Showing posts with label spam. Show all posts
Showing posts with label spam. Show all posts

Monday, September 30, 2019

iProfile / Vertifi / Jobzooma at it **AGAIN**??? (Updated)

Updated 23rd November 2019; Originally posted 30th September 2019

Amazingly the Jobzooma team are still at it.

After tendering some applications for contracts earlier today I had an email from our old friends Jobzooma. I can find no trace of any connection between the potential clients I emailed or how they acquired my details, yet somehow I've sent them my CV???

Yeh but no
This isn't how to deal with consent - there's no opt-in, there's no request about whether I've asked for it. The email asks you to click a link to verify that they have the right data, which I'm absolutely not going to click. That could be interpreted as explicit consent for them to continue storing my data - I've never done any business with them!

Have sent chaser email but be warned - they're still at it. If you read the previously linked scam alert you'll realise why you're better off avoiding altogether.

I've asked them where and how they got the alleged CV and they've acknowledged receipt of the request. Will update when I have more but on the face of it appears to breach PECR and DPA 2018 [inc. GDPR 2018].

It's no good asking for consent after you've already acquired, stored and processed the data.

Updates

I finally received a response from ICO, in which they stated that:

"We have considered the information available in relation to this complaint and we are of the view that Jobzooma has not complied with their Data Protection obligations. This is because you did not receive an appropriate response to the data protection concerns you raised. We consider this to be an infringement of the legislation.

Subsequently, we have written to Jobzooma, via the Data Protection Officer, to explain that we expect the organisation to review your complaint and take action to resolve any outstanding matters.

We have issued guidance to Jobzooma as a result of your complaint and expect they will be in contact with you in due course. Thank you for bringing your concerns to our attention.

This complaint will be kept on file and this will help us over time to build a picture of Jobzooma’s information rights practices.  We keep a record of all the complaints raised with us about the way organisations process personal information.  The information we gather from complaints may form the basis for action in the future where appropriate.
"

I wasn't happy with this response because it isn't a strong enough message for a repeat offender, and also I've recieved no responses from Jobzooma at all. I asked the case officer to look into further evidence I provided, and examine the linkages evidenced between Vertifi, Talent Spa and Jobzooma.

I asked the case officer to then review the outcome and proceed with a publishable decision, so that Jobzooma would be the target of ICO enforcement should they offend again.

That reply to the ICO case officer was sent on 4th November 2019, and I have not yet received a response, other than the auto-acknowledgement.

However it is good to see ICO confirming my suspicions that Jobzooma are / were acting unlawfully.

I've noted further updates in November 2019 on the scam alert post on the portal.

Thursday, September 05, 2019

Insecure Security at the DMA

It's been a while since I've had a chance to write up anything, having been so busy with consultancy work over the last few years.

A number of people have asked what steps I'd take to keep your phone numbers off spam call lists and the answer is simple - don't give it out in the first place! However that's not really a practical approach is it?

Having had to go through the pain of successfully chasing spammers and cold-callers in the courts over the last half a decade (because the regulators for advertising and data protection weren't willing to lift a finger), I've devised more manageable approaches.

More likely what will work is burner numbers from platforms like Hushed, which allow you to create a number (at a price) for a set period of time. I find this really useful for CVs (resumes & business profile documents for tender submissions) with companies I've not worked with before or jobsites I know not to trust; and also email signatures at client site.

Often the level of information security requires that I do not move client information off their own systems necessitating an email address on their platforms - they also usually prefer a signature so I supply my own company details and a VoiP / burner number.

Once I've finished the client visit or project there's no need to get in touch so the number is removed. Same thing with tender documents and resumes - once I have enough clients I close down the entry on the jobsites or notify the companies that those tender documents are out-of-date.

Of course with your own phone number it's a bit different so wherever possible use the Telephone Preference Service. It's a Direct Marketing Association-led initiative to help it's members adhere to PECR and the Data Protection Act. However that's not really true as PECR states that no-one can send you unsolicited messages (section 22) or cold call you (section 21) without your prior consent or purchase of goods. The Data Protection Act states that your data cannot be stored, processed or used without your prior consent either - which means that the DMAs explanation of the TPS mechanism dodges the issue at heart - where did they get your data and what makes them think you want to speak to them in the first place?

