Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Friday, September 30, 2022

If you are wondering why there are so many security/PII breaches this is one

 All I wanted to do was purchase an item from the same online storefront I purchased a similar item from a few weeks ago.

During the process of 'age verification' (this time) I was again asked to provide my *actual* birthdate. This previous time I provided one that was a day or so away from my actual birthdate (for obvious security/PII reasons) as this is a third-party service, and because...WTF this is against everything I've been writing about for years since my security blog for the Concord Monitor. It's against best practices (security-wise).

As I said a few weeks ago I purchased a similar item from Arizer, and in the process used a close-but-not-exact birthdate which is typical of how I approach sites that ask for my exact age. I'm not lying in any material way that affects the purpose of the 'age verify' and I am protecting my PII. Today however was a bridge too far.

Today I was presented with a message to provide an image of my driver's license and send [it] to this 3rd-party 'service'. I started to comply but thought better of it after the first 'photo' was rejected. I called their support # but ended hanging up after I said "I'm sixty-five goddam years old" and the woman told me not to swear at her (I was holding my tongue). So I decided to send a support message to Arizer, telling them the story and voicing my opposition to this intrusive and serious Pll/security FAIL Oh, and also the fact that they'd just sold me an item without my exact birthdate and no one died, no laws were broken, my PII was kept private and we all lived quite happily after... until I wanted to spend another $150+ on their site, but this time with the [potential] added price of my PII.

After this incident I decided to do a Google search for "security question: Should I give out my birthdate to purchase something"? Take a look - 

IF there are state/federal regulations that mandate exact birthdates they need to be changed with common-sense legislation to protect citizens' PII while controlling underage persons with a different (non-invasive) method.



Saturday, August 20, 2011

The Security Consequences Of Mozilla's Rapid Release Schedule

'Mascot' image from the Mozilla ADD-ONS Blog

Continuing on a topic from my last post I want to focus on the security threat created by the 'rapid release' schedule the Firefox browser is now on.

I won't dispute the positive aspects of this move for Mozilla, however from a security standpoint it creates multiple hazards. A 'Ready or not, here we come' dictum may be OK in some cases, but it's a recipe for trouble when it comes to security.

Like it or not Mozilla bears the responsibility for not just it's browser alone, but also for taking into consideration the extended 'technosystem' of add-ons that have a somewhat symbiotic relationship with Firefox. They also have a responsibility to contribute to overall Internet security.

When so many of their users have security software that either integrates with or is a standalone 'add-on' to Firefox (and these users are to be commended for contributing to the overall security of the Internet),  rushing ahead and leaving them vulnerable is irresponsible and thoughtless.

Rushing to get something done often results in mistakes. You can rush things and get your product out first, but it rarely results in a quality product (and in this case you can add "secure" to that).

I realize that Mozilla can't simply wait until every 3rd-party piece of software is updated on their own schedule. There has to be some form of cooperative effort to find a middle ground however.

The consequences of the current situation are giving even more ground to the security threats confronting Firefox users. You wouldn't leave your children home alone (before the sitter gets there) while you go to work, and a wilderness guide wouldn't forge ahead and leave people behind to fend for themselves.... would you?

As people mature they learn to consider the consequences of their actions and hopefully become less self-centered. I realize that many businesses don't act this way, but good ones do (in varying degrees) and those get my respect (and patronage).

This world needs more cooperation not less.

Edit/add [8/20/2011 1:05 PM]:

I left out (in my haste!) the people on the security software side of the equation who need to do their part by starting their update process as soon as they can. They too have a responsibility to work in cooperation with Mozilla so both end up with a reliable product and safer users.

Wednesday, August 17, 2011

Caught In The Middle

Numerous issues are impacting me that have me caught in the middle and [nearly?] powerless to change (at least in the near-term). The first two affect many people, not just myself.

The first is the recent (and ongoing) fight over the debt ceiling and budget. I and many people like me that are living solely on their Social Security/Disability income had to wait literally until the last moment, not knowing if they could pay their bills. You know, little things like rent, utilities, food & medications..

