Wednesday, May 16, 2012

The check is in the mail

CBS news Los Angeles has an interesting story about identity theft. A church reported its bank account information was stolen and used to counterfeit checks of $1,100. Detectives traced the ID theft to an LA couple "where they found hundreds of bank account numbers, fictitious and stolen IDs, check manufacturing equipment, identity profiles and counterfeit checks, according to officials." In total this couple had stolen more than $16,000 from 20 victims.

How were the bank accounts stolen? The couple admitted to dumpster diving at a Self Storage company "and stealing hundreds of partially-shredded checks, which they reassembled to access the routing and bank account numbers. Detectives say they used the information to manufacture more than 30 counterfeit checks" which they used throughout the region.

When you dispose of a check be sure that the routing numbers at the bottom are unreadable. You might cover it with a permanent black marker or tear the numbers into tiny parts and dispose of the bits in different places.

When the US Embassy in Iran was taken over back in the 70's the US diplomats dutifully dumped all sensitive documents into a cross-cut shredder. The Iranian government collected the shredded bits and gave them to their best carpet weavers who pieced the documents back together again.

So even a good shredder won't help you if you dump the bits in one place and a determined thief wants to put them together again. Try cutting checks in two or more parts along the routing number and shredding each part separately into a different bag.

Labels: , ,

Friday, February 10, 2012

I'd rather be phishing?

"Give a man a fish and you feed him for a day. Teach a man to phish and you feed him for a lifetime."
- paraphrasing a Chinese Proverb
Phishing is the act of catching unwary users of email and tricking them into giving personal information or clicking on a link for the purpose of installing malware or other nefarious actions. Phisherman are never so crude as to say, hey look, you don't know me but click here please. Instead they pretend to be someone you know having already stolen your friends email address book, or pretend to be a legitmate business that you deal with, or provide some incredible other that is too good to pass up.
  • Never open or reply to any e-mail when you are unsure of the sender.
  • If it is too good to be true - it is.
  • E-mails that appear to come from a known entity (like your bank, the government, someone from your old high school, etc), often are spoofed e-mails and do not come from them at all.  
    • If you see an e-mail from your bank - sign into your account directly from the official website - NEVER follow the helpful link they send you. That helpful link will take you to a fake website that will save your account # and password for later theft.
    • If you get an e-mail notice from the government about your tax info, think about it. How did they get your e-mail address? And the IRS does not use email; they send you a nicely registered letter requesting your presence at an audit.
The internet is seeing a continuing dramatic rise of e-mails designed to fool you into action; and it does work or they would not be doing it.  Some of the most recent tricks are:
  • Notices of copyright/trademark infringement
  • Notices from the BBB about a complaint
  • Notices from banks requesting an update of some kind or another
  • Notices about problems with an electronic check/deposit (ACH)
  • Notices from the Government looking for you to update your tax data
  • Notices about problems with your tax return 
  • E-Mails from old friends (they get that data from Facebook, Linkedin, etc, etc...)
  • E-Mails asking you to help a friendly prince get his inheritance out of a country controlled by an unfriendly tyrannical government
  • etc, etc, etc...
Bottom Line

This is nothing new - just a reminder to practice safe computing. Below is a screenshot of e-mail quarantined by one person in one morning; you can clearly see  examples of phishing.

Labels: , , , ,

Wednesday, January 25, 2012

The Top 25 Worst Passwords

"To err is human, to really foul things up requires a computer."
~Bill Vaughan, 1969
Web site Internet Crime Complaint Center's (IC3) and other sites have published a list of the worst passwords. A study was done on a list of millions of stolen passwords posted on-line by hackers and here are the top 25 passwords found in the list.

1. password
2. 123456
3. 12345678
4. qwerty
5. abc123
6. monkey
7. 1234567
8. letmein
9. trustno1
10. dragon
11. baseball
12. 111111
13. iloveyou
14. master
15. sunshine
16. ashley
17. bailey
18. passw0rd
19. shadow
20. 123123
21. 654321
22. superman
23. qazwsx
24. michael
25. football
Bottom Line

If you use any of these passwords, change it now. Here's some advice on creating a good password:
http://perpetualpreparedness.blogspot.com/2011/05/passwords.html

