Amazing Arizona Comic Con 2016

I don’t know why, but on mobile devices, the pictures come out sideways, on computer, they show up just fine…

20160213_201047431_iOS

20160213_203401778_iOS

This is Daryl, Daryl has a booth at Arizona Comic Con! Daryl is my cousin’s roommate!

20160213_203744712_iOS

Who would win in a fight? Superman or Goku? Trick question! They’re buds!

20160213_212131789_iOS

20160213_212140260_iOS

Beau loves his slippers! He’s so friggin’ big!

20160214_005216000_iOS

Been caught stealin’

20160213_213355537_iOS

Family selfie time!

20160213_215734935_iOS

I met instagrammer Amber Skies

20160213_221014680_iOS

Deadpat and Dogpool!

20160213_230958939_iOS

We met a cosplayer named Nikki with a huge dress. We talked briefly about logistics of traveling with a large costume. She talked a little about her friend Tia, who was a Swashbuckling Poison Ivy

20160213_233034961_iOS

Who did we see in the parking lot as we were leaving? We had a brief conversation with Tia about just talking to Nikki.

Posted in life | Tagged , , | Comments Off on Amazing Arizona Comic Con 2016

Con Job on the Department of Justice!

A hacktivist, who had a compromised email account belonging to a DOJ employee, was poking around the DOJ portal. With the determination to get further in, and getting stopped with a challenge of needing a token code they were stuck…

What would any new person do?
Probably call up support, say they are new, and ask how they can get in.
And that is exactly what went down. The support personnel even gave up their own token code.

Once the hacktivist was logged on, they had access to personal VMs with mapped drives. It’s reported that 200GB was exfiltrated.
hacker-shows-proof-of-doj-hack-100643742-large.idge

Yesterday, the hacktivist dropped information on 20,000 FBI employees on Cryptobin
dotgovs

When Motherboard was trying to vet the data, calling the Homeland Security’s National Operations Center; the reporter’s call was the first NOC had heard about the leak. This negative event shows that we aren’t doing the basic security fundamentals! The least amount of effort necessary to keep data secure!

Posted in Security Blog | Tagged , , , , , , , , , , , , | Comments Off on Con Job on the Department of Justice!

Arizona Renaissance Festival 2016

It was so nice to spend the day with family at our annual trip to the Renaissance Festival.

20160206_175649846_iOS

20160206_175718099_iOS

20160206_183454048_iOS

20160206_183732464_iOS

20160206_185732532_iOS

20160206_185840410_iOS

20160206_192033996_iOS

20160206_192958887_iOS

20160206_195137814_iOS

20160206_201246522_iOS

20160206_201459609_iOS

Posted in Event | Tagged , , , , , , , , | Comments Off on Arizona Renaissance Festival 2016

Video on “What is a Social Engineer?”

Here is a nice primer video I found on social engineering. Yes, it’s basic, but we always start with the basics before we get into the advanced!

Posted in Security Blog | Tagged , , , , | Comments Off on Video on “What is a Social Engineer?”

It’s Tax Season ∴ CyberThieves Are Working Full Time!

With most things going electronic, it’s beneficial to be aware of some of the tricks a con-artist would use to get your W-2 and try to claim your tax refund before you have the chance to.

One popular method is for the crooks to set up a fake employee benefits website that asks for your details, like name, birthdate, and social security number; then send out some phishing emails that look like your W-2 is ready for download.

Another popular method is to set up a fake Tax preparation company cloned website that also asks for your details, but the phishing email that hits your inbox has promises for pretty large tax returns.

But how do these thieves know who to target? They look to social media and start harvesting information. Some social media sites offer pretty detailed search capabilities, such as the ability to list out who lives in Alabama, likes Intuit Turbo Tax, and likes Walmart. (Nothing against Alabamians, it’s just the first State alphabetically). Now a cyberthief can set up a fake Turbo Tax website and a fake Alabama State tax website, send out a fake Alabama State Tax and Turbo Tax phishing email, and since the majority of people who shop at Walmart are usually looking for a great deal, may not have a lot of spending money, will see an email with possible promises for a large refund…

It sounds like a lot of work for cybercriminals, but the work to reward ratio is crazy successful! Plus, know that if it didn’t work, we wouldn’t see it around.

