Showing posts with label Privacy. Show all posts
Showing posts with label Privacy. Show all posts

Wednesday, March 07, 2012

Credit Card Reporting

I have heard this story a few times. A married person brings their child for a car, goes to take out a car loan, and finds their credit is ruined. The reasons can be anything from identity theft to marriage problems. Either way, however, it is a bad situation to be in.

Maybe you have heard the "free credit report" Web sites advertising. The main one of these, freecreditreport.com, is free but requires users to sign up for services in order to get their "free" report. However, why do that when the companies that keep track of your history are legally required to provide you this information for free once a year?

In 2001, I graduated from college, and a friend mentioned that New Jersey residents could get copies of their credit reports by sending a letter to each agency. When I got the report, I was surprised to find I had a few active credit card accounts. They were open because I applied. Since I wasn't living at home, I didn't get my mail often, so I had accounts open. I recall applying for one in college in exchange for a t-shirt, and I filled one out at a Devils game for a hat. I spent a while calling credit card companies and closing accounts I did not use.

At that point in time, each state had different laws regarding this, but today, residents of the United States have the right to view this information online once a year for free from each of the three credit reporting bureaus. In order to get a copy of your report, you can log on to the Web site the three agencies have set up:


They may offer to sell you extra services, but if you decline, you will not be charged anything. The general rule of thumb is if they offer premium services, you don't want those.

In my experience, it was good to do a credit report for the first time to see what information they had there. Today, I check it for identity theft or fraud, and fix any errors they might have on there (they may have mistakes, and if it costs you a loan, that is bad).

For most users, an annual credit report for free is enough, but there are services for people who want something more (like real-time monitoring, or access to your credit score). For most users, I think spending an hour a year on this is a great idea. I put it on my calendar to do each year, so if something does happen, I should become aware of it.

Monday, January 09, 2012

The Perils of Communication

This is a story that 20 years ago probably might have made the local news, and not CNN.

An Asian Papa John's customer in New York City ordered a pizza and after she left she noticed the area that says "customer name" listed her name as "lady chinky eyes". Obviously, a cashier thought they were being funny identifying her in this way.

Twenty years ago, she might have just ignored it after being annoyed. These days, she posted a tweet with a picture of the receipt, and it went viral.

This led to the employee being fired within 48 hours and an official apology being posted on Papa John's Facebook page.

The perils of being a smart ass in the information age!

Link to CNN story

Wednesday, June 15, 2011

Google Image Stalking

So, Google is introducing a few new features, and as always, the applications can be used for evil.

One of the features aims to allow users to ask questions through their microphone, and have Google search for the words you speak rather than requiring you to type them in. It will recognize your voice and send the words to the search engine.

Another new search is the Google Search By Image. This feature claims that it will let you upload a picture and find information about that picture. For example, if I have a picture of me in front of a building, Google Search By Image would attempt to identify that building. That seems really interesting.

I decided to test it out with some pictures of a trip I took. I went to the Google image search, and downloaded the Firefox extension which allows you to right click on any image in your Web browser and search the Google Search By Image tool for it. However, it doesn't work with Firefox 4.0 yet, so I decided to try it in Google Chrome. I then dragged a few images in to the browser.

I had some pictures of a cruise I took last summer, so I decided to try those.

First, I tried a picture of a lighthouse I saw in Canada. It came up with some pictures that were very similar, but they were the lighthouse in Cape May, NJ.

I decided to try something easier, and I dragged a photo of the Statue of Liberty there. Google Search by Image correctly identified it and returned other images of it and a link to the Wikipedia article.

I tried a picture of a random chunk of the NYC skyline, taken from sea, and that also did not return anything useful.

I tried a picture of a pretty distinctive tour bus from St. John's, Canada, and it wasn't able to match that either.

Verdict on the image locator: weak so far.

