Damus
Bob Young profile picture
Bob Young
@Bob Young

Remote English-speaking tech support to residential, small business, and SOHO clients, mainly (but not exclusively) in the USA. Sole proprietor, FIFO Networks.
Cybersecurity - Networks - Wireless – Telecom - VoIP

I do a fair amount of custom work for people when a loved one dies: unlocking computers, data recovery, and account recovery (Advice: keep paying their cell phone bill until you've got all their data back).

Use https://fifonetworks.com/contact-us/ for questions or to schedule service. It's just me. You'll be communicating directly with me.

Licensed and Insured.

Relays (1)
  • wss://relay.ditto.pub – read & write

Recent Notes

Bob Young profile picture
And speaking of Meta Muse: I wonder if anyone on the board at Meta has figured out yet that Mark Zuckerberg has become toxic to the brand. His face and his name are associated with loss of privacy, dishonesty, and forced opt-in.

If the Meta board would decide to oust Zuckerberg and publicly denounce him, they might have some opportunity to recuperate the brand names they manage.

But right now, Zuckerberg is the very face of user exploitation.

#meta #muse #zuckerberg #facebook #instagram
Bob Young profile picture
I see a lot of posts without adequate context. In other words, the Original Poster assumes a "common base of knowledge" without any evidence that the common base of knowledge exists. Newsflash: we don't all read the same things. We don't all see the same posts. Without context, your post falls flat. You expend energy with unpredictable return on your investment. There are two solutions, use either one where appropriate. (1) Your posts should be self-contained. They should stand alone. They shouldn't assume prior common knowledge. Or, (2) Your posts should include the background information (for example, a hyperlink, picture, whatever) that will deliver the context.
If you want to speak out, at least try to have an impact. You've got to communicate effectively, or your post is nothing more than emotional self-gratification.
Bob Young profile picture
Botnets everywhere...

The client’s firewall was installed with the default settings only. They changed IT resources and started paying me a monthly fee for network infrastructure monitoring (yay!). I tightened up the firewall’s security settings, and discovered they were paying licensing fees for seciurity features that had never been activated. Next, I reset the log counters, set up email alerts, and started paying attention.

Wow. In a couple of days I was seeing a lot of outbound traffic communicating with known botnet command-and-control (C&C) servers.

I notified the business owner, and he authorized me to do a network scan during working hours to identify the devices with the IP addresses recorded in the logs.

Good news! Every one of the compromised devices was a mobile device; some Apple, some Android. No servers, no workstations, no printers. This company has two Wi-Fi networks: StoreName, and StoreName Guest. The next step was to change the encryption key (what most people call the Wi-Fi password) for the StoreName network, and limit access to devices like wireless printers and security cameras. This ensured that no employee or customer phones were connecting to the enterprise LAN.

As a courtesy, employees were notified that there were some infected smartphones (“We don’t know who, but it may be you”) and offered the opportunity to compare their phone’s Wi-Fi IP address against the list derived from the logfile.

LESSON 1: A firewall installed with its default settings is good. A firewall configured by someone who knows what they’re doing is better. A firewall that is configured and actively monitored is best.

LESSON 2: A guest Wi-Fi network, isolated from the company network, isn’t a luxury; it’s a necessity, if you’re going to let employees and customers use Wi-Fi in your building.

#CallMeIfYouNeedMe #FIFONetworks +1 206-465-2422

#RemoteSupport #TechSupport #HelpDesk

Bob Young profile picture
How to be popular on social media... Post stupid stuff.

Example 1: I posted a meme making fun of grok. Result: 133 favorites, 72 boosts.

Example 2: I posted about a real Microsoft vulnerability, which is password reuse institutionalized in Microsoft policy. Result: 2 favorites, no boosts.

