work life

Catching Up

So it’s been a while since I posted anything. So let’s catch up, shall we?

The reasons I haven’t posted are several. I had a killer head cold for about 2 weeks, that I couldn’t shake (same one I mentioned in my Celebrate Good Times (Come On)! post).  My work issued laptop died on me, and I’ve been so busy at work that when I get home and I feel like crap due to the cold, I had no desire to sit in front of any PC. When you consider how much computer time I log at work, it’s rather surprising how much I use one at home.

But not everything was bad. I bought a new SiriusXM radio for my aging truck. It’s an external device that plugs in through the aux port on the existing radio. I also stream, mostly the “Classic” (oh, how I hate that term. Can we go back to AOR please?) stations. I like SiriusXM over the local radio because the DJs don’t think they have to be funny so they can get hired and go to a larger market. SiriusXM’s market is North America. Quite a bit bigger than any terrestrial market. Plus these DJs know what they’re talking about.  I also like SiriusXM over most streaming services (Spotify, Pandora, iTunes, etc.) because they play the music the way it was recorded. One thing that always pissed me off with the various streaming services is they tend to cut apart songs the segue into each other. A classic example is Jackson Browne’s “The Load Out/Stay”. Streaming radio turns those into two separate songs. It increases the total number of songs in their library, but it totally screws up the listening experience.

My office replaced my very small Micro$oft Surface Book with a beautiful 17″ HP laptop.  This thing is a beast! An i7 CPU, 16GB RAM, 256GB SSD, and this wonderful huge screen! These tired old eyes can see again!

Wifey® and I have planned, and made the deposit on, something that is on both of our bucket lists. A trip to Scotland, the land of our heritage. We’ve both did the Ancestry DNA tests. I’ve posted about this before.  Turns out both of our DNA points directly to Scotland/Ireland/Land of the Vikings. I’d like to try to find the ancestor that made the trip over the pond to settle in America before we go. But that costs money, and right now we’re trying to save, not spend so we can blow the whole wad while in Scotland.  I’m hoping the duty-free shop in the Edinburgh airport has a good selection of native scotches.  I will have a separate post(s) about the trip as things get closer, and when we are in country.

We had a wonderful dinner the other night with my brother and his wife here at my house.  I smoked three whole chickens. Not that I expected we would eat them all that night, I planned on leftovers so we (as in Wifey® and son-the-younger and myself) could make pot pies from the leftover chicken and other veggies we made that day.

wp-1533321237490..jpg

Yup, there are 3 whole chickens in there!

wp-1533321237469..jpg

We ended up with 10 pot pies of varying sizes

I confirmed something I learned the last time I smoked chicken. From now on I’m only buying leg quarters. There were 4 and a half breast quarters left, but only one leg quarter. Seem we prefer the dark meat!

And I’ve read a couple of good books too. I won’t write any reviews.  If you want book reviews, there are plenty of sites that have them (I recommend Once Upon A Spine).

I’ll leave you with a video. Has nothing to do with this post, but the opening line “Been away, haven’t seen you in a while”, fits with the theme. Plus it’s Dave Mason.  I’ve been a fan of his since his days with Traffic.

So what have you been up to?

Peace,
B

Twitter  FaceBook

Conference Time

Last week I had the great pleasure of attending the KnowBe4 conference in Orlando. (Official hashtag: #KB4Con18). This was without a doubt the best tech conference I have ever attended. Not only were there absolutely dynamic speakers, all attendees were treated to the best food!  I’m talking some of the healthiest stuff I have ever seen at any conference.

I’ve mentioned KnowBe4 before. This is the vendor we use at the city to train, test and generally harass our end-users (OK, maybe not harass). (KnowBe4 website) With just a small part of their product, I can train my co-workers on the latest ways the “bad guys” try to use social engineering to do well, bad stuff. I will admit that I enjoy sending out simulated phish emails. Why? Because it shows me where are weak links are. And this gives me the means to do targeted training to make our city network, and by association everyone’s home PC/Network, that much more secure. I don’t do it to shame someone or hold it over anyone’s head. Since I have been an instructor of some sort for very many years, I use this primarily as a training tool. But on to the conference itself.

