Tag: fraud

  • Notes of Hybrid meeting – 13th October 2022

    The meeting opened with a welcome to new members – Ian, Kate, Sue, Fred and Marion Poyner, and to Mike Payne making his first meeting (if my memory serves me well). We had David Hughes, Paul, Renee and Ralph join us on Zoom. John, Jonathan, Jim, Don, Stella and Fred were with us as well. Tony, Marilyn Barrack, Linda, Mike Chapple, Christine, Sianed, Margaret, Jeanette, Seifi and Sally presented their apologies.

    I started by explaining that we had been overwhelmed by the interest in the group shown at the “Meet the Groups” meeting the previous Tuesday where 20 members, or prospective u3a members, had expressed an interest in attending group meetings. I felt duty bound to admit 12 members as we had no Waiting List policy in place at that time – this has now been introduced and some of the prospective members of have now been placed on that list. With a membership approaching 40, I felt it was necessary to review how we operated. I thank Pat, Marilyn Guest, Owen Parry and Phil Edwards for stepping down as active members – they do however continue to have the ability to use this website, the Signal group and have access to the Flipboard magazine.

    I reiterated that we don’t attempt to resolve members’ hardware issues – other than perhaps problems with printers, or connectivity issues, eg routers. We do recommend using “We will fix your PC” – Neil has done a wonderful job in supporting and helping us by resolving problems for several years now. It might be worth mentioning Cardiff u3a and the Computer Group should you chose to use his services. I also repeated what I’d said to many at the “Meet the Groups” session … namely we are not a training group. We cannot train you how to use Word, Excel, or whatever. We DO however focus on internet issues, applications and anything that is not machine/device dependent. In that way all meetings are usually accessible to all users who have access to a web browser (Chrome, Firefox, Brave, Edge, Safari, Opera, etc.).

    We are fortunate in that we have established, quite quickly, a workable hybrid (ie Zoom) meeting format. This is in no small way down to the excellent technical support offered by Craig at Sight Life, and the overall welcome and excellent facilities they are offering us.

    I am proposing, and circulated a pro-forma to start the ball rolling, to allocate members to either a 2nd or 4th Thursday preference group, with them being able to attend via Zoom on the alternative Thursday. Hopefully, this will keep the in-person group a manageable size whilst we still struggle with Covid-related issues. Some members who are essential contributors to the group will be able to attend in-person all meetings, if they are able to.

    To that end, I gratefully acknowledge the assistance of Sianed who will facilitate the “issues round the table/screen” part of the meeting; Don who has taken on the meeting attendance/subs task; Jonathan who will help me by screening Windows/PC news and issues; Paul (via Zoom currently) who will do the same for Android matters; and Jim – our official photographer and my adviser, proof reader and frequent contributor to the website.

    We’ll just need to see how this plays out. Hopefully, in time I will be able to remove restrictions on in-person attendance, but please be supportive of the difficult situation we have put ourselves in, by virtue of meeting a need. Perhaps a second group is the answer, but that would mean finding another facilitator.

    Starting the meeting proper, I explained to new members how we usually operated, the way the Thought grazing website operates, the benefits of the Signal group and the existence of the Flipboard magazine that I encourage all members to browse occasionally, and contribute to if they so wish (after creating an account).

    I then launched into a description of the theft and fraudulent event that I’d mentioned at the previous meeting and had written up as a blogpost earlier that day. I won’t repeat what I’ve written, I’ll just repeat the warning and the recommended action you should take – don’t keep your credit/debit cards near to your phone, and seriously consider activating a SIM-lock to lock your SIM to your phone – so that it can’t be taken out and put in another phone on which a banking app can be downloaded and possibly a password obtained from your bank. The case in point here was Santander.

    The issue of reporting scams to ActionFraud was mentioned, and the action you might wish to take if you receive a phishing phonecall is described here. Otherwise, I recommend you subscribe to the free Which? email scam alert service, and to look at other advice on the Which? website, and the Citizens Advice website.

