Skip to content
 

Focus on the businesses new online technology doesn’t kill

California’s Coachella Valley is full of ultra-new shopping centers. They house the nation’s chains. In recent days I’ve been perusing them. There aren’t many that impress. Costco is an exception. The many chains of cheap clothing and cheap shoes probably have a limited life. Those being hit by Amazon’s exploding online sales — like Barnes and Noble and Best Buy — are destined for history’s dustbin.

Stores that deliver stuff that can’t be provided by Amazon (or anyone else) from afar should survive handsomely. Two categories that stand out: retail medical services

and cheap, quality restaurants. The two restaurants standing out are Panera Bread

and Chipolte Mexican Grill. I wish I had done my little drive-by last year when I was last here. Both Panera and Chipolte’s stocks have exploded in the past twelve months.

I asked myself. “Was their stock still worth buying?” I compared the two.

Panera Bread (PNRA)
Chipolte Mexican Grill (CMG)
Sales
$1,542,490,000
$1,835,920,000
Employees 15,900 26,500
One year growth in sales
13.96%
20.91%
One year growth in earnings 30% 41.1%
Restaurants 1,453
1084
Market capitalization
$3,705,050,000
$7,569,770,000
P/E ratio
32.83
43.24

The short conclusion: Both are fully priced. Panera probably has the edge. I kick myself because I heard about Panera when it was around $65 and I thought it fully priced then. Before you buy either, go eat at both. Our family like Chipolte. I wanted to eat last night at Panera, but the line — at 5:30 PM no less — was huge.

And so were many of its happy customers.

Wireless speed beyond comprehension. Verizon is obsessed with delivering speed to its customers. It clearly believes that the more speed, the more customers. It’s right! I’m a sucker for Verizon’s fibre optic to the home service called FiOS which delivers reliable Internet speeds beyond any I’ve ever seen — by a substantial order of magnitude. Now it’s delivering the same thing via its new 4G LTE network, which is now available in major cities. Yesterday Walt Mossberg of the Wall Street extolled the virtues of Verizon’s new ThunderBolt phone — its first to work the 4G LTE network. But don’t do as Walt suggests and buy ThunderBolt. Verizon will have a zillion phones on 4G LTE in coming months. Moreover, by then we’ll know how much Verizon will charge to use the phone as a WiFi hotspot — so you can tether your laptop and get the speeds.

How fast? According to Mossberg:

I also tested it as a Wi-Fi hotspot and got download speeds on my laptop of 7  to 10 mbps and upload speeds of 2 to 3 mbps.

That is really fast for wireless cell phone data — and a lot faster than many people are getting on their broadband wired landlines — on either DSL or cable modem. Trust me. Verizon’s 4G LTE is a gamechanger. But wait a few months for more Verizon products.

As disasters spread, so do online scammers. This is Jan Bultmann in the latest issue of Windows Secrets. It’s reputable.

The outpouring of generosity from people all over the world following the earthquake in Japan has been accompanied by a profusion of donation scams. These scams no longer prey on the simply gullible but have moved to less obvious ruses such as malicious websites that use clickjacking and drive-by attacks.

Natural disasters bring out extremes of human behavior. Workers at the devastated Japanese nuclear power plants place themselves in harm’s way trying to protect other people from explosions and radiation poisoning. Military and social services staffers work days without sleep under horrifying conditions.

And in response, strangers around the world ask how they can help, what they can do, what they can send. Unfortunately, predators also respond, seeking to exploit the suffering and generosity of others for personal gain.

Online donation scams are not new, but they became really evident in 2005 in the aftermath of Hurricane Katrina. Most of those scams were e-mail–based phishing, also known as 419 scams. The least sophisticated claimed to be from victims; they explained complicated and peculiar circumstances leading them to write e-mails asking individuals for money. More advanced phishing scams imitated the look and feel of reputable charities’ Web presences.

Thanks to the increasing efficiency of spam filters, e-mails such as these reach fewer users today — and most Web users have learned to recognize and discard them quickly.

Since 2005, online scams have grown in sophistication. So it should be no surprise that, in the wake of Japan’s crisis, donation scams are harder to spot. Clickjacking and drive-by threats don’t depend on our charitable impulses — they target our interest in the unfolding events, using such common sources as news photographs, links to YouTube videos, and information updates.

Since March 11, 2011, scores of domain names have been registered — names containing terms such as Japan help, tsunami, or nuclear disaster, according to a Forbes report.

Often, these URLs are similar to the Web addresses of popular sites or are based on common misspellings. These malicious sites are also heavily seeded with now-familiar search terms (Japan, tsunami, nuclear disaster, radiation, Japan help, and so on) to draw the clicks of (or clickjack) people searching for information. This practice is known as search engine optimization poisoning.

A TrendMicro blog shows a search return list that reportedly includes fake sites.

Sometimes the scams are relatively innocuous; scammers register these bogus Web addresses as a way to earn money through advertising or delivering traffic to online survey sites. But others are far more dangerous. Clicking malicious drive-by sites, for example, can easily result in an infected PC.

Search-engine companies watch for these sites and eliminate the dangerous ones as quickly as possible. But so many have appeared in the aftermath of Japan’s disaster that even Google is having difficulty keeping up with them, reports Bojan Zdrnja at Internet Storm Center.

PC users can also be directed to drive-by sites through links circulated on Twitter, Facebook, and other social-networking sites as well as in discussion forums. Wall posts, IMs, and messages represent themselves as containing links to newly uncovered disaster videos that might be tsunami simulations, doctored images, and worse.

