Watch your online identity!

Posted by Leah On February - 28 - 2012

Watch Your Online Identity!A typical identity theft today is not due to a stolen wallet or a bank ATM card. Instead, an overwhelming majority of cases related to stolen identities are from transactions on the Internet. From online shopping and trading to social networks and email, your computer serves as the perfect partner in crime for cyber criminals.

According to the Federal Trade Commission (FTC), more than nine million Americans fall victims to identity theft each year. The rise of email communication, online shopping and social media surely contributes to the growing number of online identity theft. Such theft occurs when someone uses personally identifying information, such as your name, Social Security number or credit card number without your permission to commit fraud or other crimes. Most individuals don’t discover such thefts until reviewing their credit report or credit card statement.

Online identity theft can occur in many places, such as “phishing,” which occurs when someone pretends to be a financial institution or company and sends email messages to obtain personal information. Other thefts can occur during online shopping occasions if a security suite is not installed on your computer.

Today more than ever before, individuals and families must take protective measures online to ensure they don’t fall prey to identity theives. Luckily, there are several steps individuals and families can take to ensure online safety.

Shop safely online. Install  security software on your computer and keep it updated. Such securities include firewall, antivirus and anti-spyware. It’s also important to keep your web browser current.

Verify the website’s reputation before releasing your sensitive information. A closed padlock sign on the web browser’s address bar or a URL address beginning with shttp or https indicates that the site is secure. Never use unsecured wireless networks to make online purchases. Using a safe payment option, such a credit card or PayPal account, allows buyers to seek credit from the issuer if the product isn’t delivered or damaged.

Be aware of “phishy” emails. Cyber criminals often use emails to collect personal information or trick individuals into downloading malicious software through email attachments or requests.

Never reveal personal or financial information in an email or respond to such enquiries. Contact a company directly if you are unsure if the email request is legitimate.

Secure your social spaces. Learn and use social media network privacy settings, such as Facebook, Twitter and LinkedIn. Such settings control who sees what you post. Keeping personal information, such as your street address, private and using long, complex passwords ensures online safety.

Turning off your computer when not in use protects from online identity theft. Leaving the computer on continuously allows scammers constant access to install malware and commit cyber crimes. For more detailed online safety tips visit StaySafeOnline.org, a national cyber security alliance.

At SafeList.com, online safety is the No. 1 priority. Real people in real communities can build relationships and trade safely through a trusted online marketplace. Although buyers and sellers are anonymous to each other, all are verified and each transaction is linked directly to each individual. It’s the kind of built-in accountability that makes SafeList unique to securing online safety.

Safelist’s family-to-family trading is secure, and all transactions can include receipts for tax deductions. SafeList offers a very simple solution that verifies the identities of all participants. With the Verified Anonymity concept, all members can stay anonymous, but have still been identified. It’s a turnkey solution for online safety that discourages online thieves access. Browse SafeList’s “safe” listings in your area today.

How Safe is Your Password? (2 of 2)

Posted by SafeList Team On July - 26 - 2011

“Internet security is broken, and we need to roll up our cyber-sleeves and fix it.” — Becky Ferreira, in her recent Popular Science article exploring the problem with online identification today.

Last week, we discussed the growing problem of single password authentication and how passwords lack adequate protection for our online accounts. In an ideal world, we all would have a strong, unique password for each of our online accounts. However, the reality is that many of us keep the same, easy to remember password across multiple platforms. This leaves our personal information at risk for security breaches, identity theft, and other crimes.

As we highlighted in Part 1 of this post, groups such as Anonymous and LulzSec have recently hacked into organizations like Sony and even the U.S. government and released sensitive data to the public. Security breaches like these put a glaring spotlight on the problem we all have with keeping our web activities private and secure.

High profile incidents such as these are just pieces in the web of cyber-crime that plagues the lives of U.S. citizens. According to the U.S. Department of Justice, an estimated 11.7 million Americans were victims of identity theft of some kind including online identity theft over a recent two-year period.

