Dropbox Smeared in Week of Megabreaches
krebsonsecurity.com
krebsonsecurity.com
Experian a few months ago had a breach whereby millions of T mobile customers who had no idea that Experian was storing their data, had all of their sensitive data stolen. Experian's "solution" to the problem was to offer those who had their data stolen 2 years of free credit monitoring. Think about that for a moment - "we allowed your sensitive data that you didn't approve of us storing to be compromised and so we will now offer you a 2 year service after which you will be charged."
That is so completely outrageous, people should be out with pitchforks and torches but you can't fight this stuff, these agencies are far too powerful.
Just to further underscore how outrageous Experian and the other two agencies are - Experian notified people who had their data compromised using snail mail! What kind of decision is that for a time-sensitive situation?!
Lastly the letter they sent to customers and I read my friend who was a victims letter, said that the data that was compromised was data they were storing on T Mobile's behalf, as if they were in no way culpable.
So I guess I this is their strategy going forward is to acquire a half-baked and suspect security firm that will damage innocent companies reputations the same way they themselves have damaged innocent people's credit and identities.
I would urge people to call the three big credit agencies - Trans Union, Experian and Equifax and request that your credit be "locked." This means that nobody can look at your credit profile, except for people you currently have a line of credit with. You will be issued a pin and if and when you need to apply for credit you can then unlock your credit profile and re0lock it afterward. You need to re-up on this every two years which is insane as having your credit profile locked should be the default and should be in perpetuity, but you do what you can.
Keep in mind you will be charged for this.
https://www.consumer.ftc.gov/articles/0497-credit-freeze-faq...
> You'll need to supply your name, address, date of birth, Social Security number and other personal information. Fees vary based on where you live, but commonly range from $5 to $10.
[0]Libelous comments will come from my "partners", so I can't be held responsible for the accuracy of those claims.
Until then...
Fun Fact: According to a anonymous source, the board of Experian eat children on Friday.
But yes it's completely outrageous - you have to pay someone you didn't approve of having you data in the first place from giving it to another party likely did't approve of also having it.
The first level is realizing that "Identity theft" is a bullshit cover-your-ass scheme invented by banks and card networks to absolve themselves of responsibility for improperly securing their own systems.
Consumer identities are never "stolen". Maybe a criminal gets to know some numbers associated with you. Then, the fraud protections of a bank are breached by a fraudster. Thats a crime between the fraudster and the bank, and it's really a crazy innovation to say the consumer is responsible for the loss in that situation.
I'm not endorsing the mislabeling, just explaining how it came about. Obviously sanity, sustainability, and individual freedom depend on pushing back against that system's prescriptions and "keeping it real".
"Your identity has been stolen, sir"
"Uh, I don't believe it has. I'm me, and I always have been."
"Well, no, somebody came in and said they were you, and then they took all your money."
"And you believed them? That was foolish. It sounds like this is a bank robbery to me."
"No, no, no. We didn't get robbed. You got robbed. They took your money."
"But you gave it to them, right? Even though they weren't me. This still sounds like your screw up here."
edit: Ah ha, I found it! https://www.youtube.com/watch?v=CS9ptA3Ya9E
Eventually, I figured out it was nominally legit, but then I figured out the same organization that leaked my info was asking for more personal info so they could protect me. I opted not to do anything, because I couldn't think of any course of action that would improve the situation, and I certainly wasn't going to voluntarily give Experian any more of my info.
Experian's customers are not the people who received the letters. Their customers are those doing credit lookups for various reasons, and paying for it. Incentives matter, and Experian (et al) have an incentive to serve their customers, which is why they gather so much information and make it expensive, difficult, and inconvenient for their data subjects to withhold information.
Unfortunately this state of affairs is going to be difficult to fix with regulation (you can bet they'll lobby hard against that).
https://www.reddit.com/r/technology/comments/4m7ay6/teamview...
After using TeamViewer for over 5 years, I started getting a handful of invites on the service from random names about a month ago (I had never gotten a single invite prior). That alone signaled to me that something may be amiss. I'm afraid that where there is smoke, there's fire.
I couldn't find anything in that thread so I'll ask here in case anyone knows: is TeamViewer safe if it's NAT'ed with no open ports, or is there an opportunity when it phones home to compromise the machine?
The amount of fact checking tech "journalists" do means wrong information can really spiral out of control. I wonder if Dropbox can sue?
[0]https://www.troyhunt.com/heres-how-i-verify-data-breaches/
ah the old cut and paste from one site's article, rearrange some words, grind it through a thesarus-izer, then repost.
“But if someone takes out a mortgage in your name and now you owe the bank $100k or more – nobody covers that, and that’s what they need to cover.”
http://krebsonsecurity.com/2014/03/are-credit-monitoring-ser...
LifeLock's insurance covers court/lawyer fees/damages, IIRC.
It's called identity theft, but that's just a successful marketing campaign by the lazy banks and credit bureaus. It's fraud, and they (try to) push the consequences off on a party that is not really able to prevent it from happening. We should just tell them they aren't allowed to do that. Then we don't need Lifelock anymore.
The alert only says that the "Potential Site" of where the email was compromised is listed as www.dropbox.com .
The option for changing a password in online mail clients is lost in the menu clutter. In Gmail the process is to click Menu Bubble > My Account > Signing in to Gmail > Password. The issue I had is that at the 1st menu level there are options for Google+ Profile, Settings, Privacy, and My Account which all seem like valid places for the Change Password option to live. Each submenu is similarly cluttered, though when I found the correct path it made sense in retrospect.
I can't imagine Grandma changing her Gmail password this way. Maybe Google could replace the "Dvorak Keyboard" menu (Select Input Tool > English Dvorak) with an Update Password button. Is there a simpler process I'm not aware of?
Says it's version 5.3.19.