The cloud icon has been used to symbolize a larger, connected network in technology diagrams for at least 30 years, so it’s not hard to imagine how the concept has migrated to its modern context: a collection of inter-connected computing and storage resources that can be shared amongst multiple services that can scale up and down as needed. If you are of a generation that recalls mainframes, mini-computers and batch runs (today’s PC is actually a “micro-computer” in the vernacular of the mainframe age), it’s a similar concept, except that instead of a single, gigantic device, the mainframe is now an array of CPU’s, storage devices and network interfaces spread across multiple locations and interconnected by the internet. If your understanding is still amorphous, you have creeping semantics to blame for that as well – the term “cloud” has become synonymous for internet-based resources, which can lead to plenty of confusion and debate about privacy, resilience and security.
Clear skies or storm warning ahead?
Just as being able to tell the difference between thunderheads and fluffy cumulonimbus can help us make decisions about grabbing the umbrella or sunglasses, understanding what is “cloud-based” or “hosted” or “virtualized” (or all three) can help you make informed decisions about what services and resources you utilize for your organization’s technology needs. As “cloud-based” has become something of a marketing hobby-horse that is frequently used out of context, it may be very hard to understand how the “cloud” comes into play in any given offering, if at all. If the “cloud” is mentioned to denote omnipresent resources or availability, it may be worth investigating whether this claim has any substance. Is the company or service in question making use of Amazon’s Web Services or Microsoft’s Azure platform? Those are examples of true cloud-computing platforms – very large endeavors and companies use services like these to power their own services and apps. Is your website or email “in the cloud” or is it “hosted”? For casual conversation, it doesn’t really matter (what matters is you don’t have a server on premise to manage anymore!), but it may be important make that distinction when it comes to evaluating your own organization’s technology security and resilience, especially if you are required to maintain compliance with industry regulations or federal laws.
Image courtesy of Vichaya Kiatying-Angsulee at FreeDigitalPhotos.net
In the latest dramatic chapter of the ongoing encryption battle between the FBI and Apple, the feds have admitted that they worsened their chances of ever finding out the contents of the San Bernardino shooter’s iPhone when they reset its associated iCloud password in a misguided attempt to access the locked device. According to Apple, prior to that reset, the FBI may have been able to gain access to the device without Apple having to provide a controversial backdoor to its otherwise very secure smartphones. On top of the FBI’s blunder and lack of understanding of Apple’s iPhone security, it’s also clear that several members of the House Judiciary Committee leading the hearings on this controversy are also poorly versed in how smartphone security works. To be fair to everyone, Apple’s iCloud system is arcane even to me, so it’s easy to see how someone unfamiliar with the system could make this mistake.
What this means for you:
Making fun of government officials being ignorant about high tech subjects is like shooting fish in a barrel. The “series of tubes” analogy used by Senator Ted Stevens is just one of many examples of US lawmakers struggling to understand admittedly complex technologies like the internet and encryption. Back then (10 years ago!) it might have been acceptable to dismiss their technology naivety as understandable – after all they are congress people, not IT consultants. But now, in an increasingly technology-permeated society, their ignorance or willful disregard of technology can lead to very bad decisions that have widespread and long-lasting consequences. This is just as applicable to your personal and workplace tech. While it’s impossible to be an expert on everything, if you rely on technology for critical business operations, you should have more than a basic understanding of how to turn it on and off. At minimum you should know what risks come with that technology, and if you cannot claim to be an expert in the technology in question, you should always consult with an experienced technology professional before making game-changing decisions.
Image courtesy of Stuart Miles at FreeDigitalPhotos.net
Apple made a big splash last week when CEO Tim Cook published an open letter in response to the FBI’s request and subsequent court order to hack the iPhone of the primary assailant in December 2015’s San Bernadino mass shooting. As one might expect, Mr. Cook basically told the government that they would not comply, and fortunately, they might be the one company that could afford to fight this battle in the courts. Though the tech industry has typically maintained a similar stance on device encryption, even the most staunch champions of digital privacy such as Google and Twitter have had suprisingly muted responses to the growing battle. Also revealing is a recent Pew poll that suggests while the tech industry may be largely united on device encryption and government backdoors, the American public isn’t quite sure what to think about this complex issue.
