Craig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity

Craig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity

By Craig PetersonBusinessNewsTech News
Download on the App Store

Craig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity episodes

  • Welcome! Why You Have to be Applying ALL Patches Not Just the OS ones plus more on Tech Talk with Craig Peterson on WGAN

    Welcome!

    Craig Explains Why companies believe that they are Completely Patched up and Why it means more than your Operating System.

    For more tech tips, news, and updates visit - CraigPeterson.com

    ---

    Read More:

    iOS 13.7 launched today with a new system for battling the pandemic

    Hackers are exploiting a critical flaw affecting >350,000 WordPress sites

    The accidental notary: Apple approves notorious malware to run on Macs

    Most IoT Hardware Dangerously Easy to Crack

    55% of Cybersquatted Domains are Malicious or Potentially Fraudulent

    Feds Can’t Ask Google for Every Phone in a 100-meter Radius, Court Says

    The Hidden Cost of Losing Security Talent

     

    Don’t forget Cybersecurity on Your Back-to-School List

    ---

    Automated Machine-Generated Transcript:

    Craig Peterson: [00:00:00] Hey, do you have a 99% patch rate? Gonna talk right now about why that is a load of UMHUM in every case that I've ever seen?

    Craig Peterson here and here we go.

    Hey everybody. Thanks for joining me today. this is something that I don't know if I can ever repeat enough, but I want to take a little bit of a different angle on this than I have before. Most of us know that we're supposed to patch. What do we patch? What are we using? You might turn on automatic updates on windows. You might have those turned on MacOS, of course, on your iOS devices. Maybe you've got an Android device it's less than two years old and still gets updates so you have that turned on. Here's the problem. I have yet to walk into a business that doesn't say that they have just a phenomenal patch rate.

    You know, so for instance, you'll walk in there and you say, how good are you guys at keeping up on patches?  Almost every last one of them says, yeah, almost a hundred. We're probably 99, 98% of the patches are up to date and we're just phenomenal. We're safe. Yeah, we're safe. don't worry about us. Yeah, we're safe. Don't worry about it.

     I've been in a couple of businesses and said that and then, they got nailed something awful and they were too embarrassed to call me back. When I talked to them later on, I found out what had really happened with them.

    Many people and many businesses are focused on that patch rate and that kind of makes sense. We have to make sure the patches are done, particularly the critical patches. But why is it that I go into a business and every business says, yeah, we're patched up. it might not be a hundred percent, but we're patched up. Every business says that.

    Yet I always find critical vulnerabilities when I poke around. When I do a scan. When we do these paid assessments to come up with an action plan for businesses. We scan their systems, which means their workstations, it also of course means there are servers and maybe other devices that are out there. I have never scanned a device that did not contain a critical vulnerability.

    Where's the disconnect? Why are businesses and people saying, yeah, we have this 99% patch rate? Yet I am continually finding major problems. It has to do with what's being patched. People are not patching the right thing. So let's look at a couple of different things here.

    First of all. When we're talking about workstations, desktops, laptops. Here are the four types of software that are attacked the most. Number one internet browser add-ins. How many of us have extensions on our browsers? Some of those extensions are in fact, malicious themselves. Internet browsers.

    Another big attack vector is operating systems. Of course, all of our office applications, all of our productivity stuff, software like I'm using right now for the radio show. All of this stuff gets attacked. But when we're talking about a 99% patch rate yeah. We're pretty much all patched up. What they're almost all always thinking about and talking about is patching the operating system and that's where things end.

    Now on the server-side, when we go into businesses, we're finding the webserver software, the database server, the operating systems on those servers, the remote server management stuff, like RDP, the active directory. Those are what is always being attacked. So why the disconnect? It's because it's difficult to patch everything.

    Microsoft, I already mentioned has the ability to automatically install updates. In fact, if you don't have the business versions, the enterprise versions of Windows, professional, you're forced to do updates. You don't even get to say when you want those updates to happen. If you're running iOS, on your iPhone, on your iPad, again, updates just happen automatically.

    But how about all of those apps? If you're getting those apps on your mobile devices, from the stores, like the Google play store or the Apple store, you were probably getting updates for your applications. If you're not getting them from there, you're probably not getting updates.

    So not patching the right thing is a very big deal.  I wanted to talk right now about one specific thing that people are not patching. Frankly, that is our web server. You've got a website, right? If you're a business, any size business, you've got a website. You have to have a website. You have to get the message out.

    Now, of course, you can have some emails from other things too, but we're going to focus on one thing right now, the website. Hackers are actively exploiting right now, a vulnerability in a WordPress plugin. Now, I mentioned our browser plugins are the extensions for our browsers and how those can be hacked in many cases.

    It's another vector, obviously for the bad guys to get on to our computers and really start messing around. in this case, we're talking about WordPress web server, which is the number one most popular web server out there, WordPress and there are more than 700,000 active installations of this. We are using it for our own little websites for our families, We're using it for our businesses. We're using it for our associations or organizations. This particular file manager plugin, which extends features for WordPress allows bad guys to run command and malicious software things, like scripts whenever they want to. Now, how many people are keeping their WordPress installation up to date.

    Are you keeping your flash UpToDate? Are you keeping your other Adobe software up to date? How about all of the other software you're running on your computers? I look at this computer and it's just astounding how much software I have installed here on my Mac that I use all the time.

    So the attackers are using this exploit to upload files that have these shell scripts in them that are hidden in an image. Makes it even harder for you to find.

    So we have to be very careful. We don't know the impact of all of this yet. It's probably pretty bad. There are some companies that are blocking it. We block it as well, but we're talking about millions of exploit attempts.

    Over the course of the last couple of weeks, that is pretty bad. And we're only seen about half of the sites out there. The WordPress sites actually patched up. So make sure you do the update. You have to inventory everything you have. Everything your enterprise uses. What software do you have? What is it installed on? Is it up to date?

    Don't just Willy nilly, allow people to install software on their computers, and don't do it yourself either. Every time you install software, you open up another potential way for bad guys to get in. Its something else you have to track. It's something else you have to inventory. It's something else you have to update. You have to upgrade.

    People are just downloading stuff, Willy nilly. And remember what was the very first thing I said, that's attacked frequently internet browser, add-ins. That means internet browser add-ins means that those wonderful little bars that people install on their browsers are, yeah, those are malicious much of the time. At the very least, they are providing something called adware that's tracking, where you're going. Sometimes it replaces the ads on the website shows you stuff. It clicks through to these not clickbait sites, but click through to make them money on ads that they're running.

    It's bad. We can't do it now. I wish we had more time. All right.

    Your listening to Craig Peterson.

    Stick around because when we get back, we're going to talk about an Apple problem with security this time.

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    10 min
  • Welcome! How app design libraries are defeating design security plus more on Tech Talk with Craig Peterson on WGAN

    Welcome!

    Craig explains how app design libraries are causing problems with the security of apps for some of the big tech firms.

    For more tech tips, news, and updates visit - CraigPeterson.com

    ---

    Read More:

    iOS 13.7 launched today with a new system for battling the pandemic

    Hackers are exploiting a critical flaw affecting >350,000 WordPress sites

    The accidental notary: Apple approves notorious malware to run on Macs

    Most IoT Hardware Dangerously Easy to Crack

    55% of Cybersquatted Domains are Malicious or Potentially Fraudulent

    Feds Can't Ask Google for Every Phone in a 100-meter Radius, Court Says

    The Hidden Cost of Losing Security Talent

    Don't forget Cybersecurity on Your Back-to-School List

    ---

    Automated Machine-Generated Transcript:

    Craig Peterson: [00:00:00] We're going to get into the guts right now of something called notarization. When it comes to our apps. What's Apple doing what's Google doing and how did Apple mess this is up so badly, frankly.

    Hey, you're listening to Craig Peterson. Thanks for joining me today. We've had a problem for a very long time when it comes to any sort of apps. I saw a funny meme about yeah about Bill Gates this week. It said Bill Gates couldn't even stop viruses and Windows. It's a really good point that Windows was never designed to be secure at all.

    When they came out with NT, that was their first attempt to design it like a real operating system. They took the design of VMS, basically of Dave Cutler and company that had been designed over a DEC - digital equipment. And they said, Hey, we'll use this as a framework. This really works. It's not a hack. Let's just make this work.

    Then, of course, Microsoft had his fingers on it. So they really messed it up. They wanted to be compatible with everything that they could possibly be compatible with in the past. In the past, Microsoft did not have the barriers walls. If you will between the apps between the operating system, between the hardware and the apps. They didn't have the appropriate protections in place. Programmers used some lazy mechanisms to get around the operating system, going directly to things like graphics cards, because the operating system just slowed it down and they couldn't do the graphics they wanted to do that way. So it's been a real problem, frankly.

    It's been a real problem for a long time in the windows world, and NT was supposed to fix some of that. It did initially, and then it didn't. Now they're trying to tighten up this whole thing. how do you, if you're Microsoft or Google or Apple, how do you protect the people who are using your products from some of this malicious software?

    What's the way to do it? What Apple has come up with is a mechanism and Google as well that signs the software. You might have noticed that if you are trying to install software on your computer or your Google device from a third party website, it will come up and say, can't be opened, It can't be installed. There are a few different messages that come up.

    In the case of Apple now, with MacOS Catalina, which is the latest Operating system. Although, there's another one that is about to hit and it looks like they're going to change the whole nomenclature to, with the next release, but in Catalina, Apple now requires what they call notarization for all apps.

