Wednesday, October 5, 2016

your money or your files are gone forever

Thursday, May 19, 2016

Friday, May 13, 2016

Now THAT’S embarrassing!


A goatse hosting site is hacked leaving users with their asses vulnerable (pun intended)

Reality. You can’t make this up. It’s so much better than any reality TV show.

A data breach at a forum for "anal fisting" has resulted in the exposure of 107,000 accounts. More than a third (37 per cent) of those affected by the Rosebutt Board were already included in the Have I Been Pwned? site, according to security researcher Troy Hunt. Victims will be able to use Have I Been Pwned? to check whether their data has been exposed once Hunt uploads the leaked data.

Info exposed includes usernames, email addresses, IP addresses, and weakly hashed passwords, Vice reports. Info uploaded to Have I Been Pwned? will be flagged as "sensitive" and not publicly searchable.

The Rosebutt Board caters to enthusiasts of “extreme anal dilation and anal fisting,” many of whom have been placed at risk of public humiliation or blackmail as a result of their sexual proclivities.

Not surprisingly, multiple .gov and .mil email addresses were exposed in the Rosebutt breach, Hunt reports.

Note: You know what this means, don’t you? After years of the government sticking it up our rear ends, it’s time for some serious payback!

Here’s the cherry on top
How often do you find this kind of synchronicity in life?

Right after reading the above news article, I turned to the Guardian. And what do I find? The 2016 Turner Prize shortlist features the sculpture of a man’s ass! Here’s the picture. 


Wednesday, May 11, 2016

More than just another brick in the wall

Sats answers published online...the second time in 3 weeks! Testing to go ahead despite leak

Pink Floyd's The Wall
News published by several media sources yesterday revealed that the Department for Education suffered a second major embarrassment after the answers for its Spelling, punctuation and grammar tests for 10 and 11 yr olds across england were published online.

When we grew up and went to school there were certain teachers who would hurt the children any way they could...

Despite the leak, testing would go ahead. A DfE spokesperson said the key stage 2 test of spelling, punctuation and grammar (Spag), which is compulsory for pupils in the final year of state primary school in England, would take place as planned but said its investigation would continue.

By pouring their derision upon anything we did and exposing every weakness however carefully hidden by the kids.

A whistleblower revealed to the Guardian that Pearson, the multinational education publisher responsible for administering the Sats, posted the tests a day early on a password protected site for test markers. According to the BBC website, a company statement said that "a small number of markers accessed the paper, although as contracted markers they are bound by confidentiality and have a duty not to share any papers. We do not have any evidence that the content of the paper has been compromised."

But in the town it was well known when they got home at night their fat, psychopathic wives would thrash them within inches of their lives.
John Fallon, Pearson CEO, said the company believed 102 markers had seen the paper in the four hours it was available. "Unfortunately, in this case we have made a mistake which we are very sorry for," he said.
We don't need no education.

The DfE said while the paper had not been put into the public domain, it appeared a "rogue marker" had then leaked the paper to the Guardian newspaper.

We don't need no thought control.

The new key stage 2 tests for 10- and 11-year-olds have also been widely criticised by teachers and parents who say they are too difficult for the age group. Last week parents across the country took their children out of school in protest at the tests.

No dark sarcasm in the classroom; teachers, leave them kids alone.

One experienced primary school headteacher said the new grammar tests would have stumped Jane Austen. “I have a degree in English language and there are a number of questions that I couldn’t answer,” she said.

Hey, teacher! Leave them kids alone! All in all you're just another brick in the wall.

Special thanks to Pink Floyd for a great album.

A new cybersecurity study reveals that…

Cybersecurity studies - how many does that make this year, 12...15?

No one keeps a secret for long
Has anyone noticed?

Almost daily we are being treated to the findings of yet another cybersecurity report designed (and not by accident, I might add) to scare the living bejesus out of us.

For some reason, everytime I see a new cybersecurity report has been released, regardless of its content, I am instantly transported back to that popular 80s arcade game, Pac-Man ━ that canary yellow, jaw-chomping, insatiable dot eater, whose 8-bit wakka-wakka wav sound file was the inspiration for Shakira’s 2010 World Cup Waka-Waka theme song, I’m guessing. OK, that’s not even close.

