Posts Tagged ‘protection’

12 Security Resolutions for 2013

Sunday, January 6th, 2013

Among your standard New Year’s resolutions—lose weight, stop smoking, be happier—you should cruise creation some pledges to improved secure your digital life. You competence even be healthier if we can forestall a highlight of a digital disaster, like malware wiping out your PC, carrying your online accounts hacked, or apropos a plant of brand burglary since of a phishing fraud or information theft. With that in mind, here are some confidence resolutions we should cruise for a new year.

Use PIN insurance on your mobile devices


Smartphones and tablets are mini computers, and if they get mislaid or stolen, others might be means to entrance your email and amicable networks, crop by your photos, files, and calm messages, and entrance other accounts that you’ve downloaded apps for. However, we can capacitate tighten shade insurance to need a PIN or cue before regulating your device.

How we spin on PIN insurance varies between devices, though we should be means to find it in your phone or tablet’s settings app. A cue or PIN isn’t foolproof, though it’s a good initial line of invulnerability opposite snoopers and would-be information thieves.

Install an anti-theft app on your mobile devices

If your smartphone, iPad, or inscription gets mislaid or stolen when you’re out and about there’s a good possibility you’ll never see it again. But carrying an anti-theft resolution increases your chances of recovery. You could remotely locate it on a map from another device or PC, make it play a summons to assistance we find it (useful for when your phone slips between a cot cushions), or clean your device if we cruise we won’t get it back.

Many mobile carriers offer an anti-theft or remote locating service, though there are also giveaway apps we can download for your Android or iOS device. Take a demeanour during Lookout Mobile Security for Android, that also includes insurance opposite Android malware. If we possess an iOS device, a giveaway Find My iPhone and Find My iPad apps from Apple are value downloading.

The same goes for your laptop

Like with smartphones and tablets, we can setup an anti-theft resolution on your laptop. And if it becomes mislaid or stolen we can remotely locate it around Wi-Fi positioning and IP residence locations, if someone connects it to a Internet. Some anti-theft solutions let we remotely control a web cam and guard a shade as well, serve assisting we to find a thief.

Some laptops come with a built-in anti-theft solution within a BIOS so it’s still locatable if a burglar wipes or replaces a tough drive. But if yours doesn’t support this we can still implement an anti-theft applicationLojack for Laptops is one option, and it works on both Mac OS X and Windows. Prey and GadgetTrak are other services value considering.

Perform PC confidence checks


You should intermittently perform a by confidence check of your PC. Antivirus is a must-have, though it doesn’t detect all vulnerabilities. It doesn’t always check for blank confidence updates for Windows, and for exposed applications like Abode Reader and Flash, Java, and your Web browser. And they customarily don’t investigate your passwords to detect diseased ones. See a prior story, Beyond antivirus software: Eclectic PC confidence collection for system-wide audits, for what we can do to tie your PC’s security.

Encrypt your laptop

A Windows cue prevents a normal Joe from booting adult your mechanism and accessing your files and personal documents, though it can simply be private or bypassed. A burglar or snooper could mislay a tough drive, bond it to another computer, and entrance your files that way. Or they could use a special CD to mislay your Windows cue and afterwards be means to record into your Windows account.

Since a laptop can be simply mislaid or stolen, it’s a good thought to encrypt your whole tough drive, that prevents someone from stealing or bypassing your password. Check out a tutorial to learn how to go about it.

Encrypt your USB drives

External USB and peep drives are easy to lose, and all someone has to do is retard them into their mechanism to entrance your files. With that in mind, if we ever send or store any supportive papers on outmost drives, we should cruise encrypting them, that requires we to enter a cue before we can get during your files. You can buy drives that come encrypted or we can encrypt any expostulate yourself. Whatever track we go, it’s best to use those with 256-bit AES encryption. Also, cruise shopping those carrying a government-standard “FIPS 140-2 Level 2″ or aloft certification.

