Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Wednesday, October 10, 2012

Have a CryptoParty

Do you value Privacy and Anonymity online?? Do you want to be more secure online while using your PC or Smartphones??

Check out 'CryptoParty' documents and Wikis accessible from the site here

The CryptoParty document is a work in progress - but all the same it provides valuable security tips for all levels of users - very lucidly written and worth a read!!

You can download the 'CryptoParty' document PDF format (about 28 MB as on date) or can read it online here

What is CryptoParty?
Interested parties with computers, devices, and the willingness to learn how to use the most basic crypto programs and the fundamental concepts of their operation! CryptoParties are free to attend, public and commercially non-aligned.

CryptoParty is a decentralized, global initiative to introduce basic cryptography tools - such as the Tor anonymity network, public key encryption (PGP/GPG), and OTR (Off The Record messaging) - to the general public

Though each and every chapter are enlightening,  the chapters on 'Secure Calls', 'Email Encryption' and 'Safer Browsing' standout.  

Hope most of us become aware of issues like below:-
A GSM Interceptor (http://en.intercept.ws/catalog/2087.html) is an off the shelf device to record mobile phone conversations when in the vicinity of the call.
 Tor is a system intended to enable online anonymity, composed of client software and a network of servers which can hide information about users' locations and other factors which might identify them. Imagine a message being wrapped in several layers of protection: every server needs to take off one layer, thereby immediately deleting the sender information of the previous server
The only safe way of encrypting email inside of the browser window is to encypt it outside and then copy&paste the encrypted text into the browser window.

Have a CryptoParty if possible - and do send me an invite!!





Sunday, September 25, 2011

Protect your online banking accounts

Most of us have heard of 'Phishing Attacks' where innocent enthusiastic banking online users find themselves on the receiving end of criminal attacks by having their online bank accounts compromised/swindled. Though most are aware of the dangers, there are some who believe in their online immortality - that is 'It just cannot happen to me'!!! These are the guys I want to alert!!

Check out this detailed explanation of an online banking swindle attack targetted at Indian Banks (this is specifically for Reserve Bank of India accounts).  Just to alert you on the methodology and maybe, for you - it is seeing (by example) is believing!! And hope you never become a victim.

Check out this website of a reputed anti-virus/cyber security company called F-Secure.

Hope this example helps to convince you take necessary care!!

Sunday, March 13, 2011

Internet Security - Parental control setup

With the easy access to the Internet Broadband to everyone in the family, the need for parental controls has never been felt more. 

There is a need to prevent access to dangerous sites at which family members unwittingly land up with, or to control the usage hours etc. 

Check out these useful websites (rated safe!) for setting up parental controls easily.




Friday, August 13, 2010

Have you patched up your Windows?

Have you patched up your Windows systems? Well, only licensed users can do it up!

Check out: http://bit.ly/9C3E6x
 

Microsoft today issued a record 14 security updates to patch a record-tying 34 vulnerabilities in Windows, Internet Explorer (IE), Office and Silverlight.
Of the 34 flaws, Microsoft rated 14 as "critical," the highest threat ranking in the firm's four-step scoring system. Seventeen were pegged as "important," and three were labeled as "moderate."

And Microsoft site for the details:http://bit.ly/ah0NnJ
 

Today we released fourteen security bulletins
 
. Eight have a maximum severity rating of Critical with the other six having a maximum severity rating of Important. Furthermore, six of the fourteen bulletins either do not affect the latest version of our products or affect them with reduced severity. We hope that the table below helps you prioritize the deployment of the updates appropriately for your environment.
Microsoft
 
rated all those vulnerabilities with a "1" on the exploitability index.


Looks like a SysAdmin's nightmare!! In the Indian Govt context, those entrusted to take care and be responsible for huge IT infrastructures, with most machines on Windows platforms (licenses??? - who heard of them!!) can only pray! :-/

Sunday, November 29, 2009

CAUTION: AFNHB Official Site dangerous

The official AFNHB (Air Force Naval Housing Board) site - http://afnhb.org site has been rated dangerous/un-trustworthy by the popular WOT (Web of Trust) rating agency. Various domain control agencies have blacklisted the site.The site has a poor malicious/virus rating making it dangerous.
Check out the details at:
http://www.mywot.com/en/scorecard/afnhb.org/comment-2899237#page-1
http://www.mywot.com/en/forum/4618-malwaredomains-new-update-10-14

Please exercise caution when when accessing the site.

