Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #243294 > unrolled thread
| Started by | rhkramer@gmail.com |
|---|---|
| First post | 2021-12-20 16:40 +0100 |
| Last post | 2021-12-21 18:40 +0100 |
| Articles | 20 on this page of 41 — 22 participants |
Back to article view | Back to linux.debian.user
Identity Theft rhkramer@gmail.com - 2021-12-20 16:40 +0100
Re: Identity Theft Nicholas Geovanis <nickgeovanis@gmail.com> - 2021-12-20 17:00 +0100
Re: Identity Theft John Hasler <john@sugarbit.com> - 2021-12-20 17:20 +0100
Re: Identity Theft "Jeremy Nicoll" <jn.ml.dbn.25@letterboxes.org> - 2021-12-20 19:10 +0100
Re: Identity Theft John Hasler <john@sugarbit.com> - 2021-12-20 19:40 +0100
Re: Identity Theft Nicholas Geovanis <nickgeovanis@gmail.com> - 2021-12-20 19:50 +0100
Re: Identity Theft Nicholas Geovanis <nickgeovanis@gmail.com> - 2021-12-20 20:00 +0100
Re: Identity Theft "Jeremy Nicoll" <jn.ml.dbn.25@letterboxes.org> - 2021-12-20 20:10 +0100
Re: Identity Theft rhkramer@gmail.com - 2021-12-21 03:00 +0100
Re: Identity Theft John Hasler <john@sugarbit.com> - 2021-12-21 06:00 +0100
Re: Identity Theft Curt <curty@free.fr> - 2021-12-21 17:00 +0100
Re: Identity Theft rhkramer@gmail.com - 2021-12-21 18:50 +0100
Re: Identity Theft Curt <curty@free.fr> - 2021-12-21 19:50 +0100
Re: Identity Theft rhkramer@gmail.com - 2021-12-21 20:10 +0100
Re: Identity Theft Brian <ad44@cityscape.co.uk> - 2021-12-20 20:30 +0100
Re: Identity Theft rhkramer@gmail.com - 2021-12-21 03:10 +0100
Re: Identity Theft Jeremy Ardley <jeremy@ardley.org> - 2021-12-21 03:20 +0100
Re: Identity Theft local10 <local10@tutanota.com> - 2021-12-21 09:20 +0100
Re: Identity Theft Kenneth Parker <sea7kenp@gmail.com> - 2021-12-21 13:50 +0100
Re: Identity Theft Eike Lantzsch ZP6CGE <zp6cge@gmx.net> - 2021-12-21 14:30 +0100
Re: Identity Theft "tv.debian@googlemail.com" <tv.debian@googlemail.com> - 2021-12-21 14:40 +0100
Re: Identity Theft Tim Woodall <debianuser@woodall.me.uk> - 2021-12-21 15:20 +0100
Re: Identity Theft Markus Schönhaber <debian-user@list-post.mks-mail.de> - 2021-12-21 16:30 +0100
Re: Identity Theft Dan Ritter <dsr@randomstring.org> - 2021-12-21 16:40 +0100
Re: Identity Theft The Wanderer <wanderer@fastmail.fm> - 2021-12-21 16:40 +0100
Re: Identity Theft Tim Woodall <debianuser@woodall.me.uk> - 2021-12-21 19:20 +0100
Re: Identity Theft Celejar <celejar@gmail.com> - 2021-12-21 22:40 +0100
Re: Identity Theft "tv.debian@googlemail.com" <tv.debian@googlemail.com> - 2021-12-21 14:40 +0100
Re: Identity Theft rhkramer@gmail.com - 2021-12-21 18:40 +0100
Re: Identity Theft Andrei POPESCU <andreimpopescu@gmail.com> - 2021-12-25 18:10 +0100
Re: Identity Theft rhkramer@gmail.com - 2021-12-26 14:40 +0100
Re: Identity Theft Hans <hans.ullrich@loop.de> - 2021-12-27 20:10 +0100
Re: Identity Theft Jeremy Ardley <jeremy@ardley.org> - 2021-12-21 03:20 +0100
Re: vulnerability classifications (was: Re: Identity Theft) Jeremy Ardley <jeremy@ardley.org> - 2021-12-21 03:50 +0100
Re: Identity Theft Richmond <richmond@criptext.com> - 2021-12-21 16:50 +0100
Re: Identity Theft harryweaver@tutanota.com - 2021-12-21 21:20 +0100
Re: Identity Theft "tv.debian@googlemail.com" <tv.debian@googlemail.com> - 2021-12-21 23:30 +0100
Re: Identity Theft Jeremy Ardley <jeremy@ardley.org> - 2021-12-21 23:50 +0100
Re: Identity Theft Polyna-Maude Racicot-Summerside <debian@polynamaude.com> - 2021-12-22 00:40 +0100
Re: Identity Theft Philippe LeCavalier <support@plecavalier.com> - 2021-12-22 16:00 +0100
Re: Identity Theft rhkramer@gmail.com - 2021-12-21 18:40 +0100
Page 1 of 3 [1] 2 3 Next page →
| From | rhkramer@gmail.com |
|---|---|
| Date | 2021-12-20 16:40 +0100 |
| Subject | Identity Theft |
| Message-ID | <DwsVB-4vI-15@gated-at.bofh.it> |
