Help

My Pictures Online: New System

Click a Topic (Label)

Search This Blog

Showing posts with label Macintosh. Show all posts
Showing posts with label Macintosh. Show all posts

24 March 2017

Apple ID - Hacked

A few days ago, it was reported that a hacker group was claiming that they had obtained millions of Apple's user credentials: both usernames and passwords, apparently.







We are advised to enable _two-factor authentication_ for login to Apple's services (iCloud, etc.).

Oddly, as of Friday morning 24 March 2017, a day or so after the hack was announced (and some allegedly stolen IDs confirmed), Apple's web site seems completely silent on the subject.  It is worth noting that in other places Apple has denied that _it_ was hacked; speculated that the materials came from elsewhere.

Even so, bad enough.  The suggestion is that users engage _two-factor authentication_ (2FA), which means that each time you log into an Apple service, a second device must be used to verify your identity.  

This is not the same as having to involve the second device each time a service is _used_; most of our interactions occur without having to log in again; a login session can persist for days or weeks.  (Consider your email client; it can silently check for mail in the background because it remains logged into the mail server over days or weeks or more.)

Even so, it can seem like a minor additional hassle, because it requires ready access to two modern Apple devices simultaneously.  A code will be sent to the "other" one, which must then be entered into the one being signed in.  I assume that the two must be on the same Apple ID (and that having the spouse's device/s on that ID could be even more problematic than it already is).  (Spouses should have their own Apple IDs, to keep network things from tangling.)


Engaging 2FA
------------


• Modern devices (things that can run the latest Macintosh OS or iOS): <https://support.apple.com/en-us/HT204915>
• Less-modern (vintage; legacy) devices: <https://support.apple.com/en-us/HT204152>

We should all do this.  I will have made the change by the time the ink has dried on this post.


Mark_
24 March 2017

08 November 2011

A Better Skype

Not everybody likes Skype version 5 for Macintosh; many have reverted to a perfectly good previous version that doesn't eat up as much screen real estate as the new one does: Version 2.8. This one is what I am using.

Quit and Trash version 5, then download and install _2.8_. And breathe a sigh of relief.

Mark_
12:39 08 November 2011

07 June 2011

Macintosh "Hardening" (from NSA)

Our National Security Agency (NSA) has some rather tech-y advice for making Macintosh as secure as possible from intrusion or manipulation by outsiders. Some of this is easy, some is obvious, and some is extremely technical and/or not actually reasonable or even possible for ordinary users.

The information is in the form of a downloadable PDF that your browser will either display to you or put wherever it stows its downloads. If display, you can use save to keep it for later reference. Once saved to your local disk, Preview can open and show it to you.

My advice would be to read through it--with the intention of understanding it--today and again tomorrow. Some of it is pretty technical, so pay close attention to the parts that do seem understandable, and don't worry about the rest. Implement anything you are certain you understand, ask me about anything you like, and don't sweat the rest.

Cult of Mac: Introduction to the NSA document
• NSA: Information Assurance > IA Guidance > Security Configuration Guides > Operating Systems > Apple Mac > Apple Mac OS X 10.6 'Snow Leopard' > Hardening Tips for MAC OS X 10.6 Snow Leopard
• Apple document (also linked from that NSA page): Mac OS X Security Configuration (Snow Leopard). There are several useful sections here (amid quite a lot of information that only professionals would either understand or care about). This is PDF that can be viewed in browser or downloaded.

The important message is this: Be careful (vigilant, methodical), but do not sweat this issue. With the single exception of Mac Defender (or whatever its most recent name happens to be) there are no threats out there for us. This one doesn't threaten our computers (our data); it intends to get our credit-card information. If you don't provide that, the worst we know of now that can happen is nuisance. After you have deleted the installed malware (following instructions elsewhere), there is no danger.

At present. That we know of.

Mark_
12:30 07 June 2011

01 June 2011

More on Macintosh Malware

MacRumors has some information about how fast this issue is developing. (Still no reason for panic, however.)
MacRumors

More:

Apple
AppleInsider
The Unofficial Apple Weblog (TUAW)
ZDNet: Malware spreading via Facebook
@ Huffington Post (video)

While on the subject of computer security: Facebook Scams.

