In a rare public admission, Apple has indicated that some of its own internal Macintoshes have been compromised in a cyberattack that security researchers believe similar to the one that breached Facebook last week. Announcements from Apple of this type are very rare, as Apple has long touted one of the strengths of its platform was how “unhackable” it was compared to Windows. In this particular case, Apple has little to lose, as it’s pointing the finger of blame for the hack at Java and a vulnerability that was taken advantage of to gain access to Apple employee computers.
What this means for you:
Apple’s recent breach is just one more notch in cybercrime’s belt that includes a long list of illustrious companies like the Wall Street Journal, Twitter, Facebook, Jeep, and Burger King, not to mention the numerous intrusions of government agencies and countless hacks of businesses that go unnoticed and un-reported. In the case of the Apple and Facebook breaches, the source has been tied to a mobile development website that both company’s employees accessed, and according to both companies, there appeared to be no evidence that customer data was compromised in the attacks. As I’ve maintained all along, the business world is now entering a new age of security unknowns as serious criminals continue to exploit technology to serve their needs, and are able to outspend and outgun the average small and medium size business. Before the age of computers and the internet, your odds of being targeted by a criminal organization were minute compared to today, where organized crime can now “crowd-source” affiliate-based networks that pay anonymous hackers in any number of a dozen untraceable ways to rent out zombified computers and webservers by the hour for a handful of dollars, and use pre-scripted attacks to launch massive, shot-gun targeted campaigns that only need to snag a small percentage of victims in order to be profitable. This is not some imaginative, cyberpunk movie plot – it’s happening right now, as you read this article. Moving forward, the only way to combat this growing threat will be a combination of vigilance and smart investments in security technology, policy and training.
Industry analysts are taking off their rose-colored glasses after examining the results of BlackBerry’s largely lackluster launch of their OS 10 platform. Original estimates had the newly renamed company (formerly Research In Motion) selling as many as 1.75 million new phones following the Jan 30 debut. Using words like “soft launch” and “modest demand”, analysts are now revising their estimates down by as much as 83%, putting BlackBerry’s comeback into serious doubt.
What this means for you:
It’s probably too early to call it, but BlackBerry really needed a big splash with the 10 launch and to keep surging forward with momentum to stay on par with upcoming anticipated Samsung and Apple launches on tap for Summer. Early reviews indicate that version 10 phones have caught up with the competition, but the technology hasn’t leapfrogged the competition, something BlackBerry really needs to do to gain any footing in this market, as they can’t outspend Google, Apple or even Samsung. If your company is heavily invested in BlackBerry and still supports it for corporate communications, you can’t go wrong with a Z10 or Q10, as long as your IT department has committed to keeping their BB infrastructure current. If they seem even the littlest bit wishy-washy on that subject, or they already support Android and iOS devices, you’ll make a safer investment in another platform.
Microsoft is (re)launching Outlook.com and consolidating its various “free” email service domains under the Outlook.com brand in an effort to regain the former glory it once held with Hotmail.com which has since fallen to a distant third behind Google’s Gmail and Yahoo Mail. Microsoft estimates it will be spending anywhere from $30 to $90 million in marketing in all the major media over the next 3 months on a combination of attack ads aimed at Gmail users as well as informational campaigns they hope will help persuade users to switch (back, in many cases) to Microsoft.
What this means for you:
If you already have a Hotmail.com or MSN.com email address and you haven’t already converted over, you’ll be migrated over to Outlook.com gradually as Microsoft consolidates the services under the new brand. If you are considering switching (or opening another webmail account), the only feature Outlook.com is offering that differs from the competition is Contacts stored in your online address book will automatically update information based upon information available on social media platforms like Facebook, Twitter and LinkedIn. Gmail does this with G+ but you have to resort to third-party extensions and services to mine the other social media sites for this information. Beyond this feature, Outlook.com is mostly playing catch-up to Gmail, though their marketing dollars may steal some of Yahoo’s marketshare despite the company’s revamp of its webmail service a little over a year ago.
