Get Tech Support Now - (818) 584-6021 - C2 Technology Partners, Inc.

Get Tech Support Now - (818) 584-6021 - C2 Technology Partners, Inc.

C2 provides technology services and consultation to businesses and individuals.

T (818) 584 6021
Email: [email protected]

C2 Technology Partners, Inc.
26500 Agoura Rd, Ste 102-576, Calabasas, CA 91302

Open in Google Maps
QUESTIONS? CALL: 818-584-6021
  • HOME
  • BLOG
  • SERVICES
    • Encryption
    • Backups
  • ABOUT
    • SMS Opt-In Form
    • Terms and Conditions
    • Privacy Policy
FREECONSULT

Serious Security Hole Revealed in iOS

  • 0
admin
Tuesday, 25 February 2014 / Published in Woo on Tech
Apple Logo

Usually Apple is able to sit on the sidelines of today’s technology security circus , enjoying a (debatable) reputation for being more secure than Windows and even Android. Unfortunately, it had to step into center stage this week and own up to a security flaw in its core networking code used in both iOS and OS X. And not just a little one either: this one affects how SSL-encrypted network traffic is handled, and it affects iPhones, iPads running iOS 6 or 7, and any computer running OS X 10.9 “Mavericks”.

What this means for you:

In a nutshell, the bug essentially prevents the affected device from verifying the identity of the certificate used to guarantee the SSL encryption. When your Apple device fires up a secure connection using SSL, the first thing it’s suppose to do is check the SSL certification of the destination by verifying it’s identity. Except, in the case of the bug, it doesn’t but reports back to the device that everything is OK. This would be the equivalent of putting a blind doorman in front of your bar to check ID’s. Apple has released a patch for iOS 6 and 7, but still has not issued a fix for the OS X platform.

For now, until you verify you’ve patched your mobile device with the latest security update for your version of iOS, I recommend against using any applications that transmit confidential data (your’s or your client’s) over the internet. On the desktop/laptop side, avoid using Safari until OS X is patched, and switch to a browser like Chrome or Firefox, both of which implement their own SSL code that is not affected by this flaw. To keep track of whether or not Apple has fixed this hole, you can visit: http://hasgotofailbeenfixedyet.com/

Update: As of Feb 25, Apple has issued a patch for OS X 10.9. Make sure your Apple devices update to the latest version of their corresponding operating system.

Appleconfidentialencryptionflawsafarisecuritysslvulnerability

New Top Level Domains Coming Next Week

  • 0
admin
Wednesday, 29 January 2014 / Published in Woo on Tech

Late last year, the Internet Corporation for Assigned Names and Numbers (ICANN) announced that they were opening up registration for more top level domains on the internet. Starting next week, the familiar “.com”, “.edu” and the other 20 well-known TLD’s maybe joined by as many as 1900 new domains over the course of the next few years. Among the first that will be released for use will be “.book”, “.bike” and “.wed” as well as specific corporate domains for large companies like “.apple”, “.google” and “.ford”.

What this means for you:

If you already work for a company with a well-established and/or well-known domain, your marketing folks (and the lawyers) may explore the new TLD’s primarily to protect the company’s brand from competitors or domain squatters. They should know that as part of the introduction of more TLD’s, ICANN has also introduced a new trademark clearinghouse where infringement challenges can be handled before the legal knives come out. If you are in the process of establishing your online identity and have been under the impression that all the “good” domain names have been taken (for TLD’s like “.com” they have, for the most part), the new TLD’s may present an opportunity for certain businesses and creative marketers.

However some industry analysts are worried that the proliferation of TLD’s may just lead to more confusion and uncertainty on the internet for the majority of users. For example, once “.google” goes live, when I want to search for something, do I go to “google.com” or “search.google” or “www.google” or “google.google”. My guess, at least with Google, all of those will work, but imagine trying to tell your grandmother the difference between them (there might be!) or why there is more than one URL, especially after you finally got her to start using Google in the first place. It’s too soon to say, but given how confusing the internet is now, one thing it’s not likely to simplify will be internet security.

Image courtesy of jscreationzs / FreeDigitalPhotos.net

AppledomainsfordGoogleicanninternettop level domains

Can the NSA hack your new iPhone?

