Categories
security

An ingenious – and dangerous – new scam on “automatic debiting”

I received this email today. Clearly a scam. So curious, I called the number, and asked to cancel my “subscription”.

A man who called himself “Gerry”, clearly in an overseas call center, proceeded to tell me it was no problem to cancel it, they would just need a form filled out.

The scammer then routed me to Anydesk.com, a remote control product, and asked me to download this tool.

I hung up.

Here are some of the things that could happen if I had continued on this path:

  • He would take control of my computer and install malware and steal information.
  • He would run a fake “scan” to show me that my computer was “infected”, thus selling me some other suspect product.
  • Or, any number of other scenarios too awful to contemplate.

If you get such a notice, delete it and move on. It’s a complete scam.

(I’ve provided the full text of the scam below so that people searching will find this post and hopefully not get fleeced.)

Hello Customer ,

Thank You for your payment. Your account has been debited with $398.99 for the Auto Renewable plan of your McAfee family. The charges might reflect within a few moments to 24 hours. For any query or assistance please reach out to us @ +1 (903) 493-9025  / +1(903) 493-9025   .

Invoice Number –YHK83676

ProductIssue DateExpiration DateQtyAmount
McAfee Security 360 PlanJune, 14, 2021June, 13, 20261$397.99
PC Solution 2811 Mission College Blvd, Santa Clara, CA 95054, USA 

 We are an associate of the Geek Squad.

You are important:-     

In case of any dispute or query or to cancel the subscription please reach out to our support team @ toll free 

+1 (903) 493-9025     / +1 (903) 493-9025    and get a full refund. Please note you have 24 hours to report a dispute.

Thank You.

#PCSolutions_ McAfee

Categories
finance

Anatomy of a SPAC

SPACs (Special Purpose Acquisition Companies – aka “blank check companies”) are the new new new thing, but they really aren’t. Blank check companies have been around for some time, and in the past, there were more failures than successes.

Infographic: SPAC Boom in the U.S. | Statista

Now, everything has changed and everyone wants to do things with SPACs. There are powerful benefits – a fast path to an IPO without a lot of the hassle and a path to liquidity.

However, a fair number of executives and investors aren’t entirely clear on the process, so I thought I’d jot down some notes as to what a SPAC is and how the process operates — at least at a high-level.

Here’s how a SPAC works (using approximates):

  • A group of well-connected execs (the sponsor) partner with an investment bank to do an IPO.
  • The sponsor doesn’t receive any cash compensation, apart from expenses. However, in exchange for suffering for up to two years without any salary, they get to purchase 20% of the SPAC as “founders shares” for a nominal amount of money. (The economics are ridiculously in favor of the sponsor but it’s Wall Street, so whatever.)
  • The sponsor will also buy warrants to fund the SPAC’s operations (warrants are similar to options1). This is done by buying several million warrants at $1.50 each to purchase the stock at $11.50.
  • Proceeds from the IPO are put into a trust. A relatively small amount of money from the IPO will be be put aside to fund expenses.
  • The sponsor usually has 18-24 months to find a target company to buy. Once they agree to buy a company, there is a process of getting approval from the shareholders. Shareholders who don’t like the deal can get their shares redeemed from the trust. (yep, one of the few places in Wall Street where there is a “money back guarantee”).
  • If a SPAC doesn’t find a company to buy, they also have to give the money back from the trust.
  • The shares offered in a SPAC IPO are not typical – they are hybrid securities, called “units”, each unit being a share with a warrant component. The stock is almost always priced at $10 (it’s a nice, easy number). And the warrants typically exercise at $11.50.
  • The ratio of warrants per share is referred to as warrant coverage, an investment term which means how many warrants are offered as a percentage of a share offering. Less warrant coverage means less dilution for the target company. Units typically have 1/2 or a 1/3 of a warrant for every share. This is why when you look up a SPAC on an exchange, it might look odd, in that there will also be a warrant portion.
  • To make it clear, let’s say you have 10 units, each with 1/2 a warrant. You would have 10 shares and 5 warrants (warrants are never exercisable partially, they are only exercisable in full).
  • The stock becomes free-trading and may go up in value2.

After the SPAC finds a target company, the real work starts.

  • The SPAC will offer a price to the acquiring company – usually a competitive price. It’s a sellers market and SPACs are anxious to get deals done. So they pay well. However, they usually pay largely in stock and hence, if the target company performs poorly, it will not go well for everyone.
  • The SPAC will solicit shareholder approval for the SPAC. This will be done through a proxy statement (the form used when soliciting shareholder votes). If the company is also registering new securities, it would use a Form S4 (which combines a proxy statement with a registration of the new securities). This is useful to know as you find out a lot in a proxy statement, such as exec comp, business relationships, outlook, etc. in a relatively simple and clear format.
  • This shareholder approval is like a mini-roadshow. At this point, the target company and the SPAC will do price discovery to see if the deal is marketable. If investors yawn at the deal and it’s not appealing, the deal may get scrapped.
  • In some cases, a SPAC will want to raise additional capital during the merger. This may be used to buy out existing shareholders of the target company, or to provide additional capital to the combined entity.
  • The additional capital may be raised in the form of debt, but is often done in the form of a Private Investment in Public Equity (PIPE). PIPEs are common instruments on Wall Street for public companies raising money in a fast, efficient method. Investment funds are active in this area, so the buyers are there; and the paperwork and process is relatively straightforward.
  • If the shareholders approve and all the paperwork is proper, the merger is done and the SPAC goes away and the target company becomes the new public entity.

