Showing posts with label eBusiness. Show all posts
Showing posts with label eBusiness. Show all posts

Sunday, December 30, 2012

HOBBY LOBBY COUPONS: Show Your Support for the First Amendment

Michelle Malkin, among others, is encouraging Americans to support Hobby Lobby in its fight against Obamacare's unconstitutional abrogation of the First Amendment (see "Hobby Lobby Won't Violate Faith over Abortion Drugs").

It's going to be a long, expensive fight against Obamacare, and the company can use your help.


If you'd like to show your support with your pocket book, visit Hobby Lobby's coupon page for online and in-store deals.


Hat tip: BB.

Saturday, September 22, 2012

My time in the 11th circle of hell, otherwise known as trying to get customer service from the cable company

The terms customer service and cable company go together about as well as Robb Stark and Cersei Lannister. Which, if you don't watch Game of Thrones, means they go together like the Bears and the Packers.

After more than 15 years of utilizing the fine, upstanding services of my cable provider, the latest outage debacle drove me over the edge. It was the final straw. It broke the camel's back. It was the end of the line. The final nail in the coffin. And other metaphors that indicate just how pissed off I was.

Here's what transpired:

Sunday 9:00am - All cable services go out. Every box in the Blog-Bunker™ is suddenly unable to connect. I initiate a web-chat with a representative on the well-designed support website (that's sarcasm - finding customer support is roughly akin to a Where's Waldo). The rep indicates that indeed, there is an outage in the area.

Sunday 9:00pm - Still assuming the neighborhood is experiencing an outage, all of the cable boxes remain dead.

Monday 6:00pm - Return from work. Cable is still out. Now questioning whether this is a neighborhood outage. I ask a neighbor if they are experiencing any issues. Nope. There's been no outage at all on our street. The web-chat representative "feedback" was completely bogus.

Monday 8:30pm - After at least four separate calls to, and web chats with, customer service -- and several escalations with "managers" -- the fastest anyone can get to our neighborhood is... wait for it... eight (8) days from now. I believe cable repair service at Bin Laden's compound in Abbottabad was faster. We put in our request, with the oh-so-fine-grained repair window of sometime, eight days from now. Despite several threats to cancel service, no earlier date was offered.

Monday 8:55pm - After ruminating on the conversations with "customer service", I've decided I've had enough. After more than 15 years of various debacles, this is finally the last straw. I decide that I no longer deserve the luxurious, 12-star customer service offered by the cable company.

Monday 9:03pm - I call the customer cancellation line. After a short delay; I am told that... wait for it... canceling service can only be accomplished prior to 8:30pm or after 9:00am. Can I put a name in a queue to be called on my cell when they open in the morning? The rep almost laughs in my face. Aren't government-regulated monopolies super?

Tuesday 12:18pm - I enter the "service downgrade" queue for my area.

Tuesday 12:25am - I get an agent, who tells me that her phone system is acting up and she can't access my information because she's in the wrong region of the country to service the account. Perfect. She says they've been having phone system routing problems -- do tell? -- and she will transfer me to the correct queue.

Tuesday 12:28am - The new rep, who I believe is speaking into a diving mask, says that she can't perform any transactions at the moment. The systems, it would seem, are down, and she is unable to make changes. I will have to call back. Is there an estimated time that the systems will be back up? I'll give you one guess and "yes" isn't it.

Tuesday 07:05pm - I enter the cancellation queue; and, as you might expect, they're not going to make it easy to cancel services.

Tuesday 07:29pm - After 15 minutes, I am able to convince the very nice customer retention specialist that I really do want to quit the cable service. Amazingly, they can schedule the home visit and shutdown this coming SUNDAY within a 1-HOUR WINDOW.

Stunning. They can show up within a 1-hour window on a Sunday to turn the service off. To fix something? Not so much.

I did a quick, back-of-the-napkin estimate and discovered that I've probably spent about $36,000 with the company over the last 15 or so years. So the lifetime value of a typical customer is significant.

In fact, the company should call their "customer service" area the "customer annoyance" department, because I missed out on the actual "service" part and they seem to treat customers as a bother than anything else.

I'm interested in your opinions. Am I the one being unreasonable here?

* * * * * * * * * * * * * * * * * *
The most terrifying aspect of this debacle? There's at least a tiny bit of competition when it comes to television services. You can opt for DirecTV or Dish Network. You can get a broadband Internet connection and try Roku or a similar, IP-based service. Some lucky consumers even have two cable providers.

Now I ask you: can you imagine the customer service you'll get from the government-run healthcare system after Obamacare takes hold? Imagine the DMV the Social Security Office, only without the peppy and motivated employees. Faceless, nameless bureaucrats will be providing "customer service" and, thanks to civil service and public sector unions, firing a bad employee will require an Act of Congress.

When Obamacare is finished rolling out, there won't be any insurance companies left. A company forced to cover a pre-existing condition is somewhat akin to a home insurer having to cover a house after it's been set afire. Whatever you may call it, it's not insurance.

