Showing posts with label social. Show all posts
Showing posts with label social. Show all posts

Tuesday, December 12, 2017

Ho-Ho-Holiday Spams and Scams

   It's that time of year again folks.  And whatever holiday you may, or may not, celebrate... there's something we're all likely to see.  It's not presents, though maybe there are some for you.  It's not snow, though we're already seeing that here in the upper midwest US.

   It's malware and holiday scams!

   Unfortunately, it happens every year.  Sometimes it's malicious attachments.  Sometimes it's links to malware to download or phishing sites with forms ready to collect your personal and financial information.

   Here is my 2017 edition of my Top 10 Tips To Avoid Holiday Spams and Scams...

Tuesday, October 24, 2017

Internet Safety for our Parents

   It's US Cyber Security Month and the key themes I've been discussing here for years are very bit as relevant today.  In honor of Cyber Security Month I'm re-running a post from 2016.  The more things change, the more they stay the same.  Happy Cyber Security Month!


   I've written about Internet safety for families, kids, teens and I've even spoken on safety for pre-schoolers.  But it's important to think about online safety for parents as well.

   That's true both for parents of young children was well seniors with grown children.  The safety challenges for seniors are similar but there are some differences.  They may not be as familiar with technology and, according to the FBI:
  • they are often financially secure and/or have good credit
  • they may be more trusting and they don't think they'd be a target
   This article by the AARP lists some common scams against seniors including some we've discussed like fake Microsoft support calls or IRS-related tax fraud.

   What got me thinking about this topic was a great article entitled "10 Ways to Help Our Parents With Online Security".  The article touches on a number of themes we've discussed in the past.  I'll list the 10 items with links back to some past editions of this blog - typically they:
  1. don't think they have anything worth stealing
  2. have bad password habits - just like most people
  3. are confused by 2-factor authentication - something we all should use
  4. leave mobile devices unattended and without security measures
  5. don't recognize phishing emails
  6. don't understand social media and how it can be used in scams
  7. share too much information
  8. can be manipulated by online media
  9. place too much trust in an anti-virus product
  10. don't understand how sophisticated scams and attacks can be
   In what ways can you help your parents stay safe online?

Tuesday, August 8, 2017

You Gotta Be You

   I just received an update from the Social Security Administration.  Yes, it was real! :-)  It was a reminder to log in to the SSA website to check my information online.  That also made me think about advice I've written about in the past... it's critical that you connect and establish your presence on critical government websites before someone else can create an account in your name.

   Here's a rewind of a 2016 post with all the information...



   I recently received a letter from the SSA (Social Security Administration).  It provided instructions for me to finish setting up my online account.  As I've written in the past you can, and need to, create personal accounts on the SSA and IRS websites.  The key issue is that you need to reserve and establish your identity on these critical government websites before someone else does it for you!  This is ID Fraud is still a big issue.

   These accounts are straightforward to set up.  One thing you will need to do is go through an Identity Proofing process.  That process asks you for some personal information that, in theory, only you should know.  I list info about the irs.gov account creation process in this post.

   Here is some info from the ssa.gov website:
You can create a my Social Security account if you’re age 18 or older, have a Social Security number, a valid email, a U.S. mailing address, and a cell phone that can receive text messages. You’ll need to provide some personal information to confirm your identity; you’ll be asked to choose a username and password; and then provide your cell phone number. You’ll then receive a security code via text that you will be required to enter when you first create an account. We’ll send your cell phone a new security code each time you log in with your username and password. The security code is part of our enhanced security feature to protect your personal information. Keep in mind that your cell phone provider's text message and data rates may apply.
   Now SSA has increased their security by offering two-factor authentication (2FA) on their site.  We've written about 2FA a number of times in the past.  SSA had said this was coming and now it's available.

   I highly recommend that you create accounts on these sites and use 2FA where available.  Here are the instructions for SSA.  Here for the IRS.  You can enable 2-factor authentication on the SSA site when you create your account.  Here's a link to a previous post looking at other sites where 2FA is available.  Double up wherever you can!

Tuesday, April 11, 2017

Cyberbullying and the New Math

   According to Cyberbullying Research Center, the National Crime Victimization Survey (NCVS) is a large-scale data collection effort led by the U.S. Census Bureau and the Bureau of Justice Statistics.  This study has been going on since 1973.  In 1989 they added supplemental questions focused on school-related incidents, and stepped this up to a more in-depth biennial survey in 2005.

