<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[Plain Speak Cyber]]></title><description><![CDATA[I'm Aaron, a cyber security engineer with a passion for enabling the everyday person to defend themselves against online criminals in practical ways with approachable guidance.]]></description><link>https://plainspeakcyber.tech</link><image><url>https://substackcdn.com/image/fetch/$s_!lNh6!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53db8219-3006-4240-b219-05279d924d08_1024x1024.png</url><title>Plain Speak Cyber</title><link>https://plainspeakcyber.tech</link></image><generator>Substack</generator><lastBuildDate>Tue, 21 Apr 2026 08:25:39 GMT</lastBuildDate><atom:link href="https://plainspeakcyber.tech/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Aaron Matassa]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[plainspeakcyber@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[plainspeakcyber@substack.com]]></itunes:email><itunes:name><![CDATA[Plain Speak Cyber]]></itunes:name></itunes:owner><itunes:author><![CDATA[Plain Speak Cyber]]></itunes:author><googleplay:owner><![CDATA[plainspeakcyber@substack.com]]></googleplay:owner><googleplay:email><![CDATA[plainspeakcyber@substack.com]]></googleplay:email><googleplay:author><![CDATA[Plain Speak Cyber]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[Passwords Stolen from Photo Storage]]></title><description><![CDATA[What's in your photos?]]></description><link>https://plainspeakcyber.tech/p/passwords-stolen-from-photo-storage</link><guid isPermaLink="false">https://plainspeakcyber.tech/p/passwords-stolen-from-photo-storage</guid><dc:creator><![CDATA[Plain Speak Cyber]]></dc:creator><pubDate>Tue, 24 Mar 2026 11:10:42 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!lNh6!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53db8219-3006-4240-b219-05279d924d08_1024x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Many of us take pictures of sensitive information for quick reference and we often don&#8217;t delete them when done. </p><p>Criminals <a href="https://securelist.com/sparkcat-stealer-in-app-store-and-google-play/115385/">have been reported</a> using apps loaded with a virus to scan photos using Optical Character Reignition (OCR) - which is how computers can recognize text from images.</p><p>When a photo with sensitive information was found the app would upload it to the criminal. In this case they were looking for passwords to crypto-currency wallets, though it&#8217;s not a far stretch to apply this process to other types of sensitive information.</p><p>What should we do?</p><p>Both Android and Apple devices allow us to search by keyword in our stored photos. Try searching for the below types of phrases.</p><p></p><ul><li><p>Password</p></li><li><p>Account</p></li><li><p>Account Number</p></li><li><p>Bank Account</p></li><li><p>License</p></li><li><p>Driver&#8217;s License</p></li><li><p>License Plate</p></li><li><p>Document</p></li><li><p>Birth Certificate</p></li><li><p>Social Security Card</p></li></ul><p></p><p>Find data we wouldn&#8217;t want someone else to have? Simply delete the photo. If the information is needed for reference consider saving it in a password manager, which we can <a href="https://plainspeakcyber.substack.com/p/top-recommendation-use-a-password">review my guide</a> if we don&#8217;t have one.</p><p>My photos were <strong>not</strong> innocent during this process, but I did free up some space and deleted a lot of receipts.</p><p>Did you find a different phrase that was useful? Share it with me and I&#8217;ll update this post.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://plainspeakcyber.tech/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Subscribe to receive cyber guidance and alerts in plain speak.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p>]]></content:encoded></item><item><title><![CDATA[Top Recommendation - Use a Password Manager]]></title><description><![CDATA[And not the web browser's manager]]></description><link>https://plainspeakcyber.tech/p/top-recommendation-use-a-password</link><guid isPermaLink="false">https://plainspeakcyber.tech/p/top-recommendation-use-a-password</guid><dc:creator><![CDATA[Plain Speak Cyber]]></dc:creator><pubDate>Tue, 03 Mar 2026 04:12:43 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!gMYn!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff40c23c8-ffc4-43e5-91c3-efeb961ead4d_740x601.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>If there&#8217;s one piece of advice I can give to anyone it&#8217;s to use a password manager. It&#8217;s a change that can seem daunting, but is very doable.