At $439, the DJI Flip could be a good starting point for people who don’t typically buy drones at all. You can unfold it, launch it from your hand with a single button, land it on your hand again, or optionally use joysticks, all while capturing higher quality photos and video than the immediate competition.
Technology
Tired of getting those mysterious password reset emails? Here’s what to do about it
Passwords can definitely be a frustrating part of our lives. Remembering which passwords you used for your dozens of different accounts is nearly impossible without the help of password managers.
Should you suddenly start receiving constant emails telling you that you have to reset your password for whatever reason (or sometimes with no reason listed) on top of everything else, you may be at the end of your patience.
Several reasons exist for receiving these email messages, and they can range from legitimate to scam to somewhere in between.
CLICK TO GET KURT’S FREE CYBERGUY NEWSLETTER WITH SECURITY ALERTS, QUICK VIDEO TIPS, TECH REVIEWS AND EASY HOW-TO’S TO MAKE YOU SMARTER
What is a password reset email message?
When you are entering your username and password at a website to access your account, you may see a small “Forgot Password” text link. If you can’t remember your password, and you click this link, the account holding company will send you an email that allows you to reset your password. This type of email reset message, like the one below, would be a legitimate one.
However, some password reset emails you receive are fake, usually attempting to trick you into revealing your username and password to a hacker.
MORE: THIS IS HOW YOUR EMAIL GETS INTO WRONG HANDS
Why do I receive fake password reset emails?
When you receive email messages asking you to reset a password when you did not make the request, the message could be a fake. Some of the reasons you may receive fake emails like this include:
Beware the bait: A hacker is attempting a phishing attack, hoping you’ll click on a fake link in the message.
Privacy alert: You potentially shared your email address at an unsafe website, and hackers are trying to steal your account password by tricking you into revealing it.
Security warning: Your account has some sort of security issue that is triggering these messages.
Update required: You may need to update your software or app to the latest version.
MORE: HOW TO KEEP YOUR ONLINE PASSWORDS SAFE
What should I do if the password reset emails are legitimate?
The password reset email message you are receiving could be a legitimate request. It may indicate that your account is under attack from a hacker. You can protect yourself in a few ways.
Go to the website directly and access your account. Then change your password to make it stronger.
Set up two-factor authentication (2FA) on your account. Should someone figure out how to hack your account password, having the second verification requirement significantly protects you.
Reach out to the website that holds your account for help with taking the necessary steps to protect yourself.
You may receive the message because you need to change your password every few months to match the requirements of the company holding the account.
Never click on a link in the email message as it could be a fake. If you click on it, you may actually give the hacker the information to take over your account rather than protect your account. The best way to protect yourself from clicking malicious links that install malware that may get access to your private information is to have antivirus protection installed on all your devices. This can also alert you of any phishing emails or ransomware scams.
Get my picks for the best 2024 antivirus protection winners for your Windows, Mac, Android & iOS devices.
Steps you can take to eliminate password reset emails
You can take a few steps to try to reduce the number of emails you receive requesting a password reset.
1. Double-check your username and password. When accessing your account, you may have a typo in your login information. Should you repeatedly attempt to access your account with this error, the company that holds the account may believe a hacking attempt is occurring, triggering an automatic reset. If your web browser automatically populates your username and password for you, make sure this information is free of typos.
RURAL TEXAS TOWNS REPORT CYBERATTACKS THAT CAUSED WATER SYSTEM TO OVERFLOW
2. Remove unauthorized devices. Some accounts maintain a list of devices authorized to use your account. If a hacker manages to gain some of your personal information, it may be able to add one of its devices to your authorized list, triggering account login errors as it tries to hack your password. Check the list of authorized devices and remove any items you don’t recognize.
The process varies, depending on the type of account. We’ll cover steps for Microsoft, Gmail, Yahoo and AOL.
Microsoft:
- From your Microsoft account home page, click on your personalized logo at the top right of the page.
- Then click My Microsoft Account
- Scroll down the page until you see your list of trusted devices.
- Click View All Devices
- On the next page, you can click Remove Device for any device you want to remove from your account.
Gmail:
- Sign in to your Google Account at myaccount.google.com.
- Click the Security tab on the left side of the page.
- Scroll down to the section labeled “Your Devices” and select Manage all devices.