  • 0
admin
Wednesday, 08 January 2014 / Published in Woo on Tech
Eye (of Sauron) Phone?

German newspaper Der Spiegel launched a media frenzy last week with the provocative story that the NSA can (and probably has) compromise the iPhone in a way that gives them complete “ownership” of the device for the purposes of surveillance. Fueled by documents released by infamous informant Edward Snowden, the article details a specific program called “Dropout Jeep” that could completely compromise an iPhone…in 2007.

What this means for you:

Today, in the internet economy, media outlets have priorities that aren’t always compatible: keep their audiences informed, and get as many eyeballs/clicks/likes as possible. As you can imagine, stories about iPhones and NSA spying are hot commodities right now, so when the two subjects align, how can you not lead with such an explosive story?

Several articles spurred by the Der Spiegel piece speculated that Apple may have been working with the NSA all along. Most suggested that the NSA can and has owned even current gen iPhones. Apple, of course, has denied any collaboration with the spy agency. The NSA itself continues to remain silent on stories like this. But, as mentioned above, the Dropout Jeep program was active in 2007, and required the hacker to have physical access to the device. As many of you have heard me say before, if someone has physical access to your device, compromising the device (regardless of manufacturer or type) becomes much more straightforward. The Snowden document did indicate that the NSA was working on future versions of the spyware that wouldn’t require physical access to the device, but for the moment, there is no proof that they can “own” modern iPhones.

But there’s no proof that they can’t, either.

 

Appleder spiegeldropout jeepHackingiPhonensaspying

It’s Raining Tablets

  • 0
admin
Wednesday, 23 October 2013 / Published in Woo on Tech
The iPad Air

Earlier this year, CEO Thorsten Heins of beleaguered tech company BlackBerry infamously stated, “In five years I don’t think there’ll be a reason to have a tablet anymore.” The press had a field day with this quote and the explosive growth of tablets in 2013 alone seems to be proving otherwise. As if to rub Mr. Heins’ and other tablet-doomsayer’s faces in it, October is seeing the launch of multiple new tablets, including new lineups from Microsoft, Nokia and Apple, all essentially debuting on the same day.

Apple dominated the American media on Oct 22 with the debut of “the lightest full-sized tablet” on the market, the iPad Air, weighing in at a diminutive single pound. It also updated the wildly popular iPad Mini with its high-resolution “Retina” display, bringing the 7″ tablet up to par with competing models from Google and Amazon. In an attempt to not be out-done (and sadly not quite succeeding in that effort), Nokia announced its first tablet today as well. The Lumia 2520 will run Microsoft’s Windows RT, a move that analysts questioned given the tepid consumer response to Microsoft’s tablet OS, but is not unexpected in light of the Redmond tech-giant’s recent acquisition of Nokia’s hardware business. Not wanting to be left out of the tablet party, Microsoft held its own midnight release event on Oct 21 at its retail stores around the country to celebrate the arrival of the Surface 2. Despite loud music, flashy displays and enthusiastic staff, the Surface 2 launch parties seemed to be (unsurprisingly) sparsely attended.

What this means for you:

If you’ve been holding off on buying a tablet for some reason, the market is currently overflowing with choices, and many of them are very strong on features and backed by staunch developer support and healthy ecosystems, notably the iOS and Android family of products. Though many are saying it’s too early to tell, the Windows RT and Windows 8 tablets have a stiff, uphill climb in the market, something that is keeping developers away from the OS, leaving Microsoft’s app marketplace relatively barren compared to the competition. There’s been a minor stir of interest in the Surface tablets from the arts industry, primarily because of the hardware’s robust pressure sensitivity, but unless you have a specific use case in mind, I’d steer clear of the Windows tablets for now. If you’ve been concerned about the size and weight of the 10″ tablets (very hard to use as bedtime readers or if you spend any time as a standing commuter) you can’t go wrong with a 7″ tablet from either Apple, Google or Amazon, all of which now feature high-definition screens, robust app stores and great portability.

