<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Google Archives - CritchCorp Computers Ltd</title>
	<atom:link href="https://www.cc-computers.com/tag/google/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.cc-computers.com</link>
	<description>Complete Computer Support</description>
	<lastBuildDate>Thu, 17 Aug 2023 06:55:19 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.4</generator>

<image>
	<url>https://www.cc-computers.com/wp-content/uploads/2020/07/favicon.ico</url>
	<title>Google Archives - CritchCorp Computers Ltd</title>
	<link>https://www.cc-computers.com</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Not long left to get 2 year SSL certificates</title>
		<link>https://www.cc-computers.com/2-year-ssl-certificates-going/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=2-year-ssl-certificates-going</link>
					<comments>https://www.cc-computers.com/2-year-ssl-certificates-going/#comments</comments>
		
		<dc:creator><![CDATA[CritchCorp]]></dc:creator>
		<pubDate>Tue, 11 Aug 2020 08:37:20 +0000</pubDate>
				<category><![CDATA[Archive]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[Google Chrome]]></category>
		<category><![CDATA[SSL certificates]]></category>
		<guid isPermaLink="false">https://cc-computers.com/?p=2866</guid>

					<description><![CDATA[<p>If you usually buy 2 year certificates for your website then you are probably already aware that they are going. Yes, as of the 20th August 2020 they will no longer be available. Why are 2 year Certificates going? This is due to Google making Chrome not accept certificates that are valid for more than [&#8230;]</p>
The post <a href="https://www.cc-computers.com/2-year-ssl-certificates-going/">Not long left to get 2 year SSL certificates</a> appeared first on <a href="https://www.cc-computers.com">CritchCorp Computers Ltd</a>.]]></description>
										<content:encoded><![CDATA[<p>If you usually buy 2 year certificates for your website then you are probably already aware that they are going. Yes, as of the 20th August 2020 they will no longer be available.</p>
<h2>Why are 2 year Certificates going?</h2>
<p><span id="more-2866"></span>This is due to Google making Chrome not accept certificates that are valid for more than 1 year. Other browsers have followed suit. Their reasoning behind this is to force certificates to be issued more frequently. If they are then there is less chance for things to go wrong with stolen certificates. Google don&#8217;t use the SSL revoked list, a certificate that has been issued, compromised and subsequently revoked can be used. Other browsers that do use the revoked list would not accept this certificate. This new method means that the certificate is only valid for a year so the maximum time it could be used is 1 year.</p>
<p>No matter what their rational behind it is, the fact remains that as of the 20th August you will no longer be able to purchase a certificate for 2 years and any that are issued after this time will automatically be rejected by all browsers as of next year.</p>
<p>What can I do?</p>
<p>If you want a 2 year SSL certificate then get one that is issued before 20th August 2020 and it will be valid. After that time you will just have to buy a 1 year one.</p>
<p>We have already removed the 2 year option from our certificates but if you want one then please submit a <a href="https://shop.cc-computers.com/submitticket.php?step=2&amp;deptid=4">support ticket from your account</a> or a <a href="https://shop.cc-computers.com/submitticket.php?step=2&amp;deptid=3">presales ticket</a> before the 18th August to give us enough time to get a certificate issued. The higher the grade certificate the longer it needs to be issued. so do not delay.</p>
<p><a href="/services/website-security/">Read more about Website Security and SSL certificates</a>.</p>


<hr class="wp-block-separator has-alpha-channel-opacity is-style-wide"/>



<h2 class="wp-block-heading" id="h-don-t-forget-to-checkout-these-other-products-too">Don&#8217;t forget to check out these other Products too</h2>