The right-wing's lack of concern for some of the more vulnerable citizens is disheartening, and the notable favoritism shown towards the upper class and corporations combined with their manifest contempt of those in need is despicable. I want to mention that the silence ("willful ignorance"?) on this subject by vast majority of the media is disgraceful, and will be looked back on (along with many other examples) as a major failure of the Fourth Estate during this time in our nation's history. The abdication of power and responsibility by this Fourth Estate has enabled  those with selfish and dangerous ambitions to take our country in a direction far from the ideals so thoughtfully laid out by our Founding Fathers.
___________________________________________



Caught between Mozilla - Firefox and security software

Since Mozilla started it's rapid release schedule for the Firefox browser many of the security add-ons & extensions I rely on haven't been updated to work with the current version (at the time of this post Firefox 6.0 has just been released). Previously, security software companies such as AVG (LinkScanner), Symantec-Norton, M86 Security (SecureBrowsing) and others had plenty of time between 'major releases' of Firefox to update their software (so it will work with whatever changes the new version of Firefox has).

That time has been drastically cut since this 'rapid release' initiative began.

This is from the "Mozilla Firefox: Development Process" page:

"Firefox uses a schedule-driven process, where releases take place at regular intervals. That means each release happens regardless of whether a given feature is ready, and releases are not delayed to wait for a feature to stabilize. The goal of the process is to provide regular improvements to users without disrupting longer term work."

- Further down the page:

Security Releases

"This proposal makes security updates occur along with Firefox releases, meaning we'll no longer be maintaining old branches. Having security branches for each major update is untenable if we release as often as we aim to."
-----------------
Extension Compatibility 

"Extension compatibility is the trickiest part of the transition. In particular, it's not what the policy should be when a user has extensions that are incompatible with a new Firefox release. Each release will have at least 12 weeks to identify extensions that are no longer working, but this issue will be complicated."
--------------------------------------------------------------------
On the Future Release Blog there's a post named "Every Six Weeks".
"We’re studying the effects of the process carefully; it’s a big change and we will be flexible in our approach as new information comes in. We may decide that 6 weeks is the wrong interval, for instance, though it’s worth remembering that Firefox maintenance releases have been released on 6-8 week intervals for years, and sometimes included major changes. We’re also paying close attention to the impacts this cycle has on our ecosystem of add-ons, plugins, and other 3rd party software that interacts with Firefox. We’re working with large organizations, too, to understand how rapid release can fit into their software deployment systems."

"Whatever adjustments we make, it’s clear that rapid release is a major improvement in our ability to respond to the needs of our users and the web. Every 6 weeks we have a new Firefox to evaluate and, unless some surprising and irreconcilable breakage is discovered, release to the world. No one will have to wait a year for the developer scratchpad now in Beta, or the massive memory and performance improvements already on Aurora, or the slick tab management animations soon to land on Nightly. Rapid release is already paying dividends, and we’re just getting started."

Johnathan Nightingale
Director of Firefox Engineering"
-------------------------------------------------------------------------

Now as far as the security software (companies) side of things, I haven't read any comments directly from them about this issue. 
 However:
I have heard directly from M86 Security after I posted a comment on Twitter about their "SecureBrowsing" browser add-on:
---------------------------
Firefox just updated to v5. When will your plug-in be updated?
(Posted 22 Jun)
---------------------------
Their reply:
---------------------------
@TRDaggett We do not have a definitive date at this time, as we are currently reviewing Firefox 5. We'll keep you posted
(Posted 27 Jun)
---------------------------
It's now August 17th and Firefox 6.0 has now been released.... and if you go to the M86 SecureBrowsing (FAQ) page it says:
--------------------------------------------------------
5. Q: Where will SecureBrowsing work?
    A: SecureBrowsing has been designed to work on the most commonly-used Internet tools.
         The current version of M86 SecureBrowsing supports the following:

 Web Browsers:
  • Microsoft Internet Explorer 6.0, 7.0, 8.0 and 9.0
  • Mozilla Firefox 3.x and 4.0
  • Google Chrome 10
 ------------------------------------------------------
 BTW, Google Chrome's current version is 13x.
Despite the fact that @M86Security told me "We'll keep you posted", I've heard nothing from them [to date]. So if they were "reviewing Firefox 5" and still haven't gotten back to me by the release of Firefox 6..... 
Thoughts:
1.) They don't care enough about their users to (proactively) keep them informed.
2.) They're not able to keep their SecureBrowsing product updated (for 2 major browsers) in a timely manner leaving those users unprotected.
3.) M86 Security SecureBrowsing needs to append the FAQ page "Web Browser" information with a note regarding future updates to Firefox and Chrome or remove them from the list.
(Make a decision M86 Security. Then please inform your users.)
------------------------------------------
I also use the (free to Comcast Internet customers) Norton Security Suite. This version complicates the update issue even further because it's different from both Norton Internet Security and Norton 360 and [probably] has it's own 'team' of people working on it's updates (including various browser add-ons).

