By Michael Seese
It's been a while since I'd gotten a good SPAM. But his came the other day.
Hmmm.
It's from "Apple <Support@paypol.securnet>
Why "paypol?" Are the spammers worried about PayPal suing them over copyright infringement?
(So that would be SPAM hint #1.)
It's addressed to "Dear,"
(So that would be SPAM hint #2.)
When you hover over either "Verify Now" and "My Apple ID," the URL resolves to http://www.dopropriobolso.com.br/images/stories/2014/ree.php/
(So that would be SPAM hint #3.)
I have no idea who this website is. If I had to guess, this probably isn't a site which will load malware; they're probably just trying to nab your Apple credentials. The top-level domain .br means it's Brazil.
I won't even go into "Extend our this request."
Remember, when in doubt, stop and think.
And then, still don't click.
Be safe out there, cyber-surfers.
Showing posts with label information security. Show all posts
Showing posts with label information security. Show all posts
Thursday, September 11, 2014
Saturday, March 22, 2014
SPAM Tennis, Part 2
By Michael Seese
Two posts back, I recounted my adventures in the world of Singaporian (is that a word?) finance. To be exact, I had received an email from Mr. Cham Tao Soon of Chairman Audit Committee of UOB Bank, Singapore with an offer to "lay claims" to a secret account worth millions." In this case, the money belonged to Mr. Dimka Ilkovska-Boskovic, who was a member of Macedonian President Boris Trajkovski's cabinet, who perished along with the President in a plane crash.
Mr. Soon and I exchanged pleasantries, as well as sensitive documents. At the time of my last post, he was traveling on business. After a few days, I thought I would touch base, since that's what friends do.
Dear Mr. Soon --
I hope your travels have been productive. I look forward to hearing from you so that we may continue our enterprise.
Warmest,
DJ
He replied:
I see the phone number you give to me as yours turns out to be the fax number for Russian online visa application. Thanks for the time wasting.
Office in Moscow
Address: 107014 Moscow, Zhebrunova Street 6, Office 117
Phone: 7-495-505-6325
Fax: 7-495-649-8328
E-mail: moscow@visitrussia.com
Wow! He checks references? Bummer. I had so many fun responses planned for his inevitable request for good-faith money. It really was going to be a tennis match. Oh well. I answered nonetheless.
Dear Mr. Cham --
Or should that be "Sham?" Or perhaps "Scam?"
I'd hardly call it time wasting. I had a lot of fun imagining how excited you must have been to think you actually had a sucker on the line.
Tchau, mother-----r.
DJ
I chose the sign-off "tchau," as is it goodbye in Brazilian Portuguese. If you'll recall from the previous post, the original email came from the .br top-level domain. I was hoping that maybe, just maybe, he really was from Brazil, and would think, "How did he know...?"
A few days later I got this, in the same mailbox. (Bear in mind, my dear friend Cham was the only person who knew of it, and I can't imagine him "sharing" it with anyone.)
I think the moral of the story is obvious. If you're hiding untold illegally obtained millions, don't fly. The odds are you will crash.
I responded to this one with "Nice try, (expletive deleted)."
Until next time crime fighters.
Two posts back, I recounted my adventures in the world of Singaporian (is that a word?) finance. To be exact, I had received an email from Mr. Cham Tao Soon of Chairman Audit Committee of UOB Bank, Singapore with an offer to "lay claims" to a secret account worth millions." In this case, the money belonged to Mr. Dimka Ilkovska-Boskovic, who was a member of Macedonian President Boris Trajkovski's cabinet, who perished along with the President in a plane crash.
Mr. Soon and I exchanged pleasantries, as well as sensitive documents. At the time of my last post, he was traveling on business. After a few days, I thought I would touch base, since that's what friends do.
Dear Mr. Soon --
I hope your travels have been productive. I look forward to hearing from you so that we may continue our enterprise.
Warmest,
DJ
He replied:
I see the phone number you give to me as yours turns out to be the fax number for Russian online visa application. Thanks for the time wasting.
Office in Moscow
Address: 107014 Moscow, Zhebrunova Street 6, Office 117
Phone: 7-495-505-6325
Fax: 7-495-649-8328
E-mail: moscow@visitrussia.com
Wow! He checks references? Bummer. I had so many fun responses planned for his inevitable request for good-faith money. It really was going to be a tennis match. Oh well. I answered nonetheless.
