Monday, October 18, 2010
Identity Theft Protection Week
No reputable business wants to let that happen, but it does occur because the powers might be so determined to keep costs down that mid-level decision-makers choose not to upgrade their security. In the medical community, it's worse. Hospitals are usually non-profit entities, but they run on thin margins even if they are, for all practical purposes, making money. Most private practices don't make huge profits because they have at least one receptionist, one nurse, one medical secretary and one billing clerk. There is no consensus on Electronic Medical Records -- say, the Microsoft Office equivalent that's the standard in the industry. Even though the system for EMR is about $10-12K, many doctors are reluctant to put the money into it, especially if they are going to have to change in a few years.
Note to anyone who does get electronic records: When asking for medical information by e-mail, make sure it is encrypted. Standard e-mail is not protected by PHI (Personal Health Information) compliance standards. Chances are, those e-mails won't contain items that the identity theft perp wants, but there is no reason why anyone other than immediate family or health providers should have information about your personal health.
Thursday, October 7, 2010
Mergers and VDR
1) Different companies probably have different levels of security. Staff members of both IT departments should compare every level of security. For example, it's a well-known fact that banks own shares in each other, as do insurance companies. Let's say that a regional bank merges into another regional bank. The bank with the more advanced IT security may or may not be the one that swallowed the other one. If its IT security is vulnerable, there could be a major problem because often computer systems are changed.
2) Software requires licenses. In an effort to save additional costs, the dominant company may not want to spend money upgrading security or buying additional licenses for software.
3) No one really knows what's going to happen once Obamacare takes effect. The president has talked about having all medical records go digital, but the truth is that hospital computer systems are often incompatible with each other. In addition, many doctors are reluctant to go digital because of the cost and the fact that there is no standard, like Microsoft Office for administrative office work.
Most lawyers use MS, but there are some that still use WordPerfect. If two lawyers can't send each other documents that are readable by their systems, imagine what it would it be like if two financial or insurance firms merged and their security was incompatible. It's an invitation to a security disaster.
Right now I'm doing some research on ShareVault, a leader in Virtual Data Room products. Supposedly, the company has the experience of handling billions of dollars in transactions. If anyone has experience in it, please contact me and let me know your thoughts.
Sunday, October 3, 2010
Stop, Thief!
I just came across this frightening and interesting statistic: online fraud more than doubled to $559.7 million in 2009, up from $255 million stolen in 2008.
This should come as no surprise. Online purchases are a way of life. Just try buying some ordinary things, such as tires or wedding gifts at stores. Hardly anyone keeps inventory at each store, so you have to pay for things in advance and, preferably online. Moreover, as apps have become more popular, guess what? If they're not free, you need to pay for them by credit card.
In theory, it is very easy to detect fraud and to prevent future fraud with a sound strategy. But that costs money and most companies are not willing to part with it if it doesn't bring in immediate revenues. If you are a small business owner, you may not have much budget to combat fraud through the use of intrusion detection systems, but here are things you can do:
- Look for unusual account activity.
- Call customers to notify them if you suspect there is a problem. Give them the option of verifying their account activity before they receive nasty surprises on their statement. It will save you a lot of angry calls later.
- Arrange to have all revenues go in a deposit only account. You would be surprised that company employees innocently give away wiring instructions which have bank routing numbers and your company's account number to anyone who calls. It is easy for a thief to take money out once he or she has your company's account number.
You need to take this evolving security threat seriously or everything you worked hard to achieve will vanish.
Tuesday, September 28, 2010
Virus Alert - For Real
But something really is going around. Three different people I know were affected by a virus that cracked their free e-mail account and then sent out e-mails with their address books with a link to a website. Social media sites, such as twitter.com, have also been affected by this virus. The link contains a virus that reads both Outlook and proprietary address books (such as that of AOL) and send out e-mails.
How do you prevent it? Use a complex password and change it often. When you create or change your password, use upper case and lower case letters as well as numbers and punctuation, such as underscores or dots). Another good idea is to create an e-mail address on a free e-mail service and use this e-mail for all your junk e-mails. Finally, keep your spam filter on high. Somehow, e-mails from disreputable people and companies will get through, but it's one of the best measures you can take.
