Blog

  • The features a good website you must have to be highly effective

    The features a good website you must have to be highly effective but before we dive into these features, let us look at the common mistakes you can find in almost all the websites today no matter how fantastic their designs are.

    What you find more in the society are people who just learn how to design a website not for the love of the career but for the love of the money and that’s why sometimes, they only design a website with images flying all around and feel the site is done but there are more to a website than just this.

    These are some of the mistakes you can find which are hardly noticed either by you or the designer:

    Not Enough Copy

    Most people don’t add much about their company on their website and some companies are afraid to put too much copy on their website.  They worry that visitors won’t take the time to read it or, that if they do, they’ll have learned what they need to know and won’t call.  If they don’t call, the company doesn’t get an opportunity to interact with visitors and convert them into customers.

    As long as you make your copy interesting and informative, you don’t have to worry about overwhelming visitors.  They’ll find what appeals to them and skip over the rest.  More information won’t hurt.  It helps visitors perceive you as industry experts, as an authority in your field.

    But here’s the important thing: if visitors don’t find what they’re looking for, they’ll hit their back button, and you’ll have lost them for good.

    Who Are Your Target Audience

    The most company website doesn’t show who their target audience is and is always nice to declare your target audience, it will help connect with your prospective customers.

    When a prospect lands on your website, you want them to be able to see themselves as potential customers.  If you don’t make that connection, you won’t get a chance to make the sale.

    No Differentiation from the Competition

    Most of the websites don’t seem to show the services they offer and in some case, they might be offering more of other services which will differentiate them from other competitors.

    A Call to Action Is a Necessity

    Most of the websites are beautifully designed but they don’t have a call to action that will allow a customer to make a move.  After you’ve described your product or service, you need to prompt the prospect to contact you.  You need to move him forward in the sales process, just as you would if you were making a presentation in person.

    Make Contact Information Easy to Find

    In some of these beautifully designed websites, the contact information is hard to find and sometimes you can only find it below or the inside pages. Don’t make visitors search for your email or phone number.  Put those items right in front of their face, no matter where they are on your site.

    The About Us Page Isn’t Optional

    Some website is beautifully designed but they lack the use of the about us page and this is one of the most important pages where you tell the customer all about your company.

    How could visitors decide if they liked and trusted the company enough to award it their business if they didn’t know anything about it?

    Confusing Navigation

    Navigation is a place on the website through which your prospective customers move around your website with ease and the most beautifully designed website lack the proper use of this feature.

    What Does Your Company Do?

    The most website does not explain to there prospective customers what they do in their company but they end up just telling them how they do their job.

    Get Real with Photos

    Real pictures are an important component of telling your company’s story. Without them, the visitor doesn’t feel he knows you and can trust you.

    No Testimonials Is a Red Flag

    People considering purchasing decisions seek out reviews and testimonials.  They want to know that others in the same situation found the right solution.

    No SEO?  Uh-oh!

    Some websites are beautifully designed but customers cannot find it on search engines except they type the company name and also the title of the pages and meta description will be missing it so getting a customer is always an issue.

    Here are the features a good website you must have to be highly effective

    Make your Home page compelling

    Your Home page is prime real estate. After all, that’s how most visitors will enter your site. Make your pitch strong, as well as visually appealing, so anyone who lands there is persuaded to walk through the door to the other pages of your site.

    Explain what you do, not just how you do it

    This information should be readily apparent, easily found on or from your Home page.

    Give facts about your company

    Don’t hide behind generic statements and fluffy descriptions that could apply to any business (i.e.“We’re committed to quality and customer satisfaction.”) Be clear. Be specific.

    Include a call-to-action on every page

    Remember, the whole goal of having a website is to persuade someone to take action, whether it’s to contact you, subscribe or purchase a product.

    Make site navigation logical

    The navigation menu is not the place to get creative. Use terms people know and understand. Place buttons where visitors expect them to be. They should not have to search hard to find what they want.

    Optimize each page of your copy for specific keywords

    If you want to rank high on the search engines, optimization is a necessity.

    Craft good title tags and description meta-tags

    Every page should have unique title tags and description meta-tags. They should employ the same keywords used in the content of the page.

