Showing posts with label Computer. Show all posts
Showing posts with label Computer. Show all posts

Tuesday, 2 September 2025

Those silent mobile calls

Last week, I wrote here about the fake Facebook friend requests that land in our notifications with regularity. This week it’s the turn of another petty irritation. This one arrives not through social media but through the good old-fashioned telephone call: the kind that rings once, we pick up and immediately it is gone.

At first, I wondered if these were some exotic new scam, like the so-called “one ring” tricks that tempt you into dialling back premium numbers. But actually, these are more mundane, if no less irritating. They come from robocallers and autodialers. Sometimes, dropped calls from busy call centres. The real culprit, though, is usually a machine pushing through numbers at industrial scale.

It is a familiar pattern. Our phone rings, we answer, a silence from the other end, and then click, gone. A dead line. That silence is a machine quietly registering our number as live so that we confirm ourselves as targets for the next wave of nuisance calls.

How did they get our numbers in the first place? I suspect through the endless breaches of telco and online government databases, or some website portal with leaky security. Our details get spilled into an underground marketplace of the Internet. Once a number escapes into that underground marketplace, it never escapes. It gets copied, repackaged and resold. Other times, the fault lies with “legitimate” data brokers, who scoop up information whenever we sign up for something trivial, in exchange for their free gifts. A common ploy nowadays which I counter with fictitious numbers and email addresses. Then there’s brute force autodialers that simply spin through every possible number in a given sequence until someone answers. 

And finally, spoofing. The number flashing on the mobile screen may look local or familiar, but it is fake. The sensible course of action is not to call back. Don’t feel obliged to answer unknown numbers. Block nuisance calls when we can, which I've begun to do lately. None of this will make the problem go away but at least it helps to know the game the scammers are playing.

If there’s any consolation, it’s that silence is still the best reply. Don't even say hello. After all, why waste words on a machine that doesn’t listen? At least with phones, unlike with people, we can block the number with a single tap and move on with our lives.


Friday, 22 August 2025

It's all in the planning!

My old blog, It’s All In the Planning, is gone forever. I let it lapse on the 19th of last month. For years, I had toyed with shutting it down, yet each time the renewal reminder arrived, I gave in and paid the fee out of habit and sentiment. But there comes a point when even old projects deserve their rest.

It’s All In the Planning was my second attempt at blogging. The real beginning was with ssquah.wordpress.com, which I started in 2007 when The Star temporarily ended my chess column in February that year. That initial WordPress blog, suggested to me by a co-worker at JonStreet.com when I voiced my frustration to him, was my way of filling the sudden void. I needed a release for my creative energy and found it in the blog. My first personal digital space for self expression. Unfortunately, WordPress in its infinite wisdom decided one day that I had violated something or other, and suspended it without warning.

Frustrated but unwilling to stop, I moved on to a local hosting provider and set up It’s All In the Planning. I even reproduced most of my earlier writings there so little was lost. That’s the blog that lasted the longest, consisting of more than a thousand stories and presumably reaching almost a million words, and in a sense became my enduring online home.

When I finally ignored the automated emails asking me to renew the domain, letting it slip away on the 19th of July, it felt like closing the door on a chapter that ran for well over a decade. But then, traffic had dwindled to almost nothing, and I hadn’t written anything new there for years. The site had become a shadow of its former self, and the 1,534 stories had become old and dated, with some made irrelevant by changing circumstances. Nevertheless, I took to archiving them all, so there was no risk of losing my output. What remained was only a domain name and my own stubborn attachment to the past.

Now, anyone visiting the site would be greeted only by the finality of an error page: a simple punctuation mark at the end of a long sentence. An end to one of my efforts. Impermanence to the core.

Anyhow, my writing has never really stopped, has it? It's only the ground that shifted. What I once poured into It’s All In the Planning has long since found continuity here on this present blog, Anything Goes, which I'm sure will remain visible as long as Google exists. The voice there is the same as the voice here, only tempered by time and filled with more reflection as I grow older. Those first two blogs may be gone, but the act of writing carries on. One chapter closes, another continues.



Thursday, 21 August 2025

Fake facebook friend requests

How much can Facebook be trusted nowadays? On a regular basis, I keep receiving friend requests from people I already know to have a Facebook account. When I dig deeper into these requests, I find that they come from newly created accounts with either very few friends or none at all, and with timelines that are completely empty. Should I be careful with accepting such requests? Absolutely.

In fact, these are classic warning signs of fake profiles, and there are plenty of risks if we are to accept them blindly. Scammers and spammers set up these ghost accounts precisely to gain access to our personal information. Once “accept” is clicked, they can peek into whatever we’ve set to “Friends only”: photos, contact details, snippets of our lives that we wouldn’t ordinarily share with strangers. That information is enough to be exploited. Sometimes for phishing purposes, sometimes for identity theft.

The danger doesn’t stop there. A fake “friend” can start messaging us with links, often dressed up as something harmless or even urgent. If we're not careful, we might end up with malware lodged in our devices, malware that quietly siphon away our data. There’s also the trick of impersonation: scammers pretending to be someone we know, sending messages to our real friends asking for money or sensitive information.

This isn’t just theory either. Several years ago, it happened to my wife. One day, I received a Facebook friend request under her name. I was puzzled: why on earth would she be opening a second account when she barely touched the first one? I asked her, and she flatly denied it. Then I showed her the request, and her reaction said it all: she hadn’t created the account. The giveaway was the profile picture. It was one of hers, but the choice of image was questionable. Controversial, even. That was the moment we both realised she had been impersonated. I immediately told her to lodge a complaint with Facebook, and eventually, that bogus account was taken down.

