Saturday, October 19, 2013

Windows Defends

The Windows 8.1 update detected that my ZoneAlarm for Windows 8.0 was not compatible with 8.1. It then took the below actions.
  1. Disabled ZoneAlarm
  2. Enabled Real-Time Protection using Windows Defender
  3. Displayed an Action Center notice about ZoneAlarm.
  4. Gave a link in the Action Center notice directly to the ZoneAlarm web page about the incompatibility and fix status
Congratulations, Microsoft! Great job of:
  • Defending the customer's computer
  • Alerting the customer to a security issue with their software
  • Displaying crucial information about the customer's product
  • Providing a direct link to the customer's Anti-Malware app developer page about the issue and its status
Wow! These update-related actions are a truly excellent  automatic adjustment to a bad security situation. After reading the Action Center notice, I opened Windows Defender and fully expected to have to manually set it up. It was already running real-time protection!

This is one of the best customer-oriented software behaviors I have seen in a long time. Again, kudos to Microsoft for a job well-done.

Friday, October 18, 2013

My Windows 8.1 "update" experience

First, I would not call this an update. It's more like a refresh of the entire OS. Caution: The update takes quite some time to finish. So make sure no power outage is headed your way. Set aside at least 30 minutes.

As always, I recommend a backup of all your data before starting this major update. I use a custom batch program to backup all my new files to an external 2TB hard drive.

Tip: Check to see if your Antivirus software is compatible with Windows 8.1. Some companies (like ZoneAlarm) were a bit slow getting out an updated app. If there is a compatibility issue, disable the Antivirus and make sure Windows Defender is running before doing this OS update.

My system

  • Dell XPS 8500
  • 1TB HDD
  • 24GB RAM

My Windows 8 update (upgrade) experience

First try failed

  1. Logged in with my Windows Account ID and password (not a local account).
  2. Checked the Windows Store, expecting to see Windows 8.1 there. No. It was not listed.
  3. Did a web search and located a Microsoft web page with a link to download and install 8.1
  4. I chose that update link.
  5. The update process started with a huge download -- Gigabytes! That took a bit of time on my Comcast broadband connection even though it averages about 15Mbps for downloads.
  6. The actual install started.
  7. When the screen notice that the system was ready for a restart, I chose the "Restart" button.
  8. Problem. As the PC did a restart, it never proceeded past the Dell splash graphic. Even Ctrl+Alt+Delete failed to work.
  9. Shutdown PC.
  10. Restated PC.
  11. Windows announced that "we could not update the PC to 8.1".
  12. Windows restored Windows 8.0 without a problem .

Try # 2 succeeds

  1. I logged in again.
  2. Checked the Microsoft Store. It now showed the 8.1 update as the prime one (large and at left).
  3. I chose the update.
  4. The update detected that files were already downloaded. It completed the installation.
    Note: The last screen warns that the process will require several PC restarts. They don't lie.
  5. At the prompt to restart or close, this time I chose "Close".
  6. I then made sure all apps were closed and manually restarted the PC via the Charms Power Settings.
  7. The PC this time processed fine and at the Dell logo splash screen displayed the twirling dots "busy" cursor. (I find the two ways Windows 8 uses moving dots to show action kind of cute.)
  8. After a restart, "Setting up your PC" appeared. Then a restart.
  9. "Setting up Devices". Then a restart.
  10. "Setting up Devices" (yes, a second time). Then a restart.
  11. "Setting up your PC settings". Then a restart.
  12. "Setting up a few more things." Cute. I just laughed at this point.
  13. "Getting Ready".
  14. The license agreement screen appeared. I accepted.
  15. You must choose "Express" or "Customize" settings. You can change these settings later. I chose Express.
    A few pucker-factor Express settings you may want to consider:
    -- Send information to Microsoft to help improve software, service, and location services.
    -- Use page prediction in Internet Explorer. This preloads pages IE expects you to use next. This sends your browsing history to Microsoft.
    -- Let Windows use your name, account picture, and advertising ID, and request location from the Windows Location Platform.
  16. "Account Setup." Login with your Windows account. My method sent a security code to my cell phone, then I entered it to proceed.
  17. Auto-backup to SkyDrive (cloud). This backs up new photos and documents plus PC settings. There is a link to turn off this feature if you prefer. I left it at the default.
  18. "Hi", said Winny 8.1. "We're setting things up for you." This is taking a while. While this is processing, the background rotates through several attractive solid color backgrounds.
  19. "Installing your apps". This may be where Windows is installing the new Win 8.1 apps.
  20. "Taking care of a few things". The message line at the bottom reads, "Installing your apps", then later changes to "Don't turn off your PC". 
  21. "Let's Start"
  22. The Windows 8.1 Start Screen appears.

