Showing posts with label email. Show all posts
Showing posts with label email. Show all posts

Tuesday, 24 September 2013

LinkedIn denies harvesting user email accounts without permission

LinkedIn denied charges that the company breaks into the email accounts of its members without permission to harvest contacts’ addresses.

A class action complaint by four users has charged the professional networking site with hacking into their external email accounts and downloading addresses of their contacts for monetary gain by repeatedly promoting its services to these contacts.

Paul Perkins, Pennie Sempell, Ann Brandwein, and Erin Eggers charged LinkedIn with breaking into “its users’ third party email accounts, downloading email addresses that appear in the account, and then sending out multiple reminder emails ostensibly on behalf of the user advertising LinkedIn to non-members.”

The so-called hacking of the user’s email account and download of addresses is done without “clearly notifying the user or obtaining his or her consent,” which is likely to emerge as the crux of the case.

LinkedIn does not access a user’s email account without the user’s permission, and claims that it hacks or breaks into members’ accounts are false, Blake Lawit, senior director of litigation at LinkedIn wrote in a blog post on Saturday. LinkedIn never deceives by “pretending to be you” in order to access the user’s email account, Lawit wrote.

“We never send messages or invitations to join LinkedIn on your behalf to anyone unless you have given us permission to do so,” he added.

New users signing in to LinkedIn are asked for the external email address as their user name, though they aren’t told what it will be used for, according to the complaint filed last week in U.S. District Court for the Northern District of California.

If a LinkedIn user leaves an external email account open, LinkedIn is said to pretend to be that user and downloads the email addresses in that account to LinkedIn servers, according to the complaint. Linkedln is able to download the addresses without requesting the password for the external email accounts or obtaining users’ consent, according to the complaint.

If the LinkedIn user has logged out from his email applications, the network requests the user name and password of an external email account to ostensibly verify the identity of the user, and then, without notice or consent, attempts to access the user’s external email account to download email addresses, according to the complaint.

Linkedln does not inform its users that email addresses harvested from a user’s external email account will be sent multiple emails inviting the recipient to join Linkedln with the user’s endorsement, the complaint said. Users have complained to Linkedln about its “unethical harvesting” of email addresses and repeated spamming of those addresses, according to the complaint, which asks the court for damages and an order prohibiting LinkedIn from continuing its “wrongful and unlawful acts.”

John Ribeiro covers outsourcing and general technology breaking news from India for The IDG News Service.
More by John Ribeiro, IDG News Service


View the original article here

Monday, 2 September 2013

Even suspicious email is too tempting to skip, survey finds

In a study conducted by TNS Global for Halon, an email security service, 30 percent of those surveyed admitted they would open an email, even if they were aware that it contained a virus or was otherwise suspicious.

The study included only 1000 adults within the U.S., so this isn't a national index by any means. But of those surveyed, one in 11 admitted to having infected their system after they opened a malicious email attachment. Given the fact that email is still an easy way for attackers to gain access to the network, often via social engineering (phishing/spear phishing), the survey's results are somewhat alarming.

The reasons given for accessing the messages are telling: For women, the survey results marked messages containing invitations from social networks as the most alluring, while men were tempted messages with the time-tested suggestions of money, power, and sex. More often than not, the malicious messages claimed to be from banking institutions (15.9 percent), social media sites like Facebook or Twitter (15.2 percent), and online payment services, like PayPal (12.8 percent).

According to the stats form the Anti-Phishing Working Group (APWG), in its 2013 First Quarter report, there were more than 74,000 unique phishing campaigns discovered during the reporting period, leveraging over 110,000 hijacked domains and targeting more than 1100 brands.

Based on the data reported by the APWG and various security vendors, Phishing kits are rather inexpensive and the time to develop a workable campaign is rarely longer than a few hours. So the numbers mean that the attack surface is large, and the pool of potential victims is rather full. Combine this with a reported 30 percent success rate, and the criminals behind these campaigns are more than likely pleased with their return on investment.

Still, Halon's study is focused on the consumer, so how do these figures translate to the corporate world? The simple answer is directly, because users who open malicious attachments at home are often the ones who do so at the office too.

To be sure though, CSO contacted two experts on the topic of social engineering: Chris Hadnagy, the President and CEO of Social-Engineer, Inc.; and David Kennedy, the creator of the Social Engineer Toolkit and the founder of TrustedSec. We asked them a few questions about what they do and their opinions about the Halon study.

phishing

"It is important to remember that as an attacker, often, all I need is one person with a vulnerable browser or software or client and that can give me access to click. So from an attackers perspective, a 30 percent success rate is great number for broad attacks," Hadnagy said.

In agreement, Kennedy said that when his firm stages attacks against large organizations, with customers in the Fortune 50 to Fortune 1000, their success ration is around 94 percent. The difference between what he does for his customers and what the criminals are doing with the previously mentioned malicious messages is focus.

The attackers in the Halon study are casting a wide, generic net for victims, and are still able to pull a 30 percent success rate. Those numbers will only climb if the messages are less generic and more finely tuned.

"It only takes about an hour or so to craft up a 'pretext' or attack that we know will be believable. It only takes the employee to believe the fantasy is real in order for them to click something...these are completely obscure emails that have no relevance or believability in a lot of cases and it's still a 30 percent success ratio...For us, the attacks have moved from the external perimeter to the [social engineering] route because of the ROI," Kennedy said.

In their day-to-day work, both Kennedy and Hadnagy seek to lower the ROI many attackers are seeing though social engineering. Each of their respective firms use ongoing training and education in order to accomplish this. Humans are the weakest link in the security chain, so there isn't an appliance or solidly technical control available to prevent focused Phishing attacks (spear phishing) or to stop someone from doing as the attacker has asked one-hundred percent of the time.

"I think the alarming trend in all of this is that we are literally defenseless right now with our current technology or procedures to handle these types of attacks," Kennedy explained.