I have said this to several friends:

The thing that makes this age seem new & different (not in a good way), is that for more of our lives most of us more or less never came into direct contact with overt criminality. Now, it's inside our very houses, right on our desks, at least once every day. That nice, Christian, Nigerian who has family or client money for which he will pay for help with [whatever], the traveling friend who is stranded in a foreign city after [whatever misfortune], the helpful Facebooker who will give you code so that you can see who is looking at your stuff--these are all criminals [unconvicted = a mere technicality], and it requires rather an act of will not to get the willies when their garbage infests the Inbox. Even when it seems only to involve an attempt at commerce, why do they think you would buy V1@gr@ from someone who isn't respectful of your wishes not to see their spammy come-on? (They respell their products' names to get past anti-spam filters.)

Couple that with attempts to break into our business, government, infrastructure, and defense computers, and one wonders what the next decade will be like. We may find that little by little, our stuff will have been so completely subverted that the only things (utilities, tools, weapons) that work are things that have no moving parts (physical or electronic). The childish and the sociopathic will have broken everything else.

Crud.

Mark_
10:36 01 June 2011

25 May 2011

More MacMalware _Bad News_

I'm pretty disappointed to find that the black-hat hackers and my good & decent friends are still on the same side of the Rapture divide.  Worse, the criminals are getting "better" at their work:

"
New MacGuard malware variant gets slightly easier to install"

In this case, of course, "easy" is a bad thing.

The executive summary is that the necessity for the user to provide the system password has been removed; this means one fewer stopping points. Note that this is still not as bad as some of the worst stuff on Windows; one must still run the installer (or permit it to be run automatically by the browser that downloaded it--un-check that setting!) AND one must click at least one of the installer's buttons to complete the installation.

The notification about this new form of Mac Defender, now called "MacGuard" came from a security company that sells anti-malware software for Macintosh. I am not recommending that anyone purchase that product.

As before, I am recommending that we pay attention to what's happening on-screen (operating computers on auto or on insufficient sleep is not good), and then not worry too much. More information is @ LifeHacker.

(I am saving my own rapture for the next iPod iteration. I expect that rapture will not disappoint. )

Mark_

14:02 25 May 2011

21 May 2011

Gang targets users with Mac Defender

Recent attacks ("exploits") against Macintosh are still being discussed. The headline of this Guardian newspaper online article caught my eye.

Some of the comments below the article are interesting, too (although not everything said is helpful).

The advice to disable automatic file opening (i.e., of downloaded picture, program, or other such files) is probably useful. After years of not bothering, I have just done that on my machine. (Exchanging one minor nuisance for another.) Because the actual risk is fairly low, I may change back if having it off is too annoying.

Also, consider enabling _block pop-up windows_ in the Safari menu. Occasionally a legitimate web site may want to open a pop-up, but you'll be prompted if needed.

To make clear: For many years, Windows has been attacked by various kinds of nefarious stuff that arrived and acted without the user's knowing it. This is not like that. The Macintosh victim knows that something is up--perhaps not exactly what--and the exploit must be permitted at more than one point before it can do any actual damage.

Sadly, this situation could change; for now practice relaxed vigilance.


Sophos note: I installed it--and immediately uninstalled it (using their provided uninstaller); it is intended to be running at all times, in background, instead of a being run and quit as needed--an approach widely considered to be at least mildly bothersome if not actively bad. Note that once uninstalled it's completely gone--nothing remains on the hard drive; one cannot retain it in reserve just in case. Instead, retain their web site link for access to the latest version should trouble be suspected. Unlike other 'ware being discussed, this one is probably as real as everybody says it is; it's just that many of us don't like their particular approach to protection.

11 May 2011

Macintosh Malware

Dear Macintosh-using friends,


Historically, Macintosh has seemed to be less vulnerable to malware than Windows; this remains true, although perhaps very, very, slightly less true than in the past. (Note that this is about the OS [the operating system], not about the hardware; Windows running on an Apple computer is real Windows, with all that is implied.)


To help us sleep at night, however, we do pay attention to the issue, so that we can understand what's being said to us if the situation were to change, or so we'll know how to react if we were to see anything strange on our own machines.


