You might also like...

Showing posts with label Internet. Show all posts
Showing posts with label Internet. Show all posts

Thursday, January 14, 2021

Et tu, Insta?



Following my post Bye Bye Whatsapp my friend Harsha pointed out that Instagram is also owned by Facebook and has anybody read its privacy policy? 

So, I read it and Insta's data sharing is as intrusive and invasive as Whatsapp is going to have. So, for the moment, I have turned off all permissions for the insta app on my phone and the app still works. I never entered my phone number in that and they will still have my usage data but that every website and their brother do via cookies these days. 

That's where I am drawing the line for the moment. Telling you in case you didn't know that Insta can use your camera for face recognition and use it for their purposes. 

Wednesday, January 18, 2012

Stop SOPA - Freedom of speech is more important than corporate greed.


Adding my support to Wikipedia, Reddit and other sites protesting SOPA today on 18th January 2012 I have decided to add this banner to my blog as my own protest.

More information here: http://viewpointsofasagittarian.blogspot.com/2012/01/anti-sopapipa-blackout.html


Monday, January 16, 2012

Wikipedia going dark on Wednesday!



Yes, this is not a joke. In protest of the Internet censorship bill SOPA, Wikipedia community had decided to make the website offline for 24-hours. Anyone who uses the internet knows how popular and how valuable Wikipedia is when you want answers to casual questions or research queries.

If it is going to affect your work, you can take steps so you don't lose access to the massive knowledge-base. Just Google "Offline wiki" and you will find several solutions to download the entire content of the Wikipedia to your personal device. These solutions are available on various platforms from Android to Windows. I think it's a good idea to have an offline Wikipedia anyway for those moments when you are not hooked up to the internet.

More information on the link below:
http://www.theatlanticwire.com/technology/2012/01/wikipedia-go-dark-wednesday/47467/

Sign Into Your Google Account on Public Computers Without Typing Anything



This is why I love Google. Absolutely ingenious and so useful. I have just tested it, from my own computer of course, but it works like a charm. Amazing!

http://lifehacker.com/5876559/sign-into-your-google-account-on-public-computers-without-typing-anything?popular=true

Monday, November 28, 2011

Google now censoring some websites





[Photo credit: http://www.toonpool.com/cartoons/Do%20no%20evil_5798]

My outspoken disgust for Apple and iPhone does not stem from personal reasons and as such it does not stop as a particular company or product. My objection, vehement and strong objection, is against limiting the users, restricting how they can live their lives. I have never been a big fan of Flash, I have never been a Flash developer and frankly I hate those annoying Flash ads that you have to watch on some websites. But I despise that Apple should decide whether users can have Flash on their devices or not. NO! It's the user's right to decide.

So when Google starts acting like a big brother and starts with censorship, no matter how small, no matter how benign in appearance, I wouldn't stand for  it. As of now, I am looking for a new search Engine. The link below is an article that'll explain why.

http://torrentfreak.com/google-now-censors-the-pirate-bay-isohunt-4shared-and-more-111123/

Tuesday, November 22, 2011

PSA: Be Safe On The Web



This is a public service post. Recently I have realized that there has been a flood of dodgy email messages and viruses spreading through emails and Facebook etc. With more than a decade of experience in IT I have had my share of such scam/viruses/trojans and phishing emails. I have learnt from them, having fallen for some of them and then avoiding the rest. I decided to give the benefit of my experience to anyone who might need it. Right at the outset I want to declare that I am not a security expert and not a hacker, my sole qualification is my firsthand experience with such things and my commonsense which has saved me in the past.

Disclaimer: The ideas and suggestions in this post are mine, based on my own intelligence, skill and experience. They work for me. I don't know if they will work for you or whether they will be good or bad for you. Therefore, I cannot take responsibility for anything you do with them. Read the post, consider the ideas, evaluate each suggestion with your own mind then do what you think is best for you. If you follow any suggestions from this post, you take the responsibility for all results. There, that's done!

There are so many types of such malware (things that want to do harm to you or your computer) around and so many variations on each that it would need a whole book not a blog post to cover them all. Therefore, I would just focus on the things that I think will provide the most benefit to the maximum number of people. I might do supplementary posts on the same topic later.

Attack type 1: Phishing
What is Phishing?
Phishing is simply an attempt to fool a person with fake data to get him to send you his(real) data. It can be done in various ways. Some of the ways are to send a fake official email or create a fake but official looking webpage.

Examples
You receive an email that claims to be sent by the bank NatWest. It tells you that your account has some issues and you should login to your account and check the account activity or something like that.

