Showing posts with label antivirus. Show all posts
Showing posts with label antivirus. Show all posts

Saturday, August 31, 2019

Sleeping with the Enema

A large number of android antiviruses are full of holes.


Hey, how bout those cellular carriers who don't throttle video speed except when necessary?  Oops.

I hate like hell to enable this, so consider it a warning in case you want to. 
10 Best Free VPN Chrome extensions.
Why not?
Chrome is Google. Isn't that enough? This browser phones home.
READ the VPN companies' privacy policies and logging disclosures. Some of them are beyond bad. The performance isn't always that good. If it's free, how do they make money?  
Opera has a built-in VPN, but the browser is Chinese. They don't have a great privacy record.




Dear lefty

  • What would you do if I sang out of tune?

a. get you a huge record contract
b. You'd be the singer in my band, and we'd go to the next song
c. stand up and walk out on you



As is pointed out to me frequently, freedom of speech is not absolute.
---> Chicago man arrested for threatening to commit massacre at abortion clinic.  I'm pro-life and I'll kill you to prove it.



  • Pro Tip: Prostrate is laying on your back. Prostate is up your butt. You should avoid mixing them up. Trust me.


ThermionicEmissions is kicking off a new feature today.
It's called "I'd Rather".

No thanks, I'd rather wear a MAGA hat to the next Democratic debates.

If you have any ideas, comments, complaints, whining, praise, or offers of chocolate, use the Comment button. If you have no comment, use the Comment button.

Don't forget to tell your friends, or people you don't like, to come by and read the blog. Google informed me that we had one visitor yesterday. I want to keep this streak going. If we hit over 20 members, I'll make the blog free.



  • Why is Dwayne pronounced du-WAYNE?
  • Who taught the South that "Do whut?" is an acceptable substitution for "Could you repeat that, please?"



Twitter is under fire for thousands of ads attempting to influence voting.
In other news, people read ads?




  • Giving back: I love stories about animals assisting and saving people. We had a small chance to give back when over 100 humans volunteered to help a few stranded whales get back to sea.




In the background as I type is a drawn out debate on how we watch tv and movies, mostly about using cell phones. One lady said she doesn't like it because it ruins the 'viewing experience.' I try to avoid personal insults as arguments so I won't say 'blithering idiot'. Ok, fine, lady, but who cares what you think? People can watch however they want. They can choose to ignore the entire show and look at pr0n on their phones. So long as they're not bothering anybody, what does it matter? At the movies, however, these people require a serious learning experience.




Dyatlov Pass

A group of hikers went exploring the tundra in the Urals and wasn't heard from.
A few weeks later, a search party found their bodies. They were in really bad shape.. some huddled together, some half naked, some half a mile away, all fleeing something.

The tent was shredded. Examination showed knife cuts. The cuts were made from the inside of the tent. A scrap of paper left there said 'the Snowman exists.'

Autopsies were performed. The medical examiner said no human could have produced the damage that was inflicted upon the bodies. One was missing its tongue.  One student, Yuri Yudin, headed home before the incident. He recently passed away, but identified one of the belongings as being from the military or KGB, indicating someone made it to the scene before the rescue party. Not included were claims of huge footprints.

In short order, the Russian government shut the investigation down. It's been a mystery for 50 years.

Some say an animal. Some say aliens. Cattle mutilations showed tongues removed. Some blame an avalanche. Some indigenous folk who were alive at that time said 'Menk,' meaning Yeti/Sasquatch. Footprint casts from the area are huge. The Russian government put together a group to bring back a Yeti, disbanded in 1959, right before the hikers left. Everything else is classified. Links are to Wikipedia, Dyatlov Pass, and the An American Nationalist blog, with its own theory.

These are the facts as I know them. Draw your own conclusions.




SJW Streaks

Tourette's charity wants apology over award-winning joke.
Make sure to choose at least one topic to be offended by..
I used to perform with a comic who had a stutter and built his act around it. Time went by and he cured himself. Unfortunately, he had no more act.

