
The spirit of giving has hit Google. They are generously providing free Wi-Fi at 47 airports from November 10, 2009 to January 15, 2010. That's great, but there are a few precautions you should take to keep yourself safe.
Using the free service is simple. You simply select the free Wi-Fi and accept the terms of service and there's no need to give any form of payment. However, Google wants you to catch the giving spirit and give a donation to any of the three non-profit organizations [2] they've partnered with. But, donate [2]once you're using a secure Internet connection at home - not on the Wi-Fi network. In addition to providing free Wi-Fi, Google's having a photo contest. You could win a prize just for submitting a photo [3] of you using the free Wi-Fi.
You can take advantage of Google's generosity at one of the following 47 airports:
| Austin (AUS [5]) | Indianapolis (IND [6]) | Panama City, FL (PFN [7]) |
|
Baltimore (BWI [8]) |
Jacksonville, FL (JAX [9]) | Pittsburgh, PA (PIT [10]) |
| Billings (BIL [11]) | Kalamazoo (AZO [12]) | Portland, ME (PWM [13]) |
| Boston (BOS [14]) | Las Vegas (LAS [15]) | Sacramento (SMF [16]) |
| Bozeman (BZN [17]) | Louisville (SDF [18]) | San Antonio (SAT [19]) |
| Buffalo, NY (BUF [20]) | Madison (MSN [21]) | San Diego (SAN [22]) |
| Burbank (BUR [23]) | Memphis (MEM [24]) | San Jose (SJC [25]) |
|
Central Wisconsin (CWA [26]) |
Miami (MIA [27]) | Seattle (SEA [28])* |
| Charlotte, NC (CLT [29]) | Milwaukee (MKE [30]) | South Bend (SBN [31]) |
| Des Moines (DSM [32]) | Monterey (MRY [33]) | Spokane (GEG [34]) |
| El Paso (ELP [35]) | Nashville (BNA [36]) | St. Louis (STL [37]) |
| Fort Lauderdale (FLL [38]) | Newport News (PHF [39]) | State College (SCE [40]) |
| Fort Myers (RSW [41]) | Norfolk (ORF [42]) | Toledo (TOL [43]) |
| Greensboro (GSO [44]) | Oklahoma City (OKC [45]) | Travers City (TVC [46]) |
| Houston Hobby (HOU [47]) | Omaha (OMA [48]) | West Palm Beach (PBI [49]) |
| Houston Bush (IAH [50]) | Orlando (MCO [51]) |
*Seattle launches late November
Airport Wi-Fi - like other public hotspots - is not secure and you should avoid logging into your bank account or other sites with sensitive info. Wireless network security can be compromised and put your passwords and other data out in the air and available to a fellow traveler with the right hacking tools.
We don't mean to scare you out of using the Google's Wi-Fi gift but to educate you about the potential risks
Here are some tips on how to protect yourself when using any Wi-Fi connection:
This video from Forbes provides more details on what you should watch out for:
Check out Google's Free Wi-Fi for the Holidays [52] site and their FAQ page [53] for more details.

Microsoft launched an update Tuesday to patch about fifteen holes in Windows 2000, Windows XP, Windows Server and Office. While most of the patches are related to various Word and Excel, or Windows Server issues, a critical vulnerability was found within the Windows OS kernel - a fairly rare occurrence.
The Windows kernel is the core of the operating system and the flaw is related to how embedded font files are processed. We're not going to get into the technical mumbo-jumbo here, so we'll just tell you that the problem - if exploited - would allow malicious code to be passed directly to the system, bypassing any browser defenses that have been created to stop this sort of attack. The code could be downloaded just by visiting a web page prepared by hackers. With the increase of URL shorteners being used [56] as well as advertising attacks [57], it's easier than ever to be accidently exposed to some nasty code.
Microsoft rated the kernel flaw as critical and gave it an exploitability ranking of 1. This means that Microsoft expects there to be a working exploit within 30 days and is similar to "SEVERE - Severe risk of terrorist attacks" on the Homeland Security advisory system (if anyone is actually paying any attention to that any more).
Researchers agree that the bad guys are going to move quickly:
"An exploit will appear sooner rather than later," said Jason Miller, the security and data team manager for patch management vendor Shavlik Technologies. "The target is Internet Explorer, and browsing is the number one attack vector in the world right now. Users can be infected simply by browsing on a [malicious] site.