Another example could be when you by mistake type a URL incorrectly and land on another website which is reserved to trap people who mistype a well-known website, like typing 3 O's in Yahoo.com or an extra O in google.com. The resulting page would look almost exactly like the one you were going to visit but would be fake.

There are different variations of both these approaches including combining the two.

How to recognize the fake
Even though the fakes are getting better and better, it's still possible to recognize them with a few common sense precautions.

1. Check the source of the message. If you regularly receive messages from that source that'd be one thing but if this is the first time, be extra careful. When I say "source" I don't mean just the name of the sender. Dig deeper. On the internet it's ridiculously easy to make an email appear to have come from "NatWest Customer Support" when the email address it was sent from is info@natwestphishingscam.com.
So, when you check the source, look at the actual email address. There's usually a button on most email sites to expand the "To:" field and look at the email address not just the name of the sender. If you know how to check the email headers look at them as well, they tell the real story. (It's just a question of finding the button that say something like Full Headers).

2. Read the message carefully, the spelling and grammar on these emails is usually far from perfect. It used to be terrible, like an instruction manual translated from Japanese to English but it's been getting better. Still, the language would not be as letter perfect as it would be coming from a big corporate like NatWest.

3. Do NOT click on any of the links in the email. Instead, just HOVER your mouse pointer on the link. In most web browsers when you hover your mouse over the link you'd see its target address in the status bar at the bottom of the window. Just like the email address, it's extremely simple to make a link that looks like www.natwest.com/security when it actually it goes to a totally different address that has nothing at all to do with NatWest.

4. When looking at addresses pay attention to the DOMAIN name. In http://mail.yahoo.com the domain name is yahoo.com. In http://yahoo.scam.com the domain is scam.com and has nothing to do with Yahoo. Also understand that http://www.yahoomail.com may have nothing to do with yahoo.com. The address has to be literal not just similar to the correct address. It's not very hard to create a website called www.yahoosecurity.com and make it look like it belongs to Yahoo. A real address would be more like either http://security.mail.yahoo.com OR http://www.yahoo.com/accountsecurity. Get the drift?

(And please for God's sake do NOT go to any of the fake addresses I am using as an example. Not even to the yahoo ones, I am just making them up to make a point.)

What to do
1. First thing for you to remember is that you do NOT have an account at NatWest. Just delete the email. These emails are sent en masse to a huge number of people, on the assumption that some of them will have an account with NatWest. Another similar email may be sent to another million people purporting to be from HSBC.

2. If you do happen to have an account with that bank, do NOT click on any of the links in the email. Think about whether that issue could really be true or you just used your account 2 hours ago and it was fine.

3. If you are really concerned that the problem might be real (it would seem really urgent and serious in the scam email) call the bank directly and ask them about it. Call the regular number you have called before or find it from directory assitance. Do NOT call any of the numbers in the scam email.

4. If for any reason you cannot call the bank and must use the web, do NOT click the links in the email. Instead, open a new browser window and type the bank URL yourself. And still be on the lookout for any suspicious behaviour.

5. For the second type of scam where the web page is fake, remember to type the URL correctly when it's something as important as your bank's online banking URL. Save a bookmark and use it every time if you are prone to tyop's.

6. Delete the scam email, of course. Remove it from the Trash folder as well.

Just this weekend I received an email from Homebase.co.uk that annoyed me. It said "Thank you for confirming your subscription to our weekly newsletter." That, of course, would annoy me since I didn't ask for any such subscription in the first place so how could I confirm it! I knew I would have to unsubscribe. There were a couple of helpful, conveniently-placed links in the email including an Unsubscribe link. Having never asked for this subscription, I was still suspicious although I had never had such a scam tried on me before.

I hovered my mouse over the links first and noticed that the link went to something like homebaselife.co.uk etc. etc. NOT to homebase.com or homebase.co.uk. Now, I don't KNOW of my own knowledge that homebaselife.co.uk is a bad site, but since the email pretended to be something else while being something else, I would NOT click on those links!

Trojans
What are trojans?
The term Trojan comes from the old, legendary Trojan Horse, the wooden horse which was a gift from Troy but had soldiers hidden inside. Trojans are like that as well. They claim to be some workable, usable piece of software but inside is a virus that would infect your computer and cause damage.

The software coule be as simple as a freeware photo viewing tool or as big as "MS-Office - cracked and registered". Yes, I mean illegally downloaded software from the net. No, I am not saying they are all infected, I am just saying that's how trojans are spread in the market.

How to avoid them?
1. Well, one way is to always buy software from known retailers and buy them on disks. Since disks are read-only, they cannot be infected, even if you put them inside an infected computer. That's how we reinstall Windows if a system is infected.

