There is actually a silver lining in the brouhaha over the hacking of Sony. Forget about the right to free speech. That is only pertinent in some countries. The fact that the backlash to the intended release of The Interview was so swift should make people realize that every organization is vulnerable to having their IT security systems compromised. This hacking wasn't done by some smartass kid or by someone who is bitter about not being gainfully employed or by someone who can prove that he can get into a system. This was a foreign government that authorized the hacking and, thus, already had in place people who were trained to infiltrate systems. If Korea can hack into one company, it can get into the financial exchanges and the U.S. government websites and databases. The implications are horrendous.
Recently, Richard Beales wrote about the idea of having cyberinsurance for banks. It's an interesting idea, and there are insurance companies that offer some form of it. Right now, I would imagine that it's still hard to figure out the cost of premiums. A few years ago I reported the cost of a security breach by account at a health care organization. It was about $350 per account. Assuming that number is still accurate, what would cost in premiums to a company such as JPMorganChase, which was already hacked>What's the premium to pay some $29 billion? What would be for the defense department? For Social Security?
http://dealbook.nytimes.com/2014/12/23/the-need-for-bank-cyberinsurance/?module=BlogPost-Title&version=Blog%20Main&contentCollection=Breakingviews&action=Click&pgtype=Blogs®ion=Body
There is another aspect to hacking for a company such as Sony. In addition to the usual security measures that every company has to take in order to protect HR and bank information, there is the constant battle to prevent people from distributing its content on the Internet. You may think that just because can't copy a DVD that it's not an issue, but it is. You see, content is shared for editing and approval and everyone who plays that content is vulnerable to having his or her computer or mobile device hacked. It's a managerial problem when content is leaked before a series' ending is shown on TV, and it's an insult to the unsung heroes who construct sets and design costumes. Piracy is not a victimless crime.
But back to insurance. Everyone complains about insurance companies, but they're not made up of greedy, evil people who just want to take your money and shell out nothing if there's a claim. I'm confident that as cyberinsurance becomes standard, companies will be able to reduce their premiums with the guidance of insurers. This would include upgrading firewalls and hiring people to do daily penetration testing. As for piracy of content, that's a matter, I think, of being able to trace paths and fingerprints.
Note: This image was taken from en.wikipedia.org.
Thursday, December 25, 2014
Monday, October 6, 2014
The Media and The Hackers
Today's edition of The New York Times featured a topic in its Room For Debate column that's near and dear to my heart: security breaches. The title was: "Keeping Credit Cards and Bank Account Data from Hackers." http://www.nytimes.com/roomfordebate/2014/10/04/keeping-credit-cards-and-bank-account-data-from-hackers?ref=opinion
While some made good points such as stressing the adoption of E.M.V. technology for credit cards, none of the four experts could even scratch the surface of how to do it. Even if you gave up your credit cards, as suggested by Jose Pagliery, and use one-time virtual numbers via smartphones, there are other areas for potential security breaches.
Take health care for example. Whether medical records are still on paper or electronic, hackers love them. They don't care if you have an infectious disease or a clean bill of health. They just want four pieces of vital information: your name, your address, your date of birth and your Social Security number. Bingo! They have what they need for identity theft (read: steal your money).
Another example is content. Piracy is a huge issue for the entertainment business. It's not just about preventing someone from posting a spoiler on Youtube. There are people who are trying to sell movies and shows overseas without paying for it. If you stole the hot dog vendor's food to sell to someone else, you've committed a crime. It's the same thing with content.
At the risk of sounding paranoid, there is always someone who wants something of yours for nothing. Who is watching out for hackers? Sadly, companies do not hire enough of people like me who are trained to detect intrusions and vulnerabilities. In the end, we are all at risk.
While some made good points such as stressing the adoption of E.M.V. technology for credit cards, none of the four experts could even scratch the surface of how to do it. Even if you gave up your credit cards, as suggested by Jose Pagliery, and use one-time virtual numbers via smartphones, there are other areas for potential security breaches.
Take health care for example. Whether medical records are still on paper or electronic, hackers love them. They don't care if you have an infectious disease or a clean bill of health. They just want four pieces of vital information: your name, your address, your date of birth and your Social Security number. Bingo! They have what they need for identity theft (read: steal your money).
Another example is content. Piracy is a huge issue for the entertainment business. It's not just about preventing someone from posting a spoiler on Youtube. There are people who are trying to sell movies and shows overseas without paying for it. If you stole the hot dog vendor's food to sell to someone else, you've committed a crime. It's the same thing with content.
At the risk of sounding paranoid, there is always someone who wants something of yours for nothing. Who is watching out for hackers? Sadly, companies do not hire enough of people like me who are trained to detect intrusions and vulnerabilities. In the end, we are all at risk.
Labels:
JPMorgan Chase,
The Home Depot,
The New York Times.
Thursday, July 10, 2014
China and The Hackers, Again
At this point, it almost sounds like the name of a rock band. China and The Hackers.
The news of the March hacking of the security at the Office of Personnel Management wasn't so bad because employee and contactors' personal data wasn't stolen is still disturbing. The point is that even though hackers are usually unsuccessful when trying to breach security in the public and private sectors, sometimes they are. It's irrelevant whether they are out to steal the data they need for identity theft, for blackmail or for government secrets. There should be accountability at multiple levels within an organization.
Everyone who knows me knows I am cheap. Not just frugal, but outright cheap. Just ask my wife every time I see a grocery bill. But I know we need food. And, guess what, folks? Computer systems need security. They need new firewalls. They need updated software to detect malware and to protect attacks. Above all, they need experienced, reliable people who can do penetration testing to check for vulnerabilities. The CIO needs to know not just how to hire IT security people, but how to fight for a bigger budget because, folks, the threats are nonstop. Nonstop.
About 15 years ago, my mother-in-law, now retired, used to work for a self-made multimillionaire whose son was allegedly part of a loose ring of people that was caught hacking into a large corporation. His son was a teenager who, by then, had some 10 years of computer experience. He was always bright and even early on, he would love to see what a computer could do besides load games. He knew he wanted to program his computer to turn on the lights in his room. When he was frustrated that his computer was too slow, "something happened" to it. It would fall down the stairs in school and break. One part of it would catch fire. Yeah, right, but his parents bought his lies hook, line and sinker and simply buy him a new one each time. Oh, and he had memorized his parents' credit card numbers so he would rack up unauthorized charges on their accounts. And at that time the term identity theft had not yet been in popular use.
