Google Search

Showing posts with label click. Show all posts
Showing posts with label click. Show all posts

Sunday, May 5, 2013

Evernote shoots itself in foot over "never click on 'reset password' requests" advice

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

After being hacked, Evernote, quite responsibly, has sent out emails to its users informing them of the security breach - and letting them know that it has decided to reset all passwords.

The email goes on to give some password advice - including a warning:

Evernote advice

Never click on 'reset password' requests in emails - instead go directly to the service.

That's a very sound piece of advice, because of the obvious threat - after millions of Evernote customers had their usernames and email addresses stolen - of phishing email attacks.

But take a closer look at the email that Evernote has sent out, with the subject line "Evernote Security Notice: Service-wide Password Reset":

Evernote email

Uh-oh, in the same email that Evernote tells users not to click on 'reset password' requests sent via email, they have clickable links.

And what might make some recipients pause for thought is that the links don't go directly to evernote.com, but instead link to a site called mkt5371.

Now, before you panic that someone is attempting to phish your Evernote credentials with a craftily-designed email, just relax.

Evernote and emailThis was just carelessness on Evernote's part. mkt5371 is a domain owned by Silverpop, an email communications firm who Evernote has clearly employed to send emails to its 50 million or so affected users.

The links in this case *do* end up taking you to Evernote's website - but go silently via Silverpop's systems first.

Presumably that's so Evernote can track and collect data on how successful the email campaign has been.

That's a technique commonly used in a normal marketing email communications, but looks very out of place in an email about a security breach which tries to hammer home the point to "Never click on 'reset password' requests in emails - instead go directly to the service".

You could certainly understand why someone freaked out by the Evernote security breach would be alarmed to receive an email with links like that.

Follow @gcluley

View the original article here

Wednesday, November 21, 2012

Nude photos of Justin Bieber a ruse: bellybutton tells the tale! Think before you click

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Justin BieberDon't click on that photo of Justin Bieber!

It's not him, fans say.

Sure, there's the trademark bird tattoo on the left hip, but the nipples are all wrong.

A photo distributed on the internet shows a headless naked male body engaged in what might perhaps be a sexual act with himself.

It was allegedly leaked when a thief made off with the singer's laptop and camera after a show in Washington.

The gadgets contain "a lot of personal footage," the star tweeted within hours of the theft:

There's just so much wrong with this picture, and I'm not talking about Justin Bieber's pink parts.

The first bit of wrongness has to do with anybody who'd actually risk their cyber security by clicking on an alleged celebrity photo.

The land of Twitter has plenty of skeptical Twitizens, but so too does it have far too many drooling fans eager to click on JB's charms.

Take Breanna, for example:

Hopefully, young fans like Breanna have wise friends who can educate them regarding malware, which loves to hitch a ride onto PCs using come-ons like nude celebrity pictures.

Earlier this week, Microsoft released its most recent Security Intelligence Report, which showed that photos, movies, software and other media are increasingly infested with Trojans and other attack vectors.

Anybody who goes out searching for nude photos of celebrities is just asking to be taken advantage of.

There's a long history of malware authors making the most of splashy celebrity-related headlines, whether it's the death of Michael Jackson or Amy Winehouse, Rihanna sex videos or a purported video of the killing of Osama Bin Laden.

Beyond the danger of clicking on what could be malware-laced photos, what in the world is Bieber doing storing personal footage on a laptop that hasn't been properly encrypted and secured with a strong password?

Sophos's Graham Cluley made this YouTube video a while back to explain how to choose a hard-to-crack but easy-to-remember password, but if you're tackling the task of security education for Beliebers, you might want to cut right to the part where he addresses password management software programs like 1Password, KeePass and LastPass, any of which will lift the task of remembering all their different passwords.

And with that accomplished, we will leave Bieber's fans to the task of bellybutton analysis.

But do point out to them that, as the Huffington Post shows, the star's belly button is clearly an outie.

Follow @LisaVaas

View the original article here