 

amazonAndroidAppleBlackBerryGoogleiosipadlumiamicrosoftnokiasurfacetabletwindows

Lockscreen Siri Access Exposes iOS7 Security Flaw

  • 0
admin
Tuesday, 01 October 2013 / Published in Woo on Tech
Siri

You thought you’d done a good thing: you finally listened to all the warnings and locked your iPhone with a passcode or, if you are one of the lucky few with a shiny new 5s, the new fingerprint lock. Sadly, one of Apple’s other famed technologies may betray you in the end. An Isreali security analyst has uncovered a significant flaw in iOS7 security when access to Siri on your iPhone’s lockscreen is enabled. The problem is part convenience and part bug: using Siri while your phone is locked allows you to make calls without having to punch in a passcode, something that is indispensible while driving, or when your hands are otherwise occupied. Unfortunately, using Siri in this manner leaves a back door open in the form of unfettered access to the phone app, while your phone is still locked. Oh, and did you remember that Siri responds to anyone’s voice, not just the owners? 

What this means for you:

“How bad could this be?” I hear you asking. While in the phone app, the user can access the phone’s voicemail, send text messages, view the calendar and look through all the contacts in your phone. If you don’t consider that private, you are part of a very small minority on this planet. The fix is simple: disable access to Siri from the lockscreen. The recommendation: do it now if you care about your phone’s security. It’s likely Apple will fix this flaw, but will they do it in time to protect your confidential data?

Applebugconfidentialexploitflawhackios7securitysiri

Cross-platform Chat App May Be Dodgy

  • 0
admin
Wednesday, 25 September 2013 / Published in Woo on Tech
ID-10021674.jpg

A new app has appeared on Google’s Play store that purportedly offers Android users the ability to chat with iOS users via Apple’s iMessage platform, and it has security eyebrows raised, primarily because it wasn’t released by Apple. Cydia (app store for jailbroken iPhones) developer Jay Freeman delved into the code of “iMessage for Android” and discovered another alarming fact: the app appears to be authenticating not through Apple’s servers, but through some unknown platform in China, even though it requires a legitimate Apple ID to work. Another developer also noted that this app has the ability to silently download code to your Android smartphone, a permission that could lead to a malware infection. The app is very new and these security peculiarities have yet to be widely verified, but it has already been downloaded from the Play store over 10,000 times.

What this means for you:

Firstly, your Apple ID (which may have money and many, many apps, songs, movies, etc. tied to it) is being passed through an unknown server in China. There is no guarantee that the owners of that server aren’t collecting these IDs for nefarious purposes. Add this to the fact that the app can download code without notifying you, and the scales are now dipping alarmingly towards “dangerous” if not outright “malicious”. Also at stake is the trustworthiness of Google’s Play Store app vetting process – how could this app have possibly made it through without raising some red flags. Sure, there is no love lost between Apple and Google, but Google is usually smart enough to not poison its userbase with a dodgy app just so Android users can text chat with iOS users. It remains to be seen whether this app is truly on the up and up, but all signs indicate otherwise at this point. I’d err on the side of caution and avoid installing this app for now. If you really need to talk to that iPhone user, just send them a text!

Image courtesy of Idea go / FreeDigitalPhotos.net.

AndroidAppleapple idChinaGoogleimessageiPhonemalicioussecurity

German Hackers Bypass iPhone Fingerprint Protection

  • 0
admin
Tuesday, 24 September 2013 / Published in Woo on Tech
Touch ID Hacked?

When you are king of the mountain, everyone lines up to take a shot at you, and the iPhone is no exception. In this particular case, security analysts were taking bets on how long it would take for someone to defeat the brand-new iPhone 5s fingerprint scanner. They didn’t have to wait long, as it seems a German hacking group known as the Chaos Computer Club was first to publish a technique they claim will defeat Touch ID’s technology. Though the claim has yet to be independently verified, it has the same trappings as the infamous “gummi bear hack” that poisoned public perception of biometric security measures over a decade ago. In a nutshell, the hack requires a high-resolution scan of the target’s fingerprint, which is then used to create a fake finger from a laser printer and a thin layer of latex.

