Get Tech Support Now - (818) 584-6021 - C2 Technology Partners, Inc.

Get Tech Support Now - (818) 584-6021 - C2 Technology Partners, Inc.

C2 provides technology services and consultation to businesses and individuals.

T (818) 584 6021
Email: [email protected]

C2 Technology Partners, Inc.
26500 Agoura Rd, Ste 102-576, Calabasas, CA 91302

Open in Google Maps
QUESTIONS? CALL: 818-584-6021
  • HOME
  • BLOG
  • SERVICES
    • Encryption
    • Backups
  • ABOUT
    • SMS Opt-In Form
    • Terms and Conditions
    • Privacy Policy
FREECONSULT

Who protects the protectors?

  • 0
admin
Wednesday, 18 May 2016 / Published in Woo on Tech
Get Patched

In case you are new here, let me catch you up on the primary purpose of this blog. My objective is to scare you into being more secure with technology. It doesn’t always work – one person’s phobia is another’s fetish, but this one ought to give you pause. A white hat security hacker has uncovered a bug in Symantec Antivirus that would allow for an almost trivial exploitation of its scanning engine to actually compromise the computer its supposed to be protecting. And this bug exists across all three major operating systems – Windows, OSX and Linux – something that is very rare in any type of software. Not worried yet? A victim doesn’t even need to open an infected file because Symantec will do it for them when it scans the file in your email, or scans a link in your web browser. Just touching a file designed to exploit this bug will cause a memory buffer overflow, which is tech-speak for “OK malware, I’m puckering up so you can plant a big haymaker right in my kisser.”

What this means for you:

If you don’t use Symantec or Norton products for malware protection, carry on and enjoy that feeling of schadenfreude most technology users rarely experience. If you do use either of those products, Symantec has already patched this bug, and if your software is set to update automatically, it should no longer be a problem. There in lies the rub: do you know if your antivirus is up to date? How many of you have been ignoring the little warning flags your AV has been waving at you from the corner of your screen, “Hey, I need to update but I can’t for some reason!” Do you know how to make sure your antivirus is updating regularly? By the way, “regularly” means daily, if not multiple times a day. Zero-day exploits are sometimes seen within hours of an vulnerability being published. Security companies like Symantec stake their reputation on reacting quickly, but they can only lead your computer to the update river. You need to make sure it’s drinking deep, daily. Not a software update wrangler by trade? Well it just so happens I know someone who is, pardner.

You wouldn’t let your business be run by amateurs, why would you leave your technology to anyone less that an experienced professional?

exploitpatchsecuritysymantecupdatevulnerability

GWX Deal Ending in July

  • 0
admin
Wednesday, 11 May 2016 / Published in Woo on Tech
Windows 10 logo

As the adage goes, “All good things must come to and end.” Microsoft has announced that as of July 29, 2016, it will no longer offer the free Windows 10 upgrade to Win7 and 8 users. Now whether this offer qualified as “good” is a matter of debate for some folks, especially the ones that have been nagged to the edge of patience to upgrade, or the ones that finally relented, only to discover that despite Microsoft’s assurances that their computer was readyfor the switch, it was very much not. For those of you still dutifully ignoring Microsoft’s system tray app “Get Windows 10” (aka GWX), your ordeal will be over before the summer is done.

What this means for you:

If you’ve been holding out upgrading, but still plan to take the plunge, you’ll have to make a decision very shortly. Though it’s likely Microsoft will have some sort of upgrade offer to carry on the Windows 10 crusade, it may not be as generous as the one expiring in a few short months. My recommendation hasn’t changed in this regard: your computer needs to be a late model computer (2 years old, max!) with at least 4GB of RAM and at least 500GB of hard drive space, running a 64-bit OS before you should even consider upgrading. On top of this, your OS must be in tip-top shape, meaning no recent malware infections, major software crashes or undiagnosed performance issues – these things will wreck a Windows 10 upgrade without exception. Additionally, you need to make sure any critical software on that computer is Windows 10 compatible and supportable. The latter is key – lots of software will run on Windows 10, but the manufacturer may not provide any support, and even if you have pros like C2 in your corner, there’s only so much we can do without official support. Look before you leap, but start looking now!

gwxmicrosoftupgrade offerwindows 10

SmartThings home automation not secure

  • 0
admin
Wednesday, 04 May 2016 / Published in Woo on Tech
Home automation key

For those of us old enough to remember the cartoon, I’m willing to bet that at least a few of us are still holding out hope for a Jetson’s future, complete with personal jetpacks, flying cars and fully automated homes. We’re getting closer on the car and jetpack thing, but it seems we have some way to go on the home automation, despite it being around in some form for decades now. Samsung’s SmartThings platform has been around for a few years now and the continuing permeation of mobile devices across all aspects of our daily lives has led to some amazingly convenient but woefully insecure home automation systems. Researchers at University of Michigan have demonstrated several security vulnerabilities in internet-connected door locks, fire alarms and lighting systems to name a few. At the moment, using the Internet of Things to upgrade your home may actually downgrade your security.

