Showing posts with label Internet. Show all posts
Showing posts with label Internet. Show all posts

Thursday, October 2, 2014

"Security" software that violates all security principles, being given out by cops

EVERYBODY: Be careful about 'free' software that schools and government agencies are handing out - most are handing it out for free: ComputerCOP.
https://www.eff.org/deeplinks/2014/09/computercop-dangerous-internet-safety-software-hundreds-police-agencies

This stuff, if installed, will literally record every single thing you type (and that means passwords and usernames), and send them UNENCRYPTED across the internet to who-knows where.

There are several agencies in many states that are sending this out. Don't fall for it. If somebody offers this to you for free - take it - then BURN THE DISC. Agencies are paying for it, so make them spend their money on nothing.

The software is supposed to protect kids, but it actually endangers them to exposing activities, login information, etc. And, if I were to be an attacker, I could see all this EXTREMELY EASILY with nothing more than a wi-fi enabled laptop.

Here is a link to a list of agencies in many states that have been known to either buy many copies, or even to distribute them.
https://www.eff.org/pages/whos-giving-out-computercop 

Friday, December 20, 2013

12/20 - Sending An Encrypted Email Easily (and Free!)

So, I figured I'd talk about how to send encrypted emails for free, and using any email program that you're already set up for. There are literally thousands of methods we can do moderately safe encryption - some for files and messages, others for full file systems (entire hard drives). There are also many algorithms and methods that are used to make the encryption harder to break.

This post will focus on messages and small files, so we will use a freely-available algorithm, called PGP. 'PGP' stands for 'Pretty Good Privacy', and is one of the most widely-adopted and freely distributed forms of encryption. In fact, it is so good that it was once considered illegal to send this algorithm overseas because it's considered a type of weapon. (Source: http://www.cypherspace.org/rsa/legal.html)


So the software I'll use for demonstration purposes is Portable PGP (http://ppgp.sourceforge.net/). Like the algorithm, this software is free, and can be downloaded from the site linked here. It's capable of signing files/messages (for integrity - proving the message hasn't been tampered with in transit), or for encrypting them (for confidentiality - so it can't be ready by unintended parties), or doing both at the same time.

Portable PGP
For windows users, there are two ways to install. You can download the USB-stick version, which you just unzip to a USB drive, which you can then use on any Windows computer. Or you can download the full setup version, and install it on a specific computer. Both look exactly the same, and operate the same way. 

The first time you run the application, it will ask you to either generate a new key pair, or import an existing one. This guide assumes this is the first time you've had a key pair. It'll open a new window, and you'll need to enter in some information. I HIGHLY recommend you use the Paranoid ElGamal option, and slide the slider towards the right. It will take a lot longer to create the key pair, but once it's created, it's done. If you like, you can also make a larger Key Size. 
Creating a Key Pair

Once that's done, the next part is allowing others to send you messages. You need to find your PUBLIC key in the lower box, and click the "Export Selected" button (it's the one that looks like a disc). Save it to your computer with an *.asc extension. It's this file you want to hand out (NOT your private key).

Now, you want to upload your public key to a key repository. Probably the best one is the PGP Global Directory: https://keyserver2.pgp.com/vkd/GetWelcomeScreen.event. You'll need to click on Publish your Key, upload the *.asc file, and assign an email address (required). Once it's uploaded, you need to verify your email by clicking on the link you'll receive. This makes the public key searchable by others; they can search by your name (or the name you gave), an/or your email address. Other people can then download your key, and import it into their installation of PGP. Whoever you're communicating with should follow all of the same steps, and upload their public key, which you'll need to search for.

Okay - now each of you has the other's public key, and your own private keys. Now what?

Well, click on the "Encrypt" button on the left, and choose "Encrypt Text" or "Encrypt a file", as desired. In the bottom drop down Target box, choose the PUBLIC key of who you are sending to. If you want to sign the message for integrity, choose YOUR private key in the "Sign" box. This doesn't transfer the key, but they must have already imported your public key already for the signing part to work.

Click on "Encrypt" in the lower right, and enter YOUR key pair's passphrase.

You will get a new window with your encrypted message. This message is what you will send to the recipient. 
Encrypted Message

Your recipient will choose the "Decrypt" option in their program, and paste the encrypted message into the program. They will be prompted for their private key passphrase. But make sure they don't paste in the readable portions (---BEGIN PGP MESSAGE----) and the version number, as well as the end pgp message tag.

Assuming you signed it, and assuming they type in the correct passphrase, they'll see this: 
Signature Verification

That means that the sender "signed" it, and the message hasn't been tampered with in transit. 

Once they click "OK", they'll be presented with the decrypted message:
Decrypted Message

Now, that seems like a lot of work. But after the initial setup, it's not that much. But that setup is everything. 

Sure, there are ways to do this automatically, but mostly that requires enterprise-level resources, or a LOT MORE setup, and usually full control of both machines at some point. This guide was made for the everyday user in mind, who just want to protect their privacy just a little more more.


Oh - and for those who email me, I'd prefer you to do so with my Public Key: I've made it available for download on my personal site: http://cashfamily.clanteam.com/files/rcash_pgp_pub.asc.

Monday, July 1, 2013

The Damage Caused by Clicking a Link

So our recent security awareness exercise has a lot of people thinking about everything they do on the computer. And rightfully so. Nearly 30% of my company’s users who received the email clicked on the link, and were warned that they had opened a “phishing” site. Now, the email was fake, and not harmless. But there will be cases where a real phishing email will be sent.

Let’s explain what “phishing” is. It’s a type of information-gathering technique, designed to trick people into providing valuable information for seemingly (but not) valid reasons. The techniques range from claiming a breach and that you need to change some part of your profile, or your password, or some such. Other cases may ask for seemingly innocuous information, such as your name, email address, or other data. But a basic phishing attack doesn’t need to implant a virus, Trojan or other evil code. It just gathers information and then goes to work.