Labels: , , , ,

Monday, November 7, 2011

When to Call your Credit Card Company

Remember that credit is money
- Benjamin Franklin
MSN Money suggests there are seven occasions when you should always call your credit card company.
  1. When a new card arrives - most cards require a phone call to activate a new card
  2. Unauthorized charge - if you see something on your credit card statement that does not make sense, call immediately. ALWAYS review your credit card statement line by line. You might have been enrolled in some monthly fee program by visiting a web site or responding to a text message on your phone. Or it could be fraud or identity theft. Years ago a restaurant changed the amount of the tip on my card to a higher value. That is illegal.
  3. Lost card - If you're not sure where your card is it's safer to have it canceled and a new card number assigned.
  4. Stolen card - call immediately to get the card canceled. File a police report and also notify the credit rating bureaus.
  5. Change of Address - don't make the mistake of letting your bank and card statements go to an old address and into someone else's hands.
  6. Missing credit card statement - if your monthly statement does not arrive on time, call. Someone can do a lot of damage if they steal your statement which contains card number, name, address, etc.
  7. Before a vacation or big purchase - companies monitor cards for unusual activity and may shut it down if they suspect fraud. We have a friend who now lives in Florida but rents out his prior home in New York. While visiting New York to make house repairs, his card company froze his account because of all the "unusual activity" in New York. Before I traveled to Canada this summer I called my credit card companies to warn them about my travel plans. (And to find out their money conversion fees.)
Bottom Line

Credit cards are great to have when used responsibly. Card rates are outrageous so this is not the best way to obtain a "loan" when you're short of cash. Never pay just the minimum suggested - pay more, pay it all if you can.

Labels: , , , ,

Thursday, November 3, 2011

How to Avoid Fraud after a Storm

“There is no recourse against hiring an unlicensed contractor. We're not saying anything about the good companies that come in to make a decent living, but unfortunately, there are the bad ones that try to come in and suck people's insurance checks and move on.”
- Larry Johnson
Last month FEMA published an alert about identify theft fraud after Tropical Storm Lee hit New York. Residents in Tioga County had encountered a potential fraudster canvassing neighborhoods claiming to be a “financial consultant” doing a survey for FEMA in a bid to obtain personal financial information.

FEMA notes that
Many legitimate persons -- insurance agents, FEMA Community Relations personnel, local inspectors and real contractors -- may have to visit a storm-damaged property. Survivors could, however, encounter people posing as inspectors, government officials or contractors in a bid to obtain personal information or collect payment for repair work. Your best strategy to protect yourself against fraud is to ask to see identification in all cases and to safeguard your personal financial information.
Be suspicious of anyone who:
  • Has no proper identification (a shirt or jacket saying FEMA or some other org is NOT enough). Ask to see their photo laminated card.
  • Wants your personal financial information
  • Asks for cash to fill out a form or for an inspection.
  • Demands cash or full payment up front for home repairs. Won't provide a contract.
  • Is a contractor with no physical address on their card.
  • Urges you to borrow to pay for repairs, then steers you to a specific lender or tries to act as an intermediary between you and a lender.
  • Urges you to use a contractor they recommend
  • Asks you to sign something you have not had time to review.
To avoid scams:
  • Question strangers and demand to see identification
  • Never give any personal financial information to an unfamiliar person
  • Never sign any document without first reading it fully. Ask for an explanation of any terms or conditions you do not understand
  • Do your own research before borrowing money for repairs. Compare quotes, repayment schedules and rates. If they differ significantly, ask why.
Bottom Line

For more information about avoiding charitable giving scams, visit the Federal Trade Commission’s website at http://www.ftc.gov/opa/2011/05/homerepair.shtm

Labels: , , ,

Tuesday, August 23, 2011

Online Photos

I got a Nikon camera
I love to take a photograph
So mama don't take my Kodachrome away
- Paul Simon lyrics to Kodachrome
US News asks, "Is It Safe to Post Photos Online? It's a wonderful thing to share photos online but those photos can also be stolen and misused. Imagine your face used in an online dating service by someone not blessed with your good looks. Will friends believe you when you say, "But that's not me!"  Or your photo used by an advertiser without permission.

1. Check your online privacy settings.
Never allow everyone access to your photos. Restrict them to friends only.


2. Make sure you know who your friends are.
I have over 200 connections on LinkedIn. Are all these people really my friends? Do I trust every one of them? Consider de-friending anyone you don't trust 100%.

3. Disable the GPS technology before taking photos with a smartphone.
Even regular cameras are starting to apply GPS data to digital photos. When you post a photo with GPS data embedded, anyone can know where the photo was taken. Fun perhaps for a vacation photo but risky if the photo was taken at home.

4. Watch out for lower-tech ways of sharing too much personal information.
Your child's T-shirt could contain a school logo. Blur out your car license plate in any photos you post.

5. Don't post embarrassing photos.
Once posted, items on the internet may never die. Even dead websites can be brought back to life with http://wayback.archive.org/web/ or Google cache. Photo facial recognition is getting more and more powerful so in a few years it may be trivial for anyone to find online naked baby photos that match an adult face.

