Showing posts with label email. Show all posts
Showing posts with label email. Show all posts

Wednesday, September 17, 2014

the PayPal pot calling the Apple Pay kettle black

so if you haven't heard yet, PayPal took out a full page ad in the New York Times trying to drag Apple Pay's name through the mud based on Apple's unfortunate celebrity nude selfie leak. This despite the fact that PayPal happily hands out your email address to anyone you have a transaction with. In essence, PayPal has been leaking email addresses for years and not doing anything about it, so they shouldn't get to criticize others for leaking personal information.

what's the big deal about email addresses? while it's true that we often have to give every site we do a transaction on an email address, we don't have to give them all the same address. in fact, giving each site a different email address happens to be a pretty good way to avoid spam, but more importantly it's a good way to avoid phishing emails, and that's important where PayPal is concerned because PayPal one of the most phished brands in existence.

unfortunately, because PayPal wants all parties in a transaction to be able to communicate with each other, they do the laziest, most brain-dead thing one can imagine to accomplish this: they hand out your PayPal email address to others, which is pretty much the worst email address to do that with. i have actually had to change the disposable email address i use with PayPal because they are apparently incapable of keeping that address out of the hands of spammers, phishers, and other email-based miscreants. furthermore, i also use their service less because i don't want to have to clean up after their mess.

at some point i may have to start creating disposable PayPal accounts and use prepaid debt cards with them. certainly if i were trying to hide from massive spy agencies then that would be the way to go, but if i'm only concerned with mitigating email-borne threats i really shouldn't have to go to that much trouble. there are other, more intelligent things that PayPal could, even should be doing.

  • they could share the email address of your choosing, rather than the one you registered with their service unconditionally. that way you could provide the same address you probably already provided that other party when you created an account on their site. it shouldn't be too difficult for them to verify that address before sharing it with the other party since they already verify the one you register with.
  • they could offer their own private messaging service so that communication could be done through their servers (which would no doubt aid in conflict resolution).
  • they could provide a disposable email forwarding service such that the party you're interacting with gets a unique {something}@paypalmail.com address that forwards the mail on to the email address you registered on PayPal with, and once the transaction is completed to everyone's satisfaction the address is deactivated.
they don't do anything like that, however. here's what you can do right now with the facilities PayPal makes available. it's a more painful and less intuitive process than anything proposed above, but it does work.
  1. before you choose to pay for something with PayPal, log into PayPal and add an email address (the one you want shared with the party you're doing a transaction with) to your profile. PayPal limits you to 8 addresses.
  2. confirm the address by opening the confirmation link that was sent to that address
  3. make that address the primary email address for your account
  4. confirm the change in primary email address (if you have a card associated with your PayPal account, PayPal may ask you to enter the full card number)
  5. at this point you can use PayPal to pay for something and the email address that will be shared with the other party is the one you just added to your PayPal account
  6. once you've paid with PayPal you will probably want to log back into PayPal, change the primary email address back to what it originally was (and confirm the change once again) and then remove the address you added for the purposes of your purchase. the reason you'll likely want to do this is because PayPal sends emails to every address it has on record for you, and those duplicate emails will get old fast.
most people aren't even going to be aware that they can do this to keep their real PayPal email address a secret from 3rd parties. as a result all manner of email-borne threats can and eventually will wind up in what would otherwise have been a trusted email inbox. make no mistake, this isn't PayPal providing a way to keep that email address private, this is a way of manipulating PayPal's features to achieve that effect. there are too many unnecessary steps involved for this to be the intended use scenario.

as such, PayPal is leaking a valuable email address by default every time you pay for something. yes Apple's selfie SNAFU was embarrassing to people, and yes if Apple doesn't do something about that now that they're becoming a payment platform it could be not just embarrassing but financially costly for victims, but PayPal is already assisting in similarly costly outcomes right now (not to mention potential malware outcomes) so they really have no right to be criticizing Apple. Apple, at least, is taking steps to correct their problems - what is PayPal doing?