</p><h4>What is a password manager</h4><p>Simply, it&#8217;s a platform that stores our passwords or other sensitive items such as files or even credit card details. And yes, they store passkeys as well so this is still a relevant tool for the long haul. </p><h4>Why use a dedicated password manager</h4><p>Password reuse, using the same password across multiple online services, is a practice that eventually will lead to a criminal getting hold of our passwords and with access to multiple services from a single breach. Password managers allow us to remember <em>one</em> password and save all of our other passwords, which will be a long string of random characters that are unique to each platform.</p><p>Many rely on their browser to save passwords for them or a file on the computer desktop named Passwords, but these are highly susceptible to theft by malware or social engineering and often lead to a fragmented/confusing experience.</p><p>A dedicated password manager keeps the keys in <em>our</em> control in an encrypted manner reducing the probability of a criminal stealing the password data significantly. </p><p>The downside - if we lose access to the password manager there is no recovery option. But don&#8217;t fear, below we review a method to prevent just that.</p><h4>What are some services to consider</h4><ul><li><p><a href="https://1password.com/">1Password</a></p><ul><li><p>No free tier, Individual plan ($48/yr) is fully featured and recognized as being very easy to use</p></li><li><p>Supports sharing of passwords with people not on 1Password </p></li><li><p>Family plan option at $72/yr</p></li></ul></li><li><p><a href="https://bitwarden.com/">Bitwarden</a></p><ul><li><p>Highly featured free tier</p></li><li><p>Paid tier ($20/yr) </p></li><li><p>Supports Emergency Access, where you can designate a trusted person, who also has a Bitwarden account, to be granted access to your passwords upon request after a waiting period</p></li><li><p>Family plan option at $48/yr</p></li></ul></li><li><p><a href="https://www.keepersecurity.com/">Keeper</a></p><ul><li><p>Free tier is essentially a very limited trial </p></li><li><p>Individual plan ($40/yr) is fully featured</p></li><li><p>Family plan option at $85/yr</p></li></ul></li></ul><p>Which to choose? It&#8217;s hard to argue against Bitwarden&#8217;s cost, but 1Password may be better for those who appreciate an easier to use design. Keeper is more commonly used with businesses with features for teams.</p><p>There are more options and this is an area where diversity is a good thing. Feel free to spend some time on a few different sites to see what feels best, the steps below will be the same regardless of this choice. </p><h4>What are some services to avoid</h4><ul><li><p>Web browser managers like Microsoft Edge, Google Chrome, and Firefox</p></li><li><p>Apple Keychain / Safari Auto-fill - While a step up from browsers, any service that can recover your passwords for you is susceptible to social engineering attacks. Additionally, Keychain is targeted in similar malware attacks as browsers.</p></li><li><p>LastPass - A popular password manager that has suffered <a href="https://en.wikipedia.org/wiki/LastPass#Security_incidents">multiple significant security breaches</a>.</p></li></ul><h4>How to set up a Password Manager</h4><h5>A) The Pass Phrase</h5><p>After you have chosen a service create an account. In doing this you will need to create a Master Password.</p><p>Or in this case, we will use a Pass Phrase, which is the same thing as a password except it is a handful of words without any special characters.</p><p>I highly recommend <a href="https://preshing.com/20110811/xkcd-password-generator/">this password generator from XKCD</a> which will generate random pass phrases. Their comic does a great job of explaining why: </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!gMYn!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff40c23c8-ffc4-43e5-91c3-efeb961ead4d_740x601.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!gMYn!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff40c23c8-ffc4-43e5-91c3-efeb961ead4d_740x601.png 424w, https://substackcdn.com/image/fetch/$s_!gMYn!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff40c23c8-ffc4-43e5-91c3-efeb961ead4d_740x601.png 848w, https://substackcdn.com/image/fetch/$s_!gMYn!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff40c23c8-ffc4-43e5-91c3-efeb961ead4d_740x601.png 1272w, https://substackcdn.com/image/fetch/$s_!gMYn!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff40c23c8-ffc4-43e5-91c3-efeb961ead4d_740x601.