<sigh>

Social media isn’t really about learning, is it? It’s about shitposting.
2
tekhedd · 20w
nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpqu926d69pfyl83jl5mytdpmrvz9la9z3zr5g35h3rjar5hsyn8m6snr75wv er, insert "It's All Shitposting; Always Has Been" meme here ;)
Mark T. Tomczak · 20w
nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpqu926d69pfyl83jl5mytdpmrvz9la9z3zr5g35h3rjar5hsyn8m6snr75wv Yes, correct. Or, if I may... The metrics are off, in that they don't track what you may care about. Posts that are least specific resonate with the most readers, and that'll boost you...
Bob Young profile picture
There’s a lot of misleading advertising about residential (consumer grade) VPNs. The purpose of this post is to clarify the difference between IP Masking and Virtual Private Networks.

WHAT IS A VPN?
From the official IETF documentation:
RFC 4026, Paragraph 3.10. Virtual Private Network (VPN)
“VPN is a generic term that covers the use of public or private networks to create groups of users that are separated from other network users and that may communicate among them as if they were on a private network. It is possible to enhance the level of separation (e.g., by end-to-end encryption), but this is outside the scope of IETF VPN working group charters.”

What does that mean in non-technical terms? It has two parts:
1) A VPN is a private link between two endpoints connected to each other over a network that is also used by others.
2) The private link may be encrypted (and often is), but that’s not a requirement to be classified as a VPN. (For those who are trying to wrap their head around the idea of an unencrypted VPN, I’ll give one example without going into any technical explanation: an unencrypted GRE tunnel is a VPN).

WHAT IS IP MASKING?
Refer to the middle picture. IP masking is when you use a relay service to hide the source IP address, or the destination IP address, from interested third parties.

WHAT’S MISLEADING?
Refer to the bottom picture. You don’t need to pay for a VPN service to do safe online purchasing or banking. Every time you see the padlock in your browser, or the “https” prefix on the address, you’re using an encrypted VPN connection.

THE LESSON
Next time you see an ad for residential VPN service, pay attention to the wording. What are they really trying to sell? The privacy of the VPN is automatic with https. All they’re really offering is IP masking. Do you need it? (Some people really do).

#CallMeIfYouNeedMe #FIFONetworks

Cybersecurity - Networks - Wireless – Telecom – VoIP

Bob Young profile picture
My Android phone just got the March feature drop, and it took me a half hour to go through the settings to find and disable all the changes they made that I don't want or care about. There's still one more thing I want to disable, but I haven't been able to find it yet in the settings.
Which I interpret to mean they really, really don't want me to disable it.
#android
alcinnz · 29w
The fedi should have relevant experts able to inform my upcoming threads... How does flash memory behave as it wears out? I'm particularly interested in figuring out what the most appropriate error-...
Bob Young profile picture
@nprofile1q... From Lumo AI:
"Testing flash memory for errors involves checking for bad blocks, verifying data integrity, and assessing the drive's health metrics. Since flash memory (like SSDs, USB drives, and SD cards) behaves differently than traditional hard drives, the methods vary slightly depending on your operating system and the level of detail you need.

Here is a breakdown of the most effective methods:

1. Using Built-in Operating System Tools
These are the safest first steps as they don't require installing third-party software.

Windows (CHKDSK): The chkdsk utility scans the file system and the physical disk surface for errors.

Open Command Prompt as Administrator.
Run: chkdsk X: /f /r (Replace X with your drive letter).
/f fixes logical file system errors.
/r locates bad sectors and recovers readable information.
Note: This process can take a long time on large drives.
macOS (Disk Utility):

Open Disk Utility (Applications > Utilities).
Select the flash drive from the sidebar.
Click First Aid and then Run. This verifies and repairs the partition map and file system.
Linux (fsck):

Ensure the drive is unmounted: sudo umount /dev/sdX1.
Run: sudo fsck -v /dev/sdX1.
For a more thorough check that attempts to recover bad blocks, you can use badblocks, but be cautious as some modes are destructive.
2. Specialized Third-Party Tools
For a deeper analysis, specifically looking at the physical health of the NAND flash cells and the controller, dedicated tools are superior.

CrystalDiskInfo (Windows): This tool reads S.M.A.R.T. (Self-Monitoring, Analysis, and Reporting Technology) data. It provides immediate insight into:

Total Bytes Written (TBW).
Reallocated Sector Count.
Uncorrectable Error Count.
Power-On Hours.
Verdict: If the status is "Caution" or "Bad," the drive is likely failing physically.
HDDScan: A free utility that allows you to run surface tests (Read, Write, Erase) on the drive.