Cases like this are textbook examples of account cloning, where a scammer copies a name and a photo and then tries to worm their way into your circle of friends. Once accepted, they can start spreading their scams under the guise of someone you trust.

Over time, I’ve learnt to look out for red flags. A profile with very few friends and no posts is the most obvious. But there are subtler signs too, such as the account might be brand new with hardly any history, the profile picture suspiciously generic or lifted from elsewhere on the internet, or the page lacking the sort of personal touches a genuine account would naturally have, like school, workplace or location. very few mutual friends is another telling giveaway. And on the rare occasion the profile does have posts, they often read as oddly repetitive or littered with strange links.

So what to do? The simplest answer is to ignore the request. I don’t give a fake account even the faintest toehold into my social circle. If I’m certain it’s bogus, I alert the friend that has been impersonated. If there are mutual friends listed, I check with them directly, outside of Facebook if possible, before telling them to unfriend the account fast although it may already be too late to prevent any data loss.

For me, the lesson is clear: vigilance is the only safeguard. The Facebook of today is not the same platform it was in the past. It’s more crowded, more complicated and more riddled with traps. It's unfortunate, but one careless click can open a door I’d rather keep shut.


Monday, 28 July 2025

The man who connected Malaysia

It all began quietly in 1983. In a lab at Universiti Malaya, Dr Mohamed Awang-Lah, then head of the university’s computer centre, was already thinking several steps ahead of everyone else. Even then, he could see the potential for Malaysia to connect with the rest of the world through emerging computer networks. It was still the pre-Internet era, and most people were just trying to get their heads around floppy disks and dot matrix printers.

He collaborated with institutions in Canada and the United States, laying down a skeleton framework for early data exchange. By the late 1980s, he had helped establish RangKoM (Rangkaian Komputer Malaysia), a government-supported academic network linking research institutes and public universities. It relied on clunky X.25 lines and primitive routing, but it worked. RangKoM proved that a national academic network was possible, and laid the foundation for something more ambitious.

That came in 1992, when Malaysia’s first full-fledged Internet service provider, JARING, was launched. Dr Awang-Lah was its founding director, and it was run under the wing of MIMOS, the Malaysian Institute of Microelectronic Systems. The name stood for “Joint Advanced Research Integrated Networking,” but more importantly, it marked the country's formal entry into the global Internet community. JARING replaced RangKoM by absorbing its infrastructure and extending services to the public.

In its first year, JARING had only about 200 users. These were not casual consumers but mostly academics, tech hobbyists and engineers willing to pay RM50 a month for access to text-based services like Telnet, FTP and Gopher. Everything was dial-up. Everything was slow. But it was the Internet, and we were on it.

Help was hard to come by, which made JARING’s early outreach stand out. There was a JARING newsgroup on the Usenet, where people could ask questions, air grievances or simply learn from each other. Occasionally, Dr Mohamed Awang-Lah himself would appear in the thread to offer replies that were calm, detailed and technically sound. It was a rare thing: the head of an organisation engaging directly with end users on a public forum. It made an impression.

So did their technical support. In the mid-1990s, when dial-up modems were still temperamental and drivers didn't always play nice with your desktop computer, JARING technicians made house calls. I once had the benefit of this in Penang. A young technician came over all the way from KL, traced the problem, fixed it and stayed long enough to show me how to troubleshoot in the future. It felt like being part of a quiet, growing movement.

By the late 1990s, JARING was no longer just a research backbone. It had become the primary commercial ISP in the country. Other service providers leased bandwidth from JARING. They introduced higher-speed dial-ups, leased lines for businesses, and eventually even international Internet gateways. For a brief but significant window, JARING was the Internet in Malaysia.

That changed in 1996, when Telekom Malaysia launched TM Net. Backed by greater resources, a nationwide telephone infrastructure, and a massive marketing budget, TM Net quickly captured the mass market. JARING, still operating under MIMOS, struggled to keep up. It had the engineering talent but not the commercial muscle. The difference in user support was stark: JARING remained deeply technical, while TM Net courted the masses.

Still, JARING held on. It rolled out broadband, hosted servers, introduced VOIP services and continued serving corporations and niche users who valued reliability over flash. But the ground was shifting. In 2013, the government handed JARING over to a private entity, Utusan Printcorp, in an effort to revive or reposition it. That, unfortunately, never materialised.

The irony was that JARING had always been ahead of its time. It introduced video-on-demand and broadband services before Malaysians were ready to embrace them. But without control over national infrastructure, it couldn’t scale fast enough to compete.

By 2015, JARING was no more. The company went into liquidation. Domain names were deactivated. Servers shut down. Email accounts disappeared. The digital bridge that had once carried Malaysia’s first Internet packets quietly faded out of existence. And with that, the country’s Internet pioneer bowed out and left behind a legacy that many now overlook.

But for many of us, JARING represented something special. It wasn’t just an Internet provider. It was a pioneer, built by visionaries, and run by engineers who believed in the mission. It was where we learned how the Internet worked, where we got our first static IP, where we discovered how to access a world that was slowly coming online and through it all, there was Dr Mohamed Awang-Lah—calm, firm and deeply committed to the idea that Malaysia deserved a place in the global digital conversation.

He didn’t just connect us to the Internet. He connected us to each other.


Thursday, 24 July 2025

Early Internet days

I’ve mentioned elsewhere on this blog that I signed up for a Jaring account sometime in 1992 or 1993, but I hadn’t been able to pin down the exact year. It was all too long ago, and I’d kept no written record. So unlike me! But then, just a few days ago, I stumbled upon an old story I’d written for my chess column in The Star, dated 28 December 1995. In that piece, I had casually remarked that it was “now close to two years since I began surfing the Net.” That line helped jog my memory: I must have applied for my Jaring account sometime in 1993, and the informal North Malaysia Internet Society (NOMIS) came into being a year later.

