Pages

Friday, 27 November 2015

Five practical steps to protecting data on mobile devices!



Every month we see another story hit the headlines of how a household name has lost customer data. These type of incidents can cost millions to put right, not just in updating the IT systems, but in terms of lost revenue due to loss of good reputation, and potentially punitive fines.
When the new EU General Data Protection Regulation (GDPR) comes into force, expected during 2017, fines for non-compliance could be 5 per cent of global turnover. This is a significant sum for any size of organisation and deserves serious consideration.

Lost or compromised data costs

The causes of data breaches are many and varied, but the majority are a result of either malicious attack or human error. Recent research into the root causes of data breach found that 47 per cent involved a malicious or criminal attack, and 25 per cent involved a negligent employee or contractor.
The losses arising typically fell into three categories:
  • The value of the data stored on the device itself
  • The increased risk of a targeted attack on the company’s people and systems
  • Fines levied by regulatory authorities, particularly if the breach involved personal information.

How organisations fail to protect data

Many companies lack policies for governing how data is managed and protected, especially on portable devices. This is often accompanied by limited awareness among employees about the implications of their actions and what they can do to reduce risk.
Businesses fail to adequately protect data stored on desktops, laptops and portable media, often due to some common misconceptions.
  • Just because a user needs to enter a password to log onto their Windows domain, doesn’t mean that the data is protected. A hacker could still easily access the data.
  • Many companies install Endpoint Protection products to protect devices from malware and targeted attacks, assuming that this will protect the data. It doesn’t.
  • Even with full disk encryption, if data can be copied on to an unencrypted portable device (such as USB devices or smartphones), then the data is still at risk.
However, if security is too complex or restrictive and impacts peoples’ ability to do their work, they will simply find a workaround, leaving a company in an even worse position falsely believing that their data is secure.

Cabinet Office supports flexible working with encryption

The Cabinet Office, which is the government department that supports both the Prime Minister and Deputy Prime Minister, ensuring the effective running of government, faced a similar problem to many commercial organisations. They needed a security solution to protect data held on laptops. The challenge they faced was maintaining a high level of security while improving the user experience. Previously they had used two factor authentication resulting in lengthy login times, and loss of tokens causing disruption to both the user and manager.
By installing a solution that provides strong encryption, that is transparent to the user and without the need for two factor authentication, they have significantly improved login times for users, and removed the disruption caused by lost tokens. As the security solution can be managed centrally, the IT department can provision devices quickly and easily, reducing waiting time for staff, and dramatically reducing the cost of ownership.
The adoption of more flexible and mobile ways of working is a key enabler for Cabinet Office staff, and good data security is a key component of this. Productivity is maintained, while laptops are managed and controlled centrally, saving time, resources and protecting valuable data.
In a world where cyber attacks are on the increase, at least if the worst happens and data is stolen, if it is encrypted, it is worthless to the criminal.

Five Practical Steps

1. Protect your data
Implementing effective security measures begins with understanding what data you have, where it is stored and how it is shared. More breaches occur from data being copied onto removable media and devices, rather than lost or stolen laptops. Protect your data by ensuring that any data that is copied to a peripheral device is fully encrypted.
2. Don’t rely on single layers of security
Multiple layers of protection reduce your vulnerability to malicious or accidental breaches. For example, as well as requiring user authentication via password, you could implement technology on your devices that prevents the hard disk being unencrypted if removed from the device.
3. Reduce complexity where possible
The more convoluted your security procedures for users, the greater the likelihood of breaches as a result of their actions. Enabling single sign-on to any device limits the impact on your users and reduces your risks.
4. Security is key – but the business still needs to operate
If your security policies and technologies prevent people doing their jobs, they’ll inevitably find a way to bypass those controls. When implementing technology solutions, check that they’re flexible enough to meet the needs of your business and your users.

5. Ensure you have effective management control
Having the right technology on your endpoints is of limited value if you can’t easily manage that technology and you don’t have visibility of what users are doing on their devices. Ensure you have the tools to monitor and report on which devices have been encrypted and what data users are copying to removable media.


If you can’t prove to regulators that you’ve taken all reasonable measures to protect your data, you’re more liable to receive a substantial penalty.
Image source: Shutterstock/Maksim Kabakou


Windows10 might still be spying on you!!



Instead of removing a spying program from its operating systems, Microsoft has just renamed it and hoped nobody noticed.
Tweakhound, however, noticed and as you might suspect – people won’t be too happy about it.