I noticed that if I open up the Norton interface on my desktop and click on Identity Protection [View Details] it says that Norton Safe Web and Identity Safe are both on and working!


I called the Norton Security Suite support folks today and was told that they were working on the browser compatibility updates but they wouldn't provide any time table as to when they would be released. I want to mention that the support call must have gone to India because there was a noticeable delay and the woman was very hard to understand, So the combination of those two factors made for a poor quality support call (which I have to say has not been the case with most of my previous support calls involving outsourced support centers in India). It was unfortunate that I was already irritated by several factors including the fact that this was my second call to Comcast support about this matter. The first customer tech support person tried to transfer me to Norton support but used the wrong number, aborted, came back to tell me what she did, and then on the second attempt ended up transferring me to Netgear support!
------------------------------------------------------
Finally, AVG LinkScanner (which I've used for years, since before AVG bought them out and ruined incorporated LinkScanner into their products) partially works with Firefox 6.0 but the feature that checks web [page] links and search results (like Google) hasn't been updated yet. AVG has been quite a bit quicker than Norton to update their Firefox add-ons. I can still use the AVG Toolbar to search via the AVG secure search feature or open the desktop LinkScanner interface and enter (and scan) a URL manually. It's not as convenient, but it adds a valuable security resource to my kit.
------------------------------------------------------
Conclusion: 

Mozilla's rapid release schedule has created a security issue for Firefox users who rely on various security add-ons and extensions. I'm not saying that the problem is solely because of the faster schedule though. Other security add-ons (like Giorgio Maone's "NoScript" and Wladimir Palant's "Adblock Plus" ) have kept pace, but it seems likely that the security software produced by the bigger security companies has a much different (and complicated) process that it has to go through. A good analogy is probably that of an aircraft carrier vs. a Coast Guard cutter.
As I recall after Firefox version 5.0 was released my Norton Toolbar* and IPS 'broke' and after a few weeks some protection features (like search results) were updated but the toolbar wasn't (and still hasn't been updated).

Ultimately I hope to see [at least] two things happen. Security software companies who's products integrate with Firefox (and Google Chrome) will adapt to a faster update schedule, and Mozilla will adapt their release schedule to better enable security add-on software to stay current (and 'on the job'!). Rapid release schedules are great but not if it results in leaving your users vulnerable. 
Best practices call for a 'layered' approach to security. We need to work together as much as possible to increase Internet security.


*The Norton Toolbar includes the Identity Protection features like the 'Identity Safe' that I used daily. [Among other things] It securely stored passwords for websites and automatically logged me in to those sites. It also held 'cards' that I could fill with customized identity information which in turn could be automatically entered into forms on web pages.

Tuesday, May 10, 2011

On Newspapers & Paywalls



There are some basic requirements that must be met before I'll consider paying for online news. In my case it's [specifically] the Concord Monitor.

First let me preface this by explaining that I survive solely on my disability check from Social Security each month (which hasn't increased for a year or two, and isn't likely to next year either). So every expense I incur comes out of a fixed amount. I have to consider the value of every cent spent and also weigh it against every other expenditure. And despite what the CPI* indicates, the cost of many of these are going up.

So for me to take a portion of this [shrinking] pie and spend it on the local newspaper there has to be:

1. Exclusive content that I value and is well written, informative, complete & accurate.
2. A well laid out & easy to navigate website.
3. A website that is secure and well maintained (best security practices incl. 3rd-party audits/pen testing).
4. Also a secure payment system utilizing the best security available to protect customers including full encryption of transactions and storage of customer data. Also requiring the same of 3rd-party payment processors (or *other*) are used.
5. Plenty of local content.
6. Lots of compelling photography.
7. Blogs (but EXCLUDING political** blogs!)

