Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
Another helpful security tip from Carnegie Mellon (via CERT): know when to use BCC when sending mail. Some of you might know some users who would benefit from this idea, and it certainly would go a long way towards making foward-chains less useful to spammers. . . .. Benefits of BCC Although in many situations it may be appropriate to list email recipients in the To: or CC: fields, sometimes using the BCC: field may be the most desirable option. What is BCC? BCC, which stands for blind carbon copy, allows you to hide recipients in email messages. Unlike addresses in the To: field or the CC: (carbon copy) field, addresses in the BCC: field cannot be seen by other users. Why would you want to use BCC? There are a few main reasons for using BCC: * Privacy - Sometimes it's beneficial, even necessary, for you to let recipients know who else is receiving your email message. However, there may be instances when you want to send the same message to multiple recipients without letting them know who else is receiving the message. If you are sending email on behalf of a business or organization, it may be especially important to keep lists of clients, members, or associates confidential. You may also want to avoid listing an internal email address on a message being sent to external recipients. Another point to remember is that if you use the To: or CC: fields to list all of your recipients, these same recipients will also receive any replies to your message unless the sender removes them. If there is potential for a response that is not appropriate for all recipients, consider using BCC. * Tracking - Maybe you want to access or archive the email message you are sending at another email account. Or maybe you want to make someone, such as a supervisor or team member, aware of the email without actually involving them in the exchange. BCC allows you to accomplish these goals without advertising that you are doing it. * Respect foryour recipients - Forwarded email messages frequently contain long lists of email addresses that were CC'd by previous senders. These addresses are highly likely to be active and valid, so they are highly valuable to spammers. Furthermore, many email-borne viruses harvest email addresses contained in messages you've already received (not just the To: and From: fields, but from the body, too), so those long lists in forwarded messages pose a risk to all the accounts they point to if you get infected. Many people frequently forward messages to their entire address books using CC. Encourage people who forward messages to you to use BCC so that your email address is less likely to appear in other people's inboxes and be susceptible to being harvested. To avoid becoming part of the problem, in addition to using BCC if you forward messages, take time to remove all existing email addresses within the message. The additional benefit is that the people you're sending the message to will appreciate not having to scroll through large sections of irrelevant information to get to the actual message. How do you BCC an email message? Most email clients have the option to BCC listed a few lines below to To: field. However, sometimes it is a separate option that is not listed by default. If you cannot locate it, check the help menu or the software's documentation. If you want to BCC all recipients and your email client will not send a message without something in the To: field, consider using your own email address in that field. In addition to hiding the identity of other recipients, this option will enable you to confirm that the message was sent successfully. _________________________________________________________________ Authors: Mindi McDowell, Allen Householder _________________________________________________________________ Copyright 2004 Carnegie Mellon University. Terms of use: This document can also be found onlineat . Benefits of BCC Although in many situations it may be appropriate to list email recipients in the To. another, helpful, security, carnegie, mellon, cert), sending. . LinuxSecurity.com Team
Watch out--the spam choking your e-mail in-box may be loaded with software that lets marketers track your moves online, and you may not even be aware that you've been bugged. . . .. Watch out--the spam choking your e-mail in-box may be loaded with software that lets marketers track your moves online, and you may not even be aware that you've been bugged. Web sites have long planted bits of code called "cookies" on consumers' hard drives to tailor Internet pages for returning visitors and better target ads. Now, enhanced messages that share the look and feel of Web pages are being used to deliver the same bits of code through e-mail, in many cases without regard for safeguards that have been developed to protect consumer privacy on the Web. "All of the security and privacy issues on the Web now relate to e-mail," said Adam Shostack, director of technology at Zero-Knowledge Systems, a Montreal-based privacy and security company. "The shame about this behavior is that it's going on surreptitiously and people are not given an obvious way to opt out." The link for this article located at ZDNet is no longer available. . Stay vigilant regarding unwanted emails; they could harbor programs that monitor your digital activity unbeknownst to you.. Email Tracking, Spam Security, Consumer Tracking, Privacy Issues. . LinuxSecurity.com Team
The bipartisan, bicameral Congressional Privacy Caucus will hear from Internet security and privacy experts on Thursday regarding some of the sneakiest forms of online surveillance technologies in use today. The panel for Thursday's hearing will examine threats to consumer privacy online . . . . The bipartisan, bicameral Congressional Privacy Caucus will hear from Internet security and privacy experts on Thursday regarding some of the sneakiest forms of online surveillance technologies in use today. The panel for Thursday's hearing will examine threats to consumer privacy online via e-mail wiretapping and "Web bugs" - tiny hidden images that Internet ad companies and malicious programmers can embed in Web pages to track consumers as they surf the Web and read e-mail. The link for this article located at is no longer available. . The nonpartisan Legislative Data Protection Committee plans to investigate digital surveillance and online tracking technologies with specialists.. Congressional Privacy Caucus, Internet Surveillance, Online Tracking. . LinuxSecurity.com Team
Imagine being able to trace where your e-mail goes, and where it's forwarded. Say you had a way to verify that the CEO of the Fortune 500 company you've been hounding for a job indeed got the resume you e-mailed . . . . Imagine being able to trace where your e-mail goes, and where it's forwarded. Say you had a way to verify that the CEO of the Fortune 500 company you've been hounding for a job indeed got the resume you e-mailed him. Or that you could tell if your girlfriend lied when she denied getting your message that begged her not to go to that conference in Jamaica with her assistant who turned out to be rather hunky? Both scenarios are possible, thanks to services that track when and where e-mail messages are read without the recipient's knowledge. The technology has long been used by online marketers to determine who reads their spam; now it's available to consumers as well. The link for this article located at Wired is no longer available. . Follow the path of your communications and unveil engagement with sophisticated monitoring technologies. Explore their influence on confidentiality.. Email Tracking, Digital Communication, Privacy Tools. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.