    Any apps that you are installing on that computer need to be signed digitally by Apple. So the developer, when they write the software, they compile it, they sign it themselves. It's a whole public key cryptography thing. Apple takes that software and checks it and then signs it.

    Both Google and Apple are using automated systems that try to verify whether or not the software is malicious. So it'll go through this automated system and will try and figure out well, is there any malicious content? Are they doing things they shouldn't be doing? Are they making suspicious calls to the operating system? Is it trying to get into files that it shouldn't be getting into?

    Now, there are ways to hide things from these automated systems. In fact, obfuscation seems to be the norm when it comes to any program or programming anything. It's just absolutely amazing. It does look for code signing issues and then it's designed to return the results to the developer very quickly and say, okay, it's all set. It is signed. You are ready to go. Then they can put it up for sale on the app store or available for free, et cetera. The same trick over on the Google side.

    In this case, in the Google side, they've got this alphabet owned malware scanning service called virus total that looks at data from over 60 different antivirus providers to figure out, is this software malicious? Is it using any sort of malicious libraries or routines?

    Now we have seen that happen, unfortunately, and it's scary because we have now found that even in the Apple app store, there have been many apps that included this library that was designed to basically steal personal information from you.

    Developers would use this library and it wasn't flagged by this notarization process. Now you install it and it's not the main feature of the app, but the app is spying on you. Now, there is a new piece of software out there that they're actually not all that new. It's been around for quite a while.

    It's called S H L E Y E R Schleyer and it is a Trojan that has been one of the most prolific pieces of Mac malware now for the last couple of years and it was notarized by Apple. Now, this is interesting, right? This whole notarization thing it's been in the last couple of major releases, but it snuck by.

    There is if you're an Apple user, there is a piece of software there's you can put on your Mac called brew and it uses open-source software to install all kinds of features. I use many of these pieces of open-source software all of the time. And they provide functionality that does not come with the base Mac operating system. And so in the case of brew, It is verified and validated by the brew people, right?

    Apple has nothing to do with this. There is another site out there called a homebrew.sh, which is a knockoff of the brew site, which is brew.sh. And the number of people were tricked into using that site, this homebrew.sh, and it apparently had fake flash updates. So it pops up and it says, Hey, you need to update.

    And we've all seen that before if we have flash on our computer. you click on it and open it and install it. In fact, this Schleyer was slash is so smart. It gives you instructions on how to get around Apple's notarization checks. So in case you didn't know if you install an app on your Mac and you, first of all, you probably can't get it to install, but if you do get it to install or if you download it and you try and run it out of your downloads. If you right-click on it, you then have the option to just open it and get around the signatures from Apple.

    Not good, not a good thing. So this, bottom line means that you cannot 100% trust these signed apps from Apple or from Google. Just, this is just to remember. Okay. This isn't something that any of these companies messed up recently. It's just normal. So be very careful. About what you install and it goes right back to something. I said a little earlier today, which is, do not install any software you do not absolutely need and make sure that you keep it all up to date. Some of this stuff does clickJacking. It tricks users into installing these cryptographic certificates. It decrypts and reads all of your HTTPS traffic.

    So if you're going to a secure server that is using SSL, it's decrypting it. It's harvesting your user IDs, everything. Okay.

    Apples goof, in this case, and they fixed it very quickly. It was reported to Apple. Apple did not figure this particular one out by themselves. So that goes right back to how important it is to have third parties out there that are looking at security, not just for Apple, but for many other pieces of software.

    All right, stick around. When we come back, we're going to talk about a new little study that was done about the internet of things hardware.

    Make sure you get all of this and more. My newsletter, Craig peterson.com/subscribe and stick around. Cause we'll be right back.

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    10 min
  • Welcome! How app design libraries are defeating design security plus more on Tech Talk with Craig Peterson on WGAN

    Welcome!

    Craig explains how app design libraries are causing problems with the security of apps for some of the big tech firms. 

    For more tech tips, news, and updates visit - CraigPeterson.com

    ---

    Read More:

    iOS 13.7 launched today with a new system for battling the pandemic

    Hackers are exploiting a critical flaw affecting >350,000 WordPress sites

    The accidental notary: Apple approves notorious malware to run on Macs

    Most IoT Hardware Dangerously Easy to Crack

    55% of Cybersquatted Domains are Malicious or Potentially Fraudulent

    Feds Can’t Ask Google for Every Phone in a 100-meter Radius, Court Says

    The Hidden Cost of Losing Security Talent

    Don’t forget Cybersecurity on Your Back-to-School List

    ---

    Automated Machine-Generated Transcript:

    Craig Peterson: [00:00:00] We're going to get into the guts right now of something called notarization. When it comes to our apps. What's Apple doing what's Google doing and how did Apple mess this is up so badly, frankly.

    Hey, you're listening to Craig Peterson. Thanks for joining me today. We've had a problem for a very long time when it comes to any sort of apps. I saw a funny meme about yeah about Bill Gates this week. It said Bill Gates couldn't even stop viruses and Windows. It's a really good point that Windows was never designed to be secure at all.

    When they came out with NT, that was their first attempt to design it like a real operating system. They took the design of VMS, basically of Dave Cutler and company that had been designed over a DEC - digital equipment. And they said, Hey, we'll use this as a framework. This really works. It's not a hack. Let's just make this work.

     Then, of course, Microsoft had his fingers on it. So they really messed it up. They wanted to be compatible with everything that they could possibly be compatible with in the past. In the past, Microsoft did not have the barriers walls. If you will between the apps between the operating system, between the hardware and the apps. They didn't have the appropriate protections in place. Programmers used some lazy mechanisms to get around the operating system, going directly to things like graphics cards, because the operating system just slowed it down and they couldn't do the graphics they wanted to do that way. So it's been a real problem, frankly.

    It's been a real problem for a long time in the windows world, and NT was supposed to fix some of that. It did initially, and then it didn't. Now they're trying to tighten up this whole thing. how do you, if you're Microsoft or Google or Apple, how do you protect the people who are using your products from some of this malicious software?

    What's the way to do it? What Apple has come up with is a mechanism and Google as well that signs the software. You might have noticed that if you are trying to install software on your computer or your Google device from a third party website, it will come up and say, can't be opened, It can't be installed. There are a few different messages that come up.

    In the case of Apple now, with MacOS Catalina, which is the latest Operating system. Although, there's another one that is about to hit and it looks like they're going to change the whole nomenclature to, with the next release, but in Catalina, Apple now requires what they call notarization for all apps.

    Any apps that you are installing on that computer need to be signed digitally by Apple. So the developer, when they write the software, they compile it, they sign it themselves. It's a whole public key cryptography thing. Apple takes that software and checks it and then signs it.

    Both Google and Apple are using automated systems that try to verify whether or not the software is malicious. So it'll go through this automated system and will try and figure out well, is there any malicious content? Are they doing things they shouldn't be doing? Are they making suspicious calls to the operating system? Is it trying to get into files that it shouldn't be getting into?

    Now, there are ways to hide things from these automated systems. In fact, obfuscation seems to be the norm when it comes to any program or programming anything. It's just absolutely amazing. It does look for code signing issues and then it's designed to return the results to the developer very quickly and say, okay, it's all set. It is signed. You are ready to go. Then they can put it up for sale on the app store or available for free, et cetera. The same trick over on the Google side.

    In this case, in the Google side, they've got this alphabet owned malware scanning service called virus total that looks at data from over 60 different antivirus providers to figure out, is this software malicious? Is it using any sort of malicious libraries or routines?

    Now we have seen that happen, unfortunately, and it's scary because we have now found that even in the Apple app store, there have been many apps that included this library that was designed to basically steal personal information from you.

    Developers would use this library and it wasn't flagged by this notarization process. Now you install it and it's not the main feature of the app, but the app is spying on you. Now, there is a new piece of software out there that they're actually not all that new. It's been around for quite a while.

    It's called S H L E Y E R Schleyer and it is a Trojan that has been one of the most prolific pieces of Mac malware now for the last couple of years and it was notarized by Apple. Now, this is interesting, right? This whole notarization thing it's been in the last couple of major releases, but it snuck by.

    There is if you're an Apple user, there is a piece of software there's you can put on your Mac called brew and it uses open-source software to install all kinds of features. I use many of these pieces of open-source software all of the time. And they provide functionality that does not come with the base Mac operating system. And so in the case of brew, It is verified and validated by the brew people, right?

    Apple has nothing to do with this. There is another site out there called a homebrew.sh, which is a knockoff of the brew site, which is brew.sh. And the number of people were tricked into using that site, this homebrew.sh, and it apparently had fake flash updates. So it pops up and it says, Hey, you need to update.

    And we've all seen that before if we have flash on our computer. you click on it and open it and install it. In fact, this Schleyer was slash is so smart. It gives you instructions on how to get around Apple's notarization checks. So in case you didn't know if you install an app on your Mac and you, first of all, you probably can't get it to install, but if you do get it to install or if you download it and you try and run it out of your downloads. If you right-click on it, you then have the option to just open it and get around the signatures from Apple.

    Not good, not a good thing. So this, bottom line means that you cannot 100% trust these signed apps from Apple or from Google. Just, this is just to remember. Okay. This isn't something that any of these companies messed up recently. It's just normal. So be very careful. About what you install and it goes right back to something. I said a little earlier today, which is, do not install any software you do not absolutely need and make sure that you keep it all up to date. Some of this stuff does clickJacking. It tricks users into installing these cryptographic certificates. It decrypts and reads all of your HTTPS traffic.

    So if you're going to a secure server that is using SSL, it's decrypting it. It's harvesting your user IDs, everything. Okay.

