Crowdstrike Incident

July 19th, 2024, Crowdstrike distributed a faulty update that caused an estimated 8.5 million computers and servers running Microsoft Windows to crash. Causing multiple machines to stuck at blue screen of death and can’t restart.

The outage disrupted businesses around the world. Affected industries included companies, airlines, airports, banks, hotels, hospitals, manufacturing, stock markets, broadcasting, and more.

Outages were experienced worldwide, reflecting the wide use of Microsoft Windows server by global corporations in numerous business sectors. Widespread outages were immediately reported across multiple countries. Sending and receiving emails may be affected with companies that use Windows server.

Setting Thunderbird

Thunderbird is a free and open source mail client. Steps to setting Thunderbird:

  1. Click 3 stripes Menu icon on toolbar above > New Account > Existing Email.
  2. Input Name, Email Address, and Password. Check Remember Password if you don’t want to input password everytime.
  3. Click Continue button. Thunderbird should auto detect settings. Click Done. Finish.

If auto configuration failed, click configure manually:

Server type: IMAP (recommended)
Incoming & outgoing server: mail.yourdomain.com. Replace yourdomain with your own domain.
Username: yourname@yourdomain.com. Replace with your full email address.
Incoming port: 993
Outgoing port: 465
Security: SSL

KeyBCA App

KeyBCA is token used to generate apply-1 and apply-2 for BCA’s internet banking. BCA has launch KeyBCA app. KeyBCA app has its pros and cons.

Pros:
1. Eliminate expensive Rp 50.000 out of battery token replacement.
2. Less device.
3. Approval history.

Cons:
1. It might not be the safest bet to carry token everywhere.
2. More difficult to delegate to representative.

Regardless of pros and cons, looking at development path KeyBCA maybe discontinue on future. It is a good habit to migrate earlier.

To use KeyBCA app, we must first unlink KeyBCA token:
1. Login to mybca.bca.co.id.
2. Click the settings icon on the top right.
3. Select the Connect KeyBCA menu.
4. Select Change KeyBCA.
5. Select the e-Banking mobile number to be used and enter the APPLI-1 response from the physical KeyBCA, then click Continue.

After unliked, KeyBCA token will be deemed useless.

Install KeyBCA app from Google Play: https://play.google.com/store/apps/details?id=com.bca.keybca
1. Open the KeyBCA app, click Set Up Now. Agree to the terms and conditions, click Next.
2. Enter your 16 digit ATM card number, click Verify Account.
3. Verify by SMS.
4. Create a 6-digit PIN that will be used to log in and approve transactions through the KeyBCA app.
5. Confirm PIN, click Verify Account.
6. Verify yourself by taking a photo of yourself, click Next.
7. Verify by entering the OTP code sent via SMS.

Digital SIM

Digital Korlantas Polri is an app for renew SIM online. Install it from Google Play: https://play.google.com/store/apps/details?id=id.qoin.korlantas.user

The first step is to register digital SIM. The app have 3 options:

  1. Input driver license number manually.
  2. Photo. App will automatically locate driver license number.
  3. NFC. Put SIM behind phone to scan the chip. This option only work with electronic SIM.

Either of these options are same is just to input driver license number. Then save. If successful, SIM will appear on app. Repeat the process for SIM A / C.

Change Mail Server

Sometime mail provider may change server domain. Or maybe changing provider. Webmail user is automatically updated because it is server side. Because mail client settings are saved on local, user may need to update settings. Step to change mail server:

Thunderbird

  1. Click on 3 strips Menu icon on top > Account Settings.
  2. Locate your email account and click Server Settings.
  3. Change Server Name with mail.yourdomain.com. Eg: if your domain is ekomersial.com then it is mail.ekomersial.com
  4. Save.
  5. On left panel scroll until bottom and click Outgoing Server (SMTP).
  6. Click on your mail account > Edit.
  7. Change Server Name with mail.yourdomain.com same as above.
  8. Click OK.

Android

  1. Click on 3 strips Menu icon on top.
  2. Click on Gear icon.
  3. Click on your email account.
  4. Click Server settings.
  5. Change IMAP server and SMTP server with mail.yourdomain.com. Eg: if your domain is ekomersial.com then it is mail.ekomersial.com
  6. Click Done.

Digital KTP

Starting 2024, Indonesia’s government will not print new KTP card. Install Identitas Kependudukan Digital to get digital KTP. First of all, this must be done on Disdukcapil. Link to install Identitas Kependudukan Digital: https://play.google.com/store/apps/details?id=gov.dukcapil.mobile_id

Go to Disdukcapil and follow through registration desk. This app also have integrated digital Kartu Keluarga if you already have electronic Kartu Keluarga.

.id Alphanumeric EPP Code

The new Pandi’s .id domain rule only allow alphanumeric EPP code. That is a-z, A-Z, and 0-9. Old domains EPP code may still contain symbols. That will cause domain transfer failed with error 2005: Parameter value syntax error (DomainAuthInfoType: alphanumeric). If you have this error, request new alphanumeric EPP code to registrar. Repeat domain transfer with the new EPP code.

Avoid Phishing Email

Phishing email is a type of fraud where an attacker send a fraudulent email by masquerading sender email as looks like it sent from official website. For example our domain is ekomersial.com:

Official: John <john@ekomersial.com>
Phising: John <john@somedomain.xyz>

Phishing is dangerous if not observed carefully. Steps to mitigate phising email on platform:

Android
Click on sender name to reveal sender email address.

Roundcube Webmail
1. Click on cogwheel icon on left.
2. On Preferences > Displaying Messages. Switch on Show email address with display name.
3. Click Save button.

Thunderbird
Sender email address automatically displayed behind sender name as Sender Name <senderemail@domain.com> format.

Now sender email address displayed along with sender name. We can check the domain if the email is from official website. If you found phishing email, do not click any link and delete the email immediately.

Captcha

Brute force attack is password hacking method by guessing every possibilities. We can use Recaptcha to prevent brute force. Recaptcha use adaptive challenges to prevent bot from login and register on your website.

This simple checkbox is easy for human, hard for bot.

Recaptcha isn’t just for login. Recaptcha also useful for filtering spam comments. So that only legitimate users will be able to comment.

Security is our top priority. All of our web development packages included Recaptcha for your website security.

How to Properly Close Android Apps

How do you usually close Android app? Press home button? Do you know the app is still running on background?

To check running apps on Android press menu button on bottom. If there are too many apps running will slow down phone and drain battery.

It is a good habit to close app every after use. Rule of thumb is only keep one app running at a time. Unless you are doing transaction between apps. This way you use battery efficiently and last longer.

How to properly close Android apps: