+
Science

IT pros share some crucial lessons on how to avoid getting hacked.

A few lessons from IT professionals about securing your personal data.

hackers, computers, IT pros, theft, community
Photo by Kenny Eliason on Unsplash

There are unsavory people interested in your information.

True
Mozilla

This article originally appeared on 06.19.17


In 2009, Scott McGready stumbled on a massive phishing scam targeting his company's email server.

Thousands of emails bombarded the company in a short period of time. They all came from the same source, pretending to be someone or something they weren't in order to lure people into clicking on shady links and giving up their personal data.

"While investigating it, I stumbled upon the phisher's database which had [the] personal data of thousands of people," McGready says. "I was surprised how little effort was required on the fraudster's part to acquire such a trove of information."


This discovery sparked McGready's interest in information security and teaching others how to protect themselves from fraud. Since then, this journey has taken him from the U.K.'s National Trading Standards department to the documentary series "Secrets of the Scammers" to his own company and beyond.

Here are just a few lessons from McGready — and some other IT professionals — about securing your personal data:

data hacking, browsing, protection, financial

Is your information protected online?

Stomchak/Wikimedia Commons

1. Know there is a LOT of data about you online.

"Having data readily available online means that things like phishing emails can be automatically tailored to targets without much effort," McGready says.

But what does "data" really mean in this case? Um. Er. Pretty much everything. Even if we don't realize it. Something as simple as your basic browsing habits and location history can actually reveal a lot about you. Even if your name's not attached to it, a savvy social hacker could still figure something out.

2. Be aware that your friends may expose info about you — even if you're not on social media.

"We tend to share every detail of our lives on social media because we feel obliged to by peer pressure — whether that be adding your birthday to your Facebook profile because the website keeps asking for it," McGready says. But it's worse when your friend tags you in that photo from high school with your school mascot in the background and — oops. There goes another security question.

social media, data leak, Facebook, friends

Things don't always go as planned with technology.

Photo by Elisa Ventur on Unsplash

3. Pay attention so you can mitigate the risks (though probably not completely avoid them).

McGready recommends keeping your social media profiles as private as possible and asking your friends and family to do the same. "Even those that intentionally aren't on social media may be easily findable by their friends or family that share the 'dinner table selfie.'"

4. It's better to be proactive than wait until you're compromised.

"We hear about data leaks almost every week, it seems," McGready says. "The general public are no longer asking 'if' their data is compromised, but rather 'when.'"

This might sound scary. But it's also a good reminder to stay sharp.

public, risk, education, accounts

Do you know everyone that's using your computer?

Image via Pixabay.

5. Check the Facebook apps and third-party services that might have access to your account.

"It's worth checking what data you share with specific companies and only giving out the bare minimum in case of a data breach in the future," McGready explains.

For example: Does Bejeweled Blitz really need permission to access everything you've ever put on Facebook, to post on your behalf, and to spam your friends and family? It's not just annoying — it puts you at risk if that information leaks.

6. Take some time to get rid of those old accounts.

A clever hacker might still be able to figure out something through your iwasdefinitelyacool15yearold@aol.com email address. "Many of us, myself included, also have a large number of 'dormant accounts' on websites that we no longer use," McGready says. "I'd fully recommend logging into these accounts and changing all the profile information before deleting the account."

science, history, websites, companies

It's important to know what accounts are open in your name.

Photo from Daderot/Wikimedia Commons.

7. Don't feel bad if it happens to you. Even IT professionals fall for it!

Georgia Bullen, technology projects director for New America's Open Technology Institute, recounts how she was hacked:

"My password wasn't secure enough and so someone had built a program that was logging into not-secure-enough accounts and then spamming."

What she felt at the time is all too familiar for anyone who's been hacked: "Embarrassed, confused, and then really worried that someone else was going to click on something from me."

8. Be smart, pay attention, and know what you're getting into with any website or service you sign up for.

This bears repeating because a little awareness can make a big difference.

security, passwords, service, defense

What type of security for your accounts do you have?

