Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

October 29, 2025

AI-related scams via Google Calendar

Whose calendar is it, anyway? A cautionary tale

A while ago I noticed an odd "Paypal to BTC" calendar item that I didn't recognise, so I clicked on it and saw this.

"Interesting," I thought, "where on Earth did this come from?" You'll notice that only my identity is listed, as whoever created it has concealed their own identity by withholding the full guest list.

Intrigued, I clicked on the edit button to get a full view, and found this.


I don't know about you, but I very much doubt the fundacjawidzialnedzieki.org domain exists, let alone represents any kind of legitimate organisation. Further investigation revealed several similar entries scattered around my calendar, some containing specific instructions to transfer funds. An AI, however, might not "understand" (I use apostrophes because thinking and understanding are beyond the capabilities of the current chatbots) that this indicates a scam.

Being the cautious techie that I am I have not and do not intend to use automation to take unsupervised actions as a result of unsolicited input from Internet randos. To me, therefore, this represents a nuisance rather than a threat. As you will imagine, I have cleaned up my calendar and closed the loophole that allowed those events on to my calendar—see "Protecting yourself" below.

I can well imagine, however, that less conservative business people will be thrilled to avail themselves of the advantages of technology that helps them to set up appointments and keep on top of regular tasks, including settlement of outstanding accounts. Until their ever-helpful digital robot acts on an instruction injected by a third party in a similar manner to this. Who will be responsible for those losses?

Protecting yourself

It can happen to you. Check that arbitrary senders can't add events to your calendars by opening the calendar, bringing up the settings, then under "Events" make sure that the "Add invitations to my calendar" selector is set to "When I respond to the invitation in email."

This Google support page says it's not a new issue—in  fact the issue is so old the solutions refer to a setting that's no longer available). Here's what my settings page looked like.
Screenshot of fully-documented paged linked below

The process is fully documented in this support page.

Further thoughts


A current search implies it's still an issue.
Top four "people also ask" selections from a Google
search for "google calendar unrecognised events:"

Be very careful about automating any processes which could cost you money if they don't do what you expect. Until recently, automation was predictable. Once "AI" enters the picture, predictability becomes problematic. In a carefully designed system, most of the time nothing will go wrong. What you have to do is to limit the downside when it does, as it inevitably will (ironically just like systems with humans in the loop, while totally lacking in empathy or creativity). The more automation the greater the risk.

Understand that vendors don't always provide systems that are secure by default. Google made two mistakes here: the first was allow external users to make entries in your calendar; the second was to allow those who do make such entries to hide their identity. Neither shows much concern or respect for the people who use their products. At least the former can be switched off, so why isn't it switched off by default? I can't imagine in my long use of Google's products I would have ever selected such an option voluntarily.

In the past we have mostly had human adversaries to contend with. Nowadays exploits involving large networks of fictitious identities can be constructed en masse with minimal effort in industrial quantities. We can't rely on luck to avoid the attention of bad actors forever when without effective protection and sensible precautions a business can be ended overnight.

September 15, 2009

Apple's Cynical Approach

It turns out that for a long time now Apple iPhones have been lying to Exchange Server mail hosts, telling the mail servers that on-device encryption is supported. It now transpires that only the recently-added 3G S model supports encryption through hardware, and this came to light when a recent upgrade made the phones tell the truth.

The unfortunate consequence for any business that has standardized on iPhones for remote mail access is that if they have required on-device encryption the iPhone has been breaking their security guidelines since it was installed. According to Apple their only alternatives are to change their security policies to allow iPhones to store plain text emails or upgrade everyone to the new 3G S device.

What a crock. Not only that, the iPhone users apparently had to wait until after they'd been upgraded to even learn that this issue existed. I am so glad I'm not a corporate Apple user.

January 18, 2008

Python Gets Security Plaudit, Moves to Coverity Rung 2

This is something that hasn't yet made big news, but I don't know why not. For over a year now Coverity, funded by the Department of Homeland Security's Open Source Hardening project, has been working to report potential security flaws in open source projects. The company recently announced that eleven projects had been sufficiently proactive in responding to defect reports that they now move to "rung 2", giving them access to further levels of Coverity's hardening technology.

