Get Tech Support Now - (818) 584-6021 - C2 Technology Partners, Inc.

Get Tech Support Now - (818) 584-6021 - C2 Technology Partners, Inc.

C2 provides technology services and consultation to businesses and individuals.

T (818) 584 6021
Email: [email protected]

C2 Technology Partners, Inc.
26500 Agoura Rd, Ste 102-576, Calabasas, CA 91302

Open in Google Maps
QUESTIONS? CALL: 818-584-6021
  • HOME
  • BLOG
  • SERVICES
    • Encryption
    • Backups
  • ABOUT
    • SMS Opt-In Form
    • Terms and Conditions
    • Privacy Policy
FREECONSULT

Home Internet Routers Could Be Next Hacker Target

  • 0
admin
Wednesday, 03 April 2013 / Published in Woo on Tech
Hackers invading your home

As if you didn’t have enough to worry about, the security blogosphere has dragged another bogeyman out into the daylight, and this one is ugly. Researchers from ioActive are now positing that rather than targeting businesses and their more sophisticated technology defenses, hackers could very easily begin to target consumer-grade equipment installed by internet service providers (ISP’s e.g. Time Warner or Comcast) in your home.

Why would they do this? Aside from the much flimsier technology used throughout the home-internet industry, the IP address assigned to your device is easily discoverable because the ISP’s themselves publish information about entire blocks of internet addresses that are allocated to them. This is doubly bad because not only do hackers now have an easy-to-parse list of targets, they can make assumptions about the targets based upon the ISP that services those addresses: things like the types of equipment used by the ISP (and default passwords), geographical locations, even the types of internet service (ie. DSL, cable, satellite, etc).

As part of their investigation into the feasibility of such an attack, ioActive researchers were able to compile a list of 400,000 actual devices installed in customer homes that might be vulnerable to a simple attack that could allow hackers to “own” the device and use it as a means to gain access to any computer connected to that device, ie. all the computers in your home. The basis for the attack? The simple assumption that the default administrative password was not changed since it was installed by the ISP.

What this means for you:

Having equipment installed in your home that you don’t understand and can’t personally confirm as secure is risky and negligent. It would be akin to leaving power tools lying around within reach of a child. Sadly, most ISPs have very thin (to nonexistent) policies around governing the security of the devices they install in your home, and worse, they often rely on third-party labor to do the installs, further increasing the chances that your router was installed quickly and possibly carelessly. On top of this, how many of you after having waited multiple hours for an internet install to happen, watched the installer rush out the door before learning anything about how your new equipment works, who to call for support, or how to change the password on the newly installed router?

Do yourself a favor: familiarize yourself with your internet router, WiFi access point, or any other piece of network equipment in use in your home, figure out how to log into the device(s), and then change the password to something that is hard to guess, and written down in a safe a secure place. Don’t make it easy for the hackers by continuing to ignore the backdoor into your home network!

adslcablecomcastHackinghome networkinternet servicepasswordroutersecuritytime warner

Wiped Cell Phones Still Retain Data

  • 0
admin
Monday, 01 April 2013 / Published in Woo on Tech
Cell Phone Security

Matt Honan, the Wired writer who had his digital identity stolen in a harrowing cyberattack last year, is back with another chilling article about yet another technology failing to protect us: this time it’s our beloved smartphones. More specifically, it’s the ones we’ve left behind, donated or possibly even sold via eBay, when we upgraded to a newer mobile device. The problem? Even though we may “wipe” the phones, the process may still leave enough information behind for the wiped phone to reveal sensitive information about their owners, including where the phone has been (geographically), what websites have been visited, and even phone numbers, addresses and other confidential data we thought erased.

What this means for you:

Depending on the type of phone you are discarding, and how it is wiped, this may or may not be an issue for you. For example, iPhones after the 3G mentioned in the article are encrypted by default, and if “reset” properly, the encryption key is destroyed, rendering any data on the phone unreadable, even if it is recovered. Most large organizations with a savvy IT department will only allow smartphones to access corporate email and files after your phone has been configured with proper security settings, up to and including an encrypted partition to store your email and any files you might access from the corporate network. Most Android phones should be able to encrypt all data (check “Settings -> Security”) depending on version of Android your phone is running, providing the same type of protection that Apple has on its late-model iPhones.

