Tag Archive for 2021

Have a Merry T. rex mas

T.Rex ChristmasMerry Christmas from T. rex. ‘Rex’ an animatronic Tyrannosaurus Rex at London’s Natural History Museum is sporting a giant ugly Christmas sweater. His ugly sweater sports a Stegosaurus-inspired snowflake pattern.

Despite what Steven Spielberg tells us T. rex did not have anything to do with the Jurassic period. Tyrannosaurus Rex lived during the Cretaceous period, about 50 million years after the end of the Jurassic. That means they would be used to much higher temperatures than we are today. So it makes sense that a modern T. rex would want a holiday sweater.

Carla Treasure, a buyer and product developer at London’s Natural History Museum, told the BBC they wanted to do something fun to encourage people back after a tough year of COVID lockdowns. Ms. Treasure said, “There is nothing more funny than a jumper fitted for a dinosaur that has the tiniest arms in the world.” She continued, “I think he looks absolutely fabulous …  we really wanted to do something which would generate interest.

Ms. Treasue explained human-sized versions are available at the museum gift shop or online. Proceeds will help to fund the museum’s work. “All the proceeds from the sale of these jumpers goes back to supporting the museum, not only for its pioneering research but also caring for its 80m specimens.

T.rex Ugly Christmas sweater

The Natural History Museum chose British Christmas Jumpers to make the Tyrannosaurus Rex’s ugly Christmas sweater. The UK-based firm was chosen because the T. rex sweater was manufactured using recycled yarn and plastic bottles.

Snahal Patel, director at British Christmas Jumpers, said T. rex’s ugly Christmas sweater was the company’s biggest job. It took staff 100 hours to complete. The jumper is 12 times heavier than a regular sweater.  He said,  “We’ve never done anything like this.

Stay safe out there!

Related article

 

Ralph Bach has been in IT long enough to know better and has blogged from his Bach Seat about IT, careers, and anything else that catches his attention since 2005. You can follow him on LinkedInFacebook, and Twitter. Email the Bach Seat here.

9 Fun Facts About Christmas Vacation

9 Fun Facts About Christmas Vacation

National Lampoon’s Christmas Vacation made its debut in movie theaters on December 1, 1989. Christmas Vacation unleashed more Griswold family dysfunction upon the world and created a classic holiday movie. Here are some things you might not know about one of my favorite Christmas comedies.

1. Christmas Vacation is based on a short story

Christmas Vacation is based on the short story, “Christmas ’59,” written by John Hughes for National Lampoon in December 1980. The movie pays tribute to the short when Clark is trapped in the attic and pulls out a box of old home movies, including one labeled “Christmas ’59.”

2. The Christmas Vacation cast was very impressive

Christmas Vacation’s cast is chock-full of seasoned comedy performers, including leads Chevy Chase and Beverly D’Angelo but also featured older stars and early roles for younger actors.

  • Johnny Galecki – Rusty Griswold, went on to star in Roseanne before being cast as co-lead Dr. Leonard Hofstadter in The Big Bang Theory. He earned a Golden Globe nomination for Big Bang Theory.
  • Juliette LewisJuliette Lewis – Audrey, made more movies post Christmas Vacation including Natural Born Killers, What’s Eating Gilbert Grape, and the 1991 remake of Cape Fear, for which she received a best-supporting actress Oscar nomination.
  • Julia Louis-Dreyfus was the Griswolds’ yuppie neighbor Margo Chester. Soon after Christmas  Vacation, she would debut on “Seinfeld” and the rest is television history.
  • Randy Quaid – Cousin Eddie, earned a best-supporting actor nomination. He was a Saturday Night Live member from 1985 to 1991. He also starred in the Roland Emmerich disaster sci-fi Independence Day.
  • E.G. MarshallE.G. Marshall – Art Smith, played the father to Ellen Griswald. Before his role in the Christmas classic, appeared in 1957’s 12 Angry Men. His TV credits include  The Defenders, The Cosby Show, and Chicago Hope. He died at the age of 84 in 1998.
  • Doris Roberts – Francis Smith (Clark’s Mother-in-law), career began in 1951. Her most notable role is probably as Ray Romano’s outspoken mother, Marie, in Everybody Loves Raymond. She died in 2016 at the age of 90.
  • Diane Ladd – Nora Griswold, the mother to Clark. her career started in the 1950s. Her credits include Gunsmoke, Alice, and The Love Boat and the movie Chinatown and Primary Colors.
  • Mae Questel – Bethany, Clark’s aunt. Her career began in 1930. She was the voice of both Betty Boop and Olive Oyl. She passed away at the age of 89 in January of 1998.