    Apples goof, in this case, and they fixed it very quickly. It was reported to Apple. Apple did not figure this particular one out by themselves. So that goes right back to how important it is to have third parties out there that are looking at security, not just for Apple, but for many other pieces of software.

    All right, stick around. When we come back, we're going to talk about a new little study that was done about the internet of things hardware.

    Make sure you get all of this and more. My newsletter, Craig peterson.com/subscribe and stick around. Cause we'll be right back.

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    10 min
  • Welcome! How app design libraries are defeating design security plus more on Tech Talk with Craig Peterson on WGAN

    Welcome!

    Craig explains how app design libraries are causing problems with the security of apps for some of the big tech firms. 

    For more tech tips, news, and updates visit - CraigPeterson.com

    ---

    Read More:

    iOS 13.7 launched today with a new system for battling the pandemic

    Hackers are exploiting a critical flaw affecting >350,000 WordPress sites

    The accidental notary: Apple approves notorious malware to run on Macs

    Most IoT Hardware Dangerously Easy to Crack

    55% of Cybersquatted Domains are Malicious or Potentially Fraudulent

    Feds Can’t Ask Google for Every Phone in a 100-meter Radius, Court Says

    The Hidden Cost of Losing Security Talent

    Don’t forget Cybersecurity on Your Back-to-School List

    ---

    Automated Machine-Generated Transcript:

    Craig Peterson: [00:00:00] We're going to get into the guts right now of something called notarization. When it comes to our apps. What's Apple doing what's Google doing and how did Apple mess this is up so badly, frankly.

    Hey, you're listening to Craig Peterson. Thanks for joining me today. We've had a problem for a very long time when it comes to any sort of apps. I saw a funny meme about yeah about Bill Gates this week. It said Bill Gates couldn't even stop viruses and Windows. It's a really good point that Windows was never designed to be secure at all.

    When they came out with NT, that was their first attempt to design it like a real operating system. They took the design of VMS, basically of Dave Cutler and company that had been designed over a DEC - digital equipment. And they said, Hey, we'll use this as a framework. This really works. It's not a hack. Let's just make this work.

     Then, of course, Microsoft had his fingers on it. So they really messed it up. They wanted to be compatible with everything that they could possibly be compatible with in the past. In the past, Microsoft did not have the barriers walls. If you will between the apps between the operating system, between the hardware and the apps. They didn't have the appropriate protections in place. Programmers used some lazy mechanisms to get around the operating system, going directly to things like graphics cards, because the operating system just slowed it down and they couldn't do the graphics they wanted to do that way. So it's been a real problem, frankly.

    It's been a real problem for a long time in the windows world, and NT was supposed to fix some of that. It did initially, and then it didn't. Now they're trying to tighten up this whole thing. how do you, if you're Microsoft or Google or Apple, how do you protect the people who are using your products from some of this malicious software?

    What's the way to do it? What Apple has come up with is a mechanism and Google as well that signs the software. You might have noticed that if you are trying to install software on your computer or your Google device from a third party website, it will come up and say, can't be opened, It can't be installed. There are a few different messages that come up.

    In the case of Apple now, with MacOS Catalina, which is the latest Operating system. Although, there's another one that is about to hit and it looks like they're going to change the whole nomenclature to, with the next release, but in Catalina, Apple now requires what they call notarization for all apps.

    Any apps that you are installing on that computer need to be signed digitally by Apple. So the developer, when they write the software, they compile it, they sign it themselves. It's a whole public key cryptography thing. Apple takes that software and checks it and then signs it.

    Both Google and Apple are using automated systems that try to verify whether or not the software is malicious. So it'll go through this automated system and will try and figure out well, is there any malicious content? Are they doing things they shouldn't be doing? Are they making suspicious calls to the operating system? Is it trying to get into files that it shouldn't be getting into?

    Now, there are ways to hide things from these automated systems. In fact, obfuscation seems to be the norm when it comes to any program or programming anything. It's just absolutely amazing. It does look for code signing issues and then it's designed to return the results to the developer very quickly and say, okay, it's all set. It is signed. You are ready to go. Then they can put it up for sale on the app store or available for free, et cetera. The same trick over on the Google side.

    In this case, in the Google side, they've got this alphabet owned malware scanning service called virus total that looks at data from over 60 different antivirus providers to figure out, is this software malicious? Is it using any sort of malicious libraries or routines?

    Now we have seen that happen, unfortunately, and it's scary because we have now found that even in the Apple app store, there have been many apps that included this library that was designed to basically steal personal information from you.

    Developers would use this library and it wasn't flagged by this notarization process. Now you install it and it's not the main feature of the app, but the app is spying on you. Now, there is a new piece of software out there that they're actually not all that new. It's been around for quite a while.

    It's called S H L E Y E R Schleyer and it is a Trojan that has been one of the most prolific pieces of Mac malware now for the last couple of years and it was notarized by Apple. Now, this is interesting, right? This whole notarization thing it's been in the last couple of major releases, but it snuck by.

    There is if you're an Apple user, there is a piece of software there's you can put on your Mac called brew and it uses open-source software to install all kinds of features. I use many of these pieces of open-source software all of the time. And they provide functionality that does not come with the base Mac operating system. And so in the case of brew, It is verified and validated by the brew people, right?

    Apple has nothing to do with this. There is another site out there called a homebrew.sh, which is a knockoff of the brew site, which is brew.sh. And the number of people were tricked into using that site, this homebrew.sh, and it apparently had fake flash updates. So it pops up and it says, Hey, you need to update.

    And we've all seen that before if we have flash on our computer. you click on it and open it and install it. In fact, this Schleyer was slash is so smart. It gives you instructions on how to get around Apple's notarization checks. So in case you didn't know if you install an app on your Mac and you, first of all, you probably can't get it to install, but if you do get it to install or if you download it and you try and run it out of your downloads. If you right-click on it, you then have the option to just open it and get around the signatures from Apple.

    Not good, not a good thing. So this, bottom line means that you cannot 100% trust these signed apps from Apple or from Google. Just, this is just to remember. Okay. This isn't something that any of these companies messed up recently. It's just normal. So be very careful. About what you install and it goes right back to something. I said a little earlier today, which is, do not install any software you do not absolutely need and make sure that you keep it all up to date. Some of this stuff does clickJacking. It tricks users into installing these cryptographic certificates. It decrypts and reads all of your HTTPS traffic.

    So if you're going to a secure server that is using SSL, it's decrypting it. It's harvesting your user IDs, everything. Okay.

    Apples goof, in this case, and they fixed it very quickly. It was reported to Apple. Apple did not figure this particular one out by themselves. So that goes right back to how important it is to have third parties out there that are looking at security, not just for Apple, but for many other pieces of software.

    All right, stick around. When we come back, we're going to talk about a new little study that was done about the internet of things hardware.

    Make sure you get all of this and more. My newsletter, Craig peterson.com/subscribe and stick around. Cause we'll be right back.

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    10 min
  • Welcome! iOT hardware makes your Business Vulnerable plus more on Tech Talk with Craig Peterson on WGAN

    Welcome!

    Craig discusses IoT hardware and how these gaget-y devices can put your business at risk. Listen in to find out why?

    For more tech tips, news, and updates visit - CraigPeterson.com

    ---

    Read More:

    iOS 13.7 launched today with a new system for battling the pandemic

    Hackers are exploiting a critical flaw affecting >350,000 WordPress sites

    The accidental notary: Apple approves notorious malware to run on Macs

    Most IoT Hardware Dangerously Easy to Crack

    55% of Cybersquatted Domains are Malicious or Potentially Fraudulent

    Feds Can't Ask Google for Every Phone in a 100-meter Radius, Court Says

    The Hidden Cost of Losing Security Talent

    Don't forget Cybersecurity on Your Back-to-School List

    ---

    Automated Machine-Generated Transcript:

    Craig Peterson: [00:00:00] Sometimes it seems like the easier things are the tougher they are. And man is that true according to this new study we're going to talk about right now when it comes to these wonderful little appliances we have.

    Hello everybody. Craig Peterson here. Thanks for joining me. I enjoy being here on the radio answering questions. I got a lot this week. I got dozens of them, so that's wonderful. Keep them coming in. I pick the best ones for what we call our newsletter. That typically goes out Saturday mornings. Again, it depends on what our weeks are like. Getting those out and I try and answer them there.

    That's part of what we're going to be doing. Midweek starting next week. We're going to be sending out these little emails, a long tail thing, explaining a specific topic. Something you can read and just a few minutes and get something out of.

    We want it really to be transformational. If you can do that in three minutes. We have been transforming our lives in a lot of ways. Many ways of us, of course, have been using computers for decades now. We've been using these smart devices for at least a decade. Before I had my first Android smartphone and my first iPhone, I had the Palm pilot phones and just what I could do with my Palm. It was just absolutely amazing.

    Do you remember handspring and some of these other guys there are just so many wonderful things we could do with them that the Apple Newton, which never really hit it off, it was very expensive? All of these devices were designed to make our lives a little bit easier and they all required a lot of intelligence.

    Now we have devices pretty much everywhere. I was going to say, come out of our ears, but that's true too. When it comes to hearing AIDS, these extremely small devices that have embedded computers, a whole computer system. Now when you're trying to manufacturer something like a light bulb that has smarts in it, it might be smart to be able to change colors. It might be smart to get on a network and accept a remote control code. It might be some smarts that are just designed to make the whole house easier. you turn on. A movie and automatically the lights in the room. Dim, the surround sound turns on. Just everything happens for you automatically.

