Thursday, July 28, 2011

SECURITY - Cybercrime, Attacker Arrested

"British Police Make Arrest in Net Attacks" by SOMINI SENGUPTA, New York Times 7/27/2011

Excerpt

The British police announced the arrest on Wednesday of a 19-year-old man who they said was the spokesman of the online vigilante group Lulz Security, which has claimed responsibility for a string of attacks on the Web sites of government agencies and private corporations.

In a statement, the police said the man used the online alias Topiary and had been picked up during a raid on a residence in the Shetland Islands, the rugged archipelago off the northeastern coast of Scotland. The police said they were also questioning a 17-year-old but had not arrested him.

On Twitter, Topiary described himself as a “simple prankster turned swank garden hedge.” His missives were often facetious, suggesting the handiwork of someone who relished playful language.

Lulz Security, the offshoot of a larger and more amorphous hacker group called Anonymous, has said it was responsible for attacks on the sites of PBS, the Senate, the Arizona Department of Public Safety and a company associated with the F.B.I.

Friday, July 15, 2011

LINUX - Opinion, Mint vs Ubuntu

"Is Linux Mint a Better Choice than Ubuntu?" by Matt Hartley, Datamation 7/12/2011

Excerpt

Could the rapidly growing, user-friendly Linux distro attract converts away from the mighty Ubuntu?

For many advanced Linux enthusiasts reading this, I doubt that any recent changes to the Ubuntu desktop swayed you very much. Most of you already have had plenty of time to select alternative distros -- from Fedora to Arch Linux -- should you decide you want to.

Each distribution has its own set of advantages and differences. But for those people who cannot bear to part with some features that are considered to be unique to Ubuntu, Linux Mint might be a viable option to look into.

Linux Mint is perfect for new users

I've used Linux Mint GNOME edition off and on for a few years now. I have mostly used it in testing, as I'm really not the target audience for this distribution. Yet I continue to be impressed with how simple and user-friendly this desktop is. In addition, there are other factors that I think give Linux Mint a huge edge over Ubuntu for the casual user.

When running the Linux Mint software updating tool, you'll find things are numbered from 1 to 5. Packages numbered with a 1 are from Linux Mint developers while those packages with a "2" or higher come from Ubuntu or a third-party.

This numbering system all but guarantees that you won't hose a system with a bad set of updates from a rogue repository you added and forgotten about.

The next big thing with Linux Mint is how concisely the menu layout is presented. Unlike the old Gnome menus or even Unity, everything in Linux Mint is tightly laid out to make the entire experience as logical as possible. This menu setup makes migrating from another operating system much less overwhelming for newer users. For "old hat users" such as myself, I enjoy finding everything within reach. And if it's not visible, the provided search box takes care of anything that's missing.

Another huge push in the right direction for newcomers would have to be the introduction screen that appears on the first boot. Documentation, support, and so forth is presented right away. From there, items that I think should have been provided by Ubuntu out of the box are a given with Linux Mint.

Gufw (Easy to use Ubuntu Firewall) is installed and ready to go. There is a Mintbackup utility that not only offers the same functionality as SimpleBackup on Ubuntu, but it even backs up your application titles. This means you can take this list to another PC, run the program and install the same software list as before. That’s always been possible via the command line, and now it's nice to see this functionality provided for newer users with a friendly GUI.

Without any doubt, the biggest reason for me to love Linux Mint is that I can install software by name from the control panel -- with greater speed than I could have with apt-get.

Plus I can avoid all the package managers and directly type in the application's name, which presents me with the option to install it. Best of all, it's done very quickly and without the bloat of the software center. It's almost like being able to run the terminal without needing to know how. I love it!

It feels like Ubuntu

One of the biggest reasons I still rely on Ubuntu is because of the huge number of software packages available for it. If there's software for Linux, then there's an Ubuntu package somewhere for that application title.

Luckily, these same applications also work well for Linux Mint as it offers a release based on Ubuntu. This means that should Ubuntu's direction force me to drop it completely I can stick with the same applications.

Below is my laptop's Linux Mint-10 Desktop.

(click for better view)


NOTE: The calendar shown is Rainlendar which has Windows and Linux versions. Rainlendar Lite is freeware, Rainlendar Pro (allows calendar network sharing and MS Outlook sync) is shareware license-fee.

What I run on both my WinXP Pro desktop and Mint laptop is Rainlendar Lite.