What this means for you:

Despite the technology being available for several years, most Americans have only just begun to discover a small glimmer of a Jetson-esque future. This is due to a combination of factors that include price, complexity and a (justifiable) lack of trust in remote control devices to secure their most prized (and pricey) investments. Even Silicon Valley darling Nest (now owned by Alphabet née Google) suffered multiple PR setbacks via highly-publicized bugs, failed hardware and canceled products. As such, these products and others like Samsung’s SmartThings are only just starting to realize enough critical mass in the market to capture the attention of security researchers. For now, the University of Michigan researchers are cautioning against using the SmartThings platform wherever security is a paramount concern. I don’t know about you, but as far as this homeowner and business-owner is concerned, my house and office can stay dumb for the moment. I already have problems with phones that are too smart for their own good.

Image courtesy of Stuart Miles at FreeDigitalPhotos.net

alphabetautomationGoogleinternet of thingsnestsamsungsecuritysmarthingsvulnerability

Time to retire your company email server

  • 0
admin
Wednesday, 27 April 2016 / Published in Woo on Tech
Dead End Ahead

In the early days of the internet, building a server dedicated to providing email for your company was a sign that you understood the significant role it played (or would play) in your company’s success. Even small companies spent countless thousands of dollars investing in these complex technology beasts, primarily because it was either that, or use consumer services like CompuServe, HotMail or AOL which just couldn’t meet the growing security and legal needs of most companies. Fast forward to today and I’m still seeing SMB companies insisting on running their own servers for reasons that have since become a liability to their own business.

Things you should consider if you are still running your own email server:

  1. Do you think your email server is more secure than the ones run by Google, Microsoft or any technology company who’s entire business model is built around providing that service? Unless you are in the business of providing email services, you should focus your efforts and money on your core business.
  2. How reliable is your technology infrastructure? What happens when your internet goes down? What about the power in your building? Most clients I know have at least one planned power outage a year and probably several unplanned ones, on top of the occassional internet circuit failure. One client was recently down for over a week during the Verizon-Frontier fiasco. Could you survive without email for that long? Could your company?
  3. How much money have you spent supporting an email server that provides service for a small staff? Have you calculated the cost per user per month? Is it less than $5? If not, you are not “beating the market”. And even if you are, how long do you think that will last? Did you factor in spam and malware filtering licensing costs?
  4. After having the same mailbox and server for years, has your mailbox grown to an enormous size and now you are running out of space and have no real means to do anything about it? Is your mail backed up? Can you even reasonably search through that much email and not have constant problems?
  5. Have changes in your industry required you provide security like encryption or compliance filtering? Suddenly you are faced with the prospect of needing to not only purchase new software, but also having to update your technology infrastructure just to be compatible with the new software.

If any of these five points hit close to home, you should definitely be considering the move to a hosted email provider. The market has stabilized to the point of being able to provide enterprise-grade email services on an SMB-sized budget, leveling a playfield that used to favor deep pockets and dedicated IT staff. It’s time to retire the in-house email server and invest in the future of your business instead of a dead-end technology strategy.

budgetcomplianceemailencryptionhostingsecurityserversmb

QuickTime for Windows is Vulnerable

  • 0
admin
Wednesday, 20 April 2016 / Published in Woo on Tech
QuickTime zero day warning

During it’s heyday, Apple’s QuickTime software was arguably hailed as the king of digital video. Though there were many competitors (remember Real video?) Apple’s codec reigned supreme in both editing as well as playback for many years, making Apple’s Mac computers the defacto standard in high-end digital video editing. Not unwisely, Apple realized the untapped market potential on the Windows side of the fence, and released a version of QuickTime for Windows 3.1 in 1996, and has steadily iterated on the platform through last year, though its use has declined steadily since the rise of streaming web video. Apparently usage has fallen off so dramatically that Apple recently announced it was no longer supporting the Windows version of QuickTime, hot on the heels of the announcement by US-CERT that the latest version of QuickTime for Windows had two significant zero-day vulnerabilities.