Dear Mr. Cham --
Or should that be "Sham?" Or perhaps "Scam?"
I'd hardly call it time wasting. I had a lot of fun imagining how excited you must have been to think you actually had a sucker on the line.
Tchau, mother-----r.
DJ
I chose the sign-off "tchau," as is it goodbye in Brazilian Portuguese. If you'll recall from the previous post, the original email came from the .br top-level domain. I was hoping that maybe, just maybe, he really was from Brazil, and would think, "How did he know...?"
A few days later I got this, in the same mailbox. (Bear in mind, my dear friend Cham was the only person who knew of it, and I can't imagine him "sharing" it with anyone.)
I think the moral of the story is obvious. If you're hiding untold illegally obtained millions, don't fly. The odds are you will crash.
I responded to this one with "Nice try, (expletive deleted)."
Until next time crime fighters.
Thursday, March 13, 2014
SPAM Tennis Anyone?
By Michael Seese
Normally when I get a SPAM email, I share it in this space, give it the MST3K treatment, and move on. Also, since I work in infosec, I try to throw in a few helpful hints on detecting and investigating the email.
A few weeks ago, I got this rather mundane ploy.
A few noteworthy points:
- Though it's hard to see, the "From" ends with .br That's the top-level domain code for Brazil.
- The "Reply to:" email address ends with .sg That's Singapore. OK, he got that right.
- The email was sent to "undisclosed-recipients." Note the plural.
Initially, I discarded it. But then I got a notion to have some fun. So I created a fake email account using a free service provider -- in this case Microsoft -- and sent the following:
Dearest Mr. Soon --
Yes, this would be acceptable. Please to send all funds to
the PayPal account associated with this email address.
Best,
DJ
Fans of revisionist literature may have picked up on my use of the dialect of Quadling Country.
He responded a little over 12 hours later. Naturally, his email went on and on. The germane points were:
Before the plane crash of Macedonia's President and his aides on February 26th, 2004, our client, Mr. Dimka Ilkovska-Boskovic, who was a member of President Boris Trajkovski's cabinet advisers, and also a business man, made a numbered fixed deposit for 18 calendar months, with a value of €105,000,000.00 EUR (One Hundred & Five Million Euros Only) in my branch.
...
After further investigation, it was discovered that Mr. Dimka Ilkovska-Boskovic did not declare any next of kin in his official documentations including the paper works of his bank deposit. And he also confided in me the last time he was at my office that no one knew of his deposit in my bank. So, €105,000,000.00 EUR is still lying in my bank and no one will ever come forward to claim it.
...
my suggestion to you is that I will like you as a foreigner to stand as the next of kin to Mr. Dimka Ilkovska-Boskovic, so that you will be able to claim the funds in question.
...
There is no risk involved at all in the matter, as we are going to adopt a legalized method and the attorney will prepare all necessary legal documents. Please endeavor to observe utmost discretion in all matters concerning this issue. Once the funds have been transferred to your nominated bank account, we shall share in the ratio of 60% for me and 40% for you. I have attached herewith a comprehensive detail of this business venture for your perusal in MS WORD.
As soon as I hear from you, I will go ahead to do the needful.
So I replied:
Hon. Mr. Soon --
To be certain, My name and address are:
Dmitri Jakov
100 Lihacheva str.
Kiev Ukraine 09355
But, since the banks in Ukraine are corrupt, please deposit all funds in my PayPal account, which uses the name dmitrijakov@outlook.com
Kindest,
DJ
(Yes, I intentionally gave my alter-ego a name which would make a teenaged boy snicker.)
He started asking for more (reasonable, if this were legit) info:
Before we proceed further, I will need you to re-affirm your full names, mobile number and a copy of any legal form your identification (Driver's license or International Passport). I hope you understand why I need all these, the money in question is huge, and I have to ensure that I know you well enough before I furnish you with all the details to execute this project. As soon as I get the above information from you, I will forward it to my hired attorney to commence the necessary legal paper works.
He also added a "security code," which probably is the "Unique Sucker ID" in his database.
NOTE: that for security purpose, I would appreciate that you input this code: [UOB-X1H] in all email messages directed to me.
