remove an item, click the circle on the far right.
Hulu: Log in to Hulu.com and open the Account page. Go to Privacy and Settings. Select Manage Nielsen Measurement and opt out. Select California Privacy Rights. Under Right to Opt Out, click Change Status and opt out. To clear the watch history: Under Manage Activity, click Watch History, then Clear Selected.
Amazon Prime video suggested settings are in the Amazon section
Oregon FBI Tech Tuesday: Securing Smart TVs
(Nov 2019). A smart TV is a computer that bad guys might be able to hack into. Many Smart TVs have microphones so that you can shout at them to change the channel. Yet another thing that can be hacked. A number of smart TVs also have built-in cameras. If you can find the camera, but tape over it. Some TVs use the camera for facial recognition so the TV knows who is watching and can suggest programming appropriately. Ugh. Suggested defense: know exactly what features your TV has and how to control those features. Do a net search on the TV model using words like "microphone," "camera" and "privacy."
Also, review security settings.
Smart TVs getting hacked: Watch a Drone Take Over a Nearby Smart TV by Andy Greenberg in Wired (Aug 2019). About hacking into smart TVs that use the internet-connected HbbTV standard. Weaknesses in HbbTV could be combined with vulnerabilities in Samsung smart TVs to gain full remote access to the television sets. This remote access persists even after the TV is turned off.
Samsung and Roku Smart TVs Vulnerable to Hacking, Consumer Reports Finds (Feb 2018). Much ado about nothing. They found flaws in sets from TCL using the Roku TV platform and in Samsung, which uses their own Tizen operating system. Other brands that use the Roku TV platform, are also vulnerable, as are Roku boxes. However, the Roku attack has to come from your home and I have the defense in the
TV watches you topic (first item). The article does not walk you through the defensive configuration. The Samsung attack can only be exploited "if the user had previously employed a remote control app on a mobile device that works with the TV, and then opened the malicious web page using that device."
(topic created Nov. 28, 2019) top
When there is too much electricity a surge protector is designed to absorb the overload and perhaps even die, to protect the devices plugged into it. Some surge protectors look like a power strip, but there is a big difference.
As a rule, you get what you pay for with surge protectors. If you need to protect something very important or very expensive, than spend more for the surge protector.
It is very likely that any surge protector will eventually fail. What then? Some will continue providing un-protected power after they have failed. Others will cut off the power rather than leave you unprotected.
Be sure to look for a surge protector that has a visible indicator of whether it is providing protection or not. Also, a Ground indicator is good to have.
Surge protectors are sold based on Joules which is not the most important criteria. PenLight, a power company in the US, says"Joule ratings can be misleading ... Joule ratings are an unreliable measurement for determining a products surge capacity because there is no test standard. The Joule rating listed on a surge protector’s package is determined using an unknown method by the manufacturer."
What is a surge? There is no one answer, different devices kick in at different levels. The amount of extra electricity that is allowed is referred to as both the let-through voltage and the clamping voltage. The lower the let-through voltage, the better the protection. The lowest (best) UL 1449 rating is 330 volts. You may see devices rated for 400 or 500 volts.
Clamping response time is how quickly the device responds to a surge. Faster is better. Nanoseconds (billionths of a second) are good. Picoseconds (trillionths of a second) are the best.
If you can't get the above specs for any particular surge protector, it might be that the vendor does not want you to know them because they are poor.
If Internet access is important, then, at the least, protect the modem and router with a surge protector. If Internet access is very important, then protect them with a UPS.
Surges are not limited to electrical lines, they can also be carried by telephone lines and cable TV coaxial cables. Some surge protectors also offer protection for cable and telephone lines.
Buy a portable battery charger (Anker is a big brand). Maybe a solar battery charger.
Buy a UPS. A line interactive UPS costs more money but your devices get protected by both boosting power in a brown-out or trimming power when needed. If your only need is a big backup battery for a power outage, then a cheaper standby class UPS will do.
Download the Google Maps map for your area. It can work using nothing but GPS, no Internet needed. In an emergency, you may find yourself traveling to new places.
If fires, floods or storms happen often enough in your area, then maybe buy a satellite messenger. REI sells messengers from Garmin, Spot and ZOLEO. A subscription is required to the satellite service and there are two competing services.
Some pair with a cell phone via Bluetooth, others are totally standalone, with their own screen and keyboard. Messages take a few minutes before they are sent, as a satellite has to be overhead. Some services only let you send messages, others are bi-directional. Prices vary, but a well reviewed model can be had for $200.
Unplug computers, modems, routers and expensive electronics. Th power may come back on with a damaging surge.
Unplug all wires that feed into these devices. A power surge can also be transmitted over the coaxial cable used by cable TV or the phone line used by DSL
If you have a UPS, consider plugging a lamp into it at night, preferably, one with an LED bulb.
Put a cellphone in low power mode. iPhone: Settings -> Battery (not available on iPads). Android: maybe swipe down from the top and look for Battery Saver. Maybe Settings -> Battery. Maybe Settings -> Battery and Device Care -> Battery -> Power Saving mode.
(last updated August 15, 2021) top
Anyone concerned with being tracked on-line needs to be familiar with web browser fingerprinting. Without using cookies, fingerprinting can convert the web browser on your computer into a unique identifier. Fingerprinting stems from looking at many, seemingly trivial, aspects of your computer and browser and combining that information into a profile/identifier. Most of the time, these profiles turn out to be unique, which lets websites track your behavior without cookies. Some attributes that are examined are: the computer operating system, what time zone are you in, what language your computer is using, how much RAM memory the computer has, the screen height and width in pixels, what web browser you are using, what version of the browser, what fonts are installed, what plug-ins are installed, what audio and video formats are supported by the browser, and much more.
Testing: one website for testing the fingerprinting of a web browser is amiunique.org. As of Nov. 15, 2019 they had collected 1,408,000 fingerprints. By March 12, 2020 it was up to 1,713,000.
Testing: the EFF has offered an online test similar to amiunique.org since 2010. It used to be called Panopticlick but now
it is called Cover Your Tracks. In August 2021, I tried this on Windows. Brave with OpenDNS and no plug-ins did well: "your browser has a randomized fingerprint". Firefox using NextDNS and with uBlock Origin and Privacy Badger installed, failed, it had a unique fingerprint.