Early 1993 was also when I began reconnecting with some of my old schoolmates. One of them told me he was using the computer network at the University of Science Malaysia to access newsgroups and communicate with people abroad. That fascinated me. I’d already been exposed to the idea of long-distance data transmission while working at Ban Hin Lee Bank in the mid-1980s. Back then, I was helping to set up the ATM Centre. Though I wasn’t a techie, sitting through meetings with programmers and system analysts gave me a decent grasp of how data could travel through telephone lines. We were working on computerising bank services as far back as 1983, and I was familiar with the idea of sending strings of information down a wire.

Around that same time, a colleague had passed me a copy of The Cuckoo’s Egg by Clifford Stoll, a thrilling account of how a hacker from across the world was infiltrating American university networks. That book made a lasting impression. So when my friend told me that he could send emails and participate in USENET discussions simply by having his desktop computer dial a local number into the university system through a modem, I was intrigued.

Not long after, he handed me an application form for Jaring, which was then operated by MIMOS. I was excited, but applying wasn’t as straightforward as it sounds. I needed approval from someone at the bank. Trust MIMOS to include that layer of bureaucratic approval, even for private individuals like me! So I approached my Senior Manager, prepared for a round of puzzled questions. Back in 1993, the Internet was practically unknown to 99.99 percent of Malaysians. But after some explanation, he signed off on my application. Phew!

The timing turned out to be fortunate. As secretary of the Penang Chess Association, I was due to accompany our team to the annual Merdeka Team Championships in Kuala Lumpur. While they competed, I submitted my form to MIMOS, along with the RM350 fee: RM300 for the annual dial-up subscription, and RM50 for processing. A few weeks later, my Jaring account came through. I was user number 321-5, the "5" here being the check digit. At that time, there were fewer than 350 Internet users in the entire country. I suppose that made me something of a pioneer.

My first modem was a borrowed, portable unit that plugged into the back of the desktop and ran at a sluggish 300bps. Eventually, I bought a more decent internal card that could do 14.4kbps. I still remember the sound of the modem connecting—the chirps, whines and crackles, all signalling that I was about to tap into the wider world. It was painfully slow by today’s standards. Browsing the worldwide web tested patience, and I learned to do more with less. But even at that speed, it opened up a new world right from my home.

Telekom Malaysia charged 13 sen per local call back then, regardless of duration. Later, they switched to four sen per minute, but Jaring negotiated a special 1511 dial-up number at just 1.5 sen per minute. Telekom eventually launched its own TM Net service in 1996 via the 1515 number.

With my new account, I immediately began exploring the Internet for chess-related content for my newspaper column. I started following international discussions, made contacts like Mark Crowther from the UK and Sam Sloan from the US, and pulled in material that otherwise would have taken weeks to arrive by post, if at all.

Then in February 1994, shortly after Chinese New Year, a group of local Internet enthusiasts gathered at the YMCA in Penang. That meeting led to the formation of NOMIS. We came from different backgrounds but shared the same curiosity and excitement. For several years, NOMIS was invited to computer fairs in Penang to demonstrate how to get online. We gave talks, set up booths, showed people how the web worked, and most of them were seeing it for the first time.

Looking back now, those really were the good old days of the Internet in Malaysia. We were explorers, figuring things out together, one dial-up connection at a time. The Internet is now so commonplace that we take it for granted, but there was a time, not that long ago, when the idea of communicating instantly with someone on the other side of the world felt nothing short of magical.


Tuesday, 22 July 2025

Data breach

Two SMS messages landed on my phone at exactly the same time in the dead of night. To be precise, at 2:08am. The first one read: “RM0 OTP is vzLa-0615xxxx for online trx for UOB card ending 0376 for PHP4525.38 @ Traveloka on 21/07 18:08PM. OTP expiry 22/07 02:11AM MY time.” The second came immediately after: “RM0 UOB Cards: Thank you for using your UOB Card ending 0376 @ Traveloka3DS*******5272 for PHP 4,525.38 22/07 02:08. For any enquiry please call UOB.”

I normally ignore messages like these. Scams, mostly. Usually from banks I don’t even have accounts with, or referencing card numbers that don’t match any of mine. But this was different. UOB and the last four digits of my credit card? Together in the same message? That got my attention.

So, at around 7:30am, I called UOB’s customer service to report a potential fraud. The lady at the other end confirmed that the transaction hadn’t gone through and it had been automatically reversed. Still, I requested for my card to be blocked. Just in case.

But that wasn’t the end of it. Hours later, a third SMS arrived: “RM0 OTP is fCWE-0105xxxx for online trx for UOB card ending 0376 for MYR1689.60 @ Cebu Pacific Ai on 22/07 03:18AM. OTP expiry 22/07 11:21AM MY time.”

Another transaction attempt. Same card number. This time, it was from Cebu Pacific Airline, and again, I hadn’t initiated anything. Another call to UOB. They confirmed the card was already blocked, and this new attempt never even made it to my statement. So what have I learnt from all this?

First, never ignore those strange, late-night SMSes especially if they look even remotely relevant to you. Check the details. Call the bank. You just never know. Second, don’t get lulled into a false sense of security just because the OTP goes to your phone. It’s true that the fraudster probably can’t complete the transaction without the OTP, but what if there’s a breach somewhere and they can intercept or bypass that step? It’s rare, but not impossible.

And finally, we need to ask: did the UOB system suffer a data breach? I can’t say for sure, but it’s suspicious. I barely use this card; just the occasional petrol purchase where I tap and go. No PIN, no online transactions, no manual data entry. So how could my card details end up in the wrong hands? If not a data breach, then what?