Wednesday, April 06, 2011

why the epsilon breach shouldn't be an issue

the epsilon breach (where an email marketing company that does business with a veritable who's who of big name corporate brands and financial institutions lost the names and email addresses of the customers of those companies) seems to be on everyone's mind recently, and to tell the truth i find that kind of strange.

it's not as though i'm under any illusion about it not being able to affect me. a colleague of mine at work got a notification about the breach affecting him so while i haven't received one yet myself, the possibility of receiving one certainly exists. yet i find myself completely unconcerned about the possibility. why? because i took steps to protect myself proactively (steps my colleague knew he should have taken such that now wishes he'd been more vigilant).

i have been using disposable email addresses since the fall of 2004. with them i've managed to keep any email accounts i created after that point completely spam free for the past 6 1/2 years, i've come up with a sender authentication protocol to foil phishing, and as it happens i've recovered from email breaches in the past in mere moments.

and that's the reason a breach like epsilon is a non-issue to me. not only is it old hat, recovering is as simple as logging into the disposable email provider and clicking disable or delete (depending on the provider) for each compromised address, and then going on about the rest of your day.

it's dead simple to recover from the breach of something when that something happens to be disposable - you simply dispose of it. what i don't understand is, why aren't more people and especially more security practitioners doing the same thing? why hand out your real personal contact information like candy on halloween if you don't have to (and believe me, you don't have to)?  even if you decide you still want to do business with these companies who saw fit to hand your contact information over to a marketing company (hey, you're already their customer, why do they need to keep trying so hard to sell to you), it's a heck of a lot easier to make a replacement disposable email address than it is to make a replacement real email address. just a couple of clicks and some random typing (or just mash keys if you prefer); no captcha, no verifcation, no profile info, you filled that all out when you created an account at the disposable email provider in the first place.

cory doctorow gave a short talk about kids and privacy and he mentioned that they're being trained to not value their privacy, in part by over protective parents who prevent them from learning how to protect themselves. i don't think kids are the only ones who've been so trained. one of the most regrettable schools of thought that i've seen displayed from users all the way up to security pros is the one that says 'they are (or are supposed to be) protecting me'. there is a profound absence of self-reliance in favour of letting protection be the responsibility of someone else.

most people wouldn't hand their phone number out to every tom, dick, or harry they meet on the street, but when it comes to email addresses somehow people think the rules are different. they trust everyone who asks for it and expect everyone to protect it for them instead of protecting it themselves. this is an absurd position to take, but authorities (ie. people who are supposed to know better) have groomed the masses to systematically take just that position when it comes to anything that has to do with online protection.

i'm not holding my breath but, considering the scope of the epsilon breach, maybe some people will start to think
well if you're going to protect me from the bad guys, who's going to protect me from you?
i know, i'm probably being too optimistic, but surely some people out there will see this incident and realize how truly pervasive the mishandling of personal information is by the people we entrust it to. dozens of companies handed that data over to one completely unnecessary entity which then became a single point of failure, and because most people weren't protecting themselves from those companies (either their intentional bad acts or their ineptitude) many people are now at much greater risk of falling victim to targeted phishing and other related attacks.

a clever reader would probably realize that entrusting your real email address to a disposable email provider is still expecting that provider to protect it for you. the thing is, instead of trusting many entities with your data, under this model you're only trusting one. you also don't have to trust them with the same address you use for personal correspondence (which would be the hardest kind of address to change); i certainly don't.

Thursday, February 11, 2010

user database breach at instructables?

many have at least heard the advice to use unique passwords at every site they visit. well i go a few steps beyond that. not only do i use unique randomly generated passwords at every site, i use unique randomly generated email addresses at each site too.

that probably sounds like overkill, but consequence for me (besides knowing exactly which sites are spammy) is that the older identities collectively form a kind of honeypot for detecting user database breaches.

it was as a result of my address for ethicalhacker.net receiving spam that i realized (and later verified) that something untoward had happened there and so it is that today i'm going to come out and say that something fishy is going on over at instructables.com.

a unique, randomly generated email address (basically a secret shared between only myself and instructables) that is unguessable (there are approximately 4.7x10^18 possible values so the chance of them guessing one of my 200 or so addresses is so small that if they guessed 1 million times a second it would still take on average 375 years before they got one) should only be usable by those who know it, so the fact that i'm receiving drug spam at this email address tells me that somehow the user information they had in their database for my account has been leaked.

*update*: it appears i miscounted the number of characters in the email address and thus my probability calculations are off. there's only 1x10^14 combinations, which means that at a million guesses a second someone could get expect to guess one of mine in (on average) about 3 days. i'm not convinced that sort of brute forcing operation is going on, however (it seems like it would be too much work for too little benefit).