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!gMYn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff40c23c8-ffc4-43e5-91c3-efeb961ead4d_740x601.png" width="740" height="601" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f40c23c8-ffc4-43e5-91c3-efeb961ead4d_740x601.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:601,&quot;width&quot;:740,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!gMYn!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff40c23c8-ffc4-43e5-91c3-efeb961ead4d_740x601.png 424w, https://substackcdn.com/image/fetch/$s_!gMYn!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff40c23c8-ffc4-43e5-91c3-efeb961ead4d_740x601.png 848w, https://substackcdn.com/image/fetch/$s_!gMYn!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff40c23c8-ffc4-43e5-91c3-efeb961ead4d_740x601.png 1272w, https://substackcdn.com/image/fetch/$s_!gMYn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff40c23c8-ffc4-43e5-91c3-efeb961ead4d_740x601.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The key is to NOT use words that are associated with ourselves, such as pet names or street addresses. Keep away from anything that would be a common security question or guessable from social media. Hence the value in the generator.</p><div><hr></div><p><em>Feel free to generate multiple pass phrases until you find one you like. And it&#8217;s ok to choose 3 of the words instead of 4. </em></p><div><hr></div><p>When we have chosen our passphrase we need to store it somewhere safe, such as written down at home.</p><p>Note that if we lose this password our password manager account is not recoverable. This is a key security feature to prevent criminals from accessing this information. Don&#8217;t worry - by using the above pass phrase technique we will remember it <em>much</em> sooner than we realize. </p><p>Then we sign up with the service using this password. Don&#8217;t forget to install the browser extension (if you use a desktop/laptop) and the app on our phone. </p><p>See, already getting password memorization reps in.</p><h5>B) The Migration</h5><p>There are two options in migrating from using the same password or the password file. The right option simply is determined by what works best for us and it&#8217;s likely that we will mix the two. </p><p>I) Do it all at once</p><p>II) Do it over time</p><p>Option I consists of sitting down for an hour or two to log onto each website to change your password, saving the new password in the password manager. </p><p>Option II is to preform the password change and save process as you visit each site during normal use when you see that it&#8217;s not saved in your password manager. </p><p>Both options follow the same core workflow below. Note that if following Option I this will be easiest on a laptop/desktop computer vs a phone.</p><p></p><p>Step 1) Visit the site and log in. Navigate to the Change Password setting and start the password change process. </p><p>Step 2) When prompted for your new password open your password manager, ideally by the browser extension, and select new login. Enter your Username and use the generate button to generate a unique password. </p><div><hr></div><p><em>Different sites will have varying password requirements to follow. When possible choose a password length of 20 or more characters with a mix of upper case letters, lowercase letters, numbers, and symbols.</em> </p><div><hr></div><p>Step 3) If using the browser extension often the website URI will autofill. (URI is the technical term for a website URL). If it is not auto-filled be sure to populate it if we are saving a password for a website. A proper URI will look like https://example.com/. It&#8217;s ok if there&#8217;s a bunch of words after the /. </p><p>Step 4) Save the password manager entry then paste the password in the site to complete the change process. </p><p>This website is now stored in your password manager. We can test it by logging out and signing back in. The password can be accessed by copy/paste from the phone app or browser extension. And depending on the device we use the service may autofill the username and password when it recognizes the URI.</p><h5>C) Disable Default Password Managers</h5><p>Recall how we recommended against default password managers like the web browser? Well, they won&#8217;t be happy and will still insist to be used. Here&#8217;s how to disable that in popular platforms</p><p><strong>Google Chrome</strong>: Copy and paste the following into Chrome <em>chrome://password-manager/settings</em> and toggle off the pictured settings: </p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!gNWo!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefec7865-ef5e-4a8a-ad6e-48110a20e5bd_688x189.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!gNWo!