I have seen the future of health care: it's like cable customer service, only with your family's life at stake.


Thursday, August 9, 2012

Wonderful: Facebook moves into online gambling

I didn't think running an electronic gambling establishment (even for other countries) was legal in the U.S., but what do I know?

Facebook has launched a bingo game that uses real money, only for users over age 18, in the UK. The "Bingo & Slots Friendzy" app has 90 slot machine and bingo games that take real money, not Facebook Credits.

The move could be a money maker for the company as Facebook takes 30% of the revenue. UK-based Gamesys, the app developer, will take the other 70% of revenue. Certainly it seems a positive move given all the negative attention the company has recieved.

In true Facebook fashion, activity on the app will appear in users' timelines, but Facebook's age-gating and geo-location technology will restrict those posts from appearing to underage users and those outside the UK.

Kewl! And maybe the app will automatically update the player's status to read, "I've got a serious gambling problem... please arrange an intervention for me!"



Monday, July 30, 2012

"Savor their sweet tears of despair"

Whoa. Reason asks the provocative question: "Do 3D Printers Make Prohibitions Impossible?"

The Web thingies are buzzing with news that a 3D printer — sort of a first-generation Star Trek replicator — was used to make a gun that actually goes bang when you pull the trigger. Aside from the sheer cool factor, the development makes it clear that a wide range of bans, restrictions and prohibitions are becoming increasingly unenforcable.

From ExtremeTech:

An American gunsmith has become the first person to construct and shoot a pistol partly made out of plastic, 3D-printed parts. The creator, user HaveBlue from the AR-15 forum, has reportedly fired 200 rounds with his part-plastic pistol without any sign of wear and tear.

HaveBlue’s custom creation is a .22-caliber pistol, formed from a 3D-printed AR-15 (M16) lower receiver, and a normal, commercial upper. In other words, the main body of the gun is plastic, while the chamber — where the bullets are actually struck — is solid metal.

The lower receiver was created using a fairly old school Stratasys 3D printer, using a normal plastic resin. HaveBlue estimates that it cost around $30 of resin to create the lower receiver, but “Makerbots and the other low cost printers exploding onto the market would bring the cost down to perhaps $10.” Commercial, off-the-shelf assault rifle lower receivers are a lot more expensive. ...


...HaveBlue's schematic, which he used on what's considered a relatively low-tech StrataSys 3D printer in these fast-moving times, are available at Thingiverse.

Scientists at the University of Glasgow have used a relatively low-cost system to synthesize chemical compounds, with the intention of developing the means to create custom drugs. That may well mean the end of the orphan drug problem around the word, and very real price drops on pharmaceuticals... From the BBC:

Researchers have used a £1,250 system to create a range of organic compounds and inorganic clusters - some of which are used to create cancer treatments... Longer term, the scientists say the process could be used to make customised medicines.

They predict the technique will be used by pharmaceutical firms within five years, and by the public within 20...


[The process] also holds out potential for evading yet another class of legal prohibitions on recreational drugs.

Think of it — a world of plenty, with easy localized manufacture of almost anything you might need. It's a world in which "that should be illegal" becomes a punch line.

The next time your control freak friends start in on their latest litany of should-be-banneds, tell them that their arguments are now irrelevant. Tell them why. And savor their sweet tears of despair.

To paraphrase Nicholas Negroponte, we are seeing the convergence of the "atom business" (physical intellectual property) with the "bit business" (virtual I.P.).

And virtual I.P. is exceedingly difficult to protect, as the RIAA found out.


Hat tip: BadBlue.com/Money.

Thursday, July 26, 2012

Freelancer's Fast 50 Reveals Fastest Growing Tech Jobs

Interesting data from a roll-up of 190,000 tech job listings, with some observations after the table.

FREELANCER FAST 50 (FASTEST MOVERS)

