How to thrive under pressure

Your body is a miraculous creation that is able to quickly adapt to different situations often without you even realizing it. When working in pressure situation, your body reacts by making physiological changes [for the worst] that also impact how you think. Truth is pressure is the new normal and you must learn to deal with it or it will crush you. 

Here are simple steps to help you conquer any pressure situation:

Be in the moment

As an IT professional, I have seen the effect of extreme pressure on experts handling large and complex IT outages or security incidents. Even the most expert professional can find themselves in a vortex of destruction. If I notice people going down the wrong path, I try to help them centre themselves and concentrate on this moment. 

I ask them to sit down and find an object they can concentrate on. I ask them to find a small spot on that object and to stare at it. I ask them to then be mindful of their breathing. To concentrate on long inhalations, to hold it and then to do a long exhale. I ask them to keep looking at that spot and to feel their body breathing. To feel their chest expanding and contracting.

Gratitude

When you are under stress, your body releases cortisol. This is what fuels the fight or flight response and isn't ideal when the situation requires deep thought and solid reasoning. 

Once we complete the first breathing step. I then work with the person to find out what they are grateful for. Research has shown that gratitude can reduce the level of cortisol by 23%. Even when things seem very bad, there are always things to be grateful for. Think about what is going right, even when it seems there isn't much. 

As an example, there are large forest fires in Fort McMurray right now forcing the evacuation of tens of thousands of people. It is a horrible situation but if I were a family being forced out of my house, I would also be grateful that i was with my family and they are safe. I would be thankful that I had a car that is allowing me to evacuate. You get the idea. regardless of how bad things may seem at first, there is always something to be grateful for.

Prioritize

When under extreme pressure, the situation may seem hopeless and you may lose track of what really is important. IT is important to take a step back and put things into perspective. My mantra is "this isn't brain surgery". I recommend you sit down in a quiet area and (once you have done the breathing exercise) ensure you are working on the right priorities. It is easy to get "mixed up" and focus on the wrong things when under extreme pressure. We tend to fix the thing that is the latest and loudest. 

Surround yourself with the right people

We were handling a major datacenter outage a couple of years ago and the entire tech team was struggling to figure out what was going on. As I observed the lead, I realized he was getting too stressed and was starting to make "less rational" decisions. I took him aside and guided him through the first 2 steps. Once he was calm, I asked him to perform the prioritization activity alone in an isolated room and he did an excellent job. As soon as I put him back in the control room, things started to boil over again and I realized it was partially due to the amount of technical people around him being overly pessimistic. 

I replaced to people with fresh non negative experts and realized the lead was now "more in control" and less stressed. Moral of the story is to take the time and ensure you are surrounded by the right people. If there are people being overly negative, push them away and you will see the level of pressure diminish greatly.

Take a break

You may be under pressure because you are handling a major situation or because your boss expects a major deliverable in a short window and key information may be missing. Regardless of why you are under pressure, sometimes you have to take a short break and change your mindset. Once you perform the above steps, it is also important to stop, walk away from the situation and do something that changes your mood, mindset and situation.

Let's say you are working on an important report, information is missing, people are not cooperating and your boss is breathing down your neck. You may be a little stressed. You will feel pressured to perform. Make sure you follow the above steps, then determine an interval at which you will step away from your desk and go for a short walk.

As an example, my personal limit is 45 minutes. After 45 minutes of straight undivided concentrated work, I will typically walk away for 5 minutes and do something else. The something else may be a short walk in the office, a trip to get a coffee, sit outside and take a breath of fresh air, etc.

You will be energized when you get back and be much more productive. The complaint I hear too often is I can't go because there is too much work. Research has shown that not taking these short breaks will actually hurt your productivity and the stress will also dull your abilities,

 


Creators of Siri to launch next generation AI assistant May 9

Siri, Google Now and Cortana launched with great fanfare. We expected great things and for the most part, they are all disappointing. Truth is none of them really lived up to our expectations.

The creators of Siri have been hard at work creating the next generation of AI, which they claim will be able to handle much more complex tasks. The new AI will be able to parse natural language queries and will be able to handle chained commands. We expect you will be able to ask it to find a flight Toronto to Los Angeles next Thursday in the afternoon priced between $300-$700. And it will be able to do all of this without kicking you out to another app. 

Integration with important services will be critical and it is expected to launch with at least 50 name brand partners from Uber to GrubHub. 

Forrester research believes consumers spend 80% of their smartphone time in as little as 5 apps. Like most of you, I have too many apps on my phone. My apps are all soloed and don't talk to each other. My smartphone doesn't really feel smart when I ask it to buy movie tickets and it sends me to an app or website. Truth be told, my phone's built in assistant is nothing more than a circus performer: fun to watch but not really helpful.

As an iPhone owner, I worry that Apple's walled garden will prevent me from being able to use the Viv technology when it is eventually made available to the public. A good strong digital assistant may be enough to persuade me to switch platforms, but for now I wait for Monday's demonstration. 

If Viv is everything we expect it to be, then it could end up owning the most lucrative platform of the future.


Are Apple's best days behind it?

[caption id="" align=“alignnone” width=“1200”] Image by  Dominik Fusina  used under Creative Commons License Image by Dominik Fusina  used under Creative Commons License [/caption]

Apple stock took a tumble even though the company made boatloads and boatloads of cash last quarter. Why? Because some investors believe Apple's profitable run has lasted too long and obviously it must eventually come to an end. They saw the reduced growth rate in iPhone sales as a bad omen.

Unfortunately this is not how the world works and it isn't how statistics work. This misguided belief actually has a term and its called the "Gambler's fallacy". 

[...] is the mistaken belief that, if something happens more frequently than normal during some period, it will happen less frequently in the future, or that, if something happens less frequently than normal during some period, it will happen more frequently in the future (presumably as a means of balancing nature).
— Wikipedia

When a product has been such an incredibly huge success (like the iPhone), it is natural for observers to be pessimistic about the company's ability to generate another similar home run hit but... Keep in mind that Apple is supplementing its product revenue with service revenue. 

