by Michael Smith (Veshengro)
London, Wednesday, May 14, 2008
The most interesting, to me at least, part of the seminar was – no, not the food, though that was great as well – more than anything, the presentation by Graham Taylor of Open Forum Europe.
Here it was especially interesting to learn that, while the EU and the European Parliament, etc., claim to be open and all that, citizens wishing to – properly – interact and communicate with their MEPs are “forced”, by designs, to have to have computers running a particular operating system and also a particular piece of software from the same provider as the operating system, that is to say that the computers MUST be MS Windows and run Internet Explorer and Windows Media Player. Other operating systems, especially here Open Source Software and Operating Systems, do not work in that field. This is interesting to learn but, at the same time scary to some extent, realizing how much influence a certain software giant has over everything and that Europe and its institutions has locked itself so tightly into Microsoft and other proprietary software.
No, I am not Windows bashing – that would leave too many shards – and neither was the Open Source Forum really. Many Open Source Software can be run happily on Windows.
The other seminar sessions that I attended too were most interesting and informative and I would be happy to repeat such experience any day if the opportunity would present itself.
Unfortunately I had to leave straight after lunch needing to return home urgently for personal reasons. Therefore I also had to forego the other seminars sessions, especially the cases studies. I was particularly interested in the study of the use of Open Source Software (OSS) with the Oyster Card. Alas, as they say, such is life.
Obviously, to a degree, the forum, though being kept “vendor agnostic”, nevertheless, as it was sponsored by Red Hat Enterprise, had a slight RHEL slant to it. This was fine, however, and anyone could learn a great deal as to OSS and as to where the OSS “movement”, for a movement it is, is headed.
The way Open Source Software (OSS) is going and the great quality of the products, more often than not superior to that of the proprietary software available for lots of money, from operating systems, whether Red Hat or Ubuntu, to applications, and everything else in between, we should be seeing a lot more Open Source Software in use and that not only by the geek, the home user and the SMB sector but in enterprise and especially in government.
The United Kingdom in both industry and especially in government as the great, if not the greatest, laggard when it comes to the uptake, implementation and use of OSS. Aside from the USA, the world leaders as far as the use of Open Source Software and Technology is concerned are France, Germany and Spain, and that not only as regards to being leaders in Europe in this field.
In Germany and France we are twice more likely to see the use of Open Office than in the UK.
It is true that the world still uses to over 60% Microsoft Office, followed immediately by Open Office with a share of 25%. All other systems are just about “also rans”.
Many people, and I am sure some of my readers are, or have been, among them, see Open Source Software, including the operating systems, even such easy ones as Ubuntu, as the domain of the geek or of those that are anti-Microsoft. This is, however, not so.
Many also think and try to make it look as if Open Source Software movement and FLOSS movement are all about Linux-v-Microsoft, but this is not the case. It is a lot more nowadays. It is primarily a case of freedom, freedom in many points.
© M Smith (Veshengro), May 2008
Open Source Forum 2008
Anti-virus software is not the only computer security tool
The truth is that anti-virus software is but one of many computer security tools and the way things are going we seem to be needing ever more. This is a shame and could turn people off the Internet and such all together.
By Michael Smith (Veshengro)
When Mike Saign received an email - purportedly from an eBay auctioneer - accepting his rather low offer for a high-end golf club he reckoned there to be something fishy about it and smelled a rat.
The sender of the email claimed that his PayPal account was down and asked Saign to wire payment to him via Western Union. Instead, however, having his suspicions aroused, Saign, downloaded Iconix e-mail ID, a free tool that pegged the e-mail as a fake.
Then, having saved from being scammed, Saign disabled Iconix and hasn't used it since. Because, he says, he feels like the security software in a normal computer keeps you away from most bad things.
That, however, is not necessarily so and I am sure those of us in the know would rather disagree with him in that.
In fact fraudulent e-mails and tainted and “contaminated” websites are more prevalent than ever. Spam, much of it pitching fake drugs and financial scams, according Symantec, accounts for 80% of all e-mail. The number of new strains of malicious programs has increased fivefold in 2007 over 2006, and about 20,000 new malicious programs are unleashed on the Web each day, according to AV-Test Labs.
Most consumers are, however, in a real and serious fog about the array of security tools they can – and probably should – use to protect themselves.
Craig Spiezle, Microsoft's director of security and privacy, says his own wife couldn't tell anyone which security tools they really ought to be using. "The big challenge we're dealing with is the volume and velocity of new threats," says Spiezle.
The thing is, though, if Microsoft actually would configure their software in a better way – we know it can be done from the likes of Linux (a system that I use for work) – people would actually have no need for such an array of security software which, again, also slows down the performance of the computers often. Especially here the performance of the older models and those with a low memory.
