Showing posts with label Internet security. Show all posts
Showing posts with label Internet security. Show all posts

Tuesday, August 11, 2026

AI Security Threats - Is It Time to Panic?

Introduction

It’s been over nine years since my last post about how to stay secure online. A lot has changed since then, particularly with Artificial Intelligence making everybody more effective at everything. (At least, this is what Corporate America is telling itself, and in the case of fraudsters, it’s actually true.) In this post I’ll briefly highlight some of the most pressing AI-driven threats, and then focus on what you can actually do to protect yourself, vs. what we’ll have to hope “they” can protect us from. Short version: be extra wary of phishing and spear-phishing attacks. (Oh, and no point in panicking … yet … as far as I know. I put “panic” in the title of this post just to grab your attention—and look, it worked!)


Major AI-driven security threats

Here are some of the top Internet security threats presented by AI:

  1. Autonomous attacks: Fraudsters are using agentic AI to unleash fully automatic phishing and other attacks, greatly speeding up their campaigns.
  2. AI systems as attack surface: As companies build AI into email, documents, and workflows, attackers are targeting the AI stack directly rather than going around it. (Some call this “AI supply chain compromise.”) Malicious instructions can be hidden inside the content that an AI reads as it goes about its job, and training data can be poisoned.
  3. Deepfake-driven identity collapse: AI can produce realistic voice, face, video, and document forgeries cheaply and at scale. This can undermine authentication systems across corporate, banking, and consumer platforms.
  4. Data leakage from ordinary use: As corporate employees use AI normally, and get very specific in providing context for their prompts, they often share more info than they mean to, giving bad actors access to sensitive data without even having to steal it.

(Why four threats, instead of a nice round number like three or five? I based my assessment on queries I made to ChatGPT, Gemini, Copilot, and Claude, and these are the four top threats that all these models agreed on.)

On top of these threats, and overlaying them, is Open Source Intelligence (OSINT), which in the context of Internet security refers to personally identifiable information (PII) that over time has become public due to voluntary posting of it, such as on social media (e.g., Facebook users sharing info about themselves, their activities, and their families, assuming it’s only seen by friends and online “friends” and not realizing how easily shareable it is across the entire Internet). All this data has been increasingly well indexed by Google and other Internet tools, and now web scrapers and other generative AI tools can easily harness this sensitive data to create targeted phishing (i.e., spear-phishing) attacks.

An example of an OSINT hack

This will all make more sense, I think, if I provide an example. It occurred to me recently that anyone with a Gmail account could create a Gemini Notebook into which they could feed large batches of albertnet posts, to turn this very blog into a chatbot. They then could query this chatbot for any and all PII that could be used to answer security questions when trying to impersonate me. To identify such vulnerabilities, I did this exact exercise myself (employing a tactic called Defensive OSINT—basically beating hackers to the punch). I fed the most likely categories of albertnet posts (e.g., Parenting, Bits & Bobs) into a Notebook and asked the chatbot to build a comprehensive “public knowledge index” of PII based on the categories most often used for website authentication security questions. Then I had it produce a report describing the vulnerabilities it found.

Did it come up with anything? Well, yes: it found one item of rather sensitive information based on a bit of handwritten text that was included on a picture that was posted. I found that pretty embarrassing, but it was easy enough to remove since this is my blog and I manage the content directly. (Also, because I own the domain used by my blog, I can go to web.archive.org and have the original version of the post removed forever.)  Fortunately, I’ve had an eye on privacy and security for the whole time I’ve been blogging, so other than some pet names and schools I attended, I’m overall in pretty good shape. Here’s a particularly amusing excerpt from the Gemini Notebook security audit report:

Category V: Workplace & Career

The author’s career trajectory is extensively documented, providing a roadmap for Business Email Compromise (BEC) and “Career Gate” attacks.

Security Risk Assessment: Attacker groups scrape metadata from Blogger sidebars (e.g., the “Specialist” title) to craft highly targeted BEC lures. By referencing past roles like “underwear canner” or “radio station receptionist,” an attacker can establishing [sic] a false commonality to bypass corporate security screenings or impersonate a former HR representative for the purpose of credential harvesting. 

As you can see, when you share personal information on the Internet, it’s highly advisable to bullshit a lot. I have a feeling that the above career information, even in the hands of the most devious hacker, isn’t going to get me in a lot of trouble. I do need to warn family members not to use any of the PII in my report (e.g., a pet’s name, a school name) as security answers, though I’ve already cautioned them—as I’ll now caution you—to not use real PII for security questions in any case; after all, you can’t change your mother’s maiden name or the city you were born in, so once somebody hacks a website and gains these answers, you’re pretty much hosed. And good luck remembering what security questions and answers you’ve set up over the years across all the sites that use them for authentication.

So can everyone run this kind of audit? Well, any blogger can, but if you’ve been active on multiple social media platforms over the last ten or fifteen years, it’s gonna be really tough. And remember, in many cases (e.g., Facebook) you do not actually own that information. Probably the best thing you can do is keep an eye out for spear-phishing attacks.

Some updated anti-phishing basics

In my previous post on phishing, I pointed out that you could often spot fraud based on bad spelling or grammar (e.g., “Security fraud alerted corporate card!” or “Account info updating needs!”). This is no longer a reliable rule of thumb, because AI has gotten so good at grammar and even at matching the style of the supposed sender. It’s more likely to produce a realistic subject line as well (as opposed to something generic like “Hello”) and isn’t so prone to excess emoticons, weird fonts, and/or tacked-on numbers (e.g., “✅  π™‹π™‘π™šπ™–π™¨π™š π™˜π™€π™£π™›π™žπ™§π™’ if you're qualified for a compensation 5078227).” My previous advice still stands: don’t click on any link in an email unless you completely trust the sender, and have hovered your cursor over the link to make sure the domain matches what you’d expect based on what your contact purports to be sending you.