Testing: fingerprintjs.com/demo is a demo of how good fingerprinting can be from a company offering it as a service.
ChromeOS Defense: An excellent defense against fingerprinting is a Chromebook in Guest Mode. All Chromebooks of the same model running the same version of ChromeOS should share a fingerprint. Interesting fact: only 0.23% of the devices tested by amiunique.org were Chromebooks.
Tor Browser Defense: The Tor browser has a number of anti-fingerprinting features enabled by default. It runs on Windows, macOS, Android and Linux. Note however that websites will be very slow to load.
Firefox Defense: As of version 72, released in Jan. 2020, fingerprint defense is on by default. The browser blocks third-party requests from companies known to engage in fingerprinting. To verify this, look in Options -> Privacy & Security. To see if it blocked anything on the currently display web page click on the shield to the left of the address bar. See a screen shot from Computerworld and one from
metageek.com (desktop Firefox v73 March 2020).
Brave defense: Brave has two generations of defense. In March 2020 Brave announced their second defensive approach - randomizing fingerprintable values in ways that are imperceptible to humans, but which confuse fingerprints. Quoting: "This approach is fundamentally different from existing fingerprinting defense approaches ... [that] attempt to make all browsers look identical to websites (an impossible goal). Brave's new approach aims to make every browser look completely unique, both between websites and between browsing sessions." They claim this provides the strongest fingerprinting protections of any popular browser. Not sure when it will be released.
Their older defense is the Device Recognition option in the Settings. I found that it worked, see it reporting that it blocked two fingerprint attempts by Ars Technica. I tried both fingerprinting test websites (above) and, on each one, their first generation blocker blocked a fingerprinting attempt.
Defense: Disconnect offers a free browser extension that blocks trackers. Maybe it also blocks fingerprinting. They partnered with Mozilla in providing the Firefox defense.
No defense: Private browsing mode does not prevent fingerprinting. Neither does a VPN or the Tor network. Blocking cookies also does nothing.
No defense: Chrome, of course, offers no defense. Tracking people is what Google does.
FYI: The deviceinfo.me website shows many of the computer attributes used in fingerprinting.
OS Defense: The Tails operating system might be a defense. It is a version of Linux that runs off a boot CD/DVD/USB flash drive and always uses the Tor network and the Tor browser. Everyone using the same version of Tails will have much in common. However, attributes of the screen will differ. Also, it is a big pain to setup. And, again, the Tor network alone, is no defense.
PROTECTING CHILDREN FROM BAD ADULTS
(topic added Dec 10, 2019) top
This is not a subject I am at all familiar with. Thus, nothing but links and not many at that. Feel free to help me add to this topic.
Many developed countries allow most citizens to file their taxes for free. In the US, this was the stated intent, but the scheme was corrupted. According to Pro Publica, TurboTax tricked customers into paying for tax preparation they could have gotten for free. TurboTax even has a service with the word "free" in it - that is/was not free. US taxpayers owe a debt to Pro Publica for their reporting on this.
Hide your main/actual phone number by having more than one and giving out an alternate second phone number when appropriate. For example, I once checked my coat at a museum and rather than give me a ticket, they wanted my phone number. Another reason for second phone number is for use with Signal. If you are interested in secure messaging, many people recommend the Signal app, which uses a phone number as the userid. So, maybe create a second number just for Signal.
TextNow offers Wi-Fi only phone numbers (my term) that do voice and texting. Its a VOIP phone number and also works over 4G/LTE. The service is free with ads or $3/month without ads. No phone needed, its an app, so it can be installed on a tablet. Or multiple tablets. Or, an old Wi-Fi only cellphone. When a call comes in, and no device with the app installed is on-line, they take a message and email you that you missed a call. They also send a text transcript of any message left by the caller. I have used it for a while without ads and without complaint. If nothing else, its a great defense against SIM Swaps as no cellphone companies are involved.
In January 2020, TextNow started offering cellphone numbers on the Sprint network. If you have a phone that works on Sprint, they charge $10 for a SIM card. The service is free with ads or $10/month without ads.
Ting.com can be used for a permanent secondary, rarely used, cellphone number. To me, it makes the most sense to use it on an old cellphone. They do CDMA on Sprint or GSM on T-Mobile. It costs $6/month for the number and then you pay monthly for what you use: $3 for up to 100 minutes of talking, $3 for up to 100 texts and $3 for up to 100MB of data.
The MySudo mobile app combines a second phone number with three new email address into a profile/personality, which they refer to as a Sudo. You make phone calls, send/receive texts and send/receive emails from within the app. There is a limited free account, pricing starts at $1/month. iOS users also get three new disposable credit card numbers. Profiles can be deleted and new ones created.
Ed Bott of ZDNet likes Line2. He explains (Dec. 2020) that it works on Android, iOS, Windows and macOS. It is a full-featured product offering voice, text messages, MMS messages, voicemail, etc. It can work over either a data connection (Wi-Fi, 4G) or a mobile network. The cheapest plan is $150/year.
Vyke offers up to four phone numbers with a single Vyke account. The service only works over the Internet (Wi-Fi, 4G) it is not a cell thing. It runs on Android and iOS and the app can be installed on tablets. You pay either by the week/month/year or by the minute for phone calls. They have phone numbers in the US, UK, France, Canada, Netherlands and Poland (as of Dec. 2020). You need a cellphone number to setup an account. I have not used it.
I have heard good things about textverified.com. They give you short-term use of a non-VOIP phone number that can be used for SMS and Text Verification on their website. They get the text and display it on their site. The explanation of their services for new users is miserable however, I could make little sense of it.
Google Voice is free but I would rather not have Google know more about me than they already do. Plus, it requires a cellphone number when you sign up, not the best way to hide said number.
In episode 141 (Oct 2019) of his Security, Privacy and OSIN podcast, Michael Bazzell told of how he gets a phone number for a week for $2.50. He buys two pre-paid Mint Mobile SIM cards for $5 on Amazon. Each comes with a one week free, limited trial. He uses them to setup assorted social media accounts. Once setup, converting the accounts to 2FA means never needing the phone number again.
