White Collar Handyman
In-Home and In-Office Technology Concierge Services
Lessons & Tutoring • Repair • Troubleshooting • Upgrades & Installation
Fast Response • Reasonable Rates • In Your Home or Office • Same Day Service Available
(781) 989-2373
Hey! We've moved to a new URL to better reflect who we are and what we do! Please visit Rob Falk Technology Concierge Services at http://robfalk.net and update your bookmarks.
Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Monday, November 23, 2015

Safer Computers, Tablets, and Phones in Minutes

From time to time, I speak at community centers and social groups on easy and inexpensive ways to tighten up security on electronic devices. It's a 45 minute session that is both entertaining, informative and immediately useful.

I cover:

  • Password Managers
  • using HTTPS
  • OpenDNS & crowd sourced trusted sites
  • 2 Factor Authentication
  • Virtual Private Networks
  • Finding lost devices
  • Hard drive encryption
  • Phishing
  • Scams
  • Malware
Here is a link to the resources I discuss in the body of the talk.

If you think your club, group or community center might enjoy this talk, please send me an email.

Monday, May 18, 2015

Improve your iPhone Security by more than 1 Million Percent?

I like using the Simple Passcode option on my iPhone, but I've always been kind of bugged by the idea that there are only 10,000 possible passwords under that scheme. Since it's always 4 numbers, lots of people tend to use a month/day combination which makes guessing a fairly easy task for many people. Is your first digit 0 or 1? Do your 3rd and 4th digits add up to no more than 31? Is your combination your birth year? Last 4 of your phone number?

If you would like a longer simpler password, here's a cool and easy trick I just learned:

  1. Open Settings on your iDevice and go to "Touch ID & Passcode."
  2. Turn off "Simple Passcode"
  3. Next, change your passcode to something longer, using all numbers.
  4. Enjoy your new improved security!
Look what happens when you get to the lock screen now! Instead of needing to enter your long password with the keyboard (really kind of a drag) you just punch it in on the keypad (not too shabby!) The only difference between this and the simple passcode option is that you need to tap the "OK" after entering your code.

OK, I lied. The only difference is you have to tap OK, and your password is now more than 111,000%  harder to crack! (Assuming you have used 7 digits.) You've gone from 10,000 combinations to 11,111,110. Add one more digit and you've increased the number of combinations to over 100,000 which is more than a One Million Percent increase!

I really like the idea that the length of my passcode is no longer known. While I'd never recommend a 1, 2 or 3 character code, a would be thief/hacker would have to try all of them in order to rule them out. They also need to try all the 5, 6, 7 and so on combos, thereby increasing the amount of time it will take to unlock your phone.

Yes, you may have set your phone to erase all data after 10 failed passcode attempts, so perhaps you're not too worried. Then again, you may have a kid or a wise guy friend who just loves wiping out all your data every so often. Me? I'd rather not have to restore from a backup. And if you're one of those people who says "Back… what?" or doesn't know how to restore from a backup or one of those who knows how long it takes to restore from a backup, maybe you would like to make your password a little bit longer and less obvious than a sentimental date.

Saturday, March 21, 2015

No, Your Computer is NOT "Critically Infected"

This is a bogus alert that seems to be hitting Mac users, and these people will not help you.

They will take a lot of money if you call them and listen to them. There is actually no harm done to your computer by this little bit of javascript trickery.

The damage gets done if you call them and they convince you to give them remote access to your computer so they can "help" you. In fact, all they do is help themselves to private information, and a couple hundred dollars if you then give them your credit card information.

If you find yourself locked up on that page:

  1. Hit Command-Option-Escape.
  2. Quit Safari.
  3. Start Safari with the Shift key down.
  4. Under the Safari Menu, Choose "Clear History and Website Data…"
  5. Clear at least Today and Yesterday
  6. Restart the computer.
  7. Stick to a less unsavory part of the web.

If you have been subject to this phishing/harassment, please let me know, and let me know if this helped. I offer a free 50 minute multimedia presentation called Safer Computers, Tablets and Phones in Minutes to clubs and community/social groups in Massachusetts and Connecticut. Please email or call me if you think your organization would be interested.

