Friday, 8 March 2013

Reasons SumRando is awesome #465


There are a million reasons to use a VPN, but the ability to hide your IP address, re-route your connection and become completely anonymous are certainly chief among them.

Before we go on it’s worth saying that if you aren’t using a VPN yet, you’re missing out. But once you decide you’re ready to take your privacy seriously and open up the range of content a VPN can provide, how do you choose the right service?

Let’s talk privacy.

ALL VPNs encrypt your data, change your IP address and re-route your connection. Any VPN will give you solid protection from unsavory hackers, criminals, evil masterminds, or whoever is trying to get your data. But if you’re really concerned about privacy, it’s time to think outside the obvious…

Logging

Like we said, any VPN will protect your data from outsiders. But what about the VPN itself? How much data do they hold onto? Lots of VPNs preach privacy, but keep logs of every site you visit, every file you download, and your login locations.

See where we’re going?

Although that data is locked up, all it takes in most countries is a court order to make all your carefully protected information completely public.

But here’s the good news.

AWESOME VPN’s like SumRando delete their user logs. That means, that even if a court orders us to turn over your protected information, we won’t and simply can’t.

What you do online is your business.

Look, there are a lot of great VPNs out there (but we’re pretty sure ours is the best), so when you’re shopping around, READ THE FINE PRINT. There’s no sense in paying for protection when all you get is a false sense of security.

Wednesday, 6 March 2013

6 Funniest Twitter Hacks of All Time


We’ve seen a lot of Twitter accounts hacked in the last few years. In case you've forgotten, here’s a recap of the best.

Justin Bieber

Back in 2010 a teenager in Detroit, Michigan hacked into the Twitter account of one of Bieber’s friends and stole the pop star’s phone number. All part of the burden of fame, right? Just take it in stride…right?

Nope.

In a stroke of revenge, Bieber found the hacker’s mobile number and posted it to his own account.

The tweet read: “Everyone call me [phone number removed] :) or text”

The hacker, Kevin Kristopik, later posted a YouTube video showing messages and calls coming into his mobile phone faster than he could delete them.

Brittany Spears

While Brittany’s music may have controlled the minds of teenage girls, there are some who think the pop singer is in control of a lot more. Some crazies people think she is a member of a secret society that worships the Devil and works to bring about the end of days.

And a few years ago, an enterprising hacker played to these theories and revamped Spears’ account with demonic imagery and tweets about establishing the “New World Order” and kicking off the apocalypse.



Donald Trump

We reported the Donald’s twitter hack a couple of posts ago, but it definitely merits re-mentioning because although it was relatively short lived, it was hilarious.



Yep. Donald rapping. So good.

Jeep

Last month marked several Twitter hackings, but American auto brand Jeep definitely turned out among the most amusing. The hackers that commandeered the account claimed the brand was sold to Cadillac and that the company was having problems because its executives were using crack cocaine. Admittedly, not super clever, but pretty extreme as far as Twitter hacks go.





Burger King

The same week that Jeep fell prey to hackers, Burger King too found their account compromised.


Much like the Jeep incident, the Burger King hackers claimed the company had been sold and that the management was on drugs. In this case, the account name was changed to McDonalds and said the company had been sold because “the Whopper flopped.”

On the bright side, Burger King gained around 5,000 new followers in the first 30 minutes of the hack.

Westboro Baptist Church

In late December, the bone-headed Westboro Baptist Church announced plans to picket the funerals of children murdered in the Sandy Hook Elementary school shooting. The church tweeted they would picket "to sing praise to God for the glory of his work in executing his judgment." Real classy.
In response — a little dose of social justice.

A 15 year-old hacker who goes by the alias, Cosmo the God, took over WBC spokeswoman Shirley Phelps-Roper’s account (@dearshirley) and posted a White House petition to officially label the church as a hate group.

The hack was associated with the hacktivist group, Anonymous, who posted the following message:

We will not allow you to corrupt the minds of America with your seeds of hatred...We will not allow you to inspire aggression to the social factions which you deem inferior. We will render you obsolete. We will destroy you. We are coming.

Friday, 1 March 2013

Massive world-wide information leaks. What are you gonna do about it?


New reports say that a hacker group is stealing upwards of 1 Terabyte of data from governments and businesses every single day. This is not the work of 17 year-old techies in their mom’s flat, this is industrial hacking and it’s state-sponsored.

