Wednesday, April 20, 2011

Why I Won't Be Buying Videos from SONY PSN Anymore

[UPDATE, Aug 11, 2011: Sony finally corrected their ToS:http://www.qriocity.com/us/en/legal-snei-tosua-redlines.html  Thanks SONY!]

Even though the new Terms of Service for Sony Network Entertainment America (SNEA), formerly a part of Sony Computer Entertainment America (SCEA), came out on April 1 I have confirmed that what sneaky back-handedness they wrote into it was not an April fools joke.

For those who own a PS3 (or other PSN/Qriocity capable video device) in Canada SONY apparently doesn't like you.

...or at least they don't care about your continued loyalty and continued business.

They have written the terms so that everyone who clicked the I Agree button to log into their PSN account has agreed that even if they are in Canada they will not watch the videos bought on the PSN Video store outside the United States.  That means that if you are in Canada and purchased a video from SONY's PSN video store and you then watch it in Canada you are violating the Terms of Service and SONY is free to do whatever they want to your account.

I sought first a change to fix what looked like an embarrassing mistake on SONY's part, but then when that did not seem to be coming I asked for an official statement that what they said is what they meant.

This is the final e-mail I got back from them:

Hello Rod,

We do apologize for this inconvenience or confusion regarding this issue,

This is an official document listed below.

Please refer to the Terms of Use, section 8.

Terms of Use and User Agreement
Article Link: http://playstation.custhelp.com/app/answers/detail/a_id/1109

Regards,
Don K


For anyone interested, but not wanting to follow the link here is Section 8 of Terms of Service and User Agreement Version 9 (April 1, 2011)

I have highlighted in RED the part I'm talking about.


8. VIDEO CONTENT

You may use either your Qriocity account or PSN account to purchase video content. Subject to the terms of this Agreement and any additional terms and conditions for the particular item, SNEA licenses digitalized content, including television shows and movies ("Video Content") to you for your personal, private, non-commercial viewing in the United States only, using a limited number of activated PlayStation®3 computer entertainment systems, PSP® (PlayStation®Portable) systems, personal computers ("PSN Devices") and VOD Devices (collectively, "Authorized Devices") during the authorized viewing period ("Authorized Term"). Video Content may be made available to you as a rental for a limited duration ("Rental Content") or purchase ("Sold Content"). Use of Video Content is subject to certain digital rights management rules and terms and conditions of this Agreement. Except for rights explicitly granted to you, all rights in the Video Content are reserved by SNEA and its licensors.

Only one copy of Rental Content may be viewable on an Authorized Device and each copy will have a rental time period ("Rental Period") during which you can begin playback for that copy. The Rental Period for each copy of Rental Content will be displayed to you prior to finalizing your rental payment. Once you begin playback of your Rental Content copy, that copy is viewable for up to 24 hours. After such time, you will not be able to view the Rental Content. Rental Content may not be reproduced.

You may select the Authorized Device on which you want to view your Rental Content. If you have a Qriocity account, you may view your content from any one of your activated VOD Devices only. If you have a PSN account, you may view your Rental Content purchased on PSN or Qriocity from any one of your activated Authorized Devices, except that if the Rental Content is in high definition format, it may be viewed on one (1) activated PlayStation®3 computer entertainment system or one (1) VOD Device. Rental Content may not be transferred between a PSN Device and a VOD Device. Once playback has started on a VOD Device, you may not view that content using any other Authorized Device without a separate payment. If you start Rental Content playback on a PSN Device, the account that purchased the Rental Content may, during the Authorized Term, transfer that content to a limited number of activated PSN Devices, as described below.

Rental Content in standard definition format downloaded onto a PlayStation®3 computer entertainment system or a personal computer may be transferred to up to three (3) PSP® (PlayStation®Portable) systems. Rental Content in standard definition format for use with a PSP® (PlayStation®Portable) system may be transferred to up to one (1) PlayStation®3 computer entertainment system and two (2) personal computers.

You may view Sold Content for an unlimited number of times on an activated PSN Device only. The account that purchased the Sold Content may copy that content to a limited number of PSN Devices, as described below.

Sold Content in standard definition format downloaded onto a PlayStation®3 computer entertainment system or a personal computer may be copied for use on up to three (3) PSP® (PlayStation®Portable) systems. Sold Content in standard definition format for use with a PSP® (PlayStation®Portable) system may be copied for use on up to one (1) PlayStation®3 computer entertainment system and two (2) personal computers. Sold Content in high definition format may be viewed on only one (1) activated PlayStation®3 computer entertainment system.

You may have the option to purchase Video Content in high definition and standard definition format. You acknowledge that delivery of content is dependent on variables not under SNEA's control, including but not limited to, the speed and availability of your broadband or network connection. You may experience delays or technical difficulties caused by or related to such variables. If you have purchased Video Content and view it using a VOD Device, you may not be able to view your content in the format that you've purchased due to such variables. To the extent permitted by applicable law, you will not receive a refund or credit for any content that you are not able to view or have difficulty viewing due to such variables. We strongly encourage you to purchase content suitable for your viewing capabilities. You bear all responsibility for ensuring that you have the viewing capabilities to view content in the appropriate format or at all.

Proper activation of an Authorized Device by the account that purchased the Video Content is required for all downloads, transfers, copies and viewings. Purchase of Video Content is connected to the purchasing account. An account can activate no more than the maximum number of Authorized Devices, regardless of the number of copies of Video Content purchased. Video Content may not be transferred from one account to another. You may not exceed the total number of accounts on any Authorized Device. Please refer to http://playstation.com/ and http://qriocity.com/ for more information on the total number of permitted Sony Online Services accounts. SNEA reserves the right to limit the number of times an Authorized Device may be activated or deactivated.

Downloading or streaming is not permitted outside the Authorized Term. In addition, once Video Content has been downloaded or accessed, you will not be able to download it again without purchase of another copy.

Some content such as movie trailers may not be representative of the actual feature presentation. Digitalized versions of some content may not be identical with the original formatted content or previously released versions of the same titled content.

Video output in certain formats may require additional equipment, sold separately.



So there you have it Canadian PS3 users, SONY wants you to only watch your PSN video content in the USA, if you watch it at home you've violated the terms of your contract with SONY.

What were the e-mails leading upto all this you ask?

Here is the whole conversation. In typical e-mail style, it's best to start at the bottom and work your way up:


Subject
Dear Sony, I cannot agree to your April 1 terms of service. Sect. 8 Video Conten...

Discussion Thread
Response Via Email (Don K) 04/20/2011 08:40 AM
Hello Rod,

We do apologize for this inconvenience or confusion regarding this issue,

This is an official document listed below.

Please refer to the Terms of Use, section 8.

Terms of Use and User Agreement
Article Link: http://playstation.custhelp.com/app/answers/detail/a_id/1109

Regards,
Don K
Customer By Email (ROD MACPHERSON) 04/19/2011 04:58 PM
I think you misunderstood me.
I am not asking for a refund of wallet moneys or to cancel my account.

I just want one of two things. Either a correction in the Terms of
Service so that it makes sense, or clarification from SONY that you (as
a company) really meant what you said and that it is no longer legal to
watch movies and TV shows I purchased in Canada on a Canadian PSN
account outside the USA.

As it stands, your Terms of Service say that I cannot watch videos from
PSN outside the USA. That means that if I watch my videos I am in breach
of this contract. I am holding off on accepting until I get either a
statement that that is indeed SONY's intent, or a new Terms of Service
appears with the mistake corrected.

If you do intend to make it a breach of contract for me to watch videos
that is fine, I will simply continue to use the PSN's other services and
no longer buy videos. .... although, if that is true, it'd be nice of
you to refund me for the videos you are stealing back, but I am not
going to force the issue. I'll just continue to play my games and watch
videos on other services.


Please let me know which it is. I want an official statement that the
terms of service are correct as they stand, or some indication of what
SONY's plan is to fix the error.



