Showing posts with label email. Show all posts
Showing posts with label email. Show all posts

Thursday, July 4, 2024

Cybersecurity: No, your email was (probably) NOT hacked, it's (probably) just spam

Over in the subreddit /r/cybersecurityhelp we get one of these daily. This is NOT an exact copy, but the sentiments are the same. 
Help! I got an email sent from my own email address and shows my password! It claims it had tracked me and if I don't send him Bitcoins he'll hack me and ruin me! 

This is unlikely to be real, and it's a case of psychological manipulation, by combining two simple tricks, to make you think he's more powerful than he actually is. 

In other words, it's a case of 2+2=5. 

Photo by Andrey Matveev on Unsplash

Sent from my own email address... No! 

While the email may indeed show "from" as your own email address, it was NOT sent by you. No one hacked your email and use that to send email to yourself. 

What really happened was the "from address" was changed to say YOUR email address instead of the sender's own email address. 

Do you still remember paper letters? That you write your own name and address in the upper left hand corner of the envelope? 

There's nothing stopping you from writing someone else's name and address, is there? Same thing with email. 

Yes, you can say "that's dumb". But you have to remember, email was invented in the 1960s, and the current standard, SMTP, was invented in the 1980s, and extended as ESMTP in 1995. Authentication (i.e. make sure the sender matches FROM) was not a part of the protocol until SMTP AUTH (included in ESMTP) became popular in the 1990s. Adoption of ESMTP is not universal, however. And most email servers do not require ESMTP. 

Please keep in mind that emails transit through the Internet from one SMTP server to another until they reach their respective destinations, accumulating delivery headers in the email itself. And thus, any email (including spam) can be backtraced. Most email clients hide the headers from the user as they are of no use to the end user... until you want to track the true origin of the email. But that is a completely different topic. 

So that email that say its from your own email address? It was (probably) NOT sent by you. Someone merely put your email address in the "From" field. 

What about my password? How did he know about that?

That's actually pretty simple: there are data leaks as different websites got hacked, and the data ended up on the Dark Web.  They contain all sorts of info, from simple email / password pairs to full profiles and possibly more, depending on where the data came from. 

Some security researchers and good samaritans collated all those leaks on the Dark Web and created a website called "haveIbeenpwned.com" where you can enter your email address and see if any data associated with that email was on the Dark Web, and associated with which leak. 

Back to the email... The sender simply got the data (the password in this case) from the Dark Web leak that's associated with your email. 

Add them together, and it's scary to the average citizen

So what do I do? 

Short answer is: nothing. It's just spam. Mark it as spam in your email client. Done. 

You can change all your passwords "just in case". You should do that every 3-6 months anyway. 

Here's the longer explanation: 

You initially panicked, believing the sender of that warning message is a powerful hacker (because he claimed he was), who not only hacked your email inbox to send you a message from it, he obviously knows your password too, demonstrably so. 

But as I've explained above, your email inbox was NOT hacked, and the password came from a public leak list. 

The spammer wanted to scare you into believing 2+2=5.  But the real answer is 4. 

The "warning" or "threat" is just spam email. Indeed, the spammer probably got a whole LIST of email / password pairs (hundreds? thousands) and probably sent the same message (albeit customized with the correct email address and password, in a simple procedure known as templated mail merge) to EVERYBODY on the list. Cost them almost nothing. Someone may be scared enough to send them Bitcoins for real. 

So again, mark it as spam in your email client. Done.  Change your passwords if you want to. 

Takeaway:  Don't believe what random email told you, esp. ones that wants you to pay them. 

Tuesday, April 30, 2024

Darn it, Aliexpress, TAKE MY MONEY!!!!!

 Aliexpress.us is basically the international website of China's Alibaba group, sort of their international Amazon that long predates sites like Wish, Shein, and Temu. It has a ton of bargains, long recognized by bargain hunters willing to put up with longer shipping times. If you look at watch enthusiast sites, you'll find frequent mentions of Aliexpress as where you find Chinese "homage" watches (read: clones of well known watches) for nearly the same quality but at bargain prices, under $100 USD, or even under $50. But that's not what I was looking for. 

Just the other day, I saw that "Fashion Over 40" guy was advertising a special collar stay that's reusable, that goes around the whole collar instead just under the tip of the shirt collars. I swear I've seen this before elsewhere, and Google search finally located them on Aliexpress... for $2.00 (or less) instead of 2 for $25 in the US. 

So I tried to order one. Then Aliexpress started doing the Temu dance... Throwing various special deals at me, free shipping if you take X items, etc. etc. Got me distracted with a variety of items, from a tiny display screen for PC internal status to $1 infinity cube fidget toy to name-brand (Lenovo, Xiaomi, etc.) ANC BT earbuds for a few bucks, and much more. There are even a deal where $1.00 gets you a watch plus a couple "leather" bracelets (it won't be a good one, that's for sure). Fountain pens for a few bucks, comes with 10 to 50 extra ink carts... Add to cart they were. 

Then I placed an order, and in order NOT to enter my own card info into their site, I went through Paypal. Unfortunately, I forgot I hadn't made the payment on my CC, so the Paypal was rejected. I had to swap payment method in Paypal (to draw from my bank account) to make it go through. And that order went through... Except for the collar stay, why I got on there to start with, ARGH! 

So I went back to make a new order. 

And Aliexpress refused to take my money. Keeps saying "Account protection, contact customer service". Tried logging out and back in, won't let me check out. Talking to customer service did not help. Tried waiting 48 hours, didn't help. Tried waiting a week, didn't help. Tried making a new account, did not help. As soon as they detected the same address, same error! Chatted with customer service multiple times, didn't help. They assured me the issue is being escalated, then nothing. 

I must be mad, because I refused to give up on buying that collar stay. This time, I'm going to enlist two new tools: my mail.com account, and privacy.com virtual card. 

Weapon 1: Mail.com

Mail.com is where you can get a new email address. If you pay a reasonable price per year, you get a email linked to a domain name that doesn't say gmail, yahoo, or outlook. As for what you do get, why don't you go there and take a look? What's even better deal, mail.com premium allows the creation of up to 10 "alias" email addresses, all of them using the various premium Mail.com domains, and wipe them out when you no longer need them. This will allow me to register a truly new account on Aliexpress. 

Weapon 1.5: Google Voice

If they want a new phone, I have my Google Voice phone number for them. 

Weapon 2: Privacy.com

If you haven't heard of privacy.com, you should check it ASAP. It makes shopping online MUCH safer. This is how it works: by connecting to your bank account, it will provide "virtual credit cards" for you. The free-tier account gives you up to 10 card numbers, all of them with their individual numbers and expiration dates. Generate one for each online merchant if you wish. Pay a monthly fee to generate even MORE card numbers. Cut each off at any time, or set a spending limit to each number, by day, by week, by month, by transaction... Set a ridiculously low amount like $35. You can't lose more than that. Get notified each and every time a charge goes through. Or use the card a SINGLE time, and have it automatically expire after 72 hours so it can't be used again. It's all up to you. And there's even a Chrome extension to help you shop online.

Yep, this card cannot be linked back to me personally, as long as I don't put in my own address into Aliexpress. Fortunately, my neighbor already takes my packages when I am not there. So I'll just put in his address. 

And this time, the order *did* go through. Half dozen items. 

I am trying to SPEND money on your website, Aliexpress. I should not have to outsmart your pathetic "security" measures to do so.