Because we are basically in a pandemic situation as far as consumer PC infections go that (home) PC users are left to decipher for themselves what set of security products they ought to be using and how much protection they are actually getting. No one has, as yet, figured out a business model to cure that.
There are many tools in the armory of computer security, but each will only offer narrow protection,therefore, consumers need to try to understand what each of these tools actually tackles.
Anti-virus programs fail to catch every malicious program. So keeping anti-virus subscriptions current isn't enough, though it does a great deal. Consumers must also get in the habit of quickly installing all software program updates from Microsoft (With caution, I would add there. Always do a “manual” install and choose what you want to install), Apple, Adobe, Mozilla and Java, because many contain the latest security patches.
Beyond that, consumers should consider using:
Certified e-mail: Iconix and Goodmail each sell services to businesses that assure the authenticity of e-mails sent to customers.
Iconix recently launched e-mail ID as a free program consumers can install in their Web browser. The program verifies e-mail sent from 500 companies, including eBay, PayPal, Citibank, Amazon.com and Expedia.
However, the Iconix program can also be a pain the the backside, I am afraid to say, and sometimes takes quite a while to deal with the emails. It also does not work, I have found, with email clients other that Outlook, and with only some of the Web-based services.
The best way, in most cases, as far as untrustworthy emails, phishing emails and scams are concerned, is good old fashioned common sense. If something is too good to be true it more than likely is. If someone tells you you have won a lottery that you have no idea of ever entering then it is a scam, as simple as that. Bill Gates also does not give away any of his money to the likes of you and me. So, do not forward such scam emails. They clog up the Net.
Web page scanners: These tools use varying technologies to gauge the reputation of most Web pages. Programs such as AVG's LinkScanner, ScanSafe's Scandoo, Trend Micro's TrendProtect, McAfee's SiteAdvisor and Finjan's SecureBrowsing grade Web pages as safe, unsafe or questionable.
Web scanners aren't perfect. But they provide a layer of protection against what has become cybercrooks' favorite way to spread malicious programs: via the Web. "The more layers you have, the safer you are," says Roger Thompson, AVG chief research officer.
While, once upon a time, not so long ago, I have been one of the greatest advocate of AVG and would tell everyone to get it, anyone who has read my recent article on the AVG8 program will know why I have changed my tune.
Browser security tools. Microsoft's Internet Explorer 7 (anyone using IE7 must their head examined – I was forced by something from MS to install it but refuse to use it) and Mozilla's Firefox 2 (this is the browser that cannot be too highly recommended for security and safety), the most widely used Web browsers. Both those browsers offer anti-phishing filters that alert users if they try to click to bogus websites set up to fool them into typing passwords and other sensitive data. Microsoft, however, distributes IE7 with this feature disabled, so users must choose to turn it on, while in Firefox 2's anti-phishing filter is always on.
There are no 100% solutions in security as far as computers are concerned for you tell a hacker that a system is safe and the first thing he is going to do is set himself the task to crack it. This is the same with viruses. As soon as the virus writers realize that their virus is being caught they change the code and create a new one. Only the greatest of vigilance as to what sites we visit and what email we deal with can give us some measure of safety, combined with some good tools. But, common sense is also useful on the Internet; let's use some more of it.
© M Smith (Veshengro), May 2008
Bluetooth: A Danger to Privacy
Bluetooth leaves you open to intercept by anyone
by Michael Smith (Veshengro)
If you are concerned about your civil liberties and privacy then it may come as a shock to you to discover that you may have, unwittingly, been allowing your phone to signal your every move to the great wide world, including your communications.
Bluetooth, which is, as most will know, a wireless link built into many mobile telephones, makes our movements trackable by anyone equipped with a PC and an appropriate receiver. And this means ANYONE, not just the security services and the police, if that would not already be bad enough. Anyone, as the word says, can listen in and track where you are if they have the right equipment.
Vassilis Kostakos at the University of Bath in the UK placed four Bluetooth receivers in the city's centre. Over four months, his team tracked 10,000 Bluetooth phones and was able to "capture and analyse people's encounters" in pubs, streets and shops.
Bluetooth is now more of a privacy threat than the more frequently publicised RFID chips, Kostakos says. "If people are worried, they should turn off the Bluetooth function on their mobile phones."
Not everything, as we can, yet again see, that is supposedly good for us, is so.
“Oh, but without my 'Bluetooth' I cannot make phone calls on the move”, I hear some complain. “Can we not just make those things safer?”
Well, we probably could and could add encryption, if you, the consumer, is willing to pay the high costs then.
