Tag Archive for 1%

Labor Day 2020

Labor Day 2020It is Labor Day in the U.S. In the past, Labor Day was a celebration of working men and women. On Labor Day 2020, in the midst of the COVID-19 pandemic and economic havoc, the percentage of people actually employed in the U.S. has recently hit an all-time low.

COVID-19 virrusIn August 2020 (the last full set of data) the BLS says the employment-population ratio stood at 56.5%. For comparison, the rate stood at 59.8% in December 2016, before Trumpie and his fellow travelers started their reign. That means that 45.4% of the civilian noninstitutional population – did NOT have a job. 

This number is an improvement from the historically low 51.6% we saw in April 2020 – there are still over 7 million people not working.

Statista Employment Population ratio
24/7 Wall St. reviewed unemployment at the metropolitan area level for USA Today to identify the cities with the worst unemployment problem. It is not a big surprise that Michigan has been hard hit. They ranked 4 Michigan metro areas in their list of areas most impacted by the COVID-19 layoffs.

Battle CreekFlintDetroit metroMuskegon
Impact33211211
Unemployment rate15.1%16.6%17.7%17.8%
YTD change-8.7%-8.2%-19.0%-8.0%
COVID cases69981311,83629
Poverty rate18%18.8%14.3%15.8%

rb-

Middle class squeezed

Real unemployment at the height of the 2020 recession (so far) has reached levels not seen since the Great Depression. In April 2020, the real unemployment rate, including discouraged, marginally attached, and part-time, was 22.8%. The unemployment rate during the Great Depression surpassed 25% from March 1933 to June 1933. 

In case you’re wondering, the civilian noninstitutional population comprises of all persons aged 16 and older who reside in the 50 states and the District of Columbia, are not inmates of institutions (e.g., penal and mental facilities, homes for the aged), and who are not on active duty in the Armed Forces.
 

Are you better off this year than last year?

View Results

Loading ... Loading ...
 

Stay safe out there!

Related article

Ralph Bach has been in IT long enough to know better and has blogged from his Bach Seat about IT, careers, and anything else that catches his attention since 2005. You can follow him on LinkedInFacebook, and Twitter. Email the Bach Seat here.

What You Need to Know About Zoom

Updated 12/01/2020 – Zoom has agreed to settle allegations (PDF) made by the US Federal Trade Commission (FTC) that it “engaged in a series of deceptive and unfair practices that undermined the security of its users.” Among the charges were that Zoom misled users by:

The settlement does not require Zoom to admit fault or pay a fine – So they got away with it.

Updated 05/01/2020 – Zoom made a big splash when CEO Eric Yuan claimed the video conferencing firm had surpassed 300 million daily Zoom meeting users last week. That’s impressive growth in the face of security and privacy holes documented on the Bach Seat and around the Intertubes.

Well in a Zoom tradition they “back-tracked” that announcement, just like they back-tracked their definition of “end-to-end encryption.” Zoom artificially inflated the number of users by counting meeting participants as “users” and “people.” 

Daily meeting participants can be counted multiple times – if you have four Zoom meetings in a day then you’re counted four times. SVCOnline explains that by calling meeting participants “daily users” makes Zoom usage seem larger than it is. The term most companies use to measure service usage is a daily active user (DAU). A DAU is counted once per day. 

Updated 04/08/2020 -Zoom now faces four lawsuits over its security and privacy practices. Today,  Google has banned employees from using Zoom, joining NASA, SpaceX, NYC schools, Clark County (Las Vegas) schools. the governments of Germany and Taiwan as well as Apple.

Updated 04/07/2020Reports of a new blow to Zoom’s security cred’s researchers have discovered up to 15,000 private Zoom recordings exposed online. Many of them were apparently stored in Amazon Web Services (AWS) S3 buckets without passwords.

What You Need to Know About Zoom

Zoom has taken off. Thanks to the global COVID-19 lock-down Zoom’s (ZM) stock has surged over 250% on the NASDAQ since October 2019. Zoom’s video conferencing platform daily usage has exploded from 10 million in December 2019 to more than 200 million in March 2020.

