Oct 22, 2013

Preparing Your Employees for 'Bring Your Own Device' Policies

Image by Michael Coghlan via Flickr
'Bring Your Own Device' (BYOD) policies have been gaining in popularity, especially among the 18 to 24-year-old working demographic. According to Magic Software, 42 percent of this demographic uses a personal device for work. Smartphones are the most popular personal workplace device at 42 percent, with laptops coming in second at 38 percent. While BYOD has many security challenges, one significant hurdle you have to overcome is the way your employees think. It's common knowledge to put anti-virus software on your computer, but Kaspersky reports that 40 percent of smartphone owners do not utilize anti-virus software. Teaching your employees about the best security practices for smartphones is an essential step in improving your overall BYOD security.

Major Virus Vectors for Smartphones

Apps, especially ones you load from outside of official app stores, may carry malicious code and viruses. Mobile anti-virus and anti-malware applications help cut down on infections, although zero day viruses get around this protection until the virus definitions are updated. Teach employees to only download and install apps from trusted sources and official websites, instead of third-party sites.
Unsecured wireless networks and Bluetooth connections are another way for malicious code to get injected on employee devices. Security settings on Android and iOS prevent devices from automatically connecting to untrusted networks. MMS messages with attachments also provide another way for hackers to get viruses onto the system, according to Qresolve. When employees are careful about what message attachments they open, they cut down on the amount of virus vectors to keep their smartphones more secure.

Device Loss

According to BGR, 113 smartphones are lost every minute in the U.S. If employees store work files or login information on their smartphones, this data could easily be used against the company if the phone is stolen. Anti-theft software cuts down on data breaches by locating the phone if it's lost, or remotely wiping the data if it's stolen. Another point to bring up in training is to tell employees not to store passwords on their smartphones, or encrypt any stored passwords. You can also install apps that provide lock screens for every individual app, preventing a thief from accessing any data stored in apps instead of mobile browsers.

Enterprise App Stores

Instead of letting employees use their own apps for work-related purposes, provide them with approved, secure apps for productivity and utility. While some employees are more productive with their own apps, enterprise app stores do cut down on unsecure data transfer. You provide solutions to your employees for data transfer, cloud storage, collaboration tools, and other essential workplace apps.

Mobile Management

You can cut down on the amount of work managing multiple mobile platforms by using mobile device management (MDM) software that supports iOS, Blackberry and Android phones. Solutions that provide substantial mobile security include features such as virtualized work spaces and secure, self-contained applications that don't interact with the rest of the smartphone's system files.
Enhanced by Zemanta

Oct 18, 2013

Unable To Connect To RDP Server in Remmina

A while back I completely ditched Windows on my work computer, and went to Bauer-Puntu Linux. I've tried doing in in years past, but I've always gone back to Windows for work... Until now.

One of the tools I use on a daily basis to manage my Windows servers is Remmina, which is a multi-protocol remote desktop and ssh client. In general it works great, except there were a few Windows 2008 R2 servers in my environment that would not let me connect with Remmina. When I tried to connect I would get an error saying:
Unable to Connect To RDP Server x.x.x.x


I finally figured out a fix. Here's what you do:

  • Right click on the problem server, and click Edit
  • Click on the Advanced tab


  • Under Security, change the drop down from Negotiate to TLS


  • Click Save
That's it, now you should be able to remote desktop into your Windows 2008 R2 servers in Remmina!

Enhanced by Zemanta

Oct 17, 2013

When It Comes To Anti-malware, For God's Sake Listen To The IT Guy!

Malware logo Crystal 128.
(Photo credit: Wikipedia)
So the other day my dad tells me that he can no longer send emails from his email account. When he tried to send it, he got a bounce back from his email service provider saying that his account had sent too many suspicious emails, and he had to call support.

What does that sound like? Some kind of spam malware right? Maybe a worm or something right?

Well he calls his email provider's tech support and they said he had to run an anti-malware tool on his machine and send them the report before they would turn his email service back on.

First he ran Microsoft Security Essentials, and didn't find anything. He said he wanted to run an anti-spyware program too. At that I told him that I recommend Spybot Search and Destroy, as well as Malwarebytes. I told him how both are free, and very good at detecting and removing malware.

Well yesterday morning he was running a scan from a program I've never heard of called SpyHunter 4. He told me he paid for the program, and is running it.

WHAT? Why would you pay for a program when I gave you two great programs that are free for personal use? Two programs that have been proven to work, and are NOT rogue anti-malware programs?