What is wrong with safely stopping your car, motorbike or your bicycle, to take or make that call? Also, no call is that important that it cannot wait until you get to a safe location where to return the call or make a call.
If you are concerned about your privacy, as said, turn the Bluetooth function off. While it may be something that can and does make life easier it also, yet again, is something that can be used to invade our privacy and to spy on us.
© M Smith (Veshengro), May 2008
BAILEY SOLUTIONS: LATEST RECRUIT TO SOLSEARCH
The library software provider of choice for legal and professional services firms, Bailey Solutions, has joined forces with Solcara to provide SolSearch for its clients.
Bailey Solutions and Solcara already have a number of mutual clients such as William Fry Ltd, A&L Goodbody and Lane and Partners. As part of the agreement, Bailey Solutions will resell SolSearch as its preferred search solution. The companies will also support each other in joint marketing and sales activities.
SolSearch was selected as it is the most widely used federated searching tool in the UK and is already integrated with all primary legal research in the UK and Ireland.
Solcara’s Managing Director, Rob Martin said:
“Having Bailey Solutions as our partner and reseller is another major step forward for the federated search technology SolSearch, now the premier search solution for legal and professional services firms. We very much value the help and assistance this new agreement offers and we are looking forward to working with Bailey Solutions”.
An initial heads of agreement was signed last year and commences this May 2008.
AVG 8.0 – What a Disaster
by Michael Smith (Veshengro)
For many years I have used Grisoft's AVG anti-virus software, the FREE editions, from about 5.something onwards. Until recently I have had AVG FREE version 7.5 on my computer and have had absolutely no problem with this software whatsoever. Every virus that circulated and somehow came my way AVG dealt with immediately and dealt with it well.
I have had heard rather negative reports about the latest version of the AVG anti-virus program from Grisoft, namely AVG 8.0, including in the pages of “Computer active” magazine, but have reluctant to believe them I have always been rather positive inclined towards AVG, as it has done a great job for me over the years. Every virus, as said already, that was in circulation on the Internet and cam my way, AVG always dealt with and killed them with, maybe one or two zero day attacks that I had to deal with in another way, but that was a number of years ago. But it is NOT any viruses that may have been let through in this instance.
The other day I was prompted to install the upgrade from AVG 7.5 FREE to AVG 8.0, as AVG is removing support from AVG 7.5 on May 31, 2008, and this is when the problems began.
Having followed the advice to upgrade to AVG 8.0 from AVG 7.5, due to the already mentioned fact that the company if removing support from the latter in the form of updated and we all know that without the virus updates any anti-virus software is useless – I did so downloaded AVG 8.0 (build 100) and installed it on my PC. This was, as I found out, a very bad move and idea indeed.
Why? Because nothing worked anymore. The PC kept freezing up and had to be crash-shut down again and again. I spent, literally, hours trying to get the PC to work with the AVG anti-virus. After about five or six attempts I then decided that enough was enough and that AVG 8 was/is useless and a problem I decided to uninstall AVG 8 and then to simply get another free anti-virus program.
You would think that uninstalling it should have been easy but do not be fooled. It took several attempt and working basically in safe mode to actually being able to get the darned thing off the PC again. Phew!!!
I shall think that I will never again, in my live, most likely, unless some serious improvements be made to the software, use and especially recommend AVG anti-virus and other security software to anyone and especially our readers, as I have done in the past.
So, now we have had a PC without protection against viruses and such. What to do?
I simply found the website of BitDefender and downloaded the latest version, BitDefender 10 and installed the same. The interface and all is a little bit a learning curve as it is not as intuitive as was AVG but the scanning options are much broader, especially the ability to predetermine scan times for a variety of scanning tasks. It has to be said though that a full in depth scan can take hours, literally.
On the other hand, during that deep scan, two viruses were located that AVG 7.5 never seems to have come across. They were, however, not in any dangerous location but simply in the Temporary Internet Files. One, a Trojan, BitDefender was unable to isolate but, as far as I know, should now have gone as I removed all files out of the Temporary Internet files. The only way to deal with those things.
So, in summing up I must say that what “Computer active” said about AVG 8.0 is probably right and they did not even mention the fact that it is difficult to get a PC to work with that software and that it is extremely difficult, to say the least, to get rid off AVG 8.0 again once it is on the PC.
I cannot, as yet, be the judge as regards to BitDefender, as I have not had it on the system long enough to see how it performs under attack.
I may just have had a strange experience with the latest AVG but I had the problem with a download and with a copy on a CD. So, as far as I am concerned the jury had returned and found the defendant guilty as charged. Be careful with the latest version of AVG unless you have a lot of resources, e.g. a RAM of 512MB or higher.
