• Welcome to the FREE TUGBBS forums! The absolute best place for owners to get help and advice about their timeshares for more than 32 years!

    Join Tens of Thousands of other owners just like you here to get any and all Timeshare questions answered 24 hours a day!
  • TUG started 32 years ago in October 1993 as a group of regular Timeshare owners just like you!

    Read about our 32nd anniversary: Happy 32nd Birthday TUG!
  • TUG has a YouTube Channel to produce weekly short informative videos on popular Timeshare topics!

    All subscribers auto-entered to win all free TUG membership giveaways!

    Visit TUG on Youtube!
  • TUG has now saved timeshare owners more than $24,000,000 dollars just by finding us in time to rescind a new Timeshare purchase! A truly incredible milestone!

    Read more here: TUG saves owners more than $24 Million dollars
  • Wish you could meet up with other TUG members? Well look no further as this annual event has been going on for years in Orlando! How to Attend the TUG January Get-Together!
  • Now through the end of the year you can join or renew your TUG membership at the lowest price ever offered! Learn More!
  • Sign up to get the TUG Newsletter for free!

    Tens of thousands of subscribing owners! A weekly recap of the best Timeshare resort reviews and the most popular topics discussed by owners!
  • Our official "end my sales presentation early" T-shirts are available again! Also come with the option for a free membership extension with purchase to offset the cost!

    All T-shirt options here!
  • A few of the most common links here on the forums for newbies and guests!

I am getting REALLY tired of this... [account hacking]

My "real" account is straight savings. Small-town bank. We have flags on the account, "No transactions at all above $X unless BOTH account holders are physically at the bank requesting a cashier's check."



The kind available to consumers. I don't run any kind of security at all. But I don't spend time on piracy/porn/gambling/meme/religious/political/genealogy websites which are rife with malware.

I completely agree that most hacks are phishing expeditions using thumb drives dropped in bank parking lots or simply calling someone and asking for the password. "Yeah, this is Chip in IT. I need you to confirm your logon information. I'm seeing a discrepancy."

However, the top 100 most common passwords are STILL the top 100 most common passwords. I'm willing to literally bet my farm that someone reading this has a password of "password." Or "123456." Or "qwerty123."


It is surprising that some people use simple PIN #'s to unlock their cell phone.
 
I was going to argue a little, but in reality I run Linux and no extra security so I can't really say much. I have found that as long as I have been judicious in what I download and from where, even back years ago when I used Windows at home, I've been fine. Most of the security software was always "defense in depth". That said, it has been proven that "be smarter about cyber security" doesn't work with the masses. So while I usually hate to be the "do what I say and not what I do" - well, as you point out, in reality people who take away "don't run security software" are missing a lot of the other "what I do" part, such as not running Windows.

I agree with all of this.

I like Linux just fine. But I also run windows because I like games such as Civilization, StarCraft and Obsidian/Bethesda RPGs. They just run better in WinDoze. (Mainly, I'm with Windows for access to her hotter, younger, faster sister -- DirectX.)

There's one final piece to this puzzle. Let's say I download a virus and lose everything. It would take me roughly four hours to go from "Oh [excrement]" to "Virus? What Virus?" Because I have the system completely backed up. I would only lose three months worth of software updates.

Roughly quarterly, when I'm happy with how the system is running, I fire up Macrium Reflect and back up the entire M.2 that holds the OS and the software. I have a removable HD for that. It also holds all my music, pictures, my film collection and similar. (24tb worth of stuff). That drive is ALSO backed up on another enterprise 24tb drive.

The most common cause of system failure for the WinBlows system has been Windows Update. I will typically do a quick backup before any big update. It has saved my bacon several times.

Here's a joke:

Jesus and Satan were called to the Heavenly coding room to compete for "Best Programmer in the Empyrean."

They both sat down at their computers (Jesus on Linux, Satan on a Mac). They loaded c++ (God is old-school) and started coding a "fix Earth for good" application. Both typed code so fast, their keyboards were smoking. Five minutes before deadline, the power went out. Satan roared with disapproval. The power returned a few seconds later. Jesus typed a few commands, and handed in His application.

The moral of this story? Jesus saves.
 
That's not good. I am not sure if I have used that site, but sounds like it may be more of back end service, so users may not even know if they have used it
 
It looks like some big companies may use this service for back end age and identify verification. Some of the companies that turn up are Target, Caesars Entertainment, Hertz and others. So if you happen to have a Caesars Club card or rented from Herts, then your ID could be compromised.
 
Add that to the list of data breaches. Three months from now, I will likely get a mail offering one year of identity monitoring service for free.
There was a post discussing this breaches and the token free identity monitoring services that will inevitably follow.

 
Last edited:
I will likely get a mail offering one year or identity monitoring service for free.

And you shouldn't accept. Putting actual financial security measures in place is better than false-sense-of-security "monitoring."