What this means for you:

Because I know you, I won’t bore you with the how the zero-days work, just know they are serious enough for the Department of Homeland Security to issue an alert. It’s not likely you will have Apple’s QuickTime software installed on your late-model business computer, but if you own an older computer at home (5-6 years old), and you’ve installed iTunes on that computer you probably have QuickTime is installed as it was bundled into iTunes as recently as 2011. If you happen to be in the relatively narrow demographic of digital video editor using Windows and Adobe’s Creative Cloud suite, you might also have QuickTime installed as it’s a requirement for certain video editing formats.

Either way, if you have it installed, remove QuickTime immediately. Apple has no plans to patch the vulnerabilities, and even though there are no known exploits in the wild as I write this, you can bet the high profile exposure has already triggered a wave of malicious programming. The easiest way to determine if QuickTime is installed is to go to Control Panel -> Programs & Features -> Uninstall Programs and scan through the list for “QuickTime” (not Apple QuickTime, like you might think). On older OSes you might have to look in Control Panel -> Add/Remove Programs. While you are there, you can look for other old programs you don’t use anymore and remove them in the spirit of spring cleaning. 

Applequicktimesecurityvulnerabilityzero day

Is discounted tech worth the risk?

  • 0
admin
Tuesday, 12 April 2016 / Published in Woo on Tech
Big Sale?

There is no question that the cost of technology has decreased dramatically over the years, especially if the average return on investment is taken into account. However we at C2 have always taken the stance that bargain technology isn’t always a bargain for a variety of reasons. As famously said by astronaut Alan Shephard, “It’s a very sobering feeling to be up in space and realize that one’s safety factor was determined by the lowest bidder on a government contract.” Likewise, would you trust your business and security to something that was the cheapest on the market? Well, what about virtual things, Chris? Those aren’t the same as a charger you plug into your phone, or a tablet you use to check your email, right? Thanks to the expansion of top level domain names like “.top”, “.date” and “.xyz”, market competition has driven domain registration prices into the basement for the lesser known (and commercially used) TLDs, going for as cheap as $0.88 per domain. Security thinktank Talos has done the math and their research into cheap domain names bears out our philosophy: cost does correlate to quality and risk.

What this means for you:

In a nutshell, the Talos blog tells us what real estate agents already knew long ago: “Location, location, location.” In this case, because of how readily available and cheap certain top level domains have become, the security analysts behind this blog article figured there would be a correlation between cheap TLDs and malware distribution sites, i.e. cybercriminals would take advantage of the cheap domains for their attack and payload sites. As anyone with a lick of business sense knows, lowered costs equals increased profits, and as has been amply demonstrated by the large amounts of money at stake in cyberfraud, the folks behind the rising tide of profitable malware are no dummies. All this to say, just because a domain name is cheap and available does not make it a good buy, especially if the TLD is associated with pursuits irrelevant or at odds with your brand. As an (absurd) example, would it make sense for an accounting firm to register a “.party” domain?  Unless they were looking to make a radical change in their market direction, this isn’t going make sense, regardless of how inexpensive it was. For the new TLDs it will be awhile before a new normal is established (if it ever will be). Their currently cheap prices are lowering the rent in that area, and its not a neighborhood you want to settle into, at least for the moment.

Image courtesy of Stuart Miles at FreeDigitalPhotos.net

bargaindomainsqualitysecurity

New ransomware encrypts entire disk

  • 0
admin
Tuesday, 05 April 2016 / Published in Woo on Tech
Warning!

Looking back over the past few weeks I realize I’ve fallen down on my job of terrifying you with news of the latest technology boogeyman. There’s a new ransomware in town and this one gets down to business in a hurry. Dubbed Petya by security company F-Secure, this vicious piece of malware works in a similar fashion to its brethren by encrypting data and holding it for ransom, with a twist: instead of encrypting just your documents, it will “kidnap” the entire disk by encrypting the master file table, and it can do so very quickly because the MFT is just the “index” of all the files on your drive. If you were to think of your drive as a book, this is the equivalent of putting a lock on the cover and holding the key for ransom.

What this means for you:

At minimum, any virus infection is going to result in a bad day even if you have a full backup of your important data. Before your data can be restored, you need to be certain the malware hasn’t spread to other machines and is waiting to pounce the moment you get the data restored. With previous versions of ransomware, the attack would leave affected machines more or less operational as the malware only encrypted documents and usually left applications and the operating system intact. Not so with Petya which locks out the entire disk. If this malware were to attack a server, it could paralyze an entire company within seconds. If you though recovering and cleaning up a workstation took a long time, double or triple the time needed to bring a server back online, and that’s only if you had full-disk backups and not just files. A malware attack is inevitable – no amount of money, time or paranoia can provide 100% protection. Your only hope for a recovery is proper data backups managed by an experienced professional. Are you ready to test your backup plan?

