This guideline is based on our own experience and I hope that it will help you if you are new to e-gold. I do not wish to go over the same preventive measures like having an updated virus scanner/patch for your OS as well as having common sense of not opening link from unknown strangers and stuff like that. For details at:
Security Recommendations
What I wish to highlight here is something that many e-gold users are
not aware of, as a result of having their fund stolen or account hacked.
Do not ever Allow Automation Access from any IP in your e-gold account setting if you do not know what you are doing.
It is very important not to allow automation access from any IP if you are using a customized script with e-gold automation interface within your business or any activity you are engaging in. Many people do this out of convenience especially when they are using a dynamic IP address.
Having automation access from any IP enabled allows other people to make spend from your account without you knowing it. This is done through the use of a bruteforce script. Basically, what a bruteforce script does is to try out different combination of password based on a dictionary or rather any combination from scratch e.g. 0001, 0002, 0003 ... ... AAAA, AAAB, AAAC, so on and so forth.
The bruteforce script is useful because
no turing number verification is required when someone is trying to login to an e-gold account. There is also no way to know that someone is trying to bruteforce your account if you allow automation access from any IP. And when you already know it, it is often too late.
We advise you to only allow automation access from a specific IP or IP range if you need to use the e-gold automation interface. So that you will receive a notification e-mail from e-gold even when someone is trying to bruteforce your account.
Do not access your e-gold account through a public/open proxy other than the one assigned by your own ISP.
By using a public/open proxy to access your e-gold account, you risk having your e-gold number and password recorded by the proxy provider. Cookie information stored on the proxy server will also pose a serious threat to the security of your e-gold account.
Your e-gold account will definitely be compromised if the proxy owner is dishonest and greedy because whatever you do (including the header information) will go through the proxy server before reaching the e-gold server.
You will also not be able to delete the cache/cookie information stored on the proxy server by yourself.
Try not to access your e-gold account from a public computer or even friend's computer.
It is not even safe to do so even if you were to clear the cache/cookie information on the computer after use.
Why is that so? Imagine that someone were to install a key logger or packet sniffer without you knowing it. Whatever you type on this computer will be saved for further analysis by the owner of the key logger if he/she has any ill intentions such as stealing fund from your account or hacking your e-mail or any other accounts logged by the key logger.
IP header/packet information that contain all your internet activities can also be recorded to aid in these malicious acts.
Do not click on any link from e-mail that claims to be from e-gold.
The link may lead you to a phishing site where you may be tricked into believing that it is an actual e-gold website. Your account number and password will be recorded by the fake site if you are not careful and have entered these information. You will also see your e-gold account being emptied out the very next minute.
Other than the above possibility, you may land on a malicious site where your computer can be infected with trojans/virus without your knowledge if you do not have a good scanner. All your sensitive information (cache/cookies) can also be stolen.
Please note that E-gold will not ask you to visit any link or enter any password anywhere at all times.
Therefore, be extra careful when you receive e-mail like this.
.