Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Sunday, January 30, 2011

Protect Your Personal Info

We all know the need for antispy and antivirus protection for our PCs and laptops, at home and work. But most of us probably haven’t given much thought to our handheld devices, especially smartphones.

It’s scary, but the chances of getting personal information hijacked from your iPhone, Android, BlackBerry, or similar device are far greater, even if you believe the phone is turned off.

It costs only $15 for spyware purchased over the Internet to gain access to your phone and all it contains – text messages, e-mails, photographs and files; and track your location through constant GPS updates.

Your phone can even be turned into a surreptitious microphone. “When the phone is off – in a pocket, purse or on a table – it can remotely be turned on so conversations around the phone can be heard,” says Tim Wilcox, owner of International Investigators Inc., an Indianapolis security firm.

The best defense is to use a handset pass code to lock your phone and prevent others from using it, writes Sid Kirchheimer for AARP Bulletin. And never open links in e-mails sent to you by unknown parties. If you don’t recognize the person’s name or company in the e-mail address, delete it.

For complete privacy, Wilcox says, “Your best defense is to buy a $20 phone with prepaid minutes for your sensitive conversations.”

Even the most innocent of activities can put you and loved ones at risk, notes Dick Eastman, who blogs on computers and genealogy. The security gap has to do with GPS tracking.

“Pictures taken with GPS-equipped digital cameras usually embed the GPS coordinates within each picture,” Eastman says.

“Most cameras have an option to turn this capability on or off, but the default setting usually is ON. Unless you have taken action to specify otherwise, the camera probably is recording the exact location of every picture you take, plus or minus 10 feet to perhaps 50 feet.”

Eastman adds that not all digital cameras are GPS equipped although most smartphones do have both cameras and GPS capabilities. That uploaded digital photo to Facebook of your new car or your kids playing in the yard can provide exact locations.

Not convinced you might have a problem?

Security experts say millions of smartphones already may be infected with spyware, though the risk for basic “dumb” cell phones is far less.

Some Warning Signs

•Your bill may show texts to unknown phone numbers, often occurring at the same time as legitimate calls. It's at these numbers, surreptitiously called by the spyware, that someone is monitoring you.

•The battery is warm when the phone isn't in use, or it dies quickly — this may mean power is being drained by the spyware.

•Your phone flickers when not in use.


Confirming a spyware infection isn't easy. The phone needs to be sent to a lab where experts look for a few lines of identifying programming code.

“With the typical smartphone having up to 300,000 lines, it's finding a needle in a haystack,’’ says Wilcox, whose company charges $2,200 for such jobs.

What We See

WMB's advice is to educate yourself thoroughly on the features of any device you own that contains personal information and, of course, be very careful about what you upload online, especially if it involves an unprotected smartphone.

Today’s fast-evolving technology is a wonderful thing in the right hands; in the wrong hands, it can be a nightmare for unsuspecting consumers.

As the old saying goes, “An ounce of prevention is worth a pound of cure.”

Ken Cocuzzo

Thursday, June 17, 2010

Smart Grid Stuck In Slow-Go

The National Academy of Engineering just a few years ago ranked America’s electrical power grid as the greatest technological achievement of the 20th century. But this technical wonder has become antiquated, perhaps dangerously so.

As digital technology races ahead in the home, the power grid, as it is commonly known, has become stuck in a quagmire of static development. Regulations aside, power companies lack government incentives to justify research and development spending for state-of-the-art technology.

But aging technology means more blackouts, greater vulnerability to computer hackers and, perhaps worst of all, power consumption inefficiency, according to Alex Kingsbury, a U.S. News & World Report associate editor who covers national and international news with a focus on homeland security.

As part of the economic stimulus package, President Obama has pledged $3.4 billion toward development of better power grid technology. The aim is to stabilize the infrastructure in case of failure, incorporate green technology, and vastly improve efficiency.

But many experts, including N.Y. Times columnist and Pulitzer Prize winning author Thomas Friedman, whose most recent book - "Hot, Flat, and Crowded" - explains how America can lead the green revolution in the 21st century, agree it will take upward of $100 billion to achieve practical power grid goals for our country.

There are several basic building blocks of a smart grid. Currently, power plants simply provide electricity to homes. But, as part of a smart system, homes equipped with solar panels or wind turbines also are able to supply the grid. Such a system can be stable and repairable in the event of a brownout or blackout.

“In the more distant future, smart power grids may be able to coordinate the use of electricity in the home — for instance, turning on an appliance like a washing machine at a time of the day when there is ample power on the grid and prices are low,’’ says Massoud Amin, an electrical engineering professor at the University of Minnesota, credited with coining the name “smart grid.”

Waste reduction is the most important long-term objective for smart grid development. Eliminating small inefficiencies can have dramatic effects on the entire system.

The incandescent bulb is a good example. By the time the bulb is converted into light, only about 0.8 or percent of the power is used. New LED technology over the next two decades could save $265 billion or remove the need to build another 40 power plants, thereby cutting demand by more than 30 percent, according to the U.S. Department of Energy.

Other advancements can be found on the Internet. Google introduced a new product called PowerMeter which allows users to track their power consumption in near real time on their computers.