So let’s take into account a basic link you click on, similar to the one in last month’s exercise. If an email like this was sent to every possible combination of “companyx.com” email addresses, clicking tells the attacker a lot of information. By clicking on the link, you have confirmed that your email address exists. From there, they know your name – after all, an email address of “jack.rock@companyx.com” makes it easier to guess that my name is “Ryan Cash”. So now, the attacker knows my name, and the company for which I work.

Next, it’s a simple matter of taking that information to LinkedIn. Very few people hide much information on LinkedIn, as a lot of professionals use it as a way to be found by recruiters. So that site shows what I do for CompanyX, my previous jobs, possibly my certifications/education, probably a picture, and at least a general idea where I live.

Scared yet? You should be. Now that they know where I live, what I look like and my name, it’s not a bad jump to go to Facebook, since a huge amount of people are on it. The attacker can look at my pictures, and if my privacy settings aren’t very well done (and routinely audited), a lot of personal information can be seen; information like children’s names, pet names, spouse names. And a HUGE amount of people (including many who are reading this article) use these items as bases for passwords, so they can more easily remember them.

Now, if the attacker has any password cracking tools (they are easy to get, and freely so), they can put this information into the tool to start running millions of guesses a second. With a child’s name of five letters, that’s five letters out of 12 that they don’t have to guess – cutting their work almost in half.

Now, we have protections against this type of password guessing scheme, but we can’t rely on those alone. And even with them in place, there are other things they can do with that same information.

So BEFORE you click on a link, or open an attachment, in an email that just seems “weird”, call the helpdesk and ask about it. If an attack is real, then clicking on a link at all is dangerous, even if you close the browser immediately.

Friday, June 7, 2013

Why I’m Afraid For You

Okay, I just got back from my first day at the Ethical Hacker class. First, let me give you a background from where I come from.

See, my very first formal IT class was for Security+. And, like many other industries, the first class you take tends to color everything you do in that field. As an example, my first martial arts school was Taekwondo, so I tend to use more kicking than, say, a karateka. So when we deal with networking, I tend to think more on how to secure them, rather than implement or fix them.

So, I’m already scared of networks and the Internet. Of course, it’s necessary to use in today’s world as an IT technician, but a certain amount of trepidation accompanies what I do at work. Keep that in mind:  a small amount of trepidation.

Today’s class was quick, and spent more on legality of ethical hacking. We spent about 15 minutes of just looking at publicly accessible items, breaking no laws, and not even TOUCHING our target site. With about five minutes, we had:

  • The webmaster’s name
  • His work phone
  • His personal mobile phone
  • His direct employer (hint: he does NOT work directly for the company)
  • How long he’s been in that position
  • What type of server the website is hosted on
  • What types of technologies were used in the website (like javascript, Java, active server pages, etc.)

Okay, it took all of about half an hour to show us this. That’s half an hour WITH explanations and questions. That means all this information could be found within less than five minutes – and the attacker would never even be detectable at this stage by the target. And would not have broken any laws at all within that period.

So keep this in mind when the world starts talking about protecting your GMail with two-factor authentication, or when your IT department requires larger and more complex passwords.

Wednesday, May 8, 2013

PC Cleaning Apps, Scams, and speeding up your PC on your own

So I'm not going to re-invent this post. A recent article on How-to-Geek has explained this concept far better than I could.

Here's the article:
http://www.howtogeek.com/162683/pc-cleaning-apps-are-a-scam-heres-why-and-how-to-speed-up-your-pc/?utm_source=newsletter&utm_medium=email&utm_campaign=080513

So there ya go. Those paid apps are next to worthless, if not outright malicious, and do next to nothing for your computer.  I've used CCleaner for years in my PCs, my clients' PCs, and have had no issues. And CCleaner's registry cleaner includes a backup option (which is on, by default), so you can undo any registry deletions you may perform, just in case the system becomes unstable.

Monday, February 25, 2013

What does the signal strength REALLY mean?

So I take a lot of calls on network issues, specifically about laptops connecting to wireless networks.

The common misconception is that signal strength equals speed. While signal strength is, indeed, a factor, it’s not the only factor nor even a major one. Signal strength is an indicator of one items – strength from your laptop/mobile device/PC/macbook to your wireless router. That’s it. Not to the internet, not to your work website, not to Google, not to ticketmaster.com, nothing.

You see, when you connect to the Internet, you’re not connecting directly to the website. You connect to your router, which connect to your modem, which connects to a backbone line, which connects to another (very high powered) router, which connects to another one, and another one, and then maybe your intended site/server. Each “hop” of this transmission takes time to jump from each step to the next, and then any information coming back takes a similar path to come back

Huh?

That means your computer sends a request to a website or other server, then that server sends back the information you requested (web page, file download, video feed, etc.). So each connection is a two-way street, encompassing at least five different sub-connections, all taking their sweet time.

So what does this have to do with signal strength, JR?

Not much, and that’s the point.

As I said above, signal strength is what people use as an argument for “my internet connection should be blazing fast”. They think that since they have four or five bars, they should have instant connection to anywhere in the world, and that’s simply not true.

It only means you have a strong (not necessarily fast) connection to your router. After that, the signal strength means nothing.

So what does it means if I have very LOW signal strength?

As I mentioned, signal strength CAN impact your speed, but not in the way you want. If you have a poor connection, indicated by a low signal strength, you can get a very low speed, as the network and your laptop have to compensate for data packets missing, etc.

Okay, so signal strength is important, to a degree. How do I improve strength if I have a low signal?

Well, understand that wi-fi, or wireless networking, is still a radio signal. Have you ever driven your car into a long roadway tunnel, and your radio started getting fuzzy, or just outright not playing at all? That’s called EMI, or “Electromagnetic Interference”. In layman’s terms: stuff that gets in the way of your radio signal.

