The Saving Advice Forums - A classic personal finance community.

Avoiding scams, fraud, stolen identity, theft, etc.

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • myrdale
    replied
    Originally posted by QuarterMillionMan View Post
    And this after I drained my Coinbase account putting all my cryptos from Coinbase on to Arculus cold wallet.
    I have had very little experience with crypto thus far, only $20 worth of Bitcoin (actually it's probably $80 today). However the motto "Not your keys, not your crypto" has stuck with me. I wouldn't leave any significant amount in an online wallet for any longer than I had to. Mine at least is in a Ledger.

    Leave a comment:


  • QuarterMillionMan
    replied
    Got a text saying my Coinbase account may be compromised from Tokyo, Japan, and to call a number for support. Obviously a scam. And this after I drained my Coinbase account putting all my cryptos from Coinbase on to Arculus cold wallet. The only cryptos on my Coinbase is the free cryptos totaling $48. Something that wasn't a scam was my Microsoft account where I got both an email and text saying my password may have been compromised. So as a precaution I changed my password via the official Microsoft website but the email & text didn't have links so I'm guessing it wasn't a scam.

    Leave a comment:


  • ua_guy
    replied
    Speaking of avoiding identity theft. Sharing some knowledge I gained recently... I received a discount for one of those ID theft prevention services through a popular credit bureau. Figured, why not, <$20 is worth an hour of entertainment. And it was.

    Of course, my PII is on the dark web. That didn't surprise me. What did surprise me are the recommended steps if theft occurs. The presence of your data isn't cause for alarm, the use of it is. SO far, nobody has used it in malicious ways. Even then, the service recommends:

    a) Filing a police report to document that PII was found on the dark web, specifically, for social security numbers.
    b) Filing a report with the FTC in the event that your PII or SSN is used to steal your identity, apply for credit, employment benefits, etc.

    I took the liberty of locking all 3 of my credit bureau reports. That was very quick and easy to do. Just have to remember to unlock if I ever apply for credit.

    The service also recommended setting up your Social Security account and reviewing the work/income history they have on file. Check.

    It also recommended setting up a PIN with the IRS to prevent others from filing tax returns in your name. Check.

    Of less importance to me, the service also included automated removal of personal or public information found on the internet, i.e. people search sites that correlate names, addresses, employers, phone numbers, etc. It did find a few, no big deal, and I guess there is value in having that stuff removed from search results. Basically, it makes it harder for would-be thieves to find enough information to have your "identity" if they get hold of an actual valuable piece of information, like a username/password to a bank or something.

    As part of the service you get copies of your credit reports, credit scores. It's always worth reviewing those to make sure you are familiar with all the history and all account status are as expected.

    For <$20 I feel like this was about worth what I paid, a good way to spend an hour checking in on identity health and any vulnerabilities. Nobody is completely safe, of course, but there is some peace of mind in completing an annual inspection checklist so identity theft isn't a blind spot -- as it tends to be for many people!

    Leave a comment:


  • ua_guy
    replied
    If someone really wanted to, they could potentially read the contents of the drive even if they don't have your passwords. Data can be lifted straight off a physical hard disk or SSD. The drive would have to get into the wrong hands, someone would have to be really interested, etc. It's not something I'd give away to a thrift store, but it's possible the drive could end up somewhere you don't want it to be. It really depends on what's on it, that matters.

    If the drive is still functional, you might be able to create a boot disk other than the HD and then wipe it from the command prompt. I think that's still possible on windows pc's?

    Or...add it as a secondary drive, provided you have an open slot for another HD, and wipe it from your primary OS

    Or...buy an enclosure, connect it as an external drive, and wipe it, and then you have a backup or portable drive...

    Or...do like lots of people do... smash it with a hammer if you no longer need it, or if it's no longer working. A screen freeze kinda seems like maybe it could be a data corruption issue with the OS or another hardware problem.

    Leave a comment:


  • james.hendrickson
    replied
    QMM - I'm not an expert, but if the hard drive is not in the laptop, then how can the buyer get access to your personally identifying information or passwords?

    Maybe someone who knows will weigh in here.

    Leave a comment:


  • QuarterMillionMan
    replied
    1) unable to wipe the hard drive due to unable to log-in (screen freezes)
    2) I have the hard drive. It's a Western Digital 256 GB SSD.

    Click image for larger version

Name:	1awd.png
Views:	81
Size:	761.4 KB
ID:	750282

    Leave a comment:


  • james.hendrickson
    replied
    Originally posted by QuarterMillionMan View Post
    After selling my dead laptop which is currently in transit to the eBay buyer it crossed my mind that if the buyer can revive the broken laptop, maybe the buyer can even access some of my bank accounts even though I have the M.2 NVME SSD hard drive. I doubt that my passwords are stored on the motherboard but I'm not taking any risks. All this morning I've changed my passwords on my banks, brokerage accounts, credit cards, SSA, Treasury Direct, cyrpto accounts, etc. Later will have to change passwords for Amazon, eBay, Walmart, Temu, etc. Had to take care of important stuff first.
    I think the lesson learned here is...maybe wipe the hard drive before selling a computer?

