Thursday, July 30, 2026

Is public Wi-Fi safe?


Public Wi‑Fi in places like airports, hotels, and coffee shops comes with inherent security risks. However, modern websites use secure transport, shown as https:// in front of the website name in your browser, so the risk is not as high as it once was. The fear surrounding public Wi‑Fi is often driven by misinformation from social media, VPN vendors, and misinformed non‑technical users, and in some cases even technical users. While complete safety is impossible to guarantee, you can greatly improve your online security by practicing good cyber hygiene. Follow as many tips as you can from this blog.
https://blog.selvansoft.com/2025/01/online-safety-tips.html

Although public Wi‑Fi is generally safe, it is best to avoid sensitive transactions such as logging into bank websites, credit card portals, or other financial platforms unless absolutely necessary. If a website does not support HTTPS protocol, avoid it, whether you are on public Wi‑Fi, your home network, or a corporate connection. Pay close attention to browser warnings. If your browser reports that a site is not secure, shows a certificate mismatch, or displays similar alerts, do not proceed. Enable your firewall. All modern operating systems include a built‑in firewall, and you do not need special firewall software. Make sure it is active and set to block all inbound connections. This simple step significantly strengthens your security on any network, public or private.

Last but not least, regardless of what you may have heard, you do not need a VPN. It is not a security tool but a privacy tool. Contrary to popular belief, a VPN does not make you safe. If you are curious, read this blog.


Stay Informed & Safe Online
If you enjoyed this blog, you'll find many more cybersecurity related microblogs at link below. They offer valuable insights to help you stay informed and safe online. Explore them at https://blog.selvansoft.com. Also, checkout free online security tools at https://selvansoft.com/tools/

Thursday, July 23, 2026

Your IP Address Isn’t a Security Risk


The myth
There is a common misconception among many internet users, especially younger generation gamers, that someone knowing their IP address somehow gives them the ability to "hack" them. This myth has been spread by non-technical users, social media, and various news outlets. The fact is that every website you visit knows your IP address because it needs this information to send content (text, images, ads, etc.) so it can be displayed on your browser. This is how the internet works, not just websites. In addition to your IP address, your browser provides much more information to the sites you visit than you may realize. Visit this link (https://myip.selvansoft.com) to see some of the details your browser shares with websites, which may surprise or even shock you, but that is a different topic for another blog.

What is an IP address?
An IP address is just a number. Your internet service provider (ISP) assigns one to your internet connection, and it can change over time. Only your ISP knows that it was assigned to you, and they will not disclose your information unless they receive a request from law enforcement accompanied by a proper court order. Being afraid that someone knows your IP address is like worrying that people saw your car’s license plate while you were driving around the city. Unless you have committed a crime and are fleeing from law enforcement, this is not a problem. Similarly, if you have not done anything unlawful online, you have nothing to worry about if someone claims they have your IP address. They cannot do anything with it.

Realistic but unlikely risks
To be complete, there are a few extremely rare scenarios worth mentioning. If you intentionally expose a vulnerable service or enable UPnP on your router, it is possible for someone to attack your machine. Some gamers enable UPnP to run gaming server without fully understanding the impact. Finally, if someone with a deep understanding of TCP/IP networking is determined to attack you for some unusual reason, they could perform a denial-of-service attack on your router using only your public IP address and knock it offline. While this is technically possible, it is not probable.


Stay Informed and Safe Online
If you enjoyed this blog, you'll find many more cybersecurity related microblogs at link below. They offer valuable insights to help you stay informed and safe online. Explore them at https://blog.selvansoft.com. Also, checkout free online security tools at https://selvansoft.com/tools/

Sunday, July 12, 2026

Smart Home devices & the hidden security loophole



These days, most households have smarthome gadgets. They are designed to make life easy. You plug them in, open an app, and they just work. However, there is a hidden security flaw that appears when your home internet goes down or when your smart home device temporarily loses connection to your Wi‑Fi router for any reason. Recently, I had an internet outage at my home ISP and discovered that all my smart home devices were engaging in risky behavior and expose a security flaw which can be exploited by someone within Wi‑Fi range.