[Twitter]
"....robots can be trans"









Monday, April 20, 2015

Be Very Quiet: Advertisers and the NSA Are Watching You

We here at Thermionic Emissions are very keen on privacy, or what little we can rescue of it. Allow me to share some ways to keep yourself safe(r) and less visible in these weird times. Follow most of them and you'll get the Thermionic Emissions Honorary Tinfoil Hat<tm>. Follow all of them and you won't be able to surf or see your email.

Here are the overwhelming, important items for any operating system and program: Use up to date software, patch your software, use a good antivirus. I'm a linux and occasional Windows user, plus android. While you won't find Mac-specific info here, some of this info will apply and most of the programs run on Mac or iDevices.

EMAIL

I hate to sound like a cave dweller but I long for the days of text-only email. No viruses.  Because we have to have formatted text, smilies, blinky lights and animated signatures, we're using HTML mail.

  • You can adjust Outlook or Thunderbird (probably most others) to use plain text or RTF, which is a good first step, although you will miss the graphics and blinkies.  
  • Turn off the preview pane, as this can set off a virus, although Outlook allegedly patched this. Better safe.
  • STOP CLICKING ON LINKS. I don't care if it's allegedly from your BFF - don't click. Ask first.
  • DON'T OPEN ANYTHING you don't recognize. Better yet, don't open anything. Check first.

SURFING
  • Don't surf - it's dangerous.
  • If you must search, use a safer browser. This means don't use Internet Explorer unless absolutely necessary. 
  • Lock the browser(s) down. Turn off Flash, Javascript and cookies. Only use at highly trusted sites and get an extension that allows them per-site to make things easier for yourself. Surf in Privacy Mode or set the browser to delete everything when you close it.To surf more anonymously (but not totally invisibly), use TOR (The Onion Router). It's a little slower but worth it. Do not torrent or watch video - it will be painful and tax the system. It is composed of a specially configured version of Firefox and some invisible routing components. Read up at the site. It is available for multiple platforms.
  • ALWAYS use HTTPS. This is a secure connection and much more difficult to eavesdrop upon. Don't bother typing it in - go to the EFF site and download their HTTPS Everywhere plugin for your browser. This will automatically search for an HTTPS version of the site and go to it.
  • Do NOT set the browser to remember passwords, unless you want anybody in your house and the authorities to be able to use them too.
  • When you set your browser to FORGET EVERYTHING after you're done, don't forget that History has to go also. This is also handy to hide some of those interesting sites you visit.
I use a bunch of browsers for different circumstances. Since I use linux, the only browser I can't run is Internet Explorer, which is good thing, as I don't like to use it when I use Windows.  Firefox is my main browser, which I keep pretty locked down. Qupzilla is a new, very fast browser that runs on most operating systems. It's not as full-featured as Firefox, which is probably why it's faster. Don't forget Opera, which is still around and even includes email. I use Qupzilla and Opera in various degrees of lockdown or open for different sites. 

Why not Chrome?  I'll tell you why not: it phones home. Isn't enough of your life sent to Google already?  If you absolutely insist on Chrome, use Iron or Chromium; they're both open source, free, the same code minus spying, and use all the same plugins. While we're speaking of Google, don't use it for searching: use Duckduckgo instead. It does not identify you or phone home. You can even make it the default search engine in all of your browsers. I use it exclusively.

One of the main reasons I use Firefox is plugins. Although other browsers have them, FF seems to have the best and most comprehensive plugins.  Here's what I recommend:

  1. Adblock Plus: stops all ads, period. Just make sure to uncheck 'allow unobtrusive ads' if you want to.
  2. Adblock Plus Pop-up Addon: self-explanatory.
  3. Better Privacy: cleans up after you by deleting leftover garbage like tracking cookies.
  4. Cookie Monster: allows you to block, accept or accept all but 3rd party (tracking) cookies on a per-site basis. I block all cookies by default.
  5. Ghostery: blocks trackers and will show you what it blocks as the page loads. Comprehensive.
  6. Noscript: blocks javascript on a per-site basis. I block everything by default.
  7. Self-Destructing Cookies: blows away cookies when you leave the page. Very satisfying blow up notice.
Versions of most of these plugins are available for other browsers. (Hopefully) buried within the plugins' infomation is their privacy policy. This is very important, as it tells you what info is kept (leaked), if any. Be very careful here. Most leak info, some are downright unsafe.  If in doubt - AVOID.  Be aware that number of plugins will affect performance in all browsers. Check all available configuration options to get the best protection.