SECURITY - Department of Defense 'Cyber Command'

"Is the U.S. Prepared for Battle in Cyberspace?"
PBS Newshour 7/14/2011


"Pentagon Gears Up for the Digital Battlefield"
PBS Newshour 7/14/2011

Monday, July 11, 2011

MALWARE - Rootkit Threat to NTFS Loader

I'm posting this because of the high danger of this type of malware.

"New Rootkit Infects NTFS Loader" by Lucian Constantin, Softedia 7/6/2011

Security researchers from Kaspersky Lab have identified a new piece of malware which writes malicious code to the NTFS boot loader.

The threat which Kaspersky detects as Cidox, features two rootkit drivers, one for 32-bit versions of Windows and one for 64-bit ones.

As part of its infection routine Cidox determines the version of the operating system and copies the relevant driver to the empty sectors at the beginning of the drive.

It only infects NTFS partitions and determines the active one by looking at the MBR code. It then proceeds to replace the Extended NTFS IPL (Initial Program Loader) code. The original one is encrypted and saved at the end.

This is part of a special technique that leverages Windows kernel features to load the malicious driver into the system.

The driver has the purpose of hooking into several processes including svchost.exe, iexplore.exe, firefox.exe, opera.exe and chrome.exe via a special DLL.

"This library modifies any browser output, substituting it with its own. As a result, the user sees a browser window displaying an offer to renew the browser due to some malicious programs allegedly detected on the system," Kaspersky's Vyacheslav Zakorzhevsky explains.

This threat is effectively a form of scareware, as the user is asked to pay for the browser renewal by sending an SMS message to a premium rate number.

In order to appear more convincing, there are custom pages for each browser borrowing design elements from other official ones displayed by their developers.

This is one of the most sophisticated scareware threats currently in the wild, but at the moment it only appears to target Russian-speaking users.

It seems that malware authors are increasingly using advanced techniques. One of the most dangerous threats at the moment, the TDL4 rootkit, infects the MBR (master boot record) in order to hide itself.

NOTE: Although I could NOT find the exact references to "Trojan-Dropper.Win32.Cidox" stated in the Zakorzhevsky article, Microsoft Malware Protection Center had the following references:

Note the Softedia article says "new" but I found references to NTFS Loader threats, at several virus sites, back in 2009.

Wednesday, June 29, 2011

HARDWARE - A New Type of Mouse

This is so evolutionary I had to post it

Celluon evoMouse - the evolution of the mouse

Thursday, June 16, 2011

SOFTWARE - MiniTool's Partition Wizard Pro

This is about a hard drive management tool form MiniTool, Partition Wizard Pro.

In the past (long, long time ago; in a galaxy far, far away) I used Partition Magic from Symantec. Problem, Symantec no longer supports it, AND it does not work with today's large hard drives. In fact it can screw-up your hard drive if you [OK] at the message when you launch Partition Magic (sees a non-existing problem with the drive).

I had to find an alternative because I had replaced my old HD0 (C: & D:) with a larger one and had to resize the partitions after recovering the image backups of each drive.

The answer is MiniTool's Partition Wizard Pro. The screenshot below is of my home system with my larger HD0 (aka Disk 2), C: highlighted, after resizing.

(click for better view)

For those that notice, the "Disk" order is what Windows sees after boot. "Disk 1" (H:Games4) is a Firewire drive and Windows sees that first.

CAUTION: You should run CHKDSK on the drive after your done. Example = chkdsk c: /f/v

List of features:
  • Resize/Move Partition: Easily resize/move partition without data loss

  • Create, Format, Delete Partition

  • Convert Partition format from FAT to NTFS

  • Hide and Unhide Partitions, set active partition, label drive letter

  • Merge Partition

  • Hot Extend Partition without reboot

  • Change cluster size without data loss

  • Support Linux Ext2, Ext3, Ext4 (file systems)

  • Partition Copy: Copy entire partition to unallocated space with high performance file-by-file, moving technology; backup or move data without any data loss

  • Partition Recovery: Scan disk to restore deleted or damaged partitions

  • Hard Disk Copy: Copy an entire disk to a different diskquickly and easily with data clone technology. Backup disk data without data loss

  • Support Windows 32/64 bit Operating Systems

  • Visually demonstrate your disk/partition configuration to preview changes before apply

  • Support RAID

  • Support single disks or partitions larger than 2 TB

  • Support up to 32 hard disks within one system

  • Set partition as primary

  • Set partition as logical

  • Rebuild MBR (must use if you copy a boot partition)