Zoom logo

After its stock price run-up and exploitation of the COVID-19 pandemic Zoom has come under intense scrutiny. The FBI issued a warning about using Zoom. The New York Attorney General’s office sent a letter to Zoom about its practices. Security professionals have found a disturbing list of flaws on Zoom. Here is a brief list of the risks you take when using Zoom.

Zoom Risks

Phishing – Security firm Check Point Software says criminals are waging phishing campaigns with Zoom-related themes as a lure. The phishing emails that Check Point has observed spoof Zoom login pages and attempt to get victims to input their credentials. The Zoom credentials are then harvested by the attackers. Also, Check Point has also uncovered malicious files with names that include “zoom” in the title. 

Encryption

Phony end-to-end encryption – Zoom uses misleading advertising to claim that its meetings use “end-to-end encryption,” according to The Intercept. Zoom uses the term end-to-end encryption” incorrectly. Zoom admitted their definitions of “end-to-end” and of “endpoint” are different from everyone else’s. A spokesperson told The Intercept, “When we use the phrase ‘End to End … it is in reference to the connection being encrypted from Zoom endpoint to Zoom endpoint.

Unlike Apple, Zoom’s data is only encrypted when it travels back and forth from an end-user to a Zoom server. Your data is decrypted at the Zoom server. Zoom (or TLA) can see and hear whatever is going on in its meetings. Zoom Chief Product Officer Oded Gal wrote:

We recognize that there is a discrepancy between the commonly accepted definition of end-to-end encryption and how we were using it.

The Intercept concludes that Zoom doesn’t decrypt user transmissions — but it could.

What You Need to Know About Zoom

Zoom bombing – Zoom bombing occurs when a third party interrupts or takes over a video conference. Anyone can “bomb” a public Zoom meeting. All they need is the meeting number. Attackers can use the file-share to post shocking images or make annoying sounds in the audio. The host of the Zoom meeting can kick out troublemakers, but they can come right back with new user IDs The FBI issued a warning about zoom bombing.

To prevent Zoom bombing do not share Zoom meeting numbers with anyone but the intended participants. Also require participants to use a password to log into the meeting.

Windows password stealing
Bleeping Computer reports that malicious users can use the Zoom side chats to post a Universal Naming Convention (UNC) link that points to a remote server. From there the victim’s Windows computer will try to reach out to the hacker’s remote server specified in the path. From there the PC will automatically try to log in with the user’s Windows username and password. The attacker could capture the password “hash” and decrypt it, giving them access to the Zoom user’s Windows account.

Windows malware injectionWindows malware injection – The same flaw allows a hacker to insert a UNC path to a remote executable malicious file into a Zoom meeting. If a Zoom user running Windows clicks on it, the computer will try to load and run the malicious software. The victim will be prompted to authorize the software to run, which will stop some hacking attempts but not all.

Apple iOS profile sharing – Zoom sends iOS user profiles to Facebook. This is done with the “log in with Facebook” feature in the iPhone and iPad Zoom apps. After Motherboard exposed the practice, Zoom said it hadn’t been aware of the profile-sharing. Zoom’s initial response was to blame the social network’s software development kit used in the Zoom software. CNet concludes that Zoom shares enough personal data that it qualifies as selling your data

Mac malwareMalware-like behavior on Macs – Zoom was caught using hacker-like methods to bypass normal macOS security. It was thought this flaw had been fixed. But security researcher Felix Seele noticed that Zoom installed itself on his Mac without the usual user authorization.

The application is installed without the user giving his final consent and a highly misleading prompt is used to gain root privileges. The same tricks that are being used by macOS malware.

A backdoor for Mac malware – Patrick Wardle, a former NSA hacker and now principal security researcher at Jamf said in a blog post that Zoom used a discontinued installation process. The deprecated process could allow malware to add malicious code to “escalate privileges.” This would allow an attacker to gain total control over the machine without knowing the administrator’s password

Zoom privacy issues

CSO Online reports that he demonstrated the backdoor. He installed a malicious script into the Zoom Mac client. This could give any piece of malware access to the Mac’s webcam and microphone. It would turn any Mac with Zoom into a spying device.

