Wednesday, June 29, 2011

What You Can Do If Your Bank Has Been Hacked: Not Much













Citigroup has admitted that several thousand customers lost more than $2 million not by misplacing their credit cards, falling victim to scammers or making risky gambles. Their only mistake: trusting the bank with their data.
By no fault of their own, consumers that entrust companies with their personal information -- something that has essentially become mandatory in a day and age where every click, swipe, note and check can be immediately and cheaply stored on servers -- are being put at risk for theft and fraud because corporations can't defend themselves against hackers aiming to pilfer vast troves of data consisting of names, email addresses, credit card numbers and more.
Citigroup told government officials that $2.7 million had been stolen from 3,400 consumers after hackers compromised credit card information belonging to over 360,000 accounts, according toBusinessweek. While the account holders will be reimbursed by the company, Citigroup cannot retrieve their data, which included names and contact information.
The bank is one of several corporations that have suffered major online security breaches. Earlier this year, over 100 million users had their names, passwords, addresses and email addresses stolen by hackers that broke in to Sony’s servers, while Epsilon, an email marketing provider that sends 40 billion emails a year for over 2,500 clients, acknowledged hackers had accessed its list of names and email addresses.
This rash of cyberattacks highlights the new risks consumers face as more and more information about their bank balances, shopping habits, friends and hobbies is being stored on remote servers that are vulnerable to break-ins by hackers around the world. These breaches also underscore how powerless customers are: Once they have handed over their data, there’s little they can do to safeguard it. Though users can take precautions, such as steering clear of malicious software and being wary of fake phishing sites, to ensure they are not personally attacked, experts say there’s really only one thing that individuals can do to prevent hackers from breaking into companies’ databases: cross their fingers.
“There’s not much that consumers can do when Citibank gets hacked,” said Jeremiah Grossman, the chief technology officer of WhiteHat security, a web security company. “They can protect themselves from getting hacked, but not Citibank. That’s outside their control.”
Analysts predict that the number, scale and sophistication of cyberattacks targeted at corporations -- and the data they hold -- will continue to grow. And though companies may fortify their defenses after each successful breach, hackers are likely to stay at least one step ahead, they warn.
“Everyone’s data is out there and everyone uses online systems, so breaches have been the natural course of events and they will continue to be,” said Grossman. “No one would say the breaches will stop or even slow down at this point. Companies will become more secure, then the bad guys will shift tactics.”
Consumers cannot verify that a company is doing everything in its power to protect their information, such as encrypting the data, using updated software and maintaining logs of everything going into and out of its servers. But individuals can mitigate the damage they would suffer from a data breach by being choosy about what information they share with services and in some cases, lying about the personal details they pass along.
Of course, some sites need honest answers -- giving Amazon.com a fake address would make it all but impossible to effectively order books -- but other websites need not necessarily know when you were born or where. Experts recommend that users invent the answers to security questions that are used to recover lost or forgotten password to ensure that if the "secret answer" to one account is compromised, others will not be vulnerable. Gmail will not know that "Batgirl" was not your mother’s maiden name.
“You need to think about whether you need to tell the truth to certain organizations,” said Graham Cluley, a senior technology consultant at Sophos, a security provider . “Sony has no way of verifying my date of birth. If you haven’t told the truth then you doesn’t matter if you lose that data, you haven’t lost anything that matters.”
Users can also mitigate the effect of a hack by ensuring that they use a different password for every account they have on the web. If hackers gain access to a trove of usernames and passwords, they may attempt to use that information log into other accounts, and one compromised account could quickly put every other at risk.
"Even if your password at Sony is compromised, let’s make sure that that doesn’t unlock any other doors for hackers," said Cluley. "You should use a different password for each site, it limits how far hackers can spread the harm."
Though no company is invulnerable to cyberattacks, consumers concerned about the safekeeping of their personal information ultimately have the option to turn their backs on firms that don’t demonstrate a commitment to safeguarding their data. Corporations that lose users' trust also lose their dollars and their data, and web giants like Facebook and Google have repeatedly said that their success is tied directly to how users perceive the safety of their information.
“More fool you if you keep on working with a company which has a poor track record of looking after these things,” Cluley said. “My hope is that individuals will begin to put more emphasis on security and the track record of how well these companies keep track of our data than on some of the bells and whistles they might offer.”

