As if having your Windows computer files and iPhone being held for ransom wasn’t bad enough, Android-based devices can now “enjoy” that ignominious fate as well. Security researchers are reporting that hundreds of Android devices, primarily in Russia and the Ukraine are being infected by a Trojan called “Pletor” which can do just like it’s Windows based counterparts: the victims were tricked into installing the trojan by fake websites, apps and games, and once the victim’s content is encrypted, the trojan demands a ransom of approximately $30-35 USD to unlock the data.
What this means for you:
Though it has happened before, it’s still extremely rare for a Trojan like the above to make it through the screening process that Google performs on all the apps that are available through the Google Play store, and even if one does, it’s pulled quickly. Google can even reach out retroactively to affected phones to remove the harmful app. That being said, it’s not hard to “side-load” apps on Android devices, which is primarily the way Android malware spreads. The easiest way to keep your Android devices safe: don’t side-load apps. Only install apps published through Google’s Play Store. Keep in mind, for everything not a Kindle Fire, installing apps from Amazon’s App Store is considered side-loading, and should only be done if you really know what you are doing. And if you just can’t live without side-loading apps, make sure you don’t store any important information on your device, and keep it well away from sensitive business data. The more risky your activities are on the device, the more likely it is that device will get compromised.
In case you were wondering where that whole “Network Neutrality” debate ended up, legislation/regulation is still being ruminated upon by the policy wonks at the FCC, Congress critters are still confused about “tubes”, but the knives have come out between content providers and ISPs. Netflix and Verizon are currently spatting over a particularly accusatory “error message” Netflix has been “testing” that shows a warning to its subscribers that Verizon’s network is too congested for them to enjoy Netflix content in HD. This, not just weeks after Google started its own page that shows you how well your ISP does when transmitting YouTube videos to you. In case you were wondering, most consumers weren’t pleased that Google & Netflix confirmed their worst suspicions: their ISP sucked when it came to watching videos, and it’s a safe bet that video watching wasn’t the only thing suffering from poor performance.
What this means for you:
Nothing as of this moment. Google and other content providers have been very vocal in the Network Neutrality debate, but when it comes to dealing with the government, “vocal” means writing a very stern letter and rounding up lobbyists to start scratching backs and/or eyes. But over here in the real world, the ringside bell just signaled another round of sparring and Netflix came out swinging. Verizon immediately lawyered up and sent its own sternly worded demand to Netflix to cease and desist, who just shrugged and said, “Hey, it was just a test. But we might be doing that again in the future. And oh, by the way, this is really your fault to begin with.” We’re fairly certain that it got a ton of attention from (allegedly) poorly served Verizon customers, who, like millions of other Americans, are basically stuck with zero choice when it comes to internet broadband. Get settled in, this is going to be a long fight, and those of us on the sidelines will probably get bloodied just as much as the titans, because, in case you hadn’t noticed, we’re all players on their gigantic chessboard.
Image courtesy of jasadaphorn / FreeDigitalPhotos.net
Coming hard on the heels of the international sting two weeks ago that resulted in the arrest of nearly 100 “RATters”, law enforcement agencies in several countries again acted together to take down two very large botnets that together number well over 1.2 million compromised Windows computers, arresting a Russian hacker who allegedly managed the powerful zombie networks. Botnets are essentially large collections of “zombified” computers that can be controlled remotely and are a favored tool of cybercriminals and hackers that can execute a variety of activities including widespread phishing campaigns to steal sensitive personal data and focused DOS attacks used to cripple websites and servers.
What this means for you:
The UK Crime Agency believes that though they have control over the botnets for the moment, that control won’t last long – maybe 2 weeks – before the zombified computers are drafted into another botnet. In those 2 weeks, the various involved law enforcement agencies are hoping to take advantage of the temporary reprieve to notified the owners of the infected machines that they need to clean up their computers ASAP. If you receive a conspicuously official looking notice from some form of local law enforcement, it might be legitimate and not just another scareware scam. Some obvious signs that your computer might be infected (and possibly part of the one of the 2 busted botnets) include:
- Websites loading in your browser that are clearly not where you intended to go, or what the search results said they would be
- Computer performing unusually slowly or erraticly, unexpected crashing or other unusual behavior
- Files suddenly becoming corrupt or unusable
The last one is of special concern – it could mean your computer is infected with Cryptolocker, a nasty bit of malware that locks your files up and holds them for ransom. This might also mean that even if you were inclined to pay the ransom to get your data back, you may not be able to, as the take down of the botnet may also result in no one, criminal or lawful, being able to unlock your files. Sadly, if you hit this point and don’t have a recent backup of your data, it is gone forever.
Image courtesy of Stuart Miles / FreeDigitalPhotos.net
A new scam to extort money out of Apple mobile device users has surfaced in Australia, with scattered reports in other countries as well. Affected devices are locked out via Apple’s own “Find my iPhone” platform with a message that demands a ransom payment of $100 USD to unlock the phone. Security analysts are unsure at this point as to how the perpetrators are gaining access to victim’s AppleID accounts, and so far Apple is refusing to comment on this issue. According to posts on Apple’s Support Forums, the only reliable way to unlock the device is to reset it back to factory settings and restore your data from a backup, if one was actually created and maintained for that device.
What this means for you:
So far, there is a tenuous link between some of the victims and the recent eBay hack that exposed user accounts and encrypted passwords, where the victims admitted to using the same password for both eBay and iCloud. However, several other victims of this new ransom scam did not use the same password as their eBay account, so eBay’s exposed data may not be the only source. Bottom line, you should use strong, unique passwords for online accounts, especially for the ones that are tied to important services like online banking, email and any account that has access to confidential data, either yours or your clients/customers.