6. No means no.
If a friend or relative posts photos of your child and you don't want them to, ask them to take them down. If they refuse, some sites allow you to flag a photo as objectionable and taken down at your request.

7. Use a watermark.
Watermarks can be visible or invisible and will help prove that you own a photo if it's stolen and makes millions of dollars selling coffee. A watermark is an image or text that is mixed into the image itself.

Bottom Line

Share with friends but protect your photos.

Labels: , , , ,

Tuesday, August 16, 2011

10 Things You Shouldn't Keep in Your Wallet or Purse

What's in your wallet?
-Capital One slogan

Fox Business News lists 10 Things You Shouldn't Keep in Your Wallet or Purse.

1. Social Security Card
With your Social Security card a thief could open a credit card, apply for a loan, or even buy a car with the information. Memorize the nine digits instead.

2. Your Passport
A passport is a must if you're traveling internationally, but leave it in the hotel safe. When abroad, carry a photocopy of your passport for identification. "If you lose your passport or get mugged in a foreign country, it's such a horrible hassle. You have to go to the embassy, and it's a vacation nightmare."

If you're traveling in the U.S., carry only your driver's license.

3. Passwords/Pass codes
"If you store any type of ATM password or even a code for your home alarm in your wallet, you have basically gifted a thief with access to your life." If you must write them down, enter them in backwards or add one to each number so that 1234 becomes 2345. Use some kind of a code to alter the number that you will remember.

4. A Non-Password Protected Phone
Some smart phone applications allow instant access to bank accounts, PayPal accounts, medical records, and more. Even email on an unprotected phone could give a thief way too much information. Be sure to password protect your smart phone AND don't carry that password on you.

5. Your Checkbook
A checkbook has your bank account number and routing number on it, and your address.

6. Too Many Credit Cards
If you carry every credit card you own and your wallet is lost or stolen then you'll have to cancel every one. If you leave at least one card at home (in a safe place) you'll have a card you can use when the others are gone. Also make sure you keep photocopies of the front and back of each card at home; the back of most cards carries the 800 number for reporting a lost or stolen card.

7. Too Much Cash
Carry only as much cash as you're willing or able to afford to lose.

8. Gift Cards/Certificates
Gift cards and gift certificates are just like cash -- they don't require ID for use.

9. USB Devices
USB devices can be bad news in the hands of thieves if they contain confidential files.

10. Receipts
Some receipts have your credit card information on them, as well as your signature, which thieves could do a lot of damage with.

Bonus Item:
"It may sound silly, but if you're changing earrings ..., it's very possible you may forget and toss these things in the zipper compartment of your wallet. It would be horrible to get your wallet stolen any day, but if you're also losing your grandmother's earrings ..., it's even worse!"

Bottom Line

What's in your wallet? Does it contain anything besides a drivers license that a thief can use to steal your identity?

Labels: , ,

Wednesday, May 4, 2011

Is your phone spying on you?

And (I always feel like)
(Somebody's watching me)
And I have no privacy
- lyrics, Rockwell, "Somebody's Watching Me"
The Guardian.Co.UK reports that,
"Security researchers have discovered that Apple's iPhone keeps track of where you go – and saves every detail of it to a secret file on the device which is then copied to the owner's computer when the two are synchronised. The file contains the latitude and longitude of the phone's recorded coordinates along with a timestamp, meaning that anyone who stole the phone or the computer could discover details about the owner's movements using a simple program"
And this is apparently legal. Near of end of the iTunes license (which no one reads), is a paragraph that grants permission for "location-based services."
"Apple and our partners and licensees may collect, use, and share precise location data, including the real-time geographic location of your Apple computer or device. This location data is collected anonymously in a form that does not personally identify you and is used by Apple and our partners and licensees to provide and improve location-based products and services. For example, we may share geographic location with application providers when you opt in to their location services."
So far only the iPhone is known to keep a location record on the device itself. However all cell phones leave a history of your travels as you move from one cell tower to another. We trust the cell phone companies to keep that information private and only release it to the police with a court order.

Bottom Line

In the modern world, total privacy is impossible unless you give up credit cards, ATM machines, cell phones, Internet and just about every other modern convenience. Still it is important to know what information about yourself is being collected and how it is being used. This is why I recently advised my father not to use Facebook. It has a history of violating privacy protocols or enabling vendors to violate privacy with your information. Facebook is fun to use but you must be very careful with what you share and expect that anything you post may leak out. For my part I "blur" the data I post by moving my birthday a few days or picking the town next door as my residence. Close enough for friends but incorrect for identity theft.