    These are all being done with these various small, hopefully, easy to use and install devices. But the problem that we've been noticing is that, wow, wait a minute. Now, none of these devices were really designed with security in mind, and in order to keep the costs down, they have to really strip those operating systems bare.

    So there are versions of Linux, many of them now that are just very stripped down. The same thing's true with BSD Unixes or units are used in a lot of this internet of things, devices, and the idea is to get it small, get it simple. So that we don't have to provide them with a big computer or a bunch of computing power.

    We can just do it simply. Get that information together, put it out there for the people to use. So what's that information as I said, it can be almost anything. It's about the internet of things. Now, because they have cost reduced all of these devices all the way to just out saving a fraction of a penny on each board. Remember they're making these things by the tens of thousands and ultimately by the millions and billions at least that's the plan, that's what five G is been designed to help handle. They have a whole problem when it comes to what we in the industry might call root-level access.

    We've got a security researcher out there who presented over at the Octas virtual disclosure security conference last week that most of this internet of things hardware is dangerously easy to crack and completely take control of. Then they use it for malicious purposes.

    The federal government has really cracked down now on anybody that's not just a direct contractor with them, but a subcontractor. We're seeing this all of the time. We're helping businesses. These enterprises that are making things, everything from a cable harness through power supplies, through control systems and control circuits. That now as of mid-August, this year, have to get rid of everything that's in their buildings that do not meet these new CMMC and other standards.

    So things like the security cameras that you might have right there. Weren't they real cheap, like the Hikvision stuff, right? Heck, you could just go to any big-box retailer and buyHikvision. Hikvision is illegal to have in the building. You used to be able to separate the network. So you could say, yeah, my Hikvision security cameras on a different network than my Chinese made telephone voice over IP system, which is on a different network than my computer systems. You can't do that anymore. It has to all be gone. Why? It's because none of those systems meet the minimum security requirements.

    If we go into a place that is just, for instance, we just picked up another client that's a pizza shop. They're doing really well because of the COVID thing, because people are ordering pizzas, they are being delivered to people's homes and they're just raking in the dough and they were having some problems. So they had us come in.

    What was the problem? In their case, they found out that they were about to be audited by our PCI friends. PCI, that's the payment card industry folks. So if you accept credit cards, you now have PCI obligations. What are those obligations or what do you do? How do you deal with those in their case? It turned out okay. That for whatever reason, their credit cards had been stolen, the credit card information. It could have been a skimmer. We walked into and did a security audit on this chain of restaurants. Pretty big chain here in my home state. We had to poke around. I could not believe it, they had for all of the waitstaff, Android tablets. The Android tablets were all in developer mode, full access to everything on the tablet, including the card reader, that PCI non-compliant card reader. It's great for the servers because they come up, they take the order on this Android tablet, and then at the end of the meal, they just swipe the card in the side of the tablet. Wow. Isn't this just wonderful? Because of the way the software was being run and being used, anything malicious could be installed on that unit that was being carried around by the wait staff. All the wait staff had to do was put something on there that just the read the credit card numbers as they were being scanned or copied all the information from the transactions and TaDa they now have money in their pocket that happened here in my home state again and it's happening in yours.

    Believe me, Wendy's is where this one was and they ended up having people go to jail over that one. This pizza shop. We went in there, they had credit cards, apparently stolen, and that's why they were getting a PCI audit. They brought us in a week before the audit was supposed to happen. We had a look and yes, indeed their equipment had been compromised. It's like I say, all of the time. We never have gone into a business and found that their security is up to date. Every machine we've looked at has had severe security problems and in every case where we've gone in and it's a government subcontractor of some sort. Every case we have found Chinese back doors and other, very malicious software on it. What does that mean to you a regular, a home person, right? Home user. What does it mean to you as an enterprise business, an organization, tax-free whatever you might be?

    It means that this internet of things, hardware, whether it's things like the Hikvision cameras that can't be used anymore, legally anyways, for DOD subcontractors on any network on any piece of equipment or our voiceover IP phones that are being hacked or the pizza shop whose POS system had been hacked. What are you doing?

    It's across the board for everybody? So Mark Rogers is this white-hat hacker who presented at the Okta virtual disclosure security conference. He was saying that these devices were hooking up to our networks have weak to no protections at all against attacks. Against the firmware on the devices against the software that's running on the devices, et cetera.

    He claimed he's able to gain complete route access, route level access means that he can do anything he wants on the machines, including the ability to reflash firmware. In other words, put his own software on the device on 1,012 devices that he's tested.

    And going back to this chain restaurant that we tried to help out and they decided no we're all set. Na-Na right fingers in the ears. We could have easily and so could their waitstaff have completely hacked any of these devices. None of them, none of it was probably protected. It's just shocking to me. It is shocking to me just continually.

    The issue with all of these systems, and this is true of almost every internet of thing device out there is that most of the proprietary information about the devices, including their certificates or keys, the communication program or protocols it's stored in poorly secured flash memory.

    You think of your flash memory like a hard disc drive, but there are no moving parts in it. Anyone with access to these devices, anybody with some basic knowledge of hardware hacking, even basic software hacking can access the firmware, look for data, including vulnerabilities. We've seen that happen before where security cameras are being used to launch attacks against the rest of the business and it includes DOD contractors, and it includes restaurants. We're seeing that every week.

    Be very careful. I'm not getting into the details of how they're using Uart and J tag routes to get into them. But. This is a real problem, everybody.

    So again, be careful the best stuff out there right now when it comes to the internet of things to smart devices, to these speakers that you can talk to is now, I'm going to sound like a broken record, but it's Apple. The Apple devices, the Apple speakers, all of that stuff tends to be more expensive, but it is well engineered and they do seriously consider security as part of all of this.

    Well, there's going to be a lot more, go online, and stick around.

    You're listening to Craig Peterson here and WTAG we'll be back.

    After the top of the hour, we'll be talking about the Cybersquatting offense. Asking Google for phone information and more stick around. We'll be right back.

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    13 min
  • Welcome! iOT hardware makes your Business Vulnerable plus more on Tech Talk with Craig Peterson on WGAN

    Welcome!

    Craig discusses IoT hardware and how these gaget-y devices can put your business at risk. Listen in to find out why?

    For more tech tips, news, and updates visit - CraigPeterson.com

    ---

    Read More:

    iOS 13.7 launched today with a new system for battling the pandemic

    Hackers are exploiting a critical flaw affecting >350,000 WordPress sites

    The accidental notary: Apple approves notorious malware to run on Macs

    Most IoT Hardware Dangerously Easy to Crack

    55% of Cybersquatted Domains are Malicious or Potentially Fraudulent

    Feds Can’t Ask Google for Every Phone in a 100-meter Radius, Court Says

    The Hidden Cost of Losing Security Talent

     

    Don’t forget Cybersecurity on Your Back-to-School List

    ---

    Automated Machine-Generated Transcript:

    Craig Peterson: [00:00:00] Sometimes it seems like the easier things are the tougher they are. And man is that true according to this new study we're going to talk about right now when it comes to these wonderful little appliances we have.

    Hello everybody. Craig Peterson here. Thanks for joining me. I enjoy being here on the radio answering questions. I got a lot this week. I got dozens of them, so that's wonderful. Keep them coming in. I pick the best ones for what we call our newsletter. That typically goes out Saturday mornings. Again, it depends on what our weeks are like. Getting those out and I try and answer them there.

    That's part of what we're going to be doing. Midweek starting next week. We're going to be sending out these little emails, a long tail thing, explaining a specific topic.  Something you can read and just a few minutes and get something out of.

    We want it really to be transformational. If you can do that in three minutes. We have been transforming our lives in a lot of ways. Many ways of us, of course, have been using computers for decades now. We've been using these smart devices for at least a decade. Before I had my first Android smartphone and my first iPhone, I had the Palm pilot phones and just what I could do with my Palm. It was just absolutely amazing.

    Do you remember handspring and some of these other guys there are just so many wonderful things we could do with them that the Apple Newton, which never really hit it off, it was very expensive? All of these devices were designed to make our lives a little bit easier and they all required a lot of intelligence.

    Now we have devices pretty much everywhere. I was going to say, come out of our ears, but that's true too. When it comes to hearing AIDS, these extremely small devices that have embedded computers, a whole computer system. Now when you're trying to manufacturer something like a light bulb that has smarts in it, it might be smart to be able to change colors. It might be smart to get on a network and accept a remote control code. It might be some smarts that are just designed to make the whole house easier. you turn on. A movie and automatically the lights in the room. Dim, the surround sound turns on. Just everything happens for you automatically.

    These are all being done with these various small, hopefully, easy to use and install devices. But the problem that we've been noticing is that, wow, wait a minute. Now, none of these devices were really designed with security in mind, and in order to keep the costs down, they have to really strip those operating systems bare.

    So there are versions of Linux, many of them now that are just very stripped down. The same thing's true with BSD Unixes or units are used in a lot of this internet of things, devices, and the idea is to get it small, get it simple. So that we don't have to provide them with a big computer or a bunch of computing power.

    We can just do it simply. Get that information together, put it out there for the people to use. So what's that information as I said, it can be almost anything. It's about the internet of things. Now, because they have cost reduced all of these devices all the way to just out saving a fraction of a penny on each board. Remember they're making these things by the tens of thousands and ultimately by the millions and billions at least that's the plan, that's what five G is been designed to help handle. They have a whole problem when it comes to what we in the industry might call root-level access.

    We've got a security researcher out there who presented over at the Octas virtual disclosure security conference last week that most of this internet of things hardware is dangerously easy to crack and completely take control of. Then they use it for malicious purposes.

