Thanks to the commoditization of computer hardware, it’s possible to buy a serviceable laptop that costs less than $500 brand new. This has resulted in many companies relaxing the restrictions they had on their purchase and use, but a small healthcare provider in North Idaho learned a harsh lesson that hardware costs are the least of their worries when it comes to losing a laptop. The Hospice of North Idaho recently had a laptop stolen that contained unencrypted, sensitive personal information on over 400 of their patients, and because this is a violation of the Health Insurance Portability and Accountability Act, the Department of Health and Human Services is slapping the non-profit hospice with a $50,000 fine.
What this means for you:
Even if you aren’t a healthcare provider, being aware of the data on your company’s laptops should be a top concern, regardless of whether you think the data doesn’t fall into the protected class outlined by HIPAA. Mobile electronics, like laptops and smartphones are a prized target of thieves, on top of being ridiculously easy to damage and/or misplace all on their own. If your laptops are used heavily on the road, you should consider encrypting some or all of the data on the device, as well as making sure employees are using physical security devices like cable locks whenever the laptop is set down for more than 5 minutes, even if in a “secured” working environment. If your smartphone has access to any company or customer data, you should have auto-locking enabled and at least a 6-digit pin or password to unlock it. Cable locks won’t stop a determined thief, but it will deter most casual theft, and data encryption + passwords will make sure you never have to have that meeting with a client (or worse, a prospect) to let them know that their data might be at risk.
Image courtesy of “cooldesign” / FreeDigitalPhotos.net
A recently published whitepaper from Redwood, CA security firm Imperva reports a disturbing trend that many technology professionals already suspected: current anti-malware manufacturers can’t keep up with the pace of virus development now that malware has moved from the realm of mischief to big-time criminal enterprise. Researchers from Imperva and students from Technion-Israel Institute of Technology put together a study that pitted 80 new viruses against over 40 of the top commercial antivirus products on the market, including Symantec, McAfee and Kaspersky and found that they were only able to detect 5% of the new malware infections.
It’s important to note that the sponsor of this study, Imperva, has a material stake in future anti-malware development, as their focus has been on developing a method of protection that differs from the traditional signature detection approach used by the mainstream antivirus developers. Signature detection relies on antivirus manufacturers being able to “capture” and reverse-engineer a computer virus strain to develop ways to combat infection, a process that is entirely reactive and time-consuming. As you might have guessed, new viruses can do their damage in minutes on a vast scale thanks to the internet, so relying on protection developed after the virus has been in the wild is of no help to those already infected. Cybercriminals realize they have the advantage of surprise on their side, and are investing heavily in staying ahead of signature detection algorithms.
What this means for you:
Future security is going to rely heavily on a combination of methods: signature detection, heuristic analysis (watching for anomalous behavior), virtualization/compartmentalization and good old fashioned paranoia/preparedness. The public at large has been lulled into a false sense of security in thinking that purchasing a product off the shelf will absolve them of the need to remain vigilant. As some of my clients can personally attest, you can have the best antimalware products on the market and still get infected. Technology security is more than purchasing software and hardware – it’s a process and state of mind that must constantly be maintained. If you are uncertain how to evolve your business practices to step up your state of readiness, give C2 Technology a call – we can help!
Image courtesy of graur razvan ionut / FreeDigitalPhotos.net
A 2013 whitepaper published by security firm Fortinet provides eye-opening details on the increasingly well-organized world of cybercrime that now features standardized pricing, polished branding, affiliate networks and zombie armies that can be rented for as little as $15/hour. Depending on the size of the botnet army, an incredible amount of damage can be done in an hour, making this one hell of a deal if your business is exploiting security flaws and stealing identities. Criminals have noticed the huge upside to cybercrime and, like they have always done, wasted no time investing big dollars and resources in this new “industry.”
