Hackers have compromised a Department of Energy website, leveraging a previously undiscovered security flaw in version 8 of Microsoft’s Internet Explorer. IE 8, which is now 2 versions back from Microsoft’s most recent release (v10), is used by almost a quarter of all Internet Explorer users, and is most commonly found on Windows XP computers. The “watering hole” style attack is thought to be the work of Chinese hackers based upon the malware used and the command and control protocols used. The hacked website is used by the DOE to disseminate information on radiation-based illnesses, leading analysts to believe that this was a targeted attack aimed at compromising the computers of government employees working with nuclear weapons and reactors, ostensibly for the purposes of gaining access to classified information and systems.
What this means for you:
This is the first instance of this particular exploit being discovered, but given the publicity and Microsoft’s well-known inertia in issuing security updates for it’s older products, there is a chance that if you are still using IE 8 you could be at risk. Microsoft recommends upgrading to a new version of Internet Explorer, but in the event that you are unable to upgrade due to your business requirements or application limitations, Microsoft has issued the following guidance for working around the security flaw until it can be patched:
- Set Internet and Local intranet security zone settings to “High” to block ActiveX Controls and Active Scripting in these zones
- Configure Internet Explorer to prompt before running Active Scripting or to disable Active Scripting in the Internet and Local intranet security zone
- Add sites that you trust to the Internet Explorer Trusted sites zone to minimize prompt disruption
As I’m not a Microsoft employee, I can also recommend switching browsers to Chrome or Firefox. Both issue security updates much more rapidly, and though they are not free of security flaws and zero-day exploits, both browsers typically fair better than IE in terms of overall security strength.
According to BlackBerry’s CEO, Thorsten Heins, tablets will lose their market dominance in 5 years, to be replaced by, presumably, smartphones like the BlackBerry, and larger monitors. Assuming he is referring to the business space, it’s hard to decide whether his prediction is some parts sour grapes – BlackBerry’s own tablet, the Playbook, was a market failure and nearly bankrupted the company – and some parts wishful, magical thinking to self-fulfill their own business goals, which is to supplant tablets (dominated by the iPad and to a lesser extent Android) with their devices. As is usually the case with controversial predictions, Heins’ prognostications have roots in fact. Apple’s profits have been declining, as has its margins on the iPad, giving analysts cause to speculate on the longevity of the platform.
What this means for you:
Unless you are about to make a substantial investment in bringing tablets into your business processes (and even if you are), Heins’ predictions are likely to have little impact on you. BlackBerry wants to be considered a competitor in the mobile device space, and as they can’t compete on the tablet level, the traditional business tactic one can take in this situation is to attempt to invalidate the competition’s strategy by influencing the market. “Tablet’s will be dead in five years. Everyone will be using BlackBerries,” makes for good headlines, but any student of technology history will tell you that smarter technology leaders and innovators got more wrong than right when attempting to predict the future.
Shoppers enjoy online purchasing for a variety of reasons, but the lack of sales tax is probably highest on that list of perks. That may soon change due to a revamped Internet Tax bill re-introduced last week on the Senate floor, and one which could be voted on as early as this week. The “Marketplace Fairness Act“, penned by Sentor Mike Enzi (R., Wyoming), essentially requires any internet business with more than $1M in online sales to collect taxes on the US’s estimated 9600 state and local taxing authorities, something that brick-and-mortar businesses don’t have to do, even if sales come from across state lines (and presumably through channels other than the internet). Opponents of this bill state that this places an unfair burden on smaller internet businesses, as calculating and processing taxes for nearly ten-thousand different localities presents a logistical nightmare with which even large companies struggle. Obviously, brick-and-mortar companies back this bill, especially the big ones – Wal-Mart is a vocal backer, but even online retail giant, Amazon.com has thrown in their support. It may surprise no one that they have a dog in this race – Amazon offers a subscription-based tax-processing service to online retailers.
