Showing posts with label email. Show all posts
Showing posts with label email. Show all posts

Monday, February 6, 2012

Lemming Tracks: States Provide Voter Information (and email addresses - EEEEK!)

If you registered to vote in one of these states, and put your email address on the voter registration form, you'll probably be spammed:
  • Arkansas
  • California
  • Indiana
  • Iowa
  • Missouri
  • Oregon
  • New Jersey
  • Rhode Island
  • Wisconsin
    (FoxNews.com)
The government in these states decided to sell email addresses they'd collected during voter registration. Don't worry, though: they didn't sell to just anybody. Only the 'better' sort could buy your address.

States Sell Contact Lists: Legal, Yes; Smart, Dubious

"Move over robo-calls, states sell email addresses for campaigns to reach voters"
Kathleen Foster, FoxNews.com (February 6, 2011)

"If your email inbox starts overflowing with messages from political campaigns this election season, it could be because your state sold you out.

"A Fox News study has found 19 states plus the District of Columbia, now ask for an email address on voter registration cards. In nine of those states, email addresses from the cards are then sold to political parties, organizing groups, lawmakers and campaigns who can use them to send unsolicited emails.

"If it were a Viagra ad, it be considered a crime in some states. But a political message, that's all perfectly legal.

"The CAN-SPAM (Controlling the Assault of Non-Solicited Pornography and Marketing) law enacted in 2003 puts restrictions on commercial mass emailing, but not on political mass emailing. Politicians can 'spam' and do. Political messages of any kind, including electronic, are protected free speech under the First Amendment...."

Here's where it gets interesting.

On the one hand, folks who cooperatively gave their email addresses to (some) state governments will be getting a whole lot of more-or-less coherent campaign stuff in their inbox. Assuming that their spam filters don't deal with it first. That could be annoying.

On the other hand, these spam lists are fairly well-focused. The only folks affected are those who:
  • State residents
    • Who registered to vote
      • Presumably have some interest in who
        • Runs
        • Wins
    • Wanted to give their email address
  • Politicos and their ilk
    • Political
      • Parties
      • Organizing groups
      • Lawmakers
      • Campaigns
People who vote presumably want to know something about the candidates they'll support, and the issues they'll support or condemn. That's the idea, anyway: and that's another topic.

Voters could reasonably be expected to be interested in what politicos and their marketing people have to say. Int a way, selling email lists is no more an 'invasion of privacy' than providing a list of names and addresses.

The difference is that it's a whole lot easier, faster, and cheaper, to email than to call or drop envelopes into the United States postal system. That can mean more efficient communication: or massive accumulations of drivel. So much depends on whether the folks sending emails have common sense.

What If the Government Wouldn't Share?

"...'Political communications are not spam. Political communications are a demonstration of free speech in America,' said Stuart Shapiro, president of iConstituent, a Washington, D.C.-based firm which uses state-generated email lists to send messages on behalf of clients on all sides of the political spectrum.

" 'There is a tenet in government that is based on communicating with our constituents, and email is one of the most effective ways to do it,' Shapiro said. 'People look forward to it and want it.'

" 'Politicians love the fact that their perceived freedom of speech is more important than voters' privacy,' said Shaun Dakin, president and CEO of The National Political Do Not Contact Registry, a non-profit voters' rights advocacy group based in Falls Church, Va...."

"Political communications are not spam" is true, to a point. Provided that the states sell lists to all political parties, and keep the cost low enough so that all but the best-funded are excluded. Then there's the potential for excluding parties and candidates who aren't sufficiently green, patriotic, or diverse.

"Privacy," and Getting a Grip

"...Like phone numbers, email addresses are not required to register to vote anywhere in the United States. Giving the information is optional, but that may not be clear to the average voter.

" 'I think this is really one of those untold stories. It's all going on behind the scenes,' said Kim Alexander, president of The California Voter Foundation, a nonprofit organization which produced the study "Voter Privacy in the Digital Age.'..."

Since the Lemming lives in a small town, "privacy" in the sense of anonymity isn't a factor. Like the old gag says, 'if you can't remember where you were today, ask someone: they'll know.' The Lemming loves it here: but folks who want to be part of a faceless crowd probably wouldn't like it. And that's yet another topic.

A key point here is that states aren't demanding email addresses as a voting requirement. That, in the Lemming's opinion, would be as bad an idea as the old pre-civil-rights voter registration requirements that kept the 'wrong sort' away from elections.

And 'not clear to the average voter?' The Lemming suspects that The Masses are nowhere near as stupid, ignorant, or irresponsible, as the establishment believes we are. Yet more topics.

These states ask for email addresses on voter registration forms:
  • Arizona
  • Arkansas
  • California
  • Colorado
  • District of Columbia
  • Delaware
  • Indiana
  • Iowa
  • Maryland
  • Minnesota
  • Missouri
  • Nebraska
  • New Jersey
  • Oregon
  • Rhode Island
  • Tennessee
  • Virginia
  • Washington
  • Wisconsin
  • Wyoming
    (FoxNews.com)

Opting Out/Confirming and Common Sense

"...Receivers of political emails do have the right to opt-out from lists -- they just can't do it in one click. Instead, they must do it with every email they receive, clicking on an "unsubscribe" link, if the email has one or by replying to the sender with 'Remove Me' request.