What this means for you:
Overall, it’s unlikely criminals are outspending the big companies in the cyber arms race, but it’s almost a certainty that they are outspending and are better “armed” than most small and medium-sized businesses, especially ones that can’t (or won’t) afford the necessary investment in preparation and security. The most important thing you can do as a business owner that uses technology for any aspect of your business is ensure that you are taking the appropriate precautions and making the right security investments in your technology platforms. Keep in mind this doesn’t stop at buying hardware and software, but also includes training your employees as well as holding your vendors accountable for security as well.
Image courtesy of chanpipat / FreeDigitalPhotos.net
It might be the last day of 2012, but there’s still time to issue yet another patch to fix a zero-day exploit in Microsoft Internet Explorer 6, 7 and 8. Confirmed on Saturday by Microsoft, this patch fixes a vulnerability in all versions of IE prior to v9 that may allow hackers to gain control over a victim’s machine. This latest weakness is likely to be exploited when a computer using one of the versions of the aforementioned browser visits a malicious website, allowing it to run code that can corrupt the memory on the victim’s computer and from there execute malicious code as the logged in user, potentially resulting in backdoor installations, malware infections, and zombification.
What this means for you:
It’s conceivable you are still running IE 8 which was released in 2011, so you may be affected by this weakness. If you are running IE7 or, impossibly, IE6 (it was released in 2001 – over 10 years ago!), I’d say you are better off upgrading to the latest version of IE you can reasonably run on your computer, and then making sure it is patched appropriately.
Holidays usually bring out the best in people, especially those who truly are kind-hearted and enthusiastic about the season, but it’s also an opportunity for the Grinches among us to take advantage of everyone around them. E-cards aren’t new to the internet, and may have actually waned in overall popularity since their inception many years ago, but the winter holidays usually see a spike in their usage. Internet blackhats know this trend, and ironically, it’s like Christmas for them, because they know they can trick more than the usual number of people into opening fake greeting cards that instead of delivering cheer and love, drop a big helping of malware coal in your digital stocking.
What this means for you:
Frankly, I verge on the side of paranoia, and and don’t open any digital greeting card these days unless I recognize the URL (and confirm it’s not a counterfeit). This makes me feel vaguely Scroogish, but I’d rather not spend the holidays disinfecting my computer. If you get a E-card from someone that you weren’t expecting, especially if it’s from someone you know wouldn’t send one (or they already sent you an actual physical greeting card), take a moment to contact that person to verify they actually sent it, especially if you don’t recognize the URL. Heck, it could be your opportunity to reach out to someone you haven’t spoken to in awhile, and there’s no better time like the holidays to reconnect with acquaintances, right?
If you do decide to open that virtual card, make sure your antimalware is up to date, your operating system fully patched, and you have C2 Technology on speed dial!
Image courtesy of “mrpuen” / FreeDigitalPhotos.net
Responding to a maelstrom of criticism, Instagram announced today that they plan to withdraw the proposed Terms of Use changes that sparked outrage across the internet yesterday. According to co-founder Kevin Systrom, Instagram never had any intent to monetize user photos without fairly compensating the photographer, and they are working to revise the TOU wording in a manner that is less confusing and less likely to start a another protest/boycott. Ironically, other sources have pointed out that the outrage was ill-informed at the start, and as things are wont to do on the Internet, spun out of control, perhaps unfairly so for Instagram.
It would seem that Instagram has always had the right (according to their current TOU) to monetize your content, and that the withdrawn change actually narrowed the rather broad terms users agreed to previously. I’d publish a full mea culpa on this, but the point of my previous article was more to point out the icky terms governing the use of photos that contain minors, as well as the very vague terms that assume minors are using Instagram with implicit parental consent. I understand it’s hard to police the use of free apps, especially when parents are noticeably absent with respect to knowing what their kids are doing on their personal media devices, but that seems like a cop out.