Back to China and The Hackers. The hackers of the People's Liberation Army Unit 61398 the Shanghai-based Unit 61486 are not the only ones who are involved in cyber attacks. Hacking is not exclusive to China. Don't think for one nanosecond that there are hackers in other countries who are trying to break into U.S. government and corporate servers. They're after the military, education, banks, news, online gaming, dating, law enforcement and e-commerce. The world is crawling with hackers. Everyone needs to be concerned.
The news of the March hacking of the security at the Office of Personnel Management wasn't so bad because employee and contactors' personal data wasn't stolen is still disturbing. The point is that even though hackers are usually unsuccessful when trying to breach security in the public and private sectors, sometimes they are. It's irrelevant whether they are out to steal the data they need for identity theft, for blackmail or for government secrets. There should be accountability at multiple levels within an organization.
Everyone who knows me knows I am cheap. Not just frugal, but outright cheap. Just ask my wife every time I see a grocery bill. But I know we need food. And, guess what, folks? Computer systems need security. They need new firewalls. They need updated software to detect malware and to protect attacks. Above all, they need experienced, reliable people who can do penetration testing to check for vulnerabilities. The CIO needs to know not just how to hire IT security people, but how to fight for a bigger budget because, folks, the threats are nonstop. Nonstop.
About 15 years ago, my mother-in-law, now retired, used to work for a self-made multimillionaire whose son was allegedly part of a loose ring of people that was caught hacking into a large corporation. His son was a teenager who, by then, had some 10 years of computer experience. He was always bright and even early on, he would love to see what a computer could do besides load games. He knew he wanted to program his computer to turn on the lights in his room. When he was frustrated that his computer was too slow, "something happened" to it. It would fall down the stairs in school and break. One part of it would catch fire. Yeah, right, but his parents bought his lies hook, line and sinker and simply buy him a new one each time. Oh, and he had memorized his parents' credit card numbers so he would rack up unauthorized charges on their accounts. And at that time the term identity theft had not yet been in popular use.
Back to China and The Hackers. The hackers of the People's Liberation Army Unit 61398 the Shanghai-based Unit 61486 are not the only ones who are involved in cyber attacks. Hacking is not exclusive to China. Don't think for one nanosecond that there are hackers in other countries who are trying to break into U.S. government and corporate servers. They're after the military, education, banks, news, online gaming, dating, law enforcement and e-commerce. The world is crawling with hackers. Everyone needs to be concerned.
Tuesday, October 15, 2013
Portable, Personal ECGs and Security
Several months ago I heard the exciting news that a doctor invented an iPad app to replicate an electrocardiogram at a fraction of the cost of its being done in a doctor's office. I'm trying to understand why the use of this hasn't accelerated. Doctors' offices are often busy. Insurance companies are always trying to control costs. And, of course, this could help prevent heart attacks and strokes. So what gives?
I can't answer that part, but I can remind health care providers and insurance companies of one thing: security on mobile devices must not be overlooked. This app is an awesome idea. Someone holds the iPhone in his hands and it can replicate the measurements of an ECG and send it to the doctor. But that also means tracing the patient's name, address, date of birth and electronic medical records, which often have the Social Security number as well. No pun intended, but you don't want a patient to have a heart attack because he found out that his identity was stolen while doing an anywhere ECG via an app!

I can't answer that part, but I can remind health care providers and insurance companies of one thing: security on mobile devices must not be overlooked. This app is an awesome idea. Someone holds the iPhone in his hands and it can replicate the measurements of an ECG and send it to the doctor. But that also means tracing the patient's name, address, date of birth and electronic medical records, which often have the Social Security number as well. No pun intended, but you don't want a patient to have a heart attack because he found out that his identity was stolen while doing an anywhere ECG via an app!
Wednesday, October 9, 2013
Under the Radar: VA IT Department Furloughs
I am completely apolitical, so I have not done much hand wringing about the government shutdown. However, I just read that the furloughs at the Veterans Affairs Department means stopping software development.
That sounds sort of harmless, but what is under the radar here is that the processing of veterans' claims will be affected. And then what? The VA Office of Information and Technology sent 2,754 employees home. That's the size of an impressive corporation.
During the many years I've been working, I've experienced several layoffs. Once it was because the financial meltdown five years ago caused a company I worked for to lay off 20 percent of its personnel six months later. At other times, the contracts I had expired and the end client wanted someone cheaper. At many companies, the thinking is flawed. You need all hands on deck in certain departments. You need toll collectors, even though many drivers have transponders. It's like the Emergency Department of a hospital. You need doctors and nurses, a phlebotomist to draw blood, a technician to perform CT scans and MRIs, and a radiologist to read the results -- 24/7. Just because the CEO may not be prone to getting kidney stones doesn't mean that others may not suffer attacks and need medical care urgently.
Trying to save money by cutting personnel, either with furloughs or permanently, is a temporary stop gap measure. It's like taking out an uninfected appendix in order to lose a few ounces. The decision makers at the top need to see in the future and realize that there may be consequences down the road. You don't need a crystal ball for that. You can be sure that the VA is going to have a huge backlog because a few politicians can't decide on the budget.
That sounds sort of harmless, but what is under the radar here is that the processing of veterans' claims will be affected. And then what? The VA Office of Information and Technology sent 2,754 employees home. That's the size of an impressive corporation.
During the many years I've been working, I've experienced several layoffs. Once it was because the financial meltdown five years ago caused a company I worked for to lay off 20 percent of its personnel six months later. At other times, the contracts I had expired and the end client wanted someone cheaper. At many companies, the thinking is flawed. You need all hands on deck in certain departments. You need toll collectors, even though many drivers have transponders. It's like the Emergency Department of a hospital. You need doctors and nurses, a phlebotomist to draw blood, a technician to perform CT scans and MRIs, and a radiologist to read the results -- 24/7. Just because the CEO may not be prone to getting kidney stones doesn't mean that others may not suffer attacks and need medical care urgently.
Trying to save money by cutting personnel, either with furloughs or permanently, is a temporary stop gap measure. It's like taking out an uninfected appendix in order to lose a few ounces. The decision makers at the top need to see in the future and realize that there may be consequences down the road. You don't need a crystal ball for that. You can be sure that the VA is going to have a huge backlog because a few politicians can't decide on the budget.
Thursday, October 3, 2013
Hackers Like Creative Folk
Hey, you, on Photoshop! Yes, you. I know you bought Photoshop Elements to enhance photos of your kids. Or maybe you bought Adobe InDesign in order to create your own marketing materials. Or you want the full-blown version of Adobe Acrobat because the free reader isn't enough for your needs.
