Starting in October of this year, pedestrians in Honolulu, Hawaii can be fined up to $100 if they are caught crossing a street with eyes on their cell phone instead of traffic. Coincidentally (and somewhat ironically), I read this bit of news on my phone, in Hawaii, while I was on vacation last week. However, I wasn’t walking so I can’t claim a trifecta. My first, flippant thought was, “How could anyone have their eyes on their phones while walking around one of the most beautiful places on earth?” In my defense, I was catching up with the news on my phone after a long day of specifically not looking at electronic screens, but it got me to thinking about how invaluable my phone was throughout the trip.
Could you take a vacation without your smartphone?
For those of us whose number one work tool is our phone, the answer is reflexively “Yes!”, but only because we aren’t remembering just how thoroughly indispensable the internet has become to destination vacations. Throughout the nine days we spent traversing the island, GPS, online reviews, local weather forecasts and instant access to just about any fact known to man allowed us to really get the most out of our vacation. And several of us had plenty of quality time with phone screens while standing in line, driving from scenic view to scenic view and staying in touch with friends and family who couldn’t be there with us. Could we have done the same things without the aid of such a device? Sure, but it would require a lot more planning, paper and reliance on human memory. On your next trip, make sure you leverage your technology to maximize your vacation, but don’t forget to observe local laws (and customs!) as it might just cost you more than you planned on spending!
Image courtesy of blackzheep at FreeDigitalPhotos.net
When Microsoft announced that Windows 10 would be available as a free upgrade to Windows 7 and 8 computers, millions of people took them up on the offer (some involuntarily). The upgrade was meant to jump start adoption of the new OS, and was intended to provide a way for older PCs to take advantage of a more powerful, versatile and secure operating system without having to go through a major hardware investment to do so. As many found out, the upgrade process wasn’t always the smoothest, but once your computer and you finally arrived on the proper side of Windows 10, the new OS actually performed surprisingly well on older hardware, something that couldn’t be said of previous Windows upgrades.
Unfortunately, older PCs are already being abandoned by Microsoft’s forced updates
Flash forward to present day, after the gamut of upgrade experiences, and after the most troublesome upgrades have turned the corner as productive computers, many users are finding that Microsoft’s forced updates are no longer available for certain hardware configurations or even rendering parts of their computers unusable.
As always, the fine print is where we “get got”: When the free Windows 10 upgrade was first announced we were told that Windows would be kept up to date “for the supported lifetime of the device at no additional charge.” Just prior to the actual Windows 10 launch date, Microsoft clarified this stance with the following:
A device may not be able to receive updates if the device hardware is incompatible, lacking current drivers, or otherwise outside of the Original Equipment Manufacturer’s (“OEM”) support period. (emphasis mine)
What most people still fail to realize that on top of the Windows operating system being updated by Microsoft, there are typically a whole host of drivers that your computer manufacturer provides for the various bits of hardware that comprise your particular computer model. In the past, the manufacturer would launch a particular model line as “certified” for a particular version of Windows, allowing them to also build and maintain a set of hardware drivers that were designed for a specific OS. As Microsoft marches forward, the hardware manufacturers are forced with the choice of spending resources to patch (or even rewrite) drivers to keep up with Windows on their older hardware, or focus those resources on putting out new drivers on new hardware. It shouldn’t take much thought to see why both Microsoft and your PC’s manufacturer are leaving your old PC behind.
Sadly, you are now forced to make a choice. Roll-back (if you can, and some of my clients can’t) the update that killed your PC, and then figure out how to avoid the forced updates pushed out by Microsoft (inadvisable in the long run due to security risks), or cough-up for a new Windows 10 PC. While the first choice may save you some money in the short-run, you will eventually have to succumb to Microsoft’s update cadence, and unless your PC’s manufacturer takes the unlikely approach to releasing working drivers for your old hardware, it will be time to go computer shopping once again.