Tuesday, August 5, 2014

The Argument for Phony Security Question Answers (Again)

A seventeen year old kid in Australia recently bypassed Paypal's two factor authentication. This should be troubling news to anyone who engages in financial transactions on the Internet. I've written a thing or two about password management and security on line and have been a strong advocate of two-factor authentication, hailing it as "state of the art" consumer level security.

Two-factor authentication is supposed to mean that "even if someone succeeds in hacking your
password, they won't be able to log in to your account from a device that you haven’t already approved. The log in won’t be allowed until after you receive a text message on your cellphone with a code, which must then be entered in addition to the password." But, not so at Paypal, according to our junior jackaroo.

What happened at PayPal?

As many are aware, PayPal is owned by eBay. As a convenience for their users (i.e., to encourage their users to use PayPal for everything) eBay provides their users with a direct link to their PayPal accounts. Here's the fly in that ointment: apparently eBay does not check to see whether two-factor authentication is enabled before allowing anyone who manages to log in to eBay to shoot right into the linked PayPal account with just a username/password combo.

That may not seem like such a big security hole, since it requires the crook to have your username/password combination at two sites, but that's really not that far fetched if a hacker has been able to gain access to the victim's computer.

It gets worse. According to PCWorld, "The payment processor’s two-factor authentication could potentially be defeated in other ways. For example, if a user doesn’t have a way to receive the six-digit code, PayPal allows them to skip it and instead answer two security questions." Given that most security questions involve questions like "Where were you born?" and "Where did you go to high school?" the illusion of two-factor authentication becomes more and more mirage-like.

I've shared the answer before, but it's time to share it again: How about using your random password generator to come up with a short but random string of characters, and saving it in your password management app?

Mother's maiden name? oL-eF-yeph

Monday, June 30, 2014

iOS 7.1.2 Update for iPhone, iPad & iPod Touch Now Available

According to Apple, latest iOS update includes the following changes:
  • Improves iBeacon connectivity and stability
  • Fixes a bug with data transfer for some 3rd party accessories, including bar code scanners
  • Corrects an issue with data protection class designations of Mail attachments
It also contains "miscellaneous bug fixes and security updates."

You can download the update over-the-air via Settings > General > Software Update or install it via iTunes by connecting your phone to computer using a USB cable. Even though you can update/upgrade directly over the air on your phone, don't. Although it's only a 23.1-megabyte delta update (just the changes, not a whole system file) user experiences with over-the-air upgrades vary, while those who use the tried and trusted USB method seem to be unanimous in their success stories. And, I always like to make a fresh backup to my hard drive first.

Here's the safest way to upgrade/update:
  • Attach the iPhone to your computer.
  • Open iTunes.
  • Click on "Back Up Now."
  • Wait for the backup to finish
  • Click on "Check for update" and then do update to 7.1.2
Because it's a delta update, you shouldn't have to wait to long to get back on the device, with all your data and settings intact.

As always, unless you are absolutely dying to have the listed issues fixed, maybe wait a couple days. You never know what might be broken, diminished or deleted in an update. You won't get any prizes for updating first, but you might get some surprises.

Wednesday, May 28, 2014

Need another reason to use strong passwords and two-factor authentication? iPhones Held Hostage!

One of the of the security features offered by Apple for its computers, iPhones and iPads has turned around and bitten several Australian users who found that they were suddenly locked out of their devices and asked to pay a ransom of up to $100 to a hacker holding access to their devices hostage. 

Find My Phone is a great security feature that allows an iPhone owner to remotely lock his or her device should it be lost or stolen, thereby securing all the data on the phone and rendering it useless without the entry of a security code. But, problems arose for the Aussies when a hacker going by the name of Oleg Pliss somehow obtained usernames and passwords, and locked the rightful owners out. Apple says it has not been the victim of any security breach and suggests that credentials were gained either by phishing or because of password reuse.