So this is a big hole that can do some nasty things on unpatched computers.
Take the following steps to protect your computer:
To set your PC to update automatically in Windows XP, simply access the Control Panel in the start menu, click "Automatic Updates," and choose "Automatic." 
For Vista, open Windows Update in the start menu, select "Change Settings," and then select "Install updates automatically." 
More information can be found at Computer World [59] and The Washington Post's Security Fix blog [60].

We've been educating you about phishing emails [63] for years and in trolling around your inbox, it’s not uncommon to come across one of those pesky emails just about every day. The easiest approach is to ignore it or mark it as spam and go on with your day. However, by taking just a minute or two to report it, you can help make the Internet a safer place for you and the rest of the world.
OpenDNS, the world’s largest, fastest-growing DNS service provider, launched PhishTank [64] in an effort to make the Internet a better place for all us.
Phishtank serves as a clearing house for data and information about phishing on the Internet and provides the information to developers and researchers to integrate anti-phishing data into their applications. Best of all, the Phishtank services are free!
Here are some statistics from October, 2009 to give you an idea of what kind of impact PhishTank has on scam emails:

Exercising a little philanthropy has never been easier:
As a side note, OpenDNS offers other services through innovative uses of the DNS. Some of these include free parental controls (porn filtering), phishing protection, and other advanced services for consumers and network administrators alike. Check out their free and deluxe plans here: http://www.opendns.com/start [67].

Medicare receives 4.4 million claims a day and approximately 1 out of 10 of those are fraudulent. All of the fraudulent claims add up to a large sum of wasted time and money and the government is trying to put a stop to it. The Department of Justice (DOJ) and the Health and Human Services (HHS) Office of the Inspector General have been working together to reduce fraudulent activity.
In 2008, the DOJ and HHS and the Centers for Medicare and Medicaid Services worked together through the criminal and civil systems to secure 588 criminal convictions, obtain 337 civil administrative actions against individuals and organizations who were committing Medicare Fraud, and recovered more than a billion dollars in health care fraud monies . . . To date in fiscal year 2009, the Department of Justice has already recovered nearly a billion dollars in health care fraud monies and recorded 300 convictions.
In addition to catching Medicare thieves the DOJ and HHS want to enable seniors to participate in the fight. They want to raise awareness about the kinds of fraud that are happening and give seniors the tools they need to deter, detect and defend!
Here are a few examples of how Medicare is scammed out of billions of dollars a year.
Medicare recipients need to keep themselves safe.
Learn to recognize common schemes. A few common fraud schemes are:
It's critical that Medicare recipients check their statement summary sheets and look for:
If you see any of these problems make a phone call to your provider or Medicare to get it resolved. It could just be a clerical error or it could be a fraudulent act that needs to be reported.
To some the task above may seem very overwhelming. The DOJ and HHS understand that seniors want to protect themselves but may not have the knowledge to do so. For this reason Senior Medicare Patrols (SMP's) were created. SMP's are groups or seniors, formed in communities, that help other senior citizens learn how to combat Medicare Fraud. They bring awareness to seniors in the community, teach seniors how to read and understand their Medicare summary statements and offer support.
Medical identity theft and Medicare fraud are a huge problem that the government cannot tackle on its own. While they do their part it's important for senior citizens to do their part to protect themselves from medical identity theft and be on the watch for Medicare fraud.
More detailed information is available in the Fight Back! Medical Identity Theft and Medicare Fraud brochure [71] put out by the HHS.
More information is available at Stop Medicare Fraud's website [72].
Facebook won a huge judgment from the spammer who already owes MySpace $234 million from an earlier suit.
Sanford Wallace [75] has been a known spammer since the 1990's and is one of the first to be crowned "Spam King". His most recent spamming scheme was sending phishing messages to Facebook users that contained links to phishing websites asking for login information. The information submitted was used by Wallace to spam the phishing victims' friends with the aim to pull in even more potential phishing victims. It's also believed that Wallace was paid to redirect Facebook users to money generating web sites.
"The record demonstrates that Wallace willfully violated the statutes in question with blatant disregard for the rights of Facebook and the thousands of Facebook users whose accounts were compromised by his conduct," Fogel said in his ruling.
