Wednesday, March 12, 2014

Computer Security, Big Brother and the Cloud

I suspect I may be biting the hand that feeds me, because in essence, this post will contain some observations about Google, and of course the "blog spot" site this blog is on, is a Google product. This post is also about a lot more.

Some time back I did a blog post here, on routers, router hacking, back door commands, and other interesting things. I was doing some emailing with a friend in Germany and I wanted to hunt that post down for him. Yet for some reason I can't find it. I know I didn't delete it. I have never deleted any of my blog posts, no matter what the topic or results have been. Yet .. .. .. it's gone.  With that said, I'm going to post this information again, with a bit more detail and advice. :)

I've been around the block with computers. 35 (or so) years of building, supporting, and programming them does give me a little insight on how they operate. I myself am certainly not a "hacker" per say. And I don't profess to be a real security "expert". I know enough to know some of the simple things to watch for, and how to go about protecting against them, to the best of my simple abilities.

Back in the summer of 2012, I did a screen shot of a program I use called WallWatcher. This program monitors my router, and reports in real time, all of the incoming and outgoing connections, the protocols used, the remote and local IP addresses involved and port information for all of the packets sent, or attempted to be sent. It also reports attempted connections in both directions.

I was having a terrible time with internet stability, and quite often... just going to Google Dot Com, my system would freeze up. My router would at times, go into an infinite loop of cold starts, which made all forms of communications impossible. Other times, there would be a "hiccup", and some stuff would come back. I realize some of you are going "huh?" so let me explain.

Within the configuration pages of your router (most people have one of those now) are places where you can do things like port forwarding, and allowing certain ports to be open that normally would not be. If you are a gamer, you are probably aware of what I mean. :) When you make a change in one of these configurations and hit the "save" button for it, the router stores those changes and then sends out (whats refereed to as) a "warm start" command. This allows the changes to be applied, usually without affecting any other things you have going on. Kind of like plugging in a USB device with your computer system running.  A cold start, is essentially the same thing as taking the power away from the router. No power, no communications.

Anyway, I checked my WallWatcher program, and took this screen shot of what happened back in June of 2012.


The entries in yellow, are the router reset commands being performed. If you notice that really long entry in the message area, you can see that it's going to some absurdly weird place at google. And immediately, it went into a cold start. I did nothing more than opening a web browser, and went to google. I did no search, entered nothing in the search area, pressed no buttons. .. .. and my router was attacked.  I say "attacked" because doing a remote cold start is something restricted to higher end routers, and should by all definition of security, only be allowed by a top level system administrator that has been authorized to do those functions. My router is not "high end", and sure as hell Google is not authorized for anything of this nature.

I also use another program called PeerBlock. It's great "open source" software, that I use to stop annoying advertising, and other such things. Anyway, over several months, I have built up a list of many IP addresses that I have (painfully) encountered, of many MANY other sites that also send out weird code to cause my router to cold start. They ALL have that same form of really long weird name, and for the most part, those IP's belong to systems that are a part of "the cloud" network.

When clouds first started appearing on the internet many years back, hitting one of them would at times, bring up a pop-up box with legal terms about what a cloud is, what you are allowed to do, etc. One of the things mentioned in that agreement, was that cloud servers by default, are allowed to control ports in your computer, supposedly in order to enforce the rules of the server. And around the same time in technology, newer routers began appearing on the market, replacing older models.

Older routers had a feature where you could enable "remote logging", which allowed the router to report what it was doing, to an internal port on the system. This is the feature that WallWatcher and other log reporting software uses, to display "in english" what is going on. A super powerful thing to have, for those wanting to know whats happening. All of the newer routers have had that feature removed.

Oh sure, you can still get a log report, the manufacturers tell you. But you have to open your router configuration page, go to the report page, and open the report, which appears in a web browser. And it only shows a few things, with the information being 'static', not in real time. In order to get the current information, you have to refresh the webpage. Hell, if you refreshed the page even every 5 seconds, you could easily miss thousands of "hits". So all of the router manufacturers have essentially left you in the dark. On purpose.

Why? Well, with the cloud now being out, they didn't want to cause people any worry about their ports being accessed, and a real time log display could tend to spill the beans cause concern for end users. After all, what you don't know, won't hurt you.

If you think cloud servers are still cute, then open your router log webpage and note the information. Then go to a known cloud server webpage in a new browser window. Go back to your router configurations, change or make up some port setting changes, enable them (you can clear all this later) and save the changes. Go back to your router log file and look at the new entries. I'm betting you will find additional probing, just from sitting on a cloud server. You see, it SAW those changes made, and it was curious what the heck you were doing. Of course, much of this depends on how your router logs work. By the way, even the desktop version of TweetDeck appears to have some minor cloud association with it. I've notice a few minor probes coming from them, when I make my own router changes. ... 2 or 3 tiny queries of some kind. Where as many other sites can send out requests 20 or 30 times.

And for me... I have to say... THIS is MY computer. What I do in the way of router changes is NONE of your business! If your website or cloud server is SO poorly programmed that you "can't take a chance" on what I did, then ... grow up.

