Printer-friendly copy Email this topic to a friend
Lobby General Discussion topic #13378792

Subject: "Security nerds: I received an email with my login creds in the subject....." Previous topic | Next topic
BlakStaar
Member since May 29th 2002
1261 posts
Wed Apr-15-20 06:12 PM

Click to send email to this author Click to send private message to this authorClick to view this author's profileClick to add this author to your buddy list
"Security nerds: I received an email with my login creds in the subject....."


  

          

What's my next step beyond reporting the message as spam and changing my Gmail password again? Just ignore it?

I googled the email address and found it on www.bitcoinabuse.com. Others have received the same message.

I have multiple email accounts and this one was sent to my main Gmail account. The message demanded I send $1000 in bitcoin. They threatened to share a video clip of me looking at embarrassing material to people in my address book if I don't comply within 24 hours.

Now, I'm fairly certain this is fake but I'm bothered this time because A REAL PASSWORD of mine was in the subject line. ;-/

NOTE:
- The password was an older password that I stopped using for most websites several years ago and I don't think I ever used it as my Gmail password. If I did, it ages ago. I've had the account for 10+ years.
- Last year, I received a couple of notices that my main Gmail address account was found on the dark web. Speaking of:
- I learned about haveibeenpwned.com recently, which reported that my main Gmail account was "Pwned on 13 breached sites and found no pastes."
- I stopped using public Wi-Fi. networks last year (e.g. Starbucks) after unauthorized use of my PayPal Debit Mastercard twice short duration. Still haven't figured out how that happened but the transactions were Amazon orders placed on someone else's account. I got Amazon to cancel the orders before they shipped but the site refused to disclose the identity of the person who placed it. They need to start forwarding that shit to local police departments.
- I regularly monitor my credit and receive alerts.
- I started using a camera cover on my Macbook last year

I hate that data breaches are the new normal. Everything is trash.

Ugh.

--

--
"Music is not to be possessed; it's to be shared.” - James Mtume

"Just stay loose, keep it raw, and bang ya drums out sometimes." - Madlib

  

Printer-friendly copy | Reply | Reply with quote | Top


Topic Outline
Subject Author Message Date ID
Change all the passwords you have ASAP
Apr 15th 2020
1
RE: Change all the passwords you have ASAP
Apr 15th 2020
      Lastpass can automate password changes
Apr 15th 2020
10
check this out:
Apr 15th 2020
2
RE: check this out:
Apr 15th 2020
3
2 step is annoying but it’s damn near impossible to beat
Apr 15th 2020
4
oops i missed that. i edited my reply with some more suggestions too.
Apr 15th 2020
5
also if you use a gmail address
Apr 15th 2020
8
      RE: also if you use a gmail address
Apr 15th 2020
12
yes the email is fake/scam
Apr 15th 2020
6
this is crux...password manager / don't reuse passwords n/m
Apr 15th 2020
9
your problem isn't use of public wifi
Apr 15th 2020
7
RE: your problem isn't use of public wifi
Apr 15th 2020
11
      Most phishing sites use SSL now
Apr 16th 2020
16
Like other have stated, 2FA is the bare minimum. but
Apr 15th 2020
13
What's the bitcoin address that they want you to deposit to?
Apr 15th 2020
14
It's always interesting to see how much money folks have sent to the add...
Apr 15th 2020
15
RE: What's the bitcoin address that they want you to deposit to?
Apr 16th 2020
17
Yes, it's a scam
Apr 16th 2020
18
Bruh. Throw that computer in the garbage.
Apr 16th 2020
19

legsdiamond
Member since May 05th 2011
80224 posts
Wed Apr-15-20 06:18 PM

Click to send email to this author Click to send private message to this authorClick to view this author's profileClick to add this author to your buddy list
1. "Change all the passwords you have ASAP"
In response to Reply # 0


          

****************
TBH the fact that you're even a mod here fits squarely within Jag's narrative of OK-sanctioned aggression, bullying, and toxicity. *shrug*

  

Printer-friendly copy | Reply | Reply with quote | Top

    
BlakStaar
Member since May 29th 2002
1261 posts
Wed Apr-15-20 06:30 PM

Click to send email to this author Click to send private message to this authorClick to view this author's profileClick to add this author to your buddy list
"RE: Change all the passwords you have ASAP"


  

          

There are so many but I'm going to work on that tonight. I purchased this book earlier this year:
https://www.amazon.com/Personal-Internet-Address-Password-Book/dp/1441303251/

I'm going the old-school route because I don't trust password apps.