  • Convert Dynamic Disk to Basic Disk

  • Disk Surface Test

  • Partition Surface Test

  • Change Partition Serial Number

  • Change Partition Type ID

Friday, June 10, 2011

INTERNTE - IPv6 World Test

"World Tests IPv6: Why 4.2 Billion Internet Addresses Just Weren't Enough"
PBS Newshour 6/8/2011

What I've discovered:
  1. First and foremost, most of us desktop/laptop users will not have to worry about this, WEB sites you use today can still be accessed WHEN IPv6 becomes the world standard

  2. Most major OS are IPv6 ready (examples WinXP, Vista, Win7, Linux, Mac)

  3. Your ISP will have to implement IPv6, I found out that my ISP, AT&T will be doing that in the future and will notify me when they roll it out

  4. The hardware you use to connect to your ISP (DSL/Cable Modems, routers, etc) will also have to be IPv6 capable; some hardware MAY be able to upgrade firmware or you'll have to buy a new model

  5. The U.S., and most of the developed world, are IPv6 ready when it comes to the WEB as a whole

IPv6 is an extension of the IPv4 we use today, which is why most of us will not have to worry.

The industry I see as implementing IPv6 the fastest is the hand-held-devices; your iPad, Blackberry, new-gen cell phones, etc. This is the industry that is expanding the fastest and needs more IP addresses.

As for PC industry, newer products in the future will include IPv6 capable hardware.

Here's a link to Test Your IPv6 (from Netgear forums).

Tuesday, June 7, 2011

INTERNET - Apple's iCloud and Mac OS X Lion

"Apple Unveils New iCloud Music Service, but Privacy Issues May Lurk"
PBS Newshour 6/6/2011


Excerpt from transcript, security

RAY SUAREZ (Newshour): If I put my stored and accumulated content on the cloud, is it private?

CECILIA KANG, The Washington Post: Well, that's a good question.

The -- the devices will be encrypted. And that's what Apple said in passing. But there's a lot of questions as to your privacy and the security of cloud-based applications, Internet-based services. We have seen a lot of attacks on information, hacking attacks into Sony, Nintendo, PBS. You have seen a lot of these -- this -- the vulnerability of information that resides on the Internet.

And when I say it resides on the Internet, I mean that it resides on servers. You don't know where they are, but there are large data farms all over the country around the world, where bits -- your bits and pieces, the bits, I should say, of the music that you have, the videos that you have, the bits, the actual digital packets, they reside in these places that you don't really as much control of.

So, when you make this decision to switch to cloud-based applications, it's much easier, more convenient and often much cheaper. But there often is the -- there is the consideration of a tradeoff, perhaps, in that there may be less security involved. It's much safer when you have your information on your own computer that only you can access than on the Internet.

And your privacy is also perhaps in -- in question, in that more people, more companies have access to what you're doing. And they can see what you're doing online.


ALSO

As mentioned in video Mac OS X Lion (Wikipedia) (Apple) (links open in new page)

Thursday, June 2, 2011

CYBERCRIME - Latest on Hacker Attacks

"Gauging the Impact, Motivations of Today's Hackers"
PBS Newshour 6/1/2011


This is the related story mentioned in video

"Google Says Hackers in China Stole Gmail Passwords" by JOHN MARKOFF and DAVID BARBOZA, New York Times 6/1/2011

Excerpt

Google said Wednesday that hundreds of users of Gmail, its e-mail service, had been the targets of clandestine attacks apparently originating in China that were aimed at stealing their passwords and monitoring their e-mail.

In a blog post, the company said the victims included senior government officials in the United States, Chinese political activists, officials in several Asian countries, military personnel and journalists.

It is the second time Google has pointed to an area of China as the source of an Internet intrusion. Its latest announcement is likely to further ratchet up the tension between the company and Chinese authorities.

Tuesday, May 17, 2011

SECURITY - Global Cybersecurity

"U.S. Calls for Global Cybersecurity Strategy" by HELENE COOPER, New York Times 5/16/2011

The Obama administration on Monday proposed creating international computer security standards with penalties for countries and organizations that fell short.

While administration officials did not single out any countries in announcing the strategy, several officials said privately that the hope was that the initiative would prod China and Russia into allowing more Internet freedom, cracking down on intellectual property theft and enacting stricter laws to protect computer users’ privacy.

“The effort to build trust in the cyberspace realm is one which should be pushed in capitals around the world,” said Commerce Secretary Gary Locke, who will soon be taking over as President Obama’s ambassador to China.

The strategy calls for officials from the State Department, the Pentagon, the Justice Department, the Commerce Department and the Department of Homeland Security to work with their counterparts around the world to come up with standards aimed at preventing theft of private information and ensuring Internet freedom. A fact sheet released by the White House also promised that the United States would respond to attempted hacking “as we would to any other threat to our country.”