Secure your amicable network accounts

If we aren’t holding on amicable networks seriously, it’s usually a matter of time before we get taken by antagonistic links and amicable apps that try to take your personal information or money, or widespread spam. And that doesn’t even embody a remoteness issues in play—you substantially don’t wish your employer to see all your personal life. So cruise securing your amicable network confidence and remoteness settings. Take a tighten demeanour during a confidence and remoteness settings for a amicable networks we use; learn what any of a settings mean, and adjust them as we see fit.

Also, cruise about regulating a security app to assistance locate threats and keep adult with a latest threats around sites like Facecrooks. Some stream confidence suites, like Trend Micro’s, embody facilities that will check your Facebook remoteness settings, and offer suggestions for improving your privacy.

Sign adult for online backups

You substantially know that we should emanate a backup of your computer’s tough drive, usually in case. But what happens if your backup hoop goes bad? Using an online backup use is a good approach to strengthen your many profitable documents, usually in box double-disaster strikes and both your tough expostulate and backup go dead, or both are broken in a diaster. There are plenty of services out there, and some antivirus companies yield online backup services for their customers.

That said, confidence practices can change between online storage providers. Check out a overview of online storage security for some providers with difficult confidence practices.

Install a two-way firewall


ZoneAlarm’s Free Firewall.

A firewall helps retard hackers from being means to entrance your mechanism around a Internet and internal network by determining what trade can pass through. Windows comes with a firewall, though by default it usually monitors incoming traffic. To assistance locate malware or other antagonistic applications from promulgation information from your computer, a firewall needs to also guard your effusive traffic. If we use an all-in-one confidence apartment like Norton Internet Security or McAfee Internet Security, we expected already have a two-way firewall. But if we don’t, cruise regulating standalone two-way firewall like those from ZoneAlarm or Comodo.

Use OpenDNS for calm filtering

An Internet calm filter is a good thought regardless of either we have youngsters in a home. In further to restraint adult and other inapt sites, OpenDNS can assistance retard virus-spreading sites and other dangerous corners of a Internet. Best of all, a basic-level OpenDNS use is giveaway and we can request it both to particular computers or to your whole network.

Check your Wi-Fi security


If your Wi-Fi network isn’t encrypted—that is, if we don’t have to enter a cue when connecting—anyone circuitously can bond to a network and prevent your Internet traffic. To keep unapproved users off your network, you’ll wish to make your wireless router in your home is set adult with wireless security: Wi-Fi Protect Access (WPA or WPA2).

To check if your wireless router is cumulative move adult a list of accessible wireless networks in Windows. Those that aren’t encrypted will have a warning indicator subsequent to them and those that are will uncover a confidence form when we float your rodent pointer over a network names. If yours isn’t cumulative impute to a primer that came with your router for instructions on how to spin on encryption.

Article source: http://www.pcworld.com/article/2023756/12-security-resolutions-for-2013.html

Data storage strategy: Pre- and post-cloud computing

Friday, January 4th, 2013

I am in a midst of defining a cloud strategy. We need a framework, during slightest for a subsequent few
years, that will assistance us confirm that services we support on-premises and that services, naturally
and logically, go in a cloud.

In a early theatre of defining a strategy, cost is positively a factor. So is what we call
“capacity.” We have so many projects in a tube that if we can giveaway adult my inner staff and
infrastructure resources for new projects by off-loading upkeep activities to someone else, I
create ability that puts me proceed ahead. We still have some work to do before we can use this
framework to make each decision, though there are some cloud decisions that are easy to make … and cloud
data storage
is one of those.

Our organizations are dependant to data
retention
. Just take a demeanour during your possess or others’ email inboxes. Still got that invitation to
the 2007 association Christmas party? What about that email from a CEO seeking a doubt that you
answered months ago. Why do we keep such data? Because of a entrenched fear that, during some point
in a future, we competence need that email, file, request or record. This creates it scarcely impossible
for us to undo it. After all, what if it turns out we unequivocally do need something that was in that
invitation to a 2007 association Christmas celebration and a invitation is no longer there?

Our organizations are dependant to information retention.

