Jul 05

Technology

Yahoo Browser Plus BrowserPlusSummary. BrowserPlus by Yahoo is a browser plugin that allows sophisticated programming on top of a simple website making it possible to launch programs written on the BrowserPlus platform. It is similar to Adobe Flash, Adobe Shockwave, and Adobe Air.

Because BrowserPlus can potentially allow access to your hard drive and other computer components, it could potentially present a security or privacy risk.

Removal Instructions. The removal instructions for BrowserPlus offered by Yahoo are incorrect, at least for anyone using Apple OS 10.6 Snow Leopard. The removal instructions offered by Yahoo state that the removal script can be found in the user’s home folder [users/yourname] under the following directory path: Applications > Yahoo! > BrowserPlus. This is incorrect.

  • Users of Snow Leopard should go to their home folder [users/yourname] and look for the removal script under this directory path: Library > Application Support > Yahoo! > BrowserPlus. This is where you will find the BrowserPlusUninstaller script. Double click on this file to remove the BrowserPlus software.

Tagged with:
Apr 26

Technology

Summary. We research and implement best practices regarding website security and stability. In addition to preventative measures, our site is scanned and monitored regularly by multiple redundant internal and external automated systems for any unauthorized content changes that may indicate the presence of malware on our site. We also scan our site manually multiple times a day and sometimes conduct non-stop visual code assessment monitoring to detect and observe malicious activity. This provides for more effective digital forensics and site hardening.

If any malware is discovered, the site is taken down immediately and restored to the most recent clean backup to reduce or eliminate the possibility harm to our site visitors.

Security Tools. For your own assurance, you can scan our site with McAfee Site AdvisorNorton Safe Web, and Sucuri.net scanning services to confirm the safety of our site. AVG AntiVirus software for Windows will evaluate sites before you visit them and warn you of sites known to contain malicious code.

For your privacy and security, we do not collect or store personal or financial information on our site. Instead we rely on trusted third-party service providers like Amazon and PayPal.

Tagged with:
Mar 22

Effective Living | Relationships | Technology

Summary. This document addresses the safety, security, and authenticity problems arising from anonymity on the Internet.

Benefits of Anonymity. Anonymity has some benefits to the individual and the community, such as:

  1. Creates a Sense of Security. Some people feel more secure when online if they can be anonymous. Concerns about stalking or unwarranted retaliation can be alleviated simply by deleting an account.
  2. Offers Privacy. People wanting to get advice in a public forum about a private issue can do so without concern of disclosing who they are, or the others involved.
  3. Promotes Freedom of Speech. People sometimes feel safer sharing their views when they are anonymous knowing that verbal retaliation or harassment can be avoided. For example, an employee will speak more honestly about their employer if they can do so anonymously. This is why employee hotlines are often made available by third party organizations that can ensure anonymity. In this regard, anonymity can create a more honest and open environment.
  4. Protects Public Image. Anonymity is nice for people concerned about saying something that could be taken out of context and used against them later.
  5. Reduces Self Consciousness. People who are shy about talking openly in front of others can join in a conversation without having any attention on them personally.

Drawbacks of Anonymity. Although there are some apparent benefits to anonymity, the benefits are outweighed and are nullified by the drawbacks of anonymity. These are some of the drawbacks of anonymity to the individual and the community.