    Include testimonials, case studies, and client lists

    Nothing is more persuasive than a third-party endorsement. Those votes of confidence will build your company’s credibility and authority.

    Use real photos when possible

    Stock photos are too generic and too fake to make a meaningful impression.

    Determine the path you want your visitors to take and then lead them

    Look at your site’s analytics and see where visitors enter your site (Hint: it’s not always the Home page), the order of pages they’re viewing and the pages they exit from. Then modify your content to better control the visitors’ path and steer them to take action.

    Let us fix your website for you at an affordable cost. Need a website? then click here for me to take you there to start up.

  • The inventor of the World Wide Web has unveiled a plan for a new secure internet

    The inventor of the World Wide Web has unveiled a plan for a new secure internet but they are still looking at the economic value of it but it will give power to the people who own their data and not to the internet giants. From what he is saying, it will allow people who want to access or share your pictures to ask you first then you decides either to grant it or not.

    Why it matters: The internet is not what its founder, Tim Berners-Lee, wanted it to be. It has finally exploded into his dream of an open resource that everyone can see and interact with, purchase things, connect and innovate on. But that’s come with something no one saw coming back when the internet was in its infancy: unwanted control and manipulation of our data.

    For several years Sir Tim Berners-Lee and his team at MIT have been developing a decentralized platform designed to give every internet user full control over their data: Solid(Social Linked Data). This week he is revealing the first start-up to take advantage of the Solid platform, called Inrupt. Berners-Lee and his partner John Bruce will lead a small team of inspired developers to take the power back from the internet giants.

    “The intent is world domination. We are not talking to Facebook and Google about whether or not to introduce a complete change where all their business models are completely upended overnight. We are not asking their permission.”

    Berners-Lee says that Facebook’s continuous failure to protect its users is something that drives him: “We have to do it now. It’s a historical moment.”

    I think we can all agree a change is sorely needed; only two days ago it was revealed that 50 million Facebook accounts may have been compromised. Berners-Lee says that Facebook’s continuous failure to protect its users is something that drives him: “We have to do it now. It’s a historical moment.”

    Solid works through something called a Solid POD, a Personal Online Data storage system. A POD is simply a file that contains all your data: videos, images, calendar, address, preferences, friend lists – everything from where you work to the name of your Labrador. The Solid development team is working on software that creates and manages a POD, and once it is fully complete (soon, we’re told) companies and individuals will be able to create and use their own POD servers. What this means is that you can store your own POD on an internet-connected device or simply pay a company to store it for you.

    Any and all sites or apps that want access to information about you simply ask your POD for it – depending on your choices, it will say yes or no. For example, a social media platform may ask your POD for your name, age, phone number and any images you might want to share. But the social media platform doesn’t control the information: by disabling the platform’s access to your POD the information is removed.

    This is where Inrupt enters the fray: it allows you to create a POD on Inrupt’s servers, and it will create apps and assist other companies to create apps using Solid. Technically, you can create a POD right now on their website and play around with calendar and note-taking apps, but, to be frank, the interface is dreadful and nowhere near ready for use. Inrupt is currently funded by Glasswing Ventures, who specialize in AI and other technology start-ups, but Inrupt is pursuing further funding.

    The Solid platform is a good idea with good goals. Solid PODs are a good and technologically feasible execution of that idea. But will it get its feet off the ground?

    We can look at this in two ways. The first is the perspective of an up-and-coming platform. It’s brilliant; the next big thing. Like pretty much all platforms, ad-revenue is an important aspect. The platform’s creators are faced with a choice: use PODs to protect users’ data and make less money, or trust that they can protect users’ data themselves and make more money. The creators will likely have good intentions (think WhatsApp or Telegram) but it is hard to find investors who’ll agree to make less money.

    The second perspective is of an established platform. Take YouTube as an example. It would be extremely difficult for them to switch over to PODs even if they wanted to: shareholders would not be impressed by suddenly switching over to a less profitable business model (e.g. non-targeted ads). Particularly when they can easily just continue with their current business model.