For example, if a cycling buddy sends you an email that says, “You’ve got to check out this Tour de France blow-by-blow report from albertnet,” and the link says “Tour de France Stage 15,” and you hover over the link and see the URL “https://www.albertnet.us/2026/07/biased-blow-by-blow-2026-tour-de-france.html, ” that would be safe. But if you get an email from $CashApp$  (nxaqlvxcvm@ekgkx1ylmv.co.us via arbeitsstellepro.com) with the same message (or any message, actually), you shouldn’t click on any link in it. Or, let’s say you get the same aforementioned Tour de France email from a trusted pal, but hover over the included link and see “https://www.xtremecloudmontzer.xyz/encryptvictimHD” … you obviously shouldn’t click it. Now let’s say you got a legit albertnet link to the Tour de France post, but from a friend who constantly bags on my blog and/or on the Tour de France. Valid-looking URL aside, you might reasonably decide the message fails the sanity test, and you should send a separate email to that friend asking, “Did you really send me a link to an albertnet post?”

Always be especially careful with any email that conveys a sense of urgency and wants you to take immediate action. Fraudsters will employ that to try to get you to bypass your normal habit of being careful and deliberate with your email. It isn’t always the foreboding kind of urgent; it could alternatively be the upbeat kind of urgent, like a party invitation, which gets us excited because hey, fun, party! 

Anatomy of a spear-phishing attack

A friend of mine fell prey to a spear-phishing attack recently because an email she received was from a friend who’d been on a volunteer board of directors with her, who quite reasonably could be hosting a reunion. The email looked like a standard punchbowl.com invite, with the right logo, etc. My friend, due to a momentary lapse of reason, clicked the link without hovering over it. If she had bothered to hover, she’d have seen this (click to enlarge):


Since my friend doesn’t use Outlook, she wouldn’t have been falsely comforted by the “Protected by Outlook” indication and in fact would have found it suspicious—had she hovered over and seen it! Meanwhile, even if the fraudster had lucked out and my friend were on Outlook, she would have been wise to suspect the “roves.sbs” because a) it isn’t the punchbowl.com domain, b) it isn’t anything recognizable, and c) that .sbs top-level domain is automatically suspicious because that’s an extremely cheap domain, perfect for hackers. (They love a cheap domain they can set up to snare as many victims as possible before the fraudulent site is identified and flagged by security community filters like Google Safe Browsing or Norton.) On top of all this, the URL shown above isn’t even itself the real URL—it’s a bogus tooltip set up by the hackers. You need to look in the lower left of your browser screen to see the real URL, which in this case was “accounts.lifeofastartryfghjgd.icu,” which a) also isn’t the punchbowl.com domain, b) also isn’t recognizable, c) looks like somebody started to type something plausible but lost patience, and d) has another disposable, cheap, very phishy landing page domain. Alas, my friend missed all of this, delighted as she was to be invited by a friend to a party, and just clicked the link.

From here, things went even more sideways. First, she was presented with a CAPTCHA she had to solve to prove she was human. This was employed by the attacker for three reasons:

  1. It stymied her security software, hiding the phishing page and thereby preventing the software from blocking it;
  2. It established a sense of trust, because users associate CAPTCHA screens with security (i.e., it made my friend think the site was establishing that a bot wasn’t trying to accept the invitation);
  3. It confirmed to the attackers that a real human—i.e., a dupe—had actively taken the bait, and they probably added my friend to a list of suckers who should be actively phished again in the future.

Then, the page went in for the kill, saying that to accept the invitation and add it to her calendar, my friend should log in to her Google account. It helpfully provided the input fields to do so. Only at this point did my friend smell a rat, and closed the page instead of serving up her Gmail address and password to the hackers. Probably there was no harm done, but man, what a close call! (It’s possible the site could have meanwhile instigated a “drive-by” malware download, but this probably wouldn’t have worked without her browser asking her to explicitly approve a file download or browser extension installation.)

As you can see, phishing has gotten more sophisticated. And the worst part of the phishing email my friend received was that it did come from a known person, and (whether through luck or knowledge of the person’s work experience) created a plausible scenario: this was exactly the kind of invitation my friend would expect to receive from this person. This is one of the ways spear phishing attacks are engineered.

Incidentally, my friend contacted the sender, and sure enough, this person’s PC had been compromised and the attack mounted against everyone in her address book. Why she hadn’t warned anyone is a mystery to me, and I hereby implore you to let all your contacts know if your system ever gets hacked. It’s no different than the responsibility a sexually promiscuous person has to notify his or her paramours about testing positive for a venereal disease. (For a charming comedy series on this theme, you might check out “Lovesick” on Netflix.)

AI and spear-phishing

Getting back to AI, it changes the game by making phishing attacks more realistic than ever, and at a lower cost to hackers. In the past, spear phishing was time- and labor-intensive, and thus reserved for people who are (no offense) bigger targets than you. But now, with AI, producing a bespoke attack with maximum plausibility has gotten easy, fast, and cheap. Gemini describes it thus:

Traditionally, gathering intelligence on a target required significant manual effort. If an attacker wanted to map out a corporate hierarchy, scrape executive social media, identify software stacks, or build custom spear-phishing personas, it took days or weeks of painstaking human research.

AI-driven OSINT compresses that timeline from weeks to seconds:

  • Automated Harvesters: AI tools can scrape public records, forum posts, code repositories, blog archives, and dark web dumps simultaneously.
  • Instant Synthesis: LLMs [large language models] parse millions of lines of unstructured text, connect disconnected data points across 15 different platforms, and output a clean, actionable “target profile” with zero fatigue. 

This means that instead of a person employing just a few methods to get the target to let his or her guard down (e.g., crafting a realistic-looking, well-written email seemingly from a friend who might plausibly have written it), AI can generate a hyper-personalized attack, presenting specific contextual details designed to boost the sense of authenticity, with a high likelihood of dissolving the recipient’s natural defenses of skepticism and caution.