This Pac-Man, however, has my face on it and I’m being chased around an ever increasingly, difficult-to-survive, digital maze by 4 hungry little chomping “ware” ghosts - adware, malware, spyware and ransomware. Actually, any 80s arcade game is a great metaphor for today’s cyberattacks ━ Joust, Frogger, Space Invaders, Caterpillar, even Q*Bert ━ they’re all coming to get you, the hero, and you know that, sooner or later, you’re going to die. There’s no escape.

I may be wrong but it’s as if these reports are being released almost simultaneously with the news of some cyberattack. And that makes me wonder if somehow security developers might be in cahoots with code hackers.

I don’t want to belittle the gravity or consequences of these attacks ━ they are real. But it’s not surprising either that most of these cyberreports originate in the US, the masters of fear mongering. Americans live off fear; just look at their news and adverts. It’s how they make their money. They spread fear and get you to buy stuff. Erectile dysfunction? We have a pill; Weird, suspicious looking neighbors? We have guns; Fear of illegal immigrants? We’ll build a wall; Running out of oil? We’ll start a war somewhere. All you have to do is pay.

In fact, this heightened state of collective paranoia has reached such a fever pitch that, just this past weekend, a lady on a flight from Philadelphia to Syracuse reported to flight attendants that the person sitting next to her might be a terrorist because he was “writing strange things on a notepad.” It turns out the person next to her was professor Guido Menzio, an Italian economist working on some differential equations. I’m sure authorities at the Pentagon and NSA love this woman because she bought into the fear like a champion. To me, though, this woman just went off on a (sinα / cos α). In case you’re wondering, that equation translates to tangent. Hey, maybe I’m a terrorist, too!

So the big question remains. How do we sift through all the fear tactics with the least amount of psychological and emotional damage?

There are at least two ways. The first one is guaranteed to rid you of your fear forever. Live off the grid. Throw away everything electronic - TVs, phones, computers, cars, radios, watches, microwave ovens, trainers, etc. - basically anything with a chip in it, sell your house and belongings, buy a 60s or 70s vintage car, move out into the country far away from CCTV cameras, grow your own food and live free away from prying eyes, negative news reports, inane reality shows and doomsday-predicting politicians! Some people have done it and swear by it.

It’s a great life, if you can find it. Just ask this fellow from Alabama. Wait...what? That’s right, if you don’t buy any stuff, the government will come for you and evict you from your own land for being “unpatriotic.” So much for freedom, then. Clearly, you’re only allowed to be as free as the stuff ‘fear’ tells you to buy.

The other way is to use common sense, the ability to act in accordance to the consequences of cause-effect, a commodity of which we are in short supply. The demographics here are quite clear: millennials are, by far, the most tech savvy group. In other words, they’re the ones who spend the most time online, and, by extension, the demographic with the least awareness for common sense. Again, I don’t blame the ordinary millennials for their lack of cybersecurity awareness. They’re programmed to be online 24/7 with no regard for consequences. It’s a trend that’s been slowly developing and taking hold since the 80s.

Those of us who are older, and hopefully wiser, know the dangers of information, i.e., data, overload. We were brought up with phrases like, “Loose lips sink ships” and “Mum’s the word.” So we’re naturally wary of all these bits of personal data flying about in cyberspace. But millennials have no such compunction; they don’t know anything else.

So, use common sense because there’s no other alternative.

  • Install a good, reputable security program on all your devices. Make sure these offer VPNs and are cloud compatible.
  • Install a good password manager.
  • Make sure all your system devices are patched and updated.
  • Don’t go putting stuff on the internet you wouldn’t want your mother to see.
  • If you must do porn, go only to reputable porn sites. (yes, they exist!)
  • Don’t share everything with everybody - your real life is more important than your virtual one.
  • If you’re going to cheat on your spouse, do it the old fashioned way - go to a brothel and pay for it; don’t look for it online. Check out The Girlfriend Experience on Showtime.
  • READ! Preferably more than 140 characters at a time. There’s a lot of great advice out there; inform yourself. We have more knowledge available to us than at any point in history, and yet, we seem to be dumber than ever before.
  • Employ a “best practices” strategy.