On the June 26, 2020 episode of The Privacy, Security, & OSINT Show the show host, Michael Bazzell, went into detail on using a Mint Mobile pre-paid SIM card as part of a private cellphone number. He suggested buying the SIM cards at Best Buy and paying cash. Amazon also sells them.
There are many other companies offering similar services.
Just like web pages migrated from insecure HTTP to encrypted HTTPS, so too, DNS is changing. Legacy DNS uses plain text over UDP (not important) on port 53 (also just for techies). New DNS is encrypted using either DNS over HTTPS (DoH) or DNS over TLS (DoT). New DNS uses TCP on port 853 or 443.
Android leads the way among operating systems. Version 9, 10, 11 and 12 have a Private DNS feature that uses DoT system-wide. This setting even over-rides DNS from an active VPN. See the Android topic for more. Android versions 4 through 8 can use the Intra app from the Jigsaw division of Google. It installs as a VPN but only to get control of DNS. More. The Quad9 Connect app enables encrypted DNS from Quad9.
As of July 2020, Windows does not support encrypted DNS. Windows 10 will in the future.
Encrypted DNS was added to macOS in version 11 released around October 2020.
ChromeOS has a system wide encrypted DNS setting that carries over to Guest Mode. However, an active VPN seems to over-ride the system wide setting (tested July 2022).
I don't know the status on the many Linux distributions.
iOS 13 does not offer system-wide encrypted DNS The Cloudflare 220.127.116.11 app offers it on iOS 13 but only with their own DNS service which does no blocking. The NextDNS and Adguard apps both offer blocking and encrypted DNS on iOS 13.
iOS 14, released around October 2020, includes system-wide encrypted DNS (DoH) but it is complicated (on Android 9, 10 and 11 it is simple). I suggest reading the instructions for iOS 14 from your preferred DNS provider. There are at least three places within iOS where DNS can be specified. Which ones take precedence? One source is individual apps. Does encrypted DNS specified by an app over-ride competing specifications elsewhere in the system? Which apps do this? I don't know how you can tell. On a system level, DNS can be specified at Settings -> VPN & Network -> DNS. Then too, like any OS, DNS can come from a VPN. iOS also has profiles. NextDNS lets you generate an Apple Configuration Profile. This requires you to have a NextDNS account and it must be downloaded using Safari on the iOS device, which they don't say. With a VPN active, I found that the NextDNS profile was ignored and DNS from the VPN was being used instead. As explained by OpenDNS (DNS Resolver Selection in iOS 14 and macOS 11) its complicated.
Without OS-wide support, you can still configure a browser to use encrypted DNS, at least on desktop OSs.
How to configure web browsers on Windows to use Encrypted DNS (as of March 3, 2021)
Chrome version 87: Settings -> Privacy and security -> Security section -> Use secure DNS
Firefox version 86: Options -> General -> Network Settings -> Settings button -> Enable DNS over HTTPS
Brave version 1.20.108: Settings -> Additional Settings -> Privacy and security -> Security section -> Use secure DNS
Opera version 74.0.3911.160 Settings -> Basic -> System -> Use DNS-over-HTTPS instead of the system’s DNS settings
Edge version 88.0.705.81 was miserable in my tests. To find the setting:
Settings -> Privacy, search, and services -> Security section -> Use secure DNS to specify how to lookup the network address for websites
On Windows 10 Home service pack 2004 with bug fixes as of Feb. 2021, I could not turn this on. The error was "This setting is turned off for managed browsers".
There was nothing managed about the browser. On Windows 10 Pro service pack 2004 with bug fixes as of Nov. 2020, I was able to turn the setting on but when I selected Quad9 as the
DNS provider, it warned "Please verify that this is a valid provider". It also did not support NextDNS. Typical Microsoft.
Vivaldi version 3.6.2165.36 does not support encrypted DNS
Note that encrypted DNS is nice but not great security. Network observers can still see the IP addresses you communicate with and the domain names of secure web sites you visit. Not the full URL, just the domain name. And, it does nothing for HTTP web pages. Both a VPN and Tor hide everything, but, each is end-to-middle encryption, not end-to-end.
As with VPNs and Tor, you can not hide the fact that you are using encrypted DNS. A network observer can see the initial old style DNS lookup for the encrypted DNS server name.
All the ways Slack (and your boss) tracks you and how to stop it by Matt Burgess for Wired (October 2020). By default, Slack never deletes your messages or files. The biggest risk for many people is bad passwords and the lack of two-factor authentication. Private channels and DMs could be revealed during a legal case or other type of investigation. When adding a new person to a Slack channel they are able to see past messages and files, including any gossip about them.
7 Slack privacy settings you should enable now by Jack Morse in Mashable (July 2019). In the paid version of Slack, the article explains how to tell if your boss can read your direct messages. How to tweak the retention settings on your direct messages. The Chrome browser extension Shhlack, can encrypt messages. Use Signal instead for real privacy. Some Slack accounts track edits and maintain records of the messages before they were edited.
What if All Your Slack Chats Were Leaked? by Gennie Gebhart in NY Times (July 2019). No defense, just things to be aware of. "Slack stores everything you do on its platform by default - your username and password, every message you've sent, every lunch you’ve planned ... That data is not end-to-end encrypted, which means Slack can read it, law enforcement can request it, and hackers ... can break in and steal it." On the free Slack service, all messages are kept forever.
We Tested Ring's Security. It's Awful by Joseph Cox for Vice (Dec 2019). Great article about many things Ring could do to improve security. Read this before making a decision on trusting Ring. Some take-aways: change the password (even if its unique), add two factor authentication (everyone suggests this) and at initial setup give it a phony address and phone number (my idea, not tested).
We're not rescinding our recommendation of Ring’s cameras. Here's why by Mike Prospero for Toms Guide (Dec 2019). Suggested defense: Don’t share video or incident reports with the Neighbors app because it might let others learn where you live. And be aware that sharing video with a law enforcement agency will tell them your name and address and the video might be shared with other agencies.
This section is about payment apps (aka pay apps) such as PayPal, Venmo, Cash App, AppleCash, Google Pay and Zelle.
The article How Private Is My Pay App? from The Markup (Nov 2020)
discusses the data these apps share. The apps that most protect your privacy are Google Pay, AppleCash and Zelle.