    The bottom line is, the Solid platform is a brilliant idea but because it doesn’t make economic sense, it’s hard to envisage widespread adoption. Unless Inrupt can somehow make PODs profitable for companies to adopt, or create their own platforms to rival Google and Facebook, our data will remain in the hands of the corporate giants.

  • MPs demand answer from Facebook boss over hack shock

    MPs demand answer from Facebook boss over hack shock and have demanded that Mark Zuckerberg travels to the UK to face questions about his “terrible disrespect” for the data of citizens, following last week’s data breach at Facebook that resulted in 50 million user accounts being ­exposed to hackers.

    They want answers from the Facebook boss after millions of users were left vulnerable to identity fraud in the biggest cyber attack on the social media giant since it was created in 2004.

    Questions over the company’s “cavalier attitude” to data security are to be asked by the digital, culture, media and sport select committee.

    On Friday, Facebook revealed that hackers had been able to access ­accounts due to a security flaw that had remained open for more than a year.

    Damian Collins, who chairs the select committee, said: “Facebook’s latest data breach demonstrates more clearly than ever why Mark Zuckerberg should face public scrutiny about the practices and policies his company employs to keep British users’ data safe.”

    Mr Zuckerberg was summoned by Parliament earlier this year to be questioned over its investigation into fake news on Facebook and has three times refused to attend the select committee.

    But he has, however, agreed to be scrutinised by US legislators in Washington and EU politicians in Brussels earlier this year. Julian Knight, a committee member, said: “It would be helpful to hear from Mr Zuckerberg, but I won’t be holding my breath.”

    Facebook has more than 2.2 billion monthly users around the world and 40 million in the UK. Facebook ­declined to comment.

  • Facebook warns that recent hack could have exposed other applications

    Facebook warns that recent hack could have exposed other applications, including Instagram, Tinder, and Spotify

    Why it matters: Facebook’s bad year isn’t getting any better. As the dust from the Cambridge Analytica scandal started to settle, the social network revealed a security vulnerability that could have exposed 50 million accounts. But the company has confirmed the hack is worse than first suspected: other apps that use Facebook’s login service, including Spotify, Tinder, and Airbnb, could have also been compromised using the vulnerability.

    Facebook announced Friday that it identified the security issue earlier in the week. It involved exploiting a vulnerability in the “view as” feature, which lets people to see how their profiles look to others. The fault allowed hackers to steal Facebook’s access tokens and take over people’s accounts. As a security measure, Facebook forced over 90 million users to log out.

    Facebook said there was no evidence the hackers had access to “private messages or posts,” but warned “that may change” as the investigation continues.

    Following the initial announcement, Facebook revealed in a follow-up conference call that other services using the company’s login feature could also be at risk of having these accounts compromised. Many apps and websites allow people to sign-up using their Facebook credentials, and while there’s been no confirmation of any being breached, it’s another concern for the company and its users.

    “The access token enables someone to use the account as if they were the account holder themselves. This does mean they could access other third-party apps using Facebook login,” said Guy Rosen, Facebook’s vice president of product.

    Facebook’s photo- and video-sharing app Instagram could also have been affected.

    Facebook said it has patched the vulnerability and reset the access tokens of all the accounts known to have been affected by this breach, but it’s not enough to repair the PR damage that’s been done. The fact that CEO Mark Zuckerberg and COO Sheryl Sandberg were among two of those affected by the hack hasn’t helped matters. Since the news broke, $12 billion has been wiped from the company’s value.

    If all this hasn’t been enough to deal with, this week also saw Facebook admit that it uses 2FA phone numbers for ad targeting purposes.

  • The Massive Facebook Hack Might Have Affected Other Apps

    The massive Facebook hack might have affected other apps and websites, too and this is report was coming few hours after the 50 million Facebook account has being compromised. So if you account is hack that means, app and website that is using the Facebook sign-up and login has also being affected.

    Hours after Facebook announced on Friday a huge data breach that affected at least 50 million users, the news got worse.

