>

Buy Microsoft Office Ultimate 2007!
Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

July 26, 2009

A War is Brewing…

In what might be one of the companies biggest mistakes, AT&T has decided to block /b/ for many of its customers.

/b/ for those who don't know, is a dark corner of the  internet that only the brave should venture, (seriously, not for the faint of heart), and it the epicenter of 4chan.org and home to anonymous.

Moot, founder of 4chan, has acknowledged the issue:

 

It's come to our attention that AT&T is filtering/blocking img.4chan.org (/b/ & /r9k/) for many of their customers. There is no remedy at this time.
If you've been affected, I would advise you call or write customer support and corporate immediately.

 

Calls for Pizza Delivery to AT&T store, attacks on the AT&T network, and many other actions (most high juvenile, other highly sophisticated) are being called for.

Think about your next steps very carefully AT&T. You are a very large company with billions of dollars to lose, these are a group of internet users, with little to nothing to lose, and have a history of doing damage to those who they dislike, imagine what they will do to someone targeting them…

 

Will AT&T be the next Hal Turner, Scientology, or Kenny Glenn? Time will tell.

Bookmark this post:
StumpleUpon DiggIt! Del.icio.us Yahoo Technorati Reddit Google

June 22, 2009

Virus Harvests Confidential Banking Info from ATMs

A new virus has been discovered on ATMs throughout Russia and the Ukraine. The ATMs; running Microsoft’s Windows XP operating system, appear to have had been infected with a 50Kb piece of malware. The malware, which ran under the guise of lsass.exe, an executable which is normally used to cache users credentials to make accessing data easier, evaded normal virus scans and security checks.

As the piece of malware sits undetected, it gathers not only the card number of any card used on the machine, but also the start and expiration date of the card, the pin, and the 3-digit security code. All of this information was stored on the ATMs hard drive until the person controlling the virus decided it was time to collect. The method for retrieving the data was also very smart and likely contributed to staying undetected for so long. When the thief was ready to collect, they simply went to the ATM, inserted a preprogrammed “trigger” card, and all of the data was printed out via the ATMs receipt printer. So far, the malware has been found on 20 ATMs, and the experts at SpiderLabs, the company that located the bug, has said that it is likely it if more wide spread, and likely to continue to spread. It is up to banks to now tighten up their security procedures as well as pay careful attention to the audit trails that up until now have been used to make sure customer data was being transmitted securely.

As a bank user, the best thing you can do is pay careful attention to your bank and credit card statements and your credit report. You can get a free credit report for the Big 3 credit agencies by visiting https://www.annualcreditreport.com/, or check with your bank/credit card company to see if they offer free/cheap credit monitoring.

 

 

See the article on New Scientist for more info.

Bookmark this post:
StumpleUpon DiggIt! Del.icio.us Yahoo Technorati Reddit Google

June 19, 2009

FBI agent looks back on time posing as a Cyber Criminal

A good Q&A with FBI Special Agent J. Keith Mularski (AKA: Master  Splynter), the agent who went undercover for 2 years pretending to be an infamous hacker and spammer to infiltrate "Dark Market"; an online group of cyber criminals.

"It was like a soap opera. There was constant drama going on. A lot of people were accusing one another of being cops."

After spending 2 years undercover, the sting ended with over 60 arrests in Germany, Turkey, The UK and the United States, with charges ranging from Identity theft to kidnapping.

Q. What sorts of crimes were they doing on Dark Market?
A. They were doing all sorts of identity theft. They were hacking into companies and stealing credit card numbers and selling them. They were selling counterfeit drivers' licenses and other photo documentation, as well as manufacturing fake credit cards. They were selling harvested bank accounts and brokerage accounts and selling different types of malware or spyware programs or Trojan horses that you could infect peoples' computers with. The whole gamut of the cyber underground was available there. If you needed it you could get it there on the site.

"The attackers have changed with the emergence of organized crime into these cybercrimes...It's all about the money now and not just about how elite my hacking skills are to get into this Web site. Profit is driving these groups."

Q. How old are they?
A. The average guy is in his mid-20s or so. We've seen guys in their 40s. Ages range from 17 to 40something, typically. A lot of the guys who we arrested were in their mid-30s.

Q. The stakes are higher now for everyone?
A. Definitely.

Read the Full Q&A on CNET

Bookmark this post:
StumpleUpon DiggIt! Del.icio.us Yahoo Technorati Reddit Google

April 2, 2009

More Warranty Services Calls…

More fun…

This time the calls came from: (269)768-2200

scam_alert_big

Call 5: (co-worker3’s work phone) 3:35pm
*blahblahblah press 1 to talk to a sales person*
Kiko:
Hi, this is Kiko calling from Warranty Services, are you interested in a warranty for your car?
Me: Hi Kiko, may I have your corporate offices number please?
Kiko: I’m sorry, I can’t give you that, I hope you have a good day *click*