But above all, just remember this - everything you do online is visible in some form or another. What would you like strangers to know about you...or not?

Sunday, February 17, 2013

Secure.me your Facebook page (pt. 2)

OK, we've discussed the first two sections of Secure.me. Before jumping into the third section, I thought I would post links to a couple of reviews I found online. The first one is from the Secure.me website and provides a primer on how Secure.me works. It also provides some interesting statistics on their analysis of 500,000 social media apps. The statistics alone should give you cause for concern. The second one is a blog written by a mother who expresses her concerns about online stalkers and the need to protect her children. Needless to say, she uses Secure.me to monitor her children's facebook profiles.

3. Threat summary
On the left hand column, Secure.me displays your threat summary. The number is orange next to 'Summary' is the total number of threats over the time period you set (see '2. Scan now' below) found by the scan process. The total is broken down into the 5 different areas I described previously. As you can see, in my particular case, I have a total of 232 potential threats of which 201 are due to photos. And these are the threats found over the previous 7 days only. (I dread to think what Secure.me will find if I perform a scan back to 2007!)

  1. Photos
  2. Go ahead and click on the 'Photos' tab located at the left hand column. Secure.me will open a new page providing a summary of all the photos scanned at the top part of the page. Directly below are the images you have uploaded, and directly below that are the pictures your friends have uploaded. See image below. Again, right click the image and select 'Open image in new tab' to view the full sized image in a new tab.
    Photo Analysis Section
    At the bottom of the screen, turn the photo monitoring option (red box) to 'ON' by clicking the button.

    Read the page carefully. It says a total of 2693 images have been scanned. Of these, 1020 are the total number of photos I have uploaded, of which 34 photos (the red box on the right) were scanned over the past week and the remaining 1673 images were uploaded/posted by friends. The number 1673 represents the photos/images posted by ALL my friends over the previous week, and out of those 1673 photos, I have been tagged or mentioned in 134 of them.

    Right about now you're probably wondering, so what? Again, there may be unflattering photos of you which you would rather delete, especially if you're looking for a job, or your children may be posting pictures of themselves which you would rather not let the world see.

    At present, you will have to review the pictures one by one as Secure.me does not have a feature that allows the user to select multiple photos at a the same time. However, they are working on offering this feature.

    To summarize, if there are no pictures of you throwing up or urinating at the curb after an evening of bacchanalian revelry, you probably have nothing to worry about. Nonetheless, it's a feature that's useful to have.

  3. Activities
  4. The Activities section is where you check, not only all your status updates, shares, likes and comments, but those of your friends as well over the given scan period. Again, it allows you to check which wall posts are objectionable. The right column displays the number of daily posts over the scan period. See image below (right click and open in a new tab).
    Activities Analysis Section

  5. Privacy Analysis
  6. Now we're getting to the good stuff because this is were your personal information can be at risk. Take a look at the image below (right click and open in a new tab).
    Privacy Analysis Section
    This is the information you (in this case me) have on your profile page, stuff like date of birth and email on the top part, and Education, Work, Family, Religious beliefs and Relationship status on the bottom. As you can see, I have 5 possible threats (only the first 3 are shown) and score only 4 out of a possible 10. In other words, I should review the information I'm making public. Note the 3 red boxes on the left side and the 3 on the right side. On the left side, two of the boxes are POSSIBLE threats (text in yellow) and one is considered a HIGH threat (text in red). Click the text in these boxes or the "i" on the right side boxes to get an explanation of WHAT it means, WHY this profile entry is considered a threat and HOW you can correct the security settings of the information displayed. Observe that even if you make the appropriate changes as recommended by Secure.me, this page will continue to show this information as possible threats.

    The important thing to take into account is to review and apply the appropriate measures recommended by Secure.me. This is called 'locking down' the security on your personal information. For some users, however, locking down their profiles isn't sufficient; they should be locked up...in a cell.