I used to email passwords to my Gmail account. Stopped doing that ish in recent years.

--
"Music is not to be possessed; it's to be shared.” - James Mtume

"Just stay loose, keep it raw, and bang ya drums out sometimes." - Madlib

  

Printer-friendly copy | Reply | Reply with quote | Top

        
Nopayne
Member since Jan 03rd 2003
52651 posts
Wed Apr-15-20 08:18 PM

Click to send email to this author Click to send private message to this authorClick to view this author's profileClick to add this author to your buddy listClick to send message via AOL IM
10. "Lastpass can automate password changes"
In response to Reply # 0


  

          

fwiw

---
Love,
Nopayne

  

Printer-friendly copy | Reply | Reply with quote | Top

Reeq
Member since Mar 11th 2013
16347 posts
Wed Apr-15-20 06:24 PM

Click to send private message to this authorClick to view this author's profileClick to add this author to your buddy list
2. "check this out:"
In response to Reply # 0
Wed Apr-15-20 06:48 PM by Reeq

          

https://haveibeenpwned.com

google chrome also has a feature that checks the passwords you enter against ones in known data breaches.

on top of changing your email password (or any other site that uses that password)...you should enable 2 step/factor authorization whenever possible.

also NEVER use a debit card for purchases. that gives thieves a direct line right into your bank account and theres no protection of your money (your bank will prolly make *you* pay it back if you have a negative balance). use a credit card whenever possible (0 fraud liability and chargebacks).

if you cant get a credit card and need something for online purchases...sign up for http://www.privacy.com. you can create virtual cards for each site/purpose you need them. the charges do pull from your bank account but you at least have the option to pause cards, close cards, set spending limits that block anything over the maximum, etc.

  

Printer-friendly copy | Reply | Reply with quote | Top

    
BlakStaar
Member since May 29th 2002
1261 posts
Wed Apr-15-20 06:28 PM

Click to send email to this author Click to send private message to this authorClick to view this author's profileClick to add this author to your buddy list
3. "RE: check this out:"
In response to Reply # 2


  

          

Thank you. I mentioned this in the OP. See item No. 3 in my bulleted notes.

I'm going to look into 2-step authorization more. I have that turned on for a couple sites and services, including my Apple account. I need to use that whenever it's available even though it's annoying.

--
"Music is not to be possessed; it's to be shared.” - James Mtume

"Just stay loose, keep it raw, and bang ya drums out sometimes." - Madlib

  

Printer-friendly copy | Reply | Reply with quote | Top

        
legsdiamond
Member since May 05th 2011
80224 posts
Wed Apr-15-20 06:30 PM

Click to send email to this author Click to send private message to this authorClick to view this author's profileClick to add this author to your buddy list
4. "2 step is annoying but it’s damn near impossible to beat"
In response to Reply # 3


          

****************
TBH the fact that you're even a mod here fits squarely within Jag's narrative of OK-sanctioned aggression, bullying, and toxicity. *shrug*

  

Printer-friendly copy | Reply | Reply with quote | Top

        
Reeq
Member since Mar 11th 2013
16347 posts
Wed Apr-15-20 06:30 PM

Click to send private message to this authorClick to view this author's profileClick to add this author to your buddy list
5. "oops i missed that. i edited my reply with some more suggestions too."
In response to Reply # 3
Wed Apr-15-20 06:38 PM by Reeq

          

as for 2 step auth...there are authenticator apps that make it a lot less painful.

check this one out: http://www.authy.com

i tend to use an auth app when possible (instead of sms) because its less likely to get compromised as opposed to someone getting the sms code from your notifications or lock screen or something like that. authy also requires another pin (separate from your phone pin) to open up on your phone. so thats at least 2 separate barriers a thief would have to go through to hack one of your accounts.

  

Printer-friendly copy | Reply | Reply with quote | Top

    
Reeq
Member since Mar 11th 2013
16347 posts
Wed Apr-15-20 07:10 PM

Click to send private message to this authorClick to view this author's profileClick to add this author to your buddy list
8. "also if you use a gmail address"
In response to Reply # 2


          

start appending the + sign and an identifier to track your email.

like sign up to sites (or change your account email there) to youraddress+amazon@gmail.com, youraddress+walmart@gmail.com, etc.

sometimes it makes it a lot easier to figure out where your info was compromised when you start receiving spam messages addressed to youraddress+grubhub@gmail.com.

