Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #243294 > unrolled thread

Identity Theft

Started byrhkramer@gmail.com
First post2021-12-20 16:40 +0100
Last post2021-12-21 18:40 +0100
Articles 20 on this page of 41 — 22 participants

Back to article view | Back to linux.debian.user


Contents

  Identity Theft rhkramer@gmail.com - 2021-12-20 16:40 +0100
    Re: Identity Theft Nicholas Geovanis <nickgeovanis@gmail.com> - 2021-12-20 17:00 +0100
    Re: Identity Theft John Hasler <john@sugarbit.com> - 2021-12-20 17:20 +0100
      Re: Identity Theft "Jeremy Nicoll" <jn.ml.dbn.25@letterboxes.org> - 2021-12-20 19:10 +0100
        Re: Identity Theft John Hasler <john@sugarbit.com> - 2021-12-20 19:40 +0100
          Re: Identity Theft Nicholas Geovanis <nickgeovanis@gmail.com> - 2021-12-20 19:50 +0100
            Re: Identity Theft Nicholas Geovanis <nickgeovanis@gmail.com> - 2021-12-20 20:00 +0100
          Re: Identity Theft "Jeremy Nicoll" <jn.ml.dbn.25@letterboxes.org> - 2021-12-20 20:10 +0100
            Re: Identity Theft rhkramer@gmail.com - 2021-12-21 03:00 +0100
              Re: Identity Theft John Hasler <john@sugarbit.com> - 2021-12-21 06:00 +0100
              Re: Identity Theft Curt <curty@free.fr> - 2021-12-21 17:00 +0100
                Re: Identity Theft rhkramer@gmail.com - 2021-12-21 18:50 +0100
                  Re: Identity Theft Curt <curty@free.fr> - 2021-12-21 19:50 +0100
                    Re: Identity Theft rhkramer@gmail.com - 2021-12-21 20:10 +0100
    Re: Identity Theft Brian <ad44@cityscape.co.uk> - 2021-12-20 20:30 +0100
      Re: Identity Theft rhkramer@gmail.com - 2021-12-21 03:10 +0100
        Re: Identity Theft Jeremy Ardley <jeremy@ardley.org> - 2021-12-21 03:20 +0100
          Re: Identity Theft local10 <local10@tutanota.com> - 2021-12-21 09:20 +0100
            Re: Identity Theft Kenneth Parker <sea7kenp@gmail.com> - 2021-12-21 13:50 +0100
              Re: Identity Theft Eike Lantzsch ZP6CGE <zp6cge@gmx.net> - 2021-12-21 14:30 +0100
                Re: Identity Theft "tv.debian@googlemail.com" <tv.debian@googlemail.com> - 2021-12-21 14:40 +0100
                  Re: Identity Theft Tim Woodall <debianuser@woodall.me.uk> - 2021-12-21 15:20 +0100
                    Re: Identity Theft Markus Schönhaber <debian-user@list-post.mks-mail.de> - 2021-12-21 16:30 +0100
                    Re: Identity Theft Dan Ritter <dsr@randomstring.org> - 2021-12-21 16:40 +0100
                    Re: Identity Theft The Wanderer <wanderer@fastmail.fm> - 2021-12-21 16:40 +0100
                      Re: Identity Theft Tim Woodall <debianuser@woodall.me.uk> - 2021-12-21 19:20 +0100
                      Re: Identity Theft Celejar <celejar@gmail.com> - 2021-12-21 22:40 +0100
                Re: Identity Theft "tv.debian@googlemail.com" <tv.debian@googlemail.com> - 2021-12-21 14:40 +0100
          Re: Identity Theft rhkramer@gmail.com - 2021-12-21 18:40 +0100
          Re: Identity Theft Andrei POPESCU <andreimpopescu@gmail.com> - 2021-12-25 18:10 +0100
            Re: Identity Theft rhkramer@gmail.com - 2021-12-26 14:40 +0100
              Re: Identity Theft Hans <hans.ullrich@loop.de> - 2021-12-27 20:10 +0100
        Re: Identity Theft Jeremy Ardley <jeremy@ardley.org> - 2021-12-21 03:20 +0100
          Re: vulnerability classifications (was: Re: Identity Theft) Jeremy Ardley <jeremy@ardley.org> - 2021-12-21 03:50 +0100
          Re: Identity Theft Richmond <richmond@criptext.com> - 2021-12-21 16:50 +0100
            Re: Identity Theft harryweaver@tutanota.com - 2021-12-21 21:20 +0100
            Re: Identity Theft "tv.debian@googlemail.com" <tv.debian@googlemail.com> - 2021-12-21 23:30 +0100
              Re: Identity Theft Jeremy Ardley <jeremy@ardley.org> - 2021-12-21 23:50 +0100
              Re: Identity Theft Polyna-Maude Racicot-Summerside <debian@polynamaude.com> - 2021-12-22 00:40 +0100
              Re: Identity Theft Philippe LeCavalier <support@plecavalier.com> - 2021-12-22 16:00 +0100
          Re: Identity Theft rhkramer@gmail.com - 2021-12-21 18:40 +0100

