Encrypt all the things!

Posted on
Page
of 138
  • Examine the link to see if it was actually malicious?

  • Fwiw it was https://searchfor.cc/recommend/ Question mark q=toys+for+kids&u=220928954

    And searchfor.cc seems to be a dodgy site.

    Not really sure what to get them to check for. Can you get antivirus scans for android?

  • Back again. This time it's my fuckup.

    I got an email that appeared to be from a someone I worked with from their company address sharing a file via sharepoint.
    https://jnscorp-my.sharepoint.com/:b:/g/personal/ [surname_company] /EQm01HYobrtOgAM53jhoHzcBnN7a7yaurExlelbGCLl11w?e=4%3acSyVfS&at=9

    It then gave me a verification code and showed me a document that was blurred out with a link. When I clicked on it it asked me to login with my outlook/sharepoint/etc account which didn't work so I tried a few passwords then tried to set up a new account with the email it went to.

    What should I do?

    1. change any passwords using the ones I typed in.
    2. run an antivirus on my laptop

    Anything else?

    I'm also having a hard time remembering exactly what I did as ultimately I was just trying to open/view a document so was just focusing on getting that done.

    Pretty pissed off. I only opened the document because I was going to message the person's boss about a reference and mistakenly thought I must have and this person was sending the email. Literally any other time I'd have known it was dodgy. Only upside I guess is that I used my "online birthday" instead of my real one... not much comfort.

    Microsoft account team account-security-noreply@accountprotection.microsoft.com

    Microsoft Account email@engage.windows.com


    1 Attachment

    • is this spam.png
  • Yes, change passwords as soon as you can.

    Edit - this should include the email account that you received the email to, if different to your outlook/sharepoint account.

    Edit 2 - is there a ‘log out of all sessions’ option for outlook? Once you’ve changed password, and signed in again, do the log out everywhere option.

  • Review whether the account has granted any third party access to anything.

    Review your sent email to see if there is anything unexpected.

  • OK... so i've just had an email from them saying;

    Please disregard the above named email as it is invalid.

    I've double checked and it's their correct work email, as I emailed them when my first kid was born.

    EDIT: should add that it's a US company so emailing now isn't weird, and while their English is excellent they're not a native of the US.

    Is it likely that someone can use her work email?

  • Energy meters to report usage to suppliers in half hour units by default as opposed to the current opt in position.
    https://archive.ph/JQADy

  • I fucking hate this. I had a neighbour push my mental state to the ragged edge because they used their washing machine at night. This was up against my bedroom wall. For about 4 years most nights were heavily interrupted sleep.

  • I wouldn't mind this if it's implemented fully.

    Not Economy 7 or Economy 10 which offer 7 or 10 hours of cheaper electric... but full dynamic pricing that matches the peak use and type of use.

    i.e. domestic daytime use should be cheaper than domestic evening, but domestic night time should be even cheaper still. But this pricing should be down to 30 minute increments too, so 11am is cheaper than 12:30pm as domestic lunchtimes will see slightly higher use than domestic mid-morning.

    Of course, this is the UK and we'll fuck it up. But it has the potential to be good.

  • Of course, this is the UK and we'll fuck it up. But it has the potential to be good.

    I suspect that there will be unintended consequences (or intended, who knows) that end up massively disadvantaging those that are the least equipped to deal with them.

  • Also. time to invest in big batteries / energy stores.

    Imma build one of these in the back garden:

  • This is what Octopus Agile tarif does, priced in 30 min blocks which are decided the day before. Lots of variables, including negative pricing at (fairly rare) times.

  • There's obviously the concern that granular data could be very useful in the wrong hands. Electricity usage can give a good indicator whether or not the property is occupied.

    Also, that suggested tariff seems pretty beneficial for those working from home which, I would guess, are the more affluent workers.

  • The daily update would already reveal that stuff.

    A house occupied for 12 hours, 24 hours, or 0 hours already reveals that through energy usage, even if the update period is measured in weeks rather than smaller increments.

  • Ugh... I feel I'm going too far, but yet to not do so feels dumb.

    I've basically accidentally de-Googled my life.

    So far I've moved email to Fastmail, calendar to Fastmail, Google Drive has been replaced by Syncthing, Maps I use whilst logged out, authenticator has been replaced with Aegis (Android), and password manager with Bitwarden.

    But now I've even stopped using Chrome, am using VPN more, relying on NoScript and Firefox.

    Seems weird... what started were concerns that I'd made my email account too powerful and that all my eggs were in one basked (a basket where an automated script might find me in breach of some undefined rule and then rescind all access to the account).

    Has now been further reinforced by reading about the sheer breadth of tracking that is being undertaken and how they're making blocking it really hard.

    No real point to this comment except to say that my prior posts are out of date... my approach to being online is evolving. And LFGSS is one of the very few properties I trust online.

  • I started that process a few years ago but it's too much of a headache and I stayed on gmail, etc.

  • Fastmail made it so easy I ended up further down the road than I really intended. Kinda just carrying on now I have momentum.

  • I've basically accidentally de-Googled my life.

    What sort of phone do you have?

    De-googling that (unless it's Apple) is the real fun.

  • Yeah, I had all my mail in fastmail trial account and then just didn't use it so never moved forward with it. I dread to think how many sites I'd need to change email on and I have a bunch of other email addresses that forward to my main one. Urgh

  • Android still, a Pixel.

    I thought it couldn't be anything else... I was too heavily into Google. But for a couple of years now I've been replacing apps with links to web pages (i.e. even Deliveroo on my mobile is a link to a web page), and I've changed my default browser to Firefox, and I run NoScript with that, and then have NextDNS as my Private DNS. It's suprising how few apps one really genuinely needs.

    I can't consider Apple as they only allow Safari. I do feel open to a rooted Android now.

    The last Google things I have are the phone, and the Google Nest things. I could live with keeping the accounts on the smart home hardware, it's dumbed down by my lack of other stuff and microphones are off by default (I use my phone).

    The phone doesn't feel as critical as it once was in this equation.

  • I've also been gradually edging away (although not to that extent). Maps is a difficult one to move away from though, I have a lot of stuff starred from over the years and I don't know if there are any decent alternatives out there.

    I'm still surprised by the amount of targeted advertising I get given I'm running adblockers and NextDNS.

  • I'm very bored with LastPass only on one device now and should probably do something about it- a) is Bitwarden multi device and b) is it possible/easy/safe* to transfer passwords from lastpass to bitwarden?

    *for a bit of a luddite.

  • Bitwarden is effortless to migrate over... you export a text file from Lastpass and import into Bitwarden.

    I recall carefully checking a few passwords that contained special characters like % and & before nuking Lastpass just to re-assure myself.

  • Post a reply
    • Bold
    • Italics
    • Link
    • Image
    • List
    • Quote
    • code
    • Preview
About

Encrypt all the things!

Posted by Avatar for Velocio @Velocio

Actions