Monday, December 4, 2017

Windows 10 update woes cont'd, Apple's update woes, Amazon Echo Dot

Arrrrgghhhh!  Microsoft, you killing me.

Sorry for the delayed response to my last post about upgrading my desktop to the latest version of Windows 10, Fall Creator's update, version 1709.  If you remember from my last post, after upgrading my PC I was presented with a black screen and flashing cursor with no available solution.  My only recourse after exhaustive searching for a solution was to restore my system to the previous version of Windows 10, version 1703.

Microsoft acknowledged the issue and released a couple of more updates that supposedly addressed the issue so last week I attempted to upgrade my system again.  This time was a complete disaster.  After the upgrade I once again was greeted with black screen and cursor.  Failing to resolve the issue  I tried to revert back to the previous version of Window 10 with no success.  I received a message stating that Windows encountered a problem and was unable to restore my previous version.

Great, right?  My only choices were to perform a recovery keeping my files and documents or recovery losing all my files.  Either way I was going to lose all my programs and settings.  Fortunately all my data/files are on a network drive and were safe.  I pulled the hard drive from my Core i7 desktop and connected it to a Core i5 desktop in hopes of it working there but the same black screen with cursor appeared on the new hardware.

Not wanting to be stuck with a machine that could not be upgraded, I downloaded the latest version Windows 10, Fall Creator's update, v1709, created a  USB boot installation drive and performed a fresh install of  Windows 10 successfully.

Windows 10 will notify you when the Fall Creators Update is available for your device. When the update is ready, you'll be asked to pick a time to install it if you're not ready.  To protect your data be sure to maintain a backup of your critical files in the event that something goes wrong.

If you are uncertain if the upgrade has occurred on PC yet, to check which version you are on please visit the following link,

https://support.microsoft.com/en-us/help/4028685/windows-10-get-the-fall-creators-update

If your computer has already been upgraded your version should be;

The issue with Windows machines is that there are so many available programs and options that no 2 machines are ever alike.  I'm sure there was some program or device driver or some combination of the two that was causing my black screen problem since I was able to successfully perform a clean install on the same hardware.

a bright note in all this, I discovered a free screen snapshot utility, Snip.  It works great and it's free.  Get it at; https://mix.office.com/snip


and don't gloat Apple users...

Apple's had a shockingly bad week of software problems

In the past week a massive security vulnerability was discovered in the latest macOS upgrade.  Anyone with access, either direct or remote could bypass administrator authentication and login without a password.

To make matters worse Apple then released a patch, followed by another upgrade which broke the patch and reintroduced the vulnerability.

https://news.google.com/news/search/section/q/apple%20problems/apple%20problems?hl=en&ned=us

Amazon's Echo Dot and my week with Alexa.

On a good note I purchased an Echo Dot during the Thanksgiving sales and I must say I am very impressed by it.  I interfaced it with my smartphone and in addition to providing me weather, music and news I use it as a speaker phone to place calls.  It is so easy, "Alexa", call so and so and she places the call, the audio is very good.  I tell Alexa to pair with my BlueTooth devices and she accomplishes this with ease.  I am just beginning to explore how Alexa can assist me in automating my house and will try to post updates as I explore the Dot's capability.

I purchased the Dot, regular price $49.95 for $29.95 on sale during the holidays.

https://www.amazon.com/b/?ie=UTF8&node=9818047011&ref_=fs_ods_fs_aucc_cp

This push into home automation is being spear headed by Amazon with Goggle Home trying to play catch up.  Apple is also trying to move into this market but has missed the important holiday season with the release of their HomePod not schedule until 2018.  Of course in true Apple tradition it is priced at $349, much higher than Amazon Echo or Google Home.

https://www.cnet.com/products/apple-homepod/preview/


support your local blogger, buy a computer!  Happy Holidays!




Thursday, November 16, 2017

Windows 10 Fall Creators Update Woes

Windows as a Service

Microsoft has made available to all Windows 10 users the latest version named Fall Creators Update through the new modern servicing technology referred to as Windows as a service.

My experience with the update is to beware.  Thus far I have one client who encountered the stuttering issue, i.e. using LogMeIn remote service to access the computer, within a minute reaction to keyboard or mouse input would slow to minutes before finally crashing the computer.  If remote access wasn't used she would find her computer unresponsive each morning and would have to turn it off and back on to use.