3. Christmas Vacation has ties to another holiday classic

Footage from the Frank Capra classic holiday movie It’s A Wonderful Life appears in the Christmas Vacation. In the scene where the Griswolds are putting up their tree, Capra’s 1946 film It’s a Wonderful Life is on the TV. Christmas Vacation has another fun tie to It’s a Wonderful Life: Frank Capra’s grandson, Frank Capra III, is Christmas Vacation’s assistant director. 

2. Clark Griswold grew up in Samantha Stevens’s house

BewitchedClark’s childhood home is the same house featured on Bewitched as well as The New Gidget. It is part of the Warner Bros. backlot, located on what is known as Blondie Street. And if the home of their snooty neighbors, Todd and Margo, looks familiar, that’s because it’s where Roger Murtaugh (Danny Glover) and his family lived in Lethal Weapon.

9. Clark’s rant was fake

Beverly D’Angelo explained in a 2015 conversation with The Dinner Party Download, that Clark’s rant was scripted.

… this particular scene … was blocked in a way that would allow each of us to have around our necks a piece of rope that was attached to a big cue card. The rant was divided into sections so that he could go all the way through from the beginning to the end without a chance of forgetting his lines … If you watch it, you can see him. His eyes go from character to character as he’s going on in the speech because we’ve got the lines there.

 

8. Ellen Griswold lied to the cops

In the scene where Ellen Griswold apologizes to Mrs. Shirley—the wife of Clark’s boss/Eddie’s kidnapping victim—assuring her that “This is our family’s first kidnapping,” when, it was the second kidnapping that we know of. In the first Vacation film, the Griswolds force Lasky (John Candy), the security guard to open Wally World for them.

6. You can buy your own Dickie

Randy Quaid borrowed many of Cousin Eddie’s mannerisms from a guy he knew growing up in Texas, most notably his tendency toward tongue-clicking. But Eddie’s Dickie? That was an idea from Quaid’s wife. You can buy your own Cousin Eddie dickie at the National Lampoon’s Christmas Vacation Collectibles, a website dedicated to all things Christmas Vacation.

5. Roger Ebert did not like Christmas Vacation

Though it has become a bona fide holiday classic, not everyone was a fan of Christmas Vacation. Roger Ebert gave it two stars out of five in his review of the film. Mr. Ebert described the movie as “curious in how close it comes to delivering on its material: Sequence after sequence seems to contain all the necessary material, to be well on the way toward a payoff, and then it somehow doesn’t work.”

Stay safe out there!

Related article

 

Ralph Bach has been in IT long enough to know better and has blogged from his Bach Seat about IT, careers, and anything else that catches his attention since 2005. You can follow him on LinkedInFacebook, and Twitter. Email the Bach Seat here.

How Long It Takes Elon Musk to Make Your Salary

How Long It Takes Elon Musk to Make Your SalaryElon Musk is the CEO of the electric car company Tesla (TSLA) and space tourism company SpaceX. He is also notorious for his Tweets, pimping cryptocurrencies, fathering a human baby named X Æ A-Xii, and hosting Saturday Night Live. But there is one thing he is even more known for.

Elon Musk's wealth exploded over 600% during the COVID pandemic.Elon Musk is wealthy. His wealth exploded over 600% during the COVID pandemic. According to Forbes, his net worth in 2020 was $24.6 billion. That was good enough to be placed number 31 on Forbes’s list of billionaires. In 2021 Bloomberg called the SpaceX CEO the richest person on earth with a personal wealth of $266 Billion. Outpacing Amazon CEO Jeff Bezos by $66 Billion.