What this means for you:
Late model iPhones ship with encryption enabled by default, and as long as you enable some form of authentication on your device, the data on that device will only be accessible if you unlock it. Law enforcement can’t break the encryption, and Apple, by it’s own admission, cannot decrypt your phone’s contents with out the proper authentication, even if the phone owner asks them to do so. If someone tries too many times to guess your pin, the device will be automatically wiped – no intervention from Apple or your carrier is required. The FBI is demanding Apple create a way for them to unlock the iPhone of the San Bernadino shooter, which if Apple were to actually accomplish such a feat, could theoretically allow anyone with possession of this backdoor to decrypt any iPhone protected by similar technology. Like the atomic bomb, the development of this backdoor cannot be unmade, nor will it remain only in the hands of the “righteous”. While the data on the SB shooter’s phone may prove useful in providing some closure to the incident and may even help further other domestic terror investigations, it’s easy to see that the FBI means for this case to set a precedent that will give them unfettered access to an area that has traditionally been protected, both by law and by technology.
It’s getting harder and harder to make excuses for Microsoft when it comes to Windows 10, and they are quickly eroding whatever good will they may have sown with the free upgrades offered last year. If you weren’t already traumatized by an intentional or unintentional “upgrade” to 10, or if you happened to be one of the lucky few to walk the upgrade gauntlet (relatively) unscathed, Microsoft seems determined to make you regret installing its new operating system – let’s call it “death by 1000 annoyances.” The latest insult: many users are reporting a recent update to Windows 10 is resetting the default app assignments on their computers to – you guessed it – Microsoft apps.
Whatchoo talkin’ ’bout Woo?
One of the “features” of Windows 10 is the inexorable, unstoppable OS updates that Microsoft forces upon everyone. There are ways to trick Windows 10 into not downloading updates, and if your computer happens to be a part of a managed domain your administrator may be able to exert some control, but Microsoft has gone on record stating that giving users less control over this aspect is really for everyone’s own good. In the above case, a yet-to-be-identified recently released update from Microsoft is actually resetting choices you’ve made to your own computer to a setting that arguably benefits Microsoft. A good example of this is one that several of my clients have already experienced: instead of using Acrobat to open PDF’s, the OS is being reset to use Microsoft’s new browser, Edge – hardly a comparable substitute, especially for those that paid good money for the full versions of Acrobat. The default PDF app setting is one of possibly hundreds of default settings that Microsoft can “accidentally reset” so the annoyance potential on this “feature” is incredibly high. Fortunately it’s not permanent, and once you figure out what the heck is going on, it’s not hard to reverse. But it’s just another thorn on this once attractive, but increasingly prickly, OS rose.
I’ve put enough notches in my cyberbelt to speak with confidence on tech security and I’m reasonably sure most of you take me seriously, but it’s nice when the President of the United States backs up your message about the state of cybersecurity, especially when that message is that our work has only just begun. In a Wall Street Journal Op Ed piece published today, President Obama announced an aggressive plan to improve America’s cybersecurity profile, starting with increasing the nation’s budget on technology security to $19 billion. Three billion of that planned increase is targeted at upgrading Federal computer systems, many of which he recognizes as being woefully past due for an upgrade. And as is always the case, those computer upgrades are going to need tech-savvy hands, hopefully supplied by a tech-focused “Peace Corps” initiative and a new cybersecurity Center of Excellence which will formed as a collaboration point between the government and private sector. Some of this new money will also fund a national security awareness campaign (and you thought my password nagging was bad!). To cap it off, he is also calling for the creation of a bi-partisan Commission on Enhancing National Cybersecurity and creating a new national Chief Information Security Officer.
What this means for you:
In the short run, not much is going to change for you or your organization, even if you happen to work for or with an organization that might be first in line for Federally-funded computer upgrades. Federal programs never move swiftly, and I doubt this one will be any different. In order for any problem to be solved, it must be first acknowledged. Allocating money (however trivial it may seem in the face of our defense spend) is an important step in the right direction. Many business both big and small fail to budget for security issues, sometimes through willful denial, and most often because of a lack of understanding about how important cybersecurity has become. We all know the government regularly gets low grades on their technology proficiency – hopefully money won’t be a part of that problem going forward. The more important lesson here is that while money does help, talent, cooperation and a plan to change are crucial to developing a sound security policy, whether you are the federal government or sole proprietor.
Image courtesy of Stuart Miles at FreeDigitalPhotos.net
Most of us have seen the persistent little icon in the system tray, and clicked the many variations of “Not now!” to Microsoft’s constant reminders to upgrade to Windows 10. Some of you even caved in and upgraded your computer to Winodws 10, and an even smaller percentage of you have come out on the other side mostly intact and productive. I still continue to recommend against upgrading existing Windows 7 and 8 computers without considerable caution, planning and the watchful supervision of a trained technology professional. “Cleanly” installed (either on a blank hard drive or from the factory new), Windows 10 is a good operating system that performs well but still has many rough edges, and I have seen way too many upgrade installations go south faster than geese in winter. For reliabililty and performance, Windows 7 is still very hard to beat, and is still considered the standard in enterprise/corporate technology. Despite all of this, Microsoft continues to advance its agenda of “Upgrade all the things”, and has now made the Windows 10 upgrade installer a “recommended update”.
