>

Buy Microsoft Office Ultimate 2007!

November 29, 2007

How Hackers Get Your Data: (Part 1 of 3)

It seems like every other day we are hearing about how a large company has lost their customers data, or how they are investigating a breach in their security. You would think that in this day and age it would be almost impossible for a company to just "lose" 100,000 customers names, social security numbers, and credit card info. So how does it happen? How are people still able to sneak in and steal hundred of thousands of records from private corporate records.

Here is how:

  1. Password Theft: if you have read this blog, you will see that I mention passwords being vital to security over and over again. Passwords are like the keys to your house, if someone else gets them, then they are as good as in. Stealing or cracking a persons password is without a doubt the most common way hackers are able to bypass a companies security and get at the data they crave. As computers become more and more powerful, it becomes easier for hackers to use software to crack a password. A password really is just a string of letters, numbers and special characters, and because there are a finite amount of choices, a computer can eventually crack any password you try, the stronger the password, the longer it takes, and the longer it takes for a hacker to crack a password, the greater the risk of them getting caught. So as computers get faster and are able to try more password combinations in a shorter amount of time, the faster passwords will get cracked. So when choosing a password your goal should be to keep it as strong as possible and as long as possible but not to the point where you need to write it down. Also, try not to use things like your name, birthday, address, or other things so easily associated with you, or if you do, make them more complex. For instance, if your Wifes name is Amber, you could make the password @Mb3r!. Notice the combination of Uppercase and lowercase letters, numbers and special characters. Because of this combination it will take a computer significantly longer to crack the password than just using Amber. Remember, the goal of security isn't to make things uncrackable (that is impossible) it is abut making them harder to crack than they are worth.

    In addition to that, people who use the same password for every site they visit cause a problem as well, because if one site has a security flaw and a hacker gets your password, they now have access to your accounts everywhere. Also, as tempting and convenient as it is, do not write down your password. writing your password on a post it and sticking in under your keyboard is like hiding a copy of your house key under your doormat. So please, don't do it.


  2. Viruses, Worms, and Trojan Horses: Have you ever gotten an email from someone you never new with the subject line of "Really cool picture!!!" and the attachment was named Awesome_Picture.jpg.exe or something similar? Of course you have, we all have. That my friends, is a virus. Viruses come in all sorts of shapes and sizes and have many purposes. Some are written to simply delete your files, while others are written to just send out spam. Some of the worst how ever are written to collect information from the computer they get installed on, and these are called Trojan Horses. A Trojan Horse will typically install it self and run silently in the background, if it is a good one, you wont even notice that it is there. It will simply sit and silently collect data about everything you are doing, logging information like your user name and password for websites that you go to, credit card numbers and bank information. Then, it sends that information off to its creator. Without even noticing it, someone may have just stolen your identity.

    So how do we protect against things like this? The best way is to just use common sense. When going through your email, pay attention to what you are opening. If you aren't friends with a guy named John Doe, then you probably don't care about his vacation, so why open a picture from him? Just delete it and move on. When surfing the web, if something is big and bright and flashy, don't click on it, the old saying "if it seems to good to be true, it probably isn't" has never been truer than when surfing on internet. Also, if you see a pop up that says "you have a virus" then tries to sell you something, it's a lie.

    In addition to being careful, you can use technology to help you! Using anti-virus and anti-spyware software is a great way to not only keep your computer running smooth, but to keep you identity safe. This software is made to search of viruses not only on your computer, but in the emails your receive as well. There are a number of titles to choose from like Symantec Anti Virus and my personal favorite Kaspesrky Anti Virus, both sell for around $40, or you can go with a free option like AVG by Grisoft. The paid versions have a few more options, and typically have better support, but AVG is a great product as well.


See Part Two

Bookmark this post:
StumpleUpon DiggIt! Del.icio.us Yahoo Technorati Reddit Google

November 27, 2007

Securing Your Wireless Network

As more and more people buy laptops instead of desktop, or smart phones with wifi access we will begin to see a huge in crease in wireless networks being set up. I did a little experiment about a few years ago and set up my laptop to search out and log every wireless signal t saw while I was driving through various neighborhoods (this is called war driving) I expected to see maybe 100 wireless networks and knew about half were going to be insecure. What I found was astonishing. Over 700 wireless networks and less than 1/3 of them were secure. This was in an area of about 5 square miles. Not big at all. It amazed me that I could literally park anywhere and was able to get an internet connection. Because of this, I wrote a small guide on things you should do to secure your wireless network.