    Turning to members issues …

    Fred reported the latest fortunately unbelievable text scam he’d received. I think as group members we’re getting much, much better at identifying these – the parcel that couldn’t be delivered, the transaction that know we couldn’t have made, the offer that seems to be too good to be true, the offer to help with obtaining a refund/grant/subsidy/entitlement which wouldn’t come via a text message. Just stay alert everyone, and remember … if it’s really important, the organisation will contact you again and not usually by text!

    Paul reported issues with TalkTalk and their new website. Sue had a similar issue (see below). it is disappointing that he may need to change the settings on his talktalk.net email account to get it to re-direct (as it had done previously) to his gmail account where he aggregates all his emails.

    Sue had a similar problem. The old TalkTalk website from which she’d accessed (occasionally) her email had stopped working. She hadn’t received any emails since before July. The solution hopefully, would have been to “upgrade” to the new website, but unfortunately as she’d moved to Sky (??) it was unlikely that she’d be receiving any emails from her talktalk.net email address anymore. This highlights an issue we’ve discussed before. It is advisable to move to an email provider that’s not connected to your Internet Service Provider (ISP). I used Google (and Gmail) for many years and have never used VirginMedia – my current ISP – to provide an email service for me. I migrated all my old BT email messages away from that service to avoid paying an annual charge for retaining the account after I stopped using BTinternet. I now aggregate most of my emails on iCloud – Apple’s service, as it is EXTREMELY unlikely that I’ll ever move away from them, but I retain my Google email accounts … just-in-case. Ian and Sue both used aol and asked whether this was a viable service. It was confirmed that now aol was owned by Verizon, it’s future was probably very secure.

    John wondered whether the increase in “promotional” messages he was receiving was connected to his use of his Kindle advice. You can set your communications preferences from Amazon here.

    Kate raised an issue of connecting to iCloud to delete “stuff”. I described (and demonstrated) how to login to iCloud.com using your AppleID and password.

    Ian asked the question on whether stuff deleted on iCloud was also deleted automatically on a device. I had to admit I wasn’t sure. I’d written a blogpost on the situation with Google Drive (particularly for Google Photos), but had to check-up on the situation with Apple, which I reported back to him here. I told him that I needed to do further tests to satisfy my own curiosity. I can confirm that deleting a file on iCloud Drive from the Files app on an iPhone will delete it from icloud.com and your iCloud drive on MacOS as well – which is what you would expect should happen. He also asked (after the meeting) whether his daughter could change the account name/details on an O2 account, since she was now in a position to pay for it herself. The issue being she would want to keep the phone number. I had to admit that I didn’t know, and the O2 website was less than encouraging for what seemed to be a reasonable use case, so I recommended visiting the O2 shop in St David’s Centre (I believe). I also suggested looking at GiffGaff (operating over the O2 network and owned by the parent company of O2 – Telefónica UK) as a good pay-as-you-go (PAYG) alternative. She might be able to port the number to that network (or any other network) after obtaining a PAC or STAC code.

    Here ends nearly the most rapid Notes I’ve ever written up – have to impress the new members.

  • Immobilise App

    Immobilise is a free register of home items. It is available to the police if you are burgled.

    Immobilise System set up 2003

    1. Largest free system to register household property.
    2. Used for public and businesses.
    3. Police online checking service used 1000 s of times a day.
    4. Returns property to owners.
    5. Recommended by E-Bay to reduce fraud.
    6. Funded by the sale of marker pens and stickers.
    7. Displayed stickers mean you are less likely to be burgled.

    Benefits of Registration.

    1. Immobilise helps police identify the owners of recovered property.
    2. Property updates immediately available to the Police nationally.
    3. Combats the sale of stolen items in the second hand trade.
    4. Simplifies insurance claims and police reports.

  • Using Paypal instead of Credit Cards

    This was a question that was raised during the General Meeting discussions. PayPal has a Buyer Protection and Fraud Protection policy which for small transactions (ie <£100), and for transactions with companies/individuals you regularly do business with, is probably sufficient protection.