Dilution

Dilution is an important consideration for the target company. Let’s look at some basic math. To keep things simple, I’ve kept fees and warrants out of the picture for now. The fees are important, but the warrants become very important. More later.

Let’s say we have a SPAC IPO (“Trifecta Spac”) with 30 million shares, offered at $10/share. 20% of the post-IPO shares are reserved for the sponsor. The IPO would look like this:

Oversimplified, the resultant cap table would look something like this:

The sponsors find a company, “Unobtanium Electric Cars”. They offer $1 billion to acquire this company, payable partly in cash and partly in stock. Like a typical M&A deal, the $1 billion figure would be on a Total Enterprise Value/Debt Free Cash Free basis (simply, the price of the company without regard to debt and cash).

Now, the cash portion is tricky, because there is still a chance that shareholders might redeem, so they need to hold some aside for potential shareholder redemptions (in addition to the fact that the newly combined entity likely needs to have cash on the balance sheet).

So the sponsor offers $150 million in cash, and $850 million in stock:

The post-merger cap table would then look something like this.

However, there is a desire to raise additional capital at the time of the merger. The two entities raise $200 million through a PIPE, concurrent with the close of the merger. The price of the PIPE offering will be $10/share. In that case, the result looks something like the following:

Warrants

Warrants are a key part of a SPAC, in that they add extra return for the sponsors and the initial investors.

Warrants are usually exercisable at 15% above the initial IPO price, or $11.50 However, the SPAC will often limit the upside on warrants by forcing a redemption if the stock exceeds $18 (effectively capping the gains).

There are generally two warrants applicable to a SPAC deal:

  • The Sponsor Warrants: The SPAC sponsor initially purchases warrants to fund the SPAC (and to generate more upside for the sponsor). These warrants are typically priced at $1.5 per warrant at an exercise price of $11.50. Most SPACs raise $7-$10 million by this method. Let’s assume Trifecta Megaspac raised $7.5 million at $1.50/warrant. This makes for 5 million shares exercisable at $11.50/share.
  • The Unit Warrants: These are the warrants provided to the initial investors. Since most deals these days are being done at 33% warrant coverage (meaning, for 3 shares, there is 1 warrant), we can assume that Trifecta, with 24 million units, would have 8 million warrants available.

So, if your math is quick, we have 13 million shares as an overhang. These will be dilutive starting at $11.50/share. However, we should look at the whole picture (the Treasury Stock Method, which assumes that all the in-the-money warrants will be exercised) to really understand the fully dilutive picture.

So at $18 we would have a picture of something like the following:

That’s the big picture and again, my math does not include fees, and fees payable to the SPAC board, and some additional dilutive effects of warrants not covered here (and probably many other things). It’s illustrative.

If you are seriously considering a SPAC, get a good banker to represent you on the sell-side. And if you partner with a SPAC, remember that you’ll need to be every bit as good as a real public company. You’ll need the networks in place to market the new merged entity (which a good SPAC can help with), you’ll need to have your financial house in order and you’ll need to run like a real public company.

The SPAC offers major benefits over going public directly: The paperwork is relatively straightforward and you’ll have very clear picture as to what the market appetite for your company is before going through a full IPO process (speed to market is no different between an IPO and a SPAC). On the downside, you could do the deal at $10/share and find yourself being a crappy $2 stock in a year. So do your homework and get good help. It means a lot.

If I’ve made any errors, just email me or put something in the comments.

References:

https://www.kirkland.com/publications/private-investment-and-family-office-insights/2021/01/spac-overview-and-the-current-market

https://www.pwc.com/us/en/services/audit-assurance/accounting-advisory/spac-merger.html

https://corporatefinanceinstitute.com/resources/knowledge/strategy/special-purpose-acquisition-company-spac/

https://seekingalpha.com/article/4403134-what-is-spac-everything-spac-and-how-works-video

https://www.mayerbrown.com/-/media/files/perspectives-events/publications/2020/10/top-10-practice-tips-pipe-transactions-by-spacs.pdf

  1. 1 SPAC warrants are similar to options, with some exceptions, most importantly a) their availability may be triggered on certain events such as revenue or the strength of the company’s share price over time, and b) the money for the warrant exercise goes directly to the company’s treasury. []
  2. However, any increase is speculative; the intrinsic value of the stock is the offering price (the $10). That’s what the “guarantee” is behind the stock. Anything excess is speculation. So if you find a SPAC trading at $15 and you’re excited about it, you only have the guarantee of the $10 held in trust []
Categories
security

A preliminary look into who was hacked in the Sunburst attack

At Prevasio, we started to narrow down those potentially affected by the Solarwinds hack as the Sunburst used a DGA (Domain Generation Algorithm) that gives us a glimpse into who may have been infected.

