Thursday, March 2, 2023

US Marshals Service suffer Ransomware breach, TikTok Bans continue to grow

US Marshals computer system hit by ransomware attack

The US Marshals Service computer system suffered a major breach last month.  The incident was discovered on February 17 and the affected system was disconnected.  It was determined that the hackers stole personnel data and info about investigation targets.

On the same date CNN reported a breach in an FBI computer system at the agency's New York field office.

The attacks are the latest in a trend targeting government agencies and has some questioning cybersecurity protocols at the Justice Department.

These attacks should serve as a warning to all computer users to be vigilant about maintaining security firewalls and software.

https://apnews.com/article/marshals-hackers-ransomware-breach-cybercrime-67de6b7f0f30445ab2eb341679f857bb


Here are the countries that have bans on TikTok

The number of U.S. States banning the use of TikTok on government devices has now grown to over 25.  The ban applies only to government devices.

However, it's not just the U.S. that has banned the use of TikTok.  Other countries include;

INDIA

TAIWAN

CANADA

EUROPEAN UNION

PAKISTAN

AFGHANISTAN

The U.S., India, Taiwan, Canada and the European Union, cite national security concerns.

Pakistani authorities have temporarily banned TikTok at least four times since October 2020, citing concerns that app promotes immoral content.

Afghanistan’s Taliban leadership banned TikTok and the game PUBG in 2022 on the grounds of protecting youths from “being misled.”

Who is monitoring your devices?

https://apnews.com/article/tiktok-ban-privacy-cybersecurity-bytedance-china-2dce297f0aed056efe53309bbcd44a04


Wednesday, January 18, 2023

Identity Theft and RansomWare are growing problems.

Identity thieves bypass security questions to access Experian credit reports

When I read this article, I thought if people you don't know, already have your name, address, SSN and birthdate, perhaps you have another problem other than your credit report being accessed illegally.  But then, this information is all over the place, in offices, firms and online.

There is no telling how many places your name, address, SSN and birthdate are stored on the internet.  These key pieces of data are in multiple databases related to insurance, credit cards, banks, etc., etc.  Many of these sites have already been breached, hacked, stolen!

After a tip from a Telegram user who frequented identity theft channels, Brian Krebs tested and confirmed that anyone who knew your name, address, social security number (SSN), and birthday could view your full credit report at Experian.

Protect yourself and please read;

Identity thieves bypass security questions to access Experian credit reports


Ransomware has now become a problem for everyone, and not just tech

Ransomware attacks have rumbled on for years and show no signs of slowing down. It's time we faced the threat head on.

In 2022, ransomware affected

    - 1981 schools

    - 290 hospitals

    - 105 local governments

    - 44 universities and colleges

Researchers suggest that much of the rise in reported ransomware attacks against local governments can be linked to a single incident in Miller County, Arkansas, where one compromised mainframe resulted in malware being spread to endpoints in 55 different counties. 

The above figures are for the public sector only.  The private sector isn't required to publicly disclose malware attacks so the full damage caused by malware isn't known.

Ransomware and Cyber Crime are threats to everyone.  To protect against these threats, companies and individuals should apply security patches and updates as soon as available to prevent criminals from attacking known vulnerabilities and delivering their malware payload.

MFA should be imperative for all accounts in the event a username or password is stolen.  Multi Factor Authentication makes it harder to abuse compromised accounts.

I see data backups not being taken seriously.  There should be multiple and redundant backups with some form of storing a backup offline in case of attack.

Of the local government agencies hit with ransomware in 2022, only one organization is known to have paid a ransom, which amounted to $500,000. The largest ransom demand made by attackers against a government entity demanded $5 million -- which wasn't paid. 

Education remains a key target for cyber criminal ransomware groups, the number of schools affected by attackers almost doubled in a year. In 2021, ransomware reached a combined total of 1,043 schools, while the number hit in 2022 was 1,981.

According to Emsisoft, at least three victims paid a ransom demand for a decryption key, with one known to have cost $400,000.

Hospitals have long been a target for ransomware attacks.  Hospitals need their systems to be operating to treat patients but many hospital networks still rely on old, often unsupported software. 

The attacks continued in 2022, with 25 incidents against hospitals and multi-hospital health systems, impacting patient care at up to 290 hospitals, 

for further info, please read;

Ransomware has now become a problem for everyone, and not just tech

The ransomware problem isn't going away, and these grim figures prove it

The real cost of ransomware is even bigger than we realised

Ransomware attacks are often talked about in terms of the financial cost. But in reality, these incidents can have a much bigger impact.


Tuesday, January 10, 2023

On this day in history, Jan. 9, 2007, Steve Jobs introduced the Apple iPhone to the world at Macworld in San Francisco

On this day in history, Jan. 9, 2007, Steve Jobs introduced the Apple iPhone to the world at Macworld in San Francisco

January 9, 2007 - Apple Introduces iPhone




iPhone, a crappy device?

Not everyone was a fan however.  This review from the AJC Business section, June 2007.  (previously published 11/17/15, DforceATL-iPhone post

The iPhone was made available to the U.S. consumer on June 29, 2007 to much fanfare but not everyone was impressed.  An article in the AJC Atlanta Journal Constitution opined that it was too trendy and consumer would not shell out the dough for the pricey novelty.  LOL, see AJC Tech writer's review below.



Friday, January 6, 2023

A Breach at LastPass Has Password Lessons for Us All, Who is using your Home WIFI, Patch Tuesday

 

LastPass Password Manager suffers a Breach.

I always hear gripes about passwords, their complexity and the need to change.  This is not a subject to be taken lightly.  A password is all that stands between your personal/financial info and bad guys trying to steal your info or monies.

Everyone needs some system to record these keys and protect this information.  I personally use a contact located in an Outlook PST file that is password protected.  You could also use an Excel spreadsheet to record your passwords and then password protect it.  However, this is another password you need to remember.  Also, there are utilities available for purchase that will break Excel password protection.

Some people use the password managers built into browsers.  These too are vulnerable and if anyone knows your login password, they can expose your saved passwords in a browser.  please see my prior post from 2019 about this,  Browser Password Security

So what is one to do?  Many have paid for online password managers such as LastPass.  LastPass is an online password manager with a personal Premium version available for $3/month billed annually.

There have been many online credit card, bank, credit union as well as other breaches of user information.  Why would an online password manager be any different?  It's not, LastPass has been breached exposing tens of millions of customer credentials and keys.

In other words, the hackers hit the lottery.  From an article on the NY Times;

When you use a password manager like LastPass or 1Password, it stores a list containing all of the user names and passwords for the sites and apps you use, including banking, health care, email and social networking accounts. It keeps track of that list, called the vault, in its online cloud so you have easy access to your passwords from any device. LastPass said hackers had stolen copies of the list of user names and passwords of every customer from the company’s servers.

If you are a LastPass customer, please read the article in the link below to determine what steps you need to take to safeguard your valuable information.

LastPass Hack-NY Times


Keeping your Home WIFI/internet connection secure.

If the above doesn't shake you, there is more good news.

You need to keep your home internet connection secured.  There are courses available online that teaches how to expose and connect to WIFI networks.  These are the ones that can be seen via available networks.  Has anyone watched the TV series, Mr. Robot?  In the series, the main character/hacker uses Kali Linux to break into networks and computers to fight big (overreaching industry).

Kali Linux is a hacker's dream OS and is loaded with tools for breaching systems.

Anytime you are in public and connect to a Mall's WIFI or any guest WIFI, be aware that all your info is being transmitted without encryption including user name and password.  So don't access bank or credit card info while using these networks.  I get dragged to Perimeter mall by Boss Lady and I am usually stuck outside the coffee bar at Nordstrom's waiting. I have witnessed many times the same 2 characters armed with a notebook and an external WIFI adapter which is needed by Kali to intercept internet traffic.  The internal WIFI adapters built into computers aren't any good for hacking.

With that warning said, back to your home internet, please see the info in the following link;

How To Tell If Someone Is Using Your WiFi, And How Remove Them (msn.com)


FYI, Next Tuesday is Microsoft Patch Tuesday.








Wednesday, November 9, 2022

Patch Tuesday. Microsoft released 11 critical security vulnerabilities and six zero-days being actively exploited.

November 8, 2022.  Yesterday was Patch Tuesday.  Microsoft released 11 critical security vulnerabilities and six zero-days being actively exploited.

We often put a lot of faith in our firewalls and anti-viruses and ignore updating and patching our computers.  However, the good guys are always behind and are only responding to the latest threat after it has been exposed.

In total, Microsoft issues 64 patches to address security flaws in products including Windows, Exchange and Office – so get updating now.

The security flaws impact Microsoft products including Windows, Microsoft Azure, Microsoft Exchange Server, Microsoft Office and more, some of which have been targeted by malicious hackers for months.