   Cyberbullying is still a major issue.  It's been over 4 years since I've written on this subject.  While there is perhaps more visibility, the basic problems haven't changed.

  Based on the above benchmark, at first glance, bullying appears to be trending down over the past decade.


   While there have been some high-profile cases over the years, this is a real, current and ongoing issue.

Tuesday, October 18, 2016

Internet Safety for Parents

   I've written about Internet safety for families, kids, teens and I've even spoken on safety for pre-schoolers.  But it's important to think about online safety for parents as well.

   That's true both for parents of young children was well seniors with grown children.  The safety challenges for seniors are similar but there are some differences.  They may not be as familiar with technology and, according to the FBI:

  • they are often financially secure and/or have good credit
  • they may be more trusting and they don't think they'd be a target
   This article by the AARP lists some common scams against seniors including some we've discussed like fake Microsoft support calls or IRS-related tax fraud.

   What got me thinking about this topic was a great article entitled "10 Ways to Help Our Parents With Online Security".  The article touches on a number of themes we've discussed in the past.  I'll list the 10 items with links back to some past editions of this blog - typically they:
  1. don't think they have anything worth stealing
  2. have bad password habits - just like most people
  3. are confused by 2-factor authentication - something we all should use
  4. leave mobile devices unattended and without security measures
  5. don't recognize phishing emails
  6. don't understand social media and how it can be used in scams
  7. share too much information
  8. can be manipulated by online media
  9. place too much trust in an anti-virus product
  10. don't understand how sophisticated scams and attacks can be
   In what ways can you help your parents stay safe online?

Tuesday, September 6, 2016

Call Me

  I recently received some awesome news via email.  And it was totally unexpected.  Check it out:


   Now I can retire in style!  :-)

   Needless to say, this is a phishing email.  We've talked about phishing many times in the past.  And we keep talking about it.

   So why does phishing still work?  There are two primary reasons:
  1. No cost/low barrier to entry.  It is effectively free to send out potentially millions of phishing or spam emails.  Attackers can easily relay email through open mail relay servers, but there are other ways to send spam and phishing emails.  Open mail relays are systems that send email but don't require any kind of identification.  Here's some more technical info on open relays.
  2. Exploiting the human factor.  People are busy and we all receive too much email.  It's not always easy to take the time to figure out if an email is OK or not.  Attackers leverage this by sending plausible-looking email, though there are plenty of poorly-created messages as well (like the one above that I received).
   As I mentioned in a previous column, rather than looking examining an email for evidence of phishing, we can approach all email as if it's hostile and then look for indications that it's OK.

   If you'd like to have some fun... try these spot the phishing online quizzes!

   I won't be contacting the "friend" to sent me the above email.  And I did not win.

   Have you seen any interesting phishing emails you'd like to share?

Tuesday, August 9, 2016

News you Need Now (NNN)

    I recently received a letter from the SSA (Social Security Administration).  It provided instructions for me to finish setting up my online account.  As I've written in the past you can, and need to, create personal accounts on the SSA and IRS websites.  The key issue is that you need to reserve and establish your identity on these critical government websites before someone else does it for you!  This is ID Fraud is still a big issue.

   These accounts are straightforward to set up.  One thing you will need to do is go through an Identity Proofing process.  That process asks you for some personal information that, in theory, only you should know.  I list info about the irs.gov account creation process in this post.

   Here is some info from the ssa.gov website:
You can create a my Social Security account if you’re age 18 or older, have a Social Security number, a valid email, a U.S. mailing address, and a cell phone that can receive text messages. You’ll need to provide some personal information to confirm your identity; you’ll be asked to choose a username and password; and then provide your cell phone number. You’ll then receive a security code via text that you will be required to enter when you first create an account. We’ll send your cell phone a new security code each time you log in with your username and password. The security code is part of our enhanced security feature to protect your personal information. Keep in mind that your cell phone provider's text message and data rates may apply.
   Now SSA has increased their security by offering two-factor authentication (2FA) on their site.  We've written about 2FA a number of times in the past.  SSA had said this was coming and now it's available.