  1. Enables Cyber Bullies and Hecklers. People with malicious intent who are bent on harassing people (sometimes at random) are given a lot of power by the ability to be anonymous.
  2. Establishes Misrepresentations. Many anonymous accounts and users are basing their involvement in the online community on a misrepresentation about who they are. It’s common for people to create a username that appears to be a real name, but in fact isn’t their real name. They may even use a photo that isn’t their own photo. Rather than disclosing up front that they aren’t who they say they are, they create an elaborate online persona. All of this is essentially based on a lie.
  3. Degrades Transparency and Authenticity. When people aren’t who they claim to be, the authenticity of the online experience is diminished. Online and offline, societies advance through transparency, openness, and cooperation. Most online services recognize this. Many online networks and websites require users and members to honestly represent who they are. Amazon offers a real name feature to ensure people are not using a fake identity (although the use of this isn’t required). Ensuring that people are who they say they are creates a genuine and authentic community of real people. Many people online are business owners and people who are already in the media or have established an authentic online presence. So, this should not be a problem. Openness and activity online should always be balanced with common sense. Networks like Ning offer online safety guidelines and member privacy controls. Many networks request users to provide honest information about where they are located (such as City and State) and why they are joining.
  4. Derails Democracy. In anonymous networks, polls, democracy, and other kinds of equality in collaborative input aren’t really feasible because a single member could create 10 or 100 user accounts, each carrying a vote. Only by having a network of real individuals can we assure one vote per person. Each online community is different, but many attempt to have authentic users with technological restraints in place to prevent abuse. For example, with YouTube, you can’t vote on (rate) your own video. Amazon allows people to write reviews and vote on ratings for their own products. However, they can’t push any reviews up the list by personally voting on them more than once. As such, Amazon is a Democracy where each person is a voting member. This is similar to a politician being able to vote for themselves, but only once. So, with YouTube and Amazon (for example) a person can only “vote” once when rating their product or other reviews. This is a technical mechanism in place to assure that people don’t just keep clicking on a button to increase their product or video rankings. With Amazon, only people who have legitimate accounts and purchases can actually write reviews. This helps further reduce misinformation.
  5. Disrupts Equality. Mixing anonymous users with transparent users is awkward (and unbalanced) because one person (the publicly open and authentic person) has a light shining in their eyes while the other person is hidden. The hidden person is at an advantage (of sorts). They can’t be held accountable. They can “shape-shift” by returning as another anonymous user later. Etiquette, respect, and civility fall by the wayside when people can hide behind a mask and say things they would never say in public.
  6. Facilitates Shared Account Use. Having a user account with high content productivity is very valuable. High ranking members typically have broader system access. So, groups of people wanting to gain greater access to an online service and greater influence on that network, can enlist many people to use the account. Keeping it anonymous makes it possible to generate numerous product reviews that would never be possible for a single person. This escalates that accounts visibility and influence. Usually, such online anonymous usernames are built-up like a brand and typically the same unique user account name can be found across multiple sites with. Hackers can sell such accounts on the black market once they are well established, or get paid for the product reviews being generated by that one account.
  7. Fosters False Sense of Community Security. The anonymity that an individual feels protects them, sets up an online world where their security, privacy, and safety are actually at risk. Most cybercrime involves people interacting with anonymous users. A person may think they are communicating with someone across the country only to later find it is an ex-parter or disgruntled neighbor. Movies like You’ve Got Mail are based on the fun and romantic premise that an anonymous person you are talking to could be watching you every day on the way to work. Well… that’s also a scary premise. For this reason, the safest online experience is to seek out online communities and exchanges that are genuine, authentic, honest, respectful and real. Such communities have checks in place to ensure that people are who they say they are, and there are measures to track and deal with those who are abusive online.
  8. Fosters False Sense of Personal Privacy and Security. For the individual, anonymity creates a false sense of security. While people may feel secure by using fake identities, their activities can be easily tracked using a variety of simple and legal methods. So, the danger of anonymity is that a person may end up feeling more free and secure in their online behavior and activity because they think they are hidden and entirely anonymous. This can result in greater erosion of their privacy and defeats the purpose of what the person hoped for in their anonymity. Off the Internet, anonymity has similar problems. When anonymous, people might do or say things that they never would do were their identity known. So, their behavior is potentially more damaging. Sometimes adolescents covertly engage in vandalism and other activities thinking they won’t get caught. These are things they would never do in public. In the digital age, there is no such thing as complete anonymity. Digital criminals, hackers, and identity thieves explore the Internet, scouring online discussion groups, chat rooms, blogs, websites, and other public data sources attempting to gain information about individuals and organizations for purposes of hacking or identity theft. Those who think they are anonymous are often revealing too much. Those wishing to protect their public image, may discover that things said anonymously in private may end up being attributed to them in public. Legally obtained public information online can easily and quickly be assembled that helps shed light on who is really behind an anonymous username. For this reason, being authentic and genuine online creates a more realistic context for people to communicate. It prevents them from saying things and revealing things they really shouldn’t.
  9. Impedes Justice. While some anonymous users engage in simply annoying behavior, other activities of anonymous users cross the line and break the law. Unfortunately, it’s quite difficult for authorities to track down someone from simply a free email account or online username. It’s easy for abusers to cover their tracks by deleting accounts. While people can be brought to justice and sued, a deleted or abandoned user account can’t.
  10. Promotes Cybercrime. Of all the stories that make it to the news about online stalkers and various kinds of online crimes, the crimes are almost always committed by an anonymous person. When you’re building an online relationship with someone anonymous, you don’t know who they really are, where they are, or what their motives are. Victims of online fraud and crime are often led to believe something false about a person’s age, gender, or place of residence. This is how their trust is built up. While anonymous online networks have some benefits, they should be approached with caution. Transparent and open networks are safer because two people can easily verify through numerous other sources the validity of the person’s identity. If someone is posing as someone they aren’t, this can easily be fact checked against the real person’s public contact information.
  11. Reduces Effectiveness. Those who want to make a point are less effective and less personable when hiding behind a mask of anonymity. If you want to be effective online, consider establishing a verifiable identity. Read more about authenticity here.
  12. Reduces Internet Stability and Security. The security of the Internet and the communities that rely on it are put at risk by the use of anonymity. Anonymity fosters spammers, trolls (people surfing the internet for personal data), stalkers, hackers, digital vandalism, bots (human created accounts that are eventually used by computer programs), rogue accounts, online digital gang wars, abandoned accounts, name squatting (people creating an online persona using someone else’s name), fake identities, identity theft, and other illegal online activity. Anonymity online is as much a security threat as anonymity in society. Identity theft and false identities are now a multi-milion-dollar crime business. States like Iowa have moved to centralized identification offices to avoid real-world trouble makers from moving about being protected and untraceable by fake identities. This is a serious homeland security issue and also a serious online issue. Many larger institutions don’t allow anonymous use of their networks. All users must positively authenticate to the system with their verifiable identification. This helps track down and bring to justice people who would misuse the Internet.
  13. Reduced Manageability. When people violate the terms of an online service, network or community, it is important to know they can be disciplined and if necessary barred from the community for the safety and stability of the community. When online communities are filled with anonymous users, it’s impossible to hold anyone accountable. Users can easily create multiple user accounts. If banned from a site, they can come back under an alternate email and username. This creates an administrative quagmire and isn’t in the best interest of the community.