Common Zelle scam: a text message from bad guys asks to confirm some banking activity. Bank customer says it was not them. Immediately, bad guys call the bank customer, pretend to be the fraud department at the bank and ask for assorted information to verify things. A customer that responds to this, immediately becomes a victim. As noted at the top of this page, you never know who calls you on the phone or who sent a text message.
Me-to-Me scam: bad guys convince a Zelle user to send money to their own phone number. Sounds safe. But, the bad guys have assigned the victim's phone number to their account.
CONFIGURE PRIVACY SETTINGS
The settings are found in the gear icon in the mobile app. In Settings, click on Privacy, then:
Future: The app makes transactions public by default. To change that, going forward: Default Privacy Setting -> Private. The bad options here are Public or Friends
Past: To retroactively privatize Venmo posts: "Past Transactions" -> Change All to Private. You may have to scroll down to "More"
Contacts: Friend lists default to public. No other social network or service does that. For a long time they could not be made private. Now they can. Click on
"More" -> Friends List and set it to Private. While there, also turn off "Appear in Other Users' Friends Lists"
Location: Venmo wants to know your location but it is not needed. You can deny the app location access in both iOS and Android using the Operating System settings. The app can take you to the
appropriate OS settings. Again, click on "More" in the Privacy section, then Location.
Configure: Settings -> Preferences -> Friends & Social. Turn off Facebook Connect, Phone Contacts and Facebook Contacts. A gray dot is OFF, a green check mark is ON.
This is really bad: a compromised or fraudulent PayPal Business account is being used by bad guys to send emails and invoices that could not look any more realistic. From PayPal Phishing Scam Uses Invoices Sent Via PayPal by Brian Krebs (Aug. 2022). The scam emails are actually being sent by Paypal. The scam invoices that the emails link to are hosted on the real Paypal website. Yet, fraudulent. The scam part of the emails is the phone number to call to dispute the phony charge in the phony invoice. In one case, the only tip-off that this was a scam was when the bad guys tried to install remote control software on the victim's computer.
Report suspect messages from PayPal (email, text, whatever) to email@example.com and/or firstname.lastname@example.org
How to Spot a Fake PayPal Email from Paypal (Sept 2021).
They do typically use email to contact their customers about both their PayPal and Venmo accounts.
Don't use Windows. In fact, I suggest avoiding all software from Microsoft such as their web browser (Edge), their email clients (Outlook in particular) and their Office suite (try Libre Office
instead). If you do use Windows:
Portable apps are safer than normally installed apps because they are harder for malware to find. Also, they are easy to backup, just copy a folder. And, they let you have two different versions of an app available at the same time. An excellent source of portable Windows software is at portableapps.com.
A Windows system with a single userid is mis-configured. Every copy of Windows should have at least one restricted user and one administrator class user. The restricted user is what should be used 99.9% of the time.
Before running any downloaded executable file, check it at VirusTotal.com.
My Print Queue is Stuck. How Do I Print Anything? by Leo A. Notenboom (last updated Aug. 1, 2022). To clear the print queue:
turn off the printer, stop the Print Spooler service, delete all the files in c:\Windows\System32\ spool\PRINTERS, start the Print
Spooler service, turn on the printer.
Dealing with technology side of abusive relationships.
In February 2022, Zack Whittaker reported on a family of Android spyware apps that, while they looked different on the outside, were the same internally. The apps are: Copy9, MxSpy, TheTruthSpy, iSpyoo, SecondClone, TheSpyApp, ExactSpy, FoneTracker and GuestSpy. He offered advice on finding and removing them such as: in the Play store app, verify that play Protect is on. In Settings -> Accessibility look for any Downloaded services with names like "Accessibility" or "Device Health". Also look for any device admin apps. For more see Your Android phone could have stalkerware, here’s how to remove it.
How Jamie Spears Spied on Britney Spears Through iCloud by Lorenzo Franceschi-Bicchierai (Oct 2021). Using iCloud to spy on someone's iPhone is an extremely common way abusers spy on their loved ones. All that is needed is the password for the Apple ID of the victim. The article describes detecting this and stopping it. In a browser, I suggest (not in the article) a Chromebook running in Guest Mode. Login to iCloud.com -> Account Settings -> My Devices.
Stalkerware Apps Are Proliferating. Protect Yourself New York Times (Sept. 2021). Has nine defensive tips from The Coalition Against Stalkerware. FYI: An app icon can be changed to that of something innocent looking such as a calculator or calendar app. Apps to detect stalkerware: MalwareBytes, Certo AntiSpy, NortonLifeLock and Lookout.
How to Shut Stalkers Out of Your Tech by Yael Grauer for Consumer Reports (March 2021). People facing domestic abuse can take these steps to lock down their devices and eliminate stalkerware. The article has many many suggestions. For finding stalkerware on Android, use an antivirus app from Eset, Kaspersky and/or Trend Micro. On Windows, use BitDefender, Eset, Kaspersky, Norton and/or Malwarebytes. On an iPhone use the iVerify app from Trail of Bits.
Apple's AirTag trackers made it frighteningly easy to 'stalk' me in a test by Geoffrey Fowler for the Washington Post (May 2021). The article is behind a paywall. A big point in the article is that Apple does not do enough to prevent AirTags being used for domestic abuse. In a test in San Francisco, the AirTag updated its location every few minutes. When moving, the location was accurate to half a block. When stationary, it was precise. An accompanying video is not behind the paywall.
The National Domestic Violence Hotline has trained experts. Call 800-799-7233
Note however that when they say "Computers store information about the websites you visit. ... purchases you make ... messages or emails ... You should always consider that a computer might be monitored ... Safe computers can be found at your local library, Internet cafe, shelter, workplace .." they are leaving out an excellent option, a Chromebook running Guest Mode. It is impossible to install any type of spyware on a Chromebook running in Guest Mode and Guest Mode stores nothing, which makes it a far safer option than the ones they offer. They also say that "Using safe browsing practices (like using a VPN) can help prevent abusive partners from tracking your Internet history." To be clear, the purpose of a VPN is to hide activity from the ISP and from the router you are connected to. VPNs are not designed to hide activity on the computer where they are running.
The hardest computer to infect with something malicious is a Chromebook. Guest Mode in a Chromebook guarantees that no extra software is/can be installed. It can be used to access any webmail system, such as secure email from ProtonMail and Tutanota. Do not use the Chromebook with a NextDNS account as NextDNS offers logging. See the section on Chromebooks for setting DNS system-wide.
