>

Buy Microsoft Office Ultimate 2007!
Showing posts with label Cool Link. Show all posts
Showing posts with label Cool Link. Show all posts

June 26, 2009

Windows 7 Pricing Announced!

Windows 7 is an amazing OS, and I highly encourage everyone to get it. Ill be getting the Pro version for work, and Ultimate for home. Unless you need the domain connectivity and security benefits of the professional version, or the media features of the ultimate edition, home basic is what you want.  

Also, starting in mid July, all new computers purchased with Windows Vista, will be eligible for a free upgrade to the equivalent version of Windows 7 when it is released, and as much as I like Vista, after using Windows 7, I have to say, your computer will probable run even better after the upgrade.

 

For the home user: Windows 7 Home Premium

Full Version: $199.99

Upgrade from XP or Vista: $119.99 $49.99- Limited time pre order offer.

 

For Business Users: Windows 7 Professional

 Full Version: $299.99

Upgrade from XP or Vista: $199.99  $99.99 – Limited time pre order offer

 

For those who want it all: Windows 7 Ultimate

Full Version: $320.00

Upgrade from XP or Vista: $219.00 (sorry guys, no special here)

 

Special Pricing ends July 11, 2009

Bookmark this post:
StumpleUpon DiggIt! Del.icio.us Yahoo Technorati Reddit Google

June 23, 2009

Apple’s MobileMe Helps Owner find “lost” iPhone

I am about as hardcore of a Microsoft/Windows fan as you can get. I love the company and the products, but I can also recognize when someone has made a great product,  and Apple has done that. The iPhone is a fantastic device, and with the release of the 3.0 firmware, it has gotten even better, and Kevin (www.happywaffle.com) has found this out first hand.

Kevin and some friends went to have a drink at a bar after a Lego convention (yea, he is THAT awesome), but unfortunately, left his precious iPhone behind when they left. Like any good (and by good I mean addicted) phone user, Kevin noticed his error very quickly, but by the time he got back to the bar, his phone was gone. Of course, Kevin was bummed, but then it came to him, not only did Kevin have an iPhone, but he had set up the “Locate your iPhone” feature on apples MobileMe! And so Kevin’s journey (hunt) began.

Multiple unanswered texts, several ignored calls, some luck, and a high speed chase brisk walk through a crowded urban neighborhood, and Kevin, with friends, was able to track down the person who *found* Kevin’s phone! And while I don't necessarily recommend chasing down bad guys, you can help but cheer on Kevin.

Read the full tale on Kevin’s rarely updated blog

Bookmark this post:
StumpleUpon DiggIt! Del.icio.us Yahoo Technorati Reddit Google

March 23, 2009

The Ultimate Steal Is Back

A lot of people like to hate on Microsoft, but they do a lot of good, especially when it comes to helping students. Right now, you can get Microsoft Office 2007 Ultimate Edition, which usually sells for over $600.00 for only $59.99 through a program called The Ultimate Steal, which is put on by Microsoft. The only stipulations to the program are that you must be a student, and you much have an email address ending in .edu.Other than that, this is a completely legit deal, so if you need MS office, and you are a student, there is no better choice.

 Buy Microsoft Office Ultimate 2007!

Bookmark this post:
StumpleUpon DiggIt! Del.icio.us Yahoo Technorati Reddit Google

March 20, 2009

NIN|JA 2009

2 of my favorite bands, Nine Inch Nails and Jane’s Addiction, along with Street Sweepers have released a free for download compilation album as a preview to the up coming NIN|JA 2009 Tour.

ninja

 

Stream it to your computer, or download the Album for free at www.ninja2009.com

Bookmark this post:
StumpleUpon DiggIt! Del.icio.us Yahoo Technorati Reddit Google

March 3, 2009

Deleted a file by mistake?

At one time or another, everyone has mistakenly deleted a file from their computer, or deleted a picture from the memory card of their  frontscr camera thinking that they had another copy or that they no longer needed it. And while many of these files end up in the recovery bin and are easy to get back, sometimes you need something just a little better. Pirform, Ltd, the makers of awesome software such as CCleaner, has released a new piece of data recovery software called Recuva.