Facebook sought $7 billion in damages, as allowed by the CAN-SPAM act and California business code. However, California federal judge Jeremy Fogel felt that was disproportionate to the actual damage caused by Wallace and awarded Facebook only $710,737,650 instead. Judge Fogel also turned Wallace over to the U.S. Attorney's Office to be prosecuted for criminal contempt and for willful violation of a temporary restraining order and injunction.
With Wallace possibly facing jail time and owing MySpace $234, it won't be easy for Facebook to collect its money. But at least the "Spam King" as been caught and may be taken off the grid for a time.
More information on Information Week [76]. Photo courtesy of Canadian Broadcasting Centre.
26% of Twitter messages contain links, half of which are from spammers and lead to malicious websites.

With only 140 characters per Twitter message, it makes sense to shorten URLs and leave characters to say what you have to say. But with shortened URLs you have no idea what your final web destination will be. A spreader of malware and malicious websites couldn't be happier!
Researchers at Kaspersky Labs have found that as many as one in every 500 links on Twitter lead to sites hosting malware. They have also discovered that about 26% of Twitter messages - tweets - contain links and about half of those are created by spammers and people with bad intentions.
The two most popular URLs that the Krawler found posted to Twitter so far passed through the system in September. Both directed users to online dating sites. One of the sites, getion.com, is known to have hosted malware in the past, Raiu said.
So why isn't Twitter doing something to keep its users safe? Well, it is to an extent. In August Twitter started using a filtering system by Google to detect malicious URLs. The system checks the URLs against a blacklist and then either blocks the malicious URL from being posted or warns users to think before clicking on the link. However, the system only scans URLs that are shortened using the Bit.ly shortening service - the most commonly used on Twitter. Any links shortened using any of the over 200 other formats are not picked up by Twitter's filter.
Malicious URLs were discovered over a year ago before Twitter gained it's current level of popularity. Now, malware links regularly appear in "trending topics" where people are often checking to see what is the latest and greatest.
Read more at the Threat Level blog [83]. Graph courtesy of Kaspersky Labs [78]

So you received a data breach notification in the mail… no big deal, right? Not according to Javelin Strategy & Research’s latest report [86]. In fact, Javelin’s latest research reveals you are four times more likely to suffer identity fraud if you’ve received a data breach notification within the past year.
The average fraud victim will spend 30 hours and $496 out-of-pocket costs to restore their affairs, merchants and financial providers will spend billions to protect systems and brands, and law enforcement will work hard to chase the bad guys.
Many states around the country are enacting laws requiring entities that have experienced data security breaches to notify affected individuals whose personal information may be at risk. However, there seems to be a disconnect between breach notifications and consumer awareness of the risk they bring.
It might be a good idea considering the Identity Theft Resource Center [87] has already tracked 356 data breaches so far this year. Forty-six of those breaches have involved financial institutions, and when they or their third-party service providers are breached, it’s nasty.
Take for example the Heartland Payment Systems [88] breach earlier this year. The result of this breach was a staggering compromise of 130 million credit and debit cards. Now that’s a lot of Visa cards…yikes!
There is very little we can do to avoid data breaches, however there are steps that we can take to better prepare ourselves for the next time that breach notification shows up in the mailbox:
Lastly, remember the words of the orator, Robert Green Ingersoll when he said:
“It is a thousand times better to have common sense without education than to have education without common sense.”
Halloween is all about tricks, treats and pretending to be something your not. Scareware must think every day is Halloween.

Computer experts are reporting that scareware is on the rise. Scareware - a sneaky hacker technique used to steal personal information and spread viruses - is being found in more and more places online and even on trusted sites, like the New York Times.
"The recent scareware attacks are cropping up everywhere and can be found on even the most trusted Web sites online," said Alison Southwick, BBB spokesperson. "The threat of scareware undermines consumer trust in compromised Web sites, and on the Internet in general, but there are steps computer users can take to protect themselves."
Scareware usually presents itself as a pop up window on your computer that looks like it is from your computer. It gives some message that your computer has been infected with a virus that needs to be removed. Often the message tells you to go to the link provided to purchase and download anti-virus software. Once the software is purchased the download begins. Unfortunately, it is not anti-virus software that is being downloaded, but more viruses and malware.