Image courtesy of Zdiviv at FreeDigitalPhotos.net

backupsencryptionmalwareransomwaresecurity

Fake emails hit businesses in the wallet

  • 1
admin
Wednesday, 30 March 2016 / Published in Woo on Tech
ID-10067364.jpg

In a disturbing trend that bodes ill for everyone, multiple US healthcare institutions have been victimized this past month by highly effective ransomware attacks. In each instance, the malware infection has significantly disrupted operations and, in some cases, forced administrators to actually pay out thousands of dollars in ransoms to regain control of their data and IT systems. In the case of the Hollywood Presbyterian attack, the hackers initially demanded $3.6 million in bitcoin to release the data and systems their malware had encrypted, but settled for $17k. More hospitals in California, Kentucky and Maryland have also been hit and crippled by ransomware attacks, in some cases paying the ransom to regain control of their IT systems, and in other cases recovering systems and data through established data backup platforms and security protocols. And just to keep things interesting, toy-maker Mattel was also defrauded out of $3 million after falling victim to a carefully-planned an well-executed email scheme.

What this means for you:

Though some of the hospital attacks mentioned above are thought to have come from a documented server exploit known to exist in healthcare software platforms, analysts are reporting a surge in emails carrying viral payloads including new, highly-effective variants of ransomware, probably because of the highly-publicized ransom payment made by Hollywood Presbyterian. The harsh reality of this worrying trend is this: it costs criminals virtually nothing to start malware campaigns that are resulting in hundreds of millions in damages to organizations around the world, and it’s netting those same criminals an equivalent amount of money paid by desparate victims. Despite spending millions on security, businesses and individuals around the world still fall victim to this ploy because of the humble email. Previously I had written about ways to spot fake emails (and you can still spot them if you look hard enough), but given how many emails we receive, and how clever attackers are becoming, it’s only a matter of time before any of us get duped and it’s already too late after that second mouse-click. Or is it? Though the ransomware attacks managed to disrupt operations at the hospitals mentioned above, several of them were able to get back to work once the infections were cleaned out and data restored from backups. The temporary disruptions caused by the compromised systems were kept to a minimum, as was the damage to the wallet, by a tested (and now proven) disaster response and recovery/backup plan. How long could your business afford to be disrupted by a ransomware attack? Could your business survive the loss of critical data? What about the reputation damage resulting from disclosing the attack to customers? If you thought a backup platform was expensive, consider the alternative. In the case of Hollywood Presbyterian, $17k was just the down payment on a huge hit to the wallet. 

Image courtesy of  David Castillo Dominici at FreeDigitalPhotos.net

emailexploithospitalsmalwaremattelphishingransomwaresecurity

Proximity fob hack used by car thieves

  • 1
admin
Wednesday, 23 March 2016 / Published in Woo on Tech
Time for caution

In case I haven’t scared you enough about the technology innovations that make our lives easier at the cost of security, here’s another worry to add to the growing pile. Automobile security researchers (a growing subset in the security industry) in Germany have published their findings on using wireless amplification technology to trick certain makes and models of cars into thinking their owner is nearby, unlocking the doors and in some cases, starting the engine for the hacker, all while the actual proximity key fob is supposedly safe and secure in the owner’s pocket, purse or home. Though this method has been known for at least several years, this most recent publication noted that the technology is much cheaper to build, and the number of cars vulnerable to this hack has grown significantly.

What this means for you:

If you are the proud owner of one of these cars, you may want to consider keeping your key fob in the freezer:

  • Audi A3, A4 and A6
  • BMW’s 730d
  • Citroen’s DS4 CrossBack
  • Ford’s Galaxy and Eco-Sport
  • Honda’s HR-V
  • Hyundai’s Santa Fe CRDi
  • KIA’s Optima
  • Lexus’s RX 450h
  • Mazda’s CX-5
  • MINI’s Clubman
  • Mitsubishi’s Outlander
  • Nissan’s Qashqai and Leaf
  • Opel’s Ampera
  • Range Rover’s Evoque
  • Renault’s Traffic
  • Ssangyong’s Tivoli XDi
  • Subaru’s Levorg
  • Toyota’s RAV4
  • Volkswagen’s Golf GTD and Touran 5T