Apple had total revenue of $50B this quarter. Statistica says $6B came from services. Obviously Any other company would love to have a $6B quarterly service business. Apple is working hard to increase its share of the monthly recurring service business, which would complement its fixed-cycle product revenues nicely.

Apple has room for improvement in services like Siri, Apple Music, iCloud online, etc I think Apple maps is a great example of how they can dramatically improve a product if they put their money, people and determination behind it.

I believe (maybe mistakenly), that WWDC will be the launching platform for Apple's push into services. I believe they will challenge  Microsoft and Google head-on. Competition is always good for consumers.

So don't fall for the Gambler's fallacy and don't count Apple out just yet.  Yes Apple growth slowed slightly compared to last year but this is a blip in the radar of an otherwise healthy, innovative, tech leader. 


Would you like some malware with your dental cleaning?

The Health Insurance Portability and Accountability Act of 1996 (HIPAA) is a law that was created to protect millions of working Americans and their family members with medical problems.
— American Cancer Society

Most working professionals have an association they can call their own. Dentists have the American Dental Association. The ADA represents 159,000 dentists across the USA and most received a "gift" recently in the form of a USB key with new dental codes.

  <img src="https://ekiledjian2.micro.blog/uploads/2025/6e1bcbda44.jpg" alt="">



  <img src="https://ekiledjian2.micro.blog/uploads/2025/c3e56ad49b.jpg" alt="">

It turns out of of the recipients is also technically competent and he decided to take a closer look at this "gift" (check out Mike's post on DSLReports.) Re-read that HIPAA description at the top of this post, it applied here.

He checked out the contents of this magical key and realized one of the files tries to open a bad bad webpage known for hosting malware (don't go here : http://ntkrnlpa.cn). Virustotal flags the site as bad. 12/67 detected it as badware day 1. When I asked VirusTotal to rescan the site for malware today, 13/67 detect it as bad. Symantec says the site contains threats. ScanURL recommends you not visit this site. So overall it is pretty safe (no pun intended) to assume this is a bad place and you shouldn't be wondering its streets alone.

The ADA says "some drives" contain malware and believes your antivirus should catch anything nasty on it or linked by it. Anyone involved in cybersecurity knows not to trust antivirus with their safety. Remember that out of 67 major antivirus vendors, only 13 today detect the site as malicious when it is known to be very bad. Antivirus is not a good replacement for good security hygiene. Obviously the ADA says if you haven't use this key, don't.

I don't want to be too harsh on the ADA. This isn't the first time "things" manufactured in China have been loaded as malware. In 2009, we had an outbreak of picture frames loaded with malware. 

Every time you add another step to a digital process, you add additional attack vectors and increase your risks. Instead of sending out USB keys, the ADA should have made the files available for download. By removing the USB key process:

  • sending files to the Chinese manufacturer
  • Infection is possible by the manufacturer of the USB keys
  • infection is possible by the company that turns the keys into promotional cards
  • infection is possible by the company that loads the content onto the keys using a duplication machines (which is likely how the ADA mailer was infected)

By making the files available for download, they reduce (but don't eliminate) the possible attack vectors. Additionally companies need to add much more stringent security controls around their digital product production process. I would also recommend that the ADA periodically sensitive its members on HIPAA, their obligations under HIPAA and provide guidance on good security hygiene. 


Quote about success

Action is the foundational key to all success. Pablo Picasso  

  <img src="https://ekiledjian2.micro.blog/uploads/2025/9912c7beda.jpg" alt="">

Is WhatsApp security Good and trustworthy?

Quietly and with little fanfare, Whatsapp released an update to all of its products enabling end-to-end encryption for its 1B+ end users. Funny enough, most users aren't aware that their Instant Messaging tool of choice is now powered by the worlds most secure end-to-end encryption protocol : Signal. 

Can I consider WhatsApp secure?

A couple of weeks ago, OpenWhisper systems announced that its Signal secure protocol has been imbedded into Facebook's WhatsApp instant messaging application. The question I receive daily is "should I consider my Whatsapp communications protected now?"

Before signal there was OTR

Before using the Signal protocol, it looks like the WhatsApp team evaluated the OTR (off the record protocol). OTR provides encrypted point to Point communication but it requires a real time collaboration of the users (aka both have to be online to secure the transmission) which isn't practical for WhatsApp. So they went fishing for something else and stumbled upon Signal.

The Signal difference

Signal actually created an encryption model using the text messaging approach, where messaging is encrypted but it is asynchronous (both parties don't need to be online simultaneously for it to work).

Although text messaging is simple, the complexity of the encryption is model is high.

The protocol was called axolotl. The salamander it is named for has self healing capabilities and the axolotl protocol also has self healing properties.

To simplify it for mass consumption, the procotol was renamed the Signal protocol and now has open source libraries. Cryptogrsphers have been able to build fully function encryption programs comptible with the consummer Signal apps.

Now powering Whatsapp

The integration is now complete in the latest version of Whatsapp on all platforms.

Users running these versions now get full end to end encryption for every message they send and every Whatsapp call they make. All the benefits of the signal protocol are now built in.

We have confidentiality which means the communication is encrypted.

We have integrity which means message alterations will be detected and fail the verification transaction.

Authentication is possible (which is good) but you need to take extra steps to do so. Keep reading.

Participant consistency is also important but defaults to off (has to be enabled manually).

They also claim to have destination validation, which requires the above 2 to work, so technically it is available and built in.

They have forward secrecy which means a future compromise of a private key will not allow the decryption of past messages.

They have backward secrecy, which means a past compromise of a private key will not compromise future protected communications. Keys are constantly being changed and re-negotiated.

They have message unlinkability, which means messages are independent, asynchronous, can arrive independently or be missing, without affecting the fucntioning or efficiency of the entire system.

Message repudiation is also there, which means the sender can deny sending a message. This works because the receiver can forge a message that looks like it came from the other party. Which means none of the participants can claim (to a 3rd party) that a message originated from the other party with verifiability. All that can be claimed is that the sender or the recipient sent the messages. To most this seems bad but in the world of security, this is a good think.

Simple but complex

We all know Whatsapp is a simple to use product but the actual encryption is very complicated and therefore beyond the scope of this post.

As an example, they create static Diffie Hellman encryption keys. Then they create a set of ephemeral keys. Then they use a triple Diffie Hellman protocol to exchange their ephemeral keys and they use a Diffie Hellman key agreement 3 times to take their private key and the other person's ephemeral public key and create a key agreement.

The other user takes his private key and the other persons Diffie Hellman public key to create a second agreement. Then they take the ephemeral keys and use that with Diffie Hellman to get a third set of keys and they concatenate all of these together to create a master session key.

The ratchet

In an interactive protocol a ratchet is where you evolve a key that you agree upon as you send messages back and forth. You ratchet the key forward.

The problem is that this requires real time communications. The innovation here is that they developed an offline ratchet using a hash. Each time both parties are online at the same time, an online ratchet is performed and resynchronize the offline ratchet hash.

First sessions establishment

In real time communications you can create a shared key in realtime. But how do you do this is an asynchronous model with someone you have never messaged before?

To solve for this issue, when you register your Whatsapp client with the server, your client pre seeds the server with 100 ephemeral public keys and assigns an ID to each. This means someone wanting to send you a message for a new communication stream, picks up one of those keys in order to bootstrap a secure message.

They use this public key and place it back on the server until you are online. When you come online, that blob is sent back to you. Your client will never allow the re-use of that public key (by removing it from the pending ephemeral key list). This one time use prevents certain types of attacks.

Perfect encryption

Knowing that Moxie (from OpenWhisper systems) worked on it and reading all the documentation, it looks like they implemented a perfectly designed asynchronous encrypted messaging system.

The one caveat & other thing

The one major exception is that you cannot be sure who you are talking to (authentication).

Threema, my favourite truly perfect encrypted and private messaging system, solves this by only guaranteeing authentication when you physically scan the QR code of the other participant's public key.

To solve this, Whatsapp provide a (per communication thread) QR code or 60 decimal digit user verification code. This code contains both parties encryption keys.

So the problem is you need to perform this verification at least once per conversation thread. This guarantees there is no middleman. Where you can't visually exchange codes, you can read the 60 digit code to each other. If the codes are different, it means there is a man in the middle.

For some reason if the codes change, you are not automatically notified. But under account security, you can enable this notification.

Go to Settings, then Account, then Security, and ensble the switch

Everyone needs to turn this on (participant consistency). The only time a code should should change during a conversation is if the other party installs the app on a new device (or a reset device), in which case you will already likely know and can disregard the alert.

I also want to remind readers that although the messages themselves are encrypted, there is still metadata. There is no technological way to communicate without leaving a trail of metadata today. Metadata is data about your data : such as who you communicate with, how often and how much data you exchange with each other.

Whatsapp is not open source

Many security researchers dislike closed source security applications because there is no way to independently validate the implantation (aka. Know for sure that no one has implemented a back-door or injected malicious code.)

Technology is only as good as its implementation and although the encryption math is perfect, applications rarely are. At some point we have to put our crazy hats down and trust that companies are tying to do the right thing for their users.

Conclusion

Facebook has done a very good job and with the flip of a switch, they have gifted 1B people with easy to use and powerful encryption. I still love Threema because it has better authentication but the truth is none of my contacts use it.

I am excited that more people will be brought into the wonderful world of encryption and have their discussions protected.


Major shift in loyalty incentives needed for programs to survive

Users have a love or hate relationship with loyalty programs. You either love them, because they deliver amazing value, or hate them because you think they’re a worthless scam.

A 2014 McKinsey report showed that companies with loyalty programs (55 publicly traded North American & European companies were surveyed) had the same or less growth than those that had no loyalty programs : 4.4 vs 5.5% per year since 2012. Companies with strong visible loyalty programs seemed to also have EDITDA margins 10% less than companies without loyalty programs in the same sector.

On the flip side, companies with strong and vibrant loyalty programs seemed to have better market capitalization. In fact over a 5 year period, companies with loyalty programs outpaced those without. This may stem from the hope that these loyalty programs will help those organizations drive long-term growth.

The future of loyalty is upon us

No the future of loyalty points isn’t bitcoin, but rather the technology that allows bitcoin to work: the blockchain.

The easiest way to think about these 2 parts is that the blockchain is the operating system and bitcoin is simply one application running on that operating system.

What is the blockchain?

The blockchain is a public ledger that records every legitimate transaction permanently. Once recorded, the record cannot be altered, deleted or changed. Blockchain uses a distributed consensus model, which means no one person, government, group or organization can force changes onto it.

The blockchain is what allows complete strangers who have never met and will probably never meet to conduct a trust-based exchange completely transparently without having to trust each other and without having to go through a central trusted third party (government, bank, notary, lawyer, etc.)

The other characteristic of the blockchain is that it can enable trust-based transaction while maintaining total privacy and anonymity. It can but it doesn’t have to. It all comes down to how it is used.

The blockchain is moving beyond Bitcoin

Until recently, no conversation about the blockchain was possible without talking about bitcoin. People often confused one for the other, but this is changing. Large financial companies are evaluating use of the blockchain to simplify cross-border transactions while improving trust and reducing costs.

If someone is able to marry absolute verified identity to blockchain technology then we could even see very old school lawyer based (expensive) processes move to this medium and become much cheaper and digitally fast (think of marriage, voting, buying/selling of property, etc.).

I believe that in the next 5-10 years the blockchain will become the holder of digital truth, it will completely change many traditional business processes and will provide a level of digital truth that is unmatched even in the real world.

What does bitccoin have to do with loyalty?

Gift cards moving to blockchain because of fraud

The National Retail Foundation says that gift cards have been the number one requested gift for 8 years in a row. CEB TowerGroup say 125 billion dollars have been loaded onto gift cards in 2014.