What is this risky behavior?
Smart devices panic when they lose their connection to the internet. They assume the loss of connectivity means the user needs to setup and reconnect the device, which is a flawed assumption to begin with. To make setup easier for the average user, they drop their security barriers completely and broadcast an open, password-less Wi‑Fi network, known as SoftAP (a special access point), into the surrounding area. This behavior is intentional and by design on smart devices from Google and Amazon, but not Apple. That was a surprise to me. Anyone who knows me well knows I dislike the entire Apple ecosystem except for macOS, so it was a pleasant surprise that Apple’s smart devices are more secure.

How to check this behavior?
If you have any Google smart devices in your home such as Google Home, Nest Mini, older Chromecast models, or Amazon devices like Echo or Alexa, you can check this behavior yourself. Turn off the Wi‑Fi router these devices are connected to, wait a few minutes, and then scan for Wi‑Fi access points. You will see open access points appear with names like GoogleHomeXXX.k or NestMini.u, and if you named your devices, they may show up under the names you assigned. For Amazon devices, you might see AMAZON‑xxx or Ring Setup xxx. Google devices usually appear almost instantly, while Amazon devices have a much longer timeout, so you may need to wait, but they will eventually show up. In this specific aspect of the long delay, I would say Amazon devices are safer than Google. See the actual screenshot of this behavior below.

What an attacker can do?
This blog is intended for a general audience, so I will not go into technical details about what an attacker can do. However, I will say that because this exposed access point has no password, anyone sitting in a car outside your house can connect to it. While they may not be able to steal your Wi‑Fi password or spy on your home network, they can still cause harm, such as monitoring your surroundings, hijacking the smart device, recording audio, or querying data. 

What you can do to prevent it?
Unfortunately, there is nothing you can do to avoid this security loophole other than unplugging all these devices immediately after your internet service goes down or your Wi‑Fi signal becomes unreachable, which is not a practical solution. So, if this behavior concerns you, your only real option is to unplug the device and stop using it. 


Stay Informed and Safe Online
If you enjoyed this blog, you'll find many more cybersecurity related microblogs at link below. They offer valuable insights to help you stay informed and safe online. Explore them at https://blog.selvansoft.com. Also, checkout free online security tools at https://selvansoft.com/tools/

Friday, July 10, 2026

Infostealer







What is an infostealer?
Infostealers are lightweight malware that silently extract passwords, session cookies, authentication tokens, autofill data, cryptocurrency wallets, and other sensitive information, then exfiltrate them to an attacker-controlled server. They are highly successful because most infections are self-inflicted, coming from users who intentionally execute fake installers, fake captcha prompts, cracked/pirated software, game mods, or "free" software that provide a pathway for the compromise to execute. Once executed, the malware exfiltrates everything instantly, leaving almost no artifacts for antivirus tools to detect. The reason is that they use native OS components and common tools built into each platform, such as PowerShell on Windows, bash, terminal, and osascript on macOS, along with curl on both platforms to collect and siphon credentials. These actions appear as normal user or system activity to virus/malware scanners both during and after execution. So don't bother wasting time on virus/malware scans, as they will likely find nothing.

What is compromised?
Infostealers mainly focus on two things. The first is exfiltrating session cookies and authenticated tokens from the device they run on. The second is decrypting encrypted databases that contain passwords and other sensitive information from various locations. Both types of information are sent to a remote attacker‑controlled server. Whether you are on macOS or Windows, the first step always succeeds because it requires no user input and happens very quickly, so there is nothing a user can do to stop it. If your device is a Mac, the behavior is different due to macOS native protection. While session cookie exfiltration is successful on macOS, the malware needs the Mac user password for other things like decrypting password databases, crypto wallets, and similar items, so it will prompt you to enter your password. If you do not provide the password, the malware cannot steal your passwords or other sensitive data protected by the password. Aside from this, the infostealer also siphons out crypto wallet keys, TOTP seeds, API keys, SSH keys, and many other items, including installing background services. The last one listed requires doing a clean reinstall of the OS.