Thursday, August 23, 2007

who doesn't love bacn?

seems a new meme was born recently involving an email classification called bacn... it seems it's become important to classify notification and other emails that you actually want to receive but don't have time to look at right now...

it also seems that some people see a problem here... frankly, i don't... bacn isn't spam, it isn't anything like spam... it's sent by cooperative parties more or less at your request - if you don't want to receive it anymore you can ask for it to stop and it should actually stop... and since it isn't being sent maliciously it's not going to mutate and evolve rapidly in order to avoid filters that move it into folders specifically made to hold it and organize it and keep it from making your inbox unmanagable...

basically, everything we learned not to do with spam actually works on bacn because bacners (got a better term for bacn senders?) are cooperative rather than malicious...

Sunday, December 31, 2006

how to recognize phishing emails the easy way

perhaps you've seen this phishing iq test before... if not, that's ok - it's basically a bunch of examples of legitimate emails and phishing emails and you have to try and figure out which are which... the root concept is that there are these heuristics or rules of thumb that you can apply so as to determine whether a particular email is phishy just by looking at it...

the fact that browsers now come with anti-phishing technology built in that tries to identify a phishing site just by looking at the URL is strong evidence that those rules of thumb for detecting phishing emails are a failure but take the test and look at some of those rules at the end and see if you can determine why those rules aren't going to work... if you ask me, those rules are just too complex for the average person to remember or apply... add to that the fact that the characteristics of a legitimate email are possible in phishing emails (for example, ebay starts their emails to you with your ebay user name but anyone who has interacted with you on ebay knows that user name and thus has the information necessary to make a convincing fake ebay email)... finally take into account that legitimate emails often display phishy characteristics (both in the test, where only one of the emails was completely free of phishy characteristics, and in this real world example) and it becomes clear that not only are the rules complex but they're pretty much completely unreliable too...

after getting through that test, if you're like me you're probably saying to yourself "there must be an easier way"... so you can imagine how glad i am that i don't need to try to remember and follow those screwy rules... instead, i do something i touched on in my spam avoidance article - i use disposable email addresses... now, while the spam avoidance techniques actually apply to pretty much all forms of email annoyance (if the bad guys don't know your email address they can't send you bad email), i'm actually talking about more than just keeping my email address out of the hands of phishers, something that works even when your real email address is known to the bad guys... i use unique (a different one for each site) unguessable disposable email addresses provided by sneakemail.com and then when i get an email from ebay or paypal or my bank i check and make sure that it was sent to the right address for that organization...

here's how the magic works - let's say i create an address like mgbwklw02@sneakemail.com and give that address to ebay and no one else... the address is a secret that only ebay and myself know and no one else can guess so when i get an ebay email sent to that address i'll know that it was sent by ebay because they proved who they were by using a secret known only to ebay and myself... it's like knowing the secret passphrase or handshake to get into an exclusive club (or, more technically, it's like a shared secret authentication protocol)... alternatively, if i get an email supposedly from ebay but sent to some other email address i'll know it's fake because it was sent to some address that i never gave to ebay in the first place... if someone really, really wanted to send me a convincing fake ebay email they would have to either guess exactly the right email address to send to or guess the label i gave my ebay address (sneakemail.com allows you to label your disposable addresses and includes the that label in the From: field to help you determine which address the email was sent to) and try to forge a sneakemail.com header...

could using unique unguessable disposable email addresses for sites/organizations and ignoring emails sent to the wrong address for the site/organization in question qualify as an anti-phishing safe hex rule? i think so... although it requires a little more work up front (creating a new address each time you create an account somewhere), it's conceptually simpler than the multitude of rules currently being suggested and it's a lot more reliable too since it doesn't depend on questionable criteria such as how the email was composed...

Thursday, December 28, 2006

how to avoid email spam

typically, the life-cycle of email spam (in the most general sense) goes something like this:
  1. the spammer gets your email address
  2. the spammer sends you spam
  3. you receive and do your best to deal with that spam

most of the anti-spam technology that the average person is aware of works to deal with spam after it's been sent, effectively trying to address stage 3 in the spam life-cycle... you probably know this technology as spam filtering, either a black list where you record all the email addresses (or perhaps domains) from whom you don't want to receive email, a white list where you record all the email addresses from whom you do want to receive email, or some more advanced content-based spam filter such as the bayesian filtering... as most average people are at least vaguely familiar with spam filtering (even if only by way of noticing there's a junk mail folder in their webmail) they also know (or if not, should be made aware) that filtering isn't a perfect solution, that some legitimate mail can get flagged as spam and some spam may fool the filter into thinking it's legitimate mail... nothing is perfect, but as spam volume increases the number of spams that sneak through spam filters also increase, and nobody (except the spammers) want to see the amount of spam in our inboxes increase...