Rank

Category

Q2 2012

Q1 2012

Growth

1

Word

1594

728

118.96%

2

Web Scraping

3232

2025

59.60%

3

Objective C

1809

1140

58.68%

4

User Interface / IA

1756

1234

42.30%

5

Mobile Phone

5709

4209

35.64%

6

iPhone

5112

3926

30.21%

7

iPad

2308

1826

26.40%

8

C Programming

2501

2068

20.94%

9

Android

3444

2859

20.46%

10

HTML5

2108

1763

19.57%

11

PDF

1647

1385

18.92%

12

Virtual Assistant

3770

3202

17.74%

13

jQuery / Prototype

2247

1927

16.61%

14

Data Processing

21274

18331

16.05%

15

Excel

22947

20282

13.14%

16

Software Architecture

5095

4530

12.47%

17

Shopping Carts

2647

2370

11.69%

18

Telemarketing

1104

999

10.51%

19

Banner Design

1810

1672

8.25%

20

Technical Writing

2250

2119

6.18%

21

Copy Typing

2835

2709

4.65%

22

Logo Design

5768

5569

3.57%

23

Linux

1270

1239

2.50%

24

Magento

1752

1723

1.68%

25

Social Networking

5308

5250

1.10%

26

Website Design

23098

22945

0.67%

27

Data Entry

30943

30805

0.45%

28

Illustrator

2096

2103

-0.33%

29

HTML

22281

22533

-1.12%

30

Twitter

2184

2213

-1.31%

31

Flash

2522

2594

-2.78%

32

PHP

29381

30254

-2.89%

33

Article Submission

2681

2792

-3.98%

34

Proofreading

1377

1447

-4.84%

35

Internet Marketing

13848

14667

-5.58%

36

AJAX

3709

3978

-6.76%

37

Report Writing

1220

1313

-7.08%

38

SEO

9397

10133

-7.26%

39

C++ Programming

1921

2074

-7.38%

40

Link Building

6529

7120

-8.30%

41

C# Programming

1935

2122

-8.81%

42

Article Rewriting

6298

6941

-9.26%

43

Blog

3581

4086

-12.36%

44

Customer Support

1022

1171

-12.72%

45

Facebook

6510

7537

-13.63%

46

Articles

11282

13064

-13.64%

47

Academic Writing

3579

4219

-15.17%

48

eBay

1042

1284

-18.85%

49

Classifieds Posting

661

826

-19.98%

50

.NET

2919

4748

-38.52%


Mobile and user experience (UX) is hotter than a firecracker.

In what may be an anomaly, Microsoft's .NET stack fell off a cliff this quarter.

Open standards, with HTML 5, Javascript and the ubiquitous jQuery, continue to dominate.


Friday, July 20, 2012

Chart: What your social networking usage says about your politics

Spotted at The Big Picture:


I have no idea what to make of this chart, other than the appearance that electronic commerce is powered -- in large part -- by conservatives.



Sunday, July 8, 2012

Keeping your online identity safe now that every tweet in history is going to be saved in the National Archives

Theresa Payton, writing at Infosec Island, has some solid advice for Twitter users.

We have mentioned before that Twitter will send every tweet to the National Archives and the Library of Congress, so watch what you tweet.

...New tools are popping up and they can unleash a treasure trove of data in moments.  For the 140 million and growing user base that tweets over 400 million tweets per day this might be a little more than alarming.

...In the early days, people were tweeting, uploading pictures with geocodes, doing location check ins.  Many felt like they were just sharing all this information with a small group of people.

But these tweets leave behind clues that tell bad guys, potential employers, people you might date, people you might want to forget a lot about you.

What you may not realize is, that all Twitter accounts are searchable.  To test it on yourself and loved ones, try a tool like Topsy  http://topsy.com/

Tips to Stay Safe:

1.  Tweet about a location AFTER you leave

2.  Think about the tweets you do, do they show a pattern of behavior that puts you in the best light for those that don’t know you?  do they provide patterns that you would not want a bad guy to see?

3.  If you post photos make sure geocodes are turned off unless you like someone tracking your digital tracks.

RESOURCES:

Here are a few of the Twitter search tools out there:
  • If you want to look for local tweeps that leave their location information turned on, check out Nearby Tweets: http://nearbytweets.com
  • If you want to see what tweets are the most popular, try searching on Tweetmeme: http://tweetmeme.com
  • Anyone that wants to track tweets by a specific location, including one on a Google Map, try Areaface: http://www.areaface.com

In general, disclose as little about yourself online as you possibly can. And a little misinformation always helps too.

Wednesday, June 27, 2012

Don't click on this!

After all, it could be a social-engineering attack.

McAfee and Guardian Analytics have revealed the results of a months-long study that uncovered a global financial services cyber-crime operation. "Operation High Roller" targeted the online banking accounts used by high-net worth individuals and companies.

The attacks ranged from the EU, to Latin America, and most recently to the U.S. All sizes of banks were targeted, from global institutions to local credit unions. As for the size of the thefts: "the total attempted fraud could be as high as €2 billion."

Initially, the infection pattern seen in Europe was similar to other SpyEye and Zeus fraud activities, but performed hands-free, automated transactions. This is the standard flow:

• A Phishing email is sent to individuals or businesses that bank with a specific financial institution
• The email contains a disguised link. When the victim clicks the link, they visit a web page that starts a malicious sequence:
  – The page contains a blackhole exploit kit or other similar framework. The kit will look for an appropriate vulnerability in the victim’s browser, and upon finding one, will load exploit scripts that compromise the victim’s computer.
  – The exploit script installs a Downloader Trojan.
  – The Downloader Trojan then will install SpyEye or Zeus on the victim’s device.
  – The next time the victim logs into online banking, the malware will check certain parameters, such as the type of accounts and account balances. If the client parameters are what the malware is seeking, the SpyEye/Zeus Trojan contacts the command and control server and pulls down the appropriate web inject for the victim’s financial institution. The web inject carries a JavaScript payload.
• The fraud process starts when the account holder subsequently attempts to log into his account from the infected computer
• The victim sees his standard, genuine bank portal, but it displays the fraudsters’ custom JavaScript web injection to capture the information needed for the victim’s bank
• The injected script takes control of the session and contacts the fraudsters’ server for specific instructions. It may insert content within the session, such as a transaction field or error message. For example, as the victim logs in, he may be asked to answer a security question and get an error. The error message creates the delay that allows the fraudster’s software to perform the transaction.
• At this point the victim has not actually authenticated and typically is stalled with a “please wait” message for about 60 seconds (see Figure 4).