"The problem with this one is that no piece of technology can fix this alone. It's a coupling of education and awareness, handling procedures, and technical controls on the user population. Our daily lives revolve around opening up emails at a rapid response rate, clicking just this one or that one has no relevance anymore and to take a few extra seconds to review the email isn't part of our daily tasks."

What about the topics of the messages referenced in the study, and the brands represented, is that typical? According to Hadnagy, when humans see emails that hit on things that are on our minds, we're more inclined to click.

"It is basic psychology that they use social media for women and money/power/sex for men as lures... Although highly targeted attacks may use a different lure, tuning into the psychology of the intended victim plays a significant role in a successful lure," he said.

Adding a corporate example to this, Kennedy told the story of one campaign where they used the customer's health benefits program as a lure. The point, he explained, is that whenever an attacker can impact someone personally, there is a higher degree of success. Health benefits issues would impact someone personally, and they fall in-line with normal day-to-day business operations, so as expected, people took the bait.

"If health benefits are in jeopardy and they need to do something that will take two minutes out of their lives to remediate and fix, they will do it without rhyme, reason or thought," Kennedy said.

"[Social engineering] is effective, it's the most effective, and has the most ROI for an attacker. The reason we don't hear about these more in the news is that we have nothing to detect these attacks. We're already compromised, we've already experienced it, and we just don't know it yet."

How serious is this threat? Serious enough that even the professionals can be caught by social engineering tactics. As previously covered on CSO, Hadnagy ran the Social Engineer Capture the Flag (SECTF) contest at DEF CON this year. While answering our questions for this story, he shared an interesting anecdote.

As he was preparing for the DEF CON contests and a four-day training class at Black Hat, Hadnagy had made a large amounts of purchases from Amazon in order to procure the supplies needed. To make things easy, said supplies were then shipped to the hotels in [Las Vegas].

"Rushed, behind the 8-ball and trying to get 500 things done at once I [wasn't] thinking when I received an email that said: 'One of your Amazon Purchases was declined&.'. I almost clicked through until I double-checked the URL and saw it went to a [domain] in Russia," he explained.

"Even someone who does this for a living can fall for these things. Why? We are all human. No one is 100 percent all the time. Condition, psychology, curiosity, fear, greed—these are common themes that attract and make us react. I think this sounds typical for most people."


View the original article here

Indian bureaucrats may be asked not to use private email services for official work

The Indian government is expected to require that Indian bureaucrats use email service provided by the National Informatics Center for their official work, as it tries to secure its communications infrastructure.

The requirement will be part of a proposed new email policy, said sources in government who declined to be named.

India's Minister for Communications and IT, Kapil Sibal, told Parliament about a week ago that the government had decided that all its embassies would use mail servers from the government's National Informatics Centre, which will be installed in the embassies and directly linked to a server in India.

The minister was responding to concerns from the opposition about reports of large scale surveillance of telephone calls and emails by the National Security Agency in the U.S. Former NSA contractor Edward Snowden disclosed through newspapers certain documents that suggested that the NSA had real-time access to content on the servers of Internet companies. The companies have denied their participation in the program.

The Indian government appears to have been very lax on security, despite having an email service from the NIC, with some ministers listing their Gmail addresses on their websites. It is not known whether they use these addresses for official communications as well.

Google did not comment on the move by the government to require bureaucrats not to use private services for official email communications. "We don't comment on speculation," a Google spokeswoman said.

According to Indian parliamentary records, Sibal last month told Parliament: "We are stating in that [email] policy that it is mandatory for the Government of India officials stationed at Embassies or working in Missions abroad, deputationists to only use static IP Addresses, Virtual Private Networks (VPNs), One-time Password for accessing Government of India e-mail services." He assured the members of the upper house, called the Rajya Sabha, that the email will be encrypted so that nobody else will be able to access it besides the Indian government.

Some officials are recommending that the email servers for the government employees be managed by the individual government departments on their own rather than giving all the responsibility to NIC, the sources said.

John Ribeiro covers outsourcing and general technology breaking news from India for The IDG News Service. Follow John on Twitter at @Johnribeiro. John's e-mail address is john_ribeiro@idg.com

John Ribeiro covers outsourcing and general technology breaking news from India for The IDG News Service.
More by John Ribeiro, IDG News Service


View the original article here

Thursday, 29 August 2013

Usage for Tor doubles in wake of secure email shutdowns, arrival of the PirateBrowser

The Tor anonymity network is enjoying a massive uptick in popularity after two significant privacy-minded events took place earlier this month

First, there were the sudden shutdowns of Lavabit and Silent Circle, two secure email providers that voluntarily closed their doors on Thursday, August 8, rather than allow the U.S. government access to their users’ messages.

On August 10, mere days after Lavabit and Silent Circle took one for the team, the popular Pirate Bay file-sharing site released its PirateBrowser, a web browser that allows users to hop onto the Tor network in order to circumvent government firewalls to access torrent sites and other banned parts of the Web.

By August 18, the number of users accessing the Tor network started creeping up, and it has only climbed higher and higher (and higher) since. Tor now regularly sees more than twice as many daily users as it did before the email shutdowns and the PirateBrowser’s release.

Tor ProjectTor’s daily users skyrocketed just after Lavabit and Silent Circle shut down.

While the PirateBrowser and standard Tor software both rely on the Tor network, they use it in very different ways.

Once you’ve installed Tor’s software on your PC—most often in the form of the Tor browser bundle—the service allows you to surf the web anonymously by encrypting your Internet connection requests and bouncing them between numerous “relay nodes” before finally sending them on to the final destination.

No node knows the identifiable information of any nodes in the chain aside from the ones they’re taking information from and passing information to and., just to be on the safe side, each hop along the way gets a whole new set of encryption keys.

“The idea is similar to using a twisty, hard-to-follow route in order to throw off somebody who is tailing you—and then periodically erasing your footprints,” explains the Tor website. All the hip-hopping makes for a very secure (yet very slow) browsing experience, assuming you’re smart about your usage habits. It’s also great for bypassing government firewalls.