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefec7865-ef5e-4a8a-ad6e-48110a20e5bd_688x189.png 424w, https://substackcdn.com/image/fetch/$s_!gNWo!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefec7865-ef5e-4a8a-ad6e-48110a20e5bd_688x189.png 848w, https://substackcdn.com/image/fetch/$s_!gNWo!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefec7865-ef5e-4a8a-ad6e-48110a20e5bd_688x189.png 1272w, https://substackcdn.com/image/fetch/$s_!gNWo!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefec7865-ef5e-4a8a-ad6e-48110a20e5bd_688x189.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!gNWo!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefec7865-ef5e-4a8a-ad6e-48110a20e5bd_688x189.png" width="520" height="142.84883720930233" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/efec7865-ef5e-4a8a-ad6e-48110a20e5bd_688x189.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:189,&quot;width&quot;:688,&quot;resizeWidth&quot;:520,&quot;bytes&quot;:17256,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://plainspeakcyber.substack.com/i/189424915?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefec7865-ef5e-4a8a-ad6e-48110a20e5bd_688x189.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!gNWo!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefec7865-ef5e-4a8a-ad6e-48110a20e5bd_688x189.png 424w, https://substackcdn.com/image/fetch/$s_!gNWo!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefec7865-ef5e-4a8a-ad6e-48110a20e5bd_688x189.png 848w, https://substackcdn.com/image/fetch/$s_!gNWo!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefec7865-ef5e-4a8a-ad6e-48110a20e5bd_688x189.png 1272w, https://substackcdn.com/image/fetch/$s_!gNWo!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fefec7865-ef5e-4a8a-ad6e-48110a20e5bd_688x189.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p><strong>Microsoft Edge</strong>: Copy and paste the following into Edge <em>edge://settings/autofill/passwords/settings</em> and toggle off the pictured setting: </p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!gNWx!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ee79b1b-0479-4daa-a943-3198ed712b34_834x285.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!gNWx!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ee79b1b-0479-4daa-a943-3198ed712b34_834x285.png 424w, https://substackcdn.com/image/fetch/$s_!gNWx!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ee79b1b-0479-4daa-a943-3198ed712b34_834x285.png 848w, https://substackcdn.com/image/fetch/$s_!gNWx!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ee79b1b-0479-4daa-a943-3198ed712b34_834x285.png 1272w, https://substackcdn.com/image/fetch/$s_!gNWx!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ee79b1b-0479-4daa-a943-3198ed712b34_834x285.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!gNWx!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ee79b1b-0479-4daa-a943-3198ed712b34_834x285.png" width="507" height="173.25539568345323" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2ee79b1b-0479-4daa-a943-3198ed712b34_834x285.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:285,&quot;width&quot;:834,&quot;resizeWidth&quot;:507,&quot;bytes&quot;:32599,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://plainspeakcyber.substack.com/i/189424915?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ee79b1b-0479-4daa-a943-3198ed712b34_834x285.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!gNWx!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ee79b1b-0479-4daa-a943-3198ed712b34_834x285.png 424w, https://substackcdn.com/image/fetch/$s_!gNWx!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ee79b1b-0479-4daa-a943-3198ed712b34_834x285.png 848w, https://substackcdn.com/image/fetch/$s_!gNWx!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ee79b1b-0479-4daa-a943-3198ed712b34_834x285.png 1272w, https://substackcdn.com/image/fetch/$s_!gNWx!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ee79b1b-0479-4daa-a943-3198ed712b34_834x285.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p><strong>Firefox</strong>: Copy and paste the following into Firefox <em>about:preferences#privacy</em> and toggle off the pictured settings (scroll down some): </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!8TFZ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcac98fc7-87c1-43e6-8120-9ded55d227cf_671x440.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!8TFZ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcac98fc7-87c1-43e6-8120-9ded55d227cf_671x440.png 424w, https://substackcdn.com/image/fetch/$s_!8TFZ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcac98fc7-87c1-43e6-8120-9ded55d227cf_671x440.png 848w, https://substackcdn.com/image/fetch/$s_!8TFZ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcac98fc7-87c1-43e6-8120-9ded55d227cf_671x440.png 1272w, https://substackcdn.com/image/fetch/$s_!8TFZ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcac98fc7-87c1-43e6-8120-9ded55d227cf_671x440.