Saturday, March 24, 2018

Do You Know Who Has Access to Your Gmail and Facebook?


Gmail users should go here  to see every app that has privileges to access their account. To see what specifically each app has access to click it and the window will expand with details. While you can't adjust the level of access, you can remove the apps and services you no longer want.

Users should also check what third parties they've given access to their Facebook account. To do that, go to settings, then apps, then edit. Under "Apps websites and plugins," users should click disable. Facebook users should also go to "Apps Others Use," and click edit and clear that out as well.


Keep in mind that not everything that has access is insidious, but each user should be able to judge that for themselves.



JavaScrypt: Browser-Based Cryptography


JavaScrypt: Browser-Based Cryptography is a  high-security data encryption solution which runs entirely in your Web browser. JavaScrypt's encryption facilities use the Advanced Encryption Standard (AES) adopted by the United States as Federal Information Processing Standard 197. AES supports key lengths of 128, 192, and 256 bits; JavaScrypt uses 256 bit keys exclusively.

I have long been a fan of John Walker's "JavaScrypt: Browser-Based Cryptography".

In March 2018, he made some updates to the program, making this a good time to again recommend that you download a copy of this excellent encryption program.

You can run JavaScrypt: Browser-Based Cryptography while on-line, but I recommend downloading  a copy and running it as a file within your browser. The downloaded and extracted (un-zipped) files are only 844 KB. Once you have all of the files saved to a folder on your computer, just click the "index.html" file and the program will run just like the web-page on-line, but you don't have to be connected to the Internet. JavaScrypt: Browser-Based Cryptography works precisely the same whether installed on your local computer or accessed over the Web. The only difference is that you use a "file:" URL to direct your browser to the local directory containing JavaScrypt rather than an "http:" URL pointing to a Web site.

Below is a message encrypted using JavaScrypt: Browser-Based Cryptography.

The password to decrypt this message is: H4M07TOV

#####  Encrypted: decrypt with http://www.fourmilab.ch/javascrypt/
ZZZZZ GNJPF IRXFA WFCRI IOXIQ OGREC GIHGG VFEWP WMSQF EDXQU BXUAE
UGUTB ARPKC ASEBB EGKWV SEXQT KIPXW QUBWT GBCEG TXKCK BCRVW XXTGS
IMVDA XWHBO QNTGD XGRNH DIOSU NDRLN IJDAV OITTW BCERE NTVMW DUVGL
XEBXG MNERJ WLPGE QXQBC ONWIP QHEAL FMQLB MUOJO PBGUG DTPKA XPHAO
DSDJV DAAHC AKRKJ AGUNR NTMXT XBNXC SQQKM SHMVU PLXGE JPQDQ PXVMK
XBSGO JECRE OUOJA IBOSC LDBNC OSMTV IOEFK VXVFG NXOJA INBPU PMAFI
IHGSK EXBGW AALLB PLSWD RXELS ABDLD VOSHG XLGQH KWIRU CKHNI GUTIF
AAJTQ OVOKT MTBHH VOQXG EAHVC QXSQT JVJGV JDBWB NAENQ OSPWW TUSVT
IAJXM IBQCW LDVTP GTMDA NSTFR RILCM BUUHV FMGRG IFPUV YYYYY
#####  End encrypted message




Friday, March 23, 2018

Up to 880,000 Credit Cards Accessed in Orbitz Data Breach


If you’ve booked trips through Orbitz, hackers may have accessed your credit card or other payment card information in a recent attack.

The consumer data in question is from an older booking platform, where information may have been accessed between October and December 2017, and data from an Orbitz partner platform, including travel booked via Amex Travel, submitted between January 1st, 2016 and December 22nd, 2017.

Reports from March 20, 2018 state that up to 880,000 payment card numbers and related information could’ve been exposed in a data breach. The additional information could include:

Customer’s full name
Date of birth
Phone number
Email address
Physical or billing address
Gender

Orbitz, which is owned by Expedia, had two different data disclosures - trips booked  between October and December 2017 and trips booked via Amex Travel between January 1st, 2016 and December 22nd, 2017.

Check your credit reports, and be alert for fraud if you booked a trip during these times.

Orbitz says its current Orbitz.com website wasn’t involved in this incident. It is notifying customers who may have been impacted and is offering a year of free credit monitoring.

Google Is Evil


Google is Evil. Well, OK probably not evil, but Google is a giant corporation, and some things that big business does can be very much like Big Brother.

Google provides a wide selection of products and services, offering excellent functionality and security - but this is at the expense of privacy. When you use a Google product or service Google can see everything that you do, from the searches that you run on-line  to the content of your e-mail. 

A 2016 article in US News & World Report said "Google isn’t just the world's biggest purveyor of information; it is also the world's biggest censor."  Google also owns YouTube, the largest video hosting site on the Internet, and we saw in a report from Bloomberg in March 2018 how YouTube videos are banned to meet Google’s political agenda.

Do I think that we need to dump everything associated with Google? No, not at all - there are some things that Google does very well. If you want to make information public - share it with the world - then Google is fine (assuming they don’t censor your content and limit your free speech). But if you want privacy and control over your data, then you may want to consider alternatives to Google.