<div class="wp-block-blockspare-blockspare-list aligncenter blockspare-393e5569-01e3-4 blockspare-block-iconlist-wrap" blockspare-animation=""><style>.blockspare-393e5569-01e3-4 .blockspare-list-wrap{border-radius:0px;margin-top:30px;margin-bottom:30px;padding-top:0px;padding-right:0px;padding-bottom:0px;padding-left:0px}.blockspare-393e5569-01e3-4 .blockspare-list-wrap .listDescription li{color:#404040;text-align:left;font-size:16px}.blockspare-393e5569-01e3-4 .blockspare-list-wrap .listDescription li:before{color:#404040}.blockspare-393e5569-01e3-4 .listDescription li:before{font-size:14px}@media screen and (max-width:1025px){.blockspare-393e5569-01e3-4 .blockspare-list-wrap .listDescription li{font-size:14px}.blockspare-393e5569-01e3-4 .listDescription li:before{font-size:14px}}@media screen and (max-width:768px){.blockspare-393e5569-01e3-4 .blockspare-list-wrap .listDescription li{font-size:14px}.blockspare-393e5569-01e3-4 .listDescription li:before{font-size:14px}}</style><div class="blockspare-blocks blockspare-list-wrap blockspare-hover-item"><ul class="blockspare-list-arrow-right listDescription"><li><a href="https://www.cc-computers.com/critchcorp-smart-light-bulb/">CritchCorp Smart™ Light Bulbs</a></li><li><a href="https://www.cc-computers.com/incense/">Resin Incense</a></li><li><a href="/subscribe-and-save/">NEW: Subscribe and Save</a></li><li><a href="https://store.cc-computers.com/collections/all-subscribe-and-save-items" target="_blank" rel="noreferrer noopener">NEW: Subscribe and Save Collections</a></li><li><a href="https://www.cc-computers.com/free-hosting/">Free Hosting</a></li><li><a href="https://www.cc-computers.com/feature-rich-hosting-cpanel/">Feature Rich Hosting</a></li><li><a href="https://www.cc-computers.com/wordpress/">WordPress Hosting</a></li><li><a href="https://www.cc-computers.com/website-security/">Website Security</a></li><li><a href="https://www.cc-computers.com/cloud-services/cloud-email/">Cloud eMail</a></li><li><a href="https://www.cc-computers.com/cloud-services/cloud-files-data-backup-and-collaboration/">Cloud Sharing &amp; backup</a></li><li><a href="https://www.cc-computers.com/cloud-services/cloud-sharepoint/">Cloud Share Point</a></li><li><a href="https://www.cc-computers.com/phone-and-internet/">Internet &amp; VoIP</a></li></ul></div></div>



<p>You can also read more <a href="https://www.cc-computers.com/about-critchcorp-computers-ltd/">about us</a> and the products and services we offer.</p>



<hr class="wp-block-separator has-alpha-channel-opacity is-style-wide"/>The post <a href="https://www.cc-computers.com/2-year-ssl-certificates-going/">Not long left to get 2 year SSL certificates</a> appeared first on <a href="https://www.cc-computers.com">CritchCorp Computers Ltd</a>.]]></content:encoded>
					
					<wfw:commentRss>https://www.cc-computers.com/2-year-ssl-certificates-going/feed/</wfw:commentRss>
			<slash:comments>14</slash:comments>
		
		
			</item>
		<item>
		<title>Gmail and Yahoo Mail 2FA thwarted by Iranian phishers</title>
		<link>https://www.cc-computers.com/gmail-and-yahoo-mail-2fa-thwarted-by-iranian-phishers/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=gmail-and-yahoo-mail-2fa-thwarted-by-iranian-phishers</link>
					<comments>https://www.cc-computers.com/gmail-and-yahoo-mail-2fa-thwarted-by-iranian-phishers/#comments</comments>
		
		<dc:creator><![CDATA[CritchCorp]]></dc:creator>
		<pubDate>Fri, 01 Feb 2019 18:40:14 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[2fa]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[yahoo]]></category>
		<guid isPermaLink="false">https://cc-computers.com/?p=1608</guid>