My identity has been stolen, and although it has nothing to do with Debian, Linux, or computing (well, in general). I thought it would be educational / important to notify everyone I can of what happened. I did not believe it could happen, but I have convinced myself and have reasonable proof of what happened. My description starts off talking about using a computer, but that has little or nothing to do with what happened. I was on my computer, logged into a financial website, on which I could view things like my account number, current balance, and such. I needed some help, so I looked for a help number on that page. I found one and called it, and got a scammer (although I didn't realize it until too much later). He said he was from the financial website I was dealing with, and asked me to "verify" my information before he could answer my questions (or connect me to someone else to do that). On that pretext, he asked (and I answered) a lot of questions about my identity -- more than I should have, including things, like my mailing address, DOB, SSN (iirc), and, among other things, a credit card number and such. (Things like my full SSN (instead of just the last 4 digits), a credit card, and maybe DOB should have been red flags. I feel very stupid.) To get the help I needed he directed me to make another call which was furtherance to the scam, he wanted me to say yes to the questions asked on that 2nd call in order to place an order for some service (with an initial fee and then a monthly fee, probably forever). Once I realized and was quite certain that I had talked to a scammer, I called the same number (on which I got the scammer) again, and this time I got a bona fide representative of the financial company (verified by me after some extensive conversation). Once I was sure I was scammed, I hung up to try to deal with any mitigation of the problem that I could do. Later in the day, I called the same number again, and again got a bona fide representative of the financial company during which we did things like lock the account. In between those last two calls, I started calling other companies and such (e.g., the company that issued the credit card) to take steps to continue to mitigate the problem. The credit card company did have a charge on record that was not made by me (at least not intentionally) -- they deleted that charge, cancelled the credit card, arranged to issue a new one, etc. Here are some of the "kickers": * At first I thought maybe I had misdialed the number the first time, but my calls are made over VOIP with Google Voice as the "provider" -- Google Voice logs my calls (time, duration, number called or calling) and the log confirmed that I dialed the same number all three times. * After this happened, I googled for more information, eventually googling on the key words "telephone intercept" which did lead to some somewhat useful information (some was about legal entities who can be allowed to intercept phone calls (e.g., a wiretap)). The information I found indicated that what happened to me is a known thing for cellphones, but I could find nothing to indicate that it was a known thing for VOIP calls (nor for landlines). So, beware. Note: The only problem that has occurred so far is a fairly small fraudulent charge on my credit card, but my information is "out there" so who knows what may happen in the future. I've done (or am in the process of doing) what I think are all the right things as far as protecting myself, including things like: * making a report to my local police department and getting an incident number (they do not have the capabilities to investigate such a thing, but some, maybe all entities like insurance companies insist on having such a report in case of doing things like filing a claim * reporting it to all the credit rating agencies and freezing my accounts / reports (at first, they just put a warning in your credit report, I later found that I could freeze the report so no one could even access it -- I can unfreeze the freeze if I need to allow some financial institution access to it for some reason (and then refreeze it). (Aside: iirc, one agency will maintain the freeze for 7 years, another one does it for 99 years, I will have to put a reminder on my calendar to remember to renew at that time ;-) As a more serious aside, at the time I was aware of only 3 credit rating agencies, I've since become aware of at least two more which I will investitate and if the seem legitimate, I will freeze the reports there as well.) * I signed up with one of the companies like LIfeLock (actually, I chose Aura), who among other things will monitor the dark web for activity related to me. I have since found that my bank offers a free service to do the same thing, so I will be signing up with them. * I am changing (and mostly have changed) the username and password on all my financial related accounts (I mean things like Paypal and ebay) on which my information could be used. The new names and passwords have nothing in common with my name or similar information. (Any security questions now have false answers that I keep a record of.) * I made a report to the FBI, and may forward the same report (or somehting very similar) to the Attorney General of the state I live in. I made the report to the FBI at least partially because I was not aware that such a thing could happen on a VOIP phone, and maybe they are / were not aware either. * I made a report to identitytheft.gov, but don't think much of that. This event occurred back in mid-October, and I reported it to them rather quickly (within the first few days iirc (I have a record somewhere)). Now I get a notice from them (identitytheft.gov) every 15 days that, in essence, says that if don't update / add to that report within the following 15 days, they will delete it. It seems they are more interested in minimizing the reporting of such incidents rather than maintaining an accurate historical record or actually doing anthing about the problem. This is part of what prompted my report to the FBI -- they don't promise to do anything about it, but the implication / inference I get is that they will not delete the report. (And they will look at the report and consider taking action of some sort, iiuc.)
[toc] | [next] | [standalone]
| From | Nicholas Geovanis <nickgeovanis@gmail.com> |
|---|---|
| Date | 2021-12-20 17:00 +0100 |
| Message-ID | <DwteW-4C9-5@gated-at.bofh.it> |
| In reply to | #243294 |
[Multipart message — attachments visible in raw view] — view raw
On Mon, Dec 20, 2021 at 9:33 AM <rhkramer@gmail.com> wrote: > My identity has been stolen, and although it has nothing to do with > Debian, > Linux, or computing (well, in general). I thought it would be educational > / > important to notify everyone I can of what happened. > > .... > This is part of what prompted my report to the FBI -- they don't promise > to do > anything about it, but the implication / inference I get is that they will > not > delete the report. (And they will look at the report and consider taking > action of some sort, iiuc.) > The FBI is not necessarily bound by statute-of-limitation issues as state prosecutors are. In Chicago, the FBI lured and shot John Dillinger behind the Biograph Theater. The seat that the Lady In Red sat in was refinished in red velvet. And nearly 40 years later they helped assassinate the Black Panther leaders Fred Hampton and Mark Clark. Very sorry about what happened, it's always a concern.
[toc] | [prev] | [next] | [standalone]
| From | John Hasler <john@sugarbit.com> |
|---|---|
| Date | 2021-12-20 17:20 +0100 |
| Message-ID | <Dwtyh-4Y9-1@gated-at.bofh.it> |
| In reply to | #243294 |
Did you notify Google? Seems likely that's where the hole is. -- John Hasler john@sugarbit.com Elmwood, WI USA
[toc] | [prev] | [next] | [standalone]
| From | "Jeremy Nicoll" <jn.ml.dbn.25@letterboxes.org> |
|---|---|
| Date | 2021-12-20 19:10 +0100 |
| Message-ID | <DwvgJ-61C-5@gated-at.bofh.it> |
| In reply to | #243298 |
On Mon, 20 Dec 2021, at 16:12, John Hasler wrote: > Did you notify Google? Seems likely that's where the hole is. How would Google intercept a financial institution's valid phone number? -- Jeremy Nicoll - my opinions are my own.
