Showing posts with label internet security. Show all posts
Showing posts with label internet security. Show all posts

Sunday, 21 January 2018

Indoor Sunday

Another rainy day here, with two dozen people for the Sunday Eucharist. Afterwards I spoke with the elder sister of a teenager who's started singing in the choir. They're from Bulgaria. The lad is still in school, but his sister who's been here longer, has run her own restaurant in Montreux, and is now setting up a new business to import niche market food and drink products from back home, aware of the growing interest in traditional hand crafted products in Western Europe. It's good to meet a young entrepreneur in tune with contemporary interests.

After a leisurely lunch and siesta I was ready to go out for a stroll, but rain persisted, so I stayed in did some writing, and listened to a BBC local radio webcast in which the release of Kath and Anto's new Sonrisa album 'From Today' was mentioned and a track from it played for the first time. Clare has been in Kenilworth looking after Rhiannon this weekend and she returned home with the album CD. I greatly look forward to hearing this when I return in ten days time, as the track broadcasted was a beautiful piece of music. craftsmanship. It makes me very proud.

I watched another episode of McMafia, summarised in a quote I read somewhere as 'English toffs and the Russian underworld'. Oh really? Well maybe. I can't quite suspend disbelief, although I can accept how complex is the web of international financial trading within which criminal enterprises hide, and how it's possible to snoop on people, know just where they are in this interconnected world, and do nasty things to them. But surely this applies to crime fighters as well as criminals. Can crooks really do bad things, so often with impunity? Is it true that law enforcement world wide is so under-funded that it's unable to keep track, so their adversaries are always one jump ahead?

There was an interesting 'File on Four' radio programme this afternoon about criminal organisations which issue fake university degree certificates, to people who want to buy professional qualification credentials they think will do them some good in the job market. As if this isn't lucrative enough, perpetrators turn to extortion and blackmail of clients, threatening to expose them to authorities and cost them their jobs and maybe residence permits unless they pay extra. 

It makes use of thousands of websites, and uses VOIP telephone contact with enquirers which can spoof caller i/d, and ensure the real life location of the scammers is very hard for non-experts to trace. It's just like the people who ring up and tell you they're from TalkTalk, troubleshooting your compromised internet router, using real phone numbers gleaned from a hack of the company subscriber database a couple of years back. These new technologies are very capable, but have made crime and deception possible on a mass scale, and internationally, in a way few thought possible at the turn of the 21st century.

Tuesday, 29 December 2015

Cloud concerns

This morning Kath, Anto and Rhiannon departed for Kenilworth, Clare set about doing the laundry, three machine loads of it, and I helped by hanging it all out. Fortunately, the weather was mild and kind enough to allow us to have the lot dry enough to finish off on the radiators in the evening. Meanwhile it was a machine minding day for me.

The HP mini had evidently gone through a factory re-set before purchase, and Win 8.1 had to be set up before Win 10 upgrade could take place. Although I'm sure I registered the software properly with Microsoft at the outset, the machine made three two hour attempts to download the upgrade file before it alleged the O/S wasn't MS registered. Hadn't registered on their servers I'd argue. Once done, upgrade proceeded at a snail's pace, another six hours, plus an hour getting rid of crapware and setting up my choice of software for use. None of these choices are reflected by the OneDrive filing system, although passwords are, and I now learn, also encryption keys. Disturbing, even for honest citizens.

I have one piece of previous legacy hardware - a keyboard with Swiss French layout, great for writing letters in French or German. So I had to configure the system to accept its input. The option is rather buried and not easy for a first timer, but being used to it for over 20 years, I didn't take me long to set it up to use with English language as the writing medium. When later in the day, while the upgrade was still happening, I used my laptop, I had difficulty logging in, and quickly discovered that the keyboard settings stored for the desktop machine and Swiss keyboard were being imposed on a standard English laptop keyboard, and producing errors. Instead of setting and forgetting, I had to return to configure for two different switchable settings EN/CH and EN/EN for both devices. Not good news.

Given the number of multi-lingual users owning and regularly using more than one device, not storing and keeping such basic settings on each machine as has happened up to now is a serious error of judgement on the part of our American digital overlords. The reasons are several: 1) if you don't know about keyboard configurations and how to switch them, you're going to waste your own and others' time with trouble-shooting; 2) multiple errors entering passwords could on some systems lead to users being barred access to essential if not urgent functions; 3) the imposition is in effect a breach of my network security. If didn't know about it, I couldn't authorise it.

What if a hacker found a way to replace the keyboard management software on one of my computers with a lookalike containing malware key-logger, activated by switching languages, one whose payload could then be distributed to all my machines via OneDrive? As with the encryption key concern, all it requires is a Microsoft server breach to spread vulnerabilities. OneDrive is attractive and can be quite convenient, provided your devices sync properly, but does it pose too much risk of privacy or security being compromised? 

The more the usage of Windows 10 is extended and explored, the more issues of this kind will arise for debate among the less technically sophisticated who get caught out. Computer systems are complex and hard to grasp. If an operating system does too much for you presuming it's being 'helpful' (as defined by a corporate giant dominating a different culture 5,000 miles away, from which we're divided a common language), it creates unhealthy dependencies and inefficiencies we can well do without.