The list (with disclaimers) follows:

Decoded DomainMapping (Could Be Inaccurate)
hgvc.comHilton Grand Vacations
AmerisafAMERISAFE, Inc.
kcpl.comKansas City Power and Light Company
SFBALLETSan Francisco Ballet
scif.comState Compensation Insurance Fund
LOGOSTECLogostec Ventilação Industrial
ARYZTA.CARYZTA Food Solutions
bmrn.comBioMarin Pharmaceutical Inc.
AHCCCS.SArizona Health Care Cost Containment System
nnge.orgNext Generation Global Education
cree.comCree, Inc (semiconductor products)
calsb.orgThe State Bar of California
rbe.sk.caRegina Public Schools
cisco.comCisco Systems
pcsco.comProfessional Computer Systems
barrie.caCity of Barrie
ripta.comRhode Island Public Transit Authority
uncity.dkUN City (Building in Denmark)
bisco.intBoambee Industrial Supplies (Bisco)
haifa.eduUniversity of Haifa
smsnet.plSMSNET, Poland
fcmat.orgFiscal Crisis and Management Assistance Team
wiley.comWiley (publishing)
ciena.comCiena (networking systems)
belkin.comBelkin
spsd.sk.caSaskatoon Public Schools
pqcorp.comPQ Corporation
ftfcu.corpFirst Tech Federal Credit Union
bop.com.pkThe Bank of Punjab
nvidia.comNVidia
insead.orgINSEAD (non-profit, private university)
usd373.orgNewton Public Schools
agloan.adsAmerican AgCredit
pageaz.govCity of Page
jarvis.labErich Jarvis Lab
ch2news.tvChannel 2 (Israeli TV channel)
bgeltd.comBradford / Hammacher Remote Support Software
dsh.ca.govCalifornia Department of State Hospitals
dotcomm.orgDouglas Omaha Technology Commission
sc.pima.govArizona Superior Court in Pima County
itps.uk.netInfection Prevention Society (IPS)
moncton.locCity of Moncton
acmedctr.adAlameda Health System
csci-va.comComputer Systems Center Incorporated
Redacted(law firm – redacted)
keyano.localKeyano College
uis.kent.eduKent State University
alm.brand.dkSydbank Group (Banking, Denmark)
ironform.comIronform (metal fabrication)
corp.ncr.comNCR Corporation
ap.serco.comSerco Asia Pacific
int.sap.corpSAP
mmhs-fla.orgCleveland Clinic Martin Health
nswhealth.netNSW Health
mixonhill.comMixon Hill (intelligent transportation systems)
bcofsa.com.arBanco de Formosa
ci.dublin.ca.Dublin, City in California
siskiyous.eduCollege of the Siskiyous
weioffice.comWalton Family Foundation
ecobank.groupEcobank Group (Africa)
corp.sana.comSana Biotechnology
med.ds.osd.miUS Gov Information System
wz.hasbro.comHasbro (Toy company)
its.iastate.edIowa State University
amr.corp.intelIntel
cds.capilanou.Capilano University
e-idsolutions.IDSolutions (video conferencing)
helixwater.orgHelix Water District
detmir-group.rDetsky Mir (Russian children’s retailer)
int.lukoil-intLUKOIL (Oil and gas company, Russia)
ad.azarthritisArizona Arthritis and Rheumatology Associates
net.vestfor.dkVestforbrænding
allegronet.co.Allegronet (Cloud based services, Israel)
us.deloitte.coDeloitte
central.pima.gPima County Government
city.kingston.Kingston City, Australia
staff.technionTechnion – Israel Institute of Technology
airquality.orgSacramento Metropolitan Air Quality Management District
phabahamas.orgPublic Hospitals Authority, Caribbean
parametrix.comParametrix (Engineering)
ad.checkpoint.Check Point
corp.riotinto.Rio Tinto (Mining company, Australia)
intra.rakuten.Rakuten
us.rwbaird.comRobert W. Baird & Co. (Financial services)
ville.terrebonnVille de Terrebonne
woodruff-sawyerWoodruff-Sawyer & Co., Inc.
fisherbartonincFisher Barton Group
banccentral.comBancCentral Financial Services Corp.
taylorfarms.comTaylor Fresh Foods
neophotonics.coNeoPhotonics (optoelectronic devices)
gloucesterva.neGloucester County
magnoliaisd.locMagnolia Independent School District
zippertubing.coZippertubing (Manufacturing)
milledgeville.lMilledgeville (City in Georgia)
digitalreachincDigital Reach, Inc.
deniz.denizbankDenizBank
thoughtspot.intThoughtSpot (Business intelligence)
lufkintexas.netLufkin (City in Texas)
digitalsense.coDigital Sense (Cloud Services)
wrbaustralia.adW. R. Berkley Insurance Australia
christieclinic.Christie Clinic Telehealth
signaturebank.lSignature Bank
dufferincounty.Dufferin County
mountsinai.hospMount Sinai Hospital
securview.localSecurview Victory (Video Interface technology)
weber-kunststofWeber Kunststoftechniek
parentpay.localParentPay (Cashless Payments)
europapier.inteEuropapier International AG
molsoncoors.comMolson Coors Beverage Company
fujitsugeneral.Fujitsu General
cityofsacramentoCity of Sacramento
ninewellshospitaNinewells Hospital
fortsmithlibraryFort Smith Public Library
dokkenengineerinDokken Engineering
vantagedatacenteVantage Data Centers
friendshipstatebFriendship State Bank
clinicasierravisClinica Sierra Vista
ftsillapachecasiApache Casino Hotel
voceracommunicatVocera (clinical communications)
mutualofomahabanMutual of Omaha Bank

† In this case, the company in question has reached out to me directly and asked that they not be listed. The company had performed a forensic review and believes they are not affected. In the interest of transparency, I can provide more details if contacted directly.

