Erik van Straten<p><span class="h-card" translate="no"><a href="https://worldkey.io/@NadCee" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>NadCee</span></a></span> : that may convince *some* people to change their behavior/behaviour.</p><p>However, for most Joe/Jill Average's, the risk that a possibly authoritarian government will harm them personally, is actually quite low.</p><p>I'm a lot more worried (for them) about the risk of "meeting" criminals.</p><p>For example, most people use weak passwords, or reuse one single password, or both - including for their email account - because they believe that they have nothing to hide. Some are now using an Authenticator app because they were made to believe it'll save their a** (see <a href="https://infosec.exchange/@ErikvanStraten/113906668541621372" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">infosec.exchange/@ErikvanStrat</span><span class="invisible">en/113906668541621372</span></a>). Why would *anyone* be interested in their "how're you" emails with pictures of their cat?</p><p>Here's what happens: after criminals obtain access to their email account (and/or social media), those criminals start posing as them.</p><p>The criminals will get to learn the tone the naive people (aka idiots) use to communicate with their friends and family, and may ask them (friends and family) to send money (btw they just changed banks) or install malware. The criminals often will be able take over all of the other online accounts of the naives. They may use such accounts (or create new ones in your name) to exchange illegal stuff, including child pornography.</p><p>It's called impersonation aka identity theft.</p><p>Every peace of information about you may be valuable to a criminal. Knowing your email address, they'll send you phishing mails. They may plant a photo of your head on pornography and extort you. They may clone your voice to impersonate you, using that to obtain access to vulnerable people you know - such as your parents or kids.</p><p>If they know that you are (or one of your contacts is) old and/or vulnerable (like Alzheimers), and find out your/their contact details, they may phone claiming they're an employee from the bank. They'll say that the bank just noticed that criminals obtained access to your bank account, and that you must act *now* to prevent losing all of your savings. They'll offer help. Like installing "security software" (typically AnyDesk) to prevent further damage, or guide you through moving your savings to a "vault" account. And/or they'll tell you that they're sending a courier to pick up your bank cards (and PIN's).</p><p>Drag queens and other "non-standard" people, like pro-climate, anti-genocide (often called pro-Palestinian) protestors, typically *know* that they're at risk - from authorities.</p><p>I'm more worried about naive people who lack any security awareness and typically have nothing to fear from even the most authoritarian governments. They'll install *any* app (like <a href="https://infosec.exchange/tags/DeepSeek" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>DeepSeek</span></a>) because it's a lot of phun, thereby sharing details like their location and/or the address books on their phone. They'll make their home "smart" by automating it with hackable electronics. They'll pay for "cheap" things from dropshipping or plain fake websites.</p><p>Awareness includes knowing things like this: <a href="https://www.bleepingcomputer.com/news/security/unitedhealth-now-says-190-million-impacted-by-2024-data-breach/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">bleepingcomputer.com/news/secu</span><span class="invisible">rity/unitedhealth-now-says-190-million-impacted-by-2024-data-breach/</span></a>. From <a href="https://www.bleepingcomputer.com/news/security/ransomware-gang-claims-they-stole-6tb-of-change-healthcare-data/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">bleepingcomputer.com/news/secu</span><span class="invisible">rity/ransomware-gang-claims-they-stole-6tb-of-change-healthcare-data/</span></a> (condensed):<br>"the sensitive data stolen from Change Healthcare contains a wide range of information on millions of people, including their: medical records, insurance records, dental records, payments information, claims information, patients' PII data (i.e., phone numbers, addresses, SSNs/SOCIAL SECURITY NUMBERS, email addresses, and more), and active U.S. military/navy personnel PII data".</p><p>It's a long list. Protect your identity, assume breach!</p><p><span class="h-card" translate="no"><a href="https://social.wildeboer.net/@jwildeboer" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>jwildeboer</span></a></span> </p><p><a href="https://infosec.exchange/tags/PrivacyAwareness" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>PrivacyAwareness</span></a> <a href="https://infosec.exchange/tags/SecurityAwarenes" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SecurityAwarenes</span></a> <a href="https://infosec.exchange/tags/RiskAwareness" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>RiskAwareness</span></a> <a href="https://infosec.exchange/tags/Authentication" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Authentication</span></a> <a href="https://infosec.exchange/tags/Impersonation" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Impersonation</span></a> <a href="https://infosec.exchange/tags/Fraud" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Fraud</span></a> <a href="https://infosec.exchange/tags/BankFraud" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>BankFraud</span></a> <a href="https://infosec.exchange/tags/Impostors" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Impostors</span></a> <a href="https://infosec.exchange/tags/SmartHome" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SmartHome</span></a> <a href="https://infosec.exchange/tags/SmartWhatever" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SmartWhatever</span></a> <a href="https://infosec.exchange/tags/CSAM" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CSAM</span></a> <a href="https://infosec.exchange/tags/Identity" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Identity</span></a> <a href="https://infosec.exchange/tags/Awareness" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Awareness</span></a> <a href="https://infosec.exchange/tags/CyberSecurityAwareness" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CyberSecurityAwareness</span></a></p>