   I highly recommend that you create accounts on these sites and use 2FA where available.  Here are the instructions for SSA.  Here for the IRS.  You can enable 2-factor authentication on the SSA site when you create your account.  Here's a link to a previous post looking at other sites where 2FA is available.  Double up wherever you can!

Monday, October 12, 2015

Keep Celebrating! - Mobile and Social

   We continue our celebration of US Cyber Security Awareness month!  This partnership between Homeland Security, NCSA (National Cyber Security Alliance) and the MS-ISAC (Multi-State Information Sharing and Analysis Center) is an opportunity to recognize the importance of information security.  It started in 2003 as a way to build awareness for online security and privacy and to encourage individuals, business and government.

   This is another of my weekly posts connected with the weekly themes put together by DHS.  This week the theme is staying protected while always connected.  That rhymes!

   We are always connected!  According to the Pew Research Center, in 2015 90% of american adults own a cell phone, 64% own a smart phone.  And one of the major uses for smart phones is... not calls but social media!  How do we stay safe online and on the move?

Tuesday, April 28, 2015

I Know Where Your Cat Lives!

   Today's post brings together two of the most important, popular and topics online - security and privacy of your information on the Internet and... Cats!

   We know why the first topic is important.  I've written plenty about data breaches, keeping yourself safe online and how to decrease your exposure to identity fraud.  But cats?  Interestingly, the Internet has had a long fascination with cats.  And memes are everywhere starting with the early days of Lolcats and Keyboard Cat.  Disclaimer - I am not a cat person... I don't own any and am not a fan.  But I do like a good meme!

  Regardless of your pet of choice, we do care about our pets and they are often treated like members of the families.  And that includes... pictures.  If you do a search on cat pictures or pet pictures, you'll see plenty.  If you look on people's social network profiles, Facebook, Instagram, Pinterest, etc., there will be pet pictures all over the place.  You can even find them on "professional" sites like LinkedIn.

   Looping back to security and privacy... it's hard enough to keep your data safe when you're deciding what to share.  Many sites deal with the normal stuff - name, A/S/L, credit card numbers, and more.  You can enter this info to a site, or not.  But it's much harder when you don't realize that you are sharing data.  Or, put another way, how do you know when you're sharing more than you think you are.  There is hidden data and data sharing happening on the net everywhere.  For example, when you connect to a website, that connection creates a log that includes things like: your IP address, your browser type, your computer/phone/tablet operating system and other info.  The site may put a "tracking cookie" on your machine to help customize your experience while gathering more data.

   Then there's metadata.  This is data about data.  For example, when you take a picture with a digital camera or your phone, there is all kinds of additional data "attached" to that photo including: location, IP address, and timestamp.  There is also a great deal of extra visual information, other than the core subject in the photo including: views of your house, entrances, other people and surroundings.

   There is a fun and interesting website called "I Know Where Your Cat Lives".  They simply connect to photo sharing and social sites, grab cat photos, mine the metadata, connect the photo to a map, and create stats and charts.  Oh yes, and display cat photos!

   The lesson here is to pay attention to your digital surrounding.  When you take a picture, know what else is in that picture.  When upload a picture to a site, think about what data is going with that picture.  Most photo software gives you the ability to edit and alter most of the metadata.  Are you automatically uploading photos?

Tuesday, December 2, 2014

The 4 R's of ID Fraud (part 2)

   As promised, in this post we'll wrap up the series about ID Fraud.  Check here if you'd like to see the first 3 parts of this series, and the first half of this post.

   So far we've focused on what ID Fraud is, and in the third installment, the steps you should take now if you are a victim.  As we've discussed, having the information for one of your credit cards grabbed in an attack such as we saw on Target or Home Depot doesn't automatically mean you will have other ID Fraud related problems.

   But we should all take steps to reduce our exposure and the odds that our ID and financial information will be fraudulently used... or at least increase the odds that we'll notice any problems quickly.

   We'll continue with the 4 R's: Review, Reduce, Record, Report. (unlike the 5 D's of dodge ball! :-)

Reduce - the amount of information you give out online.
  • Use care when emailing personal information.  Don't unless you need to.  Provide a minimum amount of information. Use encrypted email if it's available.
  • Choose passwords and hints that are not based on personal information.
  • Don't "click here to unsubscribe" from a spam or unwanted message - it just let's them know you exist.
  • Shop online with reputable or known vendors.
  • Delete doesn't really delete.
  • Use malware protection on your home computers and devices.
  • And a bonus tip for online - watch out for Phishing messages.  That's a big topic that I've covered in the past, and probably will revisit as scammer techniques evolve.