Recuva was released a few months back, but up until about an hour ago, I had yet to try it. Yes, even I delete things by mistake....but that's not what happened tonight. It was a nice quiet night, and my phone rang... an emergency call from a client. She was trying to move some files from a thumb drive to her desktop, but along the way, the files were deleted. What better time to try a new piece of software then in a crisis?

Recuva worked like a champ. I downloaded and installed it in less than 2 minutes. Then with an incredibly clean and simple interface, I was able to select the location that the files were originally located, the types of files I was looking for and where I wanted to recover the files to.

A minute later, I had a folder full of recovered files. My client is happy, I am happy, and my future clients will be happy because we now have a new tool to help them when mistakes happen.

So the next time you accidentally delete an important folder or file, give it a try, it worked for me.

Bookmark this post:
StumpleUpon DiggIt! Del.icio.us Yahoo Technorati Reddit Google

*FREE* Achieving Information Security *FREE*

Hey everyone,

I put together a white paper entitled "Achieving Information Security". Is is a compilation/rework of a series of blog posts I had done that got some good feed back.

It is now free for download, so check it out.

Feel free to pass it along to friends, colleagues, and whoever else you want, and as always, feed back is always welcome, just use the contact me link.

Bookmark this post:
StumpleUpon DiggIt! Del.icio.us Yahoo Technorati Reddit Google

February 27, 2009

Rouge Admin or Dedicated Employee

Over the last several month, there have been many articles published about Terry Childs; the San Francisco network administrator who is img_50191_laptop_theft_wb now in jail after being accused of 'network tampering' during his tenure as Lead Network Administrator for the city of San Francisco.

For those who have not been following the story:

  • Terry Childs was the lead network administrator for the city of San Francisco, and managed a very large network responsible for the majority of government data traffic.
  • The unofficial reason for him tampering with the computer network was that he was trying to create an insurance policy of sorts for himself after he got a poor performance review and his supervisor tried to have him fired.
  • Childs' allegedly configured a single administrative username/password that only he had access to on several key pieces of equipment, and when asked for the credentials, he gave wrong info, then refused to give the correct info.
  • Child's is also accused of deleting the startup configurations on several pieces of equipment, so in the event the power went out on the device (required to reset passwords sometimes) the configuration would be lost. Password recovery features were also disabled.
  • Childs' also allegedly install data monitoring software on several supervisors computers, and was found with lists of usernames and passwords, including those of his superiors.
  • And finally, Child's is accused of setting up 'rouge' devices across the network to provide him remote access to it.

I know, this looks bad. But lets consider what his job was, the man was a network administrator, and much of the above can easily be seen as part of his job.

Things Terry did, that I do daily.

  • We have 2 administrative accounts on each computer, 1 master administrator account that stays un used, and 1 administrator account that we use for admin tasks. We do this, so in the event something happens to the one we use, we have a backup that is not used. Only we have these passwords, our clients do not. It is not rare for them to request this info, but we explain that if we provide them administrative access to servers and other equipment, we cannot be held responsible for it any longer. If they need changes made, we can do it for them. If they insist on access, we reevaluate them as customers as it is not worth our reputation to allow an untrained person admin access to a server when they have no reason for needing it.
  • Part of the service we provide is installing an application on each computer that monitors event logs, runs maintenance at night, monitors anti-virus software, provides us remote access to computers, and several other things. Monitoring computers is part of our job.
  • Configuring remote access to sites. Any network admin who has to support multiple locations sets up ways for them to access things remotely, otherwise they cant do their job. It is not rare to set up multiple methods of remote access, so in the event one fails, you have another option.

 

How do I feel about this case?

My feeling towards this are mixed. I understand that sometimes an IT admin needs to protect a company from itself. Too often company executives think that because they are high up in a company they should be allowed to do what they want on a computer and access whatever they want. This is not true. Executives are targets in the hacking world. Their information is all over the place on the web and on their company web sites because they want to be known. Because so much data about them is available, it makes it easier to exploit them. This means their accounts need to be even more tightly controlled than the average user, but this is the exact opposite of what they want, and sometimes demand.

When a CEO demands access to something, an IT professional is put in a tough position. They can give the access, and the deal with any problems created by it (and trust me, problems occur frequently when people have unneeded access), or you can stand up to the person and risk backlash.