On 04/19/2011 11:29 AM, PlayStation Consumer Services wrote:
>
>
> * Subject*
> Dear Sony, I cannot agree to your April 1 terms of service. Sect. 8
> Video Conten...
>
> * Discussion Thread*
> * Response Via Email (Don K)* 04/19/2011 08:29 AM
> Hello Rod,
>
> We do apologize for this inconvenience.
>
> Thank you for contacting us regarding your decision to decline our Terms
> of Service and User Agreement. If you are serious about not
> being in agreement with the Terms of Use, then in order to close your
> PlayStation®Network account and return the funds in the wallet
> associated with your account, we will need the following information:
>
> PSN Sign-In ID (email address used to create your PSN account)
> PSN Online ID
> First Name
> Last Name
> Complete Mailing Address (where you would like to receive your refund)
>
> You may reply to this email directly if you're already using your PSN
> Sign-In ID email address to read this email. Otherwise, if you have a
> different email address associated with your PSN Sign-In ID, you MUST
> use your PSN ID email address to send us the above information. You can
> send your email to:
>
> TOS_PSN@playstation.sony.com TOS_PSN@playstation.sony.com>
>
> The refund is only for the remaining funds in your PSN wallet. We will
> not refund any money for content that has already been purchased. Once
> the refund request has been processed, your PSN account will be
> terminated. You will lose access to any content that has been purchased
> with this PSN account, as well as any trophies awarded to the account.
> You will also not be able to use this email address to create a new PSN
> account. The termination of your account is final and cannot be reversed.
>
> If you wish to terminate more than one account, you must follow this
> process for each account (we will need to receive an email directly from
> each email address used to create the separate PSN accounts to validate
> that you are the owner of the email accounts).
>
> We value your input and appreciate you bringing this to our attention.
> Please rest assured that we will convey your feedback to Sony Computer
> Entertainment America, LLC's ("SCEA") appropriate management.
>
> Regards,
> Don K
> * Customer By Email (ROD MACPHERSON)* 04/18/2011 05:43 PM
> Nothing against you guys personally, but as I am sure that you are not
> able to contractually bind SONY in any way, I cannot accept you saying
> "I am pretty sure you found an error...." and "Please keep using your
> account" as if it is a contract that supersedes the April 1 2011 Terms
> of Service/User Agreement.
>
> It has been 10 days since my initial contact with your department and I
> still have not received a satisfactory resolution to my concern.
> I will not click Accept, binding me to that agreement until it changes
> to resolve this or until I have in hand a contract from SONY legal dept
> that supersedes the April 1 Terms of Service.
>
> I am sure that this Terms of Service document was reviewed by at least a
> dozen people at SONY and it is an absolute embarrassment that it made it
> to being presented to your customers in it's current form.
>
> Please forward this to the Legal Department, I eagerly await their response.
>
> Sincerely,
> Rod MacPherson.
>
>
> On 12/04/2011 6:45 PM, PlayStation Consumer Services wrote:
>>
>>
>> * Subject*
>> Dear Sony, I cannot agree to your April 1 terms of service. Sect. 8
>> Video Conten...
>>
>> * Discussion Thread*
>> * Response Via Email (James G)* 04/12/2011 03:45 PM
>> Hello Rod,
>>
>> I am pretty sure you found an error in the wording. I will report this
>> and say thank you.
>>
>> Once this is updated you can probably rest easy and not worry about
>> this since it was likely in error.
>>
>> Please keep using your account, as it would seem that is really your
>> intent.
>>
>> Regards,
>> James G
>>
>> Are you a member of the PlayStation®Network yet? Play games online,
>> chat with friends, access exclusive titles, downloadable games, PS
>> one®Classics, free demos, movies, TV shows and more! Highly connected
>> and endlessly entertaining.
>> Welcome to the PlayStation®Network. Join now
>>
> !
>>
>>
>> * Customer By Email (ROD MACPHERSON)* 04/12/2011 03:14 PM
>> Can I have an update on this?
>> surely I'm not the only one who refused to agree to these terms based on
>> the limitation of only being allowed to view purchased content in a
>> country I don't live in.
>>
>> An update would be appreciated.
>> I'm a loyal Sony customer, having bought 3 PS2s, a PSP and 2 PS3's over
>> the years, but I cannot agree to terms that disallow me from watching
>> content I've purchased. ...even if I'll technically be able to I won't
>> agree to the contract the way it is.
>>
>>
>> On 04/09/2011 05:43 PM, PlayStation Consumer Services wrote:
>> >
>> >
>> > * Subject*
>> > Dear Sony, I cannot agree to your April 1 terms of service. Sect. 8
>> > Video Conten...
>> >
>> > * Discussion Thread*
>> > * Response Via Email (Richard K.)* 04/09/2011 02:43 PM
>> > Hello Rod,
>> >
>> > I understand the concern caused by the mention of content purchased from
>> > the PlayStation®Store's Video Download Service only being viewable in
>> > the United States. I am glad to say the PlayStation Store's Video
>> > Download Service is still available in both Canada and the United
>> > States. I am having the appropriate department within Sony Computer
>> > Entertainment America (SCEA) look into the mentioned clause so that it
>> > can be checked for inaccuracies. I appreciate you bringing this to our
>> > attention. Please let me know if you have any other questions or
>> > concerns in the future.
>> >
>> >
>> > Regards,
>> > Richard K.
>> > * Auto-Response* 04/08/2011 07:10 PM
>> > *** PLEASE DO NOT REPLY TO THIS MESSAGE. THIS IS A SYSTEM-GENERATED AUTO
>> > RESPONSE. ***
>> >
>> > Thank you for contacting Sony Computer Entertainment America, LLC
>> (SCEA).
>> >
>> > You have received this auto-acknowledgement to confirm that we received
>> > your message. We will respond to your message within 24 - 48 hours. For
>> > immediate online support, please visit our PlayStation Knowledge Center
>> > at http://us.playstation.com/support 24 hours a day.
>> >
>> > Thank you for your patience.
>> >
>> > SCEA Consumer Services
>> > * Customer By Web Form (ROD MACPHERSON)* 04/08/2011 07:10 PM
>> > Dear Sony,
>> > I cannot agree to your April 1 terms of service. Sect. 8 Video Content
>> > says "...viewing in the United States only" I'm in Canada.
>> > I am not going to drive my Playstation3 4 hours to the nearest border
>> > crossing just to watch a video I PURCHASED from you. Update the
>> > agreement please.
>> >
>> >
>> >
>>
>>
>> --
>>
>> Rod MacPherson
>> rod@macphersonclan.com rod@macphersonclan.com>
> rod@macphersonclan.com rod@macphersonclan.com>>
>> * Response Via Email (Richard K.)* 04/09/2011 02:43 PM
>> Hello Rod,
>>
>> I understand the concern caused by the mention of content purchased
>> from the PlayStation®Store's Video Download Service only being
>> viewable in the United States. I am glad to say the PlayStation
>> Store's Video Download Service is still available in both Canada and
>> the United States. I am having the appropriate department within Sony
>> Computer Entertainment America (SCEA) look into the mentioned clause
>> so that it can be checked for inaccuracies. I appreciate you bringing
>> this to our attention. Please let me know if you have any other
>> questions or concerns in the future.
>>
>>
>> Regards,
>> Richard K.
>> * Auto-Response* 04/08/2011 07:10 PM
>> *** PLEASE DO NOT REPLY TO THIS MESSAGE. THIS IS A SYSTEM-GENERATED
>> AUTO RESPONSE. ***
>>
>> Thank you for contacting Sony Computer Entertainment America, LLC (SCEA).
>>
>> You have received this auto-acknowledgement to confirm that we
>> received your message. We will respond to your message within 24 - 48
>> hours. For immediate online support, please visit our PlayStation
>> Knowledge Center at http://us.playstation.com/support 24 hours a day.
>>
>> Thank you for your patience.
>>
>> SCEA Consumer Services
>> * Customer By Web Form (ROD MACPHERSON)* 04/08/2011 07:10 PM
>> Dear Sony,
>> I cannot agree to your April 1 terms of service. Sect. 8 Video Content
>> says "...viewing in the United States only" I'm in Canada.
>> I am not going to drive my Playstation3 4 hours to the nearest border
>> crossing just to watch a video I PURCHASED from you. Update the
>> agreement please.
>>
>>
>>
>
>
> --
> Rod MacPherson
> rod@macphersonclan.com rod@macphersonclan.com>
> * Response Via Email (James G)* 04/12/2011 03:45 PM
> Hello Rod,
>
> I am pretty sure you found an error in the wording. I will report this
> and say thank you.
>
> Once this is updated you can probably rest easy and not worry about this
> since it was likely in error.
>
> Please keep using your account, as it would seem that is really your intent.
>
> Regards,
> James G
>
> Are you a member of the PlayStation®Network yet? Play games online,
> chat with friends, access exclusive titles, downloadable games, PS
> one®Classics, free demos, movies, TV shows and more! Highly connected
> and endlessly entertaining.
> Welcome to the PlayStation®Network. Join now
> !
>
> * Customer By Email (ROD MACPHERSON)* 04/12/2011 03:14 PM
> Can I have an update on this?
> surely I'm not the only one who refused to agree to these terms based on
> the limitation of only being allowed to view purchased content in a
> country I don't live in.
>
> An update would be appreciated.
> I'm a loyal Sony customer, having bought 3 PS2s, a PSP and 2 PS3's over
> the years, but I cannot agree to terms that disallow me from watching
> content I've purchased. ...even if I'll technically be able to I won't
> agree to the contract the way it is.
>
>
> On 04/09/2011 05:43 PM, PlayStation Consumer Services wrote:
>>
>>
>> * Subject*
>> Dear Sony, I cannot agree to your April 1 terms of service. Sect. 8
>> Video Conten...
>>
>> * Discussion Thread*
>> * Response Via Email (Richard K.)* 04/09/2011 02:43 PM
>> Hello Rod,
>>
>> I understand the concern caused by the mention of content purchased from
>> the PlayStation®Store's Video Download Service only being viewable in
>> the United States. I am glad to say the PlayStation Store's Video
>> Download Service is still available in both Canada and the United
>> States. I am having the appropriate department within Sony Computer
>> Entertainment America (SCEA) look into the mentioned clause so that it
>> can be checked for inaccuracies. I appreciate you bringing this to our
>> attention. Please let me know if you have any other questions or
>> concerns in the future.
>>
>>
>> Regards,
>> Richard K.
>> * Auto-Response* 04/08/2011 07:10 PM
>> *** PLEASE DO NOT REPLY TO THIS MESSAGE. THIS IS A SYSTEM-GENERATED AUTO
>> RESPONSE. ***
>>
>> Thank you for contacting Sony Computer Entertainment America, LLC (SCEA).
>>
>> You have received this auto-acknowledgement to confirm that we received
>> your message. We will respond to your message within 24 - 48 hours. For
>> immediate online support, please visit our PlayStation Knowledge Center
>> at http://us.playstation.com/support 24 hours a day.
>>
>> Thank you for your patience.
>>
>> SCEA Consumer Services
>> * Customer By Web Form (ROD MACPHERSON)* 04/08/2011 07:10 PM
>> Dear Sony,
>> I cannot agree to your April 1 terms of service. Sect. 8 Video Content
>> says "...viewing in the United States only" I'm in Canada.
>> I am not going to drive my Playstation3 4 hours to the nearest border
>> crossing just to watch a video I PURCHASED from you. Update the
>> agreement please.
>>
>>
>>
>
>
> --
>
> Rod MacPherson
> rod@macphersonclan.com rod@macphersonclan.com>
> * Response Via Email (Richard K.)* 04/09/2011 02:43 PM
> Hello Rod,
>
> I understand the concern caused by the mention of content purchased from
> the PlayStation®Store's Video Download Service only being viewable in
> the United States. I am glad to say the PlayStation Store's Video
> Download Service is still available in both Canada and the United
> States. I am having the appropriate department within Sony Computer
> Entertainment America (SCEA) look into the mentioned clause so that it
> can be checked for inaccuracies. I appreciate you bringing this to our
> attention. Please let me know if you have any other questions or
> concerns in the future.
>
>
> Regards,
> Richard K.
> * Auto-Response* 04/08/2011 07:10 PM
> *** PLEASE DO NOT REPLY TO THIS MESSAGE. THIS IS A SYSTEM-GENERATED AUTO
> RESPONSE. ***
>
> Thank you for contacting Sony Computer Entertainment America, LLC (SCEA).
>
> You have received this auto-acknowledgement to confirm that we received
> your message. We will respond to your message within 24 - 48 hours. For
> immediate online support, please visit our PlayStation Knowledge Center
> at http://us.playstation.com/support 24 hours a day.
>
> Thank you for your patience.
>
> SCEA Consumer Services
> * Customer By Web Form (ROD MACPHERSON)* 04/08/2011 07:10 PM
> Dear Sony,
> I cannot agree to your April 1 terms of service. Sect. 8 Video Content
> says "...viewing in the United States only" I'm in Canada.
> I am not going to drive my Playstation3 4 hours to the nearest border
> crossing just to watch a video I PURCHASED from you. Update the
> agreement please.
>
>
>


--

Rod MacPherson
rod@macphersonclan.com
Response Via Email (Don K) 04/19/2011 08:29 AM
Hello Rod,

We do apologize for this inconvenience.

Thank you for contacting us regarding your decision to decline our Terms of Service and User Agreement. If you are serious about not
being in agreement with the Terms of Use, then in order to close your PlayStation®Network account and return the funds in the wallet associated with your account, we will need the following information:

PSN Sign-In ID (email address used to create your PSN account)
PSN Online ID
First Name
Last Name
Complete Mailing Address (where you would like to receive your refund)

You may reply to this email directly if you're already using your PSN Sign-In ID email address to read this email. Otherwise, if you have a different email address associated with your PSN Sign-In ID, you MUST use your PSN ID email address to send us the above information. You can send your email to:

TOS_PSN@playstation.sony.com

The refund is only for the remaining funds in your PSN wallet. We will not refund any money for content that has already been purchased. Once the refund request has been processed, your PSN account will be terminated. You will lose access to any content that has been purchased with this PSN account, as well as any trophies awarded to the account. You will also not be able to use this email address to create a new PSN account. The termination of your account is final and cannot be reversed.

If you wish to terminate more than one account, you must follow this process for each account (we will need to receive an email directly from each email address used to create the separate PSN accounts to validate that you are the owner of the email accounts).

We value your input and appreciate you bringing this to our attention. Please rest assured that we will convey your feedback to Sony Computer Entertainment America, LLC's ("SCEA") appropriate management.