Tuesday, November 18, 2014

The 4 R's of ID Fraud (part 1)

   As part of our celebration of US Cyber Security Awareness Month, we've been talking about ID Fraud.  Check here if you'd like to see the first 3 parts of this series.

   So far we've focused on what ID Fraud is, and in the third installment, the steps you should take now if you are a victim.  As we've discussed, having the information for one of your credit cards grabbed in an attack such as we saw on Target or Home Depot doesn't automatically mean you will have other ID Fraud related problems.

   But we should all take steps to reduce our exposure and the odds that our ID and financial information will be fraudulently used... or at least increase the odds that we'll notice any problems quickly.

   Our theme for today is the 4 R's: Review, Reduce, Record, Report (just like you learned when you were a kid! :-)

[as I was writing this, the post became really long so I've broken it up into 2 parts]

Review - your credit report.  You are entitled to 1 free report from each of the big 3 credit reporting agencies each year.  So, spread it out and get 1 every 4 months.  The US FTC endorsed site to get these reports is www.annualcreditreport.com.  You can also put a fraud alert on your account as we discussed last time.
   You're also entitled to a free copy of your credit report if you:

Tuesday, November 4, 2014

Got ID Fraud? - Stop, Drop and Roll

   OK, maybe not stop, drop and roll (I'll always remember that fire safety phrase from my childhood), but take action!

   Cyber Security Awareness Month is now over, and I haven't finished covering the ID Fraud topic I started at the beginning of Oct.  I did get distracted on some other issues.  Besides, we can't confine our celebrating to only one month!

   I covered the basics of ID Fraud in these posts.  But if you have been a victim, and particularly if you recently discovered you are victim, you need to take action... and time matters.

   Here are the four key things you need to do, right now, if you have recently been the victim of ID Fraud in the US:
  1. Contact one of the three major Credit Bureaus (we'll leave a discussion of the "4th credit bureau" for another time).
  2. Close the suspect accounts.
  3. File a police report.
  4. File a report with the FTC by phone and in writing.
   I'll provide more detail and add a few more steps below.

   One additional thing you must do throughout this process is to keep a record of everything you do.  This includes: noting date/time of phone calls; copies of letters; printout any web forms, and; keep a chronological log of your overall progress.

   The FTC website has the specifics here.

Contact one of the Credit Bureaus and put a fraud alert on your account.
   This is the first thing to do.  You can put what is called an initial fraud alert on your credit record.  This initial alert will last 90 days.  It should not cost anything to place this alert.  The bureau you call should contact the other two credit bureaus, but it doesn't hurt to verify this with them.
   The fraud alert basically requires extra effort to authenticate any requests for new credit.  This typically means that the credit issuer needs to contact you before issuing credit.  This should make it tougher for a fraudster to open credit in your name.  That's good!  The downside is that it also might make it more difficult for you to open new credit.
   After the initial 90 day period, you can renew the alert each 90 days.  This may cost a nominal fee depending upon what state you live in (US).
   (we'll talk about other measures like credit monitoring services in a future post)

Close the affected accounts.
   Contact the credit issuer and close any accounts you know were affected.  If your purse or wallet was stolen, then close all the accounts for the cards you were carrying.
   If you're not sure if a particular account was affected, you're probably best off closing it as well.

File a police report.
   Contact your local police and file a report.  Except in rare cases where there was additional theft (for example, if your identifying documents and credit cards were stolen as part of a home break-in), the police will not actually take any action.  You're not contacting the police so they will investigate the problem.  You are establishing documentation and proof of the event.  In the future, you may need to prove that you took action and when you took action.  The police report accomplishes this.  Get a copy of that report.

File a complaint with the FTC (US Federal Trade Commission).
   Again, this is part of establishing your documentation trail.  The FTC has a great website for information that I'll link below.  The specific instructions for filing the FTC complaint is here.  Note that they suggest filing with the FTC before filing the police report.  That is not critical, and you need to do both.  You can complete the FTC form online so that might be easier and it's available 24x7.

