Showing posts with label Emails. Show all posts
Showing posts with label Emails. Show all posts

October 9, 2011

Who invented email?

Who invented email? That is a question that many of us will not even think about as we enter the email addresses and click send to 'forward' those hundreds and thousands of cute and interesting emails that we receive on a daily basis.

Who invented email? If you do not know, email is 40 years old this month. The first email was sent in October 1971. Yes, 40 years old!

Like Internet, email too was invented by the US military. Bolt, Beraneck and Newman, a firm that was working on the military communication network hired Ray Tomilnson to work on Advanced Research Projects Agency Network or ARPANET. ARPANET was the earliest form of internet. His task was to figure out how to do a file transfer programme . Tomlinson was asked to modify a programme called SNDMSG. This was supposed to be a programme that allowed users of the same computer to send messages to each other. And in October 1971, Tomlinson figured out how to send messages between two computers. Actually, when he first invented it and showed it to a colleague, Tomlinson was told:  "Don't tell anyone! This isn't what we're supposed to be working on."

Tomlinson invented email! He did something else too - he popularized the use of "@"! He used the @ sign to separate the user and the network they were using.

It is important to remember that email was not popular untill the WWW became popular and it led to consumers embracing the internet. However, that @ sign Tomlinson used still stays on! Even on Twitter! 

May 2, 2010

Who is mailing you?

Pishing. Scamming. Spamming. And what not! Email accounts are easy targets of spammers and scammers from time immemorial. Most of the email service providers have successfully developed spam fighting systems that automatically send junk mail  into your spam folder or trash them. Yet, spammers find a way around that system and get into your inbox. Worse still, some of them impersonate people you know and trick you into downloading spyware, sending money or joining scam websites. How we wish we had some way to identify the person mailing us? There is a way you can do that now.

Rapportive!

Rapportive is a browser extension that integrates itself into your Gmail Account and it works on both Chrome and Firefox. It does a very simple thing! It shows you who mailed you the mail you are reading. For example, if you receive a mail from me and you have Rapportive installed on your browser, it will show you my photograph and any information available on web about me. It will show you links to my Facebook Account, Twitter Account, Linkedin Account etc. This helps you make sure that the mail from me is in fact from me and no one else.

You may not get the information right away for all email addresses. They have just launched Rapportive and its in the process of accumulating information on people. But I am sure, the service will improve over a period of time as you keep using it and Rapportive will be able to give you exact information about people you interact with.

Imagine receiving a mail from someone, claiming that it is from your friend stranded on an island and he needs help. Rapportive will help you understand if that mail is really from your friend. All you need to do is [if you are using gmail], to click here and install the extension on your Firefox Browser or Chrome Browser!

December 2, 2009

Career Consultant Spammers!

I am sure you are a member of one of these Indian Job Sites and you get hundreds of mails intimating you about openings at various Organizations and Companies. And I am sure you have applied many a times if you are interested in the position on offer, sending your updated detailed resume. But my question is, how many of you have really got a call back for an interview applying for these jobs that are intimated from Job Sites by consulting agencies?

My experience is I have got a call back for interview only if the mail came directly from the Organization. I have never got a call back from the Recruiting Agencies that are abundant online, even if my profile suited the position they have advertised right to the last word. How do I know my resume suited the position right to the last word? I know because I know my job, I know what you require to do my job.

So I was telling you about the mails that come from Organizations and Agencies, intimating you about a vacant job. And I think we are so caught up talking about spams and scams in other areas like Social Networks that Career Spammers go unnoticed. Even I never noticed untill I received a call to my Unofficial Phone Number, which I leave only for recruiters and some very close friends, from some Agency from Mumbai that was trying to sell me a CD that had something to do with my profession. How did they know my number? How did they know what I was doing? I am pretty sure on of the Consulting Agency or an Organization to which I had sent my resume sold it to them. I went back and looked at the mails, in a hope to find a common pattern to figure out fake Consulting Agencies who are out there to sell my details to some thugs.