Better check your credit card statements. Brad Arkin, Adobe's chief security officer, admitted in a blog post that hackers removed company data. Adobe has been shifting to the business model of pay as you go. Instead of buying the software in disk form, customers will be forced into leasing it and constantly updating it.
My wife and I don't upgrade with every version of any software we use for personal use because the changes are usually minor and the cost is unnecessary. So when Adobe started this shift, my security antenna went up. We use one-time credit card numbers for our online purchases. If we had an open number on file, the hackers who tapped into Adobe would have our credit cards numbers, even though the data was encrypted. Adobe claims that they don't believe that any decrypted numbers were taken, but I wouldn't count on that. By the way, 2.9 million Adobe customers are at risk. The hackers have their credit or debit card numbers, expiration dates and even information pertaining to their orders.
And I hate to break it to you, but all your fancy artwork isn't nearly as creative as some hackers.
Better check your credit card statements. Brad Arkin, Adobe's chief security officer, admitted in a blog post that hackers removed company data. Adobe has been shifting to the business model of pay as you go. Instead of buying the software in disk form, customers will be forced into leasing it and constantly updating it.
My wife and I don't upgrade with every version of any software we use for personal use because the changes are usually minor and the cost is unnecessary. So when Adobe started this shift, my security antenna went up. We use one-time credit card numbers for our online purchases. If we had an open number on file, the hackers who tapped into Adobe would have our credit cards numbers, even though the data was encrypted. Adobe claims that they don't believe that any decrypted numbers were taken, but I wouldn't count on that. By the way, 2.9 million Adobe customers are at risk. The hackers have their credit or debit card numbers, expiration dates and even information pertaining to their orders.
And I hate to break it to you, but all your fancy artwork isn't nearly as creative as some hackers.
Wednesday, October 2, 2013
Use of Patient Portals Rises. So Do Security Risks.
A report from Frost and Sullivan called U.S. Patient Portal Market for Hospitals and Physicians: Overview and Outlook, 2012-2017 predicts that patient portal use will increase by 221.1 percent. (For those who like dollar signs, that's an expected growth to $898.4 million in 2017.)
I tend to request my medical records on CD, but my wife uses patient portals extensively. They're terrific. She prints out the vaccination records for the kids to give to the school nurses. She can verify the dosage of medication the kids may have if they get sick. She can check appointments.
So what's the problem? There isn't any as long as the system she uses is secure. Her physician's practice requires every patient to pay for their patient portal. (Mine doesn't, so it is not a requirement for patients to pay a fee for it.) He told her that the practice has to pay extra insurance costs to prevent hacking.
That's the concern I always have. The patient portal she uses does not have our home address or Social Security numbers, but just the name and date of birth are two critical pieces of information need for identity theft. The rest is not hard to find. My wife found her late father's Social Security number on a government website. Is it any wonder that identity theft is an ongoing concern?
www.healthcareIT.frost.com
I tend to request my medical records on CD, but my wife uses patient portals extensively. They're terrific. She prints out the vaccination records for the kids to give to the school nurses. She can verify the dosage of medication the kids may have if they get sick. She can check appointments.
So what's the problem? There isn't any as long as the system she uses is secure. Her physician's practice requires every patient to pay for their patient portal. (Mine doesn't, so it is not a requirement for patients to pay a fee for it.) He told her that the practice has to pay extra insurance costs to prevent hacking.
That's the concern I always have. The patient portal she uses does not have our home address or Social Security numbers, but just the name and date of birth are two critical pieces of information need for identity theft. The rest is not hard to find. My wife found her late father's Social Security number on a government website. Is it any wonder that identity theft is an ongoing concern?
www.healthcareIT.frost.com
Wednesday, September 25, 2013
This Is News?
EMC Voice just posted a report that experienced IT security people like me know: antivirus software is not enough to prevent advanced persistent threats.
“The attackers today are creating malware faster than the anti-malware software vendors can produce anti-malware definitions,” said Leonard Jacobs, president/CEO of security company Netsecuris Inc."
But, wait, there's more. Most of this pertains to antivirus software that every personal computer should have running consistently. This is just Mickey Mouse stuff compared to what can happen to corporate networks, especially when people aren't tethered to their desks. Give them a company mobile device such as a smartphone or tablet and the potential for hacking into accounts is exponentially larger. Not marginally. Exponentially.
Throughout my career, I have had several methods of preventing security breeches that go beyond installing sniffers for viruses, worms, Trojan horses and other malware. I've installed firewalls, IPS, IDS and SEIM products to guard against attacks.. I've done penetration testing on a regular basis for vulnerabilities and confirm that systems are up to date with the latest patches. I've put together plans for remediation procedures to resolve vulnerabilities. I've designed disaster recovery plans. Corporations cannot afford to be asleep at the wheel. Hackers need no sleep. They're built for destruction.
Read more at http://www.forbes.com/sites/emc/2013/09/23/why-antivirus-software-isnt-enough-to-fend-off-attacks/?utm_campaign=techtwittersf&utm_source=twitter&utm_medium=social
“The attackers today are creating malware faster than the anti-malware software vendors can produce anti-malware definitions,” said Leonard Jacobs, president/CEO of security company Netsecuris Inc."
But, wait, there's more. Most of this pertains to antivirus software that every personal computer should have running consistently. This is just Mickey Mouse stuff compared to what can happen to corporate networks, especially when people aren't tethered to their desks. Give them a company mobile device such as a smartphone or tablet and the potential for hacking into accounts is exponentially larger. Not marginally. Exponentially.
Throughout my career, I have had several methods of preventing security breeches that go beyond installing sniffers for viruses, worms, Trojan horses and other malware. I've installed firewalls, IPS, IDS and SEIM products to guard against attacks.. I've done penetration testing on a regular basis for vulnerabilities and confirm that systems are up to date with the latest patches. I've put together plans for remediation procedures to resolve vulnerabilities. I've designed disaster recovery plans. Corporations cannot afford to be asleep at the wheel. Hackers need no sleep. They're built for destruction.
Read more at http://www.forbes.com/sites/emc/2013/09/23/why-antivirus-software-isnt-enough-to-fend-off-attacks/?utm_campaign=techtwittersf&utm_source=twitter&utm_medium=social
Sunday, September 22, 2013
Weather Report
One of my earliest blog posts was called "Cloudy Skies." In it, I expressed my concern about security on the cloud. The cloud does, indeed, have its advantages. My wife and I back up our iPhones on the iCloud and we're happy that we will never have to enter our contacts into new phones. Small companies can save money by storing data on the cloud.
