Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Wednesday, June 03, 2026

More Scams to Watch Out For

The internet is a dangerous place these days and there's always one more new thing to watch out for. Right now, it's fake  CAPTCHAs

A real CAPTCHA (which stands for “Completely Automated Public Turing test to tell Computers and Humans Apart,” by the way — just rolls off the tongue, doesn’t it?) runs in your browser. It might ask you to click a box, identify images, or wait for a quick verification. What it shouldn’t do is ask you to send a text message, open your phone’s SMS app, tell you to press a strange combination of keys, or ask you to copy and paste anything into your computer.

Take a couple of minutes to read the article. It may save you a lot of grief later.  

Friday, May 29, 2026

Avoiding a Lockout of Your Google Account

If you had to pick an account that getting locked out of would cause the most headaches, your Google account would probably be up near the top of the list. That is assuming that you have a Windows PC and use Google Chrome, or an Android phone. Mac users may be able to skip this article.

Google, rightly. doesn't make it simple to get back into a locked out account. But they do provide more than one way of restoring your account access, including a new one mentioned in this article.
We'll start with the newest feature for account recovery, which is Recovery Contacts. This is a list of up to 10 people you specify, and when you're trying to get back into your Google account, they can be asked to confirm access in the same way that you might normally approve a prompt on your own phone (which is helpful if your phone is lost, for example).

I have a friend whose phone was stolen while travelling. He was not able to recover his account and lost access to many valuable photos and a YouTube account he used to promote his business. If he'd followed some of the steps in this article, that wouldn't have happened. 

It may take some time and be a bit of a hassle to get your account set up so you can recover it, but it's worth it. 

 

Tuesday, May 12, 2026

What the Heck is Happening in Alberta?

Over the past couple of months it's become clear that the usual discontent Albertans have with the federal government has morphed into something far more concerning. I lived in Northern Alberta for five years until 1984 and there was no love lost for Ottawa and especially Pierre Trudeau and his National Energy Program. But what is happening now is very different. 

In this post, I'm going to highlight several recent articles that cover different aspects of the current political scene in Alberta. 

For a starter there's this lengthy piece (gift link) from the Toronto Star:  "I went home to the heartland of Alberta independence. Even after covering Donald Trump for 10 years, I was still terrified by what I found." by James Maclennan. I included this as it was written by someone who grew up in Alberta and provides a good overview of the current separation campaign. The scary quote:

We like to imagine we are immune somehow from whatever it is that has torn the American polity apart so violently over the past 10 years, that what is happening there could never happen here. I promise you it can. In Alberta, it already is.

In this article Dean Blundell provides (in his words). "The Alberta File: How a Foreign-Backed Separatist Cabal Doxxed Three Million Albertans, Lawyered Up Against Treaty Rights, After Being Promised "500 Billion" From The Trump Regime: A definitive, on-the-record accounting of what the hell is happening in Alberta — and why every Canadian, every Treaty signatory, and every NATO ally should be paying attention."

Yes, he can be a bit long winded, but the article provides more history and context than most of the pieces I've seen in the major media and ties it to influence from the US and wider international disinformation campaigns. 

What is happening in Alberta in the spring of 2026 is a stress test of Canadian sovereignty conducted, in part, by a foreign power in friendly contact with a domestic separatist movement, lubricated by an algorithmically amplified information environment that pays Dutch YouTubers to tell Albertans separation is inevitable, organized through evangelical and convoy networks with documented histories of contempt for the state, and enabled by a provincial government that rewrote its own constitutional safeguards to accommodate the operation."

In The Leningrad Hot Dog Maker and the Destruction of Canada Charlie Angus takes a deep dive into the Russian disinformation machine and how it might affect Canada, even if there is no referrundum.

It won’t matter that the separatists don’t have the votes to succeed. They will drive false claims that the referendum was stolen or encourage a convoy of extremists to set up camp on the Coutts border to call for American help.

Imagine the hate that will be generated against First Nation people by online bots if the courts shut down the referendum.

The Donbas playbook is about weakening our nation and creating internal chaos. A full on hate storm is brewing. The Prime Minister needs to take this threat very seriously indeed.

Finally, Patrick Lennox of The Walrus asks How Did an Alberta Separatist Group Get Its Hands on the Voter List? There will no doubt be court cases arising from this and it will be interesting to see just how high up in the Alberta government they reach.

That 2.9 million voting-age Albertans have had their personal information circulating in the Maple MAGAsphere poses a massive public safety risk and exposes the October 19 referendum process even further to foreign influence from the global far right. We can safely assume that Alberta’s list of electors has been captured by agents of authoritarian regimes who wish Canada, as the last standing democracy in North America, all sorts of harm, unrest, and collapse.