Tor’s “onion-routing” technology also enables the creation of “hidden services,” or websites that can also hide their server identity from its users and are only accessible while using Tor. This extreme level of anonymity makes the so-called “Onionland” darknet a haven—not only for seedy types, but also for people who want (or need) to stay anonymous, such as political dissidents and whistleblowers—the type of people who may have relied on Lavabit and Silent Circle previously.

[Now read: Meet the Darknet, the hidden, anonymous underbelly of the Web]

The PirateBrowser behaves a bit differently, however. From its website:

No, it’s not intended to be a TOR Browser, while it uses the Tor network, which is designed for anonymous surfing, this browser is ONLY intended to circumvent censorship. The Tor network is used [in the PirateBrowser] to help route around the censoring/blocking of websites your government doesn’t want you to know about.

To drive home the point that the PirateBrowser isn’t designed for anonymity, it doesn’t include the encryption-providing “HTTPS Everywhere” plugin found in the Tor Bundle.

Additionally, the PirateBrowser only accesses Tor when you’re using the browser to try to access a blocked website. Non-blocked websites are delivered to your browser normally, rather than hopping all around.

While the drastic uptick in usage is probably mostly attributable to the PirateBrowser—the Pirate Bay’s custom browser was downloaded more than 100,000 times in a matter of days—the Lavabit and Silent Circle shutdowns likely also drove privacy-minded people further underground.

Tor itself isn’t an email provider, though—it’s just anonymizing routing technology, pure and simple. What’s more, the most popular Hidden Service email provider in Onionland, Tormail, was recently killed by the U.S. government. It was collateral damage in the takedown of a service provider hosting many of the Web’s child pornography sites.

That’s not to say Tor can’t be used to send secure messages online, however.

Signing in to a webmail account while using Tor will obviously give your identity away, but using Tor in conjunction with dummy email accounts and PGP encryption would deliver a relatively strong level of privacy. Privacy buffs can also take advantage of Onionland’s messaging services, which deliver a very high level of anonymity.

No matter what accounts for Tor’s dramatic spike in popularity, one thing’s for certain: More people than ever are turning to technology to spite Big Brother.

Via Reddit

Brad Chacos spends the days jamming to Spotify, digging through desktop PCs and covering everything from BYOD tablets to DIY tesla coils.
More by Brad Chacos


View the original article here

Thursday, 22 August 2013

Tech legal news site Groklaw shuts down because email privacy 'is impossible'

Technology legal news website Groklaw is shutting down due to concerns over the continued availability of secure email in the wake of revelations about U.S. government surveillance.

"The owner of Lavabit tells us that he's stopped using email and if we knew what he knew, we'd stop too," site founder Pamela Jones said in a farewell post Tuesday. "There is no way to do Groklaw without email. Therein lies the conundrum."

Groklaw, which was launched 10 years ago, has been known for its exhaustive coverage of technology law, particularly involving software patents, open source software and privacy issues.

Tuesday, 20 August 2013

NSA-dodging mail service explains why email can never truly be private and secure

Earlier this month, Lavabit and Silent Circle—two privacy-minded email providers—decided to shut up shop rather than give the U.S. government the chance to access to their customer data. Shortly thereafter, Lavabit owner Ladar Levison told Forbes, "If you knew what I knew about email, you might not use it."

This weekend, Silent Circle's Louis Kowolowski dropped the cryptic comments and explained a major, inherent vulnerability with email: metadata.

While encryption technologies like PGP and SMIME can be used to obscure the actual contents of a message, assuming you use a desktop program that supports encryption software, current email protocols don't allow you to secure the "header" metadata details that are used to shuffle email from point to point. The sender, recipient, subject, date and time, and even server path information is all sent along in clear text.

That's enough to be a liability to people who truly need privacy, according to Kowolowski.

If your goal is to not have metadata leakage in your otherwise secure communications, you may wish to avoid email altogether. Email leaks the information about who is communicating, and how often. This information may be just as damaging as the content of the email.

Snowden's leaks have shown that the U.S. government is aware of the power of metadata. The NSA collects Verizon's phone records to examine metadata and analyze call patterns, and the government does not need individual warrants to do so, as courts have classified metadata as "transactional data" rather than actual communications. Again, here's Kowolowski:

With the tapping of backbone internet providers, interested parties can now see all traffic on the internet. The days where it was possible for two people to have a truly private conversation over email, if they ever existed, are long over.

Since text, video, and messaging communications don't suffer from the same header needs as email, they're able to be secured from end-to-end, with all encryption and decryption handled on the client machines—and indeed, Silent Circle still offers "Silent Phone," "Silent Eyes," and "Silent Text" services that do just that. Check out our guiding to protecting your PC from Prism surveillance for more privacy-minded tips and tricks, or if metadata security means less than the message itself, read PCWorld's guide to securing your email.

Brad Chacos spends the days jamming to Spotify, digging through desktop PCs and covering everything from BYOD tablets to DIY tesla coils.
More by Brad Chacos


View the original article here

Review: Upload files to Dropbox via email with Send to Dropbox

If you’re looking for a simpler way to send content directly to Dropbox, Send to Dropbox has you covered. This free service generates an email address, and any attachments sent to that address are automatically saved to Dropbox.

The free version of Send to Dropbox doesn’t allow you to create a custom address.

Getting started with Send to Dropbox is a breeze: You just connect it to your Dropbox account and it instantly generates an email address for you. Remembering this may be a challenge, though. My address contained a short but random string of numbers and letters.

Upgrading to the $29-per-year Pro account gives you the option of customizing your email address, which is a nice feature for business users, especially those who may want to share the address with colleagues. The Pro account also lets you create multiple addresses, and an email whitelist, so you can control who can send files to your Dropbox.