For years, we have used some elementary classification manners to conclude my proceed to information storage and
retention. we sequester a information into a few extended categories:

  • Always used
  • Sometimes used
  • Rarely used
  • Never used

In a pre-cloud days, we would put a Always used information on a quick drives (now including solid
state
). we would put a Sometimes used information on a slower drives, a Rarely used on a slower
drives, and we would try to remonstrate a owners of a Never used information to get absolved of it. But, in
practice, we was never means to get absolved of a Rarely used information and finished adult putting it on a slower
drives. Over time, we kept shopping some-more comparatively costly slower drives as a volume of Sometimes
used, Rarely used and Never used information grew.

More on information storage strategies

CIOs essay to fit storage
strategy
to business need

Storage capability cavalcade down: Windows
Server 2012

Storage
strategies
for a practical environment

Independent of any other decisions we make about cloud
services
such as SaaS, IaaS, PaaS, et cetera, cloud information storage creates my information retention
sorting many cheaper and simpler. we still arrange into Always used, Sometimes used, Rarely used and
Never used. And, we still put a Always used on my fastest storage and my Sometimes used on the
slower storage. But, we pierce a Rarely and Never used to a cloud. Do we caring about retrieval
performance of a Rarely and Never used? Not during all. Do we wish to allot my storage ability to
something that is rarely, if ever, used? Not on your life; we have too many other final on that
capacity. Do we wish to allot my storage dollars to something that is rarely, if ever, used? Not
when we can get gigabytes of delayed cloud storage for pennies. In effect, cloud storage is my data
archive.

Some people competence doubt this decision. Don’t we worry about a confidence and insurance of my
data? we do worry about that, though not during all with a reputable, proven cloud
provider
. After all, they have to be during slightest as good as we am during information confidence and protection.
Otherwise, their business indication collapses. If we am honest with myself, we think that they are
better during information insurance and confidence than we am — they have to be.

I use cloud information storage to emanate inner ability that we allot to a services that my
customers wish a most: high-performance, on-demand entrance to a information they use a most. For
everything else, we find someone who can do it cheaper and during slightest as good in a cloud.



This was initial published in Jan 2013

Article source: http://www.pheedcontent.com/click.phdo?i=03eab5534d4190d97bdc8adc4c90fdb4

Can confidence support assistance developers write code?

Friday, January 4th, 2013

How effective are a focus frameworks that offer confidence support for
developers?

There is no deputy for all developers carrying during slightest some
knowledge of secure pattern and coding principles.

In terms of confidence support, stream frameworks do yield some value, though there is still much
work to be finished to discharge vulnerabilities such as SQL injection, cross-site scripting (XSS) and
cross-site ask forgery (CSRF).

At a stream time, growth frameworks during best support a origination of secure code,
but they do not prevent a origination of uncertain code. That means developers who understand
the horizon and a confidence comforts that are permitted are in a improved position to create
secure code. But developers with small bargain of secure coding practices in ubiquitous — and
the confidence capabilities of a horizon in sold — can still deliver common
vulnerabilities into applications.

On a per-vulnerability basis, here are some of a comforts that exist in ordinarily used
frameworks that deliver confidence issues:

  • SQL injection. Object to relational mapping (ORM)
    libraries such as Hibernate can provide
    some insurance opposite SQL injection
    vulnerabilities
    by abstracting a developer divided from proceed strategy of database queries.
    However, many ORM libraries concede developers to emanate free-form queries, that still leaves the
    application open to injection attacks.
  • Cross-site scripting (XSS). The
    .NET horizon provides some out-of-the-box XSS insurance permitted around a ValidateRequest
    attribute. This is helpful, though given it relies on a blacklist of famous bad payloads, it can be
    bypassed. So developers still need to scrupulously encode information to strengthen it from XSS
    vulnerabilities.
  • Cross-site ask forgery. The latest chronicle of a Tomcat servlet enclosure has a CSRF impediment filter that offers insurance opposite many CSRF attacks.

This is a brief list of frameworks and countermeasures, though a existence is that for most
development platforms there is not a good set of customary collection and libraries that forestall the
introduction of common classes of vulnerabilities. Also, many developers are not wakeful of the
available resources and how to use them correctly. Finally, a accessibility of a standard
platform APIs to
create database queries or Web page calm allows developers to simply write to these APIs and
introduce vulnerabilities into their applications.

