Wednesday, August 14, 2013

Peek-A-Boo. I See YOU

In case you missed it, there is a breaking story today about a family who had a webcam as the baby monitor. A hacker was able to locate the camera (easy to do), but then was able to move the camera to see around the room, and then actually spoke to the child through the camera!

For the complete story, click [here]. 

Clearly this is disturbing for a number of reasons. Not the least of which is the fact that a criminal or predator now has the ability to “see behind closed doors” and know exactly what you are doing, when you are doing it, and with whom; and, with sight and sound.

The second very disturbing aspect of this story is that the hacker could have come in through the Internet connection (in which case, he could be anywhere in the world), or he could have come in through the wireless access point (in which case, he is out front right now).

In Cyber Security, there is a technique called “war driving” where basically you drive around a neighborhood looking for any wireless signal that is not secure. It is very easy to do and most smart phones do it automatically (amazingly enough).

And, just in case you think your WAP is just too obscure to be noticed, take a look at this website at wigle.net. This site contains maps of wireless access points with accompanying information. Go to the home page, click on Web Maps and then enter in a location.  Be prepared to be amazed.

Getting back to the webcam matter, while webcams are a neat tool not only for Skype-like communications and general security, unless you secure your webcam, you are only providing access to a well-organized enemy. Check out this story by Amar Toor on The Verge about “an interactive map of insecure webcam feeds”.

Now the best part is that nearly all phones, tablets, and laptops come with camera and microphone installed. Which means that no matter where you are or what you are doing, a committed hacker can find you and activate your camera and mic.

But wait, it gets worse. As we “discovered” only last week, Federal agencies are using hacking tools to locate potential terrorists. If that is true, is it possible they would even …[fill in the blank]?

Seriously, put some electrical tape over your webcam. And if you do need a baby monitor, lock it down!




Wednesday, August 7, 2013

1 Million Malicious Apps

In case you missed it – and with all that is going on this week, it would be hard not to – a new study by Trend Micro indicates that by 2014, cyber hackers will have created more than 1 million malicious apps for the Android.

See the full story here.

This is big news for several reasons:
  1. Androids account for nearly 80% of all smart phones planet-wide. This means you,
  2.  Most smart phone owners do not even have virusprotection on their phones and they don’t come pre-installed,
  3. And yet, many people use their phones for business, banking, and other “secure” activities.

And, don't think that because you have an iPhone, you are immune to the problem. Apple wants you to think the iPhone is immune (click here), but some do not agree (click here).

See, the way that apps markets are set up for Android, Apple, and Microsoft, is that you can create any kind of app you want and post it in the market place. Maybe the app is checked and maybe it is not. Either way, most hackers know that it’s not the initial app that gets you; rather, it is the malicious app “update”. This is because most people with allow updates without even a question.

In a sense, you infect yourself. Pretty cool.


Remember, awareness is half the battle.

Monday, August 5, 2013

In Defense of "The Dive"

When it comes to recent cyber security events, these past few weeks have been most strange. It was not terribly surprising to learn that the NSA has been using hacker tools to monitor for terrorism – that was to be expected. After all, if the bad-guys can use a tool, we should be able to use the same tool.

It is also not too surprising that the NSA (and possibly others) are tracking Google searches to look for anything “suspicious”. After all, an Internet connection is not private. And as recent events in Boston have demonstrated – if the Feds know that someone has potential to do something and they don’t do something about it, things can get bleak fast.

[BTW, here is a nice link about how the CDC uses Google search trends to track influenza]

And, it is not even surprising that if someone Googles related terms, such as “backpack” and “pressure cooker”, they can expect a visit from thelocal SWAT team. Although in this case, we did learn later that the fellow did a search on “pressure cooker bombs”. That changes the story just a bit.

However, when it comes to personal security, what does make me nutz is when we do it to ourselves. A perfect example of a mental lapse is this story which broke in today’s Oregonian where the folks at Sylvan Learning Center tossed a massive amount of personal data on their clients – including social security numbers and credit card numbers – into the dumpster!! It will cost them $100k for that slip up.


Grrr. And who says “dumpster diving” is a lost art?

Monday, July 29, 2013

Is Cloud Storage Raining Your Private Medical Records?

The idea of centralized storage of private medical data is a hallmark of interoperability – or, the sharing of medical information between providers – in the new push for electronic health records (EHR) and is central to Health Informatics. However, it turns out that just because data is “in the cloud” does not mean it is safe.

It appears that cloud computing may be raining on Oregon Health and Science University (OHSU). Today we learned that “physicians-in-training” in the Plastic Surgery department, looking for a way to share medical data, put private medical information on a spread-sheet in Google Docs. (see the story here, here, and OHSU’s apology here).

Now, before we go tearing into the physicians and which is obviously a breach for otherwise crème-de-la-crème medical students, we need to consider two very critical aspects of this event. First, how our culture has grown to not only accepts but relies on mobile technology. And Second, who has access to my cloud based information.

Clearly, as the use of mobile devices has exploded onto or culture, it has become a thing upon which we not only depend, but also expect to be able to use. Unfortunately, mobile tech has become so commonplace that we are now failing to be concerned about its security. It just seems to be there, and it’s probably safe after all. In fact, had the data been de-identified (that is, all identification information removed), the whole situation would have been fine. But that was not the case as over 3,000 people are finding out this morning.