*This call actually gets somewhere*

Call 6: (my work cell again) 3:46pm
*blahblahblah press 1 to talk to a sales person*
Caesar:
Hi, this is Caesar calling in regards to your automobile warranty expiring, can I have you first and last name as well as zip code please?
Me: zip code is 96813
Caesar: Thank you, and your first and last name?
Me: John Smith
Caesar: out records indicate that you have never bought a warranty from us.
Me: nope
Caesar: Thank you, and what year, make and model of your car?
Me: 1950 Ford Model T
Caesar: Do you have a newer car?
Me: no
Caesar: I'm, sorry, we cant process your warranty today.
Me: WHY NOT?!
Caesar: Unfortunately, its too old.
Me: How old can the car be?
Caesar: The car must be from 1983 or later, have fewer than 150k miles, and cannot be a commercial vehicle.
Me: Do you have a subsidiary or affiliate that can warranty commercial vehicles?
Caesar: No
Me: Well, I’m looking at buying a new car soon, can I have your number so I can call back and get a warranty?
Caesar: We don’t do that.
Me: You don't let people call to buy things from you?
Caesar: No, this is your final notice, if you don’t buy it now, we wont ever call you back, and your number will be deleted.
Me: But this is the second time you’ve called this number today.
Caesar: That is because our database takes 24 hours to update, so tomorrow your number will be deleted.
Me: Well, good luck on the not letting people buy things. Talk to you tomorrow.

Call 7 (co-worker3’s personal cell) 4:01pm

Call got disconnected before we could get to a person.

Call 8 (co-worker2’s personal cell again) 4:05pm

Call got disconnected before I could talk to somone.

Bookmark this post:
StumpleUpon DiggIt! Del.icio.us Yahoo Technorati Reddit Google

Dear Warranty Services…

Today has been a day full of fun with telemarketers. Now, normally, I simply answer the phone and let them know I am not interested. I scam_alert_big know the guy on the other line is just trying to earn a pay check, so I’m not about to start screaming at them. But this is getting ridiculous (well for my co-workers, I find it hilarious). I missed a couple of their calls yesterday because I was on the other line, but I made sure I was ready today.

The Number that has been calling so far is: (571) 431-1262
They Claim to be from Warranty Cervices, which is a well known Scam

Call 1(this was to my work cell): 11:36 am
*blahblahblah press 1 to talk to a sales person*
Girl Caller: Thank you for responding to your final notice, to ensure accurate information, can you please confirm the year, make and model of your vehicle? 
Me: How do you know the warranty is expired if you don't have the car’s info?
*Click* call ends

Call 2 (co-worker1’s work cell): 12:42p
*blahblahblah press 1 to talk to a sales person*
Girl Caller: Thank you for responding to your final notice, to ensure accurate information, can you please confirm the year, make and model of your vehicle? 
Me: Thanks for calling about this. Is this for the Bentley or the BMW?
Girl Caller:*sounds excited* What year is your BMW sir?
Me: So this is for the BMW? I thought the Bentley was the one out of Warranty?
Girl Caller: “uhhh…*click*

Call 3 (my personal cell): 12:47p
*blahblahblah press 1 to talk to a sales person*
Guy Caller:
Thank you for responding to your final notice, to ensure accurate information, can you please confirm the year, make and model of your vehicle?
Me: I’m sorry, who was this?
Guy Caller: Warranty Services
Me: And your name?
Guy Caller: Rick
Me: Rick, may I have your corporate office’s number please?
Guy Caller: I cant give that to you, I’m sorry.
Me: No problem, may I speak with your supervisor?
*Click*

Call 4: (co-worker2’s cell phone) 1:01pm
*blahblahblah press 1 to talk to a sales person*
Girl Caller: Thank you for responding to your final notice, to ensure accurate information, can you please confirm the year, make and model of your vehicle? 
Me: I’m sorry, I didn't catch your name
Girl Caller: “Mu…mu…My Name?”
Me: Yea, so I know who I’m talking to
*click*

You would think these people would have more persistence, but nope, one question and they crack. Oh well, hopefully they call more, this is getting fun.

As always people, think before you give out your information. If someone calls and asks for your info, its probably a scam. Ask where they are from, and ask for a call back number. Then, if it is someone you do business with, go find their corporate number, and call that to get back in touch.

Bookmark this post:
StumpleUpon DiggIt! Del.icio.us Yahoo Technorati Reddit Google

March 31, 2009

What's a Conficker?

What is the Conficker Worm?

Conficker (also known as Downup, Downadup, and Kido) is a worm that has been spreading across the Internet since around October of 2008, of course, this is just an approximation, and the actual origin is not known for certain. Conficker specifically targets the Windows operating system (Windows 2000 Pro, XP home, XP Pro, XP Media Center Edition, Windows Vista, Windows Server 2003, Windows Server 2008). It spreads via malicious web sites, emails, and sharing infected files via P2P software.

What does Conficker do?

