<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>markhaase.com</title>
	<atom:link href="http://markhaase.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://markhaase.com</link>
	<description>Talking about stuff…</description>
	<lastBuildDate>Thu, 09 Feb 2012 16:15:22 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='markhaase.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>markhaase.com</title>
		<link>http://markhaase.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://markhaase.com/osd.xml" title="markhaase.com" />
	<atom:link rel='hub' href='http://markhaase.com/?pushpress=hub'/>
		<item>
		<title>Somebody broke into my gmail account…</title>
		<link>http://markhaase.com/2012/02/06/somebody-broke-into-my-gmail-account/</link>
		<comments>http://markhaase.com/2012/02/06/somebody-broke-into-my-gmail-account/#comments</comments>
		<pubDate>Mon, 06 Feb 2012 15:24:54 +0000</pubDate>
		<dc:creator>mehaase</dc:creator>
				<category><![CDATA[Internet Safety]]></category>

		<guid isPermaLink="false">http://markhaase.com/?p=6</guid>
		<description><![CDATA[One day, I opened up my e-mail and found something unexpected: My inbox showed a bunch of emails that appear to be from my account (“me” in the left column) and sent with no subject line between 3:36 AM and 3:40 AM. I was definitely not awake at that time, and I was definitely not [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=markhaase.com&amp;blog=25069576&amp;post=6&amp;subd=markhaase&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>One day, I opened up my e-mail and found something unexpected:</p>
<div id="attachment_20" class="wp-caption aligncenter" style="width: 577px"><a href="http://markhaase.files.wordpress.com/2012/02/gmail.png"><img class="size-full wp-image-20 " title="gmail" src="http://markhaase.files.wordpress.com/2012/02/gmail.png?w=640" alt=""   /></a><p class="wp-caption-text">My Gmail Inbox</p></div>
<p>My inbox showed a bunch of emails that appear to be from my account (“me” in the left column) and sent with no subject line between 3:36 AM and 3:40 AM. I was definitely not awake at that time, and I was definitely not sending e-mails.</p>
<p><span id="more-6"></span></p>
<p>I opened up one of these e-mails to see what the content was.</p>
<div id="attachment_21" class="wp-caption aligncenter" style="width: 367px"><a href="http://markhaase.files.wordpress.com/2012/02/screen-shot-2010-06-15-at-9-15-55-pm.png"><img class="size-full wp-image-21" title="screen-shot-2010-06-15-at-9-15-55-pm" src="http://markhaase.files.wordpress.com/2012/02/screen-shot-2010-06-15-at-9-15-55-pm.png?w=640" alt=""   /></a><p class="wp-caption-text">Example Message</p></div>
<h1>What is this?</h1>
<p>It’s a spam e-mail – sent from my account – to a number of people in my address book. Each of the other messages (15-20 in all) were similar except sent to other people in my address book. Each message contains a link to a web site that sells cheap pharmaceuticals, such as Viagra.</p>
<p>I had also received e-mail from people who were up earlier than myself and had written back to let me know that something weird was happening with my account.</p>
<h1>What happened?</h1>
<p>If you’ve ever been a victim of a scheme like this, you know that the feeling is similar to having your car or house broken into. You probably feel insecure, violated, and (in my case) angry.</p>
<p>In addition, my geek curiosity made me wonder how this possibly could have happened. I looked at the following evidence:</p>
<ul>
<li>These e-mails had my name and my e-mail address in the From: field.
<ul>
<li>This means the person who did this was either logged into my account, or else was good at forging e-mails to appear as if they were coming from my account.</li>
</ul>
</li>
<li>These e-mails were sent to people in my personal address book.
<ul>
<li>This is more evidence that the person was logged into my account.</li>
</ul>
</li>
</ul>
<p>Neither of these points is conclusive. It is possible to forge e-mails, and it is also possible to guess somebody’s address book contacts based on publicly available information, such as what company you work at, who your Facebook friends are, etc.</p>
<p>Luckily, I am using Gmail, and Google provides a really easy way to see if somebody other than me logged into my account. At the bottom of Gmail, there is a little link that lets your view your login history. Here’s a picture of it, with a bright red arrow added since it’s so small you might miss it.</p>
<div id="attachment_22" class="wp-caption aligncenter" style="width: 475px"><a href="http://markhaase.files.wordpress.com/2012/02/screen-shot-2010-06-15-at-9-37-14-pm.png"><img class="size-full wp-image-22" title="screen-shot-2010-06-15-at-9-37-14-pm" src="http://markhaase.files.wordpress.com/2012/02/screen-shot-2010-06-15-at-9-37-14-pm.png?w=640" alt=""   /></a><p class="wp-caption-text">The Gmail Login History Link</p></div>
<p>You see it? It’s called Details. That link will show you when you logged in and where you logged in from.</p>
<p>When I clicked that link this morning, it showed me the following information:</p>
<div id="attachment_23" class="wp-caption aligncenter" style="width: 730px"><a href="http://markhaase.files.wordpress.com/2012/02/screen-shot-2010-06-15-at-10-53-06-am.png"><img class="size-full wp-image-23" title="screen-shot-2010-06-15-at-10-53-06-am" src="http://markhaase.files.wordpress.com/2012/02/screen-shot-2010-06-15-at-10-53-06-am.png?w=640" alt=""   /></a><p class="wp-caption-text">My Login History Immediately After The Incident</p></div>
<p>The smoking gun is highlighted in light blue towards the middle. Somebody logged into my Gmail account from Slovakia at 3:52 AM.</p>
<p>I’ve never been to Slovakia. I don’t know anybody in Slovakia. I can not even point out Slovakia on a map. So now I know for certain that my account was definitely broken into.</p>
<h1>How did they get my password?</h1>
<p>I will never know how my password was stolen, but I can conjecture.</p>
<p>The average internet user will use the same username and password on multiple sites. This is a <em>really</em> bad idea, but people do it anyway. Some do not know better, and others [myself included] just get lazy. I have at least 150 separate user accounts on the websites that I visit. Remembering which password works with which site is hard, but if I use the same password for multiple accounts then it gets easier.</p>
