Several technology manufacturers, including Broadcom (whose chips you probably have in several devices around your home and office) are planning to release in 2015 chips for a new networking protocol called G.Fast which can push bandwidth transmissions on twisted-pair copper lines to near fiber-optic speeds of one gigabit per second. Throughout the US and many other developed nations with significant communication infrastructures, internet speeds aren’t limited by technology but by physical wiring. The most common form of internet service in the US, Digital Subscriber Line (DSL), is delivered via the same wires that provide basic telephone service, that were, up until now, limited in how fast they could transmit data mainly by what amounts to a simple (but hard to overcome) physics problem: copper wires are susceptible to radio-frequency interference from adjacent sources, including each of the strands in a single pair that delivers the signal.
What this means for you:
Don’t rush out to cancel your existing internet service. G.Fast isn’t expected to make an appearance until 2016 at the earliest, and providers will still have to grapple with an issue that they have faced many times in the past: the full, gigabit transmission speed of G.Fast is still limited by distance, with the last leg not exceeding about 160 meters before the speed drops off drastically. This means that ISPs will still need to install equipment proximate to residences and offices, something that is costly and time-consuming to execute, and very few ISPs (maybe with the exception of Google and their Fiber initiative) have demonstrated a willingness to pursue until they are forced to (see ATT’s GigaPower counter to Google Fiber). However, the fact that this technology can utilize existing wiring that is available in just about every building in the US means that getting to gigabit internet speeds might not require companies tearing up streets and hanging from telephone poles to string the more expensive cables needed for fiber-based solutions. And you can bet that companies like ATT and Verizon will seize on any opportunity to compete with Google, especially when they can spend less money to field a competitive solution.
Image courtesy of David Castillo Dominici at FreeDigitalPhotos.net
According to security and censorship watchdog Great Fire, the latest iPhone just made its debut in China, and already new owners are being hacked by what appears to be a state-sponsored “man in the middle” attack. Though there have been many other allegedly government-backed attacks on US-based companies, presumably for commercial or political gain, this appears to be aimed at gaining iCloud identities of its own citizens, and its hard to not draw a dotted line to the recent Hong Kong protests, images and news of which were widely disseminated by mobile devices like the iPhone.
What this means for you:
Unless you are a Chinese citizen that has somehow managed to find your way to this modest blog, this particular event won’t have much impact on you. The hack is actually being perpetrated by China’s “Great Firewall” and only affects a specific, Chinese-only browser called 360 Secure Browser made by a company called Qihoo. Use of this browser is apparently mandatory for all education institutions in China. Seeing as other browsers not under the control of the Chinese government like Firefox and Chrome appear to be unaffected by the hack, it’s hard not to jump to some obvious conclusions. While the more conspiratorial among you may whisper that the American government is only a few steps behind the Chinese in this egregious breach of privacy, it’s important to note that unlike China, US-provided internet is not gated by a single, government-controlled firewall like China’s Great Firewall, nor our are students and teachers mandated to run a (allegedly) state-backed browser. However, this does not mean you should be less vigilant in protecting your security and privacy, as its quite apparent that US agencies like the NSA have no problems snooping on its citizens anyways.
If you thought you had data breach fatigue, prepare to be exhausted this week:
- Hacker tries to scam Internet with fake DropBox password database – DropBox refutes the claim, noting the “proof of hack” provided consisted of known stolen passwords from other sources.
- Kmart Hacked – Undisclosed Quantity of Credit Card Numbers Stolen – Sears-owned retail outlet may have been a victim of known point-of-sale malware “Backoff”, says no identity info stolen, just credit and debit card numbers.
- SnapChat denies it was source of potential racy photo leak – Third-party addon app “SnapSaved” blamed for providing an avenue for hackers to save pictures from SnapChat. SnapSaved admits to security breach, but downplays claims that hackers could provide a “searchable” database of photos.
- NATO Summit Gets Breached by Russian Hackers – Hackers whom security analysts believe to be Russian exploited a Zero-day flaw in Windows operating systems through a spearphishing campaign targeting Ukrainian government workers, leading to breaches on government servers and probably information leaks from Summit proceedings.
- Google Documents Flaw in SSL 3.0 Protocol – Google documents a serious flaw in encryption protocol SSL 3.0, immediately removes it from Chrome web browsers. Though outdated, SSL 3 is still widely used as a fallback protocol when newer protocols fail to function.
- 850K Records Exposed in Oregon Employment Dept Website Breach – State-run website exposes personal information on hundreds of thousands of job seekers. No financial information was exposed, but leaked info could lead to identity theft.
First the country’s largest bank has a huge data breach, and now the nation’s largest bond insurer admits that it inadvertently exposed sensitive customer information through its website. As an example of the old maxim, “Man has no greater enemy than himself,” MBIA, Inc. allowed unfettered access to a subset of very sensitive customer information (think: customer names, account and routing numbers, balances and dividend amounts) via a poorly configured webserver that opened up this data to the general internet. Access was so unrestricted as to allow search engines to index up to 230 pages of information that also included administrative login credentials that could lead to much more significant security breaches throughout the MBIA infrastructure.
