Sponsors

Sunday, May 29, 2011

How Google Increased Your Gmail Security

 

 

In January of 2010, Google made HTTPS encryption a default security setting for Gmail users email session via a webpage. (See Link Below)

This was a positive move, because it greatly reduces the risk of someone eavesdropping on your communications with Gmail. Gmail users privacy was increased significantly, which will cause a reduction in personal information breaches.
Note: Now this enhanced security can be defeated if you are using a computer that has malware that can steal your keystrokes or clicking on unfamiliar links on websites and in email that can hijack your computer and use the HTTPS security to protect their misdeeds.

Google's decision to make HTTPS the default setting was due to criticism from a  group of computer scientists, law professors and security experts, who voiced their concerns in an open letter to their CEO Eric Schmitt. The group, claimed that the default unencrypted settings put customer and information at risk unnecessarily. (See Link Below)

An open letter to Google's CEO, Eric Schmidt

What is HTTPS? See Link Below

How to Disable and Enable Gmail's HTTPS security setting

Gmail is set to use the 'Always use https' setting by default, but you can change this setting anytime. Here's some background on why we default to this option: If you sign in to Gmail via a non-secure Internet connection, like a public wireless or non-encrypted network, your Google account may be more vulnerable to hijacking. Non-secure networks make it easier for someone to impersonate you and gain full access to your Google account, including any sensitive data it may contain like bank statements or online log-in credentials. HTTPS, or Hypertext Transfer Protocol Secure, is a secure protocol that provides authenticated and encrypted communication.
To disable or re-enable this feature in Gmail:

  1. Sign in to Gmail.
  2. Click the gear icon in the upper-right corner, and select Mail settings.
  3. In the General tab, set 'Browser Connection' to 'Always use https' or 'Don't always use https.'
  4. Click Save Changes.
  5. Manually change the URL to http://mail.google.com to start accessing Gmail via http.

Please note that selecting 'Always use https' will prevent you from accessing Gmail via HTTP (Hypertext Transfer Protocol). If you trust the security of your network, you can turn this feature off at any time.
If you use a public computer to check your email, it's also important to sign out at the end each of your Gmail sessions. Just click the down-arrow next to your name in the upper right corner, and select Sign out. Also, make sure you close all Gmail browser windows.

Google's decision to make HTTPS a default security setting prompted Twitter and Facebook to follow suit and turn it on be default at well. (See Link Below)

If you use Gmail, Facebook or Twitter, enjoy the enhanced privacy protection.

Enjoy,
Julius Clark, MBA, CISSP, CISA

Saturday, March 19, 2011

How to Export Your Facebook Contacts To an Email Address Book.

Export Your Facebook Contacts

Have you ever wished you had your Facebook Contacts in an easy to use email address book?

 

Well your wait is over! Follow my simple steps with ease and simplicity using Yahoo's email service.

 

 

1. First thing to do is go to www.yahoo.com

.

2. It is best to create a new Yahoo email account to perform the export and to manage your contacts in the future.

3. Log into your new Yahoo email account and click on Contacts.

 

.

4. Click on Tools from the pull down menu and select Import.

5.Click on the Facebook icon.

6. Click OK to share contacts with Yahoo.

 

7.Yahoo will start retrieving the contacts from Facebook and display the number of contacts found.

8. When Yahoo finishes importing your Facebook contacts it will display the number of countacts imported. Click View Contacts.

Note: You can only download those contacts of Facebook users who do not block their contact information from being shared.

9.  From the Tools menue choose Export.

10. Choose the export format you would like to download your Facebook contacts in.

 

Thats it! You now have exported your Facebook contacts into your Yahoo email account.

Note: After you complete the final step to export your Facebook contacts from Yahoo, you may get an error message of page not found. If that happens a work around would be for you to go to the top of your browser menue and choose Edit, Select All, Click Edit again and choose copy. Open Notepad or Word and paste the contacts. You will then need to manually remove other items that got copied during the cut and paste step. Arrange your contacts in a manner that will work for you. Additionally, I recommend that you only use this yahoo account to manage your exported facebook contacts; this will make life easier for you.

If this becomes too much work then just use your new Yahoo email account to send your messages to your Facebook contact.

