The Latest

Internet CultureInternet CultureIt's hard to keep up with internet culture, but don't worry: Each week we'll tell you the best of what you need to know.

This week, the internet is all about the possibility of great harm. Maybe it’s a hangover from the “just do whatever, who even cares anymore?” vibe of the past four years, but for whatever reason, all I see are blinking red danger signs, from financial Goliaths being owned by internet Davids, to bad game night guests, to the myriad kinds of trouble you can get into by repeating what you see on TikTok.

This week in internet warnings

There’s never a shortage of “Don’t do the thing you saw on the internet” stories, but this week, the scolding is reaching a fever pitch, so I’ve prepared a list of online things that could hurt you, your children, and Western civilization.

G/O Media may get a commission

This week in high finance: GameStop stonks

It’s rare that young people care about the stock market, but this week, the internet nearly meme’d a billion-dollar stock fund into bankruptcy. Here’s a quick-run down of the situation, (from a guy whose entire understanding of the stock market comes from having seen Trading Places in 1996): Recently, the day-trading dregs at Reddit’s Wallstreetbets forum noticed that a hedge fund was short-selling GameStop’s stock. This might have been a good bet for the fund, given the financial trouble GameStop has been in, but when Redditors noticed, they started buying GameStop stock at the low, low shorted price. This drove the price up. With each tick toward the sky, the hedge fund lost money.

Then big investors noticed and bought into the bubble. With a tweet, Elon sent the share price flying from $147.98 to $230, and further buying saw a jump up to nearly $350 a share, then a drop to “only” $200 per share. It had been trading at around $4 a few months ago, marking an eight thousand percent increase from the lowest to highest point. With the price in the stratosphere, the hedge fund was as pwned as the Dukes at the end of Trading Places, and things will (presumably) be even worse when they are forced to buy back the shares they shorted.

Day-trading apps like Robinhood prevented its users from buying GameStop stock, which politicians from AOC to Ted Cruz agreed was bad. Poorer people made money and richer people lost (for now, anyway), and how it all ends is anyone’s guess—maybe the rules will change for short-selling, maybe Reddit will crash the international economy and send us into a Mad Max-style post-economy hellscape where we’ll buy stocks in guzzolene and metal spikes for shoulder pads.

Celebrities you’ve never heard of: Riyaz Aly

Before the internet, there’s little chance anyone in the U.S. would have heard of Riyaz Aly. The seventeen-year-old lives in India with his family and enjoys lip-syncing to other people’s music and wearing nice clothing and dreams of one day being a Bollywood movie star. He has also amassed nearly 48 million followers on TikTok. That’s about the population of South Korea... all for a random kid in India who lip-syncs.

He’s a charismatic young man, for sure, but the fact that your kids, and me, and now you, know his name must mean something, but I’m not sure what. Modern fame is so damn weird.

Viral video of the week: Game Night Stereotypes

It’s been nearly 38 years since anyone has had a game night that didn’t involve Zoom or Discord, so you can blame nostalgia for pushing “Game Night Stereotypes” to the top of YouTube’s trending chart. The comedy video from Dude Perfect was viewed 11 million times in a couple of days, and it details all the annoying types of people who would come over to play Boggle, if coming over to play Boggle was still a thing. So if you miss the Forever Dice Roller, the Poker Poseur, and “I’m Always Red” guy, this is the video for you. Make sure you stick around to the end of the video for a room-destruction sequence to remember. (By the way: you’re all invited over to my place for Settlers of Catan as soon as you can show some vaccine paperwork. I miss game night.)


from Lifehacker https://ift.tt/2LeeEpa
Photo: NASA Image Library

With everything else going on in 2020, you might have missed the story about the mysterious flying object that dropped into the Earth’s orbit in September 2020. Unsure of exactly what it was, it was referred to as “SO 2020" and considered a “mini-moon”—a term used to describe temporary satellites.

By December, NASA researchers determined that it was actually a piece of human-made space debris: the remains of a 1960s rocket booster used in the American Surveyor moon missions. Though this had been one of the possible explanations of the mini-moon since it was spotted in September, it wasn’t until it came closest to Earth on December 1 that astronomers were able to confirm its identity.

But if you missed the rocket booster’s appearance in December, you’re in luck: it’ll be back for a final farewell victory lap this afternoon. Here’s how to watch it.

How to watch the mini-moon/rocket booster’s final orbit

Today, the mini-moon/1960s space debris will be 140,000 miles from Earth, or 58% of the way between Earth and the moon, according to EarthSky. And while that’s not close enough to be able to see with the naked eye, we do have the chance of catching its final visit, thanks to the Virtual Telescope Project in Rome.