The bigger issue may indeed be the problem of access. Recent news about the government mining of Google data not withstanding (another story entirely), a larger issue is whether or not Google has the rights to “sell” your personal information to “partners and associates” (read: marketers). Here’s the rub: your medical data has value. If a certain company can direct market you for a specific product that will handle your specific condition, then your contact data is very valuable to them and they will pay good money for it. And, if you did not read the EULA (End User License Agreement) on Google Docs (and who does anyway?), you just may have given Google permission to do just that.


Here’s the lesson of the day: Just because it is on-line does not make it safe. And, before storing any data on-line, consider the impact it will have on you if it is compromised. This includes medical data, financial data, personal information, and the pictures of you at that party now on someone’s Facebook page.

Wednesday, July 10, 2013

How Texting (or email or web surfing) in Florida Can Land You In The Hootscow

"Sir! Please put DOWN that iPhone and STEP AWAY!!"

The Great State of Florida has just made computers and smart phones illegal.

Seriously: Heather Kelly of CNN reported Tuesday (http://www.cnn.com/2013/07/09/tech/gaming-gadgets/florida-slot-machine-law) that a new law was passed which makes any device which can allow gambling to be a “slot machine”. But the wording is so broad that it includes any computer of any kind on any network where gambling can occur -- to be illegal. You can’t make this up.

Of course, the Florida legislature did not intend for this. What they intended was to find a way to block computer gambling and close the internet gambling cafés. Unfortunately, the poor quality of the wording resulted in a law that if enforced would shut down the entire Floridian economy.

Pop quiz: Which “road” is paved with good intentions?

To be fair, Florida does have issues regarding gambling, and (if properly taxed and regulated) could harvest some serious income for the state. But, the level of competence exhibited here does demonstrate why it is important for all people – even politicians – to understand what technology is first before figuring out how to control it. 

There is an old business adage which goes "You cannot control what you do not measure. And, you cannot measure what you do not understand."


Perhaps the Florida legislature should take our CIS120 class. In chapter 1, we learn that there are actually many different kinds of computers.

Saturday, July 6, 2013

Yottabytes Revisited

In case you missed it, there was an interesting article published in Friday’s Oregonian by McClatchy reporter Greg Gordon on the databases that the NSA is using to record and store domestic emails and phone calls (presumably cell phones at this point). You can see the article here.

According to Gordon, the databases necessary for this amount storage are huge and he identifies one in Utah as being in “yodabytes” which he associates with Star Wars’ Yoda. Actually, it’s “yottabyte”, but either way, it truly is a lot of storage.

So… what’s a yottabyte? According to Wikipedia, it is a septillion bytes and provides us with this visual: 

To store a yottabyte on terabyte sized hard drives would require a million city block size data-centers, as big as the states of Delaware and Rhode Island. If 64 GB microSDXC cards (the most compact data storage medium available to public as of early 2013) were used instead, the total volume would be approximately 2,500,000 cubic meters, or the volume of the Great Pyramid of Giza.”

That, truly is, a lot of emails.


Wednesday, June 26, 2013

8.1 At Last

Microsoft revealed Windows 8.1 and not a moment too soon. You can read about it here and here.

The affect of the release of Windows 8, as well as Microsoft’s staunch non-allowing of earlier versions on pre-installs (software loaded into a computer before sale) has been felt world-wide. Gregg Keizer in ComputerWorld reported last April of a global downturn in PC sales between 11% and 14% (click here and here).

And while all this allows a certain “coolness” to continual Microsoft-bashing, there is another thing to consider: That possibly, just maybe, MS operating systems are actually designed to impact change in the computer industry.

Consider the following:
  • While the Graphic User Interface (GUI) was not invented by Microsoft, it was Windows 3.1.1 and especially Windows 95 that pushed us away from Command Line Interface (CLI).
  • Windows 97 is one of the reasons that DOS is emulated and programs ALL are icon driven.
  • Microsoft did not invent the Local Area network, but it was Windows 2000 that allows every computer to be a network node.
  • Windows XP impacted business globally and fought the good fight against hacker attacks and is STILL considered an excellent operating system.
  • Love it or hate it, Windows Vista was the OS that pushed manufactures to deliver multicore processors.
  • And Windows 7? I actually like this OS quite a bit.


So what about Windows 8? What is the impact that this OS is trying to have?

Certainly, PC sales are plunging worldwide and allowing for some excellent deals from tech vendors, the “blame” is more rightly placed on the consumers. We have as a whole moved into the mobile device market in a huge way. As such, the entire industry is going through an upheaval not seen since the introduction of the Personal Computer in the 70’s and 80’s.

Microsoft’s perspective is that if people are going more mobile, why not make an operating system that is very friendly to mobile devices? Then, using essentially the same structure that has been on Xbox for years, move it to the PCs. Just one problem: Laptops don’t all have touch screens. At least, not yet.

And therein lies the rub.

The backlash against Windows 8 is really not that interesting. Neither, really, is the response to that backlash with the release of 8.1. Why? It is because people hate change. And people really hate big changes. What is interesting is that Microsoft did indeed respond to a changing market environment with an operating system that can be expected to impact the direction of that market.


What else is interesting is that for the first time, Microsoft is about 3 years too late.