					<description><![CDATA[<p>&#160; A phishing gang in Iran has managed to bypass the two Factor Authentication (2FA) that Gmail and Yahoo Mail users use to secure their accounts. 2FA helps users to protect their accounts by adding an extra layer of security. Using your username and password and then something extra like a single use password which [&#8230;]</p>
The post <a href="https://www.cc-computers.com/gmail-and-yahoo-mail-2fa-thwarted-by-iranian-phishers/">Gmail and Yahoo Mail 2FA thwarted by Iranian phishers</a> appeared first on <a href="https://www.cc-computers.com">CritchCorp Computers Ltd</a>.]]></description>
										<content:encoded><![CDATA[<p>&nbsp;</p>
<p>A phishing gang in Iran has managed to bypass the two Factor Authentication (2FA) that Gmail and Yahoo Mail users use to secure their accounts.</p>
<p>2FA helps users to protect their accounts by adding an extra layer of security. Using your username and password and then something extra like a single use password which is delivered via an SMS message.</p>
<p>In this case the gang were able to get the user to go to a fake website that looked exactly like the users Gmail or Yahoo Mail login page. Once the user had entered in their details to the fake site the gang then took those details and entered them in to the real site and then the fake site asked for the code which had just been sent to their mobile phone. Once they entered this in to the site the gang were able to take the code and enter it in to the real site and gain access to the users email accounts.</p>
<p>The attackers, working on behalf of the Iranian government, sent out emails targeting US Government officials, activists and journalists, specifically those involved in the US sanctions against Iran. First they found as much information about each victim and then crafted specially targeted emails at each of them. The emails had a secret hidden picture in them which notified the gang in real-time when the user was viewing the email so they could carry out the attack while the user was trying to login.</p>
<p>The attack was notable for other reasons also it used email addresses such as notifications.mailservices@gmail.com and noreply.customermails@gmail.com to make it look like they were official emails from Google.</p>
<p>We would urge all users of any service to ensure that they check very carefully the links in emails and if possible not to use links in emails at all. Keep yourself up-to-date with security issues by opening an account and signing up for our Security Alerts, Newsletters and Promotional emails.</p>
<p>Keep Safe</p>
<p>CritchCorp Computers Ltd</p>The post <a href="https://www.cc-computers.com/gmail-and-yahoo-mail-2fa-thwarted-by-iranian-phishers/">Gmail and Yahoo Mail 2FA thwarted by Iranian phishers</a> appeared first on <a href="https://www.cc-computers.com">CritchCorp Computers Ltd</a>.]]></content:encoded>
					
					<wfw:commentRss>https://www.cc-computers.com/gmail-and-yahoo-mail-2fa-thwarted-by-iranian-phishers/feed/</wfw:commentRss>
			<slash:comments>7</slash:comments>
		
		
			</item>
		<item>
		<title>Google appeals record GDPR fine</title>
		<link>https://www.cc-computers.com/google-appeals-record-gdpr-fine/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=google-appeals-record-gdpr-fine</link>
		
		<dc:creator><![CDATA[CritchCorp]]></dc:creator>
		<pubDate>Sat, 26 Jan 2019 14:36:51 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[gdpr]]></category>
		<category><![CDATA[gdpr compliance]]></category>
		<category><![CDATA[Google]]></category>
		<guid isPermaLink="false">https://cc-computers.com/?p=1597</guid>