G/O Media may get a commission

Here’s how Italian astrophysicist and astronomer, Gianluca Masi, founder of the Virtual Telescope Project, describes today’s event:

After its extremely close fly-by last Dec., 2020 SO is safely coming very close again, this time to say farewell. As we know, it is the booster of the Surveyor 2 space mission, which was temporarily captured by our planet. Soon, this artificial mini-moon will leave our neighborhood, escaping into on a new orbit around the Sun. We will say it goodbye, live: join us from the comfort of your home!

To watch the mini-moon’s final pass, tune into the Virtual Telescope Project’s live feed here. According to Masi, it will be most visible above the group’s robotic telescopes in central Italy starting at 5 p.m. ET.

What happens to the mini-moon after this?

While the rocket booster will no longer be visible after today, it will slowly drift away, eventually leaving the Earth’s orbit in March 2021. After that, it will begin orbiting the sun. We wish it all the best in its future endeavors.


from Lifehacker https://ift.tt/39C1rQg

macOS: I go to great lengths to avoid advertising around the web unless I really want to support the site or service I’m using. Besides, all of the big companies are probably profiting off my data anyway; do they really need my tiny little impression?

That’s why I love Hijack Your Feed, a fun macOS Safari extension that replaces promoted posts (or ads) in your Twitter feed with giant, colorful items from your Reminders app. Setting it up is simple, but it has a few nuances you’ll want to know in order to make sure it actually works. Mine was fussy the first time until I figured this all out, so hang in there.

To start, download the free Hijack Your Feed app from the Mac App Store. Launch it, and you’ll a prompt that asks you to do two key things:

It’s pretty easy to set both up, so don’t stress about that. You’ll eventually jump into Safari—sorry to Chrome, Edge, or Firefox users, but there’s only a Safari tie-in for Hijack Your Feed—where you’ll need to make sure you enable the extension:

G/O Media may get a commission

Next, when you visit Twitter to start testing out Hijack Your Feed, make sure you’ve given the extension permission to mess with the contents of the site:

Finally, click on the little Hijack Your Feed icon and switch the extension’s single setting to “Hijack Ads” instead of “Hijack Posts.” I never quite saw any hijacking happen with the latter, but the former definitely worked, as you’ll see below:

Yes, that was a little snippet from my Shopping list in Reminders, letting me know that I should go get some drain cleaner for the sink. Only, I did that weeks ago and forgot to take it off my list. One great little trick of Hijack Your Feed is that it lets you actually mark tasks as complete when you finish them (or if you already have). You’re not just getting a reminder; you can actually act on it right then and there.

And, yes, the design of your reminders is giant, animated, and obnoxious. It’s a great way to ensure that you don’t just brush it off again. And it’s a lot better than another ad. 


from Lifehacker https://ift.tt/39yDgSJ
Photo: Andre_MA (Shutterstock)

As more people receive the vaccine, we’re also seeing more of them post photos of their vaccine cards to social media. After all that waiting, it makes sense to celebrate and share the news—but the Better Business Bureau (BBB) is now warning people not to post photos of their vaccine cards online, as it will lead to an increase in counterfeit cards and identity theft.

The cards contain private information, including your full name, birthday, where you got your shot, who gave it to you, and the date of the vaccination, all of which could be used by scammers to create fake vaccine cards. (The warning comes after scammers in the UK were caught selling fake vaccination cards on eBay and TikTok).

Scammers can also use this information to open credit cards in your name. Since they already have your name and your birthdate, all they need is your social security number—which might be floating around on the dark web—and your address, which is usually pretty easy to find online. Also, consider that information like your birth date or middle name are often answers to security questions on bank accounts and other important log-ins.

If you’ve already posted your card to social media, the BBB encourages you to take the picture down. They also suggest these tips for sharing vaccine news safely on social media:

  • Share your vaccine sticker or use a profile frame instead. If you want to post about your vaccine, there are safer ways to do it. You can share a photo of your vaccine sticker or set a frame denoting your vaccination status around your profile picture on Facebook.
  • Review your security settings. Check your security settings on all social media platforms to see what you are sharing and with whom. If you only want friends and family to see your posts, be sure that’s how your privacy settings are configured.
  • Be wary of answering popular social media prompts. Sharing your vaccine photo is just the latest social trend. Think twice before participating in other viral personal posts, such as listing all the cars you’ve owned (including makes/model years), favorite songs, and top 10 TV shows. Some of these “favorite things” are commonly used passwords or security questions.