  7. Profile Analysis
  8. The profile analysis section pertains to the language recognition feature of Secure.me. As you can see, out of 679 posts appearing in my page in the past seven days, 20 have been found to have objectionable language (high-lighted in yellow), all of them from yours truly. In other words, I am, by nature, foul-mouthed and prone to use offensive to very offensive language. Despite the fact I tend to use foul language in excess, the mood of my posts is positive, thus the 10/10 profile analysis rank. Furthermore, the pie chart on the right column provides a breakdown of the source of the posts. In this case, I am the source of 99% of all the dirty language on my posts. But then again, I knew that already. See image below (right click and open in a new tab).
    Profile Analysis Section

  9. Network Analysis
  10. Finally, we have the network analysis section which analyzes the language of your friend's posts appearing on your page. Similarly, by clicking on the yellow cautionary text after each post, Secure.me explains why these posts are threatening and what you can do about it if you are so inclined. Well, personally I am not so inclined to censure any posts or comments so it's a feature I don't really use. However, if you have little ones on Facebook, you may want to monitor the language of their friends.
    Network Analysis Section
4. Privacy, Profile and Network Analysis
This topic has been covered at length in the previous section and needs no further explanation.

5. Secure ranking
This topic has also been covered in the previous section and needs no further explanation

And basically, that's it! Remember: Secure.me will not fix your Facebook security. It will point out potential weaknesses in your page and recommend fixes. If you still encounter problems, email me.

One last thing, I apologize for the layout of the blog - it's horrible. I'll have to do something about that.
     

Friday, February 15, 2013

Secure.me your Facebook page (pt. 1)

With Facebook's new Graph Search capabilities, your profile page pictures and wall posts are more exposed than ever before. The New York Times recently wrote an article on several privacy tools users may find useful. So far, I've only tried Secure.me which I explain below.

Recently, lots of Facebook users have been posting privacy notices and the need to get expressed written consent for the use of their pictures or content. Out of fear, other users see the post and share it by copy/pasting it on their own walls causing the whole thing to go viral. While the post may sound legal, beguiling the user to think (erroneously) he or she is actually protected, these messages have no legal bearing whatsoever.

The worst part is, people don't even bother to check the veracity or authenticity of the message. They just simply assume that because it's being posted on Facebook, it must be true the same way chain emails are true. (If you don't forward this blog to 10 friends, the DPRK will nuke the US.) However, a quick check on Snopes.com will tell you all you need to know about the message you're posting. But if you still don't get it, College Humor has a video that will make you feel like a downright idiot. If you're still in doubt, just Google it and see the results.

So, stop posting useless, none binding legal notices and stop asking your Facebook friends to perform security tasks for you. Take responsibility for your own security. Secure.me is just one of many available free apps that can help you in this regard.

Secure.me
Let me start by saying Secure.me is a monitoring tool, it will NOT configure your privacy settings on Facebook; you still have to do that yourself. What Secure.me does is scan all your photos, activities (latest user activities, status updates, comments, likes, places and friends), privacy analysis (personal information), profile analysis (questionable language on wall posts) and network analysis (questionable language on your friend's posts), and then proceeds to give you an account summary of its findings. You may or may not care for the language analysis feature of Secure.me, but it's there for a reason. Job recruiters and HR personnel normally do Facebook background checks of potential employees. By minimizing objectionable language, candidates will have a more positive projection of themselves.

After you install Secure.me (I am assuming you know how to install a free app), go ahead and login. You should see the following screen. Right click the image and select 'Open image in new tab' from the contextual menu. A full size image will open in the new tab. I've boxed and labeled the sections 1 to 5 which are explained below.


Secure.me User Home Page

1. Automatic Monitoring
You can choose to have your Facebook page monitored 24/7 (ON) or you can manually scan your profile (OFF). If this is the first time you use Secure.me, change the setting to ON.

2. Scan Now
The first time you use Secure.me, the Automatic Monitoring option is set to OFF by default. Click the Scan Now button. After the scanning process is complete, which can take several minutes depending on the time frame option (7 days, 30 days, 90 days), set the Automatic Monitoring option to ON.

Below these two options is a graph of the results of the scan. And right below the graph, it displays a summary of the analysis of privacy issues as well as the state of your profile and your network. Each of these three topics gets a rating up to 10 points, with 10 being the best.

(cont'd. in pt. 2)