Thursday, February 19, 2015

I've Been Hacked! - Part 2

With all the high-profile data breaches recently, it is a good idea to have a plan of action if your account is compromised.  I know for a fact that my information was compromised in two recent breaches:  the Chase breach revealed late last year and the Anthem breach announced earlier this month.  Knowing what to do if your information is exposed will greatly reduce your stress and hassle as you try to keep yourself safe.

As I mentioned yesterday, the first step is to learn exactly what was stolen.  The proper response to these breaches will vary based on what data was compromised.  You don't need to pay to completely freeze your credit if an attacker only got your address and phone number.

In order to keep these tips to a manageable length, I am splitting up my suggested responses based on what information was compromised.  In part one, I discussed what to do if your username, password, or other contact data is breached; today's part two contains what to do if your credit card or bank account number is stolen; and part three will list actions to take if your social security number is compromised.

Part Two:  Credit Card or Bank Account Information Stolen:

Obviously, this is much worse than just losing your password, but unlike a social security number, these account numbers can be changed to stop fraud.  Most of these suggestions will deal with a compromised credit card number, but they are equally applicable to a stolen debit card or bank account number.  If your credit card or bank accounts have been a part of a breach, here are some steps to take:

1) Contact Your Bank - If you have even the slightest suspicion that your credit card number may have been involved in a hack, contact your bank right away using the 24-hour number printed on the back of the card, even if there are no suspicious charges.  This serves two purposes.  First, your bank will examine your transactions more carefully for signs of fraud.  This may help them catch transactions that might not have been flagged otherwise.  Second, your bank may decide to go ahead and issue you a new card, even if your card has not been used.

As a side note, it is a good idea to store the bank's contact number in your phone in case your card is ever lost.

2) Follow Up - While the phone call is a good first step, you should always follow up your phone call with a letter.  Make sure to include the date and approximate time of the call, the name of the agent you spoke with, and the matters you discussed.  Make a copy for your records, and record the date you put it into the mail.  If you want to be extra vigilant, send it using priority mail with a tracking number, and record the tracking number and a copy of the website information showing that it was delivered.  It is fine to discuss business over the phone, but if you want to have a legally-provable way to show what you discussed, it needs to be put in writing.

3) Monitor All Your Accounts - You have no way of knowing for sure how the attackers got your credit card number.  If you know your card was used at a company that was breached, you can be relatively confident it came from that attack, but it could have come from spyware on your computer, instead.  If one account is compromised, be extra vigilant in monitoring your accounts for the next few months.

4) Accept--But Don't Blindly Trust--Credit Monitoring - If a company offers you free monitoring in the wake of a breach, sign up for it!  They will help keep an eye out for suspicious activity and can even complete much of the process of reversing damage that occurs.  They can also give you excellent advice on what to do in the event your card is used or your identity is stolen.  However, do not allow credit monitoring to take the place of personal vigilance with your accounts.  Keep a close eye for unusual activity on all your accounts.  Attackers will also know how long the monitoring will last, and they may decide to sit on the data for the 1-2 years your credit is being monitored, and then use it once the free credit monitoring has expired.

5) Consider Contacting the Credit Bureaus - Contact one of the three credit bureaus (Experian, TransUnion, or Equifax) and ask that a fraud alert be placed on your account.  (This is a completely free process.)  This will notify prospective lenders who run your credit that you suspect you may have been a victim of fraud, and it will also prevent certain types of accounts from being opened without contacting you directly.  All three bureaus have online forms where you can submit the information, or you can also contact them by phone.  The three bureaus will share the fraud alert information with each other, but if you have the time, it never hurts to notify each one individually.

While you are there, it would be a good time to request your free credit report from each organization if you haven't received one in the past year.

6) Beware of Scams - Obviously, this one applies no matter what has been compromised.  Attackers will always be on the lookout for ways to trick people into giving up their personal information.  After a breach of any kind, there will be a multitude of phishing emails going out pretending to be the breached company.  Make sure you don't fall victim to these scams and add to your headache!