• If during the automated attack, the financial institution requests a transaction authorization number (TAN), the fraudsters’ client-side web injection displays a fake TAN page to the victim and the malware proceeds as follows:
  – The malware collects the TAN from the victim’s screen and presents the authentic TAN to the financial institution to enable the fraudulent transaction, while delaying the victim from accessing their account.
  – The malware uses the intercepted credentials to initiate a silent, separate transaction to a mule account (either individual or business) or in one case, a prepaid debit card.
  – The malware looks up a valid mule account from a separate database, automating a traditionally manual step in the process. The transaction is performed in a hidden iFrame, a parallel instance of the online banking session on the client that operates in the background. The code navigates to the transaction page and initiates an automated form submission that adds the mule information.
• The user is allowed to proceed with the session
• The mule withdraws the money and converts it to a Western Union or Liberty Reserve payment that he remits to the fraudster. The mule retains a small percentage of the take, and the money is untraceable within a few days.
To conceal the theft, the malware will stay resident in memory on the victim’s computer. It will alter the victim’s bank statement to show a false balance, remove line items associated with the transaction, and block printing of statements that would show the true account balance and transaction sequences.

Put simply, don't click on any email you don't have 100 percent confidence in. Even one from me.



Tuesday, February 28, 2012

Google offers $1 million reward to hackers who exploit Chrome

There's security and then there's security.

Google has pledged cash prizes totaling $1 million to people who successfully hack its Chrome browser at next week's CanSecWest security conference.

Google will reward winning contestants with prizes of $60,000, $40,000, and $20,000 depending on the severity of the exploits they demonstrate on Windows 7 machines running the browser. Members of the company's security team announced the Pwnium contest on their blog on Monday. There is no splitting of winnings, and prizes will be awarded on a first-come-first-served basis until the $1 million threshold is reached.

...At last year's competition, Internet Explorer and Safari were both toppled but no one even attempted an exploit against Chrome (despite Google offering an additional $20,000 beyond the $15,000 provided by contest organizer Tipping Point).

Chrome is currently the only browser eligible for Pwn2Own never to be brought down. One reason repeatedly cited by contestants for its lack of attention is the difficulty of bypassing Google's security sandbox.

If you're still surfing with Internet Explorer, I would recommend giving Chrome a try. It's fast, secure and free. You can download it here.


Hat tip: @KimZetter.

Friday, February 10, 2012

Time to short Amazon: Mistress of Disaster Jamie Gorelick Joins $AMZN Board of Directors

Oh, my: what could possibly go wrong with this?

Amazon board adds Jamie Gorelick, former Fannie Mae and DOJ official


Amazon.com just added a new board member: Jamie S. Gorelick, a veteran of the U.S. government and no stranger to controversy. The company announced the appointment in an SEC filing a short time ago. Gorelick, a litigator at the law firm WilmerHale, was a long-running U.S. Deputy Attorney General who... blah, blah, blah...

Gorelick is best-known for her leading roles in two epic, trillion-dollar catastrophes, which earned her the nomme de guerre "The Mistress of Disaster".

• In 2004, observers were "astonished" to discover that a key member of the 9/11 Commission had a fatal conflict-of-interest. Jamie Gorelick had served as a Deputy Attorney General under Bill Clinton from 1994 to 1997. It was later revealed that Gorelick had established a pre-Patriot Act "wall" that prevented the foreign intelligence and criminal investigative communities from collaborating. Gorelick's wall "specifically impeded the investigation into Zacarias Moussaoui", the so-called "20th hijacker."

• Where did she turn up after that delightful stint in Justice? Though she had no training or experience in finance, Gorelick was appointed the Vice Chairman of Fannie Mae and served in the role from 1997 to 2003. During that six-year period, she earned over $26 million. During Gorelick's tenure, FNMA suffered a $10 billion accounting scandal, an ominous harbinger of the firm's looming troubles. FNMA's 2008 collapse, of course, helped touch off the mortgage meltdown.

It's not often that one person plays key roles in two -- count 'em, two -- trillion-dollar disasters. Welcome, my friends, to the world of well-connected Democrat Jamie Gorelick.

You've been warned.