- You’ll see a list of devices where your Google account is currently signed in.
- If you see a device you don’t recognize, click on it and select Sign out.
Yahoo:
- Go to the Yahoo Account security page at help.yahoo.com/kb/account.
- Click on Recent activity.
- Review the list of devices and locations that have accessed your account.
- If you notice any unfamiliar activity, click Remove or Sign out next to the suspicious device.
AOL:
- Sign in to your AOL account and go to the Recent Activity page.
- Review the sections for Recent activity, Apps connected to your account and Recent account changes.
- If you find any activity or devices that you don’t recognize, click Sign out or Remove next to it.
Remember to regularly check your account settings and authorized devices to ensure the security of your accounts. If you suspect any unauthorized access, it’s also a good idea to change your passwords and review your account recovery options.
3. Sort such messages to spam. If you’d prefer to simply not see these kinds of email messages, set up your email client to sort messages like this to a spam folder. (Because many of them are spam, some email clients do this automatically.) Should you ever legitimately request a password reset, though, you’ll need to remember to look in the spam folder for the message.
4. Use a static IP address. Some accounts attempt to recognize your device through your IP address. If you have a dynamic IP address, your IP address changes constantly, meaning the account may not recognize your device, triggering the reset message. This often occurs because you are using a VPN. See if your VPN allows you to use a static IP address.
MORE: WHAT HAPPENS WHEN CYBERCRIMINAL GETS ACCESS TO YOUR EMAIL ADDRESS
Kurt’s key takeaways
Although it can be frustrating to receive password reset emails, you should investigate any request like this that comes from an account you use regularly. Reach out to the customer service team for the account where you are having the issue. You may find that a simple glitch is causing the issue. Fix that, and you can put a halt to these frustrating messages. Or if it is a fake password reset email, you now know how to handle the situation to stay safe and secure.
Can you share a time when you strengthened your online security measures in response to a threat? What prompted it and how did you do it? Let us know by writing us at Cyberguy.com/Contact.
For more of my tech tips and security alerts, subscribe to my free CyberGuy Report Newsletter by heading to Cyberguy.com/Newsletter.
Ask Kurt a question or let us know what stories you’d like us to cover.
Answers to the most asked CyberGuy questions:
Copyright 2024 CyberGuy.com. All rights reserved.
Technology
North Korea linked to crypto heists of over $650 million in 2024 alone
Hackers in North Korea stole a total of $659 million in crypto across several heists in 2024, according to a joint statement issued today by the US, Japan, and South Korea. The report specified five such incidents, like the $235 million theft from the Indian crypto exchange WazirX that is being newly attributed to the Lazarus Group. That organization is estimated to have stolen billions across previous attacks over the last decade, including $625 million stolen from Axie Infinity in 2022.
As recently as September 2024, the United States government observed aggressive targeting of the cryptocurrency industry by the DPRK with well-disguised social engineering attacks that ultimately deploy malware, such as TraderTraitor, AppleJeus and others. The Republic of Korea and Japan have observed similar trends and tactics used by the DPRK.
A warning issued by the FBI last September noted that their methods to gain access for delivering these payloads include “individualized fake scenarios,” such as enticing victims with prospective jobs and business opportunities. All three countries advised businesses in the industry to check out the latest warning to reduce their risk of “inadvertently hiring DPRK IT workers,” as described in this recent report by CoinDesk.
They’ve also used long-time common phishing tactics against employees of crypto firms, such as convincing impersonations of trusted contacts or prominent people of interest in related industries, with realistic photos and information likely lifted from public social media accounts of known connections.
Technology
Hackers claim massive breach of company that tracks and sells Americans' location data
When we talk about data privacy, tech giants like Google and Facebook are often blamed for using personal data to show ads and recommendations. Less discussed are the businesses whose entire business model revolves around collecting your data and selling it to other companies and governments. These companies often operate in legal gray areas, with the consent required to collect user data buried deep in the fine print.
What’s even more concerning is that these data brokers fail to adequately protect the data they collect. Last year, National Public Data made headlines for failing to secure 2.7 billion records of individuals whose data it had harvested. Now, hackers have reportedly stolen data from Gravy Analytics, the parent company of Venntel, which has sold vast amounts of smartphone location data to the U.S. government.