Elon Musk wealth calculator

To understand how much money that is, click on the UK-based automobile leasing company Select Car Leasing web page. They have built an Elon Musk wealth calculator. As soon as you open the webpage, the number on Musk’s earnings ticker begins climbing. You can see how much money he makes in the time you spend on the page.

how long it takes for wlon Musk to earn what you do in a yearEven more depressing is the page can calculate exactly how long it takes for Musk to earn what you do in a year. Scroll to the bottom of the page and enter your annual salary. It takes Musk less than 3 minutes to make the average American household income of $67,521. Like Mental Floss says, there’s a good chance the answer will prompt an emotion, be it inspiration or infuriation.

Stay safe out there!

Related article

 

Ralph Bach has been in IT long enough to know better and has blogged from his Bach Seat about IT, careers, and anything else that catches his attention since 2005. You can follow him on LinkedInFacebook, and Twitter. Email the Bach Seat here.

Passwords That Won’t Keep You Safe

These Passwords Won't Keep You Safe OnlineI could not let 2021 wrap up without the annual look at the OMG WTF are they thinking worst passwords list. I have been covering the sorry-state of passwords since 2010 and unfortunately little has changed. The biggest change has come in the increased number of mega-breaches leaking passwords all over the Intertubes.

Nordpass logoHere is NordPass’s 2021 list. Nordpass and independent cybersecurity researchers evaluated a database with 4 terabytes’ worth of data. You can visit the NordPass website to see all 200 of the entries from 2021. But here are the top 25 most common passwords:

2021's Worst Passwords

2021's 25 worst passwords compiled by Nordpass.
RankPasswordChange from 2020
1123456-
2123456789-
312345+5
4qwerty+8
5password(1)
612345678-+1
7111111(2)
8123123(2)
91234567890(1)
101234567+1
11qwerty123New
12000000+3
131q2w3eNew
14aa12345678New
15abc123(2)
16password1+3
171234(1)
18qwertyuiop+6
19123321+4
20password123New
211q2w3e4r5tNew
22iloveyou(5)
23654321+1
24666666New
25987654321New

Bad password factoids

  • The top 25 bad passwords can be cracked in less than 1 second by a bot (or person) according to Nordpass.
  • different types of passwords94% of the most frequent passwords – can be cracked in less than 10 seconds
  • The most secure password “myspace1” ranked #54 on the list. It was used by 1,619,027 users and can be cracked in 3 hours.
  • The most popular sport on the list is “football.” It ranked #60 and was used by 1,468,381 users.
  • Superman” protected 1,180,436 accounts. He ranked 81st but could be cracked in less than 1 second.
  • The most popular movie on the list was “starwars.” 701,474 users tried to use the Force to protect their accounts. Unfortunately the Force is not strong with this one, it could be cracked in less than 1 second.

Password risk index

The NordPass researchers also devised a risk index based on the number of passwords leaked in each country per capitaRussia came in first with an astounding 19.9 passwords leaked per capita. Other counties that leaked the most passwords are:

  • The Czech Republic 6.2,
  • France 6.0,
  • Germany 5.8,
  • U.S. 5.2,
  • Italy 4.4,
  • Canada 3.6,
  • Australia3.3
  • and Poland 3.6.

rb-

You can test the strength of your password by visiting this site and typing it in. They claim the site isn’t creating a repository of passwords because your information is never sent over an internet connection. The best part? As you type, the software tells you approximately how long it would take a computer to figure out your password. The site turns red if your password is weak but slowly turns green as you make it stronger. It’ll even give you tips on how to improve your password security.

 

Stay safe out there!

Related article

 

Ralph Bach has been in IT long enough to know better and has blogged from his Bach Seat about IT, careers, and anything else that catches his attention since 2005. You can follow him on LinkedInFacebook, and Twitter. Email the Bach Seat here.

