Showing posts with label social. Show all posts
Showing posts with label social. Show all posts

Tuesday, October 18, 2011

Shiny Objects, Dull Minds....



I hold two beliefs,  one is that technology  will never stop advancing and the second is that human beings will always gravitate toward shiny objects. 
Crows like shiny objects too.  It's been suggested that they take them to attract a mate.  Hmm, maybe that's why all the geeks feel the need to get a new Smartphone every 6 months. 


I watch a lot of technology podcasts where all the Uber geeks and tech pundits get all misty eyed over the latest bit of techno kitsch.  I t never fails.  They anxiously await the latest whatever and when they get it in their hands they fawn over for about 15 minutes;  playing with every button, adjusting every setting and trying out every new feature.   
Then the facade starts to crack.  It could be a change in how a feature works or even the removal of it entirely.  It doesn't really matter, you can always tell by the look on their face.  It goes from a happy kid on Christmas morning to a blank stare.


The end is always the same.  Unless the thing catches fire in their hands there'll be allowances made.  Phrases like, "They'll fix that in an update" or "This is an early production model" 

We're supposed to dismiss the deficiency and focus instead on the promise of this great new thing even if it's to our own detriment.  

Smartphones are a perfect example.  It's not enough for your phone to make calls anymore.  It has to be able to surf the net, update Facebook and entertain you with a game or a movie.  It's almost as if there's some grand plan to cause the world to develop Attention Deficit Disorder.
 I still find it amazing that people went so nuts over the Iphone when it had so many issues like being chained for two years to a horrible data network, high cost, call quality and usability problems.  Still , even if you had a bad experience with the phone it still managed to check off all the items on our shiny object list.


Like the MP3 that's largely replaced the CD ,we tend tolerate a lesser experience  for greater convenience or just the chance to look cool.   There may be a more insidious penalty than that, however.
Technology can be the catalyst for inspiration but it can also be a debilitating crutch .  In his book "The Shallows: What the internet is doing to our brains" Nick Carr suggests that we may in fact be gradually becoming dumber because of our addiction to connectivity.


It's not so far-fetched an idea.  We don't even care if a phone can be relied on to make a call anymore so long as our Netflix download doesn't buffer too much.   Oh yes and we must be sure that Foursquare knows where we had lunch.  I'm sorry but nobody has the right to know that much about my habits even if I didn't notice your 30 page irrevocable EULA. 
I guess it's too bad if your favorite sushi restaurant is next door to an S&M shop.  If Google maps can't pinpoint my house accurately I suppose I should forget about any hopes of public office.  There are people who believe the president of the United States  has a fake birth certificate.  What hope do I have if my favorite  sushi restaurant is suspiciously located?
It seems we'd rather not use our long term memory either.  It's simpler to just Google whatever it was that we're too lazy to remember.  Google's a godsend then; protecting us from having to spend more than 30 seconds on any stray thought.


Any forum discussion on the topic invariably degenerates into a shouting match ending in a flurry of hyperlinks supporting their point of view.  That's sad.  We're so addicted to the internet that we can't even have a debate without using it.  Are we so enamored with our connectivity that we're becoming incapable of independent thought? 
If a Pulitzer prize finalist believes it's possible then I have to believe that there has to be some truth to it.   But then, I found out about it on the Internet.


Tuesday, August 23, 2011

Why malware works

I've just returned from a late night session at one of my clients. 

It all started with an email from a user at the site informing me that another user was having issues with their PC running slowly and not allowing their email client to function.

Most of my client sites are small offices with less than 10 users so reporting issues to me is an informal process.  So while I got the report about the other user I also had a few requests from the user that sent the email.

Turns out the other user's problems were related to a rather nasty piece of malware (TDS4 rootkit) that did all those nasty things that rootkits tend to do. 

It was polymorphic so it evaded the virus scanner...
It denied access to task manager and loaded the CPU to 100% with constant attempts
to download more malware...
And finally it tried to open random nefarious web pages.

I've been dealing with this kind of issue a lot lately but usually it's the XP 2012 Fake AV that fools users into installing the malware then digs itself in, destroys the user profile and in some cases downloads more malware allowing the infected pc to become part of a torrent serving botnet.

I had just cleaned up both the reporting user and the other user's pc 3 weeks before.  They knew what happened and why.  They were given admonition against trusting anything they didn't already use on a regular basis and shown what it was that caused the problem I had to fix.

So I got the obligatory nodding of the head and promise that they'd be more vigilant because after all security is everyone's responsibility right?

Well, I guess I should just accept that it's just my responsibility.  You think I'd learn after almost 20 years...

The sad fact is that users can care less about the damage a malicious trojan or entrenched rootkit can do to their PC.  After all, that's what you're there for and they expect you'll fix it before they're back from lunch.  The next killer app that promises endless coupons or installs a cute dancing cow on their desktop will quickly nullify every attempt to counter such social engineering.  It's not unlike a speeding driver who when caught blames the car for his actions because it goes too fast.

Not the best analogy, I know...

So the battle for social engineering is lost.  It must be because we've been droning on about responsible use of computers for decades now and our advice is still largely ignored or at least quickly forgotten. 

So now we have to take preemptive action.  That usually involves the installation of a layered protection system consisting of not just Anti-Virus but also anti-malware software to save the user from themselves. 

At my client sites I currently use Sophos for Anti-Virus and Malwarebytes for malware protection. I find it a good combination of security software that keep a small footprint and don't fight with each other when doing their jobs.  This part is important.  Avoid bloated packages that get in the way of workflow and perform only marginally.

I'm not afraid to say openly that I find Most Symantec and McAfee products to be absolutely useless when it comes to malware and rootkits.  Worse, if the consumer versions end up in a business setting. They become almost completely ineffective and are sure to cause user complaints as these lumbering giants steal system resources and get in the way of every mouse click needlessly. 

The KISS principle is very relevant here.  Stick with products that do the one thing they do well and don't try to be anything else.  I used to recommend AVAST! until it contracted the Symantec bloat disease and became an ineffective security solution. 

If you find yourself at an infected user's PC searching the Internet for another software package to do what you thought you had already paid for it's a good indicator that it's time for a change.  Sounds obvious but it's surprising how much an IT department will put up with just because they have a history with one vendor.

In some cases a user will figure out how to shut off the security software if they feel it's too intrusive.  Try to avoid that scenario if possible.  Unfortunately if your clients are still using Windows XP and have legacy software then you'll have a hard time keeping them out of the settings since there are still far too many applications that require administrator privileges.  Since an Administrator account trumps all else, any pc with user running as local administrators is at risk.  Expect some type of security issue at some point in this case.

In spite of all your efforts to deploy the perfect security suite, you're bound to get complaints from users that they can't get their favorite site to work anymore. What they don't tell you is that it's the same site that almost destroyed their PC on their last visit. They'll scowl and complain regardless of the evidence or they'll claim the security software interferes with their work. 

Unless their work is collecting coupons or evaluating dancing cow version 2.3.2 I can honestly care less.  I'm not draconian, I just don't want to bankrupt my client fixing the same problem over and over again.  It's boring and hurts your credibility in the long run.

This is where communication comes in.  You have to let your clients (the ones who sign your check) know what's going on and why you're doing it.  Explain to them the implications to their business and stress the costs involved including: lost productivity, lost data and of course the cost of having you waste more time fixing the same problem.

The only way to fight entrenched bad habits is irrefutable evidence that it's costing your client/business money.  Nobody in their right mind is going to argue your logic especially if they sign your checks