As of now, all that is has done is install itself, break your antivirus software, and modify some system files to make itself very hard to remove. It is also likely that if you got the Conficker Worm, you got other malware as well that causes the common symptoms (pop ups, slowness, etc). In addition, it creates false URLs in order to spread it self, and also downloads more malware to your system.

The big concern with this worm is that is has spread so much. Current estimates indicate that it could be installed on as many as 15 Million computers world wide. Now, if it stay dormant and does nothing, that's not that big of a deal, but experts don't think that it is going to stay dormant. Analysts who have looked into the worm believe that on April 1st, 2009 (tomorrow) the worm is programmed to "phone home" and update it self with new instructions, and that is a major concern.

The potential for a worm like this is massive, and the update could make the worm do anything from delete files, download more malware, turn your computer into a spam bot (a computer that sends out massive amounts of spam) or all the infected computers could be combined to form a massive botnet, which would be leased to the highest bidder.

A bot net, is a network of computers, usually lots of home systems spread across the world, that are controlled as a single unit and used to either send out massive amounts of spam, or to DDoS targets. If used as a botnet and the target is a bank, a utility company, or even a few large organizations the results could be crippling. If they target ISPs, the Internet could come to a crawl, if they target a company, they could lose massive amounts of business.

The problem is, at this point, we don't really know what will happen, and that is scary. But not to worry, we are not helpless.

Symptoms of Conficker:

  • Users being locked out of directories
  • Access to admin shares denied
  • Scheduled tasks being created
  • Access to security related web sites is blocked.

How to stop Conficker:

This worm uses a known exploit in Windows that Microsoft has patched a long time ago. The problem is, many people don't update their computers, so the fix is never installed. So the first step is to update your computer.

  1. Go to update.microsoft.com and install all of the latest updates for your computer. Once they are installed, reboot your computer, and go back and run the updates again. Keep doing this until no more updates show as needing to be installed.
  2. Update your anti virus software. Open up the software and run the automatic update. If your subscription is expired, either renew it right now, or uninstall it, and download and install a free anti virus like AVG
  3. After the updates, run a full system scan, and delete any threats that have been found.
  4. Restart your computer, and run the full system scan again.
  5. You can also use an online scanner like Trend Micro's Housecall,  Symantec's Removal Tool, or
  6. Microsoft's Malicious Software Removal Tool


For more information about the Conficker Worm See the following:

Microsoft Malware Protection Center

Microsoft Help and Support

McAfee Conficker Information Page

Symantec's Conficker Information Page

    Bookmark this post:
    StumpleUpon DiggIt! Del.icio.us Yahoo Technorati Reddit Google

    March 28, 2009

    A Response To "Why Can't Windows Shutdown Properly"

    An article written by Larry Magid and posted on CNET today complains about a problem with the Windows Operating system  win95taking too long to shutdown and start up. And while I agree that there are times Windows moves too slowly, I also have to point out that the reason is rarely Windows.

    The first thing you have to understand is what actually happens when Windows is shutdown. If the only thing installed on a computer is the Windows Operating system, then all that needs to happen for the computer to shutdown is:

    1. Anything in RAM that will be needed later is written to the hard drive.
    2. All open files are closed
    3. All Services required to run the computer are stopped
    4. Power to the hardware is stopped and the computer is now shutdown.

    This process doesn't change very much even after other software is installed, but what does change is what files need to be closed, what need to be written to the hard drive, and what services need to be stopped. This is where the problem comes in.

    Think about what is running on your computer right now, you probably think "oh...just my Internet browser", and chances are, you are probably wrong (at least, you should be wrong)

    On a typical computer the following types of software are installed, and at least a portion of them are running in the background (i.e. they aren't being actively used by the user)

    1. Antivirus software - this is a good thing by the way.
    2. Instant messaging software (I have 2 different IM services running, 1 for work, 1 for personal use)
    3. File indexing software (things like Microsoft Desktop Search or Google Desktop)
    4. Quicktime/iTunes services
    5. Software update services (used to update various pieces of software installed, and there can be several services depending on the software)
    6. Viruses (most computers I work on have AT LEAST 1 piece of Malware or a virus)

    So when you shutdown a computer, Windows must go through each one of these and stop them from running, when they are told to stop, they all go through their own processes to store data, close files, and end services. If there is a problem with the software, it may hang, and you will see that wonderful "Program not responding" error. This happens frequently when several things are trying to close at once because they are trying to access similar resources. If any of these programs have trouble closing, Widows can't shutdown.

    So why can't Windows just force a program closed and move on? Well, it is because if Windows just started forcing applications close, files that are being written to, or things that have not been saved yet can become corrupt or deleted, and that would cause even more problems.

    Windows being slow to start is caused by the exact same thing. All of that stuff you have auto starting can cause problems, and many of the hang ups experienced are caused by other programs not starting properly.