Google also claimed it could locate an image that is on the Web. I dragged an image of something I am selling on Craigslist, and it was able to immediately find and display that for me. I dragged another image of something I am selling on eBay, and it was able to find that. Finally, I tried an image I downloaded randomly, and it was able to show me where that image came from. I would say this is a success.

Verdict: This could also be pretty powerful if you are checking to find where an image came from, in case you want to use legally it in a publication, but isn't going to be able to determine where a vacation photo was taken unless it has a pretty obvious or distinctive monument in it.

Google does claim there is no facial recognition that will be available. Color me suspicious.

For a number of years, Google had a free 411 service called Google 411. Many people felt like the reason Google was doing this was to allow testing of their voice-recognition algorithm. All of a sudden, they have Google voice search. I would assume they tested and improved their algorithms in part with their free 411 service.

Now, Google is going to claim there is no facial recognition that is available. However, they will be amassing a powerful database of photographs. The Google privacy statement seems to allow them to keep Web requests, and my interpretation of an image is that it is a Web request.  Given what they did with Google 411, I would suspect that they will save the images you upload for their own testing purposes. Could facial recognition be something they are testing?  Who knows.

I tend to trust Google more than some of the other big name companies, but just because they aren't making facial recognition available to the public, doesn't mean they aren't gathering our uploaded photos to test their software.

I also have some concerns about how, if this technology develops, people might use this to stalk or harass other people. For example, let's say someone uploads a few pictures to their Facebook, or hacks their phone, or steals their digital camera. If someone is trying to hide from someone, those pictures may be searchable and usable. In addition, let's say a criminal finds a digital camera and notices people wearing nice jewelry in it. Could the pictures possibly lead them to a person's residence? As I said before, this does not seem to be at that point yet, but always something to think about.

Saturday, February 26, 2011

Stalking? There's an app for that.

A large part of Facebook's appeal is the ability to add apps to your account. Games (such as Farmville or Vampire Wars), social apps (like Yelp or horoscope apps), self improvement apps (dieting apps, investing tips) and many more can be found on the site, many of which are free.

There are times where Facebook will determine that certain apps violate their terms. For example, in early 2009, Burger King created an app that, if you dumped 10 friends, would give you a free Whopper. Really. Facebook's rationale was that apps are not allowed to tell people if you've dumped them as friends, and this app did.

Facebook just pulled the plug on an app that many contended was a stalking app. Breakup Notifier was an app released recently. The whole purpose of the app was to let you know if someone's Facebook relationship status changed. For example, if someone was listed "in a relationship" and changed their status to "single", you would be alerted.

Many people view this as a stalking app, but in my opinion, if someone puts this information out there publicly, there really isn't anything wrong with it. I could just as easily bookmark a profile and revisit it to see if someone changed their profile status, and I would also be able to see it through my News Feed. This app would just monitor it for you and send you a response via e-mail when that status changed, providing you with real time information.

Facebook has apparently permanently disabled the app, citing some reason or another. Was it the 3.6 million users it amassed in a week (and the strain it added to their servers), was it complaints, or was it something else? I would guess complaints. I am assuming that the same people who post their relationship status publicly are the same people who wrote to Facebook to complain.

Undeterred, the creator of the Breakup Notifier has created another app, Crush Notifier. This works very much like speed dating. Let's say Sally has a crush on Tim. She would mark that she has a crush on him, using this app. Tim would not receive notification of Sally's crush, so Sally does not risk rejection or awkwardness. However, if Tim marks through the app he has a crush on Sally, they would both receive e-mail notifications that they like each other. Crush Notifier even has a business model, where you get two uses for free, and would need to use Facebook credits to receive any further e-mails.

Amazing how social media continues to change society, huh? Well, as Ricky Bobby said, "Does that blow your mind? That just happened!"

Wednesday, February 16, 2011

Web browser usage

Sites like Statcounter can track happenings on your Web site. For example, I can tell you of my last 500 visitors, 49% used Firefox, 27% used Internet Explorer, 6% used Google Chrome, 2% used Safari, 0.4% used Nutch, and 0.2% (one user) used Konqueror.

