We all get e-mails from well-meaning family members and friends. A huge virus is going around. Don't open this or your hard drive will be destroyed.
But something really is going around. Three different people I know were affected by a virus that cracked their free e-mail account and then sent out e-mails with their address books with a link to a website. Social media sites, such as twitter.com, have also been affected by this virus. The link contains a virus that reads both Outlook and proprietary address books (such as that of AOL) and send out e-mails.
How do you prevent it? Use a complex password and change it often. When you create or change your password, use upper case and lower case letters as well as numbers and punctuation, such as underscores or dots). Another good idea is to create an e-mail address on a free e-mail service and use this e-mail for all your junk e-mails. Finally, keep your spam filter on high. Somehow, e-mails from disreputable people and companies will get through, but it's one of the best measures you can take.
Speaking of hacking, some high profile hospitals in New York City admitted that patient data was compromised. Somehow it got on an open server. Hospital officials claim that no information was used inappropriately, but that remains to be seen. The real danger is not that someone is going to sell information about a celebrity's health problems to the National Enquirer, but that patients are at risk of identity theft. All a perpetrator needs is a name, address, social security number and date of birth. For a while it was available on an open server at large hospitals in one of the biggest cities in the nation. This is why they need to hire experienced security analysts and keep up to date on security software.
Imagine if there were a virus that sucked out a hospital's patient database. If that hospital were in a large city where people go to for the top specialized care, identity theft would be made easier and more widespread than ever. If you can, give only the last two or four digits of your Social Security number when asked for it by a doctor's office or medical institution. Don't make it easier for local amateurs to steal your identity. You don't know how safe your doctor's computer system really is.
Tuesday, September 28, 2010
Wednesday, September 22, 2010
Google's Breach of Trust
Google's recent internal security breach is raising questions about cloud computing. While Google claims they trust the company's Site Reliability Engineers, the fact is that the company does not have enough control over the employees who have access to its systems. Naturally, Google is trying to contain costs, but this is one of many areas where corporate decision-makers have to choose both their priorities and their misery. The company claims it regularly upgrades its security controls by auditing logs, but it won't define regularly. Is it regularly as in daily, weekly, monthly, quarterly, annually or regular when there's a problem?
In my experience as a consultant between full-time employment, I can see where there are gaps. Someone accepts an assignment for three months or six months, or even two years. If the pay isn't worth his while, he is going to keep one foot on the gas pedal, ready to take off as soon as a better offer comes in. If a company relies on consultants, the hiring managers must know that there is not going to be any loyalty on the part of the contract worker. Why would there be? What Samuel Goldwyn said about a contract not being worth the paper it's printed on was a laughable remark some 70 years ago. It turns out Goldwyn was a prophet. I had a one-year contract become worthless after nine months. I wasn't singled out. At various networking meetings, I met four other victims of the same company with the same contract. And, no, we were not spying on minors or tapping into call logs. We were putting out fires.
Cloud computing isn't going away. Companies that are thinking about using it are going to have to take security measures very, very seriously. What Google's David Barksdale did was unpleasant and immoral, but it's nothing compared to what can and does happen.
For the past several years, I've worked to prevent identity thefts. In order to prevent people from hacking into bank accounts and medical records so that they can get another person's name, address and social security, I've installed and tested various intrusion detection systems. Sometimes a company doesn't want to spend the money on upgrades, but here's what happens. Suddenly there's an announcement that ABC Financial Corporation or XZY Bank is offering free credit monitoring to its customers "because its data may have been compromised." Now you know what you mean by compromise. And that credit monitoring is only free for customers, not for the corporation. Where's the savings? it's certainly not financial. And the company's reputation among its customers has also been compromised. There's no free monitoring for that.
http://www.readwriteweb.com/cloud/2010/09/googles-internal-security-brea.php
In my experience as a consultant between full-time employment, I can see where there are gaps. Someone accepts an assignment for three months or six months, or even two years. If the pay isn't worth his while, he is going to keep one foot on the gas pedal, ready to take off as soon as a better offer comes in. If a company relies on consultants, the hiring managers must know that there is not going to be any loyalty on the part of the contract worker. Why would there be? What Samuel Goldwyn said about a contract not being worth the paper it's printed on was a laughable remark some 70 years ago. It turns out Goldwyn was a prophet. I had a one-year contract become worthless after nine months. I wasn't singled out. At various networking meetings, I met four other victims of the same company with the same contract. And, no, we were not spying on minors or tapping into call logs. We were putting out fires.
Cloud computing isn't going away. Companies that are thinking about using it are going to have to take security measures very, very seriously. What Google's David Barksdale did was unpleasant and immoral, but it's nothing compared to what can and does happen.