Start using ProtonMail for email. Messages between two ProtonMail customers are end-to-end encrypted. It has a free tier.
There are more secure versions of Android. In the Android topic, see the sub-section on Replacing Android, for an overview of LineageOS, GrapheneOS
and /e/ OS.
An app that lets you create a new profile/personality (new email address and new phone number) is MySudo. You can send and receive calls, texts and emails from the MySudo app. It runs on iOS and Android. There is a limited free account. Pricing starts at $1/month.
Every now and then turn your phone off (really OFF) and then back on a minute later. While every operating system benefits from a clean boot/startup, if you are targeted by bad guys, certain malicious stuff might be removed when the device is powered off. This applies to routers too.
How to Avoid Being Scammed by Fake Job Ads by Cezary Podkul for Pro Publica (Oct 2021).
Phony job advertisements are proliferating, often as part of identity-theft schemes. The article has 10 tips. Tip 3: Be wary of job ads touting the need to verify your identity at the outset. Tip 4: Take the text of the job ad and put it in Google.
Know that job boards do not validate that the person posting a job is actually affiliated with the company.
An excellent scam/noscam indicator is whether you deal with someone who gives you a Gmail account or someone using the actual company domain. That said, this requires an understanding of the rules for Domain Names (topic number 2 above) so you don't get tricked into thinking email@example.com is the same as firstname.lastname@example.org.
These observations are from using a new Amazon Fire HD 10 Tablet (11th generation) in July 2022. It was running FireOS 18.104.22.168. In my opinion, if you can afford to pay more for a tablet running real Android, that would be the better approach.
Even a model without ads, has ads. It just depends on how you define the word "ad". While there are none on the lock screen, across the top of the home screen is a never ending list of suggested stuff to buy and apps to install. As far as I can tell, this can not be disabled. In this screen shot, the Discover section are the ads.
You can not install a normal web browser, you are limited to the Amazon Silk browser which does not support extensions.
The selection of apps in the Amazon app store is very limited. Many available apps are old. For example, the app for NPR news is from 2014.
When a free app is installed, Amazon emails you a receipt for zero dollars paid.
Settings -> Security and Privacy. Adjust settings in Advertising ID and Location-Based Services. Turn off "Collect App Usage Data" and "Device Usage Data"
I have not used the testing tablet for very long, but updates to both apps and the operating system seem to be very non-intrusive from the end user perspective.
Although based on Android, FireOS has no system wide encrypted DNS setting. So, this is not an option for ad or tracker blocking.
You can not specify DNS servers for a Wi-Fi network (SSID), it will only use the DNS servers provided by the router. However, it always adds to this, the main Google DNS server (22.214.171.124). No doubt, Amazon does this to avoid tech support calls, they never want a DNS request to fail.
The Silk web browser has an option for Secure DNS (Settings -> Privacy and security -> Use secure DNS) which includes a custom setting. I was able to use the Custom setting with NextDNS. In my testing, Silk used NextDNS for DNS even when the system was connected to a VPN. With NextDNS active, I tested three apps. Two of them did not use NextDNS, one of them did.
FYI: The ProtonVPN app is very different on a Fire tablet compared to the software on all other supported systems.
Keeping a laptop battery fully charged at all times shortens its lifespan. Batteries last the longest when operating between 30 and 80 percent charged. A laptop that is plugged in all the time, should be set to never charge over 80 percent. In the best case, the battery should normally be charged somewhere in the 30-80 percent range and, when you expect to need it, then charge it up to 100%.
Laptop batteries can swell in size. A swollen battery should be replaced and kept cool. I would contact the hardware manufacture for specific instructions. See the Dell Swollen Battery Information and Guidance.
The only defense, so far, is to buy a Porsche Taycan SUV.
Cars spy on us: Who Is Collecting Data from Your Car? by Jon Keegan and Alfred Ng for The Markup (July 2022). A firehose of sensitive data from your vehicle is flowing to a group of companies you’ve probably never heard of. They identified 37 companies that are part of the connected vehicle data industry that seeks to monetize this data in an environment with few regulations. Based on a factory-installed cellular connection. No defense offered. The only car with privacy controls is the Porsche Taycan SUV.
Cars spy on us: These Companies Track Millions Of Cars - Immigration And Border Police Have Been Grabbing Their Data by Thomas Brewster (April 2021). Cars constantly collect location and use information and that data can is provided to the government. In the last 18 months Customs and Border Protection and Immigrations Customs Enforcement officials demanded location data from three companies who collectively track the movements of tens of millions of vehicles: GM OnStar, Geotab and Spireon. No defense offered.
Cars spy on us: Cars Have Your Location. This Spy Firm Wants to Sell It to the U.S. Military by Joseph Cox for Vice (March 2021). A company claims that it can locate specific cars in real time with data that comes from the cars themselves. The company is The Ulysses Group.
Cars often include sensors that collect information and transmit it back to the home office. Such vehicle telematics include the airbag and seatbelt status, engine temperature, and current location.
It is claimed that vehicle location data is transmitted on a constant and near real time basis while the vehicle is operating. For defense, Privacy4Cars.
The Privacy4Cars app offers step-by-step instructions for deleting your personally-identifiable information from any car. The company also sells tools to help dealerships remove data from vehicles.
I hate printers. So too, does Leo Laporte, who is known as the Tech Guy on the radio. He will not take phone calls about printers.
Background: There are two popular types of printers - those that squirt liquid ink and laser printers that, like a xerox machine, burn a toner (think colored dust) onto the paper. Liquid ink printers are called inkjets, those from HP are called deskjets. All inkjet printers print in color. Laser printers come in black/white or color versions. A laser printer should, in the long run, be more reliable, easier to maintain and cheaper to own and use. An inkjet printer is cheaper to buy. Most inkjets use very small ink cartridges that can not be refilled. A small number of inkjets use a large refillable ink tank. For more see
How to Save Money on Your Next Printer: Weighing the Cost of Tank vs. Cartridge Ink by M. David Stone (Nov 2021).
If you need a printer, you need two.
A black/white laser printer is an excellent backup printer. Expect to pay about $100 US dollars.