<p>If I use my Gmail password on another website — let’s call it “W” — then anybody who knows my W password also knows my Gmail password. A bad guy might be able to figure out my W password in several different ways. (This list is roughly in order of the actual likelihood of any of these things actually happening. I.e., #1 is very common, while #4 is less common.)</p>
<ul>
<li>W may be a shill: a fake site set up to look like a real site, except when I try to log in there is no real site there, just a bad guy collecting user names and passwords.</li>
<li>Bad guy may be an employee at W, and when nobody is looking he steals the password file.</li>
<li>W may have a security vulnerability on their website, and bad guy is able to use that vulnerability to break in and steal their password file.</li>
<li>Bad guy can eavesdrop on my internet connection, and if W does not use encryption, bad guy will able to see what my password is.</li>
</ul>
<p>In any case, by re-using my password, I have let W’s bad security leak out into my other online accounts. This could be avoided very simply by using a different password on every single website.</p>
<p><em>Let me repeat</em>: using a different password for each of your accounts means that if anybody steals an account password, you are limiting the damage to that one account and not letting it spread to your other accounts.</p>
<h1>What should I do?</h1>
<p>The irony of this story is that part of my job is to teach classes on how federal agencies respond to security incidents like this. The government requires security personnel to have a plan in place so that they can act quickly and with confidence. I, however, panicked and did not know what to do.</p>
<p>I didn&#8217;t have a plan in place, but in the aftermath of this incident, I put together an easy plan for handling a break in like this.</p>
<ol>
<li>Change your password immediately.</li>
<li>Look at your login history to determine if and when somebody else logged into your account.</li>
<li>Gmail is capable of telling you if another person is currently logged into your account. If you see that the attacker is logged into your account right now, Gmail has a button to force them out. (Look at my login history screenshot above.)</li>
<li>Review your sent mail folder to see what content was sent out. Verify that nothing private or sensitive was sent to any of your contacts.</li>
<li>Send a message to the people in your address book to explain to them what happened. Ask them to delete the spam message and not to click on the link contained in the message.</li>
</ol>
<p>So that’s what to do after something bad happens. Ideally you would never need to do that if you took good precautions. So here are some recommendations on how to avoid this type of break in.</p>
<ol>
<li>Use good passwords: totally random; mixed case; letters, numbers and special characters; at least 10 letters long and ideally up to 50 letters long. (You can <a title="a password generator website" href="http://strongpasswordgenerator.com/">use a tool like this</a> to help you come up with truly random passwords.)</li>
<li>Never use the same password for two different accounts.</li>
<li>Don’t use Internet Explorer ever, for any reason. Use <a href="http://www.mozilla.com/firefox/">Firefox</a>, <a href="http://www.google.com/chrome">Chrome</a>, or <a href="http://www.apple.com/safari/">Safari</a>.</li>
<li>Set up your computer to automatically install software updates on a daily basis.</li>
<li>If you use Windows, install both <a title="a free antivirus program" href="http://free.avg.com/">Anti-virus</a> and <a title="a free anti-spyware program" href="http://www.safer-networking.org/en/download/index.html">Anti-spyware</a> programs on your computer. Set them up to run every night while you’re sleeping, and set them up to automatically update themselves.</li>
</ol>
<p>Remembering a bunch of really long, random passwords is impossible. I suggest you use a password manager to keep them straight. I personally use a commercial password manager for the Mac called <a title="a password manager program for Mac" href="http://agilewebsolutions.com/products/1Password">1Password</a>. (I use it for all of my bank accounts. If I was using it for my Gmail account then this whole problem would have been avoided.) There is also a web-based password manager called <a title="another password manager program" href="http://lastpass.com/">Last Pass</a>. And you can find many, many more by searching on Google.</p>
<h1>Conclusion</h1>
<p>Hopefully somebody will find this story informative and will change their own habits to better protect themselves. I intend to continue writing [shorter] articles on various topics that affect average, non-technical users, such as spyware, viruses, etc. If you have any questions in particular, please leave a comment or send me an e-mail.</p>
<br />Filed under: <a href='http://markhaase.com/category/computers/internet-safety/'>Internet Safety</a>  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/markhaase.wordpress.com/6/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/markhaase.wordpress.com/6/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/markhaase.wordpress.com/6/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/markhaase.wordpress.com/6/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/markhaase.wordpress.com/6/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/markhaase.wordpress.com/6/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/markhaase.wordpress.com/6/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/markhaase.wordpress.com/6/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/markhaase.wordpress.com/6/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/markhaase.wordpress.com/6/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/markhaase.wordpress.com/6/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/markhaase.wordpress.com/6/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/markhaase.wordpress.com/6/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/markhaase.wordpress.com/6/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=markhaase.com&amp;blog=25069576&amp;post=6&amp;subd=markhaase&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://markhaase.com/2012/02/06/somebody-broke-into-my-gmail-account/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/3312219849e076b5e99adb78b9e60b58?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mehaase</media:title>
		</media:content>