I’M GIVING AWAY THE LATEST & GREATEST AIRPODS PRO 2
Enter the giveaway by signing up for my free newsletter.
What you need to know about the breach
Hackers claim to have breached Gravy Analytics, a major location data broker and parent company of Venntel, a firm known for selling smartphone location data to U.S. government agencies. The compromise is massive, including sensitive location data that tracks precise smartphone movements, customer information and even internal infrastructure, according to a 404 Media report.
The hackers are threatening to make the stolen data public. The files contain precise latitude and longitude coordinates of the phone and the time at which the phone was there. Some even indicate what country the data has been collected from.
Hackers have claimed access to Gravy’s systems since 2018. If true, this represents a serious security lapse on the company’s part. It is baffling how companies that collect and sell user data (a practice that arguably shouldn’t be allowed in the first place) failed to protect it from being leaked.
404 Media also suggests that the hackers gained deep access to the company’s infrastructure, including Amazon S3 buckets and server root access. The exposed customer list reportedly includes major companies like Uber, Apple and Equifax as well as government contractors like Babel Street.
HERE’S WHAT RUTHLESS HACKERS STOLE FROM 110 MILLION AT&T CUSTOMERS
What this breach means for people
This data breach highlights the serious security flaws in the location data industry. Companies like Gravy Analytics and Venntel have been profiting from collecting and selling sensitive location data, often without proper user consent. They’ve prioritized profit over security, and now the privacy of millions is at risk. This data could end up on black markets, endangering individuals, especially those in vulnerable situations, by making them targets for harassment or worse.
The FTC’s recent crackdown on Gravy, announced in December, underscores their negligence. The proposed order will prohibit these companies from selling or using location data, except in specific cases like national security or law enforcement. The implications are worrying. Sensitive locations like schools and workplaces could become easy targets for those with malicious intent.
BEWARE OF ENCRYPTED PDFs AS THE LATEST TRICK TO DELIVER MALWARE TO YOU
5 ways to stay safe in the age of data breaches
The Gravy Analytics breach serves as a sobering reminder of the vulnerabilities in the digital age. While it’s impossible to control how every company handles data, you can take steps to minimize your exposure and protect your privacy. Here are five actionable tips to stay safe.
1) Limit app permissions: Many apps request access to location data, contacts and more, even when it’s not necessary for their functionality. Regularly review the permissions for apps on your smartphone and revoke access to anything that feels excessive. For instance, a weather app doesn’t need access to your microphone or camera.
2) Use a VPN: Virtual private networks (VPNs) can mask your IP address and encrypt your internet activity, making it harder for data brokers and hackers to track your online behavior. A good VPN adds an extra layer of security, especially when using public Wi-Fi networks. For the best VPN software, see my expert review of the best VPNs for browsing the web privately on your Windows, Mac, Android and iOS devices.
3) Opt out of data sharing where possible: Some companies allow you to opt out of having your data collected or shared. Services like Your Ad Choices and privacy settings within platforms like Google can help you reduce the amount of data collected. Check for opt-out options with any apps or services you use frequently.
4) Avoid free apps that monetize data: Free apps often generate revenue by selling user data. Instead, consider paid versions of apps that explicitly prioritize privacy. Research the company behind the app to understand its data handling policies before downloading.
5) Invest in data removal services: Data removal services can help you regain some control over your personal information by identifying and removing it from people-search websites, data broker platforms and other online databases. Check out my top picks for data removal services here.
WHAT TO DO IF YOUR BANK ACCOUNT IS HACKED
Kurt’s key takeaway
Companies that collect and sell user data pose a significant threat to privacy, and when they fail to protect this data, it often ends up in the hands of even worse actors. Cybercriminals, and even some governments, can exploit this information to target individuals. It is crucial to implement stringent repercussions for these companies when they fail in their duty to safeguard user data. A mere slap on the wrist is not enough. We need real accountability to deter negligence and protect individual privacy rights.
Should companies face stronger penalties for failing to protect personal data? Let us know by writing us at Cyberguy.com/Contact.
For more of my tech tips and security alerts, subscribe to my free CyberGuy Report Newsletter by heading to Cyberguy.com/Newsletter.
Ask Kurt a question or let us know what stories you’d like us to cover.