    For large value items (ie >£100) and up to £30,000 you might prefer to choose using your credit card because of the Section 75 protection you get.

  • Covid-19 Tracing app

    What is Contact Tracing, and how does an app help?

    This video from The Guardian is an excellent review of how Contact Tracing works in both a traditional and technology-enable world. You should watch it.

    Contact Tracing Infographic

    An Infographic that explains how Contact Tracing works

    Approaches to creating a Contact Tracing app

    Google and Apple have combined to work out a solution that works across iOS/Android devices. Here's a document that explains how what they have done would work …

     

    But there are Privacy concerns as this BBC article (with video) explains.  Regardless of those concerns the app is being trialled in the Isle of Wight. It’s useful to know the difference between the approach being used by the NHS and the Google-Apple approach, this article explains those differences.

    However there are potentially difficulties …

    France (how unexpected) have threatened Google-Apple over the fact they won’t work with France’s standalone approach (a similar approach to the UK); and it has been suggested that failure to adopt a common approach could threaten international travel – as “health passports” will be impossible to implement.

    Then there are technical difficulties as iOS and Android devices work in different ways (not unsurprisingly) causing success of the Google-Apple approach to be dependent on a very high adoption amongst Android users.

    The new NHS contact-tracing app could be used to send malicious alerts causing people to isolate unnecessarily, The Independent has been told. The app, which is being trialled in the Isle of Wight, tells users if someone they have been in close proximity with may be suffering from coronavirus, meaning they could be exposed. But because users can set off the warnings themselves by reporting symptoms – rather than positive Covid-19 test results – it could be used to send out false alerts. Dr Michael Veale, a lecturer in digital rights at University College London, said Britain’s tracing app had no measures in place to stop individuals “maliciously triggering notifications” using its normal functionality.

    Then, on the technical front, some notes from Phil Edwards’ friend

    On the Apple-Google Indirect approach

    “Their approach seems pretty solid. I think they’re basically exposing some features that previously weren’t available to app developers. Both seem pretty determined to limit the potential for it to be exploited by governments; I think they announced yesterday/the day before that any apps using their system can’t also access location data.

    Contact tracing is totally doable without central databases. I can see why a government might want to own data themselves, but there are big downsides (especially security when building in such a rush).”

    On the NHSx Direct approach

    “The implementation of this contact tracing app really hits that sweet spot between ‘Are they incompetent?’ and ‘Do they have ulterior motives?’ I’d advise against installing it but I doubt it’s going to work properly anyway in its current implementation because of various oddities around how Bluetooth LE works. This isn’t a great article but covers some of it.”

    A better comment from Hacker News covers it clearer:

    “‘Bluetooth LE has four main states: scanning, advertising, peripheral connection, and central connection. In order to exchange the data that the app needs it needs one device in the peripheral connection mode and the other in the central connection mode. This means one device must have previously been advertising and the other scanning. The two important states are advertising and scanning.Android devices can advertise in the background but they can’t scan reliably, they can do this for a short period of time enforced by the Android time limits on apps running in the background and possibly manufacturer specific power savings measures. These limits are not well documented and cause issues on any device using Bluetooth.iOS devices can’t advertise in the background, however they do advertise an Apple specific advertisement which can’t be controlled by the app but can still be connected to. iOS devices also can’t reliably scan in the background however they can scan more reliably for iBeacons (special adverts) [1]Combined this makes it difficult to work well in the background, Android devices can’t reliably connect to any device, iOS devices can’t connect to each other but iOS devices may be able to connect to Android devices.’”

    Finally, a potential for Fraud

    Plus fraudsters have not been slow to latch-on to the possibility of piggy-backing on the NHS app as this article in The Guardian show (thanks Phil for the link).

    Other references:

    The NHS Covid-19 website

     

  • Identity Theft

    This will probably be one of the most challenging posts I’ve ever attempted to write because in all truth, I don’t think we really still know what actually happened to my daughter’s online identity, let alone wholly knowing how it happened, but I’m going to try and explain the sequence of events as an alert to you all, and a reminder to us too!