if youre signing up for sketchy sites, sites with lax security (like a low traffic web forum lol), or sites you generally wouldnt wanna be publicly traced to (like porn sites)...you should be using an entirely different email (and still using + to track). you can just forward all messages to your real email so you wont miss any.

you dont want these accounts being linked to your primary email/identity by data collectors/furnishers like intelius, spokeo, etc.

you should prolly get a google voice number to use as a spambox too if you have to enter your number somewhere that you dont want to give them your real number. i have several different google voice numbers for online stores, banks, credit cards, social media sites, etc. keep in mind credit cards (and banks if you get lending) list your number on various credit bureaus/agencies and it can be seen by anyone doing an inquiry. and most of these companies/sites sell your info off to third parties (who may sell it off to even more people). so you prolly dont wanna use your primary mobile number and have it floating around out there.

  

Printer-friendly copy | Reply | Reply with quote | Top

        
BlakStaar
Member since May 29th 2002
1261 posts
Wed Apr-15-20 08:57 PM

Click to send email to this author Click to send private message to this authorClick to view this author's profileClick to add this author to your buddy list
12. "RE: also if you use a gmail address"
In response to Reply # 8


  

          

These are really good tips. Thanks!

--
"Music is not to be possessed; it's to be shared.” - James Mtume

"Just stay loose, keep it raw, and bang ya drums out sometimes." - Madlib

  

Printer-friendly copy | Reply | Reply with quote | Top

Rjcc
Charter member
95062 posts
Wed Apr-15-20 06:32 PM

Click to send email to this author Click to send private message to this authorClick to view this author's profileClick to add this author to your buddy listClick to send message via AOL IM
6. "yes the email is fake/scam"
In response to Reply # 0


          

yes any password you've used is likely to have been hacked.

that's why you use a password manager to maintain unique passwords and turn on two-factor where available.

www.engadgethd.com - the other stuff i'm looking at

  

Printer-friendly copy | Reply | Reply with quote | Top

    
nonaime
Charter member
3119 posts
Wed Apr-15-20 08:05 PM

Click to send email to this author Click to send private message to this authorClick to view this author's profileClick to add this author to your buddy list
9. "this is crux...password manager / don't reuse passwords n/m"
In response to Reply # 6


          

.

~~~~~~~~
A bad Samaritan averaging above average men (c) DOOM

  

Printer-friendly copy | Reply | Reply with quote | Top

Rjcc
Charter member
95062 posts
Wed Apr-15-20 06:38 PM

Click to send email to this author Click to send private message to this authorClick to view this author's profileClick to add this author to your buddy listClick to send message via AOL IM
7. "your problem isn't use of public wifi"
In response to Reply # 0


          

I wouldn't nec recommend logging on to random networks, but your credit card didn't get stolen because someone MITM you at starbucks.

they hacked a store you'd shopped at before and stole the information from there, or maybe by hacking a swipe card machine somewhere

www.engadgethd.com - the other stuff i'm looking at

  

Printer-friendly copy | Reply | Reply with quote | Top

    
BlakStaar
Member since May 29th 2002
1261 posts
Wed Apr-15-20 08:57 PM

Click to send email to this author Click to send private message to this authorClick to view this author's profileClick to add this author to your buddy list
11. "RE: your problem isn't use of public wifi"
In response to Reply # 7


  

          

Thanks. I was only visiting sites with secure connections so I was a little perplexed.

When the unauthorized transactions happened, I was mostly pumping gas at Mobil/Exxon to take advantage of their reward/points system. I eventually stopped because of those damn skimmers. I started using the app to pay and collect points, which is easier, anyway.

I have since switched to pumping at Costco exclusively again but now that means I have to go back to swiping my damn card. I'm going to get a new debit card soon and only use my Citi Costco card at the pump. I read skimmers are more sophisticated now and can't really be detected. ;-(

Unfortunately, my local Costco stores don't have the pay fob option yet.
https://www.costco.com/costco-pay.html

--
"Music is not to be possessed; it's to be shared.” - James Mtume

"Just stay loose, keep it raw, and bang ya drums out sometimes." - Madlib

  

Printer-friendly copy | Reply | Reply with quote | Top

        
legsdiamond
Member since May 05th 2011
80224 posts
Thu Apr-16-20 05:45 AM

Click to send email to this author Click to send private message to this authorClick to view this author's profileClick to add this author to your buddy list
16. "Most phishing sites use SSL now"
In response to Reply # 11


          

****************
TBH the fact that you're even a mod here fits squarely within Jag's narrative of OK-sanctioned aggression, bullying, and toxicity. *shrug*

  

Printer-friendly copy | Reply | Reply with quote | Top

nonaime
Charter member
3119 posts
Wed Apr-15-20 09:03 PM

Click to send email to this author Click to send private message to this authorClick to view this author's profileClick to add this author to your buddy list
13. "Like other have stated, 2FA is the bare minimum. but"
In response to Reply # 0


          

it doesn't mean you can stop paying attention to where you're going just because you have 2FA enabled.

Receiving your code via SMS is probably the worst out of the 2FA options out there (still better than nothing at all). But, if you're concerned about someone being able to futz with SS7 and/or sim cards...then you gotta be more concerned about an active attacker intercepting the 2FA code when you enter it into a dirty website, cuz that's easier to pull off.

Example, let's say you fell for one of these "hey are you available" phishing emails and after some back and forth, I've convinced you to click on a link in an email which takes you to my phishing site. And I am waiting. You enter in your credentials into my phishing site...I pass that info along to the real site...then my phishing site tells you to "please enter in your six digit code or accept your push notification". So, you pass your code to me and I enter it into the real site that's asking for your 2FA code (and yes these codes self destruct, but I'm actively attacking you) or better yet, I just wait for you to accept your push notification.

Now, if someone is on their job, there's probably an automated process that sees that the push notification was accepted on a device with an IP address that is in a totally different geo-location than the IP address that's logging into the legitimate website and blocks the logon attempt....more likely, that process is just monitoring and they'll know something happened after the fact.

Using something like a yubikey (U2F) would probably be the more secure 2FA solution, since the device has to be accessible by the browser of whomever is triggering the authentication. As an attacker, getting you to press your yubikey attached to your computer does nothing for me....for now...

