Gone Phishing

January 13th, 2010

Recently I have been receiving a new found volume of fraudulent emails so I decided to write you while I have these fresh examples. The term ‘phishing’ has been around for quite a while. In my opinion ‘phishing’ is when a fake attempt to capture real information is cast into your sea of emails. Or a trap is anchored hidden in an ocean of websites.
I will use the recent examples that I received to explain the email method and how to identify these potentially dangerous attacks. An email was sent to me addressed as though it was from Facebook. The subject mentioned that the website was updating their login system to become more secure. This email was clearly modeled from an actual email from the site notifying that a friend request had been received or something similar. There is a button in the email that is a hyperlink just like the button that would link back to Facebook to accept the friend request or whatever. So, looks like the real thing and it came from an email address at Facebook.com so I should trust it right? NO BEANS! From email addresses can be spoofed all day long so don’t trust them if the message content looks phishy. Watch out for any email that is asking you to follow a link to enter information. If it were legitimate it would direct you to visit their website, login, and then enter the info. Any of these emails that are so persuasive that you just have to double check, you can just open your browser and type in the web site or click on one of your own bookmarks instead of using the link in the email. The technical way to check if the link in the email is bait is to hover your mouse over it (in most cases) and look at the bottom of the screen for the address to which site it is actually switching you to. You could also use the menu in your email checking program to ‘view source’ on the message and you would see before the text of the link the actual address.
The traps that used to be here and there used a method where you would reach them with a miss spelling of a popular site or a miss leading ad on a popular search term. These sites would look familiar and try to get your info. Haven’t seen one in a while though. Most of these accidental visits direct me to tons of ads or the occasional malware attack.
Many of the leading brands of protection software offer protection against email fraud by warning you that a message could be potentially dangerous and also blocking the spoofed site if the link is clicked. The new Internet Explorer version also claims to help prevent phishing. You may remember a one time message asking you to enable this feature when windows update first installed the new version. Hopefully the information I am sharing will provide you with a truly effective method of protection… your own tuned skills of awareness.

Here are some links:
http://en.wikipedia.org/wiki/Phishing
http://www.symantec.com/norton/security_response/phishing.jsp

Share and Enjoy:
  • Digg
  • del.icio.us
  • Facebook
  • Google Bookmarks
  • LinkedIn
  • Live
  • MySpace
  • Slashdot
  • StumbleUpon
  • RSS
  • Twitter

Posted in Home Computing - No Comments

WEP WPA What?

November 24th, 2009

I have not been much of a security guy in the past, but with new dangers around every corner I have been spending more time in the category. I was reading an article recently and I had one of those why didn’t I think of that? moments. Well to sum it up I had to update my wireless security because the long funky password that I knew was strong enough to sentry anyone who would care to access my network doesn’t matter. Apparently the passcode is transmitted attached to data when the wireless network is in use and there are a few fairly easy to learn methods of extracting the code from the transmission. Once you have the code you can access the network at any time. So the solution for now is not to use good ‘ol WEP shared key security anymore. The newest one on my router is WPA-2 and it has a nice big space for a secure code. Since you only have to enter this when you are connecting a wireless device for the first time you can make it long and complex. I used a phrase with some punctuation and capitalization play.
In addition to an increased level of wireless security WPA is also ready for the wireless N standard. I am guessing it is not that obvious in the setup instructions that N does not support WEP because I have heard from a couple people who had to spend some time finding out the hard way.
So it’s time to move on. Sorry WEP, it’s not you, it’s me.

