Privacy &Security

About the background image...

Privacy intrusion issues range from the simply annoying spam and telemarketing calls, to spyware and the individual-damaging identity theft, to the widespread destruction caused by viruses and other cyber-pathogens. The threats are well-documented elsewhere and I won't attempt to replicate the information here, but rather will share with you the better of the resources I have found.

Kimberly's Picks
419 Scams
Anti-Spam Resources
Anti-Scam Resources
Browsers, Browsing & Surfing
Corporate Security Sites
Heavy-Duty Reading
Identity Theft &Phishing
Internal Resources
Links
Miscellaneous Resources
Network Intrusions
Periodic Actions To Take
PGP
Recommended Reading
Spyware
Theory
U. S. Government Resources
Virus Resources
Resources for Webmasters & Webmistresses

Kimberly's Picks

SpyWareGuide http://www.spywareguide.com/product_list_full.php List of intrusive software
Privacy Rights Clearinghouse http://www.privacyrights.org/ Comprehensive Information on a variety of privacy topics
Pest Patrol – The Center for Pest Research http://www.pestpatrol.com/PestInfo/
National Cyber Alert System http://www.us-cert.gov/cas/tips/ST04-008.html about using BCC in email

419 Scams – aka Nigerian Fraud

http://www.snopes2.com/inboxer/scams/nigeria.htm
http://home.rica.net/alphae/419coal/
http://www.419eater.com/html/joe_eboh.htm
http://www.secretservice.gov/alert419.shtml
The Inboxer Rebellion http://www.snopes2.com/inboxer/

Anti-Scam Resources

Better Business Bureau Online homepage http://www.bbbonline.org
Lookup BBB Privacy Participants http://www.bbbonline.org/consumer/pribrowse.asp
Lookup BBB Reliability Participants http://www.bbbonline.org/consumer/Relbrowse.asp
NetScams http://www.netscams.com/
ScamBusters http://www.scambusters.com/
-...and browse their back issues http://www.scambusters.org/backissues.html
Victims Against Scams http://www.victimsagainstscams.com/
Senior Investor Resource Center/Scams http://www.nasaa.org/nasaa/sirc/sirc.asp
Fraud Bureau http://www.fraudbureau.com/
SEC: How to Avoid Internet Investment Scams http://www.sec.gov/investor/pubs/cyberfraud.htm
Committee for the Scientific Investigation of Claims to the Paranormal http://www.csicop.org/
Daily updates on their website, subscribe to alerts & newsletters http://www.fraudwatchinternational.com/

<Top>

Anti-Spam Resources

Coalition Against Unsolicited Commercial Email http://www.cauce.org/
http://spam.abuse.net/
http://www.telebyte.com/spamlaw/
http://www.spamreaper.com/
http://spam.getnetwise.org/
How spammers get your email address http://www.klis.com/support/kwikshield/outexpr.html
List of All Known DNS-based Spam Databases http://www.declude.com/Articles.asp?ID=97
Spam Database Lookup http://www.DNSstuff.com/ Check an IP address in multiple databases
Spam laws by state http://www.spamrecycle.com/lawintro.htm
A Guide to Combating Spam http://www.webopedia.com/quick_ref/SpamGuide.asp
http://spamlinks.openrbl.org/spamlinks.htm "everything you didn't want to have to know about spam"

Browsers, Browsing & Surfing

Sites that I block in my browsers, for varying reasons:
http://www.gratisnetwork.com/
http://www.makemoneyonline.com/


Corporate Security Sites

Note: I started to build this after receiving one-too-many scam/phish emails requesting account info, etc, even from instititions where I had no accounts. This is to facilitate my reporting these scams to the appropriate people. I always forward the email in question to the organization in question and the general phishing resources listed at the end.

Organization: Security Page: Report Phish/Fraud/Scams:
Bank of America http://www.fdic.gov/consumers/consumer/fighttheft/index.html Forward email to abuse@bankofamerica.com
Citicorp Forward email to spoof@citicorp.com
Citizens Bank http://www.citizensbank.com/misc/prevention_center.asp Forward email to fraud_prevention@citizensbank.com
Huntington Bank Forward email to idtheft@huntington.com
PayPal https://www.paypal...security-center-outside https://www.paypal.com/wf/f=sa_fake
Smith Barney Forward email to spoof@citicorp.com
Suntrust Bank http://www.suntrust.com/common/security/security.asp Forward email to abuse@suntrust.com or go to http://www.suntrust.com/common/security/fraudform.asp
Washington Mutual http://www.wamu.com/personal/welcome/security.htm Forward email to spoof@wamu.com
Bank of the West http://www.bankofthewest.com/eb_os.htm Forward email to abuse@bankofthewest.com
General Phishing Resources: Always forward phish to these resources:
(Private organization) scams@fraudwatchinternational.com
Federal Trade Commission uce@ftc.gov

