<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Transmission &#187; Security &amp; Safety</title>
	<atom:link href="http://transmission.xmission.com/category/security-safety/feed" rel="self" type="application/rss+xml" />
	<link>http://transmission.xmission.com</link>
	<description>XMission's Company Journal</description>
	<lastBuildDate>Thu, 19 Nov 2009 23:20:01 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Avoid the Dangers of Phishing</title>
		<link>http://transmission.xmission.com/2009/06/02/avoid-the-dangers-of-phishing</link>
		<comments>http://transmission.xmission.com/2009/06/02/avoid-the-dangers-of-phishing#comments</comments>
		<pubDate>Tue, 02 Jun 2009 15:15:14 +0000</pubDate>
		<dc:creator>Andrew K.</dc:creator>
				<category><![CDATA[Security & Safety]]></category>
		<category><![CDATA[Tips & Helpful Information]]></category>

		<guid isPermaLink="false">http://transmission.xmission.com/?p=667</guid>
		<description><![CDATA[Most people have heard of scams where a fake email is sent to a user&#8217;s
email, usually pretending to be from a credit card company or bank.
These are called, &#8220;Phishing&#8221; emails, because they lure users into
thinking that they need to reply.

Phishing emails are dangerous and have potentially catastrophic effects.

One particular type of phishing email could be [...]]]></description>
			<content:encoded><![CDATA[<p>Most people have heard of scams where a fake email is sent to a user&#8217;s
email, usually pretending to be from a credit card company or bank.
These are called, &#8220;Phishing&#8221; emails, because they lure users into
thinking that they need to reply.</p>

<p>Phishing emails are dangerous and have potentially catastrophic effects.</p>

<p>One particular type of phishing email could be the most malicious of
them all: an email pretending to be your email provider that asks you
for your account and personal information. Do not be fooled.</p>

<p>Read below and learn about phishing attacks, what you can do and what
XMission does to protect your accounts.</p>

<p><strong>
How phishing attacks happen.</strong></p>

<p>Phishing is an elaborate form of data and identity theft. It works by
persuading users to respond to emails asking for personal information or
to go to a website where information can be entered. These are so
effective because the emails usually look trustworthy and sound like
plausible scenarios.</p>

<p><strong>How to spot a phishing email.</strong></p>

<p>While phishing emails often differ, they almost always look legitimate
and always ask you for something confidential.</p>

<p><strong>Examples of email subjects:</strong></p>

<ul>
    <li>&#8220;Verify Your Account&#8221;</li>
    <li>&#8220;Email Upgrade&#8221;</li>
    <li>&#8220;Update Your Email Account&#8221;</li>
    <li>&#8220;Your email account has been suspended!&#8221;</li>
</ul>

<p><strong>Examples of From:</strong></p>

<ul>
    <li> &#8220;Xmission Admin&#8221;</li>
    <li>&#8220;Support&#8221;</li>
    <li>&#8220;Webmail Support Team&#8221;</li>
    <li>&#8220;email@xmission.com&#8221;</li>
</ul>

<p><strong>Example of a Phishing body:</strong></p>

<p>Confirm your email account by filling in the details below:</p>

<p>Username:</p>

<p>Password:</p>

<p><strong>Why it&#8217;s so difficult to stop.</strong></p>

<p>Often, phishing emails come for legitimate email accounts that have been
compromised, which is what XMission has been dealing with recently.</p>

<p>Phishers use a variety of camouflage techniques to avoid being detected
by our antispam/antiphishing systems by using:</p>

<ul>
    <li>Random letters or famous quotes in the subject or in the body of the
email;</li>
    <li>Invisible text in HTML emails;</li>
    <li>HTML or Java content instead of plain text;</li>
    <li>Pictures only (no other text in the email body).</li>
</ul>

<p><strong>Potential consequences:</strong></p>

<p>By replying or following links inside emails like these you can do more
damage than you might imagine.</p>

<p><strong>Common Examples of what phishers can do:</strong></p>

<ul>
    <li>Use your information to run up your bank accounts</li>
    <li>Open new accounts, credit cards, loan or contracts in your name</li>
    <li>Have access to all of the confidential emails you receive from your bank</li>
</ul>

