Monday, October 19, 2009

Malware and Social Engineering

They are getting smarter, so you need to be even smarterer. You are probably used to seeing bogus emails and web pop-ups telling you that your computer is infected and you need to download and install an antivirus program. Conveniently they always have one attached that is perfect for your computer. If you are not already aware - these are all malware - virus infectected files, spyware, trojans, and generally bad stuff.

No anti-spam/virus software company will ever send you a file directly to your email address and ask you to install it. They just don't. Even if you see a message pop up on your screen, the safest course of action is to open the security software you already have (you do have some right?) and manually run updates and scans from there.

What triggered this blog post was an email I received this morning from "Microsoft" essentially accusing me of spreading viral files. It occurred to me that many, many people may be convinced to open the attachment and infect them selves unwittingly just based on the fact that it appeared to have come from Microsoft. Here is the actual message:

Dear Microsoft Customer,

Starting 18/10/2009 the ‘Conficker’ worm began infecting Microsoft customers unusually rapidly. Microsoft has been advised by your Internet provider that your network is infected.

To counteract further spread we advise removing the infection using an antispyware program. We are supplying all effected Windows Users with a free system scan in order to clean any files infected by the virus.

Please install attached file to start the scan. The process takes under a minute and will prevent your files from being compromised. We appreciate your prompt cooperation.

Regards,
Microsoft Windows Agent #2 (Hollis)
Microsoft Windows Computer Safety Division


Of course it is completely bogus. Microsoft does not monitor viral activity, particularly not down to an individual PC level. Even if Microsoft did see a problem, they would distribute a patch through their "update" services. However, all you have to do is to actually read it because people at Microsoft would not have let this go out with grammar and spelling mistakes.

This is typical of the growing trend in social engineering used by malware distributors. There are two common ways to infect computers - send an infected file to someone, or trick them in to infecting themselves. Don't be the later.

Saturday, October 17, 2009

Calgary ... favouritism is okay... really...

The Calgary City council has just awarded a $300,000 re-branding contract ... to a US company. Not only is it a complete waste of taxpayer money to replace a perfectly good logo/brand that is very under utilized, but the award went to a US based company! In what dream scape is City council living?

1) We don't need it. The current branding may be 10 years old, but is still relevant, directed, and speaks to exactly what Calgary is all about.

2) Why send money away? How does it make any sense to send $300,000 to a private company in San Fransisco when there are a plethora of graphic design companies right here in Calgary that would take on this project? Did they completely ignore the adjacent impact of spin-off business this would create? If the money had been spend here in Calgary, many other subcontractors would have benefited as well. What happened to supporting the local economy? What gives them the right to send local tax payer dollars out of the city never mind out of the country? Where is their responsibility to the local taxpayer?

3) Waste, Waste, Waste. This seems to be a theme for Bronco and his gang. The last time a decision had me this incensed was when they spent half a million dollars on office chairs. WTF? There are hundreds of homeless people in this city who will need extra help this winter. There are community programs that need bolstering. There are schools that need new roofs. Seriously - $300,000 for a new sign? Come on!

4) It's irresponsible. They are using money that came from local taxpayers who work for local businesses and support other local businesses. We faithfully pay our taxes to the city with the expectation that they will spend it wisely on programs and services to help the local community. Sending my hard earned money to California, where it will not help any one in Calgary in any way shape or form is just irresponsible. They might as well have set fire to it.

If you haven't noticed yet, I'm pissed - and you should be too. How would city council take it if we just decided not to send them any tax money at all? That is basically what they have done to us here - taken our money and tossed it over the border like it doesn't even matter. I don't know about you but I work pretty hard for my money and I pay a good chunk to city and provincial taxes. It would be nice if our elected officials had enough respect for that money to spend it were it will benefit Calgarians most - right here at home.