nrw.social ist einer von vielen unabhängigen Mastodon-Servern, mit dem du dich im Fediverse beteiligen kannst.
Wir sind eine freundliche Mastodon Instanz aus Nordrhein-Westfalen. Ob NRW'ler oder NRW-Sympathifanten, jeder ist hier willkommen.

Serverstatistik:

2,8 Tsd.
aktive Profile

#gmail

9 Beiträge9 Beteiligte0 Beiträge heute

If you use #Gmail, you need to know about this #phishing attack, as described by Malwarebytes Labs: "Cybercriminals are abusing Google’s infrastructure, creating emails that appear to come from Google ... to persuade people into handing over their Google #account #credentials." tinyurl.com/47y6pvus

Malwarebytes · All Gmail users at risk from clever replay attackAll Google accounts could end up compromised by a clever replay attack on Gmail users abusing Google infrastructure.

#CancelGmail ❌ 📨❌
Meine Emailsignatur (also das was unter jeder meiner Emails steht) sagt jetzt, dass ich nicht mehr mit #Gmail Emailaccounts schreiben werde. Sie empfiehlt Leuten die Gmailadressen verwenden andere Email-Provider und sagt, dass ich auf diesem Weg nicht weiter mit ihnen kommunizieren werde.

Es fühlte sich schon spätestens seit den #Snowden-enthüllungen mulmig an, ungewollt meine Mails durch #Google durchschnüffeln zu lassen. Seit dem Wahnsinn, der gerade in den #USA passiert und dem kriecherischen Verhalten Googles gegenüber #Trump ist es ein #NoGo für mich geworden all meine Emailkonversationen durch diese Industrie ohne meine Zustimmung auswerten zu lassen.

Sucht euch andere Provider, Leute. Basisaccounts gibt es bei vielen besseren Providern gratis. #CancelGmail

#Posteo #Tutanota #Email #Infosec #Privatsphäre
#Datenkrake #USFaschisten #Trump

#Google is super efficient when it comes to locking innocent users out of their Google accounts, causing them to lose all their email, photos, and other data. They won't even listen to cost effective suggestions for fixing this. They just don't care about those users. But when it comes to stopping OBVIOUS dangerous phishes being sent out from #Gmail, they play helpless and flood the Internet with them. Disgusting.

GOOGLE! Do something about the endless scourge of fake #PayPal invoices pouring out of #Gmail (confirmed as coming from #Google, not spoofed). You don't even mark all of these as phishes to other Gmail subscribers, and you FLOOD non-Gmail platforms with them.

THESE ARE YOUR RESPONSIBILITY.

They should be easy for your super-duper-AI to detect. Here's a signal for you: The fake invoices virtually always include fake phone numbers for PayPal. That's the whole point, the scammers don't want email back, they want victims to call so they can scam them for payment information over the phone.

I've seen about six of these today in just a few hours. It's getting worse every day. Get off your asses and FIX THIS! Your inaction is putting vast numbers of people at risk.

I'm utterly fed up with the vast quantity of dangerous phishing emails that are sent from #Gmail (yes, verified as coming from #Google servers, not spoofed). While Google is pretty good at detecting INCOMING spams and phishing attempts for Gmail, Google still appears to permit OUTGOING phishes (that is, to non-Gmail servers) to utterly flourish.

The majority of these I see every day now come from Gmail. And the "payload" for many of these are GCP (Google Cloud Platform) servers. Fake PayPal phishes (that even bypass DKIM checks) are particularly numerous, but many don't even try to forge the From:, they just use their Gmail addresses, hoping to entrap as many users as possible.

Does Google care about this? Apparently not, probably because these are largely the same class of non-techie users Google routinely shows disdain for (e.g., in account lockout situations).

Do I need to write another formal blog post on this?

L

Fortgeführter Thread

The #GoogleDrive incident is the latest digital #security lapse for the #Trump admin. Last month, top officials inadvertently included the editor in chief of the Atlantic magazine in an unclassified chat used to discuss highly sensitive #military planning, & Trump’s #NationalSecurity adviser & his staff used personal #Gmail accounts for government communications, which experts described as insufficiently secure, The Post reported.

I have like 5 accounts that I can’t use my personal e-mail for so I’m looking to find a GMail alternative for them to continue my journey to be 100% off Google products.

Does any email provider (paid or free) offer the same level of deliverability, uptime, and have something similar to Google’s Advanced Protection Program (landing.google.com/intl/en_us/)?

Advanced ProtectionGoogle Advanced Protection ProgramThe strongest account security made to protect the personal data and information of people most at risk of phishing, hacking and targeted digital attacks.

*****Beware of Google's latest passkeys push! *****

#Google, which itself in my experience is a massive source of spam and phishing attempts sent from #Gmail to non-Gmail mail platforms, is using scare attempts again to try trick users into using their flawed passkeys system instead of passwords, without these users necessarily understanding the full implications.

While the phishing attack model described in the link below is real and the result of what is essentially a flaw in Google's handling of DKIM-"protected" email checking systems (I see phishing attacks daily from Gmail users that have passed DKIM checks), I will repeat my concern that passkey implementations routinely result in many users who are not sophisticated techies getting locked out of their Google (or other) accounts, especially if they access the Internet via a single device.

I routinely hear from such users, and Google typically tells them to pound sand -- that is, tough luck -- you're screwed.

The march by firms to push users into giving up passwords is theoretically a laudable one -- for many years I have noted the need to move beyond the password model. Unfortunately, the rushed and poorly thought out passkey systems now being pushed on users by various firms continue to result in many users being locked out and left behind to rot without access to their email or other data.

The proponents of passkeys will argue that the risk of getting locked out of your account is acceptable when viewed against the damage that can be done by the various types of sophisticated phishing attacks -- that are indeed real and are increasingly difficult to detect by many users.

However, given the absence of humane account recovery policies on the part of Google and some other firms, the risk to many users of TOTAL lockout is so severe that their using passkeys becomes a much more problematic scenario.

I have continued to recommend to Google specific approaches to improve their account recovery and passkeys systems to avoid harm to many innocent users, but continue to hit a brick wall of apparent disinterest on their part.

Of course it is your decision whether or not to use passkeys, and to weigh their advantages and disadvantages. Personally, I am not willingly using any existing passkey implementations, especially Google's, and if firms begin to force their use, they will do even more damage to many innocent users whom they in many cases already treat so very badly when account access problems occur.

L

forbes.com/sites/zakdoffman/20

Voici les résultats d'un sondage comptabilisant le vote 292 membres du groupe Facebook qui ont partagé leurs préférences pour les #alternativeEU à #google #Gmail

Voici les résultats en pourcentage :

1. ProtonMail : 25.68%
2. Mailo : 25.34%
3. Infomaniak: 18.49%
4. Autres : 13.01%
5. Orange: 9.25%
6. Laposte: 8.22%

N'hésitez pas à partager vos réactions en commentaires et à proposer VOS #alternativeEU #alternativeFR

En espérant que cela puisse aussi vous aider dans vos choix de #BoycottUSA