Tech/Computer advice from me

Yes, I use a password manager that generates complex passwords for every site I care about (ones that are financial in nature). The wi-fi devices (Blu-ray, Apple TV, etc.) are connected to my home internet. If i have a secure password for my modem/router, does that cover me?
 
I just heard about this heartbleed bug yesterday. I've changed a couple of my passwords, but just how big a deal is this?

It's a very big deal, for a variety of reasons. Any time you can get a machine to involuntarily spit contents of memory back to you, you've found the keys to the kingdom. Well... almost :)

Making it even bigger of a deal is the fact that it's open source and as such, used all over the place. Some of the bigger providers use it.

Safe bet is to change your passwords for any site that uses OpenSSL. But don't bother changing until the site has been fixed. You can check by going here:
https://lastpass.com/heartbleed/

Punch in the URL and check the status. You'll want to change common passwords for sites that aren't infected if you used it on a site that is infected.

If you changed your password before the site was patched you effectively did nothing to safeguard against it.

I have to wonder if the folks publishing every detail of how our privacy can be breached in excruciating technical detail are helping or hurting us. It's basically putting up a billboard alerting anyone interested in malicious activity advertising 'how to' accomplish it.

That's one way of looking at it.

The other is that majority of people/companies only pretend to be interested in security. They make grand statements, goals, etc; but when it comes to practice almost everything else trumps security, most common is ease of use. If making it more secure makes it 'harder' to use - then less secure and easier to use is almost always chosen.

The only way to combat that is to make the vulnerability public and force the company to fix the hole. This has been true with large and small companies, rich/poor, popular/mostly unknown.

So, without speaking to the latest issue with openSSL specifically, it's definitely an interesting debate to have.

In fact, right now there is a huge debate in the security community about whether the NSA should be forced to release all the exploits they've found. One side says that will hurt our national security, waste valuable NSA research, money, and time, and possibly give our enemies an edge. The other side is that if the NSA found out about it, so can China, or Russia, or anyone else, and unless the NSA tells manufacturers they found it then the vulnerability will exist for everyone. It's an interesting conversation, with lots of different situations and differing opinions.
 
Last edited by a moderator:
Reading today that Heartbleed can also infect home modems and routers and even wi-fi enabled devices like Blu-ray players.

What can and should the non-IT person do about that?

um, what? who is telling you this...?

heartbleed is about a problem with a specific framework for processing SSL connections - specifically OpenSSL. The only devices that are vulnerable to this are ones using openSSL.

there are modems and routers, and other random devices, that may be using openSSL but I don't think you have anything to worry about.

you have to open up a way for them to get in... if you have the firewall turned on on your modem/router, then they shouldn't be able to get in to abuse any vulnerabilities in the first place.

furthermore, I don't know what can really be expected to happen if someone manages to crack your wireless router (or modem, since that's likely the only thing they'll get into...) using this and examine contents of memory. What is it they're going to get? Your wireless password? Unless they plan on driving to your house, what harm is that going to do? your configuration for your wireless network? local IP's? all of this is meaningless information for them.

If you have a link to a report on it I'll happily read it, but I think the general home user doesn't have anything to worry about unless their network is wide open (which is something to worry about regardless of heartbleed.) You should focus your concern on creating unique passwords for every different site, changing them often, and that sort of thing. You should read the section on passwords here - http://www.bgobsession.com/5-oclock-club/51207-tech-computer-advice-me.html#post132804
 
my wife's hospital still has XP machines.

talking to a few people, the healthcare industry in general has had a real problem getting updated on time.

awful IT staffs. you're in charge of some of the most important data in the non-classified world and you don't update your machines? *sigh*
 
I was talking about the media coverage of heartbleed (which is as hysterically lacking in intelligence as the media coverage on ICANN was a week or so ago) with people and one brought up a good point...

don't most media outlets have entire departments dedicated to vetting sources and shit? why do they not walk down the ****ing hall to their IT dept and ask them "is this bullshit or not?"
like, you don't have to go through a 3rd party, YOU ALREADY EMPLOY EXPERTS

but if they do that then they wont have scary titles to attract all the clicking and ad revenue, so this is what we get.
 
the whole department? a news agency doesn't even ask their IT director about it before running with a story?

i'd like to think Fox News, MSNBC, and CNN have a better IT dept than average companies, if for no other reason than the requirements put on their systems via web and all the equipment they must be running behind the scenes...

it's just the way news is these days.

fact checking and rational thought/conversation is boring.

sensationalism and fear are what gets ratings.

and this is why we have a large number of people being concerned about something that for the most part doesn't impact them. the number of emails that came in from people at work, and family, and friends... all because the media is lazy.
 
um, what? who is telling you this...?

I'm not certain where I was reading when I posed that question, although it's not hard to find references to the subject:

Heartbleed could harm a variety of systems - The Washington Post

[h=1]Heartbleed could harm a variety of systems[/h]
NEW YORK — It now appears that the “Heartbleed” security problem affects not just websites, but also the networking equipment that connects homes and businesses to the Internet.

Two of the biggest makers of networking equipment, Cisco and Juniper, have acknowledged that some of their products contain the bug, but experts warn that the problem may extend to other companies as well as a range of Internet-connected devices such as Blu-ray players.
 