Image courtesy of Stuart Miles / FreeDigitalPhotos.net
It’s a beautiful day on the internet when I can report good news instead of bad. In what appears to be a new and very positive trend in modern law enforcement, several agencies around the world came together in a global sting that bagged nearly 100 cybercriminals selling and using the Remote Access Tool (RAT) “Blackshades”, a very popular hacking tool used to spy on and even extort thousands of victims through their compromised computers. Lest you think this is a new trend in cybercrime, “Ratting” has been around for years, but perhaps its profile was elevated through the unfortunate victimization of Miss Teen USA 2013, Cassidy Wolf, high enough to galvanize authorities to do something other than attempting to squash Ratters one at a time.
What this means for you:
According to analyst estimates, Blackshades was being used to compromise hundreds of thousands of computers world-wide at the time of the sting. It was readily available and cheap, and did not require sophisticated technical skills to use. In the case of Ms. Wolf, the software was installed by a former acquaintance, but typically users are infected and “ratted” through a link on Facebook or via email, often sent by other infected machines. As with any malware incursion, a healthy level of caution and up-to-date antimalware could have prevented the infection, and in the case of Miss Teen USA, a great deal of heartache and trauma. If you are one of the many who refuse to lock their unattended computers with a strong password, consider the victimization of Cassidy Wolf as a cautionary tale and take immediate steps to secure your privacy and safety.
A secret war is being fought in the internet industry right now, but unless you are a die-hard student of all things tech, you might not even know it’s taking place. The more conspiratorial-inclined among us accuse the mainstream media of avoiding coverage of this debate because of their close ties to the opponents of net neutrality, but it’s also a very complex, “unsexy” topic that is hard to explain in easily digestible soundbites.
The principles of “network neutrality” have been the subject of hot debate for over a decade now, but as of yet, there has only been one highly publicized incident of a company actively “violating” the basic tenet of net neutrality, which is that all data on the internet should be treated equally, both in terms of accessibility (can I see it?) and how quickly it loads. For Americans, censorship is a hot-button topic, so the accessibility issue isn’t normally included in the ongoing debate. What’s at stake is whether internet service providers like Time Warner, Comcast and AT&T can charge content providers (NetFlix, Google, Spotify) more because they use so much data, and if those companies refuse to pay the premium, would their bandwidth be throttled, lowering the quality and/or value of the service itself.
Another aspect of this debate is whether the US Government (or any government, for that matter) should regulate the internet like a utility. Both sides of the net neutrality fight are of mixed opinion on this. Some argue this would encourage (enforce) competition in the ISP market, and would allow oversight into ensuring net neutrality was observed, but as many others have pointed out, this didn’t work so well for the telecomm industry the first time we tried this. The other thorny facet of this issue is the plain fact that the internet is not owned nor controlled by any one country, though it could be argued that the US holds a “majority stake” in its creation and continued wellbeing.
What this means for you:
Today, the FCC has presented a plan that many feel completely undermines network neutrality by providing a “regulated” means for ISPs to create “fast lanes” of service into which content providers may opt, and if they do not, presumably their content would be delivered via the “normal lanes”. If no one opted into the fast lanes, this would be a moot point, but as you all know, in business, those who get to the finish line first win, and everyone else, regardless of whether they finish at all, lose. Even the most altruistic of companies (Google maybe?) are willing to get their claws out when it comes to competing, and being slow on the internet is the difference between being Facebook or being MySpace.
In my opinion, network neutrality is a concept worth understanding at minimum, and if you take the long view on improving our civilization, an important principle that should be upheld. Competition is what made America great once, and it is what created the amazing technology we have now, including the internet. Creating tiers of accessibility and quality within a service that most would view as a fundamental need (if not right) might end up creating a version of the internet (at least in America – imagine the irony) that is the antithesis of internet that is spreading information, freedom and equality around the world.
Image courtesy of Stuart Miles / FreeDigitalPhotos.net
Cable broadband was once strictly the province of residential customers, but over the past several years, the major players in this space have made large in-roads into the SMB market with fast, cheap internet circuits that, on the whole, perform more-or-less as reliably as their more expensive (T1’s) and/or slower (DSL) counterparts. The primary difference between cable circuits and T1’s, the former mainstay of business broadband, is that cable bandwidth is not guaranteed as it is on T1’s, and speeds can fluctuate wildly throughout the day, depending on the neighborhood utilization. Web-based speed tests were born, and from them probably many acrimonious disputes between customer and provider were sprung. Anecdotal research by CNET writer Dennis O’Reilly indicates that not all speed tests are created equal, can be inconsistent and even possibly slanted to favor the companies or brands sponsoring the test.
What this means for you:
A casual run of the tests on Speedtest.net may prove eye-opening, but not necessarily irrefutable proof that your internet provider has over-promised and under-delivered. In the case of a broadband circuit in use at an office, other users and devices will impact the internet speed, and unless you can guarantee your computer is the only device using the circuit, will never be a true test of the circuit’s full potential. Also, even if you were to disconnect everyone from the internet except your test machine, that’s not a true representation of the actual speed you and your co-workers will experience on a typical day. And here’s the catch behind the low-cost business-class cable – very rarely can the cable company provide any kind of cohesive reporting on how your bandwidth is being utilized, primarily because you are using a shared internet circuit. Conversely, with T1’s the higher costs pays for a dedicated, (usually) monitored circuit. Depending on your provider and contract, you may be able receive detailed reporting on utilization at any point typically within the past 7-14 days, and they may even be able to pin-point who on your network is bogarting all the bandwidth. If you have concerns about network or internet performance, speak to a technology professional who can provide you with a much broader, context-based analysis of your bandwidth usage. Don’t rely on a simple website to pass judgement on a critical part of your business performance.
Image courtesy of Stuart Miles / FreeDigitalPhotos.net