We see a lot of statistics regarding Web browser usage. It does vary by region. Firefox and Chrome seem to be more popular in Europe. According to Statowl, the latest numbers for the US, around 60% of users are running Internet Explorer, and only 20% running Firefox. World numbers are somewhere around 47% for Internet Explorer and 31% for Firefox, according to Statcounter.

None of these will be 100% accurate, but they do paint a picture for us. Why are my users more likely to use Firefox than the average world user? I would assume that, as I maintain a technology-related blog, my users are more likely than the average user to use a browser like Firefox.

If I were doing Web design and I had these numbers, I would need to make sure the browsers my users use were the browsers I was testing my site in. Though it really should not happen, there are times a page looks different in Internet Explorer and Firefox (for example).

It is interesting for me, as someone who is not running a for profit site, to look at these statistics. For someone who IS running a for-profit site, this information can be critical.

Friday, December 03, 2010

Bring out the Dancing Pigs!

"Given a choice between dancing pigs and security, users will pick dancing pigs every time."

Once someone explained that line to me, I loved it. Basically, Bruce Schneier (a US computer security consultant and cryptographer) explained, "If the computer prompts him with a warning screen like: "The applet DANCING PIGS could contain malicious code that might do permanent damage to your computer, steal your life's savings, and impair your ability to have children," he'll click OK without even reading it. Thirty seconds later he won't even remember that the warning screen even existed."

That basically seems to summarize computer security these days. Users often get taken in by phishing schemes, download viruses, give out personal information, and do other things that compromise security...for the promise of dancing pigs. Smart hackers do this and create attractive links that people will click on.

As you can see, there are tutorials taking potential phishers through the process of stealing information. Stopping sites posting information like that is like playing Whac-A-Mole.


Congrats, you shut down a phishing site! Put down the hammer, I don't think others will pop up!

I do not know that most Americans are adequately prepared to figure out what sites are legitimate and which ones are not (and to read warnings). Sadly, people seem to learn by making mistakes and losing their personal information or getting hacked.

Tuesday, November 30, 2010

Proper Hardware Disposal

In one of my classes last week, we discussed the proper way to get rid of old computer hardware, to avoid privacy issues.

I've gotten rid of old computers, but I generally either keep the hard drives (to destroy) or use software to do a thorough wipe of the drive's data When I say "thorough wipe", I am not talking about deleting files, because data can easily be recovered from a hard drive, EVEN AFTER YOU DELETE IT. Really. As a matter of fact, Microsoft's pre-Windows operating system, DOS, used to include an undelete tool which could recover deleted files easily.

eBay is one place people can purchase used hard drives, and they even provide information on why you need to thoroughly wipe a hard drive before you sell it. You can see that the site shows that social security numbers, credit card numbers, and all sorts of stuff can be found on these hard drives. This means your identity can be stolen even if you do nothing wrong, if a company you have purchased from does not follow good procedures for hard drive disposal. Aside from eBay, there are sites like Craigslist where people get rid of old hardware, and there are always garage sales. In the corporate environment, many colleges and companies pay companies to dispose of old hardware (such as eRevival locally). If you go with a cut-rate company, you may find that though they promise to clean hard drives, they may not do so thoroughly. Any of these are ways that data can be leaked if the hard drives are not wiped.

One way you can provide a level of security is to physically destroy the hard drive, though someone could pick it out of the trash and recover something. The best way is to do a full wipe of the hard drive, or what we used to call a "zeroize" at the company I used to work for. We were putting defense systems in military crafts, and one of the requirements was that the pilot needed to have a button to wipe all the data in the system, to prevent classified data from falling in to the enemy's hands. (Yes, that information is public.)