Setting Up Your Wireless Network:
Key words have been linked to their definitions so you can get a better understanding of each term.

  • The first thing you should do with any device you buy is change the default administrator password. This go for routers as well. Any security you put in place is useless if the person can just connect to your router and change the settings.

  • Change the default SSID to something familiar to you. The SSID is the name of your network, changing from the default helps you recognize your network and ensure you connect to it and not someone else's by mistake.

  • Do not broadcast your SSID. Although it is easy to see networks that don't broadcast the SSID, you can't connect to them unless you know their name. So by not broadcasting it, the SSID can kind of act like a user name, while your encryption will act like a password.

  • Turn on Wireless Encryption. If your router and wireless card support it (any made in the last 2-3 years should) use WPA or WPA2 (both are strong forms of wireless encryption) Older routers and wireless cards may not support those, in which case use WEP. (WEP is better than nothing, but is considered a weak encryption)

  • If you don't expect visitors using your network, use the MAC address filter built into most routers. MAC addresses are unique identifiers on all electronics. By enabling the filter, you can make sure your router only connects to devices you tell it to (you will need to enter the MAC address for each piece of equipment that will be connecting into the filter list)

  • If you live in a small house/apartment, turn down the power of the antennas so your wireless signal only reaches where you need it to. There is no reason to give your neighbors and people passing by free net access.


How to do each of these will vary from router to router, so consult your instruction manual, or give the manufacturer's technical support a call and they will happily assist you.




Microsoft has some tips on increasing performance of your wireless network:
http://www.microsoft.com/athome/moredone/wirelesstips.mspx

Original post I Worte: (read through the comments, anti-online has a lot of smart people)
http://antionline.com/showthread.php?t=264530

Bookmark this post:
StumpleUpon DiggIt! Del.icio.us Yahoo Technorati Reddit Google

November 26, 2007

Got Something to Sell?

In the age of the internet anyone can open their own store. Got an idea for a funny t-shirt? got a great idea for a cool new widget? With a little time, and a little help from some good shopping cart software you can have your own online store up in no time. Ashop Commerce has a really nice e-commerce software available for you to use. From an administration stand point, it is outstanding. It is very user friendly and easy to learn to use well.

From the Administrator Interface You Can:

  • Control user access (define who can make the changes in product and pricing)
  • Manage the types of payments your store will take (Which credit cards, etc)
  • Manage your inventory (Prices, sales, coupons, Brands, product reviews etc)
  • Manage your customers
  • Manage your marketing strategies
  • Track sales
And dozens of other tasks that would normally require several pieces of software. You have access to all of these tools in an easy to use web interface.

And the client front end is absolutely wonderful. Clean and easy to use, your customers will be able to easily look for every product you have to offer and then be able to pay and check on the status of their orders from the time they place them to the time their package arrives at their door.

Ashop Commerce has 2 demo sites up that you can take a look at, one is for a toy store the other for a Phone store. 2 very different products that have different requirements, but are set up very well with this software. The demos are each 2 parts, one for the administrative side of the software, the other is the customers side and both demos allow you to take control of the sites to modify the styles and the feel of each as well as to play with fake customer data so you can get a good feel for how powerful these tools are.

Bookmark this post:
StumpleUpon DiggIt! Del.icio.us Yahoo Technorati Reddit Google

Make Money Blogging

If you are online for any significant amount of time, you have probably seen dozens of "Make a million dollars from home!" type advertisements. You probably also know that they are pretty much a scam. There are ways to make money online, but the real ones will not make you rich over night, heck they probably wont even make you rich at all. But one of the ways to make some extra money is with a company called Smorty.

Smorty is a "Pay Per Post" type service that you can sign up with, and they will give you products to blog about, and then pay you for the post. They can do this because advertisers pay them for the exposure, and they in turn pay you. I think this concept is interesting because not only does it allow bloggers to make some extra cash, but it also feeds them ideas of things to blog about when they are having dry spells, so it really is win-win. The amount you are paid varies based on your blogs ranking (the higher the ranking the better the pay) and can range from $6.00 to $100.00 per post, so if you enjoy writing, and are ready to get paid to blog then follow the link and check Smorty out.