Regards,
Don K
Customer By Email (ROD MACPHERSON) 04/18/2011 05:43 PM
Nothing against you guys personally, but as I am sure that you are not
able to contractually bind SONY in any way, I cannot accept you saying
"I am pretty sure you found an error...." and "Please keep using your
account" as if it is a contract that supersedes the April 1 2011 Terms
of Service/User Agreement.

It has been 10 days since my initial contact with your department and I
still have not received a satisfactory resolution to my concern.
I will not click Accept, binding me to that agreement until it changes
to resolve this or until I have in hand a contract from SONY legal dept
that supersedes the April 1 Terms of Service.

I am sure that this Terms of Service document was reviewed by at least a
dozen people at SONY and it is an absolute embarrassment that it made it
to being presented to your customers in it's current form.

Please forward this to the Legal Department, I eagerly await their response.

Sincerely,
Rod MacPherson.


On 12/04/2011 6:45 PM, PlayStation Consumer Services wrote:
>
>
> * Subject*
> Dear Sony, I cannot agree to your April 1 terms of service. Sect. 8
> Video Conten...
>
> * Discussion Thread*
> * Response Via Email (James G)* 04/12/2011 03:45 PM
> Hello Rod,
>
> I am pretty sure you found an error in the wording. I will report this
> and say thank you.
>
> Once this is updated you can probably rest easy and not worry about
> this since it was likely in error.
>
> Please keep using your account, as it would seem that is really your
> intent.
>
> Regards,
> James G
>
> Are you a member of the PlayStation®Network yet? Play games online,
> chat with friends, access exclusive titles, downloadable games, PS
> one®Classics, free demos, movies, TV shows and more! Highly connected
> and endlessly entertaining.
> Welcome to the PlayStation®Network. Join now
> !
>
>
> * Customer By Email (ROD MACPHERSON)* 04/12/2011 03:14 PM
> Can I have an update on this?
> surely I'm not the only one who refused to agree to these terms based on
> the limitation of only being allowed to view purchased content in a
> country I don't live in.
>
> An update would be appreciated.
> I'm a loyal Sony customer, having bought 3 PS2s, a PSP and 2 PS3's over
> the years, but I cannot agree to terms that disallow me from watching
> content I've purchased. ...even if I'll technically be able to I won't
> agree to the contract the way it is.
>
>
> On 04/09/2011 05:43 PM, PlayStation Consumer Services wrote:
> >
> >
> > * Subject*
> > Dear Sony, I cannot agree to your April 1 terms of service. Sect. 8
> > Video Conten...
> >
> > * Discussion Thread*
> > * Response Via Email (Richard K.)* 04/09/2011 02:43 PM
> > Hello Rod,
> >
> > I understand the concern caused by the mention of content purchased from
> > the PlayStation®Store's Video Download Service only being viewable in
> > the United States. I am glad to say the PlayStation Store's Video
> > Download Service is still available in both Canada and the United
> > States. I am having the appropriate department within Sony Computer
> > Entertainment America (SCEA) look into the mentioned clause so that it
> > can be checked for inaccuracies. I appreciate you bringing this to our
> > attention. Please let me know if you have any other questions or
> > concerns in the future.
> >
> >
> > Regards,
> > Richard K.
> > * Auto-Response* 04/08/2011 07:10 PM
> > *** PLEASE DO NOT REPLY TO THIS MESSAGE. THIS IS A SYSTEM-GENERATED AUTO
> > RESPONSE. ***
> >
> > Thank you for contacting Sony Computer Entertainment America, LLC
> (SCEA).
> >
> > You have received this auto-acknowledgement to confirm that we received
> > your message. We will respond to your message within 24 - 48 hours. For
> > immediate online support, please visit our PlayStation Knowledge Center
> > at http://us.playstation.com/support 24 hours a day.
> >
> > Thank you for your patience.
> >
> > SCEA Consumer Services
> > * Customer By Web Form (ROD MACPHERSON)* 04/08/2011 07:10 PM
> > Dear Sony,
> > I cannot agree to your April 1 terms of service. Sect. 8 Video Content
> > says "...viewing in the United States only" I'm in Canada.
> > I am not going to drive my Playstation3 4 hours to the nearest border
> > crossing just to watch a video I PURCHASED from you. Update the
> > agreement please.
> >
> >
> >
>
>
> --
>
> Rod MacPherson
> rod@macphersonclan.com rod@macphersonclan.com>
> * Response Via Email (Richard K.)* 04/09/2011 02:43 PM
> Hello Rod,
>
> I understand the concern caused by the mention of content purchased
> from the PlayStation®Store's Video Download Service only being
> viewable in the United States. I am glad to say the PlayStation
> Store's Video Download Service is still available in both Canada and
> the United States. I am having the appropriate department within Sony
> Computer Entertainment America (SCEA) look into the mentioned clause
> so that it can be checked for inaccuracies. I appreciate you bringing
> this to our attention. Please let me know if you have any other
> questions or concerns in the future.
>
>
> Regards,
> Richard K.
> * Auto-Response* 04/08/2011 07:10 PM
> *** PLEASE DO NOT REPLY TO THIS MESSAGE. THIS IS A SYSTEM-GENERATED
> AUTO RESPONSE. ***
>
> Thank you for contacting Sony Computer Entertainment America, LLC (SCEA).
>
> You have received this auto-acknowledgement to confirm that we
> received your message. We will respond to your message within 24 - 48
> hours. For immediate online support, please visit our PlayStation
> Knowledge Center at http://us.playstation.com/support 24 hours a day.
>
> Thank you for your patience.
>
> SCEA Consumer Services
> * Customer By Web Form (ROD MACPHERSON)* 04/08/2011 07:10 PM
> Dear Sony,
> I cannot agree to your April 1 terms of service. Sect. 8 Video Content
> says "...viewing in the United States only" I'm in Canada.
> I am not going to drive my Playstation3 4 hours to the nearest border
> crossing just to watch a video I PURCHASED from you. Update the
> agreement please.
>
>
>


--
Rod MacPherson
rod@macphersonclan.com
Response Via Email (James G) 04/12/2011 03:45 PM
Hello Rod,

I am pretty sure you found an error in the wording. I will report this and say thank you.

Once this is updated you can probably rest easy and not worry about this since it was likely in error.

Please keep using your account, as it would seem that is really your intent.

Regards,
James G

Are you a member of the PlayStation®Network yet? Play games online, chat with friends, access exclusive titles, downloadable games, PS one®Classics, free demos, movies, TV shows and more! Highly connected and endlessly entertaining.
Welcome to the PlayStation®Network. Join now!
Customer By Email (ROD MACPHERSON) 04/12/2011 03:14 PM
Can I have an update on this?
surely I'm not the only one who refused to agree to these terms based on
the limitation of only being allowed to view purchased content in a
country I don't live in.

An update would be appreciated.
I'm a loyal Sony customer, having bought 3 PS2s, a PSP and 2 PS3's over
the years, but I cannot agree to terms that disallow me from watching
content I've purchased. ...even if I'll technically be able to I won't
agree to the contract the way it is.


On 04/09/2011 05:43 PM, PlayStation Consumer Services wrote:
>
>
> * Subject*
> Dear Sony, I cannot agree to your April 1 terms of service. Sect. 8
> Video Conten...
>
> * Discussion Thread*
> * Response Via Email (Richard K.)* 04/09/2011 02:43 PM
> Hello Rod,
>
> I understand the concern caused by the mention of content purchased from
> the PlayStation®Store's Video Download Service only being viewable in
> the United States. I am glad to say the PlayStation Store's Video
> Download Service is still available in both Canada and the United
> States. I am having the appropriate department within Sony Computer
> Entertainment America (SCEA) look into the mentioned clause so that it
> can be checked for inaccuracies. I appreciate you bringing this to our
> attention. Please let me know if you have any other questions or
> concerns in the future.
>
>
> Regards,
> Richard K.
> * Auto-Response* 04/08/2011 07:10 PM
> *** PLEASE DO NOT REPLY TO THIS MESSAGE. THIS IS A SYSTEM-GENERATED AUTO
> RESPONSE. ***
>
> Thank you for contacting Sony Computer Entertainment America, LLC (SCEA).
>
> You have received this auto-acknowledgement to confirm that we received
> your message. We will respond to your message within 24 - 48 hours. For
> immediate online support, please visit our PlayStation Knowledge Center
> at http://us.playstation.com/support 24 hours a day.
>
> Thank you for your patience.
>
> SCEA Consumer Services
> * Customer By Web Form (ROD MACPHERSON)* 04/08/2011 07:10 PM
> Dear Sony,
> I cannot agree to your April 1 terms of service. Sect. 8 Video Content
> says "...viewing in the United States only" I'm in Canada.
> I am not going to drive my Playstation3 4 hours to the nearest border
> crossing just to watch a video I PURCHASED from you. Update the
> agreement please.
>
>
>


--

Rod MacPherson
rod@macphersonclan.com
Response Via Email (Richard K.) 04/09/2011 02:43 PM
Hello Rod,

I understand the concern caused by the mention of content purchased from the PlayStation®Store's Video Download Service only being viewable in the United States. I am glad to say the PlayStation Store's Video Download Service is still available in both Canada and the United States. I am having the appropriate department within Sony Computer Entertainment America (SCEA) look into the mentioned clause so that it can be checked for inaccuracies. I appreciate you bringing this to our attention. Please let me know if you have any other questions or concerns in the future.


Regards,
Richard K.
Auto-Response 04/08/2011 07:10 PM
*** PLEASE DO NOT REPLY TO THIS MESSAGE. THIS IS A SYSTEM-GENERATED AUTO RESPONSE. ***

Thank you for contacting Sony Computer Entertainment America, LLC (SCEA).

You have received this auto-acknowledgement to confirm that we received your message. We will respond to your message within 24 - 48 hours. For immediate online support, please visit our PlayStation Knowledge Center at http://us.playstation.com/support 24 hours a day.

Thank you for your patience.

SCEA Consumer Services
Customer By Web Form (ROD MACPHERSON) 04/08/2011 07:10 PM
Dear Sony,
I cannot agree to your April 1 terms of service. Sect. 8 Video Content says "...viewing in the United States only" I'm in Canada.
I am not going to drive my Playstation3 4 hours to the nearest border crossing just to watch a video I PURCHASED from you. Update the agreement please.

[---001:021920:26014---]

Monday, April 18, 2011

Epsilon: Be wary of Phishing attempts coming from legitimate looking e-mails

We all subscribe to e-mail newsletters in some form or another.
We all get those deal of the day e-mails telling us the latest deals at our favourite retailers or Air Miles updates with links back to the Air Miles site and vacation deals.

We all need to be a lot more careful.

Last month Epsilon, a marketing firm that deals with many of the retailers we all know and trust was hacked.
At first it was downplayed as not important because the hackers only got names and e-mail addresses. No credit card data was ever stored by Epsilon on the systems that were breached, and in fact they would not have that info in most cases because they are just the guys who send out those e-mail newsletters on behalf of retailers and banks.

Not long after, people started to realize the implications of this breach, but the problem is, even the tech press never really got the point across very well, and it was usually ignored by readers because the news sites only ever listed a handful of companies that were affected.

Most people reading about the breach are probably thinking, "I don't deal with those companies, I'm ok" looking at the short list of 3-4 examples in most news stories about it, or "so they got my e-mail address who cares, I get spam all the time".