One engaging growth in this space is a playdoh plan from Mozilla. Playdoh is a Web focus template formed on
the Django Python Web focus framework. Developers building applications in Playdoh have
access to all of Django’s confidence facilities as good as some additional secure-by-default libraries and settings. Playdoh is still a
relatively new plan and Django is not as common in many corporate environments when compared to
Java Enterprise Edition (JEE) or ASP.NET, though Django’s proceed is promising.

In a future, maybe other platforms will take a identical extensive and secure-by-default
model for secure coding. That said, while frameworks have a place in assisting teams create
applications giveaway of common vulnerabilities, there is no deputy for all developers carrying at
least some believe of secure pattern and coding principles.



This was initial published in Jan 2013

Article source: http://www.pheedcontent.com/click.phdo?i=e9688c3b10480c321ae26ff46d0fbfe5

City Asks Computing Center To Pay Up

Thursday, January 3rd, 2013

HOLYOKE, Mass. (WGGB) – The information servers inside a new Massachusetts Green High Performance Computing Center are value a whopping $170 million, and that’s only because Mayor Alex Morse is seeking them to financially minister to a city in a new year.

“As mayor, it’s my pursuit to consider of artistic and innovative ways to lift revenue,” Mayor Morse said.

The Computing Center is taxation exempt. In a minute sent Monday, Morse asks a Center to compensate about 25% of what they would routinely compensate in taxes. He even laid out a staggered remuneration report for them, starting with $500,000 this year and stability on adult to $1.5 million over a subsequent 9 years.

“Negotiations will be negotiations, so we don’t expect it removing negative,” Morse said. “We’ll do all we can to keep it positive, and keep it cordial. We will no doubt come to an agreement that will prove both sides.”

City Councilor James Leahy says deliberation a core is immature and gets its’ electricity from a Holyoke Dam, it’s not most to ask.

“We are looking for them to chip in their share, they are removing a same military protection, glow insurance as each other citizen, each other business owner,” Leahy said.

Morse says a city will be seeking other non-profits to minister as well, and already have done hit with ISO New England, Holyoke Gas and Electric, and Holyoke Medical Center and hopes to supplement Holyoke’s newest growth to a list.

“I suspicion it was suitable that we pierce brazen in that vein, make certain we’re safeguarding a people here in a City of Holyoke, like all cities,” Morse said. “We have a parsimonious budget. We’re always looking for ways to boost income to forestall taxes from going up.”

The Computing Center pronounced they had no criticism when asked if they designed to give a city any income during all. By law, it’s their call to how most they wish to pay, if anything.

Article source: http://www.wggb.com/2013/01/03/city-asks-computing-center-to-pay-up/

F-Secure Internet Security 2013 review

Sunday, December 30th, 2012

Many anti-virus products torrent a user with a fusillade of facilities and options, yet F-Secure takes a many reduction assertive proceed with a flagship Internet Security 2013 software.

A tiny control console appears usually above a Windows taskbar. This has 3 sections, one for Computer Security, one for Online Safety and a final has links to a F-Secure web and several support and stating options. The whole menu interface is unfussy and workmanlike, with elementary explanations.

Read more: Antivirus reviews | Security procedure reviews

The assistance complement is always during hand, nonetheless it is a small sparse. Luckily, users shouldn’t need to deliberate it that mostly as a procedure is really easy to understand. Advanced settings are sincerely limited, that might deter those who like to fine-tune settings, yet for many users it is substantially a blessing.

Simple toggle switches concede any member to be incited on or off, and a outrageous red cranky appears on a interface if a pathogen insurance or firewall is incited off. Annoyingly, there’s no ‘fix everything’ button, though. The firewall member is indeed usually a front finish for a Windows Firewall, that isn’t done transparent in a specifications. Although this is good for users of Windows Vista, 7 and 8 that have good built-in firewalls, this does meant XP users get a bad deal.