Normally I try to keep to pure technology news on this blog, but I believe this issue is important, probably more so than many of my clients realize. Net Neutrality is a simple issue made complex by sophisticated marketing, partisan politics and the fact that both sides have reasonable points. What’s currently at stake is this: the FCC, after previously passing rules in 2015 to “prohibit Internet providers from blocking, throttling, and paid prioritization—”fast lanes” for sites that pay, and slow lanes for everyone else,” is now seeking to repeal those rules due to a dramatic shift in FCC leadership. Predictably, money supporting the repeal of these rules is coming from ISPs, and they are spending a lot of money to lobby for Net Neutrality to NOT be protected.
Fortunately for consumers, many of the internet companies we use everyday (Spotify, Netflix, Amazon, Dropbox to name a few) continue to fight for your right to unfiltered, unthrottled internet. July 12th has been named as a the “Day of Action” in support of Net Neutrality, and you may see sites all over the internet (like this one) sporting banners and images indicating that support. What are they asking you to do? Primarily, they are asking you to demonstrate your support by writing or calling your local congress-critter to let them know you are in favor of Net Neutrality and that FCC should reconsider their plans to repeal the rules that were established in 2015.
I believe it’s important for you to be aware of what’s at stake. The internet is an indispensable part of our lives both personally, professionally and politically whether we like it or not, so issues that affect your access and use of it should not be taken for granted. Please take a moment to familiarize yourself with Net Neutrality if only to understand what’s happening on the internet on July 12.
For those of us living in wildfire country, celebrating the 4th of July with any sort of pyrotechnics was typically accompanied with a constant refrain of keeping the holiday “safe and sane.” Seeing as I can’t legally or safely join you in feting our nation’s birth by blowing stuff up, I’ll instead share some tips on keeping your computer from joining the festivities with its own version of “bombs bursting in air”.
Computers don’t normally catch fire, do they?
Aside from the usual digital measures you should be taking to protect against virtual bombs blowing up your data, there are some practices you should follow to make sure your actual technology doesn’t go up in smoke:
- Desktop computers should be blown out with canned air at least once a year, and if you happen to be in a dusty office or one with furry/hairy pets nearby, at least twice a year. You should take the device outside before blowing it out, and pay close attention to the fans and vents. Vacuums are OK to use as long as you are grounded properly, otherwise its possible to create enough static electricity to damage older computer components. Laptops can be blown out with canned air as well – just puff the air into any exposed vents and keep your face away from the device while doing so or you might get a snoot full of dust.
- When using a laptop on anything other than a hard, flat surface make sure it has enough area around the vents on the sides and bottom to properly cool itself. If you are using it on your lap, make sure it isn’t surrounded by your clothes or other things you are using to keep it off your lap (like a jacket or pillow). Newer laptops can shut themselves down when they get too hot, but repeatedly overheating your device in this manner will considerably shorten its useful life.
- Batteries can melt, burst and even explode with enough heat and force to seriously injure someone. If you notice your device is getting too hot while plugged in, unplug it immediately and discontinue use of the device until it cools down. Have the battery and your AC charger checked if it the battery continues to behave this way.
- Do not overload an outlet or surge protector with too many devices, especially if your technology is sharing a plug with something like a portable heater that draws a lot of amps. The combined load can blow a circuit breaker if the electrical is wired properly, but not before melting your surge protector and shorting your device’s power supply.
- Be wary of cheap, off-brand chargers for your portable/mobile devices. If they spark, get too hot, or smell funny when plugged in, stop using them immediately. The same goes for cords. If your cord has exposed wires, burnt casing or has to be twisted “just right” to get it to work, stop using it and replacing it with a new cord.
Older devices will succumb to heat related problems more often than not, especially if they are used constantly. Though there are rare exceptions, most computers have a usable life of 6-8 years, and this period is shortening as we move forward towards present day. Technology today is manufactured to be replaced more frequently than in years past now that prices have dropped to the point where its often cheaper to replace than repair. Keep that in mind when judging whether its time to put that old device out to pasture for good.