Windows users will probably be unsurprised to note that Adobe’s ubiquitous Flash plug-in requires yet another patch. This time, unfortunately, Adobe is scrambling to release version 11.6 to rectify 2 serious security holes that are already being exploited in the wild, and not just on Windows machines; Macs and even Linux is affected by the latest flaws.
What this means for you:
The flaws fixed by the above release may allow malicious websites to install malware either from just visiting a compromised website, or by redirecting your browser to open infected Microsoft Word documents or Adobe PDFs. There are malware websites being found on the web right now that can take advantage of unpatched Flash plugins and they will wreak havoc on your computer.
Patch Flash now. Here’s how:
- Go to Adobe’s website: http://get.adobe.com/flashplayer/ (works for any platform)
- Windows: Go to your Control Panel and look for the “Flash Player” control panel icon. Click the “Advanced” tab and then the “Check Now” button.
If you want to verify you’ve updated to the correct version, you can check it by visiting this link after patching: http://www.adobe.com/software/flash/about/
Microsoft seems to be taking Fat Tuesday to heart: this month’s package of software updates includes a whopping 57 fixes for security flaws across most of its current product line. Microsoft isn’t the only one patching: Adobe also has a handful of security fixes for its products – the most commonly installed are Flash and Acrobat. The security exploits patched are just as potentially dangerous as the vulnerabilities patched in Internet Explorer.
What this means for you:
Ideally, you either have an IT department watching out for you and making sure your software is being updated in a timely fashion, or you have Automatic Updating turned on and will automatically download and apply all critical and important patches released by Microsoft and Adobe. In the case of the former, it may actually be a week or two before the actual patches are applied, as many IT departments routinely test all MS patches before distributing them through the enterprise, mostly to ensure Microsoft doesn’t break something proprietary to your company’s platforms. And in the case of this month’s Patch Tuesday, they will have much more to test and deploy.
If your computer is relying on automatic updates received via the internet, make sure you pay attention to the little message popups in the lower right corner of your screen. Windows Update will let you know when its doing its thing, and will also notify you when it has finished applying the necessary patches. Not sure whether your machine has been patched? For most versions of Windows (XP, Vista, 7) you can click the Start Menu and select “All Programs” and scroll until you find “Windows Update”. Review the information on the screen, and if you have any questions, don’t hesitate to call us for a second opinion!
If Forbes is writing about it, then it must be entering the mainstream, right? According to their calculations, the latest jailbreak for the iPhone’s iOS 6 has been installed over 7 million times since its release last week, which is roughly equivalent to about 2% of the overall iPhone population, and that number is likely to grow over time to 10% according to Jay Freeman, the administrator of the “unofficial” jailbroken iPhone app store, Cydia.
“Jailbreaking” (similar to “rooting” in the Android world) is basically a process that removes the restriction of installing apps from a third-party app store not controlled by Apple. Apps found at Cydia commonly enable iPhones to do things that normally wouldn’t be possible under Apple’s strict programming and content guidelines, such as (before iOS 6) multitasking or something as simple as setting Google’s Map app as the default mapping application when you click on addresses on your iPhone.
What this means for you:
The explosion in popularity of smartphones and tablets has infused cultures everywhere with elements of hacking and tinkering as people become more comfortable with customizing the phone rather than just using “as directed”, right up to the point where they hit the limitations of the device, and in the case of the iPhone, the (sometimes arbitrary) limits set by Apple. Over the years, jailbreaking, once considered arcane and only for the most foolhardy hacker, has now become something simple enough that you could walk your grandmother through the process.
Let’s be real – jailbreaking your grandmother’s iPad is probably not necessary, but if she could do it, then surely you can do it. And if it means being able to finally get rid of Apple’s miserable Maps application and return to trusty Google Maps once and for all, jailbreaking starts to look a lot more inviting. In the end, jailbreaking is about deciding whether Apple’s vision for how you should use your phone or tablet meets your needs (which it does for the majority of Apple customers) or whether you are really ready to “think different.”
Caveat: Jailbreaking your iPhone or iPad, while legal in the USA, will void your warranty according to Apple.