Categories
security

The Sh*tstorm of the Solardwinds hack

Pretty simple hack in concept – alleged Russian actors hacked an update package for Solarwinds Orion software (a sophisticated software for enterprise and institutional managing network resources).

This is an extremely crafty hack. An update package from Solarwinds Orion is uploaded onto the Solarwinds site. It’s even digitally signed.

According to Fireeye’s excellent writeup:

The trojanized update file is a standard Windows Installer Patch file that includes compressed resources associated with the update, including the trojanized SolarWinds.Orion.Core.BusinessLayer.dll component. Once the update is installed, the malicious DLL will be loaded by the legitimate SolarWinds.BusinessLayerHost.exe or SolarWinds.BusinessLayerHostx64.exe (depending on system configuration). After a dormant period of up to two weeks, the malware will attempt to resolve a subdomain of avsvmcloud[.]com. The DNS response will return a CNAME record that points to a Command and Control (C2) domain. The C2 traffic to the malicious domains is designed to mimic normal SolarWinds API communications. The list of known malicious infrastructure is available on FireEye’s GitHub page.

And now, it looks like the US Government may have been seriously compromised.

This is kind of a big deal…

Malwarebytes also has some good coverage as well, as does Prevasio

Categories
security

Is Docker secure? We executed all the containers in the Docker Hub to find out. What we found was troubling.


Docker – a way of building applications using containers (micro-apps that are used in Lego-block fashion to build larger programs) – is taking the enterprise world by storm. With customers that count among the top technology-forward companies in the world (Netflix, AT&T, PayPal, Snowflake, Verizon, Target, and many others), it’s become the new standard in deploying highly robust and distributed applications. At the core is Docker Hub, the main universe of Docker containers, with over 4 million container images*.

So with so many enterprises and institutions running Docker, security is a concern, and we have seen the growth of security vendors like StackRox, Aqua and Snyk to answer the call. And I’m sure plenty of these vendors have done analysis of containers, but in the end, these analyses will only be a static analysis, without taking into account all of the complexities and actions that occur when one actually runs a container.

So I’m happy that today, Prevasio, a company that I’m advising, has launched the results of the first and only analysis of the entire Docker Hub. What Prevasio did is new and important: They actually went through the entire Docker Hub and ran each container to see what happens.

This is not a small task; the company spent tens of thousands of dollars in computing power to perform this task. And the way the Prevasio Analyzer works is different than any other solution on the market: At its core is a sandbox which “detonates” (executes) a container to see what actually occurs during the runtime process. This sandboxing action allows us to get a unique view into what actually occurs when one executes a container. (This is the difference between behavior analysis and static analysis – a static analysis will use a signature to determine maliciousness but can never tell what an application will actually do. For a real look, one needs to analyze behavior.)

Some of the results are troubling:

  • 51 percent of all containers had “critical” vulnerabilities, while 13 percent were classified as “high” and four percent as “moderate” vulnerabilities.
  • Six thousand containers were riddled with cryptominers, hacking tools/pen testing frameworks, and backdoor trojans. While many cryptominers and hacking tools may not be malicious per se, they present a potentially unwanted issue to an enterprise.
  • Over 400 examples (with over 500,000 pulls) of weaponized Windows malware crossing over into the world of Linux. This crossover is directly due to the proliferation of cross-platform code (e.g. GoLang, .NET Core and PowerShell Core).

The full whitepaper is here, and Prevasio’s blog post is here.

But if you want to have some fun, Prevasio has all the data publicly available live on their site, at malware.prevasio.com. Feel free to look at the results for yourself.

*A container image is the template that creates the actual Docker containers.

Categories
business advice

Jeff Bezos’ three rules

Ian McAllister, a long-time Amazonian, writes about the three rules that Jeff Bezos’ uses to invest in a new business at Amazon.

I’ve used similar decision matrices myself and it’s interesting to see the simplicity and clarity of the method Bezos uses.

They are: 1) is it a big idea, 2) is it congruent with the business, and 3) is there a plan to succeed.

More here.

Categories
security

How Russian Trolls Took Over Americans’ Instagram Accounts

Interesting overview by the WSJ on this one aspect of Russian trollage. 

Categories
politcs

The best overview I’ve found of the changes in the tax code

Ligget and Webb has done their homework. Link: LW Tax Law Comparison_122017

And yes, I happen to think this is a good bill and will have very positive effects on our economy.  I’d prefer a simpler simpler tax scheme (like the Fair Tax), but this is a vast improvement over our current tax scheme.

I’m disgusted,  however, that the Carried Interest nonsense still continues (thanks to the douchebag hedge fund lobby – if there was ever a group that needed less protection, I’m not sure what it is – and I used to work in that business); and further AMT still refuses to die the death it so deserves.

But overall, it’s good.

(h/t Riggs)

Categories
General

Tampa Bay and hurricane history

Since reliable records were kept, four major hurricanes have directly hit the Tampa Bay area. They are the Tampa Bay Hurricane of 1848, the 1921 Tampa Bay hurricane, the 1946 Florida Hurricane,  and the Storm of the Century of 1993.

All of these storms had one major attribute: They developed in the southwestern Caribbean or off of central America, rather than the Atlantic or eastern Caribbean. This fact is worth noting.

Commonly, major hurricanes in our part of the world come off the coast of Africa or the eastern Caribbean, and shoot off westward, affecting the US by hitting Florida or the southeastern states on the east, or going below Florida and shooting up to the Florida Panhandle or the various Gulf states (Louisiana, Alabama, Mississippi and Texas).