Guidelines. Here are some guidelines to consider.

  1. Anonymous User Interaction Precautions. When dealing with anyone who is anonymous, do so with caution and keep exchanges to a bare minimum. Do not disclose personal information. If an anonymous person becomes abusive, stop communicating with them immediately. Be especially leery of too many personal questions from someone who is anonymous. To keep things fair and maintain equality, both parties should have equal disclosure, transparency, and authenticity. Based on the anonymous person’s online profile, postings, and other activity on the Internet, try to establish some sense of how genuine and safe they are. This can help you judge how or if you should continue communicating with them. It can also help create a context for your interactions with them. If they are lashing out at you, is there something in their profile to suggest they have a chip on their shoulder? If so, try not to take it too personally and just drop the discussion.
  2. Authentic User Interaction Precautions. When dealing with someone who appears to be genuine and authentic, still use caution unless you can validate they are who they say they are. Seek out online experiences that are genuine, authentic, and safe.
  3. Facebook. Services like Facebook offer some checks and balances to ensure people are part of a real network of individuals. Most of the time, such online communities are secure, stable, and safe. Even so, sometimes accounts are compromised by phishing emails. When this happens, a hacker (not your friend) can post links to malicious websites to your wall. Friendship requests that arrive, may appear to be from friends of your friends, but these could also be automated requests expanding the friend network of a rogue account. For this reason, always be somewhat cautious in your interactions on Facebook.

Document Background. This document is based on relatively commonplace real-life and real-world experiences over more than a decade of online computing.

* * *

Help Improve This Document. Please contact us if you notice typos or have suggestions to improve this document. Most of the content on this website reflects the feedback and input of our numerous site visitors, and we are continually making an effort to improve the quality and usefulness of our content.

Tagged with:
Feb 25

Technology

Summary. Users of Symantec (or Norton) antivirus software, such as Endpoint Security or Internet Security suite, on Apple or Windows computers may notice a slowness when trying to perform data intensive tasks, such as system backups. This can also be an issue with McAfee, Trend Micro, and Computer Associates software. Solutions are provided below for Windows and Apple users.