You may have already come across this strain of malware before: a big, official looking notice pops up on your screen accusing you of software piracy. You are offered the opportunity to pay your “fine” online, which appears to be the only way to remove the notice and get back the use of your computer. This form of extortion scam is known as “scareware” and has been around for years. Most technology users are savvy enough these days to no longer fall for this particular tactic, but a new form of scareware accusing users of viewing child pornography is now circulating that is giving even the most hardened malware veterans cause to pause. As you can imagine, being accused of this particularly heinous activity puts potential victims into the uncomfortable position of sharing this with someone else, something that they may be willing to avoid by paying what now may seem like a reasonable “fine”. Cybercriminals are counting on the squeamish and privacy-conscious nature of most people in this regard, and it’s likely we’ll see a huge uptick in this type of scareware tactic.
What this means for you:
No law enforcement agency in the United States issues fines via the internet, and they certainly don’t hold your computer hostage until the fine is paid. If your computer is infected with a scareware virus, immediately disconnect it from the network and contact your IT department or technology consultant, regardless of what you are allegedly accused of doing by the scareware notice. Any IT professional worth a darn will be intimately familiar with this particular type of malware and should be able to remove it from your computer, BUT, depending on the level of infection, your data and identity may be at risk, as well as your personal information, especially if you’ve accessed online bank accounts or other sensitive online information. You’ve backed up your important data on that computer right? Because many times, it’s easier to wipe a computer completely clean and start with a fresh operating system rather than cleaning up a malware infection. This is yet another reason in a long list on why you should be backing up your data regularly.
Image courtesy of Stuart Miles / FreeDigitalPhotos.net
Following recent attacks by hacktivist group Anonymous on various government websites, the Department of Energy has reported that it too has been hacked, and personal information on hundreds of its employees has been compromised. The DOE has been relatively tight-lipped about the breach, and it’s not immediately clear whether this may be related to Anonymous’s current campaign “Operation Last Resort” which aims to reform computer criminal laws in the wake of internet celebrity Aaron Swartz’s suicide. In the case of the Anonymous-led attacks, various government websites have been completely taken over by hackers and used to post derogatory videogame parodies and login credentials for hundreds of banking executives.
What this means for you:
The gloomiest of the doomsayers are saying that in the near future, there will be only 2 types of businesses: “Businesses that have been hacked, and ones that don’t know that they’ve been hacked.” We’re not there yet, but some analysts believe we’ve hit an inflection point in cyber security where the criminals are now ahead of the business world in terms of sophistication and advantage. If the above is any indication, many government institutions are probably even further behind businesses in terms of security. Does that mean it’s time to pack up all that technology and return to paper ledgers, brick and mortar storefronts and hand-written checks? Not yet, but the businesses that take an aggressive stance towards tightening up their ships will stay well ahead of the competition, especially when those looser ships start to spring cyber-leaks.
What’s the first step? Find out if you have an information security policy. If so, make sure it’s being enforced. If not, call me right away to start talking about how to get your company’s technology battened down for the coming storm.
Yesterday I posted about the real possibility of cybercriminals and spammers using Facebook’s upcoming “Graph Search” as a means to easily sort out and research potential targets. The Electronic Frontier Foundation, ever on the lookout for our privacy (even when we won’t do it ourselves), has put together an excellent guide on all the settings you should review in Facebook to make sure the data you want to be hidden from the general public stays that way.
What this means for you:
If you’ve ever taken a stroll (or even a dedicated walkthrough) of Facebook’s privacy settings, you probably gave it up for being unnecessary and complicated. Hopefully my previous article made you reconsider the “unnecessary” stance, and now EFF gives you a step-by-step guide to setting the privacy settings to what you want them to be. The only thing better would be having me sitting with you personally to go through each step and doing it for you. I could totally do that if you like, but while I was doing it, I’d be giving you a (possibly boring) lecture on why you should be learning how to do this for yourself, etc. Your privacy and security is important enough that you should understand exactly how Facebook shares your personal information. We are entering a period of time where getting duped by hackers is moving from nuisance to an actual threat on your livelihood and possibly even your personal safety, and the best defense is knowledge and preparedness.











