Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.
Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.
Already using Google+? Find us on Google+ for the latest security news.
Do you know someone who's been scammed online?
Chances are that you do - or you may have been scammed yourself.
Sadly, if you have been scammed, you may find some of your friends or family strangely unsympathetic.
There's still a widely-held belief that anyone who falls for an online scam must be both greedy and gullible.
? In some cases, it's true that the venality of the victim is a factor. If you send money to someone who has openly requested it as a bribe to persuade a corrupt official to pay out $22,000,000 for an oil pipeline that was never built, you have been both greedy and gullible. (You've also been a crook yourself. Don't expect sympathy.)
But there are dozens of popular online scams these days that don't require any risky character traits in the victim except a trusting nature.
Here are some examples:
Skimming. Crooks fit a duplicate card reader to an ATM so your card gets read twice when you use it.Phishing. Crooks trick you into logging in on a site that looks like your bank, but isn't.Fake competitions. Crooks persuade you to hand over personal information for geeky "prizes" that don't exist.Fake anti-virus. Crooks trick you into paying $50 for anti-virus software to "clean" malware that was never there.Fake support. Crooks pretend to be from Microsoft and offer a remote "cleanup" session for malware you don't have.The reason I'm mentioning all of this at this particular moment is that the Australian National Consumer Fraud Week 2013 starts today.
At Sophos we enthusiatically support this sort of event, because every time anyone gets scammed - even if they lose only a modest amount, such as $10 - it hurts our society and economy as a whole.
That means that helping other people to avoid scams can be considered an important civic and economic duty for all of us.
Here are five handy "outsmart the scammers" advice points from the Australasian Consumer Fraud Taskforce:
Think twice - if a deal looks too good to be true, it probably is.Find out what other shoppers say - make sure the person that you are dealing with, and their offer, is the real deal.Protect your identity - your personal details are private and invaluable; keep them that way and away from scammers.Keep your computer secure - install software that protects your computer from viruses and unwanted programs and make sure it is kept up-to-date.Only pay via secure payment methods - look for a web address starting with ‘https’ and a closed padlock symbol. Never use a wire transfer to send money to anyone you do not know and trust, and do not share your financial details with anyone.There's also a very handy taxonomy of scams on the Aussie government's SCAMwatch site.
Why not support National Consumer Fraud Week yourself?
Tell your less security-conscious friends and family about the SCAMwatch website, and get them to take a look at some of the many scams that are explained there.
Let's all learn to outsmart the scammers!
Follow @duckblog
If you're interested, Sophos provides a range of free security tools to help you stay safe online. Choose from Sophos Mobile Security for Android, Sophos Anti-Virus for Mac Home Edition, our Virus Removal Tool and the Sophos UTM Home Edition.
A cluster of top political figures in the UK, including several former Home Secretaries, has issued a public letter insisting on the revival of the so-called "snoopers' charter" - legislation to give British police and intelligence services more access to personal data.
In essence, they hired a temp (OK, "consultant", I've never been clear on where one stops and the other starts), and let him, what? Dump a load of highly-classified documents to a personal USB stick or a CD? Or send stuff out to his personal Gmail account?
The blurb is at DL1525; the 40,000-foot overview is at HT5167; and the all-important security details are at HT5281.
USA TODAYHackers cracked three companies that work with the most popular Web browsers to ensure the authenticity of Web pages where consumers type in sensitive information.The hacked firms are among more than 650 digital certificate authorities (CAs) worldwide that ensure that Web pages are the real deal when displayed by Microsoft's Internet Explorer, Firefox, Opera, Apple's Safari and Google's Chrome. A hacker gained access to digital certificate supplier DigiNotar this summer and began issuing forged certificates for dozens of marquee companies.Unable to cope with the fallout, the Dutch company filed for bankruptcy last week. Two other digital certificate companies, New Jersey-based Comodo and Japanese-owned GlobalSign, were similarly hacked this summer, exposing a glaring weakness in the Internet's underpinnings."The infrastructure baked into the Internet, which is based on trust, is starting to fall apart," says Michael Sutton, research vice president at security company Zscaler. CAs digitally certify account sign-ins, shopping and other pages where consumers type sensitive data. This sets up an encrypted connection to the Web browser, which displays the form for the consumer to fill out. The browser trusts only digitally signed pages.A counterfeiter issued valid DigiNotar certificates for 531 faked pages. Some of the pages were crafted to expertly impersonate online properties of Google, Microsoft, Skype, Equifax, Twitter, Facebook and the CIA, among others, according to consulting firm Fox-IT.This touched off a scramble to cut off the faked pages, which were difficult for consumers to spot as faked.The successful hacks demonstrated that it is possible to "impersonate any site on the Internet," says Josh Shaul, chief technical officer at security company AppSec.No banks or payment-service websites were targeted, says Mikko Hypponen, chief researcher at anti-virus company F-Secure. The hackers seem much more interested in harvesting personal data from e-mail services, social networks, credit bureaus, blogging sites and anonymity services. The pressure is on CAs and browser makers to do more to identify and quickly eradicate counterfeit certificates and faked Web pages, security experts say. "No one knows where the next breach will occur," says Jeff Hudson, CEO of digital certificate management company Venafi.Microsoft, maker of Internet Explorer, declined to comment, as did Apple, maker of the Safari browser. "The security of the Web is our collective responsibility," says Johnathan Nightingale, Mozilla's director of Firefox engineering.For more information about reprints & permissions, visit our FAQ's. To report corrections and clarifications, contact Standards Editor Brent Jones. For publication consideration in the newspaper, send comments to letters@usatoday.com. Include name, phone number, city and state for verification. To view our corrections, go to corrections.usatoday.com.