If that weren't bad enough, now the hackers have your credit card information too.
This senario is playing out all over the internet. It was in mid-September that visitors to the New York Times web site started getting the infected pop up window. The New York Times traced the infected window back to an unauthorized ad. They later found out that the ad space was sold to hackers posing as Vonage.
But The New York Times is not the only site being affected and pop up windows are only half the story with scareware. According to Computer World Magazine, hackers are also "poisoning Google search results." Hackers monitor popular search topics and then create infected web pages with related content. They work to get those to the top of Google search results and when someone clicks a link in the search results - the infamous pop up window appears.
Fortunately there are steps that you can take to protect your computer from scareware:
If you clicked on the link and have downloaded the software all is not lost, but things aren't good. The Washington Post offers advice on their Security Fix blog [96] of how to rid your computer of the viruses and malware. But if you aren't computer savvy, you may think about calling a professional to clean up the mess.
UPDATE: An article from Wired magazine's Threat Level blog [97] sheds more light on how web sites are being targeted for malware distribution:
Web ads have become much more advanced over the years and many now include scripts that provide data tracking and other functions. Because of this, crooks are working to have their "ads" run on popular websites. Their ads also contain scripts, but the code displays scareware instead of tracking clicks or views.
In the article, Gawker Media - a major blog network of sites like Gizmodo, LifeHacker, Jalopnik and others - was targeted for ad placement, but fortunately Gawker has a team of geeks that digs into the code of any ad and confirms that it contains no malicious code. I'm guessing the NY Times now is enforcing a similar policy (yep, it is now [98]).
Heaven help us when we visit sites that have no such team of geeks to protect us from malicious ads...

July 2009 not only brought the hopes of fun summer activities, but it also brought the new vicious Trojan virus called Clampi. Clampi is a newly sophisticated virus designed to attack online banking systems. And unlike most Trojan viruses this virus can be picked up from trusted sites like blogs, online magazines, search engines and mainstream news websites, not just gambling and pornography sites. It also is only designed to attack computers running the Microsoft Windows operating system. So Mac users are safe from Clampi, for now.
Currently, Clampi is tracking over 4,500 financial websites. Most Trojan viruses usually track 30-40 sites at a time. Clampi is designed to watch: banks, credit card companies, e-mails, retail sites, utilities, online casinos, wire transfer services, share brokerages, government sites and mortgage lenders. Clampi is also not just limited to the United States. It has been found attacking in the United States, Britain and other English speaking countries.
Once Clampi has been picked up it settles into your computer and waits. What does it wait for? It waits for the user to log on to a bank account, credit card or some other financial website. Once the login information is entered, Clampi grabs it and shoots it to the cyber criminal's computer. From there the criminal uses the information to fulfill their desires. Whether it is taking money from a bank account, using a credit card to make purchases or reek whatever havoc they may.
Maybe you're thinking that this can't happen to you and maybe it won't. But it has been reported that through the use of Clampi criminals have stolen $75k from a car parts company in Georgia, $30k from a non-profit childcare organization [101] in Seattle, $480k from an online city bank account [102], $150k from a public school district in Oklahoma, $350k from a Chicago-are school district [103] and $700k from the Western Beaver School District [104] in Pennsylvania. There have also been reports of companies losing anywhere from $10k to $500k because of this one virus. There is really no telling how many people have been victims of the Clampi virus.
The most important thing you can do is to be proactive about protecting yourself from getting Clampi. Here are some ways to be proactive:
Zone Alarm has made their excellent Zone Alarm Pro 2010 software available for download today - October 13, 2009 - free of charge. It will be available until 6am PST on October 14, 2009.