					<description><![CDATA[<p>Google is appealing the record breaking fine for GDPR violations in France. The new European Data protection law (adopted in to UK law as Data Protection Act 2018) sets out rules nd regulations for the way that personal data is collected and how people have a right to know what is collected and how it [&#8230;]</p>
The post <a href="https://www.cc-computers.com/google-appeals-record-gdpr-fine/">Google appeals record GDPR fine</a> appeared first on <a href="https://www.cc-computers.com">CritchCorp Computers Ltd</a>.]]></description>
										<content:encoded><![CDATA[<p><img fetchpriority="high" decoding="async" class="aligncenter wp-image-1600 size-large" title="Google" src="https://cc-computers.com/wp-content/uploads/2019/02/Google-1024x684.jpg" alt="Google GDPR fine" width="584" height="390" srcset="https://www.cc-computers.com/wp-content/uploads/2019/02/Google-1024x684.jpg 1024w, https://www.cc-computers.com/wp-content/uploads/2019/02/Google-600x401.jpg 600w, https://www.cc-computers.com/wp-content/uploads/2019/02/Google-300x200.jpg 300w, https://www.cc-computers.com/wp-content/uploads/2019/02/Google-768x513.jpg 768w, https://www.cc-computers.com/wp-content/uploads/2019/02/Google-449x300.jpg 449w" sizes="(max-width: 584px) 100vw, 584px" />Google is appealing the record breaking fine for GDPR violations in France. The new European Data protection law (adopted in to UK law as Data Protection Act 2018) sets out rules nd regulations for the way that personal data is collected and how people have a right to know what is collected and how it is being used and furthermore be able to see and opt out of data collection. It also imposes an Opt-out default stance which means that companies are supposed to presume you do not want them to collect or use your data, including for marketing emails unless you specifically give permission. In simple terms this means that the tick box asking if you want to be included in their marketing emails must be unticked by default until you tick it. It also means that they must keep and be able to prove for each person that they requested the communication or data retention and can opt out again as easily. It gives people the right to control over their personal data, something that was missing in Europe.</p>
<p>The latest fine imposed on Google is for a breach of this new law and the fact that they do not inform people correctly how they collect the data and how they are using it to serve them with advertising, something that anyone in the industry understands but now has to be explained to everyone so that they understand it. You can read more on What Google and other social media and FREE apps do with your data in our new article: <a href="https://www.cc-computers.com/why-pay-for-email-when-gmail-is-free/">https://cc-computers.com/why-pay-for-email-when-gmail-is-free/</a>.</p>
<p>Google has recently been slapped with much larger fines, such as the $5 billion fine for anti-competitive Android practices and the $2.7 billion fine ever Google shopping, but this one is the largest to date for a GDPR breach.</p>
<p>To get your company, website and network checked for GDPR compliance, <a href="https://shop.cc-computers.com/submitticket.php?step=2&amp;deptid=3">submit a support ticket</a>.</p>
<p><img decoding="async" class="aligncenter wp-image-1601 size-medium" title="EU GDPR" src="https://cc-computers.com/wp-content/uploads/2019/02/EU-Flag-200x300.jpg" alt="EU Fines Google for GDPR breach" width="200" height="300" srcset="https://www.cc-computers.com/wp-content/uploads/2019/02/EU-Flag-200x300.jpg 200w, https://www.cc-computers.com/wp-content/uploads/2019/02/EU-Flag-600x900.jpg 600w, https://www.cc-computers.com/wp-content/uploads/2019/02/EU-Flag-768x1152.jpg 768w, https://www.cc-computers.com/wp-content/uploads/2019/02/EU-Flag-683x1024.jpg 683w, https://www.cc-computers.com/wp-content/uploads/2019/02/EU-Flag-scaled.jpg 1707w" sizes="(max-width: 200px) 100vw, 200px" /></p>
<p>Stay Safe</p>
<p>CritchCorp Computers Ltd</p>The post <a href="https://www.cc-computers.com/google-appeals-record-gdpr-fine/">Google appeals record GDPR fine</a> appeared first on <a href="https://www.cc-computers.com">CritchCorp Computers Ltd</a>.]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>New 773m email address and password hacked</title>
		<link>https://www.cc-computers.com/new-773m-email-address-and-password-hacked/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=new-773m-email-address-and-password-hacked</link>
					<comments>https://www.cc-computers.com/new-773m-email-address-and-password-hacked/#comments</comments>
		
		<dc:creator><![CDATA[CritchCorp]]></dc:creator>
		<pubDate>Fri, 18 Jan 2019 10:29:07 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[connectid]]></category>
		<category><![CDATA[email hacking]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[passwords]]></category>
		<category><![CDATA[secure email]]></category>
		<category><![CDATA[yahoo]]></category>
		<guid isPermaLink="false">https://cc-computers.com/?p=1471</guid>