Wednesday, February 18, 2015

I've Been Hacked! - Part 1

It seems as though we are constantly hearing about new data breaches at various companies.  Usually, by the time the media has exhausted its coverage of one breach, there is a new breach revealed for the media to cover.  While the media has done an excellent job at keeping everyone up-to-date on where these breaches have occurred (and who has been affected), we hear very little about what to do if your information is stolen.  Most of the time, companies respond by offering identity protection--certainly a benefit you should accept--but identity protection will only help you clean-up after your information is used.  There are many more concrete steps you can take to protect yourself after you learn of a breach but before your information is used.

I have personal experience as a victim of several recent data breaches.  I shopped at Home Depot during the period where their systems were compromised, but I only shop there occasionally and generally pay in cash, so I cannot say with certainty that I was a victim of the Home Depot hack.  However, my information was compromised by the Chase hack revealed last year, and again in the Anthem breach earlier this year.  (Ironically, the insurance program for state employees in Kentucky switched to Anthem at the beginning of the year, and just over a month later, they had to inform us of this breach.)

The first step is to learn exactly what was stolen.  The proper response to these breaches will vary based on what data was compromised.  For example, in the Chase hack, no account data or passwords were compromised; the only information taken was contact data for customers.  The steps you take in this case are radically different from the ones you would want to take if your credit card or bank account numbers were exposed.

In order to keep these tips to a manageable length, I will be splitting up my suggested responses based on what information was compromised.  In part one, I will discuss what to do if your username, password, or other contact data is breached; part two will contain what to do if your credit card or bank account number is stolen; and part three will list actions to take if your social security number is compromised.

Part One:  Username, Password, or Contact Information Stolen:

Obviously, no data breach is ever good, but if some information is going to be stolen, this is the type of breach you want.  Most of these suggestions only deal with compromised user names and passwords.  If only your contact information (name, address, phone number, email, etc.) is stolen, your account online is probably still secure, but you could see an increase in phishing attempts and other scams.  If your password or other information has been stolen, here are some steps to take:

1) Change Your Password - This should be a no-brainer.  If your password has been stolen from a site, change it as soon as possible!  In many cases, it may be best to change it twice:  once upon the first reports of the breach, and then again once the company has strengthened its security.  The first password change will not lock attackers out of your account if they are still exploiting the breach and grabbing more data.

2) Check Your Information - If someone else has your username and password, they might be able to log in and change personal information, such as your address.  If you are not careful, you could quickly place an order using your account and find that it was set to ship somewhere else during the time your account was compromised.  (Obviously, sites clearly show you the shipping address to prevent this, but if you click through without checking, it could be a possibility.)

You will also want to know what other information might be available to someone who snooped inside your account.  Sure, your banking site may have only had its user names and passwords compromised, but someone can use that information to log in and see your account numbers.  If you can access any of this information from the user interface, assume that it has also been compromised.

3) Use Extra Caution with Email - Have you ever thought about how much access our email accounts grant us?  If your email account has been compromised, review what information you might have stored in your inbox.  Also, check accounts that use that email address for signs of tampering.  If someone has access to your email, they can use the "Forgot my password" link to change your password to many other sites.  (Some sites are becoming smarter about this and requiring more information before sending a link to your email, but many are slow to follow this increased security.)

4) Enable Two-Factor Authentication - Two-factor authentication requires more than just a user name and password to log in.  In most cases, this will be a code you will receive via email or text message.  My bank requires two-factor authentication the first time you log in to an account from a particular device, and then it places a cookie in your browser identifying your device as a trusted device and permitting you to log in with just your user name and password.  If an account offers two-factor authentication, it is a good idea to turn it on, even if your account details haven't been compromised.

5) Watch Your Accounts - If your account has payment information stored with it, it is possible that someone could have placed an order with your account and charged it to your stored payment method.  Review your bank statements and your order history with the site to see if there is any suspicious activity.

6) Review Your Personal Password Policy - We all know we shouldn't use the same password for multiple sites, and we have all probably broken this rule.  A smart attacker will make checking for reused passwords one of the first activities after obtaining your password.  Additional accounts could be compromised using this technique, and you might not realize it until after damage has been done.  (As a follow-up note, someone recently shared an excellent tip with me about how to manage and remember your passwords, and I will share this with you next week.)

