For the past year I have been building an editing support page which is set to private, so only you can see it. Within this page is a guide for editors and lots of additional resources, all online and built into your website.
With the changes in the Divi template (Visual Editor), I have made some changes to one of the guides I have been placing on sites.
If you are familiar with guide, you can download an updated copy here. This will tie into a template that is built into your site which is the first step for creating a news item.
For those of you that would like something like this in your site, download a copy and see if you think it would help. Drop me a line and I will see if it is feasible to add in.
If you already have an Editor or equivalent page, locate the page, open it in the editor and attach this version to the button for the Get Me Started Mark guide. If you are one of the recently upgraded Home-Start websites, I have already added it in.
Around 50% of the Home-Start sites I host, or have built are either in a rebranding queue, or have been upgraded and released. If you don’t know anything about this, then you have missed some of my messages reaching out to you. I have only responded to those that replied and currently not chased anyone else up.
As of 6th July, the following sites have been through the rebranding exercise. Most of these sites were in the Divi framework anyway, a few are more substantial upgrades from previous versions moving them to the latest version of the website.
If you don’t know about any of this, and need to be added to the list please get in touch with me ASAP. My queue of upgrades currently goes out to the end of July 2019.
This is a list of example sites that have been through the process.
All of these sites have retained the local messaging and content from the respective original website. I have concentrated on changing the colours, logo, images and incorporating other latest thinking on the development of these sites which also covers taking out old plugins and replacing them with new more up to date plugins. In many cases it has been a bit more than just changing the wallpaper. I have cleaned things up as well.
Sometimes you need to add a table into a webpage. There are several ways of doing this. You can create a table in MS Word and copy it, then paste it into a page. You can do the same with Excel. However neither of these is particularly elegant. In both cases you can end up with a largely responsive table provided you do not have too many elements in there.
There is a plugin for that..
One particularly neat solution which has a huge number of users, and very high approval ratings is TablePress. This is a downloadable plugin.
Go to the Plugins option in your wordpress site, and add a new plugin and enter Tablepress into the search box and it will find it. Add it to your website and activate it.
Post activation you will find it as an option in the dashboard menu. TO add a table simply go into the plugin settings and choose Add Table, define how many columns and rows it needs and then build your content in WordPress.
There are also options on importing tables from other sources. It is a very flexible plugin that is not too difficult to use.
I had a couple of calls over April with one particular charity group where the message was clear. The websites in both cases had not been updated for well over 12 months. The staff had reduced in the offices, and as is often the case the workload increases for those that remain.
If you find yourself in this position, give me a call. Perhaps I can help by adding a couple of things to the website. It does not take me very long to add things to a website, and if you have an urgent need it is really just a phone call. If I can help I will.
The Window into your Organisation
Your site is your online brochure and if it is not current it may reflect poorly on your organisation. Most importantly it is not going to endear potential funding sources to your organisation if it appears you are not doing much. Of course we know a lot is going on, so remember to celebrate your successes on your site as well as any new campaigns.
If you have something important, it is vital to get it on your site ASAP, so if you cannot for whatever reason just give me a call and I will see if I can do it for you. Give me a call or contact me.
I want to stress this is for critical items, not one per month 🙂 But don’t park it for later. I can permanently edit your website if you wish, but that is subject to an agreement. I prefer you to do it, but the option is there if you wish to use it.
(I am sending out the form below to my contact list, but I know my contact list may not be accurate. If you have seen this form before, you only need to fill this in once. If you have not seen it before, please just go ahead and fill it in and return it to me and I will get back in contact.) If you are not sure, just fill it in. Better to have two applicants than none.
Home-Start UK upgraded their website on or around the 30th of April and are now featuring new branding and messaging.
If you have a Home-Start website developed by me, I intend to offer a low cost upgrade to enable your site to fall in alignment with the new branding.
The details are in the attached document below. Please download this and if you would like to join the queue for an upgrade please fill in the last page and send it back to me. Costs are anticipated to be in the range of £50 to £120 per Divi (most recent template) design. Work when started will take about 1 day.
Most of us have no idea who is on the network, and if they are on my network they must be legitimate right? Well no not necessarily. If you have a decent firewall between you and the internet, (a function usually incorporated into your broadband router) then computers generally cannot get into your network from the internet. There are exceptions of course such as remote access through the firewall which needs to be configured by someone.
I have spent much of the past month decorating and installing a new office, and reviewing my network(s)…. Yes I have more than one.
Sharing your network
At home I used to share my network with the family. That is to say in the conventional sense, we were all connected together behind the same router. So the router, with its built in firewall function provided protection from intruders from the internet.
However my son tends to cruise the internet and visit all sorts of websites of dubious content. He is way past the age of trying to apply any parental controls. If he happened to click on something (I stress if, there is no evidence it ever happened) he might install a local virus on his computer, which will open access through the firewall to a remote server. He also does a lot of gaming, and I did not want that getting in the way either.
