Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Thursday, October 29, 2009

Facebook's Iron Curtain of "customer service"

One irritant about Facebook's management and minions is that they do a really thorough job of remaining behind an electronic Wall Of Invisibility, much like AOL always did.

Need an answer to a question about how Facebook works, or, as in my present case, whether a "change-your-login" email that I'm getting is spam or really from them? Get ready to spend lots and lots of all your free time being steered through pages and pages of other users' answers to anything that resembles your question.

Would it be too much to ask for more authentic Help Center texts written by employees who know the answers to these questions, as opposed to everybody guessing — and their guesses given approval ratings by other guessing users?

Okay, I realize it's free, and I'm sure that's their explanation. But the question here is one that would seem to potentially affect the security of the community at large, since enough "phishers" could cause us to start questioning who's behind any given face on FB, and whether they're trying to turn our computers into nodes on the hacker botnet — no small matter there.

I've been getting this message in my own email, looking every bit the routinely formatted FB type, every day for the last several:

>> SUBJ: New login system
>>
>> Dear Facebook user,
>> In an effort to make your online experience safer and more enjoyable, Facebook will be implementing a new login system that will affect all Facebook users. These changes will offer new features and increased account security.
>> Before you are able to use the new login system, you will be required to update your account.
>> Click here to update your account online now.
>> If you have any questions, reference our New User Guide.
>> Thanks,
>> The Facebook Team

The message looks just like and is FROM the same "@" address as legit 'friending' notices and replies to threads I'm, uh, stitching with. But the link at "Click here" goes to a specific spot at a fishy address, "www.facebook.com.mibbbah.co.uk/", and the genuine-looking "Update" button they helpfully include goes to yet another site across the Pond, "www.facebook.com.fasazae.eu/", etc. And I received no mail or message from within FB about it.

So I just spent way too much time fishing around in FB — at least I think I'm signed in to the real one, he remarked drolly — trying to find some place to read about or report this pretty sophisticated con. But it's a lot like knocking on the door and hearing a voice from inside say, "Nobody's home! Go away."

Related, here:
Posts tagged "Great Customer Service"

Wednesday, November 05, 2008

Barack Obama, President-Elect of the United States(!)

First of all… Whew!

If you write, you kind of have to write on a day like this, an historic occasion if ever there was one. Like the fall of the Berlin Wall, this is something I never thought would happen in my lifetime, and it is due both to the moment and, significantly, to the extraordinary character of Barack.

Maybe it was close earlier, maybe the Democratic candidate would have won anyway just on the strength of being the Anti-Bush, but there were two factors that decisively tipped it Obama's way. McCain's choice of the beauty pageant queen for his VP did send the hearts of the faithful to flutterin', but once revealed in Katy Couric's pivotal interview, Mrs. Palin caused everybody else to seriously doubt his judgment, and turn even conservative stalwarts like Christopher Buckley (William F.'s son, no less,) against him.

The other, less self-inflicted blow (given his legislative participation in the debacle,) was that little dust-up recently in the markets, the timing of which turned out so poorly for his campaign. Once again, It Was The Economy, Stoopit.

Note, though, that the all-but-complete count as I write this is roughly 53 million Democratic votes vs. 46 million Republican. That many people, a little over 46 percent of the voting population, voted for the maverick military-man version of the same old thing.

So how wise has it been of Obama, even through his victory speech, to strike a conciliatory, inclusive tone, recognizing the strong, deep differences that divide the people in this country, even as we face the same set of problems -- excuse me, "challenges." (Because it turns out, it actually does make a difference how we phrase these situations to ourselves.)

Yes, I got the chills, again, from his acceptance speech, especially when the crowd kept calling back, "Yes, we can!"

Some favorite views of the day:

History in the making: News headlines across the US - slide show, Boston Globe

Reactions from around the world - slide show, Huffington Post

World welcomes Obama with open arms, demands - Amanpour, CNN.com

What the world expects - BBC correspondents

Tuesday, November 06, 2007

Predators In The Televised Bushes (Tracing Back To Root Causes)

We tend to think of ourselves as "highly evolved," but while our mental world and all the technology we cook up with it has certainly evolved very speedily over the last, say, 100 to 150 years, our body and the back of our brain is still far behind. I think this fact goes a long way towards explaining how confused we are as a species, mostly clumsily crashing our way through life on this planet...

One day, watching some poor band of musicians trying in vain to compete with a couple of television screens just off to the side, I was once again troubled by the fact that I seemed unable to ignore the (stoopit) TVs. My gaze repeatedly switched to the screens, and away from the performance of the real, living, breathing bioforms that I was trying to watch.

Finally, it occurred to me that the reason we are virtually unable to ignore a flickering television, our eyes drawn to it unwillingly again and again, is due to the part of our brain, still very much active, that is always on the alert for any activity in our peripheral vision -- because it might be a wild animal in the brush, measuring us up for a snack.

So I was mightily interested when I came across the same thought applied to a different sense, in, ironically, a blog on a subject that almost could not be more contemporary or "highly evolved," that of digital musicmaking.

The post in Create Digital Music is titled, "Windows Sound Glitches Explained, Plus Glitches and the Fight-or-Flight Response" (11/2/07, by Peter Kirn).

"Your ears and mind are incredibly sensitive to tiny details of sound. Result: if your operating system can’t keep up with sound output for any reason, you’ll get a noticeable “glitch” in the sound — and that’s a big deal. "Microsoft has a great post on their Vista Team Blog today from Steve Ball --

'My colleague on the Windows Sound team, Larry Osterman, also pointed out to me recently that humans are actually “hard-wired” to be disturbed by audio glitches. In an exchange about this topic, Larry observed that audio glitches are more obvious than video glitches because the ear’s tuned to notice high frequency transients — his visceral example of this idea is an image of a stick snapping in the woods behind you as an audio event that wakes you up before a bear wanders into your path.'"
So, it's not that we are so dreadfully unfocused and ADD -- although we most certainly are -- it's more because the base of our brain is still executing a seldom-needed Primary Directive. Unless you live in a big, dirty city, in which case it's just doin' its equally contemporary job.
(Photo on Flickr by Edgar Thissen)

Friday, April 20, 2007

Crackberry Down!

Regarding last week’s post questioning the readiness of the Internet and it’s related ecosystems for Web-only applications:

I thought the 12-hour Blackberry outage Tuesday night illustrated my point in a perfect and timely fashion, although I’ll concede that its users/fans/chattels may find it difficult to find any redeeming qualities in the blackout. Blackberry users had comments (in the Reuters article in eWeek) like, “"I felt like my left arm had been amputated," and the story says that “one Wall Street analyst said she kept hitting her BlackBerry's version of a ‘refresh’ button in disbelief that the system could fail.”

It's looking like I won’t be able to resist quoting a criminal defense lawyer in New York named Charles Ross (though no relation), who said the outage left him feeling "vulnerable and uncomfortable," and that is caused him to miss breakfast! (Okay, “a breakfast appointment.” It only sounded like these people were being denied basic sustenance.)

Now it turns out that all it took was an insufficiently tested routine system upgrade (“to provide better optimization of the system's cache," according to RIM. Appropriate, perhaps, since that upgrade's sure to cost them some extra cash). That’s great – I’m sure if it was an all out criminal-hacker assault, they would have handled it much better.

So, now how do we feel about depending on the Web for even more of our most basic applications? Let me hasten to note that Web apps are a great idea in theory, and probably an inevitable evolution, but that we are (i.e., the Internet is) just not ready for it yet.

RIM explains its BlackBerry outage
Cascading software and system problems caused interruption”
April 20, 2007

A Night Without 'CrackBerry': Curse or Blessing?”
Reuters, by Franklin Paul, via eWeek - April 18
Related, here:
"Baaack it up!" * (Before the Botnets get it) 1/15/07

(...which featured this quote from a Carnegie Mellon computer scientist:
‘The war to make the Internet safe was lost long ago, and we need to figure out what to do now.”)
"A Working Simple System" - John Gall

Tuesday, February 06, 2007

Releasing the spiders, & letting Boston off the hook

Technorati Profile
(They have you save a post with the above link for signup confirmation; finally decided to join and get in the swim of it all, after having been weblogging for almost a year now.)

Hey, don't blame me for the spiders in the title -- that's what the button in Technorati says. Being in a town that just had a 2-million-dollar cow over boxes with flashing lights under bridges, one can't be too careful with what you say these days.

Listen, while we're at it, go easy on Boston over this one, alright?, despite the fact the same promotion went off without any fuss in all the other major U.S. cities. Remember that two of the planes of September 11th took off from Logan airport, and that we get these LNG supertankers in Boston Harbor, and that makes you kinda nervous.

Just as when I was obligated to wait on line last week to then hurriedly disrobe and empty my pockets to get on a flight, we've got to be ready and willing to put up with all the hassle that comes from erring on the side of caution. (Why, they even took away my aloe vera gel -- I was unwittingly carrying more then three ounces.)

In my case, I had a small reward: at the Newark airport, I turned around to find none other than Bill Russell standing behind me(!) It was 6:30 am, and he plainly was not ready to start talking to anyone, so I just told him, "Mr. Russell, it's an honor."

No sooner had the words left my mouth than someone from the airline came up to escort him around the interrogation line, which I thought was only appropriate for such an accomplished and principled gentleman.

Excerpts from his 2001 book, "Russell Rules : 11 Lessons on Leadership from the Twentieth Century's Greatest Winner"

Monday, January 15, 2007

"Baaack it up!" * (Before the Botnets get it)

Here’s one of the most ancient and didactic of the sacred injunctions of Computerdom, but one which potentially carries an even greater urgency for us now:

MAKE BACKUPS OF ALL YOUR VITAL INFORMATION --- Today

(How boring, I know: it tends to fall into that same bin with your dear sainted Mother telling you to clean up your room, or to stop doing whatever it was that you kept doing that just really drove your mother up the wall. But it’s one of those simple essentials we all know is true, yet somehow still need regular reminders to do.)

What sparked this particular ringing of the alarm was a positively scarifyin’ article by John Markoff in the New York Times last week, on the “Attack of the Zombie Computers” (which, damn, they've already archived and are charging for).
===

Botnets -- programs that secretly install themselves on perhaps millions of personal computers and band them together into a network to commit Internet crimes – “are being blamed for the huge spike in spam that bedeviled the Internet in recent months, as well as fraud and data theft. Security researchers have been concerned about botnets for some time... what is new is the vastly escalating scale of the problem."

"A security researcher analyzed the information contained in one 200-megabyte file that he had intercepted. The data came from 793 infected computers, and in a 30-day period, it generated 54,926 log-in credentials and 281 credit-card numbers, affecting 1,239 companies, including 35 stock brokerages, 86 bank accounts, 174 e-commerce accounts and 245 e-mail accounts."
That was in one file.
Said “David J. Farber, a Carnegie Mellon computer scientist and an Internet pioneer, ‘It’s an insidious threat, and what worries me is that the scope of the problem is still not clear to most people.’ Referring to Windows computers, he added, ‘The popular machines are so easy to penetrate, and that’s scary.’”

“The consensus among scientists is that botnet programs are present on about 11 percent of the more than 650 million computers attached to the Internet. A computer security researcher… who coordinates an international volunteer effort to fight botnets (said,) ‘The war to make the Internet safe was lost long ago, and we need to figure out what to do now.’”
Let’s revisit that last statement: “The war to make the Internet safe was lost long ago.” You know, just a moment of consideration of this concept, assuming it’s credible, must give one pause. We could quite possibly wake up one day and find the Internet down. Really down; brought to its knees.

But you don’t need the Web to crash for it to be a disaster; it could be your own personal information swiped from your computer, or the system of a company you’d entrusted some juicy bits to. Perhaps you’d hear a lonely whistling sound, as the breeze blew through your empty bank account.