<Top>

Heavy-Duty Reading

NIST Computer Security Resource Center Guide to Information Technology Security Services
http://csrc.nist.gov/publications/nistpubs/800-35/NIST-SP800-35.pdf
Very good papers on security topics http://www.technicalinfo.net/papers/index.html

Identity Theft & Phishing

Identity Theft Resource Center http://www.idtheftcenter.org/index.shtml
Identity Theft http://www.consumer.gov/idtheft/
Identity Theft Complaint Form https://rn.ftc.gov/dod/widtpubl$.startup?Z_ORG_CODE=PU03
Reducing the risk and coping with the occurrence http://www.privacyrights.org/fs/fs17a.htm
FDIC has good downloadables http://www.fdic.gov/consumers/consumer/fighttheft/index.html
The major credit reporting agencies:
Equifax http://www.equifax.com/ Report fraud 800.525.6285; Request credit report 800.685.1111
Experian (formerly TRW) http://www.experian.com/ 888.397.3742
Transunion http://www.transunion.com/ Report fraud 800.680.7289; Request credit report 800.888.4213

Internal Resources

International Calling Codes and GMT offsets
United States Telephone Area Codes
Reporting Spammers

Links

Good set of metalinks http://www.netscams.com/links.jsp
Lots of good links: http://www.microsoft.com/security/

Miscellaneous Resources

Report Cybercrime in Virginia cybercrime@oag.state.va.us
Center for Democracy and Technology http://www.cdt.org/
Center for Security Policy http://www.centerforsecuritypolicy.org/
Cyberstalking http://www.haltabuse.org/
Direct Marketing Assn http://www.dmaconsumers.org/cgi/offtelephonedave
Forum of Incident Response and Security Teams http://www.first.org/
FIRST Member Information http://www.first.org/team-info/
Freedom of Information Center http://foi.missouri.edu/
Getnetwise – Good privacy & safety site http://www.getnetwise.org/
Global Security http://www.globalsecurity.org/
Hoaxbusters (and viruses) http://hoaxbusters.ciac.org/
More on hoaxes & viruses http://securityresponse.symantec.com/avcenter/hoax.html
More on hoaxes & viruses http://www.vmyths.com/
More on hoaxes & viruses http://www.snopes.com/computer/virus/virus.htm
AT&T's Privacy Bird http://privacybird.com/
Electronic Privacy Information Center http://www.epic.org/
http://www.kgb.org/kgb/glossary.html
http://www.spywareinfo.com/
Junkbusters – Telemarketing, spam, junk mail, etc http://www.junkbusters.com/
Lots of good links: http://www.microsoft.com/security/
Privacy.net - excellent information and tools http://privacy.net/
Surveillance Technology http://www.eskimo.com/~joelm/tempest.html
Insurance Fraud information http://www.insurancefraud.org/protect_yourself_set.html
http://www.consumerprivacyguide.org/
Computer vulnerabilities http://www.securitytracker.com/
National Security Archive http://www.gwu.edu/~nsarchiv/
SANS (SysAdmin, Audit, Network, Security) http://www.sans.org/aboutsans.php
SANS' Information Security Reading Room http://www.sans.org/rr/
How to Stop Porn Predators http://www.safesurf.com/newsletter/issue1101.htm
Macintosh Security http://www.securemac.com/
Maps of surveillance cameras locations in several major U. S. cities http://www.notbored.org/maps-usa.html
Privacy Activism http://www.privacyactivism.org/ Lots of good info, but not the late-breaking news
International Calling Codes and GMT offsets
United States Telephone Area Codes
Reporting Spammers
http://www.quackwatch.org/ index.html "...combat health-related frauds, myths, fads, and fallacies."
Information Systems Security Association http://www.sdissa.org/index.html

<Top>

Network Intrusions

Distributed Intrusion Detection System http://www.dshield.org/
Network Abuse Clearinghouse http://www.abuse.net/
Intrusion & Attack Reporting Center http://www.doshelp.com/
Distributed Server Boycott List http://dsbl.org/main
Abusive Hosts Blocking List http://www.ahbl.org/
http://www.snopes2.com/inboxer/scams/nigeria.htm
http://home.rica.net/alphae/419coal/
http://www.419eater.com/html/joe_eboh.htm
http://www.secretservice.gov/alert419.shtml
The Inboxer Rebellion http://www.snopes2.com/inboxer/
Blacklist, blocklist primer http://www.scconsult.com/bill/dnsblhelp.html