Here’s what happened: This May, Microsoft has released a patch for Windows 10 and Windows 8.1 called KB3022345. The interesting scary thing about the patch is that it included a background tracking service called DiagTrack, or the Diagnostics Tracking Service. It was a service which gathered the user’s personal data, including “name, email address, preferences and interests; browsing, search and file history; phone call and SMS data; device configuration and sensor data; and application usage”, as Microsoft explained itself.
In recent Windows 10 builds, though, the program seemed to have disappeared – but it had not. Microsoft has instead just renamed it to “Connected User Experiences and Telemetry Service”. It has a much nicer ring to it than Diagnostics Tracking Service, right?
“It is this kind of overriding desire for control and a disregard for user choices which is harming Windows 10,” says Forbes journalist Gordon Kelly.
Tweakhound says the service should be disabled and not deleted. “Disable it via services,” he says. “In the screen shots below I ran sc delete. As the name implies this DELETES the service and may cause issues later. I DO NOT RECOMMEND THIS. JUST DISABLE IT.”

You can disable the service by pressing Windows + R keys, typing services.msc, and pressing OK. After that, look for the “Connected User Experiences and Telemetry Service”, open it and press Stop.



Google can remotely unlock most Android devices by court order


For those that have an older Android device, or have a device that has yet to be updated to the latest version of Android, Google has the power to unlock your device remotely. While this won't happen out of the blue or by random request, it is a bit unsettling.
According to documents obtained by The Next Web, Google can remotely unlock phones if served with a search warrant and a request to assist law enforcement. Although this doesn't apply to all Android devices, it still encompasses a large portion - affecting all devices running anything lower than Android 5.0 ( roughly 74%). Those with an Android 5.0 and above device will not be affected, as the device offers encryption and Google is not capable of remotely unlocking your device.
Currently, the only factory encrypted devices are offered directly through Google via its Nexus program. Android 5 and 6 both offer the ability for encryption, but manufacturers have not enabled the feature by default due to performance and other issues.

First Android Smartwatch By Fossil, Now Available!



Traditional watch and jewellery makers have started entering the smart wearables market recently with Tag Heuer being the latest one to do so. Two weeks ago, premium watchmaker, Fossil acquired Misfit, Inc to introduce more connected wearables and accessories than it already does. Now, the company has announced the pricing and availability of the Fossil Q Founder smartwatch.
The Q Founder is powered by Android Wear and runs on an Intel Atom processor. Fossil hasn't revealed any other specifications of the wearable. The smartwatch can be paired with a smartphone running on Android 4.4 and higher, or an iPhone running iOS 8.2 and higher. It includes standard Android Wear features such as changeable watch faces, activity tracking, notifications, alerts and voice commands.
Fossil will be selling the device through its online store as well as select retail stores fromNovember 25, for a price of $275. Consumers can choose from a variety of stainless steel or leather straps to customize the Founder Q for an additional price.
Source: PRNewswire via Slashgear | Image via Fossil

Are External USB Hard-Drives at Risk from Internal Condensation?

While most of us do not need to pack our external hard-drives with us everywhere we go, there are some people who may need to carry them wherever they travel. With that in mind, can noticeable differences in temperature have a negative impact on those hard-drives? 

Condensation is a real danger for hard-drives. You can see in a real-lifeYouTube demonstration by a data-recovery specialist what a hard-drive looks like when taken out of a freezer and briefly turned on (it is full of scratches):
Such scratches could possibly damage the hard-drive to a point where even a data-recovery specialist would be unable to recover the data. A Control Data (later Seagate) factory packaging manual for hard-drives says:
  • If you have just received or removed this unit from a climate with temperatures at or below 50°F (10°C), do not open this container until the following conditions are met, otherwise condensation could occur and damage to the device and/or media may result. Place this package in the operating environment for the time duration according to the following temperature chart.
are-external-usb-hard-drives-at-risk-from-internal-condensation-02
It seems that dangerously low temperatures start when a computer is brought in from temperatures below 50°F (10°C) into a room-temperature area and it may need several hours for acclimatization. This long time is explained by the fact that in a mechanical hard-drive, the head is supported by airflow entering through special air-intakes. These intakes are heavily filtered against dust, but not against humidity. They are also small enough that it slows down the evaporation process of internal humidity.
You could possibly minimize the acclimatization time by wrapping the disk in watertight plastic while it is acclimatizing in order to reduce the humidity that would enter via the air-intakes. You should allow for some drying-off time after unwrapping the disk (for the humidity in the air already contained inside the disk).
This is not the only danger, as explained by data-recovery specialist ReWave Recovery:
  • A hard-drive is at risk for sudden temperature changes including overheating and condensation.
  • A sudden change in temperature that causes condensation inside the hard-drive can cause the material on the platter to evaporate which causes the read/write heads to stick to the platter and stop it from rotating.
  • Overheating can also be an issue. Overheating can cause the platters to expand which makes the read/write heads travel farther to read the data. The expansion of platters can cause friction which can lead to a head crash.