[toc] | [prev] | [next] | [standalone]
| From | John Hasler <john@sugarbit.com> |
|---|---|
| Date | 2021-12-20 19:40 +0100 |
| Message-ID | <DwvJL-6aE-1@gated-at.bofh.it> |
| In reply to | #243299 |
Jeremy Nicoll writes: > How would Google intercept a financial institution's valid phone > number? He was using Google Voice. -- John Hasler john@sugarbit.com Elmwood, WI USA
[toc] | [prev] | [next] | [standalone]
| From | Nicholas Geovanis <nickgeovanis@gmail.com> |
|---|---|
| Date | 2021-12-20 19:50 +0100 |
| Message-ID | <DwvTs-6dY-3@gated-at.bofh.it> |
| In reply to | #243300 |
[Multipart message — attachments visible in raw view] — view raw
On Mon, Dec 20, 2021 at 12:31 PM John Hasler <john@sugarbit.com> wrote: > Jeremy Nicoll writes: > > How would Google intercept a financial institution's valid phone > > number? > > He was using Google Voice. > Moreover the vast bulk of the USA's phone traffic outside the local central office service area is VoIP over fiber. Long-distance traffic as well. > John Hasler > john@sugarbit.com > Elmwood, WI USA > >
[toc] | [prev] | [next] | [standalone]
| From | Nicholas Geovanis <nickgeovanis@gmail.com> |
|---|---|
| Date | 2021-12-20 20:00 +0100 |
| Message-ID | <Dww38-6hf-7@gated-at.bofh.it> |
| In reply to | #243301 |
[Multipart message — attachments visible in raw view] — view raw
On Mon, Dec 20, 2021 at 12:47 PM Nicholas Geovanis <nickgeovanis@gmail.com> wrote: > > On Mon, Dec 20, 2021 at 12:31 PM John Hasler <john@sugarbit.com> wrote: > >> Jeremy Nicoll writes: >> > How would Google intercept a financial institution's valid phone >> > number? >> >> He was using Google Voice. >> > > Moreover the vast bulk of the USA's phone traffic outside the local > central office > service area is VoIP over fiber. Long-distance traffic as well. > Of course the same is true of your cellular voice traffic. Once it transits your nearby cellphone tower it travels on "someone's" fiber. > > >> John Hasler >> john@sugarbit.com >> Elmwood, WI USA >> >>
[toc] | [prev] | [next] | [standalone]
| From | "Jeremy Nicoll" <jn.ml.dbn.25@letterboxes.org> |
|---|---|
| Date | 2021-12-20 20:10 +0100 |
| Message-ID | <DwwcN-6zZ-1@gated-at.bofh.it> |
| In reply to | #243300 |
On Mon, 20 Dec 2021, at 18:30, John Hasler wrote: > Jeremy Nicoll writes: >> How would Google intercept a financial institution's valid >> phone number? > > He was using Google Voice. When the OP "found" a number on screen, to ring, does that mean he eg clicked on the display of a number and then some software he has connected to a different number? Or did he use his eyes and read the number off the screen, then "dial" (presumably in software) that number he saw displayed (which later apparently worked properly) and got someone else? -- Jeremy Nicoll - my opinions are my own.
[toc] | [prev] | [next] | [standalone]
| From | rhkramer@gmail.com |
|---|---|
| Date | 2021-12-21 03:00 +0100 |
| Message-ID | <DwCBz-1J8-3@gated-at.bofh.it> |
| In reply to | #243303 |
On Monday, December 20, 2021 02:09:13 PM Jeremy Nicoll wrote: > On Mon, 20 Dec 2021, at 18:30, John Hasler wrote: > > Jeremy Nicoll writes: > >> How would Google intercept a financial institution's valid > >> phone number? > > > > He was using Google Voice. > > When the OP "found" a number on screen, to ring, does that > mean he eg clicked on the display of a number and then some > software he has connected to a different number? > > Or did he use his eyes and read the number off the screen, > then "dial" (presumably in software) that number he saw > displayed (which later apparently worked properly) and got > someone else? I used my eyes to read the number off the screen and then dial my separate phone (not attached to a computer (well, other than the ObiHai VOIP device).