    The federal government has really cracked down now on anybody that's not just a direct contractor with them, but a subcontractor. We're seeing this all of the time. We're helping businesses. These enterprises that are making things, everything from a cable harness through power supplies, through control systems and control circuits. That now as of mid-August, this year, have to get rid of everything that's in their buildings that do not meet these new CMMC and other standards.

    So things like the security cameras that you might have right there. Weren't they real cheap, like the Hikvision stuff, right? Heck, you could just go to any big-box retailer and buyHikvision. Hikvision is illegal to have in the building. You used to be able to separate the network. So you could say, yeah, my Hikvision security cameras on a different network than my Chinese made telephone voice over IP system, which is on a different network than my computer systems. You can't do that anymore. It has to all be gone. Why? It's because none of those systems meet the minimum security requirements.

    If we go into a place that is just, for instance, we just picked up another client that's a pizza shop. They're doing really well because of the COVID thing, because people are ordering pizzas, they are being delivered to people's homes and they're just raking in the dough and they were having some problems. So they had us come in.

    What was the problem? In their case, they found out that they were about to be audited by our PCI friends. PCI, that's the payment card industry folks. So if you accept credit cards, you now have PCI obligations. What are those obligations or what do you do? How do you deal with those in their case? It turned out okay. That for whatever reason, their credit cards had been stolen, the credit card information.  It could have been a skimmer. We walked into and did a security audit on this chain of restaurants. Pretty big chain here in my home state. We had to poke around. I could not believe it, they had for all of the waitstaff, Android tablets. The Android tablets were all in developer mode, full access to everything on the tablet, including the card reader, that PCI non-compliant card reader. It's great for the servers because they come up, they take the order on this Android tablet, and then at the end of the meal, they just swipe the card in the side of the tablet. Wow. Isn't this just wonderful? Because of the way the software was being run and being used, anything malicious could be installed on that unit that was being carried around by the wait staff.  All the wait staff had to do was put something on there that just the read the credit card numbers as they were being scanned or copied all the information from the transactions and TaDa they now have money in their pocket that happened here in my home state again and it's happening in yours.

    Believe me, Wendy's is where this one was and they ended up having people go to jail over that one. This pizza shop. We went in there, they had credit cards, apparently stolen, and that's why they were getting a PCI audit. They brought us in a week before the audit was supposed to happen. We had a look and yes, indeed their equipment had been compromised. It's like I say, all of the time. We never have gone into a business and found that their security is up to date. Every machine we've looked at has had severe security problems and in every case where we've gone in and it's a government subcontractor of some sort. Every case we have found Chinese back doors and other, very malicious software on it. What does that mean to you a regular, a home person, right? Home user. What does it mean to you as an enterprise business, an organization, tax-free whatever you might be?

    It means that this internet of things, hardware, whether it's things like the Hikvision cameras that can't be used anymore, legally anyways, for DOD subcontractors on any network on any piece of equipment or our voiceover IP phones that are being hacked or the pizza shop whose POS system had been hacked. What are you doing?

    It's across the board for everybody? So Mark Rogers is this white-hat hacker who presented at the Okta virtual disclosure security conference. He was saying that these devices were hooking up to our networks have weak to no protections at all against attacks. Against the firmware on the devices against the software that's running on the devices, et cetera.

    He claimed he's able to gain complete route access, route level access means that he can do anything he wants on the machines, including the ability to reflash firmware. In other words, put his own software on the device on 1,012 devices that he's tested.

    And going back to this chain restaurant that we tried to help out and they decided no we're all set. Na-Na right fingers in the ears. We could have easily and so could their waitstaff have completely hacked any of these devices. None of them, none of it was probably protected. It's just shocking to me. It is shocking to me just continually.

     The issue with all of these systems, and this is true of almost every internet of thing device out there is that most of the proprietary information about the devices, including their certificates or keys, the communication program or protocols it's stored in poorly secured flash memory.

    You think of your flash memory like a hard disc drive, but there are no moving parts in it. Anyone with access to these devices, anybody with some basic knowledge of hardware hacking, even basic software hacking can access the firmware, look for data, including vulnerabilities. We've seen that happen before where security cameras are being used to launch attacks against the rest of the business and it includes DOD contractors, and it includes restaurants. We're seeing that every week.

     Be very careful. I'm not getting into the details of how they're using Uart and J tag routes to get into them. But. This is a real problem, everybody.

    So again, be careful the best stuff out there right now when it comes to the internet of things to smart devices, to these speakers that you can talk to is now, I'm going to sound like a  broken record, but it's Apple. The Apple devices, the Apple speakers, all of that stuff tends to be more expensive, but it is well engineered and they do seriously consider security as part of all of this.

    Well, there's going to be a lot more, go online, and stick around.

    You're listening to Craig Peterson here and WTAG we'll be back.

    After the top of the hour, we'll be talking about the Cybersquatting offense. Asking Google for phone information and more stick around. We'll be right back.

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    13 min
  • Welcome! iOT hardware makes your Business Vulnerable plus more on Tech Talk with Craig Peterson on WGAN

    Welcome!

    Craig discusses IoT hardware and how these gaget-y devices can put your business at risk. Listen in to find out why?

    For more tech tips, news, and updates visit - CraigPeterson.com

    ---

    Read More:

    iOS 13.7 launched today with a new system for battling the pandemic

    Hackers are exploiting a critical flaw affecting >350,000 WordPress sites

    The accidental notary: Apple approves notorious malware to run on Macs

    Most IoT Hardware Dangerously Easy to Crack

    55% of Cybersquatted Domains are Malicious or Potentially Fraudulent

    Feds Can’t Ask Google for Every Phone in a 100-meter Radius, Court Says

    The Hidden Cost of Losing Security Talent

     

    Don’t forget Cybersecurity on Your Back-to-School List

    ---

    Automated Machine-Generated Transcript:

    Craig Peterson: [00:00:00] Sometimes it seems like the easier things are the tougher they are. And man is that true according to this new study we're going to talk about right now when it comes to these wonderful little appliances we have.

    Hello everybody. Craig Peterson here. Thanks for joining me. I enjoy being here on the radio answering questions. I got a lot this week. I got dozens of them, so that's wonderful. Keep them coming in. I pick the best ones for what we call our newsletter. That typically goes out Saturday mornings. Again, it depends on what our weeks are like. Getting those out and I try and answer them there.

    That's part of what we're going to be doing. Midweek starting next week. We're going to be sending out these little emails, a long tail thing, explaining a specific topic.  Something you can read and just a few minutes and get something out of.

    We want it really to be transformational. If you can do that in three minutes. We have been transforming our lives in a lot of ways. Many ways of us, of course, have been using computers for decades now. We've been using these smart devices for at least a decade. Before I had my first Android smartphone and my first iPhone, I had the Palm pilot phones and just what I could do with my Palm. It was just absolutely amazing.

    Do you remember handspring and some of these other guys there are just so many wonderful things we could do with them that the Apple Newton, which never really hit it off, it was very expensive? All of these devices were designed to make our lives a little bit easier and they all required a lot of intelligence.

    Now we have devices pretty much everywhere. I was going to say, come out of our ears, but that's true too. When it comes to hearing AIDS, these extremely small devices that have embedded computers, a whole computer system. Now when you're trying to manufacturer something like a light bulb that has smarts in it, it might be smart to be able to change colors. It might be smart to get on a network and accept a remote control code. It might be some smarts that are just designed to make the whole house easier. you turn on. A movie and automatically the lights in the room. Dim, the surround sound turns on. Just everything happens for you automatically.

    These are all being done with these various small, hopefully, easy to use and install devices. But the problem that we've been noticing is that, wow, wait a minute. Now, none of these devices were really designed with security in mind, and in order to keep the costs down, they have to really strip those operating systems bare.

    So there are versions of Linux, many of them now that are just very stripped down. The same thing's true with BSD Unixes or units are used in a lot of this internet of things, devices, and the idea is to get it small, get it simple. So that we don't have to provide them with a big computer or a bunch of computing power.

    We can just do it simply. Get that information together, put it out there for the people to use. So what's that information as I said, it can be almost anything. It's about the internet of things. Now, because they have cost reduced all of these devices all the way to just out saving a fraction of a penny on each board. Remember they're making these things by the tens of thousands and ultimately by the millions and billions at least that's the plan, that's what five G is been designed to help handle. They have a whole problem when it comes to what we in the industry might call root-level access.

    We've got a security researcher out there who presented over at the Octas virtual disclosure security conference last week that most of this internet of things hardware is dangerously easy to crack and completely take control of. Then they use it for malicious purposes.

    The federal government has really cracked down now on anybody that's not just a direct contractor with them, but a subcontractor. We're seeing this all of the time. We're helping businesses. These enterprises that are making things, everything from a cable harness through power supplies, through control systems and control circuits. That now as of mid-August, this year, have to get rid of everything that's in their buildings that do not meet these new CMMC and other standards.

    So things like the security cameras that you might have right there. Weren't they real cheap, like the Hikvision stuff, right? Heck, you could just go to any big-box retailer and buyHikvision. Hikvision is illegal to have in the building. You used to be able to separate the network. So you could say, yeah, my Hikvision security cameras on a different network than my Chinese made telephone voice over IP system, which is on a different network than my computer systems. You can't do that anymore. It has to all be gone. Why? It's because none of those systems meet the minimum security requirements.

    If we go into a place that is just, for instance, we just picked up another client that's a pizza shop. They're doing really well because of the COVID thing, because people are ordering pizzas, they are being delivered to people's homes and they're just raking in the dough and they were having some problems. So they had us come in.

