A bit ago, I checked out an app called Color ID. I posted an initial review of this app, and decided to follow up on it.
Several things have remained constant in the intervening time. I am still using the Samsung Galaxy S6 for the app. I still have no iProducts to compare the iTunes store version. And, I have had no change in my color vision. I have had a bit of time to try this app out in several conditions.
This app could probably be considered "abandonware". The developers have not been supporting, or updating it. So, it is as-is, and will likely remain so for as long as it is around. There is no support for it.
How have I found the functionality?
The app uses the camera and speaker. It has no zoom feature, but a round centering section for it to recognize. The default isfor the voice to be on, and to check colors every couple seconds. This can be turned off, so that you can identify color as desired. In the options, it offers "simple colors" "exotic colors" and "Ral colors". Simple offers things like "Dark purplish green", "Grey brown" and such. While not having seen them, they make sense from the "basic crayon box". They also give the numeric code that it perceives (Brownish black #0a0e0f). Exotic colors, I believe, gives a lot of new names to the individual shades (Dune, Woodsmoke, Rangoon) though still gives a numeric (Shark #232627). I'm not overly sure what "Ral colors" means, but seems to give a mix of unusual names, and modified basics (Jet black, concrete grey, sepia brown ) and gives numerics (Tarpaulin Grey #4d4943).
I've found the app to be a bit helpful, but, not as much as initially hoped. I've found that slight variations in placement of camera, or minor differences in lighting, can result in the identified color. Sometimes these minor movements (a fraction of an inch in camera placement) can switch between grey, purple, blue and green. The nature of lighting has an affect on this, as well. CFL bulbs, fluorescents, sunlight, incandescents, an LED monitor nearby... All of these change the minor perceptions of what the camera sees.
It's nice, and sometimes helpful. However, it can't be relied on. While I can be easily fooled between blue and green, I realize there is a world of differences on the spectrum of them. It's a handy tool, but it's not something that I can count on absolutely.
Thursday, May 12, 2016
Party Line Is Open
The phone lines are open: Call 1-855-326-5442, while it's still working. Some possible answers will be "Google Technical Support", "Windows Technical Support", "Yahoo Technical Support", "Technical Support", and "Computer Scammers R Us".
OK, so maybe they didn't answer the phone the last way... but I called them out on it. Until such time as Level 3 Communications can be bothered to disconnect their phone service, I declare the Party Line open.
These are not legitimate call center employees. They are criminal scammers. The same contact number claims to represent many competing corporations, simultaneously.
Examples of deception and fraud include:
- Microsoft (or Google, Yahoo, etc) will NEVER call you to tell you there is a problem with your computer!!! (While Microsoft will offer phone support, it requires you, the user, to contact them for assistance. They do not have your name and number. Yahoo no longer offers phone support - or seemingly any support.)
- Claiming that the CLSID number is your "Windows license". (This number, 888dca60-fc0a-11cf-8f0f-00c04fd7d062 is the same on all copies, it is not unique)
- Claiming that the "netstat" command "shows hackers in your system" (The netstat command, by itself, shows a list of remote connections to your computer - which includes currently visited websites, it does not necessarily indicate hackers' presence)
- Claiming that the warnings and errors in Event Viewer indicate hackers, viruses or infections (These errors are normal, and do not indicate such things as the scammers attempt to claim)
- Being very pushy to engage in a remote session with your computer. (Yes, on occasion legitimate companies will ask for remote access. This is strictly voluntary, and the level of insistence is low.)
- Use of profanity, including "The F Word" (These are termination-worthy offenses, with a generally zero-tolerance policy toward even lesser oaths, let alone "the queen mother of all profanities". )
Keep in mind that these are criminal scumbags, not legitimate business people. Have fun with them. String them along. Waste their time. Do not, however, let them gain remote access to your computer. The more their time is wasted, the less it can be used to victimize innocent people, and harm their machines - or steal their money.
Thursday, May 5, 2016
Hillary's Server - Not A Political Post
The Clinton Server
(Not A Political Posting)
I've never really wanted to delve into politics here. I find that mixing business and politics ends up being bad for business. The "Clinton Email Server" has been newsworthy for some time. I, like many, have personal opinions on this matter. I do not intend to get into those here. This is about technology, not politics. Below, the discussion will be about whether or not an extradited hacker's claims of having accessed Mrs Clinton's server are plausible. Please read this with an open mind, regardless of your opinion on Mrs Clinton.
The "quick and dirty" (or TL;DR) version to set things up: Barack Obama was elected in 2008. Upon taking office, he appointed Hillary Clinton as Secretary of State. Mrs Clinton used a home-based mail server for her State Department correspondences. Following the 2012 election, Mrs Clinton stepped down from the position of Secretary of State. In 2013, information about her private mail server surfaced, and since then has become a political topic of assorted controversies.