This Lifehacker article on anti-malware measures contains useful information. I have (but seldom bother using) ClamXav, and I will download (but infrequently use) the other free one mentioned, Sophos. (Both linked from the article.) (Note that the Lifehacker article will remain available indefinitely, even if it should have changed its URL.)

Anti-malware works in two general ways:

1. Watching for and preventing suspect activity.
2. Searching for suspect code. Sometimes removal is an option.

- Number 2 depends upon actual examples, downloaded from the developer. If not recently updated, this system breaks down.

- Number 1 can interfere with legitimate activity; it's why such software--which must be in place and running at all times--can cause problems where none would have occurred otherwise. Keeping it current is fairly important as well. 

(To be clear: The worst of misbehavior by this type of anti-malware can seem virtually indistinguishable from actual malware, and this situation is apparently not so uncommon.)

A couple of other things are going on, too.

Some of the cheesier "entertainment" sites will cause pop-ups that contain warnings about how your machine has been found to be infected, and you should [download, purchase, whatever]. For years, Macintosh users laughed at these for their attempts to look like Windows system alerts. And we dismissed them without a thought.

Now, however, there is a new push by a company "offering" Macintosh anti-malware: MacKeeper. (The web site seems safe.) It uses somewhat similar scare tactics; several of our friends have reported alerts popping up while browsing the Web; I just saw it a couple of days ago.

This appears to be fairly legitimate software that has a positive review by one (and perhaps only one) accepted source. However, look down that review page for reader comments. (Not so good.) For two reasons, then, one might have to be desperate in the extreme to consider paying for this--especially considering that at least some of what it offers is out there without charge. (Ref. the Lifehacker piece.)

This is what I think I understand about what happens: 

• The user is prompted to download an installer, which does require your permission to complete. 
• The actual software will [appear to] scan the disk
• It claims to have found problems.
• It requests a credit-card number. 
• After a working CC# has been supplied it will [do whatever] and report the disk clean. There is question about whether what it reports having found was ever real.

Dealing with the the MacKeeper alert: 

This could change, but at present it seems to open its own browser window _and_ to pop up what looks like a system alert. It does seems perfectly safe to dismiss these and not look back. It also seems safe to download--and even to launch--the installer, so long as it is not permitted to perform the installation. (Delete the installer from the Downloads folder, or from wherever you are having downloads sent.)

Deleting the installed software itself:

May be more problematic. 
• Quit, Trash, and Empty the software (probably in /Applications). (_Empty Trash_ may fail.)
• Open System Preferences > Accounts > Login Items. (These are applications and background processes that will be launched every time Macintosh starts. Some is esoteric and shouldn't be touched, and some is safe to remove/add as you desire. It's nice to have Mail, iChat, and Skype available immediately, for example. If you access your mail in Safari, put that on the list. 

I cannot check because I don't have access to an installation of MacKeeper, but if something of it is in the Login Items list, remove it: Make a note of its name, click it once, and click the _minus_ beneath the list. This won't actually _stop_ that process; it only tells it not to run automatically at startup.

• Stop that background process--two methods: 

- Use the Macintosh utility _Activity Watcher_ to locate and kill the process (may be in either /Utilities or /Applications; this is powerful magic). 
- Merely restart.

If _empty trash_ had failed before because something was "in use", it should proceed normally now. If it doesn't, more _Login Items_ is needed. Perhaps MacKeep sets _two_ pieces there.

• The last step would be to use Spotlight to search your hard drive for files that contain "mackeeper" in their filenames. If you find anything obvious, Trash it. If it's not so obvious, it may be best (and safer) to leave it.

Looking around on the Web just now, I found many complaints, quite a bit of suspicion, and oddly many "testimonials" insisting that this software is not a scam--it's great protection, and _download here_. 

It walks and quacks like Marketing, and it smells like something that has spent some time standing next to a scam, so I'm staying away.

This is all based upon friends' reports, the online reports of disgruntled "users", and other materials from the Web. Any outright errors come from those sources; the simplifications, omissions, and caution are all mine.

The Google machine can help, but call me if you like.

Mark_
11:55 11 May 2011