I'd also like to see a local 'Technology' section, possibly getting local experts to contribute regularly with advice & tips (that could even be done/sold? [tastefully] as 'Adver-Tips') and regular 'cybersecurity' information (similar to my [former] BlogsNH blog*** "TechAlert"), because caring about computer & Internet safety needs to be force-fed (subtly) to the public at every opportunity.

Finally, even though it's expensive and time consuming (and takes a certain amount of institutional intestinal fortitude), some investigative journalism would be nice to see. Frankly I see too much ...... (trying to think of the right word[s]) .. quick, superficial, non-confrontational articles, and I'm trying to recall the last time I read anything that exposed some serious wrongdoing or corruption concerning local public officials, organizations or businesses. To be fair, my memory is awful and I'm sure there have been some, but we both know the larger percentage goes unreported (and/or undiscovered).

I'm going to give the Monitor a shot and see how it goes, although I hope that I can pay 'in person' instead of online. I've been victim of numerous database breaches over the years including Concord Hospital, the VA, Student Loans, and most recently the Sony PlayStation Network (where thankfully I chose to use their prepaid cards instead of a credit/debit card). I hope they consider this option and develop a way of implementing it.


- BTW, I hope that it's only the AP [text] content the Monitor's opting not to use and not Jim Cole's outstanding photography!

_____________________________
* Consumer Price Index
** Too divisive & (many of) the regular 'article' comments are *more* than enough negativity/fringe (especially for the moderators).
*** This is the page you see if you look today.. Hey Clay, I must have missed your alert to save our blogs before they weren't available anymore? (I'm glad that I saved most of mine and didn't leave it to chance..).

Sunday, January 31, 2010

Why?


I'm talking about computer security and why some people are responsible and others not. I've written about this before, mostly in a BlogsNH/Concord Monitor Online blog called TechAlert. The reasons vary from person to person, but the two at the top of my list are laziness and apathy.

- Laziness because it takes some effort to learn how your computer works and what you need to do to protect it, and also the basic maintenance necessary to keep things like your security programs up to date. I should also add being attentive, both to how your system runs 'normally' so that you'll be alerted to events that might signal a malware infection, and also online where every web page or email could be compromised.  That's why I ended every blog post with a variation of "THINK -- BEFORE you click!"

Admittedly, nothing short of pulling the plug can guarantee you won't be hacked/infected, but that doesn't mean you shouldn't protect yourself by being informed & aware (and vigilant with a healthy dose of skepticism when it comes to unsolicited email). 

Videos or photos with "This is unbelievable!" or "You gotta see this!", and the ones about some celebrity caught naked, are typical bait to lure victims into a scammer's trap. This now includes any big celebrity (or other) news event including the recent earthquake in Haiti. If people are likely to be in a hurry to get information about a breaking event you can be sure that scammers will take advantage of the situation and use it as bait in spam email and in search engine results.
 
If an individual's security apathy just affected them it would be one thing, but it doesn't, and at some point in the future this widespread apathy will lead to something like an interruption of the power grid or air traffic control. As history has shown, often serious issues aren't addressed until after a disaster occurs. In this case I doubt anything short of prolonged widespread suffering through power/Internet outages (and intense peer pressure) will change people's behavior, and that might not be enough.. Legislation might be needed, but that will never come to pass because big business and their army of lobbyists control Congress, and requiring a license to connect a computer to the Internet would be good for overall security but bad for business. As we've seen, if Congress has a choice between what's good for the public vs what's good for big business (and the bottom line), money and influence wins most of the time.

You have to treat going online (which starts as soon as your computer connects to the Internet) like you're a spy walking through a dangerous city carrying a briefcase full of secret papers. Assume that you're being watched by people just waiting for you to make a mistake and let your guard down. Lazy or apathetic spies don't last long..

- Apathy is another shortcut to trouble. 'All I want to do is get online as fast as I can, download/watch that video, get through all this email, see that sexy pic, install this software..... All this 'security' stuff just gets in the way.'.