After nearly 30 years of working in the industry on the business end of technology failure I can confidently attribute this inevitability to two things: humans and entropy. The first one is obvious – to err is human and the second cause is really more of a cop-out: technology, just like anything, is subject to a certain degree of decay. Sometimes it’s so gradual we don’t notice the slow decline, and occasionally it’s so sudden and random that it feels like a plot twist in a bad spy film. Regardless of the cause, getting it fixed means calling your IT professional. The more prepared you are for the call, the quicker the issue will be resolved. Assuming you’ve tried the things we’ve been training you to do before calling (turning the power on and off, checking your cable connections, etc.), getting prepped prior to the call will help your IT pro get to a resolution that much quicker.
Ten things you can do to get ready for the call
- Get a picture of the error or problem. Smartphone cameras are helpful with this if you can’t get a screenshot on your computer. Make sure it’s in focus and big enough to read any text on screen, then email or text it to us.
- Can’t get a picture? Write down the error message. The exact wording on error messages is VERY important.
- If you can reproduce it (without causing further damage), write down how you got the problem to occur. You can also record a short movie with that omnipresent smartphone.
- If you can’t reproduce it, write down what you were doing when it occurred. Details are important, so doing this as close to the event as possible will save the later struggle of trying to remember details that might be relevant.
- Have associated passwords handy. It’s OK if you don’t know the password – just let us know up front.
- If you’ve done something silly, foolish or dumb, come clean as soon as possible. True IT pros have seen it before and we are paid to be non-judgmental. You might get a lecture afterwards, but we are only trying to save you from future grief.
- If you can’t spend time with us to troubleshoot – let us know up front so we can schedule the work accordingly.
- We know it’s urgent but if you can sit back and really evaluate how urgent, it helps us prioritize your call.
- If possible, prepare yourself and your computer for our call: save and close unrelated work and applications. If you are likely to be interrupted, let us know up front so we can prep for that possibility.
- Take a deep breath and smile, even if you are ready to tear your hair out. We are here to help, and we can usually get to a resolution faster when everyone is calm.
This is the follow up to last week’s “Get rid of those old email accounts” blog wherein I presented you two great reasons to thin out your collection of email accounts. Hopefully you’ve thought long and hard about this and have come to the realization that you can, in fact, give up at least one old or unused email account, but there are emails that you want to keep. Given how much drama “old emails” seems to have caused our country in the past months, it’s hard to imagine why anyone would want to keep them around, but we’ll assume (a) you have legitimate reasons, and (b) are not improperly storing classified data. If true, read on.
Why can’t I just leave them where they are?
In most cases, email is stored on a server somewhere on the internet, aka “hosted” email service. When that account is canceled, all data associated with that account is deleted, usually immediately. Sometimes there is a grace period of 30 days where you can recover the account, but don’t count on it, especially if it’s a “free” email account. If the account is located on a mail server that is managed by your (former) organization, this is known as “on premise” email service, and whether your email box is retained or deleted will be determined by that organization’s internal policy. In either case, the objective is to stop that mailbox from receiving email so that your problem isn’t compounding over time, especially since it’s likely all spam and malware, and the only way to do this is to remove that mailbox from the internet.
Most “freemail” providers like Yahoo, Gmail, Hotmail etc. offer a method to “export” your emails, and unless you’ve alredy been maintaining an archive through a program like Microsoft Outlook, this will be the quickest way to grab a full set of all emails. This process will typically provide you with an MBOX file which can then be imported into most major email programs like Outlook or Apple Mail. It’s also possible to use those programs themselves to “export” the email to dedicated archive files, allowing you more granular control over what is kept and what is not. OSX includes Apple Mail as part of its base installation, but if you don’t already own Microsoft Outlook, there are other, free mail clients that may work for you, such as Thunderbird or SeaMonkey, both of which are available for either operating system. Importing old emails into an archive creates an “offline” email box in your program of choice, which as you might have guessed by the name, is only available to that machine.
Another option you can consider is importing that old email into your current mailbox. Only do this if the number of emails you are importing is small and your current mailbox isn’t already too large. “Too large” is not a fixed number, but most email programs struggle when dealing with more than 500K old emails, or email file sizes in excess of 20GB, and that is even on a well-equipped computer with 8GB or more of RAM. Importing old email into your current mailbox will provide you with the ability to search your email from devices other than your computer, but may severely impact performance, so choose carefully.