At the moment, this is the list of confirmed vulnerable models. The researchers allege that many other makes and models that use similar technology could very likely be vulnerable to this exploit as well. If your car unlocks automatically based upon your proximity to the car, then it may be possible to exploit this convenient bit of technology. And there is even anecdotal evidence to support that this hack is already being used “in the wild” to burgle cars. Basically, would-be thieves work with a pair of devices – one near your car, and the other near your key fob. The devices work in tandem to amplify the signal put out by the key fob to trick the car into thinking the fob is in unlock range, and happily opens up for the thief. In the above mentioned case, the unlucky victim ended up storing his fob in the freezer to protect against this hack, but I’m sure most of you keep your keys right near the front door – easily within range of someone with this device. Perhaps it’s time to start storing the keys next to the milk? Call us if you have any concerns – we’re not car experts but we can always help you become more secure.

Image courtesy of Miles Stuart at FreeDigitalPhotos.net

carhackkey fobproximitysecuritywireless

Windows 10 sneak attack catches users off-guard

  • 0
admin
Monday, 14 March 2016 / Published in Woo on Tech
No Windows 10

Though they “warned” everyone that they were making a change to the way the Windows 10 upgrade was being offered to Windows 7 and 8 users, it was still distressing to discover exactly what Microsoft meant when it said it was making the Windows 10 upgrade a “recommended update“. Instead of an increasingly annoying pop-up “upgrade now” message, many of my clients woke up last week to a brand-new Windows 10 upgrade that they did not approve, nor initiate. Prior to that, only a small handful of my clients had experienced the spontaneous Windows 10 upgrade since it launched last year, and one even experienced the full combo: upgrade and then rollback, neither initiated by him. It was like some sort of social experiment gone awry. If you happened to be the surprise owner of a Windows 10 computer, you are not alone: thousands of reports are rolling in of unwanted, unapproved upgrades.

What this means for you:

If you fall into the camp of as-of-yet unvictimized Windows 7 and 8 users, you need to do the following immediately if you want to avoid your very own Windows 10 surprise party:

Easy-mode: Call us at 818-584-6021 and we’ll take care of it for you.

DIY-mode (view a step-by-step video here):

  1. Go to the Windows Update control panel and disable (uncheck) “Give me recommended updates the same way I receive important updates”. 
  2. Download and install GWX Control Panel from Ultimate Outsider, or if you are worried about visiting a strange site, you can download it from the C2 Datto Drive .
  3. Click the following buttons in GWX Control Panel: “Click to disable Get Windows 10 App”, “Click to Prevent Windows 10 Upgrades”, “Click to Disable Non-critical Windows 10 Settings”.
  4. If you never plan to upgrade to Windows 10 and the buttons are available, you can also use these buttons, “Click to Delete Windows 10 Programs”, “Click to Delete Windows 10 Download Folders”. 
  5. If you’d like the control panel to watch for more upgrade attempts, you can also use “Click to Enable Monitor Mode” which will run in the background and warn you when Microsoft tries to upgrade your computer again.

For the record, Windows 10 is a perfectly serviceable OS and is, in many ways, an improvement over Windows 7 and 8. However, an unplanned upgrade can cause a loss in productivity while you learn your way about the new OS which is the best case scenario. A worst case scenario could result in loss of data, incompatible applications and severe performance issues. Don’t let Microsoft dictate how you use your computer. If you want to upgrade to Windows 10, plan for it and make sure you have experts on hand to ensure long term success.

securitysurpriseupdatesupgradewindows 10
  • 34
  • 35
  • 36
  • 37
  • 38

Recent Posts

  • woman afraid of technology

    Why Your Team Fights New Technology (Fun Fact: It Has Nothing to Do With the Software)

    Employees resist new technology because it thre...
  • man working on his desk

    Why We Say Please and Thank You to AI

    A client of mine was using a Claude agent to he...
  • man working on open laptop

    Network Monitoring: Why Professional Services Firms Need 24/7 Oversight

    Your network does not take nights off. Neither ...
  • code in a laptop screen

    Software Updates: When to Install, When to Wait, When to Worry

    On July 19, 2024, CrowdStrike pushed a routine ...
  • half open laptop

    Technology Transparency: Why We Don’t Hide Our Markups

    Go look up Microsoft 365 Business Basic on Micr...

Archives

  • GET SOCIAL
Get Tech Support Now - (818) 584-6021 - C2 Technology Partners, Inc.

© 2016 All rights reserved.

TOP