Share and Enjoy:
  • Digg
  • del.icio.us
  • Facebook
  • Google Bookmarks
  • LinkedIn
  • Live
  • MySpace
  • Slashdot
  • StumbleUpon
  • RSS
  • Twitter

Posted in Security, networking - No Comments

Wires Required for Great Wireless

November 24th, 2009

Wouldn’t it be awesome if wireless routers had enough power to provide coverage to an entire home regardless of interference, distance, or building material.  Don’t trust the pictures on the box people.  Try it out yourself.  The best way to get the most coverage in your home is to setup your router in a central location on top of a shelf or desk where it is elevated above the furniture/appliance level.  Wireless technology is a line of sight transmission. The signal will not change direction to go through a doorway or open area seeking the path of least resistance.  It will try to go directly from point A to B attempting to penetrate any material in its path.  Many consumers that I speak to have either the problem where the router can not be conveniently located in a central area or they have building materials in their home that attenuate the transmission.   There are many solutions available at the retail level as this problem is growing more popular.  There are replacement routers that boast a larger range.  There is the  new ‘N’ wireless technology that has a wider range of coverage.  Yes, they do have a larger range, but yes they are still affected by the same physical obstructions that you may have.  There are signal repeaters called range expanders where you place the new box within your area of decent coverage and plug it into a wall outlet and it will forward the signal further.  This actually works in many cases, but there is no real way to tell if it is working or monitor its quality of signal so there is a question of reliability.  There are even devices that will send the signal over your power lines from one room to another which I haven’t really seen a good working model.  There are so many variables as far as age of household wiring, interference, junction boxes that degrade signal, even separate breaker panels within one home.  You could either continue to make trips to the electronics store making exchanges or just face the fact that a wire needs to be run.  Look to commercial installations for an example.  If they need to cover an indoor area they do not use a wireless router with a huge antenna on it.  They use what is called an access point.  An access point simply has one connection for a wire that connects to your router.  You can configure it to have the same name and security information as your router and it expands your coverage.  It is similar to a range expander as it needs to be plugged into power, but it is more reliable because there is a physical connection to the network.  Also, you can place this new bubble of connectivity as far as you can run a wire.  An out building for example.  Get help on this one, but you can bury a outdoor rated network wire out to your workshop, shed, gazebo, boat house, whatever as long as it has a power source.  So my recommendation would be to get a good Linksys router maybe with expanded range or the new ‘N’ technology and try it out.  If the signal does not reach where you want it to go and you can’t move the router then skip right to the access point.  It usually costs the same as the hoaky alternatives, but run a wire instead of the labor of traveling to and from the store.

Share and Enjoy:
  • Digg
  • del.icio.us
  • Facebook
  • Google Bookmarks
  • LinkedIn
  • Live
  • MySpace
  • Slashdot
  • StumbleUpon
  • RSS
  • Twitter

Posted in Home Computing, networking - No Comments

Caution! Dust Bunny Crossing

October 13th, 2009

Many know that computers, not just desktops, can accumulate dust that can shorten the life of the internal components. When these bunnies move in they can put a coating on parts within the machine that are designed to dispurse heat. The coating of dust acts like insulation keeping the heat in and also preventing fans from lowering the temperature of these important parts that generate their own heat as they function. Most systems have a automatic shutoff that will shut down the computer before heat can cause serious damage, but running hot will often shorten the life of components. This could cause the machine to crash, operate slowly, or in some cases stop working all together.
Maintaining a bunny free zone is easy and I will give you some money saving tips. First I need to remind you that one of your computers’ worst enemys is static electricity. Do not touch internal components unless you are properly grounded. Also it is a best practice to have no power connected to the machine while removing any internal parts.
The main expense for dust removal is compressed air. These canisters can become quite pricey if you want to bust bunnies on the regular. To use less air you can use a vacum either with the hose or the crevice attachment. You can directly touch fans and metal heat sinks with the attachments, but hover over the electronic components to avoid transferring a static charge. This can eliminate many of the heftier bunnies that will waste your air. Then you can finish off with a lite dusting with the air to flush out the residue or buildup that the vaccum couldn’t remove. Don’t forget the outside of the case. There is usually some sort of intake on the front bottom of the case that could have a constricted air flow.
So the next time you crack open your case and notice a small civilization of fuzzy critters forming, don’t wait. Get out the Hoover and go to town!