Interestingly, the timestamps suggest the transactions originated from a location in the UTC+0 time zone roughly eight hours behind Malaysia. That puts the origin somewhere in western Africa, or perhaps a British territory like Saint Helena or Tristan da Cunha. But the use of Philippine pesos and the mention of Cebu Pacific suggest that someone may have been operating through the Philippines—or trying to make it look that way. Who knows? Syndicates can operate across continents these days.

So here’s my advice: (1) Monitor your bank and credit card SMSes closely, no matter what time they come in. (2) If anything looks off, contact the bank immediately. (3) Don’t assume fraud won’t happen to you just because you don’t shop online or use your card much. Sometimes, that makes you more vulnerable as you’re not watching as closely. And (4) finally, consider using virtual cards or turning off online access when you're not making purchases. It’s better to be paranoid than to be sorry.

We live in strange times. The fraudsters are getting smarter. So let’s not make their job any easier.

Tuesday, 22 April 2025

Oroaming in Bangkok

Some phones have it, some don’t. I was lucky to find out that mine does—it’s a software feature called Oroaming.

What it does is allow me to purchase a short-term data roaming plan directly from my phone before travelling overseas. No need to buy a local SIM card, and no need to activate international roaming through my Malaysian telco. The plan is activated through the device itself, and payment can be done easily via Touch ’n Go, credit card or other supported methods. It’s meant to be convenient—and I must say, it really was.

I gave it a try during my recent trip to Bangkok. I paid RM10 for a seven-day data plan. The downside was that I only got 1GB of data which, in today’s world, doesn’t go very far. Even surfing the web is notorious for draining data, let along using the mobile apps. But when I compared it to Unifi’s international roaming fee for Thailand—RM9 per day—it was still a clear win. For a five-day trip, that would’ve cost me RM45. Instead, I stretched that RM10 plan across my whole stay while outdoors. In the evenings, I simply switched to the hotel’s complimentary WiFi to conserve my mobile data.

Honestly, if I’d known about this feature earlier, I would’ve used it during my Singapore trip last December. It would’ve saved me both hassle and some money.

Wednesday, 26 March 2025

Getting meshed up

Living in a double-storey house can be a real pain when trying to extend a WiFi connection throughout the place. My problem lies with the modem and router which are upstairs in the living area. When I first moved into this neighbourhood in Bukit Mertajam and applied for an internet line way back in 2004, all the technician did was throw the cable across the rooftop from the backlane and feed it through a ventilation gap to the living area, which was centrally located on the upper floor of the house. Straight down and into the modem and router.

Upstairs, my wireless equipment—laptops and mobile phones—had excellent WiFi reception. But because of the house layout, concrete floor and brick walls, reception downstairs wasn’t always great. Mostly okay, but sometimes my wife would complain about poor connectivity when working downstairs. The smart television? It was fine—not excellent, but good enough. We could manage Netflix and YouTube, and I could still enjoy Spotify and Tidal.

Late last year, I chanced upon a ZDNet article about how to get wired connections throughout the house using existing coaxial cable outlets. In some old houses, those outlets were originally meant for TV connections in every room, but apparently, the coaxial cables could also carry internet signals, thanks to a technology called MoCA (Multimedia over Coax Alliance). Sounded interesting, but the problem was, I didn’t have any coax outlets in the house. So it was a nice idea, just not one I could use.

Meanwhile, I was still stuck with acceptable—but not great—WiFi reception downstairs. Then it occurred to me: a mesh router might be the solution. Lucky for me, I found one that was compatible with my existing router. I paired the two units, moved the mesh unit downstairs, and voilà—my wife’s not complaining anymore! Even better, the WiFi reception on the smart TV improved, and those annoying Netflix lags are gone. Not to mention, the WiFi outside the house and in the kitchen is now excellent.

Why didn’t I think of this earlier??

Meanwhile, here is an addendum to this story. If a mesh router isn’t a ready solution, homeplugs might be an alternative. Also known as powerline adapters, they use a home’s existing electrical wiring to create a wired network connection. These come in pairs—small devices that plug into electrical outlets. I don’t know the technical details of how they work, but the setup is pretty straightforward. The first homeplug connects to the modem or router via an Ethernet cable. It then injects the internet signal into the home’s electrical wiring. The second homeplug, plugged into a different electrical outlet elsewhere in the house, picks up this signal and provides an Ethernet port for devices like computers, gaming consoles, or smart TVs. The attractive part? You can add more homeplugs in different locations to extend network access throughout the house. All sounds rather cool—but since I’m already meshed up, a homeplug network is moot for me.


Monday, 3 March 2025

PIKOM

I remember the mid-1990s, when the Internet was just starting to take off in Malaysia, and computer fairs were all the rage. Every year, there’d be at least two major ones: one organised by The Star newspaper and the other by PIKOM, the association representing the computer industry. Back then, my friends and I, already well immersed in the online world, had loosely formed the NOMIS group. We were eager to show people how to get onto the Internet and explore what could be done online. For two or three years, we participated in every computer fair in Penang, giving talks and live demonstrations.

Fast forward about 30 years, and everything has changed. Computer fairs are a thing of the past, our NOMIS group has long since run its course, and The Star no longer has its computer pull-out section—let alone organises fairs. But PIKOM is still around, organising talks! Just last month, I attended a half-day PIKOM event in Penang. Today, with artificial intelligence being all the rage, the speakers were talking about AI, ChatGPT, DeepSeek, and the like—how businesses that don’t embrace this new technology risk being left behind.

Three decades ago, our “toys” were dial-up modems, 64kbps speeds, mailing lists, bulletin boards, FTP, Telnet, Gopher, IRC and the World Wide Web. Now, it’s AI and machine learning. As I sat there listening to the speakers, I couldn’t help but think—every generation has its new toys.