Wednesday, December 28, 2011

Harbinger of Future Events: New York Times Emails Millions of Subscribers to Tell Them Their Subscriptions Are Cancelled

Paul Krugman hardest hit:

The New York Times mistakenly sent an e-mail on Wednesday to more than eight million people who had shared their information with the company, erroneously informing them that they had canceled home delivery of the newspaper.

The Times Company, which initially mischaracterized the mishap as spam, apologized for sending the e-mail. The people who received the message represented a cross section of readers who had given their e-mail addresses to the newspaper, said Eileen Murphy, a spokeswoman for the Times Company.

...The e-mail urged recipients to consider continuing their subscriptions to The Times at 50 percent off for 16 weeks. The message sent off a flood of Twitter reactions and calls to The Times...

...She said the e-mail had been sent by a Times employee and not Epsilon Interactive, a third-party service the company uses to communicate with subscribers.

I'm thinking this is just the first step in a self-fulfilling prophecy.


The 10 Funniest Passwords Exposed by the Stratfor Breach


10 ABC News: jonathan.d.greenberger@abc.com:stephanopoulos
 9 Goldman Sachs: joseph.aiken@gs.com:derivative
 8 MSNBC: gary.nease@msnbc.com:Seaweed1
 7 Goldman Sachs: amy.lee@gs.com:password
 6 New York Times: kewald@nytimes.com:9295
 5 Soros? david.steinberg@soros.com:secret
 4 Fred Burton, VP of Stratfor: burton@stratfor.com:stratfor
 3 Standard Bank: ravi.bhatia@standardbank.com:ravi
 2 Control Risks: jennifer.harbison@control-risks.com:research
 1 Goldman Sachs: muneer.satter@gs.com:bulls***

Bonus Banking Password UBS: paul.brewer@ubs.com:1234



Monday, December 26, 2011

Breaking: Statement on the 2.7 million emails obtained from Stratfor

More than 48 hours after it was rooted, the website of intelligence firm Stratfor Research remains down. In fact, as of this moment, even its temporary server (showing an "Under Maintenance" page) is inaccessible, perhaps due to an ongoing denial-of-service attack.

Via Wikileaks, the following statement describes some of the motives for the compromise.

In the wake of the recent operation by which Stratfor's servers were compromised, much of the media has focused on the fact that some participants in the attack chose to use obtained customer credit card numbers to make donations to charitable causes. Although this aspect of the operation is indeed newsworthy, and, like all things, should be scrutinized and criticized as necessary, the original purpose and ultimate consequence of the operation has been largely ignored.

Stratfor was not breached in order to obtain customer credit card numbers, which the hackers in question could not have expected to be as easily obtainable as they were. Rather, the operation was pursued in order to obtain the 2.7 million e-mails that exist on the firm's servers. This wealth of data includes correspondence with untold thousands of contacts who have spoken to Stratfor's employees off the record over more than a decade. Many of those contacts work for major corporations within the intelligence and military contracting sectors, government agencies, and other institutions for which Anonymous and associated parties have developed an interest since February of 2011, when another hack against the intelligence contractor/security firm HBGary revealed, among many other things, a widespread conspiracy by the Justice Department, Bank of America, and other parties to attack and discredit Wikileaks and other activist groups. Since that time, many of us in the movement have dedicated our lives to investigating this state-corporate alliance against the free information movement. For this and other reasons, operations have been conducted against Booz Allen Hamilton, Unveillance, NATO, and other relevant institutions. The bulk of what we've uncovered thus far may be reviewed at a wiki maintained by my group Project PM, echelon2.org.

Although Stratfor is not necessarily among the parties at fault in the larger movement against transparency and individual liberty, it has long been a "subject of interest" in our necessary investigation. The e-mails obtained before Christmas Day will vastly improve our ability to continue that investigation and thereby bring to light other instances of corruption, crime, and deception on the part of certain powerful actors based in the U.S. and elsewhere. Unlike the various agents of the U.S. Government, the hacking team that obtained this information did not break down the doors of the target, point guns at children, and shoot down any dogs that might have been present; Anonymous does not resort to SWAT tactics, and this is simply one of many attributes that separate the movement from the governments that have sought to end our campaign and imprison our participants. Of course, such points as these will not prevent our movement from being subjected to harsher scrutiny than is given to those governments which are largely forgiven their more intrusive tactics by virtue of their status as de facto holders of power in a world that has long been governed in accordance with the dictate that might makes right.

Incidentally, many of us are more than happy to proceed according to that amoral dictate if we find it to be necessary. And, increasingly, we have found it to be so.

Barrett Brown
Project PM
irc.project-pm.org


Sunday, December 25, 2011

Post-attack: Stratfor Research website still down after 24 hours

The website of intelligence firm Stratfor Research remains down more than 24 hours after it was rooted and defaced.

A comment on ZeroHedge by "Osgo" seems to summarize some of the key issues.