By default, Send to Dropbox saves your files to a new folder it creates in your Dropbox called “Apps/Attachments.” You can change this filename and add subfolders that contain the name of the sender and the subject line, if you prefer. However, you can’t share this folder with other Dropbox users, as it is a special type of folder for Dropbox applications.

By default, Send to Dropbox saves files to a folder it creates, but you can create subfolders in there, if you’d like.

In my tests, all of the attachments sent to my Send to Dropbox address appeared in Dropbox almost instantly, and were organized in the folders I’d selected. If you’re looking for a quick and easy way to send files to Dropbox, Send to Dropbox can’t be beat.

Liane Cassavoy is a veteran technology and business journalist. She contributes regularly to PCWorld and has written about business issues and products for Entrepreneur Magazine and other publications. She is the author of two business start-up guides published by Entrepreneur Press.
More by Liane Cassavoy


View the original article here

Monday, 19 August 2013

Review: Cloze prioritizes email by strength of relationship

Cloze Cloze offers interesting insights into some of your most important online relationships, but its value as an inbox tamer is limited.

Download Now

Cloze is supposed to help you deal with inbox overload, but I have to admit that this free service initially made me a bit anxious. After using it for a while, though, I came to appreciate its relationship-centered approach to email and social networking.

Cloze overall scoreSomehow, an overall of Cloze score of 47 didn't seem very impressive.

This Web service reduces the noise and clutter of messaging overload by focusing on your relationships with correspondents. It doesn't stop at email, either: Cloze works with the Facebook, LinkedIn, and Twitter social networks as well. When you connect an account to Cloze, it pulls in all of the communications you've had with your contacts, and then presents your email messages to you arranged by contact—and their presumed importance to you—not by the medium from which the communication hails.

Cloze delivers your messages in a daily digest, but you can also access them anytime from the Web app or the iOS app…and it was the Web app that that caused my first pangs of anxiety. They were caused by my overall Cloze score, which was 47 out of 100. Cloze tells you that your Cloze scores is a measure of your relationship quality, with a score of 70 indicating a very strong relationship over time.

Thanks to this dispiriting number, I began using Cloze already feeling as though I had a lot of catching up to do. I felt better when I saw that Cloze rated my individual relationships much higher, and I like how it breaks down these relationships by the day, so you can see how they change over time. By default, Cloze identifies 25 key people as "the people you need to keep an eye on," which is based on the strength of your relationship with them across your various platforms. And this was where I felt Cloze stumbled a bit.

Cloze contact detailCloze offers a terrific amount of detail on the people you contact most frequently.

It rated some folks as very high, simply because I was in contact with them frequently, but not because the quality of the correspondence was high. For example, the secretary at my children's school was listed as a key person for me. She emails often, as she is responsible for sending home all updates to the families at the school. But I rarely respond, and am not in contact with her on any social network, and while the messages she sends are valuable, I would not consider her a key contact.

Luckily, Cloze lets you add and remove contacts from this list of key people, and I like all of the details it offers on the folks you're in touch with. It rates not only the overall relationship with a contact, but also the frequency, dormancy, responsiveness, privacy, freshness, and balance that the relationship has—based on your online interactions, of course.

Cloze iOS interface on Sprint iPhoneCloze on the iPhone delivers a great experience for keeping up with messages and contacts.

It also shows you recent messages and related people, all of which would be very helpful to a businessperson looking to cultivate a relationship. But it can't measure the quality of your offline relationship, so if you're frequently texting, talking on the phone, or seeing each other in person, your relationship is likely much stronger than Cloze realizes.

Its mobile companion was far more useful for keeping up with my messages, though. Browsing your email on the small screen of an iPhone or with the less-than-perfect email client installed on the iPad can be frustrating, so I liked using Cloze's mobile app instead of default clients on my iOS devices.

Overall, I didn't find Cloze a true tool for eliminating email overload, especially when using the Web app. On iOS, Cloze made it easier to find messages and other correspondence from the folks I wanted to hear from, and offered plenty of options for browsing my messages. But on my desktop, I'll stick to my regular old email client for navigating my inbox, and will turn to Cloze only when I'm ready to take a look at where some of my key relationships stand.


View the original article here

Microsoft restores Outlook email after intermittent outage

Microsoft on Saturday apologized for a three-day partial outage of Outlook.com and said the email service was back up and running, only to note hours later that problems still plagued some customers.

Early Saturday, the Redmond, Washington company said it had finally resolved Outlook.com's issues, which stemmed from a failure in a caching service of Exchange ActiveSync (EAS), the popular synchronization service widely used to sync smartphones and tablets with company email, contacts, and calendars stored on Microsoft Exchange Server systems.

"We want to apologize to everyone who was affected by the outage, and we appreciate the patience you have shown us as we worked through the issues," Microsoft said in a note appended to its services status board.

On Wednesday, Outlook.com, the SkyDrive cloud storage service and the Peoples contacts application suffered partial outages that began around 10 a.m. ET. While the Peoples problem was fixed about five hours later, SkyDrive's was not fully resolved until Thursday around 4 p.m. ET.

Some users of Outlook.com, however, were unable to access email on mobile devices that relied on EAS—a category that includes iPhones, whose iOS uses EAS for synchronization—until around 4:30 a.m. ET Saturday.

During the outage, Microsoft said, the cache service failure "caused these devices to receive an error and continuously try to connect to our service. This resulted in a flood of traffic that our services did not handle properly."

Microsoft said it had already taken steps to prevent similar problems in the future. "[We] have made two key changes ... one that involved increasing network bandwidth in the affected part of the system, and one that involved changing the way error handling is done for devices using Exchange ActiveSync."

The cache flood problem Microsoft described sounded reminiscent of the trouble earlier this year that the company documented in iOS 6.1-powered iPhones and iPads which affected not only on-premise Exchange servers within enterprises, but also Microsoft's own infrastructure, including its Office 365 subscription service.