Periodic Actions to Take

Update to Windows operating systems http://v4.windowsupdate.microsoft.com/en/default.asp Monthly!
Check this site for product security updates http://secunia.com/ Secunia tracks vulnerabilities in over 4k products Product List
Quick links for a few browsers:
Internet Explorer 6
iCab 2.x
Opera 7.x
Safari 1.x
Netscape 7.x

Symantec online security check http://www.symantec.com/securitycheck/ Weekly!
Microsoft Baseline Security Analyzer http://www.microsoft.com/technet/security/tools/mbsahome.mspx Monthly

Public Key Encryption – PGP Links

http://www.openpgp.org/
http://www.pgp.com/
http://www.pgpi.org/
PGP 7.0 Mac User's Guide ftp://ftp.pgpi.org/pub/pgp/7.0/docs/english/PGPMacUsersGuide.pdf
Phil Zimmerman, creator of PGP http://www.philzimmerman.com/index.shtml
http://helppages.obsidian.com.au/PGPKeys

Recommended Reading

A Parent's Guide To Internet Safety http://www.fbi.gov/publications/pguide/pguide.htm
Request the Newsletter from Anonymizer http://www.anonymizer.com/
Article on Cyberstalking http://www.firstmonday.org/issues/issue8_9/mcfarlane/index.html
Brochure on Cyberstalking http://www.haltabuse.org/onlinesafety.PDF
Why Windows Is A Security Nightmare http://www.techuser.net/index.php?id=47


<Top>

Spyware Resources

SpyBuster http://www.nitrousonline.com/ Weekly!
SpyCop http://www.spycop.com/
SpyWareGuide http://www.spywareguide.com/product_list_full.php List of intrusive software


Theory

The Institute for Information Infrastructure Protection http://www.thei3p.org/
Institute for Security Technology Studies http://www.ists.dartmouth.edu/index.htm

U.S. Government Resources

DOJ Computer Crime and Intellectual Property Section http://www.usdoj.gov/criminal/cybercrime/compcrime.html
FBI Internet Fraud Complaint Center http://www1.ifccfbi.gov/index.asp
Internet Fraud Complaint Center of the FBI http://www1.ifccfbi.gov/index.asp
NIST Computer Security Division: Computer Security Resource Center http://csrc.nist.gov/
National "Do Not Call" registry http://www.donotcall.gov/Register/Reg.aspx
...and what appears to be a private adjunct to it http://donotcall.com/
National Infrastructure Protection Center http://www.nipc.gov/
NSA's Security Configuration Guides http://www.nsa.gov/... for a variety of products/platforms
U. S. Computer Emergency Readiness Team http://www.us-cert.gov/
"...improving computer security preparedness and response to cyber attacks in the United States."
http://www.us-cert.gov/cas/tips/index.html A wealth of computer security articles in everyday terms

CVE – Common Vulnerabilities & Exposures http://www.cve.mitre.org/
"A list of standardized names for vulnerabilities and other information security exposures"

OVAL – Open Vulnerability Assessment Language http://oval.mitre.org/
"The common language used by security experts to discuss technical details about how to check for the presence of a vulnerability on a computer system."

ICAT Metabase – For searching CVE http://icat.nist.gov/icat.cfm

Cassandra Tool https://cassandra.cerias.purdue.edu/main/index.html
"Simplifies keeping up-to-date with vulnerabilities in the ICAT or Secunia databases."

Virus Resources

Fairly comprehensive information on viruses http://www.unl.edu/security/viruses/
McAfee AVERT Virus Information Library http://vil.nai.com/vil/default.asp
Quickly find the date of McAffee's (Virex) latest definitions http://configuration.apple.com/configurations/......txt
The result will be a single record in the form of... idisk.mac.com/...Anti-Virus Updates/VnYYMMDD.gz
Very good resources http://anti-virus.com/
Cert Coordination Ctr. of the Software Engineering Inst. at Carnegie Mellon http://www.cert.org/
Sophos http://www.sophos.com/virusinfo/
http://www.grisoft.com


Resources for Webmsters & Webmistresses

http://www.scanalert.com/ Examines sites periodically for evidence of hacking
http://www.wholesecurity.com/ Provides behavior-based analysis for web site poseurs

<Top>

Last updated 05-04-14 19.53.20