One of the questions about this server was "How secure was it?" Staff claim that no one got in. However, a Romanian hacker, Marcel Lehel Lazar (using name Guccifer) claims otherwise. In this piece, and this link, Guccifer talks to journalists following his extradition to the US. He claims that he accessed the server, and gives some detail on "how". A valid question, though is "Does this man's story hold water?"
The Clinton camp was quick to call "bull" on Lazar's story:
Perhaps to the non-user to average computer user, this makes sense. It seems logical. Unfortunately, to the more trained eye, Lazar gave quite a bit of information in his interviews and statements.In response to Lazar’s claims, the Clinton campaign issued a statement Wednesday night saying, "There is absolutely no basis to believe the claims made by this criminal from his prison cell. In addition to the fact he offers no proof to support his claims, his descriptions of Secretary Clinton's server are inaccurate. It is unfathomable that he would have gained access to her emails and not leaked them the way he did to his other victims.”
His access to the Clinton server started, according to him, with Clinton confident Sidney Blumenthal. Mr Blumenthal still used an AOL email account. With sufficient research, Lazar found details to gain access to Blumenthal's account. We are about eight years removed from a somewhat similar incident involving participants in the Presidential Election, when Vice-President candidate Sarah Palin's email account was hacked, and leaked. While Lazar did not get into specifics, his vague description matches the specifics in the Palin hack.
For the average email user, looking at the inbox shows a sender, subject, time and date, and maybe other people that are on the cc list. There's a lot more to it than that. Depending on the mail provider/client one uses, the means of viewing the source information varies. In this email source, there is a lot of useful information to the more-trained eye. In order to arrive, mail must be addressed. (username @[instructs computer that domain follows] domain.extension) When you send mail, it goes from your device to your mail provider, to their mail provider, to their device (and significant routing points along the way).
As Lazar pointed out, each endpoint has a unique IP address. For some (home users' computers, Yahoo, Gmail, etc), the address may change with time. For others (large businesses, schools, hosted domains) a permanent, or static, IP is used. Lazar is correct that there are a multitude of tools available to examine these IP addresses.
It seems that Lazar looked a little deeply at some of the contacts with Blumenthal, and looked at where they lived on the Internet. As I read the description, I thought "This sounds vague". I was easily able to fill in the details, though, which were likely left out, so as not to provide a "how to" guide. I can see "Clintonemail" being intriguing, especially not behind a .gov server. I can see what he describes as being "one of the first things to try".
To address the Clinton group's assertion that the contents would have been leaked, motive should be considered. In the Palin case, the perpetrator was American, a Democrat, and she was an opposition candidate in a national election. There was (perceived) political gain in the September 2008 leak. By not leaking (at the time), this allows for more exploration, and more gathering. Continuing to read Blumenthal's email source, he could potentially discover many more servers of interest. These, in turn, could lead to other "productive" finds. Burning his source right away eliminates the potential of future discovery.
To be fair, the fact that he makes these claims, and knows the process does not necessarily mean that he was in the Clinton server. He tells a compelling tale, and it is extremely plausible. However, he would need to provide some pretty good proof that he was in to convince the jury.
The Clinton assertion that the server was secure, and no one got in; may be true. However, it is just as likely to be optimistic belief that has yet to be disproved; or a political mistruth to protect the image of one of three remaining major presidential hopefuls.
Ultimately, Lazar makes a very convincing and plausible argument. To be fair,anyone who has a strong functional knowledge of IP addresses and port scanning could likely say the same - with or without having accessed a particular machine. In the end, the answer will be determined by whether or not Lazar can back up his claims.
Monday, March 21, 2016
"Microsoft" attempts to strike again.
With the plethora of information out there (and the number of PSA's that I've made on this subject); I would think this is an unnecessary message. Unfortunately, people still get fooled into falling for these scams. Microsoft will never cold call you about a computer problem!
Below I will detail the recent scam calls - how they happened; what they [try to ] do; and why it's bogus.
I have the fortune (or misfortune, depending on perspective) of one of my numbers being "recycled". Based on certain events over the years, it appears the former owner is a senior citizen. Seniors end up having their information sold to a lot of legitimate advertising bodies. These lists also make good targets for criminals. Why? Yes, some seniors begin having difficulties with their decision making faculties. They make easy prey. With some others, though, they may not be "up" on the current technology, and may be more easily deceived. Mind you, there are also plenty of Gen-X or Millenials, that are susceptible to the same.
Two recent calls in. One was "PRIVATE", the other was from 800-439-7794. Both callers were looking for the former (6 years ago) owner of this number. So intent they were, that they didn't seem to notice that I told them I was someone else. Fake names didn't catch, as they kept calling me by the owner's name - one of them even addressing me with the female forename.