I can hear you saying, “I don’t have any data on my phone that is sensitive,” and unless you are 100% sure of this, always assume there is something on your phone you don’t want untrustworthy eyes seeing. Even older flip-phones have phone numbers, addresses and other data you might not want to share with a stranger. If you are at all in doubt, hold on to that phone until you can talk to a professional about wiping it securely. If you don’t plan on letting the phone have a second life through eBay or donation, take it to an eWaste facility or event that offers secure destruction. This process renders the phone (and any electronic device, like a hard drive) down to its basic metallic components, completely destroying any data stored in any component. Don’t have access to such a process? Drop your phone into a bowl of water for a day or, as the Wired article suggests, take a hammer to it (wear proper safety equipment please!) before disposing of it through a proper eWaste avenue. This isn’t a guaranteed method, but it will take a dedicated effort that most data scavengers will bypass in favor of the next discarded smartphone that will be an easier mark.

AndroiddataebayencryptionewasteiPhonesecuritysmartphonewipe

Low-Cost iPhone expected to appear in September

  • 0
admin
Tuesday, 26 March 2013 / Published in Woo on Tech
Apple Logo

Analysts are predicting that Apple will iterate on its popular smartphone in June, releasing the iPhone 5s that will have minor hardware and software upgrades to entice the bleeding edge Apple faithful. If the pattern seems familiar, it’s because Apple did the same thing with the iPhone 4s which followed its predecessor, the “4” in less than a year. It’s unclear whether the iPhone 5s launch will have the same impact as the 4s, which debuted with the popular but buggy “Siri” service. More importantly, Apple-watchers are predicting that the Cupertino company will debut a “lower cost” version of their iPhone in September, specifically to combat Android’s growing market share. An unlocked iPhone typically sells well north of $600 brand new, whereas Android devices can be bought off-contract for less than $300, which is where analysts expect the budget iPhone to land in the pricing wars.

What this means for you:

While most folks are usually more than satisfied with 2-3 year-old iPhones, if you’ve been waiting to upgrade, Apple’s pattern of hardware release usually means that the “s” version of an iPhone is a good investment. If you are still rocking an iPhone 3, the 5s will be a very nice upgrade with a noticeable improvement in speed and functionality. If you are one of the few that tries to avoid AT&T’s and Verizon’s financially-questionable 2-year contracts and you don’t want to plunk down six bills or more for an unlocked 5s, hold on to that older iPhone for a couple more months to see if Apple makes good on the low-cost iPhone in September of this year.

AppleattiPhone 5iphone 5sverizon

T-Mobile Ditches Contracts for Cellphones

  • 0
admin
Tuesday, 26 March 2013 / Published in Woo on Tech
T-Mobile Logo

In a move that is strongly reflective of its overseas ownership, T-Mobile has announced that its customers now have the option to purchase cellular services without having to commit to a contract. Unlike the US, a large majority of European and Asian cell phone subscribers routinely purchase cell phone services on a monthly basis as opposed to the 1 and 2-year contracts familiar to most Americans. T-Mobiles new pre-paid plans start at $50/month for unlimited voice, texting and data, with a couple of small catches: data may be unlimited, but access to T-Mobile’s high-speed data network is capped at 500MB for the $50 plan (Increased to 2GB for $60, and truly unlimited for $70/month). The other gotcha? Pre-paid plans will no longer subsidize the cost of expensive phones that can be gotten for “free” with 2-year contracts, at least not in the manner with which you may be familiar.

What this means for you:

Of the major carriers in the US, T-Mobile is in fourth place in terms of market, and they trail third-place carrier Sprint by a large margin. Lacking the marketing muscle to go head to head with Verizon and AT&T, T-Mobile is attempting to disrupt the US market by offering plans that are common-place and popular overseas, but still relatively untested in the US. Many analysts believe that the US cellular market will grow to mirror its overseas counterparts, but that convergence is still at least 2-4 years away.

One of the key differences in T-Mobile’s plan is how they plan to allow consumers to still “subsidize” the cost of new phones. In a traditional 2-year plan as offered by the major carriers, the cost of a new phone is incorporated into the monthly subscription fee, and presumably at a rate that pays off the phone in two years time. T-Mobile offers a similar deal with their pre-paid plan, but instead of offering a single monthly amount, they actually break out the cost of the monthly payment for your new phone.