I have been in this position in the past. A position where executives come up with inane ideas and requests, and despite the IT department explaining why the idea is bad, and the risks involved, and the potential for problems, we are pushed into making the changes. When something goes wrong, we are then looked at like we caused it, and that is not fair. I have left jobs because of situations like this.

The networks and computers we build and maintain as administrators are like a living resume. If you are named as the admin on a network with a major security breach, it can dramatically hurt your career, so when you are faced with these decisions, you are being asked to put your reputation on the line. So with every decision, you ask yourself, "is this risk worth my career?"

However, as a professional, there is a point where you just need to cave and give the boss what they want, and let them deal with the problems. When he was faced with arrest, Childs' should have left the job, and turned over all credentials and information in a proper way, there is no if ands or buts. The data belonged to the city, and while I'm sure he wanted to protect it, and while he may have thought he had been wronged, he had no legs to stand on when it came to that.

I am very interested in seeing how this will turn out.

 

More info about the case:

http://www.sfgate.com/cgi-bin/article.cgi?f=/c/a/2008/07/14/BAOS11P1M5.DTL

http://www.infoworld.com/article/08/07/15/IT_admin_locks_up_San_Franciscos_network_1.html

http://www.infoworld.com/article/08/07/17/IT_administrator_pleads_not_guilty_to_network_tampering_1.html

http://weblog.infoworld.com/venezia/archives/020956.html

http://blogs.techrepublic.com.com/career/?p=555&tag=nl.e101

Bookmark this post:
StumpleUpon DiggIt! Del.icio.us Yahoo Technorati Reddit Google

February 23, 2009

The ThinkSmarter Store is now open

I have decided that since I spend a lot of time recommending cool products and gadgets, I would give you an easy way to also buy them.

The ThinkSmarter Store, powered by Amazon, is now open, and available via the sidebar below the RSS sign up section of the Blog.

store

 

I will be adding product to the store as I review things or find things that I think you would like. Right now there are some books, movies, software and hardware that I like, and the prices are pretty good (it is amazon after all), so check it out, as I will be adding more stuff frequently, and of course, if you have any recommendations of things I should check out, feel free to send me an email, and Ill take a look, and add them to the store if I like them.

Bookmark this post:
StumpleUpon DiggIt! Del.icio.us Yahoo Technorati Reddit Google

February 20, 2009

Don't Keep Personal Data on Work Computers

ThinkSmarter is guest blogging on Dumb Little Man. Check out the post HERE

Bookmark this post:
StumpleUpon DiggIt! Del.icio.us Yahoo Technorati Reddit Google

February 19, 2009

Top 9 Dirty Tricks Scammers Use

PC World has posted an interesting article Outlining some of the more common scams that are being used to trick hard working people out of their money.

The list contains scams that are used on Social Networking sites like Facebook and MySpace, as well as attempts to trick users by emailing them at home and at work.

Scams like this are becoming more common as unemployment rates go up and the budgets shrink because people are getting desperate and looking for an easy fix. Like everything else in life, if something seems to good to be true, it probably is. Be careful who you give your personal information to, and you will be well on your way to protecting yourself from scams like these.

Read the Full Article Here

Bookmark this post:
StumpleUpon DiggIt! Del.icio.us Yahoo Technorati Reddit Google

February 13, 2009

67 Computers Missing from Los Almos Nuclear Weapons Lab

POGO reported today that 67 computers have gone missing from Los Almos Nuclear Weapons Lab, 13 of which were in the last year. While the number of machines missing is a bit alarming, Los Almost says that none of them contained confidential data. I did however find one part of the report concerning;

"Thirteen of the missing computers were lost or stolen in the past 12 months, including three computers that were taken from a scientist's home in Santa Fe, N.M., on Jan. 16, and a BlackBerry belonging to another employee was lost "in a sensitive foreign country," according to the memo and an e-mail from a senior lab manager...Only one of the three computers stolen from the employee's home was authorized for home use, which raised concerns "as to whether we were fully complying with our own policies for offsite computer usage," he said."

While I am ok with people taking their work home (believe me, I know how necessary it is sometimes) I also understand that if you are taking a piece of equipment home, there are some special security concerns that need to be addressed. It is concerning that in a place that is supposed to be so heavily secured someone was able to walk out with 3 computers.