Other than the hour plus, each way, drive on I4 (A.K.A. the devil’s highway), and being in Orlando (way too big and crazy for me), everything else went beautifully. The folks at KnowBe4 went above and beyond in this, their first ever conference.

The opening keynote speaker was Kevin Mitnick, or as he likes to call himself “The World’s Most Famous Hacker”, a title he lives up to. If you don’t know who he is, take a moment to read his Wikipedia page, even if it a bit light on his history. Kevin gave us many demonstrations of current hacks, all of which arrive via an inconspicuous email. And all of which are very nasty. But the one hack that scared me the most was when he showed how Google’s two-factor authentication (2FA) could be hacked. Google has always been one of the toughest to crack since they stay on the cutting edge of all technologies. As a big user of many Google services, this is troublesome.

MVIMG_20180517_182225.jpg

Me and Kevin Mitnick

The keynote speaker for the next day was Frank Abangale. I have to admit that I did not recognize his name. But once I heard his story I knew how he was. Here is his Wikipedia page for you to educate yourself. Frank is considered one of the foremost experts on imposters and forgery. Steven Spielberg made a movie “Catch Me If You Can” starring Leonardo DiCaprio as Frank and Tom Hanks as FBI Agent Carl Hanratty. I have not seen this movie, but I see it available on Amazon Prime so I will correct that error very soon. And if I caught his reference, he was also the inspiration for the TV show “White Collar”.  His family story and subsequent talk on how to keep safe with online financial sources was very eye-opening.

IMG_20180518_104922.jpg

Myself and Frank Abangale

Another fantastic speaker was Roger A. Grimes (he wants you to know he is not related to the Canadian political figure with the same name), the best-selling author of several tech books. KnowBe4 even included a copy of his “A Data-Driven Computer Security Defense” in the big ol’ backpack they gave every attendee. The big takeaway from his two talks was the point that you have to determine what your biggest exploitable problem is, and fix that first. Common sense, which as we all know, is always in short supply.

One thing that I really was happy to see was the inclusion of women speakers. KnowBe4 has several women in executive roles throughout the company, and that makes me very happy. Since I have two granddaughters, one of which is very interested in the sciences, I fully support women (and really anybody) in STEM (Science – Technology – Engineering – Mathematics). One of the first questions Wifey® asked me was if there were women presenters. I was so very happy to say yes!

There was one thing missing though. No vendor room. Every other conference I’ve been to there is always a room for vendors. Not only can one make some great contacts with products and services that one doesn’t know about, vendors always have cool swag (freebie gifts). I’ll have to check with my manager, but I think a conference is how we found out about KnowBe4. It may not have been in the vendor area, it may have been word of mouth from another attendee (word of mouth is ALWAYS the best advertisement).

Sorry, this is such a broad overview, but I could write about ten pages if I covered the entire 3 days. All I can say is “I’m ready for KB4Con19!”

Peace,
B

Twitter  FaceBook

PC Security, Again (or Is It Still?) UPDATED!

Before I get into Facebook and its current issues, I’d like to pass along a portion of an email I received today from KnowBe4.  KnowBe4 is the company I use at work to help test and train our users in email security. If you’d like read more about them click here.

I receive a “Scam Of The Week” email from KnowBe4 every week. Todays was very relevant, at least to me.  The headline is “Fiendishly Clever Gmail Phishing You Need To Know About”. If you’re not sure what a “phish” email is, to sum it up, it’s any email that impersonates someone else. A good example that I bet a lot of folks have received, is one from FedEx claiming that they need you to click on an attachment or follow a link because they couldn’t deliver a package.  The attachment or link is nothing but a malware-laden delivery tool. Either will infect your PC leaving you open to become a victim of a crypto tool (something that encrypts all the files on your PC, then the bad guys make you pay money, usually in bitcoin, to unlock your files. Most of the time they take your money and never decrypt your stuff). Or your PC becomes a “bot” under the control of the same bad guys, causing it do malicious acts without your knowledge.

Here is the quote from today’s scam;

“There is a new scam where hackers send you a text that asks you about a password reset on your Gmail account, and if you did not, text STOP. This is a scam. The bad guys asked for that password reset and now want you to send them the authorization code! Don’t fall for it.

Remember that Gmail or any other web email service will never ask if you *don’t* want to do something with your account. You didn’t ask for a password reset, so you shouldn’t be asked about one.