These two are related, and much of the time ignorance is in the mix right alongside. If you don't take the time to learn how to protect yourself, and you don't stay apprised of they daily warnings (that are freely available from people and organizations who work hard to gather and publish it) about vulnerabilities in software, hoaxes, compromised sites and other dangers, you're like a 'babe in the woods'.

The side effect of people ignoring security and getting their computers infected is that the rest of us suffer because of them. They get infected with malware that makes their computer(s) part of a huge group of computers controlled by one group of bad guys (and there are lots of these groups), who then 'rent' this powerful group of combined computers to other bad guys who can then attack banks, power companies, web sites, government computers, and the list goes on.. Sometimes they block a giant corporation's computer systems and hold it for ransom until they're paid millions of dollars. Oil companies to grocery chains secretly pay these ransoms adding millions/billions to their bottom lines, and who do you think ends up paying for it?
It's the equivalent of leaving all of your doors unlocked and your car unlocked in a parking lot with the keys on the seat, only worse.

These three traits are so prevalent that companies like Microsoft design their operating systems to cater to them and many security software companies do the same. It seems that so many people are so lazy that bothering them with anything that takes a second or two out of their precious time, or is 'too complicated', affects sales..

Think of the USA as a computer and these lazy/apathetic/ignorant people as the ones in charge of operating the government and taking care of our security, health, and safety.... 'nuff said. So to those I'm describing, wake up, grow up, get off your arses, do your part to help keep us all safer!
  -------------------------------------------------------------
Now a personal note..

Researching and writing a weekly security blog is (or was) a lot of work. When you dedicate your time and effort for the good of others you'd like to think you're making a positive difference. [I'd] like to think some people are heeding my calls for taking security more seriously and putting more effort into personal computer security awareness. Otherwise why should *I* make the effort? The responsible folks who give security the appropriate attention aren't the ones I write for (for the most part), although I did hope the security alerts I posted added some value to the readers of the Concord Monitor Online.

During the time I was actively writing the TechAlert blog I told my family (my brother and his wife & child in Florida) about it and told them to check it out. I never got any feedback good/bad about it. When asked they said they'd 'get around to it but things were hectic..'.

That was over a year (or three?) ago. Last week my niece asked me if I'd heard of something called "Internet Security 2010" and said that her mother possibly got scammed by it. I immediately recognized the typical 'generic'-type name that all the rogue (read Fake & Infected) security software programs use to fool the unaware. I did some research and found a computer help forum with specific instructions on how to remove it (and additional helpful information) then sent my niece the URL link with an offer to assist if needed. Two days later after hearing nothing I asked how it was going. My niece said the credit card company voided the transaction but the computer 'was a real mess'. To date I haven't had any request for help or advice.
A couple of things are bothersome about this.. The first thing that comes to mind is that if my sister-in-law had bothered to visit (and learn from) my blog she would have been aware of things like 'rogue security software' and hopefully not fallen for whatever scam technique she fell for. The second thing is that it doesn't appear that anything has changed despite this incident. If you don't learn how you got infected you're bound to get infected again.

Similar to STDs, if your computer habits are promiscuous and you don't know how to protect yourself you can expect trouble, and that includes infecting others. That's just plain irresponsible behavior.

So if my own family (who are otherwise highly intelligent people) don't bother to take my advice...........
Am I just wasting my time?
  --------------------------------------------------------

Please don't be part of the problem. Help be part of the solution.
And remember....
Always THINK before you click!

Thursday, January 31, 2008

Something's Different

Yes, I finally changed over to the new template. I decided to mirror my other blog's appearance. As I find the time I'll add more links and some different page elements.

I've been trying to concentrate on my BlogsNH blog "TechAlert", and I've got a new post there called "Parents And Kids 'Growing Up Online'". If you haven't seen the PBS - Frontline program "Growing Up Online" you should, especially if you have kids still in school.

I've been concentrating on computer security and other tech-related stuff lately and avoiding politics as much as I can, so that's one of the main reasons the posts here have been sparse.
One of the other reasons is the topic of my latest post over at The Endicott Dispatch.

The nature of campaign politics and the way it being covered by most of the media turns me off.
I'm counting the days until this group of criminals is out of the White House and we can start to repair the damage they've done.

As that time gets closer I'll have more to say. In the mean time, my posts here might change from the political rants to other topics...Inside Tom's Brain.