Showing posts with label privacy. Show all posts
Showing posts with label privacy. Show all posts

Jun 28, 2011

How to make credit cards much more safe

I have simple idea how they could make credit cards much more safe. Often when credit (or bank) cards are stolen, first thieves get somehow to know your pin code. They look over shoulder or even there are these machines that videotape or record you pin code. Then they steal your card and use it asap.

What if credit cards would have two pin codes. Those would be then used after each other. So you would have codes 1234 and 5678. When you are buying something you would this time give 1234. Then on the next buy, or withdraw from ATM, you would use 5678. Then on the next you would again use 1234. Simple.

This would make thieves life much harder. If they would track you and somehow see what was the pin code you used, they couldn’t steal your card right away, since that code wouldn’t work. To somehow track your both pin codes is much harder I think.

What do you think? Isn’t it a cheap and easy way to increase security with credit cards?

This was originally posted 17.12.2010 at lostinux.wordpress.com. I've closed that blog of mine and I'm re-posting some of the most popular and best posts from there to here.  

Written by +Henri Hämäläinen

Mar 26, 2011

Tips for good password management for people with bad memory

I bet I'm not the only one who is strucling with passwords with all different services in the internet and work life. Then in addition I have always had a bit hard to remember details on many things, like names and dates et cetera. I've read and heard many different ways to handle passwords, but I wanted to give my tips, if you are equiped with similar memory that I am.

Password management is easy if you don't care about privacy. You can use same or similar passwords for all services. Or just change a number in your password everytime you have to. Those area really not that secure. In some point for sure, one of the services you have created account, will be hacked. I want to prepared so that everything I have ever been signed to can't be used when one of my passwords will leak.

So here's my tips:
  1. Combine important dates, people and places for your passwords
  2. Have separate password for email
  3. Use different levels of passwords for services
Tip 1 Combine important dates, people and places for your passwords: I use passwords as way to remember also other important things. As an example I could combine my car's license plate number with car model. So if car would be Skoda Octavia and license plate ABC-789, then I could have password SkOcABC789. It wouldn't be easy to hack, but it would be easy for me to remember. Here's an other example, if I would have been in Barcelona in 2006 with my friends John and Jack, password would be JoJa06Barc. You can actually make up these quite easily. Things I have used have been parts of social security numbers of my family, important dates like birthdays, trips, addresses and many more. I find this system quite useful

Tip 2 Have separate password for email: Email is your most important account because, that's the way to recover passwords. If someone would hack you email, it would be really easy to get almost all passwords you have in any services, just by searching from email your account confirmation mails and then with service say that you have forgotten your password. Then you will get new password to email and your account is hacked. This is why I see email account being the most important one and that password I never use in any other services. 

Tip 3 Use different levels of passwords for services: I see this as one of the best ways to make sure that I don't lose it all, when someone gets a password of mine from one of the not that well secured services. So I have basically 4 levels of passwords:
  • 1st level are the most important ones like emails and work passwords. Those I keep unique. So I have 3-5 unique passwords for this level. 
  • Level 2 is the services I use really often like some of the social media's. And I use that password for only the couple main services and nothing else.
  • Level 3 are the ones I do use randomly, but those are not in everyday use. 
  • Then level 4 are all the services you create account without knowing if I'm ever going to use those again, but those require password to be able to even try. 
I've seen this 4 level password management to work for me, but it would work with anything from 2-6 levels depending on your ways to group applications and services you use.

This system has worked really well for me. It makes me feel safe with tens, even hundreds of services I've used and tried. I've always liked to try all things there are available in the web, but still I care about my privacy. This works for me and if you got some tips to take with you, it would be nice. Password management is really hard, but it remains really important before other ways to identify users become popular.  

Written by +Henri Hämäläinen

Jan 16, 2011

Perfect example of how street addresses have been used for identity thefts

I've been wondering that Finnish company gives street addresses of people for everyone in the web for search. Here's my posts (original and followup) about that one. I just read this morning about a guy who hijacked women's email and FB accounts anf blackmailed those with nude photos he found from send folders.

So the problem is that in many social media sites you bypass password login with a security question. And those can be something like "which street did you grew up?" or "street name of childhood home?". Using that information you can get in without password.

Now if you take that, social media services and the service you can get street addresses, it's damn easy to hijack some accounts. First find out for example who are someone's parents, then check parents home address and try to use that one. I bet that works for many.

And there's many smaller harm making possibilities with sharing home address, like someone can order you all the free vacation and shopping catalogs delivered to you post box and other similar things.

I rest my case.

Written by +Henri Hämäläinen

Jan 15, 2011

Giving people's street address in the web seems like acceptable behaviour

Couple weeks ago I blogged about privacy "violation" or at least quite careless usage of personal data. One Finnish company (Fonecta) is giving street addresses of almost all Finnish people in the web for anyone to search. I sent them a mail and asked asked about it and now I got an update from them.

They said, that they are getting the data from our mobile phone service providers and in those terms people are agreeing that it is OK to share this information. So they are not doing anything illegal.

I'm still puzzled about this one. I still think they shouldn't be sharing home addresses of people to anyone. Still I seem to be the only one complaining about this one, so maybe I'm just somehow being extra cautious.

I believe in openness, but I think that also should include transparency. Companies should be very clear that your information will be publicly available to anyone in the internet. Users should be aware on all data what is shared to everyone and there shouldn't be any surprises.

I'd love to hear some comments about this one. Would you be OK, if anyone could find your home address from the web?  

Written by +Henri Hämäläinen

Jan 3, 2011

Talking about privacy violations, how rude is this one?

I was using Pipl and accidentally found out that almost all street addresses of Finnish people are searchable openly to everyone. From http://en.fonecta.fi/white-pages/ you can without even signing in to see exact street addresses of most of the people in Finland!. I checked couple of my friends and I found all of their addresses. That's damn scary and miserable failure from Fonecta.

This connected to all social media around there, is a scary combination. This gives everyone possibility to basically stalk you. Anyone can know where you live and can go to your home when you are not there or the other way around when you are there. Perfect for stalkers and thieves.

I would think this would need to be another way around in the world we live in. People would need to have a right to decide their privacy so that they can share their exact address to the world if they want to. Not that it is somehow automatically shared with rest of the world and needs to be asked to taken away.

Don't get me wrong. I'm all for openness. But also I'm all for privacy. You have the right to decide what is shared. Your personal information like where you live shouldn't be revealed to everyone by default.

I send them a mail and asked about it and I'm waiting for answer. I will try to raise this up, for everyone's who is living in Finland, sake and safety.

They might not be violating any law, though. Maybe somewhere there is small text in some contract saying that they can do this. I just think this is against overall understanding of fair handling of users private data.
 
Written by +Henri Hämäläinen