© M Smith (Veshengro), May 2008
15 ways to lose your database
by Peter Mitteregger, European Vice President, CREDANT Technologies
Arguably an organisations most vital asset is its databases, often containing financial infor
mation, customer and employee data and intellectual property. There have been many articles written that examine the risks posed of data being exposed and the potential damage caused. In addition, external threats have long been recognised with billions of pounds spent strengthening defences to mitigate against them yet there is little acknowledgment of the very real threat from within. The statement ‘don’t leave your valuables on show’ is a simple principle so why is it often ignored by Corporate UK?
It is proven to be easier to bribe someone on the inside (or even implant them there) to gain access to sensitive data. Leaving this risk aside, how often has someone left your organisation taking company stationary with them? Do you know what else has been taken? Could they have sneaked out with sensitive material? What about a copy of the entire corporate database? Would you even know if they had?
Below, I’ve identified the most common techniques individuals will employ to copy sensitive data :
Legitimate Access Yet Inappropriate Use
Let’s be realistic, employees need to have access to corporate data in the normal course of their duties. Increasingly today, this need is 24 hours a day - 7 days a week and is not restricted to within the corporate walls or to company owned devices. It is this need that is opening up one of the biggest and growing weak points for Corporate UK as data is seeping out via unprotected end-points, a significant number of which the company is unaware exist, or they are simply outside the company’s domain, such as private USB sticks or iPods.
To illustrate, an employee in sales may need to legitimately access customer records whilst on or off site and during a normal day may do so up to 100 times, another employee in R&D may need access to the secret formula for a product that’s in development whereas another employee in the marketing department may need to access the marketing plans for this new product’s launch and email them to the various agencies tasked with delivering the plan. However, there is no viable reason for all of these different employees and departments to be able to access all of this information, in the same way, and do the same things with it. In many instances, the company may be legally obligated to limit access to information on a need-to-know basis.
Access must be restricted to just the records that are needed to perform the task, with control over which bits of each record can be viewed, combined with limiting what can be done with the record.
If there is no obvious explanation why an employee should need to be able to access confidential and sensitive data, whilst off site, then they shouldn’t be able to. It would be prudent to employ a solution that can detect devices trying to connect to the enterprise and sync up with corporate data. Additionally, if there is no reason why they should need to make an electronic copy of these records – be it to a corporate or personal endpoint such as a CD, a USB/Memory stick, an iPod or even a Blackberry, then they should not be able to do so. If there is a valid reason why they need to make a copy then it should be force encrypted with a solution that does not impede the system, regardless of the device it is stored to, to ensure the integrity of the data is protected once away from the safe corporate environment.
By the same token, if an employee does not need to print a copy of the data then they should not be able to do so and even if they do, this should be regulated as I’m positive that there can be no genuine reason for complete records to be printed. Perhaps an alarm bell should be sounded if someone does print the entire database and a means deployed to ensure that it is not removed from the premises.
Another way to identify if an employee is abusing their access rights is if their usual behaviour alters and they suddenly start accessing a greater number of records then usual for longer, or even shorter, periods of time. This could indicate that they are writing the records down in some format to bypass any security restrictions in place.
In the case of a disgruntled employee determined to cause mischief records could be altered, or even worse deleted, thereby damaging the reliability of the data.
Another danger is if an employee wishes to steal a copy of a database and may attach it to an email and send it out legitimately through the corporate gateway. A savvier employee, worried at leaving a trail, may try to bypass this by uploading the file to an external system, such as yahoo, hotmail or a hosted document storage and management solution.
There have been a few instances of people seeking employment to steal data to order or even for an employee persuaded to divulge corporate secrets for financial gain.
Opportunistic Access Is Still A Real Risk
There are some risks that aren’t hi-tech and therefore harder to detect and even harder to protect against. For example, the business case for a printed hard copy of sensitive records needs to be strong as an opportunistic may access this and make a photocopy of it, completely undetected!
Another increasingly recognised threat is the mobile employee, justifiably working while travelling; either on the train, in a service station or another location, with someone looking over their shoulder and making a note of material displayed on the screen.
One further, really obvious, risk is writing down and/or sharing passwords. This is a truly naïve practice, with no justification, yet it is still widely abused today.
Illegitimate Access So Of Course They’re Up To No Good
The easiest, yet inexcusable, way for data to be violated is by an ex-employee whose access rights have not been timely revoked accessing the network remotely, perhaps initially just to see if they can, and then tempted into taking liberties with this oversight.