Tumblr Logins Stolen In Widespread Phishing Attack: GFI Labs













"Thousands" of Tumblr logins have reportedly been compromised after a widespread phishing attack scammed users into handing their information over to an untrustworthy third party.
According to a post from GFI Labs, a part of software vendor GFI Software, the attack started with a site, designed to look like an official Tumblr page, that offered people the chance to take a "Tumblr IQ Society" quiz if they entered their login credentials. The scam has evolved, and now uses the promise of pornography to get at people's information, directing people to a landing page that reads, "This page contains adult content. Please revalidate your credentials."
"The problem does indeed seem to be out of control at this point," wrote GFI Labs in a blog post, noting that the scammers have successfully grown the scale of the attack by taking over the compromised accounts and using them gain access to even more logins.
GFI Labs writes,
The pages involved are all regular Tumblr users who have previously been compromised. Once hijacked, their pages are converted into the fake logins and then sent into the world following regular Tumblr accounts. At that point, the phisher hopes those same accounts will visit the fake login, enter their details and keep the cycle going.
Tumblr did not immediately respond to a request for comment on the matter.
Users can find out more about phishing scams affecting Tumblr on Phishing-Alert.Tumblr.com. Anemail allegedly from Tumblr, obtained by GFI Labs, outlines additional advice Tumblr has for users who have been affected by the scam. The email advises these users to immediately change their passwords and has instructions for how to change the appearance of their page.
Were you affected by the phishing scam? Let us know in the comments below.

Tech::Biz Stone Leaving: Twitter Co-Founder To Relaunch Obvious Corporation













Twitter co-founder Biz Stone has announced on his blog that he will be departing the microblogging site.
The 37-year-old entrepreneur will be moving on from the company just 5 years after its launch. He will not be cutting all ties with Twitter, however, and noted in his blog that he aims to remain a "strategic asset to Twitter" and will still "commit part of my time to hands on help with Twitter wherever and whenever I can be of assistance."
While the exact reasoning for his departure seems a bit unclear at the moment, the blog post this afternoon suggested a bit of a disconnect with the company at large. Stone wrote,
During this time—especially lately, it has come to my attention that the Twitter crew and its leadership team have grown incredibly productive. I've decided that the most effective use of my time is to get out of the way until I'm called upon to be of some specific use.
Stone's departure comes in the midst of a bit of turbulent time for Twitter. According to a recent Fortune article, there has been a bit of internal trouble at the social networking site for some time.
As for what he plans to do next, Stone also announced that he and fellow Twitter co-founder Evan Williams will be relaunching Twitter's once-parent company, The Obvious Corporation.
As for the bulk of my time day-to-day, I'm thrilled to announce that Evan Williams, Jason Goldman and myself will be relaunching The Obvious Corporation as co-founders. Our plan is to develop new projects and work on solving big problems aligned along a simple mission statement: The Obvious Corporation develops systems that help people work together to improve the world. This is a dream come true!

Tuesday, June 28, 2011

Tech::More Myspace Layoffs Expected This Week: Report

Myspace Layoffs

After laying off close to half its staff this January, Myspace will reportedly be continuing the cuts.

According to TechCrunch, the site will fire at least 150 of the 400 employees remaining, or about 37.5 percent of the staff. Another source added that an additional 150 employees would be put on a plan to work for pay for a short period of time while seeking new employment. The layoffs are said to be happening Wednesday.

Myspace's difficulties have been rapidly accelerating since the initial announcement of its staff cuts. Parent company News Corp has been actively looking for some buyer to take the ailing social network off its hands, though early reports that Myspace was in talks with such companies as Vevo and Zynga have changed to suggest that the company may have one bidder, an investment group led by Activision CEO Bobby Kotick.