This past weekend I upgraded both my notebook and desktop to the latest version with mixed results.  Each computer is based on Intel Core i7 processors and Intel Graphics.  The notebook upgraded without a hitch, however the desktop would boot and upon logging in I was presented with a black screen and a flashing cursor.  I spend approximately 4 hours researching the issue which was widely reported by other users and I tried everything from Safe Mode, Registry fixes to a new video card but the results were the same.  I finally had to revert back to the previous version of Windows that worked.  I ended up doing the same for the client who was having issues as well.

On Tuesday 11/14/17 Microsoft released new updates to address over 50 Security Vulnerabilities and address a number of problems, hopefully it addressed those we have encountered.

Microsoft Patches Over 50 Security Vulnerabilities Today – Windows 10 Builds 16299.64 and 15063.728 Start Rolling Out

https://wccftech.com/microsoft-patches-50-security-windows-10/

In the above article they are still calling it Patch Tuesday which I thought they were doing away with but apparently Microsoft still finds it the best way to correct their blunders (BTW, the black screen bug affected more than Microsoft Surface notebooks).

Microsoft has released cumulative updates to Windows 10 Creators Update (Version 1703), Windows 10 November Update (Version 1511), and Windows 10 Anniversary Update (Version 1609). The update brings fixes to the black screen bug on Microsoft Surface laptops, among other problems. Here’s what’s fixed in today’s cumulative updates. 

https://wccftech.com/microsoft-cumulative-updates-windows-10/

Should you upgrade or not?

Roll the dice, if you have no deadlines pressing and the time to troubleshoot a failed upgrade then yes, try it.  I feel it is always best to be on the latest, greatest, and with today's security threats most secured version.  However if now is not the time, consider the following.

Whether you get the upgrade or not is no longer an option for the average user.  On Windows 10, you no longer have control over how to receive updates as before, they are mandatory.  In the case of my client and myself, we received a message that informed us that the update would be applied upon the next restart of the computer.

It is possible to delay updates for up to 35 days maximum if you wish.  I am going to show you how to do that.

(BTW, there is a way to retake control and prevent the OS from downloading and installing updates automatically using the Local Group Policy Editor or the Registry, however I'd rather you not do that on your own!)

To delay the update for 35 days

1. click on Start button and then select settings button, (gear symbol)

2.  Select Update & Security


3.  When the Windows Update windows opens, select Advanced options,


4.  Within the Advanced options window, click on the Pause Updates button to turn it on.

This will buy you 35 days after which you must install all available updates before you will be allowed to pause updates again.

Hopefully within 35 days, any issues arising from the latest update will have been addressed and fixed.

My Next Update will be...

As stated before, with all the security threats that exist online it is best to have the latest patched, secured system available.  I plan to attempt to apply the latest updates that became available Tuesday, 11/14/17  sometime this coming weekend.  I will post the results of the upgrade next week.  Until then good luck, happy computing and buy a computer!


Friday, September 8, 2017

Equifax Data Breach, 143 million affected

Credit rating giant Equifax hit by data breach, affecting more than 143 million




If you haven't heard or read the news yet, Equifax one of the big 3 credit monitoring services has reported a data breach that occured from mid-May through July 2017.

from Equifax website;

"The information accessed primarily includes names, Social Security numbers, birth dates, addresses and, in some instances, driver’s license numbers. In addition, credit card numbers for approximately 209,000 U.S. consumers, and certain dispute documents with personal identifying information for approximately 182,000 U.S. consumers, were accessed."

https://www.equifaxsecurity2017.com/

Equifax is offering free the service TrustedID.  This service includes free identity theft protection and credit monitoring.

https://equifax.com

The site is very busy this a.m. and it took several attempt to finally reach it.  On the site in a red banner they have a Click Here link to sign up for the complimentary service.

Once there, there is another link for begin enrollment.

from the Equifax website;


  • When you begin, you will be asked to provide your last name and the last six digits of your Social Security number.
  • Based on that information, you will receive a message indicating whether your personal information may have been impacted by this incident. Regardless of whether your information may have been impacted, we will provide you the option to enroll in TrustedID Premier.
  • You will receive an enrollment date. You should return to this site and follow the “How do I enroll?” instructions below on or after that date to continue the enrollment and activation process. The enrollment period ends on Tuesday, November 21, 2017.

