iSD in the Tech Age!



Net-self-defense, we spend an exorbitant amount of time on our physical defense training and then we forget that our lives are in just as much danger of "Grave Financial Harm" or Financial ruin (Death) as if we are attacked by a street predator. Research and studies show, from the security experts in this field, that Anti-virus and Firewall suites only catch about 5% of the threats out there and those same folks tell us that it is in all probability worse at the Enterprise levels.


My goal here is to educate myself, and by proxy, pass on what I learn to others so that each individual who is connected at any level can take steps to achieve some semblance of security in their electronic on-line lives. We are so deeply imbedded in modern technology that to not take appropriate actions to learn iSD or internet self-defense in the technological age is just foolishness.


My goal is to provide enough of a foundation that readers, like me, can take the appropriate actions, i.e., apply those fundamental principles of technological methodologies to safeguard one of the more important, actually critical, strategies and tactics to defend ourselves from grave economical harm or even economical/financial death or ruin from nefarious predatory hacking processes.


Nothing in this blog is definitive, it is meant to set a foundation of knowledge, understanding and awareness so that you are not one day blindsided by some effort to steal your very life out from underneath you so fast you feel like you have been hit behind the ear and knocked into a daze of confusion, fear and finally anger where your tech-life falls apart and ruins your real life utterly, completely and with no light in sight down that dark, empty and black hole.


Wednesday, July 27, 2016

It’s a Hassle, It’s a pain and it Plain Old Sucks

Blog Article/Post Caveat (Read First Please: Click the Link)

But it is the way of our modern world, you have to take responsibility for your own financial security. DO NOT RELY on others to safeguard your financial stability and security. Yes, use the services but don’t just join up and then forget about it because in the end it will be your ability to remain aware of your security status and it will be your ability to remain aware that will stop the attack long before the others can and will do it for you. 

I use security software but I also know that the software security driven safeguard models are just like all coded models, they are full of holes and glitches and other points in the code that any good hacker can exploit. That includes all those services who rely almost solely on the coded programs to run their security businesses. Again, not saying don’t use them but am saying, “Make it your mission in life to keep tabs on all your financial sources, banks, cards, and other financial stuff that are exposed to the Internet and to those coders who know the flaws and understand that the code is coded by humans and humans are flawed. 

Yes, the world today is controlled by the code and the coders but remember that there are good coders and bad coders and nefarious coders out there. Remember, one major operating system always uses the selling point of how secure their next O/S is until about an hour after its release that nefarious coders communicate and broadcast the flaws that allow security breaches.

So, yes it is a hassle, it is a royal pain in the arse and it does just plain old sucks but if you want to secure your financial stability then take on the responsibility by learning how it is done, how you can protect yourself and then monitor, monitor and yes once again - monitor all your finances, etc. 

Credit Cards: As an example I use a type of statement ledger to track every credit card expense as I make the change and when my statement arrives I match them all up and ANY anomaly I call the credit card company to get feedback on who, what, when, where and how a charge is placed on my account. There are many things you can do above and beyond those service companies who preach how they will go the distance for you and remember that the distance they go will only go as far as their bottom line - they are a business and making/keeping their money is their goal. 

I advocate layered security models. As a retired physical security manager/specialist I can tell you that layered security models work best. Start with the effort you put into your personal eSecurity posture both on and off the Internet. Then find those security models you can add on the enhance our overall security posture both on and off the Internet. Then monitor, monitor, monitor, monitor, and monitor some more. The faster you discover the security breaches the faster you can stop the flow out of your pockets and the faster you get your financial security and stability back. 

Having the ability to lay blame on others when your money disappears is fine on an emotional egoistic level but it won’t stop and put back the money you are bleeding out while hoping, praying and assuming that others will get it all back right for you. 

p.s. Keeping informed is one way to remain aware and as an example I recommend Kreb’s on Security, you can go to his site HERE (http://krebsonsecurity.com), because he has consistently provided me, personally as a daily reader of his blog, information I have implemented to safeguard my financial world. Just remember, it is not the only thing and layer your education sources as well to get a more rounded and complete picture of the danger out there. 

“In order for any life to matter, we all have to matter.” - Marcus Luttrell, Navy Seal (ret)


Don't let your finances get caught in the pull of that black hole!

Tuesday, July 26, 2016

DMARC It

Honestly, if your email service is not on the DMARC wagon maybe you should find one that is AND if you are a business then whoa, what the ? If you are a user like I am and concerned about things email then at least go to the two sites below and get a better understanding of how this can help. 