Newscorp bought Myspace for $580 million in 2005, but is expected to ask for around $100 million in the upcoming sale. In the wake of Facebook's rise, Myspace has been losing users at an increasing rate. 


Mununuzi Timothy
http://about.me/munruzi
munruzi@gmail.com
+256712592279
+256700394669
Turning Green to Gold





Tech::Office 365: Microsoft Confronts Google By Putting Office In The Cloud

Microsoft Office 365


By Bill Rigby
SEATTLE | Tue Jun 28, 2011 6:24am IST
(Reuters) - Microsoft Corp is making its biggest move into the mobile, Internet-accessible world of 'cloud' computing this week, as it takes the wraps off a revamped online version of its hugely profitable Office software suite.

The world's largest software company is heaving its two-decade old set of applications -- including Outlook email, Excel spreadsheets and SharePoint collaboration tools -- into an online format so that customers can use them on a variety of devices from wherever they can get an Internet connection.

It wants to push back against Google Inc, which has stolen a small but worrying percentage of its corporate customers with cheaper, web-only alternatives, which remove the need for companies to spend time on installing software or managing servers.

"It's obvious that Microsoft has to do this if they're going to remain competitive with Google," said Michael Yoshikami, chief executive of money manager YCMNET Advisors. "It's something they have to do."

Microsoft shares rose 3.7 percent on Monday, the largest gain in a single trading day since September, partly buoyed by hopes that it can ultimately boost profits by extending its software dominance to the growing cloud sector.

"If they execute effectively and it's adopted, it could be a game changer," said Yoshikami. "Whether or not that will happen is a whole other story."

Microsoft has offered online versions of some Office programs -- chiefly Outlook email -- for its corporate customers for several years, and last year rolled out free versions for individual home users.

Chief Executive Steve Ballmer is set to present an overhauled and updated set of offerings -- collectively called Office 365 -- at an event in New York City on Tuesday morning, underlining the company's newfound online focus.

GROWING MARKET

The market for web-based software services is heating up, and every company, government department and local authority is getting pitches from Microsoft and Google whenever they re-evaluate their office software.

It's a new challenge for Microsoft, which built itself up on expensive versions of software installed on individual computers. That business model turned the Office unit into Microsoft's most profitable, earning more than $3 billion alone last quarter.

Microsoft's plan is to make up for smaller profit margins from web-based applications -- due to the cost of handling data and keeping up servers -- by grabbing a larger slice of companies' overall technology spending.

Last October, when it rolled out a test version of the new service, Microsoft said it planned to charge from $2 per user per month for basic email services to $27 per user per month for advanced offerings. Google charges a flat fee of $50 per user per year for its web-based Google Apps product, which offers email, calendars, word processing and more online.

Microsoft, like Google, will host users' data remotely, and maintain all the servers in vast data centers. Unlike Google, it will also allow companies to put their data on dedicated servers if they choose, or keep the data on their own premises.

The full launch of Office 365 will spice up the lively competition with Google for new users.

Earlier this month, Google snagged InterContinental Hotels Group as a major customer, moving 25,000 of its employees onto Google email from Outlook.

Google, which has had the most success in the small and medium-sized business range, says there are now 40 million users of online Google Apps suite. Microsoft does not publish equivalent numbers, but research firm comScore has estimated 750 million people worldwide use Office in some form.

But Internet-centric Google -- whose success is based on its dominance in web search -- is confident it has the upper hand in the cloud.

"Compared to what they (Microsoft) have in the market today, they have nowhere to go but up," said Dave Girouard, head of Google's worldwide enterprise business. "We feel we're years ahead of them in terms of building a viable cloud solution that just works."

(Reporting by Bill Rigby; Editing by Phil Berlowitz)


Mununuzi Timothy
http://about.me/munruzi
munruzi@gmail.com
+256712592279
+256700394669
Turning Green to Gold





Tech::Homeland Security Department To Help Protect Business Websites

Homeland Security Hackers

WASHINGTON -- Businesses facing a growing threat of cyberattacks against their websites will now have more tools to protect themselves and harden their Internet sites against hackers.