I checked my info and it warned me that I was possibly affected.  After signing up for the service I was told that my enrollment begins effective 09/13/17.  Why I don't know, but it said I should mark it that I will not receive additional reminders... they will probably start charging me after a year.



To read about this serious credit threat and more, visit ZDNET at;





Wednesday, August 23, 2017

Email and Browser Health. Windows security: Cryptocurrency miner malware is enslaving PCs with EternalBlue.

http://searchsecurity.techtarget.com/definition/email-spoofing


Lately I have been fielding a lot of questions about the legitimacy of emails.  Some of the emails were from users who wondered if their PC was infected by a virus or malware.  These turned out to be nothing more than their email was used to spoof a mass spam mailing.  It used to be spoofing was used because a spammer was sending millions of emails and was not concerned if their list had bad or extinct email addresses.  They simply did not want to be bothered by the returned emails.  They only hoped for at least a 1% positive bites out of the millions sent.

However, with the rise in Malware the trick is to try and appear to be from a legitimate source so that the recipients will click on the links contained within and download the malicious payload.

There has also been a wave of emails purporting to be from Microsoft Office 365 claiming that a deactivation request has been received or that your mailbox has reached the limit and action is required now to resolve this.  Microsoft does not send emails to individual subscriber mailboxes.  There are admin and alternate emails that Microsoft uses to control subscriptions.  Don't confirm your email to these hackers by attempting to use the links provided.  You will only provide them with your login credentials and possibly download some bad stuff on your PC.

Windows security:  Cryptocurrency miner malware is enslaving PCs with EternalBlue.

Stealthy and persistent cryptocurrency-mining malware is hitting Windows machines.

Now there is "fileless" malware that runs in memory, hijacking PCs to work at mining cryptocurrency.

Researchers at Trend Micro describe the malware known as CoinMiner as "extremely stealthy and persistent".

To infect Windows machine, it's using the so-called EternalBlue vulnerability employed by WannaCry and NotPetya as a spreading mechanism. Microsoft released a patch for the flaw in March but a spate of infections in Asia, mostly in Japan, suggest some systems have not been updated.

Please be sure to patch your machine and be vigilant about emails you open & links you click on.

Add-ins and Extensions.  Browser health.

It used to be that Chrome and Firefox provided safe alternatives to the contact attacks and ravages on Microsoft's Internet Explorer Browser.  That is no longer the case.  Google's Chrome has been the target of phony extensions designed to spread malicious ads.  These extensions are delivered more often than not by users who google a legit software but don't pay attention to the sites found by the search.  Be sure the download you seek is from the site of it's maker and not a 3rd party who will slip you unneeded toolbars, extensions and malware.

The main intent of the attack on Chrome extension developers is to divert Chrome users to affiliate programs and switch out legitimate ads with malicious ones, ultimately to generate money for the attacker through referrals

Windows support scams:  Microsoft taking down Fraud Kingpins



Monday, June 19, 2017

Largest ever Voter Records Leak, Windows 10 Creators Update.

Nearly 200 million US voter records leaked
Personal details of American voters were stored on an unsecured and exposed server.

Just in time for tomorrow's June 20th, 2017 special election in the 6th District of Georgia comes news of the largest leak every of voter records.  Personal data of 198 million voters which was stored on an unsecured Amazon server.

The information included personal information such as name, DOB, home address, phone number and voter registration information.

"The various databases containing 198 million records on American voters from all political parties were found stored on an open Amazon S3 storage server owned by a Republican data analytics firm, Deep Root Analytics."

What is an Amazon S3 storage server?  Another component of the Cloud, https://aws.amazon.com/s3/

To read the full story, please use the link below.

http://www.zdnet.com/article/security-lapse-exposes-198-million-united-states-voter-records/?loc=newsletter_large_thumb_related&ftag=TREc64629f&bhid=2219791

http://www.bbc.com/news/technology-40331215


Microsoft's Windows 10 Creators Update.