Please update your computers as soon as possible.  

To read more please click on the following link;

https://www.zdnet.com/article/microsoft-patch-tuesday-fixes-11-critical-security-vulnerabilities-and-six-zero-days-being-actively-exploited/

How do so many users become victims of hackers, credit card info theft and ransomware?  They oftentimes get attacked while browsing the web.  Sometimes it happens via a web search or a link on a page visited.  Before one knows it a malware script has been downloaded and installed without any needed response from the user.

Webpages themselves are actively being exploited and attacks placed in the code of the website without the authors knowing.  Thus a website can become a means of malware/ransomware distribution.  Websites too need protecting but that is another story.  WordPress and web-hosting companies provide or sell website protection but not all websites take advantage of these services.

In addition to keeping your operating system and applications updated you need to update your browsers.  Google's Chrome has become the largest target among the browsers currently used.  See article below.

There's been a big rise in hackers targeting Google Chrome - doing this one thing can help protect you

We enter and store a lot of information in our internet browsers, making them a tempting target for cyber criminals.

Google has released security updates to address 6 severe flaws in their browser.  See link below;

Google Chrome: Apply new security update now to fix these six 'high severity' bugs | ZDNET

To update your Chrome browser, check in the upper right corner of the Chrome browser to see if there is an update notification.  Please click on it to update your browser to the latest version. Warning:  it usually requires a browser restart to complete installation, you can restart at your convenience.


You can always go to Settings, Help to check for updates.  If available, Chrome will apply automatically.

In tech news;

Apple Preparing iOS 16.1.1 as Widespread Wi-Fi Bug Persists - MacRumors

Apple Experts Say You Should Never Waste Your Money On This Storage Upgrade (yahoo.com)

For the first time, I'm switching to an AMD graphics card | Digital Trends

Intel to Introduce Wi-Fi 7 in 2024 as Apple Plans Imminent Move to Wi-Fi 6E - MacRumors


Wednesday, October 26, 2022

Apple Just Quietly Raised Prices for Apple Music and Apple TV Plus

 Apple raises rates for Apple TV and Apple Music.

Everybody mad at Comcast, Direct TV and other cable providers for constantly raising their rates so they cut their TV service and began to stream entertainment.

and here come the increases, Apple TV has increased their Apple TV plus service by 2 dollars to $7/month.  I have been paying $4.99/month and with the increase it is still a bargain.  Apple Music is going up by a dollar.

Apple's bundle service, Apple One, meanwhile, will cost $16.95 per month for an individual, a $2 increase. The Apple One family plan will hit $22.95 per month and its premier plan, $32.95 -- a $3 bump for both. Apple One individual and family plans include Apple Music, Apple TV Plus, Apple Arcade cloud gaming and iCloud remote storage services; premier includes those four and both Apple Fitness Plus workouts and Apple News Plus, which unlocks multiple subscription newspapers, magazines and other news outlets.)

However Apple is not alone.  Other streamers, Netflix, Spotify, Disney and YouTube have raised their rates in the past year and the Prime membership jumped from $99 to $119 and now $139/year if you want to keep your Prime Video.

Yesterday both Google and Microsoft reported disappointing numbers on Wall Street so YouTube subscribers may see an increase soon.

FYI... to read more about the increases in streaming services, click the link below,

https://www.cnet.com/news/apple-just-quietly-raised-prices-for-apple-music-and-apple-tv-plus/


Wednesday, October 12, 2022

T-Mobile Home Internet Redux, 5 best Browsers, Microsoft Patch Tuesday

T-Mobile Home Internet Redux, the last time I'll talk about it.


I so much want to dump Comcast that I called T-Mobile again last Friday to inquire about data plans.  I was paying $50/month.

I found out this, as I stated in the 1st post 2 weeks ago, when I looked up my address online the website said the service was not available at my address but I was able to order the modem anyway.  When I setup the T-Mobile modem the phone app could not connect to the T-Mobile network and I had to set it up manually.  I was pulling 250 mbps download and pretty happy until I received the message that I had used up 80% of 100 GB allotment in 13 days and T-Mo was going to throttle my speed.

T-Mobile Home Internet vs T-Mobile Home Internet Lite

I found out that the modem couldn't connect to their actual 5G Home Internet.  It was connected to their phone networks 5G signal.  They call that Home Internet Lite.