What this means for you:
Today’s technology is a resounding testament to how innovative humans are, but equally apt to demonstrate just how fallible we can be. In the digital world, a simple mistake can lead to millions being compromised in life-affecting ways. Most of you aren’t responsible for millions of customers or their data, but imagine if you had to contact your hundreds or thousands of customers with the bad news that “due to a configuration error” their data was leaked to the internet, and probably in the hands of cybercriminals. Whether it is thousands or millions, it would still be a nightmare, especially if your business isn’t big enough to be able to count on the data breach fatigue that has allowed Target, Home Depot and JP Morgan to sail past titanic failures in security. In the end, your security boils down to one thing: humans, not machines. Knowing this, you should always hope for the best (we will get better at this) and plan for the worst: we’re going to make a lot of mistakes along the way!
America’s biggest bank JP Morgan Chase announced last week that it was the latest victim of a major security breach. According to their regulatory filing, data from nearly 80 million customers was exposed in a successful hacking attempt earlier this year. Though the bank was quick to emphasize that our money and most sensitive bits of info such as dates of birth, social security, passwords and IDs weren’t stolen, names, addresses, emails and phone numbers were – all which could be used to facilitate an identity theft, but which aren’t considered protected or sensitive in most cases. While it’s troubling that the country’s number one bank got hacked, what’s even more worrying is that the media, the public, and even Wall Street seemed to shrug it off and carry on.
What this means for you:
Americans seem to be developing what some analysts are dubbing data breach fatigue: everytime we look up, yet another high-profile company or livelihood staple has been hacked. The list reads like a modern family’s honey-do list: Target, Home Depot, Neiman Marcus, EBay, UPS, Apple, Nintendo, Sony, Albertsons, SuperValu, CHS, etc. There have been nearly 600 data breaches reported this year, up 27% over last year, and we aren’t even done with 2014. Fortunately, only a small percentage of the total population have been negatively impacted in a signficant way, though most of us have probably had one or more credit cards get canceled and replaced for fraudulent activity. What this is leading to is the general perception that these data breaches are “bad” only in a vaguely annoying way, and there is not much that an average person can do to protect themselves, “Heck, if JP Morgan can’t figure out how to keep the hackers at bay, how can I ever stand a chance?”
While it’s true you can’t stop JP Morgan from getting hacked, you can make it harder for cybercriminals to hack you: don’t give in to the fatigue – make them fight for every bit they try to steal from you. Change your passwords regularly, and use unique passwords for your important accounts. Keep a close eye on your credit card statements and your credit history. Make sure your all computers you use have up-to-date and functioning antivirus software. Avoid email attachments and unfamiliar websites. What was once considered “paranoia-level” precautions are the new standard of online safety. Considering that nearly half of Americans adults have had some form of their personal data stolen through an online breach, it’s safe to say that “they” are out to get you – paranoia or not.
Obviously stung by the world’s tepid reception of Windows 8, Microsoft announced that the next version of their operating system will be skipping Windows 9 and heading straight to 10. The jump is meant to signify a considerable advancement in the base operating system: this version of Windows isn’t just an incremental upgrade or updated version of 8. Microsoft intends to unify the operating system across mobile devices and traditional workstations (much like Apple is attempting to do with iOS), providing app makers a simpler development environment and presumably a much larger market. Previously known as “Threshold”, Windows 10 won’t be available to the general public until 2015, but preview-builds will supposedly be available starting October 1.
What this means for you:
If you’ve been holding out on upgrading your Windows 7 machine in the hopes that something better than 8 would come along, your prayers (may) have been answered. Early reports suggest that 10 is a mix of the best of 7 and 8, though you may wonder what parts of 8 qualified as “best.” Most gratifying will probably be the return of the beloved Start Menu, but with an 8 twist – the ability to add tiles to the menu (like the ones on the 8 start screen). Another eagerly anticipated feature will be improved window management utilizing the poorly-documented “snap” features of 7 and 8, as well as multiple desktops (something Linux users have had for years).
How should you prepare for coming of the mighty 10? There are rumors that 10 may be free to current Windows 8 users, but Microsoft refused to confirm this. If you have Windows 8 and were contemplating downgrading, you may want to hold off just in the off chance you can get 10 for free. Early reports indicate that Windows 10 will have the same hardware requirements as Windows 8, so older hardware may be left behind, but anything made in the past 2-3 years should be fine. If you want prepare right now, a larger monitor may provide you with the most bang for your buck, as Windows 10 looks like it will make multi-tasking even easier. More windows open equals getting more done, right?
While the world is trying to mop up the mess that Heartbleed left behind, along comes another vulnerability that might be just as big. Dubbed “Shellshock” because it affects the Bash shell commonly found on Linux computers, and (this may surprise you) some Mac OS X servers. “Shells” are the technical term for the user interface of a computer, something you may know as a “GUI” (sometimes pronounced “gooey”, an acronym for graphical user interface). In this case, Bash is a text-based user interface that has been in use on Unix & Linux machines since 1989. What makes Shellshock so alarming is the ease of which could be exploited by hackers, the scope of hacks which could come from exploiting the weakness, and the number of machines potentially vulnerable to this bug.