Enjoy,

Julius

Saturday, March 5, 2011

Improve Yourself; Increase Your Value



Improve yourself; increase your value. I grew up with the most loving parents, but my parents did not possess certain types of knowledge to teach me how to really get ahead in life. I gained access to that knowledge by associating myself with positve individuals and groups who had that knowledge and a history of success themselves; which provided proof that with hard work, I too could attain what my heart desired; even though at the time I did not have those compentecies that I would eventually learn.


In closing, anyone working on improving themselves benefit even more when they help others who have these gaps in their circule of incluence.



Peace,

Julius.

Sunday, January 9, 2011

12 Global Business Practices for Information Security Professionals



I am very happy to announce that 12 Tenants by the premier Global Information Security professional organizations have been developed to advance the profession of Information Security. This is huge! Collaboration of this effort requires egos to be left at the door; We have some huge egos in IT Security, this demonstrates that they can all get along and work together to globally practice the tenants of IT Security, which are Confidentiality, Integrity and Availability.

Objective

These 12 principles were developed as a framework for IT Security professionals to influence and guide them in their career; they are a welcome sight for individuals new to the field. The principles are intended to affect behaviors, objectives, approaches and activities, which in return will lead to more success safeguarding privacy and technology infrastructure in organizations across the globe.





Target audience

The principles for information security practitioners are aimed at all individuals working in the information security community, including
those who:
  • are employed as part of a security function
  • provide security services in local environments (eg local security co-ordinators)
  • are responsible for developing systems securely
  • supply security products and services (eg vendors and consultants)
  • influence legal / regulatory requirements for information security
  • are aspiring to become security practitioners (eg students).

Benefits to Business

Organizations that have not had a real security framework for their IT Security professionals to follow will see an immediate benefit, which can add value and become a marketable asset.
  • A - Support the Business
  • B - Defend the Business
  • C - Promote Responsible Security Behavior

Background


Information security practitioners need to respond to the changing requirements of organisations in today’s complex, interconnected world.
For example,
  • corporate, IT and information security governance have promoted information security higher up on the board’s agenda
  • the information security profession is not fully mature, traditionally has a bias towards technology and needs to be more risk focused
  • rapidly evolving threats require information security practitioners to stay ahead of the game
  • co-ordinated efforts are needed to maintain the adaptability of information security practitioners, particularly in changing business environments. Over the years there have been a number of offerings related to individual information security practitioners that cover behaviour, actions or ethics. However, there is a requirement for an independent, non-proprietary set of principles, which are:
  • more generic and complete, with less focus on professional qualifications
  • relevant to the business world – and kept up to date
  • agreed throughout the security profession, rather than being proprietary to one organization
  • able to map easily to different security standards and guidelines.
The principles for information security practitioners have been designed to meet these needs. They have been jointly developed by three
of the worlds leading global security organizations, the ISF, ISACA and (ISC)².

A. Support the business
  • A1. Focus on the business: The business is the reason that you have your job! Your goal is to help your organization make money or meet your organizations mission or vision statement.
  • A2. Deliver quality and value to stakeholders: The solutions you implement as an IT security professional in the form of technology, process and people can add value and become a marketable asset for your organization.
  • A3. Comply with relevant legal and regulatory requirements: The law and Information Security go hand and hand. The IT security professional must adhere and comply to all laws and help your organization meet or exceed required compliance objectives.
  • A4. Provide timely and accurate information on security performance: You won't know if your IT Security objectives are working if you have no way to measure the outcome of your IT security implementations; are you receiving the desired results?
  • A5. Evaluate current and future information threats: Information Security threats are forever changing and criminals are always ahead, so the IT security professional must be proactive by studying trends and defending the business from threats before they become a problem.
  • A6. Promote continuous improvement in information security: Once you implement your security solutions go back and review to see if there are opportunities to improve your security solutions currently in production.
B. Defend the business
  • B1 Adopt a risk-based approach: Protect the most critical business applications and information.
  • B2. Protect classified information: Always limit access on a need to know basis to information like the following: social security numbers, customer account information, health records, credit card numbers and proprietary business information; and don't let unauthorized individuals to access your network.
  • B3. Concentrate on critical business applications: Information or systems that are VITAL for the business to stay up and running need the most security; think defense in layers; defense in depth; Confidentiality, Integrity and Availability (CIA).
  • B4. Develop systems securely: Implement security at the beginning of your Information Technology projects. It much easier and cost effective to do so, than try to fit in after a system or data base has been implemented.
C. Promote responsible security behaviour
  • C1. Act in a professional and ethical manner: You are held to a high standard as one appointed to safeguard an organizations system and data assets. Read ethics/ code of conduct from the premier IT Security organizations: ISF, (ISC)2, and ISACA,
  • C2. Foster a security-positive culture:
Download the 12 Principles Poster

I applaud the premier IT Security organizations for working together to create the 12 principles, which will be of great value to new IT Security professionals entering the field.

