Wednesday, February 17, 2010

Paypal Phish and banking mode

Paypal Phishing Email

Last year, we received an email which was allegedly from PayPal. I've been meaning to write this up for a while, and now seems like a good time :)

Knowing that it wasn't completely beyond the realms of possibility that I'd treated myself to a new toy without telling anyone, the mail was forwarded to me by Darryl.














The email itself looks reasonably legitimate - but the fun part starts just a little further down the page - as you can see, the criminals have added a nice little "If you didn't authorise this charge, click here to dispute transaction". Cute. The first thing many folks would think when getting a mail like this is "What the hell? I never bought no mobile phone..." so the convenience of having that dispute link there is going to encourage people to click before they think.



Of course - clicking on the dispute transaction button takes you to a fake site (which is now offline). The site itself was a very close clone of PayPal's official site. It even drew in some images directly from PayPal.com - it really looked the business.




While the site was live, I decided to log in and take a look around. Of course, I didn't use my PayPal credentials - because it wasn't the real PayPal site - but I wanted to take a look around inside there, and see what was what. I would not recommend that you do this.

I also thought that this would make a good test run of Online Armor's banking mode as it's designed for situations precisely like this.

What Happened?

Logging in, we're presented with a realistic looking PayPal fake site, complete with all of the menus - but telling you that "Your account access is limited. Remove this limitation".

Under here was a form to collect info - and boy, did these guys go for gold. Full name, date of birth, Mother's maiden name, country, address, SSN, home phone number... credit card number, issuing bank, expiration date, CVV number, Pin Number (with a helpful looking "Why is card signature/pin required" and an equally helpful "Help finding your Card Verification Number.

Just think for a moment; Assuming that you'd been fooled by this, you have just logged in (in other words, given them your PayPal account details) - and then you've provided them with enough information for them to commit identity theft - or even just wholesale theft, depending on how greedy and cunning they are, they could:
  • Empty your account
  • Change your address and other details with the bank (and take control of your accounts)
  • Disconnect or divert your home phone
  • Disconnect your home internet
In other words - if you fall for this scam, you possibly hand the keys to your life to the criminals. Consider - how did you identify yourself the last time you called your bank (or ISP, or phone company)?

How does Online Armor help me?

Online Armor has a safe online banking feature called Banking Mode. It's designed precisely to counter situations where you may somehow be directed to a fake site.

How it works is very simple: It keeps a list of safe banking sites. Before you do any banking, you should always activate banking mode. Online Armor then will only connect to a site that is on your list, meaning that you cannot, even in a moment of weakness, fall for these scams provided you follow the discipline of engaging banking mode before you bank.


Monday, November 30, 2009

Going back to Paypal...

Why we're dumping RegNow and going back to Paypal.

I was originally going to call this article "Paypal may suck, but at least it works" but on reflection this would be grossly unfair to the guys at Paypal.

While we had a number of comments from our users saying "Paypal sucks" that wasn't our experience.

However, we do listen to our customers, and so we made the switch to RegNow after a timely email from one of their sales guys offering to do big things for us with their wonderful affiliate progam.

Since ClixGalore was as useful as <insert your favourite phrase here> this seemed like a great situation.

The customer is not always right

At least when it comes to selecting payment gateways :)

A few things happened that put me off RegNow right away.

When we got things up and running, we found out that a RegNow offer for about $12 or so was inserted as an option in the cart on each of our checkouts. I can't remember if this was the software backup service (irrelevent to OA, as we always want to have our users on the latest version) or the licence key service. In either case, we didn't want this, but we were right out of luck. Fineprint.

Immediately that we went with RegNow, our sales dropped, and they dropped fast.

After a chat with RegNow we managed to get the thing removed (seems people hated it, because sales did increase again) but we had a different offer added instead which sucked almost as much.

To this day, you still get the backup CD option which at least is useful for those that don't want to download the program, but we should be in control of what's in our cart and our customer experience.

Online Armor users know that they can always get their key from us, automatically, and free, sent to the email address they signed up with. A key backup "service" isn't really required for a product like Online Armor and sends a conflicting message.

Still, some of our customers wanted us away from paypal - and so we stayed away.

Straws, Camels backs, etc

One might expect that RegNow, a company that specialises in the provision of Online Sales would be , ahem, how can I say this delicately... good at it. Unfortunately, in our experience we found that our own shopping cart looks better, performs better, is more user-friendly, reliable - and it works!

