Search This Blog

Showing posts with label Marketplace Tech Report. Show all posts
Showing posts with label Marketplace Tech Report. Show all posts

Wednesday, May 22, 2013

Spear Phishing

Marketplace Tech Report ran a story today about the detection of  renewed cyber attacks by the Chinese military against United States government and corporations.  These attacks resumed after a three-month lull.  Earlier this year such attacks drew much publicity, particularly after the Chinese tried to hack into not only American government computers but also major American media computers.

The Marketplace Tech story, however, focused on "spear-phishing", a hacking technique used to gather personal password and gain access to private information.  It involves targeting individuals by email.

Chester Wisniewski, a computer security expert with Sophos and a frequent contributor to Marketplace Tech reports, explained:
 When somebody singles you out as an individual to target with an attack, we call it "spear phishing". They find some way of convincing you that they are the target brand and get you to type in your password and give it to them.
You may have seen email like this, even if you have a spam filter.  I poses as a message from a legitimate website, like your bank or credit card company, saying that a security issue has arisen or a major purchase has been made.  It then directs you to click on an embedded link to obtain more information or contact the company.

This may be easy to spot if you do not have an account with the bank or credit card company, but the email is designed to play on our temptation to contact someone immediately to find out if there is a problem or if someone has used our identity to make purchases on our accounts.  It is playing on our own insecurities in the digital age and our desire to correct things immediately.

If you get an email like this, DO NOT CLICK ON ANY LINK WITHIN IT.  If possible do not open the email; view it in a viewer or reader before opening or scan it with a security program.  The embedded links take you to a website that looks like a real bank or business site, but is designed to get you to enter your username and password.  If you do, YOU have been SPEARED.  The bad guys now have your username and password and can start creating real mayhem with them.

If you want to contact legitimate site for this type of email, do it by going to the site using your computer browser and typing in the URL for the site (or looking up customer service for the company online and going to the site).  Or, call the company.  Remember that the customer service contact information for credit card companies and banks is usually on the back of their credit or debit card.   Do not use the links in the email!

And to end with a final reminder:  change or otherwise secure your user names and passwords!  If you have a lot of them, try using a computer service like Last Pass to keep track of them for you and help you change them frequently. 

Monday, April 1, 2013

Spring 2013 - Faces, Conversations, Cyber Footprints & Maps

I missed an installment last fall, so some I am reaching back a bit to cover things that I notice at the end of last year and then moving forward into this year:

I've Just Seen A Face

One of my favorite ways to keep up with technology is to listen to the daily podcast from Marketplace Tech Report.  Back in October they ran an interesting story about facial recognition scanning at a shopping mall in South Korea.
This new commercial application of face-recognition technology combines digital photography with computer search algorithms.  A digital camera captures a photograph of your face as you walk by and the search engine searches for your image on the various databases, including social media, like Facebook and Google+ or new photographic social applications such as Instagram.  The objective is to identify the individual in the original image and any associated data available for that person.  Put  more simply, the objective is to cash in on your identity.

In this context, identity means facts about you that people will pay money to know.  Who would pay for this information?  People who want to use those facts to sell you something.  Follow the money.

Thus, the Korean shopping mall installed these facial recognition kiosks.  After capturing and searching a person's image, there follows an instantaneously display advertising directed specifically to person's interests when matched to the products sold at the mall.  The technology matches a person's likely shopping interests with the retailers located in the mall.  If you like the books, it could display an ad for mall's bookstore (if there still is one in the mall).  If the search finds that you have an interest in outdoor activities, it may display on ad for sporting goods or outdoor activities store.  If a birthday or anniversary is coming up in your family, it could display gift suggestions -- jewelry, ties, toys.

The facial recognition technology is out there, although you may think it exists only in movies or with secret government anti-terrorist squads.  And, you may doubt that you put this kind of bankable personal information out there to be found by an search engine.