I find it astounding how people who just have no f'ing idea about INFOSEC, Anonymous, 4Chan, or Lulzsec... who still think AOL is the Internetz... are suddenly Armchair Warrior Commando Supremo, ready to wreak havoc upon enemies of capitalism... actually thinking that WikiLeaks, etc..is some sort of black-ops, Soros-scheming, FEMA camp-making endeavor ready to enslave their family, firmly ensconced in their gated community where most of the cars are shiny and their kids a little too clean... get some f'ing perspective, people, this is the Internetz equivalent of you driving around in your old '73 Camaro with a few too many Oly's in you as you took out your neighbors mailboxes, laughing with glee, later discovering your erstwhile girlfriend's angora sweater along with the twin treasures within.

Stratfor's site wasn't updated, patched well or maintained in a way commensurate with their public image. Indeed, it was a public secret that anyone could read ALL the articles in Google's cache... what they just went through is typical... Podunk site from a few years ago grows exponentially without proportionate security measures that EXCEEDED growth. While they hired and promulgated new authors, contributors and analysts with a pantload of letters after their names, they 'prolly didn't hire enough IT/web developers/security folks 'cause let's face it...they're usually considered a cost center, not a name that would bring in new subscribers/biz/accolades. I seem to remember they had open positions for interns... not pro's... go figure....

Every org. has growing pains... but the pain point here? The manageable risk that was unfortunately overlooked by "America's Private CIA" endeavor? By promoting and evangelizing themselves as an alternate intelligence organization, they failed to take into account good OPSEC. Here we have hundreds of records soon to be available, dead-drop names, sovereign ID's, aliases and a Who's-Who of people and corps. who just don't wanna be found....easily cross-referenced with other public disclosures... that any counter-intel org. could use to their great advantage. At this point it may even be an issue of maskirovka, but certainly the intrusion in no way approaches a sovereign level of expertise, IMHO...

This has got to be a flat-out awful Christmas for everyone involved with Stratfor. The company's website is a crucial element of its marketing and service delivery arms; yet, as Osgo implies, the organization's I.T. function may have received short shrift.


Saturday, December 24, 2011

Screenshots: Stratfor Research Website Pwnt by Attackers

The website of intelligence firm Stratfor Research appears to have been defaced and then DOSed (suffered a denial-of-service attack) by attackers.

The message traffic (below) -- if accurate -- portrays a defiant IT manager offering a, eh, perhaps unwise challenge.

The Google cache recorded some of the content including shadow files and other sensitive info apparently rooted from Stratfor's servers. I've tactfully redacted some of the more sensitive info.

// OH STRATFOR. IF YOU ONLY KNEW WHAT ALL IS ABOUT TO GO DOWN.
// 'BUT WAIT', YOU ASK. 'IS THIS IT?' 0H N0, WE GOT MORE IN STORE...
// BUT FOR NOW, SOME INSPIRING WORDS OF WISDOM FROM IT MANAGER FRANK GINAC:

"You do realize how preposterous it is to suggest that stratfor simply
shutdown completely for 2 days, right? The plan that you've attached paints a
gloom and doom picture claiming no chance that such a move will succeed. Does
that really seem a rationale conclusion?"

// YOU DONT EVEN KNOW THE EXTENT OF THE GLOOM AND DOOM WE HAVE PLANNED, FRANK


"Attended the TakeDownCon security conference. Focus of the conference was on
wireless and mobile security. No vendors pushing product or service at this
conference. Instead, great presentations by renowned white hat hackers (good
hackers) and security experts. Bottom line is that no mobile platform is
secure, including the Blackberry, but there are best practices that minimize
the risk of their use within the enterprise. We will be incorporating these
best practices in our operation over the coming months."

// INCORPORATING PRACTICES FROM "GOOD WHITE HAT HACKERS"? HOW'D THAT WORK OUT?

"It blew my mind to discover that our email server backups are being stored on
the same physical server. I'm affectionately referring to these little
discoveries as 'Mooney turds'."

// SO SAD WE RM'D YOUR MAIL SERVER AND ALL BACKUPS, FRANK

"Most if not all of us use professional and social networking sites like
LinkedIn and Facebook. All offer levels of privacy ranging from wide open
where everyone can see your profile, activities, and posts to closed allowing
only your immediate connections (or friends) access. As a private intelligence
company we must all take extra care to protect our personal information from
those who would use that information to exploit us personally or
professionally. Although we don't have hard and fast rules on how to set your
privacy settings nor do we restrict use of such sites, I suggest that you
temper your need to share with prudence and consider the business that we are
in. It's also important to check your privacy settings regularly to ensure
that the sites you use haven't changed the meaning or scope of privacy
settings -- we've all heard or read the news regarding this practice at
Facebook. I suggest that you never include any information in your profile --
regardless of privacy setting -- that could be used to compromise your
identity. Specifically, never include: your birth date, your exact street
address (although this information can usually be found on the web quite
easily), your cell phone number, SSN or other government issued ID number
(that should be obvious), or any other information that someone could use to
compromise your identity if your account were compromised."