Tuesday, 13 August 2024

Are wikis reliable?

Are wikis reliable? I know that many people swear by them and believe in them completely. Wikis have become indispensable tools for quick access to information on an array of topics, from pop culture to historical events. Their appeal lies in their accessibility, breadth of content and the fact that they are constantly updated by a global community of contributors. However, when it comes to reliability, wikis present a more nuanced and complex picture.

The strength of wikis lies in their collaborative nature. Thousands of people can contribute to and edit content, bringing diverse knowledge and perspectives to the table. This crowd-sourced approach can lead to a wealth of information that is expansive and up-to-date. For many users, this democratic model of information creation is appealing and they trust the content implicitly. But this same feature also introduces potential pitfalls that make it essential to approach wikis with a healthy degree of scepticism.

One of the biggest challenges is the variability in the quality of information. Since anyone can edit a wiki, the content might be contributed by individuals who are not experts in the subject matter. While many wiki pages are well-researched and include citations to reputable sources, others may be based on personal opinions, outdated information or even deliberate misinformation. The open-editing model also means that content can be changed at any time, and not every change is reviewed or verified by knowledgeable editors. 

Another concern is the potential for bias. Wiki contributors come from different backgrounds and may bring their own perspectives and biases to the content they create. This can result in skewed or unbalanced representations of certain topics. For instance, controversial issues might be portrayed in a way that reflects the dominant views of the contributors rather than presenting a neutral or comprehensive overview. This is particularly problematic when readers are unaware of these biases and take the information at face value.

Cross-verification is another critical issue. Reliable information should ideally be supported by multiple independent sources, but not all wiki entries meet this standard. Some entries might rely heavily on a single source or on sources of dubious credibility, raising questions about the accuracy of the information. Moreover, the references themselves may not always be scrutinised or updated, leading to the perpetuation of outdated or incorrect data.

Recently, I came across https://penang.fandom.com/wiki/Penang_Wikia which is a small niche wiki maintained by some local enthusiasts. The work is promoting information about Penang island is commendable. But the question of reliability arises. While I am not suggesting that the information there is unreliable, I would like to point out that the challenges of reliability can be even more pronounced. These specialised wikis often focus on very specific topics, sometimes with a limited number of contributors. While the depth of information on such niche topics can be impressive, the quality control might be less stringent than on more popular, widely-used wikis like Wikipedia. The smaller the community, the less likely it is that there will be robust editorial oversight, which can lead to inaccuracies, unverified claims or even content that reflects the personal views of a small group of enthusiasts rather than a broader, balanced perspective.

Furthermore, niche wikis may lack the same level of cross-referencing and fact-checking as larger platforms. This is particularly important to keep in mind if information is used from a niche wiki for research or other critical purposes. Just because a topic is covered in detail doesn’t guarantee that the information is accurate or comprehensive.

Given these concerns, it is wise to approach wikis as a starting point rather than a definitive source. They are excellent for getting a quick overview of a topic or for discovering new areas of interest. However, if the information is going to be used for academic research, professional purposes or any situation where accuracy is crucial, it is important to cross-verify the facts with more authoritative sources. Academic journals, books by reputable authors, official reports and other peer-reviewed materials are far more reliable when it comes to ensuring the accuracy and credibility of information.

So, while wikis, including small niche ones, offer a valuable resource for general and specialised information, they should be approached with caution. They are useful for gaining a preliminary understanding of a topic, but for in-depth or critical research, it is prudent to dig deeper and consult more reliable sources. Believing everything that is read in a wiki without question can be risky, and it is always best to maintain a critical eye and verify information independently whenever possible.


Saturday, 23 March 2024

Scam alert

Be very careful if this message is received on the mobile phone through SMS. It is a known scam that works on an unsuspecting person's greed and steals his credit card details. Clicking on the link in the SMS leads you to a page masquerading as a Maxis rewards page where you are lured that by paying only RM1.35, some attractive items can be redeemed. But then the next page leads you to key in your credit card details - your name, credit card number, expiration date and CVV - and these are then lost to the scammer. Before you know it, you'll have lost substantial money from your credit card account. The warning signs to look out for are, the SMS originating from an unknown number, the bogus Maxis landing page is wholly in Bahasa with no option to choose English, and only a limited range of products to redeem. So be warned and don't fall victim to personal greed. If it's too good to be true, it usually is.


Wednesday, 6 March 2024

Facebook was down

Facebook was down last night. Affected globally. Locally at about 11.30pm, I was suddenly locked out from my facebook account. The first thing that came to my mind was, oh gawd, someone's trying to hack into my account. But I was rather cool about the matter. I had always believed that my security measures were good enough. If anyone wanted to steal my facebook account, the first thing I would do - and this was what I did - was to change my password. 

Unfortunately, all attempts came to nought. I hit a wall when I wanted facebook send their six-digit code to me. On several tries, I did not receive any SMS message from facebook. Even right until this morning, no SMS from facebook. On several other tries, I asked facebook to send the code to me via email. I had registered two different addresses with facebook, one as a secondary back-up, and to much of my surprise, facebook sent different codes to the two email addresses. Now, which one should I use? I tried both, and both were rejected. That's very silly, isn't it? I should be receiving the same code through the two email addresses, not different codes. 

Anyway, I awoke this morning to learn that the problem has been resolved. I could now access my account on my mobile phone and the desktop computer. What a relief, although there's yet to be an explanation from facebook on what exactly hit them. 