Edward Lu, a project manager at Google, says, “When consumers can see in real time how much energy they are using, they save 5 to 15 percent on their electricity use with simple behavioral changes.” The government estimates that as many as half the homes in the United States could have smart meters in the next five years.

Other problems loom and need to be addressed. Integrating more computers into the power grid brings with it the possibility of vulnerability and hacking. Experts note that some 80 percent of the electric utility companies in America are privately held and have shown little interest in investing in cyber security.

One problem was noted in 2008 when Tom Donahue, the CIA’s top cyber security analyst, unveiled information to public utility leaders that hackers had broken into one power system outside the United States. The hackers caused power outages in some 14 cities. Further, the security firm McAfee earlier this year found that over half of all power plants’ systems had been breached by hackers.

Of even more concern to national security experts are the compounding effects of a potential power grid breakdown caused by hackers.

At a major cyber war game recently held in Washington, D.C., a group of former senior government leaders, including ex-CIA chief John McLaughlin, and ex-Secretary of Homeland Security Michael Chertoff (left), found that responding to a hypothetical cyber attack against the nation’s mobile phone system was complicated exponentially when the power grid began to fail.

Amin, who leads the Minnesota Smart Grid Coalition, says the benefits of an improved power grid far outweigh potential security issues.

“Cyber security is most effective when it is responsive and flexible, which is exactly what the smart grid system will include,” he says. Only then, he continues, will the country have a grid that is worthy of the title as one of the greatest technological marvels of all time.

This post is from TechMan, WMB co-author who blogs about trends, issues and ideas affecting business, industry, technology and consumers.

Sunday, March 14, 2010

Microsoft: 800-lb Gorilla Bites PC


There’s plenty of positive to say about Microsoft’s contributions to the world: the Windows operating system, advancements in technology, and how all of it has transformed our lives and brought many of us closer than we ever thought possible.

But let’s be honest, it’s really a love-hate relationship we have with our desktops, laptops, netbooks and the rest. Why? Because like everything else human-based on the planet, the Windows operating system (aging XP probably is what most of us use to run our older PCs) is deeply flawed.

Not news you say? Sorry, you can click away but you can't hide from this corporate juggernaut and here's why.

It’s dreaded news every time Microsoft releases a security patch that forces us to make some really tough decisions. Should we allow the automatic update download and run the risk of it slowing or crashing our systems, or should we just simply ignore the old 800-pound gorilla Bill Gates fed and nurtured as a rising billionaire?

Reluctantly, you're probably better off downloading yet another patch from the Redmond, Wash.-based corporation. Ignoring security fixes really can have some unintentional but serious consequences, especially if you depend on your computer for business purposes. When was the last time you backed up your key client or customer files? Right, been meaning to get to it.

Dick Eastman, the driving force behind Eastman’s Online Genealogy Newsletter, recently explored the double-edged sword known as Microsoft, in particular the publicly-traded corporation's Internet Explorer browser (Version 8 now available for download). Eastman has considerable expertise in genealogy and computers – his experience with the latter spans more than 30 years.

“I have poked fun before at Microsoft's many security problems with Internet Explorer but this one is hilarious,'' Eastman says. "Microsoft has now issued a security advisory stating that pressing the F1 key on older versions of Windows systems running Internet Explorer can create huge problems. Hackers could use the vulnerability to take control of a user's system. The attack could come from a Web page, an HTML e-mail or an e-mail attachment, as long as Internet Explorer is used to display the file,” Eastman says.

The flaw has been found in systems running Windows 2000, Windows XP, and Windows Server 2003, according to Eastman. “Microsoft says the issue is tied to the way that Visual Basic Scripting, or VBScript -- which is used for executing functions found in Web pages -- is linked with Windows Help files.

“In the case of an attack, a victim using Windows 2000, XP, or Server 2003 would only need to visit a malicious Web site where a dialog box would be presented, enticing users to press their F1 key,’’ Eastman says. “Once the key is pressed, the system is hijacked and malware is installed on the computer.”

As Eastman notes, the problem exists only in older versions of Internet Explorer on Windows 2000, Windows XP, and Windows Server 2003. If you’re using one of these, you best be advised to visit Microsoft’s Web site and click on the menu for the proper security fixes.

Still, it’s not just MS security fixes were griping about at We Mean Business. There have been three major “service packs” for Windows XP and even downloading those presumably worthwhile upgrades have proved troublesome.

For example, many users of older computers (circa 2004-05) using Windows XP Service Pack 2 suffered total system meltdowns when they attempted to download Microsoft’s Service Pack 3.

It all came down to a few missing “drivers,” but that was never clearly explained beforehand. The “blue screen of death” gained many new victims when Service Pack 3 made the rounds, and the computer repair guys (yes, even the Geeks and Nerds) smiled all the way to the banks. Clean wipes were the order of the day (no backup? too bad, time to start fresh).

So what’s an intermediate-level PC user to do?

Educate yourself on what’s being downloaded automatically, especially if it looks vast, say four or five updates in one package. Take the time to visit Microsoft’s Web site and then decide if the update makes sense for you and your system. Weigh the risks versus the advantages.

Finally, don’t blindly download anything, even from Microsoft!

As for me, I practice what I preach at writenowworks.com.