Page 1 of 3  [1] 2 3  Next page →


#243294 — Identity Theft

Fromrhkramer@gmail.com
Date2021-12-20 16:40 +0100
SubjectIdentity Theft
Message-ID<DwsVB-4vI-15@gated-at.bofh.it>
My identity has been stolen, and although it has nothing to do with Debian, 
Linux, or computing (well, in general). I thought it would be educational / 
important to notify everyone I can of what happened.

I did not believe it could happen, but I have convinced myself and have 
reasonable proof of what happened.

My description starts off talking about using a computer, but that has little 
or nothing to do with what happened.

I was on my computer, logged into a financial website, on which I could view 
things like my account number, current balance, and such.

I needed some help, so I looked for a help number on that page.  I found one 
and called it, and got a scammer (although I didn't realize it until too much 
later).

He said he was from the financial website I was dealing with, and asked me to 
"verify" my information before he could answer my questions (or connect me to 
someone else to do that).  On that pretext, he asked (and I answered) a lot of 
questions about my identity -- more than I should have, including things, like 
my mailing address, DOB, SSN (iirc), and, among other things, a credit card 
number and such.  

(Things like my full SSN (instead of just the last 4 digits), a credit card, 
and maybe DOB should have been red flags.  I feel very stupid.)

To get the help I needed he directed me to make another call which was 
furtherance to the scam, he wanted me to say yes to the questions asked on 
that 2nd call in order to place an order for some service (with an initial fee 
and then a monthly fee, probably forever).

Once I realized and was quite certain that I had talked to a scammer, I called 
the same number (on which I got the scammer) again, and this time I got a bona 
fide representative of the financial company (verified by me after some extensive 
conversation).  

Once I was sure I was scammed, I hung up to try to deal with any mitigation of 
the problem that I could do.

Later in the day, I called the same number again, and again got a bona fide 
representative of the financial company during which we did things like lock 
the account.

In between those last two calls, I started calling other companies and such 
(e.g., the company that issued the credit card) to take steps to continue to 
mitigate the problem.  

The credit card company did have a charge on record that was not made by me 
(at least not intentionally) -- they deleted that charge, cancelled the credit 
card, arranged to issue a new one, etc.

Here are some of the "kickers":

   * At first I thought maybe I had misdialed the number the first time, but my 
calls are made over VOIP with Google Voice as the "provider" -- Google Voice 
logs my calls (time, duration, number called or calling) and the log confirmed 
that I dialed the same number all three times.

   * After this happened, I googled for more information, eventually googling 
on the key words "telephone intercept" which did lead to some somewhat useful 
information (some was about legal entities who can be allowed to intercept 
phone calls (e.g., a wiretap)).  The information I found indicated that what 
happened to me is a known thing for cellphones, but I could find nothing to 
indicate that it was a known thing for VOIP calls (nor for landlines).

So, beware.

Note: The only problem that has occurred so far is a fairly small fraudulent 
charge on my credit card, but my information is "out there" so who knows what 
may happen in the future.