Attorney General Eric H. Holder Jr. called it a “historic strategy,” adding that “the 21st-century threats that we now face to both our national and international security really have no borders.”

Last week the administration released the domestic component of its new computer security strategy, increasing and clarifying the penalties for computer crimes, and giving the domestic security agency a clear mandate for the protection of the government’s own networks. That effort was intended to reverse a growing perception that penalties for attacks on government, corporate and personal computers had been relatively small.

In addition to giving the Homeland Security Department new authority over federal computer systems, the legislation calls for the agency to work with energy companies, water suppliers and financial institutions to rank the most serious threats and find ways to counter them. The law would also require each business to have an independent commercial auditor assess its plans and, in the case of financial firms, report those plans to the Security and Exchange Commission.

About time. We have international law enforcement agreements, and military security agreements, why not this one? While nations like China or North Kora will ignore this, that should not prevent the majority of nations to come up with a plan. It would protect national interests as well as individual people.

Thursday, April 28, 2011

SECURITY - Cybercrime With World-Wide Impact

"Sony PlayStation System Hacking Incident Highlights Web-Security Gaps" PBS Newshour Transcript 4/27/2011 (includes video)

Excerpt

RAY SUAREZ (Newshour): The latest episode involved millions of people around the world who use Sony's PlayStation video game system and who may have had their credit card information stolen in a hacking incident.

The intrusion caused the company to shut down PlayStation's Internet network a week ago. It provides access to online gaming, music, movies, sports and TV shows. Seventy-seven million user accounts were disconnected worldwide. But it wasn't until yesterday that Sony disclosed a hacker obtained information, including players' names, addresses, birth dates, email addresses, passwords and log-in names.

And on the company's blog, Sony spokesman Patrick Seybold said, "While there is no evidence at this time that credit card data was taken, we cannot rule out the possibility."

Near Sony headquarters in Tokyo, some said the breach may stop them from using PlayStation.

KAZUNORI SANO, resident of Tokyo (through translator): I will be afraid of playing with the game machine after hearing of this. I don't want my credit card information to be leaked out somewhere else in the world.

RAY SUAREZ: And in Australia, police urged PlayStation users to be vigilant.

DETECTIVE SUPERINTENDENT COL DYSON, New South Wales State Police Force: It would appear that the risk in relation to credit cards may be low. But if people have concerns, they should be talking to their banks and watching for unauthorized usage of the cards.

RAY SUAREZ: Some industry experts say the scale of the breach could cost the company billions of dollars.

THOMAS PUHA, "Pelaaja": This is going to have a very negative impact on a business that they have built up, because I think a lot of -- obviously, a lot of consumers will really be very wary of putting their credit card information back online or even buying anything.

RAY SUAREZ: Sony said it expects the PlayStation Network to be restored in a week. In the meantime, an outside security firm has been hired to investigate what Sony deems the malicious intrusion.

For a closer look at all this, we turn to Kevin Poulsen, senior editor at Wired.com. A former hacker himself, he's also author of a new book, "Kingpin: How One Hacker Took Over the Billion-Dollar Cybercrime Underground."

And, Kevin, for those people who aren't gamers, why would you have to load personal information into a game console in the first place?

KEVIN POULSEN, Wired.com: Well, a lot of gaming takes place now online. You have multiplayer games where you could play with or against opponents live in real time.

And, of course, a game console isn't just a game console anymore. You want to be able to download movies and other content. And all -- you pay for all of that, which means you have to give up this information.

RAY SUAREZ: Sony says it has no direct evidence that credit card numbers were taken, but it says -- quote -- "We cannot rule out the possibility."

When you have had a breach, when someone has been rifling around in your files electronically, can you tell what they have seen and what they haven't?

KEVIN POULSEN: There are usually -- there's usually some kind of trail left, yes. But if the hacker is good and took steps to cover his or her tracks, then it could -- it could take a while to extract that.

I imagine that's why Sony took so long to announce this. They were probably hoping to find better news. They were probably hoping to find evidence that the -- that information wasn't accessed. Now that they have brought in an outside company, I expect they will know a lot more than they do now, eventually. Of course, they -- they may know more than they're telling us now.

RAY SUAREZ: The PlayStation system has been down for over week, disappointing a lot of people who are frequent users.

Does that long-term shutdown tell you something about the seriousness of the breach, that they're not patching it, but rebuilding the whole network?

