Friday, June 12, 2020

Storing Data Is a Miracle of Physics That We All Put Too Much Trust Into

We all store data on our computers. Whether you have family photos and text documents on your home computer, or databases and on-premises applications running your entire business, data is typically stored in exactly the same way. If you knew how delicate your data actually was, you’d never let a single file exist in one place ever again. Let’s explore that.

How Do Hard Drives Store Data?

A traditional mechanical hard drive, also known as an HDD, holds your data on small magnetic platters. These platters are layered on top of each other, with a small mechanical arm that rests above them. Think about a record player, with the arm and needle over the record, except you have many, many records stacked on top of each other.

Of course, a record player spins the record between 33 and 78 times per minute. Your hard drive typically spins the platters much faster, most of them clocking in at 7200 rotations per minute.

The platters spin so fast, that it creates a cushion of air that prevents the head of the arm from touching the surface of the platter while it spins. This is critical, because if the head (the needle, to continue with the record analogy) were to even graze the surface of the platter, it would destroy the data on the drive.

These hard drives are mechanical in nature. Just like your car, mechanical systems can and will fail eventually. The little motor in the drive can burn out, the spindle can seize up, and so forth. These issues will very likely make the hard drive inaccessible. Thus, your data is lost. Opening files, saving files, and general computer use (even web surfing) causes the hard drive to read and write data. You are always using it, and depending on its stability to protect your data.

(Of course, there are also SSD drives, which don’t utilize moving mechanical parts. These tend to be a little more shock resistant, but they aren’t immune to failure either.)

Yet, we trust these devices every single day. If you have a computer or a laptop, you likely have one or two of these inside it. Your servers tend to have many more. Many of us have external hard drives we use to store data to take around with us. If they are using a mechanical-based hard drive, all of our data is at the mercy of several rapidly moving parts and a thin cushion of air.

This leads us to ask:

Why Would You Ever Rely on a Single Hard Drive?

If your data is only stored on a single hard drive, consider it at high risk. It only takes one tiny issue to lose it all.

Fortunately, preventing data loss is easier than ever. We help businesses establish thoroughly tested, highly-trusted backup solutions that ensure that no disaster will be able to destroy your data. That includes storing a copy of all of your data on a separate device within the office, and a copy stored securely offsite that you can access at any time. This means even a major disaster like a fire or flood doesn’t cause data loss.

Monday, June 8, 2020

There’s a Reason Some Scams are Painfully Transparent

“Hello sir/ma’am, I am a member of royal [sic] family and I am in grave danger in my country. If you send me money to get out safely, I will share my great riches with you as reward.”
Scams like this one have become a punchline for many, which makes you wonder why they are still commonly used by cybercriminals. As it turns out, there’s a very compelling reason that they do so, one that’s been known for years.

Understanding Advance-Fee Fraud

The kind of scam that we’re referencing, officially known as advance-fee fraud, has been around for centuries. Many scams were conducted in the 18th and 19th centuries that involved letters sent to victims requesting a small amount of money, with the promise of a large reward in return. One such scam, known as the Spanish Prisoner, purported that the writer was trying to help smuggle a wealthy captive out of a prison in Spain and needed money to bribe the guards.
The famed French investigator Eugene Francois Vidocq included an account of a similar letter in his memoirs, and transnational scams have been charted from 1922.
The name “Nigerian Prince scam” comes from perhaps the most famous example, where a royal seeking to escape from some danger requests assistance in transferring their great wealth—with a significant cut going to the person who assists them, of course.
Once the Internet entered the equation, these scams became even more prevalent, as there were no longer postal costs restricting the number of messages that these scammers can send.

Why Are These Scams So Sloppy?

As we’ve established, these scams are something of a modern punchline. The premise of the scam alone has become an instant red flag for most people, which begs the question: why is it still used at all?
A few years ago, in 2012, a Microsoft researcher named Cormac Herley wanted to find out, and so he underwent a research project to dig into the tactics of the cybercriminals who launch these transparent advance-fee fraud scams. His research revealed a fascinatingly simple concept: these scams are effectively a hacker’s litmus test for promising victims.
Here’s the crux of the matter. False positives (or an incorrect assumption that something worked) influence tests and analyses of all kinds. For an attacker, they are anyone who is targeted but doesn’t ultimately take the bait. As cyberattacks require some investment from the perpetrator, the greater the number of false positives they target, the less worth their time a scam will be.
Through many complicated mathematical formulas and the analysis of assorted cybercrime statistics, Herley found that by mentioning “Nigeria” in the very beginning of a scam, it was possible for cybercriminals to only attract the most gullible people from the very beginning. This meant that the investment that was necessary for the rest of the scam was more likely to pay off.
By optimizing their target pool through outlandish stories and obvious spelling and grammar errors, scammers are simply taking the most economical option.
You can see Herley’s research article here for the full equations and details.