    Some background and a plausible explanation of why they got themselves into the situation they found themselves.

    They’d been self-employed for a short while now, working as a freelancer, and had just submitted their first tax returns in that capacity.

    They were working from home, with two young children with one under six months old, and both very demanding of their time.

    The family is living in another family member’s house whilst they “do up” their new house.

    They’re adept at multi-tasking (obviously too adept as it turns out) and is (as many of their age are able to do) capable of nestling their phone between chin and shoulder whilst doing other tasks!

    What happened next!

    She had a phone call purporting to come from HMRC (we’re presuming this was just a fortuitous coincidence from the fraudster’s point of view – they had no way of knowing the employment status of the family member) – saying that they had a refund owing. As explained above she thought this was quite possibly the case as she had just completed a tax return – again an unhappy coincidence! She was told to click on a link in a text message to complete the process of getting the refund. She had their youngest child on her hip, was preparing a meal and was “distracted”. She filled-in the required information from the link!!!!

    Agh! No!

    Shortly afterwards (the same day) she presented her credit card at a supermarket and payment was refused. She realised something was wrong. She found she didn’t have access to her online banking. She contacted the bank by phone. The bank “supposedly” froze the account there and then but it was apparent that at least two transfers of money had been made to someone who was a Payee in her account – why? That’s the clever bit of the scam, I’ll explain later!

    More payments appeared to have been made … help!!!

    How could this be? The account was frozen … wasn’t it?

    Get the family involved!

    Having a son who’s an IT expert comes in useful, especially if he lives on the other side of the world! He worked through the night (day) in securing as many of her accounts as he could. Changing passwords, which were admittedly rather weak and used more than once (should have listened to Dad) – but he had no idea just how much data had been downloaded, or indeed just how much they had to start with as a result of perhaps a previous “pwned” event.

    Having another local son who’s also very practical and logical helps also. He suggested that she contact the payee and tell them about the payment and request it be refunded. What transpired next turns out to be the “clever” part of the scam, although on this occasion it wasn’t conducted very expertly because they attempted multiple payments to the same payee. The payee confirmed that they’d had this payment, wondered what it was and had been a bit puzzled as to why Mr X had contacted them and requested a refund to a bank account because “he’d made a mistake”.

    This was obviously NOT the same account as that from which the payment had originated and turned out to be the way the scammers were hoping to transfer funds from the hi-jacked bank account to one of their own! Fortunately, my son’s suggestion alerted the payee and the payee advised their bank NOT to transfer the money.

    Phew! How did this all happen when the bank account was supposed to be frozen?

    The key to this scam was getting control of my daughter’s mobile phone number. She didn’t realise it immediately, but soon became aware that it had been “stolen” through a scam called SIM swapping. This usually is done by a seemingly distressed person going into a mobile phone shop and pleading for a new SIM with a phone number “because their phone has been stolen” and “it’s absolutely imperative they have their number back immediately as there’s something very important happening right now”.  This is described here.

    Why do they want to do this? Because they can transfer calls made to the rightful owner of the phone to their own phone.

    Why do they want to do this? Because they can then request the bank account to be unfrozen, and also use their access to the phone number for any number of authorisation features.

    And what is more they can lock you out of your phone accounts.

    How did they do this in this case? Well GiffGaff is an online service provider and they have stated that they did everything they were supposed to do to authenticate the request for a SIM swap – but it is evident that there are serious weaknesses in their processes. They have stated they are looking at this for the future. Just Google “GiffGaff SIM swap Fraud” to see what is returned – it’s frightening!

    So what happened next, and was there a happy ending?

    Well, believe it or not, even with a personal visit to the bank and assurances that no more payments would be made, the bank did allow the account to be unfrozen and transfers out of her account were attempted. A second visit to the bank resulted in heartfelt apologies being made and offered over the way their fraud department had handled the problem and a complaint being raised by the branch against their own department on my daughter’s behalf – I don’t know the outcome of that!