ON THE ROAD

Sure, all of us want to surf or check email when not home.  ALWAYS use HTTPS, especially on someone else's wireless network.  It's best to just not trust them.  Any of them.  Be paranoid.  Think before you act. Cell phones are especially troublesome, privacywise. Here are a few things I do with a new (android) cell phone:
  • turn OFF all location tracking services (any locators or programs that suggest things based upon your whereabouts or allow you to check in).
  • turn off GPS
  • try to use (android) apps from F-droid. They're free and open-source and don't track you.
  • go to your camera app and DISABLE geo-location, which stops your pictures from having your location on them. Ladies: what happens when you post a picture online with your precise location?
  • be VERY careful what apps you use. Only download from F-droid or Google Play, otherwise you may get malware/adware/viruses. Only use apps with a privacy policy with which you agree.
  • don't use the default browser - it doesn't get updated. Firefox and Dolphin are pretty good. Don't forget to have them delete everything when you're done or there will be a complete record. You can also get TOR (w/Firefox) on your android device to browse more privately. Don't play with Firefox's settings if using TOR or you could compromise your location or identity.
  • Turn OFF your wifi when you leave the house. It's now being used to track and identify you at the mall, where a shopper profile will be built. It can't get your name but when combined with other databases, it will. All you need is two data points to get the third.
  • Do you use voice control? Google and Apple  keep voice samples and, coincidentally, the FBI is very interested in obtaining voice samples around the world.


THE UNPOPULAR STUFF

Being the antisocial network guy, I avoid all the obvious sites and services. Let's face it: Facebook is the front page of the NSA.  Everything on the web is designed to track you, mostly for advertising, also for violation of your Fourth Amendment protections against unwarranted search (it's for the children). Just don't use social media (I told you this was unpopular).  People are putting their schedules and locations and sensitive info online. This is just stupid. Don't be stupid.

Don't use online (CLOUD!) services if you can help it.  I'm speaking of storage, like Dropbox, or reminder or social services. Remember: if you can't touch your data, it's no longer yours. Do you really need a to-do list accessible with your browser?  Use a piece of paper or get an app for your phone (that doesn't leak info or store data on someone else's server). Think about what you're downloading and where it stores your information. If you MUST use online storage, encrypt everything first. Encryption is beyond the scope of this post but there are many programs that will do this for you safely, like Truecrypt (still safe, although no longer updated) or its successor. Or zipped with an incredibly long, complex password (encryption is the first choice).


PASSWORDS

Don't allow any browsers to remember passwords or save information, as I said above. Everyone has so many passwords these days that no one can remember them. The solution is a password program, so you only have to remember one password, then you can get to the rest of the passwords, URLs and logins.  I really like Keepass. It's free, safe and available for most platforms, so you can run it on your phone (which is always with you) as well as your computer or tablet.  As you would expect, I strongly recommend not using online password services. There are other good programs for keeping passwords - check online and read the reviews first.

THE INTERNET OF THINGS

We love our buzzwords.  Just when we've had more than enough CLOUD, we're faced with the Internet of Things (IoT, or Idiots on Tour). These are very slippery, ill-defined terms. CLOUD is anything you're not doing on your home devices. Internet of Things is anything that you can access or control outside of the house. Guess what I'm going to say next..... go ahead.. guess!  Do you seriously want a light bulb that you can check on from work? A baby monitor or camera local people can eavesdrop on or remote people can tap into? A refrigerator that keeps track of what's inside and can order food? There is a search engine that tracks open devices all over the world. Some of yours might be there. There are unsecured video baby monitors listed. Do you want the entire internet to spy on your baby?