KEVIN POULSEN: Absolutely.

It's a really radical measure to take. And it's surely going to cost them a lot of money and a lot of fan loyalty. There are people that aren't even going care about the breach itself who are just going to be extremely angry that they were denied access to the PlayStation Network for so long. So, it's bad news all around.

If this had just been a casual intruder, a recreational intruder, some kid working from his bedroom, I doubt they would have taken this measure. So, they probably have some indication that this was a serious, focused attack.

RAY SUAREZ: Well, as we reported earlier, they got user names, passwords, various other kinds of personal information. What's the risk to account holders at this point?

KEVIN POULSEN: You know, the biggest risk is probably with the personal information, especially the passwords, because a lot of people use the same passwords everywhere.

So, that, coupled with your email address and your real name and your date of birth, the hackers will, if this was done for profit, then, all of that could wind up being sold on the black market, probably for a nice sum of money.

And then, whoever buys it, other computer intruders could use the information to try and hack into other accounts held by these PlayStation Network users. It could be anything from Facebook to online banking. You could use it to stage scams targeting the users in other ways.

So, it could be -- it could wind up that this becomes the first stage in a lingering problem that haunts users for a long time, if, in fact, that that was the nature of the breach.

Stress this quote, "You know, the biggest risk is probably with the personal information, especially the passwords, because a lot of people use the same passwords everywhere."

HINT, do not use the same password for all your online accounts.

Thursday, April 7, 2011

SECURITY - Vulnerability of Internet Certificates

"An Attack Sheds Light on Internet Security Holes" by RIVA RICHMOND, New York Times 4/6/2011

Excerpt

The Comodo Group, an Internet security company, has been attacked in the last month by a talkative and professed patriotic Iranian hacker who infiltrated several of the company’s partners and used them to threaten the security of myriad big-name Web sites.

But the case is a problem for not only Comodo, which initially believed the attack was the work of the Iranian government. It has also cast a spotlight on the global system that supposedly secures communications and commerce on the Web.

The encryption used by many Web sites to prevent eavesdropping on their interactions with visitors is not very secure. This technology is in use when Web addresses start with “https” (in which “s” stands for secure) and a closed lock icon appears on Web browsers. These sites rely on third-party organizations, like Comodo, to provide “certificates” that guarantee sites’ authenticity to Web browsers.

But many security experts say the problems start with the proliferation of organizations permitted to issue certificates. Browser makers like Microsoft, Mozilla, Google and Apple have authorized a large and growing number of entities around the world — both private companies and government bodies — to create them. Many private “certificate authorities” have, in turn, worked with resellers and deputized other unknown companies to issue certificates in a “chain of trust” that now involves many hundreds of players, any of which may in fact be a weak link.

The Electronic Frontier Foundation, an online civil liberties group, has explored the Internet in an attempt to map this nebulous system. As of December, 676 organizations were signing certificates, it found. Other security experts suspect that the scan missed many and that the number is much higher.

Making matters worse, entities that issue certificates, though required to seek authorization from site owners, can technically issue certificates for any Web site. This means that governments that control certificate authorities and hackers who break into their systems can issue certificates for any site at will.

Experts say that both the certificate system and the technology it employs have long been in need of an overhaul, but that the technology industry has not been able to muster the will to do it. “It hasn’t been perceived to be a big enough problem that needs to be fixed,” said Stephen Schultze, associate director of the Center for Information Technology Policy at Princeton. “This is a wake-up call. This is a small leak that is evidence of a much more fundamental structural problem.”

In the Comodo case, the hacker infiltrated an Italian computer reseller and used its access to Comodo’s systems to automatically create certificates for Web sites operated by Google, Yahoo, Microsoft, Skype and Mozilla. With the certificates, the hacker could set up servers that appear to work for those sites and try to view the unscrambled e-mail of millions of people, experts say.

Wednesday, March 30, 2011

HARDWARE - New nVidia GeForce GTX 590

nVidia GeForce GTX 590

Page includes demo shows and videos.

Here's the YouTube video
(suggest let full download before viewing)


One caution, when viewing the video pay attention to the requirements to get top performance for this video card. It is NOT for your common desktop system. Also, note the spec for DirectX 11 = this is intended for a Win7 system, PCIe.

Also, you may want to look at EVGA Precision Utility.

It's free and took me just minutes to get working to display what I choose (screen shot below). Just remember to enable the EVGA Precision On-Screen Display Server which allows OSD during game-play AND add your game EXE to list in the server dialog.

(click for better view)

INTERNET - Broadband Access in U.S.