What did I figure out? Let me tell you:

  • Check if the mail is sent from a Yahoo or Gmail ID than a Company ID. Any decent Company these days will have an email address of their own. 
  • If they have an email address of their own, see if they have a website in the same address. If they have a website address in the same name, visit the website. See if the profile of the Company as mentioned in the mail and what you see on the website has reasonable connections. For example your mail may claim that the Company deals with Software Testing. If you visit the Website of the Company, you will find that the it is not about a Company at all. The website will be about some IT related conference that happened in 2006.  So check if the Company Profile on the mail matches with the Company Profile on the Website.
  • Check for phone numbers. A serious recruiter will leave a phone number for you to contact. Any Tom Dick and Harry can create an email address. They can not have a valid phone number if they are fake. And a phone number is more traceable than an email address. Go ahead and see if there is a phone number. Also make sure that the phone number in the mail matches with the phone number on the website. A decent company will mention all the public contact numbers mentioned on the website in their mail. Think twice before sending your CV,  if only a cell phone number is mentioned. A valid landline number is your key to make sure that the company exists and has an address. 
  • It is not enough you check for phone numbers. Call the number given and find out if you are calling to the same person as mentioned in the mail. Sometimes they can give you all the right numbers and still dupe you. So call and find out. Especially because your resume contains all valid data about you and it is a good tool for social engineering. 
  • See if the mail is rational. Sometimes spammers can cut and paste from different mails to avoid hardwork. If it is an authentic company about an authentic job, the mail will have logical connection from beginning till end. Some of these offers may talk about totally unrealistic and unrelated skills in an attempt to sound professional. For example, the other day I got a mail from a Company looking for a Soft Skill Trainer who had knowledge of Hardware and Networking. I know Soft Skill Trainers, who train call centre people. I have never come across a Soft Skill Trainer who has knowledge of Hardware and Networking. And that is the job of a Tech Trainer and not a Soft Skill Trainer. You know your job. So check the mail and see if the skills mentioned in the mail sounds familiar and have some sort of connection. 
  • See if the mail is clear about Soft Skills and Hard Skills and Qualifications and mentions them separately. Good recruiters know the hard skills required for the job and mentions them clearly and separately. Check and make sure that what you see is not a list of randomly picked skill sets to make it sound professional. 
But you don't have to bother replying to these mails from Career Sites at all. If you are really hunting for a job,  I have a few advices for you to avoid getting fooled:
  1. Go to the company website directly and apply directly to the company instead of trusting Career Sites. Most of the Organizations advertise their job openings in their websites. 
  2. Buy a news paper one of these days when they have a Job Advertisement Suppliment. Most of the good companies advertise directly through the news papers. 
If you do this, you can be at least happy that people are not duping you, manipulating your need to get a job.

August 16, 2009

webfinger: Soon you could be using Gmail ID for more than emailing!

What do we use our Gmail Ids for? To send and receive emails, to log in to Google related services and sometimes, use other web services that require email IDs and not usernames. We use any email Id by any service provider, for that matter, to do similar things.

Try searching an email id to find out more about the owner of the ID! You will get absolutely no information about the person as there is no way a person can attach information to his or her email id. Email IDs are not linked to personal information the way social networking IDs are linked to personal information. For example, if you search for a long lost friend, it is quite likely that his or her social network profile pages like Twitter, Face Book or Linkedin would show up in the search. But not if you use an email ID instead of the name. Because as mentioned in the Google Code Summary Page on webfinger: "If I give you my email address today, you can't do anything with it except email me. I can't attach public metadata to my email address to give you more information." Now, through the "webfinger Project" launched on April 28, 2009, Google is trying to make it possible for people to attach personal information to their Email Ids. In other words, Google is on a project to make email Ids searchable!

What are the implications of this innovation? I don't know if you know, this is not a new idea. This was something tried during the initial Internet years. A finger programme was written by Les Earnest to help those users who wanted to find out information about other users using their emails. However, by 1990, websites and companies stopped using this service as it was a threat to security and privacy of individuals. Hackers used this service to carry out social engineering attacks on companies and individuals.

Why is Google bringing back a service that was tested and dropped, years ago? Why do they, all of a sudden, want to make an email id both 'writable' and 'readable' like a URL? Experts say that Google is trying to come up with an alternative to open ids! I understand the concern about the failure of Open ID System, as people don't use Open IDs often. It is perfectly fine if Google is only trying to make people use their email ids instead of Open ID URLs, to access all the web services. But I don't understand that part where Google says it is also thinking of making emails 'readable'.

I'm already thinking of taking off my profiles from the popular social networking sites. After Twitter and Face Book allowed me to customize my URL the way I want to, I am increasingly worried about the idea that I'm now more prone to social engineering attacks. [Thank God, I have an option to keep all my information closed to me and the people I know on Face Book and Twitter. But not on Linkedin!] Because every time you search my name, I show up in the search and it is not always good to leave trails online.

Google already collects information about what I search. They use my Gmail ID to keep track of what I search! Now, they are trying to get me attach personal information to the very same Gmail ID I use. If that is done, Google knows who I am and what I do online. That is a lot of information, I can give away, don't you think?

