Showing posts with label passwords. Show all posts
Showing posts with label passwords. Show all posts

Saturday, January 26, 2013

Beware of Keyloggers




Computer Care: Watch for keyloggers that can steal your password



Arthur_Glazer

POSTED: December 1, 2012 1:00 a.m.

My wife logged on to her eBay account early one morning this week to discover she had sold two Wii units to someone in South Carolina. Normally this would have been a good thing, except for the fact the she sells clothes online, not electronics.

She had been hacked. Somehow, without her knowledge (or permission), her computer had a keylogger installed on it. This allows whichever low-life who installed it to see what she types — passwords, bank account and credit card numbers included.

So without even a cup of coffee in her yet, my wife was on the phone to eBay customer service, Paypal and then our bank. It was not the way she wanted to start the day, and that was only the beginning. We had to discover what, if anything, else had been sold from her account, what money had changed hands and what else had been compromised. It was to be a long morning.

My wife and I have both bought and sold on eBay through PayPal, since it showed up on the Internet almost two decades ago. Although many people tell us they are skeptical about purchasing from an online auction site, we have experienced very little trouble in the 17 years we have been dealing with it.

They usually side with the buyer, rather than the seller. Unless you have lots of documentation and a good case to present, you’re in for a battle to get your money back being an online vendor.

As a merchant some years ago, I was taken for a couple of hundred dollars by a scammer who claimed my shipment was never received. I shipped without asking for delivery confirmation at the time. Not only did I lose the merchandise, I was forced to refund the money.

In the days following, I determined this person had scammed a dozen other eBayers similarly. Unfortunately, PayPal saw no pattern so I never got my money (or merchandise) back.

Live and learn. I believe in karma and figure soon enough this reprobate either got caught or was a victim of a scam himself. One could only hope. But I digress.

Keylogging, or keystroke logging, as it is also known, is a form of malware, or more specifically, spyware. There are various incarnations of this type if infection, each one recording what you type on your keyboard, each just as difficult to detect and remove as the next.

Your keystrokes are recorded as a log or text file and emailed back to the hacker. At this point he has your passwords, banking information and anything else he may want to steal from you.

The thing to do if you get hacked, especially with a keylogger, is to first change your passwords. This is a prime example of why one shouldn’t use the same password on multiple (or all) accounts. If you do, then go change all of your passwords, which isn’t a bad idea anyway if you know a keylogger was installed on your system.

Choose a difficult one with at least eight characters, including numbers and symbols. Avoid the obvious like addresses, birth dates and pets.

Next call your bank and look at your withdrawal history. Even have it flag your account to notify you of suspicious activity. Also call PayPal if you deal with online auctions and have an account with it.

Unfortunately, you won’t get much help from your ISP, which will say it’s all on you and to call your bank.

Last and certainly not least, clean your computer. You are infected. Run whatever security package you have on your system. If you don’t have one, now is the time to get one. As I’ve stated before, most antivirus programs just look for viruses. This is not a virus and your dedicated AV utility may not look for nor find keyloggers.

Run full scans and allow the malware utility to remove or quarantine any infections as it sees fit. Reboot your computer when all is done to be sure the infections are removed.

Do not ignore this. It will not go away on its own. It will cause you grief you do not want to experience. Keyloggers will take hold of your computer, then your money and your identity. They make pop-ups seem like a walk in the park.

Even if nothing happens immediately, don’t fall into a trap of false security. They have your personal information and are just waiting to use it. The faster you react, the better.

Keylogging can be beneficial and legal in certain applications and can also come as hardware attached to a computer. But most often it is installed clandestinely to steal financial information.

As unfortunate as this was for my wife, it did give me something to write about for this week’s column and warn you of the pitfalls of keyloggers.

Don’t let it happen to you. It’s imperative that you take action immediately, should a vicious infection like a keylogger attack your system all of a sudden one morning.

