Sunday, 22 December 2019

Powerpoint

This one is interesting in its treatment of Powerpoint for presentations. The primary argument is that it's not Powerpoint's fault.

I never thought of Tufte as primarily an anti-powerpoint person, I'm sure I was reading about and hearing about his theories on information presentation well before I ever saw Powerpoint.



And this is my favourite quote from the article.






Tuesday, 26 November 2019

#ShopSafeNZ

This might be useful: a guide to spotting those fake web shops that make offers that are too good to be true.,

#ShopSafeNZ 
The Domain Name Commission (supported by InternetNZ and .nz) has just launched a campaign... #ShopSafeNZ.

People make purchases at fake webshops more often during the Christmas shopping period, trying to find better deals. With that in mind, the DNC is running a #ShopSafeNZ campaign to raise public awareness of fake web shops, give tips of what people need to look out for and encourage people to report fake .nz webshops to DNC.  

DNC built a dummy fake webshop for the campaign. It looks legit with discounted shoes and sunglasses etc. However, at every 'find out more' or 'buy now' click there is a clear message that the website is a fake. It's full of tips and tricks that people need to be aware of when shopping online. 

The DNC has 10 supporter organisations on board to help and spread the message.    

Take a look at the website: https://fakewebshop.nz/  And here is some more info on the DNC website: https://www.dnc.org.nz/shopsafenz



Shop safe New Zealand

People make purchases at fake webshops more often during the Christmas shopping period, trying to find the best deal. 

To address that, this year we’re launching the inaugural #ShopSafeNZ campaign. We launch on 25 November - one month out from Christmas and will keep campaigning throughout Black Friday, Cyber Monday, Christmas, Boxing Day and the New Year shopping period. 

Dealing with fake webshops is part of The Domain Name Commission’s (DNC) daily routine. We work closely with the InternetNZ research team in order to identify and follow up fake webshops and we are one of the known experts in New Zealand when it comes to using machine learning to identify whether a domain name is more likely to be associated with a fake webshop.

With our #ShopSafeNZ campaign, our focus is on helping everyday New Zealanders spot a fake webshop and to share some simple online security tips to have a safer online shopping experience. 

We’ve built a dummy fake webshop for the campaign, available at fakewebshop.nz. To help spread the message, we have created a gingerbread army who will be delivering safer online shopping tips on our fake webshop. Tips will also feature in our newsletter and on social media. 

Our guide to a safer online-shopping experience, written in partnership with CERT NZ also lists the most common red flags with online stores. 

Sunday, 29 September 2019

Interesting links: NZIZIG Dunedin October 2019

Jim's away for the October meeting, and for the general update he usually hits the high points of things he has noticed, or just checks Sophos. I'm a bit more addicted to lists and dead link farms.

This was my lead, since I'm dealing with a couple right now

Email based attacks are a SysAdmin time sink.

But that is overcome by a notification that NZ Health sites are compromised. No details,  yet, but it's a concern if the Connected Health Network was compromised.

Ministry of Health fronts as cyber attack leaves patient data exposed



Up to 1 million New Zealand patients' data breached in criminal cyber hack

Public message from Tū Ora Compass Health


--------------------------------------------------------------------------------------------------


Jim's at CHCON

 and next week's he's at purplecon


Kawaiicon in Wellington next week I'm going to that one

Wednesday, 10 July 2019

PGP breakdown??

https://www.vice.com/en_us/article/8xzj45/someone-is-spamming-and-breaking-a-core-component-of-pgps-ecosystem

Someone Is Spamming and Breaking a Core Component of PGP’s Ecosystem

A new wave of spamming attacks on a core component of PGP’s ecosystem has highlighted a fundamental weakness in the whole ecosystem.

Image: Craig Warga/Bloomberg via Getty Images
Unknown attackers are spamming a core component of the ecosystem of the well-known encryption software PGP, breaking users' PGP installations and clients. What’s worse, there may be no way to stop them. 

My favourite line from that article:
If you think this is bad, consider this: the SKS software was written in an obscure language by a PhD student for his thesis. And because of that, according to Hansen, “there is literally no one in the keyserver community who feels qualified to do a serious overhaul on the codebase.”

Monday, 8 July 2019

Zoom video vulnerability

I recommend Zoom to people for video conferencing. It has features I like,  and Skype for Business didn't work for me, especially on a Mac. There's a new vulnerability in Zoom that might make me think that my recent dabbling with Teams might go further.

Zoom Zero Day: 4+ Million Webcams & maybe an RCE? Just get them to visit your website!


Yes, there are options to Zoom. Amazon's Chime maybe??  I've tried Jitsi and that didn't seem too bad.  Hard to say.

In the meantime --  as the Zoom article suggests, disable automatic video on connection to a conference, just in case.

And as always when yo have a camera setup:


  • don't point the camera at  confidential information
  • if you do point it at a whiteboard, make sure you wipe it before walking away
  • think about what else a camera might tell an attacker
  • disconnect the camera when you're not using it, if you can
  • cover the camera when you're not using it

Sunday, 23 June 2019

Consequences of phishing attacks

Here's another sobering story about the consequences of clicking on a link and not really knowing what it is.
Update: seems this affects windows users too. Advice is the same!

https://healthitsecurity.com/news/350000-patients-2m-emails-exposed-in-oregon-dhs-phishing-attack

350,000 Patients, 2M Emails Exposed in Oregon DHS Phishing Attack

Nine employees of the Oregon Department of Human Services fell victim to a targeted phishing attack, breaching a trove of personal and medical data in 2 million compromised emails.



Monday, 17 June 2019

Dunedin ISIG


isig logo

I've wanted to get a branch of the NZ Information Security Interest Group (NZISIG) going in Dunedin for a long time -- probably a decade. Hard to get momentum going.

Last year at Kiwicon I  got talking with Jim Cheetham and Chris Burgess. Jim had also been keen for a while, Chris  was in! So we agreed that when we got a bit of space in 2019 we'd get into gear and get ISIG up and running.

Jim's pretty organised and has taken on most of the technical load, even down to doing a logo for the group.

We've run a couple of sessions at Petridish, second Thursday of the month at 6 pm.  We've had some great presentations, it's been fun so far. We expect it to continue to be so.

I presented at the last session on some catph1shing I've been seeing with clients, just as a bit of a "this is a pain, and we need structured responses". The presentation is available here.