I googled "Ukrainian passport," and actually found an image of a (I assume) real one. I copied down the number -- changing the last digit -- and sent that along with a phone number I found. If memory serves, it was the fax number of the Kiev Tourist Bureau.
Since we're now partners and buddies, he sent me a copy of his passport, along with a link to the website of his bank. (Suffice to say, I did not click on it.)
He looks pretty good for a 72-year-old, don't you think?
He asked that I reciprocate with my passport. I thought, Uh-oh. What do I do now? Then it hit me. Since he (obviously) isn't who (or where) he says he is, I can use that to my advantage. I replied:
Mr. Soon --
I have mailed a copy of my document via parcel post, with necessary expediency, to your attention at the bank's address.
Please let's get started.
DJ
Take that!
Later that day, he answered:
I am glad to note that you are a noble and trustworthy person whom I can rely on to handle this transaction. I have received your ID and I want you to know that I have forwarded your data to my hired Will & Probate Attorney who will put together the perfected legal paper works to be sent to my bank for the release of the funds. This should take no longer than two working Days.
Wow! The Ukraine Postal Service sure is efficient! (And kudos on the proper use of "whom.") He also sent me a copy of my benefactor's death certificate:
I don't know about you, but it almost had me fooled. And you know, purple is a nice color for death certificate.
My "friend" is traveling now, and said he'd get back to me in a few days. I suspect that it won't be too long until he asks for the de rigueur "good faith" money from me. I have my initial response, which I'm sure is the same idea that everyone who reads about some poor soul falling for one of these scams has: "Why didn't you just say, 'Please take these funds from the €105,000,000.00 EUR. That should cover it.' " I'm sure he has a stock response. I've got a few of my own.
Stay tuned, crime stoppers!
Normally when I get a SPAM email, I share it in this space, give it the MST3K treatment, and move on. Also, since I work in infosec, I try to throw in a few helpful hints on detecting and investigating the email.
A few weeks ago, I got this rather mundane ploy.
A few noteworthy points:
- Though it's hard to see, the "From" ends with .br That's the top-level domain code for Brazil.
- The "Reply to:" email address ends with .sg That's Singapore. OK, he got that right.
- The email was sent to "undisclosed-recipients." Note the plural.
Initially, I discarded it. But then I got a notion to have some fun. So I created a fake email account using a free service provider -- in this case Microsoft -- and sent the following:
Dearest Mr. Soon --
Yes, this would be acceptable. Please to send all funds to
the PayPal account associated with this email address.
Best,
DJ
Fans of revisionist literature may have picked up on my use of the dialect of Quadling Country.
He responded a little over 12 hours later. Naturally, his email went on and on. The germane points were:
Before the plane crash of Macedonia's President and his aides on February 26th, 2004, our client, Mr. Dimka Ilkovska-Boskovic, who was a member of President Boris Trajkovski's cabinet advisers, and also a business man, made a numbered fixed deposit for 18 calendar months, with a value of €105,000,000.00 EUR (One Hundred & Five Million Euros Only) in my branch.
...
After further investigation, it was discovered that Mr. Dimka Ilkovska-Boskovic did not declare any next of kin in his official documentations including the paper works of his bank deposit. And he also confided in me the last time he was at my office that no one knew of his deposit in my bank. So, €105,000,000.00 EUR is still lying in my bank and no one will ever come forward to claim it.
...
my suggestion to you is that I will like you as a foreigner to stand as the next of kin to Mr. Dimka Ilkovska-Boskovic, so that you will be able to claim the funds in question.
...
There is no risk involved at all in the matter, as we are going to adopt a legalized method and the attorney will prepare all necessary legal documents. Please endeavor to observe utmost discretion in all matters concerning this issue. Once the funds have been transferred to your nominated bank account, we shall share in the ratio of 60% for me and 40% for you. I have attached herewith a comprehensive detail of this business venture for your perusal in MS WORD.
As soon as I hear from you, I will go ahead to do the needful.
So I replied:
Hon. Mr. Soon --
To be certain, My name and address are:
Dmitri Jakov
100 Lihacheva str.
Kiev Ukraine 09355
But, since the banks in Ukraine are corrupt, please deposit all funds in my PayPal account, which uses the name dmitrijakov@outlook.com
Kindest,
DJ
(Yes, I intentionally gave my alter-ego a name which would make a teenaged boy snicker.)