The journey of Windows as a Subscription continues, the latest iteration is Windows 10, Creators Update.  For a list of new features click HERE

If your computer is updating automatically, you may already have it installed, it is Version 1703.  To update or check your current version of Windows use the link below;

https://support.microsoft.com/en-us/instantanswers/d4efb316-79f0-1aa1-9ef3-dcada78f3fa0/get-the-windows-10-creators-update

www.drivingforce.net

Sunday, May 14, 2017

World’s biggest cyberattack hits 150 countries and the threat is ‘escalating’

If you have not heard of the latest Malware threat that first appeared this past Thursday, then please take heed now.  It's a malware type known as ransomeware and is called WannaCry.  Cybersecurity experts say the initial targets were Russia, Ukraine and Taiwan but hospitals in the U.K., universities in China and global firms like FedEx were also under attack.

The malware is spreading by taking advantage of a vulnerability in Windows.  Microsoft release a patch in March but computers and networks that have not updated are at risk.  Microsoft has even released patches for unsupported older operating systems  including Server 2003 and Windows XP.  Computer already infected will not be helped by patching.

The ransomware attempts to seize control of an infected computer, encrypt files and then demand a ransom be paid before releasing control of the computer.

Cyberattack’s Impact Could Worsen in ‘Second Wave’ of Ransomware


On Friday an estimated 74 countries had reported infected computers.  Today that number has grown to 200,000 known victims in at least 150 countries.  Authorities are fearful that the numbers could spike with the start of the workweek on Monday when employees return and start using computers were the malware already is in hiding.



To read more; visit the links below.



Thursday, May 4, 2017

Beware of Google Docs Phishing Attempt!

Heads up everyone.  There is a nasty email circulating that invites you to click on a Google Docs link.  It will appear to be from someone you know and is a phishing attempt that can open up a whole bunch of trouble for you if you click on the enclosed link.  Please don't do that, just delete the email.

The payload of the email is that the deception will give the keys to your GMail account to the bad guy who sent you the email.  Remember it was a phishing attempt that DNC head John Podesta fell for leading to his email correspondence being leaked.

"The counter-measures Google described are likely to stop the spread of the phishing attack but, as one security expert points out, the attacker has already had time to harvest millions of email addresses via victims' Gmail contact lists.

It seems such scams targeting Google accounts are becoming more common in recent months. As my colleague Robert Hackett reported in January in the article Everyone is falling for this frighteningly effective Gmail scam, hackers (usually posing as a trusted contact) have been sending around booby-trapped documents that look like ordinary PDFs."


To read more please see the links below on Fortune's website.

A Massive Google Docs Phish Might Have Stolen A Load Of Gmail Accounts - UPDATED

https://www.forbes.com/sites/thomasbrewster/2017/05/03/massive-google-gmail-phish-many-victims/#1bbaa89b42a1

http://fortune.com/2017/05/03/google-docs-scam/


What to do (from the first article link)

"For anyone who remains concerned, there are steps they can take. First, it's possible to note the phishing attempt by just looking at the message. It'll typically say something like: "Mr. Attacker has invited you to view the following document." And the recipient will be in the BCC field. That's the first clue something phishy is going on, added to the fact that the only other visible email address in the to field is hhhhhhhhhhhhhhhh@mailinator[.]com, a temporary account on Mailinator.

Then, go to https://myaccount.google.com/permissions and revoke any permissions given to an app called Google Docs. This should prevent any problems, just in case Google hasn't managed to get rid of the app already.

And in the future, if you're not expecting a Google Doc and a link looks suspicious, don't click through before validating with the sender that it's legitimate.

There is, sadly, one big problem for victims who clicked through: the attacker could have automated their scam (likely, given how they carried out the illicit operation) and hoovered up all their Gmail already. In this case, there's not much to be done other than hope nothing sensitive was stolen or that proactive measures are being taken against those who perpetrated the hack."

Monday, March 27, 2017

3 things you should do right now to protect your Apple iCloud account

3 things you should do right now to protect your Apple iCloud account.

This is a followup to my Friday post about hackers possessing passwords to 250 million Apple iCloud accounts.

Apple users really should heed the advice of the experts and pay attention to the threat to their data posed by the hacker group, "Turkish Crime Family".  The London based hacker group may or may not have access to 250 million Apple iCloud accounts but they have proven they have access to an indeterminate number of accounts.  That is more than reason enough to protect your account and data by changing your password today.

from ZDNet article, change your password!

Since Apple isn't doing this, it's up to you.


Apple talks as if your Apple ID and iCloud ID are different. They're not. They're the same, and they use the same password.