The security on these devices is non-existent or really not thought out well.  This speeding car is going to crash and it's not going to be pretty.  It's bad enough that your medical records are out where any two cent hacker can get them - soon your house will get hacked.  If you want that for the sake of monitoring lightbulbs, be my guest.  Same with smart watches, phones and your new car.

MY CAR?

Oh yeah, your car. If it's been made recently, it has a 'black box'. If you have an OnStar-like service, it can be listened to and you will be located with it. Do you have a toll saver so you don't have to pay? That will track you too. In some cases it has been used to locate 'criminals' and it's being considered as a tool to fine speeders (your time between getting the ticket and paying is too short, therefore you've been speeding).


Yeah, kids, it's not pretty out there. Do your best to stay under the radar. If you have questions, please ask or look up the info. You probably won't be able to access ThermionicEmissions from prison.

Wednesday, July 25, 2012

Is There an Antivirus That Doesn't Suck?

Ok, let me qualify my question...  an enterprise antivirus that's easy to administer from a central point, doesn't require ridiculous amounts of rebooting or research, accurately detects machines across the enterprise, can push the install reliably, and doesn't take up every last resource being the end-all of multitasking be-all antivirus/antimalware apps?

My experience would suggest there is not.

When I arrived in the Twilight Zone, no one had any idea about antivirus.  There were a few rogue installs, probably not legitimate.  I got to work making sure every desktop had antivirus.  Back then, you had to update it yourself weekly (this was McAfee).  As usual, the human element screwed everything up and in spite of weekly reminders, people didn't update their clients.

Then we switched to Norton.  Symantec is the biggest nightmare I have ever experienced.  Whether it's antivirus, backup, or whatever else, Symantec will screw it up.  When the client became so bloated it would no longer perform efficiently, we switched.  Or rather, we tried.  Uninstalling NAV/SAV was so convoluted a process that sometimes we could have saved time re-imaging the machine.  Symantec had instructions to accomplish this task, and when I say instructions, I mean twelve different sets of instructions on twelve different web pages, none the same set.  I'll hazard a guess that even Symantec can't uninstall their own products.

We messed around with other products until we found Kaspersky.  The price was right, the client wasn't bloated, and the admin console was full-featured.  Ironically, when you called tech support for Symantec, you got India.  When you called Kaspersky, the Russian company, you got a Boston accent.  At its worst, a Boston accent still trumps an India accent (to our American ears, anyway).

Kaspersky has this great concept by which you can deploy an entire installation to a pc remotely.  Furthermore, it could remove other antiviruses.  Reality, on the other hand, was something entirely different.  It could not remove lint from a desktop.  And the install package blue screened almost every pc to which we deployed it.

Aside from that, it was ok.

Regardless of Bostonian accents, we were unable to get the install package working correctly.  We discovered that you had to deploy the Network Agent first (reboot), then the client (reboot).   After doubling our work, it only blue screened a few pc's, which was livable.

After somehow managing to get Kaspersky deployed across the enterprise, the admin console became unresponsive.  We had to develop tricks to keep it moving, eventually requiring a rebuild (HINT: use external SQL instance).

Mind you, this entire post deals exclusively with administration... I don't have a thing to say about the desktop clients.

Another reason I like Kaspersky is for the mispronunciations.  We've heard `Kaprinsky' and `Kasper Sky'.

Unfortunately the recent price increase started to put Kaspersky out of our reach.   I have been using Trend on our servers in order to have something additional but that also went through the roof.  After shopping around some more, we shook our heads sadly and decided we had no choice but to continue with Kaspersky.

After paying up, I started our wide-installation/update process.  And discovered that the `new' Kaspersky console sucked just as badly as the old one.  It only looked a little different.  The pc discovery function wasn't entirely useful, in that it kept pulling up old entries and failing for various reasons on install.  I also had to locate the new versions of installs, which don't seem to match the consumer varieties.

I've had it.  This is barely one step above going to every desk in the company and installing/upgrading manually.

If you've had positive experiences in the enterprise (and you haven't), please let me know.


As far as viruses, I haven't had one; either on the Windows machine or the linux machines.  I am completely protected on Windows but I surf very safely.