My Pages

Showing posts with label spam. Show all posts
Showing posts with label spam. Show all posts

Monday, 15 February 2021

On comments without root

A dump of verbiage

Looking through the hundreds of comments awaiting moderation on my blog, I could not help but wonder why some people bother. There are scores that are just hackneyed and trite never venturing to platitude, effusive with mock praise and uninteresting, a cat could have walked one their keyboard for a minute and produced commendable prose.

Others are completely off-topic bearing no relationship to the blog, adjacent blogs or my blog in general, whether visitors in a heightened state of psychoactive abandon are attracted to my blog, I cannot say, but by what has been written, I might just be on the money.

Spam you can’t can

However, more annoying are those who insert links to plug their businesses in my comments section, it is spam, no more no less. I have no advertisements on my blog, I make no money off it, it is a personal space that is open to readership whilst managed by me. I cannot edit the comments and I doubt I will grant permission if asked, to publish adverts on my blog.

I do write reviews and that is a different activity because it is one of personal experience with objective or subjective viewpoints and let us agree it is authentic.

Thanks for coming

Now, feedback on my blogs is welcome, I encourage it within the bounds of courtesy, respect, context, and contributions that extend the debate. As abuse and expletives are not my mode of expression such aggressive deployment of language will hardly be entertained or countenanced. One owns the prerogative to publish or delete, a rejoinder might well appear on you blog with a link to mine, if you want more control of the narrative.

I provide Comment advisory and guidelines to help towards making your contribution meaningful and worthy of publishing to my audience. Thank you for engaging and I will try my best to engage too.

Tuesday, 5 April 2011

Social Engineering: That Epsilon email data breach

Another data breach and scare

News that Epsilon [1], an email marketing service provider had suffered a security breach that involved the loss of data has been received with some angst and the analysis of security of data on corporate systems.

This firm handles the email marketing for quite a number of big names in the US like Target, Chase, Marriott & Tivo referring to the names that came up in the opinion pieces that form my source for this blog.

It is interesting to note that the first article dealt with the matter of Outsourcing email [2]; this is just a matter of responsibility, the data is vulnerable no matter whose system it is on but where the data is hosted in-house, after the fire-fighting and damage control there might be a person or department to take the blame with the possible rolling of heads in mock absolution for faults.

This is a big deal

The second article dwells on the value of an email address [3] but only in reference to the service provider from reputation, through information management to the possible loss of custom – the figures are high but they hardly address the more important point which is how it affects the customer.

Another news story suggests Epsilon sends out [4] over 40 billion emails annually from over 2,500 clients which include 7 of the Fortune 10 companies. This is big business at first and quite a large customer base too.

You’ve got mea culpa mail

In one instance the writer had received an apologetic email from Epsilon and seemingly exculpatory emails from three other organization which whom he had registered for some service that used his email as part of the transactional and interaction process.

Interestingly, even one comment suggested the receipt of emails from organisation they thought they had already cancelled subscriptions to, in effect, cancelling a subscription only stops emails from going out, it does not expunge the host database of the email information.

Where it gets worrisome is that what was exposed to unauthorised access was email addresses and/or customer names.

Proof you exist

There are a number of inalienable facts that derive from this piece of information, the fact that it was on Epsilon systems means there is a likelihood that the addresses are active and where a customer name is attached, it serves enough as a uniqueness identifier just for a spammer to use or purvey and even conduct more extensive searches that can match that information to home addresses and other personal information that could be found online.

This is the equivalent of looking through a telephone directory which probably contains current and valid information to use a service or contact a person.

Over a year ago, my phone number strayed into the hands of scammers in Ghana, one of whom called me at an unholy hour, the moment I answered the call, I had validated the working order of that number and for 5 consecutive days I received calls from different people in Ghana and it was my ignoring the subsequent calls that fed back into that network that it was useless calling me.

Another analogy is the having an email address with a customer name is the equivalent of knocking on a door and knowing there is an occupant of that premises that offers the opportunity for the criminal to watch out for when they might burgle the premises.

Getting familiar

Beyond that, having a customer name allows for the spammer to send friendlier and more familiar type communication that can break down the usual resistance to spam email.

Where the customer has different email addresses with particular ones being used for trusted Internet activity, receiving spam emails on those addresses can be rather irksome.

By the time the customer has been irredeemably spammed even important emails would have ended up in the bin whilst ameliorating acts of changing email addresses can be fraught with unnecessary administrative problems of reviewing all subscriptions, informing all contacts and many other troublesome issues.

The cost to the customer is high and I have in certain instances had to discontinue the use of a service provider just because they were doing nothing to stem the flow of spam.

Remediation is fraught

However, as it stands, there is really no compensation for the inconvenience of the expected deluge of spam from a new set of spam addresses and who because they now have customer names could suggest they have established a relationship with the victims of these criminal activities.

I am saddened that of most the computer press I have read about this data breach have not really addressed this angle of the matter, it is the multitude of customers that give the companies the business they have, they seem to have been forgotten in their face-saving and damage-limitation quests.

Taking care

Customers should beware of phishing email, check that URLs in emails are really from where they purport to come from, never send any personal details to anyone seeking such information via email, at least not before verifying that with the company via a telephone call.

You should never have to share your security number, home address, credit card numbers or personal identity numbers with anyone either by email or on the phone, if in doubt, ignore the email especially if it reads like a threat and if on a phone call, excuse yourself from the call, recompose yourself and call at another time – the taker of your call should never fill you with additional angst and anxiety.