The issue is they got e-mail addresses, and names linked to retailers and banks that you DO deal with and that you are already used to getting e-mails from. ...e-mails that already link to a 3rd party, that takes stats then forwards you to the retailer's website. So you are used to seeing links in these e-mails pointing to somewhere other than the official website, but eventually taking you there.

This is prime data for a wide spread, and likely to be highly successful, Phishing expedition.

They send you an e-mail that looks like every Sears ad you've gotten on a monthly basis for years, it has a great bargain on BBQs... You think "It's spring, I should probably check out this deal on BBQs" and you click it. It takes you to what looks like a Sears website (and yes they can be VERY convincing) but it is not. It is a fake Sears website that they set up just for the purpose of collecting more info about these people that they already know are Sears customers... Maybe you will attempt to order that BBQ and they will get your credit card, and you won't know it till it is way too late.

The other scam that they are running is a fake Epsilon breach news update site (copied from the actual press release site) that offers up a downloadable tool that they tell you to run to see if the hackers have your e-mail address... That tool is a Trojan!

So do they have your e-mail address? Probably. Do you get regular e-mails from any of these companies?

1-800-FLOWERS
AbeBooks
Abercrombie & Fitch (WFNNB)
AIR MILES Reward Program (Canada)
Ameriprise
Ann Taylor (WFNNB)
AshleyStewart (WFNNB)
Avenue (WFNNB)
Barclays Bank of Delaware
Beachbody
Bealls (WFNNB)
bebe
Best Buy
Best Buy Canada Reward Zone
Benefit Cosmetics (see below)
BJ’s Visa (Barclays Bank of Delaware)
Brookstone
Capital One
Catherine’s (WFNNB)
Chadwick’s (WFNNB)
Charter Communications
Chase
Citigroup
City Market
College Board
Crate & Barrel (WFNNB)
Crucial
David’s Bridal
Dell Australia
Dillons
Disney Destinations (The Walt Disney Travel Company)
Domestications (WFNNB)
Dressbarn (WFNNB)
Eddie Bauer Friends
Eileen Fisher (doesn’t name Epsilon but same template letter)
Ethan Allen
Eurosport Soccer (Soccer.com)
Express card (WFNNB)
ExxonMobil Card (Citi)
Fashion Bug (WFNNB)
FINA (WFNNB)
Food 4 Less
Fred Meyer
Fry’s
Gander Mountain (WFNNB)
Giant Eagle Fuelperks! (WFNNB)
GlaxoSmithKline Consumer Healthcare (GSK)
Goody’s (WFNNB)
Hilton Honors
Home Depot Card (Citi)
Home Shopping Network (HSN)
J Crew (WFNNB)
J.Jill
Jay C
Jessica London (WFNNB)
JPMorgan Chase
Justice (WFNNB)
KingSize Direct  (WFNNB)
King Soopers
Kroger
Lacoste
Lane Bryant (WFNNB)
L.L. Bean Visa (Barclay’s)
M & T Bank
Marriott Rewards (FAQ on site)
Marks & Spencer
Maurice’s (WFNNB)
McKinsey Quarterly
MoneyGram
MyPoints Reward Visa
New York & Company
NTB Card (Citi)
One Stop Plus (WFNNB)
PacSun (Pacific Sunwear) (WFNNB)
Palais Royal (WFNNB)
Peebles (WFNNB)
Polo Ralph Lauren
PotteryBarn/PotteryBarnKids (WFNNB)
Quality Food Centers (QFC)
QualityHealth
RadioShack (WFNNB)
Ralphs
Red Roof Inn
Reeds Jewelers (WFNNB)
Ritz-Carlton (FAQ)
Robert Half International
Scottrade
Sears (Citi)
Shell (Citi)
Smile Generation Financial
Smith’s Food & Drug Centers (Smith’s Brands)
Sportsman’s Guide (WFNNB)
Stage (WFNNB)
Stonebridge Life Insurance
Target
Tastefully Simple
TD Ameritrade
The Limited (WFNNB)
The Place (Citi)
TIAA-CREF
TiVo
Trek (WFNNB)
United Retail Group (WFNNB)
US Bank
Value City Furniture (WFNNB)
Verizon
Victoria’s Secret (WFNNB)
Viking River Cruises
Walgreens
Woman Within (WFNNB)
World Financial Network National Bank




For more info:

http://www.databreaches.net/?p=17374

http://www.net-security.org/malware_news.php?id=1696&utm_source=Help+Net+Security+Daily+News&utm_campaign=6de5c5076e-RSS-hns&utm_medium=email

Friday, April 08, 2011

Take Back The Light

I know that the programme has been running for a year now, but I still get people asking me what to do with the used Compact Flourescent (CFL) light bulbs AKA twisty bulbs when they die.

Mainly they ask because with very few exceptions (a few vanity bulbs in the bathroom) all of my lights have been converted to CFL or halogen. (Halogen because low wattage halogen was available before high power dimmable LED) While CFL bulbs are available cheap in quantity these days, people are still reluctant because they don't know what to do with them when they die. It says right on the package that you shouldn't put them in the garbage because they contain mercury which could poison the water supply.

Anywhere in Ontario you can return ANY flourescent light tube, CFL or long tube style, to ANY Canadian Tire store.You just take it to the customer service area, and they have a bin specifically for CFL recycling. If you can't fit the bulb into the bin (because it's a long blub, or because the bin is full) just hand it over the desk to the clerk. Done.

They have them picked up and taken to a recycling facility in Ayr, Ontario, where they are safely recycled.

For more info read http://www.takebackthelight.ca/retail_take_back

Thursday, April 07, 2011

MD80 "spy camera"

I recently bought a very cheap little "spy" camera on ebay. (a little over $8 including shipping)

I wanted a helmet cam for my e-bike vlog on Youtube.

This cheap little camera fits right inside my motorcycle helmet. (it is tiny, so it doesn't get in the way at all) and records standard definition video to a microSD card. It runs off a built in rechargeable battery and charges via USB.

The video has a time stamp in the lower right corner, which is good for if there is an accident and I want to hand over the video to my lawyer or the police. The problem is that the date and time needs to be reset every time

you connect to the computer
the battery runs out. That doesn't sound bad except that it is not an automatic process, you need to manually edit a file called TAG.txt on the SD card and reboot the camera. (switch it off and on again)

I wrote a little BASH script (I use Linux as my primary Operating System) to handle that for me, so all I have to do is double click the MD80date.sh file and it generates the TAG.txt file for me.

MD80date.sh:
#!/bin/sh
DATE=`date +%Y/%m/%d`
TIME=`date +%H:%M:%S`
echo "[date] ">TAG.txt
echo $DATE" ">>TAG.txt
echo $TIME>> TAG.txt
echo "MD80 date & time have been updated in the TAG.txt file."



Here is a similar version for Windows

MD80date.cmd:
echo off
set YEAR=%date:~6,4%
set MONTH=%date:~0,2%
set DAY=%date:~3,2%
echo [date] >TAG.txt
echo %YEAR%/%MONTH%/%DAY% >>TAG.txt
echo %TIME:~0,8%>> TAG.txt
echo "MD80 date & time have been updated in the TAG.txt file."
So, if you pick up one of these dirt cheap cameras and need an easy way to set that timestamp, just copy these files into the SD card (in the root folder, or main folder, right next to the DCIM folder) then you just click on the one that corresponds to the OS you are using (Windows or Linux) before you eject and reboot the camera.

[NOTE: I've since upgraded to an 808 #11 keychain 720P HD camera]

Don't have a spy camera/dashcam yet? Get one at DealExtreme.

Tuesday, February 22, 2011

Using Ninja to Monitor And Kill Rogue Privilege Escalation

In the world of hacking, getting in is just the start. Once a hacker (if they have malicious intent we'll call them crackers) has found a way onto a system s/he then usually needs to jump to the Administrator or system or root account to be most effective.

Ninja is a program for Linux (and presumably most Unix like OSes) that monitors for such privilege escalation. Privilege escalations might not be crackers though. The common administration programs like passwd, sudo, etc. also set UID to root, so Ninja has white-listing for who is allowed to run what processes as root.

The white-list function of ninja makes it useful for enforcing policy. You can have a group of users who are allowed to run file editors as root to make changes to system configs and another group who are allowed to restart services, thus providing separation of duties. 

When you first install Ninja, it is set to logging only. This allows you to run it in log mode for a while until you are sure your white-list covers all of the normal use cases for your system before you put it into the proactive process killing modes.

There are 2 modes for process killing, one that kills the process running as root, and one that also kills the process that spawned it.

When first installed (on a debian based system like Ubuntu) it will tell you where it's configs and logs are:

Setting up ninja (0.1.3-2) ...
log: reading configuration file: /etc/ninja/ninja.conf
log: ninja version 0.1.3 initializing
log: magic group: gid=0 (root)
log: logfile: /var/log/ninja.log
log: whitelist mapped in memory at 0x7f851ba0b000
log: entering daemon mode



After install If I run a program in sudo, it will be logged as below:


rod@rod-ubuntu:~$ sudo nano /etc/ninja/ninja.conf


rod@rod-ubuntu:~$ more /var/log/ninja.log
[Tue Feb 22 06:12:23 2011] ninja version 0.1.3 initializing
[Tue Feb 22 06:12:23 2011] magic group: gid=0 (root)
[Tue Feb 22 06:12:23 2011] logfile: /var/log/ninja.log
[Tue Feb 22 06:12:23 2011] whitelist mapped in memory at 0x7f851ba0b000
[Tue Feb 22 06:12:23 2011] entering daemon mode
[Tue Feb 22 06:12:23 2011] entering main loop
[Tue Feb 22 06:12:23 2011] generating initial pid array..
[Tue Feb 22 06:12:23 2011] now monitoring process activity
[Tue Feb 22 06:25:55 2011] NEW ROOT PROCESS: nano[3686] ppid=2740 uid=0 gid=0
[Tue Feb 22 06:25:55 2011]   - ppid uid=1000(rod) gid=1000 ppid=2722
[Tue Feb 22 06:25:55 2011]   + UNAUTHORIZED PROCESS DETECTED: nano[3686] (parent
: bash[2740])
[Tue Feb 22 06:25:55 2011]   - nokill option set, no signals sent
rod@rod-ubuntu:~$


This logging alone, makes ninja worth the install because it gives you a way to track who did what as root no matter how they got to be root. (sudo, SUID, or a privilege escalation hack) Turn on the defensive modes and your system learns a little bit of self defense.

Now if only I could find a version of this for Windows machines. Anyone know of something similar (free or for a fee) for Windows?

Thursday, January 13, 2011

Illegal Content On The Internet?

What do you do when you find illegal content on the internet?

We all have heard the jokes that the main content of the internet is pornography.
So, what if you happen to be looking at some Adult content on the internet and you stray a little off the beaten track and find yourself in questionable territory, and maybe you find your way to something that looks suspiciously like images of children...

Maybe you are researching Nazis for history class and you come across some hate literature...

There are online hot-lines to report this, and if you don't know who to report it to, there is an association of these hot-lines, called INHOPE,  to help you find the right one.

https://www.inhope.org/en/makereport.html

Wednesday, September 22, 2010

Another Reason To Be Careful Where You Download From

HelpNet Security News has an article today on a new trojan that sort of holds your computer ransom.

This software is distributed as installers for popular software like Divx or uTorrent, and distributed through sites with domain names that look official to those not already familiar with what the real site's name ought to be.

Once you've downloaded and installed it, the program asks you to "unlock" it by sending an SMS text message from your cell phone to what is essentially a 1-900 type service. You send a text message, they send you the "unlock" code, and your cell phone gets billed for the "service".

Fortunately, this version isn't a drastic as some other ransom-ware that actually prevents you from using the computer until you get the unlock code.

http://www.net-security.org/secworld.php?id=9892

Wednesday, August 25, 2010

*nix System Hardening - Step 1

If you run a Linux, FreeBSD, or MacOS system with ANY server services open to the world (Apache, SSH, FTP, etc.) take a look at fail2ban.

http://www.fail2ban.org

The idea of this little program is that it watches your log files for failed attempts to log in and bans the IP that repeatedly fails to log in (usually that means they are password guessing, and not a legitimate user)

DenyHosts does something similar for just SSH, but if you have other services open fail2ban is better.

Monday, August 16, 2010

Small Businesses Hammered By Cybercrime

There is a good article over on Infosec Island by Ashesh Mamidi contributed by fellow blogger Theresa Peyton:

https://www.infosecisland.com/blogview/6481-Small-Businesses-Hammered-By-Cybercrime.html

The jist of it, as I've been trying to tell people: Viruses and Malware are NOT just an annoyance anymore. They are a real threat to your financial well being.

Everyone should be running at least a good firewall and an antivirus program. Better yet, I'd recommend trying a software whitelisting program like Faronics Anti-Executable ... if it's not on the approved list it doesn't get run.

Friday, August 13, 2010

How To Still Get Auto-updates In XP SP2

As you might already know, Windows XP SP2 has been retired, and cannot download automatic updates anymore (except to update to SP3).

If for some strange reason you cannot upgrade to SP3 (some incompatibility with a business critical app that is no longer supported by it's vendor) there is a way to fool SP2 into thinking it is SP3 and therefore allowing automatic updates to still occur. This is foolish if there is not a VERY good reason to avoid SP3, but here it is:

Go into the registry and edit this key: 'HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Windows,'  edit the DWORD value 'CSDVersion' from 200 to 300, then reboot.

I strongly recommend just updating to SP3, or better yet, buy Windows 7. ...but, if you have to stay on SP2, now you can, and not miss out on all of the patches.

There is no guarantee that this will not eventually run into a patch that will just break something, as Microsoft does not test the patches for SP2 compatibility any more, so if your computer tells the update server it's SP3 it will send you patches meant for SP3. Likely those patches will work, but there is some risk that they will not beacause they expect certain components that were updated in SP3 to be there.

Friday, August 06, 2010

Kill-a-Watt

This only really relates to people living in Oshawa, Ontario...but, Oshawa PUC is lending out Watt meters through the Oshawa Public Library.
You can borrow one of these meters:

http://www.opuc.on.ca/Conservation/Programs/WattReader.aspx


...by just presenting your Oshawa Library card and asking for one at the front counter of the library. You get it for 1 month, no fee.

I decided that even though I've done a lot (changed all my light bulbs, started using more efficient appliances, etc. over the years, there's more i could be doing. I borrowed one of these to see what I could identify as an energy hog and reduce my energy consumption even further.

I was pleasantly surprised that my laptop charger, which always has a glowing LED on it only seems to consume any appreciable power when the laptop is plugged in. I always unplug it anyway, but I was happy to see that when it is not charging the laptop it uses less than 1 watt. (the minimum that can be measured on this device). The same goes for the PSP charger and cell phone chargers. :)

I was very unhappy to see that my Playstation 3 (the old 60GB FAT version) uses a whole 25W when it is OFF!

I turned it on for a minute and it quickly went up to 180W. I imagine when I watch a movie or play a game for a while it will consume even more as the fans start to kick in.

It should be interesting to see what readings I get from some of the other electronic gadgets in the house

[Update Aug 8, 2010:
It turns out that the PS3 uses about 175W on average when it is on, regardless of how long it runs or what I do with it.

I tested my VCR/DVD recorder. It eats about 3-5W when turned off and 29W when playing a DVD. I guess I should use that to watch movies instead of the PS3. ]

[Update Aug 30, 2010:
My new favorite is our Daenyx DVD player. Not just cheap to buy, cheap to run.
It uses no power when turned off (you have to get up and push the on/off button, it's a real switch) and, surprisingly, it only consumes 5W when playing !  That's as much as the DVD/VCR combo unit (that we've now gotten rid of} used just waiting for an on signal from the remote.

The Dlink DIR-615 home wireless router (which I also like because I've installed DD-WRT on it) uses just 3-4W.]

Firefox 4.0 Beta Download Scam

People will fall for anything. There is a scam going around twitter and other social networking sites telling users that if they follow a certain shortened URL (see here for more on the dangers of shrotened URLS), they can then download a cracked version of Firefox 4.0 or a key generator for Mozilla Firefox 4.0.

This of course only leads you to a place to download all kinds of malware onto your computer.

This is ridiculous, as Mozilla Firefox is Open Source (as in free, always!)
You can download the REAL Firefox 4.0 beta from the Firefox site FREE! Keep in mind it IS a beta, there WILL be bugs.

Friday, July 30, 2010

Microsoft Security Advisory 2286198


Microsoft Security Advisory (2286198)  is about to get a patch!

It's about time. We've all (at least those of us who pay attention to these things) been waiting for 2 weeks for this very important fix. MS says they will have it ready to roll on Monday.

For those not watching MS's every move, this bug allows a malicious user to create a special .lnk file (shortcut) on a USB drive, or hard drive, or shared drive on a network... etc. and when you just browse to the folder containing it, it exectues! No double-click, you just have to look at the folder it's in. Thanks to the folks at MS who fixed it so quickly. This was a scary bug.

Note, if you don't want to wait till Monday, you can fix it now. Just disable the "WebClient" service under Control Panel>Administrative Tools>Services
If you don't know what WebDAV is, you don't need that service running.


Oh, and one more thing:
Recognize and avoid fraudulent e-mail to Microsoft customers:
=============================================================
If you receive an e-mail message that claims to be distributing
a Microsoft security update, it is a hoax that may contain
malware or pointers to malicious Web sites. Microsoft does
not distribute security updates via e-mail.

The Microsoft Security Response Center (MSRC) uses PGP to digitally
sign all security notifications. However, PGP is not required for
reading security notifications, reading security bulletins, or
installing security updates. You can obtain the MSRC public PGP key
at
https://www.microsoft.com/technet/security/bulletin/pgp.mspx.

To receive automatic notifications whenever
Microsoft Security Bulletins are issued, subscribe to Microsoft
Technical Security Notifications on
http://www.microsoft.com/technet/security/bulletin/notify.mspx.

(quoted directly from a Microsoft Security Bulletin)

Monday, July 26, 2010

What To Do With Old Hard Disks?

In the past, I have mentioned in just about every forum where the issue has come up, that the most important thing to do when disposing of an old computer is to keep the hard drive.

Sure, if you are trying to sell the old PC it will sell better with the hard disk, but in that case you should first wipe the data off it with a secure wipe program (like DBAN) not just format it.  

Back to my suggestion that you keep it.... If you keep your old hard disk you will always have access to it as a point in time backup of what your old system had installed and what files you had at the time of your upgrade. This is handy if you forgot to copy something over to the new system, or you lose a file. Just stick that disk in your handy fire safe (you have one for valuable paper documents right?)

What do you do with it when you want to copy something from it? Get one of these handy dandy USB 2.0 to IDE/SATA adapters. (this link is just an example, search your favorite tech site or computer store and I'm sure you will find one similar to this). You plug one end into the hard disk and plug the included power supply into the hard disk (it should be pretty evident how that works, the connectors only fit one way.) and then plug the USB end of the cable into a USB port on your new PC. It will appear, after a moment, as a new removable drive. ...just like a USB memory stick.

You then can copy and paste files from it, or to it, and use it as your backup hard drive. Maybe make a folder called "OLD PC" and drag and drop all of the current contents into it, then create a folder with today's date "Backup-ddmmmyyyy" and copy your new files that you want backed up from your new computer's C: drive there.

Saturday, July 17, 2010

Can You Run It?

Here's the problem:  You have an older Windows PC (or maybe a brand new one with some limitations, like a netbook) and you want to know if it can run game X, but you don't want to search out the system requirements for game X and try to figure out if your system matches that.  "Minimum Nvidia GeForce 2 or equivalent? How does that compare to my built in Intel 500 ?" you might say.

Here is a solution: http://cyri.systemrequirementslab.com/CYRI/

Just go to that website, choose the game you are trying to find from the list (or search for it) then click the "Can You Run It?" button.

The first time you run this you will have to install an active X control (click the yellow bar that appears at the top of the browser.)

It will analyze your hardware and give you a report of whether the game will run, or what part needs to be upgraded to play.

Wednesday, July 07, 2010

Beware Of Photo Printing Kiosks, There Be Dragons

Morgan Storey, a security researcher in Australia, recently blogged about something that hadn't occurred to me before, but should have.... You know those photo printing kiosks in the mall, Walmart, Costco, etc. Have you ever noticed that they run Windows? Sometimes they are built on outdated hardware, so probably they are running old, unpatched, out of date Windows?

How many USB sticks and memory cards get plugged into them every day? More importantly, how many virus infected USB sticks and memory cards? ...and how many previously un-infected cards and sticks come home from them with brand new infections?

This is a serious issue. Protect your own systems by doing one or all of these things:

1. turn off Windows' ability to run autorun.inf files. Autorun.inf files are used to automatically start install programs when you insert a CD-ROM or USB stick with software you want. Windows Vista/7 will still pop up the auto PLAY pop up asking what you want to do with your newly inserted USB drive, but it won't execute the instructions in the Autorun.inf file on it.

Copy these lines into notepad and save as disableautorun.reg

REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\Autorun.inf]
@="@SYS:DoesNotExist"


Then simply double click the disableautorun.reg file.


2. use only USB/SD devices with a read-only switch on them. Switch it to read-only mode before sticking it in the mall's computer.

3. Format the card (if you are using the camera's card) in your camera right after you get home. So far there are no cross-platform viruses that infect both computers and cameras. That doesn't mean there will never be, but for now that's a safe assumption that a virus you got from the kiosk won't infect your camera.

4. ask your favorite photo printing place if you can upload the photos to their website from home instead of bringing them in on a card/USB stick.

Friday, June 18, 2010

Playstation Move Makes The PS3 More Like The Wii

Earlier I wrote about how Kinect was making Xbox360 work more like the Wii, well, Move is Playstation's answer to the active gaming trend.


You Can see a picture of the Move Motion controler with it's little motion capture ball on the end, and the associated Move Navigation Controller here: http://us.playstation.com/ps3/playstation-move/
It will look very familiar to Wii gamers. The two piece controller is remarkably similar to the Wiimote, but reportedly much more accurate. These controllers also rely on the use of the Playstation Eye camera.

At $50 for the motion controller, $30 for the navigation controller, and $40 for the camera it comes out a little bit cheaper than the MS Kinect system, and not all games will require all 3 parts.

This should end up being an interesting year for videogames with these new motion controllers and 3D gaming toys from both Sony and Nintedo.