Labels: , , ,

Tuesday, March 1, 2011

What to Shred

"I am he as you are he as you are me and we are all together."
- I am the Walrus, lyrics
Identity Theft is a terrible crime. A person can not just steal all your money, but leave you deep in debt and destroy your credit rating. As a Consumerist article notes,
"Leaving a building with a file folder with documents in it is a lot more innocuous if a third party sees them than if they're walking out of an apartment holding a TV or a DVD player. And the long-term payoff is a lot more"
At home we shred any junk mail or junk mail envelope that has our name on it. Especially shred credit card unwanted. applications. Shred old bills from doctors and documents outlining medical benefits to prevent others from using your insurance.

If you lose your wallet, call your insurer and let them know. Also call the police, your bank, every credit card, and the credit history companies. Without your wallet, how quickly can you find out what credit cards you carry and your ID number for each?  Never carry your Social Security card in a wallet or purse.

Beware also of high tech ID theft. If you do online banking at a public Wi-Fi spot, you could have your account and password stolen. Password protect your smart phone.

Bottom Line

Here are two sites for what to do if your identity is stolen.
http://www.ftc.gov/bcp/edu/pubs/consumer/idtheft/idt07.shtm
http://www.privacyrights.org/fs/fs17a.htm

Labels: ,

Friday, November 19, 2010

ATM Scams

"Consider this: I can go to Antarctica and get cash from an ATM without a glitch, but should I fall ill during my travels, a hospital there could not access my medical records or know what medications I am on." - Nathan Deal
Hopefully you're aware of ATM skimmers. I'll discuss them below but thought I would start with a low tech way to lose money at an ATM. San Francisco police caught a crook who stuffed napkins into ATM cash dispenser slots. When people tried to withdraw cash, it would get stuck behind the napkins. After they walked away frustrated, the crook dislodged the napkins, and walked away with their cash.

If your ATM money does not come out reach up into the slot and see if there's anything stuck there. If that fails, take a cellphone picture of the ATM screen for evidence and then call the number on the ATM for service or go inside the bank for help.

Now back to skimmers. These are devices designed to steal your card information and pin. Check out the photos at http://www.snopes.com/fraud/atm/atmcamera.asp and http://consumerist.com/2009/04/heres-what-a-card-skimmer-looks-like-on-an-atm.html

There are two things to worry about.

1. A camera that records the PIN you type in. At the snopes link above the camera is hidden inside a pamphlet holder next to the ATM (pictured above). At the consumerist site the camera is in a strip attached to the ceiling.

2. A card scanner attached to the ATM. At both sites the extra scanner is part of a panel affixed to the ATM and look absolutely authentic!  At this site, http://gizmodo.com/5453857/atm-card-skimmers-are-getting-frighteningly-sophisticated, the skimmer is quite thin and covers the card reader.

Bottom Line

What can you do to protect yourself. Not much I'm afraid. Try to cover your fingers as you type the PIN from prying eyes or camera. Use the same ATM and remember what it looks like. If anything changes on the outside of the machine, ask the bank before using the machine.

Any card scanner could be stealing information - at restaurants, gas pumps, grocery stores, etc. If money is stolen report it to the bank and file a police report.

Labels: , , , , ,

Wednesday, November 10, 2010

Privacy

"Relying on the government to protect your privacy is like asking a peeping tom to install your window blinds."
-John Perry Barlow

Many people are concerned about their privacy being violated by the Internet. Information about you is collected and sold in ways you might not be aware of. For example, if you unsubscribe to a spam email then you've just told them that the email is an active account reaching a live person. They can sell that fact to other spammers.

dailyfinance.com reports on other agencies that collect information about you in Who Is Watching You?

The IRS "knows everything about what you earn and any major transactions you make. It can access every bit of information it needs to determine how much money" you owe in taxes.

The FBI "keeps a database of over 90 million fingerprints, ... It also has an extensive database of DNA, [since 9/11] It now tracks a large portion of mail, cell phone traffic and Internet activity of people it deems suspicious.

The article also list 9 industries that collect personal information ranked by the number of people they track.

1. Credit Rating Agencies: Equifax, Experian, and TransUnion
2. Cell Phone Service Providers
3. Social Media Companies (Facebook)
4. Credit Card Companies
5. Search Engines (Google)
6. Retail Chains (Walmart)
7. Casinos
8. Large Banks (Bank of America, Chase, Citibank)
9. Life Insurance Companies

Bottom Line

Visit the full article for details on how each company is recording what you do. It's quite scary.