    In a conference call with reporters—Facebook’s second of the day, after the first one left many questions unanswered—the company’s vice president of product, Guy Rosen, said that the hackers could have also gained access to users’ accounts on other apps and websites, beyond Facebook itself, via Facebook Login. That’s the feature of Facebook that allows you to sign up for, and log in to, all kinds of other online services using your Facebook credentials. For users whose Facebook accounts were hacked, the company confirmed, it’s possible that those third-party accounts could have been breached as well.

    The follow-up call was meant to clarify some of the details of the breach, which is almost certainly the most significant in Facebook’s history. In it, Rosen explained how three separate bugs combined to give hackers a path to full control of users’ Facebook accounts. They gained access not by stealing users’ passwords, but via a sort of digital key called an “access token” that’s meant to let you into your account on another device (say, your phone) automatically when you’re already logged in on another (say, your laptop).

    The good news is that the hackers don’t have anyone’s Facebook passwords—so even users who were affected by the breach don’t necessarily have to change those. The bad news: They could theoretically have used that same token to gain access to some of users’ other online accounts, depending on how the relevant apps and sites handle Facebook access tokens. It was not immediately clear whether the hackers—who remain unknown—actually took advantage of this, nor how easy it would have been for them to do so.

    Any such connections should have been broken when Facebook reset the access tokens of the affected users, beginning Thursday night. That would have logged users out of those third-party apps and sites.

    Facebook also clarified that users affected by the Facebook breach who had Instagram or Oculus accounts linked to their Facebook account would need to delink and relink those accounts. One piece of good news: Whatsapp was apparently not affected. The story is still developing, and more details are likely to emerge in the days to come.

    But there’s already one conclusion we can make: There was a time when Facebook harbored ambitions to be a sort of “universal login” for sites and apps everywhere—like a driver’s license for the online world. That never quite came to pass, but it did get pretty far along. This should be the final answer to the question of whether it was ever a good idea

  • Microsoft Office 2019: Everything You Need to Know

    Microsoft Office 2019: Everything You Need to Know and unlike the office 365 which is a cloud base, this new office 2019 is for offline use and it comes with 32 and 64 bits version and can only be install on systems with windows 10.

    You may have noticed that Microsoft began rolling out a new version of Microsoft Office early this week. That means that there are now three versions of Microsoft Office out in the wild—Office 2016, Office 365, and the brand-new Office 2019.

    If you’re curious about this new version of Microsoft Office, we’ve put together this guide to answer the biggest questions about Office 2019, such as how it differs from Office 2016 and Office 365, what features are (and aren’t) included, and when you can actually use it.

    What is Office 2019?

    Microsoft Office 2019 is a standalone, local (not cloud-based, like Office 365) version of the Microsoft Office software suite. It is a “perpetual” release, which is just a fancy way of saying you buy the software once and own it forever, rather than having to pay an annual subscription fee to access it. That said, you only get a license to use it on a single PC, whereas a subscription to Office 365 lets you use it on a PC, a tablet, and a smartphone.

    This new release updates and replaces the 2016 versions of Word, Excel, etc. and includes many of the new features that have been rolled out to Office 365 users over the past three years. We’ll get to those in a bit.

    When is Office 2019 available, and how much will it cost?

    Office 2019 is on sale now, but only for commercial-level customers. Availability will be rolling out regular ol’ customers like you and me in the coming weeks. That also means we don’t yet know what the price point is for individual users, but Microsoft will likely have that info soon. Expect to potentially pay a bit more than what you’d shell out for Office 2016 (currently $150 for the “Home and Student” version), as Microsoft already boosted the price of the commercial version ten percent to account for its “significant value added to the product over time.”

    What are the system requirements for Office 2019?

    Here’s a big change. On PCs, you’ll need Windows 10 for Office 2019; Microsoft will not support any versions of Windows 7 or 8. As always, Microsoft will make 32 and 64-bit versions of Office 2019 available.

    For Mac, Microsoft will support the three most recent versions of macOS, currently macOS Sierra (10.12), High Sierra (10.13), and Mojave (10.14). As Microsoft notes:

    What new features can you expect?

    Here’s a quick rundown of the important updates Office 2016 users will see if they upgrade to Office 2019.

