Toughening up on security: 10 tips to avoid e-mail attacks, security breaches

MANILA, Philippines - It’s been 10 years since the Philippines became known on the Internet as the originating country of the ILOVEYOU worm, which successfully attacked tens of millions of computers through a supposed love letter via e-mail.

As security breaches have become more complex and widespread, affecting users who may not even be aware of a breach in their computers, here are 10 tips that everyone should make sure to follow in order to stay safe when using e-mail, from Google, the same company that offers the e-mail service platform Gmail.

Remote sign-out

Signing out is one of the first few e-mail security precautions. For Pinoys who usually access their e-mails in Internet cafés, there is no need to fret when you forget to sign out after leaving the place. E-mail programs like Gmail have a remote sign-out function that will let you sign out and close any previous open sessions, even if you’re already using a different computer at a different location.

Always use HTTPS setting

While your e-mail account doesn’t get hijacked every day, it is advisable to take every precaution possible to ensure that your personal information does not fall into the wrong hands, especially when accessing e-mail through a public wireless or non-encrypted network, which hackers can eavesdrop on.

Use the HTTPS setting on your e-mail program to keep your mail encrypted as it travels between your Web browser and servers, so someone sharing your favorite coffee shop’s public Wi-Fi cannot read it. Your bank and credit card websites use this same protocol to protect your financial data.

If you go to the Settings and select “always use https,” Gmail will automatically redirect to the secure version.

Turn off automatic download of attachments

Disable the option to download attachments automatically when you are reading your e-mail. Certain attachments can be illegitimate - with this option, you would be able to download only the attachments you want. At the same time, it is also good to note that most e-mail providers offer users an automatic scanning function to identify malware or viruses so this allows for double protection.

It’s always good to be paranoid

If you come across a link in an e-mail message that looks legitimate but you still have your doubts, go straight to the organization’s website instead. This reduces the chances of being caught in a phishing attack. It would also be good to check if the URL on mouseover tallies with the URL stated in the e-mail.

Recover your password via text messages

Apart from requesting a new password via e-mail, you can also try other options like receiving it via a text message on your mobile phone instead. If you have a Gmail account, for example, there are three easy steps to do this - click on “Sign in,” select “Change Password Recovery Options,” enter the mobile number and save. So if you do get forgetful, you can enter your username on the password-assistance page and a recovery code will then be sent to your mobile phone.

Beware of spear phishers

Spear phishing is a targeted form of phishing in which an e-mail might look like it comes from your employer, or from a colleague who might send an e-mail to everyone in the company, such as the head of human resources or IT. Scam artists usually use Web addresses that resemble the name of a well-known company but are slightly altered by adding, omitting or transposing letters, so be sure to double check on the spelling.

When being secondary is not so secondary

Keeping a secondary e-mail address will especially be beneficial for e-mail users who cannot remember their passwords. If you’re one of them, be sure to use an e-mail provider that allows you to use a secondary e-mail address in order to alert you when your storage space runs out or even when your e-mail account experiences any suspicious activity.

Backing up your e-mail offline

Some users may need to access their e-mail when they are offline somewhere or if they are unable to access their account for whatever reason. Thus, it is always a good idea to have a backup of your e-mail from an online service. Gmail offers an offline mode, so you can open your browser, go to gmail.com and get to your mail just like you’re used to even when you are not online. You can even choose which messages get downloaded for offline use and back-up purposes.

Use unique passwords

It’s a good idea to use unique passwords for your accounts, especially important accounts like e-mail and online banking. When you create a password for a site, you might think of a phrase you associate with the site and use an abbreviation or variation of that phrase as your password — just don’t use the actual words of the site. As an example, the phrase for your banking website could be “How much money do I have?” and the password could be ‘#m$d1H4ve?” (Note: don’t adopt any of the example passwords in this post for yourself).

Use digital signatures

Digital signatures are a way to verify that an e-mail is really from the person who supposedly sent it and that it hasn’t been changed. Because it is so easy for attackers and viruses to “spoof” e-mail addresses, it is sometimes difficult to identify legitimate messages.

Authenticity may be especially important for business correspondence — if you are relying on someone to provide or verify information, you want to be sure that the information is coming from the correct source. A signed message also indicates that the changes have not been made to the content since it was sent; any changes would cause the signature to break.

Show comments