Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Wednesday, May 6, 2026

Complicated Solutions

I am currently in the middle of a work project that continues to get more and more complicated and that has me somewhat frustrated. We have a number of groups that we want to onboard to our data platform. Back when I first started my career, that could be as simple as giving someone a user name and password. Thanks to hackers and everyone discovering that data is more valuable than gold, we have had to engineer safeguards to keep our data from falling into the wrong hands.

One of the first barriers we created is locking down the network. We have a system where users of our data platform have to be on our internal network before they can even log in. That is a good start but it is not foolproof. Someone can spoof IP addresses and make it look like they are on our network and so there are several other precautions we have taken to keep bad actors out of our data.

Sony is a large company and sometimes we purchase smaller ones. I am working with a recent acquisition and their network does not meet the company's high standards and so we need them to log into our network. At first I thought it would be as simple as having them log into our virtual private network or VPN. That sounds great except it also opens a number of security vulnerabilities. Instead we need them to log into a virtual desktop interface or VDI. This is the equivalent of logging into a new desktop computer. That allows us to tightly control what software is allowed on it and instantly wipe the computer clean should we discover a security breech. This extra VDI is turning into a major issue for me as I have to support getting all of the new users onboarded and figuring out who to charge for it.

Once I get everything working, I will still have other issues to work through. Using an extra VDI has the potential to slow things down. It also creates a layer of complexity. Imagine downloading a document. While you think it may be on your local machine, it actually resides on the VDI. If you need to get it to your laptop, there is an extra download step. Sometimes it gets confusing and people give up trying to get things to work.

Ultimately today's computing environments require vigilance when it comes to security. The downside is that solutions become more complicated. The upside is your data remains safe and that makes the extra precautions necessary.  

Thursday, January 15, 2026

Updating to iOS 26.2

This morning I pulled my iPhone off the charger and saw that it wanted to update to the latest version of iOS. It is always important to keep your smartphone updated to the latest version of the operating system. This ensures you have up-to-date security fixes and helps prevent hackers from taking over your phone. Unfortunately I have been reluctant to upgrade to iOS 26 but it looks like a necessary evil if I want to keep my phone safe and so I spent part of the day doing the update.

The first problem I have is that my phone only has 64GB of storage. I've managed to fill most of it with photos and videos. I went through the photo/video library and moved a lot onto my desktop Mac where I have significantly more space. Then I had to go into my recently-deleted folder and remove everything in it to free up space on the phone. I went to install the update and removed enough so that the update process could temporarily remove a couple of apps and reinstall them at the end of the update process. That concerned me a bit but I let the update move forward.

The process of going through hundreds of photos and videos took a toll on my battery so I made sure to plug the phone in to keep the battery from getting too low. Then I just waited for the update to complete and focused on work tasks. I got back to the phone and noticed it back in working order but I'm not a fan of the new user interface (UI).

For some reason, the engineers at Apple love the new "glass" look where you can see through elements on your screen. That makes it so the time on my lock screen blended in with the background image so well, telling time is difficult. I immediately needed to fix that. While I always wear a watch, sometimes it is hidden under multiple layers of clothing while I ski. For that case, I just pull my phone out to see the time. Fixing the clock involved long pressing on the lock screen and selecting the "Customize" button on the bottom. Then I selected the time widget (that is the technical term for the part of the screen that shows the current time) where I had the option of changing the color. I tried white but it blended in too much with the screen. After playing with different colors for a bit, I noticed 2 small buttons under the colors. One said "Glass" and the other "Solid."  I switched from glass to solid and that made the time so much easier to read regardless of what color I chose.

There are a few other UI changes I will need to make. While Apple thinks they know what I will like, they are wrong and like to screw things up. Like many of the software developers I have worked with over my career, the ones at Apple suffer from hubris and think they know more than they actually do. Most the time, they leave a way for me set things the way I like. On occasion though they really screw things up which leaves me questioning my loyalty to Apple.