He started asking for more (reasonable, if this were legit) info:
Before we proceed further, I will need you to re-affirm your full names, mobile number and a copy of any legal form your identification (Driver's license or International Passport). I hope you understand why I need all these, the money in question is huge, and I have to ensure that I know you well enough before I furnish you with all the details to execute this project. As soon as I get the above information from you, I will forward it to my hired attorney to commence the necessary legal paper works.
He also added a "security code," which probably is the "Unique Sucker ID" in his database.
NOTE: that for security purpose, I would appreciate that you input this code: [UOB-X1H] in all email messages directed to me.
I googled "Ukrainian passport," and actually found an image of a (I assume) real one. I copied down the number -- changing the last digit -- and sent that along with a phone number I found. If memory serves, it was the fax number of the Kiev Tourist Bureau.
Since we're now partners and buddies, he sent me a copy of his passport, along with a link to the website of his bank. (Suffice to say, I did not click on it.)
He looks pretty good for a 72-year-old, don't you think?
He asked that I reciprocate with my passport. I thought, Uh-oh. What do I do now? Then it hit me. Since he (obviously) isn't who (or where) he says he is, I can use that to my advantage. I replied:
Mr. Soon --
I have mailed a copy of my document via parcel post, with necessary expediency, to your attention at the bank's address.
Please let's get started.
DJ
Take that!
Later that day, he answered:
I am glad to note that you are a noble and trustworthy person whom I can rely on to handle this transaction. I have received your ID and I want you to know that I have forwarded your data to my hired Will & Probate Attorney who will put together the perfected legal paper works to be sent to my bank for the release of the funds. This should take no longer than two working Days.
Wow! The Ukraine Postal Service sure is efficient! (And kudos on the proper use of "whom.") He also sent me a copy of my benefactor's death certificate:
I don't know about you, but it almost had me fooled. And you know, purple is a nice color for death certificate.
My "friend" is traveling now, and said he'd get back to me in a few days. I suspect that it won't be too long until he asks for the de rigueur "good faith" money from me. I have my initial response, which I'm sure is the same idea that everyone who reads about some poor soul falling for one of these scams has: "Why didn't you just say, 'Please take these funds from the €105,000,000.00 EUR. That should cover it.' " I'm sure he has a stock response. I've got a few of my own.
Stay tuned, crime stoppers!
Monday, January 6, 2014
Energy SPAM
By Michael Seese
This one was pretty good.
Why it almost works:
1. With that whole deregulation thing, does anyone know who his or her energy carrier is? OK, I do, because I pay attention. But perhaps some of you...
2. There is an amount due.
3. The "bill" is conveniently past due, which creates the sense of urgency that social engineering ploys often use.
But what do we always do?
1. Look at the "From" and ask, "What does a travel company have to do with my energy bill?"
2. Hover over the links and see that they would take you to http://www.manresaturisme.cat/request/QnkAh1fKMq4tjKnAsiH4k4jytThymkZ3qfsr91ZMOv4=/environment That doesn't look like an energy company.
Always be vigilant.
This one was pretty good.
Why it almost works:
1. With that whole deregulation thing, does anyone know who his or her energy carrier is? OK, I do, because I pay attention. But perhaps some of you...
2. There is an amount due.
3. The "bill" is conveniently past due, which creates the sense of urgency that social engineering ploys often use.
But what do we always do?
1. Look at the "From" and ask, "What does a travel company have to do with my energy bill?"
2. Hover over the links and see that they would take you to http://www.manresaturisme.cat/request/QnkAh1fKMq4tjKnAsiH4k4jytThymkZ3qfsr91ZMOv4=/environment That doesn't look like an energy company.
Always be vigilant.
Thursday, November 21, 2013
WhatsApp SPAM
By Michael Seese
They say that variety is the spice of life. And I was growing wearing of the FedEx / UPS SPAMs. Then along comes this one to brighten my day.
So, junior infosec pros, what can we see right away about this little bugger?
How about:
1.The subject seems to think I have five more messages than the body does.
2. The sender is a Chinese cosmetics firm. (LAME, PEOPLE! You need to at least make the sender look believable.)
3. Hovering over the "Play" button reveals that I would venture to
http://antlitz-christi.de/lsebglb.php?iRTd3y1hfLVI1VfmlbJa7bcY+4zlC+0D6tmUcTJidYQ=
Ah, yes. Click on SPAM and see the world. First China, then Germany. (And is it just me, or does anyone else's mind rearrange the stuff between http and .de into "anti christ.")