Imagine if my blog were less slippery, and the career info I posted were actually relevant and factual. I could get an email from someone purporting to have served with me in the Artillery Regiment in the late ‘80s, who has announced he’s become very successful in the underwear canning business; understands my frustration with modern corporate America; and would like to talk to me about an executive position at his startup with great pay, a signing bonus, and stock options—and all I have to do is go to this website and upload my CV! The specificity of this email might dupe me, if I actually had served in the same Artillery Regiment, and if canning underwear had been a bigger part of my career. And imagine if the fraudster spoofed the identity of a guy I actually knew (“it’s your old pal Fred, from the Hot Chillys cannery!”) … the email would seem pretty legit. Somebody harvesting LinkedIn PII instead of albertnet might actually get somewhere.

The ABC mnemonic

To protect yourself from spear-phishing attacks, I recommend borrowing a concept from police detective training: the investigative doctrine of “ABC.” Across the UK and Commonwealth, detective trainees are taught to Assume nothing; Believe nothing; Check everything.” Adapting this for Internet security:

  • Don’t assume an email is safe, just because it has proper formatting and logos, good grammar and spelling, etc.
  • Don’t believe an email is really an intentional communication from your friend, even when the source email address checks out, if there’s anything even slightly phishy about it
  • Check for any sign that the email could be fraudulent.

Here are things to watch for in that third “check everything” step:

  • The email has a mismatched “From” vs. “Reply-To” address (e.g., purports to be from Bank of America but the reply-to address has a phishy domain like banksupport@bank.sbs)
  • It includes a link it wants you to click, especially from an unusual top-level domain (basically anything other than .com, .gov, .edu, or .us and especially the johnny-come-lately TLDs like .xyz and .biz or anything you don’t recognize—always remember to hover over a link before clicking it)
  • It includes a link with a shortened URL like bit.ly (which can be used to hide a phishy domain)
  • It has a file attachment, especially something besides a PDF or JPG
  • It conveys a sense of urgency (especially from a bank or other business telling you they’re going to have to block your account, or already have, or will have to close it unless action is taken such as updating your payment details, etc.)
  • Is from a business but has emoticons in the subject line (I mean, really?!)

Is albertnet safe?

Yes, albertnet is perfectly safe. This website doesn’t run any scripts; doesn’t employ cookies or tracking pixels or Google Analytics; won’t try to install anything; and never includes links to unsafe websites. I won’t serve you ads, don’t want your money, and respect your privacy. About the only risk you’ll run is believing I served in an artillery regiment, or that Strava has a new nighttime KOM category, or that the Tour of Sweden was held in 2020 at the height of the COVID-19 pandemic. And at least when I bullshit you I always fess up.

—~—~—~—~—~—~—~—~—
Email me here. For a complete index of albertnet posts, click here.

Thursday, October 31, 2024

From the Archives - Bits & Bobs Volume XV

Introduction

This is the fifteenth installment in the “From the Archives – Bits & Bobs” series. Volume I is here, Volume II is here, Volume III is here, Volume IV is here, Volume V is here, Volume VI is here, Volume VII is here, Volume XIII is here, Volume IX is here, Volume X is here, Volume XI is here, Volume XII is here, Volume XIII is here, and Volume XIV is here. (The different volumes have nothing to do with one another and can be read in numerical order, alphabetical order, in order of importance, or by court order.)

What are albertnet bits & bobs? They’re brief passages from letters, emails, essays, shopping lists, or other combinations of letters and words that I saw fit to type at some point. Read these silently to yourself while pointlessly mouthing the words, or read them aloud to your child or pet, or read them at top volume on a city bus. Or do all three! Mix-n-match!

[The below photo has nothing to do with this post, but hey ... happy Halloween!]

August 3, 2006

I have my PC media player set up to cycle through all my music, so I get everything from alternative rock to classical to rap. Right now I’m hearing a blast from the past: “Hunted Child” by the L.A. rapper Ice-T. My roommate C—, aka Dithers, used to sing along, “I’m the honey child!” I for my part liked to sing, “Death row . . . water buffalo.” [The real lyric was “what a brutha know.] Years later, at the bike shop in Berkeley, I continued in that vein, and for a brief time had the nickname “Water Buffalo.”

August 23, 2006

There used to be a sign on the Muni [i.e., local mass transit system] buses that read, “There is no limit to the number of seeing-eye dogs on Muni.” I always wanted to nudge a fellow passenger, glance toward the sign, and say, “No kidding—this bus is teeming with them!” Later the Muni folks changed it to “Any number of seeing-eye dogs are allowed on Muni, free and un-muzzled.” Scarcely better, but did it have to be so wordy? Why not just “Seeing-eye dogs are allowed on Muni,” or, because it’s really the point, “Only seeing-eye dogs are allowed on Muni”? Or perhaps best of all, how about, “If you can read this, get your dog off the bus”?

August 31, 2006

I finally got some Tour de France coverage on tape. It’s pretty cool. They show some dudes’ heart rates in real time! The commentators talked to Floyd Landis’s coach during stage 17, when Floyd made up all that time and put himself in striking range of the overall win. They were talking about stage 16, when Floyd cracked and lost like eight minutes on the last climb. He uses this Power Tap mech in the rear hub that tells him his power output and can be uploaded to the PC after the race. His coach said that during that ill-fated last climb on stage 16, Floyd was putting out 260 watts, which was quite low for him. Well, it so happens that it’s almost exactly what I averaged on the first two passes of La Marmotte this year! (I did 262 watts on the Col du Glandon and 264 on the Col du TΓ©lΓ©graphe.) If you don’t factor in rider weight, you could conclude that I could hang with Floyd on his worst day! (Of course, rider weight is everything, and I’m sure my power-to-weight ratio isn’t even close to his.) Every night before bed both girls beg to watch some Tour de France footage. I limit them to five minutes (unless I get too caught up in the action and forget to curtail it).