Read Test: Scans for slow or unreadable sectors without modifying data.
Write/Erase Test: Warning: This will destroy all data on the drive. It forces the controller to rewrite every block, revealing weak cells that fail under stress.
F3 (Fight Flash Fraud): Essential for verifying the actual capacity of a drive. Many counterfeit flash drives report a larger size than they physically have.

F3Write: Writes data to the entire drive.
F3Read: Verifies the data.
If the read fails or data is corrupted at a specific point, the drive is likely a fake or has failed beyond that point.
3. Understanding the Results
When analyzing the results, keep these flash-memory-specific factors in mind:

Bad Blocks vs. Bad Sectors: Flash controllers often remap bad blocks internally. If a tool reports many "reallocation" events, the drive is wearing out.
Wear Leveling: Flash memory wears out after a certain number of write cycles. Tools that show high "Program/Erase Cycle" counts indicate the drive is nearing its end of life.
Controller Issues: Sometimes the NAND chips are fine, but the controller managing them is faulty. This often manifests as the drive disconnecting randomly or becoming read-only.
Recommendation
Backup your data immediately before running any write-intensive tests.
Start with CrystalDiskInfo (or equivalent) to check S.M.A.R.T. health.
If the health looks okay but you suspect corruption, run CHKDSK or First Aid.
If you suspect the drive is counterfeit or has hidden physical defects, use F3 (for capacity verification) or HDDScan (for surface scanning)."
Bob Young profile picture
Regarding the fear that AI will ruin our ability to think and our will to work: this concern was also common at the advent of...

1) Paperback novels
2) Comic books
3) Commercial AM radio
4) Television (the “boob tube”)
5) Pocket calculators
6) Gameboys

...and the list goes on.
#ai
Martin Boller :debian: :tux: :freebsd: :mastodon: :heart_pride: · 30w
nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpqu926d69pfyl83jl5mytdpmrvz9la9z3zr5g35h3rjar5hsyn8m6snr75wv in seconds (answers both)
Bob Young profile picture
There's a lot of speculation now about how reliance on AI is going to make us stupid. I disagree.

The premise is that the younger workers are going to rely on AI, and when the current truly skilled workers age out, the up and coming workers won't have the deep knowledge of their craft. They'll be dependent on AI, and won't have the experienced understanding necessary to innovate.

History tells us a different story. I'll share an illustration with you. I've used this illustration before, when personal computers became popular, and again when the Internet spread from the university to the home.

So, here you go. Think about this.

You don't know how to make lye soap.
You don't know how to make candles from beef tallow.
You don't know how to shear sheep or spin their wool into yarn.
And on and on.
And yet these skills, and others, were common in America's pioneer days

The point is that the skills and knowledge that members of a society need are constantly changing, ever evolving.

When I started my career in electronics, there were twchnicians who made their living in a TV repair shop. Today there are adults who don't even know TV repair shops were a thing. I can still repair a tube-type television, but I can't make a living with that skill. Now I do computer and network support.

It's hard for us to see the new skills that will be needed, but they're imminent. Needs will arise. Challenges will be met. People will see opportunities, and skills will be developed.

We depend on cars instead of horses.
We depend on gas furnaces instead of fireplaces.
We depend on freezers instead of salting our beef.

Will we depend on AI?
Probably. It's looking more and more likely.

Remember that we, as a species, are survivors. New problems compel us to find new solutions.

Dependencies don't finish us.
They drive us.
They drive us forward.
Bob Young profile picture
The client's firewall was blocking VPN attacks from IP addresses in the USA. Randomized timer with attempts anywhere from 2 seconds to 15 minutes apart. Brute force attack using first initial, last name. In the lower left corner, 19:47:05 is the last entry before I blocked the entire Class B address range.

#CallMeIfYouNeedMe #FIFONetworks #cybersecurity

Cybersecurity - Networks - Wireless – Telecom – VoIP