Photo by Marcello Casal Jr/ABr/Wikimedia Commons.

9. Have a solid P@$w0rds plan.

Passwords are the Achilles' heel of the modern world — but there's a trick.

"It's totally possible [for hackers] to take one password, see where you've re-used it, and then get access to those accounts as well. And that's where the bigger danger happens," explains Harlo Holmes from the Freedom of the Press Foundation.

That's why, in general, passwords should be different for every website or service used, and consist of three random words, interspersed with special characters; a DiceWare password like "correct horse battery staple" is a good place to start.

Password managers can help out by creating unique passwords for you. Which leads to...

10. Use a password manager.

Password managers can generate strong, random passwords for you. And they keep track of all of your different passwords so you don't need to memorize them yourself.

All you need to do is remember one super-secure master password in order to unlock every other possible password combination. That way, says Bullen, you can't even make the mistake of verbally giving your password away because you genuinely don't know it yourself! (Unless it's your master password, in which case, ya know, don't do that.)

11. Set up two-factor authentication (2FA) for added security.

Safety is good, but a back-up plan is even better. 2FA sends a code to a device on your person just to make sure that the person logging in is really you. Even if your password does get compromised, the hacker probably doesn't have access to your smartphone, too. (Probably.)

Mozilla's Amira Dhalla explains how it works:

12. Consider using a separate email address — with a separate strong password — for important accounts like banking.

That way, even if you do use the same password elsewhere, hackers will have a harder time getting in to your important accounts. (Make sure this secondary email account has two-factor authentication, too!)

13. Be sure to hover over links before you click them.

"Links may look legitimate, but upon hovering, they actually redirect to a completely different place," McGready says. (Don't believe me? See what happens when you click on www.upworthy.com/definitely-not-an-upworthy-page.)

14. Always double-check the URL in the address bar. (But even that's not always safe.)

Ever notice that green padlock in your browser bar? It's a good sign! ... except when it's not. As McGready explains, "While it's true that this means your data is encrypted between your computer and the website itself, it doesn't legitimize the website."

routers, world wide web, computers, Wi-Fi

Using default passwords on the computer router can leave you vulnerable..

Photo by Michael Geiger on Unsplash

15. Secure your router.

It may seem harmless to use the default password for your router, but that can actually leave you vulnerable to hackers (there are even websites that can be used to find out different routers' default settings). And someone accessing your router can access pretty much your entire home network. So it's worth taking that small extra step of setting up a strong user name and password.

16. Be wary: These days, the internet is in everything from lightbulbs to baby diapers. Which is super cool! And bad.

McGready sees "the internet of things," or IoT, as the biggest online threat on the horizon. Even if you have worried about Amazon spying on you, you probably didn't consider who else could be spying on you through a vulnerable Wi-Fi or Bluetooth system built into your smart home. "The issue comes when these wireless chips are integrated by default on all products, whether the customer wants them or not," McGready explains.

17. Exercise a little extra caution.

It all boils down to the fact that humans are too trusting.

We trust that our friends aren't going to expose our address over Twitter. We trust that some disgruntled Angry Birds employee won't hijack our linked Facebook page because we didn't pay attention to permissions. We trust the green padlock in the browser bar that keeps our credit cards secure, even if the website taking that information wants to use it for a shady purpose.

Simply put, we trust that the internet is mostly good and that people are, too.

It's hard to solve a problem you can't see — which is why McGready is so passionate about teaching online safety.

"Show the public exactly what is possible and what they should be watching out for," McGready says. "It's one thing to tell someone that a scammer can send a text which appears to be from a legitimate company or a known person; it's another thing entirely to send a text to that person's phone which comes from 'Mum.'"

There's no "one weird trick" to protect us from the dangers of technology. But we can do our due diligence — as long as we know where to start.

Community

Georgia school board refuses the resignation of outed superintendent. Community in full support.