The gist of the scam is simple. Act like they are from Microsoft. Guide you through very simple Windows commands, and then give you BS as to what you're looking at. Pretend they will fix this issue, if only you allow them remote access to your computer. Then enjoy the spoils (your confidential information harvested from the computer, your credit card number, bank account information, etc).
The recent scams deviated a little from the normal. Sure they gave the normal "I'm [fake name] from Windows Technical Support" bull. However, instead of hopping straight into the event viewer to tell lies about the logs there, they now want to tell you that your Windows Serial Number was attacked by foreign hackers in your computer, and deactivated"
As a means of "earning your confidence" they "give you the first half of the serial", which will be 888dca60, and then have you open a command prompt ("PressWindows key plus the letter R, now type 'cmd' and press enter"). Once there, they will tell you to type "assoc" and press enter. where they will read off the "rest of the serial" to you, to "match" with the number there. This will be:
888dca60-fc0a-11cf-8f0f-00c04fd7d062
From there, he'll have you type in "netstat" on your command prompt. Netstat will generate a list of active connections to your computer. With regard to "foreign", Netstat refers to "remote", while the scammer used "remote" to mean "beyond the borders of your country". Every connection that you make has a local and remote point. If you connect to Facebook, Google, Yahoo Messenger, ESPN, Amazon, and iTunes, then you will have at least six remote ("foreign") connections. There is nothing overly malicious about them despite the fact that some people can use them for bad purposes.
From this, they'll try to get you to use a remote access program (TeamViewer, Ammyy Admin, GoToAssist, etc) to allow them to "fix" the problem and "reactivate" your serial number.
Below I will detail the recent scam calls - how they happened; what they [try to ] do; and why it's bogus.
I have the fortune (or misfortune, depending on perspective) of one of my numbers being "recycled". Based on certain events over the years, it appears the former owner is a senior citizen. Seniors end up having their information sold to a lot of legitimate advertising bodies. These lists also make good targets for criminals. Why? Yes, some seniors begin having difficulties with their decision making faculties. They make easy prey. With some others, though, they may not be "up" on the current technology, and may be more easily deceived. Mind you, there are also plenty of Gen-X or Millenials, that are susceptible to the same.
Two recent calls in. One was "PRIVATE", the other was from 800-439-7794. Both callers were looking for the former (6 years ago) owner of this number. So intent they were, that they didn't seem to notice that I told them I was someone else. Fake names didn't catch, as they kept calling me by the owner's name - one of them even addressing me with the female forename.
The gist of the scam is simple. Act like they are from Microsoft. Guide you through very simple Windows commands, and then give you BS as to what you're looking at. Pretend they will fix this issue, if only you allow them remote access to your computer. Then enjoy the spoils (your confidential information harvested from the computer, your credit card number, bank account information, etc).
The recent scams deviated a little from the normal. Sure they gave the normal "I'm [fake name] from Windows Technical Support" bull. However, instead of hopping straight into the event viewer to tell lies about the logs there, they now want to tell you that your Windows Serial Number was attacked by foreign hackers in your computer, and deactivated"
As a means of "earning your confidence" they "give you the first half of the serial", which will be 888dca60, and then have you open a command prompt ("PressWindows key plus the letter R, now type 'cmd' and press enter"). Once there, they will tell you to type "assoc" and press enter. where they will read off the "rest of the serial" to you, to "match" with the number there. This will be:
888dca60-fc0a-11cf-8f0f-00c04fd7d062
From there, he'll have you type in "netstat" on your command prompt. Netstat will generate a list of active connections to your computer. With regard to "foreign", Netstat refers to "remote", while the scammer used "remote" to mean "beyond the borders of your country". Every connection that you make has a local and remote point. If you connect to Facebook, Google, Yahoo Messenger, ESPN, Amazon, and iTunes, then you will have at least six remote ("foreign") connections. There is nothing overly malicious about them despite the fact that some people can use them for bad purposes.
From this, they'll try to get you to use a remote access program (TeamViewer, Ammyy Admin, GoToAssist, etc) to allow them to "fix" the problem and "reactivate" your serial number.
Why is this a scam?
First of all, as can be seen all over the internet Microsoft will never call you about a computer problem!
But... they knew the number, and when they gave me the commands, they knew the rest:
No! Here's the quick and dirty on the "assoc" command. It tells the associations of everything on the drive. It's a very long list, and if you're so inclined, you can read through it using the steps outlined above. The CLSID number that you see (and they'll quote you) is not your Serial. It's not your key. It's not even unique to your computer. It's common amongst similarly current versions of Windows, and since it's at the bottom of the list; it's easy to use that to sound "knowledgeable".
But s/he gave me a website to show they're legitimate:
So what? Domains are a easy to create. In fact, GoDaddy - has been the recent registrar and host for quite a few scam domains recently registered with fake information. With their current promo, a year's worth of hosting can net you a "free" domain for under $15. If they've fleeced thousands of dollars, worldwide, a few disposable domains are hardly a concern.