But Outlook.com's problems were not completely behind it Saturday morning. Around 2:30 p.m. ET, Microsoft again logged a problem on the status board, saying, "A small percentage of mobile users may experience intermittent issues while syncing email."

As of 9 p.m. ET Saturday, that problem had not been resolved.

The Outlook.com outages were an embarrassment to Microsoft for multiple reasons, including a boast the week before that its Office 365 cloud-based service exceeded 99.9 percent uptime each of the last four quarters, and new attacks against rival Google Gmail in another run of its "Scroogled" campaign that kicked off Aug. 9.

Microsoft touts its own Outlook.com as an alternative to Gmail.

In fact, the latest Outlook.com outage was the second this year within weeks of a new Scroogled attack. In mid-March, about five weeks after a different Scroogled round, Microsoft's online email service went dark for about 15 hours.

Outlook.com has logged numerous interruptions in the last 60 days, including on June 14 and 27; July 1, 2, 3, 11, 12-14 and 25-26; and the event that began August 14.

Gregg Keizer covers Microsoft, security issues, Apple, Web browsers and general technology breaking news.
More by Gregg Keizer, Computerworld


View the original article here

Monday, 5 August 2013

Email security strongest from social media, report reveals

Email from social media brands is some of the safest on the Internet, while electronic posts from financial services brands is some of the riskiest, says a report released last week by an email security provider.

"Consumers may be worried about their privacy settings, but in terms of protecting consumers via email, social media is the clear leader," said the report from Agari, which analyzed more than a trillion emails during the second quarter of this year.

Agari uses that analysis to create a Trust Index for email in financial services, e-commerce, social media, travel, logistics, and gaming industries.

The index is based on a Trust Score—a reflection of the adoption and deployment of security measures in an industry to protect its customers from malicious email—and a Threat Score—which provides a measure of relative risk based on malicious activity and attempted attacks.

Social media led all industry sectors during the June quarter with a Trust Score of 73.1, out of a possible 100.

Ranking companies and industries based on the ThreatScore, and TrustScore benchmarks gives consumers and leading brands visibility into how aggressively a sector is being threatened and which companies are taking action to secure email and protect consumer data and trust, the report explained.

"Social media has been far more aggressive about protecting their customers and far more responsive to keep up with the technologies available to protect their customers," Agari founder and CEO Patrick Peterson said in an interview.

Among those technologies is DMARC (Domain-based Message Authentication, Reporting and Conformance), which Agari's report said can virtually eliminate brand abuse through fraudulent email attacks and drastically reduces the risks of consumer loss, reputation damage, and financial liability.

"A lot more people should be using DMARC because it allows administrators and organizations to be able to reject mail if it doesn't match certain parameters no matter where it says it's coming from," said Paul Ferguson, vice president for threat intelligence at Internet Identity.

Nevertheless, Ferguson was skeptical of the glowing grades given social media by Agari. "We see daily campaigns with emails harboring malicious content that's masquerading as DHL, Fedex, Dun & Bradsteet or social media like Facebook and Linkedin," he said.

In fact, social media may contribute to the problem by fueling a growing culture of interrupt-alerts that demand attention without forethought. "It allows bad guys to blend in with that noise," Ferguson explained.

Other sectors analyzed by Agari didn't fare as well as social media. "The most significant, but not at all surprising, discovery comes from financial services where there has been a huge spike in malicious activity, more than doubling from the prior quarter," the report said.

"In fact, consumers are seven times more likely to receive a malicious email from their bank than from any other type of company," it said.

Despite that spike, financial services still managed a Trust Score of 39.7, a seven percent jump over the previous quarter and significantly higher than the worst sector in the report: travel, with a score of 17.2.

"This sector, and the airlines in particular, is doing the least of all industries we analyzed to secure email and prevent their consumers from becoming victims of an attack," the report said.

"Even airlines like JetBlue that are well known for being leaders in delivering a better digital experience, are putting customers at risk with very little effort in preventing these types of attacks," the report added.

Agari also reported that many consumers do not realize that 95 percent of data breaches start with a phishing email. "I think we can safely say that after however years it has been, we've lost the battle of educating about threats," George Tubin, a senior security strategist with Trusteer, told CSOonline.

"We're just not going to be able to educate people to identify these things," he said.

"We need to keep educating, but the only way we're going to be successful with this is to fight these technology attacks with technology defenses," Tubin said. "We shouldn't be relying on human judgement to determine what's a legitimate email and what isn't."

John Mello writes on technology and cyber security for a number of online publications and is former managing editor of the Boston Business Journal and Boston Phoenix.
More by John P. Mello Jr


View the original article here

Thursday, 1 August 2013

Review: Alto mail organizer sorts your email like a pro

Alto Web-based email organizer Alto is currently in a free private beta, and it's worth queueing up for that beta.

Download Now

Alto is like an intern who sorts your email, separating the e-wheat from the e-chaff. This free browser-based service organizes mail into virtual stacks, not unlike the way you might sort physical junk mail into piles on your desk.

Developed by AOL, Alto works with the most popular email services, including Gmail, iCloud, Yahoo, and, of course, AOL. And you can use it with multiple accounts, making this a great way to manage several inboxes under one roof.

Alto Mail beta screenshotAlto helps manage your time by letting you archive messages to deal with later.

Once you sign in, Alto sifts through your inbox and sorts your messages into a handful of existing stacks: Daily Deals, Social Notifications, Photos, Attachments, and so on. You can create additional stacks as well, and once you direct an email to it, all future messages from that source will automatically land there. Thus, you could have a “client” stack, “boss” stack, “widget project” stack, and the like.

Alto’s pretty interface features a scrolling inbox on the left side that lets you preview each message without actually clicking it. If you mouse over an individual email, you’ll see one-click icons for Delete, Snooze, and Star. The Snooze option is particularly great for business users: It lets you temporarily archive an email until a later time, thus getting it out of your inbox but returning it to the top when it’s more convenient for you to deal with it.