// EVEN WITH ALL THE BEST SECURITY PRACTICES LEARNED FROM THE "RENOWNED WHITE
// HAT HACKERS" WE STILL MANAGED TO STEAL ALL YOUR PERSONAL INFORMATION. UMAD?

Interesting, to say the least.

Update: Cryptome:

Subject: Important Announcement from STRATFOR
Date: Sat, 24 Dec 2011 19:49:58 -0500
From: STRATFOR

Dear Stratfor Member,

We have learned that Stratfor's web site was hacked by an unauthorized party. As a result of this incident the operation of Stratfor's servers and email have been suspended.

We have reason to believe that the names of our corporate subscribers have been posed on other web sites. We are diligently investigating the extent to which subscriber information may have been obtained.

Stratfor and I take this incident very seriously. Stratfor's relationship with its members and, in particular, the confidentiality of their subscriber information, are very important to Stratfor and me. We are working closely with law enforcement in their investigation and will assist them with the identification of the individual(s) who are responsible.

Although we are still learning more and the law enforcement investigation is active and ongoing, we wanted to provide you with notice of this incident as quickly as possible. We will keep you updated regarding these matters.

Sincerely,

George Friedman

STRATFOR
221 W. 6th Street, Suite 400
Austin, TX 78701 US

Update II: Police-Led Intelligence:

PLI is far more concerned about the state of the classified information provided by STRATFOR to the US Government... STRATFOR maintains separate classified and unclassified networks and information, and PLI understands that none of the STRATFOR data has been spared the attention of the hacking group. Of course, had STRATFOR placed any classified data on the server which we know has been hacked, they’d be in blatant violation of the laws of the US and of common sense, but it’s against the law why? Because it’s happened before.

If classified data has been compromised in the hack, it will create a larger impact – and response – than if it is unclassified commercial intel. In addition, Sabu, a leading member of the group, boasted on Twitter that... "Over 90,000 Credit cards from LEA, journalists, intelligence community and whitehats leaked and used for over a million dollars in donations..."

The AntiSec/LulzSec crowd, on the AnonymousIRC Twitter channel, has promised that this is the first of many attacks.


Thursday, October 6, 2011

In Memoriam: 10 Quotes From Playboy's 1985 Steve Jobs Interview

When the history of the personal computing era is written, Steve Jobs' name will appear more than that of any other single person, in my opinion. Rest in peace, Steve Jobs. This world will miss you.

10. We're living in the wake of the petrochemical revolution of 100 years ago. The petrochemical revolution gave us free energy... free mechanical energy, in this case. It changed the texture of society in most ways. This revolution, the information revolution, is a revolution of free energy as well, but of another kind: free intellectual energy. It's very crude today, yet our Macintosh computer takes less power than a 100-watt light bulb to run and it can save you hours a day. What will it be able to do ten or 20 years from now, or 50 years from now? This revolution will dwarf the petrochemical revolution. We're on the forefront...

9. A computer is the most incredible tool we've ever seen. It can be a writing tool, a communications center, a supercalculator, a planner, a filer and an artistic instrument all in one, just by being given new instructions, or software, to work from. There are no other tools that have the power and versatility of a computer. We have no idea how far it's going to go.

8 The most compelling reason for most people to buy a computer for the home will be to link it into a nationwide communications network. We're just in the beginning stages of what will be a truly remarkable breakthrough for most people... as remarkable as the telephone.

7 ...remember that first the public telegraph was inaugurated, in 1844. It was an amazing breakthrough in communications. You could actually send messages from New York to San Francisco in an afternoon. People talked about putting a telegraph on every desk in America to improve productivity. But it wouldn't have worked. It required that people learn this whole sequence of strange incantations, Morse code, dots and dashes, to use the telegraph. It took about 40 hours to learn. The majority of people would never learn how to use it. So, fortunately, in the 1870s, Bell filed the patents for the telephone. It performed basically the same function as the telegraph, but people already knew how to use it. Also, the neatest thing about it was that besides allowing you to communicate with just words, it allowed you to sing.

6 ...The manual for [the IBM PC's] WordStar, the most popular word-processing program, is 400 pages thick. To write a novel, you have to read a novel... one that reads like a mystery to most people. They're not going to learn slash q-z any more than they're going to learn Morse code. That is what Macintosh is all about. It's the first "telephone" of our industry. And, besides that, the neatest thing about it, to me, is that the Macintosh lets you sing the way the telephone did. You don't simply communicate words, you have special print styles and the ability to draw and add pictures to express yourself.

5 ...[Why we added a mouse to the Macintosh:] Pointing is a metaphor we all know. We've done a lot of studies and tests on that, and it's much faster to do all kinds of functions, such as cutting and pasting, with a mouse, so it's not only easier to use but more efficient.

4 ...We've done studies that prove that the mouse is faster than traditional ways of moving through data or applications. Someday we may be able to build a color screen for a reasonable price...