What they'll do:
Here are a few things that can happen if you allow the scammers to have access to your computer:
- They install malicious software, claiming that it's there to "fix your problem". This could be anything from a program to allow them access at their leisure, or a key logger (monitors your commands, and transmits them - includes passwords)
- Snoop through your personal files for anting that may be "interesting" (tax info, bank accounts, etc) to liberate
- Install a free or trialware version of software to your computer, and ask you to pay a price for it - generally a scaled price with the "most reasonable" being for the ""life of your computer".
- Change your passwords to lock you out, and "ransom" your computer and files back to you - for a price
- Damage files or delete information necessitating you spend (more) money on useless service
What you should do:
In general, it's advised that you don't answer the phone for strangers. know that Microsoft doesn't cold call, and only allow access to your computer to people that you trust.
If you do happen to answer to these criminals, probably the best course of action is simply to hang up on them. Microsoft will never cold call, and nothing good can come of this. Even if your computer is having some difficulties, this is not the way to fix it.
Under no circumstance allow a stranger to have remote access to your computer.
It is generally not advisable to bait them, as I do at times. I know what I'm doing. I know what they're looking for - and how to answer questions to make them think I'm playing along. Also, when they find out they're being played, they may react angrily. Mostly this amounts to them cussing and calling names or making empty threats (they're not going to fly from India because someone made an ass of them for 45 minutes)
Yes, I often have better things to do with my time. Sometimes I have a project running that I can spare a half hour instead of watching TV during. I only do this when I'm able to spare the time. I also do it because the time they waste with me is time they are not trying to fleece someone's grandma or grandpa. I also do it, so that I may educate others so that they may not fall victim
Friday, January 1, 2016
App Review: Color ID (initial take)
I discovered a new app I'm testing out. It's called Color ID, and is available for free in the Play Store (Android). It looks to be available in the iTunes store, as well. To be fair, as I have no iDevices, I can't vouch for the iTunes version. Everything will be based on the version for Android. I think that the Apple version will be the same, or very similar, based on the interface, but that's speculation.
I've never had any color vision. When I was in kindergarten, I got smiley faces on everything I could learn - and a big Mr Yuk sticker under "knows and recognizes colors". This would later evolve into an occasional sense of fashion which allegedly hurt other folks eyes. Hey, it never bothered me any!
Over time, I've adjusted (happily, I think) with things that I know (or have been told) can be interchanged indiscriminately. I've also got little compunction with asking folks in stores "What color is this?". This makes a difference as sometimes I need black - not purple - pants, or red may behave differently in the wash than black or brown.
Sometimes, though, asking for help is not possible, practical, or possibly embarrassing. By "possible", I mean that there are times when either no one else is present, or a language barrier exists. By "practical", it could be very time consuming to bring a lot of items - or an employee /customer to the items - or as I found during some sales, different color tags represent different prices. By "embarrassing", I don't mean that it would hurt my pride to ask for help... but rather it's awkward to ask "What color is this?" on an item in a size/style that clearly is not meant for me, and may very well be a gift for the person to whom I'm asking the question.
So, I said to myself "Self, since there seem to be apps for about everything; I wonder if there's one that will tell me what color things are." The answer, it came back to be with the Greengar app as the top hit. I decided to give this a shot. At first glance, it starts with a 3.8 star review (Play Store, 1/1/2015 5PM Central time)Reviews seem to be skewed toward 5 more than 1. I'm an app-watcher, to some degree. I'm very skeptical of the permissions some apps use, and try to figure out the "why" of them. This one required the camera, and the photo/media files. This makes sense as it uses the camera to focus on the item, and can pause or take pictures of an item.
How does it function?
So far my testing is on the favorable side. I realize that I've tested it against a back-light from my monitors, or from some fluorescents, which may skew results. I know that with it reading the colors in hex, that there's a lot of potential variance. Something listed as #699606, #6996a6, and #699607 may (or may not) appear very close to some eyes, while being each a unique color, and a slight glare may bring some variance to recognition. The quality of the camera will have an affect, as well. For me, I tried with the Samsung Galaxy S6 which has a pretty good camera.
The results appear to be at least ballpark enough for me to get a good understanding of what I'm looking at. This app gives them to me in something a little beyond "Explain it to me in the original 8 of the crayon box". "Greenish blue" or "light purplish green"are easier on a comprehension than some of the color names out there. Even some of the less obscure names, like these, end up being a pain to sort out at times. So, I like the simplicity of the app here.
From early experimentation, it appears to be about what I'm looking for. I'm keeping in mind my initial testing is not with the best lighting, perhaps (for the app, not for me). I see that some reviews make note of possible accuracy issues, also. I'm going to have to give it some tests in different lighting situations and see how it compares. But, I do know that with the number of hex combinations of colors, it's easy to get several results for the same thing based on distance of camera, light, camera, phone, fingerprints, glare, etc.
