Ahead of a court order that is still pending, Google has blocked delivery of a single email mistakenly sent to a wrong address at the request of the sender’s employer. As most of you can attest, doing something like this, while technically possible within certain parameters, is usually not done for a variety of reasons, not the least of which is opening the Pandora’s box of requests for Google to do the same thing for every email sent to the wrong address or for the wrong reasons. In this particular instance, the sender was a contractor for Goldman Sachs, and the email in question contained significant sensitive customer data sent to the wrong address. Rather than risking a signficant exposure for the customers whose data was contained in the email, on top of saving Goldman Sachs from considerable liability, Google acquiesced to the request, which normally requires a court order.
What this means for you:
The only reason this was even possible in the first place was because the unintended recipient hadn’t actually accessed the account since the email was sent, and therefore Google knew for certain that the email wouldn’t have been read, and there could be “un-sent.” You may have experienced both the relief and disappointment of attempting to “unsend” emails via your own company’s Exchange server, which can call back unread emails, but once the email has been opened by the recipient, intended or not, there’s no way to unsend it. What you should really be taking away from this was why someone was using email to send a report with such sensitive information in the first place. In this case, convenience and ease of use led to a near-catastrophic breach. Do you use email to exchange confidential information with other parties? If you do, you should carefully consider the consequences of a mis-delivered email, and what it might cost your organization.
As if having your Windows computer files and iPhone being held for ransom wasn’t bad enough, Android-based devices can now “enjoy” that ignominious fate as well. Security researchers are reporting that hundreds of Android devices, primarily in Russia and the Ukraine are being infected by a Trojan called “Pletor” which can do just like it’s Windows based counterparts: the victims were tricked into installing the trojan by fake websites, apps and games, and once the victim’s content is encrypted, the trojan demands a ransom of approximately $30-35 USD to unlock the data.
What this means for you:
Though it has happened before, it’s still extremely rare for a Trojan like the above to make it through the screening process that Google performs on all the apps that are available through the Google Play store, and even if one does, it’s pulled quickly. Google can even reach out retroactively to affected phones to remove the harmful app. That being said, it’s not hard to “side-load” apps on Android devices, which is primarily the way Android malware spreads. The easiest way to keep your Android devices safe: don’t side-load apps. Only install apps published through Google’s Play Store. Keep in mind, for everything not a Kindle Fire, installing apps from Amazon’s App Store is considered side-loading, and should only be done if you really know what you are doing. And if you just can’t live without side-loading apps, make sure you don’t store any important information on your device, and keep it well away from sensitive business data. The more risky your activities are on the device, the more likely it is that device will get compromised.
In case you were wondering where that whole “Network Neutrality” debate ended up, legislation/regulation is still being ruminated upon by the policy wonks at the FCC, Congress critters are still confused about “tubes”, but the knives have come out between content providers and ISPs. Netflix and Verizon are currently spatting over a particularly accusatory “error message” Netflix has been “testing” that shows a warning to its subscribers that Verizon’s network is too congested for them to enjoy Netflix content in HD. This, not just weeks after Google started its own page that shows you how well your ISP does when transmitting YouTube videos to you. In case you were wondering, most consumers weren’t pleased that Google & Netflix confirmed their worst suspicions: their ISP sucked when it came to watching videos, and it’s a safe bet that video watching wasn’t the only thing suffering from poor performance.
What this means for you:
Nothing as of this moment. Google and other content providers have been very vocal in the Network Neutrality debate, but when it comes to dealing with the government, “vocal” means writing a very stern letter and rounding up lobbyists to start scratching backs and/or eyes. But over here in the real world, the ringside bell just signaled another round of sparring and Netflix came out swinging. Verizon immediately lawyered up and sent its own sternly worded demand to Netflix to cease and desist, who just shrugged and said, “Hey, it was just a test. But we might be doing that again in the future. And oh, by the way, this is really your fault to begin with.” We’re fairly certain that it got a ton of attention from (allegedly) poorly served Verizon customers, who, like millions of other Americans, are basically stuck with zero choice when it comes to internet broadband. Get settled in, this is going to be a long fight, and those of us on the sidelines will probably get bloodied just as much as the titans, because, in case you hadn’t noticed, we’re all players on their gigantic chessboard.
Image courtesy of jasadaphorn / FreeDigitalPhotos.net
A secret war is being fought in the internet industry right now, but unless you are a die-hard student of all things tech, you might not even know it’s taking place. The more conspiratorial-inclined among us accuse the mainstream media of avoiding coverage of this debate because of their close ties to the opponents of net neutrality, but it’s also a very complex, “unsexy” topic that is hard to explain in easily digestible soundbites.
The principles of “network neutrality” have been the subject of hot debate for over a decade now, but as of yet, there has only been one highly publicized incident of a company actively “violating” the basic tenet of net neutrality, which is that all data on the internet should be treated equally, both in terms of accessibility (can I see it?) and how quickly it loads. For Americans, censorship is a hot-button topic, so the accessibility issue isn’t normally included in the ongoing debate. What’s at stake is whether internet service providers like Time Warner, Comcast and AT&T can charge content providers (NetFlix, Google, Spotify) more because they use so much data, and if those companies refuse to pay the premium, would their bandwidth be throttled, lowering the quality and/or value of the service itself.
