Archive for May, 2018

If You Care About Security On Your Home Network, Turn Off UPnP

Posted in Commentary with tags on May 16, 2018 by itnerd

UPnP stands for Universal Plug And Play. The idea behind this technology is that networked devices such as personal computers, printers, Internet gateways, Wi-Fi access points and mobile devices to seamlessly discover each other’s presence on the network and establish functional network services for data sharing. It sounds great because it takes some of the complexity setting up devices on your home network.

It’s also a great vehicle for hackers to enlist your devices to pwn others. And has been for years. And when I say years, I mean that security issues have been found in UPnP going back into the previous decade.

Researchers at cyber security firm Imperva have posted a paper that describes how UPnP can be used to enlist UPnP enabled routers that may be badly secured to execute a pretty crafty distributed denial of service attack. I say crafty because the attack that the researchers describe can evade some defense mechanisms to mitigate at distributed denial of service attack. What’s concerning about this is that the researchers found 1.3 million devices that on the surface could be exploited for such an attack. That’s kind of scary.

My advice? If you have a router which supports UPnP, disable the protocol immediately. I haven’t yet stumbled upon a router which does not permit disabling UPnP, so as far as I am concerned, that should be a no brainer to help you to avoid having your router enlisted for mass pwnage.

Diamond Bank’s #TechFest2018 to Create Opportunities for African Start-Ups

Posted in Commentary on May 15, 2018 by itnerd

Nigeria’s technology space is set to witness a game-changing experiential platform with the unveiling of #TechFest2018​ by Diamond Bank Plc in partnership with MTN, Visa, Microsoft, NIBSS, Deloitte and Touche, Interswitch and Beat FM.

de618634850931e17f4bdae88abe.jpg

Scheduled for Tuesday, 15 and Wednesday, 16 May 2018 at the Landmark Event Centre, Oniru, Lagos, Tech Fest will feature the best talent in the Nigerian technology space – one of the country’s fastest growing sectors. The event will showcase technological solutions for businesses, connect technology providers with new markets, provide access-to-market opportunities for tech start-ups amongst others.

The event also featured partners like Microsoft, Beat FM and NIBSS who affirmed that Tech Fest will provide opportunities for SMEs and young tech entrepreneurs to network and meet sponsors, financiers, and partners that will help them grow their businesses.

TechFest is open to all who want to connect, collaborate and co-create new ideas that solve real problems for Nigeria.

OpenTable Unveils Business Intelligence Suite for GuestCenter

Posted in Commentary with tags on May 15, 2018 by itnerd

OpenTable has today announced a business intelligence suite for its flagship restaurant management product GuestCenter. The new suite gives restaurants the tools and insights they need to seat more guests, better understand their diners’ booking habits and preferences, and personalize hospitality to help turn first-time diners into regulars.

image001.png

The business intelligence suite provides powerful insights and recommendations to help restaurants grow and thrive:

  • Shift Occupancy Analysis: Analyzes monthly and yearly historical occupancy to help identify occupancy trends and forecast demand.
  • Turn Time Optimization: Uncovers opportunities to optimize turn times to maximize busy shifts and seat more guests
  • Booking Insights: Analyzes reservation data to provide insight into where diners are coming from.
  • Referral Insights: Tracks referrals, concierge relationships and reservations, giving restaurants insight on who is referring the business and the number of guests they are sending to the restaurant.
  • Restaurant Owner app: Presents quick analytics into how the business is performing on a monthly and shift basis, giving restaurateurs the knowledge they need to make informed and strategic decisions.
  • Monthly Business Reports: Shares actionable insights for busy owners and GMs, ensuring stakeholders stay informed with top-line reporting.

Additional analytics will be rolled out in the coming months, including a first time guest and visit frequency report; and covers and reviews analysis. These additional reports will help restaurants understand where their diners come from and how to convert them into regulars.

To learn more about the business intelligence suite for GuestCenter, please visit the website here or watch the video:

Kaspersky Moving Core Infrastructure To Switzerland To Make Spying Concerns Go Away

Posted in Commentary with tags on May 15, 2018 by itnerd

Kaspersky has been accused of aiding the Russian government in its espionage of other countries and foreign companies. Being that the company makes security software, you can see how this would be seen as a potential threat to many.  Despite if the claims are true or not, people are not choosing Kaspersky software due to its connection with Russia, and the Russian government does have a trend of getting involved in its companies. Companies with sensitive information are not using the software. Which is why Kaspersky is moving core infrastructure to Swizerland in the hopes that people will trust them again. From Security Week:

It is to maintain or regain trust that is behind Kaspersky’s Global Transparency Initiative, announced in October 2017.

