Wednesday, October 19, 2016

Can we please stop falling for this Facebook privacy hoax?

We've been debunking this hoax for seven years now, and here we are doing it again.

No, Facebook hasn't changed its privacy settings.
 
No, what you post doesn't belong to Facebook now. 
 
A note is doing the Facebook rounds claiming, yet again, that you need to post a legal gibberish to your status or you'll lose copyright control of your pictures and other content you share with your family and friends. 
 
Here's part of what you're supposed to post:
"The content of this profile is private and confidential information. The violation of privacy can be punished by law (UCC 1-308- 1 1 308-103 and the Rome Statute). NOTE: Facebook is now a public entity. All members must post a note like this. If you prefer, you can copy and paste this version. If you do not publish a statement at least once it will be tactically allowing the use of your photos, as well as the information contained in the profile status updates. DO NOT SHARE. Copy and paste."
 
Please. Don't.
 
We get that you don't want Facebook to own your weird bathroom selfies, but you need to stop sharing this post. 
 
It's not true. 
 
"Anyone who uses Facebook owns and controls the content and information they post, as stated in our terms. They control how that content and information is shared. That is our policy, and it always has been," Facebook said in a statement.
 
If you're still skeptical, try reading Facebook's actual terms of service....you know that contract that you blindly agree to when you sign up.

Friday, October 14, 2016

Scam of the week: Brad Pitt found dead!

The divorce between Brad Pitt and Angelina Jolie has been used by the bad guys for a "celebrity death hoax" which unfortunately is high-grade click bait.

A new celebrity death scam reared its ugly head. The bad guys claim that Brad Pitt has committed suicide because of the recent Angelina Jolie divorce. The scam is currently on Facebook but you can expect emails with links for "more details" and / or attachments that claim it is a video of his last moments. There are several versions that claim he hanged himself, died in a shooting range or from a substance overdose.

You might even get text messages to your smartphone that try to trick you into going to a site with the exclusive pictures of his death. If you see any social media posts or get emails with links or attachments, do not click on anything, do not open attachments or reply, and if it is social media, do not touch and do not share or forward. These bad guys will use anything to shock and trick you into clicking.

Do not fall for any of it! And if you do, call IES immediately at 781-816-9437 for a scan of your computer.


Above: example of the latest click bait - as seen on Facebook.

Tuesday, September 27, 2016

Yahoo hack: It's not just Verizon; AT&T customers should be worried too.

The massive hack that Yahoo disclosed last week is a headache for Verizon, the telecom giant set to take ownership of the company early next year.

Rival AT&T should be nervous too...

That's because many AT&T customers get the option to use a Yahoo Mail account to manage services like home broadband, wireless and pay-television services.

It's the outgrowth of a partnership from 15 years ago between Yahoo and AT&T (then called SBC Communications), bringing AT&T broadband customers to Yahoo's search engine and media services, including Yahoo Mail. At the time, critics hailed the deal as a landmark partnership that would better combat the growing power of AOL and Microsoft's MSN portal.

Today, AOL is part of Verizon, Microsoft's MSN is no more and AT&T likely isn't feeling so great about the deal.

Yahoo said Thursday that the hack compromised at least half a billion accounts containing user names, email addresses and passwords. That makes it the biggest attack ever. US Senator Mark Warner has asked the Securities and Exchange Commission to investigate the matter.                                    
The hack puts AT&T in an uncomfortable position. The company is still waiting for data from Yahoo on the specific customers who may have been affected, according to a person familiar with their dealings.

"We began investigating immediately and requested information from Yahoo necessary to determine which email accounts may have been compromised," the company said in a statement. "In the meantime, we are in the process of notifying potentially affected customers."

Chances are, a significant number of AT&T customers are affected.

AT&T was in the middle of breaking up with Yahoo before the attack, having announced in May that it would instead tap Synacor to handle its internet and mobile portal business.
The loss of the deal, worth an estimated $100 million a year, came at a time when chatter had heated up over potential suitors for Yahoo. AT&T was among the rumored bidders, but Verizon snagged the internet pioneer with a $4.8 billion offer.

For now, AT&T is offering little advice to its customers beyond the standard line: regularly change your passwords.

That, along with these other tips, is advice everyone should heed.