But there could be problems with large companies and governments when it comes to using the cloud. One of them is the fact that there is a limited number of massive scale cloud service providers including Microsoft, Amazon and Google. CFO.com reported that, "The barriers to entry are formidable; only the best-capitalized vendors need apply."
At the risk of sounding paranoid, hack one of these companies, and the implications are huge. All those credit card numbers on file at Amazon come to mind. Someone brought up the unlikely possibility that several could be breached at the same time. How much insurance for errors and omissions should these companies and their consultants be carrying?
It is virtually impossible to extrapolate the amount of damage that can occur. But here's another thing to think about when it comes to risk: problems in and tensions between India and Pakistan. India's promise as a super center isn't as bright. And if Pakistan were to strike India and data centers were casualties, it would be a catastrophe.
The bottom line is that IT security is more important than ever before. There is no room for gaps. Consultants are not as reliable as loyal employees.
But there could be problems with large companies and governments when it comes to using the cloud. One of them is the fact that there is a limited number of massive scale cloud service providers including Microsoft, Amazon and Google. CFO.com reported that, "The barriers to entry are formidable; only the best-capitalized vendors need apply."
At the risk of sounding paranoid, hack one of these companies, and the implications are huge. All those credit card numbers on file at Amazon come to mind. Someone brought up the unlikely possibility that several could be breached at the same time. How much insurance for errors and omissions should these companies and their consultants be carrying?
It is virtually impossible to extrapolate the amount of damage that can occur. But here's another thing to think about when it comes to risk: problems in and tensions between India and Pakistan. India's promise as a super center isn't as bright. And if Pakistan were to strike India and data centers were casualties, it would be a catastrophe.
The bottom line is that IT security is more important than ever before. There is no room for gaps. Consultants are not as reliable as loyal employees.
Friday, August 16, 2013
How One Contractor's Forgetfulness Affected People in 48 States
Patients in 48 states are vulnerable, not to disease, but to their information getting into the wrong hands. An article in The Tennessean newspaper reported that a medical transcription contractor left a firewall down between May 5 and June 24.
That's a long time for to discover this. M2ComSys of India was hired by Cogent Healthcare to transcribe the notes dictated by physicians. As part of the contract, it was supposed to store the patient information, which was supposedly protected, on a secure website, but the firewall was down. Who is responsible? It's not just the contractor, in my opinion, but Cogent is also at fault. This HIPAA breach is the second one for Cogent, and it's not something to be pooh-poohed. The data includes patients' names, birth dates, medical record numbers, medical history, diagnosis and treatment. Usually, medical records at practices include patients' addresses and Social Security numbers, as well, completing the information that hackers need to steal people's identity.
There was a case study done by HealthCareInfoSecurity, which outline efforts of CaroMont Health of North Carolina to track down all its contracts. That could be a few or it could be a lot of people. But here's the scary thing: experts in the security field say that there is an increase in the number of health data breaches and that are not accidental. Moreover, hospitals and practices don't take action until after a breach occurs.
Many contractors are required to take out Errors and Omissions insurance in case something happens on their tour of duty at a company that hires them as contract workers. But when it comes to identity theft, the error can't be remedied by an insurance payment. Identity theft is the only crime in which the victim has to prove that he or she did not commit the crime, e.g., buying thousands of dollars worth of jewelry or electronics on a credit card.
A poll by the Ponemon Institute reported that 94 percent of 80 participating health care organizations had at least one security breach in the past two years. Those breaches cost them a total of $6.78 billion annually. Collectively, those organizations could have paid for new firewalls, new penetration testing, oh, and enough staff, and still have a lot of money left over -- and no egg on their faces.
That's a long time for to discover this. M2ComSys of India was hired by Cogent Healthcare to transcribe the notes dictated by physicians. As part of the contract, it was supposed to store the patient information, which was supposedly protected, on a secure website, but the firewall was down. Who is responsible? It's not just the contractor, in my opinion, but Cogent is also at fault. This HIPAA breach is the second one for Cogent, and it's not something to be pooh-poohed. The data includes patients' names, birth dates, medical record numbers, medical history, diagnosis and treatment. Usually, medical records at practices include patients' addresses and Social Security numbers, as well, completing the information that hackers need to steal people's identity.
There was a case study done by HealthCareInfoSecurity, which outline efforts of CaroMont Health of North Carolina to track down all its contracts. That could be a few or it could be a lot of people. But here's the scary thing: experts in the security field say that there is an increase in the number of health data breaches and that are not accidental. Moreover, hospitals and practices don't take action until after a breach occurs.
Many contractors are required to take out Errors and Omissions insurance in case something happens on their tour of duty at a company that hires them as contract workers. But when it comes to identity theft, the error can't be remedied by an insurance payment. Identity theft is the only crime in which the victim has to prove that he or she did not commit the crime, e.g., buying thousands of dollars worth of jewelry or electronics on a credit card.
A poll by the Ponemon Institute reported that 94 percent of 80 participating health care organizations had at least one security breach in the past two years. Those breaches cost them a total of $6.78 billion annually. Collectively, those organizations could have paid for new firewalls, new penetration testing, oh, and enough staff, and still have a lot of money left over -- and no egg on their faces.
Monday, February 4, 2013
Super Redunancy
Apparently, Twitter is all aflutter with comments about how her hair dryer blew out the power during the Superbowl. (Actually, this happened when I was on my honeymoon and my wife blow dried her hair!)
But I digress. Several years ago I applied for a job with the National Basketball Association. It would have been a bear of a commute had I gotten a job offer. Nevertheless, I was very much interested in the job because it involved an aspect of redundancy I never thought of before: broadcasting. It's bad enough to have a lack of continuity during a game, but it could be an unmitigated disaster if it happens while trading.
So, redundancy is good. Super redundancy is even better.
Saturday, January 12, 2013
The Power of Networking
There is an article in The New York Times about five people who are past 50 and surviving the recession. I am one of those five people.
Here is the link:
http://www.nytimes.com/2013/01/13/business/how-5-older-workers-saw-a-chance-to-remake-their-careers.html?ref=business
This is not the first time I've been interviewed about employment. Several years ago a reporter from the Connecticut Jewish Ledger interviewed me when I was laid off from Gartner. Always networking, I mentioned my plight to my rabbi, who then sent out an email blast to the congregation to try to get some job leads.
