ID Theft Protection and stuff like that

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • Mike Blakesley
    Film God
    • Jan 2020
    • 2021
    • Forsyth MT

    #1

    ID Theft Protection and stuff like that

    Since this forum is populated by a bunch of computer-savvy folks, I'm just wondering what you all use for ID theft protection. I use about 7 or 8 different computers during the course of my work day. Five of them are at my day job -- one is a standard PC that I use for accounting and general goofing around, and the rest are tied into our point-of-sale system. What I use depends on where I'm standing at a given moment.

    At the theatre we have three computers - boxoffice, concession, and projection booth.

    So with all this "exposure" I'm not sure what would be the best bang-for-the-buck. I'm not what you would call an adventurous web surfer and I never click on emailed links or things I get in private messages, but I know one random accidental click could wreak havoc, so....what do you all recommend?
  • Frank Cox
    Film God
    • Jan 2020
    • 2314
    • Melville Saskatchewan

    #2
    Linux (I use https://rockylinux.org/), and an email client that renders embedded HTML as plain text (I use https://sylpheed.sraoss.jp/en/ on my computers and http://www.mutt.org/ on my phone.)

    And be sure to check the header information on emails that may or may not be legitimate. (CTRL-U works for that purpose with Sylpheed, mutt does it with h, other email clients may do it in different ways.)

    Both sylpheed and mutt can be used on Windows if you really insist on continuing to use an insecure operating system that has always been the main target of black hats.

    Comment

    • Ed Gordon
      Pro Film Handler
      • Jan 2020
      • 365
      • Seattle, WA, USA

      #3
      Since the large data breach at Equifax a back in 2017 I put a security freeze on my data at all the the credit reporting services.

      The greatest danger we face on the internet is having our data stolen, and the greatest risk of that comes from poor security on corporate computer systems. I have had at least four reports of data breaches. When this happens the companies offer free online monitoring. I now have four different monitoring services sending me monthly reports.

      When you put a security freeze on your data no one can open new accounts in your name. If you need to open a new account that requires a credit report you will have to request that the freeze be lifted at one of the services, like Equifax. This only needs to be done on one service, and the freeze is re-instated after 24 hours.

      On your individual machines, anti-virus software should always be used. My personal preference is Malewarebytes. I also use a VPN to encrypt data to prevent exposure of my data in online transactions.

      You should also use an Ad Blocker to prevent online tracking. See: https://robertheaton.com/2017/11/20/...actually-work/

      Even ad blockers don’t keep you private on the internet by any stretch of the imagination. Third-party trackers have plenty of options for circumventing their protections, and whether they use them or not is primarily dependent on state regulation and their PR team’s appetite for risk. First-parties still see everything that you do, and the only way to avoid sending a first-party any information is to close your laptop. Using a VPN or even Tor goes a long way to prevent unintentional leakage of your location or identity information, but as long as you use Facebook, Facebook is going to know a lot about you.

      Comment

      • Leo Enticknap
        Film God
        • Jan 2020
        • 3572
        • Loma Linda, CA

        #4
        Like Ed, I've locked my credit record on all three of the ratings agencies.

        If it's not legally required that I be truthful, I use a false date of birth and/or SSN when registering with any account provider that asks for it, and keep notes of what those are in case they are requested for later verification purposes.

        I got an employer ID number from the IRS (anyone can do this, including sole traders: you don't actually have to employ anyone) that I use instead of my SSN for occasional gig work and any other tax reporting purposes that don't absolutely require me to reveal my SSN.

        To avoid the risk of card skimmers, I always use cash at gas stations.

        Any mail that arrives with my name and home address on it is shredded before it goes in the recycling bin, and I don't allow any piece of paper with my personal information on it to be disposed of any other way.

        I limit the number of devices that I use financially and/or ID-sensitive online services from (e.g. banking, my employer's payroll management system, that sort of thing), to two only. I do not install those apps or use those services from any other device. Their data drives are encrypted, and I do not store the key backups in any cloud. In fact, I do not use cloud storage for anything personally sensitive at all.

        I use Firefox with the NoScript (only allowing scripts to run that are absolutely necessary for functionality) and Ghostery plugins for anything privacy critical, and of course only connect to ID-sensitive services using HTTPS. I haven't gone as far as to use a VPN yet, though we do have an earlier version of this semi-hardware VPN, which I think is a sensible compromise between a totally exposed connection and the speed and functionality drawbacks of connecting through a full scale VPN.

        Finally, I am very careful about what information about myself I let out into the public domain. I am not registered on any of the major social media platforms (a lot of identity theft, home title theft, targeting of addresses for burglaries, and other criminal activity starts with bad actors gathering information about you from Facebook, Xwitter, LinkedIn, etc.), largely for this reason.

        And for that reason, there are a few other precautions that I take that I am not going to mention on this thread.

        Addition/afterthought several hours later: I also avoid using the US Postal Service to send anything that could be used for identity and/or financial theft if it falls into the wrong hands. In April 2020 I mailed a check to the IRS. A couple of weeks later, I got a call from my credit union, which had been presented with several checks that I'd supposedly issued, that they were suspicious of. I hadn't issued them: the most likely explanation is that bad actors in the local mail processing center in San Bernardino had opened the envelope, taken details from my check, used them to create multiple forgeries, and then resealed the envelope and sent it on its way to the IRS. Very thankfully, the credit union caught the phony checks and bounced them. But I had to change my account numbers, re-arrange all ACH direct deposits, and deal with a lot of hassle. My wife later told me that ever since she was a child in this area in the 1980s, it was well known that any gift card mailed to or from an address that required mail to be processed through San Bernardino was unlikely to arrive, because theft and fraud within the USPS was endemic and there was no political will to do anything about it. I now make electronic payments unless there is no practical alternative to writing a check, in which case I hand it over in person. I would also never mail any forms or other documentation containing my DoB or SSN. So far I have only had to do that once since the incident in 2020. Very tellingly, the company needing that information sent us a prepaid FedEx envelope along with the forms we had to fill out, so it seems that they don't trust the USPS, either.
        Last edited by Leo Enticknap; 01-24-2026, 08:29 PM. Reason: Addition/afterthought

        Comment

        Working...