If all you want to do is move away from Google, consider switching to Yandex and VKontakte (VK). You can think of these as the Russian versions of Google and Facebook. Telegram is also a nice messenger service that originated in Russia, but is now run out of Dubai. Switching from Google to Yandex won't do much to keep you from being monitored, the Russian FSB probably monitors everything you do, but they are looking for threats to Russia and are not likely to provide your information to outside agencies or use it for marketing.

If you are just trying to gain additional privacy and control of your data, there are some alternatives to Google that you may want to consider.


The first alternative is using a search engine that does not track and save your search history. One of the most popular privacy focused search engines is Duck Duck Go. Another is Start Page,  which returns Google search results but serves as a search proxy keeping Google from tracking your search history.

Getting rid of Gmail is essential to protecting your personal privacy. I recommend both Protonmail  and Tutanota for private e-mail. Likewise, don’t use Google messaging services, rather use an end-to-end encrypted messenger like Signal or Wire.

Chrome is Google’s browser. For those that don’t use Microsoft Edge / Explorer, Firefox is the most common alternative to Chrome. However, there are several other browsers available, and for privacy I like Brave. Users who want more control over their browsers might like Vivaldi. Of course, for even more privacy you may want to connect to the Internet using TOR. 

Google Drive is fine for storing documents that you want to share with the public. For ensuring the privacy of your documents stored in the cloud, I recommend SpiderOak One and Tesorit. You might also be interested in Kolab Now. None of these services are free, which may be a consideration for minimal personal on-line file storage. If you choose to stay with Google Drive or maybe Dropbox because they offer free storage, I recommend using Boxcryptor to encrypt everything that you upload to these sites.

OnionShare lets you share files over the TOR network.  Firefox Send, provides private, encrypted file sharing, letting you send files through a safe, private, and encrypted link that automatically expires to ensure your stuff does not remain online forever.

These are just a few of the possible alternatives to using Google. You will have to decide for yourself which, if any, of these alternatives meet your needs and what trade-offs you are willing to make between the convenience and efficiency of Google products and the ability to maintain your personal privacy and control of your data.



The Most Dangerous Town on the Internet


Norton explores the secret world of bulletproof hosting that’s hidden deep in underground bunkers, isolated at sea, and spread across the Web. Uncover the threats that lie within these services, such as botnets, malware, ransom-ware, and the black market, and learn how to protect yourself in "The Most Dangerous Town on the Internet - Where Cybercrime Goes to Hide" - Episode 2.


Also, watch Episode 1 -  "The Most Dangerous Town On the Internet - Hackerville (Ramnicu Valcea)" on YouTube. The cybercrime documentary profiling the Romanian town nicknamed "Hackerville". Convicted blackhat hackers, like Guccifer (real name), talk worms, viruses, social engineering, identity theft, and even hacking Hillary Clinton's email.



Thursday, March 22, 2018

Court Rules That Medical Marijuana Card Holders Can't Buy Firearms


If you have a medical marijuana card, the 9th U.S. Circuit Court of Appeals says that you can’t buy a gun.

The court ruled 3-0 on Wednesday (March 21, 2018) that a ban preventing medical marijuana card holders from purchasing firearms is not in violation of the Second Amendment, the Associated Press reports. There are nine western states under the appeals court’s jurisdiction, including Nevada, where the case originated.

According to the BATF - The use or possession of marijuana remains unlawful under Federal law regardless of whether it has been legalized or decriminalized for medicinal or recreational purposes in the state where you reside.

When you buy a gun from a licensed dealer, you are required to fill out Form 4473. Question 11. e. on the form asks you if you're an unlawful user of marijuana or other substances. Because marijuana is illegal federally, its use will be considered to be unlawful regardless of state law.

If you answer 'YES' to Question 11. e., you will be denied a firearm.

If you lie on the form and answer 'NO' to Question 11. e., you could face serious legal consequences.

The AFT sent a letter to all federally licensed firearms dealers in 2011 instructing them not to sell guns to people with medical marijuana cards. The ATF says the card gives a dealer "reasonable cause to believe" the person uses marijuana and should be denied a firearm.


YouTube Bans Firearms Demo Videos


According to an article in Bloomberg (March 21, 2018) YouTube has banned firearms demo videos.

YouTube, a popular media site for firearms enthusiasts, this week quietly introduced tighter restrictions on videos involving weapons, becoming the latest battleground in the U.S. gun-control debate.

YouTube will ban videos that promote or link to websites selling firearms and accessories. Additionally, YouTube said it will prohibit videos with instructions on how to assemble firearms.

The video site, owned by Google, has faced intense criticism for hosting videos about guns, bombs and other deadly weapons.

For many gun-rights supporters, YouTube has been a haven. A current search on the site for "how to build a gun" yields 25 million results, though that includes items such as toys. At least one producer of gun videos saw its page suspended on Tuesday. Another channel opted to move its videos to an adult-content site, saying that will offer more freedom than YouTube.

--

YouTube is the largest video hosting site in the world, it is a site that is owned and operated by Google. Many people are trying to move away from using Google products because of privacy (and now censorship) concerns.

While YouTube's new censorship of firearms videos will certainly hurt many channel operators, there are a number of other video hosting sites that can pick up YouTube's lost business.  Some of these sites are:

Vimeo.
Dailymotion.
Twitch.
LiveLeak.
Veoh.
Break.
Metacafe.
VK.
Brightcove.