The procedure includes spam and phishing protection, yet there are no other extras or collection detached from a Online Safety module. This can retard users from accessing a internet during certain times of day, or blocked from specific websites and/or calm types. It is easy to use, yet offers small that can’t be found in giveaway products such as Microsoft’s Family Safety.

Scans are really discerning during usually over a notation on a exam PC) and memory use usually went adult from 20MB to 70MB while scanning. Scans can be scheduled, nonetheless this is incited off by default, and a magnitude of checking for updates can’t be altered from a default ‘several times a day’.

F-Secure Internet Security 2013 is a simple, simple procedure that anyone should be means to use and it is one of a cheapest blurb products for those that have usually one PC.

<!–

–>

Article source: http://www.computeractive.co.uk/ca/review/2227101/fsecure-internet-security-2013-review

Thailand to finish information centre for inhabitant work data

Thursday, December 27th, 2012

Email Security for Enterprises Governments

SecureEmail white paper.

The Ultimate Data Protection opposite APT

SecureData white paper.

Data Security in a Cloud

SecureData white paper.

SecureData for SharePoint

Press release.

Article source: http://www.futuregov.asia/articles/2012/dec/27/thailand-complete-data-centre-national-labour-data/

Dell to buy confidence businessman Credant

Thursday, December 20th, 2012

IDG News Service - Dell has done a understanding to acquire data-protection businessman Credant Technologies and skeleton to supplement a company’s record to a craving IT confidence offerings.

The companies did not divulge a terms of a deal. Credant, founded in 2001, is formed in Addison, Texas, about 200 miles north of Dell’s domicile in Round Rock, Texas.

Credant sells program and services to encrypt information and keep it secure as it is changed opposite PCs, mobile devices, USB drives, cloud services and other locations. It offers a singular console for information insurance policies opposite all those platforms and says a program can coexist with existent craving government systems. The association claims it secures some-more than dual million endpoints opposite industries including defense, health care, media and universities.

Dell pronounced it will use Credant program to raise a confidence capabilities of a Latitude, OptiPlex and Precision computers. Dell already has a corner growth and OEM (original apparatus manufacturer) agreement with Credant and uses a company’s record in a Dell Data Protection/Encryption product.

Prior to a Credant deal, Dell had already spent $4.9 billion on acquisitions this year to settle a craving credentials. Some analysts have pronounced a association hasn’t nonetheless made a many of those new assets.

Stephen Lawson covers mobile, storage and networking technologies for The IDG News Service. Follow Stephen on Twitter during @sdlawsonmedia. Stephen’s e-mail residence is stephen_lawson@idg.com

Article source: http://www.computerworld.com/s/article/9234876/Dell_to_buy_security_vendor_Credant

Dell to buy Texas-based information insurance association [Austin American-Statesman]

Wednesday, December 19th, 2012


<!– finish javascript to email a article

–>


By Kirk Ladendorf, Austin American-Statesman

McClatchy-Tribune Information Services

Dec. 18–Dell Inc. has finished another deal.

The Round Rock-based association pronounced Tuesday it had reached an agreement to buy Addison-based Credant Technologies, that it described as an attention heading provider of information insurance solutions. No terms of a understanding were disclosed.

Credant secures information sent from “endpoints” — such as personal computers and mobile phones — to servers, storage networks or to cloud computing environments.

The Credant resolution protects and encrypts information as it moves between computers and other intelligent devices. The record works within existent systems supervision processes and also works with mixed mobile handling systems. Credant currently secures some-more than 2 million “endpoints” in a accumulation of industries including aerospace, defense, energy, financial services, universities, supervision agencies, sell and health care.

Dell has done some-more than dual dozen acquisitions over a past 5 years as a association has changed to pierce toward apropos a full-service retailer of modernized hardware, program and services. Part of Dell’s importance has been to acquire some-more modernized security.

“The Credant resources will element and extend stream Dell device bonds facilities to make Dell computers among a world’s many secure,” pronounced Jeff Clarke, boss of finish user computing solutions during Dell.

The merger is approaching to be finished before a finish of January.