Tuesday, June 15, 2010

Xbox 360 Becomes More Like Wii

The video game geeks know it already as Project Natal, but it's been re-named Kinect and it's the hottest upcoming Video game technology. You can preorder a kinect set now for about $150 for the special motion tracking camera (EBGames is taking orders), plus you will need some new Kinect games.
The cool thing about Kinect is that it has no controller, just a camera that sits on top of the TV.
PS3 is doing something similar, but will use the standard Playstation Eye camera and add a lightsabre-like controlller so that you still have buttons to push and it should improve the camera's tracking... but back to Natal um, I mean, Kinect.

Here is what it looks like:

Friday, June 11, 2010

FortiGate signature for Robint.us Mass Website Hack

This is highly technical and goes beyond the "tech tips for everyday users" that I initially intended Rod'sTech to be about, but it's important and I want to share this with the InfoSec community.

If you haven't heard of this mass SQL injection hack that happened recently read about it on one or more of these sites:

http://blog.sucuri.net/2010/06/mass-infection-of-iisasp-sites-robint-us.html
http://www.net-security.org/secworld.php?id=9395&utm_source=feedburner&utm_medium=email&utm_campaign=Feed%3A+HelpNetSecurity+%28Help+Net+Security%29

For goodness sake, do not go looking for the URL mentioned here with a JavaScript enabled browser!

For users of FortiGate brand UTM firewalls I've put together a FortiGate IPS custom signature that should help by blocking/reporting on infected sites.

It is:

F-SBID( --name "robint-us-web-ad-hack"; --protocol tcp; --flow bi_direction; --pattern "ww.robint.us/u.js}{/script}"; --service HTTP; --context body; )

Note: You will have to replace } with > and { with < in the pattern section to make the signature work. I cannot publish it in full here or it might trigger the attack accidentally if a browser parsed it as an instruction.

Open up your FortiGate system, go to Intrusion Protection|Signature and click the Custom Tab at the top. Click the "Create New" button.

Paste in the code (remember to make the modifications I mentioned) and name it robint-us-web-ad-hack. Click OK.

Now click IPS Sensor on the left hand menu, and choose your sensor (If you are not using IPS refer to the FortiGate manuals. It is way beyond the scope of this blog post to tell you how to set that up) Click the little edit button in the right-most column next to the sensor you want it in.

Click the "Add Custom Override" button.
Fill in the Signature name and check enable, select the action you want to take and select logging to get your alerts.

Thursday, June 10, 2010

Good InfoSec Ad


Note: I in no way intend this to be an endorsement of the company that made the ad, I just thought it was a neat ad.

Wednesday, June 02, 2010

Microsoft Baseline Security Analyzer

Most every IT pro has heard of and (hopefully) tried MBSA at some point, but here's a reminder for those who haven't revisted it in a while, and a step by step how to for anyone new to this tool.

This is EASY to use and everyone should check their systems against this tool from time to time.

  1. Download the tool.
  2. Install it. (Double click the exe file you just downloaded.)
  3. Go to Start|All Programs|Microsoft Baseline Security Analyzer 2.1
  4. Choose if you want to scan one computer or multiple computers.
  5. Fill in what computer(s) you want to test (you must be administrator on them)
  6. Click Start Scan
  7. Sit back and drink your coffee.

Friday, May 28, 2010

Keeping Your Kids Safe Online

For parents looking for something to teach kids about online safety, there is
Zoe and Molly Online. It is a web comic and quiz designed to teach children about possible dangers online. It was created by the Canadian Centre for Child Protection, in partnership with Shaw Communications Inc. It's being introduced to kids at school all over the country.

If you find something online that exploits children report it here: http://www.cybertip.ca

Friday, May 21, 2010

Hotmail Gets More Secure

Following Google's lead, Microsoft has made the SSL/TLS secured http (https://) protocol the default for Hotmail.

In addition, Microsoft has started an attempt to make the users more aware of possible phishing attempts by marking the e-mails they have verified as coming from a legitimate source with a green shield icon.

Spam filtering finally gets personalized. You can now mark senders (who are not necessarily on your contact list) that you don't want to be sent to the junk mail folder.

And perhaps the most innovative feature, if you are away from home and accessing your e-mail from a public workstation (like a cyber-cafe or library) or simply on an unsecured wireless network and want to have the added assurance that your password will not be compromised, you can request a one-time password to be sent to your phone.

Tuesday, May 18, 2010

SecTor 2010

I registered before the Early Bird price expired again this year, and boy am I glad I did. Looking at the first round of speakers that have been announced... There are a few I'm really looking forward to, but none more than HD Moore's talk on Metasploit and penetration testing.

For those who don't know what that's all about, penetration testing is basically simulating a cyber attack. HD Moore Is one of the world's most recognized names in this field because he started the Metasploit Project to create an open framework of tools to do such testing.

This is the direction I'd like to take my career in. I'm really excited about a chance to meet HD.

Cyber Security In Canada?

A CSIS memo says risk of cyber attacks on the rise. (No surprise to me or anyone else in the computer security industry.)

Check out this video clip from CBC's The National

So far Canada doesn't have a comprehensive plan. By contrast, the USA is spending $40 billion on cyber security. Are we falling too far behind?
Public Safety Canada says that a national strategy is pending, I hope it's worth the wait.

Friday, May 07, 2010

The Very Real Dangers Of Photocopiers

In case you missed it, the internet's been all a-buzz about the dangers of photocopiers from a privacy and information data leakage point of view.

CBS did a great little 5 minute segment on this, here it is:



Watch CBS News Videos Online

Tuesday, May 04, 2010

How To Start using E-mail Encryption (Part 1)

I called this "Part 1" because there are a number of different ways to encrypt e-mail, and this is the one I use, but over time I will try to cover others.

Why encrypt? E-mail is sent in plain text. If you are careful, you connect to your ISP's mail server using SSL encrypted transports. (the https:// page of a webmail, or using the SSL versions of POP or IMAP as explained in my previous post about Gmail security). If you are lucky, your ISP might use SSL encrypted transports beween their server and the next server (still not common practice), but plain text versions sit on the disk at both servers, and eventually on the computer of your intended recipient. The recipient we are not worried about, but if it's not something you want the mail man reading you don't put it on the back of a post card, you stick it in an envelope. That's encryption. SSL trasport encryption is like those big yellow interoffice mail envelopes. All your stuff goes into one of those for transport across the office and is opened when it gets to the right department. PGP (Pretty Good Privacy) or GPG (Gnu Privacy Guard, the opensource version of PGP) is like mailing your letter in a lockbox that only your recipient has a key for.

So how do you set up GPG for personal use?
First, if you are still using Outlook Express as a mail client, switch to Thunderbird. No, really. Outlook Express is a bad mail client anyway, and the integration with PGP and GPG is dismal.

If you are using the full blown Outlook you must be using it for corporate use, just buy PGP it integrates seamlessly.

Now for those already using Thunderbird (or new converts from Outlook Express), download the appropriate version of  the Enigmail Add-on and GNUPG for your OS. (Gpg4win if you are on windows)

Install GPG. Install the Enigmail add-on into Thunderbird

When you have Enigmail installed you will see a couple of new menu items and icons at the top like this:


Then you need to create a GPG key, associate your key with your e-mail address in Thunderbird, and set the settings of when you want your key to be used for signing and encrypting. I recommend that you set it to encrypt automatically if the contact has a known encryption key.

Follow the instructions that came with your version of GPG for creating a new key. 

Associating a key with your e-mail address is pretty easy.
Open the account settings in Thunderbird (where you set your e-mail address), there is a new menu item there too.

If this is your first time ever using GPG/PGP then you can probably leave it set to use e-mail address to identify OpenPGP key. If you have old keys floating around or use multiple keys select the Use specific OpenPGP key option.

Select whether you want it to insist you sign messages or not.

Back to that OpenPGP menu item on the main window... Click it
Select Preferences.

The most important setting in this menu is this one:
When sending mail, Add my own key to the recipients list. If you don't select that you won't be able to read your own sent mail when you encrypt.
Next to that I'd say selecting the Encrypt replies to encrypted messages is a good one to check. If someone went to the trouble of securing communications with you, you don't want to reply to them in the clear.

Now when you go to write a message there is a new option icon at the top of that screen:


Now you just need some PGP public keys of friends to send encrypted mail to. Here's mine. Have fun, and stay out of trouble. :)

-----BEGIN PGP PUBLIC KEY BLOCK-----
Version: SKS 1.1.0

mQGiBEokPi0RBACEx42f/6jaMTyWSfi3165ew22znJ2lUc3hW635/uWw6kD12G3eWqe7Ph74
wMaUanH/pK0ReTHwkds7pMRU0+e+k9bX0xmwAmzVlmp8E2MpLJ9GN5c/Dl7y2wkP2b1LGszl
L51ub4KZfZUxZDDCuNu6kZoUw5rLo44XPc0wonP00wCgzkWraKCG/MVqTx7sfN4R1xoPDxUE
AIH7p3/n0smBGYqSSPxGEpzqzAmfKR4vnz38SEDlSqCtI4gv1OtW9/ujVXr4JdOD+cvPstPj
oeeluGsYDdsi/c3CVAf63sKCHoqEE8LmM2syvULA7RdkZ9bvtvyP1wtH25e/weHSUVWdX/ou
x/HG0P952O+tt95w0sYbuWWMKoQNA/4olQ6g/tT9D6hHUPfg3OZjTzIxbWreafg5ZcRoVsCy
sMyyQH7zWpzOvy1sZAg5KynvZFqmij4VBRulcieh6Yuz7lYO2XarpYlmoOa8JcbCNHIutkts
HT8DHSy18Kiq6RA1gqbT/3tmDsDfYNWEGX379GWM0l9f/3mtw2YQGFRcp7QnUm9kIE1hY1Bo
ZXJzb24gPHJvZEBtYWNwaGVyc29uY2xhbi5jb20+iGAEExECACAFAkokPi0CGwMGCwkIBwMC
BBUCCAMEFgIDAQIeAQIXgAAKCRClLPlKUhouNpKdAKCK9xZ/T0POQLJjn7/bjanGJIxmTgCg
rirVjRUGAOX+pe+X/KWvJwwxyoy5Ag0ESiQ+LRAIAMZcPrDRfiDkPLQPrDqPSBEbyQBBXqhU
5kwdFGyPTJzvluLz4NBvX8JsetQ95FTBQe5e03j+VKrzSPNglXtPYxKLbt6fpNJALF2lmPNU
Jm2ppp8PsFwUe1zPUZyf05OohHqpXper8Wpzp3C7fVFTC7Ii7hBPEyo7y/0RLd6u40X3a+5M
q/57QXAa8lqm006aG70ScDhtYvT6f8mKBWu+fgD7G5EMT8ICcO78qXLMtWv0R48UPXoqM4GM
TrVhlZSwGY5HvY/L8RtUI9irZMH2LoreXRbTaWwYzapJsw3C6oHyeb9hpCbbnwdbrKnRmeMY
VqdED2eYOY6VIJ6/vLD4QF8ABAsIAIdQWUOfNY/x7+ZDDdat62dyabzlNFk6YN444WQ+8Qno
9346gxtp4BMH8O0UksYkXl5KeCiMofMTQlZFCSdfTs5QK6NbkT5Yes/mchAJy5749zvGdVnJ
HZD6cIaCwYaf4nKbyZP4qyJK7hdBvMeNfaPI131OPtmA8DHxnb8pjPYbdTRbJ0/++iP4HcQU
sAvIY9+WXDHUMjDolfa4GtEemsudM+sBGrz5Sv4Jm3vvXazcDO4ehgIflXvF4w32OEYk+3Y5
VuSY4qBbRZlaAwdzlUcr4XMdW0518HJw9U9l+33C0D3o9klt7NzSAeLvloDdEmY1A1xd31Ue
7KuGEP2InEOISQQYEQIACQUCSiQ+LQIbDAAKCRClLPlKUhouNnfiAKCx0e8IUsBXCGDp5/Za
ZUathieLqgCaAz1aqmbfvvDM5jYDOhlW038OHJc=
=E1F/
-----END PGP PUBLIC KEY BLOCK-----

Sunday, May 02, 2010

Why Keep Passwords To Yourself?