As a rule the more you pay for a printer the cheaper it will be to operate over the years.
If you are considering buying an inket printer, this article Oct 2021 article, Canon sued for disabling scanner when printers run out of ink, from Bleeping Computer shows that without ink, a Canon printer can not even scan, which uses no ink at all. It also would not send a fax, which again, uses no ink. And, without color ink, it will not print in greyscale. These gripes go back to at least 2016.
If you are considering buying a label printer, beware of Dymo printers which force you to use their branded paper which costs much more than competing paper. Label printers from Zebra and MFLabel let you print on any brand of labels. From The Worst Timeline: A Printer Company Is Putting DRM in Paper Now by Cory Doctorow for the EFF (Feb. 2022).
FYI: Laser printers warn about the toner being almost empty well before it actually runs out. When a toner cartridge is low, you may be able to extend its life by shaking it.
FYI: Most color laser printers and color copiers are designed to print invisible tracking codes on every page. These codes reveal which specific machine produced a document and, in some cases, when the document was printed or copied. From the EFF in 2017: it appears likely that all recent commercial color laser printers print some kind of forensic tracking codes, not necessarily using yellow dots. This is true whether or not those codes are visible to the eye. To be safe, use a black-and-white printer, black-and-white scanner, or convert a color image to black-and-white with an image editor. More from the BBC (June 2020), from Robert Graham (June 2017), from the EFF (undated) and from Snopes (June 2017).
Ever wonder how expensive the ink for an inkjet printer is per gallon? According to Cory Doctorow, the ink costs $170/gallon to manufacture and it is sold for $12,000/gallon (as of Feb. 2022). Quoting: "No one would voluntarily pay $12,000/gal for ink that costs about $170/gal to manufacture, so the printer companies roll out an endlessly inventive bag of dirty tricks to force you to buy their $12,000/gal product, and keep you buying it, forever." This is just one reason to buy a laser printer.
Some printers support Wi-Fi Direct which is a type of Wi-Fi that allows two devices to directly connect to each other, without needing to be on the same Wi-Fi network. You could unplug your router and this would still work. I mention it here because unless you use this feature, it should be turned off in the printer. At the very least, change the default Wi-Fi network password to something at least 15 characters long. This to prevent the Wi-Fi network created by the printer being used to hack into the LAN.
Very old printers may have trouble feeding paper because the rubber rollers have dried out. Some suggestions:
Use an emory board or sandpaper or a nail file to roughen the rollers. Stroke side to side to make grooves in the rollers.
Use a product that claims to rejuvenate rubber. One such product is CaiKleen RBR rubber cleaner and rejuvenator. It claims to: "Re-condition rubber surfaces and bring back its original surface texture, flexibility and usability."
Assuming that the TikTok app does indeed spy on its users, the safer approach would be to use the website rather than the mobile app. Better yet, use private browsing mode. Better still, use a Chromebook in Guest Mode.
The safest first step is to use the tiktok.com website without having an account.
CREATE AN ACCOUNT WITH MAXIMUM PRIVACY
Instead of your regular/main email account, use one that is auto-forwarded and not used anywhere else. For more on this see, the page on multiple email addresses.
Do not give TikTok your phone number, it is not needed to create an account.
Do not put your real name in your profile
Give you account a nickname that is not used anywhere else
SETTINGS FOR MAXIMUM PRIVACY
Make your account Private so that you can approve who follows you: Settings and Privacy -> Privacy -> turn on Private Account
Make it hard for people to find you: Settings and Privacy -> Privacy -> Suggest Your Account to Others -> Turn off the four toggles
Hide the people that you follow: Settings and Privacy -> Privacy -> Safety section -> Following List -> Only Me
Hide the videos you like: Settings and Privacy -> Privacy -> Safety section -> Liked Videos -> Only Me
Ad Personalization: Settings and Privacy -> Privacy -> Ads Personalization -> Use of Off-TikTok Activity for Ad Targeting -> turn off
Do not share your contacts/friends: Settings and Privacy -> Privacy -> Sync Contacts and Facebook Friends. In addition, both Android and iOS should let you block the app from being able to access your contacts.
TikTok privacy settings to change now by Heather Kelly for the Washington Post (January 2022).
The social media app is all about your personal data, likes and habits. Here’s how to limit what it gathers about you. Focused on the mobile app, not the website.
TikTok Is Watching You - Even If You Don't Have an Account by Riccardo Coluccini for Vice (January 2021). The reporter submitted a request under the GDPR, and was shocked to see what data the app had been recording. No defense offered. You can ask TikTok for the data it has on you. In the mobile app: Settings -> Privacy -> Download your Data.
Scammers love to trick people into sending them money on a gift card.
An excellent article from the FTC: Gift Card Scams. May 2021. It says to report the scam at
ReportFraud.ftc.gov. Report it even if you did not pay. There is also a link to report to your state attorney general. If you lost money to a gift card scam, they suggest reporting it to local law enforcement. Alternate link
A drug store put up a warning side right in front of their gift cards. A picture of this was tweeted by @dotornot2 May 17, 2022.
No tech company will call you about a problem, any problem
If you get a phone call and callerid says it is from a tech company, the callerid has been faked
The warning on your computer about a virus or malware is almost definitely a scam
If the warning has a phone number to call, it is definitely a scam
Any situation that requires you to install software is a scam
Every attempt to access your computer is malicious
The safest computer for non technical people is a Chromebook. Right off the bat, it offers immunity from scammers calling and claiming to be from Microsoft, Windows or Apple. Most likely the bad guys do not have scripts, yet, that target Chrome OS users. Then too, a Chromebook requires no ongoing care and feeding making it a perfect fit for non technical people.