					<description><![CDATA[<p>&#160; According to popular media there has been another batch of 773 million email addresses and 21 million passwords found on a hacking forum and around 140 million of the addresses may have been recently hacked as they have not been seen before. If you use the same password in multiple places then now is [&#8230;]</p>
The post <a href="https://www.cc-computers.com/new-773m-email-address-and-password-hacked/">New 773m email address and password hacked</a> appeared first on <a href="https://www.cc-computers.com">CritchCorp Computers Ltd</a>.]]></description>
										<content:encoded><![CDATA[<p>&nbsp;</p>
<p>According to popular media there has been another batch of 773 million email addresses and 21 million passwords found on a hacking forum and around 140 million of the addresses may have been recently hacked as they have not been seen before.</p>
<p><span id="more-1471"></span></p>
<p>If you use the same password in multiple places then now is a good time to start changing them. Using a password manager, such as our ConnectID can help you to not have to remember your passwords to each site and so use a complex random password on each site or web app.</p>
<p>To find out more about ConnectID, click here.</p>
<p>Another thing to do is to make sure that your email account is secure and there are several things to do that.</p>
<p>Firstly make sure you use a decent account that is paid for, free accounts are free for a reason. Make sure that you use two factor authentication to login to your email account or use a different password for each app that uses your account and make sure it is a secure password that is not used elsewhere.</p>
<p>If you need a good suggestion for an email account to use that covers all of this and more then we recommend SecuredMail.App, found <a href="https://www.securedmail.app/">here</a>, it can help you with all your security needs and at only £2.00/month including VAT for 2 email accounts,  it is secure and reasonably priced. It can be setup securely and it is recommended, have a look at their website for more details.</p>
<p>[ink-ad-creator ad=&#8221;1327&#8243;][/ink-ad-creator]</p>The post <a href="https://www.cc-computers.com/new-773m-email-address-and-password-hacked/">New 773m email address and password hacked</a> appeared first on <a href="https://www.cc-computers.com">CritchCorp Computers Ltd</a>.]]></content:encoded>
					
					<wfw:commentRss>https://www.cc-computers.com/new-773m-email-address-and-password-hacked/feed/</wfw:commentRss>
			<slash:comments>5</slash:comments>
		
		
			</item>
		<item>
		<title>Google Forces Sites to use SSL Certificates</title>
		<link>https://www.cc-computers.com/google-forces-ssl-use/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=google-forces-ssl-use</link>
		
		<dc:creator><![CDATA[CritchCorp]]></dc:creator>
		<pubDate>Wed, 06 Jun 2018 11:01:16 +0000</pubDate>
				<category><![CDATA[Announcement]]></category>
		<category><![CDATA[Informational]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Urgent Attention]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[google forces]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[prevent hacking]]></category>
		<category><![CDATA[secure website]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[SSL certificates]]></category>
		<category><![CDATA[tls certificates]]></category>
		<guid isPermaLink="false">https://cc-computers.com/?p=596</guid>