Alto rocks. But it’s currently a private beta, meaning you need to request an invitation to try it out. The good news is that your invitation should arrive within about 24 hours, at least based on my recent experience.

Note: The Download button takes you to the vendor's site, where you can sign up to join the private beta of this Web service.


View the original article here

Win the inbox war: Four utilities fight email onslaught

Managing your inbox can feel like a full-time job, which is problematic given that you need all your time for your actual job. Like some crazed productivity Terminator, the email just keeps coming, all day, every day. If you’re not diligent about replying, filing, and deleting your messages, it won’t be long before you’re, well, terminated. Or at least terminally depressed.

But guess what? You don’t have to let your inbox win. New tools and services can help you tame that ever-expanding beast, making it easier to weed out the junk, highlight the important, and organize the rest—all without the hassle of manually creating a complex system of filters and folders.

Is such an attack plan really necessary? In these days of thoroughly indexed inboxes and fast, easy searches, the concept (and especially execution) of “inbox zero” may seem like more trouble than it’s worth. After all, when Gmail can locate any message you’ve ever received with just a few keystrokes, who cares about organization?

You’ll have to decide that one for yourself. But once you see how easily and effectively some of these solutions can whip your inbox into shape, you may decide it’s better to be proactive about mail management.

Ever wish you could hire an intern just to sort your email, to separate the e-wheat from the e-chaff? That’s the idea behind Alto, a free browser-based service that organizes mail into virtual stacks, not unlike the way you might sort physical junk mail into piles on your desk.

Developed by AOL, Alto works with the most popular email services, including Gmail, iCloud, Yahoo, and, of course, AOL. And you can use it with multiple accounts, making this a great way to manage several inboxes under one roof.

AltoAlto’s ability to temporarily archive messages until a more convenient time makes it particularly attractive for business users.

Once you sign in, Alto sifts through your inbox and sorts your messages into a handful of existing stacks: Daily Deals, Social Notifications, Photos, Attachments, and so on. You can create additional stacks as well, and once you direct an email to it, all future messages from that source will automatically land there. Thus, you could have a “client” stack, “boss” stack, “widget project” stack, and the like.

Alto’s pretty interface features a scrolling inbox on the left side that lets you preview each message without actually clicking it. If you mouse over an individual email, you’ll see one-click icons for Delete, Snooze, and Star. The Snooze option is particularly great for business users: It lets you temporarily archive an email until a later time, thus getting it out of your inbox but returning it to the top when it’s more convenient for you to deal with it.

Alto rocks. But it’s currently a private beta, meaning you need to request an invitation to try it out. The good news is that your invitation should arrive within about 24 hours, at least based on my recent experience.

Unlike most of the inbox-relief options in this roundup, Inky relies on actual software: It’s a desktop email client stocked with tools for better email management. However, that could be its downfall for some users: If you’re already vested in, say, Outlook, switching might not be a convenient (or even desirable) option.

It is compelling, though. Inky works with both IMAP and POP mail accounts and gives you the option of a unified inbox for as many accounts as you want to connect. Even better, it automatically filters certain types of messages into a variety of handy “Smart View” sub-inboxes: Daily Deals, Personal, Social, Subscriptions, Maps, and even Packages.

InkyInky’s Smart Views identify types of messages and sort them into relevant sub-inboxes.

The Packages inbox could help business users who constantly need to track package deliveries via confirmation emails, while the Personal inbox helps you zero in on important messages that might otherwise get lost in the business shuffle. I especially like the Notes inbox, which is where the email reminders you send to yourself get stored.

Inky looks almost too elegant for business use, and its heavy reliance on icons (not all of which are intuitive) steepens the learning curve. Thankfully, there’s an excellent guided tour that walks new users through the interface, and you can mouse over just about anything to get a pop-up descriptor. I found it much easier to navigate after expanding the side dock, which displays text labels alongside the icon for each section.

To help make sure the most important emails get noticed, Inky attempts to guess which ones are most relevant to you and tags them with a blue drop. The darker the drop, the more relevant the email—though you can easily fine-tune the results by clicking the icon. This should help ensure that messages from clients, coworkers, and other key people get immediate attention.

As PCWorld’s Yaara Lancet points out in her review of Inky, the program has a few bugs, but it still “shows immense promise and has real potential in revolutionizing the way you use email.” I’m not sure I’d give up Outlook for it, but I’ll agree it’s one of the best desktop mail clients to come along in years.

Frustrated by the roiling tornado that is your inbox? Mailstrom (get it?) aims to help you regain control by analyzing its contents, sorting the results, and giving you some tools to reduce the flow of mail. Admittedly, you can accomplish much the same thing using filters and targeted searches, especially in Gmail, but Mailstrom saves you the trouble.

The service, which operates in your browser, works exclusively with IMAP accounts, though for the moment you’re limited to three of them. I added AOL and Gmail accounts, then waited a few minutes to see the results.

Those results can be confusing at first. The Mailstrom dashboard lets you sort messages by sender, subject, lists, time, size, shopping, and social. When you click any of these view options, a middle pane lists the results from most to least. In the sender view, for example, you’ll quickly identify who sends you the most mail, because they’ll appear at the top of the list. You then click any sender to see a list of the messages from that person, which appears in a pane on the right.

MailstromMailstrom analyzes and sorts your email, but its inability to distinguish between read and unread messages is a major limitation.

Mailstrom gives you four key tools. For any given selected batch of messages, you can archive, delete, or mark as spam. You can also move them to another folder (in other words, out of your inbox), at the same time optionally creating a rule so that future messages land in the same spot. And if you’re looking at the Lists view, which shows any mailing lists you might be on (Groupon, stores, message forums, and so on), there’s an Unsubscribe button.