Follow Kurt on his social channels: Answers to the most asked CyberGuy questions:
New from Kurt:
Copyright 2024 CyberGuy.com. All rights reserved.
Technology
DJI Flip official: the unique bicycle spoke folding drone starts at $439
In August, my colleague Thomas Ricker told you how DJI rival Hover had changed the game by selling a $349 flying camera that doesn’t require people to learn joysticks; with the $199 DJI Neo, DJI looked poised to muscle in on that in a big way. But the $439 Flip not only lets you launch and film basic dronies, orbits, and follow-me shots from the drone itself, it dramatically increases camera quality, flight stability, battery life (a quoted 31 minutes), and lets you launch it faster. You just won’t be able to fly it FPV like some of us were hoping.
Not only is the Flip the first DJI drone to look like a Star Wars AT-AT walker or a penny-farthing bicycle when folded, it’s also the first to automatically power on when you unfold it, saving two button presses. And when you flip out each of its four spoke-filled full-coverage propeller guards — which DJI says are a first for its folding drones — they join an auto-braking, forward-facing 3D infrared sensor to protect the camera from any front impacts as well.
1/9
And while that camera isn’t quite as impressive as the 1.0-inch type found on DJI’s Osmo Pocket 3, I was impressed by my first results in good light! It’s smaller 1/1.3-inch 4K60 sensor with 4:3 aspect ratio is capable of taking 2.7K vertical video or 48 megapixel stills behind a fast f/1.7 aperture lens. Here are a couple of my unedited early flights, a drone selfie, and a photo, to give you an idea:
Frankly, the DJI Neo — which costs less than half as much — can’t come close to this level of performance; over the same lake and the same park, the Neo couldn’t even maintain a smooth level shot as the breeze blew its lighter frame around, and its images were muddy and washed out by comparison. The Flip has a three-axis gimbal to help maintain that stability. Also, pros can record in 10-bit D-Log M.
But other, pricier DJI drones could offer better performance still, plus true vertical shooting by rotating the gimbal — and it’d be hard to imagine a drone enthusiast picking the Flip instead of waiting to see what DJI’s unannounced Mini 5 might bring to the table.
“There are currently no plans to retire the Mini Series. The DJI Flip is a new entry-level drone series that will be offered alongside the DJI Neo and DJI Mini. Each of these drones are designed to meet the needs of different types of beginners,” DJI spokesperson Daisy Kong confirms to The Verge.
I am continually surprised by how large the Flip is; while it stays under the 249-gram weight limit that typically triggers government compliance standards like publicly broadcasting your location. Despite its folding arms, it doesn’t fold down smaller than a Mini so there’s no way I’m fitting it into any but the biggest cargo pants pockets I own. It’s also quite loud despite its ducted propellers — absolutely not among the quieter drones that the company sells.
And despite costing more than the $199 DJI Neo, it doesn’t support any FPV headsets to let you virtually soar like a bird.
But the Flip does cost just $439 complete with a basic RC-N3 joystick controller that lets you use your phone as a screen, plus the launch-it-from-your-hand modes; a $779 kit comes with three batteries, a carrying case, and a more capable DJI RC 2 controller with a built-in daylight visible 700-nit screen. The DJI Mini 4 Pro versions of each of same kits cost $959 and $1,099 respectively, a $320 difference.
The DJI Flip should be available to buy and ship today, from DJI’s website.
Photography and video by Sean Hollister / The Verge
-
Politics1 week ago
Who Are the Recipients of the Presidential Medal of Freedom?
-
Health1 week ago
Ozempic ‘microdosing’ is the new weight-loss trend: Should you try it?
-
Technology5 days ago
Meta is highlighting a splintering global approach to online speech
-
Science3 days ago
Metro will offer free rides in L.A. through Sunday due to fires
-
Technology7 days ago
Las Vegas police release ChatGPT logs from the suspect in the Cybertruck explosion
-
Movie Reviews1 week ago
‘How to Make Millions Before Grandma Dies’ Review: Thai Oscar Entry Is a Disarmingly Sentimental Tear-Jerker
-
Health1 week ago
Michael J. Fox honored with Presidential Medal of Freedom for Parkinson’s research efforts
-
Movie Reviews1 week ago
Movie Review: Millennials try to buy-in or opt-out of the “American Meltdown”