The Department of Defense has pretty high standards for data wiping, and there are a number of tools that meet their standards. The problem is most of these tools cost money. The one that I recommend is a free tool called Darik's Boot and Nuke (available for download at www.dban.org). Despite the informal name, it is a legitimate program (referenced by CNN and the BBC). There are commercial tools that do this sort of thing as well, but the major difference is not function, it is speed (DBAN has a reputation for being slow - the BBC article says it took two hours for an 80GB drive). DBAN is cool because it gives you a CD to boot off of, and you select the depth of the wipe you want. The more depth you want, the longer it will take to run. If you are going to do this, I would recommend choosing the most in-depth wipe, doing it before you go to bed (as a home user) or before you leave work in the evening (at work), and just letting it run overnight. That way, there is no time wasted waiting for wipe to be completed. In a professional environment, having a DBAN CD around is not a bad thing, especially so your company does not end up in violation with the standards that govern your industry (Sarbanes-Oxley, HIPAA, FACTA, etc.).

A larger company may want to invest in faster, packaged software for this, or a hard drive sanitizer (such as this one - though I am certain their claim of 7 minutes per drive is for the simple wipe and not the seven-pass version).

Any of these options are better than the ol' sledgehammer method, because who wants to clean up that mess?

Friday, October 22, 2010

Time Machine: Everything Old is New Again

Some topics of interest from this week's classes.

We discussed the Do Not Call Registry, which was a way to prevent telemarketers from calling you. Someday, we may see a Do Not Email Registry, but I wouldn't expect that for a while. I remember telemarketing being annoying in the 80's, and it took them until 2003 to do anything about it. Here's my original post about how to get on the registry and save yourself from telemarketers.

Second of all, passwords came up in one class this week. Microsoft has a free password strength checker on their Web site, where you can see how strong or weak your password is. Here's the link. We also discussed passwords, and how you can make a better password. I discussed the mnemonic device method for creating and remembering a password in class, and here is my original post on that.

Of course, for people majoring in the IT area, it's always a struggle to find a balance between security and ease of use. If you require difficult passwords, your users may end up writing them on a sticky note, or putting them in a passwords document.

Tuesday, September 21, 2010

Using Google Earth to make $75,000

Just another case of learning from my students...

In class today, we were discussing Google services, including the advanced Google search options, image search, and Google Maps. It came out during class that the town of Riverhead, NY used Google Earth in a very interesting way. People started getting summonses for having illegal pools, and it came out that they were using Google Earth to find this out. Really! Turns out they wrote about $75,000 worth of summonses before people caught on and complained.

NPR did an interview with the chief building inspector of the town, and he said they did it for the protection of the neighborhoods, saying "I use it strictly for safety." Of course, there is some validity there, because as he states, there are requirements to make sure children don't drown, and I agree with that. I also think that, well $75,000 had something to do with it. I'm a little cynical when someone won't admit to that. Of course money making is part of it. It's not just about safety.

In the "DUH" statement of the year, he stated "Most of the people that complained were the ones that didn't have the permits." Of course those are the people that complained, because they were the ones who were directly affected and may or may not have had their right to privacy violated.

The town is no longer doing this, so I think that tells us how they feel about whether it was a good decision. If they thought it was, they would have kept on doing it. My opinion? As someone who worked for a company doing government contracting, we were told that the government could not spy on its own citizens. The government tried to implement domestic spy-satellite imaging through the innocuous-sounding National Applications Office, but this idea was withdrawn over privacy concerns. If the government can't do it using our own satellites, why can they do it using Google's? Again, my opinion, they shouldn't be doing that, but that's me.

The other interesting part is Google. This sort of use of Google Earth is not prohibited, either in the main terms of service or the government agency terms of service addendum. Yes, I checked. In theory, this is fine per Google's viewpoint. Then again, they haven't updated the terms of service in a while.

Saturday, June 05, 2010

Out of Office Message and Privacy Risks

I remember as a child my parents used to have an answering machine.  For those of you too young to remember those, they were basically like voicemail, except they plugged in to the wall.  I remember at some point my parents changed the message from "we are not home right now" to "we can't take your call right now".  I remember the explanation was that if you said "we are not home right now", a criminal would know you weren't home, but the other message might give them pause.  My parents did not lock the doors, by the way, so I do not think an answering machine message would deter them.  I suppose I can see not wanting to say "we are out of the country from June 1 through June 10", but do you really confuse criminals by saying "we can't take your call right now"?  I guess I never felt like it would be a deterrent.

