Tue Sep 10, 2019, 10:33 AM
Pluvious (3,564 posts)
Google Finally Confirms Security Problem For 1.5 Billion Gmail And Calendar Users
As a rule, one should own and maintain a "banking only" laptop, kept updated, with AV installed - and NEVER used for ANYTHING but accessing your crucial remote online accounts (brokerage, banks, NOT Facebook, Twitter etc).
NEVER used for email, nor apps, nor anything else but the web browser. Make no searches, nor click links or download things. The sites you visit are never from clicking links, except bookmarks you've MANUALLY created. Use the native browser, and no added plugins. Passwords should be maintained in a secure offline password utility. Log into sites by only using the password utility, never save access info in the web browser. How does the Google Calendar attack work?
Gmail users are finding themselves on the wrong end of a sophisticated scam which leverages misplaced trust through the use of malicious and unsolicited Google Calendar notifications. Google Calendar allows anyone to schedule a meeting with you, and Gmail is built to integrate tightly with this calendaring functionality. Combine these two facts and users find themselves in a situation whereby the threat actor can use this non-traditional attack vector to bypass the increasing amount of awareness amongst average users when it comes to the danger of clicking unsolicited links. https://www.forbes.com/sites/daveywinder/2019/09/09/google-finally-confirms-security-problem-for-15-billion-gmail-and-calendar-users/amp/
|
12 replies, 2495 views
![]() |
Author | Time | Post |
![]() |
Pluvious | Sep 2019 | OP |
underpants | Sep 2019 | #1 | |
Pluvious | Sep 2019 | #2 | |
defacto7 | Sep 2019 | #4 | |
harumph | Sep 2019 | #6 | |
Pluvious | Sep 2019 | #11 | |
uponit7771 | Sep 2019 | #10 | |
defacto7 | Sep 2019 | #3 | |
Coventina | Sep 2019 | #5 | |
dalton99a | Sep 2019 | #7 | |
defacto7 | Sep 2019 | #8 | |
Pluvious | Sep 2019 | #12 | |
Delmette2.0 | Sep 2019 | #9 |
Response to Pluvious (Original post)
Tue Sep 10, 2019, 10:54 AM
underpants (174,517 posts)
1. I have passwords on a double protected spreadsheet
That’s should be good, no?
|
Response to underpants (Reply #1)
Tue Sep 10, 2019, 11:29 AM
Pluvious (3,564 posts)
2. At the very least...
Follow these two rules:
No obvious context, and obfuscate them. Like no URL's and meaningful descriptions Tac on the end or beginning extra chars that you don't actually use. But ideally, being viewable isn't good, in case your screen gets captured. And the storing of them should be encrypted. Passwords should be entered by a paste action, never typed (key logging is a vulnerability). Cnet site often has top ten lists, I use the open source keepass.org one myself, and download it from GitHub. |
Response to Pluvious (Reply #2)
Tue Sep 10, 2019, 12:13 PM
defacto7 (13,485 posts)
4. Excellent must do routines. People take too much for granted.
That is the biggest backdoor of all, taking the internet and major sites for granted.
|
Response to Pluvious (Reply #2)
Tue Sep 10, 2019, 12:27 PM
harumph (1,481 posts)
6. what is your take on epic privacy browser using the built in proxy functionality?
Response to harumph (Reply #6)
Wed Sep 11, 2019, 10:10 AM
Pluvious (3,564 posts)
11. I'm sorry but I've not yet researched that (n/t)
Response to Pluvious (Reply #2)
Wed Sep 11, 2019, 09:09 AM
uponit7771 (88,339 posts)
10. +1, "Passwords should be entered by a paste action"
Response to Pluvious (Original post)
Tue Sep 10, 2019, 12:10 PM
defacto7 (13,485 posts)
3. This is a must. It's internet security survival.
Response to Pluvious (Original post)
Tue Sep 10, 2019, 12:26 PM
Coventina (24,987 posts)
5. My place of work requires us to use Google Drive and Google Calendar.
And yes, it drives me CRAZY that people can schedule my time for me.
I never even look at my work Google Calendar, I refuse. When I get smack about missing something, I always say, "Did you bother to inform me, personally?" "Well, I put it in your calendar," they whine back. DRIVES ME NUTS!! ![]() |
Response to Pluvious (Original post)
Tue Sep 10, 2019, 12:31 PM
dalton99a (73,648 posts)
7. Never let your work Google calendar/Gmail touch your personal calendar/email
unless you want Google to vacuum everything up and keep it forever
|
Response to Pluvious (Original post)
Tue Sep 10, 2019, 01:21 PM
defacto7 (13,485 posts)
8. I agree with the op article but I'd like to add one extra level of security...
If you don't have an extra laptop or even if you do, follow the mentioned instructions but do all your finanical and banking transactions booting into a USB stick with the TOR operating system installed on it. It's has fully encrypted partitions, your connection is anonymous and it automatically wipes your RAM writing over it with random 1s and 0s when you shut it down.
You could do the same yourself if you make a separate enctypted patition on your computer and install a Linux OS in it. You can easily wipe your ram before you leave. |
Response to defacto7 (Reply #8)
Wed Sep 11, 2019, 10:11 AM
Pluvious (3,564 posts)
12. Good info and suggestions - thanks (nt)
Response to Pluvious (Original post)
Wed Sep 11, 2019, 07:51 AM
Delmette2.0 (3,577 posts)
9. I already use a seperated laptop for my banking.
Never my cell phone.
Thanks to everyone with all the extra information to keep us safe. ![]() ![]() |