2. Install a good, reliable anti-virus and keep it turned on. In that case, it will catch the virus in any other software. If you try to download anti-virus from any but the authorised site, remember that it can also be infected. But there are some free anti-virus software available as well (yes, legally free), AVG and Avast are two of them. These are usually free versions of the full software which can provide you basic antivirus functionality.

3. Whatever software you download from the web, any software, scan it with your antivirus before installing it.

Keylogging
Some malware comes in the form of keyloggers. A keylogger is a little piece of software that can monitor, and store, all the keys your press on the keyboard then it can forward this data to someone else who can then have access to ALL your usernames and passwords. A really, really dangerous and damaging situation.

There is some more information on the link below about keyloggers, how they work and how to avoid being trapped by them.
http://www.securelist.com/en/analysis/204791931/Keyloggers_How_they_work_and_how_to_detect_them_Part_1

Hacking
This is a more active form of malicious behaviour and usually involves someone targeting a particular system or network actively. Although these are usually targeted at big websites and servers including industrial espionage, in some cases individual systems can be used as a victim or a pass-through. I would not go into the details of things like man-in-the-middle attack and Denial of Service attacks, but I would say that it's better to have a firewall running with all unused ports blocked. And a good, up-to-date antivirus system running.


Other threats
1. Downloading movies and videos. Some of the ways people download movies and TV shows are illegal while others are perfectly legal. I am not going to judge how people should do it, but I can give you a few hints that might be handy in any case.
When you download vidoes, be careful what other files are downloaded with the video files. AVI and JPG files are safe enough (at the time of this writing) but any other files like .htm, .html, .com, .exe, .js etc. can all be used to deliver viruses to your system. Delete these.

A really good way (for scammers) to infect your system is by including a "Media Player" software with the video. The media player will actually work but it would also infect your computer.

If the video comes with a text file of instructions and it tells you to go to a certain website, or download a certain software to play the file, do NOT do it. Simply delete the video and all the files it came with.

2. Do not click on links in emails without being extremely sure that they are legit even if the email is from someone you know.
These days there are several viruses that infect your system then send email to all the contacts in your mailbox with a link. Anyone who clicks on that link will be infected as well. And then the virus will send emails to all THEIR contacts with the link. Yes, it is like the Zombie M.O.

These emails used to be very dumb. Just a link in the otherwise blank message. So easy to spot. But these days they have become smarter. Now, there can be a paragraph of text before the link, talking about the link. At once glance it might seem like written by a human, but if you read through carefully, it's easy to spot that it's a fake.

3. An important variation on the above is an email with an attachment. These used to be dumb too, like the link emails, just an attachment with the email with no or little text in the message. Now these come with a message that describes the attachment.

The one I received 2 days ago purported to be from UPS telling me that the delivery of my package had failed, and details were in the attachment. Since I wasn't expecting any UPS delivery I deleted the email. However, if you are expecting a delivery, you can still go to the UPS website directly instead of downloading the attachment and see what it says when you enter your tracking number.

Real official emails are easy to spot if you know what to look for. For one thing, they would quote your name and order number as well as other details about your order. Secondly, the email would be formatted much more differently. Third and most important, you can hover your mouse on the links and check where it leads to BEFORE clicking it.

Best Practices
Firewalls
- Either install a firewall or at least turn on the Windows built-in Firewall.
- If you know how to do it, block all unused ports on your system by creating firewall rules.

Changing passwords
Banking websites and other security experts usually advise changing your password frequently. I don't.
I have my own philosophy about it. Again, it works for me, if you use it, it's at your own risk.
Here's my rationale behind it.
- Any time you type your password it can be captured by a keylogger.
- If the password is saved in the browser, it is encrypted and harder to get at.
- The frequent change can be useful only if you do the change very frequently, like every day. Then you have a risk of forgetting your own password or creating a pattern which can then be guessed by the hacker.

But if you use this method which I do, you need to follow some other guidelines, very, very carefully in order to stay safe.

Physical security
- NEVER, EVER leave your computer unlocked. Not even in your own home if you live with other people.
- Never write down your password. Instead use a memorable password. If you are afraid you'll forget it, write down a hint to the password but not the actual password. Write that hint in a personal code if you can.
- Guard against leaking your password by social engineering. What it means is, if you are talking to a stranger in a pub about computer security don't start giving examples of your own "very secure" passwords. Not even the process you use to derive your password.
- Use passwords that are easy to remember for you, but hard to guess for a computer. For example - "Monty Python is a hoot & and a 1/2". Still guessable but harder than the "1A82$590#" type crap that password generators spew out.

All this discussion about security has reminded me of a scene from "Enemy of the State".

Will Smith is being hounded by the FBI for reasons of their own. They are using all the technology at their disposal from tracking satellites to phone taps and physical cars on the road. Will meets Gene Hackman who knows all this security stuff. Gene gets Will to lose all his sensors that the FBI planted on him. Then he takes him with him. Gene stops at a store on the way to buy some food. Will uses the time to make a phone call to explain to his wife...never mind what. But his home phone is tapped and FBI pick up his lost trail from there.

Gene doesn't about the phone call. He takes Will to his secret hideout. It's a well-hidden cabin where Gene has no outside links, he has no phone, no power lines, he makes his own power and connects to the internet via hardware firewalls only when he needs to.

While they are talking the FBI arrive on the scene. Gene sees them via his monitoring cameras and asks Will, "What did you do?"

Will: Me? Nothing!
Gene: WHAT did you DO?
Will: I called my wife...
Gene: You idiot!

Gene takes the car and both Gene and Will get out in a hurry. Behind them Gene's cabin blows up in a big explosion. Will looks at Gene.

Will: Your cabin!
Gene: I blew it up!
Will: but..but why?
Gene looks at Will and says bitterly, "Because you made a phone call!"

The moral of the story is that it takes one leak, a single leak to ruin everything. So, don't be silly, don't make that phone call!




Tuesday, October 25, 2011

Golden Jubilee






So now I have 50 followers on this blog. Actually 51, but it took me that long to decide that I did want to comment on it. First I was thinking why make a big deal. But in fact, it IS a big deal! There are blogs that have 100s or even 1000s of followers so why is it a big deal? Well, mine is a very humble little blog. I am not a celebrity so it's not a status symbol to follow my blog, nor do I have a team that could publish 7 psots a day making it imperative that you check every 2 hours. I write about simple things and I write as and when. So each follower is someone who liked something in my blog, in what I write about or how I write about it. And that, my friends, is a warm feeling. So excuse me while I enjoy this moment! 


Essentially, all writers, including myself, write for the sheer pleasure (?) of writing. It's kind of like a disease, they can't help writing, whether anybody reads it or not. But would they continue writing if nobody ever read it? Well, Dev Anand is still making movies, isn't he? But seriously, would I continue to write, if nobody read my blog? I doubt it. 


Even though the writing habit is like a disease and I write when I think of a topic where I want to sound off it still is wonderful to get comments from the readers. To get a comment that makes me think or one that makes me want to snub the commenter (only happens if it's an Apple fanboi being himself), it is a lot of fun when the blogging is more interactive than just one-sided. 


There are several bloggers whose blogs I myself follow and admire their writing. Irfan(http://irfanurs.blogspot.com), Bikramjit (http://mannbikram.wordpress.com/) , Purba(http://purba-ray.blogspot.com), Always Happy (http://dilkibaatblogkesaath.blogspot.com/), Red Handed(http://anuglyhead.blogspot.com/), The Technical Author (http://thetechnicalauthor.blogspot.com) are just some of them. It is such a joy to be able to share ideas and interact with such people so easily because of this wonderful thing called the Internet. Did you know that the internet was originally invented for porn? No, just kidding! It might well have been though, don't you think? 


When I was a software faculty I used to give these seminars to my students, one of the topics was the internet. And one question I was always asked, "What can we do with it?" This is way back in the 1990s when the net was not so widespread, especially in India. And my answer was, "There are 3 million users on the net. What can you do if you have access to 3 million people?" And here's the answer - interact. To share ideas, to tell jokes, to regale them with the stories of your childhood, to ask advice and to bore them with your discourse on why Apple sucks. 


So, you see it IS a big deal that there are 50 people who think that my blog has what it takes to make it into their reading list. 


A big thank you to all of you! 

Tuesday, October 18, 2011

MixReq.com - Please don't get taken in


Not that you would be naive enough to be taken in by this but just to be safe I am posting this warning here.

You can read more about this on the link below. There are some good reasons to suspect that it's a fraud and the same points you should keep in mind any time you come across a website that looks like a real great opportunity.
http://ptc-investigation.com/mixreq.aspx#idc-cover

In the same article you'd see a screenshot from the mixreq.com saying, you get paid $4 for doing a survey and you can do the same survey 3 times  a day. That made me laugh. No legitimate data-collector would let you take a survey more than once. Once you fill the form, second time around you will either enter the same data or untrue data, both are useless for statistical analysis.

So, beware. Please be careful on the internet. Not everybody is as honest and truthful as you are, tread with caution!