    What was the problem? In their case, they found out that they were about to be audited by our PCI friends. PCI, that's the payment card industry folks. So if you accept credit cards, you now have PCI obligations. What are those obligations or what do you do? How do you deal with those in their case? It turned out okay. That for whatever reason, their credit cards had been stolen, the credit card information.  It could have been a skimmer. We walked into and did a security audit on this chain of restaurants. Pretty big chain here in my home state. We had to poke around. I could not believe it, they had for all of the waitstaff, Android tablets. The Android tablets were all in developer mode, full access to everything on the tablet, including the card reader, that PCI non-compliant card reader. It's great for the servers because they come up, they take the order on this Android tablet, and then at the end of the meal, they just swipe the card in the side of the tablet. Wow. Isn't this just wonderful? Because of the way the software was being run and being used, anything malicious could be installed on that unit that was being carried around by the wait staff.  All the wait staff had to do was put something on there that just the read the credit card numbers as they were being scanned or copied all the information from the transactions and TaDa they now have money in their pocket that happened here in my home state again and it's happening in yours.

    Believe me, Wendy's is where this one was and they ended up having people go to jail over that one. This pizza shop. We went in there, they had credit cards, apparently stolen, and that's why they were getting a PCI audit. They brought us in a week before the audit was supposed to happen. We had a look and yes, indeed their equipment had been compromised. It's like I say, all of the time. We never have gone into a business and found that their security is up to date. Every machine we've looked at has had severe security problems and in every case where we've gone in and it's a government subcontractor of some sort. Every case we have found Chinese back doors and other, very malicious software on it. What does that mean to you a regular, a home person, right? Home user. What does it mean to you as an enterprise business, an organization, tax-free whatever you might be?

    It means that this internet of things, hardware, whether it's things like the Hikvision cameras that can't be used anymore, legally anyways, for DOD subcontractors on any network on any piece of equipment or our voiceover IP phones that are being hacked or the pizza shop whose POS system had been hacked. What are you doing?

    It's across the board for everybody? So Mark Rogers is this white-hat hacker who presented at the Okta virtual disclosure security conference. He was saying that these devices were hooking up to our networks have weak to no protections at all against attacks. Against the firmware on the devices against the software that's running on the devices, et cetera.

    He claimed he's able to gain complete route access, route level access means that he can do anything he wants on the machines, including the ability to reflash firmware. In other words, put his own software on the device on 1,012 devices that he's tested.

    And going back to this chain restaurant that we tried to help out and they decided no we're all set. Na-Na right fingers in the ears. We could have easily and so could their waitstaff have completely hacked any of these devices. None of them, none of it was probably protected. It's just shocking to me. It is shocking to me just continually.

     The issue with all of these systems, and this is true of almost every internet of thing device out there is that most of the proprietary information about the devices, including their certificates or keys, the communication program or protocols it's stored in poorly secured flash memory.

    You think of your flash memory like a hard disc drive, but there are no moving parts in it. Anyone with access to these devices, anybody with some basic knowledge of hardware hacking, even basic software hacking can access the firmware, look for data, including vulnerabilities. We've seen that happen before where security cameras are being used to launch attacks against the rest of the business and it includes DOD contractors, and it includes restaurants. We're seeing that every week.

     Be very careful. I'm not getting into the details of how they're using Uart and J tag routes to get into them. But. This is a real problem, everybody.

    So again, be careful the best stuff out there right now when it comes to the internet of things to smart devices, to these speakers that you can talk to is now, I'm going to sound like a  broken record, but it's Apple. The Apple devices, the Apple speakers, all of that stuff tends to be more expensive, but it is well engineered and they do seriously consider security as part of all of this.

    Well, there's going to be a lot more, go online, and stick around.

    You're listening to Craig Peterson here and WTAG we'll be back.

    After the top of the hour, we'll be talking about the Cybersquatting offense. Asking Google for phone information and more stick around. We'll be right back.

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    13 min
  • Welcome! Hackers New Tool - Cybersquatting plus more on Tech Talk with Craig Peterson on WGAN

    Welcome!

    Craig discusses Why hackers have resorted to Cybersquatting to ply their trades. Listen in to find out.

    For more tech tips, news, and updates visit - CraigPeterson.com

    ---

    Read More:

    iOS 13.7 launched today with a new system for battling the pandemic

    Hackers are exploiting a critical flaw affecting >350,000 WordPress sites

    The accidental notary: Apple approves notorious malware to run on Macs

    Most IoT Hardware Dangerously Easy to Crack

    55% of Cybersquatted Domains are Malicious or Potentially Fraudulent

    Feds Can't Ask Google for Every Phone in a 100-meter Radius, Court Says

    The Hidden Cost of Losing Security Talent

    Don't forget Cybersecurity on Your Back-to-School List

    ---

    Automated Machine-Generated Transcript:

    Craig Peterson: [00:00:00] Hey, how good are you at spelling and or typing? If you're like the rest of America, in fact, around the world, you may not be the best at either one of them. You know what the bad guys are taking advantage of that.

    Hey everybody. Craig Peterson here. Thanks for joining us today. I have had a busy week as we've been answering emails, getting the new website ready to go up and it's just been absolutely crazy.

    We've got more training coming out too. More training on the website and emails. We're going to be sending you these little two to three minutes to read emails. That'll keep you up to date on things. The number one thing that I hear comments on listeners is they really appreciate the little bit of learning that they get from the radio show and my appearances on the radio and everything else on with Matt in the morning on, of course, Wednesday mornings about seven 30, but that seems to be the number one thing and including the email.

    I'm going to do more of it. You asked for it, you're going to get it. We're going to do more of all of that. The training, keeping it simple, helping you out. We'll be doing some, some webinars stuff. Just all the way across the board. Yeah. Because we have some serious problems out there and it's getting worse and worse. And I don't see it getting any better.

    We just got news of another hack that happened. and it happened over on the Biden campaign. Man alive. It wasn't a hack-hack. What's a hack, I don't know. It's hard to say what a hack is nowadays because frankly, I count ransomware as a hack. It's something that somebody did that they weren't supposed to do, that they shouldn't have done, et cetera. That's a hack and that's what just happened to the Biden campaign.

    Apparently the Kremlin hit about 200 political targets, including a key Biden campaign Alie. Apparently this hacking attempt was caught by Microsoft. Most of them are not, and they were able to gather some information about hackers. Microsoft was able to link them to the Kremlin as the most likely suspect.

    And they were able to take all of that evidence and give it over to the FBI. So good for them. We had that happened last time too, remember Hillary Clinton's campaign. It happened exactly the same way for years later, Democrats again, the same way. Remember that whole thing, the DNC emails now turns out it was probably the Russian hackers that managed to get them and leaked all of those emails online ahead of the 2016 presidential election.

    They really want to shake things up. Obviously they don't want Trump. Trump's been very hard on them, harder than president Biden. Would be certainly harder than President Obama ever was. Trump's been very hard in Russia and very hard on China. They just want to really stir things up in a very big way.

    They apparently the Russians attempted to breach the systems at this Washington based strategy and communications firm called S K D K or S K D Knickerbocker whose been working for very hand in glove with Joe Biden's campaign, according to the daily beast. These attacks took place over the past two months. Ultimately they were unsuccessful. So that's really good news here. So maybe they did learn something from the last hack. This is the same method that was used back in 2016 to gain access to a very high, official, if you will, within the Hillary Clinton campaign.

    So here we go. Apparently this firm is "well defended." So there's been no breach. We'll see how that happens.

    We just had an instance this week. In fact, a company that we helped out a little bit, we moved them from just regular consumer network gear. We moved them up to some semi-professional network gear for their small business and it looks like they might actually have some contacts with the department of defense.

    And DOD is very particular about your security. I hope the Biden campaign is too. Cause this wasn't directly against the Biden campaign. This was against a consulting firm that they were working with.

    I want to remind everybody. These types of hacks for lack of a better term are typically phishing events. They'll send an email that looks legitimate and is a very simple plea asking for some information. In the April or March timeframes, actually, we usually see that email is going around talking about, Oh, and the W2 information, 10 99 information and pretending to be the CFO or the accountant, et cetera.

    Now, this isn't the first time Microsoft has sorted the suspected Russian government hacking, and we've thrown to them many times for our clients as well, including in emails. Apparently, that's what this was. This was an email. This was a phishing email designed to try and get somebody to click on a link or answer a question.

    Microsoft's saying they've identified over 120 new targets of the Kremlin's cyber spying. They have found them out apparently by suing the notorious hacker group known as Fancy bear. That's the group over there in Russia that is run out of the Kremlin. Microsoft's saying their legal actions led to the seizure of 70 command and control servers.

    Now, this is where I talked again on my show here a few weeks ago. This is where your home computer comes in. This is where your small business computer or even your large business computer comes in. And that is they will compromise it. They will install some software on it that allows them to remotely control it and then use your computer to send out these phishing emails, to send out emails that have attached to them either directly or indirectly, ransomware, et cetera.

    We just had a big ransomware thing just this week as well. I don't know if you heard about this one. But my gosh it's just happened, but again and again, this particular one. Hit this massive a company called Equinix, I should say. Equinix runs all kinds of data centers for businesses.

    Now it's saying that this ransomware hit their internal systems and what it did is exactly what I've been warning you guys about. It doesn't just take a hold of your computer and encrypt all of the data. no. What this did is it grabbed the data. It could get its hands on Equinix's internal computers and sent it up to the bad guy's computer. So they now had copies of some or all of their data. And then it does the encryption trick. Now Equinix is saying that their data is centers and service offerings, including their managed services, are fully operational.