Do not reply to the text (doing so will tell the scammers that they have reached a valid number). And to prevent losing your account to bad guys, it’s a very good idea to have 2-step verification set up on your Google account.”

So what about Facebook?  If you used an app called “My Digital Life”, you have not only allowed your information on Facebook, but you have also allowed anyone in your contact list to have a limited part of their data shared. Again without your knowledge.

This breach is so bad that Facebook founder Mark Zuckerberg is testifying in front of Congress as I type this. The impact of this event is that 87+ million people have had their information shared.

I cannot stress how important it is to NOT USE ANY FACEBOOK APPS this includes games. I would also strongly recommend that you DO NOT do any of the “surveys”, like What Animal Am I, or the ones that give you a list of months and days to make up a name of some kind. Just think what you just did if you responded to one of those. In the case of the ones that tell you to post your answer and you do, you just publically posted your birth date. So anyone watching these posts (and believe me, they do track this stuff) now not only knows your name but your birthday too. It would only take one or two more little pieces of information and next thing you know your identity has been compromised. It’s scary.

And as you can see at the bottom of this post, I use both Twitter and Facebook. I’m not saying you shouldn’t enjoy them.  Just be careful, please.

So, a few tips to make things a bit safer;

  • Do not click on any attachments or links in any email where you don’t know the sender or if there is no reason that they would be sending you an email of this type. Going back to my FedEx example above the email claimed the attachment was a shipping label you needed to open and print. So look at the reasoning. They can’t deliver a package to your location. So why do you need to print a shipping label? That would be the responsibility of the shipper, not the recipient.
  • Be suspicious of emails coming from known sources. It is very easy to spoof an email address. Just because a family member or a friend sends an email with an attachment or a link doesn’t mean it’s legit. Ask yourself “Self! Why would so and so be sending me an Excel spreadsheet?” Be wary my friends.
  • When on any social media (Facebook, Twitter, LinkedIn, etc..) be very careful of the information you post. The bad guys are monitoring all those sources very closely and will not hesitate to scrape any data they can get their grubby little paws on.
  • And make sure you have a good anti-virus and anti-malware program installed. And keep it updated. AND scan your PC on a regular basis.
  • Finally, NEVER, NEVER, EVER post information such as your phone number, your email address, or your home/work addresses on a public forum such as Facebook. You’re just inviting someone to steal your identity.

These exploits are not limited to Windows PCs (although since Windows has the biggest share of users in the world they get targeted the most). There are exploits for Mac/Apple (including iPhones/iPads/iPods), Android, Linux, you name it. Someone has written an exploit for that operating system.

If you have any questions about PC security, please leave a comment!

So let’s be careful and happy internetting! (Yeah I made that word up)

Peace,
B

EDIT:  This link came across my Twitter this morning. It will give you a tool to see if your data was “shared” in the Cambridge Analytica breach.  Click here for the link (you do need to be logged into your Facebook account for it to work).

 

Twitter  Facebook

Scary Email Phish

(In case you are not aware of what a “phish” is, in broad terms, it is an email designed to make you click on a link, or open an infected attachment. Once the link is clicked or that infected attachment opened, your machine (and this works on Windows, Apple, and Linux) will become a “host” for a variety of nefarious activities.)

This information came from one of the vendors we use at the city, KnowBe4. We use the tools they provide to send simulated phishing attacks to all our employees. It’s one of the fun aspects of my job. Here is a very specific phish threat they sent a notice about. I felt it important enough to pass along.

I was alerted by a customer about a really difficult scenario that’s becoming all the more frequent. While there’s probably little that can be done in terms of tuning your spam filters and endpoint security tools, new-school security awareness training can make a difference. Here is the story:

“Over the past few months, we have been hit with increasing frequency with an attack that follows this 5-step pattern;

  • A known vendor or customer falls victim to a phishing attack. Their email credentials are compromised, and the “bad guy” gets access to their email account.
  • They start by changing the password, so that the victim no longer has control.
  • They then comb through past email correspondence, and using the victim’s account, signature, and logo, send out targeted emails crafted to closely resemble legit correspondence they have had with our company in the past.
  • Depending on the “bad guy’s” dedication to his craft, these could be fairly generic, or extremely specific. We’ve received one with an inquiry that referenced a specific real invoice # for that individual.
  • The email always includes a spreadsheet or PDF. The name can be generic, or can be really specific. We’ve received one titled with a specific real invoice # for that individual.