September 8, 2006

I came across one of those questionnaires that help determine if you’re an alcoholic. Question five was, “Do you suffer from regular alcohol related accidents?” My completely honest and sincere answer is, “Not unless you count peeing on the rim.”

October 18, 2006

I’m so sorry to hear you got dragged to Kentucky Fried Chicken. I hate that “food.” E— and I went to KFC one cold, rainy day in Michigan during our cross-country bike tour, and immediately regretted it, from the first greasy bite onward. Which is weird. I mean, you’d think just about anything would taste good when you’re tired, cold, wet, and lost. I wonder if the ill-fated Donner party could have enjoyed KFC, right there at the end when they’d already eaten their boots and everything. Probably not. Man that stuff is gross.

November 11, 2006

I’m so frustrated with my work PC. The IT folks have locked down the browser to make sure the online experience is as annoying as possible. Every time a website runs a script (which means about half a dozen times per page) a window pops up saying, “Oh NO! Rush the children down to the cellar, put your tray table in the upright locked position, tuck and roll, Simon says cover your head! This website is running a SCRIPT! It’s possible that something TERRIBLE could happen! Do you really want to run this script, or should you just power off your PC and go home?” It’s systematically training you to automatically click “YES” to any dialog box that pops up, guaranteeing that if you ever got a useful dialog with a serious choice, you’d fail to recognize it. Somehow this makes the security people, who are evidently running the company, feel a bit better. Sadists. And whenever you click on a hyperlink or type in information and submit it, you get another dialog box: “You could not possibly have realized this, being an ignorant type with no concept of computer networks (the opposite extreme of us security types), but you are about to send information over the INTERNET! Do you have any idea what you’re doing? Don’t you know that OTHER PEOPLE could SEE this information? People you’ve never met, strangers, some of them psychotics, or the kind of people who don’t even put the toilet seat down? Are you SURE you want to do this? Wouldn’t it be better to go back to the IBM PC and DOS 3.1 and use WordStar? Are you really ready for this Brave New World that has such people in it? Is it really worth it?”

November 13, 2006

Not to worry, DSL [digital subscriber line, an early Internet broadband product] is pretty straightforward to have installed. After you place your order, a guy shows up at your house reeking of cigarette smoke. He might work for your actual provider, or not; he might actually work for the competitor of your actual provider, in which case another guy will come weeks later who will work for your provider, or at least a subcontractor of your provider whom you’ve never heard of. Each guy will come into the house, look in your crawl space, scratch himself a bit, then leave without appearing to have done anything. I guess one guy has one task and another guy who comes later has another task, but it never appears that anybody actually does anything. The first time through I expected to see the telco guy shimmy up the telephone pole across the street, but he must have done that in Ninja clothing the night before.

An any case it really is easy for the consumer, whose entire role is to keep an eye on the telco guy and make sure he’s not casing the house for valuables (see “Ninja clothing” comment above). Sometime before or after the telco guy’s visit, or between the telco guys’ visits, a box comes in the mail containing an install CD and a really cheap looking DSL modem. You follow some illustrated instructions and you plug a bunch of stuff in. Sometimes the DSL is provisioned on your existing phone line, so you have to put these weird filters on all your phone jacks, even ones with no phone plugged into them (if you believe the instructions, which I don’t). This is still pretty straightforward unless you’re also sharing those phone lines with your streaming digital audio system, in which case you have to draw a network diagram, scratch your head a lot, pay extra for a static IP address, and configure that. My current DSL, even though it’s a separate line from my voice line, came with a lot of filters anyway, with specific instructions to do nothing with them except save them in case you decide to switch to Voice Over IP (VOIP). So every so often I have to stop my wife from throwing out the filters, but that’s pretty easy.

I’ve had three different DSL providers, and only the first installation was difficult. My router was configured wrong and it didn’t do a darn thing. I was very distraught until I phoned a colleague and he helped me suss out the problem. The guy who installed it refused to help, and I had no recourse because I had no idea what company he even worked for, nor what he was even doing in my house.

November 29, 2006

At long last, per your previous inquiry, I’ve found a photo of the post-race meal served by the Marmotte race organizers. That shredded white stuff you see in the picture is raw jicama, I think. (Tasting it didn’t help with identification because it tasted like absolutely nothing, except aluminum, which everything tasted like, due to the physical abuse I’d just put my body through.) The dry, lifeless baguette must have been imported from the U.S. (from the Safeway deli, to be precise). I didn’t even know you could get a bad baguette in France. Maybe they have special crappy ones for the Americans. I’d really like to know why the race promoters thought anybody would be excited about this plate. (Full disclosure: there was also a second plate, of mealy penne with a bland tomato sauce, that didn’t warrant a photo. It was nominally edible.)


November 30, 2006

To be honest, I generally take a head-in-the-sand approach to the woes of ageing. I’m aware of a great many ways in which the body begins to wear out (though certainly not even a fraction of the total, nor of the myriad details of such), and I’m aware of many (but certainly not all, nor even most) of the ways in which a healthy lifestyle can delay the inevitable. That said, I’m also aware of the non-physical aspects of ageing: specifically, the emotional and psychological components, the most visible of which is the worry involved. As if the physical discomfort and reduced abilities weren’t bad enough, there’s the ever-growing concern that they’ll get worse, that they’re leading up to something dire. Toward the end of E—’s grandma’s life, I learned the hard way never to ask the open-ended question, “How are you?” This seemed to be an invitation for her to begin an endless litany of complaints and grave portents. I find that one of the great joys of (relative) youth is the illusion that it will last. To begin worrying now, to become vigilant of the pitfalls of this or that poor lifestyle choice, to start getting “Prevention” magazine, etc. would take much of the fun out of still being mostly intact. When I become a geezer one day and have to forego, with a sigh, that third piece of bacon, I want to at least have the pleasure of remembering my thirties, when the only memories I’ll have of limiting my bacon intake are considerations like “is it too hot to burn my fingers?” or “will that leave enough for E— and the kids?” Maybe one day I’ll wish I’d started the fiber and temperance a little earlier, but I’ll also, I’m sure, think back and say, “By god, I lived large as a young man, and I enjoyed it!”