As for the "security of the cloud", well... here are my thoughts. Yes, by all means, if one server goes down, the rest of them in "the cloud" can still probably serve your internet request. Some cloud servers network within the same data center, and some network amongst other data servers in other locations, which could be 100's of miles (or more) away. After all, this is the internet. :)

One would tend to suspect that if one of those servers could be hacked (and it happens) ... just think of the huge amount of data... OR monitoring ... that could be accessed or watched over.

There are a lot of people out there, that do a lot of bad things. There is a lot of spying going on. Draw your own conclusions on who may be accessing what, and ask yourselves what about the bigger picture down the road. Will there be back door commands that will eventually allow those "big brother" types to gain access to your system?

On the plus side, all is not lost. There ARE places where you can get great 'open source' firmware to restore and upgrade your router operations. WARNING! If you choose to take this route, then search and read and re-read everything you can about exactly the steps you need to take. If you fail to do this properly, you can "brick" your router. At which point you may have to toss it. Just saying...

I recommend the DD-WRT site for the firmware and TONS of information, including forums and wiki stuff... and for an example, check out this PCWORLD article for some general information.

Monday, March 10, 2014

Do you program in Dot Net or Mono?

I've been kicking the programming can now for 35 some odd years, and I have done so much, in so many different languages, I've forgotten just how many...

So much of what I do, I just take for granted. Experience is a great teacher, of that there is no question. And of course, the tools for programming have come a really long way, especially when it comes to ... dare I say ... being lazy.  The assortment of RAD (rapid application development) applications is just HUGE. I use many different ones of course, for each has their own purpose.

One of the tools I use from time to time, is Microsoft Visual Studio. It works pretty slick, and I can configure things the way I want them, especially when I build a DLL or some other object. And from time to time in the past, I've also done the odd "dot net" platform programming.

Dot Net has issues of course. One of the largest is that when you compile your code down to an EXE level, you can still dis-assemble the program back to the full source code. I know Visual Studio does have stuff in it, that will do some very simple protection, but to get your code completely protected, you need to purchase some rather expensive "options".

Do note, there is no "slight" against what MS includes, but you should be aware there are other options. For a lot less cost.

Many years back, I discovered the EZIRIZ site, and over the years I've followed the dedication that Denis has put into not only wanting to do things right, but to do them for a fair price. He has amassed a huge number of corporate users, including Xerox, Bosch, Corel, and even Microsoft.

If you develop in this environment, and you need a great product with awesome service, and a "more than fair" price, then I suggest you give them a try. They support Windows, multiple web languages, Silverlight, various smart devices, and more.

Friday, February 28, 2014

A little speeding is ok, right?

So David Staples is complaining that he got a photo radar ticket, for ONLY going 10 kilometers per hour over the limit. And he's using his job as an ... what is it.. opinion columnist, sports writer.. whatever... to gather support for being "bullied" by the law, by telling his little tale, complete with pictures of him and the ticket (side note.. could that pic be enlarged to reveal his personal info? Not that I have done that, nor would I waste the time doing it either) combined with doing an online poll, in an attempt to garner support for his cause.

He states something about a cop telling him back in the 90's that "up to 15 over is ok" (paraphrased), and the general appearances of his two stories posted to date, give the impression that this "going 10 over" is something he does all the time. After all, he admits that he has had a few tickets in the mail.

Let's face facts here. Photo radar is nothing more than a cash cow. You can't bring your accuser into court and question them. You can't offer an instant, and possibly reasonable, explanation as to why you were speeding, or why you ran that red light. And there are valid reasons for doing so.

Everyone speeds a little here and there. You almost have to at times, especially in keeping within the "flow of traffic", otherwise you face the wrath of enraged drivers, and (sadly) even the real possibility of some nut case tailgating you or cutting you off to prove a point on how much more superior they are than you. Of course, these things tend to apply on places like freeways and highways than normal city streets.

We must acknowledge that the law is the law. Yet we also understand that the law is supposed to be tempered with justice. It's clearly impossible for anyone to maintain "exactly" the speed limit. Foot fatigue, a little body shift to get comfortable in the seat, that tiny bit of pressure on the gas that lets you creep up and down in speed... especially on hills and valleys... I mean, those are normal and in fact natural. There is also the legal aspect in knowing that vehicle speedometers can and do go out of calibration, especially if you don't have the right sized tires on. Or the electronic sensors in the newer cars go out of "spec".

So generally, the law will usually avoid giving out tickets when the speed is minor. By that, I mean within a 5 kph range. And the courts tend to get a little pissed with cases within that range so for the most part they will generally look the other way when you are up to 7 kph over.

BUT... (and there is always a 'but') it will always depend on conditions and location. If the weather is bad, you can get a ticket for doing the speed limit, because you are not driving to conditions. This does NOT mean when conditions are perfect, you can go over the limit. And what about school zones, on a perfect day? If you think 10 over is ok, you are an asshat. Hell, 5 over in a school zone with kids around, you deserve a ticket and an ass kicking to boot. (no pun intended)

One major part in driving anyway, is to be aware of your surroundings, and paying attention to the roads. Clearly Mr. Staples doesn't do this, otherwise he would have seen the photo radar vehicle parked on the side of the road, where normally no car is parked.