Wait, what? What's a rogue anti-malware program? I'm sure you are asking... Here's a description from Wikipedia:
Rogue security software is a FraudTool (a form of Internet fraud using computer malware) that deceives or misleads users into paying money for fake or simulated removal of malware (so is a form of ransomware)—or it claims to get rid of malware, but instead introduces malware to the computer. Rogue security software has become a growing and serious security threat in desktop computing in recent years (from 2008 on).
That's right boys and girls, there are software companies that make programs that look like anti-virus or anti-spyware programs, that really harm your computer. That is why you can't just use any willy-nilly program you find out there! Especially if your IT guy already gave you two programs that work!

Anyway, I checked around and although SpyHunter wasn't on any current known rogue anti-malware lists, it was once listed back in 2004 because of their misleading marketing practices. Here is a full explanation from Spyware Warrior:
Enigma's SpyHunter anti-spyware application was listed on this page primarily because of the company's history of employing aggressive, deceptive advertising. The company was also known for exploiting the name "spybot" in its domain names and online advertising. These objectionable business practices were employed primarily from late-2002 to mid-2004.

Sometime during summer of 2004 the company halted the most obnoxious and objectionable aspects of its online advertising. It also unloaded all the "spybot" domains (which were promptly picked up by Paretologic for its XoftSpy anti-spyware application).

While there are still unresolved allegations that SpyHunter transmits the Windows Product ID from users' PCs, we can no longer classify this application as "rogue/suspect." Nonetheless, SpyHunter -- at least in its current state -- cannot be recommended because of its mediocre performance as an anti-spyware scanner. Testing indicates that it does not recognize some well-known spyware installations and has difficulty removing critical spyware/adware files even from those it does recognize. Given the many excellent competing anti-spyware applications that are available (some for free), users would do better looking elsewhere for trustworthy anti-spyware protection. 
 
Here are a few good lists of known rogue anti-malware programs:
So long story short, if your IT guy recommends some good free programs, don't just go it alone and disregard what they say. Chances are, they are recommending those products because they have used them plenty of times to know they work. Plus, if you screw around and download the wrong program, you could find yourself in a world of hurt by actually installing something worse than you are trying to remove. I think my dad was lucky this time.

Has this happened to you? Tell us a story about how someone you knew disregarded your recommendations and messed things up worse in the comments.
Enhanced by Zemanta

Oct 16, 2013

Fail2ban Proven To Work On My Private Email Server

English: Tux the Penguin is the official emble...
(Photo credit: Wikipedia)
I mentioned a really great program for Linux that actively combats potential hackers a while back. It's called fail2ban. In short, what it does is monitors failed login attempts in all of your logs, and if there are too many attempts on a potential service, it adds the IP address of the attacker to your iptables firewall rules.

Well, for the last few weeks my email server was blocking my own IP address. It would do it several times per day, and it was driving me nuts trying to figure it out. In order to check my email, I had to SSH into my server and reset the firewall rules. Fail2ban was clearly working.

I finally figured out what was causing the lockouts. My daughter has an iPod touch with email configured on it. I had reset her password a month or so ago, but never got around to updating the credentials in her iPod.

Well, it clicked the other day when I saw her playing with it. I updated the password, and voilla! No more lockouts!

Good work fail2ban! It works so good, it locked me out!
Enhanced by Zemanta

Oct 11, 2013

Accessorize Learning: Google Glass Will Change the Way Professors Teach

Photo by tedeytan via Flickr

When it comes to technology in the classroom, 38 percent of college students say they can't go ten minutes without using some type of device, according to a study conducted by Wakefield Research and Coursesmart in 2011. It's no wonder, then, that college professors are eyeing the many benefits of using Google Glass in the classroom. This highly anticipated technological breakthrough has the potential to change the way teachers instruct in both in-person classrooms and online settings.

Revolutionizing training for medical students

Google Glass features an on-board point-of-view camera that can be utilized by professors to create powerful educational videos to be used in the classroom, as well as online. The applications for this technology could revolutionize the way medical students learn about surgical procedures, enabling them to see through the eyes of a surgeon during real-life procedures. Vet techs attending an online program through a school such as pennfoster.edu can see professionals up close and personal with animals. These videos can be presented at lectures to create a question-and-answer approach to learning while students watch the application of their studies come to life.

Step-by-step how-to videos for use in and out of the classroom

In simpler applications, the POV videos can be used for other technical courses, such as engineering, chemistry and physics. Professors can use the videos to either enhance or replace traditional lab experiments, creating a virtual learning experience ideal for students who are attending classes online. Step-by-step videos can help students learn better, as they can be viewed repeatedly, compared to an in-class demonstration that can only be viewed once.

