Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Tuesday, June 15, 2010

ALERT: Some Customer Info Exposed by ATT, This Is New (Not Last Week's iPad Episode)

Apparently, some folks who tried to sign up and pre-order this upstart...cough, iPhone, cough, four...were greeted with data that really shouldn't be there.

This is the second episode in the last couple of weeks where ATT didn't take their customer's data and privacy seriously.  Last week, hackers (who claimed they did it for the good for the world or so they said, FBI investigating) exposed the e-mails of some iPad owners.  Hard done but not the end of the world.

However, an independent contractor blamed a rollout of servers over the weekend.  What's worse is that some customer who log in ended up with information of another customer.

So, be aware, folks.  Now, the contractor is telling folks not to upgrade because of this.  I don't see the problem of upgrading (provided you can access the sytem on this crazy pre-order day for the iPhone 4) since the exposure is going to happen no matter what.

Still, watch out for funny activities.  I can't say Apple is happy with this latest episode.

Note:  for folks who pre-ordered the iPhone today like I did, no credit card information was taken down.

More at Daily Tech.

Saturday, October 11, 2008

Wi-Fi Security Cracked - Must Read

A Russian firm used Nvidia's graphic cards, capable of doing the brute for calculations required for just this task, was able to crack through Wi-Fi's WPA/WPA2 encryptions.
A while back, there were stories of how cartels or criminal organizations can hook up a bunch of PS3 together to break bank securities or other network securities.  I haven't heard much about it since but I'm sure like everyone else, we have taken Wi-Fi security for granted and now, with parallel processing much easier, Wi-Fi security is not as secure as we think.
Now, this is not to say that we no longer will be able to use our wireless routers at home.  I doubt there are roving gangs of high-tech hackers targeting individuals.  According to SC Magazine , Global Secure Systems believes companies should elevate their Wi-Fi security to using VPN.
Nevertheless, the fact that someone can use a standard PC with graphic cards doing this is somewhat amazing, don't you think?  I don't know how much the rest of us average mobile warriors have to worry about this.  Most of us with our home networks are not likely to be targets of corporate espionage.  And if you think you might be, I expect you to be using VPN.  If not, best to do so.
I think it won't be long before even consumers will be offered more higher grade security solutions.  Is that necessary?  Would you consider upgrading?  
Note:  Makes you wonder how secure WiMax and 3G is.

Wednesday, September 24, 2008

Mobile Tip: Securing Your Passwords On The Cloud

This is how I currently remember passwords to new accounts and some old ones that I hardly use:  I write it all down on a notebook in a secret place in my work/office at home.  Shhhh!

But there are other ways and I came across one today that works well for mobile warriors from WebWorker Daily .  It involves using a password program called Password Safe for Windows and Password Gorilla for Mac, Windows, and Linux.

Heck, you can use those programs as it is if you're on one computer.  However, if you're truly mobile and you travel quite a bit or work across different systems, there another step you'll need to take.  So, using a password program is step one.

Step two:  WebWorker Daily uses dropbox. Why?  Because they encrypt the files you upload. Since these programs produce a password file, you can upload the file and access them with these password programs from anywhere you work.  WWD also suggested using regular text file and let Dropbox's encryption protect you.  I'm not so sure about that.

And that's it.  It's quite simple after you set it up.  I really like Dropbox too.  It's cloud, something we haven't talked about in a while, and making sure you have access to your accounts wherever you are.

Note:  I also use 1password as well on the iPhone and Mac.

Also read Joel On Software for info.

Saturday, September 20, 2008

DHS: Attempt To Protect Our Privacy

In late July, we spoke about protecting your data against industrial and foreign espionage in light of travelers possibly going to Beijing for business or the Olympics.

Okay, the US government did not come out and name China but we all knew who they were talking about, our future industrial overlords.  Seriously.  Little did we know that similar things would also be taking place within US borders.