 


Please exercise caution when when accessing the site http://afnhb.org.

Sunday, October 25, 2009

Reporting Software Piracy - the Dummies Guide

This is the result of a close friend of mine (Manish - hands up!!) enquiring about if there is any way of reporting Software Piracy!! Well, it got me thinking! For one, I had never ever reported any 'Software Piracy' - just felt bad when I saw it, gave a sardonic smile, and went about the daily chores including preaching about using Open Source and Freeware!! Secondly, 'Software Piracy' in India has become such a 'done thing' that every one assumes its their birthright, and never give it a second, nay first, thought!! I wonder if they ever even thought about it! This is especially true and pretty rampant in Govt. Organisations and smaller firms . For example, visit any 'Photo shop', and you would see them using 'Photoshop'  (pun intended!!) to touch up your digital photos! I always wonder if they spent the Rs. 50K minimum necessary for a licensed copy of the software!!! Check the price here - its $1000 approx).

Let me make you feel guilty!!! Are you or your organisation using original software? Well, when MS Office 2007 Professional costs Rs.15,500/- and MS Office 2007 Home costs Rs. 3000/- (hardly anyone uses the low featured 'MS-Office Home Edition'), I guess you have saved some money, right? :-)

In fact, people look at you in surprise if you enquire about their software licenses!! And some even wonder if there is anything like a software license (the whole software thing came pre-loaded you see!!!). And some even tell me "DO SOMETHING USEFUL IN YOUR LIFE U REVENGEFUL **** " :-)

Anyway, coming to the point, one can report Software Piracy in Organisations or Individuals. And am sure some actions are taken thereof!!!

What defines Sofware Piracy? From the Business Software Alliance site:
"Software piracy is the unauthorized copying or distribution of copyrighted software. This can be done by copying, downloading, sharing, selling, or installing multiple copies onto personal or work computers. What a lot of people don't realize or don't think about is that when you purchase software, you are actually purchasing a license to use it, not the actual software. That license is what tells you how many times you can install the software, so it's important to read it. If you make more copies of the software than the license permits, you are pirating."

Every major software maker have their own 'Software Piracy' reporting forms/ web-site/ mail id!! Check out a few of these sites if you are interested (???) to report Software Piracy!!
http://www.bsa.org/country.aspx?sc_lang=hi-IN  - The grand daddy of them all.
http://www.microsoft.com/india/piracy/Report_piracy.aspx
https://www.microsoft.com/howtotell/reports/report.aspx
http://info.borland.com/about/piracy.html
http://www.mathworks.in/company/aboutus/policies_statements/piracy.html

(These are just a few example sites......)

Specifically, taking the most common example, if you are in India and observe any software piracy of Microsoft software you have the option of reporting the same in the following ways:

Method 1: E-mail piracy@microsoft.com.

Method 2: Call the Microsoft Hotline at 1800-111100 (from MTNL & BSNL landline) or 1800-1021100 (from Mobile and Airtel)

Method 3: Fill out an online reporting form on their web site.

Ofcourse, in Mumbai you can report to the 'Cyber Crime Investigation Cell'

Cyber Crime Investigation cell,
Annex III, 1st floor, Office of the Commissioner of Police,
D.N.Road,
Mumbai - 40001
Email: officer@cybercellmumbai.com

Tel: +91 - 022 - 24691233

Is there some monetary reward? Well, I am not sure!! But this does throws some light!! :-)

And check out some true stories of those who indulged in 'Software Piracy' and about the Monetary rewards at http://global.bsa.org/faces/index.html

Don't use Windows for Internet Banking

Came across this must read article, which I thought is a must share when we live, connect, commerce so much online these days. The article (dated 08 Oct 09) stems from deposition by the New South Wales Police, Australia during a public hearing on Cybercrime  and can be found here.

The article is rather simplistic as it does not goes into technical details, but does drives home the point. The recommendation to use Linux clean boot or using iPhone is pretty sensible and recommended.

An extract of the article:
" Cybercrime expert endorses Linux, iPhone when banking online.
Consumers wanting to safely connect to their internet banking service should use Linux or the Apple iPhone, according to a detective inspector from the NSW Police, who was giving evidence on behalf of the NSW Government at the public hearing into Cybercrime today in Sydney.