And if Google makes my email searchable or 'readable' as they calim they are going to do, it means people can dig out my Google Profile [Or my Face Book Profile or my Orkut Profile or my Linkedin Profile or my Twitter Profile] using my email as the key word. Now, they can do that only using my the Name. Where your online life is concerend, your email id is more credible than you name, as your email id is directly linked to you unlike your name. A name or username is not considred to be credible or authentic online. Emails Ids are legal today and emails are accepted as evidence for this reason. Doesn't Google understand the political implications of this move?

August 9, 2009

The Cyxymu Lesson: Forwarding Emails is E-Sin!

I have many friends who keep in touch only by forwarding emails. There are people from whom I receive forwarded emails on a day to day basis. Many of them do it very innocently, I know, knowing little that they are possibly making themselves and the receiver vulnerable to potential internet misuse by hackers and spammers.

We have a live example in front of us: Twitter. It is quiet possible that when you click on this link you get an error message and the site does not load as Twitter is under a Denial of Service Attack. I am told that the Denial of Service attack on Twitter has increased ten times on the second day of the attack. I am not going into the 'geopolitical nature' of the attack. I am not going to make assumptions about who did this. I am not so much worried about if the Russian Government did it or some Criminal Outfit is behind this attack. That is Twitter's job to find out and tell the world. I am more bothered about how this could happen!

How could this happen? Wikipedia tells me that a Denial of Service Attack happens when the number of requests for a particular site increases beyond the capacity of the servers on which a site is hosted. They also call it Distributed Denial of Service Attack. Hackers target popular sites and prevent them from functioning through a Denial of Service Attack. And this is what happened to Twitter.

DoS on Twitter seems to have happened as an individual or an organization was targeting a blogger named Cyxymu. When repeated requests for his page on Twitter, LiveJournal et al happened on August 6, 2009, the servers where the sites are hosted could not handle it and as a result the whole Twitter Site stopped functioning.

People have different opinion about how it happened. Some say that Russian Hackers hacked Cyxymu's Gmail Account and started sending links to his accounts to people. And when people started clicking on these links to know what exactly it was, DoS began! I don't think so because an attack of this sort cannot survive on email links alone, though it is true that a Joe Job Email Campaign happened from Cyxymu's Gmail Account.

There is another theory, which is more plausible. Experts say that the attack was managed using botnets. Botnets are, in simple words a network of computers which runs software robots. The hackes who drowned Twitter seem to have a huge network of computers they could use to send repeated requests for the site. Where did they get all these computers from, because you need millions of computers to organize an attack at this level of ferocity?

Probably they got all these computers linked up through emails. People send you hundreds of forwarded emails. Have you ever wondered where they come from? Who would take such struggles to create information and send it to you for free? Who made the original message?

I have no idea who sends them. But I know one thing. The original messages are sent using automated services available online. There are sites that let you send bulk emails for free and keep a track of them. [I am not giving you a link to an example site for an obvious reason - I don't want to be a party to the prorogation of such sites] Usually these emails, though they may sound very innocent, contain malware that plant robots in your system. They link up with each other and create a network after they are in your system. This way hackers get to use your system even without your knowledge.

I think we should stop forwarding emails and opening emails that are forwarded. Forwarded emails compromise the security of personal information as well as personal computers. Forwarding E-mails should be considered as E-sin. Why?

  1. Forwarded emails are an easy way for hackers to spread their bots on systems across the world. 
  2. Forwarded emails may contain viruses that are harmful to your system.
  3. Because there are systems that can easily track forwarded mails, you should know that your are compromising the email addresses of the friends to whom you send the email. Hackers who keep track of the mails add the new addresses to their mailing list and harvest.
  4. Forwarding E-mails is a waste of other people's time. They may not be interested in the mail you have forwarded. 


After Thought: I also have another doubt. There are many companies today that allow you to use Remote PC Support for free. They permit you to use software that allows you to access and use computers from anywhere. Have you ever thought why they do it for free? If I can use that software to control computers in my network remotely, they companies who give them to me can do it too. And what if these companies used the computers that use their Remote PC Support Software and turn them into a botnet? I am told that there are companies who sell such networks to third parties for campaigns and other internet related activities. There are people who sell botnets and make good money out of it. What if the attackers bought one such botnet to attack Twitter?

How to prevent ad-type.google.com from ruining your reading experience?

Ad-type.google.com is a nuisance. It is the meanest possible click fraud one would ever encounter online. It affects your browsing experien...