Phishing attacks are just a modern form of film flam and trickery. A scammer sends an email that looks authentic, and the dupe dutifully responds with all kinds of information that is best not shared with bad guys. Phishing can be thwarted by never clicking on links in emails. If a legitimate web site needs information from you, you will be able to find their inquiry on their website. If you get an email asking for any information:

1. Make note of what website it is supposedly from.
2. Delete the email.
3. Go to the subject website by opening your browser and using your own bookmark. If you do not have a bookmark, enter the URL for the website you are trying to reach, or use a trusted search engine to bring you to the genuine site.
4. Log in and look for a message to you.

Follow this method for dealing with emailed information requests and you will avoid falling prey to almost all phishing attacks.

I've discussed Password Reuse before. In a word, it's bad. If you use the same username and password at more than one site, once a hacker gets information from one web site breach, he has access to every account you have that uses that username/password combo.

Finally, Two-Factor Authentication: In a word, it's great! Here is a large list of websites indicating which do and which do not have 2-Factor Authentication. In short, without rehashing what's been said before, if a provider offers 2-Factor Authentication, use it, and if they don't, encourage them to do so.

Monday, May 12, 2014

What's In Your (Digital) Wallet?

On April 29, the Supreme Court heard the case of a young man who was pulled over for driving a car with expired tags.

"Hmm… coulda happened to me," you think.

Sure, that or an inspection sticker, tail light out, jaywalking, whatever. What happened next is frightening. The cop who pulled him over picked up young Mr. Riley's Samsung Instinct M800 smartphone and took a look-see. There he found pictures that linked our motor vehicle violations suspect to an unsolved drive-by shooting that ultimately resulted in a murder conviction and a 15-to-life sentence.

While few of us will have sympathy for a murderer who was convicted of murder, the thought that I could be jaywalking down the street at one moment and giving the police complete and unfettered access to everything on my iPhone the next (photos, email, documents) is horrifying.

This is one more reason to have a strong password on your smartphone: Although the protection provided by a strong password might not survive a court order, it will certainly prevent the immediate disclosure of your most personal photos and emails during a routine traffic stop!

You may not have killed anyone, but is there anything on your phone that you don't need Barney Fife taking a gander at? Riley's lawyer argued that it may be one thing for cops to go through your pockets and wallet, but letting them nose through an Android or iPhone at a traffic or sidewalk stop is like giving "the police officers authority to search through the private papers and the drawers and bureaus and cabinets of somebody's house." The Court's decision may decide whether it's legal for the police to search the digital contents of your cellphone without a warrant.

Even if it's legal, it doesn't have to be easy. Even a 4-digit code is better than nothing. Maybe take a moment to lock it up, now.

Wednesday, April 30, 2014

An Open Letter to Web Sites Where I have a User Account (All 162 of You)

Dear Webmasters:

Congratulations on your new certificates. I'm very excited to change my passwords and all my security questions at each of your sites in the next few days… and to keep changing them every few months for the rest of all of eternity.

I know this "Heartbleed" thing has been a real drag for everyone, but in its wake can I ask for a few simple things moving forward? I think it's a pretty reasonable list:

1. I'd like to be able to use more than 9 characters in a password. I'm looking at you Discover. Is space on your server so dear that an extra dozen characters or so would kill you?

2. I'd like all special characters to be OK. Really, if I can type it on a computer keyboard, you ought to be able to deal with it. It's 2014. Do you realize that if I can use symbols and special characters, my password can be shorter and just as secure? An 11 character password made up of all available characters has the same 80-bit security as a 14 character password made up of only case sensitive alphanumeric characters.

3. I'd like to know up front what your particular parameters for acceptable password length and composition are. In other words, when you tell me "At least 7 characters/1 Number" it's of no use at all when I enter 30 characters, and then you tell me that's too many. And then I enter 24 characters and again you tell me that's too many. How about just telling me "at least 7 and no more than 20?" And whether or not "special characters" are OK. Thanks CVS. Changing my password with you was almost as much fun as playing Candy Crush, and just as challenging.

4. If I want to say that my mother's maiden name was "0(jK1bBn," what's it to you? To me, it's better security than posting all kinds of personal information to be stolen by hackers the next time you leave the hen house open. Just like having a different password at every site, I kind of like too have different security question answers as well.