Bookmark this post:
StumpleUpon DiggIt! Del.icio.us Yahoo Technorati Reddit Google

November 25, 2007

Dear Viewers:

Please do not believe everything you see on TV. I am a huge fan of shows like CSI and Law and Order, but I pull my hair out when I see them using computers to do EVERYTHING. They make it seem like on a whim a random detective can "hack" a computer, look up every single email ever sent, get the IP address of the sender, then get a map to their house based on the IP address alone, then put a stop on their credit cards, order a pizza to be delivered to the house they are about to raid, and they do it software that has an amazing 3d interface and works in seconds.

Take this image from an episode of CSI: Miami



Lets look at what is wrong with it.

  1. It is not a real IP address. I'm sure they do this becasue they don't want people to do something with that info (same reason they use fake phone numbers) but there are IP addresses that are real and can be used like the 169.x.x.x series (which is the default private IP network) or the 192.X.x.x or 10.x.x.x network and of course 127.0.0.1 All are real IP addresses and are no risk to put online.

  2. You cannot take an IP address and translate that into a real address on the fly. You would have to take the IP, give it to the provider who it is assigned to, have them check their logs and see who it was assigned to at the time the incident. To do this, you need a warrant, and it will take days since ISPs work slow.
You also have random detective who are now expert hackers. They flip on a computer and "crack" the password on it in seconds with nothing more than the software on the computer. Cracking a password on a computer is not hard, but you do need software to do it. In addition to that, they seem to be able to do it on every computer they encounter. Who cares if computers run different operating systems, everyone knows everything.

In addition to that, the user interfaces on every computer are outstanding. I wish every piece of software I had included a nice 3d interface, and ran as smooth as theirs. No programmer is going to program nice interfaces on utilitarian software built for the government, its un-needed and a waste of system resources. There is no need for a great user interface if you are just typing in an IP address, and why would it just show you the physical address of the home(which isn't possible) instead of say the registered owner of the account? Software is designed first for functionality, then for how it looks. When dealing with people like the government, they don't pay for a great 3D design.

What about "enhancing" pictures. How often do we see them take this ultra grainy video or photo from an ATM machine a block away, then enhance it to be nearly High Definition quality. It just isn't possible. The way cameras work are they take a picture, and what is sees is all the data you have. as you blow that picture up, a computer can try and "enhance" it some by guessing what other data would be there, but you don't go from barely legible to perfect. Maybe from almost legible to barely legible.

They do the same thing with forensics. They make it seem like DNA is the end all and can be found anywhere and prove without a doubt who committed the crime. Not only can it be done, but it is done in seconds. Real labs take WEEKS to get DNA results, it isn't done in 10 seconds.

This stuff, as fun as it is to watch, is an insult to the people who do it for a living. Forensic Technicians work hard, they work long hours and spend years learning to properly gather forensic evidence (either digital or physical) and some random person does it in seconds.

It also spreads false information to viewers. In the picture above, it makes you believe an IP address is like a fingerprint and is rock solid proof a person identity. The truth is, it isn't. IP addresses are used by many people and are cycled through users. Sure they can be traced back to an account at a specific time, but there is still no way to tell who was using the computer. What if the jurors on the Jamie Thomas v. RIAA case thought that IP addresses were solid proof, like DNA. Then they were basing their decision on false facts. I wonder if any of the lawyers asked if any of them watch shows like CSI and know how digital evidence is gathered. Probably not, and becasue of that, the jurors have false knowledge of how things work.

What about if jurors in a murder case hear the defense talking about there being a lack of DNA evidence. What if they think "wow...no DNA must mean he is innocent because DNA is really easy to get. I saw it on CSI last night!"

So please, enjoy the TV shows and movies, but realize a lot of it is fiction. Just like your favorite action hero can't really take 5 shots to the chest, jump off a building and catch a helicopter that is taking off, while throwing a grenade into a window and destroying a building while rescuing a woman who is falling from the upper floors. Its all great to watch, but just isn't true.

Bookmark this post:
StumpleUpon DiggIt! Del.icio.us Yahoo Technorati Reddit Google