"Shapiro says few people actually do this.

" 'iConstituent, last year, probably mailed more than a billion email records out throughout all of America for Congress for various other legislators and we have a very, very low unsubscribe rate. It is well under one-tenth of 1 percent.'..."

It's interesting that under 0.1% of folks respond to those "unsubscribe" notices. It may mean that folks on the voter email lists like getting the messages. Or it may mean that they've learned not to respond to such things.

It wasn't all that long ago that the Lemming learned by experience to ignore and delete unwanted email. That was when some outfits were collecting lists of working email addresses by sending to all more-or-less likely possible combinations of name ("local") and domain. Folks who clicked on the 'unsubscribe' link, or sent a 'don't bother me' email back, had confirmed that the email address was in use. And that whoever used it read their email. Spam by the bucket would follow.

Ah, the 'good old days.' Yet again more topics.

Related posts:

Sunday, December 18, 2011

King County Scam Email: The Lemming Got One, Too

"King County warns of email scam"
FederalWayMirror.com (December 16, 2011)

"King County is warning residents of an apparent email scam.

"The email is in regards to property tax payments, and is a false confirmation that a payment was received. According to the county, these emails have even been sent to people in other states and countries. The county says these emails have not been sent by the county, and that none of the county's systems have been compromised.

" 'It appears that someone copied our standard payment confirmation email and altered the header in the email so that it appears to be from King County,' said County Chief Information Officer Bill Kehoe. 'These messages did not come from King County, and the recipients have not made any payments with us.'..."

The Lemming lives more than a thousand miles east of King County's Seattle, Washington, and got one of those ersatz emails on Thursday, December 15. How the scammer got the Lemming's personal email is anyone's guess.

A few minutes' searching told the Lemming that the email was probably the result of someone spoofing, and that the Lemming should delete the email.

And, of course, not open the attachment. Seriously: Folks still open attachments arriving in odd emails from folks they don't know? Come to think about it, there's probably someone starting to use email every day - and reminders never hurt.

Moving on

"Apparent Email Scam" in the News

"King County warns of apparent email scam"
King County Executive News (December 15, 2011)

"County's e-commerce system secure, investigators looking into outside source of bogus emails

"King County is warning of an apparent email scam. The county has received calls from people and businesses within and outside of King County, including individuals from other states and countries, who have reported receiving false confirmation of an online property tax payment made through the King County e-commerce system. These emails were not sent by King County, and the county's e-commerce system has not been compromised.

" 'It appears that someone copied our standard payment confirmation email and altered the header in the email so that it appears to be from King County,' said County Chief Information Officer Bill Kehoe. 'These messages did not come from King County, and the recipients have not made any payments with us.'..."

Which is pretty much what the Lemming found on the King County website.

Why did the Lemming take time to put this post together?

For one thing, that ersatz email was different from the spam that occasionally gets past the Lemming's filters. It wasn't the obviously-bogus message from a 'law firm:' about a rich relative who doesn't exist, worded in a way that suggests the message was composed by a Croatian primary school dropout, using a Slovenian-English dictionary written by a well-intentioned Bengali.

For another, the Lemming is still a little puzzled about being included in a scam that seems otherwise restricted to the Seattle, Washington, area. Not that the Lemming's likely to spend more time, trying to find out.

Besides, it's Sunday afternoon: and the Lemming's taking a few hours off. Which sometimes results in the Lemming committing another post. And that's another topic.

Slightly-related posts:

Tuesday, March 1, 2011

GMail, Google, Backup, and the Lizard People

"Google Gmail Snafu Lesson: Backup, Backup, Backup"
Ian Paul, PCWorld (March 1, 2011)

"Gmail is hard at work restoring service to about 40,000 Gmail users after a software bug deleted their e-mail messages, folders, labels and filters. So, while things are looking good for those users affected by the bug, this episode proves, once again, that while Web-based services may be robust, you still have to take responsibility for your own data.

"Google also takes responsibility. Ben Treynor, Google's VP Engineering and Site Reliability Czar, said on Google's Gmail blog that Google backs up all Gmail to tape. 'Since the tapes are offline, they're protected from such software bugs,' he blogged. 'But restoring data from them also takes longer than transferring your requests to another data center, which is why it's taken us hours to get the e-mail back instead of milliseconds.'

"Treynor said a storage software update introduced the unexpected bug, which caused 0.02% of Gmail users to temporarily lose access to their e-mail.

"It's Not Just Google Services You Need to Worry About

"However, it's not just Gmail and other Webmail services that are the problem; we're increasingly using cloud-based tools for work and communication such as Twitter, Facebook, Google Docs, Microsoft Office Live, Tumblr, Wordpress, Blogger, Posterous, Flickr, Picasa, and on and on.

"But that doesn't mean you should forego a solid back-up plan for all your online data. If the worst ever does happen, and a free Web service dumps your stuff permanently, the only response you can reasonably expect from these companies is: "oops, sorry."..."

There are quite a few lessons one could learn from the recent GMail SNAFU. Among them are:
  1. Google can't be trusted
  2. Microsoft is evil
  3. All of the above
  4. Space-alien, shape-shifting lizard people are behind it all
  5. Trust, but do backup anyway
Answers A. B, and C have, in the Lemming's experience, some earnest and enthusiastic proponents. Still, 'if three hundred million people really believe in a stupid idea: it's still a stupid idea.' The Lemming suspects that one reason that Google and Microsoft are so roundly reviled is that both are highly successful outfits. And that's another topic.