If I could connect to their true 5G Home Internet then I would have had unlimited data for $50/month.  The Home Lite plan allows you to purchase more data but in incremental increases and it's not cost effective.

So now I am on their wait list, waiting for them to install equipment in my neighborhood.

To check your address visit the following link;


Microsoft's Patch Tuesday - October

Microsoft has released new updates addressing 84 vulnerabilities.  The Redmond company said that one flaw had already been exploited and another has been publicly announced.  Earlier this month patches were released that addressed 12 more CVEs (Common Vulnerabilities and Exposures) found in the Edge browser.

The vulnerability that has been exploited is a Windows COM+ Event System Service Elevation of Privilege Vulnerability. An attacker who successfully exploited this vulnerability could gain system privileges.

The publicly disclosed vulnerability is a Microsoft Office Information Disclosure Vulnerability. This vulnerability, discovered by Cody Thomas with SpecterOps, puts at risk user tokens and other potentially sensitive information.

If you have not updated your computer this month, please take the time tonight before leaving to start Windows updates installing on your computer.

To read more click on the link below;


What is the best browser to use?

The most commonly used browsers are Chrome, Firefox and Edge.  With Cloud services becoming more ubiquitous, cloud service companies have to make sure their products work with these major browser players.  However, which is best to use?... Chrome does not make the top 5.

I  use the Brave browser for Global Administration of client MS365 sites as well as banking activities.  Brave is rated #1 for overall privacy.

It allows me to peruse many newspapers without a subscription.  It comes with Tor browser and VPN built in.  When I launch an in-private windows using Tor however it hides your public IP address via a VPN and often assigns a European Public IP.

If you have heard of it before, Tor is the infamous browser most associated with the Dark Web.

To read more about the best browsers click on this link;



Wednesday, October 5, 2022

T-Mobile 5G Home Internet Update

T-Mobile Gateway sent packing.

As promised I wanted to update you on my experience with the T-Mobile Gateway, (see previous T-Mobile post).  The device was easy to implement and the speed was very good considering I was only getting 3 out of 5 bars signal strength.  I averaged 250 MBPS download speed and the service never faltered even after connecting my main TV along with my Surface Pro notebook.  I do all my TV watching via streaming including news.  I have an internet only subscription, Comcast business, 

I never got around to connecting all my devices which would have been 2 desktops, server, printer and 2 more TVs.  I'm glad I never fully converted since on day 13 of my 15 day trial I received a message from T-Mobile (see below) that I had used 80% of my 100 GB data allotment and they were going to slow down my speed until the next billing cycle.  Sorry T-Mobile, throttling my speed is not an option.

The customer service lady I spoke to was very nice and helpful and said that T-Mobile hopes to be able to provide unlimited data to my area some time in the near future.  If that happens and the price is reasonable, (I was paying $50/month) I'll be back.  In the meantime, bye-bye T-Mo.  




Friday, September 23, 2022

T-Mobile 5G Home Internet Review

T-Mobile 5G Home Internet, going Rogue on Comcast

When it comes to broadband internet, I have been with Comcast since 1998.  I can remember telling clients you really should see this.  I was pulling 3 mbps download and we were raiding Napster for songs at blazing speeds.  We could hook into a T3 line and download 75 songs at the time.  Friends and relatives were lucky to get a song a night using dial-up.

At the time my clients would say all we need are emails and don't need broadband.  Fast forward 24 years and civilization cannot exist without it.

Now I'm seeking an alternative to Comcast.  My location unfortunately does not have fiber yet so I am excluded from Google or AT&T fiber.  Up until this week my only alternative has been AT&T, internet 75, not fiber.  I refuse to go with AT&T since my experience dealing with them on client accounts has always been disappointing as to speeds, (they promise up to 75 MBPS, but may be only 5 MBPS).

I have had Comcast Business for 3 years now and of course the bill keeps climbing.  I have internet service only, no cable TV.

I decided to try T-Mobile 5G home internet.  I entered my address info and voila,


However, all was not as it seemed.  Upon continuing I had to verify my shipping and emergency (911) address.  The address prefilled by the website did not match my actual street address.  I'm at 4228 and it was responding with 4308.  I had to call customer service and the rep told me that the service was not available at my address.  Undaunted the next day I tried again and this time the rep allowed me to change the shipping and emergency address.  I was able to place the order and my internet appliance arrived Tuesday.  I have a 15 day trial before my service starts at $50/month.

Installation and setup.