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!8TFZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcac98fc7-87c1-43e6-8120-9ded55d227cf_671x440.png" width="497" height="325.9016393442623" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/cac98fc7-87c1-43e6-8120-9ded55d227cf_671x440.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:440,&quot;width&quot;:671,&quot;resizeWidth&quot;:497,&quot;bytes&quot;:43136,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://plainspeakcyber.substack.com/i/189424915?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcac98fc7-87c1-43e6-8120-9ded55d227cf_671x440.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!8TFZ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcac98fc7-87c1-43e6-8120-9ded55d227cf_671x440.png 424w, https://substackcdn.com/image/fetch/$s_!8TFZ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcac98fc7-87c1-43e6-8120-9ded55d227cf_671x440.png 848w, https://substackcdn.com/image/fetch/$s_!8TFZ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcac98fc7-87c1-43e6-8120-9ded55d227cf_671x440.png 1272w, https://substackcdn.com/image/fetch/$s_!8TFZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcac98fc7-87c1-43e6-8120-9ded55d227cf_671x440.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>Android Phone</strong>: Open Settings and search <em>password</em>. <em>Select Passwords, passkeys &amp; accounts</em>. Then edit the <em>Preferred Service</em> from Google to the app we installed. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!QUf2!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95e044e8-76b3-4588-8221-26dc9353d6cf_499x1120.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!QUf2!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95e044e8-76b3-4588-8221-26dc9353d6cf_499x1120.png 424w, https://substackcdn.com/image/fetch/$s_!QUf2!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95e044e8-76b3-4588-8221-26dc9353d6cf_499x1120.png 848w, https://substackcdn.com/image/fetch/$s_!QUf2!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95e044e8-76b3-4588-8221-26dc9353d6cf_499x1120.png 1272w, https://substackcdn.com/image/fetch/$s_!QUf2!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95e044e8-76b3-4588-8221-26dc9353d6cf_499x1120.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!QUf2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95e044e8-76b3-4588-8221-26dc9353d6cf_499x1120.png" width="249" height="558.8777555110221" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/95e044e8-76b3-4588-8221-26dc9353d6cf_499x1120.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1120,&quot;width&quot;:499,&quot;resizeWidth&quot;:249,&quot;bytes&quot;:105313,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://plainspeakcyber.substack.com/i/189424915?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95e044e8-76b3-4588-8221-26dc9353d6cf_499x1120.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!QUf2!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95e044e8-76b3-4588-8221-26dc9353d6cf_499x1120.png 424w, https://substackcdn.com/image/fetch/$s_!QUf2!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95e044e8-76b3-4588-8221-26dc9353d6cf_499x1120.png 848w, https://substackcdn.com/image/fetch/$s_!QUf2!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95e044e8-76b3-4588-8221-26dc9353d6cf_499x1120.png 1272w, https://substackcdn.com/image/fetch/$s_!QUf2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95e044e8-76b3-4588-8221-26dc9353d6cf_499x1120.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>*Note - due to the number of different versions of Android phones this may vary slightly. The shown screenshot is from a Google Pixel phone. </p><p></p><p><strong>Apple Devices</strong>: <a href="https://nordpass.com/blog/how-to-disable-safari-password-manager/">This blog post</a> covers the steps well. I&#8217;m working on getting better Apple guides directly in this post - please message me if this would be valuable for you. </p><h3>Bonus Step - Set up Multi-Factor Authentication<br></h3><h5>What is MFA? </h5><p>The practice of logging in with a password followed by a second step, such as typing in a code from an App like Google Authenticator. If our password is ever compromised this adds an additional verification, requiring our physical phone, making it exponentially harder for a criminal to access our data.