Post-install printing issue

After Windows 8.1 installed, all seemed well until I tried to print. No printers worked and trying to add or edit one resulted in some blank dialog boxes and an error message. Windows even failed to let me delete a printer listing and referenced Active Directory. Yipes! Active Directory!?

Finally -- before a reinstall of Windows and gnashing of teeth -- I tried something that many basic users might try first. I ran the printer troubleshooting wizard. Presto -- problem fixed.

The real cause of the problem was that the printing service had stopped. [hand-to-face] [embarrassed smile]. The troubleshooter worked like a charm detecting and fixing that. I had needless anxiety because I was expecting the issue to be complex.

Saturday, August 15, 2009

IE8 more secure than Firefox

A report on Browser Security testing by NSS Labs shows that Internet Explorer 8 security is far better than Firefox, catching 81 percent of "live threats" vs. only 54 percent caught by Firefox 3, which came in second place.

The tests include rating the browser's protection against malicious software using socially engineering and phishing attacks.

The lab tested the most recent versions of Microsoft's IE8, Mozilla Firefox, Apple Safari, Google Chrome, and Opera. Opera caught a mere 2 percent of the threats.

Sunday, June 21, 2009

Quiz: Tech user type

Pew Research has a neat online quiz, "What kind of a tech user are you?".

It's fun, fast, and easy. Me? I'm a "Digital Collaborator". How about you?

Sunday, May 24, 2009

Facebook security

Social networking sites such as Facebook and MySpace come under heavy attack, especially from phishers.There are an average of three different Facebook phishing campaigns every day, reports the Washington Post.

One prime attack method is to have a link that appears to go to Facebook and even displays what to be the official Facebook logon page. The logon display is actually not at Facebook -- it just looks like it is. The link to that faked page can come in an email or even on a hacked or malicious web page. So how can you lessen the danger from this type attack?

  • Be paranoid about emails you get. Even if they appear to be from a "friend", be wary. If the email contains a link or attachment, send a separate email to (or call) the friend. Make sure they really did send it to you. A name in a "From" field of an email message means absolutely nothing these days!
  • Always login to any site that requires a password by using your own link (Favorite or Bookmark) or manually typing it in. Never click on a link from somewhere else. Never. Ever.
  • If the web site offers it, always choose to login by using what's called "Secure Socket Layer" (SSL). That's when you use "https" (think "s" for "secure") in the address, not just "http". Facebook happens to offer that choice. Use it! That is, use https://www.facebook.com/ to login to Facebook. This same security tip applies to many sites. Some do not even work without using HTTPS. [If Facebook were really interested in customer security it would force use of https, but that's a whole 'nother topic.]

Browser address area for a valid HTTPS address

In Internet Explorer 8, a valid HTTPS connection shows the "padlock" to the right of the address bar area, as in the figure above. It also shades the address background green. If you click on the padlock area, IE8 pops up certificate information.

While having a valid certificate is not a foolproof indicator that the company or site is "good", it's a big improvement over not checking it at all.

Another caution is that Facebook currently only allows the HTTPS protection at their login page. After login, you get dumped back into a normal HTTP session.

If you just have to have a Facebook page, be as safe as possible. Then be very paranoid.