The implications of this breach, which is likely the largest in Canadian history, will come into further relief in the coming days and weeks leading up to the referendum the UCP seems hell-bent to bring on.

That will do for now. I could have easily included sevral more articles, but the ones above paint a pretty detailed, and not pretty, picture of what's going on. 

 


 





Wednesday, April 29, 2026

Featured Links - April 29, 2026

Links to things I found interesting but didn't want to do a full blog post about.

A small boat travels across the calm Lake Ontario
A calm day on the lake

Wednesday, April 22, 2026

Featured Links - April 22, 2026

Links to things I found interesting but didn't want to do a full blog post about.

Boats covered for the winter and waiting for summer
Boats at the marina waiting for summer
  • Game of drones. "As the federal government spends billions on military modernization, Canadian drone innovators are vying to meet the moment in the sky, on land and in the water." Good coverage of a new industry with lots of photos. 
  • Power imbalance. "James S.A. Corey on The Captives War, The Book of Daniel, and how the only way to survive an alien invasion might be appeasement." A fascinating interview with the authors of the wonderfu Expanse series. 
  • What Discoveries Might Be Hiding in the Artemis 2 Images and Data? "NASA’s Artemis 2 mission produced a wealth of data that experts will be analyzing for years to come."
  • They Are Killing Our People. "This past week, the Mikisew Cree First Nation of Alberta released a report on the massive cancer rates in their community. The Alberta government withheld key medical statistics, and the federal government dragged their feet. The Feds promised to fund a study that would take 10 years to complete. And so, the community paid for their own research." This is what happens when you live downstream from the biggest polluter in Canada. 
  • 'For All Mankind' alternative timeline vs reality: How Apple TV's sci-fi show diverges from history.. "How do "For All Mankind"'s six decades of space exploration "history" compare with the real thing?" Spoiler warning for those who haven't watched the show,
  • Why Medieval Bread Was A Superfood While Your Modern Bread Makes You Sick (YouTube). "There's a significant issue with the bread we consume today. While bread was once a fundamental part of civilizations, sustaining families and armies, modern bread often causes gut issues, blood sugar spikes, and leaves us feeling unsatisfied. This food history explores how the bread industry has changed, contrasting today's offerings with the traditional bread that nourished our ancestors. We conduct a food industry case study, examining how the history of bread, including ancient grains and sourdough, shows a stark difference from what we find on shelves now."
  • The Making of Miles Davis' "Birth of the Cool".  A long essay on one of the true classics of 20th century music. 
  • Facebook and Instagram Tighten Censorship Rules for Saying “Antifa”. 'Meta’s new rules let it ban users or suppress comments that include the word “antifa” alongside “content-level threat signals.”'
  • How two mathematicians created an equation that quietly runs the planet. "The Diffie-Hellman key exchange secures everything from your text messages to government secrets." This article has the best explanation I've seen ofhow public key cryptography works. 
  • Winner of top Sony World Photography Awards $25,000 prize revealed. "With nearly half a million entries, the judges must have had a tough job choosing the winners of this year’s Sony World Photography Awards. The competition is now in its 19th edition, and the overall Photographer of the Year 2026 title has been named as Citlali Fabián with the series ‘Bilha, Stories of My Sisters’."
  • Inside the stunning fall of the Maple Leafs: Chaos, dysfunction and AI. For the (probably few) hockey fans reading this blog, a deep dive into the latest pathetic season of the Toronto Maple Leafs. I was in high school the last time this team won the Stanley Cup. The way they are playing, I may not live long enough to see them win one.
  • How Ukraine became a drone factory and invented the future of war. "Ukraine has responded to a war it didn’t start by creating an industry it doesn’t want, but could the nation's drone expertise help it rebuild? To learn more, New Scientist gained exclusive access to the research labs, factories and military training schools behind Ukraine’s drones."

Tuesday, April 21, 2026

The Mythos Problem

Last week, Anthropic announced that its Mythos AI tool had found multiple serious problems with many open source software programs, including some that are core services on the internet and were long thought to be secure. They are not releasing Mythos publicly, instead opting to provide it to several major internet companies (Microsoft, Apple, Google, and the like) so that they can use it to test their software for vulnerabilities. 

This has not escaped the notice of the press. (BBC, Scientific American and many more).