7) Beware of Scams - Less than 24 hours after the Anthem hack was announced, emails came out asking people to click the link and verify their Anthem account information.  The scam could come through a variety of methods:  email, phone, postal mail, or even text message.  In many cases, attackers will simply send out batches of emails mentioning that your information has been compromised on a particular site.  (I received one for Skype last year, even though I have never used or had an account with Skype.)  However, attackers are starting to launch more personal attacks with the data they have obtained.

Imagine that your password was compromised at some company.  An attacker could use that to log into your email (which used the same password as the hacked company's site), and see that you placed an order with Amazon for a new vacuum on January 27th.  Now that they have your name and address from the receipt, they can do a simple search to get your phone number (if it wasn't also listed on the receipt) and call you with a "customer satisfaction survey."  Since they ask you specific questions about "your order from January 27th" and "your new Hoover WindTunnel vacuum", you have no doubt that they are actually from Amazon, and you give them your password when they say they need you to "confirm your identity".  You never suspect anything until you see charges on your credit card from Amazon, where you had saved your card number for convenience.  It might sound complex, but an experienced attacker with some software help could probably have the orders placed in less than 10 minutes.

Tuesday, February 17, 2015

Is That Photo Real?

Have you ever seen a picture and wondered if it was real or if it had been manipulated?  In a previous tip, I showed you how to use an image search engine to find out if a photo was available on the internet.  (You can read that tip again here.)  However, an image search won't tell you if a picture has been altered.

However, Foto Forensics can help you determine if an image has been photoshopped.  It will analyze an image to determine if it shows signs of modification.  Upload the photo from your computer or enter the picture's URL, and Foto Forensics will provide a substantial amount of data about the photo.  It will not give you a simple yes or no, but it will help you analyze a photo for inconsistencies in the rendering that indicate it was modified.  If you are not sure what to look for, scroll to the bottom and check out the link for the tutorials.

Like a forensics officer for a police department, you will have to do some work to draw any conclusions.  Plus, you may come to a point where you have to say that you cannot make a conclusive decision.  However, since most people are not expert image manipulators, you will likely be able to catch most fake images.

Monday, February 16, 2015

Four Places You Shouldn't Use a Debit Card

Most of you know that I don't care for debit cards.  (If you didn't know that, you can read why here.)  For a summary, debit cards have much fewer legal protections (although my bank's policy extends all of its credit card protections to debit cards) and for fraudulent charges, you are stuck fighting to get your money back instead of just fighting to get the charge off of your bill.  I have cut out almost all of my debit card use; I make a few small purchases each month in order to keep my account from getting a service charge, and use cash or my credit card for everything else.  However, there are a few places I never use my debit card, simply because there is an increased risk of fraud:

1) Gas Pumps - Card skimmers have become cheaper to make and easier to install.  However, the biggest problem is finding a place to install them.  Gas pumps make an excellent target because they are relatively free from employee surveillance and no one will question why you're standing around near a gas pump.  In under a minute, someone can attach a card skimmer to the gas pump and drive by every few days to download the data it collected via wireless.  Your transaction will go through just like normal, but your card will be copied and sent to an additional destination.

2) Restaurants - Restaurants are one of the few places where we accept that our card will leave our sight for an extended period of time.  Unfortunately, restaurants have not been able to come up with a practical solution for this problem.  If you wouldn't walk up to a stranger and hand him or her your debit card, why would you give it to someone you don't know at a restaurant?  Yes, the vast majority of waiters and waitresses will not try to steal your information, but you have no way of picking out the one or two people in your city who are working there for other reasons.

3) The Gym (And Other Places with Automatic Payments) - It might sound like a great idea to have your automatic payments deducted from your checking accounts.  But will you remember to deduct it from your records each month?  If you forget, you will be facing overdraft charges.  Plus, hearing stories of people who were charged for a recurring payment after the payment was cancelled should be enough to make you want those charges to go on your bill instead of coming out of your checking account.