    Well, there was a happy financial outcome. Thanks to the prompt action and thinking of my local son, the initial transfer was halted. It’s not conclusive whether my daughter could have received compensation (as detailed here) as she was the instigator of the problem through her own mistake (the HMRC phone call). All other attempted transfers were eventually trapped by the bank and refunded to her – so no financial loss.

    However …

    Much more significant than the potential financial loss was what it did to her confidence. She insisted on getting a new phone, because she wouldn’t accept any advice from any family member (especially me) that there wasn’t anything on her phone that wouldn’t continue to monitor her.

    She also lost all confidence in using any online systems – which up until then she’d been very reliant upon.

    She also lost a lot of confidence in herself as she realised just how gullible (but extremely unfortunate) she’d been … but the positive side of this, and the main reason for sharing this is that she’ll be much more careful in the future!

    Postscript.

    We don’t know whether the identity theft side of this will ever be resolved. We all know that a huge amount of information is held on us on the internet. We all know that some websites have had their security breached and identity information stolen. We don’t know what was held by others about my daughter. She had a public profile, they now have the potential to add even more information to their database about her if they had managed to download information from her email (and other) accounts before my son locked them down. We just don’t know.

    There was a mysterious book that arrived at her house with a cryptic message in it.

    There have been some scamming emails purporting to come from her since this event.

    She now uses a different email account.

    We just don’t know whether these are connected to the fraud event or are just strange random occurrences … and I suppose we never will know just how much additional information they may have downloaded – emails, photographs, documents, etc. etc. Very frightening.

    NatWest Guide to Fraud
    Some privacy tips for iPhone users.