Security expert and long-time podcaster, Steve Gibson, thought Mythos significant enough that he devoted the entirely of last week's Security Now! podcast to it. It's the best coverage of the topic that I've seen. And he has concerns. From his show notes (which are extensive):
Okay. Let me interrupt here to insert a “Holy EFF” explicative. What Mythos autonomously did, without any explicit guidance beyond just being asked to, was to discover and invent an exploit which deeply manipulated FreeBSD’s Network File System server by using Return Oriented Programming. Since FreeBSD’s NSF server is already so secure, the AI pseudo-attacker was not able to insert its own code. So it caused the server to selectively re-execute its own code, code it already contained at the tail ends of a series of 20 different existing subroutines. This enabled it to manipulate the internal state of the NFS file server to grant root access to an unauthenticated remote attacker who was unknown to, and had no account on, the machine.
Let me be very clear: This capability is truly nothing short of terrifying. If Project Glasswing has the side-effect of launching Anthropic’s forthcoming IPO into the stratosphere then as far as I’m concerned they’ve earned and deserve it. 

And this:

 And this admits to the MUCH bigger problem. I suppose we should have seen this coming. But it’s here: We all know that only a small fraction of the world’s already deployed code can and will ever be made “Mythos safe”. It’s great that AWS, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorganChase, the Linux Foundation, Microsoft, NVIDIA, and Palo Alto Networks will all get to have access. And apparently some 40 others who are equally deserving, or who are presumably the owners of many of those thousands of other bugs that Mythos found. But what of everyone else?

We could truly be poised upon the precipice of some seriously rough times. As I said, I suppose we should have seen this coming. The biggest surprise is that everything about this brave new AI world is coming at us much faster than we expected, or even still now expect. 

I've only touched on some of what he discussed in the podcast. For me, the biggest worry is all of the IOT and embedded devices that either can't or won't be upgraded and which may now be at risk because they contain embedded code libraries that are now insecure.

Interesting times indeed.


Friday, April 17, 2026

We're Toast 65

It's well past time for another one of these posts. 

This post is a collection of links that support my increasingly strong feeling that the human race (or at least our technological civilization) is doomed. 

a depiction of Planet Earth being toasted like a marshmelow over a campfire.
Our toasting Earth

Monday, March 30, 2026

The Peril of Tracking Pixels

I've known about tracking pixels for a long time but never figured that they were much of a problem. Of course, they do reveal that you read an email or accessed a web site, but there are riskier things to worry about reading emails or browsing the web. 

But things have changed, as Steve Gibson pointed out in the latest installment of his Security Now podcast. From page 8 of his show notes:

I just learned how far tracking pixels have evolved. They’re easy to miss because, much like cookies, the code their presence on any webpage allows to run is hidden from us. But last Wednesday the 18th, the security researchers at Jscrambler shared what they had recently learned about what TikTok and Meta are doing.

Their headline was: “Beyond Analytics: The Silent Collection of Commercial Intelligence by TikTok and Meta Ad Pixels”. As we’ll see, this writing is targeted at web merchants who are voluntarily adding these insidious tracking pixels to their sites’ own webpages without a full appreciation or understanding of the privacy implications for their visitors. 

It turns out that Meta and TikTok are grabbing both personal information (names, addresses, phone numbers, credit card information) and a log of just about everything that people are doing on sites with these tracking pixels. From the report, Gibson quotes this: 

Meta’s pixel includes a feature called Automatic Events, which is enabled by default. The feature automatically scans page elements and captures information such as checkout interactions and visible payment card details, including the last digits, expiration date, and cardholder name. Since this is the default behavior and not an opt-in, merchants may not be aware that the pixel is collecting this information. On separate sites, Meta captured recipients' full names and delivery addresses when users selected address options during checkout.

This information can be used by Meta to compile a huge database of behaviour that it can sell. It's also presents a risk to anyone using those sites in the case of a security breach at Meta and because the information being sent to Meta may not be encrypted, making it a vulnerability should the user be the target of an attacker. 

Both TikTok and Meta's pixel code can load and begin transmitting data before the website's consent management system has time to block it, meaning information can leave the browser before the user’s choice is applied. Even more concerning is that data may be transmitted in cleartext—occasionally within the request URL itself—exposing sensitive information to browser histories, server logs, intermediaries, and debugging tools.

This vulnerability stems not only from the pixel’s data-collection methods but also from misconfigurations during its implementation or from issues with the website's underlying architecture. Consequently, the attack surface is significantly broader than a surface-level analysis suggest

Using Firefox, which supports the full uBlock Origin, is probably a good idea. Google Chrome supports uBlock Origin Lite (which I am using), but it's not as effective as the original uBlock Origin in blocking tracking pixels, web beacons, and tracking scripts. 

Yet another item to add to my To Do list. 