Let's be safe out there.
They say that variety is the spice of life. And I was growing wearing of the FedEx / UPS SPAMs. Then along comes this one to brighten my day.
So, junior infosec pros, what can we see right away about this little bugger?
How about:
1.The subject seems to think I have five more messages than the body does.
2. The sender is a Chinese cosmetics firm. (LAME, PEOPLE! You need to at least make the sender look believable.)
3. Hovering over the "Play" button reveals that I would venture to
http://antlitz-christi.de/lsebglb.php?iRTd3y1hfLVI1VfmlbJa7bcY+4zlC+0D6tmUcTJidYQ=
Ah, yes. Click on SPAM and see the world. First China, then Germany. (And is it just me, or does anyone else's mind rearrange the stuff between http and .de into "anti christ.")
Let's be safe out there.
Friday, January 25, 2013
Triple Play SPAM Day
By Michael Seese
At the risk of jinxing myself, I don't get all that much SPAM. So I was surprised to find not one, not two, but three SPAM emails waiting for me yesterday.
If I may go into MST3K mode:
Yeah, my bank's employees all have names which require the Cyrillic alphabet.
This one almost got me, to be honest, mainly because I did just book airline travel. But it was not with American Airlines and, as I suggest when I teach "Infosec 101," hover over the link to reveal where it goes: hivewebdesign.com.au. Hmmm. That doesn't sound like American Airlines. (I intentionally did not show the images, since that potentially can be risky.)
I like this "Reply To" email address:
r-ykqzmplmqbcvtkqgmgglkcpmcjkvgwwzptczmwkpyzldbjvqpl@members.playboystore.com.
They say that size does matter, after all.
Until next time...
At the risk of jinxing myself, I don't get all that much SPAM. So I was surprised to find not one, not two, but three SPAM emails waiting for me yesterday.
If I may go into MST3K mode:
Yeah, my bank's employees all have names which require the Cyrillic alphabet.
This one almost got me, to be honest, mainly because I did just book airline travel. But it was not with American Airlines and, as I suggest when I teach "Infosec 101," hover over the link to reveal where it goes: hivewebdesign.com.au. Hmmm. That doesn't sound like American Airlines. (I intentionally did not show the images, since that potentially can be risky.)
I like this "Reply To" email address:
r-ykqzmplmqbcvtkqgmgglkcpmcjkvgwwzptczmwkpyzldbjvqpl@members.playboystore.com.
They say that size does matter, after all.
Until next time...
Wednesday, January 16, 2013
Legitimate Business Proposal Spam
By Michael Seese
The other day, I received the following "legitimate business" proposal.
What? No poisoned hyperlinks? Boring!
And do you suppose he realizes that if I read the "To:" line I see "undisclosed-recipients"
Yeah, I feel special.
Remember kids, if you want to make a small contribution to the infosec effort, forward your SPAM emails (with full header info) to spam@uce.gov
The other day, I received the following "legitimate business" proposal.
What? No poisoned hyperlinks? Boring!
And do you suppose he realizes that if I read the "To:" line I see "undisclosed-recipients"
Yeah, I feel special.
Remember kids, if you want to make a small contribution to the infosec effort, forward your SPAM emails (with full header info) to spam@uce.gov
Monday, November 12, 2012
Two Work SPAMs
By Michael Seese
On two successive days last week, I received the following two SPAM emails.
I'm trying to figure out the point. As I (and countless infosec pros) have said before, most SPAM emails nowadays contain links to malware sites. The bad guys want you to click on the link and download their spyware to your PC, giving them access to your computer and, more importantly, the passwords to your sensitive accounts.
But these emails had no such links. So I can only guess they're simply trolling for "live" email addresses to file away or sell to someone else, who then can hammer them with more SPAM. But tactic that is so yesterday! Nonetheless, the lesson remains the same:
Don't reply. Just delete.
How about you all? Are you getting more or less SPAM these days?
On two successive days last week, I received the following two SPAM emails.
I'm trying to figure out the point. As I (and countless infosec pros) have said before, most SPAM emails nowadays contain links to malware sites. The bad guys want you to click on the link and download their spyware to your PC, giving them access to your computer and, more importantly, the passwords to your sensitive accounts.