I am still believe in networking. I have joined several networking groups and try to stay in touch with people when I can't go to those meetings for months at a time. Some people think that networking meetings are just pity parties or support groups. Sure, you go to them and realize that you are not alone and that there is nothing wrong with you. You did not lose your job because of a performance issue. You lost it because of budget cuts or takeovers or, often, bad management.
Here are some of the things I learned from networking:
1) You meet people who worked at a company where you wish to work. You can find out more about the corporate culture and maybe even get the contact manager of someone who is in a position to hire you.
2) Many networking groups have a session on elevator pitches. Most people feel uncomfortable doing them, but it's one of the skills you need to have.
3) When the facilitator left the group because he or she got a paying job, it's a good idea to volunteer to run a meeting or two. Most people shy away from this. It was one of the best things I ever did because it helped me improve my public speaking, presentation and leadership skills. Sure enough, the next time I had a group interview, I didn't feel intimidated.
4) Your network can't be too large. Invite everyone you meet to join your professional network on LinkedIn. I once heard that someone who applied for a job that required community outreach got the job over her competitors because she had a 180 people in her LinkedIn network. That number is low actually. It should definitely be 500 plus. But it's not just about collecting people. You can easily share job leads in your updates. When you get an interview with someone, you can often find his profile on LinkedIn. When you go into the interview, you don't go in "cold" because you have an idea about his background. If he went to an Ivy League college and you didn't, you know the chances are not in your favor. If he went to the same college your cousin did, you have an icebreaker.
5) You can find someone who can help you upgrade your skills, from Microsoft Office to using social media.
I used to go to a networking meeting where I would meet a man who was unemployed and convinced that no one would want to date him until he got a job. My advice to him was not to put his life on hold. Good things can happen. Not long after I was laid off from Gartner, I got married. The Times article has a picture of me with my younger son. Good things and bad things can happen. I just go with the flow.
How did I get to be interviewed for the article in The New York Times? Networking. Caitlin Kelly, who is in wife's LinkedIn network, sent out a request for leads on people who are over 50 and surviving the recession. My wife responded and told the reporter about me.
Want more ideas about networking? Read Harvey Mackay's book, Dig Your Well Before You're Thirsty.
Here is the link:
http://www.nytimes.com/2013/01/13/business/how-5-older-workers-saw-a-chance-to-remake-their-careers.html?ref=business
This is not the first time I've been interviewed about employment. Several years ago a reporter from the Connecticut Jewish Ledger interviewed me when I was laid off from Gartner. Always networking, I mentioned my plight to my rabbi, who then sent out an email blast to the congregation to try to get some job leads.
I am still believe in networking. I have joined several networking groups and try to stay in touch with people when I can't go to those meetings for months at a time. Some people think that networking meetings are just pity parties or support groups. Sure, you go to them and realize that you are not alone and that there is nothing wrong with you. You did not lose your job because of a performance issue. You lost it because of budget cuts or takeovers or, often, bad management.
Here are some of the things I learned from networking:
1) You meet people who worked at a company where you wish to work. You can find out more about the corporate culture and maybe even get the contact manager of someone who is in a position to hire you.
2) Many networking groups have a session on elevator pitches. Most people feel uncomfortable doing them, but it's one of the skills you need to have.
3) When the facilitator left the group because he or she got a paying job, it's a good idea to volunteer to run a meeting or two. Most people shy away from this. It was one of the best things I ever did because it helped me improve my public speaking, presentation and leadership skills. Sure enough, the next time I had a group interview, I didn't feel intimidated.
4) Your network can't be too large. Invite everyone you meet to join your professional network on LinkedIn. I once heard that someone who applied for a job that required community outreach got the job over her competitors because she had a 180 people in her LinkedIn network. That number is low actually. It should definitely be 500 plus. But it's not just about collecting people. You can easily share job leads in your updates. When you get an interview with someone, you can often find his profile on LinkedIn. When you go into the interview, you don't go in "cold" because you have an idea about his background. If he went to an Ivy League college and you didn't, you know the chances are not in your favor. If he went to the same college your cousin did, you have an icebreaker.
5) You can find someone who can help you upgrade your skills, from Microsoft Office to using social media.
I used to go to a networking meeting where I would meet a man who was unemployed and convinced that no one would want to date him until he got a job. My advice to him was not to put his life on hold. Good things can happen. Not long after I was laid off from Gartner, I got married. The Times article has a picture of me with my younger son. Good things and bad things can happen. I just go with the flow.
How did I get to be interviewed for the article in The New York Times? Networking. Caitlin Kelly, who is in wife's LinkedIn network, sent out a request for leads on people who are over 50 and surviving the recession. My wife responded and told the reporter about me.
Want more ideas about networking? Read Harvey Mackay's book, Dig Your Well Before You're Thirsty.
Tuesday, November 13, 2012
An Invitation to Hack
Sometimes you just wonder about the decision making process. The SEC told the New York Stock Exchange that computers which have sensitive information about its Trading and Markets Division were left open to cyber attacks. It gets worse. The people who have those computers brought them unprotected to a Black Hat conference, a convention that computer hacking experts love to attend to learn about the latest trends.
What an invitation to hack! The SEC claims there is no evidence that data was compromised, but we've heard that before, usually followed by a company's promising free credit monitoring for a year to its customers. Just to be sure, the SEC spent at least $200K and hired a third-party firm to conduct an exhaustive analysis to determine if any data was indeed compromised.
What I can't wrap my head around is that this is government. There are policies. Or so there should be. People who work on laptops in the office tend to take them home because they don't want to incur the costs of buying their own. But. It's. Not. Their. Personal. Property. Also, the SEC isn't sure why their staffers brought their computers to the convention. My guess? WiFi. They wanted to check their personal email and Facebook.
It's a tough call, but someone in every organization has to set up rules, and employees should use their judgment. Even though it's a nuisance, I carry two smartphones and my personal iPad with me. I do not want my personal email on my company devices. For me, it's about separation of church and state. But enough about me. I don't want to be called into a group meeting and be told to be careful. Put it in an employee handbook in the first place. No company laptops or tablets may be removed from the premises without prior authorization. No unprotected devices may leave the building. Ever. How difficult is that?
What an invitation to hack! The SEC claims there is no evidence that data was compromised, but we've heard that before, usually followed by a company's promising free credit monitoring for a year to its customers. Just to be sure, the SEC spent at least $200K and hired a third-party firm to conduct an exhaustive analysis to determine if any data was indeed compromised.