What this means for you:
If you sell more than $1 million in taxable goods on the internet to customers in the United States, you might need to look at some serious upgrades for your online store in the near future. On top of the huge headache this creates for your website administrator and programmers, this may also complicate your shopping cart process, and your customers may be in for a shock when they discover that their online shopping isn’t paying off like it used to. Opponents say that this bill will throw a wet-blanket on online shopping, and could be a huge damper on the struggling American economy. The bill hasn’t been made law yet – but it may behoove you to find out where your local government representative stands on this issue.
Image courtesy of Stuart Miles / FreeDigitalPhotos.net. Note: image has been digitally altered by Chris Woo.
The controversial CISPA (Cyber Intelligence Sharing and Protection Act) proposal has passed committee review and is heading to the Senate for a vote, despite a clear warning from the Obama administration that it would VETO the proposed law. Unlike the equally controversial SOPA (Stop Online Piracy Act) backed by media companies and defeated through vigorous and coordinated protests from the technology industry, CISPA has divided the technology industry. Many large companies like IBM, AT&T, Oracle and Verizon backing it, while other, equally sizeable companies like Facebook, Microsoft, Google and dozens of activist organizations oppose the bill on the grounds that it doesn’t do enough to protect the privacy of US citizens.
What this means for you:
In case you are confused as to how CISPA might impact you or your business personally, here’s a summation of what the bill proposes: This law would allow telecommunication companies to share data with governmental agencies for the purposes of combatting terrorist or criminal activity, overriding any local laws that would prohibit such sharing. According to supporters, law-abiding citizens should have nothing to worry about, but opponents contend that on top of very weak protections for citizen privacy, there is nothing in the bill that would protect citizens from potential abuse by the various intelligence agencies who could amass an inconceivably comprehensive database from the information gained by CISPA. Regardless of which side of the privacy fight you stand on, it behooves you as a US citizen to be aware of where you stand on this issue, as well as encouraging everyone around you to participate as they can in helping our government come to terms with this problem.
Image courtesy of Stuart Miles / FreeDigitalPhotos.net
Just when we were getting flight attendants to relax the electronic device restrictions on flights, a German security consultant has demonstrated a real-world hack and takeover of an airplane’s critical guidance and control systems using an app he built that runs on an Android smartphone. Hugo Teso of n.run, who is also a trained commercial pilot, demonstrated the exploit at the Hack in the Box conference in Amsterdam, and has developed a framework and app as a means to illustrate just how poor the current state of aviation security actually is. Teso designed the framework to be unusable outside his simulation environment, but he maintains that his environment mirrors technology that is currently in use throughout the aviation industry. On top of being able to completely own the Flight Management System (sometimes referred to as the “Autopilot”) of an aircraft, Teso’s app, named “PlaneSploit” demonstrated how, once complete control of the aircraft’s control systems was obtained, the actual operation of a flying aircraft could be remotely controlled from a smartphone.
Teso has carefully kept his research private, and has been working closely with the aircraft industry to help them close the gap on the many security vulnerabilities that exist in the thousands of aircraft in use today. Even still, it’s possible that other security analysts could uncover the same exploitable weaknesses in avionics platforms, and perhaps behave less altruistically than Teso. Also keep in mind that the autopilot systems can be manually overridden and the aircraft flown “by hand” using backup analog instrumentation. The trick, Teso reminds us, is that unless the pilot knows the plane has been hacked, he won’t know to take over control until the damage has already been done.
What this means for you:
Unless you are a commercial pilot, or someone of influence in the airline industry, I’m afraid there’s not much you can do about this except continue to raise awareness with everyone around you about technology security. Even though I sincerely doubt we’ll see any real-world plane hijackings via smartphone any time soon, now that this Pandora’s Box has been opened, it may never be shut again.
Security tester Phil Purviance has gone public with his findings on a popular router that widely sold to consumers and small businesses. He sums it up succinctly:
…any network with an EA2700 router on it is an insecure network!
The router in question is commonly found at big box retailers like Fry’s Electronics, Best Buy and pretty much any retailer that sells consumer electronics. Purviance reported his findings to Cisco over a month ago, but the hardware giant has yet to comment or issue any fixes to the public.