You see, if a spammer or cold-call centre had asked you for your permission to acquire (c.f. buy leads database) your data first and you'd said "no", the TPS list would be unnecessary.

The concept of TPS then must focus on the scenario where you've engaged with, for example, a company to buy their products but never specifically stated that they may use your details for marketing purposes. If, in this example, the sale does not complete you should always state that the company may not re-use your personal data for any reason. If they were happy to store your data received verbally they must also accept the notice to destroy that data verbally.

This stops the issue at point although if they later spam call you, you'll need proof of that original conversation - email or support tickets are usually easiest.

Once you're on the TPS lists DMA-linked organisations must make it their priority to ensure that they regularly update the copy of the TPS phone numbers lists they keep - this should ensure that you don't get cold-calls from UK-based or UK-operating organisations.

Every year they'll send you a reminder email to renew your TPS registration - which is ridiculous. If you haven't spoken to a company for over a year why would you suddenly want to start getting cold calls and spam again? It's bad enough we're playing cat-and-mouse with the malvertising platforms that we shouldn't have to deal with the direct approaches too.

This years re-registration was a little more worrying - the email I'd received not only explained why and what... but included the username and password I'd need to log-in and verify re-registration. As an aside this is terrible practise - instead of account details I could register with initially and tidy away into a nice, secure password manager - they're not mentioning any account creation and sending me a username-password combo in a plain-text email! Added to that is the fact that the password is entirely numeric and less than ten characters. It'd take one of my Raspberry Pi's & John The Ripper the grand total of about 30 seconds to brute force that (assuming a hash had been acquired).

Looks like a Perl-based form submission - I hope it's appropriately secured but I'm not going to even think about taking a look without prior engagement with their SOC.

The domain they're using for renewals is "secure.dma.org.uk". Normally I'll use Tor for the unsubscribe / renew links I get to minimise the intrusion - although each link will have an embedded tracking mechanism Tor will prevent OS, screen res, lists of plugins etc. being available for scraping and trend analysis. There's no lawful reason to exclude Tor traffic for a service notification / required intervention.

Before I make the next statement I want to stress that this may be a Tor-specific issue and not necessarily related to the DMA at all, as the CA verification works fine in Firefox: The URL immediately gave me a "Unsecure [sic] site warning" and on closer inspection showed a self-signed certificate with issuer "Digicert Global CA G2". Bit odd. That's usually the middle cert in the chain back to the Digicert Global Root. The self-signed bit is what usually causes that red padlock in the browser address bar if you weren't aware already.



Not sure why but Tor seemed to have missed out the CA repository, but if I didn't know any better this would also look like a MitM attack.

I sparked up Firefox and used the same URL - all fine. Verified CA-issued cert matching the domain and domain name resolved via DoT + DNSSEC. And no, we don't use Google DNS or similar.

Ok, ok so perhaps a bit of click-baiting in the headline but quite a good example of what to look out for. I think it looks like there's some Tor exit nodes which are being proxied / filtered so I tried generating a new Tor circuit and then changing bridges but this didn't change the issue.

The DMA domains are not on the Tor blocking lists and other domains seems to be fine.

Regardless I'm not going to put any personal data into a web page that for some reason arouses suspicions. I used a different browser and checked the domain ownership vs. historic TPS emails and all seemed to check out.

TPS registration renewed via Firefox instead - perhaps one day the DMA will get their acts together and make this a permanent opt-in (on the basis of opt-in-by-default at their member organisations) with TPS as an elective opt-in for categories of products and services you want to hear about. This would even work well for consumers buying a new / previously used number.

I'm sure we'd all race to sign up for cold calls and spam emails after all :)  

Thursday, September 07, 2017

Très Européen


(Before anyone says / thinks anything - I'm Pro-EU. Post title not a dig at Brexit insanity)

Europcar sit within an industry which makes it's money but getting people to pay more than the cost of a car for borrowing it. It's a good business model even with the shadier parts of it's industry. They're relentless spammers too - they provide no option to explicitly opt-in to marketing messages when you purchase or sign-up for their services (not even an explicit opt-out until after the fact). We'll come back to PECR in a moment.