Because these emails are coming from a real email account for a real business partner, they are very hard to identify, and in some cases they are literally impossible to detect, as they are carefully crafted copies of past legitimate emails. Naturally, there are a few that cast a wide net, so they are more generic and often contain corrupted grammar or spelling, but others are indistinguishable from real emails.”

What To Do About This Threat

Granted, this is a frustrating and dangerous situation, as the majority of the red flags users have been trained to watch for simply aren’t present if the scammer uses a highly targeted approach like this.

However, there is one cardinal rule that you need to stress with your users to protect against a scenario like this: DID THEY ASK FOR THE ATTACHMENT?

If they did not, before the attachment is opened, it’s a very good idea to double check using an out-of-band channel like the phone to call and ask if they sent this and why it was sent . There is little else that can be done.

Yes, that is a little more work. But also, better safe than sorry. You have to constantly work on and reinforce your security culture, anywhere in the world.

As you can see, this is very scary. Especially in a corporate environment. The biggest thing to take away from this is if you get an email with an attachment THAT YOU DIDN’T REQUEST, DO NOT OPEN THE ATTACHMENT! This holds true even if you recognize the sender. The sender field on an email can be spoofed very easily.

So, as I’ve said before, keep your antivirus/antimalware up-to-date, and scan your machine on a regular basis. One of the catchphrases of KnowBe4 is “Think Before You Click”. Wise words to live by.

Happy and safe interneting my friends.

Peace,
B

Twitter  Facebook

Not That I’m Counting Or Anything

But on 25 May 2021, I will turn the magic age of 62 1/2 years old. Provided ol’ 45 doesn’t change the retirement age, on Friday 28 May 2021 I am retiring (told the boss I’d finish out the week just to be nice). I’ve already done my 20 years in the Army, and quite frankly, I’m done. Stick a fork in me.

The current countdown (give or take a few seconds since I took the snip)..

time

But like I said, I’m not counting down or anything.

Peace,
B

P.S. Yes I know it’s a long way off, but these “Stupid End Users” I deal with day in and day out required me to put the countdown on my PC so I can see the light at the end of the tunnel.

P.P.S. I’m always worried when I click the spell check button on the WP editor and it says “No writing errors found”. I think it’s just fucking with my mind…

Twitter  Facebook

 

PC Security… Again

<rant>

So once again here I am at the hands of Stupid End Users.  I have to keep reminding myself that these fools pay the bills.

I want to make one thing perfectly clear. INSTALL ALL THE SECURITY UPDATES FOR WHICHEVER OS YOU HAVE (Windows, Apple or Linux). Nothing and I mean NOTHING is more critical to the smooth operation of your computer (and even your smartphone – this applies to Android and Apple phones as well) than keeping these up-to-date.

Case in point. I am working on a laptop for one of my co-worker’s son. He claims the screen went blank “while doing school work”. Neither dad nor I buy it. Right now, his screen doesn’t work, the mouse and keyboard are not functioning properly (even with USB versions). I could not do anything (since the screen was black) without plugging in an external monitor and resetting the BIOS (the Basic In and Out System – what controls almost everything on the motherboard) to recognize the second monitor.

I still cannot get any of the usual tools I would use to scan the system for viruses (virui?), check the hard drive for errors, or even check the display properties. All of those options are missing from the system.  Normally I would do a “System restore”. This is a very nice feature that Microsoft added some time ago (in Windows ME – probably the only good thing to come out of that version of Windows). Since this machine belongs to a college student, there is a real good chance he was doing something “he shouldn’t have been doing”.

No matter how good your anti-virus/malware is if you visit “questionable” sites (and I’m not talking strictly porn – many download, or ‘warez’ sites are riddled with viruses) you run an elevated risk of getting an infection. There is an increasing problem of sponsored ads on respectable websites that are pushing viruses without you doing anything. We refer to these as “drive-byes”.