Another aspect of this debate is whether the US Government (or any government, for that matter) should regulate the internet like a utility. Both sides of the net neutrality fight are of mixed opinion on this. Some argue this would encourage (enforce) competition in the ISP market, and would allow oversight into ensuring net neutrality was observed, but as many others have pointed out, this didn’t work so well for the telecomm industry the first time we tried this. The other thorny facet of this issue is the plain fact that the internet is not owned nor controlled by any one country, though it could be argued that the US holds a “majority stake” in its creation and continued wellbeing.
What this means for you:
Today, the FCC has presented a plan that many feel completely undermines network neutrality by providing a “regulated” means for ISPs to create “fast lanes” of service into which content providers may opt, and if they do not, presumably their content would be delivered via the “normal lanes”. If no one opted into the fast lanes, this would be a moot point, but as you all know, in business, those who get to the finish line first win, and everyone else, regardless of whether they finish at all, lose. Even the most altruistic of companies (Google maybe?) are willing to get their claws out when it comes to competing, and being slow on the internet is the difference between being Facebook or being MySpace.
In my opinion, network neutrality is a concept worth understanding at minimum, and if you take the long view on improving our civilization, an important principle that should be upheld. Competition is what made America great once, and it is what created the amazing technology we have now, including the internet. Creating tiers of accessibility and quality within a service that most would view as a fundamental need (if not right) might end up creating a version of the internet (at least in America – imagine the irony) that is the antithesis of internet that is spreading information, freedom and equality around the world.
Image courtesy of Stuart Miles / FreeDigitalPhotos.net
One of my favorite bits of advice regarding suspicious emails is to encourage the recipient to pick up the phone and call the company that supposedly sent the email to see if it’s legitimate. Unfortunately that advice isn’t as valuable as it once was. Cybercriminals have broadened their repetoire to include fake customer support numbers for popular internet services, such as Netflix. This particular scam relies on a very common advertising vehicle wherein companies can buy ads that look very much like the top search result in both Google and Bing searches. Potential victims, using a search engine to find the customer support number for Netflix are shown ads with fake customer support numbers, and many searchers mistake the ad for the legitimate search result. The phone call to the phoney help desk quick escalates into the customers computer being “infected” with fake viruses, and soon followed by demands for cash to clean up the compromised computer.
What this means for you:
The internet veterans among you know how to tell the advertisements from the actual search results on Google and Bing, but there are just as many who do not realize there is a difference. This particular scam counts on it, on top of victimizing people who are already in some form of technology distress. If you count yourself among the search-engine savvy, make sure you educate those close to you on how to separate the ads from the search results, as well as showing them how to find the right support phone numbers for important services they use. This may be particularly useful to aging family members who are targeted specifically because of their neophyte technology tendencies and trusting nature towards phone technicians who sound like they know what they are doing.
Image courtesy of Stuart Miles / FreeDigitalPhotos.net
Heartbleed continues its rampage across the internet. There are too many stories to tell and too little time. Read on only if you have the stomach for it.
- Networking companies Cisco and Juniper have revealed that several dozen models of their hardware devices are affected by the OpenSSL security flaw known as Heartbleed. To see if any of your networking products made this list, Cisco’s advisory can be found here, and Juniper’s here.
- Two sources close to the NSA allege that the spy agency has exploited Heartbleed since it first appeared over 2 years ago.
- Android smartphones and tablets running version 4.1.1 of the Google operating system are vulnerable to the bug. According to Google, this may affect less than 10% of all Android devices, but given that there are nearly 900 million Android OS devices, that still means millions.
- The vulnerability was used to steal 900 taxpayer ID’s from Canada’s Revenue Agency.
What this means for you:
The security implications of the Heartbleed vulnerability are staggering and very difficult to encompass. Now, more than ever, you must keep a close eye on your digital assets and accounts. Confirm with your financial institutions whether or not they were impacted by the bug (most major, commercial banking institutions did NOT use OpenSSL), and if they were, wait until they confirm that they have fixed it before changing your password. Do NOT use any software or websites confirmed to be affected by Heartbleed until they patch the bug, even to change your password. If you do this while the vulnerability still exists, there is a good possibility that hackers can actually see you changing your password and record the new one. Right now, because of the spotlight on this hole, hackers are racing to exploit the panic and confusion, and you are more likely than ever to be hacked. Wait until your websites confirm they have patched the security hole before using them to change your password.
Keep in mind that many, many organizations are still working through the impact this bug has on their technology, and many are just as confused as you might be. There will continue to be a lot of uncertainty and possible panicky responses from company representatives who are ill-informed on their company’s official stance on Heartbleed. The vulnerability affects a technology that is sophisticated and not easily explained, and not even the most eloquent among technology professionals can convey the problem and solutions in easy-to-understand terms. During these uncertain times, constant vigilance is the only weapon many of us have at the moment, so keep your eyes open and your IT consultant on speed-dial!