The same thing happens to wi-fi signals. But because the broadcast strength is MUCH lower than a radio station’s, it’s easier to disrupt wi-fi. That means the metal in your walls, the wires running through them, the concrete foundation, nearby electrical appliances (TV, anyone?) can all have an impact on your router’s wireless transmissions.

So keep your wireless router away from appliances, and out of the basement. If you need wireless on more than one floor, there are ways to use TWO wireless routers or access points (APs) to cover more area.

So, what can I do if I have great signal strength, but have very slow internet?

First off, determine if it’s ALL sites that are slow, or just one or two. If the latter, it’s probably something to do with an internet backbone router, or the website’s server. In all of these cases, there’s precious little you can do about it. The items you need to troubleshoot are not in your control, and may not be in the control of the website’s owner. You can call them to see if they have issues, but if they find nothing problematic on their end, chances are you’ll have to wait until the Internet fixes itself (which it does have this ability to do).

If it’s ALL websites that are problematic, then call your ISP (Internet Service Provider). They can check for signal to your building, see if an outage is going on, etc. They can guide you through some troubleshooting, or send a tech out if it’s necessary.

Conclusion

There’s a lot that is affected by wireless signal strength, but it’s not the end-all-be-all of network speed. I’ll cover troubleshooting connection speeds in another post, so stay tuned!

Monday, December 17, 2012

Why all the big hubub about passwords?

1/5/12 - 45,000 Facebook passwords compromised
2/13/12 - Millions of passwords compromised from Microsoft India's site
6/6/12 - Six million passwords were stolen from LinkedIn website, compromising these users.
6/6/12 - 1.5 million passwords were compromised of dating site, eHarmony
11/14/12 - Millions of Skype passwords compromised
11/21/12 - One password stolen, causing the state of South Carolina to "lose" tax details for over 700,000 businesses statewide
5/12/12 - Stolen password allows a compromise of 1.1 Million users' data with Nationwide Insurance
And Experian has apparently had 80+ known security breaches of passwords, causing an ongoing investigation into all three major credit reporting companies.

These are a mere fraction of the ongoing attacks worldwide to online accounts. And these are just a tiny bit of the successful ones. Passwords are big business for the unethical computer geek. 

And the weakest link? YOU.

That's right - the weakest part of any security system is the users, both administrative and end-user alike. Don't take this an an insult; take it as a lesson you need to learn, and implement NOW. You see, there's a special type of computer attack, called "Social Engineering". And the interesting part is that it doesn't actually have to use a computer at all, though it often does, as we'll see later.

The movie-myth version of a hacker (actually properly known as a "cracker") sitting in front of a keyboard, typing furiously for hours to break into a Gibson computer and bring down the company is generally erroneous. But the Hackers movie has two things right: the weak password ("God"), and when Zero Cool/Crash Override calls the security guard and gets the number to the dial-up modem.

Whoops.

Social Engineering is defined on Wikipedia as:
"...the art of manipulating people into performing actions or divulging confidential information. While it is similar to a confidence trick or simple fraud, it is typically trickery or deception for the purpose of information gathering, fraud, or computer system access; in most cases the attacker never comes face-to-face with the victims."

In other words, they trick you into giving up some vital piece of information, often your password, or details to figure it out. Or they get you to reveal private details like your username. They might call you, email you, or text you.

In the movie, Crash Override tricks the guard into giving up a vital piece of information, allowing him to take over the TV network.

Okay, so that's Social Engineering. What about the title of this post (Passwords)?

See, passwords are often the only thing that separates crackers from getting into your account. Once that's gained, it's way too easy. 

So, you need a strong password. But what's considered "strong"? Basically, if any part of the password is found in the dictionary, it's a bad password. But you can't have a random string of characters and expect to remember it (well, most people can't, anyway). So you need a password that's hard to guess - even if the cracker has access to a 25-GPU Cluster that can make 63 billion guesses per second.

That's why it's important to make a STRONG password, not just an "okay" one.

What makes a strong password?

Generally, it's not complexity (though that's still a factor). It's LENGTH. Many systems still require only six character minimum. Some require eight. With today's technology, that's not nearly enough. Aim for TWELVE if you can. Maybe more. While most systems do have a maximum amount of characters, this number is very high (like 45+ characters), so you rarely need to worry about having too much.

The general requirements for complexity are that you need three out of the following four categories:
  • Upper case letters (A-Z)
  • Lower case letters (a-z)
  • Numbers (0-9)
  • Special Characters (@, #, !, &, *, and so on...)
You should have all four of these categories, even if your system doesn't require it. Also, don't make semi-obvious replacements (using @ for "a", as an example). 

What other items should I avoid when making a password?

Well, avoid keyboard patterns. I work as a desktop technician, and there was one point we had to gather every field users' passwords. Since they don't handle highly sensitive data, this wasn't a major issue, but we got to see what types of passwords are being used. Here are some examples:
  • Password4
  • Password9
  • Password99
  • P@ssword1
  • <usersname>1
  • <companysname>1
  • <dogsname>1
  • Poiuytrewq1
  • pl,okmijn
So they get from absurdly simple (and UNBELIEVABLY easy to crack), to relatively easy-to-find information (user name, company's name, pet's name), to...wait...what are those last two? They appear sufficiently random, don't they?

Nope. Look at any US keyboard, and check those keys in the order given. See any patterns emerging? We saw a lot of this, and people think they're being clever. The problem is that crackers are generally more so.

So let's avoid easily-guessable patterns and standard words as password bases, mkay?

Okay, so what can we do to get a strong, but memorable password?

First off, forget the word "password". Try to think in terms of "passphrase". In fact, many Linux systems are already thinking in this capacity.

Instead of a word, try thinking of a nonsense phrase. An example is "Correct horse battery staple". That's from a now-famous strip on XKCD, talking about how what seems to be a complex password might not be. It also shows how to make something nonsensical and somehow easy to remember. Throw in a number or special character, and now it's relatively impossible to crack (I say "relatively", because no password is truly impossible to crack - it just takes a LOT longer). 