Why is this important? With T-Mobile, once you have finished paying off the phone (which can be done on their 2-year schedule, or sooner should you decide to just buy out the remaining balance), your monthly bill will be reduced to just the amount owed for services. With the traditional contract offered by the big carriers, your monthly bill will stay the same even though you have paid off your phone. This is no big deal if you decide to switch carriers, but they are banking on the fact that you might not. So far, this has paid off, given the popularity of this type of contract, but maybe T-Mobile can bring disrupt enough of the market to put some strain on the Verizon/AT&T duopoly in place in the US.

(Full disclosure: I’m a T-Mobile customer on 2-year contract, paying down my brand-new Nexus 4. I’m paying approximately $80/month which includes a monthly payment of $20 for my phone.)

attcellularcontractnexusprepaidsmartphonessprinttmobileverizon

Apple adds 2-factor Authentication to AppleID

  • 0
admin
Tuesday, 26 March 2013 / Published in Woo on Tech
2-Factor Security

Apple has joined the growing ranks of digital services enabling two-factor authentication as a means to protect their customers from account theft. Two-factor authentication has long been a staple of secure corporate and government networks, and employs a basic mechanic of password plus a randomly-generated authentication code that is delivered to a device that you must have in your possession at the time of authentication. In the past, this device has traditionally taken the form of keychain fobs and cards whose sole purpose was to generate numeric keys constantly, but this same functionality can now be delivered through apps that are installable on smartphones, via SMS message to registered cell phones, or even via automated voice calls to your home or office phone.

What this means for you:

In Apple’s case (as with services like Gmail, Facebook, and many massive, multiplayer online games like World of Warcraft), two-factor authentication is an opt-in service, and is not enabled by default with your Apple ID/iTunes account. Enabling the extra security requires you register one or more cell phones with Apple that will receive your authentication code via SMS. Should you do this? If you use services that require an AppleID (iTunes, iCloud, Mac.com, etc.) with any frequency, and especially if you have iTunes credit banked, you should absolutely enable two-factor authentication, especially if the account is tied to a core service you rely on, such as a Mac.com email address, or iCloud for your iPhone and other Apple devices. Two-factor security makes your AppleID (or any other account like Gmail, etc.) that much harder to hack. There will be some inconvenience, especially if you are in a hurry to access your account and have to hassle with the extra security code entry, but imagine the alternative if your account is hacked.

With greater security comes less convenience, a fact of life in this digital age, and not something that will change in the foreseeable future without a significant evolution in security technology.

Image courtesy of Stuart Miles / FreeDigitalPhotos.net

2-factor authenticationApplegmailGoogleitunessecuritytwo-factor

GAO to IRS: Your Security Needs Work

  • 0
admin
Wednesday, 20 March 2013 / Published in Woo on Tech
The GAO Seal

With results that will probably surprise no one (and warming the hearts of black-hat hackers everywhere), the US Government Accountability Office has published its findings on a recent security audit of the Internal Revenue Service. The summary  reads like the report card every good parent dreads, “Needs improvement.” Despite having a comprehensive security plan (the development of which was funded by your dollars!) the GAO has found that the IRS has failed to follow through in many areas of implementing and enforcing that plan in various parts of its operation, and these failures have severely compromised the overall security of the very important data the IRS collects on all American citizens.

What this means for you:

As you might expect, the 31-page GAO report is not the most exciting of page-turners. I’ll save you the dry read with the “moral” of the story: having a security policy is only as good as how well it is enforced and maintained. It does your company no good to say that “All employees must use strong passwords that are changed every 60 days” if no one is checking to see if they are actually adhering to the policy. It’s actually much worse for your company if you do have a security policy, experience a breach, and then discover that the breach was due to lack of enforcement.

Don’t get me wrong – I’m not recommending against having a security policy. You should have a security policy, especially if you handle sensitive data of any sort, and you should be making every effort to enforce, update and maintain that policy on a regular basis. A simple security breach could cause untold damage to your company’s reputation, and even more so if you have to admit that it happened because you failed to follow through on your own company’s policies.

data breachenforcementgaogovernmentirspolicysecurity

Law Enforcement wants SMS texts retained

  • 0
admin
Tuesday, 19 March 2013 / Published in Woo on Tech
I want your texts!