Maybe that is true.  Maybe if you are Luddite who lives off the grid (and therefore are unlikely to be walking into a shopping mall in any event).  True, there are some out there who have resisted the temptation of Facebook or Twitter or Google+ or Instagram, etc.  But there are millions upon millions out there using social media.  And, what about LinkedIn?  Or, does your firm or business have a website with your picture and profile on it?  What about your children? Have they "tagged" you in photographs that they posted on Facebook?  Or perhaps your loving parents are on Facebook and have posted some of their family pictures?

It is not easy to remain obscure and faceless these days.  You may be surprised to find out what information about you is out there.  Search engines are able to search it and advertisers are able to use those searches to identify you and your likes.  How do you think Google makes its money?  It is not a non-profit.  The information that you search for through Google reveals your interests and Google channels search results and advertisements to your search result page based on those interests.  So do not be surprised if you walk into a mall or shopping center in the near future and find a kiosk flashing pictures of products directed specifically to your attention.

Big Brother Part I

The Baltimore Sun reported last fall that the Mass Transit Administration (MTA) has been eavesdropping on its drivers and passengers.  The stated purpose is to achieve greater security and safety on public transportation.  The MTA believes that this technology will aid in investigating crimes on public transportation.

"We want to make sure people feel safe, and this builds up our arsenal of tools to keep our patrons safe," said Ralign Wells, MTA administrator. "The audio completes the information package for investigators and responders."

Of course, this is often the stated goal of surveillance of all kinds.  The legal issues with other types of surveillance also are engaged here:  privacy and possible misuse of information.  Arguably, privacy is addressed by the fact that this is public transportation, so there should be no expectation of privacy.  In application, however, it may not be so clear.

More of a concern, however, is what the MTA does with the information that it gathers.  Much of it will have nothing to do with a crime, intended or perpetrated.  Much of it may be everyday conversation about mundane affairs.  Somewhere in the middle, however, is likely to be information of a sensitive nature, something that people did not intend to be public knowledge.  What if the conversation has nothing to do with safety on the MTA, but does involve criminal activity elsewhere?  What if it deals with something very personal to the passenger or driver, something that they may have told another in confidence, but now finds its way into the MTA surveillance database?

Buses have had surveillance cameras for years.  Voice recording microphones are now being incorporated.  Signage on the business lets drivers and passengers know.

The State's Attorney Office thinks that the system passes legal muster.  The ACLU disagrees:

"People don't want or need to have their private conversations recorded by MTA as a condition of riding a bus," said David Rocah, a staff attorney with the Maryland chapter of the ACLU. "A significant number of people have no viable alternative to riding a bus, and they should not be forced to give up their privacy rights."

State legislators have indicated that they will look at this issue.  Next, time you ride the MTA, be careful what you say and do.

Big Brother II

If you are worried that the MTA is listening to your conversations on the bus, you have some sympathy for what happened to General David H.Patraeus, who resigned last year as Director of the CIA after disclosure of an extra-marital affair.  The extra-marital affair part is certainly scandalous enough, but what maybe more shocking is how Patraeus was undone by a series of events when law enforcement and government investigators looked into his activity in cyberspace.  The New York Times covered the details in a News Analysis piece last November.  The Times correctly noted that cyberspace investigations can rapidly escalate far beyond their original, often limited, scope simply because of the wealth of information that is exposed by even a relatively focused inquiry.  All of the data and information that we have sitting on our computers and online suddenly may fall under the eyes of investigators looking for something entirely different.  The Times article notes that the ACLU seems to be lamenting Patraeus undoing, at least as to the investigate methods used and the privacy rights trampled (if not an endorsement of Patraeus himself, with whom the the ACLU may have other concerns).  It is also highly ironic that America's spy chief (the Director of the Central Intelligence Agency) was undone by cyber investigators combing through his email.  Perhaps, as the Times notes, it is better that our law enforcement folks caught up with Patraeus before another country's spies did.