Nuff said.

Friday, February 7, 2014

Fishy Tower Deal

Just when you thought matters could not get any worse, this new deal with Katz and the new office tower adds some major stink factors.

When the last council lead by Mayor Mandel was (cough) negotiating the arena deal, one of the items Mr. Katzlington had on the bargaining table was "and you will move all the city employees into my new office building" (paraphrased).

Naturally, the public went into an uproar and council members quickly "came to the rescue" (coughs) and publically told Katz to take a hike. "Sure showed him" was the concept presented as many on city council proudly thumped their chests.

And now guess who "won" the (coughs) public competition to build a new tower for most of the city employees. Yup, out of about 14 bidders, Katz was chosen.

The City jumps up and down swearing the process was fair, and some independent folks were watching over to make sure of it. And with that, I'd suggest this was all just a marketing ploy. And you have fallen for it.

One can easily speculate that design and "wants and needs" were conveyed to Katz during many of the secret and/or private meetings or phone calls that Mandel had with him. Perhaps the ploy all along was to have this catered to, and the demand as part of the arena deal was to just create a puff of smoke.

I recall various newspaper articles that appeared immediately after the fact the City had in camera (private) meetings about this. Other developers seemed to indicate they never really had a chance anyway.

So if the City is saying that Katz came up with "nine out of 10 points" (for value, I guess) while the next closest was a six out of ten....

There was certainly ample time to carefully craft this "slight of hand", as many call it.

If it smells like a fish...

I'm betting it would have cost taxpayers less, to have the City build our own building...

(Note: References to Katz imply assorted associations with Katz, the Katz Group, WAM, and potential others.)

Monday, February 3, 2014

So you want service, huh

I've been on quite the "vehicle" journey this past winter. Fixed incomes, tight budgets, etc. My little 85 Toyota needed some winter prep done, and I wasn't happy with the condition of the radiator so I put a new one in. Common sense also dictated that it would be wise to change the thermostat as well, so I did all of that.

I seldom go out, but when I did (after the above was done) there were heating issues. (sigh)

The Toyota has a 5MGE engine in it, which is a "straight up" 6 cylinder. Unlike a general engine where you have say, 3 pistons on each side, this engine has all 6, straight up in a straight design. And at times, this design has been known to cause air pockets within the cooling system. Several attempts were made to "move" those potential air pockets out of the engine, the new radiator was checked for flow, the thermostat removed and checked for operations... but the problem only got worse.

To make a long story short, the new OEM thermostat was a bad design, and the spring got caught in the mounting bracket, forcing the thermostat to stay closed. This caused the engine to over heat, which caused the main head gasket to blow.

It was a total "tooth and nail" fight with the local head of Parts Source to prove the thermostat was faulty, however eventually they came up with a replacement head gasket and new antifreeze to replace all that was lost. The only problem is... our garage was "full", so those repairs on the Toyota have to wait for summer weather.

A little "saving grace" was available, as my brother has a 95 Cirrus which I can use, but it also required some repairs. To make that long story short, most of those repairs had been done over the years, and last summer he finally got around to finishing the paint job. The car was then taken in for a full frame alignment (that in itself is another story for another blog post) and then I set about working on that dreaded "check engine light" stuff.

We have several scanners for the new car computer things they have come out with over the years, and while they plugged into the OBD2 scanner port, none of them worked. After a lot of head scratching and internet searching, questioning all sorts of scanner manufacturers and third party computer diagnostic programs, we found that while the connector is an OBD2 type, this specific year, make, model and engine size, was an OBD1 computer. Nothing exists anywhere for diagnosing it, other than the dealer.

Since my brother had dealt with Derrick Dodge in the past, I contacted them through social media, and went into great detail on the issues, what had been found, diagnostic codes, sensor testing, etc. This was passed on to the service manager, who made the arrangements to have the car checked out.

The Cirrus was taken into their drive through bay area. Very impressive I must say. Within a few moments, this younger looking guy came out, scanner tester in hand, and jumped in to plug it in and ran some diagnostics. I brought along our Haynes repair manual, discussed all of the things done, and he spent some time trying to inspect a few things. We then went over the schematics of the system using the Haynes book, and he didn't think some things were right, so he took more time and photo copied some sensor pages from the dealer manual to help us out.

The basics of the tests indicated that the sensors were not getting the 5 volt line it needed from the PCM (power train control module), so we left Derrick Dodge with some really awesome information, and a great experience.

I found out afterwards, this "young looking kid" was really their shop foreman! So a huge kudos goes out to Gary Winters... he obviously knows his stuff. His expertise in explaining both the electronics and the mechanics was a breath of fresh air. Mind you, it also helped a lot that I knew what he was talking about too. I've been working on cars (and many other things) since high school. And I'm not a spring chicken anymore so...

A definite "tip of the hat" has to go to Derrick Dodge Family Center on 62 ave and 104 street.