Of course Python is one of those projects. It says a lot for the developers that they responded so aggressively to the reports (some, inevitably, were specious but several represented significant issues that thanks to this initiative will never trouble Python users). The bottom line? Python, like Amanda, NTP, OpenPAM, OpenVPN, Overdose, Perl, PHP, Postfix, Samba, and TCL, is a project whose developers take correctness and security seriously.

I anxiously await the results of the first scan of some Microsoft product, but I am not holding my breath. Even if the scan takes place (and for all I know Microsoft are using Coverity's scanners every day) Microsoft would not publish the results. This shows the value of openness, one of open source's major benefits: you know that security issues aren't being swept under the rug in the name of profit.

The tail end of a ZD-Net article suggests that some people are less than happy about this project because they feel it will lead to ill-informed discussion about security problems in open source software. While this isn't a battle that will be won in a day, being seen to assiduously fix reported software problems will eventually win against the lip service paid to security by so many commercial vendors. If you're looking for well-informed discussion then this blog is the place to come (he wrote, modestly).

December 6, 2007

Voting Machine Manufacturers Don't Get It

It's reasonably well known that the governor of California instituted a thorough review of voting machines which culminated in a fairly damning report earlier this year. San Francisco is now getting ready to spend $12 million on new machines, and the manufacturers have (apparently successfully) resisted requests to open up their source code. The reason they give is that "it would amount to giving away to competitors their proprietary software code".

So never mind scrutinized correctness, let's keep the buggy stuff to ourselves. These people make me smile as I hit my head against the wall. If democracy is as important as everyone keeps claiming then the most important thing is to count the damned votes correctly. But this is America, so profits have to come first.

November 5, 2007

The Calm Before the Storm?

Bruce Schneier's Crypto-Gram is usually an interesting read, and October's was so for a fine description of much of what is known about the Storm worm (quite a lot) and its controllers (next to nothing, except that they are skilled programmers who continue to refine their technology). The scariest part was Schneier's closing remark:
Personally, I'm worried about what Storm's creators are planning for Phase II.

If he's worried I guess we should all be worried.

August 3, 2007

Electronic Voting? Just Say "No"

Because Ka-Ping Yee was involved, and because I have a professional interest in information security, I have been keeping my eye on the California Secretary of State's investigation into electronic voting machines. I'm afraid the initial results are not at all promising for the future of American democracy. Here's the most telling quote from the source code review of the Sequoia system:
Of particular concern is that virtually every software mechanism related to counting votes is exposed, directly or indirectly, to compromise through tampering with equipment that is deployed in the field. In many cases, tampering sufficient to cause compromise requires only brief physical access and may leave behind little or no evidence.
This is hardly a surprise to those who have studied computer intrusion techniques, but clearly wasn't taken into account by the system's designers. The list of vulnerabilities makes me wonder whether the people who designed the system actually had any security training at all. Yet I just know, before I look for it, that the inevitable response of the vendors involved will be to try to minimize the impact of the security issues, just like Microsoft used to (they know better now).

As far as the voting public is concerned all of this might just as well not have happened, since they are neither educated nor encouraged to value their participation in democracy. As a result I fully expect that electronic voting systems of dubious security and with no paper audit trail will be even more widely deployed in the next election, with the result that victory will go to the least scrupulous, and no challeneg will be mounted by an apathetic populace.

The depressing thing is that the majority of voters (hey, aren't they supposed to decide who gets elected?) would rather leave the dirty business of politics to someone else. It's easier to keep their heads buried in the sand than engage with the endemic corruption of the democratic process. Perhaps you really do get the government you deserve.

Because I live in the USA I can't really claim to be disinterested, but for the record I am at present merely a disenfranchised immigrant. So I am asking all the citizens I know to take an interest in these issues and force the politicos and bureaucrats to implement a more rigorous and respectful approach to secure voting. There would be a real value to open source voting machines.