</p><div><hr></div><p><em>It&#8217;s a common trick of a criminal to ask for an MFA code. Never share this code with anyone and only type it directly into the service. Additionally, avoid using Text Messaging as MFA when possible.</em></p><div><hr></div><h5>What Are Some Services to Consider? </h5><p>Most often this service will be used from a mobile phone.</p><p>Google Authenticator can be used on <a href="https://play.google.com/store/apps/details?id=com.google.android.apps.authenticator2&amp;hl=en_US">Android</a> and <a href="https://apps.apple.com/us/app/google-authenticator/id388497605">Apple</a> devices.</p><p>Microsoft Authenticator is another good option for <a href="https://play.google.com/store/apps/details?id=com.azure.authenticator&amp;hl=en_US">Android</a> and <a href="https://apps.apple.com/us/app/microsoft-authenticator/id983156458">Apple</a>. </p><p>For those aligned to Apple, there&#8217;s also <a href="https://apps.apple.com/us/app/authenticator-app/id1538761576">Apple&#8217;s Authenticator</a>.</p><h5>How to set up MFA</h5><p>When on the paid password manager plans they can also be used as an authenticator, just not to access the password manager itself. A common set up would be to have an Authenticator app just to use for access to the Password Manager, then save MFA codes for sites in the password manager. </p><p>For now, let&#8217;s just focus on setting up MFA to the password manager. </p><p>Most offerings have helpful guides of how to do this. Here&#8217;s the links for <a href="https://bitwarden.com/blog/basics-of-two-factor-authentication-with-bitwarden/">Bitwarden</a> and <a href="https://support.1password.com/two-factor-authentication/?windows">1Password</a>. </p><p>Essentially, we need to download an authenticator app, navigate to the proper setting in the password manager to setup MFA, scan the QR code, and enter the code from our phone. </p><p>From now on we will need to enter a password <em>and</em> MFA code to sign in, which is a small trade of convenience for a major security upgrade.</p><p></p><p>Congratulations! Accomplishing this is a major improvement in our online security. Let&#8217;s be sure each password is unique and that our one password to remember is stored in a safe location.</p><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://plainspeakcyber.tech/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Subscribe to receive cyber guidance and alerts in plain speak.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p>]]></content:encoded></item><item><title><![CDATA[Tracking Who Sells Our Email Address]]></title><description><![CDATA[Or who loses them in a data breach]]></description><link>https://plainspeakcyber.tech/p/tracking-who-sells-our-email-address</link><guid isPermaLink="false">https://plainspeakcyber.tech/p/tracking-who-sells-our-email-address</guid><dc:creator><![CDATA[Plain Speak Cyber]]></dc:creator><pubDate>Sat, 28 Feb 2026 02:28:30 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!lNh6!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F53db8219-3006-4240-b219-05279d924d08_1024x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h4>What Happens</h4><p>When we sign up for online services, be it a shopping account or a newsletter, often our email address is a required piece of information.</p><p>When we provide this we expect to receive email communications solely regarding the service we gave that email to, but often we get spam from companies we have never heard of. </p><p>This typically happens for one of two reasons:</p><p>1) There was a data breach and our email addresses were stolen </p><p>2) Our email addresses were sold for profit </p><p></p><h4>How To Track It</h4><p>Being aware of what website lost (or sold) our email can inform us of a possible data breach or have a better understanding of how trustworthy that service is. </p><p>We can do this using <em>plus addressing</em>, which is supported by most major email providers including Gmail, Outlook, and Yahoo. </p><h6></h6><p>When we give our email to a site, say this newsletter, most folks give their email verbatim, such as <em>name@gmail.com</em>. </p><p>If we wanted to track Plain Speak Cyber we would sign up with <em>name+PSC@gmail.com</em>. </p><p>Anything from the &#8216;+&#8217; sign until the &#8216;@&#8217; symbol will be ignored when delivering email. It&#8217;s like it doesn&#8217;t even exist except we will see it in the TO field. </p><p>If we see <em>name+PSC@gmail.com</em> delivered to our inbox from anywhere other than this newsletter then we have reason to believe that this service somehow transferred your email to another party. </p><p></p><h4>There&#8217;s One Catch</h4><p>Oftentimes our email address is the username for the service, meaning we can&#8217;t forget it. This is where using a password manager is key as we do not want to try to remember all of these variations. If we lose the exact email provided it&#8217;s possible that account recovery options may not work.