Detective Inspector Bruce van der Graaf from the Computer Crime Investigation Unit told the hearing that he uses two rules to protect himself from cybercriminals when banking online.
The first rule, he said, was to never click on hyperlinks to the banking site and the second was to avoid Microsoft Windows."

Of course I don't use Microsoft Windows - simply see no sense in spending good money on a legal copy - when I can do all my work (including word processing, presentations, graphics, multimedia) and more in my Linux distributions - Ubuntu (home use) and Debian (Office use).

We need to be much more careful and aware and consider this startling statistics, (thank your stars if you are not already a victim):
"Symantec has release a report indicating that cyber crime has surpassed illegal drug trafficking as a criminal moneymaker, and 1 in 5 will become a Victim." - from this site

And in case you are using Internet Explorer (any versions!!), the default Web-browser in your Windows OS, please do yourself a favour and switch right now. The IE browsers are bloated, slow, insecure, and doesn’t render the web correctly. Check out this BLOG on why Internet Explorer 8 sucks!! and this website on Why Internet Explorer is unsafe. Though IE8 has improved a lot (check here - read the comments too), it still has some way to go (wait for IE9???). Also do yourselves another favour and learn/be-aware about modern, standards-compliant browsers.

Though I am a big fan of Firefox (it is extensible with excellent add-ons, secure, and Open Source), you can try out other light-weight browsers too like Opera, Camino (on Mac OS), Chrome etc. Here is a long list of web-browsers!!

Tuesday, October 13, 2009

Useful 'Porn Mode' in Web Browsers

Known widely as 'Porn Mode', now every major browser ( Firefox 3.5 or >, IE8 or greater, Google Chrome had it since inception, Apple's Safari had it since 2005!!) comes with a 'Private Browsing' feature. No more do you have to remember to go post browsing to 'preference/options' menu and clear your caches, saved data/passwords etc (though this is still a good habit!!).


When browsing the  web where danger lurks around every click, one clamours for unobtrusive privacy. As the name 'Porn mode' suggests (no rocket science there in choosing the name!!), it is meant to hide your (embarrassing!!) browsing data and habits. It is most useful as a security tool though, when you are using public Internet access systems, like in Cyber-Cafes or your office systems. You must have noticed that financial web-sites (like banks, e-shopping etc. sites) warn you to close your browser windows post usage so as to delete 'cache' data. This 'warning notice' may become history if the fincancial web-server can recognise that the user is using browsing in 'Porn Mode'!!

In Firefox 3.5 or greater, a mere “ctrl+shift+p” will put Firefox into “Private Browsing”, not saving even a 'bit or byte' of history to disk (Note: I don't use 'IE8 - so go find out  yourself !). Further, rather than opening a new window, it caches off your currently open tabs, closes them, and puts the new porn mode tab as the current tab, all in the same window. When you’re finished, stopping private browsing will restore your tabs from the saved cache, including any text you might have typed in any form field.

So go ahead - make merry with the 'Porn Mode' on your browser :-)

Tuesday, September 01, 2009

Credit Card Security

Credit Card usage has its own advantages and convenience. Not to mention, the Credit Card should be also used safely and judiciously, and one should be aware of the risks associated with it.

One important aspect the protection of the CVV number (three digit number found at the back of the card!). Your credit card number and date of expiry can be easily found (from swipe machine etc), but the CVV number is required if the CC is to be used in places where you do not present the card (like online transactions!!). SO PLEASE PROTECT THAT 'CVV' NUMBER BECAUSE IF SOMEONE KNOWS YOUR CVV NUMBER THAN THEY CAN BUY ONLINE USING YOUR CC INFO. This is critical in instances when we hand over our CC in restaurants, petrol bunks, shopping malls etc.

Please follow these simple CC protection measure:-
(a) DO NOT photocopy your Credit Card EVER!!
(b) Commit your CVV number to memory and blacken the CVV number with a permanent marker so that it is unreadable. Else put a small opaque tape over it.

The above small measure makes your CC usage safer (but not risk proof!!!)