Background


Back in 2015 I rented a car from Europcar - there was no issue with payment, no problem picking up the car, nor returning it at the end of the rental.

All well and good it seems? We've used them since on holidays in Cornwall too. Again... all seemed fine.

Last year I needed the same service whilst my own car was in the shop - booked the rental online, paid upfront, scheduled the pick up date for the Sunday afternoon before I travelled and thought nothing more of it.

When I arrived on the Sunday afternoon expecting to pick up the Merc E-class (*or similar) I was told that the vehicle was no longer available.Which was interesting because I could see the receipt on my phone, and could see the set of vehicles out back that matched the description.

I asked "Do you not have the vehicle class available?".

"Yes", the member of staff said, "but we cannot provide it to you".

Well that was always going to peak my curiosity. After various different attempts at rewording the question "Why the hell not?" in different ways to try and get an answer, they offered me a vehicle the size of my shoe.

Nope.

Drive to and from Norwich in a hand basket? No thanks. 322 miles of tall-person-comedically-cramped-into-a-hatstand? Double nope.

So I cancelled the rental and got a refund ... but no-one could tell me why. I know from past experience in that same office that they were happy to explain to me why another customer was not able to rent one of their vehicles - their staff explained why the argument started to attempt to keep my business I guess.

But they couldn't tell me - to my face - what the problem was.

I sent them a SAR later that week (oh come, on, what else did you expect from me eh?). No reply. Sent a follow up over 40 days later. This isn't to some obscure email address incidentally, this to the email address advertised on their own support, contact and T's and C's pages.

No response. Now I'm irked and have had to explain to a client why I couldn't travel to client site for the week in question. So in an NBA went...again..no response. Nothing at all. Normally that gets a "Oh sorry we lost your email in all the spam, let us sort your SAR out now". But not this time.

The Case


So I try a claim in the small claims court for failure to respond to SAR - because:
  1. my website booking completed - they accepted my money and my details and we entered into a deal
  2. they failed to notify me of a problem until after I'd travelled by train to their pick-up office
  3. they refused to tell me why they were no longer honouring my booking
  4. they spammed me every time I buy something without actually acquiring express / explicit consent. Even after telling them to piss off directly
  5. they had ignored my subject access request
  6. they continued to spam me after rejecting my custom, and without asking me whether I wanted it or not
All reasonable so far - so I alleged that they'd failed to respond to SAR, added the breaches of PECR for the spam and filed it. About 4 pages of particulars / witness statements on essentially a very simple claim.

This is their filed defence:

That's the whole defence btw
As there's almost nothing to it I'll explain why this is a strange defence to file.

Paragraph 1 & 2: In terms of the consent for marketing; I agree with a more general legal opinion that "Consent by definition requires some sort of positive action on behalf of the recipient." - PECR section 22 also infers a direct and explicit action on the part of the potential recipient of unsolicited marketing in order to opt-in to it. There was also no consent statement on the page when I hired any cars - so there's no reasonable effort from Europcar at all.

Europcar's approach of burying this consent and then relying on the "purchase of goods or services" exception doesn't really wash - if the explicit opt-in was available as it should be, and the customer does nothing they are indicating they have no desire to get spammed. GDPR levels the playing field and requires explicitly activated opt-in for spam (amongst other things). Roll on May 2018.

Paragraph 3 & 4: I use a different email address for each purchase so that - when a company inevitably gets hacked or stupidly decides to sell it's customer database - I can tell who the idiot was. To say there was "no information to suggest that [I] the claimant has requested ... not be used for [spam]" is a massive lie - they'd failed to acquire consent at all.

Paragraph 5: By post?! I'd sent a number of messages (including serving the particulars of the claim) via email and they try to reply by post? Surely that's just trying to hide away from making a simple effort of sending an email? Unfortunately whomever actually received this letter must have rejected it on the basis that delivery was attempted at the wrong address. I regretfully never had the opportunity to reject it.

The Result


The defendant claimed never to have received any of the documents - the same documents they were reading in order to file a defence incidentally.

The defendant also claimed that they never received the emailed SAR or NBA.