To change your Apple ID password, sign in to your Apple ID account page with any web browser and follow the instructions to reset your password. I changed mine using Google Chrome from a Mint Linux system.

http://www.zdnet.com/article/how-to-protect-your-apple-icloud-account/?loc=newsletter_small_thumb&ftag=TRE17cfd61&bhid=2219791

I know ignorance is bliss, especially for Apple users.


DFS - 7th Generation Intel based workstations.


Friday, March 24, 2017

Apple iCloud Ransom target date April 7, 2017, New iPad

Happy Friday Quickie Blog - a couple of Apple facts.


Apple iCloud ransom demands: The facts you need to know

If you have an iCloud account you should seriously consider changing your password in light of a new threat by a hacker group called the Turkish Crime Family.  The group claims to have access to 250 million iCloud accounts.

If Apple doesn't pay a ransom in Bitcoin by April 7 the hackers are threatening to reset the passwords of the accounts and remotely wipe iPhones.

Read all about this latest Apple Hack at:

http://www.zdnet.com/article/apple-icloud-ransom-what-you-need-to-know/?loc=newsletter_large_thumb_featured&ftag=TRE17cfd61&bhid=2219791

Apple hope new cheap iPad will turn around sales

There is a new iPad available starting today 03/24/17.  The most exciting feature of this newest tablet from Apple is it's price, $329 for 9.7" 32 GB WiFi model.

It replaces the iPad Air 2 and is simply called the iPad.  In addition to the lower cost, the iPad sees a spec update, with the old A8X chip getting replaced with the 64-bit A9 processor.  Despite the more powerful processor there are compromises to hit that low price.  Apple is betting that it has hit the sweet spot to turn around flagging sales.

Also, a new red  iPhone.

Read about this new iPad at:

https://www.engadget.com/2017/03/22/apple-new-ipad-cheap-not-powerful/

https://betanews.com/2017/03/21/low-cost-9-7-inch-apple-ipad/

Thats it!  Happy Friday!  Buy a PC!


DFS-Driving Force Software Intel 7th Generation workstations.



Monday, March 13, 2017

WikiLeaks dump, CIA capabilities, your security and Best Buys assist FBI

Many things were revealed last week after the WikiLeaks dump.  Cybersecurity experts have been focusing on the "zero-day" vulnerabilities detailed in the documents.  These are holes in the code that can be used to infect a device with spyware/malware or to steal personal information.  The CIA has been criticized because they did not attempt to notify tech companies of the security flaws so they could be addressed but instead left Americans vulnerable to potential cyber criminals.

According to documents released in the dump, the CIA has the ability to hack into and control iPhone, Android and Samsung TVs.  It doesn't stop there, Skype, Wi-Fi networks and anti-virus programs can be manipulated as well.  If the CIA can hack these devices so can others.

The dump unveiled the agency's ability to hack into devices remotely and turn on cameras, microphones for tracking a person's location and messages.  The CIA along with intelligence services in the UK developed a hack targeting Samsung Smart TVs that enabled them to record surroundings while the TV appeared to be off.

In addition to the WikiLeaks dump, new federal court filings revealed a close relationship between the FBI and Best Buy’s Geek Squad.  The FBI was using Best Buy's Geek Squad to monitor and gather data on individuals.  Now I'm all for the capture of info that assists in getting child pornographers, criminals and other scumbags but I was still surprised to learn of the training and management of Geek Squad staff as FBI informants.


After CIA leaks, tech giants scramble to patch security flaws

Apple, Microsoft, and Google are analyzing leaked CIA documents to see if their products are affected, but security researchers say that most of the flaws have long been fixed.
http://www.zdnet.com/article/tech-giants-scramble-for-cia-hacking-fixes-most-flaws-patched/?loc=newsletter_large_thumb_featured&ftag=TRE17cfd61&bhid=2219791

FBI Used Best Buy’s Geek Squad To Increase Secret Public Surveillance

http://fortune.com/2017/03/12/rbi-best-buy-geek-squad/


The battle for online privacy:  What you need to know

https://www.cnet.com/news/online-privacy-what-you-need-to-know-faq/?ftag=CAD1acfa04&bhid=21042726186831923270015874178287


DFS-Driving Force Software Intel Generation 7 workstations






TEST