Leaks of email addresses and profile photos – Zoom automatically puts everyone sharing the same email domain into a “company” folder where they can see each other’s information. If you are not a user of large webmail clients like Gmail, Yahoo, Hotmail, or Outlook.com, you could end up in a “company” with dozens of strangers.

Data leakSharing of personal data with advertisers – Privacy experts for Consumer Reports reviewed Zoom’s privacy policy and found that it gave Zoom the right to use Zoom users’ personal data and to share it with third-party marketers. In a blog, Aparna Bawa, Zoom’s chief legal officer, claimed “we do not sell your personal data.” The lawyer definitely concluded, “We are not changing any of our practices.” But we don’t know the details of Zoom’s business dealings with third-party advertisers.

Cloud snitching – For paid subscribers, Zoom’s cloud recording feature can be a problem waiting to happen.  Mashable points out that any time Zoom is used, your person-to-person chat messages are saved and could be sent to your boss by any authorized user. CNet notes that Zoom administrators can limit the recording’s accessibility by IP addresses – but this is not enabled by default.

Tattle-tale attention-tracking feature – Zoom’s attention-tracking feature allows the meeting host to monitor if you are paying attention to their PowerPoint deck. The Zoom desktop client or mobile app alerts the host if any attendees go more than 30 seconds without Zoom being in focus on their screen.

rb-

I agree with those who are calling Zoom’s development processes lazy  As you can see  – Zoom’s software development process creates a huge attack surface.

Tom’s Guide is tracking the status of Zoom’s problems.  So is  Zoom safe to use?  – That is your call. – You need to make an informed decision and patch your Zoom software.

Zoom CEO Eric Yuan

You should be suspicious of “free” products. As in the case of Google and Facebook, you are the product for Zoom. They are monetizing you. Follow the money.

Eric Yuan, the founder, and CEO of Zoom is profiting by using your info. His personal wealth has increased 112% to $7.57 billion in the past three months, as the use of Zoom skyrockets amid the pandemic. While the other 99%f the world braces for a global recession.

How does he get all of that money on free software?

 

Stay safe out there!

Related article

 

Ralph Bach has been in IT long enough to know better and has blogged from his Bach Seat about IT, careers, and anything else that catches his attention since 2005. You can follow him on LinkedInFacebook, and Twitter. Email the Bach Seat here.

Bespoke Coffee Maker

Bespoke Coffee MakerIf your idea of a good coffee is frozen coffee blended with a sugary concoction picked up at the drive-thru window, move on. If you take your coffee really really seriously, this is the coffee maker for you. The Royal Coffee Maker is a balance siphon coffee brewer. Siphon coffee brewers were first seen in the 1850s. The King of Hungary wowed his guests with one during a royal banquet, transforms coffee-making into a high ceremony.

Royal Coffee MakerThe handcrafted Royal Coffee Maker could be the most extravagant coffee maker in the world. French sculptor Jean-Luc Rieutort designed this precision machine which includes 24-karat gold (or silver) and crystal and semi-precious stone. Only eight of the bespoke coffee makers are produced by hand each month. Each coffee maker takes more than 50 hours of painstaking workmanship to complete. The Royal Coffee Maker costs $24,000.

The Royal Coffee Maker is a fully automated system. It is designed to allow heat, steam, and gravity to brew the coffee at the perfect temperature. Coffee grounds are placed in the Baccarat crystal carafe, along with an optional touch of Grand Marnier or other liqueurs. Hot water is poured into the 24-karat boiling pot and the Baccarat burner vase lit. Perfectly heated water travels to the grounds before suction pulls the finished brew back into the pot. The coffee maker also comes with a matching custom-made coffee scoop. And you can have your family crested engraved on it.