That changed the moment I produced their own auto-responders for each message I'd sent; and they subsequently settled for a menial amount. I've still not received a response to my SAR but they agreed to cease spamming me. I just wanted to know why they went back on their word.

Because no-one apparently reads the emails from their customer service inbox; if you have similar issues with Europcar in future I'd recommend to contact their relations officer, John Cooper, directly. This ensures there's no misunderstandings in communication - it is 2017 after all. Email john.cooper@europcar.com or via phone on 0116 217 3422.


Don't expect a welcoming conversation or any admission of wrongdoing - even when their error is as plain as the nose on their faces.

Friday, April 07, 2017

20 Years Later....

In heady days of the mid-to-late nineties, the web was fresh and so was the spam. It was the era of Lycos, Napster and MetaCrawler - Google had barely been incorporated, Palm was making smart phones and Apple were making blue plastic TV paperweights.

During such heady days of technological marvel I signed up a for hotmail.co.uk email address - one I've been using ever since. Of course, in the [web] medieval days spam was in a different order to today: the economies surrounding ads and direct marketing was dramatically smaller, and simple junk mail rules were sufficient.

Today though things are different. Data slurping fisheries such as TeraData scrape personal data from jobs boards, people still believe online surveys and prize giveaways are actually rewarding, and companies bitter at receiving SARs and ICO complaints never used to sell your data on.

As a result the majority of traffic on my Microsoft accounts are ads, phishing attempts or newsletters I didn't subscribe to. Thanks to Microsoft - since getting shot of Balmer they've come such a long way - its easy to get shot of all this spam in one go.

Last month I added a new alias to use for my core MS services and set it as the primary alias. Aside from a couple of complications with the Xbox Insider Program and Amazons Xbox app authentication it was smooth sailing. I had to notify one organisation of an email address change - that's it. Android apps related to the account all seem to have switched themselves over.

This is no mean feat considering the authentication model, security and architecture involved with multiple devices (phones, consoles, laptops, desktops) happened seamlessly and without support intervention.

So today, with little or no incident logged as a result - an achievement in itself - I'm deleting the now unused hotmail.co.uk alias. Perhaps that will trigger an avalanche of account issues, but if there are no more posts from me on the subject over the next few weeks, assume all went well.

[Updated August 2017 - All went well, the rate of spam to my Hotmail Outlook.com addresses dropped like a stone]

From a humanist perspective I feel like departing from the Hotmail domain and fully accepting the Outlook.com moniker is saying goodbye to the old family home in a lot of ways. The email address, for me at least, dates back to essentially the beginning of the web (which evokes nostalgic thought of AOL, university HP-UX lab time, Half-Life and Team Fortress lan parties) I've no doubt there are probably still hundreds of thousands of people - perhaps millions - still using hotmail email addresses via Outlook.com, however it does feel like the personal loss of a battle in the war on spam.

I still get around 400 spam emails per month on the personal email addresses (excluding this hotmail address) I regularly use - a substantial increase from non-EEA countries of origin - the problem is far from over. But this set of spam arrives on domains and servers I control, which means the senders cannot hide. The usual jokers who begrudgingly respond to SARs and then add that email address to whatever spam subscriptions they can find basically.

I've been designing a filtering, tracking and reporting system - known only as project RingoDingo for the time being - which I hope to use to map the flow of personal data. It might just make some nice diagrams but could be useful for everyone - based on all the spam I get I'm trying to recycle it for good purpose by using it as test data. One of the primary goals is to deal with spam actors before they get to your door step. At the moment I'm looking to open-source the majority of the modules.

GDPR can't come fast enough and I just don't have time for legal action against spammers at the moment (in the last few years this has been the only effective way to force spammers into respecting the law itself); this is measured against the more recent actions from ICO, which are extremely promising. Recent direct communication I've had with ICO's dedicated anti-spam team also looks very promising and this apparently renewed sense of vigour in their approach is most welcome.

Retaining a more optimistic perspective, we could infer that the data trading and spamming industry will have to remap their entire business model, or face massive financial penalty. I've already seen tweets from DMA-affiliated accounts signal as much. So giving up my hotmail.co.uk email address is a small price to pay.

Last one to leave the domain, please turn off the lights.