addressing stage 2, trying to stop the spam from getting sent or at least making it more difficult or costly, is something most average folks aren't aware of (or at least don't often think about) because it's not something they've been a part of for the most part... early on there was account termination for those caught spamming, then there were CAPTCHA tests to stop the spammers from creating very large numbers of accounts (which would otherwise make account termination a non-issue) from which to spam from... after that there was a crack down on open mail relays and ISPs started trying to block their subscribers from connecting to outside SMTP servers... now spammers use botnets designed for sending spam, effectively moving the burden of stopping spam out of the hands of centralized organizations like ISPs and into the hands of end users whose machines have been compromised and who are least likely to be able to deal with the problem or even be aware of it's existence... if you've never heard of this before, now you've got a brand new reason to prevent malware from compromising your computer - to help keep the spam problem in check...

avoiding spam
neither of these qualify as avoiding spam, however... in order to do that one must address spam at the earliest stage in it's life-cycle, one must stop the spammer from getting one's email address in the first place... think of your email address as being like your home phone number - it's confidential information that you don't hand out to every tom, dick, and harry you happen across...

keeping your real email address secret is probably not the most intuitive thing in the world, especially since so many things require you to give them an email address, but there are services and techniques that can help make it easier... there are also limits to how well the secret can be kept, but as an example i've managed to keep a webmail address i use daily completely spam free (there isn't even anything in the spam folder) for over 2 years simply by being careful and not giving out the address except to those i trust... one other caveat is that you can't make an email address secret if it wasn't a secret before... if your current address is receiving spam then the spammers already have your email address, the address has been compromised and there's nothing you can really do about that - you can't put the genie back in the bottle...

what you can do, with a fresh email address, is use disposable email addresses that forward to that real email address... a number of people are already familiar with the idea of a throw-away email address and often use hotmail or some other free webmail provider to make one but unfortunately that leaves you with no way to know who leaked your address to the spammers so when you need to change addresses (because the current throw-away address has gotten too spammy) you'll have no way to know which organizations to not give the new address to (never mind the fact that you'll have to give a new address to a bunch of organizations)... this is where true disposable email addresses come in - you need to use a different address for each site you give an address to (whether it's ebay, amazon, or your bank) so you can identify which one leaked the email address simply by looking at which email address got leaked and so that you only have to turn off that one address when it starts getting spammed rather than changing addresses and updating a potentially long list of sites with your new address... dedicated disposable email address services make creating multiple addresses easier (certainly easier than creating multiple throw-away email addresses where you have to answer a CAPTCHA test for each one) and managing multiple addresses (ie. turning off the ones that get spammy) easier as well...

different services provide addresses with different properties; some will forward the email sent to the disposable address on to your real address while others might maximize the ease and convenience of creating a new address by allowing you to create one without contacting the disposable email address provider first... beware the combination of these two properties (something spamgourmet.com does), however, because you invariably wind up giving out the information necessary for others to create new addresses that will forward to your real address and you don't want any tom, dick, or harry to be able to do that anymore than you want them to be able to email you directly... instead, use the created-on-the-fly addresses in cases where no sensitive information is going to be sent and/or in cases where you're likely only going to need to check for mail once (because most on-the-fly disposable email address services also don't require a login to check the email - mailinator.com and dodgeit.com work this way), and use forwarding addresses (such as those from sneakemail.com or mailnull.com) for everything else so that you get the benefit of picking up the mail in one place that only you (and your real email provider) have access to...

website feedback
now that takes care of sites that ask you for your email address, what about if you have a website or even a blog like this one? you want to be able to receive feedback from people without being deluged by spam but if you put an email address on the page then software that searches for email addresses on the web will find that address pretty quickly and it will soon be filled with spam... using disposable email addresses on their own doesn't solve this problem...

one thing people like to try is email address obfuscation - where the email address is manipulated in such a way that software that searches for email addresses can't easily recognize it as one... unfortunately this runs into competing requirements - in order to truly prevent software from collecting your email address for the spammer the email address has to not be machine readable, however people expect to be able to click on something and start typing their feedback and that functionality requires that the email address is machine readable... no email address obfuscation method can achieve both requirements so you generally either have to break expected functionality or accept that the email address isn't truly hidden...

