Remember the announcement of Facebook’s new “Graph Search” feature? No? I don’t blame you. Until most folks can get their hands on it and see what it can do with data from people they know, it’s hard to envision how Facebook’s “innovation” is important. Security analysts, of course, eat and breath this stuff, and as they are trained (and expected) to do, they have extrapolated how this powerful social media search tool could be put to nefarious use. Christopher Hadnagy (Social-Engineer.org) put it succinctly:
Usually, a phisher or spammer collects a couple hundred email addresses and they’re hoping 10 percent of those who get it have an interest in what the email is about. With this tool, it gives a malicious person the ability to figure out whom to target with a particular message because they know their interests.
In case you aren’t aware how “phishing” works, the core conceit is focused on fooling the reader into clicking on links and providing confidential information to a counterfeit website. Phishing is most effective when the target gets an email that seems legitimate, e.g. using graphics and fake address from bank with which they already do business. Instead of having to rely on statistical probability, phishers can now target with ruthless efficiency any data available through Facebook’s Graph Search.
What this means for you:
If you are an avid user of Facebook with a tendency to openly share just about everything through social media, your data is already out there and viewable. If you are a casual Facebook user, but haven’t taken the time to adjust your privacy setttings, your data is already out there and viewable. Nothing has changed in that regard. However, up until now, you had a very, very thin layer of protection through the concept of “security through obscurity”. In other words, the sheer, overwhelming amount of data that is available greatly reduces your chances of being randomly identified and targeted. Think of it as wandering into the Library of Congress where the only way to find something was to know exactly what it was called and where it was located physically in the building.
Facebook’s Graph Search gives anyone the ability to search for anything in Facebook using a natural language query like, “Show me all the books on 19th century bridges built in the US with wood.” If those books are in the library and are viewable to the public, then they would be delivered in a tidy page that could be reloaded and refreshed whenever the search was needed. Here’s the key: the data is viewable only by those to whom you’ve granted permission to view. If you allow the public to see your contact information and “Likes”, that data will be viewable by not only your friends, but the internet, including the aforementioned phishers. If you haven’t reviewed the privacy and security permissions on your Facebook account, now is a good time to do so.
If you’ve been salivating at the prospect of upgrading to Microsoft Office’s latest iteration – 2013 – then your wait is officially over. Multiple SKU’s of Microsoft’s productivity platform will become officially available on Jan 29. Most importantly, Microsoft is now making the Office suite available to be “rented” via the Office365 Home Premium package. This subscription-based service will allow the main Office apps (Word, Excel, PowerPoint, OneNote, Outlook, Access, and Publisher) to be installed on up to 5 computers on your local network (Windows or Mac) for $99/year.
What this means for you:
Up until the arrival of Office365, most organizations couldn’t afford (or didn’t want to afford) an enterprise license for Microsoft products with the Sofware Assurance premium which basically guaranteed upgrades for their entire license base over a certain number of years. Instead they purchased what is known as a “perpetual use” license: it allowed the licensee to use the version of Microsoft software they purchased for as long as the software remains viable. This has manifested as many, many organizations running much older versions of Office dating back 10 or more years, and still quite happily getting work done without paying a single additional dime to Microsoft.
Microsoft, in an effort to keep the coffers full and users happy in all categories, has commoditized Office with this subscription service for everyone, allowing companies and families with tight budgets to remain competitive without breaking the bank. Office has been the predominant productivity package for business, and now with affordable pricing for entire households, Microsoft hopes to further extend and cement its grasp throughout the consumer market as well. Depending on where you stand in the industry, this is not always necessarily a bad thing. Broad standardization will lighten support burdens everywhere. On the flipside, crushing the competition might lead to stagnation in innovation, and as we all know, it’s been a long, long time since anyone every looked at a new version of Office with anything other than trepidation.
According to The Verge, Google notified Microsoft of its plans to discontinue support for ActiveSync on the Gmail platform last year, and has recently notified Microsoft that the cut-off is coming on Jan 30, despite Microsoft’s efforts to get a 6-month extension from Google. ActiveSync is widely used to sync calendar and contact data from Gmail to Windows and iOS devices. Microsoft has noted that the Windows Phone OS will support CardDAV and CalDAV, which are the protocols used currently for synching on Android devices, in a future update of Windows Phone OS, but the update release data has not been announced yet.
What this means for you:
If you use Gmail as your primary calendar and contact management system, and you are syncing contacts and calendar data to a Windows Phone or an iPhone, you will lose the ability to sync up your data between phone and the cloud for an unknown length of time once Google drops support for ActiveSync – Gizmodo projects it could be as long as six months time. If you need this functionality, start considering alternatives ASAP!
Microsoft has announced that it will be raising the price of Windows 8 upgrades at the end of January to the full retail cost of $119 to $199 for the Pro version. The downloadable upgrade from Windows 7 to 8 is currently available for $39.99, and there is a boxed, retail version available for $69.99, but those prices will no longer be available on February 1.
What this means for you:
If you were at all considering upgrading to Windows 8, but aren’t necessarily ready to make the change right now, you may want to go ahead and make the purchase now and save yourself some money. Savvy technology users will have only minor issues transitioning, and Microsoft isn’t going to change their minds and rollback Windows 8, so eventually, savvy or not, you’ll probably be using Windows 8 at some point.
Keep in mind that the $39.99 price is for an upgrade version of Windows 8, so you will need a machine with a licensed copy of Windows XP, Vista or 7 to use it properly. The upgrade version cannot be easily installed on a blank computer unless you have the install media (and activation key) for your older OS handy.