For those who may note I have not linked to the company, but rather to the app-store locations; it's because Greengar folded. The app is still around, however. It seems reasonable to presume that this is the final version of this app, unless it's brought on by the creators' next development venture. I have given some other apps a look and have been less than impressed. For instance, one called Color Detector . This one I found to be similar, and a bit too specific in identification of the colors. This one would require me to figure out "what does that color mean" in addition to "what color is it?".
I plan on giving this a bit more of a practical experiment down the line; and may post a follow-up review if needed. For now, I find it useful, and worthwhile (plus it's free).
I've never had any color vision. When I was in kindergarten, I got smiley faces on everything I could learn - and a big Mr Yuk sticker under "knows and recognizes colors". This would later evolve into an occasional sense of fashion which allegedly hurt other folks eyes. Hey, it never bothered me any!
Over time, I've adjusted (happily, I think) with things that I know (or have been told) can be interchanged indiscriminately. I've also got little compunction with asking folks in stores "What color is this?". This makes a difference as sometimes I need black - not purple - pants, or red may behave differently in the wash than black or brown.
Sometimes, though, asking for help is not possible, practical, or possibly embarrassing. By "possible", I mean that there are times when either no one else is present, or a language barrier exists. By "practical", it could be very time consuming to bring a lot of items - or an employee /customer to the items - or as I found during some sales, different color tags represent different prices. By "embarrassing", I don't mean that it would hurt my pride to ask for help... but rather it's awkward to ask "What color is this?" on an item in a size/style that clearly is not meant for me, and may very well be a gift for the person to whom I'm asking the question.
So, I said to myself "Self, since there seem to be apps for about everything; I wonder if there's one that will tell me what color things are." The answer, it came back to be with the Greengar app as the top hit. I decided to give this a shot. At first glance, it starts with a 3.8 star review (Play Store, 1/1/2015 5PM Central time)Reviews seem to be skewed toward 5 more than 1. I'm an app-watcher, to some degree. I'm very skeptical of the permissions some apps use, and try to figure out the "why" of them. This one required the camera, and the photo/media files. This makes sense as it uses the camera to focus on the item, and can pause or take pictures of an item.
How does it function?
So far my testing is on the favorable side. I realize that I've tested it against a back-light from my monitors, or from some fluorescents, which may skew results. I know that with it reading the colors in hex, that there's a lot of potential variance. Something listed as #699606, #6996a6, and #699607 may (or may not) appear very close to some eyes, while being each a unique color, and a slight glare may bring some variance to recognition. The quality of the camera will have an affect, as well. For me, I tried with the Samsung Galaxy S6 which has a pretty good camera.
The results appear to be at least ballpark enough for me to get a good understanding of what I'm looking at. This app gives them to me in something a little beyond "Explain it to me in the original 8 of the crayon box". "Greenish blue" or "light purplish green"are easier on a comprehension than some of the color names out there. Even some of the less obscure names, like these, end up being a pain to sort out at times. So, I like the simplicity of the app here.
From early experimentation, it appears to be about what I'm looking for. I'm keeping in mind my initial testing is not with the best lighting, perhaps (for the app, not for me). I see that some reviews make note of possible accuracy issues, also. I'm going to have to give it some tests in different lighting situations and see how it compares. But, I do know that with the number of hex combinations of colors, it's easy to get several results for the same thing based on distance of camera, light, camera, phone, fingerprints, glare, etc.
For those who may note I have not linked to the company, but rather to the app-store locations; it's because Greengar folded. The app is still around, however. It seems reasonable to presume that this is the final version of this app, unless it's brought on by the creators' next development venture. I have given some other apps a look and have been less than impressed. For instance, one called Color Detector . This one I found to be similar, and a bit too specific in identification of the colors. This one would require me to figure out "what does that color mean" in addition to "what color is it?".
I plan on giving this a bit more of a practical experiment down the line; and may post a follow-up review if needed. For now, I find it useful, and worthwhile (plus it's free).
Friday, December 4, 2015
December 2015 Specials
Christmas
2015 Specials:
Thanksgiving and
Black Friday are in the rear-view mirror, and December is upon us.
These specials will run through the month of December, and only need
to be ordered, not necessarily completed, during that time. So, as
long as you're in touch by the stroke of midnight at New Year's Day,
you'll get the promo. Just go to skylance.us, and fill out our form, or write to sales (at) skylance.us!
#1:
We Wish You A Merry Christmas:
Custom address
labels for your Christmas, Holiday, or other purpose cards. You
supply the information, and you'll get back labels for your cards and
letters.