The Homeland Security Department will help small companies and nonprofit groups avoid programming problems that allow hackers to get into the businesses' websites.

The government's latest cybersecurity effort follows a series of high-profile hacking attacks against corporate and federal websites, including one that shut down the CIA's site for several hours last week.

The new program was developed with the Mitre Corp. and is an effort to shore up known weaknesses in programming that give hackers a backdoor into websites. The effort began well before the recent website attacks.

It includes a list of top 25 technical software problems that hackers exploit and sets up a way to rank software so that customers can see whether it meets necessary standards.

Right now, when owners of small businesses buy software or hire a firm to build a website, it is difficult to know whether the programs are secure or not, said Alan Paller, director of research at SANS Institute, a computer-security organization.

He said the information, which has been compiled on a special website that the public can view, will tell people what to look for in setting up a secure website and how to judge potential programming errors. It also sets up a scorecard, so that companies looking for a firm to set up a website can check their security score.

The effort is aimed at the more than 1 million computer programmers and other high-tech professionals who write code, build websites and develop software. It lays out known software weaknesses and how to fix them.


Mununuzi Timothy
http://about.me/munruzi
munruzi@gmail.com
+256712592279
+256700394669
Turning Green to Gold





Tech::Anonymous Apparently Declares 'War' On Orlando, Florida

Anonymous Orlando

Orlando, Florida: home of Disneyworld, and newest target of hacker group Anonymous.

The Washington Post reports that Anonymous has apparently posted a new release threatening to take down websites belonging or relating to the city of Orlando.

This new effort comes as a response to the arrests of Food Not Bombs non-profit workers who have been distributing food to the homeless without permits. The group's compliance with city ordinances has, in the past, caused tension between workers and the city government. Orlando Mayor Buddy Dyer has allegedly referred to Food Not Bombs members "food terrorists," according to a quote in the Orlando Sentinel.

"This is a declaration of war," read the supposed Anonymous release, which TechCrunch has posted in full. "Henceforth there will be no more cease fires, no more attempts to get you to resolve this issue with human decency. We will now treat you like the human rights abusers that you are."

The release also contained a warning that "Anonymous will now begin a massive campaign against you and your city web assets. Everyday we will launch a new DDoS attack on a different Target."

The authors of the release went on to say that Anonymous planned to take down the Orlando Florida Guide at 10 AM today and leave it down until 6 PM. At the time of this writing, the site is down.

Anonymous is tweeting out its actions at the handle @oporlando2011.


Mununuzi Timothy
http://about.me/munruzi
munruzi@gmail.com
+256712592279
+256700394669
Turning Green to Gold





Tech::Fastest Mobile Networks 2011: The Top 5 Networks Ranked By PC Mag

[Ed. note: A previous version of this post incorrectly stated that AT&T had fallen to "eighth place" on this year's list of the fastest nationwide carriers. AT&T, in fact, sits at number three on the list. We regret the confusion.]

As a followup to a similar study conducted in 2010, PC Mag has tested and ranked the speediest mobile networks (both 3G and 4G) in the U.S., based on data collected in 21 cities nationwide.

"Our tests will give you information about mobile broadband Web connections from smartphones, tablets, and laptops. The results tell you which networks are the fastest, and which are the most consistent," writes PC Mag. Like last year, networks' coverage and call quality were not assessed.

There were a few shakeups on this year's list of the nation's fastest carriers, due in part to the introduction of 4G networks in the U.S. While AT&T was named the fastest in 2010, the carrier has dropped to third place. 2011's new winner (see slideshow) nabbed the top spot with it blazing 4G, which offers "speeds that often exceed home Internet connections," according to PC Mag's tests.

You can view winners of PC Mag's national assessment (below). Read the entire study at PC Mag to see which carriers were fastest by region and to learn more details about how the study was conducted. Then, view last year's results to see how they compare with this year's.