Enjoy,

Julius Clark, MBA, CISSP, CISA

References:

ISF, (ISC)2 and ISACA Release Information Security Principles

http://blog.isc2.org/isc2_blog/2011/01/isf-isc2-and-isaca-release-information-security-principles.html

12 Principles
https://www.isc2.org/uploadedFiles/(ISC)2_Public_Content/About_ISC2/Industry_Initiatives/Principles%20for%20Info%20Sec%20Practitioners_overview.pdf

12 Principles Poster Download

https://www.isc2.org/uploadedFiles/(ISC)2_Public_Content/About_ISC2/Industry_Initiatives/Principles%20for%20Info%20Sec%20Practitioners_poster.pdf






Friday, January 7, 2011

Google Releases a Preview of its Honeycomb Android 3.0 Tablet Operating System




Yesterday Google Released a Preview of its Honeycomb Android 3.0 tablet operating system designed specifically for tablets.



I love tablets that run on the Android platform! I bought a very cheap one generic from China just to play with over the holidays; the potential with Android tablets is amazing. The biggest reason for me liking Android tablets over Apple iPads is the cost. Tablets running the Android OS will be in the price range of $100 - $400 dollars. Compared to iPads in the range of $500 - $650 dollars.

Additionally, Android tablets will allow the owner to configure it more to their liking, so you won't have to worry about being locked into the default options as with the iPad. The Android version of Apples App store is the App Market that has thousands of application, which developers say is more developer friendly that Apple is.

The future is here with Android tablets and I predict that these devices will be the hottest item on many peoples Christmas list this year.

Enjoy,

Julius



Friday, December 31, 2010

How To Download Your Facebook Data Easily

My last blog for 2010! Have a Happy New Year Everyone!

Facebook in October of 2010 made it very easy to download the majority of your messages, photo's. videos and other content data that you input in to it.

1. Go to Account and choose Account Settings.

 

2. From the Download Your Information Section Choose "Learn More"

 

3. A dialog box will appear with a link for you to download your information. Click Download Now.


4. After clicking on Download Now the Request My Download will appear. Click Download.

 

5. After this step is complete you will need to wait for Facebook to send you an email with a link to a zip file containing all your personal data is ready for download. See below.

Facebook to me

You recently requested a download of your information on Facebook.

Your download has been generated and is now ready. Please follow the link below to download it. Remember that this file contains sensitive information. Because this download contains your profile information, you should keep it secure and take precautions when storing, sending or uploading it to any other services.

https://register.facebook.com/download/?h=XXXXXX8d2454667XXXXXb9180

Thanks,
The Facebook Team

6. After you click on the link Facebook send to you a download dialog box will appear. Save to a folder on your computer.



7. Once the download is complete extract the files. You will find the following file structure created, which is pretty cool, because this will allow you to view your content using a web browser like you would on Facebook, but directly being read from your computer.



That's it! Pretty simple. Now please safegaurd your Facebook data because once you download it you are 100% responsible for securing the content and making sure its backed up.

Enjoy,

Julius


Saturday, October 23, 2010

Using VoIP with a Credit Card Processing Terminal is Risky Business

Processing Credit Card Payments Using Credit Card Terminals with VoIP / Digital Phone Lines Is Not PCI Complaint



Millions of people running small businesses; especially home based businesses, also have VoIP (Voice over Internet Protocol) / Digital Phone Line services from their Internet Service Provider (ISP) in their homes and businesses. Many also use Point-of-Sale Terminals made initally for old fashion phone lines; not Digital Lines. If you are a merchant and use a card processing terminal which connects via VoIP or Digital Phone Lines to transmit and process credit card payments, then you are not PCI (Payment Card Industry) compliant; you are at risk of losing your credit card processing privileges or can be sued by your customers whose data is stolen. Credit Card data that is processed over VoIP services are transmitted in the clear over Public Networks (The Internet) and their is no way to encrypt the data.