The reason this came to mind is because as I mentioned I am going to be away from PCCC next year.  I am considering what to do with my out of office message.  By putting one out there, there is a slight risk of that information being used against the College.  A smart social engineer could in theory find a way to leverage that information.  However, the alternative is to check my work email, and I am in theory not supposed to when I am on leave.

We use Microsoft Exchange.  This will allow me to put up an out of office message.  I have the choice to reply only to people in the same domain (@pccc.edu) or only to people outside our domain (everyone else), or simply everyone.  Most people would just put up an out of office message saying to contact their department chair, but the problem is that by doing so, I open up two accounts for spam.  If a spammer sends an email that gets past the email filters, they will get a reply not only showing my email is active, but also giving the spammer my department chair's email address. 

I could also make it a little more complicated, for example, say email
person at pccc dot edu
(which would of course translate to person@pccc.edu)
...but some people would get confused with this.

Making matters more complicated is that I have some business contacts that I would like to be able to contact me.  If I want them to be able to find me, I should probably provide some sort of email address for them to use to contact me.  So, the end result is going to be me setting up a new email account, to protect my home account from spam, and an added risk to both my email address and my department chair's email address.

Now, to figure out what this message should say...

Sunday, September 13, 2009

Shut down telemarketers!

I recently wrote about the telemarketing laws that have changed. However, I realized I never mentioned the National Do Not Call registry.

A number of years back, a law was passed requiring most telemarketers to not call people if they asked not to be called. The problem is that I as a telemarketer could get your phone number and distribute your phone number to 100 other telemarketing companies. Even if you told my company to remove it, the other people still have your phone number.

The government stepped in and set up a free service - the National Do Not Call registry. You put your phone number in the system, and most telemarketers are required to not call you. If they do, you can report them and they face heavy fines. Most telemarketers will be required to stop calling you 31 days from your registration date, so if you put it in the system today, you should be safe by the end of next month at worst.

Of course, there are exceptions. First of all, any company that you have a business relationship with is exempt (though you can still ask them to remove you if they call). So, your phone company, cable company, etc. can do so. In addition, if you order from a Web site and give them your phone number, you may also be opening yourself to legal telemarketing calls.

Other exceptions include charities, political organizations (of course, because guess who passed the law - politicians!), and surveys that don't include any sales pitch.

The Federal Communications Commission does seem to pursue complaints. I was able to find a list with a hundred citations of companies that have been complained about and been fined as a result. The biggest so far was a Florida based company named Dynasty Mortgage, which got a warning and apparently kept calling people, leading to two sets of fines totaling around $1.5 million dollars.

No harm in signing up, because once again, it's free!

donotcall.gov

Friday, June 26, 2009

Goodbye, Fly Clear

A few years after the 2001 WTC attacks, there was a program started called Fly Clear. The basic idea was to give people (read: people who are too important to wait in line with the rest of us - and yes I just made a snarky comment) the chance to skip the long lines at the standard security check-in. The sad part is that many people paid ahead of time, and as I mentioned at some point, when you pay ahead of time, companies now owe you something. Whether this is a gift card or a service, it doesn't matter. As soon as the company bankrupt, they owe you something, but you don't necessarily get it back. Accounting students may recognize the concept of journal entries embedded in there somewhere.