(click for better view)

NOTE: In the full article, this is an interactive map

"Broadband Access: Exploring Internet Connectivity by U.S. Community Type" by Dante Chinni, PBS Newshour 3/28/2011

The federal government wants you to have access to a broadband connection. Badly. The Federal Communications Commission has held dozens of workshops and filed away more than 23,000 comments on its National Broadband Plan.

"High-speed wireless service is the next train station, the next off-ramp," President Obama said in February. "It's how we'll spark new innovation, new investments and new jobs."

That's an important set of goals for an economy that is still trying to climb out of the last recession, and most experts would argue an accurate one. It's one reason why more than $7 billion of the 2009 stimulus plan was dedicated to broadband expansion.

If broadband is indeed key to all those elements, how close is the United States to achieving a goal of universal access to broadband? Well, in some of Patchwork Nation's 12 county types, availability seems to be very close to reality. In others, however, much work remains to be done, according to data collected by Connected Nation and analyzed by Patchwork Nation.

In the counties holding the nation's most-urban areas, the Industrial Metropolis, more than 99 percent of the population has access to a broadband connection - figured here at three megabytes per second. But in more sparsely populated areas, the numbers are much lower. In the Mormon Outposts, largely located in the Mountain West, the broadband connection rates average about 80 percent.

But the story of broadband coverage is complicated.

Who's Plugged In?

Looking county-by-county on the map you can see the communities that are well positioned for the Web-based economic/cultural/political future. Places like the New York City metro area are saturated with broadband, while places like rural Arkansas have much spottier coverage.

When you dig further into the numbers, however, you see they are about more than just income or population density. Education plays a role, as you might imagine. The counties with the second-best connectivity rate are the collegiate Campus and Career locales. Nearly 97 percent have access to broadband there even though in terms of population density and income levels the Monied Burbs would seem likely to have better connectivity. They about $10,000 richer per household on average. The Burbs have a broadband access score of about 95 percent.

And while the exurban Boom Towns have a higher median household income than the aging Emptying Nests by about $5,000, the places are roughly look similar in their access to broadband - 93.57 percent versus 93.30 percent respectively. That may because some of those more removed Boom Town communities, newly sprouted towns, are harder to wire.

There are even differences among the most far-flung of our county types - the Service Worker Centers and Tractor Country counties. Tractor Country, which is less-wealthy and less-populated than the Service Worker Centers, is slightly better connected.

Why? As we have noted previously, Tractor Country communities in particular seem to show a stronger streak of civic pride than other communities. People in those places may tend to dislike the federal government, but they seem believe strongly in doing things for the community itself. That certainly is something we have witnessed in Sioux Center, Iowa, a Tractor Country community we visit.

So if you were to sit down with a mathematician and try to figure out a formula for connectivity - admittedly a very difficult challenge - it might look something like population density, plus education, plus income, plus civic engagement equals better access to broadband.

More to the Picture

Wiring far-flung places will not be cheap. Getting an exact cost is difficult, but the Web is littered with stories of ridiculous expenditures aimed at bringing small, rural locales fully into the digital age.

And access is only one part of the issue, the other is the ability to afford an actual connection. Some of the least-wealthy counties we look at are among those listed above that have the least access - Tractor Country, the Service Worker Centers, the Evangelical Epicenters. And while the cost of wiring those places certainly plays an issue, it may be they are less wired precisely because they are less wealthy. There may be less interest in broadband there.

The costs of broadband service vary by community and service provider, of course, but, on average the cost is about $41 a month, according to a survey from the Pew Internet & American Life Project done last August. That's about $11 a month higher than dial-up access the survey found - or over the course of the year an extra $150. That's not astronomical, of course, but it may feel like a lot in some communities that are struggling with the effect of the recession as well as long-term economic woes.

Patchwork Nation has not yet explored Internet usage by community type, but we have looked at issues like social media use in our book. And we looked at broadband access versus adoption in Ohio on our site, where we found sharp differences. The Emptying Nests were below 50 percent for adoption, even with their well-wired communities. And the Service Worker Centers and Evangelical Epicenters were at about 40 percent and 26 percent, respectively.

That means even if the broadband network is fully built out - not an inexpensive proposition - there will still be the challenge of helping those who cannot afford it and, along with that, there will be the challenge of convincing those who aren't as interested in life online that broadband is critical to their future - the key to that national transformation President Obama has outlined.

That may be the toughest sell in some communities where times are tight.