What this means for you:
By default, Windows 7 and 8 are set to automatically check for, download and install critical security updates. There is also another option rug “Recommended updates” which is also checked, and that is where Microsoft gets its virtual hooks into your precious Windows 7 (or 8, I’m not here to judge) operating system and plants the seeds of an upgrade. If your machine is still set to download recommended updates (as it will be if you’ve never changed these settings), you will soon be (if you aren’t already) the proud recipient of a 6GB hidden folder that, if you continue to deny Microsoft the satisfaction of upgrading you to Windows 10, will reside happily on its little 6GB plot of hard drive. Forever. Removing it doesn’t help – Windows Update will cheerfully re-download it for you, to make sure your Windows 10 upgrade experience isn’t slowed down by having to download it when you finally give in to their relentless nagging.
If you have a large hard drive and “all-you-can-eat” internet bandwidth, this isn’t a problem, but for those of you with smaller hard drives (like earlier model laptops with SSD drives) or metered bandwidth, 6GB is a lot of space AND bandwidth. There are ways to combat Microsoft’s insidious peer pressure, but to truly banish the upgrade nagging, you’ll need to fiddle with registry settings or install a third-party utility. If neither sounds like an activity for which you are qualified (either in patience or technical proficiency), why not have a friendly chat with your local tech professional to discuss a more moderate, considered approach to upgrading to Windows 10? If you are a business professional that uses Windows-based computers, its a bridge you will have to cross at some point, but you should do it on your own schedule and on your own terms.
Microsoft made a major splash a few years back when they announced that the NFL would be using the Surface tablets on the field and in the locker room for various aspects of team management. Up until now it really only caught the media’s eye briefly when commentators mistakenly identified the Microsoft tablets as Apple iPads, a stinging verdict on the strength of both Microsoft and Apple’s branding. Unfortunately for Microsoft, the Surface tablets were correctly identified this time at the recent AFC Championship game between the New England Patriots and the Denver Broncos. Unfortunate because the Patriots were experiencing technical difficulties with the devices at a crucial moment in the most important game of the season. As you’d expect, the internet had a field day with this, even though the the technical difficulties were quickly overcome, and the Patriots carried on.
What this means for you:
Rather than taking an easy opportunity to poke fun at Microsoft as you might expect, I’m more interested in making sure everyone grasps the more important lesson here. Even though the Surfaces had become an important part of sideline operations during a game, the Patriots were able to keep moving forward with their critical processes because the Surface tablets weren’t a single point of failure in the complex workflow of team and game management. Are there parts of your business or organization that depend on a single point of technology that, if it failed, would prevent you from executing on critical processes or tasks? Always have a back up plan, both in the literal sense (as in: Back up that data!) as well as the figurative. Important presentation tomorrow that you’ve only stored on a single thumb drive and nowhere else? What would happen if that little thumb drive accidentally fell out of your pocket while you were on the way to the big meeting? When it’s game day, make sure you have more than one way to get the ball into the end zone!
It’s a new year, and I’m sure every one of us made at least one small promise (if only whispered to ourselves at 12:01am on Jan 1) to be better or do better at something this year. I can help you out with an easy one that will definitely improve your security profile, and I’m pretty sure a safer you = a more healthier you (at least digitally).
Let’s talk about the foundation of personal security: the Password.
Change that password. You know the one. The one you use everywhere. Change it! Make it hard. There are dozens of methods for coming up with one. Here’s one:
- Pick your favorite quote (or one you have memorized), use the first letter from each word. How about, “Twas the night before Christmas” which gives us “Ttnbc” – 5 characters, a good starting point.
- Randomize the capitalization in a way you can remember. How about reverse camel caps? “tTnBc”.
- Since we need 8 characters minimum, let’s add two numbers, and since we’re talking about Christmas, let’s add “24” on the end (or the beginning, it doesn’t matter).
- And we need a special character, how about the “@” symbol which looks like a Christmas ornament.
So now we have “@tTnBc24”. You’ll remember it because you created a small story behind the password, which will make it memorable. But Chris, you always say to use a unique password for every account! No problem, here’s how you do that, while still making every password you create memorable:
- For every unique account password you need to create, pick a string of 3 or 4 letters based on the name of the account (however you remember it, company name or type) – let’s say the first 3 letters, and always use the same rule. So for your Chase bank account, you’d add “Cha” somewhere to the password, either beginning or end.