GoDaddy WordPress Sites Hacked?

GoDaddy WordPress Sites Hacked?GoDaddy (GDDY), the world’s largest domain name registrar, disclosed that it had been hacked. According to reports on Monday (11/22/2021), an unknown attacker gained unauthorized access to the system used to provision the company’s Managed WordPress sites. This breach impacts up to 1.2 million GoDaddy WordPress customers. This number does not include the number of customers of websites affected by this breach.

GoDaddy logoThe company posted, We are sincerely sorry for this incident and the concern it causes for our customers,” “We, GoDaddy leadership and employees, take our responsibility to protect our customers’ data very seriously and never want to let them down.

GoDaddy resellers also compromised

On Tuesday (11/23/2021), GoDaddy confirmed that some of their resellers were also compromised in the attack. If you purchased your WordPress domains from

Assume your WordPress site has been compromised.

According to the SEC report filed by the Scottsdale, AZ-based firm, the attacker gained access via a compromised password on September 6, 2021. The attacker was discovered on November 17, 2021, when the attacker’s access was revoked. The attacker had more than two months to establish persistence, so anyone currently using GoDaddy’s Managed WordPress product should assume compromise until they can confirm that is not the case.

What happened at GoDaddy?

credentials in cleartextSeveral sites are reporting that GoDaddy stored sFTP (Secure FTP) credentials so that the plaintext versions of the passwords could be retrieved, rather than storing salted hashes of these passwords or providing public key authentication, which is industry best practice. This decision allowed an attacker direct access to password credentials without cracking them. According to their SEC filing: “For active customers, sFTP and database usernames and passwords were exposed.”

What did the attacker have access to?

The SEC filing indicates that the attacker had access to:

  • User email addresses,
  • Customer numbers,
  • Original WordPress Admin password that was set at the time of provisioning,
  • SSL private key and
  • sFTP and database usernames and passwords.

What could an attacker do with this info?

The attackers had unrestricted access to these systems for over two months. During that time, they could have:

  • Secure FTPThey have taken over these sites by uploading malware or adding a malicious administrative user. This allows them to maintain persistence and retain control of the sites even after the passwords are changed.
  • The attacker would have had access to sensitive information, including website customer PII (personally identifiable information) stored on the impacted sites’ databases.
  • Sometimes, an attacker could set up a man-in-the-middle (MITM) attack that intercepts encrypted traffic between a site visitor and an affected site.
  • The exposed email addresses and customer numbers cause increased phishing risks.

How to resecure your GoDaddy host WordPress site

GoDaddy should be notifying impacted customers. In the meantime, experts recommend that all Managed WordPress users assume that they have been breached and perform the following actions:

  1. If you run an e-commerce site or store PII (personally identifiable information) and GoDaddy verifies that you have been breached, you may be required to notify your customers of the breach.
  2. Change passwordsChange all of your WordPress passwords.
  3. Force a password reset for your WordPress users or customers.
  4. Change any reused passwords and advise your users or customers to do so. 
  5. Enable 2-factor authentication wherever possible. 
  6. Check your site for unauthorized administrator accounts.
  7. Scan your site for malware using a security scanner.
  8. Check your site’s filesystem, including wp-content/plugins and wp-content/mu-plugins, for any unexpected plugins or plugins that do not appear in the plugins menu.
  9. Be on the lookout for suspicious emails.

rb-

These GoDaddy data breaches are likely to have far-reaching consequences. GoDaddy’s Managed WordPress offering makes up a significant portion of the WordPress ecosystem, affecting site owners and their customers. The SEC filing says that “up to 1.2 million active and inactive Managed WordPress customers” were affected. Customers of those sites are most likely also affected, which makes the number of affected people much larger.


Stay safe out there!

Related article

 

Ralph Bach has been in IT long enough to know better and has blogged from his Bach Seat about IT, careers, and anything else that catches his attention since 2005. You can follow him on LinkedInFacebook, and Twitter. Email the Bach Seat here.