Black Friday and Cyber Monday are upon us, and I know at least half-a-dozen people that are planning to go technology shopping. Many of you are like me and are wise to retailer shenanigans leveraging seasonal enthusiasm and internet hype to separate us from our hard-earned cash, but there are deals to be had if you look hard enough and are willing to battle the crush of humanity at the brick and mortars instead of just doing your shopping online like any sane human being. If you are one of the hardy Black Friday shoppers physically participating in one of America’s finest traditions (definitely sarcasm that time), please don’t let the shopping bug blind you to shady retailers taking advantage of your holiday spirit. In Office Depot’s case, they didn’t even have Black Friday chicanery as an excuse to sell completely unnecessary malware cleanup services on computers that were brand-new in the box.
Someone’s heart was clearly “two sizes too small”
Let’s be clear: big-box retailers sell technology at costs that most providers like C2 can’t hope to match. Their volume and industry position allow them to cut deals on hardware that sometimes seem impossible, and here’s a dirty little secret: those invisible margins are in fact not so thin due to bundled software deals and, in some cases, extended 3rd party warranties. Software manufacturers like McAfee, Symantec, and even Microsoft and Adobe will pay computer manufacturers to ship their software pre-installed on your brand-new computer. Sometimes it’s a convenience – who wants to go shopping for anti-virus software after fighting the crowds for your shiny new computer? But not always, as is the case of the above scam. Office Depot seems to have benefited on both sides of the market by selling computers pre-installed with a questionable anti-malware app called “PC Health Check”. This slick piece of work (more sarcasm!) was finding malware on brand-new computers, prompting concerned buyers to go back to Office Depot where they were sold unneeded “cleanup services” often to the tune of several hundred more dollars.
Are dwindling big-box margins to blame for driving adoption of these scummy sales practices? Probably, but it’s a flimsy excuse to take advantage of your customers. If anything, you are driving them online and to companies like C2 who are more interested in partnering with customers instead of merely profiting from them. As always, caveat emptor. If it seems like a deal too good to be true, it just might not be a good deal after all.
Last week’s election has the media and media watchers doing quite a bit of navel-gazing, especially the ones that predicted a wildly different outcome. Among the companies identified as a major agent of influence is Facebook, and not for respectable reasons; the social media platform has been plagued with fake news stories that spread virally throughout its millions and millions of users, most of whom accept the fabrications and hoaxes as if they were vetted and sourced by actual news organizations. Arguments have been made that these same stories might have had a measurable influence on the November elections.
As has been mentioned before, the Internet is the great equalizer when it comes to “presence”. It allows small companies to appear big while allowing big companies to target niche audiences. With a bit of savvy and determination individuals can create a presence that, at first glance, looks established and trusted. And therein lies the rub: as a rule, the public will only give a cursory inspection to the majority of what they find online. Once it passes the “sniff test”, trust is granted and that presence is essentially on equal footing with everything else. After all, who has the time to find out whether the website or person that published this news story has any credibility or reputation? It’s easier and more comforting for everyone (myself included) to read articles that align with our world views and values. Questioning everything is time consuming and often discouraging, and who has the time for that?
What this means for you:
Obviously I’m generalizing here, and I’m definitely not including my clients who have hopefully been well trained in being vigilant and suspicious of anything they find on the internet. I know you don’t come here to be scolded, but instead to learn about technology. Here’s the start of a thing that may help sort out the truth from the lies on one part of the Internet: a group of college students have written a Chrome plug-in that will use the internet to determine whether a story that appears on Facebook is actual verified news or maybe something a bit (or a lot) less. Don’t get too excited – as you might have imagined, the majority of the world doesn’t actually consume Facebook via desktop Chrome. It’s a mobile world at the moment. Hopefully we will see other tools like this appear for mobile apps, or even Facebook itself take on some responsibility as widely read media outlet. The truth is out there – but you still have to work a little harder to see it.
Unfortunately, stories of ransomware holding companies hostage are becoming so commonplace that reporting on them is almost not worth it anymore. The public is building up the same type of awareness fatigue everyone experienced last year with the numerous data breaches occurring in our most well-known companies and platforms. The latest victim is the county of Madison, Indiana which actually had to shut down all non-emergency operations due to a ransomware infection, shuttering courts and county offices, and sending government employees home. Sadly, it appears they did not have backups of what was encrypted, as they are paying the ransom at the behest of their insurance carrier.
What this means for you:
While Madison County’s lack of data backups is reprehensible (if not somewhat predictable when it comes to government IT budgets), the fact that someone in charge was savvy enough to insure county operations with a policy that would actually pay the ransom (less the deductible, of course) is the relevant lesson. Lest you take the wrong message from this, taking out a cyber insurance policy in place of having proper backups and security is being penny wise and pound foolish. The likelihood of an insurance policy getting you out of a technology disaster pales in comparison to the reliability of a solid backup system and managed security. Your best strategy is to have both insurance and a solid technology infrastructure. The insurance is best used to cover the costs of recovery, which may include cleanup, data restoration, client and customer notifications, and possible breach violation fines.
Image courtesy of Stuart Miles at FreeDigitalPhotos.net