COMPUTERS - IBM's Light-Driven Computer

IBM's Light-Driven Processor Courtesy IBM
(click for better view)

"How It Works: The Light-Driven Computer" by Valerie Ross, PopSci 3/24/2011

The speed of light is as fast as it gets, and IBM researchers are exploiting that fact to give supercomputers a boost. They’ve made the smallest-yet silicon chips that use light to transmit information.

Most parts of the chip resemble those found on any other commercial chip. The parts that process or transform information—in other words, the parts that do the actual computing—still deploy electrons moving through semiconductor gates. But the interconnects, the lines that shuttle information between different areas within a chip, are drastically different. Instead of shuttling electrons, which can slow down significantly when the interconnects heat up, they shuttle light. That’s because light is easy to contain and loses less information as it travels. The researchers hope that this quick communication will make possible the first exascale computers—that is, computers that can perform a billion billion computations per second, 1,000 times as fast as today’s speediest systems.

One other benefit, says IBM engineer Will Green: The optical interconnects use significantly less power, making them cheaper to run. That’s particularly important given that supercomputers typically consume megawatts of power during operation. IBM, which has already made a working prototype, says a commercial version of the chip will debut in a supercomputer in around 2018.

Article includes interactive Light-Driven Computer demo.

Wednesday, March 2, 2011

SECURITY - Vicious Trojan, "System Tool"

This post it about a particularly vicious Trojan (malware) called System Tool on his Win7 PC.

This is a FAKE virus scanner. DO NOT buy it, that is what the hacker is trying to do, get your money and/or credit info.

What makes this one "vicious" is:
  • You cannot uninstall it normally

  • It is NOT listed in Add/Remove Programs

  • Prevents execution of normal antivirus and other utilities

  • Hides where it is installed

See screenshots of System Tool below:

Main Dialog
(click for better view)


It also replaces your normal background with a fake like example below or a blue background.

Fake Background (example)
(click for better view)


I found how to fix it at RemoveVirus.org which provides removal guides and links to legitimate removal software or sites.

The biggest help they provide are videos on how to remove a threat. One video was how to remove System Tool on a Win7 system.




Note that on the Win7 PC I fixed the desktop link and file location were not what is shown in the video. It was a link to a "program" (not System Tool) that my client did not install.

Suggest you add RemoveVirus.org to your Favorites.

Also, many antivirus utilities, like McAfee, provide Online Virus Removal services for a fee. So if you have an account, you can consider using the service if you can afford it.

Thursday, February 24, 2011

SECURITY - It's Not Just Your PC Anymore

"Security to Ward Off Crime on Phones" by RIVA RICHMOND, New York Times 2/23/2011

Excerpt

More consumers are buying smartphones. So more criminals are taking aim at those devices.

Criminals still prefer PCs for stealing personal data, bank and credit card account numbers as well as for running frauds. However, most PC attacks focus on Microsoft’s decade-old Windows XP operating system, which is slowly being replaced by the more secure Windows 7. Over the next few years, hackers will have to find new targets.

With smartphones outselling PCs for the first time — 421 million of the hand-held computers are expected to be sold worldwide this year, according to market analysts at IDC — the long-predicted crime wave on hand-held devices appears to have arrived. According to the mobile-security firm Lookout, malware and spyware appeared on 9 out of 100 phones it scanned in May, more than twice the 4-in-100 rate in December 2009.

In fact, the most practical rule for protecting yourself is to start thinking of the smartphone as a PC.

Most malicious incidents on mobile devices involve bogus phone or text-message charges or rogue mobile applications, of which there are now more than 500 varieties, according to F-Secure, a Finnish security firm. All these ruses require users to take some kind of action, like clicking to accept or install a program, so caution while using mobile devices can prevent most problems. (However, experts warn that automated attacks are possible and could emerge in the future.)

Most attacks happen in Eastern Europe and China. An overwhelming number — 88 percent, according to F-Secure — have singled out devices running Nokia’s Symbian operating system. Symbian is the world’s most commonly used smartphone platform, but Nokia said this month that it would be replacing it over the next few years with Microsoft’s Windows Phone operating system.

Early attacks, like the Cabir and Commwarrior worms in 2004 and 2005, caused little damage. But since 2009, attacks have grown more menacing. In September, hackers trying to steal money from accounts at a Spanish bank installed malicious applications on Symbian devices when they synced to home PCs infected with a version of the ZeuS malware. The application enabled criminals to reply to security codes sent by the bank to validate cash transfers.