Technology lobbyists have been pushing for reform of the 1986 Electronic Communications Privacy Act for years, primarily to address the multitude of shortcomings, loopholes that couldn’t have been predicted almost 30 years ago. Law enforcement has also jumped onto the bandwagon, having recently submitted a rider proposal that would be attached to any changes proposed to the ECPA. Their objective? To get cellular providers to retain all the text messages passing through their network, primarily for the purposes of investigating criminal activity. Currently, most providers say they do not retain the actual text messages centrally, and smartphones by default are not designed to retain text messages long term, but each provider appears to have different policies governing exactly how much data is retained, and how long. This inconsistency troubles some lawmakers, and enforcement has long held that criminals purposefully use SMS as an “untraceable, untrackable” communication method.

What this means for you:

A proposal is a long way from actual law, but many privacy advocates and watchdog groups say a rider proposal like this could hamper much needed changes to the decades-old ECPA by weighing down progressive proposals with Big Brother agendas that most technology companies find distasteful, if not diametrically opposed to in their publicy stated values – think Google’s “Do no evil” policy. The fight for privacy continues to carry into new areas everyday, but the SMS fight could be a huge battle: six billion text messages are sent everyday. Privacy issues aside, imagine having to figure out how to store this information in a way that is useful, let alone subpoenable!

Electronic Communications Privacy Actlaw enforcementlegislationprivacysmartphonessmstexting

Is your webcam spying on you? Maybe.

  • 0
admin
Wednesday, 13 March 2013 / Published in Woo on Tech
Eye Spy

When laptops and desktops first started shipping with webcams built right into the chassis, people immediately started joking about their computers spying on them, and I saw numerous semi-serious and completely serious attempts to cover them up with tape, post-it notes, permanent marker and just about anything people could put their hands on to alleviate that prickling sensation of being watched. Unfortunately, reality isn’t typically far behind imagination, and you probably aren’t surprised to know that it is completely possible for your webcam equipped device to be hacked, and yes, your webcam activated and watching whatever is in front of it. Not scary enough for you? What about that laptop you just gave your daughter?

Sadly, this isn’t just a scare tactic. ArsTechnica has a chilling article that takes a detailed look into the creepy world of “ratters” – young, mostly-male hackers who use covert Remote Access Terminal software (RATs) installed on compromised computers for the express purpose of spying on and remotely tormenting their “slaves.” RAT software is based on the same technology commonly found in support software used by IT professionals (like C2) to provide remote assistance and control on their customer’s computers. Unlike those legitimate tools, RAT software is designed to being undetectable and easy to install and spread without the victim’s knowledge.

What this means for you:

In nearly every case of malware attacks, especially ones that can deliver a payload like a RAT package, the incursion is typically the result of an action taken by the victim: visiting questionable websites, opening unknown attachments, clicking strange links in emails. Alongside of this is a set of inactions that the user is also guilty of: failure to install reputable antimalware software, failure to make sure the OS and installed software are kept up to date, and of course, failure to remain constantly vigilant!  As you’ve heard me say many times, nothing will stop a dedicated hacker from penetrating even the most stalwart of defenses. However, a good malware application and some common sense will put you miles ahead of the less cautious and less safe and typically off the radar of hacking ratters, who are looking for easy targets.

Another simple solution? That piece of tape ain’t looking so bad now, right? Just remember to cover the lens and not the “activity” light for the camera, which will tell you when your camera is possibly watching your every move. As always, if you notice your computer behaving strangely, disconnect it from the internet immediately and call a professional for advice.

Image courtesy of idea go / FreeDigitalPhotos.net

exploitationHackingmalwareprivacy invasionratting

US to China: Stop hacking businesses and government agencies

  • 0
admin
Tuesday, 12 March 2013 / Published in Woo on Tech
Hacker invading your laptop

Though it’s no secret to the security world, the US government has specifically avoided naming Chinese state agencies as the source of a tremendous surge in cyberattacks on corporate and government institutions over the course of the past 2 years. On Monday, the gloves finally came off as Obama’s security advisor, Tom Donilon pointed the finger of blame right at China’s military in a speech given to the Asia Society in New York, NY, as evidence gathered by multiple security firms continues to build an unavoidable confrontation on this issue. The Chinese government has of course denied these allegations, but has also said that it is willing to meet with the US and other nations to discuss cybersecurity.