Finally, maybe think about not hiding the "sign out" button in a different place on every single site. If I want to play "Where's Waldo," there's an app for that.

Sincerely yours,

Rob Falk

Saturday, April 12, 2014

Your Password WILL be Hacked. Not If, When. Fight Back.

Just this week, a well-meaning financial planner sent an email blast to advise his clients to change the passwords to all their web accounts, including the investment accounts that he managed. So far, so good… He suggested that his clients use a different password at each website (good.) Unfortunately, he suggested that they use a simple formula (horrible.) He wrote:

“I take the site name for example "gmail", capitalize the first letter, and then add "my own" 3 or 4 digit code, for example "1234" (but do not use this sequence as it is easy to break) . . . so applying the formula, the password would be "Gmail1234". Similarly, if I were to be using PenPal, it would be "Penpal1234" or "Pen1234.”
The problem with this approach, is this: If I’m a hacker and I manage to get hold of one of his usernames and passwords, for instance the aforementioned “Google1234,” I would immediately try the same username with “Amazon1234,” “Chase1234,” “Citi1234,” “UBS1234,” “Paypal1234,” etc., at those sites. How am I doing so far?

For a fascinating (and depressing) explanation of why this method of password management is only a tad better than just going with “qwerty” at all of them, read Why passwords have never been weaker—and crackers have never been stronger at ars technica. It’s long and complicated. (And it's a couple of years old, meaning the situation is worse now.)

If you don’t care to dive in, then let me summarize: the guys who are cracking passwords are smarter than you are. They are using supercomputers, and can cycle through 6.2 billion combinations of letters, numbers and characters every second. They are working off of a dictionary of more than 60 million words. Every time a web site is hacked and a list of passwords is obtained, the hacking world gains even more knowledge of the passwords we use and how we use them.

This is what it’s come down to: Given enough time, your password will be hacked. All you can do is make it take long enough that you have reasonable time to keep changing your password before it is hacked.

Every one of your passwords needs to be randomly generated by a computer, and have a minimum of nine characters to make brute-force cracks infeasible. You need to change them all every three or four months.

Now is also the time to enable two-factor authentication at every website that offers it. With two-factor identification, even if someone succeeds in hacking your password, they won't be able to log in to your account from a device that you haven’t already approved. The log in won’t be allowed until after you receive a text message on your cellphone with a code, which must then be entered in addition to the password. An excellent list of sites offering two-factor authentication is found here. And remember, as good as two-factor identification is on the sites that have it, it does nothing to prevent that hacked password from being used at another site that doesn't have two-factor protection. Which is why, class repeat after me, "we use a different complex random password at every single site."

Wednesday, April 9, 2014

These Sites Don't Use SSL and Were Never Vulnerable to Heartbleed

According to data found at the Washington Post, the following is a list of 512 websites that are not vulnerable to the Heartbleed bug as of 12:00UTC, April 8, 2014. These websites don't use SSL and so they were never vulnerable to the Heartbleed bug. Nonetheless, it would not be a bad idea to change all your passwords. Save this list for last :-)