    Microsoft Word

    With Office 2019, Microsoft says it’s focused on helping you, well… focusbetter when writing in Word. To do so, Word 2019 will be getting the aptly named Focus mode, which darkens the screen and reduces the displayed UI elements.

    Users will also have new “Learning Tools,” including new text-to-speech, text spacing, and translator features. Mac users will also now have customizable ribbons (aka drop-down menus) in their version of the Word interface.

    Outlook

    Like Word, Outlook is also getting a new focus mode, called the “Focused Inbox,” to help streamline workflow and email drafting. Users can now use “@” commands for tagging people in emails, and contact cards have been overhauled.

    Also, PC users will now have travel and delivery cards, while Mac users get new email templates; a Send Later function for scheduling delivery times; and read receipts. Both platforms also get Office 365 Group integration.

    PowerPoint

    The changes for PowerPoint are all about enhanced media and visual element support in presentations. The notable additions here are support for 3D model display/manipulation and SVG files on slides; new morph transitions; the ability to export your presentation in 4K UHD video format, and you can now write by hand and move elements with your pencil while editing.

    OneNote

    OneNote is arguably the biggest change included in Office 2019. This is technically a new OneNote release entirely, one that can replace OneNote 2016 (though OneNote 2016 remains available and will be supported by Microsoft through 2025). This new version, dubbed OneNote for Windows 10, includes Ink-to-Text support, meaning your handwritten words will be turned into typed text, plus better syncing between connected devices.

    Excel

    Finally, Excel gets a host of new functions—like new formulas and chart options, and support for 2D maps and timelines—to better present and organize your data. PC users will also receive updates to Power Pivot, Power Query, and the ability to export to Power BI.

    Better pencil support and other tweaks

    In addition to these program-specific updates, there are also changes that apply to all Office 2019 software. The most important of these is Microsoft’s beefed-up support for digital pencils, like expanded “roaming pencil case” support, which lets users write by hand and move parts of documents with their pencil, as well as new support for pressure sensitivity and tilt recognition. Office 2019 also comes with some behind-the-scenes changes such as monthly security updates and a reduction to network bandwidth use.

    Will Office 2019 replace Office 365?

    No. In a post announcing the software release, Microsoft makes sure to point out that Office 2019 is a standalone package of its software geared primarily towards private users and businesses who do not have the necessary internet access required to use the cloud-based Office 365. Because of this, many of the features present in the Office 365 versions of these apps are not included in their Office 2019 counterparts, especially cloud-based and collaborative features.

    Furthermore, Microsoft makes it clear that while Office 2019 will be receiving regular security fixes, it will not be getting expanded feature updates, while Office 365 users can still look forward to new and updated features through regular monthly updates just as they always have.

    The bottom line here is that Office 2019 is not going to replace Office 365, and it really isn’t meant to. That said, regardless of the particular use case, Office 2019 still fills a crucial role and services a section of Microsoft’s customer base that may have felt a bit neglected since Office 365 took the spotlight.

  • 50 million Facebook accounts were compromised. Was yours?

    Facebook have announced that 50 million Facebook accounts were compromised. Was yours? Just yesterday as well, we give you a news on how a hacker is saying is going to live stream the deletion of MarkZuckerberg’s Facebook account on the 30th of September, 2018, now we are having this news same day that 50 million Facebook accounts were compromised.

    Your Facebook account may have been hacked this week. The social networking giant on Friday said “almost 50 million accounts” were compromised, a discovery its engineers made on Tuesday. Here’s what you need to know.

    What happened?

    According to Facebook, “attackers exploited a vulnerability in Facebook’s code that affected View As, a feature that lets people see what their own profile looks like to someone else. This allowed them to steal Facebook access tokens, which they could then use to take over people’s accounts.”

    What’s an access token?

    An access token keeps you logged into Facebook so you don’t need to enter your password each time you visit the site or app. If an attacker has your token, then he or she has access to your account.

    Was my account hacked?

    Odds are it was not. While 50 million sounds like a big number, it’s a small percentage of the more than two billion active Facebook accounts. If you go to your Facebook page and don’t need to log in, then your account is safe — it was not breached. If you go to your Facebook page and find that you are logged out, then your account may have been breached.