More from Molly: The Blockchain collection articles about blockchains. Started Jan. 2022. These
articles require an understanding of concepts such as the blockchain, cryptocurrencies, and NFTs. For that, she suggests her Glossary
Can we trust Patreon? Patreon laid off its security team in September 2022. Patreon denied that it was the entire team, but they refused to say how many remain. An anonymous internal report said there was nobody left qualified to run their security tools. See Patreon security team layoffs cause backlash in creator
community by Tonya Riley (Sept 2022)
Safe Spaces:Transacting in Person with Strangers from the Internet by Brian Krebs (Sept 2022). When buying/selling things with strangers, there is always a risk that they are an axe murderer. Nearly all U.S. states now have designated safe trading stations - mostly at local police departments - which ensure that all transactions are handled in plain view of both the authorities and security cameras. Three websites have lists of these Safe Spaces: safetradespots.com,
safetradestations.com and safeexchangepoint.com
UPS When shipping a box via United Parcel, take a picture, with your phone, of the label they create and put on the box. Maybe also take a picture of the box before bringing it to their office. At my local UPS office their printer is miserable and the tracking number is all but impossible to read.
For home security cameras I suggest the $15 eBook Take Control of Home Security Cameras. I have not read the book but I know the author, Glenn Fleishman, is excellent. As of March 10, 2021, the last update was February 23, 2021.
Think twice before buying a Honda car. This article described one type of attack, there have been other types too. The reaction from Honda in every article is very disappointing. Hackers Say They Can Unlock and Start Honda Cars Remotely by Lorenzo Franceschi-Bicchierai for Vice (July 2022).
Concerned your phone has been hacked? Civilsphere, from the Stratosphere Laboratory and the Czech Technical University, offers a great public service: an Emergency VPN. If they accept your application, they will install a VPN on your phone and monitor the data coming/going for up to three days. Then they do a security assessment of what they captured.
Be very wary of files sent to you that you did not ask for. This applies on both desktop and mobile Operating Systems. Sometimes, just downloading them is enough to get infected with malware. Open these files on a Chromebook running in Guest Mode.
Kaspersky has an Online Privacy Checker that is not that. It is a static list of configuration suggestions for Instagram, Facebook, WhatsApp, TikTok, Twitter, Youtube, Google, Skype, LinkedIn, VK, Windows, macOS, iOS, Android, Edge, Firefox and Chrome. Each product has three levels of privacy options. The site is very slow and amateurish. There are no last update dates and it does not say which version(s) of the software it is targeting. Also, the navigation is confusing. The site copyright is 2021, so it may have already been abandoned. Not that it can't be useful. Here are some examples:
URL shorteners (aka link shorteners), such as bit.ly, Twitter's t.co and Flipboard's flip.it, hide the ultimate destination of a link. You can check where a shortened link actually goes at assorted URL expanders such as: URLEX or expandurl.net or unshort.link or linkunshorten.com or GetLinkInfo.com or
checkshorturl.com. Going a step further are urlscan.io and VirusTotal which offer opinions on whether the ultimate destination URL is malicious or not. In January 2020, Simon Frey (of unshort.link) introduced an extension for Firefox and Chrome that checks short links against a blacklist and prevents them from tracking you.
The website JustGetMyData is a directory of links for you to obtain your data from assorted services. It rates each company as to whether the process is easy,medium or hard. Easy: Google, Facebook, Apple, Tinder. Hard: Zoom, Microsoft, Adobe, Craigslist. A companion website, JustDeleteMe offers links to delete your account from assorted services. More: This Simple Tool Will Help You See What Websites Know About You by Matthew Gault of Vice (Jan. 2021). Michael Bazzell has a Data Removal Guide for removing your personal information from data broker and credit reporting services (Last updated April 2022).
Don't take computing advice from the mainstream media. Many reporters that cover technology are Art History majors that do not understand the stuff they write about. Thus, they often make bad Defensive Computing suggestions. For example, have you ever seen an article suggest using a Chromebook in Guest Mode when accessing sensitive/financial websites? I have not.
The more you know about DNS the better. My Router Security website has both a short and long explanation along with a list of websites that show your currently used DNS servers. Get in the habit of checking the active DNS servers, especially when traveling.
Before you use a new USB flash drive, plug it into a Chromebook running in Guest mode and format it from there. In the same vein, If you don't know where a flash drive came from, the only computer you should plug it into is a Chromebook running in Guest mode. Malicious USB flash drives are a common tactic for infecting the computers of people who have not read this website. Running Linux off a bootable CD/DVD disc is also a safe environment. However, a USB flash drive can also destroy a computer. The usbkill.com drive overloads the circuits, converting a computer into a paper weight. So, a low end Chromebook is probably best.
Speaking of USB, the cables normally carry both data and electricity. Data can be a problem, as it is an avenue through which a device can be hacked. Companies, such as Adafruit, PortaPow and SyncStop sell USB cables/adapters that only do power. They may be called Power-Only, Charge-Only, Data Block or a USB condom. The attack is called Juice Jacking (maybe Juice-Jacking). Without a power-only cable, you can still be protected by plugging into an electric outlet rather than a USB port. Or, use your portable charger, or, get a charge in a car. Also, don't use someone else's cable or charger. This excellent article USB Data Blocker Teardown (Aug 2020) explains three different types of USB data blockers. For an intro see
How to Protect Yourself From Public USB Charging Ports (Aug 2018).
There is a chance that the camera on a computing device could be activated without your being aware of it. The defense is old school: cover the camera lens with something opaque (band-aid, tape). Try to avoid adhesive directly over the lens.
Speaking of laptop computers, they have microphones that are typically impossible to mute. This article: Why your laptop's always-listening microphone should be as easy to block as your webcam (June 2019) mentions some models that can disable the microphone. My T series Thinkpad can. Laptops from Framework have hardware off-switches for both the microphone and webcam. They are also extremely repairable (Sept 2021). The
$200 PineBook Pro Linux laptop can also mute the mic. On macOS, you can install
OverSight to be warned both when the mic is activated and when something accesses the webcam.
Or, you can buy the Mic-Lock microphone blocker for $7 (as of Feb 2020). It plugs into the 3.5mm microphone/headphone port on a laptop, phone, or tablet and tricks the device into thinking that a microphone is connected. For more on this, see the Dec 13, 2019 episode of the Privacy, Security and OSINT podcast,
Camera & Microphone Blocking. In Windows 10, turn off the mic at: Settings -> Privacy -> Microphone. In macOS turn it off at: System Preferences -> Security & Privacy -> Privacy -> Microphone.
Whenever you are offered the choice to Login With Google or Login With Facebook, don't do it. iOS 13 will introduce a new competing system: Login with Apple. As of July 2019, it is too soon to form an opinion on it, but it will let Apple read your email, something they could not do without it.