Some months ago, I tried to apply a $20 discount to our products. The maximum allowable was $10. We've seen times when the Regnow cart was simply offline - not with any error message, just "The document contains no data". The much promoted affiliate program caused at least one of our affiliates to complain over lost sales and inability to track.

Data from sales wasn't going into our system in an automated fashion, making support more complex than it needed to be and making it harder for users to use our members area. We couldn't do half of the things that we wanted to do, in the way we wanted to do it. There were problems with reporting. It was a mess.

The straw that broke the camels back was the problems handling what should be a simple transaction for a company that specialises in e-commerce.

We had an offer for $30 off any Online Armor, and I've had plenty of complaints from people because it was delivering a 30% discount instead. Contacting Regnow support and we're told it will be fixed at some point in the future, and for now, we have to make a promo code for all of our products. Right. We're quite capable of looking like idiots from time to time without help.

So, we decided to divorce ourselves from Regnow. We've implemented paypal express checkout in our own shopping cart. Non-paypal users can check out with paypal and use their credit card.

We've taken back control of the customer experience and I think we've made the right decision, even if not everyone agrees with it.



Tuesday, November 3, 2009

Online Armor 4, Windows 7 and 2010 is fast upon us

Online Armor v4 is released with Windows 7 Support

Just a few weeks ago Microsoft released Windows 7. Unlike their Vista launch, Windows 7 looks like it's going to be huge. I'll be installing it myself when I get a spare moment.

Unlike when Vista Launched, we're only a couple of weeks behind with our Version 4 with Windows 7 support, which I am really, really happy to release today in Free, Premium and OA++ versions. The release process has already started - should be done in a few hours.

This really is an incremental update to Online Armor; We've added Win7 support of course (32-bit only for now), but we've also fixed bugs, made performance enhancements and improved history logging to help you help yourself if something goes wrong.

We've also put a lot of effort these last few weeks into OASIS, trying to get as many files processed as possible to reduce popups.

If you're an existing Online Armor user, we think you'll enjoy this upgrade; If you haven't yet tried Online Armor we think we'll make a great first impression.


...and some pricing changes

Since we released Online Armor ++ we've been closely monitoring feedback from our users, sales rates, complaints, compliments - general observations from our customers.

One or two things become rather clear: firstly, many people think that Online Armor premium is $39.95 per year. And many people think that Online Armor Premium is too expensive.

To solve this, we've changed the pricing on Online Armor Premium. As of today, Online Armor Premium is $19.95. The price of subscription has also been changed to $19.95. This means that we don't have to keep explaining that the first year is $39.95 and subsequent years are cheaper.

As ever, you do not need a subscription to continue to use most Online Armor functions, but updates and server-side capabilities such as OASIS will not work without one.

As a result of this change, we've also dropped the pricing on our Family (3 User) and Family Plus (5 User) packs of Online Armor in line with the reduced pricing on Online Armor single user edition.

The pricing of OA+ remains unchanged, save for a slight increase in annual subscription costs. All in all, the pricing of our products is now fairer and more transparent.

We're going to try these prices until the end of 2009 and see how they go.



...thanks to our (extended) team, there is more to come

We're not a monster like Symantec; our development team is small; our support team is small and a large part of what we do is through the help of volunteers. What sets us apart is the dedication of our team; Our development team work all kinds of crazy hours - they hate anything that can get past OA; our beta test team and our forum admins keep our support efforts on track. We've built a community of nice and friendly people over the last few years and we are very very proud of it.

Now our development team is working on Windows 7 x64 - exciting times are ahead.




Mike

Tuesday, June 16, 2009

Online Armor: Best Practices - 1

How to get the most out of Online Armor (without losing your hair)

In order to get the most out of Online Armor, you really need to understand what it's for and how it's intended to be used. If you understand these basic concepts, you'll understand what we're trying to do, how we're trying to do it - and hopefully how to make Online Armor slip into the background.

What's Online Armor for ?
When we first started developing Online Armor, it was called "BankSafe" and was designed to stop thieves emptying your bank account. It had a very, very simple purpose, though none of the banks in Australia seemed to be too concerned about this at the time.

As we developed it, we had other ideas. The scope of protection was extended to cover anticipated (and then-current) threats.