    Now knock on wood. My company has never had this happen to us. but again, we're smaller. We use much better software than most companies out there.

    We don't have all of the details on this, but this is a very big deal. Equinix is publicly-traded. The company traded on the NASDAQ stock exchange. It has around 8,000 employees. It just bought 13 more data centers. This is really something. And by the way, bought them for $750 million, three-quarters of a billion. So this is a big company and it happens to them. It can happen to you.

    I started all of this out by asking if you were a good speller and how good a typer you are? There's another way the bad guys get to you. We've been talking right now about phishing and phishing sites.

    We were talking about how phishing is being used to get you to go to a website. oftentimes that URL that you're going to will look almost legitimate. It might be instead of microsoft.com, it might be Microsoft dot something else, or it might be a misspelling or a common typo for the URL for that website that you're trying to go to.

    Apple, PayPal, banks are being targeted by cyber squatters. Now they're taking advantage of the pandemic according to a study that just came out. In a single month, cybersquatters have registered almost 14,000 domain names. More than half of them went on to host malicious software. That is a very big deal.

    That's according to Palo Alto networks, and that is being quoted in Dark Reading. But what these cybersquatters are up to is that they put up a website that has a URL that's very similar to a legitimate URL out there. When you go there, they are going to try and trick you into doing something. Now, the study says that basically 55% of these Cybersquatter domains are malicious or potentially fraudulent.

    So it's not like somebody buying a domain saying, I'm going to, I'm going to buy it, Apple tart, because people type that in by accident when they're trying to go to Apple and maybe I can get Apple to buy it from me, or maybe I can use it as a parody site, et cetera. No. they are leading to malicious content more than 70% of the time.

    So be very careful about the brand. A good example that they've done that has been shut down recently is secure dash Wells Fargo. This is a domain using the Wells Fargo brand, targeting the bank's customers and getting them to click through and use phishing to steal sensitive information. Be very careful when you're out there typing things in or clicking on links, because many of them, it turns out 50-55% of them are malicious and 70% of them are trying to fake you into giving up your own personal information.

    Hey coming back. We've got a very interesting little article by Timothy Lee here in ARS Technica about a court order against the feds and local police departments. So we'll tell you about that. When we get back.

    Stick around, you're listening to Craig Peterson right here on WGAN and Wednesday mornings at seven 30 with Matt.

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    12 min
  • Welcome! Hackers New Tool - Cybersquatting plus more on Tech Talk with Craig Peterson on WGAN

    Welcome!

    Craig discusses Why hackers have resorted to Cybersquatting to ply their trades.  Listen in to find out.

    For more tech tips, news, and updates visit - CraigPeterson.com

    ---

    Read More:

    iOS 13.7 launched today with a new system for battling the pandemic

    Hackers are exploiting a critical flaw affecting >350,000 WordPress sites

    The accidental notary: Apple approves notorious malware to run on Macs

    Most IoT Hardware Dangerously Easy to Crack

    55% of Cybersquatted Domains are Malicious or Potentially Fraudulent

    Feds Can’t Ask Google for Every Phone in a 100-meter Radius, Court Says

    The Hidden Cost of Losing Security Talent

    Don’t forget Cybersecurity on Your Back-to-School List

    ---

    Automated Machine-Generated Transcript:

    Craig Peterson: [00:00:00] Hey, how good are you at spelling and or typing? If you're like the rest of America, in fact, around the world, you may not be the best at either one of them. You know what the bad guys are taking advantage of that.

    Hey everybody. Craig Peterson here. Thanks for joining us today. I have had a busy week as we've been answering emails, getting the new website ready to go up and it's just been absolutely crazy.

    We've got more training coming out too. More training on the website and emails. We're going to be sending you these little two to three minutes to read emails. That'll keep you up to date on things.  The number one thing that I hear comments on listeners is they really appreciate the little bit of learning that they get from the radio show and my appearances on the radio and everything else on with Matt in the morning on, of course, Wednesday mornings about seven 30, but that seems to be the number one thing and including the email.

    I'm going to do more of it. You asked for it, you're going to get it. We're going to do more of all of that. The training, keeping it simple, helping you out. We'll be doing some, some webinars stuff. Just all the way across the board. Yeah. Because we have some serious problems out there and it's getting worse and worse. And I don't see it getting any better.

    We just got news of another hack that happened. and it happened over on the Biden campaign. Man alive. It wasn't a hack-hack. What's a hack, I don't know. It's hard to say what a hack is nowadays because frankly, I count ransomware as a hack. It's something that somebody did that they weren't supposed to do, that they shouldn't have done, et cetera. That's a hack and that's what just happened to the Biden campaign.

    Apparently the Kremlin hit about 200 political targets, including a key Biden campaign Alie. Apparently this hacking attempt was caught by Microsoft. Most of them are not, and they were able to gather some information about hackers. Microsoft was able to link them to the Kremlin as the most likely suspect.

    And they were able to take all of that evidence and give it over to the FBI. So good for them. We had that happened last time too, remember Hillary Clinton's campaign. It happened exactly the same way for years later, Democrats again, the same way. Remember that whole thing, the DNC emails now turns out it was probably the Russian hackers that managed to get them and leaked all of those emails online ahead of the 2016 presidential election.

    They really want to shake things up. Obviously they don't want Trump. Trump's been very hard on them, harder than president Biden. Would be certainly harder than President Obama ever was. Trump's been very hard in Russia and very hard on China. They just want to really stir things up in a very big way.

    They apparently the Russians attempted to breach the systems at this Washington based strategy and communications firm called S K D K or S K D Knickerbocker whose been working for very hand in glove with Joe Biden's campaign, according to the daily beast. These attacks took place over the past two months. Ultimately they were unsuccessful. So that's really good news here. So maybe they did learn something from the last hack. This is the same method that was used back in 2016 to gain access to a very high, official, if you will, within the Hillary Clinton campaign.

    So here we go. Apparently this firm is "well defended." So there's been no breach. We'll see how that happens.

    We just had an instance this week. In fact, a company that we helped out a little bit, we moved them from just regular consumer network gear. We moved them up to some semi-professional network gear for their small business and it looks like they might actually have some contacts with the department of defense.

    And DOD is very particular about your security. I hope the Biden campaign is too. Cause this wasn't directly against the Biden campaign. This was against a consulting firm that they were working with. 

    I want to remind everybody. These types of hacks for lack of a better term are typically phishing events. They'll send an email that looks legitimate and is a very simple plea asking for some information. In the April or March timeframes, actually, we usually see that email is going around talking about, Oh, and the W2 information, 10 99 information and pretending to be the CFO or the accountant, et cetera.

    Now, this isn't the first time Microsoft has sorted the suspected Russian government hacking, and we've thrown to them many times for our clients as well, including in emails. Apparently, that's what this was. This was an email. This was a phishing email designed to try and get somebody to click on a link or answer a question.

    Microsoft's saying they've identified over 120 new targets of the Kremlin's cyber spying. They have found them out apparently by suing the notorious hacker group known as Fancy bear. That's the group over there in Russia that is run out of the Kremlin. Microsoft's saying their legal actions led to the seizure of 70 command and control servers.

    Now, this is where I talked again on my show here a few weeks ago. This is where your home computer comes in. This is where your small business computer or even your large business computer comes in. And that is they will compromise it. They will install some software on it that allows them to remotely control it and then use your computer to send out these phishing emails, to send out emails that have attached to them either directly or indirectly, ransomware, et cetera.

    We just had a big ransomware thing just this week as well. I don't know if you heard about this one. But my gosh it's just happened, but again and again, this particular one. Hit this massive a company called Equinix, I should say. Equinix runs all kinds of data centers for businesses.

    Now it's saying that this ransomware hit their internal systems and what it did is exactly what I've been warning you guys about. It doesn't just take a hold of your computer and encrypt all of the data. no. What this did is it grabbed the data. It could get its hands on Equinix's internal computers and sent it up to the bad guy's computer. So they now had copies of some or all of their data. And then it does the encryption trick. Now Equinix is saying that their data is centers and service offerings, including their managed services, are fully operational.

    Now knock on wood. My company has never had this happen to us. but again, we're smaller. We use much better software than most companies out there.

    We don't have all of the details on this, but this is a very big deal. Equinix is publicly-traded. The company traded on the NASDAQ stock exchange. It has around 8,000 employees. It just bought 13 more data centers. This is really something. And by the way, bought them for $750 million, three-quarters of a billion. So this is a big company and it happens to them. It can happen to you.

     I started all of this out by asking if you were a good speller and how good a typer you are? There's another way the bad guys get to you. We've been talking right now about phishing and phishing sites.

    We were talking about how phishing is being used to get you to go to a website. oftentimes that URL that you're going to will look almost legitimate. It might be instead of microsoft.com, it might be Microsoft dot something else, or it might be a misspelling or a common typo for the URL for that website that you're trying to go to.

    Apple, PayPal, banks are being targeted by cyber squatters. Now they're taking advantage of the pandemic according to a study that just came out. In a single month, cybersquatters have registered almost 14,000 domain names. More than half of them went on to host malicious software. That is a very big deal.

    That's according to Palo Alto networks, and that is being quoted in Dark Reading. But what these cybersquatters are up to is that they put up a website that has a URL that's very similar to a legitimate URL out there. When you go there, they are going to try and trick you into doing something. Now, the study says that basically 55% of these Cybersquatter domains are malicious or potentially fraudulent.