Answer D, weird as it is, reflects a minority opinion (the Lemming trusts) that lizard people from outer space are the 'real' rulers of Earth. (Another War-on-Terror Blog, footnote 1, (January 14, 2009)) And that's not quite another topic.

Answer E reflects the Lemming's approach to email services, cloud computing, and municipal sewage plants.

Trust, in the Lemming's opinion, is necessary when dealing with other folks.

Warning! Old Coot Reminiscing

When the Lemming was getting a weekly paycheck, the Lemming trusted the boss to sign checks.

The boss trusted the Lemming to get things done.

Sometimes the boss didn't sign the check. Sometimes the Lemming didn't get things done. That's because there were weeks, now and again when cash flow in the company simply wouldn't cover paychecks; and some weeks, now and again, the Lemming simply couldn't keep up with the tasks. We both caught up, but there were a few awkward moments.

Big Companies Never Make Mistakes, Right?

The Lemming suspects that there's a tacit assumption that big companies, like Google, never make mistakes: That when something goes wrong with one of their services: THEY DID IT ON PURPOSE!!!

Frustrating as finding one's account deleted is: That's not likely.

It's not that the Lemming thinks Google, Microsoft, Big Cheese, and all the rest are run by paragons of virtue. The Lemming's assumption is that, occasional debacles like the big three automakers meltdown notwithstanding, the folks who run large companies are:
  • Not particularly stupid
  • Moderately selfish
  • Aware of where their money comes from
The 'moderately selfish' part of that list is a whole different set of topics: probably for another blog.

The point is that, again with notable and spectacular exceptions, the Lemming has noticed that the folks in charge of outfits like Google - and GMail - act as if they know that if they fail to provide the services the rest of us depend on them for: we'll find someone else who will.

And there goes their job, their pension, their house in Hyannis Port, and all.

Golden parachutes, corporate greed, and mind-boggling stupidity are yet more topics.

Backing Up Data: Good Idea

Back to the PCWorld article. Op-ed, actually.

Ian Paul has, in the Lemming's opinion, pretty good observations and advice about how to be sensible with personal data and:
  • Gmail and Friends
  • Facebook
  • Blogging
  • Twitter
The Lemming doesn't follow all of Mr. Paul's advice: but the Lemming doesn't have the same needs and preferences.

It's like so many other things: The specific advice is pretty good; but the best part is the set of principles involved.

Principles For Backups

For the Lemming, there's a whole lot of data that can go away and not be missed. For that, backups are a waste of time. What the Lemming thinks is important, and what you do, won't be quite the same.

But the Lemming thinks that it's a good idea to decide what's important, what's not: and then set up a routine, preferably automated, for backing up the important data.

And storing it someplace that's a good distance from where the primary servers are.

Which reminds the Lemming: This nifty new computer doesn't have backup routines established yet.

Somewhat-related posts:

Thursday, February 24, 2011

How to Lose Friends and Alienate People With Email: 10 Easy Points

"How to Be a Jerk in E-mail"
Eric Griffith, PCMAG.com (February 23, 2011)

" 'Friends' are for social networks. But e-mail is for everyone, even enemies, frenemies, family, and co-workers, of course. E-mail remains the killer app of Internet communications for one reason: you can't really do anything wrong in e-mail. Seriously, follow these ten tips and you might end a marriage or two, lose your livelihood, or look like a complete and utter fool, but that won't be your fault. It's e-mail, where anything goes, you can do what you want, and so-called 'netiquette' doesn't apply. Right?

"Uh...okay. If you buy that, then keep reading, [insert insult here]. We're sure you'll take it all to heart.

"1. Never BCC
"You should always put every e-mail address in the "To" field, especially if you're mailing to your entire address list—and that goes double if you're at work. CC'ing folks only makes them feel unworthy. And using the BCC, well, that's just plain rude. Why not put it all out there? Don't you want all your recipients to be friends with each other?...

Eric Griffith wrote "How to Be a Jerk..." with tongue firmly in cheek, and the Lemming thoroughly enjoyed it. Your experience may vary.

And now, for those who need help being jerks, here's a sample of that advice:

"...2. Always 'Reply All'
"Remember that Super Bowl commercial where the guy was so upset that he might have done a 'Reply All?' Such nonsense. It's best to click 'Reply All' every single time, just to be sure you're covered. That way no one is ever left out. It's particularly important when you write a long-winded diatribe about the monumental stupidity of a cubicle neighbor…or your boss.

"3. Write a Book
"Do not keep to just one topic in an e-mail. What a waste. It's always best to fit in as many bullet points as possible. Better yet, eschew bullets for several paragraphs on several topics and clump them together into one gigantic über-missive. The greater the length, the more details, the more topics covered in the e-mail, the better. Bonus: Make the subject line of the e-mail a rant in and of itself....

Actually, the Lemming has used bullet points in emails, and memos: but the 'pick a topic and stick to it' advice is sound. Or, if you're trying to alienate folks: Go ahead and ramble.

Wait a minute - - - the Lemming rambles at times does that mean - - -?