I've done (or am in the process of doing) what I think are all the right 
things as far as protecting myself, including things like:

   *  making a report to my local police department and getting an incident 
number (they do not have the capabilities to investigate such a thing, but 
some, maybe all entities like insurance companies insist on having such a 
report in case of doing things like filing a claim

   * reporting it to all the credit rating agencies and freezing my accounts / 
reports (at first, they just put a warning in your credit report, I later found 
that I could freeze the report so no one could even access it -- I can 
unfreeze the freeze if I need to allow some financial institution access to it 
for some reason (and then refreeze it).  (Aside: iirc, one agency will 
maintain the freeze for 7 years, another one does it for 99 years, I will have 
to put a reminder on my calendar to remember to renew at that time ;-)  As a 
more serious aside, at the time I was aware of only 3 credit rating agencies, 
I've since become aware of at least two more which I will investitate and if 
the seem legitimate, I will freeze the reports there as well.)

   * I signed up with one of the companies like LIfeLock (actually, I chose 
Aura), who among other things will monitor the dark web for activity related 
to me.  I have since found that my bank offers a free service to do the same 
thing, so I will be signing up with them.

   * I am changing (and mostly have changed) the username and password on all 
my financial related accounts (I mean things like Paypal and ebay) on which my 
information could be used.  The new names and passwords have nothing in common
with my name or similar information.  (Any security questions now have false 
answers that I keep a record of.)

   * I made a report to the FBI, and may forward the same report (or somehting 
very similar) to the Attorney General of the state I live in.  I made the 
report to the FBI at least partially because I was not aware that such a thing 
could happen on a VOIP phone, and maybe they are / were not aware either.

   * I made a report to identitytheft.gov, but don't think much of that.  This 
event occurred back in mid-October, and I reported it to them rather quickly 
(within the first few days iirc (I have a record somewhere)).  

Now I get a notice from them (identitytheft.gov) every 15 days that, in 
essence, says that if don't update / add to that report within the following 
15 days, they will delete it.  It seems they are more interested in minimizing 
the reporting of such incidents rather than maintaining an accurate historical 
record or actually doing anthing about the problem.  

This is part of what prompted my report to the FBI -- they don't promise to do 
anything about it, but the implication / inference I get is that they will not 
delete the report.  (And they will look at the report and consider taking 
action of some sort, iiuc.)

[toc] | [next] | [standalone]


#243295

FromNicholas Geovanis <nickgeovanis@gmail.com>
Date2021-12-20 17:00 +0100
Message-ID<DwteW-4C9-5@gated-at.bofh.it>
In reply to#243294

[Multipart message — attachments visible in raw view] — view raw

On Mon, Dec 20, 2021 at 9:33 AM <rhkramer@gmail.com> wrote:

> My identity has been stolen, and although it has nothing to do with
> Debian,
> Linux, or computing (well, in general). I thought it would be educational
> /
> important to notify everyone I can of what happened.
>
> ....
> This is part of what prompted my report to the FBI -- they don't promise
> to do
> anything about it, but the implication / inference I get is that they will
> not
> delete the report.  (And they will look at the report and consider taking
> action of some sort, iiuc.)
>

The FBI is not necessarily bound by statute-of-limitation issues as state
prosecutors are.
In Chicago, the FBI lured and shot John Dillinger behind the Biograph
Theater. The seat that
the Lady In Red sat in was refinished in red velvet. And nearly 40 years
later they helped assassinate
the Black Panther leaders Fred Hampton and Mark Clark.

Very sorry about what happened, it's always a concern.

[toc] | [prev] | [next] | [standalone]


#243298

FromJohn Hasler <john@sugarbit.com>
Date2021-12-20 17:20 +0100
Message-ID<Dwtyh-4Y9-1@gated-at.bofh.it>
In reply to#243294
Did you notify Google?  Seems likely that's where the hole is.
-- 
John Hasler 
john@sugarbit.com
Elmwood, WI USA

[toc] | [prev] | [next] | [standalone]


#243299

From"Jeremy Nicoll" <jn.ml.dbn.25@letterboxes.org>
Date2021-12-20 19:10 +0100
Message-ID<DwvgJ-61C-5@gated-at.bofh.it>
In reply to#243298
On Mon, 20 Dec 2021, at 16:12, John Hasler wrote:
> Did you notify Google?  Seems likely that's where the hole is.

How would Google intercept a financial institution's valid phone
number?