   Those are the first steps to take.  But there are more.  Here are a few more steps to take:

Who else to notify?
   You may want to notify your other banks and creditors both to find out if there has been any unusual activity (banks and card issuers are usually pretty good at finding anomalous activity before you do) and so they can flag your accounts.  Consider notifying anyone who bills you monthly for services including utilities and insurance providers.

   If you think your US social security number has been compromised, you should contact the Social Security Administration.

   You can notify your state driver and vehicle services department in case someone tries to get a driver's license in your name.

Online defense.
   If this problem started online, perhaps through an information breach, you should change your passwords and consider using multi-factor authentication as I've covered in the past.

   There are more complete details on these steps on the FTC website here.

   Even under the best of circumstances, the process of reporting, documenting and repairing ID Fraud is a major pain.  In our next installment I'll talk about things you can do to help prevent you from becoming a victim, or in those circumstances where this is out of your control, how to increase the odds of early detection and minimize the impact.

   Have you had experience with any of the steps I list above?  Do you have any advice on additional steps to take?

Tuesday, September 23, 2014

"Who Am I?" (or, Who Was I?)

   I like the story of Les Mis.  I definitely like the musical.  I was not wild about the movies.  The book is definitely a good, and very long, read (or listen!).

   At it's core, Les Mis is a story about Identity Fraud!  It's the story of a man, seemingly wrongly convicted, who operates under a false identity in order to be able to live his life.  It's a common literary theme, used in stories like Martin Guirre, The Count of Monte Cristo and Matchstick Men.  In "olden times", Identity Fraud penalties were very serious. Today... not as much.  Last time we started a discussion of Identity Fraud - we'll continue our discussion of this topic.


   Breaches of online merchant websites and databases get a lot of media attention.  But there are many ways ID fraud is committed including:
  • Shoulder Surfing - this means someone looking over your shoulder, for example when you enter your PIN at an ATM
  • Dumpster Diving - it's amazing what people throw away
  • Mailbox theft - checks, financial statements and other sensitive documents get stolen from mailboxes
  • Stolen purse, wallet, laptop, tablet, phone - these all contain plenty of personal information
  • Social Engineering - be careful about what information you give out about yourself
  • Phishing - email or phone - con artists will call or email pretending to be your bank, law enforcement or other authority and ask you for information.
  • Social media - do you really know who your "friends" are?... there are all kinds of requests and information gathering schemes
  • Copy-cat websites - it's pretty easy for scam artists to create a fake site that looks just like your bank's website, perhaps with a misspelled URL like nationa1bank.com (that's a one instead of an L), and then collect the info you enter.
  • By known or unknown thieves! - some ID thieves know their victims.

   So many choices!

Tuesday, December 3, 2013

Is Your "Friend", Your Friend?

   An interesting topic came up the other day.  The question was whether to accept random social media
requests.  Does your "friend" need to be your friend?

   Your answer to that question might vary based on the social network and how you use that social network.

   There's also an important Security Awareness angle here.  Social networks can be a vector for malicious links, phishing attempts, malware and scams.  These malicious techniques often work better when the link/attachment/request comes from a "friend", rather than via a random email or connection.

Tuesday, November 26, 2013

Internet Safety... The Song Remains the Same

   As seems to often be the case in the fall, I'm doing a number of Internet Safety talks lately.  Maybe it's the tie-in with October US Cybersecurity month, and I did some posts celebrating that.  Maybe it's that fall makes us think about back to school (though maybe safety should be a "hotter" topic in the summer when kids have more free time!).

   I've been presenting to groups about Internet Safety and related topics for over 12 years.  I've got a few events coming up at work, so I'm updating my material.  I've got a number of talks on these "consumer" issues.  You can see my slides on my slideshare page.  I regularly update my material.  But what's really amazing to me is that the core, key messages have substantially remained the same.


   For example, I recently did a presentation and blog post on bullying.  The biggest change in online bullying in the past few years has been the news media attention.  But what happens, how it happens and options for victims, unfortunately, hasn't changed much.