For the past several years, I've worked to prevent identity thefts. In order to prevent people from hacking into bank accounts and medical records so that they can get another person's name, address and social security, I've installed and tested various intrusion detection systems. Sometimes a company doesn't want to spend the money on upgrades, but here's what happens. Suddenly there's an announcement that ABC Financial Corporation or XZY Bank is offering free credit monitoring to its customers "because its data may have been compromised." Now you know what you mean by compromise. And that credit monitoring is only free for customers, not for the corporation. Where's the savings? it's certainly not financial. And the company's reputation among its customers has also been compromised. There's no free monitoring for that.
http://www.readwriteweb.com/cloud/2010/09/googles-internal-security-brea.php
Tuesday, July 20, 2010
Redundancy is Welcome, Indeed
As a writer, my wife grits her teeth when she sees or hears redundancies. Example: 8:00 p.m. in the evening. But in IT, redundancy is welcome, indeed. Redundancy is instant backup. Without it, a trading company can lose millions of dollars in just seconds or viewers will miss that exciting maneuver in a football game on TV.
I designed, installed and implemented Avon's website (not the graphics) for e-commerce. Later, at Gartner, I designed the redundancy network infrastructure for e-commerce websites so that the sites can function in the event that one site is down. Almost everyone who does online banking has experienced the frustration of trying to check balances, pay bills or schedule transfers at 8:30 p.m., only to get a message that the site is down. At 3:00 a.m., it's understandable, even though many on the West Coast may still be up. Chances are, that bank has a redundancy program that is simply inadequate. The customer won't lose money because the site is down, but the bank may lose customers if it develops a reputation for failure when the end-user needs it at a reasonable time.
Here's the bottom line: get your redundancy infrastructure so that's it's available when customers need it, whether it's 9:00 a.m. in the morning or 9:00 p.m. in the evening.
I designed, installed and implemented Avon's website (not the graphics) for e-commerce. Later, at Gartner, I designed the redundancy network infrastructure for e-commerce websites so that the sites can function in the event that one site is down. Almost everyone who does online banking has experienced the frustration of trying to check balances, pay bills or schedule transfers at 8:30 p.m., only to get a message that the site is down. At 3:00 a.m., it's understandable, even though many on the West Coast may still be up. Chances are, that bank has a redundancy program that is simply inadequate. The customer won't lose money because the site is down, but the bank may lose customers if it develops a reputation for failure when the end-user needs it at a reasonable time.
Here's the bottom line: get your redundancy infrastructure so that's it's available when customers need it, whether it's 9:00 a.m. in the morning or 9:00 p.m. in the evening.
Tuesday, July 6, 2010
iFixes
It always amuses me to see people rush into the newest technology when it's common knowledge that there are bugs in first models. So what's with the bars on the iPhone 4? Users have been complaining of low signal strength and busy towers since the first iPhone came on the market. Last week, Apple shouted Eureka! They found the problem. It was a formula error. The company posted a statement on its website that explained "our formula, in many instances, mistakenly displays 2 more bars than it should for a given signal strength." They added, "Their big drop in bars is because their high bars were never real in the first place." Huh?
Apple will send a fix, but as far as I'm concerned, the company's explanation is a non-answer. I can just imagine if I gave such an answer as to why a security patch didn't work. "I called the company and was told that the indicators weren't real to begin with." Or "They said that there's an error in the coding." And my supervisor would take that at face value? I don't think so. I think I'd be shown the exit sign.
In Apple's case, it hasn't been officially determined whether the fix has to do with the software or the hardware. Critics claim that the problem is because of the new iPhone's external antenna. When a person's skin comes into contact with it, you know what happens. Other smartphones, including previous iPhones, have internal antennas, which have a natural buffer between the antenna and the hand that holds the phone. A possible solution is a rubberized case, but that means that show offs can't flaunt their trophy phones as easily.
I am in no rush for an iPhone, even when other carriers will be able to sell it. My wife and I have BlackBerry phones and we're pretty happy with them. The browser is hard to read, though, but for the most part, it serves our purposes. My wife has worked on Apple computers at her newspaper and reports that while their physical structure is "seductive," they are underwhelming in their claims of what they can do, even for graphics. My advice: hold onto your current phone until the bugs are out -- and you have a choice of carriers.
Apple will send a fix, but as far as I'm concerned, the company's explanation is a non-answer. I can just imagine if I gave such an answer as to why a security patch didn't work. "I called the company and was told that the indicators weren't real to begin with." Or "They said that there's an error in the coding." And my supervisor would take that at face value? I don't think so. I think I'd be shown the exit sign.
In Apple's case, it hasn't been officially determined whether the fix has to do with the software or the hardware. Critics claim that the problem is because of the new iPhone's external antenna. When a person's skin comes into contact with it, you know what happens. Other smartphones, including previous iPhones, have internal antennas, which have a natural buffer between the antenna and the hand that holds the phone. A possible solution is a rubberized case, but that means that show offs can't flaunt their trophy phones as easily.