<p><strong>Don&#8217;t fall for it:</strong></p>

<p>Follow these tips to stay safe:</p>

<ul>
    <li>Don&#8217;t ever reply to emails that ask for personal/confidential
information</li>
    <li>Forward the email to <a href="mailto:spam@xmission.com">spam@xmission.com</a> and then promptly delete it</li>
    <li>Do not click links in emails unless you were expecting the email</li>
    <li>Do not fill in forms that request information. Any trustful provider
will use a secure website and digital certificate</li>
</ul>

<p><strong>Safety:</strong></p>

<p>Customers with “@xmission.com” email addresses can verify that they have
spam filtering enabled on your account, this catches almost all phishing
attempts. You can verify that filtering is enabled by going to
<a href="http://webmail.xmission.com">http://webmail.xmission.com</a> and entering your login information. There
you will find a button called, &#8220;Filters&#8221;. Business customers have
filtering enabled already, unless requested otherwise. If you have
questions, you can always go to <a href="http://chat.xmission.com">http://chat.xmission.com</a> and talk with
one of our technical staff or call us at 801-539-0852.</p>

<p>Use an antivirus program that helps detect malicious emails and websites</p>

<p>What XMission does to protect you:</p>

<p>We have full time staff that monitors incoming and outgoing email for
spam, phishing and other potentially harmful traffic</p>

<p>XMission uses Spamassassin on its five email scanning servers
(<a href="http://spamassassin.apache.org">http://spamassassin.apache.org</a>) and is constantly writing rules to
account for trends in spam and phishing emails (see: What is
Spamassassin below)</p>

<p>We have Email Admins available around the clock to respond to phishing
emails.</p>

<p>We keep details statistics that you can view at:
<a href="http://postmaster.xmission.com&lt;br &gt;&lt;/a&gt;">http://postmaster.xmission.com</a></p>

<p>Our systems have been configured to automatically detect phishing emails
and notify our staff</p>

<p><strong>What is Spamassassin?</strong></p>

<p>Excerpt from spamassassin.apache.org</p>

<p>SpamAssassin uses a wide variety of local and network tests to identify
spam signatures. This makes it harder for spammers to identify one
aspect which they can craft their messages to work around.</p>

<p>If you&#8217;d like to get into the details of our filters, you can visit:</p>

<p>http://postmaster.xmission.com/senders/spamassassin/</p>

<p><a href="http://postmaster.xmission.com/senders/spamassassin/&lt;/p"></a></p>
]]></content:encoded>
			<wfw:commentRss>http://transmission.xmission.com/2009/06/02/avoid-the-dangers-of-phishing/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>A program for tracking stolen laptops. &#8220;Prey&#8221; upon thieves.</title>
		<link>http://transmission.xmission.com/2009/05/28/a-program-for-tracking-stolen-laptops-prey-upon-thieves</link>
		<comments>http://transmission.xmission.com/2009/05/28/a-program-for-tracking-stolen-laptops-prey-upon-thieves#comments</comments>
		<pubDate>Thu, 28 May 2009 18:55:13 +0000</pubDate>
		<dc:creator>John W.</dc:creator>
				<category><![CDATA[Security & Safety]]></category>
		<category><![CDATA[Tips & Helpful Information]]></category>

		<guid isPermaLink="false">http://transmission.xmission.com/?p=660</guid>
		<description><![CDATA[Chilean programmer, Tomás Pollak, developed a very cool little application that allows the owner to track a laptop if it is ever stolen. It is called Prey and best of all, it is totally free.

What is Prey ?

Prey helps you find your stolen laptop by sending timed reports to your email, including information of its [...]]]></description>
			<content:encoded><![CDATA[<p>Chilean programmer, Tomás Pollak, developed a very cool little application that allows the owner to track a laptop if it is ever stolen. It is called<a href="http://bootlog.org/prey"> Prey</a> and best of all, it is totally free.</p>

<p>What is <em>Prey</em> ?</p>

<p><em>Prey</em> helps you find your stolen laptop by sending timed reports to your email, including information of its whereabouts. <em>Prey</em> reports the general status of the computer, a list of running programs and active connections, fully-detailed network and wifi information, a screenshot of the running desktop and — in case your laptop has an integrated webcam — a picture of the thief. Pretty cool!</p>

<p>You need to have the software installed on your laptop for it to work. With enough luck you may just get your machine back.</p>