Base price: $15 for
three pages of addresses, larger orders will have an upfront quote
Turnaround time:
Generally one day – same day available for rush orders
#2:
Just Like The Ones We Used To Know:
We'll transfer your
old home movies to DVD for you. We can handle VHS to DVD, or
Blu-ray, if you prefer, for home movies. This is a great way of
preserving your family memories, or making gifts.
Base price: $10 per
2 hour tape conversion
Additional options:
-
Content on Blu-Ray Disc: +$5
-
Custom Photo On Disc: +$5 first, $3 each addtional
-
Additional DVD Copy: +2.50 each
-
Additional Blu-Ray Copy: +$5 each
-
DVD Case: +$1 each
-
DVD Custom Insert/Art: +$5 first, $3 each additional
Turnaround time:
Varies by project size. Realistic return times will be discussed
upon order. Rush orders (one or same day in some cases) are
possible.
#3:
Clean Up For Santa
While you're doing
all the prepwork for the house, we'll handle the cleanup on the
computer. Running slow? Does it take you to pages you didn't ask
for? Are things just not responding right anymore? We can fix
that!
Base price: $30 per
PC, though may increase depending on virus and malware issues.
Turnaround time:
Varies by order size, and some complexities – may be as little as
one or same-day
BONUS
PRIZE!
All orders will
result in the customer's name being entered into a drawing for a
mystery prize. Drawing will be held on 1/1/2016
Monday, September 7, 2015
Yet another scam....
How It All Began:
So, I'm sitting here, minding my own business, sifting through the mail the other day, and something unusual catches my eye. The first thing that I notice is that the name is wrong. It has an incorrect variation of my name, along with an email address which is unassigned on my domain. The latter got it caught in my catch-all, the former made me a little curious. In general, the only people who use that incorrect variation of my name are people who make the incorrect assumption that that is my full name. It's not. Before I send this into the memory hole, and block the sender's IP and domains as spam, I notice that it's also referencing a client's company by name. Perhaps I will have to look a little deeper into this. What could have happened? Disgruntled former employee? Possible. There have been enough of those, and some guesswork instead of seeing my actual business card may have yielded to guessing. One of the machines got infected/hacked/compromised? Possible, but would not explain the wrong name and email. That would involve guessing or assumption. Combing social media/search engines? Client thinks so, but I say "very unlikely". I say that because there are absolutely no professional listings that would use either name or email. There are a couple other scenarios, but the most likely are some contact of his, along with some guesswork.
What it said:
Basically, I was addressed by (incorrect) name to be a guest of a Shelly Fitzgerald. The email was written as a follow-up (titled as such) to an invitation to a "Chicago Tech Summit" at the Marriott Medical District/UIC "at no charge". However, I'm encouraged to "register right away", and I'm given a link. At this, she signs off as "Planning Director, Chicago Tech Summit". Conveniently there is no contact information. From my years in dealing with spam, I'm skeptical of return address validity. I do a little lookup:
host chicago-summit.com
chicago-summit.com has address 69.94.129.202
chicago-summit.com mail is handled by 10 mail.chicago-summit.com.
I looked up the domain, too, and here is the significant Whois information:
Domain Name: CHICAGO-SUMMIT.COM
Registry Domain ID: 1941529691_DOMAIN_COM-VRSN
Registrar WHOIS Server: whois.enom.com
Registrar URL: www.enom.com
Updated Date: 2015-06-23T13:38:22.00Z
Creation Date: 2015-06-23T20:38:00.00Z
Registrar Registration Expiration Date: 2016-06-23T20:38:00.00Z
Registrar: ENOM, INC.
Registrar IANA ID: 48
Reseller: NAMECHEAP.COM
In bold I've noted that this "Chicago Tech Summit"'s website was just registered on June 23. I left off the registrant information because they used Privacy Guard, who there's nothing useful other than the registration dates and registrar. I also don't find any significant references to it on the Internet - at least nothing positive. Time to check it out. First thing up, this site screams "cookie cutter". I'll circle back to this in a bit. Something that stands out to me is the sheer volume of "corporate sponsors"
Following up what appears to be a logo-collage, is a schedule of the day's events for this "tech summit". For some reason (maybe because this is my field?) the itinerary looks fishy. Maybe that it doesn't seem to mesh with the sponsors, maybe there is no advertised or suggested keynote speaker. Maybe it's some of the vague terminology in the "schedule of events"?
There's still also the "free" aspect, which seems to ring that bell about a free lunch - since lunch is included too.
So, as I look on this page, the only thing I see is a phone number (312) 491-1234 (this is the hotel phone number). By the way, as of the writing of this, the hotel does have an interest reservation, but it's not guaranteed, and the names affiliated do not match. What they have is "Biz Summits". I'm even more suspicious now.
I look a bit deeper...