[toc] | [prev] | [next] | [standalone]
| From | John Hasler <john@sugarbit.com> |
|---|---|
| Date | 2021-12-21 06:00 +0100 |
| Message-ID | <DwFpL-3tI-1@gated-at.bofh.it> |
| In reply to | #243309 |
rhkramer writes: > I used my eyes to read the number off the screen and then dial my > separate phone (not attached to a computer (well, other than the > ObiHai VOIP device). Didn't you also say that you later verified the number by checking the logs in your Google account? -- John Hasler john@sugarbit.com Elmwood, WI USA
[toc] | [prev] | [next] | [standalone]
| From | Curt <curty@free.fr> |
|---|---|
| Date | 2021-12-21 17:00 +0100 |
| Message-ID | <DwPIt-1ru-5@gated-at.bofh.it> |
| In reply to | #243309 |
On 2021-12-21, rhkramer@gmail.com <rhkramer@gmail.com> wrote: > > I used my eyes to read the number off the screen and then dial my separate > phone (not attached to a computer (well, other than the ObiHai VOIP device). > > I called a major international financial institution the other day with a telephone number memorized by my cell phone that I've used conceivably a hundred times previously over the years (I telephone monthly). I call a specific department in offices located on the East Coast of the United States. When the other end picked up, I heard a recorded message that gave me the impression that the Bristol Furniture Company might have moved in (a female voice spoke in a distinctly English accent about something unrelated to anything). I was so surprised I forgot exactly what she said. At any rate, it was neither my financial institutional nor the phone company. I found an 877 number on the WWW and finally reached my party (internal transfers still worked to this specific line). I asked the employee over the phone what was up; he told me they were aware of the issue and having "trouble with their phones."
[toc] | [prev] | [next] | [standalone]
| From | rhkramer@gmail.com |
|---|---|
| Date | 2021-12-21 18:50 +0100 |
| Message-ID | <DwRqV-2Do-5@gated-at.bofh.it> |
| In reply to | #243331 |
On Tuesday, December 21, 2021 10:52:56 AM Curt wrote: > On 2021-12-21, rhkramer@gmail.com <rhkramer@gmail.com> wrote: > > I used my eyes to read the number off the screen and then dial my > > separate phone (not attached to a computer (well, other than the ObiHai > > VOIP device). > > I called a major international financial institution the other day with > a telephone number memorized by my cell phone that I've used conceivably > a hundred times previously over the years (I telephone monthly). I call > a specific department in offices located on the East Coast of the United > States. When the other end picked up, I heard a recorded message that > gave me the impression that the Bristol Furniture Company might have > moved in (a female voice spoke in a distinctly English accent about > something unrelated to anything). I was so surprised I forgot exactly > what she said. At any rate, it was neither my financial institutional > nor the phone company. I found an 877 number on the WWW and finally > reached my party (internal transfers still worked to this specific > line). I asked the employee over the phone what was up; he told me they > were aware of the issue and having "trouble with their phones." Ahh, thank you -- maybe some confirmation that I'm not crazy. ;-) What kind of phone did you use to make the call -- I mean cell phone, POTS, VOIP phone, or maybe something else?
[toc] | [prev] | [next] | [standalone]
| From | Curt <curty@free.fr> |
|---|---|
| Date | 2021-12-21 19:50 +0100 |
| Message-ID | <DwSmZ-3cb-15@gated-at.bofh.it> |
| In reply to | #243334 |
On 2021-12-21, rhkramer@gmail.com <rhkramer@gmail.com> wrote: >> >> I called a major international financial institution the other day with >> a telephone number memorized by my cell phone that I've used conceivably >> a hundred times previously over the years (I telephone monthly). I call >> a specific department in offices located on the East Coast of the United >> States. When the other end picked up, I heard a recorded message that >> gave me the impression that the Bristol Furniture Company might have >> moved in (a female voice spoke in a distinctly English accent about >> something unrelated to anything). I was so surprised I forgot exactly >> what she said. At any rate, it was neither my financial institutional >> nor the phone company. I found an 877 number on the WWW and finally >> reached my party (internal transfers still worked to this specific >> line). I asked the employee over the phone what was up; he told me they >> were aware of the issue and having "trouble with their phones." > > Ahh, thank you -- maybe some confirmation that I'm not crazy. ;-) > > What kind of phone did you use to make the call -- I mean cell phone, POTS, > VOIP phone, or maybe something else? > It was my cell phone, and after your OP I thought to myself: if a human being had picked up the other day and told me, as an exceptional security measure to protect my account, to give him my full SSN number rather than the usual last four digits, I very well might've done that. Anyway, I was sorry to hear about your worries and wish you happy holidays.
