Friday, March 25, 2016

LA Times: Ransomware infects two more hospitals.


Two more Southern California hospitals have been attacked by hackers who infiltrated their computer systems with ransomware and demanded payment to unlock the data, officials said.
Favorite part:

 "FBI’s Eimiller said the bureau does not recommend paying a ransom."

That's not what Business Insider says:
Reported last week by Security Ledger, Joseph Bonavolonta, the Assistant Special Agent who oversees the FBI’s CYBER and Counterintelligence Program in Boston, spoke at the 2015 Cyber Security Summit and advised that companies infected with ransomware may want to give in to the criminal’s demands.
“The ransomware is that good,” Bonavolonta explained to an audience of business and technology leaders during the Q&A. “To be honest, we often advise people just to pay the ransom.”
http://www.businessinsider.com/fbi-recommends-paying-ransom-for-infected-computer-2015-10

Hmm, so what is it?

I think we need to figure it out ourselves.    (www.googleityourself.com)







Tuesday, February 23, 2016

Upgrade your iPhone 6 from 16GB to 128GB

 Upgrade your iPhone 6 from 16GB to 128GB

This is awesome!

Apple detects replaced fingerprint scanner but not replacing the whole flash chip? seriously?

https://www.youtube.com/watch?v=8wbbW-3be1g



 

Wednesday, February 3, 2016

Not security, but Twitter and Comcast speed test fun

I found this on ARS - 3-Feb-2016

Angry Comcast customer set up Raspberry Pi to auto-tweet speed test results
http://arstechnica.com/business/2016/02/comcast-customer-made-bot-that-tweets-at-comcast-when-internet-is-sl\ow/


Which pointed to the twitter bot code on rasp-pi
http://pastebin.com/WMEh802V

Which ran speedtest-cli from Github
https://github.com/sivel/speedtest-cli

which showed these results
daddy@raspi ~/speedtest $ ./speedtest-cli
Retrieving speedtest.net configuration...
Retrieving speedtest.net server list...
Testing from Comcast Cable (50.169.221.148)...
Selecting best server based on latency...
Hosted by Axcelx Technologies LLC (Somerville, MA) [71.49 km]: 35.279 ms
Testing download speed........................................
Download: 14.51 Mbit/s
Testing upload speed..................................................
Upload: 5.68 Mbit/s

Tuesday, January 19, 2016

EFF Pries More Information on Zero Days from the Government’s Grasp

EFF Pries More Information on Zero Days from the Government’s Grasp

Until just last week, the U.S. government kept up the charade that its use of a stockpile of security vulnerabilities for hacking was a closely held secret.1 In fact, in response to EFF’s FOIA suit to get access to the official U.S. policy on zero days, the government redacted every single reference to “offensive” use of vulnerabilities. To add insult to injury, the government’s claim was that even admitting to offensive use would cause damage to national security. Now, in the face of EFF’s brief marshaling overwhelming evidence to the contrary, the charade is over.

In response to EFF’s motion for summary judgment, the government has disclosed a new version of the Vulnerabilities Equities Process, minus many of the worst redactions. First and foremost, it now admits that the “discovery of vulnerabilities in commercial information technology may present competing ‘equities’ for the [government’s] offensive and defensive mission.” That might seem painfully obvious—a flaw or backdoor in a Juniper router is dangerous for anyone running a network, whether that network is in the U.S. or Iran. But the government’s failure to adequately weigh these “competing equities” was so severe that in 2013 a group of experts appointed by President Obama recommended that the policy favor disclosure “in almost all instances for widely used code.” [.pdf]

For more information, follow this link

Thursday, January 7, 2016

The FTC goes on record FOR good encryption for consumers!

Yay!  The government agency whose job is to advocates for consumers and taxpayers is actually doing it - give the FTC a gold star (seriously)!

FTC gives FBI the finger over govt backdoor encryption demands

Commissioner joins CTO in its 'don't be stupid' rationale

 he US Federal Trade Commission (FTC) has fired a second shot at the FBI over its demand for backdoors in encryption systems.

Following a blog post last month by the regulator's CTO in which he outlined why he was glad to have strong firmware encryption after his laptop was stolen, today FTC Commissioner Terrell McSweeny has also outlined why encryption is a good thing – and carefully suggests that introducing a way to undermine it may not be such a great idea.
"Now, more than ever, strong security and end-user controls are critical to protect personal information," McSweeney wrote in a blog post on Thursday.

more...

 http://www.theregister.co.uk/2015/09/04/ftc_sticks_a_finger_up_at_feds_over_encryption/

 

Friday, December 18, 2015

Have Comcast? Have a data cap? (yes). Are they billing accurately? Do they care?

Are they billing accurately?  Maybe?  Do they care?  Definitely not!

http://arstechnica.com/business/2015/12/comcast-admits-data-cap-meter-blunder-charges-wrong-customer-for-overage/

"I called Comcast... and was patronizingly informed that 'it must be somebody stealing your Wi-Fi,'

When he got Ars Technica involved:

Oleg provided us his full name and address so we could check into his situation with Comcast. The company investigated the problem after being contacted by Ars and confirmed that its meter readings were inaccurate. “We have reached out and resolved this,” a Comcast spokesperson told Ars. “There was a technical error associated with his account, which we have since corrected.”
 ...
“It turns out their system had my modem MAC address entered incorrectly, there was an off-by-one typo that was hard to see so they were counting data from some modem who knows where,” Oleg told Ars.

Comcast.  Die.  Die. Die.

#Comcast #ComcastDieDieDie



Tuesday, December 15, 2015

The Down side of cloud updates, and how to infuriate your customers

Well, this is a new one, how about a Fortune 100 company, Philips, making a IoT product, Hue, with a tenuous grasp on a small market share makes an open product that seems that in spite of a few warts is pretty good, and getting better, decides to change their strategy?

What if it's to delete the "open" part and only talk to own products, Breaking its functionality for users of existing third party products?


Well, the customers were furious, with light bulbs that they can't turn on, and hopefully, they'll (safely) light their Hue hub on FIRE, send it back to Philips, buy a third party hub and never buy another Philips product again.

I certainly won't.

Note to "bright bulbs" at Philips.  (get it? snort).  You know the razor blade and handle story.  Well this is what you did.  You sold a handle and a bunch of blades, and someone else made blades that fit the handle, and you changed the handle so the other peoples blades didn't work, even the ones already bought, and the customer still uses.  For some reason, the customer can't have multiple handles, but they can buy a handle from the "other guys", throw yours away, and never buy another blade from you again.

Update:  Philips backs down, also from Techdirt, that was quick - https://www.techdirt.com/articles/20151216/07562133099/after-spending-day-as-internets-punching-bag-philips-walks-back-firmware-update-that-locked-out-third-party-products.shtml