“The new measures,” the firm announced, “comprise the move of data storage and processing for a number of regions, the relocation of software assembly and the opening of the first Transparency Center,” which will be in Zurich. 

The measures in question include customer data storage and processing for most regions; and software assembly including threat detection updates. Transparency will be provided by making the source code available for review by responsible stakeholders in a dedicated Transparency Center. 

The company said that by the end of 2018, its products and threat detection rule databases (AV databases) “will start to be assembled and signed with a digital signature in Switzerland, before being distributed to the endpoints of customers worldwide.”

The firm is going further by making plans for its processes and source code to be independently supervised by a qualified third-party. To this end, it is supporting the creation of a new, non-profit organization able to assume this responsibility not just for itself, but for other partners and members who wish to join.

To me, moving to Switzerland doesn’t seem to fix this issue. I say that because all it will take is a request for the CEO to send or “Backup” their data to a Russian Data center, or to an 3rd party data-center that Russia may have access too. Assuming that Russia doesn’t just plug themselves into this environment that they’re building in Switzerland. Thus while this might be good PR, it really won’t solve the fact that people don’t trust Kaspersky.

WireIE Unveils New Partnership to Enhance Broadband Services for Canada’s Indigenous Communities

Posted in Commentary with tags on May 15, 2018 by itnerd

One of Canada’s premier wholesale network operators today announced a new partnership designed to significantly enhance and improve broadband services for Indigenous communities across the country.

WireIE, the nation’s industry leader in delivering high availability and secure data over networks in rural and remote regions, is teaming up with Frontline 360 Inc. to be the exclusive distributor of the company’s Internet Protocol TV (IPTV) platform for Indigenous communities and wholesale customers.

WireIE specializes in the deployment of MEF-Certified Carrier Ethernet networks to Canada’s underserved markets and has unique expertise in owning and operating Ethernet Networks for the carrier, oil and gas, utilities, healthcare and government industries.

The Frontline-powered IPTV platform will now be a part of WireIE’s broadband solution and is set to increase opportunities for local economic development in underserved markets.

WireIE is currently deploying Frontline’s IPTV platform with K-Net Services (a division of Keewaytinook Okimakanak Northern Chiefs Council), a First Nations owned and operated telecommunications provider and internet service provider (ISP) in Sioux Lookout, Ontario.

Following the successful rollout of today’s announcement, WireIE will pursue further partnerships with other Indigenous ISPs and communities.

To learn more about WireIE, visit their website at: www.wireie.com.

Chili’s Pwned…. Unknown Number Of Debit & Credit Cards Exposed

Posted in Commentary with tags on May 15, 2018 by itnerd

The parent company of the restaurant chain known as Chili’s has announced that the restaurant had been hit by a data breach that left an unknown number of customer debit and credit card numbers exposed to hackers. The firm said that the hack occurred between March and April and involved malware but little else has been revealed. Since the company doesn’t collect any other data, there’s little chance that SSN’s and the like are floating around out there. But this is clearly not good. The company suggests that you monitor your bank cards to ensure that no fraud takes place and the company has said that it will post updates on their website.

Clearly this isn’t a trivial hack and hopefully this sends a message that companies have to do a much better job of protecting themselves from pwnage.

Alexa Now Unlocks Yale Smart Locks

Posted in Commentary with tags on May 14, 2018 by itnerd

Yale Locks & Hardware today announced expanded support for Amazon Alexa with the addition of voice unlocking for its Assure Lock line of smart deadbolts when used with a compatible smart home hub or when used with the Amazon Echo Plus and a Yale Assure Lock with Zigbee.

The Alexa lock skill already allows Yale Z-Wave and Zigbee users to lock their door and check current lock status. With the addition of the new unlock skill, Yale Assure Locks can now be unlocked using Alexa voice commands. The unlock feature is turned off by default, and is enabled by verifying your Amazon credentials using the Alexa app. For voice unlock, users are prompted to set a four-digit voice code and then asked by Alexa to say that code to unlock. Alexa will only complete the unlock request once the correct voice code is provided. Unlocking can also be done directly from the Alexa app.