-- 
Jeremy Nicoll - my opinions are my own.

[toc] | [prev] | [next] | [standalone]


#243300

FromJohn Hasler <john@sugarbit.com>
Date2021-12-20 19:40 +0100
Message-ID<DwvJL-6aE-1@gated-at.bofh.it>
In reply to#243299
Jeremy Nicoll writes:
> How would Google intercept a financial institution's valid phone
> number?

He was using Google Voice.
-- 
John Hasler 
john@sugarbit.com
Elmwood, WI USA

[toc] | [prev] | [next] | [standalone]


#243301

FromNicholas Geovanis <nickgeovanis@gmail.com>
Date2021-12-20 19:50 +0100
Message-ID<DwvTs-6dY-3@gated-at.bofh.it>
In reply to#243300

[Multipart message — attachments visible in raw view] — view raw

On Mon, Dec 20, 2021 at 12:31 PM John Hasler <john@sugarbit.com> wrote:

> Jeremy Nicoll writes:
> > How would Google intercept a financial institution's valid phone
> > number?
>
> He was using Google Voice.
>

Moreover the vast bulk of the USA's phone traffic outside the local central
office
service area is VoIP over fiber. Long-distance traffic as well.


> John Hasler
> john@sugarbit.com
> Elmwood, WI USA
>
>

[toc] | [prev] | [next] | [standalone]


#243302

FromNicholas Geovanis <nickgeovanis@gmail.com>
Date2021-12-20 20:00 +0100
Message-ID<Dww38-6hf-7@gated-at.bofh.it>
In reply to#243301

[Multipart message — attachments visible in raw view] — view raw

On Mon, Dec 20, 2021 at 12:47 PM Nicholas Geovanis <nickgeovanis@gmail.com>
wrote:

>
> On Mon, Dec 20, 2021 at 12:31 PM John Hasler <john@sugarbit.com> wrote:
>
>> Jeremy Nicoll writes:
>> > How would Google intercept a financial institution's valid phone
>> > number?
>>
>> He was using Google Voice.
>>
>
> Moreover the vast bulk of the USA's phone traffic outside the local
> central office
> service area is VoIP over fiber. Long-distance traffic as well.
>

Of course the same is true of your cellular voice traffic. Once it transits
your nearby cellphone tower
it travels on "someone's" fiber.


>
>
>> John Hasler
>> john@sugarbit.com
>> Elmwood, WI USA
>>
>>

[toc] | [prev] | [next] | [standalone]


#243303

From"Jeremy Nicoll" <jn.ml.dbn.25@letterboxes.org>
Date2021-12-20 20:10 +0100
Message-ID<DwwcN-6zZ-1@gated-at.bofh.it>
In reply to#243300
On Mon, 20 Dec 2021, at 18:30, John Hasler wrote:
> Jeremy Nicoll writes:
>> How would Google intercept a financial institution's valid
>> phone number?
>
> He was using Google Voice.

When the OP "found" a number on screen, to ring, does that 
mean he eg clicked on the display of a number and then some 
software he has connected to a different number?

Or did he use his eyes and read the number off the screen,
then "dial" (presumably in software) that number he saw 
displayed (which later apparently worked properly) and got 
someone else?

-- 
Jeremy Nicoll - my opinions are my own.

[toc] | [prev] | [next] | [standalone]


#243309

Fromrhkramer@gmail.com
Date2021-12-21 03:00 +0100
Message-ID<DwCBz-1J8-3@gated-at.bofh.it>
In reply to#243303
On Monday, December 20, 2021 02:09:13 PM Jeremy Nicoll wrote:
> On Mon, 20 Dec 2021, at 18:30, John Hasler wrote:
> > Jeremy Nicoll writes:
> >> How would Google intercept a financial institution's valid
> >> phone number?
> > 
> > He was using Google Voice.
> 
> When the OP "found" a number on screen, to ring, does that
> mean he eg clicked on the display of a number and then some
> software he has connected to a different number?
> 
> Or did he use his eyes and read the number off the screen,
> then "dial" (presumably in software) that number he saw
> displayed (which later apparently worked properly) and got
> someone else?

I used my eyes to read the number off the screen and then dial my separate 
phone (not attached to a computer (well, other than the ObiHai VOIP device).