Enhancing the virtual learning experience

Remote teaching and tutoring can be more accessible using Google Glass. While current video chat enables students to see professors, this technology does not allow for easy document sharing, which can be done with the Google Glass application. Instructors can point students to appropriate study guides during a conversation rather than following up afterwards with an email. This collaborative approach to one-on-one teaching is ideal for schools that offer tutoring services or online university courses that require a more personalized approach.
The ability to live stream video might enable professors to simultaneously teach students in the classroom while also facilitating distance learners to attend the class from their laptops or mobile devices. This could change the way e-learning is approached, giving online students the ability to actually see into a classroom.

Note-sharing capabilities improve class interaction

Professors might be able to change their approaches to lecturing while using Google Glass by referring to their notes for each class, instead of placing them on a podium or writing them out on a chalkboard. With the ability to share files, these notes could be shared with an entire classroom, enabling each student to focus on interacting in class instead of quickly writing down notes. The technology behind Google Glass will enable professors to increase engagement with students both in the classroom and online, providing a more fruitful and positive learning experience for students, no matter where they are.

Oct 10, 2013

Cheap VPN Service For Torrenting and Protecting Your Anonymity Online

MPAA doesn't appreciate Ars Technica's decided...
(Photo credit: joe.ross)
Well it finally happened to me. After years of torrenting I finally received a notice from my ISP that I had violated a copyright or two. Well, more specifically my dad received the notice because I was torrenting at his house... Anyway, that's neither here nor there.

I have been using PeerBlock for a long time, but apparently it wasn't good enough, and the MPAA's third party company contacted my parent's ISP (SkyBeam) about the infringement. They didn't threaten any particular actions, it was just a notice. Although I'm sure future infractions would result in my parent's Internet being shut off.

Anyway, at first I considered configuring my torrent clients to use Tor, but apparently that is a bad idea. Another alternative a friend of mine suggested was to ditch Bittorrent and use Usenet. He uses a Usenet service with Sick Beard and pays $10 per month. Well I found something cheaper, a private VPN service!

There are many VPN services out there that protect your information. I settled on TorrentPrivacy though because if you pay annually, it comes out to only $3.99 per month! Plus they were listed on Torrent Freak's 2013 list of VPN's that actually protect your privacy.

TorrentPrivacy works on Linux, Windows and Mac. They offer both OpenVPN connections and PPTP. I had some issues setting it up at first, but that was because PeerBlock was blocking the connection. Once I allowed it, everything was fine.

Bam! Now try to snoop on me SkyBeam! Suck on it MPAA!

Do you use a private VPN service? If so, which one? Why did you choose it? Let us know in the comments.
Enhanced by Zemanta

Oct 4, 2013

The NSA Hasn't Hacked Tor... Yet

English: Tor Logo
English: Tor Logo (Photo credit: Wikipedia)
In the latest revelation from NSA whitleblower, Edward Snowden, it turns out that the NSA and Britain's GCHQ have been targeting the Tor anonymity network. Why? Because that's where the hackers, and criminals play!

Of course, those of us who value our privacy play there too, but that's neither here nor there...

Anyway, although the NSA and GCHQ have some proof of concepts, they have yet to actually hack it according to Snowden!

Via RT:
According to the Guardian’s James Ball, Bruce Schneier and Glenn Greenwald, the NSA’s “current successes against Tor rely on identifying users and then attacking vulnerable software on their computer.”

“While it seems that the NSA has not compromised the core security of the Tor software or network, the documents detail proof-of-concept attacks, including several relying on the large-scale online surveillance systems maintained by the NSA and GCHQ through internet cable taps,” the writers add.

The Guardian has so far published three top-secret government slideshows used to discuss the Tor network and possible vulnerabilities that might compromise users if properly exploited.
So they haven't hacked Tor, but they have found ways to exploit user's computers rather than the Tor network itself. We actually knew that back in August when we learned that there was a vulnerability in the Windows version of the Tor Browser Bundle. Linux and Mac versions were uneffected though.

So be sure to keep using Tor. As of now it is still effective it would seem. Also make sure that you keep your Tor software up-to-date, and make sure to disable javascript, and cookies as that is the primary method they use to compromise you.

Also, don't forget that Tor is built into Bauer-Puntu Linux!
Enhanced by Zemanta



Twitter Delicious Facebook Digg Stumbleupon Favorites More

 
Design by Free WordPress Themes | Bloggerized by Lasantha - Premium Blogger Themes | stopping spam