However, the basic principles remain the same:

  • If a dangerous program is not allowed to run, it will not be able to do bad things
  • If you do allow a program to run, and it starts to do things that are suspicious - tell the user about it.
  • If a trusted program runs, and does something that looks suspicious, don't alert- because it's trusted.
It would be fair to say that Online Armor is for helping you keep bad things from happening to your computer, and to stop those bad things sending your data to the "bad guys". Designed to help you protect yourself against internet malice.


Any program that you trust, mark as trusted.
On my laptop everything I run is marked as trusted. If I did not trust it, it would not be on my laptop.

If you trust it, allow it to run as trusted. You'll get NO popups if you trust all your safe programs, and have less chance of any problems.

If you don't trust the program, uninstall it.

I know some users try to control what programs can do, to try and limit them, to try and give them "what they need". That's not what it was designed for. Stopping programs from doing things they need to do may cause unforseen issues. If you understand this and want to fiddle with it - great. If not - please don't.


Autoconfigure Trusted Programs for Internet
One feature of OA I was very proud of was the idea that we could auto-configure trusted programs to access the internet. I came up with this idea after hearing the CEO of one of our clients swearing that his personal firewall asked him "all sorts of ******* stupid questions and broke his computer".

Here's the logic:
  • You install Yahoo Instant Messenger
  • This is a safe, Trusted program.
  • You want this to access the internet so that it can do what it does
  • You do not know (or care) about listening, ports, UDP, TCP, "act as server" and all that nonsense - you just want it to work!
Dodgy Analagy time: Imagine a mechanic repairing your car. You ask him to do an oil change. He asks you do you want him to use this wrench or that wrench to undo the bolt. He asks you about the type of oil. He asks you how much oil to put in the car. He asks you which oil filter to fit.

How many times do you go back to that mechanic? Autoconfigure trusted programs is the equivalent of saying to the mechanic "Look buddy, do what needs to be done, I trust you, so get on with it already!"

Make use of the "Run Safer" feature

I've written about run safer before. In simple terms, what it does is to limit the rights of programs to limit damage they might cause.

Once you have trusted all of your programs - and uninstalled the ones you don't trust :) Then it's time to apply some run-safer settings to selected programs:
  • Internet Explorer,Firefox,Opera,Any other web browser
  • Yahoo, Skype, MSN, and any other chat program you use
  • Outlook Express, Outlook, Incredimail, The Bat! and any email program that you use.
Now, you may think "But I trust these programs, and now you're telling me to limit what they can do?" - and the answer is YES!

Chances are, right now, you're logged in as a user with administrative rights. If you don't know what that means - then you definitely are - AND what that means is that programs that run get these rights too. They can do anything to your computer.

The problem arises when Great-Aunt Mabel gets infected - the virus sends you an email , you open it in Outlook Express and click the attachment. Boom. That program can now do anything on your computer it wants. Or, you're surfing a site and some strange file downloads and you accidentally run it. BOOM! That program too can do whatever it wants. The same applies to files you download through Skype (or your messenger of preference).

If you had used run-safer, then the running, malicious attachment or the downloaded file, or the file you got from Skype would be heavily restricted in what it could do.

Ok, you keep talking about Safe, trusted programs - what are they?
A safe trusted program is not dangerous. I know it sounds a little silly, but:
  • Programs you download from Microsoft are safe, even if you think Microsoft is the Devil.
  • Programs you buy on a CD in a store are safe.
  • Programs you get from trusted sources are usually safe.
If in doubt, you can use Google (or Bing) to do a bit of research before you install.

Generally speaking - big companies like Amazon, Yahoo, Electronic Arts, Quicken and so on - let's call em the brand names - are not going to release malicious software.

I know Sony did something stupid a few years back, but this was stupid, not malicious. Online Armor is not designed to protect you from stupid.

Some programs that are not going to be safe:
  • Something that tries to download automatically when you go to a web page is never going to be good.
  • Something you receive in email is unlikely to be good.
  • A web page that keeps popping up until you accept a program to install - this is almost always going to be bad, and it would be better to "end task" or power-off your computer.

If you followed my advice...
... then you should have trusted programs running on your computer. Your browsers and email clients should be set to Run Safer, which will help to protect you against dodgy drive-by downloads and email/messaging malware. You will have your trusted programs automatically configured for internet.

Using Online Armor like this should result in very few (if any) popups asking you hard questions that make you want to tear your hair out. Your programs will work. Runsafer will prevent (or at least limit damage) if you accidentally run something from a website you shouldn't have.

Add to Technorati Favorites

Add to Technorati Favorites