   As I talk with people about these issues, and research and update my presentation material, I think there are 3 main areas in which things have substantially changed.
  1. The rise and expansion of social media.  In the early 2000's, we were talking about things like email, Chat like AOL Instant Messenger (AIM) and web surfing.  Xanga.com was around, but MySpace and Facebook weren't even invented until around 2003!  And, needless to say, there's been an explosion of social media sites with the latest trends favoring pictures and video.  While kids had the ability to share too much information since the beginning, social media sites really drove the norms.
  2. Technology.  In particular... mobile technology.  I used to recommend that families keep their computer (singular) in a common place like the family room or kitchen so kids' use could be seen.  While that is still good advice, most families have more than one computer.  And most teens, and many younger kids, carry a powerful computer with them wherever they go... their smartphone.  While we still have options available for monitoring, and good communication is key, portable devices are really a game-changer.
  3. Kids get it.  During my Internet Safety talks of the mid-2000's, we used to play a little game.  It was a live demo in which I would bring up a social media site, typically MySpace.  The game was to see how few clicks it would take us to get to some inappropriate content (like kids/teens sharing too much personal information or posting pictures parents would wish they didn't).  When I first started doing this demo it would only take a few clicks.  Then, by around 2008, it took more.  Then I would just save a few URLs of TMI pages.  Then I gave up the game altogether!  It's not that we can't still find inappropriate content, or examples of kids sharing far more than parents might want.  But kids are doing a much better job of protecting their information online.  Of course, kids, teens and young adults - actually digital natives in general - do have different ideas, definition and expectations of privacy compared to their parents!
    One final thought... another thing that has changed is that the oldest digital natives - people who do not know of a time without pervasive digital media and technology - are now having their own kids and showing up at Internet Safety talks!  But some things don't change and their kids still know more about technology!


   What surprises you about changes in our online world over the past decade?  What do you think has changed, or has not changed?

Tuesday, November 19, 2013

It's That Time of Year - Holiday Spams and Scams

   It's that time of year again folks.  And whatever holiday you may, or may not, celebrate... there's something we're all likely to see.  It's not presents, though maybe there are some for you.  It's not snow, though we'll see that soon enough here in the upper midwest US.  It's malware and holiday scams!

   Unfortunately, it happens every year.  Sometimes it's malicious attachments.  Sometimes it's links to malware to download or phishing sites with forms ready to collect your personal and financial information.

   Here is my 2013 edition of my Top 10 Tips To Avoid Holiday Spams and Scams...

Tuesday, November 5, 2013

Cyberbullying - Improvements or More Problems?

   In addition to Cyber Security Awareness Month, October was also Cyberbullying Awareness Month.  There were a number of online campaigns to raise awareness on the topic including some high-profile pages on Facebook and Cartoon Network.

   This is an important topic and needs our attention.  I have given many presentations over the years on Internet Safety topics.  This past weekend my wife, a clinical psychologist, and I partnered on a presentation on Bullying and Cyberbullying at our local school district parent fair.  Here are the slides.

   Unfortunately, bullying has been around as long as there have been people.  The internet, social networks and mobile devices supplement have turned "old school" bullying into a 24x7 assault.

Tuesday, October 22, 2013

Online Self Defense - Don't Click!

   This week I'm presenting at the Cyber Security Summit in Minneapolis.  I hope to see you there!

   It's Cyber Security Month!  And the more things change, the more they stay the same.  The key advice for online self-defense I've given in the past is just as true now.  So to help us all celebrate, I'm "re-featuring" a few articles I've run in the past.


   This is the third post in my series on Online Self-Defense.  We've covered malware and passwords, two key issues effecting your online privacy and security.  If you've tried the simple tips I gave on those two subjects then you are now safer than most web surfers.

   Now, to keep you and your computer safe... don't click on that link!

Tuesday, September 3, 2013

Putting the Face in Facebook

   As can happen in a month whose name contains an "a", "e" or "u" :-), Facebook has once again made
changes to its privacy policy and practices.  And, as always we all have two choices: accept the changes (and adjust our settings and practices appropriately), or; leave Facebook.

   Of course most people won't leave Facebook, and if anything they will add more users than those that leave.

   As I look through the changes (see Facebook's notice here with links to the details), I think there are three things to know...

Tuesday, July 9, 2013

The More Things Change...

   As the saying goes... the more they stay the same.  In our ever-changing world of technology and security, it always amazes me how things often don't change!

   Let me clarify... there's always a totally new technology, programming language or social network to learn. Of course, computing power has changed drastically.  Many of the techniques used by attackers to gain improper access to our information have changed.

   Though many have not.  And the advice we give to consumers and business users to protect themselves has not changed!   Consider...