The Yale Assure Lock line includes a wide variety of keypad deadbolts in both keyed and key free versions. The line features Yale’s unique modular system that simplifies integration with a home automation or alarm system. Each Yale Assure Lock deadbolt can be purchased as a standalone PIN-controlled lock or with a Yale Network Module installed for smart home integration. Yale offers Network Modules for Z-Wave, Zigbee or HomeKit systems. The module simply plugs into the interior half of the deadbolt, and can be added or swapped at any time by the homeowner

Libraries Come Together to Help Entrepreneurs Launch Businesses with Focus on Women and People of Color

Posted in Commentary on May 14, 2018 by itnerd

Starting one’s own business may soon become the most viable path to achieving the American dream. It is projected that by 2020 half of all workers will be independent freelancers, responsible for their own fortunes and well-being. Knowing this, the Urban Libraries Council is bringing together 12 public library systems from across the U.S. and Canada to explore ways libraries can reach and engage entrepreneurs in their communities — particularly people of color, women, immigrants and veterans. Entrepreneurs play an increasingly important role in growing local economies as technology continues to transform the labor market. However, barriers to resources and information prevent many individuals from pursuing or achieving entrepreneurial success. Public libraries are uniquely equipped to reach populations who are underrepresented in today’s entrepreneurial economy and most in need of guidance.

This effort is an extension of ULC’s collaboration with the Ewing Marion Kauffman Foundation to strengthen libraries’ capacity to support entrepreneurship.

The Urban Libraries Council also released a Leadership Brief titled Strengthening Libraries as Entrepreneurial Hubs, which you can read here.

The participating library systems have proposed the following projects to explore new approaches to reaching and engaging entrepreneurs in their communities:

  • Austin Public Library (Texas) will develop partnerships with local businesses and associations to offer workshops for starting and growing a successful small business, and will create a space for resources needed by entrepreneurial startups.
  • District of Columbia Public Library will develop a strategy to target library resources and partner-led programs toward citizens returning from jail seeking to become entrepreneurs.
  • Durham County Library (N.C.) will provide access to free co-working spaces that will feature innovative technology, resources and relevant programming.
  • East Baton Rouge Parish Library (La.) will develop a program to connect their business librarian to established and new entrepreneurs, to provide them with customized library resources to meet their specific needs.
  • Enoch Pratt Free Library (Md.) and Baltimore County Public Library will develop a program supporting economic independence through entrepreneurship for small, minority- and women-owned businesses by providing access to a collaborative network of library resources, services and partnerships that offer education, training and support services.
  • Kansas City Public Library (Mo.) will work to bring multilingual small business and entrepreneurship programs to immigrants and refugees in Kansas City.
  • King County Library System (Wash.) will develop and implement a holistic and equitable approach to addressing the needs of immigrant and refugee entrepreneurs through research into local economic development plans, sector strategies and demographics.
  • Mid-Continent Public Library (Mo.) will develop its Food Ed program that concentrates on the first steps of starting a food business.
  • St. Louis County Library will explore new ways to grow its monthly educational series that engages local entrepreneurs with outreach events, instructional sessions and a small business and nonprofit expo.
  • Toledo Lucas County Public Library (Ohio) will develop a more comprehensive understanding of the challenges facing aspiring women and immigrant entrepreneurs as well as how those obstacles differ for aspiring male entrepreneurs, and will analyze strategies to attract and effectively serve both groups.
  • Toronto Public Library will develop an entrepreneur-in-residence program and perform community outreach to newcomers in the community, focusing on women and refugees.

The Urban Libraries Council, founded in 1971, is the voice for public libraries and the force that inspires them to evolve. ULC creates the tools, techniques, and ideas to make ongoing improvements and upgrades in services and technology. ULC also speaks loudly and clearly about the value public libraries bring to communities, and secures funding for research that results in the development of new programs and services. And by serving as a forum for library leadership, ULC produces innovative ideas and best practices that ensure community impact.

PGP & S/MIME Email Vulnerable To Being Read By Third Parties Say Researchers

Posted in Commentary with tags , , , on May 14, 2018 by itnerd

A group of European security researchers have released a warning about a set of vulnerabilities affecting users of PGP and S/MIME. These are standards that prevent people from reading your email by securing and encrypting it. Except the researchers have shown that people can still read your email. Here’s the details from the EFF:

A group of European security researchers have released a warning about a set of vulnerabilities affecting users of PGP and S/MIME. EFF has been in communication with the research team, and can confirm that these vulnerabilities pose an immediate risk to those using these tools for email communication, including the potential exposure of the contents of past messages.