[toc] | [prev] | [next] | [standalone]


#243314

FromJohn Hasler <john@sugarbit.com>
Date2021-12-21 06:00 +0100
Message-ID<DwFpL-3tI-1@gated-at.bofh.it>
In reply to#243309
rhkramer writes:
> I used my eyes to read the number off the screen and then dial my
> separate phone (not attached to a computer (well, other than the
> ObiHai VOIP device).

Didn't you also say that you later verified the number by checking the
logs in your Google account?
-- 
John Hasler 
john@sugarbit.com
Elmwood, WI USA

[toc] | [prev] | [next] | [standalone]


#243331

FromCurt <curty@free.fr>
Date2021-12-21 17:00 +0100
Message-ID<DwPIt-1ru-5@gated-at.bofh.it>
In reply to#243309
On 2021-12-21, rhkramer@gmail.com <rhkramer@gmail.com> wrote:
>
> I used my eyes to read the number off the screen and then dial my separate 
> phone (not attached to a computer (well, other than the ObiHai VOIP device).
>
>

I called a major international financial institution the other day with
a telephone number memorized by my cell phone that I've used conceivably
a hundred times previously over the years (I telephone monthly). I call
a specific department in offices located on the East Coast of the United
States. When the other end picked up, I heard a recorded message that
gave me the impression that the Bristol Furniture Company might have
moved in (a female voice spoke in a distinctly English accent about
something unrelated to anything). I was so surprised I forgot exactly
what she said. At any rate, it was neither my financial institutional
nor the phone company.  I found an 877 number on the WWW and finally
reached my party (internal transfers still worked to this specific
line). I asked the employee over the phone what was up; he told me they
were aware of the issue and having "trouble with their phones."

[toc] | [prev] | [next] | [standalone]


#243334

Fromrhkramer@gmail.com
Date2021-12-21 18:50 +0100
Message-ID<DwRqV-2Do-5@gated-at.bofh.it>
In reply to#243331
On Tuesday, December 21, 2021 10:52:56 AM Curt wrote:
> On 2021-12-21, rhkramer@gmail.com <rhkramer@gmail.com> wrote:
> > I used my eyes to read the number off the screen and then dial my
> > separate phone (not attached to a computer (well, other than the ObiHai
> > VOIP device).
> 
> I called a major international financial institution the other day with
> a telephone number memorized by my cell phone that I've used conceivably
> a hundred times previously over the years (I telephone monthly). I call
> a specific department in offices located on the East Coast of the United
> States. When the other end picked up, I heard a recorded message that
> gave me the impression that the Bristol Furniture Company might have
> moved in (a female voice spoke in a distinctly English accent about
> something unrelated to anything). I was so surprised I forgot exactly
> what she said. At any rate, it was neither my financial institutional
> nor the phone company.  I found an 877 number on the WWW and finally
> reached my party (internal transfers still worked to this specific
> line). I asked the employee over the phone what was up; he told me they
> were aware of the issue and having "trouble with their phones."

Ahh, thank you -- maybe some confirmation that I'm not crazy. ;-)

What kind of phone did you use to make the call -- I mean cell phone, POTS, 
VOIP phone, or maybe something else?

[toc] | [prev] | [next] | [standalone]


#243339

FromCurt <curty@free.fr>
Date2021-12-21 19:50 +0100
Message-ID<DwSmZ-3cb-15@gated-at.bofh.it>
In reply to#243334
On 2021-12-21, rhkramer@gmail.com <rhkramer@gmail.com> wrote:
>> 
>> I called a major international financial institution the other day with
>> a telephone number memorized by my cell phone that I've used conceivably
>> a hundred times previously over the years (I telephone monthly). I call
>> a specific department in offices located on the East Coast of the United
>> States. When the other end picked up, I heard a recorded message that
>> gave me the impression that the Bristol Furniture Company might have
>> moved in (a female voice spoke in a distinctly English accent about
>> something unrelated to anything). I was so surprised I forgot exactly
>> what she said. At any rate, it was neither my financial institutional
>> nor the phone company.  I found an 877 number on the WWW and finally
>> reached my party (internal transfers still worked to this specific
>> line). I asked the employee over the phone what was up; he told me they
>> were aware of the issue and having "trouble with their phones."
>
> Ahh, thank you -- maybe some confirmation that I'm not crazy. ;-)
>
> What kind of phone did you use to make the call -- I mean cell phone, POTS, 
> VOIP phone, or maybe something else?
>

It was my cell phone, and after your OP I thought to myself: if a human
being had picked up the other day and told me, as an exceptional
security measure to protect my account, to give him my full SSN number
rather than the usual last four digits, I very well might've done that. 

