WoodCentral Forums

Est. 1998 — 27 years of woodworking knowledge

Webmail Revisited (longish)

Posts

Webmail Revisited (longish)

#1

Webmail Revisited (longish)

David Yoho

Earlier there was some discussion here about using Webmail versus an email program that checks and downloads it to one's computer. The point was made that Webmail can generally be safer because it remains on the provider's server, keeping harmful code from the user's computer. While there is some validity to this, it isn't always the case.

Yesterday I got a call from a good friend who just finished getting her credit card bank to cancel her card, remove charges she didn't make, and issue a new one after saying her computer had been hacked. She described watching her mouse cursor move across the screen clicking on sites and making the purchases. I asked her a few questions and then it became clear to me what happened.

She uses Webmail on her provider's site. She got an email saying something about her PayPal account having some kind of a problem. BOOM - RED FLAG - a classic Phishing scam. She doesn't have a PayPal account! I asked her if she clicked on any kind of link and she said - Yes!! That's all it took. Doesn't matter if the mail is on your computer or not. Clicking the link opened the door for the bad guys. She learned a lesson the hard way but it could have been worse.

While Webmail may be convenient for some it isn't bulletproof. I like downloading my mail, keeping important ones in various folders for later reference, and deleting those I don't need. I also use a program called Mailwasher Pro that checks both of my email accounts, allows me to preview what's there, flags known spam for deleting from the server while allowing me to manually add to that list, then I click on the Wash Mail button and it deletes what is either spam or I don't want, opens my email program from which I can download only good mail.

I'm not affiliated with Mail Washer - just a happy customer. Between it and some common sense when it comes to Phishing, I've never downloaded anything harmful to my computer.

Re: Webmail Revisited (longish)

#2

Re: Webmail Revisited (longish)

John McGaw

Well, I've certainly downloaded things in mail that were meant to be harmful but decades of experience tells me that blindly clicking on links is suicidal. Responding to a "problem" with an account you don't even have is, well, incredible.

Every now and then I get a barrage of robocalls telling me of dire security breaches in my iCloud account. I don't have one. Looking at the phone's transcripts of the calls shows how the calls are programmed quite clearly. I get maybe eight or ten of these calls in a day and then they just go away until, a couple of weeks later, they come back. The numbers are, of course spoofed, and even good filtering seems to be unable to block them entirely but I've learned to ignore them quite efficiently.

DON'T BLINDLY CLICK ON LINKS, PEOPLE!

Re: Webmail Revisited (longish)

#3

Re: Webmail Revisited (longish)

Bill Howatt

Just because the source message in webmail doesn't obviously get downloaded to your computer doesn't mean that nothing is happening with the contents on your computer. The computer has to execute the instructions contained in the message which is how you get your formatting, links, etc. There is nothing to stop the malware writers from embedding other code in the webmail message to do nasty things since your computer just executes whatever it gets presented with.

Another thing, there is nothing stopping a malware writer from affixing nasty code to the buttons labelled things like Close, Exit, Ignore, or even the X on a window which would normally close it. If I'm in doubt in MS Windows i use Alt-F4 to close the program to avoid other buttons that may be compromised. I'm not sure if they could compromise the Alt-F4 but I think it is much less likely. You can always turn off the computer and then power it up again.

Bill

Re: Webmail Revisited (longish)

#4

robocalls

David Yoho

Hah, that's another one. We maintain a landline in addition to our mobile phones. Our house phone gets at least several robocalls a day. We have caller ID as well as an answering machine. Unless it's a known good caller, we let the machine get it. Usually those calls don't leave a message.

The other day the phone rang and I looked at the caller ID. It said Napa Auto Parts. The message was about my Apple Account being in some sort of peril. I laughed and thought to myself - Times must be hard out there for real. Apple is now working out of the back of Napa Auto Parts stores!

Re: Webmail Revisited (longish)

#5

Re: Webmail Revisited (longish)

Walt

DON'T BLINDLY CLICK ON LINKS, PEOPLE!

Firefox and I assume most browsers will, if a link is hovered over show the real URL of the link. It usually ain't what it claims to be. Some of them can be pretty sneaky though and can at a casual glance appear legitimate.

👍 This page answered my questions

Your vote helps other woodworkers quickly find the answers and techniques that actually work in the shop.