guardianproject / haven

Haven is for people who need a way to protect their personal spaces and possessions without compromising their own privacy, through an Android app and on-device sensors
https://guardianproject.github.io/haven/
GNU General Public License v3.0
6.57k stars 729 forks source link

malware and certificates being used on android OS to take control and datamine #462

Closed somebody277 closed 1 year ago

somebody277 commented 1 year ago

i have had my personal info and identity stolen plus all pictures/cloud storage taken from me and i cant seem to get a responce from google or microsoft for help. i have gone through 9 devices now and i am pretty sure my router is probably infected aswell as firestick roku etc. could anyone give me advice on how to send logs to verify if this is the case and any guidance to fixing this problem?

Thanks M

fat-tire commented 1 year ago

You've given no details about anything, really, about why you think your identity was stolen, what the 9 devices are, why you think your router and firestick was "infected" or by what ("malware and certificates" isn't very helpful)-- but overall, here are some thoughts--

Someone else can jump in if I'm saying something stupid or ill-advised, but right now you apparently got nothing, so this is a start and something to think about and/or build on.

  1. Start on a computer you know is safe and not compromised. Ideally you want a "base-of-operations" that isn't infected or potentially being watched/data collected by a bad guy.
  2. Then physically disconnect everything else from the Internet. Depending on the device this could be done by pulling ethernet plugs, turning off your wifi router, or whatever.
  3. If you think anything with email may have been compromised, change your email's password first--why? If someone has your email address, they can potentially use that access to then change your passwords or info on other accounts that would send you a confirmation email.
  4. Additionally, if you believe someone else is controlling your email, notify (not via email obviously) your friends, contacts, business associates, etc. that you believe that email has been hacked and to NOT assume emails from that address (including emails sent in the past starting with when you were hacked) are really from you. You do not want a hacker to use your account to target others (or to target you by getting sensitive info about you info from others)
  5. After locking down your email accounts, prioritize your other online accounts (financial stuff maybe would take priority for example) and change the passwords for them too. Make sure you are recording the new passwords in a secure way-- such as with a password manager.
  6. For google stuff- go to myaccount.google.com/security and check the Recent security activity and where you are signed on. Turn on 2-step verification, disable access to apps or devices you don't personally have control over. Follow any additional security recommendations.
  7. Microsoft, roku, firestick-- I know nothing about this.
  8. On android, you can wipe/reset the device, then re-log in with your new password and it should be able to recover most app settings that are saved in the cloud. Make sure you back up any unsaved pictures or whatever other important data on the phone/device first if possible.
  9. router-- reboot and make sure your router is up to date with the lastest firmware available for that router model. If you're really paranoid, get a new router.
  10. Again, if you're super-paranoid wipe all machines that you are not sure about their security-- back up whatever data you can, then reinstall the operating system from scratch, using known-good media, if possible. (One thing to consider is that you don't accidentally back up whatever-infected-you-in-the-first-place and then restore it to the new operating system, reinfecting yourself.)
  11. Identity theft-- freeze all your credit, and I think there are lots of sites that have more info on what to do here.

That's all I got offhand, especially with no specifics. But in any case, good luck.

somebody277 commented 1 year ago

as i wrote fattire im just a dumb ass who thought ppl with computer skills wouldnt mind dropping me hints. but its alll good i dont mind im gonnna erase this and happy new year

somebody277 commented 1 year ago

it was because the "bad guy" with crtificates and knowledge got me by using a google licence and tellin me i had to log in to get my email unlocked.. then he erased my name from all the connected emails and that is about 15 or so thruout my years.. im pissed and he stole my cloud or hard driveof my phone which had me and my girlfriend and her son on there plus my fuckin young family!! and i also had my identity stolen so yeah i think he isnt juust a figment of my imagination.. have a good one

fat-tire commented 1 year ago

figment of your imagination? I was just saying I had no specifics. If you were phished/social engineered it doesn't sound like your system was "infected"... but anyway, sorry that happened.

somebody277 commented 1 year ago

Thank you I apologize for the way I wrote back to you I was just overwhelmed with everything and felt like I was being talked down to. I am sorry I didn't come across more respectful. Take care With respect AJ


From: Fattire @.> Sent: Sunday, January 1, 2023 2:27 PM To: guardianproject/haven @.> Cc: somebody277 @.>; State change @.> Subject: Re: [guardianproject/haven] malware and certificates being used on android OS to take control and datamine (Issue #462)

figment of your imagination? I was just saying I had no specifics. If you were phished/social engineered it doesn't sound like your system was "infected"... but anyway, sorry that happened.

— Reply to this email directly, view it on GitHubhttps://github.com/guardianproject/haven/issues/462#issuecomment-1368515399, or unsubscribehttps://github.com/notifications/unsubscribe-auth/A47UKHOBHJW4FUMBLXCGFD3WQHLBFANCNFSM6AAAAAATMCMPYA. You are receiving this because you modified the open/close state.Message ID: @.***>