G/O Media may get a commission

Another tip: If you lose your vaccination card, visit the CDC’s website and subcribe to VaxText, which will text you a reminder when it’s time to get your second dose of the vaccine. (You can also contact your local public health department if you lose your vaccine card).


from Lifehacker https://ift.tt/3oCx1ld
Photo: Basilio Dovgun (Shutterstock)

My 10-year-old has many wonderful qualities. He’s funny, generous, and curious about the world. He does not, however, like to lose a game. And to be fair, that’s not all that unusual. I think, given the choice, most of us would prefer to win any game we play—otherwise, what is the point of keeping score? But it’s something we’ve had to work on over the years in my home, and I’ve learned a few tricks along the way.

Start with cooperative games

The point of keeping score is to figure out who has won the game, but winning really isn’t the point of playing. Kids don’t start playing soccer when they’re six years old because they want to crush their opponent; they play because it’s fun. So before you start challenging them to a Candy Land duel, introduce them to cooperative games.

Preschoolers are a prime age to start playing cooperative games, which don’t pit you against them. Instead, you work together toward a common goal, while still getting all the benefits of practicing things like taking turns, following directions, and honing fine motor skills. A favorite in our home was Feed the Woozle, but other popular cooperative board games include Hoot Owl Hoot, Mermaid Island, and Race to the Treasure.

Teach them to play the long game

Something clicked with me recently when my son and I started playing a round of Skip-Bo and he was already bristling before he’d even finished his first turn. Whereas I know fortunes can swing widely and quickly in that game, he was treating every hand, I realized, as its own miniature game. Four bad hands in a row might as well have been four losses to him. No wonder this was no fun.

G/O Media may get a commission

When I put it to him in those words—“try not to think of every turn as its own game, but as one piece of a much bigger puzzle”—it resonated with him in a way that “I don’t understand why you’re already getting upset; we just started playing” never did.

If it doesn’t resonate quickly with your kids, point out your own misfortunes as you play, so they can see how the game is playing out from both perspectives. You might say, “Oh wow, I was so far ahead of you before, and now you’re right on my tail!” or “I thought I was going to be able to catch you, but I think you’re too far ahead of me now!”

Young kids are often only seeing the game playing out from their perspective, and having you narrate some of your experience (particularly when you’re being a good sport about losing) can help them build empathy for their opponent. The goal is not to make them feel bad about winning, but to remind them that at any given time, if someone is winning, someone else is losing.

Be a gracious loser (and winner) yourself

Once, on a weekend trip with my husband and two good friends to a cabin in northern Arizona, someone accused me of something. The four of us were sitting around the cabin’s dining room table, drinking beers and playing a rousing game of Clue—as adults do—when one of my friends let it drop that he thought I was the most competitive one of our group.

Knowing this to be Patently False, I laid out a detailed argument of precisely how I was not the most competitive of the group (which is not at all a competitive thing to do). Since then, I have had to look deep within myself and admit there is a chance I have a slightly competitive nature, which mostly comes out when I play board games or flip cup (but only because I am very good at both). However, really wanting to win and acting shitty about winning or losing do not have to go hand, and this is a thing you should model for your kids.

Since my son was very young, we have a standing practice that when a game is complete, we shake hands and say, “Good game.” This has been a good way for him to watch me lose with a smile on my face—not necessarily happy to have lost, but happy to have played at all. It’s also a good way to practice and model gracious winning. There is to be no gloating.

Kids will, more than anything else, pick up on our cues for how to react when we lose a hand of Uno or, say, when your football team loses a big game (I’m a Browns fan, so...). If you let it ruin your day, they pick up on the fact that winning is important enough that losing means it should negatively affect your mood. Show them how to let the losses, both big and small, roll off your back as much as possible.

Put it away if you need to

Games are supposed to be fun, so if game night is ending in a mess of tears every time, it might be time to take a little break from gaming—or at least from the one game in particular that seems to frustrate them beyond reason (I’m looking at you, Monopoly Gamer). You can always try again once some time has passed, tensions have eased, and they’re ready to give it another shot.


from Lifehacker https://ift.tt/3pFbVUr

Just when we thought 2020 couldn’t get worse, security firm FireEye broke the news that the compromise of a software solution by IT solutions provider SolarWinds had resulted in security breaches across the public and private sector, at dozens of companies and government agencies, including the U.S. Departments of Commerce, Treasury, Justice, Defense, and the Center for Disease Control.

combat cyber warfare

The National Security Agency, the main body tasked with protecting government assets from hackers, did not detect the breach. FireEye did—after discovering that it, too, had been hacked. Some security experts and U.S. government officials have described it as the worst security incident in the past few years.