I really don’t think this is alarmist in any extreme way. “Shift Happens.” We’ve just got to be truly prudent, and create our own backups. Then, if the unimaginable does occur, you can say, with considerable relief, “Well, at least I’ve got a copy of everything.” (That might be handy if you had to go to court to get your money back from the bank, for instance. You know, the one that charges you $35 for any oversight or slip of the pen?)

Protecting the data on your machine is just the start. For example, I’ve got one bank account that I use (sparingly) to buy things over the phone or Web, but I just leave a little in there, and the bulk in other, disconnected accounts. It’s not foolproof, but it lessens the odds of potentially getting thoroughly cleaned out in one swell foop.
===

Related, here:
"Hey, NYT, What About Fair Use?"
===
* - “Baaack it up!” Couldn’t resist quoting the anonymous garbageman who woke me with this cry every early morning, numerous years ago, as he guided his truck in backwards to pick up the refuse from the restaurant I lived next door to.
(That was “Maddies,” for you Marbleheaders, which is actually named “The Sail Loft.”)

Tuesday, September 19, 2006

“How to Hack an Election in One Minute”

September 13: Princeton researchers release a study and video detailing their successful attempt to hack the widely-used Diebold AccuVote-TS electronic voting machine. (Oops.)

“The University's Center for Information Technology Policy (CITP) is not the first group to demonstrate the vulnerability of Diebold's machines,” says the article in MIT’s Technology Review. “BlackBoxVoting.org, Open Voting Foundation, and Johns Hopkins professor Avi Rubin have all published accounts of security compromises in Diebold products. BlackBoxVoting.org wrote about their successful guerrilla project to swap out a Diebold voting machine's memory card using $12 worth of tools in four minutes (the Princeton team says it can execute its hack in one minute).”

They had three main findings: “First, the CITP group discovered that not only could it install malicious code on the voting machine, but also that the code could easily be configured to ‘disappear’ once its work was done,” leaving no trace of tampering.

Second, it was easy to physically hack into the machine to get at the removable memory card that stores vote counts.

Third, "By planting a virus far enough in advance, [a hacker] can ensure that a significant number of machines can steal votes on election day" even if the criminal had access to only one voting machine.
(“Criminal”? That’s pretty harsh, isn’t it? They'd probably prefer the term, “political operative.”)

That’s the thing about relying on technological solutions – you can always flip a couple strategic bits and come up with an opposite effect ('"A Working Simple System').
'Security Analysis of the Diebold AccuVote-TS Voting Machine'
By Feldman, Halderman, and Felten of Princeton's CITP

Technology Review is owned by the Massachusetts Institute of Technology (MIT). “The oldest technology magazine in the world (est. 1899), Technology Review aims to promote the understanding of emerging technologies and to analyze their commercial, social, and political impacts.”

Sunday, August 27, 2006

Public Web Surfing Advisory

Since we're on the subject of personal digital security, here’s another tip to consider. The New York Times ran a piece on the wide open Web surfing that’s available at your local wireless hotspot. That is, all your communications and actions on the net wide are potentially open to whoever has the inclination and the equipment.

“Although obsessing about computer security is a bit like worrying about a toddler — potential hazards lurk everywhere and you can drive yourself crazy trying to avoid them — the fact is, business travelers take certain risks with the things they do on most trips.”
(Thought that was a great quote.)
“’Where I’d draw the line is putting in your bank account information or credit card number,’ said Robert Vamosi, a senior editor with CNET, adding that ‘checking e-mail messages probably is not that risky,' and you can always change your e-mail password later.

"Wireless networks at airports, hotels or cafes are not as secure as most people think. 'Someone may have software on their computer that allows them to look at all the wireless transactions going on around them, and capture packets floating between the laptop and wireless access point,' he said.

"Last fall, InfoWorld magazine published an article about a security researcher who managed to collect more than 100 passwords, per stay, at hotels with lax security (about half the hotels she tested).