Normally you can access System Restore through the Control Panel and “Advanced Features”. Naturally, that’s missing on this machine as well. The other way to get to System Restore is by booting into “Safe Mode” and running it from a command prompt (the old DOS black & white screen where you have to type everything. Oh how I miss those days.) But for whatever goddamn reason Micro$oft took the “F8” feature out of the boot cycle in Windows 10. In previous versions, you could hit “F8” while the system was booting to be presented with a menu of boot options or just use “F5” to go straight into Safe Mode. Micro$oft, you made a stupid, stupid, stupid decision to remove that.

So now, 3 hours of working on this machine and I tell it to reboot, hoping (beyond hope) that at least the mouse and keyboard will work. What happens? My options are “Apply Updates and Restart or Shutdown”. So now I’ll have to wait for it to apply who knows how many updates before I can go back to troubleshooting. (edit: so far 90 minutes on the “Getting Windows Ready” screen).

There is a very good chance that if these updates had been applied when first available (the last update from Micro$oft was 2 weeks ago), what has crept into this machine may have been prevented. Even though this machine has a reliable Anti-virus installed (I cannot tell if it’s up-to-date though), without these security patches something can get through.

Wifey’s® office will not install any updates for fear it will “break” a program or something. Now, yes, it’s true. M$ updates have been known to cause havoc. But when that happens it’s (usually) easily reversible. A simple “roll back” (sometimes you need to go to safe mode) is all it takes. And M$ is pretty good about fixing those bad patches, either by sending a remote uninstall or an updated patch within 72 hours.

Second example.

Working on another laptop (this one city owned). The user claims the screen “scrolls on its own”. Looking at the machine when he brings it in (interrupting lunch as usual), I see it is doing just that.

Looking a bit deeper I see that there have been no updates applied to this machine since it was issued to the user almost one year ago. Now this machine could be considered “mission critical”. But instead of being out in the field, where it’s needed, and up-to-date, it’s sitting here on my desk slowing applying a years worth of updates. One update at a time. Because that’s how fucked up this machine is.

It not only needs updating to the latest version of Windows 10, it needs every security update since the beginning of time.

Also, keep any Anti-Virus and/or Anti-Malware product you use up-to-date (you do have an Anti-Virus/Malware program installed, Right?? RIGHT???), and scan your machine on a regular basis. There are many excellent free choices out there, pick one, any one. My favorite is Malwarebytes (I do not get any money from them, but I’ve been using their product for over 10 years without a single infection). They have both a free and a paid version, I HIGHLY recommend the paid version. Last I looked, if you download the free version you get a 2 week trial of the paid version, so it’s worth a look. The extra benefits of the paid version make it a good investment for your PC.

Malwarebytes has blocked very many of the “drive-by” ads I mentioned above. I will get either a little notice that says “access to <website name> blocked”, or just a blank spot on the webpage where the ad would have been.  You can also look into an “ad-blocker” for your web browser that can plug into either Chrome or Firefox (I’m not sure about Safari as I don’t have a Mac). IE and Edge users are out luck. Drop those and go with either Chrome or Firefox (I like and use both of those).

</rant>

I apologize for the rant, but it has been Monday all month here at work. My frustration level is quite high for many reasons, just not here at work. (Don’t ask me about yesterday’s useless dentist appointment)….

Peace,
B

I’ve Been Tagged!

My friend Kiersten over at Once Upon A Spine tagged me as part of the “Unique Blogger Award”. I have no idea what makes my blog unique, as it tends to meander its way around various subjects without ever really coming to any conclusions.

But anyway, first thanks for the tag Kiersten (and you folks should go read her blog. Some excellent books reviews that my Wifey® has found helpful.)

Here are the “rules”;

  • Share the link of the blogger that has shown you love by nominating you.
  • Answer the questions.
  • In the spirit of sharing, nominate 8 – 13 people for the same award (not sure I know that many bloggers).
  • Ask them 3 questions.

Onto the questions I was asked!

First – If you were to choose a different topic/theme for your blog, what would it be?

Since this blog has no theme or topic (hence the name Random Ramblins’), this is a bit tough for me to answer. When I first thought of coming back into blogging I knew I was not going to go back to the old technology blog I had years ago. Things have changed so much, I couldn’t keep up with it. My next thought was something about faith and my struggles with mainstream Christianity and why I’ve left it. But that was boring. And lots of people can explain it better than I. Then I thought food, who doesn’t love food? I love to cook and eat, but then health issues got in the way and I’ve had to change everything there, so that went out the window. How about mental health? I do have Bipolar Disorder type 2, some anxiety and social issues, but compared to what I’m reading on other blogs, mine is rather mild, or maybe my meds are just working better I don’t know. But again, better things are being said already.