Wednesday, October 1, 2025

Cybersecurity Awareness Month

Among other things, October is Cybersecurity Awareness Month. I received an e-mail this morning alerting me to this fact and I found it timely given my post yesterday about my wife's Instagram account being hacked. The e-mail went on to provide 4 tips to stay safe online. I thought I would share them with you:

  1. Recognize and report phish - While you may not have anyone to report the Phishing e-mail to, hopefully you can recognize suspicious e-mails and not click on any links in them nor respond. Interestingly I had a phishing text message this morning that claimed to be from UPS. I expected them to be delivering my new skis and the text indicated a problem. Fortunately my skis arrived just before the text or I might have been tempted to respond. Instead I deleted the message and reported it as junk.
  2. Use strong and distinct passwords - Since I have been forced to create longer passwords I have embraced long phrases. I then replace characters with numbers and symbols to make them harder to guess. Instead of something simple like "skibum" I now use phrases like "iAmAt0ta!skiBum" where the "o" into total is replaced by the number zero and the "l" is replaced by the exclamation mark. It is easy to remember and tough to guess. For the record, that is not any of my passwords, just an example.
  3. Turn on multi-factor authentication (MFA) - When you have the chance to turn on MFA, do so as it it adds another layer of security. Today I had to log into one of my credit card accounts and the usual MFA code grew from 6 characters to 8. That surprised me but is significantly more difficult to guess than the 2-digit codes I use 95% of the time.
  4. Keep your systems updated - This is important because companies are always learning about security vulnerabilities in their systems and update them frequently to lock out bad actors. If you are using an old version of your phone or computer's operating systems, you could be vulnerable to hacking. Always make sure you have the latest software. Make sure you have automatic software updates set up on your devices to help ensure this.

Staying vigilant about your online security will help save you from potentially bad situations in the future. Unfortunately nobody is immune and the attacks will continue to get more realistic and tough to spot. Paying attention to all online communication is all the more important.

Tuesday, September 30, 2025

A Hacked Instagram Account

I woke up this morning and started the day with my usual routine. Shortly after I got out of bed, my wife received a phone call. I initially thought it to be a work associate but then I discovered her sister called. My wife's Instagram account got hacked and her sister wanted to warn her to update her password. My wife immediately went into her office and changed her Instagram password. My son also sent my wife a text message letting her know her account had been hacked.

Now I will confess that I don't even own an Instagram account so I am not sure how my son and wife's sister knew the account had been hacked. When I talked to my wife she said they both received "Follow" requests and incoherent messages. I assume that meant the hacker tried to contact all of my wife's Instagram connections. If I hacked my wife's account I assure you I would have been much more intelligent in my actions. I probably would have promoted my YouTube channel or something equally beneficial to me.

After changing Instagram credentials my wife logged into her Facebook account and changed her password there. Facebook owns Instagram and the two services are tightly linked and a breach in one account could lead to a breach in the other. Unfortunately my wife's Facebook account initially wouldn't let her change the password. She had to force a security code to be sent her and then she could change it. My guess is that the IP address associated with our Google Fiber account recently updated and it looks to Facebook like my wife is using an unknown computer to access the service. Ultimately my wife updated both Facebook and Instagram login credentials.

Now the question I have is how someone hacked my wife's account in the first place. Unfortunately all I can do is guess. Perhaps they discovered her password that is common with another account. That would be my first guess and underscores the importance of using separate passwords for all of your different logins. Other additional security measures include 2-factor or multi-factor authentication and passphrases that rely on face recognition or fingerprints. Unfortunately we live in a time when passwords may not be enough.

Monday, June 30, 2025

Time For Annual Security Training

As a Sony employee I am required to run through an annual 30-minute training course on computer security. In the past the training has seemed to be the same as previous years. Today I ran through the training again discovering it has been updated and it seemed like a whole new course, which I appreciated.

The course had the usual warnings against clicking on links in e-mails and verifying URL's before going to the sites. This year, they provided some more details that helped understand how different character sets can be different than the regular Latin letters we are used to in English. The example they provided is that a Cyrillic V looks like the letter B. Someone could then create a mischievous website using the Cyrillic V for something like the Better Business Bureau and you wouldn't know you are going to the wrong site. Having a concrete example like that really helped underscore how subtle character substitutions can cause havoc.

