Connect to your account and we’ll send your message to Twitter.
Twitter Account: Not authorized (update)
Celebrating ‘The Twilight Saga: New Moon’
In honor of the opening day of New Moon, the latest film in The Twilight Saga, we thought we ...
The Cheryl Behind the Cheryl
Known to many as the long-suffering (ex)wife of funnyman Larry David, the man behind Seinfeld, ...
BlogTalkRadio Host of the Week: Alfred McComber from...
By Christina Blodgett In our continuing effort to spotlight more members of the BlogTalkRadio ...
http://IDTheftSecurity.com
Country: United States
Language: English
Follow on Twitter
Visit on Facebook
Visit on MySpace
Add to Friends
Send Message
Identity Theft Speaker, Author and Television News Correspondent Robert Siciliano is an expert on personal security and identity theft with more than 25 years of experience in security work, white collar crime prevention, and self-defense. He is a television news correspondent, security analyst, Certified Identity Theft Risk Management Specialist, CEO of IDTheftSecurity.com, and author of “The Safety Minute: Living on high alert; How to take control of your personal security and prevent fraud.”
Date / Time: 7/21/2009 9:47 PM UTC
Robert Siciliano identity theft expert
I recently appeared on Fox and Friends to discuss email hacking. Dave Briggs, a FOX & Friends Weekend co-host, lost access to his Hotmail email account when hackers were able to guess either his password or his qualifying question. (He admitted that his password was not as strong as it should have been.) The hackers locked Briggs out of his own account and spammed all of his contacts with a fraudulent email that appeared to be written by Briggs himself, claiming that he was trapped in Malaysia and requesting that someone help him by transferring money via Western Union. Only after persistently contacting Hotmail administrators was Briggs able to regain control of his own email account.
Twitter was targeted by a similar hack, which led to a data breach. It is likely that the hacker guessed the answer to a Twitter employee’s security question and reset the employee’s password. On Wednesday, Twitter co-founder Biz Stone blogged, “About a month ago, an administrative employee here at Twitter was targeted and her personal email account was hacked. From the personal account, we believe the hacker was able to gain information which allowed access to this employee’s Google Apps account which contained Docs, Calendars, and other Google Apps Twitter relies on for sharing notes, spreadsheets, ideas, financial details and more within the company.”
And of course, Sarah Palin’s Yahoo email account was hacked into last year, during the presidential campaign. The hacker explained how easy it was in Wired.
Web-based email rocks! Since you’re no longer tethered to a PC-based client, you can access your email from anywhere. And all the data saved in your email account will be safe if your PC crashes. Many web-based email providers offer gigabytes of free storage and other useful tools like documents, RSS readers, and calendars. Life in the cloud is easier and more convenient. But is it secure?
PC Pro reported on a study run by Microsoft Research and Carnegie Mellon University, which measured the reliability and security of the questions that the four most popular webmail providers use to reset account passwords. AOL, Google, Microsoft, and Yahoo all rely on personal questions to authenticate users who have forgotten their passwords. The study found that the “secret questions” used by all four webmail providers were insufficiently reliable authenticators, and that the security of personal question appears much weaker than passwords themselves. Yahoo claims to have updated all their personal questions in response to this study, but AOL, Google, and Microsoft have yet to make any changed.
Once a hacker has your email address, he or she can simply go to the “forgot password” section of your email provider’s website and respond to a preselected personal question that you answered when signing up for the account. With a little research, the hacker has a good shot at finding the correct answer.
Some of the current questions could be answered using information found on a user’s social networking profile, or through a website like Ancestry.com or Genealogy.com. Some answers might be found in the user’s trash. Some questions seek opinions, rather than facts. For example, “Who is your favorite aunt?” requires an opinion in response, but if a hacker knew the names of all your aunts, he or she could enter them all one by one. Some questions would be more difficult to answer. Unfortunately, if you signed up for your web-based email account over a year ago, before these email hacks became more common, your questions may be even easier to answer.
Gmail’s current personal questions are:
Yahoo’s current personal questions are:
I suggest that you check out the “forgot password” section on your own web-based email account, to see your current personal question. If it’s easy to answer, or would only require a little research to solve, update the question with one that you create based on opinion, as opposed to fact. And keep in mind that most people list “pizza” as their favorite food and “liver” as their least favorite. So be creative. You should also beef up your password. Combine uppercase and lowercase letters, as well as numbers. Don’t use consecutive numbers, and never use names of pets, family members, or close friends.
1. Get a credit freeze. Go online now and search “credit freeze” or “security freeze” and go to consumersunion.org and follow the steps for the state you live in. This is an absolutely necessary tool to secure your credit. In most cases it prevents new accounts from being opened in your name. This makes the SSN useless to the thief.
2. Invest in Intelius Identity Theft Prevention and Protection. While not all forms of identity theft can be prevented, you can effectively manage your personal identifying information by knowing what’s buzzing out there in regards to YOU.
Includes;
Personal Identity Profile – Find out if you’re at risk for identity theft with a detailed report of your identity information, including a current credit report, address history, aliases, and more.
24/7 Identity Monitoring and Alerts – Prevent identity theft with automatic monitoring that scans billions of public records daily and alerts you to suspicious activity.
Identity Recovery Assistance – Let professionals help you recover your identity if you ever become a victim of identity theft.
Robert Siciliano, identity theft speaker, discusses hacked email on FOX & Friends
You are not logged in. Please log in to write a comment.
LinkedIn http://www.linkedin.com/in/robertsiciliano Twitter https://twitter.com/RobertSiciliano FriendFeed http://friendfeed.com/identitytheft Blog http://realtysecurity.com/blog/ YouTube http://www.youtube.com/stungundotcom Finextra http://www.finextra.com/community/profile.aspx?id=44396 BankInnovation http://bankinnovation.net/profile/IdentityTheftSpeaker Facebook http://www.facebook.com/people/Robert-Siciliano/534933030 IMDB http://www.imdb.com/name/nm2892079/resume Wiki http://en.wikipedia.org/wiki/Robert_Siciliano
Business builder, strategic marketer, security analyst, published author, television news correspondent, actor. Deliver presentations throughout the United States and Canada on identity theft protection and personal security.
Work with Fortune 1000, IT and startups. Launching, branding, messaging, representation, m&a facilitator, SEO and media.
Current projects include dynamic biometrics, credit card platform multi-factor authentication, identity theft securityAAS, laptop tracking, security investigations and telemarketing fraud mitigation.
Specialties Appear in print, radio and televised media, on Today Show, CBS Early Show, CNN, MSNBC, FOX, CNBC, E!THSi, Inside Edition, Tyra, Montel, Maury, Howard Stern, USA Today, Forbes, Cosmo, Good Housekeeping, Readers Digest, Consumer Digest, Smart Money, NY Times, NY Post, BOS Globe, LA Times, Wash Times, Wash Post, Chicago Trib, Atl Journal, MIA Herald, SF Chronicle, SEA Times, ABC News.com, Maxim, CNet, CSO, TechRepublic, Search Security, Security Mgmt, AP, UPI, Reuters, and Entrepreneur.