					<description><![CDATA[<p>***Notice to all Website owners*** That&#8217;s right, as of July 2018 Google Chrome will start reporting non-SSL sites (that is sites that don&#8217;t use https:// for access) as insecure. This is a major change from the current norm which is to highlight sites that use SSL certificates with a green SECURE next to the address [&#8230;]</p>
The post <a href="https://www.cc-computers.com/google-forces-ssl-use/">Google Forces Sites to use SSL Certificates</a> appeared first on <a href="https://www.cc-computers.com">CritchCorp Computers Ltd</a>.]]></description>
										<content:encoded><![CDATA[<h1>***Notice to all Website owners***</h1>
<p>That&#8217;s right, as of <strong>July 2018</strong> Google Chrome will start reporting non-SSL sites (that is sites that don&#8217;t use http<strong>s</strong>:// for access) as insecure. This is a major change from the current norm which is to highlight sites that use SSL certificates with a green <strong><span style="color: #339966;">SECURE</span></strong> next to the address and other browsers who use a green padlock. They will from July this year not show the green <strong><span style="color: #339966;">SECURE</span></strong> but they will show a<strong> <span style="color: #ff0000;">NOT SECURE</span> </strong>next to any site that does not have an SSL certificate. Making the norm to have an SSL certificate. That is going to be followed in the future by a warning screen that informs users that continuing to your site is not recommended. Though the warning wall is not being implemented right away it is planned for the future.</p>
<p><figure id="attachment_598" aria-describedby="caption-attachment-598" style="width: 640px" class="wp-caption aligncenter"><img decoding="async" class="wp-image-598 size-full" src="https://cc-computers.com/wp-content/uploads/2018/06/google-https-july.png" alt="Google's July update, what it looks like" width="640" height="231" srcset="https://www.cc-computers.com/wp-content/uploads/2018/06/google-https-july.png 640w, https://www.cc-computers.com/wp-content/uploads/2018/06/google-https-july-600x217.png 600w, https://www.cc-computers.com/wp-content/uploads/2018/06/google-https-july-300x108.png 300w, https://www.cc-computers.com/wp-content/uploads/2018/06/google-https-july-500x180.png 500w" sizes="(max-width: 640px) 100vw, 640px" /><figcaption id="caption-attachment-598" class="wp-caption-text">What the browser will report before and after July for sites that do not have an SSL certificate.</figcaption></figure></p>
<p>The new move forces website owners to have an SSL certificate and make their site secure, even if it is not required, or risk losing visitors that are scared away.</p>
<p>There are several different types of SSL certificate and the higher (more expensive) ones will still show the green bar in the address bar, but the norm will be to have one of the cheaper ones and if you don&#8217;t have any or it expires, the company backing the SSL cert (Cert provider not the retailer) goes out of business or has their master certificate rejected then you will be faced with a blocking screen when trying to get to your site which will prevent users from going there, with warnings that your site is insecure and should not be visited. This is obviously not good for business.</p>
<p>Google have also hinted that sites that use SSL certificates currently get a boost in the Google rankings over those who do not.</p>
<p>At CritchCorp Computers Ltd we have a quick and easy way for you to comply with this new Google rule for all our shared hosting customers you can purchase a fully managed SSL certificate from your yesDomains account or submit a support ticket <a href="https://shop.cc-computers.com/submitticket.php?step=2&amp;deptid=3">here</a> to get the ball rolling. It is quite an in-depth process but we will take care of it for you, with as little interaction as possible required by you. Please go <a href="https://shop.cc-computers.com/cart.php?gid=2">here</a> to get started.</p>
<p>The industry is working towards lowering the cost of SSL certificates to nothing and automating the install and renewal process, but that is still in development so for the time being you will need to purchase an SSL certificate in the normal way. If you want the users browser to light up in green then you need to select the Extended Validation (EV) certificate otherwise the cheaper normal one will suffice to prevent you being labelled as <span style="color: #ff0000;"><strong>NOT SECURE</strong>.</span> We have monthly or annual billing options to spread the cost but all certificates are annual commitments.</p>
<p><span style="color: #3366ff;"><em>We use Comodo, DigiCert, Symantec, Thwarte, GeoTrust and Trustwave certificates  that are strong providers in this field and highly unlikely to go out of business or have their master certificates rejected. This provides you with stability and reassurance that your certificate will not become invalid before it expires as does happen from time to time with smaller SSL providers.<br />
</em></span></p>
<p>If you want to read the Google blog entry about this; with their advertising spin on it then click <a href="https://blog.chromium.org/2018/02/a-secure-web-is-here-to-stay.html">here</a>. What this does do is add further costs to businesses. Whilst we absolutely agree that any site that accepts payments or collects user data should be secure, there are still many sites that do not and so forcing them to have this does seem unfair to us, but that is what the mighty Google has decided and so it shall unfortunately be.</p>
<p>There has been some discussion about the colour of the <span style="color: #ff0000;"><strong>NOT SECURE</strong></span>. The current <span style="color: #339966;"><strong>SECURE</strong></span> label is green and it is understood that the new <strong><span style="color: #ff0000;">NOT SECURE</span></strong> is going to be Red, although some discussions at Google say it will be more neutral, which ever it is it isn&#8217;t good for business.</p>
<p>Keep safe</p>
<p>CritchCorp Computers Ltd</p>The post <a href="https://www.cc-computers.com/google-forces-ssl-use/">Google Forces Sites to use SSL Certificates</a> appeared first on <a href="https://www.cc-computers.com">CritchCorp Computers Ltd</a>.]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>About Mat Honan&#8217;s Epic Hacking</title>
		<link>https://www.cc-computers.com/mat-honans-epic-hacking/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=mat-honans-epic-hacking</link>
		