Another potentially soft target is a portable endpoint; such as, but not limited to, a laptop, blackberry or USB/Memory stick, that is misplaced or stolen. Should the device be unprotected then any data stored on it is exposed. Additionally, in the case of a laptop or blackberry, it may prove to provide a back door to the corporate network.
So What’s Corporate UK To Do
It may seem like a nightmare with so many trusted employees out to steal your most vital asset yet there are ways to mitigate against these risks :
Restrict access to only those employees who need it and limit what they can see, and what they can do, with the records
Appropriately monitor employees’ behaviour, ideally setting control mechanisms to flag any significant deviations from the norm
Employ a solution that can detect devices trying to connect to the enterprise and sync up with corporate data and force encrypt information when it is removed, legitimately or illegitimately, from the safe environment of the corporate network
Do not make unnecessary hardcopies of records or leave them unsecured
Educate the mobile workforce to the risks posed by their activities and the devices that they use
When an employee leaves, ensure all access rights are revoked immediately
Never leave a written record of passwords
Perform background checks on new employees, including contractors and any periodic workers. It may be prudent for these checks to be conducted at regular intervals to ensure that nothing has changed as is the case for those working with children via the criminal records bureau
Never leave data security up to the end user. It is imperative that this is controlled and managed centrally which can also reduce TCO (total cost of ownership) as machines don’t need to be locked down or brought in to the office to update them
Corporate Governance requires you now to have security and to be able to prove it. Use a solution that includes a central management console – that way every machine is protected and can be tracked.
Box Out : Quick Overview of 15 Ways to Lose Your Database :
Employees able to access a database regardless of their need to do so, with sight of complete records including information that they do not necessarily need to see
Unrestricted downloading of the database to removable media
Employees able to print individual records, or even the full database, in hard copy format
Employees able to access records, in undefined quantities or for unlimited periods of time, providing the opportunity to make a written copy
Records, or even the entire database, altered or deleted
The full database, or individual files, emailed as an attachment
The full database, or individual files, uploaded to an external storage facility/website or a hosted document storage and management solution.
Secure employment for the purpose of having unrestricted access to confidential data with criminal intent
Existing employees being coerced into removing data for financial gain
Ex-employees who have not had their access rights revoked
Photocopy hard copies
Over the shoulder screen theft from mobile workforce
Writing down, or even sharing, passwords
Loss of external or portable media (memory sticks, CDs, laptops, etc) that contain unencrypted information, often during travel.
Misplaced, or stolen, devices (laptops, blackberries, etc) used as a back door to the corporate network
For more information contact www.credant.com
ThreatFire Free Version – Product Review
Review by Michael Smith (Veshengro)
At the recent Infosec 08 I was given a copy of the ThreatFire anti-e-threat tool, which is a FREE program (though a paid for version is available as well) and I decided to install and test it.
ThreatFire, by PC Tools Software, is a powerful PC security tool that, however, can be a little daunting with its many warning and alert pop-ups, of which there can be quite a number; at least to begin with until the program has been instructed as to what to ignore and allow and what to block. In this way it is a little bit like, say, Zonealarm Firewall.
My “problems” as to the amount of warnings and alerts may be due to the fact that I have set the security settings to the highest level. I like to run a tight ship, so to speak, and if leaks can be avoided the better.
If you, like me, run a software firewall – in my case Zonealarm – then you will have quite a number of pop-up alerts to content with as well, every time that ThreatFire, for instance, asks for Internet access to update and such, and so they can be quite a lot. Not really anything bad, I think, to ensure that one's PC is not infected and hacked. In the long run, as I have just said, for security and peace of mind, as fas as I am concerned, this is all well worth it.
The software could do with some intelligent programming, maybe, to understand from the beginning that the likes of Firefox, Internet Explorer, Outlook Express, etc. do go onto the Internet· Then again, firewalls do not come with that as standard either. The program itself, like firewalls, can be instructed to let programs through the next time round and therefore not really a problem, as said before.
Seeing all the threats that are about on the Internet presently, from the ordinary (if there ever is an ordinary one) virus, over Trojans and worms, etc. to outright malicious hacking, etc. and which are distributed via email but also just simply by some unsavory characters inserting malicious code on innocent websites where the then unsuspecting visitor gets his or her PC infected, the more security devices, in this case software applications, the better, as long as they do not clash with one another, and such practice can only be commended. Only one should never ever have more than one dedicated anti-virus program running on a PC. They do tend to clash and often can cause serious problems on a PC.
As far as I can see ThreatFire definitely is a great addition to ones anti-virus/anti-malware armory and considering that the basic version if free there is nothing that you can lose.
© M Smith (Veshengro), May 2008
