Sunday, November 28, 2010

Of Sugar Plums and Fairies...

Happy Hanukkah, festive Pancha Ganapati, contemplative Eid ul-Adha, joyous Yule, eventful Saturnalia, but most of all...

Merry Christmas to all my friends, colleagues, associates and readers.

Yes I said "Christmas" - go ahead and call the authorities, write me up, throw the cuffs on. You can haul me away in irons if you want to, but I celebrate Christmas at this time of year and I am not afraid to say so. I do not celebrate "festivus" or "winter break" or "December holidays", I celebrate Christmas as in Christ-Mass, as in the celebration of the birth of Christ.

Whether you believe December 25th is the actual birth day of Jesus Christ or not, and whether you believe that person was/is the messiah or a prophet or just a highly skilled public speaker, is completely irrelevant. There is no doubt that the person we know historically as Jesus Christ lived, taught, and died somewhere in the Middle East about 2010 years ago and he left behind a controversial legacy that still lives on our calendars today.

The fact is that it is highly unlikely that December 25th is an actual official birth date since most of us know that day was stolen from the Celts when the early Catholic Church "purified" that part of the world. Some date in May makes more sense based on celestial regression, but whatever. I still put up the tree, sing Christmas carols, decorate with copious quantities of light and celebrate like a Roman Counsellor throughout the month of December.

I make or buy presents for people who matter to me and I get them something that will make them feel warm and comforted. This is as close as I can get to the gift of life, peace, and joy that all Christians (all people for that matter) should aspire to. If we all thought this way throughout the year, there would be no need for borders, walls, armies or politics. I fill my world with bright lights, shiny bobbles and reflective things that make my house look like something Clark Griswold would be proud of. This is a purely symbolic presentation of "light" defeating "darkness" and all the metaphorical implications that go along with that.

Maybe it seems old fashioned, or quaint, or outdated to some, but I don't care. My Christmas season includes baking gingerbread and decorating sugar cookies with my family. We go to friends houses and sing Christmas carols by the fire with one of us playing an old upright piano and another handing out sheet music. Christmas morning starts with a full viewing of "A Christmas Carol" - the 1938 version - followed by a breakfast of Japanese oranges and an exploration into the depths of the stockings that were hanging by the fire just the evening before. Some time during the holiday, I absolutely must watch Its a Wonderful Life and Scrooge (Alasdair Sim version). My ideal Christmas Eve is spent with friends out for dinner or at a movie followed by a candle light service in a country church surrounded by fir and cedar trees - a little snow on the branches makes that perfect.

I have friends who are Jewish, Muslim, Hindu, Christian, and Pagan and I try to acknowledge their religious holiday's when I know about them. Its never a problem for me to say "Happy Hanukkah" or "Festive Yule", so why do people take exception when I say "Merry Christmas"? I understand the need for a generic "Winter Holiday", but when I say Merry Christmas, that is exactly what I mean.

So I hope my Jewish friends have a Happy Hanukkah and I wish my Pagan friends a Festive Yule. As we approach the 25th though, I want to wish my Christian friends a Merry Christmas filled with joy, peace, light, and hope for more of the same throughout the coming year.

Friday, November 26, 2010

Spear Phishing Attacks On The Rise

I am not usually one to jump on "the band waggon" and parrot what every other blogger is saying, but I am going to make an exception in this case because it is important - really, really important.

Within the high volume mail industry there are companies known as ESPs or Email Service Providers, who provide a platform for others to send mail through. Some of the biggest in the world are clients I work with and they help small to medium sized businesses send valuable mail to their clients and end users. These are not spammers, they are legitimate delivery platforms that provide a valuable service to legitimate clients. If your small business needed to send a product alert to 50,000 end users by email, you would probably use one of these services instead of spending thousands of dollars on your own mail system.

Here is the problem though. Some very bad people - lets call then "organized criminals" - have managed to inject a viral spear phishing attack into about 100 ESPs worldwide. The mail looks legitimate to the ESPs so they transport is as per their contracts. When you receive the mail, you may click on an embedded link that takes you to a third party web site that looks completely legitimate, but in the back ground this site is installing a virus into your computer that is designed to steal passwords and other important data.

I need to stress that this is NOT the fault of the ESPs or their clients, but rather a complex criminal act perpetrated by third parties. There is a very good article on the problem and the background in this following link so I wont rehash it myself in too much detail.

http://krebsonsecurity.com/2010/11/spear-phishing-attacks-snag-e-mail-marketers/

In a nutshell, do NOT click on ANY link in ANY email that you do not know has come from a trusted source. I received one of these myself and it looked like an update from a friend who had just been married and the link was to weddingphotos.net. That site actually looks legitimate, but in the background it tries to install malware that will steal your system passwords and try to install remote control software to your PC.


And here is another:

Dear Tom Mairs,

Stephanie just sent you an ecard from 123Greetings.com

You can view it by clicking here:

http://www.123greetings.com/send/view/2210394848736232

You can also copy & paste the above link into your browser's address bar.

Or if you prefer, you can go to http://www.123greetings.com/ and type your
ecard number (2210394848736232) in the "Search Box" at the top right of the page.

Your ecard is going to be with us for the next 30 days.

If you need any help in viewing your ecard or any other assistance,
please visit our Help/ FAQ section at: http://help.123greetings.com/

We hope you enjoy your ecard,

Your friends at 123Greetings.com
http://www.123greetings.com

We respect your privacy. You will not be receiving any promotional emails from us
because of this ecard. To view our privacy policy, click on the link below:
http://info.123greetings.com/company/privacy_policy.html

Note: This is an auto generated mail. Please do not reply.

If you have any other problem please contact us by clicking on the following link:
http://help.123greetings.com/contact_us.html

This email was sent by 123Greetings.com, Inc., 1674 Broadway, New York, NY 10019.



So please be very careful of anything you get in your email that does not look ligit - it probably is not.