What this means for you:

It’s still very early in the ballgame to decide if this is going to make things better or worse for the average business. At the moment, unless you are on the short list of companies that have information worthy of corporate or state-sponsor cyber-espionage, nothing will change for you, as your threats are likely still coming from the “traditional” vectors: either organized criminal elements seeking to steal from you, or random mischief and mayhem generated by malware controlled by those with less focus and malice. Today, as before, constant vigilance remains the most effective tool in your defense.

Targets of state-sponsored cyberattacks will continue to have a great deal to worry about. Where a “garden variety” attacker encountering strong defenses would normally move on to easier marks, cyber espionage targets will typically suffer through a dedicated, prolong campaign of multiple types of attacks (brute force, trojan horse, spear phishing, social engineering, etc.) because of the valuable data or services protected within and the deep pockets of the government powering their efforts.

It’s not immediately clear what either government hopes to accomplish around meeting on cyber warfare, other than to set up guidelines that will only be used for political leverage when violated by the other party, and probably ignored when it suits either country. As you can imagine, rules like the Geneva War Conventions only work when both sides are willing to abide by them.

Chinacyberattackespionagegovernmentpoliticssecurity

iPhone: Your next back-seat driver

  • 1
admin
Tuesday, 12 March 2013 / Published in Woo on Tech
Automatic Logo

Classic car enthusiasts have bemoaned the industry’s shift towards computerizing every aspect of automotive operations, especially things that in the past could be tuned and maintained with a set of tools and a little elbow grease. The rise of technologies like fuel-injection, ABS and automatic transmissions have made our cars some of the most sophisticated electronics we use on a regular basis, aside from our smart phones and computers, and like them, sometimes we know very little about how to keep them operating at top efficiency. A new company, Automatic, aims to change that with a small device called the “Automatic Link” which plugs into your car’s ODB-II port – the same one auto shops use to run diagnostics on any car made after 1996.

The device connects to your iPhone via Bluetooth, and using telemetric data gathered by your car’s own onboard computers, GPS data tracked on your phone, and (presumably) some powerful cloud-based data analysis, will analyze your driving habits and start to put together recommendations on how to drive more safely and efficiently, as well as providing historical analysis of all previous travels in your vehicle including time spent on the road, distance traveled, and average fuel-efficiency. If it spots trouble with one of your car’s systems, instead of flashing a cryptic message code that you have to dig out of your car’s instruction manual, it will again leverage the internet to provide more meaningful clues as to what might be wrong, and then show you nearby highly-rated auto mechanics that can help.

What this means for you:

The Automatic Link isn’t shipping until May of this year, so aside from media hype, all we have to go on are the promises of Automatic’s website. At the moment, it’s only being launched for iPhones, so if you aren’t among the Apple faithful, you are out of luck at the moment. This device is following a growing trend where we are tying larger portions of our lives to our smartphones, which, as I’m hoping you realize, is a double-edged sword. There are a great many benefits to be gained from devices such as this – but at what cost to your personal privacy. No doubt, Automatic has plans for the massive amount of data these devices can gather, and I imagine the demographic information contained within has any location-based business salivating at the prospects.

Appleautoscarsfuel efficiencyiPhoneprivacysafetytelemetry
  • 58
  • 59
  • 60
  • 61
  • 62

Recent Posts

  • woman afraid of technology

    Why Your Team Fights New Technology (Fun Fact: It Has Nothing to Do With the Software)

    Employees resist new technology because it thre...
  • man working on his desk

    Why We Say Please and Thank You to AI

    A client of mine was using a Claude agent to he...
  • man working on open laptop

    Network Monitoring: Why Professional Services Firms Need 24/7 Oversight

    Your network does not take nights off. Neither ...
  • code in a laptop screen

    Software Updates: When to Install, When to Wait, When to Worry

    On July 19, 2024, CrowdStrike pushed a routine ...
  • half open laptop

    Technology Transparency: Why We Don’t Hide Our Markups

    Go look up Microsoft 365 Business Basic on Micr...

Archives

  • GET SOCIAL
Get Tech Support Now - (818) 584-6021 - C2 Technology Partners, Inc.

© 2016 All rights reserved.

TOP