Protecting Your Business

However, this doesn’t mean that all scams are so obvious, so it is important that you and your team are aware of what to keep an eye out for. The Federal Bureau of Investigation has a few suggestions to help you and your users keep an eye out for advance-fee scams that Net It On can get behind:
  • If something sounds too good to be true, it is safe to assume it is.
  • If you receive correspondence from someone asking for money or information, go through the proper steps to confirm the message’s legitimacy through other means, like a phone call.
  • Have a professional go over any agreement you’re about to enter so that you can fully understand what it says.
As for your business, your team needs to be able to spot the warning signs that a message isn’t all that it says to be. This kind of activity is now known as phishing and comes in many forms.
To learn more about phishing and other threats (and how to keep them from becoming a problem for your business), subscribe to our blog! Of course, we’re always available at (732) 360-2999 to discuss your business’ cybersecurity needs as well. Give us a call today.call today.

Wednesday, February 13, 2019

SMBs Beginning to Embrace Augmented Reality

There are moments when a technology solution presents itself and is simply too valuable to pass up, but they are generally few and far between. One particular solution you can use to great effect is augmented reality, and we believe that with the right implementation and support, you can overcome challenges that the future might hold.
Understanding Augmented Reality
Augmented reality is all around us, whether we notice it or not. It’s what happens when your everyday surroundings are integrated with computer-generated content. This effectively adds to the experience and provides users with a new way to interact with the world around them. Some of these applications aren’t necessarily business-friendly, but augmented reality can be used in both a consumer and professional business environment. Some examples include the hit mobile game Pokemon Go, as well as the Snapchat filters used to turn selfies and other pictures into caricatures of reality, or even smart glasses that create a heads-up display of your notifications.
How AR is Used in a Professional Environment
One example is how smart glasses developer ODG were able to create an oxygen mask for pilots that used AR to showcase how visibility can be improved. ODG created the SAVED (Smoke Assured Vision Enhanced Display) to bypass the vision-obscuring smoke that would occur should he or she ever need to use the cabin-mounted oxygen mask. It simply shows an augmented reality display of the controls and outside view, providing more information to the pilot than otherwise might be available to them. Other examples include those that interact with Internet of Things data to show manufacturers when they are losing money or wasting resources on a new prototype. Doctors have been known to use AR-powered devices to scan a patient’s skin for veins before inserting needles. Even some of the largest forces in the world, including Walmart, the U.S. Army, and General Electric Healthcare, have all turned to AR for training purposes.
It’s only a matter of time until augmented reality becomes a permanent addition to the office environment. Virtual whiteboards, immersive video conferencing, and other solutions could all be viable options for businesses in the future.
A Shift
It’s possible that the future holds a transition from a solo AR experience to a shared one in which meetings can be held in a physical space but with cyber elements added to the fold. In fact, a brand called Spacial is already looking for ways to create these kinds of spaces to collaborate.