</p><p></p><h4>PSC&#8217;s Promise</h4><p>I&#8217;ll never sell your email to another party. Want to keep me honest? Use this technique and let me know if you ever receive an unexpected email.</p><p> </p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://plainspeakcyber.tech/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Subscribe to receive cyber guidance and alerts in plain speak.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Phish Alert: Tricky Website Domains]]></title><description><![CDATA[Use of Japanese character '&#12435;' in malicious links]]></description><link>https://plainspeakcyber.tech/p/phish-alert-tricky-website-domains</link><guid isPermaLink="false">https://plainspeakcyber.tech/p/phish-alert-tricky-website-domains</guid><dc:creator><![CDATA[Plain Speak Cyber]]></dc:creator><pubDate>Fri, 27 Feb 2026 03:31:44 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!E2rp!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f0c7090-ec88-44a8-8929-3767ba2a7ee3_1536x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>This is a sneaky one to look out for. </p><p>Attackers are using a Japanese character, &#12435;, to trick people into thinking they are on a legitimate website. </p><p>It is trivial to copy the look and feel of a website, so verifying the website in the address bar, known as the URL, is a key precaution. </p><div><hr></div><p>TIP: Hover over links without clicking to preview the URL</p><div><hr></div><p>Take a look at the below webpage, at a quick glance most would believe this to be Booking.com&#8217;s webpage</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!LqNi!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8bd74395-5aa0-406a-866a-10535dab4b75_733x181.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!LqNi!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8bd74395-5aa0-406a-866a-10535dab4b75_733x181.png 424w, https://substackcdn.com/image/fetch/$s_!LqNi!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8bd74395-5aa0-406a-866a-10535dab4b75_733x181.png 848w, https://substackcdn.com/image/fetch/$s_!LqNi!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8bd74395-5aa0-406a-866a-10535dab4b75_733x181.png 1272w, https://substackcdn.com/image/fetch/$s_!LqNi!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8bd74395-5aa0-406a-866a-10535dab4b75_733x181.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!LqNi!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8bd74395-5aa0-406a-866a-10535dab4b75_733x181.png" width="733" height="181" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8bd74395-5aa0-406a-866a-10535dab4b75_733x181.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:181,&quot;width&quot;:733,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:53983,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://aaronmatassa.substack.com/i/189321692?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8bd74395-5aa0-406a-866a-10535dab4b75_733x181.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!LqNi!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8bd74395-5aa0-406a-866a-10535dab4b75_733x181.png 424w, https://substackcdn.com/image/fetch/$s_!LqNi!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8bd74395-5aa0-406a-866a-10535dab4b75_733x181.png 848w, https://substackcdn.com/image/fetch/$s_!LqNi!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8bd74395-5aa0-406a-866a-10535dab4b75_733x181.png 1272w, https://substackcdn.com/image/fetch/$s_!LqNi!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8bd74395-5aa0-406a-866a-10535dab4b75_733x181.png 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div><p>So what&#8217;s the problem? First let&#8217;s break down how a URL works. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!E2rp!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f0c7090-ec88-44a8-8929-3767ba2a7ee3_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!E2rp!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f0c7090-ec88-44a8-8929-3767ba2a7ee3_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!E2rp!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f0c7090-ec88-44a8-8929-3767ba2a7ee3_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!E2rp!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f0c7090-ec88-44a8-8929-3767ba2a7ee3_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!E2rp!