As for whole-wheat pasta, I lump that into that category of foods you should either enjoy in their proper form or skip entirely. This substitutes-to-avoid group includes Hydrox cookies (imitation Oreos that taste bad), turkey bacon (inedible), soy cheese (culinary blasphemy), light beer (urine), grocery store pastries (a waste of fat and a carbuncle on the already ugly face of American food), margarine (proof that man is essentially evil), frozen yogurt (not yogurt, not ice cream, and not good), low-fat ice cream (the only noble justification for suicide I can think of), soy milk (tofu urine), and of course carob (the existence of which means the terrorists have already won). I mean, food ought to be pleasurable, life ought to be pleasurable, and if you’re not a total sloth and/or glutton you ought to be able to enjoy yourself somewhat. Those who do fake workouts (dangling by their wrists over a Stairmaster so their feet can paddle ineffectually around, while they read a frickin’ magazine, for crying out loud) can have their fake foods, and the rest of us—big strong creatures with appetites and a zest for living hard and well—can do whatever produces good results. That’s my take, anyway.

November 30, 2006

Congratulations on Baby M—! She is darling. I can’t tell which of you she looks like. In my experience babies seldom look like their parents, who are, after all, adults.

—~—~—~—~—~—~—~—~—
Email me here. For a complete index of albertnet posts, click here.

Wednesday, October 31, 2018

The Samsung Smartphone Iris Scanner


Introduction

I have a new smartphone that can use biometric technology—specifically, an iris scanner—to authenticate me (i.e., to unlock itself). Though I was initially thrilled at the space-age modernity and ease of this feature, I ultimately decided not to continue using it, for a reason that may surprise you.


Why biometrics?

Biometric authentication might seem to some like a solution looking for a problem. Why not just use a password or PIN to unlock a phone or other device? Actually, static passwords are pretty fallible. People are lazy and choose really lame passwords. It’s also possible to intercept them; both my daughters managed to learn my smartphone’s PIN by looking over my shoulder.

But that’s not actually the biggest problem with traditional authentication. After all, security can be increased by using two factors, e.g., a static PIN or password plus a token or app that generates a new password every minute. But this process is annoying. To securely connect my work PC requires a complicated password to unlock it, followed by VPN authentication involving a numeric user ID, an 8-digit static PIN, and a 6-digit constantly changing PIN that I need to get from my phone, which (until recently) required that I unlock it with yet another 6-digit PIN. That’s 42 keystrokes total.

Meanwhile, throughout the day I’m typing this or that other username and password to reach various resources; I have well over 100 different logins to keep track of. Most of the time, the password field you type into doesn’t show you what you’re typing—just asterisks. This leads to typos, of course, so you have to start over. If you’re at a cafΓ©, this makes sense, but don’t most of us work in an office or at home 90% of the time? Why not show the password by default and have an optional “mask” button for public spaces?

This is where fingerprint readers, facial recognition, and iris scanning can really help. They’re faster and easier, removing an annoyingly repetitive behavior.

Samsung optical recognition

My new Samsung Galaxy S9+ phone has three ways of optically authenticating the user. It can use facial recognition (i.e., using the front-facing camera to see if it’s my face); it can use an infrared scanner to inspect my irises and compare them to the baseline image I stored in the phone; or it can use both. In practice, the facial recognition isn’t considered secure enough for sensitive applications. The combined method is also pointless, because the phone tries the less rigorous facial recognition method first, thus dispensing with the secure iris scan most of the time. In practice, only the iris scanner by itself makes any sense.

So, does the iris scanning work? There are two definitions of “work.” First, the phone needs to easily perform the test and unlock itself, without any false negatives (i.e., failing to recognize my irises). On top of this, the authentication has to actually be secure (i.e., avoid being circumvented by a malicious actor).

At first blush, the iris scan seems great. You swipe up from the bottom of the touch-screen to tell the phone to scan you; then, a fraction of a second later, your phone is unlocked. It’s like magic, and far easier than the six-digit PIN I had to type on my old phone. (That was actually seven taps total: the PIN and then—pointlessly—having to tap Enter.)

As far as whether the technology really is secure, that’s harder to ascertain because it’s like proving a negative. But honestly, I don’t care if it’s completely foolproof. For me, the security needs to meet exactly two standards: 1) my employer’s IT department trusts it; and 2) Google Pay trusts it. I don’t see that there’s that much real risk involved here. After all, what are the odds that a malicious actor will gain physical access to my phone? Negligible. And if someone did, well, I’d kick his ass! (Meanwhile, if I were to lose my phone, one quick phone call to corporate IT would have it wiped clean—i.e., “bricked”—within minutes.)

That said, this is a full-service blog so I’ll share what my cursory Internet research turned up. Yes, somebody has already hacked this technology. They used a digital camera with an infrared light, captured a photo of somebody’s irises, printed it out, and then put a contact lens over the iris in the printout to create the right curvature. One article called this “alarmingly easy” but is it, really? I don’t typically let strangers take a photo of my irises in infrared mode from three feet away without my consent. Meanwhile, let’s not forget that this methodology still requires that the malicious actor get physical access to my phone. How’s he gonna do that? And what exactly does he hope to get off my phone … my beer photos?

Anybody who fixates on security measures involving physical access is missing the point. This is not how hackers operate. Let me explain how they actually do their thing. Recently I was sitting in a doctor’s office reading Readers Digest and came across an “article” (i.e., thinly veiled ad) for a free app that gives emergency first responders a way to get pertinent info off your phone if they find you unconscious in a ditch. They will want to find out if you have any medical conditions, and have a way to contact your family members to let them know you’ve been in an accident. Without a screen lock this is pretty easy—they just call the last number you dialed, or sift through your contacts. But with a screen lock, things get harder. The app described by the Reader’s Digest article makes your medical information and emergency contacts available when your phone is still locked. Pretty cool, right?