So if I choose a nonsense phrase as my password (er...sorry, passphrase), why do I need to change it periodically?

Well, this is a two-part deal. 

First, if a cracker gets access to your account and you don't know, changing your password will immediately cut them off of access. This is generally not a big issue, as most crackers won't sit around silently, allowing you to retain your access. They'll dive in, get their information, cause whatever damage they want, and get out. But the process is still sound.

The second part has to do with how long it takes to crack a password. Remember that XKCD comic? They said it could take 550 years at 1000 guesses per second. But with advanced technology, crackers have significantly reduced that time to months or weeks - perhaps even less.

So if your systems password database is stolen, the encryption takes a while to crack, but not forever. If you change your password after the database is stolen, but before it is cracked, the cracker has just wasted a large amount of his/her time, and gotten nowhere. 

But with that huge 25-GPU machine you mentioned earlier, doesn't that make all this pointless?

Yes...and no. As I mentioned, passwords are often the only line of defense for your account - but they don't have to be. We can enable (on many, but not all, sites) 2-Factor Authentication. But that's a topic for the next post.

Tuesday, December 11, 2012

How To Ask For Help From Techies...

...and nearly any other group of experts on a particularly involved topic.

NOTE: I tried to do a TL;DR version, but with the commentary, it was almost as long as the original article. I STRONGLY suggest you read the entire article linked.
You see, as a computer technician, I get a LOT of questions about computers and how to fix them. Frequently, it's a quick "how do I..." question, asked in passing at work or by friends while I'm out and about. Generally speaking, I'm okay with quick "how do I..." questions, as long as it doesn't take more than a couple of minutes to answer.
But there are always (and frequently so) the users who constantly barrage technicians like myself with issues they have on their personal or work PCs. Unfortunately a LARGE MAJORITY of these issues are the type that just irritate the hell out of me and other technicians.
So today, I bring to you a link for downtime reading. It is long and a bit brash. It's written by a "hacker". No, not one of those malicious little punks who write viruses and break into your systems (those are more accurately called "crackers"). No, he's a hacker, meaning a high-level expert in a variety of systems and computers in general.
So in this article, now about two years old in its latest iteration, he talks to end users about how to ask smart questions to techies. How to elicit better responses (hint: 'better' responses are not always what you'd think), and how to make it more likely to get a response AT ALL.
So, without further ado, the link is here (beware, this is a long, but very useful read):
http://www.catb.org/esr/faqs/smart-questions.html
(Note: reposted here in accordance with author's policy)
I urge everybody to read that - it shows how to make it more likely to get answers from very technical people on websites, and to find your answers for FREE! But bear in mind that it's not all easy work. In fact, it puts a lot of the responsibility on you, the end user. In short, it shows user and technicians alike how to LEARN.
I very much agree with the author's point of view. It is, by and large, how I learned so much about computers. I didn't keep asking question after question after question. No, I did my own research and then asked when I honestly couldn't find the answer. I still hold to that, and even teach my sysadmins a few things that they don't know (because hey - nobody knows EVERYTHING about computers).
Keep in mind that the suggestions in the above article are not just about asking for free help; it’s also a valuable set of lessons for dealing with your company’s IT support, as well. While some of the items don’t translate to in-house IT, a lot of it does (especially the part about Googling for your answers).
It’s not about lazy IT technicians not wanting to do work; it’s about technicians who want you to learn. We want you to learn how to resolve your issues; that way, when you run across the problems you can’t resolve, we’re presented with the challenges that much US learn. That’s why there’s a joke that the #1 tool for IT techs and sysadmins is Google. Here’s a hint: that’s not a joke – it’s the actual truth. In fact, that’s very frequently how many of us learned enough to become professional techs.

Monday, December 10, 2012

Beginner Monday–More Terminology

So there’s a lot of users in the workforce that confuse terminology, and inadvertently say the wrong thing to their IT support. This post is about correcting some of those misperceptions. That way, when you talk with your Tech Support, you can say the right things (hopefully) and get them on the right path. Because if you say server, and you mean wi-fi, you can send your tech support down the wrong path (and thus take a lot longer to fix your issue).

1. Network – This is any setup that allows one computer to talk with another. Any method that allows two computers to interact is a network. There are a lot of types of network, but there are two categories that most users care about: wired (or LAN), and wireless (or WI-FI). More on these terms later.

2. Server – This refers to an actual machine type, called a server. It has a special operating system. There are three versions, Windows Server, Linux Server (which has several sub-versions, called distros), and Unix Server. Some applications are accessed on a server. Some network items are done from servers – such as your account and relevant password, anything done by Citrix, emails, websites, and much more.

3. LAN/Wired network – This is when you plug a network cable into your laptop/desktop/netbook. It uses a special type of cable, the most prolific of which is known as an “ethernet” cable, or RJ-45. It looks like a phone plug, but larger.

4. Wireless/Wi-fi – This is a huge up-and-coming technology. Like anything else in computers, there are several types. But for simplicity’s sake, we’ll leave it in general terms, and just call it “wireless”. There’s been some misconception about wireless – it only refers to networking, nothing else. For some reason, a lot of people think that it refers to wireless power (thus no need for a charging cable), which is absurd.

Wireless networking requires two items: a wireless router or wireless access point, and a wireless-capable device. The device is usually a tablet, cell phone or laptop. The “wireless” is only between these two items. Some confusion is people thinking the router didn’t need to be plugged into the wall. There still need to be power and network cables between the router/AP and the wall; just not between the router/AP and the laptop/device.

The general range of wireless is a couple of hundred feet if you’re really crazy lucky. House walls and lots of power lines and metal construction can interfere with signal. Most of the time is pushing it after 50 feet in real-world conditions.