    In response to discovering the attack, Facebook reset the access tokens of the 50 million accounts it found to be compromised, which will require those users to enter their password to log back in. Facebook also took the precaution to reset access tokens of an additional 40 million accounts for those users who used the “View As” feature in the last year.

    If your account was affected, Facebook will notify you in a message at the top of your News Feed when you log back in to explain what happened.

    Facebook has also temporarily turned off the View As feature while it investigates.

    Has Facebook fixed the breach?

    According to Mark Zuckerberg himself, “We patched the security vulnerability to prevent this attacker or any other from being able to steal additional access tokens.” The company, however, still does not know who is responsible for the attack.

    I’m still nervous. Should I change my password?

    Facebook says there’s no need to change your password, but it certainly wouldn’t hurt to pick a new one. After all, the Cambridge Analytica fiasco was worse than Facebook initially believed or admitted.

    You could also just log out of your Facebook account and then log back in without needing to change your password. This simple action will reset your access token, which should put any immediate worries to rest while we wait for Facebook to share more information about the attack.

    To log out of Facebook on all of your devices, go to the Security and Login pageand in the Where You’re Logged In section, click See More and then click Log Out Of All Sessions.

  • FBI warns companies about hackers increasingly abusing RDP

    FBI warns companies about hackers increasingly abusing RDP connections. Not too many of us knows the full meaning of RDP so, we are going to explain it in a brief for you to understand what this warning is all about.

    RDP is an acronym which means remote desktop protocol and is a proprietary protocol developed by Microsoft, which provides a user with a graphical interface to connect to another computer over a network connection. The user employs RDP client software for this purpose, while the other computer must run RDP server software.

    In a public service announcement published on the 27th of September 2018 by the US Federal Bureau of Investigation’s (FBI) Internet Crime Complaint Center (IC3), the FBI is warning companies about the dangers of leaving RDP endpoints exposed online.

    RDP stands for the Remote Desktop Protocol, a proprietary technology developed by Microsoft in the 90s that allows a user to log into a remote computer and interact with its OS via a visual interface that includes mouse and keyboard input –hence the name “remote desktop.”

    RDP access is rarely enabled on home computers, but it’s often turned on for workstations in enterprise networks or for computers located in remote locations, where system administrators need access to, but can’t get to in person.

    In its alert, the FBI mentions that the number of computers with an RDP connection left accessible on the Internet has gone up since mid and late 2016.

    This assertion from the FBI correlates with numbers and trends reported by cyber-security firms in the past few years. For example, just one company, Rapid7, reported seeing nine million devices with port 3389 (RDP) enabled on the Internet in early 2016, and that number rose to over 11 million by mid-to-late 2017.

    Hackers, too, read cyber-security reports. Early warnings from the private sector about the increasing number of RDP endpoints caught hackers’ attention long before sysadmins.

    For the past few years, there has been a constant stream of incident reports in which investigators found that hackers got an initial foothold on victims’ networks thanks via a computer with an exposed RDP connection.

    Nowhere has this been more the case than in ransomware attacks. Over the past three years, there have been tens of ransomware families that were specifically designed to be deployed inside a network after attackers gained an initial foothold, which in many cases ended up being an RDP server.

    Ransomware specifically designed to be deployed via RDP includes strains such as CryptON, LockCrypt, Scarabey, Horsuke, SynAck, Bit Paymer, RSAUtil, Xpan, Crysis, Samas (SamSam), LowLevel, DMA Locker, Apocalypse, Smrss32, Bucbi, Aura/BandarChor, ACCDFISA, and Globe.

    Here’s just one user recounting one event on Reddit where hackers broke in via RDP and launched ransomware that encrypted countless of his systems.

    There are three ways in which hackers usually tend to get in. The easiest way is when sysadmins enable RDP access on a server and don’t set up a password. Anyone accessing that computer’s IP address on port 3389 will be prompted by a login screen where they can log in just by pressing Enter.

    The second way is derived from the first but requires on attackers either guessing login credentials (via a brute-force attack) or by using precompiled lists of common username-password combos (via dictionary attacks).