		<dc:creator><![CDATA[CritchCorp]]></dc:creator>
		<pubDate>Mon, 27 Aug 2012 14:49:54 +0000</pubDate>
				<category><![CDATA[Informational]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Urgent Attention]]></category>
		<category><![CDATA[amazon]]></category>
		<category><![CDATA[apple]]></category>
		<category><![CDATA[backups]]></category>
		<category><![CDATA[customer service]]></category>
		<category><![CDATA[deleted]]></category>
		<category><![CDATA[documents]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[hotmail]]></category>
		<category><![CDATA[icloud]]></category>
		<category><![CDATA[ipad]]></category>
		<category><![CDATA[iphone]]></category>
		<category><![CDATA[mat honan]]></category>
		<category><![CDATA[pictures]]></category>
		<category><![CDATA[yahoo]]></category>
		<guid isPermaLink="false">http://www.cc-computers.biz/Blog/?p=180</guid>

					<description><![CDATA[<p>I am sure that you have all heard about Mat Honan&#8217;s very bad weekend by now, But just in-case you have not, here is an overview of what happened. There is a very good podcast that you can listen to if you want the full story or read the transcripts: http://www.grc.com/sn/sn-364.txt or you can read [&#8230;]</p>
The post <a href="https://www.cc-computers.com/mat-honans-epic-hacking/">About Mat Honan’s Epic Hacking</a> appeared first on <a href="https://www.cc-computers.com">CritchCorp Computers Ltd</a>.]]></description>
										<content:encoded><![CDATA[<p>I am sure that you have all heard about Mat Honan&#8217;s very bad weekend by now, But just in-case you have not, here is an overview of what happened. There is a very good podcast that you can listen to if you want the full story <del></del> or read the transcripts: <a title="Mat Honan Podcast on GRC" href="http://www.grc.com/sn/sn-364.txt" target="_blank" rel="noopener noreferrer">http://www.grc.com/sn/sn-364.txt</a> or you can read Mat&#8217;s story : <a title="Mat Honan&#039;s Epic Hacking" href="https://www.wired.com/2012/08/apple-amazon-mat-honan-hacking/" target="_blank" rel="noopener noreferrer">http://www.wired.com/2012/08/apple-amazon-mat-honan-hacking/</a></p>
<p>If you regularly keep up-to-date with security news then you will have heard all about this story. This is intended for those who do not keep up with the news or find it too complicated or technical to follow, or just don&#8217;t have time to keep up to date with this stuff. As this is an important story, I have written this brief article about here.</p>
<p>Firstly, who is Mat Honan? He is reporter for Wired magazine and former senior reporter for Gizmodo. He knows a thing or two about technology.</p>
<p>This is a brief sumary about what happened to him a couple of weeks ago. Just so you can be aware and not make the same mistakes as he did. He thought he was safe because he used secure long gibberish passwords, but that did not help him in this case.</p>
<p>In the space of one hour Mat&#8217;s entire digital life was destroyed. Here is the order of things that were done:</p>
<ol>
<li>Google account taken over, then deleted</li>
<li>Twitter account taken over</li>
<li>Apple ID taken over and remotely erased his iPhone, iPad and MacBook</li>
</ol>
<p>Here is how they did it and what you need to watch out for.</p>
<p>The hackers were only after his Twitter account as he has a nice handle (@mat). To get to this they destroyed his digital life. Firstly, they noticed that his Twitter account was connected to his personal website. On his personal website they found his GMail.com address. Using Google Mails account recovery they discovered that he had a @me.com address, which he used as the backup to receive password resets to.They also had his name and address, which they obtained form his website but could be obtained in a number of ways. Lets face it every time you order pizza you give your name and address, you probably chuck out lots of junk mail with your name and address on it. There are also numerous ways on line to get that information. So, with this information they phoned, yes phoned Amazon. Claiming to be Mat they said that they wanted to add a credit card to their account. With the Name and billing address they were able to do this and using a credit card number made up by a website devoted to generating numbers that conform to the algorithms used they added a card to his account. They then hung up and phoned back and said that they could not get in to their account (Mat&#8217;s account). They were then asked for their name, billing address and a credit card on file. Using the credit card they had just added they were then able to add a new email address to the account. They then went to the Amazon website and preformed a password reset to the new email address that they had just added.</p>