Arthur Glazer is a freelance writer and computer technician in Gainesville. His column appears biweekly on the Business page and on gainesvilletimes.com.

Password Security





Computer Care: The password is ... Best bet is to mix it up




POSTED: October 19, 2012 11:59 p.m.
Passwords are part of computing; there is no way around that. If you use a computer and the Internet, you will eventually need to use them. You may or may not need a password to log onto your computer, but one was needed to get your email this morning. Even if you didn’t have to manually type one in, your computer recalled it for you.

I use a password manager and also allow Google Chrome to remember my passwords for me. There are 15 or so of them that I refer to on a regular basis to access various websites like email, my cloud storage, Amazon and other ecommerce sites that I frequent.

There are also banking PIN numbers, alarm keypad codes and wireless router keys which are forms of passwords. You may use one to gain entry to your smart phone.

Call them what you will, but any series of alpha-numeric codes you use to access something secretly is a password.

There is no easy way for most of us to remember all of those codes, especially when choosing different ones for each site or application.

If you use the same password for all of your websites and accounts, all could be compromised if just one is. So why take a chance?

The poor choices are the obvious ones like your birthday or anniversary dates, your street, pet or your children’s names. Don’t choose the easy options. Stir it up a bit.

Spell out anything that you can remember. Chocolate chip ice cream with chocolate syrup becomes ccicwcs; then add a number or symbol or caps. The end result could be CCiCwCs9*.

Stir things up even more; spell things backward. A. Jones becomes senoja, then add numbers, caps or symbols to spice it up, like senojA5#. Be creative.

Instead of your dog’s name, try using mydogbubba. Add caps or symbols for even more security as in mydogbubbA*7 or shorten it to dogbubbA*7. Backward, bubba becomes abbub.

While on the topic of passwords and email, spam is something we all unfortunately get with email. One of the easiest ways to get spam is by having your email address sold to online merchants. The best way to avoid that is to be careful to whom and where you use your email address.

Many times when you subscribe to a newsletter or sign up for something, it’s stated your address won’t be sold. Often times though, it is. That’s where most spam originates.

One way to avoid this is to create secondary additional Gmail, Yahoo, Hotmail or other accounts that you won’t regularly check or only to verify a subscription that you just signed up for. When the inbox is full on this throw-away account, just sign up for another.

An alternative is to use a Disposable Email Account. I use yopmail, but there are many others to choose from.

They include Dispostable, Dudmail, MailExpire, DeadAddress, Spamex, Incognito Mail, Dodgeit, Yopmail and Mailinator. All work basically the same way. You create a name, they offer an extension and a duration with most adding the ability to check the account for incoming mail.

Sometimes you can get away with simply making up an address with a nonexistent domain and have it work. I’ve used xyz5@abcmail.com, but if a response is required, then that strategy won’t work.

Recently, I signed up for a free sample online that required me to click on a link in an email to verify my address. Using yopmail, I created an address on the fly and checked it from their site (the same page I used to create it) a few minutes later. There was the link.

You don’t need to commit anything to memory; just create a new name next time you need a DEA.
Remember to change your passwords regularly. Use password managers like LastPass, Roboform or Password Safe to help you recall them. Although less secure, you could simply allow your browser to remember them for you.

Visit pwnedlist.com to see if your email address has ever been hacked.

Choose passwords that are unique for every account, not the same one for all of them and give them to no one.

The longer the better. Use at least eight to 10 characters and mix them up with caps, numbers and symbols.

There’s a password generator at random.org if you have trouble on your own.

Don’t fall for phishing scams. Beware of any emails or websites asking you to provide sensitive personal information. Not even your bank will ask you for your password.

Avoid using addresses, birthdays or dog’s names.

To circumvent spam effectively, use disposable email accounts.

The end result will yield higher security for your accounts with less paranoia about being hacked.
As easy as it has become these days to have your privacy compromised, you want to make it as difficult as you possibly can.