This is not the first time that an attack spread spread across many organizations and sectors. Consider the NotPetya ransomware outbreak in 2017: the attackers managed to spread the infection after breaching the servers of Ukrainian software company MeDoc and inserting a malicious payload into its tax processing program, which was used by many of the victims.

The SolarWinds breach was a wake-up call for all those who have not begun to consider the reality that, security-wise, we live in a totally different world. You just need to look at the numbers to see how bad things can get.

According to SolarWinds, as many as 18,000 of its customers have downloaded the trojanized version of the Orion platform that the hackers uploaded to its servers, even though the ultimate targets were the U.S. government and specific companies like FireEye. In the NotPetya outbreak, the primary targets of the attackers were Ukrainian government bodies, but the ransomware also ended up locking hundreds of thousands of computers at other organizations in the span of a few days.

With digitization and internet connectivity spreading to all sectors of life, business, and politics, the meaning of peace and security has changed monumentally. Cyber-battles have come to every home and office, industrial control systems, public transportation, personal vehicles, and every piece of a nation’s physical and digital infrastructure.

The nature and identity of the fighters and battles have changed a lot, too. Today, nation-states hide behind faceless hacker groups that are hard to pinpoint and even harder to link to governments, and their activities blend into those by cybercriminals that are primarily after money.

Unfortunately, in today’s world, where software systems, web services, APIs, and the IoT have created a complex web of interconnected ecosystems, every security incident can have ripple effects and spread across many nodes and geographical locations. Companies like SolarWinds or MeDoc, which are relatively unknown to the general public, can end-up becoming windows to national crises because their services are used by many private and public entities.

The key point is that, in our increasingly connected world, we all have a vested interest in promoting security and making sure every piece of software and hardware is secure. Just think of the various applications you use every day at home and work. Think of the multitude of on-cloud and -premise applications that keep your enterprise online and working. Any one of them failing can lead to a chain reaction of security incidents.

Success is no longer an individual achievement. Even if you develop the most secure software, even if you’re FireEye, you’ll fail if the hardware, software, and services you rely on are insecure.

So, what is the remedy? First, we must acknowledge that we’re all in this together. Then, we must act uniformly to secure personal, enterprise, and government networks. While this might sound easier said than done, there are concrete steps that can help us move toward this goal.

One necessary step would be to promote and augment collaboration in dealing with cybersecurity incidents and threat actors. The past few years have seen some positive developments on this front in the form of threat intelligence sharing, where government agencies and private firms consolidate threat indicators and indicators of compromise (IoC) such as IP addresses, domains, binary signatures, and malware source code. These concerted efforts have helped discover the identity and source of many attacks and reduce the response time. Threat intelligence sharing should be complemented with transparency and responsible disclosure.

At the same time, we need to establish a culture of safeguards at every organization that is either developing or using software (that practically means everyone). The need for secure encryption practices, encrypted storage of data, strong authentication options, and proper security policies are often highlighted after an organization is breached when it’s too late. That needs to change.

While we continue to compete for market share and customers, we should also compete for better security standards. Companies should not be valued only for their growth and revenue, but also for the security of their data and infrastructure.


from Help Net Security https://ift.tt/3j37IaT

In order for organizations to prevent becoming the next victim of a breach due to unauthorized third-party user access, as has happened in prominent recent breaches, a strong security posture built around privileged access management (PAM) and identity governance and administration (IGA) is critical.

Many companies struggle to implement some of the most basic PAM and IAM practices when managing third-party users, such as immediately deprovisioning users and ensuring rules for managing access (such as not sharing accounts and credentials) are being followed.

To select a suitable PAM solution for your business, you need to think about a variety of factors. We’ve talked to several industry professionals to get their insight on the topic.

Leigh Dastey, CTO, My1Login

select PAM solutionPAM is a key component in an organization’s security strategy and protects accounts that, should they be compromised, can inflict the most damage. Here are four considerations when selecting a PAM solution:

Ease of implementation and speed of deployment: There are a litany of examples of technology solutions failing to deliver anticipated benefits because they were not fully implemented, so your chosen PAM solution should easily integrate with the existing technology stack and enable rapid roll-out. SaaS or hybrid PAM solutions can expedite roll-out and time-to-value.

Ease of use: The PAM solution will only deliver ROI if it’s adopted. Difficulty and complexity in use risk the solution being ignored or circumvented. Choose a solution that ensures low friction for privileged users and potentially one that can run in the background.

Ease of integration: The PAM solution should be compatible with all application types, from on-premise Windows desktop to cloud apps. It must integrate and be interoperable with third-party solutions, such as your Access Management and SIEM solution, to maximise your security investments.