Essentially, we have to relinquish our laptop and any electronics with storage capability to border agents at their wills.  The following are Onxo posts about this serious matter:
Ars Technica has reported there is now an attempt to curtail this open-ended access to our data at borders, H.R. 8669.   We'll provide our own analysis after we review the bill in more detail.  So, what will it do?  It won't stop such searchs and seizures.
  • Rules on information security - imagine the nightmare of that "oops, I lost my government issued laptop" excuses or unsecured servers.
  • Days a device can be detained.
  • Ability to report abuses.
  • Owners of data or devices may be present during searches.
  • Impact studies in privacy and civil liberties.
As toothless as this bill is, we are in an election year and no one will want to appear weak in light of patriotism and national security issues playing promptly in the hotly contested Presidential race.   It's interested the sponsor, Loretta Sanchez, a Democratic in the Republican stronghold of Orange County in Southern California, did this during her own re-election.

Pretty gusty if you ask me.

Wednesday, August 27, 2008

ISS Laptops Catch Computer Virus

Talk about mobility.  It doesn't get any more mobile than taking your laptop onto the International Space Station.  Nor is catching or bring a computer virus up there.  Wired has reported that two laptops aboard the ISS has caught a computer virus.


You'd really have to wonder with all the security involved, how this can happen.

Sadly, this is not the first time.  More than that, NASA, at least publicly, is not calling this a big problem.  Privately...

According to NASA, everything is scanned before it's allowed to go up to the ISS.  A storage device, as it may be the case here, was taken up there without being scanned or authorization. Both possibilities points a great lapse in judgment and likely violation of protocols to the greatest degree.

Regardless, if this can happen to astronauts more than 200 miles above Earth, it can happen to any of us.  I'm sure the Mac guys should have a field day with this one.

Friday, August 22, 2008

VP Pick Via Text Messaging

Just want to pass this along.  Regardless if whether you're are a Senator Barack Obama supporter or a Senator John McCain supporter, this is kind of exciting and as far as we know, the first.  


Senator Obama, the presumptive Presidential nominee from the Democratic Party, has decided on his running mate but is trying to keep it a secret and wants only YOU to know first.  You and thousands if no millions of folks who signed up with his campaign on the Internet to receive updates through text messaging.


The name of his VP candidate will be text out in the next 24 hours.  If you're interested in this historic occasion, you can sign up to get the text message here.


It's just something to do if you've got nothing else going on this weekend...you're chilling by the pool and bleep!  You pick up your Sidekick, iPhone, and/or Blackberry.  Oh, Obama pick...

Update (12:50PM PST):  There are going to be quite a few updates between now and then.  All of them fake.  Look at the address to make sure you're getting the real thing.  CNN reports.
Note:  Onxo is not endorsing anyone.  But from a mobile stand point, this is just a glimpse of what the future will be like in politics.  Want to vote with your mobile device one day and forget about those hackable election boxes?  Could happen!

Friday, August 15, 2008

Could Thursday Be the New Friday?

For a lot of mobile workers, it may not be as pertinent nor will it like catch on like the latest fashion or social trend.  If you have heard, certain schools and cities are beginning to experiment with 4-day work weeks to save on rising energy costs.
Has anyone realistically given them any thought?  Wow, four day work weeks.  Three day weekends.  It does sound great from the perspective of the workforce.  However, I'm not sure things will work out as we like it to be.
We don't suddenly end up getting paid more for working less.  We are still working 40 hour weeks with longer days.  So, how does this affect the mild-mannered mobile folks?
I like to think we enjoy the longer weekend like everyone else but with our mobile devices with wireless access, we are forever tethered to our offices, data, and work in general.  Try telling your biggest client that you did not get back to him because it's the law that you don't work on Fridays.
Yeah, he'll be most understanding.  
So, how would we adjust?  It's really difficult to say right now because we don't have a large percentage of the workforce with such a four-day work week.  I imagine companies and governments would have to made adjustments to workforce scheduling.  Some may have Fridays off while other may have Mondays.  Or even the middle of the week.  
Of course, this is will not be effective if the purpose is to save on energy costs.  It's likely we may still have a 5-day work week but with more people working out of their home one or two days out of the week.  
Maybe telecomputing is a more effective solution?