Arthur Glazer is a freelance writer and computer technician in Gainesville. His column appears biweekly on the Business page and on gainesvilletimes.com.

Monday, May 25, 2009

Creating Passwords That Work


Computer Care: Complicated passwords will keep you safe

By Arthur Glazer
arthur@glazerthepctech.com
POSTED April 10, 2009 9:52 p.m.

The easiest forms of passwords are your children’s names, perhaps your pets, your address or birthday. But guess what? They are the most common ones and hackers know that. They will try those first. With just a little research your password is broken and your security is gone. Fluffy1? I don’t think so.

So what is a good password? I’m glad you asked.

First, don’t use a universal password. If a hacker guesses one, he gets them all. Use different passwords for different things.

Next, change them on a routine basis. Keep the hackers guessing. If you can’t remember them, use a password manager, but we’ll get into that in a moment. But by no means should you have sticky notes framing your monitor with your secret names on them. It’s like writing your PIN on the back of your debit card.

Change the temporary password that you’re given by your ISP, bank or router software. Don’t keep 0000, Admin or password as your password. It’s just not a good idea. Sure, it’s easy, but you know someone other than you already knows it.

Last, but equally as important, use at least eight characters (some say 10-14) and mix them up. By that I mean use upper and lower case letters, as well as numbers and symbols. It makes hacking that much harder. The password RenruT*63 is infinitely better than mykitty or fluffy1, and gives your computer a considerable defense.

RenruT, you ask? This is what I like to do. Use acronyms that make sense and spell things backwards. Then, top them off with numbers and symbols. If your name is Turner and the last two digits of your address or birth year is 63, you could safely (until now) use RenruT*63. It’s strong and easy to remember.

How about Wolfe? It becomes Eflow or efloW and spiced up could be EfloW#87, a strong password. Of course, the longer the word is, the stronger the security.

Alternatively, you could make up sentences and remember the abbreviations. Try something like, MdLiaAS11#, which for me translates to: My dog Lola is an Australian Shepherd, eleven years old. It’s a 10-character password using upper and lower case letters with numbers and symbols.

Mbhind2#5911 could be, "My brown house is next door to number 5911." Whatever works for you. Be creative. Make it something you can recall, but mix it up. No password is totally secure, but some are obviously better than others.

For those who have trouble remembering, there are password managers. You could let it do all the work for you and to make it secure, have the manager itself be password-protected. This way you would have only one word to remember.

Go to www.roboform.com and check out their product. I’ve mentioned this one before; it’s a good one. Roboform is a password manager that also fills in forms for you. When you get to a web page that requires a secure login, it jumps into action by signing you in. Should there be a form to fill out, it will type your name and address as required. How cool is that?

The free version is good for 10 different web sites, with no time limit. For more than that you’ll have to purchase it. The paid version ($30) is for an unlimited number of sites. You could also have it generate random passwords for you, and then have it remember them.

There are others on the market, some included in utility suites. Go to www.download.com and initiate a keyword search for "password manager."

Having a strong password plays such an important role in computing, now more than ever. There are people out there whose job it is to get your personal information. If they don’t use it for themselves, other people pay them for that information.

Your bank or ISP will never call or e-mail you and ask for your password. If it does happen, it’s a scam. Tell them nothing. If you aren’t careful, your bank account could be cleaned out before you even realize it. Not only would you lose your money, but the bad guys will probably never get caught.

It’s not just your bank account either. If someone hacks your eBay account and bids on something under your name, you bought it if they are the high bidder.

Think of all the passwords you have. They are all protecting something.

Even an online forum that you joined could be suspect. Someone disguised as you could leave a comment that could damage your reputation or that of someone else.

There’s no end to the damage that could be wrought. All it takes to prevent it is a clever eight digit code.

So remember, Jusp2bso! (Just use strong passwords to be secure online!)

Arthur Glazer is a freelance writer and computer technician whose column appears biweekly and on gainesvilletimes.com.