Lost

Since passing of Steve Jobs, Apple has moved forward under new leadership.  No doubt some new Apple developments were in the pipeline before Jobs died and he had some degree of influence and role in the decision making.  I doubt, however, that he would have approved of the launch of the Apple Maps application.

This is old news now for many of us who have Apple devices and for those you follow Apple's latest product changes and development.  For those who need a quick summary, last year Apple launched a new version of its operating system for iPods, iPhones and iPads, designated iOS 6.0.  This new operating system brought may improvements to Apple mobile devices.  It also brought a significant change is a key default application that Apple installs in all its devices.

When you get a new iPod, iPhone or iPad now, it comes with these native applications pre-installed.  They include basic Apple apps for email, text messaging, the Apple App store, contacts, and now Apple's application for finding places and getting directions, simple called Maps.

Until iOS 6.0, Apple had used Google Maps as its native geographic application.  Each of these applications has several basic functions: looking up addresses or points of interest, in your locality or around the world and displaying them on a map; using Geo-positioning software ("GPS") in the device to coordinate with your current location and provide a set of directions to your destination.  The new generation of these applications competes directly with commercial GPS devices by adding a voice-over that narrates step by step instructions for reaching you destination.

The Google Maps mobile application came with a long track record of success behind it from similar software on Google's website.  Many people (including me) loved Google Maps online and loved its mobile app on devices.

Apple, however, had a kind of love/hate relationship with the Google Maps app.  It was a wonderful addition to the native applications that came with your Apple device, but Google was competing with Apple in the mobile device arena by developing and promoting its operating system for Android  mobile devices.

So Apple began the development process to replace Google Maps on its devices with a native Apple Maps app.  Apple even went so far as to eliminate the choice to use Goggle Maps.  Everyone knew this was coming, including Google.  It was no surprise that Apple wanted to do this.  The surprise came in how poorly Apple Maps performed its basic function, finding where you are and where want to go.

Apple's interface for its Maps app is somewhat different from the Google Maps app that customers knew and loved.  Arguably, Apple made some improvements in the interface, which is somewhat easier to read and use, particularly if you are driving and trying to follow the directions, either visually or audibly.  Apple also took advantage of its Siri voice feature to give verbal versions of your directions.

The problem, however, is that very often the directions that Apple Maps provides are wrong.  Within days of the release of iOS 6.0, commentary in print and cyberspace was buzzing with complaints and examples of how faulty the Apple search results were.  One example sticks clearly in my mind.  The Apple Maps misplaced an Apple store in a major U.S. city, putting in on the wrong side of the street.

Here is my own personal comparison.  By chance, before in downloaded iOS 6.0 on my iPhone, I took a trip to Maine with my wife to attend a wedding and then vacation and site see, as we had never been to Maine before.  As we were renting a car, we took along a GPS and we had our iPhones.  It turned out that the GPS was set on a "minimalist" setting for verbal directions and did not update you frequently with repetitive step by step instructions.  Instead, it would remain silent for long periods and then suddenly announced "In 200 feet, turn right".  As we had borrowed the GPS, neither my wife or I wanted to changes the settings, least we forgot to set them back (or forgot how to set them back) when we returned it.

So we followed the maps on the GPS, but I also used my iPhone and the Google Maps app to locate our designation and directions, so we could anticipate where we were going.  The Google Maps app did not replace the GPS, but it was unfailingly correct in determining our destination and plotting us a course that led exactly to the place were were going.  We used this repeatedly all over Maine and into Canada without an error.

When we returned home, I downloaded iOS 6.0 with the Apple Maps app.  In its initial performance, it was batting about .250.  It can get you to the general vicinity of your destination, but it errs frequently when it tries to close in on the exact location.  And the errors can be somewhat dangerous.