Monday, August 11, 2008

Changes in Mobile Habits

We are posing a short subject on gas prices as we change to a more digital mobile life.  When it was near $5 a gal here in Los Angeles, we were wondering if we were going to see $5.50 by Labor Day.

Thanks to our sense of self-preservation and dwindling bank account as cost of aspect of living rocketed, we decided we don't need to go out as much, eat out as much and, drive a couple of blocks to the supermarket.

How are mobile warriors coping?   I think in the long run, we will cope quite well.  A lot of us are now discovering public transportation and, yes, our legs are for walking.  Pretty neat, eh?  (I've picked up biking again.)

It is still a far-cry from seeing people waiting at bus stops or train stations like Japan where people are engaged in their web-novel or catching up on the morning news.  

When will we see that in the United States?  Los Angeles?  Will the new generation of smartphones and mobile platforms like the iPhone change all this?  

We've cut back in fuel use quite a bit, enough to cut the futures of crude future in the 140s a barrel to about $115.50 today.

Mobile buds, I think we can do much better.  

Saturday, August 9, 2008

TSA Approved Cases

As you may know, TSA has announced they are for checkpoint friendly cases to be used to help protect laptops and streamline the security process.  It was back in March that TSA began working with bag designers on how best to serve the public.

TSA has outlined the following criteria for the bag in their press release:
  • A designated laptop-only section
  • The laptop-only section completely unfolds to lay flat on the X-ray belt
  • No metal snaps, zippers or buckles inside, underneath or on top of the laptop-only section
  • No pockets on the inside or outside of the laptop-only section
  • Nothing packed in the laptop-only section other than the computer itself.
What has happened since?  Well, we've got the cases from a variety of manufacturers.  Here a few links from sources on the Internet about bags that are checkpoint friendly.  Keep in mind this is still early and unforeseen issues may pop up.
Onxo will keep an eye on other manufacturers as they become available.  There is no doubt this will put mobile warriors at ease a bit and having to take the laptop out and having an uncaring TSA agent treat your most precious mobile tool harshly.

Here is the direct link to Targus' Zip-Thru.

Thursday, August 7, 2008

Mobile Tip: OpenDNS with Phishing Tools

Previously on Onxo, we shared with you some common sense tip and discussion on phishing and cyber thieves.  What we neglected to explain what phishing is for some of our more novice readers.  Phishing is an attempt by cyber thieves through e-mails or false websites designed to look like the real thing.  It could be a bank or a shopping portal like Amazon.  They look and feel like the same thing except once you click on it, the phishers will attempt to fright or simply cordially ask you to divulge information that will allow them to steal from you. 

Popular phishing attempts can come from eBay, Paypal, or a bank.  So, what's new Onxo can offer now?  Well, not Onxo but an article from Macworld that introduces a DNS service called OpenDNS, a free service with phishing tools.  How does this help mobile warriors and other computer users?

Basically, most of us are using the domain name server provided to us by our internet service provider (ISP).  Domain name servers (DNS) is an address book for the Internet.  Without getting into it much more, you can use the servers from OpenDNS with phishing protection that helps is always up and running and sorts through the DNS that are responsible for a lot of phishing activities.

Macworld, and Onxo agree, that this is a very valuable tool to have against cyberthreats and works with all browsers including Safari that was decried by Consumer Reports for not having phishing tools. 

What it all comes down to as we have said is common sense.  Most services will not ask for logins, passwords, and social security numbers directly over the Internet and if there is an issue, I've always found it prudent to call customer service to resolve it. 

Let us know if you're going to try OpenDNS and how it goes.

Note:  OpenDNS counts UPS and Kaiser Permanente as its customers.  Also, if you need help setting it up, Macworld has a simple guideline for OS X and OpenDNS has their own set of help at their support page.  For me, when I need help, I call my friend Dave but I was able to handle this one on my own. 