5. Bluetooth – this is a type of wireless that requires a special mention here. It’s a type of radio signal (similar to your car radio), but with a very short range; about 35 feet. It has to be “paired” with devices, so the bluetooth-capable device has to have a passcode to connect. The most common use of bluetooth technology is between a cell phone and headphones. Though, it can be used between a computer and other devices: printers, speakers, docking stations, keyboards, mice, and even between a computer and a cell phone or another computer.

6. Internet – This is the network of all networks. It is a network of networks. Connecting to anything beyond your own building/house/structure is almost certainly going to the Internet before it gets to the destination. The Internet carries the signal from computer to websites or other buildings/cities/countries.

7. Intranet – This is an internal network, meaning it’s only accessible if you’re connected to the same network as the other device (the internet doesn’t count, as it’s not one network, it’s millions of networks). Some portions of a company’s network can only be asked if you’re on the same network; some websites, email, etc. If your intranet is not available, that doesn’t necessarily mean that your internet is down. The reverse is also the case; just because the internet is down, doesn’t mean your intranet is not working. If both are not working, then it’s a local network issue, or a problem with your PC not connecting.

Wednesday, December 5, 2012

11 Reasons Your IT Guy Might Just Despise You

Originally posted here. Re-posted with permission from author.


Don’t get me wrong.  I like to help folks out – but its the users that don’t really think before they call us that get me.  Somewhat on the heels of “10 things your IT guy wants you to know,” I present to you some pet peeves I’ve experienced personally.

11. You get pissed off and hang up on IT because they asked you to “open a ticket” because they were already busy with something and didn’t want to forget what it was you called about.

10. You keep asking IT “when is the server going to be up,” but instead only delaying the server repair by doing this every 5 minutes because you have a report to get out.  You’re acting like a pop-up ad.  Stop it.

9. You ask IT to train everyone on how to use the calendaring system, but you don’t show up to training because you don’t know how to use the calendaring system; making you by far the worst offender.

8. You can’t find your battery for your laptop and blame IT because they “never gave you one.”

7. You keep submitting tickets to IT asking for “more coffee” or alerting them that “a customer threw up in the lobby.”

6. You submit tickets with information like “Computer not working” or “Internet is broken” with no additional details.  Thanks.

5. You complain about how your “monitor doesn’t look right” and how “IT always messes up your computer” after they came in and completely restored your system because you infected your computer with a virus…this occurring AFTER being explicitly told “NOT to open that attachment” in yesterday’s email.

4. You keep figuring out ways of removing administrative privileges from your computer because you “don’t trust anyone.”

3. You complain your “laptop NEVER works right” as you drop it on IT’s desk from a height of 2 feet, when in fact the wireless switch was turned off.  By you.

2. You call IT to “do you a favor” and figure out how to work your way around the web filter so you can shop for Victoria’s Secret merchandise during work hours.

1. You call IT for an emergency on Christmas because you can’t get your son’s iPod connected to your wireless network.


My commentary:

The above was written by somebody on Faildesk.net by an IT technician. While it is written quite angrily, and not very friendly to end users. However, end users need to take away a few things from this: you should work WITH your IT support, instead of trying to get them to work FOR you. We’re not servants, we’re co-workers. And just like most of you, we’re experts; just not experts in the same fields you are. With that in mind: I’m going to make a slightly-less-angry commentary on each of the above points.

#11 – We ask you to open a ticket for a couple of reasons. First and foremost, so we don’t forget what we’re working on. The idea that “we work on one thing until it’s done” is simply not possible in our field. Computer move fast, and break just as fast. The only way to tackle one problem at a time is to have one technician FOR EACH MACHINE – period. That means if there are 2,500 computers in your company, you would need an IT staff of 2,500 technicians. That’s just not going to happen.  Also, by having a ticketing system, we have an area we can document steps taken so far (to avoid duplicating steps we’d already tried). It also allows us to use your issue, and its resolutions, to solve future issues of the same type.

#10 – Trust me, we KNOW you need your problem solved. You don’t need to keep asking when it will be resolved. If you are asking the helpdesk or technician several times when it will be back up, they have to stop working and answer your call/visit/email, and respond. Sure, that might be two minutes, but if it’s a major system outage, you can be sure you’re not the only one asking. Take a few hundred of these calls, and that can effectively paralyze the resolution. The other alternative? Ignore the requests for updates, and that means there’s a few hundred users out there who complain that “IT is ignoring them”. Don’t be a part of the problem; Report the issue and let us do our job so you can eventually do yours.

#9 – This one’s a little far fetched, but does happen. It’s one of the main reasons I posted Monday’s post about researching your own answers. If we just give people the answers, they rarely learn the answer; they instead learn to rely on asking IT for how to use the computer.

#8 – For some strange reason, IT is blamed for all problems with electronics. I don’t get it. But trust me, we are very unappreciative when users blame us for losing items that were checked out to somebody else. All too often, a laptop will be checked out to a user, who claims they never received a batter/charger/case/mouse when we gave it to them. If that were true, the appropriate time to bring it up is RIGHT AWAY. Before you even walk away from picking it up. Not months later.

#7 – This is a particular annoyance to IT. We are not “The Help Desk”. We are “The IT Helpdesk”. Too many people think we “help” on all issues – period. We’re IT. We’re not electricians, remodelers, suppliers, accountants, HR reps, janitors, or anything else. We are IT professionals – we help with Information Technology concerns – PCs and related equipment. If you’re annoyed that you have to dial yet another phone number to get your issue resolved, you need to remember that it was your fault – YOU called the wrong number, not us. Generally, we’ll try to be helpful and let you know where you need to call, but don’t expect us to do it for you.