Archiving email can be a complicated process, and is often fraught with strange issues. If the old emails are important, you may want to consider hiring a professional to ensure your old emails are kept safe and accessible.
Image courtesy of Stuart Miles from FreeDigitalPhotos.net
Nearly two years ago I wrote a three–part article about taming the most ferocious of virtual beasts: your email. Even though I know all of you fight the good fight on a daily basis, some of you are your own worst enemies, multiplying your load by maintaining more than two mailboxes (personal and work) on top of your regular social media addictions. I’m not talking about the folks whose work responsibility includes managing mailboxes for other people (but I feel for you, especially the ones that face 5-digit unread counts). If you aren’t in the fortunate position of having human help to manage your collection of mailboxes, you should really consider consolidating or outright deleting those old email accounts.
Sacrilege! Burn the witch!
Before you go all angry mob on me, here’s why you should slim up your email presence by ditching seldom-used email boxes.
Security – there are so many reasons why managing multiple mailboxes is a security nightmare, but here are 3 that should resonate with you:
- Remembering and maintaining passwords for all your mailboxes. You’re using strong passwords for all of them, right?!?
- Old email accounts are a treasure trove of identity info for data thieves. If you don’t check them often, they might even be compromised already, and may have been for months or even years.
- Every email address gets spam and malware. Multiply your risk by the number of mailboxes that receive email. Multiply by 2 for “free” email accounts that have poor or no spam filters.
Expense – each mailbox is another mouth to feed. Even the free mailboxes aren’t really free:
- What’s your time worth? If you spend 15 minutes a day managing a mailbox, you will spend nearly 8 hours a month that could be better spent elsewhere.
- If you are using your phone to check these email boxes, that data downloaded is costing you, especially the spam – it’s the digital equivalent of empty calories, but the only thing getting fat is your mobile carrier’s bank account.
- Get infected by malware from a poorly protected email account? A minor malware cleanup will cost you a minimum of $200-300 if handled by a firm like C2, and we haven’t even accounted for your lost time, productivity or sales. We won’t speak about network-wide infections – those costs can start piling up into really big numbers, even if you are insured and backed up.
Next week we talk strategies for thinning the email herd!
Image courtesy of iosphere at FreeDigitalPhotos.net
You know it’s a problem when even a company like Google can’t keep bad apps out of it’s own Play Store. While we’ve seen several instances of lone bad apps sneaking into public release on the official Android app store, this latest batch of malware is surprisingly prodigious and apparently managed to go undetected for almost a month. The majority seemed to have been released as games from a South Korean developer, all of which feature a character named “Judy”. The malware, dubbed the same as the titular character, isn’t actually part of the game (which has its own unavoidable advertising to click through) but is installed after the game is loaded, and is designed to open other advertisements and click them to generate revenue for the advertisers. This particular denizen of hell is known as an ad-clicker, and as you can imagine, having it clicking ads on millions of phones will add up to some serious dollars.
What this means for you
Up until maybe a year ago, my standard advice to all smartphone users has been to restrict your app browsing to the official Google and Apple stores, though Amazon has done a decent job keeping the riff-raff out as well. Most malware infections and hacked phones were typically traced back to “side-loading” apps found on “unofficial” stores, but this latest batch of nastiness was downloaded by millions of people from Google’s own backyard. My most recent addendum to this advice has been to make sure you read the reviews on the app, and to carefully monitor the permissions it requests before installing, as well as to keep an eye on the apps data consumption. Unfortunately, one of the other areas in which Google and Apple are being outplayed is in the review system which is under assault by comment bots and overseas sweatshops designed to pump store ratings on bad or spammy apps that otherwise would be downvoted into oblivion, so this method of determining legitimacy is now much less trustworthy. If you don’t have the technical chops to determine if the permissions requested for an app install are appropriate, make sure you ask an expert. And if you are at all in doubt, maybe a virtual playdate with Judy isn’t something you need on your smartphone right now. There are plenty of completely legitimate, free apps available for install that won’t turn your device into a zombie for the ad-clicking bot swarm, but it will take some vigilance to find the right one.