I'm not certain where I was reading when I posed that question, although it's not hard to find references to the subject:

Heartbleed could harm a variety of systems - The Washington Post

[h=1]Heartbleed could harm a variety of systems[/h]
NEW YORK — It now appears that the “Heartbleed” security problem affects not just websites, but also the networking equipment that connects homes and businesses to the Internet.

Two of the biggest makers of networking equipment, Cisco and Juniper, have acknowledged that some of their products contain the bug, but experts warn that the problem may extend to other companies as well as a range of Internet-connected devices such as Blu-ray players.

Hah! That was a much more informed article than I anticipated. Props to the Post.

I guess I jumped to conclusions based off your first post :)

For the average home user there is nothing to worry about. Make sure your firewall is on at your modem/router, and you don't have anything to worry about aside from changing your passwords for websites once they've patched their site.

If you're hosting stuff from home (websites, music catalogs, maybe you have security cameras you stream from outside the home, or stuff like that) then you have some checking to do.
 
I tried out this new email service, because I was tired of all the crap from Yahoo.
It's called GMX..... (gmx dot com)
At first I loved it, because the layout was sleek, easy on the eyes, and user friendly, unlike what I'm used to.
But then I started noticing that literally every single email I sent out, was returned to sender.
I double-checked each email address, and they were all spelled correctly, and valid email addresses.
So then I delved deeper into the returned email, which stated "Please contact your Internet service provider since part of their network is on our block list."
I'm like, "wtf, I never heard of this ? An email service provider has a certain internet provider on a blocked list, so they refuse to send my emails ????".
Why would they do this ?
 
people on the Ubuntu forums say stuff like, "anti-virus protection is not needed on Linux/Ubuntu systems"

is this really true ?

if so, how ?

No, it's not true.

The reason they say this is because the vast majority of viruses are written for Windows operating systems. The reason is simple: That's what majority of people use. Why spend your time writing viruses for a product that has a significantly smaller market share?

So the reason they say you don't need it is because most of the malware out there isn't written for linux.

I would recommend you put something on there.

Antivirus software is hit/miss anyways, often times miss. Your primary concern should be making sure your system is up to date and knowing what you're doing - IE: don't just click buttons.
 
Ubuntu programs require user intervention to install and run, so if you click NO, that should be the last you hear of it, but if you click YES, you are stuck with any problems that might arise.

It is advisable to have anti-virus software of any operating system, so just install one from the Download Centre. If you're not happy with any of them, there are Ubuntu packages for the free versions of commonly used anti-virus software, but you might have to compile the program before installing it.

Every year, hackers from all over the world get together for a contest to see who can hack the three main operating systems. prize money is given out to the first for each o/s. Windows is usually done within 10 minutes of starting, Apple is done is under thirty minutes, whereas Linux is yet to be cracked in four years. Mind you, there is a 90 minute time limit, so given time anything is possible.
 
the people sending out the FBI security advisories (mostly from defense security services/homeland security) are too stupid to put all their contacts in the BCC. So everyone knows direct email address for other people with security clearances.

most of these addresses contain first and last names for the person.

so pathetic.
 
Just like those emails from friends 'warning' you of the latest virus threat, so new that not even anti-virus software developers are aware of it. This virus is so dangerous that it could wipe your whole C: drive if activated. The best thing to do is to forward the email to everyone on your mailing list.

What a load of crap!

The only this virus warning does is create paranoia, and if everyone does forward it, mail systems around the world can be overloaded. The best thing to do is to contact the sender advising them that it is just a hoax, and suggest they contact everyone they sent it to and apologise for sending it.
 
Well the warnings I'm talking about are from homeland security/dss/fbi. They're legit advisories they send out in email blasts to all of their 'clients'.

The problem is the people in charge of spreading security information aren't smart enough to use BCC to conceal who they're sending it to.

They're basically just creating lots of large lists of people with security clearances.

It's a violation of common sense, both in the clearance field and in the IT security field.

I'm sure the people responsible for distributing these reports/advisories are low on the totem pole in the security department, but still, you'd think such a basic practice would be taught and put in place.

Of course, the NSA leaks all came from employees not being taught to not give their passwords out. Which is also security 101. I wouldn't even think that would need to be taught at an agency like the NSA, but apparently it does. I guess I just have too high of expectations.
 
On the subject of TV's/DVD's....

I just hooked up my Mom's new DVD player. But during video play, there is a constant large, rectangular, and solid-black box, that covers up the bottom half of the screen. If you press any command button on the TV or the DVD player, it returns to a full video screen, but only for a few seconds, then the big black box returns. I tried playing around with the video cable, and again, if you remove the video cable and put it back in, the video screen is normal for a few seconds, until the box returns.

Then I swapped out my own "working DVD player" into the same TV, and it did the exact same thing.
Now I know the issue is with the TV, and not the new DVD player.
So, my question is, is it the result of some menu setting on the TV, that can be easily re-adjusted, to remove the box ?
Or is it just a TV gone bad ? (unlike the DVD player, the TV is much older)
 
Last edited:

Users Who Are Viewing This Thread (Total: 1, Members: 0, Guests: 1)

Help Users

You haven't joined any rooms.

    You haven't joined any rooms.
    Top