How do we protect ourselves from showing up in those searches? We police our own social media profiles! We tighten up the privacy settings of who can view them.

If it’s too late and you’ve already learned that your identity was stolen, (HINT, someone already cashed out your tax refund), visit https://www.identitytheft.gov/

Here is a cool infographic on what Cybercriminals are shopping for (and what they’re paying)
2016 Cybercrimminal Shopping List

Posted in Security Blog | Tagged , , , , , , , , | Comments Off on It’s Tax Season ∴ CyberThieves Are Working Full Time!

Korea’s Self Driving Uber. The Rise of Automated Vehicles

In Seoul Korea, driverless taxis that emulate an Automated Uber, has already begun live testing. This leaps forward how we are progressing as a society and it’s relationship with vehicle ownership.

Uber has led the change of how we travel; so far Uber has:

  • Taken 40% of profits from NY Taxi services, eliminating 10,000 jobs
  • Hired famous car hackers to harden vehicles against hacks
  • Interested in removing the drivers from their services to create autonomous mobility

General Motors and Lyft have partnered to make self-driving car-sharing vehicles.

Tesla released functionality to enable vehicle autonomy.

It’s where we are headed. Just order your car via mobile device, and hop in and get delivered.

topquadrant

The future is the top right quadrant and where we are headed. Millennials and the prediction of future generations have been caring less and less about driving and buying and insuring cars and it’s starting to make sense to have a shared buying experience since cars sit on average for more than 85% of the total time they are owned. Especially in cities where parking is a huge challenge and not convenient.

Posted in Security Blog | Tagged , , , , , | Comments Off on Korea’s Self Driving Uber. The Rise of Automated Vehicles

Remember the Fappening?

Some time ago, back in 2014, I wrote about the Fappening, when someone hacked a bunch of Apple cloud accounts and stole personal pictures of famous celebrities.

Turns out that some of the victims to this hack was due to a spearphishing attack and not just the iBrute attack as originally thought, the attacker, named Ed Majerczyk, sent the following to potential celebrity victims.

“Your Apple ID was used to login into iCloud from an unrecognized device on Wednesday, August 20th, 2014. Operating System: iOS 5.4 Location: Moscow, Russia (IP=95.108.142.138) If this was you please disregard this message. If this wasn’t you for your protection, we recommend you change your password immediately. In order to make sure it is you changing the password, we have given you a one-time passcode, 0184737, to use when resetting your password at http://applesecurity.serveuser.com/. We apologize for the inconvenience and any concerns about your privacy. Apple Privacy Protection.”

According to the FBI, Ed breached 330 unique iCloud accounts from his home a total of over 600 times in 2014. Once breached, Ed downloaded the entirety of a victim’s iPhone camera roll and uploaded it to the popular 4chan.

Posted in Security Blog | Tagged , , , , , , , | Comments Off on Remember the Fappening?

New Company: KeyMe

The company named KeyMe allows you to scan your key, either via mobile app or at a kiosk, and create a digital copy. It can then ship you a key when you want a copy, or you can have one printed instantly at a kiosk. It also does car keys with transponder chips.

The company stores all this information in the cloud… Which could potentially be safe, but of course this raises eyebrows for all security professionals. Immediate thoughts lead to a successful threat and copies of all members house keys for sale on the dark web, along with copies of all their personal data (address, childrens’ names, etc). Sounds risky, right?

Posted in Security Blog | Tagged , , , , | Comments Off on New Company: KeyMe

Data Privacy Day Video

StaySafeOnline1 posted a new video today

Posted in Security Blog | Tagged , , | Comments Off on Data Privacy Day Video

Privacy is Good for Business – Infographic

77% of Americans feel that it is important for companies to disclose information that is collected about them.

Privacy is Good for Business Infographic

#PrivacyAware

Posted in Security Blog | Tagged , | Comments Off on Privacy is Good for Business – Infographic