Share and Enjoy:
  • Digg
  • del.icio.us
  • Facebook
  • Google Bookmarks
  • LinkedIn
  • Live
  • MySpace
  • Slashdot
  • StumbleUpon
  • RSS
  • Twitter

Posted in Home Computing - No Comments

Password Pondering

September 29th, 2009

There are many rules about passwords that you may already know.  These rules are now often forced upon you when creating them (ex. “Your password must contain at least one number, capital letter, the name of a non-crayola color…”).   I don’t usually spend much of my time being paranoid about every aspect of computer security, but some recent research has helped me look at passwords from a different angle.

I will start with my standard password speech.  To make it easy I recommend using a password that is a word or phrase that you will never forget where you replace some of the letters with numbers that are similar to them. For instance you could pick your favorite flowers, petunias, and make it p37un1as.  You can also add a capital letter at the beginning and symbols to make it more secure, P37un1@s!.  Because it is still based on the word you will not forget you simply have to remember which characters you replaced and should be able to figure it out in a few tries.  Making it something you remember will also prevent you from writing it down and hopefully not affixing it to your computer.

What I have noticed recently is that if you have one of these nicely made passwords you are going to use it everywhere so you are nice and safe all the while remembering how to get into all of these various places online.  Wrong! Have you ever noticed that secure sites like banks and stores have that whole ‘Secure Authentication’ thing.  Well the whole reason behind that is when you type any information into your web browser, like passwords, it will be encrypted into a lump then sent over the Internet to its appropriate destination where it is decrypted and verified.  This prevents interceptions of this sensitive data between point A and B because all they will get is the lump and not even know what it is let alone want to spend a bunch of time molding it into letters and numbers.  So if you use the same password on insecure transmissions (non-lumping sites) there is a chance of interception and what is stopping this entity from trying this new shiny bit of information on the other sites you visit.

Ok, new rule, make different security levels.  All the passwords can still be nice letter/number/symbol glyphs as mentioned earlier, but you can make separate passwords depending on how important/secure the sites are.  Banks/Credit Card type sites with the most secure multi-word abscure personal fact type.  Utilities and ‘Just paying a bill’ sites having a normal 7+ character word with at least 1 number and a capital.  Finally a junk password for social networking, forums, coupon clubs, fan sites, etc.

Some of the most secure sites like banks have a new optional feature where they can send you a message on your cell phone each time you login from a new or cookie-cleaned computer.  This is a great feature because your password and your phone would both have to be compromised to login to this bank.   (Don’t store your password in your phone :) )

Start changing those passwords.  Change passwords as often as you can.  Think of it like a game.  Every time you see a news story about identity theft or a blog about password security, update those passwords.

S7r@w83rry-F13ld2-F0r3v3r!

Here are some links:
Microsoft Password Checker
Verisign – How SSL Works
Special discounts on Norton software.

Share and Enjoy:
  • Digg
  • del.icio.us
  • Facebook
  • Google Bookmarks
  • LinkedIn
  • Live
  • MySpace
  • Slashdot
  • StumbleUpon
  • RSS
  • Twitter

Posted in Home Computing, Internet - No Comments

Parental Control for Everyone

September 8th, 2009

If you didn’t already know, Windows Vista has a built in Internet filter to block unwanted web garbage from the little one’s eyes.  I recommend turning this on and having a separate user on the computer for this age group.  You should put a password on the adult account and leave the filtered account limited and easy to access.

The way most web protection filter’s work is they cross reference each location that appears in the browser with a rating database.  It is not just good and bad anymore.  You are able to set up a level of the filter to allow only child approved sites, block only adult sites, or something in between including a DYI blacklist.

There are many people out there that don’t know this setting exists or don’t worry because the users of their computer have good judgment.   What I am recommending is turn this feature on for everyone.   Make sure it does not block the sites you wish to travel to and you can leave access to the unrated sites because it could be a new weather or news site you are blocking.   Set users on the computer based on access restriction.  Block the youngest ones from the social sites and keep them viewing the places you want them to go.  Give the older ones the same access you have allowed them in the past but choose to restrict what you know to be off limits.  Even on your account click on the most lenient filter if you must, but remember you can always disable the filter if there is a particular site you need to view.