Solution
I have several layers of network, an inner network which is tightly controlled, and an outer network which uses both wired and wireless systems in the conventional sense. Guests and anyone else that need general access can join the outer network and access email, the web and anything else they need. The wireless runs over 5GHz and 2.4GHz and uses WPA2 and PSK for encryption with complex passwords.
Inner network
While the outer network is protected from the internet using a router, there is a second router which connects the outer network to an inner network. The inner network has wired and wireless connections too at 2.4GHz and 5GHz, in this case a special configuration is used where only one SSID (Wifi Name) is used, and the router figures out which band to put them on based on the performance. It is all automatic and works quite well. But I also use another feature built into routers and WiFi which you may not be aware of.
Access Control Lists
There used to be a view when all networks were wired before WiFi came on the scene that if your premises were secure then nobody could get on to your network without your knowledge. That was because you had to be physically in the building in order to plug a cable into the network.
When WiFi came along you no longer needed to be in the building to join the network, you just needed to be within range. I once sat outside a block of flats in my car waiting for someone, out of curiosity and because I was bored I got out my iPhone and looked around to see what WiFi networks were around. I found one very near, I could establish which router it was (Netgear), found the default user name and password, and managed to log in! This was only possible because the owner never read the instructions and changed the default password. But it demonstrates it can happen. From here I could have done all sorts of things, but obviously did not.
WiFi routers have something called ACL’s or Access Control Lists. These allow you to enter the MAC (Media Access Control) Address into the router for each WiFi device on your network. Each networking device has a MAC Address, this is a sequence of hexadecimal characters usually written like this: 08:0E:05:21:DF:41 the first three sets of characters can be used to identify the manufacturer of the controller chip used in the device. They are usually but not always hardwired into a device. They are generally unique too. As in most things there are exceptions to this rule.
You set up your WiFi router to allow specific networking devices to connect to your WiFi providing their MAC address is in the list. If it is not in the list it cannot connect to the network even if the WiFi password and SSID is known. So in other words, you control who can access your network and resources on your network. A third party knowing the WiFi network and the password cannot connect to your network. It reports the password is wrong, even though it is isn’t.
Returning to who is on my network
There are tools you can use to discover who or what is on your network. These tools are well known in the Linux world if you play with computers a lot or come from a networking background. There are some programs out there that you can use to scan your network and list what is in the network.
Checkout the following if you have an iPhone: https://techet.net/netanalyzer written by Jiri Techet. If you are curious about your network and its performance, this is an incredibly useful tool. Plus it is portable, you can test any network with it.
The way it works is you connect your iPhone to the network you wish to scan, then run it. It will go through all of the IP addresses on the network to see if there are devices present. IP addresses are generally set by the router, it allows data to be sent to and from devices on your network, these are the equivalent to a postal address for a house.
For the £3 the application cost, it is brilliant and shows a list of everything that is connected. In my case on my inner network before I turned on ACL I found 12 devices ranging from TV’s, internet radio, printer, Ikea lighting controller, iPad, iPhones and other devices. But, it only shows you the MAC address of each device, you need to find out what it is.
I quickly established what most of them were, but then was stuck on the last one. It was eventually resolved to a BT Set Top Box attached to a TV.
The important point being that I now know precisely what is connected to my inner network, where it is located, and what it is doing. I can now add all of those MAC addresses into an Access Control List, and only those devices can connect to my network.
Going Deeper
It is also possible on the App to check on which ports are open on each device. If you imagine a device on your network is like a house, and the network is like the street your house is on, the ports are like doors into and out of your device. These can give you a clue about what it is and what it is doing. It may indicate something is communicating with something outside of your network. If that is the case it is important to know what it is.
WiFi Performance Test
The application can also check the performance from the smart phone over WiFi to a server on the internet to check the data performance. So you can check if there are dead spots anywhere, or areas where there are reduced performance. At my location from most areas in the house I can achieve over 60Mb/s download and 16Mb/s upload, so the WiFi performance is as good as my broadband performance. I am using advanced routers to do this that use 802.11ac WiFi.
Paranoia Prevails
So is this additional security worth the effort? I think it is, it provides some control over what can get into the inner network.
Is it foolproof?
If you are really paranoid, then it is conceivable in theory that an external monitor can monitor the network, and will over time figure out the password, even using WPA2 there are WiFi password cracking programs out there. Just do a search on Kali and WiFi, and you will find one. So this means no WPA2 network is really totally secure. If you have access to the MAC address in a hacking device, you can pretend you are a device in the Access Control List, so it is possible to get through these measures if you really know what you are doing.