How to recover?
The recovery steps depend on the type of device the compromise was executed on. If the device is Windows, unfortunately both session cookies and all passwords, crypto wallet keys, and similar data are exfiltrated successfully. However, if the device is a Mac and you did not provide your password when prompted, you only need to recover from stolen session cookies. On the other hand, if you did provide your Mac password, the compromise is identical to Windows. I have dissected several variants of infostealers and found that architecturally they are identical in how they operate, so the steps below apply to any variant. Follow the steps in the exact order specified to effectively recover from an infostealer compromise.

1. Revoke active sessions: This is the most critical step that most people miss. Unlike what many armchair experts advise on infostealer compromise, you should not waste time trying to find a clean device for this step. Just do it right on the compromised device without disconnecting from the internet as soon as you realize you are a victim of an infostealer. The reason I recommend using the same device is because not all online services provide a way to log out from all devices, and your main goal is to revoke the stolen session cookies, not the session cookies on other devices that are not stolen  and are perfectly fine. If a service does not provide a logout‑from‑all‑devices option, your attacker will keep access to that service for a long time until the stolen session cookie naturally expires, which can take hours, days, or even weeks. So it is very important to use the same compromised device for this step. The actual step to revoke the session is simply logging out from every service on that device, which makes the stolen session cookies useless to the attacker. Do not do anything else on that device. Once you have logged out of all services, turn off the compromised device.
2. Change password: This step must be done using a device that is not compromised, or on your compromised device if you have already reinstalled the OS as described in step 4 below. Login to each of your online accounts and change your password or optionally change to a passphrase. Enable 2FA if not enabled already, preferably an authenticator app or hardware key-based method rather than SMS. Make sure there are no email forwarding rules in your email accounts. Setup a recovery email if there is not one already and finally, regenerate the backup codes. 
3. Backup: Backup your documents, photos, and other data. Infostealers cannot damage them and do not even target that type of content. They are perfectly fine to backup and restore after the next step. You only need to worry about your primary drive where the operating system resides. Your external drives are fine because infostealers do not interact with them as far as I know.
4. Reinstall OS: If your compromised device is a PC, create a bootable media. It can be a USB stick or secondary SSD with an installable OS obtained directly from Microsoft. Now go to your compromised device BIOS settings and enable booting from the alternate drive, the USB or secondary SSD, and choose to do a complete wipe and reinstall of Windows on your primary SSD or hard drive. For a Mac, boot into recovery mode, choose Disk Utility, and select the top-level internal disk to erase. Follow that by selecting reinstall macOS. If you are unsure how to do this, there are plenty of tutorials on YouTube you can follow to accomplish this step. 
5. Browser Extensions: This would be a good time to review all your browser extensions, delete the ones you do not use, and validate the ones you use regularly. Most people have no idea how much access they grant to browser extensions or how dangerous they can be. I highly recommend reading this blog that explains the details. https://blog.selvansoft.com/2026/05/browser-extensions.html 
6. Safety Tips: Follow as many online safety tips as possible from the blog link below. The more of them you follow, the stronger your online safety becomes. https://blog.selvansoft.com/2025/01/online-safety-tips.html  
7. Monitor: Monitor your credit cards, online banking, and similar financial accounts. Optionally, I recommend freezing your credit following this guide: https://blog.selvansoft.com/2023/05/howto-credit-freeze.html 
8. Advice: Stay away from installing stuff from random websites. You can assume all free/pirated software has some form of malware. There is no such thing as a safe website to download free stuff. It just does not exist, regardless of what you heard or what your buddy online told you about a software from a site being safe.


Stay Informed and Safe Online
If you enjoyed this blog, you'll find many more cybersecurity related microblogs at link below. They offer valuable insights to help you stay informed and safe online. Explore them at https://blog.selvansoft.com. Also, checkout free online security tools at https://selvansoft.com/tools/