These storms rarely go up the Gulf, and then make an immediate jaunt eastward to Tampa. When in the Gulf, they just go straight up. Exceptions, such as Hurricane Charley (which came out of the central Caribbean), have not affected Tampa (but almost did, and it was a near thing indeed!).

The reason is that Tampa faces west, and the trade winds prevalent in our area move east-to-west.   In other words, the prevailing winds keep the storms pushed away from us.

Now, storms such as Elena, Irma and Frances have affected Tampa, but were not at the scale of a direct hit (although certainly not little storms – they all had an impact).

For me, the concern with Irma is that it would go further to the west, hitting us at an angle to hit Tampa Bay directly, causing a potentially massive storm surge. However, it was fairly clear by the 8th of September that it would be a major wind event – but not a big storm surge creator. Still, I took precautions.

The Storm of the Century in 1993 (often referred to as at the “No Name Storm”). See this animation for a powerful view of the storm’s path.

The track of the 1921 Tampa Bay hurricane, originating off of the coastline of the Honduras.

The Tampa Bay Hurricane of 1848 was an absolute monster storm; consensus is that the storm developed in the central Gulf region.

The 1946 Florida Hurricane developed off the coast of Guatemala.

What’s of great concern with a direct hit to Tampa Bay is that the region has a shallow continental shelf, with very warm water. That is a bad combination, creating a potential of a devastating storm surge. A big storm coming directly at us will be quite dangerous.

Remember, storm surges are where you see boats on top of trees 20 miles inland. Katrina. That kind of thing. Storm surge is the big problem in hurricanes.

So, I pay very close attention to tropical disturbances in the southwestern Caribbean, because these could hit Tampa directly. A direct hit creates the massive storm surge that is actually the major danger in hurricanes.

Now, that’s not to say that I am not wary of any major storms developing that could affect our area…

Disclaimer: I’ve lived in Florida, cumulatively, well over 20 years. I’m not an expert nor a meteorologist. But I have had to worry about the safety of my family in the face of big storms and I’m a bit of a nerd who has spent a lot of time studying the issue. This is only my viewpoint and observation. Feel free to disagree. Everyone fights about hurricanes, and the news doesn’t help by scaring the heck out of everybody, so the arguments tend to be between people who are scared witless – not the best combination. 

Categories
Uncategorized

The wall is already pretty much done

BorderAtJacumba2

1414203158407

I’ve written about immigration policy before, and this is not that kind of post.

Instead, I am addressing a conventional fiction that “there is no wall” on the border of Mexico and the US. I’ve found that this is a surprisingly widespread belief.

We don’t even have to go to Mexico to get them pay it. Legislation is already in place for the wall, and for funding. With some modifications, we could have that wall.

You see, we have finished building about 60% of a wall. It’s actually a fence, but if you’ve seen it, it’s pretty big. And I think you’ll find the consensus is that this is much more realistic.

The border
The total length of the border is just under 2,000 miles. Roughly half of that distance is the Rio Grande (which gave rise to the derogatory term for Mexican immigrants, wetback, as many illegals used to swim the river to get to the US).

Securing the border
In 1994, a National Border Patrol Strategic Plan started the process of improving security on the border to stem the flow of illegal immigration. The post-9/11 war on terror gave this attempt a big boost, with the Bush administration pushing hard to build a fence and ultimately passing a series of laws.

In other words, we have had legislation in place for many years to build the wall. And it’s largely funded.

Quite a bit of the wall has been built
So far, the US has built roughly 600 miles of fence. Taking out the river, we’re more than halfway there.

(The remaining land is handled by the Border Patrol and various infrared and technical contraptions.)

The Rio Grande
Now, here’s where it gets complicated: We have this big river, the Rio Grande.

Putting a fence in a river causes all kinds of environmental problems, which even if you’re a conservative, are cause for some concern (I live in Florida, and have seen the damage that the Tamiani Trail did to the Everglades, and while a porous fence isn’t nearly as bad as a dam, there are some real issues at stake here.)AP_BORDER_FENCE_WILDLIFE

No worries! In 2006, the Real ID Act was passed, which, in part, gave the Secretary of Homeland Security (then Michael Chertoff) the ability to waive environmental regulations in this context. He really wanted a wall, so he did just that.

Yet, we still don’t have a fence completed.

A major problem is the fact that there are three Native American reservations that sit on the border in Arizona. This leaves a gap in the “wall” which is occupied by sovereign Indian nations.

Most notable is the Tohono O’odham reservation, which is huge — about the size of Connecticut — and includes the vast Sonora Desert. Citing its sovereignty, it once successfully barred the Border Patrol from entering the reservation. They’ve since changed their tune, since now, this opening in the border has driven drug smugglers into the area (as well as illegals, who are dying in the thousands trying to cross the Sonoran Desert).

This is a major issue: we have to figure out a way to build a wall through a sovereign Indian nation. It’s not insignificant. Imagine a wall going through your own neighborhood — the Native Americans are not crazy about this idea. And we can’t move the border south, nor north. It has to be a wall right through these Indian nations.

In other words, it’s a bit more complicated.

 

Categories
General

Breaking: Goldman Sachs’ view of the election

untitled

Goldman Sachs shares with its wealthy clients various views of the market. Here, they’ve taken on the election in terms of markets.