"…Access to your corporate network through a V.P.N., or virtual private network, (is) safer than using public hot spots. There are services you can subscribe to for about $10 a month that do the same thing."

"Web Surfing in Public Places Is a Way to Court Trouble"
(This may require free registration to read)

By SUSAN STELLIN, NY Times
Published August 22, 2006
.
But in a show of faith in the medium, I am boldly posting this from a public wi-fi spot. Go, Tech!
===

A good little wireless hotspot locatorboston.jiwire.com
…although I chanced across a place yesterday that didn’t turn up in their listings, your traditional, Mom ‘n’ Pop Internet cafĂ© along Fort Salonga Road. On balance, though, very useful.
===
(Editor's note: oh, how that headline yearned to be, “Web Surfing Naked in Public” or the like, but that would be a cheap shot, wouldn’t it? Just wanted to let you know what we didn’t do, so you could congratulate us on our great dignity and reserve.)

Saturday, August 19, 2006

Getting Closer to Microsoft (for purely defensive purposes)

“Deluge of flaws” being found in Office

You are not going to see much in here that’s all warm and fuzzy on the subject of Microsoft, or even particularly friendly. But let’s be practical, everybody uses their stuff. And it’s because of that fact that this is bulletin is important, nay, crucial.

Ziff-Davis’s E-Week reports that:

"What started as an amusing eBay listing of an Excel vulnerability for sale has developed into an all-out hacker assault on Microsoft Office applications.

"Security researchers and malicious hackers have zeroed in on the desktop productivity suite, using specialized 'fuzzing' tools to find a wide range of critical vulnerabilities in Word, Excel and PowerPoint file formats."
("Fuzzing tools”? You mean, marketing? No, eWeek explains,)
"Fuzzing, or fuzz testing, is an automated technique used by researchers to find software bugs."
The article points out that as Microsoft (belatedly) got serious about security vulnerabilities in Windows, hackers and hence security researchers have moved up the software ecosystem to go after “the low-hanging fruit” in applications. Well, there ain’t any bigger trees in the orchard than Word, Excel and Powerpoint, which were originally put together with the same oblivious attitude to security as the OS.

In short, what this means is that in order to keep our lives simple, we’d all better keep in touch with all the bug fixes, "service packs," etc., for Office from the E-Empire. (That “E-“ is for “electronic” – no, honest! ; - )


(…half an hour later:) Oooh, boy, is my head spinning. Well, try this, bravely found by starting at microsoft.com, Gawd help us:
Security and Office: Find out how to help protect your data

This page was obtained by clicking Office under Product Families in the navigation column at left, then typing “security” into the search box. (I’m specifying all this as a disclaimer, since there’s an awful lot of stuff there, and who knows what’s the most recent and comprehensive.) There are, naturally, thousands of rabbit holes there you could disappear down, so if you’re a masochist with a week or two to spare, have at it!

Here's a case where you really might be better off hiring a professional to at least get you set up with this. (No, we don't do that; this is not a subtle sales pitch.) It'll cost you, true, but it beats the hell out of having your computer taken over by zombies, spending long hours trying to get it exorcised, and losing all your data (because few are those who back theirs up).

Just a sec -- here we need to say, BACK UP YOUR COMPUTER! This weekend! At least just copy all your own files onto CDs, preferably rewritable CD-RWs. (There, now you can't say nobody warned you, okay? And we've done our duty as digital citizens.)

How much do I hear for a hole in Excel?

That Excel vulnerability for sale on eBay was indeed pretty funny. eWeek's story on that explains,

The seller openly taunts the software giant, poking fun at the company's delays in providing fixes for known security bugs. "It can be assumed that no patch addressing this vulnerability will be available within the next few months. So, since I was unable to find any use for this by-product of Microsoft developers, it is now available for you at the low starting price of $0.01 (a fair value estimation for any Microsoft product)," the listing read.

"Microsoft representatives get 10 percent off the final price. To qualify, you MUST provide @microsoft.com e-mail address and MUST mention discount code LINUXRULZ during checkout," it added.