Anyway, I was sorry to hear about your worries and wish you happy
holidays.

[toc] | [prev] | [next] | [standalone]


#243341

Fromrhkramer@gmail.com
Date2021-12-21 20:10 +0100
Message-ID<DwSGm-3yB-13@gated-at.bofh.it>
In reply to#243339
On Tuesday, December 21, 2021 01:44:51 PM Curt wrote:
> On 2021-12-21, rhkramer@gmail.com <rhkramer@gmail.com> wrote:
> > Ahh, thank you -- maybe some confirmation that I'm not crazy. ;-)
> > 
> > What kind of phone did you use to make the call -- I mean cell phone,
> > POTS, VOIP phone, or maybe something else?
> 
> It was my cell phone, and after your OP I thought to myself: if a human
> being had picked up the other day and told me, as an exceptional
> security measure to protect my account, to give him my full SSN number
> rather than the usual last four digits, I very well might've done that.

Thanks.  I still feel dumb, but...

> Anyway, I was sorry to hear about your worries and wish you happy
> holidays.

And thanks for that, too, and the same to you (and all on debian-user).

[toc] | [prev] | [next] | [standalone]


#243305

FromBrian <ad44@cityscape.co.uk>
Date2021-12-20 20:30 +0100
Message-ID<Dwwwa-6G4-1@gated-at.bofh.it>
In reply to#243294
On Mon 20 Dec 2021 at 10:32:31 -0500, rhkramer@gmail.com wrote:

> My identity has been stolen, and although it has nothing to do with Debian, 
> Linux, or computing (well, in general). I thought it would be educational / 
> important to notify everyone I can of what happened.
> 
> I did not believe it could happen, but I have convinced myself and have 
> reasonable proof of what happened.
> 
> My description starts off talking about using a computer, but that has little 
> or nothing to do with what happened.
> 
> I was on my computer, logged into a financial website, on which I could view 
> things like my account number, current balance, and such.
> 
> I needed some help, so I looked for a help number on that page.  I found one 
> and called it, and got a scammer (although I didn't realize it until too much 
> later).

[...]

May we know the URL of the financial website you contacted and the
help number you phoned.

-- 
Brian.

[toc] | [prev] | [next] | [standalone]


#243310

Fromrhkramer@gmail.com
Date2021-12-21 03:10 +0100
Message-ID<DwCLf-21E-1@gated-at.bofh.it>
In reply to#243305
On Monday, December 20, 2021 02:28:13 PM Brian wrote:
> On Mon 20 Dec 2021 at 10:32:31 -0500, rhkramer@gmail.com wrote:
> > My identity has been stolen, and although it has nothing to do with
> 
> [...]
> 
> May we know the URL of the financial website you contacted and the
> help number you phoned.

The website is troweprice.com, and the phone number is 855/654-5324.

It looks like I didn't record the actual URL that I was on, but I don't think 
you could see that exact page in any case as it was an https page and one that 
showed my account numbers and balances.

[toc] | [prev] | [next] | [standalone]


#243311

FromJeremy Ardley <jeremy@ardley.org>
Date2021-12-21 03:20 +0100
Message-ID<DwCUV-24G-3@gated-at.bofh.it>
In reply to#243310

[Multipart message — attachments visible in raw view] — view raw

On 21/12/21 10:09 am, Jeremy Ardley wrote:s.
> There is a type of attack called cross-site scripting (XSS). It's 
> mostly been eliminated by latest version browsers, but there are 
> always zero-day vulnerabilities.
>
> The effect is that if you are vulnerable and have two tabs open, one 
> to the legitimate site, and one to a bad guy site, the bad guy can 
> alter your trusted site and for instance change a valid link into 
> something malicious, or change a displayed phone number.
>
> More at https://owasp.org/www-community/attacks/xss/
>

You can mitigate XSS by having a single browser that is used solely to 
access high value sites. e.g. if you routinely run Firefox, have a copy 
of Vivaldi that you use to access your banks - one at a time.