Wednesday, August 6, 2008

Mobile Safety for Your Data

While many of us have system protection such as antivirus, software or hardware firewalls, and or something like Norton Internet Security.  I've always been the paranoid type but as a Mac users, some of us may have bought into the idea that we're safe from hackers, viruses, and other forms of attack from the mean streets of the World Wide Web (kids, that's what the www stands for, yes, the Internet has been around for a while).

About five years ago, I walked into an Apple store to buy a script writing program and I was surprised to see Norton's anti-virus for the Mac.  I asked the Apple guy helping me and he chucked and said, "don't get it.  It's a waste of money.  Unless you want to get it to protect your Windows friends".  I had thought that was kind of funny myself and that comment has always been with me.  I used it on occasion when a hapless friend would get a virus.

What it really comes down to as far as protecting our data and mobile devices is that white stuff in our head, our brain.  Our smarts.  No amount of virtual fortress can be installed if the user insists on letting in invaders.  Phishing is the most common way in which consumers are duped into willing give up their personal information to cyber criminals for identity theft.  According to Consumer Reports, one out of every thirteen households willing gave their personal information to thieves.

A surprising fact is the lack of phishing protection (Computerworld) on some OS such as the OS X for the Mac.  It has lead to Consumer Reports to recommend to Mac users to use Firefox as an alternative.  We've received countless e-mails from supposedly banks asking for account information for a variety of reasons.  And once in a while, e-mails would come into our spam box proclaiming to have naked pictures of one celebrity or another.  I can see how someone may be tempted to click on a variety of these spam mails, especially the ones from the "banks" claiming account verification is needed because of suspicious activities.  (The Nigerian princes seemed to have found their fortune because I've not heard from them in years.)

  • You've got smart, so use it (we know because you're reading Onxo ;)   )  If an user insists on clicking through a phishing e-mail and providing information or visiting an unfamiliar site that may download malware onto his or her system, no amount of protection can prevent what may happen next.
  • Onxo has made it a point to tell users to avoid sites readers are not familiar with.  
  • Do use a virus protection or at the very least, turn on the software firewall that comes with the operating system.  It is better than nothing.  
  • Do not asssume a Mac is immuned from the bad elements of the Internet.  OS X may not be affected by Windows viruses but it is not immune to Mac-specific trojan horses.  There was a couple of reported incidents.  So, yes, it can happen.  
  • Scanning the hard drive can be a drag, as it takes a long time and slows down the system.  Nonetheless, it is important to do it.  It a part of our lives.  
Windows Vista users have reportedly experienced less incidents of attacks than users on the XP.  According to Computerworld, it may simply be an instant in which users find Vista difficult to navigate and, thus, more careful on the Internet.

Bottomline, you are all that is between a cyber thief and your personal information.  If there are any personal habits mobile warriors employ to avoid phishing and safe-guard their personal data and information, we like you to share it with Onxo and our readers.

Tuesday, August 5, 2008

Mobile Tip: Take Your Mobile Devices With You At Time

I've done this before.  Leave my backpack in my car thinking I won't be long.  All the while, I worry if I'll see my Apple laptop and data and all my research material.  Folks, the economy ain't what it used to be.

Take heed from this poor unlucky man who had his bag with his Macbook and registeration stolen, car vandalized, and sense of security and well-being violated (Powerpage.org).

I don't ever want this to happen to me and I don't want it to happen to my dear readers.  Nor anyone else.  But it is bound to happen and it likely will at some point in our life.  At least if it happens, no one gets hurt.

Anyway, Chris, the man who had this happened to,  has some recommendations for us:
  1. Take your backpack with you.
  2. If you must leave your valuables in your car, use the trunk.  I've got tinted windows and at times, a tower I used at the gym.  I cover my backpack but really, the trunk or if you've got a SUV, the space behind your backseats.  If there is a cover, use it.
  3. Show no evidence that at any point do you have electronics in the car.  The suction cup marker is a dead giveaway and thieves could care less if they see your GPS or gadgets through the windows.  If it's enticing and convenient, you're asking for it.
I've got a couple of recommendations myself.  There is no such thing as a safe neighborhood.  In this economic state we're in (the United States), do not assume "it's safe".  I live in a relatively nice city but local papers have reported sharp increases in robberies and houses and vehicles have been broken into at a neighboring city because of its higher income residence.