  • Scams, SIMs and security – 27th June 2019

    Boot-up
    Feedback from the last meeting (John). Any progress with websites from anyone else??
    Thought grazing: Jim posted on Google Photos, Google Drive and Backup and Sync. This is Google’s blogpost on the changes they are making and here is the help document explaining what will happen after July 10th.
    I posted about using URL shorteners and reminded you how I use Pocket and Flipboard.
    The Computer Group for next year. We’ll meet as we meet now, every second and fourth Thursday of the month.
    Digital Picture Frames – anyone use them? I’ve had Nix recommended to me. Alternatives – try Foliobook on an iPad, or a screensaver linked to Dropbox on a Desktop PC.
    Travel and digital photography.
    SMART meters, SMETS2 and Hive. Discussion on optionsswitching suppliers. Hold off for now?
    How do Password Managers Work?  Should you use one? Which one should you use?
    Anything else, issues, problems.
    News
    Apple’s WWDC Showcase summary – loads of updates and new hardware. The 8-minute video summary. Apple’s promotional videos from the event. Apple splits iPhone and iPad operating systems by introducing iPadOS – what’s new in both?
    What new features will there be in iPadOS? Mouse support for the iPad. Finally, external drive support for the iPad – this is how it will work.
    New features for MacOS – Catalina coming in the autumn.
    Apple’s iOS 13 will provide some protection against spam phone calls.
    New features in iPadOS, iOS and MacOS for photographers. Click here and here too!
    Apple finally kills off iTunes!
    New features for Dropbox on the Apple platforms.
    What Wireless Security are you using, and should you consider changing your router?
    Don’t charge your phone/tablet under your pillow at night – and other electrical tips!
    Identity Theft
    This will probably be one of the most challenging posts I’ve ever attempted to write because in all truth, I don’t think we really still know what actually happened to my daughter’s online identity, let alone wholly knowing how it happened, but I’m going to try and explain the sequence of events as an alert to you all, and a reminder to us too!
    Some background and a plausible explanation of why she got herself into the situation she found herself.
    She’s been self-employed for a short while now, working as a freelance journalist, and had just submitted her first tax returns in that capacity.
    She’s working from home, with two young children with one under six months old and both very demanding of her time.
    The family is living in my local son’s house whilst they “do up” their new house.
    She’s adept at multi-tasking (obviously too adept as it turns out) and is (as many of her age are able to do) capable of nestling her phone between chin and shoulder whilst doing other tasks!
    What happened next!
    She had a phone call purporting to come from HMRC – we’re presuming this was just a fortuitous coincidence from the fraudster’s point of view – saying that she had a refund owing. As explained above she thought this was quite possibly the case! She was told to click on a link to complete the process of getting the refund. She had her youngest son on her hip, was preparing a meal and was “distracted”. She filled-in the required information from the link!!!!
    Agh! No!
    Shortly afterwards (same day) she presented her credit card at a supermarket and payment was refused. She realised something was wrong. She found she didn’t have access to her online banking. She contacted the bank by phone. They “supposedly” froze her account but it was apparent that at least two transfers of money had been made to someone who was a Payee in her account – why? That’s the clever bit of the scam, I’ll explain later!
    More payments appeared to have been made … help!!!
    How could this be? The account was frozen … wasn’t it?
    Get the family involved!
    Having a son who’s an IT expert comes in useful, especially if he lives on the other side of the world! He worked through the night (day) in securing as many of her accounts as he could. Changing passwords, which were admittedly rather weak and used more than once (should have listened to Dad) – but they had no idea just how much data had been downloaded, or indeed just how much they had to start with as a result of perhaps a previous “pwned” event.
    Having a local son who’s also very practical and logical helps also. He suggested that she contact the payee and tell them about the payment and request it be refunded. What transpired next turns out to be the “clever” part of the scam, although on this occasion it wasn’t conducted very expertly because they attempted multiple payments to the same payee. The payee confirmed that they’d had this payment, wondered what it was and had been a bit puzzled as to why Mr X had contacted them and requested a refund to a bank account because “he’d made a mistake”. This was obviously NOT the same account as that from which the payment had originated and turned out to be the way the scammers were hoping to transfer funds from the hi-jacked bank account to their own! Fortunately, my son’s suggestion alerted the payee and they advised their bank NOT to transfer the money.
    Phew! How did this all happen when the bank account was supposed to be frozen?
    The key to this scam was getting control of my daughter’s mobile phone number. She didn’t realise it immediately, but soon became aware that it had been “stolen” through a scam called SIM swapping. This usually is done by a distressed person going into a mobile phone shop and pleading for a new SIM with a phone number “because their phone has been stolen” and “it’s absolutely imperative they have their number back immediately as there’s something very important happening right now”.  This is described here.
    Why do they want to do this? Because they can transfer calls to the rightful owner of the phone to their own phone.
    Why do they want to do this? Because they can then request the bank account to be unfrozen, and also use their access to the phone number for any number of authorisation features.
    And what is more they can lock you out of your phone accounts.
    How did they do this in this case? Well GiffGaff is an online service provider and they have stated that they did everything they were supposed to do to authenticate the request for a SIM swap – but it is evident that there are serious weaknesses in their processes. They have stated they are looking at this for the future. Just Google “GiffGaff SIM swap Fraud” to see what is returned – it’s frightening!
    So what happened next, and was there a happy ending?
    Well, believe it or not, even with a personal visit to the bank and assurances that no more payments would be made, the bank did allow the account to be unfrozen and transfers out of her account were attempted. A second visit to the bank resulted in heartfelt apologies over the way their fraud department had handled the problem and a complaint being raised by the branch against their own department on my daughter’s behalf – I don’t know the outcome of that!
    Well, there was a happy financial outcome. Thanks to the prompt action and thinking of my local son, the initial transfer was halted. It’s not conclusive whether my daughter could have received compensation (as detailed here) as she was the instigator of the problem through her own mistake (the HMRC phone call). All other attempted transfers were eventually trapped by the bank and refunded to her – so no financial loss.
    However …
    Much more significant than the potential financial loss was what it did to her confidence. She insisted on getting a new phone, because she wouldn’t accept any advice from any family member (especially me) that there wasn’t anything on her phone that wouldn’t continue to monitor her.
    She also lost all confidence in using any online systems – which up until then she’d been very reliant upon.
    She also lost a lot of confidence in herself as she realised just how gullible (but extremely unfortunate) she’d been … but the positive side of this, and the main reason for sharing this is that she’ll be much more careful in the future!
    Postscript.
    We don’t know whether the identity theft side of this will ever be resolved. We all know that a huge amount of information is held on us on the internet. We all know that some websites have had their security breached and identity information stolen. We don’t know what was held by others about my daughter. She was a public figure, a journalist on a national newspaper, they now have the potential to add even more information to their database about her if they managed to download information from her email (and other) accounts before my son locked them down. We just don’t know.
    There was a mysterious book that arrived at her house with a cryptic message in it.
    There have been some scamming emails purporting to come from her since this event.
    We just don’t know whether these are connected to the fraud event or are just strange random occurrences … and I suppose we never will know just how much additional information they may have downloaded – emails, photographs, documents, etc. etc. Very frightening.
    NatWest Guide to Fraud
    Some privacy tips for iPhone users.
     