<p>The program runs on Mac OS , Linux, and Windows.</p>

<p>I&#8217;ll be installing this on my laptop tonight.</p>

<p><img src="http://transmission.xmission.com/wp-content/uploads/2009/05/prey_laptoptracker_logo.png" alt="prey_laptoptracker_logo" width="300" height="288" class="alignleft size-full wp-image-661" /></p>
]]></content:encoded>
			<wfw:commentRss>http://transmission.xmission.com/2009/05/28/a-program-for-tracking-stolen-laptops-prey-upon-thieves/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Secure your sites with XMission SSL Certificates!</title>
		<link>http://transmission.xmission.com/2009/05/05/secure-your-sites-with-xmission-ssl-certificates</link>
		<comments>http://transmission.xmission.com/2009/05/05/secure-your-sites-with-xmission-ssl-certificates#comments</comments>
		<pubDate>Tue, 05 May 2009 17:22:58 +0000</pubDate>
		<dc:creator>John W.</dc:creator>
				<category><![CDATA[News & Updates]]></category>
		<category><![CDATA[Security & Safety]]></category>
		<category><![CDATA[Tips & Helpful Information]]></category>

		<guid isPermaLink="false">http://transmission.xmission.com/?p=475</guid>
		<description><![CDATA[XMission is now selling SSL certificates!

This latest addition to the XMission domain based services makes it even more convenient to manage your online presence. Need to secure your web transactions or an email server? We can help!

Using SSL Certificates reassures your clients that you are doing everything possible to keep their information secure. Your customers [...]]]></description>
			<content:encoded><![CDATA[<p>XMission is now selling <a href="http://www.xmission.com/products/options/ssl/">SSL certificates</a>!</p>

<p>This latest addition to the XMission domain based services makes it even more convenient to manage your online presence. Need to secure your web transactions or an email server? We can help!</p>

<p>Using SSL Certificates reassures your clients that you are doing everything possible to keep their information secure. Your customers can easily spot sites using SSL because the web address contains &#8220;https://&#8221; and web browsers shows either a lock symbol, key symbol, or specially highlighted navigation bar display.</p>

<p>Like a drivers license, SSL Certificates are issued by a trusted source, known as the Certificate Authority (CA) and the SSL protocol allows applications to communicate across the net in a way designed to prevent eavesdropping, tampering, and message forgery. All this conveys a level of trust and security to increase your client&#8217;s confidence in your online presence.</p>

<p>XMission will handle all your SSL Certificate needs from start to finish. Unlike other companies, we are here to help with <em>real humans</em> that answer the phones and respond to your emails. We will help you every step of the way and with a single bill so you do not have to manage several vendors.</p>

<p>Learn more about SSL Certificates by reading about them on our <a href="http://wiki.xmission.com/index.php/How_Secure_Web_(SSL)_Works">SSL wiki support page</a>. You can order your <a href="http://www.xmission.com/products/options/ssl/">SSL online</a>, or simply call someone on our sales team. They will take care of you!</p>

<p>The XMission sales office is open weekdays from 9 AM to 5 PM, MST. You can reach us by calling 801-539-0852, 877-964-7746, or by emailing <a href="mailto:sales@xmission.com">sales@xmission.com</a>. As always, our support staff is here 24&#215;7 to help you with any technical assistance you require.</p>
]]></content:encoded>
			<wfw:commentRss>http://transmission.xmission.com/2009/05/05/secure-your-sites-with-xmission-ssl-certificates/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>DNS security and resolution</title>
		<link>http://transmission.xmission.com/2008/07/25/dns-security-and-resolution</link>
		<comments>http://transmission.xmission.com/2008/07/25/dns-security-and-resolution#comments</comments>
		<pubDate>Fri, 25 Jul 2008 17:50:45 +0000</pubDate>
		<dc:creator>Mike P.</dc:creator>
				<category><![CDATA[Security & Safety]]></category>
		<category><![CDATA[dns]]></category>
		<category><![CDATA[exploits]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://transmission.xmission.com/?p=30</guid>
		<description><![CDATA[As many have noted, a serious vulnerability in DNS was recently discovered.