Well, no, as it turns out. I downloaded the app and read the privacy policy. (If you never do this, you might consider starting, particularly when the creator of an app isn’t Google or Apple.) I discovered that this software monitors and reports all your browsing activity, even when you’re not using the app! In other words, it’s egregiously violating your privacy (which is why it’s offered for free). That’s the real risk, folks … not somebody stealing your phone and using it.

(By the way, if you want to make your emergency info available to first responders via your locked phone, check the website of your phone manufacturer. My old Motorola phones supported this natively, as does my Samsung.)

 The problem with optical scanning

So the Samsung iris scan looks pretty good, right? If so why this post? Well, as is so often the case, the honeymoon was brief.

A few days into my use of the iris scan authentication, I started having some problems. Usually the scan was almost instant, but then I challenged it in several ways. I used it while wearing contact lenses, then glasses, then sunglasses. With the first two, the phone had to work a little harder to get a good scan, but eventually worked. With sunglasses—no dice.

Still no big deal, right? But over time, seemingly as I myself got tired, this phone seemed to be working harder and harder to authenticate me. Things got worse in the evening, perhaps due to low ambient light and/or my increasingly dilated pupils. Instead of just flickering, the screen was putting two circles on the screen for me to align my eyes with. I couldn’t get a screenshot of this, but here’s how Samsung depicts it:


Still not a big deal, but not instant and automatic either. It had me doing a little bit of work, and I don’t like doing a little bit of work. I’m a Californian, man! I don’t have time for instant gratification! Moreover, I had the distinct sense that having this red light shining in my eyes was starting to cause discomfort.

Could this discomfort be in my head? Absolutely! Try this thought exercise: do you feel a little bit of an itch right now, on your head? Just a little? Doesn’t it kind of feel like something is crawling on it? Weren’t you sitting under a tree earlier? Isn’t this the season for spiders? Isn’t it entirely possible that one dropped down into your hair? There’s a little itch—admit it. You have to scratch now, don’t you? I do, and I’m the perpetrator of this ruse! (Don’t you feel a yawn coming on, too?)

The point is, any fear of side effects with this technology can start to niggle, and a little fear isn’t unreasonable. A government facility employing iris scans would screen you once every few days or weeks. But phones? We unlock these devices many dozens of times a day. I don’t think it’s irrational to wonder if frequent iris scanning might cause a cumulative problem. After all, this use of the technology is totally new.

I’m clearly not the first person to wonder if this is safe. Consider the second Google autocomplete suggestion that appeared when I typed “samsung iris scanner”:


As luck would have it, I had the opportunity to talk to a Samsung engineer about the safety of this feature. (Never mind how.) I should point out that our conversation was basically off the record. (I didn’t present myself as a blogger, because I don’t enjoy having people laugh in my face.) I also want to be clear that this guy didn’t utter a single sentence that would incriminate Samsung in any way. Everything he said indicated an essential trust in this technology.

At the same time, there were some nonverbal cues indicating that perhaps he’s not entirely confident that there’s zero risk here. This wasn’t just my interpretation … several others witnessing the exchange chuckled out loud a couple times. Due to the very essence of nonverbal communication, I cannot explain exactly how he hedged. Perhaps the most tangible detail I can convey is this cryptic statement he made, in response to my question about the high number of scans these phones are doing: “Everything in moderation, including moderation, right?”

(It was a great tech-geek conversation, by the way. The oddest thing he said was, “You can remove your irises!” I pictured a gory self-surgery for a moment before realizing he meant I could remove the stored benchmark image and try again. The idea is, if I had captured the baseline iris scan in bright daylight, then the authentication scans would also work best in bright daylight. You can experiment with different lighting conditions to capture the best sample, which will make scans work in the widest variety of conditions. The phone has an almost comically named “Manage Irises” menu for this.)

In the final analysis, I didn’t find any legitimate reason to act on my concerns … I recognize them as knee-jerk reactions, more paranoid than rational. There’s just not enough there to suggest a safety problem with this authentication method. But there’s a less slippery aspect to it that ultimately did cause me to abandon it anyway. Look at this photo:


What do you notice about that photo, particularly in contrast to the one before it? The guy in the photo looks pretty tired, doesn’t he? The Samsung photo is much nicer. The woman—surely a model—has really nice smiling blue eyes. If I looked like her, I might actually enjoy iris scans. Hell, I’d probably even snap selfies! I might even use Instagram! But the reality is much different. Unlocking my phone, particularly during the evenings after a hard day, became downright demoralizing. Here’s what I found myself looking at:


Look at those bags under my eyes! It’s depressing! I also don’t have any eyebrows left. Where the hell did they go? I used to have eyebrows. In fact, I had very nice eyebrows. I think they were my best feature—and now they’re gone … at some point they just straight-up vacated. Another ravage of age. And the above photo doesn’t even capture the expression my eyes would betray during these scans … it was one of confusion and frustration, which are decidedly unflattering.

I’m not kidding here: these iris scans were making me feel old and lost. Haven’t these damn phones, with their social media and their selfies, done enough to undermine our self esteem, without reminding us, through this new form of scrutiny, how tired and doddering so many of us have become?

The solution

Happily, there was an elegant solution to my quandary: I switched to the fingerprint reader. I’d initially refused to consider this technology because I cannot stand it on my iPad Air. That device’s fingerprint reader has always enraged me. It works about one in ten times. Typically I try it three times in a row to no avail, and then the iPad gives up and makes me type my password. So it’s actually adding effort and frustration, the net result being I almost never use my iPad for anything. It just sits in a drawer.