The device setup was simple.  I attached the power cord, downloaded the T-Mobile app on my iPhone and I was ready.  I started the app and things looked bleak.  It could not auto attach to the T-Mobile 5G network or discover my location.

I then chose manual installation and provided my street address and phone number.  Next I gave it a secured password/key for the internet and accepted the default SSID (Wi-Fi name).  The device then attempted to connect which it accomplished successfully, but only 2 out of 5 bars strength.

I attached my Surface Pro notebook, ran a speed test and found I was pulling 120 MBPS down/8 MBPS up.  The instructions advised to place the device on an upper level near a window.  I moved the device upstairs, trying 3 different rooms. all locations had 3 bars out of 5.  I found that even with 3 bars, some of the locations were not ideal for WIFI due to walls and distance so I opted for the middle level of the house with 3 bars.


So far I'm pleased with the results.  I've tested and used the internet with my notebook and I can't discern any difference between it and my Comcast signal.  I ran the http://speedof.me speed test and the results are:



So far so good... this is with 3 of 5 bars signal strength.  If T-Mobile can improve the strength of the signal to my device I have no doubt that the T-Mobile Home Internet is a worthy alternative to Comcast.  The price is no comparison, $50 vs $130 plus per month.

This weekend I plan to test the device using all my devices including streaming on the TVs.

The T-Mobile device has 2 ethernet ports.  However the location of the device isn't convenient for my lower level office.  I will drop an ethernet cable and connect to an ethernet switch to conduct the test.



I will post an update to the blog next week and publish the result of my experiment with the T-Mobile Home Internet.

Have a great weekend.





Wednesday, September 21, 2022

The Newest Windows 11 update 22H2 and more

Is it time to update to Windows 11?  The latest Windows 11 update 22H2 contains features that have many saying yes!

This feature update isn't likely to turn Windows 11 skeptics into fans. It doesn't include any major architectural changes and it preserves both the system requirements and the overall design of the user experience from the initial release. This is, at its core, a "fit and finish" update, with a handful of new features that are useful but far from essential.

The 8 best new features are:

  1. Drag and Drop for the Taskbard
  2. Folders on the Start Menu
  3. Updated File Explorer
  4. Live Captions
  5. New Touch Gestures
  6. Update Task Manager
  7. New Inbox Apps:  ClipChamp, Sound Recorder
  8. Smart App Control.

To summarize key features;

Windows 11 has changed the way security is handled.  Windows 10 left security settings up to the user to enable.  What Microsoft found was that most users did not understand how to make the changes or the trade offs in compatibility and performance.  Windows 11 has inverted that view and now makes the security settings default for users.

In addition to security, the new Windows 11 update contains improvement in performance, better throughput and more beneficial features.  Microsoft's Photos app is also getting a much needed makeover.

File Explorer's Quick Access will now be called Home, however Quick Access will shift to the right panel where you can pin files and folders.  Windows will be adding a Tabs feature to File Explorer in October 2022 as an optional preview and then in November as a full release.  A File Explorer Tabs interface will allow you to open a new Tab like in a browser where you can search and open files without opening another File Explorer instance, much needed.

The Windows 11 22H2 upgrade was made available yesterday, 09/20/22.  It may already be installed on your Windows 11 computer, waiting for a restart to finish installing.

To read about what to expect and more from this update, please see the following links.

https://www.zdnet.com/article/windows-11-22h2-how-to-get-microsofts-latest-os-update-and-whats-coming-next/ 

https://www.bleepingcomputer.com/news/microsoft/hands-on-with-windows-11s-new-task-manager/

https://www.zdnet.com/article/windows-11-22h2-these-are-the-big-new-security-features/


Windows 10 EOL (End of Life)

You have until October 14, 2025 to keep using Windows 10 and continue receiving at least some sort of support from Microsoft for it. However, the company announced in November 2021 that it will only release feature updates after version 21H2 (the Windows 10 November 2021 Update) annually in the second half of the year via the General Availability Channel.

The next Windows 10 feature update is slated for the second half of 2022. Home and Pro editions of the November 2021 Update will only receive 18 months of servicing and support, and Enterprise and Education editions will receive 30 months of servicing and support after November 2021.

After that, Microsoft says it will continue to support at least one annual Windows 10 release until October 2025.

 https://www.lifewire.com/windows-10-end-of-life-4163811 

Who Will Pay the Price for Cyberattacks?

Insurers have long excluded war damage from their coverage. A new spate of legal battles will decide whether they can consider state-sponsored hacking an act of war.




TEST