But these emails had no such links. So I can only guess they're simply trolling for "live" email addresses to file away or sell to someone else, who then can hammer them with more SPAM. But tactic that is so yesterday! Nonetheless, the lesson remains the same:
Don't reply. Just delete.
How about you all? Are you getting more or less SPAM these days?
Monday, November 5, 2012
Pre-Election Day Funny
By Michael Seese
Tomorrow is Election Day. So I won't have to post any more snarky comments until 2016. (Though if I adhere to the traditional stumping timeline, I suppose I should start in 2 ½ years.)
I thought this represented the definitive commentary on the whole stinkin' process.
In several previous posts, I've talked about targeted ads. To state the obvious, a targeted ad is supposed to resonate with me because my browsing habits supposedly have put me into various demographic buckets.
I see them all the time in the infosec and privacy e-newsletters I subscribe to. I also subscribe to the "Word Of The Day" from Merriam-Webster.
Here are two of the ads I saw last week:
Hmmm.
What makes the irony even more delicious is that day's word of the day:
Clearly, the universe has a wicked sense of humor.
As I said last year, remember the old Chicago adage: "Vote early and vote often."
Does anyone care to make a bold prediction as to the electoral vote count? Mine is 298-240. I'm not saying who will win, though...
Tomorrow is Election Day. So I won't have to post any more snarky comments until 2016. (Though if I adhere to the traditional stumping timeline, I suppose I should start in 2 ½ years.)
I thought this represented the definitive commentary on the whole stinkin' process.
In several previous posts, I've talked about targeted ads. To state the obvious, a targeted ad is supposed to resonate with me because my browsing habits supposedly have put me into various demographic buckets.
I see them all the time in the infosec and privacy e-newsletters I subscribe to. I also subscribe to the "Word Of The Day" from Merriam-Webster.
Here are two of the ads I saw last week:
Hmmm.
What makes the irony even more delicious is that day's word of the day:
Clearly, the universe has a wicked sense of humor.
As I said last year, remember the old Chicago adage: "Vote early and vote often."
Does anyone care to make a bold prediction as to the electoral vote count? Mine is 298-240. I'm not saying who will win, though...
Monday, October 1, 2012
Now This Is Unique
By Michael Seese
As an information security pro, I probably pay closer attention to SPAM emails than most folks. And by "pay closer attention," I mean read and laugh out loud at.
I get so many good ones that I think I'll start sharing. For example, this one...
If you'll notice, the body of the email is empty. The entire con is in the subject. If nothing else, this is the first email I've received with a three-digit word count in the subject line.
I'm sure that was an effort on the part of the spammer to avoid filters which look for certain keywords--he must assume--in the body only. If that's true, then his ploy makes sense. But by doing so, he cannot employ one common spammer tactic: having a live link which, when clicked, takes the email recipient to a site that most likely downloads malware.
I wonder how well his phishing expedition will go?
As an information security pro, I probably pay closer attention to SPAM emails than most folks. And by "pay closer attention," I mean read and laugh out loud at.
I get so many good ones that I think I'll start sharing. For example, this one...
If you'll notice, the body of the email is empty. The entire con is in the subject. If nothing else, this is the first email I've received with a three-digit word count in the subject line.
I'm sure that was an effort on the part of the spammer to avoid filters which look for certain keywords--he must assume--in the body only. If that's true, then his ploy makes sense. But by doing so, he cannot employ one common spammer tactic: having a live link which, when clicked, takes the email recipient to a site that most likely downloads malware.
I wonder how well his phishing expedition will go?
Thursday, April 19, 2012
My Other Self
I generally use this space to talk about writing. But as many of you know, my day job is as an infosec pro for a major bank. Occasionally, I come across something interesting in the world of cyber- (or not cyber-) crime.
Here is an example of the latter. The italics are mine.
ABA-Backed Bill Introduced to Repeal Outdated ATM Disclosure
House Financial Services Committee members Blaine Luetkemeyer (R-Mo.) and David Scott (D-Ga.) on Tuesday introduced an ABA-supported bill (H.R. 4367) that would protect banks from frivolous lawsuits by repealing the outdated requirement that a placard must be attached to ATMs stating that a fee may be charged.