Holy crap.



As much as we like to believe that our governments and corporate leaders are smart and well prepared, they aren’t. 1 TB per day isn’t a leak, it’s Victoria Falls.

Even more recently, U.S.-based security firm Mandiant told The New York Times that state-sponsored groups in China may have the ability to bring down power grids, water systems, and oil pipelines.

Yep, the cyber-apocalypse is coming. What are you gonna do about it?

First of all, while all this seems pretty scary (and it is), this is not the time to dig a bomb shelter and start hording bottled water and canned food. It is, however, the time to take charge of your data.


Strong Passwords: Guess what, using the same password, no matter how good, for everything is dumb. All it takes is one data dump from one crappy server to unlock your bank, email, Facebook, everything. Use different passwords for every site and keep them organized with a program like 1Password. Honestly, security aside, programs like this are free and will make your life so much better.

Anti-Virus: Malware is the nasty stuff on your computer taking up memory and stealing your login credentials. Anti-virus programs won’t stop zero-day attacks, but they’re certainly a big step in the right direction.

Encrypt, Encrypt, Encrypt: Seriously people. Using that wifi network at the coffee shop? Guess what? A chimpanzee could figure out how to steal your data. It’s really that easy. USE A VPN.

Don’t be Stupid: We have a tendency to check out mentally when we’re casually surfing the web, but in today’s environment, keeping your wits about you will keep you safe. Is someone asking for your password? Do you trust these guys with your credit card? Think about what information you’re giving out, then ask yourself if you trust the receiver. If an offer is too good to be true, it probably is.

Tuesday, 26 February 2013

Donald Trump’s Twitter Account Hacked. Tweets only slightly crazier than usual.


Every day, we at SumRando work hard to make sure none of our subscribers are victims of data theft or hacking. We are truly passionate about internet security and are, on principal, opposed to any type of cracking, hacking, or any other kind of digital compromise.

But let’s be honest. Donald Trump tweeting rap lyrics is just funny.



The lyrics are from Lil’ Wayne’s verses in the will.i.am song Scream & Shout. Fortunately for The Donald, the hack was short lived and he quickly regained control of his account.

At which point he decided to direct his anger at Twitter.

Or maybe you should just use a decent password...
No information is currently available that explains exactly how his account was hacked. The most likely scenario is a weak password or the same password used on multiple sites. USE STRONG PASSWORDS, PEOPLE! But we should all be glad the hack wasn’t worse.

What if the compromised account offered links to scam sites under the guise of a contest or giveaway? Most people wouldn’t think twice to trust a link on the feed of a high-profile celebrity.

Just a reminder to always stay vigilant. 

Thursday, 21 February 2013

OMG my second-cousin's great uncle is a Nigerian prince!

Dear Sir or Madam,
 
First I must solicit your confidence in this transaction. This is by virtue of its nature as being utterly confidential and top secret. We are top officials of the Federal Government Contract Review Panel who are interested in importation of goods into our country with funds which are presently trapped in Nigeria. In order to commence this business we solicit your assistance to enable us RECEIVE the said trapped funds ABROAD. For your kindly assistance we can reward you with the sum of $14 million...


This is Eddie Murphy, not a Nigerian prince.
But he's more likely to send you vast amounts
of money than the guy in your inbox.
I think it's safe to say we've all received an email that started off something like this. Conveniently, I usually only find scams like this floating among other bogus offers in the abyss of my spam folder. Unfortunately, Google says you might start seeing offers like this in your inbox—and sent from your friends' addresses.

Basically, not very many people are falling for the rich Nigerian prince ruse anymore. Though, the fact that anyone is still falling for it is pretty depressing. Anyhow, to make phishing scams like these seem legitimate, scammers are now sending messages from the hacked accounts of your friends.

This means many spammers are turning into account thieves. Every day, cyber criminals break into websites to steal databases of usernames and passwords—the online "keys" to accounts. They put the databases up for sale on the black market, or use them for their own nefarious purposes. Because many people reuse the same password across different accounts, stolen passwords from one site are often valid on others [Google].

Google has a ton of great info on their blog, but the gist is, if you're prompted to change your password, do it. And no, "password", "123456", and "myownname" are not acceptable passwords. Your best bet is going to be to keep a different password for each site or service you use and use a client like 1password to manage them. That way, even if say, your Facebook password gets leaked, your email and other accounts will still be safe.