netrom<p>With it being <a href="https://infosec.exchange/tags/BlackFriday" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>BlackFriday</span></a> and all, I hope nobody is caught up in scams or phishing attacks while doing their (frantic!) online <a href="https://infosec.exchange/tags/shopping" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>shopping</span></a>.</p><p>Here are a few <a href="https://infosec.exchange/tags/security" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>security</span></a> and <a href="https://infosec.exchange/tags/privacy" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>privacy</span></a> tips that I hope will help somebody:</p><p>1) If you have a coupon code, don't follow a provided link to the shopping page. Instead find the page yourself, e.g., via a <a href="https://infosec.exchange/tags/searchengine" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>searchengine</span></a>, and then input the coupon code manually.</p><p>2) Access online shops without being logged in, and without any <a href="https://infosec.exchange/tags/cookies" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>cookies</span></a>, such that the shop cannot set prices according to <a href="https://infosec.exchange/tags/personaldata" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>personaldata</span></a> or previous purchases (yes, they do that). Except, of course, if the discount is only available when actually having an account. Attempt anonymously first.</p><p>3) An improvement to 2) is accessing online shops via <a href="https://infosec.exchange/tags/TorBrowser" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>TorBrowser</span></a> or similar. </p><p>4) Use a <a href="https://infosec.exchange/tags/VPN" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>VPN</span></a> such that <a href="https://infosec.exchange/tags/ISPs" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ISPs</span></a> and other adversaries cannot obtain or spoof information. It also protects your data, like credit card info, if you are using public a <a href="https://infosec.exchange/tags/WiFi" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>WiFi</span></a> (never do that without VPN).</p><p>5) As corollary to 4) you can even sometimes get discounts by using a different location than your own.</p><p>6) Use a <a href="https://infosec.exchange/tags/passwordmanager" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>passwordmanager</span></a> for your credentials such that they can be longer and harder to guess/crack. This also means you don't have to remember (or even know) them by heart.</p><p>7) Setup <a href="https://infosec.exchange/tags/MFA" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>MFA</span></a> for your accounts such that, together with 6), it is harder for adversaries to break in and steal data and/or make automated purchases on your behalf if possible. It is highly advisable using an authenticator app instead of code-by-SMS. For further protection, you can even use <a href="https://infosec.exchange/tags/biometrics" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>biometrics</span></a>, like <a href="https://infosec.exchange/tags/fingerprints" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>fingerprints</span></a> or facial scans. And/or a hardware device supporting <a href="https://infosec.exchange/tags/FIDO2" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>FIDO2</span></a>/#U2F or similar.</p><p>Note that these tips are applicable also when not shopping, and I would encourage them all.</p><p>Stay safe and have an awesome Friday!</p><p><a href="https://infosec.exchange/tags/mastodontips" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>mastodontips</span></a> <a href="https://infosec.exchange/tags/feditips" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>feditips</span></a> <a href="https://infosec.exchange/tags/profiling" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>profiling</span></a> <a href="https://infosec.exchange/tags/personalidentifyinginformation" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>personalidentifyinginformation</span></a> <a href="https://infosec.exchange/tags/pii" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>pii</span></a> <a href="https://infosec.exchange/tags/internetserviceproviders" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>internetserviceproviders</span></a> <a href="https://infosec.exchange/tags/tor" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>tor</span></a> <a href="https://infosec.exchange/tags/multifactorauthentication" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>multifactorauthentication</span></a> <a href="https://infosec.exchange/tags/2fa" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>2fa</span></a> <a href="https://infosec.exchange/tags/twofactorauthentication" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>twofactorauthentication</span></a> <a href="https://infosec.exchange/tags/yubikey" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>yubikey</span></a></p>