Friday, July 15, 2016

The Dark Web - the darker side

Blog Article/Post Caveat (Read First Please: Click the Link)

Since criminals also make use of the benefits of secrecy to prey on us in the regular WWW it seemed apropos to say that when hit by those predators it means pretty much that our money, our economic status as well as wealth, is caught up in a dark-web ‘black hole.” Nothing escapes once the gravitational pull of that black hole latches on to you and yet most of us surfing the White Web tend to remain ignorant to the dangers luring below the surface, that division between the White and Dark Webs because the dark side has the skills and abilities to reach up through that surface that hides, latch on to you and pull you toward its black hole where the black, the darkness, will consume and absorb you and your life as if you never existed.



The reason I use this analogy is because our protectors and enforcers of the legal and rightness of our way of life are ill equipped, lack appropriate knowledge and understanding and remain with their heads hidden in the sand to the dangers of such predatory efforts hidden and protected by the very same things that should be here in the White Web protecting us against them.

Beware the Ghost in the Code!
Now, that may sound like I advocate a focus on “others” protecting us and please don’t take this personally but I am not, they should be an intricate part of a layered security of the White Web where the first line of many levels should be YOU, the USER and the actions YOU TAKE when using computers and when surfing the Web. 

Here are a few links to what I consider the best security blog on computers and the iNfrastructure of the electronic age, the iRevolution. Kreb on Security:




If you find his articles above of interest consider following his blog, KrebsonSecurity, on a daily basis. As an IT expert of over twenty years I find his information refreshing, current, beneficial and critical to my personal online and computer safety and security.  

Hat tip to KrebsonSecurity as the inspiration for this post.


Tuesday, June 28, 2016

WWIII - eWars

Blog Article/Post Caveat (Read First Please: Click the Link)

I was quite surprised when studying Boyd’s modern art of war, his discourse on winning and losing, that even in his time long before data mining and data brokers took such dominance in our electronic world he developed the art of war to cover the Internet Electronic Frontier. The only issue I was able to detect, limited and inexperienced view, was his tendency to couple such electronic wars to the more conventional maneuver type of warfare. In my humble opinion, the future eWars well be totally and completely electronic while repercussions will be felt in the physical world.

In my humble opinion we are already at war with the dark-web, i.e., the more nefarious efforts of those who would remove us from our hard earned income through spam, phishing and other electronic predatory efforts. They are already crossing over from pure electronic warfare to one that hits in the physical world as well.

Yet, that ain’t all folks because the efforts of those who would and desire to free us from the bonds of our physical economic and governmental trappings would create an electronic world that is just as susceptible to the faults of man and human greed. In lieu of those who have control of the economic world trough the trappings of wall street would become the eWall Street thieves, those who control the code. 

Things like bitcoin and other such efforts while commendable and seemingly beneficial even spread throughout the code by dispersed coopted coding efforts still puts that power in the few in lieu of the many because not everyone can be coders or experts in such electronic worlds. The masses will still be subjected to and controlled by the whims of the governing eBody of the internet, the one we see and use and the dark web seen and used by others. 

As we continue to be connected and become totally dependent on those electronic worlds the old world may disappear and lose its control on humans but only to the effect that the power structure will shift and barely change. It will be the code and the coders who will now rule and dictate and you can bet your bottom bitcoin those powers will be used in pretty much the same way the old power structure use their power base to control and profit, etc.

If I had to bet against a military electronic driven fense in eWars vs. the Coders my bet would be on the coders because the most talented of the talented are the very people leading the change in the dark world of coding, that secret society that is there and slowly taking over the Internet Foundation Economy that is growing by leaps and bounds under the false belief that when said and done will allow the masses control and removing the yoke of governments. 

Boyd does have a great plan and modern art of war called the discourse but to truly win this one you have to change human needs and human flaws that seem to take us back again and again into the same old yoke but with a different collar to disguise the same obstacle and flaws that nature and evolution may never be able to shake and change. It is our nature and it is how it will be yet with different leaders, same of sheep following and with seemingly different yet the same old human crap that has haunted societies for centuries, since the dawn of man. 


Bibliography (Click the link)

Tuesday, June 14, 2016

ATM Self-Defense

Blog Article/Post Caveat (Read First Please: Click the Link)

With more and more banks resorting to technology to do bank business, i.e., not only teller’s becoming just another teller machine in the bank but fees when you do use a human teller along with other fees to make MORE money by banks, it has created an industry of what one reporter is calling “Deep Insert Skimmer w/Hidden Camera” scams.