However hackers generally look for soft targets and will go for those that are easier. So all I have achieved is mine is quite a bit more difficult to get into. There are other layers of security which are used to access and protect resources on the network such as passwords and accounts. Other monitoring will also quickly figure out if a duplicate MAC address or IP address is in use, which will also flag up a problem to the user.
I have received this message, and several of you out there have received them too. It is a bit disconcerting when you see it because it appears it has been sent from your email address to your email address. The person sending it states they have hacked into your email account, which is what it looks like. – Chances are though it is not real. First take a look at an example ( note the highlighted parts):
Example Extortion Email
The format of the message is the same, I have seen it in multiple places over the past month. The message is often an image file embedded in the message, not editable text. The reason they do this is to get around spam filtering which would normally trap messages like this.
The first thing to note is it appears as though it was sent to and from the same mailbox. If that was your mailbox, it means someone has hacked into it? No, probably not. But I can understand why someone would be concerned about receiving a mail like this.
It is seeking payment in Bit Coins which I don’t think can be traced to people, unlike a bank payment or “normal financial transaction”. Which is probably why this scam is operating.
If you get one of these, don’t panic. It is most likely a spoofed message, meaning someone has manipulated the email headers to make it appear that they have sent the message from your email box. By checking the header of the email, it is possible to detect where the email really came from. If the sender address is not via your mail box, it did not come from your mailbox. On the examples I have taken apart they all come from compromised servers which have a newsletter function built into them. Someone has figured out how to use the bulk mailing feature in the newsletter function. So it is highly likely that hundreds of these spoofed messages go out each time. They have also never been the same server, and each server is in a different country. This one came from Argentina, but was initiated from the USA.
I have heard from many sources that there are some changes being planned from HSUK which may alter the branding for the corporate image and people are expressing concern about their websites. HSUK will expect websites to follow suit in a period yet to be defined. This may cover logos, colours, fonts, images as they re-launch their new image.
If you are wondering if you need a new website, you probably don’t. Depending on how Home-Start launch this, and the extent of the support they provide to those people that already have websites online, I would anticipate that they will release a branding guideline which will contain the relevant information.
Once I see one of these I will put some more detail on this site about the action I recommend you take to bring your site in alignment with the new guidelines and how I can help.
Websites, particularly the more recent Divi based sites use a lot of elements within them which can globally change colours, fonts, header images and layouts relatively easily. The ones I have created over the past two years are built that way, so it is easy for example to change the iconography of the brand, colours tag lines on all pages in a few minutes.
Changing images, will take a little longer. Bottom line is don’t panic. I am panicking for everyone 😉 so let’s not waste any more effort here than we need to.
I anticipate that it should be possible to change many elements of your current site to meet new branding guidelines relatively easily. There may however be a line we need to draw if the changes are too prescriptive. So I will seek a compromise that pays due respect to HSUK, and does not create a hole in your budget; which is better applied to the services you provide to your clients. Any branding change is a licence to spend money with no appreciable benefit to your bottom line in the short term. The need for a branding change is most likely at the UK level rather than the local offices. But you will all be expected to fall in line.
As I have supported at various times over 60 Home-Start organisations and some of you are on your third generation website, I do understand something about the organisation. If you would like to recommend that HSUK talks to me, I would be more than happy to do so. None of the approaches I have made in the past have yielded anything of value so far. So I suspect that they may be more inclined to listen to the Home-Start offices I support, in the knowledge that I for one am not in this for the money; just to help charitable institutions.
The last approach I made to HSUK which was to recommend a PAYG website at £10 per month for three years (dropping to £5/ month on the 37th month), no minimum contract, all at my risk to help people with no website to get started was dismissed by them in case we may be competing. So as far as I know it was never advertised.
There is so much we could achieve together. An opportunity lost regrettably so far.
I thought I would flag this again, as it has happened several times now. If you allow Microsoft Word to name a file based on the content of the document there is a small risk that it may have an apostrophe in the file name.
For example if I created a document and the first piece of text in it said “Fred’s Success Story” and then saved it (without giving the file a name), Microsoft would save the file based on the first few words in the document. It might save it as fred’s success story.docx for example. Ordinarily there is nothing wrong with this until you try to add it to a WordPress website by uploading it as either a PDF or MS Word document. The presence of the ‘ in between the d and s will throw an HTML error on upload.
No that was not a typo. There is a website that has access to data breach information. It is not clear whether it lists all data breaches in the public domain, or a select few of them. The website asks you to enter an email address into the site, it will check through the information it holds and will respond if a match is found.
I tried one of mine and it returned several results indicating that my email address and an associated password to access an online account is in public circulation. It also shows if your email address is in spam lists as well.
I have seen two sets of results on data breaches, one indicated your email address exists in a list somewhere that is in circulation, (typically a junk mailing list). You cannot do anything about this. The other case tells you the website and your email AND a password is in circulation. In the latter case you should be concerned about it if you were previously unaware.