Mununuzi Timothy
http://about.me/munruzi
munruzi@gmail.com
+256712592279
+256700394669
Turning Green to Gold





Tech::Citigroup: $2.7 Million Stolen From Customers As Result Of Hacking

Citigroup Hacked Hack 27 Million

After a cyberattack hit Citigroup, exposing over360,000 user accounts, the bank has come forward to reveal just how much money's been lost.

The answer: $2.7 million was lost, affecting about 3,400 people, according to Bloomberg Businessweek. The bank will reimburse customers for their loss. Over 200,000 customers were issued new cards with a notification letter.

Citibank has been criticized, however, for not offering customers a full year of preventive credit file monitoring services, the standard for large companies having suffered such attacks.

Experts have suggested that hackers used spywareto capture data from customers as they logged in, though they were not able to get the CVV codes that accompany the physical card. With 154 million Americans owning credit cards, the incidence of such hacks is only expected to rise.

The first half of 2011 has already seen a number of major hacks, including, but not limited to, a series of hacks on Sony, subsequent hacks on Sega, PBS, the CIA, the Senate, and more.


Mununuzi Timothy
http://about.me/munruzi
munruzi@gmail.com
+256712592279
+256700394669
Turning Green to Gold





Thursday, June 23, 2011

Tech::6 Easy Steps To Increase Your Privacy On Facebook

Organizing all of your Facebook friends into separate lists can help save you time and enhance the privacy of your posts and profile information.

You can set up friend lists for family, close friends, college pals, coworkers, industry friends, exes, and, well, whatever else you like. Then you will able to selectively share information using your Facebook account.

For starters, you'll be able to post messages that are viewable only to the lists you designate. What's more, you'll be able to adjust your privacy settings so that your profile details are accessible only to your chosen friend lists.

Six Really Easy Steps

Follow these six simple steps to create a friend list on Facebook. You can create up to 100 friend lists and each list can contain up to 1,000 friends. If you like, friends can appear on multiple lists.

  1. On your Facebook homepage, click on the friends icon  in the navigation bar running down the left column.
  2. At the top right of the page, click on the icon with the pencil that reads "Edit Friends."
  3. At the top right of the page, click on the icon with the plus sign that reads "Create A List."
  4. A box will appear that reads "Create New List." In the text box below this, that reads, "Enter A Name," type in the name of the friend list you want to make, for example, "Industry".
  5. You will see all of your friends appear in this box. Click on the names of the people you would like to add to the list you just made. Once you select a name, a check box will appear and the name and photo of the person you selected will be highlighted in blue. As you view all of your friends using the scroll bar at right, you can toggle at the top left of the box between "All" (which shows your entire friend network) and "Selected" (which shows the friends you have chosen to be to part of the list).
  6. Click on the link labeled "Create List" to save the changes you made

Modifying Friend Lists

At any time, you can change the name of the list or change the people on the list by selecting the "Edit" link that appears to the right of the list name.

To view, add or delete friend lists, go to your friends page and click on the "Edit Friends" button. Your friend lists will appear in the column at left. Click on each list to modify or delete it.

Limiting Who Sees What

When you post a status update, you can make it visible only to a selected friend list. To do this, after you type your message into the status update box, click on the lock icon. Scroll down and select "Customize." Click on the drop-down menu under "Make This Visible To." Select "Specific People." Type in the name of the list you want to be able to see the status update.

To limit the people who can view your profile information to a friend list, click on "Account" at the top right of your screen.

Click on "Privacy Settings." Then click on "Customize Settings" at the bottom left of the main text box.

For each option listed at left you can select from the drop-down menu at right "Customize." Then, where you see "Make This Visible To", click the drop-down menu and select "Specific People." Type in the name of the selected friend list that you want to be able to view your profile.

Keep in mind that Facebook may continue to change its friend list interface in future. In the meantime, we suggest you forward this post to people you know who don't have any lists set up yet — this might help get them started.


Mununuzi Timothy
http://about.me/munruzi
munruzi@gmail.com
+256712592279
+256700394669
Turning Green to Gold