What I can't wrap my head around is that this is government. There are policies. Or so there should be. People who work on laptops in the office tend to take them home because they don't want to incur the costs of buying their own. But. It's. Not. Their. Personal. Property. Also, the SEC isn't sure why their staffers brought their computers to the convention. My guess? WiFi. They wanted to check their personal email and Facebook.
It's a tough call, but someone in every organization has to set up rules, and employees should use their judgment. Even though it's a nuisance, I carry two smartphones and my personal iPad with me. I do not want my personal email on my company devices. For me, it's about separation of church and state. But enough about me. I don't want to be called into a group meeting and be told to be careful. Put it in an employee handbook in the first place. No company laptops or tablets may be removed from the premises without prior authorization. No unprotected devices may leave the building. Ever. How difficult is that?
Wednesday, October 24, 2012
A Book, A Nook and A Crook
Pity Barnes and Noble. While Borders was going belly-up and Amazon released the Kindle Fire, Barnes and Nobel started to look for a buyer for itself and took its eyes off security. It doesn't take long for bad things to happen. Recently the bookseller admitted that hackers hit 63 of its stores in nine states, including at least nine stores in the New York area.
Barnes and Noble first learned of the attack in mid-September and happily complied with the Justice Department's request not to disclose the problem yet, but wait until December 24 to tell its customers so that the FBI can conduct an investigation.
That would have been one nasty Christmas present. Barnes and Noble explained that the hackers "planted bugs in tampered PIN pad devices" and when credit cards were swiped for payment, so were credit card and pin numbers.
Flashback to 30 years ago when capsules of Extra-Strength Tylenol were tampered with and laced with cyanide. In theory, McNeil Consumer Products, the subsidiary of Johnson and Johnson, was not responsible for the tampering. The product left their distribution centers and they had no control once the product was placed on the shelves. But the company immediately pulled the product, halted advertising and changed their packaging to regain customers' trust.
Note to Barnes and Noble's CEO: Take a page from that playbook. When a crisis happens, manage it and fix it. Don't hide it.
Every individual who has a credit card, should spend time looking online at the account activity. Most major credit cards now post pending transactions in real time. I get notices when my card is being used. I even spooked my wife by calling her and asking what she just bought at a particular store.
One more thing, Barnes and Noble. Don't skimp on security. It doesn't make you look good.
Barnes and Noble first learned of the attack in mid-September and happily complied with the Justice Department's request not to disclose the problem yet, but wait until December 24 to tell its customers so that the FBI can conduct an investigation.
That would have been one nasty Christmas present. Barnes and Noble explained that the hackers "planted bugs in tampered PIN pad devices" and when credit cards were swiped for payment, so were credit card and pin numbers.
Flashback to 30 years ago when capsules of Extra-Strength Tylenol were tampered with and laced with cyanide. In theory, McNeil Consumer Products, the subsidiary of Johnson and Johnson, was not responsible for the tampering. The product left their distribution centers and they had no control once the product was placed on the shelves. But the company immediately pulled the product, halted advertising and changed their packaging to regain customers' trust.
Note to Barnes and Noble's CEO: Take a page from that playbook. When a crisis happens, manage it and fix it. Don't hide it.
Every individual who has a credit card, should spend time looking online at the account activity. Most major credit cards now post pending transactions in real time. I get notices when my card is being used. I even spooked my wife by calling her and asking what she just bought at a particular store.
One more thing, Barnes and Noble. Don't skimp on security. It doesn't make you look good.
Get ready for Halloween: Scareware, Scams and other Nasty Tricks!
Top 4 Scary Internet Threats Users NEED to Know
Guest Blog Post by Nick Nascimento

Amid a season of Halloween horrors, the scariest thing most of us will contend with are the litany of Internet threats that can readily crash our computer system and wreak havoc on our personal and business lives.
To compute with confidence this season, heed this hit list of "scareware"-the 4 creepiest threats Internet surfers should be aware of right now:
1. The FBI MoneyPak Trojan. This is in a class called "ransomware." which are Trojans or Virus' that force you to PAY for them to "remove it " and of course after you pay they never do, If while surfing the Internet your computer screen is filled with a FBI warning page that claims you have to pay the $100 fine, you're infected! Most of the time, ransomware locks up the user's desktop, disables task manager and other system utilities to avoid the termination of the process by the user as well. However, FBI MoneyPak ransomware takes it to the entirely new level by adding a little video recording square in the top right corner of the fake FBI warning page. It supposed to be your built-in web camera. Curiously, this little square shows up even if your laptop doesn't have a built-in camera.
FBI MoneyPak is a very convincing looking scam. It has the official FBI logo at the top and lists victim's IP address, location, and the name of their ISP. The fake warning claims that your PC has been locked by FBI because you downloaded or distributed copyrighted material or viewed child pornography. Creepy, isn't it? And, it asserts that if you don't pay the fine you will go to jail. Simply visiting an infected web site is enough to trigger this exploit kit which will download a malicious DLL file onto your computer. This is an Advanced level Bug to deal with so if you are not familiar with more advanced parts of your computers operating system such as editing the registry etc. it's advisable to consult a professional Removal Specialist.
2) Malicious 'eventvwr' SCAM from Offshore Call Centers. This second troublemaker doesn't START with your computer but it very well ends there. This scam can be especially dangerous for unsuspecting, less computer-savvy target victims. The scam goes like this: You get a call from a guy with a generic name such as "Adam Smith" who explains to you that he's a registered Microsoft technician and received a call alerting him that your IP address is the source for serious attacks on their servers due to multiple computer virus infections on your end. If you ask for any information on the source or target IP addresses involved, the person will attempt to deflect the question, and inform you that he/she is unauthorized to provide you that information!
They will proceed to try convincing you that your computer is full of viruses (based on some standard status and error messages automatically generated by your computer), and they try to get you to grant them complete access to your entire computer, including passwords, credit cards, and other sensitive information, via the free "Ammyy Admin" remote desktop control software. If you don't agree to buy their useless, thieving "support services", they'll use the computer access you openly granted them to damage your computer and randomly delete files.
3) Fake Virus Alerts / Scareware. One of the most virulent is known as "MSREMOVAL TOOL".?It is just ONE of the Fake Virus removal programs that install themselves onto your PC and request Money to make them work.?THEY WILL NOT WORK AND IF YOU PAY THEM THEY WILL NOW HAVE YOUR CREDIT CARD INFORMATION. Here are the two most common ways they are distributed:
(a) Via Infected IMAGES you may view Via Search engines!