<p>They can now see all the credit cards that had been previously added to the account, including the real card that Mat uses. Granted it is only the last four digits of the card as that is what Amazon considers safe to show you (as do a lot of other companies). They now called Apple Care and said that they had lost access to their (Mat&#8217;s) @me.com account. Apple kindly helped this fake Mat to recover his password using a temporary password which they issue over the phone which you can then use to access the account and to change the password to the account. This was issued despite the fact that the hackers<strong> <em>could not answer any of the security questions on file!!</em></strong> In the end all they needed was his name address and yes, you guessed it the last four digits of a credit card on file.</p>
<p>Once they had hacked in to his @me.com account they could send a password reset from his Twitter account which went to his @me.com address and they quickly reset his twitter account password. This was there intended goal as they could now tweet in his name and upset his followers, <em><strong>just for the fun of it!</strong></em></p>
<p>Here is the horrible bit: In order to stop Mat from regaining control over his account, they did the following. Deleted his GMail account. Preformed a wipe on his iPhone, iPad and MacBook, thus deleting his entire and only copies of his daughters first year and a half pictures and pictures of relative who are no longer in this word. It was not the intention of the hackers to delete these things but just collateral damage to the main goal, his Twitter account.</p>
<p>You need to be aware of where your accounts lead to and what information you leak out on them. Information these days is very easy to get to because people do not protect it well enough.</p>
<p>Amazon has since confirmed that it will no longer accept information over the phone in this way. Apple has not confirmed yet that it has closed these obvious loop holes, however it did make immediate temporary message and stopped issuing temporary password over the phone, we are still waiting to see what their permanent fix will be.</p>
<p>It is important to note that the companies followed their procedures and the procedures let the customer down. We make it easy from a customer service point of view and that lets the bad guys get in too. It is a shame that we need to have any security at all, it would be nice if we could just have username and no need for a password, but we need passwords and we need to make sure that they are secure and the problem that most companies face is keeping the customer happy, wand secure and that is a tall order as most of the time convenience is the enemy of security. The easiest way to thin of it is a sliding scale with security on one side and convenience on the other. The more convenient we make it the less secure we make it.</p>
<p>Keep your personal data private and do not exposes it unnecessarily. As I have always said, best to have your own domain name and email address and not to use a free generic one for any of your key services, one that you can maintain complete control of and cannot be taken over in anyway by use of social engineering attacks, such as this one. Don&#8217;t get me wrong, there are uses for the free accounts but not as your main email address and not as password recovery addresses as these free accounts are constantly hacked in to by this and other methods. They are far too liable to this kind of attack.</p>
<p>&nbsp;</p>
<p>CritchCorp.</p>The post <a href="https://www.cc-computers.com/mat-honans-epic-hacking/">About Mat Honan’s Epic Hacking</a> appeared first on <a href="https://www.cc-computers.com">CritchCorp Computers Ltd</a>.]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