Samsung, on the other hand, has a great fingerprint reader. For one thing, it’s located on the back of the phone, which just makes sense. Plus, it happens to work perfectly. Furthermore, it offers a significant extra advantage: you don’t have to “wake up” the phone to use it. With the iris scanner, you have to un-snooze the phone by pressing a button on the side, and then you swipe up on the screen, point your eyes at the phone, and then it does the scan. With the fingerprint reader, even if the phone is sound asleep, you just touch the reader and the phone unlocks. I can do this in the same motion as pulling my phone out of my pocket, so it’s instantly ready to use. Moreover, the phone can store multiple fingerprints, so another trusted person (e.g., your spouse) can borrow it (e.g., you’re driving and he or she wants to navigate). I give Samsung’s fingerprint authentication an A+ … they really nailed it.

(No, Samsung didn’t give me a free phone or anything for writing this; I’d be required to disclose that if they did. So, if anyone from Samsung is reading this: you’re welcome.)

--~--~--~--~--~--~--~---~--
For a complete index of albertnet posts, click here.

Tuesday, February 21, 2017

How to Survive a Phishing Attack


Introduction

This post describes a super easy way to avoid falling prey to phishing and spear-phishing.  While I’m at it I’ll explain about ransomware and botnets so you can sound impressive during fishing  trips and/or ladies’ luncheons.  I’ll even provide a real-life example of a recent situation requiring me to apply my method.

Couple quick notes:  1) You cannot get a virus by reading this blog or clicking on any link within it, ever; and 2) I actually did my homework on this post, and ran my anti-phishing technique past the Chief Information Security Officer of a giant corporation, who gave it her blessing.

Some terminology

In a previous post, I covered plain old spam, which is simply unsolicited e-mail that doesn’t even pretend to be personal.  For example, the subject line is “Enhance your male member!”  The sender hasn’t targeted you based on knowing anything about your, uh, membership … from the sender’s perspective, every man should enhance his mail member!  (And if a woman receives this message, no harm done—she can just forward it to the man in her life.)  Spam is basically electronic junk mail.

Phishing is an attack on your computer which relies on you clicking on an embedded link or opening an attachment, which either loads a virus directly on your computer or takes you to a bogus website that attempts to lure you into disclosing personal information.  Phishing messages are usually blasted out like spam, though the sender will often pretend to be a company you do business with, such as your bank.  There’s usually a sense of urgency, something like “Account locked – update password!” (i.e., “Tell us your old password, sucker!”).

Spear-phishing is more targeted and requires the sender to find out stuff about you in advance (e.g., thru social media) to make the e-mail look more realistic.  Is it important to differentiate between regular phishing and spear phishing?  Probably not.  I think the latter term was contrived mainly to help security experts sound cool.

Ransomware is a computer virus that encrypts your computer’s entire hard drive, so that only the fraudster can decrypt it, which he or she will only do upon being paid a ransom.  (A criminal with no hacking skills can actually buy “exploit kits” from the fraudsters to carry out his own attacks.)  Ransomware is one of the biggest reasons to be careful with your e-mail.

You know how vampires and zombies can make you one of their own by biting you?  Similarly, computer viruses can take over your computer and use it in a separate attack.  Such an infected computer is called a bot, and when hundreds or thousands of them are herded together to mount a large-scale attack, you’ve got a botnet.  (Think of it as an online zombie apocalypse.)  Note that as more devices—not just computers and phones but thermostats, security cameras, DVRs, etc.—are connected to the Internet, they become targets for botnet attacks as well.  In fact, they’re ideal candidates because they’re often cheaply made, poorly designed, and lack security.  They’re like really dumb zombies.

How to survive phishing attacks

My phishing survival technique employs a single simple rule:  if an e-mail appears to be from any bank (even yours), or any other business with which you have an account (e.g., a utility), automatically assume it is a phishing attempt and just delete the e-mail.  You can apply this rule even before opening the message.  It’s that simple.  The decision tree looks like this:


 There is a very small risk, with such a broad rule, that you’ll miss a legitimate e-mail from your bank, but a) it’s better to be safe, and b) remember, your bank knows how to reach you!  They have your money and are very resourceful about getting their business done.  In general, they prefer to phone you or send postal mail because they hate phishing as much as you do and have no interest in training you to fall prey.

The one blanket exception would be account statements.  If you signed up for electronic statements and receive them on a predictable schedule every month, and these statements provide account information without asking you to do anything, you’re probably fine.

As for these “Oh, no, you need to do something!” messages, keep in mind that if there’s really something wrong with your account—like your card number has been compromised, for example—that’s ultimately the bank’s problem.  They are on the hook for the cost of the fraud, so let them do the heavy lifting.  If they can’t be bothered to pick up the phone or mail you a postcard, they can face the consequences.  (For what it’s worth, my card number has been compromised a number of times, and in no case did I get an e-mail.)

All of this being said, I recently decided to amend my very simple rule.  If you’re interested in my amendment, read on.  If you’re already bored and/or have no problem with the simple rule outlined above, you’re done—goodbye!  Go get on with your life!

Sometimes it’s not quite that simple

What if you made a purchase that falls well outside your normal pattern of behavior?  For example, you just made a purchase for $2500, and the largest purchase you’ve ever made previously with this card was $1000?  Or what if you normally shop at J. Crew and Brooks Brothers, and one day get a ghetto impulse and buy something at J.C. Penney?  If you do something outside of your norm and then immediately receive an e-mail purporting to be from your bank, you might consider evaluating it further.

I got an e-mail recently from slcfraud@aexp.com titled “Your Corporate Card.”  This “From” address and subject line didn’t look obviously wrong.  The capitalization in the subject line, “Your Corporate Card,” was a bit odd, but not obviously wrong (e.g., it wasn’t “Security fraud alerted corporate card!!” or “Account info updating needs!” or some other butchered English).  The return address, slcfraud@aexp.com, struck me as feasible, though these things can be spoofed.  Only because I half-expected Amex to choke on a recent transaction, I decided to open the e-mail:


Note how it’s in plain text with no logos or anything.  That might seem a bit odd, but actually it’s completely okay.  Fancy logos and formatting are methods hackers use to make their e-mails look legit.  Don’t be fooled!  It’s far easier to manipulate graphics and logos and such than to say the right things, in perfect English, in an e-mail. 

