All posts by Martin Sansom

Net Neutrality – It’s a Good Thing

Heard about this “net neutrality” stuff? Assuming you are like the other seven hundred million Americans (or so) who use the Internet, if you haven’t, you should probably make a point to familiarize yourself with it, lest you end up like Senator Ted Cruz (R-Texas), embarrassing yourself publicly by comparing Net Neutrality to Obamacare.

Rather than go too in-depth here, we’ll let this article from The Oatmeal help out Senator Cruz (and you) get a handle on why we need it. Titled “Dear Senator Ted Cruz, I’m Going To Explain To You How Net Neutrality ACTUALLY Works“, that’s exactly what it does, in typical The Oatmeal fashion, a small bit of which is excerpted here:

net-neutrality-theoatmeal

Personally speaking, I think one of the reasons I love stuff like this from The Oatmeal is the Pink-Floyd-The-Wall-ishness of their illustrations. Now go call your Senator and tell them to read this blog post!

Why We Use Wordfence (Reason #256)

wordfencelogoOK, maybe there aren’t that many reasons, but there is one that counts, and that is: Wordfence is the best security plugin for WordPress out there, period.  Here’s an excellent article on one of the ways Wordfence keeps our sites secure, titled “Remote Scanning vs Source Code Scanning“. Without getting too technical, source code scans cover everything that makes your site what it is, including images, while remote scans can only cover, by their nature, the end result your source code produces.  Here’s a great metaphor (and you know how we love metaphors) taken directly from the article:

“Imagine you ask someone to check your home for a rat infestation. They arrive at your house, but they don’t get out of their car. They’re parked on the other side of the street and they’re examining your front door, front garden, porch, the walls on the front of your home, parts of the basement windows that they can see. Once they don’t find anything they honk the horn, shout out the car window “Yo, your home is clean” and drive off. Doesn’t sound very effective does it?”

No, it does not! So, if you want to keep your WordPress site “rat-free”, you need Wordfence.  If you need help installing or using it, be sure to call us!

Online Safety Tips for Your Family

sanford-lea-online-safetyThe latest issue of “In The Loop”, from Sanford, Lea & Associates, has a terrific article on tips for keeping your family safe online.  Everyone is a computer user these days, from your child playing online games to grandma learning to use Facebook.  There are security and privacy concerns with any type of online activity, so be sure to read up and familiarize yourself with what you can do to be more secure.  (And if you need accounting services, you can’t go wrong with Sanford, Lea & Associates!)

Read the entire article here.

WordPress 4.0 Is Here!

WordPress — our CMS of choice here at Diamond Mind Web Design — has just released the newest version of their core software, version 4.0, otherwise known as “Benny” (for jazz great Benny Goodman).  What does this mean for you? Not much if you’re a viewer-only of WP blogs and websites, but quite a bit if you are a user of same.

Like Benny Goodman’s sweet jazz, the new WordPress gives a much smoother experience for creating and posting.  New (and much needed) features like a visual plug-in browser, and the ability to view embedded media right in your post draft without the need to preview or publish, make for a much more seamless experience.

Watch the video if you are interested in further details about the new upgrade.  And if you’re interested in starting your own WordPress-based blog, or converting a non-content-manageable site over to WP, give us a shout!

New Site! Nearly…

diamondmindwebdesignThe new (and unofficially official 10th Anniversary) Diamond Mind website is nearly done!  A few more items to complete, including a revamped Portfolio page, an expanded Services page, and a few more surprises still under the hood.

Still working some of the kinks out, though, so please be patient if something is a bit wonky.  If you find a 404 after the next week or so has gone by, please be sure to let us know via our Contact Form.

Thanks, and we look forward to serving your website needs!

SEO

Don’t get lost in the fog of Google rankings! Climb the steps of Mount SEO-ya, Jim, and rank at the top of your chosen categories. Read more here.

eBay Hacked, So Time To Change Passwords… Again!

ebhackYesterday, eBay reported that hackers had access to a stored password database sometime between February and March of this year. The company says no financial data was revealed — but it’s urging its users to update the passwords on their accounts anyway. (And if you use the same password for other sites, change them as well!)

Unfortunately, the hacked database DID include, in unencrypted format, eBay customers’ names, email addresses, physical addresses, phone numbers and dates of birth. Which means even if your eBay password is never cracked, hackers still have all the information needed to attempt identity theft.

Although the company did not release the number of people affected, if you do belong to eBay, expect to receive fake deals and offers. Be very aware of getting duped into revealing even more sensitive information, like your bank details or Social Security number. And, as always, keep an eye on banking and credit card transactions for anything that looks suspicious.