    The third method also relies on mass-scanning the internet, but instead of guessing credentials, attackers deliver exploit code for known vulnerabilities in the RDP protocol. If the port is exposed, then hackers can exploit it.

    According to Rapid7, between 2002 and late early 2017, there have been 20 Microsoft security updates specifically related to RDP, updates that fixed 24 major vulnerabilities. Patches for RDP continued even after Rapid7 stopped counting, with the latest of these fixes being deployed this March for a flaw in CredSSP, one of the smaller protocols part of the RDP package.

    In an interview with ZDNet about the FBI’s alert, Mark Dufresne, VP, Threat Research and Prevention at cyber-security Endgame, shared some of his dealings with the RDP threat.

    “RDP has been baked into Windows for a very long time and has been abused by attackers since it became widely deployed,” Dufresne told ZDNet.

    “We can look at sources like greynoise.io to see that attackers are constantly looking for open RDP connections,” he added. “Almost a thousand unique IPs were looking for RDP services listening on the default port each day over the past week.”

    Once attackers get in, it’s all fair game, unless they’re not careful and security products expose their presence.

    But not all RDP compromises result in ransomware infections, data theft, or malicious behavior. Some of the people behind these RDP scans don’t always exploit the hacked systems –at least not directly– and stockpile hacked RDP endpoints to sell online.

    Since mid-2016, just about when cyber-security firms were noting a rise in RDP servers, a group of hackers set up xDedic, a web portal where they and other criminals could sell or buy these hacked and hoarded RDP systems.

    Initially, it was said that xDedic provided crooks access to over 70,000 hacked RDP endpoints, but one year later, despite the media attention and attempts to take down the site, xDedic’s RDP server pool had gone up to 85,000.

    But xDedic was only the beginning. Other copycat “RDP shops” –as they became to be known as– popped up everywhere. This reporter has been tracking some of these services for the past few years on Twitter [1, 2, 3, 4, 5, 6].

    The most recent of these was discovered just this summer, in July. McAfee security researchers found it peddling access to RDP workstations located on some pretty sensitive places such as airports, government, hospitals, and nursing homes.

    But these shops wouldn’t be a problem unless people stopped exposing RDP endpoints altogether. Through its alert, the FBI is now urging companies to secure these systems before it’s too late and they get hacked.

    Together with the Department of Homeland Security, the two agencies have published today the following advice in regards to improving RDP security.

  • Hacker says he’ll livestream deletion of Zuckerberg’s Facebook page

    Hacker says he’ll livestream deletion of Zuckerberg’s Facebook page this sunday being the 30th day of September 2018 and he said we can login to our facebook page to see if that will not happen and this was said his 26,000 plus followers.

    A white-hat hacker is promising to livestream his bid to hack into Mark Zuckerberg’s Facebook account on Sunday (30th September). “Broadcasting the deletion of Facebook founder Zuck’s account,” Chang Chi-yuan told his 26,000-plus followers on the social network, adding: “Scheduled to go live.”

    According to Bloomberg, the self-proclaimed bug bounty hunter is a minor celebrity in Taiwan who’s appeared on talk shows and was reportedly sued by a local bus operator after breaching their systems to nab a ticket for just NT$1 (3 cents). Earlier this month, Chi-yuan shared a screenshot showing an Apple Pay loophole he’d found that allowed him to pay NT$1 for 500 iPhones. His other claims include cyber-attacks on Apple and Tesla, and he’s also listed on Japanese messaging giant Line’s 2016 bug-hunters’ hall of fame.

    “I don’t want to be a proper hacker, and I don’t even want to be a hacker at all,” Chang said in a recent post. “I’m just bored and try to dabble so that I can earn some money.” Facebook, like other tech giants, dishes out cash to cyber-security experts who point out flaws in its system as part of a bug bounty program. But considering all the setbacks it’s currently facing — including the departure of Instagram’s founders and its ongoing fake news crisis — it probably doesn’t want to deal with a high-profile hack right now.