Windows Users. For best performance and security, consider using AVG or Avast available for free at the Download.com CNET website where they are usually found as the top two downloaded programs. You may need help removing your current Symantec / Norton software since it is very much like a virus or malware in that it is difficult to remove. For this reason, Symantec offers a software removal tool (similar to a virus removal tool) to remove their AntiVirus software.  Among Google searches for Symantec, the third most popular search is for the removal tool since many people want to remove Symantec software shortly after it’s installed. If the removal tool doesn’t work, then a manual installation is necessary. This is a very tedious and time consuming mutli-step process, but since it’s so commonly needed, Symantec has provided manual removal instructions on their website that outline the 139 steps required to remove it. Unfortunately, many viruses are immune to Symantec software and are written to not be detected by it (source), so the best virus defense is to use AVG or switch to an Apple computer since there are over 250,000 known viruses for Windows computers but only two for Apple.

Apple Users. There are over 250,000 known viruses for Windows computers but only two for Apple computers, so Apple users will likely have fewer problems with viruses. Even so, it’s helpful to use antivirus software to avoid passing on viruses to less secure Windows users. Although Symantec antivirus for Windows can be problematic, the Apple version seems to work okay. There are other Apple AntiVirus programs such as Avast or ProtectMac, but the Symantec software seems fine. Follow these instructions for installation and configuration.

1. Download. In addition to retail purchase installation from CD, your business or institution may have purchased a license for antivirus software.

For example, University of Iowa students, staff, and faculty can click here for the University of Iowa ITS antivirus download page (requires login). At the bottom of the download page, you’ll find the Symantec AntiVirus Corporate Edition for Mac. Click on the download button.

2. Install. If you download the software, double click on the downloaded dmg file to expand it. Regardless of how you obtain the software, the installation should be as follows. You will be presented with the following window.

If you need to remove a previous version of Symantec AntiVirus, you can use the Uninstall tool found in the Support folder. When ready to install the new version, double-click the Symantec AntiVirus Installer icon to begin the installation process. This will walk you through the simple installation process and, at the end, require you to logout and then login again to your user account on the Apple computer.

3. Configure. Open System Preferences (found under the Apple menu in the upper left corner of the screen). You will now see two Symantec icons in System Preferences (as shown below).

Click on Symantec Auto-Protect icon to reveal the options. You’ll see the General options first as seen below.

Click on Safe Zones to reveal the following menu.

Click on Everywhere Except In and then click Add to select your backup drive (which needs to be plugged in). Do this for other trusted storage devices such as USB memory sticks and external hard drives used for video production. Any unknown and/or unlisted drives would not be considered safe zones (and would still take a long time to eject after transferring files to them).

At this point, you should be able to backup without any slowness.

There’s only one final setting that you might want to change to make your life easier. It’s described below.

Disable Scan on Mount. By default, the Symantec software will scan every storage device you connect to your computer (such as CDs, memory sticks, hard drives), even if it has completely scanned the device recently and nothing has changed since the last scan. This can be very time consuming. It can be cancelled, but this is an nuisance. Since the antivirus software is actively blocking virus activity anyway, this is a bit unnecessary. For this reason, Symantec offers a simple way to disable this feature.

Using the new Symantec menu that is accessible at the top of your screen, navigate the menu as indicated below to find Disable Scan On Mount (under Symantec AntiVirus). This does not disable the antivirus software, it only disables the knee-jerk action of scanning every storage device plugged into the computer.

Tagged with:
Feb 19

Technology

Summary. The world’s largest data heist and hacking campaign was recently discovered and it is still underway. There are a surprisingly small number of news reports about this story so far. According to a report by PC World, the Kneber botnet virus “puts the potential threat of last year’s Conficker worm to shame.” According to an article published by InformationWeek, “this botnet makes Operation Aurora, the cyber attack directed at Google and 33 other companies last December, look insignificant.”

