Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Tuesday, October 09, 2018

The Daily - Tuesday, October 9, 2018

PRIVACY: A PARADIGM SHIFT

In cyber news lately we learned of a "breach" of sorts affecting Google+, the failed social media competitor to Facebook. This breach, which was kept quiet by Google, allowed developers to capture the personal information of a Google+ user and that of their friends. Google, apparently, did not report this because it did not see evidence that the data was misused by developers that had access to it. Whether this will be proven wrong months down the road remains to be seen. Google is shutting down Google+ as a result of lack of use and the effects of the breach. Google+ will be retired next August.

What impressed me in the news clip is the apparent expectation that privacy of any kind is still possible for anyone that has had any type of online presence. I think that is an obsolete concept. Privacy is dead; we might as well get used to it.

Further, hackers benefit from this expectation of privacy and security, and thus seek financial rewards from exploiting our data in as many ways as possible. But what if that incentive was removed? What if we implemented a worldwide system in which there no longer be an incentive to get someone's credentials and steal their money or information? Such a system would be a radical shift in human behavior. It would involve the gradual shift away from materialism, and the elimination of greed from the human paradigm. That panacea would take centuries to implement unless something radical happens that forces humanity to shift more quickly.

In the meanwhile, let us not expect privacy or online security, and be ready for the loss of more on both fronts. As long as the rewards are high enough, then the bad guys will continue to attack.

DANGEROUS WINDOWS 10 UPDATE

In case you missed it, read all about why Microsoft is pulling the October Windows 10 Update: it basically can delete your documents and pictures. Here is the Microsoft page on the update.

TRUMPISM

How bad can Trumpism be? Just watch this video.


It is sad, it is disgusting, it is shameful.

Sunday, October 07, 2018

The Daily - Sunday, October 7, 2018 (AM)

SHORT RUN BETTER THAN NO RUN

This morning's jog was short (less than a mile) and that's OK. At least I was able to get out there and log some time on the road. This, of course, does not preclude a longer run later this afternoon or evening. Or perhaps I will use mowing the lawn as my cardio for today. Or maybe I will do both. Let's see what the energy level is as the day progresses.

USE A PASSWORD MANAGER!

In several of the security-related podcasts I listen to there have been in-depth analysis of the state of password security and why it is impossible for humans to produce (much less remember) hundreds of random-character passwords that are safe to use. The only solution: use a password manager. I have been using an old password manager called PINs. Although it is an older Windows-based program, I have been able to successfully run it under Linux. If you have an older system and you want a fast and low-resource password manager, then PINs maybe a good choice for you. I have been able to run it from a USB drive for years, although this has been curtailed as many environments no longer allow USB devices to connect to their machines.

Another password manager I think is worth considering is Keepass. This application is free, open source, and runs in Windows, Linux, Mac OS X, Android, iOS, and other platforms.

Many security experts recommend Lastpass as one of the best password managers. The fact that you can have one account and all your passwords are accessible anywhere you log in (home, work, smartphone, tablet, etc.) is a great feature.

In the past, security experts had recommended using a root part of a password with a variable portion to make passwords easier to remember. For example, you could use something like "Mypass" + "Face" + "99" to make up a password for Facebook. Hackers have figured this scheme out and, experts indicate, using this makes it easier for a hacker to break into other accounts once they have one of your passwords.

The best approach:use a password manager and generate random-character passwords for each site/application, and make each password at least 16 characters long. Passwords should contain upper and lower cases, numbers, and special characters. Just as important: change your critical account passwords every three to six months. A password manager can alert you when a password needs to be updated. All websites allow you to change your password as long as you can provide your current password. Changing your passwords regularly prevents hackers from breaking into your accounts using old lists of hacked passwords that are readily available for sale.

Wednesday, October 03, 2018

The Daily - Wednesday, October 3, 2018 (AM Edition)

CYBER SECURITY MONTH: A Cybersecure Home

October is Cyber Security month. We can start being safe in cyberspace by securing our home network. The SANS Institute has an excellent article on the topic:


DEPLORABLE!

Hillary Clinton once used this term to describe all of our current Liar-In-Chief supporters. Using such a term to define a group is a dangerous maneuver as Mrs. Clinton knows all too well.

What is obvious is that the term does apply to #45. His despicable rhetoric attacking Professor Blasey Ford puts him square in the definition of deplorable. He is disgraceful, shameful, dishonorable, unworthy, inexcusable, unpardonable, unforgivable; reprehensible, despicable, abominable, contemptible, execrable, and heinous.

Such behavior is beyond reprehension. But then again, what else can we expect from a misogynistic Fake President? 

WEALTH SHAM? SCAM?

The NY Times is reporting that the wealth claimed by #45 is based on scams, lies, cheating and fraud. Here are "11 Takeaways From The Times’s Investigation Into Trump’s Wealth".

The "Scammer-In-Chief" has openly stated that he took advantage of every legal tax loophole to avoid paying taxes. It looks as if he and his family also created a few loopholes, holes large enough to allow a semi truck to go through: "Trump Engaged in Suspect Tax Schemes as He Reaped Riches From His Father".