Labels: , , , ,

Tuesday, April 27, 2010

Online Privacy

“Privacy is not something that I'm merely entitled to, it's an absolute prerequisite.” - actor Marlon Brando

While I really like Facebook, you do have to be careful with the information you share and who you share it with. Some people I think go too far and lock down all information so all I have is a name and no clue if this person is my long lost friend from college or not. Other people publish everything about themselves to the world, their birthday, where they live, etc. That is too much sharing. I restrict that level of detail to just my “confirmed” friends. My public profile shows my workplace, my “town”, the colleges I attended, and a single photo carefully chosen.

Many websites (like games I play) ask for a birthday, so I’ve created a new one of January 1 with the year rounded down to the nearest decade. That won’t do on Facebook since friends want to celebrate my real birthday. So I entered a date that is near but slightly off. The town I list is the township I live in, not the smaller village jurisdiction.

Am I being paranoid? Perhaps not. There is a new company at http://www.spokeo.com/ that uses Facebook and other online data to build individual profiles. The amount of information they had on me was disturbing – my actual village, my house value, my age and birthday month, married, number of kids, etc. And this was the “free” display. If I paid I could have seen even more details (or so they claim).

Type in your name and see what comes up about yourself. If you have a common name, try [name], [city], [state].

Bottom Line

The good news is that Spokeo supports privacy requests. Go to www.spokeo.com/privacy and put in the URL of “your” page on their site. Then give them an email address (you could create a temporary email for this). Within seconds I had an email, clicked the response and immediately my name disappeared from their search results.

Labels: , , , ,

Wednesday, August 12, 2009

Don't Share Personal Information

“Money isn't everything - there's also credit cards, money orders, and travelers' checks”

A few nights about I called my credit card companies and each one required that I answer the official security questions. What is your zip code? What is your card number? What is the mother’s maiden name for the primary cardholder? This last one is kind of tricky since I can never remember if the primary cardholder is me or my wife.

Sadly as security goes, the official questions are quite lame. Any store employee can steal your card number. Zip codes can be found via Google with person lookups. Mother’s maiden name could be found on ancestry.com or through a friend of the family.

What can your do?

  1. Ask for different security questions. Some sites let you choose your question or write your own like, “You’re first pet’s name”, or “Your first friend”.
  2. Make up an imaginary maiden name. You do not have to use your real mother’s name but you do have to remember the alternative you give.

Bottom Line

When teens, children (even adults) surf the Internet they should be taught that there is some information that is never shared on facebook, blogs, etc.

  • credit card number

  • social security number

  • mother's maiden name

  • debit card number and PIN

  • bank passwords and logins

  • internet account passwords

The end of my post Espionage has details on creating strong passwords.

Labels: , , , ,

Wednesday, February 11, 2009

Personal Information

“In a real estate man's eye, the most expensive part of the city is where he has a house to sell” - Will Rogers
Any time you fill out forms with personal information you run the risk that that information will be misused or lost. A recent story said that Monster.com had its data base hacked and the passwords and personal data stolen for all its customers.
And today I see this story about a real estate office that dumped old records in the street.

What are those papers blowing down Columbus Avenue? Why, those are your tax returns, driver's licenses, credit reports, bank statements, and 401k statements. It seems that the real estate company, Citi Habitats, dumped an entire years worth of sensitive client documents in the streets of New York. - ABC7 News

Bottom Line

The real estate office claims that the papers were disposed of improperly due to their offices being renovated. But that is just a lame excuse for a serious lack of fiduciary responsibility. Don't expect others to keep your information safe.

Labels: ,

Wednesday, October 8, 2008

A Stormy Vacation

While the Caribbean is the "most feared" hurricane-season destination, 64% of travelers said they would be willing to visit a destination in the hurricane zone if it meant significant savings.
- Robert's Caribbean Travel Blog

If you like traveling, check out the article Part of vacation planning includes Emergency preparedness plans! by Terrie Modesto on the blog "Train For A Hurricane". The author points out that many travelers will visit the Caribbean during Hurricane season and sometimes you get caught in a foreign country with a storm headed your way. This happened to a friend of my wife during his honeymoon.

Do you have trip insurance? Will your hotel stay open or force you into a shelter? What is your airline's policy for getting you back home? Very likely you'll be on space available standby and it can take days to obtain available seats with no guarantees.

Bottom Line
Preparedness is not just for home. If your wallet/ID/passport are stolen on vacation, do you have photocopy backups in your suitcase? You will find it very difficult to get money and board a plane with no ID.

If someone gets sick do you know your insurance company's policy for doctors and hospitals while away from home? Do you have to call to get approval prior to treatment or find a doctor within your plan? If you are traveling outside your home country, call your insurer before you leave to find out the rules for coverage in a foreign country.

Labels: , ,