It’s an interesting read, here.

 

Categories
security

It really comes down to beer (endpoint security redux)

572px-Dutch_beersUpdate: SentinelOne responds in the comments. Additionally, they claim (and I have no reason to doubt this claim) that the report I referenced was an older version that had incorrect information on the part of Tevanos.

As a follow-on to my recent post about endpoint security (see “A bomb just dropped in endpoint security…“), I thought I’d share some additional thoughts, conclusions and opinions.

It really comes down to beer. But more on that later.

Reuters
First off, Joe Menn at Reuters wrote a story this morning. It’s a good story, fair and balanced.  Worth reading. There will likely be more stories as well.

Beating up vendors isn’t really my thing
In the recent blog post, there were a lot of slings and arrows thrown at a few endpoint security players. My blog got trolled quite a bit. I cleaned it up.

Cylance certainly came under heavy attack by some commenters, and I removed those comments.

I’m not interested in beating the crap out of some company; I’m really just interested in writing about stuff that I find is interesting.

On Cylance
There was a possible confusion that got propagated that Cylance was using VirusTotal directly in their product. I now have information that this may be incorrect.

Cylance was using VirusTotal, as they said in the Reuters article. It’s possible they were using the service to download samples to train their engine, not directly from inside their product. It’s also possible that they used VirusTotal to help detect malware.

I don’t know for sure, and that’s why I expect to be talking to them in the next several days.

Note that Cylance is not a bad group of people. There are many very good people working there, and they run a good business. I’ve challenged them to get more public tests, and I hope they do so. So far, there have been two tests that I know of — a condoned test by Av Test, and another test, where AV Comparatives/Effitas had to basically break the rules to try and get a copy of Cylance (one can’t just download Cylance and test it, as Cylance keeps its trials very closely monitored).

So testing more, and being more public, would be a good thing.

At any rate, peace, people.

Other endpoint players
I don’t know about other endpoint players. I know SentinelOne, for example, has been open about using VirusTotal.

Specifically, this report (PDF) on SentinelOne’s capabilities in healthcare, highlight this point:

SentinelOne ensures that it is always up to date, checking file hashes against reputable sources such as Virus Total. Using this method, SentinelOne’s platform does not suffer the traditional time lapse in needing to push out new definitions…

[Edit – As mentioned earlier in this blog, SentinelOne tells me this quote is from a PDF of an older document that incorrectly noted VirusTotal as a source and has since been corrected.]

Regarding Palo Alto Networks and CrowdStrike, I really don’t know the involvement of these players. But as the Reuters article mentions, they have been users of VirusTotal (and have not been participating with the community). That’s not to say they’re bad people or have bad products (CrowdStrike and Palo Alto both make excellent products). It’s just something that has been addressed.

Endpoint security
My knowledge of the endpoint security market comes from the fact that I’ve been there in the trenches.

I’ve presented at conferences like VirusBulletin and submitted papers, etc., but that’s the fun stuff. Actually being in the day-to-day sweating bullets to try to keep your customers protected is a very difficult task.

You see, we created a full-stack antivirus product at my last company (Sunbelt Software’s VIPRE) and I personally ran the antivirus lab for some time.

When we released the product, it was probably mediocre, and we avoided tests. It got better when we started opening up to tests, and in fact, it got quite good (and then I sold the company and, well, I don’t recommend the product anymore).

We were on VirusTotal, and it was painful to see us miss detections. But at least we saw ourselves for what we were, and made our product better as a result.

Is there a “next-generation?”
The truth is there are only so many ways to skin a cat. The former Eastern Bloc countries were famous for producing some of the world’s most brilliant mathematicians and now we have companies like Kaspersky and BitDefender with just those same type of people. Yet even they have a tough time of it (no matter what they say publicly). It’s not an easy business, trust me.

I don’t entirely buy a lot of the “next-gen” security arguments. I think that there is room for innovation, but I’ve seen companies like Malwarebytes (of which I’m a board member and incredibly biased toward) and (recently) Symantec do some very impressive work in detections, without resorting to anything of the next-generation type. It really comes down to a lot of hard work, block-and-tackling type of stuff.

So, it’s no surprise that people do whatever it takes to get the best result possible. If this means using VirusTotal to do a hash lookup (which IMHO is fairly silly, since polymorphism makes hash lookups far less useful than people might think), or good old fashioned PR to paint lipstick on a pig, well, so be it.

The key is openness. If you have something special, open it up to the world for them to look at, to test, to validate. Be a part of the community and give back to it. It will make your product much better.

Which comes to the beer
Information sharing in security happens around conferences and beer. (When I brought in a new lab manager for my research team years ago, I urged him to spend as much time as possible going to conferences and drinking beer with other experts. He didn’t object).

Perhaps that is a bit tongue-in-cheek, and it’s not that we’re a bunch of alcoholics (well, mostly not), it’s simply that a lot of information sharing happens at conferences, when experts talk to each other freely. The swords of competition are put down briefly, people open up, and you hear a lot of interesting things.

And what I hear around the tables is what is reflected in some of my blog posts. There is good data, but it can’t be substantiated and it won’t ever be confirmed. So, I’m sorry I can’t be specific, despite many of you emailing me for much more detail than I am prepared to give. Trust is everything in security.

But beer? Yes, we can all share that freely. So, here’s to beer (in my case, the ever excellent Buckler Non-Alcoholic).