- Before you tack it on the end of the password, pick a symbol that will act as the glue (or divider) between your specific account divider, let’s just say “+” because that makes sense right?
- Now you have “@tTnBc24+Cha”.
WARNING: if anyone ever gets ahold of more than one of your passwords generated via the above method, they may spot the pattern right away, especially if the account is known for each password, making it relatively easy to guess other account passwords. My recommendation here is to not use this method with passwords that you have to share with other people (it will be obvious if they see more than one). For those, use a random generator and store them in a known secure password utility, such as LastPass, KeePass, Dashlane or Roboform.
Use the above method for the accounts you access frequently, but don’t want to lower your security because of how valuable they are. Examples should include your email account (especially the one you use to send password resets/reminders to), anything that is attached to your money, accounts that has sensitive private information like insurance websites, and, most importantly, all of your social media sites, especially any in which you interact with friends and family.
If you are wondering if a password you’ve used in the past has been exposed, you can check https://haveibeenpwned.com if you know the email address to which the account was attached. This website is essentially a giant database of all the known data breaches over the past couple of years. If your email address raises a red flag, you should change the password you used for that account, especially if you used that same password elsewhere.
Image courtesy of Stuart Miles at FreeDigitalPhotos.net
Back in 2014 Microsoft announced that in 18 months it would cease to support older versions of Internet Explorer on currently supported operating system platforms. As of January 12th, Microsoft is making good on that promise and will only support the latest version of its web browser on supported OS’es. You might think that this will mean less zero-day exploits of older versions of IE (one of the biggest security risks to date) because people will be forced to abandon the older browsers, but not so fast! Microsoft is trapped within their own doublespeak, and the catch is “lastest version of IE released on a particular supported platform”.
What on earth does that mean?
If you happened to only skim (instead of read) their 2014 announcement or the news stories released this week about this new policy, you might have come away with the impression that Microsoft was finally dropping support for older versions of IE, namely 6, 7, 8, 9 and 10. Depending on your business need, this may have been cause for celebration or hair pulling, but a slightly deeper dive on this tells a less draconian tale. In a nutshell, depending on the operating system, some older versions will still be getting patched and updated, but only because the newer versions of IE were never officially released on a particular OS. Still confused? That’s OK, it’s Microsoft, so just shrug and take away the following:
- Microsoft will still be patching older versions of Internet Explorer as far back as version 7, but…
- Patches for versions 7-9 are likely to be hard to get, if not near impossible for normal consumers.
- Don’t use older versions of IE unless you have a compelling business restriction that prevents the use of IE 11.
- Businesses relying on websites that require the use of older versions of IE should be upgraded ASAP. You are putting your employees/clients/customers in danger.
- Remember #3? If you have to use Internet Explorer, you should be using version 11. It has competent backwards-compatibility capabilities that should work with websites that require older versions of IE to function.
Reports are streaming in of Dell customers being targeted by scammers pretending to be Dell support staff, leading many in the industry to wonder if the computer manufacturer has been hacked and their customer database stolen. The con artists are phoning Dell users and gulling the victims with convincing information about equipment and service records that should only be known to Dell. After the fake support techs gain access to their target’s computer, the usual scare scam follows, intimidating users into paying for virus removal, performance tuning, etc. This may have been going on as far back as May of last year, but with reports flooding Dell’s actual service desk, they are finally admitting it’s a problem without confirming whether any data has been stolen.
What this means for you:
Unless you’ve hired a company like C2 to monitor your equipment and network, it’s extremely rare that a company like Dell or Microsoft will call someone directly to fix a problem, especially if you didn’t initiate the interaction from the onset. While manufacturers like Dell do actually ship some of their models with software that can perform monitoring and remote access, they aren’t actually in the business of monitoring the millions of computers they sell. The same is true of Microsoft – they have support desks, but proactively contacting customers about problems on individual machines is just not something either company will do. Anytime you receive a call like this from someone you don’t know, your best course of action is to disengage immediately and contact a trusted technology professional. If you are feeling cheeky, you can try to get a callback number (they may actually give you one) and get someone like C2 to vette the caller. Ninety-nine times out of 100, it’s going to be a scam. Don’t waste your time on these con artists, and always get a second opinion before acting on an unsolicited technical support call.
Image courtesy of Miles Stuart at FreeDigitalPhotos.net