Immediately after release of the patch in question and prior to exploit code being released into the wild, along with most other major providers, XMission has patched its servers for this serious issue on both its primary nameservers as well as its dedicated resolvers.
]]></description>
			<content:encoded><![CDATA[<p>As many have noted, a <a href="http://news.cnet.com/8301-10789_3-9989292-57.html">serious vulnerability in DNS was recently discovered</a>.</p>

<p>Immediately after release of the patch in question and prior to exploit code being released into the wild, along with most other major providers, XMission has patched its servers for this serious issue on both its primary nameservers as well as its dedicated resolvers.</p>
]]></content:encoded>
			<wfw:commentRss>http://transmission.xmission.com/2008/07/25/dns-security-and-resolution/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows patch breaks net access for Zone Alarm users</title>
		<link>http://transmission.xmission.com/2008/07/14/windows-patch-breaks-net-access-for-zone-alarm-users</link>
		<comments>http://transmission.xmission.com/2008/07/14/windows-patch-breaks-net-access-for-zone-alarm-users#comments</comments>
		<pubDate>Mon, 14 Jul 2008 17:18:58 +0000</pubDate>
		<dc:creator>hektorg</dc:creator>
				<category><![CDATA[Security & Safety]]></category>
		<category><![CDATA[patch]]></category>
		<category><![CDATA[tech support]]></category>
		<category><![CDATA[Windows 2000]]></category>
		<category><![CDATA[Windows update]]></category>
		<category><![CDATA[Windows XP]]></category>
		<category><![CDATA[Zone Alarm]]></category>

		<guid isPermaLink="false">http://transmission.xmission.com/?p=12</guid>
		<description><![CDATA[Software incompatibilities can really be a pain, especially when they cause problems with your internet access. It&#8217;s even worse when an update meant to improve security is the one that causes problems.

This past Tuesday (July 8), Microsoft released a patch (KB951748) via Windows update which was meant to fix a DNS exploit where hackers could redirect [...]]]></description>
			<content:encoded><![CDATA[<p>Software incompatibilities can really be a pain, especially when they cause problems with your internet access. It&#8217;s even worse when an update meant to improve security is the one that causes problems.</p>

<p>This past Tuesday (July 8), Microsoft released a patch (<a title="Information about the exploit and Microsoft Patch" href="http://support.microsoft.com/kb/951748/en-us">KB951748</a>) via Windows update which was meant to fix a <abbr title="Domain Name Service">DNS</abbr> exploit where hackers could redirect web page requests to <span>malicious pages. <a title="Information about the exploit and Microsoft patch" href="http://support.microsoft.com/kb/951748/en-us">This exploit</a> widely affected hardware and software from many different companies. However, when combined with <a title="ZoneAlarm, by Check Point Software" href="http://www.zonealarm.com/store/content/home.jsp">ZoneAlarm</a>—a popular software firewall by Check Point Software—Windows XP and 2000 users found themselves without internet access after applying the update.</span></p>

<p><span>Since many Windows systems are set to automatically update the system, many people woke up that morning to find that they could no longer browse websites or get their email. We received many calls about this problem, and the fix at the time was to either set ZoneAlarm&#8217;s security level to medium, or uninstall the Microsoft update.</span></p>

<p>On Wednesday (July 9th), Check Point Software <a title="ZoneAlarm - Workaround to Sudden Loss of Internet Access" href="http://download.zonealarm.com/bin/free/pressReleases/2008/LossOfInternetAccessIssue.html ">updated ZoneAlarm</a> to correct this problem. They suggest users either update to the latest version of ZoneAlarm, or use either workaround mentioned above. (Instructions are provided <a title="ZoneAlarm - Workaround to Sudden Loss of Internet Access" href="http://download.zonealarm.com/bin/free/pressReleases/2008/LossOfInternetAccessIssue.html ">on ZoneAlarm&#8217;s page</a>.)</p>

<p>As always, XMission tech support is available 24/7.</p>
]]></content:encoded>
			<wfw:commentRss>http://transmission.xmission.com/2008/07/14/windows-patch-breaks-net-access-for-zone-alarm-users/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Getting Phished?</title>
		<link>http://transmission.xmission.com/2008/06/25/getting-phished</link>
		<comments>http://transmission.xmission.com/2008/06/25/getting-phished#comments</comments>
		<pubDate>Wed, 25 Jun 2008 15:25:16 +0000</pubDate>
		<dc:creator>Emily H.</dc:creator>
				<category><![CDATA[Security & Safety]]></category>
		<category><![CDATA[Tips & Helpful Information]]></category>
		<category><![CDATA[email]]></category>
		<category><![CDATA[identity theft]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[safety]]></category>
		<category><![CDATA[scam]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[threats]]></category>

		<guid isPermaLink="false">http://transmission.xmission.com/?p=5</guid>
		<description><![CDATA[Recently, a few dozen of our subscribers received an email claiming to be from XMission that urged them to email their password. This fraudulent, &#8220;phishing&#8221; email did not come from XMission; unfortunately, it looked authentic enough that a few customers responded.

