julesjones: (Default)
I have my own private domain which comes with unlimited email addresses. I use a different, extremely non-public, address for each site that might have access to my banking details.

I've just received emails from two sites that do have some business sending me email -- but *not* sent to the address they ought to have on file. No, they've both sent emails to the address I used for one of my bank accounts before the Epsilon hack a couple of months ago. Interestingly, while at first glance they look like legitimate emails, the links they want me to click are of the www.ebay-upgrades.com type (no, that wasn't one of them). Looking at the headers, my guess is that a third business really ought to get a security expert to look at its mailserver, because they're being parasitised. I suspect that I would deeply regret even clicking on the link, never mind downloading and installing the software updates I'm being invited to install.

I'm surprised it's taken this long to get hit with this, but this is one reason why I use the multi-address approach -- it makes a lot of the phishing attacks stick out like a sore thumb, even when they've managed to grab a private address.
julesjones: (Default)
***ETA: see this update from LJ re security exploit***

old news, ignore the bit below and check the official update at the link above.

This is LJ-specific, but given the cross-over audience I'm going to cross-post it to DW.

epi-lj reports:

Some of you may have noticed that weird flash objects rendering as a big hunk of whitespace are showing up on some of your recent posts. I don't know for sure what's going on, but I *suspect* it's something busted with their new, "Your Journal - Your Money" feature. I'm hoping they fix it soon. (I have not opted in to that feature. It seems to be happening on lots of journals that are eligible for the feature, even though the people have not opted in, so, to be clear, this could happen to your posts even if you do not use that feature.)

I'm just posting about it because [info]eeyorerin noticed that when it ads the objects, it also makes your post public. This could be a pretty big concern if you posted anything that you thought was going to be filtered or that you really didn't want public. I just tried this out myself, and it did indeed change the security from friends-only to public.

[info]eeyorerin reports that you can re-edit your security as long as you don't delete the flash objects, and the new security setting seems to stick. (If you remove the flash objects, it'll re-add them and re-reset your security.)

full post

Major security breach, reported in a couple of places to look like a weird bug from an interaction with ljtoys. (Gacked from
brooks-moses.)

Profile

julesjones: (Default)
julesjones

May 2025

S M T W T F S
    123
4567 8910
11121314151617
18192021222324
25262728293031

Syndicate

RSS Atom

Most Popular Tags

Style Credit

Expand Cut Tags

No cut tags