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f0c7090-ec88-44a8-8929-3767ba2a7ee3_1536x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!E2rp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f0c7090-ec88-44a8-8929-3767ba2a7ee3_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2f0c7090-ec88-44a8-8929-3767ba2a7ee3_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2090507,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://aaronmatassa.substack.com/i/189321692?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f0c7090-ec88-44a8-8929-3767ba2a7ee3_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!E2rp!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f0c7090-ec88-44a8-8929-3767ba2a7ee3_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!E2rp!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f0c7090-ec88-44a8-8929-3767ba2a7ee3_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!E2rp!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f0c7090-ec88-44a8-8929-3767ba2a7ee3_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!E2rp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f0c7090-ec88-44a8-8929-3767ba2a7ee3_1536x1024.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>When validating what website we are on we want to look at the <em>Domain</em> section. Anything before this is a subsection of the main website. Anything after it is often perceived as noise that we ignore. </p><p>Let&#8217;s look at our &#8220;Booking.com&#8221; example again</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!IPl7!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F29274588-f0c0-4f5e-a4e9-a7a00f671989_733x181.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!IPl7!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F29274588-f0c0-4f5e-a4e9-a7a00f671989_733x181.png 424w, https://substackcdn.com/image/fetch/$s_!IPl7!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F29274588-f0c0-4f5e-a4e9-a7a00f671989_733x181.png 848w, https://substackcdn.com/image/fetch/$s_!IPl7!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F29274588-f0c0-4f5e-a4e9-a7a00f671989_733x181.png 1272w, https://substackcdn.com/image/fetch/$s_!IPl7!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F29274588-f0c0-4f5e-a4e9-a7a00f671989_733x181.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!IPl7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F29274588-f0c0-4f5e-a4e9-a7a00f671989_733x181.png" width="733" height="181" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/29274588-f0c0-4f5e-a4e9-a7a00f671989_733x181.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:181,&quot;width&quot;:733,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:54729,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://aaronmatassa.substack.com/i/189321692?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F29274588-f0c0-4f5e-a4e9-a7a00f671989_733x181.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!IPl7!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F29274588-f0c0-4f5e-a4e9-a7a00f671989_733x181.png 424w, https://substackcdn.com/image/fetch/$s_!IPl7!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F29274588-f0c0-4f5e-a4e9-a7a00f671989_733x181.png 848w, https://substackcdn.com/image/fetch/$s_!IPl7!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F29274588-f0c0-4f5e-a4e9-a7a00f671989_733x181.png 1272w, https://substackcdn.com/image/fetch/$s_!IPl7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F29274588-f0c0-4f5e-a4e9-a7a00f671989_733x181.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>We can see that the actual <em>domain</em> is &#8220;www-account-booking.com&#8221; and &#8220;account.booking.com&#12435;detail&#12435;restric-access&#8221; is the <em>subdomain</em>, but the Japanese character makes us thing anything after &#8220;booking.com&#12435;&#8221; is just <em>path &amp; page</em> noise. </p><p></p><p>While web browsers, like Safari and Google Chrome, eventually block these malicious domains it&#8217;s an ongoing game of cat and mouse and there are always people who fall for newly minted scams. </p><p></p><p>We can protect ourselves by taking time to inspect the URL when our gut gives us pause and by using a Password Manager which will automatically identify the real domain. </p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://plainspeakcyber.tech/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Subscribe to receive cyber guidance and alerts in plain speak.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><p><em>Original story and example image from <a href="https://www.bleepingcomputer.com/news/security/bookingcom-phishing-campaign-uses-sneaky-character-to-trick-you/">Bleeping Computer</a></em></p>]]></content:encoded></item></channel></rss>