    The number 1 cause of these slowdowns are viruses and malware. Most software like this is not written to be efficient, they don't take standard coding 'rules' into account and are very rarely thoroughly tested. Because of this, they cause all kinds of problems, and the authors don't have to answer to anyone since the software shouldn't be installed in the first place. Pirated software that has been tampered with is also a major cause of these kinds of errors, as well as running software when your computer does not meet the required hardware specifications. Now, this isn't to say that Windows is always perfect, because it is not, but considering how universally used it is and how much different software can run on it, it is almost impossible to make sure it is 100% perfect all the time.

    Oh...and if you are thinking about comparing it to a Mac, please think about the total combinations of hardware/software available to work on a computer running Windows, and what's available for your Mac. There is no comparison, and because of that, you cant fairy compare the problems they have.

    Bookmark this post:
    StumpleUpon DiggIt! Del.icio.us Yahoo Technorati Reddit Google

    March 10, 2009

    Your Digital Legacy

    In a world where protecting your online identity is as important as protecting your credit cards, car titles, and home deeds, it onlylegacy makes sense that if something happens to you, there is someone you trust to take care of it. 

    A company called Legacy Locker has now made that task a little easier. According to their website Legacy Locker is

    "a safe, secure repository for your digital property that lets you grant access to online assets for friends and loved ones in the event of death or disability."

    Essentially, legacy locker gives you a place to store all of the information that makes up your online identity. Email account information, online banking usernames and passwords, online bill pay and stock trade account information. In addition to providing a secure and easily accessible place to store all of this information, they allow you to select a beneficiary (or multiple beneficiaries) and in the event something happens to you, the information will be released to them. This can potentially save your family days, if not weeks of grief while trying to hunt down this information.

    I love this idea...but am hesitant. Not only are you putting all the information necessary to access your online life in a single place, but you are putting it in place that really has no reputation, and this for me is a major concern. Now, there are security risks any time you are storing valuable information anywhere, so to mitigate these risks, people spread their information around, but this means more time spend managing information.

     

    The Bad:

    1.  No real reputation: While founder Jeremy Toeman is known in the blogging and marketing world, he is not a security expert, nor is he an expert in estate management.
    2. All of your information is in one place: Never put all your eggs in one basket. Not only does it increase the risk of loss if there is a breach, it also increases the chance of a breach because they are now a high profile target.
    3. Website is not up to par: Their website lacks a lot of information, their ToS, Privacy Agreement, and Conditions of use are very cookie cutter, and not specific to the service they provide. In addition, there are A LOT of spelling errors, and other mistakes in terminology which indicates a lack of understanding of the service itself.  If they can't pay a proper copy editor, how can we trust they are paying someone to properly secure their site.

    The Good:

    1. They make it clear that they will share your information, but only with affiliates who will be working with them on the service you bought, not 3rd party services.
    2. They have a proper SSL certificate in place through thawte, inc. Who is a trusted source in security
    3. They claim to have been audited by both thawte and McAfee.
    4. Data is encrypted at a higher level once stored than it is during transmission. Now this may sound bad, but they are using a 256 bit encryption during transmission, which is what banks use. Data is stored with a 512 bit encryption on the server, which is exceptional.
    5. It really is a good idea, and with the proper backing and effort it can be a great product.

     

    My Opinion:

    I think it is too early to pass judgement, especially since the product doesn't go live for another month. I like the idea, and I like that they are working with known security experts. I am however highly skeptical of storing so much information in one place, especially online. I wont be one of the first to sign up, but I will be keeping an eye on this product.

    Bookmark this post:
    StumpleUpon DiggIt! Del.icio.us Yahoo Technorati Reddit Google

    March 5, 2009

    The Happy Computer Checklist

    Computers are great tools and awesome toys. They do the work of thousands of people, allow you access to more information than anyimages single person could ever need and let you play awesome games. And after all this, many people still treat them like crap, and its time we put a stop to it. A happy computer, is a great computer, and a computer you will love to use.

    The key to a happy computer is maintenance! you clean up your house, you clean your car, you clean you favorite sun glasses, why wouldn't you clean your computer?

    To keep your computer running like a champ, I recommend the following:

     

    • Anti-virus software - This is a must. AV software comes in all shapes and sizes, and in all price ranges, find one that fits your needs and get it. I use the free version of AVG on my home computer, and my company manages over 1200 desktops and servers that use the paid for version. The software is clean and easy to use.
    • Updates - Many updates that are released resolve bugs found in software. Bugs in software usually mean less efficient software, so keeping all of your software and hardware drivers up to date, will help keep your computer running smoothly. To update Microsoft products, you can use the built in update tool, most other software also comes with an update tool, but if they don't, just check the manufactures website from time to time.
    • Elbow Grease - Once every few months, it is a good idea to look at what you have on your computer and get rid of what you don't need. Uninstall software you don't use, archive documents or photos you don't really access anymore to an external drive or DVD. This will keep hard drive space free, and that means faster responses when your computer is looking for other data.
    • General Clean Up Tool -  With everyday use, computers are bound to get tons of files that really aren't needed. Temp files from viewing websites, residual files from software that you uninstalled, and numerous other things. And while Windows comes with tools built in to get rid of them, there are better solutions out there. I like to use a tool called CCleaner. CCleaner will remove all of the junk that gets on your computer during day to day use, and it will do it in a easy to use way. And best of all? IT IS FREE. I like to run a tool like ccleaner about once a month, you can do it more frequently, but once a month is what I find to be a good balance.
    • Disk Defragmenter - When you save data to a hard drive, it will search for the first open space available to write that data. As you write more and delete more, the free space becomes scattered around (fragmented). When drives become fragmented, your computer starts running slower because it takes the computer longer to find what it is looking for. Windows comes with a disk defragmenter tool, and it will get the job done. For more advanced users, you can use a tool like Defraggler (free and made by the same people as CCleaner). You should run disk defragmenter each time you do any major clean up (like running ccleaner or manual clean ups like the ones listed above)

    If you do these things, your computer will be happy for a long time. I've seen way too many people throw out perfectly good computers because they were "running slow" and had they followed the above, they could have saved themselves some money.

    And as an added bonus, doing the above also helps keep your computer secure!

    Bookmark this post:
    StumpleUpon DiggIt! Del.icio.us Yahoo Technorati Reddit Google

    March 3, 2009

    *FREE* Achieving Information Security *FREE*

    Hey everyone,

    I put together a white paper entitled "Achieving Information Security". Is is a compilation/rework of a series of blog posts I had done that got some good feed back.

    It is now free for download, so check it out.

    Feel free to pass it along to friends, colleagues, and whoever else you want, and as always, feed back is always welcome, just use the contact me link.

    Bookmark this post:
    StumpleUpon DiggIt! Del.icio.us Yahoo Technorati Reddit Google

    March 1, 2009

    Jamming Cell Phones

    In the United States it is illegal for anyone other than the federal government to interfere with licenses radio communications, this includes cell phones. But with cell phones being more popular than they ever have been, many businesses are trying to change this rule.NoPhoneSign1

    Many people think that cell phones should be jammed in places like schools, hospitals, libraries, movie theaters, and restaurants because of the potential to disturb others. The biggest argument against this type of action is that in the event of an emergency, a call cannot be made out, and no calls can come in. I believe this is a reasonable argument.

    Personally, I think that individuals should be responsible and have some common decency. If you are in a place like a theater, library, or basically any other place where a sudden ring would cause an interruption, then put your phone on silent, and obviously don't talk on your phone. Unfortunately, many people don't seem to get this.

    This is very different then people talking loudly in public places, while it can be incredibly annoying to hear a guy 20 feet away screaming into his cell phone, it is out in the open, I am not paying to be there, and I can move 10 more feet away without really being put out any. But in an enclosed place, where I am paying for an experience, I expect others would respect that and be courteous, after all, I'm sure they would hate me sitting next to them and talking while they are trying to watch a movie or enjoying a nice dinner.

    So do I think anyone outside the federal government be allowed to use jammers? NO.

    I responsibly use my phones (I carry up to 3 phones at a time because of work) daily. If I am in the movies, and feel my phone vibrate, I get up and leave so I can see what is going on. I expect everyone else to do the same. I rarely use my phones in public (its hard for me to hear my clients, and for them to hear me), and my phones are on vibrate 99% of the time. I should not be punished because others are irresponsible. The one exception to this is on an air plane. I REFUSE to give my business to any airline which allows people to use their cell phones in the air. I can leave a restaurant if someone is being really annoying, I can leave a movie theater if it gets that bad, but I cant walk off a flight halfway through, and while I am a very controlled individual, I don't think it would take more than an hour of someone talking loudly in an enclosed place before their phone met the business end of my boot.

    I am however ok with the federal government  using jammers in emergencies or for security purposes. Id rather not have cell phone service then a bomb explode, and id rather emergency services have all the bandwidth they need then get an email.

     

    See PC Worlds Article for more about Jamming cell Phones

    Bookmark this post:
    StumpleUpon DiggIt! Del.icio.us Yahoo Technorati Reddit Google

    February 27, 2009

    Rouge Admin or Dedicated Employee

    Over the last several month, there have been many articles published about Terry Childs; the San Francisco network administrator who is img_50191_laptop_theft_wb now in jail after being accused of 'network tampering' during his tenure as Lead Network Administrator for the city of San Francisco.

    For those who have not been following the story:

    • Terry Childs was the lead network administrator for the city of San Francisco, and managed a very large network responsible for the majority of government data traffic.
    • The unofficial reason for him tampering with the computer network was that he was trying to create an insurance policy of sorts for himself after he got a poor performance review and his supervisor tried to have him fired.
    • Childs' allegedly configured a single administrative username/password that only he had access to on several key pieces of equipment, and when asked for the credentials, he gave wrong info, then refused to give the correct info.
    • Child's is also accused of deleting the startup configurations on several pieces of equipment, so in the event the power went out on the device (required to reset passwords sometimes) the configuration would be lost. Password recovery features were also disabled.
    • Childs' also allegedly install data monitoring software on several supervisors computers, and was found with lists of usernames and passwords, including those of his superiors.
    • And finally, Child's is accused of setting up 'rouge' devices across the network to provide him remote access to it.