Research In Motion (RIM), makers of the once-dominant BlackBerry platform, has announced the launch date of its BlackBerry 10 phones to be January 30 by all the major US carriers except Sprint, who has promised a BB10 phone later in the year. Many analysts believe that this launch is the last-ditch effort by RIM to regain relevance in an industry dominated by iPhone and Android devices, and just as many have already counted them out.
What this means for you:
If you are one of the dwindling BlackBerry faithful, there is a lot to whet your (by now, monstrous) appetite: the new RIM OS modern look and all new code-base (supposedly no carry-over code from older RIM OS’s) will hopefully update BlackBerry’s staid, corporate image. However, the new BB10 phones have multiple strikes against them:
- Developers for the “staple” apps (Facebook, Google, Netflix, etc) will undoubtedly develop versions of their omnipresent apps because they can fund the development off the backs of their profitable iOS and Android counterparts, but don’t expect surprise hits from indie developers appearing on BB10 first – there just isn’t a large enough userbase to warrant the investment gamble. RIM has sponsored some recent events to kickstart development, but proof will be in whether BB10’s launch will be a repeat of Microsoft’s Windows Phone lackluster debut.
- BlackBerry’s current infrastructure has some serious redudancy flaws that has led to some titanic outages. Once viewed as the most reliable platform in the early days of smartphones, the series of recent, widespread outages has severely tarnished RIM’s image.
- RIM has been lapped by Apple and Google, OS-wise, at least 2 to 3 times now. RIM is just launching a competitor to phone OS’s that were developed years ago. Unless this horse can fly, there is no way BB10 is catching iOS6 or Jelly Bean in this race.
I suspect that RIM isn’t quite done – they still have a nice chunk of the market, but they aren’t going to supplant iPhones or Androids anytime soon.
Carnegie Mellon University’s CERT and the Department of Homeland Security have issued a broad warning about using the latest version of the Java 7 plug-in for web browsers, and some browser manufacturers have already taken steps to disable Java application execution until the vulnerability can be fixed. The security flaw is already being exploited in the wild, and can be used to run malicious code without the victim’s permission or even awareness. Oracle is investigating, but has not indicated when the hole would be patched, aside from promising a fix “shortly.”
What this means for you:
Unless you have a really good reason to keep running it, you should probably disable Java until Oracle can fix this problem. Unlike other vulnerabilities that affect specific browsers (Internet Explorer has been notorious for flaws in the past), this particular problem affects all browsers that have a Java 7 plugin, including the Apple OS. Oracle has had problems in the past with providing quick patches for the Java platform, so until they do, the safest approach is to disable the plugin in your browser.
Over the past four months, many of the Western world’s largest banking institution websites have been under attack by a well-organized and funded cyber “brigade” that is allegedly part of the US-branded terrorist group “Izz ad-Din al-Qassam” – the military arm of Hamas. Aside from the publicly-stated political agenda motivating the attacks, little else was known about how the attacks were being carried out. Security analysts believed that rather than using large numbers of zombified consumer computers, this series of attacks were actually being powered by a smaller number of more-powerful webservers.
Security firm Incapsula confirmed this theory after recently discovering that a single UK webserver was behind a most recent attack on PNC, HSBC and Fifth Third banking websites. The server had been compromised with a simple backdoor program that allowed a remote operator to launch DDoS-style attacks using a simple, light-weight interface that may have been operating for months unbeknownst to the host or the server’s legitimate admin. Even though it was a single, relatively small server, it was capable of crippling websites of major financial institutions.
What this means for you:
The server in question wasn’t compromised using some sophisticated exploit, brute force attack or clever social engineering. According to Incapsula, the server was using an easily guessable admin password that resulted in an effortless and undetectable security breach. As consumer technology has become more accessible, so have server-class platforms that can be rented out by anyone with a credit card, and typically can be set up in minutes with only a rudimentary knowledge of server administration. This results in situations that look a lot like handing a powerful weapon to someone who has only been given very basic instructions on which end to hold and which end to point at the target. However, in the hands of a skilled hacker, a small “team” of compromised webservers is the equivalent of having a small special forces team operating behind enemy lines. Bottom line – if you have servers in your technology portfolio that aren’t being managed properly, your own technology might be waging an invisible war right under your nose.
Image courtesy of “renjith krishnan” / FreeDigitalPhotos.net
According to security firm Exodus, the patch to Internet Explorer 6, 7 and 8 released on December 31 only fixed one of several ways to exploit a weakness in Microsoft’s browser. In their research on this exploit, Exodus continued to develop more aggressive ways to exploit the documented weakness and in doing so, uncovered a means that bypasses Microsoft’s fix, but are witholding details from the public until Microsoft has a chance to address their findings. A number of human rights and government sites have been compromised with malware agents that exploit this weakness and appears to be part of a larger campaign by the “Elderwood Gang” – a highly effective and well-backed group of hackers that have been targeting high-profile government sites since 2009, ostensibly with financial and espionage-based goals.
What this means for you:
Internet Explorer 6, 7 and 8 are still considered vulnerable, though no one has documented any websites yet taking advantage of the exploits discovered by Exodus. The fact that there are still holes in IE browser security will not go unnoticed, and if Exodus can develop work-arounds for Microsoft’s patch, you can bet groups like “Elderwood” will be able to do the same, if they haven’t already. Your best short-term solution is to either use another browser like Chrome or Firefox until Microsoft can fully patch this weakness, or upgrade your Internet Explorer to version 9 or 10 as soon as possible. If you are working for an organization or using software that requires backward compatibility to IE 7 or 8, you should consider having a serious discussion with the IT department about their reasons for maintaining what is increasingly becoming an untenable stance. If you are required to use IE 6 for some unfathomable reason, you should stop what you are doing immediately and consult with an IT professional, as IE 6 is a magnet for security exploits.