A very sneaky trick that some websites pull is making third party cookies look like first party cookies. Everyone allows first party cookies so this lets you be tracked. The website trackingthetrackers.com tests for this and reports on it. Great service.
The Princeton IoT Inspector software only runs on macOS High Sierra and Mojave (not Catalina as of Feb 2020). It lets you spy on the IoT devices that normally spy on you.
At dehashed.com you can search for your physical address, email address, userid and/or phone number to see if they have been leaked in a data breach.
I read an article that said victims of Identity Theft should go to ftccomplaintassistant.gov and I wondered if that site was legitimate. That is, is it really from the Federal Trade Commission, a division of the US Government? We have already seen that just having "FTC" in the name means nothing. The FTC has their own website at ftc.gov, so why the need for another domain name? Instead of a new domain, they could (read should) have used complaintassistant.ftc.gov or ftc.gov/complaintassistant. Both leave no doubt that they are from the FTC.
On thing pointing to its being a scam is that the home page of ftc.gov has a link to identitytheft.gov for reporting identity theft. There is no link on the FTC home page to ftccomplaintassistant.gov. And, identitytheft.gov has its own assistant (identitytheft.gov/Assistant) which does not link to ftccomplaintassistant.gov.
Looking at the ftccomplaintassistant.gov site, the first thing to notice is that it does not have the extra identity assurance. If it is legit, that would be pretty ironic, eh? In techie terms the site is Domain Validated (DV) rather than having Extended Validation (EV).
All domains have to be registered and whoever pays for the registration can chose to make their identity public, or not. Looking up this information is called a Whois search and every company that registers domains offers a Whois search. However, this turned out to be a dead end. I could find no Whois information for any .gov websites.
A couple things point to the site being legit. There is a page on ftc.gov with consumer information about Identity Theft and it has a link to "File a Consumer Complaint" that goes to ftccomplaintassistant.gov. And, while the home page of identitytheft.gov has no links to ftccomplaintassistant.gov, an examination of the underlying html (i.e. page source) showed that pulls in a script from chat.ftccomplaintassistant.gov.
So, is it legit? I would have to call the FTC on the phone and ask them.
On a related note, ftccomplaintassistant.com is definitely bad news. That was an easy call.
Protecting Yourself from Identity Theft by Bruce Schneier May 2019. No good news here. Quoting: "there's nothing we can do to protect our data from being stolen by cybercriminals and others." True, but nonetheless, an easy out for anyone too lazy to do the things suggested here.
Speaking of reading, be aware that much, if not most, of the security and privacy advice offered in the main stream media is wrong. They hire reporters, not nerds. The New York Times, in particular offers sub-optimal computing advice.
Surveillance Self-Defense from the Electronic Frontier Foundation is pretty big. But, it was funded by the Ford Foundation and the funding may have run out. The News section was last updated Nov. 2018. A couple Windows 10 examples are based on Service Pack 1703. The oldest page I saw was last reviewed July 2018, the newest was Feb. 2021.
*Privacy Not Included evaluates the privacy of assorted products. From the Mozilla foundation, the company behind Firefox.
The Privacy Guides website is fairly extensive. It recommends software and services and also has configuration suggestions.
Personal Security Checklist by Alicia Sykes. A curated checklist of 300+ tips for protecting digital security and privacy. As of July 2022, it is actively maintained. Has a section on Physical Security. Too bad its on GitHub which is not meant for non-techies.
PrivacyTools.io makes software recommendations. However, there is nothing on configuring the software. Continually updated.
Security Guide by Maciej Cegłowski. Very short. Last updated April 2019.
Information security resources for laypeople by John Opdenakker is a list of sites competing with this site. This site is not included. Despite claiming that the list will be continually updated, the last update was Sept. 2019.
GetSafeOnline claims to be "the UK's leading source of unbiased, factual and easy-to-understand information on online safety." I heard a segment on BBC radio 4 about two people in England who were scammed out of money in their bank accounts. Both were interesting and useful stories. This was followed by advice from GetSafeOnline and the advice was, in my opinion, bad. I would look elsewhere for advice. Compare their advice for being safe on Public Wi-Fi networks to mine.
Watch Your Hack created by six professional hackers. More than just a checklist. Has a change log. Last updated Aug. 2021
securityplanner.org from Citizen Lab is a very mixed bag. For example, they recommend the Chrome browser. And, their trust in HTTPS is dangerously mis-placed. And they suggest installing Windows bug fixes ASAP which is clearly wrong. Last updated February 2020.
A Family Security and Privacy Review by Gabriel Fair. Last update Oct. 2020. Depressingly long list, just like this site. Just a checklist however, no additional information.
Digital Safety Kit for journalists from the Committee to Protect Journalists. Last Updated July 2019. This is much more a checklist than this site. In my opinion, the lack of context or background info makes these recommendations barely useful. The topic on encrypted email is really bad.
Security Planner from Consumer Reports was introduced in Oct. 2020. I am not impressed. For Windows, they suggest installing Windows bug fixes immediately, which is wrong. For web browsers, they are fine with using Chrome; I am not. For file encryption they suggest using one of the two options built into Windows. To me, VeraCrypt is the better option. They buy into the cult of password manager software as the only solution for managing passwords. I strongly disagree. The advice seems to come from people who read about technology but are not actual computer nerds. I am a computer nerd.
From the New York Times: How to Protect Your Digital Privacy. Yuch. Don't ever take computing advice from the New York Times. Really. That there is no date on this article is your first clue.
Whew! Seems like a lot, it is a lot.
All the credit/blame for this site falls on me, Michael Horowitz. If I left out anything important, or something is not clear, let me know at defensivecomputing -at- michaelhorowitz dot com.
2022: July 685 | June 379 | May 367 | April 328 | March 320 | Feb 315 | Jan 368 2021: Dec 293 | Nov 411 | Oct 315 | Sept 290 | Aug 275 | July 214 | June 227 | May 282 | April 246 | March 332 | February 377 | January 337 2020: Dec 332 | Nov 318 | Oct 333 | Sept 279 | Aug 282 | July 258 | June 267 | May 317 | April 296 | March 303 | Feb 377 | Jan 212 2019: Dec 200 | Nov 180 | Oct 194 | Sept 178 | Aug 176