However, Mailstrom doesn’t distinguish between read and unread mail, which I found a serious limitation, and the color-coding it assigns to each filtered list of messages seems to serve no purpose. Plus, you can’t view individual accounts; the service lumps everything together.

Although PCWorld reviewer Liane Cassavoy liked Mailstrom a lot, I found it less helpful. I felt like I spent more time trying to figure out how to use the tool effectively than I would have simply processing my inbox the usual way. That said, it’s definitely worth a try, and for now the only cost is your time: Mailstrom is currently free.

Picture a bouncer stationed at the door to your inbox. VIP messages (like those from business contacts) get past the red-velvet rope; all others must stand in line. Outside. Like the undesirables they are.

That’s SaneBox in a nutshell. The service works with webmail clients like Gmail, iCloud, and Yahoo, and also Exchange, Lotus Notes, and Outlook, making it without question the most business-savvy inbox attacker in the group. I tried it with a Gmail account.

In a matter of seconds after I signed up (with nothing to install, thankfully), SaneBox had analyzed some 1500 messages and relegated roughly a third of them—those deemed unimportant—to a newly created SaneLater folder. So in one fell swoop, the size of my inbox shrank by more than 30 percent. However, I was still looking at a mix of business and personal mail in both locations; SaneBox analyzes based on communication history, not content.

SaneBoxWith support for Gmail, iCloud, Yahoo Mail, Exchange, Lotus Notes, and Outlook, and the ability "train” the filtering system, SaneBox is a powerful inbox manager.

Over time, as you drag messages between folders to “train” the filtering system, SaneBox will indeed keep the important stuff in your inbox and consign the rest to SaneLater. You can also add SaneBlackHole (a trash bin for senders you never want to see again), SaneTomorrow (which holds emails until tomorrow), and SaneNextWeek (which holds them until the following Monday). Need a custom “defer” folder? SaneBox lets you add those, too. The service even has a reminder option similar to that offered by Followup.cc., along with loads of other customization options to help steer mail to more desirable places. (Think: attachments automatically saved to Dropbox.)

Now for the bad news: SaneBox isn’t free, and it’s not exactly cheap, either. The $6-per-month Snack plan affords you just one email account, five of the aforementioned reminders, and five attachment routings. For $15 monthly, Lunch buys you two accounts and 250 each of reminders and attachments. And the $20-per-month Dinner plan supports three accounts and unlimited everything else. At least you can get price breaks if you prepay annually or biannually.

Still, you’ll have to decide if SaneBox’s bouncer is worth the expense. Gmail users in particular might prefer to roll their own "sane" inboxes via filters and labels, which cost a grand total of zero dollars. But if money is no object, SaneBox is perhaps the single best way to control email overload.

Some people can zero-out their inbox every day, and some people just can’t keep up. And then they give up. There’s no need to suffer alone, though. Inbox-taming apps like SaneBox, Mailstrom, and others can sort, filter, and prioritize emails, so you can spend less time scanning subject lines and more time responding to the messages that really matter—or doing other important work.

For more than 20 years, Rick Broida has written about all manner of technology, from Amigas to business servers to PalmPilots. His credits include dozens of books, blogs, and magazines. He sleeps with an iPad under his pillow.
More by Rick Broida


View the original article here

Win the inbox war: Four utilities fight email onslaught

Managing your inbox can feel like a full-time job, which is problematic given that you need all your time for your actual job. Like some crazed productivity Terminator, the email just keeps coming, all day, every day. If you’re not diligent about replying, filing, and deleting your messages, it won’t be long before you’re, well, terminated. Or at least terminally depressed.

But guess what? You don’t have to let your inbox win. New tools and services can help you tame that ever-expanding beast, making it easier to weed out the junk, highlight the important, and organize the rest—all without the hassle of manually creating a complex system of filters and folders.

Is such an attack plan really necessary? In these days of thoroughly indexed inboxes and fast, easy searches, the concept (and especially execution) of “inbox zero” may seem like more trouble than it’s worth. After all, when Gmail can locate any message you’ve ever received with just a few keystrokes, who cares about organization?

You’ll have to decide that one for yourself. But once you see how easily and effectively some of these solutions can whip your inbox into shape, you may decide it’s better to be proactive about mail management.

Ever wish you could hire an intern just to sort your email, to separate the e-wheat from the e-chaff? That’s the idea behind Alto, a free browser-based service that organizes mail into virtual stacks, not unlike the way you might sort physical junk mail into piles on your desk.

Developed by AOL, Alto works with the most popular email services, including Gmail, iCloud, Yahoo, and, of course, AOL. And you can use it with multiple accounts, making this a great way to manage several inboxes under one roof.

AltoAlto’s ability to temporarily archive messages until a more convenient time makes it particularly attractive for business users.

Once you sign in, Alto sifts through your inbox and sorts your messages into a handful of existing stacks: Daily Deals, Social Notifications, Photos, Attachments, and so on. You can create additional stacks as well, and once you direct an email to it, all future messages from that source will automatically land there. Thus, you could have a “client” stack, “boss” stack, “widget project” stack, and the like.

Alto’s pretty interface features a scrolling inbox on the left side that lets you preview each message without actually clicking it. If you mouse over an individual email, you’ll see one-click icons for Delete, Snooze, and Star. The Snooze option is particularly great for business users: It lets you temporarily archive an email until a later time, thus getting it out of your inbox but returning it to the top when it’s more convenient for you to deal with it.

Alto rocks. But it’s currently a private beta, meaning you need to request an invitation to try it out. The good news is that your invitation should arrive within about 24 hours, at least based on my recent experience.

Unlike most of the inbox-relief options in this roundup, Inky relies on actual software: It’s a desktop email client stocked with tools for better email management. However, that could be its downfall for some users: If you’re already vested in, say, Outlook, switching might not be a convenient (or even desirable) option.

It is compelling, though. Inky works with both IMAP and POP mail accounts and gives you the option of a unified inbox for as many accounts as you want to connect. Even better, it automatically filters certain types of messages into a variety of handy “Smart View” sub-inboxes: Daily Deals, Personal, Social, Subscriptions, Maps, and even Packages.