a better solution is to use a contact form, specifically one that doesn't contain your email address in it's code... mailnull.com happens to offer this facility, it's what i'm currently using for this site at the time of writing, you can see what it looks like by clicking here... the only major drawback to using a web-based contact form is that people can't send you attachments but considering how troublesome attachments can be from a security standpoint, not providing a way for first time contacts to send them to you doesn't seem like all that big a deal... if you do encounter a scenario where it is a problem, the first time contact could use a file storage solution like dropload.com with their own disposable email address in the To: field and then paste the resulting URL into the web contact form...

additionally, if you not only have your own website but your own domain, you may want to turn off the default/catch all email functionality (where email sent to any non-existent address on that domain is 'caught' and collected for review and possible redirection to relevant parties)... so long as you are providing people with a clear way to directly contact the right individuals within your domain there should be no reason for anyone to send email to non-existent addresses on your domain or firing emails blindly at arbitrary addresses on your domain...

friends and family
as i mentioned before, there are limits to the extent to which you can keep your email address secret and a potentially very big hole in the strategy involves your trusted contacts (be they friends, family, or business contacts)... these are people you can't reasonably be expected to keep your email address a secret from and so may wind up being a source of email address leakage... what can you do?

pretty much what you can do boils down to treating their email addresses with the same care you would treat your own and teaching them to do the same for you (maybe even pointing them here)... that means that you shouldn't give their addresses to websites no matter how cool those websites might happen to be or how interesting you think your friends/family/contacts will find the site (even those greeting card websites that are so popular around the holidays) - instead you should give those sites one of your own disposable email addresses and then forward the resulting email to the person you wanted to share the site with, thus giving them exactly the same information you would have given them if you'd exposed their email address to the website but without actually exposing their email address to the website...

additionally, don't share people's email addresses with other people they don't know... if you're emailing people that don't know each other, put your own email address in the To: field and put the other email addresses in the Bcc: field so that they can't see each other's addresses... if you're forwarding something to people, make sure not to include any of the email addresses that it was previously sent to or from as forwarded emails otherwise tend to build up large numbers of email addresses on a large number of strangers machines - any one of which might get compromised by a piece of malware that harvests email addresses for spammers and other email miscreants and that's something you want to minimize where possible...

anti-spam safe hex
all these things effectively form a set of spam-related safe hex rules... summarized, they are:
  1. treat your email address like a secret
  2. use a different disposable email address for each website you give an address to (so that if you do get spam you can tell who to blame)
  3. use contact forms instead of email addresses on your website
  4. turn off the catch-all email functionality for any domain you might have
  5. don't give your friend's/family's/contact's email address to websites
  6. don't give your friend's/family's/contact's email to people they don't know
  7. try to teach your friends/family/contacts to show your email address the same care that you show theirs

Tuesday, February 28, 2006

user education is working

there is a fairly prevalent opinion in security circles that user education doesn't work... no matter how much you try to teach users, they never learn...

my retort to this is generally along the lines of "ok, give me your name, address, telephone number and credit card information and i'll prove you wrong"... obviously no one is going to give me that information and that proves them wrong - users of credit cards learned not to give that information out to every tom, dick, and harry a long time ago (we know they learned it because it's not knowledge they were born with)...

but sometimes that fails to convince, so here's a personal anecdote... i was out having a meal with some people not too long ago and the conversation briefly turned to email and the woman beside me (whom i had never met before and never coached in any way) said she tends to delete anything with an attachment... she was the first and only person to mention attachments during the brief discussion of email...

we're not talking about a security person or even necessarily a computer person here either - she's a school teacher and she's adopted a behaviour that was unheard of in the general populace 10 or even 5 years ago...

people never stop learning things, and netizens learn to adapt to the threats present in the environment they inhabit - how could they not? staying safe online is a competitive advantage and successful strategies will be discovered and adopted and spread like memes through the computer user population... they don't need to know the internals of how various threats operate or why certain safe-hex behaviours work, only that they do work...

Thursday, January 13, 2005

anti-virus developers, listen up!

take a look here... (Message-ID: wa6dnTcvF_JsK3jcRVn-qA@comcast.com if the link is broken)

this poor user has a virus stuck in his email and he can't figure out which message it is that he needs to delete... folks, do me a favour, when you detect a virus inside what you recognize to be an email envelope could you report not just the virus name and filename but also some kind of identifying information for the email in question (From:, To:, Subject:)?

i mean really - when your product detects a virus in an email database and it can't clean it, without this information you might as well be telling the user "there is a virus somewhere on your computer"... that's just too vague to be useful...