Sources

[1] Epsilon is a subsidiary of Alliance Data - Wikipedia, the free encyclopedia

[2] Outsourcing email: Do the benefits outweigh the risks? | ZDNet

[3] Epsilon data breach: What's the value of an email address? | ZDNet

[4] Massive Breach at Epsilon Compromises Customer Lists of Major Brands | SecurityWeek.Com

Monday, 13 September 2010

Social Engineering: Appealing to my vanity

So much spam

The process of moving my blog to http://akinblog.nl has been slow and fraught but it is beginning to gain some traffic and recognition. Hopefully, with time it would become the primary reference point of searches that have usually gone to http://akin.blog-city.com

One thing I have noticed about hosting my new blog on Google’s Blogger facility is the amount of spam that comes round most of which seems to appeal to different aspects of one’s masculine vanity.

One good look in the folder of spam messages captured on my gmail email account shows about 75% of the emails recommending some augmentation to the male protuberance either for length or stamina to be able to as it were satisfy your partner.

Appealing to my physical vanity

Indeed erectile dysfunction can be an issue when pleasure is truncated by the premature incidence of orgasm just when you thought you could go on for longer, it probably dwells on many a mind and it could be frustrating.

For those who are otherwise blessed the receipt of such odious and unflattering emails is annoying but the spam filters seem to be putting in their hours.

On the blog front however, each comment logged each particular blog creates a notification which does not end up in the spam folder and incurs the additional work of management even though the blog commenting system might well recognise the comment as spam.

Appealing to my mental vanity

That is just one side of appealing to ones vanity, the other part came in a comment I received on my blog this morning.

As follows: Anonymous has left a new comment on your post "Thought Picnic: Vulnerability offering opportunity...":

I usually do not leave a comment, but the ideas really rocks, also I have a few questions like to ask, what's your contact details?

-Johnson

Anonymous who has signed off as Johnson probably does not have a Google blog, nor does he (if a first name) or her (if a surname) have a website they are willing to publish as part of receiving feedback for the comments they have left.

Comments appealing to vanity

There is probably nothing to read from the comment but the basic compliment until one has a second or third reading and then it begins to matter a lot more than it seems. This is a generic comment can be left on any and every blog with one singular aim in mind.

Indeed, one of the signs of having a following comes from people commenting on your blogs and this supposed fan rarely leaves comments but now decides to do so in the quest for something other than the views expressed in the blog.

Given that the person does offer the passing opinion masquerading as praise that “the ideas really rocks”, I am really confused about the urban language with the apparent number confusion as to the idea and the context that the person is referring to.

Having appealed to my vanity with the notion of my rocking ideas, the person has a few questions to ask, fair enough and somehow expects me with the additional request to publish my contact details in response.

One can only wonder what questions that person has to ask that cannot be put in the comments or forwarded as an email, because those details are not that difficult to get if the person does try.

Generic comments as social engineering

Between you are me, this is another classic case of social engineering; having appealed to my vanity and flattered me in some way, just as the title of the blog goes, it has provided a window of vulnerability offering the opportunity to request my contact details which I am supposed to foolishly volunteer to some non-descript stranger to ask personal questions.

It was a good try but this will not work with me and it really should not work on anyone else too, if anyone wants to engage you on matters so personal the need for full-disclosure is paramount and it should be initiated by the enquirer and not by you.

Otherwise, this is just another case of Johnson probably leaving a similar generic comment on as many blogs as he/she can to harvest details for some nefarious activity beyond which the victim has little control.

Beware of the flattery that leaves you vulnerable to volunteering information you should best keep for your protection and safety.

Monday, 11 December 2006

The Naija Bruises of Reply All

Object to the subject

Never has an objective assessment of a situation garnered outrageous subjectivity than when I have had the fortune of expressing an opinion amongst fellow Nigerians.

It would appear the issues of basic netiquette are beyond the comprehension of seemingly knowledgeable people, I wanted out faster than a bullet leaves a gun.

I had written about the use of the Reply All button in a forum where I have had the unfortunate circumstance to find reluctant membership, in which I also offered possible alternatives to accommodate that type of content.

The forum coordinator had announced that a few new persons had joined the community, that was fine by me, but before the cock could crow the first time, 10 emails had arrived in my mailbox, people echoing the welcome greetings to everyone rather than the just the particular new entrants.

True African SPAM

I must have missed something in my upbringing, as I learnt later on; it is in the true African tradition to receive unsolicited email which in the West would be called SPAM.

It was impossible to keep the focus on that issue, by the time I knew it; I was mired in sycophantic acquiescence, dribbled over with the spittle of contrived disappointment and dispossessed of my Nigerian heritage because I dared to challenge an unacceptable convention.

Then, someone said I was bringing Nigeria into disrepute, I had to read over all that I had written, between and over the lines and could find nothing to corroborate that inspired waffle.

Informed consent is a cardinal principle

The issue still is; I was co-opted into that forum because someone just assumed I would want to participate in the forum without seeking my consent; one comment read that as a goodwill gesture.

Where have these people been? Organisations cannot just co-opt you without an opt-in which includes informed consent even if their surveys indicate you might be interested in their products – that principle applies regardless of if it is a village forum or a sophisticated gentlemen’s club.

Read my script upside-down

In the end, I asked for my name to be expunged from their records and mailing lists – for which I received a few brick-bats, I did not say for once that my mother-tongue is in fact English – there is a possibility that what I was conveying in language – tone, context and syntax – was lost in translation - my foible - I say what I mean.

Anytime you are tempted to Reply All, just think about what is actionable about your email and if it is relevant to that audience.

I would talk of this no more, one is utterly miffed and certainly not amused.