(b) Via Pop - UNDERS (pop-ups that hide behind the page you are viewing.) When you see that FLASH be sure to LOOK QUICKLY. You just may see a very small window that is downloading the Malware CLOSE IT!! If it completes its task it will then launch that warning window. That is the other way they are delivering this malware.
4) FakeInst SMS Trojan and its variants. Now we turn to the most overlooked segment for attacks: mobile users. Mobile users are MUCH easier to attack, not just because of their cell phone vulnerabilities but the fact that people do not even THINK about their phones as the Small Computers they are.
"FakeInst disguises itself as popular apps like Instagram, Opera Browser, and Skype, and sends SMS messages to premium-rate numbers. There are more than a dozen variants of this bug and growing. There are well-known companies that produce security software for mobile phones and many of them have FREE versions that can and do help keep you safe from these types of attacks. Remember, by simply getting your apps from the OFFICIAL app sources, either your phone's app store or the app developer's own site, you can virtually eliminate this type of threat all together.
"Computer users need not despair," Nick notes. "Sometimes we do win the fight as was the case when a Federal court imposed a $163 million judgment on a woman who the FTC says helped run a scareware ring that tricked more than one million consumers across six countries into purchasing fake security software. But it's imperative to be vigilant and 'in the know' as dangers definitely lurk."
Nick Nascimento is Chief Executive Geek at aGeek2Go LLC Computer Repair, San Diego's most trusted provider of IT Services & Support as well as computer repair for home and business users both on-site and remote. He may be reached online at www.ageek2go.com.
Guest Blog Post by Nick Nascimento

Amid a season of Halloween horrors, the scariest thing most of us will contend with are the litany of Internet threats that can readily crash our computer system and wreak havoc on our personal and business lives.
To compute with confidence this season, heed this hit list of "scareware"-the 4 creepiest threats Internet surfers should be aware of right now:
1. The FBI MoneyPak Trojan. This is in a class called "ransomware." which are Trojans or Virus' that force you to PAY for them to "remove it " and of course after you pay they never do, If while surfing the Internet your computer screen is filled with a FBI warning page that claims you have to pay the $100 fine, you're infected! Most of the time, ransomware locks up the user's desktop, disables task manager and other system utilities to avoid the termination of the process by the user as well. However, FBI MoneyPak ransomware takes it to the entirely new level by adding a little video recording square in the top right corner of the fake FBI warning page. It supposed to be your built-in web camera. Curiously, this little square shows up even if your laptop doesn't have a built-in camera.
FBI MoneyPak is a very convincing looking scam. It has the official FBI logo at the top and lists victim's IP address, location, and the name of their ISP. The fake warning claims that your PC has been locked by FBI because you downloaded or distributed copyrighted material or viewed child pornography. Creepy, isn't it? And, it asserts that if you don't pay the fine you will go to jail. Simply visiting an infected web site is enough to trigger this exploit kit which will download a malicious DLL file onto your computer. This is an Advanced level Bug to deal with so if you are not familiar with more advanced parts of your computers operating system such as editing the registry etc. it's advisable to consult a professional Removal Specialist.
2) Malicious 'eventvwr' SCAM from Offshore Call Centers. This second troublemaker doesn't START with your computer but it very well ends there. This scam can be especially dangerous for unsuspecting, less computer-savvy target victims. The scam goes like this: You get a call from a guy with a generic name such as "Adam Smith" who explains to you that he's a registered Microsoft technician and received a call alerting him that your IP address is the source for serious attacks on their servers due to multiple computer virus infections on your end. If you ask for any information on the source or target IP addresses involved, the person will attempt to deflect the question, and inform you that he/she is unauthorized to provide you that information!
They will proceed to try convincing you that your computer is full of viruses (based on some standard status and error messages automatically generated by your computer), and they try to get you to grant them complete access to your entire computer, including passwords, credit cards, and other sensitive information, via the free "Ammyy Admin" remote desktop control software. If you don't agree to buy their useless, thieving "support services", they'll use the computer access you openly granted them to damage your computer and randomly delete files.
3) Fake Virus Alerts / Scareware. One of the most virulent is known as "MSREMOVAL TOOL".?It is just ONE of the Fake Virus removal programs that install themselves onto your PC and request Money to make them work.?THEY WILL NOT WORK AND IF YOU PAY THEM THEY WILL NOW HAVE YOUR CREDIT CARD INFORMATION. Here are the two most common ways they are distributed:
(a) Via Infected IMAGES you may view Via Search engines!
(b) Via Pop - UNDERS (pop-ups that hide behind the page you are viewing.) When you see that FLASH be sure to LOOK QUICKLY. You just may see a very small window that is downloading the Malware CLOSE IT!! If it completes its task it will then launch that warning window. That is the other way they are delivering this malware.
4) FakeInst SMS Trojan and its variants. Now we turn to the most overlooked segment for attacks: mobile users. Mobile users are MUCH easier to attack, not just because of their cell phone vulnerabilities but the fact that people do not even THINK about their phones as the Small Computers they are.
"FakeInst disguises itself as popular apps like Instagram, Opera Browser, and Skype, and sends SMS messages to premium-rate numbers. There are more than a dozen variants of this bug and growing. There are well-known companies that produce security software for mobile phones and many of them have FREE versions that can and do help keep you safe from these types of attacks. Remember, by simply getting your apps from the OFFICIAL app sources, either your phone's app store or the app developer's own site, you can virtually eliminate this type of threat all together.
"Computer users need not despair," Nick notes. "Sometimes we do win the fight as was the case when a Federal court imposed a $163 million judgment on a woman who the FTC says helped run a scareware ring that tricked more than one million consumers across six countries into purchasing fake security software. But it's imperative to be vigilant and 'in the know' as dangers definitely lurk."
Nick Nascimento is Chief Executive Geek at aGeek2Go LLC Computer Repair, San Diego's most trusted provider of IT Services & Support as well as computer repair for home and business users both on-site and remote. He may be reached online at www.ageek2go.com.
Sunday, October 21, 2012
Standardize That!
Recently I bought an iPad and I must admit that I love it. My Crackberry contract has been up for several months, but I wanted to wait until the new iPhone came out. Still, I've been postponing it because of the cost.
The demand for iPhones continues to be strong and, surprisingly, many businesses are giving into the demands of employees who prefer them to BlackBerry devices. The iPhones are much cooler than any other smartphone, and that's why, I think, most people want them. Really want them. To the point where they will shell out their own money for both the phone and the plan if their employers won't supply them with them and they'll carry the company-issued phone as well.