Excellent article on this topic can be found at The Merchant Account Blog:

Note: Most VoIP providers do not utilize encryption

When these terminals are connected to a true analog phone line the merchant is operating within PCI Compliance. This is so because it is very unlikely that data can be stolen over an old fashion telephone line while processing credit card payments. An attacker would have to tap into your home or business phone line to steal credit card data and that is highly unlikely to happen so this is rated as very low risk.

VoIP is very susceptible to Man-in-the-middle attacks, where an attacker can eavesdrop or alter the originating message by anyone on the internet; in this case capturing your customers sensitive credit card information. Most credit card phone line processing terminals won't work over VoIP services because of dropped packets, but even failed attempts to try and process credit cards over VoIP could lead to an attacker stealing customer credit card data. See diagram below.

Man In The Middle Attack



Work Around To Be PCI Compliant

Many of these credit card terminals also have an Ethernet Port (RS232) and can easily process customer credit card payments via an encrypted connection over the internet. You may need to contact your credit card processing provider to help you get it setup; usually at no additional cost! See picture below.



Another work around is to switch to a Wireless Credit Card Terminal. Note, these terminals incurre higher business expenses as compared to a dial-up phone line terminal. These terminals use GPRS/ Cell phone technology just like moble phones do to securely connect and encrypt the credit card transaction, which is PCI compliant. A wireless credit card processing terminal is great for businesses who sell goods or services on the road. See Wireless Credit Card Terminal below.

More Secure and Convenient Credit Card Processing Method

Wireless Credit Card Processing Terminal




19 Year Old Demonstrates VoIP Hacking - Scary Stuff!




Be careful out there!

Julius, MBA, CISSP, CISA


Wednesday, October 13, 2010

Hip Hop Can Influence Kids To Pursue STEM Careers




Dr. Dre who is one of the best music producers in Hip Hop history is making his mark these days as an Engineering and Technology innovator. Dr. Dre has the hottest selling brand of High-Tech headphones on the market, and everyone from the B-Boy to the corporate executive wants a pair. 



Time Magazine - The Beats by Dre Headphones are state of the art because they incorporate High-Tech Noise Canceling circuitry.

though they have some noise-canceling tech built in to them — the Beats are designed to enhance the listener's enjoyment of music rather than drown out the snores of your seatmate. Dre, who for three years collaborated with Jimmy Iovine, chairman of Interscope Geffen A&M Records, and audio "connectivity" company
Monster® to create the Beats, says his goal was to give people a way to "hear what the artists hear and listen to the music the way they should — the way I do."

In other words Beats™ by Dr. Dre™ headphones produce the same sounds that studio engineers listen to on full size speakers. Additionally, a high end pair can range from $199 to $450 bucks.

The audio company Bose™ is the standard leader in premium priced headphones, and from many of the reviews I have read, Beats™ by Dr. Dre™ headphones are equal or far superior than Bose™ branded premium headphones--I bet they are not sleeping well at Bose these days, because they would of expected competition from a electronic giant like Sony™ not from a hardcore Hip Hop artist; you have got to love it!

Noise Canceling Diagram



As you can see from the figure above, there is some intricate expertise that needs to be known to design the Beats™ by Dr. Dre™ headphones. The cool thing is that anyone can learn to design electronic circuits at any two year community college with an Electronic Engineering or Technology program. Hip Hop has the star power to influence million s of kids; particularly minorities, to pursue STEM careers. A movement can be started if the right people work together and clearly paint a picture of superior opportunities for kids either as working professionals or as entrepreneurs like Dr. Dre; and even Snoop Dogg.

Technology makes magic happen and can turn your wildest ideas and fantasies in to fruition. Hip Hop has a fierce and powerful youthful force that has ears listening from neighborhood streets to Wall street. I feel that STEM education when fused with Hip Hop can ignite a sleeping giant in our country that will keep America innovating unbelievable new products and services, which will keep the U.S. as the number one economy in the world.

In closing, I have to leave you with this bad futuristic Hewlett Packard™ (HP) commercial showcasing a HP laptop integrated with Beats™ by Dr. Dre™ technology and Rapper NAS's video to the youth "I Can". Hip Hop Makes STEM Careers too cool!





NAS - I Can



Enjoy!

Julius



Get Expert Advice!