What this means for you:

According to the Chaos Computer Club, their intent behind publishing the findings was to demonstrate to the public the weakness of fingerprint-based security, pointing out two very obvious weaknesses: (1) we can’t change our fingerprints if they happened to get compromised, and (2) we leave them everywhere we go. Whether or not CCC’s technique proves replicable, it is only a matter of time before other techniques are published, and their points still stand. Multi-factor authentication methods can surmount this particular problem, as can biometric patterns that aren’t so easily replicable (such as your cardiac signature), but the fact remains that the easiest method to gain access to your phone is for someone to gain access to one that isn’t protected at all, either by fingerprint, pin or password. Unless the only thing you use for smartphone for is games, you should always have some form of protection on your phone, and doubly so if you use it to conduct work.

Applefingerprinthackiphone 5sscannersecuritytouch id

New iPhone 5S and 5C Announced as Expected

  • 0
admin
Wednesday, 11 September 2013 / Published in Woo on Tech
iPhone 5C

True to form, Apple announced at a press event today the arrival of the iPhone 5s and 5c. I’ll keep this one short, so you can get down to the business of deciding whether or not you are buying one!

What this means for you:

The 5c is Apple’s rumored budget phone. Priced (with 2 year contract) at $99 for a 16GB model, and $199 for the 32GB, this model replaces the metal with plastic, and comes in five bright colors. Aside from that and the fact that it ships with iOS 7, it’s functionally the same hardware as the iPhone 5 released last year. If you’ve been on the fence until now about buying an iPhone because of the price, this may hit your sweet spot, assuming you don’t mind the 2-year commitment.

The 5s features a faster processor; early tests show a 30% speed increase but Apple claims up to 2X faster performance. It also comes with a fingerprint scanner to unlock the device, and a new, low-power chip that is designed specifically to work with fitness apps (hinting at the imminent arrival of an “iWatch”), and an improved camera. This one is priced at the expected $199/$299 price point (with 2-year contract, of course!) and is available in Gold, Silver and “Space Gray”. This will be a tougher sale for a lot of people, especially since rumors are flying that the iPhone 6 may be released in early Spring 2014 as opposed to the usual timeframe of late Summer, early Fall. The 5s isn’t a huge leap forward from the 5 in terms of hardware specs, so don’t buy one expecting a big performance increase.

If you are holding on to an older model iPhone 3 or 4, the 5s would be a nice step up. If you are budget conscious, or considering a new phone for your pre-teen or teenager, the 5c may be a great choice to hook up your kids without breaking the bank.

Appleiphone 5ciphone 5siphone 6upgrade

Gmail’s Spam Filter Isn’t Foolproof

  • 0
admin
Monday, 09 September 2013 / Published in Woo on Tech
Phishing email or legit?

If you’ve taken to heart any of the security advice or practices that I or many other technology professionals have been dispensing for the past few years, you’ve probably developed a healthy skepticism for any emails that land in your box that are unexpected and contain unfamiliar links. Even more so if your email provider marks the email as spam or a possible phishing attempt.

For example, I recently received an email with the subject “iPhone iPod touch Class Action Settlement” that was immediately marked as spam by Gmail. This email purportedly offered me a part of a class action settlement with Apple. Seeing how many people own iPhones and iPods, it seemed like good phishing bait so I assumed this was yet another scam. It had all the trappings of a well-made con:

  • broad target demographic
  • based on a recent, actual event
  • contained lots of official-sounding text that didn’t read like a 4th grader wrote it
  • no overt clues that the sender was an obvious bad agent (non-US domains, inappropriate reply-to addresses, spoofed mail headers, etc.)

It would probably lure people into clicking a link that would either load up their machines with malware, or entice them into giving up some personal information that would later be used in an identity theft attempt. I opened it up with the intent of warning my audience and clients about the potentially well-crafted fraud.

As it turns out, this is a legitimate email that Gmail incorrectly identified as spam, probably because the sender was flagged as a spammer by justifiably suspicious readers like you and me. A little research online reveals this is part of the original case that made headlines back in May of this year. Emboldened by this information, I used Chrome (bolstered by a variety of anti-scripting extensions) to visit the included link, and, lo and behold, it’s a legitimate website. Because of the relative newness of this initiative, there isn’t a lot out on the web about this yet, so unless you are an experienced internet researcher, your searches might have come up with little evidence that this was a legitimate email.