I will have two more articles in the evening edition.

HEALTH & FITNESS

To borrow a phrase from long-distance hikers, today was a "zero day." For through-hikers that means a day of rest with zero miles hiked. For me it was a day with no morning jogging, of sleeping in to further recover from the exhaustion of the weekend and the effects of the cold I have been dealing with.

I managed to do a nice stretching routine (call it, if you want, Yoga in bed), followed by a not-so-mindful meditation period, followed by a good period of affirmations. Overall, a nice morning start.

Having a "zero day" does not necessarily mean being lazy all day long. I plan to go for short brisk walks every 30 minutes or so at work. I will manage to put about 2+ miles by 3:30 PM.

Saturday, September 22, 2018

The Daily - Saturday, September 22, 2018

Writing Challenge- Day #24

HEALTH & FITNESS

I was very pleased to jog 3.63 miles in 66 minutes today. I used a different Podrunner track called "136 BPM - March of Progress." It has easily become one of my favorite Podrunner mixes.

One of the joys of running is that the possible routes are almost endless. As I started this morning's jog I thought about going one way and when I came to a certain point I changed my mind and decided to go a different way, one with less car traffic to avoid fumes. It was a good move and it allowed me to go further on my run.

GOALS, DREAMS, HABITS, RITUALS

Today was the first day I did not use a to-do list. It was costly in a couple of ways, most importantly that I forgot to take my meds and vitamins until this evening. Normally I take them with breakfast around 10 AM but I got distracted by having to run my daughter to her job and so I lost track of things. I think the trick for me is to get the list done the night before, and then review the list first thing in the morning right after meditating.

PERSONAL GROWTH

Despite not using a to-do list for the day, I did manage to get much done. For example, I got some things ready for next weeks trip and did some shopping. One of the items I bought (double-sided tape I will use to improve my A/C filter positioning) ended up helping to re-position the WiFi antenna on my PC. It looks better and works more efficiently than the way it was before.

TIPS & TRICKS

This gentleman has developed a great self-watering system for inside plants. Very well-thought-out system and extremely inexpensive.


PODCASTS / VIDEOS

I am a minimalist or, at the very least, a minimalist in training. I have made progress in some areas and have slipped in others. In other words, I am human. Today I came across this nice video that gives solid advise on how to get started in the process of minimalism.


I tend to be the room-by-room, do-it-now, no plan, purger. I will try some of these strategies to help me become more efficient at handling the excess items in my life.

TECHNOLOGY

The planned installation of the new router went without a hitch. The new unit is a NETGEAR Nighthawk AC1900, and the thing screams. After some minor fine tuning, the wireless speeds have gone from under 10 Mbps to just under 50 Mbps. My cellphone maxed out at 99 Mbps downstairs, and about 50 Mbps upstairs. I am very pleased with the equipment and with the increased performance.

If you are buying a new router, it is advisable to do a few things immediately:

  1. Change the administrator's password; my new router forced me to change the password, which is a very welcomed change from past practices.
  2. Change the SSID (the wireless identifier) to something unique and also that will not identify you personally. Leaving the default name (my router used NETGEAR70) could possible allow a hacker to guess the password of your unit. Change the router name makes it just a little harder.
  3. Change the default passwords. My router has two possible passwords, one for the 2.4 GHz band (for desktops and laptops) and one for the 5 GHz band (for mobile devices such as phones). You can allow the router to use the same name and password for both or you can keep them separate; I have opted for separate for now.
  4. Change the passwords for your WiFi access every three to four months. Use some cyber-security hygiene steps and use a strong password that has 10-12 characters made of upper and lowercase letters, numbers and special characters.I advocate the use of password padding: select a password/phrase that is easy to remember (for example, TheRedFox99) and now use three or more of the same special characters at the start and end of the word to make it stronger. For example, $$$$TheRedFox99$$$$ is easy to remember and not so easy to crack. By the way, that is NOT a password I have ever used. :-)  Use a password strength checker and see the difference padding can make. The one without padding came at 78% strength. The one with padding was 100% strong and the only weaknesses reported is that it uses repetitive characters and repetitive numbers. So, to make it near perfect, we could change it to !1@2TheRedFox98#3$4 … but now that gets hard to type and hard to remember. To me, the small difference between $$$$TheRedFox99$$$$ and !1@2TheRedFox99#3$4 is not worth the extra brain power and confusion.
Tomorrow I will write a little about password managers and why they are critical for online security.

STREAKS - For the record

Current list of streaks:
  • Writing: day 24
  • Blood Pressure Readings: day 11 (started on the high side but I wa able to bring it down with deep breathing and acupressure)
  • Logging to SparkPeople: day 14
  • Daily Exercise Routine: not counting for now
    • Cardio: Yes -- awesome 3.63 miles in 66 minutes
    • Yoga: Not today
    • Strength Training: Nope
    • Stretching: Yes, as I got up and after running
    • Meditation: Yes, first thing in the morning
  • Meditation: day 11
  • Number of tabs open: day 7