Overview. On 18 February 2010, a full report [PDF] published by NetWitness.com disclosed the following details about the 18-month long hacking campaign:

  • More than 75,000 computers at 2,500 companies and government agencies world-wide have been compromised
  • A single 75GB cache of data stolen over a span of just one month included 68,000 corporate login credentials as well as user login data for Facebook, Yahoo, and Hotmail. Also included were 2,000 SSL certificate files.
  • At least 196 countries have been attacked in this campaign which has been one of the broadest reaching campaigns in history encompassing numerous world languages and going beyond geo-political boundaries.
  • Seemingly independent rogue criminal hacker gangs are working together to install more than one virus per computer in an effort to ensure sustainability. If one threat is removed, the other can reinstall it.
  • There is now “evidence supporting the existence of a large and dispersed criminal enterprise.”
  • The ultimate implications of these undetected data losses and infestations of public and commercial organizations are far-reaching and complex and transcend simple labels.

“The widely deployed security technologies modern enterprises use to protect themselves such as firewalls, antivirus and intrusion detection technologies, even when well managed, are ineffective in countering the current and ongoing threat to our information systems posed by a focused criminal adversary or nation-state. … This is due to the criminal hacker element being aware of the limitations of these technologies and engineering their exploits and malware around them.” ~ NetWitness.com Report, 17 February 2010

Analysis by Operating System. Below is a chart showing the Kneber Botnet Virus attack by operating system. A simplistic analysis of this chart would suggest that XP Professional SP2 is the most vulnerable. However, the larger number of XP Professional computers hacked is simply a reflection that businesses were targeted more than home computers.

What You Can Do. Here are some suggestions for making your computing life more secure.

  1. Buy an Apple Computer. This historic data heist that impacted many businesses in 196 countries shows that even when a broad spectrum indiscriminate attack is launched, Apple computers seem to be a safer and more secure computing platform. The Kneber Botnet virus was written for Windows computers only. IT professional should consider using Apple Servers for mission critical and confidential data systems.
  2. Use an Apple iPhone. In addition to the stability and security of Apple desktop computers, the Apple iPhone is even more secure because the phone can be configured to be erased automatically after 10 failed login attempts. The phone can also be erased remotely in the event it’s lost, and the GPS system can be used to help track down the phone. Read more
  3. Use an Encrypted Database. The most secure method of storing information would be to use an encrypted database to store your financial, identity, and password information. If this encrypted database software is on an iPhone, then it provides an extra measure of security. Products such as CallPod Keeper will securely store your data, and if someone attempts to hack into the data vault, after three failed attempts the data is destroyed (so make sure you have a backup). Read more
  4. Use Different Complex Passwords. If you plan to memorize all of your passwords, you’ll probably pick a simple password (or system) and use it everywhere. The problem with this is that once a person has one password, they are, in effect, given the key to all your passwords. It’s best to use very different passwords with every system and use only complex passwords. To have 30 or 40 different complex passwords requires a data vault (as described in step #3 above). If you don’t want to spend the money on a data vault, then consider using a complex cypher code that only you know and change it frequently.
  5. Change Passwords Frequently. Your computer may be secure, but what about your bank’s computer and those used for other websites, stores, and online accounts? Hackers probably aren’t interested in accessing your home computer. What they really want is to hack into a single computer that contains hundreds or thousands of passwords. So, while the likelihood of your secured computing device getting hacked is slim, the possibility of your information being stolen from your financial institution computer is high. Changing passwords frequently ensures that once the login credentials are passed on to buyers on the black market, you will have changed the login and password by then.
  6. Key-logger Security. A key-logger system can track what you are typing. However, if your login credentials are saved (securely) and automatically entered, this will prevent a key-logger from knowing what they are. You would obviously need to do this before  having an infection.
  7. Travel Precautions. Erase your cell phone data, iPhone, and notebook prior to travel or have travel designated devices. Read more in this PDF unclassified government report.
  8. Clean System Images. Consider occasionally erasing your entire computer and restoring a known good backup image of the entire computer using software such as Acronis True Image 2010.

Video. Below is a video of Gregory Johnson discussing this security breach.

Document History. This document was first published on 20100218th1311. Additional information was added at 201018th1839. This document was updated on 20100219fr1012.

Tagged with:
Feb 09

Technology

Summary. When forwarding email newsletters and similar items, it is important to remove links from messages that may automatically give the recipient inadvertent access to your personal account with the original sender. For example, if someone who receives the email from you clicks on the one click unsubscribe button, you’ll be removed from the list. Some messages even contain an encoded link that allows you one click access to your account.