What this means for you:
My stance on the exploitation of minors for profit still stands: It’s icky. If you are a company like Instagram that is bound to feature content containing images of minors, you need to be much more careful how you glad-handle parents. As for jumping on the rage bandwagon yesterday:
Dear Instagram,
I’m sorry for assuming you suddenly became evil. You aren’t evil, but maybe you were too cavalier with your current Terms of Use, and you let too much of your Facebook allegiance shine through in your proposed changes. Please don’t be icky, and please don’t treat your users like a prize crop, even though they may act exactly as that. I’m sorry I didn’t take the time to read your lengthy and lawyered-up TOU to find out the truth that you had us by the throat from the get go, and I’m even more sorry that we willingly (through our own ignorance/apathy) let you.
The eagle-eyed internet has caught another dotcom company looking to cash in on its popularity (and recent integration with Facebook): starting on Jan 16, 2013, Instagram will be using a new Terms of Service agreement that allows it to use any content posted publicly to its service for marketing purposes.
“To help us deliver interesting paid or sponsored content or promotions, you agree that a business or other entity may pay us to display your username, likeness, photos (along with any associated metadata) and/or actions you take, in connection with paid or sponsored content or promotions, without any compensation to you.”
Also important: this not only applies to users who have an account with Instagram, but also anyone’s likeness that appears in a user’s publicly posted photos can also be used as such. Wait, we’re not done: if you are a minor and you’ve accepted the new TOU, you acknowledge that your parent/guardian is aware of the TOU and tacitly accepts the above.
What this means for you:
If you aren’t in the business of making money off your likeness, or your subjects aren’t celebrities, or if you don’t care that Instagram/Facebook might make some money off your own likeness, then carry on. However, if you happen to care how your children’s likeness may be exploited, you may want to ask any snap-happy smartphone users to not post pictures of your children onto Instagram, or at minimum, make them aware of these TOU changes. You may be surprised at how many people aren’t aware of Instagram’s control over the content they think they own, and doubly surprised at the number of people who don’t care that they may be providing profit for company’s that provide free services.
Yesterday, the internet experienced a moment of apocalypse angst when Gmail users around the world (including C2) experienced a variety of issues getting email. Lasting roughly 40 minutes, users experienced complete outages, slowness and, if they were using Chrome with browser syncing enabled, outright application crashes. It turns out, rather than being able to blame ancient prophecies, Google fingered one of their own as the root source of the problem.
What this means for you:
Cloud nay-sayers may have had a brief moment in the sun while Gmail was on the ropes, but the fact remains that it’s still a very reliable service. Several lessons may be learned from the experience, all of them common sense:
- If your critical business practices rely on a free email service being available all the time, everywhere, you may want to re-evaluate those practices.
- When making adjustments to your business infrastructure, always double-check your work, and make sure you have a backup of your data.
- When technology fails, 9 times out of 10, a human is behind the failure.
Last week, Facebook opened up a vote on its usage and terms policies that included in the changes the removal of user pivilege of voting on future changes to said policy. In order for the user vote to be binding, 30% of Facebook’s user population (approximately 300 million users) needed to cast a vote in either direction. In the “Surprising No One” column, only 700,000 votes were cast (about .06% of the total population), and even though the vote was overwhelmingly against the changes, Facebook only needs to take that result under advisement, in other words, “Thanks for your opinion, we’ll do what we want.”
What this means for you:
Most of Facebook’s user base probably had no idea they had any influence over the policies that affect how they use, and are used by, Facebook, who went so far as to notify everyone about the upcoming vote via email. Even though they provided an easy to use link, an even easier to use app to vote (you didn’t even need to leave the confines of Facebook!), most of the world couldn’t be bothered to care about this change. It’s true, as mentioned in my previous article on this, Facebook allowing its userbase to weigh in on policy change is extremely unusual. As a result of the lack of interest, Facebook will become like the thousands of other internet companies who make changes to their terms of use without asking their users permission, and internet citizen self-governance takes another step backwards in favor of convenience and “free” services.