The free download has the following stipulations:
The software is available for download here - http://download.zonealarm.com/bin/free/sum/index.html?cid=W100020 [109]
Links:
[1] http://www.fightidentitytheft.com/blog/airport-wi-fi-isnt-secure-even-if-google-makes-it-free
[2] http://www.freeholidaywifi.com/give-back/
[3] http://www.freeholidaywifi.com/photo-contest/
[4] http://www.fightidentitytheft.com/%20%20%20a.href%20%20%20
[5] http://www.google.com/search?q=AUS airport
[6] http://www.google.com/search?q=IND airport
[7] http://www.google.com/search?q=PFN airport
[8] http://www.google.com/search?q=BWI airport
[9] http://www.google.com/search?q=JAX airport
[10] http://www.google.com/search?q=PIT airport
[11] http://www.google.com/search?q=BIL airport
[12] http://www.google.com/search?q=AZO airport
[13] http://www.google.com/search?q=PWM airport
[14] http://www.google.com/search?q=BOS airport
[15] http://www.google.com/search?q=LAS airport
[16] http://www.google.com/search?q=SMF airport
[17] http://www.google.com/search?q=BZN airport
[18] http://www.google.com/search?q=SDF airport
[19] http://www.google.com/search?q=SAT airport
[20] http://www.google.com/search?q=BUF airport
[21] http://www.google.com/search?q=MSN airport
[22] http://www.google.com/search?q=SAN airport
[23] http://www.google.com/search?q=BUR airport
[24] http://www.google.com/search?q=MEM airport
[25] http://www.google.com/search?q=SJC airport
[26] http://www.google.com/search?q=CWA airport
[27] http://www.google.com/search?q=MIA airport
[28] http://www.google.com/search?q=SEA airport
[29] http://www.google.com/search?q=CLT airport
[30] http://www.google.com/search?q=MKE airport
[31] http://www.google.com/search?q=SBN airport
[32] http://www.google.com/search?q=DSM airport
[33] http://www.google.com/search?q=MRY airport
[34] http://www.google.com/search?q=GEG airport
[35] http://www.google.com/search?q=ELP airport
[36] http://www.google.com/search?q=BNA airport
[37] http://www.google.com/search?q=STL airport
[38] http://www.google.com/search?q=FLL airport
[39] http://www.google.com/search?q=PHF airport
[40] http://www.google.com/search?q=SCE airport
[41] http://www.google.com/search?q=RSW airport
[42] http://www.google.com/search?q=ORF airport
[43] http://www.google.com/search?q=TOL airport
[44] http://www.google.com/search?q=GSO airport
[45] http://www.google.com/search?q=OKC airport
[46] http://www.google.com/search?q=TVC airport
[47] http://www.google.com/search?q=HOU airport
[48] http://www.google.com/search?q=OMA airport
[49] http://www.google.com/search?q=PBI airport
[50] http://www.google.com/search?q=IAH airport
[51] http://www.google.com/search?q=MCO airport
[52] http://www.freeholidaywifi.com/
[53] http://www.freeholidaywifi.com/faq/
[54] http://www.fightidentitytheft.com/blog/airport-wi-fi-isnt-secure-even-if-google-makes-it-free#comments
[55] http://www.fightidentitytheft.com/blog/microsoft-windows-kernel-patch
[56] http://www.fightidentitytheft.com/blog/do-you-know-what-lurking-twitter-url
[57] http://www.fightidentitytheft.com/blog/scareware-everyday-halloween
[58] http://update.microsoft.com
[59] http://www.computerworld.com/s/article/9140688/Hackers_will_exploit_Windows_kernel_bug_researchers_say?taxonomyId=17&pageNumber=1
[60] http://voices.washingtonpost.com/securityfix/2009/11/microsoft_plugs_15_holes_in_wi.html?wprss=securityfix
[61] http://www.fightidentitytheft.com/blog/microsoft-windows-kernel-patch#comments
[62] http://www.fightidentitytheft.com/blog/report-phishing-email-what-do-when-you-catch-phish
[63] http://fightidentitytheft.com/paypal_scam.html
[64] http://www.phishtank.com
[65] http://www.phishtank.com/register.php
[66] mailto:phish@phishtank.com
[67] http://www.opendns.com/start
[68] http://www.fightidentitytheft.com/blog/report-phishing-email-what-do-when-you-catch-phish#comments