And:

Our advice, which mirrors that of the researchers, is to immediately disable and/or uninstall tools that automatically decrypt PGP-encrypted email. Until the flaws described in the paper are more widely understood and fixed, users should arrange for the use of alternative end-to-end secure channels, such as Signal, and temporarily stop sending and especially reading PGP-encrypted email.

The flaws seem to affect Apple Mail with GPGTools, Mozilla Thunderbird with Engimail, and Outlook with Gpg4win. You’re going to note that all those email clients have to be used with a secondary application or plugin for PGP and S/MIME to work. That’s because the problem is in how email program plugins handle the mail after it’s been decrypted, not in the underlying PGP/SMIME code. And only for HTML emails, and only in the email clients noted above. So if you are using a different email client then you are fine. Probably. If you understand how PGP/SMIME works, and are willing to do some manula work, then you are still fine.

Well see what all the affected vendors do to address this as I suspect a response will be quick.

DEVELOPING: Users Of Belkin’s WEMO NetCam Cannot Log Into Their Accounts

Posted in Commentary with tags on May 14, 2018 by itnerd

Thanks to a reader of this blog, I’ve been alerted to a problem with whatever back end service that runs access to Belkin’s WEMO NetCam products. After digging in to confirm what the user told me, I can say that the following is going on. Users of these cameras are unable to log in via their smartphones to view their camera(s) or change settings. And they sometimes get this error when they try to log in:

IMG_1521

Other times the app seems to hang. I was able to reproduce this myself and I validated that the ports that are referenced in the error message are open. Deleting and reinstalling the NetCam app does not resolve this.

Based on this thread on the Belkin forums, this started on May 12th and the moderator on the forum claims to have escalated the issue. It seems to be restricted to iOS devices at this time, and users can still log into the web portal at netcam.belkin.com assuming that they are using a browser with Flash installed. So users aren’t totally dead in the water, but this is far from ideal.

The reason why this reader reached out to me is due to the fact that he feels that disclosing this to the media is the only way to get Belkin’s attention. He has that perception because of my coverage of the Linksys WRT32X issues from last year and earlier this year. I am not sure if I truly accelerated a fix for that, but the fact that this reader feels that way is a problem for Belkin as that shows that people don’t entirely trust them. Thus I hope a fix for this comes quickly to restore the confidence of their customers.

Watch this space for updates.

UPDATE: A second thread on this topic with some not so happy Belkin NetCam users is also present on their forums. There’s also the suggestion that there is a “major” outage with WeMo products in general. But I cannot find any evidence that supports this.

UPDATE #2: There is some speculation on the Belkin forums that iOS 11.3.1 is responsible for this as people who have earlier versions of iOS appear to be fine. But using that logic, this problem should have appeared on April 25th or thereabouts when iOS 11.3.1 was released. But as far as anyone can tell, this issue appeared this past weekend.

UPDATE #3: Reports are coming in via the Belkin forums that WEMO Netcam users are able to log in now. I have confirmed this as well. I will continue to monitor this, but it appears that this issue is coming to an end. Likely via a back end fix.

UPDATE 4: Consider this issue to be resolved.

However, some points for Belkin on this that they should consider. Belkin has a Twitter handle called @WEMOCares which references another Twitter handle called @WEMOOutages. Neither have been updated in years. Which is bizarre because the former is referenced here. But to be fair, there’s a link that says @WEMOCares that goes to @BelkinCares and one that goes to @WEMOCares. Belkin should clean that up.

The reason why this matters is that I was looking to see if Belkin had posted any info on whatever happened to the WEMO NetCam and found nothing on any of their Twitter handles. And to find two of them that haven’t been used in years is very disappointing as it gives the impression that the WEMO line of products isn’t one that they care about. Not only that, but there was very little in the way of much communication from Belkin other than to say that the issue was escalated. That really isn’t a winning strategy in this day and age where transparency and communication wins the day 100% of the time. Belkin should take a good hard look at how they communicate to customers. I say that because the person who reached out to me did so because he thought that because I would publish this (which I did) it would get the issue resolved faster as it had been an issue for days apparently. There’s something wrong with the universe when a user of a product has to do that as it highlights that perhaps a company not only should be communicating better to its customers, but they also need to restore some trust as well.

Some food for thought for Belkin.