You can see who VirusTotal credits here. 

Categories
security

A bomb just dropped in endpoint security… and I’m not sure anyone noticed

wp84552171_01_1a
Pay no attention to the man behind the curtain…

Update: Reuters now has the story

Update 2: I’ve updated this post with additional information, here. 

VirusTotal just dropped a major bomb, and only people deep in the endpoint security ecosystem understand the ramifications of this announcement.

If you’re involved in endpoint security to any degree – as a customer or an industry person – you need to understand what just happened. It’s really, really big.

A bit of background.
VirusTotal is a multi-engine virus scanner. You upload a file, and it passes the file to a large number of commercial antivirus products, and it tells you which engines detected the file as malicious.

While there are other tools available, and some have come and gone, VirusTotal is the big dog in the space. It’s owned by Google, has massive computing and resource power and everyone in the security industry uses it.

VirusTotal shares the results with subscribers. So, you can pay to get extensive and detailed information on what has been detected at any moment of the day, and who detected it. 

How antivirus companies use VirusTotal to make better detections.
It’s common practice of antivirus companies to use VirusTotal as a tool to make better signatures.

For example, if a researcher finds that two high quality antivirus engines detect a file as malicious, he/she has a high confidence that it’s actually malicious without further analysis. As an antivirus researcher, it saves an enormous amount of time.

Now, there’s absolutely nothing wrong with using VirusTotal results in research, and many antivirus companies use VirusTotal to supplement their own labs. They get samples from VirusTotal, and along with the samples, what engines detected them. If they find that a couple of high quality engines are detecting a file, they can easily add the detection to their own signatures without much further thought.

Now, there’s a next step. You could set up an an API integration with your product. If you scan a user’s machine and find an unknown file, you could upload it through an API to VirusTotal and get a disposition on the file –who detects it. From this data, you can flag a file as malicious.

In other words, you can use VirusTotal to create your own antivirus program. Easily. 

Until now. 

It’s fine to use other engines. If you’re also contributing.
Using other engines to improve your detection rate is completely fine. If you’re also contributing back to the community yourself. In other words, if your antivirus product is also one of the participating antivirus engines.

The dirty little secret
And here’s the dirty little secret that very few people know. There are a number of endpoint products that use VirusTotal to determine if a file is malicious. Without any contribution to the communityWithout giving anything in return. 

They simply pay VirusTotal a subscription fee, and receive the information.

And some of these companies have been getting a lot of attention for their supposed prowess. But for some mysterious reason, they refuse to put their own engines on VirusTotal. Could it be because they don’t want to contribute back? Maybe. Or it could be that they just don’t want everyone else to see how poorly their products actually perform.

Unfair? Yes.
Using VirusTotal information without any contribution back to the community is patently unfair. The people who are actually writing detections are sharing their results with the rest of the community, while a small group of endpoint products have been boasting of their extraordinary abilities, while working off the backs of other researchers. 

So as a customer, perhaps you can ask the next endpoint security vendor if they’re on VirusTotal. If they are, they’re contributing to the antivirus community. If they’re not, they’re not. Whatever their PR story, that’s the simple truth.

Until now.
Well, the world just got a bit brighter for the many endpoint security companies that actually contribute to VirusTotal: Because VirusTotal just announced that they are requiring that all scanning companies that use their service must integrate their engines into VirusTotal. Furthermore, “…new scanners joining the community will need to prove a certification and/or independent reviews from security testers according to best practices of Anti-Malware Testing Standards Organization (AMTSO).”*

It’s big news. It levels the playing field. No longer will antivirus companies see their hard work taken by some sexy startup that’s raised millions of dollars on the false promise of “next generation” endpoint or other such nonsense, while bashing the very companies that they’re effectively stealing the intellectual property of. And perhaps, we’ll see what their products are really made of. Because without VirusTotal as a crutch, companies that rely on it are going to see their detection rates take a hit.

Poetic justice, indeed.

What does this mean for the IT manager?
If you’re an IT manager who has been duped by sparkly marketing materials to buy-in to one of these “next-generation” endpoint products, take a hard look at their actual detection capabilities. If they’ve been using VirusTotal results but not contributing back, their ability to detect malware just took a potentially serious hit. This is serious.

You don’t have to believe the marketing hype. Setup a virtual machine that’s separated from your corporate network, and go to a site like MDM to find all kinds of nasty stuff. In the words of Ronald Reagan, “trust, but verify”. One nasty piece of malicious software (especially ransomware) can have serious consequences.

In closing
My compliments to the VirusTotal team for seeing this disparity and unfairness and taking such swift action. A class act, indeed.

And now, perhaps, we can all finally see what is really behind the curtain.


* Disclaimer: I am a board member of Malwarebytes (a contributing member to the VirusTotal community), and an advisory board member to AMTSO.  The opinions in this blog post are my own and are not connected to these two organizations.

Categories
politcs

The myth of the wall

BorderAtJacumba2

1414203158407

I’ve written about immigration policy before, and this is not that kind of post.

Instead, I am addressing a conventional fiction that “there is no wall” on the border of Mexico and the US. I’ve found that this is a surprisingly widespread belief.

The border
The total length of the border is just under 2,000 miles. Roughly half of that distance is the Rio Grande (which gave rise to the derogatory term for Mexican immigrants, wetback, as many illegals used to swim the river to get to the US).