Obviously, we find emails like this incredibly frustrating.  Spam has cost us tremendously in [...]]]></description>
			<content:encoded><![CDATA[<p>Recently, a few dozen of our subscribers received an email claiming to be from XMission that urged them to email their password. This fraudulent, &#8220;phishing&#8221; email did not come from XMission; unfortunately, it looked authentic enough that a few customers responded.</p>

<p>Obviously, we find emails like this incredibly frustrating.  Spam has cost us tremendously in time, money, and network resources, and forces our customers to feel increasingly suspicious of anything in their inbox. Like you, we have all received spam from companies claiming to be eBay, PayPal, our credit union, or even the IRS. Even though XMission successfully filters out the majority of phishing spam, be aware that some still does squeak through.</p>

<p>Many of these emails ask the user to enter information using a fake web address, while others request information via email directly.  Spammers send out large numbers of emails betting on the odds that someone with a legitimate account will respond. Usually these emails have an urgent tone or even threaten penalty, suspension, or account closure.</p>

<p>Because of the volume and persistence of this threat, we wanted to share a few reminders from the Federal Trade Commission:</p>

<ol>
    <li>Simply do not reply. If you have concerns about an account, pick up the phone and call the business, or bring up a fresh browser and contact them directly using their website. No legitimate business will ask you for personal information over email.</li>
    <li>Scammers can fake anything including &#8220;from&#8221; addresses, logos, websites, and phone numbers. Even if an email includes a local phone, donít take it at face value. Call the company using a legitimate number from a trusted source.</li>
    <li>Update anti-virus and anti-spyware software regularly. Always use a firewall if you have a high-speed Internet connection.</li>
    <li>Do not use insecure websites. Always confirm the security certificates of secure websites.</li>
    <li>Review credit card and bank statements as soon as you receive them.</li>
    <li>Even if you receive an email from a trusted source, be cautious about opening attachments or downloading files.</li>
    <li>Report phishing emails to XMission (<a href="mailto:abuse@xmission.com">abuse@xmission.com</a>), the FTC (<a href="mailto:spam@uce.gov">spam@uce.gov</a>), and to the legitimate company being spoofed.</li>
    <li>If you have had your information compromised, report it immediately to the FTC, and then visit the identity theft website at: <a href="http://www.consumer.gov/idtheft">http://www.consumer.gov/idtheft</a>.</li>
</ol>
]]></content:encoded>
			<wfw:commentRss>http://transmission.xmission.com/2008/06/25/getting-phished/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Worried about Identity Theft?</title>
		<link>http://transmission.xmission.com/2008/06/25/worried-about-identity-theft</link>
		<comments>http://transmission.xmission.com/2008/06/25/worried-about-identity-theft#comments</comments>
		<pubDate>Wed, 25 Jun 2008 14:28:07 +0000</pubDate>
		<dc:creator>Stephanie S.</dc:creator>
				<category><![CDATA[Security & Safety]]></category>
		<category><![CDATA[Tips & Helpful Information]]></category>
		<category><![CDATA[identity theft]]></category>
		<category><![CDATA[safety]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://transmission.xmission.com/?p=3</guid>
		<description><![CDATA[The FTC’s national education campaign &#8211; AvoID Theft: Deter, Detect, Defend &#8211; aims to empower consumers to protect themselves against identity theft  and to minimize the damage it can cause.

http://www.ftc.gov/bcp/edu/microsites/idtheft/

Using this site, consumers can learn how to avoid identity theft, and find out what to do if their identity is stolen.  Businesses can receive [...]]]></description>
			<content:encoded><![CDATA[<p>The FTC’s national education campaign &#8211; <strong>AvoID Theft: Deter, Detect, Defend &#8211; </strong>aims to empower consumers to protect themselves against identity theft  and to minimize the damage it can cause.</p>

<p><a href="http://www.ftc.gov/bcp/edu/microsites/idtheft/">http://www.ftc.gov/bcp/edu/microsites/idtheft/</a></p>

<p>Using this site, consumers can learn how to avoid identity theft, and find out what to do if their identity is stolen.  Businesses can receive information about helping their customers prevent and cope with identity theft. This site also includes resources for law enforcement to help victims of identity theft.</p>
]]></content:encoded>
			<wfw:commentRss>http://transmission.xmission.com/2008/06/25/worried-about-identity-theft/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