I am in no rush for an iPhone, even when other carriers will be able to sell it. My wife and I have BlackBerry phones and we're pretty happy with them. The browser is hard to read, though, but for the most part, it serves our purposes. My wife has worked on Apple computers at her newspaper and reports that while their physical structure is "seductive," they are underwhelming in their claims of what they can do, even for graphics. My advice: hold onto your current phone until the bugs are out -- and you have a choice of carriers.
Friday, April 30, 2010
What Does a Security Breach Cost?
Someone finally assigned a dollar value for security breach that we can relate to. Not in millions or billions or gazillions, but in three figures - $204 per lost record. This is according to a recent report by the Poneman Institute. At 66%, loss of business is the biggest cost. Customers lose trust. Then there's the cost of spin to control bad publicity.
What can companies do to minimize costs? It helps to put a chief information security officer at the helm. It also helps to keep up to date on the most advanced firewalls and penetration software. There will always be someone who thinks he's a better hacker. Oh, and for those who like figures in the millions, the average cost to an organization is $3.43 million. The figure of $204 per record is for the U.S. because of notification laws, but the sum varies among nations. Read the Ponemon Institute's "2009 Annual Study: Cost of a Data Breach" http://www.encryptionreports.com/.
What can companies do to minimize costs? It helps to put a chief information security officer at the helm. It also helps to keep up to date on the most advanced firewalls and penetration software. There will always be someone who thinks he's a better hacker. Oh, and for those who like figures in the millions, the average cost to an organization is $3.43 million. The figure of $204 per record is for the U.S. because of notification laws, but the sum varies among nations. Read the Ponemon Institute's "2009 Annual Study: Cost of a Data Breach" http://www.encryptionreports.com/.
Monday, April 26, 2010
Visa's M-Bet
Visa, meet CyberSource. More than 40% of online payments are done through Visa, and e-commerce is getting old. Cell phone companies are pushing smart phones because they can increase their revenues as we become increasingly tethered not only to our cells phones, but to our computers.
CyberSource, Visa needs you. At $2 billion, this is the largest amount of money Visa ever paid for anything. But, hey, Visa needs to compete with PayPal. As much as people complain about the fees, they know they're stuck with it if they want to buy something on eBay. M-commerce is not going away and CyberSource may even be able to serve those who refuse to embrace BlackBerry devices and iPhones.
Now it comes down to data protection. There will be be a new level of penetration tests those of us in IT security need to learn. I hope Visa doesn't skimp on this. Otherwise, they will be in the same embarrassing -- and costlier -- position as other financial institutions that decided to gamble on security. They ended up paying for "free" credit monitoring. It wasn't free for them.
Read more at: http://www.nytimes.com/2010/04/22/business/22visa.html
CyberSource, Visa needs you. At $2 billion, this is the largest amount of money Visa ever paid for anything. But, hey, Visa needs to compete with PayPal. As much as people complain about the fees, they know they're stuck with it if they want to buy something on eBay. M-commerce is not going away and CyberSource may even be able to serve those who refuse to embrace BlackBerry devices and iPhones.
Now it comes down to data protection. There will be be a new level of penetration tests those of us in IT security need to learn. I hope Visa doesn't skimp on this. Otherwise, they will be in the same embarrassing -- and costlier -- position as other financial institutions that decided to gamble on security. They ended up paying for "free" credit monitoring. It wasn't free for them.
Read more at: http://www.nytimes.com/2010/04/22/business/22visa.html
Tuesday, April 13, 2010
Toast
Yesterday's article in The New York Times about concern over nuclear arms in Asia is long overdue. This is something that I have been concerned about for years. Any American company that has a data center in India could be toast. This risk is bigger than the ones many financial institutions have taken by not allocating money for better security domestically. How many times have you heard that a particular company will offer its customers free credit monitoring for a year because their data has been compromised. That's nothing compared to the potential physical meltdown of a company's data center. As an investor, I worry about that.
There are backups, but that may be too little too late in this scenario. It wasn't just jobs that have been outsourced to India; it's security. It's a company's lifeline. Whatever money the company has saved by not upgrading firewalls and penetration software and by hiring cheaper labor overseas and temporary workers domestically can be gone in one explosion. Not a pretty picture and that's without even thinking about the consequences to the land and to people's health.
There are backups, but that may be too little too late in this scenario. It wasn't just jobs that have been outsourced to India; it's security. It's a company's lifeline. Whatever money the company has saved by not upgrading firewalls and penetration software and by hiring cheaper labor overseas and temporary workers domestically can be gone in one explosion. Not a pretty picture and that's without even thinking about the consequences to the land and to people's health.
Subscribe to:
Posts (Atom)