Here is the most egregious example.  I was going to a client's house for a meeting.  I had not been in several years, so I put the address into my iPhone and Apple Maps provided a set of directions.  All was fine until I was nearly at the client's home.  Apple Maps indicated that I should make a left turn onto the client's street from the road on which I was traveling.  I slowed down looking for the left turn, but did not see it.  I reached another street that looked familiar, but it was not the client's street.  The app said that I had passed the client's street, so I turned around and back tracked, still looking for the client's street, now on the right.  No turn appeared.  I reversed direction again.  No luck.  I finally turned down the road that looked familiar and found the client's street about a quarter mile down this road, which was not in Apple Maps directions.

When I finished my meeting, I went down the client's street a little further in the direction of the main road, looking again for the intersection where I was supposed to turn.  All I found was a dead-end.  The client's street did not intersect the road that the Apple app said it did.

Apple finally had to make a public apology for these glaring defects in its search functions and mapping directions.  It scrambled to improve Apple Maps, with some success.  More recently, Apple finally conceded and brought back the new and improved free Google Maps application on the Apple platform.  I recently used both Apple Maps and Google Maps on another trip to new places, this time Southern California, sometimes using them simultaneously. Apple Maps is greatly improved and I will concede that I am not as familiar with it, as I have gone back to Google Maps since it became available.  Still, I would give Google Maps a higher rating.

Many people said that this would have never happened if Steve Jobs was still around.  May be so.  This was a major embarrassment for Apple and at least one key Apple executive responsible for the Apple Maps launch departed Apple in the wake of its rudderless debut.  Apple has fixed Apple Maps and it is a more respectable piece of software now.  But Apple also had to concede a place to Google Maps in the Apple Apps Store and on Apple devices.  In the end that was probably better that than have users defect to Android phones to find there way to destinations new and old.

Tuesday, May 1, 2012

Piracy, Privacy and Money, Money, Money - Part II


This is the second in a series.

PRIVACY

I have written here before about privacy and likely will again.  It has been an important area of  American constitutional law since the drafting of the Bill of Rights.  Since that day when Alexander Graham Bell summoned Watson with words spoken over his telephonic invention, we have becoming increasing concerned with protecting various forms of telephonic and electronic communication.

In January, the U.S. Supreme Court unanimously ruled United States v. Jones that the government needs to obtain a search warrant to track the public movements of a person by attaching a GPS device to the person's vehicle.  Antoine Jones was a suspected drug dealer who lived in DC.  Authorities had a warrant for Jones in the District of Columbia and attached a GPS device to his car to follow his movements.  Information on Jones' movements in Maryland was collected, however, and authorities had failed to get a warrant in Maryland. The Court split 5-4 on how the 4th Amendment applied in this situation.  Here is a link to a further discussion of the case at Marketplace Tech Report

The  Jones decision may become landmark of constitutional law.  It certainly will be important in understanding the current interface between technology and privacy.  We have seen societal situations that raise significant questions in this area. In recent political movements from the "Arab Spring" to the "Occupy" movement, electronic means of communication such as Twitter and Facebook have been used to organize protest. In response, Arab governments first tried to shut down these communications.  More recently, and more ominously, governments have been monitoring these communications in order to find dissidents and suppress protest.

The Jones case may begin to tell us where constitution protections attach in a world where we are revealing more and more about ourselves through electronic communications.  Consider, however, that we now reveal a great deal of information about ourselves willingly on Facebook and Twitter and other social networking services.  If Antonie Jones had been checking in on Facebook or FourSquare, would government monitoring of his postings and travels been protected?

One important question continues to be what expectation of privacy we have when we use such social networking services.  When people sign-up for these services, they must agree to contractual agreements that provide the terms under which the service is provided.  These terms of service agreement set out important legal rights to material posted and privacy policies.