Monday, September 17, 2018

A Look at this Year’s Worst Cybercrimes

It’s fair to say that today's organizations are faced with more online threats than ever before. To properly manage the information systems that they depend on for productivity, redundancy, and operational management, they need to ensure that they are doing what they need to do to mitigate problems stemming from the continuous flow of threats.
To give our readers just a taste of what they are up against, we’ve decided to put together a list of the most devastating hacks, infiltrations, and malware attacks that have happened so far in 2018. Additionally, we provide some telling statistics that will put into perspective just how important your network security and cybersecurity initiatives are.
Public
January
  • The Department of Homeland Security was affected by a data breach that exposed information about 247,167 current and former employees.
March
  • Atlanta, Georgia was targeted by a ransomware attack called SamSam. This resulted in a massive problem for their municipal infrastructure. The ransom price given was $51,000, but Atlanta’s leadership refused to meet these demands. Overall, the numbers show that Atlanta has spent more than 10 times that number in the fallout of the attack. Some estimates place the actual cost of this event at nearly $20 million.
  • India’s national ID database, Aadhaar, leaked data of over a billion people. This is one of the largest data breaches in history. A user could pay 500 rupees, equal to about $7, to get the login credentials that allowed anyone to enter a person’s 12-digit code for their personal information. For 300 rupees, or about $4.20, users could also access software that could print an ID card for anyone associated with the database.
  • Cambridge Analytica, a data analytics company that U.S. President Donald Trump used to help his campaign, harvested personal information from over 50 million Facebook users without asking for their permission. Facebook hasn’t called this a data breach, but Cambridge Analytica has since been banned from using the service thanks to this event.
June
  • A hack of a U.S. Government-funded active shooter training center exposed the personal data of thousands of U.S. law enforcement officials. This also exposed which police departments aren’t able to respond to an active shooter situation.
Private
January
  • 280,000 Medicaid records were exposed when a hacker attacked the Oklahoma State University Center for Health Sciences. Among the information exposed were patient names, provider names, and full names for affected individuals.
February
  • An unsecured server owned by Bongo International, a company acquired by FedEx, leaked over a hundred-thousand files of FedEx customers. Some of the information leaked included names, drivers’ licenses, national ID cards, voting cards, and utility bills.
March
  • Orbitz, a travel booking site, fell victim to a security vulnerability that exposed 880,000 customers’ payment card information. There was also about two whole years of customer data stolen from their server.
  • French news site L’Express left a database that wasn’t password-protected up for weeks, despite being warned about the security issues regarding this.
  • 134,512 records regarding patients and financial records at the St. Peter’s Surgery and Endoscopy Center in Albany, NY were accessed by hackers.
  • MyFitnessPal, an application used by Under Armor, exposed about 150 million people’s personal information to threats.
  • The WannaCry ransomware claimed another victim in Boeing, which stated that “a few machines” were protected by Microsoft’s 2017 patch.
May
  • Thanks to Twitter storing user passwords in a plaintext file that may have been exposed by internal company staff, the social media titan had to force hundreds of millions of users to change their password.
  • An unauthenticated API found on T-Mobile’s website exposed the personal information of all their customers simply through the use of their cell phone number. The following information was made available: full name, address, account numbers, and tax IDs.
  • A bug found in Atlassian development software titles Jira and Confluence paved the way for hackers to sneak into IT infrastructure of several companies and one U.S. government agency.
  • Rail Europe, a popular server used by American travelers to acquire rail tickets, experienced a three-month data breach that exposed credit card information to hackers.
June
  • A marketing company named Exactis had 340 million records stolen from it, but what’s most shocking about this is that they had accumulated information about nearly every American out there. In response to the breach, there was a class action lawsuit made against the company.
  • Adidas’s website was hacked, resulting in a loss of a few million users’ personal and credit card information.
  • A hacker collective called Magecart initiated a campaign to skim at least 800 e-commerce sites, including Ticketmaster, for sensitive information.
That list of traumatic security issues all occurred in the first half of 2018. This doesn’t consider the major hacks that are still affecting people from 2017 and before. Some examples include the Friendfinder hack that exposed 412 million user accounts, and the well-documented Equifax data breach that leaked the financial information of over 147 million people. Here are some of the statistics to help put in perspective the state of Internet threats at present:
  • In 2017 over 130 large-scale breaches were reported, a 27 percent increase over 2016.
  • Nearly 1-in-3 organization have experienced some sort of cyberattack in the past.
  • Cryptojacking (stealing cryptocurrency) increased 8,500 percent in 2017.
  • 100,000 organizations were infected with the WannaCry ransomware (400,000 machines).
  • 5.4 billion WannaCry attacks were blocked in 2017.
  • The average monetary cost of a malware attack is $2.4 million.
  • The average time cost of a malware is 50 days.
  • Ransomware cost organization’s over $5 billion in 2017.
  • 20 percent of cyber attacks come from China, 11 percent from the United States, and six percent from the Russian Federation.
  • Phone numbers are the most leaked information.
  • 21 percent of files are completely unprotected.
  • 41 percent of companies have over 1,000 sensitive files left unprotected.
  • Ransomware is growing at 350 percent annually.
  • IoT-based attacks are growing at about 500 percent per year.
  • Ransomware attacks are expected to quadruple by 2020.
  • 7.7 percent of web requests lead to malware.
  • There were 54 percent more types of malware in 2017 than there were in 2016.
  • The cybersecurity market will be worth over $1 trillion by 2025.