Friday, May 01, 2009

Adobe Reader, Acrobat security issues -- again!

In respect to the latest in a series of security vulnerabilities with Adobe Reader and Adobe Flash, Adobe says, "We are in the process of fixing the issue, and expect to make available product updates for the relevant supported Adobe Reader and Acrobat versions and platforms by May 12th, 2009."

"SANS NewsBites" newsletter editors comment that users of Adobe Reader and Acrobat may want to consider less-exploited alternatives. Adobe Reader keeps bloating in size and Acrobat seems way over-priced, so perhaps it is time to start looking elsewhere.

Thursday, April 30, 2009

Scrapers hit social networking sites

A recent article in Windows Secrets newsletter, "Viral inviters want your email contact list", stated, "The arms race between the script builders and big-name Web services is just beginning. The massive data collections that the scrapers are able to accumulate are simply too valuable to pass up.

The problem will only get worse as social-networking sites create linked systems. For example, the Facebook Connect service that launched last year allows members to use their Facebook account to sign in to hundreds of third-party sites, such as CNET and MoveOn.org."

Unfortunately, too many people are lured by friends and acquaintances that tell them, that having a Facebook page makes them "cool". But they don't tell them (perhaps because they don't know or don't believe) about the pitfalls, the need for locked down tight security, the need to keep data you share to an absolute minimum, and the real need to be skeptical of emails you get.

Criminals can only flourish in such a naively trusting environment. Here's hoping that future tightening of the world's email system underpinnings will reduce the ability of Spammers and other Criminals to pretend to be a "friend" and sucker people into hurting themselves.

Monday, April 20, 2009

First Mac botnet found

Researchers have found malware in pirated copies of Apple's iWork ’09 and Adobe Photoshop CS4. What's worse, the malware has created the first botnet for Macs.

The Mac OS has been overdue for malware attention by hackers and "safe" only due to much lower market share than IBM-clone PCs. Mac users can expect to see more such attacks.

Friday, April 03, 2009

Beware Antivirus 2009

Beware of fake antivirus software. And beware of a pop-up notice that you have a virus or "might have" a virus (unless the pop-up notice comes from software you already own).

A type of software that tricks you into installing it, then demands payment "or else" is called ransomware. And it's spreading.

One nasty piece of ransomeware seems to be a legitimate program called Antivirus2009. But after you install the software, it encrypts several document types. Then when you try to open one of the encrypted files, it pops up an alert and offers to sell you FileFix Pro 2009, which it says can decrypt the file.

So you get duped into downloading the fix. But it decrypts only one document. After that, it demands that you pay $50 to buy the software to decrypt the rest of your files (that the Antivirus 2009 encrypted).

Beware of "something for nothing". Be paranoid. Check out reviews of software at trusted sites before you download and install any.

Wednesday, April 01, 2009

Protect your personal information

A PC World test found that some search sites had random details about co-workers' and acquaintances' college roommates and boyfriends from the 1980s, political donations, shopping preferences and musical tastes.

Social networking sites give a false sense of security and if left "open" to all can result in a lot of personal information being harvested (sometimes called "scraped") by criminals.

A recent Symantec study showed that 91% of Phishing attempts are now aimed at social networking sites (the top two are My Space and Facebook). Why? The personal data is there for easy pickings. Plus, people who join social networking sites tend to feel more "free" in their personal comments.

Another disturbing tidbit ... 23% of people succumb (are tricked by) social engineering attemps via Phishing emails. At a recent Information Security conference, a speaker admitted that he had been a victim too. His daughter had joined Facebook, soon had 300 "friends" (right!) and then her got an email from "his daughter" with a link to something neat "she" wanted him to check out. He did. His computer got attacked. The problem? Too trusting. Bad assumptions.

People get tempted to take risky actions when using social networking sites. Human nature plus the very essence of a social networking site make using it risky.

How much is your identity worth? Is is humany possible to not be a social networking lemming? Just say, "No" to joining social networking sites. You'll live to rejoice in that decision.