Solution. Be sure to remove all such links before clicking send. One way to ensure this is to copy and paste the article into Notepad (Windows) or Text Edit (Apple) and remove any special formatting. For Windows Notepad, formatting is removed automatically. for Apple users, click on Format > Make Plain Text from the menus in Text Edit. Then, copy the resulting text and past it into an email message. Another privacy consideration would be to remove any of the previous recipients’ email addresses.

Tagged with:
Tagged with:
Dec 16

Technology

20091215tu-adobe-acrobat-readerSummary. At the time of this report, there is currently a 0-day (zero day) vulnerability with Adobe Reader 9.2 and previous versions. A zero day vulnerability means that the virus has been discovered spreading through the Internet today, yet most anti-virus software doesn’t yet have defense against it. This virus has been reported and verified by Adobe.comSans.org, Secunia.com, and Shadowserver.org. Secunia.com has rated this virus as Extremely Critical because it has the ability to allow remote access to systems. A security alert on Adobe’s website states the following:

Adobe has confirmed a critical vulnerability in Adobe Reader and Acrobat 9.2 and earlier versions that could cause a crash and potentially allow an attacker to take control of the affected system. There are reports that this vulnerability is being actively exploited in the wild. Adobe recommends customers follow the mitigation guidance below until a patch is available. Adobe plans to make available an update to Adobe Reader and Acrobat by January 12, 2010 to resolve the issue. [source]

Security Patch. Adobe has announced that a security patch will not be available until 12 January 2010. Until then, mitigation instructions are available as a temporary manual solution.

Windows Users. It has been reported that the fast, effective and free AVG Antivirus program has been able to protect against this threat in some cases. Unfortunately, the costly and bloated Symantec, McAfee, and Trend Micro anti-virus programs are not protecting their users. As a precaution, use a program other than Adobe Reader to open PDF files. If you have the Adobe Reader plug-in for your browser, avoid clicking on PDF links until a solution is found. An alternative PDF viewer is PDF-XChange Viewer. PDF-XChange Viewer is free, and it allows for viewing, printing, and creating PDF files.

Apple Users. This may not effect most Apple computer users, since the Apple Preview program is usually set as the default program for viewing Adobe files. However, to be sure, Apple users needing to view Adobe files should right click on PDF files and use the Open With feature to choose Preview. If you’re not sure, avoid opening PDF files directly or clicking on them as web links. Choose to right-click (control click) and download first to open them in Preview.

Future Updates and Notification. According to a security alert today on the Adobe website:

This afternoon, Adobe received reports of a vulnerability in Adobe Reader and Acrobat 9.2 and earlier versions being exploited in the wild (CVE-2009-4324). We are currently investigating this issue and assessing the risk to our customers. We will provide an update as soon as we have more information. Please continue monitoring the Adobe PSIRT blog for the latest information.

Tagged with:
Nov 05

Technology

20091105th-symantec-endpoint-protectionSummary. Symantec Endpoint Security can sometimes become corrupted to the point that it produces error messages yet can’t be uninstalled automatically by Windows. Symantec is aware of this issue.

Removal Instructions. A four page fine-print manual removal procedure document is available on the Symantec website. The instructions include about 139 steps or points that need to be completed in order to remove their software. This includes searching the Windows registry to remove entries relating to Symantec.

Damage Assessment. Depending on the hourly rate paid for computer support, the cost of removal could be $100 or more. For legal reasons, it would be advisable for any retailer selling this product to include a disclaimer with the product indicating that the store is not liable for damages resulting from a corrupted installation.

Alternative Products. Because these kinds of problems are not uncommon for Symantec, McAfee, Trend Micro, and other expensive retail products, it’s difficult to know what product one should use. Fortunately, the best antivirus solution is also free. The AVG Antivirus software is the most popular downloaded antivirus software at Download.com and also the most popular program in general for all categories of Windows software downloads. With over 2.4 million downloads as of November 2009, the product is being used by millions of people. Over 19,000 people have rated the software giving it an average rating of 4 out of 5 stars. The AVG software was produced by AVG Technologies (formerly Grisoft). A paid version of AVG is also available and offers a few more features than the free product.

Tagged with:
preload preload preload