[toc] | [prev] | [next] | [standalone]
| From | rhkramer@gmail.com |
|---|---|
| Date | 2021-12-21 20:10 +0100 |
| Message-ID | <DwSGm-3yB-13@gated-at.bofh.it> |
| In reply to | #243339 |
On Tuesday, December 21, 2021 01:44:51 PM Curt wrote: > On 2021-12-21, rhkramer@gmail.com <rhkramer@gmail.com> wrote: > > Ahh, thank you -- maybe some confirmation that I'm not crazy. ;-) > > > > What kind of phone did you use to make the call -- I mean cell phone, > > POTS, VOIP phone, or maybe something else? > > It was my cell phone, and after your OP I thought to myself: if a human > being had picked up the other day and told me, as an exceptional > security measure to protect my account, to give him my full SSN number > rather than the usual last four digits, I very well might've done that. Thanks. I still feel dumb, but... > Anyway, I was sorry to hear about your worries and wish you happy > holidays. And thanks for that, too, and the same to you (and all on debian-user).
[toc] | [prev] | [next] | [standalone]
| From | Brian <ad44@cityscape.co.uk> |
|---|---|
| Date | 2021-12-20 20:30 +0100 |
| Message-ID | <Dwwwa-6G4-1@gated-at.bofh.it> |
| In reply to | #243294 |
On Mon 20 Dec 2021 at 10:32:31 -0500, rhkramer@gmail.com wrote: > My identity has been stolen, and although it has nothing to do with Debian, > Linux, or computing (well, in general). I thought it would be educational / > important to notify everyone I can of what happened. > > I did not believe it could happen, but I have convinced myself and have > reasonable proof of what happened. > > My description starts off talking about using a computer, but that has little > or nothing to do with what happened. > > I was on my computer, logged into a financial website, on which I could view > things like my account number, current balance, and such. > > I needed some help, so I looked for a help number on that page. I found one > and called it, and got a scammer (although I didn't realize it until too much > later). [...] May we know the URL of the financial website you contacted and the help number you phoned. -- Brian.
[toc] | [prev] | [next] | [standalone]
| From | rhkramer@gmail.com |
|---|---|
| Date | 2021-12-21 03:10 +0100 |
| Message-ID | <DwCLf-21E-1@gated-at.bofh.it> |
| In reply to | #243305 |
On Monday, December 20, 2021 02:28:13 PM Brian wrote: > On Mon 20 Dec 2021 at 10:32:31 -0500, rhkramer@gmail.com wrote: > > My identity has been stolen, and although it has nothing to do with > > [...] > > May we know the URL of the financial website you contacted and the > help number you phoned. The website is troweprice.com, and the phone number is 855/654-5324. It looks like I didn't record the actual URL that I was on, but I don't think you could see that exact page in any case as it was an https page and one that showed my account numbers and balances.