Like all items of great value, there are bad people out to steal and the industry is constantly challenged with fraud. Until the recipient uses the card, anyone in the chain can steal money from it by copying the unique identification number (processor, distributor, retailer, giver).

How bad is fraud? the National Retail Foundation says 78% of retailers have been victims of gift card fraud.

Benefits of the blockchain for gift cards

Using blockchain technology could eliminate gift card fraud or theft. Each transaction is given a unique identifier, which means someone can’t use the incoming gift card identifier to spend the money. It also means the receiver can verify that the transaction is authentic and that no one else has used the received gift card, since everything is recorded in the blockchain. Once the blockchain powered gift card is stored in a digital wallet, the only person that can spend it is the true owner of the wallet since all transactions are protected by an owner-known private key. The blockchain would prevent “double spending” of a card so a fraudulent bad actor can’t sell a used gift card to an unsuspecting victim.

What’s the motivator for brands and companies

In addition to helping curb fraud, it is also much cheaper to perform a blockchain based transaction (typically about 1 penny). This includes the full life cycle of a transaction from issues, transfer to use. Compare this to most modern plastic card-based systems that cost about $1.50 per transaction.

Blockchain gift cards and the user experience

The technology may be advanced and the protection fantastic but the experience can be simple. Companies have started using bitcoin and blockchain in the back end to improve security while being completely transparent to the end users. The user receives a card and uses it as normal.

Back to Loyalty Programs

If I have airline miles, but would rather trade them for coffee loyalty points, I have to go through one of the traditional trading platforms. These platforms have preset transfer amounts and take a huge cut of the transaction.

In a world where loyalty points are digitally held in a blockchain backed system, I see the rise of highly competitive, open and transparent marketplaces where customers could trade or sell these loyalty points using an open market (supply and demand) system.

The traditional loyalty points systems will be converted to merchant issued currencies. Instead of issuing Aeroplan miles for every mile flown, Air Canada could issue Air Canada cryptocurrency that a traveller could then use to buy upgrades, tickets, amenities, on board goodies, etc. Once we move to this model, these different branded cryptocurrencies could be traded like any other currency. I could trade Tim Hortons cryptocurrency for Air Canada cryptocurrency at a fair market rate.

Trading the branded cryptocurrencies

Trading various branded cryptocurrencies in a fair, open and transparent market means everyone will see the real time value of the branded cryptocurrencies they hold.

It could be used as a market measurement of trust in a company. If the market believes that XYZ airline may go under, then its branded cryptocurrency may be severely discounted, whereas a trusted brand’s cryptocurrency may be much more expensive and used as the “gold standard” for value measurement.

Instead of wasting money on expensive consultants to conduct brand valuation, companies could look at the fair market trading value of their cryptocurrency. The company can then use this as a means of measuring its marketing or PR investments.

How it benefits the customer

Branded cryptocurrencies become a fraud-resistant, immediately tradable commodity. This means I can sell the thing I don’t want and get more of what I want immediately.

In the traditional loyalty model, I conduct a transaction with a merchant (e.g. Fly on Air Canada) but only receive my loyalty rewards in the future (could be days, weeks or months later). In the branded cryptocurrency world, I would receive my “points” immediately when I check into my flight at the gate and can then use this currency to buy goodies on the flight. If I stay in a hotel, I could use their cryptocurrency immediately in the hotel restaurant. This means customers are incentivized to use points faster then and there. It’s better for the customer. It’s better for the merchant. It’s better for the brand.

Financial benefits to companies issuing branded cryptocurrrencies

When a loyalty point is issued, it becomes a liability on the books for that company. Some new entrants are claiming that branded cryptocurrency may change this.

The founders of Ribbit.me claim that if a company issues branded cryptocurrency on the blockchain using an algorithm, it creates an asset for the receiver without a countervailing liability for the issuer because the liability lies with the blockchain itself. If this turns out to be true (and only time will tell if governments will approve this), then companies will be able to take millions of dollars of liabilities off their books.

Conclusion

I believe the market will force companies to adopt this new model, and it will be a significant shift for many.

Ultimately it will democratize the world of loyalty programs and be better for every participant involved.

  • It will improve trust
  • Completely get rid of fraud
  • Drive down transaction costs
  • Force companies to be responsive
  • Create a fair trading open and transparent marketplace that would allow customers to have more of what they want and divest from things they don’t

How to secure Windows 10

The first misconception I want to tackle is that Windows 10 is magically more secure than Windows 7/8.1. The reality is that it isn't, but it benefits for 15 years of continued hardening and security improvements to the Windows core itself.

Having said it isn't materially more secure doesn't mean it's not better. Windows 10 includes some tools to make computing safer for the average user. 

Windows Defender is included with every updated system and is Microsoft’s built in anti-malware tool. It is an all-in-one-security tool delivered for free to all licensed Windows 10 users and the best part is that everything is automatically taken care of in the back end for you. It is automatically updated and performs scans automatically. 

For most users, this is the only anti-malware product they will need. This means most users won’t have to buy a security suite from Symantec, McAfee, ESET, Kaspersky, etc. I do recommend installing a second anti-malware product configured to run only on demand (not real time). This second product is a way of getting a second opinion if something feels weird or as a monthly preventative maintenance strategy. I recommend using a free tool such as Malwarebytes free.

Automagically downloading and installing product updates for you. One of the most critical privacy and security improvements you can make is to ensure your computer is always patched and up to date. With Windows 10, Microsoft will push out OS (and Microsoft product) updates automatically. This means you never have to worry about your OS patches again. Just make sure the other apps on your PC are updated regularly. 