Speaking of hacking, some high profile hospitals in New York City admitted that patient data was compromised. Somehow it got on an open server. Hospital officials claim that no information was used inappropriately, but that remains to be seen. The real danger is not that someone is going to sell information about a celebrity's health problems to the National Enquirer, but that patients are at risk of identity theft. All a perpetrator needs is a name, address, social security number and date of birth. For a while it was available on an open server at large hospitals in one of the biggest cities in the nation. This is why they need to hire experienced security analysts and keep up to date on security software.
Imagine if there were a virus that sucked out a hospital's patient database. If that hospital were in a large city where people go to for the top specialized care, identity theft would be made easier and more widespread than ever. If you can, give only the last two or four digits of your Social Security number when asked for it by a doctor's office or medical institution. Don't make it easier for local amateurs to steal your identity. You don't know how safe your doctor's computer system really is.
Wednesday, September 22, 2010
Google's Breach of Trust
In my experience as a consultant between full-time employment, I can see where there are gaps. Someone accepts an assignment for three months or six months, or even two years. If the pay isn't worth his while, he is going to keep one foot on the gas pedal, ready to take off as soon as a better offer comes in. If a company relies on consultants, the hiring managers must know that there is not going to be any loyalty on the part of the contract worker. Why would there be? What Samuel Goldwyn said about a contract not being worth the paper it's printed on was a laughable remark some 70 years ago. It turns out Goldwyn was a prophet. I had a one-year contract become worthless after nine months. I wasn't singled out. At various networking meetings, I met four other victims of the same company with the same contract. And, no, we were not spying on minors or tapping into call logs. We were putting out fires.
Cloud computing isn't going away. Companies that are thinking about using it are going to have to take security measures very, very seriously. What Google's David Barksdale did was unpleasant and immoral, but it's nothing compared to what can and does happen.
For the past several years, I've worked to prevent identity thefts. In order to prevent people from hacking into bank accounts and medical records so that they can get another person's name, address and social security, I've installed and tested various intrusion detection systems. Sometimes a company doesn't want to spend the money on upgrades, but here's what happens. Suddenly there's an announcement that ABC Financial Corporation or XZY Bank is offering free credit monitoring to its customers "because its data may have been compromised." Now you know what you mean by compromise. And that credit monitoring is only free for customers, not for the corporation. Where's the savings? it's certainly not financial. And the company's reputation among its customers has also been compromised. There's no free monitoring for that.
http://www.readwriteweb.com/cloud/2010/09/googles-internal-security-brea.php
Tuesday, July 20, 2010
Redundancy is Welcome, Indeed
I designed, installed and implemented Avon's website (not the graphics) for e-commerce. Later, at Gartner, I designed the redundancy network infrastructure for e-commerce websites so that the sites can function in the event that one site is down. Almost everyone who does online banking has experienced the frustration of trying to check balances, pay bills or schedule transfers at 8:30 p.m., only to get a message that the site is down. At 3:00 a.m., it's understandable, even though many on the West Coast may still be up. Chances are, that bank has a redundancy program that is simply inadequate. The customer won't lose money because the site is down, but the bank may lose customers if it develops a reputation for failure when the end-user needs it at a reasonable time.
Here's the bottom line: get your redundancy infrastructure so that's it's available when customers need it, whether it's 9:00 a.m. in the morning or 9:00 p.m. in the evening.
Tuesday, July 6, 2010
iFixes
Apple will send a fix, but as far as I'm concerned, the company's explanation is a non-answer. I can just imagine if I gave such an answer as to why a security patch didn't work. "I called the company and was told that the indicators weren't real to begin with." Or "They said that there's an error in the coding." And my supervisor would take that at face value? I don't think so. I think I'd be shown the exit sign.
In Apple's case, it hasn't been officially determined whether the fix has to do with the software or the hardware. Critics claim that the problem is because of the new iPhone's external antenna. When a person's skin comes into contact with it, you know what happens. Other smartphones, including previous iPhones, have internal antennas, which have a natural buffer between the antenna and the hand that holds the phone. A possible solution is a rubberized case, but that means that show offs can't flaunt their trophy phones as easily.
I am in no rush for an iPhone, even when other carriers will be able to sell it. My wife and I have BlackBerry phones and we're pretty happy with them. The browser is hard to read, though, but for the most part, it serves our purposes. My wife has worked on Apple computers at her newspaper and reports that while their physical structure is "seductive," they are underwhelming in their claims of what they can do, even for graphics. My advice: hold onto your current phone until the bugs are out -- and you have a choice of carriers.