Friday, May 4, 2018

What Android Oreo Includes

Android 8.0 Oreo has been creating some significant buzz since it was announced, and after a long wait, the mobile operating system has been released to a select number of devices thus far. However, more devices will soon be able to take advantage of the many benefits and features of Android 8.0 Oreo, with Android 8.1 rolling out for others.
Android 8.0 Adoption Rates
As of April 16, 2018, there was an increase in Oreo adoption (combining versions 8.0 and 8.1) of 400 percent since the rates were measured in February. Comparatively, Android Nougat (versions 7.0 and 7.1) saw a 2.3 percent increase, while all past versions saw a drop-in use. This is despite the trend for many to hold on to their mobile devices for as long as possible to reduce the financial impact of an upgrade.
Despite this, there are some limitations that particular device manufacturers have placed, restricting the devices that have received the update to Oreo thus far. So far, the devices to receive this update include:
  • Asus Zenfone 4
  • Asus ZenFone 4 Pro
  • Asus ZenFone 3 Max
  • Asus ZenFone 3
  • Blackberry KeyOne
  • Blackberry Motion
  • Essential PH-1
  • Google Pixel
  • Google Pixel XL
  • Nexus 6P
  • Nexus 5X
  • Nokia 8
  • Nokia 6
  • Nokia 5
  • Nokia 3
  • Honor 9
  • Honor 8 Pro
  • Honor 7X
  • HTC U11
  • HTC U11 Life
  • HTC U11 Plus
  • HTC 10
  • HTC U Ultra
  • Huawei Mate 9
  • Huawei P10
  • Huawei P10 Plus
  • Lenovo K8
  • Lenovo K8 Note
  • Lenovo K8 Plus
  • LG V30
  • Motorola Moto Z2 Force
  • Motorola Moto X4
  • OnePlus 5T
  • OnePlus 5
  • OnePlus 3
  • OnePlus 3T
  • Samsung Galaxy S8
  • Samsung Galaxy S8 Plus
  • Xperia X
  • Xperia X Compact
  • Xperia X Performance
  • Xperia XZs
  • Xperia XZ
  • Xperia XZ Premium
  • Samsung Galaxy Note 8
  • Samsung Galaxy S8 Active (on AT&T)
  • Xperia XA1 Plus
  • Xperia XA1
  • Xperia XA1 Ultra
  • ZTE Axon 7
In addition to these devices, there are others that have been confirmed to receive an update in the near future:
  • Asus ZenFone 4 Selfie
  • Asus ZenFone 4 Selfie Pro
  • Asus ZenFone 4 Max
  • Asus ZenFone 4 Max Pro
  • Asus ZenFone 3 Deluxe
  • Asus ZenFone 3 Laser
  • Asus ZenFone 3 Zoom
  • Motorola Moto G5S Plus
  • Samsung Galaxy S7
  • Samsung Galaxy S7 Edge
  • Nokia 2
  • Lenovo K8
  • Lenovo K8 Note
  • Lenovo K8 Plus
  • LG G6
  • LG G5
  • LG V20
  • LG V30 Plus
  • Motorola Moto Z
  • Motorola Moto Z Droid
  • Motorola Moto Z Force Droid
  • Samsung Galaxy A5 2017
  • Samsung Galaxy A3 2017
  • Samsung Galaxy Xcover 4
  • Motorola Moto Z Play
  • Motorola Moto Z Play Droid
  • Motorola Moto Z2 Play
  • Motorola Moto G4 Plus
  • Motorola Moto G5
  • Motorola Moto G5 Plus
  • Motorola Moto G5S
  • Samsung Galaxy A8 2018
  • Samsung Galaxy J3 Emerge
  • Xperia Touch
What Android 8.0 Oreo Has to Offer
This upswing in adoption rates only makes sense when the features that Android 8.0 offers are taken into consideration.
Picture in Picture Mode
While Android Nougat gave users the ability to have two applications display at the same time with Multi-window, Android Oreo is taking this screen-sharing capability one step further by enabling one app, perhaps something playing a video, to share the screen with a relatively much larger app.
Notification Dots
While there are Android themes that already offer this capability, Android Oreo will have the same ‘badges’ that indicate which apps have tried to notify you about something. In addition, by long-pressing the icon, you will be able to see the notification.
General Optimization and Improvement
Of course, a mobile OS needs to do more than add a few cool features to be considered a true update. Android 8.0 Oreo offers assorted improvements to user security, as well as the device’s speed and battery life. Furthermore, Android Oreo also enables a user to manage their notifications on a more detailed level, ascribing particular permissions to different apps based on case-by-case criteria.
Now that you have a general idea of what to expect from Android 8.0 and 8.1 Oreo, are you looking forward to leveraging the updated operating system in your mobile device? Let us know in the comments, and feel free to mention other improvements you’d like to see!

