Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Thursday, November 20, 2008

Is Your ISP Reading Your Email?

Recently I had an incident with email that got me pretty fired up.
Seems AO-Hell scans and possibly reads you emails!
I sent an email to a friend who has an email account with AO#. You know who I'm talking about.
In my email to him, I included a link to my web page. Or should I say a redirected link.
For convenience and ease I use the beam.to redirect service. Works for me and is easy to remember.

So I have this link in an email to him and send it off. Minutes later it bounces back from AO#.
In the bounce back it contains an AO# web page link as to why it was rejected.
Seems the beam.to redirection service is on their black list of banned sites due to abuse from this domain.
What! Who are they to decide what is acceptable and what isn't. I'm also a bit irritated because I now see they are scanning emails for certain words and links.

Okay! I'll fix their a$$e$. I put the original email content in a text file, wrote a new email explaining the attached text file and sent it on it's merry way. A minute later it comes bouncing back for the same reason!
Now that means they are not only scanning emails but are scanning text and document files!
This is starting to scream "Invasion of Privacy!"

Alright AO-Hell! I'm gonna beat you at this game. Insert text file in a zip file. Attach to new email message and fire it off. Guess what? Yep! You guessed it! It bounced back. Same reason! Blacklisted domain link.
But now that tells me they are unzipping archive files and scanning them.
Those Privacy screams are getting louder.

I finally re-zipped that text file but added a password to the zip file. Attached it to a new email which included the password. Guess he got it. It didn't bounce back but I also haven't gotten a reply. Maybe they forwarded it into cyberspace where it will never be seen again?

There is much of the above scenario that bothers me. First is the fact that this email service and I'm sure many others are scanning your emails for certain words or links.
I use the word 'scanning' very loosely because we don't really know if it's just a scan or if the email contains certain words or links that it isn't forwarded to a real person who then reads it.

It seems that our privacy means little in the name of safety and security.
I don't know about you, but I don't need some ISP or email service making decisions for me as to whether a link is safe or not. I don't need them censoring my personal emails or scanning for words that they deem unacceptable!

So from now on if I have any sensitive or confidential info to email or just forwarding a stinking link it will be in a password protected archive file.
Just remember that TaZMAn sent it to you and that is all you will need to know.





Take care, be aware, stay safe.

TaZMAn

Tuesday, November 11, 2008

Another New Ubuntu User

I'm still on my 100 person crusade. My goal is to convert at least 100 people over to Ubuntu. Today I didn't add another person to that list. I added a business!!!
A local home center that is owned by my relatives were having major problems with viruses and spyware in XP. More about that later.

My nephew finally had enough. He had heard me talk about Ubuntu numerous times and asked if I could convert them over. Yep! No problem. I'll be down to do it.
And today it happened.

I got there and using my flash drive, I saved their documents. Then I popped in the new Ubuntu Ibex Cd and restarted the computer. Started Ubuntu as a Live Cd and checked out the hardware. Everything was detected and worked. Also to my relief, the printer they use is an HP. Opened up Firefox and went to HP's site to make sure it was supported. Found that it had full support. Good! Now to click the install link and start the process.

The system this was being installed in to is an older Pentium (1 Gig) CPU with 512 megs of Ram and using 32 megs of shared video. Not something that would be conducive to a Vista upgrade. Besides, the idea is to have a system that is immune from spyware and viruses.

The install was painless and took about 30 minutes. Once it was fully installed and I did the customary reboot and remove the Cd I was back up to their newly installed Ubuntu desktop. And I was also starring at the Updater blaring the Updates Available message. 68 of them including a kernel update.
Clicked on it and about 25 minutes later I was restarting the computer due to the kernel update.

Now I have the full system updated and ready to go. I still have some stuff to do. Get their bookmarks into Firefox and test out the printer. Everything works and looks good. Next I install VirtualBox. Huh!??? Why???
Well one of the sites they use to submit orders requires Internet Explorer because it uses ActiveX plugins to handle the login and displaying the catalog.
Talk about a security risk! Why anyone would require ActiveX to handle passwords is beyond me.
I also believe this was one of the backdoors that caused them problems with viruses and spyware.

So I install Virtual Box and XP from the Cd that came with their system.
The PC was a local computer shop build that came with a real XP Cd. But being a custom system presented it's own problems later on. I got XP installed in Virtual Box and got online with it.

Went to HP's web site and grabbed the XP drivers for the printer. Installed them, rebooted the XP and went to test the printer.
What The!.........
No printer is found! Checking around I find that there are no system drivers installed to support the USB for the motherboard.

Motherboard. What make is it? Don't know??? Nothing that identifies it. But from Ubuntu I see the audio drivers are Alsa drivers for an SIS motherboard.
Okay. Time to run some Google searches while I'm kicking myself in the arse for not bringing along my multi-driver Cd's.

Found a likely driver candidate for the USB and popped it in. New Hardware detected.
That's a good sign. Get it installed and now have a USB bus.
It's at this point I need to mention that XP had me very annoyed. Not only did it not have drivers for the USB unlike Ubuntu but everything I installed including the printer driver required a restart!

Got the USB drivers in then had to uninstall and reinstall the printer driver which required 2 more restarts! Grumble.......
Finally I got it up and running. Set up the security in Internet Explorer and shut down XP. Then I took a snapshot of the Virtual Box XP as a way to get back to a clean slate should anything happen.

I then advised them to only use XP and IE for only that site.
That using Firefox in Ubuntu will keep them clean and secure.
The job was finished.
Ubuntu install was nothing compared to the hassles I encountered with Virtual Box.

And before anyone screams foul, I will mention right now that I am not an XP newbie. I was an XP junkie and power user. I used to hack the shell and even rebuilt the dll controlling the animation for files being transferred to the trash. My version had a stick figure guy wiping his butt with the paper then put it into the trash bin.
I know my way around XP and had been using it for years.

Today was a triumphant day due to me converting a business over to Ubuntu but was also an eye opening day. I saw Windows in all it's ugliness and all I can say is I'm glad I made the switch from it.

I'm sure they will have a few questions as they get used to Ubuntu but at least they won't be calling about virus problems. And if they do, it will be in the Virtual Box XP and that will be fixed with one or two clicks.

TaZMAn

Thursday, April 10, 2008

Idiots In Charge

There are some stories that I read and say to myself WTF!!!!
Yesterday I read one of those stories.

The character's in this story are the Federal Gov't. , Michael Chertoff Homeland Security Chief and Rod Beckstrom founder of Twiki.net

You can see where this is going already!

Seems the Fed's got a dim light bulb to illuminate the empty crevices in their head where the brain is usually found and came up with another one of their "Put massive amounts of money in your buddy's pockets!" idea.

It has finally dawned on
Michael Chertoff that a hacker attack or God forbid, a 'terrorist hijacking' (His words) of the financial systems in this country could have some dire consequences.
No Shit Sherlock! You just figure that out on your own or did you need the D.C. think tank to clue you in?

He mentions that the government can't do it on their own and is asking companies in Silicon Valley to send their brightest people to D.C. to work on the project.

Meanwhile the Fed's have set up a national cybersecurity center led by Rod Beckstrom.
Now let's get this straight.
Your setting up a national cyber security center to protect our financial institutions against an attack and your putting some guy
in charge who founded a company that provides collaboration software for businesses.

But wait! It gets better. I swear these people in charge have no clue of how the internet works or even how to use it.

Mr. Chertoff and the federal government wants to build a system to detect Internet attacks before they occur.

Hmmm........ And just how do you prevent something that hasn't happened?
Maybe you would be interested in going on a snipe hunting expedition while your at it? I can provide you with a very reasonable group rate.

Mr. Chertoff described the plan to protect the federal domain from attack as "almost like the Manhattan Project" that developed the atomic bomb.

"I do believe we have capability to detect an attack before
it's launched," Chertoff said.

Ah,Um,Er.... Mr.Chertoff, the Manhattan project dealt with designing the atomic bomb, not prevent it from being launched in an attack.

Even though much of its work is classified, one goal Mr. Chertoff could talk about is reducing the number of access points to federal systems from the "thousands" to a more manageable 50 or so.

Ever hear of a data bus bottle neck?
Can only jam so many pieces of data through a port.
Cut the access points by a percentage like your talking about and you won't have to worry about outside attacks. You will do a fine job all by yourself when no one can transmit financial data in real time.

Idiots! Plain and simple. All they worry about is how to get their buddies on the federal freeloader payroll.

TaZMAn