#6 – This was addressed with a huge amount of detail on last Monday’s post. In short, when you submit a ticket (either through a web portal, or through email), you need to keep subject concise, relevant, and helpful. They should provide a modicum of information actually relevant to your question, but not so detailed that you can’t get it all in the subject line (details are put in the message body). Also, please be sure that it gives us an idea of what the actual problem is. Subjects of “PC not working” (why isn’t it working? How isn’t it working?) will often get ignored, deleted, or deferred. A subject line of “PC will not power on – power is plugged in” is succinct, helpful, and starts with the fact that you did at least the most rudimentary troubleshooting (if you did more, put it in the message body). See last Monday’s post for way more helpful detail and suggestions.

#5 – This is actually a couple of points. Keep in mind that the idea of “IT always messes up your computer” is more likely the case that we didn’t restore it to exactly the same situation in which we received it. Keep in mind that if we did that, that means we restored it in exactly the same problem-ridden situation in which you gave it to us. We have to return it to a fairly generic state, without all your customizations and pretty desktop and desktop icons arranged in the specific way. We’ll keep what we can, but that’s not always possible.

#5a – The other issue here is when users do what we quite specifically told them NOT to do. I’ve had MANY times where I told a user to stop trying to log in (because her account was continuously being locked out), while I was doing something on the server. If we ask you to not do something, we really do mean it. If you do that action, then you either don’t respect our expertise enough to listen (why are you calling us, then?), or weren’t listening to what we were saying (why are you calling us, then?). If you don’t think what we said is right (we can get it wrong, too!), then either research the issue yourself (see last Monday’s post), or seek out another IT pro to help (like seeking a 2nd opinion from a doctor’s office).

#4 – If you are the type that can’t trust your internal IT support, then don’t try to lock them out. Simply don’t put your private information on your PC. If that means you are so distrustful that you can’t work on your computer at all – then quit your job. Really. That’s company computer hardware, not yours. This is one of the reasons IT departments don’t like giving local admin rights to users.

#3 – This is a case where people blame IT for everything (see #5, above), but people won’t take responsibility for their own actions. They throw their computers around (HUGE NO-NO!!), don’t check for solutions to resolve their own issues, and jump immediately to blaming IT. You must be ready to take responsibility for your own work, your own actions, and the equipment assigned to you.

#2 – Asking for IT to work around policies and safeguards is problematic, at best. You know how that notice says your have no right to privacy? Well, we in IT have even LESS privacy than you. So when we pull back that part of the firewall to let you visit a non-work related site, our bosses know who’s done it. And we risk our jobs to let you risk yours. So don’t ask us to do it. If you’re not sure if it’s against policy, then ask! We’re happy to let you know we can’t fulfill it (though, we won’t like telling you, for the same reason you won’t like to hear the answer). If you feel that the policy should be changed, yelling at IT isn’t the answer. Put a request in through management; it usually takes a very senior-level manager (Think, “C-level”) to change IT policies.

#1 – This is the fastest way to get on an IT pro’s bad side. Think to yourself, would you work for free? Would you come into work on your day off, for no pay, with no warning, and be happy about it? If you would do so, then you are a SUPER RARE PERSON that has an unrealistic view on life. Most doctors don’t like to be called on their home phone by patients asking about this sudden cough they have. Few mechanics will work on your car for free in their own garage. Accountants aren’t likely to work on your taxes at your house at 11:45pm on April 15th, for free.

#1, cont. – For some reason, IT is looked at like we should help everybody with their PC issues. Our society doesn’t look at other professions like this – why do we treat IT like it? We have bills to pay; we have rent to make; we have groceries to buy. We’re not able to pay that in favors. If we do all IT work for free, we have to find another income source, which takes time away from us to work on your issue anyway, and makes it less likely for us to keep up with the latest software/technology.

Wednesday, September 26, 2012

Wednesday–What is VPN, and What is it used for?

So on Monday, I covered the difference between Intranets (there are many thousands) and the Internet (of which there is only one – no Highlander jokes). And, if you read that topic, you’d know I ended it with a parting note about VPN, and how it can connect one from outside to inside.
“Wait, JR. Does that mean you’re about to show me how I can in two places at once…digitally speaking?”
Yes. That’s exactly what I’m going to talk to you about today.
NOTE: Today’s discussion uses the word “company” a lot, even though intranets and VPN connectivity is not solely the purview of businesses. This topic can apply to any private network, be it a charity, or even your home network (which is almost always a type of intranet, whether you meant to or not). The use of the term “company” is to represent all these circumstances for today’s discussion.


VPN – Virtual Private Network

So last Monday’s post alluded to a certain type of privacy – network privacy. People on the outside could not connect, or even SEE the intranet on the inside of a company. So that means an intranet is a network that private for that company or organization. It’s not meant to be accessible to anybody who types in a URL into a web browser.
But what if you can’t be at work? Perhaps you’re snowed in. Perhaps you’re on a working holiday. Perhaps you’re on a business trip to some conference and you have your laptop. Whatever the reason, you need to connect to your company’s intranet while not actually being at your company. How might one connect when you can’t even get to the network you need?
The answer: VPN, or Virtual Private Network
VPN is used to create a virtual (as opposed to actual) private connection. In other words, it simulates actually being connected to your company’s network, even though you aren’t.
Does this mean you’re suddenly transported, a la Star Trek, to your company? No, of course, not. We’re not at that level of technology, yet (dammit). But your computer thinks that you have.
So, you’re now at your home, or your hotel, or poolside at some swanky beach resort….AND you’re connected to your company’s network back in the 7th Circle of Hell (or Cloud 9, if you have a kick-ass job). Thus, you are virtually in two places at once. Neat, huh?


JR, How does this work?

Well, there are several methods with which this is accomplished. I won’t go into all of the overly technical details on it, but the basic concept comes down to one word: tunneling.
What all these methods do is create a sort of tunnel, created by encryption. It’s a two-end tunnel – one end at your laptop, the other end at your company. The “walls” of the tunnel are built and fortified with very strong encryption.