~~~~~~~~
A bad Samaritan averaging above average men (c) DOOM

  

Printer-friendly copy | Reply | Reply with quote | Top

flipnile
Member since Nov 05th 2003
13632 posts
Wed Apr-15-20 09:19 PM

Click to send email to this author Click to send private message to this authorClick to view this author's profileClick to add this author to your buddy list
14. "What's the bitcoin address that they want you to deposit to?"
In response to Reply # 0


          

  

Printer-friendly copy | Reply | Reply with quote | Top

    
nonaime
Charter member
3119 posts
Wed Apr-15-20 10:42 PM

Click to send email to this author Click to send private message to this authorClick to view this author's profileClick to add this author to your buddy list
15. "It's always interesting to see how much money folks have sent to the add..."
In response to Reply # 14


          

~~~~~~~~
A bad Samaritan averaging above average men (c) DOOM

  

Printer-friendly copy | Reply | Reply with quote | Top

    
BlakStaar
Member since May 29th 2002
1261 posts
Thu Apr-16-20 10:36 AM

Click to send email to this author Click to send private message to this authorClick to view this author's profileClick to add this author to your buddy list
17. "RE: What's the bitcoin address that they want you to deposit to?"
In response to Reply # 14


  

          

I don’t know if I should post that to a public website?

--
"Music is not to be possessed; it's to be shared.” - James Mtume

"Just stay loose, keep it raw, and bang ya drums out sometimes." - Madlib

  

Printer-friendly copy | Reply | Reply with quote | Top

handle
Charter member
19005 posts
Thu Apr-16-20 11:03 AM

Click to send email to this author Click to send private message to this authorClick to view this author's profileClick to add this author to your buddy list
18. "Yes, it's a scam"
In response to Reply # 0


          

Change all of your passwords.

I switched to using the password manager Lastpass and I have it generate completely random and long passwords.


Now if someone installs a keylogger on your machine they can get EVERYTHING - but they could probably get everything before.

------------


Gone: My Discogs collection for The Roots:
http://www.discogs.com/user/tomhayes-roots/collection

  

Printer-friendly copy | Reply | Reply with quote | Top

Triptych
Charter member
30127 posts
Thu Apr-16-20 02:37 PM

Click to send email to this author Click to send private message to this authorClick to view this author's profileClick to add this author to your buddy listClick to send message via AOL IMClick to send message via ICQ
19. "Bruh. Throw that computer in the garbage."
In response to Reply # 0


  

          

.

____________________________

http://instagram.com/yogikenan
http://instagram.com/shotbykenan
http://stackoverflow.com/users/43089/triptych
http://github.com/djtriptych

  

Printer-friendly copy | Reply | Reply with quote | Top

Lobby General Discussion topic #13378792 Previous topic | Next topic
Powered by DCForum+ Version 1.25
Copyright © DCScripts.com