So, as stated in the article, there are some things you can do to thwart those skimmers such as first and foremost take defensive actions against the hidden camera’s. When you push in and remove your card you often just punch in the pin numbers but in reality you should use one hand to cover up the pad before you enter the pin. Take a look at the machine you are using, the article talks about the false overhead panel for the hidden camera so obscure the pad as best you can to hide your entry from a many angles as possible. Also, move in close like I do so your head and upper body obscures the pad not just from the above hidden camera but any camera that may be located in proximity to the machine that could capture your entering your pin.

Now, as to a general self-defense methodology use the above as well as the following:
  • Keep your wits about you when you’re at the ATM, and avoid dodgy-looking and standalone cash machines in low-lit areas, if possible. 
  • Stick to ATMs that are physically installed in a bank. 
  • Be especially vigilant when withdrawing cash on the weekends; thieves tend to install skimming devices on a weekend — when they know the bank won’t be open again for more than 24 hours.
  • Covering the PIN pad with your hand defeats the hidden camera from capturing your PIN — and hidden cameras are used on the vast majority of compromised machines (see the above paragraph for a reminder on obscuring the pin pad, etc.)
Remember, relying on technology to provide you the security and peace of mind against such trickery is just not good. You need to remember that the best security you can depend on is, “Yourself,” and that means reading articles like, “KrebonSecurity,” and my blog because the best security you can achieve is knowledge and understanding along with a concerted effort to live and work that security model. Every single new technological security method, model and code is only as good as the human programmer(s) who create it and since humans are inherently flawed so are the programs and software and hardware they create. Humans also are very clever and creative so once a new technological security program, etc., is released there are about twenty times more creative people out there finding ways to crack that very software. 

For us humans who are diligent in our security our greatest strength is our due diligence and continuous effort to learn and understand and implement while our greatest weakness is our social conditioning that leaves us susceptible to social engineering so - ‘Be careful out there!’

Bibliography (Click the link)

Addendum:

The previous article has a link to a more comprehensive one about skimmers and you should note that this is just not bank machines but also other card reading devices to include a portable one some waitresses will use for your credit cards, i.e., read the magnetic strip and then write down the three digit security code on the back. Read Article HERE

Simple but effective security precaution of covering his hand when entering his 4-digit code. The last few minutes of the following video show how to cover the pad with your hand to enter your pin: https://www.youtube.com/watch?v=JbDdsUh_sTg


It’s a good idea to visit only ATMs that are in well-lit and public areas, and to be aware of your surroundings as you approach the cash machine. If you visit a cash machine that looks strange, tampered with, or out of place, then try to find another ATM.

Tuesday, May 10, 2016

ClickBait

Blog Article/Post Caveat (Read First Please: Click the Link)

I thought I had heard a lot of things on the Internet being an IT guy but not until I read an article in the news today where someone mentioned the term, “Click-bait.” I wondered if that were something created to sensationalize the article but I found it defined when doing a search.

Click-bait is content (on the internet), especially a sensational or provocative form, that has a purpose of attracting your attention and to draw you and others toward particularly gifted web pages, i.e., the kind of gifts that keep on taking while you sit there clueless and dumbfounded trying to figure out what you missed and why you are not reaping benefits you may have thought you would get. 

I quote, “Clickbait is a pejorative term describing web content that is aimed at generating online advertising revenue, especially at the expense of quality or accuracy, relying on sensationalist headlines or eye-catching thumbnail pictures to attract click-throughs and to encourage forwarding of the material over online social networks. Clickbait headlines typically (eye-catching headlines that include exaggerations of news events, scandal-mongering, or sensationalism) aim to exploit the "curiosity gap", providing just enough information to make the reader curious, but not enough to satisfy their curiosity without clicking through to the linked content.”

When I see or hear of this I think on the old show, “Madmen,” that infers that those who create the hooks tend to make them so enticing and so that they trigger certain parts of our brains that we find it very difficult to see them for what they are and to avoid them. 

We have come to instinctively click our mouses when your hindbrain, our monkey/lizard brains, perceive outside our conscious mind something like clickbait we have already clicked the link - toooooo laaaatttteeee!

The only way to combat this type of baiting is to teach ourselves a bit of click-discipline. We must remove our hands from the mouse when we enter a web site, analyze the page and all its content both obvious and hidden in surreptitious links and then decide, like counting to ten before clicking, whether to go somewhere or ignore or leave the site. 

Bibliography (Click the link)

Don't take the bait!!!!

Friday, May 6, 2016