So, Why Couldn't I Just Create A VPN to Anything?

Because, even though it’s virtual, a tunnel still needs to be built – just like any physical structure. And like any structure, one needs tools to build it properly. Otherwise, it will all just fall down – if it ever gets upright in the first place. And, as any carpenter will tell you, there are almost always multiple versions of a tool, with some working better than others, and some are specialized for a specific job.
So we need tools to build our tunnel, and there are many to pick from; from the built-in functionality of Windows (which requires a specific configuration of Windows Server on the company side), to Palo Alto’s Net Connect to Cisco’s VPN Client software (both of which also require complementing server configurations).
We also need encryption keys, usually four: two to encrypt and two to decrypt. Once everything is set up, each side (your laptop and the company’s server) each has a pair. One key encrypts the traffic, and the other decrypts it for use. These keys are created and handled by the software I was mentioning in the previous paragraph. The whole package, then, is the tool bag that creates the tunnel.


So that’s why I can’t see my company’s intranet from home? Because I don’t have the right tool bag?

In essence, yes. Without the right tools, the correct tunnel cannot be built, and you’re out of luck for now. If you’re interested in getting the right tools, see your company’s network administrator or helpdesk – they will know how to set it up for you (though, be warned that you may be restricted to using company laptops only, or have to be granted specific access to use it).


So that’s all I need? A laptop, and the software my company’s IT gave to me?

Uh…not quite. There is one more tool that’s the required: The Internet.
“Wait, what? Didn’t you say that my Intranet and the Internet were two different things?” Yes, but to create a tunnel, you have to have something in which to create it. There is still a signal that needs to be carried; encrypted or not. The Internet carries that signal from your swanky beach resort pool to your company’s server.
Why do I mention this? Only because MANY a helpdesk analyst has been called by somebody who’s home internet is down, but won’t understand why they can’t get access to their intranet from home.
The Internet carries ALL computer signals (and most TV and phone signals) beyond your house; and TO your house. So if there’s no signals coming from or going to your house, then even encrypted/tunneled signals aren’t going, either.


So who do I thank for all this complexity?

Thank your network engineer at your company. Most of you will never meet or even talk to him or her. It’s their job to make sure it works, and it’s there job to make setting all this up on your end as painless as possible.
NOTE: I am not a network engineer. Those guys are paid VERY well, and for good reason. I just know enough of the “basic” concepts to pass it along to end users, like most of you reading this blog. Trust me when I say that network engineers earn every penny they make, to make your job easier (and in some cases, to make it possible).




Questions, comments or feedback?  Comment below or email me at jackrockblc+blog@gmail.com

Monday, September 24, 2012

Monday’s Beginners–Intranet vs. Internet

So there are two buzzwords that people like to throw around. Intranet and Internet. Surprisingly, very few users actually know the difference.

The Internet

So, a little while back, we covered the difference between the Internet and the browser. The first part of that discussion applies here. If you would like a refresher, you can read that article here.

In short, the Internet is a GLOBAL Network of networks. It spans the entire world, and exists in one form or another in pretty much every country in the world. It consists of millions of computers and networks, which can (and probably does) include your company’s network, or at least a part of it.

The Intranet

So this is a part that screws up a lot of people. And to be fair, the difference is rarely explained properly to them. The simplest, most direct (and correct) answer I was able to come up with is this: Intra = within || Inter = between

This means the Internet is a net(work) between networks. This also means an Intranet is a net(work) within the network.

“Wait, JR. What are you talking about?” Good question. Let me explain how it works in terms as it applies to our discussion here today.

See, the Internet is what we use to connect to computers all over the world – an INTRAnet is used specifically within the organization to which you belong (usually your company). It is also only accessible inside your company (as in, you must be in your company’s building, connected to the network, or LAN, to access it). You would not be able to access an intranet if you were, for example, at home – since your home network is not part of your company’s network (even though you work for said company), it’s not going to work out.

Yes, yes. I can hear a lot of people who have a little more tech knowledge say “What about VPN?'”. And they would be right to ask such a question. VPN allows somebody on an outside connection (say, from home) to connect to an intranet. But it’s beyond the scope of this discussion today. For now, we’re discussion just the differences between INTRAnet and INTERnet. Maybe I’ll cover VPN on Wednesday’s topic.

 

Comments?  Questions? Feedback?  Leave a comment below, or email me at jackrockblc+blog@gmail.com.

 

Monday, September 17, 2012

Monday’s Beginners: Address vs. Search bars

So I figured I’d run with a particular bone in many analysts’ shoes: the address bar, and what it really is (and is NOT).  As a helpdesk agent, and as a PC technician, I’ve fielded calls from users who didn’t know the difference between the Address Bar, and the Search Bar.

You see, when we ask somebody to type an address into the Address Bar, and you type it into the Search Bar, it causes different reactions on your computer.  This is especially problematic when typing such things into a company-owned computer instead of your home PC (the reason for that is the subject of next week’s post).

Here’s a screenshot showing the difference on Google’s page.

search vs address bar

And MSN’s home page (the default home page of Internet Explorer):

search vs address bar 2


In the Address Bar, one can type the search terms you want (i.e., what you want to search for), OR, you can type in the URL or web address.  A URL starts with “http”, and has dots and frequently slashes in it.  A good example is “http://www.google.com”.  Later browsers sometimes leave out the “http://” portion, but it is assumed.  It’s there, but the browser doesn’t show you, for simplicity’s sake.

In the Search Bar, you should only type in terms you want to search for.  You can phrase it like an actual question:

“What is the omnibar in Google Chrome?”

or, you can simply type in a few key words.  Remember here that the more you type, the more specific your results will be, but the more likely that a page you need will not show up in the listings.  So more is not better, here.

However, if you type only one word, you may have too many results, making it difficult to find a good page.