Read the complete article.

Bookmark this post:
StumpleUpon DiggIt! Del.icio.us Yahoo Technorati Reddit Google

February 11, 2009

Getting rid of an old computer?

Ah...the smell of new computers in the morning... there is little in life which is better (except for bacon...bacon > most things in life)anyway...

So you just got your new computer, you backed up the data off the old one, moved it to the new one and are ready to take that old box to the recycling center (you wouldn't just throw it in the trash would you)

Not so fast...

One major mistake I see individuals and companies make on a nearly daily basis is taking their old computer and just throwing it in the trash. This is a big mistake. Before you throw out any computer, you need to make sure all data is properly removed. I can't count the number of computers I have gotten for free that were loaded with personal information, and not just silly things like family photos, I'm talking about bank statements, quicken files, "personal" photo albums, etc.

Reformatting your hard drive will discourage most people from looking for information, but it is not really deleting your data, just flagging the parts of the hard drive as empty. To really delete you data, you actually need to delete it, and then write more stuff over it. To do this, you need a special tool.

While there are several commercially available piece of software out there that can do this, I'm not a fan of any of them because they cost money. I'm cheap, I like free things, so I use DBAN,

*************WARNING***************

DBAN IS PERMANENT DATA REMOVAL, DO NOT USE DBAN ON A DRIVE YOU MIGHT EVER NEED DATA OFF OF AGAIN.

DBAN is an outstanding tool that deletes your data, then overwrites its it to make sure it is gone. It then repeats this up to 7 times if you want it to. (Department of Defense requires a minimum of 5 overwrites). It is incredibly simple to use, you just pop the disk in, pick the drive, and poof! all data is gone (ok, the poof! might take an hour or so depending on the size of the drive) but still, once you have done this, the recovery would take way more time and money (if possible at all) than almost any person or companies data is worth.

For businesses who need to remove data from drives frequently, there is EBAN which allows you to wipe data from dozens of computers at once.

Bookmark this post:
StumpleUpon DiggIt! Del.icio.us Yahoo Technorati Reddit Google

December 26, 2007

New Ideas for Blogging

One of the biggest problems I have encountered with blogging is being able to continuously come up with content that was worth writing about. The way I avoid this is by writing about things problems I have encountered and then writing the solution I found for them. In addition, I like to write about new products that I find and play with. Writing about new products and tools I find and use is one of my favorite things. I am a gadget and software fanatic, and have hard drives full of just random little pieces of software that I have come across and liked. Lately, one of the best places I have found to look for new software are sites like Smorty and PayPerPost blog network.

The nature of these sites are to get bloggers to look at and review the product. Bloggers pare paid to do it, but that is because it takes time to properly evaluate a piece of software. I have decided to use them as a source for new things to write about since they are filled with vendors of new software dying to have people review it. The pay just gives me an excuse to spend more time blogging instead of doing things like spending time with my wonderful girlfriend (joking…mostly)

Take a look at the site if you have some time, it is pretty cool, and from what I have seen so far, it will be a wealth of topics to write about as well.



Bookmark this post:
StumpleUpon DiggIt! Del.icio.us Yahoo Technorati Reddit Google

December 7, 2007

How Hackers Get Your Data: (Part 3 of 3)

In Part One we talked about Hackers being able to crack or steal your passwords and using those to get to your information, in Part Two we discussed hackers exploiting flaws in infrastructure as well as software to gain access to places they shouldn't be. In part three we will talk about one of the most common elements of security, and one of the most over looked; the human element.

It doesn’t matter how much security you put in place, and how great your password is if a hacker can trick you into telling them what they want to know. One of the fastest growing ways to gain information about people and to steal information from people is just simply asking for it.

Social Engineering: When a hacker decides to contact a person to gather information rather than attacking a weakness in technology, it is called social engineering. How the attacker decides to contact you will vary depending on the situation, but one of the most common threats currently is called phishing. How phishing typically works is the attacker will send you an email that looks official (usually from a bank or large company you might do business with) and then give some almost believable reason why they need you to verify your personal information. Most people think nothing of it and just go ahead and verify the information, and without knowing, they have just given away their everything the attacker need to know to either steal your identity, or to get your password to access the other data he wants. Another variant of this attack sending you an email asking you to click on a link to go to their website and verify the information. They then point the link to a website they have built to look very similar to the real businesses website, but when you enter your information it just sends it to the attacker.