This video I found online will help explain it.

HACKING IS EASY! from Airwave Ranger on Vimeo.

Tuesday, April 27, 2010

Certified Ethical Hacker?

Yes, there is such a thing.

Although, I'd say that it certifies neither that you are a hacker, nor that you are ethical.... but it does show that you have been exposed to a wide variety of tools that hackers might use to invade your network, so that you will recognize them if you ever come across them, and you will be able to use them to test your own defenses.
("testing" someone elses defenses without written approval is illegal!)

I strongly recommend that, as a minimum, every network security professional should have this certificate.  It took me very little time, most of which was spent finding and playing with some of the programs, and very little money (less than $300 including the test and the review guide) to get this, and, while it is not the most prestigious certification on the planet (My CISSP is something I prize far more), preparing for it was a good review of all the "hacker tools" I'd read about in the past 10 years, and reminded me of some tools for network administration that I'd neglected that have made life much easier (like Microsoft's PSTools)
Update: April 29, 2010

So what does an Ethical Hacker do?
An Ethical Hacker tests a corporation's network defenses under contract by that corporation to identify weaknesses in the company's information security, so that the company can fix the problems before a malicious hacker (or cracker) finds and takes advantage of that weakness.

Why would a compnay need to hire an Ethical Hacker?
They don't want to be the next TJX. Some government regulations require companies in certain industries to have Penetration Testing (simulated hacking) done on a regular basis. The Payment Card Industry Data Security Standard (PCI-DSS) requires larger companies to have at least regular vulnerability assessments done. Ethical Hackers can help with some of these goals.

Why did I get certified?
I want to take the EC-Council Certified Security Administrator (ECSA) course later this year, and probably then become a Licensed Penetration Tester (LPT). To do that I needed to first get the CEH certificate.


Thursday, February 11, 2010

Microsoft End Of Support Coming Up Soon For Some Versions Of Windows

After April 13, 2010, Microsoft will no longer issue security updates for Vista RTM (release to manufacturing).  Vista users are encouraged to upgrade to Vista Service Pack 1 or Service Pack 2 if they have not already.

I'd personally recommend SP2.

After July 13, 2010, Microsoft will no longer support Windows 2000 at all, and will no longer issue security updates for Windows XP SP2.  If you are still running Windows XP SP2 upgrade to SP3, or Windows 7.

Wednesday, January 20, 2010

The "Aurora" Attack That Got Google And Adobe

This is why you MUST get off IE6 and onto an up to date version, and KEEP it up to date, and run an up to date Antivirus.

I'm sorry, this is really technical, but it is important. 



YouTube video courtesy of Sophos Antivirus.

Thursday, January 14, 2010

Gmail Now Secured By Default

Google has decided to make the SSL encrypted sessions in Gmail on by default now!
I talked about this little known option back in September. You no longer have to go into the settings to turn it on, it's on by default now. Yay Google!

Now if only Hotmail, and Yahoo mail would follow the lead.

[UPDATE: May 2010]
Hotmail has followed suit! now Yahoo where's your update???

Tuesday, January 12, 2010

Why Isn't Apple Giving Us A Patch? (Again!)

Why does Apple sit on bugs that have already been fixed by others for so long?
http://mobile.darkreading.com/9287/show/f4a5b8931d4d475c18ae22de0f497db3&t=dafc4b74d510e5f9ebf32b0d1a1a7475

Remember the Java one that hit the news back in May? At least you could get your Java elsewhere.

Sunday, December 27, 2009

SmartSwipe (and HomeATM)- A Very Smart Tool For The Cautious Online Shopper

I hadn't heard of this device until I was leafing through the Hammacher Schlemmer catalog tonight and the claim of a credit card reader that you plug in to your USB port that will read your credit card and encrypt the card info, and insert it into the browser, pre-encrypted, to be securely transmitted to any online store without ever passing the unencrypted data to the user's computer caught my attention.

The device is the SmartSwipe by Canadian company NetSecure.

I had a hard time believing that what the catalog was claiming was possible, but then after reading the white-paper on it at the SmartSwipe site I think it's incredibly smart. With this device installed, it's driver is used by the web browser as an encryption engine. The browser (for now it only works with IE) passes off the unencrypted form to the device, which inserts the creditcard data into the form an encrypts the page before passing it back to the browser to transmit to the store website. The device does the encryption, not the browser, so since the card scanning and encryption are done outside the computer, there is no unencrypted data for spyware running on the user's PC to read.

Normally, if you typed it in yourself, there are a number of places where spyware or keyloggers could grab the unencrypted data before the browser gets a chance to encrypt it to pass it securely over the net to the store.

This way the spyware would have to be running on the card reader (which for now anyway, isn't an issue, no one has written spyware that runs in the external card reader) so, it is safe from all the current spyware until it gets to the store's end of the chain.

These are very nice, and I hope that they manage to work deals with the major manufacturers to install these, or better yet, a next generation chip and pin version directly into new PCs.

The SmartSwipe is probably not the only such device out there, the technology to look for if you find another device like it is called Dynamic SSL. I believe Dynamic SSL is the future for secure online shopping. 

For a little company from Saskatchewan, they certainly have made inroads with this device being carried by Costco, Futureshop, Dell and Amazon already, and it only works with 32 bit Internet Explorer so far. Once it works with other browsers it'll probably become a commonplace tool for regular internet shoppers.

[Ed note: Only a few hours after the initial post which mentioned only SmartSwipe, a sales person from Home ATM posted a comment. Therefore I have changed the title to reflect that. Having read the website at http://www.homeatm.net I cannot say for sure how the HomeATM works, but I am really disappointed in the video demo that they use to show how secure it is. The fault in the video isn't really with the device itself, but the method that Western Union used to send the money that was taken from his account to the recipient.

Sure, it was securely transferred from his account to Western Union, but then Western Union sent an unencrypted e-mail to a Gmail account with a web link and all the details including a password needed to retrieve the funds. Anyone who could intercept that e-mail could take the money before it got to the recipient. Sure, then it is securely transferred to the hacker's account from Western Union, but the intended recipient is left with nothing.

It is not the device's fault how Western Union chose to implement the transfer, what W.U. should have done was what the Canadian banks on the Interac system do and have the user create a password that they tell the recipient OUT OF BAND so that an intercepted e-mail transfer is still secured by a password that is not known to the intercepting bad guy. It is a poor marketing choice to use a video of a system with such an obvious security problem to demonstrate a security device.

The biggest problem I see with the device itself, aside from being a magstripe and PIN device as opposed to Chip and PIN (which I'm sure will be the next version) is that there doesn't seem to be any way to actually get one.]

Friday, December 18, 2009

New Adobe Reader Vunerability

Adobe Acrobat has another newly discovered 0 day vulnerability.

As usual the fix is to disable JavaScript in Acrobat Reader. Adobe won't have a patch out till Jan 12.
If you have to do it network wide follow the instructions from this post I did back in October to do it via logon scripts.

Upgrade to 9.2 even though it is technically vulnerable, if you turn off JavaScript (which you should do even after the patch is out) 9.2 will let you enable JavaScript on a document by document basis as needed. (usually it is NOT necessary)

Monday, December 14, 2009

Xmas Gifts For Techies 2009

Ok, it's already Dec 14, you only have 10 days of Xmas shopping left. If you haven't already got a big gift for your resident techie, here are a few ideas:

1. PS3 slim. One of the first posts on this blog back in 2006 was the PS3 line watch. Back then I was drooling with anticipation of the upcoming PS3. I bought one in the summer of 2007 because I was stuck at home all day for a few months because of a car accident. ...even back then with hardly any games available it was fun. The new slim version is out now for this Xmas season. It doesn't play PS2 games anymore, and only plays PS1 games if you download them from the online store (about $6 each) but there are lots of PS3 games and bluray movies out now so that's not much of an issue, and if it is, you can always pick up a PS2 slim to go with it for peanuts.

2. Drobo. Every techie needs more disk space... constantly. Drobo will manage it all by itself. You just stick a disk in, when you need more space you stick in another disk, when you need more, stick in another. when you run out of slots to stick disks into you pull out the smallest disk and stick a bigger one in in it's place. No config, no copying files around, it takes care of it all for you.

3. ReadyNAS. For the techie that has more stringent requirements for his/her data storage, ReadyNAS is like Drobo on steroids.

4.Amazon's Kindle e-book reader. For a geek or a book lover (or a geeky book lover) this is a great gift idea. It stores and displays (in black and white) books and magazines bought through Amazon or downloaded as PDF. It has a rechargeable battery, but it only needs to be charged about once a week, even when the wireless is left on all the time. You can go much longer than that if you remember to turn off the wireless connection when you aren't actually downloading a new book.

Network Vulnerability Scanners

Back in September I mentioned that GFI LanGuard was available for free for small companies or home use where you only needed to scan 5 PCs.

One other option that has come up since then is the new much easier to use web-based Nessus 4.2.

Nessus has always been free for home users, but now I feel that it's easy enough for most home users to set up. It comes in a windows version, and there is only the server end to set up now, everything else is done through a browser.

Unfortunately the Pro version of Nessus is a little pricey for the average small business at $1200 per year, but you can hire a pro, like me, to come in and scan your network on a regular basis with this tool for probably a fair bit less than that. (pro licenses are not tied to a physical network, but limited to one machine... so if that machine is a laptop, a pro feed license can go wherever the security contractor takes it.)

Rapid 7 has also recently released NeXpose Community Edition, which I have yet to try out, but is free to use for a network of up to 32 PCs, and there is the open source OpenVAS, which was spun off from Nessus back at version 2, when Nessus was still an open source project. These 2 options I suspect would be more difficult to get up and running than the first two, as they are really aimed at folks with a high level of tech knowledge. NeXpose comes in several other versions for varying levels of additional features, and larger networks, but it is more expensive than the Nessus Pro feed, so very much out of the reach of the average small business or home user, but the Community edition is supposed to be very good, and I'll be playing around with it in the next few weeks and I will let you all know what I think.

No matter which you choose, scanning your network, especially for business networks, is an important part of keeping your network secure. If you don't scan it to find the holes in your security, someone else will, and they probably won't point out the holes to you, they'll probably just use those holes in ways you don't want them to.

One other option, from the folks at Rapid 7 is the free online scan. You can scan 2 IP addresses for free from the internet at http://www.rapid7.com/freescan.jsp This should give you an idea of how exposed your servers that are attached to the internet are. This will only scan public Internet IP addresses. It is probably best to get a local scanner set up or hire a pro to come in and scan the private address space as well, especially if you use wireless.