The placard disclosure is duplicative because the actual fee also appears on the ATM video monitor before the transaction is completed. But if the placard isn’t attached, Regulation E (Electronic Funds Transfer Act) permits successful class-action plaintiffs to recover the lesser of $500,000 or 1 percent of the ATM operator's net worth plus attorneys’ fees and costs.
As a result, some people have removed placards, photographed ATMs without them and filed lawsuits. In a February letter, ABA and six other trade groups asked the House Financial Services and Senate Banking Committees to pass a bill repealing the placard requirement because such lawsuits were growing precipitously and could reduce both the number of ATMs and consumer convenience.
House Financial Services Committee members Blaine Luetkemeyer (R-Mo.) and David Scott (D-Ga.) on Tuesday introduced an ABA-supported bill (H.R. 4367) that would protect banks from frivolous lawsuits by repealing the outdated requirement that a placard must be attached to ATMs stating that a fee may be charged.
The placard disclosure is duplicative because the actual fee also appears on the ATM video monitor before the transaction is completed. But if the placard isn’t attached, Regulation E (Electronic Funds Transfer Act) permits successful class-action plaintiffs to recover the lesser of $500,000 or 1 percent of the ATM operator's net worth plus attorneys’ fees and costs.
As a result, some people have removed placards, photographed ATMs without them and filed lawsuits. In a February letter, ABA and six other trade groups asked the House Financial Services and Senate Banking Committees to pass a bill repealing the placard requirement because such lawsuits were growing precipitously and could reduce both the number of ATMs and consumer convenience.
Thursday, March 8, 2012
If You Can Read This (Anonymously) Thank A Privacy Pro
As I have referenced in other posts, my day job is as an information security and privacy professional. Some of you may be asking, "What exactly does a privacy professional do?"
The answer is, we keep tabs on what the government and businesses are doing when they collect our personal information: how long they keep it, how they protect it, and (perhaps most importantly) with whom they share it. If you want a frightening illustration, here is a link to an article that appeared in the New York Times a few weeks back which goes into great detail about what author Charles Duhigg found out about Target's targeted (pun intended) marketing efforts. Even though understanding the marketing techniques he writes about are a component of my job, I found it to be a real eye-opener.
This article draws from Duhigg's upcoming book, The Power Of Habit: Why We Do What We Do In Life And Business.
If you're concerned, or even curious, about your personal info, you'll want to read at least the article, if not the book.
.
The answer is, we keep tabs on what the government and businesses are doing when they collect our personal information: how long they keep it, how they protect it, and (perhaps most importantly) with whom they share it. If you want a frightening illustration, here is a link to an article that appeared in the New York Times a few weeks back which goes into great detail about what author Charles Duhigg found out about Target's targeted (pun intended) marketing efforts. Even though understanding the marketing techniques he writes about are a component of my job, I found it to be a real eye-opener.
This article draws from Duhigg's upcoming book, The Power Of Habit: Why We Do What We Do In Life And Business.
If you're concerned, or even curious, about your personal info, you'll want to read at least the article, if not the book.
.
Monday, February 20, 2012
Helping A Fellow Propeller Head Writer
It gives me great pleasure to write this entry. I'm always happy to help out any fellow author, more so if he or she is a friend.
The other day I had a luncheon with the IAPP, a professional privacy organization that I belong to. In attendance were two former colleagues, Jack and Matt.
The other day I had a luncheon with the IAPP, a professional privacy organization that I belong to. In attendance were two former colleagues, Jack and Matt.
Early on in the lunch conversation, Matt said, "So I hear you have a book of ghost stories that has been published."
I said, "I do. And a book on infosec."
As it turns out, Matt has written his first book, also on information security, specifically penetration testing. It's titled, "Wireless Reconnaissance in Penetration Testing." He's thrilled, and I'm thrilled for him. There is nothing like the feeling of knowing that your first book is coming out...well, actually holding the book probably beats it. But he'll know that feeling soon enough.
He expects it to be published in Q3 of this year. But for now, it is available for pre-order on Amazon. I'm sure once it comes out, I'll enjoy reading it. Matt is one of those people--like me--who has good technical chops, but can explain things in human terms. (Though between you all and me, I think his technical knowledge is deeper than mine.)
So check out the preview now, and check back here at some point in the future for another shout-out.
.