  1. Have a savings account with no electronic in or out. When that grows large enough to lose sleep over, put funds in something even less liquid. CDs, Index Funds, buy an investment property, whatever. Make sure this account is in a different bank. No online banking. No app on your phone. Nothing.
  2. Have a minor checking account at a different bank than your main account. This is for incoming and outgoing bills. If an account is going to get hacked, this is it. So keep the minimum to pay your monthly expenses.
  3. Lock your credit and lock Chex.
  4. Stay away from the websites where malware is common -- gambling, porn, "devotional" sites, memes, genealogy, cat pictures, "free" games, conspiracy theories etc. (Places where people who don't have strong passwords or financial security plans congregate.)
  5. Have strong passwords. Here's an example. Take a movie quote you'll never forget. Such as, "Frankly, my dear, I don't give a damn." Take the first letters of that. FmdIdgad. Add your favorite number and a special character. FmdIdgad42$. This is now the beginning of every password. Now add the first few letters of the website. FmdIdgad42$tugbbs.

You'll never forget it and it's different for every website.

For financial institutions, I use random VERY secure passwords and write them down. For websites that are prone to attacks, (like this one) I use random very secure passwords and let my browser store them.
 
And you shouldn't accept. Putting actual financial security measures in place is better than false-sense-of-security "monitoring."

  1. Have a savings account with no electronic in or out. When that grows large enough to lose sleep over, put funds in something even less liquid. CDs, Index Funds, buy an investment property, whatever. Make sure this account is in a different bank. No online banking. No app on your phone. Nothing.
  2. Have a minor checking account at a different bank than your main account. This is for incoming and outgoing bills. If an account is going to get hacked, this is it. So keep the minimum to pay your monthly expenses.
  3. Lock your credit and lock Chex.
  4. Stay away from the websites where malware is common -- gambling, porn, "devotional" sites, memes, genealogy, cat pictures, "free" games, conspiracy theories etc. (Places where people who don't have strong passwords or financial security plans congregate.)
  5. Have strong passwords. Here's an example. Take a movie quote you'll never forget. Such as, "Frankly, my dear, I don't give a damn." Take the first letters of that. FmdIdgad. Add your favorite number and a special character. FmdIdgad42$. This is now the beginning of every password. Now add the first few letters of the website. FmdIdgad42$tugbbs.

You'll never forget it and it's different for every website.

For financial institutions, I use random VERY secure passwords and write them down. For websites that are prone to attacks, (like this one) I use random very secure passwords and let my browser store them.
cat pictures :ROFLMAO:
 
cat pictures :ROFLMAO:

It's not just the vice websites that are riddled with malware. Scammers toss their electronic bait anywhere users lack critical thinking. Conspiracy websites are a prime example. They also rely on people being conditioned to click "OK."

old-people-at-cassino-pressing-bottom-nosolohit.gif
 
The problem here is multi fold IMO.
  1. We keep expanding "strong ID requirements" to services that historically had 0 need of such, and wouldn't have had it in the physical world. An offline version of Facebook (a community gathering space, social clubs, book clubs and game clubs) almost never asked for ID, and certainly never stored that info. Stop having places and services that are not at all prepared to be a cyber and operational security fortress collect valuable data.
  2. Stop centralizing ID checks - for almost all real needs, a trained cashier at the gas station can use their eyes to validate an ID and a person and age without digitally doing anything. Long existing "secret shoppers" for compliance works absolutely fine. And where it fails, the "blast radius" is some small amount of local kids getting beer and cigs. Not an entire country having their data stolen.
  3. Publically be honest about what we're willing to pay for our goal of "protecting the children". Maybe as a society we're willing to have en masse ID theft, stolen money, directed attacks on military or DV or witsec people in order to stop some small percentage more kids seeing porn or drinking beer. But let's be clear that's what we're doing.
  4. Stop taking non digital native IDs and trying to use them digitally with pictures of them. I don't know why anyone thought this was secure 20 years ago, forget about today. Would they have thought a photocopy of a drivers license would have been sufficient back in the 90s in person?!
    1. It sucks, but for most people, the only way digitally to verify identity in a strong way is to meet offline first - verify ID that way and then sign a key of some sort that is used in the future. Easy way is binding something like a Yubikey, but that costs someone money. Harder is learning and properly using GnuPG, but is free.
    2. I'd say actually trusted third parties, but outside of friend to friend web of trust, we know commercial providers cannot actually be trusted a la this article. I might have said the Government, simply because they already supposedly provide strong ID via Passports or State IDs, but after DOGE and them still pushing everything to commercial vendors - not to mention the other concerns about it being government run - I'm not sure that's realistic either.
These kind of half assed cheap ID verification sites are never going to work out. Haven't in the last 20 years, won't in the future IMO.
 
All my credit is frozen, I have Lifelock and various free credit monitoring from numerous companies. I have an IRS pin too(former Banker). As to CA- I used the toll road and paid within the time allocated. Within a week I got several more requests asking for more money or there would be fines etc. CA info is NOT secure.
 
We all know where the world's best security experts work
They also employ the world's best hackers
State Actors like US, China, Russia, Canada, Israel, Ukraine, etc. etc.

Back in the day, it was believed that people who wrote virus protection software were probably the people writing the viruses

It is probably true that the best security experts are the best hackers

Plenty of novels written with that plot

It is my belief that all of my personal data is already available online to the "bad" guys
This includes my passport information, credit cards, SS Number, DL, Tax Returns, Medicare Supplement info, etc., etc.

For a hacker the problem becomes
1. Which person do I focus on
2. What can I gain by focusing on that person (How much money does he/she have)
3. How well has that person guarded his money accounts

Now the hacker picks a target,
Gathers information on the target
This information takes time to pull together
Attempts to move money, use credit cards for purchases, etc. etc from the target
Comes up empty

Occasionally he pulls some money in
Now he has to worry about the money being seized, stolen by the bank, legal authorities catching him/her
Lots of worries
Not the life of leisure they planned

At some point, a hacker becomes sophisticated enough to make low to mid 6 figures as a security expert
Stops being the hacker and takes a real job
Works 40 hours a week
Has health insurance, etc., etc
Not worried about having made a mistake and being arrested

The point of the story is to protect your accounts where you have your money
Make it hard for the bad people to use the data on the dark web
Realize the bad people have your data already

My TED talk for this month
 
  • Like
Reactions: Tia
Just received a letter from HCIactive. I have never heard of them before, but the story is basically as outlined by the OP. Someone breached their network, they brought in specialist to review, your information may or may not have been stolen, an offering of free credit monitoring services.
 
I just yesterday got my virtual $50 Mastercard as part of a settlement for a security breach at an orthopedic group. Then they sent me an email to sign up for free one year credit monitoring by some company I never heard of.

I'm not doing it. Obviously with all these breaches and then signing up for credit monitoring hasn't solved anything,
 
  • Like
Reactions: Tia
I just yesterday got my virtual $50 Mastercard as part of a settlement for a security breach at an orthopedic group. Then they sent me an email to sign up for free one year credit monitoring by some company I never heard of.

I'm not doing it. Obviously with all these breaches and then signing up for credit monitoring hasn't solved anything,
There are no solutions to credit breaches for smaller storage repositories of client information

The best and brightest security specialists are guarding high value storehouses of information

Think cloud farms like AWS, Azure by Microsoft, etc., etc.

ATT was hacked in 2024

Some people had all their information compromised in this breach

I am one of those people

There is a lawsuit

I will end up with about (some piddly amount) in compensation

The law firm partners handling the class action lawsuit will divvy up enough to buy private jets

I do have credit monitoring

It is the new reality
 
Been streaming Pluto today. Free, but ads. So very many ads for download this game, win cash. Lots of different games, maybe same developer, maybe not. My personal opinion is that the download anything set put themselves at greater risk. Were I a scammer, how much easier does it get than to promise money wins while my embedded theft bot busies itself unlocking everything findable on a phone. Sure, you can win a couple hundred here or there, while I find ways to take much more than that.

I deliberately don’t download anything on my phone, I simply use it as a phone, not a business center storing all the keys. It astounds me how many people run their lives from these little gadgets. I think most of those folks don’t consider the risks to downloading so much crap. Wouldn’t be so many of these games if there weren’t money in it. Kinda sad how many people need cash so badly that they will download these casino games. Hard to know what personal info they give up just to download or play,but pretty sure it’s not zero info. How else are the wins transferred to their bank accounts? Yikes.
 
Been streaming Pluto today. Free, but ads. So very many ads for download this game, win cash. Lots of different games, maybe same developer, maybe not. My personal opinion is that the download anything set put themselves at greater risk. Were I a scammer, how much easier does it get than to promise money wins while my embedded theft bot busies itself unlocking everything findable on a phone. Sure, you can win a couple hundred here or there, while I find ways to take much more than that.

I deliberately don’t download anything on my phone, I simply use it as a phone, not a business center storing all the keys. It astounds me how many people run their lives from these little gadgets. I think most of those folks don’t consider the risks to downloading so much crap. Wouldn’t be so many of these games if there weren’t money in it. Kinda sad how many people need cash so badly that they will download these casino games. Hard to know what personal info they give up just to download or play,but pretty sure it’s not zero info. How else are the wins transferred to their bank accounts? Yikes.
Supposedly the games are vetted by the likes of Google with the Google Play store or the equivalents at Microsoft and Apple
Every so often we find out that "bad" things have snuck by the vetting
You are absolutely correct about the danger of many of the apps

But I still say the most important thing to do is follow every security recommendation for the areas where your money or money equivalents are stored
Most of us use digital methods to get to our banks, brokers, insurance companies, etc., etc.
Protect these accounts in the best manner possible
Lock down money transfer portals like Venmo, paypal, cashapp, etc., etc
This is the ultimate goal of most hackers
Get the money is the name of the game
 
Top