Of note recently is that both Google and (yet again) Facebook have changed their privacy policies.  These changes have received wide publicity. As we provide more and more personal information on such services, including using such services to reach  or interact with others online destinations, these policies are very important to our online privacy.  These policies, however, are not really intended to protect our privacy as much as they are to govern what information Google or Facebook or other service providers can access and use for their own business purposes.
Remember that Google, Facebook and other online services are businesses looking to make a profit. 
These social networks want you to post personal information on their services.  Such sharing is fundamental to the business model on which such services are built.  The information that you share encourages your friends to join to see your posts and to share their own information.  This cycle brings more and more people onto the network.  Participants keep the treadmill of information spinning round and round by providing the product for the social network.  In one way or another, good Internet businesses use our information and usage history to make money.

Not only are the users the product, but they are also a potential customer. Let's take a look at a simple scenario.  You go to Google and search for information on the book, "The Devil and the White City".  You find links to various bookseller's sites and go to them.  Google now knows that you may be interested in books, even the type of book, and can place paid advertising for a booksellers on your search pages.  Or you go to Amazon and buy the book.  Amazon knows that you purchased this book and will recommend similar books to you in the future when you visit Amazon.

In one sense this is good for you.  You may get "better" search results or better service, because the search engine or the vendor knows something more about our preferences.  This is certainly a critical element that makes such services "smarter" and, thus, faster in getting us to the things we are trying to find.  What you may not realize, however, is that your activities are leaving behind a kind of electronic footprints or fingerprints, showing where you have been on the Internet and what you have been viewing.

Technologically, much of this deals with little pieces of code called "cookies" that you leave behind in your travels in cyberspace.  These markers allow sites to recognize you next time you visit and improve your use of sites, but they are digital signposts as to where you have been and what you have seen or done.

Do we want this kind of information available?  If we do, to whom -- Google? Facebook? Amazon? The government?  What limits are there?  Privacy policies and terms of service are designed to protect this information from general dissemination.

There is a conflict of interest, however, because most commercial sites want to use such information to target you for advertising or products when you use the sites.  Such sites do not want to give up the use of such information entirely, because it would mean cut off a significant source of their revenue and profit -- advertising or sales.  Once the site has the information, however, when should it be made available beyond the reach of the terms of service to which you agreed?

These are important societal questions deeply embedded in the technology that we use today.  It will not be easy to draw lines here, especially because of the money involved.  More on the money in the final post in this series.


Friday, February 17, 2012

Piracy, Privacy, and Money, Money, Money! - Part I

This post is the first part of a round-up of significant developments in 2012.

Piracy

"Well, yes mate. See, I’m dishonest. And a dishonest man you can always trust to be dishonest. Honestly. It’s the honest ones you need to watch out for, because you never know when they’re going to do something incredibly… stupid."  Captain Jack Sparrow (IMDb Link; captainjackblog.com Link)
In January, the Justice Department took down one of the largest file sharing services on the Internet, Megaupload, for alleged piracy of copyrighted material.  The colorful cast of characters involved in Megaupload will guarantee a forthcoming movie to rival Social Network.  You can read more details, including endorsements of Megaupload by celebrities, its purported rapper CEO, and its founder Kim Dotcom and his $6 million worth of automobiles in these linked reports from Marketplace Tech Report and The New York Times.