Choosing a secure browser is the second recommendation. My primary browser of choice is Google's Chrome because it is fast and includes many security features (such as auto-updating, sandboxing, etc). Once it is installed, go out and add a plug-in called UBlock Origin (exists for Chrome and Firefox). Ublock origin is a web firewall whose purpose in life is to keep you safe (plus it is an ad blocker so the web becomes faster and more responsive),

Backup your system regularly. I cannot over state how important it is to backup your critical information. Computers will crash. Hard drives will die. Make sure you have a plan B,C and D. Read my article about backups. The TL;DR version is that all data should follow the 3:2:1 rule:

  • 3 copies of your data
  • on 2 separate mediums 
  • at least 1 offsite copy

So for a home user, this could look like: Keep your data on your computer's hard disk, copy it to an external hard disk and use an external backup service like BackBlaze (use this link to get 1 free month to test out the service with no obligation.). You have 3 copies of your data (PC, hard disk and remote service), in 2 separate mediums (disk/ssd plus internet) and at least 1 offsite.

Use a regular user account. Most malware needs an elevate privilege account to run, install and or propagate. This means you should ensure the account you use for everyday work isn't a privileged account (aka not an admin account). 

Password protect your accounts. Some home users gave one generic family account that can be accessed without a password. This means that any one user can infect the system and then affect everyone else. Always create separate (non privileged) accounts for each user and make sure they each have a password to login.  

Use a trusted VPN when connecting to third party WIFI hotspots. It is easy to track and steal information from users connecting to open (or public) WIFI hotspots. The minute you connect to one, make sure you use a trusted VPN service to make sure no one on the local WIFI network can trick you, spoof a site or otherwise do nasty things to your connection. After reviewing the various VPN services available, I personally use ProXPN because of their no logging policy. I use this on my laptops, smartphones and tablets anytime I connect to a WIFI network I don't own and control.

Use good internet hygiene. Be smart to stay safe. Unless there is an absolute need and you are expecting it, don't execute attachments received via email or instant messaging. Never access a protected website (bank, trading account, etc) through an email link. Always enter the URL yourself in the browser. Don't download applications from unknown/untrusted sources (or use pirated software). These often contain malware just waiting to infect your system. Never give a third-party remote access to your computer (even if they claim to be from Microsoft, Dell, Hp, Apple, etc). 

Is Windows 10 spying on me?

This is a question I receive a lot and the answer is maybe a little bit. The reality is that Windows 10 is a connected operating system and it must send some information back to it's home-base, but Microsoft is not spying on you!

Does Windows 10 contain a Keylogger?

Blogs are abuzz with claims that Windows 10 has a built in keylogger sending everything you type back to Microsoft. Worst yet, some blogs have gone as far as claiming this was done to help the NSA.

The reality is that it does not have a keylogger but does log some keystrokes that it sends back to Microsoft. This is done to improve it's autocorrection functionality. This is similar to how most web based SAAS services work. If you use any Google services, they do the same thing.

Windows 10 has simple privacy settings

Go to Privacy Settings and you will find a dozen different privacy options you can toggle to your hearts content.

  <img src="https://ekiledjian2.micro.blog/uploads/2025/1d92c3ad4c.jpg" alt="">

You can turn off settings like Microsoft's unique Advertising ID (think of it like a supercookie). The truth is you can turn this off, but any advertiser worth their salt will still track you using your unique browser footprint and any one of the other dozens of web tracking techniques. 

If you want to see one of these techniques in action, visit the Panopticlick website created by the Electronic Frontier Foundation.

One setting you may want to change is in the Feedback & Diagnostics tab.

  <img src="https://ekiledjian2.micro.blog/uploads/2025/a681f7a25a.jpg" alt="">

Change the feedback request frequency to Never and the Send your data to Basic.

Other trick is to "not use the Edge Browser". It doesn't yet support plug-ins (no ad blockers, etc). 

You can also log into this Bing website and delete all of the information Cortana has learned about you. This will lobotomize Cortana but if you want more privacy go ahead and delete it, 

We are living in a connected world

Living in a connected world means we are leaving digital breadcrumbs everywhere. Advertisers know more about you than your mother.

How Target knows you are pregnant through data analytics

Most people don't realize that every smartphone picture they have taken (iPhone, Android, or Windows Phone) contains the exact GPS location where it was taken. 

Manufacturers are fighting (Microsoft, Apple and Google) to build the next best intelligent personal assistant. But to do this, they must analyze your data to provide context aware relevant information you need before you realize you need it. Microsoft and Google perform this analysis in the cloud, which is why they typically provide more relevant responses. Apple, the self stated privacy company,  parses your data for its Proactive Siri functions on the phone and to be honest, it is pretty worthless.

So you have a choice, use these new wonderful tools or become a digital hermit. I do believe we must take educated intelligent decisions about our privacy, but we have to give some of it up, in order to benefit from the wealth of advantages these companies are providing.

 


Quote about new day

[caption id="" align=“alignnone” width=“2048”] It's a new day, make it great It’s a new day, make it great [/caption]


Do this to keep your free Microsoft OneDrive Storage

What Microsoft giveth, Microsoft can taketh away. And so Microsoft did the unthinkable last year and announced it would be rolling back the free storage add-ons it gave users (base free 15GB storage going down to 5GB and camera roll bonus) and was clawing back the unlimited Office 365 storage to 1TB.

Understandably there was an uproar and now Microsoft has a setup a special webpage where you can ask them to keep your free storage levels. 

  <img src="https://ekiledjian2.micro.blog/uploads/2025/08c550585c.jpg" alt="">

There doesn't seem to be any downside to using this function so go do it now using this link

 

 

 

 


Body language secrets of top negotiators

[caption id="" align=“alignnone” width=“5397”] Image by US department of agriculture used under creative commons license Image by US department of agriculture used under creative commons license [/caption]

Communication isn’t only about carefully crafted words. Negotiations aren’t about arguments and leverage. A good experienced negotiator will marry strong arguments & leverage to carefully practised body language.

There have been dozens of studies and research papers on the power of body language during negotiations. An MIT one measured a negotiator’s ability to convince a jury (body language was accurately measured using a body worn device). It turns out that the right body language can significantly improve the negotiators chances of closing a deal (or convincing a jury in this case). The key takeaways were standing upright, facing the jury and speaking in a lower tone.