Friday, August 14, 2009

Trusting the Administrator

Read this interesting article in Slashdot

"I'm a manager at a startup, and decided recently to outsource to an outside IT firm to set up a network domain and file server. Trouble is, they (and all other IT companies we could find) insist on administering it all remotely. They now obviously have full access to all our data and PCs, and I'm concerned they could steal all our intellectual property, source code and customers. Am I being overly paranoid and resistant to change? Should we just trust our administrator because they have a reputation to uphold? Or should we lock them out and make them administer the network in person so we can stand behind and watch them?"

Very relevant to my current job requirements and something that I have been persistently asking around.

The most apt answer that I felt answered this query was by mysidia:

"This suggestion above is equivalent to proposing that managers have to learn electrician skills to wire the most important room in the building, for fear the paid electricians might sabotage it, or they have to learn locksmith skils to key the locks on the most sensitive file room, because they can't trust locksmiths not to share a copy of the key or sneak in one night.

The simple fact is the management of key systems should be entrusted to skilled IT professionals whose primary responsibility is maintaining consistent, operational, available systems.

That doesn't just mean setting up systems and forgetting it, it also means implementing secure backups, monitoring audit trails, managing the complex access controls, monitoring system logs, and correcting problems."

And by Eskarel

When you hire an outsourcing company, you're hiring the company, not it's employees. You do due diligence on the company, it's achievements, it's reputation, and you hire the company. You sign a contract with them, with the same sorts of conditions you'd stick in a regular employment contract to try and ensure that you're going to get what you're paying for. The employees of the outsourcing agency are not your employees and there's really nothing you can do about them because your contract isn't with them, it's with the agency.

That doesn't of course mean you just go with "whatever you decide" on non staffing issues, the company works for you the same way an employee would and you take their advice as appropriate, but who they hire is really none of your business, so long as the company meets its contractual obligations to you. Most of the outsourcing problems are caused by companies not realizing that the outsourcing agency is essentially an employee and not writing stringent enough contracts, or hiring the cheapest option without looking at their ability to actually deliver(which is no different than hiring an18 year old to do a job which requires substantial education and experience simply because you can get them on the cheap).

Not all outsourcing is done on the cheap, sometimes it's done because it's more efficient that way. It's always good to have multiple people with your skill set to bounce ideas off of, and to have backup for absences and the like, but most smallish companies can't afford to have 3 or 4 DBA or sysadmins, etc. So they contract out to another company who, because they provide services to a number of companies, can afford to have more extra people to fill key roles. Their economic situation allows that.

There are advantages to outsourcing beyond just being cheaper, but there are disadvantages to. You don't have the same control of the staffing, you don't have the same kinds of relationships with the staff, and the loyalty of the staff is generally to their employer and not to you. That's not always a huge problem, but sometimes it is, and if it is, expect to have to pay for a redundant DBA or sysadmin so you can keep your place going when they go on vacation. There are pluses and minuses to everything, including outsourcing, and sometimes outsourcing isn't done because it's cheaper, and sometimes when it is, it doesn't turn out to be. When you run your business based entirely on trying to reduce costs, generally you eventually go out of business, that applies to pretty much every field, not just IT our outsourcing.

This is pretty interesting!! You have to follow the comments on this article to understand the passionate views of many, some pretty sane like this one, which I completely agree:

Right, and it's not just an issue of outsourcing. The reason you should trust your network administrator is that you *have to* trust your network administrator. Whether it's in house or outsourced, you have to trust someone to do the work. The only alternative is to do it yourself-- like literally you, personally.

If I'm your network administrator and I come into your office and work for you directly, I could still read your emails, steal your IP, etc. You could ask me to set up the security so that I can't do that, but you still have to trust me to do that well and not leave a back-door for myself. Also, you should understand that it might inhibit my ability to do some things. For example, if I encrypt your disk so that I can't even access it myself, and then you lose the password, I won't be able to recover anything on your hard drive. Sorry.

So that's the deal. You can try to institute some checks and balances, but there's a certain amount of trust inherent in the job. If you're concerned about security, then make the effort to find people that you can trust, and recognize that you might have to pay extra for better employees. It's an issue of what your priority is when you hire someone (or hire an outsourcing company). Which is most important, getting the person you trust most? Getting the person with the best resume? Getting the cheapest solution available?

Those might be 3 different people. Under most circumstances, I'd pick the person I trust.