    I know, this looks bad. But lets consider what his job was, the man was a network administrator, and much of the above can easily be seen as part of his job.

    Things Terry did, that I do daily.

    • We have 2 administrative accounts on each computer, 1 master administrator account that stays un used, and 1 administrator account that we use for admin tasks. We do this, so in the event something happens to the one we use, we have a backup that is not used. Only we have these passwords, our clients do not. It is not rare for them to request this info, but we explain that if we provide them administrative access to servers and other equipment, we cannot be held responsible for it any longer. If they need changes made, we can do it for them. If they insist on access, we reevaluate them as customers as it is not worth our reputation to allow an untrained person admin access to a server when they have no reason for needing it.
    • Part of the service we provide is installing an application on each computer that monitors event logs, runs maintenance at night, monitors anti-virus software, provides us remote access to computers, and several other things. Monitoring computers is part of our job.
    • Configuring remote access to sites. Any network admin who has to support multiple locations sets up ways for them to access things remotely, otherwise they cant do their job. It is not rare to set up multiple methods of remote access, so in the event one fails, you have another option.

     

    How do I feel about this case?

    My feeling towards this are mixed. I understand that sometimes an IT admin needs to protect a company from itself. Too often company executives think that because they are high up in a company they should be allowed to do what they want on a computer and access whatever they want. This is not true. Executives are targets in the hacking world. Their information is all over the place on the web and on their company web sites because they want to be known. Because so much data about them is available, it makes it easier to exploit them. This means their accounts need to be even more tightly controlled than the average user, but this is the exact opposite of what they want, and sometimes demand.

    When a CEO demands access to something, an IT professional is put in a tough position. They can give the access, and the deal with any problems created by it (and trust me, problems occur frequently when people have unneeded access), or you can stand up to the person and risk backlash.

    I have been in this position in the past. A position where executives come up with inane ideas and requests, and despite the IT department explaining why the idea is bad, and the risks involved, and the potential for problems, we are pushed into making the changes. When something goes wrong, we are then looked at like we caused it, and that is not fair. I have left jobs because of situations like this.

    The networks and computers we build and maintain as administrators are like a living resume. If you are named as the admin on a network with a major security breach, it can dramatically hurt your career, so when you are faced with these decisions, you are being asked to put your reputation on the line. So with every decision, you ask yourself, "is this risk worth my career?"

    However, as a professional, there is a point where you just need to cave and give the boss what they want, and let them deal with the problems. When he was faced with arrest, Childs' should have left the job, and turned over all credentials and information in a proper way, there is no if ands or buts. The data belonged to the city, and while I'm sure he wanted to protect it, and while he may have thought he had been wronged, he had no legs to stand on when it came to that.

    I am very interested in seeing how this will turn out.

     

    More info about the case:

    http://www.sfgate.com/cgi-bin/article.cgi?f=/c/a/2008/07/14/BAOS11P1M5.DTL

    http://www.infoworld.com/article/08/07/15/IT_admin_locks_up_San_Franciscos_network_1.html

    http://www.infoworld.com/article/08/07/17/IT_administrator_pleads_not_guilty_to_network_tampering_1.html

    http://weblog.infoworld.com/venezia/archives/020956.html

    http://blogs.techrepublic.com.com/career/?p=555&tag=nl.e101

    Bookmark this post:
    StumpleUpon DiggIt! Del.icio.us Yahoo Technorati Reddit Google

    February 23, 2009

    Don't Feel Bad...Even Banks Get Scammed.

    The New York Times has reported that Citibank may have fallen victim to none other than a Nigerian Scammer.

    "Swindles in which someone overseas seeks access to a person’s bank account are so well known that most potential victims can spot them in seconds.

    But one man found success by tweaking the formula, prosecutors say: Rather than trying to dupe an account holder into giving up information, he duped the bank. And instead of swindling a person, he tried to rob a country — of $27 million."

    Luckily (For CitiBank), it looks like the scammer has been caught.


    Read the Full Article on the NY Times Website.

    Bookmark this post:
    StumpleUpon DiggIt! Del.icio.us Yahoo Technorati Reddit Google

    February 22, 2009

    Instant Messaging in the work place

    No No No, this is not some blog about how instant messaging is a waste of company resources, or how to do it without getting caught. This is a blog about how great a tool instant messengers can be for instant-messengersa  company.

    As a tech, instant messaging has been a tool that I have used in the work place for as long as I can remember. It, along with email, are the primary way I contact other techs. Recently, many clients have thought about implementing a good instant messaging software for their employees to use, but are concerned about the risks IM software poses, as well as the loss of productivity that may occur is people can just chit chat all day.While both of these concerns are valid, there are solutions in place for both, but before we worry about the risks of using Instant Messaging software, lets look at some of the benefits.