But I'm digressing. The real issue is that no matter who provides the phone, security is key. Ditto for the iPad. Recently I spoke to someone at a financial firm who said his sales staff members are using the iPad for everything and they need to address this potential problem.
The real problem is that there are no standards for security on mobile devices because there are multiple plan providers. It seems to me that wireless companies spend more time figuring out how they can get more and more in revenues than how to protect their clients' data when they shop online via smartphones. I hope that the company that never stops working for you is working on security.
The demand for iPhones continues to be strong and, surprisingly, many businesses are giving into the demands of employees who prefer them to BlackBerry devices. The iPhones are much cooler than any other smartphone, and that's why, I think, most people want them. Really want them. To the point where they will shell out their own money for both the phone and the plan if their employers won't supply them with them and they'll carry the company-issued phone as well.
But I'm digressing. The real issue is that no matter who provides the phone, security is key. Ditto for the iPad. Recently I spoke to someone at a financial firm who said his sales staff members are using the iPad for everything and they need to address this potential problem.
The real problem is that there are no standards for security on mobile devices because there are multiple plan providers. It seems to me that wireless companies spend more time figuring out how they can get more and more in revenues than how to protect their clients' data when they shop online via smartphones. I hope that the company that never stops working for you is working on security.
Harry Potter and Healthcare IT
I just came across the best reason for doctors to embrace electronic medical records.
Farzad Mostashari, M.D., reminded members of the College of Healthcare Information Management Executives (CHIME) that a paper file is worthless. "You can't use it for anything. You can't move it, you can't learn from it." The data lover reportedly said that paper is great if you’re Harry Potter.
Vendors like standardization, he told CHIME. Patients do, too. Whenever my family needs medical care, we ask for the records. My sons' pediatricians use Webview, a program that healthcare providers and patients can access from any computer. It's terrific. We may forget the dosage of ibuprofen that the doctor recommended, but we can easily access it, even if we're traveling.
Recently, we met a seasoned doctor who said that as of February, he will have to reduce the number of patients he'll be seeing. Why? Because the hospital he's affiliated with is going to be using EPIC. It's going to be a long learning curve because he is not computer-literate, he admitted, but in the long run it will be worth it.
Farzad Mostashari, M.D., reminded members of the College of Healthcare Information Management Executives (CHIME) that a paper file is worthless. "You can't use it for anything. You can't move it, you can't learn from it." The data lover reportedly said that paper is great if you’re Harry Potter.
Vendors like standardization, he told CHIME. Patients do, too. Whenever my family needs medical care, we ask for the records. My sons' pediatricians use Webview, a program that healthcare providers and patients can access from any computer. It's terrific. We may forget the dosage of ibuprofen that the doctor recommended, but we can easily access it, even if we're traveling.
Recently, we met a seasoned doctor who said that as of February, he will have to reduce the number of patients he'll be seeing. Why? Because the hospital he's affiliated with is going to be using EPIC. It's going to be a long learning curve because he is not computer-literate, he admitted, but in the long run it will be worth it.
Snopes Is Not Enough
Every once in a while, I get a well-meaning email from a relative or friend to warn me about a new virus that comes with an email with the subject line of XYZ or whatever. Some of the emails come with the promise that the person who sent it checked it out on Snopes, so “it’s real.” I ignore those because invariably I get an email later saying that it’s a hoax.
That particular virus may be a hoax, but the fact is that email-based attacks still keep happening. A recent report by FireEye Malware Intelligence Labs claims that in the first half of this year, computer infections have nearly quadrupled in volume in comparison to last year. These viruses have circumvented traditional security measures. Additionally, the rate of successful email based-threats have increased by 56 percent.
This is in addition to hacking and phishing!
What makes the security situation more disturbing is a 2011 survey of by the Homeland Security Department’s National Cyber Security Division reported that among 162 state, territorial and city governments found a low awareness of the full risks. This is despite the fact that the majority have adopted controls. The report was obtained by FierceGovernment IT through FOIA (Freedom of Information Act).
I realize that since the financial meltdown, municipalities have had less revenue and corporations have been reluctant to invest in newer security measures and qualified people. But that’s like not carrying insurance and running the risk of damage to your home or getting sick and possibly losing your assets. There needs to be a concerted effort to prioritize where money is most needed. There is no silver bullet to balancing the budget. Just like with your personal budget, you have to give up something in order to ensure safety.
That particular virus may be a hoax, but the fact is that email-based attacks still keep happening. A recent report by FireEye Malware Intelligence Labs claims that in the first half of this year, computer infections have nearly quadrupled in volume in comparison to last year. These viruses have circumvented traditional security measures. Additionally, the rate of successful email based-threats have increased by 56 percent.
This is in addition to hacking and phishing!
What makes the security situation more disturbing is a 2011 survey of by the Homeland Security Department’s National Cyber Security Division reported that among 162 state, territorial and city governments found a low awareness of the full risks. This is despite the fact that the majority have adopted controls. The report was obtained by FierceGovernment IT through FOIA (Freedom of Information Act).
I realize that since the financial meltdown, municipalities have had less revenue and corporations have been reluctant to invest in newer security measures and qualified people. But that’s like not carrying insurance and running the risk of damage to your home or getting sick and possibly losing your assets. There needs to be a concerted effort to prioritize where money is most needed. There is no silver bullet to balancing the budget. Just like with your personal budget, you have to give up something in order to ensure safety.
Wednesday, October 10, 2012
Forget the Publicity
My wife writes both advertorial and editorial articles. Although the former is her main course, even she won't get lured into believing things from self-promoters and popular resources (e.g., consumer magazines). If you read women's magazines, the hottest web sites for shopping are fashion sites such as Blufly and Zappos. Reality: the 25 fastest growing mobile commerce sites* in the West are 16 retail business, 3 travel, 3 hotel and 3 ticketing. Retail sites that have grown 200 percent or more include the British retailer, Marks & Spencer, Netshoes and the University of South Carolina's Gamecocks football team's GarnetandBlackTraditions.com. Stubhub and Fandago take it for ticketing. Orbitz is still doing well and Hilton and Best Western are popular for hotels. Fab.com grew 567 percent from a single app!
Three things to think about: Security, security and security. Mobile commerce is not going away anytime in the foreseeable future. If an app is worth creating, there better be security to go along with it.
*Source: The Mobile 400 Guide from Internet Retailer
Three things to think about: Security, security and security. Mobile commerce is not going away anytime in the foreseeable future. If an app is worth creating, there better be security to go along with it.
*Source: The Mobile 400 Guide from Internet Retailer
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Subscribe to:
Posts (Atom)