At this point in time, I have looked at the domain (chicago-summits). On the surface, this seems a dead end, since I don't have much to go on from. Ahh, but I also have the email headers. This indicates to me that the email came from a device called "shelly-mac" on an internal network to the server "columbussummit.com". Looking at this site, it appears pretty much the same as chicago-summit. Pictures are the same, the domain was registered the same day, same registrar, and the same privacy guard as the Chicago. The only differences are that this one is hosted in a hotel in Columbus, OH, and has the hotel's info: The Westin Columbus - (614) 228-3800.
host columbussummit.com
columbussummit.com has address 66.118.163.227
columbussummit.com mail is handled by 10 mail.columbussummit.com.
I am noticing something though an email with a techsummits.org domain. Techsummits.org has a little more info in the whois. For instance, they list a registratnt of Biz Summits, with an Atlanta, GA postal address. They also list a human as their point of contact - Shelly Fitzgerald (I've read that name before....). For the time being, I will refrain from posting the contact number, as the Tennessee phone number listed in Whois is apparently her personal cell phone, and she was very surprised to have a phone call on it regarding the... anomalies ... in her email. She did her best to assure me that this is a legitimate "summit" and should prove valuable, and such. Sorry, but I'm not buying it. I'm also noticing the "confidentiality notice" in her email. She would like me to mail her so that she can figure out "how I got contacted, in the manner I was".
As I'm listening to her try to go into snake-oil mode, I'm also noticing the "confidentiality notice, which again has the wrong name & email address. However for contact information, it tells me to contact a Thomas [left out] at [Address Withheld] in Kankakee, IL. A public records search of that man's name shows two people in America with that name. There is a possible 80+ year old man in Michigan, and a 65+ year man in Indiana. Neither is close to Kankakee. In fact, the woman at the Kankakee address has had her postal address used and abused by purveyors of the bogus, and this is just one more thing with which she is not affiliated.
A little deeper into it...
Using the phone number and contact name from the "techsummits" whois, I run a search. It wouldn't be a surprise to see that it's either a fake number, or has a ton of complaints. The number matches up with some other cookie-cutter "summit" sites. They also reference Ms Fitzgerald connected to this phone number. This is the point at which I made my contact. She did seem genuinely surprised, as she thought her number was sanitized from the websites.
I mentioned earlier about the "logo collage" on the page. It's interesting that some of these "sponsors" don't know that they're sponsoring events in at least two cities (per the email referencing Chicago, and coming from Columbus). Playing around with certain keywords, other cities can be found to be tied to this outfit - more than just two cities.
I also find interesting the low quality that went into putting this together. I would expect a company that is claiming to be on the cutting edge with "tech summits" to inform guests of the latest and greatest; would have such mediocre presentation, images lifted from other sites, and very poor SEO. In order to actually find a first-page result with Google, I need to to provide more search terms. This doesn't do well for their visibility.
Also interesting is that when I plug in some other terms (like "BizSummits") I find a lot of people that take issue with the parent/other aspect of this "company". For instance this site breaks down some similar *summit emails over a few year period of time. This one from 2012 describes how one individual questioned the legitimacy, with her follow-up detailing an attempted (empty) threat by a representative of the company for daring to question legitimacy. Getting a bit more direct, this link calls them out as the scam they appear to be. Not only are the "advertising tactics" called into question, but the photos used for the web sites are shown to be pilfered from other web sites. hrm, I wonder, if they get their pictures and templates from others,... do they actually buy their software, or .... (Not accusing, just wondering....).
That last page also includes a conversation thread where the "executives" are attempting to bribe their way into having the post removed/amended with "free membership". They're also attempting to shout-down criticism. Riddle me this, Batman: If this *summits outfit is so big, and busy and whatnot, how doe their executives have the time to get into spats with bloggers?
I found another interesting thing about them. Their signup page? Well, that's not secure, either. So, they have a web submission form, where you can put in all your personals - including CC, expiration, CVN. It looks an awful lot like most of the bank scam sites I've reported over the years. But, even if they are "legitimate business people", the payment site is not secure, and subject to malicious behavior.
My conclusion:
I see a lot of scams cross my inbox and catchall. This feels like another one. Frankly, I don't care if Shelly Fitzgerald, Michael Price, or Kristin Mathis get their knickers in a twist over this. My opinion is my opinion. It is not for sale in exchange for snake oil, and I do not intend to retract this. My conclusion is based on the following facts:
- The "summit" domains were mostly registered with privacy guard just over two months ago as of the time of this posting. If legit, I would expect them to proudly attach their name.
- Basic Internet searches for the events (which if truly sponsored by the claimed corporations should be highly ranked) reveal second or lower page results - This indicates poor SEO, Why would major corporations (or professionals) invest trust or money?
- The advertising is deceptive, and shady (sending to a non-person and unassigned email address, and writing as if they had a pre-existing relationship with this non-entity?)
- The email contains intentionally false contact information.