    So it's not like somebody buying a domain saying, I'm going to, I'm going to buy it, Apple tart, because people type that in by accident when they're trying to go to Apple and maybe I can get Apple to buy it from me, or maybe I can use it as a parody site, et cetera. No. they are leading to malicious content more than 70% of the time.

    So be very careful about the brand. A good example that they've done that has been shut down recently is secure dash Wells Fargo. This is a domain using the Wells Fargo brand, targeting the bank's customers and getting them to click through and use phishing to steal sensitive information. Be very careful when you're out there typing things in or clicking on links, because many of them, it turns out 50-55% of them are malicious and 70% of them are trying to fake you into giving up your own personal information.

    Hey coming back. We've got a very interesting little article by Timothy Lee here in ARS Technica about a court order against the feds and local police departments. So we'll tell you about that. When we get back.

    Stick around, you're listening to Craig Peterson right here on WGAN and Wednesday mornings at seven 30 with Matt.

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    12 min
  • Welcome! Hackers New Tool - Cybersquatting plus more on Tech Talk with Craig Peterson on WGAN

    Welcome!

    Craig discusses Why hackers have resorted to Cybersquatting to ply their trades.  Listen in to find out.

    For more tech tips, news, and updates visit - CraigPeterson.com

    ---

    Read More:

    iOS 13.7 launched today with a new system for battling the pandemic

    Hackers are exploiting a critical flaw affecting >350,000 WordPress sites

    The accidental notary: Apple approves notorious malware to run on Macs

    Most IoT Hardware Dangerously Easy to Crack

    55% of Cybersquatted Domains are Malicious or Potentially Fraudulent

    Feds Can’t Ask Google for Every Phone in a 100-meter Radius, Court Says

    The Hidden Cost of Losing Security Talent

    Don’t forget Cybersecurity on Your Back-to-School List

    ---

    Automated Machine-Generated Transcript:

    Craig Peterson: [00:00:00] Hey, how good are you at spelling and or typing? If you're like the rest of America, in fact, around the world, you may not be the best at either one of them. You know what the bad guys are taking advantage of that.

    Hey everybody. Craig Peterson here. Thanks for joining us today. I have had a busy week as we've been answering emails, getting the new website ready to go up and it's just been absolutely crazy.

    We've got more training coming out too. More training on the website and emails. We're going to be sending you these little two to three minutes to read emails. That'll keep you up to date on things.  The number one thing that I hear comments on listeners is they really appreciate the little bit of learning that they get from the radio show and my appearances on the radio and everything else on with Matt in the morning on, of course, Wednesday mornings about seven 30, but that seems to be the number one thing and including the email.

    I'm going to do more of it. You asked for it, you're going to get it. We're going to do more of all of that. The training, keeping it simple, helping you out. We'll be doing some, some webinars stuff. Just all the way across the board. Yeah. Because we have some serious problems out there and it's getting worse and worse. And I don't see it getting any better.

    We just got news of another hack that happened. and it happened over on the Biden campaign. Man alive. It wasn't a hack-hack. What's a hack, I don't know. It's hard to say what a hack is nowadays because frankly, I count ransomware as a hack. It's something that somebody did that they weren't supposed to do, that they shouldn't have done, et cetera. That's a hack and that's what just happened to the Biden campaign.

    Apparently the Kremlin hit about 200 political targets, including a key Biden campaign Alie. Apparently this hacking attempt was caught by Microsoft. Most of them are not, and they were able to gather some information about hackers. Microsoft was able to link them to the Kremlin as the most likely suspect.

    And they were able to take all of that evidence and give it over to the FBI. So good for them. We had that happened last time too, remember Hillary Clinton's campaign. It happened exactly the same way for years later, Democrats again, the same way. Remember that whole thing, the DNC emails now turns out it was probably the Russian hackers that managed to get them and leaked all of those emails online ahead of the 2016 presidential election.

    They really want to shake things up. Obviously they don't want Trump. Trump's been very hard on them, harder than president Biden. Would be certainly harder than President Obama ever was. Trump's been very hard in Russia and very hard on China. They just want to really stir things up in a very big way.

    They apparently the Russians attempted to breach the systems at this Washington based strategy and communications firm called S K D K or S K D Knickerbocker whose been working for very hand in glove with Joe Biden's campaign, according to the daily beast. These attacks took place over the past two months. Ultimately they were unsuccessful. So that's really good news here. So maybe they did learn something from the last hack. This is the same method that was used back in 2016 to gain access to a very high, official, if you will, within the Hillary Clinton campaign.

    So here we go. Apparently this firm is "well defended." So there's been no breach. We'll see how that happens.

    We just had an instance this week. In fact, a company that we helped out a little bit, we moved them from just regular consumer network gear. We moved them up to some semi-professional network gear for their small business and it looks like they might actually have some contacts with the department of defense.

    And DOD is very particular about your security. I hope the Biden campaign is too. Cause this wasn't directly against the Biden campaign. This was against a consulting firm that they were working with. 

    I want to remind everybody. These types of hacks for lack of a better term are typically phishing events. They'll send an email that looks legitimate and is a very simple plea asking for some information. In the April or March timeframes, actually, we usually see that email is going around talking about, Oh, and the W2 information, 10 99 information and pretending to be the CFO or the accountant, et cetera.

    Now, this isn't the first time Microsoft has sorted the suspected Russian government hacking, and we've thrown to them many times for our clients as well, including in emails. Apparently, that's what this was. This was an email. This was a phishing email designed to try and get somebody to click on a link or answer a question.

    Microsoft's saying they've identified over 120 new targets of the Kremlin's cyber spying. They have found them out apparently by suing the notorious hacker group known as Fancy bear. That's the group over there in Russia that is run out of the Kremlin. Microsoft's saying their legal actions led to the seizure of 70 command and control servers.

    Now, this is where I talked again on my show here a few weeks ago. This is where your home computer comes in. This is where your small business computer or even your large business computer comes in. And that is they will compromise it. They will install some software on it that allows them to remotely control it and then use your computer to send out these phishing emails, to send out emails that have attached to them either directly or indirectly, ransomware, et cetera.

    We just had a big ransomware thing just this week as well. I don't know if you heard about this one. But my gosh it's just happened, but again and again, this particular one. Hit this massive a company called Equinix, I should say. Equinix runs all kinds of data centers for businesses.

    Now it's saying that this ransomware hit their internal systems and what it did is exactly what I've been warning you guys about. It doesn't just take a hold of your computer and encrypt all of the data. no. What this did is it grabbed the data. It could get its hands on Equinix's internal computers and sent it up to the bad guy's computer. So they now had copies of some or all of their data. And then it does the encryption trick. Now Equinix is saying that their data is centers and service offerings, including their managed services, are fully operational.

    Now knock on wood. My company has never had this happen to us. but again, we're smaller. We use much better software than most companies out there.

    We don't have all of the details on this, but this is a very big deal. Equinix is publicly-traded. The company traded on the NASDAQ stock exchange. It has around 8,000 employees. It just bought 13 more data centers. This is really something. And by the way, bought them for $750 million, three-quarters of a billion. So this is a big company and it happens to them. It can happen to you.

     I started all of this out by asking if you were a good speller and how good a typer you are? There's another way the bad guys get to you. We've been talking right now about phishing and phishing sites.

    We were talking about how phishing is being used to get you to go to a website. oftentimes that URL that you're going to will look almost legitimate. It might be instead of microsoft.com, it might be Microsoft dot something else, or it might be a misspelling or a common typo for the URL for that website that you're trying to go to.

    Apple, PayPal, banks are being targeted by cyber squatters. Now they're taking advantage of the pandemic according to a study that just came out. In a single month, cybersquatters have registered almost 14,000 domain names. More than half of them went on to host malicious software. That is a very big deal.

    That's according to Palo Alto networks, and that is being quoted in Dark Reading. But what these cybersquatters are up to is that they put up a website that has a URL that's very similar to a legitimate URL out there. When you go there, they are going to try and trick you into doing something. Now, the study says that basically 55% of these Cybersquatter domains are malicious or potentially fraudulent.

    So it's not like somebody buying a domain saying, I'm going to, I'm going to buy it, Apple tart, because people type that in by accident when they're trying to go to Apple and maybe I can get Apple to buy it from me, or maybe I can use it as a parody site, et cetera. No. they are leading to malicious content more than 70% of the time.

    So be very careful about the brand. A good example that they've done that has been shut down recently is secure dash Wells Fargo. This is a domain using the Wells Fargo brand, targeting the bank's customers and getting them to click through and use phishing to steal sensitive information. Be very careful when you're out there typing things in or clicking on links, because many of them, it turns out 50-55% of them are malicious and 70% of them are trying to fake you into giving up your own personal information.

    Hey coming back. We've got a very interesting little article by Timothy Lee here in ARS Technica about a court order against the feds and local police departments. So we'll tell you about that. When we get back.

    Stick around, you're listening to Craig Peterson right here on WGAN and Wednesday mornings at seven 30 with Matt.

    ---

    More stories and tech updates at:

    www.craigpeterson.com

    Don't miss an episode from Craig. Subscribe and give us a rating:

    www.craigpeterson.com/itunes

    Follow me on Twitter for the latest in tech at:

    www.twitter.com/craigpeterson

    For questions, call or text:

    855-385-5553

    12 min

About Craig Peterson - Secure Your Business, Your Privacy, and Save Your Sanity

From the publisher's feed

Listen up, folks! At Craig Peterson's one-stop virtual corner, we distill gems from the comically chaotic world of tech and security. It's like grabbing a cuppa joe with your good old buddy, who just…