"Cheers erupted among hundreds of students and other community members and colleagues who gathered in support."

Georgia school board refuses the resignation of outed superintendent

It should go without saying that having your private business shared with people you didn't consent to hearing about it can be upsetting. But imagine having it shared publicly, with the entire town after you took on a prominent role. It would be devastating. Except what happened to Dawn Clements, interim superintendent of Ben Hill County Georgia, was even more upsetting. Someone publicly outed her as gay.

Coming out as part of the LGBTQ+ community is something that someone does on their own time in the way they feel most comfortable. It can take years for someone to build up the courage to do it, and some people never feel comfortable enough to share that part of themselves with the world. But no matter when or if someone comes out, their existence within and outside of the queer community is still valid.

And while many people respect that the decision to come out is deeply personal, not everyone does and Clements was on the receiving end of hateful behavior. According to LGBTQ Nation, Danny Pate wrote the letter outing Clements as gay and sent it to local pastors before the letter began circulating the community. This led to Clements handing in her resignation.

Keep ReadingShow less

A truck carrying Shell gasoline.

In a historic legal maneuver, ClientEarth is personally suing 11 of Shell’s board of directors for failing to bring its business policies in line with the Paris Agreement. The suit is the first time that a corporate board of directors has been sued due to a lack of climate action.

The Paris Agreement is a landmark 2015 international treaty to reduce global warming below 2° and, preferably, 1.5° Celcius.

ClientEarth is a Shell shareholder, giving it the right to bring a suit against the company for failure to manage the risk posed by climate change under the UK Companies Act.

“Shell’s Board is legally required to manage risks to the company that could harm its future success, and the climate crisis presents the biggest risk of them all,” ClientEarth said in a statement.

Keep ReadingShow less

"I don’t need to be muscly. That’s what henchmen are for."

In HBO’s “The Last of Us,” actress Melanie Lynskey plays Kathleen—a tough, formidable villain and ruthless leader of a rebel alliance, not to mention apocalypse survivor.

Do these attributes require any particular sort of body type? Common sense screams no. And yet, outdated views dictate that the answer must be yes.

Case in point: former "America's Top Model'' winner Adrianne Curry recently criticized the legitimacy of Lynskey for the role solely because of her naturally soft body frame, implying that only someone toned and athletic could pull it off.

Referencing a photo of Lynskey in a dress for InStyle Magazine, Curry tweeted, "her body says life of luxury...not post apocolyptic [sic] warlord. where is linda hamilton when you need her?"

Lynskey, who is no stranger to standing up to body critics, had some choice words to say in response.

Keep ReadingShow less
Education

Sojourner Truth's real 'Ain't I a Woman?' speech was nothing like the famous one we all read

A prime example of how historical distortions can paint a totally inaccurate picture.

The famous Sojourner Truth speech most of us learned is a fabrication.

For generations, students have read the extemporaneous speech Sojourner Truth gave at the Ohio Women’s Rights Convention in 1851, known widely as "Ain't I a Woman?" As a formerly enslaved Black woman speaking out against slavery and for women's rights, Truth made some powerful points in her speech—except the speech most of us read is almost nothing like the one she delivered.

The way "Ain't I a Woman?" is written makes it sound as if Truth walked straight off a Southern plantation. But Truth was a Northerner her entire life. The Southern dialect that permeates the popular version of her speech is a total fabrication.

It wasn't Truth who altered her speech, though. A white abolitionist woman named Frances Dana Gage published the speech 12 years after it was given, and her version is the one that became popularized, in all its glorious inaccuracy.

Keep ReadingShow less

David Rossler returns to the place where he hid from the Nazis during World War II.

David Rossler, 84, and his mother were taken in by Georges Bourlet and his four young adult children in 1944 and allowed to hide in their home in Brussels in the waning months of World War II. Rossler and his mother were Jewish, and Belgium was occupied by Nazi Germany. If caught, they’d be taken to a concentration camp.