Back to the 'be a jerk' article:

"...4. Don't Sweat Infection
"Sure, others may be chicken about getting a computer virus, but you're not as cowardly and stupid as them, right? Forgo the installation of anti-malware software and feel free to download and click those attachments. All of them. Especially the ones in spam. What's the worst that could happen? Maybe you will actually get some free 'enhancement' pills.

"5. Attach Big Files
"Got a fantastic digital photo of your sleeping cat you want to share?..."

And that's just the first page. Here's what you'll find on the second, with the occasional interjection by the Lemming:

"...6. SHOUT IT, SHOUT IT OUT LOUD..."

Yes, some folks still use ALL CAPS. or not capsatall and minimalpunctuationmaybeitsbeingcreativelikeeecummings

"...7. Make Esoteric Signatures..."

Eric Griffith explains, with a picture. One that's worth, in the Lemming's opinion, a thousand words:



"...8. Pass On Problems..."

The Lemming expected something about those memorable folks who inform you, in clinical detail, what the doctor discovered during their last colonoscopy, or why they never eat meat. Instead, the topic was those wonderful opportunities the Lemming finds now and again: heads of state who need the Lemming's help to move their fortunes around; work-at-home opportunities; that sort of thing.

"...9. Spread Out Your Bad Self..."

On this one, the Lemming agrees: to an extent. One email address is best, for anyone who's serious about getting replies. On the other hand, sometimes it's better to have a 'personal' and a 'business' account - and that's another topic or two.

"10. Write When Enraged..."

The Lemming loves a particular bit of this point: "...You need to get your lizard-brain thoughts down quickly, without thinking it through. It's called catharsis, people, look it up!..."

"Lizard-brain thoughts:" That's a wonderful way to describe those knee-jerk, instant reactions that most of us learn to control somewhere before adolescence. In the Lemming's opinion, of course. Then there's that word, "catharsis." The Lemming remembers those balmy days after wig pickers started saying that 'catharsis' was good for you - and before others noticed the mess that catharsis spills make.

Moving on.

The PCMag.com article is fun, a fairly fast read, and full of fanciful philosophizing. Fraught, in fact.

Enough of that.

For what it's worth, the Lemming suspects that quite a few folks are sensible - and don't clog email with what Eric Griffith described. It's like the fellow at a gathering whose voice has two settings: loud; and overbearing.

The Lemming will skip the usual hand-wringing about the appalling state of communication skills and emotional maturity online. You've probably heard it all before.

Besides, it's a beautiful day here in central Minnesota: and the Lemming's not going to rant.

Well, maybe just a little.

Here's something the Lemming ran across, back in 2008:



I found it on a page whose title is 'the disordered clipboard of Giuseppe Mazza,' except it's in Italian. Not the cartoon, the title.

Enjoy.

Related posts:

Thursday, February 18, 2010

Kneber Botnet Infects Corporate Computer Networks: HAL was Right


UPDATE (February 18, 2010 - 9:22 a.m. Central)

"Malicious Software Infects Corporate Computers "
The Wall Street Journal (February 18, 2010)

"A malicious software program has infected the computers of more than 2,500 corporations around the world, according to NetWitness, a computer network security firm.

"The malicious program, or botnet, can commandeer the operating systems of both residential and corporate computing systems via the Internet. Such botnets are used by computer criminals for a range of illicit activities, including sending e-mail spam, and stealing digital documents and passwords from infected computers. In many cases they install so-called 'keystroke loggers' to capture personal information.

"The current infection is modest compared to some of the largest known botnets...."

"...The hacking operation, the latest of several major hacks that have raised alarms for companies and government officials, is still running and it isn't clear to what extent it has been contained, NetWitness said. Also unclear is the full amount of data stolen and how it was used. Two companies that were infiltrated, pharmaceutical giant Merck & Co. and Cardinal Health Inc., said they had isolated and contained the problem.

"Starting in late 2008, hackers operating a command center in Germany got into corporate networks by enticing employees to click on contaminated Web sites, email attachments or ads purporting to clean up viruses, NetWitness found.

"In more than 100 cases, the hackers gained access to corporate servers that store large quantities of business data, such as company files, databases and email.

"They also broke into computers at 10 U.S. government agencies. In one case, they obtained the user name and password of a soldier's military email account, NetWitness found. A Pentagon spokesman said the military didn't comment on specific threats or intrusions...."

"...The computers were infected with spyware called ZeuS, which is available free on the Internet in its basic form. It works with the FireFox browser, according to computer-security firm SecureWorks. This version included a $2,000 feature that works with FireFox, according to SecureWorks.

"Evidence suggests an Eastern European criminal group is behind the operation, likely using some computers in China because it's easier to operate there without being caught, said NetWitness's Mr. Yoran.

"There are some electronic fingerprints suggesting the same group was behind a recent effort to dupe government officials and others into downloading spyware via emails purporting to be from the National Security Agency and the U.S. military, NetWitness's Mr. Yoran said...."
"Botnet attack"
Daily Briefing, UPI (February 18, 2010)

"More than 70,000 computers from 2,500 companies have been infected with the Kneber botnet, an Internet watchdog said Thursday.