Securing the border
In 1994, a National Border Patrol Strategic Plan started the process of improving security on the border to stem the flow of illegal immigration. The post-9/11 war on terror gave this attempt a big boost, with the Bush administration pushing hard to build a fence and ultimately passing a series of laws.

In other words, we have had legislation in place for many years to build the wall. And it’s largely funded.

Quite a bit of the wall has been built
So far, the US has built roughly 600 miles of fence. Taking out the river, we’re more than halfway there.

(The remaining land is handled by the Border Patrol and various infrared and technical contraptions.)

The Rio Grande
Now, here’s where it gets complicated: AP_BORDER_FENCE_WILDLIFEWe have this big river, the Rio Grande.

Putting a fence in a river causes all kinds of environmental problems, which even if you’re a conservative, are cause for some concern (I live in Florida, and have seen the damage that the Tamiani Trail did to the Everglades, and while a porous fence isn’t nearly as bad as a dam, there are some real issues at stake here.)

No worries! In 2006, the Real ID Act was passed, which, in part, gave the Secretary of Homeland Security (then Michael Chertoff) the ability to waive environmental regulations in this context. He really wanted a wall, so he did just that.

Yet, we still don’t have a fence completed.

A major problem is the fact that there are three Native American reservations that sit on the border in Arizona. This leaves a gap in the “wall” which is occupied by sovereign Indian nations.

Most notable is the Tohono O’odham reservation, which is huge — about the size of Connecticut — and includes the vast Sonora Desert. Citing its sovereignty, it once successfully barred the Border Patrol from entering the reservation. They’ve since changed their tune, since now, this opening in the border has driven drug smugglers into the area (as well as illegals, who are dying in the thousands trying to cross the Sonoran Desert).

This is a major issue: we have to figure out a way to build a wall through a sovereign Indian nation. It’s not insignificant. Imagine a wall going through your own neighborhood — the Native Americans are not crazy about this idea. And we can’t move the border south, nor north. It has to be a wall right through these Indian nations.

In other words, it’s a bit more complicated than a simple stump speech.

My Dystopian Vision
FOT1213780I talked to a Trump supporter recently in San Francisco. I asked him how he thought Trump would fix the economy.

“He’s going to get rid of all those fucking illegal immigrants,” he said, enthusiastically*.

So here’s my dystopian vision:

Trump enters office. Since “The Wall” is already approved and funded (by us, not Mexico, who will tell us to fuck off), it finally gets built.

Yay for Trump.

But then there’s the nagging problem of all of those “fucking illegals”. Trump wants forced deportation.

The last time that happened, the program, Operation Wetback, was stopped after Mexicans started dying in a trial of tears (we’re so good at this trial of tears thing, aren’t we?).

But what if, as some speculate, the military or others won’t follow his orders?

I see those, like my San Francisco Trump supporter, who will become effectively “brown shirts” for Mr. Trump.

I’m not making this up. Look at the protests. Watch Cartel Land, with citizen paramilitary outfits taking shots at Mexicans. The stuff going on right now is crazy.

Perhaps they will be called “Trumpeters” or some such name.  I expect they will bang on the doors, wrench the illegals out of their homes, and probably engage in a bit of good old-fashioned pillaging.

Outlandish? Not really. We’ve had plenty of paramilitary groups in our nation’s history. 

It’s only one of the disasters I foresee with a Trump presidency.

————–

* A silly statement. Getting rid of 11 million illegals will do nothing positive for our economy. It might very well crater it. The real problems — the massive national debt, the Federal Reserve hell-bent on printing money into ridiculous asset bubbles, massive spending on the military instead of national infrastructure, well… those are some of the real problems. Further simplistic arguments by Trump about taking on waste and fraud in the government? A drop in the bucket. 

I’m not in favor of illegal immigration at all, but getting rid of the people who pick our lettuce, wash our dishes and clean our cars isn’t going to do a thing to help the economy. Illegals are easy scapegoats, they always have been, but they are not the correct reason WHY things aren’t going well in our country.

Categories
Uncategorized

The fake review problem on Amazon

Fake-Companies-List-Announced-By-TCS-and-IBM-2015

Amazon got a lot of press recently for going after fake reviewers.

Sadly, this problem has not gone away.

For example, let’s take this product on Amazon, which ironically has quite a few good real reviews (no idea why they have to get fake ones):

Untitled

reviews

We have our first red flag — so many of the positive reviews are not verified purchases.

Simply clicking on the reviewer’s names shows that these are professionally paid reviews.  For example, both “Grant_Williams” and “Patrick K. Bracewell” amazingly have the same tastes — they both love breast pumps. In fact, they both love a lot of the same products.

reviews2

Without going on ad nauseam, this pattern continues for other reviewers. They magically like the same products.

Other types of reviews come from “Reviewer Clubs”. Companies like AMZ Tracker, ILoveToReview.com and others offer Amazon sellers the ability to get reviews from reviewers, in exchange for a free or discounted product. These are legitimate (and encouraged by some) and as long as the reviewer makes it clear that the review came in exchange for product, I don’t really have an issue with it.

Enter FakeSpot
Curious about a brand’s level of “fakiness?” Try FakeSpot. It will try spot the fake reviews.

Amazon, please change.
Reviews are a cornerstone of Amazon’s success, and allowing non-customers to post reviews has to end. Furthermore, Amazon can still do a lot more to make sure that fake reviews, even from “verified” customers, don’t happen. Their brand depends on it.