Wednesday, March 25, 2026

The Bloated Web Page

I'm constantly annoyed and frustrated by the crap that websites are blasting my phone with when I try t o read an article or browse a web page. Popups, autoplaying videos that refuse to close, ads that jump out and shove the text I'm reading out of the way;; I'm sure you've seen it all.

If you want to get a better idea of what's happening and why, read The 49MB Web Page by Shumham Bose, a developer and user interface design expert. The article was triggered when they looked behind the scenes at what was happening when they opened an article from The New York Times website and found that the browser downloaded 49 MB of data. (That's roughly equivalent to an album of MP3s or 50 books in EPUB format). 

When you open a website on your phone, it's like participating in a high-frequency financial trading market. That heat you feel on the back of your phone? The sudden whirring of fans on your laptop? Contributing to that plus battery usage are a combination of these tiny scripts.

I don't usually see most of this on my PC because I run an ad blocker (uBlock Origin Lite) that blocks much of the crap that the article discusses.  I use Firefox with uBlock Origin as my default browser on the phone, despite the annoyance of having different browsers on my PC and phone. (I know, I know; it's just laziness that keeps me from using Firefox on my PC). Apps, where publishers seem to consider pushing ads their primary purpose in life, are also problematic. 

I should point out that there are real security problems inherent in the use of programmatic ad auctions and tracking pixels and their associated scripts. (I'll have another post about this tomorrow or Monday). 

This is the best article about web design that I've seen in a very long time. Even if you're not particularly technical, it's worth reading just to understand why your browsing experience is so unpleasant.

Wednesday, March 11, 2026

Featured Links - March 11, 2026

Things I found interesting but didn't want to do a full blog post about.

A small brown and white cat sitting in an empty box of lactose-free yogurt
Lactose-free cat



Monday, December 29, 2025

A Futurist Looks Ahead to 2026

Amy Webb is an American author, futurist, and founder to the Future Today Strategy Group. I read her book, The Genesis Machine, a few years ago and was seriously impressed. 

Every year she publishes a newsletter article looking at what happened during the year and what it portends for the coming year. If you want to get a handle on these topsy turvy times, it's essential reading. 

She starts out by looking at what she expects to be the big themes for 2026. These are the first three. (All are described in detail in the newsletter)

  1. Convergences will drive the next wave of disruption and growth. 
  2. The post-search internet. 
  3. The rise of unlimited labor. 
After that, she looks at some of the signals to watch for in 2026.

At FTSG, we define signals as indicators of emerging change. Longtime readers of this annual letter know that 18 years ago, I created an end-of-year inventory of signals to methodically reflect on the prevailing forces that are likely to influence the world ahead. It proved to be an invaluable catalogue months later for our clients and partners, so I've continued to publish this end-of-year letter with impactful signals for the entire FTSG community.
Cataloging signals is a practice I've refined and honed for two decades. My annual inventory is a way to think about the evolution of technology, science, business, and society as part of a long continuum.

Below is a short list (not hyperbole!) of signals I collected from the past year that are likely to shape the year ahead.

This is a long newsletter article but well worth the time it takes to read through it. A good idea would be to bookmark and look at it again in mid-year.  

Tuesday, November 25, 2025

Featured Links - November 25, 2025

Things I found interesting but didn't want to do a full blog post about.

A lifeguard station at Scarborough Bluffs
Lifeguard station at Scarborough Bluffs
  • Reinventing the Subsistence Economy. "How Energy and Food Decoupling Rewrite the Map of Post-Growth Futures." An optimistic look at a possible future from Karl Schroeder.
  • The Terminator Future Has Arrived. "Gaza represents a future of warfare that will be repeated elsewhere as the algorithms are proving efficient, merciless and remorseless."
  • The Worst Part About Publishing a Book in 2025 Is The New Kind of Spam. Authors are getting buried in targetted AI-authored spam. 
  • Google’s New Gmail Upgrades—Why You Must Choose Carefully. Unless you live in the EU, Google may be opting you in to giving them access to your private data.
  • Russian Unreality and American Weakness. "Notes from a bizarre moment of diplomatic history." An absolutely devastating take down of the proposed "peace plan" to end the Ukranian war from historian Timothy Synder. 
  • Open the pod bay doors, HAL (Arguing with A.I.). A detailed post showing how AI can provide misleading results, with examples.
  • Bitcoin isn't anonymous — investigators can trace every transaction on the blockchain. Just in case you thought all those drug buys were safe. 
  • Wednesday, October 29, 2025

    Featured Links - October 29, 2025

    Things I found interesting but didn't want to do a full blog post about.