But what I’d really like to do is humor. Back in the day (as in pre bipolar meds) I had a knack for telling the right joke at the right time. I could cheer someone up (even when I was struggling) with just a little humor. I had a flair for what my Soon-To-Be-Wifey® called “Gonzo Journalism” (a term stolen from the late, great Hunter S. Thompson, one of my favorite authors of all time). But since I’ve been on the meds, it seems my creativity level, my Gonzo if you will, has left me.  Maybe the meds are doing too much, or not enough, I don’t know.  But humor is what I’m shooting for.

Second – If you could befriend any author in real life, who would you choose? Why?

Another difficult question mainly because I feel I could do better with a really good copy editor than with an author. Come on, you’ve tried to read some of my stuff and just had to shake your head because it made no sense what so ever. Between the typos and the left out words…

But to answer the question, finally, I would choose Dr. Bart D. Erhman. From his Facebook page (easier to copy and paste – still looking for an editor you know) – Bart D. Ehrman is the James A. Gray Distinguished Professor of Religious Studies at the University of North Carolina, Chapel Hill, and is a leading authority on the Bible and the life of Jesus. He is the author of more than twenty books, including the New York Times bestselling Misquoting Jesus, God’s Problem, Jesus, Interrupted and Forged. I have read many of his books and I think his reasoning for leaving the Christian faith very closely echoes my reasons. Find him here. A close runner-up would be Dr. Pete Enns. I don’t have all his details, but he is an Old Testament professor. Find him here. One more to add to list is Dr. Amy-Jill Levine. A Jew who teaches New Testament. Such an oxymoron that I love it, plus she has a great sense of humor. Alas, she has absolutely no web presence.

Third – What’s the weirdest blog post you’ve ever written?

A long time ago (thinking about 2002) I wrote a post on my original website about my somewhat dysfunctional family. Nothing out the ordinary, just questions like “How did you get mashed potatoes on the back of your head son?”.  That site is long gone now, couldn’t find it on the “Wayback Machine” either. So for this blog, I’ll have to go with News You Can Use…No Not Really.

Questions for my nominees:

  • What is the one subject you wish you knew more about? A course you wish you had taken even just a seminar or such? And why.
  • Anybody alive or dead you’d love to have dinner with, and what would you talk about?
  • And since I ask this every time I get to sit on an employment interview committee; Star Fleet Academy or The Vulcan Science Academy and why? You’d be surprised how many supposed IT Geeks don’t understand the question.

Now I have to nominate folks… I don’t have many followers so I’ll only add these;

Sorry I don’t have more to add, but feel free to join in even if you’re not listed.

And free feel to send along any cheap copy editors, Wifey® says she won’t do it anymore. Well not really, she just can’t do it while she’s at work, and then I’d probably forget to post anything by the time I got home and she could edit it for me.

Peace,
B

P.S. Thanks again Kiersten!

Before and After

One of the “joys” of working in IT is how fast the technology changes.  Due to this phenomenon, most IT office seem to get cluttered quickly.  Mine is no exception. Add to that fact that I work for a city it only makes matters worse. We have to submit requests for bids from salvage companies and then have our city council approve a contract which whichever firm they decide on. The process can take months, if not longer.

When I left work last Friday, this is what the front “working” area of my office looked like;

MVIMG_20180112_162815.jpgMVIMG_20180112_162824.jpg

MVIMG_20180112_162833.jpg

This is about a 6-month accumulation of “junk” anything from dead monitors, printers, PC, cameras, mice, keyboards, battery backups, you name it.

Today we finally had a salvage company pick up most of the junk. There are still two more rooms in another building to pick up. Unfortunately, the guy ran out of room in his truck!

So here’s what the office looks like now;

IMG_20180115_134446.jpgMVIMG_20180115_134452.jpg

MVIMG_20180115_134458.jpg

Still some work to do, but much better.  My main concern is how quick will we fill it up again?

Peace,
B