The government has taken notice of the problem. On April 15, the U.S. Chamber of Commerce hosted the launch of a Whitehouse initiative entitled National Strategy for Trusted Identities in Cyberspace (NSTIC).The goal of the initiative is to create a joint public and private effort toward finding effective solutions to problems plaguing the online authentication process. NSTIC is designed to enable the development of “trusted credentials,” a term which refers to any method considered to be more secure than a single password.

The proposal comes soon after nominal efforts in the private sector to solve the problem. Google led the way in February by introducing their optional two-step authentication process for Google accounts. A two-step process combines two things in online authentication: something you should know (password) and something you should have (a device).

Once a user opts into this Google service, the password is only the first step. Users then also have to enter a verification code that is sent via phone, text message, or mobile application. A potential hacker would not only need to know your password but would also have to have access to your device that receives the verification code.

Google’s solution is a step in the right direction, but it is also somewhat cumbersome. In reality, most users won’t adopt a new process unless they are forced to.

But what are other private companies doing? Unfortunately, not much. Last week the tech blog Gizmodo requested that “Facebook and Microsoft and Apple start taking on this challenge in earnest.” Sites with tens of millions of users have a responsibility to their members to protect them.

For users who want to take their security into their own hands, security tokens are a noteworthy example of a “trusted credential.” A security tokens is a device that displays a unique passcode that changes about once per minute. In order to gain access to their accounts, users need to enter their traditional password and also the passcode displayed on the device in real time.

Unfortunately, even security token providers can be hacked. EMC, the makers of the security token SecurID, admitted in an open letter to customers this past March that they were victim to “an extremely sophisticated cyber-attack.”

Yet another solution that attempts to make our passwords more secure is the advent of applications like 1Password. This program not only creates strong and unique passwords for your myriad of accounts, but it also stores them for you, requiring you to remember just one. Every time you need to access an account, 1Password automatically enters an encrypted password directly into your web browser.

While we wait for emerging innovations to solve the growing problem of online authentication, let us ensure that your current passwords are strong and well-protected from criminals. Here are a few tips that should help:

  1. Use numbers, upper and lower case letters, punctuation marks, and symbols.
  2. Change your password frequently. Experts recommend doing so every 3 months.
  3. Avoid writing passwords down. Whether at home or in the office, having written passwords offers them to an unauthorized person on a silver platter.
  4. Use a unique set of letters – nothing personal like your name, pet, date of birth, or the city where you live.
  5. Do not use the same password for any of your highly sensitive accounts – including email, banking, finance, etc.

We will keep you up to speed with the newest technologies that may help protect your online accounts from unauthorized access.

But we also want to hear from you.

Please share your comments and suggestions so that we may, with your help, build a safer online community for everyone.

 

How Safe is Your Password? (1 of 2)

Posted by SafeList Team On July - 18 - 2011

Since the advent of the Internet, our daily lives are moving online at a rapid pace. We have become very comfortable, and even somewhat carefree, in conducting our most sensitive and private activities – banking, bill paying, email, chat, etc. – on the web.

And how do we protect ourselves from strangers’ prying eyes? A password, of course. Pinning our hopes on a 6-12 character combination, assuming that it will help keep others out of our business.

Unfortunately, that is no longer the case. A slew of hackings and security breaches in 2011 helped highlight the fact that the password has become outdated and can no longer be relied upon to protect us online. Our fast changing, web-driven world now requires a better solution.

Part of the problem is the sheer number of passwords that an average online denizen is expected to remember. It seems like almost every site we visit requires us to sign up with a log-in name and a password. As a result, our natural inclination is to use the same password everywhere to help simplify our lives.

Results from a survey published last year in the New York Times highlighted online privacy issues that were troubling to say the least. The article reported that two out of the five most commonly used passwords were “12345” and “password.” And “password1” appeared in the top list as well, seemingly because many sites attempt to protect users by requiring a number in passwords.

If we are not forced to create a strong, varied passwords, it is human nature that we just will not. The technology blog Gizmodo recently published a worrying report that serves as evidence of this tendency. Gizmodo matched a list of their users against a recently released list of hacked Sony users’ passwords. They found that two-thirds of those who used both services had the exact same password. That doesn’t sound too alarming, but chances are that these folks use the same password to access their Facebook, Gmail, or banking accounts as well.