Monday, September 26, 2016

This is what you should do if your Yahoo account was hacked.

The company said on Thursday at least 500 million user accounts were affected by a massive data breach. The hack happened in 2014, when "state-sponsored actor" stole account information, including names, emails, passwords, telephone numbers and answers to some security questions.

So what should you do if you have a Yahoo account?

First and foremost, you'll want to change your password immediately. All Yahoo account holders should also change their security questions and answers.

If your account is one Yahoo suspects was compromised, you'll be prompted to enter a new password as soon as you log on. If you used the same password on other accounts, change those, too.

Here are other steps to take to secure your online accounts.

Change passwords often
Yahoo is asking anyone who hasn't changed their password since 2014 to update it. This is good advice for everyone: Passwords should be changed often. You won't always get a timely notice from a company that an account was compromised -- and sometimes it might not even know about a hack until much later. In this case, it took two years for the company to confirm the breach.

Never use the same password twice
If hackers get the password for one of your online accounts, they can try to use it to access your other accounts that take the same credentials.

Pick better passwords
Consider using a phrase instead of single words that are more easily guessed. Don't go for common phrases like cliches: Pick a combination of words that don't go together -- i.e. rather than "herecomesthesun," go for something like "waterfiresnowsunshine".

Avoid using common passwords like 1-2-3-4-5-6 or p-a-s-s-w-o-r-d, and include a mixture of numbers, letters and characters.

Use a password manager
Since strong unique passwords are a huge pain to memorize, try a password manager like 1Password or LastPass. These platforms generate and store passwords and security answers for every account you have, so you only have to remember a single master password.

Update those security questions
If you forget a password, using security questions is an easy way to gain access back into your own account -- its not like you'll ever forget your mom's maiden name. But some Yahoo security answers and questions were a part of the breach. The company has already disabled any unencrypted security answers on its accounts.

If you frequently use the same security questions and answers for other online accounts, you'll want to change those, as well. Attackers could use the information taken from Yahoo to obtain access to other online accounts that contain even more sensitive information.

Avoid choosing the obvious questions and don't provide answers that are easy to find online through Google searches or social media sites.

Be alert
The company is urging users to look through their Yahoo accounts (email, calendar, groups, etc.) for any signs of suspicious activity. Although it doesn't say what to look for, start by checking outgoing emails.

Be extra careful about clicking on links or opening downloads from unknown email addresses. If anyone emails asking for your password, it's a red flag -- even if it looks like it's coming from a legitimate place like Yahoo or a bank. Never share any account information or passwords over email.

Turn on two-factor authentication
On its own, a password isn't a strong line of defense. Adding a second type of authentication, like a one-time code sent over text message or generated by an app, can greatly secure your online accounts.

Yahoo is recommending people turn on its two-factor authentication tool: Yahoo Account Key. It even eliminates the need to memorize a Yahoo password.

If you use the Yahoo Android or iOS app, log in to your account, go to your profile and select Account Key. You can also set it up in a web browser. Each time you try to access your account, Yahoo will send a confirmation to your phone.

While it's certainly an extra step, make it a part of your daily routine. Next time there's a story about a massive data breach, you'll be glad you did.

Thursday, September 22, 2016

HP detonates its time bomb: printers stop accepting third party ink.

On September 13, owners of HP OfficeJet, OfficeJet Pro and OfficeJet Pro X began contacting third-party ink vendors by the thousand, reporting that their HP printers no longer accepted third-party ink.

The last HP printer firmware update was pushed in March 2016, and it appears that with that update (or possibly an earlier one), HP had set a time-bomb ticking in its customers' printers counting down to the date when they'd begin refusing to follow their owners' orders.

HP says that the March update's purpose was "to protect HP's innovations and intellectual property."

In 2003, Lexmark (then an IBM division) sued Static Controls, saying that the company had violated Section 1201 of the Digital Millennium Copyright Act by reverse-engineering its toner cartridges and refilling old ones that could successfully pass Lexmark's checks for valid, full cartridges.

Lexmark had an "I am empty" bit in their cartridges; when the cartridge ran out of toner, the bit flipped to "true." Even if you refilled your cartridge, your printer wouldn't use it, because it saw the cartridge as empty. Static Controls figured out how to flip that bit back to "false."

Lexmark invoked Section 1201 of the DMCA, which makes it a criminal and civil offense to bypass an "effective means of access control" for a copyrighted work. The DC Circuit court asked Lexmark which copyrighted work was being protected by its access control, and it argued that the checking routine itself was copyrighted, as well as the "Empty" bit. The court found that the DMCA could only be invoked where there was a copyrighted work apart from the access control, and that a single bit didn't qualify as a copyrightable work. Lexmark lost.

HP will likely raise similar arguments when, inevitably, its competitors start making cartridges that trick your printer into obeying you, rather than HP. But there's a potential difference between HP and Lexmark: namely that HP cartridges now have lots of copyrighted software, not just "I am empty" bits and access control systems.

This isn't just true of HP cartridges: software, and access controls that give manufacturers the legal right to reach into your home and boss you around via your gadgets, has proliferated into pacemakers, insulin pumps and implanted defibrillators; into thermostats, baby monitors, and home security systems; into cars and tractors; into voting machines and seismic dampers in skyscrapers.

One thing is for sure...if you buy ink through IES, you would not have noticed this change. We sell only certified HP branded products at a discount. Call or email us today for a quote! 781-816-9437 / estimates@iesadvisors.com

Wednesday, September 21, 2016

What to do with a wet iPhone 7.

Apple's newest smartphones, the iPhone 7 and 7 Plus, are water resistant - which means they're designed to withstand a bit of wetness but aren't meant for underwater use. They can handle being submerged under a meter of water for up to 30 minutes, but it's not officially recommended.

However, if you do get the smartphone wet by "accident," or can't resist a tiny splash test, Apple has some new advice on exactly what to do to minimize the chance of damage. Best of all, no rice is involved!

First, don't get it wet on purpose. Apple's warranty still doesn't cover water damage, and there's always a chance the phone could take in liquid. Yes, Apple will know if water was the cause of death. Buried inside the phone is a liquid contact indicator - a small sticker that changes colors if it comes into contact with water.

If it does get damp, unplug any cables and do not attempt to charge it or plug anything into the Lightning connector for at least five hours. You want the phone to be completely dry before introducing electricity. Refrain from opening the SIM tray as well, since that can give water a way into the inner workings of your iPhone.

To dry the device, wipe off the outside with a soft cloth. Stand it up and gently tap it on your hand to shake out any water that's pooled inside the Lightning port. Do not try and dry the port by probing it with a wadded up bit of paper or a Q-tip.

Next, leave it out someplace with good airflow. Don't try and speed up the process with a hair dryer. Placing it in rice won't make the process go faster, and the grain can actually damage the port. A cool fan pointed at the Lightning port is ok, but beyond that it's just a matter of patience.

The device is rated iP67, so it's built to keep out both dust and water. The 6 refers to its level of dust protection and means the phone is totally protected from dust. The 7 is how waterproof it is, out of a possible rating of 8. Be especially careful around salt water, which is more corrosive and can cause much more damage than freshwater.

Thursday, September 15, 2016

The Pokemon Go ransomware virus is out to catch’em all!

A Pokemon Go-themed ransomware virus has appeared on Windows computers, tablets and phones. The ransomware is the latest in a series of malicious applications that have popped up in the wake of the global Pokemon Go obsession.

This particular piece of malware is known as POGO Tear and it’s based on open source ransomware code called Hidden Tear. POGO Tear encrypts the files on victims’ computers, changes the extension to “.locked” and then demands a ransom on a screen emblazoned with famed character Pikachu’s picture.

POGO Tear is currently coded to display its ransom message in Arabic only as shown below. The text informs users that their data has been encrypted and instructs them to contact blackhat20152015@gmail.com to decrypt their files. It also thanks them for their generosity.


What’s interesting about this malware is that it incorporates several features not usually found in other ransomware viruses. POGO Tear creates an administrative user account called Hack3r on the victim’s machine and then hides it from the logon screen so the user can’t tell it’s there.

It also creates a network share on the victim’s computer and copies itself to all available network drives. The ransomware automatically executes when Windows starts.

If your computers have been infected with ransomware or any other viurus, call IES today at 781-816-9437. The longer you wait, the worse the situation will be!