"NetWitness Corp. of Virginia said the attack is used to reap user names and passwords to gain access to financial information, social networking Internet sites and e-mail. The rogue software has been circulating for about 18 months and is known to have gathered about 75 gigabytes of data...."

"...The [Wall Street] Journal said the botnet software is spread when a computer user opens phishing e-mail that links to the code."

And the moral of this story is - no, really: don't open that email attachment.

Or as the HAL 9000 computer said, "It can only be attributable to human error."

There's quite a bit more on this SNAFU, including:

"Malicious Software Infects Corporate Computers"
The New York Times (February 18, 2010)

"A malicious software program has infected the computers of more than 2,500 corporations around the world, according to NetWitness, a computer network security firm...."

"...NetWitness said in a release that it had discovered the program last month while the company was installing monitoring systems. The company dubbed it the “Kneber botnet” based on a username that linked the infected systems. The purpose appears to be to gather login credentials to online financial systems, social networking sites and e-mail systems, and then transmit that information to the system's controllers, the company said.

"The company's investigation determined that the botnet has been able to compromise both commercial and government systems, including 68,000 corporate log-in credentials. It has also gained access to e-mail systems, online banking accounts, Facebook, Yahoo, Hotmail and other social network credentials, along with more than 2,000 digital security certificates and a significant cache of personal identity information...."

"...'Many security analysts tend to classify ZeuS solely as a Trojan that steals banking information,' stated Alex Cox, the principal analyst at NetWitness responsible for uncovering the Kneber botnet. 'But that viewpoint is naïve. When we began to detect the correlation among both the methodology used by the Kneber crew to attack victim machines and the wide variety of data sets harvested, it became clear that security teams must rethink their entire perspective on advanced threats such as ZeuS.'

"Half of the machines infected with the Kneber botnet were also infected by an earlier botnet known as Waledec, the company noted.

"The existence of the botnet was first reported by the Wall Street Journal, shortly before the company issued its press release."

"Virus has breached 75,000 computers: study"
Reuters (February 18, 2010)

"A new type of computer virus is known to have breached almost 75,000 computers in 2,500 organizations around the world, including user accounts of popular social network websites, according Internet security firm NetWitness.

"Technology

"The latest virus -- known as 'Kneber botnet' -- gathers login credentials to online financial systems, social networking sites and email systems from infested computers and reports the information back to hackers, NetWitness said in a statement.

"A botnet is an army of infected computers that hackers can control from a central machine....

"..'Conventional malware protection and signature-based intrusion detection systems are, by definition, inadequate for addressing Kneber or most other advanced threats,' Chief Executive Amit Yoran said in a statement."

Kudos to the Reuters article for helpfully defining "botnet" - a term that may not be familiar to many readers.

Then they end the article with "...Conventional malware protection...inadequate for addressing ... advanced threats..." That's true (but, in my opinion, misleading) statement reminded me of the old "bullets won't stop them!" line from fifties monster movies.

If, by "conventional malware protection," Reuters meant systems that rely exclusively and completely on software to scan programs and messages - yes, it's true. "conventional malware protection" won't stop the Kneber botnet.

Because it apparently relies on some human being opening an attachment to a phishing email.

How long have we been hearing and reading "DON'T OPEN EMAIL ATTACHMENTS" unless you have verified that the person it's supposed to be from actually sent it - and doesn't have an infected machine?

That sound you didn't hear was me, mentally beating the desktop with my head. I don't know which will be easier: developing a global system of cooperating lawmakers, law enforcement agencies, software developers, ISPs, and users to identify and prosecute the outfits that create problems like this? Or getting folks in the office to exercise common sense?

Tuesday, January 19, 2010

Google Gmail Hack: a Followup

"After Google hack, Microsoft asks users to abandon IE6, XP"
One Microsoft Way (January 18, 2010)

"Microsoft is using a widely publicized flaw in Internet Explorer as a way to push users to upgrade both their browsers and operating systems.

"On its Security Research & Defense blog, Microsoft explains that while IE7 and IE8 on Windows Vista and Windows 7 both include the flawed code that was exploited in the recent Chinese attacks on Google, the publicly published exploit code only works against IE6 on Windows 2000 and Windows XP. So the company is urging users to think about upgrading their version of IE, or even their OS (which also results in a newer version of IE)...."
"Assessing risk of IE 0day vulnerability"
Security Research & Defense (January 15, 2010)

"Yesterday, the MSRC released Microsoft Security Advisory 979352 alerting customers to limited, sophisticated attacks targeting Internet Explorer 6 customers. Today, samples of that exploit were made publicly available.

"Before we get into the details I want to make one thing perfectly clear. The attacks we have seen to date, including the exploit released publicly, only affect customers using Internet Explorer 6. As discussed in the security advisory, while newer versions of Internet Explorer are affected by this vulnerability, mitigations exist that make exploitation much more difficult. We would like to share a little more information about both the vulnerability and the exploits we have seen to help you understand the risk to your organization...."

"...Ways to block Code Execution

"The vulnerability is present in Internet Explorer 6, Internet Explorer 7, and Internet Explorer 8. All versions may crash after opening the attack code. However, there are a number of ways to limit the attack to an IE crash and prevent attacker code execution...."

The first item is to disable JavaScript, a fairly standard move.