That list of Sony users’ passwords was released by the hacker group LulzSec, which recently went on a widely publicized, 50-day rampage of cyber terrorism. They called it “50 days of Lulz”, which draws from the Internet abbreviation for laughing out loud (LOL). In addition to Sony, this unidentified group of computer criminals released major lists of secure data from the CIA and the U.S. Senate as well.

While it is claimed that LulzSec’s motivation is not to profit from their criminal acts but rather to have fun by spreading mayhem, some in the security industry have given the group credit for helping expose holes in large corporations’ online security systems. No matter how you slice it, their brazen activity of hacking into these companies’ computer systems is illegal. However, it is unfortunately an example of a new and growing trend called “hacktivism.” Along with other groups like Anonymous, hacktivists commit illegal acts online not just for fun but also for political reasons.

In a public message issued to defend its Sony break-in, the folks at LulzSec stressed that they are not “master hackers” and are simply exposing the vulnerabilities plaguing the Japanese company’s computer security systems. “Why do you put such faith in a company that allows itself to become open to these simple attacks?” they asked.

The answer to their rhetorical question is that we shouldn’t. But the unfortunate reality is that we do because we incorrectly assume that these large corporations behind the brands that we admire and trust will ensure the protection of our sensitive personal data. Groups like LulzSec help remind us that that the time has come for us to no longer take our online security for granted, and that we must take steps to ensure that our Internet activities and personal data are safe and secure.

In part 2 of this post, we will examine recent industry developments aimed at solving the problem of online identity theft and share steps that you can take to protect yourself from cyber criminals.

 

 

10 Tips for Parents Dealing with Cyber-Bullying

Posted by SafeList Team On June - 13 - 2011

Cyber-bullyingCyber-bullying has recently become a serious issue in online safety. In fact, The National Crime Prevention Council reports that almost half of all American teens are at one time affected by cyber-bullying. Just as it sounds, cyber-bullying occurs when someone publishes hurtful or embarrassing messages about another person on the web. It occurs frequently on social media platforms, such as Facebook and MySpace. It can also occur through blogs, email, forums, text messages and other communication methods.

Recently the news has reported an increase in cyber-bullying cases. When they are not dealt with, it can lead to tragedy, as was seen with the 2010 death of Phoebe Prince. Cyber-bullying can lead to depression and suicidal thoughts in young adults and children, not to mention poor academic performance. Parents have a responsibility to monitor Internet usage and pay close attention to their child’s social lives.

Here are 10 tips to keep in mind if you have children who may be exposed to cyber-bullying:

  1. Limit the amount of time your child spends on the web. Try setting time limits.
  2. As a parent, become “friends” with your children on their social media accounts so you can track any visible signs of bullying immediately.
  3. Put the computer in a common area, such as near the kitchen or family room.
  4. Talk to your child’s school to start a program on bullying prevention. If they already have one, make sure that cyber-bullying is an aspect of the program. It should have a system to report to teachers any signs of trouble.
  5. Investigate further if your child seems hesitant to attend social events or school.
  6. Take action if you notice your child becoming withdrawn or showing signs of lower self-esteem or depression.
  7. Contact the school and get the principle and teachers involved.
  8. Change phone numbers or email addresses if bullying continues.
  9. Block bullies on social media like Facebook, MySpace, Twitter, etc.
  10. Report to the website owner any harmful content on their site posted by bullies.

 

Six Tips to Nix Facebook Predators

Posted by SafeList Team On May - 31 - 2011

Today, for millions of people, having a Facebook page has almost become de rigueur. Just in the United States alone, more than 33 million people of all ages visit this new cyber destination and cultural phenomenon, almost daily, and spend hours socializing and networking with friends, business associates, acquaintances and also total strangers. Because Facebook also has the ability to give criminals, including sexual predators, unfettered access to the website’s uninitiated users, it is very important to know how to use some of the privacy tools that the site offers.

Facebook began as a socializing tool for college students however, today, it’s used by just about everybody, all over the world. Users face potential danger especially when posting personal information, including photos and videos. So it is important to use precaution(s) when using this social media juggernaut.