Unless you’ve been living under a rock for the past year, most will leap to the conclusion that I’m writing about the ongoing government snooping that seems to permeate the internet these days. Unfortunately, another of the tech industry’s dirty little secrets is being dragged out into the light of day, and it’s something you’ve probably known all along but didn’t want to acknowledge: Your email is not private. Microsoft recently underlined and highlighted this fact by releasing details on an investigation into an ex-employee’s attempt to sell confidential information. The individual in question was identify primarily through the contents of his Hotmail account, which Microsoft openly admits to reading. While this may seem to be a blatant and gross invasion of privacy (it is), it’s also well within Microsoft’s rights as outlined in the Terms of Service every single customer agrees to when creating and using the free webmail account.
What this means for you:
Before you think this is a Microsoft bashing party, Google and Yahoo have the same sort of Terms of Service, as does just about any other email provider out there. They can read your email any time they want to, and they don’t have to get a search warrant like law enforcement supposedly has to do. They own the equipment, software and data services that deliver your email, and they assert openly in the Terms of Service in one way or another that your email is not yours to keep private. You might also want to review your employer’s information security policy: it’s highly likely that they advise you that any email transmitted through their servers is company property, and is subject to review at any time. This is not something new – policies like this have been around since email first started being used in large organizations that could afford lawyers.
The only way to keep email truly private is to use end-to-end encryption, a process that most people find daunting to establish, and inconvenient to use. Until there is a radical change in how we communicate on the internet, the only way to truly keep things away from prying eyes is to not put them on the internet in the first place.
Image courtesy of Stuart Miles / FreeDigitalPhotos.net
Late last year, the Internet Corporation for Assigned Names and Numbers (ICANN) announced that they were opening up registration for more top level domains on the internet. Starting next week, the familiar “.com”, “.edu” and the other 20 well-known TLD’s maybe joined by as many as 1900 new domains over the course of the next few years. Among the first that will be released for use will be “.book”, “.bike” and “.wed” as well as specific corporate domains for large companies like “.apple”, “.google” and “.ford”.
What this means for you:
If you already work for a company with a well-established and/or well-known domain, your marketing folks (and the lawyers) may explore the new TLD’s primarily to protect the company’s brand from competitors or domain squatters. They should know that as part of the introduction of more TLD’s, ICANN has also introduced a new trademark clearinghouse where infringement challenges can be handled before the legal knives come out. If you are in the process of establishing your online identity and have been under the impression that all the “good” domain names have been taken (for TLD’s like “.com” they have, for the most part), the new TLD’s may present an opportunity for certain businesses and creative marketers.
However some industry analysts are worried that the proliferation of TLD’s may just lead to more confusion and uncertainty on the internet for the majority of users. For example, once “.google” goes live, when I want to search for something, do I go to “google.com” or “search.google” or “www.google” or “google.google”. My guess, at least with Google, all of those will work, but imagine trying to tell your grandmother the difference between them (there might be!) or why there is more than one URL, especially after you finally got her to start using Google in the first place. It’s too soon to say, but given how confusing the internet is now, one thing it’s not likely to simplify will be internet security.
Image courtesy of jscreationzs / FreeDigitalPhotos.net
Last week, Google made a change to it’s widely used webmail platform Gmail: instead of asking if you want to “show images” in emails, Gmail will automatically display them by default instead of asking permission. This particular behavior is also seen in the other two webmail titans (Yahoo and Microsoft), as well as a common feature in mail clients like Outlook. Why aren’t images loaded by default? Primarily because when you open that email full of graphics and you actually want to see them, the mail client (or webpage) makes a request to the server hosting the images, which is usually the same server that sent the email in the first place.
If that sounds like a sneaky way to confirm that you’ve opened a particular email, that’s because it is. This process reveals certain data about the recipient, including date and time of opening, what browser or mail client you are using to view the email, as well as some rough geographical data about your location, based upon your IP address. So why is Google loading images by default? It’s because now they are caching the images to their own server, and then showing them to you, which effectively acts as a proxy between you and the sender, and blinds many marketers who were relying on the image requests to track you.
What this means for you:
Whether you realized it or not, your email client’s annoying tendency to not show you images in emails was actually in your best interests. Because displaying images required you to actively “opt in” by choosing to view the graphics, if that email was sent by a marketer, you sent them a nice packet of data and a positive affirmation that you saw the email, whether you intended to or not. With Gmail’s image caching, some of that data is no longer being unwittingly sent by its customers, however, notice that I wrote “some.” The more clever marketers out there (including Mailchimp, the service I use for my own email) tag email images individually, so they can still track opens, as Gmail still has to load the image to its servers before showing it to you. In my case, this is merely so I can tell if anyone is reading my newsletters, but even that one point of data is still valuable information to email marketers, and you can bet they will find other ways to track your online activity.