 

rb-

How 2016 presidential candidate Donald Trump spends his billions 2/19 Slideshow One Page Trump's penthouse has a gold- and diamond-covered doorIntrigued? Prepare to skip your next 4,800 Starbucks to afford the most self-indulgent coffee maker on the planet. Of course, if you are going to be Trumpian about it, you might as well brew up some Kopi Luwak coffee beans in your 24-karat gold balancing siphon coffee brewer.

 

Related articles

Ralph Bach has been in IT long enough to know better and has blogged from his Bach Seat about IT, careers, and anything else that catches his attention since 2005. You can follow him on LinkedInFacebook, and Twitter. Email the Bach Seat here.

Labor Day 2018

Southeast Michigan is, in many ways, the birthplace of the American Middle Class. Labor Day is here again the celebrate the working man’s contribution to America. But in 2018 the working class is under siege. One way to celebrate labors’ contribution is to look at the artifacts of the last time the economy was so out of whack.

Detroit Industry

One magnificent artifact is “Detroit Industry” at the Detroit Institute of Arts. “Detroit Industry” is a four-wall mural created by Diego Rivera in 1932-1933. The murals depict the history of Detroit and the development of industry.

"Detroit Industry" by Diego Rivera. 1932-1933

The DIA commissioned Detroit Industry, with backing from DIA patron Edsel Ford. The only request was that the murals address the history of Detroit and the development of industry.

Diego Rivera

Rivera and his spouse Frida Kahlo arrived in Detroit in 1932 during the depths of the “Great Depression.”  He completed the fresco in 1933. The images show Rivera’s take on big-time American capitalism. They simultaneously glorify the culture of the modern factory as well as slyly savaging the men in charge.

This panel, from the north wall. “Production and Manufacture of Engine and Transmission,” is based on Rivera’s observations of the 1932 Ford V-8 being produced at Ford Motor Company‘s (F) River Rouge factory. Rivera’s work represented a multiracial workforce was an important aspect of his idealism.

rb-

The 1% and their wanna-be fellow travelers have out-organized the working class to pick a president to further tip the scales in their favor.

Related articles

 

Ralph Bach has been in IT long enough to know better and has blogged from his Bach Seat about IT, careers, and anything else that catches his attention since 2005. You can follow him on LinkedInFacebook, and Twitter. Email the Bach Seat here.

Google Founder Sets Sail on Senses

Google Founder Sets Sail on SensesGoogle co-founder, Larry Page has bought a $45 million yacht. The New Zealand Herald reports that Mr. Page bought the 193-foot superyacht Senses from the New Zealand millionaire Douglas Myers for $45 million. The boat is equipped with twin 1600 HP Deutz diesel engines with a maximum speed of 15 knots, a cruising speed of 11 knots, and a range of 6,500 nautical miles.

Larry Page $45 million 193-foot super yacht Senses

The Business Insider says the 37-year-old Google billionaire’s new toy includes:

  • Larry Page $45 million 193-foot super yacht SensesInteriors finished by French designer Philippe Starck
  • Two dining rooms, one inside and one outside
  • A gym
  • On-deck jacuzzi
  • Accommodations for 24 people (10 guests and 14 crew)
  • Helipad
  • and a small flotilla of pleasure crafts

Mr. Page’s new boat is a toy among the tech elite’s boats.  Oracle’s Larry Ellison‘s boat ‘Rising Sun’ is 454-ft long, and Microsoft co-founder Paul Allen‘s ‘Octopus’ comes in at 415-ft in length (which may explain why Allen is suing most of the tech world – which I wrote about here).

rb-

Larry Page $45 million 193-foot super yacht SensesIs this Larry Page’s reward to himself now that Eric “Mr. Creepy” Schmidt is out and Mr. Page is the CEO of Google? Is this a case of Mr. Page looking to one-up or hide from the hype Facebook’s Mark Zuckerberg, Time Magazine’s Man of the Year who also has an eagerly anticipated initial public offering and a  movie loosely based on his life?

Related article

Ralph Bach has been in IT long enough to know better and has blogged from his Bach Seat about IT, careers, and anything else that catches his attention since 2005. You can follow him on LinkedInFacebook, and Twitter. Email the Bach Seat here.