4) Online - It seems that hackers are getting into everything these days.  In fact, I sometimes wonder if it is even safe to buy anything online these days.  However, if you are going to make a purchase online, it will be much safer to keep the number that accesses your checking account off the internet.

While it is true that your credit card is just as vulnerable as your debit card at these locations, your credit card will be much better protected and you won't be without your money until your bank completes its investigation.  Cash is obviously best, but it is inconvenient at the gas pump and impossible to use online, so when you must swipe a card, credit is your safest alternative.

As a final note, I have had a couple people tell me they are concerned about overspending on their credit card and not being able to pay the bill when it comes due.  Fortunately, there is an easy solution:  transfer the money from your checking account onto your card as soon as you make a charge.  This way, you get the safety of a credit card while preventing a large bill at the end of the month.

Friday, February 13, 2015

Set Your Facebook 'Legacy Contact'

One of the problems many people have had with Facebook was the lack of a way to pass your accounts on to others.  Yes, you could give someone else your password (or leave a list of your passwords for someone to find), but that is difficult to maintain if you like to change your passwords (which you should do on a fairly regular basis!)

Until yesterday, Facebook's only option for your page was to convert it into a memorial page, which basically froze the page, but kept it alive as a way to remember the deceased.  Now, any Facebook user in the United States can designate a "legacy contact" who will have permission rights over some parts of your page.  (Facebook will also honor statements naming someone as a "digital heir" for online accounts, even if you do not list a legacy contact on your profile.)

The legacy contact will not be able to edit or delete posts you have made, but he or she will have the power to write a memorial message at the top, change the profile picture, and accept friend requests.  If you grant permission, the contact will also have the power to download all your posts and photos or to delete your account.  If you do not set a legacy contact, Facebook will continue to freeze your account as it did before.

There are a few complications that may need to be adjusted.  Currently, Facebook is only allowing for one legacy contact--no backups or splitting the duties--and the legacy contact responsibility cannot be passed on to someone else.  This may create a tough situation for couples who travel together frequently:  they might want to designate someone else in case of a problem on their travels, but a surviving spouse would then be locked out of the other spouse's page completely.  Plus, the legacy contact has no ability to change much of the content of the page.  If the person's final post is not something they would want to be remembered by, the legacy contact has no power to change it.

Regardless, this is certainly a step in the right direction.  This is a change many have wanted for a long time, and it will definitely be adjusted over time.

To set your legacy contact, go to the "Settings" page and select "Security".  The section to control your legacy contact selection is at the bottom.

Thursday, February 12, 2015

Stop Google from Using Your Face

Imagine that you are doing a Google search for a product, and underneath that product is a picture of your best friend with a review he wrote last year.  Would you be more likely to purchase that product?  Of course, you would!

That's why Google updated its privacy policy last year to allow it to use your public images and reviews to try to sell more items.  Although your name and image must be publicly available and they will only be shown to your friends, this still feels like an invasion of your privacy.

Google calls these Shared Endorsements.  If you are over 18, Google has enabled permission to use your name, picture, and review in its ads by default.  However, you can disable this permission by unchecking one box.  Head to the Shared Endorsements page, scroll to the bottom, uncheck the one check box, and click save.

This permission applies based on your Google account.  If you have set up multiple Google accounts, you will need to follow these steps for each account.

Wednesday, February 11, 2015

Scan Your Machine for Security Issues

Do you know if your computer is secure?  Have you applied all updates?  Are you using strong passwords?  Are administrator accounts only in use for people who should have that privilege?  As you can see, there is a lot to keeping your computer safe.

Fortunately, Microsoft has a free tool that will analyze your computer for security issues with Windows and Office programs.  It will make sure each program is properly patched, check for strong passwords, and check to see if users have too many permissions.  It will then provide you a comprehensive report listing any problems found.

However, do not just implement every change.  Sometimes, you need certain changes for programs to operate correctly.  If you are not sure of what you are doing, do not change anything without checking with a computer technician.

If you want to try out a free security scan, check out the Microsoft Baseline Security Analyzer here.