    The Benefits:

    1. Fewer Interruptions - A lot of the work I do requires me to concentrate on several things at once. Because of this, other interruptions, big or small can cause a problem. If I'm "in the zone" and get a phone call or even worse, someone comes over to talk to me, I usually get distracted and then have to take the time to regroup my thoughts before I can get back to what I am doing, some times it takes only a minute, but sometimes, it takes longer depending on the task at hand. If someone IM's me, I can wait until a natural break in my work occurs, like when I complete a thought and write it down, I can then look at the message, respond, and then move on. And lets face it, most things can wait a couple of minutes, so that delay usually isn't a big deal, and if it can't wait, you can still call.
    2. Convenience - For me Instant messaging is easier and more convenient that making a phone call. I have a list of names in front of me so I don't need to look up a number, and most times I only have a  quick question, so its just simpler to ask. It also gives the other person a minute to look up and answer if they need to, and you aren't wasting that minute sitting on hold. You also aren't interrupting the person like mentioned above.
    3. Tracking Employee Conversations - Yes, I know, most people absolutely hate this, but it is a perk for a business. My company logs all conversations held via IM for every employee, the boss will occasionally read through the logs just to see what we are up to. Do we stop joking around, sending funny links and pictures, nope, and he doesn't expect us to. Then why does he do it? So he can see what we are up to. If we are asking each other a lot of questions, or a lot of people are asking about the same thing, maybe its time for an email explaining something, or a training. If we are all complaining about a customer, maybe its time to reevaluate them as a customer. It is also helpful for when we ask a question to a superior and then do what we are told and it turns out to be wrong, we simply pull the log and say "I did ask, and was told to do this" or if a dispute occurs between what was said and what was done. It gets resolved quickly.

    The Risks:

    1. It is Informal - People sometimes forget that not everything should be discussed via IM. Confidential client information, or confidential company information usually shouldn't be discussed over IM. IM should be an unofficial communication channel. Things that need to be "on the record" should be communicated in person or in formal writing, like email.
    2. Data Security - There are some risks when using IM. Most are not encrypted by default, because they are meant to be informal forms of communication. The logs are also not encrypted in many cases, so information that shouldn't be shared may be. Depending on the software you use, this data could also get out of the company (although much of the IM software available currently has the ability to make it internal only)
    3. Viruses and Malware - There are a lot of viruses and Malware that target popular IM software. If you allow communication with outside users, this can be an issue. To prevent this, make your IM internal use only and have a good AV software running.
    4. People will use it for Chit Chatting - Yes, people will chit chat with one another and talk about non work related things. As long as it is within reason, its no big deal, they are going to do it anyway, and there are far worse things your employees can be doing aside from communicating with one another.

    Bookmark this post:
    StumpleUpon DiggIt! Del.icio.us Yahoo Technorati Reddit Google

    February 20, 2009

    Update From Yelp.com

    Yelp.com has replied to the allegations that they are trying to sell a service of removing bad reviews from their site. They attribute the report to miscommunications regarding the services they do offer (the ability to highlight a good review) and also the algorythims used to sort the reviews that are listed.

    "It appears that a key source of confusion is our anti-spam algorithm which makes
    a small number of reviews come and go from a typical business' page.
    We
    realize we need to do better at communicating the why and how of this
    counter-intuitive "feature" and we will."


    Read the Full Response on Yelp's Blog.

    I hope this really is all just a miscommunication. The idea Yelp.com is trying to bring to life (and has been) is a good one. Consumers need a place to voice their opinions, and if a company is manipulating those opions, then there is a problem.

    See the comments left on The Consumerist, apparently several users there agree with the assesment that Yelp is a scam.

    Bookmark this post:
    StumpleUpon DiggIt! Del.icio.us Yahoo Technorati Reddit Google

    Don't Keep Personal Data on Work Computers

    ThinkSmarter is guest blogging on Dumb Little Man. Check out the post HERE

    Bookmark this post:
    StumpleUpon DiggIt! Del.icio.us Yahoo Technorati Reddit Google

    February 19, 2009

    Top 9 Dirty Tricks Scammers Use

    PC World has posted an interesting article Outlining some of the more common scams that are being used to trick hard working people out of their money.

    The list contains scams that are used on Social Networking sites like Facebook and MySpace, as well as attempts to trick users by emailing them at home and at work.

    Scams like this are becoming more common as unemployment rates go up and the budgets shrink because people are getting desperate and looking for an easy fix. Like everything else in life, if something seems to good to be true, it probably is. Be careful who you give your personal information to, and you will be well on your way to protecting yourself from scams like these.

    Read the Full Article Here

    Bookmark this post:
    StumpleUpon DiggIt! Del.icio.us Yahoo Technorati Reddit Google

    February 17, 2009

    Update on Kenny Glenn

    Update#1 - http://www.kenny-glenn.net/ is now online.