[toc] | [prev] | [next] | [standalone]
| From | Jeremy Ardley <jeremy@ardley.org> |
|---|---|
| Date | 2021-12-21 03:20 +0100 |
| Message-ID | <DwCUV-24G-3@gated-at.bofh.it> |
| In reply to | #243310 |
[Multipart message — attachments visible in raw view] — view raw
On 21/12/21 10:09 am, Jeremy Ardley wrote:s. > There is a type of attack called cross-site scripting (XSS). It's > mostly been eliminated by latest version browsers, but there are > always zero-day vulnerabilities. > > The effect is that if you are vulnerable and have two tabs open, one > to the legitimate site, and one to a bad guy site, the bad guy can > alter your trusted site and for instance change a valid link into > something malicious, or change a displayed phone number. > > More at https://owasp.org/www-community/attacks/xss/ > You can mitigate XSS by having a single browser that is used solely to access high value sites. e.g. if you routinely run Firefox, have a copy of Vivaldi that you use to access your banks - one at a time. -- Jeremy
[toc] | [prev] | [next] | [standalone]
| From | local10 <local10@tutanota.com> |
|---|---|
| Date | 2021-12-21 09:20 +0100 |
| Message-ID | <DwIxj-5A2-1@gated-at.bofh.it> |
| In reply to | #243311 |
Dec 21, 2021, 02:13 by jeremy@ardley.org: > You can mitigate XSS by having a single browser that is used solely to access high value sites. e.g. if you routinely run Firefox, have a copy of Vivaldi that you use to access your banks - one at a time. > Installing NoScript also may help as it has an option to sanitize cross-site suspicious requests. NoScript also speeds up the browser by disabling all the tracking and spying scripts many sites load nowadays. Just make sure to disable all the garbage it has enabled by default after the installation.
[toc] | [prev] | [next] | [standalone]
| From | Kenneth Parker <sea7kenp@gmail.com> |
|---|---|
| Date | 2021-12-21 13:50 +0100 |
| Message-ID | <DwMKC-8bJ-9@gated-at.bofh.it> |
| In reply to | #243315 |
[Multipart message — attachments visible in raw view] — view raw
On Tue, Dec 21, 2021, 3:15 AM local10 <local10@tutanota.com> wrote: > Dec 21, 2021, 02:13 by jeremy@ardley.org: > > > You can mitigate XSS by having a single browser that is used solely to > access high value sites. e.g. if you routinely run Firefox, have a copy of > Vivaldi that you use to access your banks - one at a time. > > > > > Installing NoScript also may help as it has an option to sanitize > cross-site suspicious requests. NoScript also speeds up the browser by > disabling all the tracking and spying scripts many sites load nowadays. > Just make sure to disable all the garbage it has enabled by default after > the installation. > +1 on NoScript. I particularly like the White List capabilities, where you can allow Scripts by Website, and even only one time. I only know it to work with Firefox, at this time. Kenneth Parker >
[toc] | [prev] | [next] | [standalone]
| From | Eike Lantzsch ZP6CGE <zp6cge@gmx.net> |
|---|---|
| Date | 2021-12-21 14:30 +0100 |
| Message-ID | <DwNnj-bV-3@gated-at.bofh.it> |
| In reply to | #243320 |
[Multipart message — attachments visible in raw view] — view raw
On Dienstag, 21. Dezember 2021 09:43:42 -03 Kenneth Parker wrote: > On Tue, Dec 21, 2021, 3:15 AM local10 <local10@tutanota.com> wrote: > > Dec 21, 2021, 02:13 by jeremy@ardley.org: > > > You can mitigate XSS by having a single browser that is used > > > solely to> > > access high value sites. e.g. if you routinely run Firefox, have a > > copy of Vivaldi that you use to access your banks - one at a time. > > > > > > > > Installing NoScript also may help as it has an option to sanitize > > cross-site suspicious requests. NoScript also speeds up the browser > > by disabling all the tracking and spying scripts many sites load > > nowadays. Just make sure to disable all the garbage it has enabled > > by default after the installation. > > +1 on NoScript. I particularly like the White List capabilities, > where you can allow Scripts by Website, and even only one time. I > only know it to work with Firefox, at this time. > > Kenneth Parker Is this *No-Script Suite Lite by AdblockLite[1]* (this one has a whitelist feature) or *NoScript Security Suite by Giorgio Maone[2]* (has a whitelist feature too) or other? I'm using Privicy Badger among other means like limiting and redirecting DNS requests. But that does not avoid JS. Cheers Eike -------- [1] https://addons.mozilla.org/en-US/firefox/user/11285580/ [2] https://addons.mozilla.org/en-US/firefox/user/143/
[toc] | [prev] | [next] | [standalone]
Page 1 of 3 [1] 2 3 Next page →
Back to top | Article view | linux.debian.user
csiph-web