Privileged account discovery: The PAM solution should be capable of auto-discovering privileged accounts, ensuring none fly below the radar and present an attack vector.

Ease of implementation, integration, and use, combined with auto-discovery, provide the best opportunity to realise the benefits of your security investment.

David Higgins, technical director, CyberArk

select PAM solutionBefore choosing a PAM solution for their business, the first question a CISO should ask themselves is what it is that they aim to protect? Adopting PAM is as much about mindset and approach as it is about technology.

Thousands of PAM programme engagements with the world’s largest organizations have cemented our view that the best way to protect the business is first to identify critical data and assets, then assess the paths that an attacker might take to compromise them. This sounds obvious but it is not yet the common practise that it should be.

Privileges identities, credentials, secrets and accounts are found throughout IT infrastructure, whether this be on-premises, multi-cloud or a mix thereof. The ones that allow access to your critical data and assets are what the initial focus should be on. Once these are determined, there are a number of essential features that apply:

  • Ease of implementation, ease of use, and ease of integration. The latter is essential. Look for integrations with your existing vendor stack.
  • Cloud readiness is key. You are likely going to be moving applications into the cloud. Their privileged access needs to be secured.
  • Session management and recording.
  • Credential management for humans, applications, servers and machines.
  • Audit and reporting features.
  • Privileged threat alerting.

Ben King, CSO EMEA, Okta

select PAM solutionPAM is a way of governing and controlling users and accounts with elevated access privileges. This is done to protect an organization’s most critical systems and resources, from external and internal threats, by reducing their attack surface.

Like so much organizational change, choosing a PAM solution requires considerable analysis of requirements and definition of why this is important for the organization and what the end goal is.

Three considerations key to the selection process are:

  • Know which requirements fall above and below the line. Most customers only use a very small subset of PAM functionality, so leverage the 80/20 rule. Identify the primary use cases for your organization which will deliver the bulk of the value, and hold off on the rest so you don’t try to do too much. Are the requirements compliance driven? Or use case/value driven? How is success measured?
  • Ensure resources are in place not just for deployment, but ongoing management. Many PAM deployments fail due to complexity and a lack of internal resourcing to operate a system and required processes after going live.
  • PAM is one component of a successful identity and access strategy, so consider integration and consolidation. Does your organization need a discrete PAM solution because it has specialised or complex requirements? Or does consolidation with the identity layer make sense?

David Pignolet, CEO, SecZetta

select PAM solutionWhile being a perimeter-less organization might be advantageous from a business perspective, it increases the complexity of safeguarding an organization from cyber threats.

It’s important for businesses to consider how their PAM solution will work with their employees, but it’s just as important to consider how a chosen PAM solution can apply to workers outside of the organization as well. Especially now, as the number of non-employee workers – from vendors and contractors to non-human entities like bots, IoT devices and RPAs – oftentimes outnumbers the actual, full-time employees within an organization.

Whereas an employee is given certain privileges and access upon employment and has said privileges and accesses altered as he or she advances in his or her position and revoked upon termination of employment, non-employee workers – and moreover non-human workers – will typically have their accounts deactivated upon completion or termination of work.

However, that non-human account’s access privileges are either ignored or left intact. This opens up the organization to potential cyber risks and gives cybercriminals the ability to exploit the orphaned accounts for unauthorized access privileges. Given how different the life cycles of employee and non-employee workers are, organizations will want to ensure that their PAM solutions align with the monitoring and management of those lifecycles.

Yash Prakash, COO, Saviynt

select PAM solutionI recommend enterprises take a two-pronged approach to selecting their next PAM solution.

First, buyers should be thinking with the future in mind. We’re seeing rapid changes to IT infrastructure and application portfolios as companies complete digital transformations. Any new solution an organization considers must provide the agility to adapt and cover ongoing enterprise and PAM needs.

Buyers should also keep in mind that critical applications are no longer on-premise, and sensitive data is now in the cloud. So, their next solution needs to focus on privileged access for those cloud applications and take a “no asset left behind” approach towards identity, whether users are human or silicon identities.

Second, buyers should be seeking more value through improved security. The changes to enterprise infrastructure mean they should consider modern ways to secure privileged access — such as breaking away from traditional PAM approaches, including jump boxes and accounts with standing privileges. Instead, they should look towards a cloud-based solution to increase flexibility and deliver higher ROI by reducing infrastructure overhead and upgrade costs.

Modern converged identity solutions that bring IGA and PAM under one roof can provide excellent value while simultaneously improving security across the IT ecosystem.


from Help Net Security https://ift.tt/36u9HzH