    Update #2 - Video of Second cat found

    http://www.kswo.com/Global/story.asp?S=9859463

    The second cat has alow been removed from the home, why it was left there to begin with, I dont know.


    When asked about the fate of the abuser, Sheriff "Schulte says he did not know what punishment the boys may face if found guilty, but said the penalties for a juvenile conviction could include psychological counseling, court monitoring until they turn 18, community service to provide restitution for treatment of animals, and/or placement in court custody."

    Please remember that this is a Minor that is being delt with, so do not harass the family. Contact the DA if you want to punish him, we dont want others being hurt becasue of this incident.


    Update#3

    This story has now made it to CNN. Well done everyone. This type of thing is why the internet really is the great equalizer, the power is back with the people when we are able to come together and right the wrongs that have been committed.

    Bookmark this post:
    StumpleUpon DiggIt! Del.icio.us Yahoo Technorati Reddit Google

    February 16, 2009

    Kenny Glenn Caught...

    Yesterday a kid in Oklahoma decided it would be a good idea to wake up, and with a friend record him torturing a cat and then post the video to YouTube, this would make him cool right? Wrong!

    What Kenny Glenn did not expect was the wrath of the Internet coming down.

    The Internet is a powerful place. A place where those who do good and bad on a daily basis come together at times when a single enemy has emerged. Last night, that enemy was Kenny Glenn, and no one held back.

    Within hours, his name, address, phone number, school, parents phone numbers, dads business phone number, maps to his house and constant updates were up on their own web site kenny-glenn.com (web site has been taken down, probably for the kids safety.) People were enraged, and these people have the know how to get things done.

    How did they find Kenny? The were able to locate the kid via MySpace based on his YouTube user info, they then verified the information because he had some pictures up which showed enough of his house to match with what was seen in the video. His gross green carpet, a drum set, a strange window, and a confederate flag. From there, is was only a matter of a little investigating to get all of his personal information. It was like a game to these guys, and trust me when I say they had fun doing it. The boards were lighting up last night, updates faster than most could read them. Some updates were solid info about the kid and family, verification of information, work some of the best private investigators in the world would take hours or days to do was being done in minutes by an Army. So to gents at 4chan and the DGers who made this their personal mission, good work.

    Sine the uproar Kenny was taken into custody, released back to his parents, and from the info I have is set to meet with the DA on Tuesday to determine the charges.

    I wont link to the original video because it really is painful to watch, I'm not exactly a cat lover, but this kid deserves everything he is going to get. So let this be a warning for everyone out there who thinks they can be anonymous, who thinks no one will know it was them, be careful. There is an Army out there who love nothing more than to ruin pieces of trash like this.

    Oh, and Dusty the cat is ok. He was removed by the sheriffs department last night and taken to vet for treatment. Kenny on the other hand is going to be miserable for a while...

    YouTube Video of a local news report

    Lawton news (site is slow to heavy traffic)

    Bookmark this post:
    StumpleUpon DiggIt! Del.icio.us Yahoo Technorati Reddit Google

    Woman Sues Microsoft Over XP Downgrade Charge

    PC World has published an article about a woman in Washington that has decided to sue Microsoft for charging users who purchase computers with Windows Vista a downgrade charge if they want XP installed.

    Her argument is that Microsoft is being unfair because they are forcing people to buy Vista if they want XP, because XP is being discontinued. Because of this, she things they should give her XP for free since she is buying vista.

    Lets remove Microsoft from he equation, and pretend its another piece of software. Lets say Adobe release Version CS4 of Photoshop, with CS4 do you get CS3? CS2? no, absolutely not, you get CS4. If there was something you wanted in CS3 that's not in CS4, you pay the money for the older version (and they don't give a discount)

    Microsoft is charging just under $60 dollars as a downgrade fee. They do this because now they not only have to give you a copy of XP, they have to continue to manage the licensing for it and provide support for it. I think this is very reasonable.

    Also, the women fails to realize that a product manufacturer is allowed to discontinue any product they want, regardless of level of demand, so saying but people hate vista, and want XP" is not a legal argument for them to allow people to just buy XP.

    As an IT company, we buy these downgrade rights all the time for clients. Many don't want to move to Vista on new computers because they want to keep all of their systems running the same OS and they don't want to pay to upgrade 40-100 machines to Vista since they have no reason to. This makes sense to me. Smaller companies who are just getting started and are buying new company computers buy all Vista machines, because Vista IS a good operating system despite what all the people who have never given it a shot have to say.

    The bottom line is, if you want a piece of software, you are paying for it. If the only way to get it is packaged with something else, that's a manufactures decision, not yours. What's next. Apple getting sued because I need to use iTunes if I want to upgrade the software on my iPod?

    Read the full PC World Article Here

    Bookmark this post:
    StumpleUpon DiggIt! Del.icio.us Yahoo Technorati Reddit Google