Such assaults could be a preview of what is to come for devices popular in the United States. Criminals have attacked phones running on Google’s Android, Research In Motion’s BlackBerry, Apple’s iPhone and Microsoft’s Windows Mobile operating system software, suggesting that more is ahead.

Tuesday, February 15, 2011

COMPUTERS - Watson Who?

"A: This Computer Could Defeat You at 'Jeopardy!' Q: What is Watson?"
PBS Newshour 2/14/2011

Excerpt from transcript for techies:

MILES O'BRIEN, Newshour science correspondent: That's David Ferrucci, Watson's proud papa.

DAVID FERRUCCI, Watson Project, IBM: So, you're looking at 10 racks of power 750. So, there's 10 racks. There's 90 what they call power 750 servers.

MILES O'BRIEN: He introduced me to his silicon progeny.

DAVID FERRUCCI: So, overall, there's about 2,880 cores in that system, about 15 terabytes of RAM.

MILES O'BRIEN: For those of us who don't have a doctorate in computer science, Watson is equivalent to about 6,000 high-end home computers. But the secret sauce is the software that gives Watson the ability to understand language like no computer ever has.

NOVA - Smartest Machine on Earth (full show)

Friday, February 11, 2011

SECURITY - NSS Labs Report

Anti-Virus Utilities will never stop all malware. It's a race between protection software/hardware and publishers of malware.

The reason I'm posting this old article reference, there is a Newsnet post that quotes an Inquirer article, but the article did NOT provide links to NSS Labs source. Which is why The Inquirer is NOT a creditable source on this subject.

"NSS Labs Finds Most Endpoint Security Products Lack Vulnerability-Based Protection" Report NSS Labs 3/12/2010

Excerpt

NSS Labs, Inc., the leading independent security testing organization, today announced the results of its evaluation of seven popular consumer endpoint security products in protecting the vulnerability exploited in the recent “Operation Aurora” attack conducted against Google and at least 30 other organizations. This test—the first of its kind in the industry—was designed to identify which products truly shielded the underlying Microsoft Windows Internet Explorer vulnerability (CVE-2010-0249) against additional attack variants. Products that defended the vulnerability versus simply stopping a single variant or its malicious payload are considered to have a more effective security model.

In its Austin, Texas facility, NSS Labs created variants of the Operation Aurora attack and tested the anti-malware software to see which of the seven products stopped the exploits and malicious code payloads. Given the level of visibility of the attack and the time that has passed since its initial discovery, it was thought that most, if not all, of the products would cover the vulnerability. However, only one out of seven tested products correctly thwarted multiple exploits and payloads, demonstrating vulnerability-based protection (McAfee).

"Generally, there are multiple ways to successfully exploit a vulnerability," said Rick Moy, president of NSS Labs. “This test case underscores the need for IT security vendors to provide greater vulnerability-based protection. Rather than reactively blocking individual exploits or malware, vendors should focus on minimizing their customers’ risk of exposure by insulating the vulnerability.”

Products tested included:
  • AVG Internet Security, version 9.0.733

  • ESET Smart Security 4, version 4.0.474.0 (see caution below)

  • Kaspersky Internet Security 2010, version 9.0.0.736

  • McAfee Internet Security 2010 with SecurityCenter, version 9.15.160

  • Norton Internet Security 2010, version 17.0.0.136

  • Sophos Endpoint Protection for Enterprise - Anti-Virus version 9.0.0

  • Trend Micro Internet Security 2010, version 17.50.1366.0000

A full report of the test and its findings is available here. Additionally, Vikram Phatak, CTO of NSS Labs will be discussing the test and demonstrating the Operation Aurora exploit on March 13, 2010 at BSidesAustin, to be held at Norris Conference Centers.

COMMENT:
  • I do NOT recommend "Security" nor "Internet" suites for home users because they tend to be resource hogs

  • I DO recommend a good Antivirus, that is not part of a suite

  • At home on my WinXP SP3 desktop system I use ESET NOD32 Antivirus 4, which is very fast, uses little resources; and includes Antivirus, anti-Trojan, anti-spyware protection.

CAUTION: ESET recently came out with ESET NOD32 Antivirus 5 and since I could "upgrade" for free, I tried it. In the next 5 days after upgrading I had problems I never had before, and my system became unstable. I was using the same settings I had for NOD32 Av 4. I did try changing settings. But after 5 days of instability, I uninstalled NOD32 Av 5 and reinstalled NOD32 Av 4. My system is back to being stable.

With NOD32 Av 5 I noted from its look-and-feel, that is likely written with Win7 in mind. I suspect that ESET did not fully test Av 5 on a Win XP system.