0427d7.se
104.com.tw
163.com
17ok.com
2345.com
24h.com.vn
2ch.net
360.cn
39.net
4399.com
51fanli.com
55bbs.com
58.com
6.cn
6park.com
9gag.tv
abc.es
about.com
abril.com.br
accuweather.com
addmefast.com
adnxs.com
adscale.de
adultfriendfinder.com
aili.com
airtel.in
aizhan.com
akamaihd.net
alarabiya.net
alibaba.com
aliexpress.com
alipay.com
all-free-download.com
allegro.pl
allocine.fr
allrecipes.com
almanar.com.lb
altervista.org
amazonaws.com
ameblo.jp
ancestry.com
anyoption.com
aol.com
aparat.com
apple.com
appledaily.com.tw
as.com
ashleyrnadison.com
ask.com
ask.fm
asos.com
autohome.com.cn
avg.com
awesomehp.com
azlyrics.com
b5m.com
babycenter.com
babylon.com
babytree.com
backpage.com
baidu.com
bankmellat.ir
baomihua.com
behance.net
bestblackhatforum.com
bestusefuldownloads.com
bet365.com
beytoote.com
biglobe.ne.jp
bild.de
bing.com
bitauto.com
blackhatworld.com
blogfa.com
bongacams.com
bp.blogspot.com
brainyquote.com
businessweek.com
buzzfeed.com
ca.gov
caijing.com.cn
cam4.com
canadaalltax.com
cbc.ca
cbs.com
cbsnews.com
cbssports.com
ccb.com
ce.cn
chexun.com
china.com
china.com.cn
chinabyte.com
chinanews.com
chinatimes.com
chinaz.com
chip.de
ci123.com
citibank.com
citrixonline.com
cj.com
ck101.com
clicksvenue.com
cloob.com
cloudfront.net
cnet.com
cnn.com
cntv.cn
cnzz.com
coccoc.com
codecanyon.net
comcast.com
comcast.net
commentcamarche.net
corriere.it
coupons.com
cpmterra.com
cy-pr.com
dailymail.co.uk
dantri.com.vn
daum.net
dealshark.com
dell.com
delta-homes.com
delta-search.com
digikala.com
directrev.com
dmm.co.jp
dmm.com
dmoz.org
doorblog.jp
douban.com
drtuber.com
drudgereport.com
dubizzle.com
eastday.com
eastmoney.com
eazel.com
ebay.co.uk
ebay.com
ebay.com.au
ebay.de
ebay.fr
ebay.in
ebay.it
echo.msk.ru
ehow.com
elmundo.es
elpais.com
eluniversal.com.mx
enet.com.cn
engadget.com
eonline.com
ero-advertising.com
espncricinfo.com
espnfc.com
etao.com
exoclick.com
expedia.com
eyny.com
facenama.com
farsnews.com
fastdailyfind.com
fatakat.com
filehippo.com
firstpost.com
fishcod.com
flipora.com
foodnetwork.com
forbes.com
force.com
forexfactory.com
forobeta.com
foxsports.com
gamefaqs.com
gamer.com.tw
gap.com
gateable.com
gazeta.pl
gazeta.ru
gc.ca
getbootstrap.com
gismeteo.ru
github.io
globo.com
gmw.cn
gmx.net
go.com
goal.com
godaddy.com
goo.ne.jp
goodgamestudios.com
google.cn
googleusercontent.com
gotomeeting.com
graphicriver.net
gsmarena.com
gulfup.com
gumtree.com
haber7.com
haberler.com
haberturk.com
habrahabr.ru
hao123.com
hdfcbank.com
hindustantimes.com
hm.com
homedepot.com
homeway.com.cn
hongkiat.com
hotels.com
howstuffworks.com
hstpnetwork.com
huanqiu.com
hubspot.com
hudong.com
huffingtonpost.com
hupu.com
hurriyet.com.tr
hypergames.net
ibm.com
icicibank.co.in
icicibank.com
icloud.com
idnes.cz
ifeng.com
ig.com.br
ign.com
ikea.com
ileehoo.com
imagebam.com
imdb.com
iminent.com
immobilienscout24.de
in.com
independent.co.uk
india.com
indiamart.com
indianrail.gov.in
indiatimes.com
infobae.com
internethaber.com
intoday.in
iqiyi.com
irctc.co.in
irs.gov
it168.com
jd.com
jimdo.com
jobrapido.com
joomla.org
jqw.com
jrj.com.cn
justdial.com
kakaku.com
kayak.com
keepvid.com
keezmovies.com
kijiji.ca