As Graham Cluley, senior technology consultant at Sophos, wrote on the Sophos blog:

“Facebook users are being tricked into clicking on links which claim to be raw CNN footage of the Japanese tsunami by cold-hearted scammers — as part of a plot to earn money by driving Web traffic to take online surveys. The videos, which in the examples seen by Sophos exist on a website called spinavideo, purport to be footage of the horrifying tsunami which hit parts of Japan on Friday.”

Clicking the link takes users to a spoof website that looks like YouTube. Users are tricked into agreeing to ‘Like’ the page on Facebook, which spreads the scam even further on Facebook.

But misdirection to online surveys and likejacking, as Cluley describes above, can be the least of a deceived user’s problems. A user who activates a clickjacking link is taken to a drive-by website that might (or might not) look legitimate but that automatically downloads malware onto the user’s machines. The most frequently downloaded type of malware is rogue security software, often also called rogue antivirus software (or rogue AV).

Rogue security software masquerades as legitimate security software. Sometimes it even imitates legitimate security software interfaces, such as Microsoft Update. After it’s installed on your machine, antivirus malware might simply pretend to detect viruses and then entice you into paying for a subscription to have your machine cleaned.

Or it might install more malicious software — keyloggers, password recorders, or rootkits — that can go undetected while stealing your data. This software might lie dormant until it detects a specific event, such as when you enter a bank account number. Then it comes to life and starts collecting your keystrokes: recording your passwords, social security number, date of birth, and other personal data.

The scammers resell your credit card numbers or passwords to other criminals. Then they change their company name, change the credit agency they’re using to bill you for your “malware subscription,” and vanish before they can be identified. Rogue security software costs the banking industry billions of dollars a year, a cost borne by consumers.

Figure 1 shows an example of rogue security software that’s disguised as a Microsoft alert.

How can you avoid clickjacking scams and drive-by websites? It’s simple, but in the heat of a disaster, it can be harder than it sounds. Sophos’s Cluley wrote, “Remember to always get your news from legitimate news websites, and if you’re hunting for a video, make sure that you go to the real YouTube website rather than a replica set up by scammers.”

Meanwhile, old-fashioned donation fraud, featuring spoofed charity sites and phishing e-mails, has not gone away. ScamWarners has reported detecting a fake Salvation Army site. FBI spokeswoman Jenny Shearer told MarketWatch.com that a fraudulent e-mail, purportedly from the British Red Cross, is soliciting wired donations.

Here are tips to help you protect yourself from donation fraud:

+ Make informed choices about where to donate. Before turning over the personal information needed to process your donation, visit an online watchdog site such as charitywatch.org to evaluate the receiving organization’s legitimacy.

+ Don’t click links in online forums, e-mails, or IMs that say they are from charity organizations — even well-known ones such as the Red Cross or Red Crescent, Mercy Corps, World Vision, or others. These e-mails could easily be spoofs that will direct you to a website that looks like the real thing but steals your data.

+ Do not respond to unsolicited requests for donations, particularly from people who claim to be victims. “Symantec has observed a classic 419 message targeting the Japanese disaster,” said researcher Samir Patil in a post to the company’s security blog. “The message is a bogus ‘next of kin’ story that purports to settle millions of dollars owing to an earthquake and tsunami victim.”

+ To get to the website of a charitable organization you want to support, type its web address into your browser’s address bar yourself — don’t rely on links, however professionally designed they may look, to take you there.

+ When you are on a charitable site, take a moment to check the spelling of the organization’s website in the address bar. Scammers often use common typos or misspellings to create URLs that fool an unwary eye.

+ Make sure the page where you enter your credit card or other personal information is encrypted. The beginning of the address should read https:// instead of http://.

+ Make sure any site that you donate through has a written privacy policy.

+ Get your news about events in Japan from reputable news sites.

If you believe you have been a victim of a charity-related scam, contact the National Center for Disaster Fraud by telephone at (866) 720-5721, by fax at (225) 334-4707, or by e-mail at disaster@leo.gov.1.

You can also keep an eye on samples of fraudulent e-mails and messages by watching the forums at ScamWarners, a reputable Internet Fraud Center that will also examine and evaluate material you submit and post samples to help other people avoid being scammed.

Flying to Texas.
A Baptist Preacher was seated next to a cowboy on a flight to Texas. After the plane took off, the cowboy asked for a whiskey and soda, which was brought and placed before him.

The flight attendant then asked the preacher if he would like a drink.

Appalled, the preacher replied, “I’d rather be tied up and taken advantage of by women of ill-repute, than let liquor touch my lips.”

The cowboy then handed his drink back to the attendant and said, “Me too, I didn’t know we had a choice.”

May I please buy some cyanide?
A nice, calm and respectable lady went into the pharmacy, walked up to the pharmacist, looked straight into his eyes, and said, “I would like to buy some cyanide.”

The pharmacist asked, “Why in the world do you need cyanide?”

The lady replied, “I need it to poison my husband.”

The pharmacist’s eyes got big and he explained, “Lord have mercy! I can’t give you cyanide to kill your husband, that’s against the law? I’ll lose my license! They’ll throw both of us in jail! All kinds of bad things will happen. Absolutely not! You CANNOT have any cyanide!”

The lady reached into her purse and pulled out a picture of her husband in bed with the pharmacist’s wife.

The pharmacist looked at the picture and replied, “You didn’t tell me you had a prescription.”


Harry Newton who loves the weather here — at least in March. it gets very hot here come May. I think that’s where they got the old stockmarket adage: Go away in May. Come back in November.

2 Comments

  1. bmforbes says:

    Of course the first phone on the LTE website gets all the speed. The more phones however… the less speed. At least the calls won't drop.

  2. Finefood says:

    Harry,
    Just wanted to mention a new restaurant named Coal Burger that could possibly become the next Panera or Chipolte.