Showing posts with the label security
It is time to clarify another common technology term here on Spam Resource. Today we're decoding 2FA , short for two factor authentication . You'll also see people use the broader phrase multi factor authentication, or the alternative phrase two step authentication. And while 2FA security is not unique to email accounts, it is often used in the email space, so if you're not famil…
Microsoft is removing support for inline SVG images in Outlook for Web and Outlook for Windows. This started rolling out in early September and should hit everyone by mid October. BleepingComputer has the full writeup here . Email designers and coders, be aware. Though, I rathe…
Google just announced that end-to-end encryption (E2EE) is now available for Gmail for business users. According to Google's official announcement , this new feature is being rolled out more broadly after a beta phase and is now accessible to all Google Workspace customers …
Niamh Ancell, writing for Cybernews , asked me an interesting question recently. The question was: Should you delete your old emails? Is it risky to keep a long and lengthy email history accessible and online? Why or why not? Most of the guidance I (and others) came up with for…
Last week on the Valimail blog, I shared a status update on the DKIM L= tag vulnerability that allowed bad guys to repurpose signed email messages, replace or append their own bad content, and then re-inject the content into the mail stream, having it then pass DKIM (and DMARC…
Hey, nerds! Do you use the Laravel php framework when developing web applications? Do you also use Mailgun to send email from said application? Did you forget to turn off debug mode when your web application went live? A certain set of circumstances can lead to you accidentally…
On Friday, May 17, 2024, security researchers from ZONE published details of a vulnerability inherent to the DomainKeys Identified Mail (DKIM) email authentication protocol – one that can allow bad guys to take existing messages, modify or add content significantly, and re-inj…
Bleeping Computer’s Sergiu Gatlan reports on a dire DMARC warning from the US National Security Agency (NSA): It seems that North Korea loves to send phishing emails, and they seem to be finding success by picking domains with weak DMARC policies , when looking for whom to targ…
Multiple folks have shared this along lately and though I’ve mentioned it in passing in a prior post , I thought it would be good to pull together an overview and roundup of what this actually is, what you should know about it, and what you should do about it. Let's talk ab…
Just recently discovered in my own inbox: a notice from Google indicating that they're going to require OAuth access for third party applications connecting to "Gmail, Google Calendar, Contacts via protocols such as CalDAV, CardDAV, IMAP, SMTP, and POP." Most mode…
Brian Krebs has a grand writeup on the new ICANN thingy (technical term) meant to help folks standardize requests for access to WHOIS data via a new "Registration Data Request Service" process. I'll let Brian give you his good overview and history of what happene…
GPT -- Google Postmaster Tools (or Gmail Postmaster Tools) is a truly handy thing for email senders, especially email marketers who need data and deliverability monitoring. It is a reputation dashboard that pulls together IP address reputation, domain reputation, bounce and co…
The Verge reports on a new change announced by Google : There's now a good chance they'll ask you to verify your login when you change certain Gmail settings, adjusting things like IMAP email access or adding email forwarding to a new address. Here's the details fro…
Rackspace appears to have suffered a security issue related to their Hosted Exchange mailbox environment, starting on December 2nd. You can find more information here , here and here . From what I can tell, their Hosted Exchange systems make up only a small portion of the over…
PCWorld's Mark Hachman explains Google's plans to automatically enroll new users into multi-factor authentication to better protect Google accounts from unauthorized access. This is a good thing, I think. Though I suppose there are a few edge cases where perhaps not ev…
It's Twitter's turn to jump on the two factor bandwagon. I'm sad that it didn't happen sooner , but still happy to see them joining the ranks of Apple , Yahoo, Google, Microsoft and Facebook . Please, please, please consider turning on two factor authentication…
I'm a big fan of two factor authentication. I've been using it on my Google accounts forever. Yahoo has it. Microsoft has it. Now, Apple has it, too! I'm very glad to hear this. I'll be setting it up for my account this weekend.
Just ask former CIA Director Gen. David Petraeus . And truth be told, 99.9% of the time it doesn't even require the FBI's help to figure out where that email message actually came from.
According to Return Path and Next Web , LinkedIn was hacked today and the bad guys were able to steal passwords for about 4% of their userbase, affecting approximately 6.5 million accounts. Are you one of that 4%? Let's not find out; go change your LinkedIn password as so…
In early 2007, Ed Falk , John Levine, and other trusted anti-spam and network security folks started to note that email addresses given only to TD Ameritrade were beginning to receive spam from unrelated entities.