Wednesday, October 07, 2009

European Commission to Market Test Browser Option in Windows 7

At a Press Conference today in Brussels, the European Commission announced (finally):
"I am pleased to announce that the Commission will formally market test proposals made by Microsoft to address the Commission's concerns regarding the tying of Internet Explorer to the Windows PC operating system."
Brad Smith, General Counsel, Microsoft Corporation, welcomed the European Commission announcement to move forward with formal market testing of Microsoft’s web browser proposal in Europe. An example of what to expect in the Web browser ballot is shown in the image below.


Click for larger image
http://securitygarden.googlepages.com/EU_sm_BrowserBallot.GIF


Ideally, Europeans will be given the opportunity to select multiple browsers. This compromise is a major improvement over the prior option necessitating the separate downloading of a browser. The video and statement by Mr. Smith is available at Microsoft PressPass.

Clubhouse Tags: Clubhouse, Information, News, IE8





Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...

Monday, October 05, 2009

Windows Live Hotmail Phishing Scheme

Earlier today, Neowin reported that thousands of Windows Live Hotmail account details were publicly exposed:

“An anonymous user posted details of the accounts on October 1 at pastebin.com, a site commonly used by developers to share code snippets. The details have since been removed but Neowin has seen part of the list posted and can confirm the accounts are genuine and most appear to be based in Europe. The list details over 10,000 accounts starting from A through to B, suggesting there could be additional lists. Currently it appears only accounts used to access Microsoft's Windows Live Hotmail have been posted, this includes @hotmail.com, @msn.com and @live.com accounts.”

The Windows Live Team, Windows_Liveconfirmed that the logon account information of several thousand Windows Live Hotmail accounts were exposed on a third-party site. It is believed that this was due to a likely phishing scheme.

Edit to add Windows Live Team Update:

"As of 3pm PT: We want to provide a quick update, that as a result of our investigation we are taking measures to block access to all of the accounts that were exposed and have resources in place to help those users reclaim their accounts.

If you believe your information was documented on the illegal list, please fill out the following form to reclaim access to your account."

If your account was compromised, please see “What to do if you think your account has been stolen”.

The Windows Live Team provided the following steps to take if you are a victim to this or any phishing scam:

“Q: What should you do if you fall victim to a phishing scam? How should you respond? What steps should you take?

A: If you think that you may have responded to a phishing scam with personal or financial information or entered this information into a fake website, you should take four key steps: (1) report the incident to the proper authorities, (2) change the passwords on all your online accounts, (3) review your credit reports and your bank and credit card statements, and (4) make sure you are using the latest technologies to help protect yourself from future scams.

  1. For the first step:
    • If you have given out your credit card information, contact your credit company right away. The sooner a company knows your account may have been compromised, the easier it will be for them to help protect you.
    • Next, contact the company that you believe was forged. Remember to contact the organization directly, not through the e-mail message you received. Or call the organization's toll-free number and speak to a customer service representative. For Microsoft, call the PC Safety hotline at:
      1-866-PCSAFETY.
    • Then, report the incident to the proper authorities. Send an e-mail to spam@uce.gov to report it to the Federal Trade Commission and to reportphishing@antiphishing.org to report it to the Anti-Phishing Working Group.
  2. The second step is to change the passwords on all your online accounts. The reason for this is that a lot of people use the same password for multiple accounts. Start with passwords that are related to financial institutions or personal information. If you think someone has accessed your e-mail account, change your password immediately. If you’re using Hotmail, go to: http://account.live.com.
  3. The third step is to review your bank and credit card statements and your credit report monthly for unexplained charges, inquiries or activity that you didn’t initiate.
  4. Finally, make sure you use the latest products, such as anti-spam and anti-phishing capabilities in e-mail services, phishing filters in Web browsers and other services to help warn and protect you from online scams.”

As a precautionary step,it is advised that Windows Live Hotmail passwords be changed every 90 days. Instructions for changing your password as well as getting a refresh reminder are available in “Let Hotmail Remind You To Refresh Your Passwords Every 72 Days”.

With the end of the year Holidays approaching, phishing scams will be on the rise. Learn how to Create strong passwords, Protect your Windows Live ID and much more at the Microsoft Online Safety Fraud Prevention web page.

Clubhouse Tags: Security, Password, Windows Live, How-to, Hotmail, Clubhouse, Safety, Phishing, Information




Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...


Trackback: http://windowslivewire.spaces.live.com/blog/cns!2F7EB29B42641D59!41528.trak

Sunday, October 04, 2009

October is Cyber Security Awareness Month

NCSAM-2009

Canada and the United States have set aside the month of October as Cyber Security Awareness Month. Where ever you may live, the tips provided by supporters of this endeavor are appropriate for all computer users.

To support the Cyber Security Awareness theme last year to "Protect Yourself Before You Connect Yourself", I scheduled a new "tip of the day" at Security Garden each day during October (Available in the Cyber Security label). Although it was a lot of fun, the theme this year is "Our Shared Responsibility".

With that in mind, where ever you may be, I challenge everyone who reads this to join in the endeavor – share the responsibility! As a home computer user or tech enthusiast, take responsibility for keeping yourself and your family safe online.

Cyber_FamilyA starting point is ensuring that your family computer(s) have basic protection. Some months ago, I wrote a popular tutorial, Basic Computer Security for the Home User. If you are a “beginner”, that is a good place to start.

After your computer is protected with the basics, it is time to consider that the Internet is a virtual world with potential dangers and . . .

PROTECT YOUR FAMILY

Cyber_Mother_DaughterCyber_BrothersAs part of "Our Shared Responsibility", teach your children, grandchildren, cousins, nieces and nephews that “stranger danger” applies to the internet as well as on the street. This is especially important today with the wide usage of social networking sites by young adults. Be sure your children understand the importance of maintaining their privacy. If you are uncertain where or how to begin, Microsoft has published a number of articles, available from the Microsoft Family Safety webpage: Cyber_Mother_Son


For those members of your family who are mature enough to participate in social networking sites, additional guidance is available from the Microsoft Family Safety webpage:

Cyber_Father_DaughterParticularly for younger children, I suggest child care-givers use Windows Live Family Safety or Windows Vista Parental Controls to create age-appropriate filters for internet usage of the children in your care.

Additional information on Cyber Security Awareness Month is available at the following locations:






Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...