So clearly there is something to this body language mumbo-jumbo and it is worth studying and practising. To get you started, here are some tips:

  • While your partner is talking, don’t look down, shuffle papers or mentally start thinking about your next argument. Actively listen to what your partner is saying. Show genuine interest.
  • Try to measure your partner’s general modality and body responses. How do they typically sit. How do they talk (modality). How much eye contact do they typically make. How much do they move around. Do your homework and prepare. Know the baseline body language cues of your partner and you will be able to spot variations. You can also use this information to mirror them and more easily build rapport.
  • Look for gesture clusters. Some movements are nothing too complex but sometimes a person will exhibit a series of body gestures together that happen during specific situations. As an example, maybe your partner crosses his arms regularly and you shouldn’t read too much into this. But if he crosses his arms, taps his foot and does XYZ then it means ABC. Look for these cluster gestures, try to figure out what they mean and record it for future negotiations.
  • Last but not least, feet. Look at the feet. They can show impatience, boredom, etc. If you want to come across as strong and trustworthy, feet your feet still.

Body language secrets of leaders

A true leader captivates the attention of his audience almost immediately and hold it without fail. Certainly being self-confident and a good wordsmith are important but the reality is that body language plays a much more important role.

When you walk in front of an audience, most have already made up their minds about you before you utter your first word. This isn’t magic but basic physiology. This non-verbal communication is a combination of many factors including your posture, tone, facial expression, eye contract, arm and hand movements and more.

Study after study have confirmed that we evaluate a person’s credibility, likeability or trustworthiness within seconds of meeting them.

This primal evaluation comes from the brain’s limbic system. These are the structures that are responsible for memory and emotions. It is our brain’s first response system. As soon as it receives information, it determines whether there is a threat. It’s automatic and almost immediate.

Most of us don’t live with the constant treat of tiger attacks but this basic human system is still alive and well.

Another interesting fact is that body language interpretation seems to be uniformly coherent across different cultures. Basic emotions (fear, anger, etc.) are the same everywhere.

I have been in hundreds of meetings where participants have crossed their arms. Regardless of the reason why, this is seen as a primal sin in body language interpretation. It comes across as cold and unwelcoming. So what is the opposite? Use an open body stance. - This means face your speaker. Don’t sit diagonally from them. Don’t swing your chair back into a semi-sleeping position. Don’t talk to them over your shoulder. - Synchronize your body movements with the other person. If the person is leaning slightly towards the table, do the same. This is often called mirroring. - Nod occasionally to show you are following the conversation (don’t just sit there like a tree stump). - Smile sometimes if acceptable - Sit with your legs and arms uncrossed. - Don’t fidget (including your feet), bite your nails or wipe your forehead.

So a good leader must be authoritative and confidence inspiring. Maintain good posture. Speak at a comfortable pace and pronounce your words clearly. Keep your eyes (comfortably) focused on the other person.

In an increasingly connected world, even the smallest companies can afford video conferencing services which means there will be more and more opportunities for people to judge you based on your body language.

The best tip I can give you is to practice speaches and presentation in front of a mirror, a friend or to record it. You may have ticks or habits that aren’t immediately apparent to you. Practice, learn, practice, learn & repeat.


The Hidden Killer of Your Creativity

[caption id="" align=“alignnone” width=“1090”] Image by  Becky Wetherington  used under creative commons license Image by Becky Wetherington  used under creative commons license [/caption]

Last minute work on school assignments was the norm for most university students. They wait until the last minute then “pull an all-nighter”.

Many feel that this pressure to deliver makes them work better but recent scientific evidence shows that this may actually be completely false.

It seems pressure may actually stifle innovation and creativity. It pushes you down a conventional path.

Some of the most successfully entrepreneurs are people that have learned to deal with pressure. Even when carrying the weight of the world, they are cool, calm and in control.

Be mindful

Any yogi or meditator will extort the virtues of living “in the moment”.

Think about the last time you were waiting in the lobby to be interviewed for a job. In this particular situation, most people feel stressed. They feel fear. They feel eager. Their body reacts to this stress by releasing cortisol. They may sweat a little and even have some nervous ticks.

None of these is ideal for creativity. You are rarely putting your best foot forward in these stressful situations.

But remember that the stress you feel isn’t because of something that is happening then and there (in the moment). It is because you are worried about what you think may happen.

If you are able to be “in the moment”, then you will release the stress and shine like the star you are meant to be.

The research

Professor Teresa Amabile (from Harvard Business School) conducted research into creativity in the workplace and discovered that employees under pressure almost never performed optimally when completing tasks. Funny enough many thought they were optimally creative but measurably they were not.

Rear my article Monotasking is the new productivity hack

Read my article How to set personal goals, which talks about starting with the end in mind.

Stress Physiology

Epinephrine and norepinephrine are stress hormones produced when you feel stressed. It is the physiological response know as flight or fight. These hormones help you move faster during emergencies.

The other hormone produced during excessive stress is cortisol. Psychology Today called Cortisol The Stress Hormone public enemy No 1

Excess cortisol in your system can lead to a host of health issues including weight gain, osteoporosis, digestive problems, cancer and much more (1, 2, 3.

In addition to wreaking havoc on your body, it can have devastating effects on your mind.

Stress creates free radicals

Cortisol creates a surplus of the neurotransmitter glutamate. Glutamate in turn creates free radicals that attack brain cells (similar to how rust affects metal).

Stress makes you forgetful and emotional

One of the early symptoms of stress is becoming forgetful and emotional.

Studies show that stress causes a reduction in brain electrical activity associated with memories and an increase in activity associated with emotions.

Stress negatively impacts intelligence

I wrote about stress on creativity and stress makes your brain seize up. Think about our primitive ancestors and how they reacted when being chased by a lion. The fight or flight response means your physical characteristics are improved, your reactions are improved but your reasoning and logic suffer. After all you don’t need deep critical thinking when running to save your life.

How can you handle pressure?