Here is what I find interesting about this story:
  • There seems to be little dispute that Megaupload was trafficking illegally in copyrighted material.
  • Megaupload was wildly popular, being ranked in the top 20 of Internet sites.
  • The Justice Department had to reach across the waters to take down Megaupload, which is based outside the United States, and to arrest some of the indicted principals.  Kim Dotcom (a.k.a. Kim Schmitz) was living in New Zealand.
  • The Justice Department’s action prompted a retaliatory protest from Anonymous, a loosely organized group of Internet hackers (more on which can be found at this NYT link).  In what the Times called "digital Molotov cocktails," Anonymous appears to have launched digital denial of service attacks on computers at the Justice Department and major entertainment companies as protest over the shutdown of Megaupload.
  • The scope of action taken by the Justice Department is significant.  The Times reported:
As part of the crackdown, more than 20 search warrants were executed in the United States and in eight other countries.  About $50 million in assets were also seized, as well as a number of servers and 18 domain names that formed Megaupload’s network of file-sharing sites. 
Concurrent with the Megaupload take-down, Congressional consideration of legislation to stop Internet piracy came under attack from major Internet players.  Two bills were before Congress: the Stop Online Piracy Act, or SOPA, in the House, and the Protect Intellectual Property Act, or PIPA, in the Senate.  The day before the Megaupload take-down, major Internet sites such Wikipedia and Google launched campaigns in opposition to the legislation, arguing that it would result in serious impairment on the freedom to share information on the Internet.  Wikipedia actually "went dark" for a day, taking down access to its site, one of the most widely used on the Internet, and posting instead a message to users who accessed the site asking them to oppose legislation and to contact their representatives in Congress to pass the message along.

The SOPA/PIPA protest is notable for several reasons.  It marks an historic moment when Internet giants like Google and Wikipedia set aside commercial and competitive differences and acted in concert to express a political view.  More importantly, they did so in a way that demonstrated again the considerable power that the Internet has to reach people, communicate ideas and organize political action.

These Internet companies are expressing valid issues about the provisions of SOPA/PIPA, particularly whether the measures to prevent piracy go too far and would impede legitimate exchanges of information.  That does not mean, however, the the proposed legislation is wholly wrong or the that Internet companies, most of whom have commercial interests to protect as well as the freedom of information sharing, are completely right.  New York Times columnist David Pogue has a good commentary on this protest of SOPA/PIPA.

In that commentary Pogue points out that the opposition to SOPA/PIPA falls into two different groups that are not really in agreement with each other.  The first group would agree the piracy of protected intellectual property should be stopped, but takes issue with the steps that SOPA/PIPA would take to stop such piracy.  The concerns of this group could be addressed by re-writing the provisions of the legislation.  The second group really believes that piracy is good, a kind of an Internet variant of Gordon Geko’s famous "Greed is good" statement from the movie Wall Street.  This second group wants to be able to have free Internet access to copyrighted material, whatever its nature.  The second group wants no legislation or enforcement efforts at all.  In this respect, the people protesting the take-down of Megaupload, including Anonymous, also may represent those who want free information without cost, even if it is protected by copyright or other intellectual property rights.

With these two developments occurring side-by-side, it is also most interesting to note that the existing laws that were used to take down Megaupload appear to have rather far-reaching enforcement powers already.  If you believe that the artists and businesses who create music, film, literature, photograph and other forms of intellectual property should have their rights protected and that fair compensation should be paid for use of such material, then it would seem important to improve the existing laws that protect such rights in a way that does not threaten the free speech and the free exchange of ideas.


Thursday, January 13, 2011

The iPhones are Coming, The iPhones are Coming (to Verizon)!!

This is old "news" even to the online readers of this column, but the deal is done.  Apple and Verizon have come to terms and the iPhone will be available on the Verizon network, starting February 10.  See David Pogue's piece in the New York Times yesterday, which highlights two immediate differences in the operation of the iPhone on Verizon vs. ATT (no surfing the internet while calling and no usage abroad), and one significant advantage that Verizon has:  far better coverage on its more extensive network here at home.

Pogue cautions, however, that the influx of new iPhone users and the spike in data demand  may sap Verizon's network.  It is too early to tell. Marketplace Tech Report had a report on whether Verizon's network is up to the challenge.

The Wall Street Journal's Smart Money reports that you can expect some marketing changes at Verizon that are designed "encourage" existing customers to move to the iPhone.  Verizon will be discontinues its popular upgrade program.  Meanwhile, ATT and other businesses in the smart-phone wars are bracing for the effects.

I will have to look at details of the service contract, but this Verizon customer is ready to end his long wait to get an iPhone.