The best way to protect yourself against phishing is to educate yourself.

  • Banks and other large companies will NEVER ask you to send them your personal information via email. If they do, you should leave that bank and find one that cares about security.
  • When you click on links, pay attention to where they really go. At the top of your web browser, it gives you the address of the page you are on. If the link says it is going to Paypal then the address should be www.paypal.com/someotherwebinformation and not paypal.imgoingtostealyourdata.com notice the placement of the word Paypal. Web Sites names are called “domains”. Only one person can own a particular domain and have a website there. So in the first example, Paypal is the domain, you can tell because it is the part directly before the .com in the second example they are using what is called a sub-domain. The domain in the second example is Imgoingtostealyourdata (again you can tell because it is right before the .com) so pay attention.
  • If you are ever concerned or suspicious, you call the company that it says sent it and ask them. And if it’s a company you have never done business with, you can be sure it is indeed fake.

Other techniques used in social engineering include calling and just pretending to be someone else (usually someone high in the company or another figure of authority like the police). Pretending to be a new employee and just needing some help (people almost always want to help the new guy). Some social engineers are so confident that they will walk right into an office and claim they are a “computer repair guy” or some other professional there to fix something.

To guard against attacks like that, you just need to be very careful who you give information to. If you have never seen a particular repair guy before, ask for some type of ID, and ask who sent him, then verify that they sent him. When working with people on the phone, don’t just take their word for it when they say they are, have them prove it, or verify with someone that they can have access to the data they are requesting. And under NO CIRCUMSANCES should you be giving people your password, not even to your IT guys. NO ONE. The IT staff can reset your password if they need your account specifically, and then you can change it back to what you want later.

If you work in a company, be sure you have a way to verify who the people calling are. This is especially true if you are in a position where you are tasked with resetting passwords for people. Don’t just rest a password because “John Doe” called and said he needed his password reset. You need a way to verify who they are. Come up with a set of validating questions that your company has answers to so you can validate their identity. It might be personal information like date of birth or something business related like their supervisors name. Or better yet, have them select the questions upon hire and fill out a form that you reference when they call.

If you haven't noticed, the trend through out this series has been "knowing" is the best protection. That is what Think Smarter is about. I want to share as much information as possible so everyone is aware of what can happen, and is on the lookout for things that should be happening. Knowing the weaknesses is the best way to fix them.


More information:
Sonicwalls Phishing IQ Test (how well can you spot a phishing attempt)
The SEC has some tips on recognizing Phishing
List of current major phishing scams

Bookmark this post:
StumpleUpon DiggIt! Del.icio.us Yahoo Technorati Reddit Google

December 4, 2007

Cool Gift Card Idea

I received an email today, and thought it was cool. A company called Gift Card Lab is allowing people to make custom gift cards for the holidays. The gift cards are backed by Visa, so they are good at any store who accepts Visa, that way you don't need to guess which store the receiver wants something from.

The way the customization works is you can either pick a photo from their database or you can upload your own. I think it would be really cool if you took say a family Christmas photo (like the ones many people send out in cards) and then put that on the card and give them to people you would normally give a gift card too. It makes a normally unpersonalized gift personalized.

Or for the ultra security conscious, you can take a picture of yourself, edit in a note that says "I am the owner of this card" next to your picture, and never worry about someone stealing your card!

Pretty nifty. The link to the site is below.



Gift Card Lab - Create Photo Gift Cards Online

Bookmark this post:
StumpleUpon DiggIt! Del.icio.us Yahoo Technorati Reddit Google

November 14, 2007

The Paypal Mafia

CNN Money has a great article high lighting The Paypal Mafia a group of founding members of PayPal, lead by Peter Thiel, who has gone on to fund and run some of the internet's most successful startups such as FaceBook, YouTube, Digg, and many more.

Bookmark this post:
StumpleUpon DiggIt! Del.icio.us Yahoo Technorati Reddit Google