    Trees showing fall colours in the park
    Autumn colours in the park

    Tuesday, October 21, 2025

    Featured Links - October 21, 2025

    Things I found interesting but didn't want to do a full blog post about. 


    Tuesday, July 15, 2025

    Featured Links - July 15, 2025

    Links to things I found interesting but didn't want to do a full blog post about.

    A large patch of daisies
    Summer daisies

    Tuesday, June 03, 2025

    Featured Links - June 3, 2025

    Links to things I found interesting but didn't want to do a full blog post about.

    A row of boats at the marina with an empty dock in the foreground
    Springtime at the marina

    Monday, May 26, 2025

    Featured Links - May 26, 2025

    Links to things I found interesting but didn't want to do a full blog post about.

    The main building, a small barn, at the Crooked Creek Garden centre with shelves of plants off to the right side.
    Crooked Creek, our favourite garden centre

    Tuesday, May 20, 2025

    Featured Links - May 20, 2025

    Links to things I found interesting but didn't want to do a full blog post about.

    A basket of pink flowers hanging on a fence
    Spring flowers
  • Space United Us. Putin Tore Us Apart. "Former International Space Station commander. Watching my Russian cosmonaut friends turn to the dark side was a troubling lesson in how easily normal people can be bribed into supporting a tyrant."
  • World’s first personalized CRISPR therapy given to baby with genetic disease. "Treatment seems to have been effective, but it is not clear whether such bespoke therapies can be widely applied." Given that the US wants to ban MRNA technology, can banning CRISPR behind?
  • The First Human to Undergo In Vivo CRISPR 2.0 Personalized Genome Editing. "Potentially a lifesaving intervention with major implications."  This article goes into more detail than the article from Nature.
  • Not saying it's aliens: SETI survey reveals unexplained pulses from distant stars. "In a recent paper, veteran NASA scientist Richard H. Stanton describes the results of his multi-year survey of more than 1,300 sun-like stars for optical SETI signals. As he indicates, this survey revealed two fast identical pulses from a sun-like star about 100 light-years from Earth that match similar pulses from a different star observed four years ago."
  • There's a huge Cold War-era nuclear bunker in Ontario 600 feet underground. "Buried 600 feet beneath solid granite in Ontario lies a colossal relic of Cold War military engineering — the NORAD North Bay Underground Complex, better known simply as 'The Hole.' The massive underground fortress was Canada’s front line in the defence of North America at a time when the threat of nuclear war felt imminent. Built at the height of Cold War tensions, the complex stands as the most ambitious and heavily fortified military project in Canadian history." I went on a tour of the SAGE base in 1983; it was seriously impressive.
  • I Went to Rome to Understand What’s Happening in America. What I Found Was a Warning. "A pilgrimage to the ruins of empire reveals a terrifying truth: America’s democracy is at the tipping point—and Trump is no Marcus Aurelius."
  • Scientists have been studying remote work for four years and have reached a very clear conclusion: “Working from home makes us happier.” Absolutely. I much preferred it to having to spend 2-1/2 or 3 hours a day getting to and from the office. 
  • Ronnie Wood: ‘I was thinking, I want to be in the Rolling Stones. Then a car pulled up with Mick and Charlie’. "Galleries, gigs and grand old friends – the veteran rocker reflects on a life of lucky timing and grit."
  • For this CVS Health developer, making tech more accessible is personal. "Apple’s ‘Accessibility Nutrition Labels’ will put investments in inclusive design in the spotlight. But Cory Joseph says companies don’t need to be huge to embrace accessibility." These are a really good idea and I hope Google copies them. 
  • We Finally Know Why Ancient Roman Concrete Lasts Thousands of Years. They need to start using this on the Gardiner Expressway. 
  • JerryRigEverything says 'do not buy' the Pixel 9a despite it passing a stress test. Google has made a bad design decision here and it would keep me from buying it.
  • Beware SVG graphics used to Bypass Microsoft 365 Security Measures. "SVG and invisible Unicode is being increasingly used to hack Microsoft 365 and Google/Gmail users even with multi-factor authentication (MFA).  It’s possible because of significant enhancements in the Tycoon 2FA platform."
  • Tuesday, April 22, 2025

    Featured Links - April 22, 2025

    Links to things I found interesting but didn't want to do a full blog post about.

    A large wooden shed, very badly weathered, and looking like it's ready to fall down.
    I am surprised this shed lasted the winter. 

    Monday, April 07, 2025

    Featured Links - April 7, 2025

    Links to things I found interesting but didn't want to do a full blog post about.

    A floor-cleaning robot
    A floor-cleaning robot