    Leave a comment:


  • QuarterMillionMan
    replied
    After selling my dead laptop which is currently in transit to the eBay buyer it crossed my mind that if the buyer can revive the broken laptop, maybe the buyer can even access some of my bank accounts even though I have the M.2 NVME SSD hard drive. I doubt that my passwords are stored on the motherboard but I'm not taking any risks. All this morning I've changed my passwords on my banks, brokerage accounts, credit cards, SSA, Treasury Direct, cyrpto accounts, etc. Later will have to change passwords for Amazon, eBay, Walmart, Temu, etc. Had to take care of important stuff first.

    Leave a comment:


  • QuarterMillionMan
    replied
    Nice ua_guy. My line was unlocked and just locked it. Holy moly I could have gotten hacked.

    Click image for larger version

Name:	1alocked.png
Views:	59
Size:	21.0 KB
ID:	749742

    Leave a comment:


  • ua_guy
    replied
    Originally posted by QuarterMillionMan View Post
    My local news did stories on SIM swapping scams where a man lost $30,000 and another woman lost $17,000. It works something like this. The scammer somehow gets ahold of the SIM number and contacts Verizon, AT & T, or T-mobile to transfer it to the scammers phone. Anyone know how to prevent this?
    Enabling the security features through your carrier could be a simple way to protect against SIM swapping, and here are additional tips.

    Leave a comment:


  • QuarterMillionMan
    replied
    My local news did stories on SIM swapping scams where a man lost $30,000 and another woman lost $17,000. It works something like this. The scammer somehow gets ahold of the SIM number and contacts Verizon, AT & T, or T-mobile to transfer it to the scammers phone. Anyone know how to prevent this?

    Leave a comment:


  • Fishindude77
    replied
    Originally posted by EasyMoney00 View Post
    All of your banking apps and password managers require a login even if your phone is unlocked and stolen. Not sure how someone would access those accounts either way.

    Now, since people set up a face Id to unlock phone and apps, you could be murdered and someone could hold up the phone to your face. Same with a finger print unlocking. We all use it, but it's not secure at all. Just an FYI.

    The most secure way is to not use apps. If you must, a 6 digit pin is more secure than face recognition or finger prints. Not many crooks will torture someone until they unlock a phone. Although a keylogger could be installed i suppose. Then there's pegasus. The newest version only requires a phone number to install...v1 required touching the phone. I know no one here believes in these secret programs or operations, but Jeff bezos is a believer. Google it.
    You aren't planning something are you?

    Leave a comment:


  • EasyMoney00
    replied
    Originally posted by srblanco7 View Post

    And in perhaps an "over the top" moment, I deleted apps related to my investment accounts from my mobile devices. Going forward, these will only be accessed from my home computer (too many examples of phones being stolen while they were unlocked). I've also added a "face id" requirement to many apps (in addition to needing face id to unlock the phone) - including all email apps which might be used to reset a forgotten password.
    All of your banking apps and password managers require a login even if your phone is unlocked and stolen. Not sure how someone would access those accounts either way.

    Now, since people set up a face Id to unlock phone and apps, you could be murdered and someone could hold up the phone to your face. Same with a finger print unlocking. We all use it, but it's not secure at all. Just an FYI.

    The most secure way is to not use apps. If you must, a 6 digit pin is more secure than face recognition or finger prints. Not many crooks will torture someone until they unlock a phone. Although a keylogger could be installed i suppose. Then there's pegasus. The newest version only requires a phone number to install...v1 required touching the phone. I know no one here believes in these secret programs or operations, but Jeff bezos is a believer. Google it.
    Last edited by EasyMoney00; 12-24-2024, 04:09 AM.

    Leave a comment:


  • srblanco7
    replied
    Since the last time I've posted I've added a password manager and an IRS pin. For those not familiar, each year the IRS provides a new pin number to the taxpayer that you're required to enter in order to e-file tax returns. I've also added a password manager to create/store non-duplicative & complex passwords.

    And in perhaps an "over the top" moment, I deleted apps related to my investment accounts from my mobile devices. Going forward, these will only be accessed from my home computer (too many examples of phones being stolen while they were unlocked). I've also added a "face id" requirement to many apps (in addition to needing face id to unlock the phone) - including all email apps which might be used to reset a forgotten password.

    Leave a comment:


  • ua_guy
    replied
    Originally posted by QuarterMillionMan View Post
    FBI warns against 2-factor text authentications.

    FBI warns against using two-factor text authentication

    I've been changing to either email authentications or using Google authenticator.
    I think the article needs a little more context...two-factor authentication (password plus information gained from another device owned by you) even if it's over SMS, still works really, really well for most people. Authenticating over email is just as vulnerable, maybe even more vulnerable than SMS. Some sevices are using apps with push notifications to authenticate, which is good. My opinion is that most people with good online hygiene don't need to instantly switch their 2FA methodology.

    Good online hygiene can be things like using virus scanners with online traffic defenders. Don't click on unknown links, don't visit shadowy areas of the internet..) Don't connect to open/public wifi, and if you do, don't pass sensitive information (i.e. don't log into your bank account ,or send a form with your SSN and other PII). Secure your home wifi access points with strong unique passwords and encryption. Encrypt your hard drive (iOS, it's very easy to do this). Use unique usernames across sites and always unique passwords. And you can vary your 2FA authentication methods.

    Leave a comment:

Working...
X