What this means for you:
Unless you run a Linux or Mac OS X Server, most folks could be affected by this the same way they were exposed with Heartbleed – anyone who uses the internet has probably visited a site or used a service that is run on Linux-based webservers, and a large percentage of them probably use Bash. Security firms have already discovered attacks “in the wild” attempting to exploit un-patched servers, and due to the pervasive access a command line interface has to the computer’s operating system, any number of system compromises can be executed once the hacker has control of the Bash shell. In other words, if an internet service you use gets “Shellshocked”, any data they may be storing about you on their servers could be exposed. For now, unless you are a server administrator, there’s not much you can do, other than inquire with your critical providers whether they have taken steps to protect against the Shellshock vulnerability.
It pains me to write about this, but I think it illustrates a valuable (if obvious) lesson. Immediately following the opening weekend of iPhone 6 sales, a web page began circulating on the internet advertising a “hidden” feature of Apple’s just-released iOS8 operating system update for its mobile devices. Called “Wave” this feature of iOS8 allowed upgraded iOS devices to be charged by microwaving them for 60-70 seconds. Needless to say, this does not work. As a matter of fact, it will destroy your shiny new phone in the time it takes to say, “I shouldn’t have done that.” This type of hoax has been around for quite awhile, in various forms, but invariably someone knows someone who knows someone who destroyed their phone after being taken in by one of these pranks.
What this means for you:
At first blush, I thought to myself, “Really, anyone that dumb deserves to have their iPhone fried,” but as I thought about it, their are legions of folks of all ages, from those old enough to remember when microwave ovens first appeared (1946) to those younger than the appliances they use, that do not know (a) how the technology works, and (b) the dangerous bits that everyone assumes everyone else knows. My daughter doesn’t know that metal shouldn’t go in the microwave – we’ve never had occassion to discuss it. Most of the tech we use on a daily, even hourly basis is well beyond average human comprehension, and the benefits gained from attempting an understanding feel intangible. Instead, we take it for granted, and are schooled on occasion through painful lessons like, “Everything you read on the internet isn’t necessarily true,” and, “Microwaving an iPhone is bad, mmmkay?”
A flaw in an Android open source web browsing app found on nearly half the active Android user base could potentially be used by malicious websites to steal user information. Reported by white-hat hacker Rafay Baloch earlier this month, this bug affects the Android Open Source Platform browser – also known as “Android Browser” – which was the default browser on all Android phones shipped prior to Android OS 4.2, when Google switched the default browser to Chrome. Even then, parts of Android Browser were still being used by other OS applications up until version 4.4, when Google swapped those parts out for Chromium ones. A survey of web browsers used shows that nearly half of all Android users may be using Android Browser actively, which could equate to nearly 40 million potential victims.
What this means for you:
Note that “Android Browser” (with capital B) is the actual name of this program, and should not be confused with the Chrome app, which is also an “Android browser” – as in it’s an app that lets you browse the internet on your Android device. If you still have the Android Browser app installed on your 4.X Android phone, you should replace it with Chrome. However, this may only solve part of the problem, as many other apps that have some form of internet browsing built into it may be using the flawed engine embedded inside the app itself, and there is no clear way to know for sure without asking the developer.
Now that Google has officially acknowledged the bug, a fix is supposedly in the works, but hasn’t said when it will release the update, which will have to be delivered as part of an OS update (ie. going from 4.3 to 4.4) and not throught Play Store. Also, it’s not clear whether that update will trickle down to the many apps that still use the engine to power their own embedded browsers. For now, stick to using Chrome, and be wary of apps that have built-in web browsing capabilities.
After the massive security breach Target experienced in 2013, Home Depot management had the best intentions in immediately planning for a similar attack being directed at them. Unfortunately, they were about only a quarter of the way through their plans to beef up security at their stores when the big-box DIY chain recently announced that they’ve been hacked, with potentially tens of millions of customers exposed. To add insult to injury, its beginning to look like hackers penetrated Home Depot point-of-sale systems as far back as April.
What this means for you:
By now, you probably realize that there’s not much you can do other than what you’ve already been doing: use credit cards, not debit cards, wherever possible, and always keep an eagle-eye on your purchase history. Credit card companies are already doing a pretty good job with their fraud-detection algorithms – don’t ignore those automated calls when you get them. Given the massive number of breaches happening, it’s very likely that your credit card number has been stolen (or soon will be) if you shop at most large chain-based retailers.
As a business, you can take a lesson from Home Depot’s woes: move quickly. Home Depot’s implementation was likely hampered by both logistical complexity (hardware replacement at thousands of locations scattered across a gigantic area) as well as “traditional” corporate bureaucracy. There’s not much to be done for the first part except to take it into account when combating the second part, which while understandable, will lead to disastrous consequences. Cyber criminals aren’t slowed by corporate chain-of-command – don’t let your decision making process expose you to a damaging security breach.