 

Here are 6 safety tips to help keep your profile private and reduce chances of falling victim to predators lurking on Facebook:

  1. Limit visibility of your Contact Information (phone number, email address, IM screen name and physical address) by going to “Privacy Settings” under “Account.”
  2. Limit visibility of status updates, especially if posting potentially offensive statuses.
  3. Block any users you find threatening so that they cannot search for your profile. In essence, it appears that you no longer exist on Facebook to that person. You can do this under “Privacy Settings” or click the “Report/Block This Person” button on the bottom left of their profile.
  4. Be careful when posting your whereabouts. Make sure only your friends can see your location. For example, “John Doe: is having lunch at Olive Garden on 1st and Wetmore St.” or “John Doe: is on vacation in Hawaii…won’t be home for 2 weeks!” This provides ample opportunities for predators to target your home during your absence.
  5. Make use of your “Limited Profile,” where you can selectively block information from an entire group by placing people you don’t know well into a “Limited Profile” group.
  6. Hide pictures or wall posts if you are concerned about too much of your personal life being exposed. Individual photo albums can be blocked from certain people or groups.

To update these settings go to the drop-down menu at the top right that says “Account” and click on “Privacy Settings.” Here you will find options that allow you to a) let everyone see all your information, b) only friends of friends, c) friends only, d) recommended, or e) custom. In order to hide information or pictures only from select groups, choose the custom option.

Facebook, along with all other social media sites, is an invaluable personal and business networking tool, but it is imperative that people use caution when using them. Remember, information posted on the Internet can easily be tracked and while the Net provides many opportunities and benefits to individuals, it can also lead to tragedy. Always be aware of unidentified users, especially when sharing personal information with them, because they pose potential threats. However, by following these 6 simple steps, you’ll be on your way to enjoying a safer Facebook experience.

 

San Diego Craigslist Murder – 5/11

Posted by SafeList Team On May - 27 - 2011

Around 10:30pm on May 11, 2011 Garrett Berki, an 18-year-old resident of San Diego who graduated from La Jolla High School was shot and killed during a planned Craigslist transaction.

Garrett Berki replied to a Craigslist ad for a $600 MacBook Pro in the San Diego area. When Berki and his girlfriend appeared for the transaction, three 17-year-old boys robbed them of their cell phones and money. The attackers then chased Berki and his girlfriend in a vehicle where Berki was shot in the chest while attempting to drive away. Berki died about an hour later at the hospital.

The accused killers are Rashon Abernathy, Seandell Jones and Shaquille Jordan. Although they are minors, they are being tried as adults and may face 50 years to life in prison if convicted.

Stories like these are occurring more and more frequently. At Safelist.com, we feel, as citizens and parents, it’s our job to create a safer community. Online local classifieds are here to stay, so Safelist.com is taking extra steps to make the online shopping experience safer.

All members who join Safelist.com have their identity verified before they can post or respond to ads. Therefore the risk of someone using a fake email or name is essentially eliminated. To get even greater reliability as a member, upgrading to a Gold membership requires a criminal background check. Although this does not guarantee buyers are free from potential harm, it is an extra step that other classifieds sites like Craigslist do not offer.

No matter how extensive background checks are, classified users still need to use precautions and their own best judgment when completing transactions.

A few tips to stay safe during classified transactions include:

  • Meet in a public place such as Starbucks or grocery stores to complete the transaction.
  • If you are uncomfortable for any reason, walk away. Just because you set up a place and time to meet doesn’t commit you to purchasing if you don’t feel safe.
  • Research. If you are buying something big such as a computer or a car, do your research to ensure the item you’re buying works and is priced fairly.
  • Remember: If it sounds too good to be true, it probably is. Be wary of scams if a price is set too low.
  • Take advantage of Safelist’s advanced features like voice or video chat to talk directly to the buyer/seller before meeting.

 

Tragedies like the death of Garrett Berki can be prevented by taking security measures into your own hands. At Safelist.com we’re building a safer community to prevent these types of tragedies from occurring.