3 ...How come the Mac group produced Mac and the people at IBM produced the PCjr? We think the Mac will sell zillions, but we didn't build Mac for anybody else. We built it for ourselves. We were the group of people who were going to judge whether it was great or not. We weren't going to go out and do market research. We just wanted to build the best thing we could build. When you're a carpenter making a beautiful chest of drawers, you're not going to use a piece of plywood on the back, even though it faces the wall and nobody will ever see it. You'll know it's there, so you're going to use a beautiful piece of wood on the back. For you to sleep well at night, the aesthetic, the quality, has to be carried all the way through.

2 ...[Smaller portable computers] are OK if you're a reporter and trying to take notes on the run. But for the average person, they're really not that useful, and there's not all that software for them, either. By the time you get your software done, a new one comes out with a slightly bigger display and your software is obsolete. So nobody is writing any software for them. Wait till we do it... the power of a Macintosh in something the size of a book!

1 ...The original video game, Pong, captured the principles of gravity, angular momentum and things like that, to where each game obeyed those underlying principles, and yet every game was different... sort of like life. That's the simplest example. And what computer programming can do is to capture the underlying principles, the underlying essence, and then facilitate thousands of experiences based on that perception of the underlying principles. Now, what if we could capture Aristotle's world view... the underlying principles of his world view? Then you could actually ask Aristotle a question. OK. You might say it would not be exactly what Aristotle was. It could be all wrong. But maybe not.



Thursday, August 25, 2011

AT&T reveals T-Mobile acquisition truly about helping rural subscribers and killing competition but mostly killing competition

Consider this Exhibit 2,034 proving that Washington, DC is the world's capitol of crony capitalism.



AT&T Inc. was asked Wednesday for more details on why it needs to acquire wireless operator T-Mobile, following the disclosure—accidentally released by its lawyers—that it could have expanded its high-speed wireless service to most Americans for one-tenth of the T-Mobile purchase price...





...The request by regulators to AT&T highlights the central issue in the proposed $39 billion acquisition: whether the combined company would benefit consumers enough to overcome concerns that the deal could limit wireless competition...



...Earlier this month, AT&T sent a letter to the FCC about the merger, intending to protect sections of confidential data from the publicly available version. Lawyers accidentally filed an unredacted copy, which was available briefly on the FCC's website before it was removed at AT&T's request... The full version says that AT&T had considered and rejected plans to expand the network on its own to 97% of the U.S. at a cost of $3.8 billion. That's about a tenth of the cost of the proposed T-Mobile acquisition...


As an aside, this kind of blunder has the imprimatur of the Mistress of Disaster written all over it.



Of course, I feel certain that our completely aboveboard and ethical federal government would never permit AT&T to reassemble itself into a government-subsidized monopoly like the old Ma Bell. After all, the old telephone monopoly did its level best to crush competition, destroy innovation and shackle the Internet, once going so far as to threaten customers using WiFi routers that they were committing a 'federal crime'.



No, I'm sure that AT&T isn't trying to destroy competition through federal regulators. The fact that AT&T employs 93 lobbyists and spent $15.5 million lobbying last year alone is, I'm sure, purely coincidental.





Sunday, August 21, 2011

Surprisingly, government-run health care system results in massive disclosure of personal health and identity data

Isn't government-run health care neat?



Until recently, medical files belonging to nearly 300,000 Californians sat unsecured on the Internet for the entire world to see.



There were insurance forms, Social Security numbers and doctors' notes. Among the files were summaries that spelled out, in painstaking detail, a trucker's crushed fingers, a maintenance worker's broken ribs and one man's bout with sexual dysfunction...



...Southern California Medical-Legal Consultants, which represents doctors and hospitals seeking payment from patients receiving workers' compensation, put the records on a website that it believed only employees could use, owner Joel Hecht says...



...The personal data was discovered by Aaron Titus, a researcher with Identity Finder who then alerted Hecht's firm and The Associated Press. He found it through Internet searches, a common tactic for finding private information posted on unsecured sites.


Say, I've got an idea! Let's put all Americans' most sensitive health records online and let the government run the system!



What could possibly go wrong?




Friday, July 22, 2011

Time to reach 20 million users...

Google+ reaches 20 million users in only three weeks?

"I've never seen anything grow this quickly," said Andrew Lipsman, vice president of industry analysis at comScore. The only other site that has accumulated as many new visitors in a short period of time is Twitter in 2009, he said, "but that happened over several months."

...Of course, Google has a long way to go to reach the scale of Facebook Inc., which has more than 750 million users, and Twitter Inc., which has more than 200 million registered accounts...

...Google+ also has unique technology, such as a "hangouts" feature, that lets people do "video chats" using their computer webcams, speaking to numerous friends simultaneously. The company plans to include Google+ in its suite of online software for businesses...

Google's ability to group users is a decided advantage over Facebook. Whether it has legs, however, is an open question.