-- 
Jeremy

[toc] | [prev] | [next] | [standalone]


#243315

Fromlocal10 <local10@tutanota.com>
Date2021-12-21 09:20 +0100
Message-ID<DwIxj-5A2-1@gated-at.bofh.it>
In reply to#243311
Dec 21, 2021, 02:13 by jeremy@ardley.org:

> You can mitigate XSS by having a single browser that is used solely to access high value sites. e.g. if you routinely run Firefox, have a copy of Vivaldi that you use to access your banks - one at a time.
>


Installing NoScript also may help as it has an option to sanitize cross-site suspicious requests. NoScript also speeds up the browser by disabling all the tracking and spying scripts many sites load nowadays. Just make sure to disable all the garbage it has enabled by default after the installation.

[toc] | [prev] | [next] | [standalone]


#243320

FromKenneth Parker <sea7kenp@gmail.com>
Date2021-12-21 13:50 +0100
Message-ID<DwMKC-8bJ-9@gated-at.bofh.it>
In reply to#243315

[Multipart message — attachments visible in raw view] — view raw

On Tue, Dec 21, 2021, 3:15 AM local10 <local10@tutanota.com> wrote:

> Dec 21, 2021, 02:13 by jeremy@ardley.org:
>
> > You can mitigate XSS by having a single browser that is used solely to
> access high value sites. e.g. if you routinely run Firefox, have a copy of
> Vivaldi that you use to access your banks - one at a time.
> >
>
>
> Installing NoScript also may help as it has an option to sanitize
> cross-site suspicious requests. NoScript also speeds up the browser by
> disabling all the tracking and spying scripts many sites load nowadays.
> Just make sure to disable all the garbage it has enabled by default after
> the installation.
>

+1 on NoScript.  I particularly like the White List capabilities, where you
can allow Scripts by Website, and even only one time.  I only know it to
work with Firefox, at this time.

Kenneth Parker

>

[toc] | [prev] | [next] | [standalone]


#243321

FromEike Lantzsch ZP6CGE <zp6cge@gmx.net>
Date2021-12-21 14:30 +0100
Message-ID<DwNnj-bV-3@gated-at.bofh.it>
In reply to#243320

[Multipart message — attachments visible in raw view] — view raw

On Dienstag, 21. Dezember 2021 09:43:42 -03 Kenneth Parker wrote:
> On Tue, Dec 21, 2021, 3:15 AM local10 <local10@tutanota.com> wrote:
> > Dec 21, 2021, 02:13 by jeremy@ardley.org:
> > > You can mitigate XSS by having a single browser that is used
> > > solely to>
> > access high value sites. e.g. if you routinely run Firefox, have a
> > copy of Vivaldi that you use to access your banks - one at a time.
> >
> >
> >
> > Installing NoScript also may help as it has an option to sanitize
> > cross-site suspicious requests. NoScript also speeds up the browser
> > by disabling all the tracking and spying scripts many sites load
> > nowadays. Just make sure to disable all the garbage it has enabled
> > by default after the installation.
>
> +1 on NoScript.  I particularly like the White List capabilities,
> where you can allow Scripts by Website, and even only one time.  I
> only know it to work with Firefox, at this time.
>
> Kenneth Parker

Is this

*No-Script Suite Lite by AdblockLite[1]*
(this one has a whitelist feature) or
*NoScript Security Suite by Giorgio Maone[2]*
(has a whitelist feature too) or other?

I'm using Privicy Badger among other means
like limiting and redirecting DNS requests. But that does not avoid JS.

Cheers
Eike

--------
[1] https://addons.mozilla.org/en-US/firefox/user/11285580/
[2] https://addons.mozilla.org/en-US/firefox/user/143/

[toc] | [prev] | [next] | [standalone]


Page 1 of 3  [1] 2 3  Next page →

Back to top | Article view | linux.debian.user


csiph-web