Rossler had already lost his uncle and grandfather after they were taken to Auschwitz concentration camp in Poland and he would lose his father, hiding elsewhere, to an illness.

Bourlet and his family were also in danger if they were caught hiding the mother and child from the Nazis. "People who protected Jews were simply risking their lives. You wouldn't end up in jail, but in Auschwitz—and Auschwitz, you didn't end up anywhere but in the crematoria," Rossler said in a video produced by MyHeritage.com.

After Allied forces liberated Belgium in 1945, Rossler, who was born Daniel Langa and later took the name of his stepfather, moved to Austria and lost touch with the Bourlets.

As Rossler entered his 80s and was in declining health, his final wish was to thank Bourlet’s family for the incredible bravery and humanity he showed him and his mother during the war.

For years, Lionel Rossler, David’s son, did everything he could to find the family, including putting ads in the paper and posting on social media. After one such post, he received a message from Marie Cappart, country manager for MyHeritage in Belgium, who wanted to help.

MyHeritage is an online genealogy platform with 90 million family trees. Rossler's story hit close to home with Cappart.

"My husband lost his grandfather during the war. He died at the concentration camp in Auschwitz-Birkenau," Cappart told Newsweek. "My own great-grandmother also died in the camp at Ravensbrück. She was British and was in Belgium as part of the resistance. Sadly she was caught by the Nazis and deported. She never came back."

“After browsing records and cross-referencing data, Cappart found an Anne-Marie Bourlet, born in Auderghem in 1929,” Lionel said, according to SWNS. “She discovered that Anne-Marie married someone with the surname Dedoncker and had five children—all of them possibly still alive.”

“After a bit more research, Cappart found Xavier, one of Georges Bourlet’s grandsons, and managed to contact him,” he continued.

Finally, after 75 years, David Rossler returned to the place where he hid in 1944 and 1945 and thanked Bourlet’s five grandchildren.

“It was an incredibly emotional day for us,” Lionel explained. “I was able to see, with my own eyes, the place where my father was kept safe from the Germans all those years ago.”

“If I had Mr. Bourlet in front of me, I would want to kiss him,” said David. “To say thank you with all my body, with all my life, I am alive, I have a family of which I am very, very, very proud. To tell him that my life is thanks to him.”

Bourlet didn’t know it then, but his bravery saved the lives of nine people.

“Because of his heroic action, Georges was able to save the lives of my father and grandmother,” Lionel said. “Nine people were saved thanks to what he did; my brother, myself and our children would not be here today if not for his courage and kindness.”

As a final “thank you” to Bourlet and his family, the Rosslers want him to be recognized as Righteous Among The Nations at Yad Vashem, the World Holocaust Remembrance Center. This honor is for non-Jews who risked everything during the Holocaust to save Jewish people.

The medal given to honorees has an inscription with the Hebrew saying: "Whosoever saves a single life, saves an entire universe.”

Motherhood

LGBTQ daughter surprises mother with pregnancy after secret IVF

She thought she would never have grandchildren and got the surprise of a lifetime.

LGBTQ daughter surprises mother with pregnancy after secret IVF.

Many parents dream of becoming grandparents. Oftentimes, people think about grandkids before they even become a parent as a "when I'm old" daydream about what life will be like at a later stage. It shouldn't be surprising that some parents of adult children may feel a little bummed when their child decides not to have children or can't have them. Or in some cases, parents assume their child's membership in the LGBTQ community would prevent them from having babies.

The majority of parents simply want their children to be happy, so they readjust their dream and support their children. But in the case of one mom of an adult child, her assumption was simply wrong.

TikTok creator Aurelia uploaded a video to reveal a birthday surprise for her mother wrapped in a large box. She explains to her mom why she's recording but doesn't give away what's inside the box.

Shortly after unwrapping it, Aurelia's mom pulls a teddy bear dressed in a t-shirt and little pants out of the box. Through excited confusion, she yells, "What is this?!" before Aurelia instructs her to press the paw on the bear.

Keep ReadingShow less