InkyInky’s Smart Views identify types of messages and sort them into relevant sub-inboxes.

The Packages inbox could help business users who constantly need to track package deliveries via confirmation emails, while the Personal inbox helps you zero in on important messages that might otherwise get lost in the business shuffle. I especially like the Notes inbox, which is where the email reminders you send to yourself get stored.

Inky looks almost too elegant for business use, and its heavy reliance on icons (not all of which are intuitive) steepens the learning curve. Thankfully, there’s an excellent guided tour that walks new users through the interface, and you can mouse over just about anything to get a pop-up descriptor. I found it much easier to navigate after expanding the side dock, which displays text labels alongside the icon for each section.

To help make sure the most important emails get noticed, Inky attempts to guess which ones are most relevant to you and tags them with a blue drop. The darker the drop, the more relevant the email—though you can easily fine-tune the results by clicking the icon. This should help ensure that messages from clients, coworkers, and other key people get immediate attention.

As PCWorld’s Yaara Lancet points out in her review of Inky, the program has a few bugs, but it still “shows immense promise and has real potential in revolutionizing the way you use email.” I’m not sure I’d give up Outlook for it, but I’ll agree it’s one of the best desktop mail clients to come along in years.

Frustrated by the roiling tornado that is your inbox? Mailstrom (get it?) aims to help you regain control by analyzing its contents, sorting the results, and giving you some tools to reduce the flow of mail. Admittedly, you can accomplish much the same thing using filters and targeted searches, especially in Gmail, but Mailstrom saves you the trouble.

The service, which operates in your browser, works exclusively with IMAP accounts, though for the moment you’re limited to three of them. I added AOL and Gmail accounts, then waited a few minutes to see the results.

Those results can be confusing at first. The Mailstrom dashboard lets you sort messages by sender, subject, lists, time, size, shopping, and social. When you click any of these view options, a middle pane lists the results from most to least. In the sender view, for example, you’ll quickly identify who sends you the most mail, because they’ll appear at the top of the list. You then click any sender to see a list of the messages from that person, which appears in a pane on the right.

MailstromMailstrom analyzes and sorts your email, but its inability to distinguish between read and unread messages is a major limitation.

Mailstrom gives you four key tools. For any given selected batch of messages, you can archive, delete, or mark as spam. You can also move them to another folder (in other words, out of your inbox), at the same time optionally creating a rule so that future messages land in the same spot. And if you’re looking at the Lists view, which shows any mailing lists you might be on (Groupon, stores, message forums, and so on), there’s an Unsubscribe button.

However, Mailstrom doesn’t distinguish between read and unread mail, which I found a serious limitation, and the color-coding it assigns to each filtered list of messages seems to serve no purpose. Plus, you can’t view individual accounts; the service lumps everything together.

Although PCWorld reviewer Liane Cassavoy liked Mailstrom a lot, I found it less helpful. I felt like I spent more time trying to figure out how to use the tool effectively than I would have simply processing my inbox the usual way. That said, it’s definitely worth a try, and for now the only cost is your time: Mailstrom is currently free.

Picture a bouncer stationed at the door to your inbox. VIP messages (like those from business contacts) get past the red-velvet rope; all others must stand in line. Outside. Like the undesirables they are.

That’s SaneBox in a nutshell. The service works with webmail clients like Gmail, iCloud, and Yahoo, and also Exchange, Lotus Notes, and Outlook, making it without question the most business-savvy inbox attacker in the group. I tried it with a Gmail account.

In a matter of seconds after I signed up (with nothing to install, thankfully), SaneBox had analyzed some 1500 messages and relegated roughly a third of them—those deemed unimportant—to a newly created SaneLater folder. So in one fell swoop, the size of my inbox shrank by more than 30 percent. However, I was still looking at a mix of business and personal mail in both locations; SaneBox analyzes based on communication history, not content.

SaneBoxWith support for Gmail, iCloud, Yahoo Mail, Exchange, Lotus Notes, and Outlook, and the ability "train” the filtering system, SaneBox is a powerful inbox manager.

Over time, as you drag messages between folders to “train” the filtering system, SaneBox will indeed keep the important stuff in your inbox and consign the rest to SaneLater. You can also add SaneBlackHole (a trash bin for senders you never want to see again), SaneTomorrow (which holds emails until tomorrow), and SaneNextWeek (which holds them until the following Monday). Need a custom “defer” folder? SaneBox lets you add those, too. The service even has a reminder option similar to that offered by Followup.cc., along with loads of other customization options to help steer mail to more desirable places. (Think: attachments automatically saved to Dropbox.)

Now for the bad news: SaneBox isn’t free, and it’s not exactly cheap, either. The $6-per-month Snack plan affords you just one email account, five of the aforementioned reminders, and five attachment routings. For $15 monthly, Lunch buys you two accounts and 250 each of reminders and attachments. And the $20-per-month Dinner plan supports three accounts and unlimited everything else. At least you can get price breaks if you prepay annually or biannually.

Still, you’ll have to decide if SaneBox’s bouncer is worth the expense. Gmail users in particular might prefer to roll their own "sane" inboxes via filters and labels, which cost a grand total of zero dollars. But if money is no object, SaneBox is perhaps the single best way to control email overload.

Some people can zero-out their inbox every day, and some people just can’t keep up. And then they give up. There’s no need to suffer alone, though. Inbox-taming apps like SaneBox, Mailstrom, and others can sort, filter, and prioritize emails, so you can spend less time scanning subject lines and more time responding to the messages that really matter—or doing other important work.

For more than 20 years, Rick Broida has written about all manner of technology, from Amigas to business servers to PalmPilots. His credits include dozens of books, blogs, and magazines. He sleeps with an iPad under his pillow.
More by Rick Broida


View the original article here