The other question in situations like this is what happens to your private information. SOMEONE is going to buy this company. In this case, there is important information about their customers - passport numbers and driver's license numbers (needed to fly), THUMBPRINTS (FlyClear used biometric identification) and SOCIAL SECURITY NUMBERS (they did background checks on all people using the service). What happens to the privacy practices that you agreed to when a company is sold? You would hope that they abide by the privacy practices you agreed to, but this isn't necessarily something they HAVE to do. Even worse, what if a less honorable corporation buys out this company? They could cause a lot of trouble with the information they have. Think like a hacker for a moment. If you had the money, you could purchase this company's assets, and now you have their database of thumbprints, document numbers, and other things. And the people involved? Rich people, who don't want to wait in line like everyone else.

Yeah, there could be some problems if an unethical corporation buys FlyClear, but hey, maybe I am just the type that thinks the worst in a situation like this.

Thursday, June 18, 2009

Security Sense Summer 2009

My colleague David Csuha has posted his latest "Security Sense" newsletter. His newsletter promotes some good security habits, among other things.

I particularly love the section this month about peer to peer file sharing (Limewire, etc) put people's security at risk. This doesn't require any hacking skills. ANYONE with Limewire can do this. David shows a few things, including a bank vice president who is sharing her personal photos and credit reports, and a model sharing her resume and some, er, risque pictures.

He also discusses how Twitter is being used by places such as the New Jersey State Police to disseminate information in ways that Web sites or emails don't accomplish.

Read more...Summer 2009 Security Sense

Sunday, June 14, 2009

Old Data Never Dies

In 1997, I was working for a department at Montclair State University. The woman in charge had a lot of large files, and a need to be portable, so she used Zip disks (this is before the days of USB flash drives). At one point, one disk stopped working, and she hadn't backed it up, and was very upset that her data was gone forever.

Except that it wasn't. Many people don't realize that just because you delete something doesn't mean it is gone forever. The malfunctioning disk was sent to data recovery specialists, who recovered about 99% of what was originally on the disk. I looked like a genius for knowing that this type of company existed.

Whether a disk fails, things CAN be recovered. The key is, how important is the data? There is usually a price associated with this.

Another thing - if you delete something from your hard drive, it's not gone. Going back to the Microsoft DOS days, there used to be ways to undelete files. When you delete a file, it's not shredded; the hard drive simply says "oh, okay, I can use that space to save stuff now" - which means the original file is still there, just not being recognized by your operating system.

The next step up is computer forensics. There are more advanced ways to pull information off of a hard drive, which means that if you plan on being investigated by the FBI, deleting is NOT enough.

Anyway, some students in our Cyber Security and Computer Forensics certificate decided to put the skills learned in to use and open up a data recovery consulting firm called Old Data Never Dies. I've had most of the students in at least one class, and it's great to see the growth they've all undergone since the "Introduction to Windows" class days to the point where they are now.

The company's Web site can be found below.
www.olddataneverdies.com

Friday, May 29, 2009

Stalking tips and tricks

One of the things I bring out from time to time is how easy it is for companies to find information about you given your email address.

For example, if you have an uncommon email address, people can Google that. (That's easy).

Another, more advanced way is to use Facebook or Myspace. You can put in an email address, and it's easy to find people.

Okay, so many people are smart enough to hide themselves. However, there is always a more advanced way to find people. One of those ways is Pipl.com. I find that people use the same username everywhere. So, for example, if your email address is abc123@yahoo.com, you are likely to use abc123 as your username everywhere.

You can take that username and put it in to pipl.com and it searches all over the Web for that username. Let's say you have a blog on xanga.com...or an account on flickr...this site will find all sorts of accounts associated with that username.

Be it a potential employer...or a private investigator...a lot of this information can be found for free, if you know where to look.

http://pipl.com/username/

Sunday, March 15, 2009

Security, or lack thereof

In another case of security being an illusion, a man from New Zealand bought a used MP3 player in a thrift store while visiting the United States.

Stored on the device, instead of songs, were pieces of information - solider names (not so bad), soldier cell phone numbers (a little worse), soldier social security numbers (bad), lists of equipment that had been shipped to Iraq and Afghanistan (really bad), and information about military missions being run in those countries (outrageously bad).