Good Advice: But I'm Not Taking It - Quite

My computer, the one I do practically all my work on, is over five years old and uses Windows XP. I'd upgrade: but don't have the budget for it. Yet.

On the other hand, I've got pretty good security: malware scans on a programmed schedule, a protocol I follow when downloading files: and I don't use Internet Explorer unless I absolutely have to.

Some companies, for reasons or unreason unknown, won't do business online unless transactions are mediated through IE. I avoid dealing whenever possible, but sometimes - - -.

I use Firefox, the most recent upgrade (3 point something now). And have my security software watching Firefox.

I like to think that Microsoft is doing a better job these days, of making Internet Explorer a comparatively safe browser. But: trust IE, with its track record for security issues? I think not.

Related post:
A tip of the hat to Twitter_Tips, on Twitter, for the heads-up on the article.

Monday, January 18, 2010

Google Gmail Accounts Vulnerable, China Hack Went Public

Followup (January 19, 2010)
If you've got a Gmail account, you should be interested in this.

Looks like the hack that China has used to get into Gmail accounts in its worker's paradise has gone public.

(The format of this Apathetic Lemming of the North post is a little different than the usual: excerpts from a few news articles and a post in another blog, then a fairly short comment.)

"Chinese Attack On Google Seen As Cybertheft"
National Public Radio (January 18, 2010)

" Google's carefully worded announcement last week that it had experienced "a highly sophisticated and targeted" cyber attack in China caught the attention of both human rights advocates and industrial espionage experts, though for quite different reasons.

"Activists focused on a Google statement that a 'primary goal' of the attack had been to access the Gmail accounts of Chinese dissidents. Espionage experts, however, were drawn to Google's acknowledgement that the cyber attack 'resulted in the theft of intellectual property.'

"Those words say a lot. 'Intellectual property' means knowledge and ideas. It's what makes innovation possible, and it can include everything from secret formulas to computer source code. Google is among the most innovative companies on the planet, and someone in China has been stealing its secrets. Some China experts see this as the real story behind Google's threat to pull out of China.

" 'For Google to have made such a profound decision, to turn its back on the fastest growing economy in the world, it had to have been more than a bunch of dissident e-mail accounts, says James Mulvenon of the Defense Group consultancy..."

"Google Hack Leaked to Internet; Security Experts Urge Vigilance"
FOXNews (January 18, 2010)

"The code that was used to hack Gmail accounts in China is now publicly available on the Internet, and security experts are urging computer users throughout the world to be highly vigilant until a patch can be developed.

"The hack involves Internet Explorer 6, the browser that came with the Windows XP operating system that, while outdated, still powers millions of businesses and home computers and is now dangerously compromised.

"On Thursday, the code that was used to hack Gmail accounts in China and led Google to threaten to close shop there was posted to malware-analysis Web site Wepawet. By Friday, security site Metasploit had posted a demonstration of just how easily the exploit can be used to gain complete control over a computer.

"Metasploit is intended to let security professionals test out security threats...."

"Google Investigating If China Staff Involved in Cyber Attack"
The Wall Street Journal (January 18, 2010)

"Google Inc. is investigating whether any of its employees in China played a role in facilitating a major cyber attack that prompted a decision to stop censoring its search results in the country, according to people familiar with the matter.

"One of these people said consideration of employee involvement was part of the normal course of investigating the attack, which Google has traced to China and which resulted in some loss of the company's software code.

"While the company is still investigating, another person familiar with the matter said Google believes the attacks would have been successful whether or not the company had a presence in China.

"Whether the company has found any evidence to implicate employees remains unclear. It is also unclear whether the Google investigation is focusing on the possibility of employee involvement in the main attack against its systems or separate attempts to breach the Gmail accounts of Chinese human rights activists, or both...."

"Google China insiders may have helped with attack"
CNET (January 18, 2010)

"Google is looking into whether employees in its China office were involved in the attacks on its network that led to theft of intellectual property, according to CNET sources.

"Sources familiar with the investigation told CNET last week that Google was looking into whether insiders at the company were involved in the attacks, but additional details were not known at the time.

"Insiders could have played a part in what is believed to have been a multi-prong attack on the company, according to the sources.

"Employees in the Google China office were put on leave and others were transferred, Reuters reported on Monday, citing local media reports and unnamed sources. Employees in the office were temporarily cut off from the network so Google could run tests and scans to ensure that the network was secure, sources familiar with the investigation told CNET...."

"Google probing possible inside help on attack"
Reuters (January 18, 2010)

"Google is investigating whether one or more employees may have helped facilitate a cyber-attack that the U.S. search giant said it was a victim of in mid-December, two sources told Reuters on Monday.

"Google, the world's most popular search engine, said last week it may pull out of the world's biggest Internet market by users after reporting it had been hit by a 'sophisticated' cyber-attack on its network that resulted in theft of its intellectual property.

"The sources, who are familiar with the situation, told Reuters that the attack, which targeted people who have access to specific parts of Google networks, may have been facilitated by people working in Google China's office.

" 'We're not commenting on rumor and speculation. This is an ongoing investigation, and we simply cannot comment on the details,' a Google spokeswoman said.

"Security analysts told Reuters the malicious software (malware) used in the Google attack was a modification of a Trojan called Hydraq. A Trojan is malware that, once inside a computer, allows someone unauthorized access. The sophistication in the attack was in knowing whom to attack, not the malware itself, the analysts said...."