		<media:content url="http://markhaase.files.wordpress.com/2012/02/gmail.png" medium="image">
			<media:title type="html">gmail</media:title>
		</media:content>

		<media:content url="http://markhaase.files.wordpress.com/2012/02/screen-shot-2010-06-15-at-9-15-55-pm.png" medium="image">
			<media:title type="html">screen-shot-2010-06-15-at-9-15-55-pm</media:title>
		</media:content>

		<media:content url="http://markhaase.files.wordpress.com/2012/02/screen-shot-2010-06-15-at-9-37-14-pm.png" medium="image">
			<media:title type="html">screen-shot-2010-06-15-at-9-37-14-pm</media:title>
		</media:content>

		<media:content url="http://markhaase.files.wordpress.com/2012/02/screen-shot-2010-06-15-at-10-53-06-am.png" medium="image">
			<media:title type="html">screen-shot-2010-06-15-at-10-53-06-am</media:title>
		</media:content>
	</item>
		<item>
		<title>Automatically visiting a website every day</title>
		<link>http://markhaase.com/2012/02/06/automatically-visiting-a-website-every-day/</link>
		<comments>http://markhaase.com/2012/02/06/automatically-visiting-a-website-every-day/#comments</comments>
		<pubDate>Mon, 06 Feb 2012 14:50:02 +0000</pubDate>
		<dc:creator>mehaase</dc:creator>
				<category><![CDATA[Computer Tips]]></category>
		<category><![CDATA[cli]]></category>
		<category><![CDATA[osx]]></category>