First thing first, remember that regardless of how important you think your job is, you aren’t performing brain surgery. Our job is important to us but it isn’t critical to the survival of all humans so chill. Take it easy on yourself.

When feeling stressed about an upcoming situation, ask yourself, “whats the worst that can happen? Then realize that things aren’t actually that bad and relax.

Olympic athletes spend as much time mentally preparing as they do physically. They mentally perform their duties over and over to ensure they are relaxed when they need to perform. It becomes automatic and routine. If you are heading into an interview and you know you will be stressed, prepare and practise.

The second tip is to mentally practice over and over. Make sure you know what the ideal final result looks like and focus on that.

I ran the information security team for a large multinational manufacturer that was regularly attacked. By constantly practising the incident handling processes, our handlers were calmer and more confident when the real thing did happen.

Confidence is the third technique I want to share.

Having confidence in yourself will usually lead to less stress and increased productivity.

When handling an incident, it is easy to get overwhelmed. You are dealing with a skilled adversary out to get you. They are technically strong, well funded and extremely motivated. It is easy to get overwhelmed and freeze up. But I always tell my people to be optimistic. Regardless of how bad it may seem in that moment, I truly believed that things would get better. And my ensuring my team believed in that as well, it makes the process easier to manage and made my people more productive and efficient.

Optimism is the fourth technique.


Travel Tip : Use a reliable VPN when connecting to WIFI

[caption id="" align=“alignnone” width=“2667”] Image by  EFF Photos  used under Creative Commons License Image by EFF Photos  used under Creative Commons License [/caption]

As a security professional, I know the risks of using WIFI, particularly when using WIFI outside of work or home. It can open you up to an entire world of hurt from hackers and bad actors. They can steal information and trick you into visiting questionable websites.

But WIFI is how most hotels offer internet connectivity these days. WIFI allows you to connect to the wonderful world wide web when flying 30000 feet in the air using services like Gogo.

Instead of telling you *not to use wifi*, I’m here to tell you to protect yourself by using a VPN service (from a laptop, tablet or smartphone).

A good VPN service means your communication (between you and the VPN service provider) is encrypted which means bad guys snooping on WIFI won’t be able to steal your information. 

Using a VPN when connecting to WIFI means you are protecting your identify, you are protecting your sensitive information, you are ensuring bad people aren’t tracking you and you can visit geo-locked websites when abroad (HULU, Pandora, etc). I used a VPN when travelling in China to visit sites that would have otherwise been blocked and to conduct more sensitive tasks like banking.

There are a lot of VPN services out there and you have to remember that the VPN service you use *will see all of your outbound traffic* as they send it of to the public internet. You should pick a reputable company that ideally has a very minimum level of loging. 

My personal VPN service of choice is ProXPN. ProXPN has outbound locations around the world which is useful for accessing geo-locked content. ProXPN uses OpenVPN technology and works on all platforms (Windows, Mac, Android, iPhone, iPad, Windows Phones, etc).

ProXPN has a no loging policy, which I like. They have a VPNGuard feature for PCs and Macs that allows you to shut down any running app on the desktop if the VPN connection were to drop (this is useful for apps that must absotely be protected).

I am not paid by ProXPN and do not receive any compesation for recommending them. I am simply sharing my personal tool to help you guys/girls.


Travel Tip: What food can I bring back

[caption id="" align=“alignnone” width=“2592”] Image by  Antony Stanley  used under creative commons license Image by Antony Stanley  used under creative commons license [/caption]

Frequent and infrequent travellers usually are confused about what food products they are legally allowed to bring back. Since many of my readers are American, I will write about USA regulations.

Americans coming back home with food

It is important to ensure you comply with these import control rules as breaking them can be punished with a slap on the wrist of a very severe high cost fine. The US CBP website says >“Failure to declare food products can result in up to $10,000 >in fines and penalties.”

You should checkout the special US Customs and Border Protection webpage entitled Travellers bringing food into the U.S. for personal use

The (partial) list of acceptable imports : - Condiments such as ketchup (catsup), mustard, mayonnaise, Marmite and Vegemite and prepared sauces that do not contain meat products

  • Olive oil and other vegetable oils

  • Bread, cookies, crackers, cakes, granola bars, cereal and other baked and processed products

  • Candy and chocolate

  • Cheese- Solid cheese (hard or semi-soft, that does not contain meat); butter, butter oil, and cultured milk products such as yogurt and sour cream are not restricted. Feta cheese, Brie, Camembert, cheese in brine, Mozzarella and Buffalo Mozzarella are permissible (USDA Animal Product Manual, Table 3-14-6). Cheese in liquid (such as cottage cheese or ricotta cheese) and cheese that pours like heavy cream are not admissible from countries affected by foot-and-mouth disease (FMD). Cheese containing meat is not admissible depending on the country of origin.

  • Canned goods and goods in vacuum packed jars (other than those containing meat or poultry products) for your personal use

  • Fish- personal amounts of fish, shrimp, abalone and other seafood are allowed and can be fresh, frozen, dried, smoked, canned or cooked

  • Dried Fruit- things like apricots, barberry, currants, dates, figs, gooseberries, peaches, prunes, raisins, tomatillos, and zereshk (USDA Miscellaneous and Processed Products Manual, Table 3-69)

  • Liquid milk and milk products intended for use by infants or very young children are admissible if in a reasonable amount or small quantity for several days' use.

Note: Milk and milk products from goats must be accompanied by a USDA import permit if from regions classified as affected with foot-and-mouth disease (FMD) or Rinderpest.

  • Powder drinks sealed in original containers with ingredients listed in English. However, admissibility is still under the discretion of the Customs and Border Protection (CBP) Agricultural Specialist.

