Google Search

Showing posts with label family. Show all posts
Showing posts with label family. Show all posts

Sunday, April 7, 2013

Ex-President Bush doxed - family photos, personal email, bathtub portraiture leaked

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

George H W Bush George H W Bush

A hacker using the alias "Guccifer" has claimed responsibility for hacking the Bushes, aka the political family that gave the US its 41st president (George H.W. Bush) and its 43rd president (George W. Bush).

In email exchanges with The Smoking Gun, the hacker indicated last week that he (the male gender having been indicated by The Smoking Gun's coverage) had breached at least six email accounts, including:

The AOL account of Dorothy Bush Koch, daughter of George H.W. Bush and sister of George W. Bush;Willard Heminway, 79, an old friend of the 41st president; CBS sportscaster Jim Nantz, a longtime Bush family friend; former first lady Barbara Bush’s brother; and George H.W. Bush’s sister-in-law.

The Smoking Gun reports that the hacker claims to have stolen and published private material, including "interesting mails" about George H.W. Bush's recent hospitalization, "Bush 43," and other Bush family members.

The doxed material allegedly contains a confidential October 2012 list of home addresses, cell phone numbers, and emails for dozens of Bush family members, including both former presidents, their siblings, and their children.

Intimate details were stolen, including a four-digit code needed to enter a Bush home security gate, as well as correspondence about the need to write a eulogy for the elder Bush, who was hospitalized and assumed to be on his death bed at the time.

Bush emails

Photos of George W.'s self-portraits were also published.

If you can't live without having experienced the 43rd president's knobby knees sticking out of a bathtub or ex-presidential lathering in a steamy shower, the internet can now ease your need. No worries, the paintings are safe for work.

Guccifer also posted private photos of the Bush family, which The Smoking Gun republished.

The hacker told The Smoking Gun that "The feds" began investigating him a "long time ago," and that he has hacked "hundreds of accounts."

He also downplayed the FBI/Secret Service investigation that's sure to come, saying:

"I have an old game with the f**king bastards inside, this is just another chapter in the game."

What hubris, to pick on innocent people in the execution of a "game".

Regardless of whether you approve of the political agenda of the Bush dynasty, you've got to feel sorry for those whose personal correspondence, photos and artwork gets pulled into the glaring light of the public eye just to satisfy some guy's ego.

The takeaway: take care of what you send electronically. We're all fair game to be picked on by bullies like Guccifer.

If you don't want to see your words and images held up for public scrutiny and ridicule, think twice before you hit send.

By the way, the Bushes are far from the first Republican politicans to have suffered at the hands of hackers. Perhaps most memorably, Sarah Palin had her private Yahoo email account broken into when she was campaigning to be vice-president. On that occasion, the hacker ended up with a prison sentence.

Follow @LisaVaas
Follow @NakedSecurity


View the original article here

Sunday, September 16, 2012

Facebook glitch lets spear phishers impersonate users' friends and family

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Spear fishing. Image from ShutterstockFacebook, blaming a "temporary misconfiguration," accidentally let spear phishers vacuum up users' personal details so they could pose as friends and family and thus make their come-ons convincing, the company told Forbes on Wednesday.

Forbes staffer David M. Ewalt was alerted to the threat when he himself received two targeted spam messages in the preceding week, both sent to a personal email address registered with his Facebook account.

Both emails appeared to come from someone he interacts with on Facebook. The sender personalized the subject line with the text "for David."

When Ewalt checked the messages' header fields (here are instructions on how to do that), he saw his friend's name in the "From" field, but the originating address wasn't their typical account; instead, it was "a bogus-looking Yahoo! Philippines email," he wrote.

He quickly found that others had reported similar spear phishing Facebook emails, all received in the past few weeks.

Facebook told Forbes that it has discovered what it called a "single, isolated campaign that was using compromised email accounts to gain information scraped from Friend Lists due to a temporary misconfiguration on our site."

The social network said it's since enhanced its scraping protections to protect against such attacks and will continue to investigate, but that there's been neither a mass compromise of Facebook accounts nor any leak of private information.

According to Ewalt, the spear-phishing emails pose as messages from close friends or family members, address the intended victim by name in the subject line or body of the message, and include a link to a website controlled by the spammers, all meant to exploit people's tendencies to click on strange links if they come from those whom they trust.