     
     

  • How much do you know about computer fraud?


    Recently in a U3A meeting we discussed Computer Fraud. We often do, or so it seems. If it’s not fraud, it’s security online, or scams and what’s done with our data … but more about that later!!!
    This short post is just to alert people to a simple, short quiz (or test) that has been produced in conjunction with the UK Government to help people recognise fraudulent activity.
    Go to this website, satisfy yourself it’s genuine and is a government backed initiative, and take the test and see how you do. According to the Daily Mail – so it must be true – only 9% of people taking the test were able to accurately recognise all the scams and false messages, that despite a claim that 80% felt that they were able to recognise a fraudulent message.
    For further guidance try this link.

  • Thoughtgrazing, Forums, Buying an iPhone, online Fraud and Google Hangouts – 8th Feb 2018

    Thoughtgrazing and Forums
    http://digital.cardiffu3a.org.uk/
    http://digital.cardiffu3a.org.uk/cardiff-u3a-computer-group/community/forums-and-topics/ – not active any more
    Buying an iPhone (Marilyn), and a used one at that, contract free
    The phone Jenny has is an iPhone SE, I have an iPhone 6s. Both of these (though not the latest models) are still obtainable from Apple, or from the Service Providers. So here are some links for you to chase-up. Unless you plan to hold a lot of photos/videos on your phone, I wouldn’t worry too much on having more than the minimum amount of memory (RAM).
    You might consider buying a used model. This is a good article which explains the options. I can’t recommend, because I’ve never done it – https://www.macworld.co.uk/feature/iphone/how-to-buy-second-hand-iphone-3496606/.
    However the Service Provider I use, and would seriously recommend using (GiffGaff owned by O2 and using the O2 network) do offer pre-owned phones and I would have no hesitation of thinking about buying from them – https://www.giffgaff.com/mobile-phones/pre-owned.
    Can I also pleas stress that you should NOT consider buying a phone on a contract if you can at all possibly afford the up-front cost, as the long-term cost is SO much greater; the same goes for the instalment options. Your best option is a SIM-free purchase – I pay just £7.50 a month for my deal with GiffGaff, and I could quite possibly drop that down to just £5 per month.
    So here’s the page for buying a phone from the Apple Store – https://www.apple.com/uk/iphone/ – you’ll see that both of our phones are still current models.
    The iPhone SE – https://www.apple.com/uk/iphone-se/ – and The iPhone 6s – https://www.apple.com/uk/shop/buy-iphone/iphone6s
    Please feel free to contact me again for further advice/guidance before you make a decision.
    I think I may spend some time on this in the Computer Group on Thursday. Always a good topic.
    GiffGaff and 3 (PAYG)
    https://www.three.co.uk/Store/SIM/Pay_As_You_Go
    https://www.giffgaff.com/
    https://www.giffgaff.com/mobile-phones/pre-owned/apple
    Fraud website from UK Gov
    https://takefive-stopfraud.org.uk/
    and course from FutureLearn
    https://www.futurelearn.com/courses/cyber-security? 
    Hangouts (and also Chrome Extensions)
    https://hangouts.google.com/