___

(c)2012 Austin American-Statesman, Texas

Visit Austin American-Statesman, Texas during www.statesman.com

Distributed by MCT Information Services

<!–

Print

Email

–>

Article source: http://www.equities.com/news/headline-story?dt=2012-12-18&val=839229&cat=tech

NIOT moots sea tech centre during NIT-K

Saturday, December 15th, 2012

It is expected to come adult within a year, says Atmananda

The National Institute of Ocean Technology (NIOT), an unconstrained physique underneath a Union Ministry of Earth Sciences, Chennai, has due to set adult an sea record centre during a National Institute of Technology – Karnataka (NIT-K) during Surathkal nearby here, according to NIOT Director Atmananda.

Addressing a entertainment after inaugurating a two-day seminar on “Conservation of H2O resources of a west-flowing rivers in coastal Karnataka” during NIT-K on Friday, he pronounced that a support routine was on. The offer would be placed before a Ministry shortly for approval. The centre was expected to come adult within a year.

He pronounced NIOT would be a facilitating hospital of a centre. Being a technical institute, NIOT had several projects in sea record with range for research. As NIT-K concerned in investigate activities with imagination in it, NIOT would like to engage it for investigate compulsory for a projects. Once a centre came up, it could collect information compulsory for coastal insurance by observation. The information would be analysed and stairs compulsory to be taken for a insurance would be placed before policy-makers for action.

Mr. Atmananda pronounced that in coastal areas, additional use of groundwater could lead to salinity. Hence, government and engineering techniques were indispensable for tolerable scrutiny of groundwater.

He pronounced Karnataka had 10 west-flowing rivers, providing 60 per cent of a State’s internal H2O resources.

Mr. Atmananda pronounced that inter-linking of rivers should be finished after a minute study. There was no indicate in hostile inter-linking of rivers but a correct basement and systematic investigate of impact of inter-linking of rivers. Environmentalists had lifted regard about hazard to aqua life, deforestation and submergence of land. “…So it is required to strike a around media. This is really important. we am not suggesting that forests are to be destroyed. Via media is important…”

Chief Executive Officer of a Dakshina Kannada Zilla Panchayat K.N. Vijay Prakash pronounced a panchayat would desilt 122 tanks in a district.

He pronounced there was over exploitation of groundwater in 44 habitations in Dakshina Kannada that now faced nonesuch of H2O in summer. The groundwater list in a district had depleted from 90 mts a few years ago to 120 mts now.

Swapan Bhattacharya, Director, NIT-K, spoke.

Article source: http://www.thehindu.com/news/cities/Mangalore/niot-moots-ocean-tech-centre-at-nitk/article4202990.ece

Securing a information centre

Friday, December 14th, 2012

Data insurance looms vast for many businesses today, generally with unchanging reports of information burglary and hacking attacks. But while practical insurance is important, companies shouldn’t forget that their information has a earthy participation too – increasingly housed in a information centre.

When it comes to constructing a new information centre, a initial step in confidence is customarily removing a confidence blockade in place, though this will of march be usually a initial of many measures to keep a finished trickery and a useful information inside safe.

It’s sincerely singular for a information centre to be purposefully threatened, though it does occur from time to time and a formula can be intensely costly. Hundreds of thousands of Vodafone business mislaid phone and internet entrance faced in early 2011 after burglars pennyless into a trickery and done off with profitable network equipment, causing widespread outages.

An even some-more impassioned instance came in in 2007 when Scotland Yard unclosed a tract by Al Qaeda members to penetrate and destroy a vital information centre. The London-based colocation site was owned by Telehouse Europe – deliberate one of a categorical hubs for a internet in a UK during a time. While a conflict was prevented, it done it transparent that information centres are indeed on a radar as a aim for terrorism.

The chances of an conflict might seem remote, though only as with a slim probability of an trembler or flood, a risk contingency be accounted for. Data centres are advantageous in that they will always have clever puncture measures in place as a standard, distinct many other businesses and facilities. With so most during stake, it’s always improved to be protected than contemptible with security.

 

Article source: http://www.datacenterdynamics.com/blogs/ed-jones/securing-data-centre&u=6555