So, has Facebook now fixed the problem? Perhaps not judging by this tweet from Reuters reporter Joseph Menn:

While Facebook tries to get to the bottom of the problem, here are its recommendations on the steps users should take to protect their accounts:

Review your security settings and consider enabling login notifications.Don’t click on strange links, even if they’re from friends, and notify the person if you see something suspicious. How do you determine if a link is "strange"? Hover over a link without clicking on it. You'll see the full URL of the link's true destination in a lower corner of your browser. Don't use the links in an email, instant message, or chat to get to any web page if you suspect the message might not be authentic or you don't trust the sender. Instead, navigate to the website directly.Be suspicious of any email with urgent requests for login or financial information, and remember, unless the email is digitally signed, you can't be sure it wasn't forged or spoofed.Don’t accept friend requests from unknown parties.If you come across a scam, report it so that it can be taken down. Facebook earlier in the month introduced a dedicated email address for reporting phishing scams: phish@fb.com. Don’t download any applications you aren’t certain about.When accessing Facebook from places like hotels and airports, text "otp" to 32665 to receive a one-time password to your account.Visit Facebook’s security page and read the items "Take Action" and "Threats".

And on a related note, how do we verify whether email addresses are fake? Well, you could alway ping it.

Tech blogger Amit Agarwal wrote up instructions on how to ping an email address to determine if it was real of fake.

Or you could plug the questionable email address into this nifty little email verifier I came across.

It seems to work. Therefore, I'm sorry to report, NehemiahHesters@lisavaas.com, that you don't exist, so I guess I can't "Buy Ciails and Viarga online," which is a shame, since they sound like new drugs, tropical resorts, or a combination of both - the last of which strikes me as genius.

Follow @LisaVaas

Spear fishing image from Shutterstock.


View the original article here

Wednesday, September 12, 2012

Wayward Instagram account creates security scare for Norwegian Royal family

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Norwegian royalsThe secret life of the Norwegian royal family has been on display for anyone with an Instagram account after the son of the country's Crown Princess was found to be over-sharing photos of family holidays and other events, according to media reports.

Marius Borg Høiby, the 15 year-old son of Crown Princess Mette-Marit, had been posting the photos on a personal Instagram account. The photos included GPS information that could reveal the location of the royals – a major security lapse.

Høiby is the son of Crown Princess Mette-Marit from a relationship prior to her marriage to Norwegian Crown Prince Haakon. He is the half brother of their two children: Princess Ingrid Alexandra and Prince Sverre Magnus, royal heirs to the Norwegian throne.

Høiby'a Instagram account was public for close to a year, with the teenager posting frequent photos of himself and his family on holiday and in other informal settings. The photos were also shared with Høiby’s Instagram contacts.

The teen shared 133 photos, including pictures of the family at the Royal Palace in Oslo and on vacation. He also divulged information on the family’s location and planned travel, according to reports.

The incident has caused a minor scandal in Norway, where the media and security officials were quick to declare it a dangerous breach that could have put the family’s physical security at risk. Fingers pointed at Norway's police intelligence unit, the Politiets sikkerhetstjeneste (PST), for failing to properly inform the family about the risks in social media.

VG tabloidThat prompted Mette-Marit to write an open letter to VG editor Torry Pedersen Wednesday.

In it, she noted that the Instagram account had been removed, but questioned the media uproar over the leaked photos. The family’s movements and residences were a matter of public record, Mette-Marit argued, so Høiby's photos revealed little information that wasn’t already known.

But the incident has fed into an already simmering debate within Norway about what some see as the government’s lax attitudes about public safety. This, following the mass murder of 77 people in Oslo and the island of Utøya in July, 2011 by far-right nationalist and paranoid schizophrenic Anders Behring Breivik – an incident that continues to command headlines.

Geo-tagging is a common feature of most modern cameras, including cell phone cameras. The GPS coordinates in photos can be easily read and displayed using image editing tools or on photo-sharing sites like Flickr, which extract the GPS data from digital photos and map photos to their real world locations.

In a story published today, Naked Security contributor Paul Ducklin posted a photo of the daily specials board at an unnamed restaurant in his home town of Sydney, Australia. He challenged Naked Security readers to name the restaurant and give its address. In a matter of hours he had his answer – from Adrian in The Netherlands, who used an online photo processing tool to extract the location data.

The easy accessibility of location data poses a big problem for consumers and for security conscious organizations.

The US and British military have restrictions on the use of mobile phones in war zones. Earlier this year, the US Army warned about the dangers of geo-tagging by soldiers, as well.

Follow @paulfroberts

View the original article here