    Neither is the company keen on paying out bounties to people who test vulnerabilities against real users. Back in 2013, it refused to reward Khalil Shreateh — a systems information expert from Palestine — for hacking into Zuck’s account and posting an Enrique Iglesias video on the wall of one of his college friends. The Facebook founder has also previously had his Twitter and Pinterest accounts breached by notorious hacker group OurMine.

    News source: engadget

  • Without invading our privacy, does Google even have a business?

    Without invading our privacy, does Google even have a business?

    Without invading our privacy, does Google even have a business?  Google is on a seemingly-ceaseless crusade to turn every one of its users into an open book that it can exploit for valuable information, and much of the public seems unaware. What’s worse, many of those who do know about Google’s illicit tracking services and shady operations oftentimes don’t seem to care.

    As a matter of fact, Google’s intrusive policies are becoming a defining facet of modern life and warrant intense discussion if we’re ever to progress meaningfully as a society.

    One question stands out above them all: without invading our privacy, does Google even have a business?

    The foundations of a digital empire

    This is huge question to unpack, so it’s worth looking at the foundation of Google as a company before arriving at our answer. First and foremost, we need to dispel any notions that Google has the best interest of people or society at heart. It is, at its very core, a capitalist corporation that seeks to supplant competitors and extend its influence over as much of the globe as possible.

    This isn’t controversial – the company even admits to it in its mission statement, which reads that it intends “to organize the world’s information and make it universally accessible and useful.”

    The consequences of this statement are exciting and terrifying at the same time. On the plus side, we all derive many benefits from Google every single day – whether we’re tapping away on one of the company’s smartphones or using its services to look up a new recipe or the address of a friend, the lives of pretty much everyone everywhere have been positively impacted by Google in some way.

    The more insidious consequences lurking below the surface warrant discussion too, however, and only by prying into Google’s skeleton-filled closet can we see that the company isn’t always on our side.

    According to an exclusive report from the Associated Press, for instance, Google’s extensive location tracking services are so robust that they keep track of your whereabouts even after you’ve turned them off. Like it or not, the AP reminds us, Google is tracking your movements everywhere you go in the physical and virtual worlds.

    The company’s proponents argue, sometimes persuasively, that it essentially has to do this if it’s to meet our demands. How can Google show you which food truck or day spa is in your area, for instance, or what the weather will be like in your town, if it’s uncertain of where you are at the precise moment of inquiry?

    But whether that gives Google extensive rights to probe into our personal business is a wholly different question. This is worrying, because a strong case can be made for the fact that Google essentially can’t run a business if it can’t invade our privacy to some extent.

    To snoop or not to snoop, that is the question

    The latest scandal surrounding Google isn’t centered on location tracking, but rather the new way in which Google Chrome’s sign-in works. A slew of updates brought with it a change to Google’s popular web browser, which now automatically forces you to login on a Google account on Chrome if you’re trying to use that browser to access a Google service (like Gmail). A breakdown of the changes illustrates that they’re deeply concerning from a privacy standpoint and help us answer our question.

    To be quite frank, it’s likely true that Google simply didn’t need to force this latest change on its users, and that it can survive and thrive as a company without forcing you to login to a Google account every time you use Chrome to access a Google service. But the broader question of whether Google needs to invade our privacy in general to exist as a business is more difficult, and the answer to that question is likely the inverse to the one above.

    Whereas Google doesn’t need to force foolish and intrusive changes like that Chrome sign-in scandal mentioned above onto users, it definitely needs to invade your privacy to some extent in order to operate. The key phrase there is “to some extent.”

    Google, for instance, necessarily has to ascertain your physical location to give you directions from your home to the nearest coffee shop when you ask for it, after all. It also needs to keep track of you to give you timely weather updates, security alerts in your local area, and other info we regularly request from it every day.

    But the fact that we need to let Google know a little bit about us to rely on its services as extensively as most of us do doesn’t give the company free license to spy on us in all manners of life.

    Google may not be able to exist without invading our privacy to some extent, but the company needs to understand that certain lines can’t be crossed and consumer confidence must be maintained if it’s to achieve its goals in the future.

    This post is part of our contributor series. The views expressed are the author’s own and not necessarily shared by TNW.