What this means for you:
If you are using a Cisco Linksys EA2700 router for your internet connection, your device and any computer connected to the EA2700 is at risk. Seeing as most folks aren’t even aware that their routers have software/firmware that can be upgraded, it’s likely that even if Cisco were to fix all the vulnerabilities outlined by Purviance, those fixes are unlikely to be applied by most consumers and small businesses. At the moment, the only true fix for the EA2700 is to replace it with something else, but with what? Researchers are still playing catch-up in this space, as there are literally hundreds models of consumer-grade routers installed in the US alone.
As a business owner, you should consider upgrading to a business-class router from a major manufacturer like Dell, Cisco, Fortinet, etc. (Cisco’s business-class equipment, ironically, is typically considered a standard choice). At the very minimum, understand what you have installed, upgrade the firmware if possible, and check with your local IT professional (C2 is always there to answer your questions!) to determine if there are any widely known exploits published about your particular router model.
Consumers looking to “cut the cord” with cable and satellite providers have often been stymied by the fact that certain programming, most notably live sports and new TV shows, are often unavailable on the traditional streaming services like Hulu and Netflix. Depending on the content and the availability of a dedicated DVR box like a Tivo unit, savvy consumers could record over-the-air broadcasts using an old-fashioned TV antennae, but depending on the device (and the content!) you might be limited to watching it only on that device.
Aereo is attempting to help consumers with this last content “mile” by setting up data centers in key markets (starting in New York City) that are basically acting as cloud DVR’s that can stream (or record) over-the-air TV content to your devices for as little as $8/month. Think of it as Netflix for your local TV programming. As a matter of course, the major networks are in an uproar about the service, as it completely disrupts their current revenue models, but to little avail as US courts, up to this point, are siding with the internet startup. Not content with the rulings, the networks are planning to appeal, and are also talking about moving their content to paid networks and away from free, over-the-air broadcasts as a means to combat Aereo’s plans.
What this means for you:
Over 50 million Americans still watch TV via good, old-fashion TV antennaes, and many millions are still without proper broadband that might enable them to stream content from providers like Aereo. The content networks are in no danger of losing those folks, but their reactions to companies like Aereo may cause them to abandon broadcast TV altogether, moving all their content to services that are suddenly out of reach for a significant portion of the population. For those of us trying to cut the cord, Aereo’s disruptive influence may bring us a little closer to the next age of entertainment where, instead of buying predetermined services filled with channels we don’t watch, we can purchase and watch content on an a la carte basis, on our schedule, and on the devices we choose.
Image courtesy of digitalart / FreeDigitalPhotos.net
In an announcement that surprised pretty much no one in the technology industry, Facebook frontman Mark Zuckerberg announced the arrival of both a Facebook application suite, dubbed “Facebook Home” as well as a phone from HTC called “First” that will have Facebook Home pre-installed. It’s not an operating system, like iOS or Android, nor is the “First” a dedicated Facebook phone. Facebook Home is really a set of apps (only for Android phones at the moment) that essentially makes your phone more like Facebook and less like Android.
What this means for you:
If you live and breathe Facebook (and millions of Americans do just that), then you’ll want to give this app a try, but only if you have an Android phone. iPhone users will be out of luck for the forseeable future, as Apple does not allow the sort of access to the base operating systen that Facebook Home requires. For those of you wondering why anyone would want such a thing on your smartphone, consider this: For many, the Android OS is overwhelming and complicated. They just want to make calls, answer email, and connect with friends. These users are looking for what’s known as a “Walled Garden” experience, very similar to the way AOL offered the “internet” to millions who weren’t interested in (or bewildered by) the unfiltered and un-curated experience of the 1990’s world wide web. You could think of Facebook Home as the new “AOL” for your smartphone.
One thing to keep in mind: Facebook’s revenue model is based upon knowing as much as they can about all of their users. By using Facebook Home, it’s conceivable that Facebook will harvest much more data about you, including location data and browsing habits above and beyond what they can collect while you are sitting at home in front of a computer. If you’ve been living your life on the internet and have nothing to hide, and you don’t mind Facebook mining your smartphone activity for marketing data, Facebook Home might just give you the Facebook phone you’ve always dreamed of.