China hosted the Olympics in 2008, which may explain why innovatively suicidal stunts by Chinese companies and occasionally goofy behavior by the Chinese government was in the news so much, here in America.

Poison toothpaste and factory-loaded malware in consumer electronics didn't help, of course.
"...I still think it's likely that China's new export industry is infested with criminally incompetent nitwits, who have no clue about why you make sure that
  • "Consumer electronics don't have factory-loaded malware
  • "Cough syrup doesn't kill the customer, as well as the cough
  • "Children's toys aren't coated with lead
  • "Baby food isn't poisonous
"On the other hand, as these over-the-top examples of not-as-advertised products pile up - along with dead bodies - it isn't all that crazy to wonder if the Chinese government is trying to sabotage other countries.

"And doing a bad job of it...."
("Thai Police, Punctured Protesters, and Exploding Tear Gas from China," Another War-on-Terror Blog (October 13, 2008)
As I said, 2008 wasn't a good year for China, in terms of good public relations.

The Gmail hack that the Chinese government was using to monitor enemies of the state - real or imagined - just happening to go public could be really, really bad luck for China.

Or maybe Google has very good reason for backing out of "the fastest growing economy in the world". (NPR)

Related posts:

Sunday, November 1, 2009

CEO In Trouble: For Attacking the Firm He Founded

"Former CEO charged with cyberattack on firm"
SFGate, San Francisco Chronicle (October 30, 2009)

"Khalid Shaikh, former CEO of YouSendIt, has been indicted by a grand jury on four counts of mail fraud after allegedly launching four denial-of-service (DOS) attacks against the company's servers, the U.S. Department of Justice said.

"Shaikh allegedly used the ApacheBench software program to launch the DOS attacks against YouSendIt's servers between December 2008 and June, the DOJ said in a press release...."

That's a little more in the news articles, and the FBI press release. If any of the fairly reliable sources online mentioned motive, I missed it. There's plenty of ideas about why Mr. Shaikh DOSed the company he founded - many, in my opinion, of the "round up the usual suspects" variety.

Me? I think Khalid Shaikh had a motive: that this wasn't something that he 'just happened to do.' But what that motive was, I haven't a clue. And, happily, I don't have anything to do with the situation.

I hope YouSendIt comes out of this okay: which they should, with the publicity they're getting. (Hey! There's a conspiracy theory: This was a publicity gimmick - and no, I don't really think so.) The PC World sketch of their service, oversize email attachments, indicates that they were serving a specialized - and moderately uncommon - service.

In the news: Background:

Monday, November 17, 2008

Nigerian Scams, Internet Safety, Fraud, and Human Nature: The Lemming Gets Wordy

"Woman out $400K to 'Nigerian scam' con artists"
KATU (November 11, 2008)

"SWEET HOME, Ore. – Janella Spears doesn't think she's a sucker or an easy mark.

"Besides her work as a registered nurse, Spears – no relation to the well-known pop star – also teaches CPR and is a reverend who has married many couples. She also communicates with lightning-fast sign language with her hearing-impaired husband.

"So how did this otherwise lucid, intelligent woman end up sending nearly half a million dollars to a bunch of con artists running what has to be one of the best-known Internet scams in the world?..."

It's a fairly detailed account of how and why "this otherwise lucid, intelligent woman" sent almost a half-million dollars into oblivion in about two years.

My hat's off to Janella Spears, who "has gone public with her story as a warning to others not to fall victim." I think quite a few people in her position would just as soon not spread the story around.

How to Lose $400,000 in Just Two Years

Here's how it goes:
  1. Respond to an email that promises big bucks for a little money up front
  2. When they ask for more money, give it to them
  3. If you have more money, go to step 2
  4. If you do not have more money, borrow some and go to step 2
What got Janella Spears hooked was the scammers using her grandfather's name. What kept her hooked, apparently, was the idea that each step was the last step. Besides, she got letters from
  • The president of Nigeria
  • President Bush
  • FBI Director Robert Muller
    • (I know: it's Robert S. Mueller, III, but that's how the scammers spelled it)
She got documents from the
  • Bank of Nigeria
  • United Nations
President Bush and the FBI Director needed her help. The letter from Bush said that terrorists could get the money if she didn't help.

No, President George W. Bush isn't in on the scam: the letters were fakes. So were the documents.

Meanwhile, the amount of money she thought she'd get was going up.

I'd Never Fall for This, Right?

Actually, I can't imagine a situation where I'd believe a line like this, but I know it's a theoretical possibility.

My email service has pretty good filters, but I still get scam emails from time to time. The ones that just might be legitimate messages get opened, the rest don't. (I've also got pretty good internal security on my system, don't open attachments, and have rather cautious settings on the email reader.)

I actually enjoy those wonderfully polite messages, telling me that the grand high poobah of Lower Slobovia, or whoever, needs my help to move money around; or that my Uncle Louie in Australia has died, and left me money that runs into seven or eight figures.

But believe it? No.

Using a real relation's name was something special, of course, in this lady's case.

And, over the years, some scams have come close to hooking me.

There was the one from a very good imitation of my credit card company: I wound up having a nice chat with someone in that company's security division, which confirmed some assumptions I'd made about the company having an ounce of sense.