This brings us to my analysis of the grammar etc. in the e-mail itself.  There is a stray bracket in the message (toward the end:  “Corporate Payment Services}”).  That’s a bit spotty, and such things should be considered suspicious.  There’s also a dangling participle:  “In order to assist you in a timely manner, please call us at the numbers provided rather than responding to this message.”  (The first clause refers to them—i.e., they would be assisting you—but the second clause refers to you; i.e., here’s what you should do.)  Certainly this is bad grammar, but it’s the kind of error a native speaker would make—even an Amex employee.  It’s not the kind of error made by dastardly foreign hackers who hate America.  Even still, as a general rule I would normally delete this e-mail on the basis of this, or any, grammatical error.  If this makes extra work for your bank, shame on them for filling corporate communications positions with people who can’t write a decent sentence.

All of this aside, there was one fundamental characteristic of this e-mail that caused me to take it seriously:  it didn’t ask me to click on anything, and it suggested I call the toll-free number on the back of my Amex card.  That is exactly the kind of action a bank would legitimately ask you to take, and dialing this number is an inarguably safe thing to do.  (I cannot imagine how a hacker could print a fraudulent toll-free number on the back of my card.  He would need physical access to my wallet, in which case he would presumably have no need to do anything online.)

I did note that the number provided in the e-mail didn’t match the number on my card, but it’s not uncommon for a financial entity to have multiple toll-free numbers.   You should never dial a toll-free number provided in an e-mail.  While that’s not as obviously dangerous as clicking on a link in an e-mail, it could still get you in trouble.  What if you reach a voice-response system that sounds authentic, and asks you to enter your card number?  That would be an easy way for a fraudster to hack your account.  Always go with the phone number printed on your statement or card.

Based on the e-mail above I called Amex, and sure enough, they had locked out my card because my last transaction looked suspicious to them.  During the call they authenticated me based on my caller ID, and accurately described the suspicious transaction.  I told them it was legit, they unfroze my account, and all is well. 

So:  does this mean opening the e-mail was a good idea?  No, not really.  If I had my life to live over, I’d probably have deleted the e-mail and just called Amex.  The slightly more complicated decision tree is this:


How common is all this, anyway?

Is this much ado about nothing?  Actually, I think this stuff is important because phishing is so rampant.  Looking in my junk mail (i.e., messages my ISP determined were fraudulent), I see the following: 
  • 2 messages from Apple on 2/11 saying “Your account is locked”
  • 3 messages from my regular bank between 2/3 and 2/9 saying “Action Required”
  • 1 message from my Visa card issuer on 12/21 saying “Notification ID: 2591912…”
  • 1 message from Apple on 11/07 saying “Apple Inc | Security notice”
  • 1 message from PayPal on 10/27 saying “Your PayPal account ha…”
Along with this, I see messages seeming to be from friends of mine that somehow triggered my ISP’s junk mail filter.  What if my ISP hadn’t filtered these?

Address book phishing

I’m not aware that the phrase “address book phishing” has any widespread meaning, but I’m talking about viruses etc. that replicate by forwarding themselves to everybody in the victim’s e-mail address book.  If your ISP lets these through, it can be tricky spotting them.  Here are a few ways.

Message is unexpected – Often I’ll get an e-mail from somebody I know, but who very seldom e-mails me.  For example, my friend’s wife e-mails me every so often and has done so for years.  Why would she?  Either her PC’s got a virus, or she’s trying to start an affair.  Either way, my reaction is the same:  delete that message!  If she really needs to contact me she’ll surely find another way.

Here’s a true story:  my wife e-mailed my brother several times to ask about some bike thing she wanted to buy me for my birthday.  My brother didn’t respond, either because he suspected phishing, or was just really behind on e-mail.  So the next time my brother called me on the phone, my wife intercepted the call and, before fetching me, said to my brother in a low voice, “Call me!”  He was totally perplexed, and she eventually had to call him herself.

Subject line is missing or suspicious – Of the four bogus messages I received recently purporting to be from friends, three have no subject line at all and the fourth has the subject line “RE: ” with nothing else.  The lack of a subject line is usually a giveaway unless you have really lazy friends.  Other suspicious subject lines would be the sender’s name, your name, or something insanely generic like “Hello.”  (If I e-mail a friend just to say hi, I’ll say something a bit more specific, perhaps involving an inside joke.)

Text of message doesn’t read right – Say you’re fooled into opening such an e-mail and now have text to look at.  The hardest thing for fraudsters to get right is grammar (either because they’re foreigners or because they’re stupid).  If your friends use terrible grammar and spelling, I recommend you find some better friends.  Otherwise, be very careful with messages that don’t read right.

If, for whatever reason, you decide not to open an e-mail that appears to be from a friend, it never hurts to create a new message, address it to the friend, give it a subject like “Suspicious e-mail…” and ask if he or she e-mailed you recently.  You can leave the original message in your Inbox while awaiting a response (unless you’re afraid you’ll open it by accident, like if your software is set up to automatically move from one message to the next).

So, here’s a more complete flowchart of how to handle messages:


Will this approach keep me safe?

Actually, avoiding phishing scams is not enough to keep you safe.  We’re probably all eventually doomed, because data breaches of giant databases have become so common.  For example, an insurance company I do business with was hacked awhile back, and had over 70 million customer profiles compromised, including mine.  So, if you screw up and disclose personal information and/or help a virus to spread, you shouldn’t feel too bad. 

Still, I guess it’s nice to have a methodology for not being a complete sucker, and that’s what I’ve endeavored to provide.

--~--~--~--~--~--~--~---~--
For a complete index of albertnet posts, click here.