Friday, December 11, 2009

Making E-mail Private

Ok, hopefully some folks read and made use of my previous post on using SSL in Gmail.
If you didn't and you use Gmail, go read it now. It only takes about 10 minutes to read and another 10 minutes to implement.

Now, I have to wonder why is it that people never seem to care enough about privacy to encrypt e-mails?

Sure, for some it's a matter of not knowing you CAN encrypt, for others it's a not knowing HOW to do it... but it seems the biggest thing is an aversion to using passwords.

I have a 30 character password that I type in whenever I want to encrypt or digitally sign an e-mail. Most people would not go to such an extreme, but even a 6 or 8 character password with PGP or GnuPG that you only had to type once per mail session, when you first open your mail program or when you send the first message that day, would afford a lot more privacy and ensure that mail you think is from friend X isn't really from stranger Y pretending to be friend X.

How many people have had an e-mail come to them apparently from a friend that turned out to be spam, or worse, a virus? ...or even a roommate playing a practical joke on the supposed sender? PGP/GPG would solve that. I've been using this technology on an off (and recently more and more) for years, but surprisingly few others I know use it. I could understand if it were like S/MIME encryption that requires a yearly fee for a certificate, but PGP is free. All it takes is a little bit of effort to get started then you can stop sending love letters and secret passwords and Grandma's secret family recipes on the electronic equivalent of postcards and start mailing things in e-envelopes. (strong e-envelopes).


If anyone reading this is thinking "hey, I should do that, but it's too hard" e-mail me and I'll help you get started. ...just don't get discouraged if Microsoft and I are the only ones who even send you signed e-mails for a while. It's something that will take time to catch on amongst your friends, and that many people won't ever bother with....some folks will always think that secret codes are only for spies and criminals, but if you don't try to protect your privacy, who will?

Rod MacPherson
rod@macphersonclan.com
My PGP key

"Spacebook" Security Lessons In The Form Of A Comic

From http://www.gocomics.com/stonesoup/2009/12/09/







Friday, October 23, 2009

Upgrading From An Old BlackBerry?


If you have a blackberry and you have your personal e-mail forwarded to it (not your corporate mail) when you upgrade it, send it in for replacement, or even just toss it away, you MUST remember to log in to the BIS server at bell.blackberry.net or telus.blackberry.net or rogers.blackberry.net ...  depending on who your phone company is, or just through the mail setup icon on the blackberry device, and disable the forwarding. This does not happen automatically when you cancel your phone plan or move it to a new phone.

The corporate mail is different, it comes through a corporate BES server hosted at your company, and they can easily shut off the forwarding of any info to the blackberry device, but BIS used for personal e-mail is managed via the blackberry.net servers and linked to an account that only you know the password to. It collects the mail and forwards it to the device you specified by PIN #, which is attached to the device, NOT your account!

If that device is reused by another user with another phone #, the BIS server will still send your mail to the device until you log in and tell it not to.

That is just one more reason I dislike the BIS setup rather than letting the blackberry connect directly to the POP/IMAP server for personal e-mails. #1 I don't like that I have to trust RIM and their partners with my personal account passwords, and #2 wiping the blackberry and cancelling the phone plan isn't enough to ensure that the next guy doesn't get free access to my mail. I also have to either log in to the BIS and cancel forwarding, or change my e-mail password.

This is also why I discourage the use of PIN messaging except as an alternate, emergency communication channel if normal e-mail is down.

People still think of PIN as being more private than e-mail, but it is not. It can be, and often is, logged at one or both end's corporate servers, but if your contacts have an old PIN# in their address books and they try to PIN you a message, but somone else owns that Blackberry device now, guess who gets the message!



Wednesday, October 21, 2009

Tips Of The Day

If you have a Google Reader account or use an RSS reader here is a link you ought to be following:
http://feeds2.feedburner.com/security-awareness-tip-of-the-day

Wednesday, October 14, 2009

Adobe Virus Update

Users can undo the change, as it is in the Current User part of the registry, but here are the lines to add to the login script.
reg add "HKCU\Software\Adobe\Adobe Acrobat\9.0\JSPrefs" /v bEnableJS /t REG_DWORD /d 0 /f
reg add "HKCU\Software\Adobe\Acrobat Reader\9.0\JSPrefs" /v bEnableJS /t REG_DWORD /d 0 /f

You need both lines to get Adobe Reader and full Acrobat Reader/Writer.
The new Reader 9.2 gives the users a better warning saying that it can be potentially hazardous to turn it on and allows them to choose to turn it on "for this document" or permanently. (until they log in again and the script shuts it off again.)


Friday, October 09, 2009

More Adobe PDF Viruses On The Loose Patch On The Way

"You can get viruses from a PDF?" you say??
YES you CAN!!! and Seth Hardy of Symantec's MessageLabs just did a talk the other day at SecTor 2009 about how he's been able to (in a test lab) create a virus, embed it in a PDF and get past every known antivirus. This is scary stuff folks, and there is one little thing you can do to stop most of it.

HelpNet Security says that a new round of these viruses is out in the wild and Acrobat 9.1.3 is vulnerable, but a patch is coming on Oct. 13th. In the meantime they recommend turning off Javascript.

Open up Adobe Reader/Acrobat and turn off JavaScript! Yes, PDFs can have Javascript, though you've probably never even seen a PDF file that legitimately uses Javascript.

Here is how you do it in Reader 9.1.x :
Click on the Edit menu, click Preferences.

Select Javascript from the Categories menu.
Click the checkbox OFF next to Enable Acrobat JavaScript

Saturday, October 03, 2009

Loading CD-ROMs On A Netbook

OK, everyone knows that the biggest fall back of a netbook is it's lack of CD-ROM/DVD-ROM drive.
Most people know you can get a USB CD-ROM drive and fix that.
A few know about CD-ROM emulators like the one included with Alcohol 120%... but that has an extra cost.

After a little browsing around the net I found a FREE CD-ROM emulator from Microsoft!

Download the Microsoft Virtual CD-ROM Control Panel package now.

Thursday, October 01, 2009

OWASP top 10

This is a little higher level then what I normally post here, but this is info that every IT guy ought to know about so I feel I should pass this stuff on. October, being Cyber Security Awareness Month, will probably see more than the usual rate of security related posts here, and some may be aimed at IT people, others will be aimed at home users and small business owners.

OWASP Top 10 Security Vulnerabilities Part 1 (Barry Dorrans) from Edge UG on Vimeo.



OWASP Top 10 Security Vulnerabilities Part 2 (Barry Dorrans) from Edge UG on Vimeo.

Friday, September 04, 2009

Gmail Security

There are a few things you really should do if you use Gmail that will make it more secure (and more convenient).


First, log in and then click the Settings tab as shown.


Now scroll down to the bottom and check the "Always use https" option.
This will help keep people from spying on you at public WiFi stations like McDonalds, Starbucks, or the library.


Now for the more convenient part...
You can actually check Gmail in your own e-mail program! You don't need to log into the website, or to download some special Gmail only software to get the "you have mail" pop-up.

Click on the "Forwarding and POP/IMAP" link.


Down at the bottom, again you will find the "Enable IMAP" option. Turn that on.
Then follow the instructions in the Configuration instructions shown as step 2 in the image.
make sure you always select SSL as the connection method. (on port 993)

DO NOT cheat and select the gmail option in Thunderbird if that is your mail client. That will set you up with unencrypted POP mail. Trust me you want SSL encrypted IMAP. In fact, no matter who you are getting your e-mail from, you want SSL, or better yet, TLS encrypted IMAP. POP is so 1994. (and if you run it unencrypted you are enabling "Big Brother"...so maybe I should have said it's so 1984.)

PCI DSS

If you don't know what PCI-DSS is and you run a business that takes credit cards you need to read this:
Click for a free PDF copy

The Payment Card Industry (PCI) Data Security Standard (DSS) is something you have already agreed to, and MUST follow. Does your bill for your merchant account include a line about non-compliance fees? This is what it's about.



GFI LanGuard


There are all kinds of different network vulnerability scanners out there, but the best bet for small businesses is probably GFI Languard.

The reason? It's simple and it's free.

It is an easy to use Windows based program, so no need to learn or install Linux to use it.
It is absolutely free if you have 5 or fewer IP addresses (computers) to scan.
It is free for a 30day trial if you have more than 5 IPs to scan.

Wednesday, September 02, 2009

VirusTotal

VirusTotal is a free service that lets you check a suspicious file against 35 different Antivirus tools.
If you get an e-mail attachment that you really are not sure about, and your own AV doesn't see a problem, you can check it here and know with some certainty that at least no other AV vendor sees the problem.

Monday, August 31, 2009

Secunia - Keep ALL Your Software Up To Date

You have Windows Automatic Update to keep windows itself up to date, and if you remembered to opt in to it maybe you've even upgraded it to Microsoft Update to keep your Office programs up to date too. ...and some software like Firefox and Java have their own updaters, if you didn't disable them to keep your performance up...

But what about all the other programs you run? do you know you are upto date?
Secunia will tell you.

You can go to their web portal for a free scan of your system any time you like, and it will check it all for you. If you are using it at home you can download Secunia PSI (Personal Software Inspector) or if it is for business use there is the cooler sounding Secunia CSI (Corporate...) at a cost, but well worth it.

Wednesday, August 26, 2009

SecTor 2009 - Last week for discount pricing


SecTor (Toronto's big InfoSec conference) admission prices go up on Sept 1.
If you haven't got your tickets yet now is the time.

After Sept. 1 it'll cost $250 more to get in to this great IT security conference.

If you are a member of TASK or OWASP You can get an additional 10% off, just look through those mailing lists, there have been discount codes posted.

There are some great speakers booked for this year. I'm really looking forward to it.

Tuesday, August 11, 2009

Canadian pricing for Windows 7 family pack

Windows 7 will be available in a "Family pack" 3 pack of licenses for $200 ($67 each license) for home users wanting to upgrade from XP to Win7 Home Premium.


Read more at Digital Home.

Thursday, June 25, 2009

Certified


I recently (June 23, 2009) became certified as a CISSP® by (ISC)2.

Wednesday, June 10, 2009

BlackBerries and E-Mail

Why is it after all these years in the messaging business BlackBerries cannot handle E-mail as well as my old Pocket PC or Zaurus handhelds did? Sure they weren't cellular, but they could handle POP and IMAP over wired or wireless 802.11 connections without help. Even encrypted IMAP wasn't a problem.

Yes I can access my IMAP account from my Blackberry, but it has to use an intermediary server hosted by RIM which means that I have to enter my e-mail credentials for my private personal account into RIM's server so that it can check my IMAP mail and relay it to my Blackberry. Why doesn't my Blackberry come with an IMAP capable e-mail client?

The way they are doing it now has several problems.
#1 I have to give RIM my account info instead of just inputting it into a device that would normally be on my person.
#2 I can't access anything but the inbox. None of the other folders are available via this 2 stage e-mail retrieval process.
#3 (ok this is more a complaint about the OTHER type of e-mail BlackBerries do....) My BES e-mail from work doesn't get it's own icon like the BIS ones do so while I can look at each of my personal mail accounts individually, when I want to read my work e-mails it's all mixed up with the e-mails from my home accounts.

If I could have encrypted IMAP done on a 400 Mhz ARM processor 8 years ago, why can't my BB Storm do it?