I've gotten emails, written in bad imitations of lawyerese, telling me that I'll inherit a fortune if I respond. As I recall, one actually did refer to a dead relative in Australia. I like to think that, even if the scammers used the name of a real person, I wouldn't respond. Not to them, anyway.

Appeals to Authority - Misspelled and Otherwise

I would be very dubious, if the president of the United States wrote a personal letter, saying that my help was needed.

It wouldn't matter if it was George W. Bush, or Barack Obama. The odds that someone would say, "help me, Obi-Wan Kenobi, you're our only hope" are slim. At best. I'd be particularly dubious, starting next year, if the president spelled his name "Barak Obama."

Does that make me really smart? Or immune? No. Just wary and better-trained in evaluating data than most people.

At that, some of those messages have really tugged at my heartstrings. And purse strings.

The Nigerian Scam and Other Ways to Lose Big in the Privacy of Your Own Home

Online scams are old hat. Some news services aren't even covering this Oregon incident. Nosing around for this post, I found a few useful and/or interesting resources:

Sunday, July 20, 2008

"But Everyone Uses..." Tale of a Clueless Librarian

"Stupid Client Quote #6149"
Clientcopia (April 7, 2008)

"I was once using the library computers to check my mail on Yahoo. The computer-inept librarian walked up behind me.

* Her: (shrieking) 'WHAT ARE YOU DOING???'
* Me: 'I'm checking my email--"
* Her: 'It looks like you're breaking into the computer!!'
* Me: 'No really -- I'm checking my mail.'
* Her: 'But that's not HOTMAIL!!'
* Me: 'I don't use hotmail. I use--'
* Her: 'But EVERYONE uses HOTMAIL!!'...
"

I believe this one: I've dealt with people like that. Odds are, you have too.

Thursday, April 17, 2008

To Forward, or Not to Forward, That is the Question

Should You Forward that Email graphic.

Another humorous flowchart. Habitual forwarders may (or may not) recognize themselves.
Update (February 24, 2011)

The graphic is embedded in:

Thursday, April 10, 2008

Email Personality Types: An Unscientific, Superficial, Thoroughly Fun, and Rather Accurate List

"Which E-mail Personality Type are YOU?"
Of Cabbages and Kings (April 9, 2008)

"Forwards, spams, scams, notes from family and friends... It all ends up in our email Inboxes and we each have our own way of dealing with it.

"So here at Of Cabbages and Kings, our diligent team of researchers... (okay, well, the Jane Austen bobblehead on my desk and I)...."

What follows is the result of almost a half-hour of exhaustive study.

Now, revealed to the world: an exhaustive categorization -- well, a list, anyway, of email personality types, from "The Serial Forwarder" to "The Generous Newbie."

Enjoy.

Tuesday, March 25, 2008

A Gmail Inbox for Firefox

"Getting Things Done with Gmail"

"GTDInbox is an addon for Firefox that transforms Gmail into a powerhouse of productivity and manageability. GTDInbox gives you a better inbox."

Tuesday, February 19, 2008

Robot Tricks Humans Into Reading Captchas

"Trojan tricks users into reading captchas"
The H Online (October 29, 2007)

You may have read about this already.

Captchas (Completely Automated Public Turing Test to Tell Computers and Humans Apart) - those weirdly-displayed letters and numbers that email services, blogs, and websites use - are pretty effective at telling the difference between the difference between a human being and a robot.

So, now there's a trojan that picks out a legitimate website that uses captchas and a human being. The human is typically shown a free striptease, where all (he) has to do is read a captchas for each piece of clothing.

I suspect that it's fairly effective at bypassing the 'good sense' circuits for human males between the ages of about 12 and 125.

Thursday, February 14, 2008

E-Scams and Warnings: FBI Information Page

"FBI / New E-Scams & Warnings"

The Valentine's Day STORM WORM VIRUS warning is the most recent.

Others this year were
  • FBI IDENTIFIES RECURRING FRAUDULENT E-MAIL SCAM
  • VISHING ATTACKS INCREASE
  • AN INCREASE IN INTERNET SCHEMES CLAIMING TO BE FROM THE FBI
  • NEW TWIST CONCERNING THREAT AND EXTORTION E-MAILS
I'm pretty sure there will be more.

Saturday, January 19, 2008

Old Joke, New Tech

"The Misdirected Vacation E-Mail"

I first ran into versions this joke before there was email, but it's still funny.

Sunday, September 2, 2007

Never Heard of Quechup? Lucky You!

"Spam alert! Just say no to Quechup" explains what Quechup is, and why you shouldn't sign up for the service.

It looks like good advice. I did a quick search, and found "spam" and "sting" repeated in reference to the service.
Unique, innovative candles

Visit us online:
Spiral Light CandleFind a Retailer
Spiral Light Candle online store

Pinterest: From the Man Behind the Lemming

Top 10 Most-Viewed Posts

Today's News! Some of it, anyway

Actually, some of yesterday's news may be here. Or maybe last week's.
The software and science stuff might still be interesting, though. Or not.
The Lemming thinks it's interesting: Your experience may vary.
("Following" list moved here, after Blogger changed formats)

Who Follows the Lemming?

WebSTAT

Family Blogs - Blog Catalog Blog Directory