kioskea.net
klikbca.com
kompas.com
kooora.com
ku6.com
lady8844.com
lanacion.com.ar
latimes.com
leboncoin.fr
lenta.ru
lequipe.fr
libero.it
linkbucks.com
linkedin.com
linksynergy.com
linkwithin.com
linternaute.com
live.com
livedoor.com
livejasmin.com
liveleak.com
livescore.com
loading-delivery1.com
mackolik.com
mama.cn
mapquest.com
marca.com
marketwatch.com
match.com
mbc.net
mediaset.it
mercadolibre.com.ar
mercadolibre.com.mx
mercadolibre.com.ve
mercadolivre.com.br
merdeka.com
microsoft.com
microsoftonline.com
mihanblog.com
milanuncios.com
milliyet.com.tr
mirror.co.uk
mlb.com
mmbang.com
mobile.de
mobile01.com
moneycontrol.com
monster.com
movie4k.to
mp3skull.com
msn.com
myfreecams.com
mynet.com
mysearchresults.com
myspace.com
mywebsearch.com
narod.ru
naver.com
naver.jp
ndtv.com
netflix.com
newegg.com
nhl.com
nicovideo.jp
nih.gov
nikkei.com
nokia.com
nordstrom.com
novinky.cz
nownews.com
nuvid.com
nydailynews.com
nytimes.com
olx.in
oneindia.in
online.sh.cn
onlinesbi.com
opensiteexplorer.org
optmd.com
orange.fr
orf.at
outlook.com
over-blog.com
overstock.com
ovh.net
p5w.net
pantip.com
pcbaby.com.cn
pcgames.com.cn
pchome.net
pcmag.com
pconline.com.cn
pcpop.com
people.com
people.com.cn
persianblog.ir
peyvandha.ir
photobucket.com
pinimg.com
pixnet.net
porn.com
postimg.org
pravda.com.ua
premierleague.com
primewire.ag
qinbei.com
qq.com
qtrax.com
qvo6.com
rakuten.co.jp
rakuten.com
rbc.ru
realtor.com
rednet.cn
reference.com
renren.com
repubblica.it
retailmenot.com
reverso.net
ria.ru
rutor.org
rutracker.org
sahadan.com
sahibinden.com
sakura.ne.jp
samsung.com
sberbank.ru
screencast.com
searchenginewatch.com
searchfun.in
secureserver.net
sex.com
shareasale.com
shutterstock.com
sina.com.cn
sky.com
skype.com
skysports.com
slideshare.net
smh.com.au
snapdeal.com
snapdo.com
so.com
sofanti.com
softonic.com
softpedia.com
soku.com
soso.com
souq.com
sozcu.com.tr
spankwire.com
speedtest.net
spiegel.de
staples.com
statigr.am
stockstar.com
streamcloud.eu
subito.it
subscene.com
sulekha.com
swagbucks.com
systweak.com
t-online.de
tabelog.com
tabnak.ir
tagged.com
taobao.com
target.com
theblaze.com
thefreecamsecret.com
thefreedictionary.com
theguardian.com
thehindu.com
themeforest.net
theverge.com
tianya.cn
timeanddate.com
tinypic.com
tmall.com
tokobagus.com
tomshardware.com
tradedoubler.com
tribunnews.com
trovigo.com
trulia.com
tube8.com
tudou.com
tukif.com
twimg.com
twitch.tv
twoo.com
ucoz.ru
udn.com
uimserv.net
uol.com.br
urbandictionary.com
usatoday.com
usps.com
v1.cn
varzesh3.com
vcommission.com
verizon.com
verizonwireless.com
vesti.ru
video-one.com
vimeo.com
viralnova.com
virgilio.it
vnexpress.net
w3.org
w3schools.com
walmart.com
warriorforum.com
washingtonpost.com
watchseries.lt
weather.com
webmd.com
webmoney.ru
webs.com
website-unavailable.com
weibo.com
welt.de
wikihow.com
wix.com
wmtransfer.com
wordreference.com
worldstarhiphop.com
wow.com
wp.pl
wunderground.com
xcar.com.cn
xgo.com.cn
xinhuanet.com
xnxx.com
xunlei.com
xvideos.com
xywy.com
y8.com
ya.ru
yac.mx
yahoo.co.jp
yaolan.com
yesky.com
yoka.com
youboy.com
youjizz.com
youku.com
youth.cn
youtube-mp3.org
youyuan.com
zappos.com
zimbio.com

zol.com.cn