Here’s the main tip to take away from this: Don’t type the web address (URL) into the search bar.  Yes, it may get you eventually to where your going, but it takes a lot longer, and sometimes counterproductive (which we’ll cover next week).

Remember that a URL is an address.  Just like the address on your house.  So typing a URL into the Search Bar is like writing down the address on a piece of paper, driving over to the local post office, and asking them what address this address is at.  See what you did there?  You asked what address that address is at….kinda redundant, isn’t it?  And once you bring intranets into the picture, that may turn up a negative result.

So URLs (web addresses) into the Address bar, and search terms into either the Address Bar or the Search Bar.


Questions, comments or feedback?  Comment below or email me at jackrockblc+blog@gmail.com

Monday, September 10, 2012

Monday Beginners: What is a Browser?

Many people confuse “internet” and “browser”.  In fact, many business users of computers seem to not know the term, “browser”.  As a helpdesk analyst, I would frequently ask users to open their browser, and they’d have no idea what I was talking about.  Once I finally explained it to them, they almost invariably respond with “Oh, you mean open the ‘Internet’!”.

No.  I said browser, and I meant browser.  Today’s post is dedicated to answering that distinction.


The Internet

The Internet is a collective term for all things online, across the world.  Wikipedia defines it as follows:

The Internet is a global system of interconnected computer networks that use the standard Internet protocol suite <snip> It is a network of networks that consists of millions of private, public, academic, business, and government networks, of local to global scope <snip>. The Internet carries an extensive range of information resources and services, such as the inter-linked hypertext documents of the World Wide Web (WWW) and the infrastructure to support email.

(I’ve snipped a couple of points because those parts don’t contribute to this discussion)

So, let’s take the above cited paragraph, and make a few key notes:

  • It is a global system, meaning it’s not just your home network, and it’s not your company’s network.
  • It uses the Internet Protocol (or, IP) suite – this is the system it uses as a sort of “address” for computers and networks.  It’s like a street address for your computer and/or network.
  • It is an extensive range of information resources and services – it is NOT just email, or just Google, or just a place to download illegal music and movies.  It is NOT the World Wide Web.  It is ALL of these, and much, much more.

The Internet uses a variety of methods, but in short, it is  what was noted above; a network of networks.  Your computer and router and/or modem at home is a network, connected to the Internet.  Your company’s system is probably a network.  All of these are part of the Internet.  The Internet is everything “online” that goes beyond the building in which you’re sitting/working.


The Browser

So, then, what is a browser?

A browser is a program, a tool that users and technicians alike use to view the World Wide Web (www) and Intranets alike (more on the difference between intranets and the Internet in a later post).  The browser itself is not the Internet, but it is how a person views the Internet.

If a person were to look at a web page in its raw form, it would be mostly unintelligible to all except the geekiest of geeks:

1:     
2:  <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "
http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">  
3:  <html lang="en" dir="ltr" class="client-nojs" xmlns="
http://www.w3.org/1999/xhtml">  
4:  <head>  
5:  <title>Internet - Wikipedia, the free encyclopedia</title>  
6:  <meta http-equiv="Content-Type" content="text/html; charset=UTF-8" />  
7:  <meta http-equiv="Content-Style-Type" content="text/css" />  
8:  <meta name="generator" content="MediaWiki 1.20wmf10" />  
9:  <link rel="apple-touch-icon" href="//en.wikipedia.org/apple-touch-icon.png" /> 
10:  <link rel="shortcut icon" href="/favicon.ico" /> 
11:  <link rel="search" type="application/opensearchdescription+xml" href="/w/opensearch_desc.php" title="Wikipedia (en)" /> 
12:  <link rel="EditURI" type="application/rsd+xml" href="//en.wikipedia.org/w/api.php?action=rsd" /> 
13:  <link rel="copyright" href="//creativecommons.org/licenses/by-sa/3.0/" /> 
14:  <link rel="alternate" type="application/atom+xml" title="Wikipedia Atom feed" href="/w/index.php?title=Special:RecentChanges&amp;feed=atom" />

All that code, and NONE of that actually shows anything on the screen yet (that’s only about 5% of the Wikipedia page I quoted above).  But it is code for your browser to process and do different things with it.  Some of that code allows it to show up better when searching for the page.  Some changes how the page looks on the screen.  Some simply point to other parts that process portions of the website.

What to take away from this, however, when a technician or analyst asks you to open the browser, they don’t necessarily mean “the Internet”.  They mean the browser.  The reasons for the distinction vary, but it is important for an end user to understand and apply the difference.


Types of Browsers In Use Today

Internet Explorer

This is by far the most common browser used today.  Why?  Because it come standard on all forms of Windows since 1995.  And most people don’t change their browser if they’ve already got one that works.

Internet Explorer’s (IE) icon looks like this: 

Safari

This is the most common browser in use by Mac users.  Like Internet Explorer in use for Windows computers, Safari comes standard with Macs.

Safari’s icon looks like this:

Mozilla Firefox

Also just referred to as “Firefox”, this is probably the 2nd-most used browser in the world today.  It is highly customizable, very effective, and free.  It is also included in many distributions of Linux operating systems. 

Firefox’s icon looks like this:

Opera

A growing browser, this is another free alternative to Internet Explorer and is also available on Linux and Mac computers, as well as Windows.

Opera’s icon looks like this:

 

Google Chrome

My current choice in browsers.  Available for most all major operating systems (Windows, Mac, Linux, and even some mobile platforms).  It is fast, customizable, and like all the others – Free.

Chrome’s icon looks like this:

 


There are hundreds of other browser options in the world today, each can be downloaded from the Internet.  Feel to try them.  So far, no browser worth using has ever cost money to download, so feel free to download, install and try them out!  The only one you can’t uninstall is Internet Explorer (And even that can mostly be removed, but I won’t show you how…yet).

 

If you have any comments or questions, comment on this page, or email me at jakcrockblc+blog@gmail.com.