- There clearly was no "opt-in" to this. There clearly was no pre-existing relationship in any fashion. Nor will there be, moving forward.
- There also was no real "opt out" (not like those usually work with spammers and scammers) either.
- The "summit hosting company" made it intentionally difficult to find contact information beyond hotel phone numbers and addresses.
- The agenda looks to be rushed and vague. No "keynote speakers" are listed. Also, some of the topics seem vague to the point that they appear worth less than a basic Internet search
- If the quality of the program is questionable, the quality of the signup page looks worse. How is it that a "tech summit" is accepting credit cards through a non-secure page?
- Regarding their pages, they seem to copy a lot from others. or just use stock. Professionally, I see this as somewhere between a no-no, and a lazy/incompetent web designer. This doesn't inspire confidence in their leadership ability.
Data:
"Columbus Summit" (from source of email)
host columbussummit.com
columbussummit.com has address 66.118.163.227
columbussummit.com mail is handled by 10 mail.columbussummit.com.
whois 66.118.163.227
[trimmed a bit for relevance]
[trimmed a bit for relevance]
NetRange: 66.118.128.0 - 66.118.191.255
<>
OrgName: Sago Networks
OrgId: SAGO
Address: 4465 W. Gandy Blvd
Address: STE 800
City: Tampa
StateProv: FL
PostalCode: 33611
Country: US
<>
OrgAbuseHandle: ABUSE32-ARIN
OrgAbuseName: Abuse Team
OrgAbusePhone: +1-866-366-3640
OrgAbuseEmail: abuse@sagonet.com
whois columbussummit.com
Domain Name: COLUMBUSSUMMIT.COM
Registry Domain ID: 1941527913_DOMAIN_COM-VRSN
Registrar WHOIS Server: whois.enom.com
Registrar URL: www.enom.com
Updated Date: 2015-06-23T13:16:53.00Z
Creation Date: 2015-06-23T20:16:00.00Z
Registrar Registration Expiration Date: 2016-06-23T20:16:00.00Z
Registrar: ENOM, INC.
Registrar IANA ID: 48
Reseller: NAMECHEAP.COM
Domain Status: clientTransferProhibited https://www.icann.org/epp#clientTransferProhibited
Registry Registrant ID:
Registrant Name: WHOISGUARD PROTECTED
"Chicago Summit" (from body)
host chicago-summit.com
chicago-summit.com has address 69.94.129.202
chicago-summit.com mail is handled by 10 mail.chicago-summit.com.
whois 69.94.129.202
NetRange: 69.94.129.192 - 69.94.129.203
CIDR: 69.94.129.192/29, 69.94.129.200/30
NetName: DATANOC
NetHandle: NET-69-94-129-192-1
Parent: DATANOC (NET-69-94-128-0-1)
NetType: Reassigned
OriginAS: AS16578
Customer: MICHAEL PRICE (C01244624)
RegDate: 2005-12-15
Updated: 2010-04-28
Ref: http://whois.arin.net/rest/net/NET-69-94-129-192-1
CustName: MICHAEL PRICE
Address: 801 Kellerman Kreek
Address: BIZSUMMITS
City: Marietta
StateProv: GA
PostalCode: 30068
Country: US
RegDate: 2005-12-15
Updated: 2011-03-19
Ref: http://whois.arin.net/rest/customer/C01244624
OrgTechHandle: IPTEC7-ARIN
OrgTechName: Ip Technician
OrgTechPhone: +1-916-366-0170
OrgTechEmail: iptech@lanset.com
OrgTechRef: http://whois.arin.net/rest/poc/IPTEC7-ARIN
OrgAbuseHandle: ABUSE1152-ARIN
OrgAbuseName: Abuse Department
OrgAbusePhone: +1-916-366-0170
OrgAbuseEmail: abuse@lanset.com
whois chicago-summit.com
Domain Name: CHICAGO-SUMMIT.COM
Registry Domain ID: 1941529691_DOMAIN_COM-VRSN
Registrar WHOIS Server: whois.enom.com
Registrar URL: www.enom.com
Updated Date: 2015-06-23T13:38:22.00Z
Creation Date: 2015-06-23T20:38:00.00Z
Registrar Registration Expiration Date: 2016-06-23T20:38:00.00Z
Registrar: ENOM, INC.
Registrar IANA ID: 48
Reseller: NAMECHEAP.COM
Domain Status: clientTransferProhibited https://www.icann.org/epp#clientTransferProhibited
Registry Registrant ID:
Registrant Name: WHOISGUARD PROTECTED
"Techsummits.org" (referenced in the website)
As a courtesy, I will not post the whois information, as it appears to contain Ms Fitzgerald's personal cell phone as the number.
host techsummits.org
techsummits.org has address 72.9.103.219
techsummits.org mail is handled by 10 mail.techsummits.org.
Subscribe to:
Posts (Atom)