Also thieves recognize the white buds of the head sets.  If you know what that means, so do muggers.  It's almost the same as brandishing to the world you've got an iPod or iPhone.  Get a cheap set if you have to.  It should help.

Also, if keep that old laptop.  It might be worth it to bringing that instead your brand new Macbook on some trips.

One more thing:  Always check your six.

Wednesday, July 30, 2008

Cyber Threats: Just Some of the Time?

I recently read a WSJ report, about cyber security in light of the Olympics.  For some traveling to Beijing for the games, as spectators or those seeking business opportunities, they may take with them laptops, smartphones, or digital storage media.  Pay attention.

WSJ reported that a debate had taken place whether to warn the public of the danger posed by Chinese hackers.  Let me put the debate to rest.  I'll do it here and now.  Okay, it's public.  But shouldn't cyber security be a year round threat and not just during the Olympics in China?

And it's not just Chinese hackers we need to be wary of.  How about being wary of hackers in general?  Despite the paralysis suffered by the US government on this issue, the Department of Homeland Security has issued warnings of cyber threats against mobile workers who travel overseas.  Because the threat was not specific, this alert was not made public.  


The WSJ article came out before it was made public of the IOC's deal with the organizers of the Beijing Games to allow the Chinese government to implement Internet censorship it deemed not related to the Olympics, cutting off thousands of journalists off at the knees.  

Somtimes bloggers to reprint materials from other sources, I have reservations about copyright ownership.  So I will offer links to pertinent information instead of posting the relevant information here.  I apologize for the inconvience :)

I've included the Homeland Security assessment here.  I hope WSJ will make this perpetually available to the general public.  It is a 3-page PDF file that described key finds as follows:  foreign powers targeting Americans traveling abroad with the goal of fathering "economic, military and political information".  Essentially, viruses, trojan horses, or exploitations of any security holes will be pursued to that end.  Even trickery.  

I think the report is right in not mention any specific foreign state or body that poses as a threat.  This is not just a matter of the Olympics because cyber security threats exist all year around all over the world.  Here are the highlights of the report:
  • Travelers are to assume that they will be unable to protect their data that they may transmit over the Internet.
  • Expect no privacy.  You're always a potential target.
  • Expect all transmission to be intercepted.  
  • Expect viruses, malware, and spyware to be installed at all ports of electronic access - cafes, hotels, etc.  And expect all portal media to be infected if they were connected to to these access points.  
  • Assume foreign authorities may find an excuse for inspections of laptops or portal media for the sole purpose of copying information.  
I stated those main points to highlight what a mobile worker could be up against.  The later part of the report, "protective measures", offer tips on what to do to avoid being a victim of information theft.  The gist of the report recommendation is this:  use common sense.  
  • If you don't have to bring your laptop overseas, leave it at home. 
  • Assume your portal media is infected with malicious software.  Plug it into your network back home can make things worse.
  • Use the best encryption available to you to protect your data.  
While I generally believe in our government's ability to provide for the common defense and against terrorism, I believe it our duty to be pro-active in matters where it's within our control.  I hope the information and guidelines help you protect your data whether you're a mobile warrior in the private or public sector.


The US Cyber Consequences Unit also offered a similar guideline to protect your data.  They help you assess whether you are a potential target of cyber theft, how to do a presentation without a laptop, and how best to secure your portable devices.  Also for your consideration:


I understand the sensitive geopolitical nature of making such an announcement so close to the Games.  I'll leave the politics to the politicians.  Luckily for the rest of us, we don't have to worry about that.  

Apple Should Prepare to Leave China (There Is Still Time To Execute Such A Plan)

At first glance, you might think that the title of this article is a clickbait considering that China is the second biggest economy in the w...