What are you talking about Rich?  I don’t need limits.  I am a grown adult!

There are many reasons to filter today’s Internet viewing.   Even the top name security programs are starting to have ‘Safe Web’ and ‘Safe Search’ features.  The sites that are being blocked through this massive list of no no’s are not just grown eyes only sites.  These sites could be malicious spyware sites, scams, unwanted advertisements, or even fake sites that promise the content you are looking for and then deliver nada.  When you travel to these sites your judgment is keen and you go back to the next result, but during that brief visit there could have been attack on your browser for spyware, malware, virus, or even hijack.  With the filter enabled you are given a warning when the site is blocked allowing you to think again before entering and most of the time just go to that next result without hesitation.  Same thing with the kids and their spaces and faces.   They see ads for things like “Make money testing Chewing Gum” and “Free Pink Pony Laptop!”.  Its not that they have bad judgment, but that their curiosity on a seemingly harmless ad could end up junking up your machine.   I am not saying that your expensive protection software that you renew yearly isn’t doing its job.  Just there are some more little things you can do to prevent annoyances and take control of what you and your family are exposed to on today’s web.

Here are some links:

Share and Enjoy:
  • Digg
  • del.icio.us
  • Facebook
  • Google Bookmarks
  • LinkedIn
  • Live
  • MySpace
  • Slashdot
  • StumbleUpon
  • RSS
  • Twitter

Posted in Home Computing - No Comments

Many still believe that each computer system needs every attachment and accessory for that workstation to complete the tasks it has been purchased to do.  There are ways to save time, space, and money that are now much more affordable.   Networks are not just for office buildings anymore.

With the drastic increase in broadband coverage and the drop in technology prices, networking equipment for the home is mass produced and more affordable than ever.  Powerful home networks already exist in broadband connected homes everywhere.  These networks can be used  for more than just sharing the plentiful internet connection.

In this article I am going to touch on some of the advantages of networking the different kinds of retail printers.  There are basic printers with just a USB connection, wired network capable, wireless capable, and bluetooth printers.  A common misconception is that you need to purchase a wireless printer (more expensive) to print wirelessly from a laptop.  As long as the printer is connected to the network there are options to print wirelessly even if it is not a wireless printer.  In fact if you would like to have your printer in the same area as your broadband connection and router I recommend to use the wired network connection for a faster, interference free link.  It is the computer you are printing from that needs to be wireless to print over the network from the couch, not the printer.  Granted there are some situations where the wireless printer would be preferred as if you need to put the printer on the opposite wall from the router and would like to eliminate running wires around the room or if you would like to put the printer in a more centrally located area because your new found ability to share this printer has family members coming from all reaches of the house to gather their prints.  If you have an older printer that just has the usb connection you still can print wirelessly, but it requires some configuration to share the printer across the network from the computer to which it is attached.  Aside from the extra configuration, another negative would be that the attached computer or host would have to be powered on and functioning for the wireless clients to print.  Bluetooth connected printers can be shared in a similar manner where the host would have to be on and within the bluetooth pairing range to the printer for others to print.

The overall advantages to networking your existing or purchasing a network capable printer in my opinion are costs.  In the past consumers would attempt to purchase all the same printers to only have to buy one type of ink cartridge.  Networking solves this by all users sharing one set of ink.  With the rise of ink prices and the lowering of printer prices a household can wait untill all of the ink is depleted in the various printers around the house (may only be one or two).  Calculate the cost of replacing all that ink and use that amount to purchase a new networkable printer that comes with some ink.  Also, it seems as though there is a trend that the higher price the printer is the lower the cost per page on ink it runs.  Sharing one slightly more expensive multifunction printer will save on overall ink purchases in this way.  Even the amount of household clutter can be reduced by having that many less printers and desks to put them on.   Some laptop users may remove the desk from the picture all together.

There is a good chance you can do more with the technology you already have…

RSL Tech may be the place you finally learn how.