A new entry in this year's training highlighted mobile device security. I prefer a full-sized keyboard and so if I can keep my phone in my pocket and use a computer instead, I do. I am not normal though as the average person uses their smartphone 6 hours a day. My usage is down around an hour per day. The training pointed out a number of helpful tips to keep from clicking on malicious links that could open your device to malware and other bad actors. I decided that by doing as much as I can on my computer, I reduce my risk for security issues. Should I get a nefarious text, I now know what to look for.

Finally the training had a section on how artificial intelligence (AI) can be used to create more realistic e-mails. Bad spelling and grammar used to be dead-giveaways of scam e-mails. Now those e-mails can be created to sound exactly like your supervisor or manager. They also warned against voicemails that can sound like the people you work with. That is a sobering thought.

The point of this post is that there are some persistent thieves and crooks trying to get access to your computer, online accounts, and smartphone. It is a good practice to review security best practices to remind you to remain vigilant against those bad actors. If you are not required to run through a 30-minute training session, you might want to find a trusted resource on the Web and do your own training.

Sunday, December 11, 2022

Digital Privacy

This afternoon I checked my personal e-mail and received a message claiming to be from my company. While I work for Sony, my personal e-mail is through a domain that I own and it looks like another company. The message claimed to be from the admin account and said that I had 3 undelivered e-mails because they were SPAM. My e-mail account has a different filtering mechanism and I would never get an e-mail from the "admin". I had a link I could have clicked but I'm sure the results would have been nefarious. This is what is known as a Phishing attack. Paying attention helps ensure I don't inadvertently install a virus or malware on my computer. This has the potential of releasing all sorts of personal information to bad actors that can steal my identity, drain my bank account, and ruin my credit.

Your digital privacy is very important and you should do everything you can to protect it. Being aware of potential phishing attacks is only one step of many. I also limit the information I share with various websites where I have login accounts. I never provide my social security number nor do I provide my birthday. There are many websites that require a birthday simply to verify age. I use the same fictitious date for such occasions and avoid providing my real birthday if I can help it.

Another trick to maintaining your digital privacy is to limit your payment information. There are a lot of websites that want to make purchases as simple as possible and so they offer to store your credit card information. Then you just have to hit the "purchase" button and it automatically bills your credit card. I actually have my primary credit card memorized and re-enter the information every time I make a purchase from infrequent accounts. It only slows me down a few seconds but gives me piece of mind every time I receive an e-mail about websites being hacked and payment information stolen.

One final word of caution is to severely limit who has access to your bank account information. This includes debit cards. Once someone gets into your bank account, it is very difficult to get your money back once it is gone. By using credit cards for all payments, you have a level of protection that ensures you don't lose any money. You just need to notify your credit card company about fraudulent transactions and they will credit your account while they investigate. You may have to provide additional documentation but most credit card companies will catch the invalid purchases before you do.

Unfortunately there are some thieves out there and the ubiquity of the Internet makes it easy for a small number of bad guys to inflict harm on a large number of good ones. Taking your digital privacy seriously will help reduce damages. I just wish there was a sure-fire way to keep yourself 100% secure.  

Monday, February 4, 2013

Another Apple Mistake

I think Steve Jobs would die he wasn't already dead and if he knew what his successors were doing to his company. I used to be a big fan of Apple and their products. That is changing at an alarming rate. This last week was the crowning moment that has me avoiding everything and anything to do with Apple. I even had a pear for breakfast this morning instead of the usual red fruit.

Last week I was in a meeting when a coworker walked in and asked me to try and log into our company's virtual private network or VPN. While other coworkers could accomplish the task on their Window's-based laptops, I couldn't on my Mac. I logged a support ticket with our IT's help desk. They got back to me and said that Apple turned off Java. Our IT department had a workaround that solved the problem but it left me with a few questions.

I did a quick search on the Internet and discovered that the Department of Homeland Security sent out a warning that running Java in your browser could open you up to potential security threats. Apple then decided to turn off Java running in browsers on every Mac computer connected to the Internet. My first question is: How did they do that? A good second question is: If Apple could screw up my computer, doesn't that mean someone else could? If I was an unscrupulous hacker and found out about Apple's little trick, I would be looking for a way to exploit it.

Frankly it scares me knowing that a company can reach into my computer and make modifications without my consent. While I have been happy with Apple in the past, I'm not any more. It is time to start looking for another laptop, tablet, and phone supplier. At least it gives me something to write about.