Tuesday, 1 November 2022

Almost new

I built my present desktop computer from scratch about nine years ago when my eyesight was better. The motherboard is a Gigabyte Z87-D3HP but I'm only using a fourth generation Intel i3 processor. I wasn't looking for anything high-end - I'm no gamer - but only a modest set-up that could satisfy my need to play audio files and view videos. No huge processing needs required. When Windows 10 was introduced in 2015, my desktop upgraded to this operating system quite seamlessly. And it went through countless automatic updates through the years. I didn't have to touch anything much. Very contented, actually.

Then at the start of last month, the desktop started developing the dreaded Microsoft blue screen (of death.) At first, the desktop rebooted with success but much later, I could stare at the blue screen for hours if I wanted to, and it would stare back at me. Arghh....there was nothing I could do but to try and instal the operating system onto the same harddisk. It worked for a while but the problem returned. I finally gave up after repeated failures.

Initially, I thought of building another desktop but then baulked at the work involved. Then I remembered that I had an unused solid-state drive (SSD) somewhere in the house. Purchased it a long time ago but I didn't find the need to open my desktop's casing. To do that, I would have to pull all the cables from the back of the motherboard and it was something I was quite reluctant to do. But here, inevitably, there was no other choice for me than to do just that!

So now, I have a SSD fixed up as my new C:/ drive and the old harddisks in the desktop have been converted into my storage devices. I had to replug all the cables one-by-one carefully and then reinstal Windows 10, the drivers and also all my essential programs. Too bad my set-up prevented me from upgrading to Windows 11; I would have done that too if I could. 

A whole mess of wires and cables inside the casing



Saturday, 25 June 2022

Scam message

One of the latest scam messages that is being spread through email. I received this one in my inbox this morning. The immediate giveaway is that it is impossible - at least for now - for the scammers to hide their originating email address. A message from any bona fide company will display the company's domain name which in this case is replaced by a string of seemingly randomised numbers and letters. That should alert anyone not to be gullible enough to respond to the scammers or click on any other link in the email message. Oh, besides which, I don't have a Netflix account. 😉



Tuesday, 8 March 2022

Scam emails

Over the past few days, I've received a number of emails from financial institutions informing me to be aware of scam emails purportedly issued by banks. So here you are: emails received from CIMB Bank, Standard Chartered Bank and Public Bank.

One of the first messages came from CIMB Bank. It started off by saying: CIMB will never call you to request for your banking or personal details. If in doubt, call the number at the back of your CIMB card or refer to CIMB website "Contact Us" page. 

There is a link to more security tips:

Do NOT respond to any SMS/phone calls

  1. Do not respond to SMS or call from unknown person asking for your credit/debit card or online banking details.
  2. Do not respond to any SMS or call that claiming it's coming from Bank Negara. Their officer will never call you to ask for your credit/debit card or banking particulars.
  3. If someone claiming to be from your card service provider calls you and asks you to confirm the security numbers on the back of the card (the last three digits on the back of the card), you should end the call immediately.

What you have to do

  1. If you're unsure, ask for a reference number and call back on a trusted number (i.e phone book) to confirm if the call was genuine.
  2. Watch out for poor grammar in the SMS.
  3. Check your transactions regularly.
  4. Change your password periodically.
  5. Safeguard your personal information.
Standard Chartered Bank took a different approach. Here is their email message:

Dear Valued Client,

Everyone loves a bargain, but the internet is an easy place for scammers to hide.

They may pretend to be 'sellers' and persuade you to make a purchase. Or pressurise you into paying them via bank transfer to their account. Once they get the money they disappear.

Here are some signs that a 'deal' could be too good to be true:
  • Rock-bottom prices with a small window of opportunity
  • Scammers hook you in with low prices and a short time frame, to make you take action quickly, for fear of missing out.
  • No reviews or consistently negative feedback
  • See what other purchasers think, and make sure to read the reviews, including negative ones.
  • Requests to transfer money directly into the seller's bank account
  • Always use secure modes of payment to protect yourself (and your money).
Here are some ways to help you stay safe when purchasing online:
  • Shop on websites or online stores with enough information about refund policies, terms and conditions or contact details. 
  • Look for sellers with high ratings and good reviews. 
  • Only make payment through a secure payment service (look for the padlock icon displayed in the url). 
  • Never provide your payment card details to the seller directly. 
  • Avoid engaging with sellers in messaging apps where they may provide 'evidence' of identity to lure you into the deal. 
  • Don't share more information than needed, always limit to your billing and shipping information.
If you suspect you've been a victim of an online purchase scam, report it to the authorities right away. For more fraud prevention tips, visit sc.com/fightingfraud/myaccount.

And then there was this email from Public Bank. Here is their message:

Spotted an amazing offer online that seems too good to be true? Be careful to not act on it too hastily as there may be a scam waiting for unsuspecting victims like you.

Warning Signs
  • The offer or product is advertised at an unbelievably low price, or to have amazing benefits or features that sounds too good to be true.
  • The seller requires immediate payment or forces you to pay via an unknown third party platform or website.
  • The seller profile is brand new and has no product reviews.
Additional Warning!
Some sellers will require you download their app in order to claim a special discount or an exclusive product. Be wary! These apps are not downloaded via official app stores such as Google Play/Apple App Store and are most likely malware designed to steal your online banking and credit card information.

How to Avoid
  1. Only purchase products from reputable shopping platforms.
  2. Ensure that the online shopping platform has a refund or returns policy.Always do your research on the seller before committing to the purchase.
  3. Check for seller or product reviews, make sure the reviews are relevant to the product they are selling.
  4. Never make any payments via unverified third party apps or websites.
For more information on how to protect yourself online, visit our online security microsite.


Monday, 15 November 2021

Phishing at its worse!

I came across this post on facebook, written by a chap called Smith Ang. I thought it is significant enough to warrant a reproduction on my blog. The incident shows that you cannot trust seemingly innocent posts on the Internet nowadays, social media included. We have to be very careful about the information we disclose. So this is the facebook post in question....