You can read the official post from eBay here: http://www.ebayinc.com/in_the_news/story/ebay-inc-ask-ebay-users-change-passwords

HeartBleed Vulnerability No Laughing Matter

By now you have probably heard about the HeartBleed security vulnerability — news about this bug has been so widespread in the last few days that it even made the Tonight Show monologue.  But HeartBleed is no joke — it is potentially the most serious issue to ever have affected the Internet.

A quick technical explanation of HeartBleed: This bug allows remote attackers to read 64k of memory of systems running affected versions of OpenSSL. That means an attacker can potentially pluck out usernames, passwords, the secret keys of SSL/TLS encryption to crack secure communications and other sensitive information, and so on.

hblogoOne important thing to know about HeartBleed is that it does NOT affect every website where you may have stored a password.  It DOES, however, have a good chance of affecting all the most important, sensitive websites, such as your bank, your credit cards, anywhere it is necessary for secure communications on the Web.

What should you do, then?  IMMEDIATELY log in to all of your critical websites (PayPal, bank, credit cards, loans, etc.) and change your passwords.  You can do this for all stored-password sites if you want, but for those less critical, it may be wise to wait around a week, to be sure the vulnerability has been addressed.  After a week, though, you should log in to all of your sites, including the critical ones, and change your passwords AGAIN.

A brief note on passwords: NEVER use the same password across multiple sites, especially critical ones.  Passwords should NEVER be words that can be found in the dictionary, proper names, easily identifiable dates (such as birth dates, anniversaries, phone numbers, etc.).  Passwords SHOULD be at least 13 characters in length, and consist of some combination of numbers, letters (lower- and upper-case), and punctuation.

If you are interested, you can find a Random Password Generator here: https://identitysafe.norton.com/password-generator/

There are also many password-storage programs out there, if you have trouble keeping track.  One free service that comes highly-recommended is Dashlane.  (Thanks, Preston.)

Finally, for an in-depth technical explanation of the bug and what’s being done about it, visit Heartbleed.com.

Hold Onto Your Butts!

As we’re whisked back in time to 1993, when one Dennis Nedry was head programmer at a certain Park on a certain island. (Can it really have been that long ago?) If you already have figured out what I’m talking about, then you’ll want to head right over to this site…

www.jurassicsystems.com

…to see if you’re smart enough to gain access to the main security grid.  (And don’t forget the magic word!)

If you have no clue yet, then it might be wise to watch this short clip:

 

So, what are you waiting for? Jam a cigarette butt in your mouth, practice your best Samuel L. Jackson impersonation, and if you’re a really good hacker, you might even find the Zebra Girl!

Full credit goes to Tully Robinson, the programmer who re-created this high-tech (in ’93) piece of wizardry.

Facebook Giveth, Facebook Taketh Away

Fbook-IconThough in this case, I suppose, the order of the above should be reversed.  Facebook just announced that it has (once again) tweaked its News Feed algorithm.  The new change gives Business Pages more reach, by allowing posts tagging another Page to potentially appear in both Pages’ feeds.  According to this post over on Mashable.com, the new change “means brands will have greater reach than ever.”

Of course, this comes less than a year after Facebook devalued Business Page posts almost to the point of non-existance, in order to force more businesses to choose Facebook’s “Boost Post” monetary option.  Hence the title of this post.  And Business Pages have always been able to tag other Pages.  Though the potentiality of showing up in both News Feeds is something new, you’ll pardon me if I don’t go all gaga over the latest “upgrade”.

Still, any advance in potential eyes-on-posts is better than no advance at all.  A couple of notes about this change: It will not work for individuals tagging Pages (just as Pages cannot tag individuals), and don’t expect to start tagging Google’s (or Facebook’s) Facebook page and see your post views multiply astronomically.  The News Feed algorithm will still take account the relevancy of each post to both Pages to decide what to show.

In any case, we’ll certainly be giving it a shot. What are your opinions on this change?

WordPress Brute Force Attack Underway

One of the largest distributed brute force attacks on WordPress installations ever seen is currently going on, as reported by Mark Maunder of Wordfence Security on his blog. You can read the full post here. The attempts at hacking are running 30 times more frequently than average.

A brute force attack is when an attacker tries many times to guess your username password combination by repeatedly sending login attempts. A distributed brute force attack is when an attacker uses a large number of machines spread around the internet to do this in order to circumvent any blocking mechanisms you have in place.

If you have a WordPress-based site, I highly recommend that you pay close attention to it until these brute force attempts have waned.  If you suspect that you’ve been hacked, and need help recovering, you can always contact us here at Diamond Mind Web Design.

Friday Funny – November 15, 2013

Okay, so this isn’t funny — nor is it meant to be.  Inspirational, rather, as it was to me when I first read Tolkien some (cough, cough) years ago.  Not only was he a scholar, professor, linguist, and author, but a poet as well, and skilled at all, able to open entire worlds in his readers’ imaginations with mere words.

tolkiengate