Thursday, April 5, 2018

Tech Term: What is a Dongle?

There are countless examples of words that have evolved to meet the needs of their times. Meat once referred to solid food of any kind before it came to mean the edible flesh of animals. The word nice once had many meanings that completely contradicted each other. Today’s Tech Term, dongle, is another word that has evolved, albeit at a faster pace.
There is no questioning that the term dongle is largely used in reference to technological devices, just as there is no questioning that “dongle” is an inherently silly word.
However, this silly word has become a constant in the world of tech, especially on the consumer side of things. Dongles can be found everywhere, from the adapters that allow headphones to be used with devices that are now made without headphone jacks, many of the streaming devices that can be found in the home could be considered dongles, and arguably any device that plugs into a computer via a USB port qualifies as a dongle.
Officially, the term dongle (if defined by its most common denominator in computer networking) is any small device that is plugged into a computer to allow a particular network connection to be made. We see them most often today in USB devices. However, this blanket term doesn’t include USB devices that serve as data storage devices. Instead, the term dongle applies to other USB devices, such as Wi-Fi dongles that connect a device to a wireless network, or a modem dongle that connects to 3G or 4G wireless Internet networks.
As for the name itself, there are a variety of theories, including that the term is simply a play on the work ‘dangle’ (which most dongles do), or that the term held some significance to the developers of the Commodore PET Computer, which was released in 1977 and used a device similar to a dongle to boost its memory.
Regardless, the dongle is a term that is ingrained in modern technology. For more tech terms, tips, and tricks, make sure you subscribe to this blog!

Have You Considered What You’re Really Losing When You Lose Your Phone?

Losing a smartphone can be a problem for anyone. For the modern business, it can really cause issues. Mobile devices are notorious for housing a lot of personal information, which makes them extraordinarily dangerous to lose track of. How much is at stake with mobile devices going missing; and, what kind of information is stored on these devices that makes them so dangerous to misplace?
To get started, let’s think about the information that’s being put at risk. Here is a list of information that could possibly be stolen from mobile devices--a surprising amount of data for most users, to say the least.
  • Payment information: The applications on your device could potentially be storing credit card numbers or bank routing numbers, which could become problematic if stolen. Hackers could make off with all of your precious, hard-earned cash.
  • Passwords and usernames: If you use your device’s web browser, it’s likely that you have passwords and usernames saved on it--even if it’s been done accidentally. These usernames and passwords can be stolen from the device, or used on the device by whoever is accessing it.
  • Application data: There are a lot of applications installed on your business’ devices, and these applications store lots of information that a hacker could have a field day with. Even if applications are locked behind a login screen, these accounts can be infiltrated if the login credentials are stored on the device
  • Cloud storage: Access to cloud storage is one of the best things about mobile devices, but if you lose one, you’ll be compromising any sensitive data that your account has access to. Any information that’s shared with your device will be accessible by whoever finds your misplaced device.
  • Social media accounts: If you have social media applications on your device, it’s likely that you have the password and username saved to the device. This means that anyone who finds your device will have access to your social media accounts, ready to use for whatever vile purposes they want.
  • Email: You’d be surprised by how much information you keep hidden in your email inbox. Think what would happen if any of your countless messages was accessed by a hacker who has found your smartphone. Now THAT’s frightening!
  • Contacts: You might not think the people you associate yourself with are valuable targets for hackers, but they certainly are. Contact lists for both business and personal use hold a lot of value, as it essentially becomes a list of potential targets to hit with phishing scams.
Keeping all of this in mind is of the utmost importance, especially if you want to make sure your mobile devices don’t become a liability in the event of a loss scenario.