Now, not all of this information was up to date (most dated in 2005 or so, and this story broke in 2008), but still - this is a case of someone who was honest and came forward. It scares me to think of what happens when this falls in to the hands of someone a little less ethical. I also have this feeling that, for every one case that is made public, there are hundreds more that are not reported. Think about it - even if you have the most hacker proof firewalls in the world, all it takes is one employee to do something like this, and people could die.

Link to article

Sunday, January 25, 2009

British police hackers

Information security and online privacy are things that always concern me. This is why this recent story from the Times Online in the UK is a little scary.

Basically, it's been approved that police in the UK can hack in to people's computers. I know a lot of people will say "what is the big deal"? However, I think of it this way. You wouldn't want people wandering through your house, and the same thing should go for your computer. If police wanted to go in to your house, they need cause, or a warrant.

Of course, our laws are different...but it's still scary, and instructive to see what other countries are doing. We are talking about the UK, also...a decent enough country when it comes to human rights.

I just can't see this one holding up, somehow.

Web Link:

Wednesday, October 08, 2008

The Wayback Machine

Did you know that myspace.com used to be a Web based storage company? Much like some of the other companies like xdrive.com, it was a site that would allow you to have an online backup of your files. I know this because I actually used it back around 2001 or so.

What's very interesting (and educational, for a Web developer) is to look back and see how the design of Web sites and pages has changed over time. The Internet archive tool on Archive.org - also called "The Wayback Machine" (a nod to the WABAC machine on the Rocky and Bullwinkle show) - has archived and continues to archive millions of Web sites. Want to see what Myspace.com looked like in 2001? Just search. It goes all the way back to 1996.

The part that is a little scary is that even if you deleted something off the Web, if they archived it, it may still be out there.

It's kind of sad to look back at my old Internet startup company's page and see how they get kind of desperate towards the end - it was apparent even on the Web site.

Web Links:

Monday, October 06, 2008

How to turn the tables on human resources

What you have on your Myspace or Facebook, someone can find easily.

Try this. Log out totally, search for your name. See what information you can see about yourself.

This information can be used in electronic warfare, as David Csuha discussed recently in his Security Sense blog, but also can be used in scenarios such as job hires, and often is! According to recent estimates, 20% of companies use social networking sites like Myspace or Facebook as part of the hiring process.

For example, put forth a cover letter saying how responsible you are, and a company may check up on you - Googling your full name in quotes may lead to pictures of you falling down drunk because someone tagged a picture with your full name on Facebook.

If you are job seeking and this is your Myspace picture, change it.

What happens if interviewers search Myspace - will they find a public blog you wrote saying "hey, I'm at work and it sucks here, but it's nice to be paid to hang out on Myspace instead of working"?

What sort of comments are your friends leaving you, and what do those things say about you?

Here are some examples of what can happen:
What's interesting is that you could even turn it in to a POSITIVE. If your Myspace or Facebook are well written, and you have a blog that details that you are really hopeful that your interview with company X goes well, and that you are excited about getting a chance to work with that company, it might be a good idea.

Wednesday, October 01, 2008

Identity Theft Made Easy on Limewire

Are you using Limewire or Ares or any of these file sharing networks?

Did you just click on "Yes" when it asked if you wanted to share everything?

Do you have a file on your hard drive with account numbers, school applications with your social security number, or a list of user names and passwords?

Ahem. That's not good.

David Csuha, a friend and one of the CIS department's part-time faculty, has an excellent "Security Sense" blog up, and he recently did a screen capture of what he found with no real effort on Limewire. It's great to see, at least, it's not only Americans that are lax about security - notice the address on the first file that is opened. If David can do this with the best intentions in mind, what can someone who wants to steal identities do?

(Answer: A LOT)

Oh, and this isn't hacking. This is the same thing as someone leaving a copy of your social security card on the copier for anyone to take. This is another example (like the Sarah Palin email situation) of how sometimes, no hacking tools are required to steal the most valuable thing you have - your identity and reputation.

Web Links: