Showing posts with label cybersecurity. Show all posts
Showing posts with label cybersecurity. Show all posts

Sunday, April 27, 2025

Cybersecurity: AI Dulls Our Critical Thinking and Enables Scammers to be More Effective (Microsoft Warned Us!)

The rise of "AI" (mostly Large Language Models, or LLMs, like ChatGPT, Claude, Perplexity, and so on) does enable a lot of "productivity hacks". However, Microsoft had warned us back in Jan 2025 that the most you rely on them, the more atrophied your critical thinking skills. Most "knowledge workers" who admitted to using AI tools, only use their own critical thinking skills to "fact-check" the LLMs. This suggests that the "average user" may be doing even less than that. 

This bodes ill for the average user, as they seem to regard ChatGPT and LLMs as some sort of generic "expert", when it is nothing of the sort. Indeed, merely by browsing /r/cybersecurity_help there are a number of topics where the poster openly admitted to "I checked my logs with ChatGPT..." when they lacked even the skills to fact-check the LLM they used. They suspected something, and they wanted ChatGPT to confirm their suspicions. 

But that's not the actually worrying part. Instead, Microsoft security is ringing the alarm: scammers are using LLMs to craft their latest scams to enhance their social engineering... by leveraging every sort of fakery possible, from fake website to fake job posting to fake customer service chatbots, because making them is so much easier with LLMs consolidating such knowledge. 

Be wary out there. 

Sunday, March 9, 2025

Cybersecurity: Stop the Fake CAPTCHA Run Trap

Recently, there has been a spade of reports in Reddit's /r/cybersecurity of a "new" attack that relies on users being unaware of how their computer works, and tricked into executing a malicous script, by describing the attack as a CAPTCHA challenge. 

CAPTCHA stands for "completely automated Public Turing test to tell computers and Humans Apart". It's those picture tests where you need to answer certain question, such as "pick out the tiles in a segmented picture that contains a bus" or "which pictures has a motorcycle in it?" But later the term was genericized to mean any sort of "are you human" challenge test designed to weed out the automated scripts. 

The fake version asks the user to press Windows-R on their keyboard, followed by Control-V, to prove they're human. 

EDIT: The attack has been highlighted by KrebsOnSecurity and named "ClickFix" attack

If you didn't recognize these keystrokes, Windows-R (Win-R) brings up the Windows Run box, where you are supposed to enter a program to run. And Control-V (Ctrl-V) pastes what's in the clipboard into the whatever you have open. 

In other words, you just ran something, but you have no idea what. 

That is indeed... VERY bad. Because you basically just gave away control of your PC to the bad guys. And who knows what they'll do with it, probably download malware to your PC, steal all your accounts, and more. 

Given that 99% of the users will NEVER need to touch the Run box, you should disable it ASAP, esp. if you have computers being used by users who can be tricked into running this (very young, or very old)

To disable the Windows Run box, please follow this article: 

https://www.auslogics.com/en/articles/enable-or-disable-run-command-winr-box/

There are ways around it, but if you trained your users well (call me if you run into any errors you don't understand), you can stop them from trying to further compromise their PC. This is basically a barrier that says "are you sure what you're doing? Call me before you continue..." instead of blindly follow some malicious instructions. 

Wednesday, March 5, 2025

Cybersecurity: How Do You Know If Your Antivirus is Working (without actual Malware)?

Antivirus is a lot like having insurance... you have it, but hope you never have to use it. 

What if I tell you that you can test your antivirus on your PC, without downloading any malware, by simply typing something on your keyboard? If it reacts, the antivirus is working. If it didn't... your antivirus' real-time scan is not working. 

This only works on Windows, by the way. 

Open a powershell window. (If you don't know what is Powershell, please read this from Microsoft. It's already in your system.  https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/powershell )

What you will type or copy is just a string, a bunch of characters. It is NOT a script or malware. It is offered by Microsoft as a way to test their own AMSI (Microsoft Antimalware Scan Interface)

Enter this at the prompt:  ‘AMSI Test Sample: 7e72c3ce-861b-4339-8740-0ac1484c1386’ 

Note, please replace the fancy quotes with single quotes to get this to work properly. Yes, the single quotes are important. 

Microsoft Security should trigger as you press enter. Depending on whether you have any clipboard management software, it may react as soon as you try to copy the string onto the clipboard. 

Now you know whether your antivirus is active or not. 

There are, of course, other ways to test this. For this method (all credits goes to Black Hills Info Sec) and other ways, go read BHIS's blogpost: https://www.blackhillsinfosec.com/is-this-thing-on/

Sunday, January 12, 2025

Cybersecurity: Stop Diagnosing Yourself with Pegasus!

As one of the "trusted contributors" on /r/cybersecurity on Reddit.com, one of the FAQs was "Is my phone hacked with Pegasus? My (evil ex) is stalking me." 

The answer is "extremely unlikely". Pegasus is reserved for nation-state actors because it costs a TON of money to license, so it's only deployed against mostly political people, or people with possibly high influence and wide reach, such as reporters. While Wired deployed sensational headlines "Spyware  Scandals are Ripping Through Europe", and the verbiage was literally "commercial spyware has been deployed by more actors against a wider range of victims", implying that even normal citizens can be targeted by commercial spyware, the literally truth is, again, only people of high influence (politicians and reporters) are being targeted, i.e. "prevailing narrative has still been that the malware is used in targeted attacks against an extremely small number of people", even though the article was stating that literally despite trying to claim the opposite. Yes, Pegasus, developed by NSO Group, is getting some competition in Europe, where OTHER companies are developing similar spyware... with similar price tags.  

The article in question "$1 phone scanner finds seven Pegasus spyware infections" basically states that iVerify has managed to develope a tool to detect Pegasus and other commercial spyware. It sold $1 trial package called "IVerify Basics", and if the user choose to turn on Spyware Detection, they can generate a fingerprint to be submitted to iVerify for analysis, and 2500 or so people have done so. Out of the 2500, they found SEVEN instances of Pegasus infection. According to iVerify, "people who were targeted were not just journalists and activists, but business leaders, people running commercial enterprises, people in government positions", even though in the next paragraphs, they pointed to a Sikh political activist (and a lawyer) as one of the iVerify successful detections. They also pointed out that two of Harris-Walz staff's phones were infected.  

The article concludes with "the rate (of spyware infection) is much higher than the prevailing narrative". Yes, it is much higher, but the original number was such an infinitisimally small number, even if it's 10-100x higher, it STILL a tiny number of users being targeted. Important people... Business leaders, CEO, Company Presidents, government employees, political employees, etc. in addition to the typical reporters and political activists. 

Not average citizens on the streets. 

Sunday, December 29, 2024

App Discovery: Destiny, the secure cross-platform file transfer method

Want to transfer a file across platforms (Windows, MacOS, iOS, Android, Linux) but can't find common ground? Destiny can help. Download from

https://github.com/LeastAuthority/destiny?tab=readme-ov-file#installation

There is nothing to set. If both platforms are on the same network (i.e. phone to PC, or vice versa), simply sender run the app and pick SEND, and receiver pick RECEIVE. Then sender choose the file to send, and a passphrase is generated, easy to type in English. As soon as receiver type in the same passphrase, file transfer will start, and since it's happening at local network speed, it's almost instantaneous.  

The client, using "magic-wormhole" protocol, will automatically negotiate alternative protocols if you are on different networks, through the Internet, and so on. And the traffic is encrypted. No interception. Remember, cross platform too. You can go any client to any other client. You can send the passphrase through any "normal" means: SMS, encrypted chat, email, or even call them up and tell them. 

I've tested Android to PC and vice versa on local network. It works great. Previously I had to rely on Google Drive or DropBox to sync the files, and I've also purchased a "Wifi Server" where the Android app hosts a GUI that allows a browser to access the local storage. First is slow, second is a little PITA to run. This manages to be neither. 

My only nitpick is you can only transfer ONE FILE AT A TIME. For each file, you have to initiate a send, and thus, a new passphrase. Not quite frictionless, but for the amount of security it provides, it's almost unbeatable. 

So if you need to frequently transfer single file between your devices, this is a very simple way to do it. Worth a try, at least. 

Tuesday, July 9, 2024

Cybersecurity: Where did the term "pwn" come from?

It is surprising how many people got the "true" origin of the verb "pwn" not quite right... even operators of "HaveIBeenPwned.com". They at least understood it's a typo ("O" and "P" are right next to each other on the keyboard!). But they then linked to an Inverse article, who went into a bunch of alt explanations such as it's a corruption of "pawn" (from a chess match) to "Phrack World News" (abbreviated as PWN). Neither theory explains how it was transformed into a verb. In fact, Inverse article chose to disregard the typo theory.  

The true origin of the term pwn, is synonymous with own, usually used in past tense as "owned". In l33tspeak of the time, being "owned" means you were utterly controlled, dominated, and humiliated, usually because you are losing or lost in an online multiplayer game. 

So how did pwn variation got created? 

For that, you need to thank Warcraft, NOT World of Warcraft that came much later. The ORIGINAL Warcraft: Orcs & Humans RTS, and its mods, basically, maps, at the time. 

To make a long story short, one of the map designers wrote a "losing condition" text. When you lose to the other side, you're supposed to get a message to the effect of "You've been owned!" However, he had a typo that day and the map was uploaded with the text "You've been pwned!" instead. The expression then, as we would say today, "went viral", and the rest is history. 

In fact, you can still find this definition in the Urban Dictionary. 

But wait, you ask, what is "HaveIBeenpwned.com"? 

It is a website where you can check your email addresses to see if your information have been leaked in various hacks and data leaks before. Those information tend to surface on the Dark Web, and some gather those up and make them search accessible to let people check if they were affected by the leak. 

Thursday, July 4, 2024

Cybersecurity: No, your email was (probably) NOT hacked, it's (probably) just spam

Over in the subreddit /r/cybersecurityhelp we get one of these daily. This is NOT an exact copy, but the sentiments are the same. 
Help! I got an email sent from my own email address and shows my password! It claims it had tracked me and if I don't send him Bitcoins he'll hack me and ruin me! 

This is unlikely to be real, and it's a case of psychological manipulation, by combining two simple tricks, to make you think he's more powerful than he actually is. 

In other words, it's a case of 2+2=5. 

Photo by Andrey Matveev on Unsplash

Sent from my own email address... No! 

While the email may indeed show "from" as your own email address, it was NOT sent by you. No one hacked your email and use that to send email to yourself. 

What really happened was the "from address" was changed to say YOUR email address instead of the sender's own email address. 

Do you still remember paper letters? That you write your own name and address in the upper left hand corner of the envelope? 

There's nothing stopping you from writing someone else's name and address, is there? Same thing with email. 

Yes, you can say "that's dumb". But you have to remember, email was invented in the 1960s, and the current standard, SMTP, was invented in the 1980s, and extended as ESMTP in 1995. Authentication (i.e. make sure the sender matches FROM) was not a part of the protocol until SMTP AUTH (included in ESMTP) became popular in the 1990s. Adoption of ESMTP is not universal, however. And most email servers do not require ESMTP. 

Please keep in mind that emails transit through the Internet from one SMTP server to another until they reach their respective destinations, accumulating delivery headers in the email itself. And thus, any email (including spam) can be backtraced. Most email clients hide the headers from the user as they are of no use to the end user... until you want to track the true origin of the email. But that is a completely different topic. 

So that email that say its from your own email address? It was (probably) NOT sent by you. Someone merely put your email address in the "From" field. 

What about my password? How did he know about that?

That's actually pretty simple: there are data leaks as different websites got hacked, and the data ended up on the Dark Web.  They contain all sorts of info, from simple email / password pairs to full profiles and possibly more, depending on where the data came from. 

Some security researchers and good samaritans collated all those leaks on the Dark Web and created a website called "haveIbeenpwned.com" where you can enter your email address and see if any data associated with that email was on the Dark Web, and associated with which leak. 

Back to the email... The sender simply got the data (the password in this case) from the Dark Web leak that's associated with your email. 

Add them together, and it's scary to the average citizen

So what do I do? 

Short answer is: nothing. It's just spam. Mark it as spam in your email client. Done. 

You can change all your passwords "just in case". You should do that every 3-6 months anyway. 

Here's the longer explanation: 

You initially panicked, believing the sender of that warning message is a powerful hacker (because he claimed he was), who not only hacked your email inbox to send you a message from it, he obviously knows your password too, demonstrably so. 

But as I've explained above, your email inbox was NOT hacked, and the password came from a public leak list. 

The spammer wanted to scare you into believing 2+2=5.  But the real answer is 4. 

The "warning" or "threat" is just spam email. Indeed, the spammer probably got a whole LIST of email / password pairs (hundreds? thousands) and probably sent the same message (albeit customized with the correct email address and password, in a simple procedure known as templated mail merge) to EVERYBODY on the list. Cost them almost nothing. Someone may be scared enough to send them Bitcoins for real. 

So again, mark it as spam in your email client. Done.  Change your passwords if you want to. 

Takeaway:  Don't believe what random email told you, esp. ones that wants you to pay them. 

Tuesday, April 30, 2024

Darn it, Aliexpress, TAKE MY MONEY!!!!!

 Aliexpress.us is basically the international website of China's Alibaba group, sort of their international Amazon that long predates sites like Wish, Shein, and Temu. It has a ton of bargains, long recognized by bargain hunters willing to put up with longer shipping times. If you look at watch enthusiast sites, you'll find frequent mentions of Aliexpress as where you find Chinese "homage" watches (read: clones of well known watches) for nearly the same quality but at bargain prices, under $100 USD, or even under $50. But that's not what I was looking for. 

Just the other day, I saw that "Fashion Over 40" guy was advertising a special collar stay that's reusable, that goes around the whole collar instead just under the tip of the shirt collars. I swear I've seen this before elsewhere, and Google search finally located them on Aliexpress... for $2.00 (or less) instead of 2 for $25 in the US. 

So I tried to order one. Then Aliexpress started doing the Temu dance... Throwing various special deals at me, free shipping if you take X items, etc. etc. Got me distracted with a variety of items, from a tiny display screen for PC internal status to $1 infinity cube fidget toy to name-brand (Lenovo, Xiaomi, etc.) ANC BT earbuds for a few bucks, and much more. There are even a deal where $1.00 gets you a watch plus a couple "leather" bracelets (it won't be a good one, that's for sure). Fountain pens for a few bucks, comes with 10 to 50 extra ink carts... Add to cart they were. 

Then I placed an order, and in order NOT to enter my own card info into their site, I went through Paypal. Unfortunately, I forgot I hadn't made the payment on my CC, so the Paypal was rejected. I had to swap payment method in Paypal (to draw from my bank account) to make it go through. And that order went through... Except for the collar stay, why I got on there to start with, ARGH! 

So I went back to make a new order. 

And Aliexpress refused to take my money. Keeps saying "Account protection, contact customer service". Tried logging out and back in, won't let me check out. Talking to customer service did not help. Tried waiting 48 hours, didn't help. Tried waiting a week, didn't help. Tried making a new account, did not help. As soon as they detected the same address, same error! Chatted with customer service multiple times, didn't help. They assured me the issue is being escalated, then nothing. 

I must be mad, because I refused to give up on buying that collar stay. This time, I'm going to enlist two new tools: my mail.com account, and privacy.com virtual card. 

Weapon 1: Mail.com

Mail.com is where you can get a new email address. If you pay a reasonable price per year, you get a email linked to a domain name that doesn't say gmail, yahoo, or outlook. As for what you do get, why don't you go there and take a look? What's even better deal, mail.com premium allows the creation of up to 10 "alias" email addresses, all of them using the various premium Mail.com domains, and wipe them out when you no longer need them. This will allow me to register a truly new account on Aliexpress. 

Weapon 1.5: Google Voice

If they want a new phone, I have my Google Voice phone number for them. 

Weapon 2: Privacy.com

If you haven't heard of privacy.com, you should check it ASAP. It makes shopping online MUCH safer. This is how it works: by connecting to your bank account, it will provide "virtual credit cards" for you. The free-tier account gives you up to 10 card numbers, all of them with their individual numbers and expiration dates. Generate one for each online merchant if you wish. Pay a monthly fee to generate even MORE card numbers. Cut each off at any time, or set a spending limit to each number, by day, by week, by month, by transaction... Set a ridiculously low amount like $35. You can't lose more than that. Get notified each and every time a charge goes through. Or use the card a SINGLE time, and have it automatically expire after 72 hours so it can't be used again. It's all up to you. And there's even a Chrome extension to help you shop online.

Yep, this card cannot be linked back to me personally, as long as I don't put in my own address into Aliexpress. Fortunately, my neighbor already takes my packages when I am not there. So I'll just put in his address. 

And this time, the order *did* go through. Half dozen items. 

I am trying to SPEND money on your website, Aliexpress. I should not have to outsmart your pathetic "security" measures to do so.