This is the Most Sophisticated Phishing I've seen so far. And it happened to me minutes ago.

Part 1: The Bait- Creating the Perfect avenue 

I've been searching for cleaners, and Facebook prompted one of the ads that caught my attention. Promotion! Who doesn't like a good 50% promo 🙂

Part 2: The Hook- The power of "Call To Action"

The "Call To Action" of the ads will bring you directly to the "vendor" WhatsApp. As you can see in the WhatsApp chat, I was asked to download an App, an APK file to be exact. Rarely do vendors ask their customers to download APK files directly, Most will give you a link to the official app store. (Tip1: Don't trust anyone that sends you .APK file. That doesn't mean the official app store is safe either)

Part 3: The Trojan

After installing, the app requested SMS read permission. Huh? Why do you need that for a Maid Booking App? (Tip2: If App request permission for something more than it should, then it shouldn't)

Part 4: Intel Gathering

The App is well-built, even had its PDPA disclosure done correctly. The registration info required are Name, Email, Password, Mobile Number. Upon finding the date and package I wanted, I had to key in my address. 

Part 5: The Bank

Now come to the part where I have to make payment. Conveniently, the credit card payment is grayed out ("Under maintenance"), the only option available is FPX. There are a few banks to prey on: Maybank, Affin, Public, CIMB, BSN and RHB. After selecting the desired bank, a very familiar bank interface appears in front of you. If you see the Maybank UI, there is a note:- "Note: you are in a secured site" that replaces the catchphrase. (Tip 3: Hmm... will a thief tell you he is not a thief?)

Okay, so when filling up the bank login detail, no matter what you put in, it will always show "Invalid User ID or Password [Err Code: FE0067]. Now, this gibberish error code is the same for all the banks you selected. Don't tell me all the banks are using the same system developer? I had a bad feeling, but I brushed it off as I was too tired.

Part 6: Heist

The next day, I received the SMS:

RM0 PBe DO NOT share this code. DuitNow Transfer RM4,860.00 to NOORALIF SAFWA.
S/N: DC0334071 
PAC No: 
12Nov21 14:52 
For enquiry, pls call 03-21799999

I immediately log into my bank account, and I receive the "Duplicate Login" and there, what I suspected. Without hesitation, I spring into quick finger mode. I was fighting access with the intruder for the login rights. Whenever I tried to change my password, it will be logged out. Years of playing Speed Typing games during my younger days boosted my typing speed +99999. I won the login match and changed the password. (Tip 4: Don't wait, stay calm and secure the situation)

Part 7: Data Exposure

So what is the data that was exposed by using this app?

1. Name
2. 3. Phone Number
4. Email Address
5. Mobile Phone
6. Address
7. Bank User ID
8. Bank Password

This is a very sophisticated operation. Why?

1. It prays on our (mainly me la) weakness- Got Promotion ah?

2. The entire scam ecosystem is well planned- From the curation of the Marketing and Advertisement to the almost flawless APP.

Note: 

For those who are unaware, when you allow the app permission to read your SMS, this will include the incoming PAC/OTP code that your bank sends (SMS) to you for dual-factor authentication.

So this is my adventure on the 12 of Nov 2021.

Enjoy reading and be careful.

Wednesday, 20 October 2021

Clifford Stoll

It was 1990 or 1991. I was still in charge of the ATM Centre at Ban Hin Lee Bank. Already at that time, computer security was an issue that commercial banks in Malaysia had to contend with. Although branches were connecting to their Head Office through their own private telecommunication network, there were still possibilities of security breaches. Someone at the Information Technology Division recommended that I read a certain book, IF I could find it.

It so happen that I did find this book a few months later at the British Council library. I borrowed it and for the next few days, I couldn't put it down. It was that interesting. The book was by Clifford Stoll, an astronomer turned computer sleuth. His book was The Cuckoo's Egg, which described his adventure in ultimately tracking down someone who had hacked into the central computer system at the Lawrence Berkeley National Laboratory in California.

It all started with an anomaly of 75 cents of computer time in 1986. The nascent days of the Internet. That someone who hacked into the Berkeley Lab computer had used up nine brief seconds of computer time without paying. Nine seconds, equivalent to 75 American cents. Stoll was assigned to find out what happened. One thing leading to another, he discovered that the person had found his way into military systems across the United States. 

Tracing backwards, the greater surprise was that the hacker was dialing into the German telephone network from a computer in Germany and then connected via satellite to Berkeley Lab. Nowadays, I would be very much surprised to learn that this hacker was simply using a 1,200-baud modem to break into the US military systems but that was technology in those days and that was the type of modem used. None of the speedy 100Mbps or 300MBps broadband lines we typically have today. 

Finally, a trap was set for this hacker named Marcus Hess, and he was eventually caught and tried by the German authorities for selling military secrets to the KGB in the old Soviet Union. Today, Stoll's The Cuckoo's Egg remains the go-to bible for computer security experts. Many of his early methods of detecting unauthorised intrusions in computer systems are still in use, although they have been upgraded and improved over the decades.

I've no idea when exactly I acquired my own copy of this book but it was not too many years after my initial reading. It only showed how impressed I was with the tale. I was very happy to rediscover the book in one of my cupboards recently. I'm rereading it. Still can't put it down often enough. After all, good computer espionage stuff is hard to find.


Sunday, 27 June 2021

Artificial intelligence

How often does chess make the front page of our local newspapers? Probably not more than two or three times within living memory. It is even rarer to find chess hitting the front pages of a local Chinese language newspaper but this actually happened in 1997 when the Guang Ming Daily reported on the match between Gary Kasparov and the IBM computer known as Deep Blue. 