  • Juices- commercially canned (USDA Miscellaneous and Processed Products Manual, Table 3-75)

  • Tea- commercially packaged and ready to be boiled, steeped or microwaved in liquid. Coca, barberry and loose citrus leaves are prohibited (USDA Miscellaneous and Processed Products Manual, Table 3-148)

  • Coffee- roasted or unroasted if there is no pulp attached. (USDA Miscellaneous and Processed Products Manual, Table 3-48)

  • Spices- most dried spices are allowed except for orange, lemon, lime and other citrus leaves and seeds, lemongrass, and many vegetables and fruit seeds

  • Honey- comb honey, royal jelly, bee bread, or propolis if it is not intended to be fed to bees (USDA Miscellaneous and Processed Products Manual, Table 3-100)

Canadians coming back home with food

If you are a Canadian travelling back home, you have a similar webpage from the Canadian Food Inspection Agency called What can I bring Into Canada in terms of food, plant, animal and related products?. The webpage is comprehensive and worth taking a look. This webpage is also important for Canadians that want to shop for food in the US and bring it back to Canada for consumption.


Security Researcher claims to have downloaded 13M accounts from MAC Scamware apps

If you visit shady internet sites from an Apple Macintosh computer, you may have already seen an add from a product called MacKeeper. The researcher in question said:

"I have recently downloaded over 13 million sensitive account details related to MacKeeper, Zeobit, and/or Cromlech." Reddit

He said the information collected includes "names, email addresses, usernames, password hashes, computer name, ip address, software license and activation codes, type of hardware (ex: "macbook pro"), and type of subscriptions."

And he provides this screenshot as proof of his claim :

  <img src="https://ekiledjian2.micro.blog/uploads/2025/88cf7c9e7d.jpg" alt="">

The sites used encryption but used it badly... The researcher says:

"MD5 with no salt… so very weak hashing"

The moral of the story is be careful what you believe on the internet and where you buy your software from.


Travel Tip: Find safety tips for your travel destination

[caption id="" align=“alignnone” width=“3330”] Image by  Manoj Vasanth  used under creative commons license Image by Manoj Vasanth  used under creative commons license [/caption]

The Paris Terror attacks were a stark reminder that the world is a dangerous place. It is now and has always been but this should prevent you from exploring this great big beautiful world of ours.

There are tips to stay safe, of course, and one of those is to “Be Prepared”. In my previous blog post, Travel tips when travelling alone, I talk about doing your homework but it’s important enough for me to re-mention it here again.

Many government websites list travel advisories but also provide important information about the countries you will be visiting. As an example some Asian countries have this nasty tradition of convincing young male travellers to visit certain bars where they end up paying 10–20 times normal prices for drinks (and these are pay up or else type shady places).

If you are American, you want to consult all the information the state department has for your destination. In addition to that site, visit the US embassy webpage for that location (if it exists).

Regardless of your country of citizenship, it is also a good idea to checkout the foreign ministry information pages produces by other countries such as: - UK Foreign and CommonWealth Office

"Chance favours the prepared."


Trace Me Luggage Tracker will make sure you never lose your bags again

As many of you gear up for holiday travel, you may have the lingering concern of losing your luggage. Most airlines will credit you a couple of hundred dollars for a lost and unrecoverable bag, but this rarely covers the actual cost of the contents. You can also buy insurance but that doesn’t help when you are standing around the carousel waiting to start your vacation and your luggage never shows up.

Do bags really get lost?

SITA’s baggage report 2015 provides some interesting industry information. Passenger numbers rose 5.5% from 2013 to 2014. The Passengers Without Bags (PaWoB) statistic rose to 7.3 bags per thousand passengers (previous year was 6.96).

The statistic is more worrisome than some realize.

The low-tech solution

There are many high-tech solutions (think GPS trackers) but these are techniques you have to perform to locate your bag. A less high tech but very effective product is Trace Me.

Trace Me is a plastified card with a unique identifying bar code. You register this code online. When an airport staff scan it (or law enforcement, baggage handlers, etc.), you are notified via text message letting you know where it was scanned . It also tells the scanning agent whom the bag belongs to. Then the airline performs its delivery magic to reunite you with your “stuff”.

Who is SITA and How does this work?

SITA is a Geneva-based airline technology provider. Trace Me uses their WorldTracer global bag-tracing and matching system.

WorldTracer was developed by SITA in co-operation with IATA and is a global lost and found system for luggage. WorldTracer is used at 2,800 airports worldwide so Trace Me will work in most airports worldwide.

WorldTracer stores your tracking information in their database and is a member of the Worldtracer system. As soon as any WorldTracer user scans the unique bar code, they are presented with your information and Trace Me knows your luggage was scanned (when, where and by which entity).

Where can I buy it

If you search the web, there are a handful of online retailers that sell it. The most popular one seems to be TravelSmiths at a cost of $19.


Travel Tip : Show up to the gate early

In an effort to meet departure times, some airlines (worldwide) seem to have adopted an earlier than printed (on the boarding pass) boarding start process. This doesn’t seem to be happening at every airport with every airline but I have been hearing about this more and more from readers, airline employees and frequent flyer contacts.

This means that if you aren’t there a bit early, you may not board the plane early enough to get space in the coveted overhead bin. This is even more problematic for frequent flyers with special boarding privileges that may not be aware and get stuck having to gate check their carry-on bags.

The moral or the story is to show up to your gate at least 20 minutes before the printed boarding time on your boarding pass.


Afterlight photo editing app for iPhone & iPad free

After light is a wee designed and easy to use photo editing application that offers 74 filters, 78 textures and 128 frames. Overall a well stocked application that any iPhone photographer should have. 

Now you can download this app for free (normal $US1) courtesy of Apple's Apple Store iPhone or iPad app. 

You can download the Apple Store App from the iTunes store (link)

Open the application

Scroll down until you see the free app offer

  <img src="https://ekiledjian2.micro.blog/uploads/2025/9b80b01865.jpg" alt="">

Click on the offer.

  <img src="https://ekiledjian2.micro.blog/uploads/2025/7f47695e52.jpg" alt="">

You will be presented with the description.

Click on download now.

You will be given a unique iTunes offer code. Just redeem it and the app will download.

  <img src="https://ekiledjian2.micro.blog/uploads/2025/1bac97b973.jpg" alt="">

That's all folks.

Enjoy