after visiting the forum I received a scam email

After visiting the forum I received a scam email, phishing for my credit card details. It can only have come through the apple website or the forum. Troubling.

MacBook Pro, OS X Mavericks (10.9.2)

Posted on Feb 12, 2015 1:29 PM

Reply
14 replies

Feb 12, 2015 1:38 PM in response to McDonald Brown

There is no evidence of phishing email being derived from participant information here.


Excepting for those instances where persons actually would post their address & email

in the open ASC discussions. And the Community Hosts remove personal information.


Over the course of some 12 years, I've never received any phishing or other email that

would have been considered such, from participation in these ASC discussion forums.


Check elsewhere to be certain that none of your other activities online are responsible.


Good luck & happy computing! 🙂

Feb 12, 2015 1:47 PM in response to K Shaffer

The phishing email looks like a Apple document and says I bought a game today when I was on the Applestore website (I don't do computer games) . It says I'm being charged a little over £20 but if I didn't make the purchase, please enter my credit card details for verification. Should I believe it's a coincidence that I visited the store site today, was referred to the forum, and then got the scam email? These events seem connected.

Feb 12, 2015 2:47 PM in response to McDonald Brown

I suggest installing the Ghostery Safari extension to help prevent tracking. That way, it will block the Omniture (Adobe Analytics) tracker that Apple Support Communities uses. Nothing is perfect though. Make sure to go into Ghostery's settings and tell it to block everything. The default settings are pretty pathetic. And keep an eye out for news and similar tools. It is always possible that Ghostery could sell out for cash like others have done.

Feb 12, 2015 6:09 PM in response to etresoft

Howdy mi amigo...


As I always follow your sage advice, Ghostery installed and running. Forgive me trying to read too much into this, but are you suggesting that Adobe Analytics should be considered suspect in the OP's phishing attempt?


buenos noches

ÇÇÇ


EDITadded

BTW, the link's page you provided reads one's UserAgent and displays the correct add-on for one's browser - Firefox in my case, likely Chrome too, others?

Feb 13, 2015 4:31 AM in response to ChitlinsCC

ChitlinsCC wrote:


are you suggesting that Adobe Analytics should be considered suspect in the OP's phishing attempt?

Not specifically. I am saying the internet should be considered suspect. Do any of us really know what goes on in our browser? Including after Javascript has been loaded and additional dynamic content installed into the DOM? You can't just look at the web inspector you know. You would have to track each message and deconstruct it all. Even when all is said and done, your web sites could be selling your information on the back end, from their own servers.


I am just saying that Ghostery reports an Omniture (Adobe Analytics) web bug and claims to have blocked it. I have to take their word for it too. My own inspection of the site seems to suggest that the Omniture web bug may be left over boilerplate code. But I don't really know because it would be quite difficult to track that down. And what good would it do? Can I do that with every site I visit? Apple is probably the least likely to share my information with 3rd parties. All I can do is try my best without wasting too much time on it. It is a no-win situation. But at the very least I have a responsibility to inject noise into the system and do what I can to increase costs and decrease value for advertisers and scammers.

Feb 13, 2015 10:02 AM in response to etresoft

I didn't think so... but opened a door and I walked in. 👿 I don't doubt that Apple is not selling our info - but the fact that the data exists leaves it vulnerable to possible theft. Hackers have proven repeatedly that they are capable of penetrating what we think should be impenetrable Bastions.


In the mean time, it occurred to me that Apple employment of the tracking "beacon" (? - is that right?) might be related to the JiveWare's ability to tell if we a have merely visited threads (ala tt2's forum params " /content?filterID=contentstatus[published]~objecttype~objecttype[thread] " ) that gives me my magenta-ish visual cues??

User uploaded file


You make excellent points, amigo - in particular "What good what it do?"


You and thomas_r do a great and thankless job. Let me take this opportunity to THANK YOU So Very Much!


Ya'll DO make a difference by continually increasing the pesky critters costs and decreasing their ill-gained profits.


Now, if we could only get Apple/Jive to fix broken "All Activity" page and recent failure of some email notifications nearly All would be right with the world.

buenos tardes

ÇÇÇ

Feb 13, 2015 10:21 AM in response to ChitlinsCC

No, that's different. When you login to ASC, the database automatically tracks all of your actions. That's how it works. It doesn't need beacons for that. Those are to forward your activity to a 3rd party, usually in exchange for a fee, so it can be aggregated into any of a number of "Big Data" stores of such information. Google Analytics works this way and it is marketed to web site owners as a way to have Google track and visualize traffic to your web site. It certainly does that, but not just for the website owner.


I'm not certain Apple actually does send any information to any 3rd party services like this. For one thing, Apple wouldn't really need a beacon like this. They already track everything just to run the site. They could ship that data off in bulk far easier than installing a web bug. I actually think it is just a bug in the site and no data is being sent to Omniture or Adobe. But I can't really be certain about that. Plus, people who specialize in such things tell me that Apple is doing that. Who do I trust? My own intuition and experience with Apple? Or an automated tool that just scans Javascript? I have little confidence in any of the above.

Feb 13, 2015 12:45 PM in response to etresoft

"😉😉 say no more" - Monty Python

I was confident that ASC database (JiveWare) had all the abilities you state (and more as evidenced by the unaltered Jive Community). It is a good thing to have this discussion in open forum for higher educational purposes, methinks.


Regarding the balance of your post, I (and most all of us that are of sound mind) knew that these facts were true intuitively. It is great that you and those that dig into "how the sausage is made" are here to tell us the details.


As far as I know there is only one way to be totally safe... go UnaBomber = back to the stone age (tin can telephone?)

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

after visiting the forum I received a scam email

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.