		<guid isPermaLink="false">http://markhaase.com/?p=7</guid>
		<description><![CDATA[I want to keep track of investments on a daily basis, but some times I get so busy at work that I forget to check. I&#8217;d really like some way to automatically pull up my portfolio at a scheduled time each day so that I can&#8217;t miss it. Here&#8217;s how to do this on a [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=markhaase.com&amp;blog=25069576&amp;post=7&amp;subd=markhaase&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>I want to keep track of investments on a daily basis, but some times I get so busy at work that I forget to check. I&#8217;d really like some way to automatically pull up my portfolio at a scheduled time each day so that I can&#8217;t miss it.</p>
<p>Here&#8217;s how to do this on a Mac. (It&#8217;s a little tricky if you&#8217;re not used to used to running commands from the command line, but this is completely do-able if you follow the instructions carefully.)</p>
<p><span id="more-7"></span></p>
<h1>Instructions</h1>
<p>1. Run the &#8220;Terminal&#8221; program. (It&#8217;s in Applications, then Utilities.)</p>
<p>2. Type the following exactly and press Return: &#8220;EDITOR=nano crontab -e&#8221;</p>
<p><a href="http://markhaase.files.wordpress.com/2012/02/screen-shot-2012-02-06-at-9-14-17-am.png"><img class="alignnone size-full wp-image-9" title="Screen Shot 2012-02-06 at 9.14.17 AM" src="http://markhaase.files.wordpress.com/2012/02/screen-shot-2012-02-06-at-9-14-17-am.png?w=640" alt=""   /></a></p>
<p>3. You should see a black bar across the top that says &#8220;GNU nano&#8221; in the top left.</p>
<p>4. Type the following and press Return: &#8220;45 9 * * 1-5 open http//www.marketwatch.com/myportfolio&#8221;</p>
<p><strong></strong><a href="http://markhaase.files.wordpress.com/2012/02/screen-shot-2012-02-06-at-9-18-33-am.png"><img class="alignnone size-full wp-image-10" title="Screen Shot 2012-02-06 at 9.18.33 AM" src="http://markhaase.files.wordpress.com/2012/02/screen-shot-2012-02-06-at-9-18-33-am.png?w=640" alt=""   /></a></p>
<p>If you make any mistakes, you can use arrow keys and the delete key to fix it, but you won&#8217;t be able to edit using your mouse.</p>
<p>When you&#8217;ve got it right, press Control+o (that&#8217;s &#8220;o&#8221; as in &#8220;oscar&#8221;), then press Return, then press Control+x. You should see a mesage that says &#8220;installing new crontab&#8221;. If you see <em>anything else</em>, then something went wrong. Try repeating the steps above.</p>
<p><a href="http://markhaase.files.wordpress.com/2012/02/screen-shot-2012-02-06-at-9-20-58-am.png"><img class="alignnone size-full wp-image-11" title="Screen Shot 2012-02-06 at 9.20.58 AM" src="http://markhaase.files.wordpress.com/2012/02/screen-shot-2012-02-06-at-9-20-58-am.png?w=640" alt=""   /></a></p>
<h1>Variations</h1>
<p>The example I showed will open the <a href="http://www.marketwatch.com">MarketWatch</a> site every <em>week day</em> at 9:45. You can change the time by changing the 9 and the 45 in the example. You can also change the website address in the example to suit your own needs. If you really want to do something crazy, you&#8217;ll need to learn more about the program being used here, which is called <a title="Wikipedia article on cron" href="http://en.wikipedia.org/wiki/Cron">cron</a><em>.</em></p>
<br />Filed under: <a href='http://markhaase.com/category/computers/computer-tips/'>Computer Tips</a>  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/markhaase.wordpress.com/7/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/markhaase.wordpress.com/7/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/markhaase.wordpress.com/7/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/markhaase.wordpress.com/7/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/markhaase.wordpress.com/7/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/markhaase.wordpress.com/7/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/markhaase.wordpress.com/7/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/markhaase.wordpress.com/7/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/markhaase.wordpress.com/7/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/markhaase.wordpress.com/7/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/markhaase.wordpress.com/7/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/markhaase.wordpress.com/7/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/markhaase.wordpress.com/7/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/markhaase.wordpress.com/7/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=markhaase.com&amp;blog=25069576&amp;post=7&amp;subd=markhaase&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://markhaase.com/2012/02/06/automatically-visiting-a-website-every-day/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/3312219849e076b5e99adb78b9e60b58?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">mehaase</media:title>
		</media:content>

		<media:content url="http://markhaase.files.wordpress.com/2012/02/screen-shot-2012-02-06-at-9-14-17-am.png" medium="image">
			<media:title type="html">Screen Shot 2012-02-06 at 9.14.17 AM</media:title>
		</media:content>

		<media:content url="http://markhaase.files.wordpress.com/2012/02/screen-shot-2012-02-06-at-9-18-33-am.png" medium="image">
			<media:title type="html">Screen Shot 2012-02-06 at 9.18.33 AM</media:title>
		</media:content>

		<media:content url="http://markhaase.files.wordpress.com/2012/02/screen-shot-2012-02-06-at-9-20-58-am.png" medium="image">
			<media:title type="html">Screen Shot 2012-02-06 at 9.20.58 AM</media:title>
		</media:content>
	</item>
	</channel>
</rss>