Share and Enjoy:
  • Digg
  • del.icio.us
  • Facebook
  • Google Bookmarks
  • LinkedIn
  • Live
  • MySpace
  • Slashdot
  • StumbleUpon
  • RSS
  • Twitter

Posted in networking - 1 Comment

Complete factory system restore is a valueable feature for today’s branded systems.  Some of the new machines don’t even come with restore discs.  They make you create them yourself with your own blank media.  Many of them have built in restore methods to return to factory without the discs.   The problem is that the built in restore can become corrupt or if the hard drive needs to be replaced the built in restore is no use.  That is when the disks need to be found.  If the discs can not be found and the machine is out of warranty then new discs need to be ordered or a new liscense of windows needs to be purchased.  When the manufacturer is contacted to inquire about restore discs they will often try to transfer you from parts ordering to technicial support so they can attempt to charge you an hourly rate to tell you what you already know.  Then they charge you for the discs also.  The other option, purchasing windows, is even more expensive since to properly purchase windows you will need to buy a retail copy from a store which costs $2-300 depending on the version.   Usually after the frustration of calling the manufacturer and the annoyance of the price of new windows the next step is taking it to the repair shop or starting to look for a new computer.
This can all be avoided by keeping the restore set safe when you purchase a new computer even if you have to make it first.

Share and Enjoy:
  • Digg
  • del.icio.us
  • Facebook
  • Google Bookmarks
  • LinkedIn
  • Live
  • MySpace
  • Slashdot
  • StumbleUpon
  • RSS
  • Twitter

Posted in Software - No Comments

Auto-Updating Virus?

May 7th, 2009

Initially when I saw all the many names of what I still call XP AntiVirus2008 I thought that every time it was blocked by all the major protection companies the makers just tweaked it a little, changed the name, and sent it back into the world winding its way back to popularity.  I no longer think this is the case.  It seems as though this is an intelligent self-updating program.  I believe the makers place a patch in some location that the program checks periodically and the copies of the virus still in circulation update themselves to survive another day.   These copies could still be in circulation because the operators of the computers where they have installed themselves have not updated their virus protection or have no protection at all.  The program not only patches its vulnerability to the protection programs it also seems to change appearance and name to appear different to the end user.  From what I have heard these creators of turmoil are making tons of cash for the people who believe their program has magically appeared on their system to help them and they pay $50 to register for the full protection.

So spread the word when you see a new name for these doom laced supposed helpers.  Maybe when the money train slows to a crawl these people will leave us alone.  Oh, and Happy Birthday AV2008!

Here are some links:
http://www.symantec.com/security_response/writeup.jsp?docid=2008-050906-3727-99
http://en.wikipedia.org/wiki/Antivirus_2009

Share and Enjoy:
  • Digg
  • del.icio.us
  • Facebook
  • Google Bookmarks
  • LinkedIn
  • Live
  • MySpace
  • Slashdot
  • StumbleUpon
  • RSS
  • Twitter

Posted in Virus Removal - No Comments

When I think about rainbows, I think of something very beautiful to behold, but very out of reach indeed. You know you can’t touch a rainbow, so why chase it, right?

Well, for me chasing rainbows is like chasing technology. Beautiful to behold, but you can never reach the end of it.

Don’t get me wrong, I’m a technology freak. If I could afford to have every gadget that comes along, I would. I want to buy a new computer, but I know that inevitably within the next year, there will be faster processors, more storage, and more RAM. But I need the computer NOW, so I can’t wait until next year, or the next, or even the next few months.

So you see my frustration. I want to spend money on the best there is, but the best is always changing. That’s the good news, though. Technology is getting better and better, so we humans are able to accomplish more in less time.

So is chasing technology like chasing rainbows? You bet it is. But it is well worth the endeavor.

Share and Enjoy:
  • Digg
  • del.icio.us
  • Facebook
  • Google Bookmarks
  • LinkedIn
  • Live
  • MySpace
  • Slashdot
  • StumbleUpon
  • RSS
  • Twitter

Posted in Uncategorized - No Comments