What this means for you:

Most cautious internet citizens might have trusted their email provider’s guidance on this and just deleted this email, potentially missing out on as much as $200 as a settlement award. False positives are an unfortunate side-effect of a proper security protocol, and in this case, even Google didn’t provide enough information to immediately assuage my suspicions, and a few search results actually led to conversations where people immediately labeled it as a scam. Sometimes the internet does not provide instantaneous answers, nor is it always right, and as always, you should always take your search results with a grain of salt, especially if there is money at stake. If your search results turns up a dearth of information, your best course of action is to wait a few days for the internet to catch up (it always does!) and research again, or to contact a tech expert like C2 Technology to get a second opinion.

Image courtesy of David Castillo Dominici / FreeDigitalPhotos.net

Appleclass actioniPhoneiPodlawsuitscamsecuritysettlementspamwarrantywater damage

Android Top Target for Mobile Malware

  • 0
admin
Wednesday, 28 August 2013 / Published in Woo on Tech
Android Logo

Confirming what many commercial security companies already claim, a security bulletin published on the Public Intelligence website by the Department of Homeland Security and the Federal Bureau of Investigation identifies the Android OS as the most attacked mobile operating system. Nearly 80% of all malware threats in 2012 targeting mobile devices were focused on Google’s platform. The distant second place (19%) was held by Nokia’s Symbian OS, most commonly found on older feature phones. At the other end of the spectrum was Apple’s iOS, which despite being one of the most popular mobile devices on the planet, was only targeted less than 1% of the time in 2012.

What this means for you:

The malware focus on Android is not unexpected: the platform is fractured across multiple versions and multiple carriers, and there are hundreds of thousands of phones running older versions of Android that have well-documented security flaws that have been fixed in later versions. Unlike Apple’s relentless updating of the iOS, many Android phones rely on the carrier to push OS updates, which they do reluctantly, if at all, especially to hardware lines that are no longer being sold or considered a significant portion of the market.

Unfortunately, the carriers have also locked down the OS on many models, requiring a series of highly-technical processes to “unlock” and “root” the phone to force an update to the OS. Of course, doing so voids any warranties with the carrier, and has a chance of “bricking” the phone itself if the process is done incorrectly, or if it is updated with an OS that has bugs or is incompatible with that specific model phone.

Here are some things you can do if you find you are using an Android phone running an older version of the OS:

  1. Contact your carrier to request an OS update. If they tell you one is not forthcoming immediately, or that your particular model is essentially no longer receiving updates, let them know you are concerned about security flaws in the older OS, and ask for an upgrade to recent model phone.
  2. Whether or not a new Android phone is in your future, you should be extremely careful about “sideloading” apps. Only install apps from Google’s Play store, and be very careful following app install links from anyone. Instead, get the name of the app you want to install, go to the Google Play app already installed on your phone, search and install from there. If you can’t find the app, it’s likely the link was to a sideloading site (and potentially unsafe), or a disguised attempt to get you to install malware on your device.
  3. Install a malware protection app. Several reputable companies make apps for Android. I’ve been using SecureAnywhere from Webroot for several months now, without issue, and I will soon be testing Kaspersky’s app. Look for a name you recognize, and give their app a try. Some of them might slow your phone down on ocassion as they scan for issues, but the temporary inconvenience may save you from serious heartache later on.
AndroidApplebrickingGoogleiosmalwareoperating systemrootingsecuritysideloadingunlocking
  • 1
  • 2
  • 3
  • 4
  • 5

Recent Posts

  • man working on his desk

    Why We Say Please and Thank You to AI

    A client of mine was using a Claude agent to he...
  • man working on open laptop

    Network Monitoring: Why Professional Services Firms Need 24/7 Oversight

    Your network does not take nights off. Neither ...
  • code in a laptop screen

    Software Updates: When to Install, When to Wait, When to Worry

    On July 19, 2024, CrowdStrike pushed a routine ...
  • half open laptop

    Technology Transparency: Why We Don’t Hide Our Markups

    Go look up Microsoft 365 Business Basic on Micr...
  • mid year check-in

    Mid-Year IT Health Check: 10 Things Professional Services Firms Should Review Now

    Most firms set their technology priorities in J...

Archives

  • GET SOCIAL
Get Tech Support Now - (818) 584-6021 - C2 Technology Partners, Inc.

© 2016 All rights reserved.

TOP