I think it’s safe to say that many of us would have very much liked Samsung’s sexy new iris recognition feature on their new Galaxy S8 smart phone to be more than an over-used movie gimmick. Sadly, like its previously defeated brethren fingerprint and face recognition protections, it too has proven to be fallible, and not in a gory, Hollywood-esque fashion, but in a mundane, easy to implement way. The German security team Chaos Computer Club has published its methodology demonstrating the bypass hack, which involves the use of a camera with night-vision capabilities and a contact lens. Yes, you read that right. This $750 smart phone can be defeated by taking a picture of the owner’s face, printing out a properly sized picture of the eyes, and then placing a contact lens over the iris in the picture.
What this means for you
Unfortunately, we still don’t have the magic bullet solution for securing our mobile devices. And by “magic” I mean a method that is both easy to use as well as highly secure. As I’m sure you’ve personally experienced, “convenience” and “strength” are on opposite ends of the security teeter-totter. Tip too far in one direction and the opposite suffers. Currently the most secure method is multi-factor authentication, which requires at least 2 different forms of identification to unlock an account or device, and on the opposite, you have methods like Android’s Smart Lock which can keep your phone unlocked based upon its proximity to known devices like your home WiFi or your car’s Bluetooth connection. The safety implications of the latter are fairly obvious, but can be useful when considering the various scenarios and inherent safety risks. Using Smart Lock to keep your phone unlocked while you are driving is fairly secure, and actually is a form of multi-factor authentication: it requires the presence of the phone and your running car. Having both stolen at the same time could happen, but unless you are someone who tends to forget their phone and keys in the car, highly unlikely. When deciding on how inconvenienced you are willing to be, consider what sort of data and services a thief might have access to on your unlocked phone. A few more key presses is still more secure than bio-metrics at the moment.
Famed painter and TV personality Bob Ross was beloved for his soothing instructional style and effortless technique, but he was also well known for referring to his occasional painting mistakes as “happy little accidents” which would quickly be transformed into art. In the technology industry, “accidents” are rarely happy and even the little ones have a tendency to “go big” way too often, but this past weekend a British security researcher for Ars Technica briefly held back the WannaCry horde purely by accident, possibly long enough for Microsoft to rally and release an out-of-band patch for the old operating systems that were being hit hardest by the malware.
Tell us a story, Woo!
I’d like to say that his exploits would make for a great Hollywood movie, but that would be a happy little lie. Instead, the researcher known as “MalwareTech” registered a domain name he found in the code of WannaCry as part of standard operating procedure. Contemporary malware often uses random/junk domain names to host command and control infrastructure used to direct activities of their bot armies, and security researchers like our hero often register any unregistered domains they find in malware code in order to “sinkhole” infections and dismantle bot armies built around domains now under the control of the good guys. Think of it as a virtual sting operation. Usually this would put a small dent in the overall cyberattack, but in this case the WannaCry malware stopped in its tracks as, in this case, the domain was designed as a kill-switch. Once the malware saw that the domain actually existed on the internet, it was programmed to stop working.
Sadly, this wasn’t the triumphant conclusion to an epic trilogy, but the dark, middle chapter in the ongoing war: shortly after the accidentally won respite, new variants of WannaCry started propagating sans the kill-switch, and the battle is rejoined. Fortunately for the “good guys” Microsoft issued emergency patches for Server 2k3 and Windows XP and several other End-of-life operating systems still in wide use around the world, but this desperate Hail Mary only prolongs the slow slide into complete obsolescence for some companies that foolishly cling to unsupported technology in a classic example of “penny-wise, pound foolish.”
Despite the brief, shining moment of hope, the kill-switch didn’t magically undo the thousands of encrypted hard drives already kidnapped by WannaCry. Unless they have backups of their data, the victims face the hard choice of paying the ransom or wiping it all out and starting from scratch. And even if they are able to restore from backups, will the sting of this attack be enough to galvanize change, or just another Sisyphean trudge up a well-worn hill?
Image courtesy of Stuart Miles at FreeDigitalPhotos.net