Saturday, December 10, 2011
Applying Fiction In The Real World
I truly believe in my heart that I will be a full-time author some day. Hopefully it is sooner rather than later. After all, I am actively, diligently working toward that goal. So let's hope that good things really do come to those who wait...and work their tails off.
When I do finally get "there," I know that I won't entertain ANY thoughts of "if only..." as in, "If only I could have done this 20 years ago, I never would have needed a 'real' job," just like my current hero, Richard Castle. No, I don't regret for a second having to work my myriad day jobs. I've made good friends, and I've learned a lot, about people, about politics, and about cool computer stuff. In fact, my current career -- information security and privacy -- has provided me with what I consider to be a valuable life skill for the high-tech world we live in now: a healthy sense of paranoia. Of course, as Dr. Johnny Fever once said, "When they are after you, paranoid is just good thinking."
For example, every now and then on my way to work, I pass a car which has several stick-figure family stickers on the back.You've probably seen them:
This car that I often see shows the "mommy" figure, two kids, and two pets.
Does this woman realize that she basically is advertising the fact that she's a single mom? Whether or not it's really true, it is a logical inference, based on the stickers. If I were a criminal, I might have another name for that: easy target. Clearly, one can't know whether she's a martial arts expert, or has a concealed carry permit. She might be formidible. But on the surface, she is saying, "I am alone."
And even if I were a non-violent criminal (i.e., not a kidnapper), I'd try to find out where that car goes every night, reasoning that the house almost certainly is vacant during the day, since she's clearly not a stay-at-home mom. To help with that effort, there also is a bumper sticker which displays the emblem of the school district they live in. Sure, it doesn't say what street; but it narrows down the search.
I hope this post doesn't come across as negative. Obviously, I'm not advocating violence or crime. But I am advocating caution and vigilance which, as an infosec pro, I have to exercise every day. I often have to put on a "black hat" in order to think about what sort of escapade a scammer might be dreaming up in order to separate our customers from their money. Similarly, as a writer of fiction, I frequently have to ask, "WWBGD?" (What Would a Bad Guy Do?)
The takeaway, I suppose, is to remember that if you can concoct an awesome fictional criminal attack, some real-world bad guy already has.
So be aware, and don't fall victim to some scheme that you thought was your personal property. Let's be careful out there, people.
When I do finally get "there," I know that I won't entertain ANY thoughts of "if only..." as in, "If only I could have done this 20 years ago, I never would have needed a 'real' job," just like my current hero, Richard Castle. No, I don't regret for a second having to work my myriad day jobs. I've made good friends, and I've learned a lot, about people, about politics, and about cool computer stuff. In fact, my current career -- information security and privacy -- has provided me with what I consider to be a valuable life skill for the high-tech world we live in now: a healthy sense of paranoia. Of course, as Dr. Johnny Fever once said, "When they are after you, paranoid is just good thinking."
For example, every now and then on my way to work, I pass a car which has several stick-figure family stickers on the back.You've probably seen them:
This car that I often see shows the "mommy" figure, two kids, and two pets.
Does this woman realize that she basically is advertising the fact that she's a single mom? Whether or not it's really true, it is a logical inference, based on the stickers. If I were a criminal, I might have another name for that: easy target. Clearly, one can't know whether she's a martial arts expert, or has a concealed carry permit. She might be formidible. But on the surface, she is saying, "I am alone."
And even if I were a non-violent criminal (i.e., not a kidnapper), I'd try to find out where that car goes every night, reasoning that the house almost certainly is vacant during the day, since she's clearly not a stay-at-home mom. To help with that effort, there also is a bumper sticker which displays the emblem of the school district they live in. Sure, it doesn't say what street; but it narrows down the search.
I hope this post doesn't come across as negative. Obviously, I'm not advocating violence or crime. But I am advocating caution and vigilance which, as an infosec pro, I have to exercise every day. I often have to put on a "black hat" in order to think about what sort of escapade a scammer might be dreaming up in order to separate our customers from their money. Similarly, as a writer of fiction, I frequently have to ask, "WWBGD?" (What Would a Bad Guy Do?)
The takeaway, I suppose, is to remember that if you can concoct an awesome fictional criminal attack, some real-world bad guy already has.
So be aware, and don't fall victim to some scheme that you thought was your personal property. Let's be careful out there, people.
Subscribe to:
Posts (Atom)