HealthCare Industry Can Save $10 BiIllion Annually By Using IoT Packaging


The Internet of Things (IoT) is growing in the packaging industry, as companies recognize the ways that it can help track important items such as medications, according to Scott Jost, vice president of innovation and design at Berlin Packaging.
Jost said he's seeing more packaging requirements now where the package has to offer some bi-directional communications, something that you would associate with IoT.

Compliance packaging: The first application of IoT in packaging

Probably the biggest application area for that right now is in compliance packaging, Jost said.
"It's a $10 billion a year loss that the healthcare industry associates with people not taking their medication in a timely fashion," Jost said. He pointed to medications where if you take that any other frequency or dose that what was prescribed for you, the medication will have little or no effectiveness. In some extreme cases, medications can be dangerous to you if you break from the prescribed dosage and frequency.
"We've all seen the little containers that folks have with the Sunday, Monday, Tuesday and so forth," he said. "You put your pill or your vitamin supplement in the appropriate chamber, and that's where it gets even more complex, and people have multiple doses per day or doses that skip a day."
Jost says that as these containers grow and become more difficult to use that there have been proposals for IoT-type solutions to replace the containers. These solutions have an integrated container and closure that link up with a cloud-based application to which a patient and their doctor can input the information for reminder to take medication at a certain time. Many of these containers will have an indicator or light showing that it's time to take medication.
"That's probably going to be the first application of IoT from a packaging standpoint because that's where there's a confluence of both money being lost, lives being lost and a system that could bear the cost of doing so," Jost said. "It's hard to imagine the world where we would need that for shampoo. Let's face it, nobody's losing any more money than the cost of one dose of shampoo if I forget the shampoo tomorrow."

IoT smart packaging in healthcare environments

According to Jost, hospital pharmacies have a secure system in place (for example, Pyxis) that secures controlled substance upon entry into the hospital. Jost said, "Then the caregiver, the authorized caregiver in the hospital has to login, has to input the correct information for the patient and then submit to some level of security before the machine will automatically dispense the product that they're allowed to have."
There's also a checks and balances system of scanning the patient wristband to make sure the right patient is getting the right product.
"This is where we can get to the point where we're talking about packaging-level IoT; now we've got another level of traceability," Jost said. "The traceability would continue all the way to the point of the patient and to the point of opening the final primary component. We could see a system like that taking the form of replaceable component, because unlike the disposable packaging that you see in pharmacies today, this could be something that just goes back into the system and is reprogrammed to get it back to a blank slate so that you can reset it and redeploy into the hospital setting."
The traceability would continue all the way to the point of opening the system, which for which a trigger or alert can be set, he explained.
Typically, once the product is removed from Pyxis, at that point what happens with can be a little bit of an unknown.
"I can swipe in as an attending nurse, get the product out using the patient information and then walk to the right instead of the left and do something with it. Or if somebody could divert my attention and maybe there's a mismatch in terms of which patient gets which product," Jost said.
"If I have IoT traceability to the level of all the way to the patient room, I could keep that container locked until a wrist scan," Jost said. "There's an indication that I am standing next to the patient for which that product should be dispensed."


How To Be Mentally Strong??



Being physically strong is easier as compared to overpowering the demons in one's head. For physical fitness, you workout, eat healthy foods and in two months, you can see the result yourself. However, being mentally strong isn't that easy. There is no hard and fast rule, neither a trainer to promise positive results. Well, here are 5 effective ways to strengthen your mind.
Be positive: That's one of the best ways to develop inner strength. Even if you lose a battle, never say 'no' or take a U-turn. Resigning from a losing match never makes one strong. Rather figure out the reasons of failure and try to rectify them in future.
Never feel sorry for yourself: You might have committed a mistake. But to err is human. So, learn to forgive yourself. Many psychologists say that you should feel sorry for your mistake. No, rather accept your failure and try to achieve the winning feat in the next move.
You can't please all: If you find a flaw with something, be frank and express yourself. You can't please everyone. People with a strong mind aren't afraid of speaking their heart out.
Don't repeat mistakes: Making mistakes is fine, we have said this earlier. But that doesn't mean you keep repeating your mistakes. One mistake is okay but multiple mistakes are simply unpardonable. Einstein once said, "the definition of insanity is doing something over and over again and expecting a different result." Learn from your past.
Self fear: Try to spend time in introspection. Recapitulate your day's work and activities, both good and bad. If you don't get time throughout the day, just before hitting the bed, give a thought to the things that helped you rise and the ones you need to improve upon.