The Guang Ming Daily or Kong Ming Yit Poh (光明日報) was formed from the closure of the Sin Pin Jit Poh (星檳日報) newspaper which was founded by the Singapore Tiger Balm king, Aw Boon Haw in 1939. Ten years earlier, Aw had also started the Sin Chew Daily (星洲日報). The Sin Pin Jit Poh had its headquarters in Leith Street, Penang. When it stopped publishing in 1986 following major management changes, the former staff of the newspaper launched the Guang Ming Daily in December 1987 with the help of Lim Keng Yaik who was then the Minister of Primary Industries. In 1992, the Rimbunan Hijau Group bought over Guang Ming Daily and thus making it the sister company of Sin Chew Daily again.

This particular historical connection aside, I discovered this page of the Guang Ming Daily of 13 May 1997 when going through my store room. 

The Deep Blue versus Kasparov matches were a pair of six-game chess matches involving a reigning world chess champion and an IBM supercomputer. Deep Blue was the successor to the original ChipTest and Deep Thought computers developed at the Carnegie Mellon University to research artificial intelligence. The rights to Deep Thought were later acquired by IBM and Deep Blue became the next iteration of a chess-playing super-computer. Kasparov won the first match against Deep Blue in Philadelphia in 1996 but a vastly improved Deep Blue v2 won the return match in New York a year later. This second match marked the first defeat of a reigning world chess champion by a computer in a match played under tournament conditions. Unfortunately, IBM chose to retire Deep Blue after the machine attained this landmark achievement. But the match received a lot of media attention worldwide and that was where the story was picked up even by a Chinese-language newspaper like Guang Ming Daily.


Thursday, 8 April 2021

Faker, masquerader

What I can say at this point of time is that yesterday, a faker was trying to pass himself off as me on social media. This person had created a phony instagram account using my name and profile picture. Luckily, he couldn't take over my username and had to use another. Anyone who did not know better would have thought that this fake account belonged to me.

At about 11.30pm last night, I was alerted by my nephew to ask whether I had tried to contact him on instagram. He even sent me a screenshot. Though half asleep, I replied that no, I had not posted anything to him on this social media platform. 

By now, I was awake and my mind was whirring. My presence on social media was being compromised. Immediately, I sent a message to my friends and relatives on whatsapp and facebook to warn them against accepting any message from this spurious account. 

In the morning, I reported the incident to instagram, asking them to block and remove that fake account. This evening though, another of my facebook friends in the Philippines told me that she had also been contacted through this spurious instagram account, but having been warned by me, she had ignored the message. 

This is not the first time that either my wife or I have found ourselves in this situation. Many years ago, someone had tried to clone a facebook account with my wife's name. That fool, however, had chosen to use a war-time Germany-related picture as the profile picture. Once I had reported the incident, facebook immediately removed that fake account.


Thursday, 10 September 2020

Self-service


This is my wife's laptop. Bought five years ago to enable her to work from home. At that time, it could boast of an Intel i5 chip and a 1TB hard disk, although a bit lacking in internal memory, what with only 4GB RAM. Solid state disks weren't popular yet and besides, were expensive. So I had plumbed for that configuration. Value for money, I thought. 

The laptop served her well enough. As she used it mostly for word and spreadsheet processing, it could be considered under-utilised. But for whatever reason, it began slowing down. Took a long time to boot up and to open programs. Sometimes, had to wait almost five minutes before she could start any work. No prize for guessing correctly who was pressured to do something about this. 

Sometime last year, I bought a 512GB solid state drive. Had wanted to replace her hard disk with it. However....every time I wanted to take away the laptop, she was hogging it. So I deferred the moment to a better time, which never came. But finally, the frustration got to her recently and she implored me to do the upgrade as soon as possible.

At first, I took the laptop to a nearby computer shop along Jalan Maju in Bukit Mertajam, which shall remain unnamed. Showed them the laptop and asked for a quotation. The shop assistant texted me on the next day. The cost for a 512GB SSD, formatting it and installing Windows 10, and setting the old hard disk into a new external casing would cost me RM698. How much was the 512GB SSD, I asked back. The reply: RM400.

I knew that I was being ripped off. They had no qualms about ripping off this old uncle. RM400 for a 512GB solid state drive? The last I checked on Lazada, this SSD was available for abour RM210. Okay, so the price has risen very slightly over the past year but it doesn't matter much. I would willingly pat RM210 for a new 512GB SSD today if I had not already have one. If the computer shop was going to charge me RM400 for an SDD that could be bought online for RM210, I wondered what other inflated prices they were going to be thrust on me.

Back to some self-research. First, it was possible, I found out, to download an officially sanctioned copy of Windows 10 from the Microsoft website. Next, YouTube showed me how to open up the laptop and do the replacement. And that's what I did. Removed all the screws. But then I hit a problem. Tried to remove the DVD drive but couldn't do so, no matter what I tried. Looked so easy in the video but I really couldn't figure it out.

Resigned, on the next day I took the laptop and the SSD to the ph&co (formerly known as PC Depot) outlet close to the Pacific Megamall. The technician took a look and asked me, "No formatting required?" "Nope," I replied. "Then it will cost you RM20 for the labour charges," he said. "Okay," I said, "please proceed. And while you are at it, please also put in another 4GB of RAM." Everything was done on the spot and the bill came round to RM119. So together with the RM205 that I had paid for the SSD last year, the total cost came up to RM324 only. 

At home, I installed Windows 10 on the laptop and then added in the old Microsoft Office 2003 (yes, I'm still using this old version!) and Kaspersky Internet Suite. That's all she really needs on her laptop. No need for any other urgent bell-and-whistles program. And it is now working fine. No more complaints from her.