[69] http://www.fightidentitytheft.com/blog/medicare-fraud
[70] http://www.smpresource.org
[71] http://www.stopmedicarefraud.gov/fightback_brochure_rev.pdf
[72] http://www.stopmedicarefraud.gov/index.html
[73] http://www.fightidentitytheft.com/blog/medicare-fraud#comments
[74] http://www.fightidentitytheft.com/blog/facebook-awarded-711-million-spam-king
[75] http://en.wikipedia.org/wiki/Sanford_Wallace
[76] http://www.informationweek.com/news/global-cio/security/showArticle.jhtml?articleID=221400140
[77] http://www.fightidentitytheft.com/blog/facebook-awarded-711-million-spam-king#comments
[78] http://www.kaspersky.com/
[79] http://linkscanner.avg.com/
[80] http://securebrowsing.finjan.com/
[81] http://blog.bit.ly/post/68979274/expand-urls-and-get-traffic-summaries-before
[82] http://www.tweetdeck.com
[83] http://www.wired.com/threatlevel/2009/10/twitter_malware/
[84] http://www.fightidentitytheft.com/blog/do-you-know-what-lurking-twitter-url#comments
[85] http://www.fightidentitytheft.com/blog/data-breach-danger-study-shows-it’s-real
[86] http://www.javelinstrategy.com/2009/10/27/between-paranoia-and-compacency-educating-consumers-on-data-breaches-and-fraud-risk/
[87] http://www.idtheftcenter.org/artman2/publish/lib_survey/ITRC_2008_Breach_List.shtml
[88] http://www.bankinfosecurity.com/articles.php?art_id=1200
[89] http://www.fightidentitytheft.com/credit-monitoring.html
[90] http://www.fightidentitytheft.com/credit-freeze-laws.html
[91] http://www.fightidentitytheft.com/blog/identity-theft/protect-your-privacy-by-becoming-a-privacy-grouch
[92] http://www.fightidentitytheft.com/blog/data-breach-danger-study-shows-it’s-real#comments
[93] http://www.amazon.com/gp/product/B001U3PYLQ?ie=UTF8&tag=fightidentity-20&linkCode=as2&camp=1789&creative=390957&creativeASIN=B001U3PYLQ
[94] http://www.amazon.com/gp/product/B002L7BR20?ie=UTF8&tag=fightidentity-20&linkCode=as2&camp=1789&creative=390957&creativeASIN=B002L7BR20
[95] http://www.avast.com/eng/avast_4_home.html
[96] http://voices.washingtonpost.com/securityfix/2009/09/what_to_do_when_rogue_anti-vir.html
[97] http://www.wired.com/threatlevel/2009/10/gawker/
[98] http://www.wired.com/threatlevel/2009/09/nyt-revamps-online-ad-sales-after-malware-scam/
[99] http://www.fightidentitytheft.com/blog/scareware-everyday-halloween#comments
[100] http://www.fightidentitytheft.com/blog/new-trojan-virus-attacks-world-online-banking
[101] http://voices.washingtonpost.com/securityfix/2009/09/online_bank_robbers_target_hea.html
[102] http://www.theregister.co.uk/2009/10/14/microsoft_windows_bank_thefts/
[103] http://www.eschoolnews.com/news/top-news/news-by-subject/technologies/index.cfm?i=61006
[104] http://www.computerworld.com/s/article/9138636/School_boards_hit_with_cash_stealing_Trojan
[105] http://www.fightidentitytheft.com/blog/airport-wireless-network-not-as-safe-as-you-think
[106] http://en.wikipedia.org/wiki/Wi-Fi_Protected_Access
[107] http://www.fightidentitytheft.com/blog/new-trojan-virus-attacks-world-online-banking#comments
[108] http://www.fightidentitytheft.com/blog/free-zone-pro-firewall-software-oct-13-only
[109] http://www.fatwallet.com/redirect/bounce.php?afsrc=1&mid=14241339&url=http://download.zonealarm.com/bin/free/sum/index.html?cid=W100020
[110] http://www.fightidentitytheft.com/blog/free-zone-pro-firewall-software-oct-13-only#comments
[111] http://www.fightidentitytheft.com/blog?page=1
[112] http://www.fightidentitytheft.com/blog?page=2
[113] http://www.fightidentitytheft.com/blog?page=3
[114] http://www.fightidentitytheft.com/blog?page=4
[115] http://www.fightidentitytheft.com/blog?page=5
[116] http://www.fightidentitytheft.com/blog?page=6
[117] http://www.fightidentitytheft.com/blog?page=7
[118] http://www.fightidentitytheft.com/blog?page=8